AI is no longer a future feature in application security; it is rapidly becoming a core part of how application security (AppSec) tools identify, prioritize, and remediate risk. Yet despite aggressive vendor investment, adoption remains constrained by trust concerns, questions about value, and uncertainty about pricing models. In our new report, The State Of Artificial Intelligence In Security Tools: Application Security, we analyzed responses from 31 application security vendor respondents to understand where AI is delivering value today and where the market is headed.

Here are three key takeaways.

  1. Trust Remains The Biggest Barrier To Adoption

The application security market finds itself in an unusual position. Vendors are racing to embed AI capabilities into their products, while many buyers remain skeptical about the outcomes.

AppSec teams are particularly cautious because many AI-enabled features require access to sensitive proprietary code or are expected to make recommendations that could impact production systems. While organizations are eager to improve efficiency and reduce toil, they are also balancing concerns around accuracy, privacy, governance, and explainability. As a result, trust continues to outweigh technical capability as the primary factor determining adoption.

The challenge for vendors is no longer proving that AI can generate output. The challenge is proving that users can depend on that output.

  1. AI Value Is Concentrated In Practical, Workflow-Level Improvements

Despite the excitement around autonomous systems, today’s most successful AI features are remarkably practical.

Our research found that vendors see the greatest customer adoption around capabilities such as data analysis, information summarization, rule recommendations, and response recommendations. These features help security and development teams make sense of overwhelming amounts of security data and reduce the effort required to perform routine tasks.

The figure below illustrates an important dynamic, pointing to an opportunity for vendors not doing so today to use AI to provide recommended responses or rules and add those features to their offerings to increase customer value.

The winners in AppSec AI won’t necessarily be the vendors with the most features. They will be the vendors that help teams make better decisions faster.

  1. Pricing Is Becoming A Competitive Differentiator

One of the more surprising findings from the research is how vendors are approaching monetization.

Many application security vendors currently include AI capabilities as part of their existing offering rather than charging separately for them. Others are experimenting with hybrid approaches, add-on models, and consumption-based pricing for more advanced capabilities such as automated remediation, reasoning-intensive analysis, or agentic workflows.

The specific pricing distributions are covered in the full report, but the broader takeaway is clear: The market has not yet settled on a single monetization strategy. Security leaders evaluating AI-powered AppSec products should look beyond headline functionality and carefully assess how pricing aligns with expected usage, value, and operational outcomes.

What’s Next?

Today’s AI capabilities in application security are largely assistive. But vendors are already looking beyond summarization and recommendations toward agentic workflows, automation, and eventually autonomous security operations.

The key question for security leaders is no longer whether AI will become part of application security programs. It is which capabilities provide meaningful business value today and which remain aspirational.

To learn what AppSec vendors are delivering now, where they plan to invest next, how customers perceive value, and how AI pricing models are evolving, Forrester clients can read the full report, The State Of Artificial Intelligence In Security Tools: Application Security, or request an inquiry or guidance session with us to discuss AI in application security solutions.

Share