Skip to content

Image: datocms-assets.com · rights & removal

Executive Summary

Wiz AI SAST is a Public Preview capability offering AI code scanning to find complex business logic flaws, backed by Wiz Research. This capability analyzes application behavior to uncover weaknesses (CWEs) missed by traditional scanners. The tool leverages the Atlas harness and continuous refinement through AI security investments. Findings are correlated with the Wiz Security Graph, allowing teams to prioritize vulnerabilities using existing workflows. The platform handles the complexity of running AI scanning without requiring internal teams to build the necessary infrastructure. Furthermore, it incorporates automated lifecycle management for findings, including retesting and deduplication across scans, to ensure finding stability. Finally, Wiz AI SAST integrates context from the Security Graph to uncover hidden risks and utilizes a Green Agent to automate remediation plans based on full-context understanding.

Facts Only

* Wiz AI SAST is available as a Public Preview capability for Wiz Code customers.
* The tool analyzes application behavior to uncover weaknesses (CWEs).
* Findings are correlated with the Wiz Security Graph.
* Prioritized findings flow through existing policy, ownership, and remediation workflows.
* Wiz AI SAST incorporates automated lifecycle management for finding states across scans (Retest and Deduplicate).
* The system grounds analysis in the Wiz Security Graph to uncover vulnerabilities at the intersection of application logic and infrastructure flaws.
* The Green Agent investigates findings to build remediation plans grounded in context from code, pipeline, infrastructure, and runtime.
* The feature extends detection into logic-based vulnerabilities like Insecure Direct Object Reference (IDOR).
* The system integrates with AI coding agents like Claude Code for potential fixes.

Full Take

The narrative positions AI not as a replacement for security tooling but as an extension that addresses the limitations of traditional, rules-based scanning by introducing semantic reasoning about intent. The core tension lies between the potential for frontier-grade discovery and the operational reality of deploying non-deterministic AI in enterprise workflows. The solution attempts to resolve this tension by abstracting away the infrastructural complexity (model selection, harness management) and managing the inherent volatility of LLMs through automated lifecycle controls. This suggests a pattern where high-value, cutting-edge capability is gated behind an extremely complex infrastructure requirement; the vendor's leverage is in owning and simplifying that prerequisite complexity. The claim that AI enhances, rather than replaces, rules-based scanning by addressing intent-dependent flaws like IDOR introduces a necessary guardrail: the deterministic layer remains vital for syntax checks, while the probabilistic layer handles reasoning. The move toward Agentic Code Security suggests a structural shift from reactive tool management to autonomous lifecycle execution, raising questions about where ultimate accountability resides when AI agents autonomously execute remediation steps based on correlated context. What assumptions are being made about security team capacity versus agent capabilities in this new paradigm?

From the original · Wiz Blog

Find, validate, and fix complex business logic flaws with an AI code scanner backed by Wiz Research, operationalized within your existing security program. We’re excited to announce that Wiz AI SAST is available as a Public Preview capability, bringing frontier-grade vulnerability discovery to all Wiz Code customers.
Read the full story at wiz.io

Sentinel — Human

Confidence

The text reads like high-level B2B product positioning, effectively blending claims about cutting-edge AI application with established security processes, suggesting human authorship informed by technical knowledge.

Signals Detected
low severity: Moderate sentence length variance; strong use of declarative statements mixed with explanatory flow.
low severity: Highly focused argument, clearly structured around a product narrative (Wiz AI SAST) and its claimed benefits. Shows thematic consistency but leans heavily into promotional language.
low severity: Effective use of explicit structure to link features (AI, Harness, Agents) back to established security concepts (CWEs, TCO). The narrative flow is characteristic of marketing-infused B2B technical writing.
low severity: Claims about research backing (Atlas, CyberGym), and specific feature descriptions (e.g., Insecure Direct Object Reference example) are complex and context-heavy, suggesting human domain expertise integrated with marketing framing.
Human Indicators
The integration of highly specific, albeit abstract, concepts (Atlas harness, CyberModel Arena, Green Agent, Red Agent) suggests deep internal conceptual structuring beyond simple LLM summarization.
The narrative successfully balances technical aspiration with practical process management (e.g., handling non-determinism) in a way that reflects real security engineering concerns.
Introducing Wiz AI SAST: Application Security that Understands Your Code and Your Infrastructure | Huntaegis