Searches every page: governance library, books, services, glossary, tools, insights.
The AppSec Program for a Probabilistic Runtime
Available nowBook 08 of 9 in The Operating Discipline for AI Library™, Book 4 of 5 in AI Risk Governance & Security™. Every application security tool in production today was built on a quiet assumption: that an application produces the same output for the same input. AI features have invalidated that assumption, and most AppSec programs do not yet realize it. This book introduces The Runtime Determinism Gap and provides the working frameworks AppSec leaders need to rebuild their program for applications that no longer behave deterministically.
Hardcover, 350 pages, $109.99, ISBN 979-8-9981369-4-8. Paperback, $46.99, ISBN 979-8-9981369-1-7. Kindle edition, $24.99, ISBN 979-8-9981369-3-1. Published September 14, 2026 by SRJ Consulting & Services Publishing.
Open Library edition OL62551257M, work OL45983747W. Amazon ASINs B0HJSVVWX1, B0HJSLWSS1, and B0HJWQVTVK. Every figure from the manuscript and all twenty-two instruments of the Consulting Toolkit are free to download below.
Volume VIII of The Operating Discipline for AI Library™ · 350 pages · Hardcover ISBN 979-8-9981369-4-8. The library sell sheet fits on one page and carries the full bibliographic record, ISBNs and list prices for every format, a summary of what is inside, and the collections the book suits.
A condensed visual companion to the book. The Runtime Determinism Gap and why pre-runtime assurance is impossible rather than merely hard, the five instruments that answer it, the three properties a running estate must hold, the coverage number a board can fund against, and the first ninety days sequenced by dependency. Twenty-six slides, built for the practitioner who owns the work and the leadership team that funds it.
The moment an application calls a language model, retrieves dynamic context, or hands control to an autonomous agent, the entire AppSec stack starts seeing partial behavior. Scans pass. Runtime defenses match patterns that no longer reflect what the application actually does. Bug bounties pay for reproducible exploits in an environment where reproducibility has become probabilistic. The result is a program that looks healthy on every dashboard while the actual risk profile of the product portfolio drifts somewhere the program cannot see.
This book names that condition The Runtime Determinism Gap and treats it as the single most important shift in application security since the move to cloud. Teams that close the gap use AI to compress the review and triage cycles they have been losing for a decade, and they rebuild their runtime defenses around behavioral validation rather than pattern matching. Teams that do not keep shipping applications that pass every existing scan and still fail in production.
The old application had three stages: input, code, and output. Every instrument the discipline owns assumes the behavior lives in the code. An AI application has six: input, interpretation, decision, authority, action, and consequence. Three of those did not exist before, and the toolchain sees one of them.
That is how a program reports green across every control it runs while covering a single stage of the application it is meant to secure. Pre-runtime assurance is not merely hard in the general case, it is impossible, so the bound has to hold while the application runs.
At its center are five working frameworks AppSec leaders can apply directly: The Behavioral Attack Surface™ (the application surface areas that change once AI is introduced); The Semantic Vulnerability Class™ (the bug taxonomy that exists at the meaning layer and how it extends OWASP Top 10 and OWASP LLM Top 10); The AppSec Capacity Equation™ (the math of vulnerability management when AI changes both the production rate of code and the inspection rate of security); The AI Application Security Lifecycle™ (the integrated operating model that merges DevSecOps with AI-specific controls); and The Continuous Validation Loop™ (the release-and-runtime model that replaces point-in-time scanning with ongoing behavioral validation).
The frameworks are aligned with OWASP LLM Top 10, the Google Secure AI Framework (SAIF), and emerging AI procurement expectations. They land inside existing DevSecOps cadence without breaking release velocity.
AppSec leaders and program managers, security architects, senior developers and tech leads, DevSecOps and platform engineers, CISOs and security directors, and product engineering managers in organizations shipping AI-enabled applications. Precise enough that a principal engineer respects it, accessible enough that a VP of Engineering walks into a Monday review with a specific list of questions.
Twenty-two working instruments ship with the book as its appendix set, from the Defensible AI Application Security Baseline Scorecard and the AI Application Portfolio Register through the Blast Radius Tier Map, the Seven Stop Conditions, the Authority Ledger, the runtime authority plane policy template, the Telemetry Specification, the Control Evidence Pack assembly guide, and the first ninety days plan. Every figure behind them, and every framework diagram from all eighteen chapters, is in the Chapter Graphics Library below, free to download and use within your organization today.
The book is the operating manual, written for the application security leaders who will run the program themselves: the register, the tier map, the authority plane, the behavior baseline, and the debt model, installed against their own estate. The Application Security in the Age of AI™ engagement is the execution of that model, designed for organizations that want the baseline scored, the discovery sweep run, the bounds drawn, and the first ninety days sequenced inside a defined timeline, not learned, drafted, and refined over two quarters of internal effort.
Teams that want the discipline in book form work from the book. Teams that want the register built against their own applications, the authority plane specified against their own platform, and the evidence pack assembled for their own auditors, work directly with the firm.
The worksheets and templates that ship with this book are free. Enter your email once, click the confirmation link we send you, and every book's downloads unlock across the site, forever.
The twenty-two operating instruments from the book, free and editable, one for every item in the Appendix. These are the working material of the first ninety days and the operating year that follows, not reading material. The spreadsheets work in Microsoft Excel, Google Sheets, Apple Numbers, and LibreOffice Calc; the fill-in forms open in any word processor.
The program’s first artifact. Seven areas, scored on one product, dated and reviewed. Fill it in first: in an afternoon it tells you where the program actually stands, and it produces the baseline every later instrument reads.
Every diagram, framework, and chart from the book is available here as an individual file. Use them in your slide decks, internal memos, board presentations, or training sessions. Free to use within your organization. Browse by chapter, click any image to download.
The Operating Discipline for AI Library™ is the nine-book series across two pillars — AI Business Services™ (four books) and AI Risk Governance & Security™ (five books) — each mapped to one of the nine SRJ service lines. Browse the series, or speak with us directly about applying the framework in your organization.
| Edition | ISBN-13 | List price |
|---|---|---|
| Hardcover | 979-8-9981369-4-8 | $109.99 |
| Paperback | 979-8-9981369-1-7 | $46.99 |
| Kindle | 979-8-9981369-3-1 | $24.99 |
Buy on Amazon List prices shown. Retailer pricing varies.