Things have changed, really fast. Exhibit A: It's now perfectly normal for a company to declare that 80% of its code is written by AI - and that this number is expected to grow even more in the coming months. In case you hadn't guessed, that company is Appcharge.
"Is it more scary or exciting?" I asked Lior Mazor, Appcharge's security chief, who faces the daunting task of keeping the company ahead of AI-related risks.
"I think your question should be: do you think the world is becoming more secure or more dangerous?"
"It depends on the day," he admits, answering his own question with a wry smile.
We talked on the sofas in Appcharge's Tel Aviv office, floor-to-ceiling windows behind him looking out over the skyline and the sea. Lior speaks the way you'd want someone responsible for safeguarding a platform processing north of a billion dollars a year to speak: measured, fluent, no hesitation, no filler. Twenty years in cybersecurity will do that.
His argument, stated early and returned to more than once, is that the old model of security is changing, fast.
"The paradigm that the solution will come to you, I think that's outdated," he says. "I need to build these things myself now, not wait for a security company to hand me a feature six months from now. I need to protect my company today."
For twenty years, security leaders waited. A new threat emerged, a vendor built a product for it, and eventually the fix arrived. Lior's view is that this sequence no longer works. AI-written code now moves faster than any procurement cycle can.
He's watched that speed play out well beyond code. "We are a startup company. I think our main strength is that we can move fast. I've been in meetings where we thought about a very tough issue and brainstormed solutions, and by the next morning it was developed. That's the pace we're working at, and this is what our customers require. It always amazes me."
That's the environment his framework has to hold up inside. "Business use cases emerge daily. We need to move fast and produce value for our customers, publishers, and players," he says. "But every piece of code produced by AI still gets scanned for vulnerabilities and fixed, sometimes automatically, before it can put our customers or our company at risk."
Using AI against AI

He uses a framework called AI-SDLC, an AI-secure software development lifecycle. The distinction matters because most companies, he says, are still running a traditional SDLC and assuming it covers AI-generated code.
"Even when I talk about AI-SDLC, most companies have only implemented the old SDLC. It's a different animal. Even the toolset is different."
In practice: internal systems scan every commit, flag vulnerabilities, and generate a fix as a pull request before a human sees the problem. Developers are becoming reviewers of AI-produced fixes rather than authors of first drafts. Accountability doesn't move with the work. If shipped code breaks something, the developer who reviewed it owns that, regardless of who wrote the original line.
A separate system he calls AI-DR checks that only approved AI tools are in use across the company, and flags policy violations before they become incidents.
"You can use any AI tool you want personally," he says. "But you don't know its privacy posture, or whether the AI itself can be attacked. Here, we need an approved tool."
We're hiring.
Join us
Thinking like a hacker and AI agents – the modern toolkit
Ask Lior how he actually keeps pace, and the answer is a habit he's kept for years.
"I'm thinking like a hacker". He takes a beat. “To know how to protect the organisation, you need to know how to hack it."
If waiting for a threat report was the old model, the new model is about proactively staying ahead. Running alongside the human intelligence gathering: three AI agents that report to him directly. One continuously scans and fixes security defects in code. One checks the company's alignment with compliance standards. One functions as an AI-driven security operations center, triaging alerts and running initial investigations around the clock.
"They work 24/7," he says. "They can alert me to a breach and even start the investigation before I've seen it."
Even if one layer is breached, another is built to catch it - what the industry folks call Defence in Depth. No single control protects customer data alone.
But he's careful about what this does and doesn't replace. "Someone still needs to tell the AI what should be done. It's extending what we can do."
Where he draws the line
For a security lead enabling his company's push toward higher AI-written code, Lior is quite specific about where AI still doesn't belong. HR and certain finance processes at Appcharge remain human-in-the-loop by design.
"The risk is that information gets disclosed to the wrong people," he says. "So we've decided: let's wait."
It's a small detail, but it separates conviction from recklessness. The old way of thinking about AI adoption was binary: locked down everywhere, or open everywhere. His version enables AI wherever the risk calculus supports it, and holds the line everywhere it doesn't.

The teacher

Twenty years in, Lior describes his role in a way that breaks from how most CISOs talk about the job.
"I realized I'm basically a teacher of security," he says.
That shapes how he runs phishing drills and training internally. He runs them, but refuses to treat them as a trap.
"I don't want to fail someone. I don't think that's the right way to learn."
Appcharge's scale gives this more weight than it might carry elsewhere. Enterprise clients now routinely send security questionnaires that probe AI usage before signing anything, and Lior treats those less as compliance paperwork and more as a preview of where the whole industry is heading.
"We're seeing more RFPs come in with AI security requirements built into them," he says. "Some of these aren't legally mandatory anywhere yet. They're just becoming the standard."
It's the same instinct behind the advice he'd give other security leaders directly, and he doesn't hedge when asked.
"Always learn. Be open-minded. Become a business enabler," he says. "I'm not here to be a blocker of new technology. I'm here to make it possible to move fast, safely".
--
Not long after our interview, Lior mentions he sails and recalls his experiences navigating through stormy weather.
He's facing another kind of storm now, and if one thing is certain from our time together, it’s that he’s in his element.
Lior Mazor is Appcharge’s Director of Security. Charged is Appcharge's editorial publication, covering the people and craft inside the company and beyond.
