Loading…
Friday November 6, 2026 3:30pm - 4:15pm PST
Security review is getting squeezed from both sides. Product teams ship faster, GenAI has accelerated how quickly new features get built, and review teams are still expected to read each design doc from scratch and decide what can ship. That breaks down long before the roadmap slows down.

This talk shows an AI-assisted pre-launch review pattern built for that problem. The pipeline does not stop at generating a generic threat list or a dashboard for leadership. It starts with a structured risk taxonomy, mapped control expectations, and a corpus of historically reviewed launches. Given a PRD or design document for any new feature or application—not only GenAI products—it produces a reviewer-ready first pass: likely risks (from OWASP and internal), targeted follow-up questions, relevant control areas, and concrete mitigations grounded in both reviewer expertise and decisions that were approved in similar launches before. The same structure can support rollups for leadership, but the real value is at review time: better questions and earlier mitigations.

A key step is similarity-based retrieval over historical reviews. After the initial pass, the system looks for comparable launches and reuses the risks, control signals, and mitigation patterns that mattered in those cases. This helps recover issues that a single pass often misses and keeps the review grounded in how the organization actually makes launch decisions. Every completed review becomes another case in the corpus, so future reviews start from a richer set of approved precedents.

We will walk through the architecture, the feedback loop, and the places where this fails: thin design docs, stale taxonomies, misleading historical matches, and overconfident model output. We will also share results from a labeled benchmark of 19 PRDs and 205 human-reviewed risk labels. At a recall-oriented operating point, the pipeline reached 75% recall and 60% precision, and historical retrieval recovered 4–9 additional relevant threats per PRD on similar cases. Next steps including adding more data sources such as code repositories & live traffic.

The initial deployment focuses on fraud, but the pattern is being extended to other threat domains that matter in large product organizations, including abuse, privacy, and product security. This is not about replacing reviewers. It is about giving them leverage. Attendees will leave with a practical blueprint for turning blank-page review into a faster, more consistent workflow that surfaces mitigations before the design is already on its way to launch.
Speakers
avatar for Liat Ben Porat

Liat Ben Porat

Director, AI Science, Intuit
Liat Ben Porat leads the AI science organization within Intuit's global trust, fraud, and security group, where she drives the strategy, development, and adoption of AI solutions across security, fraud, compliance, and workforce teams. She also serves as her organization's lead for... Read More →
GS

Guy Shtar

AI Security & Safety Architect, Intuit

Guy Shtar is an AI Security & Safety Architect at Intuit, working on the intersection of GenAI, security, and Trust & Safety. His work focuses on turning subjective review workflows into measurable technical systems, including AI-assisted risk discovery, adversarial testing, and security... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom C (Street Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link