VOOZH about

URL: https://thenewstack.io/the-modern-apis-roundtable-how-ai-creates-new-challenges-for-api-security/

⇱ The Modern APIs Roundtable: How AI Creates New Challenges for API Security - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-10-15 11:00:17
The Modern APIs Roundtable: How AI Creates New Challenges for API Security
contributed,
AI / API Management / Security

The Modern APIs Roundtable: How AI Creates New Challenges for API Security

By embracing these solutions, organizations can unlock the full potential of AI-driven innovation while maintaining security, compliance, and operational efficiency.
Oct 15th, 2025 11:00am by Adam LaGreca
👁 Featued image for: The Modern APIs Roundtable: How AI Creates New Challenges for API Security
Photo by Ilya Pavlov on Unsplash.

APIs are the lifeblood of the internet, enabling seamless communication between applications, services, and devices. With the rise of AI technologies, APIs have taken on even greater strategic importance, powering intelligent applications, large language models (LLMs), and complex ecosystems. However, this rapid evolution presents significant challenges in terms of discovery, security, standardization, and governance.

I recently had the privilege of hosting a roundtable discussion featuring panelists Joni Klippert (CEO of StackHawk), Rodric Rabbah (Head of Product at Postman), and Alex Drag (Head of Product Marketing at Kong). These industry leaders highlight key issues and emerging approaches that are shaping modern API management in the era of AI.

The Challenge of API Discovery and Visibility

As APIs proliferate across organizational environments, maintaining a comprehensive and up-to-date inventory becomes increasingly challenging. Alex Drag of Kong discusses at length the challenges with wrangling APIs across multiple gateways. At the same time, Joni Klippert of StackHawk notes that security teams often overlook only a fraction of the total API landscape, exposing organizations to significant security risks due to these blind spots.

To address this, the panel emphasizes the importance of having a centralized place to discover and view APIs across an organization, including metadata such as ownership, security policies, and usage monitoring. Techniques such as code-based scanning and integrations with existing developer tools help improve visibility and control, enabling organizations to keep pace with their expanding API ecosystems.

Proactive API Security in a Complex Ecosystem

Moving from reactive to proactive security practices is also a recurring theme in the conversation. StackHawk’s focus on testing APIs during development underscores the importance of identifying vulnerabilities early. The concept of “security debt” — the accumulation of untested or insecure APIs — poses a significant threat to organizations.

Postman’s Roderick stresses the importance of continuous monitoring, scanning, and securing APIs even before deployment. Aligning developer incentives and offering clear security guidance fosters proactive behavior, reducing the risk of breaches and enhancing overall API resilience.

Streamlining Documentation and Standardization

Keeping API documentation current and accurate remains a core challenge. Developers often view documentation as a burdensome chore, leading to gaps that can hinder security and governance. StackHawk advocates for AI-powered solutions that automatically generate API specifications from source code, reducing manual effort and improving accuracy.

Another issue is a lack of standardization within organizations. Rodric Rabbah of Postman acknowledges that diversity in API gateway implementations complicates this effort, but ultimately concludes that maintaining a consistent, centralized API landscape is crucial for governance and security assurance in rapidly evolving environments.

API Monetization and the Impact of AI

APIs are increasingly seen as strategic assets capable of generating revenue through monetization models, both internally and externally. The advent of AI and LLMs introduces new layers of complexity and opportunity — necessitating better governance, security, and visibility.

Drag opens a discussion on the evolution of API management tools to support emerging use cases, including API scorecards and the Model Composition Protocol (MCP). As the convergence of APIs and AI accelerates, organizations must adapt their management strategies to ensure security, cost control, and operational agility.

Conclusion

The roundtable discussion paints a comprehensive picture of the challenges and solutions shaping modern API management. As APIs become increasingly intertwined with AI, organizations require proactive, centralized, and automated tools to discover, secure, and govern their digital assets effectively.

Vendors like Kong, Postman, and StackHawk are leading the charge from different angles, offering innovative approaches that address the complex realities of today’s API landscape. By embracing these solutions, organizations can unlock the full potential of AI-driven innovation while maintaining security, compliance, and operational efficiency.

The Modern Observability Roundtable: AI, Rising Costs and OpenTelemetry

TRENDING STORIES
Adam LaGreca is the founder of 10KMedia, a boutique public relations agency for B2B DevOps. Prior, he was the director of communications for DigitalOcean, Datadog and Gremlin.
Read more from Adam LaGreca
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Postman.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.