Navigating AI and Security with Jessica Mosley, TrustCloud
Categories: Podcasts , BrowserStack Talks
AI plays a significant role in quality engineering and security, but its limitations must be understood, and it should not be blindly trusted. Quality assurance is essential and often overlooked, requiring human judgment and oversight to ensure products are secure and compliant.
BrowserStack Talks
BrowserStack interview based podcast. Released as audio and video
- https://www.browserstack.com/community/podcast
- https://youtube.com/playlist?list=PL1vH6dHT3H7o6pnechxr17kUX---Bjj5K&feature=shared
Episode Details
- Show Notes: N/A
- Published: 2026-01-27T05:09:49Z
- Duration: 00:41:13
- Author: BrowserStack
Overview
The podcast explores how AI is transforming quality engineering and security, offering tools that can increase efficiency but also highlighting its shortcomings when dealing with human-based threats such as social engineering. It stresses the importance of using AI as a supportive tool rather than a complete replacement, with human oversight necessary to ensure AI outputs are accurate, ethical, and aligned with real-world security needs. The discussion also touches on challenges like AI drift, hallucinations, and the dangers of relying on unverified AI-generated results, emphasizing the need for robust guidelines and certification processes to ensure responsible AI use in these fields.
In addition, the podcast emphasizes the role of empathy in testing, the value of measuring bug costs as a key quality assurance metric, and the importance of fostering personal accountability and relatable examples to encourage stronger commitment to security and quality within teams. It underscores the necessity of continuous learning, effective communication, and collaboration among tech teams to adapt to the evolving landscape of AI integration in engineering and security practices.
What If
-
What if you implemented role-playing simulations to stress-test your AI-assisted QA processes?
Concrete move: Create D&D-style scenarios (e.g., simulating social engineering attacks or AI hallucinations) to practice responding to edge cases with your AI tools.
Why now: As AI adoption grows, so do exploitation vectors (e.g., hidden malicious commands in innocuous inputs). Simulations force you to identify blind spots where AI fails.
Expected upside: Youll preemptively validate AI outputs, reducing risks and building robust workflows that combine human judgment with automation. -
What if you integrated empathy-driven testing into your AI model quality checks?
Concrete move: Develop user personas representing diverse backgrounds and use them to craft test cases that stress-test AI for bias or data-handling flaws.
Why now: AI drift and hallucinations often stem from biased or incomplete training data, which can disproportionately affect underrepresented groups.
Expected upside: Youll catch hidden flaws in AI models, improving fairness and user trust while aligning with compliance requirements. -
What if you established a “Friday Learning Hour” to analyze recent AI security failures in your domain?
Concrete move: Dedicate 12 hours weekly to study real-world AI vulnerabilities (e.g., poisoned datasets or adversarial attacks) and simulate fixes in your own tools.
Why now: Cyber threats evolve rapidly, and solo developers cant afford to rely solely on outdated knowledge. Learning from actual breaches keeps your defenses current.
Expected upside: Youll stay ahead of emerging risks, build a proactive security culture, and avoid costly overreliance on unverified AI outputs.
Takeaway
- Validate AI Outputs Regularly: Integrate manual reviews of AI-generated results, especially for security-critical tasks, to detect hidden vulnerabilities (e.g., malicious commands in unexpected formats like poems). Avoid over-reliance on AI without human scrutiny.
- Commit to Weekly Learning Sessions: Dedicate time (e.g., Fridays) to study recent security threats, vulnerabilities, and AI risks through resources like security advisories or community discussions to stay updated on evolving risks.
- Track Bug Costs, Not Just Counts: Shift QA metrics to measure the financial impact of bugs (costs) rather than just defect numbers, encouraging prioritization of fixes that reduce long-term business risks.
- Practice Scenario-Based Testing: Use role-playing or “choose your own adventure” simulations (inspired by D&D) to model real-world security threats (e.g., ransomware attacks) and improve your ability to anticipate and test for edge cases.
- Engage in Collaborative Knowledge Sharing: Participate in online communities, attend virtual meetups, or collaborate with remote QA/security professionals to avoid silos and gain diverse perspectives on emerging threats and tools (e.g., Mable, BrowserStack).
For a PDF of longer Software Testing Podcast Episode Summaries with Briefing Notes and more detailed summary notes, visit EvilTester Patreon Podcast Summaries.