AI-assisted software development means security teams need an ‘engineering-first’ mindset
As AI-powered coding accelerates, security teams need to start operating like developers
AI represents a prime opportunity for security teams to keep pace with accelerating development timelines, according to GitLab CISO Chaim Mazal. But this will require tweaks to traditional processes.
The use of AI in software development is fast approaching near-universal levels, with figures from Stack Overflow’s 2025 Developer Survey showing 84% of developers have adopted the technology.
While AI is helping speed up code production, streamline development lifecycles, and drive productivity, Mazal told ITPro it’s also creating new security risks.
“Businesses have decided that in order to be successful in this next wave of the journey, AI has to be leveraged and teams have to go full bore,” he said.
“I think in tandem and parallel, security teams have been working on figuring out how they can build appropriate solutions to be able to enable their organizations to do that.”
Mazal noted that enterprises are still working around the “same practices and principles that we’ve historically followed” - robust testing, reviews, and security checks.
But with the advent of agentic AI and the pace of change, there’s a risk that blind spots could emerge somewhere in the process.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Indeed, it’s an issue that GitLab recently highlighted in a study. Analysis from the company in June warned that eight-in-ten organizations are adopting AI tools faster than they can develop policies to govern them.
The influx of AI-generated code is also proving troublesome for enterprises, with a study from Tricentis showing that roughly 60% of organizations have shipped untested code.
The result here is that security teams now face a confluence of challenges. Potentially dangerous AI-generated code and increasingly fast development timelines are placing huge pressure on teams to ensure products ship in both a timely and secure manner.
An engineering-first approach
Keeping pace with AI-powered development will mean security teams essentially have to start operating more like their counterparts in development in an ‘engineering-first’ approach.
This is an operating model that takes core engineering principles such as automated testing and CI/CD pipeline techniques and embeds them within security processes. Simply put, rather than acting like manual auditors and policy enforcers, they play a more involved role in development processes.
Moreover, they build parallel products designed to support development from the get-go. Fundamentally, this is about being a “first-level contributor” in software development, Mazal said.
“As our engineering teams move fast, having the security team have the ability to contribute code, make iterative adjustments, and be part and parcel with the development process is key to our success,” he told ITPro.
“Being able to move fast, iterate fast, and not just be consultative in nature, and being able to really roll up our sleeves and work alongside the rest of the teams to build that secure path and the secure guardrails is something I think most modern security teams don’t have the luxury of foregoing.”
When it comes to AI, what’s good for the goose is good for the gander. Security teams should view the technology as a means to keep up with development processes – as with developers, teams need to automate where they can.
Humans in the loop
Ensuring humans remain in the loop throughout the development and testing process will still be vital moving forward, according to Mazal. The exact scope of human involvement is still up for debate, however, and the long-term goal is to automate as much as possible in the safest way
“I think most organizations who make commercial-level software want to get to a place where there are only humans in the loop in places that it’s absolutely necessary, based on the risk to the organization,” he said.
“They’d like to be able to have the overwhelming majority of their code auto-generated and auto-reviewed.”
Mazal said this has the potential to pose new challenges for developers, testers, and security teams alike. Fully-automated pipelines are still evolving, and as ITPro recently reported, some enterprises are exploring the concept of ‘dark testing factories’ to ramp up automation with little human input.
“Collectively we’re still trying to figure out as an industry what those best practices are, but we’re definitely making very big leaps and bounds in very short periods of time.”
GitLab itself is ramping up the use of agents in a software factory approach, Mazal noted, focusing intently on a security-conscious strategy. Agents need strict guardrails, and enterprises need to implement certain restrictions from the get-go.
“How we’re thinking about this at GitLab from a software factory perspective is that you have the ability from the very initial inception of design to bake in those security guardrails and requirements,” he explained.
“You can go ahead and create and craft them and define them based on the data sensitivity and requirements that you have, and you can uniformly implement governance controls across the board.”
These processes will naturally evolve as requirements change, Mazal said, and teams will “continuously make adjustments along the way”.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
The key to a successful IT strategyPodcast Exploring how IT leaders can implement change, lead by example, and deliver successful transformation projects
-
AMD talks up sustainability efforts with rack-scale energy efficiency gainsNews The company says it can help deliver more AI performance without increasing power, improve cost of ownership, and help customers scale faster