{"id":9503,"date":"2026-09-16T08:25:00","date_gmt":"2026-09-16T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9503"},"modified":"2026-09-16T08:25:00","modified_gmt":"2026-09-16T08:25:00","slug":"ai-made-software-development-unrecognizable-is-cybersecurity-next","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9503","title":{"rendered":"AI made software development unrecognizable. Is cybersecurity next?"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual \u201c<a href=\"https:\/\/www.bloomberg.com\/news\/features\/2026-07-16\/anthropic-and-openai-tools-transform-the-profession-of-coding\">solitary ritual<\/a>\u201d of a developer writing code for hours is giving way to collaboration with an army of chatbots.<\/p>\n<p class=\"wp-block-paragraph\">In its 2025 report on the <a href=\"https:\/\/services.google.com\/fh\/files\/misc\/2025_state_of_ai_assisted_software_development.pdf\">State of AI-Assisted Software Development<\/a>, Google Cloud researchers found that even then, LLM usage was almost universal among coders, with 90% of developer respondents using AI as part of their work, and 80% believing it has increased their productivity. An earlier Microsoft study <a href=\"https:\/\/www.microsoft.com\/en-us\/research\/publication\/the-effects-of-generative-ai-on-high-skilled-work-evidence-from-three-field-experiments-with-software-developers\/\">documented<\/a> the effects AI had on productivity, with software developers who used AI completing 26% more tasks than developers who didn\u2019t use AI.<\/p>\n<p class=\"wp-block-paragraph\">The downside of the increased productivity is the impact on software developer jobs. Although data is hard to find, anecdotal evidence and some research show an impact on employment. For example, a March 2026 Federal Reserve Board <a href=\"https:\/\/fedinprint.org\/item\/fedgfe\/102997\/original\">working paper<\/a> found that <a href=\"https:\/\/www.cio.com\/article\/3951133\/remember-when-developers-reigned-supreme-the-market-for-software-coding-goes-soft.html\">coder employment is slowing<\/a>. \u201cWe find robust evidence that annual coder employment growth is about 3% lower now than it was pre-ChatGPT,\u201d the authors concluded.<\/p>\n<p class=\"wp-block-paragraph\">Not only has the number of developer jobs potentially dipped, but the organization around those jobs has also shifted. Gartner <a href=\"https:\/\/www.gartner.com\/en\/articles\/top-technology-trends-2026\">predicts<\/a> that \u201c80% of organizations will evolve large software engineering teams into smaller, AI-augmented teams by 2030,\u201d with more midlevel and senior specialists; managers supervising a wider arena of activity; new roles emerging that include <a href=\"https:\/\/www.cio.com\/article\/4137022\/new-it-roles-emerge-to-tackle-ai-evaluation.html\">AI-governance specialists<\/a>, context designers, and AI-augmented UX designers; and greater demand for systems-thinking.<\/p>\n<p class=\"wp-block-paragraph\">Experts predict these kinds of changes will soon be felt across the cybersecurity sector with agent-run SOCs, continuous vulnerability triage, machine-speed containment, and <a href=\"https:\/\/www.csoonline.com\/article\/4168681\/8-guiding-principles-for-reskilling-the-soc-for-agentic-ai.html\">humans directing fleets of defensive agents<\/a>, posing the potential to make information security unrecognizable from its current state.<\/p>\n<p class=\"wp-block-paragraph\">And yet, the analogy between the evolution of software and cybersecurity is imperfect.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe hard part for us is, if we\u2019re talking about where engineering is moving \u2014 to fully looped autonomous agents, feedback loops, all the things that they\u2019re building now, and just having humans supervise the machines \u2014 security really requires reproducibility,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/dlindner\/\">David Lindner<\/a>, CISO at Contrast Security, tells CSO, meaning that a security control must produce consistent, repeatable results.<\/p>\n<p class=\"wp-block-paragraph\">Moreover, any changes won\u2019t be as rapid for cyber as they were for software development.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI don\u2019t think cybersecurity will be completely changed that quickly, but certainly we will see month-by-month big changes, and two years from now, it may be unrecognizable from what it is today,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/jimreavis\/\">Jim Reavis<\/a>, CEO and co-founder of the Cloud Security Alliance, tells CSO.<\/p>\n<h2 class=\"wp-block-heading\">The autonomous SOC is almost here<\/h2>\n<p class=\"wp-block-paragraph\">The transition to a new world of cybersecurity has already begun, and the most obvious area transforming is the <a href=\"https:\/\/www.csoonline.com\/article\/3840447\/security-operations-centers-are-fundamental-to-cybersecurity-heres-how-to-build-one.html\">security operations center (SOC)<\/a>. Most experts agree that AI agents can easily do the job that fully staffed SOCs do today, and do it faster and better.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe had an incident come in through Jira, and the agent went and pulled all the information from GitHub, pulled all the information from Datadog, and then gave an initial triage,\u201d Contrast Security\u2019s Lindner says. \u201cI don\u2019t want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage.\u201d<\/p>\n<p class=\"wp-block-paragraph\">But there appears to be disagreement regarding how much authority SOC-replacing AI agents <a href=\"https:\/\/www.csoonline.com\/article\/4064158\/agentic-ai-in-it-security-where-expectations-meet-reality.html\">should be granted<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019re definitely leveraging AI tools, and maybe some of what would have been first-level triage is now being done by agents,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/lionellitty\/\">Lionel Litty<\/a>, CISO at Menlo Security, tells CSO. \u201cBut at this point, at least for us, we\u2019re not yet comfortable with just letting agents run wide in our SOC and make the ultimate decision of, \u2018Hey, this is something that we can ignore, or this is something that definitely we should look at.\u2019 We use them to help provide context and prioritize.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Still, experts believe that much of the <a href=\"https:\/\/www.csoonline.com\/article\/4186569\/5-new-security-operations-roles-the-ai-soc-will-create.html\">first-level work performed by SOC analysts<\/a> will move to agents, leaving humans to handle escalation, oversight, and higher-level judgment.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBasically all of cybersecurity is going to need to operate at machine speed,\u201d Reavis says. \u201cSOCs absolutely are going to have a layer of activity where it\u2019s going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Vulnerability discovery becomes abundant, but absorption becomes scarce<\/h2>\n<p class=\"wp-block-paragraph\">It\u2019s undeniable that the most immediate and ongoing changes from AI for cyber defenders are the rapid discovery of massive numbers of cybersecurity vulnerabilities, a shift the industry is already experiencing. But even this transformation comes with downsides because chasing down and fixing every flaw is an arduous task that consumes most defenders\u2019 time.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe problem absolutely is absorption,\u201d CSA\u2019s Reavis says. \u201cHow do I absorb this information? How do I triage it? How do I fix it?\u201d<\/p>\n<p class=\"wp-block-paragraph\">Menlo\u2019s Litty has seen this problem before with static analysis systems that generated more findings than engineering organizations could address. \u201cYou can find hundreds of things, but if you send hundreds of things to engineering and most of them aren\u2019t relevant, engineering will just ignore you,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">AI can already find and test problems in source code, but autonomous validation against complicated production environments remains harder. <a href=\"https:\/\/www.linkedin.com\/in\/calebsima\/\">Caleb Sima<\/a>, chair of the CSA AI Safety Initiative and founding partner of White Rabbit, distinguishes between analyzing source code and autonomously testing complex production environments.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI think vulnerability discovery today in source code is done,\u201d he tells CSO. \u201cBut in terms of real vulnerability discovery in an autonomous way, in a real enterprise production network that produces valid vulnerability and exploitation, we still have a bit of ways to go.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The so-called \u201cvulnerability apocalypse\u201d is less a fundamental cybersecurity change that will make the field unrecognizable and more a question of an increasing disconnect defenders know too well. As Lindner puts it: \u201cWe don\u2019t have a problem finding problems. We have a problem triaging and remediating all the problems that we find.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Machine-speed attacks force machine-speed containment<\/h2>\n<p class=\"wp-block-paragraph\">Another change that could leave traditional cybersecurity practices in the rearview mirror is what happens when autonomous attacks alter the threat environment, necessitating machine-speed response.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s no longer about a single attacker rooting through your network, but it\u2019s a landing of an agent that spawns 200 agents that rapidly move through your enterprise to identify and exploit its vulnerabilities,\u201d Sima says. These agents can scope out the environment, locate valuable assets, and abscond with data before defenders can respond.<\/p>\n<p class=\"wp-block-paragraph\">Cyber defenders should be positioned to respond in equal lightning-fast fashion. \u201cThe cloud, the application, and the endpoints should all be able to actively quarantine, move, and adjust controls at machine speed without breaking production,\u201d Sima says.<\/p>\n<p class=\"wp-block-paragraph\">Litty believes that defenders should assume any component could be breached and design the environment to limit the resulting damage. \u201cThis goes back to fundamentals: least privilege and separation of duties,\u201d he says. \u201cHow do I make sure that I have separated components, defense in depth, so that one vulnerability being exploited doesn\u2019t take my entire company down?\u201d<\/p>\n<h2 class=\"wp-block-heading\">Defender teams become flatter, more agent-heavy<\/h2>\n<p class=\"wp-block-paragraph\">Although it would be tempting to conclude that as SOC analyst jobs disappear, the AI-centric cybersecurity landscape would result in net job losses across the industry, experts say that likely won\u2019t happen.<\/p>\n<p class=\"wp-block-paragraph\">Instead, they anticipate a restructuring of roles and the emergence of smaller, agent-heavy teams. \u201cI see a flattening of organizations between the leaders and the builders,\u201d Reavis says. \u201cThe more senior people are going to have to go and build things.\u201d<\/p>\n<p class=\"wp-block-paragraph\">White Rabbit\u2019s Sima sees a workforce model that is barbell-shaped, consisting of highly experienced professionals on one end and AI-native junior workers on the other end, with pressure on the workers in the middle who are devoted to coordination and project management. \u201cI think you\u2019ll see a barbell: top-tier, senior individual contributors and then juniors and interns,\u201d he says. \u201cThe middle is going to struggle.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Contrast Security\u2019s Lindner agrees that workers with the highest knowledge and experience will fare well in the future.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe things AI isn\u2019t going to be able to replace are experience and judgment,\u201d he says. \u201cMy team is uber-senior today, and I need that. I need them to fully understand and have the experience and the judgment to know how and when AI is going to work for us, and where we need to add different controls where AI isn\u2019t going to work, because it\u2019s not going to work everywhere.\u201d<\/p>\n<p class=\"wp-block-paragraph\">AI will likely never replace skilled cyber professionals, according to Litty. \u201cI\u2019m definitely not seeing the humans going away in those areas for now,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">From tool sprawl to an AI control plane<\/h2>\n<p class=\"wp-block-paragraph\">One beneficial restructuring of the cybersecurity market as AI takes hold fully is that LLMs may be the interface that connects, but does not reduce, today\u2019s existing security tool sprawl.<\/p>\n<p class=\"wp-block-paragraph\">Sima describes controlling firewalls, endpoint tools, and other systems conversationally without having to grapple with each product\u2019s interface. \u201cAI becomes the interface and the glue across all of these fragmented security products,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">The ability to manage sprawl will surely be welcomed in a world with enormous agent proliferation and accelerated churn. \u201cThe technology footprint is exploding, and it\u2019s so vast,\u201d CSA\u2019s Reavis says. \u201cOn the one hand, you see a lot of sprawl, and we\u2019re going to have trillions of agents.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Litty, on the other hand, thinks that existing tools will evolve instead of proliferating. \u201cWhat we\u2019re seeing so far is that it changes the tools,\u201d he says. \u201cIt doesn\u2019t necessarily mean more tools. So far, I\u2019m not seeing an explosion of tools.\u201d<\/p>\n<h2 class=\"wp-block-heading\">What should CISOs do now?<\/h2>\n<p class=\"wp-block-paragraph\">CISOs don\u2019t need to wait for these and other AI-related changes to occur before taking action. Experts recommend that security leaders identify bounded, high-volume tasks such as alert enrichment, initial triage, and vulnerability prioritization, where agents can be tested with restricted authority.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat I would consider telling senior people is: Go build things,\u201d Reavis says. \u201cBuilding things doesn\u2019t mean going to an entry-level position, but go build things that create a new way of doing your job.\u201d<\/p>\n<p class=\"wp-block-paragraph\">CISOs should also direct attention to creating a new governance discipline based on an inventory of every agent and AI-enabled security function.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFirst, [have] a registry of where you are using AI, and then look at the quality of the output,\u201d Menlo\u2019s Litty says. \u201cHow do you do drift detection for what your AI tools are doing? Is this still working? If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?\u201d<\/p>\n<p class=\"wp-block-paragraph\">Finally, autonomous agents should not be considered anonymous agents. Every agent should have a named human or team that is accountable for it, with human review reserved for situations that are consequential or difficult to reproduce.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere has to be a named owner,\u201d Sima says. \u201cWhether that named owner is a team or an individual is all dependent upon what that AI agent is responsible for, what its goal and objective are, and the job that it does.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The task for CISOs, then, is not to automate everything. It is to learn where agents work, restrict what they can do, and establish who answers for them when they fail.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual \u201csolitary ritual\u201d of a developer writing code for hours is giving way to collaboration with an army of chatbots. In its 2025 report on the State of AI-Assisted Software [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9504,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9503","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9503"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9503"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9503\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9504"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}