Building Trust in the AI-Powered SDLC
AI is accelerating software development faster than most security programs were designed to handle. Recent IDC research indicates that developers are using AI coding assistants at scale, increasing throughput while also introducing new risks tied to code quality, provenance, oversight and software supply chain security. As AI-generated code becomes a larger share of production output, organizations need security practices that can operate at the same speed as development.
Securing the SDLC at the speed of AI
Traditional application security tools were designed for a world where humans wrote and reviewed code at a manageable pace. With AI-powered code generation, the volume and velocity of code, along with the associated vulnerabilities, have outpaced the capacity of conventional security teams and processes.
Key challenges include:
- Scaling vulnerability triage: AI can identify and triage vulnerabilities at scale and speed, but human expertise remains essential for complex cases and final validation.
- Managing dependencies: As open source and third-party components proliferate, vulnerabilities can spread quickly across the software supply chain.
- Continuous change: The concept of fixed patch windows is becoming obsolete as IT operations shift toward continuous integration and deployment, requiring security to adapt to rapid ongoing changes.
Evolving a secure SDLC for the AI era
Organizations are responding to these challenges by rethinking their approach to application security:
- Emphasizing security hygiene: Consistent processes and human oversight remain critical, even as AI tools automate many tasks. For example, in a recent open source project, AI identified five vulnerabilities, but only one was confirmed after human review.
- Fostering collaboration: Standardized languages and interfaces are needed to enable seamless communication between security tools and teams, supporting efficient triage and remediation.
- Developing new frameworks: The industry is actively working to define frameworks and best practices for securing AI-powered engineering, though these efforts are still in early stages. Harnesses are emerging to address some of these objectives.
The emergence of harnesses
In the context of the SDLC, the term harness refers to a custom framework, integration layer, or set of tools and skills used to control, benchmark or secure AI models and their outputs. In detail:
- A harness can be a specialized piece of work (such as a custom configuration or script) that enables teams to leverage AI models for specific tasks, like vulnerability triage.
- A harness may represent a shared skill set or knowledge base that helps teams apply AI securely and effectively.
- Increasingly, harness is used to describe emerging products or frameworks that integrate, customize and manage AI-powered development and security tools within the SDLC.
The term is evolving, and its meaning depends on context, but generally it denotes the mechanisms, whether technical or procedural, that allow organizations to safely and efficiently use AI in software engineering.
Looking ahead: Building a resilient AI-powered SDLC
To secure the AI-powered SDLC, organizations should:
- Establish a program of governance and oversight: Such a program should dictate how AI coding tools are used, providing visibility into assistants, agents, models, extensions, MCP-connected services and rule sets and supporting policy enforcement around approved tools, data access, workflow boundaries and acceptable use.
- Implement point-of-generation security controls: Apply security guidance at the moment code is created through mechanisms such as rules files, prompt controls, hooks, skills and MCP-connected security services. Such controls can guide assistants and agents toward safer outputs by embedding secure coding rules, organizational policies and architectural context before insecure code is produced.
- Close the loop with validation and traceability: The SLDC process should assess, document and govern code after it has been generated. It should include scanning, reviewing workflows, policy checks, provenance, attribution, testing and release controls that help organizations determine whether AI-authored changes are acceptable and how they were produced.
These practices combine in a virtuous cycle of manageability, auditability and efficiency that optimizes the use of AI in a controlled and risk-reducing manner.
The adoption of AI in software development is inevitable and transformative. By proactively evolving security practices, organizations can channel the benefits of AI while minimizing new risks.
The world of software security is changing fast. Those who adapt will thrive.