Home
/
Blog
/
AI coding agents ship code faster. Can security keep up?

AI coding agents ship code faster. Can security keep up?

Photo of Andrew Zigler
|
Blog_AI_coding_agents_ship_code_faster_but_multiply_security_vulnerabilities_2400x1256_e01f7f959f

The software development lifecycle has quietly been renamed. Coding agents now write, review, test and deploy a growing share of production code, while the security, review and ownership practices built for human developers struggle to keep pace.

On a recent episode of Dev Interrupted, Thomas Dohmke and Idan Plotnik looked at that shift from two sides. Dohmke, CEO of Entire and former CEO of GitHub, comes from the forge where code lives. Plotnik, CEO and co-founder of Apiiro, comes from the security layer that has to keep it safe. Their argument is that building faster and building safer, long treated as competing goals, have become the same problem in an agent-driven world. What follows covers why agents are multiplying vulnerabilities, how shift-left security has to move inside the agent loop, why context drives both safety and cost, and what it takes to get agent-authored pull requests merged.

The agentic development lifecycle replaces the SDLC

"There is no such thing as SDLC anymore," Plotnik says. "It's ADLC, agentic development lifecycle. Everything is agentic across, I think, any company in the world."

The path here ran through clear phases, as Dohmke traces it. Autocompletion landed in 2021 and chat followed in 2023. Then 2025 became the year of agents, with Claude Code, Codex, Cursor and GitHub Copilot's coding agent moving from suggesting code to executing work. By 2026, agents write, review, test and deploy the code. The default unit of work has moved from a human-authored commit to an agent-generated pull request.

The industry is still early in this transition. Teams let agents run for hours or even days, then arrive on Monday trying to work out what actually got produced and how many tokens were wasted along the way. Nobody has yet figured out how to run, evaluate and trust that output at scale. Whether agents write the code is settled. Whether anyone reviews it, and whether it can ship with confidence, is not.

More code, more vulnerabilities, and the same size AppSec team

The throughput gain is real, and so is its shadow. Apiiro's research found that AI coding assistants help developers ship roughly four times faster while introducing roughly ten times the vulnerabilities. That widens the gap between what gets written and what anyone can review.

Two forces are converging at once. Nearly every company has adopted coding agents, and developers increasingly no longer write, review, test or deploy the code themselves. At the same time, Fortune 500 companies are scanning their codebases with new frontier models like Anthropic's Claude Mythos Preview and surfacing thousands of previously unknown vulnerabilities overnight, a moment Plotnik calls the Mythos storm. For a CISO or CIO, that means suddenly owning risks they never knew existed. The AppSec team has not grown, but the backlog has multiplied by ten.

J.P. Morgan's July 2026 Eye on the Market report, Patchmageddon, put data behind the fear. It showed that zero-day discovery now outpaces the industry's ability to fix, especially when open source maintainers cannot keep up. In Plotnik's view no slowdown is coming, because the train has already left the station. Risk management has to happen inside the agent loop rather than after it. That means training coding agents to write secure and compliant code on every prompt instead of catching the damage downstream.

Shift-left security moves inside the agent loop

Shift-left security was born in the GitHub era. Its logic held that vulnerabilities should be caught before they reach production, and well before a company has to hold a press conference explaining how it lost millions of customer records. Agents have pushed that principle to its limit. "With AI agents, we've basically went all the way to the left. If you wanna go further left, then you have to sit in my brain," in Dohmke's words.

That is the new frontier. There is no longer a step where an idea gets converted into something abstract like code or a diagram. A developer types, and code appears. So the guardrails have to move into the agent's prompt and reasoning process itself. They operate at the pre-prompt, pre-commit and post-commit stages so the agent corrects itself before anything reaches a pull request.

The old approach failed on exactly this point. Five years ago, security tried to stop developers at the pull request and ended up blocking every pull request, because there was no context to separate a real business risk from noise. That blanket enforcement bred friction between security and development teams. Agentic AppSec has to be precise instead, with security tooling that plugs directly into the agent's workflow rather than bolting on afterward. The payoff is measurable. According to Plotnik, enriching the agent's prompt with organization-specific context has prevented 81% of vulnerabilities and compliance violations in Fortune 500 deployments. Agents handle the fixes between themselves before the code ever lands in the repository.

Context engineering makes coding agents safer and cheaper

All of that precision depends on what goes into the agent. Too generic, and the context is useless. Too thin, and there is no way to stop a risky change without creating friction. "The secret sauce is the context. What do you bring into these hooks?" Plotnik asks. Apiiro's answer is a software graph and risk intelligence layer that understands the architecture behind every change. It injects organization-specific policy directly into the agent's prompt, hooks and review cycle.

Storing the right artifacts matters just as much as the code itself. For Dohmke, the real work product is now the session log, the record of the interaction between a developer and their agents, and it should not sit in a cache directory on one laptop. It belongs in the repository alongside the code. The code is the what and the how, and the session log is the why. It captures the model's reasoning, the tool calls and the intent behind a change. That makes long-term memory, agent-to-agent handoffs and resumable work possible. An agent can pick up a session where another left off, learn from past prompts and avoid repeating the same mistakes.

Good context engineering also cuts cost sharply. When agents reason over a large monorepo again and again, spend spirals. On one such codebase, a complex auto-fix cost $6.10 per query when the agent reasoned over the raw code. The same task cost $0.20 using Apiiro's data fabric. The intelligence that prevents vulnerabilities also turns expensive, repeated reasoning into a one-time enrichment step. Enterprises are already applying it even earlier, running threat models against a Jira ticket or GitHub issue before the agent starts work, so the countermeasures are part of the task from the beginning.

Agent-authored pull requests stall in review

Faster shipping only helps if the work actually merges, and often it does not. LinearB's 2026 benchmarks drew on 2.7 million pull requests across 253 engineering organizations, split into human-only, AI-assisted and fully agentic cohorts. The data shows agentic PRs piling up at the review and merge stage. At fair-tier organizations, only 37% of agent-opened pull requests merge within 30 days, against 81% of human-only ones. Dohmke recognizes the pattern. Security findings once went unresolved in similar numbers because nobody wanted to work through long lists, and agent-generated pull requests are now headed for the same fate.

The mechanics of human collaboration explain the stall. Reviews used to move on social capital, whether a ping in a company chat, a phone call across time zones, or one person spending their standing with another to get a pull request looked at. Agent-authored pull requests carry no such currency. Without a clear owner, nothing drives a human to act on them.

Ownership shifts from code authors to business outcomes

Two changes break the logjam. The first is mechanical. A certainty score plus automated tests lets low- and medium-impact fixes merge automatically under a defined rule. That cuts the backlog dramatically instead of leaving everything to wait in a queue.

The second is a redefinition of ownership. Agents have inflated the number of components, APIs and dependencies by more than 1,000%, and code with no owner produces pull requests with no code owner. The fix is to attach a business owner rather than a code author. When a feature closes a $10 million deal or a pull request holds up a critical CVE fix, someone merges it, regardless of whether a human or an agent wrote it. Ownership is moving from who wrote the code to who owns the business outcome.

Faster and safer turn out to be the same problem

A business owner who answers for an outcome cares about both halves of it: whether the feature shipped, and whether it shipped safely. That is the quiet resolution to the tension this conversation started with. The constraints on engineering leaders have not changed, only their shape. They still run businesses with priorities, budgets and margins. Separating main quests from side quests matters as much for a thousand agents as it did for a hundred interns.

What changes is where the work of keeping code safe happens. Context shapes the prompt, session logs preserve the reasoning, and guardrails let the agent correct itself before a pull request exists. With all of that in place, security stops acting as the brake on speed. Building faster and building safer become one job, done inside the loop rather than after it.

Hear more from Thomas Dohmke and Idan Plotnik on the agentic development lifecycle, shift-left security and pull request review bottlenecks in the full episode of the Dev Interrupted podcast.

Headshot3_d7231cbda7

Andrew Zigler

Andrew Zigler is a GTM Engineer at LinearB and the host of Dev Interrupted, a twice-weekly podcast and newsletter where 40k+ builders decode the transition to AI-native development and agentic orchestration. A classicist by training with a degree from The University of Texas at Austin, Andrew spent his early career teaching in Japan before channeling his interdisciplinary instincts into the tech world. His polymath background informs everything he builds, from automated workflows to the stories he tells about the seismic shifts reshaping software creation.

Connect with

Your next read