AI adoption in software development is near-universal, with 84% of developers now using the technology, according to Stack Overflow's 2025 Developer Survey. That speed is putting new pressure on security teams, who must now vet code produced faster than ever while facing a rising tide of AI-generated vulnerabilities.
GitLab CISO Chaim Mazal said security teams need to shift from acting as manual auditors to becoming first-level contributors in the development process. The approach, which he calls "engineering-first," borrows core practices from software development - automated testing, CI/CD pipelines, and direct code contribution - and applies them to security work.
Security teams as contributors, not gatekeepers
"As our engineering teams move fast, having the security team have the ability to contribute code, make iterative adjustments, and be part and parcel with the development process is key to our success," Mazal said.
"Being able to move fast, iterate fast, and not just be consultative in nature, and being able to really roll up our sleeves and work alongside the rest of the teams to build that secure path and the secure guardrails is something I think most modern security teams don't have the luxury of foregoing."
This marks a departure from traditional security models, where teams review finished code and enforce policy from a distance. In an engineering-first model, security professionals build parallel tools and guardrails that support development from the start, rather than inspecting the output after the fact.
The blind spots of AI-generated code
The urgency comes from real gaps. GitLab research from June found that eight in ten organizations are adopting AI tools faster than they can develop policies to govern them. A separate study from Tricentis showed that roughly 60% of organizations have shipped untested code.
Mazal said enterprises are still working around the "same practices and principles that we've historically followed" - testing, reviews, and security checks. But the pace of agentic AI creates risk that blind spots emerge somewhere in the pipeline.
For professionals working in IT and development, this means the security role is changing in real time. Teams that treat security as a separate checkpoint will struggle to keep up with AI-accelerated delivery cycles. Those that embed security directly into development workflows - with automated checks and shared tooling - will have a clearer path. AI for IT & Development training can help teams build these integrated practices.
Humans in the loop, but fewer of them
Mazal said human oversight remains essential, but the goal is to reduce it over time. "I think most organizations who make commercial-level software want to get to a place where there are only humans in the loop in places that it's absolutely necessary, based on the risk to the organization," he said. "They'd like to be able to have the overwhelming majority of their code auto-generated and auto-reviewed."
Fully automated pipelines are still evolving. Some enterprises are exploring automated testing environments that require minimal human input, but Mazal acknowledged the industry is still defining best practices. "Collectively we're still trying to figure out as an industry what those best practices are, but we're definitely making very big leaps and bounds in very short periods of time."
GitLab is applying this approach internally through a "software factory" model, where security guardrails are baked in from the initial design phase. Agents operate within strict boundaries, and governance controls are applied uniformly based on data sensitivity and requirements. Those controls will shift as needs change, with teams making "continuous adjustments along the way," Mazal said.
Why this matters for IT and development professionals
For developers, the takeaway is direct: security is becoming a coding discipline, not a review step. Expect to work alongside security engineers who contribute to the same repositories and pipelines you do. For security professionals, the skills that matter are shifting toward automation, CI/CD fluency, and the ability to write code that enforces policy. AI for Software Developers courses cover the practical side of this transition - how to build and secure AI-assisted workflows rather than just review their output.
The teams that adapt fastest will treat security as a feature of the development process, not a bottleneck after it. The ones that don't will keep shipping code at AI speed while trying to inspect it at human speed.
Your membership also unlocks: