
Agents are making it cheap for attackers to find unlocked doors. The window to invest in CI, test coverage, and fast safe rollback is now.
You're going to need to be able to safely test and deploy a fix to your software in minutes, not days. It's not going to wait for a scheduled maintenance window.
I'm not normally a fear, uncertainty, and doubt guy. But it's getting much cheaper and easier for an attacker to use agents to compromise software. I'm not even necessarily talking about the level of sophistication that's been in the news with the Hugging Face incident, although it seems inevitable that jailbroken open weight models will eventually get there.
There's just a whole lot of unlocked doors out there. With Stripe keys and personally identifiable information and keys to data workflows that can be held for ransom.
It was almost always worth it to invest in good CI and a testing pyramid for software with traction — making many small changes in quick succession is a more effective way to run a software product in terms of quickly delivering what customers need at high quality.
Most codebases I've worked on over 20 years aren't up to that standard. At best, we had a decent test pyramid in place and acceptable CI/CD. Even fewer codebases I've worked on can quickly smoke test and roll back a bad change. It's pretty common for underlying frameworks to be years out of date and out of support.
We relied on it not being worth it for an attacker to put in effort for an uncertain payoff. Maybe there was a pen test during a compliance audit once a year, and not everything was fixed right away.
That time is about to be over.
I've been saying you need great CI and regression testing to do software engineering at AI speed, and that's as true as ever. It's fun to invest in going faster.
But we in the software industry need to take advantage of this window we have now with powerful models and harnesses at our disposal to bring our security posture up to code, and invest in CI/CD and test coverage ahead of a likely flood of updates we'll need to make quickly and safely. We need to explore how we'll use agents actively in a defensive posture.
It's a real investment and it's hard to make the business case for it, just like it was hard to make the case for it before.
The good news is we have agents, models, and harnesses that are really good at accelerating this work. We have the code, the data, the source material to work from.
Start now, and get faster and safer at delivery. Or you're likely to be scrambling soon.
When regression tests are lacking but upgrades can't wait, let AI do the heavy lifting while you focus on other work
Why effective testing remains crucial even as AI makes writing code nearly free
Agents can run multiple rounds of review and verification before you look. But ship to humans without looking yourself, and something subtle always feels off — because fully specifying a system that feels right to a human is hard.
Get More Like This
Follow along as I build and share what I learn
Found this helpful? Share it with your network!