Info-Tech Research Group argues that faster AI-driven development and automated delivery are exposing the limits of traditional security practices built for a slower software cycle.
Info-Tech Research Group is warning that traditional approaches to application security are struggling to keep pace with the accelerating use of AI in software development. As AI-assisted coding and automated delivery increase the speed and volume at which applications are created and changed, the firm argues that security practices need to become more adaptive rather than remain a separate checkpoint in the development process.
The challenge extends beyond AI-generated code itself. Modern applications increasingly depend on APIs, automated pipelines and interconnected services, expanding the areas security teams must monitor while developers face pressure to release software faster. Info-Tech identifies fragmented coordination among development, security and operations teams, limited visibility into security maturity, and poorly integrated tools as recurring obstacles to improving that process.
Its newly released blueprint, Develop a Strategic Plan for Intelligent Application Security, proposes evolving the conventional secure software development lifecycle into what the firm calls an intelligent SSDLC. The approach combines automation and intelligent security tools with human expertise, while treating application security as a set of capabilities that can be assessed and prioritized according to organizational risk and business needs rather than simply adding more technology.
The framework begins by identifying which security capabilities matter most, along with relevant threats, business opportunities, metrics and governance responsibilities. Organizations then assess their current maturity against desired targets before developing initiatives to close gaps, weighing costs and benefits and creating a roadmap for investment. The emphasis on sequencing matters because introducing new security tools without clear integration or governance can create additional complexity rather than resolve existing weaknesses.
The broader issue is whether security programs designed around traditional development cycles can adapt to software production that is becoming increasingly automated. Info-Tech’s recommendation does not remove people from the process; instead, it calls for intelligent tooling to work alongside security, development and operations professionals. As AI makes producing and modifying software faster, organizations may increasingly find that the effectiveness of application security depends less on adding isolated controls and more on ensuring that security can operate at the same pace as development.