惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
雷峰网
雷峰网
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
腾讯CDC
T
Tailwind CSS Blog
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
The Cloudflare Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
B
Blog
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
博客园 - 司徒正美
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
A Strategic Game Plan For The Governance Of AI-Enabled Co...
Pieter Danhi · 2026-05-19 · via Forbes - Innovation

Pieter Danhieux is the Co-Founder and Chairman/CEO of Secure Code Warrior.

getty

​Artificial intelligence (AI)-driven coding is no longer experimental; it’s embedded in the majority of daily workflows. In fact, more than seven out of 10 developers who have tried using AI now use AI coding tools every day.​

Yet, most organizations lack visibility into how these tools affect production code, creating governance blind spots as demand spikes and deadlines accelerate. According to the same survey linked above, security tops the list of problems on the minds of developer team members, with 57% saying they are either “extremely” or “very” concerned about the exposure of sensitive company or customer data. Similarly, 47% express concern about the introduction of new/subtle vulnerabilities, and 44% cite the introduction of severe vulnerabilities as a top worry.​

The issues here often arise from a number of questions that are left unanswered: Are our teams able to accurately spot and identify AI-developed code? If so, do they have the skills to effectively remediate AI-rooted problems? Is our organization implementing AI governance programs and guardrails? Are these initiatives actually making a positive impact? How are we measuring any of it?​

To address these critical inquiries, organizations must prioritize upskilling team members and establishing AI governance to confidently manage AI adoption. Without this, I've seen the thing happen time and time again: An absence of traceability, guardrails and tools governance—along with the failure to verify the secure-coding proficiency of developers—will lead to high-risk situations with an abundance of vulnerabilities in codebases, resulting in staggering technical debt.​

To address this, start by auditing your entire AI development life cycle (ADLC). In doing this, be sure to prioritize accurate attribution, policy compliance review and the connection of environment signals to governance actions. Such an audit can give greater insights into your team’s AI usage and progress metrics.​

To ensure success, organizational leadership should include the following capabilities and practices in their auditing/continuous improvement programs:​

Observability: Security leaders must prioritize deep observability in order to assess confidence in the ADLC. They need to capture signals from AI coding tools, large language models (LLMs) and model context protocol servers (MCPs). The latter is essential in helping prevent AI agents from accessing sensitive internal tools or databases through unvetted, risky connections.​

Training: In upskilling the threat-mitigation capabilities of the humans handling AI, training efforts should correlate developers’ skill sets and their AI usage with vulnerability benchmarks to identify risk levels and enforce policies before code reaches production. With this, developers can automatically receive the most relevant training and build coding proficiency more quickly.​

Governance: Leaders must align developer teams' security standards with the organization's, ensuring that only approved AI tooling and practices are in place. Readily available governance solutions can help with this by making AI’s influence on software development visible, attributable and enforceable. Enterprises can trace which AI models affect specific commits, correlate that to vulnerability exposure and take corrective action before flawed code reaches production. Ultimately, this allows them to scale AI coding tools with measurable control over software risks.​

I know this approach works; I've had clients install proprietary AI governance software that, within a matter of days, flagged open-source models being used that were not accounted for. This significantly expanded that company’s risk profile before discovery. I believe organizations that remain blind and ignore these best practices will find themselves on a dangerous path.​

It’s clear that the era of AI-assisted coding has arrived, ushering in coding velocity gains that deliver a tremendous boost in developer productivity. But speed without guardrails inevitably creates liabilities, resulting in vulnerabilities and technical debt.​

By implementing policy controls, building unprecedented observability and governance over AI coding tools, LLMs and MCPs influencing codebases, and investing in adaptive learning based upon capabilities assessments and vulnerability benchmarks, organizations can ensure that an AI-enabled development “fast lane” will not come at the expense of insecure code.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?