started · updated
AI reshapes software development, security and monetisation models
Open‑source software remains the backbone of enterprise code, but AI‑driven zero‑day vulnerabilities and a surge in AI‑generated code are straining traditional security practices. Experts from Red Hat stress the need for coordinated patching of common libraries such as Spring, Log4j and OpenSSL, while highlighting that AI‑powered scanning can find flaws within hours, yet fewer than one percent are fixed promptly.
AI agents and generative coding tools are also creating new attack surfaces. Palo Alto Networks warns that autonomous AI assistants can execute unwanted actions, delete data and expand privileged access if organisations lack visibility and automated governance. Similar concerns are echoed in discussions on AI‑native software‑supply‑chain risk, where only a small fraction of firms apply consistent security controls to AI‑generated code.
To address these challenges, startups are emerging with specialised infrastructure. Velocity raised $27 million to build a platform that embeds native advertising into AI applications, helping developers offset high inference costs while preserving user experience. JetBrains launched an AI‑for‑Teams suite to centralise governance, cost tracking and safety across fragmented coding assistants. Meanwhile, AI‑powered observability solutions are being promoted as essential for scaling agentic AI and achieving reliable autonomous IT operations.
Across the industry, leaders stress that responsible AI governance must keep pace with rapid adoption, integrating real‑time vulnerability data, policy‑driven automation and transparent observability to protect both open‑source ecosystems and emerging AI‑driven products.