Kumar Chivukula leads Opsera‘s innovation in Agentic DevOps and AI-SDLC, empowering secure, AI-driven software delivery.
For decades, human effort constrained software delivery. We gathered requirements, designed the architecture and wrote code, and it took weeks or even months to complete. Then we established processes to test, validate and deploy the software, which were equally slow and arduous.
Today, we have the incredible power of generative AI to generate code, tests and documentation in minutes. Developers have tools like Claude, Cursor and GitHub Copilot to move from idea to prototype at unprecedented speed.
No doubt, this is a massive advancement in software development. But, as with all disruptive technology waves we’ve experienced in the past, we now face a new set of complex challenges.
The challenge I address in this article is this: Software is now faster to create than many enterprises can govern.
The Imbalance Between Speed And Control
There’s a lot of attention on and discussion about AI and software development. Thankfully, there’s also a growing understanding that, although productivity gains are undeniable, software delivery involves more than writing code.
When we look at the bigger picture, it’s clear that value-driven enterprise software development and delivery requires strong architectural oversight, governance and compliance, security and operational readiness. These elements of the software development life cycle (SDLC) are constant and haven’t disappeared with AI development.
In fact, they’ve become more critical.
As a result, many organizations, regardless of their pace of adoption, face growing tensions between speed and control. What I see is this: As software creation continues to accelerate, the processes required to govern and operationalize these new dynamics are struggling to keep pace.
The Enterprise Governance Gap
The governance gap will affect every enterprise differently. Some are prudently experimenting with coding assistants, whereas others have aggressively deployed AI-assisted development across their engineering and development teams. As we’ve seen the rise of “agentic” capabilities, a growing number of enterprises are now exploring how to put autonomous agents to work.
Regardless of the circumstances, software change is currently outpacing the systems designed to govern it.
This growing disconnect impacts organizations in several ways:
• Architectural Inconsistency: Disjointed code generated by a host of different tools is prone to stray from established enterprise standards.
• Shadow AI Adoption: Developers are introducing new AI coding assistants and, more recently, agents, without centralized oversight or approval.
• Mounting Security Review Burdens: Security teams are overwhelmed by the need to adapt to and manage new threats posed by the sheer volume of AI-generated code requiring validation.
• Fragmented Visibility: AI-coding has made tracking changes and maintaining context across multiple tools, environments and workflows increasingly difficult.
Why Existing Tools Fall Short
The software industry has responded quickly to the rise of AI-assisted development. As coding assistants boost developer productivity, DevOps platforms have evolved to automate software delivery, whereas security tools and observability platforms are better at identifying vulnerabilities and delivering operational insights.
Although these solutions solve important problems, most still work best where software development moves more slowly.
As we look at the tools we use, coding co-pilots clearly generate software faster. Still, they lack the governance for how the software aligns with enterprise policies, architectural standards or operational requirements. Traditional DevOps platforms focus on workflow efficiency, yet they can’t provide contextual understanding across the enterprise. And, as I touched on, security and compliance tools are good at identifying issues after they appear, but they rarely connect software changes to broader business intent and governance requirements.
Organizations then find themselves with more tools, automation and change, but no unified framework to govern them.
Governing Change At AI Speed
Today, the primary challenge has shifted from generating code to governing change. To operate safely in this new environment, enterprises must solve several operational issues, including:
• Traceability: There must be a clear understanding of exactly how, when and by whom the software was created.
• Auditability: Every change must be properly logged, documented and easily reviewable for compliance purposes.
• Policy Enforcement: Validate compliance and security requirements continuously throughout the delivery process, not after the fact.
• Cross-System Dependencies: Managing the growing and complex relationships is necessary and includes all applications, infrastructure and security controls.
• Operational Readiness: Production environments must be fully prepared to deploy and support software at this new and accelerated pace.
Today’s Enterprise Requirement
AI-driven software delivery requires an operating model built on governance-aware workflows. It must incorporate context throughout the software life cycle and policy-bounded automation, rather than unrestricted autonomy. It must also keep humans firmly central in all decisions that have operational, security or compliance implications.
I see this approach emerging as the foundation of a modern AI SDLC.
Rethinking The AI SDLC
The first wave of AI transformed how we create software. The next wave will transform how we govern it.
The operational realities we face today demand visibility, context and control, and competitive advantage will come from governed execution, not just accelerated generation. Now is the time to rethink the AI SDLC operating model.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


