The accelerating use of artificial intelligence in software development is rapidly changing the scope, skills, and strategies required to secure code as it is created. AI tools are reshaping DevSecOps, enabling security and development teams to more effectively embed security mechanisms into software products from the earliest stages.
See also: Cybersecurity for everyday users: What you do wrong every day

However, AI’s impact on DevSecOps is not limited to tools and processes; it extends to the very framework, skills, and strategies that support it. AI is reshaping DevSecOps primarily by integrating security earlier in the development cycle and improving how issues are identified and remediated, notes Katie Norton , research manager for DevSecOps and software supply chain security at IDC
According to Norton, this impact on DevSecOps processes focuses on three main axes. The first is the secure writing of code with the help of AI. “One of the most visible changes is the integration of third-party security tools into programming assistants and agents,” it says. “Rather than assuming that code generated by AI is secure from the start, organizations are increasingly embedding security controls directly into the creation process.”
These controls provide policy guidelines, secure code standards, verification mechanisms, identification of sensitive data (secrets), and suggestions for approved dependencies or configurations during code production. As a result, the role of security within the software development lifecycle is changing significantly.
See also: AI threat detection strengthens cyber resilience

The second area involves vulnerability detection using large language models (LLMs). “LLMs are increasingly used to analyze code, configurations, and APIs to detect vulnerabilities, based on contextual logic rather than fixed rules,” Norton says. “This allows them to detect logic errors and unsafe usage patterns that often escape traditional scanning tools, thereby expanding detection coverage, especially in complex or modern application architectures.”
At the same time, the scanning process itself is evolving, becoming more autonomous and in some cases can initiate analyses, confirm findings and be directly integrated into development flows without requiring explicit human intervention.
The third area is automated recommendations and remediation. “AI is increasingly being used to create solutions to vulnerabilities, such as code changes, dependency updates, and configuration adjustments,” Norton notes. “These recommendations are often integrated directly into developer workflows, such as pull requests or integrated development environments (IDEs), reducing remediation time and the level of expertise required to resolve issues.”
See also: Security gaps in Phidias' Agorà – Data of 40,000 users exposed

Overall, the impact of AI on DevSecOps processes is that it drastically reduces the distance between writing code, identifying vulnerabilities, and fixing them. “This makes DevSecOps more continuous, but also more dependent on mechanical intervention,” Norton concludes. “The key challenge now is to verify the code generated by machines, the findings they identify, and the recommended fixes throughout the development lifecycle.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
