Could Agentic AI In DevOps Create New Security Flaws?
devops.com, Friday, July 11th, 2025
Agentic artificial intelligence, software that can gather context, reason about goals and then act without minute-by-minute human supervision, is no longer science fiction inside DevOps pipelines.
Tools like GitHub Copilot, once mere autocomplete sidekicks, now ship with 'agent' modes that can open pull requests, roll back failed deployments and chat with incident dashboards while the rest of us sleep.
Microsoft says enterprise usage of such agents has more than doubled since 2024. Early adopters are celebrating breathtaking cycle-time reductions, but each new autonomous capability also moves critical decision-making out of human sightlines, subtly reshaping the security surface.
This article explores both sides of the ledger: First, I'll take a look at agentic AI's abilities to enhance software delivery; second, how these capabilities could introduce fresh security flaws; and finally, the guardrails that let teams harness agentic AI's autonomy without worry.