The integration of artificial intelligence into IT operations and software development is transforming how organizations build, deploy, and manage technology. AI-powered self-service IT enables employees, even those without deep technical expertise, to perform complex tasks such as application development and deployment, increasing efficiency and productivity across businesses. This democratization of technology, facilitated by generative and agentic AI, allows for rapid scaling of IT solutions and empowers non-technical users to contribute directly to business innovation. However, this shift introduces significant security and compliance risks, as employees may inadvertently create vulnerabilities or misconfigure systems without fully understanding the implications of their actions. The rise of low-code and no-code platforms, now enhanced by AI, further accelerates this trend, making it easier for organizations to adopt self-service workflows but also increasing the attack surface. Research from Apiiro highlights a concerning trade-off: while AI coding assistants reduce simple coding errors and speed up development, they also lead to a dramatic increase in complex, high-impact vulnerabilities that are difficult for automated tools to detect. These vulnerabilities often reside in business logic or require chained exploits, posing a substantial risk to the software supply chain. Security leaders are increasingly worried about the risks introduced by third-party software, and the widespread adoption of AI-generated code compounds this concern by introducing new, less understood classes of vulnerabilities. The rapid pace of AI-driven development can outstrip traditional security review processes, making it essential for organizations to implement robust guardrails and human oversight. Automated security tools alone are insufficient to identify and remediate the nuanced flaws introduced by AI-generated code, necessitating a combination of AI and human-led security practices. Companies must balance the benefits of increased velocity and efficiency with the imperative to mitigate security and compliance risks. This requires a strategic approach to risk management, including continuous monitoring, education, and the development of new security frameworks tailored to the unique challenges of AI-powered environments. The evolution of self-service IT and AI-assisted development is reshaping the digital supply chain, demanding heightened vigilance and proactive measures from CISOs and IT leaders. As organizations continue to embrace AI, the need for comprehensive security strategies that address both technical and human factors becomes increasingly urgent. Failure to adapt to these new realities could result in significant business harm, including data breaches and regulatory penalties. Ultimately, the era of AI-powered IT calls for a reimagining of security practices to ensure that innovation does not come at the expense of safety and trust.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.