The Expanding Attack Surface of Agentic Development
Agentic development is transforming software engineering by enabling AI agents to rapidly design, write, test, and deploy applications. While this dramatically accelerates innovation, it also creates a significant security challenge: an exponentially growing attack surface. As organizations use AI to generate hundreds or even thousands of applications, maintaining consistent security becomes increasingly difficult. Applications may be built using different frameworks, third-party APIs, open-source libraries, and cloud services, each introducing new dependencies and potential vulnerabilities. Without strong governance, security reviews can quickly become a bottleneck—or be skipped entirely. The speed of agentic development also means that vulnerabilities can be introduced and deployed faster than traditional security teams can detect them. Misconfigured permissions, exposed secrets, insecure APIs, and outdated components can all become entry points for attackers. When multiplied across ...