Amazon Web Services (AWS) this week at the Black Hat USA conference revealed it is working with both Anthropic and OpenAI to integrate their respective coding tools with a service it has developed that makes available artificial intelligence (AI) agents to help application developers write more secure code.
Launched earlier this year, the AWS Continuum service provides access to AI agents that discover, validate and prioritize vulnerabilities and surface remediation recommendations. Currently available in preview, the integrations connect AWS Continuum with coding tools from Anthropic and OpenAI to create a tighter feedback loop for developers as they write code.
At the same time, AWS has also expanded the reach of AWS Security Hub Extended, a unified cloud security and posture management service, to include data shared by Chainguard, a provider of curated open source libraries and container images, and Socket, a provider of a platform that flags malicious software packages, to better detect and block malicious dependencies before they are incorporated into an application. The findings generated by AWS Security Hub are shared via an Open Cybersecurity Schema Framework (OCSF) that is being advanced under the auspices of the Linux Foundation.
Finally, AWS is also working with Miggo Security, a provider of an AI runtime security and application detection and response (ADR) platform, to integrate rule sets directly within the Amazon Web Services (AWS) Web Application Firewall (WAF) console.
Gee Rittenhouse, vice president for agentic security at AWS, said, in general, AWS is working toward securing agentic workflows both as code is developed and after AI applications and agents are deployed. The challenge is that the AI agents that drive these workflows tend to change personas and roles at various stages of those workflows, he added. Applying the right controls at the right time requires a significant amount of visibility and context to ensure, for example, any patch that might be created is trusted enough to safely deploy, noted Rittenhouse.
In the meantime, however, the rate at which AI coding tools and agents are being adopted continues to increase. A global survey of 839 IT decision-makers conducted by the Futurum Group finds 54% now work for organizations that use AI across more than half of their software development lifecycle (SDLC), with 40% reporting AI already generates the majority of production code merged in the last 90 days. Within the next three years, a total of 58% expect AI to build 80% or more of their software, the survey finds.
However, three-quarters of survey respondents (75%) have also encountered a production issue that they have confirmed is attributable to AI, with 42% experiencing multiple incidents. That suggests there is still significant work to be done when it comes to applying governance to agentic AI engineering.
Regardless of how each DevOps team goes about achieving that goal, the one thing that is clear is that, rather than being in the middle of those workflows, software engineers will instead become orchestrators of agentic AI workflows that will soon span every aspect of the software development lifecycle (SDLC).

