Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI can help teams write code faster, but faster code creation does not automatically mean software is tested, secured, deployed, or governed faster. That gap is the AI velocity paradox: upstream coding accelerates while the work needed to release code safely may not keep pace. “Decades behind” is rhetorical, not a measured finding; the available evidence does not establish a literal multi-decade security lag.

What the AI velocity paradox means

Harness introduced the phrase “AI Velocity Paradox” in its 2025 State of AI in Software Engineering report. It describes a delivery mismatch: developers may produce code more quickly with AI tools, while testing, security review, deployment controls, and governance remain bottlenecks. The issue is not simply whether AI-generated code is good or bad. It is whether the whole software lifecycle can verify and safely release the larger or faster flow of changes.

In a September 30, 2025 announcement, Harness SVP and GM Trevor Stuart said, “The AI Velocity Paradox is real. Teams are writing code faster, but shipping it slower and with greater risk.” This is Harness’s framing and an executive statement, not an independent expert finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the surveys say—and what they do not

Harness commissioned Coleman Parkes to survey 900 engineers, platform leaders, and technical managers in the United States, United Kingdom, France, and Germany in August 2025. Respondents reported both faster development and problems associated with AI-generated code:

Reported finding How to interpret it
63% of organizations said they shipped code faster after adopting AI. A respondent-reported change, not an independently measured delivery-time reduction.
45% of deployments involving AI-generated code reportedly led to problems. A survey finding; it is not a universal probability that any given AI-assisted deployment will fail.
72% of organizations reported at least one production incident caused by AI-generated code. A report of whether an organization had experienced an incident, not an incident rate per release or proof that AI code is inherently less secure.

Harness’s 2026 State of DevOps Modernization survey extends the argument that code creation has accelerated while downstream testing, security, and deployment have not necessarily kept pace. Coleman Parkes conducted the survey in February 2026 among 700 engineers and technical managers in the United States, United Kingdom, France, Germany, and India. It is a current industry survey, not proof that every organization has the same gap.

These results support a concern about delivery capacity and assurance. They do not establish that AI-generated code is always less secure, quantify a universal security failure rate, or prove the title’s “decades behind” claim. Those stronger conclusions would require evidence beyond the reported survey findings.

Why security and delivery can fall behind

Code generation is only one stage in getting a change into production. Every change still needs appropriate validation, security review, deployment verification, and a traceable decision to release. If AI increases the volume or pace of proposed changes but teams do not increase the capacity or automation of those later steps, queues can grow and assurance can become a constraint.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assess the mismatch across the full path from code to production rather than treating “AI adoption” as a single measure:

  • Code creation: How broadly is AI used, and how much code or how many changes does it help produce?
  • Testing and validation: Are changes checked with suitable automated tests and other verification before release?
  • Security review: Are security checks integrated into development, and are vulnerabilities triaged and remediated?
  • Deployment controls: Can teams verify releases, limit or monitor rollouts, and roll back a change when needed?
  • Governance and evidence: Can the organization show what was reviewed, which controls ran, and why a change was approved?

This framework separates process capability from claims about any particular vendor tool. More automation can help, but the relevant question is whether controls cover the risks and stages in the organization’s actual delivery process.

How to secure AI-generated code

Use the same secure-development discipline required for other software, while accounting for the AI models and systems involved. NIST’s finalized SP 800-218A supplements the Secure Software Development Framework (SSDF) version 1.1 with AI-specific practices, tasks, recommendations, and considerations across the software lifecycle. NIST says it is intended for AI model producers, producers of AI systems that use models, and acquirers of those systems, and that it should be used together with SP 800-218.

  1. Set a lifecycle baseline. Use NIST SP 800-218A alongside SSDF 1.1 to identify relevant secure-development practices for the AI models or AI-enabled systems your organization produces or acquires.
  2. Keep verification in the release path. Require appropriate tests and security checks for changes before they can be deployed; AI assistance is not a substitute for validation.
  3. Make security findings actionable. Define how findings are reviewed, prioritized, and resolved, rather than treating a completed scan or review as proof that a change is safe.
  4. Control and verify releases. Establish deployment checks, rollout oversight, and a workable rollback path so that faster code production does not remove release safeguards.
  5. Retain governance evidence. Record the checks, approvals, and release decisions needed to demonstrate that the process was followed.

NIST’s publications listing identifies SP 800-218 Rev. 1 (SSDF 1.2) as a draft released for comment on December 17, 2025. The listing continues to identify SP 800-218A as final. Because publication status can change, confirm the current status on NIST’s publications page before treating the 1.2 draft as a finalized framework.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to tell whether your organization has a velocity gap

Compare AI adoption in code creation with the downstream assurance capabilities that turn changes into production software. A useful assessment looks for imbalances: for example, growing use of AI without corresponding test coverage, unresolved security findings, dependable release controls, or governance evidence. The objective is not to slow every team down; it is to ensure that verification and control capacity grow with the work entering the delivery pipeline.

Harness’s 2025 report uses a quadrant model comparing upstream coding adoption with downstream automation. NIST’s SSDF guidance provides a lifecycle-oriented secure-development frame. Together, these perspectives help distinguish high AI usage from the broader ability to deliver changes safely; neither by itself proves that a particular organization is secure or insecure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.