Guest Blog Post by Eric Newcomer, Principal Analyst, Intellyx
Conventional wisdom says that adopting gen AI requires you to re-think and re-examine how your organization functions.
This is true for any new technology, especially for one as revolutionary as gen AI. But first you need a clear understanding of what the new technology is good for, what it does, and how it works.
When AI agents do a lot of the manual work people used to do, organizational structures change to reflect that. Teams can be smaller, and individual team members can take on multiple roles.
Conway’s Law says that an organization’s IT systems mimic its organizational communication structure. The question then is what impact the human-to-agent communication has on an organization’s structure, and therefore on its IT systems.
Change Can be Hard
Agentic AI’s impact on DevSecOps primarily involves communications among the dev, security, and ops organizations.
Dev is perhaps the most impacted by gen AI, because of the widespread adoption of AI coding tools for productivity improvement.
However, cybersecurity is significantly impacted as well. There is so much new code that it’s hard for them to keep up.
For ops, the impact is probably the least of the three combined functions, but nonetheless the increased rate of change presents opportunities for re-examining processes and roles.
In many ways, adopting agentic AI parallels the adoption of CI/CD pipelines. CI/CD automation also impacts the roles of dev, security, and ops.
The most important consideration when introducing change is to evaluate how the proposed change impacts business outcomes. In the case of CI/CD, the impact was to shorten the release cycle and improve the rate of application change.
Process and Organizational Transformation
AI agents take things a step further, allowing DevSecOps teams to move to a “do it for me” from a “do it yourself” mode of operation.
Teams can give AI agents tasks that complete manual work that the team members would otherwise have to do for themselves, freeing their time for more strategic work.
AI rapidly shifts the primary SDLC bottleneck from writing code to architecture, verification, security, and spec writing. AI coding agents boost individual output, alter career pathways, and put pressure on DevSecOps to keep up.
At the same time, AI-based security issues also increase rapidly. Every new release of a foundation model introduces a new set of threats and vulnerabilities, and cyber criminals are quick to exploit these new capabilities.
Agentic AI promises to transform and modernize the technology underpinnings of DevSecOps to keep up with the increasing rate of threats and vulnerabilities. But keeping up with this constant rate of change also impacts organizational structures and processes, which must be rethought to achieve optimum defensive capability.
One new role could be called the Agent Captain, responsible for driving the “agent swarm” toward the shore safely. The Captain is responsible for determining how agents interact, and selecting the right AI agents to use.
Dev / Cyber Tension
If anything, generative AI coding tools increase longstanding tensions between dev and cyber teams. Cyber teams traditionally feel they never have enough time to adequately review and approve security for applications before they go into production, and dev teams often feel that security policies impose too much work and slow down projects too much.
Devs often say that cybersecurity gives them more work than they can possibly do, and the cybersecurity team is often frustrated because the only way they can get devs to do the work is to escalate to the CIO or CISO.
But it’s also highly challenging because organizational leaders often juggle multiple competing priorities; balancing both the business need and the sheer number of vulnerabilities that organizations face today. It’s this perfect storm that drives organizations toward the DevSecOps agentic AI transformation.
Agentic AI in Cybersecurity
The goal of agentic AI automation in cybersecurity is to reduce the fatigue factor for analysts, helping them focus on significant issues. Delegating manual work to AI agents means more time for analysis, thought, and decision making.
Agentic AI tooling often fails to transition from prototype to production, which ultimately becomes a significant cost rather than a return on investment. Organizations often struggle to develop and deploy AI agents on their own and achieve targeted business outcomes.
But technology is just part of the solution. Dev, ops, and cybersecurity teams also need to re-evaluate their communication patterns and working processes.
And all teams have to ensure the business is aware of the benefits they are delivering by adopting the new technology and following the new processes. This is where AI agents come in.
Appdome’s Mobile Agentic AI
When adopting agentic AI for mobile DevSecOps, consider what you can buy instead of build.
Appdome’s AI agents support the mobile CI/CD pipeline with anti-fraud, anti-scam, deepfake detection, ATO protection, malware and spyware detection, geo-fraud prevention, know your client (KYC) checks, and more inside Android & iOS apps.
Appdome’s mobile app AI agents include:
- Build Agent: Selects, configures, and automatically builds more than four hundred security, anti-fraud, anti-malware, and compliance protections directly into Android or iOS apps.
- AI Support Agent: Identifies on-device mobile threats and offers precise, real-time removal steps.
- SOC Agent: Autonomously analyzes an organization’s mobile attack surface and delivers clear, actionable insights.
- DPM Agent (Defense Posture Management): Analyzes and evaluates an organization’s overall mobile defense posture using Appdome’s unified data, build history, and threat signals.
- DevOps Agent: Applies agentic AI to the mobile app build and deployment process, using defense and build data to guide DevOps teams on configuration, implementation, and release readiness.
- Research Agent: Leverages Appdome’s global threat telemetry, consisting of trillions of live events, to investigate, correlate, and reason about emerging mobile attacks.
The Intellyx Take
Every organization is different. There’s no “one-size-fits-all” agentic AI transformation for your people, process and technology.
Every organization has to re-think, respond, and adapt to realize the new technology’s benefits for them.
Resistance to change due to agentic AI adoption often stems from fears about the impact of AI on jobs.
But in my experience, there’s no end to the requirements for new projects, new features, new capabilities, and applications that increase business, cut costs, and expand revenue. Especially in the mobile application area.
DevSecOps staff still need to be reskilled and assigned roles that require human judgment for decision making. But if mobile app protection is what you need, it makes sense to evaluate the set of AI agents Appdome provides, and redesign your organizational processes accordingly.
Copyright © Intellyx BV. Appdome is an Intellyx customer. Intellyx retains final editorial control of this article.
No AI was used to write this article.



