
The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was sound — for an enterprise where humans wrote code and humans ran applications.
That enterprise no longer exists.
AI agents are moving from research projects to production workloads at a pace most security organizations weren’t designed to match. They operate autonomously, consume tokens and APIs directly, make decisions without human checkpoints, and leave behind an audit trail only if someone thought to require one.
The s...