The era of the lazy security gatekeeper is dead.
It's a well-kept secret in tech that a lot of security teams don't actually do much. They run a scanner, export a 400-page report of raw alerts, dump it over the fence to the engineering team, and call it "risk management."
AI is completely eliminating this comfortable hiding spot.
My past newsletters focused on how to make engineers and security teams not hate each other. This week, I’m looking at a much more cynical operational reality.
Compliance reporting, user access audits, and dependency bumps are entering a rapid race to the bottom, fully automated out of existence by background LLM jobs that run for pennies.
The real budget is shifting to intense, outcome-driven Security Engineering.
With terminal agents like Claude Code, security practitioners can no longer just find flaws and file Jiras. You are now expected to step directly into the repo, write the code patch, and submit the completed PR yourself.
But this creates a brutal culture shock: most security people suck at product and can't code.
Because AI has made writing syntax trivial, software engineers are spending their cycles on high-level system design and crafting exceptional user experiences. If security keeps building clunky, bureaucratic guardrails that add user friction, developers will simply write a script to bypass you entirely.
This opens up a massive market opportunity for an entirely new software category: Security Development Tooling, i.e., platforms engineered to turn traditional analysts into automated code contributors.
How to survive the shift:
👉 Stop building controls for yourself. Shadow your developers and design for the user experience.
👉 Ditch legacy vanity metrics. Track engineering-level ownership (Change Failure Rates, Lead Time for Secure Changes).
👉 Be highly opinionated. Don't hand teams a checklist; build the gold-standard secure pathway and sell it as an elite internal experience.
If security doesn't upskill into a builder mindset, software engineers will use AI to absorb the security function themselves.
open.substack.com/pub/frankl…