
Episode #197
197 / TiPS: Building Secure, Trustworthy Products in the Age of AI
Long before ChatGPT burst onto the scene, ITX shared a blog post that outlined The Seven Perspectives of Digital Quality – among them we included app and system security. How secure is your software in terms of data integrity, coding standards, and infrastructure? How well does it stand up to access breaches, threats, and other vulnerabilities? AI is helping product teams do research, design, and build software. But faster development doesn’t reduce the need for security or sound engineering judgment. In this latest Topics in Product Series (TiPS) episode, Jonathan Coupal , ITX Vice President and Director of Security, and Besong Tabenyang , ITX Developer and Data Engineer, bring hands-on security and AI development experience to this critical conversation. Perhaps Besong said it best: “AI hasn’t removed the need for software discipline. Instead, it increased the penalty for overlooking it.” Here are a few tips for how your team can use AI to accelerate product development while building secure, trustworthy products. Proceed with Caution To Protect Sensitive Information The first step in secure AI development is understanding what happens to the information we feed into the models we use, Besong says. For example, product teams should never assume an AI tool protects sensitive business or customer data. Instead, they need to understand its privacy posture, data retention, isolation, and administrative controls. Enterprise-grade tools can provide protections that public AI tools may not. As Besong puts it, “If you put confidential business information in a public AI tool, don’t assume it stays private.” Jonathan adds, “AI is kind of dumb, so you have to be really clear about how you state your requirements as you’re going into the design process. Telling the AI to include security features as part of your build cannot be left as an assumption, it has to be declared.” Shift Security Left To Save Cost, Deliver Faster Maybe you recall Product Momentum episode 131 / Shift Left: Integrating a Security Mindset Early in the SDLC – in which security expert Paul Connaghan urged product builders to include Security as part of the product’s design, well before QA or post-release. In this conversation, Jonathan points to an article referencing IBM research that shows how addressing security during design can significantly reduce both cost and delivery time. AI can also help product teams identify potential threats during discovery and design, he adds. “There’s two types of security problems in a product,” Jonathan continues. “One is engineering problems. We consider those bugs, but security design problems can’t be fixed as bugs because they’re not bugs. Sometimes, it’s a consequence of how someone could misuse a feature.” Apply Human Judgment To Preserve Engineering Discipline AI is really good at generating code, tests, documentation, and architectural recommendations – with remarkable speed. But it’s precisely that speed that makes it easier to skip the human reasoning that supports good engineering decisions. Teams spend less time identifying edge cases, validating assumptions, and evaluating trade-offs. “AI increases code output,” Besong says, “but if our review discipline doesn’t increase with it, we get faster production of unexamined work. AI didn’t remove the need for software discipline. Instead, it increased the penalty for skipping it.” Jonathan places the responsibility firmly on the shoulders of human decisionmakers: “Every time an AI recommends a particular design choice, it’s up to human judgment; and that’s where people with your experience still matter is that bringing that judgment to bear.” [04:13] AI is kind of dumb , so you have to be clear about declaring your security requirements as your work through the design process. Telling the AI to include security features as part of your build can’t be left as an assumption, it has to be declared. (Jonathan Coupal) [08:23] Public AI solutions are built mainly for convenience and broad adoption. But you have to be mindful of what type of data you’re putting in there. (Besong Tabenyang) [11:02] Security information about vulnerabilities is so black and white that the models have been trained on this. The level of expertise that you’re granted by using AI to do security work in the design phase is so good that there’s almost no reason not to use it. It gives you a superpower that you don’t get from a lot of other types of ideation assistance; the quality is so high. (Jonathan Coupal) [13:45] Security isn’t just a governance layer. It materially improves how you build because it enforces clear system boundaries, better failure modes, and more trustworthy products. (Besong Tabenyang) [17:43] It’s pretty easy to declare essential security requirements. It’s even as simple as take a security framework or the compliance rules of the company, feed them into the model as additional inputs as you’re doing the build and say, ‘in addition to taking into account these compliance or security constraints, let’s talk about how to build out this feature.’ So we don’t even have to say it out loud. (Jonathan Coupal) [18:48] AI has increased the volume of code output, but if our review discipline doesn’t increase with it, then all we get is faster production of unexamined work. AI didn’t remove the need for software discipline. It, instead it increased the penalty for skipping it. (Besong Tabenyang) Stay tuned for our next TiPS episode, as Sean and Dan invite ITX experts to explore the security implications that unfold when AI is integrated into the product itself as a feature or agent, granted rights and privileges as an actor in the system. The post 197 / TiPS: Building Secure, Trustworthy Products in the Age of AI appeared first on ITX Corp. .

