Viral Wire

Spacelift Survey Reveals 'AI Infrastructure Governance Gap' as Developers Outpace Security Controls

AI-written code ships with minimal review, causing incidents for 90% of organizations

Deep Dive

Spacelift's survey of 406 IT and platform leaders in North America exposes an 'AI Infrastructure Governance Gap' as developer AI adoption surges ahead of downstream controls. While AI-assisted development lets developers go from idea to working code in hours, that code flows to infrastructure teams who don't get the same speed boost. Two-thirds of organizations say developers adopted AI ahead of their infrastructure teams, creating strain. The report categorizes organizations into four groups: Exposed (AI use with little governance), Fragmented (uneven adoption), Outpacing (aggressive without governance), and Pioneers (already have governance and automation). Most teams ship AI-generated infrastructure code with minimal or no review, and a large majority of leaders express confidence in their AI governance—yet only a small fraction have an actual policy in place, with the widest confidence gap among those with fewest controls.

Consequences are already materializing: nearly all organizations report at least one AI-caused infrastructure incident in the past year, including rework, security misconfigurations, compliance violations, and drift. Exposed organizations are far more likely to have experienced these incidents, while Pioneers—who use validated pipelines—often avoid them. The next concern is agentic AI: most plan to adopt it, with a quarter aiming within six months. Agentic systems remove human review checkpoints, shifting control entirely into the workflow. Early adopters already report incidents from agentic AI. Spacelift recommends platform engineering as the structural fix, making the governed path the easy path. Pioneers already show that shared tooling improves collaboration across engineering, platform, and security teams.

Key Points
  • Two-thirds of organizations adopted AI for developers ahead of infrastructure teams, causing downstream strain.
  • Most teams apply AI-generated infrastructure code with minimal or no review, risking misconfigurations.
  • Nearly all organizations reported at least one AI-caused infrastructure incident, with agentic AI adoption set to remove human checkpoints.

Why It Matters

As agentic AI arrives without human review, platform engineering becomes critical to prevent cascading failures.

📬 Get the top 10 AI stories daily