Opens in a new tab
vmblog logo 2024 wht (updated)

Rethinking the Future of Human-AI Collaboration in DevSecOps

Share: 

By Bryan Ross, GitLab

Every discussion about AI in software delivery comes back to the same assumption that equipping engineers with smarter AI tools means one engineer will complete the work of an entire team. It’s an appealing idea, but a flawed one. 

AI has expanded what a single developer can accomplish, but it has also expanded what that developer is expected to know. An engineer relying on AI to produce infrastructure code still needs to assess its security implications. Even with AI-assisted security scanning, one still needs to understand the underlying business logic. The more AI takes on, the wider the judgment required to validate what it produces. 

The organizations that see the greatest returns on AI investment will be those that deliberately invest in collaborative practices, cross-functional reviews, structured knowledge sharing, and intentional mentoring, so that individual engineers build the multidomain fluency AI requires but cannot supply. 

Great software doesn’t come from better tooling alone. It comes from better teams. 

Collaborative foundations as bedrock

The core goal of DevSecOps is to establish a collaborative engineering culture that spans the entire software delivery lifecycle, from business strategy to technical implementation. This culture emphasizes reusability and best practices that directly improve developer productivity and delivery efficiency. Organizations accomplish this through a dual-gate system:

  • Human consensus-based code reviews ensure knowledge transfer and maintain quality standards across disciplines.
  • Automated quality and security gates catch issues before they reach production.

This approach balances speed with control. It minimizes risk in software change management while ensuring that acceleration doesn’t come at the expense of stability or security.

Most organizations stop here. They implement the processes, install the tooling, and measure the velocity improvements. Yet, they miss the deeper transformation happening beneath the surface.

Knowledge transfer mechanisms

The collaborative model operates fundamentally as a system for learning and knowledge acquisition at scale. Research in educational psychology, particularly Bloom’s Taxonomy of Learning, suggests that the highest form of understanding is achieved through teaching concepts to others.

This is where the dual-gate system reveals its deeper value. Code reviews become structured knowledge transfer sessions. Each person operates as the knowledge expert in their domain while learning from adjacent domains:

  • The security engineer reviewing code teaches secure development practices while learning about business requirements
  • The architect understands product priorities while sharing knowledge about technical constraints
  • The junior developer learns patterns from seniors while bringing fresh perspectives on tooling

This creates a network effect where each person’s knowledge elevates everyone else’s capabilities. Expertise flows in all directions across the organization. This collaborative culture develops a learning organization in which every interaction creates teaching opportunities and accelerated growth.

When you view DevSecOps through this lens, code review becomes a teaching moment. Security scans provide a learning opportunity. Every interaction in the system enables knowledge transfer and capability development. This is what sets certain engineers apart: They’ve internalized knowledge from adjacent domains through years of collaborative interaction.

The autonomous engineer: AI as a partner, not a replacement

The natural evolution of this collaborative model is the “autonomous engineer,” a knowledge worker augmented by AI that enables unprecedented independence and efficiency. The promise stays compelling. Every engineer gains AI partners that handle lower-level work, such as remembering, understanding, and basic application of concepts. Instructing an agent to perform these redundant tasks dramatically lowers cognitive load, freeing mental capacity for higher-order thinking, including analysis, evaluation, and creative problem-solving.

This is how AI can amplify human capabilities rather than replace them. Recent GitLab research found that although 83% of DevSecOps professionals believe AI will significantly change their role within the next five years, 76% agree that AI will actually create the need for more engineers, not fewer.

However, a dangerous counter-narrative emerges in executive circles. Some leaders believe highly capable AI agents can replace knowledge workers entirely. This represents a fundamental misunderstanding of how people develop expertise.

Even with highly capable AI, you still need human experts who can:

  • Evaluate outputs across multiple disciplines
  • Establish trust in AI recommendations
  • Provide domain-specific judgment
  • Take accountability for production systems

In fact, GitLab’s research found that 40% of DevSecOps professionals agree that AI tools will actually accelerate career growth for junior developers.

The argument that “we don’t need junior developers anymore” ignores the fact that someone still needs to review, validate, and take accountability for what AI produces. Junior developers aren’t just writing code; they’re learning to evaluate it across multiple domains, building the judgment needed to verify AI outputs.

The opposite argument, that AI might replace experienced architects and senior developers, remains equally problematic. This logic suggests we could skip foundational learning entirely and restructure computer science education to focus only on prompting AI agents. But without understanding what good code looks like across security, infrastructure, and business domains, how would these graduates know whether AI outputs are correct? Both extremes miss the point.

The actual bottleneck: Limited collective wisdom

The actual constraint isn’t AI capability. It’s the scarcity of people who can actually operate as that “autonomous engineer.” You need engineers with sufficient skills across multiple domains to effectively evaluate AI outputs in security, infrastructure, quality, and business logic. And you need educators who understand how to develop these multi-skilled practitioners.

The collaborative model from the original DevSecOps goal remains essential because it is the mechanism through which people develop the breadth of knowledge. The autonomous engineer isn’t someone working in isolation. This person has internalized the collective wisdom of the cross-functional team and can now operate with AI augmentation while maintaining the judgment and accountability that only human expertise provides.

The way ahead

Organizations face a critical choice. The tempting path views AI as a cost-reduction strategy by replacing expensive senior talent with cheaper tools and whoever can operate them. This path leads to brittle systems, technical debt, and ultimately failure.

The sustainable path recognizes that AI serves as a tool that amplifies existing capability but cannot replace the judgment that comes from deep, cross-functional knowledge.

The companies that will win are those that double down on collaborative learning while simultaneously investing in AI augmentation. They understand that creating an autonomous engineer requires first building a team that teaches each individual across multiple domains. They recognize that the code review process transfers the knowledge required to use AI tools effectively. They invest in building knowledge-transfer systems that create engineers capable of operating autonomously, having learned from the collective.

This illustrates the paradox of the AI age in software delivery. As our AI tools become increasingly capable, the value of collaborative learning becomes even more essential. The only way to create people capable of effectively wielding those tools is through the cross-functional knowledge transfer enabled by DevSecOps.

The goal hasn’t changed. We still need to increase productivity, maximize efficiency, and reduce risk. What’s changed is our understanding that achieving those goals at scale requires both collaborative learning and AI augmentation, not a choice between them.

The future belongs to organizations that build cultures where everyone teaches, everyone learns, and everyone becomes capable of operating as an autonomous engineer when augmented by AI. Ultimately, the real competitive advantage isn’t AI; it’s the people who know how to apply it effectively.

##

ABOUT THE AUTHOR

Bryan Ross

Bryan is an accomplished leader, seasoned technologist, and public speaker. With over 15 years of industry experience as a senior IT leader, he now helps customers realize business value from IT faster. Equally comfortable speaking with executives and engineers alike, he bridges the gap between technical and business stakeholders through compelling storytelling and real-world examples.