Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Scott Gregory, CISO, Sonar
The year 2025 marked a watershed moment where AI’s impact on code generation shifted from an interesting possibility to a dominant industry force. This exponential acceleration of development speed has brought incredible productivity gains, but it has simultaneously introduced an equally exponential set of security and accountability challenges. As CISOs, our traditional strategies must evolve.
Heading into 2026, the successful CISO will be one who views their role not as an auditor, but as a strategic technology partner, enabling developers to harness the power of AI securely. The future of software security hinges on automation, a fundamental redefinition of the developer’s role, and a commitment to securing code at the very first keystroke.
Here are my three core predictions for how the security landscape will evolve in 2026 and what CISOs must do to prepare.
1. The Developer’s Shift From Curator to Creator
We are currently seeing an exponential increase in code volume thanks to AI, creating a challenge far more complex than just a one-to-one increase in flaws. The core threat is one of velocity and scale. Since human attention can no longer manually verify code quality at the speed AI generates it, this shift has forced a fundamental change in the developer’s primary role: from being a core code creator to becoming a code curator and validator.
In 2026, the developer’s new core skill will be leveraging advanced tooling to validate AI-generated code at scale and knowing precisely where to focus their human attention. As CISOs, we must move past an oversight role and embrace a technology partner role. Our priority must be to work closely with development teams, asking: How can we help support building or buying the automation needed to enable this change? Success here means empowering developers, not scrutinizing them.
2. Reversing Alert Hyperscale to Restore Accountability
The single biggest security implication for developers stemming from AI is alert fatigue at hyperscale. Developers are now responsible for reviewing a significantly larger volume of code, and the sheer number of potential issues-both subtle and complex-is overwhelming the systems we have in place.
CISOs must approach this problem from the developer’s perspective. With this unprecedented increase in alerts, we are also inadvertently seeing a dangerous shift in developer accountability. As an industry, we must clarify that AI does not reduce personal accountability; it reframes it. Accountability in an AI-driven world shifts from the traditional “Did you write this code well?” to the modern “Did you validate this code effectively?” Committing AI-generated code is the exact same as committing your own. The developer must remain responsible for what they merge. Scaling with AI simply demands automation-specifically, the effective implementation of CI/CD pipelines leveraging trusted tooling-to make those reviews fast, effective, and manageable.
3. Start Left and Secure at Speed: Strategy for CISO’s to Win the AI Arms Race
The greatest urgency comes from the attacker side. Adversaries are using AI to find exploits faster, creating an exponential growth in attack vectors. The old security model of “find and fix”-using vulnerability scanning and pen testing on code after it’s written-is officially broken. The sheer volume of fixes required will overwhelm any security or development team trying to keep up.
Heading into 2026, the only winning strategy is to “Start Left” and “Secure at Speed.” CISOs must deploy tools that verify code as it is being written, directly within the developer’s Integrated Development Environment (IDE). We can no longer afford a verification bottleneck in the CI/CD pipeline. The CISO’s best strategic move is to empower developers with intelligent, automated tools that find and fix issues before they ever become part of the codebase. This is the only way to effectively neutralize the velocity advantage AI has given the attacker.
Overall, 2026 is the year where security teams must fully embrace automation as the foundation of secure software development. Our focus must shift away from trying to find and fix every flaw in a massive codebase, to giving developers the tools to ensure secure code is written from the start. By partnering with our development peers and automating verification at scale, we can restore clarity of accountability, mitigate hyperscale alert fatigue, and ensure security remains an enabler, not a blocker, to the incredible speed of AI-driven innovation.
##
ABOUT THE AUTHOR
Scott Gregory is an accomplished cybersecurity leader and trusted advisor with over 20 years of experience protecting global enterprises, securing critical assets, and enabling strategic growth by embedding risk management into corporate DNA. As the CISO at Sonar, he is responsible for defining and executing the security and risk strategy across the organization. Previously, he was Head of gTech Risk at Google, where he focused on mitigating data risks originating from third parties with access to Google’s systems. Before that, he spent 11 years at Amazon, culminating as Director of Security Risk and Compliance, building the program from the ground up and advising senior executives and the Board of Directors on global security posture.





