Skip to content
Insights

Engineering

By Luke Hermida

The Patch-or-Perish Cycle: Why Your DevOps Team is Losing the AI Arms Race

4 min read

The Patch-or-Perish Cycle: Why Your DevOps Team is Losing the AI Arms Race

If 2025 was about integrating AI into software development, 2026 is about cleaning up the wreckage. This week’s disclosure of a critical vulnerability (CVE-2026-90970) in GitLab’s AI Gateway—which allows attackers to escape prompt sandboxes and execute arbitrary commands on self-hosted instances—should be a wake-up call for every engineering manager.

The message is clear: By accelerating your code generation, you are accelerating your vulnerability exposure.

The "Babel 2.0" Risk

We have entered a phase of "Babel 2.0," where AI-assisted coding tools are generating code that is syntactically correct but security-illiterate. Worse, the gateways that manage these AI connections have become the new "crown jewels" for attackers. When an attacker compromises an AI Gateway, they aren't just getting access to a server; they are getting access to the very brain of your development pipeline.

The GitLab incident is a perfect example of how modern infrastructure is struggling to keep up with AI integration. Because these gateways must interact with various models, sandbox prompt templates, and provide low-latency responses, they often introduce complex "neutralization" weaknesses that traditional security tools fail to detect.

Engineering for Resilience, Not Just Speed

The current reliance on "patch-first" reactions is unsustainable. Engineering leaders need to rethink the "AI-in-the-loop" architecture entirely.

Practical Takeaways for Engineering Leaders:

  • Air-Gap Your Development Context: If your source code is sensitive, stop connecting it to public-cloud AI gateways. Technologies like IBM’s recently available self-hosted agentic platform allow enterprises to keep source code and build artifacts entirely within customer-managed, air-gapped infrastructure.
  • Assume Prompt-Template Poisoning: Treat your AI Gateway’s prompt templates as untrusted code. Implement strict input/output validation that operates independently of the AI model's own "security" features.
  • Prioritize Agent Observability: You cannot secure what you cannot see. Ensure your CI/CD pipelines include logging that tracks not just the code committed, but the AI suggestion that led to it. If a vulnerability is introduced, you need to be able to trace it back to the specific AI agent instance that generated it.

The New Reality of Maintenance

The "patch-or-perish" cycle is now a permanent feature of the modern enterprise. With CISA adding AI-gateway-related vulnerabilities to its Known Exploited Vulnerabilities catalog, your security team can no longer operate in a silo. Security must become an integral part of the AI development loop—not a hurdle that engineers attempt to bypass for the sake of velocity.

The reality is that AI is not just writing your software; it is dictating your attack surface. If your development team isn't treating AI tools as "untrusted contributors," you aren't just at risk—you are already compromised.

Put it into practice.

If this described a problem you recognize, the next step is a conversation about your workflow.

We use optional analytics to understand how this website is used. No analytics loads until you allow it, and declining keeps everything on the site working.