Most teams will ship AI-written infrastructure code with little review
The proliferation of AI-assisted development has dramatically reshaped the software landscape, enabling developers to convert ideas into functional code at unprecedented speeds. However, this acceleration on the development front is creating a bottleneck and considerable pressure on infrastructure teams responsible for deploying and maintaining this AI-generated code. A Spacelift survey, encompassing 406 IT and platform leaders across North America, reveals the emerging disparities and challenges when one segment of the software pipeline rapidly outpaces another.
The survey indicates that while most organizations acknowledge AI's role in boosting developer velocity, a significant majority also report that it has imposed new and substantial demands on their infrastructure teams. The downstream consequences are already evident, manifesting as earlier surfacing security problems, increased difficulty in governance, a surge in change volume, and heightened strain on existing pipelines. A notable finding is that approximately two-thirds of organizations saw their developers adopt AI tools ahead of their infrastructure teams, directly contributing to where the operational burden now primarily resides.
One of the most critical findings is the willingness of teams to deploy AI-generated infrastructure code with minimal or no review. While 'Pioneer' organizations also utilize AI for infrastructure coding at a high rate, they do so within well-defined, governed pipelines. This structured approach ensures that any erroneous output is identified and rectified before it can reach production environments. In contrast, less mature organizations risk deploying misconfigurations with a broader blast radius, posing significant operational and security threats.
Despite these emerging risks, a large proportion of infrastructure leaders express confidence in their organization's ability to govern AI, yet a much smaller fraction has actually implemented formal governance policies. This discrepancy suggests a potential overestimation of control, particularly among organizations with fewer established safeguards. The report categorizes organizations into groups based on their AI readiness, from 'Exposed' (using AI with minimal governance) to 'Fragmented' (uneven adoption) and 'Outpacing' (aggressive adoption with lagging governance). The core message is that platform engineering offers a structural solution by providing a governed path for AI-generated code, making the secure route the most efficient one and fostering better collaboration among engineering, platform, and security teams.
Read original source