AWS Extends DevSecOps Reach to AI Coding Tools from Anthropic and OpenAI
Amazon Web Services (AWS) this week at the Black Hat USA conference revealed it is working with both Anthropic and OpenAI to integrate their respective coding tools with a service it has developed that makes available artificial intelligence (AI) agents to help application developers write more secure code. Launched earlier this year, the AWS Continuum […]
Amazon Web Services (AWS) announced at Black Hat USA that it is collaborating with Anthropic and OpenAI to incorporate their AI coding tools into AWS Continuum, a service designed to assist developers in writing secure code. AWS Continuum, launched earlier this year, offers access to AI agents capable of discovering, validating, and prioritizing vulnerabilities, along with providing remediation recommendations. This integration aims to streamline the feedback loop for developers during the code-writing process.
In addition to these partnerships, AWS has broadened the scope of AWS Security Hub Extended, a unified cloud security and posture management service, to include data provided by Chainguard and Socket. Chainguard offers curated open source libraries and container images, while Socket specializes in identifying malicious software packages. The security findings from AWS Security Hub are disseminated through an Open Cybersecurity Schema Framework (OCSF), which is being developed under the Linux Foundation's guidance.
Furthermore, AWS is teaming up with Miggo Security, a provider of AI runtime security and application detection and response (ADR) platform. This collaboration involves integrating rule sets directly into AWS Web Application Firewall (WAF) console. Gee Rittenhouse, AWS's vice president for agentic security, emphasized the company's focus on securing agentic workflows throughout the development process, from initial coding to post-deployment stages.
However, Rittenhouse highlighted the complexity of this task due to the dynamic nature of AI agents, which can assume various personas and roles at different stages of the workflow. Ensuring the trustworthiness of patches before deployment is crucial, he noted.
The adoption of AI coding tools and agents is surging. According to a survey by the Futurum Group of 839 IT decision-makers, 54% work for organizations utilizing AI across more than half of their software development lifecycle (SDLC). Moreover, 40% reported that AI is currently generating the majority of production code merged within the past 90 days.
Within the next three years, 58% of respondents anticipate AI to be responsible for 80% or more of their software development. However, three-quarters of the respondents have faced production issues linked to AI, with 42% experiencing multiple incidents, indicating the ongoing need for improved governance in agentic AI engineering.
Despite the challenges, AWS's strategic partnerships aim to facilitate the orchestration of agentic AI workflows, which will eventually encompass all facets of the software development lifecycle.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.