How AI Is Transforming Development and Supply Chain Security
CHAPTER 6 AI in Software Development
In the ever-evolving digital landscape, artificial intelligence (AI) and machine learning (ML) stand out as transformative forces reshaping software development. As innovation takes center stage, an expanding toolkit of AI components and models play a pivotal role in driving this transformation.
Our exploration into the impact of AI and ML on software development draws from our research and survey of more than 800 developers (DevOps) and application security (SecOps) professionals. These insights reveal a broad adoption trend, with 97% currently incorporating generative AI in their workflows to some degree.
While the influence and intricacies of these tools offer immense opportunities, they also present challenges, including concerns for security and impact on jobs. Adding to these, and of particular interest to open source software and software supply chains, the consumption of AI and ML libraries has seen incredible rates of adoption. Unfortunately, additional concerns are present for teams including unplanned costs and increased liability.
This section covers two distinct but interrelated questions that have emerged on this topic: What role do AI and ML play in assisting developers, and what are the challenges that AI practitioners face in developing AI products? We explore both of those questions here.
Sonatype's survey: Risks and rewards of AI
For our recent AI-specific survey, we engaged DevOps and SecOps Leads responsible for software development, coding, developer relations, application security, threat intelligence, and analysis or security operations. Our primary objective was to understand how teams were using AI in their workstreams. Our questions ranged from frequency of use to what they found beneficial and challenging. We asked about the tools they were using, which industries are facing AI-related risks, and where they see the biggest opportunities. We’ll give you a peek at some of the fascinating results below.
The intersection of AI and software development
Code generation and testing
One of the most significant implications of AI in software development is its potential to generate code. Platforms like OpenAI's Codex, which powers tools like GitHub's Copilot, can assist developers by suggesting entire lines or blocks of code. Nearly half of the respondents — 47% of DevOps and 57% of SecOps — reported that by using AI, they saved more than six hours a week. Automated code suggestions mean faster development cycles.
Beyond speeding up the coding process, AI helps reduce the potential for human errors thereby expediting time-to-market and improving the quality and maintainability of software. Emerging AI-driven solutions can identify vulnerabilities, bugs, and inefficiencies in software code more swiftly than traditional methods. By understanding the context and intent of the code, these systems can predict potential failure points, enhancing the software's resiliency. The majority of SecOps (82%) and DevOps (79%) leads surveyed said they used AI for testing and analyzing.
AI tools
Among the 97% of DevOps and SecOps leaders who confirmed they currently employ AI to some degree in their workflows, most said they were using two or more tools daily. Topping the list at 86% was ChatGPT, with GitHub Copilot at 70%. Notably, GitHub Copilot caters primarily to developer teams. The capability and widespread adoption of these tools underscores the notion that "the hottest new programming language is English." Additionally, respondents also mentioned the utilization of other tools such as SCM Integrations, IDE Plugins, and Sourcegraph Cody.
Opportunity for developers at all levels
The benefits of AI for software developers are evident across all levels of the experience spectrum.
FOR SENIOR DEVELOPERS: ENABLING A MOTIVATED JUNIOR
- Senior Developers can leverage AI tools like GitHub Copilot to quickly complete tedious tasks.
- ChatGPT offers the promptness of AI technology while allowing juniors to be part of the development process and work with the senior developers.
FOR JUNIORS AND SENIORS: STREAMLINING WITH PRIVATE REPOSITORIES
- GitHub Copilot Chat allows developers to query the repository directly.
- These tools benefit developers working with a legacy project with little documentation, local knowledge, or when they need to learn a new code base.
- AI tools could reduce new-hire onboarding time from several months to a few weeks.
FOR JUNIORS AND SENIORS: ACCELERATING WITH AN EXTENSIVE REFERENCE
- Generative AI tools serve as a practical reference book for developers of all levels.
- ChatGPT helps look up common behaviors in programming languages and give clues on how to accomplish something without knowing basic syntax.
- Generative AI reduces time spent teaching standard techniques to juniors and helps senior developers with brainstorming.
- ChatGPT can also be a valuable tool for debugging.
FOR JUNIOR DEVELOPERS: BENEFITING FROM AN AI MENTOR
- Junior developers benefit from having AI/ML tools to answer quick questions and provide insight into technical terms and jargon.
- ChatGPT saves time for senior developers by handling basic queries, allowing them to focus on more complex issues.
- Large language model (LLM) tools can help answer questions about why a particular tool or architecture might be chosen, helping juniors understand tradeoffs and potential decisions.
Navigating concern
While the prospects of generative AI in software development are undoubtedly exciting, it doesn’t come without its challenges—even if those challenges are just perceived and not realized. 61% of developers believe the technology is overhyped compared to 37% of security leads. Although the majority of respondents are utilizing AI to varying degrees, it is not necessarily driven by personal preference. A striking 75% of both groups cited feeling pressured from leadership to adopt AI technologies, recognizing their potential to bolster productivity despite security concerns.
Introducing security challenges
Three (3) out of four (4) DevOps leads have expressed concerns regarding the impact of generative AI on security vulnerabilities, especially in open source code. Additionally, more than 50% of these individuals believe that this technology will complicate threat detection. Interestingly, less than 20% of SecOps professionals shared these concerns.
Perhaps not surprisingly, 60% of large companies surveyed were more likely to be concerned about security risks compared to less than 50% for smaller organizations. The same went for the illegal use of unlicensed code, where 49% of large organizations are worried about this, compared to 41% and 35% for mid-size and small organizations, respectively.
Tools require guidance
AI tools, particularly large language models (LLMs), offer significant assistance in various tasks, but they require considerable guidance to check their work and look for signs of bias. LLMs are not bound by fact, so they should not operate autonomously. For one, LLMs experience hallucinations or false information that require the person using the model to recognize when a mistake is made. AI is also not bound by rules or logical constraints. This reinforces the concept that AI is a tool to augment human capability rather than replace it. It will require experience and knowledge to identify these mistakes when LLMs generate code. If not carefully monitored, the risk of developing technical debt, a concern of about 15% of each surveyed group, might become a reality.
Job implications
One of the most palpable fears associated with the rise of AI and ML is job displacement. 1 in 5 of the SecOps Leads in our survey noted this as their top concern. Specifically, the current shortage in cybersecurity talent forces organizations to get creative to fill that gap. AI might be one way to do that. However, the reality points to a shift in roles rather than outright replacement. The technology is creating an environment where human creativity, intuition, and strategy are more valuable than ever.
AI's open source toolkit: Components and models in focus
Doubling down on AI and ML: Enterprise adoption trends
The usage of AI and ML components has also experienced a remarkable surge in enterprises. Over the past year, the adoption of these tools within corporate environments has more than doubled, reflecting a significant shift in how companies approach data science and machine learning. This surge underscores a growing awareness of the transformative power of AI and ML, as businesses strive to leverage these technologies to stay competitive and drive innovation in their operations.
Data scientist burden
Data scientists and engineers tasked with deploying open source LLMs shoulder a substantial burden, encompassing numerous critical decisions:
- Model Selection: With a vast repository of over 337,237 models available, they must carefully select the most suitable one for their specific application.
- Version Selection: Deciding which version of the model to use — be it chat-oriented, instruction-tuned, or code-tuned — requires consideration to align with the project's objectives.
- Parameter Size: Choosing from a spectrum ranging from hundreds of millions to hundreds of billions of parameters, they must determine the ideal model size.
- Embeddings: The selection of embeddings plays a crucial role in fine-tuning the model's performance.
- Context Window: Defining the appropriate context window is essential to optimize the model's responsiveness.
- Licensing and Security: Data scientists must remain vigilant about licensing and security implications, verifying the model's release license and assessing security risks.
Licensing risk
Deploying open source LLMs presents significant opportunities for natural language interaction with company products and knowledge bases. However, it is imperative to recognize the potential licensing risks associated with these models. In many cases, developers may fine-tune these models to suit specific applications, but the licensing terms of the foundational model must be carefully considered. This situation can lead to legal liabilities and intellectual property disputes, underscoring the importance of due diligence in understanding and adhering to licensing terms.
Conclusion: A collaborative future
The rapid evolution and integration of AI, especially LLM tools such as GitHub's Copilot and ChatGPT, have brought about a significant shift in software development. These advancements offer transformative benefits, including increased productivity, advanced language understanding, and diversified AI components. However, along with these advantages, there are also challenges to be addressed. Striking a balance becomes crucial. Transparency, accountability, and due diligence should be emphasized as we move forward.