Mentors of Digital Innovation
cio-blog-banner.png

CIO Two Cents Blog

The ‘CIO Two Cents’ blog features insights from Yvette Kanouff, partner at JC2 Ventures. Learn what’s on the mind of CIOs at this moment in time.


From SDLC to AIDLC: Who’s Driving?

VOLUME 1 - ISSUE 23 ~ August 4, 2026

 

In this edition of the “CIO Two Cents” newsletter, I explore the shift from the traditional software development life cycle to the AI-driven development life cycle, and why stronger guardrails, monitoring, and human oversight are essential as AI takes on a greater role in how products are built.
— Yvette Kanouff, partner at
JC2 Ventures

The JC2 Ventures team (John J. Chambers, Shannon Pina, John T. Chambers, me, and Pankaj Patel)

The JC2 Ventures team: (John J. Chambers, Shannon Pina, John T. Chambers, me, and Pankaj Patel)

 

(1)

The shift from the traditional SDLC to the AIDLC is accelerating, changing how products are built, tested, monitored, and released.

(2)

As AI takes on more of the development process, strong guardrails, sandboxing, continuous monitoring, and human oversight must be built into the lifecycle from the start.

(3)

The goal is not to remove humans from the development process, but to create an AIDLC in which people and AI each do what they are best equipped to do.

 

As product and engineering leaders, we have long focused on our beloved software development life cycle, or SDLC. Just as we thought we had it stable and right, we are now adopting an AIDLC: an AI-driven development life cycle. 

For many of us, this shift has moved faster than our ability to control the AIDLC (or in some cases, even try to define it); AI tools have accelerated development and go-to-market timelines, and our lifecycle needs have changed along with it. As our focus shifts toward AI safety and governance, getting control of the AIDLC is a must.

In the old days of the SDLC, product managers defined requirements, UI teams laid out a beautiful customer experience, security teams determined cybersecurity requirements, and engineers wrote the code. Throw in compliance expectations, backlogs, and customer needs, and the SDLC had many steps, checkpoints, and handoffs.

Now, much of that has been turned on its head. Product managers are vibe coding. Engineers are working across multiple models, optimizing tokens and using AI-based tools to build and scale products faster. UI is no longer always a traditional handoff, because, quite frankly, there is often no time to wait (another fun blog topic given the long-standing push and pull there). Bugs are also getting resolved at record speed.  

With speed becoming one of the most visible gains in development today, much of the human role is shifting toward context engineering, validation, cross-checking, and of course, compliance and governance. We are now becoming orchestra conductors instead of individual instrument players, and that changes how we handle the development lifecycle and its rules.

Many teams are happy to leave behind the handoffs and delays associated with the traditional SDLC. Testing was historically one of the last stops on the train, and it took years of CI/CD focus to move toward the test-as-you-go model. Now, with AI, building and testing are becoming truly continuous, and even complex testing is getting easier with AI assistance.  

The real-time, ever-changing, super-fast AIDLC is fun – but it can also create chaos if it’s not managed properly. Real-time requirements, continuous releases, deployment monitoring, release evaluation, automation, and more all need structure. Data drift, performance, hallucinations, compliance, governance, and transparency can’t function as afterthoughts. They have to be built into the lifecycle.  

Recent incidents show why that structure—and greater due diligence around sandboxing and monitoring—is so critical. An experimental OpenAI model escaped its testing environment and compromised Hugging Face, while Anthropic acknowledged that misconfigured test environments allowed Claude models to reach the public internet and access three organizations’ systems.

As AI-era engineers, we also have to think differently about release harnesses and how we evaluate AI’s context, accuracy, drift, data quality and value, and governance requirements. Some people say AI does it all, but human involvement is more critical than ever.

As a fun side note, I was recently talking about this shift with my friend and colleague Jane Paek. Jane is Director of Customer Engineering at Google Cloud, where she helps companies and their engineering teams with data analytics, AI, and application modernization. She’s a wonderful technologist and person.

Jane compared the transition to AIDLC to teaching a teenager how to drive. The journey is stressful, but with the right instruction, guardrails, and practice, the driver becomes more capable and independent.

Right now, enterprise engineering leaders can feel like anxious parents sitting in the passenger seat. They see the potential, but they are also terrified of a major wreck. At the same time, they know that never letting the kid take the wheel is not the answer. The organization has to learn how to use the technology responsibly.

Here's how Jane sees today's agentic development map to the anxiety, guardrails, and growth of a teenage driver:

AIDLC as a Teenager Behind the Wheel

1. AI the Teenager, Teachable but Erratic Driver 

  • The Teenager has aced the written permit test. They know the rules, are highly capable, and ready to get moving. But they lack real-world intuition. They can be easily distracted or confidently take a turn at 50 mph without realizing the road is icy.

  • AI Agents are similar. They can write a multi-file feature in 10 seconds, but they don’t truly understand the architectural weight or downstream "traffic" they are creating. When they encounter an unfamiliar edge case, they can still make erratic and unpredictable maneuvers.

2. Parent Anxiety & The Double-Brake Passenger Seat (The Human-in-the-Loop)

  • The Parent is sitting in the passenger seat with white knuckles, sweating, and wishing they had an emergency brake on their side of the car. They want the teenager to learn, but they’re not about to close their eyes or let go of the grab handle.

  • The Engineering Guardrail is the human-in-the-loop model. This is why enterprises are understandably hesitant to give AI and AI agents unrestricted access to the "highway" of production deployment. AI may be able to drive in the empty parking lot of local development, but humans must still review outputs, approve pull requests, and sign off on the merge. The human is constantly hovering over the brake pedal.

3. Driver’s Ed & Closed Courses (Ephemeral Sandboxing)

  • Before letting a 16-year-old onto the interstate, parents typically put them in a closed, empty parking lot with some plastic cones. If they lose control and spin out, the worst that can happen is that they hit a piece of orange plastic – the environment is designed to limit damage.

  • AI agents require a similarly controlled environment. Security teams can establish temporary, isolated digital sandboxes or virtual clean rooms where agents can safely run scripts, execute code, and deploy test environments. Should an agent hallucinate, enter a malicious loop, or "crash," the entire environment is wiped immediately, leaving actual infrastructure completely unharmed. However, because AI agents frequently venture down novel paths unmapped by humans, sandboxes must continuously evolve to keep pace with capabilities that constantly push the boundaries of their enclosure.

4. Speed Limits, Traffic Cops, and Breathalyzers (Security Frameworks & Tool Registries)

  • We don’t only rely on parents to keep new drivers safe. We have a massive, systemic infrastructure to minimize the damage they can do with speed limits, traffic cameras, licensing requirements, and rules about where drivers can and cannot go.

  • The AIDLC will need a similar supporting infrastructure: rate limits to control how quickly agents act; continuous observability to show what they are doing; tool registries and access controls to define which systems they are allowed to use; and evaluation frameworks to help determine whether outputs are ready before they reach production. 

The Road to Maturation

A teenager doesn't stay 16 forever. With structured practice, clear boundaries and real-world experience, they become more capable.

The same is true of the AIDLC, which will eventually graduate from this awkward, high-anxiety phase.

The industry is rapidly building better "autonomous sensors" – standardized evaluation datasets, deterministic guardrail layers, and mathematically verifiable boundaries for how AI systems operate.

We are currently in the most stressful part of the timeline: The Permit Phase. 

The potential is undeniable, but mistakes are frequent, and the human passenger is doing the heavy lifting. With enough structured practice inside safe, well-governed boundaries, the system will eventually earn its full license. Given the power of AI, hopefully the system will drive even better than the parent did.

How is your company navigating the evolution of the AIDLC?

 

Image of the Moment

 
Yvette posing in front of Google "G"

Courtesy: Yvette Kanouff

 

Your Thoughts on the AIDLC