Why secure engineering, governance and accreditation remain the key to delivering AI-assisted software in high-assurance operational environments
Over the past year, we've seen remarkable progress in AI-assisted software development. Tasks that once took days can now take hours, and working prototypes can be produced at an impressive pace. Yet for organisations responsible for national resilience, a prototype or an minimum viable product (MVP) is only the beginning.
For organisations responsible for critical services, the real measure of success isn't how quickly an application can be built. It's whether it can be trusted to operate in a live environment.
That means meeting the same standards for security, governance, operational resilience and maintainability as any other production service.
Recently, we supported a client operating in a high-security environment facing an urgent operational requirement. Waiting for a conventional delivery programme would introduce an undesirable increase in operational risk, but a rapid deployment that negatively impacted security and/or assurance was equally unacceptable.
Using the client's approved AI development platform, we accelerated the build while working within the controls already established across its technology estate.
The application was subsequently approved for deployment into the high-assurance production environment.
That outcome wasn't just significant because AI generated the code. It was significant because the application was fully AI generated AND it satisfied the standards expected of any production service.
This is where I think much of the discussion around AI still misses the point.
The question isn't whether AI can help us write software. We already know it can. The more interesting question is whether we can re-engineer the SDLC to incorporate AI code generation while continuing to deliver software that meets the expectations of organisations operating in highly regulated and security-conscious environments. And while we’re at it, we can work with our clients to re-engineer their governance and assurance processes so that they can take advantage of the AI-related speed and productivity gains.
From my experience, the answer depends far less on the AI itself than on the engineering discipline surrounding it.
AI can accelerate development, but it doesn't replace the need for sound architecture, secure design or a thorough understanding of a client's operating environment.
In this case, security and accreditation were part of the delivery from the outset. The application was integrated with existing authentication services, GitLab CI/CD pipelines and Transport Layer Security (TLS). Data handling, deployment controls and assurance requirements shaped the design from the beginning rather than becoming a checklist at the end of the project.
Generating the code was relatively straightforward. Designing something that could be released into a secure production environment requires engineering experience, domain knowledge, an understanding of the client's governance processes and close collaboration throughout the delivery. That's an important distinction.
Across sectors responsible for national resilience, we're seeing plenty of AI demonstrations. Fewer examples show how AI can become part of a repeatable delivery approach that satisfies enterprise standards and robust operational scrutiny.
For organisations delivering mission-critical services, that's where the real opportunity lies.
AI should help experienced teams solve problems more efficiently in order to scale their output - not to encourage shortcuts around governance or security. When used within established engineering practices and approved tooling, it can reduce delivery times while maintaining the confidence that critical services demand.
Ultimately, success won't be measured by how much code AI can produce. It will be measured by how many secure, reliable and valuable services reach production and continue to deliver long after the demonstration has finished.
Discover how CGI helps organisations operate critical national infrastructure and security-sensitive environments deliver trusted AI solutions securely and at pace.