From Gates to Flow: How AI Is Redesigning Software Engineering

Updated: 10 hours ago

Recently, I met with a client in the financial services industry to discuss exactly this kind of transformation.
The conversation started with technology, but quickly became much broader.
We discussed the development of new applications, modernization of legacy systems, productivity gains, integration with existing platforms, security, compliance, specification quality, and the use of AI agents.
But as we went deeper, it became clear that the challenge was not simply:
“How do we use AI to develop software faster?”
The questions were broader.
How do we ensure that a specification produced by the business has enough quality to feed an increasingly automated process?
How do we integrate agents with existing systems, APIs, data, and processes?
How do we ensure security, traceability, segregation of duties, and compliance?
Which decisions can be delegated to agents?
Which should remain under human responsibility?
How do we preserve architecture standards?
How do we modernize applications without automating existing problems?
How do we measure productivity when humans and agents begin working together?
And perhaps the most important question:
How do we dramatically increase speed without losing control?
That conversation reinforced an important perception.
The transformation AI is bringing to software engineering will be much larger than adding a Copilot to the developer or placing a few agents inside an existing pipeline.
We are beginning to redesign the development system itself.
It Is Not Just a Technology Transformation
It is natural to look at Agentic Development through the lens of tools.
Foundation models.
Coding agents.
Orchestrators.
AI gateways.
RAG.
MCP.
Automation.
All of this matters.
But it is only one part of the transformation.
When agents begin executing activities previously performed exclusively by people, other dimensions change as well:
culture, processes, roles, frameworks, governance, architecture, controls, metrics, and operating models.
An architect is no longer only someone who reviews solutions. The architect also begins defining policies that agents continuously interpret.
QA is no longer limited to working after development. It becomes part of a permanent validation process.
Security is no longer just a gate. It becomes continuous.
Product Managers and business teams take on even greater responsibility for the quality of intent and specifications.
Developers stop producing every artifact manually and increasingly guide, supervise, and validate work produced by agents.
Engineering leaders begin managing a hybrid workforce.
Human + Agent.
For Decades, We Built Software Around Handoffs
A demand originates in the business.
Someone turns it into a requirement.
Architecture designs the solution.
Development implements it.
QA tests it.
Security reviews it.
Operations prepares it for production.
Each stage exists for a legitimate reason.
The problem is that these stages also created:
handoffs, queues, waiting, meetings, approvals, and rework.
In many projects, software does not take long because the code is particularly difficult to write.
It takes long because it spends much of its time waiting.
Waiting for a specification.
Waiting for a decision.
Waiting for architecture.
Waiting for testing.
Waiting for another team.
Waiting for approval.
Now we insert AI into this system and ask the first wrong question:
How much faster will we be able to write code?
Perhaps the more important question is:
How much faster can we make the entire engineering system flow?
Faster Coding Is Not Faster Delivery
The ability to produce software is increasing rapidly.
Copilots increase individual productivity.
Agents can already build entire components.
Low-code and no-code continue to advance.
Models can generate applications from natural language.
But if we produce code five times faster and still wait days for architecture, security, testing, integration, or approval, the systemic gain will be much smaller than it appears.
The bottleneck simply moves somewhere else.
Optimizing one activity does not mean optimizing the flow.
This may become one of the major debates in Software Engineering over the next few years.
The opportunity is not only to accelerate development.
It is to redesign the Software Development Lifecycle itself.
From Gates to Flow
Traditional software engineering was built around gates.
Specification.
Architecture.
Development.
Testing.
Security.
Compliance.
Integration.
Deployment.
These gates will continue to be necessary, especially in large enterprises and regulated industries.
What is likely to change is the way they operate.
Today, many still work like this:
Create → Wait → Review → Fix → Wait → Approve
In an increasingly agentic environment:
Create ↔ Validate ↔ Correct ↔ Integrate
The goal is not to eliminate quality gates.
It is exactly the opposite.
The faster production becomes, the stronger validation capacity must become.
Controls need to evolve from isolated checkpoints into Continuous Quality Gates.
Continuous Quality Gates
Imagine a new demand entering the process.
Before a Developer Agent even starts working, another agent analyzes the specification.
It searches for ambiguities.
Identifies missing requirements.
Checks acceptance criteria.
Analyzes non-functional requirements.
Compares the demand with standards and policies.
Then an Architecture Agent verifies:
architecture standards;
approved technologies;
security;
regulatory requirements;
resilience;
observability;
performance;
costs.
During implementation, other agents can work simultaneously.
QA generates and executes tests.
Security checks vulnerabilities and dependencies.
Architecture monitors compliance.
Documentation keeps artifacts up to date.
FinOps evaluates economic impact.
Observability checks readiness.
Validation stops being a phase.
It becomes a permanent characteristic of the process.
Garbage In, Garbage Out — Now at Scale
This transformation creates a critical issue.
AI dramatically increases execution capacity.
But it also increases the speed at which we can implement a bad decision.
The principle remains familiar:
Garbage in, garbage out.
The difference now is scale.
Previously, a poor specification typically produced human rework.
In an agentic environment, it can rapidly produce:
inadequate architecture,
inadequate code,
tests built on incorrect assumptions,
incorrect integrations,
inconsistent documentation,
and the wrong software reaching production faster.
Garbage in can become garbage at scale.
That is why Specification Engineering becomes critically important.
When specifications feed agents capable of executing work, they stop being merely documents.
They begin functioning as executable intent.
And executable intent requires quality.
Before execution, the system itself should assess:
Is the requirement complete?
Is there ambiguity?
Are the acceptance criteria objective?
Are the NFRs defined?
Are security, data, integrations, and compliance clear?
Is the expected business outcome explicitly defined?
The greater the autonomy of execution, the higher the quality required at the input.
Low-Code Is Not Plug & Play
This discussion also changes how we should interpret low-code, no-code, and AI-generated applications.
These technologies significantly reduce the difficulty of creating software.
But reducing coding complexity does not mean eliminating engineering complexity.
There is a huge difference between generating an application and putting an enterprise application into production.
There are still:
identity,
data,
APIs,
legacy systems,
integration,
security,
privacy,
compliance,
observability,
performance,
resilience,
costs,
architecture,
operations.
That is why:
Low-code reduces coding complexity. It does not eliminate engineering complexity.
Some of the complexity simply moves elsewhere.
It shifts from manual implementation to:
context, integration, architecture, governance, and operations.
Software will become easier to produce.
High-quality enterprise software will not automatically become simple.
Modernization Will Also Need to Be Reinvented
The same logic applies to application modernization.
For years, we structured programs around:
Assess → Classify → Refactor → Test → Migrate
Agentic AI can transform every stage.
Agents may be able to:
analyze millions of lines of code,
reconstruct documentation,
identify dependencies,
discover APIs,
extract business rules,
map databases,
generate tests for current behavior,
propose future architectures,
convert components,
analyze risks,
test functional equivalence.
This even changes the initial question.
Modernization may stop beginning with:
“How do we convert this system?”
and instead begin with:
“What does this system actually do, why does it do it, and what should continue to exist?”
Legacy applications carry decades of decisions and institutional knowledge.
In many cases, the real asset is not the code.
It is the business rules hidden inside it.
Using AI only to convert code may simply mean:
modernizing the problem faster.
This Transformation Is Already Appearing Across Major Platforms
This movement is not happening only in the discussion around AI Coding.
Ecosystems such as AWS, SAP, Oracle/OCI, and other major providers are beginning to incorporate agents, context, automation, governance, and assisted development directly into their platforms.
AWS is advancing the combination of specification-driven development, agents, cloud engineering, security, observability, and agentic runtime.
SAP adds a critical dimension: business context.
Processes, data, business rules, extensions, and modernization are increasingly being combined with agents and AI capabilities inside the enterprise ecosystem itself.
Oracle and OCI are moving in a similar direction, bringing agents, enterprise applications, data, transactional processes, development, and cloud infrastructure closer together.
Other ecosystems will follow the same trajectory.
This reinforces an important point:
the future will not simply be about choosing which LLM to use.
Large enterprises will have different agents operating across SAP, AWS, Oracle, Salesforce, custom applications, data platforms, and legacy systems.
The challenge will be making all of this work together while respecting:
architecture, integration, identity, security, data, compliance, observability, and corporate policies.
Agentic Development does not eliminate enterprise complexity.
It requires a new way to orchestrate it.
Human + Agent Will Be an Organizational Transformation
The discussion should not be:
human or agent?
But rather:
what is the best combination of humans and agents for each activity?
Agents are particularly powerful at:
execution,
repetitive analysis,
comparison,
generation,
testing,
documentation,
monitoring,
compliance,
validation,
correction.
Humans remain especially important for:
intent,
context,
judgment,
strategy,
trade-offs,
exceptions,
risk,
accountability.
In some scenarios, we will have Agent-in-the-loop.
In others, Human-in-the-loop.
And progressively we will see Human-on-the-loop, with agents operating within clear guardrails and humans supervising exceptions, risks, and outcomes.
Having a human approve every action taken by every agent would recreate exactly the bottleneck we are trying to eliminate.
Autonomy needs to evolve together with governance.
Frameworks Will Also Need to Evolve
Most current frameworks were created for predominantly human organizations.
SDLC.
Agile.
Scrum.
DevOps.
ITIL.
Architecture Review Boards.
Security Reviews.
Change Management.
They do not need to disappear.
But they will need to answer new questions.
Who is accountable for a decision made by an agent?
How do we version the policies that guided that decision?
How do we know which information the agent used?
When is human intervention mandatory?
What level of autonomy can each agent have?
How do we measure the quality of agentic work?
How do we handle segregation of duties?
How do we test agents before putting them into production?
These are technology questions.
But they are also questions of process, risk, control, and culture.
Software Engineering May Evolve from a Pipeline into a Network
For a long time, we represented development like this:
Product → Architecture → Development → QA → Security → Operations
A sequence.
In an agentic system, different capabilities may work simultaneously.
A Developer Agent implements.
A QA Agent tests.
An Architecture Agent verifies adherence.
A Security Agent evaluates risk.
A Compliance Agent verifies controls.
A FinOps Agent evaluates cost.
An Observability Agent checks readiness.
An Orchestrator coordinates dependencies.
Humans enter where judgment and accountability are required.
Some of the work that happens sequentially today begins happening in parallel.
That gain is very different from simply writing code faster.
It is flow productivity.
Consulting Firms Will Also Have to Change
This transformation will have a profound impact on the technology services industry.
Historically, much of a consulting firm’s intellectual capital has been distributed across:
people,
methodologies,
frameworks,
templates,
reference architectures,
past experience,
industry knowledge.
This intellectual capital has always been difficult to scale.
Much of it lives in the experience of professionals.
Agentic AI can change that.
Consulting firms may progressively transform this knowledge into specialized agents.
An Architecture Agent incorporating accumulated standards and decisions.
A Modernization Agent carrying methodologies and prior experience.
A Security Agent incorporating policies and failure patterns.
An Industry Agent containing specific knowledge of banking, manufacturing, or retail.
A QA Agent incorporating validation strategies developed across numerous projects.
The agent stops being simply an LLM.
It becomes a composition of:
Model + Tools + Context + Policies + Methods + Experience + Proprietary Knowledge
This may become a new kind of asset:
Agent as Intellectual Capital.
The Professional No Longer Arrives at the Project Alone
Imagine a senior architect joining a major transformation program.
Today, that professional arrives with experience, methodologies, documentation, and access to specialists.
In the new model, they may arrive accompanied by a digital workforce:
Architecture Agent
Modernization Agent
Security Agent
QA Agent
SAP Agent
AWS Agent
Compliance Agent
FinOps Agent
The human professional remains essential for relationships, context, judgment, decisions, and accountability.
But their capacity becomes multiplied.
Two consulting firms may use exactly the same foundation model and produce completely different results.
Because the competitive advantage will reside in the knowledge built around the model.
Foundation models may become commodities. The intellectual capital encoded around them will not.
This Could Change the Economics of Technology Services
For decades, professional services scaled primarily by increasing headcount.
More projects required more people.
More specialists.
More hours.
The traditional model could be summarized as:
Expertise × People × Hours
Agentic AI adds a new dimension:
Expertise × Agents × People × Platforms
This does not mean removing people from the equation.
It means reducing dependence on a linear relationship between capacity and headcount.
Knowledge can be reused.
Frameworks can become executable.
Policies can guide thousands of decisions.
Accumulated experience can be distributed across multiple projects simultaneously.
This changes the nature of intellectual capital itself.
Our Metrics Will Also Have to Change
If this transformation happens, traditional metrics will lose relative importance.
Lines of code?
Commits?
Story points?
Number of developers?
We will continue looking at some of them.
But more relevant questions will begin to emerge.
How much time exists between an idea and its arrival in production?
How much of that time is actual work and how much is waiting?
What percentage of validations happen automatically?
How many problems are discovered before development begins?
How much rework exists?
How many decisions can be resolved within guardrails?
How many times does a human need to intervene?
How many defects escape the quality gates?
How much knowledge can we reuse?
Perhaps one of the most important metrics will be:
Flow Efficiency.
Because the objective is no longer simply to make people work faster.
It is to make the entire system work better.
It Is Not Enough to Add AI to the Current Process
Perhaps that was the main conclusion from that conversation with the client.
We are not facing just another productivity tool.
There is potential for a transformation that is:
technological,
process-driven,
cultural,
organizational,
and economic.
New ways of developing software will require new forms of control.
More automation will require new quality mechanisms.
More autonomy will require better policies.
Greater productivity will require better specifications.
New agents will require new accountability models.
Modernization will need to incorporate knowledge, not merely technology conversion.
Consulting firms will need to transform intellectual capital into reusable and executable assets.
Companies will need to revisit their engineering frameworks for a world in which a meaningful part of the work is no longer performed exclusively by humans.
From Software Development Lifecycle to Software Development Flow
DevOps reduced barriers between development and operations.
CI/CD automated integration and deployment.
Cloud made infrastructure programmable.
Platform Engineering increased standardization and self-service.
AI-assisted development is increasing individual productivity.
Agentic Development may represent the next leap:
automating part of the intellectual work required to understand, design, build, validate, integrate, operate, and evolve software.
But this will not happen simply by connecting agents to the current SDLC.
We will need to redesign the system.
Fewer handoffs.
Less waiting.
More parallel work.
Better specifications.
Continuous Quality Gates.
Executable guardrails.
Autonomy proportional to risk.
Reusable intellectual capital.
And a new composition between humans and agents.
Perhaps we need to think less about a Software Development Lifecycle and more about a Software Development Flow.
A continuous flow of:
Intent → Design → Build → Validate → Correct → Integrate → Observe → Learn
where people, agents, tools, platforms, policies, and knowledge work together as an integrated system.
The question for business and technology leaders is no longer simply:
“How do we use AI to write software faster?”
It becomes:
“How do we redesign our engineering system to transform business intent into high-quality software, with security, compliance, and the least possible friction?”
Because the next revolution in software engineering will probably not be defined by who can generate the most code.
It will be defined by who can transform:
knowledge, intent, engineering, governance, and quality
into a continuous flow between a business need and its execution.
The future of software development is not just faster coding.
It is better flow.



Comments