InfoWorld |
|
||||||
Five keys to controlling AI token costs11:06 We spent the last decade building entire finops departments just to decipher what the cloud bill was saying. Just when we figured out how to stop leaving idle compute instances running, generative AI introduced an infinitely more opaque, faster-moving layer of spend. AI bill shock has spread like a slow moving hurricane across the industry. Aside from the spike in large language model (LLM) costs… Cursor writes all my code now11:06 I was at the gym yesterday, talking with a relatively new CrossFitter named John, and naturally he asked me what I do for a living. I said I write software all day. But it hit me—I don’t actually write software anymore. I told him that, nowadays, Cursor writes all my code—I just tell Cursor what to do. I’ve written about how code isn’t important anymore and that we won’t be writing code much long… Atlassian launches AMP to tackle AI code visibility, attribution9:19 Atlassian today rolled out new offerings designed to make it easier for IT to differentiate coding by AIs from human coding. The problem is that such distinctions in the enterprise today are rarely binary, as much coding has lots of each. The lack of meaningful visibility into code origin is a massive problem for most large businesses, said Jamil Valliani , head of AI products at Atlassian, in an… Atlassian’s critical flaw turns eight enterprise products into one big security problem4:53 A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio. CVE-2026-21589 , rated 9.3 (critical) in severity, is an arbitrary file access vulnerability that could allow an attacker with no login access to read files in web app root directories that they should not otherwise see, and pote… AI has accelerated coding. Now software organizations must redesign everything around it23:23 Software teams running AI coding tools are generating more output than ever before. Commits are up. Pull requests move faster. By the numbers, developer productivity is what the tools promised. Delivery performance is a different story. Many organizations report that deployments have slowed and governance overhead has grown. The AI tools worked. The system around them did not scale with them. The… One week to TechCrunch Disrupt: What’s next for AI and software development18:01 First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code suggestions and code generation, where AI writes new code or improves existing code based on a natural language prompt. Today, coding agents can look at your code, suggest improvements, compile and test the improved code, and iterate on that to come… ServiceNow takes aim at enterprise AI’s workflow bottleneck with AI Workflow Factory15:20 ServiceNow has launched two AI solutions that can help enterprises identify business processes ripe for automation, build the workflows to address them, and continuously improve them with AI agents. AI Workflow Factory and Autonomous Engineer, announced on Tuesday, will bring process discovery, AI-assisted development and workflow execution into a single system that ServiceNow says can help enter… Don’t buy a consultant’s AI framework11:44 Every major consulting firm offers its own prebuilt architectural framework, model, or reference architecture for generative AI and agentic AI . The pitch is nearly identical from firm to firm: “We’ve done this before, we’ve packaged the patterns, and if you start from our blueprint, you’ll get down the path faster.” It’s an age-old consulting technique. Get the client interested in an out-of-the… Money can’t buy enterprise trust11:44 I thought the AI boom was producing a new level of bad behavior , what with MongoDB CEO CJ Desai peacing out, not to mention Google’s earlier controversial “acquihire ” of Windsurf’s executive team. But I was wrong: Money has a long history of hollowing out our ethical norms. The problem in these and other AI moves isn’t really about the money, but rather about the trust, or lack thereof, left in… JDK 27: The quiet before the storm5.října Every September, with metronomic regularity, we have a new version of the Java platform. One small point about timing is that the first release candidate of JDK 27 was delayed by two weeks due to the release of the first Critical Security Patch Update (CPSU) for the JDK. The need for a CPSU is a direct implication of AI models , such as Anthropic’s Claude Mythos, becoming much better at identifyi… What cloud infrastructure taught me about building billing systems5.října For years, I thought of billing as a domain I would have to learn from scratch. Ledgers. Taxes. Proration. Regulations. Money. After 11 years building cloud datacenter management systems, I assumed my infrastructure experience would take me only so far. I was wrong. A few years ago, when I began working on billing, what surprised me most wasn’t how different the domain was. It was how familiar th… Knowing which vulnerability to fix first5.října Common Vulnerability Scoring System (CVSS) severity tells you how serious a vulnerability could be. Exploit Prediction Scoring System (EPSS) estimates how likely exploitation is in the next 30 days. Neither one, by itself, tells you what your team should fix first. Run a dependency scan on any moderately sized JavaScript project and you will probably see a table of findings, many of them labeled … IBM’s Bob wants to move in: Agent available for on-prem deployment2.října Bob, IBM’s agentic software development platform is now available to run on premises and in private clouds, sovereign clouds, and air-gapped environments to give users more control over their data. IBM is hoping to lure companies operating in heavily regulated environments or managing sensitive source code and regulated data. In such environments, running AI operations means that they are under s… AI is less dangerous than humans2.října Over the past few weeks, people have been pushing a stack of reports at me as evidence that AI is dangerous to humanity. The OpenAI incident disclosures , the METR and Redwood Research joint investigation, the Nightingale Collective’s DseWiki report, and Ruby Central’s RubyGems update are the latest chapter in a story many people already believe: The machines are turning on us, and this time we h… AI could boost software engineer productivity by 32.6%2.října Tools such as Anthropic Claude Code or OpenAI Codex have changed the face of software development, and all the signs are that this investment is set to increase further. But is paying a monthly subscription (and perhaps additional usage fees) cost-effective? Will the increasing level of investment in AI-generated software prove to be worthwhile? That’s a question several economists from the US Na… |