Article Artificial Intelligence
03 July 2026

AI-Enabled SDLC Future Visions Panel: Q&A

Our first write-up of our AI-Enabled SDLC Future Visions panel covered the whole discussion. This is the second half of the conversation, the questions the room put to David Low, Ewan Nicolson, Morgan Kainth, Lynsey Brownlow and Brian Graham once the floor opened up. Four questions, four straight answers on automating governance, the AI use cases actually paying off, why the UK is lagging the US, and what happens to software once it's cheap to build.

Can governance actually be automated into the pipeline, or will it always be an external blocker?

Yes, to an extent. Architecture-as-code and automated guardrails can bake compliance into the deployment phase, and an agentic SDLC lets subject matter experts programme compliance rules directly into the development cycle, so best practice carries over from one project to the next rather than being relearned each time. Some organisations are going a step further and building custom AI tools specifically for their governance teams, to automate the more tedious compliance checks those teams currently do by hand.

The “to an extent” matters, though. Accountability doesn’t disappear just because a process is automated, someone still has to be legally responsible for certifying what an AI agent produces. And it’s worth watching for what the panel called human-in-the-loop fatigue: humans placed in a loop purely to verify AI outputs tend to get worse at the job over time, often ending up feeding the results into a second AI to check the first one’s work, which rather defeats the point.

The alternative that’s worked well on a recent greenfield build is what the panel called a “human-look” model rather than human-in-the-loop. Individual QA sub-agents check the work continuously, and a single oversight agent compiles a daily summary of everything that changed in the previous 24 hours. The team reviews and accepts that summary once, at stand-up, rather than reviewing code line by line, which keeps everyone genuinely engaged with what’s changing instead of rubber-stamping it.

What’s the most exciting application of AI you’re seeing right now?

The honest answer, several panellists agreed, is that the most exciting applications are usually the most mundane ones. Lynsey Brownlow’s example was from UX design: teams building synthetic personas grounded in real user research, letting product teams simulate feedback, run filter tests and surface edge cases before anything goes live. AI is also acting as a kind of content canvas, handling the mass data synthesis and production work so designers can spend their time on judgement, creativity and actually collaborating with people, rather than assembling the raw material.

Brian Graham’s example came from financial services, where agentic, proactive fraud detection is now operating in near real-time. Rather than chasing reactive metrics after the fact, these agent networks handle the bulk investigation work themselves, freeing human fraud analysts to spend less time digging through data and more time directly supporting the customers affected.

The example that stuck with the room, though, was a traditional wealth and pensions client who wanted to experiment with AI but was effectively paralysed by risk. The fix wasn’t a smaller pilot, it was delegating the risk itself: an external delivery partner designed, built, deployed and monitored the whole system, which let the client prove the technology’s value without having to carry the exposure of getting it wrong themselves. For risk-averse organisations in regulated sectors, that’s often a more realistic route in than trying to build internal confidence from scratch.

Why is enterprise AI adoption still so far ahead in the US compared to the UK?

Regulation and macroeconomics, more than appetite. The EU AI Act is weighing heavily on European and British companies trading in Europe, and a lot of UK enterprises are simply hedging until the regulatory picture settles, which the US doesn’t face in the same way.

There’s a cultural and structural gap too. Silicon Valley-adjacent companies tend to operate with larger budgets and a higher baseline expectation that engineers will use AI tools freely, while UK enterprises lean more heavily on structured change boards and traditional governance processes to get there. On top of that, there’s a genuine, and not unreasonable, hesitancy among some UK firms about routing proprietary data and intellectual property through US West Coast infrastructure, given how exposed that can leave a business to decisions made elsewhere.

That is an argument for building the governance model now, so that when the regulatory picture does settle, the only remaining question is deployment speed, not whether you’re ready.

If AI lets us build software faster, does that mean our software will start changing daily?

In some respects, yes, and the shift is already visible. In health-tech, applications are starting to synthesise symptoms, lifestyle data and third-party signals to anticipate what a user needs before they ask, moving toward a much more hands-off interface. Accelerated production is also forcing a pivot in how product teams work: historically, most teams spent too much time building, some time measuring, and almost no time actually learning from what users do. That balance has to flip. And because software is getting cheaper to build, expect more hyper-segmented, single-use micro-tools built to solve one specific, often temporary problem, rather than sprawling platforms built to do everything.

The ceiling on all of this, though, is human expression, not technology. Twelve years ago, Skyscanner set a product “North Star” to reserve a flight for a customer before they’d even realised they needed one. The team mapped out a detailed picture of what agent-driven travel could look like a decade on, and got most of it right, but ran into the same blocker every time: roughly 30% of travellers arrive at a search tool with no real idea where they want to go. An agent can’t act on preferences a person hasn’t worked out for themselves yet. Until that gets easier to solve, autonomous agent-to-agent transactions will stay confined to simple, well-structured tasks, turning on lights, playing a song, rather than anything that requires a person to know what they actually want.

If you missed the main recap of the panel discussion, you can read it here. And if you’d like the full research behind both, download the AI-Enabled SDLC Future Visions Opportunity Report below.

Future Visions Report

The AI-Enabled SDLC

Read more
Share this article

Related