AI’s Impact on Platform Engineering at PlatformCon NYC
Platform engineering took center stage in this Techstrong Gang session, recorded live at PlatformCon Live Day NYC. Alan Shimel and Mike Vizard dig into how AI is reshaping platform engineering, software development, security and the future of work. Their conversation captures the mood of a New York crowd that clearly sees platform engineering as a strategic priority, not a passing trend.
Why platform engineering matters now
The hosts frame platform engineering as the discipline that turns scattered tools into a coherent internal developer platform. Instead of asking every team to wire up its own pipelines, a platform team offers paved paths, sensible defaults and self-service APIs. That shift lets developers ship faster while the organization keeps guardrails in place. Alan and Mike argue that AI now accelerates this pattern, because smart automation can generate configuration, catch mistakes early and reduce the toil that slows delivery.
Live Day NYC gave the discussion a practical edge. Attendees traded notes on real deployments rather than slideware, and that grounded perspective comes through in the conversation. The hosts note that many organizations are past the “why platform engineering” debate and are now focused on how to scale it responsibly across teams.
AI, security and the future of work
The gang also weighs the trade-offs. AI can speed up code and infrastructure work, yet it raises fresh questions about governance, provenance and trust. Mike points out that security teams need clear visibility into what AI agents actually do. Alan adds that developer experience still matters most, so platform teams should treat their platform as a product with real users. The pair close by looking at how these changes affect careers, hiring and the day-to-day work of engineers.
For a deeper technical grounding, the CNCF Platform Engineering Maturity Model offers a useful framework for measuring how far a platform practice has matured. You can catch more roundtable analysis on the Techstrong Gang show page, where Alan, Mike and guests break down the stories shaping DevOps, security and AI every weekday.
Transcript
Hey everyone, it's Thursday, and welcome to "Techstrong," gang. If you couldn't tell, this isn't some AI background. We're actually up in New York City.
I'm home in New York. And if you're in New York, who better to be with than our New York guy, Mike Vizard? Mike, welcome.
We are at, well, what is this? The Convene Conference Center in Hudson Yards, right, which is on the Far West Side of Manhattan. And too bad, well, the camera's facing this way, facing out.
We've got a spectacular 270-degree view downtown down there with Freedom Tower. We've got the Empire State Building and the rest of Uptown over here. It's amazing.
Great view. But Mike, welcome. What we got?
Welcome to New York, and welcome home. You know what? As soon as I landed at JFK Airport, and I grew up 15 minutes from there, I felt home.
I really felt home. And of course, the hour-and-a-half cab ride in from JFK to New York reminded me of the downsides. But once you're in the city, the city's vibrant.
The city is, I don't know. We went to a Broadway play last night, dinner, and all things New York. There's always mojo in New York.
But hey, I wanted to revisit something. Since last we chatted, the election was completed, and it turns out that Midtown- Everybody, AI, Mark. Yeah.
Midtown New York decided that AI was not the only issue on the ballot, so Alex Boris did not win. I forget how many millions of dollars. It was like, totally in the primary, it was north of $50 million, but I would guess half of that went into that one election.
But it turns out that Mayor Bloomberg lives in that particular area, and so his candidate, his chosen one- Who was actually out of office ... was the insider's candidate, yeah. So not by much, though.
So, you know, this- Although it was a very crowded primary with seven people running, two of which, beyond AI, were very, very well-known, one being George Conway, Kellyanne Conway's ex-husband, who is very outspoken, very well-known, and second was Jack, Jack Schlossberg, JFK's grandson, who's a bit of a social media influencer himself. But I think the lesson here, Mike, for the tech crowd is, though we live and breathe AI every minute of the day, it seems, the average person walking in the street here, it's not the bread-and-butter pocketbook issue that we think it is. I think people are much more worried about healthcare, jobs, what's going on in our country, and stuff like that than just AI.
Yeah. I don't disagree, but I think we're going to hear more about this because Boris only lost by like four points, I think. So clearly, he was able to resonate with a significant percentage of the population.
And if he ran maybe in the People's Republic of Brooklyn, it'd be a different answer and different. Yeah. Maybe in a more progressive...
Because this was more of a moderate Democrat thing. But the other thing to remember is let's not just focus on that one race. The PACs on either side of the AI formula, they put in much, much more money than they did here in this New York race.
They're dumping money all over the place, too, including lobbying in DC itself. Right? So this future of AI is going to be paid for by lobbyists, and political influence is far from over.
It's coming back in the midterms. But hey, we're here at PlatformCon, and I want to talk about platform engineering. Okay.
And my current theory is that platform engineering had a certain amount of momentum early on. But now with the rise of AI, I have a feeling that the whole conversation around platform engineering is now being forced because organizations are sitting there saying, "Hey, we have all these AI coding tools. We have all these development environments.
We're trying to do this at scale. " What do you think? So I think, again, this is part of a bigger conversation, right?
I think if you look at the genesis of platform engineering, it originally came about managing Kubernetes platforms, right? If you managed Kubernetes, you were a good platform engineer. And of course, it evolved into IDP and other things.
But if you look at that core functionality of the Kubernetes platform, our virtual event, our Cloud Native Now, which is coming up, I want to say right before KubeCon in October, says the cloud-native stack is the AI stack. So if the cloud-native Kubernetes platform was platform engineering, and the cloud-native platform is now the AI platform, ipso facto, or whatever they say, platform engineering is about managing the AI platform. I think, though, there's a question in my mind, and it kind of goes to what degree will the developer agree to give up some of their independence as this comes around?
" And so there's a little more shift towards, for lack of a better phrase, a totalitarian approach to platform engineering. Well, we like to call it centralized, but- We want to bring politics into it. But here's the thing.
I used to think, Mike, that you would have to rip control out of the cold, dead, stiff hands of the developer. But again, in the words of one of my favorite quotes, Virgil Sollozzo from "The Godfather," "The Don was getting old, Mike. He ain't got that kind of juice anymore," right?
The developer, I don't want to say they've been a loser in this AI thing, because they're not. But certainly, we are seeing the transition from just pure coders, developers, to software engineers who manage the AI writing the code. And in that exchange, I think the developer has maybe lost some of their alpha predator status.
Or are they evolving as they become software engineers, and the alpha side of that equation moves to the, "I'm managing the whole thing, and I've got this small army of agents, and they're working for me," and everybody's a manager? Well, I think that is the future of human work. To me, that we're all going to be managers, but by the same token, we're all creators.
Right? And we're creating, and we're just using these agents and digital workers to create what comes from our imagination. Because at the end of the day, that's what the developer has.
That's what each of us will have as humans, the imagination and what we want to create. Whether we actually screw the nuts and bolts together or do the code is a different topic, but we will imagine it. I was talking to a couple of folks about that too, and they were, one, hopeful, but the practical underside of that that they were complaining about was now everybody thinks they're a developer.
And everybody's "vibe coding" stuff and shoving stuff into the pipeline, and it's like, well, guys, not all that code is of equal quality, and not much of it is making it into the production environment. " So you're back to AI scale. Whether we're talking about that or we're talking about the amount of vulnerabilities we're finding, the problem is as we move to an AI scale, both in terms of velocity and quantity of no matter what it is that the AI is doing, we need processes and platforms that can cope with that.
Because you could stamp your feet and hold your breath, people are not going to stop vibe coding. " And they're going to do it. So, a lesson from the security world, don't let the train leave the station without you, right?
At some point, you got to just go with it. Mm-hmm. It was interesting too, as this vibe coding thing continues to evolve, we're moving to a world where people now are just going to express an intent, and then the intent will be converted into a prompt, and then the prompt will be converted into a pull request.
So this becomes like a flywheel because everybody who's got a particular itch or an idea or whatever can suddenly generate a pull request. And I'm not quite clear that DevOps teams and platform engineering teams are fully cognizant of just how far this can go. You know what I say?
Welcome to Thursday. Excuse me. What you just described is the world we're living in.
And so I think DevOps and platform engineering teams are deadly cognizant of it. They know exactly. It scares the heck out of them.
But, to me, this is all a theory of constraints thing. So where's that next bottleneck? Is it the platform?
Is it the DevOps teams? We'll work that out, and then there'll be another bottleneck, I'm sure. But train's left the station.
We've got to do this. So the other part that I cannot quite figure out what will happen exactly is there's two things in my mind that could play out here. " Right.
On the other end of it, though, you could see a world where there's going to be more of those than ever because the AI agents are handling all the work, and it doesn't really matter what the underlying thing is either. " So I don't know, between those two extremes. Yeah.
So what you're really talking about is the bespoke model where, hey, if I've got my own army of agents who could build exactly what I want, when I want, how I want- I don't need to reuse code. I don't need to reuse a platform. Everything is custom.
And historically, if you look at the arc of history over the last 250 years, we did the exact opposite. We went from a world of guilds, craftsmen who made bespoke, everything was custom done from a piece of furniture to anything. Everything was done one-off, bespoke, to factories that mass-produced.
What you're getting at is are we going to move back from mass produce to custom? Is that what you think? We can have mass customization.
So I don't know if you remember when the internet first went commercial, there was a bunch of companies, one of them, I think it was called PointCast. So the idea was, instead of everyone having to watch what's on NBC, you get to make your own bespoke network of just what you want to watch. And we kind of have that world today.
With on-demand streaming and everything. But it didn't really work the way they thought it would, and people didn't embrace it the way they thought it would. I think at the end of the day, I don't know if it's something in human nature or what, but people like putting on comfortable processes and doing things that, hey, I know it worked for Mikey.
If it worked for Mike, it'll work for me. I also don't want to manage 10 different vendors if I don't have to. And there is that again, too.
But we see that consolidation, right? And that's the whole point of platforms as well. And it brings that all together into one platform.
What vendors are under the covers, that's for the platform engineer to deal with. Right. The other thing I hear people struggling with is, so all right, the developers aren't writing as much code.
Some of them aren't writing any code. And yet somebody has to review that code, and nominally it's the developer, but if it's not the developer, then it's a software engineer. The problem is, AI wrote it, neither the developer or the software engineer really understand how the code was created, and they don't have a feel for what the issues are or the context or whatever.
" Ship it along. " And others are saying, "Some of this code is overly verbose. " Well, we don't seem to have the ability to get in there and understand what this AI code actually does.
So, how do you see that evolving? Because the function has changed. I think we're just in a gangly teenager period right now.
That'll pass. First of all, I don't think it's going to be the software engineer or the developer or whatever you want to call them who actually reviews that code. I think a different AI than what wrote the code will review the code.
But even now, you could look at code, and if you're not sure what it is, ask the AI. And the AI, that's one thing it's pretty good at, is telling you that's what this is. This is why it's there.
This is the functionality of it. It may not be good at saying, yeah, you're right, this isn't elegantly crafted code. It's bloated, and we need to clean it up.
But this goes into the whole Jen Easterly Mythos Glasswing thing, which is as we use AI to find vulnerabilities and look at our code and examine code, it's going to force the whole development process, I didn't use the word developers, but the whole development process to make better code. Mm-hmm. See, that's a good thing.
Yeah. To that point, yeah, you can see how this will evolve in a certain way. And there might be more pain early on, but eventually we'll get to a better place.
But right now, folks are going- It's painful ... there's a lot of vulnerabilities being chucked into these applications by AI agents. And some of it is true, and some of it is not.
There's certain vulnerabilities that no longer appear because the AI actually doesn't generate those. There are others where it does. And so as the thing gets smarter over time, hopefully, we'll see less vulnerabilities, and there'll be better application security.
But I feel like there's a gap here between where we are and that promised land and the shiny house on the hill kind of thing. But no one seems to know how long that gap's going to be. You're right.
I agree with you. We don't know how long that gap's going to be because I think one of the biggest wild cards is, are we going to be allowed to continuing to develop better AI systems that code and look for vulnerabilities? Or has this whole Mythos fable thing put a damper on the release of the next models?
If we're going to say, my God, these models are getting so powerful, we can't put them in the hands of the average Joe, the average developer, the average software engineer, the average security person, the average platform engineer And we're stuck at this awkward teenage year stage. It's going to blow up. We need to keep moving forward.
" Probably Chinese. Well, and like I said the other day on the gang, the open source models will continue to evolve, and those might be Chinese as well. Well, sounds like we're getting started here.
It does. Sounds like we're going to move on to this whole thing. So, the other side of the security question goes something like this in my mind.
Theoretically, the AI discovers a vulnerability, and it can be exploited now in a matter of hours because they'll use AI to reverse engineer it. But at the same time, I should be able to create the patch faster and deploy it faster. So is this whole DevOps platform engineering motion going to start moving at machine speed in response to this cybersecurity issue?
It has to. It has to. And I'm actually doing a panel at 10:00 here this morning.
John Willis is on with me, my friend Ian Ahmed from Gabach, Mandy Walls from PagerDuty, and one other gentleman who's a former CISO, and I'm drawing a blank, I apologize. But the thing is here, even before Mythos, we had more vulnerabilities than we knew what to do with, than we could deal with. Right?
I was doing vulnerability management in 2003, and it was like that. Right? And we just have continually built up this technical debt.
Mythos is only 100x that. Right. So, if we don't do something, it's just we're going to drown in it.
I'm reminded, I remember going to a DevOpsDays Austin event years ago. I was talking about this with John Willis in the prep for the panel. And a friend of ours put up a graphic of the unicorn, and that was the DevOps unicorn.
Well, behind the DevOps unicorn was just a poor security guy cleaning unicorn crap. Well, that's the platform engineer today. Mm-hmm.
The platform engineer, they have to AI scale vulnerability remediation. So, to your point about that, it's no secret there's not been a lot of love lost between developers and security people over the years. Is that relationship going to change?
Because now, if I'm a developer, I'm going to go, "You know what? I got to go deal with these security issues, because they're not going to be things that occasionally happen. " And the security people now might be my best friend because they're helping me figure this out so that all my code doesn't keep constantly being chucked back.
I mean, couple of factors there. So the developer has gotten a little more humble, perhaps, right? Not being the alpha predator.
I think the security people-- Here's the bottom line. Theoretically, at least, we all want the same thing, don't we? Theoretically.
Okay. And I think part of this whole process is recognizing that, realizing it, and acting like it. It's going to be painful.
Mm-hmm. Be painful. I think the thing we all don't want is that call at 3:00 in the morning that says that, "Hey, your application just got breached, and we need you to come up with a patch," right?
This is the issue. Now, the good news is if we could improve the vulnerability scanning before deployment, and so have less bugs in production, you get less of those calls. But again, getting from here to there.
Well, let's be honest. The reason we don't scan is it takes too long and it creates too many false positives. But if it's an AI agent doing the scanning, well, A, the other AI agent doesn't care how long it takes, and B, will men get fewer false positives if the AI is actually better trained?
But again, AI scale is not just breadth, it's velocity. Mm-hmm. So I don't know.
I think how long it takes to scan now is drastically less with AI. Yeah. Drastically.
And like you said, they don't care. It's 24/7. That said, there's more code to actually scan.
It is kind of a... So, it makes the whole world go round and round, doesn't it? There you have it.
So ultimately, what is going to be the role of that developer as we go forward? Because, to your earlier point, they were kind of the center of the universe for a long time now. And so are they now just another cog in this larger-- In these wheels?
Another... Portraying the Pink Floyd song. Another brick in the wall.
There you go. Look, developers will always be Key to this whole software thing. And maybe developer is the wrong term.
Software engineers will always be the key player in this whole thing because it is their imagination. It is their ability to say, "I want to get from here to there. This is where I want to be.
" And that's an engineer foyer. That's an engineer job. And that's a particular mindset because as I think about this, at some point, there's, I don't know, hundreds of AI agents, and they all have sub AI agents.
The cognitive load of keeping track of what all those AI agents are doing at any given time requires a certain mindset, right? It is a kind of an engineering discipline. It's not for everybody.
Yes. So there's going to be software engineers, but I think, again, we discussed this on the Gang earlier this week. We're living in an age where engineers in general are going to be even more and more important than they've been in the past.
Whether we're talking about software engineers, hardware engineers, quantum, fusion, biotechnology engineers. We're moving into a world where the engineers are the creators. Mm-hmm.
And I think that's why the phrase I keep hearing now is agentic engineering, which kind of lays right in on top of the platform engineering. Right. And these may be two sides of the same coin.
I think platform engineering is going to be a form of agentic engineering, but not all agentic engineering is platform engineering. Fair enough. Good.
That'll work. All right. Hey, Mike, I got to go get prepped up for this panel.
Thanks for coming up here with us. Thank you for watching us. We are doing a lot of videos here that'll be showing up in the next couple of days as well.
But for now, here at beautiful Hudson Yards in New York City, this is Alan and Mike for Techstrong Gang. We'll see you tomorrow.