Organizations are missing a big target when developing governance and developer training programs for AI-assisted software development.
Those efforts still largely focus on professional developers, a reasonable position given the dramatic changes agentic AI is bringing to the software development lifecycle (SDLC), which is itself evolving into the agentic development lifecycle (ADLC). But the fastest-growing risk surface is actually coming from business users and other non-technical staff, a.k.a. “citizen developers,” who are rapidly producing applications using low-code and no-code tools, or building applications outright. When they ask AI how to share and deploy their creation, we see the tool often suggests Cloudflare or another non-approved environment (another layer of “Shadow IT”). And they are often executing these processes without a shred of training in software development or security.
We know people from marketing and HR to finance and operations are using artificial intelligence to build and implement automated processes, and sharing plenty of sensitive or critical data with AI tools to do that. Consider a hypothetical: a citizen developer building an automated workflow needs an API key to connect their AI tool to other systems. The key gets generated, and the integration works… but there’s little visibility into where that key is stored, who else can access it, or what happens if it’s exposed. If an attacker compromises that access point, there’s often no documentation of what systems it connects to or what data could be exposed as a result.
It’s not that citizen developers are in the wrong, since they are only doing what companies want them to do. But by taking advantage of low-code/no-code and AI tools, they are unintentionally introducing a bevy of vulnerabilities into their enterprises. The industry may see this as a tooling or visibility gap that requires scanning for shadow AI and enforcing role-based access control (RBAC) policies. But in reality, it’s a training, AI security and literacy gap that must be addressed before it’s too late.
The growing reliance on citizen developers may boost productivity, but it also creates a high-risk environment that demands unique AI governance and education protocols if organizations want to keep their software development safe and secure.
In the Wrong Hands, AI Tools Are Risky
The output of citizen developers is no small thing. Research studies project that 70% of new business applications and 75% of enterprise apps will be built using low-code or no-code tools this year, with 80% of no-code users working outside IT departments.
From a business point of view, this is by design, going back at least a decade as organizations sought to take advantage of low-code/no-code tools. In 2017, when an estimated 60% of custom apps were being built outside IT departments (30% by employees with little or no development skills), most companies surveyed said business departments were better suited than IT to develop custom app strategies.
The productivity boost, however, has raised risk levels, especially with the rapid growth of large language models (LLMs) and agentic AI.
A 2026 report by the Cloud Security Alliance showed that AI-assisted commits expose sensitive information at more than twice the rate of human-written code (3.2% versus 1.5%) and noted that independent studies found AI-generated code introduces security vulnerabilities in 45% of development tasks. CSA also cited studies finding that AI-generated code produces 2.74 times more security issues than human code, with a 100% failure rate on basic security controls like cross-site request forgery (CSRF) protections. In fact, a study by Georgetown University’s Center for Security and Emerging Technology (CSET) examined samples from five major LLMs and found cross-site scripting (XSS) vulnerabilities in 86% of their AI-generated code.
And security company Escape, addressing concerns of vibe coding, investigated more than 5,600 publicly available applications and found over 2,000 vulnerabilities, more than 400 exposed secrets, and 175 instances of PII exposures, including medical records, international bank account numbers (IBANs), phone numbers, and emails.
The combination of non-technical people building apps and the acceleration of security vulnerabilities may bring to mind the old appeal to “protect us from amateurs,” but it’s not like citizen developers are secretly building rogue apps under the radar. From their point of view, they are creating apps that work and are adding value to the organization, all on the up-and-up. The problem is that their AI coding assistants make mistakes that citizen developers don’t know how to catch or fix.
This is creating a wide training and governance gap. Employees using AI tools need the same kind of AI literacy and skills training that professional developers are getting.
Citizen Developers Need Practical Education
In many cases, security leaders aren’t fully prepared to effectively address the lack of security awareness among people who work outside of the SDLC. They often lack visibility into the tools employees are using, what they are building with those tools and how those applications are performing.
Security teams need to apply the same kind of education and upskilling to citizen developers that many provide to professional developers. They would benefit from having a framework, such as an established AI Adoption Model, which offers a three-phase, eight-stage guide to defining AI activity, the accompanying risk levels at each stage and the level of developer upskilling required at each stage. Such a framework can help organizations map where their citizen developers sit in the organization’s risk profile while shedding light on the path going forward.
The model mirrors the typical pattern of AI adoption, from small-scale functions to large-scale orchestrated implementations.
Phase 1. AI-Assisted: Phase 1 is an ideal time to establish governance policies and upskilling programs, as organizations make rudimentary use of AI with supervised human assistance. Risk levels are low to moderate. These early days are also a good time to begin using a tool such as Trust Agent: AI to establish baselines and track developer performance.
Phase 2. AI Native: At this point, teams are taking the training wheels off AI models and letting them work more on their own, so user education and upskilling should focus on preparing users to become code reviewers, an essential skill as AI takes the code-creation reins.
aSDwn, work with other agents in parallel and operate at scale. This phase, covering stages 5 through 8, calls for orchestrating multiple AI agents working as a team, with an understanding of policy enforcement, application risk scorecards and tracking commits for audit purposes.
An adoption model like that may be tailored for upskilling professional developers, though it can be applied to business users and others within an organization too. Citizen developers, however, aren’t pros, no matter how much they use AI tools. They need a level of AI literacy that they don’t have. That’s where an education program designed specifically for citizen developers would be indispensable.
AI Spans the Enterprise; Education Should Too
Secure software development has long been a challenge, with developers traditionally lacking security training and relying on security teams to fix flawed code before it goes into production. But the accelerating speed of the CI/CD pipeline made it imperative that developers acquire secure coding and review skills. Now, with nontechnical users powered by AI and low-code and no-code tools increasing organizations’ software output, it’s clear that education and upskilling must extend throughout the enterprise.
Enterprise-wide training is critical to reaping the benefits of agentic AI while effectively managing its risks. And the time to implement it is already here.


