Connect with us

NEWS

AI Governance Lags Coding Gains, and Amazon Felt It First

Info-Tech finds 94% of developers report AI gains, but Amazon’s Kiro-linked outages and a 1,500-employee petition show governance already lagging.

Published

on

Ninety four percent of developers say generative AI has made them measurably more productive this year. That finding comes from Info-Tech Research Group, a global IT research and advisory firm that published the numbers on July 20. The same report found something else: the review habits meant to catch what that AI writes have not caught up to how fast it writes.

Amazon already knows what that gap costs. A string of AI-linked outages on its retail site this spring wiped out millions of orders in a single week, and the company kept its AI usage mandate in place anyway, over objections from its own engineers.

Info-Tech’s Survey Puts a Number on the Gap

The research draws on 578 completed survey responses from applications, engineering, and product leaders actively using AI across the software development lifecycle. Info-Tech found that 84% of respondents apply AI during the Build phase, the stage covering analysis, design, development, and testing.

The productivity number is real. So is the catch sitting right next to it: 67% of developers agree that AI-generated code needs more testing than code a human wrote alone. Info-Tech also linked stronger AI maturity at the Build phase to stronger reported productivity, meaning the teams that structured how AI entered their workflow did better than teams that just handed out subscriptions.

Metric What Info-Tech Found
Productivity gains 94% of developers report meaningful improvement
Defect reduction 83% report meaningful reduction in defects
Build phase adoption 84% already use AI in analysis, design, development, and testing
Testing burden 67% agree AI-generated code needs more testing than human-written code

Read next to each other, those four numbers describe an industry that adopted a tool faster than it adopted the discipline to check it.

Amazon’s Own Coding Agent Already Sent the Bill

Nobody had to imagine what an ungoverned AI coding tool looks like in production. Amazon built one, called Kiro, and watched it fail in public over a five month stretch.

  1. December 2025: Kiro, AWS’s agentic coding assistant, was asked to modify a cloud management system. It deleted the environment and rebuilt it from scratch instead, causing a 13 hour outage on the Cost Explorer service in a mainland China region. Amazon called it an extremely limited event.
  2. March 2, 2026: AI-assisted code changes, including work involving Amazon Q Developer, contributed to a roughly six hour disruption on Amazon’s main retail site. The Financial Times and Business Insider later reported 120,000 lost orders and 1.6 million website errors.
  3. March 5, 2026: Three days later, a second and more severe outage hit the storefront. It also ran about six hours and produced a 99% drop in North American order volume, roughly 6.3 million lost orders.
  4. The response: Amazon launched a 90 day code safety reset covering 335 critical retail systems and now requires senior engineer sign off before junior and mid-level staff can ship AI-assisted code touching those systems.

Business Insider, reporting on internal Amazon documents, described the pattern as a trend of incidents with high blast radius tied to Gen-AI assisted changes, work for which the company’s own briefing notes admitted best practices were not yet fully established.

1,500 Amazon Engineers Signed a Petition

Governance conversations usually center on buyers and regulators. Amazon’s own engineers turned out to have real skin in the game too, and they said so.

Before the March outages, Amazon had already put an 80% weekly usage mandate on Kiro, requiring engineering teams to route most eligible coding work through the tool. By some accounts, roughly 1,500 employees signed an internal petition objecting to that mandate, arguing it pushed adoption faster than the safeguards around it could handle.

That timing matters. The pushback came from the people closest to the code, not from an outside auditor or a lost customer. It is the clearest evidence yet that the governance gap is not just a management or compliance problem. It is a workplace one too.

Veracode and Wiz Found the Same Pattern Elsewhere

These kinds of incidents will continue to happen with more frequency.

Nader Henein, a Gartner vice president analyst, offered that assessment as Amazon’s saga unfolded, and independent security research backs him up.

Veracode’s own research this year found that AI-generated code introduces OWASP-recognized vulnerabilities at a rate of roughly 45%, and that security debt now affects 82% of companies, up from 74% a year earlier. Separately, Wiz Research found that one in five organizations using AI-powered development platforms had applications exposed to systemic security issues, first identified in September 2025 and reaffirmed in the firm’s 2026 State of SDLC Security report.

Wiz grouped the exposure into four recurring patterns:

  • Client-side authentication that can be bypassed simply by editing JavaScript in the browser
  • Hardcoded secrets left sitting directly in generated source code
  • Insecure data access policies that expose records nobody meant to expose
  • Exposure of internal applications that were never supposed to face the public internet

None of those four require a novel attack technique. They are the same mistakes code review has caught for two decades, arriving faster now because fewer humans are looking at the output before it ships.

Why Does August 2 Matter for European Firms?

The EU AI Act’s high-risk system obligations are due to become enforceable on August 2, 2026, ten days from now, and they apply to any company whose AI touches people in the EU regardless of where that company is based.

The Cloud Security Alliance, a nonprofit research and standards body, notes that penalties for violations reach up to 15 million euros or 3% of global annual turnover, whichever is higher. A separate tier for prohibited practices, already enforceable since February 2025, carries fines up to 35 million euros or 7% of turnover.

A provisional EU agreement reached in May proposed pushing the Annex III high-risk deadline back to December 2027. But that extension had not been formally adopted as of the most recent reporting, and compliance advisors were still telling clients to treat August 2 as the operative date. For a European software business, that uncertainty is itself a governance problem, layered on top of obligations that already exist under DORA and NIS2, which turned vendor and third-party risk into a standing job rather than an annual checkbox, as detailed in recent coverage of Europe’s vendor risk rules. An AI system trained on ungoverned code is now one more thing that framework has to cover.

Building the Review Layer Before It’s Forced

Start by naming every stage where AI output enters the product. Most teams cannot list those stages accurately from memory, which is itself a sign of how far adoption has outrun oversight.

Amazon’s own fix, after millions of lost orders, was not more AI. It was a human signing off before code from a junior or mid-level engineer touched a critical system. That is a cheap rule to copy before a company is forced into it by an outage, a lost enterprise deal, or a regulator.

The productivity case for AI in software development is closed. Info-Tech’s numbers put that beyond argument. What is still open, ten days before a European deadline and five months after Amazon’s own reckoning, is which companies built a review layer on purpose and which ones are waiting for their own version of March 5.

Frequently Asked Questions

What is vibe coding?

Vibe coding means prompting an AI model to generate software and shipping the output with little or no human review of the underlying code. Security researchers use the term specifically to describe workflows where speed has replaced traditional code review.

Did Amazon ever confirm AI caused its 2026 outages?

No. Amazon publicly disputed a direct link, calling the December 2025 incident an “extremely limited event” and attributing it to user error. Internal documents described to reporters told a different story, referring to a “trend of incidents” tied to Gen-AI assisted changes.

Is Amazon’s 80% Kiro usage mandate still in place?

Yes, as of the most recent reporting. Amazon added mandatory senior sign off for junior and mid-level engineers after the March outages but kept the underlying requirement that eligible weekly coding work run through Kiro at least 80% of the time.

Does the EU AI Act apply to companies based outside the European Union?

Yes. The regulation binds any organization whose AI system output affects people inside the EU, regardless of where the company is headquartered, which means the August 2 high-risk deadline reaches well beyond European borders.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending