Trust but Verify, How to Use AI in Engineering Without Breaking Security
Manage episode 524377726 series 2833920
Software is still eating the world, and AI is speeding up the clock. In this episode, Amir talks with Tariq Shaukat, co CEO at Sonar, about what it really takes for non tech companies to build like software companies, without breaking trust, security, or quality.
Tariq shares how leaders can treat AI like a serious capability, not a shiny add on, and why clean code, governance, and smart pricing models are becoming board level topics.
Key Takeaways
• “Every company is a software company” does not mean selling SaaS, it means software is now core to differentiation, even in legacy industries.
• The hardest shift is not tools, it is mindset: moving from slow, capital style planning to fast iteration, test, learn, and ship.
• AI works best when leaders stay educated and involved, outsourcing the whole strategy is a real risk.
• “Trust but verify” needs to be a default posture, especially for code generation, security, and compliance.
• Pricing will keep moving toward value aligned consumption models, not simple per seat formulas.
Timestamped Highlights
• 00:56 What Sonar does, and why clean code is really about security, reliability, and maintainability
• 05:36 The Tesla lesson: mechanics commoditize, software becomes the experience people buy
• 09:11 Culture plus education: why software capability cannot live in one silo
• 14:21 Cutting through AI hype with program discipline and a “trust but verify” mindset
• 18:23 Boards, governance, and setting an “acceptable use” policy for AI before something goes wrong
• 25:18 How software pricing changes in an AI world, and why Sonar prices by lines of code analyzed
A line worth saving:
“Define acceptable risk as opposed to no risk.”
Pro Tips you can steal
• Write down what you want AI to achieve, the steps to get there, and the metric you will use to verify outcomes.
• For code generation, scan and review before shipping, treat AI output like a draft, not a final answer.
• Set clear rules for what is allowed with AI inside the company, then iterate as you learn.
Call to Action
If you want more conversations like this on software leadership, AI governance, and building real impact, follow The Tech Trek and subscribe on your favorite podcast app. If someone on your team is wrestling with AI rollout or developer productivity, share this episode with them.
585 episodes