Google deploys agentic pre-submit scanning across millions of lines of infra code — 92% precision, 3% false positives
dl_weekly · x · 2026-09-30
A Google Cloud blog post by Distinguished Engineer Andrés Lagar-Cavilla and VP Parthasarathy Ranganathan details Google's AI-native infrastructure security system:
- Pre-submit agentic scanning: instead of slow, context-starved one-off scans, AI agents evaluate every code check-in in real time, integrated into developers' existing tools like linters or readability reviews
- Scale and results: every change across hundreds of millions of lines of infrastructure code is scanned; hundreds of vulnerabilities per month are blocked before reaching production
- Triage agent performance: 92% precision with only 3% false positives
- The motivation: AI-accelerated code generation brings new AI-based vulnerability exploits, so security must be systematically embedded in the SDLC
More from coding & agent
- Hillel Wayne: TLA+ is great, but 'formal methods will save AI' hype misses what it can't even express — leland_mcinnes · 2026-09-30
- Decision model Jev makes web agents 4.3x faster and 13x cheaper across 240 runs — EdenEmarco177 · 2026-09-30
- Coinbase CEO unveils financial accounts built for AI agents and superintelligence — J0se · 2026-09-30
- Dev insight: AI's real change isn't speed, it's that momentum stops leaking — dfinke · 2026-09-30
- What actually breaks when LLM features meet real users, from production experience — Early-Sir-932 · 2026-09-30
- After 18 months building a CRM, Operate relaunches as an AI-native sales tool with durable agents — soleio · 2026-09-30