← All Posts
Personal Reflections

AI Motivation Strategies: Stick, Spark, and the AI-DLC

By James Carder · · 8 min read

AI Motivation Strategies: Stick, Spark, and the AI-DLC

The Stick, the Spark, and the AI-DLC, the motivating factors driving the win for AI and Software Development

The Motivating Factors Driving Success with AI and Software Development

There’s no shortage of software companies out there trying to push AI adoption, but the way they go about motivating their teams varies wildly and with it, the outcomes they achieve. The style of motivation a company chooses, and how leaders measure its success, reinforces not only the chosen approach but also the broader culture of software development within that organization.

The Stick

On one side of the spectrum, you’ve got companies using the stick approach. They lead with fear. They harp on how AI can replace developers and then double down on that fear by conducting layoffs, claiming it’s all about becoming “more efficient” and achieving better results with fewer people, thanks to AI. This turns AI into the digital boogeyman. These companies anchor their adoption metrics by looking at how many lines of code were generated by AI, reasoning that fewer lines means lower adoption (even though not every line of code is created equal and more lines don't often equate to better and/or more product) and while somewhat true, the response to that metric is often either terminating those with lower numbers of AI generated code or assuming that developers have the ability to flip a switch and move to AI development first and that they must not be because they are incapable, in fear, or just a non believer. But this fear driven strategy doesn’t just fail to inspire, it breeds resistance. Developers get spooked, worrying AI is out to snatch their jobs. This can create a downward spiral in company culture. Fear not only creates toxicity but ensures the very thing the organization hoped to achieve with AI slows to a crawl which can lead to the ultimate failure for the business if not corrected quickly.

The Spark

Then there are companies that take a different route, they use AI as a spark. They focus on inspiration and showing what’s possible. They look at "vibe coding" as a cool demonstration of the art of possible without scoffing that the outcome you produce is not a "real" product fit for production. They bring in AI enthusiasts who showcase the tech and its potential, demonstrating how easy it can be to achieve impactful results, even tackling back burnered ideas once shelved out of fear of the unknown. Sometimes all it takes is 5 minutes with someone to explore the art of possible and generate excitement that returns immediate results. The excitement becomes infectious. People are inspired to experiment, to explore, to innovate. This kind of motivation nurtures a culture curious about advancement and eager to discover how AI can create real, meaningful impact for the business and teams alike. Instead of counting machine generated lines of code, they measure what truly matters; outcomes, realized benefits, gains, team and individual satisfaction, and overall happiness (like a happiness quotient). Yes, AI can boost happiness! These companies don’t monitor every keystroke as if AI were the grim reaper looming in the corner, waiting to strike. They’re not turning AI into some paranoid game of Royal Kingdom; they’re turning it into a tool for maximizing already existing potential.

Ultimate Win, the AI-DLC

Then there are other companies that are taking it even a step further. They're turning the viewpoint of AI from being a tool that just helps developers write code, a co-pilot or assistant, and instead moving to an AI-DLC model putting AI in the driver seat, the pilot, taking ideas and driving those into requirements and design through coding, testing, securing, and generating an outcome. AI has become the driver of the race car while the human driver has turned into the crew chief or race team manager. They're no longer measuring the differences between lines of code written by AI and lines of code written by a human but doubling down on the positive and meaningful motivations we outlined earlier and focusing purely on the outcomes that are realized and the benefits of speed. The developers get measured on these outcomes with the inherent expectation that a developer will never have to write another line of code. The developer as we used to know it, is now the moderator, the overwatch, the supervisor, they all just got promoted to a software delivery manager without even knowing it.

The companies adopting the AI-DLC have thrown out the traditional SDLC models and Agile frameworks and almost taken a really mature, formalized, structured, context known, aware, and driven, "vibe coding" approach. Sure, they've kept some similar concepts and changed some wording but really it’s only to baby step folks from something familiar and engrained into something else just to ease the transition. If a Developer can say, "oh, this is called a bolt now but it’s basically just a faster sprint," it gives them an ability to relate and adapt.

As a part of moving to AI-DLC, the Engineering groups, the Developers, have also moved the preverbal bottleneck from Engineering to Product, a true shift left, and added pressure to Product to come up with even more great ideas that will generate meaningful business value (inception), faster, as the code and feature delivery gets turned around in hours instead of months. In turn, Product organizations get to focus on conducting "deep research" and then mostly generating ideas that the AI will then take and turn into consumable requirements documents, designs, sizing, organizing, and ultimately scheduling work to be done with the Engineering teams and their AI developers. The Product team becomes a "good idea factory," producing lightbulbs every hour, just to keep pace with Engineering's ability to deliver.

Security Wins Too with the AI-DLC!

For me, as a life long security advocate, the AI-DLC is probably one of the best things in the world, no offense to sliced bread. It is the first time in history that the product security function gets to REALLY win at the same pace as the developer. Instead of security being late to the innovation game (assuming security doesn't also fight it and is involved with the implementation and adoption of the AI-DLC from the beginning too) they get to adopt innovation at the same time as their developer colleagues. They get to shift security requirements, guardrails, rules, all the way to the left and prevent so many vulnerabilities from ever seeing the light of day. Then the ones that do get through the pipeline there is additional AI and AI processes that give you the capability to remediate the vulnerabilities in quick order, in nearly real time, automated, and done by the AI with a little bit of human over top. There is no longer the arduous work of trying to meet CISA recommended SLAs for remediating vulnerabilities (which I assume will also start to move left as the AI-DLC adoption and AI tooling become more engrained in our operation) and with the latest announcements about Anthropic Mythos and Project Glasswing, shifting remediation timelines to hours and days will be more than mandatory now. Not to mention, all the other client and other activities involved when you aren't meeting those SLAs and the level of explanation and oversight required. Then let's not speak to the incidents and events and breaches as this will have a massive, cascading, downstream impact. We talked about the happiness quotient with the developers earlier but imagine the life of the security practitioner!

One of the other pain points every software company and subsequently, product security teams, agonize over and deal with, relates to software composition and third party code that is outdated, systems and technology that haven't kept up and all things in urgent need of modernization. With the AI-DLC, modernizing software and technology is no longer a five year journey plan that never seems to get there. You get a chance to recreate the capability newly, in an extremely fast and fairly inexpensive way, wiping away years of vulnerabilities with every new line of code and outcome produced. That never ending story of backlogged vulnerabilities and issues related to outdated code often hidden behind your WAF or other technology, single points of protection failure, without a prayer of ever getting updated, without breaking your software, gets to make progress, sprint or bolt to the finish line, and win the race.

To Summarize

In the end, companies moving to an AI-DLC model can almost remove the human vs. AI game of Thunderdome as it creates space for both to work together successfully, as a team. There is a lot of up front work to get the AI-DLC going but it sure pays off in massive ways. For companies that are not yet ready to move to AI-DLC (good luck to you in the long run) and are still looking at AI as a tool to just help the developer write code, one approach we covered is rooted in positivity and inspiration, while the other clings to fear and negativity. The bottom line is that motivation matters no matter what approach you choose. One sets up an environment where natural, enthusiastic adoption thrives, while the other sparks resistance, wreaks havoc on culture, and drives away top talent. It’s never AI itself that’s the problem, it’s the intent, the strategy, and perception behind adopting it. As leaders, it’s on us to reinforce the right narrative through our choices, measurements, and actions.

If we truly want to leverage AI’s potential, keep pace in this ever-evolving tech world (hello Mythos), and empower our teams to rise above, we’ve got to approach AI adoption the right way. Stick, spark, or just bite the bullet on AI-DLC? The choice is ours...for now.

James Carder
Strategic Advisor for Cybersecurity · Cardiant Security
← More Posts