Skip to content
Security & Trust Talking point

AI-built apps may be easier to secure if agents edit a model, not raw code

An OutSystems CEO argues a shared model lets apps inherit security rules and lets one patch fix many systems.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
AI-built apps may be easier to secure if agents edit a model, not raw code
In brief
  • Woodson Martin of OutSystems argued that AI agents should edit an abstract model of an app, not raw code, so security rules carry into everything built.
  • He said shared building blocks let a vulnerability be fixed once, while hundreds of separate AI-built systems make it hard even to find the flaw.

Woodson Martin, CEO of OutSystems, argued that the safer way to multiply AI-built software is to let agents edit an abstract model of an app instead of raw code. He made the case on The Cognitive Revolution, in an episode published on October 7, 2026. His claim is that security rules carry over automatically, and that one fix can reach many systems.

What was said

Martin described a layer that sits between the AI and the finished code. It holds an abstract picture of what the app should do. Any coding agent, such as Claude Code or Codex, changes that model. It does not touch the code directly.

The platform then generates the code in a fixed, repeatable way. Security and role-based access controls are built in at the platform level, he said. They also reuse parts the company already approved, so teams do not repeat compliance work for rules like GDPR or HIPAA. In his words, a team building this way is "inheriting every piece of your enterprise control plane, if you will, in every code asset that gets generated."

He then turned to fixing flaws. With a portfolio built on shared primitives, meaning common building blocks, he said response is much easier. The alternative is hundreds of AI-built systems, each on its own frameworks and open-source parts. There, a team facing a new vulnerability struggles even to learn where it is. Martin called that "Wild West AI builds all the things." With reused components, he said, a fix can be made once and have broad impact.

Why it matters

Our reading: the question for anyone buying or approving AI-built software is wider than whether the code works. It also covers how fast you can find and fix a flaw after launch. Martin said the speed of cyber threats is rising, so response time is part of the risk.

That points to practical questions. Do new AI-built apps start from shared, already-approved parts, or from scratch? Could you list every system affected by one vulnerable component? If not, each extra AI-built app adds to the number of places you must search.

The other side

Martin runs a company that sells this approach, so his argument is also a sales case. The excerpts give no figures on how often such systems fail. The host asked about breakage in the era of vibe coding, but the excerpts show no numbers in reply.

Martin himself offered limits. He said security has no finish line, because technology that helps defenders also helps attackers. He called the idea of perfect security a pipe dream. He noted that many large firms still run decades-old systems, such as COBOL and Lotus Notes.

The show notes also mention securing shared primitives as a practical challenge. The excerpts do not say how that works. A fix made once helps everywhere, but a flaw in a shared part would also sit everywhere. That question stays open.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight