Harness CEO Jyoti Bansal on Why AI Coding Doesn't Help You Ship Faster

By The New Stack

Share:

Key Concepts

  • Inner Loop vs. Outer Loop of Software Engineering: Distinction between code writing (inner loop) and code delivery to production (outer loop).
  • Continuous Delivery (CD): Automating the release of software changes to production.
  • Continuous Integration (CI): Automating the process of integrating code changes from multiple contributors into a single software project.
  • Test Intelligence: An AI model used to optimize CI builds by running only necessary tests based on code changes.
  • Generative AI (GenAI): AI capable of generating new content, including code and text.
  • Large Language Models (LLMs): A type of GenAI specifically designed to understand and generate human language.
  • Agentic AI / AI Agents: Autonomous or semi-autonomous AI programs designed to perform specific tasks or workflows.
  • Harness AI: Harness's unified platform for AI agents, designed to streamline software delivery.
  • SDLC Knowledge Graph: A customer-specific knowledge base created by Harness to provide context to AI agents, detailing infrastructure, service dependencies, environments, and policies.
  • Code Property Graph: A technology used by Quieti (now part of Harness) to analyze code for exploitability and reachability of vulnerabilities.
  • Code Exploitability / Code Reachability: Determining if a vulnerability can be triggered and if the vulnerable code path is accessible in a given application.
  • Multi-Cloud Platform (MCP): A flexible integration layer, described as the "new API" for connecting AI systems and workflows.
  • Internal Developer Platform (IDP): A self-service platform for developers, often built on tools like Backstage, to streamline development workflows.
  • FinOps: A practice that brings financial accountability to the variable spend of cloud, enabling organizations to make business trade-offs.
  • SRE (Site Reliability Engineering): A discipline that applies software engineering principles to infrastructure and operations problems.
  • Consumption-Based Pricing: A business model where customers pay based on their usage of a service or product, rather than fixed subscriptions or seats.
  • AI Augmentation vs. Replacement: The debate on whether AI enhances human capabilities or replaces human jobs.
  • Vertical AI Solutions: AI applications tailored for specific industries or domains (e.g., healthcare, finance, manufacturing).
  • Unusual Ventures: A venture capital firm co-founded by Yoti Bansal, focusing on early-stage investments.

Harness's Early AI Foundation and Evolution

Yoti Bansal, founder of AppDynamics and Harness, discussed Harness's long-standing commitment to AI in software delivery. Harness, launched out of stealth in 2017, prominently featured "artificial intelligence to continuous delivery" in its press release. This early AI was primarily based on neural networks and machine learning (ML), not Large Language Models (LLMs), and was crucial for verifying if deployments would cause issues.

By 2020, Harness extended its AI capabilities to Continuous Integration (CI) with an AI model called Test Intelligence. This model analyzes code changes to determine which tests are necessary, significantly speeding up builds by 4x to 5x by avoiding unnecessary test runs. Bansal emphasized that AI's utility in software engineering predates the current LLM boom, though LLMs have created a "100x thousandx turbocharged environment." He stressed that the goal is to solve problems effectively, sometimes with deterministic automation (e.g., 1 second) rather than AI (e.g., 30 seconds) if speed is critical.

The Software Delivery "Outer Loop" and Generative AI Integration

Bansal highlighted the distinction between the "inner loop" of software engineering (developers writing code, accounting for 30-40% of time) and the "outer loop" (the delivery process to production, consuming 60-70% of time). The outer loop is complex, involving 30-35 workflows such as various testing types (integration, load, API), security tasks (code security, vulnerability scans, open-source checks, API security), compliance approvals, deployments (feature flags, database changes, infrastructure as code, canary/blue-green deployments, rollbacks, artifact management), and cost optimization (FinOps).

Harness's core mission is to streamline this outer loop, reduce developer toil, and automate these workflows. The platform offers 16 different modules to address these challenges. When Generative AI (GenAI) emerged, Harness initially focused on using LLMs to simplify configuration (e.g., creating pipelines) and fix security vulnerabilities.

Harness's Agentic AI Framework

Harness has evolved its approach to leverage agentic AI, building a library of interconnected AI agents called Harness AI. This framework includes top-layer agents for broad tasks like DevOps, SRE, Testing, FinOps, and Security. Underneath these are numerous purpose-built sub-agents designed for smaller, specific tasks. For example, creating a deployment pipeline might involve 30 different sub-tasks, each handled by a specialized agent.

These agents are powered by a customer-specific SDLC Knowledge Graph, which provides context about the customer's infrastructure, service dependencies, environments, security tools, and SLAs. This contextual information allows agents to perform tasks with high relevance and accuracy. The architecture emphasizes breaking down large problems into smaller, context-rich tasks for individual agents.

Customer Adoption and Trust in AI Agents

A critical aspect of AI agent adoption is trust. Harness's agents are designed to create production deployment pipelines, not to directly deploy to production. These pipelines are deterministic, auditable, and subject to human review for compliance and security. This "human-in-the-loop" approach ensures comfort and control, especially for highly regulated industries like banking.

Bansal contrasted AI for code generation, where 95-99% accuracy might be acceptable, with AI for code delivery, where there is zero room for error. He cited the CrowdStrike outage as an example of how "one line of bug can bring the world down," underscoring the need for determinism and rigorous checks in production environments. AI's role in delivery is to assist in pipeline creation and troubleshoot issues, reducing the burden on developers.

Prioritization of AI Agent Development

Harness prioritizes AI agent development based on the most critical and complex tasks in software delivery:

  1. Setting up Pipelines: Automating the creation of complex, fully automated CI/CD pipelines, especially for large enterprises with specific policies, security controls, and governance checks.
  2. Testing: Helping developers keep pace with testing requirements for the increasing volume of code. While unit testing is easier, agents focus on more complex areas like end-to-end, resiliency, and chaos testing.
  3. Security: Addressing the pain points of managing security vulnerabilities. This includes prioritizing, automatically fixing, detecting, and determining the "reachability" and "exploitability" of vulnerabilities, as many reported vulnerabilities are not real or relevant to the actual code paths used.

Strategic Acquisition: Quieti (formerly ShiftLeft)

To address the challenge of security vulnerability management, Harness acquired Quieti (formerly ShiftLeft). The acquisition was driven by the need to manage the overwhelming "noise" from security scanners, which often report vulnerabilities in unused features of open-source libraries. Quieti's technology, the Code Property Graph, excels at analyzing code for exploitability and reachability, helping to prioritize and focus on actual threats. This technology is now integrated into Harness AI to automatically detect, prioritize, and fix critical vulnerabilities.

User Experience and Internal Transformation

Harness users interact with a unified "Harness AI" interface, similar to ChatGPT, rather than individual agents. The system learns user behavior and suggests common tasks (e.g., production deployment pipelines, cost optimization), making the experience intuitive. Harness is also launching capabilities for users to create their own autonomous agents for specific tasks, such as upgrading a codebase library version and ensuring all tests pass. This involves the agents directly interacting with and modifying code.

Internally, Harness had an advantage due to its early focus on AI/ML since 2017, possessing strong data infrastructure and talent. Bansal noted that most engineers can learn to write agents, and the company's engineering culture has transformed into an "AI-first thinking" approach. Harness does not build foundational models but leverages existing ones from providers like Anthropic, OpenAI, and Gemini, focusing instead on deep domain expertise in software delivery and building purpose-built agents with rich context.

Business Model and Customer Insights

Harness's business model was already consumption-based (e.g., based on services deployed, cloud cost optimized), not seat-based. AI capabilities are included in the consumption pricing of modules, rather than being charged separately. This decision was made to encourage a single, AI-native user experience and avoid the complexity of maintaining separate AI and non-AI versions of the product.

A surprising observation has been the rapid and high adoption of AI integration by customers, even in large, traditionally slow-moving enterprises. Many customers are using Harness's Multi-Cloud Platform (MCP) server, described as the "new API," to integrate AI into their internal toolchains and build their own AI systems. This rapid uptake stems from the realization that while AI for coding increases code generation, it doesn't inherently speed up shipping; the bottleneck remains in the delivery process (testing, deployment, security, compliance). Harness also offers an Internal Developer Platform (IDP) module built on Backstage, enhanced with a "knowledge agent" to answer questions about services and automate onboarding workflows.

Internal AI Usage and Productivity

At Harness, almost every developer uses AI tools (e.g., CloudP, Cursor, Windsurf), with an estimated 40%+ of code being written through AI. Best practices for effective AI use include:

  1. Configuring tools and setting parameters: Providing clear rules and desired output patterns to the AI.
  2. Breaking down tasks: Decomposing large tasks into smaller, manageable units for AI to handle effectively.
  3. Reviewing AI-generated work: Critically evaluating the output.

Bansal personally uses AI extensively for product management and writing specifications, reducing the time to create detailed specs from weeks to about an hour. He views AI as an augmenting force, increasing velocity and enabling more work to be done, rather than primarily replacing human labor. The competitive pressure and pace of innovation have significantly increased, shrinking timelines for product development and market changes.

Investment Landscape and the AI "Bubble"

As a co-founder of Unusual Ventures, an early-stage venture firm, Bansal noted that 100% of investment pitches now include an AI element. The firm is actively investing in AI infrastructure and vertical AI solutions tailored for specific industries like healthcare, finance, and manufacturing.

Regarding the notion of an AI "bubble," Bansal acknowledged that all areas of AI are currently "bubbly." However, he suggested that a bubble isn't necessarily negative for disruptive technologies. Like the internet dot-com bubble, while expectations might be accelerated (e.g., 1 to 100 in 2 years instead of 5), the underlying impact of the technology is real. He anticipates that out of many startups trying to solve similar problems (e.g., 20 companies), only a few (3-5) will succeed, leading to a natural consolidation and the emergence of significant winners, alongside adaptation by incumbents.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video