Dan Lorenc of Chainguard, founder and chief executive officer, joins Rebecca Knight and Paul Nashawaty at Chainguard Assemble 2026 to discuss the role of artificial intelligence and autonomous agents in software delivery and software supply chain security.
The conversation, produced as part of theCUBE Research coverage, explores agent-driven pull requests, the shift from hand-written code to AI-assisted code creation, continuous integration and continuous delivery readiness, open source maintenance and strategies for operationalizing secure high-velocity development.
Lorenc emphasizes the urgency of shifting security left into the build pipeline and prioritizing code trust over contributor identity. They recommend hardened minimal container images and comprehensive automated testing to reduce the attack surface as agents become more autonomous. Nashawaty highlights rapid adoption of AI in production and notes the prerequisite of confident CI/CD systems before enabling autonomous agent workflows. Recommended practical actions include generating comprehensive tests, slimming images and investing in change management.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Chainguard Assemble 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Chainguard Assemble 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Chainguard Assemble 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Chainguard Assemble 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Chainguard Assemble 2026
Please sign in with LinkedIn to continue to Chainguard Assemble 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Dan Lorenc, Chainguard
This interview at Chainguard Assemble 2026 examines securing the modern software supply chain and artificial intelligence-driven development. John Sapp of Texas Mutual Insurance Company appears on theCUBE Research with hosts Rebecca Knight and Paul Nashawaty. The conversation addresses the evolving role of the Chief Information Security Officer and approaches to modernizing the secure software development life cycle.
Sapp emphasizes that CISOs must enable secure, responsible AI adoption through governance, inventorying software components and embedding security by design. They recommend shifting security left, reducing developer remediation time and measuring return on investment for supply chain controls. Nashawaty highlights Chainguard as an emerging application security innovation that automates lifecycle visibility and helps organizations achieve near-zero Common Vulnerabilities and Exposures.
Topics covered include supply chain security, secure software development life cycle, AI-driven development, open source security, developer experience and strategies for measuring security ROI. The discussion provides practical guidance and strategic considerations for organizations balancing speed and security in modern software delivery.
Practice Lead and Principal AnalysttheCUBE Research
HOST
Rebecca Knight
HostSiliconANGLE Media
HOST
In this interview from Chainguard Assemble in New York City, Dan Lorenc, co-founder and chief executive officer of Chainguard, joins theCUBE's Rebecca Knight and theCUBE Research's Paul Nashawaty to discuss how the rapid shift to AI-powered code generation is transforming the trust equation in software development. Lorenc describes the industry's transition from "hand tools" to "power tools," where AI and autonomous agents are now producing more code than humans can review. At Chainguard itself, agents are already submitting more pull requests each week than ...Read more
exploreKeep Exploring
What do you mean by saying we're now in a "power tool era" where AI writes code, and what are the implications and risks of that shift?add
How are AI tools and autonomous agents changing software development workflows, and are agents now writing and deploying code autonomously?add
What are the trust, governance, and compliance challenges posed by increased automation and AI-generated code (agents communicating with agents) in software development, particularly in secure environments and under regulations like the EU Cyber Resilience Act?add
What would need to happen for Chainguard to become the center of gravity for AI-driven software development?add
>> Hello everyone and welcome back to theCUBE's coverage of Chainguard Assemble here in New York City on St. Patrick's Day. I'm your host, Rebecca Knight, alongside Paul Nashawaty, principal analyst at theCUBE. This is your second time here at Chainguard Assemble.
Paul Nashawaty
>> Yes, absolutely. This is a great event. I absolutely love this event because it shows the progression of what's happening in the security world and the impacts of developers. So it really is really cool stuff.
Rebecca Knight
>> Indeed. And well, we have the man, the myth, Dan Lorenc. He is the co-founder and CEO of Chainguard. Welcome, Dan.
Dan Lorenc
>> Thanks for having me and thanks for being at the event.
Rebecca Knight
>> Yeah. So you were just up on the main stage and it was one of the-
Dan Lorenc
>> ....
Rebecca Knight
>> most creative demos I've ever seen where you brought an actual power saw-
Dan Lorenc
>> I did....
Rebecca Knight
>> to illustrate this point that we are now in this power tool era where code had been written by hand, now it's being done by a power tool that is AI, which is fast and fun, but also very dangerous. Can you just lay the land for our viewers a little bit and talk about what you mean by that?
Dan Lorenc
>> Yeah. We've been taking our time. We've been writing code by hand for decades. That's how everyone has been doing this. There were no other tools. There was like the Stone Age before when people were doing punch cards and stuff like that, but then we got hand tools, and hand tools were great. They let you take time. They let you think through designs. They let you understand the code that you're working with. But now we handed the entire industry circular saws and they're having a lot of fun with it because yeah, the bottleneck now isn't your hands and the keyboard anymore. The bottleneck is how fast you can think. But you're making more code than you can look at. It's not all correct. But we're going to have to figure that out. And I think for this, the answer to a lot of this is more. We can't just use AI to write the code. We have to use AI to review the code and figure out how to build pipelines that let us do this securely and safely.
Paul Nashawaty
>> Dan, I absolutely love the keynote. It was awesome. You were spot on with some of the points that we were talking about with the adoption of code and AI. Our research and our 2025 research shows that as of August, 50% of production code was written with AI. As of November, December, we're seeing that code jump up to 70%, 70 to 90%. So you're absolutely spot on. I look at it like the 2025 was a year of experimentation, '26, year of implementation. So I think a couple of things you talked about is software should be built, not patched later. So moving the delivery, the responsibility of the code back into the build cycle and the CICD pipeline, that resonated well with me. What are your thoughts there?
Dan Lorenc
>> Yeah. The power tool era we're in right now, it's not going to last for very long, I don't think. You have those stats on code written with AI, and that's still people in the loop. Are you vibe coding right now?
Paul Nashawaty
>> Yeah.
Dan Lorenc
>> I see your laptops. Yeah. . You might have Claude Code running or something running on your laptop. I usually am when I have it open. But there's a new world we have to get into though, which is agents doing this stuff in the background and agents deploying it by themselves and that kind of thing. As of three weeks ago here at Chainguard, we finally got a lot of this stuff working. And every week now we have more code written by agents, not just AI. We've been at that 90% of people writing code with AI on their laptops and sending it up. We now have agents sending the pull requests themselves and people reviewing and clicking merge. We have more of that going in every week now than code written by people. And that's the only way we're really going to turn this kind of dangerous era of experimentation into production grade assembly line level software factories.
Rebecca Knight
>> But more to the point of the danger, you had Dan Gillespie up there, which I know that is a good colleague of yours from way back, talking about how with the bottleneck no longer being the human, it is the trust.
Dan Lorenc
>> Yeah.
Rebecca Knight
>> So where are organizations with that level of trust? Where are they today and where do you want them to be by the end of this?
Dan Lorenc
>> Yeah, I don't know if you were in the room, but we did like the show of hands thing of how many people are confident enough in their CI systems that when the checks are green, they can click merge and it'll go to production without breaking anything. That is a prerequisite for all of this. And it's not just a prerequisite for agents. The first book on CI and continuous integration was written 15 years ago. Everyone knows that if you get these things in place, developers can move faster. Now we have an army of super developers and they're going to go super fast too if we get these things in place. And so it's kind of those downstream systems that we have to build and rethink through and redesign and reimagine to turn that kind of increased velocity on code to increase roadmap velocity. That's been the biggest thing I hear when I talk to customers all the time of like, all my developers are writing a hundred times as much code, but that thing that was on the roadmap for Q3 is still in Q3. What is going on here? How do we make that make sense?
Paul Nashawaty
>> Yeah. Yeah. The software factories, as you touched on that, that the automation piece, I absolutely agree with it. It's the competitive advantage to move forward. It's really what we want to do, have agents talking to agents. Right now, I agree with you. There is still the accountability piece of the human in the loop saying, "Hey, we want to make sure..." Like you said, in that keynote, we saw the hands go up saying they're confident that trust is there. The thing that also needs to be taken into consideration, especially with new rules going into place like the EU CRA, you have the governance compliance and regulations. As you're starting to have individuals write code that may not know the underpinnings of the code, how is that being impacted, especially in the secure environment?
Dan Lorenc
>> Yeah. When we look at open source in particular too, open source has already faced a lot of these challenges. If you run a popular project, you've been getting pull requests from brand new GitHub accounts with the default avatar and a made up username. Can you tell if that's a person, a nation state attacker, a kid who's writing his first code on the internet for the first time, is going to take mentorship from you, or an agent? You can't tell. And we haven't been able to trust the contributor behind the code for years already. And open source has figured out ways to trust the code, not the source of the code. Things like the CRA have dabbled into putting maintenance burdens on open source maintainers and they've walked back a lot of those, thankfully. But it still means someone has to apply a level of trust to the code. Whether it's the person writing it or whether it's the company that takes that code under a license that sells, this code comes with no warranties or fitness for a purpose and putting it into a production system. I really liked what Dan Gillespie said. OpenAI, the bottleneck is not writing code anymore. The bottleneck is establishing trust and determining whether this code is safe and fit for purpose and are we willing to run it in our environment.
Rebecca Knight
>> So one of the harder problems you're trying to solve is helping organizations clean up their existing environments without having to tear everything down and start over. So for a company that has been shipping software for 10 years, what does that journey realistically look like?
Dan Lorenc
>> Yeah, it's around getting confidence in your change management process as a whole. When we start working with a customer, they have to migrate. They have to do a little bit of migration work to get on our product today. And we've done a lot to make that easy and we have new tools to make that easier. But a lot of the concern is still confidence changing anything. It's not even really the migration toil to move to our software. It's just nobody's touched this service in three years. The last person that deployed it might not even be here anymore. Every company kind of runs into these problems at scale, and we're going to have to press a button and we're going to have to change it and we're going to have to hope nothing breaks. Thankfully though, this is a solved problem. It just takes a lot of work. And for years, it's been the type of work engineers hate doing. No one likes writing tests. No one likes writing monitoring tools. No one likes checking these things in production, but agents don't care. They'll do all of this work for you. Before we make any change now with our agents, we first generate comprehensive tests, and the person can then review that set of tests and see if anything, in word form, if anything is missing. You're not reviewing hundreds of thousands of lines of boilerplate, you're reviewing which scenarios are tested and which scenarios are covered and helping the agent make sure it's thought through everything. And then once you have that baseline in place, then you can go and make changes. And once you can do that, once you can change your infrastructure confidently, then everything is easy.
Rebecca Knight
>> But what you're describing is a lot of technical changes, whereas change management in practice is a lot about changing mindsets, about and changing worker attitudes and approaches. How much are you working hand in glove with customers on that part of the leadership?
Dan Lorenc
>> I think about a year ago, I would say there was a lot more skepticism, right? A lot of people wanted to keep the stuff out of their environments or scared. Vibe coding is like a dirty word. You don't see much of that anymore. Everyone, since I would say December when model capabilities and tooling capabilities kind of crossed this threshold, now it's just this look of like, well, we have to do this. How are we going to do it? How are we going to do it as quickly as we need to? And yeah, how can we bring our organizations along for the ride? But there's not as much fear or skepticism or worry or doubt that this is the way we all have to go anymore. It's really changed, I would say, over the last 12 months. Are you seeing the same thing?
Paul Nashawaty
>> I am, absolutely. And when I look at it from the perspective of a year ago to now, the adoption rate was accelerated by 200%, right? The other thing I wanted to touch on was your support and your commitment to the open source community. That is something that's key because like you said, a lot of these challenges that organizations run into are solved in open source, but we also see, sometimes we see open source projects go end of life. That's a challenge sometimes. How do you kind of overcome some of those challenges?
Dan Lorenc
>> Yeah, it's just pure software engineering at the end of the day. And one of the books I've reread recently, and it's hilarious how right these people got this stuff, but it was Mythical Man-Month. When was that book written? Was it like the '70s? It's been around forever since the pre-history of software and they had all of these laws and rules for software development. One of them is that the easiest way to fix an issue in software is as far left as possible. The cost of fixing an error if it's in production is a hundred times larger and more expensive than fixing it in staging, which is more expensive than fixing it before you deploy to staging, which is more expensive than fixing it on your laptop before you've sent code up. The same applies to open source. If you're a company that's taking the vended open source components and running them in production and something like this happens, it's very hard for you because you're at the end of the supply chain to deal with and fix these issues when things go out of life. But the right way to do it is all the way upstream, back in that project. Open source comes with these freedoms, these guarantees that if something goes end of life, you still have the source code, you can maintain it yourself. And so that's the approach we're taking. We're not taking these end of life projects and trying to patch them at the end. We're working with projects to take them at that point and source code and continue maintaining them there because it's cheaper for us to do and then it's cheaper for all of the customers that rely on it.
Paul Nashawaty
>> Yeah. I like that approach. I like where you're going with that because as we saw at Coupe Con North America, we saw that the end of life for Ingress NGINX, that was something that kind of caught the community by surprise. You actually have a solution around that as well.
Dan Lorenc
>> Yeah. The same factory and infrastructure and automation we have to build and release all open source software, we just plugged that project into it. It's still available in source code format. The maintainers have decided to shut it down because there are a lot of alternatives now that are available, but we can just plug that into the factory and all of the automation we have and continue maintaining it for our customers. And because we're doing it at that source code level, because we've invested in all that infrastructure, we can do it for relatively cheap and save people tons of time. We're talking to one large financial services organization. They have hundreds of development teams that had to drop their roadmaps for the next three quarters to plan a migration off of that as soon as those maintainers announced it as end of life. This is costly for people depending on it, but the open source maintainers own them nothing. They don't owe continued migration, continued maintenance here. Those companies need to find a path off eventually, and enterprises can do that. They can plan on longer time horizons and they can execute. But what's really disruptive is a surprise to that whole roadmap because all these roadmaps are intertwined and one delay here means hundreds of other countless projects are delayed. So really excited we're able to work with the open source community and companies to help them do this on their own timelines.
Rebecca Knight
>> So last year at this time, this is a company that was founded in 2021. So you're a baby company, a toddler company.
Dan Lorenc
>> We're four and a half years old now.
Rebecca Knight
>> Okay. All right, getting there. Last year at this time, 150 customers. Right now, 480, a really impressive growth trajectory. And you're essentially saying that Chainguard needs to become the center of gravity for AI-driven software development, which is an ambitious position. What needs to happen in order for that to actually occur?
Dan Lorenc
>> Yeah, I think we kind of have to be, because we sit at the intersection of all of the code that's being now written with AI by other strangers on the internet, brought into organizations for their developers to then take AI and put their code on top and get their production. We're kind of forced into this spot where we're at the center here of the way open source projects ship code and the way our customers ship code. And we operate in a part of the stack that requires a lot of trust, right? We are the core fundamental piece of a supply chain every organization is bringing in to build our infrastructure on top of. So we have to solve this velocity security problem. We have to be able to move fast and tackle the whole scale of open source without compromising on the trust that our customers rely on us for. And we've spent a long time doing that this year, and I think we finally started to figure some things out.
Paul Nashawaty
>> Well, I think that adoption is actually very interesting. I think a lot of it has to do with the fact that you have introduced ways in the CSED pipeline that really help accelerate. Like for example, hardened images and reduce of the attack space. That was something that was addressed in the keynote, right? When you look at the fewer packages, fewer CVEs and what that means to the delivery cycle, it actually helps with acceleration, but also builds the trust, right? And that's the piece I think is important to note as well.
Dan Lorenc
>> Yeah. Yeah. Those kind of hardened images play a really critical role here with the future of agents too. Autonomous agents are now putting non-deterministic... I don't want to say sentient, but non-deterministic, almost sentient actors running inside of your production environment. It's a very different security challenge from what we've dealt with before. You can place code and production. You know what that code does. It's deterministic. You know with this input, it's going to do that output. Now we're placing in things that are going to do different things with every input. Prompt injection is still terrifying. And the only real way to do this safely is to reduce the attack surface. If the tool isn't there, an agent can't call it. That kind of technique of slimming, hardening, all of these best practices we already knew we should be doing are now even more important with the randomness and chaos agents are injecting to our infrastructure.
Rebecca Knight
>> So you're talking about very scary things on one hand, and yet you are very much a tech optimist. Your talk up there was very positive. So I'm curious, at this time where AI is really reshaping how software gets built from the ground up, where we are in that transition and what the industry is underestimating right now, maybe dangerously underestimating, but where you hope it will go from there.
Dan Lorenc
>> Yeah. I think an AI is probably the best business model anyone has ever invented because it is the cause of and solution to all of the problems we're facing now. AI is giving us more. It's turning tons of systems up to 11. And the only possible way to keep up with it is to sprinkle more AI on all of the other systems that are kind of falling apart. I'm in a very good mood today, you're right. Yeah, but it swings. There are some days I'm terrified. I think one of the scariest things the industry has to eventually figure out is the whole prompt injection piece we just talked about. If that's fundamentally unsolvable, then it's going to be very hard to get value out of these agents.
Paul Nashawaty
>> Well, I'll add one piece to that, because I think that this does matter. I'm going to quote you, quote the keynote, "Security should not slow down developers," right? So making security invisible to developers, that helps with the overcoming the prompt injection issues. And that piece I think is important to note because the more that's pushed on the developer, the more that they have the responsibility of delivering. And that's where it gets a little scary because they're overtaxed, right?
Dan Lorenc
>> Yeah.
Paul Nashawaty
>> So I think that's a big factor to point out.
Dan Lorenc
>> Yeah. That's one of the ones we really do have to grapple with as an industry and figure out the prompt ingestion piece because for agents to have value, they have to be able to take action and do things and talk to external systems and send WhatsApp messages like OpenClaw is doing, and book hotel reservations. But if this piece is unsolvable, then if you apply principle of least privilege, an agent can only take action with the security context of the least trusted data coming into it, that's going to kill a lot of the velocity gains that agents are going to get and give to us. And human in the loop works to a point. Operator fatigue sets in. If you've got a person whose whole job is to click approve on agents forever, are they going to catch the time it did go rogue? We've studied this for years and it's a hard problem to solve. So I think that piece is going to be key to really unlocking agents for everyone. Everything else we can just sprinkle more on, but that's kind of this fundamental one that keeps me up at night.
Rebecca Knight
>> Excellent. Well, Dan Lorenc, pleasure having you on the show. I really appreciate it. Good luck. Congratulations.
Dan Lorenc
>> Yeah, thanks for joining us. And I'm glad the weather finally turned around. This was a pretty terrible couple days in New York.
Rebecca Knight
>> But it's chilly out there. It's pretty chilly out there.
Dan Lorenc
>> But yeah, at least the sun's out.
Rebecca Knight
>> Exactly. I'm Rebecca Knight for Paul Nashawaty. Stay tuned for more of theCUBE's coverage of Chainguard Assemble. You're watching theCUBE, the leader in enterprise tech news and analysis.