Ask any IT executive at a small or mid-sized company what their team’s biggest constraint is, and the answer is rarely talent or ambition.. it’s hours in the day. Small teams wear big hats: reviewing each other’s code, chasing down requirements, testing releases, patching vulnerabilities, all with a fraction of the headcount a large enterprise would throw at the same problems. So when AI tools promised to “save time,” company leaders had every reason to be skeptical. We sat down with two of our own software engineers, Azahra Andani and Gita Fitria, to find out what actually changed in their workflow.
The old grind: slow by design
Before AI became part of the daily toolkit, the most time-consuming parts of the job weren’t the glamorous ones. Azahra points to three in particular: reviewing colleagues’ pull requests, gathering technical requirements, and testing. None of these are creative work. They’re careful, repetitive, detail-heavy work, exactly the kind that eats a day without producing anything visibly new. For a small team, that’s hours that could have gone toward shipping features or closing security gaps instead.
Where AI actually moved the needle
The interesting part isn’t that AI made everything faster. It’s which things it made faster, and by how much. Azahra recalls the moment it clicked: “Cursor built me a mocked server in only minutes, compared to hours or even days to get similar-looking data as the real case. This helps a lot as we can test our implementation faster compared to actually hitting an API with real credentials.” That’s not a marginal improvement but a workflow that used to require real credentials, real coordination, and real risk, compressed into a task that takes minutes and touches nothing sensitive. For SMEs, where testing environments are often an afterthought, that kind of shortcut is exactly where AI earns its keep.
The bottleneck didn’t disappear, it moved
Here’s the part that gets missed in most AI hype cycles: speed didn’t remove the need for human judgment, it concentrated it. Azahra put it plainly: “I trust AI to handle everything, but I’m always at the final gate. The final seal of approval is always from me.” Gita takes the same stance from a different angle, treating AI strictly as a tool to drive rather than be driven by: “As a baseline, I don’t trust AI 100%, even AI providers claim that AI can make mistakes, and indeed most of the time it will hallucinate if the context is already maxed.” For companies without a dedicated QA or AppSec function to catch mistakes downstream, that final human checkpoint isn’t optional, it’s the whole safety net.
Garbage in, garbage out
Gita’s other observation cuts to the heart of why context matters more, not less, in an AI-accelerated workflow: “Always remember “Garbage IN, Garbage OUT”. AI will go further based on the context you put in, if you don’t give the correct or full context, AI can bring you a result that probably isn’t true.” The most capable models bring their own risk too: a tendency to overanalyze or over-engineer a problem if you don’t set clear limits when prompting. Azahra’s take on AI-written content echoes the same theme. People can usually tell when writing is AI-generated, because it over-explains in a way that isn’t natural, a reminder that AI output still needs a human editorial pass to feel credible.
Conclusion
The common thread across both interviews is this: AI didn’t eliminate the need for expert judgment in software and security workflows. It shifted teams from doing repetitive work to reviewing and directing AI’s output. That’s precisely the dynamic playing out in vulnerability management too. AI-powered scanning and AI pentesting can surface far more findings, far faster, than a small IT team ever could manually.. But more findings without prioritization just means more noise.
That’s why Autobahn Security’s platform is built around prioritizing your data by real hackability, not just raw volume, so your team’s “final gate” can be spent on the vulnerabilities that actually matter. If your IT or dev-ops team is feeling the AI-speed-versus-human-oversight tension firsthand, explore our full platform overview or get in touch to see how we help lean teams keep up without losing control.
About the team behind this guide
Gita Fitria is a Software Engineering Lead at Autobahn Security, where she has built her career over 5+ years, growing from Frontend Engineer to leading engineering across tenant management, scanning, and authentication systems. With 11+ years of experience spanning SaaS, cybersecurity, and enterprise platforms, she combines hands-on engineering with squad leadership, roadmap ownership, and process design.
Azahra Putri Andani is an Engineering Team Lead at Autobahn Security with over six years of full-stack development experience. After architecting the platform’s foundational authentication system, she now leads the integrations team to streamline and secure cross-platform connectivity.