Software development has emerged as the killer use case for generative AI today, with half of all tokens consumed on OpenRouter being used for code generation. Cursor, for example, has ramped from $100M to $4B of ARR in the last 12 months. We’re in the first innings of the biggest shift in the history of software development: from humans manually writing code to swarms of long-running AI agents autonomously building software. The software-development lifecycle is being completely redefined, with new primitives and processes being built in real-time to match the pace of agentic code velocity.
The traditional SDLC had a natural, built-in bottleneck in the “build” phase where humans wrote code by hand. This process of writing out code manually acted as a rate limiter on the rest of the SDLC process, allowing sufficient time for other functions, both upstream (planning) and downstream (testing, security, CI/CD, storage) of code generation.
Because coding agents build code in a fraction of the time humans can, the rest of the SDLC – planning, testing, security, code storage – is fraying at the seams, trying to operate at a pace that existing infrastructure and workflows weren’t built for.
We see a new agentic SDLC being built with many of the same elements as the old SDLC, but reimagined for the era of agentic coding. We’ve spoken to engineering leaders at startups and enterprises alike, as well as the founders building the next generation of dev-tooling. Based on these conversations, we’ve broken down how each part of the SDLC is being reshaped.

1. Planning & Triaging – The Always-On Product Manager
The first step of building software is figuring out what to build and why to build it. As the cost of writing code approaches zero with AI, we are seeing firsthand the consequence of poor prioritization and planning. “AI slop” has proliferated, with poorly scoped products and features being pushed to production. SaaS menu bars look like Cheesecake Factory menus, confusing users who can’t keep up with the barrage of new products they didn’t need or ask for. New iOS apps are up 60% Y/Y, but overall app downloads are down, showing that more options don’t necessarily mean increased engagement.
A new class of companies like Linear, Modem, and Intent Lab are building tools to help product and engineering teams plan at the pace of AI. These tools help teams manage context, gather and triage customer feedback, and scope roadmaps so the right features get shipped. Once priorities are set, they help translate that into specs and context coding agents can use to build exactly what was intended.
2. Build, Review and Test – Software Factories
At the core of the agentic SDLC are coding agents writing new code. The category has evolved quickly, from “copilots” and “pair-programming” tools like GitHub Copilot to Cursor’s autocomplete Tab model to, now, fully autonomous coding agents such as Claude Code, Cursor, Cognition, Factory and Blitzy* that can build end-to-end features without a human having to write a single line of code.
Downstream of the code generation itself is code review and testing. When junior engineers can write thousands of lines of code a day with the help of their coding agent, it becomes nearly impossible for senior review or testing teams to effectively review and test all the code manually. We are seeing new specialized tools emerge to handle code review and testing with AI, but we’re also seeing coding agents like Cursor and Cognition build code review and testing into their agentic loop or broader platform. Many enterprises we’ve spoken to are wary about AI reviewing AI, but they see no other option to handle the volume of code being written by coding agents.
While today, many of these fully autonomous coding agents are being used for “brownfield” code refactoring, migrating legacy code to more modern languages, as foundation models and agent harnesses improve, we believe these agents will increasingly be used for “greenfield” new code development as well, becoming part of vendor-neutral software factories that marry upstream context with the best coding agents for a given job. We’re already seeing this take place in forward-thinking enterprises like Ramp, Stripe and Coinbase, who have each developed their own internal fully autonomous software factories.
3. Security – Securing the Codebase
The increased volume of code being generated by AI today increases the attack surface area for codebases. At the same time, bad actors are now armed with powerful AI models they can use to find vulnerabilities faster than defenders can patch them. Anthropic’s Mythos model has reportedly found thousands of vulnerabilities in the core operating systems and web browsers powering the internet today, and open-source software packages are under siege with new supply-chain attacks seemingly every other week. Vulnerability management, supply-chain security and penetration testing are high level, P0 priorities for engineering and security leaders we speak to.
We’re coming to the point where “AI reviewing AI” stops being an uncomfortable compromise and becomes the only workable answer. Humans were already the bottleneck in security review before agentic coding arrived, so this isn’t a new problem, just a much more urgent version of an old one. Newer types of AI-native tooling are emerging to help security teams defend against attacks. Tools like DepthFirst, Socket, Tenzai* and Corridor are enabling CISOs to secure their codebases proactively, and we believe that agentic security tools will become a core part of securing code moving forward.
4. CI/CD & Sandboxes – New Build Pipelines for Agents
Existing build pipelines are struggling to keep pace with agent-driven code volume, pushing teams toward next-gen, continuous integration pipelines built for the velocity of agentic coding.
Sandboxes have emerged as an essential part of the CI/CD process for agentic coding, providing coding agents with an environment to build and test the code that they are writing. These sandboxes enable state and isolation of code, enabling long-running agents to build over long time horizons without damaging the production codebase with hallucinations or exposing security vulnerabilities The rapid rise of sandbox solutions like Modal, Daytona, E2B, Starfolk and exe.dev reflects how central this layer has become to the agentic SDLC.
5. Code Storage – Next Gen Version Control for Agentic Velocity
GitHub’s infrastructure was designed around human code velocity, not agentic code velocity. The platform’s recommended limit, a maximum of 6 commits per minute per repository, is more than sufficient when humans are writing code, but nowhere close to the volume of code AI agents are writing across the most AI-native organizations. As a result, GitHub outages have become a more frequent aspect of life in 2026, with several major incidents leaving developers scrambling for alternatives solutions.
New solutions such as Code Storage from the Pierre Computer Company, East River Source Control and Origin from Cursor are attempting to build code-storage primitives that are compatible with coding agent velocity. We believe these code-storage solutions will expand into sandboxing solutions to own CI/CD, following the GitHub and GitHub Actions model of owning both storage and the pipelines around it. AI-native organizations such as Lovable are already moving from GitHub to these new solutions, a trend we expect to continue as the pace of code velocity increases across organizations.
We are still extremely early in the shift to AI Coding. In our recent survey of enterprise technology leaders, most said they are still using GitHub Copilot for agentic coding and most code is still written by hand. As agentic coding diffuses through the enterprise, we expect this new agentic SDLC will become increasingly important, representing a generational opportunity for dev-tool founders during a platform shift. If you are building in this new agentic SDLC, we’d love to hear from you!
The information contained here is based solely on the opinions of Abhi Agrawal, Sudhee Chilappagari, Danel Dayan, and Jason Mendel and nothing should be construed as investment advice. This material is provided for informational purposes, and it is not, and may not be relied on in any manner as legal, tax or investment advice or as an offer to sell or a solicitation of an offer to buy an interest in any fund or investment vehicle managed by Battery Ventures or any other Battery entity.
Diese Informationen umfassen Investment- und Marktaktivitäten, Branchen- oder Sektortrends oder andere allgemeine Wirtschafts- oder Marktbedingungen und dienen zu Bildungszwecken. Die anekdotischen Beispiele sind für ein Publikum von Unternehmer*innen gedacht, die ihre Unternehmen aufbauen möchten, und sind keine Empfehlungen oder Befürwortungen für ein bestimmtes Unternehmen.
*Bezeichnet Battery Portfolio Eine vollständige Liste aller Battery finden Sie unter Bitte klicken Sie hier.
Ein monatlicher Newsletter zum Austausch neuer Ideen, Erkenntnisse und Einführungen, um Unternehmer*innen beim Ausbau ihres Geschäfts zu helfen.

