Jimmy Malhan: How to Lead With Clarity When Your Teams Are Still Figuring Out AI

AI adoption is moving faster than most companies can write policies for it. Engineers are already using ChatGPT, Claude, Copilot, and other tools to write code and accelerate development. The challenge for leaders is how to make that adoption secure. For Jimmy Malhan, Founder and Chief Executive Officer of Pretense, the answer is to make responsible AI use easier than working around the rules. “The rules it needs to stick mean it has to be a convenient option for an engineer as they write code, and it needs to be safe and provide audit trails,” he says.

Shadow AI Is a Leadership Problem, Not Just a Security Problem

The rise of shadow AI has exposed a gap between how organizations think employees work and how they actually work. Engineers under pressure to move quickly will find tools that make them more efficient, particularly when official alternatives are slower or more restrictive. Malhan saw this dynamic firsthand while working with engineering teams at large companies. Even when employees understood the rules, they looked for workarounds because efficiency remained a priority. Traditional firewalls and restrictive policies could not fully address the problem because AI tools introduced a different path for data to leave the organization.

That creates a difficult situation for security teams. Source code, customer information, credentials, and other sensitive material can be entered into an AI prompt through a browser without passing through the traditional controls designed to monitor email or file transfers. “What left the building” becomes difficult to answer, especially when there is no audit trail showing what data was sent to an AI model.

Security Has to Follow the Data

For Malhan, source code deserves particular attention because it often contains the keys to an organization’s most sensitive information. “The source of truth of every database of every customer’s data” can ultimately sit within the codebase, he says. Protecting that code, therefore, means protecting far more than intellectual property. It can also mean protecting customer data, credentials and the systems connected to them.

This changes the conversation around AI governance. Security teams need to know not only which AI tools employees are using, but what information is being sent to them and whether there is evidence to demonstrate that appropriate controls are in place. That evidence matters when organizations face frameworks such as SOC 2, HIPAA, GDPR or PCI-DSS. Compliance cannot simply be an assertion that an environment is secure. Leaders need an audit trail that shows what happened.

Guardrails Should Be Invisible to Engineers

The most effective AI guardrails may be the ones engineers barely notice. Malhan argues that security controls should work within existing developer workflows, rather than forcing teams to abandon the tools that make them productive. Pretense, for example, operates on the laptop before sensitive information reaches an AI tool, replacing real data with realistic stand-ins and restoring the original values in the response.

The principle is straightforward: developers should be able to keep using the tools that help them move quickly, while organizations gain greater security visibility. “They would never know that the rule even exists,” Malhan says, describing the ideal experience for engineers. The goal is not to make developers think about security every time they use AI. It is to build security into the workflow itself.

AI Agents Raise the Stakes

The challenge becomes even more significant as AI agents move from assisting developers to writing and shipping software themselves. Malhan describes this shift as a new model in which “the developer itself has become a manager of a set of agents.” Developers can become dramatically more productive, but that increased capability also makes clarity around security and compliance more important.

For early-stage companies in particular, this creates an opportunity to establish good practices before technical debt and compliance gaps become harder to unwind. Rather than treating compliance as something that arrives once a company reaches scale, it can become part of the product development process from the beginning. Malhan describes the ideal approach as “set it and forget it”: establish the right controls once, then allow them to operate quietly in the background.

The next stage of AI adoption is less about figuring out what the technology can do and more about ensuring the systems built with it remain secure. As AI becomes embedded in software development, the companies that navigate the transition successfully will be the ones that understand how their teams actually work and build guardrails around that reality. 

Follow Jimmy Malhan on LinkedIn or visit his website.

You May Also Like