Skip to main content
Join Adaptavist and The Adaptavist Group at Team '26 in Amsterdam | 6-8 October
Read more
Harness Unscripted London 2026: AI-speed software delivery
Share on socials

Harness Unscripted London 2026: keeping up with AI-speed software delivery

Image of Paul Cavanagh
Paul Cavanagh
Published on 1 October 2026
Last updated on 30 September 2026
7 min read
Image of the Harness Unscripted event: The AI software delivery conference 2026
Image of Paul Cavanagh
Paul Cavanagh
Published on 1 October 2026
Last updated on 30 September 2026
7 min read
Jump to section
The bottleneck has moved
Governing at machine speed
From CI/CD to a set of agents
Context, Worker Agents and a dial for autonomy
Security at the same pace
Testing AI agents is different
Two early previews
From token spend to unit economics
What this means for your organisation

A recap of the Harness Unscripted keynote in London, what it said about moving AI-generated software safely into production, and where Adaptavist can help.

Harness Unscripted came to London on 24 September, with Jyoti Bansal, Harness’s CEO and co-founder, delivering the keynote. Adaptavist's Field CTO, Paul Cavanagh, also joined a panel on DevSecOps at AI speed. The message running through the day was simple: AI has made writing software much faster, and the harder problem is now getting that software into production safely, securely and at a cost that makes sense.

The bottleneck has moved

Coding assistants can create code quickly, but teams still have to build, review, test, secure, approve, deploy and run it. Harness cited research showing a 180% increase in code volume alongside a 30% increase in software shipped. These are Harness-cited figures rather than independent benchmarks, but the direction is easy to recognise. More code arriving at the same review queues, security triage and change approvals mostly means more waiting.

Governing at machine speed

Bansal described two approaches that don't hold up: letting coding agents ship straight to production, or keeping human-heavy processes and adding people every time volume rises. Harness's position is to keep the controls and automate the work behind them, so throughput scales with change volume rather than headcount. In practice, that means agents choosing relevant tests for each commit, reviewing pull requests against policy, assessing the risk of each change and triaging failures.

From CI/CD to a set of agents

Harness is extending its CI/CD roots into four agent families:
  • A software delivery agent for code review, build and test decisions, change assessment, progressive deployment and rollback
  • A security testing agent for finding, triaging and fixing vulnerabilities
  • A runtime protection agent for discovering and protecting APIs, agents and MCP interactions
  • A cost management agent for tracking AI usage and cloud spend
Developers keep their choice of coding assistant. The difference Harness pointed to is what happens after the code is written.

Context, Worker Agents and a dial for autonomy

Two ideas underpinned the demos. The SDLC Knowledge Graph is a live layer that connects repositories, builds, services, environments, incidents, costs, vulnerabilities and policies, because an agent can't determine your real blast radius from a code repository alone. Worker Agents turn pipeline steps into task-specific agents that run inside the pipeline's existing policy and identity model. In the live example, an agent investigated a failing CI job, prepared a fix and reran the pipeline.
Autonomy is configurable by application, environment, service or task. Harness described three levels: agents assisting, agents preparing actions for human approval, and agents executing approved actions where risk policy allows. In the demo, an AI code review flagged a potential exposure of customer PII, and a change with latency concerns and no rollback path was held until a person explicitly accepted the risk.

Security at the same pace

Bansal argued that finding more vulnerabilities doesn't help if prioritisation and remediation can't keep up. He cited a tenfold rise in vulnerabilities found, linked to frontier-model-enabled discovery through Project Glasswing, and a six-hour figure for time to first exploit. Neither came with a full methodology, so treat them as illustrations of the pressure rather than universal numbers.
The security demo focused on working out which findings are actually reachable and exploitable, then preparing and validating fixes. The runtime demo showed an e-commerce agent trace, including a prompt injection attempt, and how production findings can feed back into earlier pipeline decisions.

Testing AI agents is different

Customers are also building business-facing agents, and those need the same build, test, release and security discipline as any other application. Because an agent's answers vary, testing has to assess behaviour such as response quality and faithfulness, rather than matching an exact output. Harness showed offline and online evaluations, run-level traces with token spend, and a deployment to AWS AgentCore using canary-style verification.
Image of the Human cost of AI transformation report

Report: understanding the human cost of AI transformation

Faster delivery is only half the story. We surveyed 2,500 knowledge workers across the UK, US, Canada, Germany and Spain to find out how AI is really changing the way people work, from the hidden 'verification tax' to the effect on workplace culture and trust.

Two early previews

Harness was clear that both of these are early previews. The first was an autonomous software factory that starts from a ticket and checks the design before coding begins. In the example, it caught an agent proposing a new payment service when an approved one already existed. The second addressed citizen developers, framed as roughly 40 million professional developers alongside 300 million citizen developers (a directional estimate). The idea is a simple route for business users to publish what they've built, within guardrails set by platform teams.

From token spend to unit economics

The keynote closed on cost. Harness argued that a large AI bill isn't evidence of return, and showed how consumption could be traced to shipped code, or to business transactions for runtime agents. The measure that matters is cost per shipped improvement or completed outcome.

What this means for your organisation

The most useful takeaway is a question: if the volume of changes doubled tomorrow, which control would break first, and how would you know? For most teams, the answer sits in review queues, security backlogs or approvals that exist because nobody has gathered the evidence to decide with confidence.

How Adaptavist can help

As the first Harness Advanced Delivery Partner in EMEA, we help large organisations get more from their Harness investment. We implement Harness, migrate teams away from legacy tooling and drive adoption across every line of business, so AI-powered delivery becomes measurable business performance rather than a promising pilot. Depending on your priority, that looks like:
  • Faster delivery. Using the Harness software delivery agent, we help you retire Jenkins, Bamboo and other legacy CI/CD tools without losing your pipeline logic, and build golden paths developers will want to use.
  • Security in every pipeline. Using the Harness security testing agent, we embed SAST, SCA and supply chain integrity checks so security and compliance are validated automatically.
  • Protection in production. Using the Harness runtime protection agent, we build API posture management, runtime protection and AI security into how you operate.
  • Control of cloud and AI costs. Using the Harness cost management agent, we connect spending data with engineering efficiency.
Not sure where to start? Our discovery assessment maps your pipelines, tooling, security gates, and governance gaps, and provides a costed roadmap and business case before you commit to scaling. From there, we handle implementation and help embed a Software Centre of Excellence, adoption leads and governance metrics, so adoption and ROI keep climbing after go-live.
If you'd like to talk through where the friction lies in your delivery process, speak with our Harness experts. You can also read our take on continuous verification with AI.
Written by
Image of Paul Cavanagh
Paul Cavanagh
Field CTO, Strategic Accounts
Paul is a technologist with 30+ years in enterprise financial services, covering everything from M&A to architecture and governance. He helps regulated clients embrace platform engineering, shift to long-lived products, and streamline their SDLC and ways of working.