87. Generative AI Coding Tools Make Enterprise Applications Worse – Tech Field Day Podcast
AI is writing a large proportion of modern software and Generative AI coding tools make enterprise applications worse. This episode of the Tech Field Day podcast looks at AI generated applications with Calvin Hendryx-Parker, Jim Czuprynski, Jay Cuthrell, and Alastair Cooke. Satya Nadella says that up to 30% of the code Microsoft writes is AI generated, AWS is at about 25% AI generated code. We ponder whether there is a link between this AI generated code and the quality of the Windows 11 codebase, possibly even the recent AWS outage? Calvin has hands-on experience with a range of AI coding tools, finding he uses different AI tools for specialist tasks in his development projects. The easy task for AI coding is translating existing applications from one platform version to another, or rewriting existing application code in new languages. Both these tasks are onerous for human developers and ideal for an AI assistant. The unanswered question is whether generative AI tools can handle creating new functionality in enterprise applications, can AI fulfill the role of the senior developer or software architect?
Transcript
AI coding tools are everywhere. In fact, AI tools are everywhere. Do you have the right tools to make your applications, your enterprise applications work?
Well, join me on the Tech Field Data podcast and we'll find out. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community.
It's often recorded in association with one of our events. Tech Field Day is part of the Future Room Group, and this podcast is also published on our sister company Site Techstrong tv. On this episode, we'll be discussing how generative AI coding tools are making enterprise applications worse.
But before the discussion, let's meet who's on the panel today. I'm Calvin Hendricks Parker, I'm CTO and co-founder of Six Feet Up. I'm Jim Rinky, chief storyteller at Zero Defect Computing Incorporated, Jeral Chief Product Officer at Nexus Tech.
And of course, I'm Alister Cook, an event lead here at Tech Field Day. And I, uh, recognize this interesting topic for us about how generative AI coding tools are enabling a whole lot of applications to be built, vibe, coding of applications, and that some of the major software vendors have made statements about having large proportions of the code in their applications written by generative AI tools. Yet at the same time, some of those same organizations are commenting that these large applications that are full of AI generated code maybe don't work as well as they used to.
There being some commentary on Windows 11 needing some rework. And it does lead me to wonder whether that rework is being required because the generative AI applications, while they're good at making small pieces of code, aren't necessarily very good at making enterprise code. I wonder, um, Kelvin, you get involved in some development projects at times.
Do you think generative AI tools are good at small scale and not so good at big scale, at least for building applications? I'll, I'll preface that with, it depends. I think the, the, the tools themselves are, uh, Excel based on who's driving them and their level of expertise with managing the context.
Um, I actually, I'm at reinvent, uh, Amazon's big conference this, this week, and they announced their, uh, three agents, uh, on day one's keynote. And I think they're obviously trying to double down on, uh, AgTech with Kiro and, and some of the tooling that they're, they're releasing, uh, they have the AWS transform, uh, tool, which is supposed to be able to move you from an a legacy code base to a, a more modern code base. Uh, I think they've seen success, but I think they've also been working very hard at, uh, generating some soundbites that are, uh, meant for keynote, uh, consumption.
I think there's still a lot of work behind the scenes that's gonna go into making this a true reality for most enterprises to pick up these tools and, and go, that's kind of my take on it to start with. And that translation from one, uh, programming language to another, one framework to another is something that came up when, uh, we were at K Con and I was talking with, uh, Martin Reynolds of, of Harness, uh, he pointed me to some, some work that had been done about translating something that was written in, um, JavaScript and was being translated into Rust in order to make it a more maintain. And, and these tools are really good at that part because it's well known what you're going to, and so you're just saying, go find, go look up all the world's knowledge on the, on the technology you're moving to, given the context of what we're going from.
That's, that's actually a, I think a straightforward use case for this. The, the enterprise tooling of let's go build brand new, uh, never before seen bespoke software is a different case. I mean, we've had success with it on small projects and some large projects, but it, again, it's that careful, the careful driving of it by a, I find very senior resources who understand and have been in the industry for a long time.
It's hard to pass that knowledge of how to drive these tools down to more junior folks. On a related question, if I could, uh, I, I, I have my theory on why BUN was acquired, but I'm wondering if there's gonna be a vertical integration that is part of the m and a strategy of some of these, uh, AI providers so that they can have relevance in what, uh, someone believes is the biggest market they could go after right now. And, and as a data point, my why I think that is, you know, IBM clearly with their granite models and the stories that they brought with Watson X really made it, uh, very straightforward for people that have very strong in-depth COBOL legacy bases, uh, to bring those to more portable Java, uh, for your particular runtime.
I'm sure they have a very specific runtime in mind for you, uh, for you to do that. But it is interesting that BUN was acquired. So I'd, I'd like to get, uh, other, other input from folks on what they think about that.
I think Bun Bun was a natural acquisition for them, given Claude code, the fact that that was the, the, the TUI framework behind it. So I, I dunno if I read too much more into the tea leaves on that one. I don't know if Jim has an opinion on that Since you mentioned IBMI also saw a story, I believe it was just this morning that the CEO of IBM was talking about where we are with, uh, ge uh, general AI intelligence, and he basically said there's about a 1% chance that it's gonna happen and it would require immense upscaling and all other kinds of things.
So, um, I, I'd like how you put that Calvin, the, uh, meant, meant for keynote consumption. I think there's a lot of that going on. And I'll speak personally this morning.
I just did a presentation, uh, implementing a chat bot against some really sensitive crime data for the city of Chicago with a colleague of mine. And, uh, it is not easy to implement complex stuff even with really good, uh, coding tools. Uh, the reason we have senior developers, right, is so that juniors can learn from them.
And the, the person I was working with, she's been working with this particular tool for 25 years, and in five minutes she showed me more stuff about the tool I was using that I didn't even know about how to use it properly. And, uh, so I, my concern a again, I consider myself to be one of the people that's down in the trenches here, and this all sounds awful pie in the sky to me. And I, I just don't know if organizations, you know, I, I imagine senior developers are rolling their eyes so hard that they're hitting the backs of their heads when they hear claims like this.
Uh, AG agentic is one that really frightens me from the perspective of turning over that much control to tools that no one really understands underneath the covers of what's happening. Uh, so that's my take. I I thought the IBM CEO's take, uh, was quite intriguing.
Does, does it mean that there were looking at only incremental benefits in the, in the tooling that is used by the developer as compared to the onstage keynote promise of Yeah, just, uh, right de declare what you want and then sit back and watch it? You know, we go from Vibe Co to like vibe, I don't know, audience. We we're, we're literally just watching.
Uh, and and there's are, there are already memes going through this, right? Where, you know, it's the, it's the picture of, you know, I think it's from, um, uh, the social network movie and Zuckerberg staring at his laptop with that dejected look on his face, and it's the, the caption is, you know, watching chat. GB two do the job that I used to love.
Um, and so it, I mean, so, um, I'm, I'm, I'm a horrible Python developer, right? But, uh, I've shipped better quote, quality, uh, passing test code, um, recently because I do use Gemini. Um, and that that's my tool that I use.
Um, I've even tried to use Gemini inside of, you know, uh, vs code, um, vs code, of course defaults to, Hey, you're gonna use copilot, right? You're gonna use copilot, right? Um, so for me, I, I do see incremental benefits, but I don't, I don't know if I, I'm really ready to say wholesale turn over, you know, the whole design, uh, process of product engineering over to an AI quite yet.
I wonder that if one of the challenges is that most of that information, most of the, this is how you build an enterprise application, this is how you build a good enterprise application, that that information doesn't exist anywhere that these ais have been trained. Mostly it exists inside people's heads and is transferred person to person as gym experienced, uh, not through documentation or, uh, books, white papers that could be scooped up and fed into a large language models training path. I think possibly, uh, the challenge is that information simply isn't easy to feed into an AI to, uh, a large language model in order to, to learn how to design enterprise software.
I feel like, I feel like that's gonna change really fast. I feel like tools like Antigravity and, and Kiro, uh, from Amazon, they're going to be watching what the developers are doing and reacting and actually incorporating, I think are gonna start incorporating that into the, either the training, the fine tuning, uh, that some other, again, I'm, I'm, I'm a little Amazon biased this week because of where I'm sitting, uh, but there's, there's interesting things on the horizon. I think those things that they presented at the keynote are probably 12 months away still.
Like the, they looked good. They, they sounded amazing. But I think when it comes down to actual use cases, Amazon is probably getting that kind of improvements internally when they're saying they're migrating old versions of their services to do new versions of code going from old J dks and New J dks.
Again, those are like best case scenarios. They make great case studies, like the great white papers are gonna be of those things, but when they go to build the new things, I think that's, and, and I kind of wanted to touch back on the a GI comment that Jim made. Uh, I I think that's interesting.
What got us here will not get us there is absolutely my take on it as well. I, I think we're gonna see more putting together domain specific small language models that are highly specialized. Like you'll have a JavaScript model and a Python model and a, you know, Java model in your toolkit and a, and a orchestrator model sitting at the front end watching and, and kind of making these things all make the right kind of decisions.
You're already seeing that today with some tools like Goose from Block. Uh, that's one of my favorites that I, I talk about quite a bit. They've got their, um, kind of, um, uh, the, the director and, and the, the worker, uh, models that you can actually configure today to have a multi-model set up where one's watching the others doing the work.
Yeah, you, I, I watched your, uh, side by side where you kind of like, uh, doing like a bake off, if you will. Um, and please Pillsbury, uh, dough do not sue us for me using the term bakeoff on this, uh, you know, podcast. But it, it is, it is interesting because effectively what you were doing was like a speed dating version of what I think is gonna have to happen every single enterprise where they have some capacity to ship digital product.
And if, and if they're doing that, and if, and if let's say that they're, you know, kicking the tires internally, you know, there might be, uh, they, they, they maybe start with the world of maybe what Alistair was referring to earlier is just like that, that enterprise data. None of these companies have seen that before and it's just trained upon it. Um, so they may start with, uh, Hey, I'm gonna come up with some lightweight way of doing fabric, a data fabric, and from that data fabric, then someone says, ah, we should have a way to like, uh, materialize views and personalize and save and tie it to this line of business.
And they may start with low code, no code within a vendor ecosystem of what would've been their business intelligence group. But, but I do believe that there is going to be this appetite for, uh, to your point, Calvin, I wanna imagine something that never existed before. Um, and I, I just don't, I don't know where the connected tissue would come from for that.
Uh, legacy enterprise specific, call it quirky, uh, you know, uh, uh, approach that Alistair's referring to of, well, that's the way we've always kind of done it here. Uh, this is our data standard and format. So, um, that, that's that bake off that you did.
I'm just trying to imagine like what's the, what's the toil in the enterprise setting knowing that your time probably has to be tracked somehow or tied to some cost center? How, how, how do, how does an enterprise have any chance of succeeding? And does, does, does this mean everything has to go to the, some like global systems generator, probably several of them on the floor at AWS saying, no, no, no, no, sweet summer trial.
Don't try to do this. Let us help you. Right?
But the, the issue that I'm gonna see with the enterprise is they'll probably hamstring themselves by saying, you'll get to use one tool, it's gonna be co-pilot inside a VS code. Where I think the real advantage of like that bakeoff when it showed was given certain kinds of context, certain tools performed better. They're obviously gonna converge over time, but you may still have sweet spots where certain agentic coding tools are just better at building the CI pipeline than another.
Uh, I did that during the, the last tech field day, I built a blinky lights electron app, and sure enough, codex one shot at it built it up real quick. I was like, incredible. Now let's make a CI pipeline that can build it in the cloud for me.
I could not get Codex to do it for the life of me. I went and dropped over into Goose, you know, one shot at a CI pipeline, and then it started working, but I didn't spend a bunch of time trying to like force that square peg in the round hole. I, I, I quickly defer to another tool because I think that either it's, you know, there's too much junk in the context window.
The, the system prompts that are behind some of these tools just don't have my use case in mind. And so that's where some of these tools are very limited. I think enterprises are gonna need to adopt some specializations.
Like I could see there's the, you know, IBM version of this tool. com platform, those kinds of things. And they'll be very specialized and understand what you want a lot better.
And so one shot, it'll be easier, But one thing I'm not hearing in all of these discussions, by the way, is, um, how secure is all this, uh, across my Thanksgiving reading was, was an article on the Atlantic about chatbots are becoming really good criminals. And they were describing how, and we just saw this recently, right? Where, uh, you know, state actors are using ai, generated AI to write really good code, really code that penetrates from a thousand different directions, whatever it might be, right?
And, uh, in fact, I was mentioning back to boots on the ground, you know, my topic today that I was working on with my colleague was about how do we lock down access to embeddings? Because we don't wanna let everybody have access to the embeddings themselves because, well, somebody may not know how to write Python to connect to say, a MySQL database to actually get at it, but an AI tool could, and, you know, what do people think about WWW? You just, it's all vectorized.
Don't worry about it. But it ain't that hard to get an AI to look at vectors, you know? And so I'm just, this, this, the, the headlong rush I'm not hearing about, you know, really, we should make sure that the wheels are down before we land.
You know, that's like a really important thing. And maybe, uh, they're down and locked. And as, as a lifetime developer of 45 years, that's what concerns me.
I'm not saying we should stop, but do we have a checklist? Do we have a checklist to at least check that the AI is doing what we really said it should do? And are you hearing that I'd be interested from the AWS or IBM perspective, whatever you guys have heard, are people talking about that or Not mean they actually are, that was a, a big impetus on the keynote on Tuesday was the security aspects of the various models, the new policy guardrails that they're releasing inside their agent, uh, uh, framework.
But I, I, as I look at that, even like Google's anti-gravity tool that they released, what, a week and a half ago, it's been a week and a half, maybe, uh, within two days of that releasing, there was an exfiltration, um, vulnerability discovered almost immediately because these, a agentic tools have the ability to use tools like they, that's the, that's their key feature is also their key weakness. You're gonna have to employ other techniques and be given that, like we're not only developers, like a lot of us on this call are also systems, people using tools like Ana Mac, uh, little snitches, like an absolute required, uh, I don't want, I wanna know if a process on my machine is making a connection I was not expecting. Uh, 'cause that's, that's May's the only surefire way to know and have it proactively block those kinds of things.
Uh, because I don't think you can write a bunch enough guardrails yet with these tools, they're still non-deterministic. They still can do things because it's statistically probable to do them. And if they've been trained with some nefarious, you know, materials, uh, baked into them, it's, you have no, you have no control of that.
You're not auditing or analyzing these models. Uh, you sometimes you don't know where they'll come from. Uh, that's a difficult piece, but you have to take other countermeasures, I think to, especially in the enterprise.
The enterprise absolutely. Having, uh, watching their outgoing traffic like a hawk, I, I assume they are. And I, I do it at my own desktop level.
When, when you think about what it means for an enterprise to take on a net new creating of an application, uh, what's that joke and software, once you've started writing the software, now you have two problems or whatever, whatever that is. Um, so as they, as they create this new software, I am still left wondering the, the cho uh, the, the, the chores that need to be done. Uh, do we see any indication that if you know Jim, like your example, like is this thing gonna do das Rast and all the other things that need to happen on that stack to make sure it's secure and stay secure as it drifts through, like updates and changes.
But the other part of that is, is I'm wondering if, is there, is there any, is there anything we're seeing where, um, relief on the, call it site reliability engineering side or the, or the platform engineering side, these, these teams have literally less toil on their plate as we ship new, you know, applications. So I'm, I'm, I'm kind of wondering about the full lifecycle, you know, setting aside like whether we can even get there or not, but let's say when something lands, um, now what, um, day two is forever, That's here. I mean the, well, it's announced again, keynote ware.
The other two agents other than the kiro application agent was a security agent and a DevOps agent that were announced. Again, you can, you can recreate these on your own with your own sets of like cloud code or GOOSE or ER type tooling where you have system prompts that are geared toward these pieces. You have the right hooks into the event systems to, to hook into your CI pipelines and watch and and maintain.
And, but it's early days. I think these tools are still very early days. You can't, I don't think you can, should rely on them a hundred percent.
Um, it, but they're gonna, they're gonna definitely reduce the cognitive overhead that developers and operators and platform engineers have. Uh, and it's gonna make for better software down the line. I, it'll be so much, I, if I was a enterprise SaaS platform like A-S-A-P-A Salesforce, uh, you name some large SaaS platform, I would be worried because now these enterprises are gonna have the ability to not only build a, a, a replacement that does exactly what they want, but maintain it because they'll have agentic tools sitting in the, in the, in the sides making sure that these things stay patched, secure.
Uh, someone wants a new feature that can write up a spec. I, I think that's coming. I, I don't think we're far no one, I don't think anyone's safe from this.
I, I think if I wanted, 'cause everyone would love to have exactly the software that fits their need, everyone settles for an 80 to 90% solution because it's already built and probably costs less than if you were to go build it yourself. Even with the prices that like a ServiceNow and a Salesforce, et cetera charge on their subscriptions is still cheaper than going in and probably building right now. Hmm.
0 this, you gotta be lurd per, you gotta, you have all these acronym soups and is there gonna be an agent that keeps you closer to the acronym soup checkbox, you know, validation That, that exists today? That, I mean, there are open source tools like cloud custodian that can, you can build those checkbox checkers that are real time event driven in your inco system. Those are, those exist today.
And I think you're gonna see more of that because more folks are gonna wanna say they are compliant and they're actively staying compliant. Yeah, it's, it's interesting move from we're compliant at audit time to we are, yeah, provably continuously compliant. Uhhuh, We gotta get there.
That's absolutely vital. One of the other fun parts in this is, is, Jay, you were asking for less toil by the operations team. I think both Jay and Coleen would like to see that.
Um, I was just on a call with, um, big Pando who have, uh, that what we also saw at, at Kon a lot, which is an AI that sits on top of all of the observability data that you are getting out of your applications combined with all the inventory data that you've got from, uh, from your configuration management systems and then also bringing in all of the incident information, the tickets that are coming through ServiceNow and correlating all of that into some insights. I thought that was a, a really useful thing because, uh, particularly when there's high criticality incidents going on, getting rapidly to what the actual root causes rather than getting rat hole in some symptom, uh, could be incredibly beneficial. And there's some really nice AI driven tools around making it easier to join an active incident or to identify possible resolutions.
I thought there was some really good pieces in there, but we are straying away from our initial, uh, premise that was around how AI coding tools are either helping build better software or maybe not helping build better software. Kelvin, you've used a bunch of them. Uh, your, your conclusion is that you, you like AI coding tools, but you still want a human involved.
I I, I think human guided right now is still the way I, at some point, these eight agentic coding tools are going to be building software that we as humans can't read. Like it's written in a certain way currently because we still are in the loop and reading the software and analyzing what's going on and trying to code review the tools will become as ubiquitous as, or as, as, uh, useful or, uh, generally, um, capable as like a compiler at some point where you trust its output because the compiler has been well tested and and build software that you trust or does it, uh, it's been posited that the, the GCC compiler many, many years ago in the first iteration could have been, could have been compromised with a, a backdoor we would never know. And I, I think that's, that's an interesting element around at the moment we want AI tools to write code that humans can maintain, but in the end that, that the end solution is not necessarily for humans to maintain that code.
It's for the AI to build tools that builds code that the AI can maintain over time. And that we take that observability process of just treat it as a black box. And when I send that this input, does it do the thing I want it to do?
Because fundamentally we're just moving up the layouts, right? We're not caring about the individual layout and code calls. We're caring about the results that are being delivered.
And that's where AI tools and, and AI coding pipeline tools, well, it's not even gonna be code Pipeline, is it? Right? What does, what does code quality at that point?
Yeah, Uh, uh, uh, to go back to my entertainment example, like maybe we're just becoming just, you know, an audience, uh, for what's happening. Um, there will probably be, uh, situations regulatory or otherwise where even if you did ship unquote, you know, byte code binary only or whatever, they're still gonna have to be the human readable compilable, uh, the old fashioned way version of something. So we may have, we have may have that burden where you're actually doing, like you're doing a, uh, dual source, uh, uh, or, or, or whatever the, the, the, the requirement would be so that if, if, if for, gosh, you know, sakes, this thing did go sideways and it starts eating, you know, the hand that feeds it, we need to cut over to the human inspectable.
Um, I think observability has always been, uh, this, this phrase getting, uh, constantly re-injected into the conversation. And so I, I do think there probably is something to be said for, you know, being a log a Lang Smith and throw a decorator on something and see how long it took. Um, but how many people have been doing that with application performance management and monitoring, you know, for, for o well over, you know, decade or so and the original like Mercury interactive stuff, going back to the older days of like just testing how you can hit or, or load test a web application.
Um, these are the same and similar patterns. But again, I go back to that same toil thing when you, when you take the automated binary only machine only talking to other machines when you have to put it to where the human can inspect it when something goes sideways. I still think that observability part is, um, I'm, I'm still thinking like, how, how are we solving for the proliferation?
'cause Calvin, you've convinced me this is gonna happen. I'm just thinking like what's the operational impact proliferation wise, if we, to your point, we don't have more of these agents to come help us along the way. Yeah, well you, you see that today in the enterprise.
This is a, this is like something that plagues them anyway, is that the proliferation of tools, the stack of tools and places you have to go. So we're gonna, I, I don't know if there'll be winners, but I think there'll be correlations Actually, what could be interesting is if you see more of, because of data gravity, because you, the way, you know, you've got logs in one spot and your database is in another, you don't want to bring those things together because it takes too long to then get to a conclusion or a, a root cause analysis. You're gonna be having, uh, at Edge Compute sitting next to your data in, in these cases that are very specialized and understand what it's looking at.
Yeah, I said the small language models people have been, uh, talking a little bit more about which is where this is the specialist, it, it, it, it can't tell you the capital of Kansas, but boy does it know a lot about this particular log file in sequence. Oh yeah. And they can run on very lightweight hardware.
I mean, raspberry PIs, you know, running like, you know, 1 billion parameter models that are, you know, small and fast. Like speed is gonna be part of the, the feature, right? It's, I I feel like speed is a feature of tooling.
Like when I'm programming in Python and we now in a new world and we've got tools like UV to install and manage Python install and manage my dependencies, I use it mostly because it's so freaking fast. Um, and it makes my life as a developer so much easier. 'cause I, I, I'm, I'm not, you know, waiting, it kind of goes with my flow a lot easier and I think these tools, these generative AI tools need to be in that same speed realm, which is why the smaller ones are gonna come to the forefront.
As usual, I opened a conversation that couldn't really fit in the space that was available for us. So thank you for joining us today at this Teak Field Day podcast. But before we go, we can the audience, we can people connect with you and potentially carry this conversation on.
Yeah, absolutely. com/i/calvin hp I typically post quite a few things there. com.
I'm also on Blue Sky. That's that new thing all the kids have been talking about. com and of course on LinkedIn, if you know, there's only gonna be one of me with that last name, Of course you'll have to spell it correctly and I seldom do.
Sorry, Jim. And of course I'm Alistair Cook. You can find me on LinkedIn as well as across various tech strong and tech field day sites.
Uh, just Google my name and avoid the cricketer. Uh, so thank you for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please subscribe on YouTube or your favorite podcast application so you can see far more of these discussions.
Consider us giving us a rating and a nice review so that other people get to consider it too. This podcast was brought to you by Tech Field Day, the home of IT experts from across the enterprise and a part of the Futureum Group. com/podcast.
View us on Textron tv and thanks for listening. We will see you next week.