How to Manage and Secure AI Coding Agents
Blog post from Kong
AI coding tools are projected to exceed $13 billion in spending in 2026 as autonomous agents increasingly plan, write, test, and deploy code while calling language models, MCP-connected tools, and other agents. The expanded connectivity creates governance challenges beyond code quality, including insecure generated code, prompt injection, excessive tool permissions, data leakage, unmanaged non-human identities, and uncontrolled token costs; cited research reports limited visibility into developer AI usage and finds that only 55% of tested AI-generated code was secure. Drawing on OWASP’s agentic-application risks and Gartner’s AI TRiSM framework, the discussion argues that policies alone are insufficient and recommends continuous infrastructure-level controls: inventorying agents and their connections, assigning least-privilege identities, applying data and prompt protections, restricting MCP tool access, setting token budgets, and centrally logging activity. It positions AI gateways as a way to enforce these controls across LLM, MCP, and agent-to-agent traffic, while emphasizing that gateways complement rather than replace code scanning, human review, identity management, and other security tools.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 26 | No monthly metrics for this publish month. | |||
| AI Coding Assistant | 13 | No monthly metrics for this publish month. | |||
| LLM | 6 | No monthly metrics for this publish month. | |||
| Observability | 4 | No monthly metrics for this publish month. | |||
| AI Agents | 1 | No monthly metrics for this publish month. | |||
| OpenTelemetry | 1 | No monthly metrics for this publish month. | |||
| Real-time | 1 | No monthly metrics for this publish month. | |||
| Secrets Management | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.