Product Leader Claims Trust is Key Advantage in AI Copying Simplification Era
Read more
YourStory [india, en]
yourstory.com

Product Leader Claims Trust is Key Advantage in AI Copying Simplification Era

A.R. Rakhman, a composer who began his career in 1989 by setting up a home studio and independently handling composition, production, and engineering, achieved success with the soundtrack to his first film in 1992. Decades later, he continues to refine the sound of film music.

Kunal Shrestha, Vice President of Product at Responsive, used this composer's story in his presentation at DevSparks Chennai 2026. He applied this story to illustrate a situation where developers observe artificial intelligence making software creation cheaper and faster, which in turn facilitates its replication. His talk, titled 'The New Level Playing Field for Developers: Beyond Features,' focused on finding differentiators when features themselves cease to be protected.

Shrestha noted that the number of questions on the Stack Overflow forum has decreased to a negligible fraction of its former level. He explained this by stating that developers joining the market after 2021 have started using AI tools instead of turning to forums.

He stated: 'If you don't redefine, you will be replaced.' Shrestha emphasized that pressure is exerted in both directions: development companies risk losing customers to internal alternatives created with AI, and internal engineering teams must prove the reliability of their own AI systems over time. He referenced a recent McKinsey study indicating that 32% of organizations abandoned purchasing a software product because it could be built internally using agent coding tools.

Responsive, a company that helps enterprises respond to RFPs, security checks, and vendor questionnaires, released its first AI-powered feature in 2024. Shrestha clarified that the company does not develop or fine-tune its own models; the initial priority was addressing what he called the 'trust gap' between customers and AI-generated results.

'What started with 10% of our customer base using AI in our products is now 70%,' Shrestha reported. He added that Responsive serves 2000 clients globally, including over a quarter of Fortune 500 companies. Many of these companies possess the engineering talent to build comparable tools themselves but have not done so yet.

After trust was established, the company moved to automation, launching agents to speed up customer request processing, and then to implementing intelligent capabilities when speed ceased to be a sufficient differentiator.

Shrestha identified three areas where, in his view, companies can still create a defensible competitive advantage: trust, intelligence, and distribution.

Regarding trust, he believes that AI systems require more than just a confidence score attached to their outputs. Users must be able to trace any answer back to its source, and every step the AI system takes to make a decision must be logged for both internal support and ultimately for users who wish to understand the system's reasoning.

Concerning intelligence, Shrestha pointed to agentic RAG—a method where an AI system extracts information from the company's own data rather than relying solely on the data it was initially trained on. This method is combined with customer history memory so that systems do not start interactions from scratch with every query.

He also described the possibility of learning from patterns gathered from multiple clients, such as using anonymized onboarding data to accelerate the adaptation process for new clients without revealing any single client's data.

On the topic of distribution, Shrestha advised companies not to expect users to come to their application. AI tools should be integrated directly into the platforms customers use daily, either through direct integrations or via the Model Context Protocol—a standard allowing AI systems to connect to external tools and data sources.

He stressed: 'Don't get stuck on your application.' Adding that the appropriate interface depends on the task, he concluded that a true omnichannel experience allows a user to start work in one interface and switch to another without losing context.

Shrestha compared Responsive's approach to software development two years ago, when a product manager wrote specifications, a designer created mockups, and an engineer implemented them in three separate handoff stages. He contrasted this with the newer approach the company uses for simpler projects. In this new approach, as he explained, one person, often a developer, inputs a prompt via an AI coding tool connected to the company's design system, and then reviews and publishes the result. Shrestha noted that 'for simple projects only one person can do this from start to finish,' but complex initiatives still 'require input from people across numerous functions.'

In conclusion, Shrestha returned to the theme of curiosity, advising developers that staying relevant means constantly questioning whether the problem being solved is the right one, not just how well it is solved.

Similar stories

Experts note that the human factor is important in vulnerability hunting despite AI capabilities
Read more
techcentral.co.za

Experts note that the human factor is important in vulnerability hunting despite AI capabilities

Businesses across South Africa are preparing for the introduction of AI-based security testing services, which will be conducted continuously rather than annually and will be cheaper than current solutions.

Two out of three statements regarding this trend are true, but the third requires careful verification before signing a contract.

Figures that settled the debate

According to the Cobalt’s AI and Pentesting Pulse Report 2026, published in June, researchers compared two surveys of security specialists conducted with a one-year interval. In 2025, 29% of organizations relied entirely on AI automation for testing. However, by 2026, this figure dropped to 9%.

The study explains this trend by noting that about 78% of respondents reported that fully automated scanning tools failed to detect critical vulnerabilities in their infrastructure. The issue is not an excess of alerts that any team can handle, but that the system provided a clean report when, in reality, the business was at risk.

Martinus Engelbrecht, CEO of NEWORDER, notes: 'When a scanner issues a false alarm, the security team has to spend a week verifying it. It's annoying. But when a scanner stays silent about something real, the business is told everything is safe. They accept the report, stop worrying, and never check that part of the business again. That silence is a costly failure, and no one finds out about it.'

Vulnerability is not an attack path

The key difference determining the choice between solutions is not technical; it lies in the distinction between a list and a route. A vulnerability is a fact related to a single system. An 'attack path,' however, is a sequence of actions: it could be a weakness in a vendor portal, an undescribed connection between two systems, or a disabled login leading to the financial system in three steps.

Automation handles the first point well. Every item on the list might be true, but the report can still miss the most important thing because the danger lay not in any single element, but in the order in which they were connected. Creating a chain of discovered issues into an attack path is called Adversary Path Engineering. This is the same work an attacker does, and it is done in the same sequence. No one hacks a company using a severity rating.

Data from direct comparisons confirms this, and the details here are more important than flashy headlines. In a hacking competition organized by Hack The Box in November 2025, teams using AI and teams working without it were asked to solve the same 36 tasks. AI-assisted teams solved them 3.2 times faster. This gap is due to weaker participants. Among the top 5%, the difference narrows to 1.69 times. The best team scored all 36 points, while the best AI-assisted team stopped at 32.

The less qualified the tester, the more automation helps. The higher the tester's qualification, the less difference it makes. The market has already changed: now 47% prefer a hybrid model where automation is used for coverage, and qualified specialists are used for decision-making.

Engelbrecht emphasizes: 'Automation is applied where it is truly better: in breadth and repetition. Then every finding is confirmed by a qualified specialist before it reaches the client. This is Scaled Human Validation, and this is what differentiates a report from a full assessment.'

A clean report does not mean a clean business

The proposal for continuous testing without the need for rare specialists is a strong argument, especially in a country where CSIR found that 63% of cybersecurity vacancies are either unfilled or partially filled.

If a test misses a path an attacker could use, no warning is issued. The report comes back empty, which looks exactly like a good result. Nothing raises suspicion until something happens. This is worse than having no testing, which at least makes the business feel appropriate anxiety.

Engelbrecht adds: 'An empty report is the easiest thing in the world to accept. It costs less, it arrives faster, and it tells you nothing is broken. The problem is that a test that found nothing and a test that missed everything produce an absolutely identical document.'

King V Act, applicable to financial years starting January 1, 2026, or later, requires including data, information, and technology governance on the agenda. A company that cannot specify what was tested, by whom, and what remained outside the scope of verification is liable for it.

Ask what they actually did

Most buyers, faced with this issue, look for a certificate or accreditation. A certificate is useful, but it describes the company itself, not the work performed. It says nothing about your specific test: what exactly was done or who did it.

Five elements can provide such an answer, and any good provider can supply all five. This is a detailed description of how the testing was conducted. The name of the person who performed it. The path found in your systems and where it led. Proof that every finding was confirmed by a human, not a tool. And retesting demonstrating the closure of that path.

Engelbrecht shares experience: 'We have been doing this since 2010, and we hold ISO/IEC 27001 certification, which any client can request. But a certificate is not the proof that matters. Ask us to provide these five points. And then ask all other providers you are considering. Those who cannot provide them will explain why they are unnecessary. No one who can provide them will say that. That is how you recognize those selling a document, not the test itself.'

Three questions before signing

No owner needs to allow a debate about artificial intelligence. They need three written answers:

  • What did the tool do, and what did the human do? A provider who cannot draw this line either doesn't know or prefers you to find out yourself.
  • Were the findings linked into a chain, or were they just listed? A list ranked by severity is an inventory. Ask to see the path the operator built and where it led.
  • Who bears the cost if the test misses a real risk? The answer will show what the provider truly thinks about its product.

Engelbrecht concludes: 'If nothing was chained together, the business was given what the automated system considered its environment at the time of launch. Nine percent of this market still operates only on that. And there is a reason why the other ninety-one percent refused, and it is not nostalgia.'

About NEWORDER

NEWORDER is a tactical cybersecurity management company founded in 2010, operating in Africa, Europe, and the Middle East, and expanding into the UK through its global office on the Isle of Man. The company holds ISO/IEC 27001 and ISO 9001 certifications.

Trust in the Indian real estate market is growing: AI and data centers are becoming investment drivers
Read more
www.aajtak.in

Trust in the Indian real estate market is growing: AI and data centers are becoming investment drivers

According to a JLL report, the Indian real estate market is becoming more transparent and reliable, with significant growth in investments in artificial intelligence (AI) and data centers. These positive changes could attract major global investors to the Indian real estate market. However, for India to fully realize this potential, it needs to implement several important reforms, including simplifying property-related regulations, broader adoption of new technologies in sales transactions, and ensuring easy access to complete and accurate property information.

The JLL report, based on the Global Real Estate Transparency Index 2026 (GRETI), shows that transparency has significantly improved in two-thirds of the 88 tracked markets and regions. However, the same document notes that the gap in transparency levels between leading and less transparent markets continues to widen.

In the GRETI 2026 survey, the Asia-Pacific region led global improvements in real estate transparency, with half of the ten markets showing the greatest progress belonging to this region. Among them, India took the lead, followed by Vietnam, South Korea, Australia, and Thailand.

The report highlights that India demonstrates steady growth, ranking fourth in improvement over 10 years and third over 20 years in the Asia-Pacific region. This growth in transparency is accompanied by a sharp increase in cross-border investments in the Asia-Pacific region, with India and Vietnam achieving record transaction volumes. Furthermore, India attracted $8.1 billion in cross-border investments, the highest figure in the last two decades.

JLL notes that despite India being at a critical juncture, having made the most progress in the Asia-Pacific region in the last two years and entering the top five countries globally, much still needs to be addressed. According to the report, the growing interest in AI and data centers represents not just an opportunity but the very engine that can attract major international investors. However, this is only possible if India strengthens its rules and systems at the same pace as the new opportunities.

According to JLL, 'land pooling' mechanisms in India, created to consolidate scattered private land parcels, are still in the initial stages. While master plans at the city level are undergoing administrative procedures, they are not being implemented on a large scale.

For plans to be uniformly implemented across the country and translated into measurable results, the application of GIS and aerial photography (drone) based digitalization needs to be expanded beyond pilot cities. Discrepancies also remain in plans concerning regulations and reporting on building operational performance standards, energy consumption disclosure at the property level, and climate risk reporting for sustainability.

From a technological standpoint, the adoption of technology in real estate acquisition and sales processes lags behind more developed markets, and government interaction with PropTech remains uneven. There is a significant disparity in the availability and depth of data in smaller Indian cities, creating gaps that better-resourced markets have already managed to address to a greater extent. The use of new technologies, such as digital registries and software, in real estate transactions is currently limited to major cities and has not reached smaller towns. Although tenants' rights to audit landlord accounts have improved, they still lag significantly behind those in developed countries.

Popular