For the last half decade, engineering teams globally have discussed and debated platform engineering. Thousands of conversations at thousands of enterprises discussing what it is, how to enable it and whether to invest or commit to the discipline. That debate is over. Adoption is basically universal, with 90% of organizations running platform engineering practices and 76% standing up a dedicated platform team. The issue is. The platform that won that argument was built for a world still exists, but over the past two years five forces have come crashing down on top of it. These forces are measurable, and are already sitting in your innovation needs, cost reports and security findings, and left unanswered they will hit your platform where it hurts. They are the subject of the new report, Platform Engineering 2.0: An evolution for the AI era, written by myself and Sam Barlien. This article is part of a series on this topic from overview to a deep dive on AI security and compliance. Here is each force, and what your platform has to do about it.
1. AI-driven coding acceleration
The old constraint was writing the code. That constraint is gone, and it is not coming back. Almost every developer is now producing a deluge of AI-generated code, with 90% using AI coding assistants and volumes up 2 to 10 times. The bottleneck has not disappeared. It has slammed straight into delivery.
The developer's job is changing shape with it. They used to write most code by hand, one feature at a time. Now they specify, orchestrate, and validate work produced by assistants and agents across several streams at once, and the pipeline underneath has to keep pace. The move to make now is to widen the delivery path itself, with parallel builds, automated policy checks, and review tooling that scales with machine-generated volume, so validation is not the choke point on the productivity gain AI was supposed to deliver.
2. The agentic future
This is the big one. Agents are the first genuinely new persona platform engineering has had to design for in over a decade, and they are the force blowing everything up rather than just adding load. Every other user of your platform is a human consuming an interface. Agents are not, and they are on track to outnumber every human user you have.
They consume APIs, not portals, and they need things no human ever requested. GPU and TPU allocation, Model Context Protocol (MCP) gateways, non-human identity, scoped permissions, bounded-autonomy guardrails, and an audit trail for every action they take on your behalf. Most platforms today are effectively GPU-blind, unaware the accelerators these workloads need even exist. An agent acting without a bounded scope is not a feature you shipped. It is an incident you have not had yet. This is where the Internal Developer Platform (IDP) evolves into the Agentic Development Platform (ADP), the same operating model on an expanded substrate.

The move to make now is to treat agents as first-class users before they arrive uninvited. Give them scoped non-human identities, budget and egress limits, and a full audit trail, because a platform that cannot host agents will not host the next generation of enterprise applications.
3. The FinOps reckoning
Cloud waste was always with us. AI just turned it into a full-blown FinOps reckoning, and nobody is exempt. The baseline still sits around 35% wasted cloud spend, and AI infrastructure pours fuel on that fire, because GPU, inference, and training jobs dwarf anything traditional workloads cost. On top sits the tokenomics of large language models, growing exponentially and invisible to almost every cost-reporting tool teams own. Token maxing is real, with teams burning through a year of budget in months.
Per Harness FinOps in Focus 2025, 52% of engineering leaders name a FinOps-developer disconnect as a driver of wasted spend. Cast.AI's 2026 State of Kubernetes Optimization report found public-cloud Kubernetes workloads running at 8% CPU, 20% memory, and 5% GPU utilization on average, while GPU and memory prices have risen 2 to 3 times on flat budgets. And 55% of developers ignore cost management entirely, while 62% want more control but lack the tooling to act.
These are platform design shortcmings , not individual ones. The platform does not put cost in front of developers, so they provision without it, and retrospective FinOps cannot respond when one misconfigured workload triggers bill shock overnight. The move to make now is provisioning-time cost gates that surface budget impact and cheaper alternatives at the moment of the deploy, so cost becomes a platform signal rather than a monthly surprise.
4. Sovereignty and compliance
While the platform absorbs AI workloads and their costs, the regulatory floor is not just rising for sovereignty and security compliance , it is rising fast, with new rules landing in almost every country on the planet. The EU AI Act, the Cyber Resilience Act, US executive orders on AI safety, sector rules across financial services and healthcare, and hardening data-residency requirements all pile into the platform's lap, faster than annual compliance cycles can handle.
Worse, compliance in most platforms is a snapshot, not a continuous guarantee. You pass the audit, and it drifts the next day. AI opens a brand-new attack surface that barely existed eighteen months ago, from shadow AI sprawl and prompt injection to model poisoning and inference data leaks, and no scanner on earth catches prompt injection in a live inference stream. Shift-left helped but could not hold on its own, and most vulnerabilities are still caught in production.
This is the pillar to act on first the moment you start shipping AI. The move is to make compliance continuous rather than periodic, with policy-as-code at admission, real-time drift detection, and audit trails covering human and agent actions, so security lives in the substrate and every path is secure by default.
5. The multi-persona enterprise
For most of its history, platform engineering served one persona exceptionally well and mostly ignored the rest. That was defensible when developers were the only users who "mattered". It is indefensible now. Why would a platform this powerful serve only developers when the same golden paths and self-service could serve the whole organization?
The modern platform has to serve six distinct personas. App developers, platform engineers, engineering and business leaders, security and compliance teams, data scientists and ML engineers, and AI agents. Each needs its own tools, abstractions, and intelligence, and data scientists were the most underserved of them, despite being central to the AI roadmap leaders are now judged on.
The move to make now is one shared platform API with persona-specific frontends. Fragment the backend instead and you fragment governance. And the team that built the platform for developer autonomy is the same team that will build it for enterprise-wide agentic autonomy. That is the biggest expansion of mandate platform engineering has ever had, a strange thing to call a problem.
What these forces demand next
The forces do not arrive one at a time. A single AI workload pulls on all five at once, needing GPU provisioning, multiple personas, cost visibility, new security surfaces, and the flexibility to swap tools as the landscape shifts. You do not have to answer all five at once, though, and you should not try. Audit your platform against them, find the one causing the most pain today, and start there, because that is where you will have executive sponsorship and a clear return. AI workload pressure dominates where data science teams are already shipping models; cost pressure where the AI bill has started to surprise the CFO. Begin where it hurts most. A few moves you can start on first.
- Map an experience layer per persona. Write down what the app developer, platform engineer, security team, data scientist, and AI agent each need, and stop pretending one portal serves them all.
- Embed security and FinOps into the platform, not the person. Move scanning, policy checks, cost attribution, and budget gates into the platform layer so they happen by default.
- Get ready for agents now. Your developers and business teams will spin up agents whether you govern them or not, so give them scoped identities, guardrails, and an audit trail before they arrive.
And for the executives funding this, treat it as a business case and tie platform investment to developer velocity, cloud cost reduction, and AI-readiness metrics; stand up a platform P&L; and set a 12-month AI-native milestone covering GPU workloads, non-human identity, and MCP gateways. Twelve months sounds generous. In this cycle, it is not.
Move now and you get to define what platform engineering becomes next. Sit still, and you will spend the decade playing catch-up. Learn more with the full report, or read read the overview article and the deep dive on AI security and compliance.











