"Move fast and prove things."

At the end of June, Joseph Kiniry opened a National Academies convening on AI for defense software engineering in Washington, D.C. This post covers the argument Kiniry presented from the podium.

His thesis: AI does not lower the assurance bar. It moves the bottleneck.

  • AI already accelerates software development and exploit generation. Critical systems still require evidence, certification, and recertification. The current state of affairs still gives adversaries the speed advantage.

  • For most of Kiniry's thirty years in rigorous engineering, four activities consumed substantial expert time: writing precise models and specifications; linking requirements, models, code, and evidence; creating and maintaining proofs; and translating between levels of abstraction. AI can now assist with all four.

  • The new constraint is preserving intent and trust as those artifacts are produced faster than people can review them. Every layer still needs to remain consistent, justified, and connected to the engineering decision above it.

  • Formal methods, engineering evidence, technical architecture, model-based techniques, and modern programming languages work best as one assurance chain. NINJA is Sigil Logic's methodology for connecting them; HOARDE is the agent platform that applies that method.

  • Assurance is also a recurring cost. When a requirement or model changes, specifications, proofs, code, and evidence must all be checked again. HOARDE regenerates them together. A recent specification update that previously would have taken weeks was completed in minutes.

AI can accelerate attackers as well as defenders. The practical requirement is therefore clear: update critical systems quickly without abandoning evidence, certification, or human review.

Visual recap: Move fast and prove things (PDF, 8 pages)

If your team is responsible for a system that must change quickly and remain certifiable, we would like to compare approaches. Get in touch.