# From Copilot to the Garden of Eden - Adam Cogan - NDC Oslo 2026

## Executive summary

The talk argues that the industry is moving beyond the initial 'Copilot hype' phase toward sophisticated, agentic AI workflows that fundamentally reshape the enterprise stack. AI agents are shifting roles from simple assistants to proactive workers capable of automating complex tasks, from generating presentations and analyzing data across systems (GitHub, Azure DevOps) to managing calendars and performing deep research. For developers, this necessitates a heightened focus on security, dependency management, and shifting the primary activity from manual coding to prompt engineering and architectural oversight.

## Key takeaways

- The Shift to Agentic Workflows: AI is evolving from reactive chatbots to proactive agents (e.g., OpenClaw, Hermes) that can perform multi-step tasks, such as booking meetings or finding optimal travel dates, representing the next major leap in AI assistance.
- Security and Dependency Management are Critical: The increasing accessibility of AI tools means that 'everyone is a target.' Developers must prioritize security by pinning dependencies, using short-lived lease privilege tokens, sandboxing agents, and assuming prompt injection. The speaker cites incidents like the Shy Shy Hulud and npm package infections.
- The Developer Role is Changing: The primary developer activity is shifting from writing code to 'prompting, testing, reviewing.' Roles are evolving, with designers and product owners increasingly using AI tools (like Claude Code) to bypass traditional handoffs and accelerate development.
- AI in Communication and Process: The talk advises against 'AI slop' in professional communication. If using AI-generated content, transparency is key; users should be explicit about the AI's role (e.g., adding a robot emoji) and avoid automation bias.

## Technical details

- AI Tools and Platforms: Multiple AI models and tools were discussed, including Claude Code, GPT, Gemini, Anthropic, OpenClaw, Hermes, and Yak Shaver (an AI tool that converts recordings into a backlog/bug report).
- Development Workflow & Security: Best practices for mitigating AI-related security risks include: pinning dependencies, using short-lived lease privilege tokens, sandboxing agents to allow lists, and implementing MFA everywhere. The speaker recommends using tools like Renovate over Dependabot for dependency updates.
- CI/CD and Code Review: The trend is moving toward automated, agent-driven code reviews. Copilot Co-reviews can now approve a Pull Request (PR) if it doesn't modify a core tenant isolation control, indicating a shift toward automated quality gates.
- Data Integration and Reporting: AI can analyze data from multiple enterprise sources (GitHub, emails, Azure DevOps) to generate reports and presentations (e.g., using PowerBI reports over 'Eagle Eye' data), enabling non-developers to quickly derive insights.

## Practical implications

- Shift focus from writing code to mastering prompt engineering and architectural design.
- Implement robust security controls (pinning dependencies, sandboxing) to mitigate risks from AI-driven vulnerabilities.
- Establish formal processes for AI usage, ensuring transparency and human oversight in all communications and automated processes.
- Integrate AI tools into existing CI/CD pipelines for automated code review and quality assurance.

## Topics

Artificial Intelligence, Software Development, DevOps, Security Engineering, Productivity Tools, GitHub Copilot, Claude Code, Yak Shaver, Tina CMS, OpenClaw

Source: https://www.youtube.com/watch?v=Epyiqh19rH4
