AI Engineering Revolution: Winners, Chaos & What’s Next | FirstMark

3 Jul 2025 · 50 min · 29 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The rise of AI coding (code generation) and its effects on engineering productivity, reliability, security, and CTO decision-making; includes historical analogies (Gutenberg press, Ford assembly line, smartphones) and a “cleanup crew” pattern where new problems create new industries.

Guests

David Waltcher (FirstMark colleague; assembled a CTO-summit presentation; VC lens on AI engineering). Matt Turck (FirstMark; host).

Key claims

Coding is the fastest-growing genAI use case because of abundant training data (public GitHub), structured/precise language, pattern-based work, and clear ROI. Adoption is already widespread (82% of surveyed engineers using AI to write code). Throughput rises (30–50% faster), but downstream reliability/process metrics worsen: more debugging, more security vulnerabilities, higher CI flake rates, more build/test instability, and QA/code review overwhelmed.

Notable examples

Cursor ($500M ARR), Lovable (0→$60M ARR in two quarters), GitHub Copilot ($400M ARR; 15M developers), V0, Windsurf (rumored OpenAI sale; $100M ARR), Replit ($10→$100M ARR in six months). Historical examples: Gutenberg press misinformation/overload; Ford assembly line safety/infrastructure; smartphones privacy/regulation.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

AI Industry Growth Overview

0:00 to 0:10

Learn about the rapid growth of AI-related companies and their ARR.

“Cursor announced they're at$500 million of ARR.”

Key Trends in AI and Engineering

0:45 to 1:46

Explore the key trends affecting the engineering ecosystem due to AI.

“And what opportunities and challenges does that create for engineers, founders and investors?”

Historical Context for Generative AI

1:46 to 2:15

Understand the generative AI moment and the evolution of developer environments.

“Yeah, well, thanks so much for having me on.”

Impact of Historical Events on AI Development

2:15 to 3:58

Examine the historical events that have shaped the current AI landscape.

“So I'll start with pre-cloud when we used to just deploy code directly onto servers.”

Success Factors for AI in Coding

3:58 to 7:09

Discover the factors contributing to the success of AI in coding applications.

“So generative AI, this massive shift in delivery model, in the way that developers work, and one that I, you know, in this presentation really talk about being probably the most impactful thing on this page.”

Emerging Companies in AI Coding

7:09 to 10:21

Learn about the fast-growing companies leveraging AI for coding.

“I believe IntelliSense was created in 96 or something like that by Microsoft, which was already an automatic code completion.”

The Ongoing Innovation in AI

10:21 to 11:03

Discuss the continuous innovation in the AI landscape and its implications.

“And what's interesting is actually that is the setting where people are now growing up in an AI native way from an engineering standpoint.”

AI Integration in Engineering Processes

11:03 to 12:39

Understand how AI is changing engineering processes and the metrics involved.

“My argument in this presentation really is that behind all of the marketing gloss, there really is more substance than there ever has been before.”

Lessons from Historical Production Surges

12:39 to 14:00

Explore historical analogies of production surges and their effects on markets.

“Yes, but then there's that whole discussion of autonomous agents versus more of a sort of coding co-pilot.”

Historical Analogies in Production Surges

14:00 to 14:51

Learn how historical production surges lead to new markets and problems.

“And I think many of the best organizations and engineering leaders I talk to deploy all sorts of things across their stack, depending, again, on the use case and the people.”
Show all 29 chapters

The Gutenberg Press: Disruption and Challenges

14:51 to 16:40

Discover how the Gutenberg press revolutionized publishing and created challenges.

“this really was the advent of our ability to print books at scale.”

The Ford Assembly Line: Transforming Society

16:40 to 17:50

Explore how the Ford assembly line transformed transportation and produced new challenges.

“But if you can imagine then, they felt much more extreme.”

Modern Code Production and its Challenges

17:50 to 19:11

Examine the parallels between historical production surges and modern code creation challenges.

“If you think about code, I would argue we're very much seeing a similar trend where on the canonical DevOps cycle diagram, you're seeing code commit just accelerate so much.”

The Shift in Engineering Roles

19:11 to 21:51

Understand the evolving roles of engineers towards code reviewing in the AI age.

“To put some numbers to how these pressure points are starting to begin to explode, we're just seeing a lot more time spent debugging.”

Metrics of Engineering Output

21:51 to 23:45

Learn about the metrics used to evaluate engineering output in the context of AI advancements.

“You know, we did a study at FirstMark across, I think it was a little over 300 engineering organizations.”

Emerging Security Vulnerabilities

23:45 to 26:11

Explore new security challenges that arise from increased code production and AI.

“It re-anchors the reality of, okay, it's cool to have AI, but now what does that mean, right?”

Opportunities for Innovation in Engineering

26:11 to 28:00

Identify potential areas for innovation and investment in response to engineering challenges.

“And we see a ton of them across all of these spaces.”

The Evolving AI Landscape

28:00 to 29:16

Explore the rapidly changing landscape of AI companies and the challenges VCs face.

“Yeah, it's fascinating to think about all of this as a system where everything is interdependent and this keeps on shifting.”

Hiring Trends for CTOs

29:16 to 31:13

Discuss the significant shifts in hiring practices for software engineers and the rise of AI-related roles.

“And then most interestingly, I would say, you know, we've talked mostly about engineers themselves.”

Shifting Team Dynamics

31:13 to 34:24

Analyze how AI is reshaping team structures and collaboration in engineering.

“The idea of prompting, too, is just fascinating.”

Governance and Security Challenges

34:24 to 36:25

Examine the importance of governance and security in rapidly evolving AI systems.

“Like this notion that we would do like a peer review of that much code.”

Navigating Market Challenges

36:25 to 38:08

Understand the obstacles and opportunities present in the current AI market landscape.

“And then we've talked about security, but I think we'll see a lot of things that come out of this space that look very much like products that are actually catching bugs and problems at the time of write.”

Opportunities in the AI Market

38:08 to 42:03

Discover the potential for new startups and products in the evolving AI space.

“The more they serve customers, the more they lose money, which I think the industry obviously collectively hopes is just a moment in time that's related to a certain cost structure and then disappears at scale.”

The Cloud Opportunity Landscape

42:03 to 42:25

Explore the evolving opportunities in the cloud market and coding.

“well, AWS, Azure, and GCP came around and they ate up the whole cloud opportunity.”

Startups and the New Product Landscape

42:25 to 43:13

Discuss strategies for startups in the new AI-driven product landscape.

“and there are going to be a lot of products that exist to serve the new needs that come along with that.”

Building Credibility as a New Company

43:13 to 43:56

Learn how new companies can gain credibility in a competitive market.

“You see more reviews and love and hate for software tools in the B2B universe than you do sometimes for like mass market consumer phenomenons.”

The Shift in Who Influences Decisions

43:56 to 45:14

Understand the changing dynamics of decision-makers in tech.

“and in many ways it feels like we are at risk of being like a copycat world where you see some success online and then you go copy it the next day.”

The Developer Tools Dilemma

45:14 to 47:13

Examine the evolving perception of developer tools in the tech industry.

“So everybody wants to buy things that were bought by the most discerning people.”

The Evolving Definition of Developer Tools

47:13 to 49:04

Discover how the definition of developer tools has transformed over time.

“And so, like take HashiCorp, for example.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Cursor announced they're at$500 million of ARR. Lovable has gone$0 to$60 million of ARR in the last two quarters. GitHub Copilot,$400 million of ARR. There really is no plateau in sight for innovation. You might miss something spectacular and industry shifting. Welcome to the Matt Podcast. I'm Matt Turck from FirstMark. Today, we're doing something a little different. My FirstMark colleague David Waltcher and I sit down to unpack one of the key trends of the year, the rise of AI coding. We talk about key startups in the space, draw some lessons from history, and think through second-order effects on the rest of the ecosystem.

0:34With every surge in production, there's just a cleanup crew that naturally comes and a new market and industry that falls in its wake. If thanks to AI, everyone can now be a developer, then what does that mean for software, the role of the CTO, as well as the broad tech industry going forward? For CTOs, this is going to be sort of a hallmark moment for them over the next five years or so, where they have a lot of important decisions to make across talent, architecture, team structure, governance, principles, security. And what opportunities and challenges does that create for engineers, founders and investors?

1:06All of the problems that I'm talking about are very much our opportunities as investors and founders. And we see a ton of them across all of these spaces. I'll call out a few. This is a VC lens on one of the biggest stories of the year and very relevant for anyone trying to make sense of the ever-changing AI landscape. All right, David, excited to do this. Today, we're going to talk about a really hot topic, the impact of AI on engineering. So it's a little bit of a different format for this episode of the Matt podcast. We have a presentation. We're going to go through it and talk about it together.

1:42So I'll let you drive and get started. Yeah, well, thanks so much for having me on. So quick context, I was asked to pull this presentation together for the CTO summit that we threw last week. You know, I would say it is one of the most interesting times in engineering and this broader ecosystem of technology. And so maybe I'll just kick off the presentation with talking about a quick summary of how we've arrived to this generative AI moment in our engineering ecosystem by just giving a quick highlight of the six trends or so that have demarked the last two decades in the world of developers. So I'll start with pre-cloud when we used to just deploy code directly onto servers.

2:22A.k.a. prehistoric times. Correct. And then around, call it 2010, along with cloud, DevOps finally got coined, which was really the merging of dev and operations into this whole subsequent tool set and set of workflows that emerged around it, like Git, CICD, etc., that we all know today. And that very much spurred this generation of SaaS explosion. All of the small, mid, large cap companies today that we think of as being venture backed very much belong in that category of company. And then two sort of things between then and now that I think are worth noting. One is the proliferation of APIs, which essentially gave all of those SaaS applications the ability to very quickly expand their capabilities by almost outsourcing things like payments and messaging and search to companies like Stripe and Algolia and MessageBird.

3:17and then two is abstraction so you think about companies like HashiCorp and Sneak and dbt and Vercel very much catering to an audience of developers who are using code interfaces to all of a sudden do things that historically have been very much outside the purview of developer workflows and so think about infrastructure provisioning with terraform or think about dbt when all of a sudden we're now data engineering through a code interface and and over that time So from, call it, 2006 all the way to now, estimated about 7x growth in the number of global software developers, which I think of as sort of an index to this tech ecosystem.

3:58And that's where we've arrived today. So generative AI, this massive shift in delivery model, in the way that developers work, and one that I, you know, in this presentation really talk about being probably the most impactful thing on this page. It's interesting to think about why coding and development has been such a major success in generative AI. When people talk about, okay, what generative AI applications have been successful so far, coding seems to be number one by far. There is something about code that lends itself particularly well to AI. First of all, because there's tons of training data out there.

4:37So GitHub has been a godsend for AI training because so much of GitHub is public. So publicly available repositories. We're talking about hundreds of millions of repositories on GitHub. Two, the coding language, by definition, is highly structured and very precise. It's a grammar that you have to get right for the machine to work. And then three, it operates through patterns. which lend themselves well to AI training. And then four, that's a very clear ROI to all the things. So people spend a lot of time doing grunt work around coding. So anything that enables them to automate the work is incredibly impactful.

5:27Yeah, I think you nailed it. The first point you made is really interesting, which is this corpus of open source code that all of these models could use as training data, which is very much true. And actually, I think later in the presentation, we'll talk a little bit about some of the bad or somewhat negative effects of that corpus of data that those models have been trained on and how that's created specifically security concerns. The empirical nature of code has certainly made it a great early use case for AI. And then the last thing I'd say is just developers have always been the type of persona that loves to try new things.

6:05And so as a buyer and a user, they always made a ton of sense for AI. And obviously, you know, across the broader world of consumers, it's been well-documented that ChatGPT has made its way into, you know, millions of people's hands. So it's not to say that AI is not a mass market phenomenon already, but I think from an enterprise perspective, they've just been a great buyer for tools like this and the results have been very much measurable. Yeah, that's a really interesting thought. in that in some ways, generative AI has accelerated a behavior that already existed, meaning that developers have been using Stack Overflow for many years.

6:46So the idea of using somebody else's code or pre-existing code, copying and pasting, is not a new behavior versus a lot of other things that people outside of coding need to do with generative AI which is, you know, figure out how to use those things. In many ways, it's leveraging and existing behavior. And also, the concept of having code completion in the IDE is not new either. I believe IntelliSense was created in 96 or something like that by Microsoft, which was already an automatic code completion. So that may be another reason why adoption has been so dramatically fast. Yeah, absolutely.

7:32And so maybe to kind of exemplify a lot of what we've been talking about, we're about 24 months into this wave, give or take. It's changed a ton of behavior. It's taken our community by storm, but it's also just created a ton of really, really interesting special companies that have grown especially quickly. And so Cursor, maybe three weeks ago, announced they're at$500 million of ARR. Is that actually the fastest growing company of all time, maybe in B2B? I believe so. Lovable, which allows people to create prototypes and web apps through a series of prompts, has gone zero to$60 million of ARR in the last two quarters.

8:12GitHub Copilot, which I know you just had Thomas on the podcast not too long ago. $400 million of ARR, 15 million developers, very much the steward of this category, first mover. Yeah, exactly. The interesting thing that Thomas highlighted, among many other things, and this is really an episode worth listening to, was how they actually were thinking about AI when GitHub was acquired in 2018. So it's not just that they released Copilot a full year before the whole ChatGPT craze, but they had been thinking about it way ahead of time. I thought that was really interesting. And yeah, Copilot came out in 2021 running on Codex, which was the first coding model by OpenAI, which came out in 2021, I think, which was basically based on GPT-3 at the time.

9:09And recently has had a large resurgence in a new form. A couple other examples. So V0, again, you just had Guillermo on the podcast. Another great episode. Sorry, I'll stop shilling the podcast on the podcast, but that was phenomenal. He's such an incredible founder. Winsurf, which is rumored to have sold to OpenAI, hit$100 million of ARR quite recently. And then Replit, which went from$10 to$100 million of ARR in just the last six months. Yeah, after being at it for a solid 10 plus years. So I also had Amjot on the podcast, I promise. I'll stop now. But that was another great episode. He's such an incredibly thoughtful guy.

9:53And yeah, I mean, the story of Replit was that he was, from what I understand as an outsider and not an investor, pretty flat for many, many years with a little bit of a kind of like hobbyist student kind of user base. And when they launched their agent a few months ago, it's been, well, what you see on the screen here, this dramatic acceleration, such a wonderful story. Yeah, it's fascinating. You know, historically, they were known for being very much in the hobbyist indie developer educational setting. And what's interesting is actually that is the setting where people are now growing up in an AI native way from an engineering standpoint.

10:34And so in many ways, like doubling down and betting on that distribution channel over the long run has actually probably created the moment that they're having. Well said. So anyways, you know, point is just to say, like, this is a very special group of companies that is ramping quickly and has no sign of stopping. And there really is no plateau in sight for innovation. I mean, it's just, you know, for all of your listeners who spend their time on Twitter and TechCrunch and VentureBeat every day can feel quite overwhelming. Yeah, which is something that we as VCs certainly do not do. Never. My argument in this presentation really is that behind all of the marketing gloss, there really is more substance than there ever has been before.

11:12And if you, I hate to say this, but if you go offline and you aren't keeping up with the updates for a week at a time, you really might miss something spectacular and industry shifting. And so far, you know, we've seen really remarkable, tangible results across our network of engineering organizations. So hopefully this can just put some numbers to, at an organizational level, how code generation is really changing engineering process. We've seen a 30 % to 50 % faster throughput. We've seen 12 % increase in PR merges. This is a really important compounding stat here on the bottom left, which is a 17 % increase in the amount of time folks are spending on roadmap versus maintenance and keeping the lights on and support.

11:53And then in my mind, most impressively, 82 % of people we've spoken to are already using AI to write code. And so that is just, again, an adoption curve that is pretty much unprecedented. And I think, you know, we can talk more about why that is. But I think predominantly it lends itself, again, to the audience and the arena of distribution, IDEs, where people live today. These aren't net new interfaces for the most part, very much embedded in people's style of working. And again, with very similar distribution mechanisms and keystrokes and delivery models. And so it's just been a fascinating couple of years.

12:27On that note of people using AI, I guess there's another topic we could cover. But, you know, we've got to pick, we could talk about this for hours. So we've got to pick what we discussed. Yes, but then there's that whole discussion of autonomous agents versus more of a sort of coding co-pilot. And I think it's more shades of gray in between now. It used to be a little bit of a starker kind of distinction not that long ago. Now it looks like the co-pilots are starting to be agenic in many ways. But still, there's like this really interesting question in the industry where for the, you know, the cursors and the lovable on one hand, you have companies like Devon trying to build fully autonomous agents that basically go away and come back with a fully baked product.

13:22And, you know, which by all accounts doesn't seem to be working yet. But that seems to be pointing to a future that is pretty mind blowing. Yeah, I would say today what we're seeing is this spectrum of people and use cases that vary by experience and complexity. And for now, many of the agentic solutions that are truly end to end, you know, complete something are very much being pointed at lower level tasks that I'd say are, quote unquote, more mindless, that have less dependency, complexity, you know, that have less of a need for context and knowledge. And that's worked very well. So, yeah, there really is a diverse array of ways that you can apply AI to this problem.

14:05And I think many of the best organizations and engineering leaders I talk to deploy all sorts of things across their stack, depending, again, on the use case and the people. You know, I would say, despite all of these amazing numbers and stats, I want to pose sort of a historical analogy here to draw to this space, basically to say that with production surges, it tends to be the case that actually a lot of problems emerge. and in their wake, markets follow. Or maybe a punchier way to say that would be with every surge in production, there's just a cleanup crew that naturally comes and a new market and industry that follows in its wake.

14:39Yeah, so if you'll allow me, we're going to go back in time as far back as the 15th century and talk about a couple examples where we've seen this happen and how we might be able to draw some analogies to today. Let's do it. So starting with the Gutenberg press, this really was the advent of our ability to print books at scale. And so in the 1440s in Europe, we went from about 40 to 3.6K pages being printed per day. I think over the next 60 years or so, there were 20 million books in circulation in Europe, up from 3 ,000. Big disruption, right? It put monks out of business. The people that spend their entire lives copying by hand.

15:19Yes, they turned to making chartreuse. So anyways, this sounds like a great thing, right? I would hope we all love books. But actually, like many of the content issues that we see today, there were a lot of challenges that emerged, namely misinformation, mass reproduced quality issues, a bunch of informational overload. And so we saw a bunch of new industries emerge in the wake of the press, which were all the things that we think about when we think about books, printing, publishing houses, editors, libraries now for consumers to deal with the abundance of options that they have, almost serving as physical indexes of the many books that they could access.

16:01And then a bunch of regulation that came around around licensing and censorship. And again, all the things that we associate with content today. Another example, almost 500 years later, was the Ford assembly line. So in the early 1900s, Henry Ford invented the first continuously moving assembly line, and we dropped the time per car assembly-wise by almost 90%. And so over the next 20 or so years, the output of Model T's soared to about 10 million in the U.S. And we went from a society that was mostly horse and carriage, railroad and trolley driven to all of a sudden being a car country. So we still have car challenges today.

16:40But if you can imagine then, they felt much more extreme. Things like infrastructure strain, safety issues, the need to build all of the roads and infrastructure to support this new economy. factory workers' rights, environmental issues. And so again, we saw these industries emerge. I'll highlight the ones that feel very much endemic to auto. So quality inspectors, mechanics, dealerships, gas station attendants. And then on the regulation side, all the licensing, our driver's licenses, our license plates, traffic police, and again, all of the build out over the following 50 years or so of the freeways, highways, roads that we all use and drive on today.

17:17And so there are a bunch of other examples of this in history. I sort of arbitrarily chose those two, but railroads, map making, the postal system. I think smartphones is probably the most recent example where all of a sudden we have tons of compute in our hand and the ability to take as many pictures as we'd like in a day. And in its wake, you've seen a ton of industry emerge, mostly social media, influencer marketing, et cetera. And then all of the regulation around privacy and biometrics that still feels very top of mind today and that has been evolving over the last decade or so. And so, again, I would just posit, as production surges, you see all of these problems come in the wake of that production and then new industries come around.

17:59And so we didn't bury the lead here. If you think about code, I would argue we're very much seeing a similar trend where on the canonical DevOps cycle diagram, you're seeing code commit just accelerate so much. and today at least many of the processes that are downstream of that, our CICD pipelines, our testing suites, our build infrastructure, the way that we think about observability and monitoring has very much stayed the same, but it's kind of breaking. And so I'll talk a little bit more about that. Yeah, what happens next, yeah. On yet another episode of the Mad Podcast, just a couple of weeks ago, we had Brendan Humphries, CTO of Canva, who was talking about that exactly, which is okay.

18:47It's great that you can create code, but we had one guy who submitted a PR that was 50 ,000 lines, and they have a peer review culture, and they basically had to make the point that it was not okay to just lob over the fence 50 ,000 lines, and now good luck. Somebody's got to review it. So yeah, more code, now what? To put some numbers to how these pressure points are starting to begin to explode, we're just seeing a lot more time spent debugging. We're seeing a ton more security vulnerabilities, which we alluded to a little bit earlier when we were talking about how these models have actually been built and on what data.

19:27We're seeing a ton of performance issues emerge as a result. And, you know, I know you did your podcast with Guillermo. I actually did an event with Malte Uble, who's the CTO at Vercel. and yeah and that that event is on our guilds you know since this is turning out to be a shilling episode we can shill the First Mark guild so guilds are is the name for our private communities that we have at First Mark where we have a bunch of people on a per job basis from the portfolio but also from outside of the portfolio and this specific event was from our CTO guild and so you ran a sort of intimate fireside chat with the CTO of our cell, just for context.

20:09So this was a great event for our CTO guild. And Malte, among many interesting things, I think one of the most fascinating things that he said was that most of his great engineers who have been with the company for a while as they've dogfed, you know, V0 and they've used things like Cursor and Windsurf in-house is that many of his great engineers are actually becoming predominantly professional code reviewers. And this notion that as AI cogen has just totally increased the rate at which they're producing and outputting code commits. You need people who almost act as, you know, people sitting in a toll booth, letting cars pass or not pass, very much doing the same thing with code, but people in those seats that have great taste and know what bad or good or great looks like.

20:55And so I thought that was sort of the tip of the iceberg as you think about, you have these large engineering organizations that have all been trained somewhat similarly on how they should all think about working together and what sorts of jobs that certain people should be doing and not doing and how teams should work together. And we've seen this really, really fast shift where individual ICs who used to be, you know, green dots everywhere on their GitHub repo are all of a sudden becoming code reviewers. And so, yeah, I thought that was a really interesting analogy and I'll expand more on it, but.

21:27That's fascinating, right? So you used to have front-end engineers and back-end engineers and full-stack people. and yeah, there might be a future where people are none of that and just everybody's a code reviewer, which opens up this whole conversation about how do you become a good engineer in the future in this new age of AI and how people should be trained and all those things. But let's keep going. You know, we did a study at FirstMark across, I think it was a little over 300 engineering organizations. And we asked them just sentiment, basically, on CodeGen and how it's made them feel about certain metrics that they use to measure their engineering output.

22:08Yeah, so let's go through some of this, including for people that may be listening to this in a podcast-only version. So what are some of the metrics and numbers we have here? Yeah, so I would say everything in purple, unsurprisingly, which is positive, is very much linked to speed and efficiency and velocity. And so most of these stats are measuring in some way or another time, time spent to develop something, the number of times in a certain period that we commit, how often we're deploying. And so all of those things have been very much sped up in this age of AI. But what's interesting is many of those things don't take into account what happens afterwards.

22:50And so again, we could make as many commits as we want, but that's very much just the first step in the DevOps process as it exists today. In blue are most of the sort of negatively impacted areas across the survey that we did, which are mostly reliability and process oriented. And so like take mean time to restore, for example, if something goes down, how long does it take to restore it? Well, all of a sudden, if we don't have provenance over the piece of code that's relevant to something that happened, an incident, it's much harder for us to go back and say, oh, actually, there was a bug over there.

23:26And so that's been what's generally interesting. I think this slide really just goes to say, again, everybody's getting sped up. The amount of commits is skyrocketing. But all the stuff that we measure when we think about efficiency and all the downstream things that we want to happen post-code commit seem to be faltering. Yeah, I love it. It re-anchors the reality of, okay, it's cool to have AI, but now what does that mean, right? Yeah, so I can be a little more specific here in terms of what's breaking. Yeah, let's do it. We can start with security. Put simply, we're just seeing more security vulnerabilities than ever before.

24:02And new types of security vulnerability. Yes, I would say new types of security vulnerabilities, especially given, and this is sort of separate from the conversation about coding, but given deepfakes and all the stuff that's happening in the arena of email right now, certainly on that side, and then also in the world of CodeGen, to our earlier conversation, many of these models have been trained on really large bodies of open source code. And many of those pieces of code just share vulnerabilities and bugs that you can't see coming in the same way because, again, you're not operating with the same level of decisiveness and meticulousness.

24:41And so as a result, you're seeing things like CICD pipelines and build systems completely breaking. We're seeing, I mean, folks have had brittle CICD pipelines for a while now. We've seen a lot of companies emerge over the last decade to sort of ameliorate that and change the way that we think about CI and CD. But the flake rate is just much higher. And that's true of testing too. So flakes basically is just your ability to either trust or not trust a pass-fail result. And if you have a flake, it essentially means something passed and then it failed, but the inputs were the same. And so we're just seeing flakiness generally across code skyrocketing.

25:19I would say build has come under a lot of duress. It's just much harder in a cache code, which a lot of build tools try to do when Cogen is relatively stochastic. And so again, like the notion that given the same set of inputs or similar inputs, you're just not going to get the same set of outputs. And then QA and code review are areas that we've talked about. But we've seen QA processes just completely overwhelmed. And on the code review side, we're just seeing a new focus on code review that is pretty unrelenting, that I'd say has gone from a step in a process to very much a job in and of itself.

25:54Yeah, and I'm sure we're going to talk about it. But obviously the question is, to which extent can AI review AI? Unfortunately, for those people that are viewing the podcast that are engineers or practitioners, all of the problems that I'm talking about are very much our opportunities as investors. And founders. And founders. And we see a ton of them across all of these spaces. So I won't go into every single one, but I'll call out a few. On the security side, so there's a lot of companies, older companies, Fortune 1000 companies that use EOL software. So maybe they're on like a very old version of CentOS or, you know, maybe they're using a old package, old version of an open source library.

26:35And the notion that they could just upgrade is actually quite, it's a difficult thing to do. And so we're seeing a handful of companies that have actually pioneered what's called auto patching. And so the ability just to, instead of like forcing folks to make a potentially breaking change, just patch a project and let things stay status quo and smooth. That's a capability that you'd be shocked. There are thousands of engineers that have spent days, weeks, months trying to just keep something afloat because of an old dependency or an old package. Sounds brittle. Yeah. you know, across, I'll say QA, we're seeing a lot of interesting agentic solutions that are reasoning based on essentially semantic requirements.

Read the full transcript

27:24Better to almost tell the solution what the solution needs to be than to try to do any sort of like diff analysis or anything else that, again, given the stochasticism of AI actually might take you down a dark place. And then in code review, we're just seeing a lot of tools that are getting really fast adoption that are doing essentially agentic first pass checks for code. So yeah, the space is moving quickly. And I would imagine if we did another check-in in six months, we'd probably be talking about a whole new slew of problems, but also a bunch of solutions that have addressed many of the things that we've talked about today.

28:00It's moving fast. Yeah, it's fascinating to think about all of this as a system where everything is interdependent and this keeps on shifting. I'll use this a bit to shine some light on a handful of the companies across these different categories. We're VCs, so we have to do a little landscape and put logos in categories. Correct. This is what we do best. We'll find a better name for this at some point. The AI. Landscape. The mad landscape. You just throw this in the mad landscape, right? But yeah, it's been fascinating. And maybe I'll use this slide just to say this is one small sliver of the total companies in this market.

28:37And again, you know, back to the point about us being on Twitter and reading blogs and news articles, there are probably a dozen companies that come out every day that sit in this space. And so it's made this job both exhilarating and fun to spend time in this category. It makes things harder on the company side because there's so much noise. You need to just power your way through noise and for people to start noticing you, the bar is higher. So, you know, hype in the red hot market comes with pros and cons. Yeah. Yeah. And then most interestingly, I would say, you know, we've talked mostly about engineers themselves.

29:22But I think for CTOs, this is going to be sort of a hallmark moment for them over the next five years or so, where they have a lot of important decisions to make across talent, architecture, team structure, governance, principles, security. I wanted to take the opportunity, especially given we were talking to a room of CTOs, just to sort of talk through those things and see what's different. So I'll start with hiring and I'll share an anecdote that I had read recently, which is that computer science grads are actually among the top five or six majors graduating from college right now with the highest unemployment rate.

29:59which is, I mean, it is shocking. And, you know, I think it speaks in many ways to the fact that despite that there's a huge demand for software engineering as a concept, the people who are trained in that practice are actually not in high demand. And so, you know, I very much think whereas we used to focus on hiring these canonical 10x engineers and developers who can write code, We're seeing CTOs very much focused on hiring great editors and reviewers and prompt engineers who can almost shape and validate and curate that AI-generated output. The CEO of Canva was saying that while this is not the only reason that paused on hiring for a bit, in part to figure out what to do.

30:49As we alluded to earlier, then the question becomes, you know, how do you become a great editor or QA person if you don't write the code and build fundamental knowledge and habits around the core? how do you build the taste that you need to be able to review those things? It's a complicated topic. The idea of prompting, too, is just fascinating. So I was having an interesting conversation with an engineer the other day who was talking about the ability to one-shot Salesforce. And by one-shot, they mean, could I recreate Salesforce in just one sitting with one of these tools? I mean, obviously the answer is no.

31:35But if you ask why, it's mostly because actually like if you're trying to recreate something through a series of prompts, you actually have to really understand what it is that you're creating. And most of us, when we do that, we're starting visually. We think we understand, you know, maybe the database logic sitting underneath an app. But I mean, Salesforce is a fantastic example of a very, very complex, deep app with a ton of different use cases and integrations and reporting structures. And so, you know, it's not just the reviewing side, I think, that will evolve, but it's also just how we think about prompting and that being a skill set.

32:06So that is fascinating. I think on the architecture side, too, we're seeing a similarly sized shift where, you know, we used to sort of define these systems via design docs and then a bunch of human enforced conventions that might have sat in a Confluence doc somewhere to follow. Whereas today, we're seeing just this huge push to define systems in a very machine enforceable way, where you're almost setting these IAC-esque guardrails that AI can just conform to and see and know in a way that is much more stress-free for a CTO who's putting, I mean, let's say the 10 dev in engineers to work. So that is also an equally large shift.

32:48We alluded to this too. I'd say the third thing is team structure. So we used to, to your point about front-end engineers and back-end engineers, we used to just organize teams in a very structured way. And one of the fascinating things I think that's come out of AI, generally speaking, is we're just seeing companies and teams being able to do a lot more with a lot less. And I think that's especially true in the engineer context, which, you know, again, speaks to this college grad stat. But we're seeing smaller teams where some people just review and manage AI written code. and that's very much okay.

33:19And it spans from front end to back end to systems and everything in between. There is the whole question of what happens as you start getting product people to create code and functioning applications. And how does that fit? If everybody's a coder, this change of persona within the enterprise of like who actually produces code and the fact that it can in theory be everyone, what does that mean? Yeah. I mean, historically, EPD, engineering product design, has been a super complicated hierarchy system in companies where you have a ton of different handoffs between engineers and designers and product people.

34:02And company to company, it always looked very different whether product people interface directly with engineers at all, whether they were really there to ideate and then hand off entirely. And so to your point, as like the technical barrier to create something has dropped, it is straining and changing the way that those teams operate together quite a bit. And your story from Canva is exactly right. Like this notion that we would do like a peer review of that much code. There needs to be a change in the way that folks think about governance and this culture of reviews in general is changing very quickly.

34:39And to close the loop on that story, I think the punchline was that the CTO reinforced the fact that every pull review needs to be a few hundred lines, not thousands, certainly not tens of thousands, but that was the outcome. So do whatever you want with AI, but whatever you pull over the fence needs to be a few hundred lines. Yeah, enforcing constraints. A big thing we've seen come out of this is this notion of provenance, which is, in layman's terms, essentially the lineage of code. So who owns it? What are the dependencies? Where did it come from? And increasingly, again, with just the amount of volume that we're seeing across code in general, and then the new sort of sources of code that aren't coming from like specific human identities in an organization, this notion of provenance has actually been pushed to its outer limit and remains from a government.

35:32standpoint and for a bunch of downstream processes, just super important. The last two things I'll talk about are velocity and security. So on velocity, a lot of engineering folks have historically talked about eliminating bottlenecks. And so, you know, I mean, it could be any number of things that cause a bottleneck in that entire DevOps flow. Whereas now, very much there's a focus on containing this idea of entropy and then managing, from a governance standpoint, the coherence of AI systems to system architecture. That's been another really interesting theme. where you have these broad-based products that are being used by everyone, but everyone's stack looks very different.

36:09And how can you conform and give context to an AI product, especially in this world, for what it is that the constraints need to look like? And so we've seen from a velocity standpoint, these notions of entropy and coherence just much more important today than they were two years ago. And then we've talked about security, but I think we'll see a lot of things that come out of this space that look very much like products that are actually catching bugs and problems at the time of write. And that will be a very interesting shift in the ASPM world. So yeah, maybe to bring it full circle, again, to this analogy about productivity surges and booms, we see a ton of challenges that come from those historically and we see new industries come in the wake of those challenges.

36:55And I think we're very much for now seeing that in CodeGen. And so, you know, I'm as excited as I've ever been to be an investor in this space. I think it's rare to see problems happening as fast as the companies that are solving those problems grow. Everything is just moving so fast. And so, again, I think in six months' time, maybe we'll get back together and this will look either like something that's been completely solved or something where the problems have shifted in form factor completely. But, yeah, it's been fascinating. And it also feels like a lot of those companies that are doing incredibly well, to some extent, are also an experiment in the making, meaning that there are, from what we hear, a lot of unsolved issues in these companies.

37:44One is retention. There's a lot of use cases around prototyping and creating new things, but time will tell whether that sticks. As an industry, we don't know yet. And there's reportedly open questions around gross margins as well, which means that on a unit basis, a lot of those companies operate at a loss. The more they serve customers, the more they lose money, which I think the industry obviously collectively hopes is just a moment in time that's related to a certain cost structure and then disappears at scale. but it's not for the faint-hearted. Yeah, look, like many spaces in AI at the application layer, many of these products started out with what I would say are very simple delivery models of technology that wasn't quite their own with really smart distribution strategies.

38:39And I mean, in many ways, I think the IDE companies are pushing the outer limits of what zero switching costs could really look like. But what's interesting is now they all have a war chest of money, of usage, of talent, and they are going after much harder problems that are very much differentiated and proprietary. And so, you know, it will be fascinating to see how the space changes over time, but I would say the parameters with which we've, or within which we've operated thus far have been very much unique, right? I mean, we're talking about forking VS Code, which is - Which is what Croson did.

39:19That is not something that I would have seen coming if you had asked me in 2018 to imagine what generative AI would look like, right? But that has been thus far the most impressive business that's been built in this space. And they've done a phenomenal job. So what do we think that means for founders in the space? Do we think there's more opportunity, less opportunity? It's more complicated or clearer now, in particular vis-a-vis what the large companies are doing? Because, you know, certainly Microsoft has been making big moves. But, you know, Google has a bunch of products in the space. And there seems to be one more competitor somewhere every day.

40:04You were mentioning the pace of innovation. I think, you know, a couple of weeks ago, Mistral came up with their own code product, which was, you know, a combination of several pieces that they had before. But, you know, there's so many companies in the space. So is that a good space if you're thinking of starting a company or has the alpha largely left the room? I think it's always incredibly easy to say the alpha's left the room, especially if you're the person who wants to start a company and you don't know where to begin. Again, we talk about being overwhelmed by headlines. I couldn't imagine being a founder without an idea right now because at once there's a million things to go build.

40:46And on the other hand, there's also probably a million people trying to do it. look, I think you'll get very different perspectives on this. Developers have always been a very opinionated picky buyer. And that's created a lot of opportunity for a lot of different companies that start with very specific frameworks or ways of doing a certain task or a delivery model. And they get uptake if they are right, at least among a subset of people. And so I think it's rare and you know GitHub is a great counter example this which is a you know I mean it's almost like a consumer top a thousand Alexa domain it's probably much higher than a thousand but in general like you don't it's rare that you see ubiquity is what I'm trying to say in the world of developers so I still believe just on that alone there's a ton of opportunity left to go build something really interesting and then two I would say again it's a it's a market that's young, fast, but also huge.

41:42And to everything I've talked about in this presentation, a lot of the early opportunity, you could say the alpha is gone, so to speak. But all of the companies that have absorbed that and captured that have been moving at such breakneck speed that there's just a ton of derivative stuff to go do now. And so, you know, it'd be like saying, well, AWS, Azure, and GCP came around and they ate up the whole cloud opportunity. So I guess there's no more money in cloud anymore. Of course, that wasn't the case. It just meant that there were going to be all these new things that we needed around the ability to be cloud-based.

42:20And I mean, we could talk for hours about what those things were, but I think loosely that analogy holds where we have a new way of writing code and there are going to be a lot of products that exist to serve the new needs that come along with that. And certainly there's been a halo effect to those incredibly fast-growing products that have served products that were part of their stack. So famously, Superbase and Neon on the database side have had a massive sort of uptake based on the success of Cursor and Lovable. So there are strategies there for startups that are interesting. If you can get close to any of those products, there's some really sort of interesting derived velocity to gain.

43:12And this is the magic of like the Twitterverse and everything else. You see more reviews and love and hate for software tools in the B2B universe than you do sometimes for like mass market consumer phenomenons. And so, yeah, to your point, the ability to become part of the de facto stack for building a company in this era, whether it's on the database side with a Postgres database like Supabase or Neon or, you know, whether it's with the actual tool like Cursor that you're using to then write and deploy that code, that is a huge opportunity right now. And I think with this surge and people that are deciding to build something all at once, there is a good social proof element to what people want to be doing and what's been working and what's not.

43:55And I think that's, you know, we talk a lot here at Firstmark about what are the new ways that you can have advantages as a company, especially in a world where it's never been easier to build product. and in many ways it feels like we are at risk of being like a copycat world where you see some success online and then you go copy it the next day. But it feels like marketing and distribution and the ability to communicate directly one-to-one with your audience has never been more important. And a lot of the companies that we're talking about today do an exceptional job of that. And it's probably true of all big platform shifts, but in this one it's even more obvious than in prior ones.

44:31you can be a one-year-old or two-year-old company and actually be a lot more credible than a five, seven, ten-year-old company, which may be 10x, 100x your size. But because you're part of that platform shift and you're like AI native, people take you more seriously than they do, which must be infuriating for the older companies that are just bigger and have products that work. But that tension between like, you know, young companies with great demos on Twitter versus slightly older companies. We're not talking about companies that have been around for 100 years, you know, is kind of amazing to watch.

45:14So everybody wants to buy things that were bought by the most discerning people. And the notion of like who is the most discerning person just seems to ping pong around and change over time. So to your point, most people will care, at least in our world, what the smartest buyer at Cursor thought about a given tool than what the smartest person at the, you know, 80 billion software business that IPO'd in 2012 might think. Yep. And I mean, even in my 10 or so years of investing, it's been wild to watch the shift almost socially of like, who are those companies that everybody is looking at for guidance on the right way to do things or the right tool to buy for a certain space.

45:58And yeah, you're 100 % right. It's a very powerful thing to say some of these companies that we talked about today and many others are your customers or are your partners or are people that are willing to even put their name next year on an infographic. And so, yeah, it moves quickly and it changes often. And by the way, taking a step back from an investor perspective, it's fascinating that those most successful companies in the AI, generative AI world would be developer tools. Because, you know, historically, at least for certain VCs, there was a little bit of a love-hate relationship to DevTools.

46:35Sometimes it was a hard category. Sometimes it was an unloved category. but, you know, there was a perception that developers are difficult people. They're very hard to reach. It's very, they're cheap. They don't want to pay money. Therefore, it's hard to build big developer tool companies. And look, you could argue that between GitLab and Datadog and other companies, the proof was already in the pudding, but like this is a sweet revenge for anyone that ever doubted developer tool as a category. Yes, I think that sentiment has been shared widely. What's interesting to think about, too, is just over time how the definition of developer tool has changed.

47:20And so, like take HashiCorp, for example. It's a tool that very much, Terraform, is a tool that very much developers use. Super successful outcome, you know, recently sold to IBM for over$5 billion. dollars, I think it was six, seven billion dollars. And what's been interesting to watch and why I use that example is just, again, developers have been, while they have been cheap, so to speak, and picky and opinionated, their relative importance across organizations has seemed to just go up and to the right over the last decade or so. Their ability to make influential decisions on stack products, et cetera, really has seemed to change over time.

48:06And it's interesting to say that now, given now we're talking about maybe their skillset is less needed now more than ever. But I think developer tools in and of itself is sort of this loose category that very much used to be tools that developers use, and maybe that was limited to DevOps. And now it feels like it's tools that have development, either development implications or that have interfaces that developers use, whether or not they're for the development process. And that has yielded a much bigger set of companies. And so Stripe is a great example. Like Stripe is not a developer product in the typical sense.

48:37Like nobody, historically, nobody has thought of payments as a developer problem. But the magic of what that company was, was that they were able to cater it to developers and made it really easy to use and adopt and play around with in a sandbox. And yeah, I mean, we all know how that story played out. And so I think, yes, while they've been a hard group to sell into, I think if you can do it right and kind of capture that taste and that like feeling of capturing the moment, it has yielded some of the larger outcomes that we've seen across our world. Wonderful. Well, that feels like a great place to live it.

49:11David, thanks so much for doing this. This is fun. And indeed, the question is, you know, in six months from now, when we do this again, as we should, you know, will all of this be still true, partly true, will have completely changed in the context where stuff changes every week. Yeah. Well, thanks so much for having me. It was a treat. All right. Great. Thanks a lot. Hi, it's Matt Turk again. Thanks for listening to this episode of the Mad Podcast. If you enjoyed it, we'd be very grateful if you would consider subscribing if you haven't already or leaving a positive review or comment on whichever platform you're watching this or listening to this episode from.

49:48This really helps us build a podcast and get great guests. Thanks and see you on the next episode.

From the publisher

Welcome to a special FirstMark Deep Dive edition of the MAD Podcast. In this episode, Matt Turck and David Waltcher unpack the explosive impact of generative AI on engineering — hands-down the biggest shift the field has seen in decades. You’ll get a front-row seat to the real numbers and stories behind the AI code revolution, including how companies like Cursor hit a $500M valuation in record time, and why GitHub Copilot now serves 15 million developers.


Matt and David break down the six trends that shaped the last 20 years of developer tools, and reveal why coding is the #1 use case for generative AI (hint: it’s all about public data, structure, and ROI). You’ll hear how AI is making engineering teams 30-50% faster, but also why this speed is breaking traditional DevOps, overwhelming QA, and turning top engineers into full-time code reviewers.


We get specific: 82% of engineers are already using AI to write code, but this surge is creating new security vulnerabilities, reliability issues, and a total rethink of team roles. You’ll learn why code review and prompt engineering are now the most valuable skills, and why computer science grads are suddenly facing some of the highest unemployment rates.


We also draw wild historical parallels—from the Gutenberg Press to the Ford assembly line—to show how every productivity boom creates new problems and entire industries to solve them. Plus: what CTOs need to know about hiring, governance, and architecture in the AI era, and why being “AI native” can make a startup more credible than a 10-year-old giant.



Matt Turck (Managing Director)

LinkedIn - https://www.linkedin.com/in/turck/

X/Twitter - https://twitter.com/mattturck


David Waltcher

LinkedIn - https://www.linkedin.com/in/davidwaltcher

X/Twitter - https://x.com/davidwaltcher


FIRSTMARK

Website - https://firstmark.com

X/Twitter - https://twitter.com/FirstMarkCap



(00:00) Intro & episode setup

(01:50) The 6 waves that led to GenAI engineering

(04:30) Why coding is such fertile ground for Generative AI

(08:25) Break-out dev-tool winners: Cursor, Copilot, Replit, V0

(11:25) Early stats: Teams Are Shipping Code Faster with AI

(13:32) Copilots vs Autonomous Agents: The Current Reality

(14:14) Lessons from History: Every Tech Boom Creates New Problems

(21:53) FirstMark Survey: The Headaches AI Is Creating for Developers

(22:53) What’s Now Breaking: Security, CI/CD flakes, QA Overload

(29:16) The New CTO Playbook to Adapt to the AI Revolution

(33:23) What Happens to Engineering Orgs if Everyone is a Coder?

(40:19) Founder opportunities & the dev-tool halo effect

(44:24) The Built-in Credibility of AI-Native Startups

(46:16) The Irony of Dev Tools As Biggest Winners in the AI Gold Rush

(47:43) What’s Next for AI and Engineering?

More from The MAD Podcast with Matt Turck

All 44 episodes
AI Engineering Revolution: Winners, Chaos & What’s NextThe MAD Podcast with Matt Turck · 50 min
Listen in VO