Cycode has introduced Agentic Workflows, a new capability for its Agentic Development Security platform that enables AI agents to automatically detect, prioritize, and remediate security risks while keeping security teams in control. The launch is designed to help organizations secure AI-driven software development by enabling security operations to respond at machine speed without sacrificing governance or oversight.
Quick Intel
Cycode has announced Agentic Workflows, a new feature that enables AI agents to automate vulnerability detection, prioritization, and remediation across software development environments. The capability advances security operations from human-driven and agent-assisted processes to an agent-driven, human-controlled operating model.
As AI accelerates software development, organizations face increasing security challenges due to faster code generation, expanding attack surfaces, AI-specific vulnerabilities, and shorter windows between vulnerability disclosure and exploitation.
Agentic Workflows enable security teams to define automated workflows by specifying triggering events, AI-driven actions, confidence thresholds, and governance controls.
Once configured, workflows automatically execute whenever predefined events occur, including:
Organizations can determine which actions AI agents execute autonomously and which require human approval, allowing automation without compromising governance.
"Risk now moves at machine speed while security stays bottlenecked at human speed, and no team can hire its way out of that gap. Waiting for a person to notice each risk and start each response is no longer a viable way to operate," said Lior Levy, co-founder and CEO of Cycode. "Agentic Workflows remove that constraint without removing control. Agents triage and remediate the moment risk appears, and security teams set the scope and the boundaries of autonomy. This is how security finally becomes as agentic as the development it protects: agent-driven and human-controlled."
To simplify deployment, Cycode provides a library of pre-built workflow templates that organizations can use immediately or customize based on internal security policies.
Available templates support:
One example highlighted by Cycode is the exception management workflow. When a developer ignores a high-risk CVE with a known exploit, the AI agent automatically performs exploitability analysis. Depending on the results, the workflow either recommends accepting the exception or reopens the vulnerability if exploitability is confirmed.
Cycode positions Agentic Workflows as a new operating model designed to help security teams keep pace with increasingly automated software development.
By combining AI-driven orchestration with configurable governance controls, organizations can automate repetitive security tasks while ensuring critical decisions remain under human supervision.
The company says this approach enables security teams to scale vulnerability management and risk remediation without proportionally increasing staffing requirements.
Agentic Workflows are currently available through an early access program. Cycode will demonstrate the new capability during Black Hat USA 2026 in Las Vegas, showcasing how AI agents can automate security operations while allowing organizations to define the level of autonomy appropriate for their environments.
The launch reinforces Cycode's focus on securing AI-powered software development through automated risk management, governance, and continuous protection across the software development lifecycle.
Cycode is the leader in Agentic Development Security that secures AI development from prompt to runtime. Through unifying control, context, and autonomy in a single platform, Cycode continuously identifies risk across the AI development lifecycle, governs the AI tools developers use, correlates context across the entire software factory, and deploys and manages agents to prevent risk at AI speed.