You don't have an AI problem. You have a process problem.
3m read time

You don't have an AI problem. You have a process problem.

AI doesn't introduce new mistakes. It exposes existing gaps in your process. On source maps, pipelines, and why you can't outsource discipline.

Last week, something happened that started out completely innocuous. A package was shipped with something in it that shouldn't have been there. No sophisticated hack, no obscure exploit.

Just a source map.

In this particular case, it was the source map for Claude Code, Anthropic's new tool. The kind of file you normally don't think twice about, until someone opens it and suddenly has the complete original source code right in front of them.

Not a small snippet. Everything.

The pipeline trap ​

If you've ever built software that goes through a pipeline, whether frontend or backend, you'll recognise this. You build something nice, you add a step to your build process, then another. You quick-fix something along the way. At some point, you just trust that the process "is fine".

Until it isn't.

The interesting part? The AI did nothing wrong. The models worked perfectly. In fact, AI played virtually no role in the mistake itself. And yet it immediately feels like an "AI incident".

AI as a magnifying glass ​

What I see more often is that AI doesn't so much introduce new mistakes as make existing gaps in your process more visible. Or rather: more tangible.

Because AI agents now sit right in the middle of your workflow, they touch everything. They write code, execute commands, make decisions. As a result, they inevitably come into contact with the things we've been doing on autopilot for years:

  • Pipelines that "more or less" work.
  • Permissions that are "temporarily" wide open.
  • Build scripts that copy files a little too enthusiastically.

Those same pipelines decide how much your fastest developer actually delivers.

The "AI" label ​

There's nothing futuristic about this problem. If you strip away the AI component, you'd simply say: "Someone deployed a bad build." That's it.

But the moment the AI label gets slapped on, it suddenly feels heavier. More dramatic. Even though the root cause is entirely mundane.

That's not to say nothing changes. AI accelerates everything. Not just your output, but also the speed at which a mistake propagates. Where a manual error used to stay local, a mistake in an automated AI flow can now have an impact in ten places at once.

You can't outsource discipline ​

AI agents give you a sense of control. You ask for something, you get a result, and it works. That feels tight. But under the hood, nothing has changed about the foundation of your system. The shortcuts and the "we'll fix that later" mentality are still there. You just notice them less quickly.

AI makes many things better, faster, and sometimes even cleaner. But it doesn't improve one thing: your discipline. That's still something you have to bring yourself. Skip that step and you drift straight into copy-paste engineering.

Claude Code's source code shouldn't have ended up on the street because of a misconfigured setting in a package. That's the whole story. No complex analysis needed. But it's a good reminder that the real challenges aren't in what AI does, but in the foundation we build around it.

(1 of 40)
1You don't have an AI problem. You have a process problem.2Why you should never ship code you don't understand3Stop copy-paste engineering4The lava layer: why AI code is slowly petrifying your codebase5The brilliant parrot problem: what AI actually does when it 'thinks'6The prompt is not the spec7The bureaucracy of bots: why we are checking the checker8The day Claude deleted my production database9The arms race for your trust: Mythos, Cyber and the security hype10Stop letting your agents write Markdown11Your agent's suffering is your technical debt speaking12You can't spot the bug if you didn't write the code13One in four: the security debt nobody's counting14Your 10x developer is gated by a 0.1x pipeline15Benchmarks said frontier. Developers said "dumb."16Caveman vs context-mode: small mouth, or smaller room?17Code churn is the lava you can still measure18The ceiling is made of concrete19The token-saver tax: walking back my Caveman advice20Even the malware is AI slop now21ThePrimeagen was right22Tokenmaxxing is what happens when you measure the wrong thing23They just asked the bot nicely: your support agent is the attack surface24Speed got cheap. Judgement didn't.25Your coding agent has no world model. You built it one.26The Ferrari has a limiter: a day with Claude Fable 527The off-switch was never yours28An open MCP server is worse than an open database29The most resilient job is eating its seed corn30The off-switch works both ways now31AI writes the tests. Mutation testing checks if they work.32How to get better at reading code: a practice routine33Learning to program in the age of AI: what I would learn first34Who is responsible for AI-generated code? You are, and 2026 wrote it down35When not to use AI for coding: the tasks I still do by hand36Hiring junior developers in 2026: the collapse is a hiring decision37Software estimation with AI: the typing was never the estimate38Slopsquatting: checking that the package exists is not a defence39Eight reports, one bar: judging an AI safety sprint40Nobody's agent went rogue