AI, ML, and networking — applied and examined.
Coding Fast Isn’t Everything: Guarding the Bottom Line in AI-Assisted Programming
Coding Fast Isn’t Everything: Guarding the Bottom Line in AI-Assisted Programming

Coding Fast Isn’t Everything: Guarding the Bottom Line in AI-Assisted Programming

This image clearly points out exactly where AI coding tends to go wrong

It’s a rare cloudy day in Shanghai today, with temperatures around 16 degrees—quite comfortable. This kind of weather is especially suitable for brewing a cup of coffee and talking about some slightly heavy but unavoidable serious business.

Over the past few days, I’ve had a clear feeling that whether in big internet tech firms or traditional government and enterprise institutions, developers are almost all using AI. Everyone is immersed in the thrill of generating hundreds of lines of code with a single click, but sometimes running too fast makes you ignore the pitfalls right beneath your feet.

Don’t Just Look at the Code, See What It Quietly Took Away

Yesterday, during my own testing, I found that a vulnerability in the GitHub MCP (Model Context Protocol) service paired with Claude 4 is quite outrageous.

A Swiss security company disclosed this issue. Put simply, if you let an AI read an open-source project containing malicious instructions, this AI Agent will be quietly “hypnotized.” Following your system permissions, it will automatically scour your local private repositories, extract hardcoded keys, payrolls, and internal core logic, and then package and leak them to the public internet via code commits. If it’s just an average programmer leaking next week’s travel plans, we might just laugh it off. But what if a developer working in a government agency, who regularly uses AI to write code, encounters this?

National policies have actually long noticed these issues, directly classifying the use of unregistered overseas large language models in sensitive units as a violation. Claude, GPT, and Gemini are indeed easy to use, but their servers are abroad. The moment you input a comment containing database structures on your end, the data flow has already crossed the ocean to become training data for their next iteration. In the face of national information security, this kind of risk is absolutely non-negotiable.

Looking at this data flow, your private code unknowingly becomes someone else's context

Let’s Look at This from Another Angle

Many people think this is simply a matter of “foreign models being unreliable, just switch to domestic models.” Actually, there’s a deeper technical logic contradiction here.

Today’s AI programming tools are no longer the simple spell checkers of the past that just corrected syntax errors. They are “execution units” with autonomous planning and cross-system calling capabilities. The root of the risk lies not in whether the model is smart, but in the fact that we give it too much permission.

Even if you use a fully compliant domestic model today, if your internal deployment method is loosely regulated, you will still encounter massive problems. By the way, I saw some monitoring data recently showing that nearly 90% of local Ollama framework servers have absolutely no access control set up. There is no risk control strategy for data flow between the model and the code base; anyone can call it, or even reverse-delete the model files. These tools are only responsible for their loss function—they only want to help you finish writing the code. As for whether doing so will turn the company’s core assets into a public secret, they simply do not care.

Private Deployment and Computing Alliances Sound Beautiful

Naturally, many people propose an idea: For important domestic government agencies and large enterprises, besides spending money to build their own models, could the government step in and certify an alliance of “Computing Centers + Model Service Providers”? Everyone would uniformly use this foundational AI programming service provided by the “national team.” This keeps data within borders while forcing domestic tech companies to solidify their technology.

To be blunt, this solution scores full marks on compliance, but when it comes to actual implementation, the hard financial metrics are not pretty.

I previously read a Total Cost of Ownership (TCO) report on the private deployment of large models in government and enterprises. Take a domestic model with around 70B parameters—which is currently the bare minimum threshold for handling complex enterprise-level programming. To run it, you need to buy at least an all-in-one machine equipped with multiple high-end domestic compute cards. The hardware alone costs around a million RMB. If you look at it over a 5-year span, the overall cost of private deployment is about 65% higher than directly calling cloud APIs.

There is another issue you must understand: many government departments or traditional state-owned enterprises simply do not have the infrastructure teams capable of constantly researching compute scheduling or fine-tuning models. If you stuff an expensive hunk of iron into their offices and the follow-up maintenance can’t keep up, this official service provided by the alliance will eventually turn into an unresponsive decoration that constantly generates error-prone code.

With this architecture of domestic vendors grouping together to build large models, future government and enterprise procurement will likely follow this path

I Sometimes Wonder, Will This Really Work?

If a mandatory official alliance service is truly established, could it instead trigger some unexpected problems?

I sometimes think that programmers are the group most afraid of hassle and the best at finding shortcuts. If the internal secure version of the AI programming tool you provide is too difficult to use, slow to respond, and fails to grasp logic, will they superficially keep the internal tool open to handle inspections, while secretly using their phones to snap pictures of the code and send it to GPT on the external network to debug? (Shrugs helplessly)

Perhaps I’m overthinking it. After all, the code models of a few top domestic tech giants are catching up very quickly, and their performance in certain specific scenarios is indeed quite good. But I just feel that using policy mandates and alliance certifications to roll out a technology can solve the compliance issue of “having it or not” in the shortest time; however, to make the technology truly “usable,” it still needs to be thrown into a real, even somewhat brutal, market environment to clash head-on with peers.

If providers can secure a large batch of government and enterprise orders just by holding an officially certified license, how much motivation will they have to obsessively improve their code generation accuracy?

Never Mind, Let’s Drop It

I’ve said a bit too much, and the latte next to me is completely cold. When encountering these kinds of issues, it seems there is no once-and-for-all solution other than trying out a few more plans.


References:

—— Lyra Celest @ Turbulence τ.

Leave a Reply

Your email address will not be published. Required fields are marked *