Krithi's gated, human-reviewed agents show where AI already belongs in the software factory.

Enterprise software engineering is the clearest place AI earns its keep today. Developers use these tools daily, three vendors have each crossed a billion dollars of annualized revenue, and the productivity gains show up in controlled studies, not only in marketing decks. The same evidence shows why enterprises hesitate: AI-written code fails security tests in roughly four cases out of ten, and most agent pilots never reach production.
lowtouch.ai's Krithi answers that hesitation directly. It runs requirements, coding, testing and deployment as one agentic workflow that stops at five points for a named person to sign off, and it is already modernizing production systems at companies including Thermo Fisher and Everest Re. For a CIO sitting on a backlog that budget and headcount never let past the wish list, the tooling and the governance model both exist now.
The gap between those last two figures, fast code and unreliable code, is exactly where a gated workflow earns its place.
Every model lab has made coding a headline focus, and Andreessen Horowitz's 2026 survey of enterprise AI spend explains why: coding already runs on a tight human-in-the-loop workflow, so a faster model is additive rather than a leap of trust. Code is also upstream of every other piece of software, so gains in generating it should eventually show up everywhere else a business builds.
IBM's own guidance on enterprise AI use cases singles out legacy application modernization as an area where these tools are especially valuable: migrating an old codebase to a modern language or framework, improving consistency, and cutting the manual errors that come from doing it by hand. That is precisely the kind of project most engineering organizations have wanted to do for years and never funded.
Adoption numbers keep climbing. The Pragmatic Engineer's February 2026 survey of 906 developers found 73% of engineering teams use AI coding tools daily, up from 41% a year earlier. Claude Code alone reached an estimated $2.5 billion annualized run rate by early 2026, with more than 1,000 customers each spending over a million dollars a year on it, according to Anthropic's own disclosures reported by Reuters.
Getting an agent from a pilot to a system that touches production code is a separate problem, and most organizations are still stuck on it. Northflank's 2026 analysis puts the pilot-to-production failure rate at 88%, and traces it to missing deployment infrastructure, isolation, governance and compliance controls, rather than to model quality. McKinsey's 2025 global survey found a similar split: 62% of organizations experiment with AI agents, but fewer than 25% have scaled one to production. ISG's 2025 State of Enterprise AI Adoption report put the figure at 31% of prioritized use cases reaching full production, double the 2024 rate but still a minority.
Forrester's 2026 guidance to CIOs and VPs of engineering: gains compound only when AI is applied consistently across the software development lifecycle, not bolted onto code generation alone, and governance has to scale with adoption.
Veracode's 2025 GenAI Code Security Report tested more than 100 large language models across 80 real coding tasks and found security flaws in 45% of the resulting code. Java came out worst, failing 72% of the time; the same code failed to defend against cross-site scripting in 86% of relevant samples. Apiiro's tracking showed AI-generated code introducing more than 10,000 new security findings a month across the organizations it monitors by mid-2025, a tenfold jump from December 2024. A 2025 USENIX study found that roughly one in five AI-suggested package dependencies do not exist at all, a supply-chain risk of its own.
None of this has slowed adoption, and none of it should. It does mean review cannot stay a courtesy step. Teams that adopted AI coding tools without changing their review process report review time rising by roughly 40 to 91% as diffs grow larger and defects grow subtler, which only pushes the bottleneck downstream instead of removing it.
"GenAI models make the wrong choices nearly half the time, and it's not improving." Jens Wessling, chief technology officer, Veracode, 2025.
A consensus is forming across security and engineering research on what governed AI coding actually requires. Industry writing on the shift from a traditional SDLC to what several vendors call an agentic development lifecycle agrees on one point: humans set intent and guardrails, agents handle execution, and the accountability for a change never moves from a named person to a model.
This is where the theory has to meet a real workflow. The next section walks through one that already runs this way in production.
Krithi is the agentic SDLC engine every Velocity Pod runs on. It carries a two-week sprint through five stages, with a human gate between each one, and an Orchestration Agent that keeps ticket and status data in sync with the client's existing Jira, or its own tracker if preferred.
| Stage | What it does | Gate |
|---|---|---|
| 1. Requirements extraction | Reads the legacy codebase and customer voice, drafts requirements with full traceability | Human review |
| 2. Planning | Turns approved requirements into a sprint plan and per-sprint tickets | Plan approval |
| 3. Coding | Builds each ticket into working code, merges to the dev branch | Repeats each sprint |
| 4. Testing | Runs automated UI, API and regression checks, opens the PR to main | QA sign-off, repeats each sprint |
| 5. Production | Merged to main by a human reviewer, live in the client's own environment | Human merge |
Set against the governance checklist on the previous page, the match is direct: a quality gate before merge, explicit human sign-off before, during and after agent work, and an audit trail on every ticket. Sprints that took two weeks close in about half a day once requirements, planning, coding and testing all move at agent speed.
Krithi is not a standalone product. It is the same platform lowtouch.ai already runs in production for SRE, finance, sales and compliance agents, pointed at the engineering backlog. ISO 27001, SOC 2 Type II, GDPR-ready and RBI-ready controls have been in place since that platform's first agent shipped, and Krithi inherits all of them. Its leadership built their careers on this kind of system, with prior roles spanning CTO and chief architect positions at major financial-services technology platforms.
The reinsurance client's migration is the pattern worth noticing: a database migration, a framework upgrade, a data pipeline rebuild, the kind of work every engineering leader has wanted to schedule and never had the budget or the specialist headcount to start. A gated agentic workflow is built for exactly this backlog.
Every Velocity Pod runs on Krithi, reviewed at every gate by a dedicated pod. A free sandbox evaluation runs against a real backlog item from the client's own codebase, not a demo script, before any further engagement is scoped.
Additional context: lowtouch.ai, Velocity Pods and Krithi product materials, v11.
Next step: Run the sandbox evaluation against a real item from your own backlog, not a demo script, and decide on a tier once you have watched the gates work. See lowtouch.ai/agents/krithi for the full agent specification.
Build grounded agents
See how lowtouch.ai turns enterprise rules, policies, and semantic context into governed agents running inside your appliance.
About the Author

Rejith Krishnan
Founder and CEO
Rejith Krishnan is the Founder and CEO of lowtouch.ai, a platform dedicated to empowering enterprises with private, no-code AI agents. With expertise in Site Reliability Engineering (SRE), Kubernetes, and AI systems architecture, he is passionate about simplifying the adoption of AI-driven automation to transform business operations.
Rejith specializes in deploying Large Language Models (LLMs) and building intelligent agents that automate workflows, enhance customer experiences, and optimize IT processes, all while ensuring data privacy and security. His mission is to help businesses unlock the full potential of enterprise AI with seamless, scalable, and secure solutions that fit their unique needs.