The AI Feature Your CTO Funded That Your Security Team Will Not Let You Ship
The post-mortem says "we found security too late." The actual finding is that security found you on time. Your process found security too late.
This is the AI feature that cleared the budget gate in January because the CTO and the CFO agreed the company needed an AI moment. It cleared a light legal review in March because it was a prototype. Engineering built against the agreed spec through Q2. In late July, the launch-readiness security review opened, and on day one the threat model came back with blockers on the auth scopes, the data-exfiltration paths, the model provider's residency story, and the prompt-injection surface. The team's quarter is now spent rebuilding to address findings that should have shaped the original spec. Two quarters of slip, an executive memo about "process improvements," and a quiet decision next planning cycle to "deprioritize AI deep-integrations."
The launch did not fail because security was slow. It failed because security entered after the shape of the feature had already been frozen.
