Key Takeaways
- AI removed the traditional gate to software development, allowing more employees to build applications to solve their own business problems.
- This compounds risk as more builders can mean duplicated work, more access to sensitive data, and more tools with no owner.
- Expedient’s citizen developer layer gives builders an approved environment to work with the right guardrails already in place.
For decades, the number of people who could build software inside an organization was limited to a team of professional developers. Software builders not only had to know how to write code but they also had to know how to test it, secure it, connect it to enterprise data, and maintain it over time, limiting their numbers to a small team in many organizations.
AI changed all that almost overnight, both for developers and for employees.
Gartner predicts that by 2028, 90% of enterprise software engineers will use AI code assistants, up from less than 14% in early 2024.1 AI-assisted development has quickly become part of mainstream software engineering. But AI is also lowering the barrier to building software for everyone else, opening the door to the movement knows as citizen development.2
Today, an employees can simply describe what they want to do in plain language and AI will generate the application, the workflow, or the code behind it, often without ever writing a line of code themselves. The barrier to entry is no longer about whether you know programming language. It’s simply whether you know the problem you’re trying to solve.
When the Number of Builders Explodes
Citizen development is no longer a future trend. In fact, 89% of development executives say their organization is either implementing or planning a citizen developer strategy.3
So what happens when a handful of developers building software turns into dozens of employees building their own applications?
As more employees begin building applications, the potential for shadow AI grows. It becomes less about people using generative AI tools to answer questions and more about employees creating business applications outside IT governance, often with unknown dependencies, security gaps, unmanaged subscription costs, and growing technical debt.3
We touched on this shift from an infrastructure perspective in a previous blog—the great inversion.
More Builders, More Complexity
At first, it feels like a win. More people are automating work, building internal applications, and solving business problems without draining valuable IT resources.
Then the questions start.
- Who approved this application?
- Is it secure?
- What data can it access?
- Does it follow company policies?
- Who will maintain it?
- Did three different teams build the same tool without knowing it?
When a small development team built every application, knowing who owned it was clear, so those questions usually answered themselves. As software development spreads across the business, knowing what has been built, who owns it, and how it’s governed becomes anything but clear.
Why the Risk Compounds
The challenge companies now face isn’t about the number of builders they have. It’s more that every new builder is adding multiple new risks that have to be managed. Every builder added means an added set of credentials, new integrations, new connections to enterprise data, and a new application that has to be maintained.
A Safe Place to Build
The message isn’t to slow down the momentum around citizen development. Giving more people the ability to build software can deliver solutions faster, automate more business processes, and reduce the backlog on development teams.4
And trying to stop momentum like that rarely works. Instead it just moves development into the shadows where IT can’t see it. Instead of suppressing citizen builders, it’s more effective to give them a place to work that can answer any tough questions before they turn into problems.
That’s exactly what Expedient’s citizen developer layer is designed to do. Expedient AI CTRL Platform gives builders an approved environment to work with the right guardrails already in place: secure access to enterprise data, persistent storage, identity and access controls, and centralized visibility. Builders shouldn’t have to become security experts just to create an internal application.
With the right foundation in place, the tradeoff between speed and governance largely disappears. People naturally choose the fastest way to solve a business problem. Make the approved environment the easiest place to build, and citizen development becomes a driver of innovation and competitive advantage.
Can You See What’s Being Built?
If you can’t answer how many AI-built or employee-built applications are running across your organization today, that’s a question worth answering before it becomes the number grows even larger. Talk to Expedient about enabling a citizen developer layer at your organization with Expedient AI CTRL Platform.
FAQs
Does AI mean anyone can build software now?
Not exactly. AI lowers the barrier to building software using natural language to create applications, workflows, and code. With AI-based tools, employees no longer need years of programming experience to create business applications, but they still need secure, governed platforms to build responsibly.
Is citizen development just another way to say shadow IT?
No. Citizen development is a legitimate, governed way to allow employees outside of IT build applications using IT-approved tools and security controls. Shadow IT is when those same activities take place outside IT’s visibility or governance, potentially leading to security and compliance risks.
Does governing citizen development slow innovation?
No. Effective governance should remove friction, not create it. When employees have an approved environment with security, identity, and data access built in, they can build faster while IT maintains visibility and control.
Where should we start if we don't know how many citizen-built tools we have?
The first step is to understand what’s already being built, who is building it, what data those applications access, and which tools are being used. That baseline can help you identify security risks, duplicate applications, and opportunities to move solutions into a governed environment. From there, establish a secure platform where employees can continue building with the right guardrails already in place.
Sources
- Gartner, Gartner Identifies the Top Strategic Trends in Software Engineering for 2025 and Beyond, July 2025
- TechRadar, Are we vibe coding our way to a new legacy crisis?, August 2026
- Deloitte, Accelerate software development utilizing citizen developers, accessed August 2026
- Forrester, “Velocity IS The ****ing Strategy”: What Citizen Development Means For AI-Enhanced Businesses, August 2025