More The Secure Disclosure episodes

PostHog is placing a wild bet on AI Coding w/ James Hawkins thumbnail

PostHog is placing a wild bet on AI Coding w/ James Hawkins

Published 15 May 2026

Recommended: Should you go open source?

Duration: 00:37:32

PostHog's open-source analytics platform prioritizes transparency, developer autonomy, and AI integration while critiquing corporate norms, emphasizing price clarity, building in public, and balancing automation with security governance in product development.

Episode Description

In this episode of Secure Disclosure, James Hawkins, the co-founder and co-CEO of PostHog, dives into the "radical transparency" that turned a pivoted...

Overview

The text explores PostHogs mission as an open-source product analytics platform, emphasizing its developer-centric approach, radical transparency, and rejection of corporate norms. The company prioritizes empowering engineers to analyze user behavior and influence product decisions, challenging traditional hierarchies where product managers dominate roadmaps. Its culture values direct access to user data, pricing transparency, and "building in public," while avoiding excessive meetings and promoting independent problem-solving. Engineering decisions are driven by technical expertise, with a preference for permissive open-source licenses to foster collaboration and accountability. The platforms evolution reflects a pivot from a narrow analytics tool to a broader development ecosystem, emphasizing simplicity and practicality in software tools.

A significant focus is placed on security in the AI era, balancing the risks and opportunities of AI integration. While AI accelerates productivity through code generation and automation, it also raises concerns about vulnerabilities, requiring robust governance and human oversight. The text critiques corporate inefficiencies, such as unproductive meetings and over-reliance on collaboration, advocating for streamlined workflows and smaller, experienced teams to maintain security and reduce technical debt. Open-source philosophy is central, with arguments that transparency flushes out security issues early, though challenges like dependency management and potential exposure to vulnerabilities are acknowledged. The discussion also highlights the shift in engineering rolesfrom routine tasks to strategic planningas AI automates repetitive work, while stressing the need for technical experts to ensure system reliability and avoid over-reliance on opaque AI tools.

The podcast delves into broader themes of product development, including the importance of feedback loops, long-term vision, and creating integrated solutions rather than fragmented tools. It critiques the "spiky" nature of AI, advocating for human-AI collaboration to balance innovation with systemic understanding. Future directions include evolving coding interfaces and collaborative workflows resembling hybrid human-agent teams, while emphasizing the role of trust, context, and iterative refinement in building scalable, user-focused products. Security remains a recurring priority, with a focus on cultural safeguards and targeted efforts over large teams, as the integration of AI into development workflows demands careful oversight to mitigate risks without stifling progress.

What If

  • What if you adopted a permissive open-source license for your core product, even if you plan to commercialize it later?

    • Move: Release your MVP under MIT or Apache licensing, with clear commercial usage terms.
    • Why now: The text argues that in the AI era, data, branding, and trust matter more than proprietary code. Open source builds community trust and accelerates feedback loops.
    • Expected upside: Reduced risk of direct competition, faster iteration via community contributions, and alignment with developer-centric culture (e.g., PostHogs transparency focus).
  • What if you integrated AI agents into your workflow to automate repetitive coding tasks, freeing you to focus on strategic design?

    • Move: Use AI tools (e.g., code generation, error detection) for 80% of routine tasks, reserving your time for architecture and product vision.
    • Why now: The text highlights that AI can automate 80% of repetitive work, allowing developers to shift focus to long-term planning and innovation.
    • Expected upside: Increased productivity, reduced burnout, and faster time-to-market for high-impact features.
  • What if you implemented strict dependency pinning for open-source packages, even if it slows down updates?

    • Move: Lock all third-party libraries to specific versions in your project, avoiding automatic upgrades.
    • Why now: The text warns against dependency risks (e.g., malware, breakages) and emphasizes security in the AI era. Pinning mitigates supply chain vulnerabilities.
    • Expected upside: Safer, more predictable codebase, reduced debugging overhead, and alignment with PostHogs cautious approach to security governance.

Takeaway

  • Adopt permissive open-source licenses (e.g., MIT, Apache) to reduce competition risks and maintain developer trust, as closed-source models are seen as ineffective for tools targeted at engineers.
  • Implement strict security guardrails for AI-generated code by integrating automated code review and auditing tools, balancing productivity gains with oversight to mitigate risks from AI's "spiky" capabilities.
  • Reduce redundant meetings and prioritize asynchronous collaboration, aligning with PostHogs rejection of excessive collaboration in favor of independent problem-solving and direct engineering decision-making.
  • Build feedback loops with users by leveraging session recordings, error logs, and surveys to iteratively refine product features, ensuring alignment with real-world usage and developer needs.
  • Focus on long-term security culture over large teams by fostering engineer autonomy in design choices and embedding security into engineering workflows, rather than relying on isolated security teams.

Final Notes

Here are some key insights and takeaways from the text:

Key Insights

  1. Empowering engineers: PostHog's open-source platform aims to empower engineers by giving them direct access to user behavior and allowing them to shape product decisions.
  2. Radical transparency: The company prioritizes radical transparency, which involves openly sharing their handbook, pricing, and more, to build trust with customers and employees.
  3. Challenging traditional roles: PostHog challenges traditional roles, such as product managers dictating the roadmap, and instead gives engineers a more direct say in product decisions.
  4. Security and AI: The company emphasizes security, particularly in the AI era, and explores ways to balance AI's capabilities with human oversight and system understanding.
  5. Automation and human-centric value: PostHog prioritizes automation but also emphasizes the importance of human-centric value, guiding users toward actionable insights rather than simply automating tasks.
  6. Long-term product vision: The company's long-term vision involves integrating AI with data models to create a "self-driving product" that can detect and resolve issues autonomously.
  7. Collaboration and adoption: PostHog encourages internal adoption of AI-driven tools, but also acknowledges the challenges of changing workflows and emotional attachment to existing tools.

Takeaways

  1. Engineering autonomy and responsibility: PostHog's approach prioritizes engineering autonomy and responsibility, allowing engineers to prioritize security and architectural decisions over arbitrary deadlines.
  2. Security governance in AI systems: The company highlights the growing importance of security governance in AI systems, including data protection and trusting the integrity of AI tools.
  3. Balancing innovation and practicality: PostHog balances innovation with practicality, acknowledging that current systems may offer flexibility but lack refinement.
  4. Long-term product development: The company's focus on long-term product development involves understanding product usage through feedback, building and refining products iteratively, and prioritizing complete product solutions over individual components.
  5. Automating routine tasks: PostHog expects AI to automate 80% of routine tasks, freeing humans to focus on creative, AI-resistant work.

These insights and takeaways are relevant and useful to readers interested in:

  • Understanding the future of product development and AI integration
  • Learning about PostHog's approach to empowering engineers and prioritizing security
  • Exploring the challenges and opportunities of AI adoption in the workplace
  • Gaining insights into how to balance innovation and practicality in product development
  • Discovering the importance of long-term product development and feedback-driven innovation

Recent Episodes of The Secure Disclosure

22 May 2026 AI Broke the Security Ecosystem w/ Chris Hughes

Evolving cybersecurity challenges include supply chain threats, AI vulnerabilities, and outdated tools, highlighting the need for systemic reforms like developer incentives, regulatory clarity, and industry-government collaboration to address gaps in vulnerability management and the dual risks of AI's role in both threat detection and exploitation.

6 May 2026 AI Panic is Driving Shadow IT w/ Noora Ahmed-Moshe

AI's impact on employment and cybersecurity risks, driven by shadow AI, phishing, and emerging threats like prompt injection, require balancing workforce skills, security measures, and organizational trust.

29 Apr 2026 When AI Agents Change their Intent w/ Frank Vukovits

AI agents, autonomous non-human entities operating in enterprise systems without human oversight, pose security and governance challenges requiring updated access control frameworks, real-time monitoring, and intent-based governance to address risks like unauthorized access and shadow AI, paralleling historical tech challenges like Y2K.

22 Apr 2026 OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

Gaps in cybersecurity education, persistent vulnerabilities like SQL injection, OWASP data limitations, evolving supply chain risks, high training costs, AI's contextual challenges, and the need for secure-by-design principles and collaboration highlight systemic challenges in addressing evolving cyber threats.

15 Apr 2026 The Future of Hacking is Agentic w/ Jason Haddix

Recommended: Security Testing will change, and might change quicker than this episode suggests. Keep Security Top of Mind during Development.

AI transforms security with automated penetration testing and threat detection, but requires human oversight to mitigate risks like prompt injection, ensure ethical use, and balance AI efficiency with creative problem-solving in an evolving threat landscape.

More The Secure Disclosure episodes