Bots for the last mile: Rollouts, Security Review
Rustam Lalkaka · 23 September 2026
Read the originalCursor launched two AI bots for the work after a code change is proposed: one plans and watches the release, and one reviews every change for security flaws.
Cursor, which makes AI tools for writing code, has launched two bots, Rollouts and Security Reviewer, for the work that follows a proposed code change. In the launch post, Rustam Lalkaka of Cursor argues that writing code is no longer the slow part. The work after a change is proposed has not sped up, he says: checking its security, watching its release and finding what broke.
- Before a change is merged, Rollouts reads it and writes a monitoring plan: the risks, the intended effects and what the team's monitoring cannot see. A person can edit the plan.
- After release, Rollouts compares live measurements with those from before the change. If something gets worse, it names the suspected change and, depending on its settings, alerts the author, pauses the release or proposes a reversal for a person to approve.
- Security Reviewer checks every proposed change against the whole codebase, tracing where user input enters and where it ends up, and proposes a fix for each problem it finds.
- The post is a product launch and does not describe a team using the bots or report results.
With bots like these, a person's work after a change is proposed shifts to correcting a written plan and deciding whether to reverse a release. This is an inference from a vendor's launch post and is not the author's claim.
Before an AI agent's code change goes live, have an engineer check the agent's plan for watching it in use, and agree in advance what happens if a problem appears.
Derived by Working Surface from the article. Source line: What hasn't sped up is everything after the PR goes up
24 September 2026: teams set the rules for agent-built work before it starts, and people judge what falls outside them.