AI-Impact: AI transformed Amplified Creations by enhancing efficiency and establishing itself as a product foundation.
Security-Boundary: AI raised both development speed and security risks, requiring comprehensive measures and human oversight.
CTO-Leadership: AI informs every aspect of product development but requires human judgment for governance and accountability.
Senior-Judgment: Hiring now focuses on senior developers for their judgment and ability to manage AI-created complexities.
Development-Acceleration: AI has expedited development timelines significantly, transforming cycles and improving team output efficiency.
Pedro Thomaz is the founder and CTO of Amplified Creations, as well as the products in its portfolio.
We sat down with him to discuss AI's opportunities, as well as its critical security threats. Here's what he told us.
When AI "Clicked"
I'm Pedro, CTO, builder, and recovering "just ship it" developer.
I started in tech the way most do: writing code, delivering projects, and keeping clients happy. For years, I ran Amplified Creations, a creative and technology studio I cofounded in 2007, building custom software, virtual tours, and digital experiences for companies across Portugal and beyond. Good work. Solid work. But mostly execution mode.
Then AI happened. Not the hype wave, the actual useful part. The shift clicked for me at the end of 2023 while working on RVer, a VR healthcare system we're building internally.
We were creating immersive environments to reduce patient anxiety in clinical settings: hospitals, nursing homes, etc. When we layered AI into the system, something changed. Doctors, clinicians, therapists — the people who operate in a genuinely complex, high-stakes environment — became measurably more efficient.
That's when I stopped thinking about AI as a feature and started building it as the foundation.
Today, through Amplified Creations, I work with businesses across industries to help them apply AI where it moves the needle: operations, content, automation, and delivery.
A Need for Technical and Operational Boundaries

Amplified Creations is a unique blend of a creative studio, tech house, and AI consultancy.
We're a lean but senior team. Depending on a project's stage, we coordinate over 25 people, a mix of in-house staff and specialized subcontractors. Our organization prioritizes flexibility, not headcount.
Our product portfolio is varied. On one end, RVer — our in-house VR healthcare platform — runs on private, air-gapped infrastructure. Health data doesn't go to the cloud. Full stop. On the other end, our AI automation work for clients — Portuguese SMEs across retail, industry, and services — is usually cloud-native, deploys quickly, and integrates with their existing systems.
Architecturally, we're pragmatic. We don't have a religion about stack. We choose what fits the security model, client maturity, and the delivery timeline. This usually means cloud, but when the domain demands it, we build for private, secure, on-premise deployment instead.
Context-switching across all these areas creates complexity. Leading a team that ships a heavily regulated VR health system and a retail AI automation in the same sprint requires very clear boundaries — technically and operationally.
How AI Changes How CTOs Build and Govern Products
AI touches everything, but the final word is always human. Especially in health.
It affects how we build, what we deploy, and how we govern.
AI informs every layer: architecture decisions, code review, testing, backlog prioritization, incident response, and security review. We also run dedicated agents for development, code review, deployment, and client feedback loops.
For example, when a client flags a usability issue, it feeds directly into an agent that helps us identify the fix and implement it faster. The product gets more complex, but paradoxically, the team moves faster because agents absorb the overhead.
But AI operates as a highly capable draft machine, not a decision maker. A human reviews, approves or adjusts, and signs off. Every time.
In the case of RVer, this isn't just a philosophy. It's a regulatory reality. Infarmed - Portugal's health products authority - holds us to a standard where a misplaced comma in documentation can cost us our license. Wrong information surfaced by a code snippet and a slow incident response both carry consequences that no AI agent can be held accountable for. So we keep humans in the loop, not just for quality but for accountability. Someone always owns the outcome.
That said, the boundary isn't always clean.
How an AI-Powered Building Workflow Works
Here's how our AI-powered building workflow works.
It starts with an idea. Sometimes from the team, sometimes from client feedback, and increasingly from AI suggesting improvements based on identified patterns. Every idea goes to our medical team first. If it doesn't make clinical sense on paper, it dies there. We write no code.
If it passes that filter, we prototype fast. AI can produce a working MVP in a handful of sessions, so we don't debate ideas long. The prototypes become the discussion.
We build them, test them internally with both medical and technical staff, and let the results decide. If the prototype shows promise, we move to production.
Production means the team and AI code together — we bake in error logging from day one, feeding our back office in real time. When a new feature ships, we watch it live. The team reviews, approves, and pushes nothing until it's clean.
Why Claude Code Is Crucial for AI Development
Claude Code is the most important tool in our development stack.
It's not just a coding assistant; it's the closest thing I have to a senior developer available 24/7. It writes, reviews, suggests, catches errors, and integrates with everything through its plugin ecosystem.
Most AI coding tools do one thing well. Claude Code does the full loop from "here's a new feature idea" to "here's the code, here are the potential issues, here's what I'd watch out for in production." That's not a tool. That's a workflow.
If I had to rebuild everything from scratch with one tool in my corner, it's that one.
How AI Creates Security Risks

AI accelerates everything, including the people trying to break your systems.
We learned this recently when a client's third-party server infrastructure was compromised. We didn't manage their security, but their API keys lived in an AI system we built. The keys leaked. We helped them rotate credentials immediately, advised their server team on what to harden, and then rebuilt our own system's security layer from scratch. Even if their infrastructure gets hit again, the keys in our system are now significantly harder to reach.
This taught me not to lean on security we don't control. Own every layer you can, regardless of who manages what downstream.
AI turned the pace of development up to 11. It turned the pace of attacks up to 11, too. Same race as before, just much faster.
Why Technical Leaders Need to Understand That Security Is Not AI's Default
The example above might have played out differently if it had been a purely human-built system. Maybe. We'll never know. But I see it all the time in vibe-coded projects. And this reinforces something important: AI accelerates production, and if the humans overseeing it aren't rigorous, the gaps get bigger, not smaller.
Put another way, AI didn't cause those problems. The absence of a real engineer behind the AI did.
Because right now, every CTO needs to know that security is not AI's default.
When AI refuses to help you hack a government website, that's a values decision baked into the model. It won't do it. Full stop. But that same model will happily generate code that exposes API keys, skips MFA on a login form, or ships a .env file into a public repository because nobody told it not to.
Honestly, that asymmetry bothers me. If AI has the architecture to enforce ethical guardrails, it has the architecture to enforce basic security hygiene too. A first-time developer asking an AI to build their first app shouldn't need to already know what they don't know about security. The model should handle the baseline automatically: never commit secrets, always implement MFA for authentication, never expose sensitive config in compiled output, etc.
The same logic that stops AI from doing harm externally should stop it from creating harm internally. We're not there yet. And until we are, a junior developer with an AI assistant is still a junior developer, just shipping faster and making costly mistakes faster!
AI accelerates production, and if the humans overseeing it aren’t rigorous, the gaps get bigger, not smaller. AI didn’t cause those problems. The absence of a real engineer behind the AI did. Every CTO needs to know that security is not AI’s default.
How AI Changes Development Timelines
The results of AI have been significant. But so have the lessons.
On the upside, the numbers speak for themselves. Across client work, we've reduced administrative task time by up to 85% in some cases, and some tasks are now fully automated, making the question of "how much time did we save?" almost philosophical. Development cycles that would have taken six months now ship in three to four.
Internally, our development output is roughly 5x what it was pre-AI — measured in lines of code per session, git commits per day, and features delivered per sprint. The pace is genuinely hard to explain to someone who hasn't seen it firsthand.
And no one was let go. We're not big enough to discuss layoffs, but more importantly, it was never the goal. The thing that changed is what people do. The team that used to spend most of their time writing code now spends it reviewing, deciding, and improving. That's a better use of senior people.
How AI Shifts Hiring Focus to Senior Expertise

The old hiring question was, "What languages do you know?" That's now almost irrelevant. AI handles the syntax. What we hire for today is judgment.
Can you spot a security flaw in AI-generated code? What do you do if your AI system accidentally exposes a .env file? Do you understand why that matters? How do you review output you didn't write line by line?
In practice, we no longer hire junior developers. Not because we don't value people early in their careers, but because AI has absorbed the junior workload. AI writes the code. What we need is someone senior enough to know when it's wrong.
We now evaluate every developer we hire like a senior hire. Security awareness, critical review, professional judgment. The bar moved up because AI raised the floor.
How AI Removes the Moat of Complexity
Leaders underestimate how fast AI enables others to replicate what took years to build.
Consider SaaS CRMs as a case study. For years, the moat was complexity. The time, cost, and expertise required to build something comparable meant most companies simply paid the subscription and moved on. That calculus has changed. I've helped companies build their own CRM from scratch, tailored exactly to their needs, at a fraction of the long-term cost. No bloat. No features they'll never use. No monthly bill that grows every year.
SaaS companies that built their business on "this would take years to replicate" are discovering that's no longer true. Stocks reflect that.
This is the risk CTOs consistently underestimate. Not that AI will disrupt their industry from the outside, but that it quietly gives their competitors, clients, and even their own customers the tools to build around them.
If your defensibility relies on complexity and time-to-build, AI just removed your moat. The question is whether you noticed before someone else did.
Why the AI Job Apocalypse Is Nonsense
Here are four pieces of advice. And I mean all of them.
First: AI is a tool, not a worker. Even when it behaves like one through agents, automation, or autonomous pipelines, someone is accountable for what it does. A human needs to be in the loop. Not just for liability, but because the output is genuinely better when a thinking person is steering it. Never forget that.
Second: Humans built AI, so it has human-grade bugs. It hallucinates. It cuts security corners. It makes confident mistakes. Treat it like a brilliant but junior team member: incredible output, needs supervision. The moment you stop checking its work is the moment it quietly ships something you'll regret — or deletes your entire database!
Third: When configured correctly, AI is an absolute monster, in the best possible way. With the right parameters, the right context, the right guardrails, it can manage your calendar, answer calls, automate your back office, fix your family photos, fill your pipeline, and on and on. If a process involves a computer, AI can either do it or dramatically reduce the time it takes. The ceiling is genuinely hard to see from here.
Fourth: The AI job apocalypse is nonsense spread by people who never studied history. We've been here before. The Industrial Revolution. The assembly line. Industrial robotics. Every time, the prediction was mass unemployment. Every time, what happened was humans stopped doing the boring, repetitive, soul-crushing work and shifted to more creative, higher-value tasks. AI will do the same, just faster.
Yes, some roles will disappear. I've already seen it. Positions that once required specialist interpretation of data, a model now handles better and faster. But those people aren't redundant. They're freed.
Think about it this way: how many 10-year-olds today could build an app from their bedroom? Now ask the same question in a world without AI. The kid hasn't changed. Their ideas haven't changed. AI just removed the barrier between imagination and creation. That's not a threat, that's the best possible version of where this goes.
We just have to shift our mentality. Embrace it, explore it, build with it, and learn to live with it. The machines do the heavy lifting. We command them.
Follow Along
You can learn more about Pedro's work on LinkedIn. And check out Amplified Creations.
More expert interviews to come on The CTO Club!
