Harish Apuri, Mukesh Aurangabadkar, Shikher Goel, Madhan Mohan Reddy Chinthala, Charani Yepuri
Infrastructure as Code IaC is the accepted approach to provision cloud infrastructure declaratively. Still, misconfigurations in IaC remain the primary cause of cloud security incidents, accounting for 67 percent of all disclosed cloud breaches. However, the current set of countermeasures, such as rule-based static scanners, policy-as-code tools, and manual review gates, is inadequate to prevent such misconfigurations or to address them through autonomous remediation. In this paper, the authors propose a multi-agent generative AI system called GenSecOps, comprising four agents that work together to prevent misconfigurations in IaC. These agents are the IaC Understanding Agent IUA, which uses the IaC artefact to create a semantic resource graph; the Risk Prediction Agent RPA, which uses a hybrid model of the Transformer and Graph Neural Networks to create risk mappings; the Generative Remediation Agent GRA, which uses the risk mappings to create corrected policy-compliant IaC templates; and the Autonomous Enforcement Orchestrator AEO. Experiments on a corpus of 48,000 IaC templates Terraform, CloudFormation, Kubernetes show that GenSecOps achieves a misconfiguration detection F1 score of 0.934, a 73.2 percent reduction in critical findings overrule based baselines, an 81.5 percent improvement in mean-time-to remediate MTTR, and drift-recovery latency below 4.2 minutes. These results demonstrate that generative AI agents provide a viable, deployable foundation for self-healing, autonomously secured cloud-native infrastructure.