I don't see why they have to be mutually exclusive. Assuming the vendor risk profile is acceptable to the infosec people and procurement are happy with the AI tools vendor relationship, then it's a tool inside the information security perimeter.
As long as there's evidence that work meets quality gates for any required customer audits, and your customers are happy and in the loop that AI is a thing that may or may not be used to produce the service, then those engineers that want it can have it and those that don't, don't.
Feels like a revision to an SDLC rather than a new one. Without seeing the SDLC it's hard to find common ground though. It really depends on how it's written and implemented and of course: culture. In the example we're working from sounds like the tools are being forced on people, and that's less infosec, SDLC and more unbearably bad leadership.