Most software teams now write code with an AI assistant open beside them. That is no longer a differentiator, and it is not the real risk. The risk is what happens to the code after the assistant produces it.
A longitudinal study published in July 2026 followed one enterprise software company after it mandated a doubling of developer output with AI tools. Code volume rose quickly. Review and testing capacity did not. The paper’s title summarizes the result: AI writes faster than humans can review. The bottleneck had moved from writing to reading, and the organization had not moved with it.
That gap is where problems collect. Code that nobody read closely is code that nobody fully understands, and the parts most likely to be skimmed are the parts that matter most: who is allowed to see which record, how a payment is confirmed, where a password reset link goes. An assistant produces code that satisfies the request it was given. It does not supply the unstated assumptions an experienced engineer applies without thinking.
Photo: Jakub Żerdzicki on Unsplash
The same pattern appears one level higher. Gartner has predicted that more than 40 percent of agentic AI projects will be canceled by the end of 2027, and it names three causes: escalating costs, unclear business value, and inadequate risk controls. None of the three is about how well a model writes. All three are scoping and governance problems.
For a business buying software, this changes which questions are worth asking a development partner. Asking whether they use AI tells you very little, because the honest answer from any competent team is yes. Better questions are these. Who reviews the code the assistant produces, and is that person someone other than the author? Which parts of the system get line-by-line review regardless of deadline? What has to pass before a change is accepted? Who is accountable when something breaks at two in the morning?
Our position is straightforward. AI tools draft; engineers decide. Every change is read by a second engineer before it is merged. Authentication, permissions, payments, and anything that touches customer data are reviewed line by line, and automated tests run before a change is accepted. The speed the tools provide goes into more careful review and tighter iteration, not into shipping unread code sooner.
A written scope supports all of this. When the deliverables, the exclusions, and the acceptance tests are agreed before development starts, review has something concrete to check against. Without one, faster code generation simply produces a larger pile of work to argue about.
Photo: Photo via Unsplash
The technology is genuinely useful, and it improves every quarter. The businesses that benefit most will be the ones that treat review capacity as part of the plan rather than an afterthought.