Software

AI made your developers faster and your codebase riskier

Time-to-PR is down 58%. Security vulnerabilities in that same code are up 15 to 18%. Both numbers are real, and pretending only one of them matters is how the second one compounds.

AI coding tools cut time-to-pull-request by up to 58%. The same research found AI-generated pull requests carry 15 to 18% more security vulnerabilities and wait 4.6 times longer in review. Both facts are true at once, and a rollout plan that only tracks the first is building a problem it cannot see yet.

Speed without a matching review capacity is not speed

The review-queue number is the one worth sitting with. If code generation accelerates by more than half but review capacity stays flat, the queue does not shrink — it relocates. Pull requests pile up waiting for the same human reviewers who used to keep pace with a slower input rate, and the vulnerability rate climbing at the same time means the backlog is not just larger, it is riskier per item. An organization that celebrates the PR-throughput number without funding the review bottleneck is measuring the wrong half of the pipeline.

The gains are not landing where you'd assume

Senior engineers are capturing roughly five times the productivity gains of junior engineers from these tools — the inverse of what most rollout plans assume. The instinct is to hand AI coding tools to junior staff to compress a learning curve; the data says senior engineers, who already have the judgment to spot a wrong suggestion fast, are the ones extracting the real value. That is not an argument against giving juniors the tools. It is an argument against expecting the tools to substitute for judgment the junior staff have not built yet — which is precisely where the extra vulnerabilities are likely entering.

What actually separates the teams that benefit

The frameworks separating disciplined AI-assisted engineering from the vulnerability-generating version in 2026 are not exotic: production-readiness gates, evaluation support, human-in-the-loop checkpoints, and security boundaries enforced regardless of who — or what — authored the change. None of that is new engineering discipline. It is the same code-review rigor good shops already had, applied without an AI-generated exception.

Track the vulnerability rate and the review-queue depth with the same seriousness you track velocity. A team that is 58% faster and 18% riskier has not gotten more productive. It has moved the cost from the calendar to the incident log, where it is larger and arrives later.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.