AI

AI Writes 40% of Code Now. Here's What's Breaking

GitHub's own data says AI-assisted code has a 2x higher rate of security vulnerabilities in production. Everyone's celebrating the speed. Nobody's talking about the blast radius. I've got the numbers and they're ugly.

AI Writes 40% of Code Now. Here's What's Breaking

73% of developers are using AI coding tools daily in 2026. That's not a prediction. That's Stackoverflow's developer survey, published March 2026, 89,000 respondents.

Here's the thing. We're measuring the wrong thing.

Everyone's tracking how fast AI writes code. Nobody's tracking what happens six months later when that code is running your payment flow at 3am and PagerDuty is screaming.

The Number That Should Scare You

GitHub's internal research, leaked through a blog post they quietly updated in February 2026, showed that Copilot-generated code had a 40% higher rate of SQL injection vulnerabilities compared to human-written code in the same repos. Not in toy projects. In production codebases at companies with 500+ engineers who absolutely had code review processes.

I watched this happen firsthand. In 2024, we had a team of 12 engineers at a fintech startup processing $2M daily transaction volume. They went all-in on Cursor with Claude 3.5. Velocity went up 60%. Everyone celebrated. Eighteen months later we found an auth bypass in an AI-generated middleware function that had been sitting in production for eight months. The fix took one engineer four hours. The audit, the customer notifications, the compliance review cost us $340,000.

The code looked right. It passed review. It had tests. The tests were also written by the AI, and they tested the wrong behavior.

What the Adoption Curve Actually Looks Like

42% of all code merged to main on GitHub in Q1 2026 had AI involvement. That number was 4% in 2023. Think about that trajectory for a second. We went from experimental to majority contributor in 36 months, and our security tooling, our review culture, our testing philosophy hasn't moved at anything close to that speed.

Snyk's 2026 State of Security report found that repos with high AI code contribution had a mean time to detect vulnerabilities of 94 days. Repos with low AI contribution: 23 days. The theory is that AI-generated code is stylistically consistent enough that it doesn't trigger reviewer intuition. It looks like it belongs. Reviewers pattern-match on style, not correctness.

Don't do this. Don't let AI code skip the paranoid review just because it's readable.

The Productivity Numbers Are Real And Incomplete

McKinsey says AI coding tools deliver 35-45% productivity gains. I believe it. I've seen it. Junior engineers at Netflix-scale companies are shipping features that would have taken twice as long in 2022.

What McKinsey didn't measure: rework rate, incident frequency, on-call burden 12 months post-ship. Those numbers aren't in the report because they're hard to attribute and they make the ROI story complicated.

The real statistic nobody's publishing: teams that adopted AI coding tools without updating their definition of done are running 2.3x more production incidents than teams that didn't. That's from Datadog's engineering effectiveness survey, n=4,200 engineering orgs, published January 2026. Buried in appendix C.

What Actually Works in 2026

The teams I've seen get this right do one thing differently. They treat AI-generated code as code written by a very fast, very confident junior engineer who has never been paged at 2am and has no idea what your system actually does under load.

Review it like that. Test it like that. You'll be fine.

The teams getting wrecked are the ones treating it like a senior engineer who's already done the thinking. It hasn't. It's autocomplete with a marketing budget.

OPEN IN REEDL_ FEED →← Back to feed