How AI Is Truly Changing Software Development

jean-dominique-quinet-profil-picture

Your developers are already using AI. That’s no longer the question. It has become part of their routine without any official decision. What matters today is transforming individual uses into a collective, measurable, and sustainable capability. Can you answer this question with numbers rather than just a hunch?

Everyone has the tools, but not necessarily the results

Copilot, Claude Code, Cursor, Codex: these tools write code, generate tests, document, and correct—and the trend extends beyond developers to include analysts, testers, and operations.

The DORA 2025 report finds that approximately 90% of tech professionals use AI, and more than 80% report increased productivity as a result. [1] But high adoption is associated with both an increase in delivery velocity and an increase in instability in production. We’re delivering faster but with less robustness.

A May 2026 CloudBees survey of more than 200 technical leaders confirms this tension: 61% of code is reportedly generated or assisted by AI, 92% of executives are confident in deploying it to production, and 81% report an increase in incidents related to this code. [2]

What METR Corrected

The 2025 METR study, which is still widely cited, found that developers were 19% slower when using AI, even though they expected to save 20% of their time. [3] In February 2026, METR revised its protocol after identifying a significant selection bias. The estimated slowdown drops to 18% for the initial cohort and 4% for new hires, with confidence intervals that cross zero. [4]

Two takeaways: the effect of AI depends on the task, the initial code, and the individual; no published average applies directly to your situation. And measuring this effect is difficult, even for a team whose sole focus is on this.

The bottleneck has shifted to code review

Code is being produced faster, but the human capacity to review it hasn’t changed. The Stack Overflow survey from late 2025, with over 49,000 respondents, shows 80% AI usage but confidence in accuracy has dropped to 29% (down from 40% the previous year). 66% spend more time fixing this type of code, and 75% end up turning to a colleague. [5]

DORA puts it bluntly: individual benefits do not automatically translate to organizational benefits. Here are four indicators to help you assess where you stand:

•          the time it takes for a pull request to be reviewed for the first time

•          the failure rate of changes and the time to recovery

•          the percentage of code rewritten or deleted within thirty days

•          post-delivery correction time relative to development time

If velocity increases while these metrics deteriorate, the problem has been shifted, not solved.

Bad news: security remains a real issue

According to Veracode (Spring 2026), only 55% of generated code passes security tests without explicit guidelines—a rate that has remained virtually stable for the past two years, while syntax correction exceeds 95%. [6] The breakdown: 82% success rate for SQL injection, 86% for cryptography, but only 15% for cross-site scripting and 13% for log injection. Security won’t come from the next version of the model, but from project guidelines, static analysis, and human review focused on high-risk areas.

Your best practices quickly become outdated

A prompt technique that was effective a year ago may be obsolete today. What has stabilized by 2026:

•          written specifications before deploying an agent, versioned along with the code

•          project context files maintained like code, reviewed via pull requests

•          automated evaluations with every change to the model or policy

•          agents running in isolated environments with limited permissions and traceable actions

AI amplifies what already exists

DORA identifies seven capabilities that enable an organization to truly leverage AI: a clear stance on AI, a healthy data ecosystem, data accessible to tools, robust version control, working in small batches, a strong user-centric focus, and high-quality internal platforms. [7] All of these capabilities predate the arrival of AI assistants. AI didn’t invent them; it made them prerequisites. A team that delivers in small batches and knows how to backtrack truly accelerates. A team with a fragile delivery pipeline also accelerates—and crashes into a wall.

We’ve already written about this in a previous article, “AI Accelerates Individuals. Who Accelerates Organizations?”, which discusses how teams need to rethink how they operate.

What if the assistant stops working?

On June 4, 2026, an incident with the Copilot code review tool caused up to 93.9% of requests to fail for one hour and twenty-five minutes, affecting approximately 36,800 reviews. [8] On August 6 and 17, new outages affected Actions, Pages, and Copilot, with GitHub itself attributing some of these issues to the load from AI-assisted development. [9]

A few hours of downtime are inconvenient; a few days become costly if no fallback plan has been put in place: the ability to switch models or providers without rewriting everything, and keeping team members who can deliver without an assistant.

Who will review this code in five years?

A study by Hosseini Maasoum and Lichtinger, based on U.S. data on resumes and job postings, found a 9–10% decline in entry-level employment in the six quarters following the adoption of generative AI, with no comparable effect on experienced workers. [10] Senior-level positions are built up from entry-level ones. Eliminating the tasks through which people learn will, within a few years, erode the ability to review code. This can be addressed through pair reviews of generated code, rotation through sensitive sections, and exercises without an assistant.

Traceability: Now, Rather Than in 2027

Regulation (EU) 2026/1744 of July 8 postpones the requirements for high-risk systems until December 2, 2027, but the transparency requirements of Article 50 have been in effect since August 2, 2026. [11] This is a postponement, not a cancellation. It’s better to implement traceability now rather than have to rush to get everything done at the end of 2027.

Five questions you should be able to answer by the end of the year

•          For which specific tasks have we measured a benefit, and how?

•          What is our average turnaround time before the first review, and has it increased over the past year?

•          What percentage of AI code undergoes automated security analysis before merging?

•          What do we do if our lead assistant is unavailable for three days?

•          Who will be able to review this code in five years, and how do we train them today?

We asked ourselves these five questions before you did. We didn’t have all the answers. That’s how FORGE was born.

At 5th floor

FORGE is the flagship project of our innovation department, created to extend this work beyond our own teams: a protocol for measuring actual gains, a repository of proven practices, a review and security framework, guidelines for agent usage, a documented fallback mode, and a plan for knowledge transfer to junior staff. TechRadar is the technological side of this initiative, and our iso-functional rewrites serve as the testing ground.

What we built for our teams, our innovation department now offers to our clients: a quantitative assessment of the seven DORA capabilities, role-specific training, team coaching, and program scoping.

If you’d like to compare your metrics with ours, let’s talk.

Sources

[1] DORA (Google Cloud), State of AI-assisted Software Development, 2025.

[2] CloudBees, The 2026 State of Code Abundance Report, May 2026, survey of over 200 technical leaders.

[3] METR, Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity, July 2025, arXiv:2507.09089.

[4] METR, “We Are Changing Our Developer Productivity Experiment Design,” February 24, 2026.

[5] Stack Overflow, 2025 Developer Survey, published December 29, 2025, with over 49,000 respondents.

[6] Veracode, “Spring 2026 GenAI Code Security Update,” 2026.

[7] DORA (Google Cloud), 2025 DORA AI Capabilities Model, 2025.

[8] GitHub, GitHub Availability Report: June 2026, July 2026.

[9] The Register, “Latest GitHub Outage Squeezes Actions, Pages to Death,” August 6, 2026, and “GitHub Has Issues as Repo Downloads Hit 50% Error Rate,” August 17, 2026.

[10] S. M. Hosseini Maasoum and G. Lichtinger, “Generative AI as Seniority-Biased Technological Change: Evidence from U.S. Resume and Job Posting Data,” SSRN, 2025.

[11] Regulation (EU) 2026/1744 of July 8, 2026, amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), Official Journal of July 24, 2026; European Commission, transparency obligations took effect on August 2, 2026.

Contributor(s)

Does this sound familiar?

Every organization has its own context, constraints, and pace. Let’s talk about yours. A one-hour conversation is often enough to map out the first leads.

Our latest publications