AI in Development
Did anyone review the code AI wrote?
Coding agents now write a real share of most codebases. CodeDD measures how much of the estate — every repository in scope — AI wrote, whether a person reviewed it before it merged, and how much reached production.
98% of AI-authored commits matched a pull request — the funnel is well covered.
253,686
Lines written by AI
at least — provable from git
9,365
Human-reviewed
4% of merged
243,958
Merged with no human review
96% of merged
16,821
Reached production
7% of merged
AI-authored
Starting volume
Merged via pull request
of AI-authored
Reviewed by a human
of merged
Approved in review
of merged
Reached production
of merged
Trusted by




Beyond the adoption slide
Using AI is not the risk. Unreviewed AI code is.
Management can say the team uses Copilot or Cursor. The question is how much of that work landed in the product, and whether anyone looked at it first.
How much AI wrote
Lines and commits that name a coding agent. Deliberately conservative — a floor you can defend, not a vendor dashboard number.
Whether a person reviewed it
From commit to pull request, human review, approval, and production. The number that matters: AI code merged with no review on record.
What is still waiting
Open AI pull requests — how many, how old, and how many no person has looked at yet.
Work in flight
Paid for, not yet shipped.
Open AI pull requests have cost engineering time but delivered nothing yet. Old ones with no reviewer are work that may never land.
By repository
Which teams can report a real number.
Some repositories record which agent wrote what. Others have AI tools set up and no trail — unknown, not zero. That gap is a finding in itself.
AI delivery inventory
4
Open AI pull requests
68 days
Median age
3
No review yet
0
Merged, not yet in production
- <7d
- 7–30d
- 30–90d
- >90d
cube-command-center
72% authored
Claude CodeAGENTS.mdSKILL.md2 open PRs24 days
cube-pipelines
3% authored
Claude CodeNo skills on disk2 open PRs112 days
reports-svc
— unknown
CursorNo authorship trail0 open PRs
reports-svc has an AI tool set up but no record of what it wrote — unknown, not zero.
Across the investment cycle
Where it changes the conversation
Pre-deal tech DD
Know how much of the product was written by AI without review — a quality and IP question before signing.
Hold period
Get the productivity of AI without the risk: require review on AI code, and track the unreviewed share coming down.
Pre-sale preparation
Show a buyer that AI-written code went through the same review as everything else.
Connect your Git host
GitHub
GitLab
Azure DevOps
Bitbucket
FAQ
Questions
What does “AI-authored” actually mean?
It is the share of committed work that names a coding agent. Only commits with evidence an agent wrote them enter the count, so the number is a floor — the team may be using AI more than git can prove. Vendor dashboards that count accepted suggestions measure a different thing, and we do not add those figures together.
Why might this look lower than what the team reports?
Many tools insert code under a human’s name. If the repository does not disclose agent authorship, the share is unknown — shown as a dash, not as 0%. A repo with Cursor or Claude Code configured and no authorship trail is a visibility gap, not proof the team writes everything by hand.
What is the delivery funnel?
It follows AI-authored code from commit through merge, human review, approval, and production. Each stage answers a different question: did it go through a pull request, did a person look at it, was it signed off, and did it ship. Approval and production are compared with merged code, not with the row drawn above them.
What does “merged unreviewed” mean?
AI code that reached the default branch with no human review on record. That is the governance figure — agent-written code that skipped a person. It is only shown when the Git host actually exposes review data, because “no review found” and “reviews are not visible” are different facts.
Why do some stages show unknown instead of a shortfall?
The funnel needs a Git connection to see pull requests, reviews, and deploys. If that data is missing, the stage is unknown — not treated as drop-off. Reading unknown as “AI code is bypassing review” would be the wrong conclusion.
How is this different from AI Native?
AI Native looks at AI inside the product: models, agents, wrappers, and how much of the shipped code is machine learning. AI in Development looks at AI in how the team writes and ships application code. A company can have little AI in the product and a large share of AI-written code, or the reverse. You need both.
How is this different from DORA?
DORA measures how often and how safely the estate ships. This view measures how much of what is written is AI-authored, and whether a human reviewed it before it merged. A team can have healthy DORA and still merge most AI code without a human review.
Do you name individual developers?
The portfolio funnel reports counts, not names. Repository views show which codebases disclose agent use, which tools are configured, and how old open AI pull requests are.
What data do you store?
Structured results: AI-authored line and commit counts, pull-request and review linkage, production landing where it can be observed, detected agent tools, and whether instruction files are present. Not source. Cloud audits overwrite raw source after analysis.
See the AI delivery funnel on an estate you care about
We will walk AI-authored volume, review coverage, and open pull requests on a repository set you choose — and separate a real unreviewed gap from missing Git data.