Skip to content
CodeDD Logo

AI in Development

Did anyone review the code AI wrote?

Coding agents now write a real share of most codebases. CodeDD measures how much of the estate — every repository in scope — AI wrote, whether a person reviewed it before it merged, and how much reached production.

Start for FreeBook a Demo

Trusted by

Beyond the adoption slide

Using AI is not the risk. Unreviewed AI code is.

Management can say the team uses Copilot or Cursor. The question is how much of that work landed in the product, and whether anyone looked at it first.

  1. How much AI wrote

    Lines and commits that name a coding agent. Deliberately conservative — a floor you can defend, not a vendor dashboard number.

  2. Whether a person reviewed it

    From commit to pull request, human review, approval, and production. The number that matters: AI code merged with no review on record.

  3. What is still waiting

    Open AI pull requests — how many, how old, and how many no person has looked at yet.

Work in flight

Paid for, not yet shipped.

Open AI pull requests have cost engineering time but delivered nothing yet. Old ones with no reviewer are work that may never land.

By repository

Which teams can report a real number.

Some repositories record which agent wrote what. Others have AI tools set up and no trail — unknown, not zero. That gap is a finding in itself.

Across the investment cycle

Where it changes the conversation

  1. Pre-deal tech DD

    Know how much of the product was written by AI without review — a quality and IP question before signing.

  2. Hold period

    Get the productivity of AI without the risk: require review on AI code, and track the unreviewed share coming down.

  3. Pre-sale preparation

    Show a buyer that AI-written code went through the same review as everything else.

Connect your Git host

  • GitHub
  • GitLab
  • Azure DevOps
  • Bitbucket

FAQ

Questions

What does “AI-authored” actually mean?

It is the share of committed work that names a coding agent. Only commits with evidence an agent wrote them enter the count, so the number is a floor — the team may be using AI more than git can prove. Vendor dashboards that count accepted suggestions measure a different thing, and we do not add those figures together.

Why might this look lower than what the team reports?

Many tools insert code under a human’s name. If the repository does not disclose agent authorship, the share is unknown — shown as a dash, not as 0%. A repo with Cursor or Claude Code configured and no authorship trail is a visibility gap, not proof the team writes everything by hand.

What is the delivery funnel?

It follows AI-authored code from commit through merge, human review, approval, and production. Each stage answers a different question: did it go through a pull request, did a person look at it, was it signed off, and did it ship. Approval and production are compared with merged code, not with the row drawn above them.

What does “merged unreviewed” mean?

AI code that reached the default branch with no human review on record. That is the governance figure — agent-written code that skipped a person. It is only shown when the Git host actually exposes review data, because “no review found” and “reviews are not visible” are different facts.

Why do some stages show unknown instead of a shortfall?

The funnel needs a Git connection to see pull requests, reviews, and deploys. If that data is missing, the stage is unknown — not treated as drop-off. Reading unknown as “AI code is bypassing review” would be the wrong conclusion.

How is this different from AI Native?

AI Native looks at AI inside the product: models, agents, wrappers, and how much of the shipped code is machine learning. AI in Development looks at AI in how the team writes and ships application code. A company can have little AI in the product and a large share of AI-written code, or the reverse. You need both.

How is this different from DORA?

DORA measures how often and how safely the estate ships. This view measures how much of what is written is AI-authored, and whether a human reviewed it before it merged. A team can have healthy DORA and still merge most AI code without a human review.

Do you name individual developers?

The portfolio funnel reports counts, not names. Repository views show which codebases disclose agent use, which tools are configured, and how old open AI pull requests are.

What data do you store?

Structured results: AI-authored line and commit counts, pull-request and review linkage, production landing where it can be observed, detected agent tools, and whether instruction files are present. Not source. Cloud audits overwrite raw source after analysis.

See the AI delivery funnel on an estate you care about

We will walk AI-authored volume, review coverage, and open pull requests on a repository set you choose — and separate a real unreviewed gap from missing Git data.