Machine Learning & AI

AI-Powered Coding: Boosting Productivity or Introducing New Risks? Every CTO Must Know

July 15, 2026 - 3 min reading
ML Engineer
Share:
As 2025 draws to a close, AI-powered coding tools have become a staple in software development workflows. Tools like GitHub Copilot, Cursor, Claude-based agents, and emerging options such as Windsurf and Devin are now used regularly by 85% of developers, according to JetBrains’ State of Developer Ecosystem 2025 report. Stack Overflow’s 2025 Developer Survey echoes this, with 84% of developers using or planning to use AI tools up from 76% the previous year. In some projects, AI assists in generating up to 41% of code.These tools promise significant productivity gains, but the evidence is mixed. While many developers report feeling more efficient, independent studies reveal a “productivity paradox” where perceived speedups don’t always translate to measurable outcomes and can even lead to slowdowns.
AI usage

The Productivity Promise and the Paradox


AI excels at routine tasks like boilerplate generation, debugging suggestions, and documentation. JetBrains found that nearly 90% of AI users report time savings, with a fifth claiming to save a full workday per week. Google’s 2025 DORA report notes that teams heavily relying on AI see enhanced productivity and code quality.

Yet rigorous research paints a more cautious picture:

  • A randomized controlled trial by METR (Model Evaluation & Threat Research) in early 2025 tested experienced open-source developers on familiar repositories. Surprisingly, those using AI tools (primarily Cursor Pro with Claude models) took 19% longer to complete tasks despite perceiving a 20% speedup.
  • Faros AI’s analysis of over 10,000 developers showed high adoption but no clear company-wide productivity gains, with AI often increasing pull request sizes and review burdens.

The disconnect arises because AI boosts individual output volume but requires extra time for review, correction, and integration. Subtle errors in “almost right” code consume debugging time, offsetting generation speed.

The Rising Risks: Security and Quality Concerns

Rapid code generation amplifies risks, as models inherit patterns from training data including insecure ones.

Key findings:

  • Veracode’s GenAI Code Security Report analyzed code from over 100 LLMs across 80 tasks: 45% contained OWASP Top 10 vulnerabilities, with Java failing over 70% of the time.
  • CodeRabbit’s study of open-source pull requests found AI-generated code had 1.7x more defects in logic, maintainability, security, and performance.
  • Common issues include SQL injection, XSS, improper input handling, and hallucinated dependencies.
Risk statistics

Over-reliance also raises concerns about skill erosion, especially for juniors, and declining trust: Stack Overflow reports positive sentiment dropping to 60% in 2025, with 46% distrusting AI accuracy.

Best Practices: Maximizing Benefits While Mitigating Risks

Successful teams treat AI as an assistant, not a replacement. Leading recommendations include:

  • Thorough Review and Testing: Always scan AI code with static analysis tools and enforce human reviews.
  • Provide Strong Context: Use files like CLAUDE.md or GEMINI.md to document architecture and standards, improving output quality.
  • Start Small: Apply AI to isolated tasks before complex features.
  • Governance and Policies: Define usage guidelines, integrate security scans in CI/CD, and measure real metrics like cycle time.
  • Process Adaptation: Redirect time savings to high-value work like architecture.
  • Tool Selection: Match tools to needs Copilot for integration, Cursor for deep context with caution for agentic features.
code gets bigger and buggier

Looking Ahead

In 2025, AI-powered coding is a powerful but double-edged tool: invaluable for routine acceleration yet demanding vigilance on quality and security. As agentic systems evolve into 2026, thoughtful integration backed by governance and measurement will separate leaders from laggards.

For software teams, adopting AI responsibly isn’t optional; it’s essential for competitiveness in building reliable systems.

What’s your experience with AI coding tools this year?

References

  • JetBrains State of Developer Ecosystem 2025 
  • Stack Overflow Developer Survey 2025 
  • Multiple sources, including Index.dev and Second Talent reports  
  • Google DORA 2025 Report
  • METR Study on Early-2025 AI Productivity
  • Faros AI Productivity Paradox Report 
  • Veracode 2025 GenAI Code Security Report
  • CodeRabbit State of AI vs Human Code Generation 
  • Aggregated from enterprise guidelines in DX, Cerbos, and similar reports

Looking to scale your IT team with the best talent?

Request a free, no-obligation quote and find the right talent for your project.

Follow us :