There's a quiet loop forming in a lot of teams right now, and almost nobody has named who's responsible when it fails.
An agent writes the PR. A second agent reviews the PR. A human clicks Merge because both bots said it's fine and there are nineteen other tabs open.
On paper it's beautiful. In practice, here's the number that keeps me up: GitHub reports developers finish coding tasks ~56% faster with AI — and the 2025 State of Software Delivery Report says 67% of developers now spend more time debugging AI-generated code, and 68% spend more time fixing AI-created security issues.
So we got faster at producing code and slower at trusting it. That's not a productivity win. That's debt with a shorter feedback delay.
Why "AI reviews AI" feels safe and isn't
A human reviewer and an AI author fail in different ways. That difference is the entire value of review. The human notices "wait, why are we deleting the audit log here?" precisely because they weren't the one who wrote it and bought into its logic.
When the reviewer is the same kind of model as the author, you lose that. They share priors. They share blind spots. They both find the confident-looking wrong answer equally plausible, because they were trained to. You haven't added a second opinion — you've added a louder echo.
Two models agreeing isn't verification. It's correlation. The bug that slips past the author is exactly the bug most likely to slip past the reviewer.
The accountability gap
Here's the part teams haven't priced in. In the old world:
- Author writes code → author is accountable
- Reviewer approves → reviewer shares accountability
- It breaks in prod → there's a name on the commit and a name on the approval
In the new world:
- Agent writes code → accountable to… whom?
- Agent approves → the approval is a rubber stamp with no skin in the game
- It breaks in prod → the human who clicked merge "didn't really write it"
AI generates code. Humans own outcomes. That sentence sounds obvious until you watch a team quietly stop reading diffs because the bot's summary is right often enough. The accountability didn't move to the AI. It evaporated — until 3am, when it lands entirely on whoever's on call.
What actually works (from watching this go sideways)
I'm not anti-AI here — I ship with agents every day. But the loop only stays safe if a human stays adversarial to it, not friendly:
- The human reviews the AI, not the other way around. Use the AI to draft the review — flag risky diffs, surface untested paths — then you make the call. Reviewer of last resort is a person, always.
- Gate on consequence, not on volume. Read every diff that touches auth, money, deletes, migrations, or anything hard to undo. Let the reversible stuff flow. You can't read everything; read what bites.
- Make the AI show its work, then distrust the summary. "Looks good to me" from a model is worth nothing. "Here are the three inputs that would break this" is worth something — and you still verify it.
- Keep one name on every merge. Not the model. A person who is saying "I looked, I own this." The moment that's a formality, the loop is unsupervised.
The uncomfortable truth: the faster the loop gets, the more judgment it demands from the one human still in it. Speed was 2025's flex. Knowing what not to merge is 2026's.
Be honest in the comments: when a coding agent opens a PR and another bot approves it, do you actually read the diff — or has "the bots agree" quietly become good enough on your team? 👇
I write about AI, building real things, and the honest ways they break. Follow me here if that's your lane. 👋
Top comments (1)
Some comments have been hidden by the post's author - find out more