AI coding assistants have moved quickly from autocomplete to tools that can read a whole codebase, edit several files and run commands. Clients now ask development teams two questions about them, sometimes in the same meeting: are you using AI to work faster, and is our code safe if you do?
Both are fair questions. Here is how we think about the answers.
Where AI assistants genuinely help
Understanding unfamiliar code
Taking over an existing site usually means spending the first weeks understanding code someone else wrote, often without documentation. Asking an assistant to explain what a module does, trace where a value comes from or summarize how a feature is wired together saves real time. The answer still needs checking, but you start from a useful map instead of a blank page.
Repetitive, well-defined changes
Renaming an API across dozens of files, replacing deprecated function calls before a major version upgrade, converting configuration formats, or writing the tenth similar migration mapping. These tasks are clearly specified and easy to check, which is where assistants are most reliable.
Tests
Assistants are good at proposing test cases, including edge cases a developer might skip when tired. Writing the tests is often the part of a change that gets cut under deadline pressure, so making it cheaper improves quality directly.
First drafts of boilerplate
Scaffolding a new component, a form with validation or a small script. The assistant produces a first version quickly, and a developer shapes it to the project's conventions.
A second reader
Asking an assistant to review a change for obvious bugs, missing error handling or accessibility problems can catch some issues before a human reviewer sees the code. It does not replace that review.
Where they need a short leash
Security-sensitive logic
Authentication, access control, payment flows, input validation and anything handling personal data deserve particular care. Assistants can produce code that looks correct and is subtly unsafe, for example a permission check that works for the common case and fails for an edge case. In these areas AI output is a suggestion at most.
Architecture decisions
Choosing how a system should be structured depends on the client's team, budget, hosting, future plans and many things that are not in the code. Assistants will happily propose an architecture. Deciding is still the job of the people accountable for it.
Anything nobody can explain
If a developer cannot explain why a piece of code works, it should not be merged, regardless of who or what wrote it. This applies to AI-generated code exactly as it applies to code copied from a forum.
Best practices for client work
These are the practices we consider the baseline for any team using AI tools on code that belongs to someone else.
- Keep secrets out of prompts. Passwords, API keys, private keys, database dumps and production personal data should never be sent to an AI tool.
- Know where code goes. Understand what each tool sends to its provider, how long it is kept and whether it can be used for training, and choose tools and settings that fit the client's agreements.
- Follow the client's policy. Some organizations restrict AI tools on their code or allow only approved ones. Ask at the start of a project and respect the answer.
- Review everything. Every change should be reviewed by a developer who understands it before it reaches the client's repository. Using AI does not reduce responsibility for the code that is delivered.
- Keep tests and checks in place. Automated tests, linting and security scanning matter more, not less, when code is produced faster.
- Watch for licensing issues. Assistants occasionally reproduce code from public sources. Substantial, unusual snippets deserve a check before they are committed.
What this means for clients
The practical effect is not dramatic. Projects do not take half the time. The gains are uneven: large on routine, well-defined work, small or zero on the ambiguous problems that take most of the effort on real projects, such as unclear requirements, legacy integrations and decisions about trade-offs.
Where AI helps most is in the work that used to get squeezed: more tests, better documentation, more thorough upgrade preparation and faster onboarding onto unfamiliar code. Those are improvements clients feel later, as fewer regressions and easier maintenance.
If your organization has a policy on AI tools, or concerns about them, raise it with your development partner at the start. A good partner will explain how they work and adapt to your rules.
Have questions about AI and your codebase? Ask us and we will talk it through with you.