With expert input from Andri Vanem, Head of Software Development at Netcorp.
AI-assisted software development has moved from an experiment to a regular part of how many developers work. AI tools can write code, explain unfamiliar systems, generate tests, and help with debugging, but their impact is far less straightforward than the productivity claims suggest. In the 2025 Stack Overflow Developer Survey, 84% of developers said they use or plan to use AI tools, and 51% of professional developers use them every day.
But using AI and getting results from it are two different things.
One controlled experiment found developers finished a small coding task 55.8% faster with an AI assistant. A different trial found experienced developers were 19% slower when they used AI on their own large, mature codebases. Both studies are real. They measured different kinds of work.
That gap runs through everything below. The research explains part of it. The rest comes down to how the tools are set up, how tightly they are controlled, and how clearly the work was described before anyone started. This guide covers both, with input from Andri Vanem, Head of Software Development at Netcorp, who runs these tools on production systems.
AI-assisted software development is the use of AI tools to support developers across the software development lifecycle: writing code, debugging, testing, documentation, and understanding existing systems.
The word "assisted" matters. AI produces a draft. A person reviews it, corrects it, and decides whether it ships.
Common uses include:
Popular tools include GitHub Copilot, ChatGPT, Claude Code, Cursor, and Amazon Q Developer. This is not the same as vibe coding, which means generating software from prompts without closely reading the output. Most professionals are not doing that: 72% of developers say vibe coding is not part of their professional work.
For companies adding AI features to their own products, Netcorp provides AI development outsourcing services with engineers who build and review these systems.
Sometimes, and by less than the marketing suggests. Here is what the strongest studies found.
The results suggest that AI's productivity impact depends heavily on the type of work and the development context. The METR study, in particular, found no productivity benefit when experienced developers worked on their own mature codebases.
There is a warning inside the METR result that matters more than the headline. The developers who were 19% slower believed they had been 20% faster. "The team feels faster" is not evidence of anything. METR later said developers are likely getting more productivity benefits from AI tools in early 2026, but cautioned that its newer data is too affected by selection effects to estimate the size of that improvement reliably.
Practitioners who control the setup tend to put the range higher. Asked whether juniors or seniors gain more from AI,Andri Vanem answered both at once:
“This is a perfect opportunity for juniors to learn. And for a senior, with the right tooling and instructions, you can be at least 40 to 50 percent more efficient in your work.” — Andri Vanem, Head of Software Development at Netcorp
Two things are worth pulling out of that. The 40 to 50 percent is an estimate from practice rather than a measured figure, and the condition attached to it is doing most of the work in the sentence. The same tools, without the right tooling and instructions, produce the METR result instead.
The second point runs against the common worry that AI removes the struggle juniors need in order to learn. He takes the opposite view, on one condition: someone senior still has to review what they ship.
AI can support every stage of development. The value comes from putting it inside a structured process, not bolting it on.
AI can summarise requirement documents, draft user stories, and flag technical risks early. It is also the stage developers trust it with least: 69% do not plan to use AI for project planning. Planning depends on business context the model cannot see.
This stage matters more than it looks, because everything left undefined here comes back later as code nobody asked for. Companies that need more capacity at this point can use a team extension model to add experienced developers alongside internal teams and AI tools.
AI is useful for exploring options: comparing technologies, explaining design patterns, drafting architecture documents. It should not be chosen for you. An AI assistant may suggest four ways to build a system, but engineers pick the one that balances scale, security, cost, and the skills your team already has.
This is where AI is used most. It writes boilerplate, builds standard components, explains code someone else wrote, and translates between languages. Speed here is real, but faster code is not automatically better code.
Testing is a useful area for AI assistance because it can generate test cases, suggest edge cases people might overlook, and help expand coverage. Netcorp provides software quality assurance outsourcing services to help companies hold quality standards steady as delivery speeds up.
This is where experienced teams stop, and the survey data agrees: 76% of developers do not plan to use AI for deployment and monitoring.
Asked where he will not let AI operate at all, Vanem is specific:
“Infrastructure management and live data. You cannot control all aspects, and one missing instruction can create irreversible chaos.” — Andri Vanem, Head of Software Development at Netcorp
That distinction is the one to borrow. In application code, a mistake surfaces in review or testing. In infrastructure and production data, a mistake can be permanent before anyone sees it. A sensible rule follows: AI can propose changes anywhere, but a person approves anything that touches live systems.
One of the most common frustrations, reported by 66% of developers, is AI output that is “almost right, but not quite.” and 45% say debugging AI code takes longer than writing it themselves. The usual explanation is that the model is unreliable. Vanem's experience points somewhere less comfortable.
“AI writes code as good as the coder using it. If you know what you want and you specify it, it is really hard to say that AI makes repetitive mistakes. It fills the voids you have left unspecified.” — Andri Vanem, Head of Software Development at Netcorp
That reframes the problem in a way that is more useful and less comfortable. AI rarely makes random errors. It makes confident assumptions wherever your instructions ran out, and those assumptions arrive looking like finished work. "Almost right" is usually a symptom of an incomplete brief, not a faulty tool.
The same principle explains the worst failure he describes, which came from giving an agent too much room rather than too little detail:
“The last time it happened was a year ago, when it screwed up the codebase by being an eager coder. It removed working code that was no longer available in git. It took almost three days to get it working again. But when you are in control of the AI agent and limit the context where it can operate, it is absolutely a huge gain.” — Andri Vanem, Head of Software Development at Netcorp
Both halves of that last sentence matter, and most teams only implement the second one. The conclusion is not that agents are unsafe; it is that they need boundaries. Two practical lessons follow from the experience: give agents a narrow, explicit scope rather than unrestricted access to a repository, and commit frequently so unwanted changes can be recovered more easily.
Veracode tested over 100 large language models across 80 coding tasks and found that 45% of code samples failed security tests and introduced OWASP Top 10 vulnerabilities. Java was the worst at around 72%. And it is not improving: Veracode's 2026 follow-up found that models improved substantially at producing functional code, while security performance remained largely unchanged.
Human involvement does not automatically eliminate the security risk. A Stanford study found developers using an AI assistant wrote less secure code than those without one, and were more likely to believe their code was secure. False confidence is the real danger, and it is the same pattern as above: code that looks finished gets less scrutiny than code that looks unfinished.
This is why the review step is not optional. DevSecOps services put scanning into the pipeline so these checks run automatically rather than depending on someone remembering to look.
AI writes code fast. It does not tidy up after itself. GitClear analysed 623 million code changes and found maintainability moving the wrong way: duplicated code blocks up 81% since 2023, refactoring down from 21% of changed lines in 2022 to 3.8% in 2026, and updates to code older than a year down 74%. The data points to more code being produced alongside weaker maintainability signals, a combination that can increase technical debt over time.
Google's 2025 DORA report surveyed nearly 5,000 technology professionals. 90% use AI and over 80% say it makes them more productive, yet higher AI adoption was associated with greater delivery instability. DORA's conclusion is worth repeating: AI amplifies the process you already have. Weak testing and slow feedback loops get worse, not better.
Before entering source code, customer data, credentials, or internal documentation into an AI tool, understand how the provider stores, processes, and uses that data. Data-use and intellectual-property protections vary by provider, product and plan. Before using AI coding tools with proprietary code or customer data, check the provider's current terms, training policy, retention settings and any applicable IP protections.
In outsourcing there is an extra layer, and in practice it sits with the client rather than the vendor. There is rarely one internal ruleset that covers every engagement, because each customer sets their own requirements for what may be shared with AI tools. If you are hiring a development partner, the rules are effectively yours to define. Agree them before the first line of code, not after.
This follows directly from how AI fails. Vague instructions do not produce vague code. They produce confident code built on assumptions nobody checked. The clearer the specification, the smaller the gap the model has to fill on its own, and the less review time you spend finding out what it decided for you.
Agents are more useful and more dangerous than autocomplete. Give them a defined set of files or a defined task, not open access to a repository. Commit frequently so anything removed can be restored quickly. Frequent commits can make unwanted agent changes much easier to recover from.
There is no need for a separate review track for AI code. Asked what happens to AI-generated code before it reaches a client project, the answer was short:
“It goes through the same code review process as any other line of code. It is basically a secure SDLC methodology.” — Andri Vanem, Head of Software Development at Netcorp
The simplicity is the point. The risk is not that AI code needs special handling; it is that it gets treated as pre-approved because it arrives looking finished. Automated gates make the standard hold at volume, which is what CI/CD services are for: security scanning, coverage checks and duplication detection running on every pull request.
A written policy is one of the capabilities DORA identified as making AI adoption succeed. Cover which tools are approved, what data can be shared, which parts of the codebase need extra review, and who is accountable when AI-generated code causes a problem.
The METR trial showed developers can be badly wrong about their own speed. Track four numbers before and after adoption:
If throughput rises while failure rate and duplication also rise, you are not faster. When teams need more capacity to do this properly, combining AI tools with software development outsourcing gives access to engineers who already work this way.
It depends on the task and the setup. Field trials across 4,867 developers found 26% more tasks completed. But senior developers working on their own mature codebases were 19% slower. Practitioners who control scope and write clear instructions report gains at the higher end, which suggests the setup matters more than the tool.
Not without review. Veracode found 45% of AI-generated code samples introduced a known security flaw. AI code should go through the same code review, scanning and testing as any other code.
Infrastructure management and live production data are the clearest limits, because mistakes there can be irreversible before anyone reviews them. Architecture decisions and security-critical code also need a person in charge.
AI-assisted software development can deliver real productivity gains, but those gains depend on the work, the codebase, and how the tools are used. AI is most useful for routine tasks, smaller features, and helping developers work through unfamiliar code. In mature systems and higher-risk areas, human judgment remains essential.
The strongest lesson from both the research and practitioner experience is simple: AI works best when developers stay in control. Define the work clearly, limit what an agent can access, and review its output with the same care as any other code. Used this way, AI can increase development capacity without lowering the standards for security, quality, or maintainability.
If you are deciding how to add AI to your development process, book an outsourcing consultation to talk through what makes sense for your team and your codebase.
Paavo Pauklin is a renowned consultant and thought leader in software development outsourcing with a decade of experience. Authoring dozens of insightful blog posts and the guidebook "How to Succeed with Software Development Outsourcing," he is a frequent speaker at industry conferences. Paavo hosts two influential video podcasts: “Everybody needs developers” and “Tech explained to managers in 3 minutes.” Through his extensive training sessions with organizations such as the Finnish Association of Software Companies and Estonian IT Companies Association, he's helped numerous businesses strategize, train internal teams, and find dependable outsourcing partners. His expertise offers a reliable compass for anyone navigating the world of software outsourcing.
Download the free copy of our "Software Development Outsourcing" e-book now to learn the best strategies for succeeding in outsourcing!
