AI-Generated Code
AI-generated code is source code written fully or partly by a machine learning model, usually a large language model (LLM), rather than typed by a developer. It ranges from single-line autocomplete suggestions to whole features produced by coding agents. It carries the same obligations as any other code: someone has to review it, test it and take responsibility for it.
How AI-Generated Code Is Produced
Most AI-generated code comes from one of three modes:
- Inline completion: the editor suggests the next line or block as the developer types, and the developer accepts or rejects it.
- Chat-based generation: the developer describes a change in a conversation and copies or applies the result.
- Agentic generation: an AI coding agent reads the repository, edits several files, runs commands and tests, iterates on failures and often opens a pull request.
In every mode the model predicts code from the context it receives: the prompt, open or retrieved files, project instructions and any linked documentation. It has no access to product decisions that are not in that context, so where the input is silent it fills the gap with a plausible default.
Why AI-Generated Code Matters
It changes the economics of building software: features that took days can be drafted in minutes, and people without deep programming experience can ship working prototypes. The risk moves from writing code to judging it.
Tool vendors are explicit about this. GitHub's responsible-use documentation says Copilot may generate code that appears valid but is not semantically or syntactically correct, and that developers should carefully review and test it. Research points the same way: in a user study published at ACM CCS 2023, Perry and colleagues found that participants with an AI assistant wrote significantly less secure code than those without one, and were more likely to believe their code was secure.
There is also a product-level risk. Code can be technically correct and still product-wrong: it adds a field nobody approved, changes how errors behave, or names the same entity two different ways. Over many generations these small deviations become specification drift. The usual controls are tests, human review, explicit requirements and requirements-to-code traceability, so each behavior can be checked against what was actually decided.
AI-Generated Code Example
A solo builder asks an agent to add CSV export to an admin dashboard. The generated code runs, the tests the agent wrote pass, and the file downloads correctly. A review against the requirement shows the export includes an internal notes column that the spec said must never leave the system. The code is correct; the product behavior is not. It was caught only because the requirement listed the exported fields explicitly.
Catching problems like this before the code is generated is cheaper than after. See how solo builders catch architecture flaws in requirements before AI builds them.
AI-Generated Code vs. Vibe Coding
Vibe coding is a way of working: describing what you want, accepting generated code largely without reading it, and steering by whether the result seems to work. AI-generated code is the artifact itself. It can come from vibe coding or from a disciplined workflow with specs, tests and review. The code is the same kind of thing; the level of scrutiny is what differs.