Detecting Malicious Intent Across AI-Generated Pull Requests: A Governance Framework for Engineering Leaders
No single pull request has to look malicious to create a serious security problem. One adds logging. Another introduces a background job. A third...
14/07/2026
AI Code Review Is Not Enough: How Engineering Leaders Should Gate AI-Generated Code
The easiest pull requests to approve are often the ones that deserve the closest inspection. AI-generated code tends to arrive well formatted, well...
09/07/2026
Why Engineering Teams Keep Building In-House AI Code Review Tools, and What It Really Costs
LLMs made internal AI code review tools easy to prototype. They did, however, not make them easy to operate.
09/07/2026
Agentic Development Is Standardizing Faster Than Its Operating Model
Right now, an agent is probably opening pull requests against your production code. You may not be able to say which agent, who configured it, which...
08/07/2026
Repository Instructions Are Becoming Engineering Artifacts. Treat Them Like It.
Your team already treats CI config, dependency manifests, and policy files as things that need an owner, a review, and a drift check, because they...
03/07/2026
The AI Coding Maturity Scale: The Path to Loop Engineering
Over the last few quarters, we talked to hundreds of software teams about how they're actually using AI coding agents. What surprised me was that most...