Literature review reveals variable productivity gains and persistent security vulnerabilities in software engineers, indicating a shift toward verification and architectural supervision.
The Impact of Artificial Intelligence on Software Engineering:Productivity, Code Quality, Security, and the Changing Role of Software Engineers Muzaffar AbdukadirovSoftware Engineering · 2026 Abstract Artificial intelligence (AI) coding assistants are changing how software engineers write, review, test, and maintain software. This paper examines the effects of AI-assisted development across four areas: developer productivity, code quality, software security, and the changing responsibilities of software engineers. The study uses a focused literature review of recent empirical studies and industry research, supplemented by practical observations from software development. Existing evidence suggests that AI can substantially reduce effort for some coding tasks, but the magnitude of the benefit depends on task complexity, developer experience, workflow, and the quality of the surrounding engineering system. Research also shows that faster code generation does not necessarily imply better overall software delivery. AI-generated output can require additional verification, testing, security review, and integration work. The paper therefore argues that AI shifts engineering effort from code production toward problem definition, verification, architectural judgment, security assessment, and maintenance. Rather than eliminating software engineering fundamentals, AI increases the value of skills that allow engineers to evaluate and control generated output. Keywords Artificial Intelligence; AI-Assisted Programming; Software Engineering; Developer Productivity; Code Quality; Software Security; Code Review 1. Introduction Artificial intelligence has become an increasingly visible part of modern software development. Coding assistants can generate functions, explain unfamiliar code, suggest tests, produce documentation, analyze errors, and support refactoring. These capabilities have changed the speed at which developers can move from an idea to an initial implementation. However, faster code generation does not automatically mean better software engineering. The central issue is therefore not whether AI can write code, but how AI changes the distribution of engineering work. A recent longitudinal study of professional software engineers reported that participants spent less time on many development activities and described a broader shift from creation toward verification and correction. The researchers characterized this emerging work as supervisory engineering. [1] At the same time, other controlled research has found that AI effects are highly dependent on the development context. For example, an early-2025 randomized study by METR found that experienced open-source developers took longer on the studied tasks when AI tools were available, demonstrating that perceived productivity gains cannot be assumed to apply to every workflow. [2] This paper analyzes the opportunities and risks of AI-assisted software development and argues that the engineer's responsibility remains central. AI can accelerate implementation, but requirements analysis, architecture, validation, security, and accountability still require human judgment. 2. Methodology This paper uses a focused literature-review approach. Recent academic studies, empirical research reports, and industry research concerning AI-assisted software development were examined for evidence related to productivity, developer experience, code quality, security, and engineering practices. Sources were selected for their direct relevance to software development and for providing empirical observations rather than purely speculative commentary. The analysis does not claim to be a systematic review or meta-analysis. Instead, it synthesizes selected recent evidence with practical software-engineering observations to identify recurring patterns and implications for developers and engineering teams. Because AI systems and developer workflows are changing rapidly, findings from individual studies should be interpreted within their specific experimental context rather than generalized to all software development. 3. AI and Developer Productivity AI can create substantial productivity gains for well-defined programming tasks. In a controlled GitHub Copilot experiment involving 95 professional developers, the Copilot group completed the assigned HTTP-server task 55% faster on average and had a higher completion rate than the control group. [3] Such results demonstrate that AI can reduce the time required for certain implementation tasks. However, productivity is not a single measurable property of software engineering. A developer may generate a function quickly while spending additional time understanding, testing, correcting, integrating, or reviewing the result. METR's randomized controlled trial provides an important counterexample: in the early-2025 setting studied, experienced open-source developers using AI took 19% longer on the selected tasks. [2] METR later reported that its subsequent experiment was affected by selection effects and provided weak evidence about the size of current AI speedups. [4] These findings suggest that AI productivity should be evaluated at the level of complete engineering workflows rather than by measuring only the time needed to generate code. Task familiarity, repository complexity, AI-tool quality, developer experience, and the cost of verification can all influence the final outcome. 4. From Writing Code to Directing and Verifying Work As code generation becomes easier, developers increasingly spend time defining problems, providing context, reviewing suggestions, and integrating changes into existing systems. The longitudinal study by Vella and Blincoe found that 82% of participants reported spending less time writing code and identified a broader movement toward verification activities. [1] This shift changes the practical role of the engineer. A developer must understand requirements before prompting an AI system, recognize incorrect assumptions in generated output, and determine whether a proposed implementation fits the architecture. A useful AI response is therefore not the final product; it is an input into an engineering process. 5. Code Quality and Technical Debt AI-generated code can be syntactically correct and functionally plausible while still being unsuitable for production. Problems may include weak test coverage, unnecessary dependencies, duplicated logic, inconsistent architectural patterns, and poor maintainability. Research from METR comparing algorithmic evaluation with manual review found examples in which AI agents produced functionally correct code that was not easy to use as-is because of issues involving tests, formatting, linting, and general code quality. [5] This creates a risk of shallow development: the volume of implementation increases faster than the team's understanding of the system. When developers accept large generated changes without tracing their behavior, they may struggle to reason about failure cases, concurrency, performance, and long-term maintenance. AI should therefore be used with small, reviewable changes and clear engineering constraints. Generated code should be evaluated against the project's architecture and conventions rather than accepted solely because it passes a basic functional test. 6. Security and Privacy Security is one of the areas where human review remains particularly important. AI-generated implementations can contain incorrect security assumptions involving authentication, authorization, input validation, database queries, secrets, file handling, and infrastructure. A 2026 empirical study of 44 developers working with security APIs found that AI assistance improved functional correctness but did not significantly improve secure API usage. The researchers also found that developers frequently did not recognize that their final implementations remained insecure. [6] Earlier qualitative research involving software professionals similarly found widespread use of AI assistants for security-related tasks while emphasizing the need to critically check AI suggestions. [7] Privacy must also be considered before using an AI service. Source code, customer information, credentials, internal architecture, and incident data may be restricted by organizational policy or contractual requirements. Engineers should understand the data-handling rules of the AI service they use and should never expose secrets simply to obtain a convenient answer. 7. Code Review Becomes More Important When code generation becomes cheaper, verification can become a bottleneck. Effective review of AI-assisted code should therefore examine both correctness and context. Reviewers should ask whether the implementation satisfies the actual business requirement, follows the existing architecture, handles invalid input and failure, respects authorization boundaries, and remains maintainable. Automated engineering controls can provide additional protection. Static analysis, type checking, dependency scanning, formatting, unit tests, integration tests, and continuous integration pipelines can identify common problems early. These controls do not replace human judgment, but they can make the verification process more reliable as the volume of generated code increases. 8. Skills That Become More Valuable System design Engineers need to understand service boundaries, data ownership, scalability, reliability, and architectural trade-offs. AI can suggest patterns, but it does not possess the complete historical and organizational context of a system. Debugging Generated code will fail in some situations. Reproduction, observation, hypothesis formation, log analysis, and independent verification remain fundamental engineering skills. Communication Clear requirements and constraints improve results whether the audience is a teammate or an AI assistant. Engineers who communicate precisely can direct
No takes yet. Share an insight, caveat, or question.
Abduqodirov Muzaffar (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: