Survey: AI Coding Tools Outpace the Policies Meant to Govern Them
Organizations have adopted AI coding tools faster than they can govern them, with many saying they cannot tell which code was written by humans, according to a study commissioned by GitLab Inc. and conducted by The Harris Poll.
It surveyed 1,528 developers and technology buyers last April across six countries across North America, Europe, and Asia-Pacific, raising questions about whether their teams can control the code they are deploying.
More from WWD
The report defined AI accountability as the organizational capability to answer three questions about AI-generated code: Where did it come from? What was it meant to do? Who is responsible for it once it's in production? GitLab said most of the respondents could not answer the questions.
Speed is outpacing control, the study showed. Ninety-one percent of organizations have two or more AI coding tools in active use and 78 percent report that developers are writing and committing code faster since adopting AI tools. However, 43 percent said they could not reliably say which code was AI-generated and which was human-written.
Moreover, 73 percent of respondents are concerned about the maintainability of AI-generated code in their organization's codebase. Eighty-two percent said this risks creating a new form of technical debt their organization is not yet prepared to manage. Eighty-four percent agreed that the biggest challenge with AI -generated code is governing what happens to it after it's created .
"AI coding tools have delivered on their promise of speed. But the events of the past few months, including supply chain attacks, reliability issues, and regulators tightening expectations around AI traceability and provenance are making clear that speed without control is a liability, not an advantage," said Manav Khurana, chief product and marketing officer at GitLab.
There is also the question of traceability. Eighty-seven percent said they are confident they could determine within 24 hours whether AI code contributed to a production incident, and yet the 34 percent that did experience an incident in the past year could not tell if AI was partly to blame.
The majority (80 percent) agree that they adopted AI tools faster than their organization developed policies to govern them, with 44 percent calling AI-generated code a "top technology risk."
While the survey heavily focused on respondents in the tech industry (43 percent), as opposed to consumer markets (3 percent), the findings come at a time when advancements in AI like Anthropic's Claude Code have democratized what is otherwise a highly specialized function, allowing anyone to speak in the language of machines even without technical training or experience.
Coding plays an understated role in industries that are traditionally analog, such as the fashion industry. It's code, whether human-made or partly done by AI, for example, that runs shopping websites and develops softwares for virtual try-ons. Now that AI coding is "mainstream," as the GitLab report noted, the bigger question comes after AI has written the code.
"The teams thinking ahead are already asking the harder question: can we actually control all the code we're generating? The organizations that will ship trusted software faster are the ones building the foundations of accountability with context, traceability, and governance baked into the platform, not just bolted on after the fact," Khurana said.
Best of WWD
