AGP Picks
View all

DeviQA releases first QA-focused study on AI-generated code quality

Jul. 21, 2026
By AI, Created 13:28 UTC, Jul 21, 2026, AGP -

DeviQA has published what it calls the first large-scale industry report on AI-generated code from the QA perspective, based on a 300-person survey of testers and leads. The findings point to more bugs, heavier testing workloads and longer review cycles as AI-written code becomes a default input to software teams.

Why it matters: - AI-generated code is moving from experiment to routine input for QA teams, and the report argues that software quality risk is shifting downstream to testers. - The findings suggest organizations adopting AI-assisted development may need more regression testing, stronger review processes and more AppSec investment. - The report frames QA as the team that inherits defects developers miss, making the testing gap a practical issue for product reliability and release speed.

What happened: - DeviQA released State of AI-Generated Code: The QA and Testing Gap 2026 on July 21, 2026. - The report is based on a proprietary survey of 300 QA engineers, SDETs and test leads. - DeviQA says the study is the first sizable industry report to examine AI-generated code from the QA perspective rather than the developer perspective. - The report was fielded in 2026 through DeviQA's internal QA network.

The details: - 65% of respondents said their development teams actively use AI to generate code. - Another 16% said AI use is occasional. - 52% said bug volume has increased since developers began using AI. - 2% said bug volume has decreased. - 58% said their own testing workload has grown. - No respondent reported additional QA headcount being added in response. - 0 of 300 respondents gave AI-generated code a full trust rating on a five-point scale. - Mean trust across respondents was 3.16 out of 5. - LinearB data cited in the report shows a 91% increase in pull request review time in AI-adopting teams. - LinearB's dataset covered 8.1 million pull requests across 4,800 organizations. - The report says AI-authored pull requests wait 4.6 times longer for reviewer pickup than human-authored ones. - The report says QA is absorbing the review deficit downstream. - The report's defect taxonomy is led by logical errors at 58% of substantive respondents. - Unhandled edge cases appeared in 52% of responses. - Duplicated or redundant code appeared in 42% of responses. - Non-compliance with requirements appeared in 42% of responses. - The report says these are defect types that pass syntax checks and linters but surface under structured test execution. - Only 10% of respondents named security vulnerabilities among their top defect categories. - The report distinguishes that figure from external benchmark studies that have found vulnerability rates as high as 45% in AI-generated code. - The report says QA is not staffed to serve as the security net, which makes the result a role-clarification signal for AppSec planning. - Respondents described a pattern the report calls the regression amplifier, where AI-authored changes trigger failures in areas the change did not seem to touch. - Multiple QA respondents said they expanded regression scope beyond smoke testing because of that instability. - The report covers eight sections, including adoption patterns, defect anatomy, security exposure, review dynamics and operational recommendations.

Between the lines: - The report suggests AI code generation may be increasing velocity for developers while increasing verification costs for QA teams. - The lack of added QA headcount points to a possible capacity gap if AI adoption keeps rising. - The trust score and review-delay data together imply that human oversight is becoming the bottleneck in AI-assisted delivery. - The security findings do not mean AI code is safe; they suggest QA teams are seeing quality failures before they are seeing security failures.

What's next: - DeviQA says the full report is available via the link. - Organizations adopting AI-generated code may use the report as a prompt to reassess regression scope, review workflows and AppSec staffing. - The report's recommendations point toward tighter testing coverage and more explicit ownership of AI-specific quality risks.

The bottom line: - AI-generated code is now a QA problem as much as a developer productivity story, and DeviQA's report says testing teams are paying the cost in bugs, workload and review time.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Smart's Business Wire

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Smart's Business Wire

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.