Skip to content
back to the archive page
#AI

SonarSource’s State of Code Developer Survey (Category AI)

Image 1 of 1 for “State of Code Developer Survey report by SonarSource (Category AI)”

An interesting 57-page report from the maker of SonarQube, a code quality verification tool. Published on 8 January 2026, it is based on an October 2025 survey. Its main message: AI has not removed the burden from development; it has moved the bottleneck from writing code to verifying it.

The quantitative online survey covered 1149 respondents worldwide: adults in technology roles who write code or manage developers and had used AI at work during the preceding year. It asked how AI changes engineering, not simply whether people use it:

  • Where does AI actually help?
  • Where is the gap between adoption and effectiveness?
  • Do developers trust AI code?
  • How do security and technical debt change?
  • How do junior and senior engineers differ in their attitudes?
  • How are agents used?
  • How is this growing collection of tools managed?

The results:

  • AI is routine rather than experimental: 72% of those who had tried coding tools used them daily, and on average 42% of committed code was AI-generated or AI-assisted.
  • Value is uneven: documentation, explaining existing code and generating tests work best; refactoring and modifying existing code work less well. Remember that the survey preceded the major improvement in model capabilities in autumn 2025.
  • Teams juggle an average of 4 AI tools, and 35% of developers use some through personal accounts rather than approved workplace access.

Individual speed increased without a corresponding rise in trust. 96% do not fully trust AI code’s functional correctness. 95% spend time reviewing, testing or fixing AI output; 38% find it harder to review than human-written code; and only 48% always check AI-assisted code before committing. Unsurprisingly, respondents identified reviewing and validating AI code for quality and security as the most important skill of the AI era.

On risks, 57% worry about sensitive data leaks and 47% about new, subtle security vulnerabilities. Technical debt presents a mixed picture: 88% saw at least one negative effect, most commonly code that looks correct but is unreliable (53%) and unnecessary or duplicate code (40%). Yet 93% also saw benefits in documentation, tests, debugging and some refactoring. Junior developers rely on AI more and more often report that checking its code takes greater effort than senior developers report.

Company size matters too:

  • Small and medium-sized businesses gain more from faster delivery and improved time to market. Enterprises more often report better code quality and maintainability, apparently through stronger governance and AI risk controls.

The authors recommend tracking code provenance, strengthening review, adding quality gates and static analysis, and establishing effective governance for AI tools. Otherwise, what accelerates is unverified code production rather than delivery. And, of course, the authors’ SonarQube can help with all that :)

#Engineering #Software #DevOps #DevEx #Process #Management #Metrics