AI-Assisted Software Development: Coding Agents in PracticeCode review, migrations and CI integration · Lesson 10 of 17

Code review with AI, and reviewing AI code

Article · 13 min · 9 min lecture

Video lecture

Code review with AI, and reviewing AI code

14 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 14

Code review with AI

  • What AI review is good at
  • Tuning for signal
  • Reviewing agent-written code

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Two directions of AI code review

AI review cuts both ways:

  • AI reviewing human (or agent) code. Automated first-pass review on pull requests: GitHub Copilot code review, Cursor's Bugbot, Claude Code or Codex running in CI, and dedicated review products. Good at catching slips humans skim past: unhandled errors, missing null checks, inconsistent naming, obvious security smells, missing tests.
  • Humans reviewing agent code. As agents write more code, human review becomes the bottleneck and the last line of defense. It needs a different technique from reviewing a colleague's code.

What AI review is good at, and what it is not

StrongWeak
Local bugs visible in the diffWhether the change solves the right problem
Style and consistency with nearby codeArchitectural fit across services
Missing error handling and input validationBusiness rules not written down anywhere
Common security patterns (injection, secrets)Subtle concurrency and distributed-systems issues
Summarizing large diffsKnowing which trade-offs your team has accepted

AI review should add to human review, not replace it. The most useful framing: the AI is a tireless junior reviewer who reads every line; the human is the senior reviewer who judges intent, design and risk.

Configuring AI review so people read it

Noise kills AI review. If every PR gets twenty nitpicks, developers learn to ignore all of them, including the one real bug. Tune for signal:

  • Give it your standards. Most tools read repository instructions (for example Copilot's instruction files, Bugbot rules, or AGENTS.md/CLAUDE.md for agents running in CI). Tell it what matters and what to ignore.
  • Ask for severity and confidence. Only surface high-severity or high-confidence findings as blocking comments.
  • Focus by path. Money, auth, data deletion and public APIs get deeper review.
## Review guidelines (in AGENTS.md or the tool's review instructions)
- Prioritize: correctness, security, data loss, money/tax calculations, public API changes.
- Ignore: formatting (Prettier enforces), import order, naming nits unless misleading.
- For each finding give: severity (blocker/major/minor), confidence (high/medium/low),
  the exact line, and a concrete fix. Post at most 5 findings; summarize the rest.
- Flag any change to tests that weakens assertions.

How humans should review agent-written code

Agent code looks fluent, which makes it easy to approve. Use a deliberate checklist:

  1. Intent first. Read the issue and plan, then the PR description. Does the change do what was asked, and only that?
  2. Tests before code. Read the tests: do they express the requirement? Are any weakened or skipped?
  3. Look for plausible fakes. Hallucinated APIs, functions that exist in a different version, config keys that do nothing, invented environment variables.
  4. Check dependencies. New packages? Are they real, maintained, and the intended ones (not typo-squats)?
  5. Security scan. Input validation, authorization checks, secrets, logging of sensitive data.
  6. Duplication. Agents often re-implement helpers that already exist. Ask "did we already have this?"
  7. Run it. For anything user-facing, check out the branch and try it.

Worked example: a review that caught the real bug

A Lahore fintech's AI reviewer flagged four minor issues on an agent's PR that added a refund endpoint. The human reviewer, following the checklist, read the tests first and noticed there was no test for a refund larger than the original payment. The implementation allowed it. Neither the agent nor the AI reviewer had the business rule, because it lived only in a finance team's spreadsheet. The fix: add the rule to the domain code, a test, and one line in AGENTS.md about refund limits.

Hands-on: a self-review step before the PR

Ask the implementing agent to review its own diff with a fresh context (a subagent or new session) before opening the PR:

You are reviewing a diff you did not write. Read `git diff main...HEAD`.
Report only: (1) bugs, (2) security issues, (3) requirement mismatches versus ISSUE.md,
(4) weakened or missing tests, (5) new dependencies. For each: file:line, severity, fix.
If you find nothing significant, say so. Do not comment on style.

A fresh context avoids the author's blind spots, and catching issues before the PR saves reviewer time.

Pitfalls

  • Rubber-stamping fluent code. Confidence of prose is not correctness of logic.
  • Letting AI approve PRs. Keep a human approval requirement on protected branches.
  • Unbounded comment volume. Tune or reviewers will mute the bot.

How to measure success

Track the share of AI review comments that lead to a code change (a signal-to-noise proxy), defects found after merge, and median review time for agent PRs.

Key takeaways

  • AI review is a tireless first pass, strongest on local, visible issues.
  • Tune AI review for signal: priorities, ignores, severity, confidence and a comment cap.
  • Review agent code with a checklist: intent, tests first, plausible fakes, dependencies, security, duplication, run it.
  • Keep human approval on protected branches; measure how often AI comments lead to changes.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Developers have started ignoring the AI reviewer. What is the most likely cause and fix?
  2. Which issue is AI review least likely to catch on its own?

Put it into practice

Add review guidelines to your AGENTS.md and run the fresh-eyes self-review prompt on your next agent PR; note what it caught.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.