Agentic Code Post-Merge: More Bugs and Vulnerabilities?

Explore how AI-generated code fares after merge: it requires more fixes and introduces more security weaknesses than human-written code.

martes, 28 de julio de 2026 • 3 min read • Q2BSTUDIO Team

Estudio revela mayor mantenimiento correctivo en código de IA

The rise of agentic coding tools is transforming software development. These AI-based tools enable autonomous changes to entire repositories, speeding up feature delivery. However, a recent longitudinal study (arXiv:2607.09902) sheds light on what happens after those changes are merged: does agentic code remain stable or require constant fixes? The results indicate that while overall maintenance rates are similar to human code, contributions generated by AI agents need significantly more corrective maintenance and introduce more security vulnerabilities and problematic dependencies. This finding is particularly relevant in a context where more companies are adopting AI agents for development tasks, from patch generation to large module refactoring.

The study analyzed 182 repositories, tracking the post-merge fate of both human and agentic contributions. It observed that after merging, agentic code is more prone to require bug-fix patches and to introduce security weaknesses. Furthermore, a statistically significant correlation was found between the project’s review rate and agentic maintenance burden: for every 10 percentage-point increase in the no-review rate (changes accepted without review), corrective maintenance increases by roughly 6%. This suggests that the lack of human oversight exacerbates the problems of AI-generated code. Organizations integrating AI agents without thorough review processes may be taking on hidden technical debt that manifests months later.

The types of vulnerabilities introduced by agentic code range from outdated dependencies with known security flaws to insecure coding patterns like SQL injection or improper authentication handling. The underlying language models often generate snippets based on training data that may contain obsolete or unsafe practices. In contrast, human developers usually have broader project context and can apply domain-specific security criteria. Therefore, integrating AI agents demands a proactive cybersecurity approach, such as the one we offer at Q2BSTUDIO through pentesting and continuous dependency analysis services.

At Q2BSTUDIO, we understand that software quality does not end at the merge. Our approach to custom software development includes thorough review processes and continuous integration practices that mitigate these risks. We combine custom software development with expert human oversight, ensuring every change—whether generated by AI or by humans—passes a quality and security filter. Additionally, we implement cloud architectures on AWS and Azure that provide isolated testing environments and automated monitoring, reducing the attack surface and facilitating early anomaly detection.

Artificial intelligence is not only the cause of these challenges but also part of the solution. At Q2BSTUDIO, we use AI agents for auxiliary tasks like generating unit tests or documentation, always under senior developer supervision. Our AI consulting services help companies design hybrid workflows that maximize productivity without compromising security. Likewise, we integrate Business Intelligence solutions with Power BI to monitor code quality metrics, such as the frequency of corrective patches or vulnerability density, enabling teams to make data-driven decisions.

The study also highlights the importance of a review culture. Projects with high no-review rates experience greater corrective maintenance in agentic code. This underscores the need for CI/CD pipelines that mandate review for AI-generated changes. At Q2BSTUDIO, we design customized DevOps processes that include peer review, static code analysis, and automated security testing. Our clients benefit from a significant reduction in technical debt and improved software resilience against attacks.

In conclusion, agentic code after the merge presents real challenges that cannot be ignored. Companies betting on AI in development must be prepared to invest in rigorous reviews, security testing, and robust architectures. From Q2BSTUDIO, we accompany our clients on this path, providing services from AI consulting to cloud implementation and BI systems. Software quality does not end at the merge: a new phase begins where vigilance and continuous improvement are essential to prevent errors and vulnerabilities from turning into costly technical debt. If your organization is considering adopting AI agents in development, we invite you to contact us to design together a strategy that combines innovation with quality control.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.