Treat AI output like a talented junior developer's pull request: promising, fast, and unverified. AI code is an input to your quality process, not an output of it — don't trust, verify, and read every line.

Your quality stack still matters

Layer What it does With AI in the loop
Tests RSpec, Jest, pytest — prove behavior, catch regressions. Coverage targets unchanged. Ask the AI for happy and sad paths — it will skip the sad ones unless you ask.
Linters ESLint, RuboCop — consistency and common-error catches. Wire into pre-commit hooks so AI-generated code meets your standards before it lands.
Static analysis & secret scanning GitHub Advanced Security — flaws and committed credentials. Already part of the ND standard stack. Treat findings as real until proven otherwise.
Dependency analysis Dependabot and supply-chain review. Extra important: AI-scaffolded projects arrive with dependencies you didn't consciously choose.
Vulnerability scanning OWASP-style scans of the running app. Don't be the team that bypasses them because “the AI's code looked clean.”

The bar goes up, not down

AI doesn't relax the quality bar — it raises it. You're shipping more code per hour, so the percentage that gets meaningfully quality-checked has to stay high or your risk grows exactly as fast as your velocity. The habits that keep it high:

  • Tests land with the code, not after. The core workflow makes “tests + docs” its own phase — don't let it fall off the end.
  • Make the AI test its own work. “Write the tests for this — include edge cases and failure modes” then read them skeptically: a test that can't fail isn't a test.
  • Run everything locally before the PR. Lint, test, scan — the pre-commit commands belong in your context file so the AI runs them too.
Passing quality checks gets code to the door; human review is still the last gate. That's the next page: Shipping & review.