What an AI code review can and cannot catch

Pattern review is fast at local mistakes. It is not a substitute for tests, threat models, or someone who knows the product.

2026-03-04 · Vericode Team · 7 min read

Automated review is good at the mistakes that leave a fingerprint in a single snippet: dividing by a length that can be zero, comparing with `== null` in a language that has a better check, wiring `innerHTML` to a string you do not control, or leaving `FIXME` in a path that ships.

It is weaker on anything that lives outside the paste box. A function can look correct and still violate a product rule stored in another service. An SQL query can be syntactically clean and still miss a tenant filter. No local analyzer sees the ticket, the SLA, or last quarter’s incident write-up.

Concurrency and distributed failure modes are also easy to miss. A debounce helper can be textbook and still drop events if two tabs share storage. A “looks fine” retry loop can amplify load. Those reviews need runtime evidence: tests, traces, and load assumptions.

Security review of a snippet can flag obvious sinks. It cannot certify that your authn story is sound. Do not treat a clean first pass as permission to skip dependency updates, secret scanning, or a real threat model for new attack surface.

Vericode is an assistant, not an oracle. We will not publish fake accuracy percentages. Keep a human in the loop before you merge.

Use AI review as a first pass before human review, not instead of it. Ask it for structured severity, locations, and suggested fixes. Then apply judgment. If the tool cites an API you do not have, discard that finding. If it repeats a maintainability note you already knew, keep moving.

The highest-leverage pairing is review plus tests. A heuristic can say “empty list is dangerous.” A unit test proves the function returns a defined value. Keep both.

When you evaluate a vendor, ignore cinematic landing pages. Look for language limits, retention policy, and whether the product admits what it cannot see. That is the difference between a checklist and a liability.

A practical rule: if the finding would not survive a skeptical teammate asking “show me the line,” drop it. Keep the ones you can turn into a test or a comment in the same hour.