Programming guide

Review and test AI-generated code before using it

Check AI-written code for correctness, security and fit with your project, then test it properly before it goes anywhere near real users or data.

Estimated time: 20–60 minutesUpdated: 28 September 2026

Use this guide every time an AI assistant gives you code to add to a project. Have the code, your project open in an editor, a way to run it locally and version control set up so you can undo changes.

Step by step

  1. Read it before running it

    Read through the code line by line and make sure you understand what each part does. Ask the AI to explain any section you do not follow. Be especially careful with code that deletes files, changes databases or sends data elsewhere.

  2. Check dependencies and imports

    Look at every library the code imports and confirm it is real, maintained and actually needed. Watch for package names that look slightly wrong, as they may not exist or could be malicious. Prefer libraries you already use.

  3. Look for security problems

    Check that there are no hard-coded passwords or keys and that user input is validated. Look for database queries built by joining strings, which can allow injection attacks. Make sure errors do not expose sensitive details.

  4. Run it on a safe copy

    Commit your current work first, then add the code on a separate branch. Run it locally with test data, never live customer data. Check it does what the prompt asked, including with empty or unusual input.

  5. Add or run tests

    Run your existing tests to make sure nothing else broke. Add at least one test for the new behaviour and one for an edge case. If a test fails, fix the cause rather than weakening the test.

  6. Review the diff and merge

    Look at the full diff of changes before merging, and remove unused code or debug output. Write a clear commit message describing what changed and why. Only then merge into your main branch.

Ready-to-use checklist

  • Code read and understood
  • Every import checked
  • No hard-coded secrets
  • User input validated
  • Tested on a separate branch
  • Test data used, not live data
  • Existing tests still pass
  • New tests added

Practical tips

  • If you cannot explain the code to someone else, do not ship it yet.
  • Ask a second AI session to review the code for bugs and security issues, but still make the final judgement yourself.
  • Keep AI-generated changes small so each one is easy to review and undo.

Common problems

The code runs but gives slightly wrong results.

Write a small test with an input and the exact output you expect, then run it. Share the failing test with the AI and ask it to fix the code until the test passes.

The AI used a function that does not exist.

Check the official documentation for the library and version you use. Tell the AI the correct function or version and ask it to rewrite that part.

I merged AI code and now something else is broken.

Use Git to revert the commit or compare it with the last working version. Then reintroduce the change in smaller pieces with tests.