Insights
Who checks the code when AI writes it? How we review every change.
What good looks likeBy Whitelam Media6 min read
All insightsAI coding agents write most of the code on the websites we build. The model that writes a change never reviews it. Here is every check a change passes before it reaches a live site, and the questions to ask any agency that uses AI.
AI coding agents write most of the code on the websites we build. We're not unusual. At Google, Sundar Pichai said in April 2026 that 75% of all new code is now AI-generated and approved by engineers.
So the useful question for a buyer is who checks that code, and how. This is our answer, step by step. For what AI tools do to the cost and speed of a build, see how AI tools change a website rebuild.
What an AI coding agent does.
An AI coding agent reads the code of a whole website, plans a change across many files, makes it and runs the tests. We build with Claude, from Anthropic. A change that took a developer a day, such as a new page type or a form connected to your CRM, now often takes an hour or two.
Speed without checks makes sites less stable.
Google's DORA 2025 report, from a survey of about 5,000 technology professionals, found that 90% use AI at work. It also found that more AI use goes with less stable software delivery, unless teams have strong controls such as automated testing, version control and fast feedback. And 30% of respondents had little or no trust in the code AI produces.
That matches what we see. The tools are fast and mostly right. The checks are what make them safe to use on a live business website.
Rule one: the AI that writes a change never reviews it.
A reviewer from the same family as the writer tends to share its blind spots. So every change is reviewed by a model from a different AI company, OpenAI or Google, and never by the one that wrote it.
The reviewer reads the change against our written standard: security, payments, personal data and the house rules for every page. It returns a verdict, safe to merge or needs fixes, with each problem it found. Every finding is fixed or answered with evidence, and the change is reviewed again. When a reviewer once doubted that four new articles would appear on the right page, we wrote an automated test that proves it, and that test now runs on every change.
Rule two: nothing ships on a failed check.
Every change runs through the same automated checks:
- type checks, which catch code that uses data the wrong way;
- code rules, which catch common mistakes and unsafe patterns;
- tests for the parts that matter most, such as prices and payments;
- a full production build, the same one the live site runs.
A change goes live only when the review says it's safe and every check has passed on that exact version of the code. A fix pushed afterwards starts the checks again.
Rule three: risky changes get their plan reviewed first.
Anything touching payments, sign-in or client data gets one more step before any code is written. The plan goes to a separate agent that didn't write it, whose job is to attack it: what fails, what's hard to undo and what a customer would see if it went wrong. We change the plan, then build.
Rule four: some things AI never does alone.
- Changes to a live database need a person's go-ahead.
- Passwords and keys stay out of the code and out of the chat.
- Messages to clients come from a person.
Every change is checked again on a preview and live.
Each change goes up on its own private preview link before it reaches the live site, so it can be seen working. After release, we check the live pages. If anything's wrong, Vercel's Instant Rollback puts the previous version back in one click.
What it means for you.
- Changes are quick. Small changes are often live the same day.
- You can see every change. Each one has a preview link and a written review.
- You're not tied to the AI. The code is ordinary Next.js in a repository you own, so any developer can work on it, with or without AI tools.
Questions to ask any agency that uses AI.
- Does the same AI that wrote the code review it?
- What has to pass before a change goes live?
- Who can change data on the live site?
- Where do passwords and keys live?
- Can we see the review for a change?
See how we build on Next.js and Payload, or book a call and we'll show you a real review.







