A year or two ago, whether to let developers use an AI coding assistant was still a live debate inside a lot of IT departments — a pilot program, a "let's see" policy, maybe a hold while legal worked through the licensing questions. That debate is mostly over. Stack Overflow's 2025 developer survey found that 84% of professional developers now use AI tools or plan to, and just over half use one every day.

The enterprise numbers moved even faster. Gartner's research puts AI-assisted development in production at 78% of Fortune 500 companies, nearly double where it stood two years earlier. Whatever hesitation existed in 2023 and 2024 mostly resolved itself the way IT hesitation usually does — not through a decision, but through developers adopting the tools on their own until policy caught up.

What hasn't caught up as quickly is oversight. One industry survey published earlier this year found that while the overwhelming majority of developers were actively using AI coding tools, fewer than a third worked somewhere with a genuinely governed approach to reviewing that output. That gap matters: researchers publishing in ACM TOSEM examined a large sample of AI-generated Python code and found security weaknesses in nearly 30% of it — not catastrophic bugs necessarily, but exactly the kind of thing a code review is supposed to catch before it ships.

None of this means AI coding tools are a bad idea. The productivity data is real too, and teams that use them well are shipping faster. It means the question worth asking has changed. It isn't "are we allowed to use this" anymore. It's "who's actually looking at what it produces." If your organization has developers, contractors, or an MSP writing code on your behalf, that's a fair thing to ask them directly.