Your AI coding tools are fast. Your pipeline isn't. That's the real problem.

Two things happened this week that, taken together, tell you everything you need to know about where software development is headed in 2026.
First, the State of DevOps Modernization 2026 report dropped on March 11, based on a survey of 700 engineers across the US, UK, Germany, France, and India. The headline finding: teams using AI coding tools multiple times per day are deploying to production faster, but 69% of those same heavy users say they experience deployment problems "always," "nearly always," or "frequently" when AI-generated code is involved. Meanwhile, 51% report more code quality issues and 53% report more security incidents since adopting these tools.
Two days earlier, Anthropic launched Code Review for Claude Code, a multi-agent system that automatically reviews pull requests for logic errors. Their own internal numbers explain why they built it: code output per engineer at Anthropic grew 200% in the past year, and the company went from 16% of PRs getting substantive review comments to 54% after deploying their review system internally.
See the pattern? AI is making code production cheap and fast. Everything after code, the testing, the security scanning, the deployment, the review, is now the bottleneck. The Harness report calls this the "AI Velocity Paradox." We just call it Tuesday.
We've been watching this happen in real time
From our PHP and Docker work with enterprise clients, especially in regulated industries like Swiss finance, we've been seeing a version of this problem for months now. Teams adopt AI coding assistants, output goes up, and then the CI/CD pipeline that was designed for 2022-era commit volumes starts choking. Builds queue. Tests take longer because there's simply more code to test. Security scans that used to be a minor annoyance become a 45-minute wall between a developer and their deploy.
The Harness data backs this up: 73% of engineering leaders say "hardly any" teams have standardized templates or golden paths for their pipelines. Only 21% can spin up a functioning build-and-deploy pipeline in under two hours. Developers are spending roughly 36% of their time on manual tasks like chasing approvals and rerunning failed jobs.
That last number should bother you. A third of your engineering capacity, burned on toil. Not building features. Not fixing bugs. Just babysitting a pipeline that wasn't built for this throughput.
The code review bottleneck is real, and it's a security problem
Here's where it gets uncomfortable from a security perspective. During our penetration testing engagements, we regularly find bugs that should have been caught in review. Authentication edge cases, authorization logic that's almost right but not quite, input validation that covers 90% of cases and misses the 10% an attacker actually cares about.
Now multiply that by the volume of AI-generated code flooding into pull requests. The Anthropic blog post is refreshingly honest about this: before their Code Review tool, most PRs were getting skimmed, not read. Engineers are stretched thin. They see a 400-line PR, skim for obvious issues, approve it, and move on. That's not a character flaw. It's a capacity problem.
Anthropic's tool is interesting because it focuses on logic errors over style nitpicks. On large PRs (over 1,000 lines), 84% of reviews surface findings, averaging 7.5 issues. On small PRs under 50 lines, that drops to 31%. They also caught an authentication-breaking change internally, a single innocuous-looking edit that would have disrupted their own auth system.
I keep thinking about that one. A single line. In an auth service. Caught by an automated reviewer. That's the kind of bug we find during pen tests, weeks or months after it shipped. Catching it in the PR is orders of magnitude cheaper.
What you should actually do
Look, we're not going to tell you to go buy a specific vendor's platform. But based on what we see across our web and mobile projects, here's what's working:
Audit your post-code pipeline this week. Seriously, just map it. How long from merge to production? Where are the manual handoffs? Where do things queue? Most teams we talk to have never actually measured this end to end. They know their build takes 8 minutes but have no idea they're losing 3 hours to approval chains and environment provisioning. That's your starting point.
Automate security scanning earlier, not later. When we configure WAF and DDoS protection for travel platforms, we always push for security checks to be as close to the developer as possible. The same principle applies to your pipeline. Static analysis, dependency scanning, and secret detection should run on every PR, automatically, before a human reviewer ever sees it. If you're still running security scans only in staging, or worse, as a gate before production, you're finding problems too late to fix them cheaply.
Don't skip human review just because you added AI review. Anthropic's tool won't approve PRs. That's a deliberate design choice, and the right one. In our native iOS and Android projects, we've seen that AI tools catch different classes of bugs than humans do. The AI is good at spotting logic inconsistencies across a large diff. Humans are better at asking "wait, why are we doing this at all?" You need both.
Standardize your deployment paths. The Harness data says 73% of teams lack golden paths. If every service deploys differently, you can't automate the downstream checks, and every deployment is a bespoke risk. From our work building cloud-native apps on AWS, the single highest-return investment we've seen teams make is a well-maintained deployment template that every new service inherits by default.
The uncomfortable truth
The real story this week isn't that AI is making developers faster. We knew that. The real story is that most organizations built their delivery infrastructure for a slower world, and AI coding tools are stress-testing those systems to the breaking point.
The Harness report found that 77% of teams are regularly blocked waiting on other teams for routine delivery tasks. That's not a tools problem. That's an architecture and process problem. No amount of AI-generated code is going to fix it.
If your team is writing code 2x faster but deploying with 2x more incidents, you haven't gained velocity. You've gained chaos with better syntax.
Sort out your pipeline. Then let the AI rip.
If any of this sounds like your team's week, let's talk. We've been helping startups and enterprise teams work through exactly this kind of growing pain, across web, mobile, and security.