forumNew topic

Does it make sense to have an AI review delivered software code before acceptance?

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#1

I run a small wholesale distribution company in Frankfurt. We worked with a local agency on a custom software project for our warehouse management with a 26.000 EUR budget. The process took six months, and yesterday evening they told us they delivered the final state of the repository, asking us to sign the final acceptance protocol and pay the remaining 35 percent.

Personally, I'm not technical, I can't read code. People around me suggested putting together a thorough code review prompt and scanning the files chunk by chunk with a large AI model so I could see code quality, security vulnerabilities, or bloated lines.

Is doing this a sensible move technically and legally? Does this kind of tool actually provide a meaningful audit, or will I look technically clueless if I put it in front of the agency?

İİsmail T***MemberCommunity member
Joined
Jan 2024
Message
418
Most Helpful#2

Short answer: A code review prompt tailored for AI is a decent preliminary check for catching superficial syntax issues, forgotten credentials, and obvious security flaws, but it cannot understand system architecture, business rules, or performance bottlenecks. What's more, an error report generated by an AI doesn't count as legal or contractual evidence you can present to the other party.

These tools do an okay job reading isolated code snippets. For instance, they quickly flag exposed API keys, SQL injection risks, undocumented modules, or non-standard naming conventions. But they can't grasp the software as a whole. An AI won't be able to tell if database transaction management is set up properly, whether the system will freeze under hundreds of concurrent orders, or if the custom logistics algorithm agreed upon in the contract's technical specs was implemented correctly.

If you sit down with the agency for the acceptance process and dump raw AI output on the table as an objection list, you'll lose all credibility. These models throw false positives all the time; they might flag an intentional design choice specific to that project as a bug. The right way to handle this: 1) Use the AI solely as an initial filter to spot suspicious areas, 2) Hand those concrete suspicions over to an independent senior developer for a 3-4 hour review, 3) Bring only verified technical defects mapped directly to contract clauses to the final acceptance meeting.

GGökhan G***MemberCommunity member
Joined
Nov 2022
Message
223
#3

There's a major legal risk here. What do the confidentiality or IP clauses in your agency contract say? Uploading proprietary codebase files to a cloud-based AI system could unintentionally put you in breach of contract. If the data is used for training on third-party servers, you'll leave yourself wide open while trying to defend your rights.

FFerhat C***MemberCommunity member
Joined
Aug 2024
Message
225
#4

From a technical standpoint, the biggest limitation is the context window. A 26.000 EUR warehouse system likely spans dozens of services, database schemas, and external integrations. Models look at files in isolation. Because it doesn't see the data validation handled by a function three files over, it might falsely raise an alarm crying 'security vulnerability here'.

SSelin K***Member
Job title
QA Tester
Sector
Education
Organization type
120-person company
Joined
Jan 2026
Message
254
#5

Under German contract law, defects must be concretely documented before signing the acceptance protocol. Text output from an AI does not count as a valid defect notice. The defect must be reproducible in a running system, and you have to prove that it fails to meet the requirements set out in the technical specifications.

EEmrahMember
Job title
Business Analyst
Organization type
chain store
Joined
Feb 2024
Message
108
#6

We tried this exact thing last year on an 18.000 EUR B2B portal. The model spat out a 47-item list. Before taking it to the agency, we paid a freelance senior dev 400 EUR to review it. Only 4 of those 47 items were actual defects; the rest were bogus. But one of those 4 bugs was severe enough to crash the system in production. Useful as a filter, totally inadequate as a final judge.

MMurat Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
chain store
Joined
Jan 2025
Message
27
#7

instead of pasting all the code and sying find the bugs, you'll get way cleaner results if you go module by module with focused prompts like list dependencies and security vulnerabilities, but definitely don't send raw model output to the agency they won't take you seriously.

İİsmail K***Veteran
Job title
QA Tester
Sector
E-commerce
Organization type
medium-sized business
Joined
Sep 2022
Message
3
#8

Don't overcomplicate it. Run the acceptance process straight through user experience and functionality. Set up test scenarios: 1) What happens when an invalid barcode is scanned? 2) Does stock sync break if the internet drops and reconnects? 3) Does the system hang while issuing an invoice? Your job is to verify whether it does the actual work, not critique the prose of the code.

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#9

Did your contract include an automated testing clause or a test coverage threshold? Also, are there unit tests written by the agency in the delivered repository? If test suites exist, running them gives you a far clearer, indisputable acceptance metric than having an AI read the code.

VVolkan C***Member
Job title
Digital marketing specialist
Sector
Cleaning services
Organization type
family business
Joined
Jun 2024
Message
224

Doki · KVKK compliance consulting · 2024

#10

One of our clients pulled something like this. They brought an eight-page list generated from a prompt to our meeting and claimed 'your software is garbage'. One item said 'database password is hardcoded', but it was literally just an example config template, the actual password was read from an environment variable. The whole room got incredibly tense and delivery was delayed by two months for nothing.

ÖÖzgür G***Member
Job title
Software developer
Sector
Cosmetics
Organization type
8-person team
Joined
Jun 2023
Message
16
#11

This is exactly what we experienced. Most time waste accumulates in tasks waiting for approval.

Hope this helps.

MMerve Y***Member
Job title
Data entry clerk
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Mar 2024
Message
151
#12

I've been dealing with this for a long time. Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

BBurcu V***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
120-person company
Joined
May 2023
Message
2
#13

To get into the details: Everyone rushing into code review prompt gets stuck at the same point.

CCem T***Expert
Job title
Warehouse Manager
Sector
Real estate
Organization type
cooperative
Joined
Jul 2023
Message
22
#14

Here's how it went for us. The harder it is to reverse a decision the slower you should make it.

Correct me if I'm wrong.

HHakan Y***Member
Job title
Production planning
Sector
Seafood
Organization type
20-person company
Joined
Sep 2022
Message
42
#15

I don't think this advice fits everyone. When making decisions, write down the worst-case scenario too, not just the best.

Of course, it varies if your situation is different.

İİbrahim S***New memberCommunity member
Joined
Jun 2026
Message
20
#16

There's a part I don't understand. If you don't write this down from the start, it leads to arguments later.

Most time waste accumulates in tasks waiting for approval. I'm also curious if anyone does it differently.

HHavva Ö***MemberCommunity member
Joined
Aug 2025
Message
25
#17

I'm writing this so you don't make the same mistake. If you don't write this down from the start it leads to arguments later.

If you post the result here, it will help others too.

EEbru Ö***Member
Job title
Supply chain manager
Sector
Glass
Organization type
early-stage startup
Joined
Oct 2025
Message
302
#18

How did you solve this? Every "we'll look at it later" in a meeting means unbilled work.

That's all, sorry if I went on too long.

VVeli Ç***Member
Job title
Courier coordinator
Sector
Energy
Organization type
20-person company
Joined
Apr 2022
Message
347
#19

Three different views emerged, they all complement each other. The harder it is to reverse a decision, the slower you should make it.

Hasty decisions become decisions you have to fix six months later.

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#20

youre righht but the biggest time-waster for us was not knowing who had the final say.

of course, it varies if your situation is different.

Reply