Menu

3 Things to Keep in Mind When Developing with AI

3 Things to Keep in Mind When Developing with AI

Artificial intelligence is already a common tool in development teams. It can help us generate code, set up tests, document components, debug errors, and automate repetitive tasks. 

However, developing with AI isn’t about simply accepting the suggestions that appear in the editor. These tools can speed up our work, but they can also generate incorrect code, introduce vulnerabilities, or propose solutions that don’t fit the project’s architecture. 

AI should function as an assistant. It helps us work, but it does not replace our technical judgment. There are three aspects we should keep in mind to use it effectively and safely. 

1. Provide sufficient context

The quality of the result depends heavily on the information the tool has about the project and the task it needs to perform.

If it isn’t familiar with the architecture, the team’s conventions, or the business rules, it will have to fill in those gaps with assumptions. The generated code may appear correct but still fail to fit with the existing solution.

To minimize these issues, it’s important to have the entire project well-documented, covering aspects such as:

1. The architecture used.

2. The repository structure.

3. Naming conventions.

4. Accepted design patterns.

5. Error handling.

6. Permitted libraries and versions.

7. Security requirements.

8. The testing strategy.

9. Acceptance criteria.

 

In reality, all of this information should already be clear at the start of any software project. It’s not a new requirement brought about by AI. With the use of these tools, many people have realized the importance of properly defining a project from the outset. When the context isn’t defined, AI fills in the information on its own, and the result can easily stray from what we need. 

One tip for streamlining and refining instructions is to organize the documentation by topic and include a table of contents that explains the purpose of each document. For example, we can separate information on architecture, security, testing, coding conventions, and business rules. 

This way, the agent can consult only the context necessary for each task. If we’re going to modify an API, it’s probably sufficient to review the controller conventions, error handling, and security requirements. Thanks to the table of contents, it may not even be necessary to explicitly tell the agent where to look for this information for each task. This allows us to reduce specific instructions and avoid constantly repeating the same context. 

This documentation does more than just provide context for the developer. It also makes it easier to onboard new developers and helps reduce differences between implementations. 

2. Review and understand all the generated code

As we’ve seen, by default, an AI tool doesn’t know the project as well as the team that develops and maintains it. It may use obsolete features, duplicate existing code, ignore edge cases, or mishandle an exception. 

You also need to pay attention to dependencies. AI may recommend a package that is unnecessary, outdated, or has known vulnerabilities. It may even suggest a package that doesn’t exist or confuse its name with that of a real library. 

For this reason, all generated code should undergo the same review process as any manually written change. It is important to understand what it does, why it was implemented that way, how it responds to unexpected inputs, and what happens when one of its dependencies fails. 

You should also pay attention to the dependencies it recommends. The AI may suggest a package that is unnecessary, outdated, or has known vulnerabilities. It may even misidentify the name of a library or recommend a package that doesn’t exist.

Before adding a dependency, you should check its source, the suggested version, its maintenance status, the license, and any known vulnerabilities. You should also check whether the project already has another dependency that meets the same need. You shouldn’t install a package just because it appears in a suggestion.

It’s best to automate these checks as part of the continuous integration process. This way, you can prevent a change from moving forward if it doesn’t pass the quality and security checks defined for the project. This does not replace a technical review, but it helps detect some issues before the code is integrated.

A simple rule is not to integrate code that we cannot explain during a review. If we do not understand an implementation, we will likely have trouble maintaining, debugging, or modifying it later on.

AI can help us generate and review code, but the responsibility for the result still lies with the development team.

3. Protect the code and project information 

When we use an AI tool during development, some of the code and context may leave our environment to be processed by an external service. This may include files from the repository, internal documentation, error messages, or snippets containing information about the application’s architecture. 

Paying for an AI tool does not mean they won’t use our data. If we share code, it may contain sensitive information or intellectual property belonging to the company or a client. We should review the privacy terms and verify how that information is stored and used before using the tool.  One key point to check is whether the provider retains the submitted content or uses the interactions to improve or train its models. These terms may vary depending on the product, account type, and subscription plan. 

Before authorizing a tool, you should review what information it processes, how long it retains it, where it is stored, whether third parties are involved, and whether it can be used for training. 

The main idea is simple: a private repository must remain private when working with AI. To achieve this, it’s not enough to rely on a tool’s reputation or popularity. It would be necessary to choose a method that offers adequate safeguards, review its terms and conditions, and implement the organization's security and data protection policies. 

Conclusion 


Artificial intelligence can help us develop faster, automate repetitive tasks, and devote more time to solving problems. However, the outcome depends on how we integrate it into the development process. 

We must provide sufficient context, review and understand the generated code, and protect project information. 

The question should not be how much code AI can generate, but rather how much value it adds without compromising the quality, security, and maintainability of the solution. 

Developing with AI does not diminish the importance of the developer. On the contrary, it makes the developer’s judgment even more essential for defining the problem, reviewing proposals, and making technical decisions. 

Related posts
How to Keep Your Postman Collections Up to Date Using Copilot and Git
By Pablo Suarez Romero  |  05 May 2026

Not long ago, Postman introduced Git version tracking for your work. This makes your life easier when tracking your changes.

Read more
How Blazor in .NET transforms web development with C#
By Emiliano Montesdeoca del Puerto  |  18 February 2026

Discover how Blazor unifies web development in .NET, using C# for both frontend and backend to build modern, secure, and scalable web applications.

Read more
Optimize software projects with GitHub Copilot
By Intelequia  |  12 August 2025

What is GitHub Copilot? What are the benefits of using it with Visual Studio and other Microsoft technologies? Find out in this post!

Read more