What to do
Use AI review as an additional pass, not an approval authority. Give it the change intent and relevant context, verify every finding against the code, and require normal tests and human ownership before merge.
Prepare useful context
Provide the issue, expected behavior, relevant architecture notes, and the actual diff. Ask the reviewer to separate definite defects from questions and style preferences. Without intent, it may flag deliberate behavior or miss a requirement violation.
Review by risk area
Run focused passes for correctness, security, concurrency, data integrity, performance, compatibility, and tests. Focused prompts produce more auditable output than a vague request to find anything wrong.
- Trace changed inputs to side effects.
- Check authorization at the point of action.
- Look for missing failure and rollback paths.
- Confirm tests assert behavior, not implementation details.
Verify findings
Reproduce suspected defects or point to the exact invariant that is broken. Reject speculative comments that cannot be supported. A named human remains responsible for the merge decision.
Practical checklist
Continue researching
This guide is an editorial framework, not a product endorsement. Recheck vendor documentation and your organization's requirements before making a purchasing or security decision.