# AI Writes More PRs. Who Validates Them? — Ali-Reza Adl-Tabatabai, Sonar

## Executive summary

The increasing volume and complexity of AI-generated code are transforming traditional CI and code review into a critical bottleneck. The solution presented is 'agentic validation,' an automated system that fully manages the PR lifecycle. This agent reviews code, analyzes CI failures (including flaky tests), automatically fixes issues until the PR is green, and can auto-approve and auto-merge based on customizable rules. The most advanced approach combines this agentic validation with deep program analysis (e.g., taint analysis, control flow analysis) for superior precision and coverage.

## Key takeaways

- The CI/Code Review Bottleneck: As engineering scales and AI generates more, larger PRs, the centralized validation phase becomes a major bottleneck, leading to costly delays measured in hours and days. Teams face a difficult choice: slow down or risk production incidents by rubber-stamping.
- Agentic Validation Workflow: An agent automates the entire validation process: it reviews PRs, posts actionable issues, analyzes CI failures, automatically fixes code, and can auto-merge PRs once defined rules and conditions are met.
- Building Trust and Automation: The adoption path is gradual: users first implement automated reviews, then use autofix capabilities to achieve green PRs, and finally establish rules for the agent to automatically approve and merge PRs.
- Advanced Insights for Teams: The system provides valuable insights, such as categorizing top CI failures (e.g., flakiness vs. infrastructure issues) for platform teams, and categorizing PRs by intent (e.g., feature vs. chore) for leadership.

## Technical details

- Agent Architecture: The system comprises a control plane (orchestration layer for PR workflows), a custom agent runtime/harness (handling multi-agent execution, context management, and tool calling), and an NLM proxy (for model routing and failover).
- Program Analysis Integration: Combining agentic validation with traditional program analysis techniques—such as taint analysis, control flow analysis, data flow analysis, and software composition analysis—significantly improves both precision and coverage.
- Automated Remediation: The agent can automatically fix code review issues or CI failures. Users can set up rules to automatically loop until all identified issues are resolved, ensuring a green PR ready for merging.

## Practical implications

- Platform teams can use the system's failure categorization insights to proactively address systemic CI reliability issues.
- Development teams can shift focus from manual code review to defining and refining automation rules, increasing developer sentiment and productivity.
- Implementing agentic validation allows organizations to maintain high development velocity while mitigating the risks associated with AI-generated code.

## Topics

Code Review, CI/CD, AI Engineering, Agentic Workflow, Software Quality Gates, Platform Engineering, SonarQube, Gitar by Sonar

Source: https://www.youtube.com/watch?v=uuwDWRbxoYo
