AIToday
AI Coding AssistantsZenn AI/MLPublished: Oct 7, 2026, 22:00 JST

Don't line-read AI code: split by contract, tests

Don't line-read AI code: split by contract, tests

3 Key Points

  1. What happened

    Writing on Zenn, the author proposed reviewing AI-generated code by contract (Design by Contract, defining preconditions, postconditions, invariants) verified with property-based tests like Hypothesis, shrinking human review from hundreds of lines to a few.

  2. Why it matters

    Humans can then focus on whether the contract itself matches business rules rather than on the implementation, and the author notes this approach is a practical way to avoid attention fatigue from reading every line equally.

  3. What to watch

    The author says this only works where contracts can express intent; authorization, payments, and deletion should still be read line by line and mutation testing is needed to catch weak tests.

WHO IT HITSSoftware engineers and engineering managers at teams using AI code generation will likely see review checklists and pull-request templates change, with pure functions handled by contracts and tests while authorization, payment, and data-deletion changes still get full human reads.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The article builds its argument on a simple observation: as AI generates more code, the time humans can spend reading it runs out first. Rather than reading everything at the same density, the author proposes separating what can be mechanically enforced — types, tests, static analysis — from what cannot. The key move is putting the human on the contract, not on the implementation. In the example, a discount function's preconditions, postconditions, and invariants are written as a docstring before the AI fills in the body, and property-based tests generate inputs to try to break those promises.

The author is careful about limits. The proposal assumes stable specifications, a functioning CI test setup, and code that isn't dominated by side effects. In a comparison table, pure functions and data mapping are described as easy to express in contracts, external API integration only partly so, and authorization, payments, and deletion as hard to express and therefore requiring line-by-line reading. The author notes that gaps in authorization are a major risk in the OWASP Top 10, and that passing tests does not mean authorization is correct — often such tests were never written.

To keep weak tests from undermining the whole scheme, the author points to mutation testing, which deliberately breaks code to see whether tests fail, and suggests limiting it to important modules. On effort, the author is explicit: this is not about working less. Writing contracts is a different burden from reading implementations, and the total may just move rather than shrink. The real test is whether a team can articulate, for each area, who decides something belongs in the 'can't be protected' layer.

FAQ
Should AI-generated code be reviewed more strictly than human-written code?
No. The author says strictness should depend on the area the change touches, not on who wrote it. Authorization, money, or deletion changes get a full read regardless of the author.
Can contracts and tests replace reviewing AI-generated code entirely?
No. The author says they widen the mechanically verifiable range and narrow what humans read, but the validity of the contracts themselves must still be checked by people.
What is property-based testing?
Instead of writing input examples one by one, you write properties that must hold for any input and let the tool generate inputs to verify them. In Python, Hypothesis is the representative library.
Should mutation testing run in every CI build?
The author says it doesn't need to run everywhere each time, since it is slow. Limiting it to important modules or running it as a nightly job is presented as realistic.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleChatGPT forges signatures of over 15 New Yorker cartoonists