I have watched a senior engineer merge an agent PR because the diff looked boring. The service failed an hour later on a path the tests never touched. Nobody lied. The team simply trusted the shape of the change.
That story is why the trust numbers in
DORA's 2025 State of AI-assisted Software Development
matter more than another LOC chart. Adoption is nearly universal. Skepticism never went away.
Direct answer: assume generated code is wrong until your pipeline proves otherwise. Build verification that runs faster than agents write. Reserve human attention for decisions that change blast radius.
What DORA measured
The report blends qualitative interviews with a global survey of nearly 5,000 technology professionals fielded in mid-2025. Two stats show up in every newsletter recap for good reason:
| Signal | Approximate share |
|---|---|
| Use AI as part of work | ~90% |
| Believe AI increased productivity | >80% |
| Little or no trust in AI-generated code | ~30% |
Those numbers can coexist. You can feel faster at the keyboard and still refuse to ship without proof. DORA's headline framing is sharper: AI amplifies what you already have. Strong platforms and review habits get stronger. Weak habits get louder.
Why the trust gap persists
Three forces keep skepticism rational even when vendors show cherry-picked demos.
Volume. Async agents can open pull requests while you sleep. Reviewers still have the same calendar hours. Trust becomes a shortcut when the queue is full.
Plausible wrongness. Models optimize for coherent diffs, not for your edge cases. A change can read like a refactor and still break authorization on one route.
Stability trade-offs. DORA still reports tension between throughput and delivery stability for many organizations. If your last three agent merges needed hotfixes, trust erodes fast regardless of survey optimism.

Trust-but-verify as an operating model
I do not ask teams to "believe in AI." I ask them to define what must be true before a human looks.
Minimum bar for agent-authored diffs on services I touch:
- Scope tag. Issue link or spec snippet in the PR body so reviewers know what "done" means.
- Automated proof. Unit and integration tests, typecheck, lint, and dependency audit on the branch.
- Risk tier. Auth, payments, PII, and infra changes always get a human owner named in the template.
- Discard lane. Agents may open drafts; only maintainers promote to "ready for review."
That is the same spirit as the NBER attenuation story covered in AI agents write 741% more code and the ADLC playbook in From SDLC to ADLC . Upstream speed is cheap. Downstream proof is the product.

DORA capabilities that actually move trust
DORA's inaugural
AI Capabilities Model
is not a shopping list of copilots. It is organizational scaffolding: clear AI policy, healthy internal data access, quality platforms, user-centric focus, and value-stream management so local speed does not create downstream chaos.
On client work I map that to concrete gates:
| Capability (DORA language) | What I ship |
|---|---|
| Quality internal platform | One-command preview envs per PR |
| Healthy data ecosystem | Agents read sanitized fixtures, not prod exports |
| Clear AI policy | Allowed tools, secret handling, retention rules |
| User-centric focus | Eval scenarios tied to real support tickets |
If you are building AI agents and RAG for internal tools, the trust conversation starts with what data the agent may touch, not which model logo appears in the IDE.
What I would ship this quarter
If I inherited a team with high AI adoption and flat release confidence, I would not buy another codegen seat first.
- Publish a one-page agent PR policy (templates, risk tiers, discard rules).
- Add merge-queue metrics (time from green CI to deploy) beside commit counts.
- Run a blameless retro on the last five agent regressions and patch the missing test, not the prompt.

When skepticism becomes a feature
The 30% who distrust generated code are not luddites. They are often the people who still get paged. The goal is not to convince them AI is magic. The goal is to make verification so fast and routine that trusting vibes is never the cheapest path.
If you are scaling agents and the trust gap is showing up as Friday night rollbacks, book a free discovery call and we can map gates that match how you actually ship.

