{"id":114456,"date":"2026-07-22T06:36:13","date_gmt":"2026-07-22T06:36:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114456\/"},"modified":"2026-07-22T06:36:13","modified_gmt":"2026-07-22T06:36:13","slug":"small-teams-are-the-heaviest-users-of-ai-coding-agents","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114456\/","title":{"rendered":"Small teams are the heaviest users of AI coding agents"},"content":{"rendered":"<p>The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/09\/github-open-source-collaboration\/\" rel=\"nofollow noopener\" target=\"_blank\">GitHub<\/a> that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/AI_coding_agents.webp\" class=\"aligncenter\" alt=\"AI coding agents\" title=\"AI\"\/><\/p>\n<p>Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed them and who committed to them. The repositories all carry at least 100 stars, the agents are the ones most developers have already met, GitHub Copilot and OpenAI Codex and Claude Code, and the window runs from May through July 2025.<\/p>\n<p>One developer does the reviewing and the fixing<\/p>\n<p>Most agentic pull requests pass through the hands of a single developer, who reads the agent\u2019s code, fixes what needs fixing, and merges it. The setup covers 78.9% of the pull requests in the dataset.<\/p>\n<p>It plays out the way plenty of maintainers already work. Prompt the agent, wait for the pull request, open it, edit a few lines, ship it. Count the cases where someone reviews the agent\u2019s work and leaves it as is, and one-person oversight covers close to nine in ten.<\/p>\n<p>Group review stays rare at every size of project. Small teams lean hardest on the solo routine, and bigger teams spread the work around more often without displacing it.<\/p>\n<p>Most repos run one or two a quarter<\/p>\n<p>The median repository opened one or two agentic pull requests in three months. That is the whole quarter. For most projects on GitHub the agent turns up now and then and goes quiet again, and only a sliver of contributors ever touches its work.<\/p>\n<p>The heavy usage belongs to the tiny teams. Repositories with one to five contributors averaged 50.2 agentic pull requests apiece, many times what medium and large teams managed, on the strength of a few outliers running agents hard. Line the small projects up and the one in the middle looks like everybody else.<\/p>\n<p>More output, same one reviewer<\/p>\n<p>Raida went back to the small teams that cleared 30 agentic pull requests in the window and checked who was reviewing them.<\/p>\n<p>\u201cEven among the most active small repositories (i.e., small teams with more than 30 agentic PRs), the majority of agentic PRs continued to follow a single-reviewer workflow,\u201d Raida told Help Net Security. \u201cThis suggests that increased <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/09\/securing-autonomous-ai-agents-rules\/\" rel=\"nofollow noopener\" target=\"_blank\">agentic activity<\/a> did not necessarily lead to more distributed review practices.\u201d<\/p>\n<p>The agent scales up. The review desk stays one person wide.<\/p>\n<p>Review is the ceiling<\/p>\n<p>The catch is review. Code review already eats a large slice of the workweek for most developers, and every agent pull request still has to be read, tested, and judged worth merging. That work sits with a human, and there are only so many hours in it.<\/p>\n<p>The limit shows up in the numbers. Twenty-five projects in the sample generated agent pull requests at the clip a working developer ships code, going by a Worklytics benchmark of professional output. Everybody else came in under it.<\/p>\n<p>Solo and group review end the same way<\/p>\n<p>Pull requests handled by one person get merged at close to the same rate as those handled by several.<\/p>\n<p>\u201cThe merge rate (i.e., the percentage of PRs merged within the timeframe described in the <a href=\"https:\/\/arxiv.org\/pdf\/2607.14037\" target=\"_blank\" rel=\"nofollow noopener\">paper<\/a>) was very similar between the two collaboration patterns: 81.2% for single-reviewer pull requests and 80.3% for multi-reviewer\/committer pull requests,\u201d Raida said.<\/p>\n<p>The two groups do different jobs. According to Raida, \u201cthe most common type of PR among single-reviewer workflows was feature-related, whereas fix-related PRs were the most common among multi-human workflows.\u201d Solo maintainers point their agents at new functionality. A crowd shows up for the repairs.<\/p>\n<p>Those numbers cover acceptance inside the study window and stop there. Reverts, follow-up bug fixes, and how well merged agent code holds up over time sit outside the dataset.<\/p>\n<p>The one-person review desk<\/p>\n<p>The pattern is ordinary practice, familiar to anyone who has merged their own Copilot output on a quiet afternoon, and it holds up under load. Small teams running dozens of agent pull requests kept one person in the loop the whole time. Few projects have pushed hard enough against that ceiling to find out where it gives.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/divider.gif\" class=\"aligncenter\"\/><\/p>\n<p>Must read:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n<p>Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"The pull request arrives with the tests already run and the description already written, the work of an&hellip;\n","protected":false},"author":2,"featured_media":114457,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,24,5189,3282,52,641],"class_list":["post-114456","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-ai","tag-code","tag-github","tag-research","tag-software-development"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114456"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114456\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114457"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}