Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
162525 stories
·
33 followers

Code Quality Never Changes – Or Is AI Challenging This Notion?

1 Share

This post was adapted from Kai Schmithuesen’s talk at JetBrains Game Development Day 2026. See the full video presentation and Q&A below, or keep reading!

First we are going to define what we mean by code quality then have a look at how this impacts business outcomes, where AI comes in, AI’s impact on quality and how to safeguard it in your team.

You can take the methodologies described in here and use it for many solutions but we will also explore a Qodana example.

Code quality is a topic that tends to get overlooked at times, especially in game development where you might have other issues on your plate. However, speaking with a lot of JetBrains customers at game development conferences, there is an awareness that this is an important topic. That being said there isn’t a set of industry best practices in the gaming industry and so we share some of these best practices from other industries in this presentation.

What do we mean by code quality?

This can be “fuzzily” defined for such an important topic. If you speak with ten colleagues it could be that you get a lot of different answers. Point one, is correctness.

Correctness: Does my code do what I designed it to do?
Performance: Important for gaming, is it fast enough?
Stability: Does it crash or not crash, and how stable it is from a players perspective.
Security: Also important where you don’t want to show up in an industry news story because you got hacked.
Maintainability: Does my code work today and will it work in a couple of years as well?Especially with some games going on for 10 to 12 years.
Reusability: This is a topic getting more relevant for larger studios: can I reuse the code I’ve already developed for other projects? And all of these give you an overview of what code quality entails.

If you go to the wild west that is X or LinkedIn, for example, you can see that whether or not code quality is important is a hotly debated topic. From one person saying they don’t care how their code looks, to the other extreme “My code needs to be beautiful and spotless before I release it,” and anything in between. There are loads of different opinions out there.

The Qodana team advises that code quality can have a real impact on your business and how your game is received. There was a AAA studio that lost 33% of its value a week after launch.

70% was cut from GTA load times by simply fixing two small code flaws. Time to load was cut from 6 minutes to 2 minutes (by a player) and then Dark Souls was offline for 2 months because there were remote code execution flaws (security issue) and if you lose players over these two months they are most likely not coming back and there is real-life impact on revenue. Bad code doesn’t only stay on your side. It lands with your players which can lead to refunds, bad reviews.

When we look at IGN or PC Gamer, quality, bugs, how stable is it, always influences scores. This ultimately determines how many players you will attract and buggy games lead to disgruntled payers. There are some examples of big studios able to get away with it, like Bethesda but this is something you shouldn’t risk.

Why is bad code released?

In a lot of conversations, we find that just the pressure of getting your game to market is immense. Scheduling is a real issue and is reflected in the number of game developers who had to do crunch periods or extended hours – which is over half. This entices a lot of studios to figure out how they can use AI to help with this topic.

AI, especially in game development is a hotly discussed topic. However, 95% of Unity developers (2026 Unity Game Developer Report) use it at work for assistance in the coding process so this shows that AI if it is used correctly can be a helpful tool.

You can prototype much faster, try out new game mechanics, etc. In the past you had to spend a couple of months but now you can use a couple of days and throw out what doesn’t work. You don’t have to spend so much time on boiler issues which results in increased efficiency.

Qodana AI

The goal is not to cut developers from the teams, only enable your team to use AI to do something more interesting. However, this speed and the usage of AI comes with a potential downside when it comes to code quality. AI can generate a lot of code real fast but it’s not necessarily better or worse but does exasperate the amount of issues. In the past you may have written a couple of hundred lines. Now, in the same time AI can write 10,000 lines. This leads to real-life issues for example:

Slow code, is my game up to scratch when it comes to performance, is it stable? Is it exploitable or does it have potential security issues? The good and bad news is that AI code is not necessarily worse than human-generated code, it seems quite on par when it comes to the overall amount of issues but it fails in different ways compared to human-generated code.

When it comes to logic and errors, it creates 1,7x more issues than human-generated code. When it comes back to maintainability etc. is it worse and most concerning it will also potentially create more security issues than a human developer would. This is coming from a study by CodeRabbit. They are an AI vendor themselves.

Qodana AI

However, it’s not necessarily what kind of issues are created by who (humans or AI) but the only question that we pose is “Is our code overall up to scratch and does it meet our quality standards and this is where static analysis can help. The good news is that you can use static analysis to basically cover all of these 6 areas.

Using static code analysis to solve problems for game developers

When it comes to correctness, you have standard inspections. You can also check for code coverage thresholds, which are becoming more important. Not only in coverage but how to use them as well.

Performance is an area that static analysis can cover. Stability a couple of examples would be null safety, resource leak, exception inspections, security inspections and software component analysis – checking for outdated dependencies or doing taint analysis as part of your static analysis to find more complex issues like SQL scripting and so on.

From a maintainability perspective, you can locate code smells, code complexity and duplication. This is something AI is really well-known for. It likes duplications but it doesn’t like refactoring. if you don’t have a way to keep that in check, this will really hurt your maintainability going forward, as no one will be able to understand your code at some stage.

The same with reusability, duplicate code makes it more complicated and static analysis can check if your code adheres to your own internal coding standards, in order to have the same approach – regardless of the project that you’re working on. This way you are also able to share your code much more easily.

AI creates these kind of issues, the most common reason is because it got trained on outdated sources. These are all sucked dry and there isn’t much new work coming up which is what can lead to outdated dependancies and similar.

Static analysis in conjunction with AI as the answer

The downside is, this kind of analysis has been around for a long time but for good reason. One is the results are deterministic.

If you give a static code analysis tool an analysis ten times, it will give you the same set of results ten times. If you run it ten times, it doesn’t cost you more too because it doesn’t consumer any tokens. If you give AI the same piece of code 10 times you’ll get 20 answers.

It’s fast and cheap, if you compare an AI reviewer to static analysis – usually static analysis is much faster. Coming back to being deterministic, you can ties every result to a specific inspection and see why it’s an issue.

This will become more important as compliance keeps growing. One big one is the new EU Cyber Resilience Act already in effect in some areas. Part of this act requires you to create a software bill of materials. If you use AI this will be difficult. If you use static code analysis and you can show a 1-1 relationship between the result and the source you are more likely to comply. However both have their pros and cons.

Pros and cons of static analysis and AI analysis

It can’t understand the intent of your code because it basically looks for patterns. This is where AI comes in. If you want to check that the code does what you want it to do across files or across your project for check for logic-related issues, that’s where AI comes in.

So Ideally, you’d use a combination of static analysis to cover the base and AI on top of that. A human writes the code and AI can also write some . Then once you kick off your pipeline, static analysis covers the initial analysis. Qodana can check for any issues but can also create quick-fixes automatically. So you can still automate even without AI.

These quick fixes are not generated by QIA so this gives you the advantages of static analysis in general, fast, doesn’t cost extra, and reliable. Then you will move on to your AI tool of choice and review the rest and create fixes for other complex issues like a logic issue or refactoring. This can compliment your pipeline.

Ideally you then have a loop, AI will push it back in the pipeline to your static analysis so that static analysis can reconfirm that what AI created is up to scratch and passes your code quality and security standards. Then you can merge the code into your main branch.

It sounds time-consuming but the irony is that this probably takes a couple of minutes each time and can save you time in future. These are a couple of minutes to not spend hours later if there were uncaught issues.

What do the numbers say?

There are already some studies out there that show the advantages of this approach. If you combine static analysis with LLM calls, then the amount of token usage was going down by 72 to 92% while still increasing the code used in that study. The second study found that if you use this combination then you can have up to 33% fewer vulnerabilities in your LLM code going into your master branch.

Here is a quick example of how this can look in Qodana or a static analysis tool of your choice. We support the most common gaming engines out of the box. This is what it looks like in Qodana itself. Normally as a developer you wouldn’t spend much time in here. This is nice for a team lead or a project manager. One of the Qodana team vibe-coded this example project below. It was a banking front-end written in Java and the vibe-coding part itself just took a few minutes to get it up and running.

Watch Qodana Demo

Qodana found 126 issues and gives you a nice way to give you a quick view into what is important. Then you can apply quick-fixes to them. There are different ways to set this up (with varying levels of automation).

Here we’ve done it as part of a GitHub Actions pipeline. Then we put the remaining problem into the Baseline. Once they are in the Baseline they don’t slow you down. The next time you run a scan with Qodana and you find new issues, ideally it would fix 3 automatically, and you’d only see 2 new ones. So it’s easier to figure out how to spend your time.

If we look at the five remaining issues, you can see some show duplicated code. While you can view them from Qodana, you don’t fix them from here. So if we open this in IntelliJ IDEA. You can see it brings us to the exact position in the IntelliJ IDEA codebase.

This will work for our IDEs however, it also works with Visual Studio, Visual Studio Code and Cursor. You can also use our CI tool as well. Here you can review the issues, like duplicated code, by hovering over it (depends on your solution) and then go to more actions, AI actions and have AI fix these issues for you.

You can do it manually or with an agent, semi-automating it so it works in the background and you wait for the clean code on the other end. If you are interested in finding out more, please contact us and we can show you how to use it or you and your team can try it out for free.

Try Qodana

Users have also tried Qodana for game development. Read how Doc Bok used Qodana for a Minecraft game – or how Qodana works on Unity and Unreal Engine projects.

Once you ask AI to add tests, eventually these tests and all repositories start to overflow and even trivial processes like linting can lag. Do you have experience with this?

In some cases you have to jump through ten different loops to release code. Most of the time this is due to someone starting but no one ever reviews the pipeline, what makes sense and what not but static analysis shouldn’t slow you dow.n So, in Qodana, a so-called pull request mode only checks the changed files and should only take a minute or two.

How much can the JetBrains built-in agents in the IDEs read the IDE’s static analysis tools?

Rider has a feature called Hooks. Every time the agent generates code, it’ll call the Hooks in rider. One of them will be to reformat the code and the other to check for the current problems in a file, do the linting, check the problems and report that back to the agent, then the agent can regenerate the code using your standards or fix what you only ask it to expect. It is deterministic so the agent is forced to use the hooks rather than being advised. The hook is enabled and executed every time.

Please note: Widely adopted AI technology is relatively new and the results of burgeoning data should always be deeply interrogated, including data presented in this post.

Special thanks to Kai for his insights.

Read the whole story
alvinashcraft
7 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Famous quotes we've been getting wrong, from Robert Frost to 'Don't mess with Texas,' with Eli Burnstein

1 Share

1227. This week, we talk to Eli Burnstein, author of "Phrased & Confused." We look at why Robert Frost's "road less traveled" wasn't really less traveled, and why the other half of Stewart Brand's "information wants to be free" will make you think about it differently. Then we look at why "Hell is other people" isn't about crowds and how "Don't mess with Texas" began as an anti-littering campaign.


A hearty thank you to the Keepers of the Commas and one Immortal on Patreon. We appreciate your support!

  • Larry Rosenblum
  • Mahala Russell
  • George Wilson
  • Laurel Paul
  • Linda Cox
  • Birna Anna Björnsdóttir
  • Kate Wade


🔗 Share your familect recording in Speakpipe or by leaving a voicemail at 833-214-GIRL (833-214-4475)

🔗 Watch my LinkedIn Learning writing courses.

🔗 Subscribe to the newsletter.

🔗 Find an edited transcript.

🔗 Get Grammar Girl books.


| HOST: Mignon Fogarty

| Grammar Girl is part of the Quick and Dirty Tips podcast network.

  • Audio Engineer: Dan Feierabend
  • Director of Podcast: Holly Hutchings
  • Advertising Operations Specialist: Morgan Christianson
  • Marketing and Video: Nat Hoopes, Rebekah Sebastian
  • Podcast Associate: Maram Elnagheeb

| Theme music by Catherine Rannus.

| Grammar Girl Social Media: YouTube. TikTok. Facebook. Threads. Instagram. LinkedIn. Mastodon. Bluesky.


Hosted on Acast. See acast.com/privacy for more information.





Download audio: https://sphinx.acast.com/p/open/s/69c1476c007cdcf83fc0964b/e/6ac037295558f9dbe286a0a7/media.mp3
Read the whole story
alvinashcraft
7 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Narrative intelligence and the human advantage

1 Share

As AI reshapes how we work, create, and think about our roles, staying adaptable means understanding not just the technology, but our own stories and identities. Reed Frerichs joins Daniel and Chris to explore narrative intelligence, storytelling, leadership, and personal growth in an AI-driven world. They discuss how entrepreneurs and leaders can use AI tools to navigate changing roles, embrace uncertainty, and develop emotional intelligence along with Reed's “own, author, act” framework.

Featuring: 

Links:

Sponsors:

Resources and Events:





Download audio: https://pscrb.fm/rss/p/dts.podtrac.com/redirect.mp3/media.transistor.fm/f2fcb677/ee0419b3.mp3
Read the whole story
alvinashcraft
7 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

First Draft Notes: Verifiable Credential Threat Models

1 Share

The Verifiable Credentials Working Group has published a series of W3C Working Group Note Drafts for threat models. All identify and analyze security and privacy threats specific to their respective recommendation-track documents:

The working group welcomes comments via GitHub repository issues; the respective repository URL-s can be found in the header of each document.

Read the whole story
alvinashcraft
8 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

New Report: The State of CI/CD in 2026

1 Share

CI/CD remains one of the foundations of modern software development. According to the JetBrains Developer Ecosystem Survey 2026, 83.4% of respondents who use DevOps practices run CI/CD pipelines.

The new report looks at how teams are running those pipelines, which tools they use, and where AI fits into their workflows. It brings together findings from four JetBrains studies, including the State of CI/CD Tools Survey 2026.

Here are some of the numbers that stood out:

  • 72.8% run their primary CI/CD system on premises or on self-managed cloud infrastructure.
  • 30.5% use an on-premises installation, the highest share recorded in five years.
  • 48.8% of organizations use AI for at least one CI/CD task.
  • Only 8% run AI-powered steps directly inside a build or test.
  • 28% interact with their CI/CD tools through MCP or agent skills, compared with 10% who use an assistant built into the CI/CD product.

Most AI use currently happens around the pipeline. Teams use it to review code, write or fix tests, and diagnose build failures. 

At the same time, self-hosting remains an important part of the CI/CD landscape, especially for organizations that need more control over their infrastructure, data, security, or costs.

The report also explores the most widely used CI/CD tools, why organizations maintain several platforms, what makes teams consider switching, and the main barriers to wider AI adoption. Give it a read!

See the report

Read the whole story
alvinashcraft
8 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

v2026.9.9

1 Share

OpenClaw 2026.9.9

Read the whole story
alvinashcraft
9 minutes ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories