Skip to main content
How We Use AI Code Review Without Letting It Review Us — Anselm Fowel
AI & Technology

How We Use AI Code Review Without Letting It Review Us

5 min read
762 views
Share:

AI code review tools have gone from novelty to default in about eighteen months. We adopted them, they genuinely help, and they have also quietly created a set of new failure modes that nobody put in the marketing material. On a fintech codebase where the cost of a missed defect is measured in real money and regulatory attention, getting this balance right matters more than it would almost anywhere else.

AI review is a first pass, never the final word on money-movement code.
AI review is a first pass, never the final word on money-movement code.

This is how my teams actually use AI in review, where we lean on it hard, where we refuse to, and the cultural risk I watch most closely.

What AI review is genuinely good at

The strengths are real, consistent, and worth leaning into. AI reviewers are tireless about exactly the boring, high-value checks that human reviewers skip when they are tired, distracted, or reviewing their fortieth pull request of the week.

  • Null and boundary conditions that a human skims past at 5pm on a Friday.
  • Inconsistent error handling across functions that should behave the same way.
  • Obvious security smells: unparameterized queries, secrets committed to the repo, missing authorization checks.
  • Drift from the conventions the rest of the codebase already follows.

For this whole category the machine is faster and more consistent than I am, and it never gets bored on the hundredth file. That is real leverage, and pretending otherwise out of pride helps nobody.

Where it quietly fails

The danger is not that AI review is sometimes wrong. The danger is that it is confidently wrong about things that look entirely plausible. It does not understand your business domain. It does not know that this particular transfer must never round, that this field is regulated and cannot appear in a log line, or that this seemingly redundant check exists because of an incident two years ago.

The AI reviews the code. It does not review the decision the code encodes. That part is still entirely yours, and it is the part that actually moves money.

It will happily approve a change that is technically clean, well-formatted, idiomatic, and financially catastrophic. The cleaner the code, in fact, the more likely a tired human is to wave it through on the AI's implied endorsement.

Enjoying this article?

Get more like it in your inbox — practical engineering leadership, fintech, and AI. No spam, unsubscribe anytime.

The rule we settled on

AI review is a first pass, never the last word. It runs automatically on every pull request and clears the noise: the formatting nits, the obvious bugs, the convention drift. That frees up human attention for the things humans are uniquely good at.

Then a hard rule kicks in. Any pull request that touches money movement, authentication, or compliance-relevant data gets a human reviewer who owns the sign-off with their name on it. The AI informs that human; it never replaces them. We made this a written policy rather than a cultural preference precisely because cultural preferences erode under deadline pressure and written policies do not.

The skill-atrophy problem

The thing I watch most carefully is not a bug. It is what happens to junior engineers who grow up with these tools. If a junior learns to fix whatever the AI flags without ever understanding why it was flagged, they never build the judgment that turns a junior into a senior. They become very fast at applying corrections they do not understand, which is a fragile and dangerous kind of competence.

So we treat AI comments as teaching moments. When the tool flags something on a junior's pull request, the senior reviewer takes thirty seconds to explain the why in the thread, not just confirm the fix. The tool should be growing your engineers, not quietly hollowing them out while making them look productive.

Avoiding a new single point of failure

There is a quiet irony here. In our systems we work obsessively to eliminate single points of failure, redundancy everywhere, no one service that can take down the business. And then a team will let an AI reviewer become exactly that in their process: an unquestioned authority whose approval ends the conversation.

The discipline is to keep the human in the loop not as a rubber stamp but as the actual decision-maker, with the AI as one more input. The moment "the AI approved it" becomes a sufficient answer to "why did this ship," you have built the single point of failure you spend your whole architecture avoiding.

Anselm Fowel, CTO and fintech architect
Anselm Fowel — CTO & fintech architect

Conclusion: a tool, not an authority

Used well, AI review gives my team back real hours and catches real defects before they reach a customer. Used badly, it becomes an authority no one questions, which in a payments system is precisely the kind of risk we work hardest to design out everywhere else. The technology is genuinely good. The discipline around it is what determines whether it makes you safer or just faster on the way to a worse incident.

Enjoyed this article? Share it with others!

Share:

Get new posts in your inbox

Occasional, practical notes on engineering leadership, fintech, and building with AI. No spam, unsubscribe anytime.

Comments (8)

Leave a Comment

Comments are moderated and will appear after review.

Damilola Adebayo

July 17, 2026

Good writeup. One nit on "What AI review is genuinely good at": in Aurora Postgres you get most of this for free via a config flag.

Thomas Halliwell

July 13, 2026

Quick q on "Avoiding a new single point of failure" — how do you handle duplicate events when the partner API sends duplicate callbacks? We're on NATS and the sidecar reconciler feels overkill for our scale.

Nicole Wright

July 4, 2026

Does the "Conclusion: a tool, not an authority" still hold on a 254-service estate? We're at the smaller end of that and some of these patterns feel like they need a dedicated platform team to run properly.

Yetunde Olatunji

July 1, 2026

Quick question on "What AI review is genuinely good at" — does the pattern hold when the workload is bursty rather than steady state? We keep running into the high-fanout case and the textbook answers do not always survive contact.

Nafisa Adamu

June 23, 2026

Good topic. 4 years at Interswitch before going independent here. What we do differently: keep an append-only audit log and rebuild state from it on demand on Thales HSM. It is not universally better; operational complexity is real, but the testability is dramatically better and that pays for itself the first time you have to answer a SOC 2 auditor question at 4am.

Ikechukwu Onyeka

June 18, 2026

Refreshing to read this framed for our market rather than lifted from a Silicon Valley playbook. Specifically the "Avoiding a new single point of failure" piece — the settlement partners audit for it, and that changes the design constraints in ways the US-centric literature never touches.

Ashley Hernandez

June 11, 2026

Good topic. SRE at a B2B card issuer here. What we do differently: split the read and write paths at the DB level on GKE. It is not universally better; operational complexity is real, but the debuggability is dramatically better and that pays for itself the first time you have to answer a forensic investigator question at 4am.

Ashley Mitchell

June 7, 2026

15 months into my first eng job at a mid-size fintech, so a lot of this is above me, but the "Conclusion: a tool, not an authority" bit made a concept click that I had been nodding along to in code review for months. Thanks for writing at a level that doesn't gatekeep newer engineers out.

About the author

Anselm Fowel

Anselm Fowel

Chief Technology Officer & fintech architect. 16+ years leading engineering across AlliancePay, Mondu, Transalliance, Global Accelerex, and Fidelity Bank — writing here about engineering leadership, fintech architecture, and AI in production.

Read next

Subscribe to the newsletter

Practical notes on engineering leadership, fintech, and building with AI — delivered to your inbox. No spam, unsubscribe anytime.

Anselm Fowel

Chief Technology Officer | Fintech Architect | Engineering Leader

Building the future of financial technology through innovative engineering and strategic leadership.

Expertise

  • CTO Advisory
  • Fintech Architecture
  • Team Leadership
  • Technical Strategy
  • System Design

Get In Touch

[email protected]
Lagos, Nigeria

© 2026 Anselm Fowel. Crafted with passion.