Banks face ‘scale problem’ as AI-generated code floods testing pipelines

California-based Igor Kirilenko

As financial institutions accelerate the use of generative AI in software engineering, quality assurance and software testing teams are facing a growing challenge: how to validate increasingly large volumes of AI-generated code without compromising resilience, compliance, or reliability.

According to a senior industry insider, the answer lies in combining AI-assisted development with rigorous shift-left testing, static analysis, and continuous integration practices that keep human oversight firmly embedded in the lifecycle.

In a new analysis, Igor Kirilenko argued that embedded and safety-critical software teams are embracing AI cautiously because of the operational and regulatory risks associated with unverified code generation.

“Embedded software development faces many challenges. Teams are under pressure to build increasingly sophisticated systems in less time,” the Chief Product Officer of major U.S.-based vendor Parasoft wrote.

“But, unlike counterparts in enterprise software development, embedded systems need to meet stringent safety, security, and reliability requirements.”

For banks and financial services firms increasingly deploying AI into testing, DevOps, payments infrastructure, trading systems and customer-facing platforms, the concerns highlighted by Parasoft mirror wider industry anxieties around governance, resilience and software assurance.

AI governance

Kirilenko stressed that financial and embedded software teams cannot rely on AI coding assistants alone, particularly as code generation volumes rapidly increase.

“One of the challenges developers face with AI coding assistants is not simply that the generated code may be incorrect,” Los Angeles, California-based Kirilenko stated.

“The real issue is scale. AI can generate large volumes of code very quickly and validating that output becomes significantly more demanding.”

That warning is especially relevant for banking QA teams already grappling with AI-driven development velocity increases, tighter release cycles and mounting regulatory expectations around operational resilience.

“AI-generated code often looks correct but still requires rework,” Kirilenko explained. “More than 70% of developers report rewriting or refactoring AI-generated code before production use.”


“The key piece of the puzzle is to embrace continuous integration practices.”

– Igor Kirilenko

In highly regulated financial environments, defects missed during testing can have systemic implications ranging from outages and failed payments to compliance breaches and cyber vulnerabilities.

Kirilenko argued that this is pushing organisations toward stronger shift-left development models built around continuous integration and automated validation.

“A major element in reconciling the seemingly disparate needs for development speed, flexibility, and safety in embedded systems is to adopt a shift-left strategy based on continuous-integration practices,” he wrote.

“The key piece of the puzzle is to embrace continuous integration practices where developers use system specifications to create unit and integration tests in concert with the software itself.”

Static analysis

Parasoft’s analysis places particular emphasis on static analysis as a critical control layer for AI-assisted software engineering.

“Tests that are complementary to those that check functionality are equally important,” wrote Kirilenko. “It is easy for security vulnerabilities such as buffer overflows or poor memory usage practices to sneak into code.”

“Today, static analysis can handle far more than conformance with coding styles, such as MISRA, CERT, or AUTOSAR C++14,” he added.

Igor Kirilenko

“By performing control flow and data flow analysis, static analysis can identify memory leaks, potential data corruption, unsafe memory usage, race conditions, and common security vulnerabilities such as buffer overflows and injection flaws.”

For financial institutions deploying AI-generated code into cloud-native banking platforms, mobile applications and payment systems, those capabilities increasingly align with regulatory scrutiny around secure software development practices and digital resilience controls.

Kirilenko argued that combining automated testing with static analysis allows organisations to establish practical governance boundaries for AI-generated code.

“By running static analysis and unit testing on each code update, the code generated by AI can be driven to a much higher level of quality than is possible using a coding assistant on its own,” he wrote.

“As AI becomes more ingrained in development, static analysis and test-driven validation become the guardrails that enable teams to build trust in AI-generated code.”

Human touch

Despite growing experimentation with autonomous agents and AI-assisted workflows, Kirilenko emphasised that human review remains central, particularly in safety-critical or highly regulated sectors.

“Crucially, development teams remain in control of which parts of the project are automated by AI,” he pointed out. “Those decisions can evolve over time as teams gain confidence in the real-world performance of the tools.”

The company also highlighted the emergence of multi-agent AI workflows capable of generating code, remediating static-analysis violations, creating tests and improving coverage metrics.

“Some banks are beginning to explore multi-agent workflows, where different AI agents specialise in tasks such as code generation, remediation of static-analysis violations, test creation, and coverage improvement,” Kirilenko explained.

However, he stressed that such workflows remain constrained and closely supervised in high-risk environments.

“In safety-critical embedded development, however, these workflows are typically constrained and remain under human supervision.”


“Some banks are beginning to explore multi-agent workflows, where different AI agents specialise in tasks.”

– Igor Kirilenko

Kirilenko pointed to technologies such as the Model Context Protocol (MCP) as mechanisms for constraining AI agents within approved operational boundaries.

“Through mechanisms such as the Model Context Protocol (MCP), software agents can invoke static analysis, unit testing, and coverage tools as part of the development process,” he wrote.

“MCP provides the structured contextual information needed to ensure that the agents operate within defined boundaries and act on relevant data.”

Coverage optimisation and incident response

Beyond code generation itself, Kirilenko sees AI increasingly being applied to automated test generation, coverage analysis and post-incident diagnostics.

“Code coverage analysis is a key part of any project that involves high-criticality software,” he wrote. “AI can analyse which parts of the application remain uncovered and generate new test cases that exercise those functions more fully.”

He added that “this can help teams satisfy demanding structural coverage objectives, including statement, branch, and MC/DC coverage.”

Kirilenko also suggested generative AI could support incident management and remediation workflows by analysing logs, telemetry and stack traces to identify root causes faster.

“Generative AI can also assist in identifying the causes of problems found in the field,” he stated.

“By analysing logs, stack traces, and telemetry, AI can help identify likely causes, highlight gaps in test coverage, and accelerate the verification of fixes before they are delivered through an OTA update.”

For QA and software testing teams inside banks and financial institutions, the broader message is clear: AI-assisted development may accelerate software delivery, but without automated verification, static analysis and disciplined testing frameworks, development speed risks outpacing governance and resilience controls.

As Kirilenko concluded: “The key is not fully autonomous AI. It is combining AI with static analysis, testing, coverage, and human oversight to create a faster, safer, and more controlled development process.”


WHY not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS