# AI-generated code: pre-release checklist

For code written with AI coding tools (Cursor, GitHub Copilot, Claude Code or any other) before it reaches your users. The same checks work for hand-written code; AI just makes some failures more likely and easier to miss in review, because the code looks right.

The research behind each item, with sources, is in the guide [how to test AI-generated code](https://shipperag.com/how-to-test-ai-generated-code/?utm_source=github&utm_medium=repo&utm_campaign=release-kit).

## Before anyone prompts

- [ ] Acceptance criteria, business rules and edge cases are written down for this change.
- [ ] Non-functional targets are agreed: accessibility level (for example WCAG 2.2 AA), performance budget, browsers and devices.
- [ ] Unclear or conflicting requirements go to the product owner, not to the code.

## For every change

- [ ] **Business logic:** test cases come from the requirements (prices, VAT, discounts, limits, eligibility), not from reading the code.
- [ ] **Edge cases:** empty and expired states, failed or slow API calls, long input, other languages and time zones.
- [ ] **Access control:** tried with several roles and accounts, including changing IDs in URLs and calling APIs directly.
- [ ] **Secrets:** no API keys or tokens in front-end code, config or commits (run a secret scanner).
- [ ] **Dependencies:** every new package exists, is the one you meant, and comes from the expected publisher.
- [ ] **Input handling:** forms and APIs reject bad input safely.
- [ ] **Accessibility:** automated rules pass, and the changed screens work with a keyboard and a screen reader; no placeholder attributes left behind.
- [ ] **Design system:** colours, type, spacing and component states match the design tokens.
- [ ] **Regression:** whole journeys re-tested (sign-up, log-in, checkout or your equivalent), not only the changed screen.

## Independence and evidence

- [ ] Tests were written or run by a different person, tool or session from the one that wrote the code.
- [ ] Whoever (or whatever) fixed an issue did not approve its own fix.
- [ ] Results are recorded: what was checked, what failed, what was fixed, what was not covered.
- [ ] A named person signed off the release. Use the [release readiness checklist](release-readiness-checklist.md) and the [release readiness report](../templates/release-readiness-report.md).

---

Licensed CC BY 4.0. Made by [ShipperAG](https://shipperag.com/?utm_source=github&utm_medium=repo&utm_campaign=release-kit): agentic AI QA testing for tech and product teams (private pilot).
