Generative AI and Technical Debt in Software Development: Productivity Gains versus Code Quality and Security Risk
DOI:
https://doi.org/10.70917/ijcisim-2026-5434Keywords:
Generative AI, Technical Debt, Software Development, Developer Productivity, Code Quality, Security Vulnerabilities, AI Coding Assistants, Software Maintainability, Productivity Paradox, IT FirmsAbstract
Generative Artificial Intelligence (GenAI) coding assistants like GitHub Copilot, ChatGPT, Amazon CodeWhisperer, and new agentic development environments have taken the software industry by storm, with the promise of enhancing developer productivity. But there has been increasing evidence to the contrary, that since these benefits come with a parallel increase in what has been dubbed "technical debt"—quality, maintainability and security problems only become apparent at a later point in the software lifecycle. This paper empirically analyzes the impact of GenAI coding assistants on developer productivity, code quality and maintainability and security posture from two perspectives, that of IT companies. Concurrent mixed method (triangulation) design is used with structured survey of 412 software professionals and repository-level analysis of 1240 software code commits with the authorship of each commit identified, and 22 semi-structured practitioner interviews. Two methods are used to test the hypothesis of the ‘productivity paradox' – structural equation modelling and non-parametric artefact analysis. The results suggest that the use of GenAI can statistically significantly improve productivity in the short term (β = 0.48, p < .001) particularly when using GenAI for the routine aspect of work, but benefits appear to be lower for more experienced developers when considering the maintenance burden (β = 0.06, p > .05). Lacking good governance, AI-assisted code has substantially higher technical-debt density (37%) and security-vulnerability density (41%) than do codes written by humans. The governance maturity is the key moderator that has significant increase in the value of Δ R^2 = 0.14. The study suggests a governance model that consists of these three dimensions: velocity, maintainability, and security, and extends the concept of technical debt in the field of information systems and software engineering, adding the concept of technical debt as a socio-technical risk instead of automated.