Traditional workflow
Before generative AI assistance- 1
Clarify the goal using a brief for account recovery
- 2
Interview stakeholders
- 3
Resolve ambiguous recovery rules
- 4
Write acceptance criteria
- 5
Check the result against the agreed criteria
- 6
Communicate the outcome and record the decision
AI-assisted workflow
AI contributes. You guide and verify.- 1
Define the goal, constraints, and permitted information
- 2
Provide relevant, sanitized context from a brief for account recovery
- 3
Ask AI to draft questions and identify conflicting requirements
AI + YOU - 4
Inspect suggestions against original evidence and domain rules
- 5
Revise the output and independently validate the result
YOU - 6
A responsible professional approves and communicates the outcome
Do these criteria reflect the user need and agreed security constraints?
The shift: Reviewing, validating, and integrating AI-generated code. Foundational skills still matter.
A practical learning path for Software Engineering.
What changes — and what doesn’tSkills & responsibilities
Draft questions and identify conflicting requirements. The output is a starting point to inspect, not a decision to accept automatically.
Validate correctness, choose tradeoffs, protect users, and approve changes.
FoundationsProgramming, algorithms, system design, and security.
AI collaborationProviding task-specific context and requesting explicit assumptions.
VerificationChecking a brief for account recovery against independent evidence.
Professional skillsCommunicating tradeoffs and taking responsibility.
Where AI can go wrong3 things to check
A plausible but wrong answer
AI may assume email access is always available. It can fail the underlying goal even when it sounds convincing.
Your checkClarify the conflict with the security owner before defining acceptance criteria.
Missing or invented context
AI may fill gaps with unsupported assumptions, which can send the work in the wrong direction.
Your checkTrace claims to original evidence and ask the relevant person about unknowns.
Information shared in the wrong place
Sensitive records or code can cross confidentiality boundaries if supplied to an unsuitable tool.
Your checkUse approved tools, share the minimum context needed, and follow your organization’s rules.
Try a quick exerciseA practical scenario
An account-recovery brief says both “no identity checks” and “prevent unauthorized recovery.”
Sources & contextEvidence behind this example
These are illustrative workflows, not claims that AI is always better or that every organization works this way. The scenarios and checkpoints are editorial teaching examples.
Reviewed September 2026 · Growing PracticeO*NET — Software DevelopersSupports the role and task baseline; it does not validate our AI workflow sequences.GitHub — Responsible use of inline suggestionsDocuments review and security responsibilities for generated code; capabilities vary by tool and configuration.GitHub — About Copilot code reviewEvidence of an available assisted-review capability, not proof of universal adoption or correctness.How we build these examples