AI-assisted web development is now everyday work for a lot of developers. At the time of writing (July 2026), the AI coding tools involved range from autocomplete that suggests code as someone types, to chat assistants that explain unfamiliar code, to agents that edit many files and run commands on their own. For anyone paying for a website, that raises fair questions. Should the site cost less now? Is machine-written code safe to put in front of customers? And what is your developer actually doing with it?
The honest picture is mixed. AI makes some jobs much faster and adds new ways for things to go wrong, most of them invisible until a site is live. This guide covers both, plus “vibe coding” and the questions to ask whoever builds your site.
It is part of our wider guide to how AI is changing websites; the design side is covered in AI in web design.
The short answer
AI-assisted web development means developers using AI tools to write, explain, test and restructure code, while a person reviews the result and stays responsible for it.
- It speeds up well-defined work whose output is easy to check: boilerplate, tests, refactors, migration scripts and making sense of someone else’s code.
- It fails in quiet ways: code that works but is insecure, advice that was right a few years ago, packages that don’t exist, accessibility regressions and heavier pages.
- It needs the usual safeguards: human code review, automated tests, a staging site, and dependency and security checks.
- It doesn’t remove the expensive parts of a project, which are decisions, content and quality assurance.
What AI-assisted web development speeds up
AI helps most where the task is clear and the output can be checked quickly. Examples from a typical WordPress build or redesign:
Boilerplate and repetitive code
Registering a custom post type for projects, marking up a set of form fields, adding the same schema markup to twenty templates. A developer already knows how to do this and can verify it at a glance, so AI turns an hour of typing into minutes of reviewing.
Tests
AI is good at drafting the test cases people forget: an enquiry form submitted empty, with a very long name, with an invalid email address, or in a writing system the form has never seen. One caution: tests generated from existing code tend to confirm what the code does, not what it should do. The expected behaviour has to come from a person.
Refactors
Splitting a sprawling template into readable parts, replacing repeated markup with one reusable component, renaming things consistently. With tests in place to catch breakage, AI handles the mechanical work well.
Migration scripts
Redesigns involve one-off data work: mapping hundreds of old URLs to new ones, cleaning a spreadsheet export, moving posts between systems. AI writes these scripts quickly, and because they run once on a copy of the data, mistakes are cheap to fix. Deciding where each old URL should point still needs someone who knows the site, as our website migration SEO checklist explains.
Explaining legacy code
Inheriting a site often means reading code nobody documented. AI can summarise what a custom plugin does or trace where a form sends its data. That speeds up audits and handovers, provided each explanation is confirmed against the code, not taken on trust.
Where AI-generated code goes wrong
AI-generated code rarely fails obviously. It works in the demo and fails later, in ways a non-developer might never notice.
Plausible but insecure code
A classic WordPress example: a handler that lets staff update listings, written without checking a nonce (WordPress’s protection against requests forged by another site), without checking the user’s permissions with current_user_can() and without sanitising the input. It works perfectly in testing, and it can let the wrong people change your data. Other common patterns: database queries glued together from strings instead of using $wpdb->prepare(), output printed without escaping (the usual route to cross-site scripting), and API keys in JavaScript that every visitor can read.
In a Stanford University study published in 2023, participants with an AI assistant wrote less secure code than those without one, yet were more likely to believe their code was secure. The assistant was an early model, but the lesson about false confidence stands. AI-generated code security comes down to review: someone checks each change against the risks in the OWASP Top 10 and the basics in our WordPress security guide.
Outdated APIs and advice
Models learn from code written in the past, and the web moves on. Typical examples:
- Tracking code for Universal Analytics, whose standard properties stopped processing data in July 2023 in favour of GA4.
- Speed work aimed at First Input Delay, which Google replaced with Interaction to Next Paint (INP) as a Core Web Vital in March 2024.
- PHP functions and WordPress techniques that have since been deprecated or removed.
The check. Before a suggested fix goes live, confirm in the official documentation that the approach is still current.
Packages that don’t exist
AI tools sometimes recommend packages that sound right but were never published. Security researchers have found that models suggest some of these invented names again and again, so an attacker can register one, fill it with malicious code and wait for someone to install what the AI suggested, a tactic nicknamed “slopsquatting”. The defence is simple: a person confirms every new dependency exists, is maintained and is the one intended.
Accessibility regressions
AI output often looks right while failing people who use a keyboard or a screen reader: a clickable div instead of a real button, icon buttons with no accessible name, form fields labelled only by placeholder text, focus outlines removed because they looked untidy, or grey text that falls below the WCAG 2.2 contrast minimum of 4.5:1 for normal text. Automated checkers catch some of these, not all, so keyboard testing still matters. Our web accessibility guide covers what to test.
Extra dependencies that slow pages
Asked for a small effect, AI often reaches for a large library: a full animation framework for one fade-in, a slider package for a single carousel. Each adds JavaScript that phones must download and process, and the page starts to feel sluggish to tap. Google rates an INP of 200 milliseconds or less as good, and heavy scripts are a common reason sites miss it, as Core Web Vitals explained sets out.
Vibe coding: fine for prototypes, risky in production
“Vibe coding” is a term coined by AI researcher Andrej Karpathy in a February 2025 post for building software by describing what you want, accepting whatever the AI writes and judging it only by whether it seems to work. Nobody reads the code.
That has real uses:
- A clickable prototype to test an idea with customers before paying for a build.
- An internal tool that one person uses and nobody would miss.
- A demo that helps stakeholders agree on what they want.
It becomes risky the moment the result faces the public and has to last. A vibe-coded site that collects enquiries handles personal data whose security nobody has checked. It may fail keyboard users or search engines, and nobody can maintain it, because no person understands how it works. When something breaks, the only option is to ask the AI again and hope.
A useful test: could someone other than the AI explain every part of the code that handles your customers’ data? If not, treat the prototype as a specification for the real build, not its foundation. The same applies to prompt-to-site tools, which we compare in AI website builders vs a professionally built website.
The safeguards that matter
None of these is new, but they matter more now that code arrives faster than anyone could type it.
| Safeguard | What it involves | What it catches |
|---|---|---|
| Human code review | A developer who understands each change reviews it, and whoever commits it owns it | Insecure code, outdated APIs |
| Automated tests | Forms, key pages and integrations tested before every release | Features broken by a refactor |
| A staging site | Changes checked on a private copy before they reach the live site | Surprises on the live site |
| Dependency checks | New plugins and packages verified, versions pinned, known vulnerabilities checked (for example with npm audit or composer audit) |
Invented or vulnerable packages |
| Accessibility and speed checks | Keyboard testing, an automated scan, PageSpeed Insights before and after | Accessibility regressions, slower pages |
| Rules for AI tools | No customer data, passwords or API keys in prompts; business accounts with clear data terms | Leaked data and credentials |
AI code review tools can be a useful second reader, flagging issues a tired human might miss. Treat them as an extra check, never the only one. For WordPress sites, our guide to WordPress best practices explains how staging should be set up.
Why AI doesn’t make a website cheap
Typing code was never the most expensive part of a business website. The bigger costs sit elsewhere:
- Decisions. Who the site is for, what it must persuade them to do, how pages are structured and which trade-offs are worth making. AI can suggest options. Someone accountable still has to choose.
- Content. Words that carry your real expertise, prices and proof, photos of your own work, and copy in the languages your customers use. This is often where projects stall, with or without AI.
- Quality assurance. Testing on real phones, in every language, with keyboards and screen readers, and with real form submissions reaching real inboxes. AI-generated code needs more of this, not less.
A website that brings in enquiries comes from strategy, UX, design, development, performance, SEO, content, conversion and continuous improvement working together. AI is one more ingredient, and it shortens only part of the work. Where it saves genuine time, a sensible developer puts it back into testing, speed and content, or passes it on as a lower price for routine work. Either is reasonable; ask which you’re getting, and compare what’s included in our website packages and prices.
Questions to ask your developer about AI
You don’t need to read code to judge how carefully it was produced. These questions work for any developer, alongside our wider list of questions to ask before hiring a web designer.
| Question | A reassuring answer | A warning sign |
|---|---|---|
| Which AI tools do you use, and for what? | Specific tools for specific tasks | Vague, or “for everything” |
| Who reviews AI-generated code before it reaches our site? | A developer, on every change | “The tool is very accurate” |
| What do you put into AI tools? | No client data or passwords, on business accounts | Unsure, or personal free accounts |
| How do you check new plugins and packages? | Verified, maintained, versions pinned | “Whatever the AI recommends” |
| Where are changes tested before going live? | On a staging site, with automated tests | Straight on the live site |
| How do you check accessibility and speed? | Keyboard tests, scans and speed checks before and after | “It looks fine on my screen” |
| Could another developer maintain this code? | Yes, it’s readable and documented | Only by prompting the AI again |
What to do next
AI-assisted web development is neither a shortcut to a cheap website nor something to fear. In careful hands it removes drudgery. Without review, tests and staging, it produces code that looks finished and isn’t.
If you are planning a new site, our website design and development page walks through how a build runs, from planning and content to testing and handover. Bring the questions above to the first conversation; we’re happy to answer every one.
Already have a site that was put together quickly, by an AI tool or anyone else? A free website audit is a sensible first look at its speed, security and mobile experience before you decide whether to fix it or rebuild.