Human Review Sampling for AI-Generated Code: Cost per Defect Escaped
By Eric Bush · August 25, 2026 · 7 min read
Human Review Sampling for AI-Generated Code: Cost per Defect Escaped is fundamentally a unit-economics question. Teams should connect risk-stratified human review to completed, reviewed engineering work instead of treating tokens, benchmark throughput, or a product announcement as the outcome.
Agent output is not independent. One faulty prompt, stale dependency, or misunderstood repository rule can create correlated defects across many changes. Random sampling alone may miss high-impact clusters, while full manual review can consume more labor than the automation saves.
Start With the Evidence Boundary
Sampling is appropriate only where policy permits and where automated gates plus rollback limit the consequence of an escaped defect. Record the source date, environment, model, workload, and excluded costs before using the evidence in a forecast. A precise boundary keeps a useful observation from turning into a universal assumption.
For risk-stratified human review, separate observed facts from your own scenario. Facts belong in an immutable research note. Assumptions such as utilization, engineer time, task mix, and failure rate belong in an editable cost model. When an assumption changes, the forecast should update without rewriting the evidence.
Choose a Business-Level Cost Unit
Use expected defect loss prevented per reviewer hour as the primary unit. Token price remains an input, but it cannot reveal whether work was correct, timely, accepted, or worth doing. Include failed attempts, abandoned sandboxes, review, retries, and shared infrastructure in the numerator.
For risk-stratified human review, define completion with an auditable event: tests passed, a reviewer accepted the artifact, the pull request merged, or the incident action was verified. Keep a second quality-adjusted view that weights security and production failures more heavily than cosmetic corrections. Otherwise a system can appear cheaper by producing more low-value output.
Map the Full Cost Stack
- change risk and blast radius: measure the quantity, unit price, owner, and whether it scales per request, per minute, or per retained artifact.
- review depth: measure the quantity, unit price, owner, and whether it scales per request, per minute, or per retained artifact.
- automated test strength: measure the quantity, unit price, owner, and whether it scales per request, per minute, or per retained artifact.
- correlated failure probability: measure the quantity, unit price, owner, and whether it scales per request, per minute, or per retained artifact.
- incident and rollback cost: measure the quantity, unit price, owner, and whether it scales per request, per minute, or per retained artifact.
For risk-stratified human review, avoid averaging away peaks. Agent workloads are bursty, stateful, and heavy-tailed. A monthly average can hide the concurrency window that causes rate-limit retries, reviewer overload, or idle reserved capacity. Segment interactive work, background maintenance, urgent incidents, and scheduled bulk jobs.
Instrument the Decision
- defects per reviewed change
- severity-weighted escape rate
- review minutes
- false reassurance from passing gates
- clusters by prompt or model version
For risk-stratified human review, attach these signals to one task identifier that survives across chat, model calls, tools, sandboxes, commits, and review. Aggregate dashboards are useful, but task-level joins explain why two apparently similar jobs have different costs. Preserve model snapshot, prompt release, repository SHA, cache state, and policy outcome.
Run a Controlled Comparison
For risk-stratified human review, replay a representative set using the current configuration and the proposed change. Hold task inputs, acceptance tests, reviewer rubric, and consequence boundaries constant. Include easy, median, difficult, and negative cases. Run enough repeats to expose stochastic retries instead of selecting one favorable trajectory.
For risk-stratified human review, report distributions, not one mean. Compare p50 and p95 cost, latency, tokens, tool calls, and reviewer corrections. A change that helps median tasks but makes difficult tasks unstable may raise incident risk. Document censored runs and timeouts as failures with real cost, not missing data.
Put Guardrails Around Scale
- Review all high-risk surfaces.
- Sample by model and task family.
- Increase sampling after drift.
- Trace every change to its behavioral release.
For risk-stratified human review, set a hard ceiling for dollars, wall time, model calls, tool calls, and external side effects. Add a lower warning threshold so operators can investigate before cancellation. A task stopped by policy should retain enough trace data to diagnose the cause without automatically retrying the same expensive path.
Account for Human Time and Risk
For risk-stratified human review, price the minutes spent clarifying requests, watching progress, reviewing diffs, correcting output, and recovering from mistakes. Use a loaded hourly rate and record active versus waiting time. Automation that shifts work from implementation to repeated supervision may change the job without reducing its total cost.
For risk-stratified human review, estimate expected loss separately: probability of an escaped defect multiplied by its remediation and business impact. Security, data handling, and production changes need stricter gates than documentation or isolated tests. Cheap inference is not a discount on accountability.
Review the Decision on a Fixed Cadence
For risk-stratified human review, recalculate after model price changes, tool revisions, repository growth, or a shift in task mix. Keep the old cohort and assumptions so improvements are distinguishable from easier work. Owners should be able to explain both the current unit cost and the largest uncertainty in it.
For risk-stratified human review, do not optimize every stage simultaneously. Change one major variable, observe enough tasks, and then keep or revert it. This produces a reusable learning loop and prevents a cheaper model, wider permissions, and looser review from being mistaken for one coherent improvement.
Bottom Line
Allocate review where marginal expected loss reduction is greatest, then continuously update the strata from real defects. Tie the choice to verified outcomes, preserve the evidence boundary, and revisit it when traffic or pricing changes. The durable advantage is not a single low number; it is a measurement system that shows when risk-stratified human review creates or destroys engineering value.
Want to calculate exact costs for your project?
Frequently Asked Questions
What is the best cost unit for risk-stratified human review?
Use expected defect loss prevented per reviewer hour, then retain tokens, runtime, infrastructure, and review as diagnostic inputs.
Why is token price alone misleading?
It excludes failed attempts, tool and sandbox costs, human review, latency, and the business impact of incorrect work.
How should teams test a proposed change?
Replay representative tasks with fixed acceptance criteria and compare cost, latency, quality, retries, and reviewer corrections as distributions.
When should the decision be revisited?
Review it after material price, model, tool, repository, workload, or policy changes and on a regular operating cadence.
Related Articles
AI Code Review Cost Calculator: Tokens, Human Hours, and Defect Risk
A practical AI code review cost calculator for 2026 teams, combining model tokens, reviewer time, CI cost, false positives, missed defects, and escalation rules.
AI Code Review Cost: Single Reviewer vs Multi-Agent Judge Panel — Which Actually Saves Money?
Comparing the cost-per-PR economics of a single Claude Opus reviewer against a multi-agent judge panel. We use Apple's June 2026 'correlated errors' research to design a panel that saves 60% without losing signal.
The Cost of AI Code Review: Should You Build Cheap and Review Expensive?
Using a premium model to review code written by a cheap one is a popular cost-saving pattern. We break down when the build-cheap, review-expensive split actually saves money—and when it doesn't.