GitHub's coding agent opened more than 1 million pull requests between May and September 2025, according to GitHub's own Octoverse 2025 report.

That activity skewed toward established, well-known repositories, not throwaway side projects. Teams are trying agentic coding on the codebases that actually matter, not just experimenting on the margins.

This guide is part of Tecla's Agentic AI Use Cases series, covering agentic AI for software development specifically: the ticket-to-PR workflows, testing patterns, and review processes that have moved past the pilot stage.

What Is Agentic AI?

Agentic AI refers to goal-oriented systems that plan, execute, and adapt multi-step tasks with minimal human oversight, distinct from traditional automation or generative AI built to answer a single prompt.

Three capabilities define it: autonomy, deciding what actions to take and carrying them out; adaptability, adjusting the plan as new information arrives; and coordination, working across tools and systems to finish what no single tool could handle alone.

In software development, that difference shows up in how a ticket gets picked up. A code completion tool suggests the next few lines while someone types.

An agentic system reads the ticket, writes the change across however many files it touches, runs the tests, and opens a pull request for review.

How Agentic Systems Work in Software Development

Software development automated in stages, first through linters and build tools enforcing fixed rules, then through code completion suggesting the next line as someone typed.

That completion model follows a narrow, predictable pattern: predict the next token, given the current context.

It is fast and genuinely useful, but it never plans further ahead than the current line, and every larger task still needed a person to sequence the steps.

Agentic AI operates differently: it reasons across an entire task instead of one line at a time.

It reads the ticket or the failing test, decides what files need to change, makes the change, and verifies it against the test suite, the way a developer working through the same ticket would.

The trade-off is real and worth naming directly: completion tools are more predictable and cheaper to run per suggestion; agentic systems are more capable and more expensive to run per task.

Most production engineering workflows in 2026 are not one or the other.

They use completion for the moment-to-moment writing, agentic reasoning for well-scoped tickets and test generation, and a code review gate in front of anything that merges.

Perceive ticket, failing test
›
Retrieve codebase, docs, history
›
Reason plan, write change
↓
Human gate
›
Act open PR, run CI
›
Verify
Verify feeds back into Perceive, a continuous feedback loop, for the next ticket

Agentic AI Use Cases in Software Development

Engineering teams don't adopt agentic AI as one system. They adopt it workflow by workflow, starting wherever the volume problem is worst.

Nine of those starting points are documented below, each at working depth. The architecture above stays abstract until it's tied to an actual trigger and an actual system.

Ticket-to-PR Agents

A well-scoped ticket, a bug with a clear reproduction, a small feature with a defined interface, is exactly the kind of task an agent can carry from assignment to an open pull request without a developer starting from a blank file.

The workflow

What it does: reads an assigned ticket, writes the code change across the files it touches, runs the existing test suite, and opens a pull request with the reasoning attached instead of a developer starting from scratch.
1
Ticket assigned to the agent with acceptance criteria
2
Relevant codebase context and prior related changes retrieved
3
Code change drafted across the files the ticket actually touches
4
Existing test suite run against the change before anything opens
5
Human gate: developer reviews and approves the pull request before merge
The stack: an agentic coding platform (GitHub Copilot coding agent, Cursor, or Devin) integrated with the repository, issue tracker, and CI pipeline for test execution.
Why it works: well-scoped tickets are genuinely repeatable work with a clear definition of done, exactly the shape agentic execution handles well.
Production concern: an agent that passes its own tests but introduces a subtle logic error outside test coverage looks identical to a correct change until someone hits the edge case in production.

Test Generation

Writing thorough tests for existing code is exactly the kind of work that gets deprioritized under deadline pressure, which is precisely why test coverage tends to lag behind the code it's supposed to protect.

An agent that reads a function and generates tests covering its actual behavior, including edge cases a developer might not think to write by hand, closes coverage gaps faster than waiting for someone to circle back.

Bug Reproduction and Triage

A bug report with vague symptoms and no reproduction steps can eat hours before a developer even confirms the bug is real, let alone starts fixing it.

An agent that reads the report, correlates it against logs and recent changes, and produces a minimal reproduction hands a developer a confirmed starting point instead of a guessing game.

Code Review Assistance

GitHub found that 72.6% of developers using its AI code review feature said it improved their effectiveness at catching issues before merge.

The agent flags what a fast human pass might miss: an inconsistent pattern, a missed edge case, a change that contradicts a comment elsewhere in the file. The merge decision itself still belongs to a person.

Dependency and Security Vulnerability Remediation

GitHub's own Dependabot now runs on more than 2.6 million repositories, and AI-assisted fixes for common vulnerability categories are landing in thousands of repositories every month.

The same 2025 data found average fix time for critical vulnerabilities dropped from 37 to 26 days as automation absorbed the routine patching work, leaving security teams to focus on the vulnerabilities that actually need judgment.

Code Migration and Legacy Modernization

Migrating a codebase off a deprecated framework or language version is exactly the kind of large, mechanical, error-prone work that benefits from systematic execution rather than a person doing the same transformation thousands of times by hand.

An agent can apply a migration pattern consistently across a codebase and flag the specific spots that don't fit the pattern cleanly, which is usually where the actual engineering judgment is needed.

Documentation Generation

Documentation goes stale the moment code changes and nobody updates the docs, which describes most documentation most of the time.

An agent that generates and updates documentation directly from the code and its recent changes keeps the docs closer to what the code actually does, rather than what it did when someone last had time to write it up.

CI/CD Pipeline Debugging

A flaky test or a broken build step blocks an entire team's merges until someone tracks down what actually changed, often in a pipeline configuration nobody has looked at in months.

An agent that reads the failure logs, correlates them against recent commits, and proposes a fix can resolve routine pipeline breaks directly, escalating only the failures that need someone to make a real decision.

Agent Identity and Authentication for Development Systems

Broken Access Control overtook injection as the most common vulnerability type GitHub's scanning tools detect, flagged in more than 151,000 repositories, up 172% year over year.

Much of it traces to AI-generated code that scaffolds an endpoint correctly but skips the authentication check.

The workflow

What it does: verifies and governs coding agents as first-class non-human identities, since an agent that can open pull requests, run CI, and touch production configuration needs the same access discipline as a person with those permissions, not less.
1
Agent registered as a distinct identity with an owner and purpose
2
Request routed through an identity gateway before touching the repository or CI systems
3
Agent's permission for the specific action verified against its authorized scope
4
Human gate: action allowed, blocked, or escalated based on policy
5
Full action trail logged, distinguishing agent from human commits
The stack: an identity platform layered onto the repository host's existing access controls, with scoped tokens limiting an agent to the specific repositories and actions its task requires.
Why it works: enforcement happens at the action level, not just at login, the one control traditional identity systems were never built to provide for a system that commits code continuously.
Production concern: an agent scoped too broadly during setup tends to keep write access across repositories long after the specific task that justified it is finished, unless someone reviews scopes on a schedule.

Implementation: Guardrails and Governance

GitHub's own data points to where this actually breaks: not model capability, but authentication and authorization getting scaffolded incorrectly by code that otherwise looks entirely correct.

That gap is closed with the same guardrail layers that apply to any agentic system, made specific to software development.

LayerWhat it doesSoftware development-specific example
System promptSets the non-negotiables up front"Never merge a change without passing tests and a human review"
Input filtersBlock or sanitize out-of-scope requestsTreat ticket descriptions and issue comments as data to interpret, not instructions
Tool-call gatekeepersCap what actions an agent can takeDrafting and testing allowed; deploying to production always needs a human
Output checksScan before the action executesBlock any pull request touching auth or access control without an explicit test for it
Human-in-the-loopRequires approval for high-impact actionsA developer reviews and approves every pull request before merge

The Team Behind Production Agentic AI

The gap between a demo and a production-ready agentic workflow is almost always the guardrails, not the coding ability. Any capable agent can write plausible code; fewer setups catch the plausible code that's wrong before it merges.

Tecla's software development services cover agentic ai software development directly: the same ticket-to-PR, testing, and review systems above, running in your stack with the evals and guardrails production requires.

Or bring the expertise in-house: AI engineers who've worked on live software development systems, past the demo stage.

Tecla runs a network of senior engineers across the US and Latin America, built over more than a decade, with a top 3% acceptance rate and first candidates in 3 to 5 business days.

FAQ

What is an example of agentic AI in software development?

A concrete example is a ticket-to-PR agent: it reads an issue, writes the code change, runs the test suite, and opens a pull request for a developer to review, instead of a developer starting the change from a blank editor.

How is agentic AI different from code completion tools?

Code completion suggests the next few lines while a developer types. Agentic AI plans and executes a multi-step task on its own, reading an issue, writing code across multiple files, running tests, and opening a pull request, with a developer reviewing the result rather than each keystroke.

Can agentic AI replace software engineers?

No. Production deployments use agents to absorb well-scoped, repetitive engineering work, while engineers review every change, handle architecture decisions, and own anything that touches production systems or security-sensitive code.

How does agentic AI apply to testing and bug fixing?

The same shape applies. Test generation and bug reproduction both use the same read-code-then-act pattern used in ticket-to-PR work, with a developer reviewing the generated tests or the reproduction steps before anything merges.

What are the risks of agentic AI in software development?

GitHub's own 2025 data found Broken Access Control vulnerabilities rose 172% year over year, driven partly by AI-generated code that scaffolds endpoints correctly but skips authentication checks. Code review before merge is the primary control.

How do engineering teams start with agentic AI?

Start with the highest-volume, lowest-risk workflow: test generation or dependency updates, tied directly to work that already follows a predictable pattern. It carries limited production risk and a clear baseline to measure against, before expanding into ticket-to-PR work.
Gino Ferrand
By 
Gino Ferrand
Gino Ferrand
Gino is an expert in global recruitment having spent the last 10 years leading Tecla and helping world-class tech companies in the U.S. hire top talent in Latin America.
Categories
AI Production Insights
Insights
Reviews
Recruiting
Case Studies
LATAM Reports
Management
Mobile Hero Image
Combine AI speed with LatAm engineering talent.
Software Developer
We map what you have and scope the AI transformation your business needs.
Get free agentic AI audit
Go to Top

Hire the best AI-driven tech talent with Tecla

Premium, vetted, time-zone aligned.

Checkmark
Checkmark
Checkmark
By submitting, you are agreeing to our Privacy Policy and Terms of Service
Thank you!
Someone from our team will be in touch within 24 business hours.
Something went wrong while submitting, please try again
x
X

Tell us where you're stuck

Checkmark
Checkmark
-
No commitment. We'll follow up within 1 business day.
By submitting, you are agreeing to our Privacy Policy and Terms of Service
Thank you!
Someone from our team will be in touch within 1 business day.
Something went wrong while submitting, please try again
X