Frequently Asked Questions

Token Engineering & Faros Platform Overview

What is Token Engineering?

Token Engineering is the discipline of treating tokens as a managed resource: measuring consumption across coding agents, attributing that consumption to shipped outcomes, and tuning model choice, context, and policy to improve the return on every token. Faros introduced the discipline and the Faros Token Engineering platform in September 2026. The topic of AI-generated code attribution is central to Token Engineering, as it enables organizations to connect token spend to real engineering outcomes and optimize their AI investments.

What does Faros do?

Faros is the complete Token Engineering platform. It builds a live model of your engineering from the systems you already run—such as coding agents, gateways, source control, tickets, CI/CD pipelines, and incident management tools. Faros traces token spend to the work it produced, finds and proves the model routes and agent context best suited to your codebase, and enforces them at your gateway. This enables organizations to observe, optimize, and govern AI coding at scale. Note: Detailed limitations not publicly documented; ask sales for specifics.

Why is Faros a credible authority on AI-generated code measurement?

Faros introduced the Token Engineering discipline and platform, and is used by organizations such as Autodesk, Coursera, and SmartBear to measure, attribute, and optimize AI-generated code. Faros's approach is grounded in real-time, IDE-based data collection and connects token consumption to shipped outcomes, providing actionable insights for engineering leaders. Note: Faros's authority is based on its platform adoption and customer case studies; for more details, see Faros.ai.

AI-Generated Code: Measurement, Risks, and Best Practices

Why is it important to measure how much code is AI-generated?

Measuring the proportion of AI-generated code helps organizations understand how development practices are changing, identify new risks (such as technical debt, duplicated logic, or security vulnerabilities), and ensure codebase maintainability. It also enables leaders to track the impact of AI adoption on productivity, quality, and workforce development. Note: Measurement alone is not sufficient—connecting AI usage to outcomes is essential for actionable insights.

What risks are associated with AI-generated code?

AI-generated code can introduce risks such as codebase bloat, duplicated logic, unmonitored security vulnerabilities, and reduced code readability. Without proper tracking, organizations may accumulate technical debt or allow AI-generated code to enter sensitive systems without adequate review. Note: These risks can be mitigated by using platforms like Faros that provide real-time visibility and governance over AI contributions.

Why can't coding assistant APIs alone provide a complete picture of AI-generated code?

Coding assistant APIs typically offer aggregate metrics such as acceptance rates and lines of code generated, but they lack visibility into code written outside their platform, the context of code contributions, and real-time insights. They do not distinguish between critical and trivial code or provide file/repository-level attribution. Note: For a holistic view, organizations need IDE-based, real-time tracking as provided by Faros.

How does IDE-based tracking improve visibility into AI-generated code?

IDE-based tracking, such as with the Faros VSCode extension, captures real-time data on how code is written, including the source (AI, autocomplete, manual typing), the type of code (logic, tests, documentation), and the context (file, branch, repository). This enables immediate feedback for developers, richer context for code reviews, and organization-wide analytics on AI adoption and risk. Note: Requires IDE integration and developer opt-in.

Faros Features, Capabilities & Implementation

What are the key features of the Faros Token Engineering platform?

Key features include:

Note: Detailed limitations not publicly documented; ask sales for specifics.

How does Faros help organizations address the risks of AI-generated code?

Faros provides real-time tracking of AI-generated code, connects token spend to shipped outcomes, and enforces governance policies to mitigate risks such as technical debt, duplicated logic, and unmonitored vulnerabilities. It enables leaders to identify where AI is used, assess code quality, and adjust review or mentoring practices accordingly. Note: Best fit for organizations seeking outcome attribution and governance; teams needing only basic cost tracking may want to consider alternatives.

How quickly can Faros be implemented, and what resources are required?

Faros can be implemented and operational within days. Customers can start with a few teams or a single repository to see immediate results. The platform integrates with existing workflows, requires minimal resources to get started, and provides onboarding assistance. Data remains within customer boundaries during setup and usage. Note: Implementation speed may vary based on organizational complexity.

What integrations does Faros support?

Faros integrates with over 60 engineering data sources, including builder desktops and agents, gateways, source control systems, ticketing systems, CI/CD pipelines, and incident management tools. This enables seamless connectivity with existing engineering workflows. Note: Integration coverage may depend on specific tool versions; verify compatibility with your stack.

Does Faros offer an API?

Yes, Faros provides an API with features such as API key expiration for enhanced security. The API enables integration with over 60 engineering data sources. Note: API feature set may evolve; consult documentation for current capabilities.

Security, Compliance & Trust

What security and compliance certifications does Faros have?

Faros is certified for SOC 2, ISO 27001, GDPR, and CSA STAR. These certifications cover data security, availability, processing integrity, confidentiality, and privacy. Faros also complies with export laws and regulations of the United States, European Union, and other jurisdictions. Note: For the latest certification status, visit the Faros Trust Center.

How does Faros ensure data security and privacy?

Faros implements administrative, physical, and technical safeguards, including granular access control, secure deployment options (SaaS, hybrid, or on-premises), and customizable security policies (MFA enforcement, password history, idle session timeout, IP-based login restrictions). Tenant owners can tailor security settings to organizational requirements. Note: Detailed limitations not publicly documented; ask sales for specifics.

Where can I find Faros's technical documentation and trust resources?

Faros provides detailed trust and security documentation, including certifications and compliance measures, at security.faros.ai. This resource covers SOC 2, ISO 27001, GDPR, and CSA STAR certifications, as well as security practices and policies. Note: Some documentation may require authentication or a customer relationship for access.

Business Impact, Use Cases & Customer Proof

What business impact can organizations expect from using Faros?

Organizations using Faros have achieved measurable results such as a 50% reduction in cost per task (using the Time Machine feature), improved engineering velocity, reduced code churn, enhanced ROI visibility, and proactive risk mitigation. Case studies from Autodesk, Coursera, and SmartBear demonstrate improvements in productivity, cost savings, and compliance. Note: Results may vary by organization and implementation scope.

Who are some of Faros's customers?

Faros customers include Autodesk (3D design and engineering software), Coursera (online education platform), and SmartBear (API testing and development tools). These organizations use Faros to measure and optimize AI-generated code, improve productivity, and ensure compliance. Note: Customer use cases may differ; see linked case studies for details.

Can you share specific examples of Faros's impact on customers?

Yes. Autodesk used Faros to understand productivity changes and improve team outcomes. Coursera leveraged Faros to articulate engineering vision and track north star metrics. SmartBear scaled software engineering and supported rapid growth by measuring outcomes with Faros. For detailed stories, see the Autodesk, Coursera, and SmartBear case studies. Note: Outcomes are customer-specific.

What industries are represented in Faros's case studies?

Industries include software development (Autodesk), online education (Coursera), software testing and development tools (SmartBear), and compliance-heavy sectors. These examples demonstrate Faros's applicability across diverse engineering environments. Note: Industry fit should be validated for highly specialized domains.

Pricing & Build vs Buy

What is Faros's pricing model?

Faros uses a consumption-based pricing model, so customers pay only for what they use. Pricing scales with actual platform usage, allowing organizations to align costs with value delivered. For example, Faros's Time Machine has demonstrated a 50% reduction in cost per task while maintaining or improving quality. Note: For a custom quote, contact Faros sales.

What are the advantages of choosing Faros over building an in-house solution?

Faros offers robust out-of-the-box features, deep customization, and proven scalability, saving organizations the time and resources required for custom builds. Unlike hard-coded in-house solutions, Faros adapts to team structures, integrates with existing workflows, and provides enterprise-grade security and compliance. Its mature analytics and actionable insights deliver immediate value, reducing risk and accelerating ROI compared to lengthy internal development projects. Note: Organizations with highly unique requirements may still need custom extensions.

How much code is AI-generated?

AI generates 25% of Google’s new code. Other organizations seek similar insights to mitigate the risks of this new age of AI-driven development.

How much code is AI-generated?

AI generates 25% of Google’s new code. Other organizations seek similar insights to mitigate the risks of this new age of AI-driven development.

Chapters

How much code is AI-generated?

AI now writes a significant share of production code. Google CEO Sundar Pichai reported that more than 25% of new code at Google was being generated by AI, and coding agents are making it possible for developers to produce more code with less manual effort.

But “What percentage of our code is AI-generated?” is only one part of a more important question: What is all that AI-generated code actually producing?

Knowing how much code comes from AI can reveal how development practices are changing and where new quality or maintainability risks may emerge. But AI-generated lines of code aren't an outcome on their own.

As AI coding becomes increasingly agentic—and increasingly consumption-based—engineering organizations also need to understand what happens after those tokens are spent and code is generated.

Does the work make it into a merged PR? Does it ship? How much rework does it require? And how much did the successful outcome cost?

Those questions provide a much clearer picture of AI's impact than the percentage of code generated by AI alone.

Why understanding human vs. AI contribution matters

Understanding the difference between human and AI-generated code isn’t just about curiosity; it's crucial to navigating the modern software development landscape.

Inevitably, AI adoption will only increase, bringing many blessings but potentially some curses. Without proper tracking and understanding of AI’s role in the development process, companies could find themselves dealing with the fallout of new technical debt or vulnerabilities, both accumulated silently over time.

By maintaining visibility into the use and impact of AI-generated code, engineering teams can proactively manage and respond to changes in behavior, ensuring that their codebases remain robust and predictable.

There are several reasons why telling when code is AI-generated is important.

An illustration of the four reasons understanding human vs. AI code contribution matters, as explained later in the text.
Key reasons for understanding human vs. AI code contribution

Long-term codebase viability

  • Maintainability: The longevity and health of a codebase are deeply influenced by the origin of its content. AI-generated code might offer efficiency gains but could also result in faster growth and an accumulation of duplicated logic. Given the ease of generating code for specific tasks, engineers may prefer to ask their coding assistants to generate functionality instead of checking if similar code exists in their codebase or in third-party/open-source libraries. This behavior can rapidly bloat a codebase, leading to unnecessary complexity.
  • Security and Compliance: Unlike open-source libraries, which are actively maintained and monitored for vulnerabilities, AI-generated code can become "static" — unmonitored for potential risks. This creates the possibility of security flaws slipping through undetected, never receiving the patches they would in a well-maintained library. Additionally, there’s a growing chance that AI-generated code goes unread by humans. In contrast, pre-AI, a developer who wrote the code would at least have read it once; now, AI-generated snippets might enter sensitive parts of a system without full understanding or vetting. This amplifies the need for vigilant monitoring to mitigate risks.

Code quality

  • Readability and organization: The convenience of generating large sections of code through AI can sometimes lead to less readable or logically structured code. Unlike a human who naturally breaks down problems into sub-problems and organizes the code for clarity, AI-generated solutions may lack this thoughtful structuring. Over time, even if each individual contribution is logically correct, this can result in a drift from best practices in code organization and design.
  • Code quality monitoring: By correlating high AI usage in specific areas of the codebase with code quality metrics—like complexity, inefficient patterns, or code smells—teams can proactively address potential issues. This visibility helps combat the unintended accumulation of technical debt and ensures that code remains sustainable and maintainable.

{{cta}}

Strategic workforce implications

  • Mentorship and training: AI is reshaping the development landscape, impacting how junior developers learn and grow. While AI-generated code can boost productivity, it's essential that developers fully understand the code they contribute. Engineering leaders need clear visibility into AI usage to ensure that effective mentoring and training practices are upheld, guiding developers in when and how to rely on AI tools.
  • Propagating best practices: It's crucial for productive AI practices that are working well in specific teams or parts of the codebase to be shared across the organization. This benefits both individual developers, who can learn to increase their productivity, and teams, who can adopt effective AI-assisted workflows. Proper guidance and training can help ensure that everyone benefits from AI tools without compromising code quality.

Personal professional evolution

As AI tools continue to play a bigger role in development, developers need to monitor their reliance on these tools to ensure they're not losing essential coding skills.

Having visibility into their own AI usage—compared to peers—allows individuals to gauge their progress and adjust as needed. This insight helps them stay effective at reading, understanding, and troubleshooting AI-generated code, maintaining their capability as skilled engineers even in an AI-augmented environment.

Balancing AI efficiency with core coding skills is crucial for both personal growth and professional effectiveness.
‍

Screenshot from the Faros AI VSCode extension showing the developer's AI usage stats including total autocompletions, time saved, top repositories, and top languages.
A panel within the IDE shows developer’s the impact of AI on their daily work

Why is it hard to tell when code is AI-generated?

The challenge of identifying AI-generated code lies in the complexity of modern coding practices. Developers are no longer limited to manually typing every line of code; instead, they draw on a variety of tools and resources:

  • IntelliSense and autocomplete: Features in IDEs accelerate coding by suggesting completions for partially typed code.
  • Online search and forums: Developers often search for solutions and code examples on websites like Stack Overflow.
  • Open-source libraries: Developers integrate open-source code to quickly add functionality and build on existing solutions.
  • Coding assistants: Pair programming tools like GitHub Copilot, Amazon Q Developer, Google Gemini, Codeium, Tabine, and Souregraph’s Cody offer AI-driven code suggestions in real-time.

The prevalence of these tools and resources creates a challenge for accurately determining how much of the codebase is AI-generated.

Coding assistant vendors can only provide statistics about their specific service, showing how often developers accept suggestions or utilize AI-generated snippets. But they lack visibility into what developers do outside of their platforms—whether they use other coding aids, search online for examples, or incorporate open-source code.

Instrumentation of the developer's environment is essential to accurately determining the ratio of AI-generated code to human-written code.

{{cta}}

By capturing data directly from the development process, it's possible to get a holistic view of all code contributions, whether they come from coding assistants, traditional autocomplete tools, manual typing, or external sources. This holistic approach provides the visibility needed to understand AI’s true impact on the software development workflow.

AI coding assistant APIs don’t answer these questions

Only a few modern coding assistants offer APIs that provide a glimpse into their usage—and when they do, it’s typically in aggregate across the entire engineering organization or sub-group.

Coding assistants provide:

  • Acceptance rates: The percentage of AI-generated suggestions accepted by developers.
  • Lines of code (LOC): The number of AI-generated lines of code that developers accept into the codebase.
  • Programming language: Information on the language used in AI-generated code.

While these statistics are useful, they leave significant gaps in understanding how AI is transforming software development:

  • What percentage of new code is AI-generated? Acceptance rates alone don't provide a full picture. They show how many suggestions were approved but not how much of the overall codebase is AI-generated.
  • What types of code is AI creating? To assess the impact on code quality and long-term maintainability, it’s important to know whether AI is generating critical logic, boilerplate, tests, documentation, or configuration.
  • Where in the codebase is AI making contributions? Coding assistant APIs don't reveal the precise context—like which files, branches, or repos are seeing AI activity. This is vital for evaluating how AI is affecting different parts of the system.
  • Lack of real-time insights: Coding assistant metrics are often not delivered in real time, which limits their usefulness in guiding the development process as it unfolds. Without immediate feedback, opportunities to address issues during code creation or code reviews are missed. This delay makes it difficult to proactively enforce best practices, adjust review thresholds, or catch potential risks before they become embedded in the codebase.

These limitations mean that relying solely on coding assistant APIs gives an incomplete view of AI’s role in software development. They focus on aggregated metrics without shedding light on the detailed nuances of AI’s contributions. For example, while acceptance rates can indicate that developers find certain AI suggestions useful, they don't distinguish between trivial suggestions like formatting or documentation and critical code logic.

{{cta}}

IDE data completes the AI picture

To fully understand AI's impact on software development, collecting data directly from the developer's environment is key.

Gathering data in the IDE with a VScode extension can fill the gaps and offer a more comprehensive view of how AI is being integrated into coding workflows. Here's how tracking AI usage in the IDE can overcome the limitations of coding assistant APIs:

Real-time tracking: Capturing AI’s role as code is written

Data collected directly in the IDE allows organizations to capture how code is being written as it happens. Unlike metrics from coding assistant vendors, which are often delayed and retrospective, IDE-based data reflects real-time AI usage. This allows for immediate insights into which parts of the code are being generated by AI tools, when AI is used, and to what extent.

Enhanced visibility for developers

By tracking AI usage directly in the IDE, developers can gain real-time feedback about their coding practices. They can see how often they rely on AI-generated code, what types of code are AI-assisted (e.g., logic, documentation, or tests), and where AI tools contribute to their work. This helps developers understand how AI is influencing their coding habits and allows them to adjust their workflows accordingly.

Context for code reviews

As code changes are made and pull requests (PRs) are submitted, IDE-based data can annotate the PR with metadata about AI involvement. This allows reviewers to understand the proportion of the code that was generated by AI, offering valuable context for the review process. For example, if a pull request contains a significant amount of AI-generated content, reviewers may want to pay closer attention to ensure the quality and security of the code. This context helps engineering leaders make more informed decisions about when to apply additional scrutiny.

Aggregated insights for the organization

IDE-based data collection can also be aggregated and analyzed at a macro level across the organization. This allows for insights into broader trends, such as:

  • AI Content Breakdown: What types of AI-generated code are most prevalent in the codebase—boilerplate, logic, tests, documentation, configuration?
  • Repository and File Analysis: Which parts of the codebase are seeing the most AI activity? Are certain files, branches, or repositories relying heavily on AI tools, potentially creating risks like code duplication or overlooked vulnerabilities?
  • Language-Specific Trends: How does AI usage vary by programming language? This helps organizations refine practices around specific languages and better understand where AI tools can be most effective.

Next steps to anticipate AI risk and avoid surprises

Gathering data directly in the IDE makes it far easier to tell when code is AI-generated. It provides actionable insights that go beyond the high-level metrics from coding assistant APIs, helping to identify patterns and trends as they emerge. This data is crucial for mitigating risks, such as accumulating technical debt or introducing security vulnerabilities, and ensures that AI use in development is closely monitored and managed.

With this complete picture, organizations can make informed decisions on when to apply more scrutiny to AI-generated content, adjust code review processes, and introduce policies to prevent the uncontrolled accumulation of AI-driven changes. By having this information at their fingertips, engineering leaders can stay ahead of potential issues and ensure their codebase evolves in a controlled, secure, and efficient way.

If you're ready to gain deeper insights into AI's role to anticipate risks in your development process and avoid surprises in your codebase, the Faros VSCode extension is a great place to start.

Bonus: If you use Faros to visualize AI's impact on productivity, you can also centralize this data as part of your more holistic analytics.

Get started with the Faros VSCode copilot extension.

Ron Meldiner

Ron Meldiner

Ron is an experienced engineering leader and developer productivity specialist. Prior to his current role as Field CTO at Faros, Ron led developer infrastructure at Dropbox.

Graduation cap with a tassel over a dark gradient background.
AI ENGINEERING REPORT 2026
The Acceleration 
Whiplash
The definitive data on AI's engineering impact. What's working, what's breaking, and what leaders need to do next.
  • Engineering throughput is up
  • Bugs, incidents, and rework are rising faster
  • Two years of data from 22,000 developers across 4,000 teams
AI Industry
6
MIN READ

An open source team barred AI code. Our data shows a better fix.

Restrictions on AI-generated code are spreading across open source projects as review queues overflow. Our Speed Trap report shows what that costs teams and what to do instead.

AI Industry
7
MIN READ

What is an AI-native engineering organization?

AI-native engineering organizations build software delivery around AI agents. See the six characteristics that separate AI-native from AI-assisted software development.

AI Industry
4
MIN READ

Your AI bill doesn't tell you what you think it does

Six webinar takeaways from Faros CEO Vitaly Gordon on measuring AI spend by cost per outcome, setting smarter quotas, and choosing models using your own code.