Skip to main content

Does Using AI Change How Humans Think and Learn?

What cognitive offloading research reveals about the mental habits we stop practicing when using AI and the new abilities we develop.

By Vodnala Akshith
Published: Oct 01, 2026
9 mins read
👁️ 24 Unique Views
Does Using AI Change How Humans Think and Learn?
The scale of inference: Optimized for multimodal workloads.
Premium Insight

Why It Matters

Generative AI does not make humans less intelligent; it changes how we allocate mental effort. Controlled cognitive studies show that while people stop practicing rote memory recall and initial rough drafting, higher-level skills like problem framing, critical editing, and cross-domain synthesis improve.

Does Using AI Change How Humans Think?

Generative AI coding tools like GitHub Copilot, ChatGPT, and Claude have fundamentally transformed modern software engineering. Millions of developers rely on them daily to generate functions, write boilerplate code, and resolve complex syntax errors in seconds. On the surface, the productivity boost feels undeniable: developers build working prototypes faster than ever before. However, empirical cybersecurity research reveals a dangerous reality: code that runs or compiles is not necessarily code that is secure, maintainable, or safe to deploy in enterprise production systems.

The Dangerous Illusion of Compiling Code

In professional software engineering, there is a crucial distinction between code that executes without errors and code that is architecturally secure. A function can execute perfectly during a local test run while simultaneously exposing a critical memory vulnerability, a SQL injection vector, or an unencrypted data stream. When developers evaluate code primarily by whether it compiles without syntax errors, they fall into a dangerous trap—treating functional execution as proof of security.

Inside the NYU Tandon Benchmark: 40.5% Insecure Code

To measure the security risks of automated coding assistants, researchers at NYU Tandon School of Engineering conducted a comprehensive empirical benchmark led by Dr. Hammond Pearce. The researchers designed 1,689 code generation scenarios across 89 high-risk Common Weakness Enumeration (CWE) categories, evaluating GitHub Copilot across C, Python, and Verilog tasks.

The study was published in IEEE Transactions on Software Engineering (Pearce et al., 2022, DOI: 10.1109/TSE.2022.3176881):

  • Overall Vulnerability Rate: 40.48% of all AI-generated code snippets contained security vulnerabilities capable of compromising an application.

  • Severe Flaws Identified: The model regularly introduced critical security weaknesses, including CWE-79 (Cross-Site Scripting), CWE-89 (SQL Injection), CWE-119 (Improper Restriction of Operations within Bounds), and CWE-787 (Out-of-Bounds Write).

  • Context Sensitivity: The rate of insecure code rose significantly when prompts reflected legacy coding patterns or lacked explicit security constraints.

The Stanford Experiment: False Developer Confidence

A human-subjects study conducted at Stanford University by Neil Perry, Megha Srivastava, Deepak Kumar, and Professor Dan Boneh examined how developers interact with AI coding assistants during security-critical tasks. The study was presented at the 2023 IEEE Symposium on Security and Privacy (S&P) (Perry et al., 2023, DOI: 10.1109/SP46215.2023.10179339).

The Stanford team recruited 47 software developers ranging from computer science students to experienced professional engineers to solve security-sensitive programming problems.

The experiment yielded two critical discoveries:

  1. Lower Security Output: Developers who had access to AI coding assistants produced code that was significantly less secure than developers writing code manually without AI support. AI-assisted programmers frequently selected weak encryption algorithms (such as DES or ECB cipher modes) and trusted unvalidated user inputs.

  2. Elevated False Confidence: Developers who used AI assistants were statistically far more confident that their code was secure compared to the unassisted control group. Because the AI generated syntactically clean code instantly, developers lowered their critical scrutiny and assumed the AI's suggestions were safe.

Strategic Insight: The Security-Velocity Trade-Off in Modern Software Architecture

The empirical finding that 40.48% of AI-generated code snippets contain vulnerabilities highlights a structural friction point for engineering leadership. While generative tools decrease line-writing latency, they introduce systemic risks by bypassing human architectural intuition.

As software infrastructure becomes increasingly automated, organizations must recognize that speed of code generation is a deceptive metric if it inflates downstream vulnerability patching costs. Modern DevSecOps teams must evolve beyond passive code completion, implementing automated security policy gates and mandatory adversarial peer reviews before any AI-generated code enters production deployment.

Purdue University and GitClear: Bugs, Churn, and Technical Debt

The accuracy and quality gap extends beyond individual security bugs to enterprise-scale codebase health:

  • Purdue University Study (52% Bug Rate): Researchers led by Samia Kabir analyzed 517 programming questions answered by ChatGPT compared to human experts on Stack Overflow (published at ACM FSE). They discovered that 52% of ChatGPT's software answers contained incorrect or buggy code. However, because ChatGPT's responses were written in an articulate tone, human evaluators overlooked logical errors 39% of the time.

  • GitClear Longitudinal Study (153 Million Lines): Analytics firm GitClear analyzed over 153 million changed lines of code across 21,102 repositories between 2020 and 2024. The data showed a doubling of code churn (code modified or deleted within two weeks) to 7.1%, an 11% surge in copy-pasted code blocks, and a 17% drop in structural refactoring—accelerating technical debt accumulation.

Architectural Trade-Offs and Long-Term Engineering Costs

Relying heavily on AI generation introduces subtle architectural liabilities that compound over time:

  • Micro-Architecture Fragmentation: AI models process prompt contexts locally rather than holistically comprehending an entire application ecosystem. This leads to disjointed architectural patterns, duplicate utility classes, and fragmented state management across large systems.

  • Hidden Production Costs: While AI speeds up initial line-writing velocity, it inflates long-term operational expenditures. Organizations spend significantly more engineering hours on code review, debugging obscure race conditions, and remediating post-deployment vulnerabilities than they saved during initial drafting.

  • Loss of System Mental Models: When developers delegate structural design to automated models, they fail to build complete mental maps of their software systems, drastically reducing their ability to troubleshoot critical production outages under pressure.

How Engineering Teams Must Adapt

As software powers financial networks, healthcare hardware, automotive control units, and critical infrastructure, shipping unverified AI-generated code introduces severe cyber vulnerabilities. Software engineering teams must establish strict organizational protocols:

  • Zero-Trust Code Policies: Treat all AI-generated code as untrusted third-party draft code requiring mandatory human peer review.

  • Automated Security Pipelines: Integrate static application security testing (SAST) and dynamic analysis directly into continuous integration pipelines.

  • Explicit Security Prompting: Train developers to supply detailed security parameters and boundary conditions in prompts rather than relying on default AI code completions.

References & Academic Citations

  1. NYU Tandon Study: Pearce, H., Ahmad, B., Tan, B., Dolan-Gavitt, B., & Karri, R. (2022). Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code Contributions. IEEE Transactions on Software Engineering, 48(11), 4583–4598. DOI: 10.1109/TSE.2022.3176881

  2. Stanford Study: Perry, N., Srivastava, M., Kumar, D., & Boneh, D. (2023). Do Users Write More Insecure Code When Using AI Assistants? 2023 IEEE Symposium on Security and Privacy (S&P), 2772–2789. DOI: 10.1109/SP46215.2023.10179339

  3. Purdue Study: Kabir, S., Udo-Imeh, D. N., Kou, B., & Zhang, L. (2023). Who Answers It Better? An In-Depth Analysis of ChatGPT and Stack Overflow Answers to Software Engineering Questions. ACM International Conference on the Foundations of Software Engineering (FSE).

Found this analysis insightful?

Share with colleagues, engineers, and your network.

Tags & Topics

Discussion

Leave a Comment

No comments yet. Be the first to start the conversation!

Link copied to clipboard!