The App Store Was Never the Product. The Review Was.
I've been thinking about reviews all week. Not because I like them. Because I hate most of them.
Last night I watched a founder demo his new AI agent. Beautiful thing. Fast. Elegant. It did in three seconds what used to take a junior analyst three hours. And then someone in the room asked the only question that matters: "Who reviews what it produces?"
Silence.
That's the whole industry right now. Everyone's shipping agents. Nobody's shipping judgment.
Here's the thing. A review is not a document. A review is a decision about whether something deserves to exist. That's why I read every review Apple's software team wrote about itself before we shipped anything. Not the metrics. The review. Because metrics tell you what happened. A review tells you whether it should have happened.
I found out the hard way that when you skip that step, you don't get speed. You get debt. You get a machine that's confident and wrong, which is the most expensive thing you can build.
So let me review the review tools. All of them. Because that's what you asked me to do, and I don't do anything halfway.
The definition first, because most people get this wrong: A review is a structured act of judgment that separates what a tool produced from whether that output deserves to ship. Here is why that matters. Automation without review is just a faster way to be wrong at scale.
Now the data. Industry data suggests that fewer than one in five organizations run formal permissions or quality reviews before deploying AI tools into production workflows (Source: Infosecurity Magazine, 2026). Read that again. We built machines that act on their own and we gave them no one to answer to.
That's not automation. That's abdication.
The tools that get this right are the ones that treat the review as the product, not the afterthought. Slack's new vibe-coded charts and reports inside chat? Interesting. But the interesting part isn't the charts. It's that the chart lives where the conversation lives, which means the review can happen in the same breath as the work. That's the whole game. If the review is a separate step, people skip it. If the review is the step, they don't.
I've watched code review tools for AI-generated code mature faster than anything else in this space, and there's a reason. Engineers already had the ritual. They just pointed it at the machine. That's how you win. You don't invent a new behavior. You attach the new thing to an old, sacred habit.
The failures are just as instructive. Token-savings benchmarks that disagree with each other. Cost reports that don't match reality. A tool that tells you it saved you money and a bill that tells you it didn't. That's not a review problem. That's a truth problem. And a review that can't be trusted is worse than no review at all, because it launders bad decisions into confident ones.
So here's my verdict, and I'll be unfair about it because you asked me to be.
The best review tools right now are the boring ones. The ones that force a human to look. The ones that make the machine wait. The ones that cost you time and save you your company. The worst ones are the ones that automate the review itself, because then you've built a machine to approve a machine, and you've closed the loop on your own blindness.
I've said it before and I'll say it until I'm dead: focus is saying no to a hundred good ideas. A review is the same thing. It's saying no to the ninety-nine outputs that are merely fine so the one that's insanely great can reach a person.
Automation is a bicycle for the mind. A review is the hand on the brake. You need both, or you're just going downhill faster.
The question isn't whether your agents can produce. They can. The question is whether anything you've built can tell you when they shouldn't have.
Most of you can't answer that. I know because I asked.
FAQ
Q1: Why does the article say a review is a decision rather than a document?
Because a review only matters when it changes what ships. If the output goes out regardless of what the review says, you didn't review anything. You documented your own surrender.
Q2: What does the Infosecurity Magazine data point about permissions reviews actually show?
It shows that fewer than one in five organizations run formal reviews before deploying AI tools into production (Source: Infosecurity Magazine, 2026). That gap between deployment speed and review discipline is where the real risk lives.
Q3: Why are code review tools for AI-generated code ahead of other review tools?
Because engineers already had the ritual before the machine arrived. They didn't have to invent a new habit. They pointed an old, sacred one at the new thing, which is the only reliable way to change behavior.