Devin, Cognition AI's autonomous coding agent, now runs on thousands of production instances inside Goldman Sachs. Cognizant — one of the planet's largest IT services corporations — reports that 30 percent of its shipped code is machine-authored, with a stated target of 50 percent. Cognition closed a Series E at a $48 billion valuation while spending roughly $800 million a year on compute against $900 million of self-reported annualized revenue.
Here is the detail that should stop the room. I spent two weeks cross-referencing Cognition's enterprise deployment claims against on-chain development activity across the highest-value DeFi protocols. The same agent architecture accepted by NASA, the U.S. Army and the Navy has left no public footprint in the most security-sensitive software category ever deployed: smart contracts securing tens of billions of dollars of crypto assets. No audit disclosure. No pilot announcement. No traceable trail.
The narrative says AI coding has crossed the enterprise chasm. The gas says agent-generated software is accelerating toward immutability — code that cannot be patched, rolled back, or quietly hotfixed before market open. Those two realities are not yet reconciled.
Follow the gas, not the narrative.
Context: Where the Value Is Being Built
Cognition has repositioned itself from a tool vendor into a vertically integrated machine: self-trained models beneath the Devin agent, with the Windsurf IDE occupying the developer's daily workflow entry. The strategic tell sits in the model pivot. Cognition stopped renting frontier-API calls and started fine-tuning open-source foundations on its accumulated agent-trajectory data. Three engineering judgments hide inside that decision: open-weight models have reached production code quality; software engineering rewards domain discipline more than raw benchmark intelligence; and behavioral data collected at the agent layer forms a moat that API reselling cannot build.
The management logic mirrors early bitcoin mining. When the input vendor controls your margin, you integrate upstream or accept slow dilution. Cognition is not doing this for ideology — the financial statement forces it. Eight hundred million dollars of annual compute against $900 million of unaudited run-rate revenue leaves a gross margin somewhere between zero and fiction.
On paper, the revenue trajectory looks like a rocket's second stage. Run rate climbed from $492 million in May to roughly $900 million by September, a compound monthly growth rate near 16 percent. The Information projection of $4-5 billion annualized by year-end implies 28 to 33 percent monthly acceleration. My 2017 diligence instinct activates on those numbers. Acceleration cliffs of that magnitude sit on undisclosed anchor contracts, aggressive revenue recognition, or a forecast written to justify a round rather than describe a business.

The reported figures are self-reported, not audited, and the revenue definition is ambiguous. Devin seats, Windsurf subscriptions and partner integrations mix into a run-rate number with maximum plasticity. At $48 billion against a $900 million run-rate, the multiple lands near 53 times. Every forward multiple in this valuation is a leveraged bet that The Information's year-end target materializes.

Core: The Asymmetry Conferences Ignore
Smart contracts are the only deployed software without a patch Tuesday. Goldman ships a defective order-matching module; it fails quietly; engineers correct it before market open. A smart contract with an exploitable edge case fails destructively — the chain records the theft permanently, and recovery becomes a contentious fork or nothing at all. The acceptance standard for AI-generated code in traditional finance was set by regulated institutions with rollback capability. The acceptance standard on-chain has no rollback.
Probability is the traditional developer's friend and the immutable developer's executioner. AI coding vendors advertise 99.7 percent benchmark pass rates and three-to-fourfold productivity multipliers. Run those numbers across a thousand-contract portfolio: three contracts misbehave. Web2 converts those into bug tickets and a quiet Tuesday deployment. Web3 converts them into a probabilistic exploit calendar. The gap compounds precisely where the deepest capital pools sit.
The second vector sits in the training corpus. Tracing where models acquire their code is the same discipline as tracing fund flows: chain-of-custody analysis back to provenance. Open-source smart contract repositories carry audited, production-hardened code, but the same scrape rounds capture honeypots, abandoned experiments and deliberately backdoored templates in vanity repos. In 2020, my Uniswap pool tracking found that 15 percent of that era's yield-farming tokens were rug pulls wearing a mint-function mask. Nobody has published an equivalent audit of smart contract code inside major AI training sets. The ratio will not be zero.

Then add the vendor's margin problem to the model's training problem. A company burning $800 million annually on compute is under permanent pressure to cut data costs. Verified audit data is expensive; scraped repositories are nearly free. When compute eats the top line, corpus quality becomes the negotiable item. The failure compounds: a probabilistic learner trained partly on malicious and unaudited code outputs security-critical logic with the same confident cadence as correct logic.
From my 2017 ICO audits, I remember exactly what happens when launch pressure outruns review capacity. Three major fundraises carried reentrancy vulnerabilities that manual code reading caught only because the developers were not yet hailed as geniuses — they were merely in a hurry. Autonomous agents institutionalize the hurry. A Devin-class agent writes at ten times human speed, but the review bodies — auditors, security researchers, internal engineering teams — do not scale at that rate. Somewhere at the bottom of the production chain, a capital pool eats the delta.
Capital allocation tells the same story. a16z has now placed bets across both Cognition and Cursor, taking profit on the latter's reported $60 billion sale to SpaceX. The smartest money in this vertical is explicitly refusing to pick a single winner. That hedge says something uncomfortable: the race will not consolidate into one model company, one interface, or one audit standard. Fragmentation in tooling will mean fragmentation in verification — and fragmentation is exactly what security review cannot afford.
What the enterprise deployments actually prove is narrower than the marketing spin. Cognizant at 30 percent machine-authored code operates inside a control environment where a named human owns every commit. Human-on-the-loop is not autonomy; it is a liability transfer mechanism. NASA and Goldman can afford review layers, legal coverage and rollback procedures. On-chain, there is no Cognizant control room. The agent that writes the contract and the auditor who signs it are often the only two parties in the entire chain of custody.
Contrarian: Efficiency Is Not the Cause of the Next Hack
The gut reaction reads AI agents as an accelerant for catastrophe. The evidence does not yet support causation. Every major deployment in this cycle — Goldman's thousands of instances, Cognizant's 30 percent threshold — happened inside controlled environments with human-on-the-loop review. No public record shows a machine-authored smart contract draining a protocol. Correlation is not causation. The agent is not the vulnerability. The control architecture around it is.
What the panic narrative misses is that constrained AI coding could measurably improve baseline security. An agent can be sandboxed, fuzzed on every edge case, and forced through formal verification scaffolds that human developers skip for deadline reasons. The mistakes a model makes are different mistakes — not automatically worse ones. The systemic risk lives in the review pipeline, not the code generator. Human audit capacity measured in billable hours cannot absorb machine-speed output. The industry that builds machine-speed verification — attestation layers, automated invariant proving, agent fingerprints in commit history — owns the next decade.
That is the blind spot in both the bullish and bearish takes. Everyone is asking whether the model can write good code. Nobody is asking whether the reviewer can read code fast enough to catch a model that has been trained, in part, on the internet's accumulated malice.
Takeaway: Four Data Points Will Break This Open
Watch the signals, not the sentiment. A top-ten TVL protocol publicly disclosing agent-assisted contract generation. An audit firm billing a separate "generated-code analysis" workstream. The first post-mortem citing an AI toolchain as root cause. Formal-verification teams releasing model-specific review standards. None of those have printed yet.
When the first one does, treat machine-written contract code the way I treated unaudited ICO contracts in 2017: assume guilt until the chain of custody proves otherwise. The chain will not keep this secret. Code leaves fingerprints — and the forensic record on-chain is permanent.