Did your developers already sell your codebase?

Picture this, you are a small to medium-sized company, having a small to medium-sized team and working on small to medium-sized or maybe even large projects.

You are developing projects for a number of clients, everyhing is awesome, and everybody is happy.

You would think that everything is going fine, but it's 2026 and most developers took the AI crazy pills and now they are letting AI agents loose on their computers, giving access to your clients' projects. You don't really have any strategy in place for AI use yet or maybe you do and have token limits, because AI compute is expensive nowadays...

... and you start to wonder, how is the team using AI exactly, on a day-to-day basis?

You wonder

So you ask this question in the team chat, and the replies start pouring in.

- John: Yes, I use agents unattended because I want to code faster.

- Jake: I do too, I added access to the Github repo so the AI can pull and push code automatically. It's amazing. 🤓

- Mary: I "borrowed" 😉😉 some more tokens from the interns to put it to good use, my agent is fixing a bug for 6 hours now. It's awesome, I have time to explore that other API doc you've sent earlier.

And then...

- David: Funny thing, I received an e-mail last week about an AI optimizer tool offer. The tool claims it can improve codebase quality of any repo, sooooo I tested it. It's meh...

...but that "meh" hides something much more sinister.


* * *

You see, it's not about the tool at all, it's about the access to code repositories. There is now a market for large, real-world software repositories, and developers are receiving offers or they are tricked to just give access to it and "optimize" it using these tools.

Some of the "requirements" of these tools are super specific too, such as 100.000 lines of code, 500 to 1000 commits, at least 100 PRs, older than 5 - 7 years.

Large applications are particularly attractive, because they contain the kind of complexity that is difficult to do with AI right now: real business rules, real integrations, real edge cases, real architectural decisions, internal tooling, and years upon years of engineering knowledge embedded into these codebases.

Some tools target these kinds of projects, and they are not targetting founders or business managers, but the developers who have the keys to the "kingdom" and who are unwillingly (some willingly) open the door all in the name of moving faster and optimizing harder.

Cyber security is more important than ever and companies should stop treating code as development infrastructure and instead treat it as business assets.

The question is, would you even know this was/is happening at your company?