PostgreSQL committer Tomas Vondra analyzed all 12 reverts of major features from PostgreSQL 19 in mailing list threads and refuted the viral claim that the release was broken by bugs found by AI: in only 4 of 12 cases was the problem found by AI, the other 8 were the result of standard human review. The real impact of AI turned out to be indirect — an avalanche of security reports, some of which were generated by AI, is eating up the time of senior reviewers during the stabilization phase. Result: PostgreSQL 19 will be released about a month later than planned.



What happened
Tomas Vondra published a post titled “Are we reverting patches because of bugs found by AI?”, in which he manually checked the history of each of the 12 reverts of major features that shifted the PostgreSQL 19 release date. The problem was found by AI in only 4 cases: among them was an Opus 5 review of the “Support more object types within CREATE SCHEMA” patch and a “possibly AI” note for batching in the RI fast-path. The other 8 reverts were the result of classic human review by Noah Misch, Andres Freund, Jozef, and other maintainers. Vondra also compared PG14–PG19 cycles by “Revert” commits: in the PG19 cycle there were about 2,200 commits versus about 1,700 in PG14, and against this backdrop the frequency of reverts is not unprecedented. What changed was not the volume but the timing: there was no familiar peak after feature freeze, and the spike occurred around day 430 of the cycle, in early September.
Context
The background is set by how PostgreSQL development works: patches are reviewed in public mailing list threads, the history of each revert is recorded there, and only a maintainer with access to all these threads can check the viral headline line by line. The dispute flared up after a post by Elizabeth Christensen from Snowflake on September 17, 2026, which explained the reverts as bugs found by AI — a thesis that spread, including on Hacker News. The actual load on the project increased differently this year: the number of CVEs in PostgreSQL increased from about 5 in 2025 to 44 in 2026, with 28 of them in the August patch for PG18 alone, and some of the reports came from AI. Vondra describes the resulting mechanism as “AI inversion”: AI does not directly break features but invisibly takes up maintainers' time triaging auto-generated reports — generation scales automatically, but triage throughput does not grow.
Why this matters for the industry
For the industry, the value of this analysis lies in the fact that an incorrectly set diagnosis leads to incorrect decisions: if it is assumed that AI “finds unfixable bugs,” projects will start accepting AI reviews less often, although in the analyzed cases it did indeed find real problems. The real economics are different: report generation scales automatically, but triage does not, so the flow of security reports overloads senior reviewers precisely during the stabilization phase and shifts release dates. At the same time, the quality of model review of mature large codebases depends heavily on the model generation: one version found a real problem in a reverted patch, while Opus 4.8, when Noah Misch tried to review through it, only found minor issues. For AI-review vendors, the viral headline that has already hit the market will have to be refuted with data, not opinion. The promised PostgreSQL policy on AI contributions — with requirements for provenance, reproducibility, and deduplication of reports — could become a template that other major open-source projects will follow.
Why this matters for users
For users, the most tangible thing is the date shift: PostgreSQL 19 will be released about a month later than planned, and SQL/PGQ, MERGE/SPLIT PARTITION, and GROUP BY ALL will not appear before PostgreSQL 20. Nothing in working systems is broken, but teams on Postgres should adjust their roadmaps and not plan delayed features for current migrations, while security teams are already dealing with the voluminous August patch for PG18. If you are sending bugs found by AI to open-source projects, mark the provenance of the finding and wait for the official AI contributions policy — its content is not yet determined. Vondra's analysis also shows the value of human review: even with model participation, the main work in most cases was done by project maintainers.
What is still unknown / limitations
The attribution in the analysis is partially qualitative: one of the cases is marked as “possibly AI,” and the conclusions are based on reading mailing list threads. The sample of 12 reverts is small, and the figures in the post are approximate estimates (number of cycle commits, number of CVEs), not official project statistics. The content of the promised PostgreSQL policy on AI contributions is not yet known, nor is the exact final release date of PostgreSQL 19.
Sources
- Are we reverting patches because of bugs found by AI? — Tomas Vondra
- PostgreSQL 19 Delayed: Key Feature Reversions & Release Updates — Snowflake (Elizabeth Christensen)
- Hacker News discussion: Postgres — Are we reverting patches because of bugs found by AI?
Author
Look at AI, editorial team
