The developers in this scenario are there to absorb the blame when things go wrong. "Human crumple-zones" to protect the company.
As humans, we need another human to blame when things go wrong.
Especially in situations that are catastrophic when things go wrong.
Will be interesting to see if / when enforcement happens given management is currently being pushed to encourage AI use
I would say that counts as "not having that policy". Based on what management tells us, we are dead if we don't operate this way.
But that still doesn’t mean I review all the code. I tend to review defensively, based on the potential for harm if this piece of code is broken. And I rely a lot on tests, static analysis, canaries, analytics, health checks, etc. to reduce risk for when I’m wrong. So far it’s working.