Sources and Citations
Every statistic on this site carries a publisher, a year, and a link. This page collects them in one place so you can check our work.
Our Citation Standard
Most content in this space repeats numbers that nobody can trace. These are the rules we hold ourselves to instead.
Publisher, year, link
A statistic without all three gets cut. No "studies show", no "industry data suggests", no unnamed analysts.
Pricing is dated
Vendor pricing changes constantly. Every figure states when we checked it and links to the vendor's own page.
No invented examples
No fabricated companies, executives, quotes, or outcomes. Illustrative scenarios are labeled as such and carry no names.
Uncertainty is stated
Where a vendor does not publish a number, we say so rather than repeating an aggregator's guess.
A note on vendor claims
Some figures below come from vendor marketing, funding announcements, or company blogs. Those are the company's own reporting, not independent measurement, and we label them that way. Adoption counts, revenue figures, and performance benchmarks published by the vendor selling the product deserve more skepticism than a survey with a disclosed sample size and methodology.
Developer Surveys and Industry Research
These four are the backbone of most adoption claims on this site. Three of them independently converge near 85 percent AI tool usage, which is why we treat that figure as reliable.
| Source | Sample | Key findings we cite |
|---|---|---|
| Stack Overflow Developer Survey 2025 Stack Overflow, 2025 | n = 48,885 | 84 percent use or plan to use AI tools, up from 76 percent in 2024. Only 33 percent trust AI output accuracy and 46 percent actively distrust it. 66 percent name "almost right, but not quite" as their top frustration. |
| State of AI-assisted Software Development Google Cloud / DORA, September 2025 | nearly 5,000 respondents | 90 percent use AI in daily work, up 14 points on 2024. Its central finding is that AI acts as an amplifier of existing organizational strengths and weaknesses. |
| State of Developer Ecosystem 2025 JetBrains, October 2025 | n = 24,534 | 85 percent regularly use AI tools; 62 percent rely on at least one AI coding assistant, agent, or editor. Code quality is the single largest stated concern at 23 percent. |
| Octoverse 2025 GitHub, October 2025 - platform telemetry, vendor-published | Platform-wide | 180 million-plus developers, 36 million added in 2025. TypeScript overtook Python and JavaScript in August 2025. Public repositories using LLMs grew 178 percent year on year. |
A common error worth flagging: several sites republish the 2025 Stack Overflow figures under "2026 Developer Survey" headlines. The 2026 survey opened in June 2026 and results were not published as of our last review. We cite these as 2025 figures.
Code Quality and Productivity Research
This is the most contested evidence base in the industry, and the place where careless citation does the most damage.
GitClear: The AI Code Quality Maintainability Gap
GitClear, January 2026. 623 million analyzed changes, 2023 to 2026.
- Code block duplication up 81 percent against a 2023 baseline, from 40.3 to 73.0 duplicated blocks per million changed lines
- Moved code, its proxy for refactoring, fell from 21 percent of changed lines in 2022 to 13 percent in 2023 and 3.8 percent year-to-date in 2026. Note the 2022 figure is quoted by GitClear as a pre-AI reference point and sits outside the report's own 2023-2026 dataset window, which is why the series looks inconsistent with the sample description above until you read it that way. Both numbers are the report's.
- Legacy code maintenance down 74 percent against 2022
- Error-masking constructs up 47 percent
Disclosure: GitClear sells code quality analytics, so it has a commercial interest in this finding. The dataset size and the consistency of the direction across eight independent signals are what make it worth citing anyway.
Read the researchMETR: Measuring AI Impact on Developer Productivity
METR, July 2025, with a significant author update in February 2026.
The original randomized controlled trial put 16 experienced open source developers through 246 tasks on mature repositories. Developers were measured 19 percent slower with AI, while predicting beforehand they would be 24 percent faster and believing afterwards they had been 20 percent faster.
Read this one carefully. In February 2026 METR published an update stating it now believes developers are more sped up by AI than its early-2025 estimates suggested, and that it is abandoning task-level randomization. One reason it gives is directly relevant here: time tracking became unreliable once developers began running multiple agents concurrently. The uncaveated "AI makes developers 19 percent slower" claim is widespread and is contradicted by the study's own authors.
Security and Cost Benchmarks
Figures in this category are widely misquoted, usually by attaching the right number to the wrong year.
IBM Cost of a Data Breach Report
IBM, published annually at the end of July.
The 2025 report is the current edition: the global average cost of a data breach fell to $4.44M, while the United States average rose to $10.22M. The frequently-quoted $4.88M figure is from the 2024 report and has been superseded.
Two cautions when using this figure. First, check the year - we previously carried the same $4.88M number attributed to 2023, 2024 and 2025 on three different pages, which is exactly the error this page exists to prevent. Second, it is an all-causes average across every breach type. It is not a lost-laptop figure and not a development-environment figure, so it does not belong in a calculation of what centralizing development environments saves you.
Sustainability and Energy
This is the most contested evidence base we deal with, and the one where the popular numbers are least defensible.
The headline finding: nobody has measured this
We looked for a published before-and-after carbon measurement of moving developers from laptops to cloud development environments, across arXiv, the Green Software Foundation, GitHub's sustainability writing, AWS sustainability case studies and the major CDE vendors. There is not one.
The strongest peer-reviewed study in the adjacent space found the opposite of the popular claim. Our GreenOps page sets out what the evidence does and does not support, and lists the specific figures we refuse to repeat.
| Source | What it establishes |
|---|---|
| Farthing, Langner and Trenbath NREL, in Intelligent Buildings International, September 2018. Peer reviewed. | Once data center power behind the virtual machines is counted, zero-client computing used 119 percent more power than laptop computing. Limitations matter: n=4, office knowledge work rather than development, and 2018 hardware. |
| Apple Product Environmental Report Apple, October 2024, 14-inch MacBook Pro. Manufacturer self-reported. | Total product footprint 218 kg CO2e, with production accounting for 74 percent. This is the basis of the strongest sustainability argument available: most of a laptop's footprint is manufacturing, not electricity. |
| Coolproducts don't cost the Earth European Environmental Bureau, September 2019. | A one-year lifetime extension of all notebooks in the EU would save 1.6 Mt CO2 per year by 2030, and "it never makes sense, from a global warming point of view, to replace a notebook". |
| State of the Cloud Report Flexera, 2024. Self-reported survey estimate, not a measurement. | Respondents estimate roughly 32 percent of cloud spend is wasted. Note this is what respondents believe about their own organizations, and it is a 2024 figure. |
| Energy and AI International Energy Agency, April 2025. | The reference source for data center and AI electricity demand. We link it rather than quoting a headline percentage, because the widely-repeated "data centers use N percent of global electricity" figures vary by definition and vintage. |
Standards and Protocols
Primary specifications and governance records for the conventions that agents and development environments now depend on.
Model Context Protocol
The specification and its release notes. Donated by Anthropic to the Linux Foundation's Agentic AI Foundation in December 2025.
SpecificationAGENTS.md
The agent instruction file convention. Note it has no version number and no formal specification - it is deliberately just Markdown.
agents.mdAgent Client Protocol
Created by Zed Industries, Apache 2.0. The editor-to-agent counterpart to MCP's agent-to-tool role.
RepositoryAgent2Agent (A2A)
Donated by Google to the Linux Foundation in June 2025, v1.0 released April 2026. Less relevant to coding agents than MCP or ACP.
AnnouncementRegulation and Compliance
Regulatory timelines shift, and stale compliance advice is worse than none. These are the primary and legal-analysis sources behind our dates.
EU AI Act - the deadlines moved
Under the Digital Omnibus agreement, standalone Annex III high-risk obligations were postponed from August 2026 to December 2027, and AI embedded in regulated products from August 2027 to August 2028. A great deal of published compliance content still quotes the original August 2026 date.
What was not delayed matters more for development teams: Article 50 transparency obligations for AI-generated content, plus Commission penalty powers over general-purpose AI providers, still take effect in August 2026. Prohibitions and AI literacy obligations have been in force since February 2025.
Gibson Dunn analysisEU Cyber Resilience Act - reporting starts before SBOM is enforceable
Vulnerability and incident reporting obligations begin in September 2026, on a cascade of 24-hour early warning, 72-hour notification, and a final report at 14 days or one month. Full application, including enforceable SBOM requirements and CE marking, follows in December 2027.
The nuance most coverage misses: SBOM is not legally enforceable until 2027, but you cannot meet the 2026 reporting duty without already knowing your components. In practice the capability is needed roughly fifteen months early.
European CommissionDORA - two different things share this acronym
On this site, DORA in a metrics or delivery-performance context means DevOps Research and Assessment. In a financial services or European regulatory context it means the Digital Operational Resilience Act, in full enforcement since January 2025. They are unrelated, and we name which one we mean on first use of each page.
Vendor Primary Sources
Where our platform and pricing statements come from. We link the vendor's own page rather than an aggregator, because aggregator pricing in this space is frequently wrong.
Coder
Pricing and editions
Ona
Pricing and deployment models
GitHub Codespaces
Billing and free tier quotas
Daytona
Agent sandbox pricing
Okteto
Pricing and self-hosting
Jetify
Devbox and Devspace pricing
Google Cloud Workstations
Pricing
Microsoft Dev Box
Pricing and licensing prerequisites
E2B
Sandbox pricing
Vendors that changed category
Daytona is the reason several pages here warn that a two-year-old CDE shortlist will be wrong. It began as a cloud development environment company and publicly announced in April 2025 that it had "decided to realign its focus from solving developer environment inconsistencies for humans to solving runtimes for AI agents", with the internal shift dating to around the turn of that year. Its homepage now reads "Secure and Elastic Infrastructure for Running Your AI-Generated Code" and makes no reference to development environments at all.
Its widely-starred public repository is not archived, but carries a notice that it is no longer maintained, with core development moved to a private codebase as of June 2026. We state the category change on every page that mentions Daytona; the date and the quotation are recorded here so they live in one place.
What we deliberately do not publish
Several vendors in this market do not publish per-seat pricing at all, including Coder Premium, Okteto's paid tiers, and Red Hat OpenShift Dev Spaces as a standalone product. Microsoft's Dev Box pricing page renders no figures without an account and region selected.
Where that is the case we say the vendor does not publish it, rather than repeating a third-party estimate. If you have seen a specific number for one of these on another site, it was almost certainly inferred rather than sourced.
Found Something Wrong?
This is a fast-moving subject and some of what is here will go out of date. If you find a figure that is stale, a link that has rotted, or a claim you think we cannot support, tell us and we will correct it or remove it.
Report a correction
