Press release

Sonar Globally Launches SonarQube Remediation Agent at ATxSummit, Automating Verified Code Remediation

SINGAPORE — May 21, 2026 — Sonar, the global leader in AI code verification and automated code review, today announced the global launch of the SonarQube Remediation Agent at ATxSummit 2026. A breakthrough in autonomous software maintenance, SonarQube Remediation Agent automatically fixes code issues and scans every fix before it ships, helping organizations confidently scale AI-assisted development. 

A pioneer in code quality, Sonar offers AI-native and AI-augmented solutions that provide an independent trust, verification, and governance layer for enterprises seeking to adopt AI safely and responsibly. Sonar analyzes 750 billion lines of code daily for over seven million developers, including 75% of the Fortune 100. Sonar’s regional headquarters in Singapore, supported by the Singapore Economic Development Board (EDB), serves its growing user community and customer base across the Asia Pacific region. 

Global Innovation, Singapore Roots

SonarQube Remediation Agent was developed in partnership with the Infocomm Media Development Authority of Singapore (IMDA), who served as a strategic design partner. SonarQube Remediation Agent represents the commercial evolution of AutoCodeRover—an LLM-based software engineering agent developed by researchers at the National University of Singapore (NUS), which was acquired by Sonar in 2025

Through rigorous testing and feedback from IMDA and local engineering talent in Singapore, the agent has been validated against diverse, real-world conditions. This collaboration ensures the product is optimized for the rigors of global enterprise environments. SonarQube Remediation Agent acts only on verified issues detected during SonarQube analysis, leading to a 3.2% false positive rate. SonarQube supports more than 40 languages and frameworks, delivering multi-layered review and verification through sophisticated mathematical reasoning that goes beyond simplistic pattern matching.

“AI-generated code is fast becoming the norm in software development. As engineering teams move faster, it is important that code quality checks and remediation keep pace. Our partnership with Sonar helps address existing gaps in this area, equipping enterprise software teams with practical tools to build at speed, while maintaining quality, security and responsibility,” said Dr Ong Chen Hui, Assistant Chief Executive, BizTech Group, IMDA.

"Sonar's decision to develop its AI remediation agent from Singapore reinforces our position as a leading hub for AI innovation,” said Mr. Pee Beng Kong, Executive Vice President, EDB. “Singapore’s robust R&D ecosystem and trusted environment enable companies like Sonar to develop cutting-edge AI technologies into commercial solutions that address industry needs. We look forward to seeing more companies create AI solutions from Singapore for the region.”  

Closing the "Guide-Verify-Solve” Loop

SonarQube Remediation Agent is a critical piece of Sonar’s Agent Centric Development Cycle (AC/DC) framework: a new software development methodology designed for the unique production scale and speed of AI-generated code. The AC/DC is Sonar’s methodology for ensuring AI agents are operating in a trustworthy, consistent, and transparent way, and consists of three phases: Guide, Verify, and Solve.

“AI agents are changing how software gets written, but they only work at scale if you can trust the code they generate. With SonarQube Remediation Agent, we’re bringing together Singapore-born research and Sonar’s verification engine so that every automated fix is checked before it reaches production. That’s how teams clear their most critical issues faster, without asking developers to trade speed for safety,” said Tariq Shaukat, CEO at Sonar.

Sonar's guide capabilities equip AI agents with the authoritative context and constraints they need to operate correctly within an organization's codebase. Sonar's verify capabilities checks the quality, security, and architectural integrity of AI’s work. SonarQube Remediation Agent specifically fulfills the solve phase of the AC/DC stages, taking every automated fix through verification using Sonar’s own engine before it ever becomes a pull request, ensuring developers only see verified changes. 

The impact of SonarQube Remediation Agent

While many AI tools simply flag errors, the SonarQube Remediation Agent completes the cycle by proposing concrete code changes. To prevent "AI hallucinations" or broken code, every fix is scanned, and if a proposed fix does not clear the quality gate or introduces a new code smell or vulnerability, a new fix is presented. SonarQube Remediation Agent is built on the same technology as the Sonar Foundation Agent, a refinement of AutoCodeRover. The Sonar Foundation Agent currently holds the #1 position on the SWE-bench Verified leaderboard, the leading benchmark for performance on real-world software engineering tasks.

Key benefits include:

  • On-demand Repair: Keeps pull requests moving by fixing bugs and security issues automatically. Developers review and merge rather than debug and patch.
  • Backlog Remediation: Systematically reduces technical debt without manual triage. Teams assign existing issues directly to the agent, which opens one focused pull request per issue.
  • Verified Reliability: Each fix is scanned by Sonar’s analysis engine before it is proposed, reducing the introduction of new vulnerabilities or bugs.
  • Developer Oversight: The agent opens a standard pull request for every fix, keeping human engineers in final control of the codebase.
  • AI Scalability: Pairs with AI coding tools (i.e. Claude Code, Copilot, Cursor, etc) for organizations to maintain consistent quality and governance as volumes of generated code increase.

Sonar is beginning to provide the agent as a paid offering this month, with full roll-out to be complete by the end of June. To learn more, visit the SonarQube Remediation Agent page


About Sonar

Sonar, the global leader in AI code verification and governance, helps reduce outages, improve security, and lower costs and risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.

To learn more about Sonar, please visit: www.sonar.com


Cautionary note: Forward-looking statements

This press release may contain forward-looking statements about future expectations, plans, and prospects. These statements are based on current beliefs and assumptions and are subject to risks and uncertainties. The information in this press release is provided as of this date, and we undertake no obligation to update any statements.

  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin
language switcher
한국인 (Korean)
  • 법적 문서
  • 신뢰 센터

© 2026 SonarSource Sàrl. All rights reserved.