Project Management Services for Website and Mobile App Development
A software project manager decides what the team builds next, who reviews it before it merges, and what evidence the work leaves behind. Two of those three responsibilities barely appeared in the job description five years ago. Mixcore Studio supplies project managers, delivery leads and scrum masters who run website and mobile app builds as an accountable delivery function rather than a reporting layer on top of one.
We have been shipping web and mobile products for over 8 years, with a team of around 20 and more than 320 projects delivered. That scale is relevant to how we manage. A studio this size does not run a large junior bench, so the leveraged delivery pyramid that AI has now broken was never how we staffed an account.
What changed about the project manager's job in 2026
Team shape changed before team size did. The direction the industry is moving in is the small, senior product team — commonly four or five people built around a product manager, a UX designer and at least one AI-native engineer — rather than a large team with a wide junior base. On the accounts we see, that is a restructuring of teams around AI and human expertise, not headcount elimination.
In a team of that shape the pure coordination workload drops, and three responsibilities take its place:
- Agent autonomy boundaries — deciding which actions an AI coding agent may take unsupervised in your repositories, CI pipelines, cloud accounts and ticketing system, and which require a named human approver.
- Review capacity as a planned, costed resource — review became the bottleneck the moment code generation stopped being one, so reviewer time is scheduled rather than assumed to be spare.
- Evidence collection — decision logs, AI-usage disclosure, provenance and approval records, because client contracts and EU regulation now ask for them by name.
What has genuinely died is the project manager whose main deliverable was a weekly status deck and an updated Gantt chart. That role was thin before 2023, and status reporting is the part of the work that automates most cleanly.
The delivery metrics we report, and the ones we refuse to quote
The productivity claim behind most AI-assisted delivery pitches is genuinely contested, and buyers know it. METR's randomised controlled trial, run February to June 2025 with experienced open-source maintainers working on repositories they already owned, measured a 19% slowdown when AI tools were allowed, while the same developers believed they had been about 20% faster. That is one trial, on a small and specific population, and METR is explicit about its limits rather than generalising from it — but it is the strongest evidence available that self-reported speedup is not a delivery measurement.
Google's 2025 DORA State of AI-assisted Software Development points the other way and reverses DORA's own 2024 finding: AI is now associated with improved delivery throughput, but also with increased delivery instability. DORA's framing is that AI amplifies whatever organisational strength or dysfunction already exists.
Our reading of both, and the basis on which we manage, is that AI moves the bottleneck from writing code to reviewing, verifying and stabilising it. So we report your measured numbers rather than a vendor benchmark: cycle time from first commit to production, review latency, change failure rate, defect escape rate and reopen rate. We will not quote the GitHub Copilot 55% figure or any similar controlled-task study as evidence of delivery speed, because it is not a delivery metric and a competent buyer will discount it.
Review throughput and the security of AI-authored code
Veracode's 2026 GenAI Code Security Report, published 28 July 2026, found an average security pass rate of 56% for AI-generated code and described that number as stalled rather than improving — meaning the remaining 44% of code-generation tasks failed their security test. Even the strongest model in that round still failed close to one security task in three, and Java trailed every other language at a 30% mean pass rate. With a large and growing share of committed code now AI-authored, that failure rate lands squarely on the review queue.
Developer trust tracks that reality. The Stack Overflow 2025 Developer Survey of around 49,000 respondents found 84% using or planning to use AI tools, but only 3% highly trusting the output while 46% actively distrust its accuracy, 66% naming AI solutions that are almost right but not quite as their top frustration, and 45.2% saying debugging AI-generated code takes longer.
The practical management consequence is that pull request review is no longer free residual capacity. On our accounts the project manager tracks reviewer-to-author ratio, review latency and the proportion of merges with no human review, and holds a hard rule that AI-authored diffs get the same static analysis gate and at least the same review depth as hand-written ones. If a plan requires more review hours than the team has, that is a scoping problem to solve before the sprint, not a quality issue to discover after release.
Quality assurance moved in the same direction. Capgemini's World Quality Report 2025-26 found 43% of organisations experimenting with generative AI in QA but only 15% scaled enterprise-wide, generative AI now the top-ranked skill for quality engineers at 63%, and synthetic test data use rising from 14% in 2024 to 25% in 2025 while 60% still struggle with secure, scalable test data management. The manual regression pass as a primary deliverable is over; test data strategy and verification of AI-authored code is where the effort now sits.
Compliance evidence is now part of delivery management
Regulatory flow-down became a procurement gate rather than a legal footnote, and the 2026 map is not the one most vendors prepared for. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved Annex III stand-alone high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded high-risk to 2 August 2028. This is a deferral, not a repeal, and anything already in flight still has to land.
What did not move is EU AI Act Article 50 transparency: disclosure that a user is interacting with an AI system, deepfake labelling and machine-readable marking of AI-generated content, in force from 2 August 2026. The Omnibus added only a four-month transitional period, to 2 December 2026, for the Article 50(2) marking duty on generative AI systems already placed on the market before that date. If your product has a generative feature, that obligation is live now, and the delivery plan has to carry it.
Two further dates sit inside our planning:
- EU Cyber Resilience Act, 11 September 2026 — manufacturers of products with digital elements must report actively exploited vulnerabilities to ENISA and the national CSIRT within 24 hours, including for products already on the EU market. Full obligations, including the Annex I machine-readable SBOM covering at minimum top-level dependencies, apply from 11 December 2027. You cannot meet a 24-hour report without already knowing what is in your build, which makes component inventory a practical prerequisite well before it is a formal one.
- NIS2 supplier flow-down — essential and important entities must impose enforceable cybersecurity obligations on direct suppliers by contract, backed by administrative fines scaled against global annual turnover. A development subcontractor inherits those requirements whether or not it is in scope directly, so we accept NIS2-grade clauses rather than treating compliance as the client's problem.
As a Vietnam-based supplier we also operate under a domestic technology regime alongside the EU one. Vietnam's Law on Digital Technology Industry is in force, and Vietnam has since legislated specifically on artificial intelligence, including risk classification and duties to disclose AI interaction and to mark AI-generated media. The obligations are close in shape to the EU transparency rules but not identical, so we confirm the current text with counsel per engagement — and your counsel should review it before signature, not after.
How we scope and price delivery management
Pure headcount staff augmentation priced per full-time equivalent per month is the commercial model most exposed to AI-driven price deflation, and the large IT services firms have been signalling exactly that pressure on effort-based work to their investors. Selling bodies per month is a shrinking business even where demand is growing, which is why we do not lead with it.
Procurement is moving the same way, away from pure effort-based contracts and towards outcome-based and productised delivery. We structure engagements to match that direction:
- An input tier for genuinely exploratory work, where scope cannot honestly be fixed yet.
- An output tier priced per feature or per resolved ticket, which is where most steady-state delivery belongs.
- An outcome tier written against metrics you already own, such as defect escape rate, reopen rate or first-contact resolution, rather than against vendor-defined KPIs.
- Explicit rate escalation caps, because the cost side and the price side are moving in opposite directions. Engineering salaries and attrition in Vietnam both keep upward pressure on delivery cost, while AI pushes contract prices down.
- Exit terms agreed at signature — data portability, knowledge-base ownership, prompt and agent-configuration handover, runbook transfer. AI-native delivery concentrates undocumented context in vendor-side tooling, so this is negotiated while you still have leverage.
On the question buyers ask most often, whether they are paying human rates for machine output: our answer is that AI leverage should appear somewhere visible, either in the rate card, the throughput commitment or an outcome tier. It should not be silently absorbed as vendor margin.
When a dedicated project manager is the wrong choice
A dedicated project manager is overhead you should not buy in at least three situations.
If the engagement is a single well-defined deliverable running under about six weeks, a technical lead with direct client access will move faster than a lead plus a manager. The coordination saving does not cover the cost of the extra translation layer.
If you already have a strong internal product owner who is available daily and comfortable making scope calls, adding our project manager on top usually creates a second decision queue rather than removing one. A fractional arrangement, a few hours a week on process, risk and evidence, is normally the better fit, and we will say so during scoping rather than after you have signed for a full-time role.
If your real problem is that nobody can decide what to build, a project manager will not fix it. Delivery management converts decisions into shipped software; it does not manufacture the decisions. That is a product discovery engagement, and calling it project management wastes several months before anyone admits the mismatch.
We are also cautious about agentic delivery claims, including our own. Production deployment of AI agents still lags a long way behind stated intent, and analysts expect a substantial share of agentic AI projects to be abandoned on cost, unclear value and weak risk controls. Where an agent genuinely helps a delivery workflow we will use one and show you the production data; where a scripted, deterministic automation does the job, we will use that instead and say why.
Our expertise
- Delivery planning and scope control
- Agent autonomy boundaries
- Code review throughput
- Risk and dependency management
- Compliance and audit evidence
- Outcome-based reporting
Frequently asked questions
What does a project manager actually do when AI writes half the code?
The coordination half of the job shrinks and the governance half grows. Veracode's 2026 GenAI Code Security Report puts the security pass rate for AI-generated code at 56% and calls that number stalled rather than improving, so the manager's real work becomes protecting review capacity, setting what an agent may do unsupervised, and keeping the evidence trail contracts now require. Status reporting, which used to fill the role, is the part that automated away.
Are we paying human rates for machine output?
That is the most common objection to a 2026 dedicated-team quote, and it deserves a direct answer rather than a discount. Our position is that AI leverage has to show up somewhere visible, in the rate card, in the throughput commitment, or in an outcome tier priced against metrics you already measure. We would rather structure an output or outcome tier than defend a 2023 per-person price with 2026 tooling behind it.
Who decides what an AI agent is allowed to do in our repositories?
You do, and it is written into the contract rather than left to team norms. We agree explicitly which actions an agent may take without human approval across repositories, CI, cloud accounts and ticketing, which actions need a named approver, and what gets logged. The project manager owns that boundary in practice and reports on merges with no human review, so the policy is auditable rather than aspirational.
Do we still need a dedicated project manager for a small team?
Often not, and we will tell you when. For a single well-defined deliverable under about six weeks, or where you already have an available internal product owner making daily scope calls, a technical lead with direct client access moves faster than a lead plus a manager. A fractional arrangement covering process, risk and compliance evidence for a few hours a week is usually the better fit in those cases.
Can you meet EU compliance requirements like Article 50 and the CRA reporting rule?
Yes, and we plan against the post-Omnibus dates rather than the original ones. Regulation (EU) 2026/1744 moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028, but AI Act Article 50 transparency has applied since 2 August 2026, with only a four-month transitional period to 2 December 2026 for the Article 50(2) marking duty on generative systems already on the market. We build component inventory into delivery ahead of the Cyber Resilience Act's 24-hour exploited-vulnerability reporting duty, which starts on 11 September 2026 and covers products already on the EU market, and we accept NIS2-grade security clauses in the contract.
Contacts
We are always happy to talk with you.
Feel free to contact us in any suitable way
Request a quote
Let's discuss your project!
Please, provide us with a brief description of what you
already have and what you are going to achieve.
Mail us contact@brainiacminds.com