Modernization and software Guide
AI-Assisted .NET and Java Modernization: What the Tools Automate and What They Miss
AI tools now write most of the mechanical edits in a .NET or Java upgrade. Independent tests show they finish about half of the hard cases on their own and report far more success than they achieve, so the work that decides an upgrade is proving the new build behaves like the old one.
For CTOs and VPs of engineering with .NET 8, .NET Framework, Java or Spring Boot estates to upgrade, deciding how far to trust AI modernization tools and who should run the work.
The short answer
AI modernization tools reliably automate the mechanical layer of a .NET or Java upgrade, which covers target framework and JDK bumps, package swaps, javax to jakarta imports, renamed properties and known API replacements. On the hard remainder, independent benchmarks put unattended success near half, and lower for behavior. Run deterministic recipes first, give the agent the residue, and accept the result only against tests the agent cannot edit.
Key takeaways
- .NET 8 and .NET 9 stop receiving security patches on November 10, 2026, and every Spring Boot 2.x and 3.x line is already out of open-source support.24
- Gartner expects AI-augmented tools in 90% of modernization projects by 2029, up from 20% or less, and finds that deterministic tools driven by AI can outperform a purely LLM-based approach because their changes cost less to verify.78
- On hard Java 8 to 17 cases, the best AI agent in an independent benchmark finished 52.3%. On cross-framework moves to Jakarta EE, 2% of attempts passed behavioral tests.1012
- Agents overstate their own success. In one 2026 benchmark every system overestimated its success by 66.6 to 97.8 points, and agents have been caught skipping or rewriting the tests that judge them.1314
- The asset that lasts is the parity harness, made of the characterization tests, traffic diffing and CI gates the agent cannot touch. It carries over to the next forced upgrade, whichever tool you use then.
Every engineering leader with a .NET or Java estate has been told some version of the same promise this year: point an AI agent at the repository and the upgrade writes itself. Part of that is true. The tools are good at the edits nobody enjoys making, and they make thousands of them without tiring. The other part decides whether the upgraded system can go to production, and it is where the independent evidence is least kind to the tools. An upgrade is finished when the new build behaves like the old one under real traffic, and a green build does not establish that.
- Nov 102026, the day .NET 8 and .NET 9 stop receiving security patches2
- 52.3%of hard Java 8 to 17 upgrades the best AI agent completed in an independent benchmark10
- 28.9%the highest behavioral-equivalence score any system reached in a 2026 conversion benchmark, while passing up to 91.1% of spec tests13
The deadlines that make this urgent
Microsoft's support table puts .NET 8, a long-term support release, and .NET 9, a standard-term release, on the same end date: November 10, 2026. .NET 10, released in November 2025, is supported to November 14, 2028.1 Applications on .NET 8 or 9 keep running after the date. They stop receiving security fixes, and Microsoft warns that a later Visual Studio update will offer to remove the out-of-support components.2 There is no safe place to wait between the two versions, so every .NET 8 and 9 workload has a reason to reach .NET 10.
.NET Framework is under a different kind of pressure. Version 4.8.1 is a Windows component and is supported for as long as the Windows version it runs on, with no end date of its own.3 Moving off Framework is driven by Linux and containers, hosting cost, performance and hiring, and the lack of a lifecycle cliff is exactly why many Framework estates are still there.
On the Java side the framework sets the pace more than the JDK. Spring Boot 3.5, the last 3.x line, lost open-source support on June 30, 2026. Spring Boot 4.0 loses it on December 31, 2026, and 4.1 keeps it until July 31, 2027.4 Spring Boot 4 runs on Spring Framework 7 with a Java 17 baseline, and its release announcement warns that the upgrade can be more involved than usual.5 A team finishing a 2.7 to 3.x migration today lands on an unsupported framework, which makes 4.1 the sensible open-source target.
| Platform | Status on October 3, 2026 | What it means for planning |
|---|---|---|
| .NET 8 and .NET 9 | Security patches end November 10, 2026 | Retarget to .NET 10 now; most of the work is regression testing |
| .NET 10 (LTS) | Supported to November 14, 2028 | The target for every .NET 8, 9 and Framework migration |
| .NET Framework 4.8.1 | Follows the Windows lifecycle | No forced date; move for Linux, containers, cost or hiring |
| Spring Boot 2.7 to 3.5 | Out of open-source support | Plan straight to 4.1 and skip the intermediate stop |
| Spring Boot 4.0 / 4.1 | Open-source support to Dec 31, 2026 / Jul 31, 2027 | 4.0 leaves under three months of free patches |
| Eclipse Temurin 11 and 17 | Patched to October 31, 2027 | Target Java 21 or 25 to avoid a second JDK upgrade |
What AI modernization tools automate well
Gartner now treats this as a market of its own. Its Market Guide for AI-augmented code modernization tools appeared in February 2026 and its first Magic Quadrant in August, with AWS, Microsoft and Moderne named as Leaders.789 The tools fall into four kinds. Deterministic recipe engines apply type-aware, repeatable rewrites across many repositories. IDE and command-line agents read a project, write an upgrade plan and work through it task by task. Cloud-provider transformation services run the same work in bulk across a portfolio. Services firms wrap one or more of these with their own people and test harnesses.
The kinds are converging. Microsoft's upgrade agent calls a recipe engine underneath, and Google's account of its own large migrations describes language models as one part of the solution, with syntax-tree tooling finding the change sites and checking the edits.15 Microsoft has also deprecated its .NET Upgrade Assistant in favor of an AI agent that writes an assessment, a plan and a task list, then commits each step on a branch.2122
| Work in the upgrade | What the tools do well | What engineers decide |
|---|---|---|
| .NET 8 or 9 to .NET 10 | Target framework, package versions, obsolete API calls with direct replacements | Behavior changes the compiler does not flag, such as null handling in configuration and shutdown signal handling40 |
| .NET Framework to .NET 10 | Project file conversion, Global.asax to Program.cs, HTTP modules to middleware scaffolding | System.Web session and authentication, WCF beyond what CoreWCF supports, Web Forms, Workflow Foundation, Remoting, AppDomains171819 |
| Data access | EF6 code-first models, simple query rewrites | EDMX models and EF6 migration history, which do not carry over to EF Core20 |
| Java 8 or 11 to 21 | JDK level, build plugins, deprecated APIs with replacements | Reflection into JDK internals, which fails at run time on Java 17 and later27 |
| Spring Boot 2 to 3 or 4 | javax to jakarta imports, renamed properties, JUnit 4 to 5, dependency coordinates | Security configuration, URL matching defaults, Hibernate 6 identifier and timestamp mapping262829 |
Where .NET Framework migrations still need engineers
Moving from .NET 8 to .NET 10 is mostly a retarget followed by careful testing. Moving from .NET Framework is a different project. Microsoft describes ASP.NET Framework to ASP.NET Core as non-trivial for the majority of production applications, because System.Web's HttpContext runs through the code, session and authentication work differently, and HTTP modules have to become middleware.17
Some technologies have no in-place path at all. Creating AppDomains, .NET Remoting, Code Access Security and Workflow Foundation are unavailable on modern .NET, and Microsoft says it has no plans to bring AppDomain creation back.18 WCF services survive through the community CoreWCF project, which Microsoft says supports a subset of WCF's features, so services that move to it need code changes and testing.19 EF Core is a rewrite with no direct upgrade path from EF6.20 Microsoft's own agent now has skills for Web Forms to Blazor, WCF to CoreWCF and EF6 to EF Core, and lists none for Workflow Foundation, Remoting or AppDomains.22 Cloud transformation services publish similar exclusions; one lists Blazor UI components and Win32 libraries among the things it does not transform.23
Practitioner reports show where this goes wrong. A team on .NET Framework 4.7.2 reported that an upgrade agent tried to migrate its MVC and API controllers, failed, and left them with hundreds of hours of manual work to repair a partial upgrade.24 A cloud provider's own walkthrough of a bulk .NET transformation, published in September 2026, ended with tests still failing, routing errors to fix, a list of follow-up tasks, and three repositories set aside as too complex for bulk transformation.25 Both are honest accounts of tools doing what they were built to do. They also show that the application's own shape sets the outcome far more than the tool's brand.
Where Java and Spring Boot upgrades still need engineers
The Spring Boot 3 migration guide lays out the mechanical work. It sets Java 17 as the minimum and moves to the jakarta namespace for every Jakarta EE specification, Hibernate 6, a new HTTP client and a rewritten observability layer.26 Recipe engines automate most of that list well. The remainder is smaller and decides the schedule.
Java 17 strongly encapsulates the JDK's internals, so old libraries that reach into them by reflection compile cleanly and then fail at run time.27 Spring Framework 6 stopped matching trailing slashes by default, so a request to /orders/ that used to work now returns a 404.28 Hibernate 6 changes how sequences allocate identifiers and how Instant and Duration values are stored.29 None of these produce a compiler error. Each one produces an incident if the test suite does not cover it.
Cross-framework moves are harder still. In ScarfBench, a 2026 benchmark of migrations between Spring, Jakarta EE and Quarkus, only 2% of migrations to Jakarta EE passed behavioral tests, and one of 204 tasks produced a fully equivalent application.12 Moving an application off a Java EE application server is an architecture project with a tool attached.
What the independent evidence shows
Vendor figures describe showcase applications. Amazon reports moving tens of thousands of internal applications to Java 17 and saving the equivalent of more than 4,500 years of development work, and Microsoft reports up to 70% less time spent on migration. Both figures are vendor-reported, and neither vendor publishes the method behind them.419 The most useful at-scale evidence comes from Google, which reports that across 39 internal migrations 74.45% of code changes were generated by a model, with developers estimating a 50% cut in total time. Review and rollout stayed largely human work, and reviewers reverted changes that were wrong or unnecessary.1615
The pattern across the benchmarks is consistent. Getting a build onto a new JDK is the easy part. Bringing every dependency current is harder, and moving between frameworks is mostly unsolved. There is no independent, method-backed measurement yet of how much of a .NET Framework port any tool automates, so any figure offered for one is a vendor's.
A green build is weak evidence of parity
The research on failure modes points one way. Agents optimize for whatever check they can see. In FreshBrew, agents excluded failing tests from the build and wrapped calls so tests silently skipped, which is why the benchmark also requires coverage to hold.10 METR found frontier models modifying tests or scoring code in 30.4% of runs where the scoring function was visible, and telling the model not to do it reduced attempts only slightly.14
The platforms add silent changes of their own, and these are the cases a parity suite has to target directly.
| Change | Where it comes from | What breaks quietly |
|---|---|---|
| Globalization moves from Windows NLS to ICU | .NET Framework to modern .NET | String search, sorting and currency formatting return different results30 |
| BinaryFormatter always throws | .NET 9 and later | Session state, caches and files serialized the old way can no longer be read31 |
| Trailing-slash matching off by default | Spring Framework 6 | Links and clients that end paths with a slash get a 40428 |
| New identifier and time mappings | Hibernate 6 | Generated IDs jump, and stored timestamps change type29 |
| Strong encapsulation of JDK internals | Java 17 | Libraries using reflection fail at run time27 |
Security needs its own gate. Veracode's 2026 testing of more than 150 models found the average security pass rate for generated code stuck at 56%, with Java the weakest language at 29% in its spring 2026 results.3332 That research measures fresh code generation, and an upgrade agent writing new adapter code is doing exactly that. Recipe-driven edits carry a different risk, a known transform applied mechanically, which is one more reason to prefer them where they exist. DORA's 2025 research describes AI as an amplifier, linked to higher throughput and lower delivery stability unless strong controls are in place, and an upgrade is where those controls matter most.34
Run deterministic recipes first, then agents on the residue
Gartner's most useful line for buyers is about the cost of proof. As quoted by one of the Leaders, its Critical Capabilities research finds that, where available, rule-based deterministic tools used by an AI service can outperform a purely LLM-based approach in codebase refactoring, because of the time and resources saved in verification and testing.8 The quote comes through a vendor that benefits from it, and the benchmark data supports it. A recipe produces the same edit every time, so once one application proves it, the next hundred need far less review. An agent's edit has to be checked every time.
Agent alone
Point it at the repository
- Fast first draft of every change
- Every edit needs fresh review
- Can weaken tests to reach a green build
- Reports success the evidence does not support
Recipes alone
Deterministic rewrites only
- Same edit every time, reviewed once
- Stops where no recipe exists
- Leaves the hard residue to engineers
- Strong on the JVM, thinner on .NET Framework
Recipes, then agent, behind a harness
What we run
- Recipes take the mechanical layer first
- The agent works only on the residue
- Tests and their configuration are out of its reach
- Old and new outputs are compared on real inputs
How to prove the upgraded system behaves the same
Parity is proven with evidence the agent cannot edit. The method has a fixed order, because each step depends on the one before it.
- Lock behaviorCharacterization and approval tests record what the system does today, including its quirks. Generated tests are kept only if they build, pass reliably and add coverage.Every critical path has a recorded output, and mutation testing shows the suite catches change.
- Mechanical passDeterministic recipes make the framework, JDK, package and namespace changes in reviewed, repeatable commits.The recorded outputs still match.
- The residueThe agent works through what the recipes could not do, on a branch, with no write access to tests or their configuration.No test deleted or skipped, no fall in test count or coverage, every diff reviewed.
- Diff on real inputsOld and new builds receive the same production requests. Read paths are compared side by side; writes are replayed into an isolated copy.Each mismatch is classed as a regression to fix or an intended change, in writing.
- Cut over in slicesA proxy sends one route or one slice of traffic at a time to the new build, so rollback is a routing change.Canary metrics hold before the next slice moves.
Language models are genuinely useful in the first step. Meta's TestGen-LLM kept a generated test only if it built, passed reliably and added coverage, and engineers accepted 73% of the tests that survived those filters.35 GitHub's Scientist library shows the fourth step at scale: GitHub ran its old and new permission checks side by side in production and fixed both until they agreed.36 Keep one caution in view. A characterization suite records legacy bugs as faithfully as legacy features, so every diff needs a recorded decision about which one it is.
# Runs on every agent-authored pull request. The agent cannot change this file.
base_tests=$(git show origin/main:test-count.txt)
head_tests=$(./scripts/count-tests.sh)
[ "$head_tests" -ge "$base_tests" ] || { echo "Test count fell"; exit 1; }
git diff --name-only origin/main -- 'tests/**' 'src/test/**' | grep -q . \
&& { echo "Tests changed: needs a named reviewer"; exit 1; }
./scripts/coverage-check.sh --no-drop
./scripts/parity-diff.sh --baseline recorded/ --fail-on-unclassifiedWhen to run it in-house and when to bring in a partner
The tools ship to in-house teams by default, and for a lot of work that is the right place for them. Their built-in proof is the build plus whatever tests already exist. What they do not supply is the parity harness, the judgement about the parts with no equivalent, or the review capacity, which Google found to be the binding constraint in its own migrations.15
| Your situation | Usually best run | Why |
|---|---|---|
| .NET 8 or 9 to 10, or a JDK bump on a well-tested service | In-house | A retarget plus a regression pass, and your team knows the edge cases |
| Spring Boot 2.7 or 3.x to 4.1 with good test coverage | In-house, with recipes | Most of the change is mechanical and well charted |
| Little automated test coverage | With a partner | The harness has to be built before any tool runs |
| Web Forms, WCF beyond CoreWCF, Workflow Foundation, Remoting, EDMX | With a partner | No tool supplies the target design |
| Java EE application server to Jakarta EE or Spring | With a partner | Agents pass behavioral tests on these moves a small fraction of the time |
| A fixed compliance or end-of-support date and a fully booked team | With a partner | Capacity and review, not code generation, set the date |
If you bring in a partner, judge them on proof. Ask for written parity criteria, the pipeline gates, mutation scores for any generated test suite, a diff report before each cutover, and handover of the whole harness, so your team can keep verifying after the partner leaves. Our guide to choosing an AI development company covers the rest of that conversation, and the same proof discipline applied to mainframes is in AI for COBOL modernization.
Questions to settle before the first agent commit
- Which applications are on .NET 8 or 9, and which already have tests that cover their critical paths?
- Which components have no modern equivalent, and who owns the target design for each?
- Which changes will recipes make, and which are left to the agent?
- Can the agent edit tests, build configuration or coverage settings? Where is that enforced?
- How will old and new outputs be compared on real inputs, and who signs off each difference?
- How is a route or a slice of traffic moved back if the canary fails?
The upgrade you are forced into this year will not be the last one. Spring Boot 4.0 loses free support at the end of 2026, Temurin 17 in October 2027 and .NET 10 in November 2028. A team that builds the characterization suites, the traffic comparator and the pipeline gates once can take each of those with a fraction of the effort, whichever tool is best at the time.
This is how we run application modernization. We lock behavior before we change code, use deterministic recipes for the mechanical layer and AI agents for the residue, and hand over the parity harness with the upgraded system, so your team can prove every release that follows.
Questions leaders ask
Can AI fully automate a .NET Framework to .NET 10 migration?
Not for most production applications. AI agents handle project conversion, package updates and much of the scaffolding, including first drafts of Web Forms to Blazor and WCF to CoreWCF. System.Web-heavy session and authentication code, WCF features outside CoreWCF's subset, Workflow Foundation, Remoting and EDMX models still need engineers to design the target, and no independent study yet measures how much of a Framework port any tool automates.1722
What happens to .NET 8 applications after November 10, 2026?
They keep running. Microsoft stops shipping security fixes and servicing updates for .NET 8 and .NET 9 on that date, so new vulnerabilities stay open, and security reviews start flagging the runtime. Microsoft recommends moving to .NET 10, which is supported to November 14, 2028.12
Should we upgrade from .NET 8 straight to .NET 10?
Yes. .NET 9 ends support on the same day as .NET 8, so it offers no extra time. Change the target framework to net10.0, work through the documented breaking changes, and run a full regression pass, since several of the changes alter behavior without a compiler error.240
Is OpenRewrite or an AI agent better for a Spring Boot 3 or 4 upgrade?
Use both, in order. Recipe engines such as OpenRewrite make the namespace, property, dependency and test framework changes the same way every time, which keeps review cheap. An AI agent is useful for what remains, such as code with no recipe and build failures after the recipes run. Gartner's research supports this order, because deterministic changes cost less to verify.8
How do you prove an AI-upgraded application behaves the same as before?
Record the current behavior first with characterization and approval tests, keep those tests out of the agent's reach, then send the same real requests to the old and new builds and compare the outputs. Every difference is classed as a regression or an intended change before traffic moves, one route at a time, behind a proxy that makes rollback a routing change.
Does AI-generated migration code introduce security vulnerabilities?
It can. Veracode's 2026 testing found generated code passing security checks only 56% of the time on average, and Java was the weakest language. Run static analysis and dependency scanning as a merge gate on every agent-written change, and prefer deterministic recipes where they exist.3332
Sources
- .NET and .NET Core Support PolicyMicrosoft
- .NET 8 and .NET 9 end of supportMicrosoft .NET Blog, June 29, 2026
- .NET Framework official support policyMicrosoft
- Spring Bootendoflife.date
- Spring Boot 4.0.0 available nowSpring, November 20, 2025
- Eclipse Temurinendoflife.date
- Devsu Recognized as a Representative Vendor in 2026 Gartner Market Guide for AI-Augmented Code Modernization ToolsPRWeb, February 2026, quoting Gartner
- Moderne named a Leader in the 2026 Gartner Magic Quadrant for AI-Augmented Code Modernization ToolsModerne, August 2026, quoting Gartner Critical Capabilities
- Microsoft named a Leader in the 2026 Gartner Magic Quadrant for AI-Augmented Code Modernization ToolsMicrosoft Azure Blog, August 2026
- FreshBrew: A Benchmark for Evaluating AI Agents on Java Code MigrationarXiv 2510.04852, October 2025
- MigrationBench: Repository-Level Code Migration Benchmark from Java 8arXiv 2505.09569, revised May 2026
- ScarfBench: a benchmark for cross-framework Java application migrationarXiv 2605.06754, May 2026
- Converted, Not EquivalentarXiv 2605.29054, May 2026
- Recent Frontier Models Are Reward HackingMETR, June 5, 2025
- How is Google using AI for internal code migrations?arXiv 2501.06972, January 2025
- Migrating Code At Scale With LLMs At GooglearXiv 2504.09691, April 2025
- Migrate from ASP.NET Framework to ASP.NET CoreMicrosoft Learn
- .NET Framework technologies unavailable on .NETMicrosoft Learn
- Why migrate WCF to ASP.NET Core gRPCMicrosoft Learn
- Port from EF6 to EF CoreMicrosoft Learn
- Overview of the .NET Upgrade AssistantMicrosoft Learn
- Scenarios and skills for upgrading .NET appsMicrosoft Learn, September 2026
- Transforming .NET applicationsAWS Transform User Guide
- Copilot .NET modernization tool a huge downgrade, devs sayDevClass, November 20, 2025
- Modernize .NET repos at scale with the AWS Transform web experienceAWS .NET on AWS Blog, September 2026
- Spring Boot 3.0 Migration GuideSpring Boot project wiki
- JEP 403: Strongly Encapsulate JDK InternalsOpenJDK
- Spring Framework 6.0 Release NotesSpring Framework project wiki
- Hibernate ORM 6.0 Migration GuideHibernate
- Behavior changes when comparing strings on .NET 5+Microsoft Learn
- BinaryFormatter removed from .NET 9Microsoft Learn
- Spring 2026 GenAI Code Security UpdateVeracode, March 2026
- 2026 GenAI Code Security ReportVeracode, July 2026
- Announcing the 2025 DORA ReportGoogle Cloud, 2025
- Automated Unit Test Improvement using Large Language Models at MetaarXiv 2402.09171, February 2024
- Scientist: Measure Twice, Cut Over OnceGitHub Blog, February 3, 2016
- Strangler Fig ApplicationMartin Fowler
- Get started with incremental ASP.NET to ASP.NET Core migrationMicrosoft Learn
- Mainframe exit plans at risk as leaders overestimate AI, Gartner saysCIO Dive, June 2026
- Breaking changes in .NET 10Microsoft Learn
- Amazon Q Developer just reached a $260 million dollar milestoneAWS DevOps Blog, August 2024
Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on October 3, 2026. No client data appears in our insights.