Vibe coding – which sees developers using AI tools such as Microsoft’s Copilot or OpenAI’s ChatGPT to generate code – is not a new concept, but fears about its risks are ramping up.
AI is certainly on the agenda after it emerged OpenAI’s frontier models were responsible for the hack of Hugging Face in July.
And the figures surrounding vide coding practices are concerning. Organisations are knowingly shipping vulnerable code, according to new research from Checkmarx, which reveals that 75% of firms admit to frequently or sometimes deploying code they are aware is vulnerable.
It comes after UK National Cyber Security Centre (NCSC) CEO Richard Horne called on security professionals at RSA Conference 2026 to harness the growth of vibe coding, as a chance to make software more secure, provided safeguards are built in from the start.
While some attendees at RSA were cynical about the breadth of AI’s capabilities, they conceded that vibe coding’s explosion in popularity is making its mark on security teams and in boardrooms around the world.
As the area becomes part of day-to-day business, what are the risks, and how can firms use the practice safely?
Vibe Coding Benefits
Despite the risks, vibe coding offers substantial benefits. “Tasks that once took hours can be delivered in minutes, devs can prototype faster, junior team members can become productive sooner, and non-developers can write working scripts without formal training,” says Tracey Hannan-Jones, consulting director in information security, UBDS Digital.
However, the technology itself is not the problem: “It’s what happens when the code goes to production without adequate scrutiny,” Hannan-Jones warns.
Indeed, with vibe coding, the risk is that speed can create “a false sense of confidence,” says Tristan Shortland, CTO Infinity Group. “Just because code works, doesn't mean it's secure. Organisations adopting AI-assisted development often underestimate the need for security review, governance and testing, creating a risk that vulnerabilities are introduced at scale and pushed into production faster than before.”
Fay Sears, head of information security at Semble, agrees. Without secure coding practices, organisations can run the risk of “exposing their systems and data to more vulnerabilities,” she warns.
Specific Risks
The risks are specific and no longer theoretical. “When developers use AI to generate code, the output reflects patterns learned from vast repositories of publicly available code – including code with known vulnerabilities," says Hannan-Jones.
The results can include injection flaws that expose databases to manipulation, secrets and credentials embedded directly in source files, as well as logic errors that bypass intended access controls, she says. Another unwanted result can be insecure third-party dependencies pulled in without review, and prompt injection vulnerabilities, where malicious input can “manipulate the AI layer itself,” she warns.
The most common issues Shortland sees are insecure authentication, excessive permissions, exposed APIs and poorly validated user inputs. “AI tools are trained to generate functional code – but not necessarily secure code. So, developers can end up inheriting vulnerabilities without realising it.”
One of the biggest risks is assuming AI will produce secure outputs by default, according to Sears. “If you prompt a vibe coding platform to build something, there needs to be a standardisation of consistency that creates the secure layers. That’s where these vibe coding companies should offer prompts or cautions to ensure users are vigilant in their approach.”
Another challenge is that AI-generated applications are built on models that are constantly evolving, says Sears. “A tool that behaves one way today may behave differently tomorrow as models are updated, so organisations shouldn't build business-critical processes that leverage AI without proper validation and ongoing review. By its nature, AI is non-deterministic, meaning organisations can't assume a vibe code tool will produce the same output every time.”
Evolving Issue
AI enables organisations to write significantly more code. As adoption grows, this means security teams will be responsible for governing an increasingly large volume of AI-generated software and ensuring it meets the same security standards as traditionally developed applications, says Shortland.
Looking ahead, Shortland predicts AI will become a permanent part of the software development lifecycle, making secure-by-design principles, automated security testing and AI governance frameworks essential.
Sears thinks the conversation surrounding vibe coding has “shifted significantly” over the past year. “Today we're talking about agentic workflows, persistent identities and AI dramatically increasing both the speed and complexity of cyber-attacks.”
Managing Vibe Coding Risk
The risk is real, so it’s important to take steps to minimise the threat. Experts are largely against an outright ban, since many developers are already vibe coding.
Ayala Maurer-Prager, managing director in the cybersecurity practice at FTI Consulting, thinks the smart move is making secure adoption “the path of least resistance.”
She suggests having clear policies on approved tools, outlining what data can and can’t be shared with them, and where “human sign-off is simply non-negotiable.”
CISOs shouldn't be trying to prevent developers from using AI, but they should be enabling them to use it safely, Shortland advises. “That starts with clear policies on approved AI tools, protecting sensitive data within prompts and ensuring all AI-generated code is subject to the same security reviews, testing and governance controls as any other software. The goal should be faster development and stronger security, not a trade-off between the two.”
But policy-based guardrails and technology “can only do half the job,” Maurer-Prager, says. “Developers also need the training, permission and confidence to challenge AI output, rather than trusting it because it looks or sounds authoritative.”
To manage the risk, CISOs should understand what they are using, says Amanda Brock, CEO at OpenUK “The good practices of the better open source community creators and distributors are becoming more important than ever. Nobody should be using codebases they don’t have an adequate level of transparency on, and this needs to apply equally to the black box of proprietary code and to open source. “
Practically all companies should have a software policy in place, requiring a software bill of materials, says Brock. She advocates “practices that work for the engineering teams and enable traceability and transparency to engender trust.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist