Vibe coding is the newest trend in software development: using natural language prompts to create entire apps, websites, and experiences without writing a single line of code. Think of it as “prompt-based programming” on steroids. Rather than learning how to code and then carefully planning the application architecture or logic, users simply describe what they want in plain English—and the AI does the rest. Today we explore this booming trend and its intrinsic risks.
Focus On: Vibe Coding, Too Good To Be True?
How many times we have thought “there should be an app for that” but learning how to code was too difficult? Vibe coding introduces a frictionless experience allowing anyone to create apps by simply describing them and has become quickly popular among non-developers and creators. Platforms like Lovable promise to be “the last piece of software you’ll ever need.” With just a few sentences, users can generate websites, apps, and even automations in seconds.
Vibe coding democratises software creation at scale. Just as Canva made design accessible to almost everyone, vibe coding tools turn anyone into a developer. For enterprises, this could mean:
Faster prototyping of digital products, MVPs, and experiments
Reduced dependency on overstretched engineering teams
Lower barrier to entry for employees to build their own workflows or internal tools
In the short term, this could dramatically accelerate digital transformation. Business teams can now build what they need without waiting in the IT backlog. The implications extend beyond low code applications already present across enterprises (think about Microsoft Power Platform) as vibe coding allows for complete new apps to be built.
Too good to be true?
A recent investigation revealed a critical security flaw in Lovable—a poster child of vibe coding—that left user data exposed across more than 10% of featured apps. Researchers found email addresses, API keys, and even financial data sitting unprotected across 170 applications.
The flaw wasn’t a single bug. It was systemic. Novice users were inadvertently building insecure apps, and Lovable’s platform wasn’t catching these mistakes.
The security challenge with vibe coding isn’t unique to Lovable as it stems from a deeper issue: as AI removes complexity, it also removes guardrails. Traditional coding enforces structure. Developers know to hash passwords, validate inputs, and restrict access. But vibe coding users often don’t even know those concepts exist and today’s AI is not smart enough to catch all these potential issues and correct them in the background.
In a corporate environment, transformative tools can become liabilities without proper governance. Vibe coding amplifies this challenge exponentially. The democratisation of development mirrors patterns we’ve seen before. When shadow IT emerged, enterprises initially celebrated the innovation it unleashed—until they discovered compliance gaps and security vulnerabilities hiding in departmental silos. Vibe coding threatens to repeat this pattern at a much larger scale.
At the same time, we should not dismiss this technology entirely. The competitive advantages are real: reduced time-to-market, empowered business units, and unprecedented innovation velocity. The challenge lies, as always, in balancing these benefits with maintaining security and governance standards.
What enterprises should do
Resist the hype of zero-friction development. Vibe coding is exciting, but not yet enterprise-grade. Treat early adoption as experimentation, not production deployment. Should you choose to allow it, ensure it stays compartmentalised in a sandbox and that corporate data is not part of it.
Demand secure-by-default platforms. Vendors must build tools that automatically enforce basic security practices—even if users don’t know to ask: this is fundamental to responsible innovation.
Establish internal governance. Just as shadow IT created compliance risks, shadow development now creates data exposure risks. Develop clear policies around employee development and security review processes.
Educate teams. If you’re adopting vibe coding internally, build awareness around responsible software development. Basic security literacy becomes essential when anyone can deploy applications.
We are looking at a new category of digital risk: not a malicious intent, but well-meaning innovation without guardrails.
The organisations that will thrive in this environment are those that approach vibe coding with strategic discipline: embracing its transformative potential whilst building robust frameworks for responsible deployment.
Follow me
That’s all for this week. To keep up with the latest in generative AI and its relevance to your digital transformation programs, follow me on LinkedIn or subscribe to this newsletter.
Disclaimer: The views and opinions expressed in Chronicles of Change and on my social media accounts are my own and do not necessarily reflect the official policy or position of S&P Global.