Site navigation

Comment| Vibe Coding Blurs the Line Between Innovation and Exposure

Murali Sastry

,

In a contributed piece for DIGIT, Skillsoft’s CTO, Murali Sastry, spotlights the rapid rise of vibe coding, with tools like GitHub Copilot and Claude Code accelerating innovation and slashing time-to-market, but raising questions around code security.

What began as a tweet by Andrej Karpathy, co-founder of OpenAI, has rapidly evolved into one of the defining trends of 2025. Vibe coding is reshaping how developers build and deploy software, blending creativity, speed, and experimentation in a way that challenges traditional development norms.

Vibe coding refers to a new style of AI-assisted software development, where developers guide large language models (LLMs), such as GitHub, Copilot and Claude Code, to generate, test and refine code. Rather than writing endless lines of code, developers can now prompt AI tools to build the entire workflow, accelerating innovation and lowering the barrier to entry.

It has quickly become the go-to approach for leading technology companies. Microsoft’s CEO recently confirmed that up to 30% of the company’s code is AI-generated. But while the benefits of efficiency gains and democratisation of coding are clear, emerging risks are prompting IT and security leaders to ask tough questions.

With more software being deployed without traditional review, concerns about intellectual property and expanded attack surfaces are mounting.

As the line between innovation and exposure becomes blurred, security leaders must consider whether vibe coding is the next leap forward or the next major vulnerability.

Why businesses are embracing vibe coding

Unlike traditional workflows, vibe coding enables developers to collaborate with agentic AI to plan and execute tasks, automating routine processes and even generating full features. By shifting away from manual coding, developers can focus on problem-solving and tackling more complex problems, while AI handles the execution.

This hybrid approach to software development unlocks a range of opportunities for developers and their wider organisation.

One of the most immediate advantages is accelerated time-to-market. Agentic AI tools streamline development by automating repetitive and time-consuming tasks such as debugging, boilerplate code generation, and test creation. This allows developers to redirect their focus toward solving complex challenges and delivering value more quickly.

Another key benefit is an enhanced capacity for innovation. In vibe coding workflows, AI acts as a creative collaborator, enabling developers to outline high-level ideas or goals while the AI refines, enhances, or even proposes novel solutions that may not have been previously considered.

This synergy encourages a more experimental approach to problem-solving, supporting rapid prototyping and enabling organisations to test market hypotheses faster and respond more effectively to competitive pressures.

Vibe coding also helps bridge the gap between technical and non-technical teams. By simplifying complex tasks and making workflows more intuitive, agentic AI empowers designers, product managers, and business leaders to actively participate in the development process. This shared language and accessibility foster stronger alignment, accelerate feedback loops, and lead to more user-centric outcomes.

Finally, vibe coding supports greater agility in responding to change. Agentic AI operates dynamically, learning and adapting as projects evolve. Its real-time responsiveness enables teams to pivot quickly in response to customer feedback or market shifts.

To fully harness this flexibility, organisations must invest in ongoing training programmes that equip teams with the latest AI capabilities and best practices, ensuring they remain agile, informed, and ahead of the curve.

The hidden risks behind the rapid rise

While vibe coding offers speed and innovation, it also introduces new, unprecedented risks. Research from Veracode found that 45% of AI-generated code failed security tests, with many samples introducing OWASP Top 10 vulnerabilities into production systems.

For security leaders and development executives weighing the pros and cons of vibe coding on their organisation’s security, here are five critical risk areas that demand urgent attention:

  • Intellectual Property Uncertainty

When AI generates code based on vast and often opaque training datasets, determining ownership and provenance becomes challenging. This ambiguity can lead to licensing conflicts and intellectual property disputes.

To mitigate these risks, organisations need well-defined policies that assess and manage the legal implications of deploying AI-generated code in production environments

  • Hidden Vulnerabilities in Code

AI-generated code can appear syntactically correct while concealing logic flaws or security gaps, especially when manual reviews are skipped due to tight delivery timelines. Maintaining consistent human oversight and implementing rigorous testing protocols are essential to ensure code integrity and security.

  • Increased Exposure Through Rapid Deployment

The speed of AI-assisted development can outpace traditional security checks, expanding the attack surface. As more code is pushed into production, undetected flaws increase the risk of exploitation. Security must be embedded into every stage of the development lifecycle, with governance frameworks that prioritise resilience over velocity.

  • Risks of Data Misuse and Leakage

AI systems often require broad access to internal repositories to function effectively. Without strict controls, this can result in unintended data leaks or compliance violations. Organisations must implement robust ethical guidelines, access controls, and accountability mechanisms to safeguard sensitive information and ensure responsible AI use.

  • Overreliance on AI Outputs

The convenience of AI can lead teams to rely too heavily on its outputs, bypassing essential validation steps. This blind trust can have serious consequences if flawed code is deployed unchecked. Developers must remain actively engaged, applying their domain expertise and critical thinking to maintain quality and accountability throughout the process.

Preparing your organisation for AI-dominant development

To ensure vibe coding delivers value without compromising security or accountability, organisations must adopt a comprehensive governance strategy that addresses both technical and organisational risks.

A key component of this strategy is the implementation of human-led validation checkpoints. Before any AI-generated code reaches production, it should undergo a thorough review by experienced developers, with a particular focus on identifying injection vulnerabilities, authentication weaknesses, and potential data exposure risks.

In addition, organisations should develop a risk-based classification framework for AI-generated code. By categorising outputs according to their potential impact and sensitivity, teams can apply the appropriate level of oversight and allocate resources more effectively.


Recommended reading


Real-time monitoring and traceability are also essential. Automated systems should continuously track AI contributions, flag emerging patterns of vulnerabilities, and maintain detailed audit logs to support accountability and incident response.

At the leadership level, executive ownership of AI risk must be clearly defined. Senior leaders should be responsible for integrating AI governance into existing cybersecurity frameworks and ensuring regular reporting to the board on emerging risks and mitigation efforts.

Finally, ongoing education and certification for developers are critical. Teams must be trained not only in the secure use of AI tools, but also in the legal and ethical implications of AI-generated code. This includes mastering prompt engineering techniques and understanding how to apply human judgment alongside machine intelligence.

Future-proofing starts today

With AI-generated code soon expected to make up the majority of code by 2030, organisations must act now to establish robust governance frameworks. Staying competitive and secure in this new landscape will depend not just on adopting AI tools but on using them responsibly.

The true advantage will belong to those who invest early in the infrastructure, training, and cultural alignment needed to balance rapid innovation with rigorous security.

Murali Sastry

CTO at Skillsoft

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data