Many organizations have spent the last year addressing the rise of shadow AI, where employees use unapproved AI tools without oversight from IT or security teams. While this remains a significant concern, a new trend is emerging that presents an even greater challenge: vibe coding.
Vibe coding refers to creating applications simply by describing what functions you’d like for them to have in plain language, using AI-powered development platforms. These can generate code, host applications, and provide a public web link with no technical knowledge whatsoever required from the user.
What once required a developer can now be accomplished in minutes by almost anyone. A department manager can create a project tracking application. A finance team member can build a vendor request portal. A marketing team can launch a campaign tracker.
In many cases, these applications can be built and deployed in less than an hour without any involvement from IT. While this level of accessibility is impressive, it also introduces risks that many users may not recognize until it is too late.
Why Vibe Coding Is Different
Modern AI app builders make development easier than ever by:
- Generating code automatically
- Hosting applications online
- Creating public web links
- Managing deployment and updates
The problem is that many users focus on functionality, not security. If authentication, access controls, or privacy settings aren’t included in the prompt, they may not be included in the final application.
The Risks of Vibe Coding
1. Security Isn’t Built In
The biggest risk isn’t the application itself. It’s how company data is handled.
Without IT involvement, organizations may have little visibility into:
- Where data is stored
- Who can access it
- Whether security controls are in place
Although this is the case, even the platforms themselves can introduce risk. Security researchers have already identified vulnerabilities in some AI development tools, highlighting the importance of proper oversight before deploying applications that contain business or customer information.
2. Responsibility Still Falls on the Organization
Many AI platforms promote ease of use and built-in security features. However, organizations are still responsible for how their applications are configured and how data is protected.
Before adopting any platform, it’s important to understand:
- Where data is stored
- What security controls are available
- Who is responsible if something goes wrong
Convenience should never replace due diligence.
3. Governance Is Struggling to Keep Up
AI tools are evolving faster than most organizations can create policies around them.
While banning these tools may seem like the safest option, it often leads employees to seek unapproved alternatives. A better approach is to establish clear guidelines, educate users, and involve IT teams in the process.
How Organizations Should Respond
A few simple steps can help reduce risk:
- Review cyber insurance coverage related to AI-generated applications.
- Educate leadership teams on both the opportunities and risks of these tools.
- Create policies around approved AI platforms and acceptable data usage.
- Regularly ask employees whether they have built or deployed AI-generated applications.
Open conversations often reveal risks that traditional security tools cannot detect.
Final Thoughts
Vibe coding is making application development more accessible than ever, allowing employees to solve problems and improve productivity without technical expertise. However, with that accessibility comes responsibility. As these tools continue to gain popularity, organizations must ensure innovation is supported by the right security controls, policies, and oversight.
Key Takeaways
- Vibe coding allows employees to build applications using simple prompts.
- AI-powered app builders can improve productivity, but they can also create security blind spots.
- Missing authentication, poor data handling, and lack of oversight are among the most common risks.
- Organizations remain responsible for protecting their data, regardless of the platform being used.
- Clear policies, user education, and IT involvement are essential for balancing innovation with security.
AI is evolving quickly, and so are the risks. Connect with our experts from coast to coast to assess your AI readiness, strengthen your security posture, and confidently embrace emerging technologies: https://microage.ca/contact-us/

Google’s Chrome 68 Web Browser Will Flag All HTTP Sites “Not Secure”
In Google's eyes, websites using HTTP are not secure, so it is marking them as such, starting in the Chrome 68 web browser. Find out why Google is taking this stance.
When It Comes to Diagnostic Data, Windows 10 Is a Chatterbox
By default, Windows 10 sends a large amount of diagnostic data to Microsoft. If you are concerned about the types of data being sent, you might want to take advantage of the Diagnostic Data Viewer. Learn how to use this tool and what you can do if you do not like what you see.
Find Out What Data Microsoft Is Saving about You
If you use Windows 10 and have a Microsoft account, you can easily see the types of data that Microsoft has stored about you. Learn where you can find this data and how to delete it.
Why Using Gmail’s Confidential Mode Is Not a Good Idea for Businesses
As part of Gmail's redesign in 2018, Google introduced the Confidential Mode to protect sensitive information sent by email. Learn how it works and why you should avoid using it in your business.
What You Need to Know about Google Tracking Your Location
Google is tracking the whereabouts of billions of its customers, even when they tell the tech giant not to. Here is what you need to know about this practice, including how to minimize the amount of data being stored about you.