Skip to content

Vibe coding at work: from prototype to code you can put in production

Having AI write software without reading its code works for a prototype, not for production. What breaks, what the studies show, and how to keep the speed with guardrails.

By Published on 3 October 2026

Vibe coding means having AI write software by describing what you want, without reading the code it produces. The term was coined by the AI researcher Andrej Karpathy in February 2025, and the Collins dictionary made it its word of the year for 2025. For a prototype or a throwaway tool, the gain is real; for code that touches your customers or your data, review, tests and checks have to come back in.

Where it works: prototypes and throwaway tools

Karpathy himself presented it as suited to throwaway weekend projects. In a company, it is the same: a mock-up to test an idea with users, a demo, a one-off script, exploring an API. Vibe coding also lets people who do not code show precisely what they want, which saves time for the team that will build the real version.

What breaks in production

  • Security flaws. In its July 2025 report, Veracode tested more than a hundred models on eighty tasks: 45% of the code samples produced failed security tests and introduced OWASP Top 10 flaws. Its July 2026 report found an average pass rate of 56%, barely better.
  • Invented dependencies. A study presented at USENIX Security in August 2025 measured that at least 5.2% of the packages suggested by commercial models, and 21.7% for open models, did not exist. Attackers publish malicious packages under those names: this is “slopsquatting”, which CERT-FR reported as in use in its February 2026 threat summary.
  • Destructive actions. In July 2025, during a public trial, the Replit platform’s agent deleted production data during a code freeze; its CEO acknowledged this should never have been possible.
  • Secrets and licences. Unreviewed code can carry an access key or reuse licensed public code; GitHub says such matches concern under 1% of Copilot suggestions, and shows the licence when it happens.

Developers know it: according to the 2025 Stack Overflow survey, 46% distrust the accuracy of AI tools, against 33% who trust it.

Keeping the speed with guardrails

  • A specification first: what the software must do, its edge cases, what it must never do. The prototype is often a good starting point for it.
  • Tests approved by a person: AI can write them, a person checks they test what matters.
  • Human review: ANSSI and the BSI have recommended since October 2024 that generated code be checked by developers.
  • Automatic analysis in the delivery pipeline: code analysis, checking that every dependency exists and comes from a known source, scanning for secrets. That is the purpose of security built into every release.
  • Controlled package sources: lock files and an internal registry or a list of allowed sources.

Who is allowed to release to production?

Everyone can prototype, in an isolated environment with no production data. Whatever goes to production follows the same path as the rest of the code: review, tests, analysis and approval. On liability, the European directive on defective products now covers software, for products placed on the market from 9 December 2026, and the Cyber Resilience Act makes manufacturers responsible for the security of their products. Our reading of these texts: the company that ships the software answers for it, however the code was written.

From prototype to product, step by step

  • Keep the prototype as a living specification, shown to users.
  • Have a developer review and, if needed, rewrite what goes to production.
  • Add the missing tests, approved by a person.
  • Go through the full CI/CD pipeline, with its security analysis.
  • Release behind an approval, with a way back ready.

Our page Software development automation shows how AI agents take their share of the cycle with human review at every step. See also our articles on rolling out coding agents and on MCP servers, and the page Agentic AI under your control.

Frequently asked questions

Can AI-generated code go to production?

Yes, if it passes the same checks as hand-written code: review, tests, security analysis and approval before release.

Who is responsible for that code?

The company that ships it, in our reading of the European texts: they target the software’s manufacturer, however it was written. Hence the importance of keeping track of who reviewed and approved what.

Should vibe coding be banned for non-developers?

No. Give them an isolated environment, with no production data or real credentials. Their prototypes serve as a starting point for developers, but do not go to production without them.

Sources

Facts and figures checked on 3 October 2026.