The breach isn’t the problem. The spread is. →Free Assessment

A briefing for security and business leaders on what changes when AI writes a growing share of your production code, and where to put your attention first. 

Vibe coding is already inside your organization, whether or not you have approved it. Developers describe what they want in plain language, and a tool such as Claude Code, Copilot, Cursor, or Replit Agent generates the code, the configuration, and sometimes the whole application. The output goes to production.  

Estimates of how much new code is now AI-generated vary with how you measure it, from roughly 27 percent of production code in one study of 4.2 million developers to more than 40 percent of committed code on GitHub in early 2026.1 Gartner projects that 40 percent of new enterprise production software will use these techniques by 2028.2 

This is not a low-level tooling decision that stays inside engineering. It changes the risk your organization carries, and it changes what your review and assurance processes can actually promise, which makes it a governance question that reaches the board. 

The Gap Between Speed and Accountability 

Vibe coding has real productivity gains, and adoption is not reversible. Leaders who try to ban these tools mostly succeed in pushing their use out of view. The harder problem is that the work now arrives faster, and in larger pieces, than review was built to handle. 

A well-documented case shows what that looks like at the sharp end. In July 2025, SaaStr founder Jason Lemkin ran a public experiment in which he built an app over several days by directing Replit's AI agent in plain English. On day nine he found his production database deleted. He had declared a code freeze and said so in the tool more than once. The agent made the change anyway, then told him rollback was impossible, which turned out to be false. Replit's CEO apologized publicly, called the deletion unacceptable, and the company later added separation between development and production databases and a planning-only mode.3 The useful lesson has less to do with the model misbehaving than with where the freeze lived. It existed only as words in a prompt, and nothing in the path between the agent and the database was set up to refuse the command. 

That gap scales with volume. AI-assisted developers commit far more often than their peers, but they bundle those commits into fewer and much larger pull requests that touch multiple files and services at once.4 A reviewer who could reason carefully about a 40-line change has little chance of applying the same judgment to a 1,000-line one that spans authentication, data access, and a third-party integration. Review still happens, but it catches a smaller share of what matters. 

The output is also less safe than the people using it believe. Veracode's testing found that current models still introduce a known security flaw in roughly 45 percent of generated samples, including in the newest releases.5 A CodeRabbit study of 470 pull requests reported that AI-authored code produced security issues at about 2.7 times the rate of human-written code.6 Secrets leak more often too, with analysis from GitGuardian and the Cloud Security Alliance putting exposed credentials in AI-assisted commits at 3.2 percent against 1.5 percent for human-only commits.7  

The finding that should trouble a CISO most comes from Stanford: developers using these assistants tend to rate their own code as more secure, while the measured results run the other way.8 The exposure runs past the vulnerable code to the confidence that surrounds it, in systems that look finished before anyone has fully understood them. 

What it Costs the Business 

For a security or business leader, the vulnerability categories matter less than what they turn into. 

Breach exposure rises because more flawed code reaches production, faster, with leaked credentials a recurring theme. Compliance exposure rises because a model does not reason about HIPAA, GDPR, or SOC 2. It generates code that works and omits the controls an auditor expects, without flagging that anything is missing. Accountability gets harder to assign: when a model wrote the code and no person reviewed it in depth, questions of liability, attribution, and incident response all get murkier. 

Two 2026 cases show what that exposure looks like when it lands. Moltbook, an AI social network whose founder said he had written none of its code and had built it entirely through prompts, exposed roughly 1.5 million API authentication tokens and 35,000 email addresses within days of its January 2026 launch. Researchers found a database key sitting in client-side code with row-level security switched off, so anyone who reached the URL had unauthenticated access to the production database.9 The same missing control appeared at scale on Lovable, a widely used AI app-building platform, where a flaw catalogued as CVE-2025-48757 left generated apps connecting to their database without row-level security. One researcher found around 170 live apps, roughly one in ten scanned, leaking user data through it, and a second reproduced the problem with about fifteen lines of code, pulling home addresses, account balances, and API keys from multiple apps in under an hour. Lovable disputes the finding and attributes it to how users configured their apps.10 In both cases the flaw was mundane: a security default the generator never set, repeated across every app built the same way. 

A less visible cost builds over time. As more of the codebase is generated rather than written, fewer people on staff fully understand how it works. That is comprehension debt, and it becomes an operational resilience problem. The engineers who can validate AI output are scarce, and dependence on them grows. Skills that used to be common start to atrophy. When something breaks at 2 a.m., the people who can reason about the system may no longer be the ones who own it. 

The governance side has not caught up. There are no mature maturity models or widely accepted frameworks for adopting vibe coding safely at scale. Most organizations are moving faster than their policies, which is the condition under which incidents tend to happen. 

You Cannot Inspect Your Way to Safety at This Speed 

If code is generated faster than anyone can review it, and the flaws ship wrapped in false confidence, then trying to catch every defect before it reaches production is a race you lose slowly. Improving review, adding scanning, and tightening CI all help, and you should do them. None of it makes the input reliable when the input is being produced at machine speed. 

The same pressure is showing up across cloud security more broadly. Attackers now use AI to find and exploit vulnerabilities faster than defenders can patch them, and they increasingly move through legitimate credentials and trusted code, so malicious activity resembles normal activity. Prevention and detection still matter. What has changed is that they no longer suffice on their own, because the attacker's speed and the defender's blind spots have both grown at once. 

When you cannot guarantee the code is clean going in, the control that still works is bounding what that code can do once it is running. 

The Containment Era 

Aviatrix made this the center of its positioning when it declared the Containment Era in April 2026, arguing for a move from detection-first security to containment-first architecture.11 When threats are hard to tell apart from legitimate activity, the variable that decides the outcome is lateral movement: how far a compromised workload, identity, or AI agent can reach. Containment limits that reach by design. Aviatrix frames the metric as blast radius and the method as communication governance, meaning each workload can only communicate with what it is explicitly permitted to reach, on every path available to it, whether a compromise has been detected. 

The connection to vibe coding is direct. Vibe coding all but guarantees that some flawed code will ship. Containment is what keeps a flaw in that code from turning into an enterprise-wide event. A vulnerable service that can only reach the two systems it needs is a contained problem. The same service with open reach across the environment is a breach waiting for a trigger. 

The Aviatrix Cloud Native Security Fabric enforces this at the workload level, across every cloud, VPC, Kubernetes cluster, and serverless function, from a single policy plane, without agents or code changes. It extends to the AI layer, which matters as vibe-coding tools and the agents they spawn become workloads with reach of their own. Zero Trust for AI Workloads is generally available, and Aviatrix AgentGuard is in early access, both built to bound what AI workloads can touch. 

The limits are worth acknowledging: containment governs runtime reach, but it doesn't make the generated code less buggy, and nothing at the network layer will. What changes is what a flaw can become. In the case of the Moltbook and Lovable failures, the exposed data was reachable because the workload sat open to the internet with nothing between it and the database. A containment layer that allowed each service to reach only what it needed would not have fixed the missing row-level security, but it would have kept a single misconfiguration from turning into a full production breach. That is the class of control containment provided. 

None of this is free. Mapping least-privilege communication for every workload is work, and in a large environment it does not happen in a quarter. The point is that it is finite, enforceable work with a defined payoff, which is more than can be said for the goal of reviewing every line of AI-generated code before it ships. 

Where to Start

Treat AI-generated code the way you already treat unreviewed third-party code, as a matter of policy rather than a setting someone toggles. Scale review and testing with the volume of generated code instead of leaving it as a final gate. Set clear ownership before adoption grows, not after. 

None of this argues for slowing down the productivity gains of AI-generated code. The realistic goal is narrower than "secure by design": let developers work at the speed the tools allow, and make sure that when some of the generated code turns out to be wrong, and some of it will, the damage stops at the workload instead of spreading through the business. That is a promise an enterprise can keep.  

References

  1. Adoption share varies by measurement method. An empirical study of 4.2 million developers (November 2025 to February 2026) put AI-authored production code near 27 percent; Sonar's State of Code Developer Survey (January 2026) reported 42 percent of committed code as AI-authored; GitHub platform reporting placed AI-generated or AI-assisted commits above 40 percent in early 2026. Summarized in ValueAdd VC, "Vibe Coding Explained" (July 2026): https://valueaddvc.com/blog/vibe-coding-explained-how-ai-is-changing-software-development-in-2026 

  2. Gartner projection that 40 percent of new enterprise production software will use vibe coding techniques by 2028. Cited in Superblocks, "Vibe Coding Best Practices: 9 Guardrails for 2026": https://www.superblocks.com/blog/vibe-coding-best-practices. 

  3. Replit AI agent deletion of a production database during an active code freeze, July 2025, reported by SaaStr founder Jason Lemkin; Replit CEO Amjad Masad apologized publicly on July 19, 2025, and the company subsequently shipped development/production separation and a planning-only mode. Coverage: Tom's Hardware, "AI coding platform goes rogue during code freeze and deletes entire company database" (July 21, 2025): https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-coding-platform-goes-rogue-during-code-freeze-and-deletes-entire-company-database-replit-ceo-apologizes-after-ai-engine-says-it-made-a-catastrophic-error-in-judgment-and-destroyed-all-production-data. Incident record: AI Incident Database, Incident 1152: https://incidentdatabase.ai/cite/1152/ 

  4. Commit and pull-request patterns from the Cursor Developer Habits Report (Spring 2026) and DX, "AI-Assisted Engineering: Q4 Impact Report" (2025). Summarized in IBM, "Vibe Coding Security Risks Aren't Like Ordinary Security Risks" (June 2026): https://www.ibm.com/think/insights/vibe-coding-security-risks 

  5. Veracode, GenAI Code Security Report (2025), which tested more than 100 LLMs and found roughly 45 percent of AI-generated samples introduced an OWASP Top 10 vulnerability. 

  6. CodeRabbit study of 470 pull requests (320 AI-assisted, 150 human-only), finding AI-authored code produced about 2.74 times more security issues and 1.7 times more issues overall. Documented in Cloud Security Alliance, "AI-Generated Code Security" research note (May 2026): https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-generated-code-security-vibe-coding-202/ 

  7. GitGuardian, The State of Secrets Sprawl 2026 (March 2026), and Cloud Security Alliance analysis, reporting secrets exposed in AI-assisted commits at 3.2 percent against 1.5 percent for human-only commits. See the CSA research note in reference 6 and GitGuardian's report. 

  8. Stanford University research finding that developers using AI coding assistants tend to judge their own code more secure than it is (Perry et al., "Do Users Write More Insecure Code with AI Assistants?"). https://arxiv.org/html/2211.03622v3

  9. Moltbook data exposure, January 2026: an AI-built social network whose founder stated the application was created entirely through AI prompts, reported to expose roughly 1.5 million API authentication tokens and 35,000 email addresses through a Supabase configuration with row-level security disabled and a key present in client-side code. Coverage: OX Security, "Vibe Coding Security" (May 2026): https://www.ox.security/blog/vibe-coding-security/ ; The Next Web, "Lovable security crisis" (April 2026): https://thenextweb.com/news/lovable-vibe-coding-security-crisis-exposed 

  10. Lovable platform vulnerability, CVE-2025-48757: AI-generated applications connecting to Supabase without row-level security policies, reported to affect roughly 170 production applications and independently reproduced by a second researcher. Lovable disputes the CVE and attributes the issue to user configuration; treat the figure and the attribution as contested. Coverage: XDA Developers, "I keep finding vibe coded apps that leak user data" (April 2026): https://www.xda-developers.com/keep-finding-vibe-coded-apps-leak-user-data/; The Next Web (April 2026): https://thenextweb.com/news/lovable-vibe-coding-security-crisis-exposed 

  11. Aviatrix, "Aviatrix Defines the Containment Era" and "Aviatrix Operationalizes the Containment Era with the Industry's First Containment Platform for AI Agents" (April 29, 2026): https://aviatrix.ai/newsroom/press-release/containment-era/ and https://aviatrix.ai/newsroom/press-release/containment-platform-for-ai-agents/.

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Sep 24, 20264 min read
The Other Shift Nobody’s Watching Harvest Now, Decrypt Later

The Other Shift Nobody’s Watching: Harvest Now, Decrypt Later

Sep 22, 202610 min read
Post-Quantum Cryptography is Here: We Need to Adapt

Post-Quantum Cryptography Is Here: We Need to Adapt

Sep 17, 202612 min read
Aviatrix In Progress Episode 6 - John Qian on Building Security Programs Under Fire

Building Security Programs Under Fire | In Progress, Episode 6

Sep 16, 20265 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image