Glitchd

Vibecoding: Faster, Cheaper, Riskier?

Season 2 Episode 1

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 7:46

Building software used to take time, money, and specialist expertise but now with Vibecoding you can simply describe an idea and have working code in minutes. 

Vibecoding is changing how startups, entrepreneurs and businesses build products. It can dramatically reduce development costs, shorten timelines and help turn ideas into reality faster than ever before.

But what happens when speed comes at the expense of understanding?

In this episode of Glitchd, we explore what vibecoding is, why it's growing so quickly, and where the risks appears.

From security vulnerabilities and governance concerns to the difference between a prototype and a production system, this episode examines the trade-offs between moving fast and building responsibly.

Whether you're a founder, business owner, developer, student or simply curious about how AI is changing software development, this episode will help you understand where vibecoding delivers value and where it can create problems.

https://skspsl.com/


SPEAKER_00

I'm Sharon, AI governance professional and founder of SKS PSL. I help businesses turn AI from theory into reality responsibly and profitably because both can happen at the same time. And they should. This is Glitched, the podcast for businesses navigating AI with speed, direction, and purpose. A new episode drops every Tuesday, and welcome to season 2. Earlier this year, one of the most respected figures in open source software built an application without writing most of the code himself. Instead, he described what he wanted in plain language, let the AI generate the code, tested the results, fixed what was broken, and continued to move. This approach now has a name. It's called vibe coding. If you're someone who doesn't know what this is, I'll explain it. It's quite a simple concept. You tell the AI what you want in plain language, it writes the code for you, and you run it. If something goes wrong, you paste the error back in and the AI suggests a fix for you and you keep going, so on and so forth. What's different is that you're not necessarily reading every line of code. In some cases, you can't explain exactly how it works if someone asks you. What you're doing is trusting the outcome because it appears to work. And this is where things get interesting. Because for a prototype it can be brilliant, but for businesses it can get complicated very, very quickly. The reason vibe coding has exploded is obvious. It removes barriers, it brings down costs. A founder with an idea can build something in hours or days instead of weeks. A small business can test a concept without hiring a development team. And someone with no formal software engineering background can turn an idea into a working product faster than ever before. And this isn't today a niche trend like it was when it first came about. In one recent startup accelerator cohort, around a quarter of companies reportedly had code bases that were almost entirely AI generated. That is a remarkable shift in a very, very short space of time. For many people, AI has moved software development from can we build this to how quickly can we build this? And this is a very exciting time to be in. However, because of this excitement, we don't look at the risks enough. Research published this year found that AI-generated code can introduce significantly more risk than code that's been written and thoroughly reviewed by experienced developers. One study found that AI-assisted code contained nearly twice the rate of serious issues compared to human written code and close to three times the rate of security vulnerabilities. Another found that a substantial proportion of AI-generated code included well-known categories of security flaws. Very, very interesting. And with many things, as I've mentioned throughout season one of this glitched podcast, when we see the risks, the answer isn't to avoid using such types of AI, in this case AI-generated code. But what we should be doing is to understand the role is playing in the process because not all AI assisted development is the same. There's a huge difference between using AI as a very fast assistant and using AI as a black box. In the former scenario, you're still reviewing the code and you're still making decisions. You're responsible for the outcome. The AI is helping you to move faster, but you're the one navigating, you're the one driving. In the latter scenario, you're running code you haven't properly reviewed because it seems to work. You don't fully understand it. And this is where vibe coding becomes a judgment call. And like most judgment calls in businesses, context matters. The person who originally popularized the term vibe coding has since spoken about using more disciplined approaches for serious projects, and this makes absolute sense. The difference between a weekend experiment and a business critical system is enormous. If an internal prototype doesn't work out, it breaks. That can be annoying. But if a customer-facing system breaks or leaks data or exposes a security vulnerability or creates a legal liability, that is a very different conversation. So where does that leave businesses? And this answer depends on what you're building. If you're testing an idea, creating an internal tool, or automating a small task, trying to figure out if something is worth investing in, vibe coding can be incredibly useful. The speed advantage is there, the ability to experiment, the reduction in cost is great. But if you're building something that handles personal, sensitive customer data, processes payments or supports critical business operations, then the standard has to be different. At that point, it seems to work, isn't enough. It just doesn't cut it. You will need testing, you will need human review, and you'll need human accountability. And you need someone who can explain what the code is doing. You can't assume or guess. So the businesses getting the most out of this AI-generated code aren't the ones avoiding it. They're using it deliberately. They understand which projects can tolerate the risks and which cannot. They know when speed matters the most and when assurance matters more. They don't confuse simple ideas or prototypes with production-ready systems. A lot of people hear the term vibe coding and assume the debate is about AI. And I don't think it is. The real question here, as with many things related to AI for businesses, is trust. How much are you willing to trust the code you didn't write, don't fully understand, and may never have properly reviewed? For a weekend project, the answer might be quite a lot. For a business critical system, I'd hope the answer is very different. Whether you're a founder trying to work out where AI generated tools fit safely into your business or further along and want a proper governance framework around how your teams build with AI, that's exactly the conversations we can have at SKS Professional Services. So head on over to SKspSL.com and get in touch. I'm Sharon, this is Glitched. I'll see you next Tuesday.