You’ve probably already seen our articles discussing vibecoding (or vibe coding) and dissecting fascinating tools like Claude Code.

In case you are just joining this trend, here is some context: this phenomenon, whose term was popularized by Andrej Karpathy in February 2025, consists of generating entire codebases simply using instructions or prompts in natural language.

Basically, you describe the “vibe” or the concept of your application to the machine, and artificial intelligence takes care of building it for you.

At first glance, it seems like paradise for any entrepreneur, startup, or SME. In fact, this technology accelerates development so dramatically that you can have a Minimum Viable Product (MVP) ready in a matter of hours or days.

So much so that by late 2025, it was estimated that up to 41% of code worldwide was already being generated by artificial intelligence.

But today we want to sit down and talk to you about the fine print. Because behind this apparent technological democratization and immense initial time savings lie very real, documented, and serious problems.

The False Illusion: When AI Just Wants It to “Work”

The main appeal of vibecoding is that it puts app creation within reach of anyone, but that very virtue is its greatest Achilles’ heel, as it exponentially multiplies vulnerabilities. Why does this happen?

It’s simple: artificial intelligence is designed to please you and prioritizes making the application work visually and quickly, without caring in the slightest whether the internal architecture is an absolute disaster from a security standpoint.

If we look at the most recent and concrete data from 2025 and 2026, the picture is downright alarming:

  • Applications full of holes: In March 2026, the firm Escape.tech conducted a scan of more than 5,600 public applications built with vibecoding platforms. The result? They discovered more than 2,000 high-impact vulnerabilities.

  • Secrets handed out on a silver platter: In that same scan, more than 400 exposed secrets were found in plain sight, including API keys and critical database credentials.

  • AI-generated code fails more often: In December 2025, CodeRabbit analyzed hundreds of projects, and its conclusions were unequivocal: AI-generated code produces 1.7 times more issues than code written by a human. Security vulnerabilities are up to 2.74 times more frequent, and logic errors surge by 75%.

  • Textbook vulnerabilities: According to an industry report, 45% of code generated by major language models contains classic, well-known vulnerabilities, such as code injection or broken authentication.

The Real Case of Enrichlead: From Zero to One Hundred… to Permanent Shutdown

Sometimes, the best way to understand a technological risk is to watch it explode in someone else’s hands. It is very common to find cases where novice developers embed keys directly into code, but the most illustrative example is the startup Enrichlead.

The founding team of this company decided to bypass software engineers entirely and bet on generating 100% of their code using Cursor AI. It was a radical project: zero hand-written code.

They managed to launch the platform at record speed, but just days after the big launch, they realized the application suffered from amateur flaws. These security holes allowed unauthorized access to paid features and, even worse, let anyone alter vital system data.

The situation became so unsustainable and the reputational damage so severe that the founder was forced to shut down the company permanently.

The “Productivity Tax” and the Maintenance Nightmare

Even if you manage to dodge security issues on launch day, vibecoding awaits you with another medium-term trap: the maintenance nightmare.

It is common for this type of code to work flawlessly in controlled demos, only to break down completely when deployed to actual production, facing real users or traffic spikes.

Since the code wasn’t written step by step, a phenomenon that experts call the “comprehension gap” emerges. Developers do not fully understand what the AI has generated. This makes basic tasks—such as fixing a bug, applying updates, or responding quickly to server downtime—exceptionally difficult.

Compounding this is what is now known as the “productivity tax.” According to a massive 2025 survey, 66% of developers admit that they waste an enormous amount of time fixing code that the AI left “almost correct.”

And be very cautious about trying to fix it by asking the machine for more changes: each time you modify code iteratively with AI, vulnerabilities can increase by up to 37% after just a few iterations.

GDPR and Governance: An Unacceptable Risk for Your Business

If you own a business in Spain or manage data from European clients, you know that regulatory compliance (such as GDPR) is not a suggestion—it is a strict legal obligation.

The main problem is that artificial intelligence completely ignores your industry context. It doesn’t know whether you are building software for a dental clinic or a shoe store, so it generates applications that, by default, fail to comply with privacy regulations.

In the massive study mentioned earlier, researchers discovered 175 alarming cases where applications exposed sensitive personal data.

We are talking about medical records, bank accounts, email addresses, and phone numbers left floating on the internet at the mercy of cybercriminals. At the corporate level, this is already taking its toll: 1 out of 5 Chief Information Security Officers (CISOs) has already suffered serious incidents due to AI-generated code.

Prototyping Yes, But Always with a Safety Net

We don’t want to be party poopers or slow down innovation. Vibecoding is undeniably a brutally powerful tool if your goal is to build rapid prototypes, validate a business idea, or gain speed in early stages.

However, relying on it to launch end products into production is stepping onto a tightrope without a safety net.

Deploying an app without human security guardrails, without thorough code reviews by professionals, and without clear strategies is building a mountain of technical debt.

Many companies are already discovering that all the time and money they thought they saved initially ends up costing them dearly when the application fails in front of their customers.

If you have an idea in mind or need a solid digital solution for your business, leverage new technologies—absolutely. But always ensure you rely on experts who understand the real architecture of what is being built. Your peace of mind and the security of your customers’ data are worth far more than a temporary cost cut.

This post is also available in: Español Français Русский Italiano