
Big Tech companies are now generating up to 90% of new code with AI. Software development is set to become the single biggest AI use case of 2026. And yet, in one December 2025 test, five separate AI coding agents were each asked to build the same type of feature — and all five introduced the exact same critical security flaw. Every single one.
That's the paradox at the center of vibe coding: it's making developers dramatically faster, and it's quietly making applications more vulnerable, often at the same time, in the same commit.
What Is Vibe Coding, Exactly?
Vibe coding refers to building software largely or entirely through natural-language prompts, with an AI model generating the actual code — as opposed to AI-assisted coding, where a developer still writes code and simply uses AI for suggestions and speed. Gartner forecasts that 40% of new enterprise production software will be built using vibe coding techniques by 2028, and expects 90% of enterprise software engineers to be using AI code assistants in some form by the same year, up from under 14% in early 2024.
This isn't a passing trend. It's quickly becoming the default way software gets built.
The Productivity Case Is Real
The speed gains aren't hype — they show up clearly in the data:
- AI-assisted developers produce over 3x more commits than developers working without AI.
- The average lines of code per pull request rose roughly 250% year-over-year, according to Cursor's Spring 2026 Developer Habits Report — and that growth rate is accelerating.
- The AI coding tools market is growing at roughly 24% per year, reflecting just how fast adoption is scaling across the industry.
- Software development is forecast to become the #1 AI use case in 2026, ahead of every other business function.
For businesses trying to ship faster with leaner teams, this is exactly the advantage they're looking for.
The Security Case Is Just as Real
Here's where it gets uncomfortable. The same speed that makes vibe coding attractive is also what makes it risky:
- Between 38% and 62% of AI-generated code contains security flaws, depending on the study and codebase.
- Georgetown's CSET found XSS vulnerabilities in 86% of AI-generated code samples tested across five major AI models.
- AI-assisted commits expose hardcoded secrets at more than twice the rate of human-written code — 3.2% versus 1.5%.
- CVEs directly attributed to AI-generated code are climbing fast: Georgia Tech's Vibe Security Radar recorded 35 confirmed cases in March 2026 alone, up from just 6 in January — and researchers estimate the real number could be 5 to 10 times higher than what's currently detected.
- Nearly 20% of AI-generated code samples reference at least one dependency that doesn't actually exist — a phenomenon researchers call "hallucinated packages," which attackers can exploit by registering those fake package names themselves (known as slopsquatting).
- 87% of global cybersecurity leaders now name AI-related vulnerabilities as 2025's fastest-growing cyber risk, according to the World Economic Forum's Global Cybersecurity Outlook 2026.
Why This Combination Is So Dangerous
It's not just that AI-generated code has more bugs. It's how those bugs get shipped.
- Pull requests are getting bigger and harder to review. "Mega PRs" — changes touching 1,000+ lines of code — nearly doubled their share of all pull requests between January 2025 and May 2026, making thorough human review far less realistic.
- AI models pull in dependencies without asking. Each generated feature can quietly introduce a tree of packages the developer never explicitly chose or audited — expanding the application's attack surface in ways nobody fully sees.
- Developers trust the output more than they should. Research shows developers frequently believe AI-written code is more secure than it actually is — a dangerous gap between perceived and actual risk.
- Exposed secrets often stay exposed. In one tracked dataset, 64% of leaked credentials in AI-generated code were still exposed and unrevoked months later. In one real case, a company's cloud access keys sat exposed in its own website's source code for over 700 days.
Worth Noting: In a controlled December 2025 test, five major AI coding agents were each asked to build the same type of feature — and all five introduced the same critical server-side vulnerability. The risk here isn't one bad tool. It's a pattern across the entire category.
How Businesses Can Get the Speed Without the Exposure
The answer isn't banning AI-assisted development — the productivity gains are real, and adoption isn't slowing down. The answer is governance.
- Treat AI-generated code like unreviewed third-party code. Read it, test it, and run static analysis before it's ever merged — regardless of how confident the AI output looks.
- Break large AI-generated changes into smaller, reviewable pull requests. Mega PRs make it structurally harder for anyone to catch what's actually being introduced.
- Run real-time secret detection, and never paste credentials or sensitive architecture details into an AI prompt in the first place.
- Audit dependencies before they ship, since AI models can introduce packages that don't exist — a risk that's entirely preventable with the right scanning in place.
- Set clear policies on where vibe coding is appropriate. Rapid prototyping is a very different risk profile than production code handling real customer data.
- Build security scanning directly into CI/CD pipelines, so vulnerabilities are caught automatically rather than relying on developers to remember every time.
The Bottom Line
Vibe coding isn't a fad, and it isn't a mistake — it's a genuinely powerful shift in how software gets built, and it's not going away. But speed without governance is how a 700-day-old exposed credential happens. The businesses winning with AI-assisted development in 2026 are the ones pairing that speed with real review, real scanning, and real accountability — not the ones treating AI-generated code as automatically safe.
At Elite Web Technologies, our React.js / Next.js development and custom LLM & GPT integration teams combine AI-augmented speed with structured human review — so you get the productivity gains without inheriting the risk. Our AI Automation & Workflow practice is also built under our ISO/IEC 42001:2023-certified AI governance framework, so security and oversight are part of the process from day one, not bolted on after.
Want AI-assisted development done with real security discipline?Contact Elite Web Technologies to talk through your project.






