Artificial intelligence is reshaping how software is built
With AI-assisted coding tools now woven into developer workflows, enterprises are racing to capture the benefits of faster delivery, reduced costs, and rapid prototyping. But this style of software creation, also known as “vibe coding”, comes with risks that, if unchecked, could quietly compromise enterprise systems.
“Vibe coding is essentially rapid, intuitive coding powered by AI,” explains John Leong, Cybersecurity Director of Knovel Engineering. “It’s where developers lean heavily on AI-generated suggestions without the rigour of traditional processes or documentation. It’s not inherently bad, but left unverified, it creates blind spots that can become vulnerabilities.”
Chris Ngo, Director of AI and Research of Knovel Engineering, notes why enterprises are so tempted, “AI-assisted coding is attractive because it accelerates development and saves costs. You can quickly prototype and experiment. But the misconception is that because the AI is smart, the code must always be correct or secure. The reality is that AI mirrors its training data, which can contain insecure patterns.”

The Hidden Risks of Vibe Coding
The promise of AI coding tools lies in speed. The danger lies in the corners cut.
“AI tools can copy insecure practices like hardcoding credentials or skipping encryption,” says John. “We’ve even seen cases where unpatched dependencies crept in through auto-generated code, or insecure APIs were exposed. In regulated sectors like finance, healthcare, and government, those mistakes aren’t just technical bugs. They are compliance failures.”
Chris explains that the flaws often hide in the details. “AI-generated code frequently misses basic safeguards such as error handling or input validation. Sometimes the tools even hallucinate functions or libraries that don’t exist, which wastes developer time and can open doors for vulnerabilities if patched in hastily. The biggest danger is when developers assume the AI got it right, when it didn’t.”
These issues rarely make headlines until they lead to breaches. But in many organisations, these risks accumulate quietly, waiting for an attacker or even a compliance audit to expose them. By then, the company’s reputation and credibility will be harmed and will take a long time to recover.
Guardrails are Essentials, Enterprises Can’t Ignore
Enterprises do not need to abandon AI-assisted coding. What they need are guardrails.
“Trust, but verify,” emphasises John. He adds that there should be mandatory code reviews by both humans and automation. It involves deploying static and dynamic application security testing (SAST and DAST), scanning dependencies, and creating audit trails of what AI suggests versus what human experts accept. He laments, “without these, you’re effectively letting the AI write production code unsupervised.”
Chris believes the workflow design underscores the efficiency and accuracy of AI assurance. He said, “AI tools should never be left to junior developers alone. Pair them with experienced engineers who can validate suggestions. Build review checkpoints into the process and make it a norm for developers to explain why they accepted or rejected the line of AI code. That culture of accountability ensures the AI remains a co-pilot.”
Both practitioners believe that guardrails and processes can safeguard the integrity of the output, reduce risks, and more importantly, build confidence where speed and security can coexist.
Looking Ahead: Tomorrow’s Threat Landscape
The pace of change means enterprises must also prepare for threats that do not yet exist. “Adversaries could deliberately insert vulnerable patterns into public code repositories, knowing AI tools will pick them up. Worse, some attackers may disguise malicious code as so-called ‘best practices’—making it even harder to spot,” observes John. However, he also believes that regulators will pay more attention to tightening governance and assurance around the use of AI.
On the other hand, Chris hopes to see more progress in builders and developers testing their AI applications before deployment. “We have developed and launched a new adversarial testing platform, DeepAssure, to stress test builders’ AI applications before their deployment. With the emergence of our AI assurance platform, formal verification with human expertise, compliance testing at scale, and continuous improvement are now possible. These are critical for building long-term trust.”
“With the emergence of our AI assurance platform, formal verification with human expertise, compliance testing at scale, and continuous improvement are now possible.
Chris ngo, director of Ai and research
These are critical for building long-term trust.”
A Cautionary Word for Enterprise Leaders
So what’s the key takeaway for enterprises considering a deeper embrace of AI-assisted coding?
“Don’t ship what you can’t secure,” cautions John. “Speed without guardrails equals hidden liabilities. If you’re a CTO, you need to adopt a zero-trust approach to AI-generated code. That means assuming it’s flawed until proven otherwise.”
Chris offers a complementary perspective, “The most important habit is to make ‘review and validate’ part of your organisational culture. Developers should treat AI as a junior co-pilot. Helpful, fast, but not infallible. The organisations that win in the long run will be the ones that innovate responsibly, not recklessly.”

Balancing Speed with Assurance
Vibe coding reflects both the promise and the peril of AI in software development. It enables unprecedented speed, but it also introduces risks that, if ignored, can erode trust, compliance, and resilience.
Enterprises need to recognise that AI-assisted coding is not a shortcut around secure development. It is a shift that requires new safeguards, new habits, and new governance.
The message from both cybersecurity and AI research leaders is clear. The future of coding is collaborative, with humans and AI working together. The collaboration only works if responsibility is shared, risks are acknowledged, and safeguards are enforced.
In short, speed matters, but security must never be optional.
Let’s Talk About What’s Possible
Knovel Engineering has the experience and capabilities to help enterprises build systems that ensure their AI delivers reliable results.
Find out more about Knovel Engineering’s latest AI assurance capabilities, or explore our DeepAssure platform for more information.
If your organisation is looking to deploy a reliable new AI system, whether you’re in retail, public service, or any field, we can tailor the solution that meets your needs.
Contact us here or email us at hello@knoveleng.com




