Vibe coding is building the next legacy crisis, one PR at a time

a computer screen with a bunch of code on it

Anthropic’s CFO recently disclosed that over 90 percent of the company’s own code is now written by its AI. Tasks that once took hours now take 30 minutes. That’s an AI-native company with elite engineering talent. Most enterprises aren’t that.

For the rest of the business world, the real question isn’t whether AI can ship code fast. It’s whether anyone can govern what it ships.

The numbers are uncomfortable

Nearly half of all new global code is now AI-generated, according to some estimates. Developer productivity is up. So is a category of debt that nobody fully understands.

  • Research across Fortune 50 enterprises found AI-assisted developers introduce security vulnerabilities at 10 times the rate of their peers.
  • 45 percent of AI-generated code contains OWASP Top 10 vulnerabilities.
  • Technical debt increases by 30 to 41 percent following AI tool adoption, per independent analyses.

The insidious part: this isn’t the debt engineers knowingly incur. Traditional shortcuts leave a trail. Vibe coding debt is invisible because the code looks correct right up until it causes a serious problem.

Shadow AI is replacing Shadow IT

Shadow IT was containable. One department running an unsanctioned SaaS tool was a defined blast radius. Shadow AI compounds across organizational boundaries. In enterprises where systems are still deeply siloed, no single team has a complete picture of what’s been generated or what it depends on.

The talent shortage that makes AI indispensable also means there aren’t enough senior engineers to review what AI produces. The same gap that justified the tool is the gap that makes the tool dangerous.

lines of HTML codes

The governance angle

The article points to two enterprise examples worth noting. The US Army addressed this by using a governed process platform to impose structure and ensure auditability while still operating at speed. Merck’s clinical supply chain, where regulatory scrutiny is intense and errors carry patient safety consequences, required a platform that could accelerate delivery without sacrificing traceability.

Both cases used AI to extract specifications from poorly documented legacy applications, converting them into visual plans covering UI, data models, and process flows. AI agents then built against those specs under human supervision. The reported result: delivery at roughly 25 percent of the time traditional approaches require.

The operator takeaway

The argument here isn’t anti-AI. It’s that speed without governance is how enterprises end up maintaining COBOL-equivalent systems in 2040, only this time written by a language model nobody can interrogate. The organizations that come out ahead won’t be the ones that generated code fastest in 2025 and 2026. They’ll be the ones that built review and auditability into the process from the start.

For smaller operators and indie builders, the same logic applies at a smaller scale. Shipping fast with AI is fine. Shipping fast with no understanding of what you shipped is a future debugging session you haven’t scheduled yet.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo