Are we vibe coding our way to a new legacy crisis?

Security News

Are we vibe coding our way to a new legacy crisis?

Credit: The original article is published here.

When Anthropic’s CFO revealed that over 90 per cent of the company’s code is now written by its own AI, it landed as a milestone.

Tasks that once consumed hours now take 30 minutes. The productivity gains are significant.

But Anthropic is an AI-native company with some of the world’s best engineering talent.

For most enterprises, the question isn’t whether AI can generate code at that speed. It’s whether they can govern what it generates.

Shadow AI: The new shadow IT

“Vibe coding”, the term for generating code via AI, has moved into the mainstream. By some estimates, almost half of all new global code is now AI-generated. Developer productivity is up. So is debt that nobody fully understands.

Part of what’s driving this is necessity. AI is helping close the engineering talent gap. Teams that lack experienced developers are using it to build at the pace the business demands. The problem is that the same shortage that makes AI indispensable also means there aren’t enough senior engineers to review AI-generated code.

Research across Fortune 50 enterprises found that AI-assisted developers introduce security vulnerabilities at ten times the rate of their peers. Forty-five per cent of AI-generated code contains OWASP Top 10 vulnerabilities. Independent analyses indicate that technical debt increases by 30–41 per cent following the adoption of AI tools.

Traditional technical debt is at least visible. Engineers who cut corners know they did it. Vibe coding debt is different: developers often don’t realize they have incurred it, because the code looks correct – right up until it doesn’t.

We used to worry about Shadow IT. The new threat is Shadow AI: code generated at pace without architectural review, security auditing or institutional understanding of what’s been built.

Unlike Shadow IT, which was typically contained within a department, Shadow AI compounds across organizational boundaries. In enterprises where systems are still deeply siloed, complex problems span multiple departments and platforms; no single team has a complete picture of what’s been generated or what it depends on.

Enterprises have spent decades paying for yesterday’s shortcuts. AI risks creating the next generation of legacy systems, only much faster.

Repeating the COBOL mistake

The market is flooded with tools promising to read millions of lines of COBOL or Java and convert the functionality into a modern language. This is technically impressive, but strategically flawed.

Legacy systems are full of inefficiencies, redundancies and “swivel chair” workarounds baked in years ago to compensate for other systems’ limitations. Translating code line-by-line replicates that bad logic in a newer language, now running on cloud infrastructure with a modern interface on top of old code and dated processes.

To get modernization right, organizations should avoid treating it as a technical exercise. Instead, they should step back and ask whether a process is still valid, not just how to replicate it.

True modernization is about reinventing how work gets done, designed around the employee and customer experience rather than the constraints of systems built decades ago. It is a state of consistent change, and it must be driven by the North Star of clear business objectives.

The agility layer

Probabilistic AI needs to operate within deterministic boundaries to be safe and useful at enterprise scale. AI that can generate anything is not the same as AI that generates the right thing reliably with full traceability, in a context where every decision might be scrutinized by a regulator.

This is why high-stakes organizations are looking for an agility layer: a governed process platform that imposes structure, ensures auditability and keeps AI outputs within maintainable boundaries. The US Army followed this approach for security with agility to operate with certainty at speed.

Ordering ammunition in disconnected field conditions is mission-critical, with zero tolerance for ungoverned outputs. Similarly, pharmaceutical giant Merck’s clinical supply chain, where regulatory scrutiny is intense and errors have patient safety consequences, required a platform that could accelerate delivery without sacrificing auditability.

These are examples of organizations trying to address the hardest part of modernization: discovery. They are using AI to extract specifications from even the most poorly documented legacy applications, converting them into visual plans covering UI, data models and process flows.

They’re generating software components rather than custom code to reuse in other applications, accelerating development time and reducing technical debt. AI agents then build against those specs under human supervision, with developers assigning tasks and iterating throughout – at roughly 25 per cent of the time traditional approaches require.

The future is bespoke, not general-purpose

There is a temptation to conclude that general-purpose AI will soon render enterprise platforms obsolete. This is premature and in regulated environments, dangerous. General-purpose models are extraordinary at generating plausible outputs. They are not equipped to ensure those outputs are auditable, compliant or maintainable by teams that did not generate them.

The vibe coding wave is real, and so is the debt it is creating. The organizations that navigate the next decade successfully and avoid falling into the same old legacy traps will not be the ones that generated code the fastest in 2025 and 2026.

They’ll be the ones to build governance and process boundaries into how AI was used from the start – so what was built quickly can still be understood, maintained and trusted years later.

We’ve reviewed, rated, and ranked the best laptops for programming.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Leave a Reply

Your email address will not be published. Required fields are marked *