Vibe Coding
Knowledge
In the beginner path, you learned about Vibe Coding as a concept: you describe in natural language what you want to build, and an AI agent implements it. Now let's analyze this approach critically -- with all its possibilities, limitations, and ethical questions.
What Vibe Coding Really Means
The term was coined by Andrej Karpathy, one of the leading AI researchers (formerly at OpenAI and Tesla). His definition:
"You set the direction and 'vibe' with the code. You don't really read it, you run it, see if it works, and if not, you copy the error message back into the AI."
That sounds casual -- and that's exactly what it is. Vibe Coding is the lowest-barrier entry into software development that has ever existed. But this low barrier comes with consequences.
Possibilities: What Works Surprisingly Well
Prototyping and MVPs: You can build a functioning prototype in hours that would have taken weeks before. A landing page, an internal tool, a simple app -- Vibe Coding delivers visible results fast.
Personal Tools and Automations: A script that sorts your photos. A small website for your club. A dashboard for your finances. For personal projects, Vibe Coding is a game-changer.
Learning Tool: Paradoxically, Vibe Coding can even help you learn to program. You immediately see what code looks like for your description and can understand step by step what's happening.
Empowering Non-Developers: Marketing teams building their own landing pages. Analysts creating data dashboards. Researchers programming visualizations. Vibe Coding opens doors that were previously closed.
Limitations: Where Vibe Coding Gets Dangerous
Security Vulnerabilities: If you can't read the generated code, you can't spot security vulnerabilities either. SQL injection, cross-site scripting, insecure API keys -- the AI agent makes these mistakes, and you don't notice.
Technical Debt: Vibe-coded projects tend toward "spaghetti code" -- it works today but won't be maintainable tomorrow. Every change can have unexpected side effects because nobody thought through the architecture.
Scaling Problems: A prototype for 10 users works. The same code for 10,000 users breaks down. Performance optimization, caching, database indexes -- that requires understanding that Vibe Coding doesn't provide.
False Sense of Security: "It works, so it must be good" -- that's a dangerous fallacy. Code can work on the surface and still have fundamental problems: race conditions, memory leaks, data loss in edge cases.
!The Responsibility Question
If you build an application with Vibe Coding that other people use, you bear full responsibility for the generated code -- even if you didn't write it and don't understand it. "The AI did it" is not a defense.
Understand
40–62% of AI-generated code contains security vulnerabilities (NYU/BaxBench 2024)
Which zone are you in?
Answer these questions for your project:
When Is It Sensible, When Is It Dangerous?
Green Zone -- Go For It
- Personal projects and prototypes
- Internal tools for your team (with IT review)
- Learning projects and experiments
- One-off data analyses and scripts
- Static websites without user data
Yellow Zone -- Be Careful
- Small web applications with user data (security review needed)
- Automations that affect business processes
- Tools that others depend on
- Projects intended to last more than a few weeks
Red Zone -- Don't Do It (or Bring in Experts)
- Applications with payment processing
- Health or safety-related software
- Anything involving sensitive personal data
- Systems where outages are costly or dangerous
- Products for the public market without professional review
The Ethical Dimension
Vibe Coding raises a fundamental question: Is it acceptable to publish software you don't understand?
Legally, you are liable as the operator of an application -- regardless of whether you wrote the code yourself or an AI did. If your vibe-coded app leaks user data, you're responsible.
Ethically, it goes even further: you have a duty of care toward your users. A doctor wouldn't prescribe a medication whose effects they don't understand. Should you deploy software whose workings you can't comprehend?
The answer is nuanced: for a personal project? No problem. For an app that processes health data? Irresponsible without professional review.
Apply
A colleague built an internal time-tracking tool using Vibe Coding. It works well and the team has been using it for two weeks. Now it's supposed to be rolled out company-wide. What is the most important next step?
Reflect
Vibe Coding is a powerful tool -- but like any tool, it must be used responsibly. The art lies in leveraging its strengths (rapid prototypes, personal tools, learning projects) while respecting its limitations (security, scalability, maintainability).
Next, we'll look at what AI-assisted development actually costs -- a topic that's often underestimated.