VOOZH about

URL: https://thenewstack.io/should-your-team-be-vibe-coding/

⇱ Should Your Team Be Vibe Coding? - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-09-05 10:00:38
Should Your Team Be Vibe Coding?
sponsor-chainguard,sponsored-post-contributed,
AI / AI Engineering / CI/CD

Should Your Team Be Vibe Coding?

Vibe coders must understand that AI is just a productivity tool, and they — not the AI — are ultimately accountable for the code it produces for them.
Sep 5th, 2025 10:00am by Matt Moore
👁 Featued image for: Should Your Team Be Vibe Coding?
Image from Deemerwha studio on Shutterstock.
Chainguard sponsored this post.

Across the industry, software is being written differently: faster, more collaboratively and increasingly through AI prompts instead of keystrokes. This shift has a name, and it’s changing the way code gets written.

“Vibe coding,” the growing use of generative AI (GenAI) to write, refactor and review code, is becoming a common part of modern software development. According to Gartner, AI-assisted development is poised to account for 40% of all new business software within three years, but that is likely a conservative estimate.

Vibe coding is a lot like having a tireless, egoless, eager junior engineer sitting beside you — one who responds instantly to feedback, churns out working code and never complains about repetitive tasks. But speed without scrutiny can have major consequences.

Vibe coders need to understand that AI is just a productivity tool, and they — not the AI — are ultimately accountable for the code it produces for them. If they accept low-quality output, they will be accountable for the risks and vulnerabilities created.

Real Experience of Vibe Coding (And Why It’s Compelling)

Using tools like Claude Code or GitHub Copilot, vibe coding enables rapid iteration for developers. You can make a request, review work and complete revisions, and in minutes, you have functioning code that might otherwise have taken hours or days to write.

In many ways, vibe coding is following the same trajectory open source did: It began as an experimental, developer-driven movement, then rapidly became the backbone of modern software. That shift delivered enormous productivity and innovation, but also introduced new challenges in governance, licensing and security.

Open source software enables developers to use existing libraries and frameworks to write less of the final code necessary to build powerful applications, but importantly, they still remain accountable for 100% of what ends up running in their environment.

Vibe coding offers a similar promise while carrying similar risks. Teams that put the right culture, guardrails and accountability in place from Day 1 will be best positioned to capture its benefits safely.

Vibe Coding Doesn’t Mean Vibing Without Rules

AI is fundamentally a productivity tool. As with any productivity tool, it is intended and expected to increase the quality and/or quantity of your work (ideally both), without regressing either. Ultimately, the person using the tool is accountable for the results. But used properly, that output should be higher quality and higher quantity.

A culture of “secure velocity” starts with shared responsibility. For organizations, that means:

  • Rigorous code review and testing: AI doesn’t get a free pass. Every suggestion requires human oversight.
  • Governance and provenance: Teams need traceability to understand where code came from, how it was modified and who signed off on it.
  • Legal and security buy-in: Collaboration between engineering, legal and security teams ensures AI-generated code isn’t introducing compliance or licensing risks.

With these guardrails in place, using AI to write code can be transformative. Without them, vibe coding risks becoming an unmonitored source of vulnerabilities.

Security Flipside: Vibe Hacking and Zero-Day Acceleration

Naturally, the same AI tools that empower developers are in the hands of attackers. Historically, zero-days have been the “holy grail” of vulnerabilities because they give attackers a potential weapon against which their prey is defenseless. (They have had “zero days” to patch it.) Disclosed vulnerabilities also appeal to attackers because many folks (the laggards) simply aren’t applying patches. But the race is on: Can the attacker weaponize the exploit before their prey has applied the patch?

Now armed with GenAI tooling, the time for an attacker to weaponize known vulnerabilities is plummeting from weeks to minutes. This fundamentally changes who they can attack, from just the laggards to everyone who hasn’t adopted modern security practices.

Just as AI enables quick iterations for developers, it also allows adversaries to find, test and weaponize vulnerabilities at unprecedented speed. Even if a patch exists, delays in upstream distributions or slow adoption by end users create a dangerous window that attackers can exploit before defenders have time to react. The result: Defenders face a shrinking response window, and security teams need to assume that bad actors are coding at the speed of AI, too.

Vibe Coding Is Not Going Anywhere

Vibe coding isn’t a fad; it’s the next evolution in how software gets built. For developers approaching it responsibly, it offers more than speed. It can elevate code quality, free up time for creative and innovative work and even foster better engineering habits. But without the right quality checks, it risks becoming a liability.

Here’s the challenge for vibe coders: Don’t stop at faster code. Push yourself toward better code. Use the time you save to do that refactor you’ve been putting off, write the documentation your teammates will thank you for, expand test coverage or improve security posture. Share how vibe coding isn’t just accelerating output, but actually raising the standard of the code you deliver.

Now is the moment to run your vibe check: Are you not only going faster, but also leveling up the quality of your work?

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.
Learn More
The latest from Chainguard
Hear more from our sponsor
TRENDING STORIES
Matt Moore is CTO and cofounder at Chainguard.
Read more from Matt Moore
Chainguard sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Real.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.