Are we vibe coding our way to a new legacy crisis?
The AI that promised to free enterprises from technical debt may be more of it.
The rise of AI-generated code, colloquially referred to as "vibe coding," has reached a tipping point for many enterprises. With over 90% of code at Anthropic generated by AI, developers are witnessing significant productivity gains, albeit at the cost of potential vulnerabilities. As AI-assisted developers introduce security issues at ten times the rate of their human peers, and over half of AI-generated code contains OWASP Top 10 vulnerabilities, enterprises are grappling with a new challenge: governing the code their AI tools produce.
This new threat, known as Shadow AI, poses a greater risk than traditional Shadow IT, as it transcends departmental boundaries and lacks oversight. Unlike Shadow IT, which is usually contained within a specific team, Shadow AI compounds across organizational boundaries, making it difficult to track and manage. The result is an increase in technical debt, which can range from 30-41% following the adoption of AI tools.
This debt is insidious because developers may not even realize they've incurred it, as the generated code appears correct until it breaks.
The analogy of repeating the COBOL mistake is apt. General-purpose AI models, while impressive at generating plausible outputs, lack the necessary mechanisms to ensure outputs are auditable, compliant, and maintainable. These models are not equipped to provide the traceability and governance required for enterprise-scale deployment. Consequently, organizations are still trying to modernize legacy systems, only this time faster and more recklessly.
To address these challenges, organizations are adopting a more strategic approach to modernization. Instead of treating it as a technical exercise, they are reevaluating the underlying processes to determine whether they are still valid. True modernization involves reinventing how work gets done, focusing on the employee and customer experience rather than the constraints of outdated systems. This requires a governance layer that imposes structure, ensures auditability, and keeps AI outputs within maintainable boundaries.
High-stakes organizations are already implementing such governance layers. For instance, the US Army uses AI to extract specifications from legacy applications, converting them into visual plans for UI, data models, and process flows. Similarly, Merck, a pharmaceutical company, employs AI agents to generate reusable software components under human supervision, accelerating development while maintaining auditability.
These approaches significantly reduce development time and technical debt, offering a blueprint for how enterprises can navigate the AI-driven code generation wave without falling into old legacy traps.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.