Vibe-Coded Apps Are Reshaping Shadow IT—Key Risks and Insights

Vibe coding is making it much easier for people to build working apps without being professional software developers. A simple description can now be turned into a web app, database tool, form, dashboard, or internal workflow with the help of AI.

That speed is changing an old workplace problem called shadow IT. Employees have always created or used technology without going through the IT department. Now, AI coding tools can turn those private experiments into real applications that connect to company data, cloud services, and business systems.

What is vibe coding?

Vibe coding is a way of building software mainly by telling an AI tool what you want in normal language. Instead of writing and checking every line of code by hand, a person can describe a feature, ask the AI to build it, test the result, and then ask for changes.

The term became widely known after developer Andrej Karpathy described this style of AI-based coding in 2025. It is different from normal AI-assisted programming because the person may have little understanding of the code being created and may judge the application mainly by whether it appears to work.

This makes software creation much more accessible. A sales employee could build a customer tracking tool. A manager could create a reporting dashboard. A product team could make a simple customer feedback app. A small business could create an internal tool without waiting for a full software development project.

The problem starts when these tools move from harmless experiments into real business use without IT or security teams knowing about them.

Why vibe-coded apps are becoming part of shadow IT

Shadow IT is not a new idea. It usually means employees use software, cloud services, devices, or systems that have not been approved or managed by the organization’s IT team.

Vibe coding adds a new layer to that problem. In the past, an employee might sign up for an outside service. Today, that same employee can create an entire application and connect it to other services in a short time.

An app that begins as a weekend experiment can end up storing customer information, employee records, company files, passwords, or other sensitive data. It may also be hosted on a public cloud service or connected to company systems without a formal security review.

Recent security research has found publicly accessible applications and related infrastructure created with popular vibe-coding and AI development platforms. The findings show why security teams are increasingly concerned about applications that appear outside normal software inventories.

This changes the traditional shadow IT problem. Companies are no longer dealing only with unknown software subscriptions. They may also have to find and manage applications that employees created themselves.

The biggest security risks

The main concern is not simply that AI writes imperfect code. The larger issue is that people without deep software security knowledge can create applications that look finished while important protections are missing.

Research into real-world vibe-coded applications has found recurring problems involving unfiltered input, exposed secrets, and incomplete or placeholder logic. The research also points to limits in the way AI agents handle longer development tasks and security decisions.

The most important risks include:

  • Sensitive information can be exposed through poorly protected databases, public endpoints, or weak access controls.
  • Passwords, API keys, and other secrets can accidentally be placed in application code or uploaded to public code repositories.
  • AI-generated code may use unsafe settings, weak validation, or outdated or unverified software components.
  • An application may continue running after its original creator leaves, making ownership, updates, and security fixes difficult to manage.

These problems become more serious when an app is connected to internal company systems. A simple form that collects harmless feedback is very different from an AI-built application that can access customer records or financial information.

Why working code does not mean secure code

One of the biggest traps with vibe coding is that an application can appear to work perfectly while still having serious security problems.

A user may test a login page, submit a form, view a dashboard, and decide that the application is ready. But those tests do not show whether someone else can bypass the login, access another user’s information, guess an administrative URL, or obtain hidden credentials.

AI tools can generate useful software very quickly, but they do not remove the need for testing and human review. NIST guidance for AI-related software development stresses the need to monitor and validate AI-generated work and maintain processes that can check whether the result is accurate and trustworthy.

This matters especially because a person who does not understand the underlying code may not know what needs to be checked.

The result can be a false sense of safety: the app looks finished because the visible features work, while the less visible security controls have never been properly tested.

The hidden data problem

Data is one of the biggest reasons shadow IT becomes a business risk.

When an employee builds an app with an AI tool, several questions need to be answered. What information does the application collect? Where is that information stored? Who can access it? Which outside services can see it? What happens to the information when the application is no longer needed?

These questions are easy to overlook when an app is created as a quick solution to a business problem.

The risk also grows when employees place company information into AI tools while asking them to create or change an application. Shadow AI and shadow IT can therefore overlap. An organization may have little visibility into both the AI service being used and the application produced from that service. Recent security reporting has highlighted the wider problem of employees using AI services outside normal company controls.

A small application can therefore create a much larger data problem if it has access to important company information.

The problem with secrets and access

Hard-coded secrets are another major concern. A secret can be a password, API key, access token, or other piece of information that allows software to connect to a protected service.

If a developer or AI-generated application places such information directly into code, the secret may later be exposed through a code repository or another public location. Security experts have recently warned that this is an important enterprise risk connected with vibe-coded applications.

Access is equally important. An application should give each person only the access needed for their job. If a quickly created app uses broad permissions, an attacker who gains access to the app may be able to reach far more information than expected.

This is why an AI-generated application should never automatically receive access to sensitive company systems simply because the application needs to perform a useful task.

Vibe coding also creates a maintenance problem

Security is only one part of the issue. Organizations also need to think about what happens after an app is created.

A quick AI-built tool may not have clear documentation, a known owner, regular updates, or a plan for fixing problems. The original creator may understand how it works, but another employee may struggle to maintain it later.

AI-generated code can also create long-term code quality and maintenance issues. Recent research comparing applications created by different vibe-coding tools found meaningful differences in code quality, complexity, and code issues across the tools tested.

That means companies should not assume that an application is safe to keep simply because it was produced by a well-known AI platform.

How companies can reduce the risk

The answer is not necessarily to ban vibe coding. Blocking every AI coding tool may push employees toward less visible alternatives.

A better approach is to give employees a safe way to experiment while making clear rules for applications that handle company information.

A basic company policy should cover:

  • Which AI coding tools employees are allowed to use.
  • What types of company data can be used with those tools.
  • When an AI-built app needs security or IT review.
  • Who owns an application after it is created and who is responsible for updates.

Security checks should also become part of the normal development process. Applications that handle sensitive data should receive stronger review than a simple personal experiment.

Companies can use automated security testing, dependency checks, secret scanning, access controls, and logging. Human review remains important because automated tools may find technical problems but may not understand whether an application’s design is appropriate for the business.

NIST’s secure software guidance provides a framework that organizations can use when building secure development processes around AI-related software.

What IT teams should watch for

Traditional IT inventories may not be enough to find every vibe-coded application. Security teams need to understand where employees are building, hosting, and connecting these tools.

A useful review can focus on applications that have access to:

  • Customer or employee information.
  • Internal databases and company APIs.
  • Financial, HR, or other sensitive business systems.
  • Administrative accounts, cloud resources, or production environments.

The goal should be visibility rather than simply punishment. Employees often create shadow tools because the official process feels too slow for a small business need. If IT provides approved AI tools, simple security rules, and a quick way to request help, employees have less reason to work around the system.

What this means for the future of shadow IT

Vibe coding is changing the scale and speed of shadow IT. A person no longer needs to know how to build a complete application before trying to solve a technical problem.

That is a major benefit for innovation. It allows teams to test ideas quickly and create tools that might otherwise never be built. But it also means organizations can create software faster than their security and governance processes can review it. Security researchers and technology analysts are increasingly pointing to this gap as AI-assisted development becomes more common.

The most important change is therefore not the disappearance of shadow IT. It is the expansion of what shadow IT can include.

A spreadsheet or outside software account was once the typical example. Now the risk can include a complete web application, its database, its cloud hosting, its AI services, and its connections to internal systems.

The bottom line

Vibe-coded apps are making software creation faster, cheaper, and easier for people who may never have considered themselves developers. That can be good for businesses when the technology is used in a controlled way.

The danger comes when a quick experiment quietly becomes a business application without proper security, ownership, testing, or data controls.

Companies do not need to treat every AI-built app as dangerous. They do need to know which applications exist, what data they can access, who controls them, and whether basic security checks have been completed.

As AI makes software easier to create, governance has to become easier and faster too. The organizations that find that balance can benefit from rapid AI development without allowing a new generation of shadow IT to grow unnoticed.

Leave a Comment