Chris Stokel-Walker, "Why untested AI-generated code is a crisis waiting to happen":
The fear is of a slow-burn crisis where generative AI engines spew reams of code, stitched from web-scraped snippets with dubious provenance.
When that code leaps from prompt to production without being vetted, the potential attack surface balloons in size. The bill for defective code is already sizable: 40% of firms say malfunctioning or miscoded software costs them at least $1 million a year, through staff churn, increased technical debt, and escalating maintenance costs, with losses above $5 million in almost half of large US firms.
So, don't let "code leap from prompt to production without being vetted" - it's not like it happens on its own. Steady hand on the tiller. Vibe coding is fine for screwing around and exploration, but assume you're going to be on pager duty for whatever hits production. And if someday you stick an LLM on pager duty, may Eris have mercy on your soul.