AI & Vibe Coded Software Rescue

Vibes stopped vibing?

Well, this is awkward.

So, you had an idea. You found someone to build it. Perhaps an agency, a freelancer, an offshore development team, your cousin or someone armed with some trendy AI coding tool and a suspicious amount of confidence. Regardless, the end result isn't what you envisioned and you've found yourself here. Perhaps you haven't yet taken the leap and are still considering Vibe Coding for your software development project and want to understand the risks. Or maybe you're weighing up a prospective development partner but have a feeling they might not be giving you the full story on how they intend to develop your software. Whatever the case, let us provide you with some food for thought.

What part does AI play in software development

First things first, AI most definitely does have a part to play in the modern software development landscape. We use it ourselves and in the hands on experienced developers it can help to speed up development, make suggestions, generate tests and produce documentation. The important bit here is the 'experienced developers' part. 

AI can generate code extremely quickly but generating code and engineering a robust and reliable software system are two VERY different things. Just because it can generate code does not mean it understands architecture, security, databases, performance, integrations, testing or the context of your business and why you need the software in the first place. The human aspects that push you towards software are alien to AI - ii doesn't understand why your current processes are making your team pull their hair out, why customers behave the way they do or why something that sounds perfectly logical on paper will simply not work in reality.

That is why experienced developers are needed. They ask questions, challenge assumptions, identify flawed logic, understand the knock-on effect of one seemingly innocuous decision on the rest of your software and most importantly, close the gap between your technical software requirements and the very human impact it is going to have.

What is Vibe Coding?

Vibe Coding is a relatively new 'approach' to software development where someone uses AI to generate code by describing what they want in plain English rather than writing and understanding the code themselves. There's no meticulous planning, writing, testing or deployment of the code, it's usually a simple case of typing 'build me a customer portal where customers log in, view orders, track orders and download invoices. Oh, and make it look pretty' and voila, there you have it. AI has generated something for you to try. And so you do. And something breaks. You ask AI to fix it. It does and something else breaks. Rinse and repeat until you end up with something that almost appears to work.

For protypes and experimentation, this is fantastic. If you're a business owner or senior stakeholder with no coding knowledge you can turn your ideas into something tangible, you can test whether something will work and you can get an understanding of what is possible. However, the problems start when a decision is made to push it into production.

Without having someone that understands what has actually been generated and what that subsequently means for the architecture, functionality, security, performance and maintainability of the software you are probably about to find yourself in a whole world of hurt. Furthermore, each subsequent AI fix can add yet another layer of complexity to a solution that no one understood in the first place. You can see how that might be problematic.

The real cost of Vibe Coded software

Vibe coded software is attractive because it's accessible. No experience required, cheap and with instant results, it's completely understandable why so many businesses want to believe it's the answer to their problems. But as the old saying goes, if it sounds too good to be true - it probably is.

Potential risk What can happen Potential cost
Security vulnerabilities Poor authentication, exposed data, insecure APIs or other vulnerabilities make it into production. Security audits, emergency development work, remediation, downtime, legal costs and potentially regulatory consequences.
Poor architecture The software works initially but hasn't been designed to consider future growth and/or development. Significant refactoring or, in the worst cases a partial or complete rebuild.
Bugs and reliability issues Features work in the 'happy path' but fail when faced with real users, unexpected data or unusual scenarios. Ongoing bug fixing, support costs, lost productivity, lengthy deep dives and potentially unhappy customers.
Technical debt Quick fixes and AI generated patches accumulate until changing one thing starts breaking something else. Development becomes progressively slower and more expensive as developers have to work around or untangle existing code.
Poor scalability The application performs fine with a handful of users but struggles as usage and data increase. Emergency optimisation, infrastructure changes, architectural work and potentially downtime while problems are resolved.
Data protection problems Personal or sensitive information isn't collected, stored, accessed or deleted appropriately. Remediation work, specialist advice, breach management and potentially regulatory action or reputational damage.
Lack of testing Nobody has properly tested integrations, edge cases, security, different devices or what happens when something fails. Bugs appear in production, requiring reactive development and potentially interrupting business operations.
Performance problems Inefficient code, database queries or API calls make the application increasingly slow. Performance investigations, code optimisation, database work and potentially unnecessarily high hosting costs.
Integration failures Connections with payment systems, CRMs, accounting platforms or other services haven't been engineered properly. Failed transactions, missing or duplicated data, manual correction and development work to rebuild integrations.
Dependency problems AI introduces unnecessary, outdated or poorly supported third party packages and libraries. Security remediation, upgrades, replacement development and additional ongoing maintenance.
Nobody understands the code The person who created the software relied on AI without understanding what was actually being generated. An experienced developer has to spend time investigating and documenting the system before they can even start fixing it.
Difficult future development Adding seemingly simple functionality becomes increasingly risky because the underlying system wasn't designed to accommodate change. Features that should take days can take weeks, increasing development costs and slowing down the business.
Complete rebuild The existing application is so insecure, poorly structured or difficult to maintain that rescuing it no longer makes commercial sense. You effectively pay twice - once for the original software and again to have it rebuilt properly.

How to identify Vibe Coders

Not every business or individual will tell you they intend to Vibe Code your software. In fact you could quite easily believe you're paying for traditional, custom software development yet a significant chunk of your system is being developed by AI at the behest of an individual or company who have no understanding of the code they are producing.

If you suspect an individual or company intends to Vibe Code your software development project and they are not being fully transparent about it, here are a few signs to look out for:

They are suspiciously cheap - Bespoke software development requires experienced people with specific skillsets. These people cost money. A quote that is dramatically below other bespoke development agencies doesn't automatically confirm vide coding but it's worth asking how they're able to deliver the same project for a fraction of the price. Here is a very rough guide detailing what you can expect to pay for different kinds of bespoke software systems (that are designed and developed from scratch).

Their timelines are out of whack - Similarly, if the timelines are a lot shorter than other bespoke development agencies, get to the bottom of how. Bespoke software is designed and developed from scratch and involves multiple stages including requirements gathering, design, development, testing, feedback, deployment and continuous improvement. If you're promised a fully bespoke CRM system with multiple features, integrations and user profiles - this is a red flag.

A very short discovery phase - The discovery phase of a software development project is one of the most important. This is where the development team get to understand what you want, why you want it, what you currently have and how this fits in with the wider context of your business environment. If you've spent very little time sharing the details behind the request then you should probably be a bit concerned. 

They can't explain 'their' technical decisions - Ask them why they've decided to use a particular language, database or framework. This should always be a decision that is made based on logic and backed up with evidence. If they look at you with a blank stare, give you a generic answer or start mincing their words - chances are, they have no idea why that particular language/database/framework is being used - it's just because AI said so.

They won't give you access to the source code - This is a huge red flag. One of the key reasons people choose bespoke software is because they will ultimately own it and can do with it, as they wish. If you aren't told - freely or when you ask - where your code is stored, who controls the repository and how you can access it, this might suggest they don't want you to see it and they certainly don't want another development team to see it.

If in doubt, ensure you speak to multiple different bespoke software development providers. Compare their quotes and timelines, ask lot's of questions even if you don't necessarily know the answers and don't be afraid to insist on explanations or ask for elaboration.

The problem with Vibe Code remediation

If you're already past the "should we give vibe coding a go?" stage and have the software sitting in front of you, you might now be wondering what on earth you're supposed to do with it.

Perhaps it's not quite finished and you're looking for an experienced development team to pick up where the vibe coders left off. Maybe it is finished, but the bugs have started appearing and neither AI nor the people who built it seem to know how to fix them. Or perhaps it's working fine right now but you've started wondering what's really going on underneath the surface.

Whichever camp you're in, you're probably hoping an experienced development team can take it over, tidy things up and carry on where the previous developer - human or otherwise - left off.

Unfortunately, that's not quite how we approach it.

We will never take over or build on top of AI generated code. 

Well, we say never, but perhaps at some point in the future, AI generated code will reach a level where we're completely comfortable inheriting it, understanding it and putting our name against it. Technology moves quickly and we're certainly not going to pretend we know what software development will look like five or ten years from now.

But at present, it's a hard no from us and here's why:

We can't vouch for the code

If we're going to put our name against your software, we need to be absolutely confident in the code behind it. With AI generated code, we haven't made the architectural decisions, written the code or seen how it's evolved following fixes or enhancements which means we will not stand behind.

Finding issues can take longer than starting again

We could spend weeks or months trawling through an unfamiliar codebase that has been generated without the benefit of conscious decision making, figuring out what everything does, why it does it and what might break if we change it. At some point, you're effectively paying us to reverse engineer software that should have been properly engineered in the first place.

Fixing one problem can create another

AI generated code is more often than not poorly structured and can contain dependencies, workarounds and unexpected relationships that are not immediately obvious. A seemingly straightforward change in one area can have unintended consequences somewhere completely different and this too, can take a lot of work to find.

We don't know what we don't know

Sure, we might identify the obvious bugs, security vulnerabilities and questionable bits of code but that doesn't guarantee that we've found everything. We'd rather not tell you your software is good to go while quietly crossing our fingers behind our backs.

We won't build on foundations we don't trust

Adding properly engineered new functionality on top of a questionable codebase is pretty pointless. I doesn't automatically make the codebase more robust and with every new feature, comes additional pressure on the already shaky foundations.

You could end up paying twice anyway

Spending money patching, refactoring and extending the existing AI codebase may feel cheaper than rebuilding the whole thing from scratch. However, often times the codebase will still turn out to be completely unviable anyway so you'll have paid money to fix it and then again to replace it.

The good news

Now, let us follow up that potentially disappointing list with some good news. As we mentioned earlier, vibe coding is fantastic for prototyping and having a prototype can significantly reduce the discovery, design and requirements gathering phase meaning costs can also be saved. The vast majority of our clients come to us with very little in the way of a comprehensive specification - some have nothing, some have high level documentation and some have a few notes (all of which is perfectly reasonable, that's why we're here after all). However, by coming to us with an existing prototype, you've already done most of the work we'd be doing to create a comprehensive specification that allows us to start the development.

So, what now?

Where we go next depends on how far you've already gone. If you haven't yet started your project and now know for sure you don't want it to be vibe coded, we'd encourage you to come and have a chat with us. We can discuss your requirements, have a chat about the options available to you and take it from there.

If you have a half finished, vibe coded software system and you're looking for someone to finish it off, unfortunately we won't be able to simply pick up where the AI (or vibe coder) left off. As we've explained above, we won't develop on top of AI generated code so we'd be talking to you about rebuilding the software properly from scratch.

The same applies if your software is finished and things are now starting to go wrong. If you're battling bugs, struggling to add new functionality, worrying about how secure your software is or feeling nervous about your customers using the software, we can absolutely help you find the best way forward.

It's worth nothing that starting again doesn't always mean going back to square one. You've already done one of the most difficult parts in identifying what you want to build and if you have something we can physically see that shows us the features you need, the workflows you're exploring and what you like/don't like even better. We can take all of that knowledge, combine it with proper discovery and planning and rebuild your software on foundations designed to support it for the long term.

You might have to say goodbye to the code. But you don't have to say goodbye to the idea!

Prefer to Call or Email Us?

If you dont like filling in these forms, or you would prefer to speak on the phone or via email then please use one of the below:

0115 772 2751
[email protected]

Follow us on Social Media

Follow us on Twitter, Facebook or LinkedIn to be kept up-to-date with Cool Code Company news and goings-on, or just to have a conversation with us.