
AI has collapsed the distance between idea and working software, and we think that is genuinely great. But the model that wrote your code never wrote your threat model, here is what that costs, and how to keep shipping fast without getting breached.
Let's be honest about what's happened over the last eighteen months. AI has quietly rewritten who gets to build software.
Your marketing lead has shipped an internal tool. Your ops manager has a customer portal running on a weekend's worth of prompts. Somewhere in your business, right now, someone is “vibe coding”, describing what they want to Claude or Copilot or Cursor, and watching working software fall out the other end.
And here's the bit that might surprise you coming from a pentesting firm: we think this is genuinely great.
Prompt engineering and AI-assisted development have collapsed the distance between “we should build something” and “we built something.” Companies that would have waited six months for a dev agency quote are now shipping in a fortnight. Internal tooling that never justified a budget line suddenly exists. That's real value, and anyone telling you to slow down and go back to 2022 is selling nostalgia.
But.
(You knew there was a but. We're a security company. There's always a but.)
Here's what vibe coding is spectacularly good at: producing something that works. Here's what it's spectacularly indifferent to: producing something that survives contact with the internet.
The model doesn't know your S3 bucket is public. It doesn't know the API key it helpfully hardcoded is now in your Git history forever. It doesn't know that the admin panel it scaffolded has no rate limiting, that the “temporary” firewall rule is still open, or that the authentication flow it generated looks convincing right up until someone sends it a request it wasn't expecting.
AI-generated code has a very specific failure mode: it's confident, it's plausible, and it's tested against exactly one user, the person who prompted it, behaving nicely.
Attackers do not behave nicely. That's rather the point of them.
This isn't scaremongering, it's arithmetic. Your product might be 99% solid. But it only takes one:
And the cost isn't the fix. The fix is a Tuesday afternoon. The cost is the breach notification, the ICO conversation, the customer emails, and the years spent rebuilding a reputation that took one exposed database to lose. Companies recover from bugs. Recovering from “they leaked our data” is a much longer road.
So no, we're not here to tell you to stop using AI to build. We're here to tell you the game has changed and your security approach needs to change with it.
Bake security into the pipeline, not the post-mortem. DevSecOps isn't a buzzword when you're shipping AI-generated code at AI speed, it's the seatbelt. Secrets scanning, dependency checks, and configuration review need to run at the pace you're now building at.
Assume the AI got something wrong, because it did. Somewhere. The question is whether you find it or someone else does. Every AI-assisted codebase we've looked at has had something usually not exotic, usually the boring stuff: exposed services, weak auth, over-permissive cloud config. Boring is what gets you breached.
Test it like an attacker, not like a user. This is where independent validation earns its keep. A proper penetration test doesn't care how the code was written or how clever the prompts were. It cares about one thing: can this be broken, and what happens to your business when it is?
AI has made building software easy. It has not made securing software easy, if anything, the sheer volume of code being shipped has made it harder. The companies that win the next few years won't be the ones who built fastest. They'll be the ones who built fast and knew, with evidence, that what they built could take a punch.
You've done the fun part. Let us do the part where we try to ruin your day in a controlled, contractually agreed manner, so nobody else gets to do it for real.
Forefront IT Security Services is an offensive security consultancy based in Gloucestershire. We test what you've built. AI-assisted or otherwise, before someone less friendly does. Get in touch for penetration testing, cloud configuration review, and security validation.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.