JetBridge Research
Version 6.0 · August 2026
Your employees are building the company's software.
What the evidence says about finishing it safely.
A meta-study of 34 research papers, security scans, vendor reports and public arguments about enterprise vibe coding — the diagnosis, the cost, and a twelve-item specification of the work AI leaves behind.
- 41 pages
- 10 min for the executive path
- PDF · free
Read the full 41-page study
One field. Enter your work email and the whole document opens in a new tab — nothing to confirm, no download queue.
of 1,072 live apps built this way carried at least one security flaw
Symbiotic Security scan, June 2026
of 5,600 production apps had properly scoped access controls at the data layer
Cloud Security Alliance, June 2026
slower with AI — while the same developers believed they were 20% faster
METR randomised controlled trial, July 2025
of the defects AI introduces are never fixed and survive into the current version
302,600 verified commits, March 2026
“Employee-built software does not create data debt. It exposes data debt that spreadsheets have been hiding for a decade.”
What's inside
- 01
Almost every app has the same hole
Four teams, four methods, one failure: the app never checks whether the person using it is allowed to see the data.
- 02
The bill did not vanish
Writing code got cheap. Checking, fixing and maintaining it did not — and 'almost right' is the most expensive kind of wrong.
- 03
Nobody can feel their own productivity
Why self-reported speed-ups are worthless as governance evidence, and what to count instead.
- 04
The sentence your employee types is the asset
Sovereign AI is four separate questions — residency, ownership, control and training rights. Ask them separately.
- 05
The twelve things AI will not do
The last mile, itemised: access control at the data layer, identity, secrets, data flow, connectors, audit logs and change control.
- 06
What to do on Monday
Classify what already exists, then move the controls into the platform so the safe outcome is the default outcome.
Written for
- CIOs and CTOs deciding whether to allow, ban or govern employee-built apps
- Security and risk leaders who need the defect evidence, not the vendor deck
- Platform teams designing guardrails for non-developer builders
Disclosure. The study is published by JetBridge, a software engineering company that also makes an enterprise vibe coding tool. Section 14 states that commercial interest and where the authors say they are the wrong answer.
Version 6.0 · August 2026 · JetBridge. Questions about the research are welcome — reply to the email that delivers your copy.
