Skip to content
JetBridge Research

Your employees are building the company's software.

What the evidence says about finishing it safely.

A meta-study of 34 research papers, security scans, vendor reports and public arguments about enterprise vibe coding — the diagnosis, the cost, and a twelve-item specification of the work AI leaves behind.

41 pages10 min for the executive pathPDF · free
98%

of 1,072 live apps built this way carried at least one security flaw

Symbiotic Security scan, June 2026

0

of 5,600 production apps had properly scoped access controls at the data layer

Cloud Security Alliance, June 2026

19%

slower with AI — while the same developers believed they were 20% faster

METR randomised controlled trial, July 2025

22.7%

of the defects AI introduces are never fixed and survive into the current version

302,600 verified commits, March 2026

FREE · NO SIGNUP

Read the full 41-page study

One field. Enter your work email and the whole document opens in a new tab — nothing to confirm, no download queue.

Company addresses only — personal inboxes are rejected.

We use your address once, to send the study and its next revision. No reselling, no drip campaign, unsubscribe in a click.

Employee-built software does not create data debt. It exposes data debt that spreadsheets have been hiding for a decade.

Section 7 — the twelve things AI will not do

What's inside

  • 01

    Almost every app has the same hole

    Four teams, four methods, one failure: the app never checks whether the person using it is allowed to see the data.

  • 02

    The bill did not vanish

    Writing code got cheap. Checking, fixing and maintaining it did not — and 'almost right' is the most expensive kind of wrong.

  • 03

    Nobody can feel their own productivity

    Why self-reported speed-ups are worthless as governance evidence, and what to count instead.

  • 04

    The sentence your employee types is the asset

    Sovereign AI is four separate questions — residency, ownership, control and training rights. Ask them separately.

  • 05

    The twelve things AI will not do

    The last mile, itemised: access control at the data layer, identity, secrets, data flow, connectors, audit logs and change control.

  • 06

    What to do on Monday

    Classify what already exists, then move the controls into the platform so the safe outcome is the default outcome.

Written for

  • CIOs and CTOs deciding whether to allow, ban or govern employee-built apps
  • Security and risk leaders who need the defect evidence, not the vendor deck
  • Platform teams designing guardrails for non-developer builders

Disclosure. The study is published by JetBridge, a software engineering company that also makes an enterprise vibe coding tool. Section 14 states that commercial interest and where the authors say they are the wrong answer.

Version 6.0 · August 2026 · JetBridge. Questions about the research are welcome — reply to the email that delivers your copy.Mobile ad kit