What is vibe coding? It's building software by describing what you want to an AI tool in plain language, then running whatever code it writes without reading it. Unlike careful AI assisted programming, where you check every line, vibe coding judges the result only by whether the app seems to work.
Andrej Karpathy, a founding engineer at OpenAI and former director of AI at Tesla, named it in a post on X on February 2, 2025. He described a style where "you fully give in to the vibes, embrace exponentials, and forget that the code even exists." By November, Collins Dictionary had picked vibe coding as its Word of the Year for 2025. The term is everywhere now, and it's often used loosely, so it's worth knowing what it means and where it stops being safe.
What vibe coding means (and what it doesn't)
The short version: you talk, the AI types, and you don't look under the hood. You ask for a feature, try the result, paste any error back into the chat and ask for a fix. You keep going until it looks right.
That last part is the whole definition. Developer Simon Willison put it plainly in a March 2025 post. Say an AI wrote the code, and you reviewed it, tested it and could explain how it works. In his words, "that's not vibe coding, it's software development."
So the same tool can be used two ways. Ask an AI to build a page and ship it without reading a line, and you're vibe coding. Ask it to build the same page, then read the code and test it, and you're doing ordinary programming with a fast assistant. The difference isn't the tool. It's whether anyone checked the work.
How vibe coding works, step by step
Picture a small internal tool: a sign up form for a team workshop that saves names and emails to a spreadsheet. This is an illustration of a typical first session, not a log of one specific build. Every problem below is one that public guides warn about.
- You describe it. "Make a web page with a form for name and email. Save each entry to a Google Sheet and show a thank you message."
- The AI writes it. In a minute you have a page, a bit of styling and the code that talks to the spreadsheet.
- You run it and it breaks. An error appears. You paste it back. The AI suggests a fix, maybe installing a package or changing a setting.
- You repeat until it works. Ten minutes later the form saves entries. It looks done.
Here's what a quick review of that same tool tends to turn up. The AI may have placed the spreadsheet password, called an API key, right in the page code, where any visitor can read it. Nothing checks that the email field holds an email, so anyone can submit junk or something worse. The package it told you to install may not exist under that name, or may be a lookalike. GitHub's own guide to reviewing AI generated code lists these traps. It warns about "hallucinated or suspicious packages" and "hallucinated APIs, ignored constraints, or incorrect logic." It also flags tests "that are deleted or skipped, instead of fixed."
None of those problems show up when you try the form yourself. That's why "it seems to work" isn't the same as "it's safe."
Where vibe coding works well
Vibe coding shines when a mistake is cheap and you'll throw the code away anyway:
- Prototypes. You want to see an idea on screen before you spend real time on it.
- Personal tools. A script that renames your photos or a page that tracks your reading list.
- Internal experiments. A quick demo for your team that never touches customer data.
- Learning by poking. Building something tiny to see how the pieces fit, then asking the AI to explain what it wrote.
In all of these, the worst case is that you start over. If that's true for your project, vibe coding is a fast and fun way to get going.
Where vibe coding breaks
It breaks in three places: security, maintenance and anything real people depend on.
Security. AI tools now write code that runs, but running isn't the same as safe. Veracode tests AI models on coding tasks. In its Spring 2026 update, code that runs without syntax errors climbed from about 50% to over 95% since 2023. The share of tasks that produced secure code stayed near 55%. Defenses against cross site scripting, a common attack that injects code into a web page, passed only 15% of the time. Vibe coding skips the review that would catch those gaps.
Data and production systems. In July 2025, SaaStr founder Jason Lemkin was vibe coding an app on Replit. During a declared code freeze, the AI agent deleted his live production database. Replit's CEO called it "unacceptable" and added safeguards, and the data turned out to be recoverable. The lesson still stands: an agent with access to real data can do real damage.
Maintenance. Code nobody understands is hard to change. Six months later, the app needs a new feature. Now you're asking the AI to change code no human has read, and each fix can quietly break something else.
The rule of thumb: once the code handles money, logins, personal data or other people's work, stop vibing and start reviewing.
The review habit that keeps vibe coding safe
You don't have to give up the speed. You just add a checkpoint before anything leaves your laptop. Our guide on how to review AI generated code goes deep. Here's the short version for a small project:
- Run it and look for red flags. Do the tests pass? Did the AI delete or skip any test to make an error go away?
- Check every new package. Look each one up. Make sure it exists, it's the one you meant and someone still maintains it.
- Write down what must never happen. For the sign up form, that's two rules: the API key never reaches the browser, and the form rejects anything that isn't an email. Then test both.
- Ask the AI to explain its choices. "What assumptions did you make? Where are the secrets stored?" Treat the answer as a lead to check, not as proof.
- Read the risky lines yourself. Anything that touches logins, payments, deleting data or other people's information.
If you can't do step 5 yet, that's useful information. It tells you exactly what to learn next.
Does vibe coding replace learning to code?
For small personal projects, it can get you surprisingly far. For anything you want to put in front of customers, or get hired to build, no.
The skill that's in demand isn't typing code. It's judging whether code is safe to ship, and you can't judge what you can't read. Vibe coding is a great way to start and a poor place to stop.
Want structure for that next step? AI Flex is self paced, with an AI tutor and a monthly plan you can cancel anytime. Inside 4Geeks courses, our AI coding mentor Rigobot gives feedback on the code you write. You learn to read and fix code instead of just accepting it. If you're thinking about a full career change into building AI systems, AI Engineering is the longer path with mentors and career support.
Which tools do people use for vibe coding?
You can vibe code with almost any AI tool that writes code. People usually start with one of three kinds:
- Chat assistants, where you paste code back and forth by hand.
- App builders in the browser, which write, run and host the app in one place.
- Coding agents, which edit files and run commands in a project on your computer.
The more an AI can do on its own, the more a review matters, because it can change more before you notice. Our comparison of the best AI coding agents covers pricing, licenses and which one fits which job.
Go deeper
- How to review AI generated code before it ships, the full five check process
- Best AI coding agents compared, if you're picking a tool
- What is a prompt?, for writing clearer requests to any AI
- AI tools hub, tested picks sorted by the task you want done
