Discussion about this post

User's avatar
Rohan Jaiswal's avatar

Anthropic's '95% of shipped code written by Claude Code' figure and the '45% AI-generated code is insecure' counter from the comments belong in the same sentence to be meaningful. If both numbers hold, Anthropic is either accepting elevated security risk as a controlled experiment or has internal review tooling the rest of us don't see. From the AI builder side at theaifounder.substack.com, my hunch is the gap is closed by internal evals not yet published, and outside teams replicating the 95% number will hit a security wall in production. Which review process do you think outside teams need before adopting that ratio, and have you seen any open implementations?

richardstevenhack's avatar

"Humans review at the end."

Except someone asked Anthropic employees if they vibe code everything. All hands went up.

Then he asked how many do NOT review the code.

Many hands remained up.

This when we know - and studies have proven - that AI generated code is messy, unmaintainable (especially if you haven't reviewed the code, you not only don't know how it does what it does, you lose your skill at doing so) and over 45% insecure.

On top of which, more and more companies are finding out it actually costs more than they thought.

And what the AI security crisis caused by vibe coding and agentic AI proves is what I knew all along: the entire edifice of "software engineering" is built on sand - because it's not "engineering". It's a "craft."

And vibe coding is even less so. Unreliable LLMs trained on unreliable human "amateur engineers" are producing crap.

This is a catastrophe waiting to happen.

And "AI influencers' are encouraging it.

No posts

Ready for more?