# Vibe coded apps are the new shadow IT

DevFeed: [Vibe coded apps are the new shadow IT](<https://devfeed.tech/articles/vibe-coded-apps-are-the-new-shadow-it-9249.md>)

Original publisher: [Read original article](<https://webflowmarketingmain.com/blog/vibe-coded-apps-security-baseline>)

Author: Andy Gombar

Published: 2026-08-13T00:00:00Z

Content type: article

Language: en

Sources: [Webflow Blog](<https://devfeed.tech/sources/webflow-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [App](<https://devfeed.tech/topics/app.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [iam](<https://devfeed.tech/tags/iam.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Vibe-coded internal applications can become a new form of shadow IT when AI agents rapidly generate code, provision cloud infrastructure, and deploy resources without tickets or security review. The article describes the resulting risks, including exposed endpoints, overpermissioned IAM roles, and production blast radius, and calls for platform controls, review gates, and detection.

## Source excerpt

Vibe-coded internal apps ship with IAM roles and no ticket filed. This baseline covers platform controls, review gates, and detection for what slips through.