The Vibe Coding Revolution Is Real — But Incomplete
Let me be direct: AI-assisted development — what the industry has started calling "vibe coding" — is the most significant shift in software engineering since the move from waterfall to agile. At AMT, we've been deep in this space for months now, building production systems with AI coding assistants, and the productivity gains are genuine. What used to take a team two weeks can sometimes be prototyped in a day.
But here's the part nobody's talking about at the conferences: the gap between a working prototype and production-ready software has never been wider. AI can generate code at extraordinary speed. It cannot, by itself, guarantee that code is secure, performant, or even correct beyond the happy path.
This article is my attempt to share what we've learned — a disciplined framework for vibe coding that captures the speed benefits without sacrificing the engineering rigour that keeps systems running in production.
The Testing-First Rule: No Exceptions
The single most important discipline in vibe coding is this: test after every single iteration. Not after five iterations. Not "when it looks done." After every prompt cycle, you verify.
Why is this so critical? Because AI-generated code has a specific failure mode that's different from human-written code. A human developer who breaks something usually knows they broke it — they changed a function, and they have mental context about what that function touches. An AI assistant has no persistent memory of your system's interdependencies. It can fix one component while silently breaking three others.
Our workflow at AMT looks like this:
- ▹Write a clear, scoped prompt — One feature, one change, one fix at a time.
- ▹Review the generated code — Not line by line (that defeats the purpose), but structurally. Does the shape of the change match your intent?
- ▹Test immediately — Run the app. Click through the affected flows. Check the console. Every time.
- ▹If it breaks, don't stack more prompts on top — Stop. Diagnose. Then prompt with the diagnosis.
GitHub Diffs: Your Debugging Superpower
Here's a technique that has saved us hundreds of hours: when something breaks, read the Git diff before you do anything else.
Most developers using AI assistants make the same mistake when things go wrong — they describe the problem to the AI and ask it to fix it. This creates a cycle: the AI generates a "fix" that introduces new issues, which prompts another fix, which introduces more issues. We call this the "fix spiral," and it's where most vibe coding projects die.
Instead, go to your version control. Look at exactly what changed since the last working state. The diff tells you the ground truth — not what the AI thought it changed, but what actually changed. Nine times out of ten, the bug is obvious in the diff. A deleted import. A renamed variable that wasn't updated everywhere. A conditional that got inverted.
Once you see the actual problem in the diff, you can write a surgical prompt: "In file X, line Y, you changed Z — this broke the connection to component W. Revert that specific change while keeping the rest." That's a prompt the AI can execute correctly because you've given it precise context.
The Domain Expertise Problem
There's a narrative in the vibe coding community that goes something like: "Now anyone can build software, even without technical knowledge." This is simultaneously true and dangerously misleading.
Yes, a non-technical founder can use an AI assistant to build a working prototype. I've seen it happen. But here's what I've also seen: that same founder ships the prototype with an open API endpoint that exposes every user's data. Or with a database schema that works for 100 users but collapses at 10,000. Or with hardcoded API keys sitting in the frontend JavaScript.
The AI doesn't know what it doesn't know. It will happily generate code that "works" while being fundamentally insecure, unscalable, or architecturally broken. It won't warn you. It won't say, "By the way, this endpoint should require authentication." It just does what you asked.
This is where domain expertise becomes more valuable than ever, not less. In the age of vibe coding, the role of the experienced engineer shifts from writing code to seeing what's wrong with generated code. It's a completely different skill — pattern recognition, architectural awareness, security instinct — and it can't be replaced by AI because the AI is the one creating the problems you need to catch.
Choosing Your AI Tooling: It Matters More Than You Think
Not all AI coding assistants are equal, and the differences matter enormously for production work. We've tested extensively across multiple models and platforms, and here's our honest assessment:
The model quality directly impacts how much debugging you'll do. A better model doesn't just generate better code — it understands your prompts more accurately, maintains context better across long conversations, and makes fewer of those subtle errors that take hours to diagnose.
Our recommendation: invest time in evaluating different AI coding tools before committing to one for a production project. The time you save with a better model dwarfs the time spent evaluating. Pay attention to:
- ▹Context window — How much of your codebase can the model "see" at once? Larger context means fewer errors from missing dependencies.
- ▹Instruction following — Does it do what you asked, or what it thinks you meant? The best models follow precise instructions without creative interpretation.
- ▹Code consistency — Does it match your existing code style, or does every generation feel like a different developer wrote it?
- ▹Error recovery — When you point out a mistake, does it fix it cleanly, or does it introduce new problems?
The Screenshot Method
One technique we've developed that's surprisingly effective: screenshot-based prompting. When something looks wrong in the UI, don't describe it in words — take a screenshot, annotate it ("this button should be here, not here"), and include it in your prompt.
AI coding assistants that support image input can interpret visual problems far more accurately than text descriptions. "The modal is misaligned" could mean fifty things. A screenshot with an arrow pointing to the problem means exactly one thing.
We've found this reduces the average number of prompt cycles for UI fixes from 3-4 down to 1-2. That's a meaningful productivity gain when you're iterating on interfaces all day.
Who Controls the API Layer Wins
Here's the strategic insight that ties everything together: in the age of AI-generated code, whoever controls the API layer controls the product.
Think about what's happening structurally. AI tools can now generate frontend code, backend logic, database queries, and infrastructure configuration. The speed at which any of these layers can be rebuilt from scratch is approaching zero. If your competitor can regenerate their entire frontend in a day, your frontend isn't a competitive advantage.
What can't be regenerated? The API contracts. The interfaces between your services, the data models, the authentication flows, the rate limiting, the webhook configurations, the third-party integrations. These represent accumulated business logic, real-world edge cases, and hard-won architectural decisions.
At AMT, we now advise clients to think of their API layer as their primary intellectual property. Document it obsessively. Version it carefully. Test it rigorously. The code above and below it can be regenerated by AI. The API layer is where your domain expertise lives.
Security Audits for AI-Generated Code: Non-Negotiable
Let me be blunt about something the industry needs to hear: every production deployment of AI-generated code needs a security audit. Period.
AI coding assistants have a systematic blind spot around security. They optimise for functionality — making things work — not for safety. Common security issues we find in AI-generated codebases:
- ▹Missing authentication on API endpoints — The AI creates CRUD operations but doesn't add auth middleware unless explicitly asked.
- ▹SQL injection vulnerabilities — Less common with modern ORMs, but still appears when the AI writes raw queries for "performance."
- ▹Exposed environment variables — API keys and secrets placed in frontend code or committed to version control.
- ▹Overly permissive CORS — The classic `Access-Control-Allow-Origin: *` that the AI adds to "fix" a cross-origin error.
- ▹Missing input validation — The AI trusts all input by default. It doesn't add validation unless you specify it in the prompt.
We now offer security audits specifically designed for AI-built projects. The methodology is different from traditional code review because the failure patterns are different. We're not looking for logic errors a developer made — we're looking for security assumptions the AI never made.
The Three Services Every Vibe Coder Needs
Based on everything we've learned, we've crystallised our vibe coding support into three service offerings:
1. Prompt Engineering Training — Teaching your team how to communicate effectively with AI development tools. This includes prompt structure, context management, screenshot-based debugging, and knowing when to prompt vs. when to code manually.
2. API Layer Architecture — Designing, documenting, and building the API middleware that AI tools can consume. This is the structural foundation that makes vibe coding sustainable for production applications.
3. Security Audit for AI-Built Projects — Professional review of AI-generated codebases before they go to production. We interpret the security warnings that non-technical builders cannot assess and provide actionable remediation plans.
These aren't theoretical offerings — they're born from doing this work ourselves, every day, on production systems for real clients.
The Bottom Line
Vibe coding is here to stay. The productivity gains are too significant to ignore, and the tools are improving rapidly. But the gap between "it works on my screen" and "it's ready for production" requires human expertise — specifically, the kind of battle-tested engineering judgment that comes from decades of building and shipping software.
At AMT, we've been building production systems for 23 years. We've seen every paradigm shift from CGI scripts to microservices to serverless. Vibe coding is the next evolution, and like every evolution before it, the teams that thrive will be the ones that combine new tools with proven engineering discipline.
Don't vibe code alone. Vibe code with guardrails.