gshc2020.com

Council Post: Vibe-Coded Apps Are Multiplying Fast. Who Protects Users When They Break?

tags:
@ 24/07/2026

Oleksandr Kosovan is a Ukrainian tech-entrepreneur, Founder and CEO of MacPaw.

getty

​Something significant is happening in software. In the first quarter of 2026, App Store submissions jumped 84% year-over-year. Last year alone saw nearly 600,000 new apps submitted—the largest wave since 2016. The force behind it: vibe coding.

This isn't just developers moving faster. According to Vercel's State of Vibe Coding report, 63% of people building with these tools aren't developers at all. They're designers, marketers and individuals who have never shipped a line of code in their lives.

That is genuinely exciting. More people building means more experimentation, more diverse ideas and more problems getting solved that traditional dev teams would never prioritize.

But we've lowered the cost of creating software without lowering the cost of its consequences. And that disconnect is growing faster than most people in this industry want to admit.

When The Prototype Becomes The Product

The signature of vibe-coded software is that the prototype looks real faster than the underlying engineering becomes real. A utility app can have a polished interface, a professional landing page and a functional demo coded in hours. What it might not have—and what the app’s users can’t see—is proper error handling, sound permission models, secure data practices or architecture built to survive the next OS update.

​This matters the most at the system level. Our engineering team recently reviewed several vibe-coded CleanMyMac alternatives appearing on GitHub, many advertised as free versions of established tools. The patterns were consistent: tools that told users the tasks were complete while actually returning incorrect or empty results. Apps that deleted files or force-quit other applications without confirming, or giving users a way to undo the damage. Tools that requested powerful system permissions and then mishandled them, producing unreliable results while seeming to work normally. ​

More concerningly, several utilities were performing actions at the operating system level, where mistakes create the same vulnerabilities that malware exploits. The research backs this up: an independent analysis found that AI-generated code produces 1.7 times as many major issues as human-written code, and 45% of AI-generated samples fail security benchmarks outright. The code looks like it works.

The app looks like it's ready. But "looks like" is no longer a reliable indication of trustworthiness, security or quality.​

The Trust Gap Users Can’t See

Most non-tech users judge software by how it looks and whether it appears to work. That’s because they can’t audit code. They don’t review how an app handles their data. They can’t tell the difference between an app built by a team that’s been navigating macOS changes for a decade and one assembled in an afternoon by someone who’s never shipped a product. At MacPaw, we've spent more than 17 years building and maintaining software for millions of Mac users worldwide. One lesson has remained constant throughout every macOS transition: trust isn't earned when software launches—it's earned through years of updates, security oversight and accountability when things go wrong. ​

There’s a common assumption that if an app passes the platform’s security checks and appears in the App Store, it must be safe. But that doesn’t confirm that the app was built by someone who deeply understands macOS and has real experience and expertise with the system. It just confirms they know how to write code or prompt an LLM to write it for them.​

This assumption creates a gap—software can look trustworthy long before it actually is. And as AI-generated tools get access to more sensitive parts of people’s systems and workflows, that gap becomes a real problem. This is exactly why ecosystem-level responsibility matters.

The Industry Is Getting This Wrong In Three Ways

First, treating generated code like it’s ready for production. Code that works in a demo can fail in ways that are hard to predict once real users depend on it. Fast output is not the same thing as quality and security. ​

Second, rewarding speed over responsibility. The industry celebrates launches, not maintenance. But for users, the app they installed six months ago matters more than the one announced today, especially if that app has access to their files, their data or their workflows. Software at that level requires continuous engineering work to stay reliable. What’s safe to do in one version of an operating system can cause damage in the next. ​

Third, assuming users understand the risks. Most people evaluate software the same way they have for years or decades: does it look professional? Does it appear to work? They’re not in a position to assess what’s happening underneath the polished surface. In the vibe-coding era, the gap between what users can see and what’s happening inside an app is widening. ​​

What Responsible AI Software Actually Looks Like

None of these industry errors are an argument against all AI-assisted software development. Every software company—including ours—is using AI in internal workflows. It’s a natural and exciting evolution of how we build software. ​

But AI is raising the bar for good engineering judgment. The work shifts from writing every line of code by hand to designing systems, maintaining reliability, overseeing security and ensuring long-term quality. Engineering’s true value now is in knowing how systems should behave, how they should scale and how they should fail safely. ​​

The companies that win in this next phase won’t be the fastest at shipping software. They’ll be the ones that combine AI-enabled speed with real operational discipline and long-term product ownership.

The Real Test Lies Ahead

The AI software boom isn’t slowing down, and it shouldn’t. The fact that more people can build software than ever before is one of the most important shifts in this industry's history.

But creation without accountability is just noise, not progress. The tools are moving fast. The standards need to move with them. ​

Users won’t remember which company built software the fastest. They will remember which companies they could trust when things went wrong.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?