Vibe coding, Real liability: The cyber law risks businesses can’t ignore
Artificial intelligence has fundamentally changed how software is built. Today, a business owner with little or no programming experience can create customer portals, automate workflows, or launch internal applications simply by prompting an AI coding assistant.
The technology is impressive—but it also creates a dangerous misconception: that if AI wrote the code, someone else bears responsibility when things go wrong.
They do not.
From a legal perspective, organizations remain responsible for protecting the personal information they collect, regardless of whether an employee, contractor, or AI assistant wrote the application.
The new attack surface
AI coding tools dramatically lower the barrier to software development. Unfortunately, they also lower the barrier to introducing security vulnerabilities.
Common issues include:
- Exposed databases or cloud storage
- Missing authentication and access controls
- Hardcoded API keys or credentials
- Insecure third-party packages
- Failure to encrypt sensitive information
- Poor logging and monitoring
These vulnerabilities often remain unnoticed until a security incident occurs.
When a vulnerability becomes a legal problem
If customer information is compromised, the consequences extend far beyond technical remediation.
Organizations may face:
- State data breach notification obligations
- Regulatory investigations
- Consumer class action litigation
- Contractual claims from customers or business partners
- Cyber insurance coverage issues
- Reputational damage
The fact that AI generated the code is unlikely to provide a meaningful legal defense.
Regulators and courts generally evaluate whether an organization implemented reasonable security practices—not who or what wrote the software.
Governance matters more than ever
Businesses should treat AI-generated applications the same way they would traditionally developed software.
That means implementing:
- Security reviews before deployment
- Vulnerability scanning and penetration testing
- Code review by experienced developers
- Vendor risk assessments for AI platforms
- Written AI governance policies
- Employee training on secure AI use
AI can accelerate development, but it should not replace security or legal oversight.
Cyber insurance is also evolving
Many organizations assume their cyber insurance policy will automatically respond to incidents involving AI-built applications.
That assumption can be dangerous.
Insurers increasingly expect policyholders to maintain reasonable security controls regardless of how software is developed. Weak security practices surrounding AI-generated applications may become a significant issue during underwriting or claims investigations.
Organizations should ensure their AI adoption strategy aligns with both their cybersecurity program and their insurance requirements.
The bottom line
AI coding assistants are becoming a permanent part of modern business. They can increase efficiency, reduce costs, and empower innovation, but AI does not eliminate legal responsibility.
Organizations that move quickly without implementing appropriate governance, security testing, and legal oversight may discover that the speed of development.
If you have any questions about your company’s compliance with cyber regulations, concerns about vulnerability to attacks or other breaches, or if you want to learn more about proactive cybersecurity defense, contact a member of McDonald Hopkins’ national data privacy and cybersecurity team.