Home » Vibe Coding Security Risk: 20i Finds 1 in 5 Firms Already Breached

Vibe Coding Security Risk: 20i Finds 1 in 5 Firms Already Breached

20i’s vibe coding security survey finds one in five firms hit by a breach linked to AI-assisted coding. Here’s what UK SMEs should do next.

Hands typing on a laptop keyboard representing vibe coding security risks

If your staff are using AI tools like Cursor or Claude Code to knock together internal tools without telling IT, you are not alone, and that is exactly the problem. Hosting provider 20i has published survey findings on vibe coding security, showing that one in five organisations using so called “vibe coding” have already had a security breach linked to it, a risk that echoes the account takeover tactics used by the Gentlemen ransomware gang.

20i’s research, covered in the original announcement, found that one in five organisations using AI-assisted coding have had a security breach connected to the practice. Vibe coding is the term for building software, web pages or automations by describing what you want to an AI tool rather than writing code by hand, and 20i surveyed 600 non-developers to see how widely it has spread through ordinary workplace roles.

The numbers point to a tool that has quietly become mainstream. Just over half of respondents (51.1%) had very limited or no coding experience before using AI, yet nearly three-quarters (73.5%) now feel confident generating code on their own. Almost half (47.7%) said the main reason they use it is simply to get more done, not to replace anyone.

What should worry small business owners is what happens after the code is written. Fewer than a third of AI-generated code (31.5%) is checked by a professional developer, and 9.3% of users do not verify it at all, a governance gap our guide on writing an AI usage policy for small businesses is designed to close. Most people (61.0%) just test their own work. Given that respondents were also using these tools for riskier jobs, including API integrations (14.0%), database queries (13.5%) and custom plugins (7.0%), that is a lot of unchecked code sitting inside live systems. Businesses wanting to set boundaries on this kind of experimentation can start with our practical guide on writing an AI usage policy.

20i’s survey covered non-developers in the US, so the exact percentages will not map neatly onto a UK office. But the underlying pattern, non-technical staff building tools faster than anyone is checking them, is not a US-specific problem. It is the same gap SME owners have already been warned about in reporting on an autonomous AI attack on a small business, and it fits the pattern behind wider staff security failures, as seen in the recent Egress research on staff scam awareness.

The governance side is the real gap. Only 26% of organisations in 20i’s survey have a formal policy covering AI-assisted coding, meaning roughly three-quarters are letting it happen under informal guidance or no rules at all. That mirrors what this magazine has already set out in its guide to writing an AI usage policy, and the stakes are the same ones covered in coverage of ransomware gangs targeting small businesses: one unchecked tool with access to customer data is all it takes.

Big technology firms including Google, Microsoft and Spotify are already building AI heavily into their own development workflows, and job adverts increasingly ask for familiarity with AI coding tools across design, marketing and operations roles, not just engineering. That is the direction of travel for smaller firms too.

What to do next: if staff outside your IT or dev team are already using AI to build spreadsheets, scripts or internal web tools, find out now rather than after something breaks. Set a simple rule that anything touching customer data, payments or a live website gets a second pair of eyes before it goes live, and put that rule in writing so it survives when the person who wrote the code moves on.