Vibe coding vs. AI-assisted engineering: what founders should know
Both use AI to write code. Only one leaves you with something you can maintain a year later.
In the past year, “vibe coding” has gone from an in-joke to a business model. Describe an app in a chat window, accept whatever the AI produces, keep prompting until it works. For a weekend prototype, it’s brilliant. For a product people pay for, it’s a loan with a high interest rate.
We use AI tools every day at Sampan Labs, and we think founders should too. But there is a difference between using AI to write code and using AI to avoid understanding code. Here is how we draw the line.
What vibe coding gets right
Speed to a first version is real. A founder can now validate an idea with a working prototype in an afternoon instead of hiring an agency for a month. We encourage clients to do this before they talk to us; it makes the first conversation much better.
Where it breaks
- Nobody understands the code. When something fails at 2am, there is no one who knows why it was written that way.
- Security is accidental. AI tools happily generate code that stores passwords badly, trusts user input or exposes admin routes.
- Every change gets harder. Without structure, each new prompt adds another layer. By month three, fixing one bug creates two more.
- There are no tests. So there is no way to know whether today’s change broke last week’s feature.
What AI-assisted engineering looks like
In our projects, engineers design the architecture, data model and security approach first. AI tools then help with the parts that are well understood and repetitive:
- Scaffolding screens and API endpoints that follow an existing pattern
- Writing test cases, especially edge cases humans forget
- Data migrations from old spreadsheets and systems
- First drafts of documentation and code comments
Every AI-generated change goes through the same pull request review as human-written code. The reviewer has to be able to explain it. If they can’t, it doesn’t merge.
The test is simple: could a new engineer understand this codebase in a week without asking the AI that wrote it?
Questions to ask any team you hire
- Which parts of the code will be written with AI tools, and which won’t?
- Who reviews AI-generated code, and what do they check?
- What is the test coverage, and who writes the tests?
- Will my data or code be used to train anyone’s model?
- If you disappeared tomorrow, could another team take this over?