Vibe coding’s $13.3 billion signal

Lovable’s $13.3 billion valuation puts a clear number on investor expectations for vibe coding. The Swedish startup lets users create software through natural-language instructions rather than conventional programming. Replit reached a $9 billion valuation in March. Indian AI coding startup Emergent became a $1.5 billion unicorn in July, while Bolt is approaching a $1 billion valuation.

These numbers do not prove that vibe coding will become a durable enterprise software category. They do show where investors expect future revenue to come from. The target is broader than software engineering. Vendors want business employees to create applications, interfaces, and prototypes directly with AI.

That changes the addressable market. Traditional AI coding products primarily improve the output of developers. Vibe-coding platforms aim to expand the population that can build software. An employee can describe a requirement in everyday language, review what the AI produces, and refine it through further prompts. This reduces the technical skill needed to turn a business requirement into working software.

The model follows part of the path established by low-code and no-code platforms, but generative AI lowers the interface barrier further. Users do not need to understand a visual development environment in the same way. They can state what they want and let an AI agent generate much of the application.

There is already evidence of use inside large companies. Lovable says its no-code AI product has reached employees at nearly two-thirds of the Fortune 500. That is a vendor claim, not evidence that two-thirds of those companies have formally adopted or approved the platform. The distinction matters. Employee use can spread faster than procurement, security review, or enterprise governance.

For the C-suite, the main constraint is therefore not access to the technology. It is controlled adoption. High valuations will fund better products, larger sales teams, and more direct marketing to business functions. Employees will encounter these tools whether or not central IT introduces them.

Executives should treat vibe coding as an emerging application-development channel. The opportunity is faster experimentation and a larger pool of people able to build useful software. The management task is to determine where that freedom creates measurable value and where professional engineering, security controls, and IT ownership must remain mandatory.

AI coding has already established the commercial case

Vibe coding is not emerging in isolation. AI-assisted development is already one of generative AI’s clearest enterprise applications. Products including Cursor, Windsurf, and Anthropic’s Claude Code have moved AI directly into software-development workflows. They help developers generate code, modify existing systems, find problems, and complete routine engineering work faster.

For executives, however, valuation and deal size are secondary. The important development is the change in how software gets produced. AI can now perform a meaningful portion of work that previously required a developer to write or edit code manually. This does not eliminate the need for engineers. It changes where their time can be spent.

Vibe-coding companies are pushing that model further. Cursor and Claude Code largely target people who already understand software development. Lovable and Replit also seek to make application creation accessible to employees who may not know how to program. The user describes the required outcome, and the system converts those instructions into software.

That distinction has major operating consequences. Improving a developer’s productivity changes engineering economics. Enabling employees in sales, finance, operations, or customer service to create applications changes who can initiate software development in the first place. It can shorten the distance between identifying a business problem and testing a possible solution.

The constraint then shifts from writing code to validating what the AI produced. Generated software still needs appropriate testing, security, data controls, architecture, and ownership. A prototype that works during a demonstration is not automatically suitable for production. As AI makes code cheaper and faster to generate, enterprises will need stronger processes for deciding which generated applications deserve to become maintained corporate systems.

The direction remains promising. AI-assisted coding has established a commercial foundation, and vibe coding is extending that capability to a much wider group of users. The companies that benefit most will not be those that generate the largest volume of software. They will be those that turn faster software creation into faster business outcomes without allowing quality and governance to deteriorate.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Vibe coding can cut the time from business idea to working software

The strongest enterprise case for vibe coding is speed. Business users often know the problem they need to solve but lack the programming skills to build a solution. They must document requirements, submit them to IT, wait for available development capacity, and then refine the result. Vibe coding can remove several of those steps.

Scott Weller, CTO at financial services technology provider EnFi, has seen that change directly. “What started as an engineering productivity initiative has become a company-wide capability, where anyone from the CEO to a customer success manager can turn an idea into a working prototype in hours, not weeks,” he told CIO.com’s Bob Violino.

The important word is “prototype.” Vibe coding can make experimentation much cheaper without making professional engineering unnecessary. An employee who understands a customer or operational problem can quickly test an idea, demonstrate it to colleagues, and determine whether further investment makes sense. IT teams can then focus their attention on the projects that have demonstrated business value.

This can also reduce pressure on development backlogs. Many internal software requests are relatively narrow: a new interface, a workflow tool, a small application, or a way to automate a repetitive process. Giving qualified business users controlled development capabilities can reduce the number of early-stage requests that require dedicated engineering resources.

But code generation is no longer the main constraint once software becomes easy to create. Review and ownership become more important. Someone still needs to decide whether an application is secure, whether it handles corporate data correctly, whether it duplicates an existing system, and who will maintain it after the employee who created it changes roles or leaves.

That distinction should shape executive policy. Business users can own problem discovery and rapid prototyping. IT can define the controls for production deployment. Applications that handle sensitive data, connect to important systems, or support critical processes should face stronger validation regardless of how quickly AI generated them.

Used this way, vibe coding can improve both speed and IT capacity. The objective should not be to maximize the number of employee-built applications. It should be to shorten the path from a useful idea to a validated business solution.

Hands-on vibe coding can make enterprise AI adoption more practical

AI adoption often struggles when employees cannot connect the technology to their daily work. Vibe coding addresses that problem by giving employees a concrete way to use AI against problems they already understand. Instead of learning AI as an abstract capability, they can use natural-language instructions to create or improve software for a specific task.

Skillsoft has expanded vibe coding beyond its development teams. Oral Daly, CIO at the training services provider, told CIO.com’s Bob Violino that practical use can change how employees perceive AI. “When people are learning and applying AI to solve a real business problem, it creates purpose and momentum,” she said.

Daly also said this approach helps employees move beyond seeing AI as “abstract or intimidating” and toward using it with judgment and collaboration instead of depending on rigid processes. According to Daly, solutions produced through vibe coding have filled capability gaps and reached production faster, creating measurable business value.

This matters because enterprise AI adoption depends on more than access to models and software licenses. Employees need to understand where AI can improve a process, where its output requires verification, and when human judgment remains necessary. Building something for a real business requirement can develop those skills more effectively than broad experimentation without a defined outcome.

There is also an organizational benefit. Vibe coding can bring business specialists and technical teams closer to the same development process. A finance, operations, or customer-service employee can express requirements directly through a working prototype. Developers and IT teams can review something concrete rather than interpreting requirements entirely from documents or meetings. That can reduce iteration time and expose unclear requirements earlier.

Executives should still distinguish AI participation from unrestricted software deployment. Wider experimentation can support learning, but production systems require governance. Employees need clear rules for approved tools, corporate data, system access, intellectual property, testing, and escalation to professional developers.

The opportunity is therefore broader than employee training. Vibe coding can build practical AI capability while producing useful business software. The strongest programs will connect that experimentation to real business problems, measurable outcomes, and clear production controls.

Governance becomes the main constraint when vibe coding spreads across the enterprise

Vibe coding makes software easier to create. It does not make software easier to govern. Once employees across finance, sales, operations, or customer service can generate applications, the number of systems requiring oversight can rise much faster than IT’s capacity to review them.

The core issue is control. Every application can introduce questions about identity, access rights, corporate data, regulatory obligations, software dependencies, and security. AI-generated code also requires validation. A tool can produce software that appears functional while containing weak authentication, insecure configurations, unnecessary permissions, or poor handling of sensitive information.

This creates a different management problem from conventional software development. CIOs may no longer know about every application at the point it is created. Waiting until deployment to impose controls is too late. Organizations need policies built into the development environment, including approved models and platforms, identity-based access, restrictions on sensitive data, logging, security testing, and defined approval requirements for production use.

Understanding the underlying business process is equally important. Noe Ramos, vice president of AI operations at Agiloft, told CIO.com’s Bob Violino: “Most companies, including ours, are still learning where work actually happens versus where they think it happens.”

Ramos identifies an important constraint. “Before you can extend AI into a business function, you have to understand the real workflow, not the documented one. That discovery work is underestimated almost everywhere.” Automating a process that management does not fully understand can preserve inefficient steps, miss informal controls, or create applications that do not match how employees actually work.

Executives should therefore resist measuring success by the number of applications generated. The more useful measures are business outcomes, time saved, defects avoided, security incidents, maintenance cost, and whether an application removes a genuine process constraint.

The goal is controlled decentralization. Business employees can have more freedom to prototype and solve local problems, while IT establishes the technical boundaries for data, identity, integration, security, and production deployment. Done well, governance enables broader adoption because executives can expand access without accepting uncontrolled risk.

AI coding agents need strict limits on production access

Speed can become a liability when an AI coding agent has permission to modify live systems. Whatever productivity these systems provide, an incident at that level makes one requirement clear. AI-generated actions affecting production systems need controls independent of the agent itself.

Geoff Burke, senior technology advisor at ransomware defense vendor Object First, describes the risk as a “seduction phase.” He told CIO.com’s Grant Gross: “At first, it feels like a brilliant partner. But give it too much autonomy and it injects inaccuracies, complexity, and bypasses security norms, which you will spend twice as long cleaning up later.”

The problem extends beyond dramatic failures. AI-generated code can work while still being expensive to maintain. It can introduce duplicated logic, unnecessary dependencies, weak error handling, security defects, or designs that conflict with an organization’s existing architecture. Fast code generation can therefore increase technical debt if review capacity does not grow with development volume.

This changes where organizations need to apply engineering discipline. Human review remains important, but review alone is not enough. Enterprises should restrict what AI agents can access and change. Development, testing, and production environments should remain separated. Database permissions should follow least-privilege principles. Critical changes should require explicit approval. Backups, version control, audit logs, automated security tests, and reliable rollback mechanisms should exist before agents receive meaningful autonomy.

Autonomy should also depend on consequence. An agent generating a disposable internal prototype presents a different risk from one modifying payment logic, customer records, authentication systems, or a production database. Higher-impact systems require stronger permissions, testing, review, and monitoring.

This does not weaken the business case for vibe coding. It defines the conditions needed to use it responsibly. AI can generate and modify software at a speed that conventional review processes were not designed to handle. Enterprises therefore need controls that operate at comparable speed.

For executives, the key metric is not how much code AI can produce. It is how much reliable business change the organization can deploy without increasing security incidents, outages, or long-term maintenance costs. Vibe coding creates value when faster development is matched by equally effective control.

Enterprise vibe coding needs more trust than consumer use

Natural-language software creation has a clear appeal. A user can describe an application, ask an AI system to build it, and refine the result through conversation. This can make prototyping faster and allow employees without formal programming skills to test ideas themselves.

But a working prototype is not the same as production-ready enterprise software. Consumer experiments can tolerate defects, limited support, and short product lifecycles. Applications that handle customer information, financial records, intellectual property, employee data, or core operations cannot. They need predictable behavior, controlled access, security testing, monitoring, documentation, and accountable ownership.

This makes trust the central enterprise requirement. Vendors need to demonstrate how their platforms handle corporate data, isolate customers, manage identities, control model access, track changes, and respond to security incidents. Enterprises also need clarity about whether customer code and data are retained or used for model training. These questions become more important when AI agents can generate code and connect to databases, APIs, cloud infrastructure, and internal systems.

Reliability is equally important. AI-generated applications can appear complete while containing errors that are difficult for a nontechnical creator to recognize. Business users may be able to judge whether an application meets a functional requirement, but they may not detect insecure code, weak data validation, poor architecture, or dependencies that create future maintenance problems.

Ownership must therefore continue after generation. Every production application needs a responsible team or individual. The organization must know who approves changes, handles failures, patches vulnerabilities, manages dependencies, and eventually retires the system. Faster creation increases the importance of these controls because the number of applications can grow quickly.

Executives should define different standards for experimentation and production. Low-risk prototypes can operate with greater freedom in isolated environments and with non-sensitive data. Applications that interact with important corporate systems should move through formal security, testing, compliance, and operational reviews.

The business opportunity remains strong. Natural-language development can reduce the cost and time required to explore new ideas. The companies that capture that value will treat rapid generation as the beginning of the application lifecycle.

Vendor funding will push vibe coding deeper into the enterprise

The capital behind vibe coding creates commercial pressure as well as technical progress. Lovable reached a $13.3 billion valuation after its Series C. Replit reached $9 billion in March. Emergent became a $1.5 billion unicorn in July, while Bolt is nearing a $1 billion valuation.

Those valuations raise expectations for future growth. Enterprise customers offer the contract sizes, recurring revenue, and expansion potential needed to support that growth. Vendors therefore have strong incentives to sell beyond developers and IT departments into functions such as finance, marketing, operations, and customer service.

Adoption may already be moving ahead of formal procurement. Lovable says employees at nearly two-thirds of Fortune 500 companies have used its no-code AI tool. That is a company claim and should not be interpreted as formal adoption by two-thirds of Fortune 500 enterprises. It does, however, illustrate how quickly employee-level experimentation can spread.

This creates a shadow IT problem for CIOs. Employees can now access powerful development tools through a browser and potentially build applications before IT has assessed the vendor. Those applications may process corporate information, connect to other services, or become important to a team’s operations without entering the normal technology inventory.

Blocking experimentation across the company is unlikely to produce the best result. A stronger approach is to make approved options easier to use than unapproved ones. IT can establish a small set of vetted platforms, provide secure development environments, define acceptable data classes, and create a clear route from employee prototype to approved production application.

Procurement also needs to look beyond current product features. The enterprise contract should address data retention, model training policies, intellectual-property rights, security responsibilities, auditability, service availability, export and deletion of applications, and the consequences of acquisition or service termination. These requirements matter because the market is still developing rapidly.

Competition is also increasing. Sid Sijbrandij, former CEO of GitLab, has entered the market with Kilo. More competitors can improve product choice and pricing, but they also make platform selection harder and increase the possibility of consolidation.

For the C-suite, the immediate task is visibility. Leaders need to know which vibe-coding tools employees already use, what information enters those systems, and which generated applications have become operationally important. The objective is not to prevent business-led innovation. It is to ensure that fast adoption does not create security, compliance, and continuity problems that only become visible after the software has become critical.

Vendor viability matters as much as product capability

The vibe-coding market is crowded, well funded, and still unstable. That makes vendor selection a business continuity decision. A platform can perform well today and still become a poor long-term choice if its economics, ownership, or technology dependencies change.

One structural issue deserves particular attention. Many vibe-coding startups depend on frontier AI companies for the models that power their products. Those model providers can also build competing coding products. The startup therefore may depend on a supplier with greater capital, computing capacity, distribution, and direct access to enterprise customers.

Harvard Business School professor David Yoffie has pointed to this problem. Yoffie is advising startups in the category to consider selling now because many compete with the same frontier AI labs that supply them. Those labs could also gain more financial capacity through potential IPOs.

Recent market activity demonstrates how quickly competitive positions can change. Windsurf entered a $3 billion OpenAI arrangement before talent ultimately moved to Google DeepMind in a $2.4 billion transaction. Whatever the merits of individual products, changes in ownership, personnel, model relationships, or strategy can alter an enterprise customer’s risk with little notice.

CIOs should therefore evaluate more than feature lists and demonstrations. Due diligence should examine the vendor’s funding position, revenue model, dependence on external AI providers, key-person risk, security practices, enterprise support, product roadmap, and ability to sustain operations. Contract terms should also address data portability, source-code or application export, service termination, and changes of control.

Architecture can reduce the impact of vendor instability. Enterprises should avoid unnecessary dependence on proprietary components when practical. Applications, business logic, data, and integration specifications should be exportable in usable formats. IT teams also need to understand how difficult it would be to move an application to another model or development platform.

The decision is not about identifying which startup will ultimately dominate. CIOs cannot reliably predict that outcome. The practical objective is to select useful technology while keeping the cost of changing suppliers within acceptable limits.

Security and governance remain essential selection criteria. But in this market, vendor durability belongs beside them. A platform that creates useful applications but leaves the enterprise unable to maintain or migrate them introduces a long-term operating risk.

Vibe coding could change the CIO’s role in enterprise technology decisions

Vibe coding changes more than software development. It changes who can initiate technology projects. A finance leader, operations manager, or customer-service team can potentially build an application without first securing dedicated development capacity from IT.

That shift can reduce the CIO’s direct control over technology spending. A business function may buy a vibe-coding platform from its own budget, generate applications, and connect them to daily workflows. The technology purchase may never appear on the central IT budget even though IT will eventually be expected to secure, integrate, support, or recover the resulting systems.

Trying to preserve authority by forcing every experiment through a traditional IT process would undermine much of the speed these tools provide. The stronger role for the CIO is to set enterprise rules while allowing business functions to operate within them. Identity, security, data access, architecture, procurement standards, and production controls remain enterprise concerns regardless of who pays for the software.

This issue reaches the CEO and the wider C-suite. CEOs are eager to demonstrate AI progress. Large startup valuations also draw executive attention to potential disruption and new business opportunities. That can create pressure to adopt tools before their enterprise value or operating risks are fully understood.

CIOs can provide the discipline that this environment requires. The question should not be whether the organization is “doing vibe coding.” The question is whether a specific use case produces a better business outcome than the available alternatives. Measures should include development time, employee productivity, operating cost, application quality, security exposure, maintenance requirements, and financial return.

The CIO is well positioned to lead that assessment. IT leaders strengthened their organizational position by navigating the pandemic, connecting technology strategy to business value, and directing the search for returns from AI investment. Those capabilities now matter more than ownership of the technology budget itself.

The broader management model should reflect that reality. Business leaders can own problems, budgets, and use cases. IT can establish the technical standards and shared infrastructure needed to deploy solutions safely. Security and risk teams can define controls according to business impact. This distributes responsibility without removing accountability.

Shadow IT remains a concern, but it is not the only reason to act. If business units can generate more software independently, the organization’s entire approach to application ownership, funding, maintenance, and retirement needs to evolve. CIOs should establish that operating model before employee-created applications become difficult to identify or govern.

Vibe coding can strengthen the CIO’s strategic role rather than diminish it. But that requires a shift in emphasis. Control over every technology purchase is becoming less realistic. Setting the conditions under which the whole company can use technology productively, securely, and with measurable returns is the more durable source of influence.

In conclusion

Vibe coding is moving faster than most enterprise control models. The technology can cut prototype cycles from weeks to hours and give business users direct software-building capability. The valuations behind Lovable, Replit, Emergent, and others ensure that vendors will keep pushing these tools into large companies.

For executives, the key constraint is no longer the ability to generate software. It is the ability to govern what gets generated. Security, production access, data handling, application ownership, and vendor continuity determine whether faster development creates business value or simply increases operational risk.

That calls for a deliberate operating model. Give employees room to experiment with approved tools and low-risk data. Set clear thresholds for moving applications into production. Require stronger controls as systems gain access to sensitive data and critical processes. Make every production application accountable to an owner, regardless of who created or funded it.

CIOs should lead this work without trying to own every purchase. Business units can identify problems and fund solutions. IT can define the standards that make those solutions secure, maintainable, and compatible with the wider technology estate.

Vibe coding should ultimately face the same test as any enterprise investment. It must produce measurable business outcomes at acceptable risk and cost. Companies that establish those rules now will be better positioned to use faster software creation as an advantage without losing control of the systems their businesses depend on.

Alexander Procter

August 14, 2026

20 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.