Vibe coders are gonna vibe code: How CISOs are tackling code sprawl

Vibe coders are gonna vibe code: How CISOs are tackling code sprawl — Cybersecurity | Versia.media

Security leaders from Datadog, Jamf, and ASOS discuss the growing visibility crisis quietly emerging as AI places code-writing capabilities into the hands of every employee.

"I spent the weekend burning through Claude tokens," the moderator remarked. "It's more fun than hanging out with friends."

He chuckled. The security leaders on the panel also laughed, perhaps with a hint of nervousness. They recognize the allure of leveraging AI to create automations and applications. They are also aware of what occurs when that same drive spreads across a company without safeguards.

This was a central theme of Workflow, a live online event hosted by intelligent automation platform Tines. The moderator, Andrew Steele, a Partner at Activant Capital, has spent ten years investing in enterprise AI and fully understands where personal experimentation ends and workplace risk begins. Unfortunately for IT and security leaders, many employees do not.

How do these leaders preserve visibility and control when AI equips every employee with code-writing abilities? This is the question he posed to Mario Villatoro, CISO at Jamf, Indu Sajeev, former CISO at ASOS, and Matt Muller, Director of Security Operations at Datadog.

The emergence of untamed code

Code sprawl is not a new phenomenon. However, in 2026, it is beginning to proliferate uncontrollably. Security and IT teams discuss code in the same way a gardener discusses weeds—spreading rapidly and threatening to overwhelm everything around them.

A report from RedAccess quantifies the issue: scanning vibe coding platforms such as Lovable, Base44, and Netlify, they discovered 380,000 publicly accessible assets—applications, databases, and related infrastructure—built without any security review, with roughly 5,000 containing sensitive corporate information.

It originates from multiple sources: AI features embedded in approved SaaS tools that are activated without IT review, scripts and automations constructed outside approved environments, and agents spun up by individual teams with no central oversight.

It is not necessarily malicious—on the contrary, it is often well-intentioned. And rather than simply tolerating it, many organizations are actively encouraging it. "Vibe coding" is appearing in job descriptions at Fortune 500 companies. Every employee who responds to that directive is a potential source of ungoverned code. The roots are already taking hold.

Watch all Workflow sessions now

Hear from leaders across IT and security on how they are actually implementing AI and automation in practice.

From securing AI systems, to demonstrating workflow ROI, to moving beyond pilots, these are genuine discussions about what is working, what is not, and what it takes to make AI operational in production.

Why policy alone is insufficient

"Employees who want to get their job done are by far the most persistent and successful APTs," Datadog’s Matt Muller stated. "If they believe that accessing the latest model will help them perform their job better, they will find a way, even if that means taking screenshots of their computer with their phone to transfer data to a personal account." Ban the obvious tools and the behavior typically shifts to less obvious ones, reducing visibility without decreasing exposure.

ASOS’s Indu Sajeev was explicit about the limitations of the conventional governance playbook: "I don't think it can be a paper-based, policy-based governance layer. It needs to be something that's codified and that runs continuously at a critical infrastructure level."

What security leaders are doing today

Starting with data classification

Before any more advanced approach can succeed, there is unglamorous groundwork to be done, Villatoro said. "Do you have your data categorized correctly? Because if you just say 'sensitive data', well, what is sensitive data? Having the data correctly tagged is critical."

Without that foundation, every downstream control—access permissions, agent governance, audit trails—is built on unstable ground.

Becoming the hub, not the gatekeeper

Muller's approach at Datadog has been to position the security team as the people who supply the tools, not the people who police how they are used. "One thing that's been really effective is serving as the centralized hub, not of the activity, but the tools to perform the activity," he said. "Make Claude skills available in an internal marketplace. Our only ask to engineering teams is: when you use it, give us feedback, help us improve the skill."

This approach works when the builder is an engineer. But code sprawl extends beyond engineering, into functions like HR, marketing and finance, where security awareness is rarely a job requirement.

The core principle holds: make the governed path more appealing than the ungoverned one. "I want everybody going down one funnel for AI usage,” Muller said. “That way, even if I don't like what's happening, I can at least see that it's happening versus forcing people into shadow channels."

Building a use-case registry

At ASOS, Sajeev tackled the visibility problem with a use-case registry, treating AI agents like infrastructure assets rather than software features.

"It organically transitions into: this was created for this specific use case, this is the human identity behind this agent," she said. The registry is not just an inventory. It makes accountability traceable—when something goes wrong, you can follow the thread back to a person and a purpose. It also surfaces the underlying data problem that tends to hide until an incident forces it into the open. "You need to be at a very mature level with your data infrastructure for any of your agentic or AI functions to work."

Investing in enablement

At Jamf, Villatoro's approach centered on enablement over restriction, giving employees the right tools, training, and acceptable use policies before they go looking for their own solutions.

"If we work on the enablement part, it's a lot easier to prevent wild code just sprawling everywhere," he said. "But if we don't enable the employees, they're going to look for ways to enable themselves, and that's what leads to problems."

The problems still to be solved

AI agents behaving unexpectedly

Muller asserts the need to observe and contain unexpected AI behaviors before they become a problem. "When Claude Code figures out it can't access something, there are scenarios where it tries to effectively build its own malware to exfiltrate the credentials it needs," Muller said. "Rather than having a policy that you can't use Claude Code to do these things, we think it's more valuable to invest in the technical controls that prevent it from reaching those credentials in the first place."

The permissions gap

Even when organizations make deliberate decisions about AI tool usage, the controls available are often too broad to be meaningful.

"We can say 'we approve Claude connecting to Gmail,'" Muller said. "What I'd love is to say, ‘I'm comfortable with my assistant reading emails tagged with a certain label, and none of my other emails.’ I can't express that today."

Sajeev pointed to a deeper gap in existing security frameworks: "Zero trust works well on human identities. It's still a gap everywhere else, and we have so many different ecosystems now." Organizations are largely dependent on first-party providers whose controls can lack granularity. Muller was direct: "If anyone from Google is watching this, we could use more granular OAuth permissions."

The path forward

The security leaders who effectively tame code sprawl will not be the ones who tried to stop employees from building. They will be the ones who made the governed path the most appealing one—safe enough to use openly, visible enough to audit.

Wild code is already inside the building. The question is not how to prevent it. It is how to track, secure and monitor it.

Watch the Workflow virtual event by Tines on demand at https://watch.workflow.live/ .

Sponsored and written by Tines.

← Cybersecurity