TL;DR
Key takeaways
- AI-assisted coding is now mainstream, but trust remains limited.
- Coding agents can complete multi-file tasks instead of simply suggesting the next line.
- Token usage, code review, security, and maintenance are becoming measurable costs.
- Enterprise adoption brings stricter controls over access, deployment, and accountability.
- Specifications, human review, and production hosting matter more as agents take on larger tasks.
Ask AI about this post:
Vibe coding looks very different from when the term first appeared in early 2025.
It started as a way to build software by describing what you wanted and working with AI-generated results. By 2026, coding agents can plan tasks, edit multiple files, run tests, and prepare code for review.
Use is growing quickly, but trust has not kept pace.
Builders must now consider cost, security, maintenance, and oversight alongside speed.
This guide looks at the data behind the biggest vibe coding trends and what they mean for anyone investing time, money, or a team in AI-assisted development.
Vibe Coding by the Numbers in 2026
Recent developer surveys and platform data show how quickly AI-assisted coding has grown:
- Sonar's 2026 survey of 1,149 professional developers found that 72% of AI-tool users used them daily. Respondents estimated that AI generated or assisted 42% of committed code.
- The same survey found AI in 88% of prototypes, 73% of customer-facing applications, and 58% of business-critical services.
- Yet 96% did not fully trust AI-generated code to be functionally correct, and only 48% completely agreed that they always checked it before committing.
- Between May and September 2025, GitHub reported that developers merged more than one million changes proposed by its coding agent through pull requests. It also recorded 518.7 million merged pull requests in its 2025 reporting period, up 29% year over year.
- Lovable reported reaching $100 million in annual recurring revenue in July 2025, with more than 10 million projects created on its platform.
The Sonar survey, GitHub activity data, and Lovable’s company-reported figures measure different groups and should not be combined into a single adoption rate.
Together, they show that AI-assisted coding is widely used even though professional trust remains limited.
Is Vibe Coding Over?
No, but its original meaning has narrowed.
In February 2026, Andrej Karpathy proposed agentic engineering as a name for professional work in which people direct coding agents and review what they produce.
Vibe coding still describes the more casual approach of accepting AI output without closely reading the code.
What is losing credibility is shipping code that nobody has reviewed, tested, or understands.
Agentic engineering adds clear requirements, limited permissions, automated tests, review steps, and clear ownership.
The Trends Shaping Vibe Coding in 2026 and Beyond
Seven changes now define how vibe coding is used, priced, reviewed, secured, governed, and hosted. These are shifts already visible in developer research and platform activity, not predictions about what might happen.
The Practice Split Between Professionals and Solo Builders
The same AI coding tools now support two very different working styles:
- Solo builders may judge an application by whether its visible features work.
- Professional teams are more likely to review every code change, require tests, and limit what an agent can access.
Lovable’s growth shows strong demand for the first approach.
Professional data provides the counterweight. Sonar found that 38% of developers considered AI-generated code harder to review than code written by a colleague, while 61% said AI often produces code that looks correct but is unreliable.
The real divide is between unverified output and accountable delivery.
Agents Replaced Autocomplete
Autocomplete suggested the next line of code. Agents can inspect a repository, where a project’s code and change history are stored, modify several files, run commands, and prepare changes for review.
GitHub’s 2025 Octoverse report counted more than one million pull requests generated by its coding agent and merged by developers between May and September 2025.
GitHub cautioned that its repository comparisons may reflect differences between the projects being compared. The figure shows widespread use, not proof that agents improve productivity.
Even with that limit, AI coding has clearly moved from suggesting individual lines to handling complete tasks.
Costs Shifted From Seats to Tokens
Flat subscriptions made a failed attempt feel like lost time.
Consumption pricing also puts that failure on the invoice because longer sessions, repeated prompts, and larger amounts of project context use more tokens, the units used to measure text processed by an AI model.
Gartner warned in June 2026 that token-based pricing creates unpredictable costs.
It forecast that AI coding costs could exceed the average developer’s salary by 2028, although it did not publish one universal monthly cost per developer.
Teams can control spending by:
- Tracking cost per accepted task
- Limiting unattended agent runs
- Providing only the necessary project context
- Using less expensive models for simpler work
Maintainability Became a Measurable Cost
Maintenance problems rarely appear in the first demo.
They emerge later, when requirements change and the generated structure becomes difficult to modify safely.
A GitClear analysis of 211 million changed lines found that refactoring, or restructuring code without changing its behavior, fell from 25% of changed lines in 2021 to less than 10% in 2024.
Copy-pasted lines rose from 8.3% to 12.3% over the same period.
The study was observational and cannot prove that AI caused the changes.
A May 2026 preprint, a research paper shared before formal peer review, analyzed 3,238 commits and found that AI-generated files received less immediate maintenance, while human developers still performed about 83% of their later changes.
Less maintenance is not proof of better code because those files may be lightly used or difficult to understand.
Security Findings Scaled With Commit Volume
Faster code generation gives security checks more code to cover.
The concern is not only that more code creates more findings, but that AI-assisted changes may contain more issues per pull request.
CodeRabbit analyzed 470 open-source pull requests and found that AI-associated pull requests contained about 1.7 times as many issues overall.
Security findings were up to 2.74 times as common in some categories. Because the researchers had to infer whether AI helped create each pull request, the results have limits.
Teams can reduce the risk with:
- Automated scanning on every pull request
- Minimal permissions for coding agents
- Protected credentials and application programming interface keys
- Human approval for production changes
- Tests focused on likely security threats
For examples of individual incidents, see whether vibe coding is bad.
Governance Arrived With the Enterprise
Once AI-built tools reached company data and production systems, security and audit teams became part of the buying decision.
Retool’s 2026 survey found that 93% of senior technology and security leaders were concerned about vibe-coded tools in production. Only 8% described their internal-tool governance as strong.
The difference between roles was also clear. While 71% of chief technology officers called AI coding a net positive, only 47% of chief information security officers agreed.
That 24-point gap helps explain why enterprise rollouts can stall: engineering leaders see faster output, while security leaders see untracked applications, data access, and unclear responsibility.
Production Hosting Became a Separate Decision
AI app builders can generate a prototype or codebase, but that does not decide where the application will run, how releases will be controlled, or who will maintain it.
Modelence Cloud provides production hosting for applications that meet its framework and hosting requirements.
Before choosing it as the production host, confirm that the application meets those requirements and that its deployment process, security and data needs, background tasks, expected traffic, logs, alerts, backups, and portability fit the available hosting setup.
What’s Next for Vibe Coding
The next stage of vibe coding is becoming easier to see.
Current tools and named forecasts point to three changes: clearer specifications, longer agent runs, and broader enterprise use.
Specifications Move Ahead of Prompts
A prompt tells an agent what to do in one exchange.
A specification records the requirements, limits, and tests the finished work must meet.
GitHub’s open-source Spec Kit and Kiro both support this approach. For someone building alone, the process can stay simple:
- Write the user stories and essential requirements.
- Turn them into a technical plan.
- Break the plan into small tasks.
- Let the agent complete one task at a time.
- Check each result against the specification.
The specification does not need to be long. It only needs to make the expected result clear before coding begins.
Agents Run Longer Without Supervision
Agents can already work across a repository, run tests, and revise their output. Longer runs will allow them to complete larger tasks, but they will also give mistakes more time to spread.
A wrong assumption made five minutes into a two-hour task can waste tokens and affect many files.
Longer runs therefore need:
- Checkpoints that reveal whether the work is still on track
- Spending limits that stop excessive token use
- Isolated environments that protect production systems
- Reversible changes that can be rolled back
- Approval before sensitive actions
Longer agent runs are valuable only when the system can detect and stop a wrong turn.
What the Forecasts Say Through 2028
Gartner has published two major forecasts:
- In July 2025, it forecast that 90% of enterprise software engineers would use AI code assistants by 2028, up from less than 14% in early 2024.
- It expects developers to spend less time on implementation and more on directing agents, designing systems, solving problems, and checking quality.
- In June 2026, it forecast that token-driven AI coding costs could exceed the average developer’s salary by 2028.
These are forecasts, not guaranteed outcomes. Model prices, hardware efficiency, competition, and better ways of working could change what happens by 2028.
What Do These Trends Mean for the Future of Software Engineering?
Vibe coding is changing engineering jobs more than eliminating them.
As agents handle more routine implementation, engineers are spending more time on:
- Defining problems and requirements
- Designing systems and architecture
- Reviewing code for quality and security
- Making product decisions
Sonar’s respondents ranked reviewing and validating AI-generated code as the most important skill for the AI era, ahead of prompting.
Speed gains are not automatic.
In a 2025 randomized study, Model Evaluation & Threat Research (METR) asked 16 experienced open-source developers to complete 246 tasks in mature repositories they knew well. With the AI tools available at the time, they took 19% longer, even though they believed AI had made them faster.
That narrow study does not represent every development workflow.
It does show why teams should measure completed work rather than lines of code or perceived speed.
The engineer’s role is moving toward that of an accountable operator who can direct agents, identify weak output, and take responsibility for what reaches users.
From Vibe Coding to Production Hosting With Modelence
Modelence Cloud provides production hosting for applications that meet its framework and hosting requirements.
Before deploying, confirm that the application meets those requirements and that its database connections, background tasks, compliance needs, and expected traffic fit the available hosting setup.
After confirming these requirements, try Modelence Cloud for app hosting.
Frequently asked questions (FAQs)
Is vibe coding still worth learning in 2026?
Yes. Natural-language development is becoming a common way to create software. Learn it alongside specifications, version control, testing, security basics, and code review.
Can an app built this way pass a security review?
Yes, if it receives the same checks as any production application. Review dependencies, credentials, permissions, likely attack paths, and how sensitive data moves through the system.
What does it cost to run AI coding agents for a small team?
Costs depend on the models, token prices, project size, task length, retries, and included usage. Run a limited pilot and track the cost of each accepted task before setting a wider budget.
Do I need a developer to maintain an app I built with AI?
For a production app, you need someone who can understand the system and handle incidents, updates, security, and data. That may be an employee, agency, or support provider.
What Requirements Must an Application Meet for Modelence Cloud Hosting?
The application must meet Modelence Cloud’s framework and hosting requirements. Before deploying, confirm that its database connections, background tasks, security requirements, expected traffic, and other services fit the available hosting setup.
How do I move an app off a vibe coding platform without a rewrite?
Sometimes, but only if the platform lets you export the code and data without depending on proprietary services that must be rebuilt elsewhere. Test portability before committing.
Is vibe coding replacing software engineers?
Not entirely. It automates parts of implementation while increasing the need for people who can define requirements, direct agents, review code, design systems, and own production outcomes.
Related articles












