Vibe Coding Grew Up: From Weekend Hack to Payroll Systems
🎯 Who this is for: Anyone who has heard "vibe coding" in a meeting and wondered whether it belongs anywhere near production.
Series: Part 1 of 13 — Enterprise Vibe Coding | Read time: 6 minutes
Picture a developer at an insurance company in her first week with an AI agent. On Monday she asks it to "clean up the claims export." By lunch it has renamed forty variables, rewritten a date parser, and quietly changed how leap years were handled. Everything compiles. The tests pass, because there aren't any for leap years.
Nobody notices until 29 February.
That story is vibe coding in one paragraph. It is fast, it is magical, and in a hobby project it is harmless. In a system that pays claims, runs payroll or bills a million utility customers, "it compiled" is not the same as "it's right." This post is about how vibe coding grew up to cope with that.
🎈 From a Throwaway Tweet to a Price List
In February 2025, Andrej Karpathy described "a new kind of coding I call vibe coding, where you fully give in to the vibes, embrace exponentials, and forget that the code even exists." He was talking to his editor by voice and accepting whatever came back. A year later he called it a throwaway tweet. It still named something millions of people were already feeling.
What followed was quick. GitHub Copilot, Cursor and Claude Code all gained agent modes that could edit many files at once. Amazon launched Kiro around written specs. IBM ran an internal pilot of Bob with 100 developers in June 2025 and made it generally available as a SaaS product in April 2026, with enterprise plans and a 30-day trial.
By the second half of 2026 vibe coding was no longer a weekend trick. It had procurement, licence tiers and an admin console.
🧥 The Navy Blazer Problem
Here is the odd part. IBM, which built one of the most enterprise-focused tools in the category, will not use the phrase. Its product messaging never says "vibe coding." When IBM's Neel Sundaresan mentioned it, it was to draw a line: "It's not about vibe coding; it's about literal programming. It's not about accessibility, it's about security."
The press did the opposite. CIO Dive's headline was "IBM unveils vibe coding tool." Techzine wrote that Bob "aims to make vibe coding enterprise-ready." IBM partner Northdoor's Tom Richards, put it best: Bob is "vibe coding putting on a navy blazer and walking into the enterprise boardroom."
Both sides are right. The experience is vibe coding: you describe what you want, and the AI writes it. The discipline around it is something else. IBM's SVP Dinesh Nirmal summed up the pitch: "We're giving development teams AI that fits how enterprises work, not experimental tools that create new risks." Strip away the marketing and that is the whole shift: same speed, new rules.
📏 The Spectrum, Not the Label
The most useful idea we have found comes from IBM's own explainers. They treat vibe coding as the informal end of a spectrum, running through agentic coding to agentic engineering, and note that these "aren't mutually exclusive." You can prototype on vibes on Tuesday and run a governed agent pipeline on Wednesday.
| Vibe coding | Agentic coding | Agentic engineering | |
|---|---|---|---|
| Who reads the code? | Often nobody | The developer, mostly | Developer plus reviewers, with tests |
| Plan written first? | No | Sometimes | Yes, and it gets reviewed |
| Approvals before changes | Click "accept all" | Per change | Policy-driven, logged |
| Typical home | Side projects, demos | Team features | Regulated production systems |
| Main risk | Code nobody understands | Over-trusting the agent | Process overhead |
Most enterprise teams will live in all three columns. The skill is knowing which column today's task belongs in. A throwaway internal dashboard can be vibed. A change to the interest calculation in a loan system cannot.
💡 Key insight: The difference between a toy and a payroll system is not how clever the model is. It is whether you can say who asked for the change, what the AI planned, who approved it, and how it was tested. VentureBeat made the same point about Bob versus Cursor and Claude Code: the difference "is not about capabilities but about control."
🏦 What Grown-Up Looks Like in Practice
Walk into a bank, a utility or a government agency using AI agents well in 2026 and you will see the same patterns, whatever the tool:
- Plan before code. Bob, Cursor, Claude Code and Kiro all offer a planning step that writes out the approach before touching a file. Bob's team puts it bluntly: "The plan is the review artifact."
- Approvals on anything risky. Reading files can be automatic. Editing files, running commands or calling outside systems waits for a human click. Bob V2 auto-approves reads but still asks before edits, commands and tool calls.
- Receipts. Admin dashboards and activity logs show who used the agent, how much, and what it touched.
- House rules. Files like
AGENTS.mdtell the agent your naming conventions, banned libraries and test requirements, so it stops guessing. - Control over where data goes. Regional hosting (Bob added EU and Japan regions in July 2026), zero-retention promises and, on IBM's roadmap, an on-premises option for data-residency and regulated environments.
None of this is glamorous. All of it is why a compliance team will sign off.
⚠️ The Honest Part
Grown-up does not mean solved. IBM's own explainer warns that vibe coding "caused a new type of technical debt called security debt," and its security guidance says to "treat any AI-derived code or modules as untrusted input." In January 2026, researchers at PromptArmor showed that a beta of Bob's command-line tool could be tricked, through instructions hidden in a README, into downloading and running malware when one command had been auto-approved. IBM pledged fixes before general availability. The lesson applies to every agent: auto-approve is a loaded setting.
And the numbers are early. IBM reports an average 45% productivity gain, but that comes from a self-reported survey of its own staff. IDC noted at launch that the "external evidence base remains limited." We will dig into that properly in Part 10.
The Bob team's own blog has the line we would tape to every monitor: "It is now easy to produce a large amount of code that works and is wrong."
Key Takeaways
- Vibe coding began as a hobbyist idea: describe it, accept it, and don't read too closely.
- Enterprises want the speed but cannot afford to forget the code exists, so the grown-up version adds plans, approvals, logs and data controls.
- Think in a spectrum (vibe coding, agentic coding, agentic engineering) and match each task to the right level.
- The real differentiator between tools is control, not raw capability, and every vendor's productivity number deserves a second look.
References
- Andrej Karpathy — original "vibe coding" post (February 2025)
- IBM Newsroom — Introducing IBM Bob (April 28, 2026)
- IBM Think — The new role of the developer (TechXchange 2025)
- IBM Think — What is agentic coding?
- IBM Think — What is vibe coding?
- The Register — IBM Bob vulnerability research (January 2026)
Series Navigation
| Previous: | Series Index — Enterprise Vibe Coding |
|---|---|
| Next: | Part 2 — The Prompt Is the New Spec |
🧰 From TheMaximoGuys toolbox: Working with Maximo? Max_autoscripts is our open-source (MIT) set of 67 Jython sample scripts plus coding standards and a ready-made AGENTS.md, so whichever agent you use (Claude, Bob, Copilot, Cursor) starts from your house style instead of vibes.
Published by TheMaximoGuys | August 2026



