
10x Insights
Ep. 11: Live from KCDC! Granny Vibe-Codes an App (And Nobody Knows Who's Responsible)
Here's a fun one: your AI agent vibe-codes a whole application. It works. It ships. And then something breaks. Who's actually responsible? The developer? The model? Whoever trained the model? Recorded live at KCDC 2026 (background conference noise included, no apologies), I sat down with Steve Poole and Brian Vermeer (Staff Developer Advocate at Snyk) for a conversation that started with "is AI going to replace developers?" and ended up somewhere way stranger — legal liability, the EU's Cyber Resilience Act, and whether your Granny should really be shipping her own app straight to production. We get into it: can AI actually find and fix vulnerabilities at scale (Anthropic's already doing this across a thousand open source projects)? Should you even bother pointing an LLM at a bug a deterministic scanner would've caught for free? And why does "AI fixed the vulnerability" still only hold up less than half the time? Steve and Brian go back and forth on the token economics of vibe-code-then-scan-then-fix (it adds up fast), the gap between a developer who vibe codes with intention and "Joe from finance" who just wants his app live on the internet, and why "I didn't know what was in my software" stopped being a legal defense. It's a fun one, but it's also the conversation every dev team should be having before their agents write one more line of production code. Hosts: Steve Poole , DevRel Advocate at HeroDevs Brian Vermeer, DevRel Advocate at Syk Resources: Project Glasswing Cyber Resilience Act No Regressions Substack KCDC 2026 10X Insights home page

