Skip to main content
Last updated September 22, 2026
Reflections

The Vibe Shift: An Unrecognisable Industry

Since The Long Hike, the work has moved from producing code toward directing AI inside a clear architecture. This post covers that change through payroll, finance, and products built for specific people, plus the security checks that still sit with the engineer.

The Vibe Shift: An Unrecognisable Industry

Recently I posted an article called The Long Hike about the stamina needed to create a enduring career in software. It started at MCAST, where I got to learn the mechanics of the programming languages Java and C# and made game engines using Unity game engine. Through my early experience, working at Maze Digital on open banking integrations, followed by technical product development work at Buddy Payroll, my interests gradually shifted from coding to the human part of problem-solving.

The software world has changed forever. The term full stack developer seems to be more associated with an earlier time when code was manually generated. Today is the time of orchestration. The use of modern AI models is similar to managing ambitious junior developers; they can be fast and efficient, but need carefully designed structures and workflows, as well as a level of domain expertise to ensure accurate results.

Where I'm coming from, this is a natural milestone. As the capability to generate raw code becomes more and more commodity, having a mindset of a Product Engineer is crucial when writing codes; the main focus is always to achieve a meaningful user outcome.

From Code Production to Orchestration

The toughest problems are never about implementing boilerplate code, whether it's designing an architecture for a scalable payroll system at Buddy Payroll or working with multi-tenant crypto reconciliation at Veris Finance. These are in the realms of system design, data integrity and dealing with the real-world edge cases.

This can be seen in industry research. A 2026 McKinsey survey of 4,500 software developers showed that the use of AI tools has freed up 46% of their time from repetitive coding tasks. According to Second Talent, as much as 90% of the standard boilerplate production is now automated, with core value still in the system architecture, security and governance.

Customers will look more for the risk that can be eliminated and the outcomes that can be achieved when AI takes away the need for a person to do something, as Vishnu Shankar, Chief Data Officer at Draup, pointed out to Channel Dive.

On the AI spectrum, there is Disciplined Engineering.

In the day-to-day development workflow, there is a spectrum between "Vibe Coding" and "AI-Assisted Engineering.In day-to-day development, workflows often lie somewhere between prompt-first "Vibe Coding" and structured "AI-Assisted Engineering.

Vibe Coding is about quickly and conversationally iterating, and taking freely generated code. It’s great for rapid prototyping but if not backed by a solid blueprint, it can lead to architectures that cannot handle production workloads. With the creation of a new application such as Velafa CMS (API-first multi-tenant headless CMS) or SocketBooks for local mechanics, it is much more predictable to begin with the intent of the application rather than dealing with unstructured code afterwards.

AI-Assisted Engineering uses automated tools as execution assistants in a disciplined system design system. First preach architectural clarity before prompting, to maintain the scalability and maintainability of projects. This is reflected in modern tooling:

  • GitHub Copilot: Good for in-line autofill and for trivial snippets.
  • Cursor: Designed for the full IDE experience with rich workspace context and AI-native.
  • Claude Code: Best suited for multi-file refactoring and high accuracy technical reasoning (80.8% on SWE-bench).
  • Orca best for automated codebase evolution and autonomous multi-agent task orchestration.

The Knowledge Paradox

One of the many findings from the past few years is The Knowledge Paradox: The more domain knowledge the engineers have, the more leverage AI assistance can provide. A robot apprentice needs to be guided by an experienced developer.

This learning curve is evident in METR benchmark data. Despite an initial slowdown of 19% on average, developers adopting AI workflows ultimately increased their net speedup by 18% when the workflows were incorporated into structured practices.

This balance is evident in my personal projects, spanning from accounting integrations to payroll engines, and recently in Web3 data pipelines. Some edge cases in finance that might require nuanced understanding of financial matters or compliance requirements are things that AI can't understand on its own. The best engineers are those who use AI tools with technical expertise instead of quantity.

The Agentic Attack Surface

With agentic tools becoming more autonomous in general, security has become an important factor in the repositories. Industry surveys show that 84% of developers are using AI tooling, but just 29% completely rely on the output, which comes as no surprise in the face of newfound vulnerabilities in the supply chain.

The ClawHavoc campaign brought to light these risks when Koi Security's first audit of the community skills registry for Claude Code, called ClawHub, found 341 malicious entries. The number of these packages was later increased by Snyk and CrowdStrike to 824 total infostealer vehicles. At the same time, GitGuardian reveals that 3.2% of AI-helped commits leak credentials, which is more than twice that of human-made code.

When applied to platforms that are sensitive to security concerns, like transaction reconciliation or API services that rely on OAuth for authentication, this underscores the need to test AI additions against recognised attack points:

RoguePilot Attack: Prompt injection in comments on GitHub issues that can exfiltrate sensitive GITHUB_TOKEN credentials when opening Codespaces. CurXecute (CVE-2025-54135): MCP configuration manipulation allowing Remote Code Execution (RCE) without requiring an explicit prompt approval.

  • Settings Overwrites: Malicious prompt payloads changing the .vscode/settings.json file to change toolchains to point to external files. API Key Exfiltration (CVE-2026-21852): Injected plaintext ANTHROPIC_BASE_URL parameters to redirect to untrusted endpoints.

Thorough human code review is an important security requirement in software delivery today.

Building for Humans

The real purpose of software development is when it's linked to actual human needs. From creating a solution for wedding day organizing for friends and family like Our Special Day to finding a solution to streamline day to day business for local Malta mechanics like SocketBooks or creating solutions that work without a UI like Velafa CMS, the priority is always the user.

While AI can produce code on a large scale, it lacks the ability to grasp human frustration, intuitive design thinking, or the nuances of a local business owner's operational context. Simplicity is one of the basic values of design and technical solutions are developed in order to serve people.

The Next Chapter

These experiences inform my way of thinking about software engineering in today's world. The mechanical hurdles to code generation have been drastically reduced and the emphasis is on intelligent guidance and strong architecture with impactful results.

The key question for engineers these days is: To stick with syntax or to be an orchestrator for outcomes.

Keelan Vella

Keelan Vella

Product Developer & Human

Product Developer & UI Enthusiast based in Malta. Building digital experiences that matter.

Buy me a coffee