Background: a workshop at IA Day Valenciennes
On 15 June 2026, Les Rives Créatives, the incubator where Nualt is based, held the first edition of IA Day (AI Day) at the Serre Numérique in Valenciennes, in northern France. The afternoon brought together 40 exhibitors, 13 workshops and a talk, with the aim of showing that useful AI is not built only in large cities.
I was there in two capacities, with a stand as an exhibitor and a 30-minute slot at 4:45 pm to run the workshop "Vibe Coding: How Not to Build a House of Cards", in front of an informed audience of entrepreneurs, makers, no-code builders and people from public institutions. The full presentation is available to download further down this article, for readers who want to see the structure used during the workshop.
The common thread: dispossession
The talk took vibe coding for what it is, an exceptional tool that it would be dishonest to dismiss. Its subject was dispossession, a concept taken directly from Marx and his Economic and Philosophic Manuscripts of 1844, which holds that when we project our own qualities into an external object, that object ends up becoming foreign to us.
Applied to code, this leads to a simple thesis. Vibe coding without understanding what you produce means giving up ownership of both your product and your means of production.
What you lose on the product side
Code you do not understand becomes impossible to fix or develop further yourself. Its technical specifications can no longer be explained to the developers who might take over the project. And when the project handles sensitive data, compliance with the GDPR, the European data protection regulation, becomes a genuine risk in its own right.
What you lose on the means of production
A tool you do not master, whose pricing, terms of use and, for most tools on the market, country of origin all lie outside your control, cuts you off from your own raw material. You come to depend on a third party in order to produce, without being aware of it.
A concrete case: my own landing page
To make this tangible, I used the example of my former personal landing page. The need looked trivial, since it was simply to change the title of the hero section. Doing so meant going through several nested files before landing, in the middle of a Hero component of more than a hundred lines, on a Tailwind class so long it read like an inventory.
This is invisible technical debt. The site appeared to work, but its architecture carried very real structural flaws, with concrete consequences for search rankings and performance. With more than 17,000 lines of code and multiple dependencies, even the AI could no longer grasp the project as a whole well enough to make good decisions.
Front-end is no simpler for an AI
There is a persistent assumption that front-end work is easier to leave to an AI than back-end work. My view as a developer is that this belief mostly reflects a human perspective. Nothing suggests it holds for a model, which has to deal with the project's architecture, the size of its context window and the fact that its decisions have very real business consequences, search rankings included.
Three back-end pitfalls that are easy to miss
Supabase and what lies underneath
Supabase is often used in vibe-coded projects to outsource the back-end. The difficulty is that its promise of simplicity rests on twelve Docker containers, seven programming languages that an AI does not necessarily master equally, and resource requirements that rise quickly. The documentation recommends a server with 8 GB of RAM, 4 cores and 80 GB of SSD storage, which is far from negligible once the load grows.
GDPR and Row Level Security, poorly understood by AI
Whether with Supabase or a more conventional stack, GDPR compliance and Row Level Security are essential and often badly handled by AI. A public key exposed without a clear data policy, or a misconfigured cookie banner, is enough for the product to become unlawful and its data corrupted, while the responsibility remains entirely with its owner.
Node.js by default, not always for good reason
AI reaches for Node.js by default, because it is the language most present in its training data. It is not a bad choice in itself, since the ecosystem is versatile, yet it is not always the right one for a specific need, while other languages exist and would sometimes fit the project's actual constraints better.
The figure that struck the audience
A study published in early June 2026 scanned more than a thousand vibe-coded projects using Supabase as their back-end. 98% had at least one security vulnerability, and 29% had at least one critical or high-severity vulnerability. The figure is meant to describe rather than alarm, as a snapshot of what happens when AI is left to decide alone and its choices are never checked.
What to take away, without rejecting AI altogether
AI is not magic, and that is fine. Something that appears to work is not necessarily soundly built, much like a ripe apple that hides a worm. AI reproduces patterns, often relevant ones, and our role as builders is to check them instead of simply accepting them. Handing over your intelligence and your power of decision to the tool means running the risk of dispossession, exactly as Marx described it nearly 180 years ago, with a somewhat different object of manufacture.
I closed the workshop with Socrates rather than Marx, and with his idea that the first knowledge is the knowledge of one's own ignorance, which is where intelligence begins. Applied to vibe coding, the conclusion is simple. It is better to know what you do not know than to let an AI decide in your place without ever asking the question.
We also run this kind of session as training
This workshop was not a one-off exercise. Alongside development projects, we also run training sessions on these subjects for training centres and companies that want to make their staff aware of the actual uses and limits of AI in development, from a short format like the one at IA Day to longer modules spread over several days.
The conviction behind it is the same as in the rest of our work at Nualt. Technical knowledge protects you, whether you are building a website or training people to use AI without being dispossessed of the work it produces. If this workshop format or a longer module would suit your organisation, we can scope it together.
Get the workshop slides
The presentation used for this workshop is available to download just below this article, in exchange for your name and email address. It gives the skeleton of the slides used during the 30-minute talk rather than the full spoken argument, and it includes the visuals and the structure of the reasoning for anyone who wants to go through it or reuse it internally.
Vibe coding, frequently asked questions
Answers to the questions we hear most often on this topic.
What is vibe coding?
Vibe coding means producing code while letting an AI make most of the technical decisions, often without a thorough understanding of what is actually being built. The term stands in contrast to development in which every architectural choice is understood and validated by the person writing the code.
Is vibe coding a security risk for a website?
Recent figures point to a real risk. A June 2026 study found at least one security vulnerability in 98% of the vibe-coded projects it analysed that used Supabase as their back-end, and critical or serious vulnerabilities in 29% of them. The risk stems less from the AI itself than from the absence of human review of the choices it makes.
Do you need to learn to code to use AI for development?
You do not need to be an engineer, but basic knowledge lets you use the tool wisely and spot problematic decisions before they turn into a real business or legal risk.
Why does Supabase carry a particular risk in vibe coding?
Supabase makes a complete back-end easy to access, but its actual architecture (twelve containers, seven languages) remains complex, and security matters such as Row Level Security are often misconfigured by an AI left to its own devices.
Do you run this kind of workshop for other organisations?
Yes, we run this kind of format for training centres and companies, from a short slot like the one at IA Day to longer training modules, adapted to the technical level of the audience.
