You replaced the front pads on your Corolla. Went fine. Took two hours, cost forty bucks, and it stopped the car.
So now you've watched a few YouTube videos on European engines and you're ready to pull the block on a BMW.
You'd never. Nobody would. And yet this is precisely what's happening across business right now, except with the thing your revenue actually runs on.
The new normal
AI writes working code. That part is real and I'm not going to pretend otherwise. I use it every day and it's made me faster at things I already knew how to do.
That's the important half of the sentence. Things I already knew how to do.
What's changed is that people who have never shipped anything can now produce something that looks shipped. It compiles. It deploys. It has a login page. It looks like the screenshots. And there is nobody in the room who knows what's missing, because knowing what's missing is the entire job.
An AI will build exactly what you asked for. It will not tell you what you forgot to ask for. It doesn't know your market, your competitors, your legal exposure, or the fact that you're about to hand a stranger a database of your customers.
A real example
Here in New Zealand there's a startup running on parkup.nz. Decent idea, real market, genuine users.
They didn't register parkup.co.nz.
In this country, .co.nz is what people type. It's the default. It's the thing your customer's mum will guess. And a domain costs about twenty dollars a year.
So now there's a similar product, in the same market, sitting on the domain half their audience will land on by accident. Every mistyped URL, every word of mouth referral, every "just search for ParkUp" is a free customer handed to someone else. Forever.
That's not a coding error. There's no AI prompt that catches it. It's a twenty dollar decision that a person with any real experience makes without thinking, on day one, before a single line is written. Along with the trademark search, the social handles, the .nz and the .com, and the three obvious misspellings.
You cannot buy that back later. Once someone else has it, it's theirs.
What actually goes wrong
The domain thing is just the one you can see from the outside. Here's what I find under the bonnet when I'm called in to clean up an amateur build.
Secrets in the front end. API keys, database credentials, admin tokens, sitting in JavaScript that anybody can read by pressing F12. I find this constantly. It takes ninety seconds to check and it's an instant compromise.
No authorisation, only authentication. The app checks that you're logged in. It never checks that you're allowed to see this particular record. Change the number in the URL and you're reading someone else's invoice. This is the single most common flaw in vibe-coded apps and it's a privacy breach the moment anyone notices.
No backups. None. Nobody thought about it because nothing had gone wrong yet.
Nothing logged. When something does go wrong, and it will, there's no trail. You can't tell whether you were hacked, when, or what they took. Which matters, because under the Privacy Act you have to notify.
Payments handled badly. Prices trusted from the browser. Webhooks not verified. Refund logic that can be triggered by anyone who finds the endpoint.
UX that only works for the person who built it. They know where everything is, so the flow makes perfect sense to them. Real users bounce. Forms with no error states, buttons that don't tell you they worked, mobile layouts nobody tested on an actual phone, and a signup flow with six steps where two would do.
No accessibility at all. Which is a problem generally and a hard blocker if you ever want to sell to government or enterprise.
Nobody can maintain it. Thousands of lines nobody in the business understands, no tests, no documentation. The person who prompted it into existence cannot debug it, because they never could.
The three ways businesses get here
The AI era developer. Two years of experience, all of it with a model doing the thinking. Genuinely capable of producing a lot, fast. Has never carried a pager, never had a production database go down, never had to explain a data breach to a customer. Doesn't know what they don't know, and the tooling actively hides it from them.
The marketing agency that added "we do apps now." Same people who were dragging boxes in a page builder last year. The output looks better now. The understanding hasn't moved an inch.
Internal staff, or you. Someone in ops who's technical-ish and keen. This is the worst one, because there's no invoice, so it feels free, and nobody wants to tell the boss that the thing they were excited about is a liability. It runs for eighteen months, becomes load-bearing, and then someone leaves.
Technology is not a cost centre
This is where most of it goes wrong, before anyone has picked a developer.
Businesses treat their website and their systems as an expense to be minimised. Get the cheapest quote, get it live, stop spending. Then they wonder why it doesn't perform, why the leads are poor, why everything takes six weeks and breaks.
Your technology is not overhead. It's the front door, the salesperson, the order book and the filing cabinet. It's how customers find you, judge you, and pay you. It's the only part of your business that runs at three in the morning.
The businesses that treat it that way pull ahead. Not because they spent more, but because they spent deliberately, once, on someone who knew what they were doing, instead of three times on people who didn't.
I've watched the cheap version cost more than the good version, every time, without exception. Rebuild, migration, lost ranking, lost customers, and the enquiries you never knew you missed because the form silently failed for four months.
What I do about it
I've spent twenty years on this. Learned PHP from a book, back when you had to read the manual because there was nothing to paste an error into. Delivered hundreds of sites and systems, from florists and Airbnb hosts through to multinationals and government departments.
That range is the point. The florist and the government agency need the same things: it has to be fast, it has to work on a bad phone on bad wifi, it has to not leak, and it has to keep running when nobody's watching. One of them just has more paperwork.
If you've built something with AI, or paid someone who did, I'll audit it. Security, data handling, infrastructure, DNS and domains, UX, performance, and whether it can be maintained by anyone other than the person who made it. Plain English, prioritised, no jargon padding.
If it's solid, I'll tell you it's solid. Plenty are.
If it isn't, you'll want to know now rather than the day it matters.