A new agentic coding concept uses the cloak of invisibility to provide security by design in vibe coded apps.

AI coding is a boon, a threat, and an opportunity: it dramatically increases the ease of development; threatens the release of insecure apps – but presents an opportunity for true security by design.

The basic problem is that the security industry has taken 50 years to learn that the internet perimeter that requires protection is the individual identity of every single entity involved. We’re learning that now, but only after decades of applying different layers of security that would have been unnecessary if the internet itself had been built secure by design.

However, we now have AI coding taking the internet by storm, and all we’ve learned over these past 50 years risks being discarded. AI coding does not build apps secure by design – it builds apps for speed and ease of development in building apps. New apps are being built by anyone, with or without any coding or security expertise, and including unprotected identities and recognized open source code containing known vulnerabilities.

Atsign has launched AI Architect to tackle the problem – a problem recently summarized by Broadband-Testing Ltd. “Securing those generative and agentic apps has not exactly been top of the list of ‘to do’ tasks before sending said apps out into the wild. This is sugar coated ether candy for the cyber attackers, especially when those apps are in supply chain environments. But businesses are under pressure to maximize the ‘AI moment’ and gain that age-old competitive edge over their rivals, while DevOps teams simply want to pump out more and more AI apps.”