The way software is built is changing at breakneck speed. Whereas developers used to write every line of code themselves, we’re now seeing a new approach emerge that’s increasingly becoming the norm: vibe coding. Developers describe what they want in plain language, and an AI model generates the code. It’s fast, intuitive, and efficient—but also risky if it isn’t backed by thorough quality control.
At M2Q, we see this shift in action every day. And we ask ourselves one crucial question: Who tests what the AI has written?
The term “vibe coding” was first popularized in 2025 by AI researcher Andrej Karpathy. The concept is simple: instead of programming the traditional way, you describe to an AI what you want to achieve, and the AI writes the code. Tools such as GitHub Copilot, Cursor, Claude, and ChatGPT are already making this possible for millions of developers worldwide.
The result? Systems that are built in record time, without the developer fully understanding or having a complete overview of every underlying line of code. Prototypes that are built in hours instead of weeks. Features that are “requested” instead of “written.”
This isn’t just a pipe dream. It’s happening right now, in companies of all sizes—from startups to large corporations such as Cebeo (Sonepar) and TotalEnergies, as well as government organizations like VDAB.
The Quality Issue with AI-Generated Code
Vibe coding raises a fundamental quality issue: AI models write code that works, but not always code that is good.
The difference is crucial. Working code does what it’s supposed to under normal circumstances. Good code is secure, maintainable, scalable, testable, and behaves correctly in all edge cases.
AI models hallucinate. They prioritize quick fixes over robust architectures. They don’t understand the business context. They aren’t familiar with your legacy systems. And they don’t test themselves.
Some specific risks associated with unqualified vibe-coded systems:
What does practical experience teach us?
At M2Q, we work with organizations that face the challenges of fast-growing, complex software environments on a daily basis. Whether it’s VDAB, the largest IT department in the Flemish government with more than 450 employees, or Cebeo with its 40+ business testers spread across eight locations in Belgium, the common thread is always the same.
Speed without a quality framework is a time bomb.
At VDAB, we found that there was no clear visibility into defects in non-production environments, that regression testing varied by team and project, and that there was a lack of transparency regarding dependencies between teams. Vibe coding without a QA foundation would exacerbate these problems exponentially.
Cebeo lacked a comprehensive testing strategy. Each team worked in its own way. Without an overarching quality framework, AI-generated code leads to inconsistent quality: good in some places, poor in others, and difficult to compare across the board.
At TotalEnergies, one of the world’s seven largest oil companies with 24/7 operations that require high software availability, there is virtually no margin for quality errors. AI assistance is a tool in this context, but it is never a substitute for structured test and release management.
Quality Control for Vibe-Coded Systems: The M2Q Approach
At M2Q, we don’t believe you should avoid AI-generated code. On the contrary: it’s a powerful tool that, when used correctly, can dramatically increase productivity. But you need a quality framework that scales faster than the AI itself.
Here are the pillars of our approach:
The biggest mistake in vibe coding is starting with the AI before it’s clear what the system is supposed to do. Acceptance criteria—in the form of user stories, a definition of done, or explicit test cases—serve as the foundation. Without this foundation, post-development quality control has no point of reference.
“Shift-left” means building quality into the process as early as possible. In vibe coding, this means: test the AI’s output immediately, even as it’s being generated. Use automated unit tests as a validation mechanism. Don’t just let the AI write code—have it generate test cases as well—and then validate whether those test cases align with business requirements.
AI-generated code must undergo a static analysis process, such as SonarQube. At VDAB, we implemented a SAST (static application security testing) approach in which all code had to achieve a security score of “A,” with a code coverage target of 80% for unit tests. These types of automated quality gates are essential for vibe-coded systems.
Individual components may work while the system as a whole fails. End-to-end testing is indispensable, especially in vibe coding, where AI-generated modules are combined. The goal is to validate whether the system as a whole does what the user expects, not just whether each individual function works technically.
Teams that adopt vibe coding need to develop their QA maturity accordingly. At VDAB, we developed a customized QA maturity model (QAMM) with five levels, ranging from reactive testing to predictive quality. The key point: the model provides teams with concrete actions, not abstract scores. This principle applies all the more when AI writes the code.
Who is responsible if AI-generated code causes a production error? Without a defect management process, that’s unclear. A structured process—with prioritization, severity assessment, ownership, and follow-up—is not optional. It is the backbone of quality control in an environment where no one fully understands all the code.
The Role of the QA Professional in the Era of Vibe Coding
There’s a myth going around: if AI writes the code, you’ll need fewer testers. The reality is exactly the opposite.
You need better testers.
Testers who understand how AI models reason. Who know what blind spots AI has. Who can translate acceptance criteria into automated test suites. Who bridge the gap between what a business requires, what an AI generates, and what a user truly expects.
At M2Q, we provide exactly that expertise. Whether it’s setting up a test center of excellence, developing a global testing strategy, coaching business testers, or guiding test automation efforts, we ensure that quality isn’t an afterthought but an integral part of how your organization develops software.
Vibe coding requires professional QA
Vibe coding isn’t just a passing fad. It’s a fundamental shift in how software is developed, and organizations that fail to anticipate this shift face real risks: security vulnerabilities, technical debt, functional regression, and production errors.
The solutions to these risks are not new. They are known as test strategy, acceptance criteria, static analysis, end-to-end testing, and defect management. What is new, however, is the urgency with which organizations must adopt these practices, because AI generates code faster than ever before.
At M2Q, we help organizations tackle exactly this challenge. From TotalEnergies to VDAB, from Cebeo to your organization: quality isn’t just a box to check—it’s a mindset.
Ready to have your vibe-coded systems tested by professionals? Please contact M2Q.
M2Q — Test. Check. Go. info@m2q.be | +32 3 451 36 60 Veldkant 33a, BE-2550 Kontich | Nijverheidskaai 3, BE-8500 Kortrijk