How Lovable Manages 100+ Daily Changes, Vibe Coding & Shadow AI

How Lovable Manages 100+ Daily Changes, Vibe Coding & Shadow AI

🎙 Ashish Rajan 👥 20K 📅 April 2, 2026 ⏱ 57 min 👁 8K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI agentsCI/CD churnPAMshadow AIsupply chain

Summary

In this episode of the AI Security Podcast, host Ashish Rajan interviews Igor Andriushchenko, Head of Security at Lovable, a rapidly growing AI-native platform. Recorded at the Munich Cybersecurity Conference, the conversation focuses on the security challenges of AI adoption in a hyper-growth environment. Igor shares his experience joining Lovable at employee #40 and scaling to 150+ employees, where developers and even PMs use AI agents extensively. Key topics include the strain on CI/CD pipelines from AI-generated code changes, the need for telemetry and visibility into AI agent usage, and the importance of treating AI agents like human developers with appropriate access controls such as PAM. He emphasizes the ‘air pocket’ strategy for safe AI experimentation, the reversal of allow-list vs. deny-list logic for AI, and the risks of AI recommending unmaintained or hallucinated packages. Igor also discusses the evolution of SAST tools for AI-generated code and the development of custom AI skills for incident response. The episode concludes with practical advice on building internal AI security tooling and managing different levels of AI users within an organization.

178 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of this episode lies in its practical, real-world insights from a security leader at the forefront of AI-native development. Igor provides concrete examples of challenges such as CI/CD load testing, the need for PAM as a guardrail for AI agents, and the reversal of allow-list/deny-list logic. His argumentation is coherent and experience-driven, emphasizing intentional adoption of AI rather than forced FOMO-driven implementation. He effectively argues that security must adapt to the speed of AI-generated changes and that traditional methods are insufficient. The discussion is well-structured, moving from problem identification to specific solutions, making it highly actionable for security professionals.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on the speaker’s professional experience rather than formal research. No external sources are cited within the episode, but the podcast’s website and newsletter are mentioned. The title accurately reflects the content, covering the high volume of changes, vibe coding, and shadow AI. The discussion is practical and grounded, but lacks citations to academic or industry standards. The adéquation between title and content is strong, as all mentioned topics are addressed in detail.

197 words

Title / Content Match

The title accurately reflects the core topics: managing high volumes of code changes, vibe coding, and shadow AI, all discussed in the context of security.

Quality & Reliability

8/10

The podcast features a security leader from a fast-growing AI company, providing practical, experience-based insights. The discussion is grounded in real-world challenges and solutions, but it is primarily anecdotal and lacks formal citations or peer-reviewed sources.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The episode provides unique insights into security practices at a leading AI-native company, particularly the application of PAM to control AI agent access and the reversal of allow-list/deny-list logic. It offers a practical framework for managing AI adoption in a fast-paced environment, emphasizing the need for telemetry and the ‘air pocket’ strategy. The discussion on AI-recommended supply chain risks and the evolution of SAST tools adds valuable perspectives.

Pour aller plus loin :

112 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the dense, practical content. The technical level is moderately high, suitable for security professionals. Overall reliability is good, though based on anecdotal evidence rather than formal research.

Reliability 7/10