As AI adoption continues to spike among advisors, it is also bringing more challenges along with it. Vibe coding, one of the latest trends, has plenty of industry-wide appeal, while its upside remains murkier.
The draw is understandable. Through vibe coding, advisors can, with a series of prompts, "speak" what once took hours or days into existence. It's a compelling process, but it commands a new set of guardrails given the risk of a potentially costly SNAFU.
Just this past summer, PwC joined EY and KPMG very publicly for a "walk of shame" after falling victim to AI-related inaccuracies in their reporting. With an increasing number of users in the driver's seat, vibe coding comes with its own limitations and potential for further inaccuracies.

How vibe coding works
The vibe coding process works by taking a user's natural language prompts as inputs and creating the output that best fits that description, or as contributor Todd Wardzinski shared in a blog on Red Hat Developer, "you describe the vibe, the AI handles the details."
Gone are the days when an advisor's time was taken up crafting Excel or PowerPoint tools that served as the visuals to then bring back to their clients. Advisors can now create tailored, bespoke visuals and materials without those old software constraints.
"Before Microsoft Excel, the yellow pad dominated a lot of this concept of being able to draw pictures for investors," said Mike Wilson, CEO and co-founder of Hamachi.ai, a software platform that deploys AI systems alongside compliant guardrails. "What vibe coding has done is like the next significant unlock for advisors being able to tell their stories in a way that they like to tell them."
Denver-based Aditi Kapadia of Wealth IQ said in an email that she has "been tinkering with vibe coding since before I launched my firm."
She has vibe coded three applications for the practice: a cashflow management tool, one called money mindset assessment to better understand her clients, and a goals visualizer "that allows me to more deeply connect with my clients to map out their financial goals."
Although Kapadia found building the tools to be fun, "maintaining and updating these applications is time consuming," she said. "The cashflow app requires a lot of testing and updating to make it generate the same outcome repeatedly."
Where the risk lies
In the case of vibe codes, Wardzinski considers them "simultaneously the most exciting and most dangerous development practice to emerge in years."
The danger, according to Wardzinski, exists because "the code itself becomes the only source of truth for what the software does — and code is terrible at explaining why it does what it does."
Advisors have grown more comfortable with AI, but risk treating these same tools "like they're a senior executive," said Sean Sandys, chief technology officer of Syntax Data.
"You wouldn't take something that your junior analyst generated and then put it in front of an external partner, a client or customer without reviewing it," said Sandys.
In the rush to be first, safety and accuracy can fall by the wayside.
"It's pretty darn easy now to build a prototype," said Wilson. "It's still very difficult to take that prototype and make it something that you should feel comfortable putting client information in."
Kapadia, who initially thought advisors "could vibe code their way into most features they needed from their tech stack," has concluded that "advisors may want to vibe code their way to an app (or two) to plug any existing tech stack gaps," she said.
Protecting data in both directions
A report by Microsoft's Macabacus revealed that 62% of its teams believed they've shipped a model or presentation with an AI-generated error.
Macabacus also found that 24% of its users have comprehensive guardrails while 36% use AI daily or weekly without any guardrails. When asked if the correct guardrails existed at their firm, 45% said yes, while 55% said no or weren't sure.
One familiar output risk is accidentally sharing sensitive client information, such as email addresses, names, or account numbers and tax IDs. Safeguarding this information remains sacrosanct, even though breaches still occur.
With vibe coding, "that data, first of all, who knows where it's going, and secondly, it could quite easily get into the hands of someone who's sinister," said Wilson, "who's going to do something bad with your data you don't even know about."
The output guardrail risk lies with "people inadvertently sharing things like credentials to their OpenAI or Claude keys," said Wilson. "Unless you know what you're really doing with building software, you can get stuck in a place where you're inadvertently sharing data or making it easy to be accessed, and you're exposing it in a way that hackers could get into."
A second set of guardrails, according to Sandys, lies in safeguarding what data is allowed to come in. For vibe codes, the industry term "garbage in, garbage out" means that if the data coming in is compromised and then "you start using that data, and then feeding that into another system, those problems compound," said Sandys.
It's not a data-leak issue, Sandys said, "it is a correctness and execution issue."
For firms that rely too heavily on AI without verifying before sending, "regardless of where the output comes from, somebody has to say they own it," Sandys said.
Some firms are getting ahead of that by writing ownership policies into their AI guidelines before a tool ever reaches a client.
Looking ahead
Regulators are also racing to keep pace with AI systems, and firms will have to keep up with them. Regulators will likely inquire beyond the systems being used and look to "understand exactly what you shared with the AI," said Wilson. "Not only what came back, but how did you make sure that it was accurate?"
To verify the accuracy, advisors experimenting on their own with tools should verify source data going into a tool in addition to what comes out rather than presuming the data pulled in is current or accurate.
"The transition between [something that works for you locally] and something that you're deploying to the others in your group or across your firm is a very different challenge," said Sandys.
Teams scaling a tool can lean on a built-in review path or a hired consultant. That audit should ask specific questions around underlying math, version control and how to trace the input data to a known source.
Wilson's parting advice: "Do not, 100%, do not put any client data into AI. Use synthesized, anonymized data for the time being, and then when you're ready to productize something, talk to someone like me."










