In spring 2026, a software developer was asked to audit a mid-sized Node.js backend. Roughly 60% of the code had been generated with AI assistance. It passed every security check. "No injection vulnerabilities, no obvious race conditions, decent error handling," the developer wrote in a Reddit post. "On paper, it was fine."
Then they read the code line by line. Functions that belonged together were scattered across unrelated files. Auth middleware had been written three different ways in three different places — all slightly different, all somehow working. When they asked the team why certain decisions had been made, nobody could answer.
"The AI didn't write bad code," the engineer concluded. "It wrote code that nobody understood."
Now consider what happens when the same tools land with finance, legal, HR, or marketing teams connecting to sensitive systems without understanding the risk.
A crisis born from good intentions
This isn't usually malicious behavior — it's often the opposite. Employees are responding to a top-down mandate to move faster with AI. Tools like Claude Code and Codex make it possible for anyone to build apps, agents, and automations — "vibe coding" is even starting to show up in job specs at Fortune 500 companies.
Many IT and security teams have responded by locking down access to sensitive systems. But locks don't always hold — employees who hit a wall will find ways to get around it.
It's easy to see why this is sometimes called "wild code" — it spreads faster than organizations can track, govern, or maintain it. Seven-time CIO Mark Settle calls it "a viral adoption phenomenon that's not being gated by IT or even by operations teams."
The data backs him up:
- 77% of organizations say AI adoption is outpacing their governance capabilities (IBM 2026 Tech Leader Study)
- 70% say business teams are deploying technology faster than IT can track it
An old problem, growing exponentially
Shadow IT isn't new — employees have long brought in unauthorized devices, apps, and scripts. What's changed is scale. "There weren't many organizations capable of governing the code hitting their production environments before AI came along," says Adam Arellano, Field CTO at Harness. Traditional governance assumes software is planned, reviewed, and deployed through established channels. That assumption no longer holds.
The real cost
Wild code carries a price tag well beyond the visible one. "The hidden costs are the long-term support costs," Settle notes — the ongoing labor and risk of keeping ungoverned code alive and secure.
An analysis of over 300,000 AI-generated commits found nearly one in four quality and security issues remained in production. Add untracked AI spend, duplicated effort across silos, and expanded attack surface (the average data breach now costs $4.4 million, per IBM), and the "look how fast we built this" narrative starts to look incomplete.
Governance that keeps pace
The fix isn't to slow AI adoption or blame employees for using it — it's building governance that moves as fast as the innovation it's meant to support. "IT and security teams have a unique opportunity to avoid contentious downstream debates by introducing construction guidelines now," Settle says.
"The risk isn't that employees are building — it's that no one has a complete view of what's been built or who's responsible for it," says Colin Bentley, VP of Product at Tines. The company's latest product release, Tines 3B, is an AI-native environment that customers at Headspace and Fin are using to solve for wild code. "IT doesn't need to control every build,” he adds. “It needs to provide the infrastructure that makes it safe for people to build on their own."
The companies that get ahead of wild code won't be the ones restricting who gets to build. They'll be the ones giving every team — technical or not — a safe, governed environment to build in from the start.
Want to dig deeper into the “wild code” challenge? Join Colin Bentley, VP of Product at Tines, for a live conversation on how AI governance needs to adapt, and how IT can shift from blockers to enablers.
Register for the webinar.