Vibe coding’s accuracy and data risks for advisors

Advisors use “vibe coding” to create visuals and simple apps quickly. Major firms reported AI-related errors this summer, prompting scrutiny of accuracy, data and governance.

Financial advisors are using “vibe coding”—natural-language prompts that generate code, visuals and simple apps-to speed production of client materials. Several large firms reported AI-related inaccuracies this summer, and industry participants flagged risks around output accuracy, client data exposure and governance.

Vibe coding converts a user description of a desired look or function into working code and visuals. Practitioners have used the method to create a cashflow management app, a money-mindset assessment and a goals visualizer. An advisor who experimented with multiple applications said prototypes were quick to build but required ongoing testing and updates to produce consistent results.

A survey by a financial modeling tool provider found that 62% of teams believed they had shipped a model or presentation that contained an AI-generated error. The same survey reported that 24% of users had comprehensive guardrails in place while 36% used AI daily or weekly without any guardrails. When asked whether appropriate guardrails existed at their firm, 45% answered yes and 55% answered no or weren’t sure.

Security and data-privacy risks include accidental exposure of client names, emails, account numbers and tax IDs when cloud-based AI systems process real client records. Mike Wilson, CEO of an AI deployment platform, warned that data submitted to these systems can travel to unknown locations and that users can unintentionally disclose API credentials, which creates access paths for others.

Technical limits add further hazards. Todd Wardzinski described vibe coding as “exciting but dangerous,” writing that “the code itself becomes the only source of truth for what the software does — and code is terrible at explaining why it does what it does.” Syntax Data’s chief technology officer compared unvetted AI outputs to work from a junior analyst and said such results should not be presented to clients without human review. He noted that poor input data can compound errors as it moves between systems.

Advisors who prototype with vibe coding reported that turning those prototypes into production-ready tools requires work on version control, traceability of input data and validation of underlying calculations. One advisor noted the cashflow app she built demanded extensive testing and frequent updates to generate consistent outcomes.

Firms are adding controls. Some have written ownership clauses into AI guidelines so a person or team is accountable for outputs before those outputs reach clients. Other teams require review steps or hire external auditors to examine code, math and data lineage. Regulators are expected to examine not only which systems firms use but also what data was shared with those systems and how outputs were validated.

Industry specialists recommend avoiding use of live client records during development. Wilson recommended using synthesized or anonymized data for testing and consulting technical specialists before turning an internal tool into a client-facing product.

Articles by this author