Tech Transformed · Sep 28, 2026 · 27:11
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
“Vibe coding is already present in your company,” according to David Hsu, CEO of Retool and governance is the only way to secure it.
Let's put this into context. Think of a Fortune 500 company’s CIO who has recently come across a vibe-coded application spotted on the public internet. This app was developed by an employee of the Fortune 500 company in question. The developer obtained a data dump from Salesforce pertaining to customers, then fed this data to an external AI tool not part of the company’s set of AI tools. The employee prompted the tool to host the resulting application on a public URL.
Since it was an external AI tool, a security review couldn’t be carried out, nor could the IT department view it. Without any internal visibility into a tool created by the employee, the actual customer data was live on the open web. It’s a scary situation, a breach of trust, so imagine the CIO’s wrath upon seeing it.
This is why, in the recent episode of the Tech Transformed podcast, host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech, sat down for a conversation with David Hsu, CEO and Founder of Retool. They talk about the repercussions of vibe coding in addition to examining why most enterprises have no conception of how much of it is already taking place within their own enterprise.
The discussion then turns from the immediate issue of governance concerning uncontrolled AI app-building to Hsu's prediction that software engineering as a profession could vanish within two to three years.
“All the CIOs that I speak to are genuinely frightened about vibe coding, and even if you don't want to admit it, vibe coding is already present in your company,” he tells Dua. This is partly why Hsu founded Retool.
Retool secures vibe coding for enterprises. Hsu explains that Retool can be connected to a company’s Snowflake database, for instance or their Databricks data lake. “Users should be able to have access to particular tables only,” he says. Access controls are required at the group level.
“If you're in this particular Okta group, you can only access this table, and it's read-only. Whereas if you're in this other Okta group, you can actually write back to this other Salesforce over here." So one Okta group could be granted read-only access to a particular table, while another group might be given write access to a connected Salesforce instance. All applications that are built on top of that connection automatically inherit the same restrictions.
Once rules of such a nature are put in place, people could then be set free, explaining why he views governance as something that enables freedom rather than something that restricts.
Takeaways00:00 The Rise of No-Code and Low-Code Development
04:52 Governance in the Age of Rapid Development
12:40 Centralisation and Control in Software Development
20:04 The Future of Software Engineering and AI
25:13 The Role of Humans in an AI-Driven World
vibe coding, AI governance, enterprise AI, CIO, AI agents, software engineering, Retool, David Hsu, enterprise software, AI security