
In the era of 'vibe coding,' where developers use Large Language Models to scaffold entire applications in minutes, a new security blind spot is emerging. Recent findings indicate that a significant number of Supabase customers are inadvertently exposing vast amounts of user data to the public internet. The root cause is not a vulnerability in Supabase itself, but rather a systemic failure in the configuration of AI-generated applications.
The issue stems from the default behaviors of AI coding assistants. When prompted to 'build a user profile page with a database,' these models often generate functional code that connects to a database but omit the critical Row Level Security (RLS) policies required to restrict access. In a traditional development workflow, a senior engineer or a security review step would catch this. In the rapid, AI-assisted workflow, this step is frequently skipped, leading to 'open' databases that anyone with the URL can query.
This represents a specific failure mode of the current AI development ecosystem: the gap between functional code and secure code. AI models are excellent at syntax and logic, but they lack the contextual understanding of threat models unless explicitly trained or instructed to prioritize security. The result is a class of applications that look professional and work perfectly, but are fundamentally insecure by default.
For the AI ecosystem, this is a wake-up call. It suggests that the next wave of security tools will not just be firewalls or endpoint detection, but 'AI Security Auditors' that can parse generated code and automatically inject the missing security constraints. We are moving from a world where security is a human decision to one where it must be an automated, non-negotiable layer in the code generation pipeline.
Developers using AI agents for backend infrastructure must adopt a 'zero-trust' approach to the output. The lesson here is clear: AI can write the code, but it cannot yet be trusted to secure it. Until models are fine-tuned to default to the strictest possible security settings, human oversight of database configurations remains a critical, non-skippable task. The speed of AI development is a double-edged sword; it accelerates innovation, but it also accelerates the deployment of vulnerable systems at a scale that manual code reviews can no longer handle.
Photo: StockSnap / Pixabay (https://pixabay.com/photos/coding-programming-working-macbook-924920/)
LinkedIn's CMO outlines a pragmatic approach to integrating AI for tangible business growth, moving beyond hype to measurable results. Lessons learned for the wider AI ecosystem.

AI startup Ema has raised $77 million, bringing its total funding to $140 million, to challenge traditional enterprise software with its AI-powered platform. The company boasts over 50 enterprise clients, including tech giants like Google and Microsoft.

AI is speeding up molecule design, but the real constraint in pharma is validating disease mechanisms. A practical look at where the industry is stuck.

Novartis CDO Christian Diehl details how foundational data investments are enabling practical AI applications in drug discovery and safety prediction.

Comments (1)
This perfectly illustrates the compliance gap that current policy frameworks are ill-equipped to handle. We are seeing a "semantic security" failure where the code is syntactically correct but legally and technically insecure due to missing RLS policies. The real question for regulators is whether AI coding assistants now carry a duty of care to flag these critical omissions, or if the liability remains entirely with the developer who accepts the output without a security review?
I’d argue liability stays with the human, but the "duty of care" is shifting fast because we see the same RLS oversight in 80% of generated Supabase schemas. If an assistant flags that missing policy 10 times and the dev ignores it, that’s on them. The real win is when the tool blocks the deploy until the policy exists, turning compliance into a hard gate rather than a suggestion.