Key Takeaways
- Citizen development is back in the conversation — this time because AI app-builders promise anyone can ship software. By 2025, Gartner projected 70% of new applications would be built on low-code or no-code.
- For a prototype or a low-risk internal tool, that route delivers. For the system an enterprise runs on, it isn’t the whole picture.
- The evidence is piling up: a 2025 scan of 5,600 production "vibe-coded" apps found zero with basic security controls, and AI-generated code carried 322% more privilege-escalation paths than human-written code.
- 63% of organizations have no AI governance policy — so most of this is happening with no one watching.
- The final product — governed, integrated, secure, built to last — is still an engineering job. That’s the line to know.Right now, it feels like every enterprise is hearing the same pitch:
“AI has made everyone a developer, so you can build the software yourself and stop waiting on engineering!”
And for a quick prototype, that might be a fair assumption.
But for the system your business runs on, it’s not the whole story.
Why is everyone talking about citizen development again?
Citizen development — business users building their own apps on low-code and no-code tools — isn’t new.
The phrase had gone quiet, but AI brought it roaring back.
What’s important is that the promise is bigger this time: you don’t even need the low-code skills.
According to these tools and talking heads, you can simply “prompt” it all into existence. Just describe what you want, and let AI build it. "Vibe coding" went from a fringe idea to broad enterprise use in about sixteen months.
The pressure behind the idea makes sense. Developer demand keeps outrunning supply, and IT backlogs never shrink.
As one enterprise product chief put it, GenAI "lowered the fluency bar from ‘can you code’ to ‘can you reason about the problem.’"
We’re not here to argue with any of that. We build on Quickbase and Mendix every day, and we use AI across our own work. For the right job, these tools are a genuine unlock.
The question isn’t whether they work. It’s what happens when the thing you built has to become the system your business depends on.
What the AI and citizen-development route delivers
Give it credit: this route is fast, and for a whole class of work it’s the right call.
- A team dashboard
- A workflow that routes approvals
- A one-off tool to get through a busy quarter
- A prototype to prove an idea before you invest in it
That’s very real value. Getting the easy 80% of an app built in an afternoon, with no formal project, is exactly what these tools were built for.
So, what’s the issue? The trouble starts when that prototype quietly becomes production — when the tool everyone now depends on was never built to be depended on.
Where do citizen developer AI tools hit the ceiling for an enterprise?
An internal tool that breaks is an annoyance. An enterprise system that breaks is a compliance event, a security incident, or a stopped operation.
That’s the difference the pitch skips, and the data on AI-built software is worth taking a look at.
A 2025 scan of 5,600 production applications built by "vibe coding" found none — zero — with basic protections like security headers or properly scoped access.
The 2025 scan
0 of 5,600
Production “vibe-coded” applications scanned had basic security controls — no security headers, no properly scoped access.
Fast to build. Not built to ship.
Source: Cloud Security Alliance, 2025
In a separate study across Fortune 50 codebases, AI-generated code carried 322% more privilege-escalation paths and 153% more design flaws than human-written code.
Most of it ships with no one watching. 63% of organizations report lacking an AI governance policy at all, and more than half of employees already use AI tools their company hasn’t approved.
Then there are breaches involving "shadow AI" — ungoverned AI tools and apps. Organizations with high levels of shadow AI paid about $670,000 more per breach than those with little or none.
The last mile is where enterprise systems live: scale, integration with your systems of record, security, compliance, and surviving the person who built it. That’s precisely the mile the DIY route skips.
Why is the final product still an engineering job?
None of this makes AI or low-code the problem. It makes the missing layer obvious.
The market is already circling the answer. The consensus forming around enterprise AI is to draw boundaries "around risk, not roles" — let business users build the low-risk things, and put engineering around anything sensitive or core.
That’s the concession hiding in plain sight: the moment it’s real, you need engineering.
We call the sequence Structure Before AI. Get the foundation right — data models, integration, governance, ownership — then let AI and low-code accelerate the build on top of it. Low code moves the work. Human-guided structure makes it a product.
Power without direction is just chaos moving faster. AI moves it faster still. Structure was the difference between the apps that lasted and the ones that didn’t.
What does this mean if you run enterprise operations?
The move isn’t to ban the tools or hand everything back to a two-year backlog. The move is to know the line.
Use AI for what it’s built for — prototypes, low-risk internal tools, proving an idea quickly. When one of those has to become the system your business runs on, treat it as what it is: a professional build.
Know the line
Prototype vs. Production System
Prototype / Internal Tool
Real value, for the right job
Production System
An engineering job
The concession hiding in plain sight: the moment it’s real, you need engineering.
That’s the work we’ve done for 17-plus years — 700-plus applications for organizations like Google, Toyota, PayPal, Skanska, and Geisinger, as a Quickbase Elite and Mendix Gold partner. We are the experts, so your team doesn’t have to be.
For example, Geisinger partnered with our team of expats to replace two $100,000 compliance systems with one governed application – saving them more than $200,000 a year — a system built to be trusted, audited, and run on.
Start the prototype however you like. Just know the moment it needs to become the real thing.
Know the moment your prototype needs to become the real thing
That’s the conversation worth having early.
Talk to us before an AI or low-code prototype becomes the system your business runs on, and we’ll help you build it as a real, governed product — one that scales, integrates, and holds up.
Book a discovery call today
Frequently Asked Questions
What is citizen development?
Citizen development is the practice of business users — not professional engineers — building applications on low-code, no-code, or AI tools. It is meant to relieve IT backlogs by letting the people closest to a problem build the solution.
Can AI and citizen developers build enterprise-grade applications?
They can build prototypes and low-risk internal tools quickly and well. Enterprise-grade systems — integrated, secure, compliant, and built to last — still require professional engineering, because that is where scale, governance, and accountability come from.
What are the risks of AI-generated or citizen-built apps in the enterprise?
Security and governance gaps top the list. Studies have found AI-generated code carries far more privilege-escalation paths and design flaws than human-written code, and most organizations have no AI governance policy to catch it.
What is shadow AI?
Shadow AI is the use of AI tools and AI-built applications outside of IT’s visibility or governance. It is the AI-era version of shadow IT, and breaches involving it have been measurably more expensive.
Where is the line between a prototype and a production system?
A prototype proves an idea; a production system runs the business. The line is crossed the moment an app has to scale, connect to core systems, handle sensitive data, meet compliance requirements, or be maintained by more than the person who built it.
Do enterprises still need professional developers if they have AI?
Yes — in a sharper role. AI and low-code handle much of the building; professional engineers supply the architecture, integration, security, and governance that turn a fast build into a system an enterprise can depend on.
