Limits, risks, and responsibility
Vibecoding makes it easier to build, but you're still responsible for what the agent can see, what it can do, and what happens when it's wrong.
What you'll be able to do
Learn to judge what information and permissions an agent should have, what risks matter, and when a task needs stronger oversight or expert help.
Use four questions:
| Question | What it helps you evaluate |
|---|---|
| What can it see? | What information and systems the agent can access. |
| What can it do? | What actions the agent is allowed to take. |
| What happens if it is wrong? | The consequences of errors or unexpected behavior. |
| Who is responsible? | Who must review and stand behind the result. |
The goal is not to avoid AI, but to use it with good judgment.
How this module is structured
Four sub-pages, in order:
1. Protect the information
Decide what the agent actually needs to see, especially when data is confidential or sensitive.
2. Control what the agent can do
Decide which actions the agent can take and where human approval is needed.
3. Understand the real cost
Consider model usage, tools, oversight, maintenance, and what happens when a workflow scales.
4. Know when not to vibecode
Recognize when a task is too high-stakes, sensitive, or complex to vibecode on your own.
Your work is still your responsibility
“The AI did it” doesn't transfer responsibility to the AI. If you submit, send, approve, or deploy the result, you're responsible for deciding whether it's appropriate.
Follow your organization's rules — and, in class, your instructor's policy — on AI use, disclosure, confidential information, and other restrictions.