Building an app with AI is easy now. That may be the problem: duplicates, abandoned apps and trust. Three things I expect next, and where I may be wrong.
I’m not a developer. And I’m part of the problem I’m about to describe.
In a few months I’ve built several products with AI tools, or what people now call vibe coding. A new-home build tracker, a chatbot generator, a career copilot, a log analysis tool, and Verilay itself. None of them needed me to write code. Some of them work well. All of them were easy to start.
That’s the thing nobody says out loud: starting is no longer the hard part.
Here’s the honest part. I don’t think “easy to build” is the good news it looks like.
98% of 1,072 apps built on AI platforms had at least one security flaw, and 16% had a critical one, according to a June 2026 scan by Symbiotic Security. In companies, people building apps now outnumber professional developers four to one, according to a survey of 200 security leaders.
Those aren’t predictions. People went and counted.
So more apps are being made, by more people, with less checking. That’s the “chaos” in the title. I think it shows up in three ways. These are my guesses, not facts, and I’d like to be told where they’re wrong.
When anyone can build in a weekend, building stops being the scarce thing. Attention is. Most new apps will get a handful of visitors and quietly fade.
That’s how every wave went before, from the early web to app stores. This one is just faster.
I tried something. I searched GitHub for open-source projects like six of my own products.
Same idea, built again and again, mostly by people who never met each other. Some of that is healthy. People learn, and competition helps. But a lot of it is weeks of effort spent on something that could have been found in an afternoon.
This is the one that worries me most.
An app isn’t finished when you ship it. The pieces it’s built from get new security problems found in them, long after you stopped looking. I wrote about what happened when my own app’s records quietly stopped being true. Nothing broke. It worked perfectly the whole time.
Now imagine thousands of apps, built in a weekend, never looked at again, still holding people’s data.
I think when there are millions of apps, “does it exist?” stops being the interesting question. “Can I rely on it?” takes over.
The big platforms already ask. Microsoft requires every Teams app to complete a security and privacy attestation. Google requires some apps that handle sensitive user data to go through extra verification, and sometimes a formal security assessment, which can take weeks.
A small builder with a good idea can get stuck at that gate, not because the idea is bad, but because nobody told them what the gate checks.
Verilay started as a way to answer one question for people like me: is this safe to share? It’s still that. Here’s what it does today, and what it doesn’t.
I should be clear about the limits. Verilay’s findings are written by AI, so they can vary between runs. It isn’t a penetration test, and it isn’t a certificate. I don’t fix your app for you, on purpose: the one time I tried automating that, it nearly broke everything. It tells you what it sees and what to check.
I don’t know if people want monitoring. Maybe the thing that matters most is that duplicates get found earlier. Maybe the platforms’ gates get easier and none of this matters.
So I’m asking. If you’ve built something with Lovable, Replit, Bolt or Cursor:
If you’d want monitoring for your own apps, there’s a short page where you can register interest. Nothing is for sale, and I’ll only email you about that.