The Governance Gap Vibe Coding Created
Marketing teams are committing code. Sales engineers are spinning up dashboards that touch production data. This is not hypothetical — it's the operating reality at a growing number of enterprises where the developer population is expanding by an order of magnitude, per VentureBeat Intelligence's analysis. The old assumption that governance happens at the boundary between "developer" and "not-developer" dissolved quietly while everyone was still writing policy documents about shadow IT.
The industry doesn't have a vibe coding problem, according to Shekhar Manjrekar of Fabrix.ai. It has a vibe governance problem. That distinction matters more than it sounds like on first read. It reframes what is AI governance in 2026: not a question of whether non-developers should be building things, but whether the platform beneath them has any opinion about what they're allowed to build or what it costs.
Fabrix.ai's answer — launched in production with paying customers earlier this year — is something they call Governed VibeOps. The thesis is architectural, not philosophical.
From Policy Document to Execution Path
Rob Strechay, lead analyst at VB Intelligence, put the current inflection point bluntly during a panel at VentureBeat: governance is moving out of policy documents and into the execution path. "DevOps really governs the delivery pipeline," he said. "What I love about VibeOps is it's aiming to govern the intent, the context, and the agent decisions that flow through it."
That's a useful frame. Traditional AI governance — the kind IBM and McKinsey published foundational frameworks for a few years ago — treated governance as a review step. You build something, someone checks it against principles, it ships or doesn't. The problem is that vibe coding generates artifacts faster than any review queue can absorb, and the people generating them often lack the training to even recognize what needs review.
Governed VibeOps inverts the model. IT operations staff describe what they want in natural language. A central platform inspects the generated code. Token spend is metered before anything reaches production. The governance isn't a gate at the end, it's the floor the code walks on.
"When you implement governance properly, you're not going to slow down those creative instincts," said Rached Blili, a distinguished engineer at Fabrix.ai. "You may actually accelerate them." The specific concern governance addresses here isn't just security. It's duplication. Without a shared platform, three different teams build three nearly identical dashboards hitting the same data sources, each burning tokens independently.
Agentic Data Federation as Infrastructure
The architectural backbone of Governed VibeOps has three layers worth understanding for anyone thinking about AI cybersecurity governance in practical terms.
First: agentic data federation. When a customer connects a data warehouse, a ServiceNow instance, or a telemetry pipeline, the platform maps it via what Fabrix.ai calls a living ontology, a persistent representation of what data exists and where it lives. Agents use this ontology to locate data without requiring full ingestion into a central store. For enterprises already navigating the unpredictability of agentic AI in production, this pattern matters. Data stays put. The agent travels to the data, not the other way around.
Second: a context engine that enforces context purity and manages token consumption through a memory architecture. Tokens aren't infinite, and context pollution, irrelevant data bleeding into a prompt window, degrades output quality. The engine treats both as first-class constraints rather than afterthoughts.
Third: a harness that bundles observability, FinOps, and evaluation. Coding agents offload detail work to this infrastructure and inherit access control, auditability, traceability, cost metering, and evaluation as platform properties. That last phrase is the one to sit with. The agent doesn't assemble permissions from scratch each session. It inherits them. When AI agents borrow human credentials, the blast radius is a design question, not a runtime discovery.
Small Models, Specific Jobs
The governance layer doesn't run on a frontier model. It runs on a family of three small language models under the Argos name, ranging from roughly 4 billion to 8 billion parameters.
Argos VX handles platform semantics: generating vibe-coded applications, AI agents, and data pipelines. Argos AIOps holds correlation policies and reads customer telemetry. Argos VE scores vulnerability exposure, what does a newly disclosed CVE mean for this specific estate, and how far does the blast radius extend?
"You don't need a frontier or foundational model for every task you're trying to accomplish in your workflow," Manjrekar said. The models run locally on customer data. Information stays put. Latency drops. Fabrix.ai's own platform pipelines consume zero tokens, a significant share of data management work is moved entirely off the billing meter.
This is where the risks conversation around agentic AI gets more interesting than the generic version. McKinsey and other research firms have flagged unpredictability, expanded attack surface, and the identity governance challenges of agents operating with borrowed credentials as core security concerns for enterprises deploying agentic systems. Small, specialized models that stay on-prem and never see their training data leave the network address several of those risks structurally. Not through policy. Through architecture.
Reliability Beats Cost as the Metric That Matters
VentureBeat Pulse survey data shows reliability has overtaken token cost as the top AI agent metric for enterprises. The VB Intelligence panel found 63% of polled organizations were either running a governed semantic or context layer in production or piloting one, with another 20% actively evaluating.
That's not a fringe experiment. That's the median enterprise trying to make AI governance real in some operational form, the same shift happening in adjacent areas like shadow AI detection and endpoint governance, where non-technical creation is reshaping the security perimeter.
But governance at this layer carries an operational tax. Platform teams need to watch individual sandboxes, inspect generated code, and confirm nobody is consuming tokens outside contract. The human overhead is real even when the platform overhead is low. There's no getting around the fact that governed vibe coding still requires humans who understand both the code and the constraints.
Tokenomics for People Who Don't Care About Tokens
Strechay made a point during the discussion that should land with anyone who's tried to explain LLM costs to a finance team. FinOps, as currently practiced, is disconnected from the work itself. It reads a monthly bill after the fact. Tokenomics needs to connect the agent, the workflow, and the business outcome, or it's just another cost center nobody can justify.
"CFOs don't understand tokens, and they don't want to understand tokens," Strechay said. "They want to understand business outcomes from development. And if you're having these many more developers, they want to know what their investment is gaining them."
Fabrix.ai describes a customer progression that maps loosely onto this: initial productivity gains, then tool consolidation, then a blurring of traditional operational disciplines. "Right now, SecOps and ITOps are essentially working off of the same set of data," Manjrekar said. "Over a period with VibeOps, you would see this collapsing around data."
What This Gets Right
The vendor incentive problem is obvious. Fabrix.ai sells the platform that solves the problem they've named. But the architectural argument underneath survives that critique. Governance inherited from a platform beats governance assembled by hand. Small models trained on your data beat frontier models trained on the internet. Reliability measured at the agent level beats reliability assumed at the model level.
The broader lesson for anyone serious about AI cybersecurity governance: stop governing the model. Start governing the environment the model operates in. The generated code is the least interesting part of the problem. The permissions, the data access paths, the audit trail, the monthly bill, that's where the risk concentrates. And that's where governance either works or doesn't.