AI Coding Agents Grow More Powerful, Costly, and Riskier

In her keynote at QCon London, Birgitta Böckeler, AI-Coding lead at Thoughtworks, examined the evolving landscape of AI coding.

2 min readInfoQ
AI Coding Agents Grow More Powerful, Costly, and Riskier

The shift from vibe coding to autonomous agents is real, and it comes with a price tag that teams need to reckon with now. Birgitta Böckeler's QCon London keynote pulls back the curtain on a year of rapid evolution, and her warnings about security and cost should command attention from anyone building software today.

For most teams, the appeal of agent-based development is obvious: swarms of AI agents can write, test, and even deploy code faster than a human ever could. But Böckeler's insight is that this speed is not free. The security landscape is worsening because agents operate at a scale that outpaces traditional review processes. When a single agent can generate hundreds of lines of code in minutes, the surface area for vulnerabilities expands exponentially. Meanwhile, the cost of running these agents, compute, API calls, orchestration, can balloon without careful governance. The question is no longer whether agents can write code; it is whether your organization can afford the risk and the bill.

What this means in practical terms is that adopting coding agents requires a new discipline. Teams that treat agents as drop-in replacements for human developers will find themselves debugging security holes and watching budgets spiral. The smart approach is to treat agents as junior collaborators that need supervision, not as autonomous production engines. Böckeler's observation about the shift from vibe coding, where developers accept whatever the AI outputs, to structured agent workflows is the right instinct. But that structure must include guardrails for security scanning, cost monitoring, and human review loops.

The bottom line is that the future of development is not about choosing between humans and agents. It is about designing systems where both operate with clear boundaries. If your team is exploring coding agents, start with a pilot that measures security incidents and cost per feature, not just speed. That data will tell you whether the trade-off is worth it.

From InfoQ

In her QCon London keynote, Birgitta Böckeler, AI-Coding lead at Thoughtworks, reflected on the changes in the AI coding space over the past year. She emphasised a shift from vibe coding to using autonomous coding agents or swarms of agents. According to her, two major concerns in the field are the worsening security landscape and the rising costs of agent-based development.

Read the original at InfoQ