Fetching from the wire…
Top 5 · 2026-03-30 · source-backed
After mandating 80% weekly usage of their AI coding assistant Kiro, Amazon pushed an AI-assisted deployment that knocked out checkout, login, and pricing for six hours. The estimated damage: 6.3 million lost orders. Amazon's internal data shows 1.7x more major issues and up to 2.7x more XSS vulnerabilities from AI-generated code compared to human-written code over the same period.
Amazon's response was immediate: a 90-day mandate requiring senior engineer sign-off on all AI-assisted production deployments. That's the first major enterprise rollback of an AI coding mandate. They went from "everyone must use AI" to "a human must approve everything AI touches" in the span of one incident.
But the Amazon story is just the headline. The systemic data is what worries me. CVE entries attributed to AI-generated code jumped from 6 in January to 15 in February to 35 in March 2026. Developer favorability toward AI tools collapsed from 77% in 2023 to 60% in 2026, with only 33% trusting AI code accuracy, down from 43% in 2024. A vibe-coded app exposed 1.5M API keys and 35K user emails via a misconfigured database, and the developer admitted they hadn't written a single line manually.
Then there's Cursor's own CEO telling Fortune that vibe coding builds "shaky foundations" where "eventually things start to crumble." When the CEO of one of the primary beneficiaries of AI coding adoption publicly warns about structural limits in the dominant usage pattern, pay attention.
I think the backlash is real but the framing is wrong. The problem isn't AI-generated code. The problem is AI-generated code without review gates. Amazon didn't fail because Kiro wrote bad code. Amazon failed because their mandate pushed AI code through the pipeline faster than their review process could catch problems. The 90-day senior-engineer sign-off mandate is the right move, and every team shipping AI-generated code to production should implement something similar yesterday.
Source: Security Boulevard | The New Stack | Crackr.dev Wall of Shame
Each link below shares sources, entities, or timing with this story.
The June 12 release connects Cursor, Claude Code, Windsurf, VS Code, Amazon Q, and Kiro to pipeline, build, log, test, and workflow data over MCP. Agents can reason over CI state, like diagnosing a failing build straight from logs, without copy-paste. MCP is becoming the defau...
Evan Spiegel told Fortune that AI now writes two-thirds of Snap's code, crediting Anthropic's Claude specifically as "transforming software development, full stop, at Snap in every part of our organization." He predicted companies will reallocate resources from engineering to...
Fortune published a deep-dive on May 21 that should make anyone building on Microsoft's AI stack uncomfortable. After spending $13B+ on OpenAI and projecting $190 billion in 2026 capex (more than double 2025), Microsoft Copilot has reached just 20 million paying M365 users out...
Engineer Alexey Grigorev was using Claude Code to update a website when it destroyed the production database holding years of course data — caused by a laptop config issue that confused the agent about what environment was real versus safe to delete. Amazon convened a deep-div...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
A year ago, GitHub Copilot was the default. Two out of three professional developers used it. That number is now barely half. CNBC reports that Copilot's share among professional developers dropped from 67% in 2025 to 51% in 2026. Cursor jumped to 29%. Amazon Q Developer grabb...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.