04/09/2026
A question we get asked a lot at the moment: "can you just check the app my nephew built with AI is actually safe?"
Yes we can. But the thing people expect us to find is almost never the thing we find.
Everyone imagines a hacker. What actually turns up is much more boring, and much more likely. Two customers use the app. One of them changes the number at the end of a web address and gets to look at the other one's invoice. Nothing was broken into. The app was simply never told that those two customers are not supposed to see each other's things.
That is not an AI problem. We have been finding the same thing in hand written software since 2008. AI has just made it possible to build an app very quickly without anyone ever sitting down and deciding who is allowed to see what.
If you have got something running that holds other people's details, the cheapest thing you can do this week costs nothing. Get a second account, log in as that, and try to look at the first account's data. If it works, you have found it before somebody else did.