Skills Are Not for Writing the Code. They Are for Knowing What to Ask
An Italian streamer shipped a social network built entirely by AI for forty euros, and its admin panel was one URL away from anyone. He knew the risk and shipped anyway — which is the part worth talking about.
For a couple of years now a belief has been going around that has done more damage than shows on the surface, and it is that building something technical only takes a good idea, because the AI will handle everything else.
It is not true, and the annoying part is that it stays believable long enough to carry you a good distance before you find out. AI tools are genuinely powerful and I have no interest in pretending otherwise, since they cut down the time between an idea and something that actually runs; the catch is that they cut it down for people who already know what they are doing, while for everyone else they only shorten the distance to the moment you discover it does not work — and by then there are real users inside.
The Baudr case, which at least happened in the open
The most discussed Italian example is Grenbaud, who on 14 March 2026 launched Baudr live on Twitch, a social network for people in his community to find each other, openly saying he had built the entire platform using only AI, that it had cost him around forty euros, and that he had consulted neither an engineer nor a lawyer. In the same stream he also admitted that the security of the database could not be guaranteed one hundred percent.
A few hours after launch, users discovered that the admin panel could be reached by typing /admin into the address bar, because the check that should have stopped them lived only in the JavaScript running on the visitor’s own machine rather than on the server, where it belonged. What followed was thousands of accounts deleted in bulk — including Grenbaud’s own —, personal data downloaded by people who had no business having it, and fraudulent messages sent from compromised accounts, to the point that he had to step in publicly and say “to the girls I messaged, if you got anything strange from me, that was not me.” The full technical breakdown, with the stack and the other holes that surfaced, is in this analysis by Pasquale Pillitteri, and it is worth reading in full.
In case you are wondering what was in there: Twitch IDs, personal photos, names, ages, cities, hobbies, music preferences, Instagram usernames and private messages. Put together, that draws a person in remarkable detail.
And here is the part that actually interests me, because he knew. He had said it on stream, in front of thousands of people, that security was not guaranteed. He shipped anyway. Not out of recklessness, I think, but because the moment was there and waiting meant losing it — which is exactly the mechanism this whole piece is about.
I am not bringing him up to pile on, quite the opposite: he did it in the open, live, and that is a great deal more transparent than the many companies doing the same thing behind closed doors, with nobody watching them do it.
Intuitiva, the example I know best
Because the part nobody sees is by far the larger one, and I have seen one of those cases from the inside.
I work on Intuitiva, a healthcare platform already in production with real users, and the engineering teams before me built much of it with these tools, driven by speed rather than by any understanding of what they were assembling. I am now rebuilding it from scratch to stricter standards, and it is not a cleanup job: it is a reconstruction, one domain at a time.
I will not go into the technical specifics, partly because that is not what this piece is for and partly because while the old system is still standing, some things do not get discussed in public. The point I need is a different one, and it is that from the outside everything looked fine: it ran, users signed up, nobody complained. The bill was somewhere else and simply had not arrived yet — and the only difference from Baudr is that there it arrived in four hours, in front of an audience.
In Italy the bill is steeper than elsewhere
We have the GDPR, which is not a formality you settle with a cookie banner, and if you handle personal data — let alone health data — you carry specific obligations about what you keep, for how long, who may read it, and above all what you must be able to demonstrate to a regulator the moment they ask.
None of that surfaces on its own while you are asking a model to write you a feature, and not because the model is weak, but because those are questions you have to put to it, and to put them you need to know they exist. That is where the whole argument lands: you cannot build serious applications on a monthly subscription to whatever AI shipped last, however good it is.
What this thing is called
We call it FOMO, fear of missing out, and I am convinced that a great many people and a great many companies are being steered by exactly that, as though AI were a goose laying golden eggs and every month spent not squeezing it were market share handed to somebody else.
Inside companies, though, the word is not quite accurate, because it is not that they are afraid of missing something: they are afraid of having to explain to a board, an investor or a client why they did not do it, which makes it a defensive decision, taken almost always by people without the means to evaluate what they are adopting. And a defensive decision taken without competence is precisely how you end up with systems somebody else has to rewrite from the ground up.
Salvatore Sanfilippo covered this in a video I would recommend, because he says it better than I am saying it here and he says it from a position that is not the nostalgic one: skills sit above pure vibe coding not as a matter of principle, but because without them you cannot even tell what you are reading when the tool answers you.
Google, which forced AI into a place where there was no problem
The example that jumps out at me most is search, and not so much because the answers generated inside the results page work badly — though they often do — as because that feature was not solving any problem I had. Searching for something and getting back a set of links to choose from was working fine: it was not broken, it was not waiting to be fixed, and nobody had ever complained about having to read three results before deciding which one to trust.
The AI in there did not arrive because I needed it, it arrived because they needed it. It is a feature born out of having to prove you are in the race rather than out of solving anything, and it is the same fear I described earlier, only now you are watching it at the highest level there is: if even the company that essentially invented search feels the need to bolt AI onto it so as not to look behind, then this is not a story about unskilled people leaning on a tool they do not understand. It is a climate.
The trouble is that when you force a tool into a place it was not needed, the cost lands on whoever uses it. The generated answer arrives before you have seen any alternatives, before you have formed a view of who is saying what and with what interest, and the critical choice is taken away upstream; on top of that, unlike other engines, they do not even give you a simple way to opt out, since DuckDuckGo documents how to turn generated answers off and offers a dedicated address that excludes them entirely, while on Google all you are left with is an undocumented URL parameter.
Add that paid results occupy the top of the page and push the organic ones off the first screen, and you get a system where paying does not improve your organic ranking but has no need to, because it buys you the space above it.
I am well aware that Google has strong models and excellent people, but having pervasive distribution and being the right place for a given product are two different things, and in tech especially the second is not something the first can buy.
A name, on its own, does not hold
This holds outside software too, since there are enormous brands that have made product decisions convinced the strength of the name would cover everything else, only to find out it covered almost nothing.
The parallel with AI seems fairly direct to me, because plenty of companies today are using “we use AI” exactly the way you use a brand, as though saying the words were already the product.
Who is doing it with their head instead
What I find interesting about what is coming out of China, and out of DeepSeek in particular, is not the race toward the smartest model but the work done on cost per token, which is a boring, concrete choice and for that very reason convinces me a good deal more than the triumphant announcements: they are not chasing perfection, they are making economically sustainable something that at current prices is not.
The bill that has not arrived yet
My sense is that the real reckoning will not be technical but accounting, because a lot of companies cut staff by labelling them unproductive, convinced the tools would cover the gap, and when the cost of tokens becomes a line item nobody can keep pretending not to see — and when it becomes clear that somebody has to check those answers — I suspect a fair number of those people will be called back, with the company having paid twice, once for the cut and once for the return.
I have no numbers on this and no intention of playing prophet, so take it for what it is: a prediction, written as one.
Where I have landed
There is something I only understood by lining these examples up, which is that it would be convenient to tell this story as a matter of competence: on one side the people who know how to build, on the other the people leaning on a tool they do not understand. Except it does not hold, because Google invented search and bolted AI onto it anyway, at a point where it served nobody. The fear of being left behind does not spare people with the skills: it makes them take bad decisions about things they are excellent at, and since they have the distribution to impose those decisions, the rest of us pay for them.
We are living through a stretch where people believe the illusion sold by those with every interest in selling it, and in doing so stop listening to their own judgement; it would be enough to stop for a moment, stop chasing, and ask whether the goal we are running after is actually ours or somebody else’s.
I am not saying don’t use AI, which I use every day and which has made me faster at things that used to cost me weeks. I am saying that a tool only answers the questions you ask it, and that the right questions come from what you learned before you opened it: skills are not for writing the code, they are for knowing what to ask and for recognising when the answer you got is not the one you needed.
Then you also need the nerve to say “I am not shipping this”, which is the part nobody teaches you and which, for Grenbaud, live, in front of thousands of people who were waiting, would have cost a lot. It would still have cost less than what came after.
That part does not come with a subscription.
References
Related
An MVP that holds up in a demo with three users isn't an MVP that holds up in production. Plaintext data, broken permissions, a fix that broke five others — what I found opening a codebase built fast with an AI coding tool, and the rule I use now before deciding whether to patch it or rip it out and start over.
Designing a healthcare logging schema on paper is easy. Booting it exposed a hashed-user count that was quietly wrong, a device fingerprint that walked straight past redaction, and a TTL test that proved a caveat I had only written down.
I read a public site's cookie banner and its privacy policy end to end. The banner has no reject option, and the policy declares a data-retention date six years in the past. Neither is a typo — they're the same mistake, twice.
Get new posts by email
No hype, unsubscribe anytime. · Powered by Buttondown