2025 English 21 slides 221 views
A fool with a tool is still a fool - Plone Conference 2025
Why we have to use AI wisely
Details
- Uploaded
- 17 October 2025
- Language
- English
- Slides
- 21
- Image size
- 2048x1152
- Views
- 221
- SlideShare ID
- 283834245
- Uploaded format
- Collected
- 2026-09-27
Source & completeness
- Content
- original + reconstructed
- Validation
- passed
- Slide text
- available (19 slides)
- Original files
- yes
- original.pdf
Checksums (SHA-256)
original.pdf: d83e2b0e4cdc24059d4df3f707d7589d8bccaa3463a20aa0ddb65b9932f2049b
Slide images come from SlideShare's public renderings (2048x1152 px, WebP). Any file marked as reconstructed is assembled from those images and is not the author's original source file.
Full text of every slide
Text extracted by SlideShare from the slide images — may contain OCR errors. 19 of 21 slides have text.
1
Andreas Jung | info@zopyx.com | www.andreas-jung.com
A fool with a tool is still a fool
Why we must AI wisely!
Plone Conference 2025 Jyväskylä
2
Recent AI„indicents“ 😂
4
Agenda
• Current state of AI tools in software development
• What are the safe practices for using AI tools in today’s world?
• „Vibe Coding“
• What is„Vibe Coding“?
• Experiences
• Conclusions
5
Recent AI models for software development
Model/Provider Cost / Access Context / Max Window
OpenAI – GPT-5 Input $1.25M / Output $10M tokens ≈400,000 tokens
(≈272k input + 128k output)
Anthropic – Claude 4.5 Sonnet Input $3M / Output $15M tokens ≈200,000 tokens
(extended thinking up to 128k output)
Google – Gemini 2.5 Pro Flash-Lite: Input $0.10M / Output $0.40M
(higher for Pro/Ultra)
Up to 1,000,000 tokens
(Pro/Ultra tiers)
Meta – Llama 4 (Scout / Maverick) Open weights (infra cost depends on
deployment)
Scout: up to 10M tokens;
Maverick: ~1M tokens
Microsoft – Copilot (GitHub/M365) ~$20/month Copilot Pro; API costs match
chosen model
Inherits from underlying models
(GPT-4.1, GPT-5, Gemini etc.)
• Token window = how much code AI can“see”at once.
• One line of code ≈ 5–10 tokens, so window size limits how many lines
fi
t in context.
• Models, numbers and pricing changing almost every day
6
✅ Where AI works reliably?
• Generate boilerplate/initial codebase code for new projects
• Create tests and test data
• Explain & document code
• Write project documentation, installation notes etc.
• Support for refactoring, migrations
7
❌ Where AI notoriously fails and fools us/me
• Lack of self-re
fl
ection regarding
• completeness of work
• consistency of work
• correctness of work
•🤥 AI constantly lies to me
8
2½ successful AI stories
in the last 12 months
9
✅ E.ON
Guarantees Of Origin - certi
fi
cates in renewable energy
• FastAPI application deployed in Azure,
• Integrations with various other E.ON systems
• 🤯 over-designed architecture, under-engineered implementation, 50% coverage, hard to
maintain and extend (blaming the junior dev)
• Claude Code:
• 70 → 400 tests, coverage 50% → 95% 😎
• refactoring and highly improved CI/CD in Azure DevOps
• foundation for further refactoring
10
✅ University of Saarbrücken
Central university shop and procurement system
• 2015: Plone 4.3 site (Dexterity), ArangoDB, on-premise hosting
• 2025: migration to Plone 6.1, Python 3.12, Azure hosting, updated functionality, decent UX, docs
• Claude Code for
• complete source code documentation
• deployment con
fi
gurations for Azure (Terraform, Ansible)
• massive migration from jQuery to native Javascript
• consistent view and templates, highly improved UX
• shiny, complex forms (originally ugly Dexterity forms)
• Claude Code enabled me to master deployment and frontend alone (not my primary skill or interest).
11
🧐 Open Grid Europe (OGE)
Simulation of hydrogen distribution networks in Germany
• 12.000 km gas backbone distribution network in 🇩🇪 aka gas pipelines
• 🇩🇪 government decided to enable distribution networks for hydrogen (Ukraine war, Germany’s
dependency on Russian gas)
• completely new territory:
• gas and hydrogen have very di
ff
erent physical parameters (density)
• di
ff
erent behavior inside pipelines (pressure and
fl
ow)
• new network components like electrolysers (hydrogen producers)
→ a simulation software is needed
13
🧐 Open Grid Europe (OGE)
Simulation of hydrogen distribution networks in Germany
• AI development totally gone wrong
• Physicists/non-programmers„trying“ to program using AI
• AI-generated code doing *something*
• AI-generated code thrown over the fence because„AI got stuck at some point“ or they got stuck with AI
• no tests
• no formal speci
fi
cations
• 🤯 😭🧐
• Claude Code:
• ~300 generated tests as foundation for refactoring
• ..and then the project budget was exhausted 🤡 🥰
14
Vibe Coding
Vibecodingisasoftwaredevelopmentmethodthatinvolvesgivingnaturallanguagepromptstoalarge
languagemodel(LLM)togeneratecode,focusingoniterativeexperimentationwiththeAI'ssuggestionsrather
thandeep,traditionalcodereview.It'sahands-o
ff
,AI-drivenapproachthatmakescreatingsmall,low-stakes
softwareprojectslikeprototypesandsimpleappsfasterandmoreaccessible,thoughitintroducessigni
fi
cant
riskstosecurityandmaintenanceincomplexsystems.
- Andrej Karpathy (former Sr. Director of AI atTesla)
15
Vibe Coding: Market Promises vs. Reality
The promises
• Democratize coding →“anyone can build software”
• Faster time-to-market, rapid prototyping
• Lower cost & resource needs
• Direct idea → product
fl
ow
• New developer role: orchestrator/prompt engineer
• More innovation, more experiments
16
Vibe Coding: Market Promises vs. Reality
Own experiment: relaunch of my website zopyx.com
• old: Wordpress, new stack: AstroJS, Tailwind CSS, 3 languages, Cursor IDE.
• ✅ Marketing texts and wording based on existing website, CV, and hints.
• ✅ Rapid initial iterations with promising outcomes (shiny, nice Tailwind usage)
• 🤨 Subpages generated with random AstroJS component structure.
• 🤨 Ongoing refactoring problematic (destruction of its own code).
• 🤨 Language trees: incomplete work, inconsistent work, and painful iterations.
• 🤥 AI constantly lying at you, doing incomplete work, lying about progress.
• 😭 AI digging its own hole with little chance to escape from by itself.
17
• Works best for MVPs, sca
ff
olding, internal tools
• Human oversight essential (debugging, testing, validation)
• Fragile code, tech debt, security risks
• Limited by context windows & model accuracy
• Poor
fi
t for complex, mission-critical systems
• Adoption is incremental, not disruptive overnight
Vibe Coding: Market Promises vs. Reality
The reality
18
• Unknown provenance of AI code → treat outputs like unveri
fi
ed paste.
• Copyleft spillover risk (GPL/AGPL) → accidental inclusion can force disclosure.
• No copyright in purely AI-generated code → only your human edits are protectable.
• EU AI Act = transparency, not liability shield → you still own compliance.
• Governance controls required → run SCA/clone scans, keep logs, add notices, check
license compatibility, maintain indemnity settings.
• Patent exposure (FTO) → generated code may implement patented methods; verify before
shipping.
Vibe Coding: Market Promises vs. Reality
Other issues and consequences (excerpt)
19
• Accountability doesn’t move: We own correctness, security, and delivery.
• AI governance: We de
fi
ne where AI is allowed, with guardrails and red-zones.
• Quality gates:“No unreviewed AI code.”(Tests, benchmarks, threat modeling)
• Licenses & provenance: Run SCA/clone checks; block unclear/GPL/AGPL drift.
• Architecture
fi
rst: Use AI for sca
ff
olds; humans own contracts & non-functionals.
• Security posture: Treat AI output as untrusted until scans/review pass.
• Auditability: Tag AI-assisted PRs; keep prompt/output logs; maintain SBOM/“AI-BOM”.
• Metrics: Track defect density, rework, coverage/perf deltas, and token spend.
Responsibilities for (us) senior developers?
Vibe coding doesn’t reduce a senior dev’s responsibility
20
AI is a tool.
But wisdom is the di
ff
erence.
21
Images:
OpenAI
Sora