2025 ·English ·21 slides ·221 views

A fool with a tool is still a fool - Plone Conference 2025

Why we have to use AI wisely

Slide 1 of 21 — A fool with a tool is still a fool - Plone Conference 2025
1/21 arrow keys or swipe · click image for fullscreen
Slide 1 of 21 — A fool with a tool is still a fool - Plone Conference 2025
1/21

Details

Uploaded
17 October 2025
Language
English
Slides
21
Image size
2048x1152
Views
221
SlideShare ID
283834245
Uploaded format
PDF
Collected
2026-09-27

Source & completeness

Content
original + reconstructed
Validation
passed
Slide text
available (19 slides)
Original files
yes
  • original.pdf PDF · 21.5 MB · 21 slides
Checksums (SHA-256)
  • original.pdf: d83e2b0e4cdc24059d4df3f707d7589d8bccaa3463a20aa0ddb65b9932f2049b

Slide images come from SlideShare's public renderings (2048x1152 px, WebP). Any file marked as reconstructed is assembled from those images and is not the author's original source file.

Full text of every slide

Text extracted by SlideShare from the slide images — may contain OCR errors. 19 of 21 slides have text.

1
Andreas Jung | info@zopyx.com | www.andreas-jung.com A fool with a tool is still a fool Why we must AI wisely! Plone Conference 2025 Jyväskylä
2
Recent AI„indicents“ 😂
4
Agenda • Current state of AI tools in software development • What are the safe practices for using AI tools in today’s world? • „Vibe Coding“ • What is„Vibe Coding“? • Experiences • Conclusions
5
Recent AI models for software development Model/Provider Cost / Access Context / Max Window OpenAI – GPT-5 Input $1.25M / Output $10M tokens ≈400,000 tokens (≈272k input + 128k output) Anthropic – Claude 4.5 Sonnet Input $3M / Output $15M tokens ≈200,000 tokens (extended thinking up to 128k output) Google – Gemini 2.5 Pro Flash-Lite: Input $0.10M / Output $0.40M (higher for Pro/Ultra) Up to 1,000,000 tokens (Pro/Ultra tiers) Meta – Llama 4 (Scout / Maverick) Open weights (infra cost depends on deployment) Scout: up to 10M tokens; Maverick: ~1M tokens Microsoft – Copilot (GitHub/M365) ~$20/month Copilot Pro; API costs match chosen model Inherits from underlying models (GPT-4.1, GPT-5, Gemini etc.) • Token window = how much code AI can“see”at once. • One line of code ≈ 5–10 tokens, so window size limits how many lines fi t in context. • Models, numbers and pricing changing almost every day
6
✅ Where AI works reliably? • Generate boilerplate/initial codebase code for new projects • Create tests and test data • Explain & document code • Write project documentation, installation notes etc. • Support for refactoring, migrations
7
❌ Where AI notoriously fails and fools us/me • Lack of self-re fl ection regarding • completeness of work • consistency of work • correctness of work •🤥 AI constantly lies to me
8
2½ successful AI stories in the last 12 months
9
✅ E.ON Guarantees Of Origin - certi fi cates in renewable energy • FastAPI application deployed in Azure, • Integrations with various other E.ON systems • 🤯 over-designed architecture, under-engineered implementation, 50% coverage, hard to maintain and extend (blaming the junior dev) • Claude Code: • 70 → 400 tests, coverage 50% → 95% 😎 • refactoring and highly improved CI/CD in Azure DevOps • foundation for further refactoring
10
✅ University of Saarbrücken Central university shop and procurement system • 2015: Plone 4.3 site (Dexterity), ArangoDB, on-premise hosting • 2025: migration to Plone 6.1, Python 3.12, Azure hosting, updated functionality, decent UX, docs • Claude Code for • complete source code documentation • deployment con fi gurations for Azure (Terraform, Ansible) • massive migration from jQuery to native Javascript • consistent view and templates, highly improved UX • shiny, complex forms (originally ugly Dexterity forms) • Claude Code enabled me to master deployment and frontend alone (not my primary skill or interest).
11
🧐 Open Grid Europe (OGE) Simulation of hydrogen distribution networks in Germany • 12.000 km gas backbone distribution network in 🇩🇪 aka gas pipelines • 🇩🇪 government decided to enable distribution networks for hydrogen (Ukraine war, Germany’s dependency on Russian gas) • completely new territory: • gas and hydrogen have very di ff erent physical parameters (density) • di ff erent behavior inside pipelines (pressure and fl ow) • new network components like electrolysers (hydrogen producers) → a simulation software is needed
13
🧐 Open Grid Europe (OGE) Simulation of hydrogen distribution networks in Germany • AI development totally gone wrong • Physicists/non-programmers„trying“ to program using AI • AI-generated code doing *something* • AI-generated code thrown over the fence because„AI got stuck at some point“ or they got stuck with AI • no tests • no formal speci fi cations • 🤯 😭🧐 • Claude Code: • ~300 generated tests as foundation for refactoring • ..and then the project budget was exhausted 🤡 🥰
14
Vibe Coding Vibecodingisasoftwaredevelopmentmethodthatinvolvesgivingnaturallanguagepromptstoalarge languagemodel(LLM)togeneratecode,focusingoniterativeexperimentationwiththeAI'ssuggestionsrather thandeep,traditionalcodereview.It'sahands-o ff ,AI-drivenapproachthatmakescreatingsmall,low-stakes softwareprojectslikeprototypesandsimpleappsfasterandmoreaccessible,thoughitintroducessigni fi cant riskstosecurityandmaintenanceincomplexsystems. - Andrej Karpathy (former Sr. Director of AI atTesla)
15
Vibe Coding: Market Promises vs. Reality The promises • Democratize coding →“anyone can build software” • Faster time-to-market, rapid prototyping • Lower cost & resource needs • Direct idea → product fl ow • New developer role: orchestrator/prompt engineer • More innovation, more experiments
16
Vibe Coding: Market Promises vs. Reality Own experiment: relaunch of my website zopyx.com • old: Wordpress, new stack: AstroJS, Tailwind CSS, 3 languages, Cursor IDE. • ✅ Marketing texts and wording based on existing website, CV, and hints. • ✅ Rapid initial iterations with promising outcomes (shiny, nice Tailwind usage) • 🤨 Subpages generated with random AstroJS component structure. • 🤨 Ongoing refactoring problematic (destruction of its own code). • 🤨 Language trees: incomplete work, inconsistent work, and painful iterations. • 🤥 AI constantly lying at you, doing incomplete work, lying about progress. • 😭 AI digging its own hole with little chance to escape from by itself.
17
• Works best for MVPs, sca ff olding, internal tools • Human oversight essential (debugging, testing, validation) • Fragile code, tech debt, security risks • Limited by context windows & model accuracy • Poor fi t for complex, mission-critical systems • Adoption is incremental, not disruptive overnight Vibe Coding: Market Promises vs. Reality The reality
18
• Unknown provenance of AI code → treat outputs like unveri fi ed paste. • Copyleft spillover risk (GPL/AGPL) → accidental inclusion can force disclosure. • No copyright in purely AI-generated code → only your human edits are protectable. • EU AI Act = transparency, not liability shield → you still own compliance. • Governance controls required → run SCA/clone scans, keep logs, add notices, check license compatibility, maintain indemnity settings. • Patent exposure (FTO) → generated code may implement patented methods; verify before shipping. Vibe Coding: Market Promises vs. Reality Other issues and consequences (excerpt)
19
• Accountability doesn’t move: We own correctness, security, and delivery. • AI governance: We de fi ne where AI is allowed, with guardrails and red-zones. • Quality gates:“No unreviewed AI code.”(Tests, benchmarks, threat modeling) • Licenses & provenance: Run SCA/clone checks; block unclear/GPL/AGPL drift. • Architecture fi rst: Use AI for sca ff olds; humans own contracts & non-functionals. • Security posture: Treat AI output as untrusted until scans/review pass. • Auditability: Tag AI-assisted PRs; keep prompt/output logs; maintain SBOM/“AI-BOM”. • Metrics: Track defect density, rework, coverage/perf deltas, and token spend. Responsibilities for (us) senior developers? Vibe coding doesn’t reduce a senior dev’s responsibility
20
AI is a tool. But wisdom is the di ff erence.
21
Images: OpenAI Sora