When Anyone Can Build Software: The 2026 Governance Headache

By: Ben Fielding | Estimated Reading Time: 3 minutes

Keep control without killing initiative

AI app builders like Replit, Lovable, and Google AI Studio are changing how work gets done.

You don’t need a development team to build software anymore. You don’t even need a budget sign-off. If someone in your business has a problem they’re bored of doing manually, there’s a good chance they can build themselves a tool (this afternoon) using AI.

That’s a big shift.
And in my experience, it’s probably already happening quietly inside your business. As Head of Client Solutions at Nxt Gen IT, I’m seeing this more and more with UK SMEs. Not as a rogue IT issue but as well-meaning people solving real problems faster than leadership realises.


This isn’t a tech problem — it’s a governance one

When I speak to non-technical leaders, the first reaction is often concern about the tools themselves.

But that’s not where the real risk sits.

The challenge isn’t that tools like Replit, Lovable, or Google’s AI Studio tooling exist. The challenge is:

  • Who knows they’re being used
  • What data they’re connected to
  • What happens when the person who built it leaves

This is citizen development. Vibe coding. No-code programming. Software built by non-developers to solve operational problems. And it’s accelerating fast. According to Nxt Gen IT’s team, most SMBs already have:

  • At least one AI-built spreadsheet replacement
  • A small internal tool automating admin or reporting
  • A workflow connected to live customer or financial data

Usually built with good intentions. Rarely documented. Almost never governed.


Why “just banning it” doesn’t work

Some organisations try to shut this down by saying “no AI tools” or “no software without IT approval”. Others take the approach of governing spend on IT tools, which assumes an employee won’t pay for these tools themselves.Multiple surveys in 2025 showed that around half of UK employees are using personal AI tools (free or paid) to help with thier job.

You can see how this “shut down” approach fails for three reasons:

  1. The tools are accessible
    Many are free, browser-based, and don’t require installs.
  2. The problems are real
    People are automating work because existing systems don’t quite fit.
  3. Innovation goes underground
    Bans reduce visibility, they don’t reduce usage.

The smarter approach is to accept the reality and put guardrails, not gates, around it.


The simple governance question every SMB should ask

I often encourage leadership teams to start with one plain-English question:

“If someone builds a tool that the business relies on, who is responsible for it?”

If the answer isn’t clear, governance doesn’t exist even if IT policies do. Good governance isn’t about technical detail. It’s about clarity.


A practical, SMB-friendly governance framework

Here’s a lightweight framework I’ve seen work well without slowing teams down.

1. Visibility: make creation visible, not scary

You don’t need approval for every experiment. You do need awareness when tools move from “personal” to “business-critical”. A simple rule:

  • If a tool affects customers, money, or core operations, it gets logged.

No forms. No committees. Just visibility.


2. Ownership: name a business owner, not just a builder

Every internal tool should have:

  • A business owner (accountable for outcomes)
  • A technical contact (who built or maintains it)

They might be the same person but the roles must exist.

This avoids the classic problem:

“No one knows how it works, but everyone depends on it.”


3. Data boundaries: be explicit about what’s allowed

Most risk comes from unclear data use. Set simple boundaries, such as:

  • What data types can be used in AI tools
  • What must stay inside approved systems
  • What requires IT review

This doesn’t need to be complex. Just written down and shared. For UK SMEs, aligning this with guidance from the National Cyber Security Centre (NCSC) is a sensible baseline external reference.


4. Continuity: plan for the “what if”

Ask one uncomfortable but necessary question:

“If this person left tomorrow, what breaks?”

For any tool the business relies on, ensure:

  • Access isn’t tied to a personal email
  • Credentials can be transferred
  • Someone else knows where it lives

That alone removes a huge amount of hidden risk.


Where Google AI Studio fits into this shift

Platforms like Replit, Lovable, and Google AI Studio make it possible to build bespoke tools without traditional development costs.

We’ve looked in detail at why Google AI Studio, in particular, is being given away and what that tells us about where this market is heading.

The key point for leaders isn’t which platform wins.

It’s recognising that software creation has moved closer to the problem, not further away.


What “good” looks like in practice

In well-governed SMBs I work with, I usually see:

  • Encouraged experimentation
  • Clear lines of responsibility
  • Fewer surprises for leadership
  • Better conversations between IT and the business

Most importantly, people feel trusted and the business stays protected.That’s what proactive IT support should enable.


Nxt Steps

When anyone can build software, the question isn’t whether it will happen.
It’s whether the business is ready for it.

If you’re unsure what tools already exist inside your organisation, that’s the natural first step.

Explore how Nxt Gen IT helps SMB leaders put simple, people-first governance around modern technology without slowing growth or initiative.

Book a call with us to learn more about building IT peace of mind as software creation becomes everyone’s job.