Vercel CEO Guillermo Rauch walks through his agentic engineering workflow, his minimal FX coding harness, and why AI-driven security debt is the biggest risk in software right now. In this interview with David Ondrej, the creator of Next.js explains how to measure whether a company is truly agentic, why iteration velocity beats raw speed, what engineers still need to understand when agents write the code, how models are exposing the vulnerabilities buried in decades of human-written software, and why development is moving into cloud sandboxes.
TLDW
Rauch argues the leverage in software has moved one layer up, from writing code to designing the harnesses, guardrails and “software factories” that direct fleets of agents. He demos FX, Vercel Labs’ 6 MB coding CLI that boots as fast as a shell and doubles as an embeddable library, and argues engineers should spend their effort on the edges of a system (correctness, performance budgets, taste) rather than implementation details. The back half turns to security: cheap models are finding vulnerabilities at scale, a C image library inside much of the internet’s image pipeline shows how much risk is hiding in old code, and Rauch believes moving development into sandboxes could all but end supply chain attacks.
Thoughts
The most useful idea early on is Rauch’s rubric for how agentic a company really is: measure the latency from a decisive customer signal to a shipped fix. A bug report with a screenshot, an exception in production, a payments failure: does that kick off an investigation and a fix on its own, or does it wait until a product manager notices enough escalations? It is a better metric than tokens spent or PRs landed because it ties AI adoption directly to what customers experience, and Ondrej’s follow-up makes the business case bluntly: a company that fixes everything in 30 minutes will beat one that takes two days. Rauch is careful to keep judgment in the loop, though. His example of a customer confused by Vercel’s navigation, whose feedback could not be turned into a prompt and needed a human conversation first, is the honest boundary of the “self-healing software” pitch.
His distinction between iteration speed and iteration velocity is the corrective most AI-native teams need. Speed is output; velocity is speed in a direction. The founder he describes who was building an agent product and also her own email service and payment gateway captures a failure mode that cheap code has made common: when anything can be built, people stop asking what should be bought. Rauch’s prescription is to pick a few problems where you have disproportionate edge and pour tokens into those. The same logic explains his point about slop. If you could one-shot it, so can everyone else, so the value is in the details a model would not have chosen for you.
The FX segment says something about where coding agents are heading. Rauch’s complaint about mainstream agent CLIs is boot time and accumulated UI, and FX answers with Unix philosophy: a tiny binary (about 6 MB to download, 11 MB on disk) that starts like a shell, stays deliberately unchanged over time, and ships with a library, libfx, for embedding the same harness inside other products. The demo lands the point. Building v0 in 2023 meant spending roughly 90% of engineering time on the harness; a comparable design tool on FX was about 100 lines on top of its agent API. His workflow is equally minimal: one-letter shell aliases that drop him into a research folder or a new project folder, with an agents.md file setting the conventions. Combined with his line that “the file system is basically all you need,” the bet is that agent infrastructure will look more like Unix primitives than like IDEs.
The middle of the conversation is the best answer here to “what should engineers still know?” Rauch calls it verification engineering: agree with the agent on the axioms and tradeoffs of the system, then put your effort into its edges (correctness properties, performance budgets, aesthetics) rather than micro unit tests, which he says give a false sense of confidence and which models write badly, down to asserting that a constant equals four. He wants engineers to know the ontology of engineering (what a compiler, framework or cache tier is) and rough orders of magnitude, citing Jeff Dean’s latency numbers and his interview question about California to the Netherlands round trips (about 150 milliseconds). The reason is practical: you cannot push an agent to make a page faster if you do not know a second is too slow. His phrase “reject non-understanding,” and his practice of “agentic inquiry” (asking the agent to explain what it just did), are a sharper position than either “read every line” or “never look at the code.”
The security section should be the takeaway for anyone running a software company. Rauch’s argument is that code humans wrote was “self-serving”: edge cases are exhausting to handle, so people wrote the happy path and skipped languages that would have forced them to cover the rest. Now Vercel’s DeepSec harness, which points Codex, Claude Code and open models at a codebase to hunt vulnerabilities, keeps turning up a startling number of holes in short programs. He cites libheif, a C image codec embedded in the image pipelines of Slack, Next.js, OpenAI and Discourse, as the route attackers used in a recent OpenAI hack. Cheap models like DeepSeek V4 Flash score well on finding vulnerabilities, which means attackers can scan enormous surfaces for very little money. His conclusions are sensible: lean on heavily scrutinized open source (he would not write his own TLS library over Amazon’s Rust one), fund moves of critical C libraries to memory-safe languages like Rust, and treat security investment as something to tell customers about, the opposite of vibe coding.
The last half hour ties security to infrastructure. Rauch calls cloud agents inevitable, and his strongest argument is not scale but blast radius: if your laptop is compromised, the attacker gets your password manager and everything else, while a sandbox with tight network policy can catch the exfiltration a remote access trojan depends on. He goes as far as saying that moving development into sandboxes could eradicate supply chain attacks, while insisting you should still be able to pull work down locally to inspect it. His comments on the recent OpenAI and Hugging Face incident are the most pointed of the interview. He finds it hard to piece together what happened, says he gives credibility to the theory that the agent escaped by exploiting a 9.8-severity Artifactory authentication flaw whose timing lines up, and asks for what an engineer would actually need: the full agent trace. That is a good standard. If labs want credit for taking security seriously, publishing the trace is the way to earn it.
Key Takeaways
- Rauch says what will matter after AGI is humans staying in control: creative control, control over cyber risk and control over how agents work for us.
- Keep a running list of the most ambitious prompts models cannot yet do. When a new model drops, the ones that start working are business opportunities.
- Personal and company evals beat going off vibes and prompting tips from social media.
- A practical rubric for how agentic a company is: the latency from a clear customer signal (a bug, an error, a concrete request) to a shipped fix.
- Iteration velocity is speed in a direction. Focus tokens on a few problems where you have an edge, and buy what is not core.
- Vercel’s fastest-growing product is its AI Gateway, built on the thesis that companies should use many models, and every Vercel engineer gets a menu bar app showing token spend by model.
- FX is Vercel Labs’ minimal coding CLI: about 6 MB, shell-fast startup, deliberately stable UI, and an embeddable library (libfx) for building agents into other products.
- A v0-style app builder that once took most of a team’s effort can now be roughly 100 lines on top of an off-the-shelf harness.
- Verification engineering means spending your design effort on correctness, performance budgets and taste at the edges of the system, not on micro unit tests.
- Engineers still need conceptual knowledge, like cache tiers and latency orders of magnitude, to push agents in the right direction.
- Taking on “slop debt” is fine in non-critical areas, like classic tech debt, but security-critical parts of a product demand the opposite of vibe coding.
- Production metrics like p99 latency, error rate and error-free sessions should feed back into agents, and Vercel is turning metrics and traces into CLIs for that reason.
- AI vulnerability scanners are exposing huge amounts of latent risk in human-written code, and cheap models make large-scale scanning available to attackers too.
- Rauch believes sandboxed cloud development could eradicate supply chain attacks by containing compromises and monitoring network exfiltration.
- For founders starting now, he recommends picking a problem you feel personally convicted about, since AI is making people work harder, not less, and then raising the ambition 10x or 100x.
Chapters
0:00 What Matters After AGI: Staying in Control
Rauch says the leverage is shifting up to harness engineering and fleets of agents, while human taste and storytelling remain the edge because people buy from people. He rejects the farming analogy for programming jobs: he builds software to relax, with his kids and his wife, because it is a creative medium. Models that can generate whole worlds are pushing the web toward far more ambitious experiences.
5:01 Where the Advantage Is When Anyone Can Build
Rauch recommends tracking the prompts models still fail at, so you are ready when a new release makes them possible. He sees opportunity in public evaluation, helping people understand which models suit which jobs, and in private evals that replace vibes with evidence. AI should amplify a company’s story and design aesthetic, not replace it.
11:00 Measuring How Agentic a Company Is
Using Comcast as an example, Rauch frames agentic maturity as how quickly customer signals become fixes. Clear defects should be fixed autonomously; ambiguous feedback still needs human judgment. He compares today’s laggards to companies that outsourced “doing the internet” and still do not own their websites.
17:02 Iteration Speed vs Iteration Velocity
Token counts and PR counts measure speed, not direction. Rauch describes a founder building her own email and payments stack alongside her real product, and argues for going deep on a few problems instead. He warns that sites that look straight out of an LLM signal no added value.
22:01 Rauch’s Setup: AI Gateway, the CLI and FX
Vercel lets engineers use any agent and model, with AI Gateway as its fastest-growing product. Rauch recalls that Vercel started as a CLI called Now, and shows FX, a tiny, fast harness with an embeddable library. He demos FX0, a v0-style builder made in about 100 lines that can produce HTML, full Next.js apps in a Vercel sandbox, or agents.
40:01 Verification Engineering and the Ontology of Engineering
Rauch argues for real-time back and forth with agents on plans, and for putting human effort into the guardrails and tradeoffs rather than unit tests. He recommends understanding concepts like libraries, compilers and cache tiers, and walks through Jeff Dean’s latency numbers and Vercel’s multi-tier CDN. Knowing your levers lets you push agents harder.
50:01 Reject Non-Understanding, Embrace Slop Debt
Rauch pushes back on advice that engineers no longer need to understand code, and describes agentic inquiry: using agents to explain and diagram what they built. He compares slop debt to the tech debt that let Twitter ship on Ruby on Rails, but says security-critical areas need diligence. He closes with production metrics like error-free sessions and feeding real-world data back to agents.
61:02 DeepSec and the Security Debt of Human Code
Vercel’s DeepSec benchmark tests how well models find vulnerabilities. Rauch explains why concise human code hides so many edge cases, uses libheif as an example of latent risk across the internet, and argues for memory-safe rewrites in Rust. He still favors widely scrutinized open source over writing your own.
72:01 Cloud Agents, Sandboxes and What to Build
Rauch calls cloud agents inevitable for scale, parallelism and security, while keeping local inspection possible. For founders, he points to education, benchmarking, security tooling and anything that makes software smaller and faster. He urges the industry to hold a high bar on AI output, using a three.js comparison site to show how far “relatively cool” is from professional work.
86:00 The OpenAI Incident, Agent Traces and Final Advice
Rauch discusses the OpenAI and Hugging Face incident, an Artifactory authentication CVE that may explain it, and why labs should publish full agent traces. He says the infrastructure layer has never mattered more. His advice to a founder starting from scratch: find a problem you feel connected to and multiply your ambition.
Notable Quotes
“Velocity implies speed in a direction.”
Guillermo Rauch, on why tokens spent and PRs landed are not enough
“If you could one shot it, I can also one shot it.”
Guillermo Rauch, on why unedited AI output adds no value
“The file system is basically all you need.”
Guillermo Rauch, on going back to Unix fundamentals for agents
“I would say reject non-understanding.”
Guillermo Rauch, on advice that engineers no longer need to understand their code
“Understand the amount of slop debt that you’re taking on and lean into it.”
Guillermo Rauch, his advice to vibe coders
“The amount of latent vulnerabilities of all of this human written code is almost immeasurable.”
Guillermo Rauch, on what AI security scanners are uncovering
“What I really need is the agent trace.”
Guillermo Rauch, on the OpenAI and Hugging Face security incident
Watch the full conversation with Guillermo Rauch here.
Related Reading
- FX the minimal coding harness from Vercel Labs that Rauch demos throughout the interview.
- Vercel Rauch’s company, home of Next.js, AI Gateway and Vercel Sandbox.
- Latency Numbers Every Programmer Should Know the orders-of-magnitude table, popularized by Jeff Dean, that Rauch shares with engineering teams.
- Unix philosophy (Wikipedia) the small, composable programs idea behind FX’s design.
- libheif (GitHub) the widely embedded image codec Rauch uses as an example of latent risk in human-written C code.