Society & Economicspreprint2026-08-01

No Test, No Claim: Untested Code Is Vibed Code

Open access0 citations

Abstract

When a large language model writes code we do not trust, we tend to blame the author: a machine wrote it, so it must be suspect. This paper argues that the instinct points at the wrong variable. What makes code trustworthy is not who wrote it but whether reproducible evidence exists that it does what it claims. Authorship is inert; verification is everything. We defend one thesis - untested code is vibed code, whether a human or a model wrote it - and build it as a single argument rather than a tour of disciplines. We begin where the argument is strongest: a correctness claim about untested code has no content. It is an unsigned promise (Design by Contract), an unfalsifiable assertion (Popper), and, in Alf Ross's sense, a tû-tû - a bookkeeping word that connects a wish to a reliance while denoting nothing in between - because the theory that would give it content, in Naur's sense, never leaves the author's head. Authorship cannot supply that content: a private, perishable understanding is, on Nozick's truth-tracking account, a belief that would persist even if the code were broken, which is to say not knowledge at all, and the human author and the model collapse into the same case. A program's real law is its behavior in execution - the legal realists' law in action - not the paper rules of its names, types, and comments; the test is the court decision that discloses it. What running on vibes costs is then contested ground: the cost splits cleanly into a part that can be priced and a part that cannot. Chicago prices the first (the Learned Hand formula renders a cheap omitted test negligent by construction; the market for lemons explains why untested modules cannot be told from working ones); Austrian marks the limit of the second (the calculation problem; dispersed, tacit knowledge) -- and the test is what a decision-maker needs at exactly that boundary, the decentralized feedback signal that substitutes for a global correctness calculation no one can perform. We make the cost concrete with a compound-Poisson actuarial model, of which the Hand formula is the point-estimate special case, and an estimable panel specification, then bound its pretensions with the Austrian caveat that its parameters are guesses at a moving target. The practical contribution follows from that model. Because operational-risk capital under Basel II and Solvency II is itself a compound-Poisson loss distribution, a test is an operational-risk control with a measurable effect on regulatory capital; the Learned Hand formula is the deterministic point estimate of that model's pure premium; and the industry's faith in "battle-tested" code systematically under-reserves the tail in which latent security failures -- Dirty COW, the XZ backdoor -- actually live, because production tenure samples the body of the loss distribution and never its tail. Under every step the same verdict returns, and none of them can find authorship on the relevant side of the ledger.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-01

Authors: Luciano Pereira