Lovable co-founder and chief executive Anton Osika used a TIME100 session at Salesforce's Dreamforce conference in San Francisco to push back on critics who call AI-built software a security risk. His answer to them was blunt: "We're way past vibes." The Stockholm company has reached $200m in annual recurring revenue in less than a year and tripled that figure in nine months, according to the numbers presented on stage. For businesses, the significance is not the growth rate itself but who is doing the building: employees at nearly two-thirds of the Fortune 500 now create software on the platform.
What happened at Dreamforce
Osika spoke with TIME's Ayesha Javed in a session titled "The future of work is software without a middleman". Javed opened with Lovable's commercial record: the company bought the lovable. com domain in August, its customers include Adidas and Nvidia, and it raised a $400m Series C at a $13.3bn valuation, also in August. Those figures match earlier reporting — TechCrunch covered the $200m milestone in November 2025, and Bloomberg reported $400m in March 2026. The panel then moved from funding to the question that matters for buyers: whether software assembled outside engineering departments can be trusted with real business processes.
Lovable's core bet is that the person who has the problem should build the solution. Osika framed this as a shift away from credentials: people with expertise close to the problem, in marketing, finance or HR, should be the ones building software, not people holding certain types of certifications. He cited internal data showing that 55% of Lovable's customers and users have more than 11 years of work experience — knowledge that, in his description, used to sit behind engineering departments and never reached the tooling layer. The platform's role is to move that expertise directly into working applications.
The examples Osika gave were operational rather than experimental. Nad, a leader at the healthcare staffing company Nursa, set out to build a prototype for a product line that trains nurses and ended up building the whole product on Lovable, including scheduling and certification. Nursa's leadership team then built more than ten applications to replace legacy tools across finance and operations, and agents and chat tools at the company connect to those apps with one click. Separately, the 300 McDonald's restaurants in the Nordics run a Lovable-built system for handling incidents and requests on the floor. In both cases the software sits in production, not in a pilot folder.
What this means for business
For companies weighing where to put development capacity, the practical consequence is a changed division of labour rather than the removal of engineers. Osika said the best engineers he knows are more productive and more valuable to their businesses than before, while people without an engineering background can be highly productive if they are close to the problem and have good judgment. A small company gets the most from this by letting a domain expert ship a narrow tool quickly; a large organisation faces a different task — deciding which of many internal apps to keep, who owns each one, and how they connect to corporate data. Osika recommended internal hackathons, starting with something not too ambitious, and then making explicit decisions about which tools to retire.
The limitations are where enterprise buyers should focus. Osika said AI is now better than humans at finding vulnerabilities, and Lovable scans every change automatically and free of charge, with external penetration testing companies ranking it at the top in his account. The harder problem, he said, is data visibility inside an app: an HR tool should show staff data only to the right managers. Lovable's connectors, including one for Salesforce, restrict what data an app can reach depending on who is logged in, and administrators can see every app built in the company and which ones hold sensitive data. The company has also taken out an insurance policy from Lloyd's to cover AI risk. None of this means AI-built software is automatically safe — it means buyers should ask who the tool was built for, how apps connect to data, what administrators can see, and whether code is checked before it goes live.
The marker to watch is whether security teams move from blocking these platforms to adopting them. Osika said that shift is already visible, describing Lovable's position as going from "this last no" to "the first yes", and pointed to Salesforce's AIforce launch as the same direction of travel. If that reclassification continues through 2026, the constraint on citizen development stops being permission and becomes governance — who owns each application once it is in production.
