Zoho’s Hyther Nizam on why AI won’t replace the human in the loop
The CEO of Zoho MEA on vibe coding, the limits of AI-generated software, and the case for governed low-code in the enterprise
04 June, 2026
TT
16
The rise of “vibe coding”, AI tools that can spin up working applications from a plain-language description, has reopened a familiar debate about who gets to build software, and how much of it can be automated. For Hyther Nizam, CEO of Zoho MEA, the shift is real but often misread. He sees AI generation as a genuine breakthrough in getting from an idea to a working prototype in minutes, putting that power in the hands of finance analysts and operations managers rather than developers alone. The harder problem, he argues, is everything that comes after the first build: maintaining interdependent workflows, approval chains, user roles, and compliance requirements as business rules change and applications scale.
In this conversation, Nizam draws the line between fast AI-assisted generation and structured low-code platforms like Zoho Creator, explains why security, auditability, and data residency have become procurement requirements rather than nice-to-haves, particularly for regulated industries in the UAE, and makes the case that traditional coding, low-code, and vibe coding are heading toward a division of labour rather than a winner-takes-all outcome. The thread running through it all: keep a human in the loop.
There’s growing talk about “vibe coding” and AI tools that can generate applications with minimal human input. Do you see this as a real shift in software development, or more of an early-stage experiment?
Vibe coding is the most significant change in who can build software in the last decade. The ability for an operations manager or a finance analyst to describe a process and have a working interface generated in minutes is not a prototype feature; it is a structural shift in how organisations will approach internal tooling.
What it doesn’t solve is what happens after the first build, particularly for serious applications that organisations actually run on. Enterprise software is a system of interdependent workflows, approval chains, user roles, and compliance requirements. Maintaining that over time, as business rules change and the application scales, is where vibe-coded outputs start to show their limits. For instance, the trail of changes made, components altered, code written and rewritten, and technology used are all outside the absolute control of a developer, resulting in a steep governance risk.
Where do you draw the line between AI-assisted development and structured low-code platforms like Zoho’s? What does each do better in practice?
AI-assisted development is good at application generation. Users can describe intent and get a prototype fast. Low-code platforms, on the other hand, combine ease of development with the layer underneath — the underlying data model, workflow logic, user permissions, security, compliance, integrations, and more — that is most critical for enterprise adoption. Low-code also lends itself to code optimisation in a way that free-form AI generation doesn’t, because the underlying structure is defined and inspectable rather than generated from scratch each time.
The distinction shows up most clearly over time. AI tools help you go from zero to something working quickly. Low-code platforms help ensure that something survives contact with a real organisation, bringing version control, role-based access, audit trails, and the ability for an operations lead to modify their own workflow without raising a development ticket. The two are increasingly complementary rather than competing.
One argument is that AI could eventually replace traditional and even low-code development entirely. What is your view on that trajectory over the next five to ten years?
Writing code was a real bottleneck, and AI has genuinely reduced it. What it hasn’t resolved is the broader challenge: whether an AI-generated application can be maintained reliably, scaled as the organisation grows, and kept relevant as business requirements evolve. Those are open questions, and until they’re answered confidently, human control remains essential in the development process.
At the pace at which things are evolving, predicting the situation over the next five to ten years is a dart thrown in the dark. That said, we expect AI to become a standard capability inside all modes of development tools, including low-code platforms. What it will not replace is domain expertise. The person who best understands how a procurement approval process should work is not a developer but the procurement manager. LLM-powered tools can act as an efficient support system, but the direction and action should be owned by the human in the loop.
Zoho has long invested in low-code as part of its broader software ecosystem. How is AI changing what low-code means inside your own product roadmap?
We’re introducing a new unified development environment that embeds AI across the entire software development lifecycle, from requirements and build through to testing and in-app agent creation. The intent is not to replace the structured low-code environment but to make it significantly faster to work within it, while preserving the human-in-the-loop approach that ensures the integrity of what gets built. AI handles the generation and suggestion; the developer retains control over what gets committed.
The foundation remains the same: Zoho’s low-code platform sits as the process layer across the broader Zoho ecosystem, connecting your applications to the same live data environment as your CRM, finance tools, and HR systems. AI capabilities are being layered on top of that structure, not in place of it.
From an enterprise perspective, how do concerns around security, governance, and scalability shape the case for low-code versus fully AI-generated applications?
For enterprise buyers, security, auditability, and scalability aren’t differentiators. They’re table stakes. A useful rule of thumb is this: if security, compliance, and clear accountability need to be in place, a governed platform is the right foundation. With fully AI-generated applications, that burden falls back on the organisation — covering security review, role testing, and ongoing maintenance as business rules change — each requiring developer time that many enterprises are already short of.
A structured low-code platform shifts that burden into the platform itself. Version control, role-based access, audit trails, and data residency controls are available by default in Zoho Creator, not things a user needs to configure from scratch. The more relevant scalability question today is whether your ops team, finance team, and regional offices can all build and adapt their own workflows without creating a bottleneck at the centre. That is where a purpose-built platform has a structural advantage that AI generation alone doesn’t address.
Are you seeing enterprises in the UAE and wider region actually move from traditional development to low-code, or is adoption still limited to specific use cases?
Adoption in the region has moved well beyond specific use cases. What’s changed is the ambition of the implementations. We’re now seeing enterprises use Zoho’s low-code platform as the backbone of their operational infrastructure, covering field inspection management, multi-entity compliance tracking, partner portal development, and custom reporting platforms that pull live data from across their Zoho environment.
The UAE specifically has seen accelerated adoption driven by data sovereignty requirements and smart government initiatives. Zoho operates its own data centres in Abu Dhabi and Dubai, which means enterprises build and run applications with their data remaining in-country. For regulated industries in financial services, healthcare, and government, that is not a nice-to-have; it is a procurement requirement. Enterprises already on Zoho CRM, Books, or Desk find that Creator applications running within that same sovereign infrastructure eliminate significant integration overhead and dramatically shorten the path to production.
Where does low-code still struggle today, especially when compared to newer AI-native development tools?
Low-code has a learning curve, and in terms of raw speed of the initial build, AI generation is faster for simple use cases. That is a fair observation. But the comparison changes significantly once you factor in maintainability, because the structured environment makes ongoing changes inspectable and predictable in a way that AI-generated output typically isn’t.
Most low-code platforms follow a human-in-the-loop approach by design, and that exists to protect the integrity of the application being built, not to slow it down. For applications that an organisation genuinely runs on — connected to live financial or operational data and expected to evolve — that integrity is non-negotiable. The first build is rarely the expensive part; keeping it working and adapting it over two or three years is where the real cost sits.
If we look ahead, what does the “ideal” development stack look like in a world where AI, low-code, and traditional coding all coexist?
There is definitely a space for all three, and the organisations ahead in the AI adoption curve are already treating it as a division of labour rather than a competition. The use case and developer persona will determine the choice of approach, and in most scenarios, a combination of all three will be preferred over any single mode, with AI embedded natively across each.
For now, AI-native vibe-coding platforms will serve non-technical business users who need rapid prototyping and deployment for simple internal workflows, lightweight automations, and proofs of concept. Traditional and low-code platforms will remain the choice of professional and techno-functional developers building org-wide solutions where compliance, security, scalability, and maintainability are non-negotiable. What low-code adds is ownership at the process layer, where business workflows can be built, maintained, and adapted directly by the people closest to the work, without routing every change through an engineering team. This helps organisations strike a balance between faster development and enterprise governance requirements.
The practical risk is simpler than it sounds. When business teams can’t get what they need, they build outside official channels. When enterprises over-rely on AI generation without a governed layer, they build fast and maintain slowly. When one tool gets mandated for everything, it fits nothing well. The right stack isn’t a single answer; it’s the discipline to match the right tool to the right problem — and the teams that get this right are the ones that build durable operational capability rather than cycling through rebuilds every 18 months.
Read: Building trust in AI: The UAE’s journey to a digital cognitive future























