v0 Democratizes App Building
How v0 evolved into everyone’s secret superpower
Jun 2, 2026 · 45 min · 11 segments
In this episode: React has become the default framework for AI-generated code AI is closing the gap between product ideation and engineering execution The ability to securely run and isolate AI…
Tom OcchinoGuest
Dev TagareHostSo I have to ask, right, as a, you know, we are a security company, I have to say that your AI SDK makes it just ridiculously easy, uh, for agents to call tools.
And so, you know, putting on kind of my security hat, and for the CISOs listening to this, right, how do you make sure that, you know, these agents don't get exploited, right? Or what guardrails are y'all thinking about kind of putting in place or out of the box?

Yeah, I mean, like, you know, under no circumstances are we, like, encouraging, uh, code execution on the client.

You're doing some of this stuff, but, you know, the, the reason we created Vercel Sandbox is because we need that untrusted, uh, code execution environment that does not have access to production secrets, that does not have access to production configuration, et cetera.

Um, but there's a, there's a really rich question of the security of agents here, and, and we're doing a bunch of things.

Um, you know, one thing recently, hardening of markdown rendering to prevent, uh, data exfiltration.

We had a, a, an actually, a blog post about this called Building Secure AI Agents, which I encourage you to take a look at.

And then the other thing is, like, you know, we created the sandbox environment, which is great 'cause you can run untru- untrusted code without worrying about it accessing production secrets, et cetera.

But there's outgoing requests that come from that sandbox, and so we need to have this, um, you know, we need to be thinking about the way that agents do things from the sandbox.

So open area of, like, research and development for us, but obviously something that, that I think all of us need to take very, very seriously because especially as you open up access to these tools to so many more people who don't have the security fundamentals from their prior career, from the first, you know, 15, 20 years of their career, um, we need to be creating systems that are sort of like secure by default and safe by default.
Well, it's al- it's almost like you read my mind, because one thing, you know, I've been also promoting internally is you gotta make the paved path the easy path, right? Because if security gets really hard, then that's where it risks becoming an afterthought.

Um, just thinking through it, is the goal for the SDK to become the OS for the, for the agentic world?

So we started building v0, and it's a front-end cloud app, but we, we needed more stuff.

What else do we need?" We needed the AI SDK because we were constantly swapping out the models in our app because new ones are released all the time, and we needed to stop changing our product code.

We needed the AI gateway because as more and more teams are using AI, they're all managing their own keys.

We needed things like sandboxes, like we ment- I mentioned earlier, for untrusted code execution.

We needed a primitive called Workflows because agents do this very, uh, you know, workflow-like, this very, uh, asynchronous kind of wait for something and do something.
So I have to ask, right, as a, you know, we are a security company, I have to say that your AI SDK makes it just ridiculously easy, uh, for agents to call tools.
And so, you know, putting on kind of my security hat, and for the CISOs listening to this, right, how do you make sure that, you know, these agents don't get exploited, right? Or what guardrails are y'all thinking about kind of putting in place or out of the box?

Yeah, I mean, like, you know, under no circumstances are we, like, encouraging, uh, code execution on the client.

You're doing some of this stuff, but, you know, the, the reason we created Vercel Sandbox is because we need that untrusted, uh, code execution environment that does not have access to production secrets, that does not have access to production configuration, et cetera.

Um, but there's a, there's a really rich question of the security of agents here, and, and we're doing a bunch of things.

Um, you know, one thing recently, hardening of markdown rendering to prevent, uh, data exfiltration.

We had a, a, an actually, a blog post about this called Building Secure AI Agents, which I encourage you to take a look at.

And then the other thing is, like, you know, we created the sandbox environment, which is great 'cause you can run untru- untrusted code without worrying about it accessing production secrets, et cetera.

But there's outgoing requests that come from that sandbox, and so we need to have this, um, you know, we need to be thinking about the way that agents do things from the sandbox.

So open area of, like, research and development for us, but obviously something that, that I think all of us need to take very, very seriously because especially as you open up access to these tools to so many more people who don't have the security fundamentals from their prior career, from the first, you know, 15, 20 years of their career, um, we need to be creating systems that are sort of like secure by default and safe by default.
Well, it's al- it's almost like you read my mind, because one thing, you know, I've been also promoting internally is you gotta make the paved path the easy path, right? Because if security gets really hard, then that's where it risks becoming an afterthought.

Um, just thinking through it, is the goal for the SDK to become the OS for the, for the agentic world?

So we started building v0, and it's a front-end cloud app, but we, we needed more stuff.

What else do we need?" We needed the AI SDK because we were constantly swapping out the models in our app because new ones are released all the time, and we needed to stop changing our product code.

We needed the AI gateway because as more and more teams are using AI, they're all managing their own keys.

We needed things like sandboxes, like we ment- I mentioned earlier, for untrusted code execution.

We needed a primitive called Workflows because agents do this very, uh, you know, workflow-like, this very, uh, asynchronous kind of wait for something and do something.
Every episode on Radar is fully transcribed, speaker-labeled, and rich with metadata. Here is a taste of this one. Try Radar for free to see the rest.
3 of 6
v0 Democratizes App Building
How v0 evolved into everyone’s secret superpower
AI Shift, Not Incremental
Tom reveals AI's radical departure from past
Replacing Work We Hate
Software deletes toil, keeps only joyful creation
+3 more clips · 6 min 15 sec of audio in all
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
All 6 clips — the highlight moments, each cut as its own audio, with a title and a speaker
All 11 segments — the transcript broken into labeled sections, every ad read marked
All 20 topics — jump to every other episode discussing the same subject
Every related episode — other shows Radar links to this one
No account is needed to search Radar.