Zum Inhalt springen

By

Software development · Perspective

Replacing Excel:the Cambrian explosion of software

September 20269 min read

Tuesday, 5:40 pm. Accounts.

The costing file opens. Its name is some mix of final, v7 and NEW in capital letters. Cell F214 holds a number that cannot be right. Nobody in the building knows anymore why it is there. The person who wrote the formula left three years ago.

Shared drive › Accounts › Costing

Which one is the right one? Tap a file.

84%

of operational company spreadsheets had errors when auditors went through them cell by cell. Nine audit studies, 163 real spreadsheets. Only one study found less than 86 percent.

Source: Raymond Panko, University of Hawaii, via FinTask, 2026

Errors in the spreadsheet are the normal case, not sloppiness. Small and mid-sized businesses have been building software for forty years, they just never called it that. The Excel spreadsheet was the first piece of software anyone could build without asking anyone.

Replacing Excel used to be a project with an agency, a specification document and half a year of waiting. Today the first working draft exists after a weekend. Search for it and you mostly find offers to build it for you. This piece is about two questions those pages leave out: what changes when every business can build its own software at the same time? And when does your app carry a different kind of responsibility than the spreadsheet on your laptop?

I call this

the Cambrian explosion of software

Around 540 million years ago, almost all of today’s animal phyla appeared in a short window. Not because one animal suddenly pulled ahead. The conditions tipped for everyone at once. Same thing with software right now: the price of the first draft has dropped for everyone at the same time.

Excel taught small businesses that they can build. The next stage teaches them that they can also take responsibility.

Illustration: replacing Excel with your own software. A person with round glasses and a watering can kneels next to a stack of spreadsheet sheets from which small app windows grow like plants. The top window has a house number and a door left ajar

01

Why did so many small businesses run on Excel for decades?

Because the spreadsheet was the first software you could build yourself without asking. No request, no budget, no development team: open it, write a formula, done.

A typical pattern in small businesses looks like this. The price list lives in Excel. Holiday planning lives in Excel. Frank (fictitious name) built the quoting tool with the macros, years ago, on a long Friday. And then there is that one file nobody is allowed to touch, because nobody knows anymore what happens if you do.

Spreadsheets are probably the most widely used programming language in the world, with hundreds of millions of users, and various studies find errors in around 95 percent of them (Source: arXiv, 2026). Formulas are code. Macros are code. Just without tests, without version control and without a second person looking at them.

When does Excel turn into a database?

The moment it tips: Excel is used as a database. The file stops calculating and starts managing. Customers, orders, stock. From then on, people depend on a spreadsheet they never built.

A case from autumn 2020 shows how little this has to do with care. Public Health England merged test results in an old Excel file format that holds only about 65,000 rows. Nearly 16,000 Covid cases went unreported for days (Source: BBC, 2020). Not incompetence: a well-run organisation, a routine file format and a limit that kicks in without warning (Source: FinTask, 2026). The sheet was full, and nothing told anyone.

Excel was never the problem. Nobody said: what you are doing is building software.

84 in 100 company spreadsheets had errors
with errors: 84no errors found: 16

163 operational spreadsheets from nine audit studies with published method. Only one study found less than 86%.

Raymond Panko, University of Hawaii, via FinTask 2026

02

What is the Cambrian explosion of software?

The moment the first working draft of an application costs almost nothing, so every business gets software of its own. Not a few more apps, but a whole new diversity of species.

Gartner expects that in 2026 at least 80 percent of the people building applications with low-code tools sit outside the IT department. In 2021 it was 60 percent (Source: Gartner via Ninox, 2026).

What is citizen development?

The corporate term for this: citizen development. It means people who are not developers building their own applications. The bookkeeper, the workshop manager, you. There are said to be around 16.2 million such citizen developers worldwide in 2026, 38 percent more than the year before, and over 25 million by 2028.

58 percent build forms and data capture, 49 percent workflows. 42 percent replace spreadsheets and paper (Source: Forrester/Gartner via ToolJet, 2026). So close to half of them build to get rid of a spreadsheet or a paper process.

In 1985 everyone calculates for themselves, in 2026 everyone builds for themselves. The shape is the same, the responsibility is not.

The vendors themselves report how much is being created, and vendor figures deserve caution. A single app-building platform reports over 25 million projects created (Source: vendor figure via Jet Admin, 2026). Another reports over a million apps built by its AI agent alone (Source: vendor figure via Panto, 2026). In Germany, according to Bitkom, 41 percent of companies with 20 or more employees now use AI, up from 17 a year earlier (Source: Bitkom, 2026).

This kind of building by description, where you tell an AI what the app should do, has come to be called vibe coding. Same movement as back then with Excel, one floor higher. Back then everyone calculated for themselves. Now everyone builds for themselves. The complexity just moves up a floor.

That building an app of your own suddenly sits in a different price bracket is something I worked through in “Custom software has become affordable”. This piece is about what happens when that price drop applies to every business at the same time.

Building happens outside IT, often against the spreadsheet
2021202660 %80 %
forms and data capture58 %
workflows49 %
replacing spreadsheets and paper42 %

Top: share of low-code users outside IT, 2026 as a forecast. Bottom: what citizen developers build, multiple answers.

Gartner via Ninox 2026 · Forrester/Gartner via ToolJet 2026

03

What happens to the economy when every business builds its own software?

The stock market marks down off-the-shelf software, software revenue grows anyway, and value moves from the vendors to the businesses and their data.

In the first week of February 2026, over a trillion dollars of market value was wiped off software stocks in seven days (Source: Forrester, 2026). The trigger was the pace of AI agents and the bet that businesses will build their tools themselves, or have them built, instead of paying licences per seat. That is an expectation on the stock market, not a measured replacement. At the same time, software revenue in Germany is growing by 10.2 percent to 58.3 billion euros in 2026 (Source: Bitkom, 2026).

The market is marking down off-the-shelf tools. There is more software overall. The value moves away from the vendor and towards what the business itself knows: its processes, its data, its special cases.

Standard tools were compromises. The special price for regulars lived in a comment field because the software had no field for it. When the tool fits your shop, your knowledge of the shop becomes the most valuable thing you have.

The flip side is called shadow software

The spreadsheet nobody knew about was shadow IT. So is the app a colleague knocked together over the weekend. According to Bitkom, just under a quarter of companies, 23 percent, have rules for using AI, and four in ten assume private AI tools are in use anyway (Source: Bitkom, 2025). In an EY survey from March 2026, 45 percent of technology executives reported a confirmed or suspected data leak through unapproved AI tools (Source: EY via Adaptive Security, 2026).

A ban tends to push these apps deeper into the shadows. The question Excel never had to ask: who can actually get to the data?

Both are true at once

Left is a stock-market expectation, not a measured replacement. Right is market revenue. Value moves, it does not vanish.

Forrester 2026 · Bitkom 2026

04

Why is a web application different from an Excel spreadsheet?

Because it has an address. A mistake in Excel stays in the building; an application on the internet can be reached from anywhere, around the clock, and often stores other people's data.

Move through the stages yourself, from the spreadsheet on your laptop to an application with a public address.

The same customer list, four stages

How far does your tool reach?

Who can get in
You.
What breaks
A number.
Whose data
Yours.
What applies
Nothing new.

A mistake stays in the building.

On the first three stages, the circle of people who can get in grows. You, your team, everyone with an account. On the fourth, anyone with a browser can get in, at night too, from countries you have never been to. What breaks then is all the data at once, and it no longer belongs only to you. Between stage three and four sits the front door.

How often are self-built apps left open?

In August 2026, Reeve scanned almost 31,000 live apps made with AI app builders. Of the 3,680 apps whose database could be tested from outside, 2,096, or 57 percent, let a stranger read at least one table without a password. A single request, no login. 394 of them had readable tables with names like users, profiles or orders (Source: Reeve, 2026).

Reeve also says that 76 percent of the apps still get the top grade, because they pass the ordinary checks. The serious flaws sit one layer deeper, in the database. Only three apps had the database master key in their code.

Often it is less the mistake of a single app than a pattern of the tool. On one large building platform, a study from May 2025 found that 170 of 1,645 sampled apps let strangers access personal data, and around 70 percent had row-level access control switched off entirely (Source: The Next Web, 2026). If you do not explicitly ask for it, you do not get it. If you are building for the first time, you do not know you have to ask. Same story as the row limit. Only now the file has an address.

What applies once other people’s data is inside?

The broad lines, without legal advice: the GDPR applies as soon as other people’s data sits in your application, no matter who built it. Access control is then not optional; Article 32 requires appropriate technical and organisational measures.

Then there is the Cyber Resilience Act. Since 11 September 2026, reporting obligations apply to actively exploited vulnerabilities and severe security incidents. The remaining duties follow from 11 December 2027 (Source: European Commission, 2026). That covers software you make available on the EU market under your name, including for free. An internally developed tool that stays in-house is, according to the Commission, generally out of scope (Source: European Commission, 2026). Once you hand it to customers, even a single one, that can change. There is no size threshold that takes small businesses out of the law. Micro and small enterprises are not fined for missing the 24-hour early warning, but the duty to report remains (Source: European Commission, 2026). The Commission published guidance with 67 examples in July 2026 (Source: European Commission, 2026). The rough line: internally a tool, externally a product. What decides it is whether you place it on the market.

57% of testable apps let strangers read tables
  • 394 with readable tables of personal data
  • 2,096 with at least one open table
  • 3,680 testable in total

1 square ≈ 40 apps. One request, no password. Scan of almost 31,000 live apps from AI builders, August 2026.

Reeve, The State of Vibe-Coded App Security 2026

05

How do you replace Excel without overstretching yourself?

In three stages: first internal and with your own data, then set the data boundary deliberately, and before the first stranger arrives, ask the questions a product has to answer.

Stage 1: internal first, your own data first

Your first app of your own replaces a spreadsheet that only your team uses and that holds no customer data. If you are not sure which one: take the file that no longer calculates but manages. Holiday rota, price list, order overview. It runs behind a login, with access only for accounts you know. Here the blast radius of a mistake stays almost as small as with the spreadsheet, and you learn to build without carrying responsibility for other people’s data.

Three things get better than in Excel right away. Every change is traceable, because the application is versioned. There is one truth instead of seven files. And there is a backup you have actually restored at least once.

Stage 2: set the data boundary deliberately

Before every new feature there is one question: whose data is this? Yours, your staff’s or your customers’? As soon as customer data comes in, you need three things. Row-level access control, meaning a rule for who may see which row. No secret keys in the code that ends up in the browser. And a deletion policy. The first two are exactly what was missing in the scans.

According to the Stack Overflow Developer Survey 2025, 84 percent of developers use AI tools, but only 33 percent trust the output, and 46 percent actively distrust it (Source: Stack Overflow via Coderfile, 2026). In August 2026, Symbiotic Security measured that AI-assisted repositories carry 42.3 vulnerabilities on average, human-written ones 9.6. That is more than four times as many (Source: Symbiotic Security via VibeEval, 2026).

The pros do not have less trust than you. They have a checklist.

Stage 3: before the first stranger

Before your app gets a public address, the question changes from “does it run?” to “does it hold?”. Who gets the call when it goes down at night? What happens when someone sends 10,000 requests a minute? Where is it written down which data you store and why? The nine questions your tool should answer before the first stranger uses it are in “Production-ready software”. You can work through them in an afternoon.

This is also the point where you decide whether you carry it alone or bring someone in. For the building, you need nobody. For the responsibility, you might.

Building it yourself is the right call. It gets risky when the app gets a public address and nobody asked whose data sits inside. Small businesses have an edge here: nobody says no. The order is the no you give yourself.

Even the pros double-check

AI tools

use them84 %
trust the output33 %

Vulnerabilities per repository

human-written only9.6
AI-assisted42.3

Top: developer survey 2025. Bottom: average vulnerabilities per repository, 1,967 repositories.

Stack Overflow Developer Survey 2025 · Symbiotic Security, August 2026

06

What changes when a spreadsheet becomes software?

The shape is the same as with Excel: first everyone calculates for themselves, then everyone builds for themselves. What is new is the address, and with it the responsibility.

Excel taught small businesses that they can build. The next stage teaches them that they can also take responsibility.

The spreadsheet died on your computer, if it died at all. The app dies in public.

The building part, you can do. When your tool is about to become a product, I will walk that step with you.

The file with final, v7 and NEW in its name is not a spreadsheet. It is your first piece of software. You get to build the second one better.


All names of individuals and companies used in this article are fictitious. Any resemblance to real persons or businesses is purely coincidental and unintentional. The examples are provided solely for illustrative purposes.

Same shape, a new threshold

The spreadsheet era

  1. spreadsheet
  2. macro
  3. shared file
  4. the untouchable file

The software era

  1. prompt
  2. app
  3. internal web app
  4. public address

Top right, a file dies on your computer. Bottom right, an app dies in public.

Qualitative comparison, not a measurement. The marker shows where a tool turns into responsibility.

Related to This Topic

Get the free Getting Started Guide: 10 concrete ways to start using AI productively tomorrow.

Did this article spark an idea? Let's find out which Sinnvampire can disappear for you.

New articles straight to your inbox

No spam, no sales funnels. Just one email when there's a new article on AI for small and mid-sized businesses. You confirm with a single click and can unsubscribe any time.