They take pains to sandbox the AI, but the resulting code is often not sandboxed and it's running on your localhost.
It will hallucinate entire libraries and then not find them and magic one up that does what-the-fuck-evah, that you probably didn't even need. (It might have known they aren't there, and this is just its preferred method for messing up your code base.)
It creates complex solutions to simple problems, and includes all sorts of bizarre shit in there because... reasons.
And so on.
Oh, let's just track this variable for performance and then upload that dataset to the cloud to...
And if you ask it why it did that, it'll say,
I didn't do nuffin.