Techstrong TV – April 20, 2026
On today’s Techstrong TV, Hart Rossman, VP of Security at AWS, joins Mike Vizard to explain why machine speed security has made traditional DevSecOps teams obsolete — and why the future belongs to nimble “two-slice” squads that co-build with AI from the very first prompt. Alan Shimel sits down with StackHawk co-founders Joni Klippert and Scott Gerlach, live from RSAC 2026, on how AI-driven auto-remediation is fixing vulnerabilities directly in the IDE before they ever reach production. Mike Vizard also catches up with Hong Wang, co-founder of Akuity, live from KubeCon EU 2026, on how Argo CD’s GitOps momentum is being supercharged by AI deployment agents built to handle the volume of code modern teams are shipping.
Transcript
Hey everyone. Welcome back here to Techstrong TV. This next person is someone I've had the pleasure of knowing for a long time, probably 10 plus years, and maybe more now that I think about it, in the world of tech and tech marketing and tech PR and reporting and media and all that good stuff.
I don't hold it against them that they're a Cleveland Browns fan, but I do want to just mention that upfront. But let me introduce you to my friend Clinton Carr. Clinton, how are you?
I'm great. Thanks for having me on, Alan. Fantastic.
Hey, Clinton, I mentioned we go back a while. You've been a PR marketing professional for as long as I know. Give people a sense of your journey and then let's transition from that into ProGEO.
Great. I've been working in cybersecurity for 20 years, and yeah, we go back about 15 years or so. I remember I was working late one night and found your Network World column, and I forget exactly who I was pitching you at the time, but I've worked with a lot of great cybersecurity brands over the years, and we connected, like you said, in spite of the fact that I'm a Cleveland Browns fan.
And I've worked agency side, in-house side, and now I've been consulting for the past 10 years, sort of fractional corporate communications and integrated content marketing, doing a lot of executive thought leadership and ghostwriting for really some of the biggest names in cybersecurity. Don't want to say who, to dispel that illusion, but- Otherwise it wouldn't be ghosting, would it? Yeah, exactly.
Very cool. Talk to us about ProGEO. Sure.
So, and the topic of today's discussion is around how marketing professionals are using AI in their workflows, and so ProGEO is Generative Engine Optimization. And coming from my cybersecurity background, it's really focused on a data-driven approach, right? That we're not just making assertions on what we think work, but we're doing the research to figure it out.
And Generative Engine Optimization is really the evolution or extension of corporate communications, content marketing, and search engine optimization. You could think about it as the sort of earned media channels of corporate communications, the owned media channels of content marketing, and then the technical elements of SEO. And then there's some elements of Generative Engine Optimization that are being studied and have possibly some new strategies and tactics involved.
I think there'll definitely be new strategies and tactics. You know, Clinton, I was just on a rant. So I'm in studio right here in our Techstrong studio.
We have three different sets. So down that way is the Techstrong gang set, and I was just there. We just wrapped that show up at 12:45 my time.
Mm. And, we were talking about Google, right, serving up Gemini searches-- Not Gemini searches, Gemini answers. New York Times ran an article, only nine out of 10 are correct.
Right. Which sounds pretty good until you take it to the trillions of search results- Right ... that Google serves up, and you get millions of wrong searches.
But more than that, fundamentally, Google has changed, which is the golden goose of their business, by the way, right? The search- Mm-hmm ... results sponsored and all of that.
They've changed the search business from, they used to tell you where to go to find information based upon what you search to find answers, to serving up answers within their own site, not sending you out. Right? So they've gone from being a search provider to a content answer provider.
And the beauty or hypocrisy of what they're doing is they're using my information to serve up answers to you without sending you to me to get those answers. And that was always the quid pro quo here is that- That's right ... Google spidered our sites, indexed our sites, so that when people search for these things, if we did a good job on SEO, Google would send them our way.
And, for many of us in media and marketing, that was the bread and butter of our traffic, organic search traffic. Mm-hmm. And now with this AI kind of serving up answers, Google has a no-click kind of mantra where they're not sending you out.
Yeah. They're calling it the zero-click phenomenon. Zero-click.
Right. I said no-click. And there was a Bain & Company research report from last year that said 80% of consumers are resolving 40% of their queries without even clicking a link.
Yeah. And that was last year. And the whole crawl-to-referral ratio thing, there's a Cloudflare Radar, it's a dashboard, and you can check it out.
Google proper will crawl your site five times for every one referral it sends to your site. Anthropic crawls it 8,000 times for every one referral it sends to you. Wow.
But what's a poor boy to do, right? And so that's what we're kind of-- the reality of today's world with this stuff and so it's important. As a publisher, it's important to me, and I see it happening.
Anyway, enough ranting. I ranted over there about it. I'm ranting over here about it.
Let's talk about this survey you did over at RSAC. Sure. So, and again, coming from a cybersecurity background, definitely not my first RSAC, and not the first time I've conducted a survey at RSAC.
Although usually we're looking at cybersecurity opinions. And so with this shift to AI, I was really curious about how marketing professionals are using AI in their workflows. And so I surveyed 112 marketing professionals that sort of self-identified as marketing professionals.
And I would say probably over 100 of them were conducted in the expo hall at the booth. So this is a largely representative sample of RSA exhibitors, right? So it is maybe important to realize that these are going to be the sort of leading-edge companies, right?
They've invested in RSA, so it likewise makes sense that they've invested in AI platforms. But likewise, I think this is then representative of the cybersecurity industry, and cybersecurity being an enterprise technology, this is something that you could extrapolate. Some of these adoption rates and usage patterns are similar to what you would see across enterprise technology companies.
Agreed. So, key findings. Thank you for providing me with the- Sure ...
cheat sheet on this, but 91, over a little over 91% of marketing professionals have an enterprise subscription. Well, that's not the $20 a month ChatGPT or the 200 a year Claude. Yeah.
It's- Or is it? probably somewhere in the middle, right? It is the Pro account, which ChatGPT Pro or Claude Pro.
It probably depends enterprise subscriptions. There's a lot of discussion right now about if those enterprise subscriptions are getting priority in terms of the quality of the results and the tokens and so on and so forth. But yeah, it's somewhere in the middle.
I think what's interesting about that 91% is there was an MIT study that came out in August, that a lot of people were talking about. People really honed in on the fact that MIT was saying that 95% of enterprise AI adoption was failing. But also in that report was the fact that really the results of this survey were flipped.
It was 90% of users had a personal subscription to an AI platform, and only 40% of companies had an enterprise subscription, right? Got it. So again, we are looking at a kind of specialized vertical here with the cybersecurity industry.
But we're now seeing 91%, nine out of 10 organizations have an enterprise account, and almost half of them are using multiple platforms, and most commonly it's ChatGPT and Claude. And then- Yeah. No, I think then Gemini and then maybe Perplexity, and then I think Microsoft is...
And now, and rounding out the track. Yeah, exactly. 1% of marketing professionals have an enterprise subscription now, when it was 40% back in August.
And almost half of those, about 49% have multiple platforms, and Claude and ChatGPT being the two most predominant subscriptions. Where was Gemini, Perplexity, and- Yeah, Gemini was- Grok? in the race.
Perplexity was an other. Copilot was other. Some people- What about Grok?
noted Cursor and that sort of thing too. Anybody mention Grok? XAI or- There was one mention of Grok, yeah.
One. Yeah. It makes sense.
So I'm a bit of a freak. I'm sure I have every single one you mentioned. And I got to tell you, I wonder what agentics is going to-- how agentics is going to change that, right?
Because- Yeah, because that's really, I think, the next level, right? Because what we did look at was marketing professionals and how they're using AI in their sort of daily workflows. And not surprisingly, content is king, right?
We're seeing that something like 83% of marketing professionals are using Gen AI to brainstorm their content, and at least once a week. And 82% are creating content, either their first draft content or editing their content. And 75% are repurposing content.
So that's definitely the sort of most frequent use case. And I also kind of broke things down between high-intensity and low-intensity users, and kind of regardless, of course, some people are using it more frequently. ButYou can see even among the low-intensity users, there's a pretty frequent use of gen AI for content creation.
And I think where you see a sort of lower adoption is around things like automation, hooking into APIs for your HubSpot, your Marketo, your 6sense for sales enablement or your email marketing campaigns. And likewise, and this was actually surprising to me, was that a quarter of the respondents said that they're vibe coding at least once a week, which is kind of incredible. Now, we counted vibe coding as anything from creating HTML to custom scripts or custom tools.
So it could be just the sort of thing that they're creating HTML for an email campaign or that sort of thing, but it's now the sort of thing where that's not a bottleneck. If you're a marketing professional and you need to get something out the door, then you can create it yourself. Absolutely.
Here's the thing, Clinton. We're in such a rapid inflationary phase. If you are using Big Bang terms, when the universe, that spark of creation, and then it went into this rapid inflation that faster than the speed of light, they say, where the universe blew up.
I think we're seeing the same thing through AI, with AI, where, yeah, when that MIT study came out, with 95% of people not seeing the ROI and only 40% using it, that was probably an accurate number. I think that's flipped on its head by now, and I think it flipped on its head around November. November, December, that release of Claude and AI and ChatGPT really flipped the switch.
I agree. Yep. I think OpenClaude was, what, February?
Mm-hmm. End of February. And some of the things that have come out since then have flipped the switch on agentics, and you're going to see people deploying and coding and using agentics to not just brainstorm or create content, but to post content, to use content.
I know for us personally here at Techstrong, we've been on a journey for the last month where we've got a few people using OpenClaude. Most of the team is on Perplexity Computer. Oh, okay.
Which is an agent. Game-changing. What we've put out.
Actually, Perplexity keeps a running website report for me of all the different projects we're using it for. And it's phenomenal. I can't even begin to start telling you.
So I'm not surprised. I think that number's moving. It sounds to me like you guys are maybe leading the charge because I did notice, being a cybersecurity conference, I couldn't help but ask both what sort of corporate usage policies looked like and how they were being enforced.
And there is a gap where 76% of the respondents said that their company has a corporate usage policy, but only 43% said that they're enforced with technical controls. And it is still early days, right? Yeah.
I think last year for me, also, when that MIT report came out and said 95% aren't achieving ROI, it's like, well, yeah, it's year one in a sense of this enterprise adoption, right? Well, yeah. Exactly.
I know 2026 is the year that people are really looking to get AI native, and I do think that gap between policy and enforcement shows that there is still a lack of strategy. And likewise, I think that if you look at marketing, the same way that shadow AI is a risk in cybersecurity, if you just have a marketing team that's sort of doing ad hoc prompting, that's also a risk. So what you're doing is that same idea of sort of governance, right?
But for a brand voice, for an editorial calendar, and I think that's where we're going to see the next level of maturity materialize is around using MCP servers- Yeah ... Claude Skills, Claude Projects, custom GPTs to create a centralized brand voice and ensure that sort of everyone's agents are working in unison. So that's the nice thing about this Perplexity Computer is you do have this agent, and it has like 400 integrations out of the box.
Right. Right? And so it really hooks into everything.
But then there's something called Perplexity Spaces that you get with the subscription. So now you and I, assuming you were on my team, we could share the same prompt, the same task, as they're called in Perplexity. You don't necessarily get that with the OpenClaude.
However, it's the difference when you're using raw open source versus sort of a commercial product, where they're responsible for locking it down more and making sure of security. Our OpenClaude users here, we absolutely have a very-- I helped build it. Our security policy on what it's allowed to do, what it's not allowed to do, how you use it, what it can have access to.
It starts with a zero trust, and we build from there. And they all run on their own machines or in a VM on top of the isolated machine, so it's abstracted one layer higher. What access to emails or files do they have?
All of these things. But it's easy because we're not an enterprise, right? Fifteen, 20, 25 people here.
So it's a little bit easier to manage. I still think we're coming to grips with that. I also think-Clinton, though, that the whole-- I've heard it called GEO, AEO, this whole idea of, I call it SEO for AI, right?
Yeah, I know. It's sort of like the Scooby-Doo meme where they pull off the mask and- Yeah ... it's still the same guy underneath.
And I do think where with SEO, you had gurus who were publishing Search Engine Watch and all these kinds of things where you can-- It was more of a science. I don't know if GEO or AEO has reached science level yet. I think it's still artistic and a little bit fuzzy.
Yeah. Well, there was a Princeton study that was produced in 2023 that kind of coined the term generative engine optimization, and it did find some correlations with things like including statistics, adding quotations, right, that those had a higher correlation with citation in the models. But the thing is, that research was produced before the retrieval augmented generation.
So it's not really reflective of what production environments look like today. And that's the problem we live in today. As soon as these studies come out, in three weeks, they're obsolete.
Yeah. It's true. I do think that there are some people that are tracking it.
You know, Muck Rack- Yes ... I'm sure you're familiar with. They put out what is AI reading, and that was, again, in December, so it's like who knows how much things have changed.
But they also found that including statistics in press releases increases the likelihood that they'll be cited. There's someone named Kevin Indig that publishes a growth memo, and he just recently did a very in-depth analysis of what's working for AI citations. And the fact of the matter is that it changes depending on your vertical.
And so- Yeah ... it's one of these things, and that's, I think, one of the values here of the survey that I produced is because it shows that within the cybersecurity market, and again, if you want to extrapolate that to enterprise technology, people are using Gemini, or they're using ChatGPT and Claude, right? And so if I was working on an enterprise marketing team trying to reach enterprise buyers, those are the platforms that I would be looking to optimize for first.
One can make the argument, though, by optimizing for Gemini, you're picking up Google. Yeah, of course. And again, with every platform being different, one thing for Gemini is that it prioritizes YouTube because- Yeah.
Of course it does ... of it being a Google property. Yeah.
And it can read all of the transcriptions into the model and that sort of thing, right? So every model has its own idiosyncrasies, and every market vertical has its own idiosyncrasies. So there isn't really a one size fits all approach, and that's why we just wanted to- You know, it's like my grandma used to say, Clinton- ...
kind of start benchmarking things now ... " So yeah. But I do think what you're going to see is-- Well, certainly here for a company like Techstrong, but I think for most marketing people, too, we can't afford to overspecialize for any one of these engines because we're going to need ChatGPT.
That seems to be the consumer choice. Claude for business. Gemini, of course, brings us Google.
As much as I am not a fan of the Copilot, I don't think it's up to snuff compared to the others, it does get you into that Microsoft world. This is why they race the horses. Clinton, is this survey something people could download?
It's not even something they can download. It's ungated. ai/research, I have a couple of different research reports I've produced.
Another one that I vibe coded a website scanner and looked at the Fortune 500 adoption rates of a few different technical signals. Very cool. Hey, man, keep up the great work.
I love what you're doing, Clinton. I'm sorry I didn't get to see you at RSAC this year. Hey.
Well, I'm seeing you now and watch you on Techstrong, so. Well, it's not quite the same. You're here on Zoom with me, and we could've seen you in person.
But that's okay. Maybe Black Hat. Yeah, we'll see.
And hey, at least, it's not generative avatars talking to each other yet, right? How do you know? Yeah.
All right. Thanks for your time, Alan. Hey, Clinton, man, I appreciate you.
You be well. Keep doing what you're doing. All right, take care.
All right. Clinton Carr here on Techstrong TV. We're going to take a break.
We'll be back with more in a little bit. Hey, guys, thanks for the throw. We're here with Hart Rossman, who's vice president of security for AWS, and we're having a little chat about, well, what is the future of security going to look like in the age of AI, and especially how our teams are going to be constructed, because everything is changing.
Hart, welcome to the show. Hi. Thanks for having me, Mike.
All right. I think it's fair to say that AI is going to enable both the good folks and the bad folks to discover vulnerabilities faster than ever, and hopefully We will use AI to create the fixes for that faster than they will be exploited, and it's a bit of a race against time, as it were, and some people might call it an AI arms race. But is it your assessment that these two things are going to happen in tandem, or is there a gap between the two and things might get a little worse before they eventually get better?
Or how should we be thinking about this? Mike, I've always approached security with a bit of an optimistic lens, right? Each new evolution of whether it's technology or tactic or operational principle gives us an opportunity to raise the bar for security and do better at scale.
And so I'm excited about AI, I'm excited about the prospect of teams learning to be more efficient and effective every day and at scale. And so I think for the security teams that are willing to lean into change, that there's tremendous upside. And that's really, I think, the challenge.
Many security teams, the new and the unfamiliar can be scary, can appear to be untrustworthy, and so they're reluctant to change. And in today's environment, the pace of change is so rapid you can't afford to sit on the sidelines and watch and wait. And to your point about that, all these things are happening now at what we would call machine speed, and maybe it'll seem kind of quaint to the way we used to think about security and call that stressful back in the day.
But the existing workflows and processes, and maybe even the ways we're organized, just don't seem to lend themselves to machine speed. So do we need to kind of rethink how we're approaching this from an organizational perspective because, well, if the tools change, so do the workflows. Yeah, I really think we do.
The way I've been encouraging my teams to think about it is you've got two gears, right? You've got kind of that fast-twitch muscle and then you've got that slower, more strategic thinking. The more strategic thinking, that looking over the horizon, this connecting the dots, sometimes we call them one-way doors at Amazon.
Those are still vitally important, right? What we have to do is recognize that most decisions, particularly at machine speed, are not that. They are fast, they are iterative, they are quick to experiment.
And so, in the past, maybe where you would have sat down and written out a BRD or a PRD or a product doc of some sort, today you should build a prototype that's a candidate to go into production. Right? So don't spend an afternoon writing a doc.
Spend an afternoon building a proof of concept. And then don't spend a week iterating and reviewing the doc with your peers. Spend the week iterating and building a candidate production build from that proof of concept.
So taking this to its nth degree, I think when I talk to IT folks, there's always been this sense of fear about patching something without first testing it and going through that whole process, and that can take days, weeks, sometimes even months. And the concern has always been that the application will break. But it seems we're approaching the point now where maybe I do need to automatically apply whatever fix is available the minute it becomes available because the bad folks are able to exploit that now in a matter of minutes as well.
So I may not have the luxury of testing things the old-fashioned human way. So does this whole loop of what we call DevSecOps need to become much more automated than we've ever imagined? So I guess I would say I don't fully agree with all of the premise of the question.
I would say, though, that the benefit of AI and the benefit of AI development life cycles is that things we've always wanted to do in security at scale reliably are now possible. So test-driven development, having complete coverage of code when you do a vulnerability assessment is all now possible in a realistic period of time. So you don't need to spend weeks or months testing.
You can do it in hours or minutes, which means you can patch infinitely faster than you could in the past. What it can sometimes surface, though, are organization-wide mechanisms that are too slow. Right?
And so it gives you an opportunity to rethink, to streamline so that you really can patch at the speed that you need to. It's just one example, right? And AI gives you that advantage.
There's a couple of different ways it does that, but this whole idea of interacting with an agentic IDE to steer the development of whether it's a piece of software or patch, whatever it might be, and then use test-driven design, use spec-driven design and development so that you get the output you're looking for and it is computationally correct. Right? It's just a huge opportunity for the defender.
The models themselves are getting smarter, and so are the reasoning capabilities. And I've talked to some other folks recently where it's rare that an AI model, for example, generates a SQL injection vulnerability these days, and that used to be the bane of our existence. As we kind of work our way through all that, is the software that we initially create going to be more secure in the first place than it was when humans built it?
It may not be immediately, but it seems like we're heading in that direction. Yeah. So what I'm definitely seeing is the code that's being generated is more often than not bug-free or it's correct.
Where there's the gap is sort of the intent, right? Is did you describe enough about the system for it to build all the right pieces and parts to get the outcome you were looking for? The code is correct, but did it build the right thing, right, and did it add all the components?
And so now you have to think about even more than you did in the past, security as a functional requirement, right? So, it will build all the security features you need if your intent is to have a security bar that it meets, right? And so then you go back to, okay, well, did I ask it good questions about the cryptography that I need?
Did I ask it good questions about the authorization model that I need, right? And if you do those things, it's likely to produce software that includes security as the right functional output of your request. I was also talking to somebody about this whole issue, and one of the things that they had pointed out is if the timeline changes in terms of what it takes to create and test a patch, well, the economics around outages changes dramatically.
Because their point was, well, if I do have an issue and I create a patch and it knocks off the app, well, it's only going to take me a few more minutes to fix the patch and redeploy it anyway, so the amount of downtime might be only measured in minutes and not hours and have this major level of disruption. So has the risk level of automated patching kind of declined? I think it is, and it will continue to decline.
What you described is a little bit of a perfect state, assuming everybody has a modern automated pipeline, they're using a monorepo, right? They've got some experience, and they've built up a point of view and some of the automation around it to do that. There are still lots of organizations in the world who are, for example, just transitioning to cloud or are, believe it or not, still getting into DevOps, right?
And then there are a bunch of workloads that, for a variety of reasons, may never be fully automated, right, in certain public health and safety systems, right? But I do think that's the direction things are going. And if you have a system that could benefit from that today, again, there's no reason to wait.
What's the impact on the security operations teams? Because I would argue that historically, there has not always been a lot of love lost between SecOps and the developers, and SecOps tends to view developers as kind of the root of their cause of their problems, and the developers always viewed SecOps as something to get around. Is that relationship going to change in the age of AI?
Will we get to the point maybe where the two will see more eye to eye? I certainly hope so, right? I've long believed that you can't protect what you don't understand.
And I think in the technology world, it's easy for us to put that lens on the technology itself, right? It's difficult to make good risk-based decisions about how to deploy a database if I don't understand the database technology. That's also so true about people in organizations, right?
And so, in my org, we talk a lot about this concept of EPIC leadership, which is a way we use to understand the people in the teams we're interacting with to get aligned and deliver the best outcome. And EPIC is an acronym. It stands for empathy, purpose, inspiration, connection.
Right? And so taking the time to deeply understand the operating system of the people in the organization, and then proactively investing in the things that are going to get the best outcome. And the addition of AI is so beneficial there.
One is you can literally create persona agents. So you can sort of pre-evaluate the impact to your builders by interacting with an agent that's representative of a particular builder community, right? Whether you're testing a message in communication or you're modeling out, right, a certain change.
But the other thing you can do is use it as a common point of understanding, right? We're all shifting into the AI era, the age of agentic. And so we've got a common set of challenges and opportunities that we can choose to work through together, or we can choose to work at odds.
And I think to your point, it's an awesome opportunity for security and the business and the engineering orgs to make the decision to invest in speed, to invest in alignment, to reduce friction, and to raise the bar for security at machine speed with big functional outcomes for the business and customers. So how do we get there? " So we have this notion of secure by design, and you mentioned intent, but how do I express my intent to follow secure by design principles in a way that actually creates that outcome?
Yeah. So there's a few ways to do it. Of course, you can start with the prompt, right?
"That's one approach. But another approach is that as these technologies are maturing, you have the ability to provide what's often called a steering doc. So it's a markdown file that basically governs how the AI should interact with everybody and everything on that project.
And so, a great best practice is to implement a security steering doc that memorializes in plain English or whatever your native language is, what are some of the security expectations, what are some of the guardrails, what are some of the requirements, what are some of the regulations that we want all of the software to meet, regardless of whether it was explicitly asked for in a particular prompt or conversation. And it's a wonderful way to scale that culture of security in your organization do it agentically. " I'll say two things.
One is, I'm always surprised at the number of people who view working with the AI as the last step in the build process. They'll have a requirements meeting, they'll do a bunch of whiteboard, they'll create all these wireframes. They'll do all of this upfront work to then go sit down and formulate their prompt.
And the beauty of the environment we're in is you can invert all that. " And start building it interactively with the AI, right? So I'd say that's the first thing is start with AI, don't end with AI.
And then the other thing I would say is that, I think people are now in a world where you can build so quickly that they underestimate the level of effort to finish. It's a little bit of the Pareto principle all over again. And so they get 80% of it done in the first couple of hours and hadn't really thought about the more complicated elements of what they're trying to do, which of course could then take days or weeks to resolve.
And so they're surprised that they didn't finish in an afternoon because they've heard all the hype about how fast AI is. And it's like, yeah, you got the 80% solution out of the gate. Now, with the human in the loop, you got to go reason about the hard part, and that could take a while.
So to close this out a little bit, historically, I think if I looked at an organization, I'm guessing, but for every 50 developers, there was one person maybe who was in charge of DevSecOps, and they were doing that on the behalf of the other 50. It's probably maybe closer to 100. Is that whole structure now obsolete because, in theory, DevSecOps is going to be pervasively deployed throughout the software development life cycle using AI, and I won't have to be dependent upon the expertise of one to support 50?
So what I'm seeing a lot of is smaller, flatter teams that are multi-dimensional, they're multidisciplinary, and they're moving very quickly. And so, in Amazon, for example, we always talked about a two-pizza team as a team large enough, obviously, to eat two large pizzas. So maybe eight to 10 people, 10 to 12 people.
Today, we're seeing maybe they're two-slice teams. You're seeing groups of two, four, maybe six people, who are working with lots of other teams of two, four, six people to build just phenomenally complicated software simply and efficiently and effectively. Well, folks, you heard it here.
The way we think about building secure software is going to need to change. There's no two ways about it. It's just a question of where are we going to fit not just the humans, but all the AI agents that make up that workflow to create something that is, well, hopefully better.
Hey, Hart, thanks for being on the show. Cool. Thanks for having me, Mike.
All right. And back to you guys in the studio. Hey, everyone.
Welcome back here to TechstrongTV. We're continuing our Wednesday afternoon coverage from RSAC here on Broadcast Alley, and I'm reaching way back to my Boulder people for this one. Let me introduce you to the founding team of StackHawk.
Right? We have Joni Clifford, who I found out is still Joni Clifford. You know?
And- But married. But married. Well, just don't call her late.
But Joni Clifford, who I've known as Joni Clifford for, I don't know, 10 years. No, more. Probably closer to 15 years- Yeah ...
I think. Yeah. Because I- I'd just stop there.
Yeah. Because there's no more time after that. That was ...
Okay. Let's not even get wrecked. And Scott Gorlick.
Gorlock. Gorlock. Also co-founder, who I've also known now probably seven, eight, nine years.
Yeah. At least. When did you found StackHawk?
Was it about eight years ago? 2019. Seven years ago.
Yeah, almost. All right, I wasn't that far off. Close.
I remember the first time I met Scott, we were in the Foundry offices- Yep ... in Boulder. Yeah.
Right off of Pearl Street. Yep. Yeah.
Anyway, though, enough reminiscing. Well, we're not done reminiscing, actually. Joni, I'm going to ask you to kick off.
I said I knew youI think the first time I knew you was, VictorOps. That's right. And that might, may or may not be a name you remember.
A lot of my DevOps people out here, you remember VictorOps? They were actually acquired by PagerDuty. No.
Splunk. Splunk. Competitor to PagerDuty, acquired by Splunk.
Yep. I don't know why I thought PagerDuty. You know why someone from VictorOps went to PagerDuty?
Yeah. Was it Jason Hand? We can play this later.
So tell us your story. Yeah. So Joni Clippert, CEO, co-founder of StackHawk.
My background is in DevOps, so what you were just saying. Right. Largely building software for software engineers.
We just went over VictorOps. It was a competitor to PagerDuty, and that company was so important because it was really in this hyperactive, we're finally releasing, DevOps is a real thing, and we had to make sure that if there was downtime or latency or anything, we were shipping those alerts directly to the software engineers who wrote the code. And I think that kind of arc of digital transformation is really what led me here.
And so, with StackHawk, it felt like application security testing was just the next mile of digital transformation. Yep. Why are we waiting until production to actually find vulnerabilities?
How come we're not collaborating with our software engineers or automating the findings so they can actually fix these and treat them like bugs? Mm-hmm. Not like even security vulnerabilities because they found them before they deployed to production.
So that is what I wanted to work on. And in the process of really getting to know, I didn't know the cybersecurity market. Right.
And it felt like a very obvious process to tackle, but I interviewed a lot of security professionals. I remember. You interviewed me.
Yes. We wanted to know- No, I do. I remember ...
what was this domain? Right. And that's how I met Scott a long time ago.
And Scott, tell us a little bit of your past. Yeah, definitely. So, security operations, security engineer by background.
Worked at GoDaddy, leading security teams there for about 10 years. Mm-hmm. And from there, moved to Colorado and joined another great Colorado company, SendGrid.
Sure. I was a CSO there for three years. Techstars company.
Yeah, right before Twilio acquired them. And I've been working on application security at pretty much all of those roles in some sort of fashion, either deep in it or tangential to it, those kinds of things. And so I had a deep passion for how to fix pretty broken process, how do we empower engineers.
We did some of that on transition to cloud at SendGrid, getting engineers involved early. " Yeah. They're the one that start the code, and then way, way later, they get to know about the problems that they have to fix.
" But- So we had a really good conversation about how can we help empower those teams, let them know about security vulnerabilities and build safer software. Mm-hmm. I think back to those early heady days of DevOps- Yeah ...
when VictorOps was founded. So Raj, my friend Raj, was at JumpCloud. You guys are in the building next up on the second floor there- Yeah ...
that brick building. Yeah. And what a revelation it was.
Hey, let's alert the developers, not just the help desk guy, but we're going to cut that handoff from level one to level two to level three. We'll get back to you in 36 or 72 hours to one boom. That's right.
One time and it's done. Now, today, we almost take that for granted that developers are part of this chain, or part of this, my code's not working, I know pretty much right away if customers have it. It was the same thing as you said with AppSec.
It was like, it's similar to observability, quite frankly. All the action was on the other side of the event horizon, the event horizon being deployed. Deployment.
Deployment. Right. That's where the action was.
And that was part of this whole shift left. We're going to- Mm-hmm ... shift to this side of the event horizon.
Now, shift left has had an interesting journey- Mm ... in the DevOps space. " And we came to find out the developer wants to write quality software.
He doesn't necessarily want to be a security pro either, though. And we need the security people in all these things. So it's been a journey which you guys have actually lived through- Mm.
That's right ... over these last seven years. Of, well, did we over-shift?
How do we keep the security team involved? How do we empower the developer without expecting him to be, or her, to be a security pro? Mm-hmm.
What about the rest of the software team, the CI/CD team, the testers, the QA folks, the SREs, everybody that's involved here along this SDLC? And then just when we thought we figured that out, AI drops from the sky. Boom.
Because life can never be easy. Never. " Yeah, it's really interesting because how we were founded was about making this type of testing that used to happen in prod, took a really long time, making it portable, easy to run on a software engineer's machine, easy to run in CI/CD.
And that's very unique. I don't know of another company doing runtime testing that has the same approach. They're all using these cloud-hosted scanners that can't be portable, they can't be fast.
So there was this really interesting architectural decision we made early on that set us up perfectly for this period. And we're now closing customers and having our existing customers come to us and say, "I think CI/CD is too right. We're living in Cursor.
" Yeah. " Yeah. And I think the AI DLC or AI-supported DLC is the place where we're really focused, which is on agentic DAST.
Right. So yeah, with runtime, you want to kind of hit the whole gamut. You want to be able to test with AI and auto-remediate issues in Claude or in Cursor.
But you may also want to test closer to prod as the secondary check from your AppSec team, and you can totally do that. So, I feel like we really have a leg up. It was just this early decision we made that now suits us perfectly for this moment.
The interview before you guys came on, I was talking to the CEO of a company called Anvil Logic. Not related to you at all. Okay.
But more of like a big data lake security company. Mm-hmm. Same thing, founded maybe two years before you, 2017.
Okay. He didn't think of AI when he founded the company. It was this problem, though, of how do you secure, at the time, Hadoop and- Yeah ...
stuff like that back in the day. But AI has made his life a lot easier because- Yeah ... he didn't realize it back then, but he really needed that technology to really wrap your head around that kind of big data.
It's the same thing here. We wanted to radically change how we look at testing code, testing applications. Well, AI, and this is only in the last two months, with Claude Opus and all these things, all of a sudden, we have the ability to test- Yeah ...
like, as we're making the code. That's right. Soon as we commit the code.
Any time along this CI/CD, virtually, and without manpower involved. We just report it back to the human in the loop, or, as a lot of people are saying now, the human at the helm- Mm ... because we don't have enough humans to be in the loop anymore.
Mm. Too many loops. There's too many loops.
There's too much code. Yeah. And so you guys, right place, right time.
I always learned that from Brad Feld. Sometimes it's better to be lucky than smart. It's good to be both.
But that's, I think, what we're dealing with here. And at the same time, though, Scott, as we just said, we have so much more code. So much.
Yeah. And so I wrote this piece about a couple of weeks ago. In AppSec anyway, we've moved from the question of how do I find bugs or how many bugs do I find- Yeah ...
to what's governance look like here? So it's no longer enough to do the scan. Yeah.
" And ultimately, you'd get half of the people say finding, half of the people say fixing. We had great tools to find problems. Prioritizing those fixes has always been hard.
And we're just not fixing problems that are discovered in code, but the power that comes with the agent being able to understand what the problem is and be able to actually fix without wasting mental power from a dev or interrupting a cycle for delivering product, delivering value, it's just radically changed how application security is working. Look, we moved the cheese in AppSec. That's what happened here.
Yeah. We went from a focus of finding to a focus on fixing. Because as much new code as we have, we could find vulnerabilities till the cows come home.
That's right. But we got to decide what to do with them, and what to fix them, not fix them. Are they real?
Are they not? Are they reachable? All the things that you guys know.
Exactly. I saw a study on this. What was it?
Claude Code found, I think it was 122 potential vulnerabilities in Firefox in like an hour or two hours, whatever it was. 11 of them were actually, call them real vulnerabilities. Two of them were exploitable.
Mm-hmm. Right? That's a huge problem in that- And that's pretty much the ratio.
Yeah. " Because the punchline to the story is always, and then we tested it in runtime to see what was actually exploitable- Right ... which is what we've been doing for the last seven years inherently.
Right. So being able to get into that loop, be the part and the function that's doing the testing of the behavior, not just does it look like it's vulnerable- Right ... and validate, yeah, this is vulnerable, and we should fix this one thing or these two things, and get rid of the other 120 other things- Yeah, right ...
that are irrelevant. And thisIt sounds like a nothing thing if you're not into security- Right ... or you're not into development.
But if you are, you realize just how radical this is. Mm-hmm. Right?
It's a totally different focus for what an AppSec solution needs to do. Yeah. And so all these people who developed the DAST and the SAST and the SCAs, they're all good.
We've got great scanners. But if that's what your business is today, I don't know if you've got a great business if you're not dealing with the how do I fix these things? Yes.
Or what should I fix? That's right. And how to fix it, and are you going to let me fix them automatically or not?
Mm-hmm. I'm sorry, but you're the first AppSec people I've interviewed here in two days. Oh.
All right. Yeah, so I'm dumping it on your laps. Well, you're like on it.
Well, I mean, right. I know a little bit about it. And I've been writing about it because to me- Yeah ...
remember, I came from before the AppSec piece. Mitchell and I standing over there, we were at Still Secure. We were vulnerability management.
We were begging people to scan their systems once a year. Oh, wow. And that was considered radical.
What do you mean once a year? I could do this every two years, three years. Yeah.
But that's what it was back then. It was job security because you gave them a list of vulnerabilities like a telephone book. If you don't know what a telephone book is, Google it.
And they'd start on New Year's, they finish on Christmas. Yeah. And they start again.
And then you do another scan- And they did it again ... and give them the book bag, a new book. New list.
So this is what progress is- Yeah ... in security. How now does- Yeah ...
you go to market with this and get that message across? It's a total sea change. Software engineering is the first job to be completely changed by AI.
Yeah. Tip of the spear. Our senior engineers haven't written a line of code since August.
They are just using prompts. We've 8X'd software engineering in the last six months. So everything around that surrounding code delivery has to change, and AppSec is the next most important thing.
We just closed a customer who was handwriting 25,000 lines of code a month. Could you imagine? Yes.
And they're in financial services, by the way, so a mid-market financial services company. They employed Cursor. The next month, it was 250,000 lines of code.
Wow. Next month, even more. So literally 10X.
And they called us, and they're like: "We're sitting on a million lines of code that we can't deploy- Because it's been tested ... " And they're in a regulated industry, so they needed to. So we've been co-creating with them this new AI DLC.
And to your point about static code analysis tools, we have to totally rethink it, because at 10X, where we're just getting started- Geez ... software engineering, it's called the vulnpocalypse, right? Yeah, it is.
" So our perspective is you have to focus on what's reachable and exploitable. There's no time to focus on anything else. You can't take a food chain.
I don't know if you ever read-- So Brad Feld used to give this book out to all of his founding teams, "The Goal" by Goldratt. I forgot his first name, but it was standard MBA book in the '80s and '90s. But it introduced something called, you're probably familiar with this, the theory of constraints- Mm ...
where as soon as you undo one bottleneck, there's another bottleneck- That's right ... behind it. Another bo-- Actually, Gene Kim's Phoenix Project- Mm-hmm ...
is the IT version- Right ... " "The Goal" is about manufacturing. But similar, if you ever read "The Goal," you'll see where Gene got Phoenix Project from.
We're not familiar with the theory. We're living it. Well, we all live it.
We all live it. So we removed the bottleneck of humans writing code, and I can only do 25,000 lines of code. And man, I could do 250,000.
I just 10X'd my lines of code. Yeah, but now you just discovered the next bottleneck. That's right.
I can't even test this and see. But what's going to happen is, okay, now I tested it. I found out originally that, I don't know, 300 vulnerabilities are really only seven vulnerabilities.
Boom, I removed another bottleneck. I'm doing that automatically. Well, now here's the next bottleneck.
I got to remediate them. What's it going to take? All right.
Maybe I'll be able to do it agentically. So we're going to do that, but there'll be another bottleneck. Mm.
Yeah. That's the theory of constraints. But from your point of view, this is really a game-changing- Mm-hmm ...
kind of new era, right? You have marketing people, I'm sure, right? But I think that's what the marketing message has to be here.
Mm-hmm. AppSec. Yeah.
I think teams are already looking for, what do I need? And they might be focused on it a little bit backwards. What product do I need?
The thing that I've found is a lot of engineering teams are in the same mode as the AppSec team- Yep ... where they're tinkering with AI and messing around with OpenClaw and trying to figure out what works in their environment. And then once they figure that out, they're starting to standardize, here's the tools that we use, here's the plugin agents that we use, so we can get the same performance out of most of the team.
Mm-hmm. Now's a great time to, as an AppSec person, go sit with the engineering team and watch them go through this iteration. Watch how they're hooking different parts of their process so that they can actually work that into their process.
Into the SDLC. Yeah, exactly. It's in the chain.
Knowing what's out there, what's capable, and then being able to understand the process at your business of what your engineering team is doing, and how do I fit a new AppSec process into my new engineering process? PS, there's budget attached with that because everyone's working together to get more value to the customer. Yeah, but you know how it is with budget, again, don't take my cheese, right?
It's my budget. You go get your own budget. That's right.
And there'll be some turf wars around that, too. Yeah, I think, from a CEO perspective, from the C-suite perspective, we're spending a lot of money on tokens, right? And the whole point is, how do we improve efficiency?
Say that again for me. We're spending a lot of money on tokens. Spending money on tokens.
You ain't kidding. Yeah. I think you're spending a lot of money on tokens.
Yeah, yes. Yeah. " And they also want to do it securely.
Yes. So being able to say, "Hey, I want to empower this process- Mm-hmm ... " It's not an easy conversation, but it's a way more acceptable conversation than- Absolutely ...
I'm trying to slow everybody down. That's right. Because when did that ever work, right?
Never. That never worked. And that's been a security problem, too, for years, right?
No. You're saying that as you see the train pulling- That's right ... into the station.
No. So let me ask you the ultimate question then, Joni. Mm-hmm.
If I'm a reporter, I'm not a reporter, I'm just Shimmy, but- ... is StackHawk an AI-empowered AppSec solution? Of course.
All right. In two ways. We are empowered by the wave.
Runtime has never been more important, and it's pretty exciting to see it happen. We're six, seven months, or seven years. We'll pretend it's months.
Yeah. Years in. Well, the time, it seems like months you've been having so much fun.
Yeah, of course. But also, we were talking about by using AI, what you're then able to do with your product. We've been able to release capabilities that would've been whole companies before.
We are using AI to really help bridge the gap. The knowledge gap between what an AppSec person knows about software delivery that's happening in their own organization, and how fast it's happening versus what they know today, is enormous. So beyond the testing piece, over time, we've added this lens of observability component into based on what's happening in your source code repositories, you have this many APIs, web applications, LLMs, LLMs talking to APIs that need to be tested with something like StackHawk, able to show them what contains sensitive data.
The amount that we can get out of the code base to help inform the AppSec team as to where to focus is incredible, and we've been- Yeah ... totally empowered by AI to do that. So really exciting to use it so natively, but then also just be able to draft on the change that's happening.
Absolutely. What's going on. Yeah.
So I've got a CTO question for you then, Scott. Hit me. How long until you're doing remediations?
Not long. It already happens today in this agentic loop. There you go.
I don't have to make tickets, which is awesome. Those days are done. Yeah.
" Go fix it. Fix it right there, before we even get anywhere near CI/CD. Yep.
It's happening. And it's crazy exciting. Yeah.
Mitchell and I had this discussion this morning on it. The days of just reporting- Mm ... without doing are over.
That's right. You got to do. You got to do.
It's an age of doing. Yeah. And look, I don't know how all this ends- Yes ...
but it's really an exciting time- It really is ... to be doing it. You know what we haven't mentioned, guys?
People want to get more information about StackHawk. Mm. How do we do that?
com. You can learn a little bit more there. We have a ton of blogs, content, ability to learn more about this AI transition and wave, and we're also pretty active on LinkedIn, so feel free to follow us, engage with us there.
I'm following you on there. Absolutely. And if you're at RSA, you can play Where's Waldo with the giant guy in a purple jacket and/or his companion.
Okay. So you're there on- Yeah ... stop us.
Yeah. Or in the bathroom. I got to tell you, I haven't even had a chance to walk down to the floor.
It's pretty calm. I heard it was a little chill this year. Not super loud.
Not very many lights. It's pretty nice. So Monday, we put on our dev, what we used to call DevSecOps.
I don't even call it DevSecOps- Yeah ... anymore because- Yeah ... I don't know what to call it.
I do know what to call it. We called it Defending AI Native Dev. Right.
And because it is all about AI native dev. And so we were there Monday, and it was interesting, but I also snuck down to the Innovation Sandbox. Yeah.
And everything there was AI. Yeah. " So it's an interesting time.
They're watching this live, so they probably are not there. Where could we see you next after RSA, C? Oh.
Black Hat. Black Hat. For sure.
Lots of regional events. Lots of regional events. With some of our partners- Mm-hmm ...
Guide Point and WWT, and some of our great partners. We're always doing regional events, some informational, come learn something, and maybe have a good steak dinner. But our next big one is probably Black Hat.
Is Black Hat, early August. Yeah. I'll be there.
Awesome. So there, I do go on the floor to do video. Here, I'm on Broadcast Alley, so I get at least a- I'm stationary.
People come to me. Exactly. In Black Hawk, I got to go to them.
I'm the Black- ... Black Hawk. I did StackHawk and Black Hat together.
Black Hawk. That's a new conference you probably haven't heard of yet. Hey.
But if you do, that's a good name for your conference, Black Hawk. Joni, it's great seeing you. Good to see you.
Scott, always a pleasure to see you. Thank you for having us. My pleasure.
We're live. We're at RSAC. We're going to be back in a little bit.
com. Yes. Check it out.
We'll be right back. Hello, everybody. We're back in Amsterdam at the KubeCon + CloudNativeCon Europe Conference, and I'm talking to my friend Hong Wang here from Akuiti, and we're going to have a little chat about, well, Argo CD.
There's been a lot of momentum building around Argo CD now for several years, and it seems like it's finally coming to a tipping point in terms of adoption. And are people thinking differently about CI and CD these days? I mean, what are you seeing exactly?
Definitely. So the Argo CD has been on this long run, and personally I have been the creator and have been working on Argo CD for about 10 years. And nowadays, I think last year, the CNCF published a survey talking about 67% of the people already using the Argo CD in production.
That's technically a majority. So I think the Argo CD is already the clear winner for the GitOps in the Kubernetes space. So what we are seeing, the trend here is, originally people are looking for, okay, I have a CI/CD system, like GitHub Action, GitHub CI to do everything.
But Argo CD proved out is actually you need something specialized for the CD. That's why people using, okay, GitLab or GitHub together with Argo CD. But we do think we have additional innovation on top.
That's why we introduced this new concept called continuous promotion. It's kind of doing the multi-environment promotion and making every environment to be the first-class citizen. So we actually introduced the Kargo about two years ago.
Right. So I think I saw at the show there's a new version of Kargo floating around. What's in there?
Yeah, I mean, we have the open source version for two years, but we keep adding new functionality on top. So last December, we announced our Kargo version actually supporting Terraform, VM, and serverless promotion now. And today, yesterday, we announced that we actually making the Kargo be able to run custom steps.
So the main usage for that is actually right now security validation or maybe any customer scripts you want to run during the promotion. So we make it like catch all use cases, means you can customize your experience and do all the things you need during the promotion. What was different about CI/CD and Kubernetes versus what we were doing in monolithic applications?
Because for so long we tried to couple CI and CD together. Mm. But it feels like with Kubernetes, we've shifted more to this GitOps mindset.
But what drives that at the end of the day? It's actually an excellent question. So I have a lot of saying about it.
So the traditional Jenkins or GitHub Action jobs, it's jobs. Means it's run to finish. It's kind of like, oh, it's successful or failed.
That's it. Basically, it doesn't continuous getting the status of your application. It's kind of like, oh, I run, successful, done.
So things could be changing even after the deployment was successful. So what it changed for the Argo CD and the Kargo is, we do the promotion during the deployment, but since then it stops there. We actually continuously monitoring your infrastructure, understanding what's going on, and that's where the people needs.
It's kind of like you don't need a job run to finish. You want to actually constantly understand what's going on about your application. Are they healthy?
Are they out of sync? Or someone actually change something behind the screen? So you want to know about it.
So that's give you the massive visibility. Have we also maybe started to see a little separation of concerns? Because maybe the CI part of that equation is really in the developer realm, and the CD part is more in the software engineering, DevOps, platform engineering teams' concern.
And is that also driving this? Yeah, I think exactly to the point, totally agree. So it's kind of like the CI is mostly for the, I would say the development.
Basically, okay, you got a new change, you want to build your binary, building a Docker image, running some testing. But for the CD side is more, I think, in the realm of the platform team, DevOps, SRE. Because what is the ultimate goal for the CD is actually we want to release something to the production.
It's a very high value, high risk, and higher level activity. Means if something's broken or something released causing the outage, we are talking about maybe millions of dollars. I work at the Intuit for four years thinking about, what's the time now?
Okay, in another month, we have the tax due date, middle of April. So every 10 minutes is about $10 million for Intuit. So that's scary.
That's why people are actually looking for a very customized experience for their deployment experience. They want to minimize the risk. They want to have more visibility.
They have better control of it. That's also all the reasons why we built Kargo. Also solving that very practical usage and meets that needs.
One of the things, too, about Argo CD that I've heard is that people actually like the graphical experience for managing CD, and they don't necessarily want to do everything using programming tools, so- Yeah ... are people flipping in and out of graphical, the programming tools, depending on the use case, or are they all kind of just basically using the graphical tool? I think people still using flip around here and there.
However, having the graphic part is totally the big advantage for everyone. Because at Intuit in 2018, that was a little bit ahead of the journey for everyone adopting the Kubernetes in large scale. So Intuit basically asked us to say, "Hey, we want to adopting Kubernetes on AWS, and we have 4,000 developers.
They don't know about Kubernetes at all. " So our answer was Argo CD plus a nice user experience to be embedded that we don't need to tell the people, "Hey, what is a pod? What is a replica set?
" Okay, where you deployed, you see this tree view. " So sure, I'm not the expert. You don't need to be the expert, but roughly you get it at least.
There is how the object are connected to each other. Additionally, we make the logs to be available, events to be available, and when something's broken, we highlight it. Okay, this pod is crashing.
So that in the end is we making the 4,000 developer to kind of self-educate themself rather than we are forcing a tutorial or we becoming the support team, we need to teaching them a lot of things. In the end, it's like, okay, the education just happened naturally. Mm-hmm.
It almost seems like Argo CD can be a higher level of abstraction above Kubernetes that makes the whole thing more accessible and maybe democratizes this so that I can have folks who are mere mortals running this back-end process. I do think so. No, definitely, the Argo CD make the operate clusters in a larger scale way better, way better experience.
I do think the, okay, we keep hear that, oh, someone is running one cluster, two cluster, they said, "Hey," they don't using Argo CD. But I rarely, rarely see anyone, they are running more than five cluster, they say they don't using Argo CD at all. That's the trend, yeah.
Mm-hmm. So where do we go from here? You can't walk down any of the aisles at the show without somebody talking about AI, so how does AI get applied to Argo CD and Cargo and everything else that we're doing?
That's an excellent question. So as the Akuiti, we are actually providing the enterprise software delivery platform. So it's made of three capability.
So Argo CD is powering our deployment. The Cargo is powering our promotion. So we do have something on top called Akuiti Intelligence.
So what does it do? It's actually a purpose-built AI agent and for the software delivery operations. So it actually observe your infrastructure in the real-time, because as the Argo and the Cargo, we know what's going on with your infrastructure.
We know the live logs, events, manifests, and deployment history, all the context we have. And then it actually interprets incidents according the people to the runbooks and operational context. So we know when something bad happened, and then we can start and react to it.
In the end, it's actually taking corrective action autonomously. So all those experience are actually built inside your Argo and Cargo control plane, which is the tool the people already trust. So we basically bring the AI experience directly into the Argo and the Cargo, so people don't need to switch a different view or different tool.
They can basically using Argo and Cargo, and they enjoy all the AI functionalities there. Mm-hmm. How will this all play out in your mind then?
Because as I look at it, each developer's going to have a bunch of AI agents, and they'll talk to each other- Right ... and other developers, and then the software engineering team and the platform folks will have their AI agents. How does all this get orchestrated at the end of the day?
What's going to be the thing that allows these AI agents to negotiate and kind of jointly accomplish a task and collaborate? I think it's in the end is we feel the AI is a little bit mimicking about how human are collaborate with each other in the end. So everyone have their different mission and different goals there.
So means for the most of the developers, they are focused on doing the development, means I'm writing the code, I'm reviewing the code, I'm getting something into build state. Then the platform team, the DevOps team, they are worried about more about, I want to deploy this successfully, but also afterwards because the application's a living creature now. Something can be broken, crashing in a day later.
Then how do you kind of babysit those applications properly? And also, security is a dynamic landscape, right? Yesterday, everything's fine.
Today, okay, there is some security breach or CVE happening. So there's a lot of the operational side about your application. That's why I think that there is a mimic about how people are working, is every side of the role, we are getting more efficient by leveraging more AIs and more agent, a purpose-built agent to make them more efficient in the end.
A lot of people seem to be worried that the developers will now be generating such a high volume of code that it will overwhelm the CD systems that they have or whatever they're using to promote and deploy software. Are we going to have to rethink this whole DevOps, GitOps notion? Yeah.
It's a very accurate observation, actually. So we actually shared some data publicly last week. So last year, our customer did a 43 million deployment through our platform.
I'm talking about our enterprise customers, not even just open source. Open source will be billion for sure. Mm-hmm.
We do think that was like 10X compared with 2024 because of the AI adoption. So one of the observation's really to the point is because of the AI, there is more development, more features, more fixes. There's more things getting deployed to the production, to your environment in the end.
So I do think it does causing more a problem in the deployment side. That's why we need more automation, more guardrail. It's like in the end is you want the AI actually also working for you in those contexts.
For example, you want to deploy something, normally it's a human reviewYou cannot review 1,000 deployments every day, but could you let AI do some risk assessment about, hey, this is what I'm going to deploy, this is what is running already in your production. What is the diff? Then the diff is, okay, you just change the documentation, then auto-approve.
Why bother, right? Just deploy, that's fine. But you're adding five different new API.
That is lower risk, it's fine, because this is a new API, means not changing the existing API, means the system should still continue running, even the new API has some glitch, it's fine. But okay, this is a massive refactoring. You are changing some existing API.
That is definitely a medium or high risk. " Maybe you need to babysit this for the next hour before you can sign off. Mm.
So that's where I see the AI can already help to do more automation together with all the automation tools we have. That's exactly the reason why we added the intelligence on top of our deployment and promotion solutions here. So what is the future of the role of the software engineer, and application developers for that matter?
Because there's still a lot of conversation out there about AI replacing people, but doesn't seem like that's necessarily the case, but what's your take? I think it's still very dynamic and a fluid situation right now. It's like I see the AI as being embedded everywhere, so people will find the right balancing in the end.
But I do think the AI will force the human to be more like a thinker, to be more like a leader, the leader of the agentic- Mm-hmm ... solutions, right? So you are more like rather than you doing a lot of, I would say, dirty job or low-level thing, you are more like orchestrating the bigger picture.
So what's your goal? How are you breaking that bigger goal into 10 chewable steps to get there? Then you validate, okay, did the AI get this done in the high quality or to your expectation?
Then you are doing the checkbox of those things. In the end, you reach your business goal properly, or development goal properly. I think that forcing the human to do a more interesting job, to me, I would say, rather than, okay, what's the full loop?
And how to reverse a linked list. That doesn't make sense to me. Why spend time writing those software?
Right. And do you think also maybe that more organizations will build custom software because with Argo, we're making Kubernetes more accessible, and with AI, we're making it more accessible to do the coding? So maybe I don't have to be a Global 2000 to build my own cloud-native applications.
I can be a mid-market company and succeed. Yeah, I do think that the software could be more customized. There will be more customized built software, which I do think that will happen, but I don't take that as a bad thing for us, especially because we're thinking that Linux is a foundation for the operating system, Kubernetes is the foundation for the cloud operating system, and Argo CD is the deployment solution for all the Kubernetes or for the foundation.
So what we are seeing there is, okay, sure, you're getting more customized software, but where they are running? So you still need to run on the Kubernetes, still running on the Linux. And you still need a deployment solution.
Actually, you need the deployment solution more urgently because you have so many you need to deploy and manage. So unless you basically are building a prototype you throw away, then you need to run it, you need to babysit it, you need to troubleshoot it. Mm-hmm.
So... So what do you see software engineering teams doing today that kind of just makes you shake your head a little bit and go, "Folks, maybe we want to be a little bit smarter than that"? I think the transition is already happening.
I talked with all my friends in Bay Area, Silicon Valley. So I do see their job responsibilities being changing, I would say. " Spend three days on it and trying to get it done, right?
Now, because AI is doing more heavy lifting on coding, so their job is more about coordination, about reviewing, validation, and having the bigger picture. So I don't know exactly what will happen in the three months later, to be honest, even now three years later. I think things will keep changing.
We are very excited. My team is already adopting cloud code in a massive scale. I see a day and night difference already regarding the productivity.
And I do know we'll be cautious about the quality, which I do think that can be addressed with more AI involved and a more experienced engineer driving the process or driving the quality control on that. So it's exciting, but it's also changing, I would say. Mm-hmm.
So what is next for Argo CD and Kargo? As you look into the coming year, what's on your agenda? I think several things.
So we do think we want to still double down on the AI native side. I do think there are so many agentic, customized agent we can build for our customer to realize the value. Because I do think the platform team or the SRE team is on the relative conservative side for a good reason.
Because, for example, if a $5 billion business is running on your platform, so you do want to be very cautious about how you run it, how you control it, how you operate it. So I do think there is more deep dive, deep expertise agent should be built to get more out of that AI experience to make more people more efficient in the AI and platform side. So on our side is also we want to make our Kargo solution to be very generic and universal...
means we already kind of like supporting the Terraform now, supporting custom stacks, supporting VM, but we also want to bring the nice developer experience to the VM user, to the Terraform user, to the serverless users, to make sure they're getting all the value out of the cargo properly there. So definitely a lot of work to do still. All right.
Well, folks, you heard it here, Argo, Kubernetes, Linux, they're all joined at the hip. Hey, thanks for coming by. Thank you.
Thank you for having me, Sam. Thank you. All right.
And we'll be back in a minute. Hey, everyone. It's Alan Schimmel from Techstrong.
Welcome to our next session in our dynamic series of conversations between the select thought leaders at Microsoft, as well as some of the analysts from the Futurum Group. In this session, we have Tiffini Tracy, VP of Product Management for the Power Platform at Microsoft, and as well as analyst from Futurum Group, Keith Kirkpatrick. This session is titled Agentic Automation.
In this session, Tiffini is going to lead us on a deep dive into the operational realities of agentic automation. It's a world where apps, agents, and chat are converging to reshape enterprise execution. We hope you'll discover how AI empowers everyone, with a special focus on those who need accessibility and disability support.
You're going to learn how business users supervise autonomous agents that execute, escalate, assist, driving inclusive productivity. Expect insights into multi-agent orchestration, human-in-the-loop governance, and chat-led transformation across support and product activation. So another great session.
Here's Tiffini and Keith. Thanks, Alan. I'm Keith Kirkpatrick, research director with the Futurum Group, covering enterprise software and digital workflows.
Today, we're going to be talking about agentic automation and how it is reshaping enterprise execution, where apps, agents, and chat functionalities are converging to assist across workflows, driving external engagement through the delivery of personalized, intelligent experiences and streamlining interactions. And hello, my name is Tiffini Tracy, and I'm the VP of Product Management for the Power Platform Core, which covers our Power Apps, Power Automate, Power Pages, RPA, and Process Mining. I've been with Microsoft for 25 years in a variety of product roles and looking forward to the conversation today.
As we're both aware, we really can't get away from a discussion about today's technology without talking about agentic AI. And I wanted to first start off by asking you about some of the ways in which agentic AI is changing the way customers are engaging with businesses on a day-to-day basis. Yeah.
So I think it's great if we first start with the fact that agentic AI is going to change the way we work, right? We're moving much more into these human-led, agent-operated environments. And some of the big changes that come with that are we're going to move much more from this very task-based focus to a more intent and goal-driven focus, and we're going to move from working in a particular app to really working across apps.
With that, we'll see this synergy of humans that are driving what we're going to do. They're adding business intelligence. They're guiding.
We're going to have agents that really do a lot of the execution work. We're going to have intelligent apps where these agents and humans can dock in to manage everything, and we're still going to have automations like we have today for very deterministic workflows. When we put all of that together, what we get from a customer experience is they're going to get much more personalized and contextually relevant experiences, much faster and with a lot less effort on their part.
And in fact, in many cases, we see that customers or organizations were able to expand the audiences that they can actually serve with this technology. So, a simple example of that might be I'm on a flight, turns out I'm going to miss my connecting flight. Today when I land, I might get a text message that I've missed my connecting flight, but you see very quickly, I'll land, the airlines has already rebooked me with an agent.
They're going to let me know what my new flight is, and then if that doesn't work for me, they're going to give me a human to escalate. That's going to change in these kind of customer experiences. Can you talk to me a little bit about how we're going to see all of this automation, intelligent automation, be managed?
So one of the powers of this agentic transformation is you begin to get intelligence on tap. So you have these different agents that you can leverage for different business functions. A level one agent, I think most of us have probably experienced in this point, and that is AI is maybe we're asking it questions or it's giving us a set of information.
And then you have level two, where the human is actually directing the agent to conduct some sort of task, and then the business rules dictate when the human will get involved in it, maybe just giving the human information so they can make a better decision. And then level three is where you see these agents actually taking action aligned to the business rules, and the human being in the loop aligned to whatever business rules you set. So what you'll find is that the goal of how we're thinking about agentic AI is we want humans to continue to work in the way they do today.
We want them to have a personal assistant that transcends with them throughout their day, whether in their business data, their productivity data, whatever task they're doing. And then they will have intelligent apps that let them manage some of these autonomous agents. But those agents can dock into their personal assistant, they can dock into their agents.
So we really want the humans continue to work the way they do today, that this AI will sort of collaborate seamlessly with them, and that's why you see that using both intelligent apps and kind of Copilot in this chat interface have their place depending on what the human's trying to accomplish. And so we want this all to kind of slot in more seamlessly versus thinking about it as they have to change as much the way they work. Right.
That makes sense. But I guess one thing that I'm particularly curious about is, as we move into this world where we have agents that work alongside of humans, and there are obviously going to be agents that work sort of autonomously, obviously still with a human in the loop to make sure that they don't go off the rails. How do you actually coordinate multiple AI agents across a platform to make sure that the agents do what they're supposed to do when they're supposed to do it?
Yeah, it's an excellent question. It's very inherent in the platform we're building across both Copilot Studio and Power Platform, and of course, some of the pieces in Azure. But it is very straightforward to design for a particular agent, what its rules are, what it's allowed to do, what knowledge it has, what memory it has, what kind of guardrails it needs to follow.
And what we see as customers are moving to these level three agents is they're really thinking through their business processes and chunking those up into reusable components. So maybe, for instance, you interact to gather information from an external company, and you do that for several business processes. You might build a dedicated agent that does that and gathers that information.
That will have a set of business rules that you set for that agent. It will have a set of points where you escalate to a human or where the agent can actually take action. And then that agent may talk to another agent.
Again, you define what that communication is and the business rules. So it's very configurable to what your business policies are, what your risk tolerance is, depending on the impact. The other piece is it's quite straightforward to evolve those business rules.
So maybe, for instance, you start with an agent that makes recommendations on approving insurance claims or approving purchase orders. You might say that when you start, every single one of those has to be validated by a human. Then maybe you say, "Wow, that's going really well.
If it's under such amount, $1,000, the agent can auto-approve. " And then you keep ratcheting that up as you build confidence in the agentic system you've created. And those things are very straightforward to configure and continuing to evolve.
Actually, how does Power Platform help to sort of manage that, as you're talking about multi-agent orchestration across different modalities, whether we're talking about chats, applications, and back-end systems, because that seems like that's going to be a core sort of requirement as organizations, whether they're dealing with regulated industries or not. Absolutely. So when you think about the Power Platform, one, we have a tremendous amount of line of business large scale apps running on the platform today.
And I think it's really important to note for those customers, we are going to bring AI to where they're working today and let them use AI to add even more value to the applications they have today. Then we're introducing new tools for building agents and some of these intelligent apps that will dock the agents in. All of that will still run on the Power Platform managed environments.
So all of the governance that you're used to in the Power Platform will extend to this agentic transformation so that customers have confidence that they are running in a managed environment, that they have the ability to set the policies, to manage it, to audit it, to understand RAI, all of the different components they need. But that will be within the core platform that they have come to trust in managed environments. Now, Tiffini, you just mentioned something that's really interesting, and you've been talking about it throughout our conversation, about the idea of human-in-the-loop governance.
I'm curious, how do you actually embed that into agentic workflows without sort of slowing down automations or creating unnecessary bottlenecks? So human-in-the-loop can be orchestrated at any milestone in the process that makes sense for that process or that business. This is one of the places that we think intelligent Power Apps is going to play a large role.
So you can imagine that I might have 1,000 automations or 1,000 agents that are running, and I have this intelligent app that lets me go through and quickly approve, guide, change, whatever needs to happen to ensure that the human is guiding but not slowing down the process. And I think this is one of the roles we see for intelligent apps as we go forward. What about, the other thing I've heard about is the use of adaptive risk models and how that might help ensure that agents just remain compliant with any kind of regulatory or even business guidelines.
Can you talk to me a little bit about that? So for every agentic solution, the organization really needs to think through a concept we call evals. And those evals are what are letting you know that the quality, the functionality, the reliability is all within your guidelines.
And so it depends on the agentic solution, but you're going to have metrics that tell you the functionality and the reliability. It's going to let you know the quality of the response. If it's a agent that's creating some sort of UX or interface, you're going to have metrics that let you test if that is high quality and functional.
And then, of course, you're going to have evals around responsible AI. And so depending on the solution, one of the first things you want to do as you get started is define for the type of solution you have, what are the areas that will be key, and what are the metrics and tests you want to use? And then there'll be multiple ways to ensure that those metrics are on track.
So we've heard a lot about agentic AI, but one of the things that I hear from talking with companies is that there's still a little bit of fuzziness or confusion around what sets agentic AI apart from sort of the chatbots or assistants that we become accustomed to dealing with in our everyday lives. There's a number of things. One is that an agent, if you give it to them, has memory.
So they can remember previous conversations with you. They can remember previous context. The second is that the agent can learn.
You can continue to train it on knowledge, and it can continue to learn and be more and more helpful as it goes along. It also has not just the initial knowledge that you trained it on, but it has generative AI, which helps it to fill in the knowledge that you've given it. So you can think of it, it has all the power of the orchestration and the LLM, or the large language model, with your specific information on top to personalize it.
All of those are things that chatbots could not do. Chatbots also cannot take action. So chatbot was really, it was great at the time, but it's really more of like a Q&A with very curated answers.
When we get to LLM, it has all of these richer capabilities, and so it's not only quicker to get the information back to the human, but it also can do more of that on its own because of the context, the shared memory, the knowledge, and the fact it can take actions. Well, one of the things I think that agentic AI is really sort of building on is that chat modality where you're able to use natural language to interact with it. Do you see that as being another sort of real selling point for using agentic AI?
Because you are able to, anyone can interact with it. You don't need to program, you don't need to remember specific terms or anything like that. Natural language interfaces are going to have a large role in agentic AI because as humans, that's an interface that we like, we enjoy, and has a much lower barrier for people to participate in.
So I think natural language and being able to type what you want an app to do or what you want an agent to do for you and be able to go create that will absolutely have a large role in that. Again, I think it will depend on the business solution. We also know that humans are more comfortable in sort of like a personal assistant, like a copilot realm, talking back and forth because that's how they interact with their other coworkers.
And so we really want as much as possible to have the humans still work in the way that they're accustomed to working. So they might ping a coworker to ask a question. Now they might ping their personal assistant to ask that question.
There will be places where they'll actually go into an intelligent app because that's the best interface for them. And then they may continue to ask their personal assistant questions about that app. So they will be much quicker to learn about that app and what they're doing.
But the natural language interface is definitely going to play a key role because of the way it lowers the barrier andAnd allows humans to continue to interact with the technology in a way that they're most comfortable. So it sounds like what you're describing is sort of an agent first or assistant first approach to interacting with systems. Is that kind of what we're moving toward?
I would kind of flip it around. I think it's a human first, a human led. I think the human is going to have a personal assistant like Copilot that transcends their day with them, understands their productivity context, their business context, how they like to communicate, how they don't like to communicate.
It's going to be more kind of, I'll call it, connected with the human and their personality. And then I think there's going to be a set of intelligent apps and agents that- Mm-hmm ... dock into those places.
Agents may dock into your apps. Agents may dock into your personal assistant, depending on what they do. All that together will build kind of the new tapestry of how we work and how we move forward.
But I think it's the human at the center with these technologies helping to make them more productive and giving them more time to think strategically, to be creative, and to think about what they can do next. We know from all kinds of studies that 80% of people in organizations say they don't have enough time to do what they want to do, to think about the things they want to think. So we're thinking about how we empower that human and how they now have more time for those strategic creative things.
And then this technology is really helping them along the way. Tiffany, one thing you mentioned is that AI should be for everyone, and I'm curious if you could talk a little bit about how agentic automation can help ensure that people with disabilities aren't just included, but actively empowered as they're working and using enterprise workflows. Yeah.
This is an area I feel extremely passionate about what we've seen so far with particularly Copilot and some of the automations that have been done in Teams and some other places. So, there's lots of different situations that people with disabilities face. You may have someone who has hearing loss, and now with the transcript on a meeting, they can fill in where something wasn't quite clear to them.
You may have someone who has ADHD, who focusing on the meeting and the notes, they feel like they miss out on both fronts. I think that's a human experience across the board. Now with meeting notes and the transcription, you can say 100% focused on the conversation in the meeting and know the rest of that is going to be there for you.
You could flip this over to other environments like schools or education, where the concept of meeting notes can help students take notes in lectures, and they can have it all there so they're focused on their learning in the moment. I mean, a lot of these agentic AI pieces are going to help humans be fully present in the moment and know all this other stuff is there for them to use later, but they're not having to multitask in the moment, and the numbers are showing people see the real impact to that. They feel like the quality of their work is better.
They feel like they are more included. They feel like they have better performance, and they feel like the meaning of their work has actually gone up. We're just seeing the beginning of all the impact that this is going to have for us.
Tiffany, can you give me an example where agentic AI has provided an outsized impact above and beyond what you either might have expected or what we could have previously done? Yes. We see many times that the spark for starting with AI is around efficiency or productivity.
But what we're hearing from customers is they're seeing a number of other vectors of impact. Accessibility and inclusion has been a really strong one, which I'll talk about. Being able to upskill and learn has been another one that's come up quite strongly.
In fact, EY, Ernst & Young, recently did a study where they interviewed over 300 people who had been using Microsoft Copilot, asking them how did it impact their work? All of these 300 people identified as having a disability. Mm-hmm.
And over 75% of them said they felt like Copilot had made them more productive at work. They kind of laid that along three lines. One was removing barriers.
88% said they were doing better communications by using Copilot than they had in the past. They also talked about feeling more included and feeling like the quality of their work had gone up. That was over 85%.
And they also talked about feeling like they were getting more meaning out of their work because of their productivity and the quality. So that is just a tremendous additional benefit that we're seeing from AI, where organizations are able to ensure that every team member is bringing their best selves to work and doing the best role that they can. And I think we will just see more and more of this as we move forward.
Because as Copilot and some of the other AI continues to learn even more and more and becomes more personalized, it can even help in other ways that will be very valuable for people So Tiffany, I was wondering if you could share some examples about how agentic technology is being designed with accessibility in mind. Yeah, so as you know, Microsoft's had a long history of thinking about accessibility features in our products, whether that's been sort of in Xbox and assistive controllers or Office and the many accessibility features we provide there. That same sort of mission is moving into agentic AI.
So we can think about what are the new accessibility features that maybe in the past weren't as feasible that now we can bring to the forefront. Some of them are already out. You think about Teams meetings, Teams transcripts, you think about things like Copilot being able to ask questions across all of your graph data.
As we move forward, we see even new opportunities. For example, the Teams team is thinking about how today in a Teams transcript, you have whatever has been said verbally. Might be another language, might be in English, might be in multiple languages, but it's what was spoken.
In the future, what they want to do is include what was signed in the meeting into the transcript. So everybody has a complete transcript, whether that was spoken or whether that was signed. And that's just one example of the many type of agentic AI features that we feel like is now feasible that we're exploring.
So I was wondering if you could tell me about how agentic automation has really streamlined very personal or sensitive processes and procedures. One of the areas that would be a great example of this might be human onboarding. So we each come to a new role or a new set of work with various backgrounds, with strengths in places, things we know nothing about, and agentic AI can really personalize helping that human onboard in a way that they feel completely comfortable.
They can ask many questions, they can get access to many resources, they can get recommendations and guidance that will help them learn at a much quicker pace. But not something, whereas in the past, they would've had to share very broadly with their new team that they didn't understand a concept or they didn't have this experience, or maybe it's very difficult in a large conference room to hear the voices. And so agentic AI has the opportunity to really help speed up that onboarding, personalize that onboarding, and do it in a way that is really taking the human into account and helping them do that in the best way possible, in a way that's sensitive to things and very positive and productive.
Thank you very much, Tiffany, for a great conversation and real insight into the world of agentic technology. Thank you, Keith. I really enjoyed our conversation today.
It's always fun to talk about the transformation that's ahead of us and how agentic AI is going to help all of us move forward. Today, we heard a lot about agents, and I think some of the things that really resonated with me was the fact that ultimately, to have success, you need to start with humans, looking at processes and goals, and then bring in the technology. Now, of course, there's a need for platforms that can really provide an orchestrated agent experience across intelligent apps, agents, and of course, all of the workflows that are integral to really driving real business benefits.
And ultimately, the other thing that really, really sort of resonated for me is the ability of agentic technology to improve the experience of people who may have disabilities, and to do it in a way that really takes into account how they're feeling, and not really kind of separating them from the rest of the employee base or other customers, but to do it in a way that's empathetic and, again, can really drive outcomes. Hey, everyone. Welcome back to our "Platform Engineering" show.
I got to be... Well, you probably already know this, but we've been on a bit of a hiatus lately because my friend Luca here, well, life jumped up and got him, so he's been experiencing life as a daddy, and we've just been missing each other, as often happens with newborns in the house. But I'm glad to have him back here today.
Luca, how are you? I'm great, and it's great to be back. Yep.
Well, it's great to be a dad, too, though. org community, doing a lot of different things. Actually, we're going to talk.
Why don't we start there, Luca? Yeah. What's new with the community?
org? I know we're coming up near Platform Con time frames. Give us a report.
Yeah, there's a few things. There's a few things. So one is, we announced a world tour for Platform Con.
So we basically have our flagship week, which is the event that people are normally familiar with. It's the end of June, last week of June. And it basically is a hybrid of virtual...
talks, virtual workshops. We have about 40,000, 50,000 people that connect virtually throughout the week. And there's panels and there's virtual roundtables, virtual workshops, all sorts of stuff, and it's all for free.
And then we have two live days, one in London, one in New York, on the Tuesday and the Thursday, and you're going to be at the New York one on Thursday. Yes. And those are where we have about 1,000 people, give or take, in each location, coming together in person.
We have incredible locations in both cities, so that's going to be really fun. And what we decided to do is essentially replicate that model of just the live day format of London and New York and bring it as a standalone to other regions around the world, because there's platform engineers everywhere, not just in London and New York. And so we're bringing it now in the second part of the year to Paris, which we already did last year.
Went really, really well. As well as also Sao Paulo and Sydney. And so we're really excited about that.
And maybe there are some more cities that we're going to announce that's in the works. But for now, this is the world tour that we announced, and we're really excited about it. I love it.
I'd love to go to Sydney, too. It's one of my favorite cities. We'll talk offline more, too.
Singapore is a place to do it, too. Singapore- Singapore is a- Also- ... tech hub ...
also what happened is already one of the local communities reached out from Auckland, so platform engineers meetup in Auckland. Well, if you're already in Sydney, yeah, jump into Auckland- Exactly ... is an easy.
So that's what we're going to do. So the week before, we're doing a thing there. And you were mentioning Melbourne, too, the last time, so maybe we should just- Yeah, Melbourne.
Well, Melbourne is the... No offense to Sydney, I love Sydney, but Melbourne's the tech hub there. Yeah.
Right. Exactly. Great.
So like to your point, once you're there, you might as well. Yep. Right, so.
Excellent. And so any information about the June Platform cons in terms of keynote speakers or anything like that, or it's too early? Yeah.
So no, we already have a good bunch confirmed. We have the usual, like Kelsey Hightower is going to be in the New York event. We're going to have Gregor Hohpe, we're going to have Nikki Watt, we're going to have Caroline Wong as well.
Oh, very cool. Yeah. I think the interesting thing is we talked on the podcast before about platform engineering really becoming increasingly the operating model for the modern enterprise and moving beyond just the traditional infra and DevX focus into security, observability, obviously data, obviously AI.
And so this is, I think, what also PlatformCon is coming to represent more and more is not just the focus on application developers and DevX, but really, like, okay, how do we interface with security teams? How do we think about policy and governance as a code? And that's where Caroline and a few other speakers are coming in to really give other perspectives from sort of all these adjacent verticals.
Because increasingly, what we are seeing at PlatformCon is enterprise teams coming increasingly as a team, as an org, right? Like 15, 20 people coming from the same company to really, A, figure out what's the lay of the land in platform engineering and talking to the vendors, figuring out what's the new tools, what's the stack, how's it evolving? But then also really to get this kind of interdisciplinary understanding of how do I think about this complex org transformation that is platform engineering across these different perspectives.
And that's one of the main focus in terms of the content program that we wanted to have. It's funny, I know Caroline Wong, Luka. 10 years- Yeah ...
maybe more, 12 years. She's great, right? She's amazing.
Yeah. She's an amazing woman. First time I had her speak at our DevSecOps event at RSA, I think she was like eight and a half months pregnant.
Wow. And here comes Caroline. No, I'm not making fun, but she's basically waddling down the aisle to get up on stage.
I was so afraid she was going to go into labor right while we were doing this, right? And she delivered a killer session, and she's spoken at so many of our events, and she's become a personal friend. Now, she actually has a new book out.
Mm. And it's sold out. It was one of the few books that sold out at RSA this year, on AI security.
Mm. And how to do AI security. And Luka- Was that the main topic at RSA?
The main topic at RSA this year was agentic. Right. Agentic AI, securing it, using it, what to do about it.
It's changing our world. Yeah. And I spoke to Caroline.
Actually, Caroline spoke at our event again this year- Yeah ... at RSA, and I spoke to her off camera. I had a chance to catch up.
Yeah. Sam said it was a super fun session. Yeah.
She's great. But we had some good... We had Guy Po.
Guy Po really from the AI- Yeah ... native Dev community. Yep.
His session was amazing as well. Yeah. But it was tough this year because they made some changes to RSA, and our room was up on the third floor, and they had sandbox under us, and it was hard, and they gaped...
I usually get about 50% security people, 50% DevX, DevOps. Right. But they did away with the free expo pass, so you had to pay.
Mm. I don't remember what it was, $150 or $175. So it used to be free, the expo?
Right. Well, it was a $50 fee, but they gave away codes- Okay ... that you could get it for free.
Right. I had unlimited free codes. Right.
So that's how we would bring the DevOps community in, because a lot of them wouldn't stay the rest of the week. Yeah. You know what I mean?
For sure. They were there for that. But that being said, certainly agentic AI was the theme in all of its flavors.
But what's happened since then, Luka, and I'm sure Carolyn's going to talk about this, this Claude Mythos- Mm-hmm ... announcement came out, and then just yesterday, we're recording this on Wednesday, 8th of April. Yesterday, Claude announced a, what do they call, Project Glasswing or something like this.
Mm-hmm. Basically, they're making Mythos available to 40 companies only. Some of the companies are their competitors, including Google and so forth.
And the reason they're doing this is basically Claude Mythos breaks every piece of software on the planet. Right. Yeah.
Right? It has found critical, not just nonsense nuisance bugs, it has found critical vulnerabilities in virtually every operating system, every browser, just about every piece of software they've aimed it at. And the fear is, not only does it find these vulnerabilities, but you could weaponize them using the tool.
Yeah. This is Defcon Level 1- Yeah ... for the security world.
Yeah. Some of my best friends, Rich Mogull, Gadi Evron, people I really, really respect in security are ringing the bells that if this... And it's going to get out.
You know what it is. Sure. Right.
I mean, it's already out. This is like Jurassic Park, right? Yeah.
Life will find a way. It's going to get out. Yeah.
And when it gets in the wrong hands, all hell's going to break loose. And I think that's why at the platform level- Yeah ... we have got to be building resiliency, capital R resiliency, man.
Capitals all the way through. Yeah. Because it's going to happen.
There's going to be vulnerabilities, there's going to be exploits, there's going to be repercussions, right? And we've got to be able to kind of roll with the punches and recover here and keep the lights on and the wheels moving. Yeah.
And I think that has to be, if it's not already, but having Carolyn there is going to, I think, spearhead that, but that has to be a major focus of platform engineers- Major ... for the next foreseeable future. You were already saying I was at KubeCon in Amsterdam, and we had actually this really interesting series of conversations, actually.
One was a round table that we did together with Chainguard, and then we did another one with Claude Smith, right? And so there was again, obviously they're looking at vulnerabilities. We talked a lot about security, and it was super interesting conversation.
And one of the guys was this very brash, he kept interrupting other people, which actually makes for, I think, a fun conversation. " Right? In an agentic AI first world, what else?
And I think he said it in that very direct way, right, and I disagreed that it's just about that, but to your point, it's mostly about that, I think at this point, right? It's going to have to be because everything else is broken otherwise. Yeah.
And if you don't, that's the table stakes, right? If you don't get your security in order, if you don't have governance, then everything else, nice DevX, nice whatever, it's all nice to have, right? And so I think this is the interesting thing, which in a way is very fascinating to me because we've been talking about platform engineering.
We've done platform engineering for the last whatever years. But I think nobody would've predicted, right, that you'd have this, obviously this huge AI spike, but then that essentially would mean that platform engineers all of a sudden are one of the most essential roles, right? Well, but this is the same thing that happened in DevOps.
Mm-hmm. DevOps became DevSecOps. Right.
For all intents and purposes, every DevOps company was a DevSecOps company because security eats its young. Yeah. You know what I mean?
Security just becomes that critical to it. In addition to the Monday event that I think Sam was at, on Thursday, I did my talk. I do a talk every year at RSA, right?
And Thursday was my session. Thursday morning, I did it with my friend Mitch Ashley. Mm-hmm.
Mitch from Futuro. From Futuro. This was even before the Claude Mythos announcement, but it was really what is fundamentally changed in the dev life cycle here, right?
And with platforms and everything else. Our whole... The world I grew up in, the world that you've come up in, Luka, was based on humans can generate X amount of lines of code an hour, a day, a week, whatever.
That code, if we use things like platform engineering and DevOps and Agile, that code makes its way into the pipeline, and we can test it, we can do all these things and move towards deployment, right? And then managing it after deployment. Part of that food chain was that humans develop X amount of lines of code, and security can scan X amount of lines of code.
So there was a balance, right? There was this balance. It was a break on the system, if you will.
We just couldn't generate more code than we generated. Mm-hmm. And so we only had to test that amount of code.
And then from the test, and that's what the whole AppSec, like Carolyn Wong is huge AppSec. The whole AppSec world, Luka, was built on humans using tools like Metasploit and stuff like that, using scanners to scan code for vulnerabilities. Yeah.
That's it. Well, now what happened is that break has become a flywheel. AI allows us to make as much code as we want.
We could write as much code. You could build anything, right? I think platform engineering, as much as we've talked about automation and being able to remove friction, I don't know if we really thought it all the way through to this extreme where- Yeah ...
AI, where code's liquid, code is- It's free, yeah ... infinite. Yeah.
It's free. Yeah. But now what we've seen with tools like, Claude Opus and some of the scanners, you know what?
Finding vulnerabilities is free, too. Yeah. We could find as many vulnerabilities.
Well, but then, you know what? I find interesting, right? Also, I appreciate how good they are at marketing, right, Anthropic, right?
Because they are really good at combining this fear element and sensationalist with-- And sync it with their product launches. You can go back and see every Dario appearance on CNBC or whatever, where he's like, "Alarm bells," blah, blah, blah. It was always two weeks before a product launch that then would address that thing.
So they're definitely playing the game because-- We'll see what happens with Mythos, right? But I think what's interesting is they released this, I think less than a week, 10 days after they had this huge f****p of actually- Well, no. So there were two f*****s.
Right. First, Mythos was pre-announced before they were ready to announce. Right.
And then a few days after that, this code leak came out. Now I'm going to tell you something, my opinion, they were both staged. Oh, okay.
I don't think either one of them were real. I think both of them were staged to ratchet up, put pressure on OpenAI, put pressure on the market, and maybe to grab attention. But what we're talking about here is the vulnerability apocalypse, right?
Gadi Evron, he had a great-- Gadi and a bunch of friends did a conference in Vegas. I think it was called Unprompted, a couple of weeks before RSA. They nailed this.
Gadi and a woman from Google called this shot six months ago. Nice. " Yeah.
We're not automated enough. Well, the focus is no longer on finding these vulnerabilities. The focus is on governance.
Yeah. The focus has to be on resilience. The focus has to be on prioritizing what we need to fix and what we don't need to fix.
And I know where you're going with Anthropic, but let me tell you another thing that came out yesterday. No, just leave alone the Anthropic thing, right? But I think it's whether they're staged or no.
I think what we're seeing, just to make your point, is that there is this, not only the models are getting better and better at going back and finding vulnerabilities, but we're generating new vulnerabilities at a much higher rate because they're- Well, we're not. You don't think? We're not generating vulnerabilities at a higher rate, right?
So here's the deal. If you look at human-generated code, the amount of vulnerabilities per 100 lines of code, it's been constant for years. Right.
There's X amount of vulnerabilities per 100 lines of code. Code generated by AI-It started up here way more vulnerabilities per 100 lines than human. Right.
But sometime around October, that line started coming down, and sometime around January or end of February, it kind of drew even. Yeah. And now it's below.
Sure. But we're releasing 100X more code. That's it, bro.
Exactly. Yeah. So it's not the rate of vulnerabilities- Yeah.
More vulnerabilities ... it's the amount of- Yeah ... that's the apocalypse.
Right. Exactly. When you've got 100X more code with theoretically- Yeah ...
you're going to have 100X more vulnerabilities with the ability to find 100 and scan and find- Right ... all those vulnerabilities. All of those things just break- Yeah ...
they break the system. Yeah. And there's another point I want to throw out at you.
I don't know, did you see the OpenAI announcement yesterday? Which one? So OpenAI- Because there's one every day.
Yeah, no. So this is not purely security-related. Uh-huh.
But OpenAI released a paper about, they're calling it the AI New Deal. Oh, yeah. And- I saw that, but I haven't read it.
No. So what is it about? And he did...
What's his name? Sam Altman did an interview with Axios on it. Yeah?
Basically, he didn't come out and say super intelligence or AGI, but he said the newest models in the industry, not just theirs, meaning anthropic, there's a lot of models out there now, are on the cusp within not a year, not three years from now, within months, of basically breaking capitalism, right? Right. Look, so here in the US, we had what we call the Age of the Robber Barons.
Mm-hmm. When the Industrial Revolution, Andrew Carnegie owned the steel market. John D.
Rockefeller owned the oil market. The Vanderbilts owned shipping and railroads. JP Morgan owned Wall Street, banking- Right ...
finance. The wealth of the US, and it wasn't the US that it is now, but it was still a wealthy nation, was concentrated in the hands of 25, 50 families. Yeah.
Right? And it was good and bad. We had tremendous growth.
But these people at the top, your typical oligarchy, and Italy went through a similar thing, I think, under Mussolini and a lot of these things, the oligarchs. It took major legislation and change, and it took us 40 years in the US, because the Great Depression came out of this, right? And it wasn't until FDR came in, Franklin Roosevelt came in before World War II, right before, and did what they call the New Deal.
Right. Things like Social Security and the safety net and antitrust, and broke up the robber barons. " Because if you own the AI, you own it, and- Right ...
a lot of people aren't going to be able to have jobs. Yeah. And so how we- There was this interview with Elon on the- Elon Musk has a similar view on this.
Yeah, where he was like they were asking him, he went on this Stripe Guy podcast, and there's this three and a half hours conversation where they kept at different points of the conversation, pressuring him on like, okay, but is it actually sustainable? Because we're putting so much money into... He's famously built Colossus 1 and 2, this- Yeah ...
huge data centers and so on. " Right? And it's like he's like- And that's- You know?
He was like, "Look at the- That's the truth ... at the call center industries," right? That's, I don't know, 100 billion or whatever it is, right, per year.
" In a heartbeat. In a heartbeat. Yeah.
So it's like, yeah, it's a crazy time, man. It's a crazy time. This is it.
So when you look at all these signals, now, but what does that mean for platform engineers? What does that mean for security people? What does it mean for the just regular people out there?
It's not a time to be afraid, though I think fear is healthy. Mm-hmm. It's a time, I think it's also a tremendous time of opportunity, right?
Yeah. There's going to be opportunity here. There's going to be- Huge ...
wealth created- Huge ... and great things to do. But you've got to go seize it.
You've got to figure out, what does my platform look like in a world- Yeah ... where there's 100X more code, 100X more vulnerabilities, and 100X more users of the platform? Yeah.
Right? Oh, sure. Oh, no, this isn't just about IT.
Yeah. This is the world changing. The way you think about anything needs to be like a system thinking that starts with a platform.
What's my platform? What's my governance? Because then code is free, but media is free, right?
Anything that we've done on these screens basically- Is free ... is terminally free, right? And so, it's like, yeah, what are the constraints that you put around that to build some sort of an advantage?
But I agree with you. I think at the end of the day, we've seen it before. We've seen it with the internet, we've seen it with mobile, blah, blah, right?
You've had an enormous amount of new millionaires that were minted out of- Yeah ... whatever. There will be wealth created- Like super apps, right?
but there's always disruption. We've already seen the first one-person billion-dollar company, right? This guy that was- Yeah ...
selling GLPs or something, and- Uh-huh ... a bunch of agents. Crazy.
But yeah, so obviously that's happening. You and I also work a lot also with large enterprises. Those are the ones that are interested in platform engineering, security, and so on.
I'm really interested in that aspect as well, right? So what happens to the enterprise? Because, obviously you're going to have all this net new wealth creation that we're talking about can happen with a way more reduced amount of people, right?
You don't need to scale up to 100,000. Look what Oracle... Did you see what Oracle did this week?
Yeah, they just fired 30,000 people, right? 3,000? No, like 30.
30. Yeah, 30. Basically, they laid off, I know, I forgot what it was, 12%, 15% of their workforce.
Yeah. And not because they're replacing them with AI. They just wanted to take that money to build out more AI data center, more AI infrastructure that they can then sell customers onto.
Yeah. So think about that. You're an enterprise.
You've got, I don't know, 250,000, 300,000 employees. That's a crazy amount of employees. Yeah.
You fire 10% of them, 30,000. You don't think that affects your business, your ability to deliver, your ability to innovate, your ability to be resilient? Do we have that much fat?
I think so. I think so still. And this is still hungover from ZIRP era, right?
If you look at the people that actually took the medicine in the last three to five years, and some of the tech companies have. Meta has done big restructurings. Amazon has done big restructurings.
Twitter famously, Elon came in and fired 80% of people. The company still worked, right? And then you got to ask yourself, it's like, okay, well, if you then move down, I think, the ladder of fast movers, right, and you go to the slower movers, and you go to companies like, I don't know, whatever, name your favorite enterprise, right?
Then have they done the RIFs? Have they taken the medicine? I don't think so.
Not as much. Also, to be fair, they hadn't built up as much fat as- They didn't hire like drunken sailors during COVID either, right? Exactly.
There is some of that. But then you have this AI thing coming, and it's like, okay, well, where are you? And that to me is really the interesting question, right?
Because I think even if I look at my personal experience, selling, for example, into platform engineering teams, right, when we're developing a tool, you'd have all these weird political conversations that essentially where you could never say a tool is replacing a human. You know what I mean? It's like- Yeah ...
it was a taboo thing to say, right? It was like, oh- Right. But today it's not ...
but it was true. And now it's like all of a sudden, you see this cultural shift where people are like, "Okay, well, this is just happening. " And so that to me is the interesting inflection point in how I think enterprises are going to think about- Society ...
buying software. It's beyond enterprise. It's how society looks at the value of a human worker.
As well. Yeah. But, in some ways, right, it's like be careful what you wish for.
Because when we started talking about platform engineering and building these platforms, right, we wanted to set up platforms that would allow us to go faster, allow us to automate more, right? And so now we see it coming through, right? Right.
And so in many ways what we're seeing is the culmination, if you will, or the coming true of our wildest sort of dreams or fantasies about being able to scale these things. Because now we're talking scale, right? Now we're talking scale.
Yeah. It's no longer human hands. It's wild.
But that's going to be, I think, our main message, going back to the community and PlatformCon, that's going to be the main thing, right? It's like, hey, it's exactly what you said. It's like be careful what you wish for, right?
Because now my friends sitting in the audience at PlatformCon, you're going to be the ones that need to figure this whole thing out. Someone's got to. Yeah.
Hey, man. So it's the week of, I think, June 25th, right? It's that Tuesday and Thursday are in person.
Monday to Thursday is online. Yeah. So Monday to Friday is the virtual event, and then Tuesday we are in London, on the 23rd and 25th of June we are in New York.
Perfect. Yes. com for more info.
Yes. I love it. Hey, Luca, I'm going to let you go take care of your little son there.
I got to get on. I got to go do more interviews, more tech strong TV. Awesome.
It's great seeing you. I hope to see you- Yeah, you too ... in person soon.
Well, I'll see you. I'll see you in Sicily in two... Well, no, we'll see- Couple weeks ...
each other before that. Yeah. Okay.
Sounds good, man. I'll be in touch. Sounds good.
All right. org. " We'll be back with another show soon.
Until then, though, we're out.