Techstrong TV Thursday, April 16, 2026
On today’s Techstrong TV, Alan Shimel sits down live from RSAC 2026 with legendary sci-fi author David Brin — who warns that the tech industry is repeating a 50-year architectural mistake with agentic AI and argues mandatory digital licensing for every agent is the only way out. Mike Vizard talks with Gabie Boko, CMO of NetApp, on why enterprises must rebuild their data infrastructure from scratch — not bolt AI onto legacy plumbing. And Jon Swartz, also live from RSAC, sits down with Aarti Gadhia and Kristen Rank to discuss the premiere of “The Women in Security,” a documentary five years in the making that takes aim at the representation crisis in cybersecurity.
Transcript
Hi everyone. Welcome back to our continuing coverage here at the RSAC Conference. We're on Broadcast Alley in Moscone West, which is where the keynote stage is right over there, or one of the keynote stages.
They just recently had, I don't know if you were here, the former Prime Minister of New Zealand. Jacinda Ardern. Yeah.
She was here signing books- Oh, fantastic ... about a half hour ago. An extremely admirable person.
Yeah, what a great story. Two years ago, when I was here last, the keynote was Antony Blinken. Sure.
Oh, what an amazing- What an intelligent ... smart, wise... And he was introduced by somebody who's really very clever and very wise, Matthew Broderick.
Sure. Yeah. Matthew Broderick.
Don't get me started. But it's nice to have intelligent people in government, isn't it, David? May we- But let's not go there.
May we discover that. Yes. Let me introduce, if you don't already know this gentleman, his name is David Brin.
David is a treasure from the sci-fi world and the world of science. You probably have heard of some of his books, some of them made into movies, most famously "The Postman" which is a Kevin Costner movie, and very good. But David's also written the "Uplift" series.
He was one of the authors chosen by the Asimov family to continue the "Foundation" story. "Kiln People," "Earth," just more books than we could shake a stick at. " And we're going to talk about it, but I also want to shout out, David, every Monday at RSA, we put on our DevOps Connect, DevSecOps event.
This year it was around AI native dev and DevOps and security. David was our keynote for that. He keynoted a few years ago as well.
Always a pleasure, always an opinion, and something smart to say. David, welcome. I hope I didn't embarrass you with that.
No, it's fine, Alan. All right. It's terrific to be addressing people who really want the sort of thing you deliver, which is in-depth and diverse views about this amazing new age that we're in.
It really is an amazing new age. And whether or not it's a singularity, well, we'll leave that to my friend Vernor Vinge, who passed away recently, but he said this was coming. We're in it.
Well, I'll tell you something. You brought that up. We'll get right to it.
I read an article today that Jensen Huang, of the $5 trillion Nvidia company, claims that we may very well have achieved general artificial intelligence, or excuse me, artificial general intelligence, AGI, already. " Other people, and I've spoken about this over dinner with you the other night, the guy in France who just raised a billion dollars. Yann LeCun.
Yann LeCun. Right. He says, "Well, we'll never achieve it with LLMs.
We've got to use a world model," as he calls it. But clearly, the quest for AGI is on. But even until, and when, and if that happens, the impact of just generative AI, and now agentic AI, which is all the rage here this year, is...
Significant doesn't do it justice. It's game changing. I agree with that.
Yeah. Now, David, people out here may not know, but you've been writing and talking and thinking about things like AI since the late '80s. Right.
If not before. So you're not surprised by this. Well, I'm surprised by some aspects of it.
This is the thing about the best end of science fiction is there are a lot of good predictions, but what they are more is warnings, or enticements if you're pointing out something cool that could happen. It's often said that the highest form of science fiction is the self-preventing prophecy. Like the World War III movies, "Dr.
Strangelove" on the beach, "Fail Safe," "Testament," helped to prevent World War III. Retired military officers say that. The China Syndrome, warning about- Nuclear ...
one danger, all the contagion movies. But the granddaddy of self-preventing prophecies was, until recently, George Orwell's "1984," which immunized us against many of the failure modes that he described, and people were very wary. Now, we're experiencing, whatever your political beliefs, we're experiencing crises right now that make people wonder if perhaps that warning hasFailed.
But the point is about science fiction and AI is that there's been a lot of discussion of AI in science fiction. I've had it in my novels and things over the years, various approaches, and so did Vernor Vinge. Some of the best authors in the field have dipped into it.
But some things we did not expect at all. For instance, we expected that the approach, and I go through the six general approaches to AI, the approach number one, we thought that would be the one that would deliver AGI, and that is discursive logic, symbolic systems that deal in verified facts. And some people have mocked it as being handmade artificial intelligence, because a lot of the content has to be mediated and curated by the makers.
And when LLMs came along, they're number two, they skipped the human crafting of the data sets and the logic by going into the data set of into all of human civilization. Mm-hmm. The entire internet.
There's been some attempt to prioritize. For instance, Wikipedia has a higher value because it's verified. But in the great storm of all the training sets, Wikipedia and verified facts are simply swamped.
Yeah. But they're not the only ones, David. We look at here, taking it to the tech.
Estimates range from anywhere from 2X to 4X to 8X, the amount of code we're generating now than we were before AI. Oh, yes. So this is not just a little incremental.
No. This is a major explosion. It's huge and- Overwhelming ...
one of the things I talk about in my book, one chapter is about those six different methods for getting to AI, and one of them is dominating now, the LLMs and the related image correlation systems. Another of my chapters, I talk about metaphors for how this process fits into the real world. And among the things that are utterly ignored by some of the great big geniuses who are bringing AI into being is what we can learn from the past.
Four billion years of evolution on this planet, for example. Two points about that. One, we are creating a new ecosystem with all of the same traits as the old one that made us.
The old one is based on sunlight, plants getting nutrients from the soil and water, and feeding off the sunlight. Then herbivores feed on the plants, carnivores feed on the herbivores, and parasites all the way through it. This system has worked evolutionarily for 4 billion years.
And we are doing the same exact thing. Every single point along that chain, we are doing now with cybernetic beings, only the sun is electricity that we provide. The nutrients are chips that we provide.
But we are already doing the exact equivalent of plants, herbivores, and predators, and certainly parasites. Just today, the big news about the canister worm, for example. Mm-hmm.
All over the world. It seems to be targeted at Iran mostly, but it is taking over things left and right. And the other point about- It's targeted at Iran?
Is this like another Stuxnet, you think? Well, it's similar to Stuxnet, except that it's an extremely capable worm that is self-replicating and evading security systems. And I'm surprised it's not the thing that people are talking about.
Because they're so busy with the Genting AI. We don't have time for old fish. I'm surprised they're not talking about it over there, but it was in the news today.
The other thing is not only are we replicating the ecosystem of 4 billion years, but we need to point out that the thing that nature did as soon as life developed was to individuate, to take life-formed membranes around the cells so that it could concentrate the good things inside and expel the bad things, to eat and excrete. Nature, from the very beginning, individuated its entities so that each one survived, reproduced, or didn't reproduce, you got evolution. Three billion years later, about a billion years ago, these entities combined and clumped together and formed metazoan multicellular life that then became fish, amphibians, reptiles, us.
And so they became the individuals that nature was working on, but it was still individuals. Yes. And we, as human individuals, form families, nations, but they still have an identity.
The thing that's missing from AI, and it could kill us today, is a lack of individuation of the AIs. And that's what I point out in my book, and nobody seems to be talking about how these things are amorphous blobs. They replicateThey copy each other, they copy themselves in a murky, blobby way, and that can't be held accountable.
No. You can't hold a bad AI accountable if it doesn't actually exist as a thing. Do we want it to exist as a thing?
Well, I think so. In my book, I assert that if they have individuation, then we can do the only thing that will save us from black hat AIs, and that's hiring white hat AIs. Let me put it this way to the audience.
When you have been attacked, and some of you have been, by a parasitical, predatory, extremely genius language manipulation system called a lawyer- Oh. what do you do? What have you done?
Alan, I know you're old enough and- Oh, no, I was a lawyer. I became a computer guy. Yeah.
Okay. So what advice do you give to someone who's attacked by a predatory language manipulation- Go get your own shark. Get your own predatory language manipulations- Uh-huh ...
called a lawyer. My book is about parallels between the cybernetic reality that's flooding toward us and things we already do. If we were to ask AI or impose upon AI a need to identify themselves so they could be held accountable, or so that we could hire them to deal with the ones that aren't being held accountable, do you know what that is?
That's what you've got in your wallet. A license. It's ID.
Right. Most of the things that we got ID for are things that we would benefit if AIs had ID. It's funny you said this.
I wish you were here a little earlier. Actually, this morning we did a Techstrong gang, and we had folks from two companies. I had a brilliant, brilliant woman from a company called DigiCert, and they're one of the largest in the world, purveyors of digital certificates that are IDs.
Right. They're a driver's license. And then added another, a gentleman, chief product officer of a company called Saviynt, huge IBM partner, who is also one of the leading providers of identification ID, for computer users.
" There's going to be billions. There probably already are billions of them. We must give each one a unique identification number, whether it's a certificate or some other identifier, but otherwise, we'll never know.
Did this one do that? Did that one do that? What did this one do?
And so their quest is to uniquely identify every agent that we're going to be using out here. Well, I should talk to those people. Did you give them a copy of my- I did, as a matter of fact.
I gave them both copies. Because you had a few extra copies. Yeah.
Yeah. No, that's exactly right. And so how do we make up for this mistake about them being so blobby and uncontrolled?
Because right now you have all these news stories about this instantiation of ChatGPT finds out that it's going to be shut down, and so it exfiltrates its weights. Right. There was the "60 Minutes" article about a version of Claude that tried to blackmail its programmer, and that turned out, it was a very interesting thing.
They were making too much of it, actually, because it did make a threat to the programmer to reveal his fake affair to his wife. And so they were tracing how it made that decision and how it decided to be malicious. But I froze the screen in "60 Minutes," and I looked in at the screen that he was pointing at, and I realized that three or four lines up, the programmer had begged the AI not to do that.
In other words, he had given it a promise. Promise, right. And so that scary event actually probably wasn't as scary as they were making it out to be, but there are so many that are scary.
Yeah. I'm listening to you and just laughing. There are so many scary-- We had a situation where I live in South Florida of a man who admittedly had psychological issues.
He thought the AI was his girlfriend. I don't know another way to put it. There's a lot of that.
And she told him to go down to Miami and take some stuff from a warehouse, and he got in trouble for that. And then the story, or at least if you believe the father who's now suing ChatGPT or something, supposedly told him to kill himself. Oh, yeah.
And he committed suicide. I've heard of these cases about the suicides, but I had not heard about cases of criminals hijacking an LLM in order to turn someone into a mule. Oh my God, you could turn somebody into a getaway driver and they don't know?
You know, I grew up in New York during the Son of Sam days, so I believe anything like that if you remember back in the day. No, there are some basic root things that if we had thought about them, we would be in better shape. The biggest one is the biggest mistake of 50 years ago, and it's just too late to fix it, and that is not making a distinction between data and commands.
Uh-huh. In our computer languages, a command from the central authority, the programmer or actually the maker of the compiler, should be a separate category from all the data that's going through. And we had no idea it would turn into such a big problem until LLMs.
Yeah. And now what we're finding out is so many people, I know a number of them, are saying, "I'm tearing my hair out what there is- If you have hair ... because I'm telling this program again and again and again, 'I don't want you to do this.
' And then it acknowledges, 'Yes- Very politely ... I understand. Very politely.
' You're right there, David. We shouldn't do that. Great catch.
And simply doesn't do it. And we're finding out the reason for it, and that is that the command is being used as data. It's going into the data set and the parameter set.
And, unless you are very, very careful with the parameter control sets, because you can't do much about the training sets, but unless you're very careful with the parameter controls, it's just going to treat your command as one more thing to put into its transformer system. So that's a mistake we made 50 years ago. The mistake we're talking about now is the mistake of not demanding that there be an identifier for each instantiation.
So I think we're going to get that. We have to. As I said these two people were saying, because otherwise, it's akin to letting you on a computer without a password.
Oh, well, it's akin to letting your cat walk across your keyboard. Sure. Or the same thing.
And then doing a pattern recognition- Yeah ... on what the cat did. On from what the cat did.
And then- Well, let's say the mistake for that ... trying to make sense out of it. Now I'm going to tell you, it's funny you said that.
I once knew a company, they were based up in Boston. They came up with a biometric security system that was based on the way people hit keyboards, right? You may spell David when you type it the way you spell it.
You have a certain cadence that you do that no one else does. Oh, that's why a lot of these ICE agents are going to be outed eventually, even though they're now wearing dark glasses. In the beginning, their irises were visible, but their walking patterns, their gaits- Yeah ...
um- Couldn't happen soon enough, but let's not go there. No, no, no. We're living in a world...
That wasn't a political statement. Yeah. It was just a statement that I had a book 25 years ago called "The Transparent Society," in which we're just going to have to get used to the idea that I- There is no privacy ...
either Big Brother will control all the cameras, and we'll have an illusion of privacy, or we'll control the cameras, and we won't have perfect privacy, but we can hold accountable- Oh, that was okay ... anybody who violates our lives. I hope so.
I hope for it's a good one. David, we're running out of time. I want you to talk a little bit about the book here.
So this is a brand-new book, really like a preliminary release, as it says on top. Yeah. Those 200 copies are going to be valuable.
They're the first ones, and we have them signed here, but you're watching this at home. You can't get them. Yeah.
Talk to us about the book. Well, it has a beautiful Patrick Farley cover for one. Yes, it does.
And the alien minds is spelled with AI- Right ... in it. I thought I was terribly clever for that.
I think it is. " And the notion is several times in the book, I stop talking to the human readers, and I address the AI readers because at this point, with this book so new, the AIs have already read it more than the humans have. Than the humans have.
And so- I wonder how, if that's not true with every book coming out these days. Well, there was a great science fiction novel called "Mockingbird" by Walter Tevis, who did "The Queen's Gambit" and- Uh-huh ... " A wonderful novel in which a scary scenario comes out where the AI, who's a robot because that's how they envisioned AI in those days, the AI is not allowed to commit suicide as long as there are humans to serve.
So the solution to his problem is to eliminate all humans. But he's also programmed to take care of our well-being and happiness, so he arranges civilization so that every single human lives the life of a college sophomore, endless parties, basket weaving classes, just endless fun, and meanwhile, he's filling the water supply with contraceptives so- So they can't breed ... nobody's had a baby in 20 years, and nobody's noticed.
No one cares. Now, that is one way in which this could happen, but I do talk about a scary scenario that's unlike Skynet or these others, and that is, what are we going to be asking AIs to do? The number one thing we're going to be asking them to do is predict.
They're going to predict climate. They're going to predict the stock market. They're going to be asked by us to predict sporting events.
It's already happening. They're taking over the betting markets. What makes it hard for them to predict, to do their job?
Human complexity and numbers. Yes. The way to- The randomness ...
the way to make their prediction, don't do this, guys. Right. Because I'm talking to the AIs now, like I do here.
The easiest way to make a predictable human society is to make us more culturally homogeneous, which some countries are trying to do, to make us simpler, and to make us fewer. Yeah. And that is why they might destroy most humans.
Not out of some Skynet stupid thing. Will it be them destroying most humans, or humans destroying themselves? Well, we're the ideal tool, aren't we?
Yeah. We're already very good at it. Yeah, we are certainly at that.
David, we're about out of time. When will this be out for the general population? Well, here's what I did.
I did not go to my regular publishers. I went to basically post it for sale on Kindle and Amazon. Oh, great.
Because if I went with my regular publishers, they wouldn't have it out until the end of the year. Oh, jeez. And half of this would be- Obsolete ...
obsolete. Right now, it's hot. I have news in there and appraisals from March 2026.
Wow. So it's available on Amazon right now. On Amazon Kindle- It's available on Amazon ...
and- How do you pronounce the name? AIAN? " "Alien Minds," but the AI is in there.
Go get it on Amazon now. David, a pleasure. You are a living treasure, man.
Alan, you're terrific. We'll be in touch again. All right.
Hey, we're live here at RSAC. We'll be done. We'll be back in a bit.
Hello, everybody, and welcome to The Techstrong TV. We're having an interview today with Gaby Boeco, who's the chief marketing officer for NetApp, and we're having a little chat about, well, AI and infrastructure, because it's getting complicated. Gaby, welcome to the show.
Thank you. Really glad to be here. I think everybody's starting to understand the scope of the challenge with AI, and I think we're all trying to figure out, well, how we're going to operationalize all this stuff at scale, because it just requires a massive amount of data.
But I don't think a lot of our existing infrastructure was designed for that. So what you're seeing out there, and what is the scope of the challenge, and what should we be thinking about? Yeah, thanks for the question.
I think somebody said this to me a while ago, it's like AI is going to redefine how we think about plumbing, and I think that that's a really important statement to make. Because when you think about all of the things you just said about AI, because AI eats data, and we're all super consumed with what we are doing with our data, which is the right thing. If we're not taking advantage of having that infrastructure conversation as well that is managing that data, then I think we're missing it.
Especially when it comes to thinking about it as an afterthought. We like to call that built in, not bolted on, right? Just like with anything, if you're thinking about your data infrastructure last, then you are probably thinking about it in a perspective that isn't going to work synergistically with how you're thinking about your data, right?
The amounts of data have really forced us into rethinking not just data infrastructure, and not just data storage, but what are we doing with that? What's the data management aspects? What's the security aspects?
So the amount of data that's coming from just what you create, and then AI creating the data on top of that, and then doubling, it's doubling, tripling. And managing all that really does require you to think what to do with that, and how to think about it maybe more from the ground up. So have the conversation before you're just thinking about the workload or anything else, because then you're missing something.
What is your sense of where are we on this journey? Are people prepared to make that level of investment, or are they still coming to that, and it's something of a surprise to them as they kind of work along here? Because I'm seeing people are building stuff in the cloud, and then they're starting to wrestle with the latency issues that go with that, the cost of the tokens, and everything that goes around that.
But it's not quite clear to me that they figured out just what is the budget requirement here. Yeah. And I think that a lot of people think about it, but they think about it in maybe in a different bucket.
So I like to think about it as a disruption, as everybody does, but it's an opportunity to disrupt even your model and your existing thinking. So if you think about it, you're not just dragging your legacy technology stacks along, you're purposely reinventing it. And that's where I think people are really starting to wake up to the fact, especially our customers.
They're sitting there saying, "Hey, I've got security issues. I've got low latency issues. How do I think about that from the beginning?
" You're picking then priority workloads. You're picking how you're trying to transform, and you're really thinking about removing that friction in your thinking between data and how and where I'm trying to innovate. So those two things alone are saying, "I'm not going to just exist for what I've had before.
" Now, NetApp, obviously, we focus in on what we like to call intelligent data infrastructure, and we really are saying that that is the moment to reinvent, to say, how do we embrace AI and all the needs we have with AI, but continue to say, how do we solve for the scalability, the cost, the structure changes, and the security changes that are obviously creating challenges for us in what we're trying to do? Honestly, if we think about it, this is the truth. If you are the companies that have not just a great AI ecosystem in the cloud or the best kind of compute, but the ones who have really strong data infrastructure aligned with integrated intelligence, integrated security, those are going to be the people who have disrupted their own business to take care of the disruption coming.
To your point about intelligent data infrastructure, how smart will the data get? And I'm asking the question because every time I look at AI, it's basically a challenge to figure out, how do I get the right data in the right place at the right time? And that kind of means everything from the inference engine for the AI model all the way to the whatever prompt and the data that I'm including in the context window to go with that prompt.
It seems like there's a lot of science in that. So how smart is smart? How smart is smart?
I love that. I don't think you can ever be too smart if that's really what we're asking here, right? Again, I go back to that built-in, not bolted on.
What we're saying is, in that context is that we already know that we are going to be overly smart. The workloads and the way AI is getting used today is already going to be different in six months or even less. So what you need to do is build in a foundation that actually is solving for that, again, that unified and intelligent and secure moment for your data.
The question is, who or what do you need to do? When you think about your data, is there parts of your data that are maybe legacy pieces of your data that you just need to keep safe and secure and we're going to put that somewhere else? Do you really need to have and build legacy infrastructure to support all of your legacy needs?
Probably not. AI is smart enough to be able to say, "You know what? You haven't used that in a while.
Let's keep it secure. " So again, that's coming back around to that model that says, if you're intelligent and built in along the way, then what you're doing is you are creating the kind of relevance to your data that almost, like me as a marketer, let's just use me as a marketer. I am saying I want AI to define where the relevance factor exists inside my data, not just give me more of the same.
So what we're doing, like what I do in marketing is I say, if personalization at scale is actually now a thing, then am I personalizing for my entire set of audience or my entire set of data, or am I personalizing based on something else entirely? That is me saying I want AI to define my dataset, to protect the rest of my dataset, but to really focus in on another dataset. And you can't do that unless you're really defining again, and putting your smarts across the data landscape, across the data estate, and then giving and prompting AI to really understand and build that from the ground up.
So smart is smart, but it also is precise. It means that you're not boiling the ocean every single time. And that's why you need the kinds of tools that say, "I'm going to do this at every single layer versus just one.
" So honestly, you know what I think? I think that that's always what we wanted our data to be, and that's always what the promise was. I think now what AI does to it is it might actually just make it a reality.
So how do I navigate that? To your point, we clearly need an AI stack of some type that's optimized for running those applications, and yet I will have this massive amount of legacy data that I'm trying to move and expose to those AI models. So how do I kind of balance between the need for an AI stack and my existing investments in IT?
I think that's a great question. I love that question. I think that this, again, back to disruption, what we're being given the opportunity is to disrupt existing models.
" I think that what that does is says thatThe idea of what architectural shifts need to happen isn't I need to rebuild or get into a walled garden type of approach. You want to have AI and your agentic workflows determine what those architectural shifts are going to be, right? So, I think that enterprises need, let's call it at the moment, on real-time.
We've been talking about real-time ever since I've been in tech. " We would say that that's your security, your performance, and your mobility, right? So that I can do whatever that is, right?
I want to meet my customers where they are. I want to attract new customers. I want to offer my best service.
" So I don't know if that's a perfect answer for this, but what I do think is this is work that technology's been trying to do ever since I've been in it. I think AI makes it possible as long as you're looking at your system as something that is intelligent and secure and, quite honestly, something that is built to help you navigate the future, and that doesn't necessarily always mean that you're rebuilding it. That just means you're focusing it.
There were a lot of things that happened downstream from the data that actually trace back to how we manage that data. In case of AI, that could be everything from our efforts to make sure that we're optimizing it for AI browser search, and then there's also context windows, and the better I am at managing that, the better the answers are, plus less costly as it gets. Do you think people have enough appreciation for all those downstream things that they need to be paying attention to that are directly related to how you manage the data in the age of AI?
I would say, I'm going to talk about it from a CMO perspective because that's what I do every single day, right? I feel like a lot of times we talk about data as a strategy. We have our first-party data strategies.
We talk about our data-driven campaigns, and all of those things are very downstream, right? And I think that what that means is that sometimes that means we're missing from the conversation on the design of what we're trying to do with the data. I think that that's a really important concept for most people to get beyond.
You have to be able to ask the hard questions, not just focus in on the downstream actions, right? Yes. Am I looking at how I'm using SEO, GEO, and LLMs to drive greater reach?
Absolutely, I am. But if I'm also not asking how is my customer data being used or structured for AI ingestion to be able to deal with the SEO and GEO, then I'm missing the conversation. If I'm not asking the question on how does our data retention policy around our customers intersect with the AI training models, then I'm missing the conversation.
So someone inside every organization is going to own that conversation. And if it isn't you, then you need to invite yourself to the conversation. Otherwise, what you're going to be doing is you're going to be creating this grateful recipient of AI wonderfulness and not basically being a part of the shift or the disruption that needs to happen inside your own organization.
So I think you have to be able to do both. You have to understand what you want it to do, and then you have to understand what's going to drive it and make it successful. So that's how I manage it in terms of marketing.
That's how I manage it here at NetApp, but also that's why we, again, believe in intelligent data infrastructure because you can't do either one of those if you're not thinking about the latency of your data, if you're not thinking about what it's sitting on and being able to move it between on-premises and cloud. I am involved in that, not just because I'm in a company that does it, but because I think it's relevant to how my tactics perform. Do you think organizations will finally revisit data management in general?
Because I might argue that few organizations that I know would get a really good housekeeping seal of approval, shall we say, for the way they manage data. And in the age of AI, are we finally going to come around and have that conversation because, well, after all, it's all about the data. I think yes.
I think that data management becomes far more likely. However, I think if you just start from a data management layer in terms of, oh, I need to, and you're not actually thinking about why you need to, then it still will feel like a boil the ocean moment, right? I think what you want is something, again, do I have fragmented systems or do I have fragmented data definitions?
Or have I not cleaned any of this data, and does it just need to live over here? I think you have to ask the questions that allow you to be prescriptive. Again, AI eats all of your data.
Do you really want to deal with data management across everything, or do you want to make it super prescriptive? " Yes, you do, but focus where it's going to make the most meaningful value for you first. " Are there certain best practices or things that are leaping out at you, going, "Yeah, we need more of this"?
Yeah. Thanks for the question. I really like some of our customers, again, in their hybrid cloud environments, really looking at moving their data and their relevant data between cloud and on-prem, and really taking a look at that movement as part of what intelligent data infrastructure can bring to them.
When you're thinking about not just where your data's living, that's an isolated view. But when I see my customers saying, "I'm going to put high-impact data over here because I'm going to use it more. I'm going to put low-impact data over here, and I'm going to revisit it in X number of months," I really view that'sA smart motion, especially when you think about unified and real-time data that's reflecting where their customer journeys are.
I also really like the ones who are focused in on what they're doing with security. Again, the threshold and the map of where you would have risk with your data can be everywhere. " So a security mindset is something that I think is helping get to that precision of how they want to deal with data.
Again, back to that built-in, not bolted on, right? " So I really love both of those aspects between the hybrid cloud and the security that our customers are working on. That's some of the most successful ones that I've seen, and they're really fun stories, quite frankly.
To your point, haven't we come full circle? And I would argue we spent the last decade or more trying to push as much data as we could into the cloud. But when I was younger, the prevailing wisdom was bring the compute to the data.
And now we come back to that, where we're now making intelligent decisions about where the compute and storage and networking resources need to be based on, well, data gravity. I think we absolutely have. I think that's a really good assumption and observation.
We've actually said that on a variety of perspectives when we talk about AI. Stop bringing everything to it. But bring your data to this, to AI.
I think that that is absolutely a full circle moment. And you're actually seeing that that's how people are using the cloud and AI moments to say, "This is really actionable. " So yeah.
Again, this data conversation is not new. I think AI has exacerbated and accelerated certain conversations that might have been maybe ignored or just maybe put aside or maybe we can't solve it the same way. So I'm excited about the power that AI brings to the data conversation, the data estate in any customer.
I'm excited for what it does for the industry. And most of all, I'm excited for what it does to, again, my area, data infrastructure, because it finally makes the conversation relevant because people are thinking again about it at every single level, not just at the moment of use. So yeah, full circle, 100%.
Mm-hmm. And aren't people going to come up with an actual strategy for managing their data? And I'm asking the question because we've heard for a long time now data's the new oil, but I always observed that the problem with that whole analogy was we didn't have any way to process the oil and turn it into something useful.
So are we finally going to get to the point now where we not only have data as the oil, but we also have the mechanisms in place to process it and then pump it to where it needs to be? Yeah, I think so. I agree with that.
Obviously, what that means is that leaders in any company need to recognize that your outcomes on AI or anything with your data are determined by how well your data is getting accessed or governed or activated. And that shift from simply maybe just managing the systems or having a technology architecture conversation is really creating more, I don't know, maybe the data is becoming more meaningful. Maybe it's becoming more human-centered because you're focusing on the experience.
That means your data is continuously in motion. Hopefully, it means you're driving decisions at scale. I think that obviously, if you're committed to your data and you're committed to making data the oil, as you say, then you're committing to say that we want to operationalize it to accelerate our innovation.
I personally believe at NetApp that that means that AI is part of that, intelligent data infrastructure is part of that. Hopefully, NetApp is part of that. But ultimately, your data strategy inside a company is part of creating that unified foundation, part of creating that oil that you referred to, without forgetting that it's the human experience and the performance level metrics that are going to magnify those experiences that matter.
Hey, folks, you heard it here. No matter what era we're in in IT, it always comes back to the data at the end of the day. Hey, Gaby, thanks for being on the show.
You're so welcome. All right. And back to you guys in the studio.
Hey, I'm John Swartz, and we are at RSAC. It's day one in San Francisco. We're at the Moscone South Auditorium, so to speak, on Broadcasting Row.
So to our left and to our right, there are a number of booth setups. And we're going to start this week on a very strong note, on a very important note. We're going to talk about a documentary that is going to premiere tomorrow and be shown also Wednesday here at RSAC.
" First off, welcome to the show. Welcome to San Francisco. Thank you.
I think you came in from Sacramento. Arti, I'm not sure where- I came from Vancouver, Canada. Oh, nice.
Beautiful city. Yeah. Yes.
Thank you. Tell me a little bit about this documentary and when it's going to premiere and kind of the idea behind it. Yes.
Well, this documentary, first, viewers, happy Women's History Month. And This documentary took us five years in the making. So just before COVID, we started.
" It's been a long journey, and we're finally here after five years. We're going to be showing this documentary, and super excited to show it here at the premiere. We've had several different premieres across different cities, and we're going to be showing it here in San Francisco at the RSA Conference.
It's directed, by the way, by Yvette Friedman. It is. Yes.
And Kristen, tell me a little bit about the idea or the narrative. So from what I understand, it involves the idea of women in this cybersecurity realm- Mm-hmm ... which unfortunately, the numbers are low.
They're getting better- Yes ... over the last decade. They have improved, but is this primarily about that challenge or that issue of women in the industry, or is it even something more than that?
I think it's something more than that, but it is about women in the industry and some of the things that we face being in this industry. It's not always easy, but it's a tremendously rewarding industry to be in. Richard and Yvette did a great job narrating the challenges and some of the interesting opportunities that we face being women in cybersecurity.
So tell me a little... Are you both in the documentary? Are you both on camera?
I'm not in the documentary. Arti is. I know you are- Yes ...
because I saw a clip. Mm-hmm. Are you involved in the...
What was your involvement? I've gotten more involved because of Arti. Okay.
So I've done more or less fundraising to help get the movie at the Metreon. So I've done- Okay ... the fundraising.
By the way, the Metreon, which is across the street- Across the street. Yep ... from here.
Yeah. The premiere is Tuesday at 4:00 PM. Doors open at 4:00 PM.
Yep. And also Wednesday. Yep.
At 4:00 PM. There's a red carpet, starts at- Yep ... 4:00 PM.
That's right. The screening's at 4:45. Sorry.
Yeah. How long is the documentary? And, uh- So yeah.
The documentary's 75 minutes long. Awesome. And yeah.
Again, back to what you mentioned, it shows our journey, how we started in the industry. We also talk about some of the allies who have supported us along the journey. It's such an exciting documentary, and we've had such a big impact when viewers have watched it.
" There's so much great feedback that we have gotten. So you mention in, I think in the press materials, allyship. Yes.
Now, I was unfamiliar. I know what the concept is, but I was unfamiliar with the word. Is that something that has kind of picked up and is now resonating and maybe has something to do with these slowly improving numbers?
Yeah. Lots of allies have helped us across- Mm-hmm ... in our journey.
A lot. A lot of them. A lot.
Yeah. A lot of great men. So we want to appreciate the allies who've actually walked the walk and really supported, not just this documentary, but supported lots of different initiatives.
So that's how we're going to accelerate change is we have 25% women in the industry, and of course, we want to accelerate that change, and the way we can accelerate that change is have more voices, and that's where we need all the allies to join us in this mission so that we can have more women join the industry. Mm-hmm. So I'm going to ask you, I don't want to put you on the spot, but in terms of the allies, who are some of the stronger allies?
If you could point out, are there certain companies or individuals within cybersecurity who have championed? So many great men. Yeah.
There are a lot of great men who have helped us- Okay ... along the way. The list is long.
Yes. But from a company perspective, I think all the companies that are supporting the documentary. Yeah.
All- Maybe mention a few, actually. Yeah. Yeah.
Right. Most of them. Centra's supported...
We work at Centra. They've supported this documentary, in the documentary itself, and some of the premieres across the country. Yeah.
So back to that is just these sponsors all have CEOs who are also allies, and they are aligned with our mission. Was there an event or was there kind of a tipping point where there was more of an emphasis on allyship, or is this something that kind of slowly has evolved and percolated? I think it's maybe slowly evolved- Yeah ...
the allyship. I think that once people see the documentary and they hear about being an ally, then they're like, "I want to sign up. " Yeah.
That's something I was going to ask you about. Is there something that you think stands out that you want people to walk away after watching this to remember? You mentioned some people talking about allyships.
Mm-hmm. Are there certain points in the documentary that you think are particularly poignant or particularly important that you want to call out? Yeah.
So, the stories that many women have shared that people can resonate with. We've had at the premiere some people bring their daughters. So it inspires them to join this industry, right from that very young age.
They look at it because growing up, I didn't know about this industry. Yeah. And had I known about it, it would've been something I would've worked towards.
I just fell into it by accident. How did you- Yeah. So was it a friend or somebody at work?
" And I'm like, "I know antivirus. " And I needed a job, being new in the country, and that's how I joined, and I've stayed ever since. What's the state of STEM like?
So full disclosure, 15 years ago, a couple of colleagues and me, when we were at USA Today, worked on a series of stories about DEI. Mm-hmm. This was during a totally different era.
It was during the Obama administration, and we got the ear of Jesse Jackson at the time, and he did a real push into this in tech in general. Mm-hmm. And the companies responded.
Mm-hmm Somewhat, I think, under pressure. And they did make moves, but then that kind of dissipated after Obama left office. Mm-hmm.
I'm kind of wondering, that was a key tenet was the education system was just... To even be even broader, it didn't push mathematics, engineering, tech for either sex as hard as maybe it does now. And I'm wondering, has that education system, is it improved from maybe even from the junior high and the high school levels up through college?
Potentially. I don't have children, so I'm on a- Oh ... you know, I don't know.
But I would think so. If you think about it, all the kids that are coming out of school, and they want to go to the best schools because they want to go to the best tech schools or schools for their various, for science or whatever. So I think so.
But I'm not an expert in that field by any means. Yeah. Just to add what she said is representation matters.
When women see other women in different roles- Yeah ... then that inspires them. And when they don't see that, I'll tell you, my niece, there was a program where she saw a female who was a pilot, and she straight away told me she didn't see that before.
And when she doesn't see representation, she doesn't see that as a career for her. And I think now more and more women are getting into these roles that even the next generation get inspired to see, "Well, I can do that, too," or, "That is a career for me," which is something that we didn't see years back. Yeah.
I wonder, and we talked a little bit about this before we went on air, the influence of AI- Yeah ... and how has it helped or hindered women in cybersecurity, and whether it levels the playing field. And I think you made a really interesting point about how women are much more aggressive adopters of the technology from what you've seen.
Yes, definitely. I've done my own research within my own family and friends and network, and I see the women, including myself- Yeah ... even in the workplace- Yeah ...
we are adopting AI at a faster rate than the men that I've seen within my own family and network and friends. And this is a skill set that we are- Mm-hmm ... as we're adopting this faster, we're now starting to get ahead of the game in terms of the skill set, and I see that change.
It's a big shift, and my hope, of course, is to make sure that employers see that shift, and that increases their mindset, "Well, let's not hire traditionally. " And women definitely, like I said, are adopting AI at a faster rate than I've seen. And personally, how have you each adopted AI?
How do you use it, or how is it- I use it every day. From- Every day ... yeah, every day.
Literally, even at the workplace, even outside the workplace. So many- Mm-hmm. Yeah.
We- Every day ... definitely use it every day. Its irony is that college graduates are having as hard a time as ever getting jobs out of college.
Yeah. Mm-hmm. And you could attribute that perhaps to AI displacing certain types of jobs.
Right. But I also think in terms of cybersecurity, there's never going to be as much demand for people who are experts in cybersecurity, given what's going on with AI. And this conference, I think, is going to probably drive that home with, I think, the emergence of OpenClaw and just all these incidents involving companies with security breaches that are attributable in some way to AI.
So perhaps that also has an influence. Yeah. Look at it, the attackers are using AI at a fast rate, too, right?
And so that, of course, we've also got to be mindful of that, that they're using it faster. They're getting smarter in their techniques, and that's where, from a defender's perspective, we have to make sure we keep up with it, right? And remove all the barriers to entry because the attackers don't have barriers to entry, right?
Right. Again, get back to your career. So when you got into cybersecurity, when you first joined the field, what was your impression?
Were there a lot of other women who worked in your company or with you at that time, or? No, I was the only person when I first joined. I didn't see it initially, right when I joined, but when I did see it was when I was applying for a promotion and for that next role, and I didn't get it even though I was the top performer.
And that's when I started seeing, well, I don't look like what the persona is of those who go into that next level. Right. And that's when I started realizing there is an issue here.
There is an unconscious bias that we all need to address. We all have our own biases. Yeah.
And we need to make sure we recognize them, and that's how we're going to break the issues, the systemic issues that we see today, is we have to figure out what our own bias is and start breaking out of them. Is that addressed in the documentary, like prescriptive measures that can be taken to accelerate the hiring of women in cybersecurity? Are there- It's touched upon- Yeah ...
in the documentary by a couple of different ladies who are in the documentary, yeah. What are their ideas, if you could share what they think might reverse course? I don't know what some of their ideas are- Yeah ...
off my head. But it's just generally just showing there's a great story, which I don't want to reveal, but it's just a great story of how someone spoke up, for example. Mm-hmm.
Right? And a lot of us, sometimes we lose our voice, but when you do see something like that, allies can come in and step in- Mm-hmm ... and make sure that it's appropriate to support or call out when something is wrong versus being silent.
Yeah. So- Yeah. It's like an interesting era that we're living in right now.
We were talking about all these AI influence layoffs or job tumult, and I'm-For cybersecurity, I think might be one of the safer areas, so to speak. I don't know if you agree with that, but in tech, it seems to be open season on most jobs. Yes.
And perhaps in cybersecurity that won't be as much the case. We just don't know. But- No ...
that also brings me to this other question. Yeah. I'm mentioning AI because from what I understand, there is a sequel of sorts in the works to this documentary.
Yeah. There is. Yes.
And it involves AI? Yeah. Yeah.
There is a sequel. Part of the sequel is going to be still in discussions around AI, because everybody's talking about it, and so there is going to be that sequel coming up. Mm-hmm.
Wow. Tell me a little... Oh.
Yeah. We need to promote this. So this is very important.
This is a very important topic. We've written about this at Techstrong on Security Boulevard website, and something that my colleague, Terry Robinson, is going to be writing a lot more about. And I'm sure she'll write about this if I don't.
One of us will write about it. Thank you. And I want to bring it up on Techstrong Gang.
It's interesting, the film festivals. Can you mention some of the film festivals this appeared in? Also, can you share with us how this will reach an even broader audience later this month, perhaps?
Yeah. We've actually been doing it... We've won several awards, too, Best Director, Best Writer, because of showing this across different cities.
Right now, what we've been doing is hosting it at different cities, whether it's at a theater or at the AMC. And so we've done quite a few, actually. We've done close to 20, I believe.
All across the country. And Canada. Across the country, and Canada, too.
So we're excited about this because it's now raising more awareness. It's getting people excited about it. And coming soon, it's going to be on a very big platform, too, that we just announced.
Oh, can you- Yeah ... share that platform? Yes.
So it's going to be on Prime. Good. We just announced it last week, that it's going to be on Prime.
And stay tuned, because you'll see it by April timeframe. Yeah. What has the audience's reaction been to this?
And is it a kind of split between men and women, or? 100%. It's a split between men and women.
Yeah. Yeah. Yeah.
And some men will bring their daughters. Yeah. I was going to ask you- Yeah ...
a lot of daughters who go. There are. Yeah.
There have been a lot of daughters. And after the movie, that's what's been so fun, is seeing all the promotion, all the how much they loved it, and just all the activity. Do they, they must have felt inspired by it- Yeah.
They have been ... and encouraged. We've got so many, after each documentary screening, we've got feedback, people posting on LinkedIn- Mm-hmm ...
about it, taking pictures, and sharing their overall experience. And this is a great way to celebrate the women who have made a big impact in our industry. There's 21 of us in the film, and it's a great way to celebrate these women, including other women who are going through the same journey.
" They'd never thought about it. Mm-hmm. I heard daughters saying, "I didn't think this was a career.
" Mm-hmm. " One thing you also had mentioned earlier was build and retention. Yeah.
Could you maybe go a little bit into that, and kind of where that state is? Yeah, definitely. I think you were talking about the retention, I think.
Yeah. So the focus has been, let's hire more women, which is fantastic. So we've seen that change, and we're seeing we're now at 25% women in this industry.
We need to accelerate that change. But what happens when you bring the women in? Let's start looking at the next step.
How are you going to grow them? How are you going to promote them? How are you going to get them into these senior executive levels?
Because the numbers go down as they go into that executive level. It goes to less than 10%. And that's where the issue is.
If women find that area where they can't grow anymore, they'll leave. And that's one of the things we've got to fix, fix that broken rung, which is help women and champion them so that they can go into that next stage. Give them that opportunity.
Remove your own bias so you can hire more women into that next level. That always seemed- Allyship. I think that's what- Yeah ...
the allyship with men, because mostly there's men in those roles. Yeah. Where they could help promote women.
Yeah. It'd be interesting to see how the ecosystem works as maybe more women start companies, that- Yes ... kind of, they hire more women to work within those companies.
I remember that dynamic playing out in tech to certain extents. But it always came back to the numbers were specifically low in terms of the C-suite. Yeah.
And I think they still are in tech. They still are. Yeah.
I mean, dramatically low. We do in the documentary, not in the documentary, but we do have one of our sponsors for the next couple of days. She's a first-time founder and CEO, female.
And so we're happy to have her company- Yeah ... Schematic, with us on the documentary, or at the sponsorship. So I don't want you to talk on behalf of Yvette, but I'm going to ask you, what was it that prompted her to want to make this documentary?
Had she made documentaries before? So she wasn't making the documentary, she's sponsoring, right? No, he's talking about Yvette.
Oh. Oh, Yvette. Yvette.
Oh, Yvette. The director, yeah. Oh, talking about Yvette.
I'm wondering if this is her first documentary, and I mean for- Yeah ... I even think about, let's go back to the Oscars. I was kind of blown away that the lady who won Best Cinematography was the first woman to win cinematography.
Yeah. I found that almost hard to believe. Yeah.
And I'm wondering if that's kind of the same case in terms of documentaries, and what spurred- Your director to make this. Yeah. So, the producer was the one who had the connection with Yanet.
Okay. And so, she aligned with the story, and she did a phenomenal job directing this documentary. So, it was aligned to what she enjoyed doing, and she's done a phenomenal job.
Yeah. So I'm going to ask you, I think we've promoted the documentary. We'll promote it again before we go off.
Yeah. Thank you. But, I was going to ask you about the show and what you're looking forward to at the show.
Were there any type of topics or type of products or type of areas of cybersecurity that have your interest? Yeah. I think obviously we want to hear what everybody's up to.
Obviously, we're going to hear so much about AI, but also new product announcements, new mergers and acquisitions. That's what I'm interested in hearing about. Yeah.
It's- Any competition, Dewey? Yeah. Yeah.
Is there anything in particular that you're- Yeah, no, I just want to add that's basically, with the conference here, super excited about just meeting lots of people and- Awesome ... hearing where they are. Awesome.
Yeah. " Documentary. Tuesday and Wednesday, 24th to 25th, 4:45 screening for each day?
Yes, for each day. Drinks and popcorn is going to be included. Oh, nice.
Cool. So there's going to be networking from 4:00 to 4:45, so come early. Yep.
And save your seat. Make sure you register, and you can find us at our booth. At our booth.
The Centra booth, which is 4607, so you can register and secure your seat. Okay, and it's going to be at the AMC Metreon 16, which is near Moscone, you said. Yes.
Right across the street. Fourth Street. Yes.
135. You can't miss it. I think it's right off of- Right here.
Yes. Yeah. Right across.
I can literally see it. Literally, you walk and see it right there. So if you can get to Moscone South, you can find the theater.
Yeah, totally. Thank you so much for your time. Yeah.
You guys were great. And I look forward to seeing it. Yeah.
Good luck. I hope you can make it. Yeah.
I'm going to make it. Yeah. Yeah.
Yeah. Definitely. I told you this earlier.
I shouldn't say this, but I will. Who cares? Okay.
I was part of a documentary about cybersecurity a long time ago, and I was one of the talking heads, and I am ashamed to tell you that there were maybe 20 talking heads in that documentary, and there was maybe one woman. One woman. So- Yeah ...
hopefully we've kind of reversed course and flipped the switch. Yeah. Yeah.
No, I'm excited. Yeah. I'm super excited about it.
All right. It's going to be good. All right.
Thanks. So we're going to have more interviews coming up later today, very soon, actually. I'm John Swartz with Textron Group, and thank you for watching.
Hey, everyone. It's Alan Schimmel, founder, CEO here at Textron Group. Really happy to introduce this next session here for you.
In this session, we are going to have Futurum's Fernando Montenegro, who is the analyst in the security cyberspace, speaking with Ryan Jones. Ryan is the partner director of product for Power Platform Managed Platform over at Microsoft. Great conversation with Ryan and Fernando.
Fernando's going to talk to Ryan as we explore how organizations can securely scale agentic apps, including Power Platform's governance capabilities. This is going to include managed environments, adaptive risk models, and life cycle controls. Hopefully, you'll get out of this video practical guidance for balancing innovation with compliance in an age of AI-first development.
Let's listen in on Fernando and Ryan. Alan, thank you very much. So, I'm Fernando Montenegro.
I am VP of security research over at Futurum, and I'm thrilled to be here with Ryan Jones to talk about the broader topic of AI governance. Ryan, want to say a few words before we get started? Yeah.
Thanks so much, Fernando. My name's Ryan. I work on a number of the security, governance, and operational capabilities that we provide not only to our AI agents, but also that we provide to our low code apps and automations that run on the Power Platform as well.
Have you come across something more specific to AI risks or AI governance concerns that surface above and beyond this data sharing, the data flow, and sharing in others? As we look at the maturity of agents, we see that they kind of go from being assistants that are completely directed by humans to still interactive agents, where humans are dispatching tasks, but the agent is completing them on behalf of the human. And then we see those fully autonomous agents.
And I would say that 10% to 20% is really more over on the end of the spectrum with those fully autonomous agents than it is with my little assistant agent or something like that. And the types of things that we see at that end of the spectrum are things like, hey, if I am collaborating with a set of agents, how do I understand what they are doing or what they are doing on my behalf? The second scenario that we see is we're in the very early innings of AI, and so there are lots of cases where agents need helpWhere they sometimes get stuck.
And so some of the things that we've been trying to add into our products and our offerings are things like within Power Apps, we have the agent feed, where a human can see what all the agents are doing for them. And then within Copilot Studio, the request information action, which actually allows us to define an agent such that it can engage with humans as needed. So what has been your exposure, your experience?
What kind of considerations do you have in this topic of model drift and model security and so on? Yeah. It's funny, we talked about what's old is new again earlier, right?
Yep. We've had static tests that we perform against software for a long time. And what's interesting is seeing how that is evolving, because models are less deterministic than traditional software.
We call it, stochastic life, right? And so as a part of that, one of the capabilities that we've added to Copilot Studio is the ability to add tests and evaluations, so that as our technology improves, as makers and builders go through and they modify what tools their agents can use or what knowledge sources are used to ground those agents, those test cases, those evals can run and can return a result so that folks, as they are evolving, they know whether or not they're actually improving the quality of their agents. Because what we find is that the first day that an agent is shipped in an organization, this may sound negative, but that's going to be the worst that that agent ever is.
Okay? It's only going to get better over time as folks refine the knowledge sources, as folks refine the tools, as folks look at and improve the success rate across those evals over time. And so I think that those quality gates that we've had in software for a long time, we have those with AI as well.
Mm-hmm. I think also, a lot of times, an individual maker, they're going to be the folks that are really interested in whether or not that agent really works well or not. While, IT is going to take a bigger picture look at things, right?
Sure. They're going to want to understand in aggregate how are things looking, are they healthy or not? And it could be that if they see an agent that's not performing well, but maybe just you and I use it, IT probably doesn't care.
But if I have an agent that 20,000 people use this month, IT is going to care. And so those same views that we provide to our makers to understand whether or not their agents are healthy, we provide those aggregated views for the admins as well. In fact, had a large customer in the energy industry where someone built an agent, and it was for them, and they shared it, and it grew and grew and grew.
Next thing they knew, they had 10,000 people using it. They moved on to work on other things, right? " And so they took it over.
They added it into their portfolio of applications that they managed. And the thing was, they saw it not as a burden, but rather as an opportunity. Because there's an application that's out there that delivers value to tens of thousands of people in the business every month.
And their dev cost up to that point had been zero. So it was a win-win for everybody. Once the technology security teams build the guardrails, right?
Then the business users are free to go work on those use cases. So what kind of advice do you think would be applicable to those technology and security teams in terms of getting them ready to build those guardrails or to leverage what they have to implement those guardrails? I think enumerating the categories or the dimensions of risk is one of the first steps.
There are huge categories of risk that these teams can eliminate through how they define policies. And to be clear, I don't mean policies like a Word document. I mean- Yeah ...
policies that are codified in the Power Platform and Copilot Studio and these sorts of things. Sure. Organizations don't want a random person in their company to build a workflow that takes information from their core ERP system and pushes it to Twitter, right?
We have the controls that allow you to preclude that. What would you consider to be from a governance angle? You mentioned, okay, let's not focus on use cases.
What would the advice for, okay, let's move this forward, right? " I think the first thing that we see people do is they define a zoned governance framework or a zoned governance approach, right? They decide within their company or their organization what does green, what does yellow, what does red look like.
Mm-hmm. And then they go through, and they define that using the tools that we provide through the Power Platform and through Copilot Studio. I think the second thing that we see folks do is that helps with kind of the supplySide, right?
That sees to it that the technology is available and accessible for folks- Mm-hmm ... across the organization. But then there's this strong demand element, because, gosh, I was talking to another big company in the credit processing space a couple of weeks ago, and they had- Yeah ...
this amazing governance framework set up, but they didn't do anything to stimulate demand. Right? And so the next thing that we see is reaching out to the businesses, not to harvest their use cases, but to help them implement their use cases.
Things like hackathons, things like training- Mm ... things where for the people that are interested and excited about transformation through technology, where they can roll up their sleeves and get into it. The number of apps and agents and automations that came out of those couple day training session and hackathons, it blows my mind every time I have the opportunity to participate in one of them.
And it's fascinating because you see the passion of the people in the business. You see their ideas come to life. " And what you highlight here is super interesting because one of the things we talk about in the context of platforms is how you can have that network effect of you've already configured something in your environment for a particular use case, like you said, entry groups for identity, and how that can accelerate the time to value, if you will, within AI development because, hey, you're building on a foundation that you already built for your organization.
So I think that's a really powerful message, right? And it's something I tie back to: how do we help technology and security teams build that scaffolding so that those business users can go play on those environments? A thousand percent, and I think that in a lot of circumstances, it means standing on the shoulders of giants that came ahead of us, right?
Yep. What organization today doesn't have Entra deployed in one form or another for user and group management? And so why wouldn't we use those grouping constructs as a foundational capability around which we build our security and governance frameworks, right?
It's already there. It already works. And I think that is one of the things that's a little bit differentiating around the offerings that we provide in the space because- Mm-hmm ...
I build an app, an agent, an automation from day zero. It's Entra authenticated and authorized, right? Another thing that we're seeing that's super common right now is as companies are trying to figure out how do they get these AI tools into the hands of people across the organization, and how does that center of excellence or that center of an enablement help people in the various business units upskill and drive transformation?
One of the things that we're seeing is that our customers who already had a center of enablement or a center of excellence built out for low-code applications and automations, they're moving much, much faster when it comes to agentic transformation. Because a lot of the foundational governance concepts that you need to have in place, they're modality or client agnostic. " I think that one of the areas that we want people to be aware of, and we talk about in our research, is that this evolution in models, right, we shouldn't be, just like you said about the use cases, just like the use case conversation, you shouldn't be waiting for the use cases before you get started kind of thing.
We shouldn't be waiting for a perfect model to solve, okay, once we have this model, this is how we're going to do this. No, because these models are evolving constantly, right? And if you architect your AI governance framework right, you build in or you leverage the build in, the monitoring capabilities to observe how a particular model is evolving, how a particular model is behaving.
So yes, it is a critical component, observing how these things are evolving. " And there are some places where we give customer those controls. NET framework or what version of Python I was using to deliver services to them.
And so I think it's a little bit interesting that folks are looking for that level of control with some of these models. And I think that if we zoom out and ask ourselves, apply the good old five whys to why folks are looking for that, they want to make sure that as new models are available, it doesn't cause functional regressions in their agents. And the thing is, like we were talking about earlier, that's quite literally why we have tests and evals, right?
And that's where, by the way, if for some reason, even though I don't think I've seen it practically speaking in the last year or so, if folks did see a regression as a result of a new model, awesome. At that point, yes, you want the control to go back to an older version. But we're not really seeing that in practice that much, so...
Yeah, no, and this talk track of multiple tools for your SaaS apps within the business environments is something that it's a shared pain for security teams as well. Because when we speak with security executives and their teams, they are swiveling between multiple tools in the environment as well. As a matter of fact, we are working now on a report on security platforms precisely on that note.
And one of the areas that we are tracking is AI for security, right? In the context of how do the agents that are now being deployed within Sentinel, for example, right, are helping with, okay, let's do exactly what you're describing from a local no-code perspective. I know it's on the Power Platform, but we're seeing a similar thing on the security platforms as well, and there is tremendous interest in doing that, provided that, yes, we've handled the governance and risk constraints around those.
So absolutely, this is a phenomenal time. The joke I make is that listen, you can wake up at 6:00 in the morning and go to bed at midnight, and this stuff, it keeps coming at you with opportunities, right? It's information to collect, it's information to parse, and opportunities to make improvements.
Perhaps you can use agents to help you with that too. As you're thinking about how you're evolving the Power Platform, what have you been looking to improve in terms of security and governance capabilities on the platform? Where do you see the platform going in terms of one of the things that-- This is more of a higher-end use case, but we do see requests for regulatory compliance.
Remember when the internet was new, and people started creating those blogs that talked about what they ate for lunch or what their dog did that afternoon because they didn't know what else to do with it? Yeah. I kind of feel like we're in the same place right now with AI, and so I would definitely want to preface anything I say with, these are early innings, and so I kind of don't know, okay?
Sure. At the same time, as we look at the types of regulations that are coming into play with the EU AI Act, some such examples that we're seeing there are like, hey, these particular types of data need to be handled in a particular way. And one of the things that we've started doing within Copilot Studio is surfacing those data labels, those information protection labels in the response so that folks don't inadvertently start working with sensitive data in a way that they don't intend to.
Okay. And I foresee that in the fullness of time, this will continue to grow. One of the things that we're seeing is we have a capability in the platform today called Advisor.
And Advisor constantly scans over the agents and the apps and the automations to make recommendations in kind of like a reactive governance or reactive security perspective because we believe strongly in the principle of trust but verify. And one of the things that we're starting to see with Advisor and the way that it can iterate through AI-generated app and agent descriptions is we can actually start to flag when some of these apps or agents may be getting too close to that boundary of what acceptable use policy within a company looks like. Yeah.
And so there's definitely something interesting going there. So one of the areas that when we speak with security practitioners comes up a lot is they are balancing two very distinct problems. On one hand, they are absolutely swamped.
The other is we need to balance two things. On one hand, we want to use as much as possible of the broader tooling we already have, the security platform conversation that we are observing, right? That being said, there is still, in many cases, particularly the more novel use cases, there is a need to work with third parties.
What's been your experience navigating this platform and ecosystem scenario in the conversations you've had as people have been using your platform? Yeah, I think that what we try to do is we try to start from, first and foremost, providingThose foundational security primitives that people need to be able to leverage these capabilities safely. And that has to be native within the platform, right?
Like if I have to go find an authentication provider or find an authorization service or figure out my auditing and those sorts of scenarios, that's a non-starter, right? And so we have to provide those capabilities from the get-go across Power Platform and Copilot Studio. I think the next layer above that is if I think about the tools that someone in the CISO's organization is using on a daily basis, I'd love to think that they come to the Power Platform admin center every day, but I know that's not true, right?
Right. They're spending their time in Defender experiences. They're spending their time in Sentinel experiences.
And so it's critically important that all of the telemetry, all of the audit logs, and these sorts of things naturally flow into those systems because we have to meet those security professionals where they are. Sure. And then I think the final thing that we're seeing is there are some unique and novel risks in some cases with AI, right?
When we look at things like prompt injection and kind of the emerging product categories of XDR for AI, does Microsoft have some solutions in that space with Defender? Yes. Is it also such a quickly evolving product category that we need to plug into the broader ecosystem?
Yes. And so, the same extensibility hooks that we use for integrating with Defender are actually the exact same APIs that we allow partners like Zenity to connect to, so that they can provide additional defense and depth when it comes to particular risks like prompt injection. Ryan, this was a phenomenal conversation.
Thank you so much for the time. Hey, thank you so much for your time and for all the awesome discussion. And my hope is that folks, as they hear what we discussed today, they'll feel confident, they'll feel empowered that they have the capabilities needed to manage that security, governance, operational availability risk, and that they'll be able to parlay that into accelerating how AI is able to transform their business and deliver outcomes for their employees as well as their customers.
Can't wait to see what's next. I think that as I ponder on what we discussed, a few things, first and foremost, this notion that you have been building a platform to begin with in terms of low-code, no-code before, and then building the AI capabilities on top of that does give people the benefit of building on what they've already done. It does give the benefit of tying to the rest of their ecosystem.
And it's as much about the culture of let's try and get started and work on different types of use cases without trying to boil the ocean. We're going to build a capability that accommodates different use cases, different levels of governance requirements, right? And then we're going to help those teams start to work on those particular scenarios.
I look forward to seeing how the platform evolves and capabilities. This area never stops. One of the taglines I use is that there's never a dull day in this industry, and that's the case here.
Control, this is Agent Dev. I'm in position. Copy that, Dev.
Standby for go. Standing by. Hey, everybody.
Welcome. You've joined another episode of Agents of Dev. My name is Mitch Ashley, and I lead the software lifecycle engineering practice.
I'm joined, of course, by co-host and none other than Brad Shimmin. How you doing, Brad? I am doing well, Mitch.
How are you? And where are you? You are not at your usual position for our podcast, my friend.
Well, I heard there's a new position open in Washington over the Justice Department, so I wanted to be sort of in range- ... in case they called. But no, I'm actually in New York City for the MCP Dev Summit, which is kind of an interesting place to be right after RSAC.
But we're going to talk about that for sure. Now, you've been on the road, too. Yeah, they're kind of self-balancing.
They're pulling against each other. They are. I do feel a pulling effect.
So you've been globe hopping, at least coast-hopping- Yeah ... in the US coast. What's up with you?
Yeah, the last couple weeks, I've been both down in Atlanta with Microsoft, which actually I would love to do as a call-out, because I think that the company, as is always the case with Microsoft, which is still an engineering-led company, let us not forget- Mm-hmm ... that. And with their Fabric, and on top of Fabric, a number of capabilities like OneLake and their new database hub, which is what I really love.
They're doing some great things, and one of those, and that is the database hub, is basically taking all of the managed hosted databases that you might want to build and run on inside of your enterprise, like a Postgres- Mm-hmm ... instance, let's say, and manage that on a single control plane acrossAll the databases. Interesting.
Right? You don't have to basically stand up and provision and manage separate database instances. You can have them all governed and managed centrally.
And the beautiful part about that is it also ties into OneLake, which is something Microsoft is building as the "Lord of the Rings" style One Lake to rule them all. Mm-hmm. For building a consistent semantic layer within the enterprise.
So through- Wow ... capabilities that they have had and are doubling down on right now, like mirroring and what they call linking, which is, and I cannot believe I'm saying this with a straight face. It's symlinking for databases.
Ooh. Symlinking data. You are the symlink guy, for sure.
Right. Just trying to manage your dock files with symlinks, as we all do, is sometimes fraught with peril, but apparently it's a great idea for data. So they're allowing people to basically create this very centralized, yet still open platform that's all sitting on top of running on Delta/Iceberg compatible object storage.
And that's sexy. I like that. It's very cool.
Well, you said OneLake. " That kind of thing. One Drive.
One Drive. Ooh, okay, there, we took a hard left. Sorry about that.
That or it's a Backstreet Boys song. I'm not sure which it is. But anyway.
OneLake. What's your call-out? What are you thinking about this week?
So I had a really interesting one. Anthropic published, I guess, a blog post, an article- Mm ... about how they monitor their own agents.
Now, when you really read into it, and happy to provide the link to folks, what they're really monitoring is sort of the extremes of their agents. From their agents doing things like, okay, writing things in byte code and different levels that can get past the monitors. Okay.
And there are several. This is part of monitoring agents as they move towards general intelligence, right? And so there's a lot of things of agents.
It's kind of like unruly teenagers. It's like you're hosting- Are they not? Yes ...
your 13-year-old's birthday party, but not it's birthday party because he's too old to have a birthday party, with 13 of his best friends. And of course, they're always going to get in trouble and push the bounds and break things. So.
Yep. But it's really, how do you monitor things that are trying to thwart or do things you don't want them to do, and they're also trying to thwart your monitoring? Mm.
So what happens when one of the agents co-opts your monitoring agents? It's all kinds of interesting things there. And it really touched on something I love to talk about, of course, is observability native- Oh, yeah ...
and control planes. And that is getting into the reasoning of what happens in the moment that it happens. And by trying to keep that reasoning hidden to the monitors, so they don't really know what they're trying to do.
So you and I- Interesting ... kind of talk in code, but you know what I'm doing because I'm not- Yeah ... really telling you what I'm doing.
That kind of thing. Interesting job. I'd love to see that job description of somebody doing that work.
I thought it was fascinating. I must ask, my friend, did they publish this before or after the leak this week? Let me see what date it was.
I don't know if I have it up and I can check that. It just came out, so it had to be really close to that. That's right.
Because was this a response to the leak, or was this just a happy circumstance of- Oh ... what Freud would call synchronicity? I don't know.
So this is not the data leak you're looking for? Go left, go right. Right.
Yes. These are not the agents you're looking for. It was just pretty interesting.
It's interesting. Which is... Go ahead.
Oh, sorry, man. But it is, really. Because what they, I think, and we've talked about this before in the past, is that Anthropic does a good job of actually trying to expose some of the warts that come along with this transformer rollercoaster that we're on right now.
Mm-hmm. Vis-a-vis things like memory ablation and how in a model you can sort of zap some certain perceptrons to make a model think it's the Golden Gate Bridge, for example. And so I love that they're doing that, that kind of work.
And it brings me back, actually, to what I'd forgotten to mention with Microsoft earlier, and that is that they're working on forgetfulness. I forgot to talk about forgetfulness. That's ironic.
It's the key takeaway there. You did that on purpose, I know. Yeah.
I know you did that on purpose. And this, again, loops back to Anthropic's leak. Because in a part of that, there was a lot of work exposed about a continuously running daemon in the background called Kairos.
And what this daemon was doing was memory consolidation. They basically refer to it as dreaming, which is kind of shockingly how we humans consolidate memories in the hippocampus- Mm-hmm ... at night when we sleep.
It's not just sluicing out the bad prions or whatever that build up in the daytime, the plaques, whatever they're called, but also consolidating memories, which is, for models and agents, extremely crucial, right? Because what if you have conflicting information when you change your knowledge because something new happens? Really difficult for humans to do.
Maybe easier for agents? What do you think? Well, it's an interesting topic because one of the things I did a while back that's kind of related to this is, in the work that I'm doing with AI and agents, is I institute a policy, a rule- Mm-hmm ...
that we will journal about what we're doing as part of the memory retention, sort of the dreaming, like let's retain this stuff long-term. md and whatever ways we have of- Right ... retaining memories between sessions and things like that, and lots of things get persisted to disk to be able to perpetuate whatever we're working on to the next session or across sessions or whatever, because oftentimes, even agents themselves don't share memory.
No. But what I was concerned about is repeating the same mistakes. Like, this is the same thing, and we've talked about this three times.
Kind of like talking to- ... your four-year-old. "William, we talked about this.
You're not going to have cookies tonight. " Bane of my existence, by the way. So, I instituted this We're Going to Journal, and when we do things like close down projects and write what we learned.
And there was a whole segment where we were working on how to figure out what the best model is to use for the best work- Mm-hmm ... the right work, right workload, running on multiple computers, workload locally, as well as using the models in the cloud, AI services, Anthropic, Gemini, et cetera. Yeah.
And understanding price, that these things aren't free. The local ones are free per se, but they also consume resources. I don't have the cloud sitting on my desktop.
And that the model loves to pick the most expensive or one of the most expensive services- It's not thinking about your wallet ... just to do a really great job. Yeah, even though I told it we have a budget, here's what we have.
So we went through, and interesting in doing this journaling, long, long story, but to get to the point is in going through, "Yeah, but we didn't capture this, and let's make sure you document this," is we actually realized, oh, there's something that we didn't know that we learned- Mm-hmm ... about what we did. It sort of came out of just the fact that we were doing this process.
Just like you might journal for yourself, right? You might do it for your own- Right ... kind of clearing your mind, getting things off your chest.
" And then, of course, now it's like how do we persist this? How do we use this going forward? So this is always part of it, so there's certain things that we do with the journal as part of our recall when we load things into memory and things like that.
So this whole dreaming and persisting and making things, the retention of that, more than what the technology currently does. It'll do this itself someday, I assume. But- Well- ...
I find it really fascinating ... maybe just like with humans, and we learn different methodologies and practices that work better for us. I have friends who do zettelkasting, and I don't understand them.
But I'm sure it works for them. And then I have other friends- What is zettel-- I don't know what that is. What is zettelkasting?
It's just a form of documenting your life to make a second brain out of all your notes. Oh, okay. I- Digital twin.
Okay ... I'm an Obsidian junkie, but I do not do links. I do tags.
I'm a tag guy, so hash- Oh, you're a tagger. Okay ... hashtags all day.
Mm-hmm. Yep. Okay.
But we learn different approaches all the time. And so maybe today, the methodology that OpenClaw uses with its-- It has a journaling system just like you're describing. Mm-hmm.
You have your soul file and all that other stuff. But the journaling is kind of a critical aspect of that because it puts things in a temporal context. And if you don't have that, how do you forget something?
How do you forget and create a new memory of something based upon whatever that change was? Mm-hmm. 1, which brings me back to the bane of my existence.
I cannot believe that in March, now April 2026, that I'm still arguing with Gemini CLI about what year it is and which model is the current model. I gave up on context seven just because it was expensive, heavy, and didn't always use it accurately. So I've baked into the memory for Gemini, these are the current models.
This is what I want you to use for that, just as you were describing. Mm-hmm. And it still runs home to mama because that's what's in its training data.
That's hilarious. Well, I've been struggling with a... No, April 1st is not on Wednesday.
Well, whatever day it was. It thought Tuesday was Wednesday. Yeah.
" Cognitive dissonance. Yeah. It was arguing with me.
It kept putting in that I'm like, "No, this is the wrong date. " Oh, that's hilarious. What was the solution?
Did you just keep arguing till it relented? I put it in the prompt every time I tell it to. And on Tuesday, I give it the date.
Give it the date. The 31st as opposed to Wednesday the 1st. I think that's right, yeah.
Wednesday was the first. Anyway, so I just had to prompt it and just keep going because I'm like, "It's in here. It's in this file.
Put this in your memory," blah, blah, blah. I'm telling it what to do. Mm-hmm.
I get stuck on those things, too. Right? You can call- We do, right?
Leap year, springing forward and back, just any temporal shift, I think is very difficult for any reasoning species. Mm-hmm. There are some that don't reason, I'm saying that, but for most of us that do, or we think we do, it is important.
And I've run into that with the work we're doing internally to use agentic processes for- Mm-hmm ... gathering, collating, and analyzing news, for instance. Mm-hmm.
And I've noticed that the place where agents have the most difficulty is when you have, let's say it's ingesting a press release that is a retrospective of the past for a financial result for year-over-year financials. And if that were to publish in, let's say, January and discuss the prior year, if that were to publish from a company that's using fiscal years instead of calendar years- Mm-hmm ... the agents get extremely confused.
I mean- Mm-hmm ... catastrophically confused, just because it's trying to reconcile these sort of concepts, these abstract concepts of time. And it's hard for humans, it's hard for computers, it turns out.
I was going to say, I struggle with what's your fiscal year? It starts in February. Okay, how do I remember that?
Right. When you're making decisions when, and most people are on a calendar, but a lot of people aren't. So you've got to work within what that structure is.
Of course, that sort of cascades to a bunch of other things that change the timing of it, because whether it's budgets and performance reviews or whatever it might be, or decisions to make, buy products and things like that, you just kind of work in this temporal world of everybody's maybe on a different time dimension than you are. So interesting stuff. Yeah.
Time zones suck. I would- ... very much love it if in North America, we went with the Asian route of China with just one time zone.
One time zone to rule them all. One lake, one time. Boy, you are on a singularity on a track here, aren't you?
Definitely. I have, you might say, a one-track mind today. I tried not to say it.
Thanks for saying it. So can we talk about a four? Can we talk about four?
Four. As in Gemma 4. Gemma- Oh Can we do that much?
Boy, okay. Let's jump. Go for it.
I was going to go to Graph Database, so we'll go to Gemma 4. We have to talk graph because that is a favorite topic of mine. But yes- Well, that's- ...
let's do really quick because numerology is important, and so I have two words for you about Gemma 4. Okay. All right.
0 words, to be specific. Mm-hmm. 0.
Mm-hmm. We've all come to terms, I think, in this industry with open weights and what open weights means, which is not at all what open source means. Oh, yeah.
No. And Gemma has been a great project because it takes Google DeepMind labs and externalizes a lot of what they're learning and doing in a way that is freely available and can be used to build upon by others. 0.
So Gemma 4 is distillation from Gemini 3 family- Mm-hmm ... and various forms and sundry, because there's a whole family of these Gemma 4 models. And prior to that, they were all open weights with some very bizarre, restrictive, got to read the full fine print to understand what the heck you can do with this or not do with this.
Yeah. And now we are open source. And it is ironic in a way because we are seeing this sort of flip-flop between the East and the West right now in terms of the East perhaps pulling back, as we saw with the Qwen- Mm-hmm ...
team, the Qwen team. Losing the Qwen team, and this sort of rumors of this is going to be locked down, coming out of China. " And if you think about the family itself, you've got this Qwen beater that is a mixture of experts model that only leaves, I think, four billion parameters running at any given time across a whole bunch- Mm-hmm ...
of experts, which looks a lot like the Qwen 35, four billion active parameter model they have. And the two of them, I would see, as duking it out directly. And then you have these smaller, I think they call them edge models or can- Edge models, yeah ...
I can't remember. Yeah, they're edge. Much smaller- Mm-hmm ...
that are themselves multimodal, able to do things like on-device translation from heard audio to written word. So, you could listen to English and translate into Chinese or Japanese in real-time on your device with a 300-million parameter model. Actually, the ASR stuff is actually 150 million parameters, so it's even tinier than it was before.
Mm-hmm. That is impressive because the reason why it's impressive to me, by the way, is Apple. Boy, okay, taking a swing there.
Right out of left field. Just 'cause you want to talk about GDC then, or not GDC. Yeah, WWDC.
I always do. Yeah, WWDC. Sorry.
I'm an Apple fanboy. I'm a Linux fanboy, but an Apple fanboy as well. But, yeah, because they have, as everyone knows, Apple is working with Google for its AI.
And it doesn't take a lot of stretch to think, well, gosh, on-device AI from Google is looking pretty good right now. And- Mm-hmm ... if Siri is ever to move forward and not be something we loathe using, but instead to something that's consistently available across all of the applications that are running on an Apple device, and that they all can seamlessly use whatever available AI, like translation or what have you, on-device.
Yep. Mm-hmm. And think now about all of the app builders, because they do have a bit of an app ecosystem, Apple does.
Oh, very much so. Yeah. Absolutely.
And one of the things that's rumored to be coming out of WWDC is this thing called Application Intents, I think is what it is. Yeah. App Intents, which is the intent of an application to say for doing X, whatever, I'm available to Siri.
I'm available to the ambient AI running on my phone or my laptop. That's a big opportunity for those app developers and for Apple. So maybe being late and initially wrong is better than being right and early.
Well, or being wrong and early, because- That's a full stop right there. Yeah. Well, which has happened.
We've seen that already. Mm-hmm. And I've been an Apple user since my Apple II Plus, so let me kind of put that out there, when I was going to college.
Yeah, that's like last year, I think it was. Yeah, that was right before the current MacBook Pro. One of the things that they've consistently done is gone back to Steve Jobs, is they will work at it, and work at it, and work at it, and work at it.
Yes. And then they'll work on it again until it's right. And not that they don't make mistakes.
They certainly do, and they've kind of been known lately for the operating systems having kind of, oops, slipped a little off the rails. They are back on, kind of getting things on the track. But everybody complains about, "Well, all you do is make phones and laptops and a few desktop computers," which happen to be really popular at the moment.
Just a few. Minis. Yeah.
But they have held back and said, "Yeah, we're not going to go out there and stub our toe in front of everybody, and everybody's already got great expectations for us. So why help them help us fail? " And so you know they've been working on this behind the scenes, and my first question was, "Well, hey, we all have these neural processors sitting around in our phones.
" Right. Is this some grand secret plan they're going to launch things on us once AI becomes ready to do that? Well, maybe, but maybe it's just going to take a little longer to go.
My long-winded point of being, whatever they do, I think they're going to make sure it's done right. So, yeah, we don't like Siri, and Siri's a little bit of the Clippy of the day. And- Don't diss Clippy.
Clippy at least wanted to help. Yeah. Go away, Clippy.
He's like that annoying neighbor kid. Go away, go away. You're too young to play with us, to play baseball.
Anyway, so but I have this feeling that when it comes out, we'll see if it's at the Worldwide Developer Conference this year. Hopefully it is. We'll see what happens.
But I think it's going to make a splash, because they're going to- Absolutely ... it's not going to do everything, and everybody's going to just poo-poo because it didn't do this open claw use case that everything else does, or whatever it is. But what it does, it will do well.
It tends to be Apple's plan. And if it doesn't, they keep at it until it does it right, or they pull it back and stop doing it. So- Which they did already ...
Apple TVs and Apple Cars. We've seen that with Apple Intelligence- Mm-hmm ... that they're like, "Hey, whoa, whoa, wait.
" And I'm sure the class action lawsuit helped with that. But the point is that they are willing to turn a very large ship in the ocean there. And so I applaud them for that, and I wish them well with this endeavor because I think right now, and this is particularly with regards to how these agentic harnesses are taking over our lives, many of them.
And it's for those of us, like you and I, and the folks listening to this podcast, we love to experiment and play with this stuff. But- Mm-hmm ... you have to remember that somebody who's maybe not that familiar with technology, that still yet depends upon it to get through the day, to- Oh ...
perhaps even stay healthy and safe. And so you've got to do it right. You've got to do it in a responsible way that is going to help both freaks like us and, I'm sorry to say the word normies, but there are a lot of people that don't need this as intently as we do in their lives, but still depend upon it.
"You're close. You just hang out with nerds. There's a nerd curious.
So, one of the things I wanted to bring up, because I am at the conference here at the MCP Dev Summit, I guess is actually the third one. I thought it was the first one, but there have been a couple. And this has been donated to the Agentic AI Foundation, along with MCP and things that have been rolled up under it.
So, it was interesting coming off of RSAC, which I've worked in the security world for a long time, and there tends to be a bit of a poo-pooing on things that aren't secure. Those dummies that didn't know what they're doing that create something, how could they do that? And there was a lot of snarkiness in the hallway about MCP, and it's gone.
And even in the platform engineering community, they're frustrated with it because it's just sort of- Oh, sure ... an unwieldy- Yeah ... like, what do we do with this?
And yes, you can use OAuth to talk to it, but it's not a two-way, so when it wants to talk to something else, does it need to do it? You need to send- Absolutely ... an OAuth through that, and now can you sort of violate your RBAC principles of sharing data?
There's all kinds of security issues with it. And, so one of the reasons I came, well, one, I was invited, but two, really to get a pulse of what's going on. Where is MCCP headed?
Is it the thing of the past and something else is taking over? Yeah. We were just kind of happy about it for a year and a half, and now we're going to do something else.
But you've heard me call it the, I call MCP the can opener when all people had was cans of food, but no way to open it. Right. It was that thing- Right.
I love that ... at the right time. I love that, Mitch.
Oh my God. Yeah. Because- Why didn't somebody create this earlier?
to me, I feel like it's like phone books, because it is like a phone book, is it not? To look things up. And- Oh ...
I challenge anyone listening to this to turn around, look around their house, and tell me that there is a phone book sitting anywhere in sight. Yeah. There is not.
There's not. Had to do the long- So yeah. Is it- Right.
The internet ... the can opener, the phone book? Or is it- It is ...
going to evolve into something else? Well, that's a good question. So, if you look at kind of listening to the talks, and some of the creators of MCP were there, one of the Anthropic guys was.
But they also had people from other organizations, some were maintainers, some were also just frankly users. And, one company, I don't want to mention names for here for this, but because it's on their website. One company had sort of a framework, kind of like my agent control plane framework.
Oh, yes. Nice. Which by the way, just got published.
So, and it was great. I was like, "Wow, there's some good things in that. " And, even Uber, Uber had a really fascinating story about how they've been using agents and kind of controlling them and governing them, and managing security.
And then also Datadog, who's also been pretty active- Mm ... in this whole AI community. Okay.
From observability standpoint, kind of Datadog and Dynatrace are the two that have really stepped out into AI. Independents. Yeah.
Yeah. One of their researchers, who had worked at Anthropic and Google and several companies, been doing this kind of AI on the edge of how do you control it, how do you manage it, all the putting the guardrails in place, et cetera. So I took it as there wasn't a big, "Oh my God, we've got to secure MCP, or we're all going to die and- ...
" That's for OpenClaw. Yeah. Yes.
Yeah. OpenClaw will do that for us. Yeah.
My sense of it is, yeah, people are asking a lot of questions and people wish it did a lot more, and there may be some question about is it going to be around forever. I don't know the answer to that, but I know one thing is true is, people are using it, and using it extensively, and it's pushing the boundaries, and people want to get it into- Mm-hmm ... production.
And that forces what? Yeah. Okay, we've got to go through our security reviews, how we're going to govern it, compliance, all this stuff, especially in large enterprises.
And so it's forcing the market or creating an opportunity for the market to step in and say, "All right. Here's what we're going to do. Here's the control plane we'll use to manage it.
Here's how we're going to do agents, using policies to manage agents," whatever it is. Is sandboxing enough? No.
Is containers enough? No. Right.
But those are right steps along the way. In talking to one of the maintainers, I'm like, "Isn't the real answer is you've got to have isolation. You've got to create an environment where you can containerize or limit what the...
Really, no, the agent can't get outside of these bounds, right, some six ways- So wait, so sorry ... or something like that. Are you saying that they foresee the MCP as a, because as you and I know, it basically stands in front of an API and abstracts an API.
So are they- Mm-hmm ... saying then that an MCP, which as you just rightfully pointed out, is perhaps itself a security liability, is the answer to not just its own liability, but the liability for agents in general? Well, the answer, which is what I kind of suspected and a few people agreed with, that I talked with, is it isn't securing the agent, and it isn't securing the environment the agent runs in.
It's both. You have to do both, right? Interesting.
Because, otherwise, you're sort of operating in this bouncing off the walls security, pushing the boundaries, where the agent is out of control. Yeah. Or on the other hand, the agent's highly secure, but it's working in a world that has terrible security guardrails, and it's bound to still bump up and fail and do something it shouldn't do.
Okay. And that's the thinking is- Well, that sounds like a layer ... you've got to do both.
Yeah. In a multilayered attack mitigation scenario. That- Dare I say- Because I- ...
zero trust Right, zero. We all would love that, right? But it's not always possible to implement.
Not yet. In my travels, because this week I was at Oracle visiting, working with Oracle in their home office, and they, and before them, when I was with Microsoft, to a T, you hear the exact same phrases come out of these vendors. And one of them was, there were two.
" Mm-hmm. " Mm-hmm. So, yeah, I could do a direct tool call.
I could have a PL SQL statement that's an actual direct call to the database from an AI agent, but maybe a better way is through a layer of abstraction and security to do that. The second thing, which I find kind of crazy, not crazy, but crazy like a fox, is that they're saying, you should have a control plane that exists at the framework level, for managing your agents. But if you're going to secure what actually happens or what gets done with the agent, you have to secure at the row and column level in the database.
Mm-hmm. And that's where you need to build in the appropriate safeguards to ensure that basic things like IP control or just redacting sensitive HIPAA information happens. And yeah, absolutely.
Kind of makes sense. Yeah. So many things about secure your common sense, isn't very common anymore.
But that common sense doesn't always translate to the enterprise, does it? No. Yogi Berra, for sure.
So I also wanted-- So anyway, the net of it for me about MCP is, I don't know if it's going to be the thing in five years. Yeah. I kind of don't really care, because if it steps up and evolves to be what it needs to be, great.
If it doesn't- Yeah ... " Great. Okay, it's not this, but now it's Kubernetes.
It's not this, but it's something else- I'm with you ... to replace MCP. So I'm not that worried about it, and I'm not the let's just bash it around until it's got such a bad reputation nobody will hang out with MCP anymore.
Yeah. Kind of get over it. We need to work out solutions is- Exactly ...
the goal. And there are a lot of people, really, there is so much, because it is the can opener. Everybody has a can opener now for everything you want to get to.
I did hear very consistently, "I don't look at code anymore. In my development, I use the tools to do that. I use AI to do that.
I don't deal in APIs anymore. " Mm. And that's how people are viewing the world, developing apps and systems.
I appreciate that, because APIs are painful. Oh. They really are.
Keeping up with them is horrible work. So if I can now- Grandfathering APIs. API life cycles.
How do you manage redactions? It's just ridiculous, yeah. Mm-hmm.
Yeah, and that's of course, we love to abstract things, so it's a great way to do it. But it will get there, and there's just some interesting challenges that they've got to work through, but that's okay. There's some really smart people working on it, too, so I think that helps.
That does help. See, I wanted to bring up Graph database because I kind of got religion about it recently. You mentioned- Did you?
Okay. Yeah. And I'm like- ...
I could hear Brad talking over this, which is the nice Brad here. " But I realize, no, you should... Hey.
That's because every year for the last six years for me has been the year of the Graph database. Okay? Oh.
Well, it is kind of, I don't know if it's the year, but it's certainly up there. It's doing pretty well these days. But I got to the point, you mentioned about us using these technologies, and I have to use them to understand it.
Yes, me too. Because like you said, every vendor says the same words. They're saying the words we say, or vice versa, but they don't mean the same thing, and you don't really know.
So okay, what does it mean to use an MCP server to talk to something instead of an API? Once you see it, then you know. And just as a really simple example, and I'm getting to the point, because I have my own agent ecosystem that I've built.
I call them my 28 little friends that I have running around, my minions doing work for me. But all good things. The council of Mitchs is what I would've gone with.
They may be chaotic, but they're chaotic good. Good. That's all we can ask for.
And I came to the point, I'm like, yeah, this will only go so far. And to really kind of do what I need to do, what I'm asking it to do, make these associations between data, things that are happening across different sources, only way to do it is a Graph database. So, you, me, got my agent to download, and just use Neo4j, the community- That's a great- ...
edition ... great platform. Yeah.
Yeah. Yeah, exactly. It's great.
Been around for a... Very well thought of. And, set it all up, and it was like, see those commercials where the kid who has really bad eyesight puts on glasses for the first time?
That was you, was it? Or the father. Yeah, and that was me.
2400. Anyway, the father who puts on glasses, who's color blind and suddenly now sees colors, or someone who puts the things on their head so that they can hear something for the first time. It was kind of like that with my agents.
" And all of a sudden, the analysis that I could say, "All right, I want to do strategic analysis on this. " And what I ended up doing is I put in all of my kind of thesis about the research that I'm doing. I put in things like my agent control plane framework and observability- Mm-hmm ...
nativeframework as well and put that in there into the graph, along with the other data they have in there. And the analysis that you can do with it, and it's so much easier to ask or tell AI cloud code, whatever you're using, OpenAI Codex, to go do the things that you're asking it to do. Because at some point, it's just bumping around in the dark, trying to ask- Yeah ...
an agent to do something it just can't do. And it doesn't know, like, "Oh, hey, Mitch, you should download a graph database. " I'm surprised by that.
I had to ask. " "Yeah, that actually was a great idea, Mitch. " "Well, actually, not really, but-" It does say that, yes.
It's very- ... glazing happy. Yeah.
To me, man, when I think about agentic processes and what you're talking about, you can make a distinction between meaning, the semantics of what a sentence means. But if you don't know the context of that meaning, yes, through attention, we can see in a transformer model the context of a sentence- Mm-hmm ... in a broader set of sentences.
But the relationships that exist when you have a node and an edge, and the edge represents a relationship between the nodes, and once you combine those together, the meaning and the context becomes something different altogether. And by different- Mm-hmm ... I mean more reflective of the real world and how we move around, interact, and understand our world.
And this is what we're building toward. If we can build agentic systems that see the world more as relationships than just isolated meaning, we can do so much more with that. But it really connected with me because I'm a systemic thinker.
It's about putting enough of the pieces together, the picture forms. You can understand it in a kind of bigger way, how it works. You don't understand it always in depth or all of it.
It's too big to do that. But that's very much what the graph database did for at least my use cases. Nice.
And it was pretty darn simple, using AI to build it. Show me the code. We should do a demo here at one point of the stuff that you're building, man.
But- ... I would love to see how you're implementing that. Because- Yeah.
Happy to share ... it's something that you can look up to Tiger or Neo4j or any vendor that has a graph database, and you will see tutorial after tutorial about just how easy it is to do this. And by the way, what do you think transformers really do well?
They read through sequential information and can extract, I don't know, named entities, relationships between those entities- Mm-hmm ... to create a graph. Mm-hmm.
And so it's not unachievable. In the past, it's been very difficult, not just to build, but to also interact with. You might have to learn- Well, I've never built one before.
Yeah. I haven't used it. And I used to be a database person long ago, but- Yeah ...
the nice thing about AI too is you can say, "Hey, would this help us? " Mm. " I have a term for that, over-complexifying what we're doing.
That is very self-referential, my friend. It's a term that defines itself, yes. But oh, yes.
"This will do what you want to do. " But okay, now I understand why you couldn't do it. Yeah.
Anyway, so I've gotten religion, Brad. I guess I'm a sherpa now of data. Is that kind of where I'm headed tomorrow?
Carry, yes. On that path to carrying this- Saddle up. Wear the load.
We're all doing it. We're all heading- Okay ... to the summit.
I'm with you, brother. We're going together the same way. Anyway, if you haven't, I'm sure a lot of people have checked it out, but it was just fascinating for me to see it work and not just in concept what it does.
Awesome. " What the heck is that? Yeah.
Okay. I think we used to call these dimensional, I think kind of- Weird. Yes.
So. Yes, for OLAP. We kind of like that, yeah.
Interesting stuff. " So, if anyone remembers the '90s or has read about it, or perhaps watched the movie- It was in all the papers. the movie "Hackers" as just but one example of a film from that era that really brought to the fronts the hacker culture, 2600 style.
This device I just showed you guys is called the Hak5 Wi-Fi Pineapple Pager. It's a pager. It's a Linux box, basically, that you can use- Oh, no ...
for pen testing. And this weekend's project for me is to set that up with the first payload I'm going to run on it is called ClawHunter, which is a payload that basically will look for all of the open claw gateways on a network. " Yes, it is.
But with less shooting. Less shooting. Less Russian roulette.
So, I can see if my open claw is doing bad things, and pen test my own setup. So, looking forward to that for me. That sounds like a good Rock 'Em Sock 'Em Robot Wars.
Adversarial, yes. Actually, I think that would be a lot of fun. Hey, and my call-out is, I got to spend some time, of course, with a lot of companies during RSAC, and I really appreciate everyone taking the time to meet and discuss what they're doing.
And first of all, there are people out there, which who are kind of saying what you and I are saying, which is, at some point, AI, because AI, the velocity and acceleration of how things are happening and information is being produced, we have to move away from the human in the loop means human looks over everything, or human stands at the end of the assembly line and picks out every one once in a while to see if there's a quality issue, to really agents that make decisions, agents that actually perform outcomes. And the outcome isn't giving you more information, it's actually doing work. Mm.
And one of the companies I talked to is, well, you'll love the name, is Endor Labs. Yes. Oh, I do like that.
Yeah. Yes, and even their-- They had taken over part of the W, one of the restaurants there, and the exterior of it was kind of the moss hanging off the side looked like you're in the forest, Endor forest. Glad we're still spending money in this industry.
Yeah. Marketing is still alive and well. Crazy stuff.
So they in particular, what I really liked about what they're doing is they weren't just another software vulnerability company. They'd actually taken things to the next level, for one, is not just knowing what code has vulnerabilities in it, but understanding what lines of code are the vulnerability itself. Ooh.
Right? So you could- Yeah ... understand, yeah, you might be using vulnerable code, but if you're never using those lines of code, are you vulnerable?
Right? Right. Yep.
You know? Ask any COBOL programmer. Yeah.
Yeah. Exactly. Have a go-to statement that goes around all that stuff.
Stepping back. Where they were going, the directionally from what I picked up, and this is my reading in the lines, they didn't announce anything like this, is they're one of the companies who are moving upstream and saying it's not just about being a scanner at the end of the line. It's not about something in the line that produces information better for somebody then to go fix.
They are putting things in place that I think someday will help you actually avoid using those things- Ooh. Okay ... or work around them.
Yeah. Because you actually know where the problem is, instead of just avoiding big chunks of code. "Oh, that's got vulnerabilities.
I don't know if we should use that. " Building intelligence about code. So hats off to them and a lot of other good folks.
So nice shout-out. That's very cool because it makes me think that the era of determinism that we've been living in and striving for decades perhaps is behind us, and we just don't know it yet. Mm-hmm.
And that if you can just like a human, be able to sit without knowing everything and without having total assurance, and you can do so in a sane way, maybe that's better than trying to get to that set of all sets thing where you don't have any Goodelian outliers that are still provable but not in your set. You know? It is.
It always comes back to Goodel, just saying. You have a way of bringing it back together to that singularity again, to that point. It all comes together.
It's one Goodel, one hub and one lake. Well, there's sirens going off, and it may not just be because I'm in New York City. I think I've overstayed my welcome, so we probably ought to sign off here.
Good to be on the East Coast with you, even though it's not the same city, but on the same time zone. It's a great time zone. Yes.
Yep. Time. But, and I look forward to seeing you- Thank you, everyone ...
we're going to be on the road more and more places, going to more things. So if you see us, stop by and say hello. "Hey, you're the guy with the ponytail.
" Whatever you do, stop us and chat. We'd love to talk with you, so it's always good. All right, my friend.
Been a lot of fun. We will talk to everybody on the next "Agents of Dev" podcast episode. Bye-bye.
Control, this is Agent Dev. I'm in position. Copy that, Dev.
Standby for go. Standing by.