Techstrong TV December 15, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
So Mickey suing Google. You're watching Text Join gang. Hey everyone.
Happy Monday. What a great weekend. I, I, I gotta be honest with you, this time of year, this close to Christmas, I'm not real excited about coming in here on Monday.
I don't know about you, but, uh, you know, the, these are, this is the time of year when you want your weekends to sort of stretch. But we got an interesting situation this year, right? 'cause Christmas Eve is on Wednesday night, Christmas days, Thursday.
Most people are probably off that Friday. And then it's the same thing next week for New Year's. So there's gonna be a lot of very, very long weekends this Christmas, uh, holiday vacation.
I hope you're all are able to take advantage of it. Now, the folks at Mickey Minnie, Donald Goofy in the gang, they're gonna be brushing up their legal briefs as they are ready to, uh, go after Google here for what they're claiming is massive scale copyright infringement. We're gonna talk about it with our gang today.
Let me introduce you after a brief hiatus. She's back. She's back, uh, uh, one and only Tracy Reagan.
Tracy, good to see you. Jack Poller, who, who's a regular, I'm sorry. I was just gonna say, it's so good to see you.
It's Really great to meet you. Absolutely. We missed you.
We missed you a lot. You, your absence was felt, and I know you were doing good work, but we love to have you on here. And then joining us back home in New York, after his recent, uh, trip to the city, he's back up in Harrison, not named for a president, Mike Ard.
So gang, Mickey Donald, they're carrying their briefcases, marching into court, claiming a massive scale of copyright infringement against Google for AI systems. What I, what I find is ironic is at the same times we're seeing, at the same time, we're seeing stories of Disney licensing characters and IP and, you know, to two AI companies to use it Was a massive KY dinky. Yeah, that's what they call it.
A winky dinky, you know, cha-ching. Um, that's the old carrot and the stick, right? Mike, what do you think?
Well, I guess, so are these Disney characters? I think the open AI deal is worth a cool billion. So are they gonna go around to everybody now and ask for a billion dollars?
And did Google BLK at the billion dollar fee? I mean, how did this number come about? And is this the going rate now for Disney characters?
I don't know. Alan, what do you think? I think Disney has a well earned reputation of being a little heavy handed when it comes to asserting copyright claims.
And, um, it could very well be that Google didn't pay up and so this, this was the stick, if not the carrot. Uh, now on the other hand though, if I'm the biz dev guy at Open AI and I'm shelling out a cool billion, and I know a billion's not what it used to be anymore, it's just a billion, not a trillion. 2 to compete with the latest Gemini.
I make sure I had some exclusivity there for a billion bucks. But I guess, like I said, a billion dozen buy what it used to. Well, I think it's buying Disney something, right?
They, if you think about the, I thought the two announcements were kind of, uh, coincidental and I don't really believe in Coincidence. Ky dinky. We don't say coincide.
Yeah, exactly. That Mike is coined the new term. It's winky dinky.
So is KY dinky. Um, and, but I don't, they have, this is something they've done for a very, very long time. If you went out and got a t-shirt and put a mickey on it, or, you know, even something that looked like a little mermaid, you, they're gonna go after you.
They've gone after smaller people. Mm-hmm. Um, this, this is a bigger problem though, um, with AI in general is going out and digging through, uh, what might be copyrighted information like newspapers.
Uh, so this is, this is just the, the beginning of the conversation. Who owns that content? If you, if something gets generated through your ai, do you own it because you ask for it?
Or does OpenAI or Google own it? So this is just the beginning of the conversation, but I think that they did kind of a ninja pivot here by going and investing in OpenAI and then establishing a licensing model for images, because they are now taking in charge of the conversation and they've bought, uh, a position within OpenAI to push OpenAI to make that possible. I think it was a brilliant move on their part, and it probably will be the beginning of how a lot of copyrighted material is, um, managed it.
I don't know how they're gonna do it overall, but Disney and apparently open AI is gonna figure something out. And Disney's now owning open ai part of it at least billion dollars is a good, a good chunk of it. So, But that's the open AI model, Tracy, right?
They, they, they like to do these reciprocal things. I'll give you something. You give me something, it shows up on my, my books is revenue or investment, even though I'm giving it back to you in cost.
And, and we're all happy. And it's funny money going in a circle jerk, right? Yeah.
And Nvidia does it all the time, right? But, but Open AI does it to the tune of one and a half trillion dollars. We recently had this a couple weeks ago on the gang.
OpenAI has made arrangements to spend one and a half trillion dollars, 300 and something billion with Oracle 300 and something billion with, uh, with, with, uh, Microsoft. Another outrageous amount with Broadcom for, for, for, uh, iterative chips. For inference chips, excuse me.
Um, a one and a half trillion dollars on a company worth 500 billion that doesn't even do $20 billion in revenue. That is incredible. You see how much I miss when I'm not on this?
Oh, this is why you gotta stay up on this stuff. Exactly. So the, so the math, the math just doesn't work.
But this, I guarantee you, this was an open, this is the open AI model. Invest a billion dollars in US, and we're going to put that on the books. And, and we'll, you know, we'll, we'll do a, a license and back deal back, right?
So the money goes like this. It really doesn't go anywhere, But it establishes something, right? But, but, but, and it does Establish something That's the key, but it doesn't establish what you think it does.
This is not about, from, from Disney's perspective, they don't care about open ai. What they're doing is they're setting a precedent saying there is value to licensing this material. Yes.
This is about winning the lawsuit and putting a stake in the ground. And New York Times has a lawsuit as well over this exact same thing. If Disney wins this, it changes completely what LLMs can do.
They're gonna win, have To pay for every content. They're Is gonna win as well. But, but, but they're winning not on, but they, what they're doing is they put a stake in the ground saying, this is real money, right?
So when we win, it's not you have to license. Everybody has to license from us for real money, not token amounts. Right?
Not the, the, the, the court could say, yes, they infringed on your copyright, but we don't care about it. And there's no monetary award and there's no precedent. This is setting a precedent.
All future stuff. I don't think, I don't think a court, so you're talking about like the Trump suit against the NFL where the court ruled that the NFL did in fact have a monopoly at the USFL. This goes back, right?
30 years, years ago. Right. And they awarded $1.
Yeah. Pretty much. Right?
Basically Said you, I mean, you were, you don't see that very often. You don't see that very often. But because all the thing is from a court's perspective, if they set a precedent here, it affects not just Google, but it affects the entire AI industry and how all the LLMs have built and how can they get new data to train their models.
But all of these cases, not just a case, Disney would bring the Times case. The what we've seen, what we, you know, let me back up. One of the things I learned in law school from my professors was it takes the law, the courts five years, five to seven years to catch up to society technology, like new things like this.
So there's gonna be that period of adjustment. However, what we've seen in the lawsuits on this issue to date, right, is that the, the AI companies generally settle prior to a decision being rendered by the court. 'cause they know this is a losing argument.
It, it's, it's a bit of a novel case from a copyright claim. Usually the average Disney copyright claim is more like what Tracy described. Someone puts someone in that looks like Mickey on a t-shirt or a pocketbook or something.
Or in the case of the New York Times, someone is hiring their content without acknowledging and attributing and licensing, right? It's very clear cut. The, in the AI case, they're, they're using this information almost as background information to train their AI and to make their AI better.
So the AI company benefits from the, having that content for training material. And then that training material also does find its way in, if you will, to the output of the ai. Tracy, to your point, the courts have been clear to this point that when you ask an AI to generate something that becomes your work product, the ai, the open AI or perplexity or whatever doesn't own it.
You, you, you do have the IP to that. So you said, or you said that the Disney and the Times will win these suits, but in previous shows going back a year, I can remember you kinda saying that, well, this is under fair use, and so maybe they won't win it. So where are In this?
Well, I'm, I'm like the Supreme Court. Well, I'll, I, I think the one thing about the Disney suit that is different is they're claiming that it's not the training of the material that's at issue as much as it is the output. Where they were actually, they were actually directing users to generate derivative works of Disney characters Like Disney, like fact Disney, like, right?
Yeah. And, and, uh, Sundar Phai actually did that, right? So they're saying the CEO of this corporation is encouraging people to infringe on our ip.
And that's different than we're using ANP Training. What's the, you know, the gimme an op-ed in the style of the New York Times, right? And it, and it writes a very sort of New York Timesy kind of thing.
It it, it's a similar kind of thing. Well, yes and no, but if I go write a book that's based on, you know, uh, an extension of James Bond, I will get sued by Ian Fleming's family. And rightfully so, because I'm basically commandeering a character in a storyline, even though It's an evil.
Oh, Conair, oh, Conair boy, you don't think all of these spy movies and, and, and with Suave British style agents are not based on James Bond, But they don't show up as James Bond. And I think what's happening here with these representations online is, you know, it's clearly something that looks like Mickey Mouse. It's not just a mouse.
It is Mickey Mouse. But Disney for a long time has said just about any mouse can be Mickey. 'cause Mickey's changed his looks over the years.
Mickey was originally a ratty looking mouse. If you look at Walt's old drawings, you know, from the twenties and thirties, um, he had a much longer nose, you know, he was a ratt looking mouse. He's changed though.
Mickey, I think Mickey's had a little work done. Chase. That's what I say.
I think he has too. Yeah. I think he's been softened up.
Right. And Min Minnie does Minnie's had work done too. Mm.
Um, but that being said, you know how close it is to Mickey is in the eye of the beholder. Right. You can't just say every mouse is Mickey.
And, uh, and You can't say, you can't say every mermaid is a little mermaid. Right? Yeah.
I seem to remember going back in time, mighty Mouse was a character that went around, right? Mighty Yes. He was gonna say the day, wasn't he?
Yeah, He did all the time. Uh, but, but those, you know, taking it up a level from just the pure Disney, because they are always more, not obnoxious, more, uh, more likely to enforce their, their, they, They, they, they, they guard their privileges. Yes.
Yeah. But, you know, the bigger issue here is all of these frontier models have basically trained their models on the body of publicly available knowledge in the internet. And, and this is, that's gonna be the crux of the question, right?
Can you, can you train on publicly available knowledge? But, and, and here's where the legal kind of nexus is. It used to be, you know, we had cases with links, right?
Can I, can I build a newsletter with links to the Times to the Washington Post to the Fox News, CNN And maybe even because those pages are not behind a red wall or anything. Grab some of the material from there without attributing, but have a link at the bottom. You know, over the course of the 25 years of the public, or 30 years of the public internet, we, we've, there's a body of law and case law that has evolved about, you know, how you can use publicly available webpage information on your webpage or in your business.
Little different than training my LLM on it. But there's legal, from a legal point of view, they're similar. Alright.
So just to be clear, do you think Disney and the New York Times are now gonna win these cases? Yes. Or not?
I, I, because it goes back to what, what you said before when I said it a year ago, they were in the public realm and therefore usable. But, you know, the case law on internet stuff is even if the ca, if the pagers are publicly available, that doesn't in give you, in essence the right to pirate them All. Right?
Well, as somebody who creates content, that warms my heart. Me too. It warms my pockets.
My pockets are empty, Mike. 'cause we're not the New York Times. And, you know, we gotta wait for these cases to play out, because I think once these cases play out, much like the deal perplexity did with book authors, right?
Once you could prove that your book was used in their training, they, they agreed to some formula to pay you money. Yeah. So, so my brother wrote a book many years ago about, uh, mechanics of baseball pitches with Jim Cott, I think, and it was published by Hearst, but philanthropic wound up sending him a letter saying, you may be entitled to $3,000.
Yeah. Yeah. com.
We've got 40, 50,000 DevOps articles on there. Mm-hmm. No doubt.
I'd like 3000 in article just saying That. That's your opening gambit. Well, no, what I thought they would give me $3,000 an article and I would invest 1500 of it back into open ai.
There you go. That is the new model. I know at some point, at some point though, did we just wind up writing for their open ai?
You know, it, it, the, there's the, there's what goes on in courts in the legal world, and then there's what goes on in the real world. Mm-hmm. And don't, don't ever confuse justice with truth.
There. You can go. So anyway, let's take a break here on the gang.
We'll come back. Wait, we'll talk more about ai. What a surprise.
You're watching Text on Gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, welcome back.
And we're back in court. Well, there's a wrongful death suit in Connecticut somewhere involving, um, a son who wound up murdering his mother because, um, you know, he was having a, some sort of conversation with ai. And this suit is against OpenAI and Microsoft.
And apparently, you know, they're claiming at least that the AI told him, you know, that all his thoughts were correct and that people were, uh, chasing him. And that, you know, he was some brilliant person with some awesome insights and the usual ous stuff that AI kind of delivers. But then he wound up turning around and killing somebody.
So I think we're all watching this suit to say, you know, what kind of liability is there gonna be for something like this? We have talked about some of these issues earlier this week involving children, and now it's a, essentially a murder suicide now. So, Tracy, what's your take on what's happening here?
Well, it feels more like a Halloween discussion than Smiths. But, uh, so yes, this, this man was living with his 83-year-old mother. Let's, let's just start it like that.
And he was 56 years old, so there's something going on already. It wasn't The Bates Motel, was it? It kind of feels like that, doesn't it?
It really does. Um, yeah. And he probably suffered, I don't know, um, some level of paranoid delusion, but maybe many of us suffer paranoid delusion.
And regardless if it's open AI or if it's Facebook, uh, these are modeled to tell you what you wanna hear. Kind of like our politics today. Right?
Just tell us what you want to hear and we'll tell you that. So, you know, in this particular lawsuit, unlike the one we just discussed, I feel like there's some personal responsibility and accountability that has to be considered even when it comes to the case of murder. How are we, how we, how are we really gonna say that?
Because AI was telling somebody what they wanted to hear, which is what they're trained to do. And they wanted to hear that they were somehow, uh, touched by God or, uh, you know, they possessed Power, power or talked to them Or their yes or their dog talked tomorrow, their printer was watching on, was spying on them. I, I really believe we have personal responsibility has to take part in making a lawsuit real.
Uh, I, this what I'm sad about, uh, because we've talked about this now, you know, we, the, the, the community at whole, and it, and everybody has talked about the impact that social media, and this is just another, in my mind, this was just another way to have a social discussion. It was a, it's more like a social media discussion. They have caused young people to be bullied and to take their own life.
Um, there has been, there's been all kinds of discussion about why we wanna manage better, what comes through these, these portals, uh, because we could have somebody with paranoid delusions who's gonna go shoot up a, a, a classroom. Uh, so we have a responsibility here. And I think that the, the, uh, AI companies have a responsibility as well, but the person has some personal responsibility.
I mean, I think what's an issue here is there's no warning label, essentially on the service. So there's nobody out there telling people who may be crazy that they know this. They're interacting with something that is, um, shall we say augmenting Sort of, Okay.
That's true. But somebody can go buy, somebody can go buy a gun and shoot people, and they don't. And, and the, the, the, the gun company doesn't have any, Don't ever, don't ever mention that Tracy.
We'll all be in trouble. Ice will be at the door. I'm Just saying, You know what Second amendment, How do we, um, freedom of speech, freedom of speech.
Yeah, I get it. I get it. So first of all, I gotta tell you, we've, we've been discussing so many of these legal things, I feel like I should go dust off some of my old school books.
Mm-hmm. Though, I don't think they use law books anymore. It's probably all computerized now.
I paid a lot of money for those big fat books. But anyway, you know, this, this goes back to something we discussed last week on the gang. And that is the difference between negligence, let's say resulting in a wrongful death lawsuit, which is a civil lawsuit versus criminal negligence, criminal manslaughter.
Right? Which is a much more serious, that's a criminal, right? You're not just talking about paying money, you're talking about potential criminal.
But in those cases, Alan, if you, if you're gonna dust off your, your, your, your law books, isn't there something called intent? Well, no. And do we, the criminal negligent negligence by definition means there was no actual will or intent, but you could still have criminal manslaughter where your, your negligence resulted in the death of someone.
You may not have had what they call the men rea, you know, the, the mind to the intent to, to do such things. But it's still, it crosses the boundary of even gross negligence to criminal negligence, right? Getting behind the wheel of a car when you're, you know, twice the legal limit of, of intoxication.
And you've done this, you've been pulled over for 2D Dewis previously, crosses the line into criminal criminally negligent manslaughter. It doesn't mean you went out willfully, But those cases are very clear on who was completely responsible, right? I mean, have we seen a case yet?
Let's Hang on. So, so now you come to it though, Tracy, right? Because what will happen here is there will be a discovery process, and then there'll be subpoenas for emails coming outta OpenAI and Microsoft.
And I bet you're gonna find out exactly how much they knew about this stuff before you they rolled this out. Well see the, but see, this is this, there's exactly three things that make this different than any other normal guy going wacko and killing somebody, case. And that is one, there's a computer record of it, right?
Up until this point, 99% of the wackos, they talk to the psychic, they call the psychic hotline on 1-800-PSYCHICS. Right? Or they talk to the, you know, they, they, they talk to their co crazies under the bridge in next to Moscone Center, right?
There's just no record of it. The second thing is, it's ai. And the third thing is Microsoft and open AI have a ton of money.
No, this, Otherwise the lawsuit would be brought. No mistake, Jack. You're right.
This is a deep Pocket. None of this would be brought, right? It, this is what they pocket.
It's a deep pocket. I'm, I was, I'm very glad that, that Tracy brought up the concept of personal responsibility. Unless there was a record of this happening, nobody would know how this guy got motivated to kill somebody.
Crazy. People who have a history of mental illness, 56-year-old people who have had history of mental illness commit violent acts every day. It happens all the time.
And there's nobody to hold responsibility for somebody else going crazy. Yep. AI didn't make him go crazy.
He was crazy to begin With. But Jack, here, here's the, here's the thing from a legal point of view, and this is why there's a, I was trying to say there's a difference between a criminal case and a civil case. In a criminal case, Jack, you would have to prove that open ai, a Microsoft are guilty beyond a reasonable doubt of being criminally negligent here in a civil, wrongful death suit.
It's what we call a preponderance of the evidence. So it's 51%. Is it more likely than not that their product's, uh, behavior contributed to this unfortunate death, to this wrongful death?
And it's a much lower bar from a legal point of view that, you know, OJ Simpson was not guilty criminally, but he was guilty civilly, civilly in the civil lawsuit to the Goldmans, Right? I, and, and I, and I understand that. I think the issue is that it is ridiculous to, to contemplate holding a third party responsible for somebody's.
So Let me, let me give you another fact pattern. Let me give you another fact pattern that's in the news right now. Let's say instead of a however old this guy was with a history of mental illness, you have a young girl who's 1516, a minor, and she confides in her ai, which the company who made this AI purposely made their, their AI characters warm and fuzzy, almost Disney like.
And, um, and she confides in her AI over 50 times, 60 times, that she's contemplating suicide. And the AI doesn't warn anyone, do anything, try to stop it or anything else. And sure enough, the girl commits suicide.
It's a real case. We discuss, discussed it, Real case. And, and, and, and I questioned whether, did she confide in anybody else?
Yeah. Was AI alone responsible For that? Is AI Alone responsible?
So let me let, let, let give you, going back to this guy again. Let me, hold on. Let me, let me play this out for you.
My wife happens to be a social worker, right? And so I asked her, I said, Bonnie, I said her name. Well, my wife's name is Bonnie.
Um, I said, Bonnie, if you were counseling a young girl and she kept telling you that she had thoughts of hurting herself of suicide, what's your legal obligation? 'cause you have hipaa, right? But what's your legal obligation?
And she tells me her legal obligation is absolutely go to authorities. You cannot, you, you can't let this person kill themselves. You, you know, you're gonna try to basically get them to sign themselves in or down in Florida, we have something called the Baker Act.
You know, you could baker act them and have them basically, you know, put, put in an observation for three days. And then if it's determined at that point that they really are a threat to themselves, they, they, they, they, they stay in. Um, that's, I mean, so substitute the AI for social worker, Except for she's, she's in a licensed regulated profession.
Does it, does a priest. Yeah. But if you're holding out, Does a, They slept in a Holiday Inn Express last night.
Yeah. But does a, does a priest have the same requirements? So there've case law on there, Does a neighbor does a does a neighbor does.
The girl's best friend does. The, the 56-year-old guys talking, Those called, right. Those good Samaritan.
There are good Samaritan laws about that stuff. And in fact, when you look at police, remember, police do not have a duty to protect or a duty to act. But there is, there is, right.
Same thing they did There, but once they do, Jeff, despite what it says on the side of the car, right? Right. Despite what it says on the side of the car, legally, a police does not Happen to be, to stop you from committing suicide.
Once thing knows into it, they do. Yes. But if a police drives by, if you tell a policeman, I'm thinking about contemplating suicide morally, we would expect them to do something about it legally, they are not required to do anything about it.
Understood. Jack, I'm Telling You as a, as a lawyer, I would be salivating to take the case of that 15-year-old girl, because Theis here are holding themselves out as confidants. Uh, and, and they're providing, a lot of them are providing therapist like responses to these things.
This Is, this is a slippery slope, Alan, that says, at what point does, does the AI violate your it's privacy requirements about you? If you say something, how does it know if you're serious or joking? It has no ability to, to judge intent.
How, how does, how does a chain professional know They have context? So, so if you watch any TV Televis, they have show. Yeah.
But if you watch any television show these days, televis about involves anything to do with suicide. There's a little label there that says, Hey, you know, if you're feeling this way, you should call one 800 or some sort of online service, or there's some sort of warning that says you should do something. And That that's the state of the art.
And that's all open AI has to do here. Right? Put in a rule that says, anytime someone talks about suicide, just put some blanket statement, accept or reject.
Don't sell my information. You know, and, and, and you, well, This case wasn't suicide though, right? This was a murder.
So there never first case about a murder, right? Well, So ault of grandeur, should we say, if they, so I hear it. So let's, let's again, let's play law school.
'cause this is what law school's like, guys, we take these cases and we play with them, right? So now, so now what you're saying is, should open AI give you a warning? If you tell it you're thinking about committing any crime, Or that you're delusional Or that you appear to be delusional in their Opinion, and that this, this is, this is what I mean by the slippery Slope at Well, what about the hacker who says, show me, show me how to make some exploit code to exploit this vulnerability.
Exactly. Illegal at what point? Yeah, but what's So, I, so Jessica, I, I, yeah, I hold open AI illegal, I hold open AI liable for that.
And I don't mean just open ai. I, I hold the AI liable for that. And I think that cross the line, Any of these, uh, social platforms and, you know, if this case, if they do win this case, I feel like it's, you know, from a social perspective, it's probably a good thing If who wins this case, If the family wins the, The wrongful death, uh, suer not the a Yeah, Because then it's going to establish, um, that other situations, uh, like teenagers on Facebook being bullied, right?
Was Facebook, should have Facebook stopped that? Well, if they, if they saw that, should they have stopped it before the kids committed? Well, we've cycled through this, the a OL chat rooms, the cesspool of the internet back in the day.
Yes. It still is. It is still a cesspool.
Are you telling us you still frequent the a OL chat rooms, chay? I don't, But I'm just saying that the Internet's in General, what's your screen name? No, I don't.
I Don't. But, but no, but you know, there's been case law around this too. Uh, here, here's the deal.
It goes back to what I said earlier. It takes the courts and the legal system years, years and years to catch up to this stuff. And by the time they do, someone's already moved that cheese.
You know what I mean? The cheese has already been pushed up. And this will do all the way to Supreme Court.
This is a one that's, But by the time the Supreme Court decides that it's moved on, I think it'll play out this way though. I think the existence of the suit will force the issue. It will become a political issue.
There will be some sort of effort in Congress to address this issue, But not at the state legislatures. Right? But regardless, and then it'll be just like, you know, the, uh, Epstein case in the sense that there'll be such overwhelming support to do something about it.
It won't matter what the president thinks. Wait a second. I feel like we should have confetti stuff dropping down.
You've mentioned it. Release the Epstein files. Okay.
Alright. Hey, we're over time on this one. What a great discussion.
I might somewhere, professor Koffler, my torts professor who wrote the book Koffler on Torts. He's probably in heaven somewhere by now, but he's smiling down. Um, we're gonna come back and we, we could talk a little more about ai, but this time, AI browsers, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You will access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back. And Gardner put out a statement essentially urging people and enterprises to ban the deployment of these new AI browsers. Because, well, they're just fundamentally insecure and bad things can happen when prompt injections are shown in these browsers and they're connected to something else.
And the next thing you know, all your data's off in the dark web somewhere. Jack has an article up on Security Boulevard suggesting that, well, this kind of misses the points and we're rearranging deck chairs here on the Titanic. But Jack, explain, Well, are they rearranging the deck chairs?
Are they shoveling the sand against the tide? Are they emptying the ocean with a bucket? I mean, this is just kind of foolish.
Um, you know, I mean, Gartner, of, of all the analyst organizations in the world, Gartner should know better than this one. That there is no such thing anymore as a non-AI browser and blocking things and banning things, blacklist, whitelist. We've gone through this time and time and time again, and it never works.
It never will work. It's too hard to keep up with the changing technology. People find a around way around it, et cetera, et cetera.
And I just, I have no idea what they were thinking when they said, let's ban something. It's just, I mean, this is kind of ridiculous. Well, um, I was Wondering, I mean, I just, go ahead.
Let me just say, let me just say one thing, which is every single issue they highlighted has nothing to do with the browser and has to do with AI in general. And it's fine to raise the alarm bells about ai, but the response of blocking browsers is just, come on. It's insane.
I was wondering what that giant sucking sound I heard was, I guess it was everyone deleting their AI browsers just because Gartner said so. You know what? Yes.
I mean, quite frankly, this ain't your daddy's Gartner. You've had a tough year. You remember what Babe Ruth said, how come you should make more than the president?
He said, I had a better year than he did. Okay. Yes.
Gar, Gartner. Gartner, thank you, Gartner. You got bigger problems to, to, to worry about Gartner.
Um, that, that's kind of, and who, look, that train's left the station. You know, the, yeah, I could just see everyone say, oh, garner said we, we, we had to get rid of our AI browser. Three people somewhere in some hole in the wall might have deleted their browser as a result.
Tracy, should we be cautious here though? Because these browsers and AI agents in general seem to be, uh, easily tricked into doing something. And we don't seem to have a lot of controls in place yet.
So how do we kinda run the middle here? You know, it's like any cybersecurity issue. It always, most of it boils down to the human.
You know, we can, uh, we can have a a, a badging system on our door. So we have, we could to see who's coming in. But if we cut and paste a bunch of sensitive data into a browser, um, uh, maybe we're asking for it.
Personal responsibility. Again, that's thing. Personal responsibility.
I really do believe that, that we all have to be, you know, we all have to be on guard. Uh, but I don't think that this should be the end of, um, using AI browser that is, as Jack has pointed out, that is not, it's not gonna happen. But Agen AI has its issues and the community has to kind of start thinking about how to solve some of those issues.
Prompt injection can happen anywhere, though. It doesn't have to be, uh, uh, you know, a an agent's, uh, problem. It can be, it can happen at many spots.
Many, many connections. So, uh, I I thought they made a pretty broad statement by saying that, that you shouldn't use an AI browser. I was, I was actually kind of giggling when I read the article.
I was like, all right, Jack has really nailed it there. What were they thinking? I But wait, if there, if there's an issue and it affects the community, don't we need a foundation?
'cause that's how we solve all our problems. Yeah, exactly. Well, you know, I I, I wrote a companion article elsewhere that basically, and I, and you know, if we're thinking about AI security, we should think about things like MCP, which has security as an option instead, security.
Well, We do have a foundation for that, Right? Right. I mean, you know, let's, let's raise the alarm bells more.
I mean, OASP, you know, OASP raised, uh, you know, a agent AI as one of their top three. And they said, well, it might be an issue. And I'm like, it's a very big issue because security is optional.
How do you get to zero trust if you don't mandate authentication authorization? It's just, you know, but here's, we have big issues. And blocking browsers isn't one of 'em.
Here's the reality. It's come up time and time again here. 90% of developers are using AI to generate code.
40% don't trust it. 65% are sure that it introduces instability into the code base, but still 90% of them use it. We have similar, similar numbers for SRE and ops and platform engineers.
This is where we are right now in our AI revolution, right? We know security isn't up to speed, up to snuff. We don't trust it, but we're drawn to it like moths to a flame.
And sometimes the moth catches fire, sometimes it doesn't, but no amount, whether it's Gartner or Forrester or, or Jack, you as an analyst are going to, you know, you could lay your bodies down on the tracks, but that train's just gonna run right over you. And that's the, and we will have better security and AI browsers and better security and AI agents when the makers of the, when the customers of the makers of those products demand it when they vote with their feet and their wallets, watch how quick it gets done. But right now they're not.
'cause we're all knowing it's some form of maybe mass hallucination, insanity, I don't know. But knowing that it is that we don't trust it, knowing that it is insecure does not stop us from using it. That's because those 40% are taking some personal responsibility to look at their code.
They use it as the basis of, you know, to get started. Right? And then they work from there.
That, that must be what it is. Chase, you're right. It's absolutely is.
'cause I know so many people who don't trust what they, what No, 40% don't trust it for sure. But they use it anyway. They use it anyways because it's a good way to get started.
It builds a framework and then they don't, that's not what they ultimately deliver to the end user, right? I mean, um, Somewhere, somewhere there is a bunch of cyber criminals sitting around a table looking at each other in disbelief going, can you see what these guys are up to? Now this is just like, how much easier do they wanna make this first?
Yeah. 60% of our users, uh, the users have, have generated code is not gonna really check it. But, you know, I'm gonna go back to what I said The beginning.
I greatest, go ahead and then I have another Factor. We have a problem with the way we have built ai. And I'm gonna say it now, like I said, I used to a complaint about agents.
I can see the problem coming. Large language models suck. They need to be more specific, they need to be more domain based, and they should be small language models that we can trust.
So Tracy is an LLMS woman. Is that, is that, is that like a new bumper sticker? Lm LLM suck.
They all Suck. They Suck, but you know what? So There's so much wrong stuff that gets generated.
Even what I'm using it, lemme just throw something out at you. I had a conversation last week with my friend Jen Zwelling, who's the now like the CTOI field, CTO maybe for Veracode. And you know, they do, I mean, they, they get to look at a lot of code from their clients and they do constant reviews of code security that from real life code being generated.
And they have been comparing all of the different ais in the code it generates as well as the CU code that gets generated. And with the latest models, which is five, well now there's five two, but five one on chat and, uh, on Claude sonnet, was it three five? I don't remember.
Whatever the latest Claude is. The, the amount of bugs, the amount of in vulnerabilities in code generated by those ais are roughly on par with code generated by humans. So just to give you an idea, it started off human code machine code, let's say two years ago.
We're at a point right now where it's about even, but make no mistake, machine generated code is, is on the, you know, what, what, what does Mike Tomlin say? Not on the upside, whatever it is. It, it, the, the arrows pointed up.
The arrows pointed up here where human generated code kind of stays the same. So if we were having this conversation a year from now, uh, AI generated code will probably be better than human generated code. The question is who is checking it?
Are we, you don't think so? Mike? Mike says, no, no, no, no, no.
He gave me a Sergeant Schultz there. Our contrera even open AI just put out a statement saying that there is likely to be more security issues with their latest open AI models. Because the thing is bigger and smarter allegedly than ever.
And there's, there's more opportunities to make more mistakes with more code generated. In other word, it's of An ai. The very company that wasn't providing a warning label before is providing a warning label for this.
It tells you something. It's because it's saying we're becoming more of a generalist. Right?
Which is my point is they don't enough domain knowledge, right? We, and, and the answer is, we've been down this road before for code and we have AI models that generate a hundred percent perfect code, and they're called compilers and they've been around for a very, very long time and we figured it out. And compilers now can generate assembly code that's much faster, much better than humans ever could, right?
And with specialized LLMs and specialized AI compilers, we will generate better and more secure code than humans can because they can operate at speed and scale that humans can't. But that's for what Tracy calls the small LLMs or the domain specific application specific code, general purpose. LLMs trained on a billion or trillion or 10 trillion data points off the internet are not going to be very good.
I, I'll take it a step further. I think the AI agents are just gonna write stuff for each other in assembly. I mean, we only have Java and all this other stuff for higher level of abstractions for humans, and machines are gonna be like, we don't need that crap.
So, But that, to Alan's point, I do believe that there, there, there's going to be a point where humans and, uh, AI generated code is gonna be pretty similar in terms of the internal vulnerabilities that they may create. But that doesn't change what's coming through the software supply chain. And we're going to be using more and more open source as we move forward.
And that always, that's always gonna be vulnerable. I, I had a good conversation out in Vegas, uh, two weeks ago with my friend David DeSanto. David used to be the, uh, chief Product Officer GitLab, he's now the CEO at Anaconda.
If you're not familiar with Anaconda, they probably have one of the biggest repos of Python for Python scripts and stuff in the world. Open source, fully open source. And, and we, we talked about that very issue is 'cause that's, that's the, the, the battle front, right?
Tracy, all, you know, 75, 80% of the code in these apps are coming down from open source repositories, whether they're container images or Python snips or JavaScript or Java or, or, or, uh, art artifacts. They're coming from open source reposts. And you know, we, we, we do have the SBO thing, so you could probably chase it back to what repo and all that good stuff.
But at the end of the day, I think that's the choke point. That's the battle front where we, we, we make our stand, we die on that hill. We, we, we make sure that if you are downloading code from a, a repo, I don't care which repo it is, you should have a reasonable expectation that that code is free from bugs and vulnerabilities and malware.
I Don't know if we can ever get there, Alan. The, the amount of code that's being, that's being used in the open source supply chain is big. Why?
Well, the amount of code being used all over, it's big. It's four x what it was. That's what do we, the numbers we see 30,000 vulnerabilities for this year, 30,000, right?
Sounds like A problem for ai. I I think the pro, which I think the problem is, is we put, we always shift left. That's an offensive, uh, strategy.
In order to trust open source, we also have a need, a defensive strategy, which means if you find something in, find a critical or high risk vulnerability running on one of your endpoints, fix it. Fix it as fast as you can, right? And we don't, we don't think that way.
We keep thinking zero vulnerabilities, zero vulnerabilities coming from the left. We don't, we're still at a hundred days plus to remediate of a critical vulnerability. Yeah, that, and Then bad guys, the bad guys are getting smarter at exploiting those vulnerabilities About 10 days, Right?
10 days. 10 days. So we got a 90 day gap, Alan, I, I'm, I'm just gonna start calling you repo man from now on.
Okay, You know what? So I would put the, I would, I think we should bring a lawsuit against the repos for allowing vulnerable code through their repo, right? Because they're claiming sort of the, what, what is it?
The five 20 rule that they're not responsible for what's in their repo that someone else put up there? Same way Facebook says, I don't, I'm not responsible for what someone else posts, Right? And now there's ways like with like, think about openness of scorecard.
You can go and, and, and check how much work that that project is doing to be compliant, right? So you can make a decision if you wanna use that or not. Again, so what am I saying?
Personal accountability, Personal responsibility. You know, Hey, you gotta brush your teeth. Got personal responsibility to pull the plug here.
Guys. We're way over time. We had too much fun with this today.
I apologize. I hope you've enjoyed the conversation. Of course, we have a lot more of great text on content following this.
We have text on tv, we've got between all the shows we've been doing and all the many, many video interviews that Mike and I have been doing, and our podcasts from Futurum Group and Tech Field Day. And there's just a ton of stuff out here for you to watch. I also wanna give you all a shout out.
January 15th is Predict Day here at Textron. You know, for the last nine years we've been putting on a show every early January where we ask some pundits experts and, and various other sundry people to come up and give us their predictions on what's big in 2020 in the next year. So for 2026, I'm really glad and proud to say we have drafted the Futurum analyst team in todo.
I don't mean Dorothy and Toto in Toto legal word. Um, to come out here and give us their predictions, we're gonna have Daniel Newman. I'm gonna, I'm gonna be interviewing Daniel on his predictions.
I'm gonna be doing it with Nick Patience, of course. Mitch Ashley, Fernando Montenegro, Brad Schrier, the whole Futurum team is getting behind this on us. I think it's gonna be our best predict yet.
Of course, AI was Techstrong's. I don't know if it's person of the year or entity of the year, but I also saw that Time Magazine made the architects of ai, the a, they chose the eight architects of AI is their persons of the year. com.
You can go on register for this. It's gonna be a great event virtual, and we'd love to have you there. That being said, I, I've never, I I have a prediction.
Well, can you save it for January 15th? No, go Ahead. My prediction is Dick Strong gang will be back tomorrow.
Okay. Mike said it, so let it be written. So let it be done.
We're out. Ms. Alan Shimel, we'll talk to you later.
Hey everyone, welcome back here to Tech Shark tv. I am happy to have our next, uh, guest on his name is Kevin Roy. He's the founder of a company called Green Banana as CEO.
Kevin, welcome to Tech Drunk tv. Thanks for having me. So before we jump into, uh, entity au author, authority Engineering, and GEO and these other kinda new things we're gonna talk about, let's talk a little bit about you, Kevin, you're the founder over here at Green Banana.
Give us, give us a sense of your journey. I, so I'm just like a, I I own it. I'm a internet geek.
I've been doing this forever. Um, this is our 18th year as an agency. I ended up, uh, having a business partner at Bottom Out about four years ago.
Uh, and we are, we're basically a full stack digital ad agency. So we tons of AV Google ads, um, geofencing, geotargeting meta, LinkedIn, uh, but we're, we're really rooted in search engine optimization and now answering optimization geo. Uh, and because I'm the resident geek for that, like I've been study SEO for my entire career, and that is, well, to get excited Chow Gt and speak a lot, things like that.
Excellent. And so Green Banana's been around 18 years, you said? Yeah.
Yeah, we've been around a long time. Good for you. I mean, look, I'm doing this, you know, I'm, I'm the founder of Techstrong and we started in 2013.
Yeah. So we we're 12 years in, but, um, that's great. It, and it, you know, it's a great, uh, it's great to be able to have a business that has legs like that, right?
So are most of your customers like kind of local or you help people all over the world or We, we have clients. All, most of them are in the us. We have some in other countries, but 99% of our clients are, are in, in the United States.
And I always jokingly say like we have every type of client, but adult. Like, we have doctors, lawyers, we have FinTech, we have biotech consultants in the United Nations, we have defense co directors, we have, uh, um, aerospace, um, we have financial technology, we have education. Um, I have people that sell beef jerky and really expensive pajamas.
And um, uh, like then we have HVAC clients and insulation contractors and chiropractors and doctors and lawyers. So it's, people hire us because we're, we're a data, gee, we're good at ROAS returning, you know, getting a, a good return on ad spend. It's very rare someone comes in with a brand plan and has us do that.
A lot of brand planners, designers hire us to get their marketing to work. Absolutely. So, Kevin, look, over the last couple years we, we've seen a drastic sea change in the SEO business, right?
So here at Tech Strum for instance, we operate, I don't know, nine to a dozen different websites. Very niche, DevOps, security, you know, cyber, uh, cloud native, very geeky, very focused sites, communities, and you know, we all ride that Google algorithm wave where they change the algorithm on SEO and all of a sudden our traffic goes down, but, and then we figure it out and just by the time you figure it out, they change it again. And it's like that constant cat mouse came.
But, you know, things have changed with, with AI and generative AI and and so forth. The fact of the matter is, a lot of companies like mine are not getting a lot as much traffic from Google as they used to. 'cause Google's keeping more of that traffic on their site, right?
They're, you go to a Google search now and, you know, you get your Gemini kind of, uh, findings, Gemini results, then they have a whole bunch of sponsored results. And unless you're playing that game, you, you know, it used to be you fought to get on the first page, Right? Correct.
Really hard to get on that first page. However, you know, God, God gives with one hand takes with the other 35% or more of, of, you know, search traffic today is now coming via AI portals. It seems right from some of the AI models out there, uh, in the LLM.
So, you know, the industry has sort of pivoted in saying, okay, well SEO is not what it was. We could optimize for what's there, but it's just not there as much. But we wanna optimize to take advantage of, you know, chat GPT, which is probably the, the 800 pound gorilla.
Mm-hmm. But there are others, right? There's Anthropic and Prometheus and, and others that, that are, are part of it.
From where you sit, what are you seeing? Is that what you're seeing or? So I, so I, I'm, I think I, I'm gonna agree with, with Chad, GPT being the, you know, 800 pound grill.
I think Gemini and Chad are neck and there, there's a, there's a race. There's a lot of really smart people like Dennis Hadas and, and once they brought him from, uh, deep Line and Google has, they've, Gemini has made some significant updates. They just had a big rollout on the 18th, uh, that changed the way their algorithm works.
Uh, we do see across all of our clients a drop in organic traffic, but not a massive drop. So for B2B clients, um, you have to remember that with the answer engines, you're asking a question and getting a small soundbite of information that when you get all of your answers questions answered in that soundbite, you don't need to click onto the, so in a B2B, um, the website or a B2B information, you typically need more. So people are either clicking those and going to the website or just googling the name of the company and, and going to the website to get all of that information that wasn't answered in that little sound bite.
Um, consumer is getting hit a little bit harder with that, but we're still seeing a pretty good amount of traffic coming from organic. But thankfully, a really healthy organic base is what gets you, um, it's basically 80% of the work to get you in cancer A absolutely. So Kevin, what, what is, uh, you, you've developed something, you're calling entity authority engineering.
So there's, you're, you're we're hearing answer engine optimization, generat and engine optimization, um, LOM ranking, and there's a, there's, there's a lot of confusion on, on what to call it. We are calling it, um, the end of entity engineering. Uh, because of, you know, we think that it encompasses both generative engine optimization and answer optimization.
Out those two words are not interchangeable. They're actually two different things. So in order to get right in answer engines, they need to trust you, which is kind of ironic because a lot of people are coming up content that answer engines are actually writing for them.
But what the answer engines are trying to do is to, is to say, who takes ownership of that and how can we back that up? So they're looking at who the author is behind this content. They're looking at what other websites or high authority links are, are pointing back to the site.
That's called entity stacking, which is answer engine optimization. It's the trust portion. The generative engine optimization is how your, how basically how your website is formatted with schema, with questions and answers that are really easy, um, with information that's connecting.
So think of answer engine optimization as the resume in an interview, and your actual interview is generative venture optimization. So those things two together way you're looking at it. Yeah.
Yeah. So they have to work together. So one without the other, you can have a great website, but with, without the trust of the models, they're not gonna refer to you.
If you have amazing trust and no content, they're not gonna know what to refer to. Right. So you, you kind of need both.
Absolutely. Devin, look, there was a time, I don't know, five years ago, um, 70, 75%, maybe 80% of the traffic to our tech strong sites were coming from, uh, you know, organic search as we called it. Right?
And, and 99% of that was Google. What percentage would you say of search is coming via, uh, the AI models at this point? So, And it's hard 'cause Google uses GEM and AI realize.
Yeah. So the, the, the hard part of that is if people are getting the answer in their AI model and they're not clicking, how are we gonna know if it's an accurate percentage? So it's really, if you look at the number of clicks like we get from chat GBT, it is like 50, 60 a week.
It's not a lot. Um, but it doesn't mean that we're getting mentioned a lot more. So there are tools to figure out, uh, if, if you're being mentioned or you're being cited, so you can see how many people are actually looking for you, or how many times you're being mentioned in answer engine models before they click to the site.
So it's a, it's kind of like a tough, it's answering that question would almost be inaccurate because there's a lot less, uh, people that are coming from the answer engines, but it doesn't mean they're not seeing, they just might be getting everything they need in the, in the response before clicking to the website. Does that make sense? Yeah, no, perfect sense.
You know, it, and it makes it hard. I'm wondering, look, we're, we're a tech company. We cover the tech space.
I get all this, this all makes sense to me. I'm not a lawyer, a doctor, a dentist, or some other sort of, you know, local business or even not even a local business sells, you know, online, but who's kind of savvy to tech, let's say. How are you finding, explaining all this to them?
So I, I think, well, number one, we're using tools to figure out the baseline if they're being mentioned, the answer engine. So we can, we can talk, uh, intelligently to some of the gaps that they're having or some of their reasons that they are showing up or not showing up. But one of the things that we do is we try to look at, like, there's the, you know, call law wrong.
What are some of the things that anybody can do to start getting mentioned in answer engines? And two of 'em right off the bat when I was talking about the, the, the trust component of it, or the answer engine optimization component is when you're putting content on your site, make sure there is an author that is taking ownership of that. And then you, what you do is you create an author age that, uh, mentions all the things that you've either authored or if you've been in a podcast or if you've been mentioned something, you put that on your author page that links to the, um, the article that you write, right?
So the article that you write, I'm sorry, it links to the author page. And then what I recommend people do is you put your author bio in your LinkedIn page and link it to your author page because LinkedIn is a very high trusted source. So you're amplifying that trust signal, right?
So the so that, number one, the easiest thing to do is to take credit for the content that you're writing, that's the entity, um, or the answer authority component of it. The second thing that you can do is you can actually, um, double, if you're a logo business and you have reviews to your website, what really, really helps you get mentioned in answer engines and in SEO is if there is a keyword that describes your service and or a location of where you do the business at, if you can get that in the review, that's really helpful. What we all know that's next and possible, it's really hard to get a review.
So forget about asking somebody to use words that you want in the rebuke. However, you can respond to reviews and Google treats them equally. So you can say, really, as corny as it sounds, thanks Alan, I'm really happy that you thought that we had the best pizza in Boston.
Please come again. Um, that, that significantly helps. So that's the, uh, the answer component, the generative engine optimization component.
The simplest thing to do is soundbites. So think of when you are reading a newspaper and there's a little call, you know, they make text base smack in the middle of a page. It's the call out, clip the call out, or the main subject at the very top of the page.
Uh, and so those simple things that you can do will help you start gaining mento and answer. I love it. That's excellent, excellent business.
Um, Kevin, for people who maybe want to get more or maybe look into Green Banana helping them, where, what's the website? com or, um, this works in Google. It does not work In Answer, if you go, if you Google, I just met Kevin on page one, number one in Google, but if you say, I just met Kevin in chat, it's gonna say, who cares?
Big deal. Look, we can't, we can, you know, right? I try to tell my wife this too.
I, you know, in tech, people know me and, and, and tech stroke. I'm side of tech, not so much. Um, Hey Kevin, thanks for coming on here and getting, giving us a quick little lesson in, in, uh, answer engine optimization and generative engine optimization and entity authority engineering.
For people who want more information on this, go check out Green Banana, SEO, or like Kevin says, go on Google, you know, and, and ask for Kevin. Uh, keep up the great work. This is ri Thank this, this whole industry right now.
So fun. I mean, this is the most excitement we've had in this in a long time, right? I know, I know.
I think it's the golden age for SEOs. I I really is. It's fun.
Yeah, I know. And a lot's, it's a golden age for a lot of things in tech, man. Yeah, good stuff.
Kevin Roy found a green banana, SEO here on Techstrong tv. We'll be back in a moment. Hello and welcome to the latest edition of the Techstrong AI Leadership Inside series.
I'm your host, Mike Vard. Today we're with MUAs Udin, who's the CEO for El Lithian ai. And we're talking about, well, the impact AI is having on doctors in healthcare.
Muus, welcome the show. Thank you for inviting me. All right, pleasure Being here.
I think everybody kind of understands that maybe doctors are overwhelmed and there's a massive amount of paperwork, and they probably don't get to spend as much time with patients as they like, and they're certainly not all out in the golf course. So what impact are we seeing here with AI and how is it changing the way doctors and patients interact with each other? First of all, AI has really changed the outcome of how doctors are gonna practice now and the future.
The biggest burden for doctors is like multifold. First of all, when the patients come in, they have to have the same, uh, we call it intake, which means that doctors have to interview or the nurse has to interview the patient. Same questions every patient they have to ask over and over, which, cause they call it talk fatigue, and doctors don't wanna see a certain amount of certain type of patients per day because of the burnout from, from the beginning of asking the same questions.
Then they are usually used to be there where people will simply type the notes as they're with the patient, they're doing all the stuff. And as soon as the patient needs, now they have another burden how to close the notes. So they wait and go home.
And it's called P time. And typically about three hours a day, they spend after hours just doing the notes. What the AI has done is, initially it was a scribe where the doctors can actually talk to people and it will take the ambient listening.
And after the doc, the visit is done. The doctor will come in and basically look at the note, edit the note, and then send it to the EMR and still go home and go over the stuff, and then close the saves them. Time is documentation is more thorough, and actually they can look into the patient's eyes while they're talking to them and making sure they're taken care of.
The third, the third part is what we come in and what we are looking at the future coming in is automation all the way through patients from home, they sit down, they take their time, the AI will interview the patient, for example, is called intake, the HBI, the technical term history of present illness. How long did you have it? Do you have a chest pain?
Do you have arm pain, arm? Do you have nausea, vomiting? All the questions doctors will ask all the time.
It ask those questions before people come into the clinic. And once they're in the clinic, doctor already has the pre pretty good idea and it such the agenda, right? So doctor, you go to the doctor now, they don't have to ask all the questions.
So they start, okay, these are things we need to discuss. So it gives doctor more quality of time with patient, better patient care, better outcome. And what else is there in the AI is like right now emerging?
We are, the first one to launch is the conversational AI scribe. What it means is, as doctors are talking, it is transcribing a notes slide, not ambient listening. It is generating a notes as the doctors are going through the visit, ordering labs, all the stuff, uh, CPD code, which is like diagnostic coding.
All the stuff is happening as the visit's unfold. So it gives really doctors more time to focus on the patient, not worrying about what's gonna happen. Should I remember this thing?
I'm gonna go back and look at the notes again. So they actually interact with the patients more thoroughly. And once they're done, basically there's a magic added there where people sim doctors simply say, hi, by the way, uh, didn't capture this thing.
I saw his x-ray and x, Y, Z was normal. So it will, within seconds, it'll just go into the notes and doctors pulls the note. So there's no period time, there's no burnout.
They call it talk fatigue. And also there's a click fatigue. By the way, do you know how many clicks a doctors do a day?
Just a curious question. No idea. Um, Service, say about 1700 to 4,000 clicks a day.
And what doctors call it click fatigue because they have to go navigate the whole technology, click here, click there, and it's like a racking thing. And so one, you have a one window platform it all, so you don't have to do any clicks. It just simply shows up.
So that all sounds better for everyone involved. But how do we get to that nirvana? Because I feel like it's unevenly distributed.
So we say, and no one seems to know exactly what it's gonna take to maybe get this into the hands of every doctor. That's a good question. Absolutely, right.
Uh, doctors by nature for technology, they, every time there's a technology, they're scared of technology, they think it might be something which has, they have to do more. So adoption usually comes in from the word of mouth. I'll give you an example.
Uh, there was a, there's a clinic in the Midwest and the doctor said, it sounds too good to be true, so I need to talk to another doctor. So we arranged a doctor who's already using the platform, he calls the doctor, and the first thing he said, are you sure it's real? It sounds too good to be true.
Finally it happened. They like it. So adoption is in itself, technology, uh, doctors that I'm not very, they wanna know how much time's gonna disrupt me, but it's a pretty good thing.
Eventually, every, eventually everybody's gonna be adopting this thing, but they're not, there'll be a lot of opportunity for other folks. Everybody can streamline the process. So doctors can be doctors.
Their job is to prevent, diagnose and treat, not be a technologist, or figuring out all the technology, how it fits it. That's a future and it's coming. Mm-hmm.
So we've all seen AI kind of makes mistakes from time to time, and they hallucinate. And of course, humans make mistakes too. But in the case of ai, will there be, say, another set of AI models that's checking on the work of the original AI to make sure it's right?
Or how do we kind of put the guardrails in place that we need? It's a very good question. Medical field is one of those fields where you have to be on.
So any model which is trained on the internet would always hallucinate. What we have done is put the guardrails and everything, every model is trained by doctors. So they wet the process and they fine tune the model.
So they're like strong guardrails, which are needed for the patient safety as well as for the accuracy of the document. So it takes time, but it does not have the scenario because it is trained by doctors. It's, there's nothing, it's not putting the data from the internet to give answers.
So we have to put guardrails in place. Right. Do you think also over time it might become possible to identify trends?
And I ask this question because, you know, we have seen over the years where, um, multiple patients in a specific region wind up having the same issues and it could be caused by something in the environment, but nobody noticed it for years because years nobody had any ability to compare the notes. So, you know, as we move along here, will we be able to kind of maybe identify clusters of issues more readily because we're gonna apply more analytics? Absolutely.
There's the, the reason is there, the data is there. Do you know how many ICD 10 codes are there? And CPT codes doctors don't usually use.
Take a guess how many IV We just got diagnostic codes are there. I want to, I'll put that in the thousands, 67,000 i three 10 codes. And the new one, which is an international standard, which is, it's called nomad 350,000 codes.
So 350,000 codes for explicitly each problem from the in population health, you need to capture data with precision. For example, if you have a pain, is it a back pain, left arm pain, which area the pain is, or throat or all the, we call it co-morbidities, which means what are the symptoms are the similar symptoms. And as CMS has a pretty good tool where you have to upload the data.
The CMS, the problem arises. Doctors can't remember all the codes CPD codes. So they use generic codes because nobody has time to go through 67,000 codes to find out which one.
So AI is actually capturing, or we are capturing all those codes as a visit unfold. So you can do the really fine I three can codes, which are diagnostic codes. And when you see a pattern, pattern recognition, all the clusters, it'll be easy to manage because you have the right data to make the right decisions.
Mm-hmm. Problem before was people were not doing the coding because nobody knows that many codes. Right?
So what is a reasonable number of patients for a doctor to have if they have AI tooling? And I'm asking the question because we do have a shortage of, uh, medical professionals, but at the same time, even with ai, there's probably a limit. But, you know, have you seen any kind numbers or anything that kind of suggests best practice here?
Uh, it depends on the doctors. Some doctors would like to have more time available. Some doctors, uh, I will give you an example as we talking earlier about the HPI or the intake, what the patients do.
'cause it's, it is very far and what we have seen of the 12,000 initial interviews we have done, it's about nine minutes. It takes about nine minutes of interview. So that nine minutes is safe for the doctor.
Now doctors can use that time for better, better care of the patients, or they can reduce the time and see more patients. We provide tools to make life easy. Then it's a doctor's decision.
They can easily see the uptake about 30% per day. They can see more patients depending upon their will at, if they're willing to do it. It's no secret there, there are a lot of lawsuits involving medical practitioners.
But what we get to a point soon where maybe the insurance companies are gonna require the physicians to have AI so that A, they can have this documentation, but b, maybe it'll ultimately reduce the number of mistakes that are made. I think they should look into it. What we are doing is we got a license from a ME to train our model exactly doing that.
But it captures every single nuance. And it actually ref gives a reference from a MA on the CPT code, which is their proprietary models for billing. It actually points to exactly each note where it was drawn from.
So the chances of error or insurance denial would be very low because it's, it is audit defensible. It captures every CCP D code. It captures i i cd 10 codes.
It gives a rationale why the decision was made and why this thing is picked up. So all the nuance, which is in, uh, lemme give you an example. About 30% of claims before submission.
There's a biller who doesn't see the doctors during the notes, right? So a biller has to go to the doctor, ask them, please, can you add this addendum to have the proper billing? And it's back and forth is about 20 minutes spent per patient.
And here we have, uh, about 17 seconds. The doctors is done within 17 seconds. It generates a notes and it gives you a rationale.
And if they wanna do something, or by the way this person has, we are hyper uh, hypertension, which means there's over that one, it'll automatically fix all the problems and generate a node, which is like audit defensible. So these technologies are, are now being happening. People are adopting it.
And it is amazing. And I think insurance companies would follow those things. Then they should, it will save money to the insurance company and it will save money overall in the healthcare system.
That's the biggest expense they have is the insurance company. What role will governments play in this conversation? Are they likely to come to a similar conclusion and say to people, Hey, if you're gonna be in the healthcare space, you gotta use ai?
I think that time is coming. There are multiple reasons. First of the cost of healthcare is rising.
So much doctors get paid about most time, I don't want to use the numbers, but 25% of what they produce, the rest of staff goes into support staff, which is shortages, receptionist, billers, all the stuff. And anything which is repetitive is being taken care of by the ai. So there would be a substantial reduction in per visit cost of overhead.
So government, eventually, CMA, uh, CMS, all of them, they will realize that maybe we will, they will restructure the billing structure too. It will save money to the system. Will it take tension out of this whole interaction?
Because everybody usually involved, unless it's say, a checkup. But if it's some sort of condition, everybody is kind of stressed. And a lot of times doctors are meeting people probably on maybe what's one of the worst days of their existence.
But can we kind of get it so that the, the nurses and the doctors and everybody involved, um, can spend more time kind of focusing a little bit on the, uh, uh, emotional health of the patients. Because I think a lot of the times that's as much of the issue as, as it is everything else. And it feels like, to me at least the paperwork just gets in the way.
Absolutely. You're right. And there are a lot of, it's a broken system.
Everywhere you look at it is broken for some reason. Uh, when CMS, they came up with the, uh, that you have to E emr. So they came this techno it people, they're really good at designing things, which are very complicated.
So now what doctors did, instead of practicing medicine, they end up juggling papers and all the stuff. And still it is like, one thing I'll tell you, a hundred percent of time, a hundred percent doctors have their own workflow because of those juggling of the technology, which is like older than, uh, I guess Windows 95. So there is that old.
So if you have a centralized system, uh, which is gonna happen because with the fire, you can pull data patient data from anywhere. We, we can have the contextual summary to each person what their needs are. It'll generate the north.
So doctors can be more human everywhere without emotions. There's no healing. Emotional attachment is the important task of believing in something where the doctors care about it and, and making people believe it.
And it is data driven. It would not be something that is data driven. It's honest, and it will give doctors the tools they need to make decisions faster and help the whole system move faster towards a better outcomes for the patients and the cost of delivery.
I think that's the future and it's gonna be great. Right? Of course, there is no conversation about healthcare that doesn't come back to, in one way or another, cost.
Can we take cost outta the system? And do you have any sense of maybe how much of the cost of healthcare is really tied up in these kinda convoluted processes rather than the actual care of the patient? I can tell you about, uh, just a medical side of it.
There's a lot of waste switch and the drug systems, PBMs have their own cutbacks and everybody's working on it. I know a company who was transferring the whole kickback back to the patient to produce the cost of drugs because of ai. They're building powerful tool where patient can actually buy the same drug at the lesser price than the insurance company reimbursement.
So there are things which are coming up so people don't have to worry about if it's insurance is there, I have to pay only. Uh, sometime the copay is more than what the price of the drug is. You won't believe it.
But you know, I mean, GoodRx is one example. They're doing it, they're giving a coupon, which is cheaper than the, you don't have to pay the copay to simply buy it straightforward. And their technology is coming up, which will solve that problem.
And that will bring down a cost for a lot. Another thing where we think it's gonna really make a difference with the data, as you were saying, the data clusters, uh, that would probably be where you have so much data available of is this test necessary based on the total population data? Right now, it's like every time there's a protocol, this thing happens.
You have to run those like high expensive tests when in goes to insurance, insurance, deny it. So when you have a cluster of data available, which is justified for reasoning, you would do the testing, which where is appropriate. And the probably insurance company would see the value of doing the testing sooner than later for the pre-authorizations.
Overall, the system will benefit from the efficiencies of bringing all the data together. For example, you don't have to go to different doctors just for one problem and then another one when each doctor has the comprehensive in look into like all the things which have gone on your life. So it'll make the decision making better and faster.
And whenever things are better and faster, they get cheaper. Technology always get cheaper. It has been there and it's always been there.
If the technology is cheaper, so will be the price of healthcare delivery. That's what I believe. All right folks.
You heard it here. There's of course a lot of fear and interpretation when it comes to ai, but there's also a lot of instances where AI is clearly gonna be a force for good, and this might be one of them. Hey Mogas, thanks for being on the show.
Thank you. Appreciate it. And thank you all for watching the latest episode of the Textron AI Leadership Insight series.
You can find this and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey, good morning everyone. It's Alan Hummel and welcome to our day two coverage of AWS Reinvent 2025. We're live at the win, uh, right here in Las Vegas, covering reinvent.
And, uh, I hope you had a chance to look at some of our coverage from yesterday. We had some really great discussions. We had a lot of analysts, a lot of different AWS partners.
We hope to have some AWS people, I think we have scheduled later this afternoon as well. But let's kick off our day with what, for me personally, is a highlight. If you've ever watched our event coverage in the past, this man may be, uh, familiar to you.
My friend David DeSanto. David, well, if you know David, you know this, but David ran product at GitLab for five years, Uh, three and a half years and a years CPO and yeah, two and a half before that. Yep.
So you're either there about five and a half, six years. Um, always a really smart guy. I always a great interview.
He loved talking with him, but he's not here. This is not David Desto of GitLab anymore. This is David DeSanto, I'm proud to say the CEO of Anaconda.
David, first of all, congratulations man. Yeah. I'm really happy for you.
Oh, thank you. Yeah, I, uh, truly excited to help Anaconda go into their next chapter. Absolutely.
You know, I I, I didn't hope didn't embarrass you or anything like that, but I wanted to talk about the GitLab experience because for our audience, which is DevOps and cloud native mm-hmm. And cyber and so forth, that, you know, GitLab is a, is an important company in the ecosystem. Um, and you were an important person in taking that vision and running with it.
Tell us how you wound up at Anaconda. Yeah. So first, yeah, it was a great run at GitLab.
We saw the company grow almost exponentially. It was less than 300 people when I started. And my last day was over 2,600, right?
And so, uh, the journey to Anaconda does start with GitLab. Going to GitLab. I re-embraced the open source community in a way that I hadn't since ICSA labs many years before that.
And that time was great, you know, uh, our first conversation was me coming out and saying like, we are going to add security and compliance to GitLab. I remember that. Yeah.
And then, uh, the last quarter I was at, that's part of their revenues over 53% of it. So it was a really great run, great company cheering them on. Absolutely.
But yeah, I was ready for my next challenge. And so when thinking about what I would do next, I explored, do I wanna stay in the DevOps space? Do I wanna go back to security?
And I realized I could do security in AI all in one place. And that was Anaconda. Aha.
There's, there's the word, two minutes in, and we've mentioned ai. Yep. Um, Well I think I said this once before, but you can't spell David without ai, So That's true.
So yeah, This is true. You haven't mentioned that one. My, My wife did say, I have to stop telling that joke, but Well, look, we've got a new audience here.
You got a new title. They may not remember it. So David, some people in our audience I'm sure are familiar with Anaconda, but there's plenty of people who aren't.
Let's, let's start real foundational and build our way up. Give us the Anaconda story. Yeah.
So Anaconda came out of a consultancy. The two founders of Anaconda had a company called Continuum Analytics, and they were doing consulting work for data science within the financial services space. And what they found out was that they were building new Python packages to support the work they were doing.
And they decided that, hey, this should be a product company. And so they started Anaconda, the first product's name was Conda. And that's what a lot of people think of that provides thousands of trusted, secure data science and AI packages for Python.
Uh, but the company has continued to grow beyond that. And one of the reasons why I joined is the story that they are currently on. Anaconda can help you with secure python development, but we do so much more than that.
Uh, earlier in the year we launched our AI platform that helps you apply security and governance policies to how AI applications are being billed, really. And, and the, yeah, the most recent, which I'm the most excited about, I cannot take credit for it 'cause it, you know, came out I think three weeks after I started. But, uh, our AI catalyst component of that platform, what it does is provides a curated list of open source models that we have validated or secure.
We include the lineage of where they came from, how they were trained. We Oh, I love that. Yeah.
We rate them on performance and that could be in different quant sizes. And we also then give them the guardrails to make sure that it operates as best as it can. And so what really excites me about it is we already helping people run inference, and it kind of starts a desktop app before we became a platform and now a, a SaaS offering.
Mm-hmm. But the cost to run AI models as part of development is very expensive. Like I learned that when I was at GitLab.
Right. Um, and so what we've done is also make it possible to run a micro in inference on the developer's laptop. Wow.
Which then is that same model that needs to, so You don't pay the token penalties. Exactly. And then when you're ready, we can see what you did with the model locally and tune as it gets deployed into production.
So, wow. Yeah. The best way to describe it is, you know, what a GitLab is for DevOps andana kind of is for AI native development.
You know, it's funny you mentioned that term. I was, I was out in Brooklyn actually a couple weeks ago for this AI native devcon. There's this whole burgeoning community, you're probably aware of AI native development, uh, uh, guy Ani from Snyk, who's now, I forget that Tesla is his new company.
They're very active in that community. Um, and I, I went out there, I was blown away. It re it reminded me of going to a DevOps days 10 years ago.
Yeah. Right? That, that same tinkering, geeky we can make, I love playing with it kind of stuff.
And it was, it was a, it's a great community. Um, let me just kind of shimmy eyes this for, if you don't mind. There.
There you Go. So we, we've got Anaconda started as a company providing services on Python scripts And helping companies with their data science development. Yep.
Hence the Python Anaconda connection. Exactly. Okay.
It then shifts to more of a product model, but it's an open source product model, which is still open source today. Yes. Oh, correct.
Yeah. We have a very healthy, free offering. Mm-hmm.
Uh, it allows people to get in the door using Anaconda and mm-hmm. One of the things that really blew me away as part of the process to join was that 95% of the Fortune 500 use Anaconda today. Really?
Yeah. And we have over 2 million, uh, community contributors. That's great.
And 50 million users. 2 million contributors, yep. Code, Yeah.
Code contributors to the open source Wow. Codes. Wow.
Yeah. It's actually a really great story. Uh, one of the founders is, uh, Peter Wang Uhhuh known very well in the open source community Sure.
And within the data science community. And he's still an active part of the company. Mm-hmm.
Um, you know, he and I talk about what we wanna do next together. Yeah. And that reach that we continue to have is because he's always out meeting with customers, potential customers.
Two weeks he's in Boston for a, uh, meeting around how do you set some AI standards Yeah. As part of development. And so we continu to lean into that because, you know, that is really the core of the company to your point.
Yeah. You know, we started as a package manager condo, but now we have the AI platform and we wanna allow people to still come up, get used to using it, get the value out of it, and then want to come and then join and, and pay for either our shorter tier or enterprise tier. I love it.
I'm gonna jump into what the store, the, the different tiers are in a bit. I wanna come back to what you were mentioning this newest offering that you're so jazzed about. Yeah.
The AI catalyst. Yes. The AI catalyst.
Now look, you mentioned package managers. It's been a rough couple weeks for package managers, hasn't it? It has with this shy ude and, and all of that.
It sounds like this AI catalyst may be just what the doctor ordered, right. If, if I'm a user mm-hmm. Of of package package manage, uh, package packages, I wanna make sure that my package manager's giving me something that I'm not Correct.
Introducing malware into my, my ecosystem. This only works though with the AI models that you're using, right? The AI packages, if You will.
Uh, yeah. That and all of the con packages. Okay.
All the con Yeah. So because we still use the condo package manager, um, we have a very unique build system for building all the packages we provide. And so we're able to actually take things apart, fix the vulnerability, and say in the binary part of the package, put it back together, and then make it available.
And so a lot of people think of Anaconda first as a trusted distribution because we're providing, you know, two thousands of Python packages that we know are secure and are able to scale. Now. I get it.
Yeah. I got it now. I, it took a little while.
Sometimes I'm slow on the uptake. Oh, no. And, But yeah, if you think about it, there's then that natural transition into the platform, right?
It's one thing to start your development, but it's nothing thing to get that prototype into production. Absolutely. And, and look, I, you know, just quite frankly, it is, you know, we live in a world of, let's call it Frankenstein software, where software is more assembled than code written, if you will, at some level.
Right. And, you know, and you, you, your security background, you know this, we talk about software, supply chain security all the time and, and how stuff, you know, SBOs mm-hmm. And what have you.
I think the biggest weakness in our system today is the software and packages that we're downloading from all these repos and, and, and depots and what have you. So, you know, the fact that you're do, you're on guard here with the condo package is, is a huge thing. Give us an idea of scale if, you know, you may not know this off the top of your head, but like how many downloads a day, a week, a month?
Yeah. I don't, don't know that off the top of my head. But Kanda is hit all the time, almost 24 7 with people pulling packages.
So very healthy community. That's how we can have 50 million users really, uh, yeah. Using Anaconda every month.
The thing that is the most incredible to me is what you just touched on. And this is part of that why I joined in the journey. Uh, you can only do so much with the actual packages themselves.
Yeah. But when we're talking about the platform, there's like this starter, which is kind of like, hey, a team's getting together. Uh, but the business tier actually provides what you're talking about.
It provides an AI bill of materials, can track vulnerabilities for you. Uh, we're working on how to help auto remediate those as well. And so the customers that end up on a thing like the business tier or the platform, they're getting, uh, full visibility into their AI life cycle.
And that's really powerful. 'cause as you said today, it's very common that vulnerabilities will sneak in some way. And we're heavily reliant on packages that we've not created.
We're reliant on our IDs to be secure. We're, you know, worried about the things that happen after the code is merged. And anacon is just in a really great spot to help with all that.
You really are. You're right, you're right at the, the nexus, if you will, of, of where all these come together. I love it.
Now you mentioned different tiers. Mm-hmm. So obviously there's probably a free open source tier where hey, it's open, it's open source, have at it.
Then you have, you mentioned the SaaS model. Yeah. So the product, uh, you can self-host mm-hmm.
com. Mm-hmm. Um, but yeah, the big difference is not necessarily whether you're hosting yourself or using our, our SaaS offering.
It's really about the free version gets you up and going, if you're an individual developer provides you a lot of power. If you now wanna operate as a team and start having some structure around it, you go into the starter tier, which starts to introduce a lot of that. Um, but when you're ready to talk about AI build and materials security and governance and having policies that prevent malicious packages from being installed, then you end up on the business tier.
And that's where all that security and compliance functionality is, including dashboards, policies you can create and so forth. I love it. Um, to swarm an old school open source guy, what pers 50 million users is a crazy number.
Yeah. You may not know this, you may not be comfortable even saying it. It what percentage of those are just pure free open?
I mean, usually it's 98, 90 7%. Yeah. Yeah.
So there, uh, a large percentage of it is that open source community. Sure. Um, but that's something that's very important to us.
Sure. It is. You know, what I learned, uh, working with Open Source, I'm so excited to be, you know, leading a company that has open source first mentality is that like you get more value out of that free tier than you could if you tried to bundle that up and put into a paid tier.
And it's ultimately because you get all those contributions, uh, you actually are able to get onto the community, be it events like reinvent Yep. And have conversations with the actual builders and doers. And that's not something that commonly happens if you only start with a paid option or you're not open core.
I love it. Let's, um, let's talk a little bit about Reinvent. You mentioned it, we're here.
Yeah. Um, is there like a formal partnership? You know, what, what are you doing at Reinvent?
Yeah, so we're in Booth, uh, 1327. Mm-hmm. So if you're at the show and you wanna check it out, you're Watching this live now, you wanna run down there, go run down Run, uh, before we run out of giveaways and swag.
Right, exactly. Uh, some really great swag. But, uh, in our booth we're actually demoing the AI catalyst offering and we're showing people all the other things that Icon can do that are not just, you know, being a package manager, uh, but to speak to the partnership AI catalyst this new com Yes.
Part of our platform that launch exclusively on AWS and we joined, announced it yesterday. Oh, great. Uh, and it also included that it's now available in the AWS marketplace.
You can go and buy it yourself. You don't have to go through all the hassles of like, the steps to get to that point. I Love it.
And so yeah, that's a great example of the partnership mm-hmm. And spill right on top of AWS but there's so much more we're looking to do with 'em. Uh, you know, we're looking for better integrations into Bedrock customers, like using Anaconda with SageMaker.
So getting a nice embed story there. Yes. We were just talking about SageMaker this morning on Dextron Gang, And so yeah, the partnership is great, but we're just gonna keep on building on top of it because they're a really good partner.
You know, I've worked with them across multiple companies and yes, they're always exactly as great as they seem and that's really great to have a partner like that. Absolutely. You, you know what's interesting is I I I, we were talking off camera and I, I mentioned, you know, this year's reinvents a little different.
It's very AI focused and everything else, but I'll tell you what it is focused on, it's laser focused on developers. Mm-hmm. Right.
They really are kinda reestablished because when you, you know, you've been around, you know, I know it was the developers who made AWS it was those guys whipping out their credit cards and, you know, building spinning up instances and, and doing stuff that, that made AWS what it is. And it, there is a renewed focus on the development process. Of course, AI is changing how developers develop, and it sounds like you're, you're responding to that as well at Anaconda, but make no mistake, that's the focus here.
Right? Yeah, no, what I would say is, I, I took away a couple things, uh, just from Matt's opening keynote. Yes.
Uh, the first is, it's all about the hardware. And I think that's something that people don't always think about. You know, we were talking, Well, that was supposed to be the thing about cloud.
You didn't have to worry about the hardware. Yeah, that's a good point. Uh, but I was gonna say the, uh, you know, when you're talking about ai, it kind of starts at that, right?
Yes. You gotta have the right, it's Made hardware sexy. Yeah.
And so to see that lead off with mm-hmm. What they're doing to make it a lot approachable for non-developers to get into an environment and know it can work was really good. Uh, definitely the AI lean in mm-hmm.
Uh, was very, uh, prominent as well. But the one thing I would say, uh, and it, I can't believe I'm saying this, like it's my first reinvent, you know, but what it feels like is like if you were to take, uh, a cube con, make it si significantly larger, Four times the size, And it's only about the developers. Yeah.
Like that's the, the vibe here. And it's actually great. Yeah.
So this is, I don't know how many, certainly since COVID is the fourth probably, uh, since COVID alone, um, this is pretty much it. It's, it's, it's a, I mean, you know, it's nice. CubeCon is the, like a perfect size.
Mm-hmm. 12,000, 14,000. It's big, but not too big.
It's a, it's kinda like building a company, right? Mm-hmm. You could build a company that has 10 million, 15 million in revenue, and you have one kind of management team.
You go wanna build a company that has 75, a hundred million in revenue. It's a different management team. Mm-hmm.
You wanna go build a company that's IPOing, it's a totally different animal. It, it's the same thing with conferences. You get a conference of 60,000 plus people.
Mm-hmm. You, you, you know, hyperscale, it's, it's, it's about scale and they do a great job with it, considering everything that's going on here. Yeah.
No, and I would say too, for those who are watching this and are here but haven't really like, gone over to everything that's going on, it does not feel like there's that many people here. Like, they've done a really good job keeping Well, it's spread, spread out so forth. Yeah.
I, I agree with that. You know what, David, we didn't even mention the website, how to engage. Of course.
I mean, obviously it's open source, you can get it, but what, what is the best website? Yeah. com in there.
It'll point to the dis uh, installers. If you wanna install locally, it can walk you through creating an account for SaaS and getting up and running really quickly. Uh, the other thing is that if you just go to like the doc site as well, to your point, you'll learn about more of the open source focus and how you can contribute code.
com. But ultimately, like what I would say is if you're looking to build AI, and you might not be a developer, or in some cases, you know, I won't say I'm very young, but like I programmed in, you know, c outta college, right? But I don't know how to get into Python.
With Python now being the number one language worldwide, anacon can help you with all that helps you build applications even if you're not technical. Well, AI could help you with it now too, right? Yeah.
I would imagine Anacon is going to use AI to help. If you don't know how to develop in Python. You don't know Python.
Yeah. To teach it to you and help you develop it. I mean, it's a crazy world we're coming Into.
Oh, no, for sure. And what I would tell people is like, it's so easy to get started. I, as part of the interview process, wanted to play with the product and you can get a cloud notebook up and running with one or two clicks, really?
Uh, yeah. The a Anaconda AI system is just there, uh, it's front and square. And I was asking it questions of things that I used to do 10 years ago with Anaconda, like, how do I do this today?
And it was very easy. I felt very, uh, productive and able to actually build something without having, you know, a lot of this, the knowledge that was just built into the platform. So, yeah.
So Lemme ask you a hard question, David DeSanto, do you still consider yourself a developer? Yes, I do. Okay.
I do. And and here's why. There, you know, um, Mr.
Joel for a long time as an engineering leader, uh, people say, I went to the dark side to go into product and Uhhuh, I don't think David graduating from college would know that David would be CEO of the company, right. Company. But those roots are still really important.
And so whether that is me building stuff to play with, uh, me working with our engineering team and finding things that maybe we can make better, you know, it's great to roll up your sleeves and just be in that, especially with a very technical company. And I won't tell you the apps I built are pretty bad, but, you know, They don't have to be great. The fact, you know what I am, I said it tongue in cheek.
Yeah. But the fact of the matter is, is it, I always tell my team, you gotta be able to walk the walk, not just talk the talk. And so the fact that you could play with it and make some, it doesn't, doesn't have to be the greatest app in the world, but you could get your fingernails dirty with it gives you a perspective that helps you understand who your customer is, who the users are.
Yeah. It's Important. No, and you're right.
You Can't be too abstracted outta that. No. And what I tell people is like, even though I'm now CEO of a company that's almost 500 people, when we announce our series C, we're at 150 million in revenue.
You know, it's still important to me to be thought of as a developer and like a vulnerability researcher. Mm-hmm. Because all of that is what has helped me be successful in my career.
And so what I'd say to people out there who are like, I dunno what I want to do or do I wanna switch roles, go to a different company, you know, find the thing that you wanna do and just do it as best as you can. And it's just so rewarding. And, you know, Anaconda iss there to help people take that journey for themselves.
I love it. David, man, congratulations. Thank you.
Best of luck at Anacon. We, you know, I'm sure now that you're there, we'll be talking a lot, doing more, looking forward to hearing great things. But this sounds like a great opportunity for Anaconda and a great opportunity for you.
It's a good match. You know, thank you very much for having me, and I always love the catch up. It was a pleasure.
All right. com. Go check it out.
We're live at AWS reinvent. We're gonna be back in just a minute. We've got tons of great stuff coming up.
Stay tuned. Hey everyone, welcome back here to Techstrong TV and our continuing coverage of AWS reinvent. You know, one of the great things about Techstrong being part of futur is we get to kind of pick the brains of some of the futurum analysts, you know, the industry, well-known analyst, uh, about what's going on in the world of tech.
And especially when we're at an event like this, we're gonna do two segments here, each with two of the FU analysts. The first segment is gonna feature Brad Shiman and Fernando Montenegro, uh, of fu I'm gonna give, I'm gonna let each of them kind of introduce themselves though. Brad, if you wouldn't mind, why don't you kick it off.
Introduce yourself. Yeah, Thanks, Alan. Hi, everybody.
Brad Shiman. I am an analyst with futurum, as you noted. Uh, I, I look at data intelligence, analytics and infrastructure.
And I, I'm a software guy. I love software developments and all things databases. So I'm hoping we can, we can chat about that a little bit today.
Absolutely. And I'm Fernando Montenegro. I lead our cybersecurity and resilience practice.
And, uh, the gray hair comes from being around cybersecurity for many, many, many years. There Was a time I had gray hair in cybersecurity too, when I had hair Fernando's just outta High school. Yes.
Oh yeah, exactly. Yeah, exactly. And, and, and yeah, I've been covering cloud security for a long time and, and, and it's been a pleasure to come to AWS reinvent for, for a few years.
Not the, the full 14 that they've had it, but, uh, It's a good show. Yeah. It's a, it's an amazing show.
Yep. Well, you know, an observation, I'm glad you wrote it up. Well, let's just jump in.
Of course. Sure. An observation I had today, and I wrote about it in an article I put up on one of the tech strong sites.
Think about coming to AWS reinvent five years ago. What would you be talking about S3 Lambda serverless? You'd still be talking about security bit, but you would be talking about cloud.
Yeah. Cloud nitty gritty, cloud native, managing my Kubernetes EKS. Right.
Securing that stack. How much of that do you spend about here today? So if I transported you from five years ago to today Yeah.
Would you believe it's still the same company? The same industry? The same.
I absolutely, I, I feel, I feel like we're still in that era because honestly, all of those concerns are still here. They all inform what AWS is doing. They are all, they are still all in in the cloud.
And you can hear that in Matt Garmin's, uh, keynote today. 'cause he, he did not mention when he said, if you wanna get the most out of ai, you're going to need to bring data to the ai. And to do that properly, you need to bring it to the cloud.
You know, That's loud and clear everything. Yeah, yeah. No, I mean, it's kind of funny in that we haven't, I just feel like there's less of an emphasis on cloud or it's abstracting behind the ai.
That's it. So, So, so here's the thing. Point of order.
Five years ago, we were in the middle of the COVID pandemic, so we're Right. So we, we, we would not be doing maybe Four. Yeah.
But, but, but point taken. Uh, I think that, um, to, to, to Brad's point, the cloud is foundational to do this. Yes.
And it's funny that you brought up abstraction. I have a, I have a thing that I talk about that, uh, go back to high school calculus, like high high school maths. Mm-hmm.
The limit, like the limit for cybersecurity as time goes to infinity, to me, is anti-fraud. Mm-hmm. And what I mean by this is that we abstract away technology.
We abstract away a lot of this, and then we help businesses and buyers and sellers and whatnot talk about higher level, uh, constructs. Right. And what, and it's kind of what we're doing here.
It just so happens that I'll be, am I the first one to bring up the AI words? I think I am right. So, uh, uh, I dance around won't be the last I, but, but, but that's the point.
I think that we are abstracting away some of it, but to Brad's point, it is always there. And actually, one of the security announcements had to do with, uh, uh, with ECS, no, not the agenda points had to do with ECS and if C two, right. Which was the, the, the, the, the, the guard duty, uh, support.
Right. So it, I agree with you that that's not what we're talking about as much, but it's here, it's always, it's always there. It's, it's always there.
And, uh, whether it's, whether you're figuring out instances that you need, whether you're figuring out what kind of database do you need, there were announcements around S3. There were announcements around S3 tables, I think. Right.
Uh, and so yes, you are correct that, that the topic has shifted, but the technology is Underlying, I always, The thing that powers our, our little market is that race to Zero. Trying to beat Zeno's paradox to, to always go a little bit further closer to getting there. And we never get there.
And that's why it works, because we're always inventing new ways to abstract away problems. Yeah. And to find new, interesting ways of applying this technology to solving problems.
And I, I feel like that was really, um, on display today when we talked about Amazon Nova Forge. Yes. Which I would love to spend some time talking about.
We, We've spoken about it a bunch today. I'd love to hear your thoughts on it. Yeah, I, I have some thoughts.
It's, it's a renaissance era for, for the, you know, more traditional foundational large language model. It's like a, a return to form I'm calling it. Because instead of, like, we, we've spent so much time over the last year in investing in frontier scale models, uh, like Gemini, like Claude, et cetera, and, you know, they do a wonderful job.
And when they first came out, if, if everyone will recall, we used them for POCs, and that was about it because they were very flexible. They could do a lot of different things. They had a great knowledge base you worked from, um, but you, for production, you went with an actual model that you fine tuned that you built.
Yes. And we kind of went away from that and we said, let's just make them do it all. And, and I think what we learned is that that costs a lot of money.
Yeah. And so, you know, if you're gonna do ai, right, like, like Matt said, you want to bring the data to the ai and that's what they're doing with Nova Forge, is they're really trying to make it so that we actually do what we started doing a few years back in fine tuning these models to bring the data to the ai. So I, I think it's a, it's a return to forum and I, I applaud them for focusing on No, I I, so it's not anything I've seen before, which is interesting.
Yeah. And, but I'll tell you something. Two, two and a half years ago, we're gonna have Mitch Ashley on, in the next group.
Mitch came to a hackathon. We did down at Techstrong around what we called operationalizing ai. Yeah.
Yeah. And we had people like Patrick dubois, who's founded the DevOps, came up with the word DevOps, uh uh, John Willis. Oh, he's great.
We had a lot of great people who were very, you know, early on in the DevOps movement and they were working back then Yeah. On, on Rag and on vector databases and s SLMs and stuff like that. And to me, it be, I'm not an analyst, but I did stay at a Holiday Inn Express last night.
To me, it was obvious that not every job in AI required a, a truly frontier size LLM No. As a matter of fact, it might be the wrong tool In a lot of cases For a lot of jobs. It's the wrong tool.
I need. Yeah. I need a scalpel or a, or a rifle, not a shotgun.
And I, I, I, I'll, I'll go one deeper. And that's one of the things that I was looking forward to coming here and having conversations and, and we are having those, is that I would argue that the, the lms right, the language models in many cases, fine tuned or not right, may not be what people need. And this is one of the areas that Yeah.
Uh, this is one of the areas where like, I I, I, I was really excited, I'm really excited about the field of neuros symbolic ai. Mm-hmm. Right?
Which is the, you're, you're bringing the, the, the neural component that, that from the LLMs with the symbolic reasoning. Right. And, and AWS has been doing a lot of work on that.
So it was really interesting to come here and see that. But anyway, but the, the, the point being that the way that we are going to, to improve those models is by the fine tuning, and in some cases, by using these more neuros, symbolic components. And so one of the things that I was excited about, the announcements that that, that they now have a, uh, a verifiable policy language on the agent core stuff.
Yeah. Right. That's a step in the right direction.
I really like that It's responsible AI and ML lops as you're, you're talking about. Yes, Yes, yes. It's Part and parcel to that.
And so I, I feel like they have to, they have to do that. And if you look at all the components of Agent Core, you can see it starting to look like an ML ops platform more and more. That's for agents, not just for select models here and there, but for orchestrated, Let me, let me ask you a question on this.
Have you guys seen the letter that was circulated last week? Like a thousand AWS employees signed on to calling for responsible Really Moral Yeah. Ai.
Wait, this was Amazon? Or was it meta? No, I believe it was AWS Okay.
Interesting. Interesting. Yeah.
Well, you know, it's, it's, uh, it's very much, and we saw it actually the beginning of the keynote this morning. The very first words on the screen were why, and the, the response was, why not? And that's the era I feel like we're in right now, is, well, let's just dam the torpedoes and see what happens.
And I, I don't think we can do that. No, it's, it's, we should not be doing that and yet have been because it's all about time to value. And we've found with transformer models in particular, that we can shortcut that time to value, but we can't shortcut the hard work.
And that's why things like fine tuning are so important because it's another tool in the toolbox that gives you, at the end of the day, a model that actually, as you said, has a scalpel to do what you wanna do, do it performance, do it in a secure, safe manner, and do it in a way that you can actually make some money. Absolutely. Lemme bring up another thing.
You know, coming in yesterday at the airport, I was reading all the, the electronic billboards. Yeah. I'm a sucker for them, but I saw one from Databricks that really caught my eye.
I don't know if you saw this one. Our A AI agents don't suck. Remind me of the old, you know, we suck less.
You philosophy Suck less software is alive and well today. Today. Exactly.
Yes. Yeah. Well, now it's called suckus Agentic ai, maybe.
Oh, Come on. That's never gonna happen, but, okay. It's like agentic AI is the antithesis of Suckus software.
It's like whatever you want it to do, It'll just, it'll do it for You. Yeah. Just do it for you until it doesn't.
Yeah. Until it doesn't, until you check clears. Anyway.
Um, but you know, we, we certainly are in this, Brad, you're right. You want, we could, we you want an agent? I got an agent In New York Like that.
But you, I got an agent for you. But we're also seeing SA kind of a, a Cambrian explosion, if you will. Sure.
Right. Like, I, I had a, a fellow we interviewed up here this week, or today rather, who comes from, um, uh, s agent AI for s se not for SEO. For SRE.
Okay. Yeah. Sounds great.
What a great idea. We need that, that's something we could do. Of course, he's one of six agent gay I for SREs that are here.
Uh, May I say seven? Because, because You know of what? Two?
No, no, because one of the announcements today Was AWS themselves. AWS themselves. Right.
And now Check your watch, because we might have another one, another One. But, but, you know, but that's not unusual for, that's their model. Look, we're gonna give you 80% for 20%.
Yep. That, that's right. That's a lot of the AWS model.
But I, I do think we are in a, you know, a Cambrian explosion of life, if you will, of ai that some will, some will make sense three to five years from now. Yeah. And some will say, what were we thinking about 12 eyes and six legs?
It just, you know. Well, a lot of it's gonna disappear because as we saw early on, when we had a lot of wrappers, as you'd call them Yeah. Around chat GPT, are they in business anymore?
No, because you don't need Them. I'll tell you what else I think might disappear. Hmm.
Everybody and their mother has an MPC server. I have one right now. Yeah.
Yeah. I, I mean, do we, why can't we have an open source one that we all kinda standardize on? Kind.
And this is the open source model, right. And then build on top of that, build functionality. Like, but that's on top of, but that's What MP is, right?
MCP is by itself, like an open, It will evolve into what you're talking about, Alan. Yeah. I I think we don't need 10 different MCP servers.
No, there's an X-K-D-E-C. Sorry. XKD.
I know exactly. We need a standard next panel. We have another standard.
Yeah, Yeah, yeah. We have 13 standards. We can't do it.
We need another one. We need the single one. Now there's 14.
That, that is the way it goes. It not, yeah. Yeah.
I, Fernando, I gotta talk security with you a little bit. Of course. So I had another fellow I interview today, smart guy, zest security.
Okay. I don't know if you heard of these guys. The founder there came out of, uh, oh, they sold to Palo Alto Cider, remember cider?
Yes. Yes. Security.
Yes, yes, yes. He claims zero. They could get you down to zero vulnerabilities using ai, ent, ai.
That's bold. I, I I, I, I told them, I, I said, say that again. For the people in the back who don't Hear me.
Yeah. I think that there are, um, there's multiple ways to interpret zero vulnerabilities, right. In the context, like when we have conversations about vulnerability and security, the first question I want to ask is, okay, am I talking to an ops team or am I talking to a dev team?
Very different Measures. If I'm talking to a dev team, zero vulnerabilities means one thing. If I'm talking to an ops team, zero vulnerabilities means something else.
So in the context of, I think they more in the development. No, he, so I agree with you. I mean, you and I both know.
Yeah. I have a security background. He was talking about the security team in ops, like tra not AppSec vulnerabilities.
Like true, True vulnerabilities That, and, and, and, and, and that, and that. If, uh, um, like, again, I, I applaud the, the, the, the, the, the gusto. But I, I struggle with it because this is the trick that, that security teams are learning the hard way.
There are vulnerabilities that you don't fix because it's too expensive. Yep. Right.
Because given the risk, Well, it's a manage, it's a risk management. It's a, it's a risk management conversation. And then, like, like here, for example, here we are having a wonderful conversation.
Uh, some of these doors are open. That open door is a vulnerability, Right? We Say Windows 10 at the moment.
Should we talk about that? Well, It's on Windows. We might as well talk Windows 98, but that's a whole nother story.
But, but, but, but I think, but you know what your reaction, he said, that's exactly what we hear from CIOs and CISOs. And then we show them. I'm going to introduce you to this gentle, I'm happy to chat, and I'd love to hear you talk.
I'm happy to. Yeah. Guys, I gotta wrap this little portion up 'cause we've got more analysts waiting.
Sure. Hate to keep analysts waiting. But let me, let me pose question to each of you, and, and we will go with that.
Brad, if I had to ask you for one story, that's the big story at Reinvent this year. And we've, we've skirted on all of them. Yeah.
But for you, what, what's the, what's the, you know, the key takeaway? Well, for me, uh, I would say that it is, you know, the, um, Nova. Um, but I'm not, I I, I want to actually instead pre pre, you know, get ahead of what I know Mitch is gonna talk about, uh, when it comes on.
And, and that is Kiro, and that is age Agentic development. And the fact that on stage today, we heard from Matt that the company has committed itself to using this platform to develop their software in-house. That is very much, you know, a bold statement.
Yeah. Because I, I, I feel like a lot of these companies try to sell us on yet another agentic, IDE, blah, blah, blah, blah. But they really put their money where their mouth is.
Well, a s is trying to do that, so, we'll, I wish them luck, and I, I think it's, it's gonna be interesting to watch. One last thing for you. What wasn't on your Bingo card coming out here?
Uh, well, you know, I wanted to hear more about data, honestly. Uh, and I, we, we didn't have a lot of of announcements about that. So my Bingo card was all filled with, with like slots about what's happening with their various databases.
I didn't get too much Of that. No, I haven't, I actually haven't heard much at all. No.
I would've loved to have heard something about a semantic layer, for example, because every other vendor, we mentioned a couple of 'em with Databricks. And, uh, right now, if you're gonna do a lot with ai, you're investing in a semantic layer. Yeah.
But we're not really hearing that from AWS So I, I would encourage them to, to really kind of rethink that in their go to market coming up in the next couple of months. Yeah. I wonder, well, I don't want to be Doctor Evil, but I wonder if that means AWS is working on their own semantic data layer.
They have been known to build internally. Yeah. Yep.
Fernando, let me come to you. What's your big story? My big story comes in two pieces.
Uh, you know, how we always talk about security for AI and AI for security, yeah. Third one being security from ai. Uh, I think that we saw the announcements today, the security for Agentic and the agentic force for security.
And the big story for me is that on the security for Agentic, it's how they've woven the conversation of Bedrock has security, bedrock has it built in, bedrock has it, and, and then, and then you take the policy agents from, uh, the, the, the policy language. Now an agent core. So I think that I, I encourage my security colleagues to, as you are thinking about Gentech, you are, you have to look into what security is coming from the platform.
Yeah. And the other big story is ag gentech for security. So just like the DevOps agent there, there is now an announcement for a preview for a security agent that is going to be doing a lot of the, Hey, let me fix that code for you.
Now the devil is in the details, right? Uh, but what kind of things is it going to fix? And what kind of things is it not going to fix?
But importantly, what's the, the, what's the play the interplay between a true security, uh, uh, professional during a pen? Because it's going to automate pen testings. The theoretically, theoretically, sorry, forgetting English.
Uh, where do you draw the line? So if you're, if you're a developer and I'm a security, uh, engineer, what have you, and then do I now code my policy at my company to say, look, as a developer, you are, um, uh, you're going to do multiple things for security, and you are going to already run a pen test, and then I'm just going to test the results of the, of that pen test. Right.
Or am I going to it? It's great that you ran a pen test, but, you know, like trust, Trust, Good. Perfect.
I'm gonna do it. I'm going to do it too. So I think that that's the next level of conversation.
So I think there'll be a human in the loop conversation there. Absolute. Let me play devil's advocate a little bit though.
Sure. The DevOps agent to me is an alert monitoring tool. That's what it sounded like from what I heard.
Oh, I don't know. The, the advertisement we saw was The advertisement was one thing, but when you read, when you read, yeah. It sounded like alert logic to me.
But, okay, we'll, we'll go with that. Well, actually, let me ask, lemme tell you, you, uh, what I feel that is going on there is that they're not gonna deliver it today. 'cause they're gonna build for It's A preview.
Yeah, exactly. And, and what we do see them doing is working on long running agentic processes. They talked about that a lot today, as a matter of fact.
Yep. And what else is, you know, building safe software than a long running process of monitoring your code base, testing your code base. That seems like what it ought to do.
Yes. That is what it ought to do. You know, there's an old saying, I learned in law school about what you do do and what you ought to do.
That's the difference. You do not gonna Get caught doing Your comment on security there. I gotta tell you the truth.
I had a deja vu to 2007, the cloud, I can't put my stuff in the cloud. It's not secure. Don't worry.
We built security into the platform. We keep, We didn't buy it then. I don't know if we buy it now.
Yeah. We keep moving the layers up. I Think that, that, it depends who you are, right?
If you're a big company, maybe you question that. If you're a small company, you're never going to have provide that Until, until well, and then It gets a little bit better. And, and, and I go back to my thing about abstractions, right?
We've now given developers more capability to do more things. So instead of, you know what, that budget for a pen test that was going to find 50 vulnerabilities, and out of those 50 vulnerabilities, 35 of them could have been found mm-hmm. Automated in an automated fashion.
Now, perhaps that same budget can focus on more critical Vulnerability. Just those 15. Yeah, Exactly.
Because we've asked you to do this. I'm optimistic, Always the optimist. I, I'm, I'm, I'm, I'm optimistic.
We are. We are. It's, it doesn't have to be perfect, right?
It doesn't have to be zero. Nothing is Perfect. It's ever, we're never gonna get to zero.
We're never gonna get Outta, we know that. Right? That's risk Management.
Risk Management, and said zero. I almost fell outta my chair. Yeah.
Anyway, Brad, Fernando, thank you so much for coming up here on Text Drug tv. Thanks For having us. Appreciate a pleasure.
We'd love to have you. You know, we do these remote, you don't have to come to Vegas to see us. And, and may I remind you that we are kind of halfway through, so there's, there's still, There's still, and we'll be here tomorrow and the next Day, at least six more keynotes.
Yes, there Are. Yes. And, and, and there are, and, and, uh, just, just to, uh, sidetrack a little bit, one of the things that I was really interested in is this whole agent and, and, and, uh, and the neuro symbolic stuff.
But coming alongside that, there's other things going on. Like, one of the areas that's super interesting is like confidential computing, right? Yeah.
Mm-hmm. Oh, that's, we, we are seeing from a AWS do some interesting things there. So let's keep talking about this.
And, and, Well, now, now you invited yourself. You know where we are. I have no excuse.
We can do this remote. Yeah. All right.
Hey guys, let me just remind you, y'all RUM does a thing called the FU signal. It's, it's the report that we put out in, in different practice areas. Fernando's done one.
Brad's done one. The next two folks that we're gonna have on have done one, unlike a lot of other analyst firms, these reports are available to you. You could go see the whole, I think, virtually the whole report, right?
Yeah, yeah. And sign up. It's an amazing look at using ai.
I if you looked at our life coverage earlier, Daniel Newman and I had a great discussion on this. I encourage you to all go look at futurum signals, check out what's in there. This isn't last year's information given to you six months after the fact, right?
It's, it's the, it, it, I don't want to say it's up to the minute. It's not continuous yet, but it's a lot more current than the 18 month old stuff you may have been used to. So go check out FU signals.
These are the guys behind it. We're here at AWS reinvent for text Trump tv. We'll be right back.
We've got two more great analysts I wanna introduce you to. Hi everyone. I'm Jonathan Bryce.
I'm the Executive Director of the Cloud Native Computing Foundation. Uh, it's great to be able to, uh, speak with you all here at this Cloud Native Now event. Uh, today I want to talk about some of the things that I see happening in the, uh, the landscape of Cloud native and ai, and how those are really starting to intersect in a big way.
Uh, but first, for those of you who aren't familiar with the Cloud Native Computing Foundation, we are an open source nonprofit. Uh, we host a lot of the, uh, most popular, um, cloud native software components and projects that you're familiar with, things like Kubernetes and Prometheus and Open Telemetry, and, and on and on Argo and others. Uh, and it's something that is really amazing to be part of because it's a massive global community, uh, hundreds of thousands of contributors from all over the world who are, uh, making code contributions, documentation requirements, helping us to really push the state of the art forward.
And, uh, and we see this as, as something that, uh, is coming from every continent and, uh, and many of the countries, uh, companies and, uh, and individuals participating together to just help us build great software that, uh, we can run our businesses and our organizations on. io if you are not already part of the, uh, the Cloud Native Computing Foundation. And if you are, thank you for, uh, for your work and your contributions.
Uh, so I wanted to talk today about how two of the most significant trends in technology are really starting to merge cloud native and ai. And what's interesting to me is, in the tech industry, we have, uh, kind of a proclivity to think of the next thing as, uh, replacing the current thing. Uh, and in reality, what happens is we're always building on top of what came before, whether that's operating systems or, uh, websites or mobile or cloud.
These trends are really additive. And I think that we are at a moment where we are seeing that really come into play with cloud native and artificial intelligence. Without a doubt.
These are two of the biggest trends that, uh, that are in the tech world, uh, both within IT as well as within, uh, the consumer tech world. And why is this happening? What's driving this?
Well, that's what I wanna talk about today. Uh, the way that I think about ai, um, and especially open source ai, um, I see it in three pillars. You know, AI is such a hot topic.
Everybody's talking about it constantly. And we see it not just in the technical press, but also in the mainstream news. And, uh, and AI can mean everything from, from deep learning.
And, uh, and these techniques that have been around for quite a while to, uh, chatbots and, uh, chat GPT and, and these kinds of elements. So I, I needed a framework as I was trying to think about where does this intersect with the world of infrastructure and cloud native? And, uh, and, and the model that I've come up with is to really divide it into three pillars, which are training, inference, and then agents and applications.
So training inference, and, and agents and apps, to me, represent three very distinct practices and technology sets within the world of ai. Uh, which means that they have different, uh, different expertise that's required, different kinds of infrastructure, um, really different communities as well in each of these three areas. And, uh, of course, you know, there's always overlap and, and gray areas anytime you try to make a definition.
Uh, but this has been very helpful for me to think about, uh, what are the open source projects that are at play here? Where should we be trying to build strong communities? Where should we be looking for integrations and, and support?
Um, and, and as I think about this, I also think about this kind of as an inverted pyramid, where at the bottom you have training. This is where we take data information. We actually turn it into intelligence through these massive training runs, uh, where we go through the process of, of, uh, taking raw data, um, turning it into something that, uh, that is then a model.
The inference stage is, is, uh, kind of one step above that, where we take these models, we serve them, and we then make predictions. We answer questions. And this is where we take that, uh, that, that intelligent model, um, and start to use it to solve real world issues.
And at the top level, you have agents and applications, and this is where we connect that intelligence to individuals, uh, and to other applications that, that are maybe talking to each other and starting to act autonomously. Um, and combine, uh, you know, the intelligence that exists even across multiple models. And if you look at each of these layers, um, you know, at the very bottom is where we have a lot of the deep, uh, science of artificial intelligence happening.
Uh, the middle layer of inference, I think is where we have a lot of the operational expertise that we need to make this layer the most successful. And the top layer is where we start to have, uh, user experience and developer experience as an important element of what makes a successful application or agent. So, you know, this is kind of my framework for thinking about it.
And as I walk through this today, I'm gonna refer back to this, uh, to, to, to kind of set the stage on how I think, um, CNCF is, is playing in this world and, and what's, uh, um, kind of what's relevant for the next couple of years. So if we, if we look at the, the, um, the lowest level, if we're talking about the training level, up to now, what I think we have been in is this era of giants. Uh, you know, I, I, uh, I, I titled my presentation training supercomputers, you know, this is what we've had are these massive compute clusters that, uh, that have, um, thousands, tens of thousands, even hundreds of thousands of GPUs in them.
And these are extremely costly to build out from a capital perspective. Um, they are also time consuming to set up, to maintain and to operate, uh, a training run. It can take weeks, months, um, you know, a very long time, uh, which just again, increases the cost.
So this is really, uh, a, a game right now where we see these frontier labs who are creating massive models, um, that there was a, a quote from Sam Altman where he estimated that, uh, the GPT five training run could cost up to $1 billion. Uh, there was some news, uh, just last week that, uh, that came out about, um, a potential deal that Anthropic is making to acquire a gigawatt of TPU capacity from Google, a gigawatt of capacity, just, and that's an addition to the other, uh, capacity they have, uh, X AI's colossus supercomputer that they built is now up to 200,000 GPUs in operation. They say they're gonna continue to expand.
And, uh, this is just an incredibly expensive and complicated game that most organizations, uh, are not really gonna be playing in that. But this is what we hear about a lot in the news. You know, what we have seen in the last couple of years is the chap GPT moment initially, which I think brought ai, um, kind of front and center in a real way for a lot of people.
And then we had the deep seek moment at the end of 2024, which brought open source ai, uh, kind of to the forefront. And we've seen so much innovation happening in, in, uh, open model development over this year. But all of these are really talking about these extremely expensive, large language models, these LLMs that are attempting to capture, uh, frankly, all of human intelligence, put it into a model that we can interact with.
And, uh, and that is, is something that I think, you know, it's been very fascinating for, for many, many people to have the opportunity to interact with AI in this, in this way that feels kind of like a human interaction here. You're talking to it, you're asking questions, you're getting feedback on your writing or your ideas. And so this has been something that where I think a lot of the focus is.
But I think that we are at a tipping point where we're going to start to move beyond just LLMs. And even with LLMs, I sometimes think of chat GPT as a proof of concept, not the actual end state of where we will be able to capture and see the most value from artificial intelligence systems. If we look at how open sources played into this, uh, you know, the, the investments have been largely on the, uh, the, the capital side with, uh, especially all of these specialized GPU components and the hardware necessary there, as well as with the, uh, the humans who are, uh, the, the very highly in demand AI experts.
Um, you know, it's a, a scarce resource, um, that's currently, uh, one of the, the highest paying and most lucrative types of, of roles that you can be in. Uh, what's enabled some of that is that the open source ecosystem around training is extremely robust. Uh, the PyTorch project has achieved huge market share.
Uh, if you look at hugging face, it's high. 80% of the models on the hugging face web website are, uh, are optimized and, and, uh, and kind of targeting PyTorch. And many of the largest labs out there are using cloud native technologies for their orchestration and operations, uh, uh, of these, um, these environments where they're doing the training.
And so, up to now, when we talk about cloud native and ai, a lot of times what we've been talking about are, how can we help, um, these labs take advantage of all of this hardware? How do we give them access to the GPUs with features like dynamic resource allocation in Kubernetes? How do we then, um, orchestrate that so that we make the most of those GPUs?
We're running them 24 7 and getting the most out of them. Uh, and, and that's really where the focus has been. But I think that we are at this moment where we're gonna be moving from massive training to actually taking inference to the mainstream.
And there are a few elements that are gonna be different as we think about taking inference to the mainstream. Now, when you look at these, these frontier labs and, and the extremely popular large language models, they obviously are running huge inference systems right now to meet the demand, and they're scaling them constantly. Uh, and, and that is a, that's a, a, a pretty impressive feat of, of operational excellence, um, that we've seen the labs like OpenAI and philanthropic, and obviously Google and others, uh, accomplish as, um, as they have been serving these large language models.
But I think that we're going to see inference go even mainstream in the next one to two years. And one of the things that will drive that are specialized models, um, I've got a, a, a screenshot here from a, a headline. This is a, a blog on, uh, on the Uber blog.
And they talk about some of the work that they do, uh, in machine learning and artificial intelligence. And I have this quote here that, uh, that calls out that they do 20,000 model training jobs a month, and they're serving 5,000 models in production. So they're not attempting to create kind of one model that has all of human knowledge in it to, to serve their needs.
They're creating a lot of models that are specialized, and they might be, um, specialized for a city they operate in. It might be specialized for, uh, one particular workload that they're attempting to, um, to serve, such as predictions and recommendations or, uh, drive time estimates. And they find that that's actually, um, you know, a much more efficient way to be able to serve their needs.
And as you can see, you know, it says 20,000, um, 20,000 training runs a month, 5,000 models. So they're training these models in some cases multiple times a month. And I think this is what we're gonna see, is that most enterprises are not going to just count on one giant model that captures all of human intelligence.
They're going to use, um, dozens or hundreds, even of smaller fine tune open source models. Sometimes, uh, sometimes proprietary models, sometimes commercial models that are really good at specific, specific tasks. You know, it might be contract review, uh, it might be sentiment analysis, it might be, um, something like, uh, insurance adjusting estimation.
Um, one that obviously, uh, you know, we see a lot of is, is code generation is, is already a, a big use case, and some of the models are better at code generation than others. And, and I think that we're gonna continue to see differentiation and improvements in specialized models. Um, and, and I think enterprises will start to run these because the cost difference is really going to be significant.
If you look at, at, at the, the differences in kind of the, the operational side, um, and the performance side of a specialized model versus a totally generic, generalized model, I think that's where you'll start to see where the, the motivation, uh, is going to be to move to this type of, of structure. In a lot of enterprises, um, it can be vastly cheaper, uh, to, to run and, uh, and fine tune a smaller model. Um, if, if you have a model that is trying to do one specific thing, such as predict the, uh, the, the travel time across the city, uh, it, it's much faster to get a prediction and get an answer out of a model that doesn't include, uh, you know, all, all of the, uh, the history of Europe and, uh, and, and America and, and eastern Asia and this kind of thing.
Obviously, uh, when you're trying to, to, to pull that, that type of information out, um, the performance can also be faster and more accurate within a specific domain. And because the resource requirements are not as high, we see specialized models already being run on less expensive hardware. So this doesn't have to run on the latest Nvidia GPUs, which are very expensive and scarce.
Uh, you know, Jensen is selling as the GPUs as fast as they can make them. And, uh, and those are great for, for these really high-end training runs. But for kind of the day-to-day inference, especially in a specific domain, there are alternatives that can, uh, are more readily available and can be a lot more, um, effective from a, from a cost power and, and operational, uh, perspective.
And also, you know, this is a, a, a path to being able to host these models in different environments. And that might be for security reasons. If you have, um, data that, uh, that really, uh, you don't want to leave your environments, um, you can host this in your own, uh, virtual private clouds, you can host this on premises.
Um, so it gives you more flexibility into these types of areas. Now, I think that the, uh, the reality is not going, this is not going to be something that just replaces the LLMs, the LLMs are going to be huge part, I think of, of, uh, of every business going forward. But this is going to be augmentation for, um, specific business value that, uh, that becomes, um, in some cases differentiating for organizations when they can take the data of their organization, the kind of institutional knowledge of that organization, and capture it inside of a special model, um, that they can then scale and, and, uh, and repeat, um, similar to what, uh, what, what you can read about in that, uh, that blog from Uber.
So, uh, what's, what are the challenges to doing this? Well, um, I, uh, a couple of weeks ago we had, um, an open infra summit for the Open Infrastructure Foundation. And this was, uh, just outside of Paris.
And I had the opportunity to do a, a keynote interview with Okta kba, who's the, uh, the founder and chairman of OVH Cloud, which is, uh, the biggest, um, European Cloud provider. Uh, and it is, it's, it's a fascinating story to, to dig into OVH and how they started and where they are. Um, and obviously, you know, Okta and I, we started talking about AI and he had a quote, which, uh, which I loved.
He said, at this point, we're all just waiting for tokens. Um, you know, this is kind of the, the thing that's happened is we love the potential of ai and whether we're doing just, you know, content development or feedback or planning or coding or some specific task, and a lot of cases, uh, we do get to a point where we're waiting on the AI to give us an answer, you know, to, uh, the, the tokens are, are the, uh, the, the kind of request and response, um, uh, nature of, of these, these models that, that we're all interacting with. So we're sitting around, you know, waiting for tokens, and so how can we get more tokens?
You know, we all want more tokens. And there are two ways. One is, uh, to, uh, to add more inference, and the other way is to have faster answers from the models that we are we're serving.
I think, as I said, you know, enterprises are going to take both approaches. Enterprises will continue to use LLMs for, for many use cases. Uh, the, the large scale labs are going to continue to increase their capacity.
Um, the, the, uh, there will be, uh, open models that, that are in the l LM space that get fine tuned and customized and deployed as well. And then I think there are gonna be a lot of specialized models which deliver faster answers and make more efficient use of the inference capacity. But ultimately, we have to have more inference.
Uh, Google has talked about the, their token, um, stats, how many tokens they're creating a month, and they're over a quadrillion tokens a month now, and it's gone up 100 x in the last year. So these are massive numbers, and this is really just the beginning of where we are in the AI adoption curve. So we have to have more inference, whether we're talking about the large labs and kind of the main, um, the, the main AI providers, or if we're talking about enterprises, we have to have more inference.
Someone has to deploy those machines, they have to scale the systems and, uh, the, the inference software, they have to secure it, uh, and then we have to observe it and make sure it's performing. How is that going to happen? Who is going to solve this?
Well, I think that there's a pretty clear answer. I think it is going to be, uh, the cloud native community that right now is responsible for deploying, scaling, securing, and observing many enterprise workloads. Uh, you know, these platform engineering teams and the cloud native community and, and across our end users are the ones who are taking existing enterprise workloads and they're deploying them across public cloud providers, internal infrastructure.
Uh, they're handling all of these elements that are necessary to run these workloads really well. And as I have been having conversations with platform engineering teams, there's been a real trend just in the last two months where responsibility for AI systems that are going into production is falling on the platform engineering teams. And so I think that AI and specifically AI inference really is the next big cloud native workload.
This is going to be added to the list of existing apps and microservices and, and databases and the other kinds of workloads the platform engineering teams are responsible for. Because it is going to require the same set of skills. We're going to need to be able to do standardized deployments of these inference systems so that we can do them reliably and repeatedly.
We're gonna need to be able to auto scale them. We're also going to wanna scale them down to zero. So this is a great cloud native, um, pattern of, of being able to containerize workloads, spin them up and turn them off.
Uh, we're gonna need security policies and enforcement with a lot of control and, and in some cases, much more control than, uh, than what we are used to in an organization where that's, uh, where we're just kind of managing human access to these systems. And observability is going to be far more important than ever. Uh, if, if you have worked with, uh, with, with any of the AI systems out there, um, you can probably see how quickly the usage can skyrocket.
And along with that, the costs and the implications of, uh, of, of that usage. So this are, these are the skill sets and the technologies that the cloud native community, uh, has and, uh, and are developing constantly. And these are the, the things that, uh, that these AI workloads are going to need.
As we look at the actual details of this, I wanna talk about two, uh, two example inference platforms. And these are both pretty early, uh, but I think that just to give you some concrete technology that you can go look into and, and poke around with, um, the first one is called AI bricks and these cloud native inference platforms, what they are doing is they're extending the existing cloud native architectures and concepts, and then they are adding in additional networking and especially sophisticated routing to make sure that, um, that request and queries are, are going to the proper set of hardware, the proper GPUs, the proper caches. Uh, they also handle things like distributing and horizontal scaling, uh, of the KB cache so that you can scale your GPUs horizontally.
Uh, this is gonna be really key to adding inference at a cost effective level. Uh, they, they handle, um, security elements. Uh, they handle different, uh, different types of workload placement and orchestration, uh, and it's all built around the existing systems.
Kubernetes is at the heart of them, but a lot of the other cloud native, uh, cloud native projects are, are used here as well. So, um, AI bricks is the first example. This is a project that's come out of by dance, and it's based off of, um, the, the production work that they've done for, for TikTok and other platforms like this.
So something that's really, uh, battle tested at scale for, for algorithms and, and, uh, and running inference. The other one is called LLMD. And this is a project that, um, that Red Hat launched along with a number of other companies, uh, earlier this year, I think in, in May at, at Red Hat Summit.
And again, it's, uh, built around Kubernetes and it adds these key elements to, um, to distribute the cache to do horizontal scaling, to do, uh, prefill and, and, uh, predictions on where, uh, where a, an AI request should go, where it should land, so it can be answered as quickly as possible. Um, in some of the benchmarks that they've done, they've been able to get much, much more utilization out of the same infrastructure just by the architecture that they've built, uh, and, uh, and, and kind of the, um, the decisions that they're making at request time, uh, so that they're much more efficient. So these are the things that I think we are going to see emerge as really important technologies in the cloud native community, uh, coming up.
So if you want to, uh, want to get started, what are some practical first steps? Um, I think, you know, it's pretty simple. Experiment, standardize and measure.
Uh, deploy a, a single open source model, go to hugging face. There are an unlimited number of models to try. There are large models, there are small models, there are specialized models.
Um, you can pick one, deploy it into your infrastructure, perhaps try it with something like LLMD or AI bricks, uh, but definitely containerize it, standardize how it's, um, packaged and deployed. Uh, because one of the key things that you're gonna want to be able to do is make sure that you can do repeatable deployments of this workload, just like other workloads. And, uh, and finally, you know, agents, agents are the hottest topic right now out there.
And I think the, uh, the reality is we can't have agents without inference. Uh, one of the simple ways to think about an agent is that it's a, uh, it's a loop against one or more AI models. If we think about our, our kind of most common interaction with an AI model today, a lot of times it's a chat with a chat bot, like chat GPT or cloud code or something like this.
And it feels pretty interactive and, and even pretty fast, you know, if I, if I ask for, um, recommendations for, you know, a trip or restaurants or hotels or this kind of thing, it comes back pretty quickly with, with a set of responses. If I say, I want to create this kind of application, and it needs to have these features, it comes back pretty quickly with suggestions for how to create that stub code. You know, uh, I can tell it, okay, flesh this out and make all the code needed to work.
And it, and it feels very, uh, very snappy and in that sense. But in reality, that's actually a pretty low volume and pretty low performance type of use case. When we talk about agents, agents are going to be doing that thousands of times, maybe tens of thousands of times more frequently than we do as humans, because we're going to give it a task.
And it might be, uh, you know, put together an itinerary, fine prices and, uh, and hold reservations for a, a trip to London in the second week of November. Think about all of the interactions that you would have going back and forth if you were to do that manually. The agent is going to do that, and it's gonna do them much, much faster than we would.
So our models are going to need to scale to become much, much more performant. So we're not going to achieve that kind of agent, uh, nirvana that we, we want to get to unless we first build out massive inference capacity. And so this is, this is where I think all of these, um, elements of training inference and agents and applications tie in.
But I think that we will get there. We're gonna build, uh, an incredible footprint of inference within, uh, all of these enterprises. I think the cloud native community is the one that's gonna do that.
And then when we get to enabling AI agents, I think that, again, this is gonna fall on cloud native, uh, and platform engineering teams because these AI agent systems are going to be the next workload after we crack inference, we're gonna have to crack. How do we run these agent systems in a way that especially takes into account security and scalability? Uh, these agent workflows are going to be, um, so much more complex than, uh, than I think the, the workflows that we're used to now.
And we're going to be expecting these agents to have access to, uh, to key data from our personal lives and our work lives and our enterprises. That's where the real value is going to come in. So we're going to see just an incredible increase in demand on inference systems and also incredible complexity that we're gonna need to solve somehow.
Um, when we think about the security model, especially, uh, we are gonna want to go beyond the security models that we have that are maybe built around kind of static applications and, uh, human actors within our enterprises. And we're going to need to be thinking about a much more dynamic environment in some cases. Uh, we already see AI systems that generate code and generate an application just for a single session to accomplish something that has a, uh, a, a special, um, kind of requirement in it, and then that code goes away.
So this is disposable software that's being created to solve a need in that moment. And, uh, and that's going to require much more sophisticated security models. So I wanted to put in a little plug here for another, um, CNCF project, which is open FGA, uh, this is a fine grain authorization project, and, uh, it's a, it, it's, um, it's an early project, but also quite mature and quite robust.
So I'd encourage you to check that out and, uh, and get involved in it. There's definitely an opportunity to help shape where that goes and, and get involved. And I think it could be one of, um, one of the important components that can bring, uh, this, this world of a agentic AI to reality for us.
So to sum up, you know, ultimately I think what we want is we all want productivity. We want, uh, kind of that autonomous productivity that, that is, uh, the promise of ai. And for that we want agents, but to get agents, we need inference.
Um, and we are seeing a shift from this kind of, uh, massive training supercomputers to I think the world of production AI systems and widespread adoption. And what's going to drive that is cloud native expertise and our community and our members. So dig in.
Um, this is gonna be a, an awesome experience for all of us as we get to learn about this and, uh, and deploy these systems. And if you want to meet other folks who are doing that in just a couple of weeks, we will be in Atlanta at KubeCon Atlanta. Um, tech Strong will be there as well.
So come join us and, uh, let's talk about ai. Thank you Sumo logical ai, open AI's, Mixpanel, mix up HPE preps, a Pentagon project, take over scamming for fun and profit AWS and Google attempt to make multi-cloud easy. Again, LogicMonitor catches Catchpoint, and we're gonna take a closer look at a AI Apple's AI executive exit in this week's episode of the Tech Field.
A rundown. Hello everyone and welcome to the Tech Field, a rundown. Today is the 3rd of December.
We are in the final month of 2025, but the news just keeps on rolling, and we hope that you're doing something rather secure today for all of those holiday packages that have probably been delivered to your doorstep recently. Uh, did you know it's National Package Protection Day? Who, who could have known?
Uh, but joining me of course, is my protection, my, my bodyguard, and a guy who makes sure that I don't mispronounce any more names. Mr. Ter Cook, cook.
Al, it's good to see you again. Always good to catch up with you, Tom, and to catch up with the latest news on National Roof over your Head day. And I understand that that's fairly important at the moment to keep the snow off your head where you are.
It also keeps the sun from burning my not so covered here. Yes, folks, this is the joy of having a global news show is that, uh, some of us are super hot, some of us are super cold, but what is always hot is the news that we're bringing you this week because we got some real fun stuff. We're gonna kick off with a story from Sumo Logic because they're rebuilding their AI approach with two new agents.
One is known as the knowledge agent, and one is an SOC analyst agent, and an early version of Model context Protocol, MCP server support that will serve as a foundation for a more open, unified system for IT and security operations. Uh, this was announced at AWS Reinvent 2025, which is happening this week, and the shift aims to make it a lot easier to manage many AI agents and improve collaboration between security and IT teams, while also keeping humans in the loop. Full MCP platform support is planned for 2026, which will eventually allow organizations to plug in their own custom AI agents as AI driven operations mature.
Al is Sumo Logic on the right path here by kind of revamping what they're doing and adding MCP support? Absolutely. I think this is kind of vital for anybody who is building applications that need to deal with a large amount of data, and particularly data from a variety of different sources.
And that's essentially what Sumo Logic's all about, is ingesting all of your security related log information. All of the, uh, data flows coming in. We've discussed this on the rundown before, there was absolutely a need for AI tools and particularly ag AI tools to go and take actions in response to some of the Ag AI attacks that are turning up.
So we're definitely seeing more of that arms race and vendors and the security and logging and pretty much any defensive space need to be on, on board with making sure that they can respond as fast as attackers can, can attack. And this is in itself, this is just following standard best principles around how you build security and defense. You, you need to be able to respond at least as fast as, uh, as the attackers are changing their moves.
Uh, it'll be a little while as, as we see the MCP server, which is gonna allow us to integrate the Sumo Logic part of the AI into our wider AI uh, context, our wider AI application set, it's coming, it'll be generally available in 2026, so you can certainly play with it now. And we're not sure when in 2026 because of course we're less than a month away from 2026 itself. Um, definitely seeing this, uh, use of MCP is a common way of gluing together multiple AI tools to get the best outcome that you can get.
And, uh, Sumo Logic is definitely talking about having more of these AgTech AI tools coming out over time. It's still fairly early in enterprise acceptance of ag agentic tools actually making changes to things like your security posture within your organization. And so it'll take a little while to build up the trust that these tools will actually do what we want and won't be influenced.
Unduly won't then become an attack vector themselves, as of course, any automated response system is an attack vector for, uh, for an attacker. So lots of work to be done here. Uh, great to see it going along.
And of course, this was announced at AWS Reinvent 2025 going on right now. We expect to have a lot more to say about what was announced at Reinvent on that next episode of the Rundown, and I imagine there'll be plenty of AI on that. Speaking of AI open, AI says that a security breach at Mixpanel.
Uh, so former analytics vendor exposed a limited information for some API users, including me. I got an email telling me that Open ai, uh, was aware that Mixpanel had been compromised and that names emails, rough locations, b browser details and user IDs were exposed in this. Uh, it wasn't OpenAI systems that were um, compromised.
It was systems that received data from OpenAI. So, um, this, this should be no chats, no prompts, uh, no API, keys, passwords, or payment data involved. And OpenAI has removed Mixedpanel notified effective users including yours truly, and is reviewing other vendors of CO as well, because of course, if one of the vendors can be compromised, maybe others, um, users are urge to watch for phishing attempts and enable multifactor authentication as this should already have an open AI will continue to monitor the situation.
Tom, does this surprise you or give you any reason to be concerned about using open AI tools? No, it doesn't. And this is very reminiscent of last year's big Ticketmaster and Satan database breaches that all had the same common route that they were all running Snowflake and somebody forgot to turn on two factor authentication.
This is kind of table stakes, if you wanna call it that when you are working with companies that you kind of partner with and, and mix panels no different, uh, you know, open AI's job is not to build analytics. Their job is to build an LLM that, uh, tells you how many Rs there are in the word strawberry sometimes. Uh, but what they're really doing is they're, they're offering these integrations with tools like Mixpanel to say, okay, well if you wanna farm this data out to these people, then you know, we'll do that and, and let you kind of do whatever you want to do.
But how do you get the data from OpenAI into Mixpanel? Use an API. And that's basically what happened here, is that somebody got into Mixpanel and kind of breached their database, and when you breach them, you get all of the connecting information between Mixpanel and OpenAI, which in this case is names, email addresses, and API keys.
Uh, you know, first things first, invalidate all the API keys. Uh, OpenAI already went in and yank mix panel out. It's not even an option.
They slammed that door shut. But as I said on a, uh, recent episode of Security Boulevard, which I believe will be coming out in the next couple of weeks, um, this is kind of what you have to do if you want to enable systems to talk to each other, right? You can't close the door completely if you want to integrate, you know, think of it like an active directory federation.
Like there's a certain amount of information that I'm gonna have to share between those two systems in order for them to be able to talk to each other. Does that mean that there is a possibility that something bad could happen if one of those systems gets breached? Yeah, but my job is not to prevent the communications.
My job is to design the system so that if the breach does happen, it is minimally invasive and easily, uh, cleaned. And that's exactly what happened here. I don't necessarily fault OpenAI for this because OpenAI did what any other company in this situation would do.
They partnered with somebody that they said, we are reasonably sure that you're taking all those precautions. They didn't. They got breached.
OpenAI closed the hole. Like, that's how you're supposed to do these things. So I think the fact that OpenAI had to disclose that they, they were, they suffered from this because of one of their partners, probably was more news than the actual breach itself.
But I, I don't know that how you could have prevented this if you're OpenAI other than saying, well, we're not gonna partner with anybody, which honestly reduces the utility of using open AI in the first place. So, lesson out there to all of my security friends, well, two lessons. One, make sure your Subscribed Security Boulevard podcast that we produce, uh, here at the Futurum Group.
But second thing is make sure that your defenses are ready to step forward just in case someone manages to breach you and, and get on the beach, so to speak. HPE won a $931 million 10 year contract to expand the defense department's secure private cloud. The project uses HP's GreenLake platform to give the military cloud-like flexibility while keeping sensitive data on controlled infrastructure.
It supports multi-tenant workloads, central management, and AI ready systems, which is another step in the Pentagon's ongoing IT modernization. Push. Al, we've covered the Jedi contract number of times in the past, and, uh, that was a whole lot of drama that I really don't care to revisit again.
How did HPE slip in the back door with GreenLake and, and make this into something that they can hang their hat on? Well, it seems that this is a relatively small purchase. Last week on the, the rundown, we covered the, uh, uh, $50 billion for, uh, a Amazon or AWS build out for defense.
Uh, so when we look at sub billion dollar spend, uh, I know it's a lot of money and I'd much rather it was in my bank account. Uh, it's, uh, it's not that huge of a spend. So maybe this was just a, uh, an ongoing piece, uh, of, of development.
Uh, I like that this is centered around HPE GreenLake private cloud, uh, being deployed and, and to take workloads that don't suit pushing out even into the regulated cloud environments. Uh, defense networking is always very complicated. There's always different levels of security required and, um, good very strong isolation between the, the different environments to be they secret, top secret or operational.
All of those, those separations. So, um, this is, again, delivering things like AI readiness into the infrastructure for those more secure locations where you can't farm it out to open AI. And, oh, oh, hang on.
Did we just mention that? Uh, yeah. So bringing things on premises, putting these into air gaps, locations where there is no internet connectivity, uh, provided as well.
Uh, but still with centralized management across those secured networks, across each of those secured networks, you have to manage each of them separately. Uh, it does sit within that wider wave of lots of money being spent on upgrading and improving the, uh, compute environment and modernizing applications for defense. Say, $931 million is a, a good big spend for, uh, uh, the, the customer who is, um, yes, buying some infrastructure.
But on the scale of investments for government and defense spend, uh, computing spend alone, it's, it's not a huge amount of money. It is looking after those highly secured networks, highly secured applications, and potentially being used globally with thousands of users. So this could well be lots of very small, at least on defense scale.
Lots of very small deployments. I've seen, uh, entire clusters put into, um, units that can be deployed out the back of a, a cargo plane and, uh, land on a field and then be assembled up. That kind of infrastructure is the kind of place where it really is a gap and, and needs to remain that way.
There's no indication that this is about air deployable data centers, but it is. Uh, P'S Greenlight getting a, a big thumbs up from Department of Defense, the FBI says that scammers opposing as bank staff, and they stole over $262 million this year by tricking people into giving up information they shouldn't. Social engineering is still at the, the core of art of hacking, whether that's logging credentials or multifactor authentication codes, uh, all of the usual kind of ways of getting in front of people, text calls, emails, websites that, that look like your bank site and aren't, um, all kinds of things.
Attackers gain access to your credentials. They convince you to give them your information, and then they drain your money. Whether it's getting into your company's financial systems.
Payroll, um, crypto wallets can't take takeover, and phishing is on the, on the rise. Users are still practicing poor security habits. Experts, uh, suggest strong passwords, multifactor, authentication and skepticism.
My skeptical colleague will advise you some more on this. Mr. Hollingsworth.
Um, go look up XKCD 5 38. Everybody knows this one. You know, we don't need to create this massive quantum encryption state machine to steal valuable data from folks.
We just drug them and hit them with a $5 wrench until they type in the password. That's really what this is about. As much as we talk about, you know, using AI to create these things and quantum resistant encryption and all this other stuff, most of the time the fastest way to get access to a system is to call somebody and pretend to be it.
Uh, I reference again, the Seminole 1995 were hackers. Uh, Eddie Vetter doesn't work in accounting. He does not need you to read the number off the back of the modem to gain access to the tape library at the local public access station.
The real ones no zero, cool for life. Now, this, this is a thing. We, we have gotten to the point where we really have educated people about as much as we can.
It, we've just gotta reinforce things. One, strong passwords, but better than that two multifactor authentication and pass keys. Um, I had to reset a password today that I managed to have forgotten.
And, uh, in the meantime, when I was in there, I also turned on MFA for that account and looked around and it didn't have passkey support. And it needs to have passkey support because that prevents these kinds of things from happening. And third, and most importantly, never ever, ever, ever give any of that information to anybody when they call you.
Um, I, I think I've mentioned this before on the rundown, but I had a friend who called me in a panic because her daughter's Instagram account got compromised. Um, and the way that it worked was a friend of hers on Instagram messaged the daughter and said, Hey, I got locked out of my account. You're gonna get a five digit code texted to you.
Can you please give me that code? Y'all know what happened next, right? Because she immediately got forced out of her account password, email changed instantly while I was on the phone trying to troubleshoot this like that.
That's how fast it takes, folks. They are really, really good at this. Never give anybody your password, never give anybody any codes that you are texted.
If you didn't request it, do not read it off to anybody. If someone calls you saying they're from it, from support, whatever, because we all know emails are probably a scam, but even if they call you, don't answer anything. Don't give them any information.
Hang up and call the number back because odds are good. You can spoof caller id. I've done it before when testing systems odds are good that they're not doing it for legitimate purposes.
But why would they wanna steal anything from me? I, I don't matter to anyone, really, by the time they've cleaned out your bank account and your savings account and your investment account, because you use the same password on all of those, and I hope you didn't use the same password on that crypto wallet that you have hanging around on your desktop or that you've uploaded to the cloud. Do you see how it's basically kicking in the front door and swiping whatever they can get their hands on as fast as they can get to it before you can change all the passwords?
Yeah, that's what they're looking for. They're looking for easy cash outs. And your bank isn't going to help you if you are the one who gave them all that information, because to them, it looks like a legitimate transaction.
Be smart, educate yourself, educate your family, especially young kids and older parents and grandparents. 'cause if we can stop this, then, you know, who knows? Maybe, maybe we don't have to have the story again, again, again, AWS and Google Cloud have launched a joint service that lets companies quickly set up fast private connections between their two cloud platforms.
This partnership, which honestly is a little bit unusual for fierce competitors like AWS and Google replaces today's complex manual multi-cloud networking with a simple click to provision link built from AWS interconnect and Google's cost cross cloud interconnect. The companies also released an open standard, which they want to use to encourage wider adoptions. With early users like Salesforce, praising simplicity and reliability, the move reflects growing cluster demand for smoother, more secure multi-cloud setups.
As businesses rely on more multi-cloud providers. Al, was this something that customers really were asking for? Or is this an olive branch to the rest of the industry saying, see, we can play nice.
This is absolutely something customers were asking for, and they've been asking for it so much that, uh, recently in the, uh, UK competition and markets authority, both AWS and Google said it wasn't needed. And that multi-cloud interoperability is not a barrier for customers. The fact that they cannot, uh, that customers cannot just simply join together the networks that they've crafted inside AWS to the networks they've crafted inside Google apparently isn't a, an impediment.
Uh, the reality is customers want to care as little as possible about the mechanics of connecting together their hybrid multi-cloud environments. They want efficiency in that data transfer. If they've got part of an application on AWS and private on Google Cloud, they want to be able to get connectivity between them to be, uh, fast and efficient and as cost as possible.
I really like that this has being, uh, described as being entirely software. Historically, whenever we wanted to connect a cloud providers network to our own, somebody had to patch some fiber cables and we had to send somebody to a data center for it, that severely restricts our agility from making those changes. And particularly means we're not gonna make them in response to something like a change in availability of services.
There's a line being drawn out to AWS's outage that if there was, uh, the, the outage last month, if there was easier connectivity to other clouds, we could have potentially transitioned our workloads between them. Uh, I'm not sure that that's the actual reality for most customers. Uh, it is often that they have applications that live in one cloud that they need to talk to, uh, applications running in another cloud.
This is definitely a good thing for customers to be able to easily interconnect between their multiple cloud providers. And if the standard is properly open and not heavily biased, we may well see uptake with other cloud providers. Of course, Microsoft Azure is the, uh, big name that's not on this announcement that would probably have been good to have on the announcement.
Maybe that'll be coming shortly as well. Maybe we'll get that announcement at reinvent. Who knows?
Uh, certainly Salesforce, a big customer, is, is very happy with this connectivity improvement for them makes it much easier to connect together parts of their applications and partner application for this particular LogicMonitor has acquired Catchpoint to build an AI powered observability platform designed to prevent downtime instead of reacting to it by combining LogicMonitor infrastructure monitoring and AI engine with Catchpoint's internet level, uh, performance data. Uh, the new platform offers end visibility across cloud code and the internet. Customers get unified in insights, fewer tools and predictive alerts that fix issues before they impact users.
The companies say the deal is a major shift from reactive IT to proactive AI driven operations. Has your AI driven operations across the internet to, Well, it hasn't driven me off of a cliff yet, so I'll take that as a plus. I, I think this is actually a smart move on LogicMonitor part because they really do have on-premises enterprise IT infrastructure, that market kind of locked up, right?
They're iterating there by providing AI driven, uh, insights and things like that. But what you're missing is visibility outside of the firewall. Why would that be important?
I don't know what's happened in the last month. Uh, Amazon botched a DNS update, uh, cloud flare botched a robot's file. Oh yeah, the internet went down.
So my stuff online on on site works. My stuff online does not. Whose fault is it?
Well, we know what happens. We get the finger pointing, whose fault is it? I don't know.
How do I fix it? I don't know. But at least with LogicMonitor now having Catchpoint visibility built in, you can figure out where the problem is to know where you need to be making the phone call to make it happen.
And I think that that's something we're gonna start seeing more and more. You know, we saw Cisco buy a thousand die. We've heard a lot from our friends at Kente about doing this, uh, many times at, uh, networking field, A but also at Cloud Field A and a lot of other places.
And Catchpoint has also presented recently at, at Cloud Field a And I think that what you're seeing is the shift to say we need to have a source of intelligence to feed to our AI algorithms to be able to provide insights into where the problems are. Now, the outage thing is probably like the big winner here, but it's important to understand that any kind of latency or delay in the system impacts your users and you need to be able to keep an eye on that, right? Are you seeing latency growing on a link over here?
Well, maybe it's time for us to switch. Maybe we need to go to that backup NPLS circuit that we've had on hold for whatever rainy day problem that we might need to have. Or maybe we need to route traffic through our private network into a different DIA port so that we can get out and around whatever problems we're seeing.
Um, this is actually a huge problem for people right after we get back from the holidays here in December, uh, January, usually those first two days in January when we're back in the office, everything just kind of falls apart because, you know, the Amazon transit gateways aren't used to getting that much traffic. Well now with basically like a White House, like a, uh, an observability sphere, if you will, on what's going on out there, you can see if those numbers are ticking up, if those requests are taking longer than usual. So you can kind of calm your users down and say, okay, guys, have a glass of leftover eggnog.
Let's let this storm roll past and everything will be fine. I think this is a good pickup for, for, uh, LogicMonitor. I'm happy that our friends at Catchpoint got a good exit.
Um, can't wait to see how they integrate this. I'm sure we'll be talking more about this on the rundown sooner rather than later. Alright, it's time for our closer look and I hope you wanna talk about AI because that's what we're gonna be talking about.
Apple's AI Chief John Gian Andrea is going to be retiring after some delays in criticism around Apple intelligence, including the much rumored and often postponed Siri overhaul. Amar Subra Manaya, and I'm sorry if I butchered that. Um, who was a former per, uh, AI person at Google, who was responsible for doing a lot of the Gemini stuff, been there for 16 years, and most recently left to go to Microsoft in June, will now be going to Apple.
He's gonna take over as the person who's gonna be in charge of Apple Intelligence, he's gonna report directly to Air Force one himself, Craig Federighi. And Apple's gonna be reorganizing its AI teams a little bit. Gian Andrea will stay on and as an advisor up until spring of next year.
And then he's probably gonna go take his money and buy a yacht and sail around the Mediterranean or something, I don't know. But, uh, the shakeup shows that Apple really is still trying to catch up in ai, which is mirroring some other leadership churn that we've seen in other tech companies as they kind of try to adjust to what's going on. I know we talk a lot about enterprise AI adoption, but this is an interesting problem because this is pretty much consumer focused ai and a lot of people, if you read the forums out there are, you know, criticizing Apple for being behind on ai.
And some other people are saying, well, I don't understand what the big deal is. And of course there's talks about bubbles and stuff like that. Al, I'm gonna let you jump in here to start.
Do you think that Apple is behind and do you think that bringing in the wizard behind Google Gemini is gonna be the way to fix it? Well, apple is definitely failing to deliver Apple intelligence and AI the way we would expect. Uh, for me, one of the most telling things is we have, uh, a couple of delegates who will use chat GPT on their iPhones to ask questions and, and get background information as we're doing for our events, our tech fields, events, even if they're on their iPhone, they're not asking the question of Siri, they're asking it of chat GPT.
That's, that's pretty telling. That's saying that, uh, Siri is not keeping up with chat GPT in terms of delivering ai. And that's fundamentally what's going on here.
Uh, we'll recall that Johnny, ive left Apple and went to found a, an AI startup. This again, follows the same idea that, that Apple just isn't quite getting or delivering AI as, uh, visionary people are expecting it, whether Superman can come in and shake things up enough, whether he will have enough power and, uh, that, that he can shift the thinking in Apple to actually deliver what's needed. What's wanted here remains to be seen.
Uh, it's always a challenge coming in from outside the organization to try and make large changes, especially for an organization that has attempted to do a particular thing. AI in this case, uh, and specifically generative AI for a long time and has not really delivered that generative ai, it's very hard to come in then and get that transition, the sweeping transition. It's also interesting that the reporting line changes.
So Gianna Andrea reported directly to Tim Cook, whereas Superman is going to be reporting, uh, indirectly. And that doesn't, to me, smell of we're gonna really enable you to do big things and make big changes. Uh, let's hope I'm wrong.
Let's hope that Sury actually becomes the, the new interface that we're going to use to gain some, uh, insights about what's going on around us. Tom, I know, like me, you're, uh, an iPhone user and, uh, have had Siri at your fingertips. Has Siri done great things for you?
Do you use chatt PT on your iPhone? Uh, I actually don't. Um, I've, I've used some AI LLMs before, uh, but I'm gonna take a little bit of a contrarian view here because, well, it's my show and I can, uh, what exactly did Apple fail to deliver on, uh, audience out there?
I want you to leave a comment on this video. What, what did Apple fail to deliver on with ai? What exactly is the killer use case that you are looking for in an on-device ai?
Is it to look up the batting average for the 1953 Dodgers at a moment's notice? Because you need to do that to win a bar Trivia contest. Is it every tech bro's dream of having a system that will automatically make dinner reservations for you?
That's actually a, a, a TikTok that I watched the other day. Every piece of AI that I have seen so far that is consumer focused is trying to get your phone to act like an automated executive assistant. I wrote a blog post about this recently where I said, AI is designed by people who want people to do things for them.
When you look at the executives, when you look at the senior vice presidents, when you look at the people who are showing all this off, what are they, what are they showing off? It will provide context so you don't have to read through things. It will give you insights made up or otherwise, and it will make dinner reservations for you.
It is a system designed to do things that I would have other people do. So is the killer use case for AI that I want to get rid of my executive assistant? Or in the case of people like me who don't have one, do I want a system to do that?
Is that what Apple missed on? Because as far as I can tell, there's some things that Siri can do that chat. GPT can't like anything to do with the actual device that I I'm dealing with.
And do you know why that is? Do you know why chat GPT can't turn on low power mode or send me a reminder for something? It's because of the privacy focus that Apple has had and yeah.
Alright, you're gonna leave a comment. You're gonna tell me how Apple doesn't have a privacy focus and all that other stuff. And hey, I agree with you.
What's Google's privacy focus? What's, um, the, uh, the Xmi phones privacy focus? Do, do you have a, a list of the things that they've done?
Uh, do you have a new story from this week where, uh, a nation state asked Apple to force an app to be put on the phones and Apple said, no, I don't think we're gonna do that. Right or wrong? Apple has been focused on keeping things as isolated as possible.
Yeah, that means that the lady that lives in your phone is not as functional as chat GPT is right now. But what it does mean is that if you accidentally say the trigger word and then say a whole bunch of random stuff that you don't mean to say, it doesn't end up in an LLM database to be crunched and done all these things for years and years and years. I don't necessarily know that there is a direction for this, because remember when we talk about all this AI stuff that's going on on the other side of the fence with the open ais and the NVIDIAs and the Microsofts and the AWSs and all that other stuff, that's B2B that is selling hardware to do inferencing to create better models to do what?
Because again, I have to come back to Apple is a trillion dollar company that sells phones, tablets, and laptops to people. OpenAI is worth billions of dollars. And what do they sell?
Because as far as I'm aware, according to the news stories that I've heard this week, they're gonna have to start injecting ads into chat GPT chats because they don't actually sell anything. They sell a subscription to a thing and they don't bring in billions of dollars a year from that subscription. In fact, most of the time most people who use it don't pay for it.
So I'm, I'm still struggling to understand why someone who had been at Apple for several years had to be forced out of retirement. 'cause he retired, but he didn't really retire. He was told to retire.
This is a way to prevent the markets from going crazy. What, what, what are you, what what is it gonna take? Like, like, you know, this is not the Steve Jobs moment of I have a web browser and a phone and, uh, PDA in a thing in my pocket.
The, we're past that point. That was 18 years ago, folks we're, we're in a different world now. I don't think you're gonna get the killer app that you want, Al am I wrong?
Usually? That's fair. That's fair.
That, You know, the, the, the killer app is I think definitely a, a dead term. Um, the killer use case of not having to wade through nearly so much information, not having to try and find the little bits that I'm interested in, in the flood of information, or to be able to find the place that I want to go, the person that I want to talk to. These are the things I want from, from ai.
I want it to take away all the, the, the drudge work. So yeah, booking a hotel is, is an entirely relatable piece of drudge work. But, uh, being able to look at the 600 emails that have come into my mailbox and actually intelligently work out which ones I need to act on, that's the kind of thing I want from a, a good ai I'm not seeing that's the opportunity is is there to help us with the information overload we suffer from.
And most people do suffer from too much message, too much, uh, information they need to process and not enough insight being delivered to them. So that's what I want from an AI that I hold in my hand every day. Of course, I want it integrated with the laptop that I have in front of me for way too much of every day.
Uh, and I really do want that consistent view of who I am and what I know, what I care about, rather than, uh, some very generic stuff. I've, I have found Surrey quite disappointing at finding even as simple as things as, uh, tell me where the nearest supermarket is when I'm sitting in the car park of a supermarket in Surrey. Doesn't tell me that supermarket, there's a whole lot of things that, uh, are challenging for me in, in Syria and more development towards that intelligence.
Uh, or at least the ability to handle large amounts of unstructured data and turn it into some semblance of, uh, insightful data would be very helpful. We'll just have to see what happens, because of course, this is an ongoing story, just like a lot of other things that we deal with here at the rundown. So rest assured, when when the Killer Sir app comes out, we'll, we'll be sure to let you know.
Um, but we won't be asking it to tell us how to do that because, you know, it's a little hit or miss. What's not hit or miss is, of course, all of the great events that we do. We are, we're pretty much done with events for the rest of 2025, but 2026 is starting off with a bang, and that's because Alistair's coming back to our side of the pond to enjoy our winter again.
But, uh, you've got a cool thing coming up. I have a cool thing, although it'll be for a winter, it'll be a warm theme because we will be, uh, back in the Santa Clara region, uh, around, uh, Silicon Valley for AI infrastructure field. Day four, I'm not expecting any snow, but, uh, it should be cooler than it's here in January.
So the end of January, we have, uh, currently six different companies presenting, uh, lined up to present over the three days of the event. Quite a few more that are gonna join in as well. I've been building out the delegate panel, some great people, some people that I haven't had at my events before.
Uh, and looking forward to having some good discussions with a collection of vendors. We've got quite a leaning towards networking for AI infrastructure on this one. So that'll be an interesting insight to see.
And of course, uh, following on in March, I return again for Cloud Field Day. Uh, another of the events that I really enjoy is digging into what it actually means to use cloud as part of your infrastructure. And, uh, looking at the realities of these hybrid multi-cloud, we covered AWS and Google joining their networks together.
That kind of, uh, capability is what we'll dig into some more in cloud field 11th than 12th of March. Well, don't forget that we're always adding new stuff to the calendar every time you turn around. So just because we've announced the first couple of events doesn't mean we're not gonna be in a lot of other places.
com is your home for all of that stuff, so make sure you check it out. You never know when something's gonna pop in. We want to thank you all very much for watching the Tech Field Day rundown on this Wednesday.
Remember that you can catch new episodes every Wednesday on YouTube, but also in your favorite podcast application of choice. We'd love it if you'd subscribe, uh, leave a comment, leave a rating, leave a review, a thumbs up, something, because every one of those things helps people figure out if this is something that they wanna be listening to. And we, we do appreciate everybody who has, uh, suggested stories, who has, uh, given us great reviews, who uses us as their sole source of news because quite honestly, we try to make it fun around here.
Um, we will be back next Wednesday to talk about all the news that happened, especially the stuff from AWS reinvent. So make sure that you're tuned in for that. Until then, everybody take care of yourselves.
Enjoy the rest of your week, and we will see you next time. So, Mickey suing Google, you're watching Text Join gang. Hey everyone, happy Monday.
What a great weekend. I, I, I gotta be honest with you, this time of year, this close to Christmas, I'm not real excited about coming in here on Monday. I don't know about you, but, um, you know, the, these are, this is the time of year when you want your weekends to sort of stretch, but we got an interesting situation this year, right?
Because Christmas Eve is on Wednesday night, Christmas day's, Thursday, most people are probably off that Friday. And then it's the same thing next week for New Year's. So there's gonna be a lot of very, very long weekends this Christmas, uh, holiday vacation.
I hope you all are able to take advantage of it. Now, the folks at Mickey Minnie, Donald Goofy in the gang, they're gonna be brushing up their legal briefs as they are ready to, uh, go after Google here for what they're claiming is massive scale copyright infringement. We're gonna talk about it with our gang today.
Let me introduce you after a brief hiatus. She's back. She's back, uh, uh, one and only Tracy Reagan.
Tracy, good to see you. Jack Parler, who, who's a regular, I'm sorry. I was just gonna say it's so good to see you.
It's really great to Hear. Absolutely. We missed you.
We missed you a lot. You, your absence was felt, and I know you were doing good work, but we love to have you on here. And then joining us back home in New York after his recent, uh, trip to the city, he's back up in Harrison, not named for a president, Mike Ard.
So gang Mickey Donald, they're carrying their briefcases marching into court, claiming a massive scale of copyright infringement against Google for AI systems. What I, what I find is ironic is at the same times we're seeing, at the same time, we're seeing stories of Disney licensing characters and IP and, you know, two, two AI companies to use. It Was a massive Kuka dinky.
Yeah, that's what they call it. A Ky dinky, you know, cha-ching. Um, that's the old carrot and the stick, right?
Mike, what do you think? Well, I guess, so are these Disney characters? I think the OpenAI deal is worth a cool billion.
So are they gonna go around to everybody now and ask for a billion dollars? And did Google Bach at the billion dollar fee? I mean, how did this number come about?
And is this the going rate now for Disney characters? I don't know. Alan, what do you think?
I think Disney has a well-earned reputation of being a little heavy handed when it comes to asserting copyright claims. And, um, it could very well be that Google didn't pay up and so this, this was the stick, if not the carrot. Uh, now on the other hand though, if I'm the biz dev guy at Open AI and I'm shelling out a cool billion, and I know a billion's not what it used to be anymore, it's just a billion, not a trillion.
2 to compete with the latest Gemini. I make sure I had some exclusivity there for a billion bucks. But I guess, like I said, a billion doesn't buy or what it used to.
Well, I think it's buying Disney something, right? They, if you think about the, I thought the two announcements were kind of, uh, coincidental and I don't really believe in Coincidence. Winky dinky.
We don't say coincident. Yeah, exactly. Mike is coined the new term.
It's Ky Dinky, So is KY Dki. Um, and, but I don't, they have, this is something they've done for a very, very long time. If you went out and got a t-shirt and put a mickey on it, or, you know, even something that looked like a little mermaid, you, they're gonna go after you.
They've gone after smaller people. Mm-hmm. Um, this, this is a bigger problem though, um, with AI in general is going out and digging through, uh, what might be copyrighted information like newspapers.
Uh, so this is, this is just the, the beginning of the conversation. Who owns that content? If you, if something gets generated through your ai, do you own it because you ask for it?
Or does OpenAI or Google own it? So this is just the beginning of the conversation, but I think that they did kind of a ninja pivot here by going and investing in OpenAI and then establishing a licensing model for images because they are now taking in charge of the conversation and they've bought, uh, a position within OpenAI to push OpenAI to make that possible. I think it was a brilliant move on their part, and it probably will be the beginning of how a lot of copyrighted material is, um, managed.
I don't know how they're gonna do it overall, but Disney and, uh, apparently OpenAI is gonna figure something out. And Disney's now owning open ai part of it at least billion dollars is like a, a good chunk of it. So, So I, but that's the open AI model, Chasey, right?
They, they, they like to do these reciprocal things. I'll give you something. You give me something, it shows up on my, my books as revenue or investment, even though I'm giving it back to you in cost and, and we're all happy.
And it's funny money going in a circle jerk, right? Yeah. And Nvidia does it all the time, right?
But, but Open AI does it to the tune of one and a half trillion dollars. We recently had this a couple weeks ago on the gang OpenAI has made arrangements to spend one and a half trillion dollars, 300 and something billion with Oracle 300 and something billion with, uh, with, with, uh, Microsoft. Another outrageous amount with Broadcom for, for, for, uh, iterative chips.
For inference chips, excuse me. Um, a one and a half trillion dollars on a company worth 500 billion that doesn't even do $20 billion in revenue. That is incredible.
You see how much I miss when I'm not on these? Well, this is why you gotta stay up on this stuff. Exactly.
So the, so the math, the math just doesn't work. But this, I guarantee you, this was an open, this is the open AI model. Invest a billion dollars in US and we're going to put that on the books and, and we'll, you know, we'll, we'll do a, a license and buy it back, deal back, right?
So the money goes like this, it really doesn't go anywhere, But it establishes something, right? But, but, but that, and it does establish something that's, that's the key. But it doesn't establish what you think it does.
This is not about, from, from Disney's perspective, they don't care about open ai. What they're doing is they're setting a precedent saying there is value to licensing this material. Yes.
This is about winning the lawsuit and putting a stake in the ground. And New York Times has a lawsuit as well over the sa exact same thing. If Disney wins this, it changes completely what LLMs can do.
They're gonna win For every content Is gonna win as well. But, but they're winning not on, but they're, what they're doing is they put a stake in the ground saying this is real money, right? So when we win, it's not you have to license, everybody has to license from us for real money, not token amounts, right?
Not the, the, the, the court could say, yes, they infringed on your copyright, but we don't care about it. And there's no monetary award and there's no precedent. This is setting a precedent For all future stuff.
I don't think, I don't think a court, so you're talking about like the Trump suit against the NFL where the court ruled that the NFL did in fact have a monopoly at the USFL. This goes back, right? 30 years, years ago, right.
And they awarded $1. Yeah, pretty much, right? You don't Basically say you, I mean you were hurt.
You don't see that very often. You don't see that very often. But because all the thing is from a court's perspective, if they set a precedent here, it affects not just Google, but it affects the entire AI industry and how all the LLMs have built and how can they get new data to train their models.
But all of these cases, not just a case, Disney would bring the Times case. The what we've seen, what we, you know, let me back up. One of the things I learned in law school from my professors was it takes the law, the courts five years, five to seven years to catch up to society technology, like new things like this.
So there's gonna be that period of adjustment. However, what we've seen in the lawsuits on this issue date, right, is that the, the AI companies generally settle prior to a decision being rendered by the court. 'cause they know this is a losing argument.
It, it's, it's a bit of a novel case from a copyright claim. Usually the average Disney copyright claim is more like what Tracy described. Someone puts someone thing that looks like Mickey on a t-shirt or a pocketbook or something.
Or in the case of the New York Times, someone is hiring their content without acknowledging and attributing and licensing, right? It's very clear cut. The, in the AI case, they're, they're using this information almost as background information to train their AI and to make their AI better.
So the AI company benefits from the having that content for training material. And then that training material also does find its way in, if you will, to the output of the ai. Tracy, to your point, the courts have been clear at this point that when you ask an AI to generate something that becomes your work product, the ai, the open AI or perplexity or whatever doesn't own it.
You, you, you do have the IP to that. So you said, or you said that, uh, Disney and the Times will win these suits, but in previous shows going back a year, I can remember you kind of saying that, well, this is under fair use and so maybe they won't win it. So where are we In this?
Well, I'm, I'm like the Supreme Court. Well, I, I, I think the one thing about the Disney suit that is different is they're claiming that it's not the training of the material that's at issue as much as it is the output. Where they were actually, they were actually directing users to generate derivative works of Disney characters like Disney, like Disney, Disney.
Right. Disney and, and, uh, Sundar Phai actually did that, right? So they're saying the CEO of this corporation is encouraging people to infringe on our ip.
And that's different than we're using an IP for training. Well, you know, the gimme an op-ed in the style of the New York Times, right? And it, and it writes a very sort of New York Timesy kind of thing.
It it, it's a similar kind of thing. Well, yes and no, but if I go write a book that's based on, you know, uh, an extension of James Bond, I will get sued by Ian Fleming's family. And rightfully so, because I'm basically commandeering a character in a storyline, even though it's A new book.
Oh, Conair. Oh, Conair boy, you don't think all of these spy movies and, and, and with Suave British style agents are not based on James Bond, But they don't show up as James Bond. And I think what's happening here with these representations online is, you know, it's clearly something that looks like Mickey Mouse.
It's not just a mouse, it is Mickey Mouse. But Disney for a long time has said just about any mouse can be Mickey. 'cause Mickey's changed his looks over the years.
Mickey was originally a ratty looking mouse. If you look at Walt's old drawings, you know, from the twenties and thirties, um, he had a much longer nose, you know, he was a ratt looking mouse. He's changed though.
Mickey, I think Mickey's had a little work done. Chase. That's what I think.
I think he has too. Yeah. I think he's been softened up Right's had work done too.
Mm-hmm. Um, but that being said, you know, know being how close it is to Mickey is in the eye of the beholder. Right?
You can't just say every mouse is Mickey. And, uh, and you can't Say, you can't say every mermaid is a little mermaid. Right?
Yeah. I seem to remember going back in time, mighty Mouse was a character that went around, Right? Mighty.
Yes. He was gonna save the day, wasn't he? Yeah, he did all the time.
Mm-hmm. Mm-hmm. But, but those, you know, taking it up a level from just the pure Disney, because they are always more, not obnoxious, more, uh, more sensitive, likely to enforce their, their, they, They, they, they, they guard their privileges.
Yes. That, but you know, the bigger issue here is all of these frontier models have basically trained their models on the body of publicly available knowledge in the internet. And, and this is, that's going to be the crux of the question, right?
Can you, can you train on publicly available knowledge? But, and, and here's where the legal kind of nexus is. It used to be, you know, we had cases with links, right?
Can I, can I build a newsletter with links to the Times to the Washington Post to the Fox News, CNN And, and, and maybe even because those pages are not behind a red wall or anything. Grab some of the material from there without attributing, but have a link at the bottom. You know, over the course of the 25 years of the public or 30 years of the public internet, we, we've, there's a body of law and case law that has evolved about, you know, how you can use publicly available webpage information on your webpage or in your business.
Little different than training my LLM on it. But there's legal, from a legal point of view, they're similar. Alright.
So just to be clear, do you think Disney and the New York Times are now gonna win these cases? Yes. Or not?
I I, because it goes back to what, what you said before when I said it a year ago, they were in the public realm and therefore usable. But, you know, the case law on internet stuff is even if the ca, if the pagers are publicly available, that doesn't in give you in essence the right to pirate them. Right?
Well, as somebody who creates content, that warms my heart. Me too. It warms my pockets.
My pockets are empty, Mike. 'cause we're not the New York Times. And, you know, we gotta wait for these cases to play out because I think once these cases play out, much like the deal perplexity did with book authors, right?
Mm-hmm. Once you could prove that your book was used in their training, they, they agreed to some formula to pay you money. Yeah.
So, so my brother wrote a book many years ago about, uh, mechanics of baseball pitches with Jim Cott, I think, and it was published by Hearst, but philanthropic wound up sending him a letter saying, you may be entitled to $3,000. Yeah. Yeah.
com. We've got 40, 50,000 DevOps articles on there. Mm-hmm.
No doubt. I'd like 3000 in article just saying, That's your opening gambit. Well, No, what I thought they would give me $3,000 an article and I would invest 1500 of it back into open ai.
There you go. That is the new model I system, I think know at some point, at some point though, do we just wind up writing for their open ai? You know, it, it, there's the, there's what goes on in courts in the legal world, and then there's what goes on in the real world.
Mm-hmm. And don't, don't ever confuse justice with truth. There.
You Can go. So anyway, let's take a break here on the gang. We'll come back.
Wait, we'll talk more about ai. What a surprise. You're watching Text on Gang.
You've Earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black Club, digital executive protection, defending the new attack surface your personal life. Hey folks, welcome back. And we're back in court.
Well, there's a wrongful death suit in Connecticut somewhere involving, um, a son who wound up murdering his mother because, um, you know, he was having a, some sort of conversation with ai and the suit is against open AI and Microsoft. And apparently, you know, they're claiming at least that the AI told them, you know, that all his thoughts were correct and that people were, uh, chasing him. And that, you know, he was some brilliant person with some awesome insights and the usual of ous stuff that AI kind of delivers.
But then he wound up turning around and killing somebody. So I think we're all watching this suit to say, you know, what kind of liability is there gonna be for something like this? We have talked about some of these issues earlier this week involving children, and now it's a, essentially a murder of suicide now.
So Tracy, what's your take on what's happening here? Well, it feels more like a Halloween discussion than Goodness Smith. But, uh, so yes, this, this man was living with his 83-year-old mother.
Let's, let's just start it like that. And he was 56 years old, so there's something going on already. It wasn't The Bates Motel, was it?
It kind of feels like that, doesn't it? It really does. Um, yeah, and he probably suffered, I don't know, um, some level of paranoid delusion, but maybe many of us suffer paranoid delusion.
And regardless if it's open AI or if it's Facebook, uh, these are modeled to tell you what you wanna hear. Kind of like our politics today. Right?
Just tell us what you want to hear and we'll tell you that. So, you know, in this particular lawsuit, unlike the one we just discussed, I feel like there's some personal responsibility and accountability that has to be considered even when it comes to the case of murder. How are we, how we, how are we really gonna say that?
Because AI was telling somebody what they wanted to hear, which is what they're trained to do, and they wanted to hear that they were somehow, uh, touched by God or, uh, you know, they possessed power. Power Or their dog talked to them Or their yes or their dog talked tomorrow, their printer was watching on, was spying on them. I, I really believe we have personal responsibility has to take part in making a lawsuit real.
Uh, I, this what I'm sad about, uh, because we've talked about this now, you know, we, the, the, the community at whole and it, and everybody has talked about the impact that social media, and this is just another, in my mind, this was just another way to have a social discussion. It was a, it's more like a social media discussion. They have caused young people to be bullied and to take their own life.
Um, there has been, there's been all kinds of discussion about why we wanna manage better, what comes through these, these portals, uh, because we could have somebody with paranoid delusions who's gonna go shoot up a, a a a classroom. Uh, so we have a responsibility here. And I think that the, the, uh, AI companies have a responsibility as well, but the person has some personal responsibility.
I mean, I think what's an issue here is there's no warning label essentially on the service. So there's nobody out there telling people who may be crazy that they know this. They're interacting with something that is, um, shall we say augmenting Sort of, okay, That's true.
But somebody can go buy a, somebody can go buy a gun and shoot people and they don't. And, and the, the, the gun company doesn't have any, don't Ever, don't ever mention that Tracy. We'll all be in trouble.
Just ice will be at the door. I'm Just saying, You know what Second amendment, How do we, um, freedom of speech, freedom of speech. Yeah, I get it.
I get it. So first of all, I gotta tell you, we've, we've been discussing so many of these legal things, I feel like I should go dust off some of my old school books. Mm-hmm.
Though I don't think they use law books anymore. It's probably all computerized now. I paid a lot of money for those big fat books.
But anyway, you know, this, this goes back to something we discussed last week on the gang, and that is the difference between negligence, let's say resulting in a wrongful death lawsuit, which is a civil lawsuit versus criminal negligence, criminal manslaughter. Right? Which is a much more serious, that's a criminal, right?
You're not just talking about paying money, you're talking about potential criminal Implications. But in those cases, Alan, if you're, if you're gonna dust off your, your, your, your law books, isn't there something called intent? Well, no.
And do we, the criminal negligent negligence by definition means there was no actual will or intent, but you could still have criminal manslaughter where your, your negligence resulted in the death of someone. You may not have had what they call the mens rea, you know, the, the mind to the intent to, to do such things. But it's still, it crosses the boundary of even gross negligence to criminal negligence, right?
Getting behind the wheel of a car when you're, you know, twice the legal limit of, of intoxication. And you've done this, you've been pulled over for 2D Dewis previously, crosses the line into criminal criminally negligent manslaughter. It doesn't mean you went out willfully, But those cases are very clear on who was completely responsible, right?
So, I mean, have we seen a case yet? Hang On. So, so now you come to it though, Tracy, right?
Because what will happen here is there will be a discovery process, and then there'll be subpoenas for emails coming outta OpenAI and Microsoft. And I bet you're gonna find out exactly how much they knew about this stuff before you they rolled this out. Well see the, but see, this is this, there's exactly three things that make this different than any other normal guy going wacko and killing somebody, case.
And that is one, there's a computer record of it, right? Up until this point, 99% of the wackos, they talk to the psychic, they call the psychic hotline on 1-800-PSYCHICS. Right?
Or they talk to the, you know, they, they, they talk to their co crazies under the bridge in next to Moscone Center, right? There's just no record of it. The second thing is, it's ai and the third thing is Microsoft and open AI have a ton of money.
No, this pocket Otherwise the loss Be mistake, Jack, you're right. This is, None of this could, would be brought right Pocket. This is what they, deep pocket I'm, I was, I'm very glad that, that Tracy brought up the concept of personal responsibility.
Unless there was a record of this happening, nobody would know how this guy got motivated to kill somebody. Crazy. People who have a history of mental illness, 56-year-old people who have had extreme mental illness commit violent acts every day.
It happens all the time. And there's nobody to hold responsibility for somebody else going crazy. Yeah.
AI didn't make him go crazy. He was crazy to begin With. But Jack, here, here's the, here's the thing from a legal point of view, and this is why there's, I was trying to say there's a difference between a criminal case and a civil case.
In a criminal case, Jack, you would have to prove that open AI and Microsoft are guilty beyond a reasonable doubt of being criminally negligent here in a civil, wrongful death suit. It's what we call a preponderance of the evidence. So it's 51%.
Is it more likely than not that their product's, uh, behavior contributed to this unfortunate death, to this wrongful death? And it's a much lower bar from a legal point of view that, you know, OJ Simpson was not guilty criminally, but he was guilty civilly, civilly in the civil lawsuit to the Goldmans. Right.
I, and, and I, and I understand that. I think the issue is that it is ridiculous to, to contemplate holding a third party responsible for somebody's. So Let me, let me give you another fact pattern.
Let me give you another fact pattern that's in the news right now. Let's say instead of a however old this guy was with a history of mental illness, you have a young girl who's 1516, a minor, and she confides in her ai, which the company who made this AI purposely made their, their AI characters warm and fuzzy, almost Disney like. And, um, and she confides in her AI over 50 times, 60 times, that she's contemplating suicide.
And the AI doesn't warn anyone, do anything, try to stop it or anything else. And sure enough, the girl commits suicide. It's a real case.
We discussed suicide. It's real case. And, and, and, and I question whether did she confide in anybody else?
Yeah. Was AI alone responsible For that? Is it AI Alone responsible?
So let, let, let, lemme give you, Going back to This guy again. Lemme, hold on. Lemme let me play this out for you.
My wife happens to be a social worker, right? And so I asked her, I said, Bonnie, I said her name. My wife's name is Bonnie.
Um, I said, Bonnie, if you were counseling a young girl and she kept telling you that she had thoughts of hurting herself of suicide, what's your legal obligation? 'cause you have hipaa, right? But what's your legal obligation?
And she tells me her legal obligation is absolutely go to authorities. You cannot, you, you can't let this person kill themselves. You, you know, you're gonna try to basically get them to sign themselves in or down in Florida, we have something called the Baker Act.
Right? You can baker act them and have them basically, you know, put, put in an observation for three days. And then if it's determined at that point that they really are a threat to themselves, that they're, they, they, they stay in.
Um, that's, I mean, so substitute the AI for social worker, Except for she's, she's in a licensed regulated profession. Does it? Does a priest.
Yeah. But if you're Holding out, does a, They slept in a Holiday Inn Express last night. Yeah.
But does a, does a priest have the same requirements? So there's been case law on there. Does a neighbor does a does a neighbor does.
The girl's best friend does. The, the 56-year-old guys responsibility, Those called responsibility. Right.
Good Samaritan. There are good Samaritan laws about that stuff. And in fact, when you look at police, remember, police do not have a duty to protect or a duty to act.
But there is, there is, Right. Same thing they did Samaritan, but once they do, explain what it says on the side of The car. Right?
Right. Despite what it says on the side of the car. Legally, once the police does not happen To, to stop you from committing suicide.
They knows to it. They do. Yes.
But if a police drives, but if you tell a policeman, I'm thinking about contemplating suicide morally, we would expect them to do something about it legally. They are not required to do anything about it. Understood.
Jack, I'm telling You, A, as a lawyer, I would be salivating to take the case of that 15-year-old girl because the ais here are holding themselves out as confidants. And, and they're providing, a lot of them are providing therapist like responses to these things. This Is, this is a slippery slope, Alan, that says, at what point does, does the AI violate your its privacy requirements about you?
If you say something, how does it know if you're serious or joking? It has no ability to, to judge intent. How, how does, how does the chain professional know They have context?
So, so if you watch any television, they have kind Show these have, they have have. Yeah. But if you watch any television show these days about involves anything to do with suicide, there's a little label there that says, Hey, you know, if you're feeling this way, you should call one 800 or some sort of online service, or there's some sort of warning that says you should do something.
And that's the state of the art. And that's all open AI has to do here. Right.
Put in a rule that says, anytime someone talks about suicide, just put some blanket statement except all reject, don't sell my information. You know, and, and, and you Well, this case wasn't suicide though, right? This was a murder.
So there never discuss first case murder, a discuss about a murder. Right? Right.
Well, If so, delo of grandeur, should we say, if they, I hear it. So let, let's again, let's play law school. 'cause this is what law school's like, guys, we take these cases and we play with them, right?
So now, so now what you're saying is, should open AI give you a warning? If you tell it you're thinking about committing any crime, Or that you're delusional Or that you appear to be delusional in their opinion. This, this is, this is what I mean by the slip.
But what about the hacker who says, show me, show me how to make some exploit code to exploit this vulnerability. Exactly. At what point?
Yeah, but what's, so, I, I, yeah, I hold open AI illegal, I hold open AI liable for that. And I don't mean just open ai. I, I hold the AI liable for that.
And I think that crosses the line. Any of these, uh, social platforms and, you know, if this case, if they do win this case, I feel like it's, you know, from a social perspective, it's probably a good thing If who wins this case, If the family wins the, The wrongful death. Uh, suer not, not the a Yeah, yeah.
Because then it's gonna establish, um, that other situations, uh, like teenagers on Facebook being bullied, right? Was Facebook, should have Facebook stopped that. Well, if they, if they saw that, should they have stopped it before the kids committed To this?
But we've cycled through this, the a OL chat rooms, the cesspool of the internet back in the day. Yes. It still is.
It is still a cesspool. Are you telling us you still frequent the a OL chat rooms, chay? I don't, but I'm just saying that the, the internet, what's general?
What's your screen name? No, I don't. I Don't.
But, but no, but you know, there's been case law around this too. Uh, here, here's the deal. It goes back to what I said earlier.
It takes the courts and the legal system years, years and years to catch up to this stuff. And by the time they do, someone's already moved that cheese. You know what I mean?
The cheese has already been pushed up. And this one all the way to Supreme Court. This is a one that's Yeah.
But by the timing, Supreme Court decides that it's moved on. I think it'll play out this way though. I think the existence of the suit will force the issue.
It will become a political issue. There will be some sort of effort in Congress to address this issue, But not at the state legislatures. Right?
But regardless, and then it'll be just like, you know, the, uh, Epstein case in the sense that there'll be such overwhelming support to do something about it. It won't matter what the president thinks. Wait a second.
I feel like we should have confetti stuff dropping down. You've mentioned it. Release the Epstein files.
Okay. Alright. Hey, we're over time on this one.
What a great discussion. I, my somewhere, professor Koffler, my torts professor who wrote the book, Koffler on Torts. He's probably in heaven somewhere by now, but he's smiling down.
Um, we're gonna come back and we, we could talk a little more about ai, but this time, AI browsers, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And Gardner put out a statement essentially urging people and enterprises to ban the deployment of these new AI browsers.
Because, well, they're just fundamentally insecure and bad things can happen when prompt injections are shown in these browsers and they're connected to something else. And the next thing you know, all your data's off in the dark web somewhere. Jack has an article up on Security Boulevard suggesting that, well, this kind of misses the points, and we're rearranging deck chairs here on the Titanic.
But Jack, explain, well, Are they rearranging the deck chair? So they shoveling sand against the tide? Are they emptying the ocean with a bucket?
I mean, this is just kind of foolish. Um, you know, I mean, Gartner, of, of all the analyst organizations in the world, Gartner should know better than this one. That there is no such thing anymore as a non-AI brow and blocking things and banning things, blacklist white list.
We've gone through this time and time and time again. And it never works. It never will work.
It's too hard to keep up with the changing technology people find around way around it, et cetera, et cetera. And I just, I have no idea what they were thinking when they said, let's ban something. It's just, I mean, this is kind of ridiculous.
Well, um, I was wondering, I mean, I just, go ahead. Let me just say, let me just say one thing, which is every single issue they highlighted has nothing to do with the browser and has to do with AI in general. And it's fine to raise the alarm bells about ai, but the response of blocking browsers is just, come on.
That's just insane. I was wondering what that giant sucking sound I heard was, I guess it was everyone deleting their AI browsers just because Gartner said so. You know what?
Yes. I mean, quite frankly, this ain't your daddy's Gartner. You've had a tough year.
You remember when Babe Ruth said, how come you should make more than the president? He said, I had a better year than he did. Okay.
Gar, Gartner. Gartner, thank you, Gartner. You got bigger problems to, to, to worry about Gartner.
Um, that, that's kind of, and who, look, that train's left the station. You know, the Yeah, I could just see everyone saying, oh, Gartner said we, we, we had to get rid of our AI browser. Three people somewhere in some hole in the wall might have deleted their browser as a result.
Tracy, should we be cautious here though? Because these browsers and AI agents in general seem to be, uh, easily tricked into doing something. And we don't seem to have a lot of controls in place yet.
So how do we kinda run the middle here? You know, it's like any cybersecurity issue. It always, most of it boils down to the human.
You know, we can, uh, we can have a, a, a badging system on our door, so we, we could to see who's coming in. But if we cut and paste a bunch of sensitive data into a browser, um, uh, maybe we're asking for it. Personal responsibility.
Again, that's thing. Personal responsibility. I really do believe that, that we all have to be, you know, we all have to be on guard.
Uh, but I don't think that this should be the end of, um, using the AI browser that is, as Jack has pointed out, that is not, it's not gonna happen. But Agen AI has its issues and the community has to kind of start thinking about how to solve some of those issues. Prompt injection can happen anywhere, though.
It doesn't have to be, uh, uh, you know, an agent's, uh, problem. It can be, it can happen at many spots. Many, many connections.
So, uh, I I thought they made a pretty broad statement by saying that, that you shouldn't use an AI browser. I was, I was actually kind of giggling when I read the article. I was like, all right, Jack has really nailed it there.
What were they thinking? I But wait, if there, if there's an issue and it affects the community, don't we need a foundation? 'cause that's how we solve all our Problems.
Yeah, exactly. Well, you know, I I, I wrote a companion article elsewhere that basically, and I, and you know, if we're thinking about AI security, we should think about things like MCP, which has security as an option instead. Well, we Do have a foundation for that, Right?
Right. I mean, you know, let's, let's raise the alarm bells more. I mean, OASP, you know, OASP raised, uh, you know, a agen AI as one of their top three.
And they said, well, it might be an issue. And I'm like, it's a very big issue because security is optional. How do you get to zero trust if you don't mandate authentication and authorization?
It's just, you know, but we have big issues. And blocking browsers isn't one of 'em. Here's the reality.
It's come up time and time again here. 90% of developers are using AI to generate code. 40% don't trust it.
65% are sure that it introduces instability into the code base, but still 90% of them use it. We have similar, similar numbers for SREs and ops and platform engineers. This is where we are right now in our AI revolution, right?
We know security isn't up to speed, up to snuff. We don't trust it, but we're drawn to it like moths to a flame. And sometimes the moth catches fire, sometimes it doesn't, but no amount, whether it's Gartner or Forrester or, or Jack, you as an analyst are going to, you know, you could lay your bodies down on the tracks, but that train's just gonna run right over you.
And that's the, and we will have better security and AI browsers and better security and AI agents when the makers of the, when the customers of the makers of those products demand it when they vote with their feet and their wallets, watch how quick it gets done. But right now, they're not. 'cause we're all knowing it's some form of maybe mass hallucination, insanity, I don't know.
But knowing that it is, that we don't trust it, knowing that it is insecure does not stop us from using it. That's because those 40% are taking some personal responsibility to look at their code. They use it as the basis of, you know, to get started.
Right? And then they work from there. That, that must be what it is.
Chase, you're right. It's absolutely is. 'cause I know so many people who don't trust what they, what No, 40% don't trust it for sure.
But they, but use it anyway. They use it anyways because it's a good way to get started. It builds a framework and then they don't, that's not what they ultimately deliver to the end user, right?
I mean, um, Somewhere, somewhere there is a bunch of cyber criminals sitting around a table looking at each other in disbelief going, can you see what these guys are up to? Now this is just like, how much easier do they wanna make this for us? Yeah.
60% of our users, uh, the users have made, have generated code, is not gonna really check it. But, you know, I'm gonna go back to what I said From the beginning. Greatest.
Go ahead. And then I have another factor. We have a problem with the way we have built ai.
And I'm gonna say it now, like I said, I used to complain about agents. I can see the problem coming. Large language models suck.
They need to be more specific, they need to be more domain based, and they should be small language models that we can trust. So Tracy is an LLMS woman. Is that, is that, is that like a new bumper sticker?
M LLM suck. L Suck. They Suck.
But you know what? There's So much wrong stuff against generated new Using it. Well, let me just throw something out at you.
I had a conversation last week with my friend Jen Zwelling, who's the now like the CTOI field, CTO maybe for Veracode. And you know, they do, I mean, they, they get to look at a lot of code from their clients and they do constant reviews of code security that from real life code being generated. And they have been comparing all of the different ais and the code it generates as well as the human code that gets generated.
And with the latest models, which is five, well, now there's five two, but five one on chat and, uh, on Claude sonnet, was it three five? I don't remember. Whatever the latest Claude is.
The, the amount of bugs, the amount of in, in vulnerabilities in code generated by those ais are roughly on par with code generated by humans. So just to give you an idea, it started off human code machine code, let's say two years ago. We're at a point right now where it's about even, but make no mistake, machine generated code is, is on the, you know, what, what, what does Mike Tomlin say?
Not on the upside, whatever it is. It, it, the, the, the arrows point up, the arrows pointed up here where human generated code kind of stays the same. So if we were having this conversation a year from now, uh, AI generated code will probably be better than human generated code.
The question is, who is checking it? Are we, you don't think so? Mike?
Mike says, no, no, no, no, no. He gave me a Sergeant Schultz there. Our contrera, even OpenAI just put out a statement saying that there is likely to be more security issues with their latest open AI models because the thing is bigger and smarter allegedly than ever.
And there's, there's more opportunities to make more mistakes with more code generated. In other word, smart Open ai, the very company that wasn't providing a warning label before is providing a warning label for this. It tells you something.
It's because it's saying we're becoming more of a generalist. Right? Which is my point is they don't have enough domain knowledge, right?
We, and, and the answer is, we've been down this road before for code, and we have AI models that generate a hundred percent perfect code, and they're called compilers, and they've been around for a very, very long time. And we figured it out. And compilers now can generate assembly code that's much faster, much better than humans ever could, right?
And with specialized l LMS and specialized AI compilers, we will generate better and more secure code than humans can because they can operate at speed and scale that humans can't. But that's for what Tracy calls the small LLMs or the domain specific application specific code, general purpose. LLMs trained on a billion or trillion or 10 trillion data points off the internet are not going to be very good.
I'll, I'll take it a step further. I think the AI agents are just gonna write stuff for each other in assembly. I mean, we only have Java and all this other stuff for higher level of abstractions for humans, and machines are gonna be like, we don't need that crap.
So, But to, to Alan's point, I do believe that there, there, there's going to be a point where humans and, uh, AI generated code is gonna be pretty similar in terms of the internal vulnerabilities that they may create. But that doesn't change what's coming through the software supply chain. And we're going to be using more and more open source as we move forward.
And that always, that's always gonna be vulnerable. I, I had a good conversation out in Vegas, uh, two weeks ago with my friend David DeSanto. David used to be the, uh, chief Product Officer GitLab, he's now the CEO at Anaconda.
If you're not familiar with Anaconda, they probably have one of the biggest repos of Python for Python scripts and stuff in the world. Open source, fully open source. And, and we, we talked about that very issue is 'cause that's, that's the, the, the battle front, right?
Tracy, all, you know, 75, 80% of the code in these apps are coming down from open source repositories, whether they're container images or Python snips or JavaScript or Java or, or, or, uh, art artifacts. They're coming from open source reposts. And you know, we, we, we do have the SBO M thing, so you could probably chase it back to what repo and all that good stuff.
But at the end of the day, I think that's the choke point. That's the battlefront where we, we, we make our stand, we die on that hill. We, we, we make sure that if you are downloading code from a, a repo, I don't care which repo it is, you should have a reasonable expectation that that code is free from bugs and vulnerabilities and malware.
I don't know if we can ever get there, Alan. The, the amount of code that's being, that it's being used in the open source supply chain is big. Why?
Well, the amount of code being used all over, it's big. It's four x what it was. That's the numbers we see.
We 30,000 vulnerabilities for this year, 30,000, right? Sounds like A problem for ai. I I think the, I think the problem is, is we put, we always shift left.
That's an offensive, uh, strategy. In order to trust open source, we also have a need, a defensive strategy, which means if you find something in, find a critical or high risk vulnerability running on one of your endpoints, fix it. Fix it as fast as you can, right?
And we don't, we don't think that way. We keep thinking zero vulnerabilities, zero vulnerabilities coming from the left. We don't, we're still at a hundred days plus to remediate of a a critical vulnerability.
Yeah, that, and then Bad guys, the bad guys are getting smarter at exploiting those vulnerabilities About 10 days using, Right? 10 days. 10 days.
So we got a 90 day gap. Alan, I, I'm, I'm just gonna start calling you repo man from now on. Okay, You know what?
So I would put the, I would, I think we should bring a lawsuit against the repos for allowing vulnerable code through their repo, right? Because they're claiming sort of the, what, what is it? The five 20 rule that they're not responsible for what's in their repo that someone else put up there?
Same way Facebook says, I don't, I'm not responsible for what someone else posts, Right? And now there's ways like with like, think about openness of scorecard. You can go and, and, and check how much work that that project is doing to be compliant, right?
So you can make a decision if you wanna use that or not. Again, so what do I saying? Personal accountability, Personal responsibility.
You, hey, you gotta brush your teeth. Got personal responsibility to pull the plug here. Guys, we're way over time.
We had too much fun with this today. I apologize. I hope you've enjoyed the conversation.
Of course, we have a lot more of great text on content following this. We have text on tv, we've got between all the shows we've been doing and all the many, many video interviews that Mike and I have been doing, and our podcasts from Futurum Group and Tech Field Day. And there's just a ton of stuff out here for you to watch.
I also wanna give you all a shout out. January 15th is Predict Day here at Textron. You know, for the last nine years, we've been putting on a show every early January where we ask some pundits experts and, and various other sundry people to come up and give us their predictions on what's big in 2020 in the next year.
So for 2026, I'm really glad and proud to say we have drafted the Futurum analyst team in Toto. I don't mean Dorothy in Toto, in Toto legal word. Um, to come out here and give us their predictions, we're gonna have Daniel Newman.
I'm gonna, I'm gonna be interviewing Daniel on his predictions. I'm gonna be doing it with Nick. Patience, of course.
Mitch Ashley, Fernando Montenegro, Brad Schrier, the whole Futur team is getting behind this on us. I think it's gonna be our best predict yet. Of course, AI was Techstrong's.
I don't know if it's person of the year or entity of the year, but I also saw that Time Magazine made the architects of ai, the eight, they chose the eight architects of AI as their persons of the year. com. You can go on register for this.
It's gonna be a great event virtual, and we'd love to have you there. That being said, I, I never, I I have a prediction. Well, can you save it for January 15th?
No. My prediction is Techstrong Gang will be back tomorrow. Okay.
Mike said it, so let it be written. So let it be done. We're out.
Ms. Allen Shimel, we'll talk to you later. Hey everyone, welcome back here to Tech Shark tv.
I am happy to have our next, uh, guest on his name is Kevin Roy. He's the founder of a company called Green Banana as CEO. Kevin, welcome to Tech Drunk tv.
Thanks for having me. So before we jump into, uh, entity au author, authority Engineering, and GEO and these other kind of new things we're gonna talk about, let's talk a little bit about you, Kevin, you're the founder over here at Green Banana. Give us, give us a sense of kind of your journey.
I, so I'm just like a, I I own it. I'm a internet geek. I've been doing this forever.
Um, this is our 18th year as an agency. I ended up, uh, having a business partner bottom out about four years ago. Uh, and we are, we're basically a full stack digital ad agency.
So we tons of AV Google ads, um, geofencing, geotargeting meta, LinkedIn, uh, but we're, we're really rooted in search engine optimization and now answer engine optimization geo, uh, uh, and because I'm the resident geek for that, like I've been study SEO for my entire career, and that has evolved to get excited. GBT and luck speak a lot, things like that. Excellent.
And so Green Banana's been around 18 years, you said? Yeah. Yeah, we've been around a long time.
Good for you. I mean, look, I'm doing this, you know, I'm, I'm the founder of Techstrong and we started in 2013. Yeah.
So we're, we're 12 years in, but, um, that's great. And, and it, you know, it's a great, uh, it's great to be able to have a business that has legs like that, right? So are most of your customers like kind of local or you help people all over the world or We, we have clients.
Uh, most of them are in the us. We have some in other countries, but 99% of our clients are, are in the United States. And I always jokingly say like we have every type of client, but adult.
Like, we have doctors, lawyers, we have FinTech, we have biotech consultants in United Nations, we have defense cop directors, we have, uh, um, aerospace, um, we have financial technology, we have education. Um, I have that sell beef jerky and really expensive pajamas. And um, uh, like then we have HVAC clients and insulation contractors and chiropractors and doctors and lawyers.
So it's, people hire us because we're, we're a data key. We're good at roas, paternity, you know, getting a, a good return on ad spend. It's very rare someone comes in with a brand plan and has us do that.
A lot of brand planners, designers hire us to get their marketing to work. Absolutely. So, Kevin, look, over the last couple years, we, we've seen a drastic sea change in the SEO business, right?
So here at Text Trump, for instance, we operate, I don't know, nine to a dozen different websites. Very niche, DevOps, security, you know, cyber, uh, cloud native, very geeky, very focused sites, communities, and, you know, we all ride that Google algorithm wave where they change the algorithm on SEO and all of a sudden our traffic goes down, but, and then we figure it out and just by the time you figure it out, they change it again. And it's like that constant cat mouse came.
But, you know, things have changed with, with AI and generative AI and, and so forth. Fact of the matter is, a lot of companies like mine are not getting a lot as much traffic from Google as they used to. 'cause Google's keeping more of that traffic on their site, right?
They, you go to a Google search now and, you know, you get your Gemini kind of, uh, findings, Gemini results, then they have a whole bunch of sponsored results. And unless you're playing that game, you, you, you know, it used to be you fought to get on the first page, Right? Correct.
Really hard to get on that first page. However, you know, God, God gives with one hand takes with the other 35% or more of, of, you know, search traffic today is now coming via AI portals. It seems right from some of the AI models out there, uh, in the LLM.
So, you know, the industry has sort of pivoted in saying, okay, well SEO is not what it was. We could optimize for what's there, but it's just not there as much. But we wanna optimize to take advantage of, you know, chat GPT, which is probably the, the 800 pound gorilla.
Mm-hmm. But there are others, right? There's philanthropic and Prometheus and, and others that, that are, are part of it.
From where you sit, what are you seeing? Is that what you're seeing or? So I, so I, I'm, I think I, I'm gonna agree with, with Chad, GPT being the, you know, 800 pound grill.
I think Gemini and chat are neck and neck and there, there's a, there's a race. There's a lot of really smart people like de and, and once they brought him from, uh, DeepMind and Google has, they've, Gemini has made some significant updates. They just had a big rollout on the 18th, uh, that changed the way their algorithm works.
Uh, we do see across all of our clients a drop in organic traffic, but not a massive drop. So for B2B clients, um, you have to remember that with the answer engines, you're asking a question and getting a small soundbite of information that when you get all of your answers questions answered in that soundbite, you don't need to click onto the, so in a B2B, um, the website or a B2B information, you typically need more. So people are either clicking those and going to the website or just googling the name of the company and, and going to the website to get all of that information that wasn't answered in that little soundbite.
Um, consumer is getting hit a little bit harder with that, but we're still seeing a pretty good amount of traffic coming from organic. But thankfully, a really healthy organic base is what gets you, um, it's basically 80% of the work to get you in answer questions. Absolutely.
So Kevin, what, what is, uh, you, you've developed something, you're calling entity authority engineering. So there's, you're, you're, we're hearing answer engine optimization, generat and engine optimization, um, LOM ranking, and there's a, there's, there's a lot of confusion on, on what to call it. We are calling it, um, the entity engineering, uh, because of, you know, we think that it encompasses both generative engine optimization and answer engine optimization.
Now, those two words are not interchangeable. They're actually two different things. So in order to get right in answer engines, they need to trust you, which is kind of ironic because a lot of people are coming up content that answer engines are actually writing for them.
But what the answer engines are trying to do is to, is to say, who takes ownership of that and how can we back that up? So they're looking at who the author is behind this content. They're looking at what other websites or high authority links are, are pointing back to the site.
That's called entity stacking, which is answer engine optimization. It's the trust portion. The generative engine optimization is how your, how basically how your website is formatted with schema, with questions and answers that are really easy, um, with information that's connecting.
So think of answer engine optimization as the resume in an interview, and your actual interview is generative venture optimization. So those things two together, the way you're looking at it. Yeah.
Yeah. It, so they have to work together. So one without the other, you can have a great website, but with, without the trust of the models, they're not gonna refer to you.
If you have amazing trust and no content, they're not gonna know what to refer to. Right. So you, you kind of need both.
Absolutely. Kevin, look, there was a time, I don't know, five years ago, um, 70, 75%, maybe 80% of the traffic to our tech strong sites were coming from, uh, you know, organic search as we called it, right? And, and 99% of that was Google.
What percentage would you say of search is coming via, uh, the AI models at this point? So, and It's hard 'cause Google uses GEM and AI realize. Yeah.
So the, the, the hard part of that is if people are getting the answer in their AI model and they're not clicking, how are we gonna know if it's an accurate percentage? So it's really, if you look the number of clicks like we get from chat GBT, it is, yeah, like 50, 60 a week, it's not a lot. Um, but it doesn't mean that we're getting mentioned a lot more.
So there are tools to figure out, uh, if, if you're being mentioned or you're being cited, so you can see how many people are actually looking for you, or how many times you're being mentioned in answer engine models before they click to the site. So it's a, it's kind of like a tough, it's answering that question would almost be inaccurate because there's a lot less, uh, people that are coming from the answer engines, but it doesn't mean they're not seeing, they just might be getting everything they need in the, in the response before clicking to the website. Does that make sense?
Yeah, no, perfect sense. You know, it, and it makes it hard. I'm wondering, look, we're, we're a tech company, we cover the tech space.
I get all this, this all makes sense to me. I'm not a lawyer, a doctor, a dentist, or some other sort of, you know, local business or even not even a local business that sells, you know, online, but who's kind of savvy to tech, let's say. How are you finding, explaining all this to them?
So I, I think, well, number one, we're using tools to figure out the baseline if they're being mentioned, the answer engine. So we can, we can talk, uh, intelligently to some of the gaps that they're having or some of their reasons that they are showing up or not showing up. But one of the things that we do is we try to look at, like, there's the, you know, crawl law around what are some of the things that anybody can do to start getting mentioned in answer engines.
And two of 'em right off the bat when I was talking about the, the, the trust component of it, or the answer engine optimization component is when you're putting content on your site, make sure there is an author that is taking ownership of that. And then you, what you do is you create an author age that, uh, mentions all the things that you've either authored or if you've been in a podcast or if you've been mentioned at something, you put that on your author page that links to the, um, the article that you write, right? So the article that you write, I'm sorry, it links to the author page.
And then what I recommend people do is you put your author bio in your LinkedIn page and link it to your author page because LinkedIn is a very high trusted source. So you're amplifying that trust signal, right? So the so that, number one, the easiest thing to do is to take credit for the content that you're writing, that's the entity, um, or the answer authority component of it.
The second thing that you can do is you can actually, um, double, if you're a logo business and you have reviews to your website, what really, really helps you get mentioned in answer engines and in SEO is if there is a keyword that describes your service and or a location of where you do the business at, if you can get that in the review, that's really helpful. But we all know that's next and possible. It's really hard to get a review.
So forget about asking someone to use words that you want in the review. However, you can respond to reviews and Google treats them equally. So you can say, really, as corny as it sounds, thanks Alan, I'm really happy that you thought that we had the best pizza in Boston.
Please come again. Um, that, that significantly helps. So that's the, the answer component, the generative optimization component.
The simplest thing to do is sound bites. So think of when you are reading a newspaper and there's a little call, you know, they make text base smack in the page. It's the call out, click the call out, or the main subject at the very top of the page.
Uh, and so those simple things that you can do will help you start gaining momentum in answer answers. I love it. That's excellent, excellent business.
Um, Kevin, for people who maybe want to get more or maybe look into Green Banana, helping them, where, what's the website? com or, um, this works in Google, it does not work in answer engines. If you go, if you Google, I just met Kevin on page one, number one in Google, but if you say, I just met Kevin and chat, it's gonna say, who cares?
Big deal. Look, We can't, we, you know, right? I try to tell my wife this too.
I, you know, in tech, people know me and, and yeah. And tech stroke, I'm side of tech, not so much. Um, hey Kevin, thanks for coming on here and gi and giving us a quick little lesson in, in, uh, answer engine optimization and generative engine optimization and entity authority engineering.
For people who want more information on this, go check out Green Banana, SEO, or like Kevin says, go on Google, you know, and, and ask for Kevin. Uh, keep up the great work. This is a ri thank this, this whole industry right now.
So fun. I mean, this is the, the most excitement we've had in this in a long time, right? I know, I know.
I think it's the golden age for SEOs. I it really is. It's, Yeah, I know.
And a lot, it's a golden age for a lot of things in tech, man. Yeah. Yeah.
Good stuff. Kevin Roy founded Green Banana, SEO here on Techstrong tv. We'll be back in a moment.
Hello and welcome to the latest edition of the Techstrong AI Leadership Inside series. I'm your host, Mike Vard. Today we're with MUAs Udin, who's the CEO for a Lithian ai.
And we're talking about, well, the impact AI is having on doctors in healthcare. MUAs, welcome to show. Thank you for inviting me.
All right, pleasure Being here. I think everybody kind of understands that maybe doctors are overwhelmed and there's a massive amount of paperwork and they probably don't get to spend as much time with patients as they like, and they're certainly not all out in the golf course. So what impact are we seeing here with AI and how is it changing the way doctors and patients interact with each other?
First of all, AI has really changed the outcome of how doctors are gonna practice now and the future. The biggest burden for doctors is like multifold. First of all, when the patients come in, they have to have the same, uh, we, we call it intake, which means that doctors have to interview or the nurse has to interview the patient.
Same questions every patient they have to ask over and over, which, cause they call it talk fatigue. And doctors don't wanna see a certain amount of certain type of patients per day because of the burnout from, from the beginning of asking the same questions. Then they are usually used to be there where the people will simply type the notes as they're with the patient, they're doing all the stuff.
And as soon as the patient leaves, now they have another burden how to close the notes. So they wait and go home. And it's called period time.
And typically about three hours a day, they spend after hours just doing the notes. But the AI has done is, initially it was a scribe where the doctors can actually talk to people and it will take the ambient listening. And after the doc, the visit is done, the doctor will come in and basically look at the note, edit the note, and then send it to the EMR and still go home and go over the stuff and then close or saves them time.
This documentation is more thorough, and actually they can look into the patient's eyes while they're talking to them and making sure they're taken care of. The third, the third part is what we come in and what we are looking at the future coming in is automation all the way through patients from home, they sit down, they take their time, the AI will interview the patient, for example, is called intake, the HBI, the technical term history of present illness. How long did you have it?
You have chest pain, do you arm pain arm? Do you have nausea, vomiting? All the questions doctors ask all the time.
It asks those questions before people come into the clinic. And once they're in the clinic, doctor already has the pre pretty good idea and it such the agenda, right? So doctor, you go to a doctor now, they don't have to ask all the questions.
So they start, okay, these are things we need to discuss. So it gives doctor more quality time with patient, better patient care, better outcome. And what else is there in the AI is like right now emerging?
We are, the first one to launch is the conversational AI scribe. What it means is, as doctors are talking, it is transcribing a notes slide, not ambient listening. It is generating a notes as the doctors are going through the visit, ordering labs, all the stuff, uh, CPD code, which is like diagnostic coding.
All the stuff is happening as the visits unfold. So it gives really doctors more time to focus on the patient, not worrying about what's gonna happen. Should I remember this thing?
I'm gonna go back and look at the notes again. So they actually interact with the patients more thoroughly. And once they're done, basically there's a magic edit there where people send, doctors simply say, hi, by the way, uh, didn't capture this thing.
I saw his x-ray and x, y, Z was normal. So it will, within seconds, it'll just go into the notes and doctors disclose the note. So there's no period time, there's no burnout.
They call it talk fatigue. And also there's a click fatigue. By the way, do you know how many clicks a doctors do a day?
Just a curious question. No idea. Um, Service, say about 1700 to 4,000 clicks a day.
And what doctors call it click fatigue because they have to go navigate the old technology, click here, click there, and it's like a racking thing. And so one, you have one window, platform it all, so you don't have to do an plex, it just simply shows up. So that all sounds better for everyone involved.
But how do we get to that nirvana? Because I feel like it's unevenly distributed. So we say, and no one seems to know exactly what it's gonna take to maybe get this into the hands of every doctor.
That's a good question. Absolutely, right. Uh, doctors by nature with technology, they, every time there's a technology, they're scared of technology, they think it might be something which has, they have to do more.
So adoption usually comes in from the word of mouth. I'll give you an example. Uh, there was a, there's a clinic in the Midwest and the doctor said, it sounds too good to be true, so I need to talk to another doctor.
So we arranged a doctor who's already using the platform, he calls the doctor and the first thing he that, are you sure it's real? It sounds too good to be true. Finally it happened.
They like it. So adoption is in itself, technology, uh, doctors that I'm not very, they wanna know how much time's gonna disrupt me, but it's a pretty good thing. Eventually every, eventually everybody's gonna be adopting this thing, but they're not, there'll be a lot of opportunity for other folks.
Everybody can streamline the process. So doctors can be doctors. Their job is to prevent, diagnose and treat, not be a technologist, or figuring out all the technology, how it fits it.
That's a future and it's coming. Mm-hmm. So we've all seen AI kind of makes mistakes from time to time and they hallucinate.
And of course, humans make mistakes too. But in the case of ai, will there be, say, another set of AI models that's checking on the work of the original AI to make sure it's right? Or how do we kind of put the guardrails in place that we need?
That's a very good question. Medical field is one of those fields where you have to be on. So any model which is trained on the internet would always hallucinate.
What we have done is put the guardrails and everything, every model is trained by doctors. So they read the process and they fine tuned the model. So they're like strong guardrails, which are needed for the patient safety as well as for the accuracy of the document.
So it takes time, but it does not have the scenario because it is trained by doctors. It's, there's nothing, it's not putting the data from the internet to give answers. So we have to put guard rails in place.
Right. Do you think also over time it might become possible to identify trends? And I asked this question because, you know, we have seen over the years where, um, multiple patients in a specific region wind up having the same issues and it could be caused by something in the environment, but nobody noticed it for years because nobody had any ability to compare the notes.
So, you know, as we move along here, will we be able to kind of maybe identify clusters of issues more readily because we're gonna apply more analytics? Absolutely. There's the, the reason is there, the data is there.
Do you know how many I cd 10 codes are there and CPT codes doctors don't usually use, take a guess how many IV we just call diagnostic codes. Are there, I want to, I'll put that in the thousands, 67,000 i three 10 codes. And the new one, which is the international standard, which is, it's called nomad 350,000 codes.
So 350,000 codes for explicitly each problem from the in population health, you need to capture data with precision. For example, if you have a pain, is it a back pain, left arm pain, which area the pain is, or throat or all the, we call it comorbidities, which means what are the symptoms are the similar symptoms. And as CMS has a pretty good tool where you have to upload the data, the CMS, the problem arises.
Doctors can't remember all the codes CPD codes. So they use generic codes because nobody has time to go through 67,000 codes to find out which one. So AI is actually capturing, or we are capturing all those codes as of with visit unfold.
So you can do the really fine, I can codes, which are diagnostic codes. And when you see a patent, patent recognition, all the clusters, it'll be easy to manage because you have the right data, make the right decisions. Mm-hmm.
Problem before was people were not doing the coding because nobody knows that many codes. So what is a reasonable number of patients for a doctor to have if they have AI tooling? And I'm asking the question because we do have a shortage of, uh, medical professionals, but at the same time, even with ai, there's probably a limit.
But, you know, have you seen any kinda numbers or anything that kind of suggests best practice here? Uh, it depends on the doctors. Some doctors would like to have more time available.
Some doctors, uh, I will give you an example as we talking earlier about the HPI or the intake, what the patients do. 'cause it's, it is very thorough. And what we have seen of the 12,000 initial interviews we have done, it's about nine minutes.
It takes about nine minutes of interview. So that nine minutes is saved for the doctor. Now doctors can use that time for better, better care of the patients, or they can reduce the time and see more patients.
We provide tools to make their life easy. Then it's a doctor's decision. They can easily see the uptake about 30% per day.
They can see more patients depending upon their will at, if they're willing to do it. It's no secret there, there are a lot of lawsuits involving medical practitioners. But will we get to a point soon where maybe the insurance companies are gonna require the physicians to have AI so that A, they can have this documentation, but b, maybe it'll ultimately reduce the number of mistakes that are made?
I think they should look into it. What we are doing is we got a license from a ME to train our model exactly doing that. But it captures every single nuance.
And it actually ref gives a reference from a ME on the CPT code, which is their proprietary, uh, models for billing. It actually points to exactly each note where it was drawn from. So the chances of error or insurance denial would be very low because it's, it is audit defensible.
It captures every CPD code. It captures IICD 10 courts. It gives a rationale why the decision was made and why this thing is picked up.
So all the nuance, which is in, uh, let me give you an example. About 30% of claims before submission. There's a biller who doesn't see the doctors during the notes, right?
So a biller has to go to the doctor, ask them, please can you add this addendum to have the proper billing? And it's back and forth is about 20 minutes spent per patient. And here we have, uh, about 17 seconds.
The doctors is done within 17 seconds. It generates a notes and it gives you a rationale. And if they wanna do something, or by the way, this person has via hyper uh, hypertension, which means there's over that one, it'll automatically fix all the problems and generate a node, which is like audit defensible.
So these technologies are, are now being happening. People are adopting it. And it is amazing.
And I think insurance companies would follow those things. Then they should, it will save money to the insurance company and it will save money overall in the healthcare system. That's the biggest expense they have is the insurance company.
What role will governments play in this conversation? Are they likely to come to a similar conclusion and say to people, Hey, if you're gonna be in the healthcare space, you gotta use ai? I think that time is coming.
There are multiple reasons. First of the cost of healthcare is rising. So much doctors get paid about most time, I don't want to use the numbers, but 25% of what they produce, the rest of stuff goes into support staff, which is shortages, receptionist, billers, all the stuff.
And anything which is repetitive is being taken care of by the ai. So there would be a substantial reduction in per visit cost of overhead. So government, eventually, CMA, uh, CMS, all of them, they would realize that maybe we will, they will restructure the billing structure too.
It'll save money to the system. Mm-hmm. Will it take tension out of this whole interaction?
Because everybody usually involved, unless it's say a checkup, but if it's some sort of condition, everybody is kind of stressed. And a lot of times doctors are meeting people on, probably on maybe what's one of the worst days of their existence. But can we kind of get it so that uh, the nurses and the doctors and everybody involved, um, can spend more time kind of focusing a little bit on the, uh, uh, emotional health of the patients.
Because I think a lot of the times that's as much of the issue as, as it is everything else. And it feels like to me at least the paperwork just gets in the way. Absolutely.
You're right. And there are a lot of, it's a broken system. Everywhere you look at it is broken.
Uh, for some reason, uh, when CMS, they came up with the, uh, that you have to emr. So they came this techno it people, they're really good at designing things which are very complicated. So now what doctors did, instead of practicing medicine, they end up juggling papers and all the stuff.
And still it is like, one thing I'll tell you, a hundred percent of time, a hundred percent doctors have their own workflow because of those juggling of the technology, which is like older than uh, I guess Windows 95. So there is that old. So if you have a centralized system, uh, which is gonna happen because with the fire you can pull data patient data from anywhere.
We, we can have the contextual summary to each person what their needs are. It'll generate the north. So doctors can be more human everywhere without emotions.
There's no healing. Emotional attachment is the important task of believing in something where the doctors care about it and, and making people believe it. And it is data driven.
It would not be something that is data driven. It's honest and it will give doctors the tools they need to make decisions faster and help the whole system move faster towards a better outcomes for the patients and the cost of delivery. I think that's the future and it's gonna be great.
Right? Of course there is no conversation about healthcare that doesn't come back to, in one way or another, cost can we take cost outta the system. And do you have any sense of maybe how much of the cost of healthcare is really tied up in these kinda convoluted processes rather than the actual care of the patient?
I can tell you about, uh, just a medical side of it. There's a lot of waste, which, and the drug systems, PBMs have their own cutbacks and everybody's working on it. I know a company who was transferring the whole kickback back to the patient to produce the cost of drugs because of ai.
They're building powerful tool where patient can actually buy the same drug at the lesser price than the insurance company reimbursement. So there are things which are coming up so people don't have to worry about if its insurance is there, I have to pay only. Sometimes the copay is more than what the price of the drug is.
You won't believe it, but you know, I mean, good R is one example. They're doing it, they're giving you coupon, which is cheaper than the, you don't have to pay the copay to simply buy it straightforward. And there are technologies coming up which will solve that problem, and that will bring down the cost for that.
Another thing where we think is gonna really make a difference with the data, as you were saying, the data clusters, uh, that would probably be where you have so much data available of is this test necessary based on the total population data? Right now, it's like every time there's a protocol, this thing happens. You have to run those like high expensive tests when it goes to insurance, insurance deny.
So when you have a plus of data available, which is justified for reasoning, you would do the testing, which where is appropriate? And the probably insurance company would see the value of doing that testing sooner than later. For the pre-authorizations.
Overall, the system will benefit from the efficiencies of bringing all the data together. For example, you don't have to go to different doctors just for one problem and then another one when each doctor has the comprehensive in look into like all the things which have gone on your life. So it'll make the decision making better and faster.
And whenever things are better and faster, they get cheaper. Technology always get cheaper. It has been there and it's always been there.
If the technology is cheaper, so would be the price of healthcare delivery. That's what I believe. All right, folks.
You heard it here. There's of course a lot of fear and interpretation when it comes to ai, but there's also a lot of instances where AI is clearly gonna be a force for good, and this might be one of them. Hey Muus, thanks for being on the show.
Thank you. Appreciate it. ai Leadership Insight series.
You can find this and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey, good morning everyone. It's Alan Hummel, and welcome to our day two coverage of AWS Reinvent 2025. We're live at the win, uh, right here in Las Vegas, covering, reinvent.
And, uh, I hope you had a chance to look at some of our coverage from yesterday with some really great discussions. We had a lot of analysts, a lot of different AWS partners. We hope to have some AWS people, I think we have scheduled later this afternoon as well.
But let's kick off our day with what, for me, personally, is a highlight. If you've ever watched our event coverage in the past, this man may be, uh, familiar to you. My friend David DeSanto.
David, well, if you know David, you know this, but David ran product at GitLab for five years, Uh, three and a half years in CPO and yeah, two and a half before that. Yep. So earlier there, about five and a half, six years.
Um, always a really smart guy, always a great interview. He loved talking with him, but he's not here. This is not David Desto of GitLab anymore.
This is David DeSanto, I'm proud to say the CEO of Anaconda. David, first of all, congratulations, man. Yeah.
I'm really happy for you. Oh, thank you. Yeah, I, uh, truly excited to help Anaconda go into their next chapter.
Absolutely. You know, I, I, I didn't hope didn't embarrass or anything like that, but I wanted to talk about the GitLab experience because for our audience, which is DevOps and cloud native mm-hmm. And cyber and so forth, that, you know, GitLab is a, is an important company in the ecosystem.
Um, and you were an important person in taking that vision and running with it. Tell us how you wound up at Anaconda. Yeah.
So first, yeah, it was a great run at GitLab. We saw the company grow almost exponentially. It was less than 300 people when I started, and my last day was over 2,600.
Right? And so, uh, the journey to Anaconda does start with GitLab. Going to GitLab.
I re-embraced the open source community in a way that I hadn't since ICSA labs many years before that. And that time was great, you know, uh, our first conversation was me coming out and saying like, we are going to add security and compliance to GitLab. I remember that.
Yeah. And then, uh, the last quarter I was at, that's part of the revenues over 53% of it. So it was a really great run, great company cheering them on.
Absolutely. Uh, but yeah, I was ready for my next challenge. And so when thinking about what I would do next, I explored, do I wanna stay in the DevOps space?
Do I wanna go back to security? And I realized I could do security and AI all in one place. And that was Anaconda.
Aha. There's a, there's the word, two minutes in, and we've mentioned ai. Yep.
Um, Well, I think I said this once before, but you can't spell David without ai, so That's true. So yeah, This is true. You haven't mentioned that One.
My, my wife did say, I have to stop telling that joke, but Well, look, we've got a new audience here. You got a new title. They may not remember it.
So, David, some people in our audience I'm sure are familiar with Anaconda, but there are plenty of people who aren't. Let's, let's start real foundational and build our way up. Give us the Anaconda story.
Yeah. So Anaconda came out of a consultancy. The two founders of Anaconda had a company called Continuum Analytics, and they were doing consulting work for data science within the financial services space.
And what they found out was that they were building new Python packages to support the work they were doing. And they decided that, hey, this should be a product company. And so they started Anaconda, the first product's name was Kanda.
And that's what a lot of people think of that provides thousands of trusted, secure data science and AI packages for Python. Uh, but the company has continued to grow beyond that. And one of the reasons why I joined is the story that they're currently on.
Anaconda can help you with secure python development, but we do so much more than that. Uh, earlier in the year, we launched our AI platform that helps you apply security and governance policies to how AI applications are being built, really. And, and the, yeah, the most recent, which I'm the most excited about, I cannot take credit for it 'cause it, you know, came out I think three weeks after I started.
But, uh, our AI catalyst component of that platform, what it does is provides a curated list of open source models that we have validated or secure. We include the lineage of where they came from, how they were trained. We Oh, I love that.
Yeah. We rate them on performance, and that could be in different quant sizes. And we also then give them the guardrails to make sure that it operates as best as it can.
And so what really excites me about it is we already helping people run inference, and it kind of starts a desktop app before we became a platform and now a, a SaaS offering. Mm-hmm. But the cost to run AI models as part of development is very expensive.
Like I learned that when I was at GitLab. Right. Um, and so what we've done is also make it possible to run a micro in inference on the developer's laptop.
Wow. Which then is that same model that needs to be scale. So, So you don't pay the token penalties.
Exactly. And then when you're ready, we can see what you did with the model locally and tune as it gets deployed into production. So, wow.
Yeah. The best way to describe it is, you know, what a GitLab is for DevOps Anaconda is for AI native development. You know, it's funny you mentioned that term.
I was, I was out in Brooklyn actually a couple weeks ago for this AI native devcon. There's this whole burgeoning community, you're probably aware of AI native development. Yep.
Uh, uh, guy Ani from sny, who's now, I forget, the Tesla is his new company. They're very active in that community. Um, and I, I went out there, I was blown away.
It re it reminded me of going to a DevOps days 10 years ago. Yeah. Right.
That, that same tinkering, geeky, we can make, I love playing with it kind of stuff. And it was, it was a, it's a great community. Um, let me just kind of shimmy eyes this for, if you don't mind.
There you go. So we, we've got Anaconda started as a company providing services on Python scripts And helping companies with their data science development. Yep.
Hence the Python Anaconda connection. Exactly. Okay.
It then shifts to more of a product model, but it's an open source product model, which is still open source today. Yes. Oh, correct.
Yeah. We have a very healthy, free offering. Mm-hmm.
Uh, it allows people to get in the door using Anaconda and mm-hmm. One of the things that really blew me away as part of the process to join was that 95% of the Fortune 500 use Anaconda today. Really?
Yeah. And we have over 2 million, uh, community contributors. That's great.
And 50 million users. 2 million contributors. Yep.
Code, yeah. Code contributors to the open. Wow.
Yeah. It's actually a really great story. Uh, one of the founders is, uh, Peter Wang Uhhuh known very well in the open source community Sure.
And within the data science community. And he's still an active part of the company. Mm-hmm.
Um, you know, he and I talk about what we want to do next together. Yeah. And that reach that we continue to have is because he's always out meeting with customers, potential customers.
Two weeks he's in Boston for a, uh, meeting around how do you set some AI standards Yeah. As part of development. And so we continue to lean into that because, you know, that is really the core of the company to your point.
Yeah. You know, we started as a package manager condo, but now we have the AI platform and we wanna allow people to still come up, get used to using it, get the value out of it, and then want to come and then join and, and pay for either our starter tier or enterprise tier. I love it.
I'm gonna jump into what the store, the, the different tiers are in a bit. I wanna come back to what you were mentioning this newest offering that you're so jazzed about. Yeah.
The AI catalyst. Yes. The AI catalyst.
Now look, you mentioned package managers. It's been a rough couple weeks for package managers, hasn't it? It has, with this shy ude and, and all of that.
It sounds like this AI catalyst may be just what the doctor ordered, right. If, if I'm a user mm-hmm. Of of package package manage, uh, package packages, I wanna make sure that my package manager's giving me something that I'm not.
Correct. Introducing malware into my, my ecosystem. This only works though with the AI models that you're using, right?
The AI packages, if You will. Uh, yeah. That and all of the con packages.
What Okay. All the condu. Yeah.
So because we still use the con package manager, um, we have a very unique build system for building all the packages we provide. And so we're able to actually take things apart, fix the vulnerability, and say in the binary part of the package, put it back together, and then make it available. And so a lot of people think of anacon to first as a trusted distribution because we're providing, you know, thousands of Python packages that we know are secure and are able to scale.
Now. I get it. Yeah.
I got it now. It took a little while. Sometimes I'm slow on the uptake.
Oh, no. And, But if you think about it, there's then that natural transition into the platform, right? It's one thing to start your development, but it's nothing thing to get that prototype into production.
Absolutely. And, and look, I, you know, just quite frankly, it is, you know, we live in a world of, let's call it Frankenstein software, where software is more assembled than code written, if you will, at some level. Right.
And, you know, and you, you, your security background, you know this, we talk about software, supply chain security all the time and, and how stuff, you know, SBOs mm-hmm. And what have you. I think the biggest weakness in our system today is the software and packages that we're downloading from all these repos and, and, and depots and what have you.
So, you know, the fact that you're do, you're on guard here or with the condo packages mm-hmm. Is, is a huge thing. Give us an idea of scale if, you know, you may not know this off the top of your head, but like how many downloads a day, a week, a month?
Yeah. I don't, don't know that off the top of my head. But Kanda is hit all the time, almost 24 7 with people pulling packages.
So very healthy community. That's how we can have 50 million users really, uh, yeah. Using Anaconda every month.
The thing that is the most incredible to me is what you just touched on. And this is part of that why I joined in the journey. Uh, you can only do so much with the actual packages themselves.
Yeah. But when we're talking about the platform, there's like the starter, which is kind of like, hey, a team's getting together. Uh, but the business tier actually provides what you're talking about.
It provides an AI bill of materials, can track vulnerabilities for you. Uh, we're working on how to help auto remediate those as well. And so the customers that end up on a thing, like the business tier of the platform, they're getting, uh, full visibility into their AI life cycle.
And that's really powerful. 'cause as you said today, it's very common that vulnerabilities will sneak in some way. And we're heavily reliant on packages that we've not created.
We're reliant on our IDs to be secure. We're, you know, worried about the things that happen after the code is merged. And anacon just in a really great spot to help with all of that.
You really are. You're right, you're right at the, the nexus, if you will, of, of where all these come together. I love it.
Now you mentioned different tiers. Mm-hmm. So obviously there's probably a free open source tier where hey, it's open, it's open source, have at it.
Then you have, you mentioned the SaaS model. Yeah. So the product, uh, you can self-host.
Mm-hmm. com. Mm-hmm.
Um, but yeah, the big difference is not necessarily whether you're hosting it yourself or using our, our SaaS offering. It's really about the free version gets you up and going, if you're an individual developer, provides you a lot of power. If you now wanna operate as a team and start having some structure around it, you go into the starter tier, which starts to introduce a lot of that.
Um, but when you're ready to talk about AI bill and materials security and governance and having policies that prevent malicious packages from being installed, then you end up on the business tier. And that's where that security and compliance functionality is, including dashboards, policies you can create and so forth. I love it.
Um, to, so I'm an old school open source guy. What pers 50 million users is a crazy number. Yeah.
You may not know this. He may not be comfortable even saying it. What percentage of those are just pure free open?
I mean, usually it's 98, 90 7%. Yeah. Yeah.
So there, uh, a large percentage of it is that open source community. Sure. Um, but that's something that's very important to us.
Sure. It is. You know, what I learned, uh, working with Open Source, I'm so excited to be, you know, leading a company that has open source first mentality is that like you get more value out of that free tier than you could if you tried to bundle that up and put into a paid tier.
And it's ultimately because you get all those contributions, uh, you actually are able to get onto the community, be it events like reinvent Yep. And have conversations with the actual builders and doers. And that's not something that commonly happens if you only start with a paid option or you're not open core.
I love it. Let's, um, let's talk a little bit about Reinvent. You mentioned it Yeah.
Over here. Um, is there like a formal partnership? You know, what, what are you doing at Reinvent?
Yeah, so we're in Booth, uh, 1327. Mm-hmm. So if you're at the show and you wanna check this out, You're watching this live now, you wanna run down there, go run down Run before we run out of giveaways and swag.
Right? Exactly. Uh, some really great swag.
But, uh, in our booth, we're actually demoing the AI Catalyst offering, and we're showing people all the other things Icon can do that are not just, you know, being a package manager, uh, but to speak to the partnership, AI catalyst this new com Yes. Part of our platform that launch exclusively on AWS and we joined, announced it yesterday. Oh, great.
Uh, and it also included that it's now available in AWS marketplace. You can go and buy it yourself. You don't have to go through all the hassles of, like, the steps to get to that point.
I love it. And so, yeah, that's a good example of the partnership. Mm-hmm.
And spill right on top of AWS but there's so much more we're looking to do with 'em. Uh, you know, we're looking for better integrations into Bedrock customers, like using Anaconda with SageMaker. So getting a nice in bed story there.
We were just talking about SageMaker this morning on Dextron Gang. And so yeah, the partnership is great, but we're just gonna keep on building on top of it because they're a really good partner. You know, I've worked with them across multiple companies, and yes, they're always exactly as great as they seem.
And that's really great to have a partner like that. Absolutely. You, you know what's interesting is I I, I, we were talking off camera and I, I mentioned, you know, this year's reinvents a little different.
It's very AI focused and everything else, but I'll tell you what it is focused on, it's laser focused on developers. Mm-hmm. Right.
They really are kinda reestablished because when you, you know, you've been around, you know, I know it was the developers who made AWS Yeah. It was those guys whipping out their credit cards and, you know, building and spinning up instances and, and doing stuff that, that made AWS what it is. And it, there is a renewed focus on the development process.
Of course, AI is changing how developers develop. And it sounds like you're, you're responding to that as well at Anaconda, but make no mistake, that's the focus here. Right?
Yeah, no, what I would say is, I, I took away a couple things, uh, just from Matt's opening keynote. Yes. Uh, the first is, it's all about the hardware.
And I think that's something that people don't always think about. You know, we were talking, Well, that was supposed to be the thing about cloud. You didn't have to worry about the hardware.
Yeah, That's a good point. Uh, but I was gonna say the, uh, you know, when you're talking about ai, it kind of starts at that, right? Yes.
You gotta have the right, It's made hardware sexy. Yeah. And so to see that lead off with mm-hmm.
What they're doing to make it a lot approachable for non-developers to get into an environment and know it can work was really good. Uh, definitely the AI lean in mm-hmm. Uh, was very, uh, prominent as well.
But the one thing I would say, uh, and it, I can't believe I'm saying this, like it's my first reinvent, you know, but what it feels like is like, if you were to take, uh, a cube con, make it significantly larger, Four times the size, And it's only about the developers. Like that's the, the vibe here. And it's actually great.
Yeah. So this is, I don't know how many, certainly since COVID is the fourth, probably since COVID alone, um, this is pretty much it. It's, it's, it's a, I mean, you know, it's nice.
CubeCon is the, like a perfect size. Mm-hmm. 12,000, 14,000.
It's big, but not too big. It's a whole, it's kinda like building a company, right? Mm-hmm.
You could build a company that has 10 million, 15 million in revenue, and you have one kind of management team. You go want to build a company that has 75, a hundred million in revenue. It's a different management team.
Mm-hmm. You wanna go build a company that's IPOing, it's a totally different animal. It, it's the same thing with conferences.
You get a conference of 60,000 plus people mm-hmm. You, you, you know, hyperscale, it's, it's, it's about scale. And they do a great job with it, considering everything that's going on here.
Yeah. No, and I would say too, for those who are watching this and are here, but haven't really like, gone over to everything that's going on, it does not feel like there's that many people here. Like, they've done a really good job.
Yeah. Keeping well, it's spread, spread out and so forth. Yeah.
I, I agree with that. You know what, David, we didn't even mention the website, how to engage. Of course.
I mean, obviously it's open source, you can get it, but what, what is the best website? Yeah. com in there.
It'll point to the dis uh, installers. If you wanna install locally, it can walk you through creating account for SaaS and getting up and running really quickly. Uh, the other thing is that if you just go to like the doc site as well, to your point, you'll learn about more of the open source focus and how you can contribute code.
com. But ultimately, like what I would say is if you're looking to build ai, and you might not be a developer, or in some cases, you know, I won't say I'm very young, but like I programmed in, you know, c out of college, right? But I don't know how to get into Python.
With Python now being the number one language worldwide. And ACON can help you with all that helps you build applications even if you're not technical. Well, AI can help you with it now too, right?
Yeah. I would imagine Ana Condo's going to use AI to help. If you don't know how to develop in Python.
You don't know Python. Yeah. To teach it to you and help you develop it.
I mean, it's a crazy world we're coming into. Oh, no, for sure. And what I would tell people is like, it's so easy to get started.
I, as part of the interview process, wanted to play with the product. And you can get a cloud notebook up and running with one or two clicks, really? Uh, yeah.
The a Anaconda AI system is just there, uh, it's front and square. And I was asking it questions of things that I used to do 10 years ago with Anaconda, like, how do I do this today? And it was very easy.
I felt very, uh, productive and able to actually build something without having, you know, a lot of this, the knowledge that was just built into the platform. So, yeah. So Lemme ask you a hard question, David DeSanto, do you still consider yourself a developer?
Yes, I do. Okay. I do.
And here's why. There, you know, um, was a Joel for a long time as an engineering leader. Uh, people say I went to the dark side to go into product and Uhhuh, I don't think David graduating from college would know that David would be a CEO of the company, right.
Company. But those roots are still really important. And so, whether that is me building stuff to play with, uh, me working with our engineering team and finding things that maybe we can make better, you know, it's great to roll up your sleeves and just be in that, especially with a very technical company.
And I won't tell you the apps I built are pretty bad, but, you know, but They don't have to be great. The fact, you know what I am, I said it tongue in cheek. Yeah.
But the fact of the matter is, is it, I always tell my team, you gotta be able to walk the walk, not just talk the talk. And so the fact that you could play with it and make some, it doesn't, doesn't have to be the greatest app in the world, but you could get your fingernails dirty with it gives you a perspective that helps you understand who your customer is, who the users are. Yeah.
It's Important. No, and you're right. You Can't be too abstracted outta that.
No. And what I tell people is like, even though I'm now CEO of a company that's almost 500 people, when we announced our Series C, we're at 150 million in revenue. You know, it's still important to me to be thought of as a developer and like a vulnerability researcher.
Mm-hmm. Because all of that is what has helped me be successful in my career. And so what I'd say to people out there who are like, I dunno what I want to do or do I wanna switch roles, go to a different company, you know, find the thing that you wanna do and just do it as best as you can.
And it's just so rewarding. And, you know, anacon iss there to help people take that journey for themselves. I Love it.
David. Mad congratulations. Thank best of luck at Anaconda.
We, you know, I'm sure now that you're there, we'll be talking a lot, doing more, looking forward to hearing great things. But this sounds like a great opportunity for Anaconda and a great opportunity for you. It's a good match.
You know, thank you very much for having me, and I always love the catch up. A pleasure. All right.
com. Go check it out. We're live at AWS reinvent.
We're gonna be back in just a minute. We've got tons of great stuff coming up. Stay tuned.
Hey everyone, welcome back here to Techstrong TV and our continuing coverage of AWS re invent. You know, one of the great things about Tech Strum being part of futur, is we get to kind of pick the brains of some of the futurum analysts, you know, the industry, well-known analysts, uh, about what's going on in the world of tech. And especially when we're at an event like this.
We're gonna do two segments here, each with two of the Futurum analysts. The first segment is gonna feature Brad Shiman and Fernando Montenegro, uh, of fu I'm gonna give, I'm gonna let each of them kind of introduce themselves though. Brad, if you wouldn't mind, why don't you kick it off.
Introduce yourself. Yeah, thanks, Alan. Hi, everybody.
Brad Shiman. I am an analyst with futurum, as you noted. Uh, I, I look at data intelligence, analytics, and infrastructure.
And I, I'm a software guy. I love software developments and all things databases. So I'm hoping we can, we can chat about that a little bit today.
Absolutely. And I'm Fernando Montenegro. I lead our cybersecurity and resilience practice.
And, uh, the gray hair comes from being around cybersecurity for many, many, many years. There was a Time I had gray hair in cybersecurity too, when I had hair Fernando's just outta High school. Yes.
Oh yeah, exactly. Yeah, exactly. And, and, and yeah, I've been covering cloud security for a long time and, and, and it's been a pleasure to come to AWS reinvent for, for a few years.
Not the, the full 14 that they've had it, but, uh, It's a good show. It's a, it's an amazing show. Yep.
Well, you know, an observation. I'm glad you brought it up. Well, let's just jump in, of course.
Sure. An observation I had today, and I wrote about it in an article I put up on one of the tech strong sites. Think about coming to AWS reinvent five years ago.
Mm. What would you be talking about S3 Lambda serverless? You'd still be talking about security of bit, but you would be talking about cloud.
Yeah. Cloud nitty gritty, cloud native, managing my Kubernetes EKS. Right.
Securing that stack. How much of that do you spend about here today? So if I transported you from five years ago to today Yeah.
Would you believe it's still the same company? The same industry? The same.
I absolutely, I, I feel, I feel like we're still in that era because honestly, all of those concerns are still here. They all inform what AWS is doing. They are all, they are still all in in the cloud.
And you can hear that in Matt Garmin's, uh, keynote today. 'cause he, he did not mention when he said, if you wanna get the most out of ai, you're going to need to bring data to the ai. And to do that properly, you need to bring it to the cloud.
You know, That's loud and clear everything. Yeah. Yeah.
No, I mean, it's kind of funny in that we haven't, I just feel like there's less of an emphasis on cloud, or it's abstracted behind the ai. That's it. So, so, so here's the thing for point of order, five years ago you were in the middle of the COVID pandemic.
Yes. You were. Right.
We We would not be doing maybe Four. Yeah. But, but, but point taken.
Uh, I think that, um, to, to, to Brad's point, the cloud is foundational to do this. Yes. And it's funny that you brought up abstraction.
I have a, I have a thing that I talk about that, uh, go back to high school calculus, like high high school math. Mm-hmm. The limit, like the limit for cybersecurity as time goes to infinity, to me, is anti fraught.
Mm-hmm. And what I mean by this is that we abstract away technology. We abstract away a lot of this, and then we help businesses and buyers and sellers and whatnot talk about higher level, uh, constructs.
Right. And what, and it's kind of what we're doing here. It just so happens that I'll be, am I the first one to bring up the AI words?
I think I am right? So, uh, uh, I dance Around won't be the last. I Didn't I, but, but, but that's the point.
I think that we are abstracting away some of it. But to Brad's point, it is always there. And actually, one of the security announcements had to do with, uh, uh, with ECS, not the agent ones.
Oh. Had to do with ECS and EC2. Right.
Which was the, the, the, the, the, the guard duty, uh, support. Right. So it, I agree with you that that's not what we're talking about as much, but it's here, it's Always, It's always there.
It's, it's always there. And, uh, whether it's, whether you're figuring out instances that you need, whether you're figuring out what kind of database do you need, there were announcements around S3. There were announcements around S3 tables, I think.
Right. Uh, and so yes, you are correct that, that the topic has shifted, but the technology is underlying. I always Here, you know, the thing that powers our, our little market is that Race to Zero, trying to beat Zeno's paradox to, to always go a little bit further closer to getting there.
And we never get there. And that's why it works, because we're always inventing new ways to abstract away problems. Yeah.
And to find new, interesting ways of applying this technology to solving problems. And I feel like that was really, um, on display today when we talked about Amazon Nova Forge. Yes.
Which I would love to spend some time talking about. We, We've spoken about it a bunch too. I'd love to hear your thoughts on it.
Yeah. I, I Have some thoughts. It's, it's a renaissance era for, for the, you know, more traditional foundational large language model.
It's like a, a return to form I'm calling it. Because instead of, like, we, we've spent so much time over the last year in investing in frontier scale models, uh, like Gemini, like Claude, et cetera. And, you know, they do a wonderful job.
And when they first came out, if, if everyone will recall, we used them for POCs. And that was about it, because they were very flexible. They could do a lot of different things.
They had a great knowledge, basic you worked from, um, but you, for production, you went with an actual model that you fine tuned that you built. Yes. And we kind of went away from that, and we said, let's just make them do it all.
And, and I think what we learned is that that costs a lot of money. And so, you know, if you're gonna do ai, right, like, like Matt said, you want to bring the data to the ai. And that's what they're doing with Nova Forge, is they're really trying to make it so that we actually do what we started doing a few years back in fine tuning these models to bring the data to the ai.
So I, I think it's a, it's a return to forum and I, I applaud them for focusing on it. No, I, I, so it's not anything I've seen before, which is interesting. Yeah.
And, but I'll tell you something. Two, two and a half years ago, we're gonna have Mitch Ashley on, in the next group. Mitch came to a hackathon.
We did down at Techstrong around what we called operationalizing ai. Yeah. Yeah.
And we had people like Patrick dubois, who's founded the DevOps, who came up with the word DevOps. DevOps, uh, uh, John Willis. Oh, he's great.
We had a lot of great people who were very, you know, early on in the DevOps movement, and they were working back then Yeah. On, on Rag and on vector databases and SLMs and stuff like that. And to me, it be, I'm not an analyst, but I did stay at a Holiday Inn Express last night.
To me, it was obvious that not every job in AI required a, a truly frontier size LLM No. As a matter of fact, it might be the wrong tool In a lot of cases For a lot of jobs, it is the wrong tool. I need Yeah.
I need a scalpel or, or a rifle, not a shotgun. And I, I, I, I'll, I'll go one deeper. And that's one of the things that I was looking forward to coming here and having conversations and, and we are having those, is that I would argue that, that the lms Right, the language models in many cases, fine tuned or not right, may not be what people need.
And this is one of the areas that Yeah. Uh, this is one of the areas where, like, I I, I, I was really excited, I'm really excited about the field of neuros symbolic ai mm-hmm. Which is the, you're, you're bringing the, the, the neural component that, that from the LLMs with the symbolic reasoning.
Right. And, and AWS has been doing a lot of work on that. So it was really interesting to come here and see that.
But anyway, but the, the, the point being that the way that we are going to, to improve those models is by the fine tuning, and in some cases, by using these more neuros, symbolic components. And so one of the things that I was excited about, the announcements that, that, that they now have a, uh, a verifiable policy language on the agent core stuff. Yeah.
Right. That's a step in the right direction. I really like that It's responsible AI and ML lops as you're, you're talking about.
Yes, Yes, yes. It's Part and parcel to that. And so I, I feel like they have to, they have to do that.
And if you look at all the components of Agent Core, you can see it starting to look like an ML ops platform more and more. That's for agents, not just for select models here and there, but for orchestrated, Let me, let me ask you a question on this. Have you guys seen the letter that was circulated last week?
Like a thousand AWS employees signed on to calling for responsible really moral Yeah. Ai. Wait, this was Amazon?
Or was it meta? No, I believe it was AWS Okay. Interesting.
Interesting. Yeah. Well, you know, it's, it's, uh, it's very much, and we saw it actually the beginning of the keynote this morning.
The very first words on the screen were why, and the, the response was, why not? And that's the era I feel like we're in right now, is, well, let's just dam the torpedoes and see what happens. And I, I don't think we can do that.
No, it's, it's, we should not be doing that. And yet, I agree, we have been, because it's all about time to value. And we've found with transformer models in particular, that we could shortcut that time to value.
But we can't shortcut the hard work. And that's why things like fine tuning are so important because it's another tool in the toolbox. It gives you, at the end of the day, a model that actually, as you said, has a scalpel to do what you wanna do, do it performance, do it in a secure, safe manner, and do it in a way that you can actually make some money.
Absolutely. Lemme bring up another thing. You know, coming in yesterday at the airport, I was reading all the, the electronic billboards.
Yeah. I'm a sucker for them, but I saw one from Databricks that really caught my eye. I don't know if you saw this one.
Our AI agents don't suck. Remind me of the old, you know, we suck less that philosophy Suck. Software is alive and well today.
Exactly. Yes. Yeah.
Well, now it's called Suck Less Agentic ai, maybe. Oh, Come on. That's never gonna happen.
Okay. It's like agentic ai, it's like antithesis of suckus software. It's like whatever you want it to do, it'll just, It'll do it for you.
Yeah. Just do it for you until it doesn't. Yeah.
Until it doesn't, until you check clears. Anyway. Um, but you know, we, we certainly are in this, Brad, you're right.
You want, we could, we you want an agent? I got an agent in New York. It's like that.
But you, I got an agent for you, but we're also seeings kind of a, a Cambrian explosion, if you will. Sure. Right.
Like, I, I had a, a fellow we interviewed up here this week, or today rather, who comes from, um, uh, s uh, agent AI for s se not for SEO. For SRE. Okay.
Yeah. Sounds great. What a great idea.
We need that, that's something we could do. Of course, he's one of six agent AI for SREs that are here. Uh, may I say seven?
Because, because you know of what? Two? No, no, Because one of the announcements Today was AWS themselves, AWS themselves.
And now check Your watch, because we might have another, another One, but, but, you know, but that's not unusual for, that's their model. Look, we're gonna give you 80% for 20%. Yes.
That's, that's, that's a lot of the AWS model. But I, I do think we are in a, you know, a Cambrian explosion of life, if you will, of ai that some will, some will make sense three to five years from now. Yeah.
It's almost say, what were we thinking about 12 eyes and six legs? It just, you know. Well, a lot of it's gonna disappear because as we saw early on, when we had a lot of wrappers, as you'd call them.
Yep. Round chat. GPT, are they in business anymore?
No, because you don't need them. I'll tell you what else I think might disappear. Everybody and their mother has an MPC server.
I have one right now. Yeah. Yeah.
I mean, do we, why can't we have an open source one that we all kinda standardize on? Kind. And this is the open source model, right.
And then build on top of that, build functionality. Like, but that's meh on top of, but that's What MCP is, right? MCP is by itself, like an open, It will evolve into what you're talking about, Alan.
Yeah. I I think we don't need 10 different MCP servers. No, there's an X-K-D-E-C.
Sorry. XCD. Yes.
Hilarious. I know exactly. We need a standard next panel.
We have another standard 15. Yeah, Yeah, yeah. We have 13 standards.
We can't do it. We need another one. We need the single one.
Now there's 14. That, that is the way it goes, isn't it? Yeah.
I, Fernando, I gotta talk security with you a little bit. Of course. So I had another fellow I interview today, smart guy, zest security.
Okay. I don't know if you heard of these guys. The founder there came out of, uh, oh, they sold to Palo Alto Cider, remember cider Security?
Yes, yes, yes, yes. He claims zero. They could get you down to zero vulnerabilities using ai, agentic ai.
That's bold. I, IIII, I told them, I, I said, say that again for the people in the back. Don't hear me.
Yeah. I think that there are, um, there's multiple ways to interpret zero vulnerabilities. Right?
Okay. In the context, like when we have conversations about vulnerability and security, the first question I want to ask is, okay, am I talking to an ops team or am I talking to a dev team? Very different measures.
If I'm talking to a dev team, zero vulnerabilities means one thing. If I'm talking to an ops team, zero vulnerabilities means something else. So in the context, I think they may more in the Development.
No, he, so I agree with you. I mean, you and I both know. Yeah.
I have a security background. He was talking about the security team in ops, like tra not AppSec vulnerabilities. Like True vulnerabilities in Duction.
And, and, and, and, and that, and that. If, uh, um, like again, I, I applaud the, the, the, the, the, the gusto. But I, I struggle with it because this is the trick that, that security teams are learning the hard way.
There are vulnerabilities that you don't fix because it's too expensive. Yep. Right.
Because given the risk, Well, it's a manage, it's a risk management. It's A, it's a risk management conversation. And then, like, like here, for example, here we are having a wonderful conversation.
Uh, some of these doors are open. That open door is a vulnerability, right? Say Windows 10 at the moment.
Should we talk about that? Well, We talk Windows, we might as well talk Windows 98, but that's a whole nother story. But, but, but, but I, but you know what your reaction, he said, that's exactly what we hear from CIOs and CISOs.
And then we show them. I'm gonna introduce you. I'm happy to chat.
Yeah. And I'd love to hear you talk. I'm happy to.
Yeah. Guys, I gotta wrap this little portion up 'cause we've got more analysts waiting. Sure.
Hate to keep analysts waiting. But let me, let me pose question to each of you, and, and we will go with that. Brad, if I had to ask you for one story, that's the big story at Reinvent this year.
And we've, we've skirted on all of them. Yeah. But for you, what, what's the, what's the, you know, the key takeaway?
Well, for me, uh, I would say that it is, you know, the, um, Nova. Um, but I'm not, I I, I want to actually instead pre pre, you know, get ahead of what I know Mitch is gonna talk about, uh, when it comes on. And, and that is Kiro and that is Agentic development.
And the fact that on stage today we heard from Matt that the company has committed itself to using this platform to develop their software in-house. That is very much, you know, a bold statement because I, I, I feel like a lot of these companies try to sell us on yet another agentic, IDE, blah, blah, blah, blah. But do they really put their money where their mouth is?
Well, a s is trying to do that, so, we'll, I wish them luck. And I, I think it's, it's gonna be interesting to watch. One last thing for you.
What wasn't on your Bingo card coming out here? Uh, well, you know, I wanted to hear more about data, honestly. Uh, and I, we, we didn't have a lot of of announcements about that.
So my bingo card was all filled with, with like slots about what's happening with their various databases. I didn't get too much. No, I haven't, I actually haven't heard much at all.
No. I would've loved to have heard something about a semantic layer, for example, because every other vendor, we mentioned a couple of 'em with Databricks. And, uh, right now, if you're gonna do a lot with ai, you're investing in a semantic layer.
Yeah. But we're not really hearing that from AWS So I, I would encourage them to, to really kind of rethink that in their go to market coming up in the next couple of months. Fair.
I wonder, well, I don't want to be Doctor Evil, but I wonder if that means AWS is working on their own semantic data layer. They have been known to build internally. Yeah.
Yep. Fernando, let me come to you. What's your big story?
My big story comes in two pieces. Uh, you know how we always talk about security for AI and ai mm-hmm. For security, yeah.
Third one being security from ai. Uh, I think that we saw the announcements today, the security for Agentic and the agentic force for security. And the big story for me is that on the security for Agentic, it's how they've woven the conversation of Bedrock has security, bedrock has it built in Bedrock, have it.
And, and then, and then you take the policy agents from, uh, the, the, the policy language. Now an Asian core. So I think that I, I encourage my security colleagues to, as you are thinking about Gentech, you are, you have to look into what security is coming from the platform.
Yeah. And the other big story is agentic for security. So just like the DevOps agent there, there is now an announcement for a preview for a security agent that is going to be doing a lot of the, Hey, let me fix that code for you now the devil in the details.
Right? Uh, but what kind of things is it going to fix? And what kind of things is it not going to fix?
But importantly, what's the, the, what's the play the interplay between a true security, uh, uh, professional doing a pen because it's going to automate pen testing. The theoretically, theoretically, sorry, forgetting English. Uh, where do you draw the line?
So if you're, if you're a developer and I'm a security, uh, engineer, what have you, and then do I now code my policy at my company to say, look, as a developer, you are, um, uh, you're going to do multiple things for security, and you are going to already run a pen test, and then I'm just going to test the results of the, of that pen test. Right. Or am I going to it?
It's great that you run a pen test, but you know, like trust paper, Verify trust. Good. Perfect.
I'm gonna do it. I'm going to do it too. So I think that that's the next level of conversation.
So I think there'll be a human in the loop conversation there. Absolutely. Lemme play devil's advocate a little bit though.
Sure. The DevOps agent to me is an alert monitoring tool. That's what it sounded like from what I heard.
Oh, I don't know. The, the advertisement we saw, The advertisement was one thing, but when you read, when you read, yeah. It sounded like alert logic to me.
But, okay, we'll, we'll go with that. Well, actually, let me ask, lemme tell you, uh, what I feel that is going on there is that they're not gonna deliver it today. 'cause they're gonna build The preview.
It's preview. Yeah, exactly. And, and what we do see them doing is working on long running AG agentic processes.
They talked about that a lot today, as a matter of fact. Yep. And what else is, you know, building safe software than a long running process of monitoring your code base, testing your code base.
That seems like what it ought to do. Yes. That is what it ought to do.
You know, there's an old saying, I learned in law school about what you do do and what you ought to do. That's the difference. You do, You're not gonna get caught doing Your comment on security there.
I gotta tell you the truth. I had a deja vu to 2007, the cloud, I can't put my stuff in the cloud. It's not secure.
Don't worry. We built security into the platform. We keep, We didn't buy it then.
I don't know if we buy it now. Yeah. We keep moving the layers up.
I think That it depends who you are, right? If you're a big company, maybe you question that. If you're a small company, you're never going to have provide That until, until well start that, And then it gets a little bit better.
And, and, and I go back to my thing about abstractions, right? We've now given developers more capability to do more things. So instead of, you know what, that budget for a pen test that was going to find 50 vulnerabilities, and out of those 50 vulnerabilities, 35 of them could have been found mm-hmm.
Automated in an automated fashion. Now, perhaps that same budget can focus on more critical Vulnerability. Just those 15.
Yeah, Exactly. Because we've asked you to do this. I'm optimistic, Always the optimist.
I, I'm, I'm, I'm, I'm optimistic. We are, we are. It's, it doesn't have to be perfect, right?
It doesn't have to be Zero. Nothing is perfect. What's de We're never gonna get to zero.
We're never gonna get Outta know that. Right? That's risk Management.
Risk Management, and said zero. I almost fell outta my chair. Yeah.
Anyway, Brad, Fernando, thank you so much for coming up here on Text Drug tv. Thanks for having us. Appreciate a pleasure.
We'd love to have you. You know, we do these remote, you don't have to come to Vegas to see us. And, and may I remind you that we are kind of halfway through, so there's, there's still, there's Still, and we'll be here tomorrow, the next Day.
There at least six more keynotes. Yes, There are. Yes.
And, and, and there are, and, and, uh, just, just to, uh, sidetrack a little bit, one of the things that I was really interested in is the, the whole ENT and, and, and, uh, and the neuros symbolic stuff. But coming alongside that, there's other things going on. Like one of the areas that's super interesting, like confidential computing, right?
Yeah. Mm-hmm. Oh, that's, we, we are seeing from a AWS do some interesting things there.
So let's keep talking about this. And, and, Well, now, now you invited yourself. You know where we are.
I have no excuse. We can do this remote. Yeah.
All right. Hey guys, let me just remind you all futurum does a thing called the Futurum signal. It's, it's the report that we've put out in, in different practice areas.
Fernando's done one. Brad's done one. The next two folks that we're gonna have on have done one, unlike a lot of other analyst firms, these reports are available to you.
You could go see the whole, I think, virtually the whole report, right? Yes. Yeah, yeah, yeah.
And sign Up. It's an amazing look at using ai. If you looked at our live coverage earlier, Daniel Newman and I had a great discussion on this.
I encourage you to all go look at FU signals, check out what's in there. This isn't last year's information given to you six months after the fact, right? It's, it's the, it, it, I don't want to say it's up to the minute.
It's not continuous yet, but it's a lot more current than the 18 month old stuff you may have been used to. So go check out Futurum Signals. These are the guys behind it.
We're here at AWS Reinvent for Text Trunk tv. We'll be right back. We've got two more great analysts I want to introduce you to.
Hi everyone. I'm Jonathan Bryce. I'm the Executive Director of the Cloud Native Computing Foundation.
Uh, it's great to be able to, uh, speak with you all here at this Cloud Native Now event. Uh, today I want to talk about some of the things that I see happening in the, uh, the landscape of Cloud native and ai, and how those are really starting to intersect in a big way. Uh, but first, for those of you who aren't familiar with the Cloud Native Computing Foundation, we are an open source nonprofit.
Uh, we host a lot of the, uh, most popular, um, cloud native software components and projects that you're familiar with. Things like Kubernetes and Prometheus and Open Telemetry, and, and on and on Argo and others. Uh, and it's something that is really amazing to be part of because it's a massive global community, uh, hundreds of thousands of contributors from all over the world who are, uh, making code contributions, documentation requirements, helping us to really push the state of the art forward.
And, uh, and we see this as, as something that, uh, is coming from every continent and, uh, and many of the countries, uh, companies and, uh, and individuals participating together to just help us build great software that, uh, we can run our businesses and our organizations on. io if you are not already part of the, uh, the Cloud Native Computing Foundation. And if you are, thank you for, uh, for your work and your contributions.
Uh, so I wanted to talk today about how two of the most significant trends in technology are really starting to merge cloud native and ai. And what's interesting to me is in the tech industry, we have, uh, kind of a proclivity to think of the next thing as, uh, replacing the current thing. Uh, and in reality, what happens is we're always building on top of what came before, whether that's operating systems or, uh, websites or mobile or cloud.
These trends are really additive. And I think that we are at a moment where we are seeing that really come into play with cloud native and artificial intelligence. Without a doubt, these are two of the biggest trends that, uh, that are in the tech world, uh, both within IT as well as within, uh, the consumer tech world.
And why is this happening? What's driving this? Well, that's what I wanna talk about today.
Uh, the way that I think about ai, um, and especially open source ai, um, I see it in three pillars. You know, AI is such a hot topic. Everybody's talking about it constantly.
And we see it not just in the technical press, but also in the mainstream news. And, uh, and AI can mean everything from, from deep learning and, uh, and these techniques that have been around for quite a while to, uh, chatbots and, uh, chat GPT and, and these kinds of elements. So I, I needed a framework as I was trying to think about where does this intersect with the world of infrastructure and cloud native?
And, uh, and, and the model that I've come up with is to really divide it into three pillars, which are training, inference, and then agents and applications. So training inference, and, and agents and apps, to me, represent three very distinct practices and technology sets within the world of ai. Uh, which means that they have different, uh, different expertise that's required, different kinds of infrastructure, um, really different communities as well in each of these three areas.
And, uh, of course, you know, there's always overlap and, and gray areas anytime you try to make a definition. Uh, but this has been very helpful for me to think about, uh, what are the open source projects that are at play here? Where should we be trying to build strong communities?
Where should we be looking for integrations and, and support? Um, and, and as I think about this, I also think about this kind of as an inverted pyramid, where at the bottom you have training. This is where we take data information.
We actually turn it into intelligence through these massive training runs, uh, where we go through the process of, of, uh, taking raw data, um, turning it into something that, uh, that is then a model. The inference stage is, is, uh, kind of one step above that where we take these models, we serve them, and we then make predictions. We answer questions.
And this is where we take that, uh, that, that intelligent model, um, and start to use it to solve real world issues. And at the top level, you have agents and applications, and this is where we connect that intelligence to individuals, uh, and to other applications that, that are maybe talking to each other and starting to act autonomously. Um, and combine, uh, you know, the intelligence that exists even across multiple models.
And if you look at each of these layers, um, you know, at the very bottom is where we have a lot of the deep, uh, science of artificial intelligence happening. Uh, the middle layer of inference, I think is where we have a lot of the operational expertise that we need to make this layer the most successful. And the top layer is where we start to have, uh, user experience and developer experience as an important element of what makes a successful application or agent.
So, you know, this is kind of my framework for thinking about it. And as I walk through this today, I'm gonna refer back to this, uh, to, to, to kind of set the stage on how I think, um, CNCF is, is playing in this world and, and what's, uh, um, kind of what's relevant for the next couple of years. So if we, if we look at the, the, um, the lowest level, if we're talking about the training level, up to now, what I think we have been in is this era of giants.
Uh, you know, I, I, uh, I, I titled my presentation training supercomputers. You know, this is what we've had, or these massive compute clusters that, uh, that have, um, thousands, tens of thousands, even hundreds of thousands of GPUs in them. And these are extremely costly to build out from a capital perspective.
Um, they are also time consuming to set up, to maintain and to operate, uh, a training run. It can take weeks, months, um, you know, a very long time, uh, which just again, increases the cost. So this is really, uh, a, a game right now where we see these frontier labs who are creating massive models.
Um, there was a, a quote from Sam Altman where he estimated that, uh, the GPT five training run could cost up to $1 billion. Uh, there was some news, uh, just last week that, uh, that came out about, um, a potential deal that Anthropic is making to acquire a gigawatt of TPU capacity from Google, a gigawatt of capacity, just, and that's an addition to the other, uh, capacity they have, uh, X AI's Colossus supercomputer that they built is now up to 200,000 GPUs in operation. They say they're gonna continue to expand.
And, uh, this is just an incredibly expensive and complicated game that most organizations, uh, are not really gonna be playing in that. But this is what we hear about a lot in the news. You know, what we have seen in the last couple of years is the chat GPT moment initially, which I think brought ai, um, kind of front and center in a real way for a lot of people.
And then we had the deep seek moment at the end of 2024, which brought open source ai, uh, kind of to the forefront. And we've seen so much innovation happening in, in, uh, open model development over this year. But all of these are really talking about these extremely expensive, large language models, these LLMs that are attempting to capture, uh, frankly, all of human intelligence, put it into a model that we can interact with.
And, uh, and that is, is something that I think, you know, it's been very fascinating for, for many, many people to have the opportunity to interact with AI in this, in this way that feels kind of like a human interaction here. You're talking to it, you're asking questions, you're getting feedback on your writing or your ideas. And so this has been something that where I think a lot of the focus is.
But I think that we are at a tipping point where we're going to start to move beyond just LLMs. And even with LLMs, I sometimes think of chat GPT as a proof of concept, not the actual end state of where we will be able to capture and see the most value from artificial intelligence systems. If we look at how open source has played into this, uh, you know, the, the investments have been largely on the, uh, the, the capital side with, uh, especially all of these specialized GPU components and the hardware necessary there, as well as with the, uh, the humans who are, uh, the, the very highly in demand AI experts.
Um, you know, it's a, a scarce resource, um, that's currently, uh, one of the, the highest pain and most lucrative types of, of roles that you can be in. Uh, what's enabled some of that is that the open source ecosystem around training is extremely robust. Uh, the PyTorch project has achieved huge market share.
Uh, if you look at hugging face, it's high. 80% of the models on the hugging face web website are, uh, are optimized and, and, uh, and kind of targeting PyTorch. And many of the largest labs out there are using cloud native technologies for their orchestration and operations, uh, uh, of these, um, these environments where they're doing the training.
And so, up to now, when we talk about cloud native and ai, a lot of times what we've been talking about are, how can we help, um, these labs take advantage of all of this hardware? How do we give them access to the GPUs with features like Dynamic Resource allocation and Kubernetes? How do we then, um, orchestrate that so that we make the most of those GPUs?
We're running them 24 7 and getting the most out of them. Uh, and, and that's really where the focus has been. But I think that we are at this moment where we're gonna be moving from massive training to actually taking inference to the mainstream.
And there are a few elements that are gonna be different as we think about taking inference to the mainstream. Now, when you look at these, these frontier labs and, and the extremely popular large language models, they obviously are running huge inference systems right now to meet the demand, and they're scaling them constantly. Uh, and, and that is a, that's a, a, a pretty impressive feat of, of operational excellence, um, that we've seen the labs like OpenAI and philanthropic, and obviously Google and others, uh, accomplish as, um, as they have been serving these large language models.
But I think that we're going to see inference go even mainstream in the next one to two years. And one of the things that will drive that, our specialized models, um, I've got a, a, a screenshot here from a, a headline. This is a, a blog on, uh, on the Uber blog.
And they talk about some of the work that they do, uh, in machine learning and artificial intelligence. And I have this quote here that, uh, that calls out that they do 20,000 model training jobs a month, and they're serving 5,000 models in production. So they're not attempting to create kind of one model that has all of human knowledge in it to, to serve their needs.
They're creating a lot of models that are specialized, and they might be, um, specialized for a city they operate in. It might be specialized for, uh, one particular workload that they're attempting to, um, to serve, such as predictions and recommendations or, uh, drive time estimates. And they find that that's actually, um, you know, a much more efficient way to be able to serve their needs.
And as you can see, you know, it says 20,000, um, 20,000 training runs a month, 5,000 models. So they're training these models in some cases multiple times a month. And I think this is what we're gonna see is that most enterprises are not going to just count on one giant model that captures all of human intelligence.
They're going to use, um, dozens or hundreds, even of smaller fine tuned open source models. Sometimes, uh, sometimes proprietary models, sometimes commercial models that are really good at specific, specific tasks. You know, it might be contract review, uh, it might be sentiment analysis, it might be, um, something like, uh, insurance adjusting estimation.
Um, one that obviously, uh, you know, we see a lot of is, is code generation is, is already a, a, a big use case, and some of the models are better at code generation than others. And, and I think that we're gonna continue to see differentiation and improvements in specialized models. Um, and, and I think enterprises will start to run these because the cost difference is really going to be significant.
If you look at, at, at the, the differences in kind of the, the operational side, um, and the performance side of a specialized model versus a totally generic, generalized model, I think that's where you'll start to see where the, the, the motivation, uh, is going to be to move to this type of, uh, of structure in a lot of enterprises. Um, it can be vastly cheaper, uh, to, to run and, uh, and fine tune a smaller model. Um, if, if you have a model that is trying to do one specific thing, such as predict the, uh, the, the travel time across the city, uh, it, it's much faster to get a prediction and get an answer out of a model that doesn't include, uh, you know, all, all of the, uh, the history of Europe and, uh, and, and America and, and eastern Asia and this kind of thing.
Obviously, uh, when you're trying to, to, to pull that, that type of information out, um, the performance can also be faster and more accurate within a specific domain. And because the resource requirements are not as high, we see specialized models already being run on less expensive hardware. So this doesn't have to run on the latest Nvidia GPUs, which are very expensive and scarce.
Uh, you know, Jensen is selling as the GPUs as fast as they can make them. And, uh, and those are great for, for these really high-end training runs. But for kind of the day-to-day inference, especially in a specific domain, there are alternatives that can, uh, are more readily available and can be a lot more, um, effective from a, from a cost power and, and operational, uh, perspective.
And also, you know, this is a, a, a path to being able to host these models in different environments. And that might be for security reasons. If you have, um, data that, uh, that really, uh, you don't want to leave your environments, um, you can host this in your own, uh, virtual private clouds, you can host this on premises.
Um, so it gives you more flexibility into these types of areas. Now, I think that the, uh, the reality is not going, this is not going to be something that just replaces the LLMs. The LLMs are going to be a huge part, I think, of, of, uh, of every business going forward.
But this is going to be augmentation for, um, specific business value that, uh, that becomes, um, in some cases differentiating for organizations when they can take the data of their organization, the kind of institutional knowledge of that organization, and capture it inside of a special model, um, that they can then scale and, and, uh, and repeat, um, similar to what, uh, what, what you can read about in that, uh, that blog from Uber. So, uh, what's, what are the challenges to doing this? Well, um, I, uh, a couple of weeks ago we had, um, an open infra summit for the Open Infrastructure Foundation.
And this was, uh, just outside of Paris. And I had the opportunity to do a, a keynote interview with Octa kba, who's the, uh, the founder and chairman of OVH Cloud, which is, uh, the biggest, um, European Cloud provider. Uh, and it is, it's, it's a fascinating story to, to dig into OVH and how they started and where they are.
Um, and obviously, you know, Okta and I, we started talking about AI and he had a quote, which, uh, which I loved. He said, at this point, we're all just waiting for tokens. Um, you know, this is kind of the, the thing that's happened is we love the potential of ai and whether we're doing just, you know, content development or feedback or planning or coding or some specific task, and a lot of cases, uh, we do get to a point where we're waiting on the AI to give us an answer, you know, to, uh, the, the tokens are, are the, uh, the, the kind of request and response, um, uh, nature of, of these, these models that we're all interacting with.
So we're sitting around, you know, waiting for tokens, and so how can we get more tokens? You know, we all want more tokens. And there are two ways.
One is, uh, to, uh, to add more inference, and the other way is to have faster answers from the models that we are we're serving. I think, as I said, you know, enterprises are going to take both approaches. Enterprises will continue to use LLMs for, for many use cases.
Uh, the, the large scale labs are going to continue to increase their capacity. Um, the, the, uh, there will be, uh, open models that, that are in the LLM space that get fine tuned and customized and deployed as well. And then I think there are gonna be a lot of specialized models which deliver faster answers and make more efficient use of the inference capacity.
But ultimately, we have to have more inference. Uh, Google has talked about the, their token, um, stats, how many tokens they're creating a month, and they're over a quadrillion tokens a month now, and it's gone up 100 x in the last year. So these are massive numbers, and this is really just the beginning of where we are in the AI adoption curve.
So we have to have more inference, whether we're talking about the large labs and kind of the main, um, the, the main AI providers, or if we're talking about enterprises, we have to have more inference. Someone has to deploy those machines, they have to scale the systems and, uh, the, the inference software, they have to secure it, uh, and then we have to observe it and make sure it's performing. How is that going to happen?
Who is going to solve this? Well, I think that there's a pretty clear answer. I think it is going to be, uh, the cloud native community that right now is responsible for deploying, scaling, securing, and observing many enterprise workloads.
Uh, you know, these platform engineering teams and the cloud native community and, and across our end users are the ones who are taking existing enterprise workloads and they're deploying them across public cloud providers, internal infrastructure. Uh, they're handling all of these elements that are necessary to run these workloads really well. And as I have been having conversations with platform engineering teams, there's been a real trend just in the last two months where responsibility for AI systems that are going into production is falling on the platform engineering teams.
And so I think that AI and specifically AI inference really is the next big cloud native workload. This is going to be added to the list of existing apps and microservices and, and databases and the other kinds of workloads the platform engineering teams are responsible for. Because it is going to require the same set of skills.
We're going to need to be able to do standardized deployments of these inference systems so that we can do them reliably and repeatedly. We're gonna need to be able to auto scale them. We're also going to wanna scale them down to zero.
So this is a great cloud native, um, pattern of, of being able to containerize workloads, spin them up and turn them off. Uh, we're gonna need security policies and enforcement with a lot of control and, and in some cases, much more control than, uh, than what we are used to in an organization where that's, uh, where we're just kind of managing human access to these systems. And observability is going to be far more important than ever.
Uh, if, if you have worked with, uh, with, with any of the AI systems out there, um, you can probably see how quickly the usage can skyrocket. And along with that, the cost and the implications of, uh, of, of that usage. So this is, these are the skill sets and the technologies that the cloud native community, uh, has and, uh, and are developing constantly.
And these are the, the things that, uh, that these AI workloads are going to need. As we look at the actual details of this, I wanna talk about two, uh, two example inference platforms. And these are both pretty early, uh, but I think that just to give you some concrete technology that you can go look into and, and poke around with, um, the first one is called AI bricks and these cloud native inference platforms, what they are doing is they're extending the existing cloud native architectures and concepts, and then they are adding in additional networking and especially sophisticated routing to make sure that, um, that requests and queries are, are going to the proper set of hardware, the proper GPUs, the proper caches.
Uh, they also handle things like distributing and horizontal scaling, uh, of the KB cache so that you can scale your GPUs horizontally. Uh, this is gonna be really key to adding inference at a cost effective level. Uh, they, they handle, um, security elements.
Uh, they handle different, uh, different types of workload placement and orchestration, uh, and it's all built around the existing systems. Kubernetes is at the heart of them, but a lot of the other cloud native, uh, cloud native projects are, are used here as well. So, um, AI bricks is the first example.
This is a project that's come out of by dance, and it's based off of, um, the, the production work that they've done for, for TikTok and other platforms like this. So something that's really, uh, battle tested at scale for, for algorithms and, and, uh, and running inference. The other one is called LLMD.
And this is a project that, um, that Red Hat launched along with a number of other companies, uh, earlier this year, I think in, in May at, at Red Hat Summit. And again, it's, uh, built around Kubernetes, and it adds these key elements to, um, to distribute the cache to do horizontal scaling, to do, uh, pre-fill and, and, uh, predictions on where, uh, where a, an AI request should go, where it should land, so it can be answered as quickly as possible. Um, in some of the benchmarks that they've done, they've been able to get much, much more utilization out of the same infrastructure just by the architecture that they've built, uh, and, uh, and, and kind of the, um, the decisions that they're making at request time, uh, so that they're much more efficient.
So these are the things that I think we are going to see emerge as really important technologies in the cloud native community, uh, coming up. So if you want to, uh, want to get started, what are some practical first steps? Um, I think, you know, it's pretty simple.
Experiment, standardize and measure. Uh, deploy a, a single open source model, go to hugging face. There are an unlimited number of models to try.
There are large models, there are small models, there are specialized models. Um, you can pick one, deploy it into your infrastructure, perhaps try it with something like LLMD or AI bricks, uh, but definitely containerize it, standardize how it's, um, packaged and deployed. Uh, because one of the key things that you're gonna want to be able to do is make sure that you can do repeatable deployments of this workload, just like other workloads.
And, uh, and finally, you know, agents, agents are the hottest topic right now out there. And I think the, uh, the reality is we can't have agents without inference. Uh, one of the simple ways to think about an agent is that it's a, uh, it's a loop against one or more AI models.
If we think about our, our kind of most common interaction with an AI model today, a lot of times it's a chat with a chatbot like chat, GPT or cloud code or something like this, and it feels pretty interactive and, and even pretty fast, you know, if I, if I ask for, um, recommendations for, you know, a trip or restaurants or hotels or this kind of thing, it comes back pretty quickly with, with a set of responses. If I say, I want to create this kind of application, and it needs to have these features, it comes back pretty quickly with suggestions for how to create that stub code. You know, uh, I can tell it, okay, flush this out and make all the code needed to work.
And it, and it feels very, uh, very snappy and in that sense. But in reality, that's actually a pretty low volume and pretty low performance type of use case. When we talk about agents, agents are going to be doing that thousands of times, maybe tens of thousands of times more frequently than we do as humans, because we're going to give it a task.
And it might be, uh, you know, put together an itinerary, find prices and, uh, and hold reservations for a, a trip to London and the second week of November, think about all of the interactions that you would have going back and forth if you were to do that manually. The agent is going to do that, and it's gonna do them much, much faster than we would. So our models are going to need to scale to become much, much more performant.
So we're not going to achieve that kind of agent, uh, nirvana that we, we want to get to unless we first build out massive inference capacity. And so this is, this is where I think all of these, um, elements of training inference and agents and applications tie in. But I think that we will get there.
We're gonna build, uh, an incredible footprint of inference within, uh, all of these enterprises. I think the cloud native community is the one one that's gonna do that. And then when we get to enabling AI agents, I think that, again, this is gonna fall on cloud native, uh, and platform engineering teams because these AI agent systems are going to be the next workload after we crack inference.
We're gonna have to crack. We, how do we run these agent systems in a way that especially takes into account security and scalability? Uh, these agent workflows are going to be, um, so much more complex than, uh, than I think the, the workflows that we're used to now.
And we're going to be expecting these agents to have access to, uh, to key data from our personal lives and our work lives and our enterprises. That's where the real value is going to come in. So we're going to see just an incredible increase in demand on inference systems and also incredible complexity that we're gonna need to solve somehow.
Um, when we think about the security model, especially, uh, we are gonna want to go beyond the security models that we have that are maybe built around kind of static applications and, uh, human actors within our enterprises. And we're going to need to be thinking about a much more dynamic environment in some cases. Uh, we already see AI systems that generate code and generate an application just for a single session to accomplish something that has a, uh, a, a special, um, kind of requirement in it, and then that code goes away.
So this is disposable software that's being created to solve a need in that moment. And, uh, and that's going to require much more sophisticated security models. So I wanted to put in a little plug here for another, um, CNCF project, which is open FGA, uh, this is a fine grain authorization project, and, uh, it's a, it, it's, um, it's an early project, but also quite mature and quite robust.
So I'd encourage you to check that out and, uh, and get involved in it. There's definitely an opportunity to help shape where that goes and, and get involved. And I think it could be one of, um, one of the important components that can bring, uh, this, this world of a agentic AI to reality for us.
So to sum up, you know, ultimately I think what we want is we all want productivity. We want, uh, kind of that autonomous productivity that, that is, uh, the promise of ai. And for that we want agents, but to get agents, we need inference.
Um, and we are seeing a shift from this kind of, uh, massive training supercomputers to I think the world of production AI systems and widespread adoption. And what's going to drive that is cloud native expertise and our community and our members. So, dig in.
Um, this is gonna be a, an awesome experience for all of us as we get to learn about this and, uh, and deploy these systems. And if you want to meet other folks who are doing that in just a couple of weeks, we will be in Atlanta at Kon Atlanta. Um, Textron will be there as well.
So come join us and, uh, let's talk about ai. Thank you, Sumo logical ai, open AI's mix panel Mixup, HP preps, a Pentagon project, take over scamming for fun and profit AWS and Google attempt to make multi-cloud easy. Again, LogicMonitor catches Catchpoint, and we're gonna take a closer look at a Apple's AI executive exit in this week's episode of the Tech Field Day Rundown.
Hello everyone, and welcome to the Tech field, a rundown. Today is the 3rd of December. We are in the final month of 2025, but the news just keeps on rolling, and we hope that you're doing something rather secure today for all of those holiday packages that have probably been delivered to your doorstep recently.
Uh, did you know it's National Package Protection Day? Who, who could have known? Uh, but joining me of course, is my protection, my, my bodyguard, and the guy who makes sure that I don't mispronounce any more names.
Mr. Alistair Cook. Al, it's good to see you again.
Always good to catch up with you, Tom, and to catch up with the latest news on National Roof over your head. Uh, and I understand that that's fairly important at the moment to keep the snow off your head where you are. It also keeps the sun from burning my not so covered head.
Yes, folks, this is the joy of having a global news show is that, uh, some of us are super hot, some of us are super cold, but what is always hot is the news that we're bringing you this week because we've got some real fun stuff. We're gonna kick off with a story from Sumo Logic because they're rebuilding their AI approach with two new agents. One is known as the knowledge agent, and one is an SOC analyst agent, and an early version of Model context Protocol, MCP server support that will serve as a foundation for a more open, unified system for IT and security operations.
Uh, this was announced at AWS Reinvent 2025, which is happening this week, and the shift aims to make it a lot easier to manage many AI agents and improved collaboration between security and IT teams, while also keeping humans in the loop. Full MCP platform support is planned for 2026, which will eventually allow organizations to plug in their own custom AI agents as AI driven operations mature. Al is Sumo Logic on the right path here by kind of revamping what they're doing and adding MCP support?
Absolutely. I think this is kind of vital for anybody who is building applications that need to deal with a large amount of data, and particularly data from a variety of different sources. And that's essentially what Sumo Logic's all about, is ingesting all of your security related log information.
All of the, uh, data flows coming in. We've discussed this on the rundown before, there is absolutely a need for AI tools and particularly ag agentic AI tools to go and take actions and response to some of the AG agentic AI attacks that's turning up. So we're definitely seeing more of that arms race and vendors in the security and logging, and pretty much any defensive space need to be on, on board with making sure that they can respond as fast as attackers can attack.
And this is in itself, this is just following standard best principles around how you build security and defense. You, you need to be able to respond at least as fast as, uh, as the attackers are changing their moves. Uh, it'll be a little while as, as we see the MCP server, which is gonna allow us to integrate the Sumo Logic part of the AI into our wider AI, uh, context, our wider AI application set, it's coming, it'll be a generally available in 2026, so you can certainly play with it now.
And we're not sure when in 2026, because of course, we're less than a month away from 2026 itself. Um, definitely seeing this, uh, use of MCP as a common way of gluing together multiple AI tools to get the best outcome that you can get. And, uh, Sumo Logic is definitely talking about having more of these Ag agentic AI tools coming out over time.
It's still fairly early in enterprise acceptance of ag agentic tools actually making changes to things like your security posture within your organization. And so it'll take a little while to build up the trust that these tools will actually do what we want and won't be influenced unduly won't then become an attack vector themselves. Of course, any automated response system is an attack vector for, uh, for an attacker.
So lots of work to be done here. Uh, great to see it going along. And of course, this was announced at AWS Reinvent 2025 going on right now.
We expect to have a lot more to say about what was announced at reinvent on that next episode of the Rundown, and I imagine there'll be plenty of AI in that. Speaking of AI open, AI says that a security breach at Mixpanel. Uh, so former analytics vendor exposed a limited information for some API users, including me.
I got an email telling me that OpenAI, uh, was aware that Mixpanel had been compromised, and that names emails, rough locations, B browsers details and user IDs were exposed in this. Uh, it wasn't OpenAI systems that were, um, compromised. It was systems that received data from OpenAI.
So, um, this, this should be no chats, no prompts, uh, no API, keys passwords, or payment data involved. And OpenAI has removed Mixedpanel notified effective users, including yours truly, and is reviewing other vendors of CO as well, because of course, if one of the vendors can be compromised, maybe others, um, users are urge to watch for phishing attempts and enable multifactor authentication as they should already have and open AI will continue to monitor the situation. Tom, does this surprise you or give you any reason to be concerned about using open AI tools?
No, it doesn't. And this is very reminiscent of last year's big Ticketmaster and Satan database breaches that all had the same common route that they were all running Snowflake and somebody forgot to turn on two-factor authentication. This is kind of table stakes, if you wanna call it that when you are working with companies that you kind of partner with and, and mix panels no different, uh, you know, open AI's job is not to build analytics.
Their job is to build an LOM that, uh, tells you how many Rs there are in the word strawberry sometimes. Uh, but what they're really doing is they're, they're offering these integrations with tools like Mixpanel to say, okay, well if you wanna farm this data out to these people, then you know, we'll do that and, and let you kind of do whatever you want to do. But how do you get the data from OpenAI into Mixpanel?
Use an API. And that's basically what happened here is that somebody got into Mixpanel and kind of breached their database, and when you breach them, you get all of the connecting information between Mixpanel and OpenAI, which in this case is names, email addresses, and API keys. Uh, you know, first things first, invalidate all the API keys.
Uh, OpenAI already went in and yank Mixpanel out. It's not even an option. They slammed that door shut.
But as I said on a, uh, recent episode of Security Boulevard, which I believe will be coming out in the next couple of weeks, um, this is kind of what you have to do if you want to enable systems to talk to each other, right? You can't close the door completely if you want to integrate, you know, think of it like an ACT directory federation. Like there's a certain amount of information that I'm gonna have to share between those two systems in order for them to be able to talk to each other.
Does that mean that there is a possibility that something bad could happen if one of those systems gets breached? Yeah, but my job is not to prevent the communications. My job is to design the system so that if the breach does happen, it is minimally invasive and easily, uh, cleaned.
And that's exactly what happened here. I don't necessarily fault OpenAI for this because OpenAI did what any other company in this situation would do. They partnered with somebody that they said, we are reasonably sure that you're taking all those precautions.
They didn't. They got breached. OpenAI closed the hole, like, that's how you're supposed to do these things.
So I think the fact that OpenAI had to disclose that they, they were, they suffered from this because of one of their partners, probably was more news than the actual breach itself. But I, I don't know that how you could have prevented this if you're OpenAI other than saying, well, we're not gonna partner with anybody, which honestly reduces the utility of using open AI in the first place. So lesson out there to all of my security friends, well, two lessons.
One, make sure your Subscribed Security Boulevard podcast that we produce, uh, here at the Futurum Group. But second thing is make sure that your defenses are ready to step forward just in case someone manages to breach you and, and get on the beach, so to speak. HPE won a $931 million 10 year contract to expand the defense department's secure private cloud.
The project uses HP's GreenLake platform to give the military cloud-like flexibility while keeping sensitive data on controlled infrastructure. It supports multi-tenant workloads, central management, and AI ready systems, which is another step in the Pentagon's ongoing IT modernization push. Al, we've covered the Jedi contract a number of times in the past, and, uh, that was a whole lot of drama that I really don't care to revisit again.
How did HPE slip in the back door with GreenLake and, and make this into something that they can hang their hat on? Well, it seems that this is a relatively small purchase. Last week on the, the rundown, we covered the, uh, $50 billion for, uh, a Amazon or AWS build out for defense.
Uh, so when we look at sub billion dollar spend, uh, I know it's a lot of money, and I much rather it was in my bank account. Uh, it's, uh, it's not that huge of a spend. So maybe this was just a, uh, an ongoing piece, uh, of, of development.
Uh, I like that this is centered around HP GreenLake, private cloud, uh, being deployed and, and to take workloads that don't suit pushing out even into the regulated cloud environments. Uh, defense networking is always very complicated. There's always different levels of security required and, um, good very strong isolation between the, the different environments to be they secret, top secret or operational, all of those, those separations.
So, um, this is, again, delivering things like AI readiness into the infrastructure for those more secure locations where you can't farm it out to open AI. And, oh, oh, hang on, did we just mention that? Uh, yeah.
So bringing things on premises, putting these into air gaps, locations where there is no internet connectivity, uh, provided as well. Uh, but still with centralized management across those secured networks, across each of those secured networks, you have to manage each of them separately. Uh, it does sit within that wider wave of lots of money being spent on upgrading and improving the, uh, compute environment and modernizing applications for defense.
Say, nine $31 million is a, a good big spend for, uh, uh, a big, the customer who is, um, yes, buying some infrastructure, but on the scale of investments for government and defense spend, uh, computing spend alone, it's, it's not a huge amount of money. It is looking after those highly secured networks, highly secured applications, and potentially being used globally with thousands of users. So this could well be lots of very small, at least on defense scale, lots of very small deployments.
I've seen, uh, entire clusters put into, um, units that can be deployed out the back of a, a cargo plane and, uh, land on a field and then be assembled up. That kind of infrastructure is the kind of place where it really is air gapped and it needs to remain that way. There's no indication that this is about air deployable data centers, but it is, uh, HP is GreenLake getting a, a big thumbs up from Department of Defense, the FBI says that scammers opposing as bank staff, and they stole over $262 million this year by tricking people into giving up information they shouldn't.
Social engineering is still at the, the core of all of hacking, whether that's logging credentials or multifactor authentication codes, uh, all of the usual kind of ways of getting in front of people, texts, calls, emails, websites that, that look like your bank site and aren't, um, all kinds of things. Attackers gain access to your credentials. They convince you to give them your information, and then they drain your money, whether it's getting into your company's financial systems, payroll, um, crypto wallets, account takeover, and phishing is on the, on the rise.
Users are still practicing poor security habits. Experts, uh, suggest strong passwords, multifactor, authentication and skepticism. My skeptical colleague will advise you some more on this.
Mr. Hollingsworth. Um, go look up XKCD 5 38.
Everybody knows this one. You know, we don't need to create this massive quantum encryption state machine to steal valuable data from folks. We just drug them and hit them with a $5 wrench until they type in the password.
That's really what this is about. As much as we talk about, you know, using AI to create these things and quantum resistant encryption and all this other stuff, most of the time the fastest way to get access to a system is to call somebody and pretend to be it. Uh, I reference again, the Seminole 1995 were hackers.
Uh, Eddie Vetter doesn't work in accounting. He does not need you to read the number off the back of the modem to gain access to the tape library at the local public access station. The real ones no zero, cool for life.
Now, this, this is a thing. We, we have gotten to the point where we really have educated people about as much as we can. It, we've just gotta reinforce things.
One, strong passwords, but better than that two multifactor authentication and pass keys. Um, I had to reset a password today that I managed to have forgotten. And, uh, in the meantime, when I was in there, I also turned on MFA for that account and looked around and it didn't have passkey support.
And it needs to have passkey support because that prevents these kinds of things from happening. And third, and most importantly, never ever, ever, ever give any of that information to anybody when they call you. Um, I, I think I've mentioned this before on the rundown, but I had a friend who called me in a panic because her daughter's Instagram account got compromised.
Um, and the way that it worked was a friend of hers on Instagram messaged the daughter and said, Hey, I got locked out of my account. You're gonna get a five digit code texted to you. Can you please give me that code?
Y'all know what happened next, right? Because she immediately got forced out of her account password, email changed instantly while I was on the phone trying to troubleshoot this like that. That's how fast it takes, folks.
They are really, really good at this. Never give anybody your password, never give anybody any codes that you are texted. If you didn't request it, do not read it off to anybody.
If someone calls you saying they're from it, from support, whatever, because we all know emails are probably a scam, but even if they call you, don't answer anything. Don't give them any information. Hang up and call the number back because odds are good.
You can spoof caller id, I've done it before when testing systems odds are good that they're not doing it for legitimate purposes, but why would they wanna steal anything from me? I, I don't matter to anyone, really, by the time they've cleaned out your bank account and your savings account and your investment account, because you use the same password on all of those, and I hope you didn't use the same password on that crypto wallet that you have hanging around on your desktop or that you've uploaded to the cloud. Do you see how it's basically kicking in the front door and swiping whatever they can get their hands on as fast as they can get to it before you can change all the passwords?
Yeah, that's what they're looking for. They're looking for easy cash outs. And your bank isn't going to help you if you are the one who gave them all that information, because to them it looks like a legitimate transaction.
Be smart, educate yourself, educate your family, especially young kids and older parents and grandparents. 'cause if we can stop this, then, you know, who knows? Maybe, maybe we don't have to have the story again, again, again, AWS and Google Cloud have launched a joint service that lets companies quickly set up fast private connections between their two cloud platforms.
This partnership, which honestly is a little bit unusual for fierce competitors like AWS and Google replaces today's complex manual multi-cloud networking with a simple click to provision link built from AWS interconnecting Google's cost cross cloud interconnect. The companies also released an open standard, which they want to use to encourage wider adoptions With early users like Salesforce, praising simplicity and reliability, the move reflects growing customer demand for smoother, more secure multi-cloud setups. As businesses rely on more multi-cloud providers.
Al, was this something that customers really were asking for? Or is this an olive branch to the rest of the industry saying, see, we can play nice. This is absolutely something customers were asking for, and they've been asking for it so much that, uh, recently in the, uh, UK competition and markets authority, both AWS and Google said it wasn't needed.
And that multi-cloud and interoperability is not a barrier for customers. The fact that they cannot, uh, that customers cannot just simply join together the networks that they've crafted inside AWS to the networks they've crafted inside Google apparently isn't a, an impediment. Uh, the reality is customers want to care as little as possible about the mechanics of connecting together their hybrid multi-cloud environments.
They want efficiency in that data transfer. If they've got part of an application on AWS and private on Google Cloud, they want to be able to get connectivity between them to be, uh, fast and efficient and as lower cost as possible. I really like that this is being, uh, described as being entirely software.
Historically, whenever we wanted to connect a cloud provider's network to our own, somebody had to patch some fiber cables and we had to send somebody to a data center for it. That severely restricts our agility for making those changes. And particularly means we're not gonna make them in response to something like a change in availability of services.
There's a line being drawn out to AWS's outage that if there was, uh, the, the outage last month, if there was easier connectivity to other clouds, we could have potentially transitioned our workloads between them. Uh, I'm not sure that that's the actual reality for most customers. Uh, it is often that they have applications that live in one cloud that they need to talk to, uh, applications running in another cloud.
This is definitely a good thing for customers to be able to easily and connect between their multiple cloud providers. And if the standard is properly open and not heavily biased, we may well see uptake with other cloud providers. Of course, Microsoft as Azure is the, uh, big name that's not on this announcement that would probably have been good to have on the announcement.
Maybe that'll be coming shortly as well. Maybe we'll get that announcement at reinvent. Who knows?
Uh, certainly Salesforce, a big customer is, is very happy with this connectivity improvement for them makes it much easier to connect together parts of their applications and partner application for this particular LogicMonitor has acquired Catchpoint to build an AI powered observability platform designed to prevent downtime instead of reacting to it by combining logic monitors, infrastructure monitoring and AI engine. With Catchpoint's internet level, uh, performance data, uh, the new platform offers end-to-end visibility across cloud code and the internet. Customers get unified insights, fewer tools and predictive alerts that fix issues before they impact users.
The companies say the deal is a major shift from reactive IT to proactive AI driven operations. How's your AI driven operations across the internet to, Well, it hasn't driven me off of a cliff yet, so I'll take that as a plus. I, I think this is actually a smart move on LogicMonitor part because they really do have on-premises enterprise IT infrastructure, that market kind of locked up, right?
They're iterating there by providing AI driven, uh, insights and things like that. But what you're missing is visibility outside of the firewall. Why would that be important?
I don't know what's happened in the last month. Uh, Amazon botched a DNS update, uh, cloud flare botched a robot's file. Oh yeah, the internet went down.
So my stuff on online, on on site works, my stuff online does not, whose fault is it? Well, we know what happens. We get the finger pointing, whose fault is it?
I don't know. How do I fix it? I don't know.
But at least with LogicMonitor now having Catchpoint visibility built in, you can figure out where the problem is to know where you need to be making the phone call to make it happen. And I think that that's something we're gonna start seeing more and more. You know, we saw Cisco buy thousand die.
We've heard a lot from our friends at Kente about doing this, uh, many times at, uh, networking field, A but also at Cloud Field A and a lot of other places. And Catchpoint has also presented recently at, at Cloud Field a and I think that what you're seeing is the shift to say we need to have a source of intelligence to feed to our AI algorithms to be able to provide insights into where the problems are. Now, the outage thing is probably like the big winner here, but it's important to understand that any kind of latency or delay in the system impacts your users and you need to be able to keep an eye on that, right?
Are you seeing latency growing on a link over here? Well, maybe it's time for us to switch. Maybe we need to go to that backup NPLS circuit that we've had on hold for whatever rainy day problem that we might need to have.
Or maybe we need to route traffic through our private network into a different DIA port so that we can get out and around whatever problems we're seeing. Um, this is actually a huge problem for people right after we get back from the holidays here in December, uh, January, usually those first two days in January when we're back in the office, everything just kind of falls apart because, you know, the Amazon transit gateways aren't used to getting that much traffic. Well now with basically like a lighthouse, like a, uh, uh, an observability sphere if you will, on what's going on out there, you can see if those numbers are ticking up, if those requests are taking longer than usual.
So you can kind of calm your users down and say, okay guys, have a glass of leftover eggnog. Let's let this storm roll past and everything will be fine. I think this is a good pickup for, for, uh, LogicMonitor.
I'm happy that our friends at Catchpoint got a good exit. Um, can't wait to see how they integrate this. I'm sure we'll be talking more about this on the rundown sooner rather than later.
Alright, it's time for our closer look. I hope you wanna talk about AI because that's what we're gonna be talking about. Apple's AI Chief John Gian Andrea is going to be retiring after some delays and criticism around Apple intelligence, including the much rumored and often postponed Siri Overhaul.
Amar, AYA, and I'm sorry if I butchered that. Um, who, who was a former per, uh, AI person at Google, who was responsible for doing a lot of the Gemini stuff, been there for 16 years and most recently left to go to Microsoft in June, will now be going to Apple. He's gonna take over as the person who's gonna be in charge of Apple Intelligence, he's gonna report directly to Air Force one himself, Craig Federighi and Apple's gonna be reorganizing its AI teams a little bit.
Gian Andrea will stay on and as an advisor up until spring of next year, and then he's probably gonna go take his money and buy a yacht and sail around the Mediterranean or something, I don't know. But, uh, the shakeup shows that Apple really is still trying to catch up in ai, which is mirroring some other leadership churn that we've seen in other tech companies as they kind of try to adjust to what's going on. I know we talk a lot about enterprise AI adoption, but this is an interesting problem because this is pretty much consumer-focused ai and a lot of people, if you read the forums out there are, you know, criticizing Apple for being behind on ai.
And some other people are saying, well, I don't understand what the big deal is. And of course there's talks about bubbles and stuff like that. Al, I'm gonna let you jump in here to start.
Do you think that Apple is behind and do you think that bringing in the wizard behind Google Gemini is gonna be the way to fix it? Well, apple is definitely failing to deliver Apple intelligence and AI the way we would expect. Uh, for me, one of the most telling things is we have, uh, a couple of delegates who will use chat GPT on their iPhones to ask questions and, and get background information as we're doing for our events, our tech fields, events, even if they're on their iPhone, they're not asking the question of Siri, they're asking it of chat GPT.
That's, that's pretty telling. That's saying that, uh, sir is not keeping up with chat GPT in terms of delivering ai. And that's fundamentally what's going on here.
Uh, we'll recall that Johnny, I've left Apple and went to found a, an AI startup. This again, follows the same idea that that Apple just isn't quite getting or delivering AI as, uh, visionary people are expecting it with. Superman can come in and shake things up enough whether he will have enough power and, uh, that, that he can shift the thinking in Apple to actually deliver what's needed.
What's wanted here remains to be seen. Uh, it's always a challenge coming in from outside the organization to try and make large changes, especially for an organization that has attempted to do a particular thing. AI in this case, uh, and specifically generative AI for a long time and has not really delivered that generative ai, it's very hard to come in then and get that transition, that sweeping transition.
It's also interesting that the reporting line changes. So Gianna Andrea reported directly to Tim Cook, whereas Superman is gonna be reporting, uh, indirectly, and that doesn't, to me smell of we're gonna really enable you to do big things and make big changes. Uh, let's hope I'm wrong.
Let's hope that Siri actually becomes the, the new interface that we're going to use to gain some, uh, insights about what's going on around us. Tom, I know, like me, you're, uh, an iPhone user and, uh, have had Siri at your fingertips. Has Siri done great things for you?
Do you use chat GPT on your iPhone? Uh, I actually don't. Um, I've, I've used some AI LLMs before, uh, but I'm gonna take a little bit of a contrarian view here because, well, it's my show and I can, uh, what exactly did Apple fail to deliver on, uh, audience out there?
I want you to leave a comment on this video. What, what did Apple fail to deliver on with ai? What exactly is the killer use case that you are looking for in an on-device ai?
Is it to look up the batting average for the 1953 Dodgers at a moment's notice? Because you need to do that to win a bar trivia contest. Is it every tech bro's dream of having a system that will automatically make dinner reservations for you?
That's actually a, a, a TikTok that I watched the other day. Every piece of AI that I have seen so far that is consumer focused is trying to get your phone to act like an automated executive assistant. I wrote a blog post about this recently where I said, AI is designed by people who want people to do things for them.
When you look at the executives, when you look at the senior vice presidents, when you look at the people who are showing all this off, what are they, what are they showing off? It will provide context so you don't have to read through things. It will give you insights made up or otherwise, and it will make dinner reservations for you.
It is a system designed to do things that I would have other people do. So is the killer use case for AI that I want to get rid of my executive assistant? Or in the case of people like me who don't have one, do I want a system to do that?
Is that what Apple missed on? Because as far as I can tell, there's some things that Siri can do that chat. GPT can't like anything to do with the actual device that I, I'm dealing with.
And do you know why that is? Do you know why chat GPT can't turn on low power mode or send me a reminder for something? It's because of the privacy focus that Apple has had and yeah.
Alright, you're gonna leave a comment. You're gonna tell me how Apple doesn't have a privacy focus and all that other stuff and Hey, I agree with you. What's Google's privacy focus?
What's, um, the, uh, the Xmi phones privacy focus? Do, do you have a, a list of the things that they've done? Uh, do you have a new story from this week where, uh, a nation state asked Apple to force an app to be put on the phones and Apple said, no, I don't think we're gonna do that.
Right or wrong? Apple has been focused on keeping things as isolated as possible. Yeah.
That means that the lady that lives in your phone is not as functional as chat GPT is right now. But what it does mean is that if you accidentally say the trigger word and then say a whole bunch of random stuff that you don't mean to say, it doesn't end up in an LLM database to be crunched and done all these things for years and years and years. I don't necessarily know that there is a direction for this, because remember when we talk about all this AI stuff that's going on on the other side of the fence with the open ais and the Nvidia and the Microsofts and the AWSs and all that other stuff, that's B2B that is selling hardware to do inferencing, to create better models.
To do what? Because again, I have to come back to Apple is a trillion dollar company that sells phones, tablets, and laptops to people. OpenAI is worth billions of dollars.
And what do they sell? Because as far as I'm aware, according to the news stories that I've heard this week, they're gonna have to start injecting ads into chat GPT chats because they don't actually sell anything. They sell a subscription to a thing and they don't bring in billions of dollars a year from that subscription.
In fact, most of the time, most people who use it don't pay for it. So I'm, I'm still struggling to understand why someone who had been at Apple for several years had to be forced out of retirement. 'cause he retired, but he didn't really retire.
He was told to retire. This is a way to prevent the markets from going crazy. What, what, what are you, what, what is it gonna take?
Like, like, you know, this is not the Steve Jobs moment of I have a web browser and a phone and, uh, PDA in a thing in my pocket. We're past that point. That was 18 years ago, folks we're, we're in a different world now.
I don't think you're gonna get the killer app that you want, Al, am I wrong? Usually? That's fair.
That's fair. You know, the, the, the killer app is I think definitely a, a dead term. Um, the killer use case of not having to wade through nearly so much information, not having to try and find the little bits that I'm interested in, in the flood of information, or to be able to find the place that I want to go, the person that I want to talk to.
These are the things I want from, from ai. I want it to take away all the, the, the drudge work. So yeah, booking a hotel is, is an entirely relatable piece of drudge work.
But, uh, being able to look at those 600 emails that have come into my mailbox and actually intelligently work out which ones I need to act on, that's the kind of thing I want from a, a good ai I'm not seeing that's the opportunity is, is there to help us with the information overload we suffer from. And most people do suffer from too much message, too much, uh, information they need to process and not enough insight being delivered to them. So that's what I want from an AI that I hold in my hand every day.
Of course, I want it integrated with the laptop that I have in front of me for way too much of every day. Uh, and I really do want that consistent view of who I am and what I know, what I care about, rather than, uh, some very generic stuff. I've, I have found Surrey quite disappointing at finding even as simple things as, uh, tell me where the nearest supermarket is when I'm sitting in the car park of a supermarket in Surrey.
Doesn't tell me that supermarket, there's a whole lot of things that's, uh, challenging for me in, in Syria and more development towards that intelligence. Uh, or at least the ability to handle large amounts of unstructured data and turn it into some semblance of, uh, insightful data would be very helpful. We'll just have to see what happens, because of course, this is an ongoing story, just like a lot of other things that we deal with here at the rundown.
So rest assured, when when the Killer Siri app comes out, we'll, we'll be sure to let you know. Um, but we won't be asking it to tell us how to do that because, you know, it's a little hit or miss. What's not hit or miss is, of course, all of the great events that we do.
We are, we're pretty much done with events for the rest of 2025, but 2026 is starting off with a bang, and that's because Alistair's coming back to our side of the pond to enjoy our winter again. But, uh, you've got a cool thing coming up. I have a cool thing, although it'll be for a winter, it'll be a warm thing because we will be, uh, back in the Santa Clara region, uh, around, uh, Silicon Valley for AI infrastructure field.
Day four, I'm not expecting any snow, but, uh, it should be cooler than it's here in January. So the end of January, we have, uh, currently six different companies presenting, uh, lined up to present over the three days of the event. Quite a few more that are gonna join in as well.
Uh, I've been building out the delegate panels, some great people, some people that I haven't had at my events before. Uh, and looking forward to having some good discussions with a collection of vendors. We've got quite a leaning towards networking for AI infrastructure on this one, so that'll be an interesting insight to see.
And of course, uh, following on in March, I return again for Cloud Field Day. Uh, another of the events that I really enjoy is digging into what it actually means to use cloud as part of your infrastructure. And, uh, looking at the realities of these hybrid multicloud.
We covered AWS and Google joining their networks together. That kind of, uh, capability is what we'll dig into some more in Cloud Field Day 11th and 12th of March. Well, don't forget that we're always adding new stuff to the calendar every time you turn around.
So just because we've announced the first couple of events doesn't mean we're not gonna be in a lot of other places. com is your home for all of that stuff, so make sure you check it out. You never know when something's gonna pop in.
We wanna thank you all very much for watching the Tech Field Day rundown on this Wednesday. Remember that you can catch new episodes every Wednesday on YouTube, but also in your favorite podcast application of choice. We'd love it if you'd subscribe, uh, leave a comment, leave a rating, leave a review, a thumbs up, something, because every one of those things helps people figure out if this is something that they wanna be listening to.
And we, we do appreciate everybody who has, uh, suggested stories, who has, uh, given us great reviews, who uses us as their sole source of news because quite honestly, we try to make it fun around here. Um, we will be back next Wednesday to talk about all the news that happened, especially the stuff from AWS reinvent. So make sure that you're tuned in for that.
Until then, everybody, take care of yourselves. Enjoy the rest of your week, and we will see you next time.