Techstrong TV – February 12, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hello everybody, and welcome to the latest episode of the Text Drawing Gang. We've got a I PCs today, a feud between AI robber barons, and a debate over, well, what's going on with finops. You're watching Textron Gang, and we'll be back in a minute.
Hey, folks, I'm your host for today, Mike Ard, and we got an awesome lineup of folks today starting with our friends in California. Once again, John Schwartz is out there in the Bay Area. John, how are you?
I'm doing good. I'd rather be here on a big Gang. Excellent.
Also out in the Bay Area. Lisa Martin, our resident, and CMO advisor, expert at the Future Room Group. Lisa, good to see you again.
Good to see you too. I'm excited for today's gang. All right.
Going, I guess clockwise. I hope maybe everybody sees it the way I see it, but Amanda Ani is down in Texas. I How cold is it in Texas these days?
Is it is? It's in the forties all last week. It was high eighties and now it's in the forties.
All right. Wow. Also hanging out in Texas.
Guy Courier. Yeah, in central Texas where I might hit 60 today, but more to the point, it's like not just cold, it's like a little windy and like wet and ugly. Maybe that's why I'm so cranky.
Or maybe it's because my, uh, because of my horrible Super Bowl prediction. Well, that could be too. And finally, Stephen Foss in Ohio, where it's as cold as it is where I am in New York.
Steven, how do you do it? It's as cold as ice. I'm willing to pay the price though.
Oh, man. Ice foreigner reference. I saw that tour, by the way.
Hey, don't call me a foreigner. I want stay here in America. Alright, noted somebody.
Well, we'll do something about that. Somebody, somebody check his birth certificate. All right, we're moving on.
No need. We can just declare him a foreigner. All right, well, let's get into our first topic of the day, which is a, I PCs our friends over at the Futurum Group have a new report out suggesting that enterprises might start buying these things earlier than anticipated to future proof, as it were, because, well, and they tend to hold onto to these things for a few years.
But John, you wrote this report. What's your take on what's going on here? Um, is it realistic or is it wishful thinking?
It's probably both. I mean, there's a, there's elements of it that are real, but I think it is in terms of wishful thinking. So the group talked to 852 enterprise IT decision makers this year, and, um, they came away with three major findings that, number one, about more than half build this need for their workforce to be more competitive as quickly as possible.
So I guess the idea is you put the technology in front of people, people on an everyday basis and kind of force them to learn it, or at least adapt to it. The second reason, which is tied to the first is that nearly half identified the impending end into Windows 10 support as a critical priority. And then a third pointed out the necessity for improvement in system performance.
Now, the, the thing that is interesting to me, and it was not in the story because it just came out, there's a Wedbush securities report that shows that the budget for AI is probably roughly going to be in the 10 to 15% range this year up from single digits, which shows this kind of acceleration of an a AI strategy over the next six to nine months. So there is like this discernible movement going on. Um, and I think that the AI PCs may play a, a, a piece of it.
I'm not sure how significant. I think there's still some sort of roadblocks, for instance, in those, uh, FU survey, 36% were concerned about the higher unit price of a I PCs and related costs, such as subscriptions to feature enabling services, um, uh, about a fourth side of the concern over the ability of A IPC to run critical enterprise software natively. So there are still obstacles, but I think it is definitely moving in this direction.
But, you know, seeing is believing I, the, the, the idea is it's go time. Um, we'll see, I know, I, I have a, a measure of skepticism about it, but there you have it. Guy, you wanna jump in here?
Well, yeah, I've been saying, uh, all along, you know, here and elsewhere that, uh, the, the AI movement feels a lot like the PC movement to me from back in the eighties, which was in the case of the pc, about 20 years of investment purchases, use, all that sort of stuff, while the economists were scratching their head and saying, well, we don't see any productivity gains. The benefits were so obvious that nobody was sitting around and measuring productivity. Nonetheless, that sort of business, bottom line, there was an adjustment to be made.
People had to be trained. And then eventually we started to see it. I think that we're gonna see that return on investment, um, for AI generally a lot quicker than in 20 years, but it's the same basic thing.
The benefits and usefulness are so obvious that investment is just going up without people sitting around trying to calculate the productivity or other gains. But I do wanna say this. So when it comes to AI PCs specifically, I think that that's the movement.
It's just there seems to be an obvious benefit. So it shops are investing in it, but I also kinda wonder if, if we know like what an A IPC is, I mean, you know, on this, in this group, uh, we can, you know, come probably I'll come up with a reasonable definition. But I'm, I'm wondering, uh, at Lisa and, and Amanda, I think of you guys having sort of your pulse on popular sentiment.
Do people know that an A IP PC is a PC that is tailored for local inference? Or do they think something else, like it's something that helps create ai? I I think that a lot of people are thinking the latter.
Yeah. I think a lot of people really are not clear on what an a I PC is. You nailed it.
Yeah, I agree with that. From a messaging perspective, I think it's not clear what that is. Um, from an inferencing perspective, I think the average person doesn't understand that.
And so they think, is it, is it an a PC with AI and built into the hardware and software, can I create AI with it? I think there needs to be some more definition and clarity around what it is. Mm-hmm.
And what those clear benefits are to any type of organization, retail, any other industry. All right. Well, as it happens, Steven fki has a video last year defining what an A IPC was, and it was one of the most watched videos he did all year long.
So Steven, what the heck is an AI Pc? Thank you, Mike. Uh, yeah, I think a guy was maybe there when I recorded this live at a tech field day event.
Um, yeah. And the, and it's, it's funny because it, obviously this video hit a nerve because that's the title, what is an AI pc? And so people are searching this and they're trying to figure it out.
Um, essentially, uh, it, what Lisa said is, is right on. It's not just hardware, it's hardware and software. And that is the important aspect to me of, you know, what is an A IPC?
You'll notice as well that in the Futurum study, um, they talk about not just Qualcomm, Snapdragon X versus X 86, they talk about Apple, and remember that Apple is right there. I mean, we sometimes use the, the, those two letters PC to exclude Apple, but in this case, apple is right there making AI PCs as well. And what I said in the video, and this is like, I, I, you know, I think what people need to know, and what as, as you know, you just mentioned Lisa, that that people don't seem to know is, um, you know, it, it's all about running AI locally on your local data, on your local machine, but it's not just about horsepower.
Now, certainly Snapdragon X and the Apple M Series have incredible horsepower for pro doing AI performance tasks, and Intel and a MD are not asleep at the wheel. They have also introduced incredible chips that can, I mean, it's, it's it hilarious because I mean, they're right there with, with chips that can do the same thing. Um, but it's not about hardware as much as it is.
Well, I mean, hardware is a necessity. It's about software and it's about integration, and it's about having those models at your fingertips. Companies like Microsoft and Salesforce and Slack and Dropbox and, and all these other companies are trying to bring that software natively into the interface.
Uh, you know, Microsoft now has, you know, co-pilot in the ribbon on office apps. Uh, you know, that's when AI becomes real. It, it can't happen until you have a PC that can handle the, the, the, the, the computing.
But it also can't happen until, you know, Joe in accounting, or Jane in software development has that copilot icon on her desktop and, and, and, and, and knows how to use it, the desire to use it. Right. That's, see, that's The, yeah, those are the two things, right?
First, we keep So much about it. You know what, you know what guys, let's just buy right now and we'll figure that out later, maybe in the third or fourth generation of A IPC that we buy. I mean, that really isn't that what's happening?
So some, So I have a question. So you say it's more about the software, it is about the hardware too supporting, but, um, I imagine a lot of people would say, well then, um, can't I just make my current computer be an AI pc? Because all the shared AI software, I mean, we see the copilot.
I already have copilot, already have chat. GPT already have Canva ai. Like, can't I just use a bunch of shared AI software and I have an AI pc?
It's, it's a, it's a really good point. And I think that in some ways, the AI industry may have done themselves a disservice by rushing this stuff out with cloud-based applications, because essentially, as, as you're saying, yeah, absolutely. That copilot, um, icon appears whether you have an AI PC or not.
And in many cases, you know, I mean, you look at chat GT's incredible success. It's running in the cloud, you don't need an A IPC to run chat GPT, you can run it on your old iPhone se, even though it's not actually running on your old iPhone, you know, it's, it's running in the cloud. But to you, does it matter?
And Apple has done an incredible job as well of seamlessly integrating cloud and local processing to the point that even if you have the latest and greatest M four, you know, iPad or Mac or, or, or the latest iPhone, um, you don't know, and you can't know whether it's running locally or in the cloud. And that kind of undercuts this entire discussion because if, if all this stuff can run whether you have an A IPC or not, then what's the point? Yeah.
Mm-hmm. All right. Think about this slightly differently.
com boom, I went toe to toe with A CFO, who subsequently became one of my best friends. But at the time, you know, he was arguing we didn't need new PCs to support a publishing staff. That was at the time, moving into the brave new world of online publishing.
And everybody's laptops were crashing, and stories were getting lost and people were losing their minds. And, um, but for whatever reason, you know, he was still on this, well, we're gonna upgrade every three year kind of cycle. Fast forward to today, I would've just told him to bugger off and went out and bought a bunch of PCs myself and just handed them out to folks and said, you know, this is our new units and this is what we're doing.
So guy who cares what the CIO or the CFO thinks anymore, people are just gonna do shadow it and do what they need to do when they need to do it. Well, I think that's a great follow up to Steven's comment because with a certain level of, like, one of the things that I'm really hot on right now is Edge ai. Steven helped get me there, by the way.
I have to say, uh, in, in and work with the tech field in with him. Why? So that answers your question, Amanda, but it's a technical question.
Where should processing occur? Should it occur at the core or should it occur at the edge? This is an architectural question.
This is an application architecture and design question. Like Steven says, like, Apple's done a phenomenal job with this sort of thing. So Mike, I don't see any reason if you got the money not to invest in what amounts to an Edge AI capability, that's the IPC recognizing that maybe it'll never be used.
So I agree with you just go, take out who cares what the CIO and the CFO says, well, you care. You're ahead of a business unit. You care about your bottom line.
You wanna show ROI, you invest in all kinds of things all over the place, the technological and non-technological, like fancy group dinners or something like that, that you're not gonna sit there and justify, hey, this particular thing had this ROI, especially if it has AI attached to it. In fact, let's just attach AI to everything that we wanna buy, whether it really is AI or not, and then everybody will let us buy it. Uh, John, what do you think the odds are that an AI PC is gonna cost a lot more in three months due to a tariff than it does today?
That's a good point. Yeah, everything is gonna cost a lot more. You know what I was gonna go back to, um, something we were talking about Apple in terms of organic growth and shadow adoption of, of a pc or in the case of a mac.
I mean, it will find a way, and I think, I suspect that might happen with AI in a certain sense. You know, it's always driven by software, you know, hardware is important, but that underlying use from the the user is, is, is just important. Yeah.
That, that's, that's interesting. Mike, with given, given the, uh, terrorists that are going to be in effect, does that kind of negate the, or, or kind of put in put a, a kibosh on the enthusiasm some of some folks when they look at their budgets? I mean, that's something we should probably take a look at, and I think it's probably gonna happen in some form.
I know. Steven, you wanna jump in here a little bit in terms of predictions for A IPC costs going up, down. What's your thought?
Well, with the CHIPS Act, I think there's a good chance that we might, uh, actually be manufacturing some of this stuff locally. I mean, uh, the news, uh, coming out of Apple is that they just, uh, produced their first, uh, US made, uh, processor, um, in, uh, TSMC, I think it is TSMC factory. Um, I, I think that we are going to see some homegrown ships, but of course, um, it's complicated as they say, because it's not just, uh, etching the chips, it's packaging, it's manufacturing, uh, final assembly, uh, distribution, all those things that matter in tariffs could get in the way of a lot of that because it is a globally interconnected supply chain.
So I'll say that I believe that we will probably be seeing, um, costs for literally everything go up in the face of tariffs, because that's what tariffs are. That's what they do, and that's what's gonna happen. All right.
I'm betting to be that PCs will be assembled in The Bahamas to get around the tariffs. That's, Hey, That happened a lot in the sixties and seventies when we had a big, uh, international tariff regime. There was a lot of outsourcing, uh, to the US Virgin Islands and Puerto Rico and places like that.
Interesting. Lisa, I wanna give you the last word on this. You know, guy and Steven talked about this a little bit, but is there a branding marketing issue around IPCs and the way we use the term and ca and do we need to kind of revisit this whole conversation?
I think so. I think a, as I mentioned earlier, I think from a clarity and a definition perspective, it needs to be that really clearly defined the future of study that John started this block up with, shows that a lot of organizations are really looking at IPCs to be more competitive. Well, what does that mean?
Um, competitive differentiation is incredibly important to every type of business. But how will an A IPC if I'm a, a retailer, help me get there? I think from a clarity perspective, the messaging needs to be refined.
The benefits need to be really clear so organizations understand, do I invest now to your point on the tariffs, or do I wait if I wait, my costs go up. But I think they, that the marketing folks, they talk about future proofing, and that's always one of those marketing terms that bothers me because it means something different to everybody, or it doesn't really mean anything. Um, what is, you know, future proofing what A IP Cs future proofing, what my business, how?
Um, so I think there's, there's a lot of, of wiggle room in an A IPC definition currently stayed and kind of nailed it with, with what should be done. So organizations can really make the the right investment decision as to whether they really need it right now or not. All right.
I'm gonna tell you where you can find future proofing. It's right here on Techstrong TV where you get the knowledge you need to make the right decisions in the future. There you go.
Alright, we'll be back in a minute. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey folks, we're back and we're gonna be talking about this bid that Elon Musk and a bunch of investors are making for open ai.
And geez, you just can't make this stuff up. It's right out of Robert Barron's and the Gilded Age. Lisa.
I mean, I don't think, at least from where I sit, I'm not sure that this is even a serious thing because last time I checked the company was worth more than the bid. And I don't think that they actually have to respond because they're not really structured like a typical company. But from your perspective, um, is this kind of outta hand or is this, you know, just silliness?
Where are we going with this thing? I, I think it's out of hand and silliness. It's Elon, when I heard it very early this morning, the news, I just thought, there he goes again.
And we were talking before we went live about the chaos that ensues when, when Elon opens his mouth and offers a bid. You know, the, I the irony in it is that he was one of the co-founders back in 2015 with Sam Altman. Um, Elon is is a top advisor to President Trump, which was something I never expected to see.
And I've followed Elon for a long time. But, and then of course, open AI with SoftBank and Oracle and Project Stargate, what they're doing there to invest in AI infrastructure in the States. Um, clearly Sam Altman didn't take it seriously with his re response, but I do vote for Sam Altman to buy X as he joked about.
I think that could make, bring, bring back the Twitter name. But I think, I think it's just, it, it is silly. I think it's Elon flexing once again.
And I, and I think from, I always think, man, what was his marketing People think it must, that must drag them crazy that they can't control the message. 'cause he's just gonna say whatever he wants. Um, now is, is X AI better than open A?
I don't use X AI personally, I use GR with a Q, but I think that it's, it's el ongoing rogue, and I think it's just to probably tie up things for open AI's next steps, which it wants to do. And we'll have to wait and see how much that affects what those next step plans are. Um, I think it's a bit of thud personally.
So I had so many thoughts rolling in my own head, and I'll tell you what those were, and then I put it, um, I put it out on social media to ask what other people think. But my first thought was, I'm not sure I like one person having control of any number of like all of the basically databases, like he already is in control of X. And then we have Sam in control of chat, GPTI would say, I don't want one person controlling all these systems because that's essentially such a huge amount of data that he has and what's he gonna do with it.
And also, it's another platform to essentially manipulate society in a way. I mean, you could, one, giving one person control of all these different platforms, that's a little scary. So secondly, I put this out on, um, social media though, just to see what people think.
You know, I put, Hey, he offered this much, um, what do you think? Um, why did you know, why did he put a bid? And so some of the, um, responses were, um, because it is the hottest tech, he believes he can run it better.
He enjoys limelight and positioning of power and money. And then somebody else put, um, to expand on that, um, they put essentially, you know, it was a very long paragraph, but essentially, um, because, um, it's worth, it could be worth trillions in the long run. And that resources in the end are more important than money in the first place.
And when you think of people of real power, while we're trying to just pay bills and enjoy life, they think in m pavillion terms, dynasties, um, somebody else put, um, uh, uh, all you have to do is, um, go watch the Netflix docu film on Cambridge Analytics and you'll understand what's going on. So I don't know if anybody's seen that. Uh, and, and then let's see, uh, because, um, Elon may not be entirely human joking, not joking, because ai, avatar hybrids are legitimate potential future.
And there are organization organizations deeper and darker than 99% of humans ever see and would ever believe. And there are things working under in Pandora's Bach that are broader and deeper than we know. Okay.
There are some of the answers that you have from, from my best, John, What are John, what are they saying in the Valley about all this? Because, um, you know, right from where, from where I sit, this is like, you know, do I like Andrew Carnegie better than John Rockefeller? I don't know.
They're all the same. Yeah, they're all, they're all despised out here as well as the rest of the country. Uh, you know, the one thing that I, when it always comes to Elon, there's always like an end game.
You know, there's, there's the short game and then there's the end game, and then there's a game that he hasn't even imagined yet in his adult brain. And, um, and he has taken, there was a legal action by Musk against open AI to force open AI to auction off a portion of his business. And I'm wondering, by making this bid as absurd as it may sound on the surface, whether he's trying to force or maybe elicit other types of bids or, or force open AI to consider other offers, or at least entertain the idea of an auction because they are moving towards a for-profit status.
Um, you're right, you mentioned earlier that the, uh, the amount they're offering is literally half of what OpenAI is valued at. So no, OpenAI is valued at about 160 billion, but there is a rumor that there will be another cash infusion, another round of funding that will elevate it to 260 billion. So, um, in, in a sense, I think he's, he's trying to muck with a company that he personally despises and a guy that he chooses his mortal enemy in a sense of Sam Altman.
I think this is all a lot of, a lot of Machiavellian twists and turns, but I also think there is some sort of end game to try to compromise open AI as a company. Yeah. If I can dive in on that one, I think that you, you know, you're, you're right there, John.
It's still early hours of us digesting this. And so, but to me, the thing that caught my eye, uh, let's be clear. Oh, Elon Musk is not bidding almost a hundred and, and his team and his alleged, uh, uh, I was gonna say co-conspirators, not exactly the right way to say it.
Um, his alleged consortium is not bidding for open ai, the makers of chat, PPT, let's be clear, this is a bid for the, a nonprofit organization that, that controls open AI rights, correct? Yes. But, and remember the valuation that you just talked about is the valuation of OpenAI, the for-profit company, and open AI's assets.
What Elon Musk is doing here, I think has nothing to do with taking over OpenAI. I know that, you know, you say Elon Musk and everybody just loses their stuff. What's happening, which I'm about to do, but please continue, feel free.
I'm just gonna say it 12 more times until your head explodes. Um, what's happening here is this is absolutely the actions of, of, you know, back to Mike, what Mike said at the beginning. This is robber barons fighting robber barons.
And what he's doing here is by offering this absurdly high, no, I mean, that's the thing. This is not a low ball offer. org kind of aspect by offering an insanely absurdly high amount for the nonprofit.
He has just set the bar that says that when the for-profit entity wants to split from the nonprofit or wants to go public, or wants to kind of cash in on this absurd valuation, what they're gonna have to do is they're gonna have to beat that amount to, they're gonna have to pay that amount to the nonprofit, because at that point, all the shareholders, everybody involved will say, wait a second, you know, you wanna split from the nonprofit and you wanna give them some money. Previously that some money might have been a billion dollars or something. Now that some money has to be over a hundred billion dollars, which means that OpenAI the company is going to basic, it's just Elon Musk, just force them to flush a hundred billion dollars down the toilet on nothing.
Or he's gonna swoop in and have some kind of really valuable minority or maybe even majority shareholder stake in that eventual public entity. And, and so this is pretty much, I don't wanna say a checkmate, this is a certainly a check on the chess board, and it has nothing to do with Elon Musk actually wanting to take over OpenAI. He's just forcing them to overpay.
I've been dying to jump in here, man. Not exactly dying. I'm just shaking my head.
So let me start with one thing. Elon Musk. Elon Musk.
Elon Musk. It's not Elon Musk derangement syndrome. Promise.
Is that, that like Beetlejuice, where were you going with that? Uhoh? Yeah, I guess so.
Look, there is no offer. Okay, open ai, profit, nonprofit, whoever, Sam Altman, nobody has seen an offer. And so this is another case, yet another 99 times out of a hundred, uh, uh, of Elon Musk saying some s**t and everybody taking it seriously.
If there's anyone in the universe whom you should pay attention to what they do, rather than what they say, it's that guy. I thought it was a different guy over and over and over and over again. He just said, now he just said some s**t and wound up buying Twitter at one time, he just put, posted a price when he was maxing and relaxing and chatting with who knows who, and you just posted a price publicly and he wound up having to pay for it didn't work out.
So every now and then, right, that happens. But he is just saying, and you know, the, the, the, the elephant in the room, the freaking like, I dunno, mammoth in the room that no one, none of the reporting is talking about is this is an employee of the US government. This is a presidential appointee in the office of digital services in the federal government.
Who is, I mean, you kind of alluded to that, Mike, in talking about, you know, oligarchs and stuff, right? His statements are a representative statement of the US government as well, because he is an officer, a compensated officer of the US government, not confirmed, all right, so a he's just saying whatever, and everybody's like, they're writing articles and they're examining, we're all doing this, we're examining it, we're looking at the strategy, the chess board and all that other sort of stuff. I'm just saying, he just said something and that's it.
It's great Marketing for himself, right? All the open ai. Yeah.
There, there's a little something I I I, I like this, like deconstruction of the strategy that tort puts the Open AI board and the funny place and all that other sort of stuff. So I'm not saying there's no motivation, there's no effect of him saying it, but really, honestly, that's all he is doing. Well know, you know, once again, there's nothing here.
Right? Right. In a sense, what he did was like the other guy, you know, who we, we've alluded to, it's a diversionary thing for a day or two.
We're gonna talk about this, then we'll forget about it, and we conveniently will overlook what's going on with Doge, which actually is the real story involving Musk. This is something he does, but he also wants to inflict some sort of damage and screw around. I, I was gonna use another word with, with open ai.
I mean, it's something he does. Larry Ellison would do the same thing. Remember Larry Ellison had a history of saying, I think I'm gonna buy this company, or I think I'm gonna do this, you know, instead everybody too.
But they didn't do it just thoughtfully just spitting out crap, Ola, it's crap, Ola, there's no intent behind. There's no offer. There's no offer here.
There's just a statement. Yeah. And we live in a time when people can say just random stuff and, um, and have it move markets.
So, But do you think he would've actually paid it if Sam Altman accepted the offer? Do you think he would've actually paid it? Bought it?
That's The question. He's, he's, he's forced to, essentially, other than the conflict of interest of working, of being a federal, uh, officer, he's forced to, just like with Twitter, okay, so he would be forced to just like he had to with Twitter, but just like with Twitter, he doesn't actually have this liquid cash and then this consortium of people that are supposedly gonna be buying it. But that being said, I think if, um, if the OpenAI, again, nonprofit wanted to accept this offer, I think there would be no shortage of funds and capital at this point to fund it and make it happen, because that would effectively give a, for $97 billion control of a 200 or $400 billion company.
And that's just a valuable commodity. Lisa Martin, is this the future of conversations between CEOs where they text to each other and then they share it with the press and you have, you know, one CEO calling another CEO allegedly a swindler. I mean, how crazy can this get Well with Elon?
I think it, I think that the level of crazy could definitely go up. I hope this is not the way that CEOs communicate. I think this, he's an outlier in that, an extreme.
Um, but I think executive communications would come in to most organizations and put guardrails around what the CEO is doing so that the organization doesn't get derailed itself, ultimately serving its customers and delivering the value that they expect. So I, I think the level of crazy, I think, uh, you know, we're probably scratching the surface with Elon. Um, it's a bit comical.
You, you mentioned the, the word swindler being used. I saw that this morning, and it's just, it's, it's silliness. Um, really what it is.
And to guy's point, there's no real offer. This is, this is fud, this is out there. He, maybe he's trying to slow open AI's plans to go for profit down, um, or provide a forcing function for the nonprofit that owns it.
But these communications shouldn't be happening at this level, um, for a healthy organization, in my opinion. Mm-hmm. John, is there room for a white knight in this conversation?
Because there's a lot of people who don't like any of the players involved, so is there part of Yeah. Well, Microsoft's invested, what, 14? I've lost track.
It's $14 billion into open ai. Um, I, I don't know. I mean, it's so early we went through the same conversation, right?
Although we did buy Twitter, I mean, for, for a long time, we dismissed that idea. Um, and there were White Knight that emerged during that, that were tended to be big, be big tech. My fear always has been, and I think the fear out here and everywhere is that if open AI were to be sold, it's the, the feeling is that given the climate now in terms of, uh, deregulation, in terms of m and a activity, that somebody in big tech is gonna end up owning it.
So we're gonna have AI in the hands of maybe three or four major, major monster tech companies. That's the, that's the long-term anxiety All. Well, here's my bet on it, is that we'll watch this drama play out for a few months, and then, um, hopefully cooler heads will eventually prevail, and we'll say, you know, we need some serious adult supervision, because clearly these folks are not, shouldn't be allowed to play with things that might go boom.
So I'm just thinking that, yeah, a lot of folks are gonna go, you know what? These guys are not the guys to trust in this situation, but we'll see how it all plays out. We'll be back in a minute.
All right, everybody, we're back and we're gonna talk about money again, but this time in the concept is called fin, which is the notion that somehow or other we're gonna programmatically put some controls in place to limit our cloud spending and other IT spending and keep that in track with our policies. Absolutely. Streaming is what I have in house back in the day.
I seem to remember when, you know, this was called how we run it, but Guy, what's your sense of, uh, is finops for real here? Because we're already seeing, for example, finops companies buying IT, service management companies, and we're also seeing it SM people just start putting in finops capabilities alongside what they already have. So do I need a finops platform?
Oh, I think you do. But is it an exclusively finops platform? I think that, that it was a really necessary area of, uh, cloud development because of shadow IT and cloud load and like, you know, all, all that sort of thing.
Um, and I think, uh, you have pointed out really well in a lot of venues, Mike, um, that Kubernetes also is this sort of enabling of, let's call it bloat waste over capacity, that sort of thing. All of these are cost and, uh, the, the very nature of the cloud and, and frankly of like, you know, DevOps and Kubernetes is to be able to be extremely elastic and responsive, um, and, uh, to, um, not sidestep exactly, but, but to be able to operate without a bunch of bean counters or, um, you know, uh, I frankly IT infrastructure people or whatever, kind of getting in your way so you can move fast, break things, blah, blah, blah. Okay.
So what arose out of that was a 'cause if, if we all remember the good grand old days was how, uh, cloud was gonna save you money. And then everybody started to realize they actually cloud cost more money and talking most about public cloud. And so as a thing, as a separate thing, finops a platform, a practice finops is more a practice than platforms, really.
Um, there's, there's a whole, you know, very successful, uh, uh, uh, consultancy industry, um, around controlling cloud costs in particular, and that that stretches out into containers and on-prem and all that other sort of thing. So, so all that is for the good that that's, that sort of shines a light on the whole issue, but in the end, and what, uh, these recent acquisitions, um, like, uh, uh, do it acquiring perfect scale, I think you just wrote about that yesterday or the other day. Um, these kinds of moves, um, to bring all of these operations under one umbrella and in particular to, not to stop saying it's just public cloud, but it's all of our infrastructure, all of our cloudified on demand, you know, scalable infrastructure that we need to, you know, provide the freedom to the developers and application managers to do what they need to do, but also enforce policies in a way so that they can do it quickly, but also not overdue or, you know, that all of this needs to be integrated together.
And so if one day we're not calling it talking about finops anymore, and it's just part of cloud ops, great if, uh, we'll still need finops experts, finops practitioners, some of them should be in the financial departments as well. So now I think, I think this is not only a good and welcome development, but you know, I, unusually for me, I don't see any problem with having this sort of marketing term of finops out there that shines a light on a really important issue that actually is what helps cloudification containerization, all of AI ization, all those things, you know, develop rapidly. What I found was interesting about that article when I read it was, um, when it said finops has, uh, been known to focus more on reducing costs, whereas they really should focus on increasing value.
And there's a little bit of difference what focus you come from, and that's why teaming up with a cloud ops team who's utilizing, um, that area, uh, what is helpful, coming together with two different teams, one focused on bringing the value. I think that's right percent on it. I, I would just dispute, uh, I I think that, um, cost control and sprawl and all those sort of things are much more the issue than value delivery.
I, I, I, I think shining a light on value delivery and getting the most out of what you got is, is correct because yeah, one overshadows the other, but I think the, the pre predominance, uh, the predominant focus really does need to be on cost and, and sprawl control. I think, I think cost and sprawl control is a, is is sort of the, the useful outcome from finops that allows this to take hold and allows companies to embrace it. Because it's, it's, it's a great, uh, sales message that says, we're gonna save you money, you know, we're gonna address the money that you're wasting.
But truly, I, I have to say, I really found this article incredible inspiring. Um, I, I love the, the, the author's perspective on this. I, I'm gonna echo what Amanda said.
You know, another thing a couple of you know, sentences down, he said it's about, um, you know, fostering a cost aware culture and creating accountability, which again, is something that those of us in it, we've not really had that. And I think that that actually is a, is a really great outcome as well. I don't know as much about this topic, but I will say that this article was really well written and, and really opened my eyes as to the possibility of what finops is.
Because again, I came at it, like you said, kind of thinking about it. Oh yeah, that's about, you know, keeping your AWS bill down. That's not what it is at all.
I'm gonna say bull dingy. Um, here's the thing, and this is the truth of the matter. IT people, we had capacity planning back in the day.
We had cost controls back in the day for everything on premise. And then the cloud came and we just basically abdicated responsibility for it. We threw it open to a bunch of developers who then showed up at a bar, like a bunch of drunken sailors and started consuming stuff and over provisioning stuff.
And everybody said, oh, well we can't get in that conversation because God forbid we slow them down with any troubling information like cost. So I think finops is a lovely little term that we've come up with that kind of circle back and maybe apply some supervision to this stuff. 'cause we are freaking out about the cloud pills.
But to sit here and say that finops is gonna be a a practice, I don't know. I'm not buying it. I think it's part of your job, it's your responsibility and it's gonna be a core feature into your ITSM platform into your DevOps platform.
And the days when we just let people consume things without any concern about cost or over, that's my Tuesday. So you're saying, Lisa, help Lisa help me attack Mike here. Finops as a practice.
Seriously, It's about, it's, It's been helpful. It's been helpful. It has been helpful.
I, I was just writing about this for TechTarget on the other week. It, what I, what I like about it as a practice is the cultural transformation that, that we're seeing going on within organizations who, with shadow IT are just spending money and suddenly it's out of control. Um, you know, getting the heads of departments together, marketing operations, sales services, you name it, and having them understand how they're using it, there's value in that.
The outcomes Steven talked about, the outcomes Amanda talked about, that's value. So maybe it's just a messaging kind of, um, kind of mix up their costs. Optimization versus value.
Well, that is a value to an organization. Um, I, I see that definitely. But I really see organizations embracing the cultural transformation, which is hard to do in order to deliver value to the end customer.
And that's what it's all about at the end of the day. Yeah. Let's, let's you wanna talk about the realities, Mike?
The realities today are the same as the realities of 20, 30 years ago, which is that the dev people hate working with the infrastructure people and the infrastructure people wish the dev people would leave them alone so that they could just run a great infrastructure. And what something like a finops does as a practice is it allows the infrastructure people to say to the dev people, just go do what you want. You don't ever have to talk to us because we are putting the policies in place that we are all mutually.
That was another great thing in that article, by the way, was talking about setting a common framework for understanding how resources should be used. So we have a common policy, everybody's bought in, you don't have to talk to us anymore. You can just go and do your stuff and have fun.
And, you know, the finops magic of tooling and all that other stuff will, will ensure the policies are put in place and you can do what you need to do. I'm not blaming the developers, they just walked into the situation and took advantage of it as they found it. So it's not really their fault.
I am saying it's the absence of leadership on the ING your IT executives that says, oh, now we need a little pin ops flag that we can wave so we can regain control of this thing. And that's kind of silly. Steven, I argue one point either way.
Well, I'll just say this. Uh, it sounds like what we're saying is that we need to foster a cost aware culture and create accountability, which is literally what our author Tatum Tonin said in this art. I Think we should accountability.
That's a key point. I just think we should take a little responsibility for the situation and not blame it on some magical thing that we weren't aware of and, and then wrap a buzzword around it. I think what I'm saying to folks is like, look, we're having this conversation and we need to have this conversation largely because you allowed this to happen.
That's all there is to It. All right, I'm gonna end it there. I guess I'm gonna get the last word on that one.
You sure guys? Yeah. We're not you, we're not.
We, we can't have my optimism finish the segment. That just doesn't work. Let's, let's stick with your dark feel of the world.
I, I, I am optimistic that this issue will get fixed. I'm just saying, guys, I don't think we're gonna be using this term for much longer. All right guys, everybody, thanks for sharing your insights today.
As always, spirited conversation, we always like to have those here in the Textron gang. We invite you all to stay tuned for all the rest of the content that's on Techstrong tv. It's an awesome lineup.
Once again, thank you all for participating and we'll see you next time. I'm Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively From Techstrong Research, this is Techstrong tv. Hey everyone, welcome back here to Techstrong tv.
You know, this next guest is a long time friend of mine in the security world, probably 20 years, maybe more. Uh, he's been also in the security business a long time. It's written for many, many different, uh, security magazine and sites, tech media sites, has his own tech media as well as working for a bunch of companies over the years.
My friend, let me introduce you to my friend Tony Bradley. Tony is currently is, uh, among other things, a senior contributor at Forbes. Uh, and as I mentioned, he does run his own, um, media business.
It's more than just a site called Tech Spec. Tony, welcome to Text Drug tv. Man, it's great to have you on.
Thank you, Alan. It's, uh, great, good to be on. We haven't, uh, we haven't, uh, chatted face to face in I was gonna a while gonna say it's been a minute.
It's been a minute. Good. Well, between Covid and RSA 'cause that's where we used to see each other more than anywhere CRSA or blackout or any of the, you know, usual security events.
I haven't been back, I haven't been back yet. Um, I was really looking forward to going this year, and then my son planned his, uh, wedding that week, so I will not be at RSA again. Well, that's what I had last year, my son's college graduation.
Yeah. But, um, I will be there for this year, hopefully, God willing, looking forward to it. Um, but anyway.
Well, I mentioned spective. Let's get that out there too, Tony, for people who want to kind of follow your musings views. Sure.
net. Um, I mean, it's a technology mostly it's, it's, it's a technology news website, but it's got a very strong cybersecurity leaning just because that is my background and that's what I tend to write about more often than not. Um, uh, but then, you know, like you mentioned, it's, it goes beyond the media outlet where, you know, I do a lot of, uh, you know, I work with a number of companies doing freelance, uh, you know, content and, and, and various uh, ways.
So, um, but you know, as you, as you introed me in the first place, I'm also a senior contributor for, for Forbes. Um, so that is, is one of my main outlets as well. Very cool.
Alright, with that out of the way, we've told them who Tony is. Tony, let's jump into what we want to discuss today. And that's, you know, look, it's all over the news.
News. The new administration comes in, Elon Musk and his, what's it, department of Government, efficiency, doge Dodge, whatever. Uh, yeah, Trying to just shake things up.
I think just, even just the name of that, you know, I, Oh, it's all Ian. There's it's tricks. It's allian and it, it just, it, it underscores that Musk and the, the guys that he's got working for him, they're their internet trolls.
Like, you know, this is the, this just, this is just internet trolling stuff. This is four chan stuff. This is, you know, I don't know.
I feel like they, like, I feel like they get off on just being trolls. Well, they are, and you know, in typical Musk's style, everything that he finds is a result of corruption, right? Where, you know, physician healed thyself.
But, um, you know, is the government the most efficient way of collecting and spending money? I don't think any government in the world is, is there a waste? Yeah, there's always some waste.
Would it be great to cut some of this waste? Yes. I think we all agree we'd love to see government cut some waste, but there's right ways and wrong ways of doing it.
And when we talk specifically on the cyber front of things, you, you can't, don't take this the wrong way, but you, you can't let everyone get polio because you're cutting the vaccines, which made, that's a whole nother story we could talk about. Um, But I mean, you gotta, you, you, you can't create cyber risk and violate cyber rules and regulations in the name of government efficiency that, Right? So my, you know, when, when I wrote, when I wrote this article for Forbes about the, you know, the cybersecurity concerns of what's going on, um, and, and, and, you know, even if I set aside the, the constitutional crisis, I actually, I can't, I can't set that aside.
They, they, they go hand in hand. Um, because I, I, I'm a, I'm a bit of an idealist, uh, when it comes to the structure of our government and, and, and the way us democracy works to the point where it's like, I, I respect that. Sometimes it doesn't go my way.
You know, like I didn't support w you know, it's like sometimes things don't go your way, and when they don't go your way, we still at least had a framework we had. There's checks and balances, there are things you can do. There are, you know, you know, there, there are ways to still, you know, limit that and, and would dissipate.
In this case, you've got these, the, you know, Musk coming in here with Doge and you have all these guys who are, you know, don't have security clearances, couldn't get security clearances. The only reason that they sort of have them is by executive Fiat, you know, because, you know, Trump says they have them, um, which, but they would never pass a security clearance. Like not even close Musk can't pass a security clearance.
Um, you know, a, a full one. So to, to allow them in. It's like, you know, as I, as I listed in the article, there are, there are, you can, you can look at what's going on and say, okay, it's probably violating hipaa, it's probably violating PCI, it's probably violating GLBA fsma the Privacy Act.
Now we're getting into, you know, because they've gotten into the Department of Education, now you're violating, uh, ferpa. Like we have all of these regulations in place to protect personal and financial data, and we have an entire cybersecurity industry built on selling solutions to do just that. So you can't then create a government agency again by executive Fiat, by the stroke of a pen.
Just say, Hey, I, I've created this agency and, and their job is to violate every, every law we have to get access to this data. And so coming back to where I'm an idealist, I respect that the election didn't go my way and that I don't agree with the party that controls the house or the Senate or the executive branch. But if you want to get around hipaa, if you want to get around fsma, if you want to get around the privacy Act, I follow the damn process.
Like there has to be, someone has to introduce legislation, there has to be discussion, there has to be a vote, and then fine sit, you know, put that in place. But there has to be some, some sort of controls that can't just be, you know, oh, well, we're just going to pretend those laws don't exist in this case. Um, and, and it also just, it, I, I know there are many people within the cybersecurity world who, who do support this administration and, and the party in power.
And I, I can't get over the sort of like hypocrisy and irony of someone supporting this and then going out to talk to prospects and customers and try to sell them solutions that will guard against data, data breaches and, and protect personal information. It's like, no, you're literally supporting the undermining of it. So, and, and from a federal perspective, it's like, how can you enforce these laws at this point?
Like if you're, if you're not willing, uh, if you're, if you, if you are violating them all yourself, then you've lost your standing to, to, to go after anyone else for violating them. So Tony, I look at this and the, and it, it falls into two camps for me. One, I think is the one you are talking about, where have they exceeded their authority, right?
'cause the fact of the matter is, as far as I know, there was no government legislative, uh, bill or mandate to even create something called DOGE, right? There is no legislative mandate or law or bill to do what they're doing, right? So if you're gonna play by the rule, right?
Our, our form of government is not truly a democracy. It's a republic. And, you know, one of the key pieces the founding fathers want was to prevent the tyranny of the majority protecting the rights of minority.
And, and so, and that's why in the Senate you have filibuster rules and you have the 60 votes and, and you have requirements. And the Congress holds the purse strings unfortunately, for whatever reason. Maybe the system's not reacting fast enough or whatever, but I think ultimately the legislative branch will have to become more involved.
Well, well, the courts may force that, and it'll be a question of do they obey the courts or not, but to keep the politics out of it for a little bit. Tony, there there's another aspect here, which is, and you hit on it briefly, which is the cybersecurity rules. These are nonpartisan, nonpolitical, you've gotta protect personally identifiable information.
You can't, you know, classify data that that's a longstanding, uh, in our government, a longstanding rules and regulations on who has access and what you can do with classified secret, top secret data, right? You can't hire 23-year-old kids off the street without background checks and give them potential access. And, and, you know, go ahead.
That to me is this is, yeah, This, This bad. Well, and, and you know, there's many stories out there, but I've seen reports that, you know, they were going in just connecting unencrypted USB drives and offloading data. And it's like, you know, I agree with you.
It's like, well, no, like again, if you want access to this, and if, if you want to analyze it for whatever, like, you know, let's, let's, let's take a step back and say that Doge was an actual agency, you know, created by an act of Congress and we gr granted them access. Great. There would be a process for that.
You still gotta follow the rules, Right? They, like, you still, there's still cybersecurity regs here. And, and to your point about some of our key friends in our discussion, a a friend of, mutual friend of both ours, the printer guy, if you know who I'm talking about, right?
He's, he, he put out a thing, well, what's the big deal? It's just payment systems. It's not like it's really classified.
And, you know, we've gotta stamp our corruption. Stamping our corruption is not carte blanche to do whatever the hell you want. Sorry, again, I come back to there, we, we, we, we, we, in theory, we have a representative government.
And, and those representatives need to have some sort of say, they need to be a part of this process. And while I, I I, when I look at it and I say, okay, well, is that just slowing things down for the sake of like, like if, if, if the people who control the house and the Senate are ultimately just going to rubber stamp it anyway, then, you know, or you know, it, it is just, it, it's become sort of pointless. But if you want to, if you, if you say, okay, look, we think there's fraud here, then the normal process is you investigate and you say, okay, here we've, we've, here's the fraud we found.
You present that there's some discussion and there's a decision about, okay, well what do we do about that? It's not just we've ripped it out. And, you know, before you can, even, before you can, even before you even know that we we're investigating the fraud, we've already like, taken the site down and, and done all, you know, I dunno, it, it's, it's, it's just like I said, I, I just want, I want the whole government involved and not just this small band of, uh, people Agreed, agreed.
But even with the whole government involved, we are a nation, and you know, this is a cliche, but we are a nation of laws and there are rules and regulations, especially around cyber and around sensitive information that we cannot take shortcuts for, whether it's in the name of stamping, our corruption or, or Jesus' name or anything else. You can't, you gotta follow these rules. They, they're there for a reason.
Well, and we, you know, in, in 2015, there was the, the, the hack of the Office of Personnel Management that was attributed to, I remember Chinese, Chinese threat actors. That was a huge deal. It was a huge deal that, you know, unauthorized people, you know, a nation state had access to this information.
So now we've got these, like, you know, whatever, you know, college dropouts or whatever, who with no security clearance, we have access. And, and that's actually another one of the things that is driving me crazy lately is the, oh, well, you know, we have to ban TikTok or nobody, we should use deep seek because of China. And, and I see a lot of people in the cybersecurity world who, and the thing is, I don't disagree.
Like I agree that China is an adversary and that China is a Asian state threat, uh, on some level. Like, I agree with that, but I'm like, that's not my main concern. You're a, you're asking me to be worried about a potential threat across the world while someone is in my house burning it down.
So like, I'm not worried about deep seek, I'm worried about X, you know, I'm worried about Facebook and meta. I'm worried about the, I'm worried about the, the, the, the, the United States based companies that are doing the exact same things that we are always worried about nation state adversaries and, and, and cyber criminals doing that. We're just allowing, I, I, I agree with you.
I, I, I mean, quite frankly, you're a hundred percent right. I, it's not that we're just allowing, are we worse than even some of these others, right? Because, and also, what message does it send where those rules apply to you?
Not to us. And, you know, and I'm, I'm doing it flouting that I'll somehow, I'll be, uh, pardoned or I have some immunity That goes into the political side that, again, that, that creates a whole, I mean, I've got a whole bunch of concerns on the, on the pol political side of that. We have, you know, again, a House and Senate who've basically abdicated their responsibility because they're just, you know, they're just not involving themselves lives All.
Mm-hmm. Um, it, there are reports that at least some of them it's because of, you know, they've received death threats and they don't have the, the the, you know, they don't wanna stand up to that. So they're just capitulating.
But if you Don't or they don't wanna be primaried, But I don't, I, I can't, I can't, I can't stand that, Alan, I can't stand it. No, it's, I know, but were left to do a job. I, Most of the people, Tony, most of the people who have principles or whatever here, they've already left the building.
Elvis has left the building. I, I, I guess because whenever someone's like, well, you're gonna gonna get primary, they're like, then get fricking primaried. Like, you're the job.
And they did already. And if doing your job means that you get elected, you get voted out, then get voted out. Because what's the point of staying?
Like if, why are, why are you staying there if you, if you're afraid to do your job? So we're almost, we're past our 15 minutes. Lemme tell you Bo on this a little bit.
I do think we are rapidly getting to the point where the courts are at least attempting to put the brakes on. A lot of this are, are saying, Hey, proper procedures, policies, regulations need to be followed. I think the next, and I don't want to get all dramatic and call it a constitutional crisis, but the next tipping point that we face is, does Doge and the rest of the executive branch follow or adhere to the court's orders?
Or did they attempt to ignore the court saying, we'll, just keep appealing it and by the time the appeals are heard, right, right. Possession's, not intent of the Law been told they'd been told to, you know, remove their access to the Treasury Department and delete all of the data they extracted. And it's like, well, are they gonna do that?
I think that's really the next stepping point. As I said, who knows? So crazy stuff, Tony.
Yes, I know you though, you'll keep writing about this and speaking out on it. net as well as in your articles on Forbes. You know what, we gotta keep fighting the good fight, my friend.
It's true. So glad to, glad, glad to, glad to fight with you. All righty.
net here on Tech Drunk tv. We're gonna take a break. We'll be back in a minute.
Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Bazaar today with Maggie Laird, who's president of the Pentaho Business Unit for Hitachi Ventera. And we're gonna be having a little chat about well data repatriation in the age of ai.
Maggie, welcome to show. Thank you for having me. Good to be here.
When I was much younger, people used to tell me, nothing good can happen when you move data. And yet here we are talking about moving data. So from your perspective, what is driving all this activity where folks are seem to be moving, um, workloads and data, and not just from the cloud back to on-premise, but sometimes the other way as well.
Um, I think there's more data moving now than I can remember in my entire years of doing this. Yeah, no, it's certainly an exciting time for data. I think gen AI have brought the core data management challenges to the front fold.
Right now, from my perspective, what we're seeing with our customers is, is the gen AI adoption experimentation, right? Companies are trying to figure out the right spot for the data, right? So, so things are moving around.
Um, some of it's coming on-prem. They want to bring the data, bring AI to the data, right? And be able to control it in a very, um, measured way, right?
And then other companies are, are try, once they know what they need, they're putting in the cloud and run and operating it. So it's, it's really this, uh, from my perspective, some experimentation, um, around how to most effectively and economically, um, take advantage of the VA opportunity that is in front of us. So a lot of folks out there trying to figure out what, what fits.
Some of this also feels like to me, to your point, they're building the first rev of the AI models in the cloud because that's cost effective. But when it comes to deployment, uh, and the inference engines, that needs to be either on premise somewhere or even at the edge. And now I've gotta take all the data that I use to create the model and get it out to the inference engine.
So is that part of this conversation? I think absolutely. So run, operate is what you're talking about, the AI ops.
Um, so once we're ready, once we know what we're doing, once we're convinced of the value, once we know the quality, right? One, once all of that is known, um, how do we do that at scale, right? And what does that scale mean, right?
And I think that's where the cost equation is coming in. Um, being able to be predictable around that cost. And for some companies that are running are gonna be running a lot of volumes through this.
That's on-prem control, visibility, predictability, um, again, is, is is coming to the forefront and being able to really wanna have those guardrails and understand, um, how, how it's gonna work in a very controlled environment. Um, I think you're absolutely right. Aren't we using traditional kind of batch oriented processes to move that data?
Or are we shifting to more of these streaming platforms? And it seems to me a lot of this conversation is just trying to make sure the right data's in the right place at the right time. Yeah, absolutely.
That's the name of the game. So I think it's both, right? We're seeing real time streaming data come in, we're seeing kind of the data at rest as well, because to unlock the value of, of a lot of this, you need all of that kind of moving.
Um, so, so then it, it's about the core elements of data management. Do I have the right data? Right?
And we don't need to take everything, right? So making sure that that right data, um, that has the right quality to that, I think that's where folks are learning a lot about the quality of their data because they put it in here and they're getting outcomes they didn't anticipate that doesn't look right and they're having to go back into the core data itself to say, Hey, did we bring the right data in because this isn't, you know, what we were expecting? So that, that real inspection of, of that source data again, is, is, is becoming real.
So again, what did we bring in? What is the quality of it? Um, do we understand it?
And, and again, do we trust it to be ultimately making decisions now? And it's, you know, at a, at a much different, um, um, scale than before. We have a tendency to be critical of the AI models 'cause they will hallucinate.
But how much do you think the real core issue is just that the quality of the data that we're exposing to the models is somewhat flawed. And, um, you know, issues that we've kind of sort of known about for decades are coming home the roost. That's a big part of it.
Um, that's what we hear from our customers who have maybe jumped farther fast to, to try to get started to have a proof of value. Um, and then they get caught back into the core challenge of data management and then they've gotta go back and start again because again, they, um, you know, been able to bubble gum and bandaid their way. Some companies have around that, these core data challenges.
But AI is exposing that risk. There is too much risk from not having, um, the quality right and the right data at the beginning of the process. So it doesn't, it, it, it does become a roadblock to production, right?
Um, you can learn some things with some sample data, right? And you can manually clean some of this in a, in a, in a very experimental way. But when it's time to go big, right?
And to put this into production, you've gotta have, you know, that scalable, um, an underlying quality of that core data, um, you know, understanding that and, and ready to go. Is there a greater appreciation for data management? And we've been talking about this now for years and years and years, but I felt it was always around the structured data and the unstructured and semi-structured data we kinda overlooked a little bit.
Let's say very few people would get a good housekeeping seal of approval for the way they manage that data. Um, so is all of this bringing, you know, a focus back on the fundamentals of data management? Yeah, no, I think that's exactly what this is bringing to the, the forefront.
There's more of a burning platform, right? It's always been a good idea to have a good quality data, right? And to, to maintain it well in a cost efficient way.
That's good hygiene. But you know, today's world, it's, it's actually required to be able to do, um, the innovation that folks wanna do on, on that data. So, so it's, it's back to reality, back to the basics, get it right, do the work, um, because the work's gonna be exposed if it's not, um, if it's not done in the right way and in a way that can be, can be scalable.
So I think all those, all those cheap data officers that, you know, getting an analytic, getting more of an AI remit now, um, it does kind of go back to the core. Um, and so, so again, it, it's, it's a good, if you, if you didn't take the steps at the beginning of the process to, to get it right now is the time, but the key messages are not gonna go very fa far. You may go fast, but you're not gonna go far until you, you know, isolate and really do the work at the foundation.
And I think that's, you know, where Penta is really focused is helping companies get that foundation, right? Because you gotta, you gotta deal with it now before you are able to take full advantage of, of the innovation off the backs of ai. You know, I was just thinking about this, but back in the day, the data more often than not was managed by somebody who we generally referred to as the storage administrator or something who was an administrator.
And now every time I turn around, um, there are data engineers that people want. So has the nature of the profession changed and what's required? Because last time I checked anybody who was called an engineer costs a lot more than anybody called an administrator.
Yeah. I mean, we're seeing, um, you know, certainly the, the expansion of the need to have higher level data skills for sure, right? And also some of these roles are starting to blend inside of the, the IT organization as well.
And then Mikey didn't even mention the, the AgTech workforce that may be coming online as well. So, so here we are, and you, you kind of step back and you look at how this will be managed, right? And then who needs to manage and what skillset they would need and really what, you know, they're, we're, we're blending a lot of, um, automation inside of, of, of these skills as well.
So, so I absolutely think that under that, a deeper understanding of this, of the engineering of the data is required. Um, but also again, what can we look to and how can we make that data as most prepared for, you know, again, Angen workforce to be able to help and assist, um, ultimately in the, the management of all this data moving forward. And so to your point then, can we expect to be using AI to manage the data that we need to train and build the ai?
Yeah, I think that's where we, where at least we see it headed, right? Um, it's gonna, we've gotta take the right steps to get there. Um, but it really is infusing AI into these core data data processes to make them more efficient.
Um, you know, you, again, we gotta step through it with the right guardrails to understand how that's happening and keep those humans in the loop as, as we begin the journey. But absolutely having, um, those automated ways to build brag pipelines, right? How to, to do some of these things that, again, took a very sophisticated, you know, skill set to do, you know, again, this is kind of the work here at pental is how do we get that into more of a data citizen world to be able to do more?
Um, you know, with, with all that you have again, um, in a, in a user in a way that's very, um, can brief the outcomes but doesn't require all that, um, you know, all those advanced skill sets that, you know, that's where the, that's where the automation and the AI comes in. And, and, and then you get to get the results a lot faster. Is all this gonna lead to some need for increased transparency into what data was used to train what model and what was used to where to run it in a way that is much deeper and maybe more profound than we're used to?
Yeah, I think absolutely. And you, you can see this with the AI regulations popping up, right? It really is about transparency, transparency.
Um, and so, so yeah, so companies are, you know, honestly having to happen to pay attention in terms of how, how they build, um, you know, what are those regulations coming, coming through to make sure that, again, they're, they're building the right hooks into the processes so that they can see, um, the data that's, that's coming in. Um, what it was there to do. Was there any data that was injected in there that shouldn't be in there?
So again, companies are gonna, if they don't already have, have tools, um, and systems like data catalogs that help to provide guardrails, to provide visibility. 'cause ultimately, if you've got a regulation around something and you wanna be compliant, you've gotta be able to produce, um, the report or the ballot, the justification that says, this is where we're getting that. So, um, companies need to be mindful of that as they are bringing, especially as they're bringing things into production.
Did they, are they setting this up, this right this up for that transparency that ultimately, um, even if the regulators aren't out there asking for it, I guarantee that the business users are gonna wanna know where did this come from? Are the C-level executives more conscious of these issues than they have been in the past? Or I think they tended to view this as some sort of, you know, lower level IT issue.
But is do they understand now the value of the data and exactly the use cases for it and how it kind of drives a process? Is the conversation getting elevated? Yeah, Absolutely.
I'd say, I'd say C-suite and board level as well. I think that's where, um, it is this kind of renaissance room for, for data. Um, you know, having ai, having CEOs talk about AI processes, I mean, who would've thought about that 10 years ago, right?
Um, and we, there is, you know, when I'm out there meeting with, with our customers leadership team that, that they are fluent, um, on the topics right now, the details, but they're asking the questions, right? And they understand that this, this is, you know, a source of risk, it's a source of innovation, you know, and so tho from, from those two pieces, then as they start to drill down and ask their organizations for, you know, plans and, and, um, you know, and, and proof of concepts and, and really point of views and governance, it, it's, um, it's, it's great to see from the data world, this elevation and it, it matters. Like this is a, this is a big deal and it's, it's very core strategically to company's strategy, right?
Um, as they move forward. If you don't have AI in a strategy, I think your board's gonna be asking you why. And that's a very different situation than we were in three, five years ago.
As part of that conversation, do you think that data management and data security is gonna converge more than it has in the past? And there'll be more focus on how to management of data in the secure fashion? Because I think those two things have been somewhat orthogonal for many years.
Yeah, exactly. I mean, depending on the architecture of where the data was sitting and who was controlling it, right? That we are seeing a lot of that merge, right?
And the access, the access to the data, right? And the secure security of that access. Those two things are, you know, front and center because, you know, I think, uh, in our consumer lives, we're all starting to realize, you know, when you are inter interacting with these models, you're, you're giving, you're getting something, but you're giving up something as well.
So the data exchange, um, around that, you bring that into the enterprise environment, you've gotta be very, very careful about what you're giving to whom, and then how that's being secured in your environment, and then what, what are the open doors that you have out? So absolutely, I think the data security, privacy, access and control, it's, it is a convergence because it all has to be solved in order to, um, you know, kind of bring the right outcome at the right risk level to the business. So as you look at organizations that you work with, what are they, the ones that are getting it, what are they doing right, that others are not then kind of, you know, that you wish other folks would kind of crib.
Yeah, yeah, we're definitely seeing some best practices out there. Um, I think companies that are taking a strategic approach, uh, and really thinking through, they, they're not gonna know everything, but they, they've got a strategy behind their, their architecture, right? They've, they understand they're likely gonna be in a, a hybrid world, but then they ask the questions, what they get down to the workload level, right?
And they start to really plan around what, what needs to be where for what reason? So with the, the cl, the more detail you can get into, you know, where does this data need to be to support the workloads? Then you can start to architect, you know, the right environment around your data with strategy in mind, but also cost in mind.
I think this is just one that is a red flag right now for a lot of people as they're starting to get their bills, you know, from their cloud providers or, you know, maybe even, you know, on the other side, they, they're examining their costs all the time. This, the cost piece is really real. So bringing the economics into the strategy, you know, to the workload.
Um, and then also those folks that can look at their data and, and make sure they're being really optimized around the estate. 'cause this, again, it data is exploding. You mentioned the un un inter unstructured to the scene, right?
Okay, now, now we're really exploding. You gotta be smart about what you're maintaining. You don't need 50 copies of that same file, right?
So I think companies that can take that big picture, bring it down to the details, and then start to make, um, you know, the decisions from, from that lens are the ones that, you know, will wi we'll win our, are kind of winning right now. You, when folks, you heard it here, they say, Dave is the new oil, but what does it matter how much oil you have if you can't manage and process it? So there we are.
Maggie, thanks for being on the show. Right. Thanks, Mike.
All right. And thank you all for watching the latest episode of the Textron AI series. You can catch this episode and others on our website.
We, we'd like you to check them all out. Until then, we'll see you next day. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers network. Hi everyone.
Welcome to another episode of DevOps Unbound. You know, uh, we were reminded by our producers right before going live on the show that the very first DevOps Unbound was in August of 2020. So we have been doing this now, going on four years, two months we're, we're into our fifth year of DevOps Unbound.
And that to me is just mind boggling. You know, it was, I don't want to take too much time away from what we want to talk about today, but DevOps Unbound was originally the brainchild of, at the time, the CEO of T Tricentis. My friend, Sandeep, Ari and myself, we brought Mitchell in very early, and at the time it was the Tricentis CMO, Brent, and I forgot Brent's last name.
And we, we concepted out this idea of doing a biweekly video podcast series that would explore all aspects of DevOps. And even though Tricentis, and this was point of years ago, right? Tricentis obviously very focused on continuous testing and testing.
The Tricentis folks thought it was very important that we explored the full spectrum of DevOps. And over that time, we certainly have, and not only that, but we've stayed current as New forces. And, you know, new technologies came into the DevOps space, right?
We're gonna be talking about one of them today, ai, but, you know, I don't want to say attaboys or Pats on the back, but man, four plus years. Rodney, congratulations to our Tech strong team and our Tricentis partners who go produce this. A special, special shout out, Jody, Ashley, and Ly nor will never get on camera, and I'm not gonna force them to get on camera now, but these two gals, you know, week in, week out, month in, months out, they, they pick the, the topics they source the guests, they get the abstracts time, they, they make the trains run on time here.
So shout out to Jody and Lanier for all, all of their work over this time. Let us now though jump into today's show. Today we're gonna be talking about AI governance, very timely topic and DevOps testing and everything else.
Uh, before we jump into it though, let me introduce you to our amazing panel. First of all, she's a frequent guest on Textron events. She's a friend of Techstrong, as a matter of fact, she's in the tech strong.
Actually, two of our folks here are in the Techron gang, but she is the CEO of Deploy hub. And, um, also an open source board member extraordinaire. Tracy Reagan.
Hey, Tracy, how are you? I'm doing great, Alan. How are you today?
It's great to be on this conversation. You know, I'm always, you know, ragged about ai, so I'm glad that you invited me to this one on this call. I hope that we really kinda dig into the technical standards, because that's the area of interest I have, because if we have technical standards and potentially we can start building those standards into our DevOps platform, and I say that because I know that we, you know, we're, we need to build security into DevOps platforms, and we have this on our tail building some sort of transparency and accountability into the DevOps pipeline for, uh, for ai.
So a huge new area. It's great to be on this call Joining Chasey and I from Tricentis. He's, he's been on a few times before, over the last four and a half years.
Martin Klaus. Hey, Martin, how are you? Hey, Alan.
I'm doing well. Thanks for having me on the call again, appreciate it. Uh, and it was great to see you in person a few months ago.
Um, yeah, so I am responsible for, uh, customer engineering at Tricentis. I've had multiple roles including product marketing, product management, and one of the things I get to do in my, in my role is to actually work with customers who are, um, defining their own AI strategy. And so, I, I'm involved in a lot of conversations where customers are trying to figure out how, how do I introduce AI in my organization?
How do I make sure it's safe, it's secure that the data stays in our data center and doesn't get leaked, uh, out on the internet. Uh, and also how do we test AI technologies, uh, so that they're safe to be used in our own environment. And so that's a really fascinating, uh, conversation to have with customers of different vertical industries and different segments, because they each have slightly different requirements, but they also, together all looking for the same thing.
So I'm looking forward to the conversation today and talk about regulations and governance. Fantastic. Thank you, Martin.
Um, next, she's also a Text Strong gang member and frequent text strong, uh, event guest, our own Hope Lynch. Hey, hope, how are you? Hi, Alan.
Uh, so happy to be on today. And funny enough, Tracy and I had a conversation recently where we started digging into, uh, AI and some of, uh, what we saw as the issue. So I'm so happy to be here today to talk about governance because it's, it's a critical topic.
It's great to be able to elaborate on it for a lot of people. Absolutely. Thanks, hope, and it's great to have you here.
Thank you. Next, well, actually last, but certainly not least, he's my co-host all for every single DevOps Unbound episode we've ever done. He's also the CTO here Ad Techstrong, as well as VP analyst for DevOps at the Futur Group.
Mitch Ashley. Hey, Mitchell, how are you? I'm doing real well.
It's a, it's an interesting time to address this. Dora just came out with a report and kind of put the pin on the AI donkey saying that's causing us to be not as efficient, which I don't believe that's really happening. But, you know, so getting into governance, we are trying to figure out ai, so it's a good time to be talking about governance, technical standards, regulatory, how do we do this, right?
So, so folks, look, it's been, I think about two years now, right? Since Chad GPT, just about two years since Chad GPT burst on the scene, I think it was November or two years ago. And, um, and it's sucked the oxygen out of the air of every conversation we've had on sids, just about it seems we're always discussing it, and we've seen the gamut of this is gonna be the greatest gift to mankind ever.
Right? I'm reminded of that old movie where they have the, the book to serve how to, how to serve, or how to serve man. Mm-hmm.
And it's a recipe, um, verse versus, you know, the, we must put the brakes on AI and stop it because it'll be the death of us all AI will fight that's imperfect. Something out of a Star Trek ger kind of episode, right? And, and seek to discharge humankind.
Um, I'm a firm believer that progress stops for nomad. And, and I think that's certainly been the case with ai. It has moved ahead, full speed ahead, damn the torpedoes.
However, in typical fashion, we have seen some governments, many in the US unfortunately, but some governments have started to try to put some governance. That's what governments do. And governance, um, you know, around the use of ai and some private industry, public consortiums are trying to establish rules of, you know, what's ethical, what's right, what's not, right?
Where does it tread on humans and human rights? Where does it help? You know, what, what's the right, what's, what's wrong?
And right here to do. Obviously, some things are clearly wrong, right? I mean, using it to, for mal, you know, my living mal, I always mispronounce that word.
Using it for bad purposes, right? Is never a good thing. These deep fakes, and we're seeing it around election season now, you know, prevalent use, no one thinks that's the right use for it, but there are right and wrong.
Um, Tracy Hope, I know you guys, both guys both have strong feelings on this hope. I'm gonna let you go first, if you don't mind. Okay.
What do you think? I think, uh, as far as governance, one of one, one thing that comes to mind, as you were mentioning, um, you know, the eu, they have the EU AI Act so that they can have comprehensive enforceable standards. There is work, I think, also happening in Canada.
Australia, they're sort of looking to see what's happening, uh, in the eu, but in the US I think it's gonna take a little longer. But I do also think if there is a company that can say that they are taking these steps to have critical oversight governance, so that, um, you know, it's not a black box, maybe it's explainable, they can ensure that there's no bias. Uh, there'd be a little bit of a first mover advantage there.
I know that, uh, some financial organizations, I think Capital One is one that is taking steps in that direction, but there is a long, long way to go, uh, to get AI governance across industries and to be something that I think is pretty commonplace. I thoughts, I, I wanna point out that there, there is work being done by the US government as well, have the Yes, true. True.
We had the Algorithmic and Accountability Act passed last year. That's right. And they, and they kind of addressed many of the same things that the, you know, the EU is trying to address, which is this idea of accountability, really.
Mm-hmm. Um, you know, uh, particularly around what, and all of these go, all of this governance is really just around high risk AI applications. Mm-hmm.
You know, surveillance, um, hopefully medical and warfare. Mm-hmm. Uh, but we, the, the US is, is making some progress, but I do feel like a lot of the governance has been turned over to the, um, European Union, uh, ever since the GDPR we're still, like, you know, they're doing data stuff, so we don't have to, but we, but the US government is still, they're looking at it that that bill was passed, and, you know, it says, Hey, you've gotta make sure that you're developing, uh, fairness and, and, you know, minimizing bias and promoting transparency and mitigating any kind of discriminatory, uh, discriminatory outcomes.
Mm-hmm. Um, you know, all of this, when I think about it, and it was kind of morbid, but I think about the opening scene of robocop, Right? In Detroit, And recently there was this insane article that came across and, um, tech on text, uh, crunch about Silicon Valley having a discussion of AI weapons should be allowed to kill people.
Oh, wow. Okay. You know, it's like, duh.
No. Well, that is, I think that's the first lo of robotics, right? Yes.
Mm-hmm. Yeah. Asmas last asmas lot of robotics.
Mm-hmm. And that's what that scene where from the robocop was, right? The, the robot goes and, you know, slaughters the entire board.
Mm-hmm. So, uh, you know, I'm sorry. We have why we have, well, we have governance, um, and it's only around these, these high risk systems.
I feel like we have a long way to go to start trickling it down to all systems that are being written and being able to take these technical standards that like NIST is working on, and apply them through the DevOps pipeline to start actually working to make sure that they are transparent and that some of these tools now can be applied, uh, to the process mm-hmm. Opening, I get it. Of, uh, of Terminator one too, by the way, crushing the skulls of humans.
But Terminator robots, um, sorry, Martin, I was just gonna jump in and, and say to me, it's fascinating when something comes along that's akin to security, it's akin to data that gets this governance, and how do we do it properly so that it doesn't escape from the lab or escape from the application data doesn't leak out, um, or in this case, do harm. I mean, you know, other software could do harm too. Algorithms could as well, you can argue whether social media does that, but AI has really jumped to the top of the list of what are we gonna do?
What do we have to do to, to secure this? And also make sure it's not used for nefarious purposes. So, Yeah, sorry.
I think it's interesting that, that you see folks like Sam Alman or even Elon Musk, uh, even asking governments to step in and help create some rules or guardrails, because to see the potential of where this technology can go, I'm not sure we're quite at the turn level yet, or robocop, what have you, but because it's going to be an evolution, uh, but the evolution is happening really, really fast. And I think we're already a little bit on the back footing, uh, with, uh, some regulations as it relates to use cases outside of business. Uh, for example, you know, uh, kids and school using AI systems to do the homework for them, uh, which, you know, now puts education systems at, you know, the back footing in terms of like, how do we deal with the situation when we require essays to be written as part of like entrance examination, entrance requirements for universities.
And now anybody can just generate an essay in the voice of Ryan Gosling, of whoever, uh, you wanted to in imitate and, and sprinkle in some grammar mistakes and punctuation to make it appear as if it was original authentic work. And so that's just one example of where we're thinking completely new uncharted territory because, uh, we don't know yet know how this technology can be used and applied in some cases. I'm thinking, especially in the business context and the kinds of customers that I'm talking to, um, the, what I'm hearing is that there's definitely a need for transparency.
And I think that's one thing that we could sort of check out very easily, because companies are asking for where is the data gonna be? What is being processed? What happens in transmission?
What about encryption? Um, who else did the results? Who wants to, you know, the models, what models are you using?
And then how do I customize it and make it my own? Because I do not want my data to get leaked out on, on tele at all. But it's a very broad field, and I think the way, um, for example, the European Union and or, or the House White House has also been proposing is a good one to say.
Let's think about this from a a point of view of, of risk. What is unacceptable risk? As you mentioned, Teresa's surveillance, um, or, uh, protected groups, uh, in, in society and other things that, uh, or medical, uh, applications.
There may be areas of unacceptable risk where, you know, we, we need to actually have some laws in place to, uh, to control those things. And then you work your way down in terms of high risk, low risk, and other use cases where, you know, uh, it's, it's a less of an issue, but this is a extremely complicated, important topic that affects all aspects of, of life. I, I, I don't necessarily disagree, but you are talking to someone who's from the generation of no, no calculators allowed in the school test, right?
I, how many did, did you, were you allowed to bring calculators into your test? No, no, no, no. But kids today, they bring scientific calculators in.
They no longer have to worry about doing those equations and figuring pie and all of that. It's all there for 'em. I think we're gonna come to the same thing.
I, I think, and call me radical, but I, I think when we get to new technologies like this, our, our part of our makeup is to think, go slow. Go slow. This could have repercussions we haven't thought through.
And we know, quite frankly, that that never works, people, right? If you outlaw guns only, guns only outlaws have guns, people are, they're still gonna be a segment of the market that's gonna go as fast as they can. Um, I think almost these governance breaks, if you will, these governors on the use of these technologies is to give our society a chance to catch up, a chance to get acclimated, a chance to get comfortable with what this, what these technologies can do for us.
And I think if we recognize that, we could look at them in a whole new light. But I also think it begs another question of how do you test for AI governance? Right?
I mean, Lauren, I'll throw it at you. You're, you're ous, you're the worldwide leaders. How do you test for AI governance?
How, how would you, you know, who's, who's minding the, who's watching the watchers here? Yeah, I don't think necessarily that it's possible to test for governance when you need to be able to, uh, it's more about transparency and really sort of, you know, like in the case of security, right? Like companies are used to, you know, expose and report and, and, uh, sort of showcase, uh, what sort of, uh, security policies and governance they are implementing the products.
And, uh, and we have standards around that. If you look at SOC two, and if you look at many different encryption standards, um, I, I think on the security side, we have gone of, uh, have come a long way already. I think that could be analogous to AI as well, to some extent.
Um, but the thing that I see with our customers that, that we speak with is that like, how do we effectively test an AI system that gives you reliable results, um, uh, in addition to how it works at, you know, uh, is it safe to use, right? So is, is the outcome useful and applicable, uh, and safe to use as well? Is it technology safe to use as well?
That's where I think we're in also new territory, because if, um, AI models are passed the Turing test then, and it's a knowledge system, an expert system that, you know, uh, can involve with time, then it's going to be much more difficult to, you know, come up with prompts or tests and parameters and say, yes, today the answer I got back was acceptable. But what about next week, next month when the now system has evolved and now it has been enriched with new information or with new, uh, you know, adaptations or waitings learnings that will, will not yield a different result. And I think that's a challenge with testing that it's no longer a point in time activity.
You have to almost like have an ongoing monitoring system in place, um, but you also don't know what you don't know and what you should be testing for that could be exposed through some sort of loophole. And I think that's what some companies are finding out the hard way. Like if you look at some of the, you know, Canada examples, for example, where it gave wrong responses, now there's a lawsuit and so forth.
Um, and that's the challenge I think with testing ai. What we do internally is, uh, we're trying to sort of adopt this monitoring model, uh, where we are going, uh, on a regular basis, benchmark test, validate, um, and have sort of a, a red team approach as well to say like, how can we expose, um, the models in a way that, um, the results we're getting are no longer in line with what we expecting to do. Um, unless there's a new way to, uh, figure out, you know, testing of not the testing models, uh, I think, you know, that's going to be the approach that a lot of people will need, need to take as well.
A couple of things I would like to, uh, insert here. For anyone who's listening and is trying to, I guess, wrap their heads around, how would I start to do these things? There are tools out there, and you still have to know what you're doing, but you could look at, um, uh, Q flow, ML flow, um, they help, they can help streamline building, deploying, managing your machine learning models, actually at scale, um, open source tooling.
So, uh, it definitely, you know, there's always a learning curve for these things, but if you're looking for some tools, uh, that can help you get started and figure out what you should do, um, those are two pretty good ones I think that folks can use. Then I wanna add too, on this topic, um, there's, there's, there's two levels here. We have testing and we have compliance.
So if we look at what we've done through, you know, over the last five years in security, we have done everything from adding signatures to, um, repo scans to things like open SSF scorecard that looks and determines how safe software potentially, um, could be. I really believe that these types of tools will also be created for looking in, uh, how compliant AI software is. Now the problem with compliance is that the data is often fragmented, and maybe you can look at a GI repo for one particular component to see, uh, how, how compliant that component is, but it is a first step.
Compliance is a, it will be, it is important today in security in software, and it will be important in securing and making sure AI software is safe. So while testing is important, understanding the compliance levels of the code that's coming across the supply chain is not gonna change. We're just gonna have different types of tooling to make sure that the, you know, that it's, that the model is fair.
For example, how do we scan for that? Not sure. I think IBM has something called like IBM 360 that, that does some kind of fairness check.
So as, uh, you know, hope Point pointed out, we do have tools out there, and that's why the technical standards become more interesting, because if we can define what those technical standards are, we can also define the compliance levels that we need to achieve. And while we have seen a lot of these governance docs, um, from NIST to the eu, uh, talk about some of the basic pieces, we still haven't seen a really clear roadmap for what is compliant, and we haven't done that for, for code in general. So maybe we'll get there.
We're trying, but we have to look at the compliance question and how do we track and report compliance? So the companies who are writing software and consuming these, uh, large language models have a way to judge how safe they are. You know, In some ways this is, you know, there's compliance against standards.
I you have to have something to test against, right? Which I think is lar largely what we're saying, and there's two forms of it. One is IEE and NIST and, and, and regulatory types of definitions of what those standards are, what what you're testing against.
Oftentimes though, compliance isn't testing against someone else's standard, it's testing against your own standard. So a lot of compliance frameworks are all about what is your policy for, for this part of security. Like if you go through a web trust compliance process, it's all about here's what our policies are to protect data, to secure this process to the handling of customer information, whatever it might be.
It doesn't tell you what the process should be. You have to define your own. Then the compliance is, we have validated that we, we have systems and processes in place to ensure that we follow those processes.
And if we are in fact following them, I, my, I have a sense that this is kind of where we're going. There'll be some things that will help guide us, um, and getting some insights to, to what we should be testing against. I, I almost think we're living in this world because it's so wide open of what you could do with AI that organizations are gonna have to publish what their, kinda like their privacy policy is or what their, their, uh, uh, online community behavior policies are.
Same thing for around ai, and then do they in fact meet those? Because otherwise the requirements could be so vast, I'm not sure you could really test against everything and really know whether is this a safe system, this a safe ai. Yeah, I think Mitch, that's a great point, and sorry, um, Joe, You go Martin.
I was gonna add one more thing. What I'm seeing already is that, um, this is not a simple question or answer already, and it's going to get even harder to answer because, um, it's going to be a more of a blended approach as well. Like right now, I think oftentimes it's pretty obvious when you're interacting with an AI chat bot on somebody's website, because that's an easy way to have some sort of customer facing interaction.
But where, uh, it's much harder to see where AI is used in process is when you have like a composite blended service where AI tools are going to be part of the outcome. And so you can see this in art, you can see this in, in, in creative, um, uh, disciplines. Uh, you can see this even like in, you know, from a business standpoint where, you know, or, you know, we were joking about the, the after for this topic was, you know, run through an L lab to say like, how, how can we clean this up and bring it down to 120 words or something like that, right?
So in those situations where AI is used as a tool, uh, uh, as part of a larger workflow, then, you know, how can you know that level of transparency, you know, be sort of transported to the, to the end user as well? Like, how do I know that a piece of artwork that I'm purchasing as an example, I'm not the a a deal at all. I'm just bring as a theoretical example, how do I know this is original work?
Um, or it was used, or AI was used as a tool in the creation of, of the artwork or in an email or whatever, what have you. I, I think that's where right now the world is moving where AI service are more, uh, in assistant role, an agent role to basically assist with the creation of, of new work in a much more productive way. Um, and then the, the, the notion of compliance and governance and transparency is going to be even harder to, uh, to say like, do we need to put a label on anything that, you know, has, has been touched, involved in some sort of AI tool in any creation of it?
So just to correct my, uh, the name of that tool, it's an open source tool. It's called AI Fairness 360, and it is an open source. I just Googled it.
Um, and it's for ML models, so something you can put in your DevOp pipeline, right? There you go. That's, you know, there any examples where things have really slowed down, right?
I mean, you think about adoption of the internet, adoption of the cloud, social media, um, I mean, the only things I can think recently around AI are Microsoft copilot recall where we got ahead of our, so they got ahead of themselves and someone thought it was a good idea to snapshot your screen every, every second, but not secure any of that information. The market reacted. The other is Apple's reaction to the EU AI Act, which is, uh, we don't, basically, I took it as we don't understand your re regulations well enough to know whether we could follow that.
So we're just not gonna bring our AI to the U until we, we feel that we can meet that compliance. It wasn't that we don't like your standard, it was like, we just don't know what it is. Other than that, there's very few places where sub A regulation has stopped ai, uh, in, in its tracks.
And, and I think one of the things we're gonna need is internal. Why don't, this is judgment call, right? And so much of it is we're gonna need the internal board of here's how we're using ai.
We're we're thinking about doing this with it. Are we delivering on the promise to our customers of safety of, uh, protecting their data transparency? We said we're gonna be transparent.
Well, are we being transparent enough? There's so much of a judgment call to this that you almost have to have some kind of an internal mechanism to say, no, maybe it's not a gate review that everything has to go through. We can use some tools, like you're talking about Tracy, to do some of those things, but it's, it's like, here's our stated policy of how we're gonna use AI and, and what we're gonna do and not do, and the line's not always clear.
So how do we help clarify when we need to make those calls? I have a more fundamental question, which is, what is the purpose of all this regulation and governance? It's to build trust, isn't it?
To build trust in AI and its use where I think the, the best way to build trust in AI is to use it and see for yourself what, what's real and not maybe not true. So good. Um, would fundamentally do having these regulations allow you to trust AI more, right?
I mean, Martin do. The, the fact that the EU has this AI act, it's not even, I mean, it's been passed, but I don't think it actually goes into effect effect until next year. Um, but by having that act, you say, oh, AI's a little more trustworthy, a little ease, safer to use.
Now I have more trust in it, because if it doesn't, why are we doing this? Yeah, I think the, that's a good point because the, the, the what, what builds trust is obviously, uh, transparency, uh, is one way to say, look, you know, there are regulations out there that requires out there, here's what we are doing in order to make you feel comfortable that the technology that we're delivering, the products and services that we're offering are safe to use an environment. And so, for example, uh, just be super practical here for a second.
At tricentis, we've actually established an AI trust center that you can look up on our website where we publish, uh, our data privacy, our, the, the kinds of technology that we're using, our security, uh, uh, that we're using. Uh, and we're also publishing the, the, the guiding principles that we use now in internal development, uh, to basically give customers that want to know, uh, a place to go to, to find out how do we, how do, what do we do internally and, and, and what do we do? And these are things that we are going to, uh, update and, uh, keep current on an ongoing basis as new regulations come out.
Um, I think there will still be an opportunity for like stains, like ISO and others to, uh, create more formal, uh, certifications as well that the vendors like us can, can sort of, um, uh, can achieve and publish it as well. Just like Tracy, as you mentioned on the security side, where we have a lot of requirements already that, uh, companies can, uh, adhere to. And then also be publishing that and say, here's what we're doing and if you have more questions, let us know because we wanna work with you to understand what specific requirements do you have that we can, uh, support as well?
And then it's about sort of, you know, showing and demonstrating and, um, and putting, um, you know, the proof in the pudding, if you will. I think this, This question of trust is pretty, is really important. Um, I, I, you know, I, even in Textron gang, I've said many times, I don't trust an autonomous driving car yet.
I, so trust is an issue, but part of that is awareness, right? Um, if I have, if, you know, when I was driving a Tesla could have put it in auto, you know, kind of an autopilot, but I never did. But I was aware that, that I was making that decision.
Part of the EU act is says that, you know, if you're kind of at a minimal risk, at minimum, you need to indicate that this is, this is AI generated. So, you know, in the United States right now, there's, you know, public service announcements going out about the potential of robocalls or AI generated, um, robocall that says go vote at some other location. The person that's listening to that doesn't know that that's an AI generated, uh, phone call.
So, you know, the awareness of the fact that you're consuming AI data is super important. Anything that comes across that's been generated by ai, it should have some kind of a stamp on it. Some kind of a, you know, a watermark that, so a Hologram or something?
Yeah, yeah. So like the doctor in Star Trek, Voyager or something. Right?
Exactly. Exactly like that. Um, because then we can, then we are aware that we are looking at something that's been, uh, that, that is actually AI and not human.
And that's important. It's very important, actually. One of, uh, one of the things that comes to mind when you say, um, do I get a sense of confidence knowing that these rules of regulations exist?
It's almost like here in Charlotte, North Carolina, let me tell you, speed limit can be 70, it can be 55, it can be whatever it wants, right? But here in Charlotte, 80 miles an hour, 90 miles an hour, pretty much everybody is doing it. And you very rarely see anyone, you know, pulled over.
So, is the speed limit actually meaningful if there is no enforcement? Right? I think one of the things that will give confidence is, uh, and, and not that you necessarily want to see governments going after, you know, everyone, but key stories about, uh, enforcement and how it actually has benefited people and, and made a difference, right?
Having the rules is great, but understanding, um, in, in common scenarios and common use cases, real world things that have an impact, um, I think that is a big confidence builder when people can see it and connect to it in that way. So I will just rule of thumb, so I could save somewhat a speeding ticket here. Yeah.
In, in Florida, it's a 70 mile an hour speed limit. And the rule of thumb is they won't pull you over up to 80. Anything over 80 you're subject to get pulled over.
Don't take that to the bank, and please don't say Alex in North Carolina, they often say five miles. Uh, but there, there, there are no, there, there are no, but, But you know what, bringing it back to ai, this is a perfect example where if you have autonomous driving one of Tracy Reagan's favorite things mm-hmm. And you tell, and you tell that AI program, Hey, not to exceed 75, you don't ever have to worry about it because it's not the human who's gonna go as fast as they can.
Mm-hmm. If the AI is told 75, the AI's going to go 75, assuming the AI behaves as intended, and we have trust in it. And that's the perfect example, right?
What if there's a bug and it goes 80 and you get a ticket? Whose fault is that? This is true too.
And are the tickets now automated? Because the car, you know, You're all in the line. We're all worrying about a scenario that's gonna go away.
If you remember back to the future national, remember Brown says where we're going, we don't need roads. Exactly, exactly. We don't have the, but this gigawatts, gigawatts, whatever.
Go ahead, Tracy. This brings me to another topic around governance. There has to be industry standards.
Uh, you know, financial is gonna be different than, you know, traffic control that's gonna be different from, um, welfare or warfare or, uh, or, uh, I don't know, surveillance. Every, I think every industry is gonna have to look at it. I think the Food and Drug Administration has done some work in healthcare, AI and healthcare defining standards.
But what will be, you know, so the question is what's the, what are gonna be the standards for the industry itself, right? The AI industry itself. So I keep going back to compliance.
If you define standards and industry specific ones, uh, and then we start figuring out a way to measure the compliance of those standards. I think we're making some progress, but bad actors are gonna do things without pur pursuing any standards as hope indicated. How do you enforce this?
You know, I have a 25 mile an hour si sign on my dirt road. Do I, you think anybody's gonna ever give me a ticket on that? No.
'cause some, some neighbor put it up there and I fly by it at 40 miles an hour, More than 10. But, but, you know, some neighbor put it up, Some neighbor put it up, right? But it's, so it's kind of like, you know, it's a neighbor putting it up, the eus putting up this sign that says you go 25 miles an hour.
Um, you know, do we honor that? And I think that most of us will try when it comes to this topic, but I do think industry standards are gonna be, uh, are gonna be as important if not more important than higher level, you know, federal level government standards on these topics, because they're very different When it, when it comes to governance. Now we see this, right?
There are different governance issues for the finance, you know, what we call the highly regulated industries, financial and healthcare and, and government work and stuff like that. And, and we've adapted to that. And as an industry, we, you know, people comply with those different vertical standards.
And they're not all industry standards. Some of them are government. Um, I, I would imagine we'll see the same thing with ai.
I just, I just, you know, I have that hologram issue where ethical people will act ethically, but unethical people will almost certainly act unethically and they may not make their hologram have the, the, the, the watermark or the, or the, or the standard, and I guess maybe this is true with a lot of governance, is the good people do their best to do good, and sometimes negligently or inadvertently, they, they may miss a compliance or governed standard, but AI has the ability or the potential, AI has the potential for people who are not ethical to really abuse the system. And I don't know if having AI acts in place, you know, maybe we have to go to criminal stuff. I, I, I don't know what the right answer is, But, you know, I think even the criminals are gonna have their own governance standards Really With their organizations, right?
It may not be a governmental or federal standard, but these criminal organizations, some of them are very large, right? They're, they're gonna have their own standards, and it, it makes Like la cosa nostros kind of, you know, you Yes. Only go out with your wife on Saturday night, not the, not the girlfriend, the widow, right?
Right. I, you know, sometimes lack of a, a federal, well, a, a federal standard, I mean, that, that's where we are now. And states are already enacting their own laws around ai.
Colorado has a lot, I don't remember the name of it, but it's basically says, if you're, if you're working with ai, that is high risk, you have to, um, there's some transparency requirements, and you have to have some type of review of what you're doing to make sure that it isn't endangering people. Something like that. But that, that's Colorado.
Who knows what, you know, Wyoming's gonna California or, or Idaho. Yeah. So, so we're, I mean, we live in a global world, but if every state has a different policy, different law, that's a complex web to try to build products and use ai, I mean, We, Before, Alan, your point, your point is, is spot on, you know, this is, the whole process of governance is really around, um, uh, kind of a democratic system between the EU and between all the states and the us.
Uh, everybody has to act, uh, in a gentlemanly way and, uh, agree to those standards and comply to it. And, and that's what drives it. And if, if we don't, um, we choose not to, um, there's very little accountability, or it's very hard to even find out that you're not a, uh, complying to those standards.
So governance is hard. It really is, uh, especially when you're trying to define governance through a, a democratic process where everybody makes their decisions across these countries and are relying on everybody to, um, be honest, and not everybody is. Guys, we're over time.
I gotta be honest with you. I apologize. But yeah, it was an interesting conversation.
I wanted to let it go a bit. I think we could all agree at this. I think there's still a book to be written, or at least a few chapters in how AI governance is gonna take shape here and what its effects going to be in a global marketplace.
And it'll be up. And, you know, the ethical people, as we said, will Actally, the trics of the world, will try to give people a sense of, Hey, we could test for this, or we can, you know, given transparency, we can show you that, you know, to, you know, be the transparency that it's in compliance or what have you, test for it. But a lot of it's good, I think is the book is still yet to be written.
So we're trying, is I, I guess the, the right thing, right, is we're trying, and it, and this is still evolving. Anyway, Martin, Tracy, oh, thank you guys for coming on our DevOps Unbound episode today. Mitchell, thank you as always for co-hosting.
Thank you Tricentis, for partnering with us for these four plus years. Now. We look forward to many more reminder for those folks out there.
This, what you just watched was a prerecorded version of DevOps Unbound. Every two or three versions, we do a live audience, and you get to ask the questions, and you get to make the comments, and you get to participate in this discussion. And we love having you.
So stay tuned for our next live round table of DevOps Unbound. But until then, this is Alan Hummel for Techstrong Group. Have a great day, everyone.
We'll see you soon. Welcome everybody. Uh, I'm Pete Garson, director of Products at Active State.
And today we're gonna talk about, uh, taming the complexity of open source with active state. And you probably know a little bit about active state. Uh, we've been around for over two decades.
Uh, we're currently helping 97% of the Fortune 1000 secure their open source. And we've been around since the sort of late nineties, uh, when we started doing, uh, Pearl on Windows and doing that port, and we sort of, we were also a founding member of the PSF. And we've been working with, uh, enterprises to help, uh, manage their open source for the better part of those two decades.
And one of the things we've done recently, uh, we partnered with PI PI on a trusted publishing initiative. And as over time as things evolved, we went from doing things like Active Pearl, active Python, uh, where you might just download a sort of curated distribution of, uh, open source and open source packages to something where instead, what you're doing now is having a tool to manage all of your open source. And so what we did was we evolved, uh, our product first to meet our own needs, uh, internally in terms of what we were doing to manage open source for various enterprises, and instead move that to a product where all of our users could use this.
And to sort of help them manage, uh, all of that open source and tame bit of that complexity, uh, around what's involved in managing open source from the ingestion point all the way through to the, uh, deployment stage. And so one of the things is, when you're not managing unmanaged open source is exposing you to sort of escalating security and license threats. Uh, supply chain threats and managing this stuff at scale is really challenging.
Uh, you know, it's one thing to know, I've got a vulnerability in this package, right? I've got, you know, my, my s e's tool is telling me, oh, yeah, you've got a vulnerability in this package. You need to update that.
But it's another thing to actually successfully update that dependency, all of its dependencies. So everything, all of its transitive dependencies. And to ensure, like the providence of all of that stuff that you're ingesting, you know, dependency hell is a real thing that can really consume a lot of developer time.
And knowing whether that is a breaking change or not, how safe is it for me to update that? It's really, really challenging. And so just that, uh, that element alone is really, really simple.
I'll just say that one again, it's there. Just managing, bringing in the updates alone is really, really challenging. And then we move over to observability where I can even understand what I'm using in the first place, right?
I'm a large organization, I'm running thousands of pieces of open source software. Is that cataloged? Is it versioned, auditable, reproducible?
Where is it running? Who's running it? All of that is super challenging.
And if you don't have systems in place, it can be very, very painful. And then on the other end of things, if you're trying to comply with, uh, government regulations or security audits, do you have tools in place there to actually develop and deliver the, uh, artifacts that you need to support the security guarantees that you're giving, right? Can you produce the documentation, the chain of custody information to be and be able to verify that and supply it when needed?
All of this stuff is really, really complex, uh, and it's very, very rarely, uh, an end-to-end solution. And so it's really, you know, it's no, no wonder that there's a lot of shortcuts that are being taken and, uh, people are shipping with known vulnerabilities, or they're doing a lot of ad hoc things. And that's really what we see is that people are really stitching point solutions together.
Uh, they're, they're maintaining spreadsheets. They're, uh, running an ad hoc report. Uh, they're doing, you know, audits on demand, very reactionary, uh, you know, they've got solutions that are kind of diffused throughout the organization department.
There's no standardization. Um, you're managing all these different, uh, upstreams, right? You've got source code, you've got vulnerability DA databases, you've got vulnerability scanning tools, you've got container registries, you've got licenses, you've got SBOs, you've got all these different tools, all these different processes for each one individually, and they're probably largely duct taped together.
They're not pro brought together in a coherent, cohesive way, and they're really only partially addressing the solution, right? They're not seamlessly stitched together. So one of the things that we've seen over the years is that you really do need to think about this holistically, especially when you're thinking about supply chain security.
And so what we're doing at active state, and what we're sort of talking about today is like, what's, how do you tame that complexity of all of this stuff? How do I deal with all of those stages across my software development lifecycle in a way, uh, that is systematic and reproducible and auditable and understandable, and also low friction for those inside my organization? So what we're doing at ActiveState here is sort of bringing our, our, you know, decades of experience with os open source management to bear and to provide a kind of holistic solution.
And so let me sort of walk you through what that looks like here from the discovery of everything that's running inside your org, right down to the deployment. And so we saw before there's an open source ecosystem and maybe your even your own private ecosystem, and there's a lot of information that's out there that you're pulling from all these different sources, and you also have a lot of open source that's running inside your organization. So the first stage is really about discovering that, right?
It's about discovering and cataloging all the open source that's running inside your organization. So discovering it from various sources, uh, knowing who's running it and where having a kind of auditable inventory, we'll see that this, this notion of having an auditable inventory is really important. Um, you know, having a spreadsheet of all the open source that's running, probably not gonna cut it, right?
Having a diffused set of requirements that TXT files or for whatever language you have diffused across your source code re repository, also probably not going to cut it. You can't do any kind of sophisticated reporting against that kind of thing. And so then we move on.
Once you've discovered, once you even know you can't even begin to manage what you're doing, if you don't know what you're running, then we can move on to the analysis stage where we can gain insights into the risk profile and generate some reports and share that intelligence across the organization, right? When you have, you know, a DevSecOps, uh, scenario where you've got collaboration happening between development and security and, uh, DevOps professionals, you need to have, uh, ways to share information across that organization and to collaborate effectively. And so the first thing you need is analysis of all that stuff that's running.
So you need license and vulnerability reports. You need, what's the impact of taking this upgrade, right? Do it, does it have a breaking change in it?
Do I have all of the, uh, supporting artifacts that we talked about from the compliance standpoint, you know, in terms of SBOs, attestations, all that stuff. But then once you have the analysis, okay, now we have to take an action, right? We need to do something about it.
We have to remediate the issue, or we need to get it deployed, or whatever. And so then you need to have tools in place to be able to scale that across your organization. So, uh, once I, once I'm taking the action to remediate something, I need to know, first of all, do I need to remediate that?
Does it, does it hit the threshold that we have to remediate? And do I have tools in place? So whether that's policies to be able to say, um, we don't, we don't want, uh, any vulnerabilities inside our organization that are, uh, you know, higher than a high, we don't want any criticals or highs inside.
But then do you have the ability to scale that across all of those upstream sources, right? So we start to think about having a curated immutable catalog where instead of drawing from all of these various, you know, unsecured, unmonitored, uh, you know, public sources, that we can have our own curated catalog where we have control over what's in there, and we also have the ability to, you know, enforce that across our organization. And then finally, okay, great, I'm gonna download, I need a new version of my package and I need to go from version one to version two, but does it build, does it work with all of the other, uh, dependencies inside my, uh, inside my project or, uh, you know, in my deployment?
And so what we've done is we've had, you know, two decades of experience building open source, and we have, you know, a very powerful, uh, build cluster where we can build things in hermetically sealed containers with guaranteed provenance. Everything is built from source, and we can integrate with your systems to be able to, uh, deploy, um, in whatever scenario you have, uh, whether it's a container or whether it's just a, a simple application and getting that into your organization. And so then we get back to the beginning, and now, instead of discovery, we're talking about monitoring on an ongoing basis, knowing what's running inside your organization, and being able to keep up up with that, whether there are changes, whether you need to, you know, emerging vulnerabilities, I need to remediate that, get it redeployed, rinse, and repeat across the cycle.
And so this sort of holistic end to end where right from the discovery, right from the source code all the way through the intermediate artifacts and the building, that kind of holistic end to end is really, uh, key to, uh, sort of taming that complexity and to having something that is a reproducible, uh, simple, understandable collaborative system, uh, across your organization. And so, when really what we're talking about is various set of different use cases where we're talking about, you know, the idea of continuous open source integration. How, how quickly can I get new versions deployed within my, uh, organization?
How quickly can I get new versions ingested into my pipeline? How can I ensure that my different environments are consistent and reproducible across my entire organization? Do I have the tools in place for effective governance so that everybody's pulling from the same catalog, everybody's pulling from the same set of trusted artifacts?
Do I have insights into all of the usage across my organization? Do I have insight into all of the places where things are deployed? Do I have the tools to be meet regulatory compliance, right?
Do I have those, you know, the, those SBOs, those ats, those type of things? And do I have, uh, support for things that are going beyond the community supported end of life? So if I need something, uh, supported beyond that, do I have a a catalog that supports that kind of thing?
And then we're gonna kind of jump into that, uh, today and sort of show you what that might look like actually in practice. You know, I showed you the little diagram here. I talked a little bit about the process, but let's talk about what that actually seems like in practice.
So I'm gonna jump over here. Let's say that we have a, a little environment where, uh, we wanna discover everything that's running inside our organization. We, it's gonna live in a lot of different places, right?
It might be in a Kubernetes cluster, right? It might be just in GitHub, basically, oh, we've got all of our, our requirements files and, and, uh, dependency manifest files across various projects. In GitHub, it might be, we might already have a bunch of SBOs and we don't know really what to do with them, but they can be a very valuable, uh, tool for understanding what's running inside your organization.
So we can get directly from our requirements file or an SBO from GitHub from, you know, helm or Kubernetes. And so let's say, we're just gonna say Kubernetes here today. So we're gonna scan our Kubernetes cluster, and here we discovered that we've got a number of sort community images that are running here.
We've got Postgres and Nginx and Spark and Elasticsearch, and, but what's inside of those things, right? It's one thing to know, okay, yeah, I'm running Postgres, but what, you know, what's actually inside that? And so our tool can analyze these dependencies and vulnerabilities and give us information and intelligence right down to the system level.
Like, you really need to understand, it's one thing to know that, uh, you know, I'm running TensorFlow, but there's a whole bunch of C libraries that underpin that, and that's where you sort of, that's where a lot of the vulnerabilities that tend to be is in languages like c in those type of, uh, libraries. And so what we've got here is we've got an immediate analysis where we can get that information at a glance. So, you know, across my little, uh, pretend organization here, uh, I've got six docker images running, and 47% of that is C code.
There's 1,099 CC dependencies running there. I've got a bunch of Java, some go, some Python in there. It's given me a vulnerability profile that's showing me, uh, here's, I've got 14 criticals 136 highs.
I've got a profile of the different licenses. So at a glance for my organization, I can see what my risk profile looks like, and I can do things like download a CBE report or download an SBO m But the key thing here is that I've discovered at an early stage what open source is running and what its composition is, and, uh, you know, sort of what my risk profile is here. And I can see some more details on those things, but we sort of covered those first two boxes.
We've got a thing where we've discovered, so now we have that, and we've also, you know, pre presumably got something in place now where we can monitor this on an ongoing basis. But then we've also got some analysis here where initially we can see what our composition is. Okay, well, we've got a lot of vulnerabilities.
How do we upgrade that, right? How go from, you know, 1500, um, vulnerabilities to something that's, that's less, right? And so what we can do is generate something, uh, a remediation plan, right?
We can get, we have a lot of information in our catalog, right? We're, we're going out there and we are ingesting a lot of these public ecosystems. We're pulling in all of pipi, we're pulling in, uh, all of, uh, you know, uh, the pearl ecosystem.
We're pulling in all of the Java ecosystem, et cetera, et cetera. And we have all of this information around versions. And so we can say immediately here, you know, what, before you had 150, after you're gonna have 188, here's what you can do.
We can also give you some additional intelligence, uh, around the risk profile here. But, uh, essentially what, what we can do is show you that we can remediate all these things. They're relatively, uh, low risk right now.
And so then what we're going to do is we're gonna take those things and we're gonna import them into our platform and manage them as projects. So each one of those containers that we saw before now becomes a project on our platform, where now I have a, a contained unit where what I can do is manage that over time. I can configure that over time.
I can see the auditable history of that. So let's say, let's pop over here and see what that actually looks like. So this is a, a little demonstration organization I have here where I've got, uh, five projects, 468 dependencies, mostly go and Java here, and a number of vulnerabilities.
But each one of these things represents either a container that's running in my, um, cluster, my Kubernetes cluster, like we saw, or maybe just a basic, uh, project that I created. So in this case, like, um, my, a basic Python project. And what I can do is I can manage the dependencies individually in those things.
I can also browse them at organization level. So, you know what, if I'm sitting there and I'm in my, uh, an organization, I'm like, I hear about some critical vulnerability. Do you have a index of all the open source that's running inside your organization that you can very quickly, uh, you know, inquire and say, am I exposed to this?
So let's say we hear about something log four J and we type that in here right now across my entire organization, I can type that in and immediately see that, well actually I have this thing log four j append that's running in one of my containers here. It's running in this Kafka test container. And so maybe I should go and investigate that, right?
And I can drill into that exact project and see the details. Um, and that project will then I'll, I'll be able to configure that. I can also see the vulnerabilities across my entire organization, and then I can go in here to my project and configure it.
So let's go like a really simple example, uh, with the, uh, Python, and let's take a look at what that, how that actually manifests. So lemme just quickly turn that off. And, um, what you see here is, here's this, the packages that are in my project.
So in this case, I've got a very simple web application, say flask and pillow. And this is sort of maybe running out there on my cluster somewhere, but I've seen here that I've got vulnerabilities, I've got a critical vulnerability here. I've, uh, four highs and I'm getting in.
I, I, so I'm inspecting what, you know, what the problem is here. I've got a couple highs here in the Python version as well. I can see my, all of my dependencies all the way down here to the system level.
I can see, you know, not just that, you know, flask brings in blinker and click and flick, or it's dangerous and stuff like that. I can scroll down here and see right down 11 LZMA and the system level C libraries. So I've got sort of unprecedented visibility right down to the deepest level.
But then I can go and I can remediate these things very simply. I can say, here's what one is not vulnerable. I'm on Python nine, uh, pillow nine 10.
Well, I'm at one critical four highs. I need to pick one that doesn't have a vulnerability, because we are ingesting all of this open source into our catalog. We're building it all from source.
You've got a trusted upstream for essentially all of the, you know, open internet. So rather than going into a situation where you are, um, managing 50 different upstreams, you can say, well, I'm just gonna point to, uh, active state's trust catalog for everything. And I can choose that version though from our catalog where we know that that doesn't have any vulnerabilities.
So we're gonna say fixing vulnerability here, then we're gonna save those changes. And now that's been changed to, uh, to the non vulnerable version. It's gonna resolve and re-figure out all of the things that are in there.
But one thing that's interesting that is a critical piece of the puzzle here in terms of taming the complexity of your open source, is the idea of that change management auditable history that you saw me do. So I logged the change. So here, rather than me just editing a text file and committing that, or, you know, just installing it on my developer laptop or something, what we've done here is kind of merge the concept of source control with dependency management, where I've got the, you can see here, here's my base project that I created.
4. And you can see that at any point I can go back in history and revert to this commit, I can generate an S bomb at any point in history. So I have a fully auditable chain of custody here where I can see that, you know, Pete made this on October 24th at this exact time.
Here's the commit id. It's fully reproducible. And unlike you can see here that we also have this catalog revision id.
And unlike the sort of public repositories where if I run, you know, NPM install on a Friday, and I run N npm NPM install on a Monday, I'm gonna get a different result. But what we are doing is we are revisioning the catalog and repoint in time, so it's fully reproducible. So not only, uh, is this saving the state of your dependencies at any point in time and all the open source that you're using, it's also saving the state of the world at that time so that you are fully reproducible, fully auditable from end to end.
The other piece that you can see is that what it's doing is it's kicked off a build into in our cluster where it will be building this, uh, from source, these individual packages. 4, it'll be building that from the source in our cluster here. And so you can see as well, our critical went away over here on our total vulnerabilities, and it's rebuilding on macOS here.
Those things get rebuilt completely in, uh, uh, in hermetically sealed containers and completely, um, in a completely reproducible way. You can get SBOs for all of those things. If I go to my overview here, I can see I can generate things like an SBO for this.
I can download a vulnerability report, I can do collaboration. But the key thing is that what we're doing is we're taking stuff from the beginning where we're discovering all the open source that's running in our organization. We're then doing some basic analysis on it to give you sort of, uh, the breakdown of the inventory, whether it's go or Java or C or Python.
We're giving you the high level rollup across your entire organization of all the vulnerabilities. So you have that initial analysis stage, then we're giving you the tools to be able to curate those things and manage a catalog, have a fully auditable history to give you the sort of, uh, governance tools that you need to be able to curate that. And then the tools to be able to build, deploy, and redeploy that.
And so I think that that key cycle there where you have end to end control and visibility on everything that you do, whether it is, um, just discovering what's going on in your organization, all the open source that you're using, cataloging that in an auditable database, then being able to do analysis, collaborate with across your organization, across your, uh, development team, your ops team, your security team, to be able to then curate that, upgrade it seamlessly remediate as we just saw, and then build and deploy that, whether it's integrating with your CICD to get deployed it out, out to your, uh, cluster or whether it's just on your developer laptop, to be able to keep working and streamline that development process. Having a system that streamlines that entire process holistically end to end is, uh, really important. And that's sort of our vision for how, uh, we should be sort of simplifying and streamlining and tame taming the complexity of managing open source, because it's really complicated, it's very complex.
There's a lot of moving parts, a lot of information as we saw shifting landscape as well. And accuracy has been really focused on taming that complexity. So I want to, uh, call it there and say, you know, thanks for coming to check this out and, uh, if you have any questions, just let us know.
And, uh, thanks very much. Hello everybody, and welcome to the latest episode of the Text Drawing Gang. We've got a I PCs today, a feud between AI robber barons, and a debate over, well, what's going on with finops.
You're watching Textron Gang, and we'll be back in a minute. Hey folks, I'm your host for the day, Mike Ard, and we got an awesome lineup of folks today starting with our friends in California. Once again, John Schwartz is out there in the Bay Area.
John, how are you? I'm Doing good. I'd rather be here on a big gang.
Excellent. Also out in the Bay Area. Lisa Martin, our resident, CMO advisor, expert at the Futureum Group.
Lisa, good to see you again. Good to see you too. I'm excited for today's gang.
All right. Going, I guess clockwise. I hope maybe everybody sees it the way I see it, but Amanda Ani is down in Texas.
I how cold is it in Texas these days? Is it is? It's in the forties all last week.
It was high eighties and now it's in the forties. All right. Wow.
Also hanging out in Texas. Guy Courier. Yeah, in central Texas where I might hit 60 today, but more to the point, it's like, not just cold, it's like a little windy and like wet and ugly.
Maybe that's why I'm so cranky. Or maybe it's because my, uh, because of my horrible Superbowl prediction. Well, that could be too.
And finally, Stephen fos in Ohio, where it's as cold as it is where I am in New York. Steven, how do you do it? It's as cold as ice.
I'm willing to pay the price though. Oh Man. Nice foreigner reference.
I saw that tour, by the way. Hey, don't call me a foreigner. I wanna stay here in America.
Alright, Noted. Well, Somebody, we'll do something about that. Somebody, somebody check his birth certificate.
All right, we're moving on. No need. We can just declare him a foreigner.
All right, well let's get into our first topic of the day, which is a, I PCs our friends over at the FU group have a new report out suggesting that enterprises might start buying these things earlier than anticipated to future proof, as it were, because, well, and they tend to hold onto to these things for a few years, but John, you wrote this report. What's your take on what's going on here? Um, is it realistic or is it wishful thinking?
It's probably both. I mean, there's a, there's elements of it that are real, but I think it is in terms of wishful thinking. So the group talked to 852 enterprise IT decision makers this year, and, um, they came away with three major findings that, number one, about more than half feel this need for their workforce to be more competitive as quickly as possible.
So I guess the idea is you put the technology in front of people on an everyday basis and kind of force them to learn it or at least adapt to it. The second reason, which is tied to the first is that nearly half identified the impending into Windows 10 support as a critical priority. And then a third pointed out the necessity for improvement in system performance.
Now, the, the thing that is interesting to me, and it was not in the story because it just came out, there's a Wedbush securities report that shows that the budget for AI is probably roughly gonna be in the 10 to 15% range this year up from single digits, which shows this kind of acceleration of an a AI strategy over the next six to nine months. So there is like this discernible movement going on. Um, and I think that the AI PCs may play a pro a, a piece of it.
I'm not sure how significant, I think there's still some sort of roadblocks, for instance, in those, a FU survey, 36% were concerned about the higher unit price of a IPCs and related costs, such as subscriptions to feature enabling services, um, uh, about a fourth side of the concern over the ability of A IPC to run critical enterprise software natively. So there are still obstacles, but I think it is definitely moving in this direction. But, you know, seeing is believing I, the, the, the idea is it's go time.
Um, we'll see, I know, I, I have a, a measure of skepticism about it, but there you have it. Guy, you want to jump in here? Well, yeah, I've been saying, uh, all along, you know, here and elsewhere that, uh, the, the AI movement feels a lot like the PC movement to me from back in the eighties, which was in the case of the pc, about 20 years of investment purchases, use, all that sort of stuff, while the economists were scratching their head and saying, well, we don't see any productivity gains.
The benefits were so obvious that nobody was sitting around and measuring productivity. Nonetheless, that sort of business, bottom line, there was an adjustment to be made, people had to be trained, and then eventually we started to see it. I think that we're gonna see that return on investment, um, for AI generally a lot quicker than in 20 years, but it's the same basic thing.
The benefits and usefulness are so obvious that investment is just going up without people sitting around trying to calculate the productivity or other gains. But I do wanna say this. So when it comes to IPCs specifically, I think that that's the movement.
It's just there seems to be an obvious benefit. So it shops are investing in it, but I also kinda wonder if, if we know like what an A IPC is, I mean, you know, on this, in this group, uh, we can, you know, come probably I'll come up with a reasonable definition. But I'm, I'm wondering, uh, at Lisa and, and Amanda, I think of you guys having sort of your pulse on popular sentiment.
Do people know that an A i PC is a PC that is tailored for local inference, or do they think something else, like it's something that helps create ai? I I think that a lot of people are thinking the latter. Yeah, I think a lot of people really are not clear on what an AI PC is.
You nailed it. Yeah, I agree with that. From a messaging perspective, I think it's not clear what that is.
Um, from an inferencing perspective, I think the average person doesn't understand that. And so they think, is it, is it an a PC with AI and built into the hardware and software, can I create AI with it? I think there needs to be some more definition and clarity around what it is and what those clear benefits are to any type of organization, retail, any other industry.
Yeah, all. Well, as it happens, Steven Foskett has a video last year defining what an A IPC was, and it was one of the most watched videos he did all year long. So Steven, what the heck is an IPC?
Thank you Mike. Uh, yeah, I think a guy was maybe there when I recorded this live at a tech field day event. Um, yeah, and the, and it's, it's funny because it, obviously this video hit a nerve because that's the title, what is an IPC?
And so people are searching this and they're trying to figure it out. Um, essentially it, what Lisa said is, is right on. It's not just hardware, it's hardware and software.
And that is the important aspect to me of, you know, what is an A IPC? You'll notice as well that in the Futurum study, um, they talk about not just Qualcomm, Snapdragon X versus X 86, they talk about Apple, and remember that Apple is right there. I mean, we sometimes use the, the, those two letters PC to exclude Apple, but in this case, apple is right there making AI PCs as well.
And what I said in the video, and this is like, I, I, you know, I think what people need to know and what as, as you know, you just mentioned Lisa, that that people don't seem to know is, um, you know, it's all about running AI locally on your local data, on your local machine, but it's not just about horsepower. Now, certainly Snapdragon X and the Apple M series have incredible horsepower for pro doing AI performance tasks, and Intel and a MD are not asleep at the wheel. They have also introduced incredible chips that can, I mean, it's, it's, it's hilarious because I mean, they're right there with, with chips that can do the same thing.
Um, but it's not about hardware as much as it is. Well, I mean, hardware is a necessity. It's about software and it's about integration, and it's about having those models at your fingertips.
Companies like Microsoft and Salesforce and Slack and Dropbox and, and all these other companies are trying to bring that software natively into the interface. Uh, you know, Microsoft now has, you know, co-pilot in the ribbon on office apps. Uh, you know, that's when AI becomes real.
It, it can't happen until you have a PC that can handle the, the, the, the, the computing. But it also can't happen until, you know, Joe in accounting or mm-hmm. Jane in software development has that copilot icon on her desktop and, and, and, and, and knows how to use it, the desire to use it, right?
That's, that's the yeah, those are the two things, right? First, we keep hearing so much about it. You know what, you know what guys, let's just buy right now and we'll figure that out later.
Maybe in the third or fourth generation of A IPC that we buy. I mean, that really isn't that what's happening? So some, So I have a question.
So you say it's more about the software, it is about the hardware too supporting, but, um, I imagine a lot of people would say, well then, um, can't I just make my current computer be an AI pc? Because all the shared AI software, I mean, we see the co-pilot already have co-pilot already have chat, GPT already have Canva ai, like, can't I just use a bunch of shared AI software and I have an AI pc? It's, it's a, it's a really good point, and I think that in some ways the AI industry may have done themselves a disservice by rushing this stuff out with cloud-based applications, because essentially as, as you're saying, yeah, absolutely.
That co-pilot, um, icon appears whether you have an AI PC or not. And in many cases, you know, I mean, you look at chat GPTs incredible success, it's running in the cloud, you don't need an A IPC to run chat GPT, you can run it on your old iPhone se, even though it's not actually running on your old iPhone, you know, it's, it's running in the cloud. But to you, does it matter?
And Apple has done an incredible job as well of seamlessly integrating cloud and local processing to the point that even if you have the latest and greatest M four, you know, iPad or Mac or, or, or the latest iPhone, um, you don't know and you can't know whether it's running locally or in the cloud. And that kind of undercuts this entire discussion because if, if all this stuff can run whether you have an AI PC or not, then what's the point? Yeah.
Mm-hmm. Alright, think about this slightly differently. com boom, I went toe to toe with A CFO who subsequently became one of my best friends.
But at the time, you know, he was arguing we didn't need new PCs to support a publishing staff. That was at the time, moving into the brave new world of online publishing and everybody's laptops were crashing and stories were getting lost and people were losing their minds. And um, but for whatever reason, you know, he was still on this, well, we're gonna upgrade every three year kind of cycle.
Fast forward to today, I would've just told 'em to bugger off and went out and bought a bunch of PCs myself and just handed them out to folks and said, you know, this is our new units and this is what we're doing. So guy who cares what the CIO or the CFO thinks anymore, people are just gonna do shadow it and do what they need to do when they need to do it. Well, I think that's a great follow up to Steven's comment because with a certain level of, like, one of the things that I'm really hot on right now is Edge ai.
Steven helped get me there, by the way. I have to say, uh, and, and, and work with the tech field in with him. Why?
So that answers your question, Amanda, but it's a technical question. Where should processing occur? Should it occur at the core or should it occur at the edge?
This is an architectural question. This is an application architecture and design question. Like Steven says, like, Apple's done a phenomenal job with this sort of thing.
So Mike, I don't see any reason if you got the money not to invest in what amounts to an Edge AI capability, that's the IPC recognizing that maybe it'll never be used. So I agree with you just go take out who cares what the CIO and the CFO says, well, you care, you're a head of a business unit, you care about your bottom line. You wanna show ROI, you invest in all kinds of things all over the place, the technological and non-technological, like fancy group dinners or something like that, that you're not gonna sit there and justify, hey, this particular thing had this ROI, especially if it has AI attached to it.
In fact, let's just attach AI to everything that we wanna buy, whether it really is AI or not, and then everybody will let us buy it. Alright. John, what do you think the odds are that an AI PC is gonna cost a lot more in three months due to a tariff than it does today?
That's a good point. Yeah, everything's gonna cost a lot more. You know what I was gonna go back to, um, something we were talking about Apple in terms of organic growth and shadow adoption of, of a PC or in the case of a Mac.
I mean, it will find a way, and I think, I suspect that might happen with AI in a certain sense. You know, it's always driven by software, you know, hardware is important, but that underlying use from the the user is, is is just important. Yeah.
That, that's, that's interesting. Mike, with given, given the, uh, terrorists that are going to be in effect, does that kind of negates the, or or kind of put in put a, a kibosh on the enthusiasm? Some of some folks when they look at their budgets, I mean, it's something we should probably take a look at and I think it's probably gonna happen in some form.
Steven, you wanna jump in here a little bit in terms of predictions for A IPC costs going up, down, what's your thought? Well, with the CHIPS Act, I think there's a good chance that we might, uh, actually be manufacturing some of this stuff locally. I mean, uh, the news, uh, coming out of Apple is that they just, uh, produce their first, uh, US made, uh, processor, um, in, uh, TSMC, I think it is TSMC factory.
Um, I, I think that we are going to see some homegrown chips, but of course, um, it's complicated as they say because it's not just, uh, etching the chips, it's packaging, it's manufacturing, uh, final assembly, uh, distribution, all those things that matter. And tariffs could get in the way of a lot of that because it is a globally interconnected supply chain. So I'll say that I believe that we will probably be seeing, um, costs for literally everything go up in the face of tariffs because that's what tariffs are.
That's what they do, and that's what's gonna happen. All right. I'm betting that be the PCs will be assembled in The Bahamas to get around the tariffs.
That's, Hey, that happened a lot in the sixties and seventies when we had a big, uh, international tariff regime. There was a lot of outsourcing, uh, to the US Virgin Islands and Puerto Rico and places like That. Interesting.
Lisa, I wanna give you the last word on this. You know, guy and Steven talked about this a little bit, but is there a branding marketing issue around IPCs and the way we use the term ca and do we need to kind of revisit this whole conversation? I think so.
I think a, as I mentioned earlier, I think from a clarity and a definition perspective, it needs to be that really clearly defined the future of study that John started this block up with shows that a lot of organizations are really looking at a IPCs to be more competitive. Well, what does that mean? Um, competitive differentiation is incredibly important to every type of business.
But how will an A IPC if I'm a, a retailer, help me get there? I think from a clarity perspective, the messaging needs to be refined. The benefits need to be really clear so organizations understand, do I invest now to your point on the tariffs, or do I wait if I wait, my costs go up.
But I think they, that the marketing folks, they talk about future proofing and that's always one of those marketing terms that bothers me because it means something different to everybody or it doesn't really mean anything. Um, what is, you know, future proofing what A IP Cs future proofing, what my business, how? Um, so I think there's, there's a lot of, of wiggle room in an A IPC definition currently.
Steven kind of nailed it with, with what should be done so organizations can really make the the right investment decision as to whether they really need it right now or not. All. I'm gonna tell you where you can find future proofing.
It's right here on Techstrong TV where you get the knowledge you need to make the right decisions in the future. There you go. Alright, we'll be back in a minute.
Discover Techstrong group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more. Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and we're gonna be talking about this bid that Elon Musk and a bunch of investors are making for open ai. And geez, you just can't make this stuff up. It's right out of Robert Barron's and the Gilded Age.
Lisa. I mean, I don't think, at least from where I sit, I'm not sure that this is even a serious thing because last time I checked the company was worth more than the bid. And I don't think that they actually have to respond because they're not really structured like a typical company.
But from your perspective, um, is this kind of outta hand or is this, you know, just silliness? Where are we going with this thing? I, I think it's out of hand and silliness.
It's Elon, when I heard it very early this morning, the news, I just thought, there he goes again. And we were talking before we went live about the chaos that ensues when, when Elon opens his mouth and offers a bid. You know, the, I the irony in it is that he was one of the co-founders back in 2015 with Sam Altman.
Um, Elon is is a top advisor to President Trump, which was something I never expected to see and I followed Elon for a long time. But, and then of course open AI with SoftBank and Oracle and Project Stargate, what they're doing there to invest in AI infrastructure in the States. Um, clearly Sam Altman didn't take it seriously with his re response, but I do vote for Sam Altman to buy X as he joked about.
I think that could make, bring it, bring back the Twitter name, but I think, I think it's just, it, it is silly. I think it's Elon flexing once again. And I, and I think from, I always think, man, what was his marketing People think it must, that must drag them crazy that they can't control the message 'cause he's just gonna say whatever he wants.
Um, now is, is X AI better than open a? I don't use Xai personally. I use GR with a Q, but I think that it's, it's el ongoing rogue and I think it's just to probably tie up things for open AI's next steps, which it wants to do.
And we'll have to wait and see how much that affects what those next step plans are. Um, I think it's a bit of thud personally. So I've had so many thoughts rolling in my own head and I'll tell you what those were and then I put it, um, I put it out on social media to ask what other people think.
But my first thought was, I'm not sure I like one person having control of any number of like all of the basically databases. Like he already is in control of X. And then we have Sam in control of chat.
GPTI would say, I don't want one person controlling all these systems because that's essentially such a huge amount of data that he has and what's he gonna do with it. And also, it's another platform to essentially manipulate society in a way. I mean, you could, one, giving one person control of all these different platforms, that's a little scary.
So secondly, I put this out on, um, social media though, just to see what people think. You know, I put, Hey, he offered this much. Um, what do you think?
Um, why did you know, why did he put a bid? And so some of the, um, responses were, um, because it is the hottest tech, he believes he can run it better. He enjoys limelight and positioning of power and money.
And then somebody else put, um, to expand on that, um, they put essentially, you know, it was a very long paragraph, but essentially, um, because, um, it's worth, it could be worth trillions in the long run. And that resources in the end are more important than money in the first place. And when you think of people of real power, while we're trying to just pay bills and enjoy life, they think in m pavillion terms, dynasties, um, somebody else put, um, uh, uh, all you have to do is, um, go watch the Netflix docu film on Cambridge Analytics and you'll understand what's going on.
So I don't know if anybody's seen that. Uh, and, and then, let's see. Uh, because, um, Elon may not be entirely human joking, not joking, because ai, avatar hybrids are legitimate potential future.
And there are organization organizations deeper and darker than 99% of humans ever see and would ever believe. And there are things working under, in Pandora's B that are broader and deeper than we know. Okay.
There are some of the answers that you have from, from my best, John, what Are John, what are they saying in the Valley about all this? Because, um, you know, right from where, from where I sit, this is like, you know, do I like Andrew Carnegie better than John Rockefeller? I don't know.
They're all the same. Yeah. They're all, they're all despised out here as well as the rest of the country.
Uh, you know, the one thing that I, when it always comes to Elon, there's always like an end game. You know, there's, there's the short game and then there's the end game, and then there's a game that he hasn't even imagined yet in his adult brain. And, um, it, and he has taken, there was a legal action by must against open AI to force open AI to auction off a portion of his business.
And I'm wondering, by making this bid as absurd as it may sound on the surface, whether he's trying to force or maybe elicit other types of bids or, or force OpenAI to consider other offers, or at least entertain the idea of an auction because they are moving towards a for-profit status. Um, you're right, you mentioned earlier that the, uh, the amount they're offering is literally half of what OpenAI is valued at. So no, OpenAI is valued at about 160 billion, but there is a rumor that there will be another cash infusion, another round of funding that will elevate it to 260 billion.
So, um, in, in a sense, I think he's, he's trying to muck with a company that he personally despises and a guy that he choose his mortal enemy in a sense of Sam Altman. I think this is all, a lot of, a lot of Machiavellian twists and turns, but I also think there is some sort of end game to try to compromise open AI as a company. Yeah.
If I can dive in on that one, I think that you, you know, you're, you're right there, John. It's still early hours of us digesting this. And so, but to me, the thing that caught my eye, let's be clear.
Oh, Elon Musk is not bidding almost a hundred and, and his team and his alleged, uh, uh, I was gonna say co-conspirators, not exactly the right way to say it. Um, he, his alleged consortium is not bidding for open ai, the makers of chat, PPT, let's be clear, this is a bid for the, a nonprofit organization that, that controls open AI rights, correct? Yes.
But, and remember the valuation that you just talked about is the valuation of open AI that for-profit company and open AI's assets. What Elon Musk is doing here, I think has nothing to do with taking over OpenAI. I know that, you know, you say Elon Musk and everybody just loses their stuff.
What's happening, which I'm about to do, but please continue, feel free. I'm just gonna say it 12 more times until your head explodes. Um, what's happening here is this is absolutely the actions of, of, you know, back to Mike, what Mike said at the beginning.
This is robber barons fighting robber barons. And what he's doing here is by offering this absurdly high, no, I mean, that's the thing. This is not a low ball offer.
org kind of aspect by offering an insanely absurdly high amount for the nonprofit. He has just set the bar that says that when the for-profit entity wants to split from the nonprofit, or wants to go public, or wants to kind of cash in on this absurd valuation, what they're gonna have to do is they're gonna have to beat that amount to, they're gonna have to pay that amount to the nonprofit, because at that point, all the shareholders, everybody involved will say, wait a second. You know, you wanna split from the nonprofit and you wanna give them some money.
Previously that some money might have been a billion dollars or something. Now that some money has to be over a hundred billion dollars, which means that OpenAI the company is going to basic, it's just Elon Musk, just force them to flush a hundred billion dollars down the toilet on nothing. Or he's gonna swoop in and have some kind of really valuable minority or maybe even majority shareholder stake in that eventual public entity.
And, and so this is pretty much, I don't wanna say a checkmate, this is a certainly a check on the chess board, and it has nothing to do with Elon Musk actually wanting to take over open ai. He's just forcing them to overpay. Interesting point.
I've been dying to jump in here, man. Not exactly dying, I'm just shaking my head. So let me start with one second.
Elon Musk, Elon Musk. Elon Musk, it's not Elon Musk derangement syndrome. Is that like Beetlejuice?
Where were you going with that? Uh, oh, yeah, I guess so. Look, there is no offer.
Okay, open ai, profit, nonprofit, whoever, Sam Altman, nobody has seen an offer. And so this is another case, yet, another 99 times out of a hundred, uh, uh, of Elon Musk saying some s**t and everybody taking it seriously. If there's anyone in the universe whom you should pay attention to what they do, rather than what they say, it's that guy.
I thought it was a different guy over and over and over and over again. He just said, now he just said some s**t and wound up buying Twitter at one time. He just put, posted a price when he was maxing and relaxing and chatting with who knows who, and you just posted a price publicly and he wound up having to pay for it didn't work out.
So every now and then, right, that happens. But he is just saying, and you know, the, the, the, the elephant in the room, the freaking like, I dunno, mammoth in the room that no one, none of the reporting is talking about is this is an employee of the US government. This is a presidential appointee in the office of digital services in the federal government.
Who is, I mean, you kind of alluded to that, Mike, in talking about, you know, oligarchs and stuff, right? His statements are a representative statement of the US government as well, because he is an officer, a compensated officer of the US government, not confirmed, all right, so a he's just saying whatever. And everybody's like, they're writing articles and they're examining, we're all doing this, we're examining it, we're looking at the strategy, the chess board and all that other sort of stuff.
I'm just saying, he just said something and that's it. It's great marketing for himself, right? The open ai.
Yeah. There, there's a little something I I I, I like this, like deconstruction of the strategy that to puts the open AI board and a funny place and all that other sort of stuff. So I'm not saying there's no motivation, there's no effect of him saying it, but really, honestly, that's all he is doing.
Well, you know, you know, once again, there's nothing here. Right, right. In a sense, what he did was like the other guy, you know, who we, we've alluded to, it's a diversionary thing for a day or two.
We're gonna talk about this, then we'll forget about it, and we conveniently will overlook what's going on with Doge, which actually is the real story involving Musk. This is something he does, but he also wants to inflict some sort of damage and screw around. I, I was gonna use another word with, with open ai.
I mean, it's something he does. Larry Ellison would do the same thing. Remember Larry Ellison had a history of saying, I think I'm gonna buy this company, or I think I'm gonna do this, you know, instead everybody two.
But they didn't do it just thoughtfully just spitting out crap, Ola, it's crap, Ola, there's no intent behind. There's no offer. There's no offer here.
There's just a statement. Yeah. And, and we live in a time when people can say just random stuff and, um, and have it move markets.
So, but do you think he would've actually paid it if Sam Altman accepted the offer? Do you think he would've actually paid it and bought it? That's the the question.
He, he's, he's forced to essentially, other than the conflict of interest of working, of being a federal, uh, officer, he's forced to, just like with Twitter, okay, so he would be forced to, doesn't just like, doesn't, he had to with Twitter, but just like with Twitter, he doesn't actually have this liquid cash and, and this consortium of people that are supposedly gonna be buying it. But that being said, I think if, um, if the open ai, again, nonprofit wanted to accept this offer, I think there would be no shortage of funds and capital at this point to fund it and make it happen. Because that would effectively give a, for $97 billion control of a 200 or $400 billion company.
And that's just a valuable commodity. Lisa Martin, is this the future of conversations between CEOs where they text to each other and then they share it with the press and you have, you know, one CEO calling another CEO allegedly a swindler. I mean, how crazy can this get Well with Elon?
I think it, I think that the level of crazy could definitely go up. I hope this is not the way that CEOs communicate. I think this, he's an outlier in that and an extreme.
Um, but I think executive communications would come in to most organizations and put guardrails around what the CEO is doing so that the organization doesn't get derailed itself, ultimately serving its customers and delivering the value that they expect. So I, I think the level of crazy, I think, uh, you know, we're probably scratching the surface with Elon. Um, it's a bit comical.
You, you mentioned the, the word swindler being used. I saw that this morning. And it's just, it's, it's silliness.
Um, really what it is. And to guy's point, there's no real offer. This is, this is fud, this is out there.
He, maybe he's trying to slow open AI's plans to go for profit down, um, or provide a forcing function for the nonprofit that owns it. But these communications shouldn't be happening at this level, um, for a healthy organization, in my opinion. Mm-hmm.
John, is there room for a white knight in this conversation? Because there's a lot of people who don't like any of the players involved. So is there room part of, Well, Microsoft's invested, what, 14?
I've lost track. It's $14 billion into open ai. Um, I, I don't know.
I mean, it's so early we went through the same conversation, right? Although we did buy Twitter, I mean, for, for a long time, we dismissed that idea. Um, and there were White Knight that emerged during that, that were tended be big, be big tech.
My fear always has been, and I think the fear out here and everywhere is that if open AI were to be sold, it's the, the feeling is that given the climate now in terms of, uh, deregulation in terms of m and a activity, that somebody in big tech is gonna end up owning it. So we're gonna have AI in the hands of maybe three or four major, major monster tech companies. That's the, that's the long term anxiety.
Alright, well, here's my bet on it is that we'll watch this drama play out for a few months and then, um, hopefully cooler heads will eventually prevail and we'll say, you know, we need some serious adult supervision, because clearly these folks are not, should be allowed to play with things that might go boom. So I'm just thinking that, yeah, a lot of folks are gonna go, you know what? These guys are not the guys to trust in this situation, but we'll see how it all plays out.
We'll be back in a minute. All right, everybody, we're back and we're gonna talk about money again, but this time in the concept is called fin, which is the notion that somehow or other we're gonna programmatically put some controls in place to limit our cloud spending and other IT spending and keep that in track with our policies. Screaming is what I have back in the day.
I seen the, remember when, you know, this was called how we run it, but Guy, what's your sense of, uh, is finops for real here? Because we're already seeing, for example, finops companies buying IT, service management companies, and we're also seeing it TSM people just start putting in finops capabilities alongside what they already have. So do I need a finops platform?
Oh, I think you do. But is it an exclusively finops platform? I think that, that it was a really necessary area of, uh, cloud development because of shadow IT and cloud load and like, you know, all, all that sort of thing.
Um, and I think, uh, you have pointed out really well in a lot of venues, Mike, um, that Kubernetes also is this sort of enabling of, let's call it bloat waste over capacity, that sort of thing. All of these are cost and, uh, the, the very nature of the cloud and, and frankly of like, you know, DevOps and Kubernetes is to be able to be extremely elastic and responsive, um, and, uh, to, um, not sidestep exactly, but, but to be able to operate without a bunch of bean counters or, um, you know, uh, frankly, IT infrastructure people or whatever, kind of getting in your way so you can move fast break things, blah, blah, blah. Okay.
So what arose out of that was a 'cause if, if we all remember the good grand old days was how, uh, cloud was gonna save you money. And then everybody started to realize that actually cloud cost more money. I'm talking most about public cloud.
And so as a thing, as a separate thing, finops a platform, a practice finops is more a practice than platforms, really. Um, there's, there's a whole, you know, very successful, uh, uh, uh, consultancy industry, um, around controlling cloud costs in particular, and that that stretches out into containers and on-prem and all that other sort of thing. So, so all that is for the good that that's, that sort of shines a light on the whole issue.
But in the end, and what of these recent acquisitions, um, like, uh, uh, do it acquiring perfect scale, I think you just wrote about that yesterday or the other day. Um, these kinds of moves, um, to bring all of these operations under one umbrella and in particular to, not to stop saying it's just public cloud, but it's all of our infrastructure, all of our cloudified on demand, you know, scalable infrastructure that we need to out, you know, provide the freedom to the developers and application managers to do what they need to do, but also enforce policies in a way so that they can do it quickly, but also not overdue or, you know, that all of this needs to be integrated together. And so if one day we're not calling it talking about finops anymore, and it's just part of CloudOps, great if, uh, we'll still need finops experts, finops practitioners, some of them should be in the financial departments as well.
So now I think, I think this is not only a good and welcome development, but you know, I, unusually for me, I don't see any problem with having this sort of marketing term of finops out there that shines a light on a really important issue that actually is what helps cloudification containerization, all of AI ization, all those things, you know, develop rapidly. What I found was interesting about that article when I read it was, um, when it said finops has, uh, been known to focus more on reducing costs, whereas they really should focus on increasing value. And there's a little bit of difference what focus you come from, and that's why teaming up with a cloud ops team who's utilizing, um, that area, uh, is helpful, coming together with two different teams, one focused on bringing the value.
I think that's right on it. I, I would just dispute, I I I think that, um, cost control and sprawl and all those sort of things are much more the issue than value delivery. I, I, I, I think shining a light on value delivery and getting the most out of what you got is, is correct because yeah, one overshadows the other.
But I think the, the pre predominance, uh, the predominant focus really does need to be on cost and, and sprawl control. I think, I think cost and sprawl control is a, is is sort of the, the useful outcome from finops that allows this to take hold and allows companies to embrace it. Because it's, it's, it's a great, uh, sales message that says, we're gonna save you money, you know, we're gonna address the money that you're wasting.
But truly, I, I have to say, I really found this article incredible inspiring. Um, I, I love the, the, the author's perspective on this. I, I'm gonna echo what Amanda said.
Uh, you know, another thing a couple of you know, sentences down, he said it's about, um, you know, fostering a cost aware culture and creating accountability, which again, is something that those of us in it, we've not really had that. And I think that that actually is a, is a really great outcome as well. I don't know as much about this topic, but I will say that this article was really well written and, and really opened my eyes as to the possibility of what finops is.
Because again, I came at it, like you said, kind of thinking about it. Oh yeah, that's about, you know, keeping your AWS bill down. That's not what it is at all.
I'm gonna say bull dingy. Um, here's the thing, and this is the truth of the matter. IT people, we had capacity planning back in the day.
We had cost controls back in the day for everything on premise. And then the cloud came and we just basically abdicated responsibility for it. We threw it open to a bunch of developers who then showed up at a bar, like a bunch of drunken sailors and started consuming stuff and over provisioning stuff.
And everybody said, oh, well, we can't get in that conversation because God forbid we slow them down with any troubling information like cost. So I think finops is a lovely little term that we've come up with that kind of circle back and maybe apply some supervision to this stuff. 'cause we are freaking out about the cloud bills.
But to sit here and say that finops is gonna be a a practice, I don't know. I'm not buying it. And I think it's part of your job.
It's your responsibility and it's gonna be a core feature into your ITSM platform into your DevOps platform. And the days when we just let people consume things without any concern about cost or over, that's my Tuesday. So you're saying Lisa, Lisa, help me attack Mike here, finops as a practice.
Seriously, It's about, It's been helpful. It's been helpful. It, it has been helpful.
I, I was just writing about this for TechTarget and the other week it, what I, what I like about it as a practice is the cultural transformation that, that we're seeing going on within organizations who, with shadow IT are just spending money and suddenly it's out of control. Um, you know, getting the heads of departments together, marketing, operations, sales services, you name it, and having them understand how they're using it, there's value in that. The outcomes Steven talked about, the outcomes Amanda talked about, that's value.
So maybe it's just a messaging kind of, um, kind of mixed up their costs, optimization versus value. Well, that is a value to an organization. Um, I, I see that definitely.
But I really see organizations embracing the cultural transformation, which is hard to do in order to deliver value to the end customer. And that's what it's all about at the end of the day. Yeah.
Let's, let's you wanna talk about the realities, Mike? The realities today are the same as the realities of 20, 30 years ago, which is that the dev people hate working with the infrastructure people and the infrastructure people wish the dev people would leave them alone so that they could just run a great infrastructure. And what something like a finops does as a practice is it allows the infrastructure people to say to the dev people, just go do what you want.
You don't ever have to talk to us because we are putting the policies in place that we are all mutually. That was another great thing in that article, by the way, was talking about setting a common framework for understanding how resources should be used. So we have a common policy, everybody's bought in, you don't have to talk to us anymore.
You can just go and do your stuff and have fun. And, you know, uh, the finops magic of the tooling and all that other stuff will, will ensure the policies are put in place and you can do what you need to do. I'm not blaming the developers, they just walked into the situation and took advantage of it as they found it.
So it's not really their fault. I am saying it's the absence of leadership on the ING your IT executives that says, oh, now we need a little pin ops flag that we can wave so we can regain control of this thing. And that's kind of silly.
Steven, I argue one floor way. Well, I'll just say this. Uh, it sounds like what we're saying is that we need to foster a cost aware culture and create accountability, which is literally What Our author Tatum Tonin said in this art.
I think we Should accountability. That's a key point. I just think we should take a little responsibility for the situation and not blame it on some magical thing that we weren't aware of and, and then wrap a buzzword around it.
I think what I'm saying to folks is like, look, we're having this conversation and we need to have this conversation largely because you allowed this to happen. That's all there is to it. All right, I'm gonna end it there.
I guess I'm gonna get the last word on that one. You sure guys? Yeah.
We're not you, we're not the, we, we can't have my optimism finish the segment. That just doesn't work. Let's, let's stick with your dark feel of the world.
I, I, I am optimistic that this issue will get fixed. I'm just saying, guys, I don't think we're gonna be using This term for much longer. All right guys, everybody, thanks for sharing your insights today.
As always, spirited conversation, we always like to have those here in the tech strong gang. We invite you all to stay tuned for all the rest of the content that's on Techstrong tv. It's an awesome lineup.
Once again, thank you all for participating and we'll see you next time. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively From Techstrong Research, This is Techstrong tv. Hey everyone, welcome back here to Techstrong tv.
You know, this next guest is a longtime friend of mine in the security world, probably 20 years, maybe more. Uh, he's been also in the security business a long time's, written for many, many different, uh, security magazine and sites, tech media sites, has his own tech media as well as working for a bunch of companies over the years. My friend, let me introduce you to my friend Tony Bradley.
Tony is currently, uh, among other things, a senior contributor at Forbes. Uh, and as I mentioned, he does run his own, um, media business. It's more than just a site called Tech Spec.
Tony, welcome to Text Truck tv, man. It's great to have you on. Thank you, Alan.
It's, uh, great, great to be on. We haven't, uh, we haven't, uh, chatted face to face in while I was gonna, while say it's been a minute. It's been a minute.
Good. Well, between Covid and RSA 'cause that's where we used to see each other more than anywhere co RSA or blackout or any of the, you know, usual security events. I haven't been back, I haven't been back yet.
Um, I was really looking forward to going this year, and then my son planned his, uh, wedding that week, so I will not be at RSA again. Well, that's what I had last year, my son's college graduation. Yeah.
But, um, I will be there for this year, hopefully, God willing, looking forward to it. Um, but anyway. Well, I mentioned tech Spec.
Let's get that out there too, Tony, for people who want to kind of follow your musings views Sure. net. Um, I mean, it's a technology mostly it's, it's, it's a technology news website, but it's got a very strong cybersecurity leaning just because that is my background and that's what I tend to write about more often than not.
Um, Uh, but then, you know, like you mentioned, it's, it goes beyond the media outlet where, you know, I do a lot of, uh, you know, I work with a number of companies doing freelance, uh, you know, content and, and in various uh, ways. So, um, but you know, as you, as you introed me in the first place, I'm also a senior contributor for, for Forbes. Um, so that, uh, is is one of my main outlets as well.
Very cool. Alright. With that out of the way, we've told them who Tony is.
Tony, let's jump into what we want to discuss today. And that's, you know, look, it's all over the news. The new administration comes in, Elon Musk and his, what's it, department of Government, efficiency, doge Dodge, whatever.
Uh, yeah, Trying to just shake things up. I think just, even just the name of the, you know, it's, I, Oh, it's all Willian. There's, it's, It's all willian and it, it just, it, it underscores that Musk and the, the guys that he's got working for him, they're their internet trolls.
Like, you know, this is the, this just, this is just internet trolling stuff. This is four chan stuff. This is, you know, I don't know.
I feel like they, like, I feel like they get off on just being trolls. Well, they are, and you know, in typical Musk's style, everything that he finds is a result of corruption, right? Where, you know, physician healed thyself.
But, um, you know, is the government the most efficient way of collecting and spending money? I don't think any government in the world is, is there a waste? Yeah, there's always some waste.
Would it be great to cut some of this waste? Yes. I think we all agree.
We'd love to see government cut some waste, but there's right ways and wrong ways of doing it. And when we talk specifically on the cyber front of things, you, you can't, don't take this the wrong way, but you, you can't let everyone get polio because you're cutting the vaccines, which may, that's a whole nother story we could talk about. Um, But I mean, you gotta, you, you, you can't create cyber risk and violate cyber rules and regulations in the name of government efficiency that, Right?
So my, you know, when, when I wrote, when I wrote this article for Forbes about the, you know, the cybersecurity concerns of what's going on, um, and, and, and, you know, even if I set aside the, the constitutional crisis, I actually, I can't, I can't set that aside. They, they, they go hand in hand. Um, because I, I, I'm a, I'm a bit of an idealist, uh, when it comes to the structure of our government and, and, and the way us democracy works to the point where it's like, I, I respect that.
Sometimes it doesn't go my way. You know, like, I didn't support w you know, it's like sometimes things don't go your way, and when they don't go your way, we still at least had a framework we had. There's checks and balances, there are things you can do.
There are, you know, you know, there, there are ways to still, you know, limit that. And, and with participate and with back control, in this case, you've got these, the, you know, Musk coming in here with Doge, and you have all these guys who are, you know, don't have security clearances, couldn't get security clearances. The only reason that they sort of have them is by Executive Fiat.
You know, because, you know, Trump says they have them, um, which, but they would never pass a security clearance. Like, not even close Musk can't pass the security clearance. Um, you know, a, a full one.
So to, to allow them in. It's like, you know, as I, as I listed in the article, there are, there are, you can, you can look at what's going on and say, okay, it's probably violating hipaa, it's probably violating PCI, it's probably violating GLBA fsma the Privacy Act. Now we're getting into, you know, because they've gotten into the Department of Education, now you're violating, uh, ferpa.
Like we have all of these regulations in place to protect personal and financial data, and we have an entire cybersecurity industry built on selling solutions to do just that. So you can't then create a government agency again by executive Fiat, by the stroke of a pen. Just say, Hey, I, I've created this agency.
And, and their job is to violate every, every law we have to get access to this data. And so, coming back to where I'm an idealist, I respect that the election didn't go my way and that I don't agree with the party that controls the House or the Senate or the executive branch. But if you want to get around hipaa, if you want to get around fsma, if you want to get around the privacy Act, I follow the damn process.
Like there has to be, someone has to introduce legislation, there has to be discussion, there has to be a vote, and then fine say, you know, put that in place. But there has to be some, some sort of controls. It can't just be, you know, oh, well, we're just going to pretend those laws don't exist in this case.
Um, and, and it also just, it, I, I know there are many people within the cybersecurity world who, who do support this administration and, and the party in power. And I, I can't get over the sort of like hypocrisy and irony of someone supporting this and then going out to talk to prospects and customers and try to sell them solutions that will guard against data, data breaches and, and protect personal information. It's like, no, you're literally supporting the undermining of it.
So, and, and from a federal perspective, it's like, how can you enforce these laws at this point? Like if you're, if you're not willing, uh, if you're, if you, if you are violating them all yourself, then you've lost your standing to, to, to go after anyone else for violating them. So Tony, I look at this and, and it falls into two camps for me.
One, I think is the one you are talking about, where have they exceeded their authority, right? 'cause the fact of the matter is, as far as I know, there was no government legislative, uh, bill or mandate to even create something called DOGE, right? There is no legislative mandate or law or Bill to do what they're doing, right?
So if you're gonna play by the rule, right? Our, our form of government is not truly a democracy. It's a republic.
And, you know, one of the key pieces the founding fathers want was to prevent the tyranny of the majority protecting the rights of minority. And, and so, and that's why in the Senate, you have filibuster rules and you have the 60 votes and, and you have requirements. And the Congress holds the purse strings, unfortunately, for whatever reason, maybe the system's not reacting fast enough or whatever, but I think ultimately the legislative branch will have to become more involved.
Well, well, the courts may force that, and it'll be a question of do they obey the courts or not, but to keep the politics out of it for a little bit. Tony, there there's another aspect here, which is, and you hit on it briefly, which is the cybersecurity rules. These are nonpartisan, nonpolitical, you've gotta protect personally identifiable information.
You can't, you know, classify data that that's a longstanding, uh, in our government, a longstanding rules and regulations on who has access and what you can do with classified secret, top secret data, right? You can't hire 23-year-old kids off the street without background checks and give them potential access. And, and, you know, that to me is this is, yeah, this, this bad.
Well, and, and you know, there's many stories out there, but I've seen reports that, you know, they were going in just connecting unencrypted USB drives and offloading data, and it's like, you know, I agree with you. It's like, well, no, like again, if you want access to this, and if, if you want to analyze it for whatever, like, you know, let's, let's, let's take a step back and say that Doge was an actual agency, you know, created by an act of Congress, and we gr granted them access. Great.
There would be a process for that. You still gotta follow the rules, Right? They, Like, you still, there's still cybersecurity regs here.
And, and to your point about some of our PE friends in our discussion of a friend of mutual, friend of both ours, the printer guy, if you know who I'm talking about, right? He's, he, he put out a thing, well, what's the big deal? It's just payment systems.
It's not like it's really classified. And, you know, we've gotta stamp our corruption. Stamping our corruption is not carte blanche to do whatever the hell you want.
Sorry, again, I come back to there, we, we, we, we, we, in theory, we have a representative government. And, and those representatives need to have some sort of say, they need to be a part of this process. And while I, I I, when I look at it and I say, okay, well, is that just slowing things down for the sake of like, like if, if, if the people who control the house and the Senate are ultimately just going to rubber stamp it anyway, then, you know, or you know, it, it is just, it, it's becomes sort of pointless.
But if you want to, if you, if you said, okay, look, we think there's fraud here, then the normal process is you investigate and you say, okay, here we've, we've, here's the fraud we found. You present that there's some discussion and there's a decision about, okay, well what do we do about that? It's not just we've ripped it out.
And, you know, before you can, even, before you can, even before you even know that we we're investigating the fraud, we've already like taken the site down and, and done all, you know, I dunno, it, it's, it's, it's just like I said, I, I just want, I want the whole government involved and not just this small band of, uh, people Agreed, agreed. But even with the whole government involved, we are a nation. And you know, this is a cliche, but we are a nation of laws and there are rules and regulations, especially around cyber and around sensitive information that we cannot take shortcuts for, whether it's in the name of stamping, our corruption or, or Jesus' name or anything else.
You can't, you gotta follow these rules there. They're there for a reason. Well, and we, you know, in, in 2015, there was the, the, the hack of the Office of Personnel Management that was attributed.
I remember Chinese, Chinese threat actors. That was a huge deal. It was a huge deal that, you know, unauthorized people, you know, a nation state had access to this information.
So now we've got these, like, you know, whatever, you know, college dropouts or whatever who, who with no security clearance, who have access. And, and that's actually another one of the things that is driving me crazy lately is the, oh, well, you know, we have to ban TikTok or nobody should use deeps seek because of China. And, and I see a lot of people in the cybersecurity world who, and the thing is, I don't disagree.
Like I agree that China is an adversary and that China is a nation state threat, uh, on some level. Like, I agree with that, but I'm like, that's not my main concern. You're a, you're asking me to be worried about a potential threat across the world while someone is in my house burning it down.
So like, I'm not worried about deep seek, I'm worried about X, you know, I'm worried about Facebook and meta. I'm worried about the, I'm worried about the, the, the, the, the United States based companies that are doing the exact same things that we are always worried about nation state adversaries and, and, and cyber criminals doing that. We're just allowing, I, I, I agree with you.
I, I, I mean, quite frankly, you're a hundred percent right. I, it's not that we're just allowing, are we worse than even some of these others, right? Because, and also, what message does it stand where those rules apply to you?
Not to us. And, you know, and I'm, I'm doing it flouting that I'll somehow, I'll be, uh, pardoned or I have some immunity That goes into the political side that, again, that, that creates a whole, I mean, I've got a whole bunch of concerns on the, on the pol political side of that. We have, you know, again, a House and Senate who've basically abdicated their responsibility because they're just, you know, they're just not involving themselves lives.
Mm-hmm. Um, it, there are reports that at least some of them it's because of, you know, they've received death threats and they don't have the, the, they, you know, they don't wanna stand up to that. So they're just capitulating.
But if you Don't or they don't wanna be primaried, But I don't, I, I can't, I can't, I can't stand that, Alan, I can't stand it. No, it's, I know, but you were left, left to do a job. I think most of the people, Tony, most of the people who have principles or whatever here, they've already left the building.
Elvis has left the building. I, I, I guess because whenever someone's like, well, you're gonna get primary, they're like, then get fricking primaried. Like you're, and They did already.
And if doing your job means that you get elected, you get voted out, then get voted out. Because what's the point of staying? Like if, why are, why are you staying there if you, if you're afraid to do your job?
So we're almost, we're past our 15 minutes. Lemme tell you, bow on this a little bit. Alright.
I do think we are rapidly getting to the point where the courts are at least attempting to put the brakes on. A lot of this are, are saying, Hey, proper procedures, policies, regulations need to be followed. I think the next, I I, and I don't want to get all dramatic and call it a constitutional crisis, but the next tipping point that we face is, does Doge and the rest of the executive branch follow or adhere to the court's orders?
Or did they attempt to ignore the court saying, we'll, just keep appealing it and by the time the appeals are heard, Right? Right. Possession's, not intent to the law, Told they'd been told to, you know, remove their access to the Treasury Department and delete all of the data they extracted.
And it's like, well, are they gonna do that? I think that's really the next stepping point. As I said, who knows?
So crazy stuff, Tony. Yes, I know you though, you'll keep writing about this and speaking out on it. net as well as in your articles on Forbes.
You know what, we gotta keep fighting the good fight, my friend. True. So, glad to, glad, glad to, glad to fight with you.
All righty. net here on Tech Drunk tv. We're gonna take a break.
We'll be back in a minute. Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Bazar today with Maggie Laird, who's president of the Pentaho Business Unit for Hitachi Ventera.
And we're gonna be having a little chat about well data repatriation in the age of ai. Maggie, welcome to show. Thank you for having me.
Good to be here. When I was much younger, people used to tell me nothing good can happen when you move data. And yet here we are talking about moving data.
So from your perspective, what is driving all this activity where folks seem to be moving, um, workloads and data, not just from the cloud back to on-premise, but sometimes the other way as well. Um, I think there's more data moving now than I can remember in my entire years of doing this. Yeah, no, it's certainly an exciting time for data.
I think gen AI have brought the core data management challenges to the front fold. Right now, from my perspective, what we're seeing with our customers is, is the gen AI adoption experimentation, right? Companies are trying to figure out the right spot for the data, right?
So, so things are moving around. Um, some of it's coming on-prem. They want to bring the data, bring AI to the data, right?
And be able to control it in a very, um, measured way, right? And then other companies are, are try, once they know what they need, they're putting in the cloud and run an operating it. So it's, it's really this, uh, from my perspective, some experimentation, um, around how to most effectively and economically, um, take advantage of the VA opportunity that is in front of us.
So a lot of folks out there trying to figure out what, what fits. Some Of this also feels like to me, to your point, they're building the first rev of the AI models in the cloud because that's cost effective. But when it comes to deployment, uh, and the inference engines, that needs to be either on premise somewhere or even at the edge.
Now I've gotta take all the data that I use to create the model and get it out to the inference engine. So is that part of this conversation? I think absolutely.
So run, operate is what you're talking about, the AI ops. Um, so once we're ready, once we know what we're doing, once we're convinced of the value, once we know the quality, right? Once, once all of that is known, um, how do we do that at scale, right?
And what does that scale mean, right? And I think that's where the cost equation is coming in. Um, being able to be predictable around that cost and for some companies that are running are gonna be running a lot of volumes through this.
That's on-prem control, visibility, predictability, um, again, is, is is coming to the forefront and being able to really wanna have those guardrails and understand, um, how, how it's gonna work in a very controlled environment. Um, I think you're absolutely right. Aren't we using traditional kind of batch oriented processes to move that data?
Or are we shifting to more of these streaming platforms? And it seems to me a lot of this conversation is just trying to make sure the right data's in the right place at the right time. Yeah, absolutely.
That's the name of the game. So I think it's both, right? We're seeing realtime streaming data come in, we're seeing kind of the data at rest as well, because to unlock the value of, of a lot of this, you need all of that kind of moving.
Um, so, so then it, it's about the core elements of data management. Do I have the right data? Right?
And we don't need to take everything, right? So making sure that that right data, um, that has the right quality to that, I think that's where folks are learning a lot about the quality of their data. 'cause they put it in here and they're getting outcomes they didn't anticipate that doesn't look right and they're having to go back into the core data itself to say, Hey, did we bring the right data in because this isn't, you know, what we were expecting?
So that, that real inspection of, of that source data again, is, is, is becoming real. So again, what did we bring in? What is the quality of it?
Um, do we understand it? And, and again, do we trust it to be ultimately making decisions now? And it, you know, at a, at a much different, um, um, scale than before.
We have a tendency to be critical of the AI models 'cause they will hallucinate. But how much do you think the real core issue is just that the quality of the data that we're exposing to the models is somewhat flawed. And, um, you know, issues that we've kind of sort of known about for decades are coming home the roost.
That's a big part of it. Um, that's what we hear from our customers who have maybe jumped farther fast to, to try to get started to have a proof of value. Um, and then they get caught back into the core challenge of data management and then they've gotta go back and start again because again, they, um, you know, been able to bubble gum and bandaid their way.
Some companies have around that, these core data challenges. But AI is exposing that risk. There is too much risk from not having, um, the quality right and the right data at the beginning of the process.
So it doesn't, it, it, it does become a roadblock to production, right? Um, you can learn some things with some sample data, right? And you can manually clean some of this in a, in a, in a very experimental way.
But when it's time to go big, right? And to put this into production, you've gotta have, you know, that scalable, um, an underlying quality of that core data, um, you know, understanding that and, and ready to go. Is there a greater appreciation for data management?
And we've been talking about this now for years and years and years, but I felt it was always around the structured data and the unstructured and semi-structured data we kinda overlooked a little bit. Let's say very few people would get a good housekeeping seal of approval for the way they manage that data. Um, so is all of this bringing, you know, a focus back on the fundamentals of data management?
Yeah, now I think that's exactly what this is bringing to the, the forefront. There's more of a burning platform, right? It's always been a good idea to have a good quality data, right?
And to, to maintain it well in a cost efficient way. That's good hygiene. But you know, today's world, it's, it's actually required to be able to do, um, the innovation that folks wanna do on, on that data.
So, so it's, it's back to reality, back to the basics, get it right, do the work, um, because the work's gonna be exposed if it's not, um, if it's not done in the right way and in a way that can be, can be scalable. So I think all those, all those cheap data officers that, you know, they're getting an analytic, getting more of an AI remit now, um, it does kind of go back to the core. Um, and so, so again, it it's, it's a good, if you, if you didn't take the steps at the beginning of the process to, to get it right now is the time, but the key messages are not gonna go very fa far.
You may go fast, but you're not gonna go far until you, you know, isolate and really do the work at the foundation. And I think that's, you know, where Penta is really focused is helping companies get that foundation, right? Because you gotta, you gotta deal with it now before you are able to take full advantage of, of the innovation off the backs of ai.
You know, I was just thinking about this, but back in the day, the data more often than not was managed by somebody who we generally refer to as the storage administrator or something who was an administrator. And now every time I turn around, um, there are data engineers that people want. So has the nature of the profession changed and what's required?
Because last time I checked anybody who was called an engineer costs a lot more than anybody called an administrator. Yeah. I mean, we're seeing, um, you know, certainly the, the expansion of the need to have higher level data skills for sure, right?
And also some of these roles are starting to blend inside of the, the IT organization as well. And then Mikey didn't even mention the, the AgTech workforce that may be coming online as well. So, so here we are, and you, you kind of step back and you look at how this will be managed, right?
And then who needs to manage it, what skill sets they would need, and really what, you know, they're, we're, we're blending a lot of, um, automation inside of, of, of these skills as well. So, so I absolutely think that under that, a deeper understanding of this, of the engineering of the data is required, um, but also again, what can we look to and how can we make that data as most prepared for, you know, again, an adjunctive workforce to be able to help and assist, um, ultimately in the, the management of all this data moving forward. And so to your point then, can we expect to be using AI to manage the data that we need to train and build the ai?
Yeah, I think that's where we, where at least we see it headed, right? Um, it's gonna, we've gotta take the right steps to get there. Um, but it really is infusing AI into these core data data processes to make them more efficient.
Um, you know, you, again, we gotta step through it with the right guardrails to understand how that's happening and keep those humans in the loop as, as we begin the journey. But absolutely having, um, those automated ways to build brag pipelines, right? How to, to do some of these things that, again, took a very sophisticated, you know, skillset to do.
You know, again, this is kind of the work here at Penta is how do we get that into more of a data citizen world to be able to do more? Um, you know, with, with all that you have again, um, in a, in a user in a way that's very, um, can boost the outcomes but doesn't require all that, um, you know, all those advanced skill sets that, you know, that's where the, that's where the automation and the AI comes in and, and, and then you get to get the results a lot faster. Is all this gonna lead to some need for increased transparency into what data was used to train what model and what was used, where to run it in a way that is much deeper and maybe more profound than we're used to?
Yeah, I think absolutely. And you, you can see this with the AI regulations popping up, right? It really is about transparency, transparency.
Um, and so, so yeah, so companies are, you know, honestly having to happen to pay attention in terms of how, how they build, um, you know, what are those regulations coming, coming through to make sure that, again, they're, they're building the right hooks into the processes so that they can see, um, the data that's, that's coming in. Um, what it was there to do. Was there any data that was injected in there that shouldn't be in there?
So again, companies are gonna, if they don't already have, have tools, um, and systems like data catalogs that help to provide guardrails, to provide visibility. 'cause ultimately if you've got a regulation around something and you wanna be compliant, you've gotta be able to produce, um, the report or the ballot, the justification that says, this is where we're getting that. So, um, companies need to be mindful of that as they are bringing, especially as they're bringing things into production.
Did they, are they setting this up, this right this up for that transparency that ultimately, um, even if the regulators aren't out there asking for it, I guarantee that the business users are gonna wanna know where did this come from? Are the C-level executives more conscious of these issues than they have been in the past? Where I think they tended to view this as some sort of, you know, lower level IT issue, but is do they understand now the value of the data and exactly the use cases for it and how it kind of drives a process?
Is, is the conversation getting elevated? Yeah, absolutely. I'd say, I'd say C-suite and board level as well.
I think that's where, um, it is this kind of renaissance room for, for data. Um, you know, having ai, having CEOs talk about AI processes, I mean, who would've thought about that 10 years ago, right? Um, and we, there is, you know, when I'm out there meeting with, with our customers leadership team that, that they are fluent, um, on the topics right now, the details, but they're asking the questions, right?
And they understand that this, this is, you know, a source of risk, it's a source of innovation, you know, and so tho from, from those two pieces, then as they start to drill down and ask their organizations for, you know, plans and, and, um, you know, and, and proof of concepts and, and really point of views and governance, it, it's, um, it's, it's great to see from the data world this elevation and it, it matters. Like this is a, this is a big deal and it's, it's very core strategically to company's strategy, right? Um, as they move forward.
If you don't have AI in a strategy, I think your board's gonna be asking you why. And that's a very different situation than we were in three, five years ago. As part of that conversation, do you think that data management and data security is gonna converge more than it has in the past and there'll be more focus on how to management of data in a secure fashion?
Because I think those two things have been somewhat or orthogonal for many years. Yeah, exactly. I mean, depending on the architecture of where the data was sitting and who was controlling it, right?
That we are seeing a lot of that merge. Right? And the access, the access to the data, right?
And the secure security of that access. Those two things are, you know, front and center because, you know, I think, uh, in our consumer lives, we're all starting to realize, you know, when you are inter interacting with these models, you're, you're giving, you're getting something, but you're giving up something as well. So the data exchange, um, around that, and you bring that into the enterprise environment, you've gotta be very, very careful about what you're giving to whom, and then how that's being secured in your environment.
And then what, what are the open doors that you have out? So, absolutely, I think the data security, privacy, access, and control, it's, it is a convergence because it all has to be solved in order to, um, you know, kind of bring the right outcome at the right risk level to the business. So, as you look at organizations that you work with, what are they, the ones that are getting it, what are they doing right, that others are not?
Then you kind of, you know, that you wish other folks would kind of crib. Yeah, yeah. We're definitely seeing some best practices out there.
Um, I think companies that are taking a strategic approach, uh, and really thinking through, they, they're not gonna know everything, but they, they've got a strategy behind their, their architecture, right? They've, they understand they're likely gonna be in a, a hybrid world, but then they ask the questions, what they get down to the workload level, right? And they start to really plan around what, what needs to be where for what reason?
So with the, the cl, the more detail you can get into, you know, where does this data need to be to support the workloads? Then you can start to architect, you know, the right environment around your data with strategy in mind, but also cost in mind. I think this is just one that is a red flag right now for a lot of people as they're starting to get their bills, you know, from their cloud providers or, you know, maybe even, you know, on the other side, they, they're examining their costs all the time.
This, the cost piece is really real. So bringing the economics into the strategy, you know, to the workload. Um, and then also those folks that can look at their data and, and make sure they're being really optimized around the estate.
'cause this, again, it data is exploding. You mentioned the un un inter unstructured to the scene, right? Okay, now, now we're really exploding.
You gotta be smart about what you're maintaining. You don't need 50 copies of that same file, right? So I think companies that can take that big picture, bring it down to the details, and then start to make, um, you know, the decisions from, from that lens are the ones that, you know, will wi are, are kind of winning right now.
You and folks, you heard it here, they say data is the new oil, but what does it matter how much oil you have if you can't manage and process it? So there we are, Maggie, thanks for being on the show. All right, thanks, Mike.
All right. Thank you all for watching the latest episode of the Textron AI series. You can catch this episode and others on our website when you'd invite you to check them all out.
Until then, we'll see you next day. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content, content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Hi everyone. Welcome to another episode of DevOps Unbound.
You know, uh, we were reminded by our producers right before going live on the show that the very first DevOps Unbound was in August of 2020. So we have been doing this now, going on four years, two months. We we're into our fifth year of DevOps Unbound.
And that to me, is just mind boggling. You know, it was a, I don't want to take too much time away from what we want to talk about today, but DevOps of B was originally the brainchild of, at the time, the CEO of Tricentis, my friend, Sandeep, Ari, and myself. And we brought Mitchell in very early, and at the time, it was the check center, CMO, Brent, and I forgot Brent's last name.
And we, we concepted out this idea of doing a biweekly video podcast series that would explore all aspects of DevOps. And even though Tricentis, and this was point of years ago, right? Tricentis obviously very focused on continuous testing and testing.
The Tricentis folks thought it was very important that we explored the full spectrum of DevOps. And over that time, we certainly have, and not only that, but we've stayed current as new forces. And, you know, new technologies came into the DevOps space, right?
We're gonna be talking about one of them today, ai, but, you know, I don't want to say attaboys or Pats on the back, but man, four plus years. Rodney, congratulations to our tech strong team and our tricentis partners who co-produced this. A special, special shout out, Jody, Ashley, and Ly nor who never get on camera, and I'm not gonna force them to get on camera now, but these two gals, you know, week in, week out, month in, months out, they, they pick the, the topics.
They source the guests, they get the abstracts done. They, they make the trains run on time here. So shout out to Jody and Lin for all, all of their work over this time.
Let us now though jump into today's show. Today we're gonna be talking about AI governance, very timely topic in DevOps testing and everything else. Uh, before we jump into it though, let me introduce you to our amazing panel.
First of all, she's a frequent guest on Textron events. She's a friend of Textron, as a matter of fact, she's in the tech strong. Actually, two of our folks here are in the Techron gang, but she is the CEO of Deploy hub.
And, um, also an open source board member extraordinaire. Tracy Reagan. Hey, Tracy.
How are you? I'm doing great, Alan. How are you today?
It's great to be on this conversation. You know, I'm always, you know, ragged about ai, so I'm glad that you invited me to this one on this call. I hope that we really kinda dig into the technical standards, because that's the area of interest I have, because if we have technical standards and potentially we can start building those standards into our DevOps platform, and I say that because I know that we, you know, we're, we need to build security into DevOps platforms, and we have this on our tail building some sort of transparency and accountability into the DevOps pipeline for, uh, for ai.
So a huge new area, and it's great to be on this call Joining Chasey and I from Tricent. He's, he's been on a few times before, over the last four and a half years. Martin Klaus.
Hey, Martin, how are you? Hey, Alan. I'm doing well.
Thanks for having me on the call again, appreciate it. Uh, and it was great to see you in person a few months ago. Um, yes.
So I am responsible for, uh, customer engineering at Tricentis. I've had multiple roles including product marketing, product management, and one of the things I get to do in my, in my role is to actually work with customers who are, um, defining their own AI strategy. And so, I, I'm involved in a lot of conversations where customers are trying to figure out how, how do I introduce AI in my organization?
How do I make sure it's safe, it's secure that the data stays in our data center and doesn't get leaked, uh, out on the internet. Um, and also how do we test AI technologies, uh, so that they're safe to be used in our environment? And so that's a really fascinating, uh, conversation to have with customers of different vertical industries and different segments, because they each have slightly different requirements, but they're also together all looking for the same thing.
So I'm looking forward to the conversation today and talk about regulations and governance. Fantastic. Thank you, Martin.
Um, next, she's also a Text Strong gang member and frequent text strong, uh, event guest, our own Hope Lynch. Hey, hope, how are you? Hi, Alan.
Uh, so happy to be on today. And funny enough, Tracy and I had a conversation recently where we started digging into, uh, AI and some of, uh, what we saw as the issue. So I'm so happy to be here today to talk about governance because it's, it's a critical topic.
It's great to be able to elaborate on it for a lot of people. Absolutely. Thanks, hope, and it's great to have you here.
Thank you. Next, well, actually less, but certainly not least, he's my co-host all for every single DevOps Unbound episode we've ever done. He's also the CPO here Ad Techstrong, as well as VP analysts for DevOps at the Futurum Group.
Mitch Ashley. Hey, Mitchell, how are you? I'm doing real well.
It's a, it's an interesting time to address this. Dora just came out with their report and kind of put the pin on the AI donkey saying that's causing us to be not as efficient, which I don't believe that's really happening. But, you know, so getting into governance, we are trying to figure out ai, so it's a good time to be talking about governance, technical standards, regulatory, how do we do this, right?
So, so folks, look, it's been, I think about two years now, right? Since chat GPT, just about two years since chat. GPT burst on the scene, I think it was November or two years ago.
And, um, and it's sucked the oxygen out of the air of every conversation we've had on tech sids just about it seems we're always discussing it, and we've seen the gamut of this is gonna be the greatest gift to mankind ever, right? I'm reminded of that old movie where they have the, the book how to, how to serve, or How to Serve man. Mm-hmm.
And it's a recipe. Um, versus, versus, you know, the, we must put the brakes on AI and stop it, because it'll be the death of us all. AI will fight this imperfect something out of a Star Trek ger kind of episode, right?
And, and seek to destroy humankind. Um, I'm a firm believer that progress stops for nomad. And, and I think that's certainly been the case with ai.
It has moved ahead, full speed ahead, dam the torpedoes. However, in typical fashion, we have seen some governments, not many in the US unfortunately, but some governments have started to try to put some governance. That's what governments do.
And governance, uh, you know, around the use of ai and some private industry, public consortiums are trying to establish rules of, you know, what's ethical, what's right, what's not, right? Where does it tread on humans and human rights? Where does it help?
You know, what, what's the right, what's, what's wrong? And right here to do. Obviously, some things are clearly wrong, right?
I mean, using it to, for mal, you know, my living mal, I always mispronounce that word. Using it for bad purposes, right? Is never a good thing.
These deep fakes and seeing it around election season now, you know, prevalent use, no one thinks that's the right use for it, but there are right and wrong. Um, Tracy Hope, I know you guys, both guys both have strong feelings on this hope. I'm gonna let you go first, if you don't mind.
Okay. What do you think? I think, uh, as far as governance, one of one, one thing that comes to mind, as you were mentioning, um, you know, the eu, they have the EU AI Act so that they can have comprehensive enforceable standards.
There is work, I think, also happening in Canada. Australia, they're sort of looking to see what's happening, uh, in the eu, but in the US I think it's gonna take a little longer. But I do also think if there is a company that can say that they are taking these steps to have critical oversight governance, so that, um, you know, it's not a black box, maybe it's explainable, they can ensure that there's no bias.
Uh, there'd be a little bit of a first mover advantage there. I know that, uh, some financial organizations, I think Capital One is one that is taking steps in that direction, but there is a long, long way to go, uh, to get AI governance across industries and to be something that I think is pretty commonplace. Arnold thoughts?
I, I, I wanna point out that there, there is work being done by the US government as well. We have the Yes, true, true. We had the Algorithmic and Accountability Act passed last year.
That's right. And they, and they kind of addressed many of the same things that the, you know, the EU is trying to address, which is this idea of accountability, really. Mm-hmm.
Um, you know, uh, particularly around what, and all of these go, all of this governance is really just around high risk AI applications. Mm-hmm. You know, surveillance, um, hopefully medical and warfare.
Mm-hmm. But we, the, the US is, is making some progress, but I do feel like a lot of the governance has been turned over to the, um, European Union, uh, ever since the GDPR we're still, like, you know, they're doing data stuff, so we don't have to, but we, but the US government is still, they're looking at it that that bill was passed, and, you know, it says, Hey, you've gotta make sure that you're developing, uh, fairness and, and, you know, minimizing bias and promoting transparency and mitigating any kind of discriminatory, uh, discriminatory outcomes. Mm-hmm.
Um, you know, all of this, when I think about it, I, it's kind of morbid, but I think about the opening scene of robocall, Right? Detroit, And recently there was this insane article that came across and, um, tech on Text Crunch about Silicon Valley having a discussion of AI weapons should be allowed to kill people. Oh, wow.
Okay. You know, it's like, duh. No.
Well, that is, I think that's the first law of robotics, right? Yes. Mm-hmm.
Yeah. Asma last asmas lot of robotics. And that's when that scene went from the robocop was right.
The Robbi goes, you know, slaughters the entire board. Mm-hmm. So, uh, you know, so I'm sorry.
Why we have, why we have, well, we have governance, um, and it's only around these, these high risk systems. I feel like we have a long way to go to start trickling it down to all systems that are being written and being able to take these technical standards that's like NIST is working on, and apply them through the DevOps pipeline to start actually working to make sure that they are transparent and that some of these tools now can be applied, uh, to the process Opening. I get it.
Of, uh, of Terminator one too, by the way, crushing the skulls of humans. But Terminator robots, um, sorry, Martin, I was just gonna jump in and, and say to me, it's fascinating when something comes along that's akin to security, it's akin to data that gets this governance, and how do we do it properly so that it doesn't escape from the lab or escape from the application data doesn't leak out, um, or in this case, do harm. I mean, you know, other software could do harm too.
Algorithms could as well, you can argue whether social media does that, but AI has really jumped to the top of the list of what are we gonna do? What do we have to do to, to secure this? And also make sure it's not used for nefarious purposes.
So, Yeah, sorry. I think it's interesting that, that you see folks like Sam Altman or even Elon Musk, uh, even asking governments to step in and help create some rules or guardrails, because to see the potential of where this technology can go, I'm not sure we're quite at the turning level yet, or robocop, what have you, but because it's going to be an evolution, uh, but the evolution's happening really, really fast. And I think we're already a little bit on the back footing, uh, with, uh, some regulations as it relates to use cases outside of business.
Uh, for example, you know, uh, kids in school using AI systems to do the homework for them, uh, which, you know, now puts education systems at, you know, the back footing in terms of like, how do we deal with the situation when we require essays to be written as part of like entrance, examin entrance requirements for universities. And now anybody can just generate an essay in the voice of Ryan Gosling, of whoever, uh, you wanted to imitate and, and sprinkle in some grammar mistakes and punctuation to make it appear as if it was original authentic work. And so, that's just one example of where we're thinking completely new on chart territory because, uh, we don't know yet know how this technology can be used and applied in some cases of thinking, especially in the business context and the kinds of customers that I'm talking to.
Um, the, what I'm hearing is that there's definitely a need for transparency. And I think that's one thing that we could sort of check out very easily, because companies are asking for where is the data gonna be? What is being processed?
What happens in transmission? What about encryption? Um, who wants to the results?
Who wants the, you know, the models? What models are you using? And then how do I customize it and make it my own?
Because I do not want my data to get leaked out on, onto the, at all. But it's a very broad field, and I think the way, um, for example, the European Union and or the House White House has also been proposing is a good one to say. Let's think about this from a a point of view of, of risk.
What is unacceptable risk, as you mentioned, trace's surveillance, um, or, uh, protected groups, uh, in, in society and other things that, uh, or medical, uh, applications. There may be areas of unacceptable risk where, you know, we, we need to actually have some laws in place to, uh, to control those things. And then you work your way down in terms of high risk, low risk, and other use cases where, you know, uh, it's, it's a less of an issue, but this is a extremely complicated, important topic that affects all aspects of, of life.
I, I, I don't necessarily disagree, but talking to someone who's from the generation of, no, no calculators allowed in the school test, right? I, how many did, did you, are you allowed to bring calculators into your test? No, no, no, no.
But kids today, they bring scientific calculators in. They no longer have to worry about doing those equations and figuring pie and all of that. It's all there for 'em.
I think we're gonna come to the same thing. I, I think, and call me radical, but I, I think when we get to new technologies like this, our, our part of our makeup is to think, go slow. Go slow.
This could have repercussions we haven't thought through. And we know, quite frankly, that that never works, people, right? If you outlaw guns only, guns only outlaws have guns, people are, they're still gonna be a segment of the market that's gonna go as fast as they can.
Um, I think almost these governance breaks, if you will, these governors on the use of these technologies is to give our society a chance to catch up, a chance to get acclimated, a chance to get comfortable with what this, what these technologies can do for us. And I think if we recognize that, we could look at them in a whole new light. But I also think it begs another question of how do you test for AI governance?
Right? I mean, Martin, I'll throw it at you. You're, you're about zenes, you're the worldwide leaders.
How do you test for AI governance? How, how would you, you know, who's, who's minding the, who's watching the watchers here? Yeah, I don't think necessarily that it's possible to test for governance when you need to be able to, uh, well, it's more about transparency and really sort of, you know, like in the case of security, right?
Like companies are used to, you know, expose and report and, and, uh, sort of showcase, uh, what sort of, uh, security policies and governance they are implementing the products. And, uh, and we have standards around that. If you look at SOC two, and if you look at many different encryption standards, um, I think on the security side, we have gone of, uh, have come a long way already.
I think that could be analogous to AI as well, to some extent. Um, but the thing that I see with our customers that, that we speak with is that like, how do we effectively test an AI system that gives you reliable results, um, uh, in addition to how it works at the, you know, uh, is it safe to use, right? So is, is the outcome useful and applicable, uh, and safe to use as well?
Is it the technology safe to use as well? That's where I think we are in also new territory, because if, um, AI models are passed the Turing test, then it's a knowledge system, an expert system that, you know, uh, can involve with time, then it's going to be much more difficult to, you know, come up with prompts or tests and parameters to say, yes, today the answer I got back was acceptable. But what about next week, next month when the now system has evolved and now it has been enriched with new information or with new, uh, you know, adaptations or ratings, learnings that will, will now yield a different result.
And I think that's a challenge with testing that it's no longer at point in time activity. You have to almost like have a, an ongoing monitoring system in place, um, but you also don't know what you don't know and what you should be testing for that could be exposed through some sort of loophole. And I think that's what some companies are finding out the hard way.
Like if you look at some of the, you know, Canada examples, for example, where it gave wrong responses and now there's a lawsuit and so forth. Um, and that's the challenge I think with testing ai. What we do internally is we're trying to sort of adopt this monitoring model, uh, where we are going, uh, on a regular basis, benchmark test and validate, um, and have sort of a, a red team approach as well to say like, how can we expose, um, the models in a way that, uh, the results we're getting on a longer in line with what we it to do.
Um, unless there's a new way to, uh, figure out, you know, testing of not the testing models, uh, I think, you know, that's going to be the approach that a lot of people will, will need to take as well. Yeah. A couple of things I would like to, uh, insert here.
For anyone who's listening and is trying to, I guess, wrap their heads around, how would I start to do these things? There are tools out there, and you still have to know what you're doing, but you could look at, um, uh, Q flow, ML flow, um, they help with, they can help streamline building, deploying, managing your machine learning models, actually at scale, um, open source tooling. So, uh, it definitely, you know, there's always a learning curve for these things, but if you're looking for some tools, uh, that can help you get started and figure out what you should do, um, those are two pretty good ones I think that folks can use.
And then I wanna add too, on this topic, um, there's, there's, there's two levels here. We have testing and we have compliance. So if we look at what we've done through, you know, over the last five years in security, we have done everything from adding signatures to, um, repo scans to things like open SSF scorecard that looks and determines how safe software potentially, um, could be.
I really believe that these types of tools will also be created for looking and, uh, how compliant AI software is. Now the problem with compliance is that the data is often fragmented, and maybe you can look at a git repo for one particular component to see, uh, how, how compliant that component is. But it is a first step.
Compliance is a, it will be, it is important today in security in software, and it will be important in securing and making sure AI software is safe. So while testing is important, understanding the compliance levels of the code that's coming across the supply chain is not gonna change. We're just gonna have different types of tooling to make sure that the, you know, that it's, that the model is fair.
For example, how do we scan for that? Not sure. I think IBM has something called like IBM 360 that, that does some kind of fairness check.
So as, uh, you know, hope pointed, pointed out, we do have tools out there, and that's why the technical standards become more interesting, because if we can define what those technical standards are, we can also define the compliance levels that we need to achieve. And while we have seen a lot of these governance docs, um, from NIST to the eu, uh, talk about some of the basic pieces, we still haven't seen a really clear roadmap for what is compliant. And we haven't done that for, for code in general.
So maybe we'll get there. We're trying, but we have to look at the compliance question and how do we track and report compliance? So the companies are writing software and consuming these, uh, large language models have a way to judge how safe they are.
You know, in some ways this is, you know, there's compliance against standards. I, you have to have something to test against, right? Which I think is lar largely what we're saying.
And there's two forms of it. One is IEE and nist and, and, and regulatory types of definitions of what those standards are, what what you're testing against. Oftentimes though, compliance isn't testing against someone else's standard, it's testing against your own standard.
So a lot of compliance frameworks are all about what is your policy for, for this part of security. Like, if you go through a web trust compliance process, it's all about, here's what our policies are to protect data, to secure this process to the handling of customer information, whatever it might be. It doesn't tell you what this process should be.
You have to define your own. Then the compliance is, we have validated that we, we have systems in processes in place to ensure that we follow those processes. And if we are in fact following them, I, my, I have a sense that this is kind of where we're going.
There'll be some things that will help guide us, um, and getting some insights to, to what we should be testing against. I, I almost think we're living in this world because it's so wide open of what you could do with AI that organizations are gonna have to publish what their, kinda like their privacy policy is or what their, their, uh, uh, online community behavior policies are. Same thing for around ai.
And then do they in fact meet those? Because otherwise the requirements could be so vast. I'm not sure you could really test against everything and really know whether is this a safe system?
Is this a safe ai? Yeah, I think Mitch, that's a great point. And sorry, um, Joe, You go Bar I was gonna add one more thing.
What I'm seeing already is that, um, this is not a simple question or answer already, and it's going to get even harder to answer because, um, it's going to be a more of a blended approach as well. Like right now, I think oftentimes it's pretty obvious when you're interacting with an AI chat bot on somebody's website, because that's an easy way to have some sort of customer facing interaction. But where, uh, it's much harder to see where AI was used in process is when you have like a composite blended service where the AI tools are going to be part of the outcome.
And so you can see this in art, you can see this in, in, in creative, um, uh, disciplines. Uh, you can see this even like in, you know, from a business standpoint where, you know, or, you know, we were just joking about the, the after for this topic was, you know, run through an L lab, just say like, how, how can we clean this up and bring it down to 120 words, or something like that, right? So in those situations where AI is used as a tool, uh, uh, as part of a larger workflow, then, you know, how can you know that level of transparency, you know, be sort of transported to the, to the end user as well?
Like, how do I know that a piece of artwork that I'm purchasing as an example, I'm not a a a dealer at all. I'm just bringing a theoretical example. How do I know this is original work?
Um, or it was used, or AI was used as a tool in the creation of, of the artwork or in an email or whatever, what have you. I, I think that's where right now the world is moving where AI services are more, uh, an assistant role, an agent role, to basically assist with the creation of, of new work in a much more productive way. Um, and then the, the, the notion of compliance and governance and transparency is going to be even harder to, uh, to say like, do we need to put a label on anything that, you know, has, has been touched, involved in some sort of AI tool in any creation of it?
So just to correct my, uh, the name of that tool, it's a open source tool. It's called AI Fairness 360, and it is an open source. I just Googled it.
Um, and it's for ML models, so something you can put in your DevOps pipeline, right? There you go. That's, you know, there any examples where things have really slowed down, right?
I mean, you think about adoption of the internet, adoption of the cloud, social media, um, I mean, the only things I can think recently around AI are Microsoft copilot recall where we got ahead of our, so they got ahead of themselves and someone thought it was a good idea to snapshot your screen every, every second, but not securing of that information, the market reacted. The other is Apple's reaction to the EU AI Act, which is, uh, we don't, basically, I took it as we don't understand your res regulations well enough to know whether we could follow that. So we're just not gonna bring our AI to the EU until we, we feel that we can meet that compliance.
It wasn't that we don't like your standard, it was like, we just don't know what it is. Other than that, there's very few places where some, a regulation has stopped ai, uh, in, in its tracks. And, and I think one of the things we're gonna need is internal.
Why don't, this is judgment call, right? And so much of it is we're gonna need the internal board of here's how we're using ai. We're, we're thinking about doing this with it.
Are we delivering on the promise to our customers of safety of, uh, protecting their data transparency? We said, we're gonna be transparent. Well, are we being transparent enough?
There's so much of a judgment call to this that you almost have to have some kind of an internal mechanism to say, no, maybe it's not a gate review that everything has to go through. We can use some tools, like you're talking about Tracy, to do some of those things, but it's, it's like, here's our stated policy of how we're gonna use AI and, and what we're gonna do and not do, and the line's not always clear. So how do we help clarify when we need to make those calls?
I have a more fundamental question, which is, what is the purpose of all this regulation and governance? It's to build trust, isn't it? To build trust in ai and its use where I think the, the best way to build trust in AI is to use it and see for yourself what, what's real and not, maybe not true or so good.
Um, but fundamentally, do having these regulations allow you to trust AI more, right? I mean, Martin do. The, the fact that the EU has this AI act, it's not even, I mean, it's been passed, but I don't think it actually goes into effect effect until next year.
Um, but by having that act, you say, oh, AI's a little more trustworthy, a little easy say, pretty used. Now I have more trust in it, because if it doesn't, why are we doing this? Yeah, I think the, this is a good point because the, the, the what, what builds trust is obviously, uh, transparency, uh, is one way to say, look, you know, there are regulations out there.
The requires out there, here's what we are doing in order to make you feel comfortable that the technology that we're delivering, the products and services that we're offering are safe to use an environment. And so, for example, uh, just be super practical for a second, uh, tricentis, we've actually established an AI trust center that you can look up on our website where we publish, uh, our data privacy, our, the, the kinds of technologies that we're using, our security, uh, uh, that we're using. Uh, and we're also publishing the, the, the guiding principles that we use now in internal development, uh, to basically give customers that want to know, uh, a place to go to, to find out how do we, how do, what do we do internally and, and, and what do we do?
And these are things that we are going to, uh, update and, uh, keep current on an ongoing basis as new regulations come out. Um, I think there will still be an opportunity for like stainless, like ISO and others to, uh, create more formal, uh, certifications as well that the vendors like us can, can sort of, um, uh, can achieve and publish it as well, just like Tracy, as you mentioned on the security side, where we have a lot of requirements already that, uh, companies can, uh, adhere to. And then also be publishing that and say, here's what we're doing, and if you have more questions, let us know because we wanna work with you to understand what specific requirements do you have that we can, uh, support as well.
And then it's about sort of, you know, showing and demonstrating and, um, and putting, um, you know, the proof into the pudding, if you will. I think this, this question of trust is pretty, is really important. Um, I, I, you know, I, even in tech strong gang, I've said many times, I don't trust a autonomous driving call yet.
I, so trust is an issue, but part of that is awareness, right? Um, if I have, if, you know, when I was driving a Tesla, I could have put it in auto, you know, kind of an autopilot, but I never did. But I was aware that, that I was making that decision.
Part of the EU act is says that, you know, if you're kind of at a minimal risk, at minimum, you need to indicate that this is, this is AI generated. So, you know, in the United States right now, there's, you know, public service announcements going out about the potential of robocalls or AI generated, um, robocall that says go vote at some other location. The person that's listening to that doesn't know that that's an AI generated, uh, phone call.
So, you know, the awareness of the fact that you're consuming AI data is super important. Anything that comes across that's been generated by ai, it should have some kind of a stamp on it, some kind of a, you know, a watermark that Hologram or something. Yeah, yeah.
Something like the doctor and star check Voyager or something. Right? Exactly.
Exactly like that. Um, because then we can, then we are aware that we are looking at something that's been, uh, that, that is actually AI and not human. And that's important.
It's very important, actually. One of, uh, one of the things that comes to mind when you say, um, do I get a sense of confidence knowing that these rules and regulations exist? It's almost like here in Charlotte, North Carolina, let me tell you, speed limit can be 70, it can be 55, it can be whatever it wants, right?
But here in Charlotte, 80 miles an hour, 90 miles an hour, pretty much everybody is doing it, and you very rarely see anyone, you know, pulled over. So is the speed limit actually meaningful if there is no enforcement? Right?
I think one of the things that will give confidence is, uh, and, and not that you necessarily want to see governments going after, you know, everyone, but key stories about, uh, enforcement and how it actually has benefited people and, and made a difference, right? Having the rules is great, but understanding, um, in, in common scenarios and common use cases, real world things that have an impact, um, I think that is a big confidence builder when people can see it and connect to it in that way. So I will just rule of thumb, so I could save someone a speeding ticket here.
Yeah. Um, in, in Florida, it's a 70 mile an hour speed limit. And the rule of thumb is they won't pull you over up to 80.
Anything over 80 you're subject to get pulled over. Don't take that to the bank, and please don't say Alex in North Carolina, they often say five miles. Uh, but there, there, there are no, there, there are no, but, but You know what, bringing it back to ai, this is a perfect example where if you have autonomous driving one of Tracy Reagan's favorite things mm-hmm.
And you tell, and you tell that AI program, Hey, not to exceed 75, you don't ever have to worry about it because it's not the human who's gonna go as fast as they can. Mm-hmm. If the AI is told 75, the AI is going to go 75, assuming the AI behaves as intended, and we have trust in it.
And that's the perfect example, right? Um, And if there's a bug and it goes 80 and you get a ticket, whose fault is that? Right?
This is true too. Brings, and are the tickets now automated because the card, you know, worried is hooked in the law enforcement. We're all worrying about a scenario that's gonna go away.
If you remember back to the future, national Brown says, where we're going, we don't need roads. Didn't, we don't have the, but this gigawatts, gigawatts, whatever. Go ahead, Tracy.
This brings me to another topic around governance. There has to be industry standards. Uh, you know, financial is gonna be different than, you know, traffic control.
It's gonna be different from, um, welfare or warfare or, uh, or, uh, I don't know, surveillance. Every, I think every industry is gonna have to look at it. I think the Food and Drug Administration has done some work in healthcare, AI and healthcare defining standards.
But what will be, you know, so the question is what's the, what are gonna be the standards for the industry itself, right? The AI industry itself. So I keep going back to compliance.
If you define standards and industry specific ones, uh, and then we start figuring out a way to measure the compliance of those standards. I think we're making some progress, but bad actors are gonna do things without pursuing any standards as hope indicated. How do you enforce this?
You know, I have a 25 mile an hour si sign on my dirt road. Do I, you think anybody's gonna ever give me a ticket on that? No.
'cause some, some neighbor put it up there and I fly by it at 40 miles down, More than dead. But, but, you know, some neighbor put it up, Some neighbor put it up, right? But it's, so it's kind of like, you know, it's a neighbor putting it up, the eus putting up this sign that says you go 25 miles an hour.
Um, you know, do we honor that? And I think that most of us will try when it comes to this topic, but I do think industry standards are gonna be, uh, are gonna be as important if not more important than higher level, you know, federal level government standards on these topics. Because very different When it, when it comes to governance.
Now we see this right there in different governance issues for the fin, you know, what we call the highly regulated industries, financial and healthcare and, and government work and stuff like that. And, and we've adapted to that. And as an industry, we, you know, people comply with those different vertical standards.
And they're not all industry standards. Some of them are government. Um, I, I would imagine we'll see the same thing with ai.
I just, I just, you know, I have that hologram issue where ethical people will act ethically, but unethical people will almost certainly act unethically and they may not make their hologram have the, the, the, the watermark or the, or the, or the standard, and I guess maybe this is true with a lot of governance, is the good people do their best to do good, and sometimes negligently or inadvertently, they, they may miss a compliance or governed standard, but AI has the ability or the potential, AI has the potential for people who are not ethical to really abuse the system. And I don't know if having AI acts in place, we have to go to criminal stuff. I, I, I don't know what the right answer is, But, you know, I think even the criminals are gonna have their own governance standards Really With their organizations, right?
It may not be a governmental or federal standard, but these criminal organizations, some of them are very large, right? They're, they're gonna have their own standards, and it, it makes Like la cosa nostros kind of, you know, you Yes. Only go out with your wife on Saturday night, not the, not the girlfriend or whatever, right?
Right. I, you know, sometimes lack of a, a federal, well, a, a federal standard, I mean, that, that's where we are now. And states are already enacting their own laws around ai.
Colorado has a law, I don't remember the name of it, but it's basically says, if you're, if you're working with ai, that is high risk, you have to, um, there's some transparency requirements, and you have to have some type of review of what you're doing to make sure that it isn't endangering people. Something like that. But that, that's Colorado.
Who knows what, you know, Wyoming's gonna do California or, or Idaho. Yeah. So, so we're, I mean, we live in a global world, but if every state has a different policy, different law, that's a complex web to try to build products and use ai, I mean, we see, Alan, your point, your point is, is spot on, you know, this is, the whole process of governance is really around, um, uh, kind of a democratic system between the EU and between all the states and the us.
Uh, everybody has to act, uh, in a gentlemanly way and, uh, agree to those standards and comply to it. And, and that's what drives it. And if, if we don't, um, we choose not to, um, there's very little accountability, or it's very hard to even find out that you're not, uh, complying to those standards.
So governance is hard. It really is, uh, especially when you're trying to define governance through a, a democratic process where everybody makes their decisions across these countries and are relying on everybody to, um, be honest, and not everybody is. Guys, we're over time.
I gotta be honest with you. I apologize. But yeah, it was an interesting conversation.
I wanted to let it go a bit. I think we could all agree at this. I think there's still a book to be written, or at least a few chapters in how AI governance is going to take shape here and what its effects going to be in a global marketplace.
And it'll be up, uh, you know, the ethical people, as we said, will act ethically, the tric of the world will try to give people a sense of, Hey, we could test for this, or we can, you know, given transparency, we can show you that, you know, to, you know, be the transparency that it's in compliance or what have you, test for it. But a lot of it's good, I think is the book is still yet to be written. So we're trying, is I, I guess the, the right thing, right, is we're trying, and it, and this is still evolving.
Anyway, Martin, Tracy, oh, thank you guys for coming on our DevOps Unbound episode today. Mitchell, thank you as always for co-hosting. Thank you, Tricentis.
We're partnering with us for these four plus years now. We look forward to many more reminder for those folks out there. This, what you just watched was a prerecorded version of DevOps Unbound.
Every two or three versions, we do a live audience, and you get to ask the questions, and you get to make the comments, and you get to participate in this discussion. And we love having you. So stay tuned for our next live round table of DevOps Unbound.
But until then, this is Alan Hummel for Techstrong Group. Have a great day, everyone. We'll see you soon.
Welcome everybody. Uh, I'm Pete Garson, director of Products at Active State. And today we're gonna talk about, uh, taming the complexity of open source with active state.
And you probably know a little bit about active state. Uh, we've been around for over two decades. Uh, we're currently helping 97% of the Fortune 1000 secure their open source.
And we've been around since the sort of late nineties, uh, when we started doing, uh, Pearl on Windows and doing that port, and we sort of, we were also a founding member of the PSF. And we've been working with, uh, enterprises to help, uh, manage their open source for the better part of those two decades. And one of the things we've done recently, uh, we partnered with PI P on a trusted publishing initiative.
And as over time as things evolved, we went from doing things like Active Pearl, active Python, uh, where you might just download a sort of curated distribution of, uh, open source and open source packages to something where instead, what you're doing now is having a tool to manage all of your open source. And so what we did was we evolved, uh, our product first to meet our own needs, uh, internally in terms of what we were doing to manage open source for various enterprises, and instead move that to a product where all of our users could use this and to sort of help them manage, uh, all of that open source and tame bit of that complexity, uh, around what's involved in managing open source from the ingestion point all the way through to the, uh, deployment stage. And so one of the things is when you're not managing unmanaged open source is exposing you to sort of escalating security and license threats.
Uh, supply chain threats and managing this stuff at scale is really challenging. Uh, you know, it's one thing to know, I've got a vulnerability in this package, right? I've got, you know, my, my s e's tool is telling me, oh, yeah, you've got a vulnerability in this package.
You need to update that. But it's another thing to actually successfully update that dependency, all of its dependencies. So everything, all of its transitive dependencies.
And to ensure, like the providence of all of that stuff that you're ingesting, you know, dependency hell is a real thing that can really consume a lot of developer time. And knowing whether that is a breaking change or not, how safe is it for me to update that? It's really, really challenging.
And so just that, uh, that element alone is really, really simple. I'll just say that one again, it's there. Just managing, bringing in the updates alone is really, really challenging.
And then we move over to observability where I can even understand what I'm using in the first place, right? I'm a large organization, I'm running thousands of pieces of open source software. Is that cataloged?
Is it versioned, auditable, reproducible? Where is it running? Who's running it?
All of that is super challenging. And if you don't have systems in place, it can be very, very painful. And then on the other end of things, if you're trying to comply with, uh, government regulations or security audits, do you have tools in place there to actually develop and deliver the, uh, artifacts that you need to support the security guarantees that you're giving, right?
Can you produce the documentation, the chain of custody information to be and be able to verify that and supply it when needed? All of this stuff is really, really complex, uh, and it's very, very rarely, uh, an end-to-end solution. And so it's really, you know, it's no, no wonder that there's a lot of shortcuts that are being taken and, uh, people are shipping with known vulnerabilities, or they're doing a lot of ad hoc things.
And that's really what we see is that people are really stitching point solutions together. Uh, they're, they're maintaining spreadsheets. They're, uh, running an ad hoc report.
Uh, they're doing, you know, audits on demand, very reactionary, uh, you know, they've got solutions that are kind of diffused throughout the organization's department. There's no standardization. Um, you're managing all these different, uh, upstreams, right?
You've got source code, you've got vulnerability DA databases, you've got vulnerability scanning tools, you've got container registries, you've got licenses, you've got SBOs, you've got all these different tools, all these different processes for each one individually, and they're probably largely duct taped together. They're not pro brought together in a coherent, cohesive way, and they're really only partially addressing the solution, right? They're not seamlessly stitched together.
So one of the things that we've seen over the years is that you really do need to think about this holistically, especially when you're thinking about supply chain security. And so what we're doing at active State, and what we're sort of talking about today is like, what's, how do you tame that complexity of all of this stuff? How do I deal with all of those stages across my software development lifecycle in a way, uh, that is systematic and reproducible and auditable and understandable and also low friction for those inside my organization?
So what we're doing at ActiveState here is sort of bringing our, our, you know, decades of experience with os open source management to bear and to provide a kind of holistic solution. And so let me sort of walk you through what that looks like here from the discovery of everything that's running inside your org, right down to the deployment. And so we saw before there's an open source ecosystem and maybe your even your own private ecosystem, and there's a lot of information that's out there that you're pulling from all these different sources, and you also have a lot of open source that's running inside your organization.
So the first stage is really about discovering that, right? It's about discovering and cataloging all the open source that's running inside your organization. So discovering it from various sources, uh, knowing who's running it and where having a kind of auditable inventory, we'll see that this, this notion of having an auditable inventory is really important.
Um, you know, having a spreadsheet of all the open source that's running, probably not gonna cut it, right? Having a diffused set of requirements that TXT files or for whatever language you have diffused across your source code re repository, also probably not going to cut it. You can't do any kind of sophisticated reporting against that kind of thing.
And so then we move on. Once you've discovered, once you even know you can't even begin to manage what you're doing, if you don't know what you're running, then we can move on to the analysis stage where we can gain insights into the risk profile and generate some reports and share that intelligence across the organization, right? When you have, you know, uh, DevSecOps, uh, scenario where you've got collaboration happening between development and security and, uh, DevOps professionals, you need to have, uh, ways to share information across that organization and to collaborate effectively.
And so the first thing you need is analysis of all that stuff that's running. So you need license and vulnerability reports. You need, what's the impact of taking this upgrade, right?
Do it, does it have a breaking change in it? Do I have all of the, uh, supporting artifacts that we talked about from the compliance standpoint, you know, in terms of SBOs, attest stations, all that stuff. But then once you have the analysis, okay, now we have to take an action, right?
We need to do something about it. We have to remediate the issue, or we need to get it deployed, or whatever. And so then you need to have tools in place to be able to scale that across your organization.
So, uh, once I, once I'm taking the action to remediate something, I need to know, first of all, do I need to remediate that? Does it, does it hit the threshold that we have to remediate? And do I have tools in place?
So whether that's policies to be able to say, um, we don't, we don't want, uh, any vulnerabilities inside our organization that are, uh, you know, higher than a high, we don't want any criticals or highs inside. But then do you have the ability to scale that across all of those upstream sources, right? So we start to think about having a curated immutable catalog where instead of drawing from all of these various, you know, unsecured, unmonitored, uh, you know, public sources, that we can have our own curated catalog where we have control over what's in there, and we also have the ability to, you know, enforce that across our organization.
And then finally, okay, great, I'm gonna download, I need a new version of my package and I need to go from version one to version two, but does it build, does it work with all of the other, uh, dependencies inside my, uh, inside my project or, uh, you know, in my deployment? And so what we've done is we've had, you know, two decades of experience building open source, and we have, you know, a very powerful, uh, build cluster where we can build things in hermetically sealed containers with guaranteed provenance. Everything is built from source, and we can integrate with your systems to be able to, uh, deploy, um, in whatever scenario you have, uh, whether it's a container or whether it's just a, a simple application and getting that into your organization.
And so then we get back to the beginning, and now, instead of discovery, we're talking about monitoring on an ongoing basis, knowing what's running inside your organization and being able to keep up up with that, whether there are changes, whether you need to, you know, emerging vulnerabilities, I need to remediate that, get it redeployed, rinse, and repeat across the cycle. And so this sort of holistic end to end where right from the discovery, right from the source code all the way through the intermediate artifacts in the building, that kind of holistic end to end is really, uh, key to, uh, sort of taming that complexity and to having something that is a reproducible, uh, simple, understandable collaborative system, uh, across your organization. And so, when really what we're talking about is various set of different use cases where we're talking about, you know, the idea of continuous open source integration.
How, how quickly can I get new versions deployed within my, uh, organization? How quickly can I get new versions ingested into my pipeline? How can I ensure that my different environments are consistent and reproducible across my entire organization?
Do I have the tools in place for effective governance so that everybody's pulling from the same catalog. Everybody's pulling from the same set of trusted artifacts. Do I have insights into all of the usage across my organization?
Do I have insight into all of the places where things are deployed? Do I have the tools to be meet regulatory compliance? Right?
Do I have those, you know, the, those SBOs, those attests, those type of things? And do I have, uh, support for things that are going beyond the community supported end of life? So if I need something, uh, supported beyond that, do I have a a catalog that supports that kind of thing?
And then we're gonna kind of jump into that, uh, today and sort of show you what that might look like actually in practice. You know, I showed you the little diagram here. I talked a little bit about the process, but let's talk about what that actually seems like in practice.
And so I'm gonna jump over here. Let's say that we have a, a little environment where, uh, we wanna discover everything that's running inside our organization. We, it's gonna live in a lot of different places, right?
It might be in a Kubernetes cluster, right? It might, might be just in GitHub. Basically, oh, we've got all of our, our requirements files and, and, uh, dependency manifest files across various projects.
In GitHub, it might be, we might already have a bunch of SBOs and we don't know really what to do with them, but they can be a very valuable, uh, tool for understanding what's running inside your organization. So we can get directly from our requirements file or an SBO m from GitHub from, you know, helm or Kubernetes. And so let's say, we're just gonna say Kubernetes here today.
So we're gonna scan our Kubernetes cluster. And here we discovered that we've got a number of sort community images that are running here. We've got Postgres and Nginx and Spark and Elasticsearch, and, but what's inside of those things, right?
It's one thing to know, okay, yeah, I'm running Postgres, but what, you know, what's actually inside that? And so our tool can analyze these dependencies and vulnerabilities and give us information and intelligence right down to the system level. Like you really need to understand, it's one thing to know that, uh, you know, I'm running TensorFlow, but there's a whole bunch of C libraries that underpin that, and that's where you sort of, that's where a lot of the vulnerabilities that tend to be is in languages like c in those type of, uh, libraries.
And so what we've got here is we've got an immediate analysis where we can get that information at a glance. So, you know, across my little, uh, pretend organization here, uh, I've got six Docker images running, and 47% of that is C code. There's 1,099 CC dependencies running there.
I've got a bunch of Java, some go, some Python in there. It's given me a vulnerability profile that's showing me, uh, here's, I've got 14 criticals 136 highs. I've got a profile of the different licenses.
So at a glance for my organization, I can see what my risk profile looks like, and I can do things like download a CBE report or download an SBO m But the key thing here is that I've discovered at an early stage what open source is running and what its composition is, and, uh, you know, sort of what my risk profile is here. And I can see some more details on those things. But we sort of covered those first two boxes.
We've got a thing where we've discovered, so now we have that, and we've also, you know, presumably got something in place now where we can monitor this on an ongoing basis. But then we've also got some analysis here where initially we can see what our composition is. Okay, well, we've got a lot of vulnerabilities.
How do we upgrade that, right? How do we go from, you know, 1500, um, vulnerabilities to something that's, that's less, right? And so what we can do is generate something, uh, a remediation plan, right?
We can get, we have a lot of information in our catalog, right? We're, we're going out there and we are ingesting a lot of these public ecosystems. We're pulling in all of Pipi, we're pulling in, uh, all of, uh, you know, uh, the pearl ecosystem.
We're pulling in all of the Java ecosystem, et cetera, et cetera. And we have all of this information around versions. And so we can say immediately here, you know, what, before you add 150, after you're gonna have 188, here's what you can do.
We can also give you some additional intelligence, uh, around the risk profile here. But, uh, essentially what, what we can do is show you that we can remediate all these things. They're relatively, uh, low risks right now.
And so then what we're going to do is we're gonna take those things and we're gonna import them into our platform and manage them as projects. So each one of those containers that we saw before now becomes a project on our platform where now I have a, a contained unit where what I can do is manage that over time. I can configure that over time.
I can see the auditable history of that. So let's say, let's pop over here and see what that actually looks like. So this is a, a little demonstration organization I have here where I've got, uh, five projects, 468 dependencies, mostly go and Java here, and a number of vulnerabilities.
But each one of these things represents either a container that's running in my, um, cluster, my Kubernetes cluster, like we saw, or maybe just a basic, uh, project that I created. So in this case, like, um, my a basic Python project. And what I can do is I can manage the dependencies individually in those things.
I can also browse them at organization level. So, you know what, if I'm sitting there and I'm in my, uh, an organization, I'm like, I hear about some critical vulnerability. Do you have a index of all the open source that's running inside your organization that you can very quickly, uh, you know, inquire and say, am I exposed to this?
So let's say we hear about something log four J and we type that in here right now across my entire organization, I can type that in and immediately see that, well actually I have this thing log four j append that's running in one of my containers here. It's running in this Kafka test container. And so maybe I should go and investigate that, right?
And I can drill into that exact project and see the details. Um, and that project will then I'll, I'll be able to configure that. I can also see the vulnerabilities across my entire organization, and then I can go in here to my project and configure it.
So let's go like a really simple example, uh, with the, uh, Python, and let's take a look at what that, how that actually manifests. So let me just quickly turn that off. And, um, what you see here is, here's this, the packages that are in my project.
So in this case, I've got a very simple web application, safe flask and pillow. And this is sort of maybe running out there on my cluster somewhere, but I've seen here that I've got vulnerabilities, I've got a critical vulnerability here. I've, uh, four highs and I'm getting in.
I, I, so I'm inspecting what, you know, what the problem is here. I've got a couple highs here in the Python version as well. I can see my, all of my dependencies all the way down here to the system level.
I can see, you know, not just that, you know, flask brings in blinker and click and flick or it's dangerous and stuff like that. I can scroll down here and see, write down 11 LZMA and the system level C libraries. So I've got sort of unprecedented visibility right down to the deepest level.
But then I can go and I can remediate these things very simply. I can say, here's what one is not vulnerable. I'm on Python nine, uh, pillow nine 10.
Well, I'm at one critical four highs. I need to pick one that doesn't have a vulnerability because we are ingesting all of this open source into our catalog. We're building it all from source.
You've got a trusted upstream for essentially all of the, you know, open internet. So rather than going into a situation where you are, um, managing 50 different upstreams, you can say, well, I'm just gonna point to, uh, active state's trust catalog for everything. And I can choose that version though from our catalog where we know that that doesn't have any vulnerabilities.
So we're gonna say fixing vulnerability here, then we're gonna save those changes. And now that's been changed to, uh, to the non vulnerable version. It's gonna resolve and re-figure out all of the things that are in there.
But one thing that's interesting that is a critical piece of the puzzle here in terms of taming the complexity of your open source is the idea of that change management auditable history that you saw me do. So I logged the change. So here, rather than me just editing a text file and committing that, or you know, just installing it on my developer laptop or something, what we've done here is kind of merge the concept of source control with dependency management.
Where I've got the, you can see here, here's my base project that I created. 4. And you can see that at any point I can go back in history and revert to this commit, I can generate an X bomb at any point in history.
So I have a fully auditable chain of custody here where I can see that, you know, Pete made this on October 24th at this exact time. Here's the commit id. It's fully reproducible.
And unlike you can see here that we also have this catalog revision id. And unlike the sort of public repositories where if I run, you know, NPM install on a Friday and I run N-N-P-N-P-M install on a Monday, I'm gonna get a different result. But what we're doing is we are revisioning the catalog every point in time.
So it's fully reproducible. So not only, uh, is this saving the state of your dependencies at any point in time and all the open source that you're using, it's also saving the state of the world at that time so that you are fully reproducible, fully auditable from end to end. The other piece that you can see is that what it's doing is it's kicked off a build into in our cluster where it will be building this, uh, from source, these individual packages.
4, it'll be building that from the source in our cluster here. And so you can see as well, our critical went away over here on our total vulnerabilities and it's rebuilding on Macs here. Those things get rebuilt completely in, uh, uh, in hermetically sealed containers and completely, um, in a completely reproducible way.
You can get SBOs for all of those things. If I go to my overview here, I can see I can generate things like an SBO for this. I can download a vulnerability report, I can do collaboration.
But the key thing is that what we're doing is we're taking stuff from the beginning where we're discovering all the open source that's running in our organization. We're then doing some basic analysis on it to give you sort of, uh, the breakdown of the inventory, whether it's go or Java or C or Python. We're giving you the high level rollup across your entire organization of all the vulnerabilities.
So you have that initial analysis stage, then we're giving you the tools to be able to curate those things and manage a catalog, have a fully auditable history to give you the sort of, uh, governance tools that you need to be able to curate that. And then the tools to be able to build, deploy, and redeploy that. And so I think that that key cycle there where you have end to end control and visibility on everything that you do, whether it is, um, just discovering what's going on in your organization, all the open source that you're using, cataloging that in an auditable database, then being able to do analysis, collaborate with across your organization, across your, uh, development team, your ops team, your security team, to be able to then curate that, upgrade it seamlessly remediate as we just saw, and then build and deploy that, whether it's integrating with your CICD to get deployed it out, out to your, uh, cluster or whether it's just on your developer laptop, to be able to keep working and streamline that development process.
Having a system that streamlines that entire process holistically end to end is, uh, really important. And that's sort of our vision for how, uh, we should be sort of simplifying and streamlining and tame taming the complexity of managing open source, because it's really complicated, it's very complex. There's a lot of moving parts, a lot of information as we saw shifting landscape as well.
And accuracy has been really focused on taming that complexity. So I want to, uh, call it there and say, you know, thanks for coming to check this out and uh, if you have any questions, just let us know. And, uh, thanks very much.