Techstrong TV February 12, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Welcome back here to Text Drunk tv. I've got a great guess.
I've been looking forward since I originally scheduled this one to talk to him about. 'cause it's a, an scenario I've been writing and talking about it too. I want to introduce you to Don Murray.
Don is the co-founder and CEO of a company called Safe Software. Hey Don, welcome to Tech Drunk tv. It's great to have you on here.
Yeah, thank you so much. I'm really excited to be here. Good, good, good.
So Don, as I mentioned that you're a co-founder, CEO over at Safe Software, but, you know, give us, you weren't born there. What, what have you been doing up, you know, until you've co-founded Safe Software? Yeah.
Yeah. The first thing I I, that's probably relevant is I did my master's degree at Simon Frazier University in parallel processing. And, uh, and then, um, after that I went and worked at, uh, McDonald, at Weer and Associates who built ground stations, and I did some work on airspace modeling and where I met the other founder, Dale Lutz.
And, um, and then we, uh, a few years later we founded Safe Software, which is a company that is focused on enabling organizations to work with all kinds of data. Our, sort of, our specialty is anything that's spatial. So IE for companies who have infrastructure on the ground, they obviously care where it is and they wanna be able to analyze it and do all sorts of operations and connect it to the rest of their systems.
And so that's a little bit about, about me and what, what Safe Software does. Yeah. Love it.
When did you, when did you found Safe Software? Yeah, safe Software is a company 30-year-old company that nobody, um, heard of. Um, both Dale and I were technical, so we just spent time, you know, building, um, you know, this solution and then selling it.
Um, and then, you know, much later we realized, you know, really we need to really get serious about our marketing. Um, and we sell around the world. Our first customer was actually in, in Sweden, if you can believe it.
And we're based in Canada. And now we have on the order of 20,000 customers around the world. Oh goodness.
From local governments to airports, to utilities. And again, any industry that cares about stuff that's on the ground is primarily, um, where we are embedded. Yeah, Love it.
Um, so another overnight success, you're telling me, huh? Yeah, that's right. 30 years.
I mean, and I tell people 30 years ago I had amazing hair and, and the funny me too is, is Yeah. And the funny thing is older, the older I get, the better it was. Right?
Yeah, Exactly. And then I look at pictures from back then. Yeah.
You know, and it's like, you know, my hair was always kind of thin. I mean, not, not like now, but you know, it's never, I never had that like, you know, no craziness. But anyway, Hey, it happens to the best of us, Don.
Right. Does. It is what it is.
Um, so let's talk ex explicitly about Safe Software does, as you said, and he gave us a little bit of background, but, you know, the world's changed, the world's changing every day, not we're in this AI Yeah, yeah. Revolution. Yeah, That's right.
As We sit here today, what's safe? Yeah, yeah, yeah. So we are like, some people said, oh, we're ETL, but we did ETL many, many years ago.
Now we just build like data virtualization, APIs, we have real time, high velocity, real time just connecting not just spatial systems, but all systems together. I guess you could think of us like the nervous system of companies. So we have everything from the top companies in the Fortune, you know, 10 all the way down to the Fortune.
Our market's like the Fortune 500,000, I guess you could say. And, um, very big clients, very small clients. Um, but they all have one thing in common.
They want to get, you know, more value from their, you know, from their data. So we basically chase data, you know, so open table formats, for example, is a big thing. Um, AI and connecting data to AI is critical.
'cause AI needs data both for training, but also for inference. And, and, um, we, you know, we do in more kinds of data than anybody. And, um, our whole model is any ai, because what is the best ai?
It depends what you wanna solve, and it depends the data you have, right? And the space is changing so quickly. So we want to give our customers that ability just to pick whatever ai, and we have some customers are using three or four just to solve different problems, right?
Yeah. I mean, no one wants to be locked in, right? Locked in's a really dirty word.
Locked is debt, really more and more, right? So people want flexibility. So was that a bit harsh?
Yep. Um, for people who, you know, want to engage with Safe Software, maybe want to dig in deeper about what they're doing, how, how did they reach out to you, Don? com, um, where we we're technology people.
We love talking to people about their data challenges. We have a free 90 minute, you know, thing where you just show up and you're actually, you show you how to use the product. Um, it's a no code platform.
And, um, if you want to try it, we just give you the software. So again, and we'll help you get, you know, get value before you have to, uh, you know, um, learn about it. We have webinars all the time, um, with customers.
And so, yeah. So just reach out happy to, you know, yeah. To chat.
Yeah. Very cool. Um, Don, if you don't mind, I want to kind of pivot and talk about our topic of discussion today.
Yep. Yep. Which is, uh, you know, that this whole debate about AG agentic AI is kind of irrelevant.
Um, what we're really seeing though is perhaps the extinction of what you call Fin sa mm-hmm. Mm-hmm. And vibe coding.
Yeah. Um, you know, and how this all fits in. Now, of course, you know, Satya Nadela, CEO of Microsoft.
Yeah. Now, he came out a few months ago and said, SaaS is dead or dying. Yeah.
Yeah. Uh, Killed by ai, right? Mm.
Mm-hmm. Um, we're seeing it in the stock market, big SaaS company service metrics, not service metrics, excuse me, ServiceNow. Mm-hmm.
Mm-hmm. You know, a, a monster of a company. Their stock's down 50% this year.
Yeah. And they, and they make their numbers. It's not like they're not making their numbers.
Salesforce, you know, kind of the granddaddy of, I don't know if I'd call that thin SaaS, it's Fat SaaS, but yeah, Salesforce one of the biggest SaaS companies down 35% this year. Yeah. Yeah.
How, what are you seeing? How do you see it? Yeah, I mean, it's really interesting space because you, the, the, the key is you have to really have something.
Having a database now with, um, you know, a, a thin UI on top of it isn't just isn't gonna cut it. I was at an investor meeting, um, where, you know, companies came and, and this company came out, I believe it was Bain, and they talk about how when they're looking at a, a company to is to buy, they actually hire four people to see what, how much of that solution they can create in four months. And if they can create a, you know, a, you know, a significant portion of it, they, you know, then that tells 'em it's not, the company doesn't have anything, right?
Because there's a lot of, there's a lot of companies out there now that have a very thin, very thin veneer that you can replace. And for example, also at Safe, our sales team was gonna buy a tool. And I said to them, why don't you try to just recreate it with Gemini?
And these are sales guys, so these are not technical people. And they were able even, they were able to create it themselves to the point where they said, we're just going to use Gemini. We're not gonna pay the, you know, the 80 grand a year for this other thing.
Because in fact, it was this very thin veneer on top of some other LLM, might've been Gemini, might've been OpenAI. You know, it doesn't, you know, it doesn't matter, right? And so, so, um, you need more than a good idea now.
You need to really have something, you know, something substantial, some secret sauce that, um, you know, that really gives you extra value in the market. Right. And, and, um, yeah, I, I agree with you.
I, and I think you, you hit the nail right on the head. What we're seeing is, you know, if I could recreate what you do mm-hmm. Using ai, what do I, I really don't need you.
Yeah, that's right. And we're even seeing it with open source software. Yeah.
I have a lot of friends who, you know, big open source advocates, big open source consumers who are like, Hey, rather than dealing with the project and trying to get this functionality, you know, into the main branch or whatever, I'm, I'm just, I'm telling AI this is the functionality I need, and it, it builds it for me. Yeah. I don't need to use the open source software.
Yeah. Um, we're, We're seeing that as well, like our, our lead. And what's really interesting is our most experienced developers are the ones getting the biggest, um, the biggest accelerator than the, the junior folks.
Right. Because again, they have that experience, they can see it. And so we're building an MCP server as part of our, our offering.
And my lead developer, the guy's a genius, he came to me, he said this the, um, they're using Claude. And he said it saved him weeks of work. Oh, yeah.
And of course, he's a very expensive resort, so to save him weeks of work is amazing. And so now I'm thinking, oh, you know, those weeks of work, it's not like he's gonna have weeks of not nothing to do. Right.
So it's, He's gonna do something else. It's just gonna be able to creep. Yeah.
Yeah. Yeah. So I, um, you know, I, I did a, i, every Thursday I do a thing called Shimmy, says I, yesterday Shimmy says, I, I spoke about this.
Mm-hmm. We're creating a world where some people are gonna live below the AI poverty line. Mm-hmm.
Mm-hmm. And then some people are really going to excel and accelerate. Yeah.
Yeah. Because the way AI works, if you are a, let's call it a master coder mm-hmm. Like a real great coder.
Yeah. The amount and quality of code you are going turn out compared to someone who is a novice junior and what they turn out with that same AI is gonna be just, you know, widely disparate. I mean, it's got Yeah.
But it's not just code. It's the same thing if you're a writer, you know, we produce content here. Yeah.
It's the same thing if you're a writer, it's the same thing. If you're a musician, I dunno if you've had a chance to say that, you know, synthetic music, they call it Yeah. AI generated music.
Well, in the hands of a real musician, it turns out crazy good stuff. Yeah. You or I maybe not as good, you know?
Well, You know, Exactly in the eye, the beholder. But, um, I think that's, you know, but it does beg the question though, is, well, where do we get the next generation of great coders? Exactly.
If the Junior guys, Yeah. I, here I was an engineering company, and this whole topic came up. They said, you know, they, the people with all the experience find they don't need the junior people anymore.
Um, and I was like, well, when they retire, who's gonna be, you know, so as a company, you need to hire your junior people and grow them up because you're, you're gonna need somebody to oversee the ai. And, you know, and they do stuff like Bridges. They're not going to take an AI generated bridge model and just, and just Let it roll.
Somebody has Yeah. Somebody has to sign off on it and Yeah. You know, and when Bridges 97% accuracy is not good enough.
Right. You know, you need, you know, so anyway, really, so we say the AI is an assistant, not the authority. Right.
And I think I, others have said that, you know. Yeah. So I, so, you know, we've talked about it a lot around here at Techstrong and with people like you on Tech Textron tv and some of our other shows.
Um, the way I look at it is fundamentally the job is changing. Yeah. And so if you were a computer coder and you spent a good portion of your day writing your code, testing your code, you know, squashing the bugs Yeah.
And, and all of that stuff, you're probably not going to do that. That's not going to be the definition of a coder tomorrow. Yeah.
No. The coder tomorrow is going to be the guy who manages the ai or gal who manages the ai who writes the code, but who, number one could tell the AI exactly what I want out of that code. Right?
Yeah. What functionality, what Yeah. Characteristics.
And number two has sort of, you know, how coders are when it's your own code, you can look at that code and you could see Yeah. You know, you almost know it by memory. And if they, if something's outta place, it kind of sticks out, right?
Yeah. Yeah. You are gonna have to be good enough to look at that code that the AI generated and see, oh, this looks, this looks good.
Right. And you, I'm not saying you're not, you're not gonna test it. Of course.
We'll test it. Yeah. But there might be another AI that does the testing, right?
Yeah. That's right. That's right.
Yeah. And so you think about AI generated code, it has two code reviewers. 'cause it has the, the guy who's writing the code, he has to make sure he understands it.
Yep. And then every line of code here, we also have another code reviewer. Right.
And because code review is critical. 'cause the most expensive part of, if code is not writing it, it's maintaining it. And, you know, and we've had some pretty smart people here who could write really great code, but nobody could understand what it, how it worked.
'cause it was so complex. And so from a maintenance standpoint, it was just too complicated. So we had to rewrite it in a simpler form that the mere mortal could understand it.
Right. And so, you know, so it's gonna be interesting, you know, right now everybody's using AI to produce code, but we're gonna have to maintain it. You can't, you know, so, yeah, I get it.
I get it. Dawn, if it's okay, I wanna talk a little bit about vibe coding specifically, right? Yeah, yeah.
Um, it's fine. Who I was talking to a friend of mine the other day, very similar to your sales guy's experience. Yeah.
He, he, he just decided, you know what? I haven't coded in about the, the last time he coded, he told me it was punch cards. So that should give you an idea.
Idea. That should give you an idea. So he, but he, but he said, I, I gave it a shot.
And you know what, in about an hour, you know, the hardest thing I had was not the code, it was just uploading the code to, to make the app run. Yeah. And once I got that there and the code ran fine.
Yeah. He was amazed, amazed, amazed. Yeah.
Um, You know, this vibe coding is gonna, we're gonna go from what do they think? There's maybe at most 50 million coders, 40 million coders in the world today. We'll have a billion coders or a half a billion tomorrow with this.
Yeah. And so, again, ai, but developers, Not coders. No, that's right.
But AI also hallucinates in code. Right. So it's gonna be interesting how, how high a qual, I mean, our, you know, our team uses Vibe coding.
Right. But then of course, they, you know, and what we're doing right now is we have a no code environment. We're using Vibe Code to create the No code environment.
No code. Yeah. Yeah.
So then you, uh, you know, so it's a, so we don't know what to call it. Is it a no-code vibe? No, It's code, code vibe.
It's no vibes. I don't know. No vibes.
The absence of vibes. It's, I, yeah. It's crazy.
This is the world's crazy world we live in though now. Yeah. When you have Milk Botts finding religion and find founding churches and everything else that goes Yeah.
There's holes, social media, that are only for bots, not for people. Yeah. Right.
Like, and they have their own language. I know. It's crazy.
Yeah. Well, No, now they wanna encrypt so that humans can't read, read what they're talking to each other about Nutty. So, Yeah.
You know, you, you didn't think of this 30 years ago and you started Safe Software. No. And, and all of us have been working with AI for many years.
Right. And then all of a sudden chat, GPT Gen AI landed, and that really was the game changer. Right.
We've been talking about machine learning and, you know, neural nets for years, and we had libraries we had used, but nothing like this. Right. This is, yeah.
This is one of those big moments. And people talk about, is there an AI bubble? And I'm like, there was an internet bubble that burst, but the internet stayed here, Stopped The internet.
The internet did not go away. So, And AI's not going away either. And it's not going away.
There may be a financial reckoning. That's another story. The technology's gonna stay.
I mean Yeah, yeah. Absolutely. But I'll, I'll give you another scary thing.
com. Uh, so Claude released their latest Opus Claude Code. Yeah.
Claude Opus by Philanthropic. Mm-hmm. 6, like within a day or two of it being released, and the anthropic people setting it free, you know, setting it loose.
It found like 600 vulnerabilities in a, across these open source projects across a whole bunch of like, important open source, not just obscure. Yeah. Yeah.
I don't know if we have the ability to deal with 600 new vulnerabilities every other. We, you know. Yeah.
We just don't, we're not equipped yet. We're gonna need AI to now respond to those Vulnerabilities, You know? So it really is a, a new game.
It's a new world, a company like Safe. Right. You guys have been keeping current, and now That's right.
And we track vulnerabilities. And it's funny you mention that. 'cause one of the mandates for that team is to have, find AI that can find the vulnerabilities in all the code that's being written.
Right. And, and also the testing and, you know. Absolutely.
Yeah. It's a great time. I mean, look, of all the timelines you could have been born in, Ah, it's, we were lucky.
I mean, really, the PC was just powerful enough that two crazy technologists could start this company. And then, and then the importance of data, you know, for the last 30 years is only getting more and more important all the time. And now we're running outta data for ai.
So we talk about synthetic data. Yeah. You know, creating our own data.
I don't know if that's like synthetic oil for the car or not, but, uh, but you know, you get the idea, right? Like Yeah. Oh, I get it.
We, I mean, we're all looking at it. And, and I think, you know, the irony of ironies is that we use AI to police ai, to, we use AI to test ai. Yes.
Um, You know, it, it's, it's a great time to be in here, is all I got to say, Dawn, we're about outta time. One more time. Okay.
What was that? com. com.
Yep. Perfect. Yep.
Yep. Awesome. I wish you success for the next 30 years.
Yeah. But don't wait that long to come back here on Text Strong tv. Okay.
No, it's been, it's been a real pleasure. And, uh, great talking with you, Alan. Yeah.
Really good. All right. Okay.
Don Murray, co-founder and CEO of Safe Software here on techstrong tv. We're gonna take a break. We'll be back.
Hey everyone, it's Alan Shimel, founder, CEO here at Techron Group. Really happy to introduce this next session here for you. In, in this, uh, session, we are gonna have a fufu, Fernando Montenegro, who is the analyst in the security cyberspace, speaking with Ryan Jones.
Ryan is the partner, uh, partner director of product for power platform manage platform over at Microsoft. Great conversation with Ryan and Fernando. Uh, Fernando's gonna talk to Ryan as we explore how organizations can securely scale agentic apps, including power platforms, governance capabilities.
This is gonna include managed environments, adaptive risk models, and lifecycle controls. Hopefully you'll get out of this video practical guidance for balancing innovation with compliance in an age of AI first development. Let's listen in on Fernando and Ryan.
Alan, thank you very much. So, I'm Fernando Montenegro. I am VP of Security research o over at, uh, at Futurum.
And I'm thrilled to be here with, uh, Ryan Jones to, to talk about the broader part, broader topic of, uh, AI governance. Ryan, wanna say a few words before we get started? Yeah, thanks so much, Fernando.
Uh, my name is Ryan. I work on a number of the security governance and operational capabilities that we provide, not only to like our AI agents, but also that we provide to our low-code apps and automations that run on the, the power platform as well. Has you come across something more specific to AI risks or AI governance concerns that surface above and beyond the, the, the, the, the data sharing, the, the, the, sorry, data flow and, and, and sharing and others.
You know, as we look at the maturity of agents, we see that they kind of go from being assistants that are completely directed by humans to still interactive agents where humans are dispatching tasks, but you know, the agent is completing them on behalf of the human. And then we see kind of those fully autonomous agents. And I would say that that 10 to 20% is really more over on the end of the spectrum with those fully autonomous agents than it is with, you know, like my little assistant agent or something like that.
And the types of things that we see at that end of the spectrum are things like, Hey, if I am collaborating with a set of agents, how do I understand what they are doing or what they are doing on my behalf? The second scenario that we see is we're in the very early innings of, of ai. And so there are lots of cases where agents need help, where they sometimes get stuck.
And so some of the things that we've been trying to add into our products and our offerings are things like within power apps, we have the agent feed where a human can see what all the agents are doing for them. And then within copilot studio, the request information action, which actually allows us to define an agent such that it can engage with humans as needed. So what has been your, uh, your exposure experience?
What kind of of considerations do you have in this topic of, of model drift and model security and and so on? Yeah, I think that, I mean, it's funny, we've talked about how like what old, what's old is new again earlier, right? Like Yep.
We've had static tests that we perform against software for, for a long time. And what's interesting is seeing how that is evolving because models are less deterministic than, than, you know, traditional software. We call it, you know, stochastic life, right?
Um, and, and so as a part of that, you know, one of the capabilities that we've added to copilot studio is the ability to add tests and evaluations so that as our technology improves, as makers and builders go through and they modify what tools their agents can use, or what knowledge sources are used to ground those agents, those test cases, those evals can run and can return a result so that folks, as they are evolving, they know whether or not they're actually improving the quality of, of their agents. Because what we find is that the first day that an agent is shipped in an organization, this may sound negative, but that's gonna be the worst that that agent ever is. Okay.
It's only going to get better over time as folks refine the knowledge sources, as folks refine the tools as folks look at and improve the success rate across those evals over time. And so I think that those quality gates that we've had in software for a long time, we have those with AI as well. Mm-hmm.
I think also, you know, a lot of times an individual maker, they're gonna be the folks that are really interested in whether or not that agent really works well or not, while, you know, it is gonna take a bigger picture, look at things, right? They're gonna wanna understand in aggregate how our things looking. Are they healthy or not?
And it could be that if they see an agent that's not performing well, but, you know, maybe just you and I use it, it probably doesn't care. But if I have an agent that 20,000 people use this month, it is gonna care. And so those same views that we provide to our makers to understand whether or not their agents are healthy, we provide those aggregated views for the admins as well.
In fact, uh, you know, had a large customer in the energy industry where someone built, um, built an agent and it was for them, and they shared it, and it kind of grew and grew and grew. Next thing they knew, they had 10,000 people using it, they moved on to work on other things, right? It was able to see and observe, oh my gosh, this agent is critical to our business.
And so they took it over, they added it into their portfolio of applications that they managed. And the thing was, they saw it not as a burden, but rather as an opportunity because there's an application that's out there that delivers value to tens of thousands of people in the business every month. And their dev cost up to that point had been zero.
So it was a win-win for, for everybody. Once the technology security teams build the guardrails, right? Then it, then the, the, the, the business users are free to, to go work on those use cases.
So what kind of advice, uh, do you think would, uh, would be applicable to those technology and security teams in terms of getting them ready to build or to, uh, to build those, those guardrails or, or to leverage what they have to, to implement those guardrails? I think enumerating the categories or the dimensions of risk is one of the first steps. There are huge categories of risk that these teams can eliminate through how they define policies.
And to be clear, I don't mean policies like a Word document, I mean policies that are codified in the power platform and co-pilot studio and these sorts of things. Sure. Organizations don't want a random person in their company to build a workflow that takes information from their core ERP system and pushes it to Twitter, right?
We have the controls that allow you to preclude that. What would you consider to be from a governance angle, uh, you mentioned, okay, let's not focus on use cases. What would be advice, uh, for, okay, let, let's move this forward, right?
Where, where are typical things that you'll see people hate? Let's do this. I think the first thing that we see people do is they define like a, a zoned governance framework or a zoned governance approach, right?
They decide within their company or their organization, what does green, what does yellow, what does red look like? And then they go through and they define that using the tools that we, that we provide through the power platform and through called Pilot Studio. I think the second thing that we see folks do is that helps with kind of the supply side, right?
That sees to it that the technology is available and accessible for folks mm-hmm. Across the organization. But then there's this strong demand element.
Um, 'cause gosh, I was talking to another, uh, big company in the, the credit processing space a couple weeks ago, and they had this amazing, you know, governance framework set up, but they didn't do anything to stimulate demand, right? And so the next thing that we see is, you know, reaching out to the businesses not to harvest their use cases, but to help them implement their use cases. You know, things like hackathons, things like training, things where for the people that are interested and excited about transformation through technology, where they can roll up their sleeves and, and get into it, I mean, the number of apps and agents and automations that came out of those couple day training session and hackathons, it blows my mind, ev every, every time I have the opportunity to, to participate in, in one of 'em.
Um, and it's fascinating because you see the passion of the people in the business. You see their ideas come to life. And then in many cases, that's the first step of a broader personal transformation and career journey where you have someone that's been in accounts receivable for the last two decades, and all of a sudden they realize, oh my gosh, like I can actually harness AI to completely change how this part of the business works.
And what you highlight here is super interesting, because one of the things we talk about in the context of platforms is how, uh, you can have that network effect of you've already configured something in your environment for a particular use case, like I said, enterra groups for, for identity, and how that can accelerate the, the, the time to value, if you will, within, uh, uh, AI development because hey, you're, you're, you're building on a foundation that, that you already built for your organization. So I think that's a really powerful message, right? And, and, and it, uh, it, it's something i I tie back to how do we help technology and security teams, uh, build that scaffolding so that those business users can go play with the, the, the, the on on those environments?
A thousand percent. And I think that in a lot of, you know, circumstances, it means, you know, standing on the shoulders of giants that came be ahead of us, right? Like, what, what organization today doesn't have entre deployed in one form or another for user and group management?
And so why wouldn't we use those grouping constructs as a foundational capability around which we build our security and governance frameworks, right? Like, it's already there, it already works. And I think that is one of the things that's a little bit differentiating around the, the offerings that, that we provide in this space because mm-hmm.
You know, I build an app, an agent, an automation from day zero, it's authenticated and authorized, right? Um, you know, another thing that we're seeing that's super common right now is as, as companies are trying to figure out how do they get these AI tools into the hands of people across the organization, and how does that center of excellence or that center of an enablement help people in the various business units upskill and, and drive transformation? One of the things that we're seeing is that our customers who already had a center of enablement or a center of excellence built out for low-code applications and automations, they're moving much, much faster when it comes to agentic transformation because a lot of the foundational governance concepts that you need to have in place their modality or client agnostic.
Um, and, and so that's, you know, I was talking with a financial services customer just yesterday, a big one, one of the G CFIs, and they were like, yeah, we have deployed, you know, this many thousands of agents over the course of the last, you know, month. And we would not have been able to do that if it wasn't for the fact that we already had this governance framework in place from what we've done over the course of the last five years with low-code. I think that one of the areas that, uh, that we want people to be aware of, like, and we, we talk about in our research is that this evolution in models, right?
We shouldn't be, just like you said about the use cases, just like the use case conversation. You shouldn't be waiting for the use cases before you get started kind of thing. We shouldn't be waiting for a perfect model to solve, okay, once we have this model, this is how we're going to do this.
No, because these models are evolving, uh, constantly, right? And, uh, if you, if you architect your AI governance framework, right? You build in or you leverage the build in the, the monitoring capabilities to observe how a particular model is evolving, how a particular model is behaving.
So yes, it, it is a, a critical component like observing how these things are evolving. Well, and and it's interesting because I know that at times we've had discussions with some customers that are like, Hey, how do I control which version of the model is being used by this agent? And, you know, there are some places where we give customer those controls, but I will say like, I'm kind of hesitant about it because I can't tell you the last time I talked to a customer that was worried about what version of the net framework or what version of Python I was using to deliver services to them.
And so I think it's a little bit interesting that folks are, are looking for that level of control with some of these models. And I think that if we zoom out and ask ourselves, you know, apply the good old five why's to why folks are looking for that, they wanna make sure that as new models are available, it doesn't cause functional regressions in their agents. And the thing is, like we were talking about earlier, that's quite literally why we have tests and evals, right?
And, and that's where, by the way, if for some reason, even though I don't think I've seen it practically speaking in the last year or so, if folks did see a regression as a result of a new model, awesome. At that point, yes, you want the control to, to go back to an older version, but we're not really seeing that in practice that much. So, Yeah, no, and, and it's, uh, this speaks very, this this talk track of, of multiple tools for your SaaS apps within, within the, the, the business environments is something that, uh, it's a shared pain for security teams as well.
Because when we speak with security executives and, and, and, and their teams, they are swiveling between, uh, uh, multiple tools on the environment as well. As a matter of fact, we're we, we, we are working now on a, on a report on security platforms precisely on, uh, on that note. And, uh, one of the areas that, that, that we are tracking is, uh, uh, AI for security, right?
In the context of how do the, the, the, the, the agents that are now being deployed within Sentinel, for example, right? Uh, are, are, are helping with, okay, let's, let's, let's do exactly what you're describing from a local no-code perspective. I know it's on the power platform, but we're seeing a similar thing on the security platform as well.
And there, and there is tremendous interest in doing that, provided that yes, we've, we've handled the, the, the governance and, and risk constraints around those. So absolutely, this is a, this is a phenomenal time. The, the, the joke I make is that, uh, like, listen, you can't wake up at six o'clock in the morning, go to bed at midnight, and, and this stuff that keeps coming at you with, uh, with opportunities, right?
It's, uh, it's information to collect, it's, it's, uh, information to to, to parse and opportunities to make improvements. Perhaps you can use agents to help you with that too, as you are thinking about how you're evolving the, the, the power platform. And what have you been looking to improve in terms of security and governance capabilities on the platform?
Where do you see the platform going in terms of one of the things that, uh, this is more of a higher end use case, but we do see requests for regulatory compliance. Like remember when the internet was new and people started creating, like those blogs that talked about like what they ate for lunch or what their dog did that afternoon because they didn't know what else to do with it. I kind of, I kind of feel like we're in the same place right now with, with ai, and so I would definitely want to preface anything I say with these are early innings, and so kind of don't know.
Okay. Okay. At the same time as we look at, you know, the types of regulations that are coming into play with the EU AI Act, you know mm-hmm.
Some such examples that we're seeing there are like, Hey, these particular types of data need to be handled in a particular way. And one of the things that we've started doing within copilot Studio is surfacing those data labels, those information protection labels in the response so that folks don't enter, um, inadvertently start working with sensitive data in a way that they don't intend to. Um, and I foresee that in the fullness of time, this will continue to grow.
Like one of the things that, that we're seeing is we have a capability in the platform today called Advisor. Um, an advisor constantly scans over the agents and the apps and the automations to make recommendations in kind of like a reactive governance or reactive security perspective, because we believe strongly in the principle of trust but verify. And one of the things that we're starting to see with advisor, and the way that it can iterate through, you know, like AI generated app and agent descriptions, is we can actually start to flag when some of these apps or agents may be getting too close to that boundary of what, you know, acceptable use policy within a company looks like.
And so there's definitely something interesting going there. So one of the areas that when we speak with security practitioners comes up a lot is they are balancing two very distinct problems. On one hand, they are absolutely swamped.
The other is we need to balance two things on one hand, we want to use as much as possible of the broader tooling we already have the security platform conversation that, that, that, that we are observing, right? That being said, there is still, uh, in many cases, particularly the more novel use cases, there is a need to work with third parties. What's been your experience navigating this, this, uh, platform and ecosystem, um, uh, scenario in, in the conversations you've had as people have been using your platform?
Yeah, I think that what we try to do is we try to start from first and foremost providing, you know, those foundational security primitives that people need to, to be able to leverage these capabilities safely. And that that has to be native within the platform, right? Like, if I have to go find an authentication provider or find an authorization service or figure out my auditing and, you know, uh, those sorts of scenario, like that's a non-starter, right?
And so we have to provide those capabilities from the get go across power platform and copilot studio. I think the next layer above that is, if I think about the tools that someone in the CISOs organization is using on a daily basis, I'd love to think that they come to the power platform admin center every day, but I know that's not true, right? They're spending their time in, you know, defender experiences.
They're spending their time in Sentinel experiences. And so it's critically important that all of the telemetry, all of the audit logs and these sorts of things naturally flow into those systems because we have to meet those security professionals where they are. And then I think the, the final thing that we're seeing is there are some unique and novel risks in some cases with ai, right?
When we look at things like prompt injection and, you know, kind of the emerging product categories of like XDR for ai, does Microsoft have some solutions in that space with Defender? Yes. Is it also such a quickly evolving product category that we need to plug into the broader ecosystem?
Yes. And so, you know, the same extensibility hooks that we use for integrating with Defender are actually the exact same APIs that we allow partners like zenit to connect to so that they can provide additional defense in depth when it comes to particular risks like, like prompt injection. Ryan, this was a phenomenal conversation.
Thank you so much for the time. Hey, thank you so much for your time and for all the, all the awesome discussion. And you know, my hope is that folks, as they hear what we discuss today, they, they'll feel confident, they'll feel empowered that they have the capabilities needed to manage that security governance, operational availability risk, and that they'll be able to parlay that into, you know, accelerating how AI is able to transform their business and deliver outcomes for their employees as well as their customers can't wait to see what's next.
I think that, uh, as a, as a ponder on, on what we discussed a few things. First and foremost, this notion that you have been building a platform to begin with in terms of local no-code before, and then building the AI capabilities on top of that does give people the, the, the benefit of, of building on what they've already done. It does give the benefit of tying to the rest of their, uh, of their ecosystem.
And it's, uh, it's as much about the, the, the culture of let's try and get started and, and work on different types of, of use cases without trying to boil the ocean. We're going to build a capability that accommodates different use cases, uh, different levels of, of governance requirements, right? And then we're going to help those teams start to work on those, on those particular scenarios.
I, I, I look forward to seeing how the platform evolves and, and, and capabilities. This area never stops. I, I, one of the taglines I use is, there is never a dull day in this industry.
And that's the case here. Hey guys, thanks to the throw, we're here with Nigel Douglas, who's head of developer relations for Cloud Smith, and we're having a little chat about, well, just how secure is all this code that we're creating with these AI tools, because well turns out there are a lot of issues to think through here. Nigel, welcome Michelle.
Thank you very much for having me. I think everybody at this point who writes code has at least experimented with an AI coding tool if they're not using it every day. But I get the sense that not everybody kinda understands like just how insecure these things are.
For example, you know, an indirect, uh, prompt injection attack can be pretty lethal. Um, what's your assessment of these tools right now from a security perspective and, and what should developers be looking out for? Yeah, That's a few things.
I, I think the main thing we need to remember about all these systems when we're talking about large language models, is that their probability statistics models at the end of the day. So it's really about predicting the next word. Um, when we think about that nature and the fact that it's non-deterministic, it means that if we ask the same prompt 10 times, there's a chance nine people get more or less the same answer and one person gets a different answer.
And that different answer is really between, am I pulling a software package or using code that doesn't make sense? It's not real, it's fabricated versus nine outta 10 times. It's something that genuinely exists in a code base and is reproducible.
And it also seems though, that the bad folks out there that are trying to compromise our software supply chains are getting about how to fool those LLMs into doing things that we don't want 'em to do. So, um, are, is the software supply chain as we currently know, it gonna be much more easily compromised? A hundred percent.
You know, that that's a point add for series will always look at. So if we think again about it being a probability system that's trained on existing data, we have to think, where's that data coming from, you know, the likes of GitHub or Reddit. And if I were an adversary, uh, what I would be looking at is, again, in the case of type of squatting, it does a package exists that sounds like a plausible package that someone's gonna ask for.
And if it doesn't, what if I started fabricating these packages and creating and uploading these packages in public upstreams on the basis that eventually LLM might say, well, here's a suggestion. Why not try that package that I know exists somewhere? But of course it's not good.
It's, it's full of malicious code. Um, so that's a thing that's expedited by LLMs is this concept of stop squatting this idea that, look, if we rely blindly on the output of AI slop, you know, we don't know what we're taking, we're just asking and applying. Um, you may be susceptible to pulling something that an adversary is put there deliberately in the hope that you consume it without thinking.
So yeah, it, I think LLMs it's, it's a fact at this point are expediting risk in a few different ways. The deliberate element where adversaries create malicious patches on the hope that someone accidentally consumes it via LLM. Um, but then there's the other outside of it is, which is, you know, when I started working with Kubernetes, I learn, I take samples from the, the docs and I apply and I start making changes based on deliberate decisions, which is maybe I want to only give access for specific scope, you know, from a network policy perspective, maybe I only allow ingress traffic, you know, egress out of it, uh, on these kind of decisions.
Um, when it comes to ai, if you just say, create me a workload, it doesn't immediately say, well, I'm gonna create the workload with these security considerations in place. Because unless you prompt it and ask for that consideration, people are blindly consuming code that is generated that is arguably insecure, and that's not deliberately to be insecure. It's just, it wasn't part of the prompt consideration.
So yeah, there are so many things to think about from a security perspective that I question our developers primarily focused on the security aspect. I would say probably not. Mm-hmm.
Are we just waiting for some sort of cataclysmic event then before we all wake up and smell the coffee? Because right now it seems like, you know, everybody and his brother's so obsessed with the productivity gains that nobody wants to talk about. Anything that might be, well, shall we say a downer?
Yeah, I, I, I think we may have had that incident in the last couple of days. So, you know, there's one element when we talk about the likes of the Claudes and cursors, these tools that already exist, but people keep pushing towards, can I have it do everything for me? This fully idea of ag agentic, you know, if I could ask an AI agent go and do something and just run it as a background task, will it make me more productive if I'm just on autopilot, I'm not involved.
And you, you may have heard the open cloth projects that came out and well, it's grown in popularity in the past two weeks, but essentially what you were doing was running this on your local hardware and saying, here's route permissions to go and be agentic and do what you need. And of course, a lot of people were compromised in that time. You know, people are pulling skills from public repositories 'cause it's all done for me, this is fantastic.
And of course, we don't know what's bundled in those skills. We don't know to what extent this agent will operate, you know, will it accidentally delete something or will it deliberately delete something? And what impact will that have on us as a an organization?
So yeah, these are the sort of incidents that are happening now is this blind trust of, well if it's ai it's gonna be better than me, but what adversaries compromise that? So yeah, that, that's probably the first real example we've seen so far. And we don't even know what other AI agents, those AI agents might be hanging out with.
'cause my AI agent could be perfectly benign, but those other ones could be fairly malicious, right? Yep, absolutely. So the idea here with this open claw is fundamentally is open source, so anyone's free to contribute.
So the idea of any type of hub since the beginning of time, if we think GitHub or we think of Python's, pi, PI or NPM for JavaScript, all of these are public repositories where it's fundamentally the core control of open source is that anyone should be allowed to contribute. But if I'm bad and you are good and you're going to your effort of creating something for community and you're uploading it for goodwill, and I'm just making malicious things and calling them similar names to yours, you know, for every good thing that happens, there's always gonna be bad things. And I think the same's happening now with ai, the difference now is the development is so fast.
I don't think people fully understand what these models are, the data sets associated with these ideas of skills that if I wanna play around with ai, I'm just gonna grab everything I can find off the internet. And of course I have no idea what I'm downloading at that point unless I actually understand what these models are. So what are we supposed to do about all this?
Because I don't think we can put the AI genie back in the bottle at this point. So are there things that organizations need to implement, especially say the DevSecOps teams that, you know, are ultimately responsible for all this stuff? Um, and and and how hard will it be to do that?
Yeah, so I mean, there's a lot of things we can think about. I always think about having like clear controls that are consistent and static in some way. So policy's always a good one.
So, uh, a type of rule you can set in your organization is like, again, this is where someone like Cloud Smith comes into place where we say, if you are pulling everything from your own private registry, assuming you audit everything that goes into your private registry, but at least you can put the control there and say, well, we only allow our developers to source from this private registry. So this idea of everything coming from public registries and we don't know what's in them is a real problem because we don't know what we're sourcing. At the end of the day.
We don't know what's running in our production systems. That's the world we don't want to live in. Um, then aside from just saying I wanna source from private, you also want to, as part of that registry control, you wanna have some kind of automated guardrail in place that that's going to do the scanning to tell us what is or is not defined as good.
So when it comes to ai, again, whether you think of something like, uh, hooking face, we have these models and data sets and we have essentially, you know, Python scripts at the end of the day to do this statistics. Um, we just have to understand, well what of those have certain file formats, which file formats can, for instance, be executed? Should we scan them to see if those executable files are potentially containing something that's deemed malicious?
So there's all sorts of open source projects that have existed. You can think of the, you know, clam avs of the world that could scan and say, I see a signature that I don't trust and that is therefore bad. But then there's also projects like, um, the open SSF, you know, they've put a, the, uh, malicious packages project in place.
So with that, they will define what are or not good malicious things, um, from these public registries. So when we have something in our private registry, we want it to automatically check against that open API to say, okay, you have a package in your private registry, but it's deemed malicious by this organization. Do you wish to continue with it?
Of course you would say no if it's deemed malicious or at least with a high level of scrutiny. Um, and we need to think about that as well. For all these new AI technologies that keep appearing.
So, you know, open, uh, source malware, which is of the things to open SSFs project, they now deem these AI skills in the same category as software packages that come from public upstreams. They deem it in a case that any person can create a skill, therefore every hacker out there can also do the same thing. And because of that, you are now in a, a wild west of skills that you don't understand how the code works.
How could you possibly know if it's malware or not? So yeah, we definitely need kind of static guardrails in place to say, these are the things I have. Check them against public APIs and say, do we know if it's safe or not?
And then how do we proceed? Otherwise, we're just consuming from anything anywhere. How do we have this conversation with the developers, many of whom are, shall we say non-conformists and have skills and they'll just spin up a server in their basement and start writing some code on something and then when they like it, they'll upload it into something.
You know, that feels more like a standard corporate DevOps workflow. But you know, as far as anybody knows, the, you know, it was created with some level of alleged oversight, but maybe not so much. So how do we kind of get everybody on board?
Yeah, it's true. Like I, I love Anthropics wording when they talk about plot, where they say essentially it's not truly age agentic because even though it can do things, there should be a human that's in control of this, at least from that level of control. They're the ones making the ultimate decision.
Do I apply, do I even push this thing into production? It's not hands off. Totally.
Um, I think those projects that we saw recently, the likes of Claude Bots, fully iGen system, um, I think those are still very much pet projects for now. To your point, anyone can have a home lab running in their basement. I can run this tool, it's open source, completely free.
I can run on a a Mac mini. That's what everyone's gonna see buying to run it on its own lightweight. Um, but when we do that, again, it does or doesn't do what I expect it to do, would I replicate that thing in my home lab and then put it in production for my company?
Probably not. You know, and I think that is where we're at today. It's that a lot of these things that seem scary, are we actually using them production?
I think we're so far away from that today because we have to look at non-deterministic systems and think, okay, how is it going to be used? A, a perfect example is you want a consistent response to happen to customers every single time. That sounds good.
Well, just by definition of non-deterministic, it can't determine that it will give that same output unless we put some human guardrails in place, like system prompts to say, in these conditions, always give the same thing. But when you start doing that, it's going back to what we were already doing, which was coding and saying, here are the hard coded rules of how you respond to things. So I think organizations, developers still have to go through heads of engineering, platform engineering, whoever it is that sets the controls and standards, and they drop at the end of the day, the design for how we're gonna use these AI tools.
You know, something like a clo, a cloud, it makes sense. It's something that's running in your environment to help you be more productive. But in regards to these agentic systems, I think companies really have to look at themselves and say, what are we trying to build at the end of the day?
What problems are we trying to solve? And if it doesn't solve a problem, how do we actually go about using, or do we use it at all? Um, but the security is a big part, you know, until we know how we can consistently secure it, can we really put it into a, uh, a highly regulated environment?
Probably not, you know, so, so it's, it's an interesting problem. So does that create something of a paradox where we're writing more code than ever faster, much of which after it is checked in, isn't making it into a production environment? Because once it gets reviewed, it's determined to be, have all kinds of flaws in it, and so we just kind of create this endless hamster loop to no point.
Yeah, I, I absolutely, you're hearing more and more companies coming back with that feedback of, okay, we fully speed up process. Like, I don't think code writing code was ever the problem. I think it was designing architecture that matters and is efficient for organizations.
So yes, you know, these, a toolings create more code than ever before and faster than ever before. But at the end of the day, if something goes wrong and you haven't wrote the code and you don't understand how the code works, you're gonna spend twice, if not longer, as much time, um, reviewing it, making sure, okay, how does this nested loop system work? And why does it work the way it does?
Whereas when you wrote it and you didn't use an AI assisted code, and then someone said, well, this function's not working, you can say, well, I, I wrote that function and I know why it does this, because I wrote it. So that is a big problem. I think more and more organizations will only learn from experience where you test it and you say, this workflow actually wasn't as efficient as we wanted.
And it also comes back to the same problems we talked about there with the ai, which is, you know, what are we trying to solve at the end of the day? Was the issue writing code, or was the issue writing secure code? Um, I can still see how AI is gonna solve a lot of problems, which was in the past, there was this tech debt problem that we write code and we can't write all the code out there.
So we use software dependencies and libraries and public sourced registries because there's no way we could write every single thing we want into our code base. But if you could use AI to write, essentially rewrite, you know, some of that functionality without needing to use libraries, I can see a world where AI is gonna reduce the amount of vulnerabilities in our code base. If we have implicit design structure in place where we start thinking about, okay, how can we make our code more secure using AI to actually generate that code part, you know?
'cause again, writing code was never the hard part. It's just riding at a pace, doing it efficiently is, was always a trouble. Will we create AI agents to essentially manage the AI agents that are writing the code?
And that ultimately may be how we lick this problem, because we're gonna have two sets of AI agents, or maybe three or four doing different jobs, but we're gonna have to surround the AI agents writing code with AI agents to help manage and ensure that their workflows are followed properly. Yeah, again, that, that is a world that's possible. I think it would be highly expensive as well.
'cause you gotta think about as well, if we're using these tools that have an API and we have rate limiting, or we have, for instance, we're charged for the credits that we're expiring, um, can we build a whole ecosystem where it's just agents that we're paying for to do that? Uh, probably not. Um, I can see a world where we have more considerable design considerations.
So we say, look, um, we are building a code base where we only want to use these programs, these dependencies, the things we trust. Again, that's something that Cloud Smith can solve, where we say, well, developers only source these things and anything else, we don't trust it 'cause it's not part of our original design. Um, and then there's other static controls in place where you say, for instance, whether it be a policy in Cloud Smith or a policy elsewhere saying, we only trust these file formats, these dependencies, these whatever it be.
You are made very explicit about the things you do and don't approve everything else. Again, implicitly would get denied. Um, I think that's probably a better world than having the AI be the, the gatekeeper of more AI necessarily.
Mm-hmm. Um, so to your point about all that, do you think that there's gonna be auditors soon who are kind of like, you know, rubbing their hands together with some level of excitement going, Hey, I can't wait to scan all this code and find out all these ways to loving new fonts? Yeah, I, I definitely think so.
I, I think a lot of testbed projects are now showing up in production that, let's say there was a race, a global race to get AI tooling out there to market. So people can say, look, I am an agent leader, please fund my project. But you have to wonder in that pace, were they thinking about security?
Was that the primary focus? Probably not. And we've seen that with other industries as well.
We see that with, uh, smart devices, that it was such a rush to get gadgets out to market that could monitor your health and wellbeing. Turned out a lot of those were insecure as well. So I, I don't think it's a uniquely an AI problem.
It's more of a, an industry and market problem. All right, folks, you heard it here. AI coding tools might just wind up being one of those things.
That's too much of a good thing. Hey, Nigel, thanks for being on the show. Uh, thank you very much for inviting me.
All right, and back to you guys in the studio. There's no doubt that AI will deeply impact enterprise software, especially as agentic AI rises in importance. But it's really an additive process.
This episode of utilizing AI features amidst a very of ServiceNow, Nick, patients of the RUM Group and John Schwartz of Textron, considering the future of Enterprise Software. Welcome to utilizing ai, the podcast focused on practical applications of artificial intelligence from the Futureum group. Every Wednesday, we explore news and use cases of the ways in which AI is transforming enterprise IT and the industries it serves.
I'm your host, Stephen Foskett, president of the Tech Field Day Business unit here at the Futurum Group. Before we dive into this discussion, let's meet who's on the panel today. Hi, I'm Nick Patience.
I'm the AI platforms lead at, at RUM research. I focus on, um, enterprise ai, uh, both at the application layer and, and down on the infrastructure layer as well. Hey, I'm John Swartz.
I'm the West Coast Bureau Chief for Techstrong and, uh, which is part of the Futurum Group. Um, I write about ai, write about it, and write about digital CXO. And it's great to be here again.
Hi, this is Amed Zari. I'm president, chief product Officer and COO of ServiceNow. Uh, I've been working in a software space for 30 years and really excited about having a conversation about AI and software.
Well, let's dive right in then. Um, we have heard many people say that AI will be in the end of enterprise software, that somehow AI is going to be an alling all dancing platform for basically everything that enterprises use. I disagree with that.
And, um, Ahmed, I think you probably disagree with that too. Let's start off by just, uh, kicking off. What is your reaction to that whole sentiment?
Yeah, no, I mean, uh, there's definitely a lot of this conversation about what AI does to enterprise software, and I've spent 30 plus years in enterprise software, and I know how complicated and what it takes to run a business. And there's a huge amount of context, huge amount of understanding of a business, uh, processes, as well as, uh, kind of governance and security required. So there's a decent amount of understanding, uh, which you need to really bring in when you're running enterprise business out there.
AI is a very good, uh, technology enabler as well as opportunity for us to redefine and re-architect the products which we built today for enterprise software, because it adds a lot of value. But having AI replace everything enterprise software does, it's really not possible. And we've seen this on a day-to-day basis.
I mean, LLMs have come a long way today, uh, but today not a single company runs just on standard A LLM. Uh, they do require a huge amount of context and huge amount of capabilities, which is built around those, uh, AI building blocks. But there's, uh, work to be done, and that continues to happen, and enterprise software is, will continue evolving to really make sure we deliver what customers need.
Uh, without just saying that AI will take over everything out there. So emit, you've, um, you've led the transition to the kind of agent AI era at, um, at, at ServiceNow. So how do we move, um, from AI that, um, simply suggests actions, um, to AI that has agency to actually execute multi-step workflows, um, across the, the enterprise without, uh, constant human handholding?
Yeah, no, I think you're right. I mean, there is, there is an opportunity now with AgTech to automate a lot of the business processes. There's always been this in interest in enterprise software to automate and remove as much human interaction as possible.
And AgTech and AI turbocharges that for sure. Right? So the way to think about this is you think about a business process, what are the pieces of business process, which you can now automate using ai?
Uh, but there are a lot of deterministic capabilities also required because what AI does is gives you a probabilistic answer. Now you wrap that around with the data you might have for years in terms of running workflows, like what we've been doing at ServiceNow for 20 years. What we do with this probabilistic kind of workflows or agent workflows is add the data element and say, Hey, is the outcome accurate?
This is what you're supposed to do or not. And if it's not, you go back and redo things or bring in a human into the loop as needed. Uh, but that has to be done end to end not doing pieces of it.
So when you look at a business process, uh, any of the standard ones, right, order to cash or procure to pay or things you might be doing for it, service management and other things like that, you require the combination of what a context is, what the data associated with the particular outcome is, and then AI enabling and kind of making some part of the decisions. But it cannot take over the whole thing without having some data associated with what, what the outcome should be, uh, what we shoulda have expected from that. That's really what we're seeing now.
And ag, uh, uh, processes are very powerful. It does reduce your cost, it gives you, makes you more agile, uh, as, as well as it gives you some, uh, ability to improve how companies run. But you hate to wrap it around in many, many other things as well.
So, Amit, your appearance is pretty fortuitous. I mean, today, the day we were recording, you announced this expanded strategic collaboration with OpenAI. I'm wonder if you could go a little bit into it.
I guess the, ultimately what you wanna do is deliver advanced ENT AI to enterprise customers. Um, part of this mad scramble among all the companies in terms of their workflows. Can you maybe discuss a little bit about what specifically this addresses and how impactful you think it may be?
Yeah. So we've been working with all the Frontier Model company, uh, providers for many years now. And, uh, we have been always an open ecosystem.
So the work we're gonna do with OpenAI, which we've been using them as the one of the large language model choices for our customers, uh, in the first phase, we were doing a lot of summarization and giving ability for people to comprehend what happened as an action. Uh, the next phase as we evolve some of those capabilities is to really now use large language models for voice capabilities. For example, multimodal, multilingual, so that we can understand what the cus what the user is trying to say, but the intent in terms of knowing what the context is and then be able to action that.
That's really the IP ServiceNow has been building for many, many years. So we still use this large language models to kind of take out some of the mundane pieces of our work and understanding lot more of, uh, user data, uh, faster. And that's the relationship we've been building with open ai.
We do the same thing with anthropic in some cases, and we do that with Gemini, but our goal always has been to use what our technologies out there and the advancements in there, but then build a lot of IP around it to make those things much more efficient, much more context driven, and much more valuable to a, a customer. So we're doing this for now, say employees, right? Understanding that employees are requesting help.
What does that help mean? Uh, if they re requires, require requiring a fixing of VPN issue or they're requiring a new laptop, or they want it to be onboarded, once we know what the request is, we know what that needs to happen because we've been doing that from the backend, from an agent perspective with human agents before now with AI agents. And OpenAI helps us now take that data and wrap it around to integrate with various different systems, but then our, uh, agent processes and things we build in our AI platform is now doing the actioning part of it as well.
So that's the relationship, and we keep on evolving that, but there's a lot of good technologies coming out, and we use that as a building block, and I would say five to 10% is IP from them, and 90 plus percent IP has been built by ServiceNow to really get you the outcome customers want, because customers shouldn't care what you're using underneath the covers. It's really the outcome driven kind of mindset. Yeah, that's really important with a solution like ServiceNow because you are reaching far beyond the technical IT staff.
And I mean, really this is a solution for the entire business. So having it be able to handle multimodal interaction, which, you know, as you said, uh, voice, uh, video, you know, things beyond typing and certainly well beyond coding is really consistent with the goals that the company has had since the very beginning, which is to make this sort of process automation, uh, applicable beyond the typical enterprise IT staff and, and really, uh, useful in, in the entire, uh, in the entire staff. And that's something I think that, uh, generative AI is particularly good at is, uh, you know, acting as sort of a user interface.
Nick, this is something that we've talked about quite a lot on the podcast. What's your reaction to the direction that ServiceNow is taking? Yeah, I think it, I think it makes, um, it makes a lot of sense.
I mean, it, it's, it's, it's an interesting to watch a, a fairly mature, um, software company like ServiceNow is obviously, yeah, as other companies that have been around longer, but, but you very mature now, um, adopt AI in a way that, um, actually speaks to some of the problems, um, that, uh, the, that companies face. And also you obviously, you're not trying boil the proverb ocean from day one. It is very much, you know, you understand your use cases, uh, extremely well.
Um, but your use case is also expanding a little bit, aren't they? Beyond, beyond the kind of yeah. The it operations into, into HR and into, into other, into our other areas as well.
So I think it's, it struck me as a, as a, a fairly pragmatic approach. And I guess, I mean, I mean, um, I mean, you came, you came from, you had long time at at Google and, and, um, and, uh, Oracle as well. I mean, how does that, that kind of experience, how has that informed what you've been doing at ServiceNow for the past, um, I guess almost two years now?
Yeah, no, I think as you point out, I mean, we've expanded our use cases in quite a few areas, right? So what we did when I joined, I made sure that one, we are very clear about the customer outcomes, what we trying to solve for, what are the areas where we can be differentiated as well as value add, uh, to our customers. So we did gotta pre-packaged agent flows and say, you know what customers, if you're doing this currently deterministic workflows, can you replace that with Gentech while I guarantee you an outcome?
And that resonated a lot with customer. Second thing we wanted to do was really think about controls, be it around governance, security, auditing, and giving customers visibility in terms of what they're doing with ai. Every customer I spoke to and every C-suite, uh, member I spoke to, they were worried about proliferation of AI technologies without any idea what happened, who did what, and who's running what.
Right? And that doesn't work in enterprise software. This is not like you can just click to a different website and start using something else.
You have to make sure a business doesn't come down or also anything which is outcome, which is wrong, and it really impacts your financial standing and everything else. So we had to make sure that we're building that controls, providing governance, providing all this scaffolding required and guaranteeing customer confidence as soon as we gave them a lot of this thing. And we launched this product called AI Control Tower, which allowed you to get visibility, uh, lifecycle management of AI technologies, ours and third party, as well as the ability to now audit and do risk management.
Once we gave that to a customer, they started doing a lot more use cases after that because they got that worry outta the way. So my experience at Oracle, my experience at Google, we really understood that ai, uh, at Oracle, of course, understood what enterprise software means, what it means to really run large companies business without having any kind of, uh, wrong outcomes. Uh, Google gave me a very good grounding in terms of what AI is capable of, what you can do with it, and it's really amazing amount of IP being built there.
Uh, but combining the two is very tricky, and that's what I think the ServiceNow has been able to do a good job of is really taking AI building blocks, using that as a technology provider and using it where it makes sense, but then really building the frameworks around it and making it easier for customers to get value outta it. So our AI control tower, the workflow, the connectivity with third party systems using AI agents, what we're doing from the perspective of, uh, understanding intent, uh, and it could be need domain, right? We're doing it for hr, we're doing it with finance, supply chain procurement, and now expanding it to CRM and then security and risk.
Those things made customers much more comfortable that we're looking at it end to end. We, we call ourself, uh, the enterprise operating system because of that, like going east to west and not to south, we're just not a verticalized tag, but really looking at business processes, which cut across. And that has been the, the goal, uh, game changer for us in most of the customer conversations.
And that's what we bringing to the table to our customers, and they still feel, feel very excited about what we can do for them. So if, if you can indulge me for a second. So I, there's no question AI agents are gonna be integral.
They're, they're absolute necessity within enterprises, but, um, we've kind of gone through this, this timeline where we are, there were a ton of announcements, including many from ServiceNow in 2025, and I, I'm kind first kind of an observation what I, that I'd like you to address, and then I have a question. The observation is, where do you think the adoption of AI agents are now and what are the real risks for enterprise that enterprises that try to adopt AI without modernizing or integrating their core systems? Yeah, no, I think there's been, of course a lot of promises out there.
I mean, as you said, there's a lot of announcements. What we've been very happy about and very excited about is the adoption we've been having, uh, with our now assist product. Uh, we have delivered that early last year.
And as soon as, as I was talking about earlier, this AI control tower, once we gave that to customers, they started feeling more comfortable going to use cases. And I'll give you an example of companies like Bell, uh, where they've been able to now use all of the customer service. Our AI automated agent flows for doing deflection, but also understanding intent and resolving issues.
So I'll tell you the common use cases we see in adoption wise, incident management, uh, resolution of, uh, any kind of, uh, request, uh, things like triaging, uh, coordination of any kind of, uh, issue they might have run with, uh, disputed disputes. Like things we are doing with Visa. When a customer requests an issue with the credit card bill, having that been automated between a merchant, a credit card issuer, uh, the consumer and Visa in an automated fashion, and reducing the friction around that has been a game changer for them because they're reducing cost using AI agents.
But it's an agent flow, not just an AI agent talking to each other. Right? Uh, what we've introduced recently is this idea of taking out, uh, L one support for any IT related requests, right?
So autonomous it, we call it. And that really changes the game for a lot of the companies because a lot of these questions and requests they get, we can resolve it as an agent, uh, employee in a way who's doing all the work for the request request and resolving it thing without having to really file a ticket. And when you file a ticket, we resolve that without having human interaction.
So that are all use cases we're seeing live being used, and we have customers across the board who are adopting it. Last quarter we announced the adoption rate went of 55 x in terms of the amount of in calls we getting back and forth between our AI systems and the Gentech use cases. So adoption is there, there's gonna be turbo shot this year, I think.
Uh, but there's a lot more comfort in, in this area from our customers than probably previously, uh, out there. So Amit, there was a, um, late, uh, 2025 service. ServiceNow made its biggest acquisition ever with Amiss and also bought to Visa, or I guess that's right.
So this kind of, I assume signals that you see security as a foundation layer of, um, of, for a AI and AI in particular. So why, why was it necessary to, to make those acquisitions, um, now especially, especially amiss, and what does it say about the kind of future product direction for, for ServiceNow? Yeah, I think, uh, we do believe, uh, security.
And so we, I don't know how many people know ServiceNow has a billion dollar plus business in security already. Uh, we've been building out a security stack and portfolio, especially in post breach, anytime an incident happens, all the life cycles, CISOs depend on ServiceNow to manage that. We integrate with Palo, we integrate with CrowdStrike, we integrate with of the world to really manage the lifecycle of any incident and resolving it and then managing the auditing and everything around it.
We see a lot of customers asking us for now, one, how do you manage the identity of the user? Uh, especially now we go into non-human identities, be it, uh, AI agents or, or devices. So the basically does identity governance, which has been a big, big kind of use case for ServiceNow already, because all the employee, when they join a company or an object you add, or asset, you add the lifecycle goes through ServiceNow.
So was a very natural extension for us to giving this identity governance for especially non-human identity. Second thing with, uh, arm, what we saw was IT and OT starting to come together. What ARM does is provides OT security, the operational technology, so any kind of manufacturing, be it devices, robotics, uh, be it, it, uh, IOT devices, how do you secure them?
So when a lot of the, what what ServiceNow has had is a product called cmdb, which tracks all the assets inside the company, hardware and software assets. That's becoming kind of the gold standard for companies to know what's inside their enterprise and how to manage them. So security around that is becoming very critical.
So customers been coming to us saying, Hey, you already know our assets. Can you really make sure that there's no breaches associated with that? So vulnerability management, as soon as you get signals, and then again, the exposure management around that is what ARM does.
Combining it and taking it to the OT environment and making it end to end, because IT teams are really managing the OT environments for manufacturing, uh, or any devices they might have inside the company. Uh, give you an example. JP Morgan Chase, the new building they put in, they have so many devices, iot, wireless, other things like that, the security associated with that was all been done by arm.
So we manage that asset, then a lifecycle, any incident happens, goes to ServiceNow again. So completing that lifecycle was very critical for us because the customers asking for it. We've giving pieces of solution, not end to end.
And as you move to AgTech, you have to think end to end. You can't just do pieces of it again, uh, without, and it has to be some partnership and some things we have to build ourselves. So our mission closes the gap for us and really expands our capabilities, and it really plays into the idea of having an open ecosystem with third party systems while we, we help them manage that lifecycle for any asset associated with that.
So that's the reason why we bought those companies. Uh, it adds a lot of domain, uh, and really expands into the security space, which we believe we've been doing very well, and our customers are pushing us to do more and more. I'm, I'm glad Nick asked about cybersecurity because, and I didn't realize how large your security business is also.
So I'm glad you pointed that out because that's something that kind of goes underneath the radar. And in a sense, I always think there's a gap and, and maybe this is one of the reasons why there is kind of a slow adoption of genic ai or a reluctance among some companies because there's that whole security issue. And that's something that when we do, Textron gang, and Steven can vouch for this, that point is hammered home that security slowly evolves rather than is revolutionary.
And AI definitely is revolutionary. So there's this gap between the adoption of AI and the urgency of now versus the consequences of a security issue. And I'm wondering, do you think that's still, uh, a significant issue or will continue to be a significant issue for enterprises that are thinking of diving whole hog into, into genetic ai?
Yeah, you're right. Uh, John, I think, uh, without security, without having a confidence in security, confidence in risk management and tracking what AI is doing, there will be reluctance to adopt AI in enterprises. I think the other parts of the world might be, okay, so if you don't sell the make, solve the foundation, have AI built, AI built with cybersecurity in mind and the ability to control it, I think customers will be very wary about not knowing what is AI doing into their environments, right?
And that's why we are doubling down on building a stack our platform. We still have this concept of one platform with one data model, one user experience, as well as one kind of end-to-end architecture bringing ai, bringing security built into the platform, not a bolt on, not something on the side. And that has to happen.
I think whoever wants to be succeed in this space has to really think about that as ground up as a P zero and then build everything around it to really make a customer successful. And that's the foundation we've laid down, and it has resonated with our customers, and they're getting a little more confident as they continue down the journey. AI is going to stay here, it's gonna be a game changer, but you have to do it thoughtfully and need to do it in a way where enterprises can benefit, uh, and not really get into risky environments, which really, uh, crumble the businesses.
So Amit, we talked earlier about, uh, the open AI partnership, and, uh, that's obviously, um, you fairly hot off the press, but you, you also have this, um, this, uh, partnership with, um, with Nvidia, um, with, uh, with its, uh, you, the, the models, the ael nitron, um, models. I'm just curious about why you, why, um, and, and, you know, why domain specific models and why reasoning models like, like that one, um, are better for a kind of service desk environment than, um, say, um, a general purpose LLM? Yeah, I think a few things.
One, see open AI and other large language models don't run in sovereign environments. They don't run in, uh, on-premise customers. We have customers which, which deploy software in many ways, public cloud in our data center, as well as in private cloud environments, as well as sovereign cloud environments.
So we have to cater to all those different kind of deployment models, and that's why we wanna give customers choices in terms of what they can use as a building block, which might meet their require security requirement, but also deployment requirements. So what we're doing with Nvidia and April, it's been pretty impressive in terms of what we've been able to build, uh, from, uh, those, uh, domain specific models is to kind of take some use cases, Hey, we can use this in this particular, uh, use case without needing a large language model or a frontier model in a way. Uh, and also it'll meet the so sovereign or any kind of deployment needs customers have.
So that's why keep on, we keep on having that investment going to ensure that customer choice is prevailing, uh, but also we understand what is the possible in many, many different cases, and can we reduce cost? Can we give you better outcome? Can we compare to different, different, uh, scenarios?
Can we do different pro uh, do a better prompt engineering? So that also helps engineering team get better when they kind of mix and match things and really get the best, uh, outcome for our customers as well. So we'll continue that part, and we'll ensure that customer choice remains, uh, and, uh, it prevails long term.
That makes sense. Just a quick one on, um, sovereignty. You mentioned it as one of the reasons for that partnership.
So are you seeing that, um, as an increasing concern for, for CIOs, um, across your customer base? Is it, is it geographic specific thing still, or do you see it across The world? No, we're seeing this globally, right?
And it depends on the industry as well. So it's more industry driven than a particular region. But I think as you've seen with some of the, uh, geopolitical theft stuff going on in, in the world right now, there's a lot of, uh, requests now coming from countries outside us who wanna run their own specific environments, and they don't wanna be completely be, uh, on a public cloud some cases, or they don't wanna be outside the particular country.
Uh, so that requirements are pretty common. It had gone up over time then it was probably a few years ago. Uh, we're seeing it by regulated industries as well.
Uh, so if you look at public sector for sure, but, uh, banking, uh, we think we see this, uh, in, uh, some of the things around manufacturing and other areas, uh, where it could be very specific use cases. They don't want that data to be outside their particular domain. Uh, so that, that, that use cases keep on emerging that a lot of local providers we work with in a particular country, because, uh, those customers in this country wanna depend on those local providers as the infrastructure providers, and we wanna make sure we support that as well.
So we run on all HyperCloud, uh, uh, hyper cloud providers. Uh, we run on our private data centers, we run on customer data centers. Uh, we run on a lot of those, uh, now, uh, I would say it's sovereign providers in some countries as well.
So we've been always thoughtful about what our customers need and where we wanna be to meet them there. You probably already touched on this, but I kind of want you to go a little bit deeper on sovereignty. I can't pronounce that word for some reason.
Um, but Deb, can you maybe talk a little bit more about that? Yeah, the sovereignty, I think the way to think about is, one, there could be multiple, there are multiple levels, and we can spend hours talking about it because it starts initially. First is data residency.
You wanna make sure data doesn't leave, uh, particular en a particular region or a country, right? That is usually, uh, p zero for many customers. Second is who's touching the data?
So once it's le not leaving the country, who's running and operating that environment, it could be citizenship of the people who are involved, involved with that particular data center or the infrastructure. Uh, third is that, uh, whatcha interacting with, uh, with systems, who is the provider? Uh, so that could be another, uh, thing.
Fourth is, are you gonna connect to anything outside? Is it completely, uh, uh, disconnected more in a way, right? So that there's no other, other than the customer's environment.
So there's so many different levels of sovereignty requirements, and we have to cater to very different, different needs depending on what the use case of a customer is. In some of the government and work we do, uh, those ones are much more stringent. Some of the industry specific, like banking and all may be regulatory driven.
So you need to kind of, uh, address those requirements. They come up with. Uh, it's usually around data access, people, uh, systems, connectivity, so various things.
And they get more and more complicated as you go down those conversations. And that's why you need a lot, a lot of good local partners, as well as you need software which is flexible, so you don't wanna keep on rewriting it. So you have to architect it in a way that is one, uh, very flexible in terms of how it's deployed, but second is very secure and it gives you controls.
So you have to have visibility. And this is where I think when you talk about ai, lot of those things are always missing. A large language models and things like that have no way to give you controls.
It does what it does, and there's no split brain, right? This is one thing and it does everything. And you land up not having idea of what happened behind, and you cannot have black boxes in sovereignty.
You need to know what was touched, when was this touched, who made changes, all that whole attribution needs to be required as well. So those are the sovereign requirements. So they're getting more and more complicated.
Uh, and that's why we get, uh, companies like ServiceNow are liked by our customers because we understand that complexity and building enterprise software requires a lot of mundane stuff to be done, but complexity is always there. And, uh, you can't ignore those things. Yeah, it, it's really kind of a refreshing, um, and realistic, uh, message.
And I think that enterprises are going to, uh, be more, uh, they, they will be rushing to embrace this sort of approach because it's, it's more mature. I mean, sometimes in the AI space, there's a bit of a sort of fast and loose break things and see what happens, uh, attitude. And that is not at all compatible with the kind of customers that major companies like ServiceNow have.
And frankly, with most of the customers that I spoke speak to as well, I think a lot of them are very wary of AI and the messaging that you're putting out here that essentially this is a powerful tool. It enhances the abilities that we already have, but we recognize that there's a lot more than just throw AI at the problem that needs to be done. So I guess to sum up here, uh, again, this is, uh, utilizing ai.
We're supposed to be very practical here. And I, and that's what I'm hearing from you. Um, let's sum up your message here.
I mean, um, if a customer comes to you and says, oh boy, that AI stuff, how's that going to impact me? What's your elevator pitch to that customer? I would tell customers to be realistic, right?
Uh, AI will impact you. AI is going to be important. Get used to it, get learn it, but learn it in the context of your business.
Don't just do it AI for the sake of ai, right? It has to be part of your solution can be the solution. So it's a building block, uh, re it's reinventing software stack.
Uh, just like a lot of other technology changes have had done. This is probably more powerful than other technology changes, but pay attention to how it runs and operates your business. Don't just take a product out there and deploy it and then realize that your business will fail.
So bring it as in, as part of the overall solution, not the only solution. You know, it's gonna be, it's gonna be interesting to see how companies think about this relationship between AI models, agents, and the enterprise architecture they sit on and, and kind of what the rise of agen AI in particular means for CIOs and tech leaders in practical terms. And it, it's gonna be, uh, fascinating to see how this path or this path leads us, um, and if we fall into the same traps we had before with early cloud and SaaS adoption.
That's kind of my takeaway. And I'll, I'll pass this on to Nick. Yeah, it's been really interesting conversation a minute.
I mean, we, we touched upon the, you know, the, the idea that, you know, we talking about the open AI partnership, the NVIDIA partnership, and it just sort of Rams home that, that point to me, that models are, I find them, you know, super interesting and they are, they're incredibly integral to what we're doing in enterprise ar ai, but they're not the application, you know, the application sits on top and its ServiceNow. And, and companies like ServiceNow that actually did deliver, you know, the, the actual enable organization to realize the value out of ai. So has been really interesting.
Well said, Nick. I completely agree. And, um, thank you very much for joining us for this episode of, uh, the utilizing AI podcast from the Futurum Group.
Uh, before we wrap up, though, uh, let's give y'all a chance to let us know where we can connect with you and continue this conversation. Uh, I mean, let's start with you. Yeah.
We have a big, uh, customer conference coming up called Knowledge, uh, in May, and please join us there. We'll have 20,000 plus people, practitioners who you can learn from and, uh, kind of share ideas. Uh, it's gonna be a great time.
Oh, yeah. You know, uh, I'm gonna vouch for what, uh, Amitha said. I, I've been to that show several times, and it is fantastic.
It's usually at the Venetian, I believe, um, and it's early May, right? Um, well, you can see I'm working on tech AI stuff. I'm on Techstrong gang, I'm on this show.
I, I use LinkedIn in Nord in amount. Uh, I, I kind of shy away from X and I, I've kind of given up on Facebook, sorry, Facebook. Um, but that's where I'm, and I'm gonna be writing about Davos and some of the political repercussions or the, the landscape there in the next couple of days.
And I'll be, I'll be focusing a lot on sovereign ai, um, and over the, over the coming months, as well as digging into the, um, the output from our decision maker survey, which is in the field at everything X as well. And as for me, uh, I'm very excited to have, be leading our AI Field Day event here in, uh, may. So, uh, tune in for that.
But in the meantime, uh, thank you very much for tuning in for this episode of the Utilizing AI podcast. If you enjoyed this discussion, please do subscribe on YouTube or your favorite podcast application and consider giving us a rating and review. This podcast is brought to you by the analysts and experts from the Futurum Group, where insights meet ai.
For show notes and more episodes, have head over to Textron ai, the utilizing AI YouTube channel, or the Textron TV app on your television or phone. Thanks for listening, and we will catch you next week. I'm Ted Weatherford, VP of, uh, business development at Xite Labs, and my distinguished colleague.
Yep. John Kearney. I'm a software architect architect on the E-Series, which is what we'll talk about.
And I'm just gonna kick it off by saying the E-Series is a separate chip, it's a sock, and we call it cloud on a chip because it's got all the elements of cloud. It's got the ethernet connectivity, it's got security, okay. It's got the virtualized, uh, storage, and of course it's got the processing with the arm cores, 64 neo versus two arm cores.
Uh, it's in production, uh, in about four months, and it's been general available for four months. Um, and these are just the different form factors you could get it in. Okay.
We sell a server, we have one here, uh, to show you guys. Uh, and we also have the add-in card, uh, and you can add it into the server. So the server has an add-in card slaughter too, in it, so we can put our own chip as a server and then a smart nick together.
And then we have, uh, the comex and the COMEX is really targeting the control plane applications, but it's actually just a really nice embedded format that, well, you could have a 64 arm core product on. John, take it away. Yeah.
Thanks. So the first thing I'm gonna do is I'll talk about, um, what the architectural differentiation is between our DPU, um, and, um, what traditionally has been, uh, the DPU offerings from our, our competitors. So, um, the, the traditional DPU really started and evolved from a nick.
Uh, so what has happened in the past is, um, the NIC would be taken, there would be some flexibility added within the pipeline of the nic. Um, and then, uh, to add even more flexibility, a CPU cluster would was added to the nic. And this is what, uh, our co competitors architectures look like as A DPU, and this architecture's constrained.
And the reason why it's constrained is because this CPU cluster is not really sized, uh, and the connectivity of the CPU cluster to the offload nick is not sized. So that all of the packets, all of the processing of the data plane could go to the arm cores or go to the CPU cluster, uh, for processing. It really relies on being able to process most of the packets, uh, in the hardware pipeline and only exception packets, or maybe the first packet of a flow, uh, goes to the, the CPU cluster.
And what we found with this architecture is that, um, what we found with this architecture is that for, um, for many workloads, um, there's, there's flexibility that you need, uh, that doesn't exist in that hardware pipeline, and you often are trying to get all of the packets to that CPU cluster, uh, and then your performance is, is limited. What we did differently is we started from that CPU cluster and we said, let's take a very energy efficient, uh, and optimize for data plane applications, server, class, compute system, and let's size it so that, um, all of the packets, uh, and, and in fact, all of the PCIE transactions when you're attached to a host can all be terminated and processed in software using standard, uh, programming models, um, not proprietary programming, um, but just a standard Linux, uh, or user space programming. Uh, and so that's what we started with.
And then we added to that, uh, an ethernet unit, which provides, uh, the ethernet connectivity, uh, and provides, um, some processing that's done on sort of the, the throughput or the, the bits of the packet, like encryption. Uh, and then we added a a P unit, which is the PCIE connectivity, which when you connect to a host or you can connect devices to the DPU, um, they go through the P unit. But again, all of the data plan processing can be done, uh, in the cores, uh, and not in this model on the left where, uh, you really have to get, do most of your processing in the nick, the nick portion of this architecture.
Um, this, this on the right, um, allows us, um, scalable performance, we can scale performance with cores. And again, it's a very standard development model. Um, and, uh, I think, uh, I think we can go to the next slide.
Yeah. The competition does, does it differently. They start at the offload nick, and they add ARM course, and they traditionally, for three generations haven't added enough ARM course and haven't added the more powerful arm cores, like the neo verse twos.
Yeah. So, and it we're really vindicated that with the blue field, right? The blue field's come out and said 64 cores, and it's, it's come out and said, okay, let's put a real compute in there.
So we, uh, we see them as our principal competition. The Intels and the pin sando AMDs are, are still kind of sticking to their guns with the, the other approach and, And your programming model On that solution is Linux. Yeah.
So, uh, we run Linux, we run, and, and we'll get into this more in some of the other slides, but, uh, we run Linux. Um, we, we are, um, we will be certified as an ARM system ready. Uh, actually we're certified as a server class, not an embedded class, uh, meaning that any, uh, operating system distribution that can run on an arm server, uh, can run on our DPU.
And so we see, uh, and we'll get into use cases as well, but we see use cases where customers want to do everything in the Linux kernel, um, you know, all of the, uh, you know, networking stack of the Linux kernel. Uh, and we see a lot of use cases where customers want to use user space frameworks like DPDK or SPDK, and do all of the data plane programming. Uh, in, in user space.
One of the big advantages that we have is that, uh, a lot of these data planes already exist. The customers have been running them on servers, um, and now what they can do is they can take those data planes that they're all running, running today on servers, and they can retarget them unmodified, uh, onto the DPU, and they get a huge, uh, gain in performance per watt, uh, in, in, in density, um, uh, to be able to put multiple of these e ones in a small form factor. Uh, and so that's really an advantage we have is that all of those existing data planes that people have run on servers, um, can just be, uh, placed onto the, the E one Go.
Sorry, go ahead. Sorry, go ahead, Jack. I'm sorry.
I was just gonna ask, so on the traditional side, it's all custom code, right? It's, yeah, so it's a combination and it actually, the combination is what actually makes it difficult because, um, there's sort of custom code that runs in that offload NIC portion of it. It's usually proprietary.
Um, it's usually very resource constrained. Uh, and then there may be more sort of standard programming model on the CPU cluster, but to create, uh, an application, uh, you kind of have to split the application between these two very two very different programming models. Mm-hmm.
Uh, and that's what makes that like, kind of that environment like very difficult to, to program. Uh, yeah. I Think it was also a problem in the security hardware market too, right?
When I've gotta do packet processing between CPU and my offloading nick, right? It's, it's a huge issue, right? Because you've got to have like almost a one core application to do that kind of processing.
So if I can put it closer, then makes a lot of sense, right? So in that case, then, because you are traditional Linux based, you can run into Linux things. So are people doing EBPF on this?
Yep. You can run eeb PF um, so we see that there's a camp that's sort of the Linux, EBPF, there's another camp that's the user space, DPDK. Okay.
And, uh, and we support, uh, both and I think we'll show that a little bit more in, in some of the future slides. Um, so it's really, again, like, um, it's just if you've programmed data planes on a server, um, this is just a very familiar envir environment to you. Um, okay.
I think we can go to the next slide. So this is a closer look at the, at the actual chip architecture. So, um, in the, the heart of the architecture is that compute fabric, um, that's where our 64 arm neo verse N two cores are.
Um, they're connected with a high speed scalable cache, coherent fabric. Um, we support 32 megabytes of system level cache that's shared by all of the cores. The cores also have their own private L one and L two caches.
Um, we have a memory subsystem where we have four channels of DDR five memory. Uh, there, those can operate up to 5,200. Um, and, uh, this is a little bit unique.
Most, most dpu, uh, don't have, uh, that much, uh, memory io. Uh, and depending on the form factor, Ted showed those form factors earlier. Um, in some form factors where you're not as space constrained, um, you can populate all four of those memory channels, uh, in some other form factors where you may be more space constrained, you might only populate, uh, two of those, those memory channels.
But we give you that ability to use, uh, uh, more, uh, memory io, uh, depending on your, your use case. Um, a very unique aspect of this chip is our PCIE connectivity. So we have PCIE connectivity that could be host attached where you connect the DPU to a host.
That's a traditional kind of DPU application where we're acting as a nick, uh, to a host. We did something unique where we in hardware, um, created PCIE hardware that presents all of the services of PCIE to the software so that the software can emulate any kind of PCIE device. So to a host, we can look like a storage device, we can look like a networking device.
Uh, we can look like an RDMA fabric device, and it's all software defined, again, using just standard, uh, pro programming models. Uh, we support up to 30, sorry, sorry, 40 lanes of PCIE Gen five. Um, some of those lanes are typically used for, you know, like an MVME boot, uh, or peripherals.
Uh, but then there's 32 lanes, which would typically be used in your data path. Uh, so, um, that data path can allow up to 800 gig of P-C-I-E-E bandwidth towards a host, uh, or towards storage. We'll talk more about storage, uh, later, um, uh, or towards other, uh, devices.
On the bottom of the diagram, we show our ethernet, or we call it a e unit. Um, and this, um, appears to, um, the programmer, um, as your nick. Um, it appears like a nick.
It appears sort of like an enterprise class NIC, with the features that you would expect in a nic. It also has several offloads. Uh, we support inline, uh, encryption.
Uh, we have a lot of flexibility and what kind of formats we can support. Um, uh, and, uh, it also supports all of the normal stateless offloads that you would find in n nick. Things like CRCs and check sums.
Um, it also supports, um, lookups and you can, you can do some flow offloads, uh, in the nick portion of this chip. And the way we think about it, and the way our, our philosophy is, is that that ethernet hardware is really there to help, um, steer traffic to the cores to enable you to scale the processing of those packets, uh, on the cores. So we're not trying to do all of the processing and all of the, um, flexibility in the NIC portion like our competitors are.
We're trying to do the primitive operations that you need there to enable you to use those arm cores, uh, effectively. Um, a little bit on, on power. Uh, so the chip itself, uh, you know, typical use cases would be, you know, for typical would be 50 to 75 watts.
Um, and, you know, for thermal design power, um, it's up to 120 watts. Um, this is rated with a spec end of one 70, which is a, you know, significant amount of compute power in, in such a energy efficient, uh, chip a and John, uh, Jack Poller with Paradigm Technica, I noticed that you have a memory encryption block in front of the memory. Yeah.
Do you support, uh, so is it, uh, you can support, uh, secure encryption data and use? So we have, uh, we have like multiple, multiple different places where we do encryption in this chip and I'll, I'll talk about them. So, um, one of them is inline, you know, as data comes in and out of the ethernet interface.
Mm-hmm. Um, and so that's like your IPSec or Google has something called PSP. Um, also ultra ethernet has their own security.
So all of those can be done in line, and if you can do them in line, that's really the best place to do it because it doesn't require you to bounce the, the data through your memory system multiple times. Sorry about that. We also have, um, uh, a look aside crypto engine.
Uh, and so there's things like TLS, uh, you know, uh, TLS where you wanna terminate, um, like TCP traffic that has TLS and it's very staple. Um, and it's not something that's easily done in line. So we have a look aside engine where the arm cores can kind of feed that look aside crypto engine, um, and do crip encryption there.
Then we have the memory encryption. The memory encryption is really there so that, um, data that's stored in the drams on the chip is, can actually be encrypted. Okay.
Uh, so that there's not any way you can kind of snoop on those memory interfaces and be able to, you know, access any kind of sensitive data. It also ultimately can allow you to have, um, multiple tenants sharing, uh, uh, um, you know, cores on this chip and be able to isolate, um, you know, their data, uh, in a way where it's, where they're each encrypted from each other. That's sort of where I was going.
I was wondering if you could do a secure uncla in this. Yeah. So I'm not really the right person to like get into the details of that.
We have security architects that could really, uh, an answer all, all of that. Yeah. Uh, very Quick question on your PCI side.
Uh, is that capable of doing CXL interfaces as well? So we did not implement CXL, uh, in this chip. Um, we're not gonna really talk about road roadmap too much for this chip, but that's something that, uh, is, is very much, uh, um, in mind for us, uh, uh, on our roadmap.
Okay. Because it's, I mean, there's, there is some interest in the industry Yeah. In the ability to actually, uh, have essentially Nick to CXL Yeah.
Interfaces. Yeah. And yeah, and this is something that we're, that we're following closely again and, and Seeing that Yeah, we're seeing that, Yeah.
Yeah. Memory for sure. Yeah.
This chip, this chip does not, uh, uh, support CXL, but, um, but stay tuned. Yeah. The follow on's called the E two.
We don't have a roadmap slide on it, but stand up. Yeah. Sorry.
Yes. Sorry. Yeah.
The, the follow on product is the E two, uh, and it's roughly, um, double the bandwidth of this one. 6 T. And that's where you'll, you'll, you'll see the CXL support come in.
Um, yeah. Okay. I think we can go next slide.
Sure. Um, so we'll talk about some of the applications. You know, starting from this server class kind of architecture.
You can imagine that there's just a very broad set of use cases, and we'll talk about some of 'em. We'll talk about the ones that we've really been focused on. Um, CHIP was really architected for this use case on the left, uh, we'll call it the front end, DPU.
Um, and this use case, um, could either be, um, you know, just a traditional public cloud compute node, uh, in that node. Um, the tenants need to get access to the infrastructure. Um, the DPU is what provides, um, the virtualization of the infrastructure, the securing of the infrastructure, um, and for, for both, you know, networking and storage.
Um, and it provides isolation amongst the tenants that are running on the host. Um, but the front end also, you know, applies to, uh, an AI cluster, um, where essentially the same kinds of things have to be done for the AI cluster to provide access to the, the infrastructure, access to the storage. Um, and in the, uh, you know, for the, the AI use case and, and both for the traditional cloud compute use case, the DPU is really offloading the host and, and offloading the DPU from having to do those functions and offloading it in a way where it's done on a, you know, very optimized architecture for those workloads that are running, uh, on the DPU, um, the backend DPU.
So in the, typically in the sort of training clusters, these high scale training clusters, this backend nick function has traditionally and, and predominantly been done with the performance nicks. Uh, those nicks allow you to get, you know, RDMA, uh, performance at very, uh, high rates and low power. Um, and, you know, the, there are opportunities in those large clusters for dpu more around innovations innovating around congestion control or, um, congestion avoidance, uh, packet spraying telemetry.
Um, there are many, many use cases where even in a training, um, uh, cluster, the DPU makes sense, but really in the inference cluster is where the DPU, um, can shine. Uh, because, uh, in the inference cluster, that's where we start to see, um, uh, uh, the offload of a KV cash offload, uh, from the GPU to something else. And the DPU is a natural place to do that because it has direct access to the GPU's memory system.
Uh, but it's also, you know, directly connected to the scale out network, uh, of those inference clusters. So as we see, you know, a push to building special purpose clusters for inference, there's a lot more opportunity for the DPU, uh, in, in those. Um, we also have use cases for local storage, um, and in the local storage use cases to the host, we can virtualize storage devices, but those can actually be, um, the, the E one and the DPU can actually be managing a local set of, of disks.
Um, there's a bump in the wire use case. And, and this is one diagram. There's many ways to draw this bump in the wire, but you can think of the bumper in the wire as just simply a network attached appliance where packets come in, maybe come in on one port, get processed, go out another port, many applications for bump in the wire, um, both, um, in security, um, and, you know, software load balancing.
Um, and, and we see many u use cases there. Smart switch, um, is another use case that I think we'll we'll touch on more later, where we actually combine the switch with the dpu. Um, and, um, what this allows, um, is it allows you to use the switch, um, to have, you know, a large bandwidth of traffic coming into the switch and to selectively choose which flows you want to go to the DPU for more processing.
Typically the switch is doing your stateless processing, um, and the DPU could do, uh, very state stateful processing. I think we can go to the next slide, Ted. And then we have, um, server use cases.
So, uh, we have edge server use cases. We see a lot of applicability for DPU for things like CDN, um, for, um, gaming. We, we see use cases.
Um, and, uh, and then, uh, on the right we see, um, the E one and sort of an appliance form factor, uh, for storage target kinds of use cases where the storage is disaggregated from, uh, from the host. Uh, this is sort of a look at our software developer kit. I've said multiple times, I think so far that we're standard programming model.
Um, but we do provide, we do provide software, um, in a few forms. Uh, we provide the drivers and the necessary infrastructure pieces of software to enable our customers to use the DPU. Uh, and we also provide reference software for many of these applications and use cases.
So at the, at the lowest level, um, we provide the secure boot, the, the bios, um, and uh, uh, uh, the sort of low level software that gets the chip booted and, and operating. Um, and then as far as the operating system, as I said earlier, um, any, um, operating system distribution that can run on an arm server, uh, can run on the E one internally, we've been using Ubuntu. That's kind of our sort of, uh, default.
Um, and then we provide the DPDK Linux drivers on top of that for our networking. Um, and then as I talked about the PCIE where we can emulate any kind of PCIE device, we implement what we call backends. So we implement a backend for networking.
We have a couple flavors of that vert io and XNA. We implement a backend for N-N-V-M-E emulation and as well as backends for RDMA and, and Rocky. Um, and then as you go above that, you start to get into the, the applications.
And typically our customers will use our chip as a platform, uh, and then they'll put their own applications on top of, uh, uh, the E one. Um, there is an application that we've developed called Sonic Dash. Um, we'll talk about that more, um, in, in a couple of slides.
Um, and that's where we'll really get into some of the performance, uh, in a real world, uh, use case SDN use case for, for the E one. Okay. Right now, so the reason why, you know, we kind of selected Sonic Dash to talk about is because this is a very heavy workload, um, SDN workload.
And, um, so what is Sonic Dash? Sonic Dash is a Linux Foundation project that was, uh, started in, in 2021. Uh, it was really a project pushed by Microsoft.
Um, and the goal of the project was to take the stateful services that run on the host in the public cloud and define them, and to find the APIs and the object models in the, um, in, in the, those services. And the goal of that was to enable a broad set of technology providers to really create performance and power and cost optimized implementations of these services. Traditionally, um, that cloud, SDN had been built on, um, frameworks that had primitive operations and a service was sort of defined as stringing these primitive operations together, um, in order to implement the service.
And over time, as the cloud matured, um, it got to the point where we no longer need, um, this kind of low level way of defining the services in the cloud that we could do it by. Actually, we know now after decades of cloud computing that these are the seven services SDN services that you need in the cloud. So they've been defined and we've implement, been implementing them.
One of the services is called vnet to vnet. Um, what does this do? So, um, packets come in.
Uh, you apply lookups transformations to be able to map the overlay to the underlay. Um, does state tracking for TCP and UDP connections, um, dash defines that you have to do five ACL operations. ACL algorithmic.
ACL is a very intensive, um, especially at high scale on memory accesses, um, accounting enforcement of rate limits, low scale limits, um, and also, uh, you need very high availability. Um, because if you are tracking millions of connections, you need to make sure that those, that state is synchronized on another data plane. So if there's any kind of failure in the network, all of that traffic can be taken over by, um, a peer data plane.
And so there's no loss of connections to the users of the network. Um, in order to run Sonic Dash at an 800 gig scale, um, it requires, um, millions of routes, um, millions of prefixes in your ACL tables, millions of mappings. The the point, um, of showing the scale is that this kind of scale is not something that you can fit on, chip on, on chip memory.
All of this has to live in dram, uh, off of the chip. And there's also no locality as packets come into the chip. A packet might be for one flow, next packets for a different flow, and you can't rely on those caches for locality.
Everything has to go to dram, uh, in order to, uh, be able to process the packets for Sonic Dash, it doesn't matter what architecture you have, it doesn't matter if what you have like the e architecture, uh, or one of our competitor architectures. It's a very dram intensive, uh, use case. Um, so if we go to the next slide, we can show that, um, there's a test defined for Dash called the Hero Benchmark.
It's the highest scale most intensive tests that you can do. Uh, the test requires that you have, um, over 120 million background connections. So this background traffic is running, and then while that background traffic is running, you have to be able to support 12 million new connections per second.
Um, and you have to be able to do that for a hundred seconds without a single packet drop. We, on the E one, uh, have been able to exceed that performance. Um, we were able to get, um, almost 20%, um, uh, excess on that performance requirement.
We're able to do it where we still have cores left over. So you can run those, uh, those remaining cores for your Sonic Control plane. Um, and even with the performance we were able to achieve, we still see, uh, the potential to achieve even more performance gain, uh, or uh, be able to do it with fewer cores.
Um, and, uh, and we see like the potential for another 25 to 40% performance improvement over what we've already tested. So this is just to give you an example of a Cloud SDN use case. It's really the use case that we designed an architect of the chip for.
Um, and to show that we're actually the only DPU, um, that's able to pass this test at 800 gig with a single device.