Techstrong TV February 19, 2026
Datadog CISO on Defending with AI: Emilio Escobar explains why security teams must use AI proactively, how feedback loops strengthen agent performance, and why integrating observability with security is essential to protect AI-native development ahead of RSA.
eBPF Goes Mainstream: eBPF Foundation board member Bill Mulligan outlines how enterprises are embedding observability, networking, and security directly into the Linux kernel—driving lower latency, higher efficiency, and deeper operational visibility.
Trustworthy Agentic AI in 2026: What it will take to operationalize secure AI—verifiable reasoning, right-sized human oversight, and production-ready security controls for agent-driven workloads.
ClawBands Restores Human-in-the-Loop Control: The open-source project adds approval gates and audit trails to the OpenClaw autonomous assistant, addressing growing concerns over agentic AI attack surfaces and system-level access risks.
Xsight Labs Smart Switch for Government Security: A 1RU, 28x400G line-rate smart switch powered by the X2 12.8T Ethernet chip and dual DPUs—delivering high-density compute, stateful L4-7 processing, and secure bare-metal performance.
Transcript
Hey everyone, it's Alan Shimel and welcome back here to Text Drunk tv. My next guest, it's actually his first time, I think, well, his first time on Text Drunk TV with me, though. He's been a Datadog six years, so I'm glad he finally made it over here.
Emilio Escobar is the CSO, CISO at Datadog. Emilio, welcome. Yeah, how are you?
I'm doing well. Thanks for having me. Pleasure to Be here.
It's my pleasure. So, Emilio, I mentioned that you're a ciso a Datadog now for, I don't know, six years or so, maybe more. Um, give us a sense of like kinda your journey to becoming CISO there.
Yeah. Um, I'm, you know, I think I'm definitely not one of them who had a career plan to end up where I'm right now. It just happened organically.
Uh, so background is a software engineer computer science degree. I, uh, did a long stint with the federal government, uh, doing some, some software engineering there, but all of it was specifically purpose in, in, in security itself. Different aspects of it.
Um, did security consulting for a bit, uh, and ended up meeting, uh, the PlayStation team while I was doing that. Went to PlayStation, ran the software security teams there for a while. Uh, then went to Hulu to lead the whole program for a couple years.
Took that through the whole Disney transition and Datadog called, uh, I by then already knew of Datadog. Uh, Hulu was a, uh, a new Datadog customer while I was, while I was there. So I already had some connections to Datadog and, and when Alexi called, uh, had the conversation with him, it, it all felt like it, it was a great fit.
And, and yeah, six years later, here I am. Excellent. Excellent.
Um, what a great story, man. Right. Just so you went from Hulu, that was a cust a new customer of Datadog right?
Over to Datadog at the time, Right? Yeah, yeah, yeah, yeah. And I remember seeing the demo of Datadog's first security version of a security product, or a demo of their first version of security product while I was at Hulu.
Uh, this was reinvent, golly, like maybe 2019, I think. Um, mm-hmm. And, and seeing the, wow, this is, this makes sense.
But back then obviously it was very early. Um, and, uh, and yeah, it's, uh, that's when we got first got a insecurity and, and, uh, needless to say, back then, I didn't realize I was gonna end up playing a major, major role in it. So, Absolutely.
That was like, that was probably like right before COVID too. Yes. So I joined the company during COVID, so I didn't, I didn't get to go to the office, uh, to meet people in person until a year after I had joined, which was, yeah.
Well, it was a crazy time. It was a crazy time. Yeah.
It was, it was interesting meeting people back on it, seeing People live and like, oh, that's what you actually look like. Absolutely. I, we, you know, we went through that.
I, you know, 'cause it was, it was COVID. We were, we were still operating, but, you know, and I, I was hired like interviewing people that, and then hiring people that you never actually met. Right.
You know what I mean? It was a little weird, interesting times. But we're, we're in interesting times now, right?
Yes, we are. And I'm sure as much as it would security was new for Datadog then, you know, fast forward now, six, seven years later, well, security's not new, but everything we're doing seems to be new because of ai, LLMs agents, agent ai, and all of these things. It's really rewriting the book almost daily.
Right. Talk to us about, you know, Datadog, how to evolve Datadog, how to adapt and change and grow. What do you know from where you sit is the ciso, how do you see that growth?
How, how does it play out? Yeah. And, and it hasn't just been security.
We've, we've seen that expansion even in our observability business as well. Uh, so what's been interesting throughout the years is to see Datadog from going from just a, an observability platform to be really a mission critical platform now. Uh, because now we no longer just tell you, Hey, something's going on in the environment, we allow you to actually act on it and security on top of that.
So the, the mission criticality for us is definitely exponentially grown. Uh, and what we mean to our customers has had means something completely different. Uh, but where there's an opportunity, there's also, um, uh, threat actors that want to, uh, want to exploit that.
So we, we definitely have been helping customers understand, uh, again, not just using AI to understand better what's happening in their environment, how to address it, to their point of, of having agents that can do the things for them, uh, but also helping them protect their AI applications as well as they're working on their journey to, to release AI applications. So we have an SRE agent that helps you find root cause analysis. Uh, we have a security agent that helps you triage, uh, all the thousands of signals the security teams have to evaluate.
Uh, and then we even have a coding agent that helps you fix code. Uh, and if you really put it together, uh, there's a, there's a whole feedback loop that we cover, right? We, we can have a, an error in production, or we can have an issue with security that was introduced by a change, and now we have an agent that would actually make the code a configuration change or propose it to address that.
Right? So really close end to end. So, uh, this is being well received, but that means our responsibility to our customers has also grown with it.
Excellent. You know, I, I was reading something the other day that 2026. So 2025 we started experimenting with agents.
Mm-hmm. But in 2026, people don't want to be experimenting anymore. They want it to just work.
Right. Right. And, and, and let's be honest, in 2025, a lot of the agents, you know, they had that cool factor, but they really didn't work so good.
Right, right. A lot of it was, yeah, I could see the potential, but this isn't quite ready yet. When it comes to the Datadog agents.
Are they ready? Are they, are customers using them to deliver value today? Yeah.
We see that, um, we see that they're working and they're delivering value, but also we continue to invest in them. Right. So what's Olivia said this, our our CEO founders said this in an interview a couple days ago.
It's interesting forever. We've been okay with humans being correct 70, 75% of the time. Uh, what's interesting about AI agents is that an AI agent is correct only 70% of the time, notice my statement, only correct.
70% of this time, we don't know, we don't accept that as a, as a good product anymore. So it's really fascinating. So, um, while they're working and customers are seeing value, we still get a lot of feedback and we still continue to, uh, work on them.
'cause we know there's so much more we can do. Uh, but then we work in them in the sense of, if there's a situation where the product didn't get to cover, now we work on it, certain scenarios that customers are going through that maybe the agent probably didn't, wasn't part of that 70% that it got. Right.
We built this feedback loops that customers can tell us, Hey, this wasn't exactly what we wanted to be, or this wasn't accurate. And then we invest in correcting that via the feedback loops that we mentioned. But, but yes, customers are seeing root cause analysis.
We use it ourselves as a lot. So we're a strict dog footing company. So all these agents are actively helping us maintain, run, and protect Datadog as a platform.
Plus we also hear from all from our customers that it's working for them. Excellent. You know, I, um, I, I did a story last week, or it was actually a video that today, in today's world, even though everybody's using ai, everybody's trying it, everybody's using it, everybody's experimenting.
It has sort of a scarlet letter, right? Where people say, oh, well, well, AI, it's only 70%. Yeah.
Well, humans we're only 60%, so we got a 10% improvement. But that's what, they don't look at it that way. Yeah's, only 70% if I'm gonna trust ai, it's gotta be 99, you know, five nines.
Right. And, uh, you know, I think this too will pass. I, I think it's sort of an artificial bar we are creating.
I think part of it is because people are, are fear outta fear, right? Because are it gonna make them, Jo, make them lose their jobs, change their jobs, what have you. Yeah.
But you know, it, it gets better. It's getting better every day. Now, you, as a CISO and, and talking on behalf of other CISOs though, is this making your job easier, harder, little, you know, some of both.
What do you think? I would say it's, it's both. Um, on, on one hand, it's making it harder because the surface, the attack surface just keeps changing and growing, right?
So, um, not just the, what people can do with ai, say shadow applications or shadow ideas as we called it, or the notebooks of the, of, or open cloud of the world. Um, but I, I, I, which inherently their nice projects to work on, they're interesting, uh, but they do carry some risk. But I think, uh, it creates that surface.
Um, but also, and also attackers using ai, right? So a lot of the things that we see are using AI to hijack things like open source dependencies, things like developer, um, the extensions that they use, the developers use in their, in their development client, the IDs. Um, but then if you use it for defending yourself, then, then in a way you're, you're say, like the, what I say is the tide.
If the tide rises, the tide rises for everyone and everyone gets lifted. Uh, so I'd say it's both, it, it creates opportunities, it creates challenges. Uh, but ironically, if you're not using AI to fight those challenges, then you're gonna be behind already, if not, um, uh, so I always encourage CSOs and security teams to think about what they can build with ai.
So also using agents internally for security purposes, also using LLMs to understand, uh, malicious patterns or malicious behaviors are, are critical for us. So, couple of things that we've done is, um, we actually use LLMs to detect, uh, not vulnerable code, because I think there's a lot of that out there already. And the, and the models are getting better at writing proper code, but we, we are using LLMs to under, to detect malicious intended code.
Um, so imagine a, a popular open source dependency package getting hijacked where the code that it gets introduced by attacker is perfect. It adds no vulnerability, no scanner will find a vulnerability with it. But what it does is bad, right?
And what it means to do is let me extract all the secrets that I can find from the developer's laptop and send it to, to a server that I own. Um, those things are, are, are happening now, and you have to use AI to be able to stay on top of that. The react to shell vulnerability, for example, is a perfect use case of using AI to find it and look at the repercussion that it had, right?
Where a lot of servers were exposed. We not only see that was the initial entry point, but then attackers get clever and, and, and use stealth techniques like our research showed to then say, okay, well if I can penetrate a web server and then have a proxy every request to a server I own, then I can extra trade all kinds of data and credentials to me. Um, so I, I think the attack patterns are changing because of ai.
No, I mean, we still see the phishing, the identity based attacks and all of those, 'cause attackers are always gonna go for the path of least resistance. But AI now open a bunch of paths for them, and I think we have to open paths for security teams to be able to use AI to defend themselves. So it's, it's both.
It is both. I, I tell you another thing, I said it on Textron gang the other day, even at this early stage of AI use, and I think it's still early, we're already on this, and I've been in security 25 years myself, right? We're already at the stage in security where we're going to need AI to fight ai.
Mm-hmm. Right? Uh, these scalability, you know, I mentioned before the 600 vulnerabilities that opus found the amount of just the, just the sheer, the, the better phishing, right?
The phishing and smishing is so much better because they're using AI to write these things, right? We, you, you need it. You need to deploy AI to fight the AI because the bad guys are using it for sure.
Yep. Yeah, yeah. Exactly.
Yeah. Yeah. Yep.
And at the end of the day, data is data, right? So these models are really good at finding patterns or, or missed patterns in the data. Um, so while attackers are using AI to create data, whether it could be a video of me saying like, Hey, I need, I need, I need a thousand gift cards.
Um, you can also u use AI to figure out like, Hey, that's not actually me in the video. So it's, uh, it's really fascinating. Oh, that, yeah, that's, that's a whole nother point.
Yes. The other thing is, you know, look, I think we had evolved to the point where observability and security were two sides of the same coin, right? I think with ai, they're both on the same side of the coin.
That's how tight AI makes them very tightly intertwined. And, um, and we're going to continue to see that, right? Because besides the effect AI is having on security, it's having an, an equal impact in the observability side of the house, correct?
That's right. Yeah. That's absolutely what we're seeing.
And, and to your point, observability and security being, um, both sides, two sides of the same coin, I think AI is, is both the heads and the tails of that coin, if that makes sense. Yep. Uh, Yeah.
No, it, it, it's the, it becomes the coin that, that, but that's what's going on here, right? AI is becoming the focal point of, of all of these things. And it's, it's, it's a little, you know, it, it's, it could be a little scary because like you said, it's only 70%, not a hundred percent, but it's better than what we had and it's faster than what we had.
Yeah. But, you know, we're still going through this phase where we're getting, we're getting comfortable with that. Mm-hmm.
Yeah. I think it's very similar to the cloud adoption phase, right? Like, I remember when the cloud was booming, um, a lot of the fear was where I lose control, where is the data gonna go?
Costs what have you. Yep. Um, and there were always nuances that maybe, okay, the first time you, you made a shift was a lift and shift.
You didn't get it a hundred percent right? Uh, but those that actually saw like, hey, there's actually something here in the future that we can continue to work on, um, are now some of the leading either cloud companies or companies that run out of the cloud. Um, so it's, it's similar of that.
It's like when the paradigm shifts, fear is part of it and uncertainty is part of it. Uh, that's why I don't subscribe to a lot of, of the, of the FUD that you see around their own. And especially with ai, because yes, attackers are using ai, but defenders so should, so I'm glad that we're actually talking about defenders using AI more so than attackers using ai.
'cause the latter, the, the, the latter doesn't really give you a way out. It's just more of like, be careful. Um, instead of, we should talk more about what people are using AI for to protect themselves.
Agreed. Emilio Emilio. Where, where can people get more information about the Datadog security, well, Datadog security offering, but also kind of, you know, what, what's going on with Datadog security in AI and, and all of these, like, how can they stay up to date in the know?
Yeah, absolutely. Uh, so we have a couple. So I will say the blog, it's, it's a, it's a, a, um, a good resource.
We have engineering blog, we have the security blog. We have security blog that's called Security Labs. That's actually where, where my group, um, when we track threat actors, when we track certain attack patterns, malware, what have you, like, we, we pose our research there.
Our engineering block is really good. Uh, Datadog is, is is very open in the sense of, we not only give you product updates, but we actually talk about things that we learn ourselves and how to run a platform of our scale mistakes that we've made, uh, new things that we've done. So, for example, we talk about outages that we've had in the past.
We talk about how we profile a certain service to gain performance improvements, how we scale systems, how we manage the data volume that we manage. And then on the security side, we talk about how we do things. That's at our scale as well.
So our blog post is great. Um, if you haven't heard of Datadog and Security in the same sentence, I don't blame you. We're pretty new in the, in the space.
But I will tell you that um, about 50% of our Fortune 100 customers use us, uh, on the security side. And about 68 or so, sorry, the Fortune 500, um, 58, 60 8% of Fortune 100 use us on the security side. And we continue to invest heavily in security.
'cause we Datadog started to remove the silo between Dev and ops. And, and we think we can remove the silo of security and dev as well with, with, with our platform. Amen.
Amen. That's why I got into DevOps, you know, all those years ago. I thought that's what needed to be done coming from security.
Amelia, thanks for coming here on Textron tv, man. We appreciate it. Thank you.
Come back. You keep us posted. Are you guys gonna be at RSA conference at all?
We will, yes. We actually have quite a few things planned for RSA, so we'll definitely have a presence. So hope To see you there.
You know what we are, uh, we'll be there all week on Broadcast Alley. And of course we act, we have an interesting thing going on Monday there. You know, every year we put on our DevSecOps event.
I think Datadog's been involved in it in years past, um, this year it's a little different. We didn't call it DevSecOps. We, it's securing AI native dev 'cause everything's ai, right?
That's, That's actually a good name for it. So it's Securing ai native deaf. I'm actually doing a panel if you uh, if you're gonna be there, you know.
We'll, we'll, we'll have your people talk to my people. There you go. I'd love to have you do it with me that Monday.
I would love to. Yeah. Sounds great.
Alright. Emilio Escobar Seeso at Day Dark here on Thank you. On text Drug tv.
We're gonna take a break. We'll be back. Thank you Emilio.
Thanks for having me. Hey guys, thanks for the throw. We're here with Bill Mulligan, who's a maintainer for Cilium, which is a project that is run by the Cloud Native Computing Foundation, but is also based on eBPF.
And eBPF has a new report out talking about, well, the level of adoption and what's driving it these days. Bill, welcome to the show. Hey, thanks for having me.
Where are we on this journey with eBPF? I feel like, you know, the technology came out and it's been a little while and it's starting to show up in the latest versions of Linux, but it's not clear to me that everybody's deployed the latest versions of Linux just yet. So where are we on the journey?
Yeah, I think we're really at an exciting point for EVPF, kind of as you said, the technology's been, uh, out for about 11 years now, but that's kind of when it first got merged into Lennox Kernel. As you know, most people probably aren't running latest kernel. They're running ones that are 2, 3, 4, maybe five years back.
And so as the technology is progressed, we're finally getting to the point where most major Linux distributions and LTS releases now support a modern enough version of eBPF that we can kind of start to do fun and exciting things with that right before just really small programs limited to 4K, now we can do a million instruction programs. So I would say the fun part about EDPF is now possible in production for the vast majority of companies out there. So are we gonna see some dramatic, uh, accelerations in performance of a lot of the tools that we used, the impact?
'cause I seem to remember the promise of eBPF was that I would run my, uh, security or my networking or my observability stack deeper in the kernel and performance would improve. But to your point, a lot of those apps are still up in user space. So are we gonna see something dramatic here?
Yes, that's a little bit what this new report is diving into. So one of the promises of EVPF is that speed. And the reason why kinda that promise is coming to fruition right now is because of flexibility that EVPF provides.
So it allows us to rewrite what's happening in the kernel to do new things. So for instance, in networking, um, a lot of the times, like what we can do is skip certain parts of the networking stack. So a perfect example, uh, of the report is CloudFlare obviously well known for building a safer, better internet.
And one thing that they have to deal with a lot is DDoS attacks. So they, uh, help mitigate a 13 terabyte per second DDoS attack with the help of EEPF. And the way that they're able to do that is the performance benefits that they get.
And the way that they're doing it with is a subset of Eeb PF called XT P or Express Data Path. And what that allows them to do is to process the packets before it hits the Linux kernel networking stack. So rather than having to process through the whole thing, they're able to say, right as the packet is coming off the neck, make the decision, should we pass this further onto the stack or should we drop it?
And by dropping it, essentially as it's coming off and uh, off the neck, you're able to massively reduce, uh, the amount of CPU that it takes to, is this packet okay, should we process it? Where should it go? You're just saying, no, this isn't a good packet, we can just drop it.
And so they're able to mitigate that while still being able to serve you basically all the internet traffic too. So that's what kind of Eeb PF is bringing it. We can rewrite parts of analytics funnel that adding this flexibility that we didn't have in before.
And by doing that, we can do smart optimizations like networking. We can process things a lot sooner without going through the networking stack. And the report goes into, well now that eBPF is available to organizations basically everywhere, what are the actual things that organizations are seeing in production to improve that?
And so one example was the CloudFair example that I gave you, um, of mitigating a huge DDoS attack. Um, and they're able to do that thanks to the flexibility and the performance of EVPF. So besides CloudFlare, who else has called out in the report?
What are some of the Highlands? Yeah, so there's tons of people called out in the report. So for instance, um, META is using eBPF for profiling.
Um, by profiling all their applications, they're able to find a one character change that helped them reduce CPU performance by, uh, 20%, because that was a really often called function. Um, another example is Datadog. Um, they're using eBPF for both networking through cilium and security.
Um, so looking at how they're able to reduce the cycles and have more fine grain control about what they're doing it. And I, I think the use of EVPF really spans across the whole ecosystem would be hard to kind of capture all the different ones in their report. Um, because there are so many different examples.
The companies that we did highlight though, um, were spanning a wide variety of industries. So we dove deep into, uh, meta into Netflix, into by dance into CloudFlare, and also into recruiting. So telecommunications, consumer applications, um, social media, you know, the internet infrastructure, the uses of Eeb PF are almost like endless across all these industries.
Mm-hmm. Um, we're of course living in the age of ai. Do you think that the rise of ai, whether it's on the server side or I don't know, even maybe these AI agents, um, is that gonna benefit from A BPF and how so?
Absolutely. Um, I, I think if you're looking at ai, it, everybody knows the amount of compute and network throughput that the model requires. I don't think that's right.
The, the, all the big stories about AI right now is how many data centers that we're gonna have to build. And I think EVPF can play a huge part in that. Um, on the, the training and the buildout side, in terms of optimization, I mean, this is actually one of the reasons, uh, meta one of the original adopters of EVPF turn towards the technology.
One of their first ca use cases was, while they're getting a lot of internet traffic from CAT videos, from memes, from the messages that we're sending through WhatsApp, we need to be able to process that faster. And they turned the eeb PF to do the load balancing into and out of all their data centers. Um, and I don't have the numbers for meta, but, uh, one of the users of cilium layer four load balancer, uh, was able to reduce CPU consumption by 72 x.
Right? So if you're thinking about at meta scale, if you can reduce how many load balancers you need, how many CPUs you need by 72 XI mean, you're literally saving data centers right now. So, right.
The, the performance, the efficiency improvements is I, I think, gonna have a massive impact, um, on the use, uh, on the, on the training of AI models. In fact, uh, another example, Brendan, Greg, one of the early adopters, um, of eBPF doing a lot of performance stuff at Netflix, he actually just moved to OpenAI, you know, to do compute optimization at the largest scale. So I think eBPF is gonna have a huge impact on both the performance side, but then also actually, like on the inference on the downstream side too, I think everybody's concerned about security, these models, what are they actually doing?
And EVPF, because it's running in the kernel, can give you granular insight into everything the application at your model is doing. So I think it's both on like the efficiency side and also the observability security side too. EVPF is a huge role to play in the whole AI ecosystem.
Do you think that as we implement eBPF more broadly, that the manage, it might fundamentally change because, well, historically we had all these different apps, whether they were networking, security observability, or to your point, AI running in user space and required different people and different tools. But if more things are running at the kernel level, can we converge the management of these things a little bit more? Yeah, definitely.
I think that's one of the exciting things about eeb PF um, when I was kind of talking, uh, at the beginning when we were speaking, right, EEB PF was merging 11 years ago, and at the time you only had 4K instructions. Well, now you can do, uh, a million instruction programs and you can do tail calls. eBPF is now turning complete.
And kind of like what we're seeing is the progression of things from user space into the kernel. I think the parallel that I would give is like, people used to wrote, right, their own user space, uh, TCP ic, uh, TCP IP implementations, right? And then eventually we kind of realized, you know, every everybody's gonna do this.
It makes sense to kind of move it into the kernel. And I think that's the exciting thing about eeb PF actually is because the whole Linux kernel needs to stay stable for a long time. If it's there, it's kind of deployed on billions of devices worldwide, from servers to cell phones, to satellites.
Uh, so we, they take very seriously what they're actually putting into the Linux kernel. Now with eeb PF what we're able to do is to experiment. What are things that, um, or we're not sure if they'll work out, if they should be in the mainline kernel.
What if I need to add this new functionality? You can start move some of those user space things into the kernel and experiment again. Um, and then if those things make sense, you can actually, you know, merge those into the kernel.
And so I think we're gonna see definitely a progression of things that used to be running user space, uh, moving to kernel space, but it really depends on the application where that makes sense. So for us in cilium, uh, one thing that we're seeing right now is like, originally it was just kinda like layer three, layer four networking, but we're actually seeing some of the layer seven networking, including things like HTTP parsers moving into the kernel. So I think that's kind of cool.
Or another really exciting area right now is scheduling, uh, billing criminal error has, has had the same scheduler, uh, for a really long time now, and it, it works really well for a wide variety of workloads. But if you have something like a very IO intensive thing, or you have gaming where you really can compare it about the latency, how do you write a new scheduler? And now you can do that with eBPF, people are seeing huge performance improvements for specific types of workloads because they can write new schedulers tailored to those workloads with eeb PF.
Mm-hmm. So where do we go from here? What's next for A BPF?
What should people be looking forward to? Yeah, so, uh, the whole ecosystem is progressing all the time. I think the exciting thing for me right now is if you look at this report, um, a lot of these things, you know, the, the companies that I listed offer are these, you know, internet scale companies that were like the original early adopters, VVPF, and seeing the, the benefits of that.
I think what's we're gonna see next is that trickling down to a lot of other projects and products a across the whole ecosystem in terms and affecting a lot more companies across the wide variety of industries. I mean, the example that I always give is like, if you have an Android phone right now, you're using eeb PF, right? So that's already billions of devices.
Um, but I think it's trickling down to more of the technologies, right? Anybody using cilium is benefiting from Eeb PF, so that's everybody running, uh, cluster with data plan V two on GKE, every single new cluster on Azure, um, you know, lots of other managed cloud providers, if you're using, uh, Datadog and their security product, uh, you're using eBPF. And so I think what's gonna be interesting kind of coming up is a lot of people are gonna be, you know, maybe looking under the hood of their technology and suddenly realizing, oh yeah, I'm using eeb PF two and I'm getting these benefits of, in terms of increased performance, better profiling, uh, more granular observability, more hardened security systems.
And they're not gonna realize like the magic behind that is eBPF. You know, it's kinda like this foundational technology. It's kind of coming this strategic platform, uh, that a lot of companies are building on.
Um, and I think these benefits that were highlighted in their report, um, are gonna be coming to a lot more companies, whether or not they realize it's because of EVPF or not, um, through the projects and the products and the tools and the technologies that are building on top of EVPF. To your point about that, should I as an IT organization be conscious in driving the fact upgrade to the latest versions of Linux that support eBPF and taking it a step further, should I be asking all my providers of tools about what their roadmap is for this? Because, you know, it has some material benefits to me.
Yeah, I think that's definitely a key question to ask. It's, you know, like the cost benefit analysis, um, you're always asking in terms of writing your own eeb PF programs. I think it's like, the question is, do we already have our own kernel team in where we need to fine tune things?
Uh, you can answer yes no on that question then that's essentially what you're doing with eeb pf is tinkering with the kernel. So are we as a team prepared to, to doing that, that do and support that? If the answer is yes, then you know, EEB PF is a great tool.
If it's not, then you're probably looking at your vendors, your service providers to do that for you. And then in terms of like updating to latest, um, kernel version, obviously there's lots of benefits, but it's what are you actually trying to do? Are you most concerned about networking and wanna upgrade for something like Nut Kit?
Are we concerned about security? So we want to have better support for something like, um, BPF tokens to manage the permissions of eeb PF, you know, do we want to upgrade to, uh, ske Sedex for changing our scheduling and looking at like what your specific use cases are will inform essentially what kernel version you need to move up to, to have those, um, things from EPPF. And then on the kinda like tooling and product side, I think like what companies are looking for is like, they're not looking for, I wouldn't look, I wouldn't think of eBPF as a checklist technology.
Like check, he like, yes, has eeb PF in the same way you'd be like, yes, check has like waf wa uh, like WAF functionality, you know, um, EEB PF is a technology, it's not a solution, it's not a business outcome. Companies are looking for solutions and big business outcomes. So I would evaluate solutions, uh, based on whether you're achieving the goals that you're actually trying to do now.
And my belief, and if you look at this report too, like eBPF is gonna be underneath those tools, those products, those services that are gonna help you achieve the business outcomes that you want to because of the performance and the flexibility benefits that it has. But, uh, whether that's actually checklist criteria, I would actually say no. But I think those types of tools and services and products are gonna rise to the top because of the benefits that Eeb PF gives 'em under underneath.
It's really becoming kind of the strategic platform. So I think you will see it come out in a lot of projects. Um, but whether it's a checklist item, I would actually say no, You're a maintainer.
So what is the, what do you need as a maintainer? Are you getting enough con contributions from folks? Do you need, I don't know, maybe just people to work on documentation, but, um, I'm asking this question because in the age of ai, it seems like we're writing more code than ever.
So are people contributing more code or what's going on from your perspective? Yeah, um, I think it really depends on what type of project you're looking at. Um, how, how that's coming to the surface.
I think the links kernel, uh, as a mailing driven, a deep deeply technical project, um, has their kind of own thing. I, I would say one actually super interesting use case from the DPF subsystem, it was actually the first one to implement AI reviewers. Um, so if you submit a patch to the BPF subsystem, it's actually reviewed by ai, um, before it goes to external maintainers.
And I think this is actually a really big benefit for open source maintainers, right? It's getting the code that's being contributed, making sure it's in the right format, it's free of bugs or as many bugs as you can think. It's actually following the guidelines.
And then when you actually have the human in the loop, you know, that's the really expensive time, the maintainers time, uh, you know, it's already kind of free of a lot of these bugs and formatting and linting things. So I think that's like a huge boost for like how AI can help the open source ecosystem. And it's cool to see that the EVPF subsystem is like at the forefront of that, that 'cause I think it'll help move the technology even faster, um, forward together, but then like what eeb PF is technology actually needs.
Um, I would say the most important thing for us is like hearing all the different use cases. You know, people contribute patches upstream, but like what, like eBPF is such a powerful and flexible technology that we can't think of all the different ways that people are using it. You know, I, I listed, you know, networking, profiling, observability security, now it's going into scheduling human, uh, it's going into devices, into hardware.
There's so many different use cases. Um, we want, we need to hear about them so we can make sure that those use case cases are supported by BPF. Alright, cool.
Well, folks, you heard it here. eBPF, maybe it's time has finally come because it's starting to show up in a lot more places, and I think the average IT organization is gonna gain a lot more experience with it in the months ahead than they have in the last decade. For sure.
Bill, thanks for being on the show. Yeah, thanks for having me. All right.
And back to you guys in Studio Enterprise AI applications need a solid data foundation bringing together disparate data sets in a secure and flexible manner. But despite years of effort, most businesses still have a diverse data environment. Before we will see the value of AI and enterprise applications, we have to solve the challenge of data access.
And that's what we're discussing today with Ken Yagen of cdata. Welcome to utilizing ai, the podcast focused on practical applications of artificial intelligence from the Futurum group. Each episode brings together diverse perspectives to explore news and use cases in the ways in which AI is transforming enterprise IT and the industries it serves.
I'm your host, Stephen Foskett, president of the Tech Field Day business unit here at the Futurum Group. Before we dive into the discussion, let's meet who's on the panel today. Hi everyone.
Brad Shiman. Um, good to be back with you. I am the VP and practice lead for data integration, excuse me, data intelligence.
I, I'm already thinking about chatting, chatting with Ken today, uh, of data intelligence, analytics, and infrastructure here at futurum. And, uh, it's, it's my pleasure to join you guys. And we have a, an exciting guest on, I'm going to introduce him now.
His name is Ken Jagan with cdata. Hi Ken. Hi, Brad.
Brad, Steven, thank you very much for having me. I'm the Chief Product Officer at cdata, Ken Jagen, and, uh, CDATA is a leader in enterprise data connectivity and integration. And, and we have one of the first managed AI connectivity platforms on the market.
So excited to talk today about ai. Uh, as Chief Product officer at cdata, my focus is really on how our customers turn data connectivity into governed scalable foundation for enterprise ai. And that's why we're happy to talk to you about this, because again, this is utilizing ai, we're all about figuring out practical, useful solutions based on ai.
And I, uh, learned about cdata last year. And boy, it, it is such a great idea because essentially one of the ways in which AI is going to become useful is when it can ingest and act on the various types of corporate data that enterprises have and really, um, bring that data together and give us, you know, help us to, uh, build applications that use it. Uh, the problem is that that data exists all over the place in all sorts of different formats and so on.
And, uh, from the initial discussions with cdata, it seems like y'all are, are really focused on solving that problem. So, Ken, let's start with just a little bit of an understanding. What's the problem when it comes to data and ai?
Yeah, Steven, uh, the, the problem around data and AI is really, data is an AI problem. Um, the strongest predictor of AI success really is that maturity of your underlying data infrastructure that takes and delivers the enterprise context to these powerful models that companies are investing in. And so the companies have to act on that data.
They need to be able to understand it, they need to be able to access it securely and correctly, and then they need to be able to take action on it, which is sometimes requires writing back into the systems as well. That is a data integration problem, and that requires a lot of sophistication and understanding the semantics of the data and how to access those systems. There's some, you know, new, new technologies and protocols and techniques that are greatly unlocking that, but you also need, uh, that understanding and governance layer as well.
And that's what we try to do at cdata. Yeah, and I, I would, I would argue that there is no AI without data. Um, I, I think that they too go hand in hand, peanut butter and jelly all day long.
And, um, like Ken, you said it is a bit of a challenge for enterprises because they have been working hard for decades now to try to modernize and streamline and democratize access to their data estates. But that is not easy. And it's certainly, you know, if you take 10 enterprises and sit down with them and say, okay guys, you know, where are you at in terms of, you know, trusting your data, having quality data available to your business users, uh, as well as your agents that you're building right now.
And I think most of them would tell you that, you know, it is very much a hit and miss sort of affair right now that they don't have full trust. They don't have full access. So we ran a survey this summer, um, uh, actually autumn, um, asking data professionals, you know, are you investing in, in, in ai and are you using ai?
And you know, as we see everywhere, you know, by and large, over 52% said, we are already using it. We are building on it. That is our top, top priority is ai.
Uh, and yet when you ask them, you know, what are your biggest obstacles? Guess, guess what the biggest one is? It's, it's not security, it's not integration, it's not money, it is data quality, trust and governance.
I agreed. And, uh, Brad, it's interesting 'cause we actually ran a very similar survey, uh, on our side, the state of AI data connectivity, and we spoke to over 200 leaders in both the enterprise and in software technology companies. And our findings were very, very similar to yours.
So we might have been talking to the same people. Um, we found this Probably were, Yeah, maybe, yes. Uh, 60% of companies had had the highest level of AI maturity, also had the most mature data infrastructure.
Yeah. And the inverse of that, 53% of companies that had immature AI also had immature data systems. So there was a strong correlation between the maturity of their data systems and the maturity of their AI initiatives.
Yeah. I wonder the, the biggest, oh, sorry, go ahead, Steven. Yeah.
Lemme just jump in there. Okay. Yeah.
Hey, here's a, and here's an edit point. We're demonstrating how to do this. All right.
I wonder if that is a cause or an effect or both. Uh, you know, I mean, if a company has a mature, uh, data foundation, if they really understand their data and they've, they've spent the time and energy and effort to, uh, bring it together in, in some way, uh, they may be better, uh, prepared to develop AI applications right from the start. But at the same time, as you're pointing out, if they haven't done that well, then they're just not going to be able to get the benefit of AI applications, even if they do invest in them.
What, what do you think of the chicken and the egg care, Ken? Is is this a, uh, uh, a, a requirement or is this a symptom? Yeah, I, I, I unders understand, and I think I agree with you with some of this sort, the, the dual nature of this.
Um, and, um, I would say that there is a, if a company has a culture of stewarding their data, having good data infrastructure, they already have a culture that's gonna allow them to move quickly and adopt ai. And, but on top of which they're gonna have that good infrastructure in which to, to do it. Those that haven't made that investment, they're trying to play catch up, they're trying to, um, swap the engine in flight by plugging in better data while also trying to plug in ai.
Um, there's some ways to accelerate that, but you're gonna have to do a little bit of the work required along the way. Um, and you know, what we try to do at C day is we try to help them sort of accelerate that, take advantage of what they have. Um, the good news is, you know, often when you talk about data infrastructure, you think about let's get everything into a data warehouse or a data lake, and let's stage it all there and everything.
And that's important, especially when it comes to understanding your business and analytics. And you can apply AI to that. But there's also sort of the need, and we saw this in our, our survey and our study as well for realtime data.
Oh yeah. And realtime data is not data that's staged in a warehouse, but the data that's sitting inside your operational systems data that you're gonna act on directly and orchestrate your workflows and business processes around. And this is where agents in the world of AI are really starting to come into their own and their ability to sort of do that.
And again, they require good understanding of that underlying data. What is, what is the semantics of that data being stored in that underlying system? You know, how do you operate on it?
What are the correct ways to work with that data? And ha combining the semantics with that data access is what will is that sort of accelerant that will allow you to take advantage of it and mature your AI projects much more quickly. Yeah, I agree, Ken.
And, um, it's, it's funny because access and understanding, you know, have to go hand in hand. And I, I feel like right now in the enterprise, we have unprecedented access comparatively to where we were just, you know, uh, a even a few months ago, uh, at the hands, for example, of the model context protocol that Anthropic came out with about a year and a half ago, and how, you know, surprisingly, you know, a a, a dominant that has become as a means of helping models in particular access data, but understanding what the data means is, uh, I think a greater challenge and one that not a lot of companies are, are really, you know, uh, able, able to chat about. Um, I mean, I would love to come back and actually talk about, you know, how the easy button of model context protocol and how dangerous that is because I think you guys, uh, are are definitely seeing that on your customer base.
But before that, can we talk about the semantic layer? Can we talk about, you know, what companies really need to do to build that understanding? Do you feel, Ken, that we're getting to a point now where we have the ability to not go the data warehouse data mart route, but instead have this open composable data lakehouse, let's say that, you know, totally separates storage and compute and lets me use whatever query engine I want depending on who I am in the company and always have, you know, access to and knowledge of when I say quarter close for accounting and sales, that it means this and not that.
Yep. Well, uh, you know, the, the, the common phrase is garbage and garbage out. So you have to make sure that you're putting good data into, into that data lake, um, in order to apply that semantic understanding of it.
So a absolutely, I think we are approaching that. And I think AI is, again, is an accelerant of that and the ability to, um, have deeper understanding of the structure of the data and the meaning of the data. And both of those are important.
Lemme lemme tell you what I mean by that. So, structure of the data is, is how's the data stored? What is, where do you find and how do you connect the different fields, uh, of the data together?
And, and, and then can interpret meaning out of that. And then understanding that data, like what does it mean? What is this number?
Is this a quarterly number? Is it a monthly number? Uh, does it include us or world or, you know, north America, you know, whatever that might be.
Understanding the context, what, you know, accounting principles, if you're talking about financial data, apply to it. So there's a lot of context in, in order to interpret that data. And AI is really good at sort of stitching that context together.
And, um, at Cdata we do is we take that we have some understanding of the underlying structure, semantics and a bit of the understanding of what the actual data is, and we inject that into the context of the model. And that semantic, semantic context is super critical. 'cause without it you like to say is you're left with a system that just burns tokens on ambiguity rather than delivering value to your user.
And that's so, uh, difficult when you have such a diverse set of data sources. Um, you know, not every data sources created equal and not everyone is going to be able to have that kind of context. Uh, talk to us a little bit more about how you deal with diverse data sets.
Sure. Well, there, I mean, enterprises, the, the typical enterprise uses hundreds of different systems with data stored in all sorts of different, uh, data, uh, locations. Uh, it could be internal databases on-prem software and systems, SaaS-based solutions, uh, partner systems and so on.
So you have to be able to pull all that data together and connect it, uh, in the LLM in order for that context to be valuable. And, and, and that is what a connectivity platform really helps with. We are actually able to go out and connect across systems and join data across systems, take a bit of the burden off the LLM, so you're not consuming all of your context and all of your tokens by having to bring all the data and do that processing in the LLM, we can push that down into these underlying systems across multiple locations, and then expediently bring that back to the LLM so we can do the final sort of reasoning or actions that it needs to perform.
So being able to handle diversity is really, really critical, especially in some of these new agent workflows that businesses are building. We as humans, we deal with that sort of, you know, diversity day by day. You move in between what used to call swivel chair integration and moving between system to system, pulling data together, copying and pasting, pulling up analytics reports.
We do that as part of our job. We're now asking AI and agents to do this. And so it needs to be able to manage and handle that diversity.
So you need to be able to, to have a system and underlying infrastructure that supports, uh, that diversity as well. Yeah. At scale, right Ken, because, um, as we start to get into, you know, these, these very advanced agentic pieces of software that we're building right now, getting data to the model is half of the challenge, half of that battle and, and not just understanding it.
And so you see a lot of investment right now in, in things like memory caching for being and being able to batch process and be able to, you know, not burn tokens, but still get the data to the models. And I think we need to also think about the fact that it's a entirely new constituency, uh, not just for consuming data, but for producing data. 'cause these age agentic processes create a lot of information as they go, and it's data that needs to be managed by the business because, you know, you, the, we, I was just actually talking to, uh, a number of, uh, companies who are building out commerce systems that are agentic, and the biggest challenge they felt they had was, was being able to take the data that gets generated from each interaction with their customers and to, you know, have that available to the agent, not just today, but tomorrow and the day after tomorrow.
Yeah. And that, that's, that's where these, uh, data management platforms, large data lake solutions can really value. You have a place you can go store that at scale and then go back through, through agents, uh, and access it and bring it into the context of, of your workflow.
Um, I do wanna, if I can go back to Brad to this point, you've brought it up a couple times in the concept of the explosion of access. Uh, and, and, and what you were saying just there reminded me of it again. And that is really important to think about because I, so I've, I've been around the data and application integration world for almost 20 years now and saw the explosion of, of APIs and SAS and, and integration and IPAs and now, uh, with, uh, AI and agents and MCP and data's getting easier and easier to access, requiring less and less sort of technical work to, to bring it to the point of use within the business.
And access is really critical access, both in terms of scale, like you said, you know, you can bring back too much data, burn a lot of tokens, uh, bring back inappropriate data that maybe the user's not, or the agent is not allowed to operate on. Or maybe the agent might do something with it that a user would know not to do. Uh, so you need to be able to sort of govern that.
You need to be able to handle at scale. Uh, you mentioned model context protocol. You can have a tool explosion model.
Context protocol represents everything as tools and you can only handle so many tools within the context of an LLM. So you need to be very efficient in the tools that you expose within an agent to the LLM and to how much data you bring back. So leveraging the power of these underlying systems, not overload the LLM with too much data.
So there's a lot of things around access that need to be thought of by someone architecting an ag agentic system. And, uh, again, those are areas that we, I spend a lot, lot of time thinking about how do you actually scale this and do it effectively and efficiently. Uh, and it's something that we see our customers, um, really kind of struggling with when they come to us, but realizing that there is, there are better ways to do this.
There are definitely better ways. Um, and, and unfortunately the, the technology is moving so quickly that it, it's becoming a, as you mentioned, too easy to access data and to do so unwittingly, un responsibly. Um, and also it, it's, you know, performance wise, the, the tech, the tools that we have available to us are allowing us to build systems that we can't support our, our infrastructure just isn't ready for.
And I, I like to think, you know, when I, when I think about cdata and, you know, vendors that are playing in the space, you are that at the end of the day, it's about, you know, it helping customers see that they should not go the shadow IT route because that, that's dangerous. Um, but there are options to, you know, accelerate what they have and to meet those evolving capabilities as well as needs that we're seeing start to, to come into market. I mean, I saw a model come out just this week, uh, that has the ability to handle 400 tool calls in a single, you know, long running pass.
That's insane. Uh, there, that is, that's, that's a lot of processing, a lot that, a lot of power that you have in that and that type of model. And that's the thing.
We don't know what's gonna come out next week. We don't know how these models are going to evolve and what capabilities they have. We know they're gonna do more than they do today.
And so you have to kind of plan for this unknown future. And so when you're thinking about how you design these systems, you do need to think about scale and governance. And you also need to think about what might be possible six months from now.
Um, and the other thing is make sure that you're designing to, to update and refresh this, realizing that your architecture's gonna change. There's gonna be innovations to take advantage of. So you have to be agile.
And so you need to use underlying infrastructure that's also agile and gives you that flexibility. Don't tie your down to, to one particular model or infrastructure vendor, uh, allow you to move around, consume new data sources that you didn't necessarily have, that you weren't thinking about before. So that agility is really important in this type of fast moving world of ai.
Well then that point that you're making about is, goes to the point of maintainability. And that's been a, a key problem. Anytime you're building an application that integrates diverse data sets or tools.
I, I is the inherent sort of fragility of those systems because, uh, you know, vendors can change the ways that their APIs work. Uh, they can change their, you know, they could abandon, uh, one API or another. They could, uh, really upset the apple cart.
And this is especially true. It gets multiplied when you have more and more and more disparate, you know, components in there. So one of the points that I was gonna ask, and, and I think you've sort of just a answered it, is why not just rely on the vendors to make this accessible?
Why not just work with, uh, you know, whatever happens to work? And I think that the, your answer might be, because even if it works now, it might not work later. And also maybe, you know, different vendors may have different approaches.
They may not wanna support this or that model, and you would perhaps allow them to, uh, integrate with, um, a broader set of data. Is that right? Yeah, exactly.
You might wanna switch vendor, you wanna wanna switch model vendors, uh, next year. You know, did you tie yourself to the, to the capabilities or the interface of that particular vendor? Or do you have the ability to kind of switch, switch, switch that out?
Uh, this is particularly the case when going with sort of full stack solutions from some of the legacy players. You miss out on some of that innovation that's happening in the market. 'cause they're gonna be a little bit more, they're gonna be a little bit slower to bring that capability to market.
And so you, you wanna have that agility. That's exactly right. Yeah.
And I, I think it's, um, you know, when I look at the marketplace for this year, uh, one of our biggest trends that we see evolving is this acceleration through integration. And that, you know, last year we probably would've talked about, you know, the format wars and is it gonna be Apache or, or you know, is is it gonna be Delta? And you know, that's done.
It is, it is definitely, you know, Apache iceberg all day long. And that separation of storage and compute I mentioned, and what that does is place the burden on the vendors who are building these systems to, to provide that sort of interoperability. And what I worry about honestly, is that we sometimes, when we get a shiny new toy, we over rely on that toy to, to scale with, you know, our needs in the marketplace.
And I think MCP is one of those that's just been so overused, uh, you know, right now that it's, it's becoming itself a, a sort of liability in terms of that. That's, you know, like we talked about before, understanding the meaning of the data that it's accessing, accessing the right data. How do you secure that access point?
Because those standards, like a 2:00 AM CP, any other framework you wanna throw out there for integration is, you know, an abstraction layer. And those abstraction layers aren't free, right, Ken? They, they do have a cost you have to pay, I think.
Well, I think I, I, I wanna agree and disagree with you on that. So, uh, I agree, I agree that there is, there is, you, there's a trade off whenever you have an abstraction layer. 'cause you're, you're always, you're always in a trade off.
'cause otherwise you would go to a proprietary approach and you might get something very much more specific for your needs. But extraction layers help markets sort of stabilize and mature. They allow people to focus on one thing, and that's what MCP has done.
It's allow people to focus on a single way to connect their data, their, uh, and their tools into the LLM. Now, if you just just utilize it in that way, you don't think about how you deal with authentication, how you deal with governance, how you deal with security, how you scale it, how do you manage it, change management, all of that, then you're gonna be in trouble, like you say, then it, then it's a crutch and it, you're, you're not going to be successful at the end of the day. Um, if you just use agreed, go grab the latest MCP server in some open source community, it might work for you original, initially, but you might, you're quickly probably gonna find out it's a bit brittle, it's a bit fragile.
Even some of the ones from some of the first party, uh, providers out there, they're incomplete. Um, and they don't maybe have all the capabilities that you need in order to solve for your problems. So you gotta build around that.
And that's one of the things at Cdata we're looking at that. We've built our own MCP servers for over 300 different critical business systems. And we built all the governance, we built the, uh, security, we built the scalability.
And I also added that semantic layer around it to make it much more effective and much more efficient, so that now you do have something that you can rely on that's stable and that you can, uh, scale your systems on top of. Well, yeah, I recall there being a market, oh, I'm sorry, Steven. Yeah.
Uh, I, I recall there being a market specific to integration, um, that that's all vendors did, and they built connectors. And we, we seem to, as a marketplace, have tried to move away from that and say, oh, you can just do it yourself. But that's really not the best approach when you're trying to, to have a system that could adapt to that changing data estate that we've been talking about, to be able to say, today I need Salesforce data cloud tomorrow, I, I need something on, you know, a totally different platform from SAP.
Yeah. And I, I would say, you know, for very simple things, for very simple APIs, uh, a lot of role at your own. But as Cdata, we've lived in that sort of world of connectivity for many, many years.
We have 10,000 customers that are, uh, that are licensing and using our connectors, including some of the largest software companies in the world, um, that are embedding it inside their platforms, uh, in order to provide connectivity out to other data sources. So connectors are a critical component. MCP as we're talking about here, model context protocol puts an abstraction over that concept.
Um, so that anything that you can connect to anything that has an API, you now have a way to plug it into an LLM and make use of the data and make use of the actions that you can perform. And, and that's important to, to think about. It's like MCP can be data access, but it can also be operational execution.
Uh, and there are other concerns when it comes to operational execution. You're changing data, you're triggering workflows, you're, you're triggering actions within your organization, within your enterprise that have implications. And so again, security governance and all around that scoping it, scoping the permissions down to the set that are necessary for that agent to perform the types of actions that would be necessary for whatever its goal or objective is, and not allowing it to stray beyond that.
Yeah, I think that you all have a lot more experience with MCP than most of the folks listening. Um, I wonder, I, I appreciate you kind of bringing those, the, uh, thoughts to, to the fore here about MCP and thinking about governance and security. Um, what else could you tell us if, if we wanna kind of step back here a little bit, um, what should people know about MCP if they're looking at it, if they're thinking of implementing it?
Um, you know, what have you learned in all the years of developing or the, the year of developing all these, these MCP servers? Um, what are the lessons you've learned? Yeah, I mean, the lessons I learned, first of all, MCP sits on top of the underlying data sources, the APIs or the, uh, the SDKs are used to access them.
There's a lot of complexity. You know, just because something is rest doesn't mean it operates in a certain way. So there's a lot of complexity underneath it that you need to deal with in order to have a good functioning MCP server authentication is still hard.
We wish it could be easier. I mean, so back in the day, I actually worked on the, uh, SAML uh, committee to develop that as a standard, took us a long way. We're still, you know, utilizing that inside of OAuth and everything else.
So, but there is a lot of complexity when it comes to identity. And you, and also with MCP, you have to think about identity in the context of the user now in the context of the agent user and the, and the scoping of that identity. So that, that's something to deal with.
Um, there are there own little sort of enhancements or additions that each, um, client has created OpenAI. They have their OpenAI, they have their apps, uh, Claude Anthropic, Claude, they have skills, they have different things that they're building around MCP that are specific to each of them. And so you need to think about how your MCP server is gonna interact with each one of these, whether it's a chat LLM type agent or an agent platform.
Uh, that's something to think about. And then there is, there's governance, there's, how do you discover the registry for discovering, I mean, it's, it's okay if, you know, you've got a handful of M CCP servers, but what if you've got thousands of MCP servers? What if everything in your enterprise is suddenly, uh, MCP enabled?
Now you need to have a concept of a service registry and some sided governance around it. Um, so we're not getting away. We had that problem with APIs and API management.
We had it back in the SOA days with SOA service registries. It's, uh, we had it even back in the corbit days in the nineties. So it, it's, you know, naming and discovery is always gonna be an issue.
It's gotten a bit easier, um, with LLMs, but with MCP, you still have that, that concern. Yeah. Bring, bring back middleware.
Uh, I, I, I, I love the, the, the SOA era just because we, we were trying to build software the right way, and it just, it just turned out that it was a little bit more difficult than we thought. Um, but may, maybe we have the option now, but I, I, I totally, you know, agree with what you're saying, Ken and I, I feel like, you know, when you're talking about CPS as just another means to, to get to those sources, you do have to consider the models. And I felt for a while now that the models themselves, especially the frontier models, are much more than just, you know, a, a, an endpoint that you're querying.
It's, they're actually platforms. And so you need to have standards, you need to have some sort of registry to understand when Google changes the Gemini, um, API subtly that, you know, it's, it's not gonna break your application tomorrow. Uh, maybe the model itself changes in, in its ability to like, um, refuse a request or continue the request.
And all of that is, is much harder to deal with when we have these models that, that are non-deterministic that we're using as infrastructure. Exactly. If I, if I can just summarize some of my thoughts on that.
Uh, so I'm a proponent of MCP. I'd like that it's being developed in real time and tested in the market and iterated on as opposed being developed in a, in sort of an ivory tower and, and over-engineered. We've seen that in the past.
So I really like the approach that, that the vendors have taken to kind of come together on this and, um, try to not try to solve too much and allow other infrastructure and software companies and the LM providers to come in and build around that, to, to kind of sort of polish those rough edges and provide the additional support and capabilities that are needed. Uh, I think that, uh, one of the key areas that, that needs a little bit more work and that we're focused on is that semantic context, as we've talked about and under understanding what's, what the capabilities are, the underlying systems. Uh, I think that it opens up and allows for real-time data access and action.
I think that's very important. Uh, and it recognizes that so much of the enterprise data is in this sort of structured format that agents being able to access and operate on and com, that combination with these types of standards and these types of capabilities will allow us to get to sort of this promise of digital employees, digital agents that are agent to agent working together, uh, swarming together to solve, uh, solve problems and operate businesses more effectively and create more enterprise value for us. So all of that said, I think it's time to, for companies to be investing in their data connectivity, investing, investing in their infrastructure, and to do this to enable AI to answer and act on their business.
Yeah, thanks for that. And, uh, I think that's a good message to leave our audience on here. Uh, as Brad said at the top, uh, you know, you can't really build an effective AI application without good data.
It's all about the data. And, um, that means that this is an area that, uh, companies are gonna have to invest in if they're going to have an effective AI application. Thanks for joining us.
Uh, before we go, uh, many of our listeners may wonder how they can continue this conversation or where they can connect with you. Uh, Brad, uh, let's start with you. Uh, what are you researching?
What are you working on, and where can people find you? Yeah, right now, I'm, I'm actually building out a new, um, comparative report using our, our, our signal, um, agent agentic report process on data intelligence platforms. And that's gonna be all about how you get that semantic layer and put that in action just like Ken said.
So looking forward to that. com. Excellent.
And, uh, Ken, how about you? Great, thank you, Steven. Uh, likewise, uh, happy to people to reach out to me, connect to me.
LinkedIn's, uh, gonna be the best way at Ken Yagen on LinkedIn, on other social, on, on X and other things as well. Uh, I mentioned earlier, but I encourage you to download cdata state of AI data connectivity report from our website. We'll provide the link, uh, along with this podcast and you can also check out our product.
com. Uh, and I'll be speaking in March at the Gartner Data and AI Summit and Florida. So if you happen to be there, come check out talk.
We're gonna be talking about, uh, the same topic there. Excellent. And, um, as for me, uh, you know, I run Tech Field Day, uh, this week is AI Infrastructure Field day four.
com and the Tech Field Day socials, and of course, we will be having another AI Field Day in May. So keep an eye on the Tech Field Day socials to learn more about that. Thanks for listening to this episode of the Utilizing AI podcast.
If you enjoyed this discussion, please do subscribe on YouTube or your favorite podcast application. Also, drop us a line, uh, give us a rating, give us a review. We'd love to hear from you.
This podcast is brought to you by the experts at, uh, Futurum Group, uh, where Insight meets ai. ai, the utilizing AI YouTube channel or textron's, uh, new TV app. Thanks for for listening, and we will catch you next week.