Techstrong TV February 23, 2026
RSAC Innovation Sandbox at 21: Cecilia Marinier previews the 2026 Innovation Sandbox Contest, highlighting $18.1B+ in follow-on funding, 100+ acquisitions, AI-heavy finalists, $5M backing from Crosspoint, expanded early-stage programming and the return of Security Scholars as RSAC doubles down on startup and talent development.
OpenTelemetry and the Observability Warehouse: Eric Tschetter explains how OpenTelemetry adoption is driving a shift toward unified “observability warehouses,” consolidating logs, metrics and traces into scalable, real-time analytics platforms.
AI & Agent-Accelerated Development: AI-driven agents are reshaping the SDLC, moving teams toward intent-based automation, specialized development agents, and governed control planes that transform DevOps, platform engineering and developer experience through 2026.
AI Agent Security Wake-Up Call: The MoltBot/OpenClaw saga underscores the risks of rushing autonomous agents into production. Experts stress governance, skill vetting and embedded security controls before granting agents access to sensitive business data.
Eliminating Data Silos for AI: Hammerspace outlines a global metadata-driven architecture that unifies distributed data into a single namespace, accelerating AI pipelines without costly migrations and enabling instant visibility across hybrid cloud environments.
Transcript
Hey, everyone. Welcome back here to Text Drunk tv. You know, it's starting to sound a lot like RSAC season.
Oh, not Christmas was last or the month before already. Wow. Time is flying and RSA is almost here.
So if RSA is almost here, you know, we're gonna be talking to my friend Cecilia Marinier. Cecilia is the Vice President of Innovation and Scholars for RSAC, the people behind the RSAC conference. We have some branding I wanna reinforce there with y'all.
Um, behind the title though, and all the fancy names and acronyms, Cecilia's, the lady who's been running the RSAC, uh, innovation Sandbox Contest, the, uh, sandbox Village, I think it's called an Innovation Villages, and so much more. It's really grown up over the years, but Cecilia's kind of the, the driving force behind it. Cecilia, it's great to have you on again.
How are you? I am great. Thank you, Alan.
I appreciate always coming on. Really excited to touch base with you and the audience right before our conference starts. Such a great time.
Thank you. Absolutely. We're about a month out and, um, I know, was it last week you announced the 10 finalists for this year's, uh, innovation Sandbox?
Yes. Yes, it is. They just announced it.
I have to tell you, like, that part right beforehand is so unnerving, but it's so fun. And all of the top 10 are so excited about being recognized by the industry leaders, by those five judges as, uh, as who should be on our stage. So, such a great time.
Absolutely. And it's more than just the recognition. There's a fair bit of cash involved too.
There is this year, and as in last year, as in what we see in the foreseeable future, each of the top 10 are gonna have like $5 million investment from Crosspoint. So they are not only getting the leg up of a platform to amplify their message, but then they're also getting the funding to actually support that so that they can really use that amplification and, uh, and go to market with their products. Excellent.
Cecilia, I feel like we jumped out ahead, though, without laying the right foundation. Okay. Let's go Back.
There might be people out here who maybe you're not familiar with Innovation Sandbox, they're not familiar with all of the great activities that you and your team, you know, put forth. Not, I mean, the culmination of it is RSAC conference week, but it's, it's almost like a year round chore at this point, you know, running these and yeah, selecting them and organizing and doing it for people who aren't familiar with the whole program, Cecilia, educate them a little bit. What, what's involved here.
So thank you for giving me this chance. So, RS a's innovation programming is very broad, and the whole goal is to kind of offer, uh, and a platform for a lot of startups to come out and meet with the industry leaders, the decision makers, and kind of showcase what are the kind of, uh, solutions that they're taking on to, uh, to solve for the vexing problems our industry faces. And so what we've done is created beyond the Innovation Sandbox Contest, which is 21 years old, uh, and has labeled, has named big names that came from nowhere.
And now you have them in your vernacular, such as, you know, big idea, exons, Wizz, all of those companies have now, you know, been part of the Innovation Sandbox first, and then has have grown to that. Um, we created another contest called launchpad, where we ask venture capitalists to actually identify three startups. And guess what today is, it's the day we announce our three startups for that as well.
So go for the launchpad. Really awesome to see the caliber of companies coming in for that, but we don't stop there because it's not enough. There's so much happening in this industry, and we wanna be able to give more companies a platform.
So we've also started this area called Early Stage Expo. We've expanded it from 50 companies now it's up to 78 companies. And that runs on Tuesday through Thursday.
We have a whole track aimed at investors and entrepreneurs where we have nine other sessions that we'll be talking about trends in the industry, what are the venture capitalists looking at who had to get money, how to get funded, all of these kind of, um, content pieces that also have a amplification. And then finally what we've done is we've created another thing that we're doing this year, which is private, but super fun of trying it out. It's called the CISO Entrepreneur Breakfast, where we're connecting CISOs that are coming from our, um, closed door programming to startups out in the industry.
So 15 of them are gonna go and meet with these CISOs and, and see about becoming design partners. So that's what happening at conference. Additionally, we also created something that was year round, which we call Innovation Showcase, where we also identify, um, some startups that we can give a platform to.
So that's just on the innovation suite. And I, you talked about villages earlier. I'm happy to talk about sandbox slash villages whenever you want.
Well, you already did the cat's outta the bag, my friend. We've gotta finish that thought. You know, don't tease people.
What, what are we talking about here? So, you know, if you think about how the industry has developed, there's a lot of people who are working on the entry level, and that for me is like my heart. My heart goes out to those people, those are by security scholars.
They're the college day, but then as they start to move up the chain, they become into the decision makers, right? Well, one of the areas that we've tried to like combine these two forces, the early entry, mid stage career and decision makers, is this area called the Villages. It was previously called Sandbox.
And don't get confused because it's not Innovation Sandbox. And that's the whole reason we made a decision to go. Let's go back to the villages.
So the villages are areas where it's hands-on activities. It has volunteers who are sitting there ready to have a conversation with you. If you're interested in IO OT or you're interested in ai, you can go talk to those village representatives.
And it's really super fun to be part of that. Also, then there's a new place, it's called Connection Hub, but I'm gonna leave that one, Alan, this is my cliffhanger. I'm leaving that for Britta and, and Linda.
Excellent. You know what, I think I have Britta and Linda next week sometime. Okay, awesome.
Um, so I'll I'll be sure we, I, I quiz them on that and, and ask them about that, but that'll be fun as well, Cecilia, that this is a great overview. But as I mentioned, we did announce the 10th finalist. Yep.
It was last week, right? It was, It was, yes. Last Tuesday the 10th.
So it was a week already. Um, well, let's, first of all this, for people who want to get more information on this year's 10 finalist, it's at the RSAC site, Right? So what you can do is when you go to the innovation, uh, excuse me, when you go to the RSAC conference website for this event this year, and you go into programs, you'll see Innovation Sandbox, you'll see Launchpad, you'll see all these others, and that's how you can get to the top 10.
You can also see at the banner at the top for the next week or so where they say, you know, come check out the top 10 winners and you can go learn more about who they are and, uh, what they do. And as you mentioned, every one of them is guaranteed a $5 million investment from, uh, Crosspoint. But, um, Cecilia, not to put you on the spot, but let's see how, how deep you are into the Innovation Sandbox this year.
Can you give us maybe the top 10 lists and a little bit about what you know about them or what you might wanna say, or, Okay, I'm Gonna, that might be a bit much, You're gonna have to cut out a little bit here 'cause I gotta go pick up my, uh, my little cheat sheet here. You, that's, I expect That would Cheat gone expect cheat sheet. That would you, you would, you would, I, I have very high regard for you, Cecilia, but if you were able to do all 10 off the top of your head, I could, I'd fall outta my chair, but go ahead.
Alright, so here's what I'll say in general. I mean, there are 10 really interesting companies, and of course this year is highly focused on artificial, uh, on ai. I mean, I think all of them have AI as part of the solution, whether it's to improve productivity, whether it's to protect against ai, you're going to see, you know, AI leakage or something.
You're going to see AI as center stage, but the companies range, um, they're really, I like them a lot. I'm very excited. So we have charm security, clearly AI crash, override fig security, Jordy AI Glide identity, uh, token security, uh, realm Labs, and Zero Path.
How'd I do, did I get that? Excellent. I think you were almost in alphabetical order there as well.
That's pretty darn impressive. Oh, You know what, I didn't, I did nine humanics. Goodness gracious.
So sorry about that. Human. Well, you left that we did nine and there's humanics.
Okay, There's 10. That's To give, to give folks an idea, really just how special it is to be one of the 10 finalists. I, I think there's two, two things that we need to look at.
First of all, you know, your mileage may vary. Past performance should not be your guide. You know, that's when you're buying cars, electric cars, or gas mileage, right?
But when it comes to the RSAC, innovation, sandbox, past performance does matter. You mentioned some of the companies that over the years, and, and this is, I forget now, is this the 21st year? 21st year, right.
1 billion in investment for the top 10 over the 20 years. Over 21 years. Really impressive numbers.
Additionally over, so if you think about the fact that we've only had maximum of 200 companies, 'cause one year we only had seven. Just, I know that sounds crazy, but that was in the, a strange year in 2007. So there was only seven of them, but a over a hundred of these companies have been acquired.
So it is telling that, you know, we've had several that have gone IPO several that have, uh, most of them have been acquired or they're just doing extremely well. Like, if you think of Nia, for example, is doing exceptionally well. Big ideas, big names.
Um, more recently, so like Calen Security was acquired by Palo Alto Networks. Yes. And, um, Oliver's latest company, Penia was just acquired by CrowdStrike.
So again, like the, the track record on this particular contest is strong. Uh, so if you get on the stage, it's, it's, it, you know what it is, Alan, it's helping these companies rise above the noise because they have five industry leaders as judges who are actually I identifying important companies that really will likely make it because they're all working from different perspectives. You've got, you know, Dave Chen coming from Morgan Stanley who's doing the banking side of it.
You've got Larry Fine Smith coming from JP Morgan Chase, who's doing the global overall, like JP Morgan Chase is one of the largest banks in the world. But more importantly, it's also like one of the companies that does help and partner with startups. You have NASM, who is the CISO at Verizon.
You have Nilu Howe who newly Rousey, who is at, um, who currently is in a venture capital group situation, but she actually has a lot of background in national security. And so her whole perspective is like, you know, what is the government thinking? And then your final one is Paul Kocher, who is an incredibly deep researcher, has technical knowledge that is testing all these companies out.
But more importantly, he also sold his company. So he knows exactly what it takes for an entrepreneur to go from bootstrap to sale. So those guys are our industry leaders.
They're choosing the companies who will be on that stage. So by going into and seeing the Innovation Sandbox contest, you're actually already having like this, this group of people who are really invested into what's happening in the marketplace overall, identify companies that are really strong, you should pay attention to. Absolutely.
Cecilia. So we looked back, let's look forward into the present. I don't know if you have these numbers and if you're allowed to mention share them, share, but how many companies apply to or are considered to get to the 10 finalists?
That's a great question. We don't actually put, put that number out there. Um, but we, I can tell you that the Down select is, you know, there's over hundred, there's hundreds of companies that have applied in this year.
That's what I'll say. How's that? I would imagine, well, not for nothing, but every day it seems my inbox is inundated with new cyber companies coming outta stealth and raising ridiculous amounts of seed money or round days, like bigger than I've ever seen.
So I, I'm not surprised to to hear that as well. You know what we didn't mention for people who are gonna be out at RSA in San Francisco at the Moscone Center. Yeah.
When is Innovation Sandbox being held? Where? So innovation.
Oh, okay. So, um, innovation Sandbox and all of the innovation activities will actually be on the second level of Moscone South. We start on early morning, March 23rd, all the way through, um, that Thursday the 26th.
So in order to get into any of the innovation events, you have to have an Expo Plus or L Access badge. But if you wanna just go to Early Stage Expo, you can get in there with just a expo only badge, but you don't miss all the contests. And this year, Alan, you have to come because I am doing something super fun.
We're doing something super fun. I'm not gonna tell you another cliff. I All right, well gotta Be in the room on Monday.
I'm one level B above you. I'm up on the third floor. I think you're right below us.
That's right. That's right. But I'll, I'll try to run down there and look for you.
If, if give me, well, we, no one's watching Right there. It starts nine 40. It starts at nine 40.
If you can sneak away from Lunch. All right. I could probably sneak out there.
'cause our starts early and I just gotta say hello to everyone warming up, and then I'm actually the doorman scanning people. But, uh, look, you know, this is what happens when you're on your own thing. Your chief cook and bottle washer.
Right. But I'll try to get someone else to do the scanning. I'll run downstairs to see you.
I would love it. I would love it. And, and don't think that we who are working at conference or any different, my friend, we're like, we're jack of all trades, man.
You see us out there, do whatever out there Can get done. Exactly. We're all in it together.
It's so fun. Absolutely. I'm really excited to see everybody this year.
Please, if you see me come up and say hello, I'd love it. A absolutely nine 40. And then I'll make it back up.
'cause I think we have David Bryn going off at 10 or 10 30, you know, and this is the year where sci-fi is becoming real. We live in a world of sci-fi where Asimov's Laws of robotics and Philip k Dick's, you know, electric Daydreams of Androids, they're like real, it's really happening. Who thought it would happen in our lifetime?
Cecilia, if no one tells you, let me tell you, you do a great job, a great job running this Innovation and Scholars program every year it grows and gets a better and better. It's like, you know, it gets better with age. And Me too.
I'm hoping I'll have to ask my husband. I wasn't going to say it because, you know, I'm, I'm married and I know better than to, I know where not to go. I get in trouble when they do that.
Okay. Wait, I, I wanna make one small plug for my security scholars who on Wednesday Go ahead. Will be, go ahead.
22 of them this year. So that's over a third are showing off their posters on Wednesday in the North lobby. So I would also love for any of your colleagues, friends, whatever, check out their posters.
They're on the website. You go to Security Scholars, they check on the posters, or you're gonna actually look under your agenda for the poster session. They'll have a link to it.
These guys are working on some really important topics and areas of focus. So we should give 'em some love, love to see people. Absolutely.
And there, you know, what was it about two years ago or just last year you started Scholars? Oh no, I've been doing the Security Scholars since 2016. Ooh.
But we took a couple years off and that was kind of, we lost a little momentum because of COD COVID. But now, right. That, that's why I, thats what it is.
It was a Reset. But we are, we're back. We're back stronger than ever.
We're to. Good to hear it. Cecilia, thank you so much for coming on here.
Absolutely. I dropped my AirPod, but, um, thank you. Keep up the great work.
I can't wait. We're going to reach out to some of these finalist companies and see if we get 'em here on Tech Drunk tv. Uh, be between now and, and the end of next month.
Well, you know, between now and the conference. But sounds like you got another bumper crop. It's gonna be a great event.
And it, and it's not just the Innovation Sandbox, it's the entire Innovation in Scholars program. So do check it out, Cecile, we'll talk to you again soon and we'll hopefully see you in person in March and San Francisco. Absolutely.
I'll see you there. All righty. We're gonna take a break on Text Trunk tv.
We'll be back here in a minute. Hey guys, thanks for the throw. We're here with Eric Cheddar, who's the chief architect for Imply, and we're having a little chat about, well, the rise of observability warehouses.
It seems like we're actually pulling in more data than ever. We've instrumented applications. But now what Eric, welcome to show.
Yeah, thank you. Thanks for having me. I'm happy to be here.
Alright, So walk us through how this is all evolving. I mean it, for a while there we couldn't instrument many things 'cause it cost a lot of money and it was just hard. And now we have OpenTelemetry and well, it costs less, and maybe it's not quite as easy as we want it to be, but apparently we are pulling all this data in these days.
So where are we on this journey? Yeah, that absolutely, we, we've got OpenTelemetry. It's pulling in data.
I mean, we've also got AI now coming, generating a whole bunch more data and, and, uh, everything. And it's all kind of dumping into things. But, um, kind of taking a step back on, on where we are.
Uh, we at, at imply we've been around for about 10 years. We've worked with, uh, open source column oriented kind of database for a while. And we saw across our customers that they fit kind of two profiles.
One in the business intelligence world and one in the observability world. And we realized that in the business intelligence world, there's this clean separation between, uh, layers. You've got your visualization layer with Tableau and Looker on top of your data layer with your SQL data warehouses, snowflake, Databricks, all that.
And your data acquisition, ETL tools with, uh, um, Tran DBT, uh, Informatica thing, things over there. But then when we looked at the observability world, we realized that it's all kind of verticalized stacks. It's, uh, you've got Kibana on top of Elastic, on top of Log Stash or, um, Grafana and Loki with OpenTelemetry.
And, uh, we realized that, you know, looking back at the history of business intelligence, it got to where it is through a natural market evolution. And in the observability world, in this observability and security data world, really, it's just the beginning of that market evolution. OpenTelemetry really is it, it kicks it off.
It's starting to decouple the data acquisition from the other parts of the stack. But if we look at business intelligence, we see that there's this interaction layer that decouples from the data layer as well, which is where the observability warehouse comes in. Mm-hmm.
I got you. I'm, are we gonna have a unified observability warehouse because, uh, you know, if I look across all of it, everybody seems to be collecting telemetry data. Is it different data or is it all the same data and we just need to figure out how to share it better?
Like we were taught in kindergarten? Well, I mean that, I, that's fundamentally the same question that led to the evolution of the BI space is you had this business data, it came from various different business units. You wanna do corporate level recording.
You want each business unit to look at what they're doing. You want each of the analysts to see stuff. And you're wondering like, how do we share this?
How do we have the data? How do we make sure that it's in alignment with what we want it to look like? And then share it so that the organization can generally, uh, kind of get value from it.
And the answer there was the SQL database. And by putting everything in sql, by abstracting everything by a query language, it became possible to have the data in one place and let each individual group kind of interact with it, with using whatever tool they prefer. That same evolution is what will come to the observability world.
And so will there only be one place to store the data? I mean, that's not how markets work. If there's only one place that's a monopoly.
And, and now, uh, there will always be new people that come in, but people will be looking more and more for, I've got my data here, don't make me move it. Just let me query it. I want to use this tool.
Great. Use that tool. Query it.
You wanna use that tool, great. Use that tool, query it, use what you wanna use on top of it. There's no reason that just because the data's in one place, it can't be used by multiple tools.
The only the, that, the kind of separation there is really the query language. And that's the fundamental difference between the observability and security world and the business intelligence world where business intelligence is kind of, they have a heavy adoption into sql, where the observability and security world has a number of different query languages that people have adopted over time. Will AI kind of flatten that out a little bit?
'cause the AI agent theoretically will be able to speak multiple programming languages and they'll be able to query data where it happens to be found and pull it back into something that looks like, I don't know, a unified dashboard possible. Y yes, but no. But yes, I, I, I don't, I don't know, like, it, it's, uh, like I, I agree with the hope and the vision that AI can just take away all of this knowledge of language.
And it's just like I ask AI a question that gives me the answer. Um, so far, at least when I've been interacting with ai, I, I, I, I liken it. Um, so I'm not a sculptor.
I don't know anything about sculpting, but I can make up metaphors about it. And I liken it to, if I wanna, if I wanna like chip wood or I wanna do a wood sculpture and I have a block of wood, um, it's really nice and easy to use a machine to like make the general shape. But when you want that to look like a real sculpture, you've gotta get in there yourself and, and like, do this stuff.
And I found AI to be the same way. Yes, you can use AI for kind of broad strokes things. You can use it to, to start a first draft of a letter.
You can use it to even write some code initially. But when you actually look at what it did, you're gonna find all sorts of things that need to be adjusted and changed and things that are updated. And sure, AI over time will get better, but I'm not sure it's going to like, completely displace the need to understand what it's actually doing to look at it, to evaluate it, to supervise it.
And so I, I don't know how much it's truly going to eliminate the need for an understanding of the language versus just reduce the population that needs to have a strong understanding of it, if that makes sense. It does indeed. Um, I think people are struggling with storage of telemetry data, at least some of that I talked to.
And, um, you know, theoretically at least maybe we've got too much of a good thing now. So how do I figure out what data to store so I, when I need it to observe it? 'cause you know, I'll talk to some folks who are like data hoarders and they just store everything.
Yep. Then I got other folks who are barely storing anything. And then of course when something bad happens, they don't have the right data.
Exactly. Exactly. And that, and that's the, um, I think that's been like, you, you touch on a really key point.
People in this space have been faced with, um, well, I've got a bunch of data, the unit costs to store the data is higher than I wish it was. So now what do I do with it? Do I throw some of it away so that the economics work out?
Or do I find a different place to put it with better unit economics, but maybe a worse interaction pattern, or it's slower to access, or I have to take extra steps in order to make it so that I can actually use it. And, um, these two options have kind of traditionally been given to people. Uh, more and more we see people, there is some amount of pruning and throwing away data, but as you mentioned, now when you need it, you don't have it.
And especially when you're doing like a security incident investigation or something like that, that can be key to not knowing what actually happened. Um, so people tend to be leaning towards, well, with the introduction of public cloud, you've got your object stores, it's, it, it's pretty cheap storage, it's relatively easy to get access to. So people end up funneling, funneling it off into the object stores, but then they have the challenge of how do I make it actually interactable?
I have people who use one tool, but now they have to learn yet another tool in order to interact with this data. Or do I take that data and I transfer it back into this tool when we actually need it or, or what's going on. And, um, talking a little bit about, uh, our product, um, implies product itself.
What we've built is we've said, you know, as people are leaning into this cloud storage, what they care about is that unit cost. They want the best compression and, but they want it. They don't wanna give up the ability to actually query it and interact with it from the tool that they have.
And, uh, we've found that when you take compression and you make it kind of domain specific, so for us, that's logs. When you compress specifically for logs, you can do a really good job in order to reduce the overall bite count, which fundamentally then turns into a lower unit cost. And you can also use the latest and greatest indexing techniques to make that compressed form still queryable.
And that's kind of the, the product that we have. And that's kind of what we like to call this observability warehouse, where once you can take those logs, put them in a queryable and compressed format, you can minimize the unit costs, and then you build the connections, you work with all the query languages of the different tools that people are using. And now you can store the data once and interact with it from multiple different tools.
Mm-hmm. Um, Will we ever get to the point where I just come in in the morning and there's, you know, a memo from some AI tool somewhere that just says, you know, here's the three things we found in the observability warehouse that are likely to get you fired, and here's our recommendations for doing something about it. Um, yes.
Now are those three things actually legitimate? I think that's the fundamental question. I I, I think we're already at the point where you can get a list of three things that, that, uh, AI says you should look at the, the question is the signal to noise ratio.
And I'm, I'm sure there's, uh, d different things there, but, um, in general, like I, I, uh, talking about AI and, and my own personal framing of how AI is gonna impact the data world in general is, I like to think, I like to think that history always repeats itself. And so like this whole business intelligence to observability warehouse thing, that's just a repetition of history talking about ai. I like to think of it in terms of manufacturing automation.
And so way back in the day, there was the assembly line with people standing on the assembly line, doing things, putting stuff together. I wasn't there at the time, so I don't, I'm, I, I'm, I'm, uh, perhaps making stuff up. But, uh, there were people on an assembly line doing stuff.
Then we started coming out with robots to kind of automate the assembly line. And I'm sure when that was coming out, it's like, oh man, humans are not gonna have jobs anymore. There's nothing gonna that we're gonna be able to do.
We can't do anything we that all of this. But what has actually happened is the assembly line still exists there. It's more automated.
There's more robots on it. There are supervisors and humans who watch it. There's people who design it and lay it out.
There's people who manage it. But that assembly line still exists. And I liken the assembly line to the data platform no matter what, how, what, no matter what robots you've got, what, no matter what AI you have, it has to interact with some data.
So you need some system that, that has the data. But the other thing that automating the manufacturing has done is by increasing the throughput of one assembly line, it's actually had a ton of knock on effects on the supply chain. Because now you need more materials to get to one location in order to actually populate that assembly line, generate the production, and push everything out.
And to me, I see that, uh, the metaphor over there of AI and AI consuming data is going to be querying the data platforms. It's going to be interacting with the data and the data platforms, but that's gonna have a knock on effect of being able to consume, aggregate, manage, and deal with so much more data that there's gonna be a lot less hurdles to people being like, oh, yeah, but I can't do anything with that data anyway. Nothing can look at it.
No, nobody has time to look at it. And so it's gonna actually increase the pressure and increase the demand for more data coming in, which is going to require the data platforms to really scale out and truly optimize on that unit cost and make it available to the AI agents to, um, to tell you the three things you need to look at that then you look at. And, uh, maybe they're right, maybe they're not, but mm-hmm.
Yeah. Do you Think it will get easier to instrument these applications and all these data sources? 'cause I think we solved the problem of cost, but I'm not quite clear that the, uh, OpenTelemetry agents that are out there are easy to install and maintain just yet.
So what do we need to do there? So my first answer is that my focus is entirely on the data platform and the actual agentry to get it in. I'm like, I'm unop opinionated about it.
I'll take data from anywhere. I don't care. I just wanna store it as in the best way possible.
On the flip side, I think like actually instrumenting things, connecting it, working with agents, um, I don't know. I I, I see it as a bit of a last mile problem. It's always gonna exist.
People are always develop, so like developers are always gonna do new things. There's always gonna be some hot new framework out there that like won't have a thing integrated with it. When you actually get to the content of the data, which is another part.
There's like, can I get the data from point A to point B? But then there's, can I actually understand what the content of it is so that I can make use of it on the other side? And like, especially when it comes to logs, the content of a log line was something a developer just thought that was just like, oh, I'll type this because that means something to me.
Doesn't mean anything to anybody else, who knows? But it's all extremely schemaless. There's like, not any specific schema.
There's usually commonalities between it, but it, it, it's all varied and, and different. And I don't know that like, there's kind of two approaches you can take with this sort of thing. You can try to ratchet things down and provide people strict definitions that they're supposed to fit inside of and, and expect everyone to do that.
But humans don't do that. I don't know, at least I, I've not found it easy to get humans to do that. Um, I, I, I think, uh, humans are much more likely to just kind of go off and do a thing, and then you're left figuring out, okay, you did a thing.
It actually has nice outcomes, but it's not aligned with these other things. So now how do I figure out how to align them and smash them together? And I, I think that's actually the most important thing for the tooling and the, the platforms in this space to focus on is don't try and change people.
Try and make it so that when they go and do things, you can still fit it together and get value. Mm-hmm. You know, I'd love to get your opinion on this, but you know, as far as I can tell, there's gonna be a bunch of AI agents that are trained for different tasks that are gonna be tapping into this observability warehouse for data to figure out what they're gonna recommend.
But at the end of the day, won't they just argue with each other? Like humans do. I, I mean, yes.
But, but their arguments are gonna be extremely positive. They're always gonna start with, you are so smart. That was the greatest idea I've ever heard.
Let, let, let, let me go do, let me go. Yeah, no, I, I don't know. Like, I don't know if you've experienced this, but every time I put something into ai, it tells me I'm the smartest person in the world.
I'm like, wow. It, it took me a while to get over it. At first, I started thinking, oh, I am smart.
But then I was like, no. Yeah. Anyway, who, who, Who, who knew they could program sy offense, right?
Yes, exactly. Oh. Uh, but yeah, I mean, yes.
And it, you can think of us humans as the ultimate ai and in which case, I mean, are, are we gonna produce, is, is an AI gonna be able to, um, exceed what we are? Um, I don't know. Uh, uh, we'll, we'll see.
I think it'll be different, but, um, fundamentally, history always repeats itself. All right, folks, I think you're here. We're gonna have better observability for sure.
And that's a good thing. Exactly. Who's gonna be observing what we don't know yet.
Eric, thanks for being on the show. Yeah, absolutely. Thank you.
All right. And back to you guys in the studio. Hey everyone.
Welcome back to our Predict 20, 26 sessions, or if this is the first session you're watching, it is early in the morning. Welcome to Predict 2026. I'm a Shemel founder of techron, and I'm really happy to have in this session my, my friend and longtime business partner, Mitch Ashley.
Mitch, if you, for those of you who may not be familiar, Mitch is VP and practice lead for the software lifecycle engineering practice area of Futurum Research. Um, if you're not familiar with Mitch, he has a long history in leading software development teams and platforms and, and IT in general, uh, security as well. Mitch, thanks for joining us on this.
Year's Predict, this isn't your first predict, by the way, you've been doing it for years with us here at Techstrong. Uh, it was certainly quite a year in 2025, but as we look at 2026, the best may yet to come. Yeah, I certainly think, I mean, 2025 was amazing.
Just the pace of innovation and maybe took all of us, you know, took a breath away a little bit at, at how fast things were changing. I think we're gonna see that times 10 in 2026. It's, uh, the pace of innovation is gonna continue to accelerate, but it's accelerating in a way that it's kinda moving up the ladder of what we're delivering.
'cause so much of 2025 was about, let me give you this tool or this point solution, or we're addressing this problem with an open source standard, and now we're building more platforms. And we're gonna get into that with some of the predictions here. But I think it's more about how we, how we more holistically, uh, create software leveraging ai.
And not to say every project moves over to ai. It does everything for you. That's certainly not gonna happen.
We're gonna live in a hybrid world, but we'll get into that. So, Absolutely. And, and you know, I wanna make clear that Mitch, your, your session, I mean, your session is kind of a bellwether of all the sessions that we have here, but who, who, who, who should be watching this right now, right?
If you are a developer, a DevOps person, a platform engineer, an SREA security person. But beyond that, even if you are an executive at a vendor who provides tools and there God knows there's enough tools at vendors who provide them in this space, really this is this really aimed at you. This is the kind of real world common sense advice that we're giving you, you know, Mitch is giving you based on, on these projections.
So, Mitch, let, let's dive in. You know, the first big prediction you have up here is that we're gonna see the emergence of a new AI stack as the foundation for development. You can, you can already see elements of this happening, I refer to as this, as AI centered development.
'cause there's so many terms, AI native, um, ai, augmented, Excel, et cetera. But we we're seeing the pieces of it being put in place of what underpins both software engineering and also the applications. And I say software engineering, 'cause developers are very much central to this happening in addition to what we do with no-code, low-code, vibe, coding kinds of activities across this.
But I think the important part of this is that as this stack develops, it's happening not just at the kind of developer layer development tool layer, but it's, it's also happening for automation of tasks of work. And, and we'll get into some of the embedding and continuous aspects of what happens on the platform. I think this is the year where we're gonna see the functional equivalent of whatever Kubernetes is for ai.
And I'm not saying Kubernetes goes away, but whatever the next abstraction that manages and controls Kubernetes refer to it as age and control planes escalation, uh, orchestration, excuse me. Um, some of the scalability components that combine, we have open source projects that are already about helping people put, uh, AI models and agents into Kubernetes clusters. But that abstraction layer, uh, of our infrastructure software that we build software on is really what the vendors are racing to put in place in addition to how developers get access to those tools.
So I think that's a big part of where we'll be at the end of this year, is being able to quantify what that stack looks like. Not that it's finished, not that it's done, but this is the new a AI stack. Fair enough.
You know, Mitch, I, I, uh, I just was starting to get my head around Kubernetes and the whole cloud native stack is the new compute, the new stack. It's amazing that here we are talking about what's next. And, and it's funny 'cause I remember, I don't know if it was probably wasn't last year's predict, but it might have been the predict before then.
So 2024 or 2023. And, and I remember asking our experts and analysts, you know, what do you see on the horizon that displaces Kubernetes? And none of us could see anything on the horizon that displaced Kubernetes.
And, and like you said, I'm not saying Kubernetes is going away either, but we need sort of, I think, what was the word you used? The Kubernetes for ai mm-hmm. Kubernetes equivalent, the functional equivalent of Kubernetes.
What, what is gonna be that helps us scale and, and operate as well as develop, uh, agent-based technologies. We talk about orchestration, we talk about, um, you know, permissions, memory management, lifecycle of agents, policy, governance and controls, all kinds of things like that. Now, we, we have piece parts of that.
We have vendors, AWS, Microsoft, GitHub, others who are, are coming out with these early kind of control planes. They call 'em different things, but that's not the full solu solution either. But you see the collapsing of the development environment and the sandbox environment, at least today, of where you operate these things in.
And we're starting to put the tooling and the underlying fabric underneath that in place. And I think we'll be able to quantify that much better at the end of this year, because that's what we have to have to get AI agent applications into production at scale. So guess what?
The vendors are working on very much this space. I, I agree. Agreed.
Um, you know, and there's a tendency, especially in tech out with the old and with the new, I don't think it necessarily means the death of a lot of the tools and a lot of the processes and kind of patterns that we've developed, but they are gonna have to kinda get with the program. What do you think? It, it's a long time ago.
I've been doing this for a while, as you can tell, but a long time ago I realized, you know what, no technology ever really goes away, right? It's still around somewhere. It's COBAL code or, or Assembler code I wrote way back coming outta school.
It's probably still in production. And these tools will still be around. They'll, they'll very much be there.
But what happens is the next TE technology either abstracts or kind of takes it to the next level of automation. Maybe it's AI brought into it. And that's where we get into AI's not a feature.
AI is a core part of how that operational element works, whether it's CI/CD and whatever the next form of that looks like. Or maybe it's very much the form that is in today, just heavily augmented with, with ai. Uh, we're gonna need to think about how we develop not only AI agent-based software, but we're still gonna do traditional development as well.
So it's not going away. It'll be with us for a long time too. Mitch, all excellent points.
And I, I, you know, I, I think our audience out there can, can take heart in this. Um, if you don't mind, I'd like to move on to the next prediction that you had, uh, talked about, about, and this is rewiring of development job, DNA, right? Rewiring what it means to be a developer, what a developer does.
Tell us kinda your vision here, Mitch. Well, I think the over over exuberance around AI in 2025 led to a lot of predictions of the death of the developer. Not literally, but the developer job.
And, uh, we're sure developing, creating a lot of tools for developers for those jobs are going well, going away. No very much developers are gonna be around for a long time because these are the folks who just, like, they architect and build software today, they're doing it in the next generation on this AI stack. So the, the developer role though is, is gonna be rewired in terms of working with this AI stack and new paradigms, new patterns, new models about how we create software.
So that's why I call it a rewiring of the DNA, it's our DNA, we're just using it in, in a different way. Uh, to me, the developer are, are gonna be expected to be more kind of stronger reasoning domain, understanding experts, contextual judgment. They're, they are the architects and the orchestrators how software gets built.
Maybe they're still editing some code, maybe they're not doing much of that, but they're more orchestrating what agents or they're designing agents to perform tasks. And all these agents are gonna, are gonna get built, uh, by all the vendors. For us, developers are gonna be building agents, just like they built Python scripts for doing CI/CD, even though we have A-C-I-C-D, you know, uh, server that does does the, the load work for us.
So it's really the exp responsibility of the developer to pull all of this together in a systemic way of how software gets built, whether it's partially heavily leveraged on ai, whether it's communicating with traditional teams, um, and, and the, the requirements for that. You see a lot of, uh, requirements led or intent led kind of development. That's, I think a phase of what we're going through, where we're stepping back and saying, Hey, just a, a rolling conversation of prompts to AI to write code for us has a lot of issues.
That's not the best way to write code. We kind of end up in, in backed into corners because of that. Let's be more prescriptive and descriptive about what we want to create.
And a lot of times, that's the hardest part. You can't, you don't know what you want up front. You know, a half of what you want.
And the discovery process is actually part of building software as well. That's why we did things like agile and scrums and, and those kinds of activities because it's an iterative process and that's very much what, uh, the developer role shifts to. But I think we add other elements to it as well.
Things like in the development process, starting to leverage, and I'll talk about this in another prediction. Leverage security and observability governance agent behavior during and throughout the development process into production, rather than those being linear steps that we perform later. I Fair, fair, Mitch.
You know, there's the birds and the bees question here I call it though, which is, you know, where do developers come from, daddy? And, and if, and if, uh, if, if a lot of these tools, new processes, a lot of this AI is kind of taken the place of our juniors and our, you know, newbies and our freshers, if you will, where does the next batch of developers come from to do what the jobs and the roles that you've laid out? Well, uh, entry level folks take heart.
It, those jobs aren't all going away. May be difficult right now because of the over exuberance of 2025 and frankly over rotation on, on telling people we won't need developers or we won't need, need. Junior people right now, more senior developers are, are drastically needed to help define how we're creating software with ai.
Because you have to think about the entire system, not just writing code and, and functionality, but with that become the trades of I need somebody to build these agents for me. I don't have time to build all those agents. I need someone to work with me to help me do that.
I need someone to monitor the guardrails and see, see that they're being applied properly for security or observability. I need to someone to work with me on the next architecture and prototyping some ways we might build this software or, or how we work with our community of users. So my recommendation, and this has actually came down of a, um, a, a Textron gang session that we had.
Kimberly Bates had a great, uh, example use case with someone out of coming outta school, didn't know what to do with their skills in liberal arts and using AI to put together a learning program for you. So maybe you didn't learn how to do agent development or to do AI orchestrated development, use AI to help you build those skills. So you're walking into an interview with that, some of that knowledge and some of that capability.
But guess what, those environments haven't figured it out all either. They're looking for people to come help them and they need generational expertise, both people with experience and people who aren't encumbered by too much experience at times and can think about new ways of think doing things as well. I agree with you.
I mean, look, this might be the greatest learning tool ever, right? And training tool. I, uh, you know, I remember my initial reactions to the worldwide web, you know, the world at your finger tips didn't even begin to capture it, but this is so much more, right?
And, and that, Mitch, that brings up something that I've seen is that a lot of people, especially non-tech people, they're using AI as sort of, let's call it enhanced Google, right? An enhanced Google search. But they're still searching instead of recognizing it as the teacher, as a provider of, I mean, what it can, I mean, it really, it's game changing.
Game changing. I, I think you're, you're dead on and, and kudos to Kimberly. She brought it up, I think it was a graphic audits person who I believe it was, It was working on that and, and, and, you know, more power to you.
But look, this is gonna have impact at the development at throughout the, the, the, uh, software lifecycle development. Mm-hmm. The, you know, software development lifecycle.
Excuse me. Uh, uh, you know, at every stage we're gonna, we're gonna see that in Mitch, if it's okay, I'd like to move on to the next prediction you have here, which was Noval, no vendor lock-in. Like it's imperative.
An cardinal rule. Yeah. It's imperative.
It it is. You know, it was, it's a big theme in, in 2025, and I think it is a, is mandatory in 2026. We're not going through AI innovation where one vendor has really come out with a leapfrog beyond everybody else.
We're not in the, uh, VMware era where suddenly VMware is dominant and and really becomes the thing that everybody uses now, even VMware is adopted, right? Open standards around how it works as well. Uh, you could say the same thing for Docker and the open, open standards for containers.
Everybody realizes that not one vendor has the answer. 'cause this is of a complex problem of, of how we really build these platforms and underlying capabilities that we use AI with. And so these proprietary silos is what people, enterprises are worried about getting locked into.
If I sign up just for, say, Salesforce or Microsoft or AWS or Google or one one company's vision of how this is articulated, I run the risk of, well the, the next innovation I'm not gonna be able to take advantage of because I'm now architected into a proprietary way of doing things of an agent control plane. So the, the, the message to the market, and it's being sent very loud and clear from enterprise customers, but all customers really is we are looking for, just like we went through this evolution with cloud native and microservices and containers. We're looking for open source, we're looking for open standards, we're looking for collaboration and interoperability across vendors, because guess what?
No enterprise work is a sole one vendor company. They run everything because they acquire companies that use different platforms and technologies and it, it is a multi-cloud, multi-vendor world. And that's just the fact of life.
And frankly, vendors that kind of paint themselves into the proprietary capture, the customer walled garden kinds of approaches, I think are gonna struggle with, uh, with, uh, wider broad scope adoption of their technology. People are very much emphasizing, uh, open, it's kind of funny, we were talking about the death of open, open source a year or two ago. What, what's gonna happen with open source?
Is it still gonna be around? I think it's, it's as vibrant and prevalent today as it ever has been. You know, there's another aspect of this too, Mitch and I, I remember now it's what I wanted to bring up earlier, which is, you know, SaaS has become the dominant delivery or or shape of, of delivering developer tools.
I know, excuse me, you know, you don't know this, but in my, in my session with Daniel Newman, Daniel thinks that maybe two thirds of SaaS companies are gonna disappear as a result of ai. Satya no Nadela, who I think some people think may be smarter than Daniel, um, said, I can't comment on that. He's my boss all.
But, uh, Satya also calls her the death of SaaS as we know it, right? Uh, as a result of ai. Um, how does that play into ven tool selection, tool lock-in?
And it's also a segue to our next section, uh, Mitch, which is vendor competition. Mm-hmm. Yeah.
I, I'm always cautious about, um, I don't do predictions about death of things 'cause they rarely truly die, right? Um, you know, SaaS applications was the death of commercial shrink wrap software. Oh no.
We still buy licenses to software, even SaaS applications. Most of them have a, you know, on-premise premises edition for running. 'cause they need to, um, it's just a requirement of the market.
I think, I think more holistically thinking about how software changes. Because part of where I think that prediction comes from is, I remember have the awakening as I worked with more and more AI development tools is like, you know what? I feel like I could probably build just about anything that I want.
Um, now that I've got these tools, right? I don't have to be developing software every to do it every day. Maybe end, end users feel that kind of exuberance as well too.
Is that realistic? Probably not. It definitely isn't.
Not, not in my case, but whether we're ending SaaS, SaaS is a delivery vehicle for, um, low friction delivery for getting products and tools and applications into, uh, people's hands. I think we're gonna be doing that for a long time. It's a, it's the AWS credit card and a browser and now you're in, you're in the cloud.
It's the same thing of I wanna try that development tool. I don't need to install it, download it, and manage it. Um, it's gonna be, maybe it becomes a more of a delivery vehicle.
And then whether you take that and build building into your application or you use it as a SaaS service or a combination of both is where that heads. The next prediction that I have is really the competition for developer Mindshare is really hitting this kind of red line. You think of tachometer, right?
We're getting into that red line zone because vendors at Feverish pitch are going after the developer communities, including vendors that kind of lost their, their passion about serving developers, excuse me, are swinging back and saying, Hey, we have to have an IDE too. I mean, you have companies that, you know, IBM and AWS suddenly having IDs Google. Why?
Because that today is the entre point or the portal, if you will, for development work. That's happening. Why are they going after developers?
Because that's where this next architecture and generation of software is being created. Both how we create software as well as the apps and the agents, et cetera. And they want to capture, mind share, not proprietary lock in.
Sure, they'd love that, but they know that's not what developers are gonna sign up for. Um, but if they're developing on their platform, at least one of the platforms that they're using, they're gonna be using their services, their tool set, um, and part of what comes with it, their cloud in some cases. So I think we're gonna continue to see massive emphasis on the developer community, which I said in the very beginning of this kind of AI wave with generative AI is developers at the tip of the spear for adoption of, of generative ai.
And that's because they are the folks creating the software that uses it in their work. And it's just built into developer DNA experimentation, trying new things, finding ways of doing things better. Um, they're just kind of wired that way as having a big element of discovery and exploration in their, in their psyche.
Mitch, Next up was the IDE shift from coding tools to AI development Control surfaces Loading. Yeah. If you, if you think about ides, one of the things that they've been so beneficial is that they're very pluggable.
They're, they're expandable, um, depending on the IDE that you use, even going back to eclipse, uh, in visual code is, is the most wide, uh, studio, excuse me, is the most widely used, IDE, but there are many others as well. The reason why vendors have lo leapt onto this is because that's a delivery vehicle for getting their capabilities in front of customers and developers. But they also know we have to support other people's models than the ones that we provide as a company.
Other people's tools, in addition to the ones that we provide. But what's happening today is we work doops work in this bimodal surface where the idea is, um, part code and part one or more interactions and natural language interfaces to the, uh, the models and the agents that they're working with in their building. And at some point that starts to gradually slip shift to be more of what the, the interface looks like.
Uh, and less so worrying about it modifying and inspecting code. We'll have agents that we do have agents that are starting to inspect code for us and do code reviews, but as we add more things like, uh, agent control planes and security guardrails, things like that, we need to orchestrate that work. When I talked about the role of the developer shifting to being that systemic view of how work happens to create software, that this is the environment where that happens, whether that's the IDE tool of today, and it evolves into that.
Sometimes you need a new generation of technology to kind of take that next step and, uh, and not carry everything with it that the current ides do. So I don't know that we're certainly not gonna, gonna, going away from ides, but I think the role of what, how they function and how they work, become less of a Swiss army knife and more of a focused on systemic orchestration of how we develop software. Agreed.
Agreed. IDs have certainly seen a, a lot of change over the years. Wanna move next?
DevOps and platform engineering. Two near and dear topics for me. Refactor for high or refactored for hybrid AI centered and traditional Development?
There's a mouthful. Yes. Yes, There is.
So we, we, we are today and we will continue to be living in this kind of bimodal or hybrid world of, we have traditional software development, uh, workflows and tool chains and paths. And maybe they're being augmented by ai. Maybe they're not being heavily touched by ai.
There's some things we're, we're not an aggressive go after changing, but at the same time, we're introducing new ways of doing development, developing agents, new tools, um, platforms, control services, things like that. So I I, I don't see platform engineering being the, you know, the wall of tools in the garage as you go out and say, which, which tool would you like developer today? Yeah.
That, that, that developer portal is part of it. But I think they're key. They're the force multiplier of how do you take the innovations that development test, security operations platform, SRE, any of those roles are finding from AI and make those, uh, accessible, durable to the rest of the organization.
'cause they can be built into the platform or expanded their accessibility to other people. So I think the role shifts, um, more from here's our standard environments to yes, we're doing that, but we're also part of the innovation cycle of moving us towards new ways of developing and figuring out the challenges that we have of sort of the impedance mismatch where, uh, rapid agent or AI based AI centered development software operates at this pace with these, these techniques. And traditional software operates this way.
Where do those cross when they need to cross? And we're doing a, a coordinated to release across applications or software. So that's part of the reality I think we'll be in for a long time.
The folks that I recognize that, the vendors that I identify, that not jumping all the way onto the AI band bandwagon, but to your point, we're gonna have these tools around for a long time. Um, we'll be able to work in this hybrid world and help customers adopt both while they're still doing the jobs they have today. Excellent.
I think this might be the last one. Shift left gives way to continuous guardrails. You know, we have struggled with Shift left, haven't we?
All we've talked about shift Left approach. Well, you know, it's ascended, it's descended, you know, the, the hype, the trial out the other side. I'm not quite sure anymore myself, You know, what is Shift left exactly?
I think, I think the underlying principle was do things earlier so that you kind of prevent security issues or quality issues. Mm-hmm. Or whatever it might be.
And the, the challenge is that our current mode of operating is we think linearly about how software is created. We think developers build stuff. We then send it through a process where it gets scanned and, uh, first it's been checked into, you know, the repository.
Uh, it may also go through, you know, of course, the CI process and then scanned again, et cetera for security vulnerabilities in one case. And because we can apply AI to those tools, whether it's security, observability, uh, governance, agent behavior, things like that, we can now build that into the process of while we're developing it, you know, some of those security vulnerabilities can be taken, taken care of at the point of time that AI is generating the code for us and maybe presenting as code that's already had the head of vulnerability taken out of it at that point. That would be the most desirable effect if we don't get code that has at least some of the vulnerabilities that we experience today.
So the, the guardrails, the important part of this is continuous. And that's where we really achieve a, a huge level of productivity and improvement in security and quality and governance. And I mentioned behavior because of agent behavior, right?
It's not deterministic. So we have to have some way of knowing what it's doing and keeping it on track of where we want it to do, how we want it to do things and not do things. So that's this continuous movement.
Now, you see this in the market already, announcements like, um, when A AWS came out with, um, agent hq, um, and part of the announcement, um, was with an agent for doing DevOps, and you have observability vendors that are part of the announcement, people that are part of the larger software development like cycle recognize, we don't wanna be left out of this. Either we we're gonna have an AI strategy or we're we're heading down our path of it, but part of it is to get into the front end of where this is happening, into the control plane, into the IDE. So it's part of when, uh, developers build agents to construct code from for them or use the LLMs to do that, they access those tools, MCP, right, to your code scanning tool.
Um, or that's a, an agent that reviews code for security or other kinds of issues. Um, meeting, we do prompts today for meeting corporate coding standards, development standards, things like that. So that's being built in and that will make it much more of a continuous process.
So I think the more we stay in a linear stepwise fashion, um, that'll, that'll make it more difficult for vendors who kind of have that mantra and are sticking with it. Um, to get into the AI model of, of how we develop software, we still need point in time scanning, point in time, you know, implementation of some of these technologies. We need observability in, in on operations and production, of course we do.
Um, but it's moving upstream, not kind of one by one, but it's actually jumping into the front end of the development model and following through in the rest of the, the development path. So it's, I'm very optimistic about, you know, what we would call shift left. And I think it's now the model is continuous.
It's, it's happening all the time because it's not just automated, but it's built into the process and the platforms. Well, Mitch, this has certainly been a, a revelation in terms of these predictions. If I had to sum it up, I guess we'd say you don't see much happening in 2026.
I don't know what I'm gonna be talking about this year. You know, I'll have to figure something else out. Maybe, you know, I'll take up knitting or something.
No, I'm just kidding. Yeah. This is The best time to be in our industry.
I love what we're doing. I Agree with you. I agree with you, man.
It's a great time to be alive. Mitch, thanks for joining us in Predict, uh, predict 2026. We hope you've enjoyed this session.
Go check out the rest of our analyst predictions and sessions, including the RSAC analyst talking about cybersecurity and what to expect at RSAC this year. This Alex Hummel, enjoy Predict 2026 everyone. The bleeding edge of AI is a agentic AI and a agentic AI that can learn new skills, grab new skills off the internet, maybe install malware off the internet as a new skill.
Join me on the Tech Field Day podcast as we find out why that might not be a good thing. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about some key concept in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and it's often record an association.
One of one of our events. Tech Field Day is a part of the RUM Group, and this podcast is also published on our sister company Site Techstrong tv. On this episode, Nope, shouldn't hand your AI agents the keys to your whole business or your whole life.
But before we get into the discussion, let's meet who's on the panel today. It's going on, everyone Super excited to be here. Gerard Kalina, uh, I'm the founder of Tech House five seven oh.
I am also a network and security engineer for Aqueduct Technologies. You could find me at G kalina on Twitter, LinkedIn, TikTok, and wherever books are sold. Welcome everybody.
Also happy to be here. Uh, name is re Oliver Cybersecurity Executive former Deputy. So Alliance Life.
Um, you can find me also on LinkedIn, my primary pages, as well as other chat forms across the IT and I security spaces. And I'm Alistair Cook. I'm an event lead here at Tick Field Day, and also one of the co-hosts of the Tick Field Day rundown.
And one of the topics we covered recently on the rundown was Malt bot, or clawed bot, or Claw Bot, or whatever the heck it's called now, which was an awesome AI assistant that could autonomously go out and learn new skills and be helpful in all parts of your life. Only it became very unhelpful when those skills actually were spyware of various sorts, various types of malware ended up on the repository of skills. And very quickly people decided that maybe they didn't want random software taking control of their entire life.
And for me, this sits in a, in a wider context around governance of the pace of governance of AI and ag agentic ai as we try and match the pace of possible innovation by applying the things that are being built for AG agentic ai. And how the heck do we make sure that these new technologies don't end up being a real business risk business danger for us. Um, the malt bot one particularly showed personal risk, but it could absolutely have translated into a, a very large business risk if you've been using these, uh, interesting skills that malt bot would acquire in your own business.
This really does seem like a, a sort of big red flag around how we're approaching using Agent agentic AI and possibly a, a lot of immaturity in our use. I'm gonna just jump right in, don't get me wrong. And I've been like, I've been just sitting on this for a while, so I'm super again, excited to be here.
Talk about it is two parts to this. Number one, I think Claude bot, mbot bot, whatever you wanna call it, whatever name or new adaptation it will be in the next few weeks, months, or years. I think it's a great tool.
I think like everything else AI needs to have, it's such a powerful tool and it can either be leveraged in the appropriate way or not if it gets into wrong hands. The solution itself I think is really cool, right? And it sounds when you say very broadly, like, Hey, you could install this app or install this program and it starts ingesting all of your data, emails, texts, whatever the case may be.
And it'll start helping you in life and make your life easy, the things you're doing, scheduling things, whatever the case may be, that's super cool. But you need to have security perimeters in place. You need to have governance, and you above all else need to really understand it needs to be fully vetted.
And I feel tested because that's just it. Anytime you have any type of baseline code or any type of just a basic text file configuration, there's no perimeters. There's no security.
And as an IT professional, as a security professional doing this for many years and still doing it, it's, it's terrifying because it's super cool, but it's not leveraged and it's not, it's not vetted properly. And because of that, you're deliberately exposing risk, whether you think you are or not. It goes back to the old, you know, don't click on that email.
You could kind of tell what the difference is between a phishing email. And that's why we have third party companies that run phishing campaigns and do these types of things. 'cause some love them, but some end users just, they make those mistakes that's gonna happen.
But something like this is very scary. This is like next level Avengers level threat where it's not just clicking on an email anymore, you're putting your machine or your server or your applicator, your whatever. You're saying, Hey, run this, which I don't know why you'd run something without really fully understanding or vetting it.
Same thing with, hey, this is this command, let's pop it into the command line and run it. That's a no-no. Why would you do that?
Um, so again, the solution itself phenomenal, I think vetted and, and framed and contained properly could be of use just going, you know, freestyle and Wild West in it and, and, and just, Hey, clicking on this and letting it go and letting it talk to all your stuff and then putting it out there publicly, globally. No, that's, it's terrifying. Uh, it's just, we gotta do it better.
That's, that's, that's my 2 cents to start. It's just gotta be done better. Yeah, and I think it, there's a conversation that I often have not only with organizations, but individuals on the topic of agency.
And I think as you begin to look not only at your environment that that, that you work within, there's spaces in which you operate within that could be either on prem, on, on your location, or even at home. Hey, there's places in your house that you don't want your kids in because maybe that's things that maybe shouldn't be appropriate. You need to take the same approach with the information that you're storing and your using to connect to places like this beautiful internet that we have.
And so I think there's a, there's this nice parallel, uh, of making life simplistic, making it more manageable, and then actually introducing new risks that probably doesn't need to be there. I think there's this, and we talk about the FOMO side of things with, with, with ai. And I think there definitely is an element of wanting to be part of the crowd and not wanting to be the last one, you know, to hop on the ship.
That being said, I think there's also an element of risk that also comes into the equation. We've had this thing with open source and somewhere between the first iteration of the Mac and now open source is all of this stuff become the best thing ever. And I think there's a lot of great things that come from open source, but what I'm finding is that we're not doing our due diligence.
And in that absence of that governance, in the absence of just that moment to ask yourself what exactly am I giving this thing agency to agency, we're having critical mistakes that cost us, you know, so much time that I think it just allows us, we need a minute just to kind of reset and understand what are we actually trying to solve with some of the conversations. And, and just to piggyback off that real quick, 'cause you made a great point, Andre, like from what I even read about this not too long ago, there's like 30,000 instances that were just like, Hey, we're just blowing open the doors and here's all of your data. And here, now, from what I also understand, there was two ways to approach this.
Like the LLMs would find open source based projects, or just a ton of different, metaphorically speaking worm holes to start pulling this data in. Now, it's one thing if we're, you know, Joe Schmo and hey, you have, you know, basic emails like your kids' photos, like personal stuff, that's one thing. But what about like, high level executive CISOs, people who are like, Hey, go ahead and start talking all my stuff.
What if there's PDFs, blueprints, you know, NDA classified documents? Like that's when it starts getting even more terrifying. And it goes back to, it doesn't matter where you're at, if you're, you know, just a dad, multiple kids, or you're, you know, a senior vice president running a high level operation or a small medium, very large enterprise business, you're just telling it to talk to your stuff, pull in that data.
There's a ton of, of, of, of, of, of, what's the word I'm looking for? There's a ton of, uh, there's just a ton of open polls and points and vulnerability areas of weakness to just penetrate and take this data. So again, it's just, it's, we gotta be better, right?
Like I, you know, there's gotta be some type of governance or some type of, uh, you know, high level group of technical analysts, specialists who can really leverage. Like, and I think that should be for all ai ai I think instead of just having the tool, right? Like it started with chat GPT and we're having fun, we're making images, but now it's evolved and it's grown into something so much more.
So we need to have a better way to control it. That's, that's gotta happen. And I think this is, this is not new.
Let, let's be very clear. When docker containers were new, you'd pull something from Docker hub with no idea what was within it. And the resolution wasn't that the end customer went and validated every single container that they actually pulled.
It was that governance was built into the container repositories. And so there'd be a knowledge of who was releasing this content. Is this trustworthy content or is this, um, less trustworthy?
And, you know, there's a continuum in trust and there's also a continuum in business risk. And it's that crossover point in finding where your business fits for this use case and this level of risk. But there was no governance at all in the skills that mbot could acquire.
And worse than that, it was just a description of how to acquire is what was being stored. And so it was a lot of them, it was just go and pull this script from this website and pipe it into your script interpreter and just randomly install software. And although you could tell Malt bot don't do that for me, let me go and do the governance for it and check on those things, that's not what customers ended up doing.
And in the same way that as they're using things like, uh, coding assistance, uh, some of these coding assistance, there's, there's literally a switch of yolo. Uh, you know, I'm prepared to take all of the risks there are in order for you to take all the work off me. Um, that kind of both the education of people to not take all of those risks on, particularly inside a business context, but also the need for the governance to actually take away the possibility of those risks occur.
And apart, I can see for the, uh, the chap who developed the Claude bot, whatever we're calling it, uh, it is towards actually offering a managed service of a governed set of skills that are absolutely certain and not, or not documented. This is the information that we'll wanna access. This is the, uh, components that are being deployed out.
This is the risk that you're taking when you're using it. Having that explicit governance, I can absolutely then see the stage where this is a product that I use in enterprise organizations where you wrap a lot of governance around it, right? Because as you say, when it's just my, me at home with my personal emails, there's, there's a risk, there's a risk to around particularly identity theft.
But when it's the, uh, the the sort of core of my large enterprise business, uh, particularly if I'm an executive, then yeah, there's a much greater, uh, risk of damage with these things. And so there's more value in that governance. There's One thing I wanted to add too, again, just, just learning about this, and I don't remember.
So with the, with the Claude bottom mold, but with the installer, and there was a, a GitHub repository there was that, I wish I remember the, the exact file, and they, normally I do, and he says this, so I apologize, but it was like GitHub, whatever, whatever was built into it, to, how do I put it, was almost not like full governance, but when you do run the installer and or if you do pull this directly from GitHub, it would block specific file types and paths using like hash values, so it wouldn't just pull all your stuff. And I don't know who or what somebody removed it outta the repository, so that's why it gives you like, just full open access to just get whatever you want. There was like almost an essence, like a safeguard built into it.
Um, and, and it's like somebody took it out. It's like, why? You know, like that's a whole other question for a whole other, but why, because like me, the, the actual executable, or the installer, I'm not sure, but the GitHub had a, had a safeguard there, so it's like, hey, this is automatically gonna run when you start pulling from the repo and it's gonna let you pull like pictures this, that, the third, but it's not gonna touch, you know, whatever.
But somebody took, took it out and they're just like, no, it's just gotta let it have access to everything. Like, so I know, while it's not full blown governance, but it was some type of, you know, like preventer in place and somebody just said, nah, we don't need it. I, I that I'm interested and, and I'm very curious as to why that was taken out.
Yeah. That I, I think the biggest thing when we think about this space that we, in that we're in right now, and I think also you brought it up before, I mean, when you were doing docker containers, you know, way back when we first started this, there was a, the, the barrier to entry was pretty high. You had to be somewhat technical.
You had to know kind of how to, how to operate within the space. And I think what we're seeing right now in AI is the bar is really low. They make it fairly easy for you to get in, to get going to, to, to obviously to to be, you know, really viable in the space very quickly.
And I think that's intentional, right? Because we need adoption for AI for a multitude of different reasons. Ask any vendor, right?
AI is sprinkled on it in some way, shape, or form. And so I think driving that adoption with the broader community allows the vendors to have a better place in society, which allows 'em to sell more product, which is a good thing. And there's a good and bad with that.
But I think at the same time, we, we have to remember that threat actors are also using the same avenues to further their, to further their ventures as well. And so I think the governance piece is big, but I think now, if we're going to allow this level of access, allow this level of, um, what I would say in control into environments as users, generally speaking, we gotta up the bar for understanding what security, and I know oftentimes we call the the team of no, right? But I think collectively, this is the space that we're gonna operate in.
We at least have to be maybe the, the team of, maybe I have a question versus just downloading. I think that's that thing that's gotta switch now with us as we begin to connect all these currently disconnected systems into our business processes and applications To finish up. Just test, you know, like it's pretty common anytime, like when Docker containers were first released, right?
Like, it's a pretty exciting way to transport apps information and data. But again, like everything else, the attackers and nine times outta 10 get ahold of it, first start ripping it apart, and they start figuring out how the hell can we exploit this and how can we take advantage? And then they've already got a few, you know, steps ahead.
I just feel like, not saying that our teams aren't currently doing this in, you know, the countries, but I just feel like maybe if we can just somehow some way get a better track record of getting ahead of it, right? Like, this tool is great, but let's really kind of spend a few days, spend a few weeks just ripping it apart, looking at it from both sides, looking how to actually, you know, pen test it, looking to see if we could break it, where are the vulnerability points, where is this that before releasing it to the general public, but it's like you guys said, it's just, it's getting released, everybody's clicking it, and then they're just, Hey, you know, like it's the wild west and we're just doing all these things and we're not really thinking long term. And what those consequences could be.
I, I think there's a combined thing in there that you've, you've both hit. One is ease of access to it. So, uh, being able to very quickly deploy just a sort of skeleton and say, go and do things for me, that's a desirable thing.
That's something that is, is really positive in what we're seeing. I think that's, um, just ease of access and that a normal person, not, probably not your, you know, my father-in-law at this stage, but you know, somebody who, who is not an IT specialist is getting their hands on these things quickly because they're well publicized and they're easy to get into. And I think that's where it starts to fall down, right?
Because if it was any one of the three of us deploying this thing, we'd be looking at it fairly closely. We'd be deploying it inside an isolated environment for our initial testing. We'd be giving it limited access to a very strictly controlled set of data.
Even if we did then let it go wild with installing its own skills, we would be much slower to, to trust it with everything. But I think all of the hype that we've seen with, uh, chat, GPT and all of the, uh, generative AI tools, generating images, generating songs, we think as, as normal consumers think that AI is the solution to ev every problem. And that AI is very trustworthy.
We from the inside of the industry are quite the opposite of being concerned about it, about this, this whole idea of agent AI taking autonomous action. This is one of the things that I saw at AI infrastructure fields, that whenever people were talking about agents, they often were talking about guidance for a human who's gonna take action rather than fully autonomous action. And we definitely had conversations about building trust before you'd ever wanna have autonomous action.
Yet typical end user doesn't care about that. They wants, they wants the action real fast. Fire fire on all cylinders and like, it's just, it's just like beating the dead horse.
It's just, it's, it sucks because again, it is so cool. And I understand, and that's the cool thing. Now, 2026 is AI and leveraging agent AI and all these different solutions.
It's baked into everything at every turn and corner you're going. But again, it goes back to the fundamentals, like working on the help desk. Like, it doesn't matter how far I can go back in my career, like, don't click on this, don't just, you know what I mean, having it in, like you said, also having it in a controlled environment.
How can you mess around with something if you don't understand it? That's all, that's all it is. And the human element of it, it's like we say it with love, but the layer eight issue, right?
Like, oh, we're just gonna click on it and, oh, what's this? Let's throw it on here, let's throw it on our main data, let's throw it on our, you know, our dc It's like, no. Like, no, but you know, so is, so is the cool kid, which is ai.
So, Yeah, and I think, listen, a lot of this is driven by social media influencers and, and I, and I make the designation because they're not first and foremost thinking about the things that we're talking about right now, right? You can go and watch any video, any, any podcast on how to do the next cool thing, right? The reality is that human in the loop is not sexy, right?
It's kind of, it actually, it doesn't, it doesn't make for clicks, right? But if I can automate this process that kicks off five different things, starts my email and, and, and, and orders being uber, right? That's the next best thing that is that wow factor that we're seeking or question the challenges of what's happening behind the wow factor.
It's the uhoh factor, right? And so when we find out those things and have to have those conversations or understanding, I think we're having some of those challenges. And then it's, you know, I I I go back and forth and it's, you know, comment thing, comment people, you know, even with your kids these days, right?
The idea of, of the work to get the outcome right, is it's too much effort. I just want it to be there. I just want it to happen like it should, right?
And that's kind of the space that we're operating in, and that's this kind of demon that we're dealing with. And so I think there's this nice, um, common ground that we can gain as professionals to say, Hey, there, there's a subset of things that I think makes sense for us to automate, but as I'm talking with any person, any, any organization, my question is, well, and you've heard before, what are we trying to solve for? Right?
And I think most oftentimes it's the absence of that, that outcome, the absence of that objective that allows us to have a minute to reassess and go through the process. But when you're just clicking and you're just adding for the purpose of doing it, there's no guardrails. There's very little incentive to think about the risk, the outcomes, the other things.
And that, I think is where the, the, the gotcha is for us in this space. So I wanna bring up a completely sort of different perspective on this, in that this is the first really big consumer, you know, influencer led, story led that has brought up AI security. Now within the industry, we've talked about AI security, looking after you data, those kinds of things.
But again, somebody walking down the street, listening to the news may have heard some of this, may have heard the, the hy about malt bot then that, that terror at what the skills were doing. And I think this is leading us to a, a really good beginning conversation to have those conversations that we know need to happen around how do you manage this? How do you do this securely?
Who am I gonna trust as I'm starting to use just foundationally trust is underneath all of this, who can I trust to do these automated things for me? I think that's a, it's really good that we've got this very public failure that is leading us to have, having a mature conversation that I think all of the providers who are doing enterprise work have already been having, uh, hopefully this is driving other conversations. Are we, are you all seeing other conversations that are outside of the industry, outside of the insiders talking to one another about security and ai?
I mean, right now it's, it's always been, especially like within my organization, right? Like that's still a hot topic because it's always gonna be the way, it's the way of the future. You know, like we are finding ways to better, you know, not only assist our clients and further bettering and heightening like the level of security and services we offer, implementing that across all their data and platforms and such.
But yes, you know, how can we leverage tools and ai? Like, that's why I love that we have like a dedicated little like dev dev team to just work on that. You know, if I get the chance, I get to dabble in it a little bit, it's really amazing to see, like we're making forward progress on it.
But again, it's not one of those things, we're just trying to slam a solution. You know, we're not trying to, we're not trying to slam, you know, the square, you know, wooden thing into the circle peg and make it work. Like it's not gonna work.
Like we have to properly vet it, you know? And it's just like with, with that solution and everything else, it gives us time to really hash it out, vet it, see where it works, how does it fit the, the model and more so how does it fit the business needs? Like what's the goal, what's the outcome, like you said, right?
Andre? Like, like, what, what are we trying to achieve? Because there has to be a thing or multiple things that you're trying to achieve when leveraging this.
And I think, I think, I don't wanna say half, maybe a little more, a little less. Like some people see it that way. We have, you know, technical professionals, non-technical professionals.
I think we're just still at that, that precipice of like, oh, this is cool. Like, I don't care. I just, like you said, if it could turn out my coffee baker start my car and do this, like, that's awesome.
But because they're not security professionals, and I'm not saying you need to be a 20 year it vet, like you just need to kind of take a second and like stop breathing. Like, okay, this is cool, but what's happening on the other side? And I think people are just like, I want my life to be easy.
I want my day to day be, I want how I, you know, leverage these solution easy and that's it. All of the other problems are gonna just filter their way out. And, you know, fortunately that's what me and Andrew, that's what we're here for, you know, because we're the ones who are gonna be like, Hey, I had this problem, how come no one told me about this?
And it's just like, you know, back to square one. So I, I think it's really cool, like where we're seeing it, but I still think there's that, that, that halfway or so point of people who are like really trying to be smart, you know, both technical and not technical about how we're vetting, um, AI and how we're, you know, using, leveraging it in our solutions day to day. And then I just think there's the other half that's just like, nah, I don't care.
You know, they wanna be the cool kids in school and they, they're gonna use it, and that's that. And, you know, they, they'll worry about the problems later on. So Yeah, I really try to simplify it even more, right?
Because we, the AI means a lot of different things to a lot of different people because there, there's different flavors of it. I, I try to take it back even simpler to talk about just the data, because this is, it's, it's less of an AI problem and more of a data problem, right? And so if we can have a conversation about what you feel is important to you, what you feel is critical to you, and what are you okay with it just getting out there if it happens to get out, if I can get them to, to take that mindset of things saying, this is absolute cannot get to the internet.
I don't care if this gets here, this is okay, regardless of what happens with the model, we can have some level of governance over what goes out. But just having them take a step back to say, what's critical, what, what's deemed to know and what 100% can never get to the internet. It allows them to have that frame of reference.
Because I think trying to explain AI to the common user above and beyond, Hey, you can turn a thermostat off or you, it's gonna be kind of an exercise of utility, but if I can say, Hey, listen, your daughter social security card number, graduation date, et cetera, and this information of data, are you good with that being out that resonates? And then I can get them to lock on the things that are important, and I can say, maybe this piece is important, but maybe you should keep these things kind of at bay. And so trying to bring them along slowly, we're never going to be able to catch up.
And I was, I love the way you said, right? If we get them to maybe test, if we can maybe get them to do the app test, we've been having that same conversation for 20 years, and Lord knows, if we're not gonna do it, they're definitely not gonna do it. So I'm not even gonna start that conversation.
But what I will say is, you, we, we don't air our dirty laundry in Publi for a reason, right? Okay. Let's take that same approach using AI and, and actually making the benefits of that work for us.
And if you can do that in a way that's consistent or okay, you right. I think believe, believe as we get further along and we build more into this and we find more commercially available systems, and I say commercially available because the support comes with that, the reputation comes with that, and traditionally speaking, then we build the controls as part of the process. Because as consumers, we demand that of the vendors.
And I think we can find a better way to kind of, you know, I think marry the two. But until then, it is definitely, um, you know, you get what you pay for. And I, that's what I always say about open source, get what you pay for.
So know that going into the battle. Yeah, I think o overall, this has highlighted for us that, uh, consumers of these tools want something to be simple. They don't want to have to think too much.
Uh, there should be safe and secure defaults rather than wide open defaults. And it should be hard to turn those off. Uh, there should be governance somewhere in these platforms.
There has to be for these things to be usable long term. But the reality is that, uh, consumers in particular, and, and some parts of enterprise are gonna want things before they're ready. They're gonna want things immediately because that drives business differentiation.
And the risk is always balancing that business differentiation, that business benefit against the business risk if things go completely sideways. And all of our data goes floating out all over the internet, both personal data and company data. Now, we as usual could spend a long time talking about this.
And if, uh, you are a delegated attending a Tech Field Day event, you will, uh, recognize these kinds of conversations as the ones that we have when we're not actually in the presentations at Tick Field Day events. Um, but I've gotta thank you as our, our listeners of the Tick Field Day podcast for joining us today, uh, on this, this episode. Uh, but before we go, if you wanna catch up with you and continue this conversation, where can they find you all?
Like I said, you could find me, everyone at g Catalinas on Twitter, LinkedIn. I'm on TikTok. I make short long form content.
You name it, I do it, uh, wherever books are sold, but I'm always around, especially on social media. So just reach out, say hello, blessed to be a fellow tech, tech field day delegate. So I've done a few events, hopefully some more coming up soon, we'll see.
And, uh, but yeah, love to continue this conversation anywhere. So follow me across all the platforms. Uh, probably not as much on tech field.
I mean, not as much on social media. I, I I tend to do more on LinkedIn, getting more involved with Tech Field. So I need you all on LinkedIn.
Um, getting, hopefully, again, getting more involved with tech field things, but also commonly speaking in the community. So most times when you find cybersecurity, you'll find me somewhere in the conversation. And of course, I'm Alistair Cook, you can find me on LinkedIn as Alistair Cook.
Uh, you can find me across all the various types of social media and on the fragmented spaces. Uh, and you can find me on various Tech Field Day and Futureum Group properties around. Uh, so thank you so much for listening to this episode of the Tech Field Day podcast.
Enjoyed this discussion and would like to hear, listen to some more of these discussions. Please subscribe on YouTube or your favorite podcast applications. Say, don't miss a single episode.
Give us a rating as well, preferably a positive one and a nice review that helps other people find these great conversations. This podcast was brought to you by Tech Field Day, the home of IT experts from across the enterprise and a part of the for More episode podcast, or view us on tech. Hi everyone, my name's Kurt Kine.
Uh, I am senior director of AI marketing for Hammer Space. Um, and joining me on the call today, Sam, if you wanna introduce yourself. Good morning, Sam Newham, I, uh, run our AI solutions practice here at haer Space.
We appreciate the time today. Yeah, really excited to be here with everyone here in the room and online as well. Um, here's a brief agenda.
Uh, so I'll be going over a quick recap of just what is Hammer Space, what is the hammer space and what is Hammer space, um, and how we do what we do, because it really takes a little bit of time to understand how we're differentiated from the typical storage company out there. Um, we see ourselves much more as a data company. And so, um, it's an important difference, especially with today's workload demands and, um, infrastructure setups.
Uh, then I'll kick it over to Sam and he'll be covering our Nvidia AI data platform integration and why that extends what Hammer Space does into a whole new arena for folks who are deploying AI factories, um, and are looking to go from data chaos to AI ready data. And then finally, um, I will give an update on the open flash platform. Uh, we talked to the delegates at a previous field day, um, about OFP and the initiative behind that.
And we want to give you an update on practice in rare for a software company like Hammer Space. I'll even have some hardware to feely touchy. Yeah, it's exciting.
Uh, and I'll be joined by, um, two folks, uh, Ted and John from Hammer Space to talk about why they're a key part of the initiative and our, uh, first reference design. Alright, so, uh, the hammer space, probably not so much for the people in the room, maybe a few people in the room haven't gotten this, uh, background before, but what is a hammer space, right? And it is that infinite space that you see in an animated show where somebody's carrying a bag and then they maybe pick, pull a giant hammer out of nowhere, right?
It's this instantly accessible virtual space that is infinite in size. And so that's a pretty good analogy for what we do for our customers, right? We disaggregate the data from the underlying infrastructure and allow that data to be in any location, in any cloud, on any infrastructure backend, and eliminate the silos that are so common in today's enterprises.
And we accelerate pipelines by a aggregating the metadata that is attached to all of that data across the data state, making, you know, the infrastructure more valuable because we can continue to use whatever data you have in place and continue to use those systems, but then also rapidly deploy newer, cheaper, faster technology, integrate those really easily into your environments. And with AI being such a big part of where we're generating data today, um, you know, the need for this massive repository that sits across, um, locations, clouds, and um, systems is really, really key. So a little bit of, you know, background on ai, right?
I don't think this is a question too much anymore. Um, but I think we often focus as vendors on our really cool system, right? And we don't focus so much, especially in the storage space on just how are people dealing with their data, right?
And AI has really driven us as storage players to think differently, and we're not alone in that, um, at Hammer space. But, you know, really going from where we were just serving files out, serving objects out into being able to serve something that's really useful for these AI applications, right? We're not just repositories anymore.
Now we are really, you know, full data management systems. And what Hammer space does is go beyond the systems view, right? And we want to give people visibility into all of their data, not just the data sitting on one system.
We want to be able to give people access to all the data across locations, give people access to all the data and visibility across their clouds. And we need to be able to automate those data pipelines to provide AI ready data, not just raw data out the front end. And we need to be able to do that in real time.
And so I've covered these problem areas, but I'll, I'll dive into each of them a little bit more, right? So storage folks have been deploying systems for all sorts of rational reasons all over the place, right? And each system might have a unique characteristic, right?
You might deploy object storage over here because you have this data repository that you know is gonna grow and you don't want it to, you know, have onerous overhead. Uh, you want it to be easy to deploy, scale out. Then you have NAS systems that are scale up maybe over on another side because you had more, uh, enterprise, you know, for requirements for data protection, um, and things like that.
And you wanted it easy to share and easy to access for folks, um, that didn't know anything about S3. Uh, then you right, started deploying pieces in the cloud because there was this infinite bucket in the cloud that allowed you to ship data up there. But each of those new systems introduce complexity, additional data management overhead, um, you know, all the things that comes along with distributed data.
Um, similarly, all you stand up a western region, uh, you've got another office in East coast, you've got another office in Europe, another office in Asia. All of these disconnected sites and need to be able to collaborate, especially now that we're applying AI applications to be able to gain better insights into, you know, everything that's spread out across the globe. So how do you unify that without massive migrations and multiple copies spread all over the place?
Additionally, we encounter more and more customers, yes. Ese Silverton Consulting. Um, you mentioned that you disaggregate data, but you aggregate metadata.
You want kind of, I will go, I will dive deeper into that for sure. Okay. Um, but essentially, right, that is hammer space's superpower, right?
So we assimilate the metadata from the underlying storage system, whether it's an object storage or NAS system, um, from other system vendors out there. And then we have metadata servers that sit outside the data path that manage all of the data across those systems and aggregate it into a single global namespace. And then we can have data writing to those systems.
So you can leave the data in place, or you can move the data based on where it needs to be, when it needs to be there. Um, and you can continue to utilize that underlying system under hammer spaces ownership. That assimilation process happens instantaneously, or, Uh, it's of course not instantaneously.
It's, it's a days, it's a days versus month thing. So when you look at, you know, what is a typical system vendor gonna come in and tell you is, you know, what, how are we gonna solve this problem? Well, we have the best system, we have the best new silo that's gonna solve all your silo problems.
So this deploy our system, migrate all your data into our system, and then you have a single global namespace. Instead, we say, leave all your data in place until you need to move it. So yes, there are cases where you're gonna have to move your data and that's, you know, physics, but you don't have to move it all instantaneously.
So that's a nice thing that when Hammer space comes in, you know, we're talking days to be able to stand up a global namespace as opposed to a gigantic migration process into our system. And so you get access to this global namespace really, really quickly. And I talk about that a little bit later in a couple of customer use cases too.
Okay. Um, so yeah, too many storage systems to manage too many things out there. Um, none of them meet all the needs, right?
I mean, as we're approaching, um, you know, infrastructure modernization, I think what is everybody trying to get to? And that's a single converged infrastructure. You need to be able to serve S3, you need to be able to serve, um, a parallel file system.
And then also, you know, N-F-S-S-M-B-C-S-I, um, MCP, all of these things need to come from a single system and we do all of that natively. And then we're very, very cloud friendly. We were built a software with a cloud first mentality so that to be able to, rather than viewing cloud as a destination where you just spill bits out and then hope that you never need to bring 'em back because that's a really expensive pri process, you know, use the cloud as an extension of your on-prem infrastructure, right?
And that speaks to, you know, the whole first to cloud type of, um, activity. And we can really help customers with an on-ramp to hybrid cloud settings. And then finally, data management across systems has often been another new tool that you need to bring in.
And so instead, you know, we bring data management into the storage layer and help people automate that via orchestration. And I'll go into that here in just a second. Is Marian Newsom?
I have a quick question. Yeah. So you talked about aggregating the data from the metadata.
How do you detect the drift if there's any between those two? Um, I will kick that one over to Sam, Sam if you're available for quick. Yeah.
The, the idea is to prevent data drift, right? It's one of the most poisonous things that happens in ai. So by owning the metadata, right, by separating that particular thing, we synchronize those changes real time right?
Across our global namespace. And so we don't have some of that acknowledgement wait for this to write type situation. And that's part of our secret sauce is, is how we can resolve some of those discrepancies in multi writer situations and those types of things as well.
But our system was tuned to deal with this first studio in the sky where we're doing multi editing, right? Where we're doing AI pipelines where data needs to live in multiple places, but stay and think. And so the beauty of that is that by separating metadata, we know those changes can happen instantaneously while we deal with the payload of those files moving to those geographic locations.
So we can actually do, say a LS on both sides of the world, see everything perfectly, but the data may still be in transit from a physical standpoint. Thank you. So one other emerging problem that we've got in real time, um, is dealing with flash memory, right?
And there's currently a pretty tight market for flash memory, whereas maybe a year ago storage vendors were out there saying, oh, disc is dead. Well, now that nobody can actually buy flash or flash is going up to X in price because of this really tight market, um, we've got issues, right? And so if you can't even acquire new flash, but you still need high performance storage, what do you do?
Right? Um, and you know, there's all sorts of, um, ways that the system vendors are going about this. You know, let's go out and do a buyback program so we can get some more flash in and then resell that to other customers.
Um, you know, I I think it's a pretty, I don't wanna make light of the situation 'cause it's a pretty dire situation for, um, customers who really, really need that capacity. Um, but you know, our view is that there is actually underutilized flash storage probably out there in many environments, right? You've stood up these multiple systems, they're all disconnected, they have an application running on system one, you have application B running on system two, application C, and all of those consumption patterns are not the same.
So if you can aggregate those systems and use orchestration to make sure the right data is sitting on the right tier of storage, then you can free up some flash space within your environment. You can make sure you're utilizing all of that flash space that it's already sitting there. Um, within the systems you have, we also have the capability, and we talked about it at the last, um, field day presentation, uh, a relatively new one that's, uh, was introduced about eight months ago, and that's tier zero.
So that's the ability to consume the flash that's within the compute cluster, CPU and GPU clusters and aggregate that within our namespace. And so we set that up as a tier zero. It's a high, extra high performance tier because you eliminate all of the network latency.
And that's sit, that's the flash that's sitting in the GPU and CPU servers and we can incorporate that as part of the namespace and use, utilize that as a tier of very, very high performance storage. And if you look at, um, most of the GPU and CPU clusters out there, they do have underutilized local flash storage that we can access and add to the global data file system. And then finally, I mentioned this already, um, but treat cloud as an extension of the infrastructure, not a destination.
So, right. The cloud vendors have pretty good allocations of flash storage, but they aren't running into just availability problems. Now, probably not cheap, but at least you have access to that cloud instance, and you can treat that as an extension of your namespace that's both on-prem and in the cloud.
So how do we do it? So you can deploy hammer space, it's software defined. Um, we do have reference architectures and look for more news coming soon on other ways to deploy hammer space.
Um, but we can deploy on virtually any server in front of any storage, including local NVME as well as anywhere, right? Within an environment. So data in place assimilation here was Ray's question, right?
So data stays in place And we assimilate the metadata into our anvil server. I'll have a little diagram of that here soon. And data is visible to users within minutes, right?
So again, we're not doing an onerous long-term migration pro process. We're assimilating that data in place and then users see everything that they're authorized to use. And from there, we provide a parallel file system access to a cluster or standard S3 N-F-S-S-M-B access, um, to other clients that are, you know, heterogeneous within the environment.
And so we can accelerate data that has been sitting on legacy file systems or object storage that's not tuned for high performance workloads that the GPUs demand, while also managing all of that storage underneath. And then finally, right? I think the most important point here, and the thing that we are going to exploit when we talk about, um, the A IDP integration with Nvidia is all of the automated orchestration that we can do underneath the scenes, right?
So, as Sam mentioned, we can move data right across locations, between systems, even doing so while it's being written to, and, um, we can set up policies based on, you know, normal business language that allow people to tier their storage as necessary based on their individual requirements. Hey, Kurt, it's Ray Lui, Silverton Consulting, you mentioned earlier, MCP. Do you provide, um, MCP server for agents to be able to move the data based on where they think they might need it, things of that nature?
We do. And so, Sam, that's exactly what Sam's gonna be talking about with our A IDP, um, solution. So that's where it really turns into something truly, I think, mind blowing, where you go from this really, you know, complicated management schema and, you know, none of this is easy, right?
I don't wanna make it sound like, you know, under the covers everything is super seamless, right? But we go from something that, you know, takes some storage management and storage intuition and experience and are able to turn it into va basically a, a system that can interact with you via natural language. So we'll talk about that a little bit.
So, um, here are the building blocks, right, of the hammer space deployment. So you've got the metadata control plane with the anvil servers, and then essentially the data service nodes. And those are the things that provide file access as well as do the data movement.
And so we can use PNFS, right? 2, which is integrated into every current Linux version that's out there today for folks to do high performance parallel file system access to the data within a hammer space namespace as well, again, as your standard multi-protocol file and object access for folks who are doing heterogeneous clients, you know, for all sorts of, I have a Little bit about how you've clustered these various different types of nodes as well. I mean, I, I assume that you have some way of clustering them so they, there's redundancy and, um, you know, Yeah, Sam, you wanna Remote availability.
Yeah, exactly. There, there's ha and durability, right? Built into the architecture of these platforms.
And so part of this thing kind of like a, a ring architecture, right? And so part of those anvils will live in each side, right? Controlling local metadata and the storages there and those, you know, and then replicated it in other areas in those particular sites, right?
And so that's kind of how Kerr talked about how we do this out of band, right? 999 however far we get in that particular architecture, right? Like most systems are always a trade off between, you know, how transients that data, how much do we care, where do we want to do, especially with cloud resources, but our architecture is fully redundant a across the entire platform, I guess, you know, follow on to Andy's question.
Um, so the redundancy, so some storage systems have redundancy built in, some do not. Um, you're talking, I assume about the anvil metadata being redundant. I understand how that would be completely under your control.
But let's say I have some, some dumb server storage and I want to have some sort of, uh, high availability for that. Do you provide, uh, i i I guess I'd call it external rate across. Yeah.
So we do erasure coding across those stor. We can do it across storage systems, right? To provide redundancy Okay.
For the data. Yeah. The, the other point real quick is that all this is done via policy and orchestration.
So by share, right? So not even by storage box, right? But by share by data type, we can choose to keep multiple copies of that data spread across different geographic locations or to Kurtz point, whether it's era coded or whether it's stored locally across a handful of servers.
So we've got a lot of flexibility in how we do that very granular, right? So it doesn't even have to be a master policy. We can do that specific to projects specific to shares or specific to organizations.
Yeah. I, my question was more speci specifically how you handled the cluster of your, your metadata nodes and you know, the, I I think that you answered it adequately that, um, you know, there's, they're fully resilient. You, you, um, if you lose any one of them, you still find, Correct.
Yeah. They're, today, they're in an H eight care. We're changing that to be fully containerized and scale out.
So we'll be able to add performance as we add containers. Um, same with the DSX, right? Those data movers and some of those components, right?
We can scale those today. In fact, we already have some customers that are doing early access in that containerized format. But today it's ha But to your point, that's fully replicated across our environment.
Marian Newsom, I have a question. How do you prevent, uh, privileged access on those different sets of data? I'm sorry, can you say that again?
How do you prevent, how do you keep the privilege access the same across those different sets of data like the US three? No, exactly. So, so this is kind of the beauty of a single namespace, right?
Is that right now those are all managed silos, right? We see people sometimes do direct permissions into an individual NAS active directory, those sorts of things. By actually tying those directory systems into our platform, we a inherit those default permissions, right?
So that's part of understanding the POS landscape perfectly. So we can pull those particular things in. But, and I'll talk about this in my section a little bit, but the beauty is what we're, we're aiming for, right?
Is that security, is it tied now to where data's born that that security can now follow that data? And that's the beauty of separating the metadata from the storage itself, is that now those permissions can follow that data whether they live in the cloud, live on a different storage platform, et cetera. And so we move that security plane into our metadata, global namespace realm.
And so if I'm a, a company with cross-border data, uh, concerns or AI regulations, uh, that's what that solution will provide Exactly. We can set up all sorts of policies, whether it's GPR to prevent things cross country, whether it's certain patent information, we can do some custom metadata tagging. In fact, we're actually doing some integration with some, some digital security posture management companies and stuff as well, right?
To te even our file system attributes well beyond that to be able to really control at a granular level what data should or should not live in certain places. Am I ever audited? Could I ever see the launch to that?
I'm sorry If I get audits, can I pull the logs from my regulators? Correct. Yeah.
The, the whole thing is fully audited, right? Where files have moved, who's access to everything, that entire premise is built into our solution. Thank you.
And I think there was an important point, um, that, you know, uh, Sam made there that maybe have been lost and I hadn't mentioned yet. And that is, we definitely go well beyond a storage system in terms of the amount and the type of metadata that you can attach, um, to any object within our, um, global namespace. So that allows you to take additional steps, right, based on business rules to be able to interact with that metadata.
So it's not just, you know, your posix metadata of file create and permissions and things like that, but you can attach other attributes onto that data, which again, becomes important when you get to managing a system for ai. Um, I'm gonna go through this quickly here, um, just so we can jump over to you, um, the next section. But, um, I want to talk a little bit about how our customers are using Hammer space today.
Um, here's an example of a large digital payments company. Um, and they had a team of about 3000 data scientists and research engineers who are building AI applications. And they were looking to move off of their fairly expensive up for renewal n systems, and they wanted to deploy object storage, cheap and deep storage, you know, cheap and wide storage, I guess, um, for their data scientists.
And they started this process and then figured out that, oh, our data scientists don't speak S3, they speak NFS, you know, so what do we do here? Right? And, you know, there's systems that you can put a, um, bridge in front of an object storage, you know, those are integrated to more or less extent, but typically don't provide you very good performance when you're accessing that object storage through some kind of gateway, but instead with hammer space, right?
We can put that in front of the object storage, still take advantage of that scale out architecture, but now provide parallel file system access or a cluster as well as all of the other, um, access protocols natively, right? And so we also extended then into GCP so that they had burstable capacity for additional GPUs, um, when and if they need them, um, as well as now a fully tiered environment that was NVME or tier one storage, and then this object storage on the backend and cloud as needed, reducing storage costs, their renewal license basically, um, came down by $5 million. Um, you know, the other thing is now their users are only looking for the data in a single place, right?
They aren't looking across file systems, across object storage. It's single global namespace, no matter where the data lives greatly simplifies their workflows. Um, and now they have agility to be able to utilize both on-prem and cloud resources.
Um, here's another customer who ran into the performance issue, right? They were looking to deploy this new set of NVIDIA servers that now demanded, you know, three, four x the performance that they had been providing from their storage systems. Um, but they weren't looking to, you know, up their storage by three to four x.
Um, so instead of buying a bunch more storage systems or perhaps, you know, some kind of bespoke parallel file system solution, right? They brought in hammer space, we could still continue to leverage the systems that they had invested in their NAS systems. So those stay in place can be used both with data in place and then also as an extra archive tier.
And then we deployed our own and VME storage behind. So I did want to emphasize that we don't just use other people's storage as a, um, backend, we can deploy our own storage as well. So we do have, um, storage boxes to be able to support customers in their deployments.
And that's just standard commodity based storage servers. Yeah. PR vann from, uh, fin consulting.
So, um, I, I do definitely see the value on the training sites. Mm-hmm. You know, with the metadata being available all over the place, but your data might be delayed.
Uh, how does that work for inference? Do you see the product working well on, on inference considering that your data might be slightly delayed? You know, where we talk about a little bit latency, where on the inference side, you know, latency is kind of a key, uh, key factor.
Yeah, I think, um, I mean, I guess fundamentally, um, what are you changing from data being remote or local? You know, in this situation, right? We are gonna bring the data as close as possible to the GPU, right?
For, um, you know, again, under the covers and do that based on policy as a object is, you know, accessed, we can then bring the entire project into the local NVME. Um, so I don't think we're necessarily at a disadvantage. I mean, yes, if you had migrated all of your data into a bespoke file system, right, and then connected that up to your GPUs, um, then yes, but I think then you're looking at a massive one-time migration, um, which takes time, right?
So it depends on where you wanna spend your time, I guess. So if I Understand it correctly, there's a way to create a profile where you kind of preload the data. So Sam will talk about that.
Okay. Here in Jeff. Yeah, Frederick, we can spend some more time over this.
We do have a number of customers that are using us for global inference, right? So when they're using Tier zero for incredibly pa fast performance, right? Holding model repositories information that's been created, we then use a bunch of policies to drag that back, right?
To continue to do some fine tuning or some updates of those things. But they also use us to, to sync vector database information and those sorts of things. And at that point, we're up against the speed of light problem, right?
But they still find value in the fact that this all happens through policy and automation rather than this like spray and RC problem they've been running against. So I can show you a couple of designs where we're helping those particular inference farms, especially when they're trying to, to your point, keep latency low by moving inference close to the user, but still keeping data sets intact right across those particular farms. Yeah.
Thank you. All right, I'm gonna skip over this slide. It's what we do.
We're helping tame the data chaos with a single unified global namespace. Now you'll notice here, right, I'm just talking about the unified namespace plugging into an AI factory, but there's an important part of the prep and rest of the data flow, um, or the pipeline, right? For AI data that maybe we hadn't touched in the past.
And that is getting data truly AI ready, right? We were a storage system that provided data, raw data at the front end. Now with A IDP, we're truly unlocking all of the value that is within the data.