Techstrong TV February 6, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here now to Techron tv. I'm thrilled to have my next guest on.
He's a friend of mine. I, truth be told, we probably spent more time talking off camera, then we're gonna spend on camera here. But, uh, I'll be seeing him in person at, uh, Shan in, uh, Shan in, uh, Prague.
I believe it's April 20 to the 23rd, something like, like that. That's correct. Absolutely.
Um, his name is Andreas Prince. Andreas has, as he told me when we first got on, he only has one job now. Right.
He is global head of Sovereign Solutions for suse. And, uh, Andreas says that, of course, tongue in cheek. He, Andreas is a former CEO the company acquired by Seus Suer, uh, Stax State.
Right? Correct. Absolutely.
And, uh, and then he, he's worn several hats at suse, but now as he says, he has just one hat and he's laser focused on it. Andreas, welcome to Text Drunk tv. It's great to have you back.
Thank you so much, and glad to be here again. Absolutely. So, Andreas, let's go right to this new role.
I, I think I interviewed you when you first were appointed, uh, global Head sovereign, or, you know, took up the mantle of moving this forward for suse. But, you know, for people out here who maybe are not familiar with digital sovereignty yet, how important it's become, talk about that and, and why Cuse in particular, you know Yeah. Saw fit to take a senior person like you to, to head this up.
Yeah, no, absolutely. Happy to, uh, happy to do that. And I must admit that I do think it's about six or seven weeks ago that we spoke, or probably a little longer, but I learned so much over the last few months.
So let's, let's talk about it in a little as well. Um, but I'm, I'm driving the global initiative around, uh, sovereignty, right? Because we see the world becoming more and more isolated, which is a kind of sad, uh, because it's killing innovation as such.
But what is the good part of that is companies and governments and, um, even continents are becoming aware of their dependencies on other parties, right? And that is posing the question is how sovereign or how resilient is actually my business. And I do think that that is a very valid question to ask by, by any company, what are my dependencies to, uh, to other countries?
And in my initiative, what I try to do is really connect all the, the gold, how I'd like to put it in our portfolio as suse is running a full open source portfolio and use that to help public sector mission critical infrastructure, highly regulated banking to let them use open source to ultimately increase their autonomy, because the more autonomous they are, the better, and they can run the business themself. So I'm bringing product marketing, sales positioning, but also a little bit of influencing Brussels, if you like, from a policymaking perspective to, um, yeah. To, to come to a better answer to all the foreign influences that the different regions in the world are facing today.
Yep. You know, I, I wanna address that for a second. Different regions in the world, a lot of people think of the digital sovereignty movement as, oh, this is a European thing.
They wanna be, you know, sovereign and independent, but no digital sovereignty. I, as I said on my shimmy, says a couple weeks ago, it's a, it's a national sovereignty issue, but it even, it goes below even the nation state. It, it's a municipality issue.
It's a province issue, it's a state issue. It goes all the way down to a personal issue. Yeah, yeah.
Right. The issue, the idea of sovereignty over one's data sovereignty over one's technology infrastructure. Yeah.
Yeah. It, it, I think it has to become sort of like a basic human right. A basic right.
Yeah. And we have to think of it as such. Yeah.
And it, and it goes beyond just Europe. Yeah. So it goes beyond Europe, as in, we see it equally happening in Africa, middle East, apec.
Right? So many, many regions are asking, and if I would ask my American colleagues, they would not call it sovereignty, but they very often speak about data security in the context of ai. Right?
It's connected back to your, to your statement, right? Because it's all about the data. Um, so we see different wording, but all, all regions, I would argue across the world, are becoming more and more aware to take action.
Um, and then on the other side of the spectrum, and suse is not that much involved there, but if you think about many countries putting strict regulations on what teenagers can do on social media platforms, right? And, and increasing the, the bar, right? The age before you can enter a platform ultimately, right?
For addiction, but also for, hey, protecting data sovereignty, these type of elements. So it's definitely a human. And last week I was at the open source, um, week in Brussels, and, uh, one of the, the German ministers from one of the, the areas in the north of Germany, he spoke about that they've moved already to 60 to 70% of all their software towards open source.
So it's not that Germany as a country, but these portions of Germany are, are moving big time. So it's hard, but there's a lot of 50, 60% that's relatively simple to do. Right.
And then the rest Yeah. Ultimately will follow if you free a budget and efforts to, uh, to get there. Absolutely.
You know, there's another element to this too that we have in hit on and driving. You mentioned here in the states, in America, um, you know, I, we've seen this in the US for some time where some states tax, right? Charge for business you do within the state, online and so forth.
So there are a lot of businesses who will say, I don't want my infrastructure, even though I'm using AWS or Google or Microsoft, I don't want my infrastructure stored in this state because then I'm subject to their taxes Yeah. And their laws. And so again, it breaks down, but, but there is the financial, as there always is, as in there, the financial aspect of, of having, again, sovereignty control over your footprint, over your data.
Well, and, and interesting, I don't know the the details, but what is the EU doing is, is the opposite. Um, so, um, uh, fonder lion, she announced an initiative, right? And let's see if we can realize it, which is called EU Inc.
So rather than having a, a company that resides in a country with its own tax rules and labor rules and whatever, and they have the ambition to establish something, and I do think ideal for IT companies across Europe, because by doing so, it's much more interesting for a startup to remain in Europe, right? Because then if you sell in one country, you're able and allowed to sell in all countries across Europe. So all of a sudden you're targeting a, a much bigger market, um, than moving first to the us, um, right.
To, because that's what a lot of European companies do if they go to series B, that they have to go to the US have to, to have much faster growth. So it's interesting that the EU is also having these considerations to, to make it easier to grow a company here in, uh, in the eu. Yeah, sure.
Standardization makes it easier because it becomes reliability, predictability, et cetera. You know, speaking of EU though, the, the, uh, the 2025 EU cloud sovereignty framework, is that what you're referring to here? Or is that something else?
No, that's, that's something else. So the, the EU Inc is really a company type, right? Right.
That is applicable for the all of Europe. The framework is another very fascinating instrument that the EU has launched. Um, I'm very positive about it because it's simple.
It's only six pages. Uh, but it helps executives, I would argue, to really understand what sovereignty is, because it have defined eight objectives to do that. And it then gives a very interesting five grade scoring mechanism to help them understand, to rate on these eight objectives, uh, scoring five.
And that's interesting because then all of a sudden they can start to assess, um, their products, their IT stack and understand what their risk is or their exposure, if you like, from a sovereignty perspective. So what I do think where EU really succeeded is to make a, a framework that is comprehensive, um, but still very easy to consume and to, to understand that we see a rapid rise. It's mentioned, people are writing, writing about it, it's popping up in RFPs, right?
So people are really using it to understand what it is they need and where they are today. Excellent. Excellent.
Now, is this, this framework, has it been pa like is it official EU legislation that they voted on, or is it, because I know in the eu sometimes they'll have like a, a working model session, right? Where they, let's see, you know, we're waiting to hear back from industry and other people before we actually make it law. Yeah.
It's much more like this. So it's early days, and so if you take a look at the regulation, it's the Cyber Resilience Act needs to, and Dora, right? Mm-hmm.
Which are really, really laws and regulations applied to the countries. And then this framework, I do think that's why the word framework is in, is still a recommendation, right? So if you need to think about sovereignty, this is how you can assess your own situation, how it might turn into law.
I don't know if that's gonna happen, is that they are requesting particular scoring levels. So imagine the, the government of the Netherlands or Germany would acquire software and they might say it needs to score, right? At least a three or at least a two, right?
On the, on the framework. Um, right? That's, that's how it's potentially be used.
So not in a law, but more as if you do procurement, you might see this framework popping up by articulating, Hey, you need to at least score a two or a three or a four, um, in this, in this perspective. Excellent. Yeah.
Andreas, I wanted to ask you, I I, I remember reading this news. I saw you were featured, you spoke out, and I think SUSE put out some pr and there I saw some LinkedIn activity, you know, AWS so one of the big three hyperscalers Yeah. Announced a, uh, sovereign environment, a sovereign offering spec specifically for eu.
And SUSE is one of the strategic partners Yeah. In that, yeah. Wanted to ask you, how does that work though, with AWS still being sort of a US based Yeah.
Uh, corporation. Yeah, that's, that's very interesting one. And if you take a look, uh, if you go back to the framework, uh, the framework articulates sovereignty in many aspects, right?
It is where your data resides. It is the personnel who's working there. It's about the supply chain.
It's about the software being used, it's about jurisdiction, it's about strategic. Um, and if you think about our customers as some customers, let's say a public, um, or a government, right? They want to go very strict, right?
And they might say, Hey, even AWS right is not good enough for my, my online identity management. I want to go to a more local regional data provider, right? That, that might be a move.
And then the AWS European Cloud isn't a so solution for them. We have a lot of other customers who say, Hey, I want to get guarantees that it runs in Europe, right? Because that's important that I have European personnel working on it, because that's important, but I'm still a global company, right?
So the fact that I'm under the cloud act, right? And because that's where a lot of people refer to, it's still okay, because I also have an American entity as a, as a company, right? So people think about this very black and white, and I do think it's much more nuanced.
There are customers who wanna benefit from a hyperscaler type of capability because they don't want to have an own data center or whatever. They wanna benefit from the rich marketplace capabilities that I'm assuming will grow there as well, um, but still get more strict, right? Than the regular AWS type of contract.
So it's a very nuanced approach, and we have a lot of customers that are across continents, right? And that are simply anyhow tied to a hyperscaler solution to make it beneficial or to make it, um, to make it work. Um, so we really follow the customer, and that's why you will see us doing announcements on very sovereign solutions, right?
Owned by European in Europe, European personnel, but also we have a lot of customers who want to go to the AWS European, um, clouds. So yeah, that's, that's the kind of meeting the customers where they are. Excellent.
Excellent. Andreas, it occurs to me that the man, you only got one job, but there's so much going on right now with it for our reader readers, excuse me. Our listeners are watchers out there.
They're not really reading this. Um, where can they go to stay up on all of this? Yeah, no, that's, uh, very hard.
There's a lot going on. If you only follow your own LinkedIn feed, say if there's a conference going on, then it's populated with lots of articles. Um, the question really is what is it that you're after?
And what I notice in sales conversations is that people are, I mean, we're, you and I are speaking about right, the world moving and, and, and, and things that we need to build and isolation and innovation, but a lot of people are, are just trying to become aware of what is actually happening, right? How do I need to assess my own stack, right? So a lot of the market is, is much earlier days.
And what we launched last week is a self-assessment based on the EU framework that helps you to measure how you score your own stack. And by doing so, you get a very extensive gap analysis, right? And I do think that gap analysis, the text, helps you to better understand and articulate where you need to go with your roadmap, with your product improvements, um, and whatever.
And the reason why we developed it is predominantly because the world, right? Or Europe, if you like, doesn't know how to express and make a roadmap, right? A lot of these CIOs or CTOs and how to make a roadmap that is reducing my overall sovereignty risk as such.
So yeah, definitely every looked it up, right? And, uh, I do think that's very helpful to, um, for many people. Excellent.
Excellent. com and find it from there? S sovereignty dash test?
Yeah. Got it there. I was hoping you'd have something Andy like that.
Absolutely. Andreas, do you have any spare time to do anything else, or is this consuming you at this point? Well, I'm a little bit of a fennel five coating, so I like to run some, uh, some tiny, sometimes personal experiments.
Uh, and my duty is at home raising a big family. So, uh, lots of hobby projects there, if you like. Absolutely.
You know, I want to, one other thing I, I noticed this morning here, I think the Netherlands specifically just came out with some sovereignty, not guidelines, but a plan of three, three areas. Yeah. You want to talk about that a minute?
Yeah, definitely. And I do think that that's pretty interesting for the rest of Europe to see how that shapes up. So we, uh, we had elections, uh, and then in less than 90 days, right, they formed a coalition, which is pretty fast for the Dutch standards.
Um, and they articulated a coalition agreement. They had three parties seeing if they can, can govern the country for four years. Um, what was really strong is that it contained a two or three paragraph, or sorry, a three paragraph, two pager, uh, in that agreement with regards to sovereignty.
So it was about sovereignty itself, cybersecurity, and really the scale, uh, and scale and skill of people and the scale, how to apply that gap. Uh, and what I like there is they did in my mind, the first attempt to make it very tangible, um, and at least address the risk. Now, I, I understand it's up to the government and the ministries had to make it tangible and to put it into motion.
Um, but what is good is that at the government level, we think about, well, to your point and the, the, the sovereignty of the nation and how we could drive that forward. And I'm expecting added other countries, a if election would pop up, and if they need to come up with an agreement, they will do more or less the same and really address sovereignty and open source and, uh, procurement processes in a very structured way. So let's, let's see, right, if, um, if this moves stuff forward, um, still the government.
So I'm very hopeful and we're having lots of good conversations, but, uh, the work still needs to happen. Absolutely. Alright, Andreas, we're about outta time.
I wanted to thank you for coming on. Look, I think what you've, it's not like you haven't worked on important things before, but this is one of the most important things you're gonna work on you, right? And, uh, I think when you look back at some point over your career, this will be a, a, a really linchpin, you know?
Yeah. A real big, big part. Um, and I could think of a better person at SUSE to run this.
So thank you. Keep doing what you're doing, do keep us informed. I'll looking forward to seeing you in, uh, April in Prague.
Absolutely. Looking forward to that. And let's continue.
And, uh, we'll continue. But if something comes before then you'll come back on. We'll talk more.
Well, no worries. We'll do that. All righty.
Excellent. Andreas Prince, global head of Sovereign Solutions to Susa here on Textron tv. We're gonna take a break.
We'll be back. Hey everyone, it's Alan Shimmel, founder, CEO here at Techstrong, and welcome to our continuing series on, uh, AI agentic ai, the Future here with, uh, the Microsoft team and our future of analyst team, as well as Techstrong. In this next episode, though, we're gonna be joined by Mitchell Ashley, uh, of Futurum, who leads the software development lifecycle and building segment at futurum.
And Mitchell is talking with Brian Good, who's official titles is Corporate Vice President and Agents Marketing. But Brian is really here talking about agent apps and chat, and it, it's, uh, you know, obviously a very hot topic as we move to a n agent AI workflow based basis. So let's join Mitchell and Brian here with me, and it's great to have them both.
My name is Mitch Ashley, and I'm VP and practice lead of the software Lifecycle engineering practice at RUM Research. And, and Mitch, uh, my name is Brian. Good.
Uh, I lead the business applications and agents team, uh, here at Microsoft. Let's start here. 2025 is described as kind of an inflection point for AI adoption.
What do you think are the most significant changes that, uh, you've seen in organizations as they're using AI and agents in their businesses this year? Well, I absolutely agree. 2025 is really an inflection point, and we'll sometimes describe it as the year that the Frontier Firm was born.
And you might have heard us talk about the Frontier Firm before. It's this idea of companies that are putting AI really at the heart of their business, and it's enabling them to do things like reinvent the way they engage with the customers or transform their business processes inside their company, um, and beyond. And it's really the year these frontier firms are sort of rising up and a time when I think we can learn a lot from these early adopters and understanding how they're deploying ai, how they're being successful, and then figure out how we can take those insights and bring 'em to, to our own businesses.
That's where you can have outsized impact As AI transforms those functions. What do you see as the new patterns of work that's enabled by copilot and agents as customers start leveraging the technology for productivity or innovation? I'll tell you what, I have studied these frontier firms as they, as they come up, and there's really three patterns that I see across these frontier firms.
The first is really enabling, uh, employee productivity. So they give every employee, uh, an AI assistant like Microsoft 365 copilot, and it helps them, those employees be more productive. The second pattern that I see is, uh, really these frontier firms deploying AI to automate existing business processes.
So, for example, they already have a way of handling expense reports, but they can use AI to speed that up and reduce costs, and, and that certainly results in some benefits to the customer. The third pattern is really where a customer, like starts from the beginning, let's say from first principles, and they reimagine a function altogether. They'll reimagine what it means to engage with a customer who has a, uh, an issue with their product.
And they'll put agents at the heart of that. Most companies can only take on one or two of these functional transformation projects at, at any given time because it's a big lift. Again, it's reimagining a function from first principles.
It's not just taking existing processes and and applying AI to them. How far along do you think most organizations are in their adoption cycle for generative ai? Well, I think we're still in early innings, uh, that there's no doubt about that.
Um, you know, customers are starting to deploy AI and different functions as we talked about, but certainly they haven't, in most cases, fully realized kind of the transformation that AI can have across their organization. So it's still very early innings, but I'd say we see very promising signs and, and green shoots, uh, of that, uh, of that adoption and success. Uh, again, the key really here is to start function by function, think about a particular function, think about peeling it back to the business processes you need to go focus on.
That's where you can have outsized impact. How do you define AgTech business applications, and why are they critical for organizations? Yeah.
Well, I do have a vision that there's, uh, the application of old is really transformed with ai, and we call that new type of application, the AG agentic business application. And the ag agentic biz app includes the assistant for the human to start to use. It includes prebuilt business process agents that basically take the drudgery out of work, and then it's built on a data foundation.
And so instead of being limited just to the data that, you know, maybe is in the CRM system or the ERP system, it joins that with data from other lines of business systems and even productivity data so that you have a rich set of data that you can build agents on top of, and you can empower your humans to get better decisions from. And so this idea that brings all those together, the assistant, the agent, the application, I call the AG Agentic biz app, and I think it's a really big idea. Let's talk about why you're optimistic about the future of ag agentic business applications.
I have a lot of optimism here because number one, I see customers already deploying these applications, uh, and and really transforming their business. So I already see people starting to get great benefit from it, but at a more human level, the thing that gets me excited is like, if you think about every one of our jobs, like there's a lot of stuff that we end up having to do that really isn't adding joy to our lives. Uh, you know, me doing an expense report or, you know, filling out a CRM uh, system, you know, with an update from a customer call, those aren't the things that, uh, that make us, uh, unique.
Those aren't the things that bring joy. Those aren't really even things that add business value collectively. But if we can delegate those things to AI and agents, I think will enable ourselves to actually go do far bigger things and really take our ambition to the next level.
And so I am absolutely excited for what the future holds. Yeah, I'd love to hear about how you see the role of AI agents evolving just over the next few years, especially as organizations start to redesign core business processes drive outcomes for efficiency. How, how do you see this taking shape?
Yeah, great question. You know, odd, I I would say that we really believe there's a spectrum, uh, of, of agents. You know, there will be very simple agents that someone will use that might just be grounded on a particular knowledge source and help you, you know, understand, you know, what, what might happen from that, uh, from that knowledge source.
Then there'll be task-based agents, and then there'll also be more sophisticated, fully autonomous agents as well. And this more autonomous agents is where you can unlock a lot of business value. These are agents that, you know, aren't called by a by a human.
They're just running independently. They're triggered based on different actions, and they can really automate business processes in some cases from start to finish. So we believe there's this spectrum of agents, and today, I'd say most ENT use cases start with those more simple kind of knowledge agents.
Uh, but increasingly we're seeing customers bring in these task-based agents and autonomous agents, uh, to automate, uh, things, uh, end to end. How about the C-suite leaders? How should they be thinking about investing in agent technologies for long-term value?
Well, every C-suite leader I talk to today is already in on ai. Like, every one of them recognizes that it's a competitive advantage if they can move quickly, and if they don't move quickly, they recognize it could be a, a disruptive force in their industry. But let's face it, ai, it's transforming businesses, is transforming functions.
It's, it's gonna reshape entire industries. And every C-suite leader I talk to recognizes that and wants on board. What they're looking for though, is a partner.
They're looking for the tech, of course, they wanna make sure they've got the right tech, but they're also looking for a partner to help them shape this in their business. And that's where Microsoft, I think, comes into play. Uh, you know, we're not a large scale model maker, uh, but we do take the best of the models and bring 'em into the workplace, uh, so that companies can use them.
You, we talk about AI being a disruptive technology, probably because it seems that it really can and will affect every part of our work, our lives, et cetera, certainly is affecting how we create software with new concept like agents and agentic ai. Curious about your thoughts. Share with us, how does Microsoft view what the transformation is going to be like with ai, really have an impact and a big benefit to businesses?
Yeah. Uh, many industry, uh, pundits will say that this move to AI agents is gonna, uh, lead to the rise of, uh, uh, more consumption like models or outcome-based pricing. And I think they're right.
I, that's definitely a direction that I see the world shifting as well. Um, the only thing I would, uh, balance that with is that many customers are still, uh, you know, most comfortable buying things on a, a per user or pre per seat basis. And so, uh, the approach I'm taking is, you know, how do I enable customers to buy offerings that they're comfortable with?
And that's typically like a per user or some type of per tenant type of type of license, while giving them the flexibility to, to grow and shift into more consumption models as they, uh, as their business changes. And so, uh, we are at an inflection point, just as we said, and I think one of the things that will change is the business model over time. Talk some more about AgTech.
When you think about agents operating on their own or more autonomously, and why, why is that an important thing that organizations are looking to move to? Yeah, It really comes down to business priorities. Like every business leader I talk to wants to find ways to grow their top line revenue, or they're looking for ways to automate, uh, things that, that they're doing so that they can save money or redirect folks to, uh, focus on more important activities.
And, you know, autonomous agents really fit that bill. You know, imagine in the sales context, you can have an autonomous agent, you know, going through marketing leads and qualifying them before handing them off to a human seller. That's work that wouldn't have gotten done in the past or would've been done by a human seller, uh, and have been relatively low value, not something they, they really enjoyed, uh, about their job.
And so an AI agent can do that and add great value to the company, and again, help that company grow on the top line. Talk About Microsoft, uh, and the offering that you have in the context of an end-to-end tool toolkit, if you will. Yeah.
For functional transformation, You know, as far as the toolkit goes, we really believe that there's three essential parts to it. The first is we think every employee should have an AI assistant in our case, uh, that's Microsoft 365 copilot. Uh, think of that as a productivity tool to help every employee work get through their workday and get more done.
That can be quite transformative. That next step up is where agents come into the picture, and I describe agents as really being for every business process or workflow in an organization. And we have, uh, a toolkit that enables customers to build their own agents.
It starts with copilot studio, but even extends into our Azure capabilities with our Azure AI Foundry product. So agents pair very nicely with that copilot that I described first, and then the final step is where the system of record becomes the system of action. And we'll sometimes call this the agentic business application, where you take a CRM system and you add agents and an assistant to it to really transform those three are the essential ingredients or building blocks for AI transformation, um, in a frontier firm or any business at this point.
That's a great term. Can you share some examples of how Microsoft customers are already seeing measurable impact from adopting agent business applications? Yeah.
One example I I think I can give is lifetime. Uh, they're a great customer of ours, uh, based here in the United States. They've used us as part of their finance and supply chain operations, and they've, uh, deployed agents to basically speed up how they handle and process e-commerce orders.
In fact, I think it saved them 95%, uh, in terms of their order, e-commerce, order efficiency by deploying, uh, AI agents and agentic business applications to solve that problem. So I think that's a great example. We also have, uh, another great example, uh, from Europe, um, uh, a large utility named Enco who deployed a multi-language, uh, AI agent, uh, for their customers to help them scale and address customer questions.
Uh, it's a pretty cool solution, saves them time and again, helps them scale up. Now, it's a, it's a really exciting time in the world of agents. You know, you talked about the C-suite in the, kind of the three phases in this adoption curve as we adopt ai.
What, what kinda recommendations do you have of like, how to get started? Well, maybe near some of the near term activities? Well, you know, as I said earlier, I think AI is gonna transform every company, every function, every industry.
And that opportunity is so vast, sometimes it's hard to know where to get started. And I've got two bits of advice really there to, to anybody that, uh, that is, is pondering that question. Uh, the first thing is, again, start with a function.
Pick a function that you want to go after and then peel it like an onion. You know, go look at the next layer, which are the business processes in that function that you can apply, uh, a copilot or agents to, to really transform. The other thing though is like, don't get into analysis paralysis.
Just pick a business process. Just go pick a business process to get started with. And as you learn from applying AI to that business process, whatever it is, whatever your thorniest business process is, go apply AI to it.
You are gonna learn, your organization's gonna learn, your culture will adapt, and then it will flow from there. So the opportunity is so vast. Don't let that keep you from getting started.
You gotta get started, start simple, pick one thing and go from there. So as we move to an agentic business environment, let's talk about the people. How do you see the role of human creativity, judgment, leadership?
How is that gonna evolve? Yeah, well, that's an excellent question, and one of the things that we'll often talk about is how AI and frontier firms is gonna transform the way we work. It's gonna change, uh, the org chart into more of a work chart.
Uh, we sometimes talk about, uh, a frontier firms taking on the Hollywood model where individuals will swarm around a problem, like focus on a problem and then disband, uh, you know, uh, when the, you know, once they've got a solution. And so it's absolutely gonna change the way we work with others inside the workplace. It also, I think, is gonna give rise to a new idea that we call an agent boss.
And you can imagine, just as a people manager today might take work and delegate it to different humans on their team, uh, you know, resolve conflicts and sort of manage performance. Every one of us in the future is gonna do that, but not just with humans, but also with agents. So imagine taking a business problem, breaking it up into pieces, delegating it to agents or agents, uh, on your team, resolving conflicts that might come up, applying human judgment.
Uh, it's gonna be an absolutely transformational moment, and I'm really excited about it. I, I really believe that, you know, there is still a huge opportunity for humans with human ambition to go do great work amplified by ai. Talk a little about, about how you see the, the difference in, in the working together between applications, assistance agents, the different technologies.
Well, that's an excellent question. And you know, we really have this complete toolkit that spans everything from the assistant to the agent to the application. And I think those three things work together in a symbiotic way.
As an example, you can imagine that I might go to my assistant and, you know, ask a simple question, my AI assistant like Microsoft 365 copilot and ask a question about, you know, uh, summarize the emails or help me respond to the emails I've got. Or I might use an agent to update a CRM record after I meet with a customer, but I'm still gonna want to go to an application. Really, that's a purpose-built experience for me if I want a more specialized or fine tuned experience.
So those three things really work together, Like a little bit about the industries or maybe the business functions that you expect to see reshaped first by agent AI transformation. Yeah, there are three or four, I'd say functions in particular that are, I'd say, um, you know, ground zero for, uh, functional, uh, transformation with AI and agents. Certainly customer service and customer experience is one that is, uh, absolutely being reshaped and say a very early adopter of ai, no doubt about it.
Another, where I'm seeing a lot of early AI adoption, uh, is in sales. Uh, and it's just because, just as we talked about, there's a big opportunity to use AI to basically increase capacity for that organization to grow top line revenue. So the business impact there is undeniable, but I also see it in places like finance and supply chain, where you can use AI to shorten the time it takes to, from an order to actually being able to ship it that order.
We're seeing people use AI to improve accounts, uh, payable and accounts receivable. Um, so we're seeing some pretty, uh, interesting impacts there. Let's Talk a little bit more about the frontier firms.
You know, they're not just adopting technology, they're also changing the way they're do doing business around AI agents and co violet capabilities. Can you talk about, you know, what they're doing to invest and support the short-term ROI that they are looking to get for long-term innovation? The most successful frontier firms are doing, actually is taking a functional approach.
And so certainly they'll think about their entire company, uh, but they'll really take an approach that's function by function. They'll think about their sales function as an example, and then they'll peel back the onion a little bit and understand which processes inside their sales department they can automate. Uh, using AI agents as an example, they'll look at which, uh, things their salespeople need help with, where you could pair up an assistant like copilot to help them throughout their workday.
And they'll even look at how they can bring agents in to really augment business capacity, maybe to grow top line revenue or take out costs. But starting function by function has really been the recipe that these, um, frontier firms, uh, are using to see success. As an example, in our sales organization, uh, by deploying co-pilot and agents, we've been able to improve revenue per seller in some cases by almost 10% in some organizations.
And you know, if you think about that giving a seller 10% more capacity is like giving them an additional month, uh, in a year, uh, without actually having them spend any extra hours through the work week. And so there's some pretty remarkable results That's just sales. We've been able to do the same in customer service and our finance department and our IT department, our legal team has been able to reduce costs by 5%, uh, by deploying AI and agents, uh, within their, uh, within their functions.
How do we ensure trust and transparency as ag agentic systems become more and more autonomous? Yeah, well, there's two things that we want to do to help with trust and transparency. The first is we have a rigorous set of principles on, uh, responsible ai.
So for any AI that, uh, Microsoft deploys, we adhere to a an important set of guidelines. Uh, and that's really table stakes. So that's the first piece, uh, responsible AI and our focus there.
The second thing that I think is important is we now have an opportunity to start to quantify the value and the impact that many agents will have. And we often will call that in the industry, we'll call that evals or benchmarks. And increasingly, I think we have an opportunity to help our customers understand how agents are being effective in their workplace using these evals and benchmarks on real world problems.
So for example, uh, we, uh, uh, a typical, uh, workflow will be a sales leader doing sales research to try to understand like how they might want to organize accounts or territories or, you know, reshape planning as they think about the year ahead. We recently released a new benchmark, uh, that we call the sales research bench, and it shows how agents can actually help sales leaders in that very specific job, and it's quantified. Uh, and so I think you'll start to see more of that.
And between following responsible AI standards and then using quantitative measures like evals and benchmarks to understand efficacy, I think we're really on the cusp of helping customers know how they can deploy AI in a safe way for real business results. Well, thank you Brian, for sharing with us your insights and kinda look into the future, what's happening with the Gentech business applications. Thank you very much.
You know, it's really amazing the pace at which AI has been adopted and continues to evolve. The technology evolves on a near daily basis, but at the same time, organizations have to figure out how they're gonna implement their AI strategies and what the business outcomes that they're most important to their business. I think it's very fascinating how Microsoft has approached the market, both from the standpoint of addressing the individual and their productivity, but also thinking about new workflows, new models of business, but doing that with not a set of tools, but a set of capabilities that provide integration with data process, workflow, and agentic ai.
No one knows for sure what the future holds and what an agentic business might really, really look like. But in situations like today, when we remove constraints of what we can do with technology thanks to ai, that's where the possibilities are created. You know, using tools like copilot, using applications like Dynamics 365 and we'll, we'll see what end users as well as technologists bring to bear in their ideas and how they reshape businesses today and tomorrow and about you.
But I'm super excited about the future that we're creating together thanks to working with technology companies and with end users like yourself. Hey guys, thanks for the throw. We're here with Jim Brennan, who's chief product and technology officer for Get Real, and we're having a little chat about, well, deep fakes, but they're coming to the enterprise now and it looks like they're targeting specific individuals who maybe have, uh, a lot of power and a lot of net worth.
Jim, welcome to the show. Well, thank you, Mike. Really glad to be here.
I appreciate the opportunity. I think when most people think about deep fakes, they're like, well, some politician somewhere was impersonated or that it was, uh, you know, maybe some actor or somebody who was saying something about something. But it seems like lately the bad guys are getting pickier about who they go to the trouble to create these DeepFakes about, 'cause they're after, well, you know, senior level execs and companies that have access to money and workflows.
So what's changing here? Yeah, that's absolutely the case. You know, it's actually, there's a couple different types of DeepFakes to think about in this conversation.
So one is, is a case where you've got maybe an image, audio or a video file floating around, and maybe to your point, it's of a celebrity or an executive saying something or doing something they shouldn't be saying or doing. But now what we're seeing is actually the use of this, this same type of technology, but instead taking place in real time forums, much like an interaction like this or a phone call. And so now these, these are actually attacks focused on the enterprise because things from candidate fraud.
So, you know, fake job candidates showing up in an interview to somebody calling the help desk claiming they got locked out of their, their Google or Microsoft account. These are ways in which these technologies are now being utilized. And so they do represent a real threat to the enterprise.
How good are they? Because a lot of folks would assume that there's, through a level of interaction and conversation, it would become apparent that that was a deep fake. And yet we hear about people being fooled for an extended period of time.
So what's changed? Well, it's changing dramatically by the day, Mike. That's, that's the reality.
New tools are coming out, the existing tools are getting better. There are some differences if you're talking about audio or video. So, so for quite some time, for about a year now, audio has been to a point where most people, including you and I, if we get a phone call, likely can't tell the difference.
Video is a little bit more complicated. Of course, you've got more signal to work with, but even that's getting better. There's new tools that have come out recently that are just uncanny in terms of how close they can mirror somebody's resemblance In the future.
Will we have to validate every interaction? I mean, before you and I joined on this call, uh, you were introduced to me by somebody we both know and hopefully trust. And as that comes together, though, it seems like a little awkward, but is that where we are?
Yeah, Well that's just it. Exactly. You know, and if you think about how, how much time we spend in a video conference or, or taking phone calls and most businesses conducted in these forums, and to your point, there's really a missing authentication layer here.
So not only are the things you mentioned, but what, what's to stop me from sending the link to this meeting to somebody else that could then pretend to be me? The reality is you and I right now have no, no real reason to believe that we're talking to who we think we're talking to, right? I don't really know that I'm talking to Mike.
You don't really know you're talking to Jim. I can assure you that you are. But there's, there's really no technical reason that we should have that confidence, but we're all conditioned to trust what we're seeing and hearing.
That's just, that's human nature. But we're now in this, this realm where that you can't rely upon these signals. So it's a fascinating change to the dynamics.
And for the last 20 years, business has transformed to again, be utilizing these types of communication forums for very important transactions and conversations and, and every type of business. And now we're at a point where you really can't trust who's on the other end of that interaction. So what's to be done about this?
Do we need some sort of missing technology or is there some service somewhere that will validate our representations to each other in a way that we can at least reasonably trust, maybe never perfectly trust? Yeah. Well, there's a couple different questions that you have to be able to answer though when you're thinking about trust, you know, so, so one question is, is the person I'm speaking with or interacting with, are they actually a real human being or are they some type of synthetic creation?
A deep fake, but that's only one, one question. The other question that is equally important in an interaction like this is, is the person I'm talking to who they're claiming to be, those are two very different questions, right? So you take an interaction, like an interview, a job applicant shows up in a Zoom call or a teams call, right?
Oftentimes that candidate fraud that's taking place is not involving a deep fake. It's involving somebody claiming to be somebody who they're not. You know, maybe they don't have the right skills.
Maybe it's a state sponsored actor hoping to infiltrate a company. So two questions. Is this a real person and is it the person that I think I'm speaking with?
And those two questions, to answer those, you need different types of, of techniques or solutions. On one hand you need some ability to, to detect synthetic content, audio and video. But then on the other side of that coin, you need some way of verifying consistency of things like facial biometrics, voice biometrics, behavioral, those are, those are some of the techniques that need to be brought together.
Then along with bringing in threat intelligence, because these are security incidents. So what can I know in advance of an interaction about somebody I'm going to be meeting with? Are they exhibiting, are they going to exhibit a face or a voice that is known to be associated with a threat actor?
These are all the things that have to come together. Yeah. Um, when we get to some point where there'll be tells, and I, and I asked this question because early on there used to be kind of the sense of, well, if there was something that somebody wanted you to do and it was urgent, was kind of a tell that maybe this is the wrong thing to do.
But to your point, it also seems like there's a lot more patients being exercised now on the bad guys and they're willing to pretend to be something for an extended period of time before they strike. So what can, what can I look for? Yeah, so there are some tells today, and I'll go through a couple of those depending upon the, the situation, but increasingly those tells are, are going away.
So in the case of, of an interview for example, there are certain things like obviously not being on camera or, or using a virtual background and refusing to take off that virtual background. Um, also in the context of an interview, you know, a lag between when the questions asked or an answer is given could mean that somebody is being fed responses from somebody else or looking something up. So these are things that exist now that're all gonna go away very soon because all the technology is getting better.
And so really what's gonna be needed is a much deeper, lower level detection of the tells and the artifacts. And here at Get Real, that's, that's really our focus. We're taking a very low level look at the actual processing pipelines of these platforms, zoom and teams, et cetera, and, and corporate telephony platforms and understanding what does normal look like?
And by the way, normal's changing every day. 'cause those platforms are themselves utilizing AI to do things like noise reduction. So it's not just a matter of it's, it is AI present, it's what does a normal non nefarious use of that platform look like?
And then you have to be able to couple that with in-depth knowledge of what do the common generator tools that are out there and that are emerging, what do those impart upon that processing pipeline? So you're essentially looking for deviations or anomalies from what healthy, normal, non nefarious activity looks like. And that's, that's our focus here.
We think that's the only way to solve this problem, but it does require a very low level of expertise and knowledge because again, the tells that exist today, some of the things I mentioned, they're not gonna be here long. Mm-hmm. Does that also include, I don't know, measuring latency?
Because, uh, theoretically if I'm talking to somebody and they're supposed to be in Green Bay, but if I'm measuring latency is pretty clear that they're not responding in the amount of time window that you would normally expect between New York and Green Bay. Instead it feels like, you know, New York to Africa, maybe something's this. Yeah, that's a good example.
I would, I would probably take that example and, and, um, look at it somewhat differently. So, so the idea of location being an important indicator, absolutely spot on. That's where threat intel can come in as well, and that's where other context and signals coming from the interaction such as IP address for example, can be really handy.
Also, things like understanding if somebody is using a virtual camera driver or audio driver, things that are associated with the use of these nefarious tools, very strong indicators. And then to, to another extent, maybe a somewhat lesser extent, just again, knowing some, something about the person on the other end of that interaction. You know, somebody's email address, you know, know what can you, what can you tell from that?
Um, are they associated with, with a company? Do they have a history at a company that you can trust? All these are signals that can definitely play a role.
Mm-hmm. So what's your best advice to folks? 'cause I think, uh, taken to its nth degree, you know, this whole communications revolution that we've been counting on for the last three decades or so, uh, might just unravel.
So how do we think about this? Yeah, well, and, and, um, I don't wanna sound alarmist, but, but internally here at Get Real Security, we, we think about the idea of a zero trust approach, but a zero trust at the human layer. So we're all familiar with that terms zero trust in terms of infrastructure and assets and so forth, but we need to apply a similar thinking to the human layer.
And again, the human layer is anywhere a human being is being represented in a digital signal. It could be, again, interaction like this, it could be a profile picture, it could be a voice recording landing in your inbox in WhatsApp, anywhere where a human being is being represented. We think of that as the human layer, and we really do think that we need to apply zero trust to that back to the conversation we had before.
Really, there's no inherent reason in today's climate where we should be trusting every interaction. And so you do have to take an approach like that, and then therefore that implies that you have to have some tools that can answer those two questions that I talked about. Is this a real person and is this the person that I think it is?
But then you also have to have tools that allow you to respond proactively when there is an incident. And then ultimately you want to know something about who's on the other end of that attack. These are attacks and, and as is the case with any attack, you wanna understand the intent and the actor behind that attack because if they're knocking on your door once, it's not only once they're probably, they're probably targeting many people within your enterprise.
What should law enforcement be doing about any of this? 'cause I guess fraud is still fraud, but, yep. Um, I wonder if the technology has just moved far beyond their capabilities at the moment, but what would you like to see happen?
Well, I would say it hasn't, it hasn't moved beyond their capabilities yet, but, and we do a lot of work with government agencies, law enforcement, that does tend to be more in the realm of file or content analysis, so perhaps evidence to be admitted in a court of law as one example. Uh, similar case with, with intelligence analysis within governmental agencies. And so they're very focused on this problem.
Again, we have a lot of, uh, conversations and some relationships in that area. It's very, it's very quick moving as we talked about. Right?
Um, and that one in, that in those cases is primarily about that deep fake detection. Is this synthetic content? Can I, can I trust this?
But if it involves a person back to my idea about the human layer, that's where the approach I mentioned can be very relevant. Not just understanding is it synthetic, but is this the person that they're claiming to be? Hmm.
What's that one thing you see people doing today that makes you shake your head a little bit and go, folks, that's no longer gonna stand. We gotta be smarter than that. Well, certainly, and this may be is a no brainer, but it's just answering, answering your phone to an unknown number and engaging in any type of serious conversation or taking any action as a result of that, you know, that, that, uh, maybe that that's no brainer, but, uh, people still do it.
I don't answer my phone if it's a number. I don't know. Um, and, and to be totally candid, even if it is a number that I know, I'm, I am much more careful these days than I used to be because numbers can be spoofed, of course.
Uh, so that's one thing definitively, but then I, I really do, I wanna emphasize this area of video conferencing because we all, we live our lives in this little window, right? We live our days and we operate our businesses on the information that we get. Uh, we can no longer trust that.
And so, um, my advice right now is to, to start viewing it as such, again, this idea of zero trust. Mm-hmm. You know, to your point, I don't even remember all the numbers I'm supposed to know.
So when I do see a number that calls me, I always wait to let it go through, and then I check to see if I've actually texted with somebody on that number, just to know that Exactly, that that's exactly the right, the right approach. I think that's a healthy thing to do. Yeah.
All right, folks. You heard it here. Better to be safe than sorry.
And all those little things you can do to protect yourself will make all kinds of difference. But we might need more tech no matter what. 'cause tech, fights, tech.
Hey Jim, thanks for being on the show. Thanks so much, Mike. Enjoyed it.
All right. And back to you guys. And Steve, Every new tool wears a scarlet letter at first, not because it's broken, but because it's misunderstood.
History always decides this the same way the output wins. The only question is, where do you wanna live. Hey everyone, it's Shimmy and welcome to this week.
Shimmy says, I'm glad you're here with me. You know, what a crazy week. What a crazy week.
There's so much going on. Originally, if you would've asked me on Monday, I would've told you we're talking about TBOs today. You know, forming their own first, their own social network, then their own religion.
Now, I saw a thing where they're actually starting a site where they can rent humans. Bogle mind boggling. But I want to talk to you about something else today.
I call it AI in the Scarlet Letter. Let's talk about it. How many of you remember reading The Scarlet Letter in school?
I see some of you aren't raising your hands. Look, the fact is, I don't even know if kids read in school anymore, but if you remember the Scarlet Letter, the poor lady had to have that a, the red a because of what she's done. But there's something that's been bugging me a while, and it, it has to do with the output of ai.
Because, you know, in a world where AI can seemingly generate anything and everything, there seems to be a scarlet letter attached to anything in everything it does. It's a stigma that somehow AI generated output is less than inferior, cheap. You know exactly what I'm talking about, because some of you are guilty of it.
I'm probably guilty of it sometimes too. Some of us, for certain percentage, we, and when we hear, oh, I did this in ai, or this was helped with the creation of ai, or this was done by ai, a lot of people just tune out. They just say, I don't care whether it's good.
I don't care how good it is. You know what? It's ai.
So therefore it's bad. It must be junk. It's less than, it's not human.
It's soulless. And what I've come to understand in talking to people about why they say that is it has very little to do with the quality of the output. It's really about fear.
And you may not wanna admit it, but I'm telling you, it's about fear you. It's fear of what can happen to you. Are you gonna have a job?
Are you gonna be relevant? Are you gonna be left behind? Are you gonna live below the AI poverty line?
Now, I don't know how long this current, let's call it scarlet letter phase, is going to going to last, but I do know one thing for sure it's going to pass. 'cause it always does. The reason simple, the rate of improvement we're seeing in AI generated work product is absolutely smoking.
The rate of improvement in he human generated work, it's not even close. Now this doesn't mean that humans don't matter. They're not important or they're not running the show.
It just means that the curve is real and eventually output and quality win arguments over prejudice and ignorance. We've seen this movie before. Now for me, it started a long time ago, believe it or not, when I was a little kid and I was a little kid once, um, the phrase made in Japan meant something derogatory.
When you had toys or items made in de de Japan, it meant it was cheap, low quality, disposable. You didn't expect it to last. It was like Tin Poy, shaky electronics and those silly Godzilla movies where you had some big rubber lizards stepping on cardboard buildings.
But you watch the movie anyway 'cause it was pretty good. Um, but nobody bought Japanese products for quality. They were made in Japan.
But then fast forward a few years, all of a sudden Japan is making the finest quality products in the world. They become world renowned for their craftsmanship. For the, the Toyota Katza, right?
The, the manufacturing, just in time inventory, precision design. Cars that run forever are electronics that define the category. Sony, Panasonic.
That stigma evaporated. Well, it really didn't. Eva evaporated.
It moved, it moved from Japan to China, right? For many of you out there, over the last, I don't know, 35 years, if you're that old, made in China, connoted a another similar kind of thing. Cheap, copied, they stole RI IP and they made a a, an inferior copy of it.
Knockoffs disposable junk. You know, over the last five, seven years, something happened. That stigma disappeared too.
All of a sudden today, China produces some of the most advanced electronics. I I couldn't do the show without Chinese electronics vehicles. Electric vehicles, industrial systems.
That scarlet letter's gone away too. And you know what? AI's right on schedule, it's Scarlet's gonna disappear too.
Let's talk about software. When I first started hearing about AI writing code, it was terrible. It didn't get the syntax right.
The logic was all wrong. There was no APIs. We didn't have MCP.
Anyone who tried it back then remembers thinking, you know, this is cute. But I would not put any production level AI generated code out in production. But here's the thing, ai, it really is learning fast, really, really fast.
And today we estimate 60% of all the code generated coming from ai. Plenty of developers will tell you that AI generated code today is roughly on par with human code, average human code. Not elite, not as good as the best developers out there, but it's usable.
It's shippable, it's product adjacent, if not product ready. But here's the scary thing that maybe no one's told you. Human code quality has basically stated a straight line for a long time.
X amount of vulnerabilities per x amount of y amount of lines. AI code quality, though it, the quality keeps going up, the vulnerabilities keep going down. So it's roughly on par with human generated code now, but it continues to go down.
And when it goes down, it's gonna be better. I know, I know I hear some of you already saying it, but shimmy, but shimmy AI will never code as well as the best developers. I agree today it won't.
But what about tomorrow? What about the day after that? That Scarlet letter isn't gonna be there forever.
Because here's what always happens. Once a tool reaches a critical mass of adoption, once it becomes responsible for a meaningful percentage of the output, acceptance follows. Not because people fall in love with the tool or forget the scarlet letter, but it's because results matter.
Results and profit beat ideology every single time undefeated. And that scarlet letter then starts to fade. And we're seeing the same thing, not just with code.
Now we're seeing with written content. You know, I still see some content sites out there. They put big banners, 100% human content, no AI used in making this content.
They wear it like a proud badge. Their own scarlet letter. I don't know.
To me that feels quaint. You know what? Maybe even a little arrogant.
'cause look, there's always gonna be craftspeople who make things by hand, one at a time. God bless 'em. We love getting handmade stuff like that.
And their work is valuable. It has value. But you know what?
Since like the early 19 hundreds mass production didn't ruin society, it empowered it, it gave rise to the middle class. It, it gave everything, right? Today we want scale.
We want mass production development. Co-development is no longer a cottage industry either is developing content, either is developing art, music, and film produced by AI is going to be the defining success story of this century. Just like mass production and assembly lines or the defining success story of the last century.
Go to Dearborn, Michigan. Go to a Ford factory. See for yourself self.
I'll tell you this, as someone who writes constantly and has been evolving in, in terms of my use of ai, let me be very clear what I think it can and can't do today anyway. I don't think AI's writing the great next or the next Great American novel or anybody's novel, not great, not today. But can it write your next email, your next blog post marketing copy or internal memo letters?
Hell yeah, absolutely. And when I say AI writes, I don't mean it writes it in a vacuum. You just don't say ai.
Write me a letter. That's the biggest mistake I see people making over and over again. I see 'em making it here at Techstrong.
I see 'em making it in other companies. I see 'em making it. Everyone I speak to, AI output is only as good as the person guiding it.
I said it before, I'll say it again. It's humans. Humans who provide the spark.
You know, borrow a line or paraphrase a line from Billy Joel. AI doesn't start the fire my friends humans do. It's that spark.
A good writer using AI will still produce better pros than a bad writer using the same tools or a bad writer. Not using ai. AI amplifies your thinking.
It amplifies your talent. It doesn't replace it. Let's move on from writing.
Let's, let's go to something even more creative. 'cause here's another area where I see craziness, right? Synthetic music, synthetic art, synthetic video.
So-called synthetic, meaning it's made with ai, it's made by ai. You know what? I've seen some people say it's soulless, it's cold, it's slop, it's fake.
I saw a guy on on LinkedIn today who, you know, posted an AI picture and put a little disclaimer, this isn't a real picture. It was created by ai. I don't care who created it.
It's still a real picture. It's just not a picture created by a human. And that's okay.
But it doesn't make it any less real. So most of the critics who, who you know, call this stuff slop, fake, soulless, synthetic. I don't know how many of them actually have listened to some of the best examples of synthetic music.
Watch some of the best synthetic videos that AI's popped up or spend time with the art that's AI is churning out. 'cause if they did, they'd be uncomfortable about admitting something. They'd have to admit that some of it is just pretty damn good and it's getting better every single day.
That's the thing. It keeps getting better. Second, just like I said, with code in writing, the quality depends on the human behind it.
A musician with skill is gonna produce better AI assisted music than someone without it. A designer with a good eye is going to create better visuals and designs than someone just clicking in random prompting. Tools don't en erase talent, they reward it and enhance it.
And AI is create AI's creating the next generation of talented tool users. Today, AI is not creating the next Picasso painting today. No, it may in the future though, given a human's input and spark.
But for a lot to what we do, 80% of what we do, social graphics, marketing visuals, short form entertainment, storytelling, TikTok videos and all of this IT friends, it's already more than good enough. It's already more than good enough. But I hear what some of you are saying.
You're saying, shimmy, we're overwhelmed. We're adrift in AI slop. There's too much AI generated content.
Hey, you know what? We're not wrong. You're not wrong about feeling that there.
No doubt it's a flood. It's exhausting. Especially some of the stuff that obviously is ai and people try to play it off as not.
But let's be honest, let's be honest with ourselves, content overload. Don't blame it all on ai. That didn't start with ai.
It's not gonna end with ai. AI just poured gasoline on a fire that was already burning. And right now, AI creation feels more to me like a kid with a new bike.
If you were ever a kid and well, you were all kids once, some of you may still be kids, but if you ever got a new bike, you remember what it was like the first day you woke up after you got your new bike. You couldn't wait to get out there. Hopefully there was no school.
You rode it everywhere. You showed it to everyone, you just kept wearing it till the tires wore out. Just couldn't stop riding that bike.
But that face passed eventually, right? Then we we're gonna go through a similar thing here with ai. I think instead of trying to use it for everything, we'll use it for the things that it makes sense to use.
And that's where we're heading. And it won't have the scarlet letter. So what won't pass is we need to rethink how we filter, how we prioritize, and how we make sense of all information.
How to pick what we should use AI for and what we shouldn't. And here's a really delicious irony into this whole thing. AI is gonna help us do that too, because it has that kind of ability.
It is total disruption. So here's my shimmy takeaway on this Thursday, guys. This scarlet letter phase of AI is not the destination.
It's no more on a mile marker, on a really great looking highway in the near future. The idea that AI generated output is inferior is going to feel ridiculous. The made by AI label is going to fade way into the background and be forgotten.
Just like so many other made in labels before it were the people who embrace AI will move faster, they'll create more, they'll compete at a different level. Those who don't will live, as I said before, below the AI poverty line, AI poverty. And that's not a threat, that's not a hype.
That's history. And that's how things work. The only real question to you guys to watching this is where do you wanna live below the AI poverty line or above it?
That's shimmy and I'll see you next week. Ai, generative AI escaped out into the internet now. AI is escaping from your data center.
Is your network ready for it? Does your network have AI for the network? Does AI AI exist in your network?
Join me on the Tech Field Day podcast as we follow up with Cisco and find out all about networking and ai. Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the tech field.
A delegate community's often record in association with one of our events. Tech field as part of the FU group in this podcast is also published us to company site Textron tv. On this episode, presented by we're discussing how AI has escaped your data center and is invading your discussion.
Meet. Hi, uh, I'm Andy Banta. I'm currently doing work with, uh, mag io and have been a longtime person in the tech industry doing storage networking.
And I'm Jack Poller. I am an industry analyst with Paradigm Technica, focused on the intersection of cybersecurity, uh, and artificial intelligence. And I'm Lee Peterson, the VP of the secure product portfolio at Cisco.
A big fan of Tech Field Day, really, really for honored to be here. And of course I'm Alistair Cook, an event lead here at Tech Field Day, the event lead for AI infrastructure field day four, where Jack and Andy attended and also colleagues of Lee's. Uh, it struck us as we're going through the, all of the presentations, but particularly this, the Cisco enterprise networking presentations that AI is both a workload, but it's also an enabling technology for the network.
And as we're seeing a bit of maturity in how companies are using aid ai, moving from just some beginnings thoughts of what they might do to actually doing useful work with ai, uh, the network has become one of those things where there's features that we might want to use. There's also, uh, much more complexity in managing that work network as a, as a whole. So, um, we definitely saw the importance of having both AI for your network, but also your network for ai.
And Andy, I wanted, wanted you to have some space on particularly that topic because I think it was one of the things you, you saw maybe a bit of confusion amongst some of the, the messages we saw at AI infrastructure. Well, Absolutely, and I mean it's, uh, we saw some presentations from companies other than Cisco networking companies other than Cisco as well. But Cisco, uh, presented a a huge amount of material and the topics kept switching where whether they were talking about the infrastructure necessary to carry ai, and that was that, uh, included like bigger, faster switches as well as more secure routing and better transport the data as well as, uh, as using AI tools to manage your network or, or to, uh, um, configure, debug, troubleshoot, configure your network as well as tools for, um, you know, AI tools for doing things like using, uh, location with, uh, wireless devices.
So there was a lot of, um, it was sometimes you needed like a scorecard to be able to keep track of whether we were talking about the infrastructure necessary for AI or how, uh, Cisco was presenting these infrastructure to enable it to, to enable their own AI for their own purposes. And it was, uh, was just a very interesting mix of topics and goes demonstrate what AI infrastructure means, uh, to these field day events where it's, it's both enabling the AI and the AI is enabling the infrastructure. I think what makes it really interesting in addition to that is it's now becoming a self-reinforcing positive feedback loop where you enhance your infrastructure to enable AI development, and then that enables you to develop, uh, more complex AI models that allows you to both fine tune your network as well as to manage it, troubleshoot it, and build even better and faster and, uh, infrastructure for your AI development.
So there's a lot going on that Cisco presented. The other part that I thought was interesting is this what, you know, sort of the premise here that we're talking about is AI escaping the data center. And traditionally we think about AI and giant data centers and training on the data centers, and there's not as many people are gonna be doing that as they are going to be doing inference and particularly inference at the edge where you have devices that are going to be generating a lot of data, moving a lot of data around and wanting to do analysis and AI with that data.
But you can't transport that back to a core data center to do your analysis because it takes too long and it costs too much time and bits moving down the wire. So you wanna move your AI infrastructure to the edge and all of the various different technologies that Cisco is bringing to bear to support that, both as networking infrastructure for ai and again, the ability to apply AI to help you build that type of infrastructure. I think what's interesting with that latter point that Jack, is that if you think about four or five years ago, most of the CIOs, CTOs were saying, we're gonna just move everything to the cloud.
We're gonna put it all in, uh, relying on the, on the, uh, hyperscalers that run these workloads for us, what we're seeing more and more is now it's much more federated. So obviously the, the, the AWSs and the Azures and the Google clouds, the world are going nowhere. There's still a very important element, but we're seeing more of a mix where also investing in the, in, uh, our customers in their own data centers, investing in colo facilities.
And then of course that idea of what can I do at the edge, particularly when it comes to those, those heavy DPU workloads that are maybe from an interesting perspective, more, uh, effective to do closer to where I need that done, where I need to be able to actually make a decision on something. Think of things like video applications, think of things like small language models from a chat perspective, much more effectiveness doing those at the edge, both from a cost perspective, but also just from a, an outcome perspective of what those customers trying to drive. Yeah, I think, uh, one of the things that I've seen over the course of Tech Field day and other presentations is that, you know, we tend to think about AI right now as we're hyperfocused on large language models and the chat GPT type things.
There's a lot of AI applications that are go beyond that or analysis of real-time analysis of data. For instance, every time you make a credit card purchase that goes back to somewhere where there's a decision made, whether that's a fraudulent charge or a valid charge, and there's a lot of data that's collected in order to make that decision. But you wanna make that in real time.
You don't want somebody to put their credit card on the reader and then wait a minute for an answer to come back whether this is good, uh, a valid or inval charge. Um, we've also seen things where you're doing sports analysis or applying AI to motion tracking and all of that has to happen as close to real time as possible. So the, the lag of moving that data into the core, whether it's on premises, uh, core data center, or whether it's moving to the cloud, sometimes that can be too much.
So there's a technology driver and a motivator towards, uh, putting stuff in your own compute infrastructure where, where, regardless of where that is versus renting that infrastructure from the hyperscalers. But there's also use cases where renting hyperscaler you can take advantage of their economies of scale. And it does make sense still.
So, and I mean, a couple of the examples Jack just talked about are talking about, uh, potentially data centers sized, uh, you know, models that you need to work with, whereas there was, uh, some discussion last week on a couple of the, um, places where you don't need data centerized models. Uh, one of the examples I remember was controlling robotics where you, uh, you would, you basically need a factory sized model to figure out what's going on. Uh, and the other one that wouldn't impress me was the, the ability to, um, feed in information about your enterprise network to the AI assistant and have the AI assistant use both the, the source of knowledge from Cisco as well as information about your local network to be able to better answer questions about your own network.
So these are, these are two examples of really edge based systems where it's using the local data rather than drawing from a huge bottle. And, and just to sort of take both of those points together, if we think of the, the robotics use case, the, the, the most of the factories that are doing things like loading and moving things around using robotics now have a rule that if any one of those robots goes missing for more than 250 milliseconds, every piece of robotics in that, that location shuts down because the, just the risk of, of human life, the risk of damage and things like that. And so that's really why it, it has to be done at the edge.
Uh, so the second point around, uh, then how do we extend some of these AI approaches and apply them to, to the technology itself? Uh, the MCP server approach is very interesting. So, uh, a lot of the investments we're making in, in AI within Cisco, we've developed this deep network learning model.
So we know networks better than say general purpose LLM, those networks. And we've been able to take, we had the largest data lake from a networking perspective of anyone in the industry. We've been able to use that to go train these models.
We able to take what we know from 30 years of running CCIE courses and all that knowledge, we've gotta take every support case that's ever been entered. We've been able to put that all into the soup and produce a model that's much more effective in terms of analyzing a network and, and understanding what's going on with it and making a sensible set of recommendations to further that out, though the idea of using MCP to further enrich that because there is gonna be data our customers have in their networks, customers have about their own applications that need to be, uh, sort of correlated somewhat with what we know about the network in order to be able to actually produce a, a, an actionable outcome to be able to make these networks better, faster, more reliable, and ultimately in service of driving employee satisfaction and customer satisfaction to let these businesses do a better job. This is where I think it gets to be a little bit of a blurring of that line between networking for AI and AI for networking where there's more of a feedback loop between those two parts where the actual data that, or that the AI that knows about how the network operates can be published out through CP so that the AI that's delivering some business value that might have some dependency on that network can talk to the, the network, the AI for your application and can talk to the AI for your networking.
And that's, this becomes a bit of a blurring of where you've got just pure infrastructure that is there to host your ai and where there's an AI in that infrastructure that's assisting the AI that's doing something for business. And this is where the whole idea of agent to agent communication and, and the MCP standards and some of this emerging cooperation between different parts of the, your AI estate become really crucial. One of the things we had joked about, um, during the presentation was do could the, uh, Cisco's LLM pass the CCIE exam?
And we were joking about it, but in some sense it's a really important point in that there is a tremendous amount of, um, tribal knowledge that has been developed over decades that Cisco has, uh, both just from the telemetry Cisco's collected and just the tribal knowledge of the CCIS and all the different people involved in this that, that you're able to bring to bear. And when you tie that in with the ability to have an agent query and get the very quickly, get the information it needs and apply, uh, changes as quickly, then you, that that sort of automation and feedback loop that Alistair was talking about becomes very powerful. And that's I think where Andy and I are very interested in, that's that application of AI for networking that isn't just, hey, we're, you know, it's not, it's, it's, uh, not a variation of, um, the traditional Silicon Valley of let's do the the next version bigger, better, faster.
We've got, you know, we've gone from a 400 G to an 800 G network, look at our switch, right? It's a lot more than that. These things are actually, are actually starting to have value above and beyond just the ability to move packets back and forth.
And I think that's very interesting and very valuable to, and to AI and even to non-AI data centers. Right? And, and I mean, regu, when the, the question came up about passing CCIE, uh, even pointed out that the, the exam itself includes lots of questions and, and just learning the answer to the questions is one thing, but one of the tests for CCIE is that you actually need to build out a network.
And it would be very interesting to, to, you know, see AI assisted get to the point where it could actually build out a network. And, uh, you know, this, this gets into the idea of AI feeding ai. Where, uh, could the, uh, could the AI assistant start figuring out that its own demands on the network were increasing the load on the network and therefore would need to expand the network?
I think there's an interesting sort of, um, parallel to this. You know, they can build an LLM that can pass the bar exam. You can build an LLM that can pass any sort of medical exams.
I don't want an AI lawyer and I probably don't want an AI doctor. And so we think about this the same way we ask ourselves the question, if A-C-C-I-E was standing in front of this screen right now, seeing what I'm seeing, what would they do based on using all that knowledge? They're very much designed around how do we do human and loop?
You still need to have some level of hands on the wheel to make sure that we don't set these things loose and have it make changes that adverse effects. The difference is though, that where this is gonna enhance the workflow for most of our operators is that that engine is able, that agent is able to look at these things at AI scale. So it's ability to look across large data sets and infer the interesting parts of that, because a lot of the time when you're doing this troubleshooting, 95% of the things you look at are dead ends being able to sort of jump straight to the root cause and go, this is the problem, and if you do this, we'll fix that.
And as we get more confidence over time, there'll be certain things that are routine and mundane that we say, Hey, you know what? AI agent, you make that change for me, monitor that change and roll that change back if it has an adverse effect that we didn't expect. Right?
And I mean, it regular been pointed out that, uh, the, there's the trust factor and right now it simply makes recommendations without actually acting on them. So it it can help it so it can build the trust. Yep.
And part of the trust is, hey, I've seen this. I, I, as the agent, I've seen this before and another network and I've made this change and this was the, this, you know, based on the, the millions of, of pieces of knowledge I've got about networks and the effect of making these sort of changes, I believe this is the best course of action for you. Right?
And you'll over time build that trust as you see that, do that and enhance that workflow. There's, there's another aspect to this, which I think we're somewhat alluding to, which is, and you know, and I'm a reformer reform software and hardware engineer and you know, I no longer code and 99% of the people no longer code in assembly because we trust compilers to do that job for us. And in fact, most people no longer code in C because we trust a high level compiler to do it in a very high level language.
And one way to look at the LLMs as well, we're interacting with this complex machinery at a very high level instead of at the very low level now. And it allows us to go from the pain and effort of having to manually tweak every single knob in the environment to, and to look at every single configurable item to see exactly what the current state is, to have the AI do a lot of that heavy lifting for us so that the human in the loop is involved in, I think this is where you're driving at the human in the loop is making a higher level decision making. It's not saying tweak it.
I want to tweak this particular command line, do this command line to make this parameter on this particular interface change, right? It's basically saying the AI is saying, I'm applying, it changes, and this is the list of changes. Does that look good to you?
Just review it rather than thinking about it all. And in fact, at some point it should be able to say, I'm going to make a change to make the network do this at a very high level instead of change interface one, interface two, and have a thousand changes. All of that's gonna be hidden, hidden by, in higher level language.
And that the value of that is tremendous in terms of changing the workload on the limited, the most limited resource we have in the enterprise is the humans, right? We, we have infinite number of compute cycles relative to humans. And, and I mean, I I think that if I was, uh, a network administrator, I might want both.
I might have, I might want something that says, we're gonna apply this set of commands to these switches and this is what this, this set of commands does. Yeah. And where, where the, the, the element of this is that that it gets, it's a true intent based networking.
We've talked about it for a long time. My ability to express in English what I would like the network to do and have it implement it doesn't mean that you, you can, I can have my 15-year-old son walk in there and with no networking knowledge and do that, you still need to know what you're doing. But a great example of that is we built into, uh, there's this approach we're taking within my product, uh, portfolio called Unified branch.
It's the ability to deploy a full stack of networking in a repeatable fashion across thousands up to, you know, 10,000 plus locations. And it starts with going into the assistant and saying, please build me a branch design based on a Cisco validated design for unified branch. And because it's a validated design, 'cause we've tested it, we pull forward what we believe the right, uh, defaults are, and you, you manually inspect those, you know, you can tweak some things and change some things and then when you press go, that agent goes in the background as the logical deployment associated with that network.
And what you're really doing then is you're reducing the amount of time upfront, reducing the risk of error. And when it comes time to do that install, you're reducing the technical capability of the person going on site to do that install because it effectively becomes plug and play all the design work and all the configurations done, send somebody out there that understands low voltage cabling and how to, how to physically wire things up and physically mount things. And, uh, they don't need to know DHCP or DS or any of the things that, you know, a network engineer would need to know to go configure that from scratch.
If I, if I can mention another topic here, the, one of the other things that fascinated this discussion was network where, uh, it, the way it was described, it could almost paint a picture of where the wireless devices are in an environment without having any cameras. And that, that I thought was kind of cool. The idea that just to define time management, it could actually locate in a, in a room or in a, a building where all the wireless devices are and essentially draw you a map to them.
I think our ability to match the physical world and the digital world together in an interesting way, and sometimes that means physical sensors, cameras and what have you, but we can infer a lot from that digital footprint that devices leave behind in order to be able to paint a pretty rich picture there. Uh, wireless portfolio is super interesting. They've been doing AI before it was really, you know, the, the thing Azure Radio resource management, having a, a, a model that understands making changes.
'cause no, you're typically not tuning things like channel selection channel with someone have you on the fly manually in a network. So the ability, again, using that, those large data sets to say, look at all the radio environments that I understand and what's, you know, almost like a digital twin approach, what's similar about this one to other networks I've seen? And if I make this change, this is the expected result.
And it's able to read that out to you, but it's not gonna come to you and say, Hey, I suggest we we turn DFS off on this channel and we move from this channel to this channel, or we, we lower this channel with, that's not the way our radios work. They've tended to self optimize for a time, but AI has allowed that to get much more effective and, and much more better understanding causality. I make this change, I see this result, and if that result is good, I leave it.
If it's not, I roll it back and try something different. What's interesting also is that the wireless has gotten to a point now where it's not either a secondary communication channel or just for users and laptops, right? We're now using wireless, as you said, in robotics, right?
In ai, we are moving enough data across the, the wireless networks that it can be a backbone, particularly at the edge for your AI information that's moving back and forth and what you're doing with ai. And I think that that's, you know, we have to change our perspective and, you know, on, on what the, the communication channel really is and why we're using it. And, you know, why would you drag a wire any everywhere if you, if wireless is capable of doing all of these things.
Um, some of the things that Cisco presented was about the, and I don't remember the name off the top of my head, but the, the, the multiple antennas, and I know there's MIMO and, but there's just, you have so many antennas and the ability to do so much with that, that gets you much better, uh, interference, uh, capabilities and, uh, uh, was it, uh, reliable wireless networking? I think ultra reliable. Yeah, ultra reliable wireless back all, it's a super interesting product because I mentioned those robots don't have time to roam from one access point to another access point the way a traditional client would.
And so we've built the ability to run standard wifi your, your standard, uh, IT environment combined with your OT environment in the same hardware unit, and be able to manage those through the same domain. And the robots are gonna use the, the ability to connect to multiple access points at once and your standard device, you know, your, your, your, um, tablets and things you might be using as a human in that, that factory space or in that warehouse space, continue to use standard wifi. So really, really interesting, uh, evolution of how we do things.
And again, it just means we're getting richer and deeper sets of data about what goes on in those environments. And our ability to do that inferencing and be able to make intelligent decisions about that is what's gonna drive a higher quality network for our customers. And it should largely be invisible.
I I joke that the, the networks like oxygen, you only notice that if you're not getting enough, right? It should really be in the background there supporting the things you're trying to do and be able to, to do that in a very intelligent way. Well, I think that's, that's actually a very interesting perspective in looking at it for ai, right?
And thinking about the AI network, and right now, I don't think we can look at it as oxygen. When you think about in, you know, a lot of what we're talking about both AI for networking and networking for ai, but specifically networking for AI is we are placing such heavy demands on the network that we can't, we're not at the stage right now where we can treat it for as, as oxygen where it's just in the background. It is a critical component that if it is not in, not architected correctly, the network itself isn't designed correctly, then the AI is not going to work the way we want it to.
Yeah. And that plays both in, in data center, but also in, in the wider, across the multiple presentations we had from different business units within Cisco AI infrastructure field four, we saw that, as I say, the, this is not, not yet a place where you can say a standard network design is gonna be am for everything I need. I'm not gonna need to be constrained both data center and and beyond out to edge.
And we know that networking out to a cloud is also a significant impact for us. Um, yeah, it's, it's a long way before we can just assume the network is good enough because it's there. And I think that's, that's a path that, that Cisco is, is definitely on.
And I think within the Cisco teams as the, this skating well ahead of, of, of where the puck is for most customers at the moment, because these technologies do take time to get out, we we're seeing, uh, a bit of a rush amongst customers to, to realize that their networking inside their own organization needs to get better to deploy AI as a production workload, as something that's delivering business value. And yeah, it'll be a little while before they, it's, it's an oxygen default kind of supply. Right?
And, and I mean, one of the things that Cisco brought out was the fact they're merging essentially their on-premises data center or, uh, enterprise networking tools with their, uh, cloud networking tools. And they talked about the features that these actually can also look at software well and be able to manage those the same way as well. One of the aspects we really haven't talked about here, I'm sure Jack would love to talk about, is all the additional security that this, these things bring up.
Uh, we talked some about secure routing last week and all the, the additional features that were needed for secure routing. And I don't think that we really have paid enough attention to how much additional, uh, infrastructure and horsepower is needed to actually do the level of security that we're gonna need in an AI ready world. Yeah.
One of, one of the things that Cisco is, I think, very proud of and rightly so, is, uh, the inclusion of, uh, PQT or post quantum cryptography in the hardware, uh, you know, in the devices, and particularly having hardware enablement for it, because as Andy said, um, doing cryptography and alone is very, uh, is computationally expensive. So the ability to have hardware that accelerates it and have, uh, the post quantum algorithms involved means that we're already prepping for it. We run have a rate, great risk right now of what's called harvest now, decrypt later, where somebody grabs the data, holds onto it for a while until that data can be decrypted.
And a lot of the data that we have is very ephemeral. We don't really care about it after a couple of minutes, but there's a lot of critical data that crosses a network that is actually very long lived. That is, should somebody get a hold of it?
It becomes very, you know, and a lot of that we think about things like PII like our, our personal identifier, social security numbers, or whatever the equivalent is in the European countries. Should somebody get a hold of that now, then, you know, at some future date they can decrypt that, get access to it, that opens up a whole ball of wax that we don't wanna, you know, we don't want people to get access to that data. So the ability to have a quantum safe encryption of that type of data is very critical, and we need to do that now rather than tomorrow.
I was gonna say, some of the ephemeral data that you talk about, Jack, is, uh, is ephemeral to the source, source and destination of it right then, but if it's information that can be held onto and decrypted later, it can be used to do predictive ana predictive analysis of what's gonna happen. And think about this in terms of robots, where if you're able to gather the information that's being fed to a robot, uh, you, you can probably say, the robot did this, and therefore if we wanna interfere with that robot's operation, uh, we know that the robot's gonna be doing this at this time so that we can interfere with it there. And so it's one of those things where it's not just personal identification, but it's also being able to pick out patterns and use them, uh, against both people.
And, and, um, robots, Before we, Before we get too far into this rabbit hole, I'm gonna have to put an end to this conversation because as always, when I get a group of my delegates together and particularly bring along some expert from within one of our, our sponsoring companies, the conversation could go on for hours. And I know we're already at about time, so if people do wanna continue this conversation after they've, uh, listened to this podcast, where can people connect with you to continue that? I answer every DM on LinkedIn, so my LinkedIn is open, looking up on, on LinkedIn, not hard to find.
Um, that's the best way to start the conversation. I'm, I'm more active there than I am on, on other social channels. And, uh, you can also find me on LinkedIn as well through dms or at, uh, paradigm technica com And you can find me on LinkedIn and, uh, blue Sky Social and, uh, on my periodic blog post at and com, I'm analyst, you can find me on Tech Field daycom.
You can also find me on LinkedIn and across all of your favorite social media, the same as you can find all of the Tech Field Day team on all of the social medias. Also watch for us on Techstrong TV and across a bunch of the other places that we work with the wider future and groups. So thank you so much for listening to this episode of the TE Field Day podcast, and please subscribe on YouTube or in your favorite podcast application so you don't miss an episode.
Make sure to give us a, a nice high rating, nice review as well so other people can find us. And this brought podcast was brought to you by Cisco and Tech Field Day, the home IT experts from across the enterprise and a part of the episode podcast listening, Permitting AI work. MCP is still flawed.
Snowflake partners with open ai, Oracle's uncertain on Cerner automation flaws abound, wifi bugs are still out there. And we're gonna take a closer look at some molting claws in this episode of the Tech Field Day Rundown. Greetings everyone, welcome to the Tech Field Day rundown.
Hey, did you know that we're not quite 10% done with the year because it's February, it is February the fourth as a matter of fact, and we are very happy to be here on the tech field Day rundown. It is national homemade soup day. And, and I don't know about some of you because I know it's cold in the country.
It it's like 60 degrees where I'm at a soup. I don't know, maybe I, I guess, but, uh, one thing that I am certain about is that my co-host, Mr. Alistair Cook, is back from his sojourn to the northern hemisphere.
Al, it's good to see you. It's a pleasure to be here. And I managed to stay in the warm parts of the Northern Hemisphere, despite it being the cold time of year.
Uh, incidentally, it's a national day for New Zealand at the end of this week. February 7th is our national day. Why tan you day?
And, um, it's an experience to look forward to. Another experience to look forward to, of course, is all of the stories we have today. Exactly.
And, uh, we we're gonna kick 'em off. 'cause I mean, there's some security stuff, it's kind of funny, uh, but of course there's some AI stuff that maybe is gonna help people be more funny. Uh, hundreds of top actors and musicians have launched a global campaign that is accusing ai companies of stealing copyrighted work to train generative models backed by major unions.
The human artistry campaign is calling for a permission first approach to AI warning that unauthorized training threatens jobs and the future of human creativity. The fight comes as parts of the music industry begins. Striking licensing deals with AI firms and revealing a growing divide be between confrontation and collaboration.
Now, I was gonna put a really pithy joke at the end of this, but I couldn't get any of the AI agents to come up with a really good one. So I guess I'll just turn it over to you. Is trying to create a collective amongst creators going to get the folks that run these AI algorithms to actually do what they're supposed to do in the first place?
Maybe, but probably not. Uh, the AI vendors build their large language models by harvesting everything they can see on the internet, whether they're supposed to or not. And that part's up for debate.
We already covered this a a couple of times, I think on the rundown, talking about some of the court cases that are currently in play around fair use of content. And all of the AI providers say they're just fair use. We're just taking little segments and we're, uh, generating something that is a combination of multiple sources the way a human does when they read content.
Uh, the challenge, of course, is that the rate at which content is being then spewed back outta these large language models. It vastly exceeds the ability of human creators to actually create content and, uh, a large number of content creators. And this includes, um, in this case Sha Kahan, Kate Blanc and S Johanson are unhappy that the things they've been creating over their lifetime have been harvested and are now being used to generate AI slop.
Um, I believe that was actually mentioned at the quotes, uh, basically American sideline creators are being sidelined, not just American, but that's where this, the jurisdiction where this is being fought is about American, uh, creators. And that's essentially the whole spirit of human creation is being diluted by these large AI models that have stolen previous creation. So, uh, it's a continuing story.
This is definitely not one we've heard the end of. Even though organizations like Open AI have already struck deals with music publishers, they haven't yet struck deals with book, uh, creation or movie houses. And so we probably will see this, we'll see a, a shift from the sort of confrontational, you can't do this to actually we can be in business together and all be successful.
You, you can compensate me for the things that I've, I've created that you're then reusing in the same way that, uh, libraries pay royalties, radio stations, pay royalties, AI companies will be continuing to pay royalties for more and more things. Um, leads us to some concerns about how things go when the, uh, recalculation of the AI AI market and the AI infrastructure market comes up. Uh, it's also probably gonna be yet another barrier to new entrance into creating large language models.
Not sure that we need new entrant creating new large language models, but that's part of how, how industry works. So yes, this is a continuing battle. This is another group of creators who have seen that there's been success by other collectives and are aiming to have more success.
I think more likely the large AI companies will talk with the publishers rather than the creators. So it'll be the large organizations like the, uh, movie studios and the large book publication houses that actually do the negotiation with the AI vendors. Uh, it's unlikely to be the, the smaller organizations that just don't have the financial clout of these, uh, large publishing companies.
Of course, our stories all revolve around AI all of the time at the moment. And, uh, we've noticed that, uh, security re researchers have found some vulnerabilities in CP servers, uh, those from Anthropic and from Microsoft. And it highlights the growing risks around age systems.
And those, these particular flaws are ones that would allow, uh, sensitive data to be exfiltrated or, but have code execution, uh, running inside the environments where the, the data or originally resides. Uh, experts warned that the MCP adoption is growing, but as I've said earlier today, the S and MCP stands for security. And so you've gotta bolt security and controls all around this.
Uh, and this needs to be done very, very rapidly because m CCP servers are proliferating in a being a headline thing. Uh, Tom, have we seen the last of these big security vulnerabilities in MCP servers or is this going to be a story for the agents? I feel like we probably do the story every week and it would still be relevant.
And the reason why is the oldest problem in security. Well, it's that guy's job. Uh, I don't know why you, you are getting onto me.
I wrote the code, I didn't know I had to secure all the function calls. What, what, what do you mean it's, it's in the server, right? I just hand it off to them and it works.
And where have I heard that before? So one of the things that we've, we've been dealing with a lot is this idea that these AI agents can just pretty much do whatever they want, and that doesn't really work very well, right? Like we can't just have 15 people, um, you know, requesting assets along the way.
And let, let's just assume for a moment that these AI agents are digital coworkers and not just scripts that are tools. Um, I want you to imagine in your office, let's just say for example, that there are 15 people running around and they all need resources and, and things from, uh, on high. Do you let them go talk to the CEO directly or call and, and buy things without that?
Or do you have a process for approving those things? And do you have, uh, guardrails in place so that for example, your employees don't go out and buy $4,800 worth of ballpoint pens? I, I'm guessing that you do, right?
That all gets funneled somewhere. And then there's a person who looks at things and makes these these judgment calls. Hey, guess what?
We have that in the AI world and it's called MCP, but I'm gonna tell you a little secret folks. MCP does not have native security. It's not designed to do that.
MCP servers are chokepoints, it's checkpoint charlie, if you will. And if you're old enough to get that reference, you probably take ibuprofen before you go to bed tonight. MCP servers need to have security attached to them.
That means we're all gonna have to get real smart real fast about where the security controls are. Because one of the things that was reported in this excellent article that I will come back to in a few minutes, so put a pin in that, is this idea that we are rapidly expanding the capabilities of these agent-based tools without checking first to see what kind of security is in place to prevent them from doing things they're not supposed to. In this particular case, one of the things that happened with the Microsoft law in particular is that a lot of the, uh, the tool sets that work on the backend were written in markdown.
Markdown is fairly easy to understand, but if you don't put any kind of guardrails in place, people can inject just about anything into markdown and make it happen because it is a plain text language. And so that's one of the things that you will see more about soon. We have to be very serious about this.
We have to create structure that includes security as well as helping people understand that there's no inherent security in using MCP and MCP servers unless you put it there. And if you didn't put it there, assume you don't have any at all. So I think that we're gonna be talking about this story for quite a bit to come, and I hope that I'm not talking about the same companies having the same problem over and over again.
Snowflake and Open AI have announced a $200 million multi-year deal to embed open AI's advanced AI models directly into snowflake's AI data cloud for enterprise use. The partnership allows companies to run AI agents alongside their own governed data across major cloud platforms, reducing security and compliance risks or so they say by focusing on deployment, governance, and real world business use, the deal signals a shift from AI experimentation towards scalable production ready enterprise ai. Al do you think snowflake's getting the better end of this deal or do you think Open AI is just trying to get another logo added to one of their slides?
Oh, I think this is definitely a, a great deal for Snowflake. Uh, snowflake has been progressively positioning themself as the place where you put all of your data that you wanna use in your AI applications, then something's gotta link those AI applications to that data. And when that's a cloud delivered AI model that's, uh, sitting in somebody else's cloud tenancy, in this case, open AI's, cloud tenancy, uh, there's some more security concerns around that.
If we can push that AI service inside snowflake's tenancy, there's one less security boundary we're crossing as we're doing these AI things. Uh, one of the fun things I saw in this is of course, snowflake being available across all of the major, uh, public cloud platforms means that they kind of a data standardization, or they, they erode the differentiation between those clouds make it easier for companies to use the same snowflake data platform across multiple clouds, wherever the data needs to be ingested. Now they're adding the open AI large language models and agents inside that same cross cloud platform where you're not nearly so tied to a single cloud or, uh, uh, essentially it's a, a meta service provider going on here with Snowflake.
And now adding these features on open AI likes this because it takes away some of the objection handling of taking your company's sensitive data and pushing it across the internet to open AI's servers. Uh, this places the data governance alongside the execution of the AI model. So that seems to be a good thing, and I like that this isn't just a, we bundle the two things together.
There's a commitment of the engineering teams to work together to particularly improve open AI's SDKs, their software development kits and their agent kits, to make it easier to create the agents on top. I've gotta think that we'll be very helpful for putting a ring fence around snowflake's clients at making sure that nobody wants to exit Snowflake service. But it will bring quite a lot of value to particularly the organizations who are wanting to use, uh, open and snowflake together naturally.
This is still early on, early on as a rolling theme throughout AI tools and Ag agent ai, uh, security of data, security of execution, security of ai. Um, we'll continue to see that need for, uh, security as we see AI being deployed at scale, particularly ag agent AI at scale. It's gonna be an ongoing story.
Just, you'll, you'll hear us talking about it a lot. Another topic we're gonna talk about a lot is some of the consequences of spending a lot of money to build out for ai. And Oracle is currently reportedly considering layoffs of up to 30,000 of the staff, as well as the sale of the entire Cerner healthcare unit that only acquired four years ago.
This is coming about because Oracle is under increasing financial pressure and having higher costs to borrow money to build out the hundreds of millions of dollars worth of infrastructure. Um, despite for, for these, uh, AI projects, um, despite these challenges, Oracle says, uh, they remain committed to its long-term AI and cloud strategy. Thomas, is that a good strategy That remains to be seen?
Because all I've seen so far is that a lot of companies are going out there and buying up huge amounts of assets and then realizing they don't have a payoff strategy for this. Uh, I don't know if you guys have been following Nate Jones on, or Nate b Jones, I think is his actual, uh, name on, on YouTube. He also has a substack and a bunch of other things, and he's one of the people that kind of first brought this idea into my head a few months ago.
Um, these companies make money, right? Like we know that we, we've seen the quarterly reports because as soon as they release one, it's all we can talk about. And they make a lot of money, but they're spending a lot of money, right?
Like, this isn't a thing where they're creating value in a cloud somewhere. They are literally buying infrastructure in the hopes that down the road, they're gonna be able to pay off when, well, according to what Sam Altman said at the Cisco AI Summit, you know, that, that, that there's some big huge breakthrough. There's a chat GPT moment, which I thought was kind of amusing coming from that guy.
Uh, but one of the things that happens though is that that money is owed to somebody else. This isn't like an Elon Musk thing where I can just trade money between a couple of companies that I own, and it all works out in the end. Or that weird circular logic problem you have where like Nvidia buys a $2 billion worth of stuff from, uh, from a company that's then gonna turn around and buy $2 billion of stuff from Nvidia and like the money that does, that's not what's happening here.
What's happening is, is that a company is giving real money to another company, and that money has to come from somewhere. Now I know where it should come from because I have a business degree and I took business accounting, oh God, uh, 30 years ago almost. Um, that money to buy that stuff comes outta your profits.
You know, the money that's left over after you've paid off everything. So like, if I paid all my salaries and I paid all of my bills and all that other stuff, and all the money that I have left over, I use that to buy things that I need. Like that's business 1 0 1, right?
But that's not how business 1 0 2 works in 2026 because the profits are what the shareholders deserve. And if they don't get their profits, they might sell their stock, and that might cause the stock price to go down. And that might mean that Larry Ellison can't buy a TV network, allegedly.
So what they do instead is the same thing that Amazon's doing. It's the same thing Oracle's doing. You gotta make the numbers work somehow.
Well, remember how I told you that you, the profit is what's left over after you pay your bills, like your people's salaries. Aha. Haha.
If I can reduce the number of salaries that I have to pay that it means I can cut the overhead and the money that I need to use to pay out, all of the stuff is gonna come out of that instead of out of the profits. So, you know, why not lay off 30,000 people that make, uh, you know, a hundred thousand dollars a year? Uh, what is that?
That's still not as much as we're spending on ai, but the important thing is, is that it looks like we're trying to do this. Why not sell off Cerner? Well, great.
What are you gonna do with the money? We're gonna plow it right back into ai. And, and when you hear people talk about this, their, their thought process behind the whole thing is, well, if we can just build enough ai, if we can just build enough supply, then people will have to buy it to do what?
Exactly, because I think we tried that one time with tulips, and I seem to remember reading about that. In business school, J Rog researchers have uncovered two high severity vulnerabilities in the innate n AI powered automation platform that could allow attackers to remotely execute malicious code. The flaws which affect both JavaScript and Python execution are considered very easy to exploit and highlight the growing security risks of, say It with me folks, AI driven automation tools.
Organizations are using N eight N and they are being urged to update immediately and rethink patching strategies. Because one of the things we're seeing is that AI is shortening the time between vulnerability, disclosure and active exploitation. It's almost like people are able to get AI to actually jump out there and start doing this.
So, al my question to you is these two severities that were uncovered in N eight n, does that mean that people really should be thinking more carefully about how they're deploying these tools? Or should they be rethinking their patching strategies to keep things up to date more quickly? Uh, and the answer of course is why not both?
Yeah. Four dose. Yeah, I, these are pretty high vulnerability.
5. They're both remote code execution vulnerabilities. 5, little harder to achieve, uh, but running that code inside whatever platform you're using in a n and NAN is a, a workflow automation tool, uh, that uses essentially a Gentech AI in the background.
Uh, consequently this falls into our top theme of today, uh, security for your, uh, agents. Uh, a couple of elements in this. One is that the NATM platform can be run as a cloud service, in which case, uh, or consumed as a cloud service, in which case you should be consuming the latest released version at all times.
That's what cloud services are about, right? You, you rapidly release all of the latest versions. I hope the cloud providers that are delivering, or at least the the N 18 cloud service does this, but you can also deploy this on premises, and that will be a pretty common mode for more regulated, more controlled, uh, enterprise use, or there's a whole lot of personal use of this as well as I've seen in my, uh, news feeds too.
Uh, fundamentally, if you're running it on premises, you, you have to keep it patched and updated. And there's nothing specific to NA that is, is here vulnerability due to, uh, the speed at which AI tools can scan and discover faults? This is, this is not specific to, its absolutely across your entire IT estate.
AI tools can find and manipulate and, and, um, exploit these security vulnerabilities very rapidly, far faster than a highly skilled human being, and certainly faster than the script who used to be your biggest concern. Uh, this does then bring about some thoughts around, well, often the, the known vulnerabilities have a known resolution and known patch resolution that we simply don't deploy fast enough. Now, if most vulnerable vulnerabilities were never exploited in the wild, this wasn't so much of a concern.
But if now it's conceivable that every vulnerability will be exploited within hours, today's of it being known to somebody, what discovered that does then make us think about how quickly can I get patches out? How quickly can I safely get patches out? API AI can help us with this.
There is absolutely a market around, there is a set of products around that will help you with understanding which updates, which types of updates to which types of software are safe to deploy at great speed, and also to discover if a fault has occurred and roll those back. These are the AI site reliability engineering tools that look at all changes, not just patching. And so like alcohol being the resolution tool and source of all of life's problems, AI is going to be the source of and resolution to many of our problems in IT infrastructure over the coming years.
Hey, this story doesn't have AI in it. A newly discovered, uh, vulnerability in Broadcom wifi chip sets has allowed attackers to knock entire five gigahertz wireless networks offline with a single un authenticated signal forcing a manual reset of the affected servers. The floor was discovered through fuzz testing, uh, sending random signals into a, a, uh, system under test, and it affects widely used hardware and raises sincere concerns about business continuity, reliability, and trust in these always on always accessible wireless networks.
Patches are available, but physical device firmware updating cycles means that this is gonna take a while to get out, particularly as wifi has become an incre increasingly high criticality service within organizations. Uh, is this a reason to have some sort of diversity in the wifi hardware you have out? Or is there some other way of mitigating this risk?
Well, it's kind of hard to do that because typically you don't buy Broadcom access points, do you? You buy from a company that buys from Broadcom and uses the wireless chip set as their underpinning. So you may not actually know whether or not you're operating one of these chip sets that's, uh, problematic.
Uh, that's why you really should be patching on a regular basis. And, and just so you know, because, uh, this is five gigahertz specific, a lot of people are like, oh, that must be bad. 4 gigahertz band offline with a single unauthenticated signal when I pop popcorn?
4 gigahertz, uh, spectrum completely offline. So the problem here is that you can send a malformed packet to one of these access points and, and it basically causes it to freeze and it needs to go into, uh, you know, you need to go bounce it. And, and I get that, like that's a problem that a lot of people have pointed out.
Why do we allow that to happen? Oh, I don't know. Why do we allow these access points to scan for clients and offer wifi networks and all these other things while being unauthenticated?
Why, why do we offer guest networks in, uh, restaurants and sporting events and things like that? The problem is not with the authentication mechanism that that's, that's not, uh, uh, up for debate. Because if you have an authenticated network, that means you have to need to provide a password somewhere.
It means you need to write it down, which means you need to restrict access to it. I applaud the researchers that found this for fuzzing it out enough to go, wow, nobody really thought about this, because it is, it's a fundamental 8 0 2 point 11 problem that's down, you know, at a protocol layer. Nobody's gonna see this unless they're looking for it and unless they're trying to to do that.
And bravo to Broadcom for getting the patches out on time, but this is a good thing. So, yeah, everybody stop. We put the keyboards down.
This is a good thing because we found it because we can patch it and because we can keep it from happening. Again, this is not something that was found by a security tool that was like doing millions of iterations on the 8 0 2 point 11, uh, standard document and found this one little weird thing. This was the kind of real security research that we should be doing more often to find these problems.
And, and I want more of that because if we can find these things before they hit prime time and become massive flaws across the entire system, then the patch lead time that we're talking about becomes a little bit longer. Because then that gives Broadcom a chance to issue a patch that then other organizations that use Broadcom hardware can implement. And I will tell you that wifi people are actually some of the best ones about pushing patches out pretty quickly because all of my wifi friends out there, you know how big of a pain in the neck it is to deal with drivers.
And this is basically a driver update. Alright, it's big time folks. Hope you guys have your little bibs and some drawn butter because we're gonna be roasting a particular crustacean security researcher Jason Miller at One Password, who is a former Field day presenter, warns that AI agent platforms like open claw, nay, mt bot, nay open claw are creating a dangerous new attack surface.
Were seemingly harmless skills written in, marked down. Oh, hey, there's that thing I mentioned before. They can function as malware delivery mechanisms.
His investigation uncovered highly downloaded skills that used fake prerequisites and setup instructions to trick users into executing info, stealing malware, exposing credentials, tokens, and sensitive data. The incident highlights how agent ecosystems blur the line between documentation and execution, which turns skill registries into supply chains that attackers can then exploit, underscoring the urgent need for stronger trust layers, providence and permission controls and AI agent frameworks. Now, here's something that I think is kind of fascinating about this whole thing.
This is all developed over the course of 10 days. We went from open claw to malt bot to open claw to claw book, is it Claw book, whatever. Uh, and then one password.
Jason Miller just comes out and basically has, if you go read the blog post that we we're gonna link here 'cause it is a thing of beauty. Jason does not mince words. If you have deployed open claw on a, on a production machine in your business, assume all of your data is on the internet and you've been breached.
So I'm gonna, I'm gonna let you start this al because I, I gotta warm up my pincers here. How do we feel about this? Um, shocked, stunned, horrified.
Well, anyway, Um, so while I was at AI Infrastructure Field day last week, I was reading some of the early news of this is what Claude Bot, malt bot, whatever it's being renamed to does. And the idea is you install the, the base software on a, on a computer, and then you say, here's everything I know, work out how to help me do what I want to do. And by the way, here's everything I communicate with.
Here's all of my data. Here's, here's access to all of my emails, all of my texts, everything go work out for yourself, how to help me, and equally, how to help other people who communicate with me. Now, what bot, uh, mal bot, what this agent then does is says, right, I've, I've discovered you need to do something.
I'm gonna go and install some software to help me do it. And this is, uh, one of the attack vectors because there are wild West style registries where you can just pull down descriptions of how to help. They're called skills.
And as, uh, Tom says, it's just a markdown text file that describes a set of actions. If you are particularly reckless and who isn't, when you're deploying this stuff, you can say to your agent, just get everything you need. Don't bother asking me.
Just download it, install it. I don't care. Don't care what it's, so they get, your agent then goes out to, uh, these repositories says, I need a skill in order to do something basic.
Uh, and it was a Twitter integration. One was the one that, that Jason particularly called out, I need to integrate with Twitter or X. Uh, there's a prereq for that integration, which is to download some malware that is gonna steal every piece of information on the computer that you have just given access to everything.
It's the most downloaded skill from that particular repository. And it's, particularly, its Mac malware, which, uh, affects me, wouldn't affect me if I was still using Windows. But of course, there's plenty of Windows malware that you could download as a skill too.
Uh, a huge number of the skills that are on these repositories contain malware. And it comes back to, we need governance around this in the same way that we need governance and security around things like docker containers. When you download a docker container from Docker hub, there is governance around it, there is history of when was it released, who has released it.
That's the very minimum we need as we're actually, as somebody's running these repositories. And that's, again, something that's called out in this excellent article. If you run one of these repositories, you need to make sure you're not being a distributor of nowhere.
Well, maybe that's not accidental. Uh, yeah. This, this is a, an interesting train wreck happening.
I sincerely hope nobody, uh, none of our listeners, none of our friends have deployed this anywhere, but inside a very controlled sandbox and gave access to all a very limited amount of data. I suspect not, I suspect people will have gotten quite excited about this amazing capability, and I'm now wondering where they're gonna work next week. Um, yeah.
Yeah. I mean, it just feels painful, doesn't it, Tom? It does.
And like, look, the, they had all the right ideas at the beginning, right? It was on Mac stories for God's sakes. Like, that's where I first saw it.
I was like, oh, neat. I don't have a use for this right now, but I'll keep an eye on it. And then we had all the renaming going on, which, by the way, all the people squatting on those names to try to sell, you know, uh, crypto tokens.
Bad, bad people don't do that. But like, the more you deal with this, and, and Jason did an amazing job on this, this, by the way, um, like, it, it is in the same problem we have with the MCP server, right? Well, whose job is security?
Well, it's their job, not mine. I passed it off to the people who are supposed to secure things. In, in general, this is the idea of what you want something to do.
If I have a, a thing that I want use to extend the capability of my device, then I give it a, uh, I give it a manifest and tell it to go get things that it needs, right? It's really, really straightforward, except nobody is checking to see what's going on. And that's the problem.
You cannot trust people. You can trust a person I trust Al I don't trust people. And these tools are written by people, not a person.
Yeah, malt bought Claude, Claude bought Claude mtm. Claude bought molt, whatever it was written by a guy. We know who it was.
And he has everybody's best intentions in heart. I'm not, I'm not telling, saying that the guy did anything wrong. He, he actually, the fact that it got mentioned on stage at the Cisco AI Summit to Sam Altman as the hot new thing, and you could just, you could physically feel Sam Alton rolling his eyes.
It's like, I am the most important human being on the planet. I'm gonna change the way the society works. And you're talking to me about some guy who wrote something in his garage that I don't think is very important.
Who cares? The fact that he's in the conversation should tell you the guy's got a, a huge future ahead of him. The problem is, is that he did not think through the fact that people are idiots and some people are deceptive idiots.
And that's exactly what happened, because all I have to do is upload the script and it says, go download this thing. That's not bad. That downloaded thing says, well, you need to go fetch this package.
That's not bad. But at no point along the way did anybody stop and do a sanity check and go, should I really be downloading things that I am not checking? And if you follow the chain down far enough, what you're doing is you're pulling a binary that has no visibility whatsoever.
And one of the first things that binary does is it restricts Mac o S's gatekeeper. Show of hands. And I'm not gonna count, but you, you know who you are.
Put a finger down if you have ever copied a command line from a webpage telling you to execute it in the terminal to make sure that a piece of software is able to install without triggering a warning message or failing to install properly. I hope every one of you people put your fingers down because we've all done it. We shouldn't.
We know better. If you don't know what a command does, don't run it. If you don't understand where a binary is coming from, don't install it.
And if it's a piece of base 64 encoded code in a URL, you better not Jason uploaded this thing to virus total and it hit immediately. It's like, I don't know what this thing is, but it's not good. This is the problem.
We, okay, you know that I have a security podcast, you know that I do Security Field day, and you know that a lot of my friends are security nerds. We all say the same thing. You cannot pass the buck on security.
And if you think you can please send me your Social security number and your bank account passwords. I mean, I'm a trustworthy person, right? What am I gonna do with them?
If you're sitting there shaking your head saying, you wouldn't do that, then don't do it for anybody else. Yeah, guess what? I I have all the hope in the world that Open Claw is going to change the way that we talk about agent workflows, because it's doing exactly what an AI agent should be doing.
It's monitoring all of your communications channels, it's munging all of that data together, and it's giving you ideas and helping you do stuff. In theory, open Claw is great in practice. People are untrustworthy idiots that are gonna try to compromise it to steal all of your data.
Because guess what, at the heart of every brand new paradigm shifting thing that we've been talking a lot for the last 20 years, are the same core group of criminal grifters that wanna make a quick buck from whatever's next. And this is fundamentally, it's a, this is a classic supply chain attack. You need to secure your supply chain.
It, it really, it, it's security 1 0 1. 01. Really, uh, uh, we could rant and rave about this all day, and, uh, we probably will, but you don't wanna listen to that all day.
What you do wanna listen to though, is Cloud Field Day Cloud Field Day will be back. I'll be back in the United States surprisingly soon. It'll be in March 11th and 12th.
Uh, we'll be back with Cloud Field Day number 25, as usual, great schedule of content, great schedule of delegates joining us. Um, looking forward to another trip back to United States. And of course, uh, doesn't get United.
You have the end of March cover. I do, because we're gonna be at RSAC this year. I bet you there's gonna be some talk about Open Claw and among other things that we talk about on the rundown every week.
But we have exciting presentations from folks like Veeam. Uh, we have, uh, great presentations from Commvault. Uh, we have, uh, a lot of presentations including Object First.
Um, they're, they're, you know, recently now part of Veeam. Uh, check out the website. Uh, we're gonna be listing our delegates there pretty soon.
There are a lot of those same people that are out there telling you don't download software, that you don't know what it does. Uh, more importantly, the reason that we're excited to be there is because there's so many other great things going around on RSA, uh, Futurum Group and, uh, techron TV have some cool stuff going on. There's gonna be a lot of content coming out of it, and we hope that you're tuned in for all of it.
'cause it really is, it's the biggest security show of the year. Uh, so big in fact, that we have to schedule our events away from it, because nobody else wants to do anything when it's RSAC time. And, uh, it, it should be a lot of fun.
And you're gonna hear a lot of familiar voices. You're gonna hear a lot of familiar things that we've been telling you guys for the last 10 years, and hopefully this time, just like the year of VDI, I hope it's gonna stick. But you know, what does stick is that every week we're back here with more great news.
Sometimes it feels like we're repeating ourselves, but you know what? That's why you watch The Rundown every week, because we put out new episodes every Wednesday. We put 'em up on YouTube.
You can download us in your favorite podcast application of choice. 2 x whatever. I don't care.
Uh, the rundown is also stream on text, on TV in a bunch of other places. Do us a favor though. We want you to go down here and leave a comment.
Um, you know, put your finger down if you did the thing that I told you that we all did. Uh, tell me if you've run Claude Bot, uh, you can use an alias if you, if you wanna make sure that you're not gonna get in trouble. Uh, but we want to hear from you, and we want to let you know that we're gonna be back next Wednesday to talk about all the IT news of the week.
That was for myself, for my co-host Alistair Cook, and for the tank of Lobsters that I have over there currently fighting to see who's gonna be my new AI agent. I wanna wish you all a happy week. And do me a favor, put some authentication in place, do it for the Lobsters.
We'll see you next week. Hey, everyone, welcome back here now to techron tv. I'm thrilled to have my next guest on.
He's a friend of mine. I, truth be told, we probably spent more time talking off camera than we're gonna spend on camera here. But, uh, I'll be seeing him in person at, uh, Sussan in, uh, ska in, uh, Prague.
I believe it's April 20 to the 23rd, something like, like That. That's correct. Absolutely.
Um, his name is Andreas Prince. Andreas has, as he told me when we first got on, he only has one job now, right? He is Global head of Sovereign Solutions for suse.
And, uh, Andreas says that, of course, tongue in cheek. He, Andreas is a former CEO, the company acquired by Seus suer, uh, stack State, right? Correct.
Absolutely. And, uh, and then he, he's worn several hats at suse, but now, as he says, he has just one hat and he's laser focused on it. Andreas, welcome to Tech Drunk tv.
It's great to have you back. Thank you so much, and glad to be here again. Absolutely.
So, Andreas, let, let's go right to this new role. I, I think I interviewed you when you first were appointed, uh, global Head sovereign, you know, took up the mantle of moving this forward for suse. But, you know, for people out here who maybe are not familiar with digital sovereignty yet, how important it's become, talk about that and, and why suse in particular, you know, saw fit to take a senior person like you to, to head this up.
Yeah, no, absolutely. Happy to, happy to do that. And I must admit, I do think it's about six or seven weeks ago that we spoke, or probably a little longer, but I learned so much over the last few months.
So let's, let's talk about that in a little as well. Um, but I'm, I'm driving the global initiative around, uh, sovereignty, right? Because we see the world becoming more and more isolated, which is a kind of sad, uh, because it's killing innovation as such.
But what is the good part of that is companies and governments and, um, even continents are becoming aware of their dependencies on other parties, right? And that posing the question is how sovereign or how resilient is actually my business. And I do think that that is a very valid question to ask by, by any company, what are my dependencies to, uh, to other countries?
And in my initiative, what I try to do is really connect all the, the gold, how I'd like to put it in our portfolio as suse is running a full open source portfolio and use that to help public sector mission critical infrastructure, highly regulated banking to let them use open source to ultimately increase their autonomy. Because the more autonomous they are, the better that they can run the business themself. So I'm bringing product marketing, sales positioning, but also a little bit of influencing Brussels, if you like, from a policymaking perspective to, um, yeah.
To, to come to a better answer to all the foreign influences that the different regions in the world are facing today. Yep. Yeah, I wanna address that for a second.
Different regions in the world, a lot of people think of the digital sovereignty movement as, oh, this is a European thing. They wanna be, you know, sovereign and independent, but no digital sovereignty. I, as I said on my shimmy, says a couple weeks ago, it's a, it's a national sovereignty issue, but it even, it goes below even the nation state.
It, it's a municipality issue. It's a province issue, it's a state issue. It goes all the way down to a personal issue.
Yeah. Yeah. The issue, the idea of sovereignty over one's data sovereignty over one's technology infrastructure.
Yeah. Yeah. It, it, I think it has to become sort of like a basic human right.
A basic right. Yeah. And we have to think of it as such.
Yeah. And it, and it goes beyond just Europe. Yeah.
So it goes beyond Europe, as in, we see it equally happening in Africa, middle East, apec, right? So many, many regions are asking, and if I would ask my American colleagues, they would not call it sovereignty, but they very often speak about data security in the context of ai, right? Which connects it back to your, to your statement, right?
Because it's all about the data. Um, so we see different wording, but all, all regions, I would argue across the world, are becoming more and more aware to take action. Um, and then on the other side of the spectrum, and souse is not that much involved there, but if you think about many countries putting strict regulations on what teenagers can do on social media platforms, right?
And, and increasing the, the bar, right? The age before you can enter a platform ultimately, right? For addiction, but also for a protecting data sovereignty, these type of elements.
So it's definitely a human. And last week I was at the open source, um, week in Brussels, and, uh, one of the, the German ministers from one of the, the areas in the north of Germany, he spoke about that they've moved already to 60 to 70% of all their software towards open source. So it's not that Germany as a country, but these portions of Germany are, are moving big time.
So it's hard, but there's a lot of 50, 60% that's relatively simple to do. Right. And then the rest Yeah.
Ultimately will follow if you free a budget and have efforts to, uh, to get there. Absolutely. You know, there's another element to this too that we haven't hit on and driving.
You mentioned here in the states, in America, uh, you know, I, we've seen this in the US for some time where some states tax, right? Charge for business you do within the state, online and so forth. So there are a lot of businesses who will say, I don't want my infrastructure, even though I'm using AWS or Google or whatever, Microsoft, I don't want my infrastructure stored in this state because then I'm subject to their taxes Yeah.
And their laws. And so again, it breaks down, but, but there is the financial, as there always is, is in there the financial aspect of, of having, again, sovereignty control over your footprint, over your data. Well, and, and interesting, I don't know the the details, but what is the EU doing is, is the opposite.
Um, so, um, uh, funder Lion, she announced an initiative, right? And let's see if we can realize it, which is called EU Inc. Mm-hmm.
So rather than having a, a company that resides in the country with its own tax rules and labor rules and whatever, and they have the ambition to establish something, and I do think ideal for IT companies across Europe, because by doing so, it's much more interesting for a startup to remain in Europe, right? Because then if you sell in one country, you're able and allowed to sell in all countries across Europe. So all of a sudden you're targeting a, a much bigger market, um, than moving first to the us, um, right.
To, because that's what a lot of European companies do have. They go to series B and they have to go to the us uh, to, to have much faster growth. So it's interesting that the EU is also having these considerations to, to make it easier to grow a company here in, uh, in the eu.
Yeah, sure. Standardization makes it easier because it becomes reliability, predictability, et cetera. You know, speaking of EU though, the, the, uh, the 2025 EU cloud sovereignty framework, is that what you're referring to here?
Or is that something else? No, that's, that's something else. So the, the EU Inc is really a company type, right?
Right. That is applicable for the whole of Europe. The framework is another very fascinating instrument that the EU has launched.
Um, I'm very positive about it because it's simple. It's only six pages. Uh, but it helps executives, I would argue, to really understand what sovereignty is, because it have defined eight objectives to do that.
And it then gives a very interesting five grade scoring mechanism to help them understand, to rate on these eight objectives, uh, scoring five. And that's interesting because then all of a sudden they can start to assess, um, their products, their IT stack and understand what their risk is or their exposure, if you like, from a sovereignty perspective. So what I do think where EU really succeeded is to make a, a framework that is comprehensive, um, but still very easy to consume and to, to understand that we see a rapid rise.
It's mentioned, people are writing about it, it's popping up in RFPs, right? So people are really using it to understand what it is they need and where they are today. Excellent.
Excellent. Now, is this, this framework, has it been pa like is it official EU legislation that they voted on, or is it, because I know in the eu sometimes they'll have like a, a working model session, right? Where they, let's see, you know, we're waiting to hear back from industry and other people before we actually make it law.
Yeah. It's much more like this. So it's early days.
So if you take a look at the regulation, it's the Cyber Resilience Act needs too, and Dora, right, which are really, really laws and regulations applied to the countries. And then this framework, I do think that's why the word framework is in, is still a recommendation, right? So if you need to think about sovereignty, this is how you can assess your own situation, how it might turn into law.
I don't know if that's gonna happen, is that they are requesting particular scoring levels. So imagine the, the government of the Netherlands or Germany would acquire software and they might say it needs to score, right? At least a three or at least a two, right?
On the, on the framework. Um, right? That's, that's how it's potentially be used.
So not in a law, but more as if you do procurement, you might see this framework popping up by articulating, Hey, you need to at least score a two or a three or a four, um, in this, in this perspective. Excellent. Yeah.
And Andreas, I wanted to ask you, I, I remember reading this news, I saw you were featured, you spoke out, and I think SUSE put out some pr and there I saw some LinkedIn activity, you know, AWS so one of the big three hyperscalers announced a, uh, sovereign environment, a sovereign offering specifically for eu. And SUSE is one of the strategic partners. Yeah.
Yeah. In that, yeah. Wanted to ask you, how does that work though, with AWS still being sort of a US based Yeah.
Uh, corporation. Yeah, That's, that's very interesting one. And if you take a look, if you go back to the framework, uh, the framework articulates sovereignty in many aspects, right?
It is where your data resides. It is the personnel who's working there. It's about the supply chain.
It's about the software being used, it's about jurisdiction, it's about strategic. Um, and if you think about our customers as some customers, let's say a public, um, eh, or government, right? They want to go very strict, right?
And they might say, Hey, even AWS right is not good enough for my, my online identity management. I want to go to a more local regional data provider, right? That, that might be a move.
And then the AWS European Cloud isn't a so solution for them. We have a lot of other customers who say, Hey, I want to get guarantees that it runs in Europe, right? Because that's important that I have European personnel working on it, because that's important, but I'm still a global company, right?
So the fact that I'm under the cloud X, right? And because that's where a lot of people refer to is still okay, because I also have an American entity as a, as a company, right? So people think about this very black and white, and I do think it's much more nuanced.
There are customers who wanna benefit from a hyperscaler type of capability because they don't want to have an own data center or whatever. They wanna benefit from the rich marketplace capabilities that I'm assuming will grow there as well, um, but still get more strict, right? Than the regular AWS type of contract.
So it's a very nuanced approach, and we have a lot of customers that are across continents, right? And that are simply anyhow tied to a hyperscaler solution to make it beneficial or to make it, um, to make it work. Um, so we really follow the customer, and that's why you will see us doing announcements on very sovereign solutions, right?
Owned by European in Europe, European personnel, but also we have a lot of customers who want to go to the AWS European, um, cloud. So yeah, that's, that's the kind of meeting the customers where they are. Excellent.
Excellent. Andreas, it occurs to me that the man, you only got one job, but there's so much going on right now with it for our reader readers, excuse me, our listeners are watchers out there. They're not really reading this.
Um, where can they go to stay up on all of this? Yeah, no, that's, uh, very hard. There's a lot going on.
If you only follow your own LinkedIn feeds, hey, if there's a conference going on, then it's populated with lots of articles. Um, the question really is what is it that you're after? And what I notice in sales conversations is that people are, I mean, we're, you and I are speaking about right, the world moving and, and, and, and things that we need to build and isolation and innovation, but a lot of people are, are just trying to become aware of what is actually happening, right?
How do I need to assess my own stack, right? So a lot of the market is, is much earlier days. And what we launched last week is a self-assessment based on the EU framework that helps you to measure how you score your own stack.
And by doing so, you get a very extensive gap analysis, right? And I do think that gap analysis, the text helps you to better understand and articulate where you need to go with your roadmap, with your product improvements, um, and whatever. And the reason why we developed it is predominantly because the world, right?
Or Europe, if you like, doesn't know how to express and make a roadmap, right? A lot of these CIOs or GTOs and how to make a roadmap that is reducing my overall sovereignty risk as such. So yeah, definitely every looked it up, right?
And, uh, I do think that's very helpful to, um, for many people. Excellent. Excellent.
com and find it it from there? Suse sovereignty dash test? Yeah.
Got it. Yeah. I was hoping you'd have something Andy like that.
Absolutely. Andreas, do you have any spare time to do anything else, or is this consuming you at this point? Well, I'm a little bit of a fennel five coating, so I like to run some, uh, some tiny, sometimes personal experiments.
Uh, and my duty is at home raising a big family. So, uh, lots of hobby projects there, if you like. Absolutely.
You know, I want to, one other thing I, I noticed this morning here, I think the Netherlands specifically just came out with some sovereignty, not guidelines, but a plan of three, three areas. Yeah. You want to talk about that a minute?
Yeah, definitely. And I do think that that's pretty interesting for the rest of Europe to see how that shapes up. So we, uh, we had elections, uh, and then in less than 90 days, right, they formed a coalition, which is pretty fast for the Dutch standards.
Um, and they articulated a coalition agreement. I had three parties seeing if they can, can govern the country for four years. Um, what was really strong is that it contained a two or three paragraph, or sorry, a three paragraph, two pager, uh, in it agreement with regards to sovereignty.
So it was about sovereignty itself, cybersecurity, and really the scale, uh, and scale and scale of people and the scale, how to apply that gap. Uh, and what I like there is they did in my mind, the first attempt to make it very tangible, um, and at least address the risk. Now, I, I understand it's up to the government and the ministries had to make it tangible and to put it into motion.
Um, but what is good is that at the government level, we think about, well, to your point, and the, the sovereignty of the nation and how we could drive that forward. And I'm expecting, and at other countries, a if election would pop up and if they need to come up with an agreement, they would do more or less the same and really address sovereignty and open source and, uh, procurement processes in a very structured way. So let's, let's see, right, if, um, if this moves stuff forward, um, still the government.
So I'm very hopeful and we're having lots of good conversations, but, uh, the work still needs to happen. Absolutely. Alright, Andres, we're about outta time.
I wanted to thank you for coming on. Look, I think what you, it's not like you haven't worked on important things before, but this is one of the most important things you're gonna work on you, right? And, uh, I think when you look back at some point over your career, this will be a, a, a really linchpin, you know, a real big, big part.
Um, and I could think of a better person at SUSE to run this. So thank you. Keep doing what you're doing, do keep us informed.
I will, looking forward to seeing you in, uh, April in product. Absolutely. Looking forward to that.
And let's continue and, Uh, we'll continue. But if something comes before then you'll come back on. We'll talk more.
Well, no worries. We'll do that. All right.
Excellent. Andreas Prince, global head of Sovereign Solutions, Susa here on Text Drunk tv. We're gonna take a break.
We'll be back. Hey everyone, it's Alan Shimmel, founder, CEO here at Techstrong, and welcome to our continuing series on, uh, AI agentic AI in the future here with, uh, the Microsoft team and our future, um, analyst team, as well as Techstrong. In this next episode, though, we're gonna be joined by Mitchell Ashley, uh, of Futurum, who leads the software development lifecycle and building segment at futurum.
And Mitchell is talking with Brian Good, whose official titles is corporate Vice President and Agents marketing. But Brian is really here talking about agent apps and chat, and it, it's, uh, you know, obviously a very hot topic as we move to a n agent AI workflow based basis. So let's join Mitchell and Brian here with me, and it's great to have them both.
My name is Mitch Ashley, and I'm VP and practice lead of the software lifecycle engineering practice at Futurum Research. And, and Mitch, uh, my name is Brian. Good.
Uh, I lead the business applications and agents team, uh, here at Microsoft. Uh, let's start here. 2025 is described as kinda been an inflection point for AI adoption.
What do you think are the most significant changes that, uh, you've seen in organizations as they're using AI and agents in their businesses this year? Well, I absolutely agree. 2025 is really an inflection point.
And we'll sometimes describe it as the year that the Frontier Firm was born. And you might've heard us talk about the Frontier Firm before. It's this idea of companies that are putting AI really at the heart of their business, and it's enabling them to do things like reinvent the way they engage with the customers or transform their business processes inside their company, um, and beyond.
And it's really the year these frontier firms are sort of rising up and a time when I think we can learn a lot from these early adopters and understanding how they're deploying ai, how they're being successful, and then figure out how we can take those insights and bring 'em to, to our own businesses. That's where you can have outsized impact As AI transforms those functions. What do you see as the new patterns of work that's enabled by copilot and agents as customers start leveraging the technology for productivity or innovation?
I'll tell you what, I have studied these frontier firms as they, as they come up, and there's really three patterns that I see across these frontier firms. The first is really enabling, uh, employee productivity. So they give every employee, uh, an AI assistant like Microsoft 365 copilot, and it helps them, those employees be more productive.
The second pattern that I see is, uh, really these frontier firms deploying AI to automate existing business processes. So, for example, they already have a way of handling expense reports, but they can use AI to speed that up and reduce costs, and, and that certainly results in some benefits to the customer. The third pattern is really where a customer like starts from the beginning, let's say from first principles, and they reimagine a function altogether.
They'll reimagine what it means to engage with a customer who has a, uh, an issue with their product, and they'll put agents at the heart of that. Most companies can only take on one or two of these functional transformation projects at, at any given time because it's a big lift. Again, is reimagining a function from first principles.
It's not just taking existing processes and and applying AI to them. How far along do you think most organizations are in their adoption cycle for generative ai? Well, I think we're still in early innings, uh, that there's no doubt about that.
Um, you know, customers are starting to deploy AI and different functions as we talked about, but certainly they haven't, in most cases, fully realized kind of the transformation that AI can have across their organization. So it's still very early innings, but I'd say we see very promising signs and green shoots, uh, of that, uh, of that adoption and success. Uh, again, the key really here is to start function by function, think about a particular function, think about peeling it back to the business processes you need to go focus on.
That's where you can have outsized impact. How do you define AgTech business applications and why are they critical for organizations? Yeah.
Well, I do have a vision that there's, uh, the application of old is really transformed with ai, and we call that new type of application, the AG agentic business application. And the ag agentic biz app includes the assistant for the human to start to use. It includes prebuilt business process agents that basically take the drudgery out of work, and then it's built on a data foundation.
And so instead of being limited just to the data that, you know, maybe is in the CRM system or the ERP system, it joins that with data from other lines of business systems and even productivity data so that you have a rich set of data that you can build agents on top of, and you can empower your humans to get better decisions from. And so this idea that brings all those together, the assistant, the agent, the application, I call the Agentic Biz app, and I think it's a really big idea. Well, let's talk about why you're optimistic about the future of ag agentic business applications.
I have a lot of optimism here because number one, I see customers already deploying these applications, uh, and, and really transforming their business. So I already see people starting to get great benefit from it, but at a more human level, the thing that gets me excited is like, if you think about every one of our jobs, like there's a lot of stuff that we end up having to do that really isn't adding joy to our lives. Uh, you know, me doing an expense report or, you know, filling out a CRM uh, system, you know, with an update from a customer call, those aren't the things that, uh, that make us, uh, unique.
Those aren't the things that bring joy. Those aren't really even things that add business value collectively. But if we can delegate those things to AI and agents, I think will enable ourselves to actually go do far bigger things and really take our ambition to the next level.
And so I am absolutely excited for what the future holds. Yeah, I'd love to hear about how you see the role of AI agents evolving just over the next few years, especially as organizations start to redesign core business processes drive outcomes for efficiency. How, how do you see this taking shape?
Yeah, great question. You know, odd, I I would say that we really believe there's a spectrum, uh, of, of agents. You know, there will be very simple agents that someone will use that might just be grounded on a particular knowledge source and help you, you know, understand, you know, what, what might happen from that, uh, from that knowledge source.
Then there'll be task-based agents, and then there'll also be more sophisticated, fully autonomous agents as well. And this more autonomous agents is where you can unlock a lot of business value. These are agents that, you know, aren't called by a by a human.
They're just running independently. They're triggered based on different actions, and they can really automate business processes in some cases from start to finish. So we believe there's this spectrum of agents, and today, I'd say most ENT use cases start with those more simple kind of knowledge agents.
Uh, but increasingly we're seeing customers bring in these task-based agents and autonomous agents, uh, to automate, uh, things, uh, end to end. How about the C-suite leaders? How should they be thinking about investing in agent technologies for long-term value?
Well, every C-suite leader I talk to today is already in on ai. Like every one of them recognizes that it's a competitive advantage if they can move quickly, and if they don't move quickly, they recognize it could be a disruptive force in their industry. But let's face it, ai it's transforming businesses, it's transforming functions.
It's, it's gonna reshape entire industries. And every C-suite leader I talk to recognizes that and wants on board. What they're looking for though, is a partner.
They're looking for the tech, of course, they wanna make sure they've got the right tech, but they're also looking for a partner to help them shape this in their business. And that's where Microsoft, I think, comes into play. Uh, you know, we're not a large scale model maker, uh, but we do take the best of the models and bring 'em into the workplace, uh, so that companies can use them.
You know, we talk about AI being a disruptive technology, probably because it seems that it really can and will affect every part of our work, our lives, et cetera. Certainly affecting how we create software with new concept like agents and agentic ai. Curious about your thoughts.
Share with us, how does Microsoft view what the transformation is going to be like with AI really having an impact and a big benefit to businesses? Yeah. Many industry, uh, pundits will say that this move to AI agents is gonna, uh, lead to the rise of, uh, uh, more consumption like models or outcome-based pricing.
And I think they're right. I, that's definitely a direction that I see the world shifting as well. Um, the only thing I would, uh, balance that with is that many customers are still, uh, you know, most comfortable buying things on a, a per user or pre per seat basis.
And so, uh, the approach I'm taking is, you know, how do I enable customers to buy offerings that they're comfortable with? And that's typically like a per user or some type of per tenant type of type of license, while giving them the flexibility to, to grow and shift into more consumption models as they, uh, as their business changes. And so, uh, we are at an inflection point, just as we said, and I think one of the things that will change is the business model over time.
Talk some more about AgTech. When you think about agents operating on their own or more autonomously, and why, why is that an important thing that organizations are looking to move to? Yeah, It really comes down to business priorities.
Like every business leader I talk to wants to find ways to grow their top line revenue, or they're looking for ways to automate, uh, things that, that they're doing so that they can save money or redirect folks to, uh, focus on more important activities. And, you know, autonomous agents really fit that bill. You know, imagine in the sales context, you can have an autonomous agent, you know, going through marketing leads and qualifying them before handing them off to a human seller.
That's work that wouldn't have gotten done in the past or would've been done by a human seller, uh, and have been relatively low value, not something they, they really enjoyed, uh, about their job. And so an AI agent can do that and add great value to the company, and again, help that company grow on the top line. Talk about Microsoft, uh, and the offering that you have in the context of an end-to-end tool toolkit, if you will.
Yeah. For functional transformation. You know, as far as the toolkit goes, we really believe that there's three essential parts to it.
The first is we think every employee should have an AI assistant in our case, uh, that's Microsoft 365 copilot. Uh, think of that as a productivity tool to help every employee work get through their workday and get more done. That can be quite transformative.
That next step up is where agents come into the picture, and I describe agents as really being for every business process or workflow in an organization. And we have, uh, a toolkit that enables customers to build their own agents. It starts with copilot studio, but even extends into our Azure capabilities with our Azure AI Foundry product.
So agents pair very nicely with that copilot that I described first, and then the final step is where the system of record becomes the system of action. And we'll sometimes call this the ag agentic business application, where you take a CRM system and you add agents and an assistant to it to really transform those three are the essential ingredients or building blocks for AI transformation, um, in a frontier firm or any business at this point. That's a great term.
Can you share some examples of how Microsoft customers are already seeing measurable impact from adopting agent business applications? Yeah. One example I I think I can give is lifetime.
Uh, they're a great customer of ours, uh, based here in the United States. They've used us as part of their finance and supply chain operations, and they've, uh, deployed agents to basically speed up how they handle and process e-commerce orders. In fact, I think it saved them 95%, uh, in terms of their order, e-commerce, order efficiency by deploying, uh, AI agents and agentic business applications to solve that problem.
So I think that's a great example. We also have, uh, another great example, uh, from Europe, um, uh, a large utility named Enco who deployed a multi-language, uh, AI agent, uh, for their customers to help them scale and address customer questions. Uh, it's a pretty cool solution.
Saves them time and again, helps them scale up. Now it's a, it's a really exciting time in the world of agents. You know, you talked about the C-Suite and kind of the three phases in this adoption curve as we adopt ai.
What, what kinda recommendations do you have? Like, how to get started? Well, maybe near some of the near term activities.
Well, you know, as I said earlier, I think AI is gonna transform every company, every function, every industry. And that opportunity is so vast, sometimes it's hard to know where to get started. And I've got two bits of advice really there to, to anybody that, uh, that is, is pondering that question.
Uh, the first thing is, again, start with a function. Pick a function that you want to go after and then peel it like an onion. You know, go look at the next layer, which are the business processes in that function that you can apply, uh, a co-pilot or agents to, to really transform.
The other thing though is like, don't get into analysis paralysis. Just pick a business process. Just go pick a business process to get started with.
And as you learn from applying AI to that business process, whatever it is, whatever your thorny is business process is, go apply AI to it. You are gonna learn, your organization's gonna learn, your culture will adapt, and then it will flow from there. So the opportunity is so vast.
Don't let that keep you from getting started. You gotta get started. Start simple, pick one thing and go from there.
So as we move to an agentic business environment, let's talk about the people. How do you see the role of human creativity, judgment, leadership? How is that gonna evolve?
Yeah. Well, that's an excellent question, and one of the things that we'll often talk about is how AI and frontier firms is gonna transform the way we work. It's gonna change, uh, the org chart into more of a work chart.
Uh, we sometimes talk about, uh, frontier firms taking on the Hollywood model where individuals will swarm around a problem, like focus on a problem and then disband, uh, you know, uh, when the, you know, once they've got a solution. And so it's absolutely gonna change the way we work with others inside the workplace. It also, I think, is gonna give rise to a new idea that we call an agent boss.
And you can imagine, just as a people manager today might take work and delegate it to different humans on their team, uh, you know, resolve conflicts and sort of manage performance. Every one of us in the future is gonna do that, but not just with humans, but also with agents. So imagine taking a business problem, breaking it up into pieces, delegating it to agents or agents, uh, on your team, resolving conflicts that might come up, applying human judgment.
Uh, it's gonna be an absolutely transformational moment, and I'm really excited about it. I, I really believe that, you know, there is still a huge opportunity for humans with human ambition to go do great work amplified by ai. Talk a little bit about how you see the, the difference in, in the working together between applications, assistance agents, the different technologies.
Well, that's an excellent question. And you know, we really have this complete toolkit that spans everything from the assistant to the agent to the application. And I think those three things work together in a symbiotic way.
As an example, you can imagine that I might go to my assistant and, you know, ask a simple question, my AI assistant like Microsoft 365 copilot and ask a question about, you know, uh, summarize the emails or help me respond to the emails I've got. Or I might use an agent to update a CRM record after I meet with a customer, but I'm still gonna want to go to an application. Really, that's a purpose-built experience for me if I want a more specialized or fine tuned experience.
So those three things really work together. Talk a little bit about the industries or maybe the business functions that you expect to see reshaped first by agent AI transformation. Yeah, there are three or four, I'd say functions in particular that are, I'd say, um, you know, ground zero for, uh, functional, uh, transformation with AI and agents.
Certainly customer service and customer experience is one that is, uh, absolutely being reshaped and say a very early adopter of ai, no doubt about it. Another, where I'm seeing a lot of early AI adoption, uh, is in sales. Uh, and it's just because, just as we talked about, there's a big opportunity to use AI to basically increase capacity for that organization to grow top line revenue.
So the business impact there is undeniable, but I also see it in places like finance and supply chain, where you can use AI to shorten the time it takes to, from an order to actually being able to ship it that order. We're seeing people use AI to improve accounts, uh, payable and accounts receivable. Um, so we're seeing some pretty, uh, interesting impacts there.
Let's talk a little bit more about the frontier firms. You know, they're not just adopting technology, they're also changing the way they're do doing business around AI agents and co violet capabilities. You talk about, you know, what they're doing to invest and support the short term ROI that they were looking to get for long-term innovation.
The most successful frontier firms are doing actually is taking a functional approach. And so certainly they'll think about their entire company, uh, but they'll really take an approach that's function by function. They'll think about their sales function as an example, and then they'll peel back the onion a little bit and understand which processes inside their sales department they can automate.
Uh, using AI agents as an example. They'll look at which, uh, things their salespeople need help with, where you could pair up an assistant like copilot to help them throughout their workday. And they'll even look at how they can bring agents in to really augment business capacity, maybe to grow top line revenue or take out costs.
But starting function by function has really been the recipe that these, um, frontier firms, uh, are using to see success. As an example, in our sales organization, uh, by deploying co-pilot and agents, we've been able to improve revenue per seller in some cases by almost 10% in some organizations. And, you know, if you think about that giving a seller 10% more capacity is like giving them an additional month, uh, in a year, uh, without actually having them spend any extra hours through the work week.
And so there's some pretty remarkable results. That's just sales. We've been able to do the same in customer service in our finance department and our IT department.
Our legal team has been able to reduce costs by 5%, uh, by deploying AI and agents, uh, within their, uh, within their functions. How do we ensure trust and transparency as a agentic systems become more and more autonomous? Yeah, Well, there's two things that we want to do to help with trust and transparency.
The first is we have a rigorous set of principles on, uh, responsible ai. So for any AI that, uh, Microsoft deploys, we adhere to a an important set of guidelines. Uh, and that's really table stakes.
So that's the first piece, uh, responsible AI and our focus there. The second thing that I think is important is we now have an opportunity to start to quantify the value and the impact that many agents will have. And we often will call that in the industry, we'll call that evals or benchmarks.
And increasingly, I think we have an opportunity to help our customers understand how agents are being effective in their workplace using these evals and benchmarks on real world problems. So for example, uh, we, uh, uh, a typical, uh, workflow will be a sales leader doing sales research to try to understand like how they might want to organize accounts or territories or, you know, reshape planning as they think about the year ahead. We recently released a new benchmark, uh, that we call the sales research bench, and it shows how agents can actually help sales leaders in that very specific job, and it's quantified.
Uh, and so I think you'll start to see more of that. And between following responsible AI standards and then using quantitative measures like evals and benchmarks to understand efficacy, I think we're really on the cusp of helping customers know how they can deploy AI in a safe way for real business results. Well, thank you Brian, for sharing with us your insights and can look into the future, what's happening with the Gentech business applications?
Thank you very much. It's really amazing the pace at which AI has been adopted and continues to evolve. The technology evolves on a near daily basis, but at the same time, organizations have to figure out how they're gonna implement their AI strategies and what the business outcomes that they're most important to their business.
I think it's very fascinating how Microsoft has approached the market, both from the standpoint of addressing the individual and their productivity, but also thinking about new workflows, new models of business, but doing that with not a set of tools, but a set of capabilities that provide integration with data process, workflow, and agent ai. No one knows for sure what the future holds and what an agentic business might really, really look like. But in situations like today, when we remove constraints of what we can do with technology thanks to ai, that's where the possibilities are created.
You know, using tools like copilot, using applications like Dynamics 365 and we'll, we'll see what end users as well as technologists bring to bear in their ideas and how they reshape businesses day and tomorrow. And how about you? But I'm super excited about the future that we're creating together thanks to working with technology companies and with end users like yourself.
Hey guys, thanks for the throw. We're here with Jim Brennan, who's chief product and technology officer for Get Real. And we're having a little chat about, well, deep fakes, but they're coming to the enterprise now and it looks like they're targeting specific individuals who maybe have, uh, a lot of power and a lot of net worth.
Jim, welcome the show. Well, Thank you Mike. Really glad to be here.
I appreciate the opportunity. I think when most people think about Deep Fix, they're like, well, some politician somewhere was impersonated or that it was, uh, you know, maybe some actor or somebody who was saying something about something. But it seems like lately the bad guys are getting pickier about who they go to the trouble to create these deep fakes about it.
'cause they're after, well, you know, senior level execs and companies that have access to money and workflows. So what's changing here? Yeah, that's absolutely the case.
You know, it's actually, there's a couple different types of deep fakes to think about in this conversation. So one is, is a case where you've got maybe an image, audio or a video file floating around, and maybe to your point, it's of a celebrity or an executive saying something or doing something they shouldn't be saying or doing. But now what we're seeing is actually the use of this, this same type of technology, but instead taking place in real time forums, much like an interaction like this or a phone call.
And so now these, these are actually attacks focused on the enterprise because things from candidate fraud. So, you know, fake job candidates showing up in an interview to somebody calling the help desk claiming they got locked out of their, their Google or Microsoft account. These are ways in which these technologies are now being utilized.
And so they do represent a real threat to the enterprise. How good are they? Because a lot of folks would assume that there's, through a level of interaction and conversation, it would become apparent that that was a deep fake.
And yet we hear about people being fooled for an extended period of time. So what's changed? Well, it's changing dramatically by the day, Mike.
That's, that's the reality. New tools are coming out, the existing tools are getting better. There are some differences if you're talking about audio or video.
So, so for quite some time, for about a year now, audio has been to a point where most people, including you and I, if we get a phone call, likely can't tell the difference. Video is a little bit more complicated. Of course you've got more signal to work with, but even that's getting better.
There's new tools that have come out recently that are just uncanny in terms of how close they can mirror somebody's resemblance In the future. Will we have to validate every interaction? I mean, before you and I joined on this call, uh, you were introduced to me by somebody we both know and hopefully trust.
And as that comes together though, seems like a little awkward, but is that where we are? Yeah, Well that's just it. Exactly.
You know, and if you think about how, how much time we spend in a video conference or, or taking phone calls and most businesses conducted in these forums, and to your point, there's really a missing authentication layer here. So not only the things you mentioned, but what was to stop me from sending the link to this meeting to somebody else that could then pretend to be me. The reality is you and I right now have no, no real reason to believe that we're talking to who we think we're talking to.
Right? I don't really know that I'm talking to Mike. You don't really know you're talking to Jim.
I can assure you that you are. But there's, there's really no technical reason that we should have that confidence, but we're all conditioned to trust what we're seeing and hearing. That's just, that's human nature.
But we're now in this, this realm where that you can't rely upon these signals. So it's a fascinating change to the dynamics. And for the last 20 years, business has transformed to again, be utilizing these types of communication forums for very important transactions and conversations and, and every type of business.
And now we're at a point where you really can't trust who's on the other end of that interaction. So what's to be done about this? Do we need some sort of missing technology or is there some service somewhere that will validate our representations to each other in a way that we can at least reasonably trust, maybe never perfectly trust.
Yeah. Well there's a couple different questions that you have to be able to answer though when you're thinking about trust, you know, so, so one question is, is the person I'm speaking with or interacting with, are they actually a real human being or are they some type of synthetic creation? A deepfake, but that's only one, one question.
The other question that is equally important in an interaction like this is, is the person I'm talking to who they're claiming to be, those are two very different questions, right? So you take an interaction, like an interview, a job applicant shows up in a Zoom call or a teams call, right? Oftentimes that candidate fraud that's taking place is not involving a deep fake.
It's involving somebody claiming to be somebody who they're not. You know, maybe they don't have the right skills. Maybe it's a state sponsored actor hoping to infiltrate a company.
So two questions. Is this a real person and is it the person that I think I'm speaking with? And those two questions, to answer those, you need different types of, of techniques or solutions.
On one hand you need some ability to, to detect synthetic content, audio and video. But then on the other side of that coin, you need some way of verifying consistency of things like facial biometrics, voice biometrics, behavioral, those are, those are some of the techniques that need to be brought together. Then along with bringing in threat intelligence, because these are security incidents.
So what can I know in advance of an interaction about somebody I'm going to be meeting with? Are they exhibiting, are they going to exhibit a face or a voice that is known to be associated with a threat actor? These are all the things that have to come together.
Yeah. Um, when we get to some point where there'll be tells, and I, and I asked this question because early on there used to be kind of the sense of, well, if there was something that somebody wanted you to do and it was urgent, was kind of a tell that maybe this is the wrong thing to do. But to your point, it also seems like there's a lot more patients being exercised now on the bad guys and they're willing to pretend to be something for an extended period of time before they strike.
So what can, what can I look for? Yeah, so there are some tells today, and I'll go through a couple of those depending upon the, the situation, but increasingly those tells are, are going away. So in the case of, of an interview for example, there are certain things like obviously not being on camera or, or using a virtual background and refusing to take off that virtual background.
Um, also in the context of an interview, you know, a lag between when the questions asked or an answer is given could mean that somebody is being fed responses from somebody else or looking something up. So these are things that exist now that're all gonna go away very soon because all the technology is getting better. And so really what's gonna be needed is a much deeper lower level detection of the tells and the artifacts.
And here at Get Real, that's, that's really our focus. We're taking a very low level look at the actual processing pipelines of these platforms, zoom and teams, et cetera, and, and corporate telephony platforms and understanding what does normal look like? And by the way, normal's changing every day.
'cause those platforms are themselves utilizing AI to do things like noise reduction. So it's not just a matter of is is AI present, it's what does a normal non nefarious use of that platform look like? And then you have to be able to couple that with in-depth knowledge of what do the common generator tools that are out there and that are emerging, what do those impart upon that processing pipeline?
So you're essentially looking for deviations or anomalies from what healthy, normal, non nefarious activity looks like. And that's, that's our focus here. We think that's the only way to solve this problem, but it does require a very low level of expertise and knowledge because again, the tells that exist today, some of the things I mentioned, they're not gonna be here long.
Mm-hmm. Does that also include, I don't know, measuring latency? Because, uh, theoretically if I'm talking to somebody and they're supposed to be in Green Bay, but if I'm measuring latency, it's pretty clear that they're not responding and the amount of time window that you would normally expect between New York and Green Bay instead it feels like, you know, New York to Africa, maybe something's missed.
Yeah, that's a good example. I would, I would probably take that example and, and, um, look at it somewhat differently. So, so the idea of location being an important indicator, absolutely spot on.
That's where threat intel can come in as well. And that's where other context and signals coming from the interaction such as IP address for example, can be really handy. Also, things like understanding if somebody is using a virtual camera driver or audio driver, things that are associated with the use of these nefarious tools, very strong indicators.
And then to, to another extent, maybe a somewhat lesser extent, just again, knowing some, something about the person on the other end of that interaction. You know, somebody's email address, you know, know what can you, what can you tell from that? Um, are they associated with, with a company?
Do they have a history at a company that you can trust? All these are signals that can definitely play a role. Mm-hmm.
So what's your best advice to folks? 'cause I think, uh, taken to its nth degree, you know, this whole communications revolution that we've been counting on for the last three decades or so, uh, might just unravel. So how do we think about this?
Yeah, well, and, and, um, I don't wanna sound alarmist, but, but internally here at Get Real Security, we, we think about the idea of a zero trust approach, but a zero trust at the human layer. So we're all familiar with that term, zero trust in terms of infrastructure and assets and so forth. But we need to apply a similar thinking to the human layer.
And again, the human layer is anywhere a human being is being represented in a digital signal. It could be, again, interaction like this, it could be a profile picture, it could be a voice recording landing in your inbox in WhatsApp, anywhere where a human being is being represented. We think of that as the human layer, and we really do think that we need to apply zero trust to that back to the conversation we had before.
Really, there's no inherent reason in today's climate where we should be trusting every interaction. And so you do have to take an approach like that. And then therefore that implies that you have to have some tools that can answer those two questions that I talked about.
Is this a real person and is this the person that I think it is? But then you also have to have tools that allow you to respond proactively when there is an incident. And then ultimately you want to know something about who's on the other end of that attack.
These are attacks and, and as is the case with any attack, you wanna understand the intent and the actor behind that attack because if they're knocking on your door once, it's not only once they're probably, they're probably targeting many people within your enterprise. What should law enforcement be doing about any of this? 'cause I guess fraud is still fraud, but, yep.
Um, I wonder if the technology has just moved far beyond their capabilities at the moment, but what would you like to see happen? Well, I would say it hasn't, it hasn't moved beyond their capabilities yet, but, and we do a lot of work with government agencies, law enforcement, that does tend to be more in the realm of file or content analysis. So perhaps evidence to be admitted in a court of law as one example, a similar case with, with intelligence analysis within governmental agencies.
And so they're very focused on this problem. Again, we have a lot of, uh, conversations and some relationships in that area. It's very, it's very quick moving as we talked about.
Right? Um, and that one in that, in those cases, it's primarily about that deep fake detection. Is this synthetic content?
Can I, can I trust this? But if it involves a person back to my idea about the human layer, that's where the approach I mentioned can be very relevant. Not just understanding is it synthetic, but is this the person that they're claiming to be?
Hmm. What's that one thing you see people doing today that makes you shake your head a little bit and go, folks, that's no longer gonna stand. We gotta be smarter than that.
Well, certainly, and this may be as a no-brainer, but it's just answering, answering your phone to an unknown number and engaging in any type of serious conversation or taking any action as a result of that, you know, that, that, uh, maybe that that's a no brainer, but, uh, people still do it. I don't answer my phone if it's a number. I don't know.
Um, and, and to be totally candid, even if it is a number that I know, I'm, I am much more careful these days than I used to be because numbers can be spoofed, of course. Uh, so that's one thing definitively. But then I, I really do, I wanna emphasize this area of video conferencing because we all, we live our lives in this little window, right?
We live our days and we operate our businesses on the information that we get. Uh, we can no longer trust that. And so, um, my advice right now is to, to start viewing it as such, again, this idea of zero trust.
Mm-hmm. You know, to your point, I don't even remember all the numbers I'm supposed to know. So when I do see a number that calls me, I always wait to let it go through and then I check to see if I've actually texted with somebody on that number just to know that's stuff Exactly that, that's exactly the right, the right approach.
I think that's a healthy thing to do. Yeah. All right folks.
You heard it here. Better to be safe than sorry. And all those little things you can do to protect yourself will make all kinds of difference.
But we might need more tech no matter what. 'cause tech, fights, tech, Hey Jim, thanks for being on the show. Thanks so much, Mike.
Enjoyed it. All Right. And be you guys.
And Steve, Every new tool wears a scarlet letter at first, not because it's broken, but because it's misunderstood. History always decides this the same way the output wins. The only question is where do you wanna live?
Hey everyone, it's Shimmy and welcome to this week. Shimmy says, I'm glad you're here with me. You know, what a crazy week.
What a crazy week. There's so much going on. Originally, if you would've asked me on Monday, I would've told you we're talking about TBOs today, you know, forming their own first, their own social network, then their own religion.
Now, I saw a thing where they're actually starting a site where they can rent humans. Bogle mind boggling. But I want to talk to you about something else today.
I call it AI in the Scarlet Letter. Let's talk about it. How many of you remember reading the Scarlet Letter in school?
I see some of you aren't raising your hands. Look, the fact is, I don't even know if kids read in school anymore, but if you remember the Scarlet Letter, the poor lady had to have that a, the red a because of what she's done. But there's something that's been bugging me a while, and it, it has to do with the output of ai.
Because, you know, in a world where AI can seemingly generate anything and everything, there seems to be a scarlet letter attached to anything and everything. It does. It's a stigma that somehow AI generated output is less than inferior, cheap.
You know exactly what I'm talking about because some of you are guilty of it. I'm probably guilty of it sometimes too. Some of us, for a certain percentage, we, and when we hear, oh, I did this in ai, or this was helped with the creation of ai, or this was done by ai, a lot of people just tune out.
They just say, I don't care whether it's good. I don't care how good it is. You know what?
It's ai so therefore it's bad. It must be junk. It's less than, it's not human.
It's soulless. And what I've come to understand in talking to people about why they say that is it has very little to do with the quality of the output. It's really about fear.
And you may not wanna admit it, but I'm telling you, it's about fear. You. It's fear of what can happen to you.
Are you gonna have a job? Are you going be relevant? Are you going to be left behind?
Are you going to live below the AI poverty line? Now, I don't know how long this current, let's call it scarlet letter phase, is going to going to last, but I do know one thing for sure it's going to pass. 'cause it always does.
The reason simple, the rate of improvement we're seeing an n ai generated work product is absolutely smoking the rate of improvement in heck human generated work. It's not even close. Now this doesn't mean that humans don't matter, they're not important or they're not running the show.
It just means that the curve is real and eventually output and quality when arguments over prejudice and ignorance. We've seen this movie before. Now for me, it started a long time ago, believe it or not, when I was a little kid and I was a little kid once, um, the phrase made in Japan meant something derogatory.
When you had toys or items made in de de Japan, it meant it was cheap, low quality disposable. You didn't expect it to last. It was like tin toy, shaky electronics and those silly Godzilla movies where you had some big rubber lizards stepping on cardboard buildings.
But you watch the movie anyway 'cause it was pretty good. Um, but nobody bought Japanese products for quality. They were made in Japan.
But then fast forward a few years, all of a sudden Japan is making the finest quality products in the world. They become world renowned for their craftsmanship. For the, the Toyota Katza, right?
The, the manufacturing, just in time inventory, precision design. Cars that run forever are electronics that define the category. Sony, Panasonic, that stigma evaporated.
Well, it, it really didn't. Eva evaporated, it moved, it moved from Japan to China, right? For many of you out there, over the last, I don't know, 35 years, if you're that old, made in China, connoted a another similar kind of thing.
Cheap, copied, they stole our IP and they made a a, an inferior copy of it. Knockoffs disposable junk. You know, over the last five, seven years, something happened.
That stigma disappeared too. All of a sudden today, China produces some of the most advanced electronics. I I couldn't do the show without Chinese electronics vehicles.
Electric vehicles, industrial systems. That scarlet letter's gone away too. And you know what?
AI's right on schedule, it's scarlet Letter's gonna disappear too. Let's talk about software. When I first started hearing about AI writing code, it was terrible.
It didn't get the syntax right. The logic was all wrong. There was no APIs.
We didn't have MCP. Anyone who tried it back then remembers thinking, you know, this is cute. But I would not put any production level AI generated code out in production.
But here's the thing, ai, it really is learning fast, really, really fast. And today we estimate 60% of all the code generates coming from ai. Plenty of developers will tell you that AI generated code today is roughly on par with human code, average human code.
Not elite, not as good as the best developers out there, but it's usable. It's shipable, it's product a adjacent if not product ready. But here's the scary thing that maybe no one's told you.
Human code quality has basically stated a straight line for a long time. X amount of vulnerabilities per x amount of y amount of lines. AI code quality, though it, the quality keeps going up, the vulnerabilities keep going down.
So it's roughly on par with human generated code now, but it continues to go down and when it goes down, it's gonna be better. I know, I know I hear some of you already saying it, but shimmy, but shimmy AI will never code as well as the best developers. I agree today it won't.
But what about tomorrow? What about the day after that? That Scarlet letter isn't gonna be there forever.
Because here's what always happens. Once a tool reaches a critical mass of adoption, once it becomes responsible for a meaningful percentage of the output, acceptance follows. Not because people fall in love with the tool or forget the scarlet letter, but it's because results matter.
Results and profit beat ideology every single time undefeated. And that scarlet letter then starts to fade. And we're seeing the same thing, not just with code.
Now we're seeing with written content. You know, I still see some content sites out there. They put big banners, 100% human content, no AI used in making this content.
And they wear it like a proud badge, their own scarlet letter. I don't know. To me that feels quaint.
You know what? Maybe even a little arrogant. 'cause look, there's always gonna be craftspeople who make things by hand, one at a time.
God bless 'em. We love getting handmade stuff like that. And their work is valuable.
It has value. But you know what? Since like the early 19 hundreds mass production didn't ruin ruin society, it empowered it, it gave rise to the middle class.
It, it gave everything, right? Today we want scale. We want mass production development.
Co-development is no longer a cottage industry either is developing content, either is developing art, music, and film produced by AI is going to be the defining success story of this century. Just like mass production and assembly lines were the defining success story of the last century. Go to Dearborn, Michigan, go to a Ford factory.
See for yourself, I'll tell you this, as someone who writes constantly and has been evolving in, in terms of my use of ai, let me be very clear what I think it can and can't do today anyway. I don't think AI's writing the great next or the next Great American novel or anybody's novel, not great, not today. But can it write your next email, your next blog post marketing copy or internal memo letters?
Hell yeah, absolutely. And when I say AI writes, I don't mean it writes it in a vacuum. You just don't say ai.
Write me a letter. That's the biggest mistake I see people making over and over again. I see 'em making it here at Techstrong.
I see 'em making it in other companies. I see 'em making it. Everyone I speak to, AI output is only as good as the person guiding it.
I said it before, I'll say it again. It's humans. Humans who provide the spark.
You know, borrow a line or paraphrase a line from Billy Joel. AI doesn't start the fire my friends humans do. It's that spark.
A good writer using AI will still produce better prose than a bad writer using the same tools or a bad writer. Not using ai. AI amplifies your thinking.
It amplifies your talent. It doesn't replace it. Let's move on from writing.
Let's, let's go to something even more creative. 'cause here's another area where I see craziness, right? Synthetic music, synthetic art, synthetic video.
So-called synthetic, meaning it's made with ai, it's made by ai. You know what? I've seen some people say it's soulless, it's cold, it's slop, it's fake.
I saw a guy on on LinkedIn today who you know, posted an AI picture and put a little disclaimer, this isn't a real picture. It was created by ai. I don't care who created it, it's still a real picture.
It's just not a picture created by a human. And that's okay, but it doesn't make it any less real. So most of the critics who, who you know, call this stuff slop, fake, soulless, synthetic.
I don't know how many of them actually have listened to some of the best examples of synthetic music. Watch some of the best synthetic videos that AI's popped up or spend time with the art that's AI is churning out. 'cause if they did, they'd be uncomfortable about admitting something.
They'd have to admit that some of it is just pretty damn good and it's getting better every single day. That's the thing, it keeps getting better. Second, just like I said with code in writing, the quality depends on the human behind it.
A musician with skill is gonna produce better AI assisted music than someone without it. A designer with a good eye is going to create better visuals and designs than someone just clicking in random prompting. Tools don't en erase talent, they reward it and enhance it.
And AI is create AI's creating the next generation of talented tool users. Today, AI is not creating the next Picasso painting today. No, it may in the future though, given a human's input and spark.
But for a lot of what we do, 80% of what we do, social graphics, marketing visuals, short form entertainment, storytelling, TikTok videos and all this IT friends, it's already more than good enough. It's already more than good enough. But I hear what some of you are saying.
You're saying, shimmy, we're overwhelmed. We're adrift in AI slop. There's too much AI generated content.
Hey, you know what? We're not wrong. You're not wrong about feeling that there.
No doubt it's a flood. It's exhausting. Especially some of the stuff that obviously is AI and people try to play it off as not.
But let's be honest, let's be honest with ourselves, content overload. Don't blame it all on ai. That didn't start with ai.
It's not gonna end with ai. AI just poured gasoline on a fire that was already burning. And right now, AI creation feels more to me like a kid with a new bike.
If you were ever a kid and well, you were all kids once, some of you may still be kids, but if you ever got a new bike, you remember what it was like the first day you woke up after you got your new bike, you couldn't wait to get out there. Hopefully there was no school. You rode it everywhere.
You showed it to everyone, you just kept wearing it till the tires wore out. Just couldn't stop riding that bike. But that phase passed eventually, right?
Then we're gonna go through a similar thing here with ai. I think instead of trying to use it for everything, we'll use it for the things that it makes sense to use and that's where we're heading. And it won't have the scarlet letter.
So what won't pass is we need to rethink how we filter, how we prioritize, and how we make sense of all information. How to pick what we should use AI for and what we shouldn't. And here's a really delicious irony into this whole thing.
AI is gonna help us do that too, because it has that kind of ability. It is total disruption. So here's my shimmy takeaway on this Thursday, guys.
This Scarlet letter phase of AI is not the destination. It's no more on a mile marker, on a really great looking highway in the near future. The idea that AI generated output is inferior is going to feel ridiculous.
The made by AI label is going to fade way into the background and be forgotten. Just like so many other made in labels before it were the people who embrace AI will move faster, they'll create more, they'll compete at a different level. Those who don't will live, as I said before, below the AI poverty line, AI poverty.
And that's not a threat, that's not a hype. That's history. And that's how things work.
The only real question to you guys to watching this is where do you wanna live below the AI poverty line or above it? That's shimmy and I'll see you next week. Ai, generative AI escaped out into the internet now.
AI is escaping from your data center. Is your network ready for it? Does your network have AI for the network?
Does AI AI exist in your network? Join me on the Tick Field Day podcast as we follow up with Cisco and find out all about networking and ai. Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from members of the Tech Field Day delegate community. It's often recording association with one of our events, tech Field Day, part of the future and group. And this podcast has also published us to company site text on tv on this episode presented by Cisco, we're discussing how AI has escaped your data center and is invading your entire network Before the discussion, let's meet who's on the panel today.
Hi, uh, I'm Andy Banter. I'm currently doing work with, uh, mag io and have been a longtime person in the tech industry doing storage networking. And I'm Jack Poller.
I am an industry analyst with Paradigm Technica, focused on the intersection of cybersecurity, uh, and artificial intelligence. And I'm Lee Paton, the VP of the Secure and product portfolio at Cisco. A big fan of Tech Field Day, really, really for honored to be here.
And of course I'm Alistair Cook, an event lead here at Tech Field Day, the event lead for AI infrastructure field day four, where Jack and Andy attended and also colleagues of Lee's. Uh, it struck us as we're going through the, all of the presentations, but particularly this, the Cisco enterprise networking presentations that AI is both a workload, but it's also an enabling technology for the network. And as we're seeing a bit of maturity in how companies are using ai, moving from just some beginnings thoughts of what they might do to actually doing useful work with ai, um, the network has become one of those things where there's features that we might want to use.
There's also, uh, much more complexity in managing that work network as a, as a whole. So, um, we definitely saw the importance of having both AI for your network, but also your network for ai. And Andy, I wanted, wanted you to have some space on particularly that topic because I think it was one of the things you, you saw maybe a bit of confusion amongst some of the, the messages we saw our infrastructure.
Well, Absolutely, and I mean it's, uh, we saw some presentations from companies other than Cisco networking companies other than Cisco as well. But Cisco, uh, presented a a huge amount of material and the topics kept switching where whether they were talking about the infrastructure necessary to carry ai and that was that, uh, included like bigger, faster switches as well as more secure routing and better transport of the data, as well as, uh, as using AI tools to manage your network or, or to, uh, um, configure, debug, troubleshoot, configure your network as well as tools for, um, you know, AI tools for doing things like using, uh, location with, uh, wireless devices. So there was a lot of, um, it was sometimes you needed like a scorecard to be keep track of whether we were talking about the infrastructure necessary for AI or how, uh, Cisco was presenting this infrastructure to enable it to, to enable their own AI for their own purposes.
And it was, uh, it was just a, a very interesting mix of topics and it, it really goes to demonstrate what AI infrastructure means, uh, to these field day events where it's, it's both enabling the AI and the AI is enabling the infrastructure. I think what makes it really interesting in addition to that is it's now becoming a self-reinforcing positive feedback loop where you enhance your infrastructure to enable AI development, and then that enables you to develop, uh, more complex AI models that allows you to both fine tune your network as well as to manage it, troubleshoot it, and build even better and faster and, uh, infrastructure for your AI development. So there's a lot going on that Cisco presented.
The other part that I thought was interesting is this what, you know, sort of the premise here that we're talking about is AI escaping the data center. And traditionally we think about AI and giant data centers and training on the data centers, and there's not as many people are gonna be doing that as they are going to be doing inference and particularly inference at the edge where you have devices that are going to be generating a lot of data, moving a lot of data around and wanting to do analysis and AI with that data. But you can't transport that back to a core data center to do your analysis because it takes too long and it costs too much time and bits moving down the wire.
So you wanna move your AI infrastructure to the edge and all of the various different technologies that Cisco is bringing to bear to support that both as networking infrastructure for ai and again, the ability to apply AI to help you build that type of infrastructure. I think what's interesting with that latter point that Jack, is that if you think about four or five years ago, most of the CIO CTOs were saying, we're gonna just move everything to the cloud. We're gonna put it all in, uh, relying on the, on the, uh, hyperscalers that run these workloads.
For us, what we're seeing more and more is now it's much more federated. So obviously the, the, the AWSs and the Azures and the Google clouds, the world are going nowhere. There's still a very important element, but we're seeing more of a mix where also investing in the, in, uh, our customers in their own data centers, investing in colo facilities.
And then of course that idea of what can I do at the edge, particularly when it comes to those, those heavy DPU workloads that I maybe from an interesting perspective more, uh, effective to do closer to where I need that done, where I need to be able to actually make a decision on something. Think of things like video applications, think of things like small language models from a chat perspective, much more effectiveness doing those at the age, both from a cost perspective, but also just from a, an outcome perspective of what those customers trying to drive. Yeah, I think, uh, one of the things that I've seen over the course of Tech Field day and other presentations is that, you know, we tend to think about AI right now is we're hyperfocused on large language models and the chat GPT type things.
There's a lot of AI applications that are go beyond that or analysis of real-time analysis of data. For instance, every time you make a credit card purchase that goes back to somewhere where there's a decision made, whether that's a fraudulent charge or a valid charge, and there's a lot of data that's collected in order to make that decision. But you wanna make that in real time.
You don't want somebody to put their credit card on the reader and then wait a minute for an answer to come back whether this is good, uh, uh, valid or inval charge. Um, we've also seen things where you're doing outta the sports analysis or applying AI to motion tracking and all of that has to happen as close to real time as possible. So the, the lag of moving that data into the core, whether it's on premises, uh, core data center or whether it's moving to the cloud, sometimes that can be too much.
So there's a technology driver and a motivator towards, uh, putting stuff in your own compute infrastructure where, where, regardless of where that is versus renting that infrastructure from the hyperscalers. But there's also use cases where renting hyperscaler you can take advantage of their economies of scale. And it does make sense, still Makes so, and I mean a couple of the examples Jack just talked about are talking about, uh, potentially data centers sized, uh, you know, models that you need to work with, whereas there was, uh, some discussion last week on a couple places where you don't need data centerized models.
Uh, one of the examples I remember was controlling robotics where you, uh, you would, you basically need a factory sized model to figure out what's going on. Uh, and the other one that wouldn't impressed me was the, the ability to, um, feed in information about your enterprise network to the AI assistant and have the AI assistant use both the, the source of knowledge from Cisco as well as information about your local network to be able to better answer questions about your own network. So these are, these are two examples of really edge based systems where it's using the local data rather than drawing from a huge bottle.
And, and just to sort of take both of those points together, if we think of the, the robotics use case, the, the, the most of the factories that are doing things like loading and moving things around using robotics now have a rule that if any one of those robots goes missing for more than 250 milliseconds, every piece of robotics in that, that location shuts down because the, just the risk of, of human life, the risk of damage and things like that. And so that's really why it, it needs to be done at the edge, uh, to the second point around, uh, then how do we extend some of these AI approaches and apply them to, to the technology itself. Uh, the MCP server approach is very interesting.
So, uh, a lot of the investments we're making in, in AI within Cisco, we've developed this deep network learning model. So we know networks better than say a general purpose. L LM knows networks and we've been able to take, we had the largest data lake from a networking perspective of anyone in the industry.
We've been able to use that to go train these models. We been able to take what we know from 30 years of running CCIE courses and all that knowledge. We've able to take every support case it's ever been entered.
We've been able to put that all into the soup and produce a model that's much more effective in terms of analyzing a network and, and understanding what's going on with it and making a sensible set of recommendations to further that out though the idea of using MCP to further enrich that because there is gonna be data that our customers have in their networks, customers have about their own applications that need to be, uh, sort of correlated somewhat with what we know about the network in order to be able to actually produce a, a, an actionable outcome to be able to make these networks better, faster, more reliable, and ultimately in service of driving employee satisfaction and customer satisfaction to let these businesses do a better job. But this Is where I think that gets to be a little bit of a blurring of that line between networking for AI and AI for networking where there's more of a feedback loop between those two parts where the actual data that, or the, the AI that knows about how the network operates can be published out through CP so that the AI that's delivering some business value that might have some dependency on that network can talk to the, the network, the AI for your application and can talk to the AI for your networking. And that's, this becomes a bit of a blurring of where you've got just pure infrastructure that is there to host your AI and where there's an AI in that infrastructure that's assisting the AI that's doing something for business.
And this is where the whole idea of agent to agent communication and, and the CP standards and some of this emerging cooperation between different parts of the, your AI estate become really crucial. One of the things we had joked about, um, during the presentation was do could the, uh, Cisco's LLM passed the CCIE exam and we were joking about it, but in some sense it's a really important point in that there is a tremendous amount of, um, tribal knowledge that has been developed over decades that Cisco has, uh, both just from the telemetry Cisco's collected and just the tribal knowledge of the CCI and all the different people involved in this that, that you're able to bring to bear. And when you tie that in with the ability to have an agent query and get the very quickly, get the information it needs and apply, uh, changes as quickly, then you, that that sort of automation and feedback loop that Alistair was talking about becomes very powerful.
And that's I think where Andy and I are very interested in, that's that application of AI for networking that isn't just, hey, we're, you know, it's not, it's, it's a, not a variation of, um, the traditional Silicon Valley of let's do the, the next version bigger, better, faster. We've got, you know, we've gone from a 400 G to an 800 G network, look at our switch, right? It's a lot more than that.
These things are actually, are actually starting to have value above and beyond just the ability to move packets back and forth. And I think that's very interesting and very valuable to, and to AI and even to non-AI data centers. Right?
And, and I mean, regu, when the question came up about passing CCIE, uh, even pointed out that the, the exam itself includes lots of questions and, and just learning the answer to the questions is one thing, but one of the tests for CCIE is that you actually need to build out a network. And it would be very interesting to, to, you know, see AI assisted get to the point where it could actually build out a network. And, uh, you know, this, this gets into the idea of AI feeding ai.
Where, uh, could the, uh, could the AI assistant start figuring out that its own demands on the network were increasing the load on the network and therefore would need to expand the network? I think there's an interesting sort of, um, parallel to this. You know, they can build an LLM that can pass the bar exam.
You can build an l LM that can pass any sort of medical exams. I don't want an AI lawyer and I probably don't want an AI doctor. And so we think about this the same way we ask ourselves the question, if A-C-C-I-E was standing in front of this screen right now, seeing what I'm seeing, what would they do based on using all that knowledge?
They're very much designed around how do we do human and loop? You still need to have some level of hands on the wheel to make sure that we don't set these things loose and have it make changes and make adverse effects. The difference is though, that where this is gonna enhance the workflow for most of our operators is that that engine is able, that agent is able to look at these things at AI scale.
So it's ability to look across large data sets and infer the interesting parts of that. Because a lot of the time when you're doing this troubleshooting, 95% of the things you look at are, are dead ends. Being able to sort of jump straight to the root cause and go, this is the problem, and if you do this we'll fix that.
And as we get more confidence over time, there'll be certain things that are routine and mundane that we say, Hey, you know what? AI agent, you make that change for me. Monitor that change and roll that change back if it has an adverse effect that we didn't expect.
Right. And I mean, it regular been pointed out that, uh, the, there's the trust factor and right now it simply makes recommendations without actually acting on them. So it it can help it so it can build the trust.
Yep. And part of the trust is, hey, I've seen this. I, I, as the agent, I've seen this before and another network and I've made this change and this was the, this, you know, based on the, the millions of, of pieces of knowledge I've got about networks and the effect of making these sort of changes, I believe this is the best course of action for you.
Right. And you'll over time build that trust as you see that, do that and enhance that workflow. There's, there's another aspect to this, which I think we're somewhat alluding to, which is, and you know, and I'm a former reform software and hardware engineer and you know, I no longer code and 99% of the people no longer code in assembly because we trust compilers to do that job for us.
And in fact, most people no longer code. And see, because we trust a high level compiler to do it in a very high level language. And one way to look at the LLMs is we're, we're interacting with this complex machinery at a very high level instead of at the very low level now.
And it allows us to go from the pain and effort of having to manually tweak every single knob in the environment to, and to look at every single configurable item to see exactly what the current state is, to have the AI do a lot of that heavy lifting for us so that the human in the loop is involved. And I think this is where you're driving at the human in the loop is making a higher level decisionmaking. It's not saying tweak it.
I want to tweak this particular command line, do this command line to make this parameter on this particular interface change. Right? It's basically saying the AI is saying, I'm applying, it changes, and this is the list of changes.
Does that look good to you? Just review it rather than thinking about it all. And in fact, at some point it should be able to say, I'm going to make a change to make the network do this at a very high level instead of change interface one, interface two, and have a thousand changes.
All of that's gonna be hi hidden by, in a higher level language. And that the value of that is tremendous in terms of changing the workload on the limited, the most limited resource we have in the enterprise is the humans, right? We, we have infinite number of compute cycles relative to humans.
And, and I mean, I I think that if I was a, a network administrator, I might want both. I might have, I might want something that says, we're gonna apply this set of commands to these switches and this is what this, this set of commands does. And where, where the, the, the element of this is that, that it gets us to true intent based networking.
We've talked about it for a long time. My ability to express in English what I would like the network to do and have it implemented doesn't mean that you, you can, I can have my 15-year-old son walk in there and with no networking knowledge and do that, you still need to know what you're doing. But a great example of that is we built into, uh, there's this approach we're taking within my product, uh, portfolio called Unified Branch.
And it's the ability to deploy a full stack of networking in a repeatable fashion across thousands up to, you know, 10,000 plus locations. And it starts with going into the assistant and saying, please build me a branch design based on a Cisco validated design for unified branch. And because it's a validated design, because we've tested it, we pull forward what we believe the right, uh, defaults are, and you, you manually inspect those.
You, you can tweak some things and change some things and then when you press go, that agent goes in the background, does the logical deployment associated with that network. And what you're really doing then is you're reducing the amount of time upfront, reducing the risk of error. And when it comes time to do that install, you're reducing the technical capability of the person going on site to do that install because it effectively becomes plug and play all the design work and all the configurations done, send somebody out there that understands low voltage cabling and how to, how to physically wire things up and physically mount things.
And, uh, they don't need to know DHCP or DNS or any of the things that, you know, a network engineer would need to know to go configure that from scratch. Yeah. If I, if I can mention another topic here, the, one of the other things that kind of fascinated me from this discussion was the define time management, uh, aspect of the wireless networking where, uh, it, the way it was described, it could almost paint a picture of where the wireless devices are in an environment without having any cameras.
And that, that I thought was kind of cool. The idea that just to define time management, it can actually locate in a, in a room or in a, a building where all the wireless devices are and essentially draw you a map to them. I think our ability to match the physical world and the digital world together in an interesting way.
And sometimes that means physical sensors, cameras and what have you, but we can infer a lot from that digital footprint that devices leave behind in order to be able to paint a pretty rich picture there. Uh, whilst portfolio is super interesting, they've been doing AI before, it was really, you know, the, the thing Jo Radio resource management, having a, a, a model that understands making changes. 'cause no, you're typically not tuning things like channel selection channel with someone what have you on the fly manually in a network.
So the ability, again, using that, those large data sets to say, look at all the radio environments that I understand and what's, you know, almost like a digital twin approach, what's similar about this one to other networks I've seen? And if I make this change, this is the expected result. And it's able to read that out to you, but it's not gonna come to you and say, Hey, I suggest we, we turn DFS off on this channel, or we move from this channel to this channel, or we, we lower this channel with, that's not the way our radios work.
They've tended to self optimize for a time, but AI has allowed that to get much more effective and, and much more better understanding causality. I make this change, I see this result, and if that result is good, I leave it. If it's not, I roll it back and try something different.
What's interesting also is that the wireless has gotten to a point now where it's not either a secondary communication channel or just for users and laptops, right? We're now using wireless, as you said, in robotics, right? In ai, we are moving enough data across the, the wireless networks that it can a backbone particularly at the edge for your AI information that's moving back and forth and what you're doing with ai.
And I think that that's, you know, we have to change our perspective and, you know, on, on what the, the communication channel really is and why we're using it. And, you know, why would you drag a wire any everywhere if you, if wireless is capable of doing all of these things. Um, some of the things presented was about the of my head, but the, the, the multiple antennas, and I know there's MIMO and, but there's just, you have so many antennas and the ability to do so much with that, that gets you much better, uh, interference, uh, capabilities and, uh, uh, was it, uh, reliable wireless networking?
I think ultra reliable. Yeah, Ultra reliable wireless backhoe. It's a super interesting product because I mentioned those robots don't have time to roam from one access point to another access point the way a traditional client would.
And so we've built the ability to run standard wifi your, your standard, uh, IT environment combined with your OT environment in the same hardware unit, and be able to manage those through the same domain. And the robots are gonna use the, the ability to connect to multiple access points at once and your standard device, you know, your, your, your, um, tablets and things you might be using as a human in that, that factory space or in that warehouse space, continue to use standard wifi. So really, really interesting, uh, evolution of how we do things.
And again, it just means we're getting richer and deeper sets of data about what goes on in those environments. And our ability to do that inferencing and be able to make intelligent decisions about that is what's gonna drive a higher quality network for our customers. And it should largely be invisible.
I I joke that the, the networks like oxygen, you only notice that if you're not getting enough, right? It should really be in the background there supporting the things you're trying to do and be able to, to do that in a very intelligent way. Well, I think that's, that's actually a very interesting perspective in looking at it for ai, right?
And thinking about the AI network, and right now, I don't think we can look at it as oxygen. When you think about in, you know, a lot of what we're talking about both AI for networking and networking for ai, but specifically networking for AI is we are placing such heavy demands on the network that we can't, we're not at the stage right now where we can treat it for as, as oxygen where it's just in the background. It is a critical component that if it is not in, not architected correctly, the network itself isn't designed correctly, then the AI is not going to work the way we want it to.
Yeah. And that plays both in, in data center, but also in, in the wider know, across the multiple presentations we had from different business units within Cisco at AI infrastructure four, we saw that, as I say, the, this is not, not yet a place where you can say, a standard network design is gonna be ample for everything I need. I'm not gonna need to be worried about, I'm not gonna be constrained by both data center and and beyond out to edge.
And we already know that networking out to it's a cloud is also a significant impact for us. Um, yeah, it's, it's a long way before we can just assume the network is good enough because it's there. And I think that's, that's a path that, that Cisco is, is definitely on.
And I think within the Cisco teams as the, this skating well ahead of, of, of where the puck is for most customers at the moment, because these technologies do take time to get out, we we're seeing, uh, a bit of a rush amongst customers to, to realize that their networking inside their own organization needs to get better to deploy AI as a production workload, as something that's delivering business value. And yeah, it'll be a little while before that. It's, it's an oxygen kind of supply, right?
Yeah. And, and I mean, one of the things that Cisco brought out was the fact that they're emerging essentially their on-premises data center or, uh, enterprise networking tools with their, uh, cloud work networking tools. And they talked about the features that these actually can also look at software defined wins well, and be able to manage those the same way as well.
One of the aspects we really haven't talked about here, I'm sure Jack would love to talk about, is all the additional security that this, these things bring up. Uh, we talked some about secure routing last week and all the, the additional features that were needed for secure routing. And I don't think that we really have paid enough attention to how much additional, uh, infrastructure and horsepower is needed to actually do the level of security that we're gonna need in an AI ready world.
Yeah. One of, one of the things that Cisco is, I think, very proud of and rightly so, is, uh, the inclusion of, uh, PQT or post quantum cryptography in the hardware, uh, you know, in the devices, and particularly having hardware enablement for it, because as Andy said, um, doing cryptography and alone is very, uh, is computationally expensive. So the ability to have hardware that accelerates it and have, uh, the post quantum algorithms involved means that we're already prepping for it.
We run have a rate, great risk right now of what's called harvest now, decrypt later, where somebody grabs the data, holds onto it for a while until that data can be decrypted. And a lot of the data that we have is very ephemeral. We don't really care about it after a couple of minutes, but there's a lot of critical data that crosses a network that is actually very long lived.
That is, should somebody get ahold of it, it becomes very, you know, and a lot of that we think about things like PII like our, our personal identifier, social security numbers, or whatever the equivalent is in the European countries. Should somebody get ahold of that now, then, you know, at some future date they can decrypt that, get access to it, that opens up a whole ball of wax that we don't wanna, you know, we don't want people to get access to that data. So the ability to have a quantum safe encryption of that type of data is very critical, and we need to do that now rather than tomorrow.
I was gonna say, some of the ephemeral data that you talk about, Jack, is, uh, is ephemeral to the source, source and destination of it right then. But if it's information that can be held onto and decrypted later can be used to predictive analysis, gather the information that's being fed to a robot, uh, you, you can probably say, the robot did this, and therefore, if we wanna interfere with that robot's operation, uh, we know that the robots gonna be doing this at this time so that we can interfere with it there. And so it's one of those things where it's not just personal identification, but it's also being able to pick out patterns and use them, uh, against both people.
And, and, um, robots, Before we dive, get too far into this, before we get too far into this rabbit hole, I'm gonna have to put an end to this conversation because as always, when I get a group of my delegates together and particularly bring along some expert from within one of our, our sponsoring companies, the conversation could go on for hours. And I know we're already at about time, so if people do want to continue this conversation after they've, uh, listened to this podcast, where can people connect with you to continue that? I answer every DM on LinkedIn, so my LinkedIn is open, look me up on, on LinkedIn, not hard to find.
Um, that's the best way to start the conversation. I'm, I'm more active there than I am on, on other social channels. com And you can find me on LinkedIn and, uh, blue Sky Social and, uh, on my periodic, um, blog post at andy banter substack com.
Course. I'm Alistair Cook, you can find me on tick field day com. You can also find me on LinkedIn and across all of your favorite social media, the same as you can find all of the tech fields team on all of the social medias.
Also watch for us on Techstrong TV and across a bunch of the other places that we work with the wider future and group. So thank you so much for listening to this episode of The Tech Field Day podcast, and please subscribe on YouTube or in your favorite podcast application so you don't miss an episode. Make sure to give us a, a nice high rating, nice review as well so other people can find us.
And this broad podcast was brought to you by Cisco and Tech Field, the home IT experts from across the enterprise, and a part of the for upcoming events and more episodes, head to Tech Field Day podcast, us on tech. Thanks for listening, and we will see you next week Permitting AI work. MCP is still flawed.
Snowflake partners with open ai. Oracle's uncertain on Cerner automation flaws abound, wifi bugs are still out there. And we're gonna take a closer look at some molting claws in this episode of the Tech Field Day Rundown.
Greetings, everyone, welcome to the Tech Field Day rundown. Hey, did you know that we're not quite 10% done with the year because it's February, it is February the fourth as a matter of fact, and we are very happy to be here on the tech field Day rundown. It is national homemade soup day.
And, and I don't know about some of you because I know it's cold in the country, it's like 60 degrees where I'm at a soup. I don't know, maybe I, I guess, but, uh, one thing that I am certain about is that my co-host, Mr. Alistair Cook, is back from his sojourn to the northern hemisphere.
Al, it's good to see you. It's a pleasure to be here. And I managed to stay in the warm parts of the Northern Hemisphere, despite it being the cold time of year.
Uh, incidentally, it's a national day for New Zealand at the end of this week. February 7th is our national day. Why Tan Day?
And, um, it's an experience to look forward to. Another experience to look forward to, of course, is all of the stories we have today. Exactly.
And, uh, we we're gonna kick 'em off. 'cause I mean, there's some security stuff, it's kind of funny, uh, but of course there's some AI stuff that maybe is gonna help people be more funny. Uh, hundreds of top actors and musicians have launched a global campaign that is accusing ai companies of stealing copyrighted work to train generative models backed by major unions.
The human artistry campaign is calling for a permission first approach to AI warning that unauthorized training threatens jobs and the future of human creativity. The fight comes as parts of the music industry begins. Striking licensing deals with AI firms and revealing a growing divide between confrontation and collaboration.
Now, I was gonna put a really pithy joke at the end of this, but I couldn't get any of the AI agents to come up with a really good one. So I guess I'll just turn it over to you. Is trying to create a collective amongst creators going to get the folks that run these AI algorithms to actually do what they're supposed to do in the first place?
Maybe, but probably not. Uh, the AI vendors build their large language models by harvesting everything they can see on the internet, whether they're supposed to or not. And that part's up for debate.
We already covered this. So a couple of times, I think on the rundown, talking about some of the court cases that are currently in play around fair use of content. And all of the AI providers say they're just fair use.
We're just taking little segments and we're, uh, generating something that is a combination of multiple sources the way a human does when they read content. Uh, the challenge, of course, is that the rate at which content is being then spewed back outta these large language models. It vastly exceeds the ability of human creators to actually create content and, uh, a large number of content creators.
And this includes, um, in this case, Chaka, Kahan and Blanc and s Johansson are unhappy that the things they've been creating over their lifetime have been harvested and are now being used to generate AI slop. Um, I believe that was actually mentioned in the, in the quotes, uh, basically American side creators are being sidelined, not just American, but that's where this, the jurisdiction where this is being fought is about American, uh, creators and, but essentially the whole spirit of human creation as being diluted by these large AI models that have stolen previous creation. So, uh, it's a continuing story.
This is definitely not one we've heard the end of. Even though organizations like Open AI have already struck deals with music publishers, they haven't yet struck deals with book, uh, creation or movie houses. And so we probably will see this, we'll see a, a shift from the sort of confrontational, you can't do this to actually, we can be in business together and all be successful.
You, you can compensate me for the things that I've, I've created that you'll then reusing in the same way that, uh, libraries pay royalties, radio stations, pay royalties, AI companies will be continuing to pay royalties for more and more things. Um, leads us to some concerns about how things go when the, uh, recalculation of the AI AI market and the AI infrastructure market comes up. Uh, it's also probably gonna be yet another barrier to new entrant into creating large language models.
Not sure that we need new entrants creating new large language models, but that's part of how, how industry works. So yes, this is a continuing battle. This is another group of creators who have seen that there's been success by other collectives and are aiming to have more success.
I think more likely the large AI companies will talk with the publishers rather than the creators. So it'll be the large organizations like the, uh, movie studios and the large book publication houses that actually do the negotiation with the AI vendors. Uh, it's unlikely to be the, the smaller organizations that don't, just don't have the financial clout of these, uh, large publishing companies.
Of course, our stories all revolve around AI all of the time at the moment. And, uh, we've noticed that, uh, security researchers have found some vulnerabilities in CP servers, uh, those from Anthropic and from Microsoft. And it highlights the growing risks around systems.
And those, these particular flaws are ones that would allow, uh, sensitive data to be exfiltrated or, but have code execution, uh, running inside the environments reside. But as I've said earlier today, the S and MCP stands for security. And so you've gotta bolt security and controls all around this.
Uh, and this needs to be done very, very rapidly because m CCP servers are proliferating and a being a headline thing. Uh, Tom, have we seen the last of these big security vulnerabilities in MCP servers, or is this gonna be a story for the agents? I feel like we could probably do the story every week and it would still be relevant.
And the reason why is the oldest problem in security. Well, it's that guy's job. Uh, I don't know why you, you are getting onto me.
I wrote the code. I didn't know I had to secure all the function calls. What, what, what do you mean it's, it's in the server, right?
I just hand it off to them and it works. And we have heard that before. So one of the things that we've, we've been dealing with a lot is this idea that these AI agents can just pretty much do whatever they want, and that doesn't really work very well, right?
Like, we can't just have 15 people, um, you know, requesting assets along the way. And let, let's just assume for a moment that these AI agents are digital coworkers and not just scripts that are tools. Um, I want you to imagine in your office, let's just say for example, that there are 15 people running around and they all need resources and, and things from, uh, on high.
Do you let them go talk to the CEO directly or call and, and buy things without that? Or do you have a process for approving those things? And do you have, uh, guardrails in place so that, for example, your employees don't go out and buy $4,800 worth of ballpoint pens?
I, I'm guessing that you do, right? That all gets funneled somewhere. And then there's a person who looks at things and makes these these judgment calls.
Hey, guess what? We have that in the AI world, and it's called MCP, but I'm gonna tell you a little secret folks. MCP does not have native security.
It's not designed to do that. MCP servers are chokepoints, it's checkpoint charlie, if you will. And if you're old enough to get that reference, you probably take ibuprofen before you go to bed tonight.
MCP servers need to have security attached to them. That means we're all gonna have to get real smart real fast about where the security controls are. Because one of the things that was reported in this excellent article that I will come back to in a few minutes, so put a pin in that, is this idea that we are rapidly expanding the capabilities of these agent-based tools without checking first to see what kind of security is in place to prevent them from doing things they're not supposed to.
In this particular case, one of the things that happened with the Microsoft flaw in particular is that a lot of the, uh, the tool sets that work on the backend were written in markdown. Markdown is fairly easy to understand, but if you don't put any kind of guardrails in place, people can inject just about anything into markdown and make it happen because it is a plain text language. And so that's one of the things that you will see more about soon.
We have to be very serious about this. We have to create structure that includes security as well as helping people understand that there's no inherent security and using MCP and MCP servers unless you put it there. And if you didn't put it there, assume you don't have any at all.
So I think that we're gonna be talking about this story for quite a bit to come, and I hope that I'm not talking about the same companies having the same problem over and over again. Snowflake and OpenAI have announced a $200 million multi-year deal to embed open AI's advanced AI models directly into snowflake's AI data cloud for enterprise use. The partnership allows companies to run AI agents alongside their own governed data across major cloud platforms, reducing security and compliance risks, or so they say by focusing on deployment, governance, and real world business use, the deal signals a shift from AI experimentation towards scalable production ready enterprise ai.
Al do you think snowflake's getting the better end of this deal, or do you think open AI is just trying to get another logo added to one of their slides? Oh, I think this is definitely a, a great deal for Snowflake. Uh, snowflake has been progressively positioning themself as the place where you put all of your data that you wanna use in your AI applications, then something's gotta link those AI applications to that data.
And when that's a cloud delivered AI model that's, uh, sitting in somebody else's cloud tenancy, in this case, open AI's, cloud tenancy, uh, there's some more security concerns around that. If we can push that AI service inside snowflake's tenancy, there's one less security boundary we're crossing as we're doing AI things. Uh, one of the fun things I saw in this is, of course, snowflake being available across all of the major, uh, public cloud platforms means that they're kind of a data standardization, or they, they erode the differentiation between those clouds make it easier for companies to use the same snowflake data platform across multiple clouds, wherever the data needs to be ingested.
Now they're adding the open AI large language models and agents inside that same cross cloud platform where you're not nearly so tied to a single cloud or, uh, essentially it's a, a meta service provider going on here with Snowflake. And now adding these features, our open AI likes this because it takes away some of the objection handling of taking your company sensitive data and pushing it across the internet to open AI servers. Uh, this places the data governance alongside the execution of the AI models.
So that seems to be a good thing, and I like that this isn't just a, the two things together. There's a commitment of the engineering teams to work together to particularly improve open AI's SDKs, their software development kits and their agent kits to make it easier to create the agents on top. I kind of think that we'll be very helpful for putting a ring fence around snowflake's clients at making sure that nobody wants to exit Snowflake service, but it will bring quite a lot of value to particularly the larger organizations who are wanting to use, uh, open AI and Snowflake together.
Naturally, this is still pretty early on and as a rolling theme throughout AI tools and ag agent ai, uh, security of data, security of execution, security of ai, um, we'll continue to see that need for, uh, security as we see AI being deployed at scale, particularly ag agent AI at scale. It's gonna be an ongoing story. Just, you'll, you'll hear us talking about it a lot.
Another topic we're gonna talk about a lot is some of the consequences of spending a lot of money to build out for ai. And Oracle is currently reportedly considering layoffs of up to 30,000 of the staff, as well as the sale of the entire Cerner healthcare unit that they only acquired four years ago. This is coming about because Oracle is under increasing financial pressure and asset having higher costs to borrow money to build out the hundreds of millions of dollars worth of infrastructure.
Uh, despite for, for these AI projects, uh, despite these challenges, Oracle says, uh, they remain committed to its long-term AI and cloud strategy. Thomas, is that a good strategy That remains to be seen? Because all I've seen so far is that a lot of companies are going out there and buying up huge amounts of assets and then realizing they don't have a payoff strategy for this.
Uh, I don't know if you guys have been following Nate Jones on, or Nate b Jones, I think is his actual, uh, name on, on YouTube. He also has a substack and a bunch of other things, and he's one of the people that kind of first brought this idea into my head a few months ago. Um, these companies make money, right?
Like we know that we, we've seen the quarterly reports because as soon as they release one, it's all we can talk about. And they make a lot of money, but they're spending a lot of money, right? Like, this isn't a thing where they're creating value in a cloud somewhere.
They are literally buying infrastructure in the hopes that down the road they're gonna be able to pay off when, well, according to what Sam Altman said at the Cisco AI Summit, you know, that, that, that there's some big huge breakthrough. There's a chat GPT moment, which I thought was kind of musing coming from that guy. Uh, but one of the things that happens though is that that money is owed to somebody else.
This isn't like an Elon Musk thing where I can just trade money between a couple of companies that I own and it all works out in the end. Or that weird circular logic problem that you have where like Nvidia buys a $2 billion worth of stuff from, uh, from a company that's then gonna turn around and buy $2 billion of stuff from Nvidia and like the money that does, that's not what's happening here. What's happening is, is that a company is giving real money to another company and that money has to come from somewhere.
Now I know where it should come from because I have a business degree and I took business accounting, oh God, uh, 30 years ago almost. Um, that money to buy that stuff comes outta your profits. You know, the money that's left over after you've paid off everything.
So like, if I paid all my salaries and I paid all of my bills and all that other stuff, and all the money that I have left over, I use that to buy things that I need. Like that's business 1 0 1, right? But that's not how business 1 0 2 works in 2026 because the profits are what the shareholders deserve.
And if they don't get their profits, oh, they might sell their stock and that might cause the stock price to go down. And that might mean that Larry Ellison can't buy a TV network allegedly. So what they do instead is the same thing that Amazon's doing.
It's the same thing Oracle's doing. You gotta make the numbers work somehow. Well, remember how I told you that you, the profit is what's left over after you pay your bills, like your people's salaries.
Aha. Haha. If I can reduce the number of salaries that I have to pay, then it means I can cut the overhead and the money that I need to use to pay out all of this stuff is gonna come out of that instead of out of the profits.
So, you know, why not lay off 30,000 people that make, uh, you know, a hundred thousand dollars a year? Uh, what is that? That's still not as much as we're spending on ai, but the important thing is, is that it looks like we're trying to do this.
Why not sell off Cerner? Well, great. What are you gonna do with the money?
We're gonna plow it right back into ai. And, and when you hear people talk about this, their, their thought process behind the whole thing is, well, if we can just build enough ai, if we can just build enough supply, then people will have to buy it to do what? Exactly, because I think we tried that one time with tulips, and I seem to remember reading about that.
In business school, JFR researchers have uncovered two high severity vulnerabilities in the innate n AI powered automation platform that could allow attackers to remotely execute malicious code. The flaws which affect both JavaScript and Python execution are considered very easy to exploit and highlight the growing security risks of, say It with me folks, AI driven automation tools. Organizations are using N eight N and they are being urged to update immediately and rethink patching strategies.
Because one of the things we're seeing is that AI is shortening the time between vulnerability disclosure and active exploitation. It's almost like people are able to get AI to actually jump out there and start doing this. So, al my question to you is these two severities that were uncovered in N eight n, does that mean that people really should be thinking more carefully about how they're deploying these tools?
Or should they be rethinking their patching strategies to keep things up to date more quickly? Uh, and the answer of course is why not both? Yeah, 4K lost dose.
Yeah, I mean, these are pretty high vulnerability. 5. They're both remote code execution vulnerabilities.
5, little harder to achieve, uh, but running that code inside whatever platform you're using in a n and NAN is a, a workflow automation tool, uh, that uses essentially AG agentic AI in the background. Uh, consequently this falls into our top theme of today, uh, security for your, uh, agents. Uh, a couple of elements in this.
One is that the NATM platform can be run as a cloud service, in which case, uh, or consumed as a cloud service, in which case you should be consuming the latest released version at all times. That's what cloud services are about, right? You, you rapidly release all of the latest versions.
Uh, I hope the cloud providers that are delivering, or at least the the N 18 cloud service does this, but you can also deploy this on premises, and that will be a pretty common mode for more regulated, more controlled, uh, enterprise use, or there's a whole lot of personal use of this as well as I've seen in my, uh, news feeds too. Uh, fundamentally, if you're running it on premises, you, you have to keep it patched and updated. And there's nothing specific to NA that is, is here a vulnerability due to, uh, the speed at which AI tools can scan and discover faults?
This is, this is not specific to NAN, it's absolutely across your entire IT estate AI tools can find and manipulate and, and, um, exploit these security vulnerabilities very rapidly, far faster than a highly skilled human being, and certainly faster than the script who used to be your biggest concern. Uh, this does then bring about some thoughts around, well, often the, the known vulnerabilities have a known resolution and known patch resolution that we simply don't deploy fast enough. Now, if most vulnerable vulnerabilities were never exploited in the wild, this wasn't so much of a concern.
But if now it's conceivable that every vulnerability will be exploited within hours, days of it being known to somebody would discover that does then make us think about how quickly can I get patches out? How quickly can I safely get patches out? I can help us with this.
There is absolutely a market around, there's a set of products around that will help you with understanding which updates, which types of updates to which types of software are safe to deploy at great speed, and also to discover if a fault has occurred and roll those back. These are the AI site reliability engineering tools that look at all changes, not just patching. And so like alcohol being the resolution to and source of all of life's problems, AI is going to be the source of and resolution to many of our problems and IT infrastructure over the coming years.
Hey, this story doesn't have AI in it. A newly discovered, uh, vulnerability in Broadcom wifi chip sets has allowed attackers to knock entire five gigahertz wireless networks offline with a single un authenticated signal forcing a manual reset of the affected servers. The floor was discovered through fuzz testing, uh, sending random signals into a, a, uh, system under test, and it affects widely used hardware and raises some serious concerns about business continuity, reliability, and trust.
And these always on always accessible wireless networks. Patches are available, but physical device firmware updating cycles means that this is gonna take a while to get out, particularly as wifi has become an in incre increasingly high criticality service within organizations. Uh, is this a reason to have some sort of diversity in the wifi hardware you have out or is there some other way of mitigating this risk?
Well, it's kind of hard to do that because typically you don't buy Broadcom access points, do you? You buy from a company that buys from Broadcom and uses the wireless chip set as their underpinning. So you may not actually know whether or not you're operating one of these chip sets that's, uh, problematic.
Uh, that's why you really should be patching on a regular basis. And, and just so you know, because, uh, this is five gigahertz specific, a lot of people are like, oh, that must be bad. 4 gigahertz band offline with a single unauthenticated signal when I pop popcorn?
4 gigahertz, uh, spectrum completely offline. So the problem here is that you can send a malformed packet to one of these access points and, and it basically causes it to freeze and it needs to go into, uh, you know, you need to go bounce it. And, and I get that, like that's a problem that a lot of people have pointed out.
Why do we allow that to happen? Oh, I don't know. Why do we allow these access points to scan for clients and offer wifi networks and all these other things while being unauthenticated?
Why, why do we offer guest networks in, uh, restaurants and sporting events and things like that? The problem is not with the authentication mechanism that that's, that's not, uh, uh, up for debate. Because if you have an authenticated network, that means you have to need to provide a password somewhere.
It means you need to write it down, which means you need to restrict access to it. I applaud the researchers that found this for fuzzing it out enough to go, wow, nobody really thought about this, because it is, it's a fundamental 8 0 2 point 11 problem that's down, you know, at a protocol layer. Nobody's gonna see this unless they're looking for it and unless they're trying to to do that.
And bravo to Broadcom for getting the patches out on time, but this is a good thing. So yeah, everybody stop, put the keyboards down. This is a good thing because we found it because we can patch it and because we can keep it from happening.
Again, this is not something that was found by a security tool that was like doing millions of iterations on the 8 0 2 point 11, uh, standard document and found this one little weird thing. This was the kind of real security research that we should be doing more often to find these problems. And, and I want more of that because if we can find these things before they hit prime time and become massive flaws across the entire system, then the patch lead time that we're talking about becomes a little bit longer.
Because then that gives Broadcom a chance to issue a patch that then other organizations that use Broadcom hardware can implement. And I will tell you that wifi people are actually some of the best ones about pushing patches out pretty quickly because all of my wifi friends out there, you know how big of a pain in the neck it is to deal with drivers. And this is basically a driver update.
Alright, it's big time folks. Hope you guys have your little bibs and some drawn butter because we're gonna be roasting a particular crustacean security researcher Jason Miller at One Password, who is a former Field day presenter, warns that AI agent platforms like open claw, nay, mbot, nay open clawed are creating a dangerous new attack surface. Were seemingly harmless skills written in, marked down.
Oh, hey, there's that thing I mentioned before. They can function as malware delivery mechanisms. His investigation uncovered highly downloaded skills that used fake prerequisites and set up instructions to trick users into executing info, stealing malware, exposing credentials, tokens, and sensitive data.
The incident highlights how agent ecosystems blur the line between documentation and execution, which turns skill registries into supply chains that attackers can then exploit, underscoring the urgent need for stronger trust layers, providence and permission controls and AI agent frameworks. Now, here's something that I think is kind of fascinating about this whole thing. This is all developed over the course of 10 days.
We went from open to mt bot to open claw to claw book, is it Claw book, whatever. Uh, and then one password. Jason Miller just comes out and basically has, if you go read the blog post that we we're gonna link here 'cause it is a thing of beauty.
Jason does not mince words. If you have deployed open claw on a, on a production machine in your business, assume all of your data is on the internet and you've been breached. So I'm gonna, I'm gonna let you start this al because I, I gotta warm up my pincers here.
How do we feel about this? Um, shocked, stunned, horrified. Uh, well anyway, um, so while I was at AI Infrastructure Field day last week, I was reading some of the early news of this is what Claude Bot, malt bot, whatever it's being renamed to does.
And the idea is you install the, the base software on a, on a computer, and then you say, here's everything I know, work out how to help me do what I wanna do. Oh, by the way, here's everything I communicate with. Here's all of my data.
Here's, here's access to all of my emails, all of my texts, everything go work out for yourself, how to help me, and equally, how to help other people who communicate with me. Now, what bot, uh, malt bot, what this agent then does is says, right, I've, I've discovered you need to do something. I'm gonna go and install some software to help me do it.
And this is, uh, one of the attack vectors because there are wild West style registries where you can just pull down descriptions of how to help. They're called skills. And as, uh, Tom says, it's just a markdown text file that describes a set of actions.
If you are particularly reckless and who isn't, when you're deploying this stuff, you can say to your agent, just get everything you need. Don't bother asking me. Just download it, install it.
I don't care. Don't care what it's, so your agent then goes out to, uh, these repositories says, I need a skill in order to do something basic. Uh, and it was a Twitter integration.
One was the one that, that Jason particularly called out, I need to integrate with Twitter or X. Uh, there's a prereq for that integration, which is to download some malware that is gonna steal every piece of information on the computer that you have just given access to everything. It is the most downloaded skill from that particular repository, and it's, particularly, its Mac malware, which, uh, affects me, wouldn't affect me if I was still using Windows.
But of course, there's plenty of Windows malware that you could download as a skill too. Uh, a huge number of the skills that are on these repositories contain malware. And it comes back to we need governance around this in the same way that we need governance and security around things like Docker.
When you download a docker container from Docker hub, there is governance around it, there is history of when was it released, who has released it. That's the very minimum we need as we're actually, as somebody's running these repositories. And that's, again, something that's called out in this excellent article.
If you run one of these repositories, you need to make sure you're not being a distributor of malware. Well, maybe that's not accidental. Uh, yeah.
This, this is, uh, an interesting train wreck happening. I sincerely hope nobody, uh, none of our listeners, none of our friends have deployed this anywhere, but inside a very controlled sandbox and gave access to a very limited amount of data. I suspect not, I suspect people will have gotten quite excited about this amazing capability and I'm now wondering where they're going to work next week.
Um, yeah. Yeah. I mean, it just feels painful, doesn't it, Tom?
It does. And like, look, the, they had all the right ideas at the beginning, right? It was on Mac stories for God's sakes.
Like, that's where I first saw it. I was like, oh, neat. I don't have a use for this right now, but I'll keep an eye on it.
And then we had all the renaming going on, which by the way, all the people squatting on those names to try to sell, you know, uh, crypto tokens. Bad, bad people don't do that. But like, the more you deal with this, and, and Jason did an amazing job on this, this, by the way, um, like, it, it is in the same problem we have with MCP server, right?
Well, whose job is security? Well, it's their job, not mine. I passed it off to the people who are supposed to secure things in, in general, this is the idea of what you want something to do.
If I have a, a thing that I want to use to extend the capability of my device, then I give it a, uh, I give it a manifest and tell it to go get things that it needs, right? It's really, really straightforward, except nobody is checking to see what's going on. And that's the problem.
You cannot trust people. You can trust a person I trust Al I don't trust people. And these tools are written by people, not a person.
Yeah, Mt bought Claude. Claude bought Claude Molt, mult Claude bought mult, whatever it was written by a guy. We know who it was.
And he has everybody's best intentions in heart. I'm not, I'm not telling, saying that the guy did anything wrong. He, he actually, the fact that it got mentioned on stage at the Cisco AI Summit to Sam Altman as the hot new thing, and you could just, you could physically feel Sam Altman rolling his eyes.
It's like, I am the most important human being on the planet. I'm gonna change the way the society works. And you're talking to me about some guy who wrote something in his garage that I don't think is very important.
Who cares? The fact that he's in the conversation should tell you the guy's got a, a huge future ahead of him. The problem is, is that he did not think through the fact that people are idiots and some people are deceptive idiots.
And that's exactly what happened, because all I have to do is upload the script and it says, go download this thing. That's not bad. That downloaded thing says, well, you need to go fetch this package.
That's not bad. But at no point along the way did anybody stop and do a sanity check and go, should I really be downloading things that I am not checking? And if you follow the chain down far enough, what you're doing is you're pulling a binary that has no visibility whatsoever.
And one of the first things that binary does is it restricts Mac o S's gatekeeper. Show of hands. And I'm not gonna count, but you, you know who you are.
Put a finger down if you have ever copied a command line from a webpage telling you to execute it in the terminal to make sure that a piece of software is able to install without triggering a warning message or failing to install properly. I hope every one of you people put your fingers down because we've all done it. We shouldn't.
We know better. If you don't know what a command does, don't run it. If you don't understand where a binary is coming from, don't install it.
And if it's a piece of base 64 encoded code in a URL, you better not Jason uploaded this thing to virus total and it hit immediately. It's like, I don't know what this thing is, but it's not good. This is the problem.
We, okay, you know that I have a security podcast, you know that I do Security Field day and you know that a lot of my friends are security nerds. We all say the same thing. You cannot pass the buck on security.
And if you think you can please send me your social security number and your bank account passwords. I mean, I'm a trustworthy person, right? What am I gonna do with them?
If you're sitting there shaking your head saying, you wouldn't do that, then don't do it for anybody else. Yeah, guess what? I I have all the hope in the world that Open Claw is going to change the way that we talk about agent workflows, because it's doing exactly what an AI agent should be doing.
It's monitoring all of your communications channels, it's munging all of that data together, and it's giving you ideas and helping you do stuff. In theory, open Claw is great in practice. People are untrustworthy idiots that are gonna try to compromise it to steal all of your data, because guess what, at the heart of every brand new paradigm shifting thing that we've been talking a lot for the last 20 years are the same core group of criminal grifters that wanna make a quick buck from whatever's next.
And this is fundamentally, that's a, this is a classic supply chain attack. You need to secure your supply chain. It really, it, it's security 1 0 1.
It's, it's, well, it's security zero one, really, uh, uh, we could rant and rave about this all day, and, uh, we probably will, but you don't wanna listen to that all day. What you do wanna listen to though is Cloud Field Day Cloud Field Day will be back. I'll be back in the United States, surprisingly soon be March 11th and 12th.
Uh, we'll be back with Cloud Field day number 25, as usual, great schedule of content, great schedule of delegates joining us. I'm looking forward to another trip back to the United States. And of course, uh, Tom doesn't get to leave the United States.
You have the end of March cover. I do, because we're gonna be at RSAC this year. I bet you there's gonna be some talk about Open Claw and among other things that we talk about on the rundown every week.
But we have exciting presentations from folks like Veeam. Uh, we have, uh, great presentations from Commvault. Uh, we have, uh, a lot of presentations including Object First.
Um, they're, they're, you know, recently now part of Veeam. Uh, check out the website. Uh, we're gonna be listing our delegates there pretty soon.
There are a lot of those same people that are out there telling you don't download software that you don't know what it does. Uh, more importantly, the reason that we're excited to be there is because there's so many other great things going around on RSA, uh, rum Group and, uh, Textron TV have some cool stuff going on. There's gonna be a lot of content coming out of it, and we hope that you're tuned in for all of it.
'cause it really is, it's the biggest security show of the year. Uh, so big in fact that we have to schedule our events away from it because nobody else wants to do anything when it's our SAC time. And, uh, it, it should be a lot of fun.
And you're gonna hear a lot of familiar voices. You're gonna hear a lot of familiar things that we've been telling you guys for the last 10 years, and hopefully this time, just like the year of VDI, I hope it's gonna stick. But you know, what does stick is that every week we're back here with more great news.
Sometimes it feels like we're repeating ourselves, but you know what? That's why you watch The Rundown every week because we put out new episodes every Wednesday. We put 'em up on YouTube.
You can download us in your favorite podcast application of choice. 2 x whatever. I don't care.
Uh, the rundown is also stream on text, on TV in a bunch of other places. Do us a favor though. We want you to go down here and leave a comment.
Um, you know, put your finger down if you did the thing that I told you that we all did. Uh, tell me if you've run Claude Bot, uh, you can use an alias if you, if you wanna make sure that you're not gonna get in trouble. Uh, but we want to hear from you and we want to let you know that we're gonna be back next Wednesday to talk about all the IT news of the week.
That was for myself, for my co-host, Alistair Cook, and for the Tank of Lobsters that I have over there currently fighting to see who's gonna be my new AI agent. I wanna wish you all a happy week. And do me a favor, put some authentication in place, do it for the lobsters.
We'll see you next week.