Techstrong TV January 22, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. My next guest is Lee Rossi.
Lee is the co-founder and CTO of a company called Sim Space. And let's welcome him. Hey, Lee, welcome.
Thanks for coming on Textron tv. Uh, pleasure to be here. So Lee, we're gonna talk about sim space, we're gonna talk about AI and cybersecurity and all that.
But let's start off talking about Lee. Give us a sense of, uh, how you got here. Yeah, happy to, of course.
The, um, yeah, so, um, well I started probably like a few of us old guys 25, 30 years ago doing cybersecurity. I, um, in 2000, I joined a place called MIT Lincoln Laboratory, and MIT, Lincoln Lab Sure is one National Lab building tech for, um, for the government, a national security apparatus, so intelligence, community, military, and all that. And when I was at the lab, it was all about creating test beds and ranges and how do I test and evaluate cybersecurity.
We didn't call it cybersecurity at the time, it was No, we called it In, it was all the other stuff. But this general problem was the same, is how do I test, evaluate, figure out what capabilities to develop for cybersecurity in that space. And the lab as a national security is all about, hey, not just cyber, but cyber with that overlap on mission systems, defending radars and air defense and missile defense and space control.
So it's always about tech rigor. It was about measurements, it was about evaluations and how do we actually create the most effective cybersecurity solutions, um, as possible. That, that's my quick answer for the 15 years at the national lab.
And then when we were there, we spun out and created SIM based a company. So actually it was a wonderful time. I, I learned a lot.
We did a lot with the, uh, with the US government, but then the question became cyber is, is broader than just the national security. It's impacting banks, it's impacting cities, it's impacting our way of living. And we spun out the company to be able to help out the broader, the broader us.
Um, so, so that's how we started 2015 and we created the company. Um, let me pause there for a quick second so I'm not monologuing Sure. Hey, that's a great story.
You know, I'm trying to think who I knew they spun out a company outta Lincoln and um, uh, Well, BitSight is another one. So Steven Boyer, uh, another Boston based company. No, all about, uh, risk and cyber insurance.
Yeah, no, I know BitSight. No, this was like a personal friend of mine and I just, you know, you, you're doing this so long that you start, it all runs into it. But yeah, they, I mean, look, the Lincoln Labs turned out some amazing, amazing technology, right?
You know, that's part of you, you talk about government investment and is it worth it? And pure r and d and stuff like that. Yeah.
Those labs were worth every penny They invested in 'em. Man, You know what? I talked to the leadership and we talk about tech transition and what does it mean to do tech transition for some of the labs?
It's one thing you do patents and do technology, but it started when I was at the lab and it was true when I left. It's about spinning out the people, the whole apparatus, which is, yes, you can spin out the tech, but there's an element of everybody that goes with it. The people that know the domain, know the space, have the passion.
Yeah. So I remember when I joined the lab, it was optical networking at the time. In 2000 and Uhhuh, the whole group spun out.
It was 50, 60 people that were created Sycamore Networks and Photon X. Yes. And yes, it's the technology, but it was literally the whole group.
So when we spun out, it was the whole team. And of course there was Hutch, the co-founder and a lot of experience in cyber command. And we created a company with the foundation of the people knowing the space, the technology, and then marrying it up to the problem, which was, which is really exciting.
I love it. I love it. And you know, there's a lesson out there, folks pay attention, Lee, let's talk sim space.
Yeah. So 2015 is what you said? Yep, yep.
So another overnight sensation, you know, not in 10 years. I, how that goes. I, I started this company in 20, well, technically 2013, but we first published 2014.
But I, I've been doing, you know, startups for 30 plus years. Um, you talked about kind of where the inspiration came from, where the passion came from. Yeah.
But you know, there's, there's been a lot of water under the bridge from 2015 to today. And maybe the biggest boat under there, of course is ai, right? AI seems to be changing everything or it has the potential to change everything.
Yeah. Talk to us about AI and, and how it's kind of changing or, or diverting or, or, you know, influencing the mission of sim space. Yeah, no, wonderful question.
And let me maybe give a two minute on or a minute on what is sim space and then Right. The impact for that. So fundamentally, what we are providing technology wise, it's a cyber range.
A cyber range is a very realistic environment to allow you to train operators, test technology, develop it, validate it. So it's effectively a proving ground. How do I provide a super realistic environment that matches, say, a bank or a power company or a military.
In that environment, I can develop, uh, new technologies, new cybersecurity solutions, make sure that they work in a beautiful dev test setup so I can really support technology. And then, um, allow operators, allow individuals, soc members, team members to train with the technology, and then, uh, train as a team. So from a training standpoint, how do I push people to failure, like attacks and realism, but in a safe environment?
So from a training, push the tech and push the people to the breaking point. So you can learn, so you can improve, you know, what it's like. It's, um, you wanna, you wanna experience failure many, many times So that in a, in a, in a safe setup in a range before you actually go through the real world to do that.
So that's from a training and a testing standpoint, AI makes it interesting because now, you know, we always have these technology evolution cycles we've gone through from mainframes to client server to cloud, and now hitting the ai. And the big push there is things are moving a lot faster. It's automating a lot of these day-to-day tasks for the SOX and the others.
And, and there is a transformation going on. Every large enterprise is trying to figure out how does this apply to what we're doing in terms of tech stack? And then also how do we actually get into the, the team aspect of it from a, from a retooling and a and adapting for the team members.
Let me pause there for a second because I wanna dive into a lot more of it, but, um, let me, let me, let me pause for a second for any. Sure. So look, the concept of a cyber range, yeah, I don't think that's foreign, you know, for our security friends out there, you, you know, you've AppSec I think they get what a cyber range is.
Some are my non-security people. Yeah. Think of it as just a huge testing environment where you can set up, you know, very elaborate, complicated, sophisticated type of environments to, to test your security on.
I mean, and this is, you know, cyber ranges are not necessarily new. No. Right.
We've had them for a while, right. Always Right. Testing.
But what, what is new, I think is the, uh, the, the, the pressure, the, the focus, you know, AI is, is making us sharpen our aim, if you will. Yeah. Shortening the cycle of Yeah.
Of, you know, when we discover things to when we gotta do things, it's, it's bringing more of a sense of urgency, let's say. It is. But it's also becoming, um, I, I'll call it going from a nice to have to a must have, and let me explain it.
So to your point, we've been doing cyber arrange, or I've been doing cyber arranger for 25 years. It just happened to be for the government and for developing and testing tools commercially. People think of cyber as more for training, but that's more recent commercial angle on it.
Yes. Um, the rea, the reason why I think the ranges are really important for AI and AgTech is they need to be able to train, they need to be able to train on an environment they need to be able to learn. So how do you create the data sets?
How do you create the environment to allow the agent to be able to understand all kinds of different types of networks, the diversity that's in them, the different types of attacks. So they need to train on an environment, train on attacks, be able to figure out, am I making the right decision or the wrong decision? And being able to actually allow the developers to be like, Hey, as I'm developing this new tech, how do I make sure that it is doing the job equivalent to a human?
And we're not quite there, but it's getting a lot better to be able to do that. So the range, we think of it as, again, it's an AI proving grounds. How do I put new tech in there to prove that it's effective?
But also is it safe? Like any new technology, it's interesting, whether it's cloud or crypto and all that, there's always the pluses. But then the question is, what about the negatives?
What are the potential risks that I may have with, um, with AI solutions? So how do I prove that the AI cannot be co-opted, cannot be deceived, cannot be, uh, manipulated to be able to do that. So you wanna be able to prove that out for that.
But to your point, things are moving fast. AI is accelerating the rate of the attacks. It is accelerating the rate of people doing, but it's also got the benefits from a defensive side is can leverage it to be able to sift through more data, understand what is happening, to be able to accelerate my response to an accelerating attack, uh, surface or an attacks attack.
Attacks. I get it. I get it.
And, and you're right. And, and you know, unfortunately, we haven't had enough experience with a lot of these AI scenarios, right? And, and so being able to train on a cyber range is, is, um, I mean it's a resource a, a deadly needed resource, let's call it that, right?
Because we just don't have the, we don't have a written book necessarily on this stuff yet. No, and I heard a great quote from somebody, any enterprise who's gonna be leveraging AI is gonna get disrupted. So there is a disruptive element to AI in that.
And that is not just the people side, it is the process. You need to be willing to change your processes, how you do business, it's gonna change your tech stack. And of course, it's also gonna have to allow the operators to be disrupted, not replaced.
In my mind. We talk about a lot of these. It's gonna eliminate a lot of tier one, tier two SOC positions.
I think people need to embrace, to some degree the changes coming with ai, even from a defensive side to leverage it to be able to actually go through and, and do the job a little bit faster and all that. But, but it is transforming the way enterprises are actually, uh, operating. And along with that is how do I now train and work with alongside AI defensive solutions, AgTech and AI solutions.
So operators coexisting working side by side with new technologies, AI based defending against potentially accelerating and more vicious attack scenarios. So AI for offensive purposes, being targeted enterprises. And so, so yes, it is, it is changing how the defense is working in terms of the tools and the people, but it's also working to counter potentially an accelerating threat.
Absolutely. Lee, if you don't mind, I want to turn back to sim space a little bit. Yeah.
'cause we're running low on time for people out there saying, Hey, this is just what we're looking for, right? We need, we need to get our people up to speed. We need to, you know, you can't fight or defend against something you don't even understand.
We need to understand, we need to, you know, get our response battle Yeah. Plans in order. What's the best way to engage sim space?
Um, well go to the website. If you go to the website, you can look at the URL, there's a link over there to be able to contact us and of course want to be able to engage and work through. com is, uh, is a way to get to us.
But I would like to make the point, I think when we talk to a lot of our enterprise customers, the first question is even is, which AI is right for me? How do I prove and find which the right solution is? How do I actually go through this pre-production before you deploy it for anything as disruptive?
How do I even make sure that it is the right tech for me and in the right area? And not only do I prove that it's effective, but how do I make sure it's safe and not bringing me down the railroad? And then of course, I wanna be able to train with whatever you've chosen, but I think there's an element of bill versus buy.
What am I building myself versus what am I buying? And then there's an element of how do I train my staff to leverage it? But there's a series of questions before to figure out what tech is appropriate and in what areas for a particular enterprise.
Because you don't wanna roll something else that's gonna make decision on your behalf that you don't fully understand of what it's doing and how it applies to, uh, your shop. But the website is the quick answer. Absolutely.
Lee, I want to, um, you know, you've, you, how do you choose what's the right ai or are they kind of interchangeable at some level? Right? We, right now, we're still at the beginning of this whole journey.
We are. So we, we, you know, we have the frontier model. So do you want to use Claude?
Do you want to use chat? GPT? Yeah, you want to use Gemini, but really I think what we're gonna see going forward is a new generation of models.
You wanna call 'em small language models, you know, based on rag, based on a lot of different things. But it's, what we're gonna find is you don't need these big frontier models for a lot of the tasks that we're going to use AI for. I, I, so this is where let the vendors come up with the base way, the best ways to be able to solve the problem, whether it's big, small, whatever the models are.
Uh, I look at it more as the solution is being provided by whomever it is. Um, I think it's gonna be interesting to be able to see is they're all gonna come up with pretty decent generic models trained on broad enterprises and broad sets of data. That's gonna be awesome.
I think the more interesting is how do you then tailor and retrain those models for the specific enterprises in terms of their network, their processes, their data and all that. So, generic models wonderful for the wide set of attacks, but then how do I choose a technology that can actually train and understand on the enterprise specific businesses model architecture to be much more, um, suited for that particular setup. So AI is great, but needs to be trained and tailored to the specific nuances of that enterprise.
Just like every human operator, they, they know their business, they know which ips are interesting, they know what their processes are. Um, that's what you want these models to train on to get more specific to the enterprise, uh, itself. I love it.
Hey Lee, I promise I'd get you outta here on time. I'm going, um, thank you very much for coming on and getting us a little smart here today and telling us about SIM space. Congratulations on 10 plus years building a great company.
Come back, keep us posted. Happy to chat with you about this anytime. Well, thank you so much.
I really appreciate the time. And again, it's wonderful chatting. Thank you so much.
Alrighty. Lee Rossi, co-founder CTO of sim space here on Textron tv. We're gonna take a break.
We'll be back with more. Stay tuned. Hey guys, thanks for the throw.
We're here with Fitz Nolan, who's vice president of AI and architecture for SmartBear. And we're having a chat about well, integrity, at least software integrity, because well, it's becoming a bigger issue in the age of AI fits. Welcome the show.
Thanks so much for having me. Great to be here. Mike.
What is going on these days? 'cause I think we are all super focused on coding faster than ever, but I'm not quite clear that that has, uh, improved the quality of the applications we're building. So what do we need to be thinking about here as we kind of go forward and what are we overlooking?
Yeah, it's a great question. Uh, obviously AI is transformative technology, and I think a lot of the attention has been paid to the software development side of the house and how it's changing, uh, the speed at which we can develop new features and we can prototype new applications. But ultimately what that means then is if you're producing product at a faster rate, you need to ensure quality at that same rate.
Uh, or else quality will just be a bottleneck for getting all those great new features you're building out into the market. So, um, that's really where we're focused a lot at SmartBear on the integrity of your applications, the correctness of your applications in this new world of software, uh, development driven by ai, who's Taken responsibility for that. And I asked the question because a lot of times developers are like, well, I checked my code in and that was it for me.
And away I go on to the next thing. So somebody on the other side of that check-in process is probably looking at all this stuff and there's more of this code than ever for them to review. So how do they keep pace?
Yeah, it's a great question. I think what you'll see is, and kind of where we're placing our bets or one of our bets is on, um, AI powered quality assurance or bringing the qa, um, task, uh, into the, the velocity of the software development world in with ai. And so if you have AI powering your software development, you need AI powering your qa.
And so, um, you know, we have AI infused to different points of the quality assurance, uh, life cycle. So whether that's managing your test cases or helping you execute test cases, or even helping you author brand new test cases using ai, we have, uh, you know, solutions in that space. And, and that's really where we're focusing, because again, all the money right now really seems to be going into software development.
If you look at the biggest names in ai, they're all focusing on coding assistance and, and, um, you know, coding agents, uh, you know, we're, we're kind of trying to meet them in the future with, uh, QA powered by AI as well. So to your question about who owns that, um, I think it's QA teams. I think it's, um, a lot of it actually will go back to product management teams, the folks who define the functional specifications of software and, um, you know, the people who decide ultimately what they want to build.
So whether that's developers at small organizations or PM folks at larger organizations, um, we think that functional specification really acts like the source of truth, both for what you're building, but also for what you're testing that functional spec becomes your set of test cases in a sense. Will those folks there maybe just call up a DevOps engineer to fix the problem then? 'cause it seems like the pace at which we're moving, maybe they don't wanna go back to the original developer, and so perhaps they're gonna have somebody else kinda review that code and, um, put in the fix as it were.
I think it, I think you'll see more of, um, almost like a blending of roles. So it, it could be a DevOps role who's kind of straddling, you know, infrastructure and, and source code. Potentially.
It could be a product manager who's straddling, uh, functional specifications and quality assurance. Um, it could be a developer at smaller organizations who's, who's wearing all the hats, right? Certain developers at, at startups, uh, will often be doing the infrastructure of the DevOps role, but they'll be doing quality assurance as well.
They might even be specking certain behaviors out like a PM might do. So it, it's going to allow AI will allow a blending of roles across the different, um, points in the software development lifecycle, I think. Mm-hmm.
Do we need a different AI model to review the code that was created using another AI model? I think there's a tendency where people are kinda using the same AI model to kind of test things, and it's like, well, I don't think that AI model is gonna catch the original error. Uh, 'cause it's kind of like asking the fox to guard the hen house, right?
That's right. That's right. Who's watching the watchmen?
Um, so totally, I think it's a good question. The, the, it's sort of a subtle one. I don't think you necessarily need a different model, but you need a different structure and framework and composition of, um, your task for QA versus for software development, you could use the same model, but, um, that's at the lowest level above the level of the model.
You have all the structure of the questions you're asking and the task you're trying to achieve. So in the case of software development, you have things like planning, um, implementation, execution, unit testing, and then post merge or post-deployment to your staging environment. On the QA side, you might have things like definitions of correctness, um, visual accuracy or visual correctness, and then functional or operational correctness.
And then even a third check kind of a little lower level. And this is maybe where we bring in DevOps. Um, you know, does the database integrity, uh, look good?
Uh, is the, the volume of traffic going through our system, is that normal or is that abnormal? Is the latency correct? Things like that, you know, you kinda have different areas that you focus on.
You could use the same model. You could use Gemini or chat GPT or Anthropics clog whatever you want. Um, but it's the structure of those prompts.
It's the focus of the prompt. It's the way you use the model that is different for those different purposes. So I think you're okay to, to te te test your AI with AI as long as you, you have a fundamentally different construction of the problem.
Um, as you kind of think this through for a minute, are you concerned that maybe we're gonna have a spate of applications showing up in production environments where the quality is even lower than it might have been historically? And we're gonna have these, um, some sort of situation where the number of incidents are gonna just dramatically increase? Yes.
There, there's absolutely that possibility. There's a bunch of different ways to take that one angle, um, which I'm, I'm not, uh, too deeply entrenched in. It's like the cybersecurity angle there.
So I'll kind of mention that That's absolutely a, a consideration. I think I saw one of your, one of your previous, uh, videos, but touched on that a little bit. Um, an area that's pretty interesting for us though, uh, is, is what you were saying, you kind of hinted at it.
You might have apps that are lower quality, but who's consuming your app in the new world? Is it still those human users that it's been for the last 70 years of software? Or is it AI agents?
And if it's AI agents, should we be building apps a little bit differently and testing them a little bit differently as well? And, and here's why. So in the past, right, if you had an app that that, um, really made your user feel great, uh, you can almost imagine like commercials, right?
They're like, bring tears to the eyes of, of the viewer. It's really compelling and captures their attention the, that application developers should be thinking about. And it all relates to who their, who their ideal customers, who their ICP is.
Um, and so I think that that may change how we test and, and, um, you know, ultimately how we structure our applications in the future. Mm-hmm. To your point about that, um, are there tells in the AI code that we should be looking for as it pertains to quality?
And I asked the question because sometimes, uh, the AI generates code that I would say is a little overly verbose, and then we wind up with a situation where maybe it costs more to run that software because it's just consuming more memory. But are there, are there things that people should be looking for specifically that are kinda like, you know, top of mind issues that should just be, you know, things you address right off the bat? I, I think, you know, functional integrity is first and foremost, the application must always still do what it claims to do.
And, and if it doesn't do that, you will lose your users, you'll lose your a ai agentic users as well. It has to function correctly. So that's always the first level of check, I think, um, to your point on, on like, uh, the veracity of the code that's generated, or, um, a lot of times what you'll see is, is the code related to veracity, it'll generate the same, um, functional code multiple times for different parts of the application.
It won't effectively refactor that code, you know, to use kind of a, um, a single deduplicated implementation. Um, the flip side of that argument is if it costs you less money to develop your application because AI generated it, then maybe you don't mind spending a little more to run the application, uh, because you were already saving so much money 'cause you didn't have to pay the human developer. Um, that that would be, it's kind of a, I guess a different debate, a different debate there if you're willing to pay, you know, go down that bridge.
Um, but, uh, to your question on kind of like what to look at, I, for me, I always just come back to functional integrity. It must do what it says it will do. If you're solving a big enough pain point for your customer, they'll overlook the, the visual wart or, um, you know, the, uh, not aesthetically pleasing UI you have if it's solving a functional problem for them.
Um, so that's always, that's always step one. And then when you get to step two, which is like, well, how easy is it to consume? How performant is it?
How enjoyable is it to use? That's where I think you kinda have to go back to this question of, well, who's using my app today? Who's using my app two years from now?
Um, and what's the best experience for those different users? Are you at all concerned that maybe we'll just get lazy when it comes to application development and, you know, we'll just let the AI generate some things and we won't think through the process and maybe we won't even know exactly how the thing works? Uh, definitely it's, it's possible.
It's a concern. Um, you know, it kind of depends, I guess, how futuristic you are. Uh, and you know how much you buy into the narrative that we hear.
Um, I think like a lot of things, it'll be gradual over time. I think there will be certain applications or certain experiences that become commoditized and, and they kind of are known to be consumed by the AI agent for this or that business or this or that consumer. Um, and then there will be other applications which are, uh, they're still always gonna be consumed by users.
And, um, you know, they'll always be, uh, the quality there will always be important. I think quality, again, has a lot of different meanings, a lot of different connotations. One of them is functional correctness.
And so that's always going to matter that you can't, you don't have software if it doesn't do what it says it's gonna do. Um, but beyond that, you know, to the aesthetics, I think again, it's gonna be a gradual thing. It'll be stuff across the spectrum where you see some usage, uh, is AI driven and other usage is human driven.
And, and I think, you know, we'll define that happy medium. Mm-hmm. There are also a lot of folks who are talking about the rise of vibe coding, and we will finally have these citizen developers generating all kinds of interesting things and the definition of what a developer might change.
But does that create some quality challenges? 'cause the folks who are building that software don't necessarily have, uh, shall we say, an appreciation for the fundamentals. Absolutely.
So for, for in, with the vibe coding question, really what you're seeing there, I think is that, um, the source of truth for an application is really no longer the source code in the 100% vibe coded application. It is more the prompts and the, um, the functional specification, if you will, of the application that generate that's used to generate the code. So you will need some expression in that same level of abstraction, uh, on the quality side, on the functional side, uh, that can be used by QA agents to test the application.
Uh, because you, you won't necessarily be able to use, uh, QA to test the source code that's generated in vibe coding because it, it could be so massive and, and it could change, it could be lots of churn, right? Every new session of vibe coding my application, the, the LLM might rewrite half of my application. And so the actual source code becomes a little less important.
And what becomes important, the source of truth are the spec, the, you know, the specifications or the context that's given to the, to the LLM to generate the app. Um, so what's your best advice to folks there for, as you kinda look at all this? 'cause I think we've been struggling with this quality issue for a long time, and there's more, people seem to be concerned about speed than quality, and that's always been something of a mix match.
So how do we get more people to care about quality? Um, I mean, the, the, the proof is in the pudding. I think you have to show people that quality makes money, you know, quality applications make money.
And I think you have to, I think, I think it's, it's reasonable and it's a reasonably compelling argument to say, look, if you're producing software at 10 times the speed today that you were before, you need to test your software at 10 times the speed you were before. And so you can't do that with a human in the loop because you're not doing it with a human in the loop on the software creation side. So I think it's compelling to say you need AI in qa, and, um, you know, from there it's, okay, well, what's the source of truth that's being fed to that ai?
Well, it's very likely the functional specs, the definitions of my applications that I want built those requirements they serve as the guardrails during qa. So, um, you know, the, the, the argument then becomes, use good tools for documenting your applications, use, use good tools, AI powered tools for, uh, testing your applications. And, um, you know, with that you can, you can maintain the same velocity on your testing side as you have on the development side.
Mm-hmm. What is that one thing you see people doing over and over again that just makes you shake your head a little bit and go, you know, folks, I wish we would think this through a little bit better. Uh, well, so this, this goes back a little bit, um, but it's still present today.
So I, I started a company called Reflect, which, uh, was an automated end-to-end testing platform, and it kind of competed with a lot of the code-based testing, uh, approaches out there, like playwright, selenium, Cyprus. And, uh, I thought then, and I, I think it only more strongly now that the exclusively human authored code-based testing of applications is, um, is rapidly going to be overtaken by, if it hasn't already been overtaken by, uh, AI powered development. And, and what I mean by that is, if AI is producing your, the source code to your application at a much faster rate, you can't have humans authoring playwright tests to, to test that software.
You have to have AI in the testing, uh, life cycle and in the qa, uh, framework so that you can keep pace. So, but I, I, you still see, you still see folks today, they're using AI to generate playwright tests, which is a little better than humans generating the playwright tests. Um, but, uh, but you need, you need AI in, in the, um, in the QA process because you need that, uh, human-like intelligence to decide when a bug is a bug.
You know, the, the famous problem with code-based testing is that, um, it's brittle to, uh, semantic, um, to, to different implementations with the same semantic. So if you move the location of a button or you change the color of a button in your application, some minor, you know, uh, literal change that it didn't change the, um, intent of the application that those tests are gonna fail. So that, that's a, a behavior that I still see that I, that makes me shake my head and, and say, you know, you gotta graduate to, to AI in the QA loop.
Mm-hmm. You know, we always talk about testing and quality assessment in the context of the people who built the software, but I wonder in the age of ai, if we won't see more organizations using those same tools that are AI driven to test the quality of the applications they're being asked to deploy and use. And the whole notion of quality assessment is gonna change because, well, the end customers are gonna get a lot savvier about doing those assessments without regard, without any aid from a developer per se, and then they'll give their feedback accordingly.
Yeah. I guess, could you go one level deeper for me? Uh, what's, are you thinking on like the, the end user consumption side there, or in the, I'm, I'm thinking there'll be some enterprising CIO somewhere who will take these tools and apply that to some custom application that they've bought, or some even commercial application just to see if this thing will stand up to the test of time and it'll become one of their buying criteria motions.
Yeah. Got it. So, so you, you're kind of, uh, positing.
Is there a, a future where enterprises use AI agents to validate or test the software that they're purchasing from third party vendors? Sure. Why not?
Yeah. Yeah, absolutely. And this gets back to one of, like a central theme of our position is like, in the future, two years from now, will it be humans using your app or will it be AI agents?
And, and if it's AI agents, it's probably different things that matter to the AI agents than it mattered to the human. Uh, and so for that CIO example, they probably care a lot about governance, compliance, um, correctness, uh, things like that, you know, integrity that might be a little different than the end user who's trying to use the software just to do their job, kind of not as part of the bigger picture, but sort of a, a smaller picture. Uh, I think it's really interesting to, to wonder if, getting back to this notion of like, if, uh, selling software was about, it was about visibility, getting in front of your customer, but then also telling a great story kind of almost even beyond, uh, accuracy or functional corrections was telling a great story.
That's what got that sale. And then, you know, obviously functional correctness keeps the sale in the AI agentic future. Do people and businesses give their AI agents personas just like the, the former buyer, the human buyers of that software had before them?
And, uh, you know, do, do software vendors then need to think, not just is it AI or human, but if it's ai, is it gonna behave and, and want things like the previous human user wanted? Or is it a different thing that, that they want? Um, you know, it's a, it's really crazy notion to think about it.
You can kind of go in all different directions, but, um, it's, it's stuff that's possible, I think. All right, folks, we're at the beginning of this adventure, but I would say one thing, it may feel really good to write a piece of code and be done, but it all feels really bad when the minute somebody calls up complaining about that very same piece of code. Hey, Fitz, thanks for being on the show.
Thanks so much for having me, Mike. Have a great day. All right.
And back to you guys in the studio. Hey everyone, welcome to this futurum executive interview series. We're going inside the AI infrastructure revolution.
It's today I'm joined by Mohamed Awad from Arm to get the arm perspective. Mohamed, welcome. Great to have you on.
Thanks for having me. Great to be here. Yeah.
So I wanna start off, let's hit the AI inflection, you know, every day, literally every day it feels like there's news massive investments, whether it's more compute, more energy, uh, you know, more mo new models coming out, the leapfrogging effect. Like, you know, I'd like to get your perspective, like what is defining this moment in the compute revolution, and how do you see arm's role broadly in that landscape? Yeah, totally.
I mean, I think, I mean, I think the easiest, the easiest way to describe, it's just transformational. I mean, I mean, things are just changing so quickly. The potential is just massive, you know, and we're really kind of shifting gears in a big way in terms of what compute is and how it works, how energy efficient it can be, and sort of the value that it can provide.
I think, you know, the, the world kind of sees that potential. It sees it on the horizon. We're, we're, we're not there yet.
We're kind of early innings, and it's, a lot of it is about, you know, how do we achieve that potential and sort of transform, you know, everything from the, the devices we carry around through to the infrastructure and the, the cloud that, that, uh, that makes it happen. So it's a pretty wild time. It really is.
And, and I speak to so many enterprises every day, and while a lot of us have been really focused on LLMs and how we're using them, and the shift in how we search, I think we're in the very earliest innings. I said something the other day, I said, we're about 1% of the way in to ai, and while people think it's farther along, it is not. We are just getting started.
But, you know, in terms of like in the hyperscaler space Yeah, like, you know, in your business, right? We've seen AWS we're seeing Google, you know, Axion, we're seeing Microsoft, we're seeing, you know, of course Nvidia the grace and you know, and GB and GH and all those different things. Yeah.
Um, it's all on, you know, I think people would love to understand, you know, 'cause we're tracking this very closely too, but the hyperscalers have clearly moved a lot of, a lot of their commitment to arm. What's, uh, kinda what's driving that? What's the technical reason behind that shift?
Yeah, it's, it is, um, you know, we've seen tremendous, tremendous, uh, adoption. We've seen a lot of, a lot of momentum as of as of recent and really a couple, a couple of things. I mean, at, at its core, it's about this idea that we enable a level of, you know, flexibility and innovation, uh, while still being able to take advantage of an ecosystem.
So if you think about how data centers were built in the past, you take some off the shelf compute and you would, you know, build up, everybody knows a story about Google, right? Built in the, in the, uh, in the Stanford dorm room. And, you know, they just kind of cobbled together off the shelf hardware and it was like, let software figure it out.
We're well past that now. The sort of performance demands, the efficiency demands you need, uh, you need these systems built from the ground up and optimized for, uh, for your particular use case. And so, and that, and that's to get the level of efficiency and get the level of performance out there.
And so what you're seeing all these guys, whether it's, you know, whether it's AWS whether it's uh, Google, whether it's Microsoft, whether it's Nvidia, you know, all of them, they're building their own general purpose compute. They're building their own acceleration, they're building their own networking. And arms get a role to play in all of that.
And, and, you know, I think that's really kind of helping, uh, you know, propel us forward, right? Yeah, It's been a great, it's been great to watch the Rise, you know, more competition puts, uh, you know, made the X 86 folks put some effort in to improve what they're doing. I think competition is good.
We always say that, you know, it creates efficiency in the market. It creates, and of course, the TAM is rapidly expanding. A lot of people always want to do these zero something.
It's like, oh, if they get it, that means everything's lost. It's like accelerated compute market's massive. In fact, you know, I know you probably can't say anything, but I keep saying, I think arm's gonna have a bigger role to play there too, um, pretty soon.
So, um, really quickly though, I think we've seen numbers like at AWS like about 50% now of the, the workloads are now running on arm, you know, we definitely measure market share, kind of where do you see your market share sitting right now? Yeah, so AWS actually just at this past reinvent and at the reinvent before talked about this past reinvent. They talked about how in the last three years, more than 50% of the compute they deployed was arm based.
And it, and it's interesting because, you know, these are guys who are clearly, uh, you know, in front in terms of general purpose compute and what they've done around custom silicon. But if you look more broadly at what's happening with the transition to ai, you know, a lot of these systems that are being deployed are being deployed as full rack solutions. And those racks, those systems, you know, come with a general purpose compute, they come with a, uh, accelerator, and it's all kind of kind of built together.
So if you're, if you're deploying in NV L 72, if you're deploying Agra, Grace Blackwell of Vera Rubin, um, you know, if you're deploying your own TPU with a head node or you're deploying your own accelerator, you know, the likelihood that that's arm sitting alongside it is actually pretty high. In addition to that, when you start to think about the networking side, whether it's things like Nitro or you know, Bluefield or otherwise, those are all ARM-based CPUs that are driving those. And at the end of the day, those are actually offloading what historically was considered general purpose compute.
So you've got a lot of compute happening there. Um, so, you know, I, we, uh, we talked about at the beginning of this year how we believe that about 50% of the compute that's gonna be deployed at the top, uh, hyperscalers will be arm based this year. Um, you know, and we continue to believe that that's gonna be the case.
Yeah. So, so quickly, you know, in terms of, you know, as your data center presence continues to grow, I'm glad you mentioned the networking, because that's another huge opportunity. We see networking as one of those big, like, I think we were obsessed that compute was the constraint, but now we're seeing networking and memory and storage and everything kind of down in the silicon supply chain.
Of course, energy's a whole nother topic. So arm's always been very focused on energy efficiency, which is a, a value there too. But like, what do you see as the big technical eco market related challenges that are gonna, you know, be critical, uh, going forward for the data center?
Yeah, This is an AL'S law game, so you're gonna, you're gonna, you know, accel, you know, your accelerators are gonna get better, then you gotta worry about your networking to connect them, and then you gotta worry about your general purpose compute to supply them. I mean, at the end of the day, what we're seeing right now where there are a couple of main challenges, first and foremost is power. If you think about the sort of scale of what we're trying to accomplish, the amount of power required in order to do that is really beyond what the grid can handle.
And so there's real, a couple ways to deal with that. You increase performance per wat, that's the number one game. So I think that's gonna be a big thing and sort of race to better and better performance for lower and lower power.
The second is, you know, availability of silicon. When you think about, um, you know, the, the, the supply chain, when you think about the cost of building the silicon, the time it takes, and then the sort of capacity available, that's gonna continue to be a bottleneck. So we gotta, again, look for ways to, to further kind of drive that out.
And advanced packaging technology, et cetera, are gonna help with that. But we gotta bring more capacity online. I mean, I think at the end of the day, um, you know, there isn't gonna be one particular issue.
I think there's a bunch of issues, and this is really gonna be an ecosystem wide effort to kind of, you know, uh, you know, squash those issues as they, as they pop up. It's a, it's a classic BELS law problem. Yeah.
And I think the markets a lot of the marginal is, is grossly underestimating the proliferation, how fast AI is gonna find its way, like I said, I keep using enterprise, but then even like edge and physical. So let's talk about that for a minute. Like, that's a lot of the, you know, the genesis of, of ARM was always, you know, small, low powered, uh, you know, whether it was mobile devices, but of course you have a business in automotive, you have a business in iot, you have a business in, you know, basically all these things.
And I think it's a multi-trillion dollar tam sitting out there for that, those markets, you know, talk a little bit about, you know, where's arms edge and, and, you know, strategy going. Yeah, I mean, it's, it's, uh, it's ama I mean, you know, it, it's amazing the sort of potential that we see in the edge and kind of how quickly those devices are adopting ai. You know, uh, obviously, you know, we've got about 99% market share in the mobile phone space.
We've got an incredible pre presence in areas around physical ai, whether that's things like robotics or automotive or otherwise, you know, you look at, uh, mobile, um, you look at like, uh, laptop and PC-based platforms, which are now going ARM-based because they're looking, starting to look more and more like, um, you know, they're starting to look more and more like mobile phones. In fact, you know, something like 90% of the apps that are are, that are, uh, run on those devices are actually, um, natively written for ARM already. And so, you know, underlying all of that is when folks look to go take those devices and then expand them, add that AI capability as it becomes infused, leveraging that same software ecosystem, leveraging that same platform that is, you know, they've, they've come to, uh, to build this massive, uh, software base on those devices, but then also that is being used in the cloud, leveraging that same software across both of those places.
We're seeing that as a massive tailwind for us. In fact, you know, we think that the Edge can is gonna be an incredible opportunity for us moving forward, and we're already capturing on it on things like our Lumex platform that we just, uh, that we just launched. Yeah, we expect that to be a really big growth opportunity.
We've been obsessing with data Center for some time, but I think what happens outside the data center is gonna be a, a long, you know, across the next 10 years, it's gonna play a massive role in terms of expanding tam, expanding market opportunity, and of course bringing AI into our everyday lives. So the devices, you know, the last few years it's been all about data center, but I don't think that's gonna stay for the long term. Um, you know, one of the things about ARM that's really interesting is your business model has evolved a lot, was really, you know, a royalty licensing focus.
You've gotten more into custom that senior margins grow a little bit, but just for those out there that are kind of like trying to understand how ARM makes money, how it, you know, goes to market, give us your sort of, the way you explain it, you know, how do you talk about it when you're at the, uh, at the family dinner table and you Get past it? Yeah, I mean, I think the way to think about it is we enable innovation and we enable a, an ecosystem that, um, that, that comes together to build amazing products based on whatever the requirements are. Some cases that means ip, some cases that means compute subsystems.
In some cases that means you, you work with one of our partners to get something like a triplet or even a full on SOC. And I think the, the, the thing that really separates us from, from, uh, from other companies is our ability to meet you at whatever integration point makes the most sense for you based on the problem you're trying to solve. So in a world that's advancing very rapidly, you're trying to adapt new technologies into it, you're trying to fight for performance per watt off the shelf isn't good enough.
You choose which integration point you want, and arm, arm and more broadly, the arm ecosystem is there to kind of make it happen. Yeah, that's a good way to explain it. I think, uh, you avoided the, the trap I put you in.
I've actually trying to break down the how the, how the different royalty and licensing and subsystem buckets, but I have, uh, it's been good to see you find ways to expand margin by adding more value. 'cause you obviously, as the company continues to be a critical provider of IP to many of the technologies we use every day, how you evaluate that, it's hard when it's only based on unit volume and you know, when you can get a little more out per unit. It's a, it's a good way to increase the, the, you know, the business's value.
Um, as we wrap up here, you know, you heard me allude to, you know, performance per wat leadership or low power. That's always been a big part of the ethos. Um, you know, what are the other advantages that, you know, you think that really are the big reinforcement points for arms?
You know, unique value proposition? I mean, I think number one, it's ecosystem. When you look at arm, you know, our ecosystem is second to nut.
And so this idea that you can, you know, you know that it's not just arm, but it's entire ecosystem standing beside you ready to help you realize whatever your potential is, uh, you know, and whatever the, the problem is that you're trying to solve, I think that is probably, um, one of, one of the greatest values beyond the sort of performance per watt and just the, the technical chops that we've got. And I think that's so important in an environment like, uh, you know, today where, you know, things are changing so rapidly, whether that's software ecosystem, whether it's our hardware ecosystem, whether it's partners in our arm, total design program, you know, we've got this massive, um, you know, uh, ecosystem ready to kind of support you. That's very different, by the way, than other architectures.
You know, other architectures either have a strong ecosystem where they'll give you an off the shelf solution and maybe have good software, but you kind of get what you get, or you've got incredible flexibility, but you don't have that ecosystem there to support you. You kind of bring the best of the, those two worlds together, and that's really what sets us apart. Mohammad Awad, I wanna thank you so much for joining me on this FUTURUM Executive interview series.
It's great to get a little more insight as to what's going on at arm. We're watching you closely. You can be sure of that.
Uh, congratulations on all the progress so far, and let's, uh, catch up again soon. Thank you. It was great talking to you.
Control, This is agent dev. I'm in position. Copy that.
Dev. Stand by for go Standing by. Hey everybody.
Welcome. Welcome to another episode of Agents of Deb podcast. I'm Mitch Ashley.
I lead the software lifecycle engineering practice at Futurum Group, and also a practitioner myself, my co-host, Brad Shiman. Hey, Brad. Good to see you again.
Hi there, Mitch. Good to see you. I, uh, I understand we, we are gonna, we're gonna chat about, uh, a little bit of anger today in the developer community and try to make some sense about it or of it Yeah, that's one.
You know, that, that's sort of one mob. You don't wanna get angry at you because they, They'll just make a new language. Tell folks about what you do at, at Rum, by the way, or did you Do that?
Oh, yeah, sorry. Sorry. For those of you, uh, haven't, uh, or aren't following us, and if you're not, we, we would love you to, to, um, tune into our podcast.
Mitch and I do this weekly, and, uh, we would love for you to join us on that journey. Um, mm-hmm. So for me, I, I'm just, uh, like Mitch, I'm very similar, uh, and in that I'm an analyst and I cover data intelligence, analytics, and infrastructure.
And I'm also a practitioner, uh, you know, sadly beating his head against the, the impenetrable wall of data science, uh, on a daily basis. Yes. Data, the, the world sometimes is an island and in the data world, but it seems less so.
But maybe that's a topic for another podcast. That Was a good topic. Yeah, we should, we should talk about that.
Yeah, I'd love to talk with you about that. Get your thoughts on it. Say, uh, so the controversy, um, which I didn't see this, you told me about it, uh, was about anthropic.
So changing their, um, use of their API to subscription customers who get the 200 you can eat buffet Yeah. Uh, of, uh, of Claude from any tool you like, but actually they changed it. Talk about what happened.
Yeah. So developers that were using, uh, a number of other tools that, that can basically use, uh, a harness to, to access, uh, anthropics models as you just described, using OAuth to get there. So you basically just log into your anthropic backend via this third party front end tooling, like open code is, which was the most vocal, uh, of the, uh, communities to, to get angry about this.
Uh, I think it was on Thursday or Friday. Um, but uh, it's the, Yeah, either what day? I think it was the ninth is when it was, whenever that was.
Yeah, I think, I think that's Friday. And, and um, so they woke up that day and booted up their favorite open source friendly CLI tool that, that does a lot of things. That o cloud, uh, co code, which is Anthropics, front ends tooling does not do, um, uh, such as at the, you know, they're catching up.
Okay. I'm not saying that it's, it's inferior. I'm just, I'm just saying that, you know, they're open source tools, like Open Code have demonstrated some great ideas, like natively incorporating language server processors for LSPs or, yeah.
Language service, service protocol, whoa, sorry, guys. To, to basically allow models to sort of look for syntax errors without having to ask, did I do something wrong? They could just fix it on their own, which is great.
Mm-hmm. And so anyway, open Code developers woke up on Friday and, and went to incorporate their clawed backend, uh, to use sonnet or haiku or, or any of the, the models they have, honestly, with their plan. And they were kicked out, uh, with a, you know, cannot log in warning.
And, um, when pressed about it, philanthropic basically responded to say that, well, you know, this was really an inappropriate use of our API backend and one that was not in line with our security, um, requirements. And so we, we have turned it off and you can make of that what you will. And, and I, I think their their right to protect their customers by ensuring the, the proper use of their backend services that is their responsibility after all.
Right. But, you know, it, it, it sort of irked a lot of people because it has, it has become very common practice right now to use the front end of your favorite front end, let's say Google's, um, anti-gravity and be able to access anthropic, uh, and their terrific models for coding. And suddenly you can't do that.
You have to go right to Claude to do that with their own software. So Anthropic with their own software, You know, I think several things kind of tick people off. One is your, uh, your Ralph Wiggins, we'll talk about Ralph Wiggins, your Ralph Loops that were running overnight suddenly stopped running, didn't complete, um, yeah, because there was no notice too.
So you, you were logged in or you went into open code and you both, you couldn't log in then, but also anything that happened to be running was already outta commission. And, you know, you're figuring out what to, to do. People are complaining this is a, is a walled garden.
I don't, I don't see it necessarily that way. Um, you know, philanthropics got a business, they, they want people to use their models, but their tools, you know, they obviously want to have the, the best access to their, to their models, and they're giving away a lot of stuff with their $200, uh, subscription a month. Yeah.
Not the 200 doesn't. Well, you know, you know what, man, I, I think that is one of the lar drivers of this decision is giving away. Because when you allow people to just use their a la carte eat all you all, you can eat, you know, license in another tool, you being anthropic can't control how that API gets used.
Mm-hmm. So if I'm in the anthropic front ends, I'm using their model router, for example, to select which model to run against whatever task i I give it. So if Haiku is gonna save them, anthropic a lot of money, that's what you want.
Mm-hmm. Yeah. Well, exactly.
And yeah, I, yeah, I get that. Of course, OpenAI immediately responded and say, Hey, we don't have such limitations. Come on over the water's fine.
Is it? I I I, I, I was, I was looking to see, you know, because Codex is open source, okay. Um, but I don't see an easy harness to bring in external models like we have in, in other tooling packages.
Even Claude, it's, uh, you know, Claude code itself and, and Gemini and others are semi open, like Gemini is open source, but it's not an open harness. And it's the same with Codex, Right? Um, and, and that's a big difference when you're talking about your tools accessing the model versus their tools, accessing their own models.
So I guess bring your own AI isn't quite totally a hundred percent. Just bring your own ai, whether that's models or tools, there are limita, you know, some limitations, some, some assembly required. Yeah.
Well, I mean, you could still use an API key, and that's, that's how a lot people do that. But you don't get the same benefits using an OAuth just log in methodology for that, for that subscription, that unlimited subscription. So, you know, it's not that they're turning things off entirely, it's just that they are tightening the constraints around how you use their licensing programs.
Um, you know, for better or worse, I guess if, you know, and we've seen this many times with lost leaders, have we not Mitch, where Oh, where companies will, will, you know, we're, we're in the, and the, the best one, the av my favorite one is, um, we're in a research phase, therefore this is free. And what that means is we're we're going to harvest every single interaction you have to better train our models, uh, to, to, you know, later on monetize, you know, o Open code does this with their Zen, um, API or sorry, model, uh, service itself wherein they have, uh, proprietary ish model called Pickle, big Pickle. Uh, and that's totally free.
You can use it all day long. Uh, but you know, you're, you're giving it everything that you're, you're asking it to do Well and often, um, you know, the there feature limited or the previous generation is free. The newest thing you have to pay for.
Uh, I think the big thing here was you could, like you said, you could still access Claude, the models. You just have to pay the API token price, which can rack up, you can rack up some big dollars pretty quick. You don't, aren't careful about, Especially with Mr.
Wiggins at the helm, The helm. Well, so what, so you're ready to talk about, about Ralph? Yeah, I mean, okay, if we're talking about Gemini CLI talking about open code, talking about even antigravity and Z with the sidebar, uh, any of these frontend COIs that enable age agent development are under the hood, basically just a, a for loop with, you know, exit clause in there upon success.
And this idea that, that we're, you know, chuckling about is, is, um, a, a methodology based upon a, a Simpson's character that, uh, was, was very helpful in that he was constantly, you know, screaming, I'm being helpful, I'm being helpful. Um, and it, it, it's sort of a, well, okay, if we, if we take this seriously and we apply that to a agentic development, and we, we just force the model to, to keep chewing on the problem that it has, instead of, uh, either refusing to comply, which happens, or failing and stopping, or early stopping or getting lost, which also happens, then uh, we, we can actually get some good code out of it. Uh, but as you, you mentioned, uh, and so, so rightly so, is that, um, that could be quite expensive and might be running for quite a long time.
Hence everyone getting a little upset on Friday when Ralph refused was was, you know, found dead in the street. Yeah. It's actually in the, uh, in the Claude Library, if you in Yeah.
In the Claude Library, you can, you can access this routine. So what, what I find fascinating about this, um, I think it's Jeff Huntley, who was the person who coined Yeah. Uh, created this, he called it a, a core loop originally, and it was a bash script, which basically essentially did the same thing without ai, but now, now it's with ai.
Um, but what I really find fascinating about it, it gets around several problems. One is this, this end state completion. How many times have we done a prompt and it says, oh, I'm done.
Here you go, here's your answer. You're like, yeah, I said there were five things and you did too. Or, you know, whatever.
And it, and it likes to stop early and claim success. Um, so, so this idea of having an end state that you defined, and then that's what keeps the, the core loop keep going until it actually does satisfy whatever the end condition is. But the other thing that goes along with it is every iteration, you know, we have, we have things like context window issues, right.
And mirror Issues. Yeah. Oh God.
Yeah. Yeah. And we want to do long running agents.
You gotta solve that, those problems. So one of ways you can kind of get around it, I dunno if it's solving it, but every loop can be another session, another instance. So you're, you, you're iterating and you're not, you know, you're not flooding the zone of your context window.
Yeah. Nice analogy. At some point it floods over the window.
It does. Yeah. And, and that's that context stuffing is not the answer.
And, you know, just, do you remember when meta released their 4 billion, you know, um, token context window? Or was it 10? Oh god, it, was it even more than that?
Sorry. 5, I think at the time. And, uh, you know, you can't just take that for granted as, as you and I have talked about, there's this, you know, u shape, you know, attention mm-hmm.
Deficit within that context window to begin with. So, you know, what you're talking about with this, this Wiggins technique is, is, uh, I think an important sort of point that we should, you know, point we should be talking about. And so I'm kind of glad that it's bringing that to light and, and that is proper use of, of the context window.
And, um, one of the predictions that, that I have for this year is, uh, this sort of emphasis on, um, optimizing that memory system for models and using a number of techniques intertwined, like semantic ging, for example, where you're not trying to save the, the entire history. You're just trying to, to save the meaning of it and reference that not the whole thing. Yeah.
Because you have, you know, anytime that you inject something into early into the process, it can carry that through, you know, it may have gone down a wrong path, and not, even though you told that that's not the right thing, it keeps some of that going. Right? You're like, Hey, this is the right relearns To fail every time.
Yes, Exactly. Um, so it, it's, it's an interesting concept. One, one of my predictions too, um, for 2026 is the emergence of the new development part paradigm of how we're creating software, uh, I think, I think is emerging this year and will, not that it would be codified and finalized by the end of the year, but I think we're gonna be talking well beyond vibe coding and just AI powered or AI native type coding.
There's a lot of these things are, are being invented and learned as as we go, of course, well, as, as the models and the tools are changing themselves. But we'll see more things like control planes and guard guardrails and things like that being a serious part of not only the architecture, but how you architect it. And, uh, my thought is that, you know, we're, we're going from software development to software engineering, and that's, 'cause that's what this upper level thing of not writing all the code, but directing the code and reviewing and assigning work and deciding how architecting how things get built.
And Wiggins is a great, great example of that, you know, in, in innovation somebody creates that gets around and architectural Limitation. Technical limitation. Yeah.
You know, it's, it's funny, um, I, I think was thinking about all of these layers of abstraction that, that we're gaining with generative AI in particular, and I, I don't know where I even heard it, but there was this quote about every layer of abstraction is a bet on the, that in the future, at some point, you won't need to understand what's happening beneath that layer. Hmm. Mm-hmm.
How oftens A terrifying, that's thing to think about. Yeah. Well, maybe at some point if you wait long enough, it's true.
But I'm sure there are many, well, Because you have another layer that will, You just forgot about the third layer under the second layer. Under the first layer. Yep.
Good point. You know, it's, it's interesting. Um, it's just such a fun ride to be part of this whole recreation, how we're building software and, uh, yeah.
Getting to experiment with it. You know, you and I aren't living in code every day. You're, you're doing a lot of projects too there, um, with our signal work, so, which has been fantastic.
Done a really fantastic job at that. So it's, it's, it's good. You're, you're able to keep your hands in me.
I get to dabble in a lot of things and do that without having the commitment of a project. Yes. The evil scientist, yes.
You're able to, to build that tower with hoist the, the sail and gather electricity from the storm. I'm the mad scientist. Exactly.
Exactly. You're like, I gotta ship product. Yeah.
Right? And, and does, is that is a bit of a conflict, is it not in, in our industry where you have companies saying that, you know, the way we're going to measure success is how many vibe coded lines you've generated in this mm-hmm. Past week.
And, you know, forget the fact, and this goes to the whole, you know, technical debt thing we're talking about with betting on abstraction layers, but forgetting that just the fact that, you know, developers can't take the time to actually think about what they're doing. Instead, they're just waiting on the prompt to come back with the solution that they're trying to solve. And that's where they're spending their time, is formulating their intents and their question and not musing about, well, maybe there's a better way to do this, and instead they're using AI to chase the solution.
I'm not saying that's wrong, but I, but I do feel like we lose something in that. And if all we're doing is, is chasing these, I'm not saying arbitrary, but they're arbitrary measures of, of value and quality. Well, and, and that seems to be a distinction, quality of some developers, you know, it, it's not a job, it's a lifestyle.
It's a, yeah. It's really part of their, their psyche there being, it's really enjoy, enjoy it that much. Oftentimes those are the folks that are, you know, you can't not work because when you work, you're playing, not working, you're playing with, With the same Technologies or different ones.
That's where a lot of those innovation and that innovation time comes from, which is great. It's great that people that are so passionate about it. Yeah.
Like, like we were joking earlier on with, you know, let's just, they'll just make a new language if you p**s them off. Uh, the reason why I thought of that was, um, thinking about Mr. Mr.
Pike at Google, who loathed all the semicolons, so much so that he developed a, a programming language where in the compiler added the men for, for you later. So you didn't have to type them or look at them. I can't remember if it was Jeffrey Gently or somebody else.
Um, used, used the Core Loop, the, the Ralph Loop to telling you to create a new programming language where all the primitives are slang from Jen Gen, gen ZI guess it's, Oh, dear Lord. Yeah. Uh, that, that exists.
Um, uh, uh, we'll have to look this up. Um, but if anyone that's, that's listening, you know what we're talking about, please put it in the comments, because I, it's called Curse, that's what it is. Yes.
Okay. Yeah. I just remember what it was.
Fantastic. That's innovation. Yes.
Yeah. That's, that's, uh, that's, that's a subscription where you have to pay it for all the tokens, is what that is. Yeah.
Well, unless you just don't care Or you don't even care. Yeah. You work it, you work at Anthropic.
Well, I think we may have done enough d damage on this subject. Um, let's move on to our closing segment. Is time for Yes, the drop.
All right. Um, I think I went first, last time. You wanna jump in with your, What's on your mind?
Sure. Absolutely. I, you know, because, because I, I think very limited scope of things.
Uh, my, the thing that's on my mind is related to today's topic, and that is that, uh, yesterday, uh, today's Tuesday, um, and yesterday, uh, anthropic dropped, um, a new tool, uh, a research tool that's free for use because, you know, they're helping to, to build it out called Cowork. And Cowork works within their, uh, proprietary application, um, on Mac, I think initially, and eventually on the other platforms they support. But basically what it, what it does is take the note, this notion that many of us have really glommed onto with CLI tools, um, and to basically use generative AI as a backend to, you know, do things that we normally would have to do either in the file system or, you know, typing it out in ACL I, um, sorry, in a file manager or on the cli.
Mm-hmm. Mm-hmm. And, you know, there's no limit to what you can do with that, honestly, because it is, it is the core of the computing experience.
Is it not you, the reason why we're sitting right now at a computer is that on that computer, we have information that we can process, uh, and do things with, and this cowork is, is really built not for Claude code developers, so per se, but, but for business users and, you know, and home users and any user who wants to do things with their computer that go beyond, um, and I'm not pointing fingers here, but there are some implementations wherein if you ask the, the operating system to help you do something, it'll basically say, okay, let's do this together. Open up your file manager and click on the third link down from the file pull down menu. That is not automation.
That is not what we want. I, I, I, you know, I would imagine that we will see more of this as we move forward, and especially, you know, to the topic we were talking about with creating these sort of, um, you know, very controlled walled gardens of, of ownership of the user experience itself. And that's what we're seeing Anthropic do here.
Well, excellent. You know, I was excited to hear about that too. It's kinda like skills, you know, another capability that was introduced to, you know, here's a different way of, of kind of feeding content in and maintaining that, that content, uh, across sessions.
Um, my drop, my, my focus right now just getting ready, it, it won't be, I don't think it's today, but probably next day or two, we're releasing the first half, 20, 26 of the software lifecycle engineering buyer decision maker data. So we completed that survey at the end of the year, and that data's ready. We just got put then polishing final touches on it into the intelligence platform.
So I'll be talking a lot about the data. Just a hint, hint. One of the kind of really interesting things is AI shot up and has now surpassed even security in the top of the list of where people are That Shocking their budgets.
Guess what that is Shocking. Security Always Tops. Yeah, Exactly.
Yeah. So security followed by cloud, followed by, you know, the, the typical things that we have, so people are investing in it and, uh, counting on making, counting on it, doing some interesting things for us. So we'll have plenty to talk about, Brad, I'm not worried about Yeah.
Just The picking, the choosing is the hard parts, That's for sure. That's for sure. And, and, you know, we're imagining you do the same thing, meeting with, uh, both clients and also people who, uh, that we follow and just kind of for the, here's what we're happening for the year, here's some of the plans we have that they have, et cetera.
So for any of our practices, Brad, mine or the others, uh, anybody listening, reach out to us. If we haven't talked to you yet, we're glad to sit down and talk about both what's happening in our world and what's happening in your world, so we can do that. Yeah.
The exchange of information is an insight is one of the best things that we humans can engage in, so we welcome that for sure. It's, it's fun. Alrighty, well, thank you everybody for listening, watching this episode of Agents of Deb.
We hoped you enjoyed a little, uh, Ralph Wiggins conversation while talking about, uh, core Loops and Ralph Loops, and also what's happening in, uh, the competitive world of models and development tools and all of that good stuff. So thank you for listening. Please follow, tell your friends about the, the we're getting stats, people are joining.
It's, uh, it's really good. Thank you all. They're coming on board listening and we appreciate it very much.
And send us, send us an email if you have a question or a suggestion or that was really great, or that was really dumb, or why don't you talk about this, or what about that? We'd love to hear from you. You can reach us at agents of dev at futur group com.
On behalf of Brad and myself, thanks for joining, blue. We'll see you on the next episode. Stay tuned.
Next week, Control. This is agent dev. I'm in position.
Copy that Dev For Go Standing by Observing snowflakes hitting a memory wall. Sovereign OpenShift Delineate gets strong. CloudFlare goes native.
FCC is pumping up the power open. AI is getting with s and are we rushing ourselves into an insecure AI future? All that and more in this episode of the Tech Field Day rundown.
Hello everyone, welcome to the Tech Field Day rundown. It is January the 21st, and we hope that you are appreciating the fine little furry creatures that are probably packing away acorns because it is squirrel appreciation day. And, uh, who better to talk about squirrels than your friendly co-host Tom Hollingsworth, captain A DHD himself.
But joining me, thankfully, is someone to keep me a little grounded and not quite so nutty. Alistair Cook. Alex, good to see you again.
Did you say squirrel? Honestly, squirrel. But it's of course also national granola day, another day that, uh, the squirrels will be taking all of the nuts out of your granola today as we get into some kernels of stories in the, uh, tech field Day rundown.
Yeah, I can't wait. We've got a packed day of news, and we're gonna kick off with some big news because Snowflake is planning to acquire AI driven SRE program, observed to significantly strengthen its observability and AI ops capabilities as enterprises push from AI pilots into AI production by combining observes telemetry logs and trace analytics with snowflake's AI and data cloud. The company aims to give CIOs unified visibility across data pipelines, models and infrastructure, while also reducing the high cost associated with traditional observability tools like Splunk and Datadog.
Analysts say that the move positions Snowflake as a scalable cost efficient control plane for running production AI reliably. Al, do you think Snowflake made the right move by picking up observe? Absolutely.
I think there are some real challenges dealing with the volume and types of, uh, interactions that we're seeing as, uh, data's being fed into ag agentic AI systems, and if we thought the DevOps inspired microservices led to fragmentation of, of knowledge and fragmentation of awareness of what's actually making our applications work, agent AI is gonna make that way worse, or it's already from any customers. And so this idea of, of improving observability and particularly moving away from tools that are really log or oriented and towards true observability tools, is, is something that's really strong. I saw this quite strongly at KU Con, uh, north America at the end of 2025, that, uh, this observability is hot again, and it's hot because we brought more complexity into our environments with these AI applications.
Of course, snowflake, uh, would much rather you paid them to store all your observability data on their platform than paying those Splunk Datadog in particular, uh, to to store that same data. So there's an element here of Snowflake wanting to, uh, hold more of your data, but also that we are definitely seeing more complexity as we're building more of these AI applications. One of the other things that we will see is an increase of site reliability engineering being done by ai.
So the AI SRE was another big topic at KubeCon, and this is the, the path that Snowflake is gonna head down as automatically resolving issues that appear in your AI applications based on this observability knowledge and ME quite a lot of observability data in order to be able to drive those AI applications to help us. So, yep, this is, this is absolutely a good thing. The only challenge, of course, is that there are a whole bunch of other really good observability tools around, and if you're a Snowflake shop, maybe you'll use observe with Snowflake rather than necessarily getting something that might suit your use case a little better.
Just because you've got access to observe through an existing contract rather than having to build up a new contract, time will tell whether observe actually best some of the other, uh, observability tools and AI SRE tools that are coming to market. We'll be watching this closely and keeping track of how the, the, uh, AI SRE actually plays out and, uh, getting good data into your AI as well. There is, as we know, a global shortage of DRAM driven by all of the DRAM vendors, switching to high bandwidth memory to fulfill all of those AI demands.
The shortage is expected to push firewall prices higher in 2026 and squeezing both customers and vendors alike. Analysts are saying rising memory costs are already cutting into margins at major firewall makers like Fortinet, Palo Alto Networks and Checkpoint with some vendors raising prices to offset the impact as next generation firewalls require more memory to hold all of that more state pressure from surging DRAM prices is likely to intensify and costs are going up. I'd like to see more value as costs go up, but I don't think that's what we're getting here.
No, no, that's not what we're getting at all. You know, what we're getting, we're less likely to get a firewall that we might need. And one of the reasons why that's happening is a little thing called supply and demand, because as we know, there is no more supply of dram.
Somebody somewhere, I won't name names, went out and bought most of it. We live in a market where one or two companies can go out and buy almost all the DRAM that's available and convince other manufacturers to switch what they're making. Eh, we'll come back to that.
The problem is that appliance models that we've been producing, like next generation firewalls and more advanced IDSI PS boxes and things like that, are no longer powered by high speed asics with relatively dumb processing capabilities. Instead, they're almost all based on similar SDNX 86 architectures that require a watt of RAM to be able to hold the contents of those packet flows in memory to be able to process them. Okay, you're following along, right?
Boxes need more memory. Where are they gonna get it from? Because this isn't like any other problem where we could just manufacture something out of thin air.
We literally are manufacturing as much RAM as we could, and we've seen this happen many times in the past. If you're old enough to remember when they had a, uh, fire at one of the manufacturers over in the, the far east, uh, that actually caused a memory price spike for about six months, and that was when we knew when the shortage was likely to end and what had caused it here. We don't know when this is gonna happen.
I mean, Corsair's already come out and said they're not gonna sell consumer DRAM anymore. The problem is that the knock on effects from these decisions cannot be seen. Okay?
They can be seen by people on Wall Street, um, they can be seen by people like us because we're sitting here going, yeah, laptop prices are gonna go up, phone prices are gonna go up, firewall prices are gonna go up, pretty much anything that uses ram, you think, I'm kidding. Your fridge uses ram, your washing machine uses ram. Anything that has a computer board in it uses some form of ram.
Do you think that the prices of those things are gonna go up when nobody can buy the ram? Because the only way to get ahold of RAM is to outbid the people who have paid through the teak for it. And what that means is that the companies who are beholden to shareholders who expect a certain return on their investment, that is then used to buy back the stock, to raise the stock price, they're not going to accept a margin cut, but they're more than happy to pass those price hikes along to their customers.
So folks, if you haven't already bought your next Gen firewall, or if someone's coming around knocking on your door, wanting you to upgrade to the next version because they need to make their boat payment this month, you might wanna get them to lock in the prices right now, because I promise you, in a month, they're gonna be a lot higher. IBM is launching a Sovereign IT platform based on Red Hat OpenShift that's gonna let organizations deploy isolated compliant workloads in as little as a day. It's designed to keep data identities and encryption keys under local control.
IBM Sovereign Core helps enterprises meet regulatory and data sovereignty requirements, which is an increasing priority as AI workloads and geopolitical concerns drive demand for regionally managed infrastructure. Al, do you think that customers are gonna buy off on a sovereign platform that they control? Absolutely, particularly right through Europe.
This is a pretty hot topic as the, uh, cloud Act in the US allows any, uh, any US court to essentially confiscate or get access to any data stored, uh, on a, on a platform that's operated by a US-based company. And that covers, uh, all of the major cloud providers that would care to, to use. Uh, the, the challenge then is, of course, the uk, the us, um, oversight, uh, of what's happening in Europe is kind of concerning in the current geopolitical climate.
The, uh, kind of tensions between European states and the US leads us to want more strongly of, we're a European company, uh, we'll strongly isolate ourselves within the actual sovereignty of the place we operate, be that, uh, broader Europe or anywhere outside of the United States. And that's where sovereign, uh, cloud has become a very significant thing. Uh, the sovereign core platform from IBM looks interesting.
It's got all of the little tick boxes you wanna have along there. I mean, OpenShift is your Kubernetes platform. It's got components in there from HashiCorp in order to automate deployment processes.
Uh, it definitely is an interesting possibility for a sovereign cloud platform for large organizations, or equally for cloud providers that are European focused and European operating. Uh, the idea for the, the sovereign Cloud is that it needs to be self-contained. It needs to not rely on external services, external, uh, authentication, those kinds of things.
Look at something like AWS where the authentication tool, the IAM service runs exclusively within the United States. Well, uh, this IBM Sovereign Cloud is, is putting the, uh, IBM verify identity service inside the cloud that runs, uh, it's not external. So yes, this is pretty significant.
Uh, general availability won't be for a little while because IBM is saying they're releasing the technical preview in February and general availability later in the year. I think we're probably seeing quite a lot of demand for this, uh, along with any other sovereign cloud platform that is available to, to customers. Uh, daily risk on this, of course, is that IBM is a US based company, and technically the Cloud Act says that these sovereign clouds that are operated with IBM software are still subject to US court jurisdiction.
So it will be interesting to see whether that gets in the way of people, whether we actually see more of a rise of open source or European based products for these things. Uh, again, time will tell. We are seeing other cloud providers building European operated clouds, European employees, European operating companies, interesting to see how this plays out over time.
Deline is acquiring strong DM to expand its privileged access management capabilities into IT infrastructure. Strong dms just in time identity based access model helps reduce cybersecurity risks by eliminating long-term credentials for both humans and importantly, non-human identity, such as AI agents. Together, Deline and strong DM aim to give security teams better visibility limit over provisioned access, and particularly, uh, long-term, uh, persistent credentials that are being reused.
And to support a move towards a zero standing privilege model, uh, this looks like an an awesome set of capabilities being added to one of the leading security companies. Uh, DEA has been in this privileged access management for a while, so this looks really cool to me, Tom, It's really cool. It was about a year ago that I finally, uh, had a chance to sit down and talk to the folks over at delania, and I wrote up an article over on my LinkedIn page, and I went back and I looked at it, and as I was glancing through everything, one of the things that stuck out to me was, you know, they're doing a really great job of limiting access to certain things, but what they really need is a way to do that on the fly.
Because one of the problems that we run into now is that so many things get overprivileged over provisioned, and we never dial them back, right? Like, like, we've all done it, everybody, right? You know, the, I'm just gonna give this user admin rights and, and that's gonna solve this problem that I'm having and, and I'll, I'll fix it later.
That was like 10 years ago, and it's still not fixed. And I've got an admin user sitting out there doing things that it really shouldn't, you know, the same kind of people who run as route on a Linux box all the time. What's the worst that could happen?
Um, I have a list of all worst that could happen. If you would like it, I'll, I'll make sure to send it to you. Now, what this is, is a great way to integrate what Strong DM is doing into things like, uh, deline as remote access system, right?
So you can, you can have a, a PAM module like fire up on the fly and give a contractor access that they need and then close it down right away when they're done, and, and you don't have to worry about it, right? Like, like this thing can automagically do things that that need to be done. And I think that that's a piece that deline really needed, and, uh, I know they're really excited about it.
They sent over the press release and, uh, I read through it. I was like, yeah, yeah, this is exactly what they need. And we're starting to see this shift, right?
More people are starting to integrate these pieces together to provide an all in one solution. And we see this a lot in the industry, right? We have these big solutions that are great for a while, and then maybe one of the parts doesn't get updated as soon as they could.
And then we, we fall back to the other extreme of No, no, no, everything needs to be a third party integration where, you know, one company does something really, really well, and this other company does something really, really well. We're gonna integrate the two of them, and that works until the companies stop talking to each other, or the integrations don't work the way that they're supposed to. But in the security space, I think why it's valuable is by having one central authority that you go to, it gives you the ability to kind of mold the solution the way you want it to without having to figure out all of that interconnection, interplay that needs to go on.
So, I, I salute the people at Delineate for doing this, and I can't wait to hear more about how strong DM is gonna, uh, you know, help them build to, uh, an awesome future for people that are trying to just basically keep people from getting into places that they should. Our friends over at CloudFlare decided to acquire AI data Marketplace, human Native, to help build a fair, transparent system for compensating content creators whose work gets used to train AI models. The deal supports cloud flare's broader effort to protect the open internet by giving creators control over how their content is licensed, monetized, or blocked from AI use, while also providing AI developers with legally licensed high quality training data.
Al it sounds like this is the best of both worlds for people that wanna advance ai. I have high hopes for this. We have a bunch of, uh, cases in front of judges at the moment around AI tools that are reusing, uh, licensed or reusing, uh, copyrighted content, uh, and can be made to reproduce that content with no attribution.
So, some suggestion that this is illegal copying of, uh, the original content rather than fair use. And if some way of resolving this out is gonna significantly help us if we don't resolve this problem out. What's gonna happen is there's gonna be no incentive to create new actual human created inspired content.
The sort of thing that, that you and I write fairly frequently. Uh, what will the incentive will be to just recreate things through AI tools and put as little effort into it as possible, because AI tools are gonna create all the content and take all the attribution anyway. Um, when I first looked at this, I thought, this is odd.
A, a content delivery network is getting into a, a marketplace for content, um, or at least for the creators to get paid for ai. And I thought it was a little odd, and until I remembered Cloudflare's job, that Cloudflare's mission statement is not to be the best content delivery network in the world. Their mission statement is to build a better internet.
And in that context, this is exactly the right thing for, for CloudFlare to be doing. Working on ways of making sure that there is an incentive for people, content creators, to continue to create inspired, unique content that is valuable to people who wish to consume content, not just AI slop that has been overwhelming, uh, the internet recently. So I, I really hope that this is successful.
The devil is going to be in how the heck you make it work, because there's huge ai, um, large language models that were, that are in widespread use. Uh, they've been trained on internet crawls that have no attribution back to the original, uh, or at least the way the, the LMS are built, have, have no attribution back, no way of showing that. We created a result here from our, our AI tool that actually used this creator's content.
And this creator should be compensated. It's just not built in at the moment. Uh, adding it afterwards is gonna be very difficult.
There's not a huge incentive to the LM builders to give that attribution, in fact, is a huge incentive to not attribute anything that your LLM creates to the original content creators that inspired it. Um, it's just, let's go wall guide and lock you in. And that's exactly what CloudFlare wants to break us away from escape from, and it's a great thing.
I wish them very well. I don't have high hopes that they'll be very successful, but I really hope they're, The FCC is set to, uh, a proven new class of high power wifi, uh, for outdoor use. It'll be in the six gigahertz spectrum, and it's been long advocated by our wifi, uh, specialist people who come and join us at Mobility Field.
They will have been asking for this change is expected to deliver faster and more reliable connections for technologies like augmented or virtual reality, as well as IOT devices. Uh, and generally getting into large open outdoor spaces more easily, but also with some fencing around it, because of course, the longer range your device has, the more likely it's to cause an interference, and that needs to be built up. Consumer groups say the, uh, decision strengthens the unlicensed spectrum use and will be very beneficial for everyday users.
Uh, where are we gonna see this, Tom? Is this gonna be making our, uh, internet connectivity at a baseball game better? It might, but the other thing you gotta consider is it's, it's gonna make the device throughput a lot better, and it's gonna make coverage a lot better.
So for those of you who don't know and have never dealt with, uh, the, the way that a, a standard gets processed, here's basically what happens in wifi. The FCC says, you guys can use this chunk of spectrum, right? 4 gigahertz, which is the same frequency as your microwave.
We had five gigahertz, which is the same frequency as a radar station. Well, in the case of your microwave, yeah, we don't care. Uh, someone, uh, by the way, that's why you don't put your access point on top of the microwave because when someone warms up their fish for lunch, it causes the wifi to go down.
Uh, the five gigahertz band was really interesting because there are radar towers that operate there. And, uh, those were in DFS, and if your access point got a DFS hit from a radar tower, it had to shut down on that frequency. Well, then we get to six gigahertz, and, and if you've ever heard a talk from, uh, Chuck Luki who used to be at Aruba, um, they did extensive testing in six gigahertz, because the one thing that occupies the six gigahertz spectrum is satellite downlinks.
And guess who was really upset when they wanted to open the six figure spectrum for unlicensed use? If you satellite downlink providers, you win the doll, they went crazy and they wanted proof that it wasn't gonna interfere, and we're the incumbent, and you need to do this. And Aruba walked into the meeting and said, here's all the proof you need.
We don't interfere. And that somehow still managed to get them shut down for a very long time. So if you've been to Best Buy recently and you bought a six gigahertz access point, you probably noticed that you can only legally use it indoors.
Why? Because there are two different power modes for six gigahertz. There's very low power, which is designed to be used in a building, and it has, it should not radiate outside of your building very far.
And it has the power basically turned down a little bit. Then you have the rest, right? And based on the stats in the article, you should be able to provide about twice the amount of power that you would get out of a normal access point, which usually runs around a hundred milliwatts.
And that would provide a much bigger coverage area. Bigger coverage area means that the devices that are out there are going to be able to hear the signal better, they're gonna be able to transmit data better. And if you're close enough to it, things like ar vr will be able to transmit a lot of data really fast.
This is a big win for all of the companies that we're lobbying the FCC to make this happen. Read the article folks, because I'm gonna tell you a little secret, this did not come from the government. Government doesn't care.
This came from all of the device manufacturers that make all the access points and a lot of really big customers who want this turned on because they need better wifi and they lobbied and pushed and probably took somebody out to a steak dinner more than once to make this happen, which means that we now have this ability to do these things outdoors. That's a huge win. Bravo to you guys for making this happen.
We can finally unlock the complete power of six of gigahertz without worrying about whether or not a satellite downlink provider is gonna yell at us. You know, there's still some geofencing and you've got that, um, a FS coordination database that you gotta worry about, but hey, we're getting there. I'll take it.
It's a win. Let's talk about our friends over at Open ai, because guess what, they signed another deal. This one's worth more than $10 billion.
With AI chipmaker and Tech Field Day presenter Sarah Bruce, to secure up to 750 megawatts of computing capacity over the next three years. The agreement helps open AI address growing compute shortages as chat GPT usage scales, while signaling a shift towards long-term infrastructure partnerships in specialized AI hardware beyond traditional GPUs. Al, is there a shortage that, uh, we needed to fill with Cbri?
I think there's, there's some interesting challenges going on. One is that Nvidia has become extremely large based on the vast amounts of money that are being spent on AI hardware. Now, when a single vendor becomes very large and becomes category, they get to dictate terms, and that's not good for the customers.
Uh, in this case, the large AI vendors like OpenAI here, OpenAI is basically hedging and spending a bunch of money with BRS to use a different architecture. So whilst NVIDIA is using GPUs, and they're sort of, uh, one of the interesting things in looking at the physical size of these, and that's one of the things that Cbus really focuses on, uh, these Nvidia GPUs are, I dunno, teacup size. What's, what's the, the US measure for something that's, you know, hand size or palm of your ham size, um, smaller than that, whereas the, uh, ceris design uses wafer scale, so they use the entire wafer of silicon, uh, dinner plate size.
They say that's, again, not a metric measure, but it's, it's a US measure of size. Uh, these much larger devices, larger, it's not a chip because it's the entire wafer, uh, can process large AI models much faster than the indi individual GPU based systems can. It has a much larger capacity just on that single unit.
So this is an interesting move for open AI to say, we're not just gonna use Nvidia chips, we're also gonna second source, and we're gonna second source at pretty big scale. As you said, this is a 10 billion deal, uh, over a few years to buy the seven megawatts worth of computing capacity. It's not just a, a second source to make a tick box on the audit sheet.
It's a second source to make sure that NVIDIA doesn't have complete dominance of, uh, of how, uh, these AI companies can actually build their infrastructure. I think it's a great thing to see. And generally, I think we do need to see innovation in the types of, uh, accelerators that are being used for ai, AI infrastructure field day event.
Next week, we'll be looking at some of the issues around building different types of AI infrastructure for different workloads, whether it's the massive training or the inference stages. Uh, these are different types of workloads and different types of, uh, chips make a big difference, particularly at the sorts of scales that OpenAI works at. Uh, this incidentally is not the beginning of the relationship between OpenAI and Cbri.
Uh, Sam Altman was an investor and Cbus previously as well, so he's been staying pretty close to this, making sure that he got some inside news as service was pro progressing. Um, it's a great thing. I I really like that this is happening, and I hope we see more than a couple of chip vendors or chip designs, uh, that can actually deliver great things for our, uh, AI infrastructure, for AI applications as they scale.
Speaking of AI applications, we got some interesting news that we wanted to take a little bit of a closer look at this specifically, a, a critical vulnerability in ServiceNow that shows that a, a rapidly and possibly somewhat carelessly deployed ai, uh, can turn into a major security threat, uh, a rushing out agent AI into production without proper authentication, authorization and guardrails around it, organizations can, can produce a, a new attack surface, uh, and these things can bypass all of the conventional defenses. Uh, AI agents, uh, need to work in a zero trust model. They need to be set up with lease privilege and all of those good security things that maybe we short circuit because we're in a rush to get our AI things out.
And that certainly happened for ServiceNow, but this isn't the first, this isn't gonna be the last story around AI agents that are deployed out in an insecure way. And I recommend you take a look back at a video that Fortine did with us at Cloud Field day 24, where they illustrated just how easy it's to get an AI application to help you to hack itself. In their demo, they prompted the AI application, this, um, poorly secured AI application to tell them how to hack into it.
And this is not normally how attackers work. Normally attackers are very smart and already have some idea of how they're gonna compromise your system. Well, if you give them an AI that knows about your system and you don't protect enough, the AI will absolutely help to attack.
So, uh, it's absolutely a, a risk, the security of your AI system is a really significant problem if you don't address it before it's deployed out. 3 out of 10, uh, severity. Uh, and it's in service now because they had done some very fast and a little bit loose moves that ServiceNow should know not to do, shouldn't they, Tom?
com because it was a heck of a read. CV 25 or 20 25, 12, what was it? 12, uh, oh, whatever, four 20.
You know what we're calling it? We're calling it Body snatcher. That's how you know it's important.
It got a name. 3 out 10. Uh, it allows anybody, anywhere to impersonate one of your admins was just an email address.
Does that sound like a controller you want in your system? Probably thinking to yourself, well, who in their right mind rolled this out to production? We dunno.
But that's part of the problem, right? Is you've got on the one hand, the traditionalists who are like, let's not do this too fast, because we've seen what happens when things break and, and we've been in the data center at 2:00 AM when it's an all hands on deck. Oh my god, things broke problem.
I was just listening to an episode of the Packet Pushers podcast from our friend Scott Roon, uh, total network operations, where they were talking to a guy who from Intel, where there was like a, you could send a malformed packet to an Intel networking card and basically shut it down. And he's like, yeah, I had to miss a Sound Garden concert, uh, to be in there to fix that problem. Well, then on the other side, you've got these, I'll try not to say bad words, but you've got these people who are like, oh, we'll just, just code it, vibe, code it, and push it to production and we'll just solve the other problems.
You know what that reminds me of? Well, hey, I know there's a leak in the tank on the space shuttle. Just launch it, we'll fix it in orbit.
How hard can it be to fix a space shuttle? Uh, pretty hard, actually. Here's a problem.
And we talked about this last week when we talked about Palo Alto Shield. Um, framework security is something that you have to think about at all times. Do not trust this to a provide coded thing.
Do not trust this to a DevOps team that is just pushing and rolling and doing stuff. And I have talked to a ton of people over the last couple of years that are trying to integrate these kinds of checks into the development process so they don't escape into the wild. Those companies are even more important now because when you code an agent and you kick it out the door like a baby bird falling out of the nest, it, like you said in the intro, if it doesn't know that, it's not supposed to tell people how to hack it, it won't.
Here's another thing. We do not let our users have privileged access everywhere. I just talked about that in the delineate story, right?
What about your AI agents? Do you put a horizon on them or do you just assume that they're like the backup operators account? Nobody ever logs into it.
It, there's no problem with it having complete and total access across my entire environment. Yeah, all of the backup people just cringe. You cannot push code out the door without a lock on it.
I'm just, I'm gonna draw a line in the sand right here with a big GPU that probably costs like $20,000. If you listen to Security Boulevard, the podcast that I do with Mitch Ashley and Fernando Montenegro and, and Alan, uh, Shimel, we talk about this all the time. Like, you cannot just throw AI at a problem and take what it gives you and not use your brain.
You've gotta look at controls, you've gotta have lifecycle management. You have to keep your eyeballs on that thing. And you know how I know that the people who are doing this are probably pretty young because they've never been around a toddler, because toddlers, you have to keep your eyes on constantly.
I feel like anybody who's writing controls in an organization should have to spend a week with a 2-year-old, because I promise you, the minute it goes quiet, the minute you turn your back, they're into something that they shouldn't be. Bet. And if you can figure out how to put baby gates up and put locks on things, now you're ready for the big time.
Folks. What you think al think we need to put 'em all with some toddlers and figure this out? You know, I, I feel bad for the toddlers.
Um, being, having vibe coded controls around the toddlers is not something I think I wanna see. Uh, but as you say, Jake Poland makes the the great point. You know, you can't add security from orbit as it's, as it's going along.
Uh, in fact, the only way to be sure is to nuke it from orbit. And that's what he's suggesting. You stop this move to, uh, try and push as many AI features as fast as you can because it, when it breaks stuff, it's gonna break your entire organization.
This particular ServiceNow vulnerability that, uh, got deployed around October time, uh, for hosted instances, it's huge. It is a really big problem. Uh, and retrofitting best practice onto something that's currently wor working is always harder than building it from the beginning with good principles.
And fundamentally, this is just about having good principles, but it's about understanding that your AI is very similar. I mean, particularly in age. Agent AI is very much similar to having a minimum wage person who is working inside your data center.
And they have no loyalty to you unless you give them very strict guidance, but they can misbehave. And that's an absolute concern for anybody that does run age agent ai. You should absolutely be starting from the beginning as with all applications starting from the beginning with a security basis.
Uh, but I think we can continue to flog this one for a long time, and we are gonna see more of these vulnerabilities come through. We absolutely are. They may not come through in such a visible place as, uh, one of our favorite organizations, ServiceNow being hit with us.
But lots of smaller organizations are gonna be hit with these kinds of vulnerabilities and province. This is gonna be a common attack vector. And we'll see the usual host of security vendors trying to help build a fence or at least be the ambulance at the bottom of the cliff to try and save.
But fundamentally, if you don't build that fence at the top, if you don't protect yourself from going wrong, it'll go wrong, can go wrong fast. Something that doesn't go wrong, of course, are the Tech Field day events that we're running throughout the year. Uh, I'm feeling a little stressed at the moment because I have a big event coming next week with the AI Infrastructure Field Day event running January 28th to 30th.
Uh, I'll be out in Santa Clara with my delegates as well as with my sponsoring companies. Got a great lineup. Uh, we've got two different business units from Cisco.
We have, uh, fabrics ai as well as Xite have solid Im Hammer Space and Forward Networks all presenting through those three days. Plus. We also have a presentation from Brian Martin talking about some re research that the Signal six five team within Futurum have done.
And I'm also gonna give a little bit of coverage of some recent reports written by the analysts at Futurum Research that are around some of the security challenges and some of the other data challenges for building AI infrastructure. Looking forward to a, a great few days there and spending time with the awesome people that are the Tech Field Day delegates. I'll be back in, in Silicon Valley again, uh, for Cloud Field Day 25 in March, that's running the 11th and 12th of March.
We're building that one out as well. You have some nice companies talking about excellent things that they're doing in cloud and, uh, really learning more about hybrid multi-cloud and, and data management across those kinds of spaces. Uh, following that, of course, Tom, you have an interesting new, uh, event that we're gonna, You're right, we are gonna be doing Tech Field Day Extra at RSAC for the very first time.
Now, for those of you who don't know, it is RSAC conference. It is no longer the RSA conference that got spun out a few years ago. Uh, we actually just recorded a really great episode of Security Boulevard, where we talk about Jim Easterly being the new CEO of RSAC.
Uh, make sure you check that out when it goes live, uh, here very soon. But we are gonna be getting some great presentations from, uh, Veeam Object First Commvault and more. And I'm going to be there.
Uh, I'm gonna be hanging out with some of our friends. Uh, the folks from Techstrong and the Future Group are gonna be there. You know, my cohosts for my other podcast like Alan and Fernando and Mitch.
Uh, we're also gonna see some of my friends like Wolfgang and JJ and you know, people from the security industry, uh, if you, if you know who they are, right? Because otherwise, you know, they're super secret packer, hoodie people, but whatever, we're gonna be there. It's gonna be fun.
We're gonna be there the whole week of RSA. I'm gonna see what kind of fun I can get into, and I hope that you're able to join us too. Just like I'm glad that you're able to join us for this week's episode of The Rundown.
You know, we publish these new episodes every Wednesday. We do it on YouTube. We also do it in your favorite podcast application of choice, uh, no matter where you subscribe.
We love that. Subscribe to both. Uh, the Rundown is also streamed on Textron tv.
You can make sure you check us on all the other stuff that we do through techron and Future and Group, whether it's other podcasts that we do or other events that we're at, like Al's gonna be at next week. Speaking of which, when we come back next week, I'm gonna have a new, uh, co-hosts because Al's gonna be enjoying Sunny California. And, uh, we'll be back to talk about all of the tech news that happens, and we might even talk about all the cool stuff that's happening at AI infrastructure if you're not able to tune in.
But until then, for myself, Tom Hollingsworth, for Alistair Cook, and for everybody across the nation, thank you so much for tuning in for this week's episode of The Rundown. We'll see you next week. Hey everyone, welcome back here to Tech Trunk tv.
My next guest is Lee Rossi. Lee is the co-founder and CTO of a company called Sim Space. And let's welcome him.
Hey, Lee, welcome. Thanks for coming on Textron tv. Uh, pleasure to be here.
So Lee, we're gonna talk about sim space, we're gonna talk about AI and cybersecurity and all that. But let's start off talking about Lee. Give us a sense of, uh, how you got here.
Yeah, happy to, of course. The, um, yeah, so, um, well, I started probably like a few of us old guys 25, 30 years ago doing cybersecurity. I, um, in 2000, I joined a place called MIT Lincoln Laboratory, and MIT, Lincoln Lab Sure.
Is one of national labs building tech for, um, for the government, a national security apparatus, so intelligence, community, military and all that. And when I was at the lab, it was all about creating test beds and ranges and how do I test and evaluate cybersecurity. We didn't call it cybersecurity at the time.
It was, We called it in, It was all the other stuff. But this general problem was the same, is how do I test, evaluate, figure out what capabilities to develop for cybersecurity in that space? And the lab as a national security is all about, hey, not just cyber, but cyber with that overlap on mission systems, defending radars and air defense and missile defense and space control.
So it's always about tech rigor. It was about measurements, it was about evaluations and how do we actually create the most effective cybersecurity solutions, um, as possible. That, that's my quick answer for the 15 years at the national lab.
And then when we were there, we spun out and created SIM based the company. So actually it was a wonderful time. I, I learned a lot.
We did a lot with the, uh, with the US government, but then the question became cyber is, is broader than just the national security. It's impacting banks, it's impacting cities, it's impacting our way of living. And we spun out the company to be able to help out the broader, the broader us.
Um, so, so that's how we started 2015. And we created the company. Um, let me pause there for a quick second so I'm not monologuing Sure.
Hey, that's a great story. You know, I'm trying to think who I knew. They spun out a company outta Lincoln and uh, uh, Well, BitSight is another one.
So Steven Boyer, uh, another Boston based company all about, uh, risk and cyber assurance. Yeah, no, I know BitSight. No, this was like a personal friend of mine and I just, you know, you, you're doing this so long that you start, it all runs into it.
But yeah, they, I mean, look, the Lincoln Labs turned out some amazing, amazing technology, right? You know, that's part of, you talk about government investment and is it worth it? And pure r and d and stuff like that.
Yeah, those labs were worth every penny they invested in 'em. Man, You know what? I talked to the leadership and we talk about tech transition and what does it mean to do tech transition for some of the labs?
It's one thing you do patents and do technology, but it started when I was at the lab and it was true when I left. It's about spinning out the people, the whole apparatus, which is, yes, you can spin out the tech, but there's an element of everybody that goes with it. The people that know the domain, know the space, have the passion.
Yeah. So I remember when I joined the lab, it was optical networking at the time. In 2000 and Uhhuh, the whole group spun out.
It was 50, 60 people that were created Sycamore Networks and Photon X. Yes. And yes, it's the technology, but it was literally the whole group.
So when we spun out, it was the whole team. And of course there was hu the co-founder and a lot of experience in cyber command. And we created a company with the foundation of the people knowing the space, the technology, and then marrying it up to the problem, which was, which was really exciting.
I love it. I love it. And you know, there's a lesson out there, folks pay attention, Lee, let's talk some space.
Yeah. So 2015 is what you said? Yep, yep.
So another overnight sensation, you know, not in 10 years. I, how that goes. I, I started this company in 20, well, technically 2013, but we first published 2014.
But I, I've been doing, you know, startups for 30 plus years. Um, you talked about kind of where the inspiration came from, where the passion came from, but you know, there's, yeah, there's been a lot of water under the bridge from 2015 to today. And maybe the biggest boat under there, of course is ai, right?
AI seems to be Yeah. Changing everything or it has the potential to change everything. Yeah.
Talk to us about AI and, and how it's kind of changing or, or diverting or, or, you know, influencing the mission of sim space. Yeah, no, wonderful question. And let me maybe give a two minute on or a minute on what is sim space and then right.
Then the impact for that. So fundamentally, what we are providing technology wise, it's a cyber range. A cyber range is a very yes, realistic environment to allow you to train operators, test technology, develop it, validate it.
So it's effectively a proving ground. How do I provide a super realistic environment that, not to say a bank or a power company or a military, in that environment, I can develop, uh, new technologies, new cybersecurity solutions, make sure that they work in a beautiful dev test setup so I can really support technology and then, um, allow operators, allow individuals, soc members, team members to train with the technology and then, uh, train as a team. So from a training standpoint, how do I push people to failure, like attacks and realism, but in a safe environment?
So from a training, push the tech and push the people to the breaking point. So you can learn, so you can improve, you know, what it's like. It's, um, you wanna, you wanna experience failure many, many times So that in a, in a, in a safe setup in a range before you actually go through the real world to do that.
So that's from a training and a testing standpoint, AI makes it interesting because now, you know, we always have these technology evolution cycles we've gone through from mainframes to client server to cloud, and now hitting the ai. And the big push there is things are moving a lot faster. It's automating a lot of these day-to-day tasks for the SOX and the others.
And, and there is a transformation going on. Every large enterprise is trying to figure out how does this apply to what we're doing in terms of tech stack? And then also how do we actually get into the, the team aspect of it from a, from a retooling and a and adapting for the team members.
Let me pause there for a second because I wanna dive into a lot more of it, but, um, let me, let me, let me pause for a second for any. Sure. So look, the concept of a cyber range, yeah, I don't think that's foreign, you know, for our security friends out there, you, you know, you AppSec I think they get what a cyber range is.
Some are our non-security people. Yeah. Think of it as just a huge testing environment where you can set up, you know, very elaborate, complicated, sophisticated type of environments to, to test your security on.
I mean, and this is, you know, cyber ranges are not necessarily new. No. Right.
We've had them for a while, right? Always right. Testing.
But what, what is new, I think is the, uh, the, the, the pressure, the, the focus, you know, AI is, is making us sharpen our aim, if you will. Yeah. Shortening the cycle of Yeah.
Of, you know, when we discover things to when we gotta do things, it's, it's bringing more of a sense of urgency, let's say It is. But it's also becoming, um, I, I'll call it going from a nice to have to a must have, and let me explain it. So to your point, we've been doing cyber arrange, or I've been doing cyber arranger for 25 years.
It just happened to be for the government and for developing and testing tools commercially. People think of cyber as more for training, but that's more recent commercial angle on it. Yes.
Um, the rea, the reason why I think the ranges are really important for AI and agent is they need to be able to train, they need to be able to train on an environment they need to be able to learn. So how do you create the data sets? How do you create the environment to allow the agent to be able to understand all kinds of different types of networks, the diversity that's in them, the different types of attacks.
So they need to train on an environment, train on attacks, be able to figure out, am I making the right decision or the wrong decision? And being able to actually allow the developers to be like, Hey, as I'm developing this new tech, how do I make sure that it is doing the job equivalent to a human? And we're not quite there, but it's getting a lot better to be able to do that.
So the range we think of it as, again, it's an AI proving grounds. How do I put new tech in there to prove that it's effective? But also is it safe?
Like any new technology, it's interesting, whether it's cloud or crypto and all that, there's always the pluses. But then the question is, what about the negatives? What are the potential risks that I may have with, um, with AI solutions?
So how do I prove that the AI cannot be co-opted, cannot be deceived, cannot be, uh, manipulated to be able to do that. So you wanna be able to prove that out for that. But to your point, things are moving fast.
AI is accelerating the rate of the attacks. It is accelerating the rate, uh, people are doing, but it's also got the benefits from a defensive side is can I leverage it to be able to sift through more data, understand what is happening, to be able to accelerate my response to an accelerating attack, uh, surface or an attacks attack attacks. Therefore, I get it.
I get it. And, and you're right. And, and you know, unfortunately, we haven't had enough experience with a lot of these AI scenarios, right?
And, and so being able to train on a cyber range is, is, um, I mean it's a resource a a deadly needed resource, let's call it that, right? Yeah. 'cause we just don't have the, we don't have a written book necessarily on this stuff yet.
No, and I heard a great quote from somebody, any enterprise who's gonna be leveraging AI is gonna get disrupted. So there is a disruptive element to AI in that. And that is not just the people side, it is the process.
You need to be willing to change your processes, how you do business, it's gonna change your tech stack. And of course, it's also gonna have to allow the operators to be disrupted, not replaced. In my mind.
We talk about a lot of these. It's gonna eliminate a lot of tier one, tier two SOC positions. I think people need to embrace, to some degree the changes coming with ai, even from a defensive side to leverage it to be able to actually go through and, and do the job a little bit faster and all that.
But, but it is transforming the way enterprises are actually, uh, operating. And along with that is how do I now train and work with alongside AI defensive solutions, AgTech and AI solutions. So operators coexisting working side by side with new technologies, AI based defending against potentially accelerating and more vicious attack scenarios.
So AI for offensive purposes, being targeted enterprises. And so, so yes, it is, it is changing how the defense is working in terms of the tools and the people, but it's also working to counter potentially an accelerating threat. Absolutely.
Lee, you don't mind, I want to turn back to sim space a little bit. Yeah. 'cause we're running low on time for people out there saying, Hey, this is just what we're looking for, right?
We need, we need to get our people up to speed. We need to, you know, you can't fight or defending against something you don't even understand. We need to understand, we need to, you know, get our response battle plans in order.
What's the best way to engage sim space? Um, well go to the website. If you go to the website, you can look at the URL, there's a link over there to be able to contact us and of course, want to be able to engage and work through.
com is, um, is a way to get to us. But I would like to make the point, I think when we talk to a lot of our enterprise customers, the first question is even is, which AI is right for me? How do I prove and find what's the right solution?
Is how do I actually go through this pre-production before you deploy it for anything as disruptive? How do I even make sure that it is the right tech for me and in the right area? And not only do I prove that it's effective, but how do I make sure it's safe and not bringing me down the road?
And then of course, I wanna be able to train with whatever you've chosen, but I think there's an element of bill versus buy. What am I building myself versus what am I buying? And then there's an element of how do I train my staff to leverage it?
But there's a series of questions before to figure out what tech is appropriate and in what areas for a particular enterprise. Because you don't wanna roll something out that's gonna make decision on your behalf that you don't fully understand, uh, what it's doing and how it applies to, uh, your shop. But the website is the quick answer.
Absolutely. Lee, I want to, um, you know, you, you, how do you choose what's the right ai or are they kind of interchangeable at some level? Right?
We, right now, we're still at the beginning of this whole journey. We are. So we, we, you know, we have the frontier models.
So do you want to use Claude? Do you want to use chat? GPT?
You wanna use Gemini? But really I think what we're gonna see going forward is a new generation of models. You wanna call 'em small language models, you know, based on rag, based on a lot of different things.
But it's you, what we're gonna find is you don't need these big frontier models for a lot of the tasks that we're going to use AI for. I, I, so this is where let the vendors come up with the base way, the best ways to be able to solve the problem, whether it's big, small, whatever the models are. Uh, I look at it more as the solution is being provided by whomever it is.
Um, I think it's gonna be interesting to be able to see is they're all gonna come up with pretty decent generic models trained on broad enterprises and broad sets of data. That's gonna be awesome. I think the more interesting is how do you then tailor and retrain those models for the specific enterprises in terms of their network, their processes, their data and all that.
So, generic models wonderful for the wide set of attacks, but then how do I choose a technology that can actually train and understand on the enterprise specific businesses model architecture to be much more, um, suited for that particular setup. So AI is great, but needs to be trained and tailored to the specific nuances of that enterprise. Just like every human operative, they, they know their business, they know which ips are interesting, they know what their processes are.
Um, that's what you want these models to train on, to get more specific to the enterprise, uh, itself. I love it. Hey Lee, I promise I'd get you outta here on time.
I'm gonna, um, thank you very much for coming on and getting us a little smart here today and telling us about SIM space. Congratulations on 10 plus years building a great company. Come back, keep us posted.
Happy to chat with you about this anytime. Well, thank you so much. I really appreciate the time.
And again, it's wonderful chatting. Thank you so much. All right.
Lee Rossi, co-founder CTO of sim space here on Tech Trunk tv. We're gonna take a break. We'll be back with more.
Stay tuned. Hey guys, thanks to the throw, we're here with Fitz Nolan, who's vice president of AI and architecture for SmartBear. And we're having a chat about well, integrity, at least software integrity, because well, it's becoming a bigger issue in the age of AI fits.
Welcome to the show. Thanks so much for having me. Great to be here.
Mike. What is going on these days? 'cause I think we were all super focused on coding faster than ever, but I'm not quite clear that that has, uh, improved the quality of the applications we're building.
So what do we need to be thinking about here as we kind of go forward and what are we overlooking? Yeah, it's a great question. Uh, obviously AI's transformative technology, and I think a lot of the attention has been paid to the software development side of the house and how it's changing, uh, the speed at which we can develop new features and we can prototype new applications.
But ultimately what that means then is if you're producing product at a faster rate, you need to ensure quality at that same rate. Uh, or else quality will just be that a bottleneck for getting all those great new features you're building out into the market. So, um, that's really where we're focused a lot at SmartBear on the integrity of your applications, the correctness of your applications in this new world of software, uh, development driven by ai, Who's taken responsibility for that.
And I asked the question because a lot of times developers are like, well, I checked my code in and that was it for me. And away I go on to the next thing. So somebody on the other side of that check-in process is probably looking at all this stuff and there's more of this code than ever for them to review.
So how do they keep pace? Yeah, it's a great Question. I think what you'll see is in kind of where we're placing our bets, or one of our bets is on, um, AI powered quality assurance or bringing the qa, um, task, uh, into the, the velocity of the software development world and with ai.
And so if you have AI powering your software development, you need AI powering your qa. And so, um, you know, we have AI infused to different points of the quality assurance, uh, life cycle. So whether that's managing your test cases or helping you execute test cases, or even helping you author brand new test cases using ai, we have, uh, you know, solutions in that space.
And, and that's really where we're focusing, because again, all the money right now really seems to be going into software development. If you look at the biggest names in ai, they're all focusing on coding assistance and, and, um, you know, coding agents, uh, you know, we're, we're kind of trying to meet them in the future with, uh, QA powered by AI as well. So to your question about who owns that, um, I think it's QA teams.
I think it's, um, a lot of it actually will go back to product management teams, the folks who define the functional specifications of software and, um, you know, the people who decide ultimately what they want to build. So whether that's developers at small organizations or PM folks at larger organizations, um, we think that functional specification really acts like the source of truth, both for what you're building, but also for what you're testing that functional spec becomes your set of test cases in a sense. Will those folks there maybe just call up a DevOps engineer to fix the problem then?
'cause it seems like the pace at which we're moving, maybe they don't wanna go back to the original developer, and so perhaps they're gonna have somebody else kinda review that code and, uh, put in the fix as it were. I think it, I think you'll see more of, um, almost like a blending of roles. So it, it could be a DevOps role who's kind of straddling, you know, infrastructure and, and source code.
Potentially. It could be a product manager who's straddling, uh, functional specifications and quality assurance. Um, it could be a developer at smaller organizations who's, who's wearing all the hats, right?
Certain developers at, at startups, uh, will often be doing the infrastructure of the DevOps role, but they'll be doing quality assurance as well. They might even be specking certain behaviors out like a PM might do. So it, it's going to allow AI will allow a blending of roles across the different, um, points in the software development lifecycle, I think.
Mm-hmm. Do we need a different AI model to review the code that was created using another AI model? I think there's a tendency where people are kind of using the same AI model to kind of test things, and it's like, well, I don't think that AI model is gonna catch the original error.
Uh, 'cause it's kind of like asking the fox to guard the hen house, right? That's right. That's right.
Who's watching the watchmen? Um, so totally, I think it's a good question. The, the, it's sort of a subtle one.
I don't think you necessarily need a different model, but you need a different structure and framework and composition of, um, your task for QA versus for software development, you could use the same model, but, um, that's at the lowest level above the level of the model. You have all the structure of the questions you're asking and the task you're trying to achieve. So in the case of software development, you have things like planning, um, implementation, execution, unit testing, and then post merge or post deployment to your staging environment.
On the QA side, you might have things like definitions of correctness, um, visual accuracy or visual correctness, and then functional or operational correctness. And then even a third check kind of a little lower level. And this is maybe where we bring in DevOps.
Um, you know, does the database integrity, uh, look good? Uh, is the, the volume of traffic going through our system, is that normal or is that abnormal? Is the latency correct?
Things like that, you know, you kinda have different areas that you focus on. You could use the same model. You could use Gemini or chat PT or anthropics, clo, whatever you want.
Um, but it's the structure of those prompts. It's the focus of the prompt. It's the way you use the model that is different for those different purposes.
So I think you're okay to, to te test your AI with AI as long as you, you have a fundamentally different construction of the problem. Mm-hmm. Um, as you kind of think this through for a minute, are you concerned that maybe we're gonna have a spate of applications showing up in production environments where the quality is even lower than it might have been historically?
And we're gonna have these, um, some sort of situation where the number of incidents are gonna just dramatically increase? Yes. There, there's absolutely that possibility.
There are a bunch of different ways to take that one angle, um, which I'm, I'm not, uh, too deeply entrenched in is like the cybersecurity angle there. So I'll kind of mention that. That's absolutely a, a consideration.
I think I saw one of your, one of your previous, uh, videos touched on that a little bit. Um, an area that's pretty interesting for us though, uh, is, is what you were saying, you kind of hinted at it. You might have apps that are lower quality, but who's consuming your app in the new world?
Is it still those human users that it's been for the last 70 years of software? Or is it AI agents? And if it's AI agents, should we be building apps a little bit differently and testing them a little bit differently as well?
And here's why. So in the past, right, if you had an app that that, um, really made your user feel great, uh, you can almost imagine like commercials, right? They're like, bring tears to the eyes of, of the viewer.
It's really compelling and captures their attention the, that application developers should be thinking about. And it all relates to who their, who their ideal customers, who their ICP is. Um, and so I think that that may change how we test and, and, um, you know, ultimately how we structure our applications in the future.
Mm-hmm. To your point about that, um, are there tells in the AI code that we should be looking for as it pertains to quality? And I asked the question because sometimes, uh, the AI generates code that I would say is a little overly verbose, and then we wind up with a situation where maybe it costs more to run that software because it's just consuming more memory.
But are there, are there things that people should be looking for specifically that are kinda like, you know, top of mind issues that should just be, you know, things you address right off the bat? I, I think, you know, functional integrity is first and foremost, the application must always still do what it claims to do. And, and if it doesn't do that, you will lose your users.
You'll lose your a ai agentic users as well. It has to function correctly. So that's always the first level of check, I think, um, to your point on, on like, uh, the veracity of the code that's generated, or, um, a lot of times what you'll see is, is the code related to veracity, it'll generate the same, um, functional code multiple times for different parts of the application.
It won't effectively refactor that code, you know, to use kind of a, um, a single de-duplicated implementation. Um, the flip side of that argument is if it costs you less money to develop your application because AI generated it, then maybe you don't mind spending a little more to run the application, uh, because you were already saving so much money 'cause you didn't have to pay the human developer. Um, that, that would be, it's kind of, I guess, a different debate.
Different debate there if you're willing to pay, you know, go down that bridge. Um, but uh, to your question on kind of like what to look at, I, for me, I always just come back to functional integrity. It must do what it says it will do.
If you're solving a big enough pain point for your customer, they'll overlook the, the visual wart or, um, you know, the, uh, not aesthetically pleasing UI you have if it's solving a functional problem for them. Um, so that's always, that's always step one. And then when you get to step two, which is like, well, how easy is it to consume?
How performant is it? How enjoyable is it to use? That's where I think you kinda have to go back to this question of, well, who's using my app today?
Who's using my app two years from now? Um, and what's the best experience for those different users? Are you at all concerned that maybe we'll just get lazy when it comes to application development and, you know, we'll just let the AI generate some things and we won't think through the process and maybe we won't even know exactly how the thing works?
Uh, definitely it's, it's possible. It's a concern. Um, you know, it kind of depends, I guess, how futuristic you are.
Uh, and you know how much you buy into the narrative that we hear. Um, I think like a lot of things that'll be gradual over time. I think there will be certain applications or certain experiences that become commoditized and, and they kind of are known to be consumed by the AI agent for this or that business or this or that consumer.
Um, and then there will be other applications which are, uh, they're still always gonna be consumed by users and, um, you know, they'll always be, uh, the quality there will always be important. I think quality, again, has a lot of different meanings, a lot of different connotations. One of them is functional correctness.
And so that's always going to matter that you can't, you don't have software if it doesn't do what it says it's gonna do. Um, but beyond that, you know, to the aesthetics, I think again, it's gonna be a gradual thing. It'll be stuff across the spectrum where you see some usage, uh, is AI driven and other usage is human driven.
And, and I think, you know, we'll define that happy medium. Mm-hmm. There are also a lot of folks who are talking about the rise of vibe coding, and we will finally have these citizen developers generating all kinds of interesting things and the definition of what a developer might change.
But does that create some quality challenges? 'cause the folks who are building that software don't necessarily have, uh, shall we say, an appreciation for the fundamentals. Absolutely.
So for, for in, with the vibe coating question, really what you're seeing there, I think is that, um, the source of truth for an application is really no longer the source code in the 100% vibe coded application. It is more the prompts and the, um, the functional specification, if you will, of the application that generate that's used to generate the code. So you will need some expression in that same level of abstraction, uh, on the quality side, on the, the functional side, uh, that can be used by QA agents to test the application.
Uh, because you, you won't necessarily be able to use, uh, QA to test the source code that's generated in vibe coding because it, it could be so massive and, and it could change, could be lots of churn, right? Every new session of vibe coding my application, the, the LLM might rewrite half of my application. And so the actual source code becomes a little less important.
And what becomes important, the source of truth are the spec, the, you know, the specifications or the context that's given to the, to the LLM to generate the app. Alright. Um, so what's your best advice to folks there for, as you kind of look at all this?
'cause I think we've been struggling with this quality issue for a long time, and there's more, people seem to be concerned about speed than quality, and that's always been something of a mix match. So how do we get more people to care about quality? Um, I mean the, the, the proof is in the pudding.
I think you have to show people that quality makes money, you know, quality applications make money. And I think you have to, I think, I think it's, it's reasonable and it's a reasonably compelling argument to say, look, if you're producing software at 10 times the speed today that you were before, you need to test your software at 10 times the speed you were before. And so you can't do that with a human in the loop because you're not doing it with a human in the loop on the software creation side.
So I think it's compelling to say you need AI in qa and, um, you know, from there it's, okay, well, what's the source of truth that's being fed to that ai? Well, it's very likely the functional specs, the definitions of my applications that I want built those requirements they serve as the guardrails during qa. So, um, you know, the, the, the argument then becomes, use good tools for documenting your applications, use, use good tools, AI powered tools for, uh, testing your applications.
And, um, you know, with that you can, you can maintain the same velocity on your testing side as you have on the development side. Mm-hmm. What is that one thing you see people doing over and over again that just makes you shake your head a little bit and go, you know, folks, I wish we would think this through a little bit better.
Uh, well, so this, this goes back a little bit, um, but it's still present today. So I, I started a company called Reflect, which, uh, was an automated end-to-end testing platform, and it kind of competed with a lot of the code-based testing, uh, approaches out there like playwright, selenium, Cyprus. And, uh, I thought then, and I, I think it only more strongly now that the exclusively human authored code-based testing of applications is, um, is rapidly going to be overtaken by, or if it hasn't already been overtaken by, uh, AI powered development.
Uh, and, and what I mean by that is if AI is producing your, the source code to your application at a much faster rate, you can't have humans authoring playwright tests to, to test that software. You have to have AI in the testing, uh, lifecycle in, in the qa, uh, framework so that you can keep pace. So, but I, I, you still see, you still see folks today, they're using AI to generate playwright tests, which is a little better than humans generating the playwright tests.
Um, but, uh, but you, you need, you need AI in, in the, um, in the QA process because you need that, uh, human-like intelligence to decide when a bug is a bug. You know, the, the famous problem with code-based testing is that, um, it's brittle to, uh, semantic, um, to, to different implementations with the same semantic. So if you move the location of a button or you change the color of a button in your application, some minor, you know, uh, literal change that it didn't change the, um, intent of the application that those tests are gonna fail.
So that, that's a, a behavior that I still see that I, that makes me shake my head and, and say, you know, you gotta graduate to, to AI in the QA loop. Mm-hmm. You know, we always talk about testing and quality assessment in the context of the people who built the software, but I wonder in the age of ai, if we won't see more organizations using those same tools that are AI driven to test the quality of the applications they're being asked to deploy and use.
And the whole notion of quality assessment is gonna change because, well, the end customers are gonna get a lot savvier about doing those assessments without regard, without any aid from a developer per se, and then they'll give their feedback accordingly. Yeah. I guess, could you go one level deeper for me?
Uh, what's, are you thinking on like the, the end user consumption side there, or in the, I'm, I'm thinking there'll be some enterprising CIO somewhere who will take these tools and apply that to some custom application that they've bought or some even commercial application just to see if this thing will stand up to the test of time and it'll become one of their buying criteria motions. Yeah, I got it. So, so you, you're kind of, uh, positing, is there a, a future where enterprises use AI agents to validate or test the software that they're purchasing from third party vendors?
Sure. Why not? Yeah.
Yeah, absolutely. And this gets back to one of, like a central theme of our position is like, in the future, two years from now, will it be humans using your app or will it be AI agents? And, and if it's AI agents, it's probably different things that matter to the AI agents than it mattered to the human.
Uh, and so for that CIO example, they probably care a lot about governance, compliance, um, correctness, uh, things like that, you know, integrity that might be a little different than the end user who's trying to use the software just to do their job, kind of not as part of the bigger picture, but sort of a, a smaller picture. Uh, I think it's really interesting to, to wonder if, getting back to this notion of like, if, uh, selling software was about, it was about visibility, getting in front of your customer, but then also telling a great story kind of almost even beyond, uh, accuracy or functional corrections telling a great story. That's what got that sale.
And then, you know, obviously functional correctness keeps the sale in the AI agentic future. Do people and businesses give their AI agents personas just like the, the former buyer, the human buyers of that software had before them? And, uh, you know, do, do software vendors then need to think, not just is it AI or human, but if it's ai, is it gonna behave and, and want things like the previous human user wanted?
Or is it a different thing that, that they want? Um, you know, it's a, it's a really crazy notion to think about it. You can kind of go in all different directions, but, um, it, it's, it's stuff that's possible, I think.
All right, folks, we're at the beginning of this adventure, but I would say one thing, it may feel really good, the write a piece of code and be done, but it all feels really bad when the minute somebody calls up complaining about that very same piece of code. Hey, Fitz, thanks for being on the show. Thanks so much for having me, Mike.
Have a great day. All right. And back to you guys in the studio.
Hey everyone, welcome to this futurum executive interview series. We're going inside the AI infrastructure revolution, and today I'm joined by Mohamed Awad from Arm to Get the Arm perspective. Mohamed, welcome.
Great to have you on. Thanks for having me. Great to be here.
Yeah. So I wanna start off, let's hit the AI inflection, you know, every day, literally every day it feels like there's news massive investments, whether it's more compute, more energy, uh, you know, more mo new models coming out, the leapfrogging effect. Like, you know, I'd like to get your perspective, like what is defining this moment in the compute revolution and how do you see arm's role broadly in that landscape?
Yeah, totally. I mean, I think, I mean, I think the easiest, the easiest way to describe, it's just transformational. I mean, I mean, things are just changing so quickly.
The potential is just massive, you know, and we're really kind of shifting gears in a big way in terms of what compute is and how it works, how energy efficient it can be, and sort of the value that it can provide. I think, you know, the, the world kind of sees that potential. It sees it on the horizon.
We're, we're, we're not there yet. We're kind of early innings, and it's, a lot of it is about, you know, how do we achieve that potential and sort of transform, you know, everything from the, the devices we carry around through to the infrastructure and the, the cloud that, that, uh, that makes it happen. So it's a pretty wild time.
It really is. And, and I speak to so many enterprises every day, and while a lot of us have been really focused on LLMs and how we're using them and the shift in how we search, I think we're in the very earliest innings. I said something the other day, I said, we're about 1% of the way in to ai, and while people think it's farther along, it is not.
Yeah, we're just getting started. But, you know, in terms of like in the hyperscaler space Yeah, like, you know, in your business, right? We've seen AWS we're seeing Google, you know, Axion, we're seeing Microsoft, we're seeing, you know, of course Nvidia the grace and you know, and GB and GH and all those different things.
Yeah. Um, it's all on, you know, I think people would love to understand, you know, 'cause we're tracking this very closely too, but the hyperscalers have clearly moved a lot of, a lot of their commitment to arm. What's, uh, kinda what's driving that?
What's the technical reasons behind that shift? Yeah, it's, it is, um, you know, we've seen tremendous, tremendous, uh, adoption. We've seen a lot of, a lot of momentum as of as of recent and really a couple, a couple of things.
I mean, at, at its core, it's about this idea that we enable a level of, you know, flexibility and innovation, uh, while still being able to take advantage of an ecosystem. So if you think about how data centers were built in the past, you take some off the shelf compute and you would, you know, build up, everybody knows the story about Google, right? Built in the, in the, uh, in the Stanford dorm room.
And, you know, they just kind of cobbled together off the shelf hardware and it was like, let software figure it out. We're well past that now. The sort of performance demands, the efficiency demands you need, uh, you need these systems built from the ground up and optimized for, uh, for your particular use case.
And so, and that, and that's to get the level of efficiency and get the level of performance out there. And so what you're seeing all these guys, whether it's, you know, whether it's AWS whether it's uh, Google, whether it's Microsoft, whether it's Nvidia, you know, all of them, they're building their own general purpose compute. They're building their own acceleration, they're building their own networking.
And arms get a role to play in all of that. And, and, you know, I think that's really kind of helping, uh, you know, propel us forward, right? Yeah, it's been a great, it's been great to watch the Rise, you know, more competition puts, uh, you know, made the X 86 folks put some effort in to improve what they're doing.
I think competition is good. We always say that, you know, it creates efficiency in the market. It creates, and of course the TAM is rapidly expanding.
A lot of people always wanna do these zero something. It's like, oh, if they get it, that means everything's lost. It's like accelerated compute market's massive.
In fact, you know, I know you probably can't say anything, but I keep saying, I think arm's gonna have a bigger role to play there too, um, pretty soon. So, um, really quickly though, I think we've seen numbers like at AWS like about 50% now of the, the workloads are now running on arm, you know, we definitely measure market share, kind of where do you see your market share sitting right now? Yeah, so AWS actually just at this past reinvent and at the reinvent before talked about this past reinvent.
They talked about how in the last three years more than 50% of the compute they deployed was ARM-based. And it, and it's interesting because, you know, these are guys who are clearly, uh, you know, in front in terms of general purpose compute and what they've done around custom silicon. But if you look more broadly at what's happening with the transition to ai, you know, a lot of these systems that are being deployed are being deployed as full rack solutions.
And those racks, those systems, you know, come with a general purpose compute, they come with a, uh, accelerator and it's all kind of kind of built together. So if you're, if you're deploying an NVL 72, if you're deploying Agra, Grace Blackwell of Vera Rubin, um, you know, if you're deploying your own TPU with a head node or you're deploying your own accelerator, you know, the likelihood that that's arm sitting alongside it is actually pretty high. In addition to that, when you start to think about the networking side, whether it's things like Nitro or you know, Bluefield or otherwise, those are all ARM-based CPUs that are driving those.
And at the end of the day, those are actually offloading what historically was considered general purpose compute. So you've got a lot of compute happening there. Um, so, you know, I, we, uh, we talked about at the beginning of this year how we believe that about 50% of the compute that's gonna be deployed at the top, uh, hyperscalers will be arm based this year.
Um, you know, and we continue to believe that that's gonna be the case. Yeah. So, so quickly, you know, in terms of, you know, your data center presence continues to grow.
I'm glad you mentioned the networking, because that's another huge opportunity. We see networking as one of those big, like I think we are obsessed at compute was the constraint, but now we're seeing networking and memory and storage and everything kind of down the silicon supply chain. Of course, energy's a whole nother topic.
So arm's always been very focused on energy efficiency, which is a, a value there too. But like what do you see as the big technical eco market related challenges that are gonna, you know, be critical, uh, going forward for the data center? Yeah, This is an AL'S law game, so you're gonna, you're gonna, you know, accel, you know, your accelerators are gonna get better than you gotta worry about your networking to connect them.
And then you gotta worry about your general purpose compute to supply them. I mean, at the end of the day, what we're seeing right now are, there are a couple of main challenges. First and foremost is power.
If you think about the sort of scale of what we're trying to accomplish, the amount of power required in order to do that is really beyond what the grid can handle. And so there's real, a couple ways to deal with that. You increase performance per watt, that's the number one game.
So I think that's gonna be a big thing and sort of race to better and better performance for lower and lower power. The second is, you know, availability of silicon. When you think about, um, you know, the, the, the supply chain, when you think about the cost of building the silicon, the time it takes, and then the sort of capacity available, that's gonna continue to be a bottleneck.
So we gotta, again, look for ways to, to further kind of dry that out. And advanced packaging technologies, et cetera, are gonna help with that. But we gotta bring more capacity online.
I mean, I think at the end of the day, um, you know, there isn't gonna be one particular issue. I think there's a bunch of issues, and this is really gonna be an ecosystem wide effort to kind of, you know, uh, you know, squash those issues as they, as they pop up. It's a, it's a classic Bel Law problem.
Yeah. And I think the market's, a lot of the market is, is grossly underestimating the proliferation, how fast AI is gonna find its way, like I said, I keep using enterprise, but then even like edge and physical. So let's talk about that for a minute.
Like, that's a lot of the, you know, the genesis of of ARM was always, you know, small, low powered, uh, you know, whether it was mobile devices, but of course you have a business in automotive, you have a business in iot, you have a business in, you know, basically all these things. And I think it's a multi-trillion dollar tam sitting out there for that, those markets, you know, talk a little bit about, you know, where's arms edge and, and, you know, strategy going. Yeah, I mean, it's, it's, uh, it's ama I mean, you know, it, it's amazing the sort of potential that we see in the edge and kind of how quickly those devices are adopting ai.
You know, uh, obviously, you know, we've got about 99% market share in the mobile phone space. We've got an incredible pre presence in areas around physical ai, whether that's things like robotics or automotive or otherwise. Um, you know, you look at, uh, mobile, um, you look at like, uh, laptop and PC based platforms, which are now going arm based because they're looking, starting to look more and more like, um, you know, they're starting to look more and more like mobile phones.
In fact, you know, something like 90% of the apps that are, that are, uh, run on those devices are actually, um, natively written for ARM already. And so, you know, underlying all of that is when folks look to go take those devices and then expand them, add that AI capability as it becomes infused, leveraging that same software ecosystem, leveraging that same platform that is, you know, they've, they've come to, uh, to build this massive, uh, software base on those devices. But then also that is being used in the cloud, leveraging that same software across both of those places.
We're seeing that as a massive tailwind for us. In fact, you know, we think that the Edge can is gonna be an incredible opportunity for us moving forward, and we're already capturing on it on things like our Lumex platform that we just, uh, that we just launched. Yeah, we expect that to be a really big growth opportunity.
We've been obsessing with data Center for some time, but I think what happens outside the data center is gonna be a, a long, you know, across the next 10 years, it's gonna play a massive role in terms of expanding tam, expanding market opportunity, and of course bringing AI into our everyday lives. So the devices, you know, the last few years it's been all about data center, but I don't think that's gonna stay for the long term. Um, you know, one of the things about ARM that's really interesting is your business model has evolved a lot, was really, you know, a royalty licensing focus.
You've gotten more into custom that senior margins grow a little bit, but just for those out there that are kind of like trying to understand how ARM makes money, how it, you know, goes to market, give us your sort of, the way you explain it, you know, how do you talk about it when you're at the, uh, at the family dinner table and you get Past it? Yeah, I mean, I think the way to think about it is we enable innovation and we enable a, an ecosystem that, um, that, that comes together to build amazing products based on whatever the requirements are. Some cases that means ip, some cases that means compute subsystems, and some cases that means you, you work with one of our partners to get something like a triplet or even a full on SOC.
And I think the, the, the thing that really separates us from, from, uh, from other companies is our ability to meet you at whatever integration point makes the most sense for you based on the problem you're trying to solve. Mm-hmm. So in a world that's advancing very rapidly, you're trying to adapt new technologies into it.
You're trying to fight for performance per watt off the shelf isn't good enough. You choose which integration point you want and arm, arm and more broadly, the arm ecosystem is there to kind of make it happen. Yeah, that's a good way to explain it.
I think, uh, you avoided the, the trap I put you in of actually trying to break down the how, the, how the different royalty and licensing and subsystem buckets. But I have, uh, it's been good to see you find ways to expand margin by adding more value. 'cause you obviously, as the company continues to be a critical provider of IP to many of the technologies we use every day, how you evaluate that, it's hard when it's only based on unit volume and you know, when you can get a little more out per unit.
It's a, it's a good way to increase the, the, you know, the business' value. Um, as we wrap up here, you know, you heard me allude to, you know, performance per watt leadership or low power, that's always been a big part of the ethos. Um, you know, what are the other advantages that, you know, you think that really are the big reinforcement points for arms?
You know, you unique value proposition? I mean, I think number one, it's ecosystem. When you look at arm, you know, our ecosystem is second to nut.
And so this idea that you can, you know, you know that it's not just arm, but it's an entire ecosystem standing beside you ready to help you realize whatever your potential is, uh, you know, and whatever the, the problem is that you're trying to solve. I think that is probably, um, one of, one of the greatest values beyond the sort of performance per wat and just the, the technical chops that we've got. And I think that's so important in an environment like, uh, you know, today where, you know, things are changing so rapidly, whether that's software ecosystem, whether it's our hardware ecosystem, whether it's partners in our arm, total design program.
You know, we've got this massive, um, you know, uh, ecosystem ready to kind of support you. That's very different, by the way, than other architectures. You know, other architectures either have a strong ecosystem where they'll give you an off the shelf solution and maybe have good software, but you kind of get what you get, or you've got incredible flexibility, but you don't have that ecosystem there to support you.
You kind of bring the best of the, those two worlds together, and that's really what sets us apart. Mohamed Awa, I wanna thank you so much for joining me on this Futurum Executive Interview series. It's great to get a little more insight as to what's going on at arm.
We're watching you closely. You can be sure of that. Uh, congratulations on all the progress so far, and let's, uh, catch up again soon.
Thank you. It was great talking to you. Control.
This is agent dev. I'm in position. Copy that.
Dev standby for Go Standing by. Hey everybody. Welcome.
Welcome to another episode of Agents of Deb Podcast. I'm Mitch Ashley. I lead the software lifecycle engineering practice at Futurum Group, and also a practitioner myself, my co-host, Brad Shiman.
Hey, Brad. Good to see you again. Hi there, Mitch.
Good to see you. I, uh, I understand we, we are gonna, we're gonna chat about, uh, a little bit of anger today in the developer community and try to make some sense about it or of it Yeah, that's one. You know, that's, that's sort of one mob.
You don't wanna get angry at you because, because they rally fast. They, they'll just make a new language. Tell folks about what you do at, at Futurum, by the way, or did you Do that?
Oh, yeah, sorry. Sorry. If, if for those of you, uh, haven't, uh, or aren't following us, and if you're not, we, we would love you to, to, um, tune into our podcast.
Mitch and I do this weekly, and, uh, we would love for you to join us on that journey. Um, mm-hmm. So for me, I, I'm just, uh, like Mitch, I'm very similar, uh, and in that I'm an analyst and I cover data intelligence, analytics, infrastructure, and I'm also a practitioner, uh, you know, sadly beating his head against the, the impenetrable wall of data science, uh, on a daily basis.
Yes. Data, the, the world sometimes is an island and in the data world, but it seems less so. But maybe that's a topic for another podcast that Is a good topic.
Yeah, we should, we should talk about that. I'd love to talk to you about that. Get your thoughts on it.
Say, uh, so the controversy, um, which I didn't see this, you told me about it, uh, was about anthropic sort of changing their, um, use of their API to subscription customers who get the $200 you can eat buffet Yeah. Uh, of, uh, of Quad from any tool you like, but actually they changed it. Talk about what happened.
Yeah. So developers that were using, uh, a number of other tools that, that can basically use, uh, a harness to, to access, uh, anthropics models as you just described, using OAuth to get there. So you basically just log into your anthropic backend via this third party front end tooling.
Like open code is, which was the most vocal, uh, of the, uh, communities to, to get angry about this. Uh, I think it was on Thursday or Fridays. Um, but, uh, Yeah, forget what day.
I think it was the ninth is when it was, whenever that was. Yeah, I think, I think that's Friday. And, and, um, so they woke up that day and booted up their favorite open source friendly CLI tool that that does a lot of things.
That cloud, uh, co code, which is Anthropics front end tooling does not do, um, uh, such as at the, you know, they're catching up. Okay. I'm not saying that it's, it's inferior.
I'm just, I'm just saying that, you know, their open source tools like Open Code have demonstrated some great ideas, like natively incorporating language server processors for LSPs or, yeah. Language service, service protocol, sorry, guys. To, to basically allow models to sort of look for syntax errors without having to ask, did I do something wrong?
They could just fix it on their own, which is great. Mm-hmm. And so anyway, open code developers woke up on Friday and, and went to incorporate their clawed backend, uh, to use sonnets or haiku or, or any of the, the models they have, honestly, with their plan.
And they were kicked out, uh, with a, you know, cannot log in warning. And, um, when pressed about it, anthropic basically responded to say that, well, you know, this was really an inappropriate use of our API backend and one that was not in line with our security, um, requirements. And so we, we have turned it off and you can make of that what you will.
And, and I, I think their their right to protect their customers by ensuring the, the proper use of their backend services that is their responsibility after all. Right. But, you know, it, it, it sort of irked a lot of people because it has, it has become very common practice right now to use the front end of your favorite front end, let's say Google's, um, anti-gravity and be able to access anthropic, uh, and their terrific models for coding.
And suddenly you can't do that. You have to go right to Claude to do that with their own software. So Anthropic with their own software, You know, I think several things kind of tick people off.
One is your, uh, your Ralph Wiggins, we'll talk about Ralph Wiggins, your Ralph Loops that were running overnight suddenly stopped running, didn't complete, um, yeah, because there was no notice too. So you, you were logged in or you went into open code and both, you couldn't log in then, but also anything that happened to be running was already at a commission and you're figuring out what to do. People are complaining this is a, is a walled garden.
I don't, I don't see it necessarily that way. Um, you know, philanthropics got a business, they, they want people to use their models, but their tools, you know, they obviously want to have the, the best access to their, to their models, and they're giving away a lot of stuff with their $200, uh, subscription a month. Yeah.
Not the 200 lot. Well, you know, you know what, man, I, I think that is one of the drivers of this decision is giving away. Because when you allow people to just use their a la car, eat all all you can eat, you know, license in another tool, you being anthropic can't control how that API gets used.
Mm-hmm. So if I'm in the anthropic front ends, I'm using their model router, for example, to select which model to run against whatever task i I give it. So if KU is gonna save them a lot of money, that's what you And Yeah, I, yeah, I get that.
Of course, OpenAI immediately responded and say, Hey, we don't have such limitations. Come on over the water's fine. Is it?
I I, I, I was, I was looking to see, you know, because Codex is open source, okay. Um, but I don't see an easy harness to bring in external models like we have in, in other tooling packages. Even Claude, it's, uh, you know, Claude code itself and, and Gemini and others are semi open.
Like Gemini is open source, but it's not an open harness. And it's the same with Codex, right? Codex.
Um, and, and that's a big difference when you're talking about your tools accessing the model versus their tools, accessing their own models. So I guess bring your own AI isn't quite totally a hundred percent. Just bring your own ai, whether that's models or tools, our limita, you know, some limitation Reply, Some, some, some assembly required.
Yeah. Well, I mean, you could still use an API key, and that's, that's how a lot of people do that. But you don't get the same benefits that you do in using an OAuth just log in methodology for that, for that subscription, that unlimited subscription.
So, you know, it's not that they're turning things off entirely, it's just that they are tightening the constraints around how you use their licensing programs. Um, you know, for better or worse, I guess if, you know, and we've seen this many times with lost leaders, have we not Mitch, where oh, companies will, will, you know, we're, we're in the, and the, the best one, the fav, my favorite one is, um, we're in a research phase, therefore this is free. And what that means is we're we're going to harvest every single interaction you have to better train our models, uh, to, to, you know, later on monetize, you know, o Open Code does this with their Zen, um, API or sorry, model, uh, service itself wherein they have, uh, an proprietary model called Pickle, big Pickle.
Uh, and that's totally free. You can use it all day long. Uh, but you know, you're, you're giving it everything that you're, you're asking it to do Well and often, um, you know, the, they're feature limited or the previous generation is free.
The newest thing you have to pay for. Uh, I think the big thing here was you could, like you said, you could still access Claude, the models. You just have to pay the API token price, which can rack up, you can rack up some big dollars pretty quick, you know, aren't careful about Yeah.
Especially with Mr. Wiggins at the helm. Well, so, so ready to talk about, about Ralph.
Yeah. I mean, okay, if we're talking about Gemini CLI talking about open code, talking about even anti-gravity and Zed with the, the sidebar, uh, a any of these frontend COIs that enable age agentic development are under the hood, basically just a, a four loop with, you know, an a break, an exit clause in there upon success. And this idea that, that we're, you know, chuckling about is, is, um, a, a methodology based upon a, a Simpsons character that, uh, was, was very helpful in that he was constantly, you know, screaming, I'm being helpful, I'm being helpful.
Um, and it, it, it's sort of a, well, okay, if we, if we take this seriously and we apply that to Agentic development, and we, we just force the model to, to keep chewing on the problem that it has, instead of, uh, either refusing to comply, which happens, or failing and stopping, or early stopping or getting lost, which also happens, then uh, we, we can actually get some good code out of it. Uh, but as you, you mentioned, uh, and so, so rightly so, is that, um, that could be quite expensive and might be running for quite a long time. Hence everyone getting a little upset on Friday when Ralph refused was, was, you know, found dead in the street.
Yeah. It's actually in the, uh, in the Claude Library, if you Yeah. In the Claude Library, you can, you can access this routine.
So what, what I find fascinating about this, I, I think it's Jeff Huntley, who was the person who coined Yeah. Uh, created this, he called it a, a core loop originally, and it was a bash script, which basically essentially did the same thing without ai, but now, now it's with ai. Um, but what I really find fascinating about it, it gets around several problems.
One is this, this end state completion. How many times have we done a prompt and it says, oh, I'm done. Here you go, here's your answer.
You're like, yeah, I said there were five things and you did too. Or, you know, whatever. And it, and it likes to stop early and claim success.
Um, so, so this idea of having an end state that you defined, and then that's what keeps the, the core loop keep going until it actually does satisfy whatever the end condition is. But the other thing that goes along with it is every iteration, you know, we have, we have things like context window issues, right. And mirror issues.
Yeah. Oh God. Yeah.
Yeah. And we want to do long running agents. You gotta solve that, those problems.
So one of ways you can kind of get around it, I dunno if it's solving it, but every loop can be another session, another instance. So you're, you, you're iterating and you're not, you know, you're not flooding the zone of your context window. Um, yeah, nice analogy.
At some point it floods over the window. It does. Yeah.
And that's, that context stuffing is not the answer. And, you know, just, do you remember when meta released their 4 billion, you know, um, token context window model? Or was it 10?
Oh God, it, was it even more than that? Sorry. 5, I think at the time.
And, uh, you know, you can't just take that for granted. As, as you and I have talked about, there is this, you know, u shape, you know, attention mm-hmm. Deficit within that context window to begin with.
So, you know, what you're talking about with this, this Wiggins technique is, is, uh, I think an important sort of point that we should, you know, we should be talking about. And so I'm kind of glad that it's bringing that to light and, and that is proper use of, of the context window. And, um, one of the predictions that, that I have for this year is, uh, this sort of emphasis on, um, optimizing that memory system for models mm-hmm.
And using a number of techniques intertwined, like semantic caching, for example, where you're not trying to save the, the entire history. You're just trying to, to save the meaning of it and reference that not the whole thing. Yeah.
Because you have, you know, anytime that you inject something into early into the process, it can carry that through, you know, it may have gone down a wrong path, and not, even though you're told that that's not the right thing, it keeps some of that going. Right. You, you're like, Hey, this isn't right to relearn, To fail every time.
Yes, exactly. Um, so it, it's, it's an interesting concept. One, one of my predictions too, um, for 2026 is the emergence of the new development part paradigm of how we're creating software, uh, I think, I think is emerging this year and will, not that it would be codified and finalized by the end of the year, but I think we're gonna be talking well beyond vibe coding and just AI powered or AI native type coding.
There's a lot of these things are, are being invented and learned as as we go, of course, well, as, as the models are, the tools are changing themselves. But we'll see more things like control planes and guard guardrails and things like that being a serious part of not only the architecture, but how you architect it. And, uh, my thought is that, you know, we're, we're going from software development to software engineering, and that's because that's what this upper level thing of not writing all the code, but directing the code and reviewing and assigning work and deciding how, architecting how things get built.
And Wiggins is a great, great example of that, you know, in innovation somebody creates that gets around an architectural Limitation. Technical Limitation. Yeah.
You know, it's, it's funny, um, I, I think was thinking about all of these layers of abstraction that, that we're gaining with generative AI in, and, and I, I don't know where I even heard it, but there was this quote about every layer of abstraction is a bet on the, that in the future, at some point, you won't need to understand what's happening beneath that layer. That's A terrifying thing to think about. Yeah.
Yeah. Well, maybe at some point if you wait long enough, it's true. But I'm sure there are many.
Well, because you have another layer that You just forget the third layer under the second layer. Under the first layer. Yep.
Good point. You know, it's, it's interesting. Um, it, it's just such a fun ride to be part of this whole recreation and how we're building software and, uh, yeah.
Getting to experiment with it. You know, you and I aren't living in code every day. You're, you're doing a lot of projects too there, um, with our signal work, so, which has been fantastic.
Done a really fantastic job of that. So it's, it's, it's good. You're, you're able to keep your hands in it.
Me, I get to dabble in a lot of things and do that without having the commitment of a project. Yes. The e evil scientist, yes.
You're able to build that tower with hoist the, the sail and gather electricity from the storm. I'm the mad scientist. Exactly.
Exactly. You're like, I gotta ship product. Uh, yeah.
Right. And, and does, is that is a bit of a conflict, is it not in, in our industry where you have companies saying that, you know, the way we're going to measure success is how many vibe coded lines you've generated in this mm-hmm. Past week.
And, you know, forget the fact, and this goes to the whole, you know, technical debt thing we're talking about with betting on abstraction layers, but forgetting that just the fact that, you know, developers can't take the time to actually think about what they're doing. Instead, they're just waiting on the prompt to come back with the solution that they're trying to solve. And that's where they're spending their time, is formulating their intent and their question and not musing about, well, maybe there's a better way to do this.
And instead they're using AI to chase the solution. I'm not saying that's wrong, but I, but I do feel like we lose something in that. And if all we're doing is, is chasing these, I'm not saying arbitrary, but they're arbitrary measures mm-hmm.
Of, of value and quality. Well, and, and that seems to be a distinction, quality of some developers, you know, it, it's not a job, it's a lifestyle. It's a, yeah.
It's really part of their, their psyche. They're being, it's really enjoy, enjoy it that much. Oftentimes those are the folks that are, you know, you can't not work because when you work, you're playing, not working, you're playing with, with the same technologies or different ones.
That's where a lot of those innovation and that innovation time comes from, which is great. It's great that people that are so passionate about it. Yeah.
Like, like we were joking earlier on with, you know, let's just, they'll just make a new language if you p**s them off. Uh, the reason why I thought of that was, um, thinking about Mr. Mr.
Pike at Google, who loathed all the semicolons. So much so that he developed a, a programming language wherein the compiler added them in for you later. So you didn't have to type them or look at them.
I can't remember. It was Jeffrey or somebody else. Um, use, use the core loop, the, the Ralph Loop to telling it to create a new programming language where all the primitives are slang from gen gen, gen ZI guess it's, Oh, dear Lord.
Yeah. Uh, that, that exists. Um, uh, we'll have to look this up.
Um, but if anyone that's let's listening, you know what we're talking about, please put it in the comments. 'cause I, it's called curse. I curse.
That's what it's, yes. Okay. Yeah.
Yeah. I just remembered what it was. Fantastic.
That's innovation. Yes. Yeah.
That's, that's, uh, that's, that's a subscription where you to pay it for all the tokens is what that is. Well, unless, unless you just don't care. You already know Care.
Yeah. You work at, you work at Anthropic. Well, I think we may have done enough d damage on this subject.
Um, let's move on to our closing segment. It's time for Yes, the drop. Alright.
Um, I think I went first, last time. You wanna jump in with your, What's on your mind? Sure.
Absolutely. I, you know, because, because I, I think very limited scope of things. Uh, my, the thing that's on my mind is related to today's topic, and that is that, uh, yesterday, uh, today's Tuesday, um, and yesterday, uh, anthropic dropped, um, a new tool, uh, a research tool that's free for use because, you know, they're helping to, to build it out called Cowork.
And Cowork works within their, uh, proprietary application, um, on Mac, I think initially, and eventually on their other platforms they support. But basically what it, what it does is take the note, this notion that many of us have really glommed onto with CLI tools, um, uh, to basically use generative AI as a backend to, you know, do things that we normally would have to do either in the file system or, you know, typing it out in ACL I, um, sorry, in a file manager or on the cli. Mm-hmm.
And, you know, there's no limit to what you can do with that, honestly, because it is, it is the core of the computing experience. Is it not, you know, the reason why we're all sitting right now at a computer is that on that computer, we, we have information that we can process, uh, and do things with, and this cowork is, is really built not for Claude code developers, so per se, but, but for business users and, you know, and home users and any user who wants to do things with their computer that go beyond, um, and I'm not pointing fingers here, but there are some implementations wherein if you ask the, the operating system to help you do something, it'll basically say, okay, let's do this together. Open up your file manager and click on the third link down from the file pull down menu.
That is not automation. That is not what we want. I, I, I, you know, I would imagine that we will see more of this as we move forward and especially, you know, to the topic we were talking about with creating these sort of, um, you know, very controlled walled gardens of, of ownership of the user experience itself.
And that's what we're seeing Anthropic do here. Well, excellent. You know, I was excited to hear about that too.
It's kinda like skills, you know, another capability that was introduced to, you know, here's a different way of, of kind of feeding content in and maintaining that, that content, uh, across sessions. Um, my drop, my, my focus right now is just getting ready. It, it won't be, I don't think it's today, but probably next day or two, we're releasing the first half, 20, 26 of the software lifecycle engineering buyer decision maker data.
So we completed that survey at the end of the year, and that data's ready. We just got put then polishing final touches on it into the intelligence platform. So I'll be talking a lot about the data.
Just to hint, hint, one of the kind of really interesting things is AI shot up and has now surpassed even security in the top of the list of where people are Advancing that Shocking their budgets. Guess what That is shocking. Security always tops.
Yeah, exactly. Yeah. So security followed by cloud, followed by, you know, the, the typical things that we have.
So people are investing in it and, uh, counting on making, counting on it, doing some interesting things for us. So we'll have plenty to talk about, Brad. I'm not worried about Yeah.
Just the picking, the choosing is the hard parts, That's for sure. That's for sure. And, and you know, we're imagining you do the same thing, meeting with, uh, both clients and also people who, uh, that we follow and just kind of for the, here's what were happening for the year, here's some of the plans we have that they have, et cetera.
So for any of our practices, Brad, mine or the others, uh, anybody listening, reach out to us. If we haven't talked to you yet, we're glad to sit down and talk about both what's happening in our world and what's happening in your world, so we can do that. Yeah.
Exchange of information is an insight is one of the, the best things that we humans can engage in. So we welcome that for sure. It's, it's fun.
Alrighty, well thank you everybody for listening, watching this episode of Agents of Deb. We hoped you enjoyed a little, uh, Ralph Wiggins conversation while talking about, uh, core Loops and Ralph Loops and also what's happening in, uh, the competitive world of models and development tools and all of that good stuff. So thank you for listening.
Please follow, tell your friends about the, the we're getting stats, people are joining. It's, uh, it's really good. Thank you all.
They're coming on board listening and we appreciate it very much. And send us, send us an email if you have a question or a suggestion or, that was really great, that was really dumb, or why don't you talk about this, or what about that. We'd love to hear from you.
You can reach us at agents of dev at futurum group com. On behalf of Brad and myself, thanks for joining. We we'll see you on the next episode.
Stay tuned next week. This is Agent Dev. I'm in position copy dev.