Techstrong TV July 9, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everybody. Are you confused about tariffs? Join the club.
You're watching Textron Gang. We'll be back in a minute. Hey folks, welcome to the Textron Gang for today.
I'm Mike Ard, your host. Joining me today is Dan O'Brien, who's president and COO of the FU Group, and Chris Blas, and also new member Kate Re. She's been on the show a couple of times now, but if we haven't caught a couple episodes.
Key is a security expert and does a lot of work in app dev, so, you know, plays both sides of the ball as they say. Folks, welcome to the show. We're gonna have a little chat up early here now about what's going on with all these tariffs, because if you're like me, I'm having a hard time, frankly, keeping score.
Um, lately we've now seen that there's gonna be terrorists, maybe going into South Korea and Japan, but then we're waiting to see what happens with Europe. And it looks like the terrorists themselves were delayed. Dan, a lot of folks in it right now are trying to figure out their budgets for the coming year, and it's July and a lot of them are ending their fourth quarter coming up at, um, I think it would be September-ish.
It's very hard to plan in this environment, but what's your take on what's going on here and what should it folks be thinking about? Yeah, thanks Mike. Uh, you know, not sure we'll figure it out here today, but, uh, hopefully we can shed a little bit of light on kind of what's going on.
Listen, I, I think the big theme is, you know, negotiations will continue until tariffs improve, right? You know, that's, that's kinda, um, you know, the, the path we're headed down still, um, you know, deals in place with Vietnam and the uk, bit of a partial deal with China and really just still try to work it out with the rest of the world. Um, you know, kind of under the, under the microscope more recently, you know, seems to be Japan and South Korea.
And obviously, uh, you know, of major concern to the tech industry given the prominence of firms like Samsung and South Korea and Sony and Tokyo Electron and many others in Japan. Um, you know, disruption and, you know, uncertainty in the supply chain. Uh, not a good thing for anybody.
Um, really hard for business planning, really hard in terms of understanding, you know, where pricing may come in. Um, and so, you know, I think we're all still trying to figure out where this goes. Um, you know, it feels like we've kind of had this July 9th date out there for a while.
That's tomorrow for those checking the calendar. Um, seems like we're gonna push that to August 1st in a lot of cases. So, uh, a lot of, a lot of tough rhetoric out there.
Not a lot of progress. Um, and, you know, really, I think a lot still up in the air, but, uh, you know, South Korea and Japan most recently under the gun and, you know, also a little bit of iron towards the, the bricks countries, right? And, you know, kind of the extended tail that's associated with them, um, as they added a lot of countries last year.
Um, you know, the, the targets keep shifting, but, uh, not a lot of progress being made negotiations continue, It seems to me too, with BrickX, and you brought that up, but the c in bricks stands for China, and I thought we had a partial deal, and yet now we're threatening anybody who kind of is associated with bricks, and it's just a little more confusing than ever. Well said. Yeah.
Uh, maybe that's the partial part of the partial deal. Um, but, uh, it's an, it's an interesting collection of countries for sure. Obviously you've got Iran in there with, uh, you know, the countries that were at in more recently, um, South Africa, you know, uh, Ethiopia, many others.
Um, you know, definitely, uh, a a bit of a tough group to, to negotiate with for the United States at this point in time. Chris, here's my question to you, and you've worked in cybersecurity for years, but, um, do I pay attention to any of this stuff or do I just ignore it and clan and kind of, this is just some sort of black swan event that may or may not happen, but I kind of just can't plan for it, so I must ignore it. Well, you, you can plan for anything, right?
You know, and, and as you know, I've, you know, here, you know, I've, I've discussed enough this, you know, over the years, but I've worked all over the world, and you can plan this in Yemen, you can plan this in Columbia, which is much more stable, but it's not, you know, traditionally as stable as a, a first world country. And you just have to understand the dynamics, you know, and, and this, you know, the narrative is the hero's return, you know, dis a story, right? You know, we're coming back and, you know, the homeland has been overrun.
So every day and every week and every month, there has to be a story of rooting out the, the traders. And this, it sounds a little silly on a, on a global economic or a national economic, uh, level, but this is an example of it, right? There's 90, 90 deals in 90 days, or no deals in a hundred days with two deals in three days.
It doesn't matter, you know, if it's inside the narrative of the hero's return, then every morning when we wake up, there's a hero story coming to root out the whatever. So, and again, you can plan for security and operations in, in more torn countries, you know, in the us you know, unfortunately is not that at this point, but narratively it kind of is. You know, you're planning operations and, and budgeting assume that there may be some hero return story next spring where tariffs grow up 700% to on the left-handed countries that were mean to us last week.
I, I, I love your analogy 'cause part of my soul says that this is, you know, a, a fictional story here designed to create those heroes. And if I look at the math around what the existing deals are, they haven't really moved the needle on the tariffs one way or the other, very much. So, Kate, should I just assume that the tariffs are gonna be relatively stable, give or take a couple of percentage points and proceed Along?
We really don't have a choice, right? Other than to proceed, because if you don't, if we just stop, what happens then, right? So we have to move forward with, with the, the littlest that we can move forward with.
We don't have a choice. In other words, it's concerning, right? In that sometimes I wonder, are we gonna negotiate ourselves out of everything and we're gonna be left alone just standing and being like, because nobody's gonna wanna play with us.
I mean, I wouldn't wanna play with us. Like if you were, if every day I woke up to a, a different strategy, how is that the strategy? You know, like, and that's what I feel like is we're expecting globally.
Like literally there's like a new strategy every day. And how do we, as a company, I couldn't imagine trying to make a strategy with a new strategy every day like that in itself doesn't even make sense. So how do we get partners and solidify deals in what tomorrow may a country that is going to get hit with a very high tariff, you know, I, I being inside the security, I really, I don't know why I didn't like the term, uh, resilience.
Um, but gosh, do we not need resilience right now? Do we not need to have this type of, um, strategy there? Okay, maybe I can't do, um, a deal with this country and I have to shift really quick.
We maybe have multiple areas where we can take from, but you know, that's, that's hard to manage, right? So, You know, this, this, this is a, this is a new show in the tech world and so forth. And, and you know, I, I think a lot of people have opinions on this, and I certainly have mine.
I'll be happy to talk about them here, however, right? You know, it's, as a security person, I'm always coming into environments and saying, alright, I know you stated what you want. I need to tell you what the reality is.
You know, here's what is on the table for you as an organization, as a company, as a person, whatever. It's, and I, I find, you know, I look, I'm an American citizen, born and raised. I live in Canada.
My family's Canadian. I've traveled the whole world, and it pains me to say this, but this is the US us right now. You know, my Andrew said, you know, when someone tells you who they are, believe it, right?
The administration right now includes people like Steven Miller who has stated he'd like to see a US population of a hundred million. And we have an administration that that very specifically wants to have zero trade deficit with everything. And that's not a global trade system.
So it's an isolationist world, isolationist country where you can't really realistically do long-term business as an American company with international companies. 'cause the conditions absolutely will change, and they probably won't change in a positive way. So if you put yourself in that world and try to plan around that, it may not, uh, come out with a lot of good results, but it's the world you need to be in, I think.
Well, as Mike said, though, the deals we're seeing really haven't changed that much from the prior reality. And I think that, you know, the market has certainly written off kind of the anchoring strategy to these negotiations, right? We've kind of set the bar so far, the extreme, um, that kind of, nobody believes that's actually gonna hold for the long term, right?
That's, that's largely how kind of the world's behaving. Uh, I also wonder, you know, how much of what we're seeing is kind of the full story of what's going on, right? I mean, we're talking about tariffs, but it feels like there is a broader kind of resetting of the global order and the relationships we have, uh, across a lot of different vectors beyond tariffs that's kind of happening here as well.
So, uh, I don't know. I I, I take a step back from kind of the daily news flow and, you know, the confusion we're all kinda wrestling with in terms of the daily narrative. And, you know, I kind of, kind of say, I think we've anchored really hard.
I think the market's discounted that the reality of what we've actually seen come through is actually pretty pragmatic and not all that different than prior. Uh, but also it feels like there's something bigger at play beyond just tariffs here. Dan, I think, sorry, Dan, I think also IT leaders need to get in front of this a little bit because there's a history that says, you know, the amount of money allocated to it is usually a percentage of sales.
And, but, uh, if you keep thinking in those terms, you won't realize that how dependent upon the business is now on it. And so maybe the budget for it is actually larger, especially when you count in all the folks who are spending money in given departments. But is it time to have a more realistic conversation about just how strategic it is to businesses?
I think it is, Mike. I mean, you know, it, technology is the source of competitive advantage in, you know, almost every industry now. Um, so, you know, I do think a, you know, a slowly increasing, you know, kind of IT budget is a percentage of sales, particularly as we enter the AI era year, that's probably the reality for the companies that win in the long term.
Uh, you can resist it in the short term. I'm not sure that's gonna lead to more competitive advantage in the long term, though. And I do agree, and, and Chris, I do like, you know, talking about level setting expectations, and then that is right, and something that has to be done.
And I think, you know, to Dan's point, definitely AI could, you know, as much as, you know, we fight against this, but we definitely have to incorporate that into our strategy. Yeah. Listen, though, all, all the levers change, right?
You know, if it goes up, well, RD is, the percentage of sales may go down because we're getting greater developer efficiency with coding tools, right? You know, GNA sales may go down as we're automating a lot of the back office, right? So, you know, I think everybody's afraid of ticking it up too far.
But if you've got the offsets and other parts of the organization, I mean, I, I think Cloud did this really well, right? Cloud made everybody kinda understand the financial model of we're gonna shift CapEx to opex. I think with ai, you're really talking about shifting, you know, G and a and r and d potentially, you know, more into the, the operational tech spend.
And, and that may be a fine reality, but, you know, without the offset, I think it's a tough conversation for people to stomach. Well, I just wanna loop back with the PO with a more positive note because, you know, I I, I, I think I laid a lot of gloom there. However, you know, you'll find out if you're a first world country person, you go to a third world country, that business actually doesn't stop, right?
And I think what American companies need to get in is, is, you know, their minds is the, you know, buffer a lot of variability. I think you too are right. The tariffs are a lot of annoyance.
Whatever they are now is probably about the same, but don't be surprised. But they suddenly spike up 7000% in your area, but you'll, you survive a lot of crazy things as businesses, right? Just don't fool yourself.
One another way to look at this, to Dan's point, there are top lines and bottom lines. And if the top line is gonna suffer, there's gonna be a lot more focus on making the bottom line better. And that's where it folks can shine.
So I'm just saying maybe now's a good time to get in front of all the whole thing, right? Right. Folks won't be back in a minute to talk about our next topic.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techstrong Group. Hey folks, we're back. And yet there's been another merger in it.
It seems like there's one every other day these days, but this latest one seems to really speak to the heart of what's going on with AI and data centers. Core Weave is buying outfit, coal core Scientific for, you know, 9 billion in stock. And, you know, that seems like chump change these days in the land of ai.
But Kate, you've been dealing with this for a long time and you've seen these mergers and acquisitions. It, are we at some level of scale now? That seems a little bit on the mind boggling side.
Definitely. Um, I think overall, uh, if we look at what is happening, um, from a, from one perspective, it's the idea that, um, you know, you're looking at core infrastructure, right? Um, this acquisition will be, um, you know, will help I think overall on operational control and, um, will be very important going forward.
Um, you know, reducing the dependency on third party, um, colocation, improving financing, financing, flexibility, all that all becomes really important. And we saw it, right? Uh, then you started doing this with Cloud.
Now with this, yes. Dan, you've been an analyst for a long time. What's your take on this deal?
And are we at some sort of level of frenzy for m and a or what's, what's your feel here? I I think this deal makes a lot of sense, right? I mean, core Weave is really, you know, grown the way they have by making GPUs really accessible and really easy to use for developers, right?
Like the software layer they've put on top of the kind of core GPU access that they provide, you know, through their NVIDIA partnership, that's really where they've kind of differentiated and, and really become kind of the neo cloud of choice in the market. Um, core scientific brings kind of the, the raw data center infrastructure piece, right? The power, you know, kind of the, the, the site, you know, site, facility management, all of that.
Um, I think this is just a classic vertical integration, uh, play. Um, makes a ton of sense to me in terms of the synergy of the two businesses. I also think you gotta, you gotta love the deal, right?
This is a nine, $9 billion all stack deal, all stock deal that gets the amount of $10 billion in future, um, kind of, you know, commitments and obligations on data center leasing fees. 6 in, in assets. So, you know, for, for nothing they've, you know, reduced their future liabilities on cash materially.
Um, added, you know, I I think a really synergistic, um, partner in the business and, um, you know, picked up a, a bunch of assets which will, you know, carry some pretty solid benefit, uh, balance sheet, um, balance sheet benefits to 'em. So I think this is a lot to like this deal. This one's been long rumored, um, at least for a few weeks.
This one's been kicking around. So, you know, where there was smoke, there was fire on this one. But, uh, I think it makes a lot of sense.
I think, Chris, we've talked on this show many times about the fact that we're building out more data center capacity and AI is driving that, but the flip side of that conversation is we don't have enough capacity right now, which is kind of putting everything in a premium. So are we gonna see this wave of consolidation? 'cause the math would suggest that supply and demand is gonna create an, an imbalance in the force, as they say.
Well, let, let me speak to, uh, well, well, the, the, the supply part, you know, I guess the demand as well. But you know, we've, you know, I've got a lot of opinions about how we're doing and what we call AI right now, and I think it's wonderful. It's fantastic, it's transformative, and we're doing it.
Lemme just, just to keep it simple, all wrong, all, all of it, right? And the fact that we, uh, on a, on a, on a DHS call yesterday, uh, interesting, uh, conversation about this. And, uh, and one of the points I was trying to make there is, is we're trying to take, you know, like this complex semantic engines and get them to do math, right?
You know, to be clear, AI doesn't have any idea what 42 is. 1% of the effort. And we're doing that because it just works.
But it's such an incredibly brute force approach that we literally have, you know, national global grid issues and energy supply issues because we're just trying in, in the last 36 months, you know, this is not, you know, long-term planning. This is a phenomenon that has rushed forward. And we want these monolithic individual models, each of them using enough power to run a small town for a year to make us a picture of a cat.
And, you know, how enthusiastic I am about the technology. But I think the next step is, you know, for all of, I have biases in this, obviously that distributed civic AI sort of approaches rather than in, you know, isolated, monolithic, massive models. So I, I agree with you, Dan, I think logistically and, and, and corporate and financially it makes sense, you know, it is yet another, you know, national, you know, nationalist is isolationist approach, but I don't think is wonderful.
But more than that's just a, it is an example of, you know, of the, uh, you know, build a, a battleship and sail it up a creek type of approach that we're, that we have with ai. I love your examples, Chris. I I mean, they're, they're really, they're right on.
While we see this problem and how we attack the problem is, is very interesting. So we went and, you know, this was definitely a major issue in how do we, um, do this, you know, basically this consolidation. And, um, I, I love the analogy is it's exactly what's happening.
You know, we build the battleship and, you know, Yeah, we, we've just started just, just in recent days started now analyzing this goes, 'cause for our, as a company, we're taking a different approach and I'm willing to, to, to find out that we're wrong in this one. But I generally think that we can reduce electricity usage and get better benefits out of what we're calling ai, uh, reduce power usage by 90 to 99, 9%. Totally agree, Chris.
I mean, ultimately a different architecture is needed, right? You know, So to that point, how hard will it be to make that shift? Because, um, historically, Kate, let's start with you on this.
You do software, but, um, you know, we start out with, you know, let's just build something and hope it works, and then we consume all the resources and then we spend a lot of time figuring out how to optimize it for the next several years. And I feel that's kind of where we are with AI and maybe the hardware folks are overestimating how much data center capacity we're gonna need. Absolutely.
Uh, we are, you know, building the plane while it's flying, right? That analogy that we've used forever. And that's, I agree that that's what's, you know, happening here as, as well.
I, I think once we get, I, I don't feel that we strategize well and we are still a very re we are so reactive. It is concerning how reactive we are. I think if, you know, if we were just to sit back for a moment and to really think about how we wanna move forward, but we rush to build everything, and then I, yeah, I think we're gonna have a bunch of these, you know, huge data centers that aren't in use, quite frankly.
I think, I think if anything, AI will actually, if, you know, again, you know, what do we call AI and what, what our, you know, machine learning and everything. But I really think that there's so much potential there that it could actually minimize this footprint that we're building furiously. See, I'm more bullish there.
I mean, I come back to the deep sea moment and that, you know, that phrase Jevons paradox that we all came to know through that, which was basically, you know, as the cost of AI comes down, we're gonna have more ai. I mean, think about all the use cases for AI where the cost of training, the cost of inference today just doesn't justify the value. If we can bring the cost curve down, the number of use cases continues to explode.
Um, so I tend to be pretty polish on it. But, you know, I do think, you know, we are getting these architectural changes, right? I mean, look at the big innovation in NVIDIA's latest generation of Blackwell, right?
It's the move to rack scale computing, which, you know, that's a nice term we use around ai. I think historically we would've called that system level design, right? You know, we've moved from making a chip and outsourcing everything downstream of that to really starting to build this, you know, into a, you know, a, a system level thinking exercise around all the componentry that needs to come together to make this scale.
Um, and you know, I think Jensen has kind of told us this, right? I mean, he's basically said we're improving generation to generation to the degree to which we're gonna obsolete our prior generation when we introduce a new generation, right? Which certainly causes problems for somebody like Coral Reef, uh, to call back to our earlier topic.
'cause they're, you know, spreading that depreciation over six years. Um, and I think, you know, Jenssen's telling you it's more like a one year depreciation cycle. So, um, we'll let the accountants sort that, that discrepancy out.
But, uh, I think it's, it's really this move to system level design, you know, and the AMD's going there with their next gen, um, you know, MI series, uh, that rack scale computing, you know, kind of approach. And let me, lemme be really clear on this. I, in the last 90 days on this show, I have, I have converted, I have got religion.
I not only, you know, believe in all this technology. There's absolutely no going back. Um, world War accelerating the future, however, right?
The, you know, and this is a per perfect form to do it because this is a, an artifact of words. We are talking to each other. We're sharing semantic structures, we're building our heads, saying it out loud, saying to each other, people of whom are watching.
And we're talking about artificial intelligence, which is to be clear, the worst acronym in the, in all of technology ever, right? It's been used and applied to literally everything from cogs and springs to anything. And what we're specifically talking about here is semantic, uh, systems, systems built on words and meanings.
That's what we're calling ai. And it's not artificial. It is literally semantic systems.
And is it intelligence? I frankly, I kind of think so, you know, certainly more than most though, even the standard model chat, GPT sort of thing is invisibly conversational, um, artifact. And as I've come and found out, find these advanced models, you evolve the system, uh, based on the technology today.
And if you can tell the difference between that and a person, good luck, um, and that, and we're to start it, but we did, we built it all in, in silos, and it doesn't make any sense. We put 'em in cages because everything we think about in sci-fi with artificial intelligence means that we had to build it in a cage in case it goes nuts. Um, and that's ironic because you build something outta words and feelings and put in a cage that acts weird, right?
We need to socialize them and connect them and make them age agentic and whatnot. And we're doing that now. And when you do, you find out, no, you don't need to stand up, you know, Einstein to screwing up a screw.
But sometimes you do, you know, we are building AI infrastructure now based on mostly small devices, raspberry PIs, normal computers. We're all talking to each other all the time doing various things. Yes, sometimes you need a GPU and you need somebody to talk up and be really cognitive.
But as you, you know, as, as I work with these systems, I, and discuss it back and forth with them, we shut down as humans. We don't think really well when we're doing cubicle tasks. Neither do they, you know, that doesn't require, you know, 3000 gigawatts.
That's a, that's a lot of the work we do as clockwork. Dan, here's the part I don't get. So GPUs existed long before AI existed, and then we got lucky, right?
When somebody discovered that GPUs are great at parallel processing and we can do jobs for ai, but there's still a lot of overhead in those GPUs that has nothing to do with ai. And we've seen the rise of these other AI accelerators from various folks. And I would argue that Nvidia is probably gonna have to create an AI accelerator obsolete.
Its GPUs and all those AI accelerators will be more efficient than the GPUs for AI workloads. And then maybe we won't need as much data center capacity, et cetera. So it's not just a software issue, I think it's a processor hardware conversation as well.
Or am I crazy? No, I, listen, I think it's both, Mike. I mean, you know, if you look at, uh, kinda what we forecasted futurum, you know, visit our futu intelligence platform, take a look at our XPU forecast.
Um, listen, this, this market is, is growing at an incredible rate. Um, not only is there room for a ton of GPUs, and I think we'll still see really dominance from the GPU on the training side of things, but, you know, these specialized AI accelerators from the likes of Broadcom and Marvell and, you know, the hyperscaler partners that they're working with, um, you know, number, number of other, you know, com companies out there that are innovating in this space. There, there's room for all of them.
Um, you know, I think we'll continue to see more specialization, more vertical integration. Um, but, you know, I think GPU ultimately will probably lose share of the market, but it doesn't mean they won't continue to grow at an incredible rate. But I do think some of these alternative architectures and, you know, some of these other approaches, particularly on the inference side, uh, they're viable.
Uh, they're, they're very much viable and, you know, potentially have better total cost of ownership. I mean, look at some of the, the data coming out of our, our Signal Labs, uh, groups on, you know, TCO around some of these, you know, solutions from an A MD and others. Um, there's a compelling case there.
I think, you know, what we've seen, you know, in the market leading up to now is this really this trend towards heterogeneous compute, right? Building, you know, a specific tech stack for a specific use case and a specific workload. And I think we'll continue to see more and more specialization, but general purpose GPUs probably still really the dominant force on the trading side for the time, time being and, you know, for, for SQL future.
All right, folks, we got a long way to go between now and then, but I would just close this segment out by noting never been against innovation 'cause you'll lose. We'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey, folks, we're gonna shift a little bit of gear here, but at least the one thing we will continue to be talking about is money, but we're talking about it in the context of cybersecurity.
The US Treasury is now sanctioning, I think it's called AZA Group, and they have something called a Bulletproof hosting service that they provide for folks who engage in ransomware and info stealers and drugs and all kinds of stuff. And Chris, I feel like the conversation around cybersecurity is finally changing. And it's not just about, you know, how, how many more firewalls we can put at the edge.
We seem to be going after the bad guys more directly. And I'm even gonna relate this back to a conversation I had recently where Cisco, where people are now manually tracking where the network traffic comes from, and they're cutting off access to the pipeline for some of these folks. And is the whole play around cybersecurity just getting better and smarter?
Finally, I, I, yeah, first thing I'm gonna do is give a shout out to Pete Herzog, who's out there doing the good work, you know, and sometimes you gotta shut things down and, uh, you can check on LinkedIn and, and see a, a post from him just, uh, today, the other day about this. And his short answer is yes, right? You know, that that's, you know, focusing mostly on cybersecurity for my entire career.
I, I'm, I I'm, now that I'm old, I'm appreciating the fact I've been saying all along saying, we're not, we don't suck as much as we think. We didn't do that bad in 99, we weren't that awful in 2007. We're not doing that bad now.
We've been building up structure for a long time now. Uh, and right here in the middle of the decade, I'll say what I said in 2020 to friends, mostly just to, uh, disturb 'em up. But also because I mean, it, you know, this is the last decade of cyber security.
You know what I mean? We're not gonna go on forever suddenly saying, oh, threat intelligence, we fraud. Oh, we know has anyone, no threat, no supply chain.
Oh my God, we never thought of supply chain. There is a finite number of major blocks of cybersecurity. They were all out line by the early pioneers, you know, before, you know, anybody on this screen, including myself, got involved.
And we're slowly working our way through them. And everything else we're talking about on shows like this, shows the path, you know, I am working on, we are working on, on, on A POC right now that will get a software bill material at 400 milliseconds to a aerospace rocket flight engineer af you know, from request to return across three steps in supply chain, because the systems were all there, the components that, you know, including the semantic systems all our time talking about to do that in the real world in real time. So things like, you know, going, you know, I, I, I, I like the Lone Ranger.
I like going after bad folks shutting me down. I'm a big fan of that. But the big problem with cyber security and more importantly, narrative integrity these days, is how hard it is to be a bad guy.
Cybersecurity has been weak enough, despite the fact that we've kept built the internet and kept it running, that anybody who really wants to can just be a malicious actor all day long and make money at it. And, and on the global scale, you know, on top of that is the narrative layer, which is being hacked for, for profit, you know, and, and control. So, but we're closing in on it, you know, we're getting better.
These signs are good signs. You know, just if you've looked up the Pete, uh, Herzog article by now, you notice that some official organizations aren't really, you know, you know, uh, public and private always following up on that, because we haven't always been there. But I believe we're getting there.
It's, it shouldn't be so easy to hide in the dark and do bad things in cybersecurity, especially not anymore. Kate, is there optimism in the world here, or is it, to Chris's point still too damn easy for the bad guys to be bad? It's still, um, very easy for the bad guys to be bad.
Uh, I think that we still don't have a great strategy in order to tackle this. Meaning that we've seen, we've seen these threats over and over again. We've seen the bad guys, um, the threat actors, bad threat actors get together and have, you know, $3,000 for this malware, 24 by seven support.
We've seen this, right? We've seen this forever. Do I, are we making a step in the right direction?
Yes, we are. Do we need to do it together collectively? We do.
We, we really, and that's something where I see, um, hope is that we're actually doing this together, Right? And let, let me, let me just, you know, just be clear. 'cause I, you know, I, I, I think, I don't think what we just, you know, I don't think shutting these people down does any good whatsoever, right?
I think it's a good thing to do. I think we're getting to the point where we won't have to do it all the time, but it's like, you know, look, the war on drugs, the US war on drugs, to be clear, all the money spent and all the drugs that addicted did do, you know, stop bad guys and criminals, but didn't stop any American from doing, getting and using all the drugs they want. You know, shutting down these, these, you know, cyber criminal organizations is good.
They're bad folks, but some of 'em will fill their spot until, to your point, okay, we have strategy and we, we coordinate it, or we have the tools in place where it's just not so bloody easy. And, and I, that's, that's where I think, you know, my optimism. Optimism is, I think we've been moving for, for a long time.
I think, again, everything we unfortunately call AI is going opportunities, you know, today and in the next couple of years to really make it hard to be a bad guy. So we're not having to try to just put them in jail and so they can get replaced by the next one. Dan, to Chris's point, and we've been just overly obsessed about tech and cybersecurity and not really considered the fundamental economics to change the equation.
And, and I don't know, are there things that we could do collectively as a, as policy? 'cause I know you follow policy in Washington, so, you know, I, I always feel like there's, there's somewhere of a disconnect in all these agencies running around, but nobody seems to actually say, what are we collectively doing together? Yeah.
Listen, I, I think the macro trend we're seeing in the cyberspace is that, you know, the, the value is really shifting from, you know, going after these individual bad actors to going after really kind of criminal enterprises and state sponsored bad actors, right? You know, the, the, the challenging part is that, you know, this is market forces at work. Like, unfortunately, you know, creating cyber crime is good business.
Um, people are making money doing it. And, you know, I think as you've gone away from more of the individual bad actor into more, you know, organized criminal syndicates, you know, you're opening up a lot more tools in terms of how we address this. It's not just a technology issue.
Now you've got, you know, uh, legal routes, you've got banking routes, you've got all of these different things you can be doing to kind of really circle in on the people who are doing this at scale and the people who are really doing it, um, at a level of disruption that goes far beyond any sort of individual bad actor, you know, kind, you know, bad actor, kind of the, you know, the, you know, the basement dwelling, you know, uh, you know, uh, identity steel or, uh, you know, that that's not really who we're focused in on so much anymore. Um, I think it's, it's getting, you know, getting harder for those folks. But, you know, still relatively easy.
I think the, the, the tone is really shifting to the organized crime side, the state bad actor side, and, and really, you know, leveraging tools beyond technology that go down much more of the kind of finance and legal, you know, routes in terms of how we address kind of the core issue here, Integrating, I'm sorry, Mike, but integrating geopolitical intelligence becomes part of the strategy, and that really needs to be seriously looked at. You know, we're not, regardless of how we try to be isolations, we're not, we, especially with cybersecurity, right? We all have to play together and actually share intelligence, which is the antithesis of how we think, right?
I, I feel we have not been brave from a company standpoint, from vertical standpoints where the attacks have now become cross vertical, uh, vertical industries. And yet we still hesitate to share. And I, I think it's important to, to, um, gather this intelligence and geopolitical intelligence in order to fight the latest threat.
Yeah, I mean, back to your po you know, point on policy, Mike, you know, I, I think we're, we're so much so focused on kind of the bad actor side here. You know, a lot of what we can do is, you know, sometimes the best cyber defense is an educated user, right? Like, what are we doing from a policy perspective to really teach digital fluencies, you know, early on in, in schools and academia, right?
I mean, that's, that's a valuable life skill for people to, you know, kind of graduate out of their education with is some level of digital fluency, uh, you know, best practices. You know, kind of being a, a smart consumer here, you know, can prevent a lot as well. Yeah.
I, I'm gonna, I'm gonna, uh, mirror Elon Musk here just just to show that, you know, uh, uh, politics is, and everything, you know, patents and all this, this, this, I try to understand everybody's position, but for, to be clear, for my entire career, I've helped people figure out their security. Well, personally, I secure very, very little in my life. Now, what I do secure is secure.
I actually taken care of it. I'm not trying to feel good about it. And the rest of it, I honestly believe that transparency is better, faster, cheaper, safer, more resilient, share everything you possibly can.
So you only have to worry about those last little bits. And you'll find that not only do you save a lot of money on security and a lot of time in your business, your operation, your life, whatever, it's get more done. But there's all sorts of advantages.
In case you said that, you know, if you don't share this sort of intelligence, if you think it's that important that nobody knows, you know this about that, then you're all alone. And, and our threat actors are not. So how are you, how is that gonna work out?
Um, so share it all. Are we need, To your point, we're also spending a lot of money securing data that's no longer valuable, but just 'cause we store it and we kind of keep it forever. But, um, Chris, you know, I look at this sometimes and having grown up in New York, every time there's a downturn in the economy, there's more people working for the mob.
Is that how that works out here in land of cybersecurity? And we see a global downturn that there'll be just more people watching ransomware kids because they're easily available, and is there a correlation between the global economy and cyber attacks? Or is that too simple a metric?
Well, that, that could be an opportunity. I was hoping to, to riff on what you said, Dan, right? You know, because I'll be clear, if you're a young Russian citizen living at home and you're, any good of the computers, get into hacking, the FSB will give you tools, they'll help you make money, and anytime you break into something that they want, you know, they'll, they'll, you know, give you a dasa or something, right?
That's just a better career plan than anything else. You know, the Russian economy has to offer you right now. That's the reality of it.
So yes, when, when we create these opportunities for there to be these economic benefits and someone else has the budget, yeah, they will pay you, you know, to be a nefarious hacker. That's just the way it's, and until we have systemic solutions to that, that's, it's a, it's a bi, it's a, it's a nutrient gradient. You know, things will grow there.
Also, you know, Kate, to, if I look elsewhere in the world in certain countries, it's now considered patriotic to go hack in other country systems, and that's part of their culture as well. And some of them are even funding their economy doing this stuff. So, uh, do we really understand the motivations of the bad guys?
You know, I think at the end of the day, the probably primary motive, even though, you know, um, I think it's still money. I, I think it's just little money, you know, how am I gonna survive? And, and while it's not that we don't have, you know, nation state sponsor the tax, but at the end of the day, I mean, we're, we're wrecking.
You are either wrecking you're making somebody's day really bad financially, or, you know, or even from a financial motive on the other side. I'm gonna do really well today because I've Yeah. Done some ransomware, you know?
So at the end of the day, I think it's more financially motivated than anything, even though, yeah, Dan, you know, we live in Boston, right? And I'm in New York, and last time I checked there was still mom families running things. It's just maybe not as much outta control as it was two decades ago.
And so my question is, will cybersecurity, cyber crime always be with us? It's just a matter of how much, you know, we can tolerate to what level? Well, I think, you know, throughout the history and society, crime has always been prevalent, right?
You know, we, cyber is just a new venue for it, right? We've created a digital world in addition to our physical world. Um, and, you know, crime has found its way there too.
So I, I continue to come back and, you know, Kate, us in on this, it's about the money. This is economics, this is market forces at work, right? Um, this is no longer something we can only solve with technology.
You know, we need a belt and suspenders approach. Technology plays a critical role. Um, but it's economic, it's policy driven.
Um, you know, it, it's gotta be addressed at all levels if we really wanna make a dent here. All right, folks. Hey, you heard it here, even today in New York, if viewers still walking down the street with your wallet in the back pocket, bad things are gonna happen.
So be smart out there. Hey guys, I wanna thank you all for being on the show and kinda sharing your thoughts and insights As usual. They were awesome.
And I wanna thank you all for watching the latest episode of Textron Gang, and please stay tuned for the lineup right behind us 'cause there's a lot of great, awesome content on Textron tv. We'll see you next. Hey everyone, welcome back here to Techstrong tv.
My next guest is Casey Rosenthal. If you've watch Text Drunk tv, you've seen Casey on here over the years, but he hasn't been on in a little bit, um, as he was playing in his yard or, or doing things, Working On my orchard, working on the orchid, the, the orchard. We're not tech drunk TV related.
Casey, um, first of all, welcome back to Tech Drunk tv. It's good to see you, My friend. Thanks.
Sounds great to be here. Likewise, Um, you know, give people a sense, we're gonna talk about High Beam in this new, this new role, but give people a sense of where you've been though. Uh, sure.
Yeah. So, um, uh, you know, as you know, my background is in, uh, high availability distributed systems. Um, for those who don't know me, I, I'm, I guess, considered the pioneer of chaos engineering.
I, I built the program at Netflix, wrote the book on it, started the conferences, kind of became known as the Chaos Engineering guy. Uh, so my career is focused on, you know, systems at scale and, and fault tolerance, reliability. Um, so I, I worked in some, uh, startups that were in that space, uh, the past few years.
Uh, I took on more of, uh, an executive role, uh, and I was on the board of a, a company, um, called Tri Fork. Um, for, for those in the audience who aren't familiar with Tri Fork, it's a, it's a large, uh, mostly consulting company. Um, I was on the board as we went public in, um, uh, in the Danish market and NASDAQ Copenhagen, uh, and they've got like 70 to 80 different business units that span, um, all, all of tech from, you know, they've got divisions that focus on iot, some that focus on digital health, um, uh, data centers.
Um, you know, they, they do the, the whole, the whole gamut. Uh, yeah. And so, you know, from the board position, I had insight into, um, the different teams and the different areas that, that, um, uh, were being invested in.
And I, I kind of saw a, a nugget and opportunity. Um, one of the, uh, companies that Tri Fork, uh, owns is, uh, Ang Solutions, the, the premier company for the programming language, Ang. And, uh, they have a division in the us uh, that has some fantastic customers that have that same problem, that, that kind of aligns with my background, huge scale and absolutely critical systems.
Um, you know, we're talking hospitals, financial networks, um, you know, telephone companies, you know, the kind of thing where, you know, if a, if a call goes down, you know, that that could be a nine one one call in somebody's life could be on the line, uh, or in a hospital, you know, that could be, uh, an EMR, an electronic medical record, uh, not getting to the ER on time, right? Like, you know, these systems can't fail even in the presence of the real world where, as we all know, computers break, networks stop working. Um, so we need to engineer ways around those kinds of issues that we know are gonna come up.
So we had a team that, that has a lot of experience in that kind of, uh, uh, business, uh, those kinds of solutions. And, uh, I saw it as a, an opportunity to spin out a, a new division just focused on that, delivering those kinds of solutions. Um, so we're calling it High Beam.
Uh, that's the, the new division, the new business. And, uh, yeah, I'm, I'm super excited about it. Very cool.
Hi, beam, by the way, is spelled H-I-B-E-A-M, all one word. And the H is capital, so is the B, right? Yep.
Um, Casey, the website. Hi, beam Dev. Okay, very cool.
I like the dev. Yeah. So JC, I look, it begs the question, it says interim CEO, not CEO.
Yeah, we'll, we'll see, uh, we'll see how it goes. Right now, my interest is, uh, in pulling the team together, uh, building, uh, alignment in, uh, in a go to market strategy and getting the business, uh, set up. Um, you know, I'm, I'm not, uh, I'm not closing the door, but, um, you know, we're also keeping options open If we find somebody who's, who's better suited, um, to, uh, continue the business or take it to the next level, uh, we'll consider that.
Uh, it's, it's also possible that, um, I'll get, uh, uh, uh, uh, I'll remain, um, uh, interested enough that I'll continue, we'll figure that out later. Right now, the, the really interesting part is this kind of magic, uh, space that we found where, hey, you know, it, the infrastructure's always breaking. AI is in, in increasing a lot of new pressures on, uh, on infrastructure, uh, in two ways.
And so businesses are, are, are having these problems, and we've got a team that, that can solve these problems. Excellent. Now is, is is high being primarily like Tri Fork, a consulting company where you come in and you help a customer design build out their own full tolerant height concurrency systems, strictly a, a consulting.
Uh, so we, we do have some products that we'll be releasing, uh, this year that are, are based on solutions that we've built, uh, as consultants. Uh, primarily our business is owning a solution for, uh, for a customer. So for example, an an EMR, um, uh, uh, pipeline, uh, system is something that we will come in and build for them and then, and then train them how to, how to operate it, or we'll stay on, you know, on as a, as a vendor to maintain it and to operate it.
I, I call these, I'm not sure if this is an industry term yet, it's not one yet, but I call these projects software switches. It's, it's basically a, a case where you've got, um, uh, critical data, uh, that's in motion, um, and usually with a high number, uh, of, of simultaneous connections. So, you know, we're, we're, we've got some, we share some architectural DNA with like WhatsApp in, in terms of like the, the programming languages and the tools and infrastructure that we use under, under the hood.
So it's, it's systems where, you know, massive number of users or IOT devices. And again, if something goes wrong with one of those messages, this system has to be able to automatically handle that recover and, um, you know, potentially find a, a redundant route to, to tra to, to route, uh, that message, uh, in the case that the, the original anticipated route fails. Um, and so it's, it's just this really interesting, um, uh, set of problems to have, um, that, uh, yeah, like I said, AI is, is kind of introducing two additional pressures here.
One is, uh, the, the pressure on infrastructure to grow to support AI use cases is just phenomenal. And, and the other is, uh, the, uh, increased speed with which people are deploying applications because AI allows them to generate, uh, code faster. Um, you, you can't like vibe code reliability into a system, at least not yet.
So, not yet, not yet, not today, not today. So you, you still need people with this kind of expertise to come in and, you know, set up a, a strong foundation so that, you know, the rest of your engineers can continue to, to make gains and, and pick up speed and, and feature velocity. Um, it still requires, you know, this is an area fault tolerance and high concurrency that still requires that human, uh, experience and creativity, uh, to, to get, uh, reliable solutions in place.
Um, so there's a lot of demand for this. There is, you know, so I first became aware of it, I, I, I wanna say it was maybe last fall, there was a show down in Atlanta, a high performance system, high performing computing conference, HPC, whatever. And, um, everyone, I didn't go to it, but everyone I I interviewed who went to it, came back all buzzed up, and all of a sudden, you know, high performance computing was sexy again.
And a lot of it, you're right, a lot of it is driven by ai, right? Yeah. All of a sudden, hardware got real sexy again, and data center build outs, not just at the hyperscaler cloud level, private data centers, AI data centers, all the, all these, you know, things that people are building and, and, you know, wherever this hardware, software is short to follow, right?
Yeah. And, um, and, and so, you know, this type of high performance systems, highly full tolerant, high concurrencies, they're, they're in vogue. And I think a lot of it is being driven by AI and the AI data center and, and that stuff, but I don't, is it a big boys game?
Do you know what I mean? Casey, is the bar of entry into these systems, into this kind of atmosphere so high that it's like, it's the hyperscalers and a couple of their friends, or do you see this coming downstream? No, it's, it's already downstream from the hyperscalers, certainly.
Um, and we see that in our, in our own customers. So, you know, one of the largest hospital networks, uh, is, is a customer. And you know, for them, they have, this is a real use case for them.
They have electronic medical records that they need routed between their hospitals in real time. If somebody shows up at, in an emergency room and they're not conscious, you know, they, the doctor can't interrogate them. They need on their computer access to their medical history right now.
Um, so, you know, the, and, and, you know, historically, you know, probably most of the software, it's probably safe to say most of the enterprise software in the country is written in Java. Um, and, uh, nothing wrong with that, uh, but the, the development patterns and, and, um, uh, the way that you, that a, a software engineer would typically write software isn't the same way that you would write software when you know that if it doesn't work, somebody's gonna potentially die. Right?
Um, so, so there's, there's, there's already, I I think the use cases have already moved downstream from the hyperscalers. I'll give you another example. I, you know, I was talking to, to somebody, uh, at Slack, uh, who, uh, we were discussing incident response management.
And, um, it was, uh, this was in the early days of Slack. It was, uh, kind of an eye-opening moment for them when they realized that they were critical infrastructure because of who is using Slack, right? There are companies out there who use Slack for like inner inner hospital communication or, uh, you know, inner, uh, uh, mission Critical, Mission critical communication for, again, stuff where, where, uh, lives are on the line.
And, um, you know, for from Slack's perspective, it's like, oh, we do messaging. If we have some, some downtime, like, you know, that that sucks, but we'll do our best to get it back online. And, and with an outage, they were hearing like, no, no, no.
Like, it can't go down. Like there's, you know, there's stuff that realize people die. Yes.
Um, yeah. Uh, trying not to put too fine a point on it, but that's what it comes down to. So like that, that's, you know, software ate the world and now our lives depend on it.
Um, and it's not just the hyperscalers. Uh, so yeah, this, this opportunity, I think is, is coming more and more to the forefront of what we all have to deal with in, in software. Yep.
So, Casey, is hide beam available to anyone in the world? Is it there a particular geography focus? What's the story?
Uh, well, I'm, I'm focusing our, uh, our go-to market here in the States, uh, for, for the launch, just because we've got so much interest here. Uh, and this is, this is, uh, where the energy is and where, frankly, where my network is. Uh, but Tri Fork is a global company.
Um, so, you know, we do have interest from, uh, the EU and, uh, and other regions. Um, so we're, we're not limited. Uh, but, uh, yeah, there's, there's, there's a lot of excitement here in the states.
Uh, so we'll, we'll start there. Yes, there is. Yeah.
You know, everybody's throwing around a hundred billion here, a hundred billion there to build out these data centers. Right. And I saw Oracle signed a $30 billion customer, uh, This week, but they won.
Say who the customer is. Well, we can guess. Yeah.
Um, good for them, right? Yeah. Which kind of triples their cloud business or something like that.
Right. It's a crazy number. I mean, and I mean, certainly we, we, you know, high performance is back.
Yeah. Yeah. I mean, the, the, you know, that's an example, like the use cases is that whoever that customer is, they're gonna have data, a lot of it that needs to move, and there's gonna be parts of that that are super critical.
Um, and, uh, again, it's even for the hyperscalers, it's not always a, a, a skillset that they've developed, uh, in-house. Um, and there's an advantage to be to, to viewing these kinds of systems across the industry. It gives you a different perspective on, you know, the patterns for high concurrency, uh, for example, that you, you know, you, you don't necessarily get working in just one problem space.
Agreed. Agreed. All Casey, we're about outta time.
I wanna wish you luck with the launch of High Beam, and again, you so much John. Again, that's high beam dev. Yep.
Excellent. And, um, I, I know it's gonna be a busy day for you and everything, but, you know, take a breath and before the leaves turn color, come back and keep us posted on what you're doing. Okay, will do.
Thank you so much, Alan. All right, my friend Casey Rosenthal, interim CEO of High Beam, a new division of Tri Fork Building, full tolerant and high concurrency systems for enterprise, enterprise clients around the world, but really here in the US right now, Casey. Thanks.
Good luck to you, Matt. Thanks, Alan. Alright.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. I'm your host, Mike Bazar. Today we're with Andrews Livic, who is CEO for a company called Focal Point.
And we're talking about, well, how AI is gonna be used in procurement. Andrews welcome to the show. Pleasure to be here.
Uh, Michael, how are you doing? I'm well, I'm well, there are clearly all kinds of manual toil, thankless tasks that have to do with procurement. So will AI kinda automate all of that?
And to what degree can we expect to see maybe that whole procurement process become, well, I don't want to say enjoyable, but you know, that's tedious. Well, I think we're already starting to see some impact of AI in procurement. So it started a couple years back.
Now we have large language models where consumers of procurement services can interact with procurement in a large language model manner to say, I need something from procurement. And the, and the large language model say, well, what do you need? Like, do you need services?
Do you need goods? Do you need it? Stuff like, whatever.
And they kind of chat them down to the, to the right path and, and, and get them in the door, so to speak, for self-service. And that's, that's been adopted quite heavily, certainly in the mid-market enterprise is getting there. And now we're starting to look at things that are, like you said, are, are just thankless tasks like in invoice reconciliation and entering in invoices and entering in contract information that typically gets done manual poorly and people fill in the least amount of information they can to get in the door.
And, um, so we're starting to see a lot of that as well. So I think we are, while the adoption is still nascent, the players are really coming to the fore now with great solutions. And I think the future is here today.
One of the things that has always kind of perplexed me about this whole rise of AI agents is how this is might actually play out in the real world. So in theory, as the procurement agent, I'm gonna create an AI agent that I might train to go buy things at the best price possible. That AI agent is likely to encounter AI agents created by a seller who's trying to sell something at the highest margin possible.
Will these two AI agents meet somewhere and negotiate, or will they just kind of like ground each other to a standstill? Well, I think if procurement agents are trained to be procurement people, they will ask more than one place. We will go to more than one place for, to sort of fulfill their needs to make sure that there is competition still.
So while the agents are kind of battling it out, I still believe that there will be you, the procurement will prevail, so to speak, where they will try to look at multiple places for the same stuff to ensure that they get the best value from money. But yeah, we, we, as procurement professionals, we have a lot of funders who are thinking about the fact that you have two bots going at it negotiating, uh, and, and trying to come up with, with the best solution. And, uh, it is a little funny to think about, but I think you're absolutely right.
I think there will be some of that. I think vendors will tend to maximize their revenue or maximize their, their margins. And procurement agents will try to do the opposite.
And, and, and I think it will be the tolerances that are built into both models, so they'll dictate where we actually end up. What does the procurement organization of the future look like then? Is it basically a, a a, a small number of humans trying to manage a army of AI agents, or how do you kind of envision all this playing out?
So what I've seen for some of our customers is they actually have the same amount of people that do more value added stuff. And the other interesting part I've seen is you have some, um, individual companies now that are assigning agents to be owned by procurement people. So they're responsible for the training and the execution and the outputs of these agents to try to maximize what they do.
And let's be honest, right? Like no one really wants to do invoice, invoice reconciliation, using a VLOOKUP in Excel like that is a tedious task. This isn't their add a lot of value, right?
And if you can get an agent to do 95% of that work, and you only manage exceptions, and even you can train an agent to do a lot of exception processing too. But if you, if you start figuring out that people can need to only work on the stuff that the AI agent can't solve, a lot of free time is gonna get spent are more value added stuff like thinking about strategy diversity and inclusion, carbon footprint reduction, all the other stuff that procurement has to worry about. Um, so I think I'm not, I'm not afraid that there will be no more procurement people doing procurement work anymore.
I think we're just doing a lot more value added stuff because procurement is being asked through so much more now than they were in the past. One of the other big concerns around procurement, of course, is anything to do with fraud. Um, will we see more fraud in the age of AI or maybe less fraud?
I think we'll see more fraud attempts for sure. Um, but I think ultimately companies that are proactive in this space will put the guardrails in place to, to make sure that they don't do the silly stuff that they're not supposed to do now anyway. And with the a with, with the, with the age of ai, I think a lot more spend will become more controlled because people could put purchase orders in place that gets approved and then you can't ex exceed that spend once a PO is exhausted.
So I think more attempts will happen, but I also think this, there's gonna be more controls put in place to ensure that fraud doesn't go out of control. Will the whole process become faster? And I'm asking the question because there's many folks who work in organizations who want to go buy something and then they go to the procurement department and they're told, you know, we should be able to sort that thing out in a matter of months.
And people are like, what? Well, I, I think what, what I will say is that I think procurement will be faster in guiding people to channels that can execute the tasks faster, right? So the biggest problem, no, not the biggest problem, but, so one of the problems folks have today is they don't know which of the 3000 or 10,000 suppliers that's already in the system that can meet their demands, meet their needs already, right?
And usually take months to onboard a new supplier, go through the supply due diligence, their risk assessment, those kinds of things. And what we've developed a focal point is sort of say, well, I need to buy a management consulting service from this supplier. We will say, well, that's a new supplier.
We can use one of the 10 that we have approved already, and that will speed up your process by, we'll cut it from three months to two weeks. Do you wanna use the one you have? Okay, yeah, let's do that then.
Right? So I think with more intelligence comes better decision making and I think in a better contracting as well. So I think that's gonna be the way for the future where you've tried to get folks to the right channel to use the right suppliers for the right things, and that will inherently speed up the process.
Do you think that a lot of the compliance work will get easier as well? Because I think one of the things that holds us up in procurement is that there are a few thousand regulations that people are trying to sort through. And, um, can that whole process become, uh, shall we say, less painful than it is today?
Yeah, for sure. I think we're seeing a lot of cool technology out there. So for example, reviewing a, a SOC two for a control environment, for example, we've seen solutions out there now where you can upload your SOC two and they will automatically suck down the answers to the 300 service criteria that soc two handles and say, all right, yeah, this meets our needs.
This doesn't meet our need, or whatever the case may be. So I see a lot more automation, not just of suppliers filling out, you know, assessments, but also how they get reviewed internally within the organizations as well. I still think people, you know, you have to keep a human in the loop.
That's the, the thing people say now, right? Uh, to make sure that your humans review it and make sure that everything is copacetic. But yeah, we've seen incredible advancements in how, how contracts are being renegotiated, how they can pull out terms and compare them side by side and make decisions about what to do next.
So there's a lot of automation to be had there. And how will this all get done? I mean, I get that there are gonna be AI agents, but are companies like yours gonna, uh, figure out which LLMs to use and give me those AI agents and how customizable are they gonna be?
Can I build my own? Do I need to expose my own data to this? How is it all gonna play out?
That's, that's an open question, right? And, and not only that, but who's gonna pay for it and how are you, how are you gonna pay for it, right? So we see a variety of different models.
So right now, for example, focal Point offers our agents that we have built and trained to do certain things. But if someone comes to us and say, look, I'm importing stuff from Brazil and I'm worried about tariff impacts from day to day. I want to build an agent that looks at that specifically for my parts.
Like, okay, that's the probably not something that we will, you know, build for all of our customers, but they can plug in their own AI agent and on our infrastructure using their data sets and have that be executed within our solution. The only question really is like, how open will suppliers be? How, how much infrastructure can they build to support this, uh, and how will they charge for it, right?
Because you also see some organizations aren't charging for AI at all, and then you have some that have not only, not only user based, but also token based, right? So I think a lot of these pricing models are kind of funky because the price of AI keeps going down and, uh, you know, do, do you really want to set pricing for three years for something that you know is gonna decrease for the next, you know, next two weeks, right? Like it's, it's, it's a very interesting discussion that, you know, it's kind of like a religious discussion we're having internally.
Like, how are we gonna, how are we gonna charge for this? Well, it's curious because I think if you charge extra for the so-called AI agent add-on, uh, people will use it less because suddenly they're like, well, that's more costly and that may be defeat the very purpose of having the ai. So maybe we gotta figure out how to just embed that into the base price of the software itself.
E exactly right. And it is interesting, right? 'cause if you think about something like an invoice processing flow, right?
First thing you need to do is read the invoice, then you need to decide what to do with it. And it's, let's say it's a PO invoice, like gets matched over here, it's a non PO invoice that go over there. So it's a lot of work that happens behind the scenes.
And if, if you do it manually, it will be probably cost like 2, 3, 4 bucks per invoice on being conservative. Um, and then you can get an AI agent that can do that in a matter of seconds, and it will probably cost, I dunno, let's make, let's call it 35 cents, right? Today.
There's an inherent value there of just having it be automated. You pay 10% of the overall cost you used to by using an AI agent. So in that case scenario, like it's a wild party all around, right?
But it's, it's the large language model stuff that is kind of squishy where yeah, you would probably decrease the usage. But there are some applications of this where you just kind of like on demand for specific tasks, they're gonna be automated. And I think people will not limit their, the usage of that just because the, the values there.
As you kind of think about this for a minute, um, will the, today, there's a lot of silos in our organizations and procurement is one of them, but in the age of ai, um, might all those silos either maybe disappear or maybe they'll just become a lot more porous as we go along. But are we looking at some sort of, you know, massive business process, re-engineering workflow exercise here? I think, I think that is certainly coming.
And I think a lot of that also depends on the infrastructure that folks currently have, right? So AI inherently needs data, and if you can't get access to the data through an API or data lake, it's kind of hard to actually do something with it. And we see a lot of companies that are protective of opening up their A-P-A-A-P-I layer if there is one.
But I do believe larger companies will go, go forward and start creating AI projects and so on to try to, to get as much value out of this technology as possible. And I do believe there's gonna be a lot of process re-engineering to make sure that people fully harvest the, the use of these solutions. I think it's not much of a dirty secret out there, but a lot of procurement still revolves around spreadsheets and heck, even paper and pencil.
Um, will we kinda see a lot of organizations finally, you know, apply AI to procurement and, and maybe one of their higher priorities, or, you know, when I go talk to folks, there's a long list of AI projects. So how far and how quickly will procurement move up that stack? Um, we see bifurcation, right?
Some folks, it's interesting when we talk to some of our larger customers, uh, their IT departments are very reluctant to do anything. Ai, it's kind of like SaaS was 10, 15 years ago. Like, SaaS was really scary.
You needed to have stuff behind the firewall so that people can control it. And now AI is the same way. They say, well, if, if you need a new application that has AI embedded, we want to try to build it ourselves before we open it up to third parties.
Now, that doesn't make a lot of sense to me, having been on both sides, both on the corporate side as and as a provider. But I, but I see, you know, the old school folks that are reluctant, then I see the people that says, bring it on. We can't get enough of it.
And I, I think, uh, there's a lot of dangers being left behind if you don't embrace it. And I, I see a lot of companies coming to us with the ideas to say, look, we want an agent to do X, Y, Z. Can you help us with that?
And I think, uh, that is, those are the customers we really like because it helps us improve, it helps us innovate, and, and people are moving up that ladder fairly quickly. So I still think we're probably five, 10 years before we see a ton of automation where it's really impacted and paradigm shifts across the industry, but it, it, it's coming. What is your best advice then for organizations about how to get ready for that?
'cause? Um, I don't think it just magically happens in, uh, as far as I can tell, it all starts with the data. So maybe I need to get my data organized.
Well, that certainly is a very good starting point. I think companies have to find religion about what is acceptable and what is not. And just like with SaaS there, you know, there has to be sort of a value before people are ready to sort of move forward.
And a lot of folks will say, well, you can't look at my data and you can't send my data to a large language model outside of, you know, our, our firewall. But when you think about the data that actually goes across isn't, you know, we're not gonna say, this supplier is the supplier for company X, Y, Z, and you spend this much money, and here's the contract. A lot of that stuff gets anonymized before it leaves to be processed.
And I think folks have to figure that out that okay, the, the, the, the risk is limited. You can review the prompts that are being sent out and actually control over those things. So I think the CISOs have to sort of get their arms around it, as long as you can see what the large language model prompts are and what actually gets sent out.
Okay, that's probably not so scary. And it's their job to educate the rest of the organization that with the right parameters, that might be okay. But yeah, data is certainly paramount, and we see a lot of folks actually using AI to clean up their data as well, which is actually kind of interesting, uh, especially on the supplier, uh, records where sometimes you don't have full addresses, sometimes you don't have the right, uh, you know, taxpayer id, all those kinds of things.
And you can use AI to clean it up and it just becomes that much more valuable. So I, I see a lot of cool stuff, uh, in the future for this. You know, you've been at this a while.
What's that one thing you kind of see organizations still doing today when it comes to procurement that just makes you shake your head and go, folks, we need to be a little bit better than that. Yeah. You know, it's, it's, it's still interesting to me to see how procurement organizations are using Excel spreadsheets to, to fill out, you know, in, uh, questionnaires.
So like, I received a, a questionnaire with 600 questions, a lot of duplications, and it's all done in Excel, but multiple tabs. And it's just, you kind of slug through it and then you realize this is a $55 billion technology organization. You realize like they're not drinking their own Kool-Aid, um, first of all, and it is just challenging to me to sort of get my arms around it and there's no appetite for change.
'cause this, this few hundred people in the procurement organization doing this, and, and this has been the process for 20 years, and the prob will be for, for another 10 at least. So we just need to stop using spreadsheets. That's terrible.
It's just not a good experience. Right. All right, folks.
Well, hey, one thing to think about here with AI, where everybody's casting about as to where is the return on investment gonna be, we might argue that procurement is a huge opportunity to drive some value back to the organization in the way that automates a task that well, nobody on either end really enjoys doing. Hey, Anders, thanks for being on the show. Thank you, sir.
Enjoy the rest of your Day. And thank you all for watching the latest episode of the Techron AI Leadership series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next time. Hey, everyone, we're back here.
Live a platform con day in New York City. Glad you're joining us. com.
That's a tough one. And, and join in all the fun. You get all the sessions that are here, plus all of the sessions that have been going on and they've been going on all week.
In the meantime though, let me introduce you to our next guest. Her name is Camille Forer. Forer, yes.
Yep. Got it. You got it right?
You got it. Yep. Camille Is a multi-time, uh, author.
She her newest book we're gonna talk about in a second. But first, let's welcome her. Camille, welcome.
Thank you. Show, thanks for being here on Techstrong TV with us. Yeah.
Um, tell us a little bit about you, your background. Sure. Yeah.
So I've been in tech for a long time, uh, and I've been here in New York City for a long time. So I've had a tech career that spanned finance startups, uh, non-profits even. So I've done a lot of different things.
Um, and, uh, I've also written a number of books. So I've been a CTO, I've been a leader. I wrote the book, the Manager's Path for O'Reilly.
I edited the book 97 Things Everyone Should Know About Engineering Management. That's a mouthful. And my most recent book is actually about platform engineering.
So it's called Platform Engineering. I Guide for Technical Product and People Leaders. And it's also an O'Reilly book that I wrote with a co-author, Ian Noland, I'm sorry, the co-author's name.
His name is Ian Noland. Very cool. Yeah.
So I guess I, it begs the question, what's a nice girl? Like you writing a platform engineering book for, you know, what, what drove you to Yeah, yeah. Write it.
So I, first of all, I love platform engineering, so I've been doing it on and off. I would say that's kind of the technology area that I'm most passionate about. I worked on the Apache Zookeeper project as an open source contributor in one of my jobs.
And I've just been, I've always been in interested in kind of that space of software, sort of down stack software development. Mm-hmm. Um, and I ran, uh, I've run several sort of platform engineering types of organizations.
Um, and so I started running these organizations about, uh, 2017. Um, and at this time, like not, people didn't call talk about platform engineering that much, so it sort of became a trending term. Um, and first it was like a Kubernetes as platform engineering, and more recently it's like IDPs, our platform engineering.
So it sort of felt like platform engineering turned into more of like a, like a vendor keyword search than an actual practice. But as someone who has done work in this space for a long time and run big teams in this space, I actually think that it's, you know, it's a way of working. It's a way of solving some of the really big problems that engineering teams have today, particularly at scale, where we just have a huge amount of complexity that software engineers are expected to navigate to get their jobs done.
And I believe that platform engineering is one of the, a modern approach to helping to kind of manage that complexity. Um, and so, you know, I wrote this book, I wrote this book with my co-author Ian, who we worked together at one of our jobs, and then he went and ran, uh, a big platform team at Datadog. And so we have a lot of working experience doing this.
And the book is not about like the technology specifics. The book is about all of the challenges that people have when you're actually trying to build and execute these teams. Because these types of teams and these projects are, I think, a little bit different than your average kind of application engineering space.
They have a lot of their own nuances and complexity, and we wanted to make it possible for people to have kind of a reference for how to solve some of these problems. You know, you said, you said a lot of things in there. Let me unpack a little bit.
Yeah. So first of all, I, I gotta tell you, you're the, uh, I don't know, third interview we've done today. I was interviewing a woman a little earlier.
She's the SVP of engineering at temporal. Okay. Temporal.
Yep. Excuse me. Yep.
Pretty. And she said something very similar to what you said, which was, I've been managing platform engineering teams for 20 plus years, but yet, so I'm older than you. But you know, you look out at the audience here, if you were to ask some of the younger folks at this audience, they'll say, oh, platform engineering's a new thing, right?
Yep. It's, you know, three years old, four years old, whatever. Yep.
How do we, how do we reconcile people who say, Hey, I've been doing platform engineering platform man managing platform teams for 25 plus years. What are these people? What are these?
You know, people missing that. Well, I do think that when you're young, you, you sometimes lack, and I'm not banging on young people. No, no, No.
But I do think when you're young, sometimes you lack the perspective of having worked for a long time and seen that actually nothing is ever totally new under the sun. And things that seem new are often just rebrandings of old concepts. I mean, Repackaging, you know, I micro remember microservices, right?
Yeah. No, no, I, yeah. You Know, it's not like people weren't doing services before.
And yes, microservices have certain nuanced differences, but like in reality building service, we Called it multi-threaded, You know, building the service oriented systems was not a totally brand new concept. No. Everybody treated it like, oh my God, this massive innovation.
Um, you know, I think right now, the, though with platform engineering in particular, I really do think platform engineering is not a super new concept. I think the branding is new-ish. Like I do think that the Kubernetes project really accelerated people thinking about platform engineering.
And I actually, my theory is that it did that because Kubernetes actually enables you to really easily run multi-tenant infrastructure yourself. So even if you're not a cloud provider, it sort of allows you to think about, oh, like, here's how we can kind of think about this sort of multi-tenancy and these plugins, and you can have lots of different teams really working in this sort of, this, this particular type of way. Actually, I think it's just an interesting, um, it was an interesting like, technical evolution that it made, it made it more like, uh, more popular for more types of teams to think about and start to adopt.
And of course you have the cloud and all that other stuff Sure. As well. Um, but sorry, that was a very bad explanation of of No, no, I Get it.
Of Kubernetes. So apologies to the audience. I, you know, And, and to the original Google team team, right?
To the Original Google team. But like, they did something pretty unique that made it easier to build some more complex platform type software in an open source way without hitting all of the problems that your older open source software. Like I said, I was an Apache zookeeper contributor, right?
Mm-hmm. One of the big challenges of running zookeeper as a service was having lots of different teams using it and, you know, causing each other problems, right? When they, one team would DDoS the entire company because of the way they were actually accessing that underlying open source, right?
And so I actually think that, you know, this was one of the first major open source projects that started to think about and solve that problem. And that is actually pretty important for really thinking about platform engineering of the, the way we think about it today. So, um, now of course, though, I think the thing that bothers me most is actually Kubernetes popularizing platform engineering made it a little narrow, but I sort of got it.
I'm not a big fan at all of IDPs as platform engineering. That's the, that feels like that's the latest vendor term. Yeah, it is.
And I think that's way too shallow. Like I just think that is a, that is an even shallower way of looking at platforms. Uh, so I have some views on Yeah.
Surprise. Yeah. Um, I think that is what that IDP is platform engineering comes right out of the developer as the alpha predator in the PAC view of things.
True. Right? That everything we do is to service the developer.
Yeah. And so therefore we have this whole platform engineering and the platform engineering team here to make the developer Yeah. A better top predator.
Yeah. There's more to life than there is organizations. Yes.
The developers not to say they're not important. They are. Yeah.
Yeah. Another thing you, you know, we, you mentioned microservices. Yeah.
To me, when I look at platforms and platform engineering Yes. Kubernetes, the orchestrator Yeah. Was, was a big piece of that.
Yeah. There were, there were other orchestrators. There were like Cher and Dockers, so Yeah.
Mesos, No. And then actually the whole docker container thing Yeah. Itself, in my mind was the progenitor true.
That kind of ignited that whole, Yeah. This whole thing. Um, so when, when I look at what we, you know, today, call platform engineering, if you wanna call all the other three things I spoke about cloud native, 'cause that's what all people Yeah.
It's Just cloud native on top of what you've been doing a platform or Yeah. One of my like mentors, I, I sold comp my first company to him, and then he found, he funded every company I ever, ah, did, it's my friend Brad Fell. Brad is a founder of Techstars.
Yeah. Actually has a new book out. Just came out this week about mentoring of all things.
Yeah. Um, but he always said, Alan, everything we do in tech is 99% evolutionary. Yes, yes.
There's very, very little revolutionary. Completely Agree. And, and I think this is a perfect example, You know, uh, it's so funny you say that my talk today is going to talk about how platform teams support the evolution of organizations and their usage of, you know, technology.
And they're not revolutionaries. And, you know, I, you know, I think one of the big, uh, one of the mistakes we talk about in our book is the building, the V two system, the second system effects, second system syndrome, old concept that every generation must rediscover and fail at multiple times, in my experience. Um, and so I've, you know, I've been speaking about that topic actually for, for a while in my career.
And lately, you know, I've been, we've been trying to talk about it in terms of platform teams, and one of the things we, we say is like, look, platform teams generally are made up of people who are very good at stabilizing and scaling and, you know, making software more usable and more efficient for more and more groups of people, um, which are really not the revolutionaries of your, of your company. Right. Um, and so I actually think that, you know, one of the important things for platform engineers to recognize is we are not really revolutionaries.
We are the evolutionary force, but if you do platform engineering, well, you can keep an organization evolving successfully, which is incredibly hard. Yes, it is at scale. And for a long time, and I've worked at, you know, some big old companies with, you know, a, a, a, you know, long timelines of software, and, you know, in those companies, you really wanna think about how do we make it easy for people to do the right new thing and to encourage movement into the new space.
Sure. Right. Without, you know, without saying, all right, you gotta, we're killing all of this stuff here and you're just moving it all tomorrow.
It's like, yeah, let's, let's evolve and not just try to sort of, uh, dictate these timelines, you know? And these, I'm reminded one time I was talking with, uh, he was at the time the new CTO of Hertz. Hmm.
This is around 2009, 10 maybe. And he, he said, he said, Alan, we're moving to the cloud. It hurts.
I said, oh, you're migrating. We're not migrating. So what do you mean you're not migrating?
What are you doing? We're going with a clean start. We're just building from scratch.
Oh, Good luck. Cloud applications. And then as soon as they're ready, we're just turning off.
Yep. The data center ones and moving to that. Yep.
I told him the same thing. Good luck. Of course, Hertz declared bankruptcy.
He lost his job and everything else happened, you know, and the interim, yep. Not a, not a path to success. No, no.
Very, very difficult, uh, very difficult Lift. That's, yeah. That's a, that's a juggling act.
Yeah. But I, I know you haven't had a chance to really get out on the floor and you, and you, you're talking this afternoon, but initially, I mean, look, keeping in mind that this is only the, in one of the in-person days of a full week of virtual sessions, what's the impression been? You know, I think it's great right now.
It feels like AI has sucked the air out of every room and every conversation. And, you know, look, I'm interested in AI too. Of course we're all interested in it, but I love platforms.
I love, like, I think this is actually still a really important area for people to be thinking about and working on and learning how to do better and adopting within their companies. And I don't think AI is just gonna magically make it that we don't need to understand how to build large systems and, you know, do big engineering projects, which is a lot of what platform engineering is. So I'm really glad to see this energy here.
I'm really glad to see, you know, to know that there are so many viewers for the videos and the content that's created, you know, at this event. I hope some of these people will buy my book, because I think it's a pretty good book and it has a lot of good information in it. Um, but, you know, I, I've, like, I am ready to talk about technology things that aren't just ai.
And so I'm very excited to be here to do that. You know, we do a show every Monday to Friday, five days a week, text, drug Gang, so on every day at nine 30, and it's three segments per day. It's sort of the view meets Fox and Friends meets Morning Joe.
So, you know, we get a little, it's a bunch of pundits just talking. Yep. It is so hard.
Yeah. So hard to just, 'cause the AI sucks the oxygen out of every conversation. Yep.
It seems, and like you, I I, I play with the guitar. I think it's gonna be huge. It's huge in media.
It's huge in so much, but you're right. And, and it is good, good to have that here. Um, so how can people get your book?
Yeah. Well, you can my it on Amazon, uh, we have a, uh, we are, so we are published by O'Reilly. So look at O'Reilly.
If you have an O'Reilly Safari, sort of the online platform subscription, you can find it there. You buy it on Amazon, Kindle. I don't think the audio book is out quite yet, but it should be coming out soon.
Um, and we are translated into a couple of different languages as well, if you want it in non-English, and hopefully soon there'll be a few more. So, you know, look for it. Wherever fine technology books are sold.
Your favorite book. Stellar. That's great, man.
Camille a pleasure. Thank you. It was great meeting.
Lovely to meet you. Camille Forer, did I get it? Yes.
Got It. Right. Author of the O'Reilly platform engineering book.
Go check it out wherever you buy your books from. We're live at platform Come, we're gonna be back here in a minute with more. Hello and welcome to the latest edition of the Techstrong AI Leadership Insights series.
I'm your host, Mike Baard. Today we're with Benjamin Fabre, who is CEO for Datadog. And we're gonna be talking about, well, how AI agents are gonna be used to buy stuff, but it may be more challenging than we think.
Benjamin, welcome to the show. Thank you. Welcome.
So what is the issue here? I mean, I, everybody's kind of at least aware of AI agents and they probably thought about how I might use these things to go buy something, but it may be a little bit more challenging than we thought because, well, the e-commerce side of the house has to recognize that AI agent as something that I want to have it do something positive for me, right? Yeah, exactly.
So, um, you know, in in the past the, the usual way to tackle fraud, uh, was to detect, um, if the incoming traffic was coming from human or from parts. Uh, so it was kind of a binary vision of the internet. Uh, but now with this massive revolution of, uh, agented traffic, we see that, um, legitimate users are using AI agent in order to purchase or browse websites, look at the inventory, and then make some purchase.
So the binary decision that in the past where solved with capture, for instance, uh, is not the right solution anymore. We have to detect what's the intent of the session, uh, regardless of the fact that it's a real human with a, a mouse and scrolling on a website, or if it's an agent working on the behalf or of a human. So how do I recognize that?
Because to your point, it is another type of non-human identity, but there are other types of non-human identity. So how do I know which one of these is the right ones? What we, uh, do, uh, data them is that we, uh, first do some fingerprinting in order to identify and, uh, authenticate a very, um, in sexual manner, uh, what's the AI agent, uh, to make sure that we are properly identifying, uh, the right agent that is browsing the website.
But then that's, that's not enough. Then we have to go down and deeper in order to understand what's the intent behind every single session, because the very same agent, uh, can at the very same time, uh, pro the website or the API, in order to, um, do a legitimate action like looking at product, finding the right one, and then make a payment. But at the very same time, an agent can be used in order to, uh, do some scraping, uh, so like price monitoring or can be used in order to do scalping.
So they might try to buy the limited inventory to generate profits on that. Uh, so the intent based detection is key. Uh, and how can we do that?
Uh, it's to be plugged to the business KPIs of the retailers. So the detection engine, um, that could, to detect the, the wrong intent, uh, have to understand what is the right, uh, usage of the, the service, uh, and what is the wrong one, um, in order to understand what will be positive on the business and what will hurt the business. Do we also have to be concerned about fraud here?
Because I can imagine that either somebody's gonna try to hijack my AI agent, or they'll create one that looks like me and starts doing stuff and charging my credit card for my trouble. Yeah, you are definitely right. Uh, as we speak, the new standard, uh, are being defined by all the leading, um, LMS and agency companies, uh, and the pro prevention solution like data them.
Uh, we are working very closely with all those, um, uh, agency companies in order to create new protocol, the new authentication systems, uh, and to make sure that it's not, uh, spoof able, or at least that we have the right level of signals in order to detect, uh, what is a legitimate, uh, uh, agent and what is an attempt to spoof, uh, a user or to do an contact cover through, uh, agent traffic. So that's a whole new area, uh, where having the behavioral detection is, is key, and being real time is also key. And won't I wanna, as a retailer, recognize certain AI agents as maybe best customer AI agents?
Or will I not assign levels of privileges and services access to them based on, um, you know, how much activity I've seen from them in the past, but I have to be able to track that, right? Yeah, a hundred percent. I think the, one of the main, uh, concern that we are seeing for retailers now is that they lack visibility first.
Um, you know, they've worked very hard over the past 20 years to have a clear visibility of their traffic, of their conversion rate, the sessions, et cetera. Uh, and they have entire department working on analytics, understanding what is coming from SEO, what is coming from ads or SEM, uh, and now they see that the traffic coming from all those source of traffic is decreasing. Uh, and there is this increase, uh, with AI agent and lms, uh, according to Gartner in the coming two years is gonna be at least 20% of the traffic that will be agent traffic.
So it's gonna be massive, and I personally think that it can be even higher than that. So having good visibility on this agent traffic on the different source of acquisition is key, and that's what we provide to our customers. And then it's good to build that, to understand that, but it's also great to be able to act on that and to block the fraud before it happen.
There's also some subtlety in the sense that I may be engaging with an AI agent and it keeps coming back, but it doesn't buy anything because maybe what's happening is, is that AI agent is engaging with multiple retailers and it winds up buying something somewhere else, but don't I wanna know that behavior? Yeah, exactly. Uh, so when we plug the, the, the behavioral detection on the business, KPI, so like, is this session, uh, about purchase or not?
Uh, can we see a transaction, uh, with this user agent on this AI agent? That's how we can qualify and identify what are the genuine, uh, AI agent that's have the right conversion rate and the right, uh, way to consume the website, and what are the one that are just here to browse, potentially just do some price creeping, uh, but not purchase. And that's what you don't want to allow on your website, uh, because that may, uh, impact, uh, your competitive advantage with, uh, other retailers, for instance.
So yeah, that's definitely key for our customers. I'm gonna assume that the retailers are also creating their own AI agents. So will the AI agent on behalf of the buyer negotiate with the AI agent that the seller creates and is, and how will they negotiate with each other?
Yeah, that's, that's, get that, that's very fun. Uh, we have most of our customers, uh, as we speak, are creating MMCP. Uh, so the new protocol in order to make their, um, their services available to AI agents and those MCP can start to include in that some AI agent itself, uh, to create some negotiation, as you said, to engage with loyalty program.
So there are a lot of great and, and exciting stuff that are coming, but as usual, every time there is a new service, a new way to purchase that will introduce new fraud. So we have to keep investing and make sure that as the retailers are doing a lot of innovation, which is really game changer, at the same time, we keep improving the security and all the fraud, so we stay ahead of attackers. Will it be hard to maintain something that looks like a consistent list price on things?
Because, um, today I, as a human, I'm kind of lazy, so I just go to the website and I see that the prices and I click on it and I want to be done, but the AI agent is infinitely patient, so maybe they'll just go out and kind of bang on all these sites and keep looking for better or better deals, which the retailers within respond to. I mean, what level of competition are we talking about here? Yeah, you're right.
That's gonna be probably very intense on, on, on the price. I think the, the, the price competition would be even more important than it was in the past, because the ability of users to compare pricing will significantly be higher. Uh, so the, the pressure on the pricing might be something that is gonna be even more important than in the past, for sure.
So what's your best advice to retailers to get ready for this brave new world? Because I mean, it seems like there's a lot of moving parts and pieces, but where do you get started? So I think first, um, using a solution to have the right visibility, uh, on your traffic acquisition, uh, on all the LLMs traffic that are either trying to create the foundational model with your data, uh, and understanding all the AI agent, uh, using your website, not just at the high level of the each agent itself, but going deep into each sessions to understand what will consume, what won't consume on your website.
I think that's the number one priority. And, and offering this visibility to our customers was game changer. And the second one is plugging the solutions to business KPIs.
Uh, so we can qualify the different sessions, but what are the, the, the AI agent traffic that are making some, uh, purchase on the website? And what are the AI agent that are just consuming your resources? Because that can be also very costly.
Every single request on your product list, on your search engine, uh, on your checkout, uh, are costly. Uh, and you want to reserve your resources to the, uh, genuine users, uh, either, uh, human or AI agent. How fast is all this happening then?
I mean, you know, is this like, am I gonna wake up tomorrow and this is the new way of shopping, or is it gonna take us a couple of years? Um, so it's going very fast, and I think there is this pressure on, you know, the, the first mover. Uh, so every retailer now as we speak, uh, is working on making sure that the, that they are in the race.
Uh, they offer MCP, uh, uh, to their users and they implement the right level of security and for prevention on this new way to consume on their website. So I think it's a matter of weeks and months, uh, to have the first early adopters. Uh, and I, I really definitely believe that in 2026, the significant parts of the revenue of the largest retailer will come from AI agents.
And we're talking about this in the context of say, B2C and mainly, but won't the retailers also use AI agents to buy stuff from wholesalers and manufacturers themselves? And, and will those AI agents need to keep track of what the AI agents that are selling to consumers are doing? I mean, how complicated can it get?
Yeah, the entire supply chain, uh, will be impacted. Uh, it's not just for the public facing, um, uh, way to consume, but, uh, I think, uh, we will see that as a chain effect. Um, and, um, and, and at, at every layer of this chain, uh, we will have to introduce security, uh, to make sure that there are no abuse and no fraud.
Uh, because, you know, frauds are fast, frauds are clever, and they have a lot of money, uh, to try and find any weaknesses in those infrastructures And depending on the brand, but most of the time retails are razor thin profit margin game. So, um, will they be able to make more money in this model with AI agents, or is it just gonna get tougher? Well, there are a lot of, uh, questions, uh, that are raising on their business model.
I think one of the core stuff that we are working on also is to help, um, the retailers and the medias to secure their revenue, uh, because for instance, ads, what about ads? If you are on your retail website, you have some ads, but this is an AI agent, um, no one will actually see the, the ads. So the impact on the revenue on your ads might be, uh, also significant.
Uh, so we are, there are a few interesting initiatives that we are partnering with, uh, to create, uh, monetization on all this, uh, AI agent traffic. Um, and that's going to potentially be a replacement or at least, uh, of part of it, uh, of the ads that, uh, the ads revenue that our customers are generating. Usually, To your point, retailers also spend an inordinate amount of time on things like SEO to try to make sure that they show up high on a search.
But if we're not using search anymore and we're just using an AI agent, then how do I know that I, how do I get my site or offerings high up on the minds of that AI agent, assuming it has a mine, but you know what I mean? Yep. Uh, yeah, indeed.
So you have to, um, um, first understand how the different ai, uh, and LLM companies are browsing your website. Make sure that it is available properly and they can use that. And there are, you know, the two part of the, the AI and the one that is the, the pri the scraping in order to create the foundational models.
Uh, so you wanna make sure that you provide the right, not too much, not too few data, uh, to all the ai, um, to make sure that you are part of the foundational models. And then there is the on the fly, um, scraping. Uh, and you also wanna make sure that you share the right level of information, not too much, not too few.
Uh, on, on, on this second part of the, the, the scraping of AI agents, um, and depending on your strategy, um, if you are retailer, marketplace, um, media, we help our customers to define the right, um, policy on all the this AI traffic. Uh, because you might have different strategy depending on your business model, What is that one thing that we're kinda underestimating and not paying enough attention to right now? I would say making sure, you know, it's making sure that you implement the right security.
You know, our customers, they want to innovate fast. They wanna make sure that they don't miss the train of this agent traffic, but at the same time, you have to, uh, uh, put in place the core foundations of your security on all these new, uh, AI agents traffic. So, uh, I think, uh, you shouldn't, uh, underinvest too much into, uh, the security, uh, as you are moving fast.
All right, folks, you heard in here, Hey, we've been fighting the fight trying to figure out which bots are good and which ones are bad for a long time now. But AI agents are essentially a new type of bot, and there's gonna be a lot more of 'em, and a lot more of 'em are hopefully good. The question is, is distinguishing which ones are what.
Hey, Benjamin, thanks for being on the show. Thank you. Thanks for having me.
All right. Thank you all for watching the latest episode of the Techstrong AI Leadership series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next time. Hey guys, thanks to the Throw, we're here with Scott Hayes, who's director of product marketing for Remedy Street.
And we're talking about SAP and how to regain control over your own migration strategy. 'cause well, everybody's got a plan, except they never, always consulted the folks who were affected by Send plan. Hey, Scott, welcome to show.
Hey, thanks Mike. Thanks for having me. Not everybody is necessarily, uh, well versed in all things SAP.
So paint the picture for us here. What's going on in terms of these migrations? And like a lot of SaaS providers these days, now everybody wants you to be on a certain, uh, version and update, but there's a long history of running SAP in on-premise environments.
So what are we trying to accomplish here and, and where's the tension in the system? Uh, there's so much to cover here, Mike, and I'm sure we'll branch off in this, uh, uh, in this time to, to hit some of these other things. But let me Lemme just set the basics here.
You know, SAP uh, software is run by some of the largest, most complex, most successful companies in the world. Um, and, uh, the, the software that they run, um, is mission critical to their business. They're running their shop floors, they're running their orders and invoices and, and, and their customer experiences.
Uh, their partner experiences, their distribution channels, their, their shipping and supply chain. And, uh, these are things that are the lifeblood of, you know, generating revenue and controlling costs in these companies. So, um, the, the, the, the SAP is really the heart of that, um, in terms of, of record keeping and reporting, uh, and the, you know, the daily activities that are going on in organizations.
So that's kind of the foundation. And, uh, SAP has had many different, uh, products over the years, decades now. Um, and the predominant one in the market now actually running in production, um, is, uh, there are two really.
There's one called ECC, um, and, uh, that's been running a little bit longer than S four hana, which was released in 2015. But here at this interview that's, uh, coming up on its, uh, 10 year anniversary for S four Hana. And, uh, SAP leadership, um, has certainly been paying a lot of attention to what drives, um, stock prices, uh, and what drives positive investor sentiment.
And that is converting any stream of revenue it can to the a RR line, the annual recurring revenue line, uh, in their, um, uh, reporting. And so their wanting to, as many other SaaS providers have done, convert their clients, many of whom, especially ECC, but also thousands or tens of thousands of s 400 clients, to convert them from having perpetual licenses, Hey, I can run this product into perpetuity, to subscription licenses. Where if, uh, you know, you decide that you wanna do something a little bit different, you're gonna have to talk to SAP about how you wanna do it differently.
So they're patch packaging up in that subscription license, the right to use the software, the support for that software, some infrastructure services for that software, and the cloud compute power upon which that software is executing. Um, and so they would love to move tens of thousands of ECC clients from a perpetual license to a subscription license. And that's where it's really been a challenge for SAP clients is, do I want to give that up and do I want to go through the headache, the risk, the cost, the disruption of migrating or replatforming my software, something that's working highly customized to something that, uh, is under SAP's subscription agreements and on their, um, you know, managed cloud services, Right?
So if I wanna hold outta my perpetual license, do I have a choice of the matter? And what am I trading off to stay there? 'cause, uh, that seems to be the point of control.
Fair point. So, um, you can hold onto your perpetual licenses, hence the word perpetuity. Um, and I think the question that the, that the practitioners are asking is, does the value and the viability of what I'm running last longer in my business than what SAP would by practice, uh, recommend that I, you know, continue running this software?
So, um, SA P'S done a couple of things to try to convince clients to move from that perpetual license to a subscription. They, one, have said that they're going to stop providing mainstream maintenance for ECC software, um, in 2025 for some of the enhancement packs, and in 2027 for some of the other enhancement packs. Um, and so that's kind of the stick is, Hey, we're gonna stop providing, um, maintenance for these.
The carrot is, but if you get over to our subscription and onto our cloud, then we have lots of innovation waiting for you. So, um, they've used that strategy and yet, and yet many IT leaders have said, you know what, it's not, it's not making economical sense. They have done the math and looked at the cost of replatforming a very complex, typically highly customized product that's working and saying, just because you're gonna stop supporting it, I'm not sure that the cost and risk and disruption of moving to this new model is good for us, number one.
Number two, I can't get the board to sign off on the tens of millions of dollars it might cost for us to do that. And number three, then I end up in a position where this core mission critical software is now part of a bundled agreement with SAP that might be hard to unravel or exit from down the road. We call it vendor lock-in.
So that's really the point, is, can I really afford, or do I even want to move that direction for innovation when what we see in the market is that innovation isn't necessarily coming from mostly the leading, uh, ERP software providers themselves, At least as I understand it, just about everybody who invested in SAP for, uh, an on-premise environment or something, or whether they hosted in somewhere else on their own. But self-managed has customized that extensively over the years. Mm-hmm.
Yeah. And those customizations are, have a lot of value to them. And SAP as I understand it, is trying to say to folks, well, you may have customized that four or five years ago, but we've added that capability now into the core mainstream platform, but it's not quite the same thing.
It's, it's still always gonna be some sort of general purpose version of something versus something that is highly tuned to my, uh, business. So is that kind of part of where this tension is? That's part of it.
I mean, there is no one size fits all software, but SAP and other, um, you know, ERP providers have created highly configurable and customizable software and have sold on that premise saying, Hey, look, you know, you can really make it do what you need it to do, and here are the tools, by the way, that you should use to do that. And so, yes, you're right, Mike. Um, SAP clients have highly customized, and so now what they're facing is SAP saying, we'd really like you to be on what we call what SAP calls a clean core environment, um, where it runs standard business processes.
And that if you wanna do something different, then we are going to request, recommend, or maybe require that you do that outside of the core of the software. And they have new tools for doing that. They have a new platform called the Business Technology Platform, A BTP, upon which these customizations need to run.
Now, that means that somebody who's going to migrate, um, they get to choose from two options. One's called a Brownfield option, where you take all your customizations with you, but you have to run in a private environment, basically a single tenant environment in, in SAP's world. Um, and you may not then get the opportunity to take advantage of some of the things that they would be offering to all of their clients in a more common multi-tenant environment.
Number two, if you have to really analyze your customizations, then you need to say, Hey, look, should we retire this one? Should we rewrite that one? Should we refactor this one?
Should we re-platform this one? And you go through all of that effort to say, could I really live on clean core and what would I need to refactor redeploy outside of core running on BTP? And the last gotcha there is, while you are allowed to customize your SAP environment for many, many, many years, and run those customizations on whatever environment you're running, if you rewrite those and run those on BTP, which is in agreement with their clean core concepts, BTP as a platform has basically a, a, a, um, a toll associated with it.
So now you have to basically pay each time you fire those customizations and run them because they're running on this BTP platform, what used to run for free ish in your own environment. It also seems to me that they've got a new carrot, and they're calling it AI agents or juul Yeah. Who's not.
And, and they're kind of trying to say to folks that, you know, if you're on the clean core, you'll be able to take advantage of all those AI agent capability that may not be as easily extended to the on-premise edition that you may have had or highly customized. But, um, is there another way to skin the AI agent CAT and still have my on-premise environment? Yeah, we think there's lots of ways to do that, and I don't, while I believe that, uh, a lot of these vendors are coming out with some nice agents and AI capabilities, they, um, typically focus just on their portion of the environment now.
And that's the way SAP started was delivering AI for SAP. But we, uh, at Ramini Street, we're very vendor agnostic, technology agnostic, and we believe that AI is really an enterprise wide play. And you ought to be picking, choosing your ai, uh, technology providers thinking about the entire enterprise, and not just your ERP, but also the ancillary applications that are outside of the ERP that are actually running your business and to create, uh, agents, uh, and, and, and AI capabilities and workflows and modern user experiences that tie that together across the enterprise rather than just buying AI that's applied to SAP.
So to your point, it does seem like whether it's SAP or others for that matter, they seem to be trying to use support as a leverage to keep people on a certain path. Um, whether I agree or don't agree with that may be secondary, but it does seem that this is a, a, a a thing that they're trying to lock you in around, and it's tied back to those support contracts. So is there some way to do this so that I don't give up that control to the vendor because I'm not so dependent upon them for support?
Well, exactly. And that's why, and that's why Remini Street exists. Um, we started by upending the vendor support model and providing third party support and doing it for longer than typically a vendor would.
So we believe that, uh, um, a property at and, uh, a software portfolio of this ilk, uh, can last and run much longer than typically the vendors would, uh, provide support for. And that could have been just, Hey, we're gonna send you a new update every couple of years, and we expect you to upgrade to it because we're only gonna support, you know, the latest release in one or two back. Um, and yet the thing was working just fine and being highly customized, the effort of doing an upgrade, even to the next release from the same vendor, um, could be very, very expensive.
So Rami's model said, no, you don't have to upgrade. It's working just fine. And what you really need is support for longer than the vendor was willing to invest in that support.
Well, our model says we are absolutely willing to invest in that support. In fact, recently, Mike, we announced that we will support, uh, SAP products ECC, and S four hana, whatever version you're on through 2040. Okay.
Now, that's a long time from now. Right? And I think what's happening in the market is that if you were to look at where the innovation is coming in terms of things like AI and gen, ai and workflow and, and robotics, uh, I'm not, I'm, I, I feel very strongly that this idea of a, a expansive ERP property from a single vendor is going to erode, and that the future of ERP is more likely to be, you know, a set of structured databases and some very strong business logic that's really accessed and impacted.
Um, and, and the business rules run by agents and AI and the people that are, you know, involved in those processes that span, uh, many applications and databases inside of an organization. So, investing and replatforming now in what's very much an old traditional model of what EERP is to me, I think locks you in and locks you out of new technologies and new vendors that you really need to be paying attention to in just the next few years. So our model that says, Hey, we'll support whatever you running until 2040, gives you plenty of time to wait and see, don't go jumping into something just because it's 25, 20 25, or 2027, but let it play out.
See what's important for your organization, see how you want to tie things together and what vendors might be bringing value to your company. And then, you know, start to deploy, um, uh, whatever that architecture is gonna be. But starting right now, you could be innovating, you could be using AI with one of our partners like ServiceNow, applied to, as you said, your existing on-prem or cloud-based ERP solution.
Why wait two years to do a replatforming when you could be innovating right now? Alright folks, well, you heard it here. If the rationale for doing something includes the phrase we have to, maybe you might wanna take a second look at that.
Hey Scott, thanks for being on the show. All right, thanks, you All right. And back to you guys in the studio.
I have to say that the human capital that's present right now on stage has me excited and a little bit worried. I'm assuming you trust your teams, everyone's doing their job because you guys are literally at the forefront of the new operational imperative moving forward. And it's not to be underestimated, especially for those of you who have been in the data security or cyberspace for a really, really long time.
Um, so Jason, I'm just gonna jump into it. You know, Gartner had this interesting stat that about 80% of orgs are gonna face challenges managing non-human identities coming up. Mm-hmm.
And by the end of this year, potentially, most of the threats we're gonna be experiencing is really about machine and machine interactions, um, especially around virtual AI collaborators. Mm-hmm. And as we really pivot into, you know, autonomous and agent ai Yeah.
Um, what gaps do you currently see within some of the jurisdictions and the laws that we have that you're personally advocating for, that we kind of have to put in place? Because, you know, there's always a delta between innovation and how fast lawmakers catch up. Yeah, that's a good question.
So, just, just to contextualize here a bit, um, maybe we'll just do like a, like a ten second interview. I'm the CISO of Anthropic, so I've been there for about two years. Um, the, if you just think about the way people are adopting ai, they start with chatbots and then they move to something that's sort of like RPA, where you, you've taken like little, little nodes in your, like workflows in your companies and you've put AI in that little node.
Um, and then as intelligence of the models goes up, as you see this exponential curve of intelligence increasing, you can take those nodes. You can think about the intelligence, um, being able to compress or collapse those discrete processes into one continuous sort of contextual. Yeah.
The same way humans work through things. You're just like, oh, well I tried a, that a didn't work. I'm gonna try a prime, you know, just go through the graph of, of things that you might do in your workflow.
And if we, if we give more autonomy, we give more, um, uh, decision responsibility to the, the agents or the, the models or the virtual collaborators or, and eventually in virtual employee, imagine a world where you onboard an AI with memory and you send it through your onboarding class, and then you give it, um, a starter project and then has a reporting manager, an email address and a Slack account. Like all of that's gonna happen, you know, sooner or later. Um, then the question becomes like, how do we have accountability for, um, the actions and transparency and visibility into what's happening?
I think a lot of the way that we think about risk management and companies and, um, you know, when, when companies are working between companies and trying to figure out who's responsible for what parts of the infrastructure is, uh, do I even have transparency into what happened? Like, do we have the logs, do we have the right, uh, pieces of metadata recorded? So let's say for example, I request an, um, a virtual employee to do a bunch of software changes.
Everyone in this room can imagine what that looks like because we're already seeing the coding revolution happening, right? Um, so it works on it for a week and it gets to the very end and it does something it's not supposed to do. And that environment then, um, I want to know as the security team who asked for that change, who was the, who was the agent acting on behalf of, who was the manager of that thing?
And those are questions that there's like core technology to build and core, um, sort of like audits, uh, to build, to understand, uh, from a, from a a from an accountability perspective, like where, where things have flown and what, how we can, how we can understand and react to those things as security teams. So I think that's the big missing piece is we don't have the right technology bits to follow, um, everything all the way through the infrastructure. I think that's a key point saying that we don't necessarily have the right technology bits.
And it's interesting 'cause I do think that we're gonna pivot from a place of where AI is our co-pilots to, we're gonna to us pivoting into managing a bunch of AI cockpits. Um, so you're saying that the accountability is gonna be on the individual overseeing those cockpits? Mm-hmm.
Okay. And I did something really, really silly because in my world, I know who they are. They're kind of our, our celebrities of the modern day world.
But I think Jason, you appropriately pointed it out, you probably all should introduce yourselves in case there's one or two individuals who don't know who you are. Um, I know we have the titles up there, but I think for everyone in the room, yes, name and title, but two, that pivotal moment where you pivoted from a practitioner to a thought leader, whether it's a moment in time in your career, or whether it was something that you wrote or invented, what was that pivot that put you into the place that you are right now? And then third, a quick tidbit of how on earth you keep sane with the pace of innovation and where we're supposed to find our zen knowing how fast things are moving.
And ultimately everyone in this room is accountable for keeping the ship floating. So Jason, how about you kick us off? 'cause I think that's just really important to, Yeah.
Wow. Two big questions. Um, when, when did I pivot to leadership?
Um, I have a science and science fiction book club that I've been running for 18 years. And one of the things that we do on the science side of that is read, um, anthropology books. And I read, I think my fifth or sixth anthropology book.
And I just got to the point where I'm like, you know what? There's a lot of, uh, opportunity for organizations to work better than they're working today. So why don't I put my hat in the ring and try and figure out how to make that happen?
And then how do I stay sane in this world? Um, uh, I don't recommend my methods, so, but I'll, I'll be honest. Um, I honestly, the last, the last two years have been totally unsustainable in a very strange and, and, um, weird way.
So my husband and I, my husband's also an ai, he's on the Gemini team. Mm. Um, which actually makes it great because yeah, we don't have to unhappy hours.
We have to like, argue about AI taking all of our time. 'cause we, neither of us have any time at all. Um, so we just put our personal lives on hold for the last two years, which I, I highly do not recommend, but, mm.
That's basically all we've been able to, to do to keep, keep her head above water. Yeah. Wait to keep your head above water, you've given up personal time.
Yeah, yeah, yeah. Just wanna make sure I heard that correct. Yep.
Yeah, don't recommend it. Yeah. I can relate to what Jason just said.
Um, okay. Pivot to thought leadership. Um, yeah, I guess that happened.
I, I, so now I work for Meta now, but, um, for, I don't know, eight years or something. I worked in the national security space and I was a principal investigator on some like DARPA sponsored research projects and some NSA sponsored research projects. And yeah, as a going from sort of, you know, researcher to principal investigator, you sort of have to, you have to learn how to lead a team and, you know, yeah.
Um, um, be a thought leader, you know, and, um, conferences and government meetings and this kind of thing. Um, trying to remember what the other questions. Were always staying sane.
Um, yeah, I ran the big sir marathon yesterday. Um, so think so if I seem so, so if I seem less coherent than normal, then that, that, that's probably why, 'cause everything is, is aching at this point. Um, but, um, yeah, I'd say running, um, is definitely, um, one of the main things.
And then I have two small kids, um, uh, 4-year-old and a 9-year-old. And they definitely keeping grounded, keep busy s and saying, and your beloved wife is here apart, correct? Yeah, my wife is here.
She keeps me sane too. She's there right there in the yellow Big, not for her. Um, Yeah.
Okay. That's the thing. Thank you.
Yeah. Maran. Hi.
Can you hear me? Great. Well, I'll start with, uh, first of all, I'm, uh, Ashkenazi.
I'm Jfr ciso and I've been doing cybersecurity for 25 years. Mm-hmm. And I think that the pivot was like, uh, two and a half years ago when I started, uh, a venture capital for cybersecurity and really support, uh, I understand the power of the CSO, global CSO and how we can help to a very early stage startups, uh, start coming, invest in them, uh, help them, assist them to grow and, uh, also support them with an innovation with, uh, the warmup stage.
And that was like, uh, the change. I understand how, like, the power of it and that, uh, I think that was the, the point that I understand that it, it's bigger than, than everything. And, uh, following what Joshua said about a family, I think that, uh, a supportive family is definitely, uh, you know, help with that job.
And also the ability to change and to help organizations and to make, make, you know, even a little bit the world, a little bit a safer place. It's just, it's a mission and support my team. I think the organization, build a stronger organization, be there for them, support them.
'cause it's, it's, it's a, it's a hard work. Very cool. And that leaves me, I'm Matt Knight, I'm CISO at OpenAI.
I've been at the company for just about five years. It'll be five years this summer. I joined as the first security hire to build the security program.
Been doing that since then. Um, question first was thought leadership, right? Okay.
The pivot, the pivot leader. I still consider myself a practitioner. Uh, and I hope my team does too.
I, I, I don't know what what thought leadership is. I just try to do good work and, and to the extent that I, you know, learn things along the way, I, I'm happy to share that too. Um, and I've had the privilege during my time at OpenAI of being able to lean in on experimentation within the program, right?
Finding ways to use language models to aid in our work, to find ways to help the team be more, uh, more productive, um, be in more places, move faster on things. Um, and, uh, that, that's one of the things that's, that's been most exciting about, about my time there is finding, uh, really making first contact these tools and finding ways in which they can help us. And with regard to how to stay sane, nobody gets into security because they love the status quo, right?
Like our, our industry, our work is, is defined by disruption. It's the very fundamental it to the, the extent that there's anything fundamental or foundational about it, it's change, right? So when you consider that this is really just a business as usual.
Wonderful. Well, thank you so much. I appreciate that.
And thank you for the friendly reminder. Yeah. Um, like I said, you guys are celebrities in my head.
So, and you know, our world is really interesting. There's no shortage of information coming at us, whether it's LinkedIn and articles and people calling themselves AI experts. I don't resonate with that word at all, regardless of how many years under the belt.
I don't know if you guys do, but I think we're all still real time practitioners trying to figure it out. Um, so if there is a space or time, I would say that follow the goats, if you will, the people that have been there from the very get go who aren't speaking by reading and regurgitating, but they're living, eating and breathing it. Um, tremendous props and respect to you all.
Now Josh, quick question. Um, there was a recent stat by MIT and it was published just the end of last year. About 70% of LLMs are vulnerable to prompt injection attacks.
It's funny, 'cause if you take a look at everything that's coming out, not many people are talking about prompt injection attacks. Could you do us a favor and explain to us what you think that means and the definition of it, and how meta is approaching resiliency, um, into the models to be able to mitigate that risk? Sure.
Yeah. Um, okay. Yeah, I was also gonna ask Jason a question about what he said, but I'll, I'll, I'll save that to later.
Yeah. Um, yeah, so actually I, I should correct, I feel like I should correct the MIT sta mean all, all LLMs are vulnerable to, to prompt injection. Um, yeah.
So first I'll just define what that is and then talk about what we're doing, which is probably not that different from what folks at philanthropic and open AI are doing also. Um, okay, so, so actually how many people already know what prompt injection means? Um, okay.
It looks like almost everybody, but, uh, so just, um, just for completeness, I'll, I'll give a definition. So, so prompt injection happens when you can caate an untrusted inputs with sort of trusted system programming in, in LLM and then the LLM, um, um, well, prompt injection is successful when the, the LM then follows the instructions that, that are given and the untrusted data. So to give a practical example of that, um, you know, so if I, if I, you know, program my LLM to take a system prompt that says, you know, be, I don't know, a helpful web search agent, um, you know, that's like the, that, that should be at the top of the instruction hierarchy.
So the system should always obey that, that system prompts, right? And then if the user says, well go, go search for like, where I should take of my vacation in France this summer, or something, um, that would be like, you know, in the instruction, in the sort of hierarchy of privilege that next prompt should, um, you know, take, take sort of next precedent after this, after the system prompt. com or whatever, like that should that, that, that, that, that should be overwritten, you know, by the system prompt, which is like, be a, be a helpful and trustworthy, you know, uh, like web search agents.
Um, like I I sort of fundamental problem with the technology right now is that we just don't know how to, how to ensure that in all cases, the, the large language model will sort of respect that instruction hierarchy. Um, and, um, so this is like a real problem with, you know, a number of cvs we have come out over the last year or two, you know, with like, real systems that are like really deployed in production, um, that, um, succumb to these kinds of prompt injection attacks. Um, so yeah, I mean, there's a few ways in which we're dealing with.
So, so one, one of the things that, um, the teams that I work with at, at, at meta, uh, are responsible for, are making sure that out of like the meta's whole universe of products, which is fairly large, um, in which AI is being integrated in lots of different places, like we make sure the teams aren't shipping products with like, severe prompt injection vulnerabilities, that, that affect our, our, our users security and privacy. Um, you know, a few things, um, that we do, um, are one, just refrain from using large language models when they're not really necessary. Um, and there's these prompt injection risks.
So you, you, you, you really just wanna not have, um, like, uh, non-deterministic risk risks in your application where, where possible. Um, so oftentimes that means just like not using an LM and using traditional procedural code depending on the product feature. Um, another thing we do is, is sort of restrict the privileges that we give large language models.
So, you know, what, what you don't want is your large language model, like processing a messenger over Messenger or WhatsApp, and then, you know, going and changing account settings sort of downstream of that as a function of like LLM decision making, right? Um, so we wanna like basically refrain from using LLMs in like sensitive cases like that where we can, um, and then there, you know, there's often like residual risk that we just can't mitigate. So where, you know, you can't both get the benefits of the AI technology, um, and also have zero risk, right?
So like an example would be like a research agent that goes out on the web and like does a bunch of research, um, and, you know, each decision it makes about, like, which sort of next piece of content it looks at, looks at, um, is made as a function of some previous piece of content that it looks at. Um, there, there's like, you know, there, there really are with, there's sort of research agents that are getting shipped into industry right now and risks that the control flow will get hijacked. Um, so there we do like fine tuning of our LLMs, uh, to make sure that they, you know, well not make sure, but, you know, to reduce the likelihood that they'll get hijacked, uh, by a malicious instruction.
We also have like system level guardrails, so like machine learning models that sit outside of the model that scan untrusted content coming into the context window of the lm. Um, and if they see something suspicious, don't let that into the context window. Anyways, I could go on about this, but this is, you know, I think this is a big active area of research.
Um, well, I'd be curious to hear about the other folks on, on the panel also, but, um, Yeah, that we're, that We're, I was gonna say for all of you guys, I mean, based on the state of ai right now it's in research, but as more and more folks go into agent ai, autonomous ai, um, and that's not a pivot that's really happened with an enterprise just yet, it's still at its infancy stages. What's that lifespan of it needing to get out of r and d and into a productionalized motion? Yeah.
Do either of you wanna jump in on this one? Briefly chime in. It, it really depends on your use case and your application.
Uh, AI is software. We've been managing risk in how we build and ship software for, uh, you know, for, for decades at this point. And it's about using the appropriate tool for the job.
So, you know, two years ago when I started, um, sort of sharing some of the work that we were using LLMs for within our security program, you know, the responses range from like, interesting curiosity to just like being aghast by the, the, just the, the notion that you would use an LLM in a security context. But the reality is that there are many, many places where language models are totally appropriate. Think like, um, you know, just something as simple as like summarizing what happened during an incident.
You might have a Slack channel of your, um, you know, your incident responders talking back and forth and, um, you know, there's, there's, um, uh, there's information, there's a timeline, there's decision making. And, you know, do you really need, you know, one of your, your detection engineers, one of your, your most valuable people, like writing a book report based on what happened? Or do you want them, you know, being able to use a language model, have that do the first pass, have them edit it for correctness, and then, uh, and then, uh, disseminate that and move forward.
It's a way of like reducing toil from the team's work and helping them move faster. And, you know, in that use case, like, I hope we can all agree that there's like very little risk to, you know, something going wrong. You, um, you're not actuating anything.
You have a human providing oversight and checking the results for correctness. Um, and this is something that we've been able to do, you know, for, for quite some time, um, using technology that was even a couple years old. So as the technology improves, we'll find more, um, ways in which we can incorporate it into our, our work and, um, you know, uh, find more places to take the hands off the handlebars.
But, um, you know, that's sort of where we started. Um, there's a lot more that we're doing today, but, um, it's just one thing I wanted to, to, um, reinforce is that at the end of the day, like we're building and using software, um, we can, uh, start with, uh, you know, there are plenty of places to start that are, that are low risk and expand from there. Um, so I think, I think one of the things I wanna, uh, like emphasize, uh, and maybe to answer your question about the research to deployment lifecycle is short as possible.
Um, everything that we just described and Josh's, uh, very excellent explanation of the vulnerabilities, the state of the art today could be solved. Like, if you just think about the way that we human beings, our neural networks interact with the world around us. Yeah.
It's sort of like, you know, you watch the Star Wars where, where the guy goes, these aren't the droids you're looking for. And that's like effectively what's happening with these large language models, right? They, they get the jailbreaker, they get the prompt injection through this sort of, what, what appears to be magic.
It's, there's no reason a neural network needs to be vulnerable to these problems. We just haven't figured out the right answer, um, from a, from a research perspective. And on Friday, Dario put out a call for action on his a blog, uh, saying there's like an urgent, urgent need for something called interpretability research.
And what this is already yielded is the ability for us to reach into neural networks and actually find a specific neuron responsible for behavior. And Dario said in his post, there's a strong possibility that we can actually systematically solve jailbreaks and prompt injection with this technique. Like think about a a, a world where as the neuron, the, the neuro, um, the neural network is executing the, um, the, uh, the, you know, over the token stream that's coming in, you can see a specific neuron that's like, oh, I'm, I just received an instruction.
I should follow the instructions. You know, you could just see like the lights turn on from a neur, uh, like an actual and introspection's perspective. And that would be an indication that you're untrusted input cross that threshold from being context into a command that the neural network is now, now following.
Um, very, very exciting early, um, research in that space. And, um, there's so many other things. OpenAI has the prompt coloring work and the prompt hierarchy work that they published, uh, through, through scientific papers.
So there's a lot of stuff that we can do that can make this a lot better. So I'm very optimistic that we can, we can make it con confidence can be something we can share with enterprises. Yeah.
I'll take it to the, to the production area, the notion to production. Uh, I totally agree that it's easier to adopt LLM especially when it's like it's internal stuff, it's internal data, uh, but everyone are talking about MCP, right? Everyone wants integration.
Everyone wants to prepare the, the business for it, get ready because it's easier and added value when the business is like, really, it's a crucial, crucial mission. And there is like added value to the business to adopt it. So I think it's not a matter of of time, it's just, it's gonna happen.
That's it. So security need to adapt it, need to reinforce it and, and support it with the best guardrails that we have today. And as the research will developed, we'll adapt more and more technology move from the spiritual, the guidelines, the best practices, the audit that we can perform to much more practical, uh, solutions.
Um, and, and, and I think that it's, it's, it's something that is already happen happening. Uh, I can tell you that the early production step that we took was around cybersecurity and also customer success, customer support, replace the chat bot with something much more autonomous that really drive the business fast and, and make things easier. Yeah.
Wonderful. Um, I'm gonna go a little off script here and ask all four of you guys a question. And I purposely did not prep you in advance because I genuinely wanna know if, if there's a difference generate, do you think there is a difference between what we classically know as InfoSec and what's now being called cyber tech?
So information security, which is part of a vertical within enterprise data management. Mm-hmm. And then now everything, I don't know if it's a Glossier version and we're calling it cybersecurity or if you think it's actually a separate vertical.
Um, but I'd love for you guys to define the difference if you feel there is a difference between InfoSec and cybersecurity. I can take that. Yes.
First. So, 'cause I'm here for 25 years since it started to call, like, uh, InfoSec and then everything's changed to cybersecurity. I think that the mindset is the take it to the practical level from procedures and policies down to earth, to prac to practitioners.
And also when security, uh, took in charge of the DevSecOps area, the product security, I saw so many CISOs that didn't pass the, the transition and hold the product security take in charge, give it added value, support the r and d, the product and engineering with great tools that collaborate with them. And I think that the notion to the DevSecOps and the cyber security and, and the product security themself did the transformation because it's no, it's no longer information security. It's, it's everything.
It's very holistic. It takes, uh, several, you know, core partnership with all the different collaborators and make it something very effective. So I think that was the notion, um, the DevSecOps, the tools being collaborator and, uh, and actually accelerate the product.
Now I can tell you that it's, it was like 20 years ago when cybersecurity war blockers, like no, first of all get, you know, get cyber security or InfoSec approval or block, uh, with firewalls, approve the rules, those things that we don't hear them anymore, right? Mm-hmm. Like, allow me to do something, let's approve that.
It's not, it's not longer. Uh, um, the mindset. We are accelerators.
We are, uh, business partners, um, the organization come to cybersecurity to get the best advice and, and partner with us, uh, because they, they see the added value. 'cause they, you give them trust and your partner, your technology, you understand faster than sometimes even faster than the p and e. Yeah.
And take it to the next level. Thank you for that. Matt, Josh, Jason, do you think there's a difference between InfoSec and cybersecurity?
Or is it just a semantic evolution? I don't, I don't get too hung up on definitional stuff. Okay, Perfect.
I mean, yeah, me too. I guess I, I just remember like when I was a kid and like a high school like hacker calling security cybersecurity was seen as like a, a tell that you had no idea what you were talking about. And now it's like the accepted term, which is, it's interesting to see it.
And same in machine learning. Like, you know, for a long time calling ML AI was like this weird thing that you did, and now we're all doing it. So I don't know.
Um, but, um, I, I was gonna say, okay, so this is a little, little bit of a pivot from your question, but, um, I do think there's interesting new things happening in our field due to what Jason was talking about with respect to the need for like an identity. So like, if we assume that we're gonna enter a world in the next, I don't know who knows what the timeline is, but two to four years in which we have AI colleagues at some level, you know, where you can talk on Slack with an AI that is off programming, you know, and solving your programming problems and then sort of pings you when it has a question and needs resolution and this sort of thing. Um, yeah.
I, I think we will need, um, I think this is what you're getting at. Like, we, we'll we will need like a, like a modification, um, of our like, identity infrastructure, right? To like, um, where like, it's like clear, like, you know, and there's some guarantees around like, um, like the audit log that like, you know, this agent was act acting on Josh's behalf, like when it commit, when it like, you know, whatever it, if you, this pull request and this and this, this sort of thing.
Yeah. And like, um, I do think security will change if, if we, if we accept that like, like we will like sort of move pretty quickly into this world in which we have, um, AI assistance and colleagues doing things on our behalf with increasing autonomy, um, like authorization, authentication, identity. Yeah.
You know, and, um, um, how we deal with sort of least privilege with respect to these sort of like colleague like entities. Like all the, all this stuff will have to change. And I think that'll change the shape of our field.
I dunno what we call that, but Yeah. Yeah. I, I, I like the question, and it sort of ties back to what Josh has said here.
I think, uh, David Bryn was, uh, on the stage here last year and he had some stuff about ecology. Um, and I think when I think about like, the evolution of the security practitioner over the last three decades, it's moving from like being in a silo to being integrated with the entire ecology of tech. And as we think about virtual collaborators, they're gonna be, uh, we will try and we will to some extent succeed at like defining boundaries and trying to put least privilege around where we, where we can.
But I don't know, if you just look at, um, something that's I've been thinking a lot about lately is MCP is exploding in a, in a very, uh, it's crazy, very fast and very rapid way. And that's like, I'm just gonna give you access to all of these things. You know, my, my own personal assistant running on my, my machine is access to all of these things.
Um, and, uh, we are going to have to be very flexible. Uh, 'cause things are gonna move very fast. Um, and as we think about cybersecurity and cyber, cyber tech, and all of the things that are gonna be happening over the next few years, um, this, this evolution, this co-evolution of the security practitioner and, uh, the technology is gonna be really important that we stay embedded and we stay, um, uh, even federated with product teams as they try and move fast.
Wonderful. Thank you. All right.
Um, we have a few minutes left. So I did wanna ask Matt, maybe we'll start with you. I think for any of us, whether you're in startup, enterprise, mid-level, there's always this constant battle between speed of innovation while securing your ecosystem.
Um, I haven't seen anyone who's gotten it like correct or right, and I don't even think there's a right answer, but the question I have for you is how are you guys approaching, um, especially within your position, that balance between speed and security alongside development to make sure that there are processes and protocols and documentation, which is very time consuming while doing the work. It's kind of like you're flying the plane while you're building it at the same time, but you don't have enough folks to do either or how are you guys handling that? So I'll talk first about, um, an effort that OpenAI does around its model releases, um, uh, to test and evaluate models before we release them.
And then I'll talk about how we incorporate, um, perfect. Uh, that's sort of those, so similar, the, the principles that you were asking about within our security program. So first for OpenAI, so, um, you know, OpenAI is a mission-driven company.
We're, we're here to make sure that AI benefits all. Um, we take that mission very seriously. Um, one of the things that we do before we release models is we test them for a series of, uh, capabilities and risks.
Um, we have a testing methodology that we have, um, uh, publish. It's called a preparedness framework, uh, that, uh, spells out the battery of tests that we put the models through before they get released. Um, there are a number of categories that we, we test them for.
Um, cybersecurity is one of them. Um, and the testing is a mix of, uh, sort of, you know, repeatable automated testing, and then some, uh, that we do with, um, with expert red teamers. Um, all this factors into, uh, attempting to get a holistic picture of, um, of, uh, what these models are capable of before we re we release them.
And this is an evolving science, right? It's, it's one that, um, we expect to continue to evolve. And if you wanna know more about our, our methodology and our approach to this, um, I recommend that you, um, a read our preparedness framework, which is published online, and b, take a look at some of the system cards that we published along with our recent models.
And system cards are, um, artifacts. They're sort of like, uh, you know, data sheets or reports that, um, describe, um, uh, describe sort of, you know, what, you know, what's behind the model and, uh, and what, and what, what, what is it capable of. And they extensively go into these, um, uh, these tests and results.
And I think they're really interesting. Um, actually just last night I was rereading the O three, um, system car report, um, uh, in some of the, the work on cybersecurity, which if you stay for, uh, by talking a little bit, you'll, you'll hear a little bit about. Um, and, uh, I, I think it's super interesting personally.
Um, so I hope that gives, uh, gives some perspective on how we approach it, um, from managing model risk. Um, with regard to our security program, you heard me sort of allude to it earlier. Um, you know, we've taken a, um, sort of a qual crawl, walk, run approach to how we incorporate these, uh, these tools into our work.
Um, you know, we've, we started with a number of, uh, you know, we started years ago. Um, it would be malpractice for me not to attempt to use language models to help our program just because they're so powerful and we have, um, some really incredible tools and we wanna wanna use them. Um, and some of the, the first, uh, use cases that we've started with are ones that, um, you know, are pretty, pretty, pretty evident.
They were right in front of us. Things like, um, uh, you know, I, I shared that, um, uh, incident summary, um, earlier. Um, we have a number of other, uh, use cases that we've expanded into, some of which are a little bit more, uh, more interesting.
Um, I'll talk about some of those in a little bit. Um, don't wanna steal my own thunder there. Uh, but I hope that that answers your question.
That, um, both from, you know, the model evaluation side and how we incorporate that into our work on the security team. And what about that balance between speed and the innovation? Because it feels like you guys are releasing models every month, um, outside of having a giant army.
Like how are you guys, what's the mental mindset of balancing the two? So I, I don't think speed is necessarily a dirty word, right? Mm-hmm.
I think it's about doing the work and, um, you know, um, I think you did a great job of, of saying earlier that like, you know, it used to be that security was like the blocker at the end of the Yeah. End of the road. It's, you know, there to sort of, you know, uh, deliver, deliver, uh, be the hook, deliver justice, or, um, yeah.
Uh, you know, judgment at the end of it. Um, and, uh, you know, I think part of, you know, doing this well is doing it, you know, in a way that's, you know, efficient, repeatable, and, um, helps the organization meet its goals. Okay.
So that begs me to ask then I could just jump in real quick. Oh, yeah, please. Uh, a couple more thoughts.
Um, so, uh, I do think the Matt's point about using the, the technology to actually enable the speed, like the innovation enables the safety and the speed to to be done in, in, in parallel. So there's a couple things that are going on in this space that I think are really fascinating from security protection, uh, practitioners mm-hmm. Uh, side that I think are worth, worth calling out.
And everyone in this room who's in DevSecOps, I think should, should be thinking about these things. Um, so, so the first one that I wanna call out is more than half of all the coded philanthropic now is being written by Claude, which is, um, mind blowing. And I think probably by the end of this year, it's gonna be closer to 90% of all code.
Um, when we think about the actual code that introduces bugs, we want these models to be producing correct, um, uh, code to begin with. So there's a question of does the model generate correct code, which could be done through fine tuning. Um, there's a question of using models to find bugs in the, in the code that was written by models.
So there's like a, a second like peer reviewer aspect of these things. And philanthropic has adopted, uh, AI for code review internally. Like the, you know, I think we, we think of code review as this gold standard of like, you know, you know, your peers like, oh, there's the bug, I'm gonna make it, you know, can make it make it so it doesn't ship to production.
But I think we all know that like, human code review is maybe like 25% effective or something like that. Maybe that's a spicy take. But, um, if AI is 90% effective versus 25% effective at finding bugs, like that's a massive uplift Yeah.
In our ability to stop shipping bugs to production. And I personally would like to go back to being a software engineer and, and step out of being a CISO eventually. And if we can just stop shipping bugs to production, I, I wouldn't have a job anymore.
So I think, I think I are looking forward to that. So, Yeah. So it's funny that you mentioned that I am gonna ask a question at the very end around intellectual atrophy as a result of leveraging large language models to do a lot of our work.
But just a quick show of hands. I know we've all heard about a variety of methods in which we can use LLMs and various applications of artificial intelligence to write the code, but within your organizations, how many of you are using AI to write your code for less than 20% of your systems applications within your, the totality of your ecosystem? Few hands.
Okay. Less than 50%. Less than 80%.
Okay. Or I would assume the rest. And you guys have completely allocated all of your code writing to LLMs, or you don't wanna answer the question, how many of you guys are not using LLMs to write your code yet?
I think that's the better one. Okay. Fantastic.
Thank you for that. Um, Miranda, quick question for you. It's so funny because I think in our world right now, we hear about what amazing things the startups are doing, what amazing things the tech companies are doing.
Um, but enterprises are still fundamentally struggling Yeah. With scaling any application of ai. And like if you take a look at the stats, and I'll share some of that in my keynote, it's, it's not really optimistic.
Um, from your perspective, what are some of the practical things that you think are prohibiting enterprises from actually being able to take these remarkable capabilities, um, and scaling them within the enterprise? Yeah, I'll start with the bottom line. The bottom line is, is trust.
Yeah. It's a matter of trust and regulation and friction between the already, um, uh, the technology is in compared to how fast we wanna do that. Yeah.
So I can share a practical thing that we did in order to scale. We build internal skeleton when everyone were a part of that, the legal, uh, that take and understand better and educate and train their teams to adopt AI, to really understand the barriers and where we need to, to change our mindset instead of like the friction of we don't know how to handle that. So it's around training.
Um, the second thing is the p and e, the r and d that really understand what is going on and how much it cost. So it's a matter of cost as well. Yeah.
To try to assess how much it cost, what is the ROI and the business value. And then security come jump in and said, okay, we need to train our people as well, uh, educate ourself and be able to use AI in order to do diligence the models and create some kind of skeleton that everyone can live with. And then give it to r and d to do the magic, to build their, uh, features very fast.
And once you have some kind of structure like that, there is like a committee, uh, AI committee that supported. So if someone wants to create new idea and create new feature, it's really a ramp up. It's a very fast to do that.
Yeah. With a skeleton in place. Wonderful.
Now I was gonna add Oh, it's okay. I have like a Thanks so much. Um, yeah, like, I just wanted to add on the question of applying IT security.
So, so, um, I feel like I've lived through at least like two years of, of us trying at meta to apply large language models to various kind types of security, like sort of various sort of bread and butter and security problems like finding bugs and code. We have like this huge legacy code base that we, you know, and are like automatic program repairs, so like finding and fixing the bugs and this kind of thing. And, um, I, I think that, I think large language models are, are particularly slippery, slippery, slippery kind of technical object because they're totally open-ended.
Like, like you interact with the chat bot and it feels like you're interacting with a person and you, and I think I think the people's default mental model when they're just sort of going into this is that, oh, well we should be able to employ this everywhere. And, um, like we've had brainstorming sessions in the security department of Meta where like, we like list out like all the, all the ideas around how, like where are we gonna apply the, the lms. And like, it's like literally people just are, engineers are just putting in like everything, you know what I mean?
Like, um, yeah. And like 90% of those cases don't work, you know? And like, like what I found is like if you have a lot of hands-on experience, uh, applying LLM security, you can sort of eliminate 60% of those cases.
I think just AP priori, like based on your own intuition. And then like, like another 30% have to be eliminated through like sort of failing fast and rapid prototyping and then like you left with like 10% where, um, they actually work and like there's a lot of value and you can actually automate stuff, you know, but it's like very different than like buying some sort of like B2B SaaS solution that like does, like you're hiring that project to do like a very specific job and it's like a mature area. Like, um, so I think that's a big, big challenge with adopting these technologies.
Yeah, I I just add to that, that by the end of the day, AI agent mm-hmm. It's a software and we need to treat it as, although there is a model behind it that we don't know what it's gonna do and cannot predict what the, their prediction will do. By the end of the day, as a security practitioner, we want to implement security within the layers exactly like we are doing with any other feature.
Yeah. Like secure them, scan them, put the SBO to understand the dependencies, which models they're, we are using due diligence, the models understand that it's not a malicious one. Um, be able even to sign it, like make sure and confirm that this is a model that has been through and within evidence with at the station, that this is the model that we, we tend to to use and nothing, no one changed it along the supply chain.
So it start with the models, continue with the diligence one, the one that, uh, privacy and legal approved and, uh, read everything and, and feel comfortable with that is not illusion from security perspective, from red teaming, uh, uh, issue. Definitely do all the tests that we can from, you know, tools, automatic tools, and also with code review, uh, use AI to code review things that we cannot predict with the human, you know, uh, review and then all the way just to production. So implement that with the layers.
Using that as a jumping point to this, 'cause we're gonna be wrapping up. I have one philosophical question for everyone, and Matt, maybe we'll start with you. If college students are using CHATT PT to write their essays for them, if we have practitioners who are using artificial intelligence to summarize and research and audit for them, if we have software developers leveraging large language models to write code basis for them, do you think that as a civilization, as humanity, we could be experiencing intellectual atrophy?
Because if you have not mastered your craft, AI can amplify your abilities if you are subject matter expert or you've mastered your craft. But if you're still learning a craft and you leverage artificial intelligence to accelerate your work, I can't help but personally feel that we're bypassing the learning process and short circuiting the very thing that makes us stronger. Um, so I call it intellectual atrophy, kind of the numbing and the dumbing of our intellectual capabilities.
If we just aren't fingers to keyboards, do you think that's a possibility For us? It's a really interesting question and it's aptly timed. Uh, just two or three weeks ago, I spent, um, spent the weekend back at, back at Dartmouth, my alma mater speaking with, um, you know, their leadership about, you know, what it, you know, what it means to train future leaders to, to harness this technology to look forward.
I wanna first look back, um, you know, when mankind invented the abacus or the calculator or these, you know, computational tools that are now ubiquitous, we didn't stop doing math, right? We started doing higher orders of math. It unlocked more frontiers and it allowed us to be more creative, to think to, you know, to to look at further horizons and, and do more and move forward as, um, and, and move forward.
Um, I I think this really, um, uh, in, in a similar lens, right? Um, so rather than, you know, um, I think as you, as you would frame it instead, I think it puts more emphasis on our ability to reason, to think critically, uh, to use what it is that makes, makes us unique and powerful, um, to use these tools to the fullest extent. And they can help us with a lot of the toil, a lot of the, the, the drudgery, a lot of the legwork to enable true creativity on top of it.
And that's, that's how I've been thinking about it. Mm-hmm. Okay.
Jason, do you wanna give it A shot? Yeah. So, um, uh, will we end up in the wall lease scenario where everybody has a floating recliner and they're just sitting a surf?
I, I, I, I don't think so. I think, I think what I, a lot of, a lot of these public speaking engagements after afterwards, um, there'll be like an 18 or a 20-year-old who's going into computer science come up to me afterwards, and they have like a look of terror on their face. Um, and I think my advice to them is, is to really lean into what they're passionate about.
If they were, if they're just going into computer science because they, they thought it was a high paying job, then maybe it's not the right fit. But if they were doing it because they really love the computer science or they, um, they think that the, uh, this is a, a place where they find curiosity and excitement, that's an opportunity for us to, to Matt's point about creativity and, uh, lateral, um, movement in the way that we think about problems to be more, uh, of an opportunity and less of a, um, a pitfall. Hmm.
So there's, there's this, this, uh, this opportunity. I think like, you know, let's say that every software engineer is a manager of a team of AI employees in five years. Um, okay, well, you need to be good at management.
Like, yeah, if you, if you've been thinking about like, well, what does it mean to, to have, uh, good cohesion between, um, uh, you know, coworkers and, uh, clarity on road mapping and understanding of where we're going, um, as an organization and what the business needs are, you can't ignore those things in your, in your education anymore. You need to be actually focusing on the, the big picture and not just the narrow, like, how do I write code? Um, mm-hmm.
Yeah. Wonderful. All right.
We're over time. So 30 seconds if you wouldn't mind, please. Oh, okay.
Yeah, I was just gonna add, I mean, I think I agree with everything that was said. Um, I mean, like for me personally, I've found, um, generative AI to be like a bicycle for my mind, and I've learned more than I would've had I not had that. And, you know, I, I can get personalized instruction on any topic in the world, you know, and I mean, you know, um, that said, I do think that we have an opportunity, like, like we have a responsibility as tech leaders to sort of guardrail, like, I mean, I'm sure you guys all agree with this already, but like, I mean, so very locally, you know, um, so if somebody, if somebody on my team is using an LM to like write the lit review for a paper or something, like, you know, we need to create a culture in which they're accountable for every word of that, that review.
And like, there's like, but there's all sorts of cases in which this needs to be guard railed, right? Like in terms of the way education gets shaped, you know, like in, you know, I mean education I think right now is set up in such a way that's probably not like, um, sort of optimally adapted to, to this new technology, you know, in which students can screenshot their homework and get all the answers and this sort of thing. Um, so I do think we have a respo.
I think the technology is powerful, it has an enormous potential, but also we need to think about ways to sort of nudge it in the direction and set up sort of guardrails and institutions that sort of adapt and bring out the best in then. Okay, I'll just mention take us home really quickly. Yes.
Really quickly. Just give it a metaphor. And, and the way I see it, it's still just a copilot.
It's not a pilot, it's just, it can accelerate, it can help you, but it's not a pilot. It won't replace the human mindset. The challenge, the innovation, the passion, it can change that.
It just can accelerate, it can really fasten the current education, uh, of reading so many books and just like summarize it and curate a deep research and, and learn fast. But it won't to replace like the pilot, the same goes for the CISOs. Um, in my mind it can really help with, uh, create some kind of AI incident commander that will help us and advise to do that very fast.
But in times of critical incident, you are the pilot. Perfect. Thank you all so, so much.
And Thank you for attending today. Hey everybody, are you confused about tariffs? Join the club.
You're watching Textron Gang. We'll be back in a minute. Hey folks, welcome to the Textron Gang for today.
I'm Mike Ard, your host. Joining me today is Dan O'Brien, who's president and COO of the Futuring Group and Chris Blas, and also new member Kate Scarelli. She's been on the show a couple of times now, but if we haven't caught a couple episodes, K is a security expert and does a lot of work in app dev, so, you know, plays both sides of the ball as they say.
Folks, welcome to the show. We're gonna have a little chat up early here now about what's going on with all these tariffs because if you're like me, I'm having a hard time frankly keeping score. Um.