Techstrong TV March 12, 2026
Taming the Observability Data Explosion: Ronit Belson and Erez Rusovsky, co-founders of Sawmills, introduce an agentic telemetry platform designed to shift observability left—reducing runaway data volumes and controlling observability costs as AI-generated code accelerates software development.
From CLI to NetOps: Ahmed Abutaleb explains how Nokia modernized its data centers using Nokia SR Linux and Nokia Event-Driven Automation, moving from manual CLI-driven operations to automated NetOps practices with stronger traceability and drift control.
Standardizing the Agent-to-Human Connection: Zachary Hanif of Twilio discusses the new A2H (Agent-to-Human) open-source protocol, designed to ensure AI agents request verifiable human consent before executing actions in regulated environments.
Future of Agents & Apps: Ryan Cunningham and Daniel Newman outline Microsoft’s vision for connecting apps, agents and interfaces through Microsoft Power Platform, enabling organizations to build and govern intelligent applications at scale.
Agents of Dev Podcast Ep. 13: A deep dive into how development teams are adapting tooling, architecture and governance to manage AI-driven software development and agentic workflows.
Closing the AI Trust Gap: Experts examine the conditions required to deploy trustworthy AI systems—including operationalized security controls, verifiable reasoning, and carefully calibrated human-in-the-loop oversight for agentic workload
Transcript
Hey, everyone. Welcome back here to Techstrong TV. You know, nothing makes me happier than to introduce first-time guests here, new companies to the Techstrong team.
And so join me in, in welcoming Ronit Belson and Erez Rusovsky. Uh, Ronit and Erez are the two co-founders. Ronit is the CEO, Erez is the CPO, chief product officer, for a company called Sawmills.
Don't worry if you haven't heard of them, we're gonna tell you all about. Ronit, Erez, welcome. Welcome to Techstrong TV.
Thank you. Uh, thank you so much for having us, Alan. My pleasure.
So I, you know, I usually start these off, especially when I have founders and co-founders, I want our audience to understand a little bit about the people they're talking to. What drove them? You know, founding a company is not something you do lightly.
" No, the, it, there's a passion driving you. You feel that, that you're doing something that's important. In some-- it may not be important for world peace or something, but for a certain group of people, whatever, it'll be important.
Erez, I know you've, you've done this before. Yeah. Right?
Um, give us... Well, let's start with you, and then we'll go to Ronit. But let's start with you.
Give us a little bit of your background and kind of what was your passion for Sawmills? Yeah. So, thanks, Alan.
Fi-first of all, I have a technical background. Used to do system DevOps for a while. Then had my own company in the dev tool space.
We did feature flagging as a service, scaled that and sold that company. Uh, and then, you know, I was, working at the acquiring companies at the time called CloudBees. They did CI/CD, and, building pipelines, CI/CD pipelines.
Um, and I think, one of the things I kept on seeing, w- with Ronit, which is a good friend that worked with me in the past, we, we kept seeing a lot of problems around observability and around, the amount of data that, is, is generated for observability, right? And when we-- I saw this internally, I saw, I saw this in the past from past experience, and I saw how that data is basically unmanaged and just creates a lot of downstream pain for both the engineers, in DevOps, SOE. So I think, I think we-- I kept seeing this and encountering this across my career, and you know, it was always there, but I didn't do anything with it, until we did something with it.
So I th- so I think that's kind of the background for me. I love it. Ronit, you heard what Erez says.
Let's hear a little bit about your journey and your passion. Sure. So, before starting Sawmills together with Erez...
By the way, we have a third co-founder. Our CTO was VP of engineering at New Relic- Mm-hmm ... in charge of their AIOps.
So we had, we had three co-founders. Uh, before starting Sawmills, I was actually at a company called Tricentis. I was a GM- I know it well.
So I was, I was a GM of the, testing business unit. Got there via acquisition. They acquired the previous company I was COO of.
I've done it a few times. I was actually three times COO of companies that were acquired, one by Splunk, one by Tricentis, one by CloudBees, where I worked with Erez. And I actually started my career many years ago in the observability space before it was called observability.
So I've seen the- APM. Observability is not new. It's just a new name.
No. Uh, a little bit of different, technology, but the, the idea of needing to, solve, observability issues have been around. And what drove me to do it is, Erez, as Erez said, we figure out that there is a huge problem in the DevOps engineering space around the amount of data that is created today.
And that was, um... When we started to talk about it, it was two years ago. This is pre-agents, and even at that time, pre-AI, even at that time, the amount of data that was-- were sent to observability solutions were growing exponentially.
That had consequences, two main consequences. The first one that we kept hearing is cost. The cost of the observability solution is just getting out of control, and it is directly impacted by the amount of data that is, is being sent to it.
The second, it... At the end of the day, junk in, junk out. If you send a lot of data that you don't need, it's much harder to make sense out of the data.
That was prior to AI. Think of the last twelve months, where a lot of the code is written by, coding agents, by AI. Observability, telemetry is an afterthought.
That means that the data that is sent today is not only growing exponentially, I don't know what's more than exponentially, but whatever it is, it's what's going on today. A lot of data sent to the observability solution without being managed, low quality, incredibly high cost. And this is the problem that we came to solve.
We wanna give control. We wanted to give, this is what we're doing, give control back to the DevOps, back to the developers over the amount of data and the quality of the telemetry data, if that makes sense. Long answer- Makes perfect sense ...
or perfect sense. No, no, it makes perfect sense. You know what?
Maybe their parents are watching. The third gen-- the third co-founder's name, we might as well mention him. What's their name?
Amir Jacobi. Excuse me? Amir Jacobi.
Amir Jacobi, okay. Well, we mentioned him. Okay.
Um, look, I, I hear what you're saying, right? This has been a problem in observability-When we called it APM, right? You-- First, first the question was, can we capture everything?
And then when we figured that out, it was, do we want to capture everything or do we want to store everything? We can't afford it. And so what do we keep?
What do we not keep? What do we act upon? What do we not act upon?
Now, AI represents maybe our best bet at being smart about observability, but at the same time, AI has created new, new attack surfaces, new vectors, new challenges that it seems that ob- only observability is gonna be able to help us meet these new challenges, these new threats. So it's like, it's like a double-edged... It's not even double-edged 'cause it, at s- at, at some-- it's a double, like a squared, if you will, right?
Problem squared. E-- We, we got all these new attacks that we're gonna use or potentially could use. We need observability to help fight against them and understand it, but observability is out of control.
We need to use AI to get more of a, a handle on, on observability. And it sounds to me that that, that intersection is where Sawmill lives. Absolutely.
You nailed it. Um, observability is going to change. Observability is critical when it comes to AI, when you have so much new code that it's being written.
At the same time, you need to make sure that data that is sent to observability solutions is optimized. The- Yeah. The optimization of that data when it comes to AI just becomes so much more important, and that is what we are doing, right?
We've done it before AI, and we're doing it now. And what we are, what we are now launching is actually the first, agentic telemetry management platform. I love it.
I love it. Yeah. So as you said...
Sorry. Go ahead. Go on.
No, no, go. As you said, AI also gives us the opportunity to finally, with a real agent, manage that tele- telemetry data in a way that was not able... we weren't able to do before.
It's continuous optimization. It's with, with reasoning. It's with loop back from what you actually see in production happening back into the way the code is written, the way the CI is, is, guarding it, is, is, analyzing it, and then back into production, if that makes sense.
It makes, makes-- To me, it makes perfect sense. Um, so look, we've been... Here at Textron, we've been going through our own agentic experiments, let's say over the last month or two.
got us all crazy, right? We're all, we're all experimenting. I have all these digital coworkers now.
Everybody here is making their own digital coworkers. The security issues we worry about, right? And, and everything else.
It, it, it's a new thing, but it seems like security issues or not, the train is leaving the station. We all recognize now the power of, of these agents and, and what they could do. And it, it almost seems like it's made for the observability problem, right?
'Cause observability during-- when the sun is out only isn't observability, it's only partial, right? Mm-hmm. We-- In, in order for observability to be used in the way we want to use it here, this new kind of security posture, it almost by definition has to be continuous.
It a-- it has to be, you know, twenty-four/seven, it never down. Mm-hmm. And, and to me, how do you do that without some sort of a-agentic processes, right?
Um, but let's... You know, Irons, we haven't heard from you as much since the beginning, but challenge is building this. You gotta build a secure agent.
It's gotta work. It's gotta be always on, right? Mission critical.
Yeah. It's not like AB testing. No.
So I think, I think... Listen, I think, agents today have gone a long way. Uh, but, you know, if, if you, if we talked a year ago, it would be still, you know, something that everybody wants but, not everybody has.
I think today we are finally at the point where there's real agents. Not everybody has them, but we are happy that we've built one. Uh, and, you know, obviously security is, is a concern.
Uh, but I think, I, I think... Listen, where we're excited about is the value, right? Being able to have, an, a agent that is-- has an objective, that is looking at, optimization, both from a cost and quality perspective, all the way from the pipeline to the code level, and optimizes continuously.
But the, the interesting thing is that, listen, there's still a human in the loop, right? So in many cases, you would need to notify someb-some-somebody on some change, and to ask for approval, and to follow up, and to follow up with an engineer, or to follow up with the SRE team, or to follow up with the DevOps team. That is all today possible, right?
You could converse with the agent. You could ask the questions if you have a question. And so I think the whole operation of managing something, and we're-- again, we are focused on telemetry data, I think that is, is, that is coming to light.
That, that is the real change. Uh, you've mentioned having a coworker or, or a digital, team member. That's exactly what we're aiming for.
That's exactly what we're seeing. And that team member could automate a lot of the stuff that was the grunt work, the, the, the tedious work that nobody wanted to do and was always neglected, right? Now, an agent could do that for you in a better way, as you pointed out, always on, always connected, always looking at things.
But good. Ronit, I'm sure you've spoken to many customers, potential customers. What are you hearing from them?
Are they ready to accept an agent, an agentic solution to their observability woes? Right. So, I can, I can talk about the telemetry, right?
The telemetry that feeds the observability. And I can talk about what I see around AI. They all...
I think at this point, they all understand that they need a solution. They all understand the value in-- of AI, and I think the openness to use an agent to solve the problems because of the size of the problems is there. Was it there a year ago?
Not so much. I think companies at that point were dubbing a little bit with AI. Six months ago, they were dubbing with AI.
At this point, they're very open and in a sense are almost looking for a solution that will do it in an agentic way rather than in a, in an LLM asking question or manual way. Yeah. I, I don't- It's a practical problem in a sense.
The problem is big enough, they'll look for a solution that will solve it. Let me ask you, and I'll throw this at both of you. Whoever wants to answer can answer.
One of the things we're seeing in the market is with the use of AI , I don't need to necessarily reuse open-source components that I didn't write, I don't know is secure, what have you. I-if I want it, I build it myself, in essence, right? We, we've seen.
The, the numbers speak for themselves. More people are just building what they want rather than downloading from a repo from a, an OS component. How does...
Now observability on the other hand, observability's been built on the back of Hotel, Prometheus- Correct ... Grafana, you know, some of these big open source projects that help, you know, kind of even the playing field around observability and, and collecting telemetry. Is, is this agentic, platform have OS under the covers, so to speak, or, or you following the new model, which is I build it all bespoke?
Erez, you can, you can answer that. It's a little technical. Yeah, no, it's- ...
it's, it's fine. I think Ronit can answer this as well, but, but I-I'll say two things. A, yes, we have an open source component.
We are leveraging the open telemetry collector, as, as, as a way to basically collect and stream telemetry data. Uh, so that's, that is important on that side of the house. Um, I also think, that, you know, again, what we're building is augmeting, augmenting, observability.
Uh, a-at, at the end of the day, you know, as we all think, it doesn't matter if you use an open source solution or a commercial solution, the, the belief system is that a lot of the observability workflow would be agentic, right? Uh, and i-in order for that to work, you have to have great data. You have to have high quality data at the right places at the right time.
So what we're focusing on is getting that data, to the high most quality and at the lower cost, right? Finding all the gaps, removing all the noise, right? Uh, and so we, we care less about if you're using an open source solution or using a commercial solution.
That's kind of where we're focusing. Got it. So when we use the word platform, generally with a platform, there's an ecosystem, right?
I realize this is brand new. You're a fairly new company, just came out of stealth a year ago. The platform itself is new.
But is the plan to be able to support sort of third party partners who would leverage the platform, maybe have their own agents, use your own agents, APIs, MCPs? Absolutely. Yes.
Uh, we do have MCP, we do have CLI that's part of our launch. Uh, and I think the new world ha- you have to live within a very, robust and dynamic ecosystem. I think the, the, the world of I, me, and I'm not talking to everyone, and you need to use it my way or the highway is gone.
You're there to help customers. If the customer wanna use our platform and our agent with the agent interface, that's great. If they wanna use it with an agent that they build, that's great as well.
Uh, so o-our belief is that we need to be as open as possible to what fits the customer's model, not our model. Um, so that's one thing. And the other thing I'll say about o- ecosystem, we're not replacing observability solution.
We are integrating with whatever that you use. You wanna continue using your Datadog as your observability solution, that's great. New Relic, that's great.
Grafana, that's great. Whatever shipper you have on the other side, whatever agent sends the data, that's great as well. We are there to optimize the data, as what Erez said, for cost and quality.
Continue using whatever you, you, you use. So we, we are strong believer in ecosystem and being a good player within that ecosystem. I love it.
That's great. You, you, you almost answered my next question, which is, you know, some... Observability used to be something we observed after an application was, was deployed, right?
But over the last few years, the, the, a lot of the action in the observability space has been on pre-deployment observability. Mm-hmm. It looks from what I'm reading and hearing and seeing that you have a big focus on that pre-deployment.
But by leveraging things like a New Relic or Datadog or what have you, i-it's really a, let's call it a three hundred and sixty degree view of observability. Yeah. Yeah, I think, I think one thing to mention over here, and, and this is something that we're launching now, which is kind of new.
One, one of the things we understood, if, if you look at developers today, you know, th- their field has completely changed, right? Um, most of the code being written today is written by agent, right? It's not the autocomplete anymore.
It's, it's agents doing the whole thing, right? And so, observability or instrumentation is being neglected, right? Um, you know, I don't know how the agent instrumented my code.
I don't know if it's sending the right metrics. I don't know if it's adding the right logs, to the code base, if it's following the standards, you know. So, so what we are doing is that we've added the capability of, of our agent to also review the code from a instrumentation lens, lens.
So now we can look at the code and understand is telemetry written correctly. We i- we close the loop because we see also what's being printed in production or when the application is running, and so we know how to stream that knowledge, that learning back to the, agent that could actually improve how telemetry is instrumented in the code base. And so to your point, we're moving the, the instrumentation or, or the, idea around observability to the left, to the engineering side, to the actual writing of the code side, because that is gonna be a major gap looking forward at how applications are written.
Agreed. Guys, we're almost out of time. I wanted-- I don't think we mentioned the website.
Is it sawmills dot- AI. AI. AI.
Okay. Yeah. S-A-W-M-I-L-L-S.
Just the way you'll see it on y- your screen on the bottom third. ai, the, the, the, agentic telemetry management platform. It's brand new, just coming out.
Go check it out. Ronit, Erez, I wish you both the best of luck. Come back, keep us posted on this.
I'm sure we'll be hearing more. Congratulations. Thanks, Alan.
Thanks, Alan. Thank you. Thank you both.
All right. Sawmills here on Techstrong TV. ai.
Go check it out, the world's first agentic telemetry management platform. This is Alan Schimmel. We'll be back on Techstrong TV in a moment.
Hello, I'm Scott Robohn with Solutional, and I'm here today with Ahmed Aboutaleb of Nokia Enterprise IT to talk about some of the very interesting network migration issues that they've been through over the last, year or so. I'm not gonna steal any of Ahmed's thunder, and we'll let him speak to it all. Ahmed, please introduce yourself to the audience.
Hi. Um, my name is Ahmed Aboutaleb. I'm the lead architect for the on-prem, data centers inside Nokia IT.
And, I had the privilege, of course, of, doing this exciting transformation where we moved a lot of data centers from legacy to modern, modern techniques, modern data centers, migrating from different types of vendors to, to Nokia equipment, mi-migrating from Nokia to Nokia. So, those two or two and a half years have been very exciting for me. I've been working in data centers for a long time, but this is like something I've never seen before, so.
Awesome. I'm excited to share this with you. Yeah, no, happy to dive into this.
And let's just set the context for, for people who w- aren't aware, you know, Nokia is just this tiny little company with just a few hundred users on the network, right? Yeah, sure, sure. We've got like eighty-eight thousand people, yes.
Yeah. Yeah. And a wide diversity of different departments and functions do you support.
You have manufacturing operations that you have to support, of course, finance, accounting- Yes ... HR, all sorts of, you know, software developers, people in sales, people in marketing. Probably one of the most complex enterprise network environments that I've run into in my time in networking.
How about you? I- I- I- I think it- it's, it's different types. Th- th- there is a variety of applications, applications that are very sensitive to disruptions.
Sure. Applications that are, you know, factories, you know, that, that could, i- you know... A brief disruption could, could throw off, the software of the factory.
It has to be restarted, things like that. So it's very critical, very interesting, and a different variety. Different variety.
Some are very sensitive to, to delays, some are very sensitive to outages. It's, it's very interesting. So you've given a little hint at kind of the first, category of things that we want to talk about.
" So what were some of those original pain points, if you think back, you know, two, two and a half years now, to when you actually started down this path? What were some of the motivators that, got you thinking about we need to go to new network infrastructure and new tooling? Well, yeah, when I started really with Nokia IT, I, I saw it, it diff- all sorts of problems, you know.
I wasn't, I wasn't in the, in the IT world, I was in the product world. Right. And everything there was, like, more rosy.
You know, you're dealing with labs, concepts, architectures, bluepr- playbooks, uh- Sure ... blueprints. Uh, but when you move to IT, it really hits, you know, the real world part.
And there I was exposed to all sorts of problems, you know. We have opera- the, our operational model, you know, where we have to do a lot of intensive work, very resource intensive. We don't have a feedback loop from the actual, from the actual deployment to the intent.
Um, we had operational problems where, where the operations team were dealing with different types of toolings that don't cooperate with each other, that don't tell you really what, what, you know, what is wrong with your network at any time. You have to do a lot of brainpower and corre- you know, manual correlation. Mm.
Um, also our designs, our designs, w- it was a lot, "Oh, well, let's go to the lab, let's try and simulate as much as possible production. " So lots of variety like that. And also, and also human aspect, of the thing is li- like, I, I think of it as a journey.
This is not only a technical part, you know? Sure. People are, you know, see excited about automation, AI, and stuff like that, and they, they wanna be part of it.
They, they wanna get exposed to it. But n- not, not just for the sake of AI and automation, but where it makes sense for us. And so all that, made, made us think of completely re-architecting the way we do everything.
Sure. From design to, to implementation, to operations. Everything was completely different.
Did you see any, like, n- not to be overly reductionistic, but any, like, specific pain points? Was there overload due to alarms or tickets generated? Um, were there communication issues on some of these complex troubleshooting issues?
Does anything specific come to mind there? Uh, of course, I'm, I'm not in operations team. I'm in, I'm in design team, so- Sure ...
I, I wanna comment on the design part because- Okay ... that affected me the most. Sure.
Uh, is, is when w- when, for example, when I got exposed and we had a network au- audit and we found all sorts of problems, you know, the thing is, we really don't know if, if what we're dealing with is, is a design intent or it is intended to be like this or, or drifted through time to be like this. Sure. And so, the common thing, the common thing is I always was told, "Go back.
Let's see the de- designer that did it two years ago. Let's talk to him. Let, let's talk to him.
" Hmm. So it wasn't, like, very consistent and, and, and drifting, and we don't know if, if reality is good or bad. So, all sorts of problems there in the design and also in the implementation.
Lots of people doing CLI where, where one node has a completely different configuration than another. Sure. Not completely, but drifted away from another, and they should be identical, and we never understood why.
Uh. So I, I, I really ne- I really thought, thought about this when, when starting the architecture that we, consistency has to be there. Yeah.
Automate, you know, something at a higher level should be, the, the engineer shouldn't be going to that low of a level to deal with things. They should, they should be dealing with a high level, and let some tooling, some automation, some t- templating do the, the real hard wo- you know, the con- you know, consistency check work. Sure.
Sure. Hey, everyone. It's Alan Schimmel.
Welcome back here to techstrong TV. I want to introduce you to Zach Hanief. I hope I got that right, Zach.
Yeah? You did indeed. You did indeed.
It's great to meet you, Alan. Nice to meet you, Zach, and thank you for joining us here on techstrong TV. Zach, by the way, is head of AI, ML, and data.
That's a lot. Yeah. A lot of stuff right there.
There's a lot that goes in there, but they all work together. For Twilio. Yep.
Yeah, yeah. Well, it does. And, and as I mentioned, at Twilio, a, a company we've been following a long time here at techstrong.
Zach, that is a lot. You don't look that old. You've been doing this, though, a while.
Tell us, like, how did you wind up here? What's your path been like? So, one, I don't look that old because fortunately the camera I have lies a great deal on my behalf.
You got a good camera. So that's, that's always the big benefit. A good ca- That's a lesson out there for you people watching.
A good camera always helps. But go ahead. Uh, two, my path has, has gotten me here because ever since the early days of my career, the thing I knew I wanted to do was work at, with data and AI and ML at large scales.
That was... It's been my entire career from the beginning. I have been blessed with the ability to do that across a wide number of domains, everything from internet security to anti-money laundering to fraud.
I've worked in financial institutions, fintech. I've worked for general purpose, large scale internet companies, all sorts of great stuff, right? Uh, I'm very grateful to be here at Twilio right now.
You get a huge amount of perspective and challenge inside of a space that up until this point I haven't, spent a lot of time with, and it's a wonderful opportunity to work directly with customers. Love it. I love it.
And i- you know what? Sometimes just things just c- c- you know, line up right. What a, what a great time for you personally with your background to be living right now in what this kind of revolution that we're, we're living through in terms of AI and, and everything that goes with it.
So- The last 15 years have been very exciting. That's absolutely true. Absolutely.
Good for you, man. Um, talk to us about Twilio. How long you been at Twilio?
So, excuse me. So I'm coming up, just on about two years now, having been- Mm-hmm ... at Twilio.
Uh, so not all that long as, as far as we kind of measure time and material like that. Um, but the company's gone through, like, a multitude of, of, of evolutions, and it really feels like it's on a incredible path forward, over the la- you know, having been built up for the last couple of years and, and looking into the future. So most people, I think-Actually have interacted with Twilio without knowing it.
One of the things I like to say is that if you've gotten a text message from like your dentist or from any kind of brand that you've worked with, if you've gotten an email, from an organization that you're subscribed to a mailing list on, statistically, it's pretty likely that within the last week, you've gotten a couple of messages sent by someone who you wanna interact with using Twilio. Twilio is one of the leading if, if not the leading, companies that build out the capability to do communication between organizations and their audiences through channels, SMS, email, whole bunch of them. What most people don't realize is that we have an incredible amount of capability in the area of customer engagement in general and have been building that out quietly for the last couple of years.
So Twilio's got this, great, union of things between the knowledge of what customers-- what our customers want to communicate with their audiences about and how they're doing that communication. And so that means we've got the ability to have a, you know, very, very powerful customer engagement platform that allows our customers to have direct personal relationships with their audiences, no matter where those audiences are and no matter how those audiences want to be communicated with. And it gives us the ability to make sure that as time goes on, and this is what drew me to Twilio, that puts us on a position where we can add intelligence to functionally every interaction and trust to every part of a customer's journey.
It's, it's an incredibly large lever that honestly most people never even think about, but has a huge ability to kind of influence how we do business on a day-to-day basis. I love it. Man, like I said, what a great time to just be alive, though, huh?
Yeah. Um, Zach, of course, you know, as you mentioned, all, all the great things here about Twilio, but for people-- I don't want... We only have fifteen minutes, and Twilio is a company that's this wide- Yeah.
-wider, you know, in terms of all the great things it does. com, what would you suggest is like the best path for people to kinda digest all of the great things Twilio does? So I would go to the website, to be perfectly honest.
And the company- Zach, I lost you there. I'm not sure- Oh. Still with me?
Okay. Back. You're back.
There we go. Okay. Uh, one, I'd go to the website, right?
Excuse me one second. Not at all. Paul, just make a note.
I lost sound there for a second. You, you're gonna have an edit. Okay.
Go ahead, Zach. Sure. I'm gonna count you down.
Three, two, one. So I'd tell people if they want to engage with the company, you probably go to the website first, right? Twilio has been, since its foundation, a developer-friendly, developer-centric firm, that makes all of our capabilities available, over APIs.
And that focus on accessibility shows up through all of our documentation and in all of our work. We've got a pretty extensive blog. We've got a bunch of material that's available.
So if you want to start engaging, I would tell you to, to go there. The second thing that I would do is say it is incredibly easy and incredibly accessible to just start working with the tools. Um, entry is very easy.
It's very accessible to play with. But most importantly, if you have someone or something you want to be able to communicate with through multiple channels, or you want to have a better understanding about how your audiences are currently engaging with your content, Twilio is the place to be. Love it.
Very cool. Zach, if you don't mind, I want to segue or pivot into, a new launch from Twi-Twilio here. It's called A2H- Mm-hmm.
-Agent to Human. Uh, this is an open source protocol. Everybody loves open source, right?
A spec that provides a single channel-agnostic audible service surface for agents to communicate with the human principals. All right, I read the, the press release part of it. Talk plain English for us here, Zach, like we're gen AI people.
Um, what is it? Last year has been the big drive where using LLMs, building agents, and leveraging those agents has become more available, not just to those of us kind of in the industry, but to the general public, right? You're seeing that takeoff happen.
One of the things that's happening right now is because agents represent a new interface, a new way of interacting between humans and humans, and humans and their computers, right? We're all starting to explore a little bit more how do we actually drive that interaction. What are the things that are available to us where it wasn't there before?
If you remember back, right, when computers started, like we're going back to the fifties here, right? You interacted with these things with punch cards and actual physical levers and lights that you could see on a machine that was the size of a wall. Over time, we started to get CRT monitors.
First, you know, you effectively had just basic lines, dots, the outlines of a shape. And now, right now, I'm talking to you on a screen that's got, you know, eight thousand pixels or whatever the, the actual value is, but, like, we have rich content and media that we can engage with natively, right? We engage with things with a mouse.
There are keyboards all over the place. We have different ways of engaging. Okay.
"Can I talk to it, for example? Is there a way that I can just type plain text and get that information back? Maybe I don't even need to pa-- intentionally communicate with it at all.
I can just simply have a camera or something display what I'm doing, and the machine will infer what I want to do next. Lots of different ways that people are exploring with this. A2H, when you get right down to it, right, is a way that standardizes how an AI agent communicates with and requests permission to do things from humans.
And it's that last part that's really important right now. How do you get consent from humans if the agent wants to do something and it's not sure if it has permission? Historically, inside of, you know, functionally all of, computing, our ability to give the computer a permission has been very coarse.
You can read something, you can write to something, or you could execute it, run it. But as we're getting into a space where agentic judgment is starting to allow a much larger realm of what a machine can do, those previous kind of like three-part models start breaking down. And so A2H gives us, excuse me, standardizes how computers talk to us when they're asking for more context, when they're asking for consent, and when they're giving us information, right?
A2H, we hope, right, is the start of a kind of like interaction mechanism or a contract for this kind of new agentic era we're finding ourselves in, right? Other protocols think about how agents talk to each other or they-- how they talk to data or other technical resources. A2H puts that in the context of, can we get a single standardized, ideally channel-agnostic surface, could be via voice, it could be via text, doesn't matter what it is, right, for how these agents talk to us.
One of the big underpinnings of it, I think I mentioned this before, is that you want that mechanism to drive that positive consent. "Hi, I need to do something. Am I able to?
" You want that to be auditable. You want it to be secure. You want it to be very clear, so that way when an agent takes an action, the human who is accountable for that action doesn't wake up the next day and realize that they have something that they need to regret.
Does that make sense, Alan? Uh, it makes total sense to me- Yeah. But this is my life these days, Zach, so I, you know...
u-u-you're talking my language, no pun intended. Effectively, it just standardizes the way you're able to speak to an agent and tell it exactly what you want it to do, and it allows the agent to standardize how it gets cla-clarification, about, hey, is this actually what you meant, and am I allowed to do something during moments of ambiguity? Now, this is an open source spec.
Yes. Yeah? Um, what exactly does that mean?
Like, is it you put it out on GitHub? Mm-hmm. People could use it without Twilio, but I assume there's some hooks for Twilio that can be used if you want.
Absolutely. So it's not just available for people to use without Twilio. We hope people use it independent of their use of Twilio, right?
We also hope, and this is part of why we have an open spec, we want commentary on it. What are the things that we may not have anticipated? What are the things that you've seen that cause us to begin to adjust this?
This is an interface thing, right? It's a new way that humans interact with something, and that means that we interact both from an objective sense, hey, was this correct, and a subjective sense, hey, did that feel like a natural interaction? Does this feel natural for us, or did it feel weird and stilted and therefore it doesn't feel good to me, right?
So we want to get that direct interaction there, right? So when we think about it, both A2H, right, as well as t- the hooks that it has going back into Twilio give us the ability to say, if this standard gets adoption, people are starting to look at it, we are adopting it as well, and we're able to drive that forward as a part of what we do. So in the event that you have something that says, "Hey, I need to make a phone call," do I have the authorization of the user to make that phone call?
That's the mechanism that we're going to be able to use for some of our own agentic capabilities, should users, leverage that. Got it. Now, look, I'm, I'm playing with a lot of agentic stuff myself.
My team is here. We've hooked up to some services that let us talk to an agent, and it talks back to us- Mm-hmm. Like a, I don't know, voice-to-text kind of stuff, if you will.
But this sounds like something more than that, right? There's-- it's not just reading words or hearing words and converting it to text. It's this, this, as you called hooks, right, in, in, into making things happen.
Um, when you say it's a specification, what do I gotta do to get this working? Like, okay, this sounds great. We'd like to use it.
Yeah. I go to GitHub. I look up A2H from Twilio.
I find it. What do I need to make it work? Well, we're still in the very early days of the specification, so we've only, we've only just published it.
Things that are starting to happen now are the development of libraries that make the adoption of this easier if you're a developer. Mm-hmm. We're starting to look with and partner with teams who want to implement the specification inside of their own agentic frameworks, right?
Okay. And of course, we're consistently bringing in and, and accepting more commentary on the spec as well. So we're still in those very early stages where there's kind of this forming action around, hey, have we proposed something that's resonating with the larger community as a whole?
Has that proposal demonstrated that it's relatively easy to begin to implement? And for areas where we have easy-to-implement libraries, things that lets you get started a little bit faster, a little bit more rapidly, are we watching that adoption and finding that people are able to go places with it and kind of bring their visions to life using that technology? So it's a little bit of all three of those things.
If you ask me again that question in six months, my quest-- my answer is going to be different to you because we'll have gotten through that initial phase of everyone kind of wrapping their heads around and beginning to interact for the first time with a lot of these capabilities. Very cool. Very cool.
Um, people watching out here, we've got developers, we've got geeks, as I call them, they're my people. What do you want to tell them, Zach? How, how did they get involved?
How did they help? What did they... Well, and help themselves as well, right?
Yeah, I think that's right. So I think the first message that I'd probably want to send is the thi-- the realization that we came to that drove the creation of this specification, and it's this, right? Conversation plus consent equals trust.
And we came to the realization that with e-even no matter how powerful the technology is, without a verifiable trail of, you know, human approvals and, and authorizations, right, agent autonomy is gonna hit a ceiling in terms of how it gets adopted, right? Think about it this way. You wouldn't trust something that isn't you with your credit card if there wasn't a way for that thing to call you up and say, "Hey, I'm about to do something with your money.
It's a little ambiguous at the moment. " You've already authorized them. We're both confident in that, but now you have a clear record of when it was you versus when it was something acting on your behalf and with your permissions.
That communication plus consent and the, the resultant trust that you get out of that is, we believe, a big part of what needs to exist to be able to unlock more and more things in the agentic world, not just from the perspective of the early adopters and the believers, but from general people on the street who otherwise would have a, a trust issue because they are not as deep inside of the space as we are. We've opted in when you think about it that way, for anyone who comes on your show, for your yourself, for people who look like me, right? And so our premise here, both in A2H and in the larger perspective of kind of where Twilio is, is we want to give our customers two fundamental things.
One, a unified platform that they can use to accomplish their goals. If your goal involves communication, and tell me if there-- I don't think there's any that don't, right? " But the second thing that's really important to us here is to make sure that you have that trust.
Trust is the thing that lets everything function in a civilized world with a minimum of friction. If we trust the interactions that we're having, if we know, for example, that, hey, if somebody is engaging with my agent, we can identify both my agent positively as something acting on my behalf, and we can identify the counterparty, the person interacting with it, as a clear, distinct, and known entity, there's trust there. If I'm a customer, and I'm using an agent, and I know and I can track that I'm getting value from that use, there's trust there.
All of that is absolutely critical. And so our goal with A2H is to give us the ability and to just deepen Twilio's commitment to making sure that we have low-friction, easily accessible capabilities in a platform that stretches across the entire life cycle of how an individual might wanna communicate with their audience and better understand that audience's needs, desires, and next steps while making sure that everyone inside of that three-part chain can trust their individual counterparties. We think it's powerful.
I think it is too, man. I think it is too. Very cool.
Zach, we're about out of time. Um- Fantastic. You wouldn't happen to have the GitHub address where people can go find this, do you?
We absolutely do. Um, it'd be a little weird for me to recite the whole GitHub repo- No, I know- ... verbally, but we'll strip it down to you.
com backslash something. Just, you know what, we'll, we'll put it in the notes on, on this, but just make a note, w-- if you could have your people send it over to us, we'll, we'll put it in there. You got it.
Absolutely. Sound good? Yes, it does.
All right. Hey, man, I'm sure you're excited. Our people here are so excited.
I got people spending weekends in the office 'cause they're working on their agentic stuff. I'm sure you're, you're seeing and hearing this too. It's an exciting time to be here.
It really is. Um, keep up the great work. Come back and keep us posted, okay?
Thanks, Alan. I appreciate it. Thank you for having me.
It's my pleasure. Zach Hanif, head of AI, ML, and Data over at Twilio here on TechstrongTV. We're gonna take a break.
We'll be back with more. Hey, everyone. This is Alan Schimmel, CEO of Techstrong.
Welcome. Welcome to this very special virtual event that we are producing in partnership with our friends at Microsoft. The event is titled Unlocking the Future of Agentic Experiences, and it's gonna be a series of videos in, in this virtual event that you're gonna be able to, you know, take a look at and, and interact maybe with some of the analysts and speakers here.
I really think you're gonna enjoy and get a lot out of these videos and this event, and look forward to hearing your feedback. I'd like to kick things off with our keynote, and i-it's our keynote 'cause I think we've got two terrific speakers in this one, and it's around the future of apps, right? And it features Futurum CEO and principal analyst Daniel Newman.
If you've ever seen Daniel on, on either many TV shows or, or sh- or conferences that he keynotes, you know he-- what a dynamic thought leader he is. I think you'll enjoy it. And Daniel is gonna be speaking with none other than Ryan Cunningham.
Ryan, of course, is corporate VP for the Power Platform at, Microsoft. And you know, Ryan is gonna share with Daniel and with you the all-up vision, the, you know, the all-around vision for P-Power Platform. We're gonna connect the dots between apps, agents and interfaces, right?
Ryan and, and, you know, with Daniel are gonna illustrate how Microsoft is leading automation in this AI era. He's gonna articulate how Microsoft is enabling every organization to build, govern and scale intelligent solutions with unmatched speed and trust, driving the future of agentic apps. It's a great discussion, and I think it's a great learning experience.
So here's Daniel Newman and Ryan Cunningham. Alan, thanks so much for that introduction. And to introduce myself, I'm Daniel Newman, CEO of Futurum.
Very excited to be here today with all of you, and even more excited to introduce my guest for this conversation, Ryan Cunningham from Microsoft. Ryan, why don't you say hello to everybody and give a little bit of background on the work you do at Microsoft? Uh, thank you, Daniel.
It's awesome to be here with everybody today. So I'm Ryan. I'm the corporate vice president for Power Platform here at Microsoft.
So, look after all the teams of, product people and engineers and designers that are building, really our low-code application platform and the future of where that is going. Uh, you know, really excited to talk to you about that today. Ryan, I've been working, with and around your team for many years as an analyst.
It's been great to follow. Mm-hmm. Of course, the change that's been going on in this market is extraordinary, and I think that everyone out there is gonna, gonna leave this, conversation knowing a little bit more.
And hopefully, maybe you'll give us a little bit of that, secret sauce about all the stuff Microsoft's doing. Nothing too secret, though. You know how that goes.
Oh, I know. So let's, let's start big. Uh, I mean, when we talk about the future of apps, connecting agents, interfaces, applications, you know, what is the kind of the North Star for Microsoft?
What are you, what are you guys heading towards here? Yeah. Uh, look, it's a, it's a crazy time to be alive in a business application platform, environment, right?
Because, this whole world is, being turned upside down in actually two dimensions at the same time. Uh, one is how we build software, radically changing in a world of agents and, and vibe coding and everything that is filling up our LinkedIn feeds as technology professionals. What's really interesting right now is the dramatic expansion in efficacy of what I can build and the dramatic expansion of who can participate at the same time.
You have to be evolving the platform even more and even more quickly- Right ... to, to get them what they need and what they're trying to do to accomplish the, the future that they're trying to build. Yeah, a hundred percent.
And you know, I would say to, to even build on your last comment 'cause it's relevant here, it's not just an opportunity for more people to tinker and build things. It's actually really an imperative. Like, if, if we're really gonna accept the premise that every company that wasn't born yesterday is operating inefficiently and needs to, to rapidly advance in a world of agents, then the expertise you need is not just the AI technology expertise.
You actually need to go get all of the process expertise. You know, all the humans who know what it really means to run a more efficient HR department or finance department or, you know, whatever it is, they're sitting with a real job in that department today. You gotta go figure out, how do I harness that expertise and bring those tools right to the, to the point where the process is actually happening today?
And that's where you need a higher abstraction platform that has agents built into it that help do the coding, that help do the work. Microsoft does have some really unique approaches in this space, and, and particularly if you look at this broader world of how software is getting built and code generation and agent swarms and every other term we're coming up with right now. You know, where we're really focused right now, particularly in the space of business applications and productivity, is really make that relevant to the way companies run and operate.
You know, we're not out there to, to, you know, serve any possible whim of any possible developer on the planet. There's lots of great tools for that. Microsoft makes some of them in other places.
But here we're really focused on-The, the core operating system of a company. And by, by that I don't mean Windows, I mean sort of all the business applications, business processes, specialist teams of people that today make a company tick. We're seeing consolidation in this era.
Uh, customers have a ton of choice. Yeah. " Right.
Um, we're gonna wanna see is, you know, the orchestration is gonna be super important, and then of course the, the speed, flexibility, access to all the tools, data, cloud, and- Yeah ... of course, Microsoft's in a very small group- Right ... of companies that has pretty much all of those things.
Right. Um, not al- not the only, but one of a very small number. Yeah.
And I think that makes you competitive. I wanna go to the, the pragmatic side, 'cause a lot of the, viewers here are probably thinking about, you know, how do I do this? How do we do this in our firm?
You know, we hear some of those stats about AI ROI in the enterprise, and, and, let's just say that I'm a, I'm a absolute believer, but I do think there's some hurdles. You know, what are those kinda key enablers you're seeing, fundamental enablers enterprises, you know, need to get right now- Right ... to make sure that those, those POCs and those production, AI projects start to work and really show value?
Yeah. We're seeing customers, a- adopt exactly the mentality you're talking about. You know, not just how do I run the current process faster, but what if I fundamentally changed the process itself, to really great effect?
Um, you know, we've, we've shared some stories of retailers, that are starting to use agents and apps and automation together to totally change how they do things like fraud detection and, even refunds and returns management. Um, you know, if I go contact an online retailer and say I want a refund, you know, traditionally that's a human going and vetting, is that a real customer? Did they buy something or is this fraud?
Does it meet our return policy? Which is, by the way, usually like a 50-page PDF that changes once a quarter. Um, you know, and then do I wanna issue the refund or can I save them as a customer?
And that's super slow, and it's super inefficient, and it's really expensive, and often it's outsourced to vendors. Um, you know, can I go implement an agent that does that instantaneously, or at least does major parts of it instantaneously, you know, really starts to change my operating and my risk profile and my customer relationships. And so, you know, even in use cases like that, starting to see, you know, millions of dollars of value unlocked really quickly and just better customer satisfaction.
Actually, the balance of value is really shifting towards that process expertise. " That's just not a thing that happens to most regular people. Um, but a whole lot of people woke up this morning and said, "Man, this part of my job sucks.
" Right? And, and really harnessing that energy, that value, those skills and those people and bringing great tools to them, that's part of the whole thesis behind why a platform is, is critical right now. You know, what does it mean to totally change that interface into a human and agent collaboration space?
What does it mean to go see the activity of what agents are doing on your behalf when they need your input? Let's talk a little bit about Plan Designer. Yeah.
Um- Yeah ... you know, we're seeing we go from manual to automated to, you know, to agentic level o- orchestration, which is great. One of the cr- key things too is gonna be trust.
We gotta trust our systems. We gotta be sure that, you know, the agent, workflows we're building, that they're expected- Yeah ... that they're constantly modified to be sure that they're right, that they're traceable.
Like, talk a little bit about kind of how Plan Designer can help companies, 'cause that's a lot of work, by the way. Yeah. That's a lot of work- Yeah ...
we can automate or, you know- Yeah ... streamline some of that out of the process. Yeah.
Well, look, for, for folks out there listening that haven't experienced Plans in Power Apps, it's worth trying out. com. You can try it today.
But, what it really is is a, a different kind of AI-centric development experience. Um, you know, you go type into that box a business problem. We do not assume that you just want us to spit out 1,000 lines of JavaScript, that you, that you need an app, like a lot of vibe coding platforms today.
We actually do what a real software team would do. In fact, we've built in a digital software team. We've trained a requirements agent, a process agent, a data agent, a solution architect agent.
It's a highly collaborative environment. This is not a sort of throw a paragraph over the fence and watch magic happen. It's really sort of training and teaching people with process expertise how to think like software architects and solution architects so that they can know up ahead of time, why do I want AI to do certain things?
Where do I want it to work? How do I want it to interface with humans? And that's really the foundation of that trust in a system.
Have you seen, some examples out there of Plan Designer being sort of delivering promise? 'Cause it sounds- Yeah ... super optimistic, but are people using this?
Oh, 100%. We have started to see really interesting sort of challenges thrown at it. Um, you know, we have, customers in highly regulated financial services contexts that are taking decades of old homegrown, non-compliant software that was built over, whether it's, you know, hacked in Excel or built one-off, and sort of saying, "Can I use this to rapidly modernize what I had before in a way where," you know, traditionally going and turning all that old stuff into full stack software was just incredibly costly and, and cost prohibitive.
Um, you know, starting to bring those things into plans and generate a more robust plan for modern software moving much faster. Um, we've even seen huge extremes of that. " Um, and actually, the results were pretty promising.
So, you know, people are getting really creative with, you know, bring the problem, bring the challenge, bring, you know, sort of the business area that you wanna improve, and then start working with these agents and on this digital software team to, to design a solution. So, you know, we're doing all this work. We are trying to train people to think differently, remove constraints, whatever's possible.
But the UI is the, seems to be the next frontier. " It's like great. But in the future, like- Right ...
I might just wanna say, "Hey, you know, Microsoft," whatever. Yeah. Uh, this is what I wanna know today.
Right. And then I want it to obviously learn based on my behavior over time what I wanna know. Right.
Then I want it to continuously, you know, things like that. Right. Like, how does the...
How do you see, being in, in this space so much, the kinda UI evolving? Yeah. Um, you know, I think, specifically chat as a UI is super compelling and natural for a lot of things.
Um, I do not believe that we're gonna go regress 40 years of a- of UI innovation and go all back to chat and the command line, though. Like, there's a lot of things for which text is actually a terrible modality, you know, in which, you know, just paragraphs are, are not great. Um, and, and I think there's, there's a more underlying thing here that you're touching on, which is a lot of traditional experiences, whether it's text-based or, or visual, assume a human shows up knowing an intent, right?
As opposed to, you know, an agent being really proactive and taking care of something for me or pushing me an update or a notification when I need to know it. Um, and so I think those experiences start to evolve a lot. What gets really interesting is where they meet, you know?
And we really th- see a lot of this, you know, task-based data entry, repetitive stuff increasingly getting delegated to agents on your team. But that means you'll need to work with that team in a totally different way, right? And, and where a, you know, traditional CRM system or HR system or, you know, whatever, you know, pick your business application was, you know, previously, like we talked about, people typing into boxes and then other people b- viewing reports.
You know, what does it mean to totally change that interface into a human and agent collaboration space? What does it mean to go see the activity of what agents are doing on your behalf when they need your input, you know, when they're blocked on something, or they've noticed a trend, or, you know, there's a form they tried to fill out but didn't complete? Then that's an important meeting space to go have experiences and user experiences.
Um, and a lot of times those do need to be structured in a visual way. A lot of times they could happen, you know, ephemerally or, or with a chat message, but how do you route people to the right place at the right time? Um, you know, we're working across all of those fronts.
You know, that's why we have a robust set of tools in Copilot Studio for, for building the agent part of, of, all of those things. It's why we have a ton of evolution in Power Apps, you know, sort of becoming this new agent-centric experience where I can see a feed of that activity, I can have agents help me, do the work in the applications. Um, and those two worlds will just continue to evolve together as we start to bring things into the future.
Yeah. So you heard me talk a little bit earlier, Ryan, about governance. Um, governance is part of the, the critical, constraint and one of the things that differentiates software, right?
The reason we can't just use OpenAI for everything would be because it doesn't know how to handle the data. " You know, "Help me do a job offer," or, "Help me do a- Yeah ... compliant healthcare notice- Right ...
" Like, it doesn't know how to do that. Right. So building applications that do know how to do that is the key.
You gotta build it with... Um, of course we wanna go fast. Right.
Fast is the new, the new rule. Right. But the trust and scale are, are, are the other words.
I know you often use- Yeah ... these words, but like- Yeah ... you know, what do you think...
And where are companies sort of struggling with governance, and scale here with automation? And, you know, kinda how do you think what you're building in Agent Oversight can help them? Yeah.
So I'd say there's a couple dimensions to governance and scale. You know, there's the breadth dimension. We have a whole lot more people who now can build a whole lot more things.
How do I make sure that all that stays on the straight and narrow when I can't centrally top-down code review every single thing that every single person and agent is doing? And then there's sort of depth scale. You know, when I do wanna roll out a mission critical solution to 100,000 employees that has AI in it, how do I make sure that that AI is not just functioning, but actually continuing to get better every single day?
Um, and, and, you know, the, the good news is we're not inventing any of that from scratch. You know, breadth scale and depth scale were a challenge in the first generation of Power Platform, and something that we've built a ton of capability into the platform over the last couple of years to really, tackle at huge scale, and we call that, the managed platform set of capabilities, and within it, there is managed governance, managed security, managed operations for life cycle, ALM management, stuff like that, and ma- managed availability even. How do I go ensure high availability, run disaster recovery drills for critical workloads?
All of that is built into solutions baked, on the Power Platform. Um, and all of that value accrues to this next generation of components being built as well. You know, an agent built in Copilot Studio benefits from all of those managed capabilities.
Um, a new app built in Power Apps with intelligent capabilities in it benefits from that entire stack. Um, and so that's why, you know, you start to see even highly regulated financial services firms, government agencies, et cetera, really trusting Microsoft here as opposed to a-20-person startup that was founded yesterday, you know, to, to really take the bet on standardizing for this, this segment of, of software. Um, then you get into the operational oversight.
Okay, I have agents doing work. How do I have humans managing the work of those agents? That's not a developer role anymore.
That's really an operational role. You know, what does it mean to be an agent manager or an agent boss in a claims department at an insurance company or in a supply chain, operation? You know, that's where we need these new interfaces, and that's what Power Apps is building in with concepts like the agent feed.
You know, how do I build a, a purpose-built oversight experience for really high volume activity of, of agents? This is one of those things that like, right, there's so much doubt across the industry about being able to do this in a sort of when you give up the human in the loop or even just have one maybe guiding, but you're moving so fast. It's like, you know, are they safe?
Are they auditable? Because when you're in a business, everything you do- A hundred percent ... has to be traceable and trackable.
Yep. Uh, is it predictable, the outcome? Right.
Like, hey, you're gonna have an agent interfacing with your customers, or you're gonna have an agent- Right ... doing a bunch of accounting work, which by the way, it's like a spiral. One mistake- Sure ...
and then it's just, you know how that goes. Yep. Like, how are you guys overcoming that doubt, you know, through the guardrails you're putting up, through the oversight, the accountability that you're kind of baking into your platform?
Because I think if you get over that hurdle, Ryan, we move a lot faster. You know, I think what's interesting here is actually a lot of our customers have had to build these systems already. You know, a lot of our customers already operate critical processes across massive employee bases and even larger vendor teams that operate at arm's length already today, right?
And we've already had to go build in a, in a world of a whole lot of variability of, of who's doing a task. How do you create an audit trail? How do you create rules?
How do you create data policies? How do you create oversight? A lot of those concepts exist today because there is variability in the human system, right?
And so a lot of the way we, we approach this, okay, how do you adapt those existing concepts, policies, features, capabilities? How do you adapt that to a world where it's humans and agents doing the work? And what are the sort of incremental, you know, sort of ten percent shifts that you need to make in those systems to accommodate agents, but not completely, you know, pave them and re-re- rebuild them from scratch, right?
Because a lot of these sort of trust concepts, or zero trust concepts in a security concept are already built into to the system. Um, and so there's a ton of work we're doing there in the managed platform in, you know, a lot of the ways that, you know, a lot of the Microsoft security governance and oversight concepts apply to agents. Um, and, and that's again, one of the benefits of building on a mature platform and a mature system in Microsoft is, you know, we're not having to recreate all that stuff from scratch like a, like a point solution startup would have to do.
Yeah. So the, the last thing just on specifically on security. Yeah.
Um, security is a super hot topic. Yep. What do the customers...
How do you want them to think about the approach? Because in the end, like you can get it all governed and right, but you have to keep your doors closed and locked. Right.
And you know, that's an increasingly large problem. AI is, is much- Yeah ... enabling it, uh- Yeah ...
as it is fixing it. Right. Well, look, I mean, we could probably spend an entire hour on, security and threat model approaches in the, in the AI era.
It is absolutely critical, and like any security challenge, there is no silver bullet. You know, every customer needs to have a defense in-depth strategy and needs to think about, what am I doing from a data security perspective? What am I doing from an exfiltration perspective?
What am I doing from an access perspective? Um, you know, the good news is we have a lot of that built into the platform today. You know, even a customer building their first Copilot Studio agent and using the managed Power Platform to roll it out, will see a security score in the Power Platform admin center.
Will see AI-driven recommendations about what to do to improve that security score. Um, you know, it has a whole bunch of capabilities in there that, that go all the way to operate this in the cloud, but with a private VNet, with your own managed encryption keys. Um, you know, again, we have a lot of highly regulated, very security conscious customers that are working with the platform today.
Um, I would say though, to zoom way out and look at that, and maybe connect it to some of the rest of the conversation we've had, it is absolutely risky to go too fast. It is also very risky to go too slow, you know, and the rest of the world is evolving, including threat actors and competitors, right? And so the cost of standing still is probably the most costly position to be in.
So let me, let me, you know, as an analyst, uh- Yeah ... I have to ask you 'cause, I've got a few things. Uh, but, what kind of in this whole evolution, this, this exciting moment for the future of apps and automation, and agents, like what's kind of keeping you up at night?
The biggest concerns that you see out there, and then what are the kind of upsides for you? Like what do you- Yeah ... most kind of think could be the biggest surprise in-into the future?
Give us that big- Yeah ... visionary moment here, Ryan, to take us home. Look, I think, I'll start...
I'll do that in reverse order. You know, I think there's a ton to be excited about right now. Um, and you know, I, I think, there's just so much potential and creativity that we can still unlock.
NET code in their life. Um, you know, what unites that community is this sense of-We can make something better. We can...
This can be better. Let's do it better. And, you know, I feel like we're at the precipice of just blowing a huge lid off of the ceiling of what you can do there.
Um, and there's a whole lot to be excited about. Um, I mean, you joke about a night job, I stayed up last night vibing a Power App that's just a Tetris game because it was awesome and fun, and so much faster to create it than it would have been in the last generation of the technology. And I think that's a tiny, tiny microcosm of, you know, go take that creative energy and apply it to everything that's inefficient about every aspect of every customer organization today.
You know, we're really standing on the precipice of completely rewiring how companies work, and doing it with people who, who have deep expertise in that process and a deep desire to make it better, and that's just incredibly exciting to me in this, in this moment. Um, and then to flip it around, okay, so what stands in the way of that? You know, it really is all about speed and pace of iteration, and, and really it's about time to wrong.
You know, there's, there's so much that we need to go invent, and co-invent with customers, and experiment with, and try, and nobody out there is perfect right now. What, you know, what will define winners and losers for technology companies, for customers, for operations, is how fast can you be wrong, and then how fast can you get less wrong and more right? Um, so that's, that's the journey we're on, that's the hill we're climbing, but it's just a super exciting time to go think about what the, the top of the mountain can be.
Ryan, this was a lot of fun. It was a great conversation. Appreciate you sharing a little bit about where all of this is heading.
There's so much potential for companies to really start reimagining- Yeah ... and realize just how big of a leap forward we, we are having right now with, with AI, with agentic, and the work that you're doing in Power Platform. So Ryan, thank you so much.
100%. Really, really enjoyed the conversation, Daniel. Thank you for the time.
Everything about the way we work is changing very quickly, thanks to the advancements in applications and of course agents, automation, and what interfaces may look like in the future are all gonna continue to change. And they're gonna enable and they're gonna power businesses to be more efficient and, of course, to be more productive. It was a great conversation over the last hour.
We really did reflect across not just Power Platform and how they are thinking, how Microsoft is thinking about building its future, but really about how businesses should be thinking about developing their future, removing constraints, being able to look at problems in new ways, and then being able to apply software, and then being able to utilize resources in new ways that can deliver more value to your business and, of course, to the customers that you serve. And this is not gonna be easy. It's gonna take some time.
There's gonna be some effort, but it is something that can be done today, and companies can start to extract value right now. And moving quickly is gonna be more and more important. That's something I'm seeing as an analyst, and that was clearly something that Ryan had seen as well.
We talk a lot about that, is the customers that are moving fast are gonna be the customers that get the biggest results and, of course, are able to benefit the most from those efforts. And lastly, we still have to keep all of those considerations that have existed with enterprise applications, with software that runs our businesses. And that's gonna be the governance, that's gonna be the controls, that's gonna be security, and that, of course, is going to be putting people in the right roles and enabling them to do the work.
All those things remain similar but, of course, with a new bend. We're gonna upskill the talent. We're going to think about problems in new ways.
We're going to move more efficiently, and together we're going to drive the future. Great conversation. Appreciate everybody spending the hour with me.
See you all soon. Control, this is Agent Dev. I'm in position.
Copy that, Dev. Stand by for go. Standing by.
Hey, everybody. Welcome to another episode of Agents of Dev podcast. I'm Mitch Ashley, one of your co-hosts, along with my friend and co-host and colleague, Brad Shimmin.
Welcome, Brad. Good to be chatting today again, again and again. Hey there, Mitch.
Good to see you. Uh, it's, it's a nice almost spring-like day, one might say, at least in terms of the calendar, so I'm, I'm going with that. So in, in Boston, there's one-- a nice, almost a nice spring day.
You mean you only have to do one shoveling duty to, for the day? Is that what that means? Yes, that is ex- precisely what that means.
This winter it does. This is the hottest winter on record in Colorado since 90, since like 93 years ago, or some, some absurd number. Yeah.
It's-- We don't have any precipitation to speak of. I, I worry about the snowpack- Just a little bit, but- ... in the Rocky Mountains, I really do.
Yeah. It's very low. Yeah.
We need, we need to get dumped on, and I mean snow. But, in the mountains particularly. It doesn't matter if it comes in Denver as much.
But, good stuff. Well, that's our weather report for today. so- It's, it's always good to keep track, I, I say.
Yeah, it doesn't hurt. It doesn't hurt to catch up. Um, so l- let's kinda jump right into our, our first segment here, and I think you had a few things you wanted to chat about on the call-out.
I do. So why don't you start? Yeah.
The call-out for me this week is an announcement that may, may have gone under the radar, and it shouldn't. Uh, last week from, I, I think it's last week, depends on when this is going out, but I know for sure it's, it's out, and that is, IBM, and their DB2 database, which is a very storied database, that is- Oh, yeah ... important.
I remember when it came out. I was an early user of DB2, for sure, yeah. Me, me too, yeah.
I, I-- It was, it's like so straightforward. I really appreciated that about it. Um, so, so on, March fifth, they will have had launched their DB2 Genius HubWhich is, a step or a stepping stone toward full automation, but they're not pretending to have full automation of the DB2 database.
So all of you DBAs out there, you know, rest easy. Uh it's not meant to, to displace you. It is, it is really...
They're, they're-- They have five tiers that they, uh... Or objectives, steps, if you will, that they wanna go for. And they're really launching this with a, a modicum of, of what I would call pragmatic autonomy, meaning it's, it's completely in the human's hands.
Mm. Uh, it is, based upon their very extensive knowledge of DB2 installations over the course of just a few years, to help you, for example, go from what might be many hours of root cause analysis to, to basically finding out what's wrong in a matter of moments. Uh, and- Mm-hmm ...
that's a lofty goal. And if you can do that with- without in- increasing risk or introducing risk, then yeah, my, my hat is off to you. And I think that they're gonna do it with this.
I think that they have the skills. They have been working toward this for some time now across all of their portfolio, but particularly focused on DB2 here. I, I feel like I- IBM is, you know, moving toward what Oracle initially, had the great idea of with their autonomous database, and that is a database that, you know, doesn't take an army to just keep the thing running.
Oh, yeah. 'Cause- Yeah ... I mean, right now, you know, if you, if you talk to a data professional , they're like, "I, I very much would love to have a l- you know, stratum of data, without the data management.
I just want the data. I want it to be accessible, I want it to be clean, I want it to work. " So if they could do it, I, I would love that.
F. Codd and all the kind of early- Mm ... relational, relational gods, if you will.
I first remember, you know, I still remember- Yeah. Oh, yeah ... you know, third normal form, so help me, Codd.
You know what I mean? All these kind of funny terms we used to say. Well, I mean, and that was the problem with, you know, Oracle Autonomous Database initially was, was, you know, people...
If you wanna do this, you need to sort of have your act together, and not every company does. Mm-hmm. Mm-hmm.
Yeah, it was... This was a big change. But, you know...
So, so, so can you kind of put in, you know, summarize, like what does it mean when we have a DB2 that's autonomous? What, what does that mean? It's, it's like going to the store to buy groceries?
It's up to buying a new car for you? Or is it like, you know- Yeah ... re-indexing itself and, you know, correcting broken pointers and references and things like that?
So the way, the way it's gonna launch, it i- isn't going to sort of ascertain which groceries you need and then go buy the groceries. It- it's going to basically, you know, be with you as you are shopping at the store and say- Mm-hmm ... "Hey, Brad, it looks like they're out of your favorite bread.
" 'Cause there's a- There you go ... there's an option over here. So it's very much in, in the control of, of the DBA, to, to basically set the tone, to decide what they want to do, and then shepherd, which is, you know, a key word for us for this year- Mm-hmm.
Mm-hmm ... to shepherd that process so that they have trust in, in the outcome. So when you're walking down...
" And it says, "By the way, that's on the end cap on aisle four. Just if you go back there, you'll find it," 'cause they always put in everything in two different places, right? So- They do.
They do. Yep. The mysteries of the world.
Well, that, you know, it's, it's amazing, you know, to have a career that spans, you know, the introduction to DB2 and, you know, to where we are now, with it, with AI and... Oh my God, it's, you know... What, what a, what a- Seems like it was just yesterday.
Yeah. Yeah. We're- Just yesterday I was loading the...
re-indexing those files, fixing those broken references, referential integrity, all of that kind of stuff. Yeah. But yeah, it's, it's- And that's what this proposes to do, is fix- Yeah ...
things like that, to, to make that something you don't have to pain over every day. It's something you just say, "Ah, there's a problem. " Interesting.
How do you think, how do you think IBM is addressing the, accountability, the trust issue? You know, we're dealing with data. You know, you don't mess around with data.
You know, find out kind of thing. F around- Yeah. I mean- ...
and find out what you do if you mess with a database. Right. Do not mess with databases.
Um, yeah, I think that it's reflected in their rollout plan. " Uh, "Oh, the shard I have s- for this region, is, is it going to get oversized in, in 30 days or tomorrow? Uh, therefore, I will, you know, you know, redo that," or, "My index is out of date.
I need to update it. " That's level five. This is, this is, you know, very much a tool that, is trained on their knowledge base, their institutional knowledge of DB2 installations.
Mm. And that's a- Mm-hmm ... big deal.
And I feel like that, that's an area of IP that we're going to see increasingly, valued, within our, our industry. So those... You know, that institutional knowledge, the domain expertise, if you will, and what that means for software that, that we rely on every day.
So, yeah, I think, I think they're taking the right approach to it. They, they have the right foundation. They have a much more, you know, pragmatic, as I said, you know, approach to doing this.
Mm-hmm. So I, I have high hopes for them with this, with this endeavor. You know, it's, it's a theme 'cause, 'cause my call-out is about a couple of things.
One is, of all things to go viral, if you go viral on, on LinkedIn, is a, a post about a report that he did of Anthropic calling out IBM saying, "Eh, bah, we don't need you. We're gonna-- we can replace all your IBM COBOL for you. " And, you know, you know- Yeah ...
and that's like, to me, that's like saying, "We don't need developers anymore. Everything's gonna be in the cloud. " You know, how many times do we do this?
The next thing will be the savior- Every year ... of everything else, and nothing will de-exist after this gets done. We're doing the same thing with AI, so you know, I, I'm a pragmatist.
Yeah. Not a skeptic, but a pragmatist, but also like a realist. I like to make it happen.
Anyway, the point being is, you know... So I, I wrote... You know, I kinda watched this happen.
" Well, it didn't. It kept going and, and IBM countered and said, "Yeah, you know, baloney. " So you know, I-- speaking of DB2 and all those things, one of the things if you've been, been in IT for a while, you may not have called it modernization, but we went through these series of re-engineering, redesigning, creating the next generation of whatever apps- Yeah ...
you work in, claims processing, billing, banking, whatever business applications. And sometimes it was upgrading to a, to a new database technology, sometimes just replacing it, 'cause like I worked in telecom and a lot of systems came from, from Bellco, which was the old Bell Labs. And, people were like, "This is great.
We've run this way for, you know, 25 years, but we need something more modern. " Every one of those projects virtually fails because- It is such a- ... inertia?
monumentous scope. Yeah, it is just... And, and I made up this axiom of never be the first or the second project manager on any modernization project- ...
because the first one, the expectations are so wildly out of, out of scope, they immediately fail, so it must be a leadership problem. The second one comes in, gets things kinda back on track, sorta going, but not quite enough to make everybody happy, and so it must be a leadership problem. And then, you know, third one, Brad or Mitch shows up and said, "Okay, I'll help you.
" And we can kinda... We've, we were able to build up enough of the problems that got solved and fixed the things that need going, keep going. Now- So what you're saying- What, what you're saying, Mitch, is, is that for all the project managers that get hired, fired, as we increase, as we go down that slope, if you will, the amount of debt that they inhe-inherit decreases.
That- That's right ... it is... So, so you really want to find yourself that optimal spot on that slope of decreasing debt, and, and inertia that you want to tackle for a, a new job.
Well, I live in Colorado. It's a lot easier to ski downhill than it is uphill, so. Unless you're on a ski lift.
Then it's pretty easy. Unless you're on a ski lift and you enjoy cross-country, which I don't. Um- Yeah, don't, don't nobody does ...
so, so, so I wrote my own... You know, I can't sit on the sidelines any longer. " That's this whole you're gonna re-rewrite all my COBOL.
Okay. Writing the code is that big of the problem. It's all of the, well, what's the business process?
While you're rebuilding it, you're gonna much make a bunch of changes. Well, what's the architecture- Yeah ... of what you built and how does it really function and does it...
Do those people still exist? So to your point, and by the way, my post went viral and it's had like over forty thousand views on it and, you know, once in a while things get up into that number on my LinkedIn, not very often, but for me that's, that's a big deal. But, it's to your point, it's that institutional knowledge, yes, that AI can both help, ingest and become part of it, its skills.
That, that doesn't make up for the intuition, the knowledge, the I can recognize- Mm-hmm ... when this is a problem that other people can't. Yeah.
Because- Yep ... we've, we've lived this experience, either living with the application, living with re-engineering or modernization or whatever it might be. Um, so it takes, it really takes a team.
It takes people that are good in business process re-engineering and rethinking- It's diverse ... what we're doing, being able to do change management, 'cause while you're changing, you're, you're modernizing, guess what? Other people want a bunch of other changes too, so a lot of things pile on all at the same time.
So it isn't just throw it at Anthropic's or anybody else's model and now you've got your problem solved. It, it takes, it takes a lot of elements to suc-suc-successfully complete a, a modernization project. So that was my soapbox and- Okay ...
people jump in- Sorry to interrupt. Yeah, yeah, yeah, yeah, yeah. " And you know, I, yeah, I agree, I agree that that could, you know, help and would help and is very helpful to use.
But you know, I think we're seeing right now in play out in real time this rediscovery of the value of that human insight and experience- Mm-hmm ... that you're talking about, and you can see that reflected in companies like IBM, who, I think in the last week started rehiring or just started hiring newbies. You know, let's bring some people in on the ground floor and show them how this works.
It might help us- I learned a new term, EICs, early in career. EIC, that's the name or term. Oh, yeah, okay.
Yeah, yeah, yeah. So we're, we're licks. You're late in your...
Yeah, or, or, uh- Won't leave our career ... whatever it might... You know, it's, and that's, that's the perfect point because again, it's sort of the overro-- it's the over-rotation on what technology- Yeah ...
will do and how quickly it will do it. Yes. Yep.
" It'll be the yeah, but agents. "Yeah, but what about this? " That's, that's not gonna work.
You know, all those kind of things that the engineering mindset is, I don't say yes until I've eliminated all the nos, right? Okay. Once I know- Yeah, right ...
these problems will be solved, then I'll say that's the right answer. It's kind of that mentality. "Pick, pick whatever the next generation of technology is, that's gonna be the thing that replaces everything else.
It just doesn't happen that way. And yes- No ... this time's different.
There's a lot of things that are different about it, but- Well ... inertia's a big thing. You know, I don't, I don't think it's gonna solve all the, today's problems tomorrow.
Several tomorrows from now it will. No, it shouldn't. I mean, we, we have to learn that the hard way as a species time and again.
Um, just- We do ... just ask anyone from Quantum. Uh, you know, we, we know- Mm-hmm ...
that it's going to happen, but how many times have we over-rotated on that? Um, it's, it's the nature of- It'd be next year. Next year- Right ...
no, it's 10 years. No, which is it? Next year or 10 years?
Which, w-where are we? Well, it's, it's a generational thing, unfortunately. You know, the Thomas Kuhn wrote a book called, um...
Oh gosh, now I'm just blanking on it. It's, it's, the, the revolutions in science are very- Mm ... much episodic in terms of they only change every 60 or some odd years.
Mm-hmm. Why is... What, what is that number, 60?
Why is that magical? Mm. 'Cause that's how long the average, you know, industrialized people, people live.
And, uh- Mm ... it i-is very true. You have to have a changing of the guard, for, for real change to happen.
There, so I did write another paper coming, another report talking about the, the depletion of the talent, talent hiring supply chain- Mm ... this junior developer. Yeah.
Just like last year, we didn't need any senior deve- any developers at all because AI would do it all. This year we're, all we're developing tools for is developers, frankly. And, and now we're starting to realize, well, wait a second, you know, that all's not gonna happen so fast.
We're not gonna have all that stuff in place with AI. We still need people. And role may change, how they develop and grow them may change.
And there was a- Yeah ... paper that came out in, Communications of AC- ACM, if you're not an ACM member, it's the Society for Computer, Computer Management, that, that, talked about... It was actually two people from, Microsoft, in their, I think it was developer relations and also one of their development organizations, an Azure CTO person.
They came up, they came up with a model. It, it's called a preceptor model, which essentially is what is sort of this mentorship, it's almost like peer programming. How many s- one senior person, and how many junior people can that senior person, I would say mentor, but work with, and then someone else who's helping both making sure that those people get the r- well-rounded experiences.
But not just- Mm ... on old ways of doing things, new ways of doing things, things too. So they accelerate and become senior engineers more quickly, but it's based on not just their own experience, which is all valuable, it's also based on what they learn on the job and they learn from more senior people.
" Well, it's, it's important to remind ourselves of that. And as, as you just mentioned, I, I think that one of the most, you know, accelerationist, real accelerationist ideas out there is the, the truth that any discovery is built on every discovery made prior to that. Mm-hmm.
And that you c- Mm-hmm ... you're not just throwing out the old and starting over. That does not happen.
That does not work. Mm-hmm. So I'm glad to see companies like IBM trying to reestablish that cadence of, you know, new people coming in and learning, and then building on that, that knowledge.
Yeah. And Microsoft too. I think they're, you know, a little more visible- Yeah, yeah ...
but I think for IBM, but Microsoft at, at, at Build last year was very clear in their, "We're on this journey together with developers," right? "You're not going away, neither are we. We are all builders," et cetera.
So that, that kind of jumps to, if I can segue, one of the main topics that I wanted to talk about is I just released something called Observability Native. So let me step back for a moment. Um, some of the things that have changed about, yes, we're using agents to create software and we're using AI in the development process, stats from our, from our research show 93% of organizations either are using, heavily rely upon or, or considering, there's only about 30% considering out of that number, using AI.
And this is from, you know, last year when, when a year ago when it was maybe 40% of people were sort of somewhere in that mix. So in one year it's- Yeah ... doubled.
More than doubled. That's a big jump. It is.
And, and s- the things that are different this time are we're using AI agents to build agents, right? So kinda ask the question like, if we need to... The level of accountability we need to have for AI software, whether it's what's built or the software that builds what's built, is, is extremely important for getting AI into production, right?
We're starting to hear about- Mm-hmm ... a-agent accountability as well as agent governance. We're starting to hear governance.
We're hearing about agent behavior guardrails as well as security guardrails, et cetera. " So that caused me to say, "Well, maybe it isn't tilting at windmills this time, but how do we get observability built into the whole process? And isn't that really gonna be fundamentally necessary?
How do you know why it built the software the way it built it, and what caused it to... an agent to go those directions during the development- Yeah ... " So long story short, that's where the windup of why did I do this.
I created this concept of Observability Native. It's not a term that's very w- you know, commonly used, observability and native are, but, it kinda says it in the name, which is-Think of it as 3D observability, not shift left. It's observability everywhere, from the...
We're working on the specs and the planning stages of using AI in development all the way through into operations, and the governance and the provenance and the agent behavior and the act-- the controllability of agents- Oh. -in production. And I think we're at a, a th-- Again, I don't think I'm tilting at windmills, if you're familiar with that term, which is kind of like spitting in the wind, right?
Like, yeah, good luck with that. I think we are at a, a time where because we're using AI in the process, and we have to secure AI and control it and, and hold it accountable while it's developing software, that will con... and security and a number of products into the development cycle.
Again, developers going away, but we sure are building a lot of tools for 'em, for something that's going away. Sorry to ask- We, we should know what those tools are doing. Well, yeah.
It's kind of want to know. It might, it might be useful. Right.
You know what reminds me, Mitch? So, but- Oh, I'm sorry, man. Yeah.
I'm sorry, please. No, no, no. Please, please.
I'm, I'm... I don't mean to hog the microphone, but I am hogging the microphone. Well, you're...
I know you're excited about it, so I'm, I I, I'm with you 'cause I, I am as well, man. And I, and I, see in our research this, this reflected as well on the, on the data side. And, but I'll, I'll get to that in a second.
do root cause analysis. If you only know the database, and you're looking at problems that are happening in the database, like latency for a query, maybe it didn't happen in the database. Maybe it's in the front-end library.
Maybe it's at a gateway. Maybe it's, you know, your EC2 instance on AWS is down, and you don't know it. If you don't have all those, if you don't have transparency and observability across all of those participants in that final outcome, you're-- you, you can't say with any level of assurity what's happening, let alone solving problems when they occur.
uh, this idea of, of, you know, having observable... Sorry, observability native. Woo.
It's like cloud native, but observability native. There you go. Yes.
Mm-hmm. You know, built for observability, is, is critical, and it's, it's... You know, we, we was one of, one of the two thousand and twenty-six prognostications we, we had is that everything is gonna be oriented around that FinOps idea of how do I, you know, control my spend?
And you can't control your spend unless you have observability. Mm-hmm. You start with observability, and then you, then you could just peek at FinOps down the road.
Mm-hmm. Mm-hmm. But if you don't have that observability, it's, it might as well be behind a wall or over the horizon.
Well, you know, and that's... It's a really good point because a lot of what goes into software engineering, I call them engineering problems. When you're s- when you're on a project, there's certain things you don't know how they're gonna work.
Yeah. Problems you haven't figured out yet what you're going to do, whether you're using AI or not, and AI might help, might help you solve that. But one of the factors is always, and how much is that gonna cost?
How many times am I calling the model per second, right? Right. So how...
W-what's my credit card gonna look do I get at the end of the month if you're on a personal plan? of the month for my company? Because I made some choices that had huge implications on the financial end of it.
And that's actually, um... So one, one of the stats from the researcher in, in s- software lifecycle engineering is AI-related areas, AI observability, agent observability, cost, FinOps of AI, are, are, are three of the four top things in AI-related in, in the what am I looking for out of an observability solution, and not just in production, but in development. So...
And that's gone from one thing in the top ten about AI observ- observability, mostly about automation actually from a year ago. So that's, that's, that's how quickly we've gone, "Well, wait a minute. Here's...
" That's kind of inevitable, isn't it? that exist within that software. Mm-hmm.
So it's a day two problem, but you need to build it on day zero, you know, to, to anticipate it on day zero, and you do that by understanding how the thing works. Well, and to... That's a great segue because in creating this idea...
A-and observability natives, it's not a product. It's not a s- piece of software. It's not an open source project.
how do we understand what's happening in the market, and who's addressing what problem, and what problems do we need to have addressed to put AI into production at, with full accountability at, at scale? So I just took the agent process of, of... Because it's non-deterministic, there's some special things we have to do.
And if you think about what every, agent does, just being real simple about it, and that's the purpose is make it simple, right, is, is I created this four-step cycle, right? So the first one is intent. What's the goals of what the agent was trying to do?
What was it told? What was it... What, what was the data?
What was the prompt? to, to consider taking an action, there's a reason why, and what was that reason? I wanna, I wanna know that because then I can understand what it was trying to do, right?
Right. " Well, that agent may change on, on every execution, so you've got to know about that. Second step is the reasoning.
So in figuring out what it's gonna do-How it's gonna solve that problem or complete that task. What did it consider? Why did it, why did it decide that this is the path I'm going to go?
Something in the goal, something in the response from an LLM, data, other information that it had. md file of, of whatever operating system it's working in. md file regularly.
Same with your Claude MD, your agent's MD. Don't just let that sit. Exactly.
Yes. That wasn't a made-up example. That's a real example.
Right. And then speaking of which, you know, the third step is, okay, what constraints were applied? Well, I had all these options, but those aren't practical, those aren't doable.
I'm not allowed to do those things. Um, what guardrails am I operating within and what was applied to it? So it also tells you if the guardrails are working or not, right?
Then the fourth is what the outcome is. What happened? What is the cycle?
And that, that's kind of the process every agent is gonna go through. And you might say regular software does that too, but it's deterministic. You can look at the code to see what it's doing.
Yeah. Very different. Right?
Very different. So that's one element. And then I created these seven principles, and I'm not gonna go through all of it, but the, probably the main thing is treating agent telemetry as kind of a first-class signal all the way through the process from beginning to end, whether it's through the software to operations or it's through the cycle intent through outcome.
Um, we have to have all of that to really have accountability, and we can. I think that's, it's possible to do now because of how we're building AI software, agent software, and using agents to do it. Well, can I ask, Mitch, do you- Yeah ...
do you think... So this is coming from a person who used to suffer through SNMP traps- ... trying to figure out why things broke.
Um, do you think that- Version two or version three, but okay. SNMP two or three. No, I'm just kidding.
Oh my God, I can't even remember. Um, but, I've, I've tried to put it behind me. Um, so yeah, open telemetry, which I, I'm seeing show up quite a bit in agentic tooling right now.
Um- Mm-hmm. Do you think that that is, up to task to accomplish what you're describing? Uh, do you think that it is something that is a standard that we can apply in every layer of that tool stack, or value chain, whatever you wanna call it, to, to accomplish this?
Um, it, it definitely is a huge part of it. I don't think it's the only thing. And again- Mm-hmm ...
observability native isn't throwing out what we did with observability. It's like taking it to the next level. So...
And this is already happening- Yeah ... in the OTel community where they are building the reference model for how da- AI data is shared, right? Building how do we, how do we manage agents- Yeah ...
as well as monitor, et cetera. And they're, they're step-- I mean, these are the vendors that are driving this effort primarily, and just like we talked about vendors rushing to be earlier in the development cycle, that normally would be an operations tool, suddenly an observability tools like for developers, that's happening in the open standards as well. So, I fully expect, confident OTel community will, will be right there and a huge part of the solution, but we'll also see n-new innovations too.
Maybe m- new open standards, maybe, of course, a lot of vendor innovations- Hmm ... that happen with it too. You think like edge cases to, to fill in gaps, things like that initially?
Things like that. Well, fill in gaps. I mean, because even with an open standard, it takes a while for that to get baked in, right?
Vendors are gonna come up with new ideas. It's BCM. Some things they'll submit back to the Linux Foundation.
Uh, they'll keep making products out of it. They'll get acquired, it gets puts in- put into larger company projects. They'll elevate it.
It's that whole cycle will continue to happen. I think the, the main thing is, is the, is the impetus, is the reason to do this sufficient with financial motivations to make this happen? And if you believe- Yeah ...
that for AI, AI agents to operate at scale in production, that you have to have this accountability in place, governance, security, guardrails, behavior, all these things. If you believe that's true, which I do, it won't be a perfect, but that is a huge requirement for enterprises, the industry responds. So I think the, the things are lined up to move this forward towards having observability throughout the life cycle.
Yeah. I... And I think the impetus is there, and just ask anyone who's using frontier models right now, you know, API services.
It's, you're just one bad bill away from colla- You're crushing your project 'cause you just didn't know what it was doing, and it was doing something wrong. Mm-hmm. Well, it's the- Yeah ...
sort of the, like, security people hate ephemeral things because, like, well, it went away. What happened when it was here? That environment's gone.
That serverless thing is gone. Do I have what I need to know what happened? And that's the problem we're solving.
So I, I jumped in there. You were gonna go somewhere next. Oh, I was just gonna complain more about, about inferencing, and I don't know if...
Do you wanna, do you want to, transfer to, to the drop section? Drop. Yeah.
Okay. It's time for the drop. Okay.
It's time for the drop. Go for it, my friend. D-d-do...
Yes. I, I want to ask a question. Um, why, is the inferencing, you know, we, we have many choices now for, for, you know, hosting providers that are offering API services for frontier models.
Take your pick. It can be GLM, whatever. Um- Mm-hmm ...
and I want to understand why, why those are turning into Netflix. Uh, and what I mean by that is in terms of availability, performance, quality, everything is, is geared around optimizing the spend of that provider, not of me, the customer. Mm-hmm.
And that upsets me. Uh- Mm-hmm ... and this is, this is like top to bottom.
I'm not just talking about the neo clouds here. I'm, as, as a user of, you know, a, a certain large hyperscaler's, you know, generative, you know, mo-model repository. Uh, it's been very frustrating over the last couple of weeks to see, some, some, like, degradation in quality with, you know, 503 errors popping up day and night.
Uh, when- I know you're saying ... " And- Mm-hmm ... the Reddit- Reddit sphere is like, "Well, that's just because nobody could use Anthropic now inside of their OpenClaw implementation, so they're just, you know, pinging this model, you know, to, to, to get whatever their email inbox is.
" The next platform. That will block OpenClaw soon. Mm-hmm.
It's just... Right. It's just a game that, that keeps, like, passed, you know, the hot potato, I guess, in a way.
And, but it's not just that. It's not just the degradation. It's sometimes purposeful.
You know, if you think that, you know, OpenAI or Google or Anthropic or any of them are presenting consistently the exact same model with all the parameters available without quantization to everyone every hour- Mm-hmm ... of the day in the same way, you're kidding yourself. You know?
It is, it is, you know, very much a game of optimization for them, and they have to, you know, because these are, these are precious dollars in terms of watts that are available to, to spend in each data center. And so I, I fear, and I feel like I, I... " Mm-hmm.
How could that be? Now just, just think if I had observability into what the agent's doing, trying to call those models- As the consumer. Yes.
I could hold them accountable. Not as the provider, 'cause they already got that. Mm.
Yeah. Well, you know, it's... I, I don't know if th-this is an imperfect comparison, but it's kind of like broadband, right?
You, you, you have one gig at your house not because you can run it at sustained one gig full throttle all day, every day, 24 by seven, right? Yep. They design infrastructure to be oversubscribed, just like an airplane seat, right?
Correct. Yeah. They, they oversubscribe those.
They oversell them. And same thing f-with the models, right? For your $20, your $100, $200, whatever your subscription is, there's a certain amount of usage they're expecting you not to use, right?
That you're gonna be somewhere in the lower, the middle- Mm-hmm ... maybe the upper end sometimes, but you're not gonna be running, you know, red lining full throttle every month. And that's, that's a, a lot of this, well, OpenClaw might push that way to the limit, maybe past it.
That's past limit. Yeah. And that's why they have to throttle it back.
Yeah. So they push us way beyond, and they go, "Well, wait a minute. Hold on.
You know, that's $1,000 a month if you wanna run at that speed, or we'll just block it because we can't control it. It went out of... " So that, that's sort of the...
You know, when you're on the consumer end in a telecom side of it, you look at your bandwidth usage over time. Mm. And you look at the peaks and the valleys, and you look how much you're consuming.
So you know with... when you're, when you're in, within- Right ... your SLA that they should be meeting.
Provision for that. Right? Right.
Yep. And that's what you expect. The, the other part of it, I was just, talking with, you know, speaking of junior engineers coming into, to our industry, I was just meeting with someone yesterday who was working on their own OpenClaw project, and they're like, "Well, how much do I budget f-for...
" I said, "Those are all things... " I do this for... all the time.
Yeah. Yeah. Like, okay, now, how much is this gonna cost if I have this many companies coming in and this many orders and this many videos or whatever I'm doing?
Expect this kind of load. Give me a cost and where the cost is and why that's gonna cost that much. And then as we test it, how come my budget was like I wiped out my 20 bucks in a day and a half?
Hold on just a second. Where did that pro- where did that occur, right? Well, right.
And that, that's... Those are things that we can kind of control as creators. But, but, you know, when you have an asset that you rely upon for what-whatever s- you know, what do you call it?
Uh, you... I, I have an SLA that I want to adhere to for my customers that's latency of no more than two milliseconds per query, for example. Mm-hmm.
Mm-hmm. If I can't rely on the infrastructure behind that to provide that if I'm paying for it, that, that's unnerving annoying. I, I want, I want inferencing to be more like critical infrastructure is, is my entire point of this rant is that I, I, I feel like we're, we're turning it into Netflix sort of, you know, attention economy, and it shouldn't be that.
It is critical infrastructure, and it needs to be something that you can count on as a creator and developer. Yep. Those...
And when you get those edges, those hard boundaries of them not supposed to be there. I remember- Yeah ... I first started using AWS.
The first week I got this message, I was asking for, whatever size survey. " Like, "Hey, wait a minute. " And then, like, I can get whatever I want when I need it.
Oh, I guess it's not. A hundred percent. Right.
There are limits. I'm late for this T-shirt size. Yes.
Come back. Come back in 30 minutes and try again, right? That kind of an answer.
Mm-hmm. Mm-hmm. Exactly.
So, so I want... The, the drop for me isThis is again kind of the evolution of where we're heading and why. Um, Google came out with, some announcements around their Google, their agent, agent development kits.
Yeah, sorry to stumble over that. But it's their SDK, if you will, for agents. Yeah.
And largely, ADK has been, here's the builder tools to build agents. But it suddenly took a different form in the last week or two, and that is, here's an ecosystem of things that are now available at the developer's fingertips: observability, security- Mm. operational environment.
All these ticks off-- tick offs of some open source things that are c- that it now supports and compatible with, but also commercial offerings. And it's gone from an, an SDK or an ADK, if you will, to kind of an execution environment that starts right in the developer's hands, that can do that. " I can make that decision- Yeah, yeah ...
right in the developer's fingertips. So again, these things are pushing up earlier into the process. Those decisions can be made much, much earlier.
But that to me is, again, it's not about writing the code, it's those things that are c- really accelerator and are the multiplying factor of what's happening. We're gonna see this more and more, I'm convinced. I'm with you, man.
Uh, you saw-- you see it with like Databricks buying Neon because, you know, most of the provisioning of that database was by agent tools, not humans. Mm. Mm-hmm.
And you want that stack, you know, to, to be... I want my API to allow me to instantiate anything I need to support my solution without, me having to, you know, drop out, go do an integration, come back and, and hope that it works. I, I love what Google's doing there.
It is. It's fascinating, and y- it, it hasn't gotten a ton of attention. You know, you, you and I go, "Oh, wow, this is awesome," blah, blah, blah.
Um, but I think in the developer community, it definitely does. And, you know, I look for, so what's the Microsoft response with their agent framework, SDK? What's the response from, other technology providers, whether it's an Oracle or an IBM or, or...
You know, the, everybody has their own IDE now, so they can put those things in their environment as well. IBM comes out with this thing that helps you with modernization because that's now at your fingertips. Not just analyze the code base, but process engineering or whatever it might be.
I'm making that item. I'm not pre-announcing anything. But that's, that I think is the stage we're at, is those accelerators are starting to take form and show us where the vendors are headed.
Sign of maturity. I think we're due. I think we, we deserve that for everything that's transpired since the end of 2022.
I agree. It's a lot of fun. Well, what, what do you, um...
So what are you working on these days? You mentioned s- the data, your survey data, your buyer information. Is that coming out soon?
Oh, yeah. Yeah. Or you already dropped that?
Thanks for asking, Rich. I haven't. No.
So, so we, twice a year do a survey of, for, for my group, we do, you know, data intelligence analytics infrastructure practitioners, so everybody who's dealing with the data side of things. And, you know, one of them, you know, this is getting ready to go live probably in a week or two, I think. Okay.
We've finalized the survey. We have all the data, and it makes sense. It's the one thing you can ask for, 'cause I don't...
For anyone who doesn't do this or hasn't done this, you have these, these panels, and you have percentages that you target a, a, on a step-by-step basis when you do a survey, and you watch the numbers like a hawk for each one- Mm. Mm-hmm ... because y- you have your expectations.
" And then if, if you start deviating from that median, you know, as, as you go along, you start getting more and more nervous. Like, either I had the absolute wrong ideas about this market, or, you know, the data's bad, which is it? You know, so, so thankfully, I don't have to worry about either of those horns on the bull 'cause it all makes sense.
So a- at, at any rate, long story short, we were asking about, observability as well, and amongst data professionals- Hmm. Oh, cool ... they, they, you know, you know, overwhelmingly, sixty-six percent said that they're increasing or accelerating dramatically their, their investment in this space specific to the challenges of anything as basic as just setting up a data pipeline to orchestrating a, a, a complex agentic workflow.
Doesn't matter. Across the board, everyone wants this. Wow.
Everyone but four percent. Four percent don't, and I want to understand them. I want to meet them.
Like- See, they're in a cabin in Montana off the grid. and that's not just, you know, in the fields. That's that four percent.
Right? Right. Exactly.
I want to understand them. I really do. Well, that's, that's fantastic, and thank you for asking that in your, in your survey, in your buyer decision-maker survey.
Very, very perceptive, very insightful for you to as-ask that question because that connects those dots, right? Observability is not a, a software lifecycle engineering unique thing. It's across the board- It's the whole...
Yeah ... for all security- Everything ... data, every part of it.
And to that point, it's, it's one of the things that are exciting about this time is DevOps elevated a lot of other practices. You s-saw kind of data start to come- Yeah, yeah ... more into the development cycle, security- Let's Opsify ...
a lot of things. Exactly. And AI is doing that I think even on a greater basis of kind of elevating all parts of what we do to say, "Okay, how's this part of the answer?
" So-Kudos to you. Excited. So we'll, we'll definitely talk about your, your data drop, your survey- Yes.
We can, we can do... We, we might even bring slides. Charts.
Charts. Not slides. Try something new.
Sorry, charts, not slides. Yeah. um, that would show some of this.
So yeah, stay tuned, everybody. Oh, goody. All the, the data wonks in the audience are like, "Ooh, great.
Yeah. " Yeah. We're actually at, at Futurum, we're, we're I think very transparent in not just the methodologies we use, but with the actual data itself.
you know, feel very strongly that the- these are... You know, the value isn't just in the data, it's in the interpretation of the data, and that's, you know, where our, our value comes in. we don't keep everything, everything locked down.
We, we open up a lot of what we do here. I encourage you guys to, to check out, you know, the, the site and what Mitch and I are doing and, and our colleagues as well, 'cause they're all opsifying and, finopsing and, and, observability-ing, verb, their, their practices, and there's a lot of interesting stuff happening right now. There's a lot of treasure chests there, and we definitely see a good bit of them.
There's still more. for people who are subscribers. uh, report on agentic orchestration.
So that'll be out in a couple months or so. And, you know, this is just coming around to, to do a refresh on the software development platforms, but I'm doing this one first. And first of all, massive kudos to you and the platform, the Futurum Intelligence Platform team of how far this process has advanced in six-ish months since I did.
I was the, I was the unofficial guinea pig, the second one to do a signal report, you know, so I'm getting code drops from F- from Brad. that second manager that was hired. Exactly.
I'm like, "Don't change anything 'cause it's gonna change, so just kinda keep... " Brad will say, "Oh, by the way, I already solved that. Here you go.
" You know, all the undocumented things that aren't there. You know, that's the fun part of being an early bird. Okay.
Here's a new problem. Exactly. So, you know, I was u- more using AI to, like, "Tell me what this code does so I understand.
" Well, now it's all plug and play. It's gone, it's gotten to a much easier... There's the things with the companies and products and some of the axioms and the announcements and data and information that we feed into AI to help, help come out with this product, this report.
So I'm excited to do this. It's like redo- doing it a whole new way. It's...
Underlying, it's the same principles. same kind of effect that we're getting of what the output of is. But this will be on agentic orchestration, so a new space that we haven't...
We talk a lot about... you and I do. Um, Nick, Patience, you know, and we all talk about this, so it's good to have kind of a starting place to look at agentic orchestration.
So you can tell I'm excited about working on that too. Plus, this coming week, I'll be introducing yet another, a second framework called the Agent Control Plane Framework. Ooh, yes.
Uh, yeah. Which builds on observability native to say, "Okay, so once you can see this stuff, how do you r- make it accountable? " Again, another framework reference kind of model.
Um, but every vendor I talk to about either or both of these are like, "Yeah, let's get together. I'm gonna see what you're doing. We need...
equally excited about that too. very carefully about, you know, and be very intentional about how we build software. that that's the right approach to take.
We should think really carefully about what we build. Our new unit of measure in software, 10 days. 10 days, yes.
And, and by the way, huge kudos to you too. Brad's been peer review and contributor to helping me with the Agent Control Plane Framework and getting that in place. So just like, Fernando, Montenegro was with the observability framework.
Oh, thanks, man. So observability native. I appreciate it.
This is the fun part of... One of the biggest fun parts about doing this is the funnest part is collaborating on stuff. Nice.
I'm still working through 10 days. I'm not quite past that. It's the word using there.
I, I, I appreciate the word usings. Yes. I have, I have lots of good words.
All the best. All the best, absolutely. Well, I think we've more than overstayed our welcome.
At least I know I have. You're probably- No, this is a long one, wasn't it? still in good graces.
We had a lot to say. Thank you, everybody, for sticking with us. If those of you who are here, thank you very much.
We appreciate you. We do. If, if you don't listen to all of it, we'll carve it up into three different episodes next time, so you'll, you'll listen to it in, A, B, and C, episode 10 or whatever it is now.
So we'll do that. But, not to belabor the point, thanks so much for, for sticking with us. Whether you stayed for 10 minutes or 20 or 50, we're glad that you're here with us, and, we appreciate the opportunity to share with you and talk with you about what we're doing.
We always wanna hear from you. com. com/brad-shimon, as well as mine at mitch-shimon, as well as all the other analysts at first name-last name at, Futurum Group.
Plus, what you don't like, if you think we're, like, spending way too mi- much time talking about, you know, ERD diagrams from, you know, 1982, okay, that's fine. You can tell us that, too. Well, we, we won't listen to you- ...
but, but we appreciate that feedback. Yeah. Thank you, thank you very much.
We're not gonna do that. But thank you so much for the feedback. Snarkity snark.
All right, take care, everybody. Thanks again for being part of Agents of Dev. Thanks to our producer, Corey.
Man, you're, you are number one, tops in the biz, and our, audiovisual team for making this happen. We'll see you all next time on Agents of Dev. Control, this is Agent Dev.
I'm in position. Copy that, Dev. Stand by for go.
Standing by. Hey, everyone. Welcome back to our blockbuster Predict 2026.
You know, as I've said before in some of the other sessions, when I origin- originally envisioned Predict as a virtual event eight or nine years ago now, I always wanted to have it chock-full of analysts that would be making their predictions based upon their analysis and reasoning, and that we'd be able to look back year in and year out and see exactly what came to be and what didn't. Well, now as part of Futurum, of course, we're lucky enough to have the Futurum, analyst or advisory services group, and our next Futurum analyst is one of my best friends at that Futurum advisory team. I- we've known each other, at least online, for many, many years.
Let me introduce you to Fernando Montenegro. Fernando runs the cybersecurity prac- I'm sure he has a full title, but in my mind, Fernando runs the cybersecurity practice at Futurum. Fernando, my friend, thanks for joining us.
It's great to have you. You, you know it's always, always, always a pleasure to speak with you, and, and, and I, I adore every interaction we have, so this is perfect. Thank you.
Perfect. As the feeling is mutual. Fernando, just to set the record straight, what is the, your official title?
Uh, so the, the official title is VP and practice lead, cybersecurity and resilience, right? Excellent. Uh, and, and there's a, there's the, there's a signal there, right?
In the context that we did add resilience, to the practice because... And we'll, we'll get to it on the predictions, right? But it, it is a foundational element of a modern, of what ails a modern cybersecurity team, so- Agreed ...
high up there. Agreed. You know, I've seen it.
We're gonna get into it, but I, I've seen that evolution from prevention to response to resilience, and, I'm looking forward to talking about, talking about that with you. But before we do, let, let's start at the macro level. Let's go 500,000 feet up here.
Yep. You know, 2020, as we look ahead to 2026, you can't look ahead without understanding where you've been. 2025 has been, in so many ways, a watershed year.
I've, I've said it, i- in my mind, in many ways, 2025 is the first year of the 21st century. Up to this point, we've lived on things that happened or were invented or envisioned, right, in the, in the 20th century. The internet, the cell phone, all of these things.
But clearly we are in a kinda uncharted waters, heading out here where no person has gone before. Who, who knows what it's gonna be? But let's just get to the, cut to the chase on this, right?
If you read the mainstream press, even some of our own press, even some of our own stuff that we put out here on Techstrong- Yep ... it sure does seem like there's a bubble out there, right? The, the, the valuations, the monies pledged, the way the money is being kept in a small circle, round and round here.
It, it can't, it just, you know, I, I've been around too long and I've seen too much to buy into the new paradigm, the new reality that this isn't gonna happen this time. I've seen it before. Well, they say, right, the, the fi- the, the four most dangerous words in investing, "This time it's different," right?
Yeah. Well, and, and, I think that as we approach 2026, I think, here we are and we're recording just before it. But so happy New Year, everyone.
Uh- Mm-hmm ... I think that one of the things very fresh on my mind is that the talk of an AI bubble, has grown significantly through the, through 2025. And, I don't know when it'll...
I don't know when we'll see the adverse consequences, but again, w- we're expecting some sort of, of adjustment at some point. What that's gonna look like, I leave it more to the financial analysts. What I will say, though- Mm ...
is that we are, when that comes, I hope that we have learned from the AI winters of before, right? I'll pick a bone with you a bit in that AI was ac- AI is actually a 20th century technology. It just became a 21st century tech- Yeah, I, you know what?
You won't argue. Right. And my friend John Willis actually put out a book about the history of AI.
Oh, my God. A lot of it- It's, it's awesome. I gotta find my, I, I gotta find the book.
Uh-huh. But, um- Yeah, no, it, it, it has its roots It has its roots. But- And- Mm-hmm ...
and way back when, in the early '80s, or early '90s, we, we lived through an AI winter, right? We, we tried a lot of things and it didn't work, and then here we areAnd, and then the, the, the story is super interesting. Here we are now with the-- at the forefront of, of, LLMs improving and whatnot.
The-- looking to '26, what I'm expecting is I'm expect-- Uh, I think that '25 was the year where, okay, we know that we can apply some of these things to security, right? '26 is the year where we do more of it. But in '26, one of the things I'm really excited about is that we are seeing a recognition from the market, and I think we'll see much more of it into '26, that there is much more about being efficient with AI.
And efficiency with AI comes in two forms. The one that, that is super, important, but it's still, it, it's still being developed a lot more, is this notion of what are the things that LLMs can do really well? What are the things that some more reasoning models can do?
What are the things that it can't do? Mm-hmm. And what are the alternatives that we have for the things it can't do?
I want people to, to look up and, and follow the, the-- what's going on around neurosymbolic AI, right? Which is this notion of mixing the capabilities of large language models with the, the formal reasoning that, we've known in symbolic logic like for, for decades, right? Yeah.
Which was the original AI, if you will. Right? And, so I think that I would call out people, pay attention to neurosymbolic AI and formal reasoning, right?
Uh, just name-dropping here, the work that AWS is doing, Byron Cook over at AWS and, and his team is really interesting. They've been working on formal reasoning for the longest time, and, they've been developing things. So I think that we are going to see much more attention to this, how do we actually understand the reasoning behind AI output?
That's one. The other one is we are going to see a little bit more around optimization of those models, right? Uh, it, it's, it's wildly inefficient to ask a high-performance, reasoning model to just do a little bit of IP enrichment, right?
Make API calls to the AP. That's, that's, that's not sustainable. Overkill.
Right. So I expect we'll see much more focus on these other models, and I hope that twenty twenty-six is the year where we're going to see a lot more around the actual outcomes of security, enhanced by AI. So all the AI SOX of the world, right?
The, the, the concept came to mind in twenty-five, right? We are seeing different approaches. There's dozens of companies working on this space, plus the larger vendors.
Uh, I'm expecting '26 to be the year where we start to see more, actual deployments and, and actual benefits from those things. That's on the positive side. Uh, there's the negative side of AI, which is I am, I don't want to use the word terrified because that's, too hyperbolic.
But I am seriously concerned that as a society, we are about to be hit with a, an influx of challenges to how we think about the world, and I'm thinking here about deepfakes, right? Uh, it's, it's interesting. Do you remember-- Like, I'm-- So I have-- My, my kids are in their, like, like, teens and twenties now.
But I remember ten, fifteen years ago, there used to be a really cute app that the, the Santa tracker that you could do, right? Sure. It, it was an app that said, "Oh, here's Santa-" But the, the interesting thing about it, it was from NORAD.
Yes. Yes, exactly. Yes.
Mm-hmm. And, and, and they did the Santa tracker, which was awesome. " Yes.
Yeah. " Right? So that's cute, right?
I just saw a deepfake video this week that blew my mind in the context of, uh... It, it had to do with the, with the selfie and, and movie, and movie actors. The same guy taking a selfie with the Star Wars crew, then switching it around and, and showing the, the Lord of the Rings crew, and then sh- and then The Matrix.
And, A, I love movies, of course, and so that, that really cool deepfake. But oh my God, we are not ready for this. And we're not ready for this not because people are going to fake, not just they're going to fake a, a, a high-profile celebrity, but society is built on trust.
And I challenge people, myself included, to find the difference between a good deepfake and not. " Right? Somebody's going to look in more detail and whatnot.
But on the day-to-day stuff, right? We are, we are-- This is going to be really, really interesting to see this industrialization of, of the erosion of trust. " Right?
It is so true. What a great quote. Right?
Absolutely. We are going to have to deal. Absolutely.
So '26, it will be the year where deepfakes make even more inroads than before. Sorry, I'm, I've-- That's, uh... I didn't mean- No, no.
I, I don't disagree ... I didn't mean to go to the pessimistic side, but- You know-Look, personally, I, I play with Sora. Yeah.
And I've been using some Sora videos on some of my Shimmy Says stuff. It has me walking the floors of AWS re:Invent when I never went down to the show floor. It has me, oh, as a football coach.
It ha- all kinds of things that are just crazy. But, you know, when I look at what we just discussed, Fernando- Yeah ... I wanna wrap it up, tie the bow on for our audience.
Sure. You know, we, we called this section the bubble in the brain. Yeah.
And clearly you could have a financial bubble. Doesn't mean the technology underlying it is bad. Absolutely.
Right? Absolutely. You're absolutely right.
The technology's real and getting more real and better. The, the expectations of the financial industry to me- to a certain extent have created the conditions for the bubble, but, but the technology absolutely works and, and it's there. But, you know, you told a couple of great examples and stories here, Fernando.
My question to you for 2026 is can we keep up the pace? Can the technology keep up with the storytelling? These deep fakes are sca- it is, it's scary.
And, and we... And you and I, look, I would consider you and I relatively tech-savvy people. Absolutely.
What about the rest of us? Absolutely. What about the rest of the folks out here?
Absolutely. And, and this is where, I, I call upon the security industry more broadly, right? Our mission is to help organizations with trust, so we need to be aware of this, and this is something that we need to handle, not necessarily through a deeper technology, solution.
But we have... I, I keep saying that one of the things about AI is that AI should be teaching us all to be business process engineers. We should all be analyzing how we do things.
I'm doing that in my practice of an analyst. Mm-hmm. How, where we do things, where does AI fit, where doesn't it fit, and so on and so forth.
And I say the same thing for trust and verification, right? How, how... And, and, and there's an army of people working in anti-fraud who are, who are well aware of, aware of this and are doing this in the context of how do you know your client in banking, right?
Um, how do you help, like, how are you doing voice prints on, on IVRs and whatnot, right? Or, but I, I, I caution us that this needs to flow down to how you do help desk authentication, right? How do you do, package delivery?
How do we do remote web calls, right? Uh, it's, it's, it... I think it'll be a challenge for us, right?
And the challenge will be answered not just with technology, but with, with business process understanding as well. Yes. Fernando, I'd love to discuss just this with you for the whole hour- Oh, yeah, look ...
but we don't have time. I wanna move on to the next segment that we want to discuss called A- Agents and the Ball of Fire. So- Now, the ball of fire, just so let's get that out of the way first.
The ball of fire, actually, we give credit where credit's due, it comes from F5. Yes. Yes.
Yes. So F5 came up with the term years ago, and I love it, right? I, I, the i- it's the idea that the modern application is not, it's not the old data centers where we used to do, external router, firewall, internal router, DMZ, DMZ, in, like, application.
No, no, no, no. It's a mishmash of APIs calling other APIs, calling a, a SaaS service hosted on a cloud, fronted on a content distributor, like, with code running on a content delivery network, right, running on the edge. And, and, and, and so that's the, that's the idea of the ball of fire, right?
And, and I think it- Mm-hmm ... it's perfect. I love that one.
I love that visual. It really is. And, you know, look, I grew up in a, in the moat-and-castle era.
Yeah. Right? Yeah.
Which is what you described here. And then the cloud changed that forever. But now in an age of, of agentic AI, and of course everyone says 2026 will be a, a year of agentic AI and agents, man, we really, we, you know...
Remember the old Jericho Forum, the deperimeterization? Yes. Absolutely.
Absolutely. Right? There's no...
We don't have a perimeter. We don't have the moat and castle. We don't have a DMZ.
Well, what do we have? So, so it's, it's, it's super interesting you brought up the Jericho Forum because it's, it's, I mean, w- we hear it all the time now, identity is the new perimeter. Yes.
Excuse me. Identity has been the new perimeter since the Jericho Forum, right? The, the...
Actually, I, if I'm not mistaken, the term about, the, the expression identity is the new perimeter, the first time we, we came across it was 2005, if I'm not mistaken, right? Yes. So we've, we've added...
Now we've actually, if, right? But now it's true. I mean, look, I'll tell my personal feeling.
Identity was the killer security app of cloud security, right? Z- I- identity and access control became the killer security app for cloud because it was all we had, right? We no longer had the perimeter.
We no longer had the router, the firewall, the IPS. Which is exactly what we want, right? Mm-hmm.
Uh, so we're now just extending it to, to, to agentic, workloads. And we have all sorts of, of interesting, ramifications from that. So the twenty twenty-six, trend/prediction is that we are going to see advancements on, uh-- we're, we're going to see advancements both in terms of, of, of deployment, right?
Whether it, whether it's centered on stuff like Microsoft's, Entra ID, whether it's, it's other technologies or other vendors, right? We will see this, this formalization around agentic identity. And the, the, the important thing here is that the, the-- I, I go back to business by, uh-- I sound like a broken record.
I go back to business process engineer, right? In the context that in the world where we have the, the ball of fire technology stack, right? A vulnerability, an, an envi- an, an organization's vulnerability is not just, it's not necessarily just the technical, "Hey, I'm behind on my patches," and somebody can do, can, can, can exploit the technical vulnerability and, and run over a buffer and, and, and do something.
The vulnerability is the misconfiguration and the access control, right? And that is what is allowing people through. It, it's the, the, um...
So in that world, what we need to do as security professionals is, okay, how well do we understand which identities we have, right? Where-- How are those identities interacting with other elements, sorry, on, on that ball of fire, right? Where do permissions come in?
How well is that process, governed? How responsive is it to change? How responsive is it to scale, right?
Uh, if I have five hundred agents, do I need, uh... how do I refer to them? Do I ha- do I refer to them as agents one through agent five hundred, or is that pool of agents one instance because they all do the same thing, right?
What- Well, i-is- Oh ... isn't it Agent Smith, like, from The Matrix? I, yeah, I always wondered, right?
If you think about The Matrix, how did the Matrix... I mean, Agent Smith was his name in relation to the Matrix, to, to, to what people saw there. How did the Matrix keep track of the multiple instances of Agent Smith, right?
That's, the- Well, were they ephemeral? Were they persistent? How does it relate to...
I mean, look, Fernando, we, we could, you know, we could do a whole session on that, you know? And, and the, the- And, and- ... The Matrix and its relevance to today's agentic AI.
Well, it, the, the, yes, and, and, and I mean, it was a landmark movie, right? So- Uh-huh ... yeah, it, it- But, but I got to tell you the truth, I never thought of this when we were watching that.
Oh, absolutely not. Yes. But, but here's, but here's my point, though.
And I, and I-- and please, my security friends, don't hate on me for this. We're hanging on by our fingernails. Right?
Just with human identity issues, and then we added APIs and Kubernetes and containers and machine identities and artificial identities. And now you're saying, "Hold on, hold on. " Who are we kidding?
Are we, are we remotely capable of managing this, Fernando, in the coming year? We-- This is one of the areas where I'm positive in the sense that you, you brought up cloud, right? I remember when we first started on cloud, the, the amount of, of information around it was relatively sparse, right?
Mm-hmm. Uh, people were, were experimenting with it. With AI, I am blown away by the amount of information that the community has ri- have, have rallied around, right?
There are OWASP, top ten for agentic, for LLMs. There is guidance from NIST. There is guidance from SANS.
There's guidance from, from, CFA, right? Everybody. So we have the right am- w- I, I think that the security community has realized that we need this, right?
The question becomes: how do we see the forest for the trees, right? When it's-- is it worth for each organization diving down into the finer points of MCP and A2A when, yes, you're going to deploy agentic at some point, but you have a massive problem with, over-provisioning or, or, or overly, or over-over-permission systems already, and should you fix that first, right? And, and- Right.
So I am, I'm optimistic. I think there is plenty of, of technology out there that's doing the, the, the visibility, the, the, the blocking of, or the, the right-sizing of permissions and so on. The question is, how well does that stuff work at scale?
How well does that stuff work in the world of the ball of fire, right? Because things are- Yeah ... beautiful inside the moat, but the world is different.
But there's chaos out there. Right. There's chaos out there.
How does it work in caddy, add parentheses, chaos? Yes. Um-You know what?
It's a, it's an interesting question. Um, you're optimistic. We'll, we'll come back to it, but we've got to keep moving, Fernando.
Absolutely. Absolutely. I wanna move to our next segment: buying dynamics- Yeah ...
the, the conversation around the reality of platforms, if you will. So this is super interesting because I, in this world where we currently are, there is, of course, a, a, a dichotomy. I, I-- There is a distinct-- this con-this conflict between am I buying a platform?
Am I, am I buying point products? By the way, I tend to prefer the, the ma- framing the discussion as platform versus point product, not platform versus best-of-breed, because you can have a best-of-breed platform just as- Sure ... you can have a, a good enough security product, right?
It, it-- If you really want to be complex about it, there's a third dimension, which is insource versus outsource, right? Build, buy versus have someone run it for you. And, and we are just about to publish, I think when people listen to this, we'll have published our, cybersecurity decision-maker data, collected in the second half of '25, fourth quarter.
And the data shows two things. The data shows that people maintain a preference for vendor consolidation and platforms, right? So we still, um...
But it's not absolute, right? We're not saying, "Oh, there's only going to be a single platform," right? Uh, no, that's not the...
But there is a preference for platforms, and the responses indicate a preference, a, a slight preference for buying my more point products in the fact-- in this edition of the survey than they did the first one, right? And the way we're looking into this is that we think that we're seeing people open to the idea of point products for these frontier areas, for, for the, I need something here. Now, of course, all the platform vendors are smart enough, and they are adding those capabilities.
We saw, a shopping spree, particularly in the end of the third quarter of '25. Uh, Check Point was picking up, CrowdStrike, SentinelOne, Palo picked up before, right? All the little AI companies, right?
So AI security companies. So we're seeing, we are seeing this notion of people indicate they prefer platforms. They, they are open to buying, they are open to buying point products in, in some selected areas.
The, the key message here, though, is like when we look at the data and people ask, "Okay, what's troubling you? " Of course, number one is we want to address the threats that we have and so on. Number two on that list is integration.
It's too complex to get everything together. So whether you have a platform or whether you have a point product, right, the end result must be that whatever you bring to market must integrate into someone's environment well enough, right? Whether that be you're taking in telemetry, whether that be you're taking in identity, whether that be you're, you're using a, a standard for data output, whatever it is, right?
But, the reality of platforms is, yes, platforms, but they must be open enough to be integrated. Yes. Yeah.
You know, whenever I think about the platform versus point, I'm reminded of a conversa- a series of conversations I had with Chris Hoff. Oh, God. Amazing.
You know Hoff. Yes. Yes.
Back in the NAC days when Still Secure, my company, was one of the leading NAC vendors, we, we got into this riff around, product versus feature. Because my experience, Fernando, is today's point products are tomorrow's features in the platform. Sure.
Right? Sure. And, and so it is just when we look at these point products, we're looking at them because the temperature hasn't yet allowed them to turn to ice or gas.
They're still liquid. But at some point, the, the physics change, and it becomes part of a platform. And, absolutely, one hundred percent.
And, and I applaud the, the founders and the, and the entrepreneurs who navigate this conversation because on one hand, they have to navigate the conversation of making their product relevant enough to be bought in the market, so you find product market fit, right? But at the same time, you have to architect it so that it can either grow into a platform yourself or be acquired into one. So the-- It's a really interesting conversation.
Sorry, I, I know we can talk about this. Yeah, no, and, and we are running low on time. But, like, one more thing I want to mention to you and your comment on, are we already seeing this with some of the buys you, you, you mentioned there?
Everything, you know, from the CyberArk to the little AI tuck-ins, if you will, that we're, we're seeing these companies make. Are they already taking these points pro-products, excuse me, taking these point products and tucking them into the platform? I think that, that this is what the platform vendors have known to do extremely well for the longest time.
Cisco has been phenomenal- Sure ... at acquisitions forever. Palo Alto- Check Point ...
has been very good at acquisitions. Palo. Right.
CrowdStrike and SentinelOne are getting their, are, are, are getting their reps in as well. I mean, they're newer, of course, right? CyberArk is, is slightly different because it's Palo Alto's largest acquisition- Yeah ...
by far. So we-- I... But they've, they've perfected the, the, the, the tuck-in game really, really well.
So I expect to see... And, and we've seen others, like we mentioned F5. Uh, so w-w-we've seen this, this corp dev motion of acquiring tech ends and, and, and doing it well enough.
I think that we are-- we're hitting a stride there. Right. The question for the, for the, the, the platforms become, okay, how do you incorporate them into your platform in a way that preserves the, the, the velocity of the feature development without getting bogged down into the everything else around the platform?
Excellent. I gotta keep us moving. We're, we're lo-low on time.
Right. And there's- Every talk point ... this last segment I wanna make sure we hit.
Yep. Resilience in the boardroom, very important. Oh my God.
And so I, we, we called it out of a major trend for, for '26 on, on account of, again, the force function from AI in the, in the context that AI is touching the business, security is touching the business much more prevently-- much more present, right? And that also means visibility from the, from senior leadership on how we're going to do this. How does...
how do we quantify the risk of AI, right? So we really expect to see some movement around cyber risk quantification, right? There have been many vendors who have been, fine-tuning their, their offerings around risk, and just calling, just as, as a reference, not as an endorsement.
Like, I mean, Qualys has done a lot around their, their risk platform, right? Rock. Yeah.
Yeah. And, and, we're seeing others as well. So there's one-- that's one side of the conversation.
The other side of the conversation is that boards and, and senior leadership were already worried about one other thing, and they were worried about ransomware, right? Because that- Yeah. Like let's not forget, cybersecurity doesn't stop just because AI is, is, is busy, right?
Ransomware has been a, a, a phenomenal threat over the past fifteen years, give or take, right? Uh, fifteen? No, perhaps, yeah, give or take, right.
I think the brain virus was even earlier, yes. Yeah. But, the, the thing about ransomware is that it's been foundational in terms of how do you handle data protection, right?
So one of the things we've observed over the years has been the evolution of data protection vendors, backup and recovery, right, dive deep into cybersecurity. Here we have, Veeam and, and, and, and Commvault and, and, and now Rubrik and others, right? And what we're seeing here is that they first, they acquired capabilities to tackle ransomware as a use case, right?
So you have quick recovery, you have clean room recovery, you have, assisted by AI, right? You have, much more efficient snapshots and, and, and, and all those things. Now we're seeing those vendors move for-- move further into data security, right?
We saw acquisitions, right? So, Rubrik with Laminar before, Commvault with Satori and, and, and, Veeam with Security just recently, right? So this signals that they are moving closer to a data security platform, right?
So I think that we'll see significant, messaging and, and, and I, I think movement around that area. How do you... Securing data gets platformitized as well, right?
Uh, I'm curious to see, I mean, I mean, Cyera is a large name in this space as well. Yeah. Right.
So, we'll see, right. I think that there is a, the, the two areas around governance is this resilience aspect and then the, the, the risk quantification. The other thing I want to bring up here, bringing the ball of fire again, is that how do you do governance when the, when your supply chain is so immensely complex?
Here, I'll call out two things. One is, how do you handle third-party risk, as, as third-party risk management? The other is software supply chain security.
Our good friend Mitch Ashley is a master at this, and, and he and I collaborate on, on supply chain security, right? Yeah. That's another area that, that we're really interested in into, into '26.
And I know we're running on time. Interesting. Yeah.
When I look at ransomware in 2024, truthfully, it was a lot scarier in 2024 than it is in 2025, and it will be in 2026. I, I think we've made actual progress. We've gotten smarter about ransomware.
I think we're accepting it. I think that we, we've gotten so th-th... A-again, this, this whole resilience and governance thing is a whole trend on its own.
We can spend an hour on this alone. Yeah. One of the things we're watching very carefully is how are cyber insurers, playing a part in this, right?
Well, they, they drive, especially in ransomware, they drive a lot. They drive a lot. A lot.
But what I want-- I, I bring this up because I think that we are learning to handle it as an incident a little bit better. We operationalized it- Yes ... if you will.
Yeah. So- I, I agree. Yeah.
But here's the thing about resilience. I think resilience is a lot closer to the language that business speaks. I think resilience is something that businesses understand inherently, where they don't understand the bits and bytes of ransomware or AppSec, e- or even software supply chain security.
At, at some level of the business, nor should they, right? Right. Uh, there are-- So this is, this is the other thing that, that drives a lot of our research, which is how is cybersecurity management changing, right?
And we are, as we get closer to the business, what changes in the language that we do, right? At, at the same, what changes in, dare I say, the political-Uh, games within an organization, right? Who reports into the CISO?
Who does the CISO report to? How much- Mm-hmm ... pull does the CISO have in dictating what engineering should be doing or what finance should be doing or, and vice versa?
Like, where does that responsibility fit, right? And I think that it varies but for each organization, right? It's, one other area to, to continue watching is how do, how do we change our management practices?
But again, another hour on this alone if you- Absolutely, and we're already in overtime. Yeah. But I'm not stopping us now.
Yep. No. It's too...
We won't stop now. But Fernando, I do wanna move to our closing beat, and that-that's the one thing, right? I-I...
Big fan, Billy Crystal, I don't know if you remember that movie, with Curly. Uh, Jack Palance plays Curly. So City- City Slickers.
City Slickers. Yes. Jack Palance always says, "Just one thing.
" So I'm gonna ask you the one thing. We've covered a lot here. Our folks watching this on Predict, what's that one thing they need to take with them?
The one thing is you need to make your decisions based on a realistic threat model. And that you need to make your decisions on that realistic threat model. And what goes into the, into that threat model is what the, the secret sauce is, right?
What goes into that threat model is where is AI right now, and where is AI going? Where are the adversaries right now, and where are they going? Where is our organization right now, and where are we going?
What are the constraints that we have? What are the regulations that are coming down the pike, right? What are the things that we need to...
Like, what does that ball of fire, right? Even... A, an even bigger ball of fire, right?
If, if that ball of fire is usually technology, right? What does the, the, the, the, the ball of fire, what's the, the ball of fire surrounding the ball of fire in terms of the regulatory? So I think that the, the one thing is manage things according to an up-to-date and realistic threat model, right?
I know it's a kind of a cop-out, but that's the only way we're going to get through this, right? I agree. " Fernando, we're out of time.
We're over time. My friend, it's been a pleasure. Thank you so much for appearing in this year's edition of Predict.
We'll look forward to see how this plays out over the coming weeks and months. Of course, we'll have the benefit of having you nearby to continue the discussion. It is an honor, my friend.
Thank you very much, and I look forward to seeing you in person and remotely, throughout the year, right? Absolutely. And again, if you wanna follow Fernando and see what his writings and pred- not prediction, well, he does predictions here.
But if you... com website and look it up there. Unlike a lot of analyst firms, most of the content there is not even behind a reg wall or a paywall.
You can go download it and s- read it for yourself and reach out to Fernando and the rest of the Futurum analysts on that. But for now, on behalf of Fernando Montenegro and myself, thank you for joining us in our cybersecurity section for Predict 2026. We've got a lot more coming your way, so enjoy.
Also, I should mention, in our exhibitor booth area, the Futurum Group does have an area set up, I believe, where you could download a lot of the latest research from Fernando and his colleagues. So check that out. We've got more coming on Predict.
Check it out.