Techstrong TV – March 4, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. You're developing software. You have a feel the vibe.
Well, vibe, coating's real. You're watching Texture on Gang. Yeah, it sounds like something out of a Beach Boys song, but I don't know.
Happy Tuesday to you, you know, feeling the vibes, you know, it's got that California dream in. I, I don't know. Help me, Rhonda.
But, um, welcome to Textron Gang here on this Tuesday. That whole vibe thing's got me going. I hope it's got you going.
I hope you had a, uh, great Monday. Let me introduce you to our gang members today, and we're gonna jump right into this exciting, exciting, uh, lineup we have for us today. First of all, joining us out in Colorado.
He's the FU and VP analyst for DevOps, app dev, all that good stuff. And our friend, the guitar man, Mitch, Mitch Ashley. Hey, Mitch.
How are you? Sending You good vibrations. Sending a good, good, I I'm digging it.
You know, I saw this biopic on Brian Wilson. What a sad, yeah. Sad story That is, um, jumping over from, you know, California dreaming a New York state of mind.
Yeah. You see what I did there? Mm-hmm.
He, it's, he's our chief content officer, Mike Ard. Hey, Mike, how are you? I'm doing well.
Good to see you guys. Excellent. Good to have you on.
So, you feeling the vibe today? I, you know, I'm always feeling the vibe for better or worse, but, Alright. And then joining me here in our Techstrong studios in Boca Rat Hotel Florida, she's our Echo Insights editor, analyst, as well as author of a new report That's right.
That we covered. If you haven't checked that out on the gang, please do. It's our own.
Bonnie Schneider. Hey Bonnie, how are you? I'm great.
Good to be here, Ellen. Good. All righty.
So Mike, I, I, I kicked it off. You know, the new, the new cool thing is vibe coating. What's old is new against, I get out like my flower power elephant bells.
And, Uh, I'm not quite clear on it myself, and I was gonna ask Mitch, but vibe coding seems to refer to this new, essentially end users are building their own software again, and maybe we just think there's gonna be more of them doing it. And there's a lot more reports of that. People are writing tens of thousands of lines of code, and I don't know, to your point, maybe I do throw on some beach Boy tombs and throw back a couple of gummies and away we go.
Well, you're talking to the right guy in Colorado. There. Is that what it's about?
Mitch, Let me know what you need. Well, a so actually by coding, the, the term is not very old. Only about a month and a half or so old this term by Anthony, I'm sorry, Andre Carpathy, who was one of the co-founders of OpenAI.
He was head of AI at Tesla. You know, this guy's no slouch, but essentially it, it is for developers. It's not just end users.
What it is, is, I think of it as leaning in to ai. Just, just do it all with AI and starting with that natural language interface. So describe what you're trying to build through natural language, iterate on it, uh, through natural language.
You know, you're not sitting here at an IDE fixing all of this code. You're using AI as much, as much as you possibly can to create and then set up and deploy code. And so what what I like about it, it is, you know, there's tiptoeing into AI use and development, you know, cautiously kinda learning it.
This is what can you do if you really kind of hand the reins to AI as much as possible? And that's, that's it. It sparked a debate.
Not everybody's on the, on the same page about this is a good idea, yet or not. Mm-hmm. Yeah.
There's more than a few developers out there who are saying this is gonna have a bad outcome because, you know, the software will be buggy, it won't scale. There'll be security issues. And yet, Alan, we've talked about this.
I mean, ultimately we think there's gonna be millions of people building software. So is this the start of it? Yeah, I mean, you know, this, this is a little truth.
Speak to me. And, and of course we live in a world or a country where truth speak has become the defacto standard. So is vibe coding really just AI generated code for the most part?
And it just makes it sound better. We wrapped it in a, in a, uh, California dreaming wrapper. I mean, that makes us, you know, It makes it sound more, it makes it sound more fun, at least, you know.
Yeah. Feeling the vibe. 7 sonnet and start describing what you want it to build and let it go.
I, I think the, the possible, one of the possible downsides is this takes off. And to your point, you know, a whole bunch of crap gets generated, gets created, it, it could put a whip blanket on, you know, AI generated code AI use and development. I don't know that that's gonna happen, but, you know, if it took off and everybody and their brothers doing this and just deploying whatever you got back from sonnet or whatever LLM you're using, that's not a good idea either.
Yeah. I will tell you what I like about it. So the whole software development process has always been a little cumbersome, to say the least, where, you know, end users put down something that feels like a requirements document, and then that gets handed off to a bunch of developers and it's a left brain versus right brain conversation.
And there's successive iterations until we get to something that feels like compromise rather than what we actually want it. So is there a way to think about vibe coding as end users describing something to the point where they understand the process and the thing that it, that they want it to do, and then maybe the code is open enough for the developers to go in and refine it, to get it to the point where we need it to scale and do all those important things that are called professional software development? I think that's a great point because that's, uh, sweeting the efficiency of it, making it a productivity process go faster.
And I'd be curious, and with the vibe coding, if depending on, you know, how it's been programmed or who's, who's behind it, if it innately is seeking to keep the code more clean and more green, I, I don't know. I haven't really looked into that, but I think it's an interesting factor to see if it, if there's an innate process that might actually do that, where a software developer might miss the mark on that. I think it's more LLMs are focused on better security, green code, things like that, those kind of things will happen.
I think now we're, we're at this, can you do vibe coding and really kind of do more complicated software architectures or design patterns, or is it just gonna generate what it's gonna generate? And you kinda live with that. I think the other benefit though is you can also take code that's been generated, even not existing code bases and say, tell me what this stuff does.
Right? I don't want to try to learn this by walking through the code and, you know, in my head while the logic paths and understand what it does, just gimme a really good description. Now here's what I want you to do with it.
Take that and do the following. 'cause you may not up touch that code in months or years even, or someone else's code. I'll tell you the other thing I like about it, and let's be truthful, a lot of corporations, you know, come up with great quote unquote ideas for developers to go implement that are just boring the developers to tears because it's just the same old frameworks and crap over and over again.
And maybe, you know, would be more exciting for everybody concerned if developers did stuff that was more interesting and challenging and the machines took care of all this rot stuff that, you know, end users need. And it is kind of crucial, but it's not all that complicated. At the end of the day, we just need something to do something.
Well, it's, rather than adding one more thing to the developer's plate, we all know about schlep and other things like that. It is, it is a different way of doing things that you can see if this is gonna be more productive. You spend more time trying to wrangle whatever LLM to give you the code that you want that's working properly as safe, secure, as green as you want it.
Or is it actually making you more efficient? And how far can you take that with vibe coding and imaginable event advance, you know, week to week of more things you could do with it. Uh, but it's still experimental.
That said, I think that's what, you know, folks like Meta and, uh, Oracle and, and, uh, Salesforce are saying about when they're talking about reducing developers in kind of that mid-tier, they're talking about moving to something like Vibe coding. Well, I gotta say, I just give them an A plus for choosing the name. Man, what a great name for this.
The guy's got style I have to, right? Good for him Style points for the name. Yep.
No doubt about it. No doubt about it. I, I would add one more thing though.
And I, and you and I have gone around on this before, Mitch, but it's like, you know, end users have all had the same experience. They're like, oh man, I got this software idea. I need a piece of software that does this.
And then they go marching down to the dev it team who looks at them, nods their head and says, yeah, that would be awesome. And, you know, here's your ticket and you are now project number 347 on a list of 512. And we might get to that in three years.
So, you know, we might actually get to the point where we do have more software developed faster because end users won't have to wait in line. Can, can you imagine you as the end user requesting this using natural language prompt, you know, gen, uh, gen AI prompt to say, now does this application do this? 'cause I, that's what I asked Mitch to make sure it does this, this and this.
Does this app do this actually query, query the code base and it'll tell you without dragging you through code or mystical development terms that end users may not want to know about. Right. And there's gonna be an AI agent that's gonna review the vibe coding.
It'll be called Buzz Killer. And, and we'll, you know, look at everything and say, is this legitimate or not? Crazy, crazy world?
All right, let's take a break. We'll come back. I didn't see it at the Oscars the Sunday night, but we, is there a new movie attack of the, or new video attack of the Killer Robot?
Must be one of those Chinese films you're watching. Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back with Mitch Ashley, Alan Shimel and Bonnie Schneider, who's, um, and we're talking now about robots.
And we had a chat about this last week in an episode where we were discussing meta and their ambitions in building AI for consumers. And I don't know, truth may be stranger than fiction, but apparently there's this Chinese robot that was in a crowd that went a little bit crazy and had to be restrained by security people. Uh, nobody I don't think was killed, but it kind of got everybody wagging their tongues for sure about, well, is this gonna be like Isaac Isabel, I robot?
Do we need to kind of have guardrails or, or are we just gonna like, turn these things loose? I don't know. Alan, what was your take on this?
So first of all, in in truth speak language, we don't call 'em robots anymore. What do we call physical ai? Okay, It's physical ai.
Um, but that being said, look, I I think, you know, it's more like Robocop than I robot, right? Maybe it was, it's an early robot. I heard, I heard the robot was named Tianmen.
Um, so who, who knows? I mean, certainly, look, here's my prediction. And you could say Shimmy said it first.
The first Rob, active functioning robots we're gonna make are gonna be soldiers, and it'll probably be the US and China that do it, because that's a great use for them. And if you're gonna have soldier robots or you know, physical ai, uh, soldiers, I think killing and hurting people is gonna be part of their programming. Hmm.
And I think we're a ways off from being as civilized or as enlightened as the third laws, you know, the three laws of robotics and the zero with law, right, Mitch? Yes. That we saw.
There's Laws now. Yeah. But yes, Uhhuh That you see in the, in the Asimov thing, we, we've got, we've got some barbarian years to go through.
First I'll pause it, a scenario that looks like this. Somebody cuts and paste code from the soldier robot into a senior healthcare robot, and suddenly some old guy is screaming at a bunch of teenagers, just get the hell off my lawn. And then the robot goes and attacks them.
So, Wow, that sounds like a Clin Eastwood movie. Stick the lawnmower on the robot lawnmower. You know, I have to think of, you know, star Wars and the Clone Wars, you know, pretty soon we'll have clones that'll you and, and Star Wars parlance that are droids.
Right? They're not robots, but same idea. So, uh, we'll, we'll see.
I mean, I, I think you're right. Alan would definitely see military applications of this. And whether it's AI aided, you know, fiscally aided soldiers or bought soldiers themselves, robot, I don't know about physical ai.
That sounds like it'd be a lot of things. I'm not sure what that, but that, that doesn't jive me like vibe coating. But anyway, we'll come up with a better term.
Okay. I I, whatever you droids. What about droids Aren't the you're looking for?
Yeah. Could be. Well, Well, well, let's take this to the natural level of the United States thinking, um, and the Bill of Rights.
But let me get this straight. If everybody else, especially those criminals has robots, I'm gonna need my own criminals, robots to fight the criminal robots. And it's all gonna be crazy.
The Bill of Rights have been suspended and it's an emergency thing. Don't worry about it. I is, is is a robot part of, or will be covered under the right to bear arms.
I don't know. Right. To bear robots if, if, if the robot's a weapon under the Second Amendment Versus Rosie the robot house cleaning.
Yeah, That was a good one. I liked Rosie. Yeah, you spoke about Rosie last week, right?
Judson? Yeah. So, so will Smith and Wesson make robots?
Is that what we're saying? Well, but but think about it. I mean, you know, if you are, if you are, if, if you're making warrior robots warrior droids, right?
Their aim is probably gonna be really, really good. Their weapons that are built into it are gonna be really, really, well, I don't know if you do them Mitchell without ai, because what good are they without the ai, quite frankly. And, um, you know, and, and not just soldiers like an army, you know, clone wars.
Seriously. Robocop robots walking the beat. Well, we know, we know that, uh, at least from Star Wars, that the bots, the droids will be much more accurate than, than the, uh, storm troopers.
The clones. Yeah. Well, the storm troopers always a little buffoonish, aren't they?
They, yeah. On, on, on the plus side, you know, when the planet is drowning in water because nobody paid attention to Bonnie. We can set robots in the safety people.
Boy, you think robots can swim? They're waterproof. That's a good question.
I don't know. Will they need to swim or will they just walk underwater? I don't know.
On the bottom. Yeah, that could be too. Look, it's certainly gonna, it, it makes for, um, it makes for an interesting world, right?
I I think the other thing we're gonna have to get our heads wrapped around is do we want robots that are sort of humanoid in shape and look right? 'cause it'll be more familiar to us. Is it more creepy?
Um, I don't know, man. It's a crazy world. It's a crazy world.
But all kidding aside, in the meantime, you did have this robot attacking a crowd at a festival in China, and I'm sure it scared the heck outta people. Mm-hmm. I eventually though, won't I wanna customize my robot kind of like a hot rod, you know, I'll just make my own little robot.
And whether it's humanoid or not will be up to me. Well, it could many forms too. Um, what about an autonomous car going crazy?
You know, mowing people down. That's, that's bound to happen too. Wasn't that a Christine the movie or something?
John Carpenter movie? Yeah. That wish That was scary.
I, it, I think it was a, it was a Stephen King novel, I believe, trying, It was originally a Stephen King novel. Yeah. Novel.
I mean, look, this, this is the world. I mean, you know, we were kidding around with Asimov's Law of Robotics. You probably do need some sort of failproof programming in there.
Mm-hmm. And then who's responsible if the robot attacks somebody or it goes crazy? Is it the owner of the robot, the person who programmed the robot?
Everyone with the deep pocket. Yeah. I was gonna Say, who's getting Sued?
Who's got the deep pocket? But, you know, so let me tie this up to vibe coding. If you've got a robot, if I own a robot, and then I wanna program it to either be more vicious, less vicious, lethal, non-lethal, and I, you know, I could do that easily with vibe coding.
You know what I mean? You know, how the heck do you control this? Maybe we need to put something in that you can't customize your robot and then, Or cut off, you know, Kill Switch.
I'm looking towards that first television ad where it's gonna be, you know, Morgan and Morgan, if you've been attacked by an AI robotics That's true. That's the feature. Your robot hot, those ads.
Your robot is hot. Yeah, They have in Florida. Yes.
Your ac keep you better keep your AC on. Um, all right. Okay.
I see where we're going with this today. Let's take a break here. We may replace the whole gang with robots.
No. And see how that goes. Um, you're watching Text On Gang.
We'll be right back. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Welcome back to the Techron Gang. I'm joined by Alan Shimmel.
We have Mike Ard, and of course Mitch Ashley. And we're glad to be here because today we're talking about in this section about sustainability. And I had a really interesting interview recently with a laco Ready.
She's the, uh, VP of product for a company called aptera, which is all about carbon tracking, how to reduce emissions. And I, I've previously talked to their CEO about supply chain emissions, which is a big factor in evolving regulations, including what's coming out of the EU for Scope three. That means your entire supply chain, very tough to track and measure when you're talking about outside vendors and every step of the process that you have.
But this topic of conversation with ika was focused on the role of the Chief Sustainability officer, how that's changed, where that fits into an organization. And I think most interestingly for, for the audience of the Textron gang, is where's the role of it in all this? And elaia points out that it's a critical role and very crucial to work hand in hand with the CSO in an organization.
So, as the VP of product at Optt here, I lead the development of our carbon accounting platform. Um, our mission is to help businesses track, measure and reduce their carbon emissions, um, running them with the insights they need to make data-driven decisions. I think what excites me most about my role in Aptera is the work that we do with companies across industries and maturity levels to really help them achieve their goals.
Through our platform and services Sustainability can sit within very different business functions from finance to operations to people. So there's little similarity and standardization across the board, which oftentimes leaves these teams feeling, uh, left in the dark. Yeah, that is true.
I mean, how do you think this lack of notoriety and collaboration can detrimentally impact an organization? Yeah, I mean, at the end of the day, sustainability teams are impactful when they're able to connect with the rest of the business and influence business behaviors that alleviate the known risks of climate change. Um, without this critical collaboration, sustainability teams really lose their ability to drive meaningful change.
And at the end of the day, an opportunity for innovation is lost. Solving climate risk business problems requires a myriad of different perspectives. And collaboration is really at the heart of that.
Well, how Do you recommend Chief Sustainability Officers change that? How can they, um, get more there are messaging out to the different business units and really convey to leadership and the entire company that what they do is important? Yeah, so much of the spirit of collaboration really starts at the highest levels of leadership at a company company.
Um, an important part of the CSO role is to create a vision for sustainability that's not just, uh, corporate responsibility, but a central business priority. And then get the buy-in and support of other business stakeholders through constant education and touch points. Um, on the more tactical side, we've seen clients with successful climate programs integrate sustainability metrics into the overall business strategy and performance reviews of peers, um, not just the CSR report and sustainability report.
So ultimately sharing the accountability of sustainability helps drive these results. I don't think I can emphasize enough how important and critical IT solutions will be to decarbonization efforts over the next decade. So aptera is one of the companies that was featured in the ECOTECH report because of the carbon tracking factor.
But I think it's interesting to have this conversation about the role of the chief sustainability officer and not being as, as I mentioned in the video, as in a silo where it's just one department. I think the importance of having that interface with IT teams is crucial, as I mentioned. And, you know, since we're all, uh, I should say except myself, IT practitioners, I'm, I'm curious to what you all think about that.
Well, I think it's gonna take a access to a lot of data that are gonna be, you know, within ERP system, CRMs, things like that. But also, you know, if, if you really follow the, the supply chain, it's back to what materials are used in manufacturing of products or, you know, may generate or use carbon, uh, as part of building something or operating something. So we think about, think about AI and all the data centers that we're running for ai.
What is the carbon footprint of that adding? Or is it, you know, substituting other things? So I, I don't know that any, any sustainability officer could truly operate on their own.
They're gonna wanna talk to all parts of the organization. Sure. That's a good point.
I, I think there, there's two aspects to ai, to it's role in sustainability. One is kind of physician heal thyself, right? What can ai, what could it do around IT usage to be more sustainable?
So to be more efficient in computing resources, to use better materials in, in your computers to, you know, just make your it more sustainable. And that there's a limited impact, but an impact. The bigger impact is how can we use it to be more sustainable through all of our business processes such as manufacturing, building, construction, you know, so much of, of the, uh, carbon that goes into, goes into during the construction process, like right in the beginning.
And so, you know, can it be more, uh, influential in, in making sustainability decisions throughout the, the broader supply chain and business of an organization? That's number one. Number two, though, you know, I was reading an article yesterday that I think a new executive order came down that we're gonna do more, uh, we're going to increase and accelerate timber harvesting, which means basically deforestation, right?
We're going to, I wake up every day and biffs in charge. But you know, if that's the kind of messages we're getting, how many chief sustainability officers are we gonna have? Is that like a dying breed or our, our organizations going to care enough right?
To, to be serious about sustainability? Well, right now it's a rising breed from the research that I've done is that it's increasing and it's in most forward, uh, larger companies. There, there is a chief sustainability officer.
But you're right. Now, we're early on in this administration. We'll have to see what the effects are of it.
Yeah. I think it's a matter of does it politicized or not? Right?
If it goes the way of DEI making it a political issue, then, then there's a real danger of the becoming a rare breed. Until then. I think, to your point, Bonnie and your research, right?
Well continue to see this building up. 'cause it is a global phenomenon, not just a, you know, in the US what our needs are. So a lot of the regulations coming outta you, of Course.
And it is the personal beliefs of at least the IT practitioners that I've, I've interviewed and Matt, um, that they, they feel strongly about it themselves. So I think that that's always gonna be a motivating factor too. Here's what I'd like to see, and it's not no different than when Bloomberg put together some law that required restaurants to show you how many calories were in the meal you're eating, right?
We should be able to just see, regardless of what you're gonna do about it, it is up to you, but, uh, how many carbons were used to create this thing that we're about to buy, consume, use, or whatever. And that should just be data that we're sharing with folks, so everybody kind of knows. And then they have a relative metric for, uh, how much carbon is being generated by, for example, I don't know that a query you just sent off to an AI agent, um, and you should be able to see that and then decide for yourself what makes sense for you.
But I think the more that we make people conscious of the fact that we're counting these things, we'll get better behavior. I think you're right. You see that sometimes when you're purchasing something on Amazon, it'll say, you know, low carbon, um, recognized for that.
So it's starting to pop up and given the choices, especially if the prices are the same. I, you know, I'm not sure of the research, but I think a lot of people would be in inclined to make that decision. Yeah, I think I wouldn't trust more in the rest of the world than here, unfortunately.
I mean, I wouldn't trust the provider of the product or service to count the carbons. I'd want somebody else to validate that, but, um, I think that's ultimately where we need to go. And maybe states will do it.
I mean, you could see the state of California driving something like this, and then everybody else will just fall in line. That works. That would win Great stuff though, on this video, your report, again, Echo Yes.
com and, um, some of the companies that are featured in it are, uh, putting out, you know, releases that they're, they're honored to be mentioned in the report, which is so great. And, um, one of the companies I, that actually did that was called Human it, and they specialize in that, that ability to recycle refurbish hardware and then give it to people in need. So it's, uh, you know, full cycle for this report of the product and sustainability and look forward to the feedback that we continue to receive on it.
Very cool. Mm-hmm. All right.
Great work on that, Bonnie. Well, guys, I think that's gonna wrap up this Tuesday. Textron gang, we got you in and outta here in 45 minutes today, which is a beautiful thing.
Uh, we've got as usual a full Textron TV lineup following, so stay tuned for that and we'll be back tomorrow with more TechOne Gang. Until then, on behalf of Mike Ard, Mitch Ashley, Bonnie Schneider, and myself, have a great day. We're outta here.
This is Textron tv. Hi everyone. Welcome back here to Techstrong tv.
Um, really happy to have this next guest on with us. We're gonna be talking about a new report that came out from our friends at the Cloud Security Alliance. Let me introduce you to Ken Wong.
That's kinda like Jensen Wong, but no relation, unfortunately for Kent. Um, Ken is the chief artificial intelligence officer at a company called Distributed Apps ai, and he is also the co-chair of the Cloud Security Alliance's AI Safety Initiative working group. And I'm interested to hear some thoughts on AI and safety from him.
Uh, they recently came out with a new, uh, report on ai, organizational responsibilities for AI tools and applications. But let's first get to know Ken. Ken, welcome to Tech Trunk tv.
It's great to have you on here. Sure. Thank you, Alan.
Nice to be here. Nice to have you. Um, so Ken, I, yeah, I gave, I gave them your title, and obviously you're doing some stuff with ai, but you know, you didn't start working yesterday.
Give people a sense of your career arc and, and how you came to be the Chief Artificial intelligence officer, as well as the co-chair of this working group. Sure, yes. Thank you, Alan.
So I look at myself as ai, uh, researcher and also book author. I wrote a few books on the ai. Uh, I started AI long time ago, uh, when I was actually a PhD student, uh, in University of Ong, where study studying the intelligent ing system, like teach, uh, the university kids the accounting system.
So I published my first paper on the ai, but at that time, it's, uh, law based. So now fast forward, uh, to the GPT movement. Uh, so, uh, when GT two coming into the life before GPT-3 coming, like charter GPT come, right, I actually realize that will be important.
So I start to write the book about the this, uh, and then eventually it was published by Spring. It's called the, uh, chat, DPT and the web Studio, right, and the landscape of the Tomorrow, or it's impacted. So this one is hugely popular book.
It has like 27,000 paid view in spring alone. Uh, after finishing this book, I, because my, uh, expertise is, uh, more on the cybersecurity side. So I look at everything from cyber cybersecurity kind of glass of view.
That's why I start to write the book with all this expert together. Write the second book on the generative AI security. That book is also published the by spring, uh, last year.
Uh, currently it has a 16,000 views, uh, or paid views in spring. So my next, uh, uh, spring book will be a agent tech, ai, CLS and practice. So, uh, the reason why I'm involved with, uh, uh, product Security Alliance, certainly Cloud Security Alliance is upper front in the cloud security, and also in the AI safety and the security.
We have the working groups, uh, four working groups. Uh, so I co-chair two working group One is the AI Organization Responsibility working group that I co-chair with Nick Hamilton, uh, from Open ai, uh, for his GGRC head. Uh, another one is AI Control Working Group.
So we actually last year produced three white papers. So one of the last white paper from AI organization Responsibility Working Group is the paper we are talking today. Uh, but in the AI control framework, we are building the AI control matrix.
Uh, this already goes through the public review. Now we to the next stage is to provide the auditing guidelines that actually right after this meeting, I will chair another meeting to with expert to define the auditing guidelines for a AI consumer matrix. So it's a lot of fun.
And I also joined, uh, the Oasp, uh, their opportu, uh, their initiatives. So I'm core member of Oasp Top 10 for larger energy models. So trying to push these things forward, make my contribution.
Absolutely. You know, so Ken, I've also been in security many, many years, 25, 30 years. Um, again, we've discussed this on our texture on gang show a year, a year and a half, two years ago when Gen ai, you know, really was first bursting on the scene, we heard the usual, the usual from the security industry, which is, Hey, go slow.
Mm-hmm. Go slow. As a matter of fact, this AI has more potential for, for, for bad than anything we've done.
And we've gotta go slow. Of course, there was that very famous letter signed by a hundred very famous technology and celebrity people who said, we've gotta go slow with ai, we've gotta worry about safety, and we have to worry about security. Um, and, and you know that this doesn't get outta control.
Some people said yes, some people said no, but it was out there. Certainly over the last two months, three months, that seems to have all gone by the wayside. Now it is.
Get AI at all costs, do as much as fast as you can, right? Of course, deep Sea came out, it was kind of a Sputnik, if you will, a Sputnik moment where companies are saying, oh my goodness, you know, maybe throwing all these hundreds of billions, these people did it on a shoes string open source, right? We've, we've gotta, we've gotta go fast.
We don't wanna lose the AI race. Everybody's in an AI race, countries, nations, companies, you know, everybody's in an AI race. Have we grown security and safety to the, to the side of the road and said, that's not important anymore.
Or I mean, is is it just dollars that's at stake here? And, and, and so we're sacrificing safety and security? What do you think?
Yeah, so I think the key thing is safety versus security, right? So I think, uh, the things, the chat GPT movement, the focus is really a sudden kind of waking up and say, oh, wow, this powerful poet it can make, right? So the idea is more like on the safety side, uh, especially on the doomsday theory, like end of humanity, like, or it can make the damage.
So that was the like, uh, last year and since the charter DPT movement, and there's a lot of people behind it, certainly. Uh, I would say this is more theoretical in my book actually, generative AI security book. I do not say it's a generative AI safety book on purpose, because in the book I said, this is all theory actually for the enterprise to really implement, leverage the intelligence from the larger land model, uh, you really need to focus on the security like CIA side of it, right?
It's, uh, it's uh, too far away in terms of end of humanity. So in the last year, we always look at the future to see what the damage area, um, should take. But this year we actually have a wake up moment say, okay, this is powerful, but not to the extent that it can end humanity.
We actually really need to leverage the bullying, which is largely model to mind the intelligence of from it to build our application, especially the agent, a AI application. This is, uh, certainly the next wave I involved in the cloud security alliance agent AI security initiative now, as well as a wasp. Uh, so we actually will announce a initiative soon, uh, in partnership with oasp AI Exchange to say how we can actually test agent tech, AI security, or rather team it so that we'll announce soon and keep tuned.
Uh, so the key thing is like a JD van in the, uh, AI action summiters, right? Uh, mentioned that it's, uh, too much regulation that's maybe, uh, kind of inhibit the, uh, innovation and also Trump kind of appeal of the exact word, biden's, exact word on the ai. There is some reason I think the, uh, behind it, uh, is that we, uh, not yet to, especially from the enterprise workflow perspective, it's not the doomsday yet.
We still need peoples like IA who is chief scientist of open ai, right? He's good, he need focus on that, that is really good for humanity. But the industry focus, not everyone doing the same thing, right?
The industry focus is given the deep seek of open ai lama, those are good models. How can we leverage this model to build useful applications and also may make sure that's secure? Like, that is the focus now.
So, uh, I, I will also speaking at a agent AI security summit in New York City, the end of next month, uh, that was organized by some cloud industry initiative, especially Zel, uh, they have the agent AI security anywhere kind of slogan for their company. So yeah, I think the conversation will start soon about the, uh, the security aspect, not the safety. So just, uh, a distinction, right?
Safety is more focused on the, uh, dunes day, like as harm it can make, and also CBIN or chemical, biological, radioactive nuclear aspect of it, right? And security is more focused on the, uh, CIAs the confidentiality, the integrity, availability of the AI system so we can actually leverage the AI intelligence to streamlines our business workflow. So that's a distinction.
Excellent. Excellent. Ken, I probably took us down a rabbit hole.
I didn't realize. I didn't mean to, but it was nevertheless valuable and good discussion. But I did wanna discuss with you today this new report that your working group is published, and CSA is published.
Give us an idea on the report. And I always like to say, Hey, what were the, in your mind, what were the top three key things in this report people should take notice of? Right?
That's very good. Yeah. I al always, it's really good.
I always like, there's so many point we need take a three top point, right? That's also like we have s whiter paper in terms of responsibility for the organization. There's so many responsibilities.
So we take, okay, we take a sli whiter paper. The first whiter paper is core responsibility, focus on model, focus on the data, focus on the vulnerability. The second one is more from the GRC and the cultural aspect, right?
The third one is actually you put it into use. You building the application, you have the tools, uh, that you need to use. Uh, what's the responsibility?
So the three, uh, key take away from that is first we actually look into responsibility from like the measurement. How do you measure it? And how do you actually, uh, have the matrix, uh, to measure and also the what kind of, uh, laboratory, uh, regulation were impacted.
And also looking at the Laci model, who is responsible, right? This laci model is important. So this is kind of cross cutting behavior we have.
And then the second one is really, uh, in terms of application, if you really build application, especially the agent AI application. So keep in mind that, uh, in the future, the majority of AI application will be agent AI application. Because if we really define the agent ai, it has a certain level of autonomy.
If you look at the deep research from open ai, it has agent behavior. You give a topic, it will break down the topic, and it's using different tools to switch the internet. And then, then it has an, an agent to summarize the, uh, text.
And then there's another agent to analyze the content and then produce the report. Uh, another agent is just produce report. So this is already like in use now the agent, right?
So we, how can we secure it? So that's the second point is when we develop application, what is your responsibility to secure it? And the final one is really the supply chain.
It's, uh, you have to leverage the third party tools. So how are they secure? So we process this responsibility into the 70 pages document.
We try to cut it, but, uh, I think it's important to put things there and people can, uh, look at, uh, look at and, uh, feel it. So, Agreed. Agreed.
Ken, you know, those are three meaty things we could jump into here if we had more time, but un unfortunately, we're coming on the end of our time. For people who want to maybe get the report though and dive into this, just wanna make sure I got this right. org, right?
Csa? Yes. org.
Dot Org, right. Excuse me. You know, I was there at the RSA conference in like 2005 or six when they formed the, the CSA.
org. And then if you look under research projects and look for AI or AI safety, it, it should show up there. Um, Ken, what about for people who maybe want to get involved in this working group?
How would, what would you recommend to them? Yeah, uh, uh, so Colorado Security Alliance has a circle like application. So once they get to the, uh, working group homepage, they can assign up and go through the circle.
The, uh, beauty of, uh, joining the circle is they have access to our document, uh, is, which is Google document. So they have access and they can also get invited to the, uh, meetings. But our meetings open, like if everyone interested, even they don't, do not want to join Circle, they can still participate in the meeting.
We have open meeting people sometimes just join, uh, to learn something that's, we welcome. If you really want to learn something, it's okay. And some people really want to contribute, so that's also really welcome.
So yeah, it's, it's, That's fantastic and that's good that it's open like that too. And that's something I know Cloud Security Alliance has always been, their working groups are always very welcoming to anyone who wants to, you know, participate. Yeah.
And thanks for coming on Techstrong TV here today. Appreciate it. Keep up the great work.
This is, look, this is whether, you know, money gets in the way of safety and security. Sooner or later, people always get smart and they need security and they need safety. So the work you're doing is very valuable and important and keep it up.
We thank you. Yeah, thank you. A uh, one more thing I just want to add is the UK government just changes their AI safety in institute to AI Security Institute.
There you go. So that's the trends, right? Yeah.
Excellent. ai, as well as the co-chair of the, of the cloud Security alliances, AI safety initiative, working group, maybe safety and security initiative working group. Soon, yes.
Here on techstrong tv. We're gonna take a break. We'll be right back.
This is techron tv. Hey guys, thanks for the throw. We're here with Charles Crosman, who's chief product officer for Redwood Software.
And we're talking about, well, the rise of automation frameworks. Charles, welcome to show. Thank you.
We've been automating things as long as anybody can remember, but I feel like, um, we wind up, uh, all these islands of automation, they're kind of isolated from one another, and then we kind of try to hand things off and things break, and we wonder why. Um, so what exactly is an automation framework and how does it fit into that context? Yeah, that's exactly right.
So what happens is over time is you introduce new applications or new platforms in your business. So you might introduce an ERP system like SAP or you might move from on-premise systems to public cloud systems. Every time you make a change, introduce a new platform or application, you tend to go out and buy a new automation product, automate that thing, automate the cloud, automate your virtualization environment, automate your SAP environment.
And what this leads to is, as you mentioned, islands of automation. So you've got little pieces of automation for each platform or application across all of your IT infrastructure. Now the problem with that is, there, there are a number of problems with that.
So the first one is, um, business processes or even IT processes don't live in a single system. They cross multiple systems. So a typical, if you're a large bank, for example, large financial institution, a single, a single process might start on the mainframe, move through some of your on-premise infrastructure out to the public cloud across multiple applications, both homegrown as well as commercial and or SaaS applications from beginning to end.
And if your automation is spread across all different platforms for each, for each one of these steps, you don't have an end-to-end process automation, right? You've effectively got to do all kinds of manual work or, or, uh, custom integration between all these solutions on your own. So the idea of an automation fabric is something that either replaces all of these I islands of automation or orchestrates them, the ones that exist or some combination thereof, so that you can get end-to-end process automation across all of your disparate applications, whether homegrown or or commercial, on premise or SaaS.
And across all of your platforms, whether it can traditional on-prem platforms or public cloud platforms. Well, I don't think most people are gonna be able to rip and replace a lot of their existing automation. So how do I orchestrate all that into some sort of meaningful way to create that and then process?
'cause I think, you know, you hear about it every day, every customer has some experience with somebody who says, I have visibility into this, but I can't see into that, so we'll call you back. Right? Right.
That's right. So, so, so this idea of orchestrating what you've already got is incredibly important. You have to be able to both automate anything new that comes in that's not, not already automated.
Sometimes you replace existing things that are coming to their end of life, or they're doing consolidation or replacing vendors. But in many, many cases, you have to effectively orchestrate across things that are already there and already implemented, as you mentioned, that they don't wanna replace. So effectively what you need, the, there, there are really three main components to an automation fabric.
The core of it's an orchestration engine, so a workflow engine that knows how to build, uh, complex workflows, but ideally in a low code, no code fashion so that, you know, you don't need to be an expert coder in order to build these automations, right? You've got visual designers and now emerging things like, uh, AI copilots to help you build these automation automated workflows. So that's the first part, the second part of the library of connectors.
So you have to be able to, this workflow engine has to be able to talk to all of these backend systems, typically through, uh, APIs that they've developed. Most, most systems now have APIs where they don't, you have to deploy agents that know how to kind of talk to these systems without APIs. So you need a robust library of these connectors to all the existing systems, again, for everything from traditional mainframes to public cloud, from, from SaaS applications to homegrown applications to open source systems and everything in between.
So you need a robust library of connectors. And the third thing, the third thing you need is this, again, this low code, no code design experience. If you're, if you're, if in order to make this work, if you have to bring in developers who know how to write Java code, for example, you're never gonna get there.
You need to have, you need to bring the skill level required to build these automations down to what we call citizen developers, non coders through a low-code, no-code interface, typically a visual designer and, or now an AI copilot. And then the last thing you need, and this should not be overlooked, is an observability layer. So the key to adoption of automation is trust.
I mean, if you think about an analogy of something like, um, autonomous vehicles, right? So autonomous vehicles we're gonna be, have been on the verge of being fully autonomous next year for the last 10 years. It hasn't happened yet because it takes time to build out this full autonomous capability.
But more important than building of the technology, it takes time to build trust in the automation. So people, humans, you've got early adopters who are gonna be the first one in these auto autonomous vehicles who are gonna be comfortable taking their hands off their wheel and their feet off the pedals. But you've got the mass market, which is waiting for those early adopters to kind of work out the wrinkles for the technology to evolve before, before they adopt.
It's really the same with automation. So in the same way that with the autonomous vehicles in version one, they don't take the steering wheel and the pedals out of the car. You still have to have human override.
You still have dials in, in to tell you what your speed is. You can still see the GPS system in an, in an automation system. You still need that set of manual controls so that humans can override the system when they feel they need to.
But also an observability layer, like the dials, like the dials in the GPS that tell you what's going on, what's succeeding, what's failing if something fails, how do I diagnose the root cause, correct it and carry on. So you need all of those components as part of a, as part of an automation fabric. Will AI further democratize that?
Because I may not even need to know how to make the low code thing. I'll just describe what it is. I wanted a natural language interface and up there, build it.
Yep, yep. So, so now we're talking, we're we, so there's, there's, when, when you're talking about the evolution of ai, you kinda have to talk again, like I mentioned with autonomous vehicles about timeframes, right? When is it gonna be at level one, level two, level three, level four, level five.
And it was very difficult to predict with ai, because it's evolving so quickly. Now, our, our, our intuition is then to say next year, we'll no longer need developers because ai, ai, AI will be able to write all the code itself. That's probably an over ambitious prediction.
But in the, in a five to 10 year timeframe, you can see many of the, of the tasks that are done by to, by traditional coders being done by AI systems. I'm not, I I can't predict exactly what that timeframe looks like. I don't think anyone can, and anybody who tells you they know is probably, uh, is probably overselling their kick, their, their knowledge as it relates to automation.
AI is going to have a dramatic effect on automation the same way as it doesn't everything else in a few ways. So remember those components that I spoke to you about? So first of all is, is the, uh, orchestration engine or the workflow engine.
So AI is evolving to be able to, um, manage complex orchestrations. It really can't today. It can do things like task lists like, like, uh, serial task lists and some decision trees, but not which you would, the complexity of what you would do with a traditional workflow engine, potentially hundreds or even thousands of decision points and branches and merges and loops and all that kind of crazy stuff.
So it's not there yet, but it will be, and it'll, and, and it will be eventually be able to create those workflows, either pro partially based on human language prompts, but probably mostly based on ingesting data that describes those processes and then turning it into automated workflows, right? Um, so over time, yes. Today, no, not yet.
Um, the, the creation of the automation, like I said, if it can automate, for example, a process document, it can maybe created, uh, uh, an automated workflow from that a hundred percent in time. Um, the integrations are things that people are building. So you hear about an agentic AI all the time.
Uh, and this is really, uh, individual companies effectively taking, uh, building, taking the APIs for their existing systems and teaching an AI system how to talk to their system so that they can be automated by an AI system. Those, uh, those, those, those AI agents are not being automatically generated by ai. They're being created by the companies that own the systems that they're being integrated to.
But over time, a, a wide library of these agentic of these AI agents will be available and many systems will be automated and orchestrated by ai. Uh, as an example, what AI doesn't have yet, and again, this may come, remember the last part that I spoke about, which is the observability layer, right? So it doesn't, so, so there, there are really three things that have to be addressed.
It has to be deterministic, meaning for a set of inputs, you have to be able to predict the outputs. And that's one of the issues with AI today, right? It's not deterministic.
You can ask it the same question twice and get a different answer each time. Now, if you're only using AI to help you as a writing assistant, that's fine. But if you're asking AI to run an automated process to, to close your, close your books at the end of the quarter, you have to know that it's not gonna make any mistakes or have any hallucinations.
So that's something that has to be corrected over time. The second is, um, is it has to be transparent. So, so you, in order for you to come to trust an automation system, again, you have to just to be deterministic, but you also have to be able to observe how it does its work in order to build that trust.
And then someday, maybe you trust the black box, but you don't trust the black box right away. And then the third one is, is again, it has to have that observability layer. So it, there has to be the ability for humans to intervene and take control and or supplement the system.
Uh, and those aren't available yet in the ai. So over time, these thing capabilities will be, will, will become more available in gen generative AI systems, uh, and the, and the traditional automation systems, and these AI systems will merge. Uh, but, but again, that's, that's a multi-year, uh, process.
That's not next, next week, next month, and next year. Do we need to revisit the processes we're trying to automate? And I ask this question because as we enter, the age of ai seems to me, when I look at a lot of this stuff, there's more exceptions than there are rules.
And the exceptions have evolved over the years, and they were meaningful at some point. But maybe we need to kind rewrite the rules. Yeah, I mean, we see this all the time, which is we go into a, a very large corporation that's been around for decades, if not hundreds of years.
And they've accumulated over the time, over, over that period of time, many, many, many systems of record, right? And some of those, they continue to operate, but nobody really knows how they work or why they do the things they do. All they know is it does what's necessary.
Um, and so there's an arcane set of rules that nobody wants to touch, because if you pull on one thread, the whole thing might come un unraveled, right? So that's one problem with, uh, with dealing with traditional or legacy systems. But when you're creating new automation, as you're, if you're, as you're implementing new applications, new platforms, and you're building new automation, you, you hit on an important thing.
This has nothing to do with the technology. This is just kind of process or philosophy, which is simpler is always better, right? We learned this in the, in the days of ERP.
You see this in the evolution of ERP systems, the original, uh, implementations of ERP systems, they took the ERP system and they massively customized it to fit their own, their, their custom processes. And they realized over time that the burden of carrying forward all those customizations from year to year, from release to release, from system to system was very heavy. Where the, the modern approach to implementing ERP systems is really to adopt your processes to the system, to, to simplify, to not create all this customization.
And so, you're absolutely right. Lightweight is better. Doesn't mean that the need for automation goes away, but you shouldn't overcomplicate it.
You should do, you should do the minimum required to get the job done, uh, and not overcomplicate it with all kinds of exceptions and custom processes and roles as much as possible. So, adopt your processes, simplify your processes as part of the automation, rather than taking complex processes and simply reflecting them in automation roles, if that makes sense. It does.
Do you think over time we might flatten our organizational structures as a result of AI and automation? 'cause when I look across these, uh, companies, there's all these silos, marketing, sales, manufacturing, and yet they're not really aligned around delivering some end result. They're just kind of aligned around a set of vertical tasks and processes that, uh, somebody stitches together manually at the end of the day.
So, are we gonna have a moment here where maybe somebody wakes up and just says, you know, the way organizations are aligned needs to change. So, so this isn't a technology answer, this is more of a kind of a philosophical question. I'm happy to answer it.
So, so my perspective is this, the most complex machine in existence is the human. And, and the most complex interface between two machines is a human to human interface, because it's not deterministic, right? You know, we're governed by emotions and it's desires and all these things.
And so when you see the complexity of interoperation between organizations, it's because interoperation between humans is difficult and messy right now. So the more that these things get automated by computers, those interfaces get simpler and more deterministic. And you'll see integration across silos, as you mentioned, right?
Because computers know how to talk to each other pretty well, pretty easily. Now, again, I'm not advocating for nor predicting that humans will be replaced by computers and all these organizations, they will be supplemented by ai for sure, for certain. So the more that you, the more that you reflect your business processes in software, in computer code, the more integrated they can become, the less reliant you are on humans, which are the most complex interfaces between, between machines.
If you wanna allow, allow me to call com humans, machines, uh, you'll simplify and start, start to solve that problem. You wanna eliminate it, but you'll, you'll start to simplify it, right? A lot of these organizational issues are, are really the root, the root of how humans collaborate with each other.
It's a messy, difficult thing. Always will be so computes, collaborate with each other extremely well. So the more that you can, um, put your processes into software and automate these things, the, the better results you'll have in that regard.
Again, not replacing humans, but supplementing them. So what's the one thing you see organizations doing as they attempt to automate things that you kind of shake your head and go, folks, we need to be a little bit savvier about what we're doing here. Yeah, so probably the number one problem is the one we started with, which is the islands of automation.
They've accumulated systems over time, particularly large companies that have existed for decades, if not hundreds of years over that period of time. They've accumulated, uh, an incredibly diverse set of systems, an incredibly different diverse set of platforms, applications and automation, islands of automation. And, and to your point around silos, they've got the ability, as I mentioned, to integrate all of this through software, but they haven't done it.
So they've got all the traditional problems of silos, uh, but they've got the ability to eliminate those silos through automation fabrics, through integrating these things across all of those islands. They just haven't done it right. Um, and it's the traditional ROI conversation, which is to say there's some upfront required to do that, but it'll pay for itself incredibly quickly.
And over a three year, it'll probably pay for itself three x, right? But you have to take that upfront effort in order to get the long-term benefits. All right, folks, you heard in here they say the definition of insanity is doing the same thing over again and expecting a different result.
Well, right. If you think about that in the age of ai, just how crazy might we be? Hey, Charles, thanks.
My pleasure. Thank you. Back to you guys in the studio.
This is Textron tv. Welcome, everyone. We are back again for Infrastructure Matters, episode number 73 with my buddies here, um, Diane iff, and of course Keith Townsend, who's coming in from Tennessee.
You got your, um, your, your jet stream or whatever that thing is called, your, The, the Airstream is, uh, Airstream parked in the middle of Forest. I I, I posted earlier this week that if you wanna learn anything about site re reliability engineering, try living off grid for any period of time, and you'll, you'll, you'll have a crash course master's level and keeping a website up. There you go.
Are you on a 5G or are you starlink? I am starlink. So our platform will cool it, it'll make up for it.
I'll break in and out in our real time recording of this, but it records locally and uploads it, so you know, it is much better than nothing. Yeah. Whole lot better The wandering man out in the wilderness.
Okay. So guys, we've got quite a bit to go through this morning, so I'm gonna jump into it. Um, first, uh, short little piece on some earnings of reflections.
We've had lots of earnings this week. Um, I just spent the time this morning going through NetApp, pure and Nutanix. I haven't gotten to Dell yet, so we're not gonna talk about that one.
They may know, um, and kind of where they were at. All in all, um, everybody's had good quarters. Pure has an outstanding quarter, um, pure storage.
Um, they've just kind of blown out their money. The, the revenue, 12% year to year growth. Um, the subscription business is up 21%, just all kinds of really good numbers that are coming from them.
And, um, but, and then NetApp had a slight miss, um, because of some delayed of some transactions, but they were still, they were 2% year to year, um, up in terms of where they're looking at and, you know, still decent quarters. Um, and tonics, of course is up as well. Couple of common themes that went through all of them.
Um, they're experiencing the softness in the market over in Europe. So there is some softness going on there because of certain uncertainty in the US is probably carrying it all. Um, the second piece, they all commented or had questions to them about, um, VMware, um, trans, trans transitions.
All of them have had, of course, Nutanix is double downs on that. That's kind of a key piece of their market. Um, and that is happening, but it's slow.
I mean, it's, it's happening is slower as you would expect because you've got licensing issues, you have hardware issues to migrate. Um, although they're coming about how fast you can move up in the cloud, like with an AWS, um, just because there's no hardware stuff there. And the third one is an ai, and we're gonna get into that.
Um, since these guys are all storage people and they're primarily storage that has to do with the enterprise, that's a slow moving ship, ship right now, or train, or whatever you wanna call it. Um, because most of that work is right, still going into the hyperscalers, um, the maybe AI factory kind of companies that are putting up CSPs, et cetera. But they are seeing, you know, definitely, um, NetApp has seen a couple of big data lakes being put into place that, you know, people are taking where they've already got this, got their environment and expanding it.
Um, a little bit less conversation about this from Pure. So that's kind of a bit on the transactional kind of piece. And I will stop there, and then we're gonna go on to some other things that are even more interesting.
So, okay. Um, let me go on to my, my, my partners in crime here because we have a bunch of things going on with chat. 7, and, um, Google giving away Gemini codes.
So, um, Keith, why don't you take it off first and then you, and then Diane can, uh, come into it. Yeah, it's been a busy week for ai, uh, product and model development. 5 hit, uh, yesterday of this recording.
Mm-hmm. And Amazon hit with Alexa. 5 for quite some time.
And I have to tell you that some of the early assessment from the AI experts is disappointment. 0 to four. Oh.
So, uh, Diane, I'd love to hear your thoughts on both of these. Yeah. Well, it's, um, it, it's the, the last big release between the, uh, uh, before the much expected GPT, uh, five and, uh, uh, opening IC they, they put a lot more pre-training work into this to find more connections, uh, between all the data.
5 than it does in deep C car one. Um, that's two orders of magnitude. Uh, and, and, you know, can they be profitable on this?
Uh, we'll see. Uh, right now, uh, only GPT, um, pro users can use this. Uh, it's available today, unlike Alexa plus, which we have no idea when, when it's actually gonna ship.
Uh, you have to get on a wait list for that and some weeks in the future. Uh, and, but, uh, plus users, which is, uh, you know, the bulk of our subscribers will have it next week, so we'll get more insight into it. Uh, it's just, it's, it's an important bump.
Uh, it still keeps them, uh, at the top of the leaderboards. So it is a highly capable model. It's not that it is, uh, that it isn't.
Uh, and, uh, it has somehow, somehow they found a lot more training data to throw at it. So they must be licensing, they must be spending, uh, to get access to data sets that, uh, that are not openly available. Uh, so, but we'll see a lot of testing now that it's in people's hands as of, uh, yesterday morning.
So it's gonna be interesting to watch. Well, okay, so how does that work? If I'm gonna license training data because it's not publicly available, and now I've trained my, my model on it, it's now publicly available, isn't it?
But through the license, right? So they, they've paid to make it available as the argument, right? So, uh, uh, hopefully the licensees know what they're, they're they're up against.
'cause you can, uh, you know, the techniques are emerging to extract almost the original dataset if you know how to query, uh, the, the, the model to get that out. So, we'll, we'll see how that, how that proceeds. I mean, it kind of feels like once it's in the wild, it's in the wild.
I mean, yeah, exactly. You've put it out there and, you know, that's the big issue about why, Well, this is what called what's, what model distillation is all about. You can actually get all the information out of a model, uh, in a way that you couldn't, like, out of a search engine.
No, it's very interesting. Okay. Okay.
Well, what about the Google giving away Gemini. Gemini? Yeah, so the, a lot, a lot of these models are, uh, kind of put into action, probably the biggest areas in AI coding.
I'm looking forward to having a really great discussion with Brian Lau, who's a principal, senior principal architect, or, uh, developer at Amazon on, not on the AI side, but he's been a big proponent of using AI in development. 0 code assistant. So I can, uh, just light up my favorite IDE and this code assistant is fully free.
There's, I think, some ridiculous token limit that the average individual developer probably shouldn't reach. The enterprise version is still need, still needs to be licensed for multiple users and work groups. 0, uh, uh, code assistant is actually pretty good.
So, uh, it's an amazing, well, it's Top of Leader Port, right? Yeah. 0 is a super capable model.
Uh, it's pretty brave of Google to give a, a huge number of completions away. Uh, so you can do a lot of work for free. Uh, and I think it's really smart to go after developers, 'cause they're the king makers.
They made AWS what they are. 0, get in the hands of lots and lots of developers, uh, 'cause it's gonna be the cheapest option for, for most to be able to get their hands on a really powerful coding ai. So the assumptions that if I'm gonna code with Gemini, that code is gonna run on Google Cloud.
Yeah. And that, I think that's a strong correlation. Kimberly, we've had Google at Cloud Field Day a bunch of times, and the delegates were always surprised at how well integrated the platform is with the model.
So you can use Google's runtime, Google, GKE, it's various serverless platforms to actually call Gemini. And it's really easy to do. com or Google whatever the website it is, and use it similar to how we will use chat.
GTP Google has made it much a much better developer experience than maybe a end user experience, if that Makes sense. Well, I think that comes from, they're being, they were kinda like third to cloud, but, uh, and that means they learned a lot of the lessons from everybody. And they have the, I think, the best cloud architecture, um, you know, product architecture of them all.
Um, uh, uh, you know, it's, it's the most modern, just there's, it's just not as used as the other two because it, you know, they, they, again, they, they came a little bit later, later to the party. So yeah, this, this will, I think, key to help them get an extra level of adoption, both in AI and in cloud. Yeah.
And these announcements don't surprise me, because as we're coming into, um, GTC, which is the, the big GPU conference that's put on, um, by Nvidia, and that was the 21st or something like the third week of the, of March. Um, you know, we we're now, right now getting briefed on announcements that are gonna be, you know, piling in over the next three weeks. Um, and it's, I'm not gonna be at the conference, but I think you, you guys are gonna be, that thing is gonna be crazy.
Absolutely crazy, No doubt. Um, yeah, it's become the defacto AI conference of the year. Yeah.
It's going, it's going to be up there with, uh, super compute as a, as a as just noise. Yeah. Um, and getting into that, so Di Diane, you raised an, uh, conversation for us today.
Um, a little, a debate around whether or not ai, the technology of AI is a layer on top of the current infrastructure, IT infrastructure or whether or not it is a, what I see people talking about, which is this thing called the AI factory. So, and Dell coined that term last June when, when they, or DTC at their big conference, um, the AI fact, the, they called it the Dell AI factory, and then they've had the, the 18 wheeler, right, rolling around all over the United States talking about the, the AI factory. And then I've seen that term picked up by multiple companies.
So it's not no longer a Dell term, it's a actual term that the market seems to be using for some reason. Um, and that's just recently happened. Um, and it's part of, actually in the briefings, couple of briefings that I've had just recently coming into GTC.
So let's talk about that. You know, why would it be part, or why would it be separate? Well, and there's, you know, there, and there's arguments being made for both, but I think this is, what's, what's coming up is, is we've, you know, traditionally kept our, our data in, you know, SQL databases.
Um, we then, you know, moved to no SQL and graph databases in a document oriented databases and so on. Um, then vector databases arrive that says, all right, no, you really need to understand, you know, much, you know, a mu much more unstructured information needs to be actually more deeply understood and e more easily accessed to retrievable. Um, and then of course, now we have foundation models and large language models, uh, diffusion models, and they store data.
There's no, there was no question about it. We were just talking about how you, you know, you can extract some of the, the, the data that's under the covers. And so is it just part of the data layer that we've always had in our infrastructure?
Is it something new? Because, um, uh, you know, AI does things that these technologies didn't do before. Uh, uh, you know, if we look at AI ages, you know, they actually take autonomous action, um, in a way that we didn't predetermine.
They, they determine how things will happen. So there's an argument that we now have an AI layer, uh, you know, a new AI layer on top of our infrastructure layer. So I just wondering if you guys want, you know, what your take was on that, Pete?
Yeah, so I'm going to say AI is just another version of compute. I think it's a, I think it does blur the, the lines in between data and compute a little bit. But if we look at kind of the vectorization of data, if we look at how models are trained, models don't keep all of their knowledge within the model for, you don't have the same level of clarity around your data.
Uh, when you're talking about the model itself. Now, when you're, uh, when you're, uh, using your own data to, uh, an adjacent to a model, that's a different layer. But again, that's compute that you're just saying, I'm going to apply this compute this application layer against my data.
So I don't see this as yet a new layer. I just see it as, you know, an advancement in compute. Yeah.
I, I, I, I view it as, as it's a new, uh, spike through the layer, right? It has both compute implications and data implications, I think, uh, and, and it's, it's an a, a new, uh, you know, column in the, in the, the infrastructure layer. So I, I'm gonna go back to some of the earnings calls that I was sitting through, because these are, these are all data, data people.
I'm not necessarily the vector people, but, um, there, if you looked at like NetApp and, um, George Curry and talked about, you know, a couple very big wins of people creating a data lake. They were already currently a NetApp customer. They're broadening that base to be a, creating a data lake capability.
Um, and then talking about, you know, your, how you're bringing in both your file, your block, which your databases, um, and then, you know, also the next piece is a multimodal kind of piece, the videos, et cetera, that have to go, go into the training. So they're creating the separate system here. However, once you train that, that training data, depending upon what the application is, is gonna go against potentially a transactional system, right?
So if I'm going to use AI to present information on my website based upon maybe a retail transaction or whatever that, you know, or if I'm gonna use ai, let's say I'm gonna use AI on insurance, you know, kind of submissions, that kind of thing. So due to that analysis, so you have this connection between the transactional traditional systems, processing systems with this AI kind of analysis that goes through, um, think also customer service, right? Customer service that's part of that application within that application.
So I asked to be integrated with that layer. Um, you guys would known better than I do because you're, you're better. You're coders and that kind, or you've coded and that kind of stuff, and I haven't done that.
Then I'm thinking about kind of like vast just came out and added block to their file and object capability. So that's recognizing the data layer. And, and why they're doing that is because they're recognizing the transactional data has to come into that training piece of it and do the training as part of it.
So they're expanding that piece of it. Um, so, and, and, and, and you have, okay, so Vast and NetApp have talked about bringing in, you know, their, they're building vector databases within their data data management system. Um, Dell has chosen a different way that what they're doing is they're just integrating with other vector databases not incorporating into their data management.
That's a strategy difference. But you still see this, you know, this integration of these pieces here. Um, so it'll be interesting to where this turns out, I get your comments blow a hole in what I just said or whatever.
Yeah, I think it, it, yeah. I mean, quite frankly, yeah, go ahead, Keith. And I think it's, that's representing a huge shift in the market.
Just, uh, a few years ago I'd be in briefings with HPE Dell NetApp and asking about the data layer, not the storage bits, the zero, the zeros and ones and deduplication and all the ser uh, uh, the, all of the storage level services they offered, but the actual data and helping to make data easier to process. And none of those players wanted anything to touch with the data. They said that was left to up to ISVs database providers, and, um, basically sis and they wanted to focus on the bits and bobs.
Now, the conversation has really changed because we're seeing, again, to the, uh, earlier comment, the, to Diane's earlier comment, this, this, this, this explosion beyond a single layer and this blurring of what's needed. If I need to retrain my model on my latest data, data or my latest transactional data, what's the fastest and easiest way to get to that? If, um, if my AI model and my data exists on the same storage system, isn't it best to do it at the storage layer?
Mm-hmm. We'll see. Mm-hmm.
Yeah. That's the, and that's the data management layer that we've been hearing them all talk about. Um, you know, for, uh, NetApp, it would be blue, blue xp for pure, it would be fusion.
Um, I'm not sure the name of what Vast is calling it. It's probably just vast, vast capabilities, uh, environment that they're doing. But bringing that out to be able to manage, you know, um, and then having a separate, you know, actual storage, storage plane that has all the traditional capabilities that you're down there.
So, interesting. Thanks for bringing that up. It's a good conversation.
So, we'll, we'll see where that pans out over the long haul. And, and, uh, and then you have to also think about how this connects with some of the people that got their, their data in the cloud, so that that's also Well, and you know, I try to look at what's, what's different in, in AI that, you know, wouldn't normally be found at, uh, at the data layer. And the only, the only example I can really come up with is what we're seeing is the safety layer that it's appeared, uh, in so many, uh, AI infrastructure that, you know, does and make sure that, you know, there's no inappropriate information being generated.
No, no private information is being revealed, uh, that the, the results are accurate, uh, reduces hallucinations. Uh, and that's not something we've ever seen before in a data layer. Um, it, uh, to that degree.
So that's something new, but I, I still think it's just, it's something that we actually probably need in our data layer. So I still, it still goes back to, for now, um, AI is a new element in our compute and data, uh, layer in the infrastructure stack. And that, um, we haven't seen anything quite yet that rises to something that would, that would require us to, to create an entirely new layer because we have some new third, or, you know, fourth entity in the stack.
So, Well, and we're really early stages into the enterprise architecting this. I mean, we heard that very much so from, from the, the, the calls that we're on, you know, the earnings calls about, you know, this is still, we're, we're looking at 20 25, 20 26 in terms of this really rolling out to the point that it's, it's in, in application. Much of the money that's going out right now is still into the big foundation models, the people that are building, um, cloud service providers that are building GPU service, um, those, or, uh, the other ones that are already research labs of some sort.
Maybe it's, uh, like Harvard, you know, medical, you know, medical that, you know, was cited by Vast or it's, you know, some, some other, you know, pharma that's already has that, but they're expanding that environment to not be an HPC, but a, you know, east west, uh, architecture to drive, you know, you know, looking at new drugs and sort of things. So anyway, all all interested in me going. So our next topic, um, HashiCorp big acquisition by IBM.
Um, who wants to take that one? I I kick it off real quick. I'd love to hear what, what Keith has to say, though.
4 billion for, for Hashi Corp, uh, infrastructure as code security firm. Uh, a ling with developers as well. Uh, but also at the, you know, during the acquisition around the same time, Hashi Corp made a major change, licensing change to Terraform, which is their, their main product, um, that really left a bad taste with a lot of developers mouths, uh, uh, developers really value the, the attributes of open source.
Um, and licensing is kind of a religious topic. Um, and so, um, you is question of what, you know, uh, is that, is I even gonna turn this into another Red Hat acquisition? Or, or, you know, how's it gonna work out?
So for our listeners, just let's briefly say what, what is Terraform? Terraform is the open source, Hashi Corp is the distribution. Yeah.
So let's, uh, I, I guess it's important to understand where, why is Hashi Corp getting acquired? Like, you know, why is this unicorn six point something billion dollar n now publicly traded company in a position where they can't grow organically? So Hashi Corp has a series of applications, Terraform being its most popular, then followed by console and a bunch of other developer, Kubernetes new web type applications.
Terraform is by far the most popular of all of their, uh, offerings and projects. It is, its role is for you to, uh, programmatically, uh, describe and deploy infrastructure. So whether you're talking about AWS Google Cloud, on-prem infrastructure, VMware, vSphere, you can orchestrate your, uh, infrastructure as code.
So I can say consistently and Do it across multiple clouds. I mean, I think that's one of the big biggest attractions, right? It abstracts cloud, uh, cloud infrastructure.
Yeah. So, uh, and they went the open source route, and frankly, it grew it, we saw what the same thing happens, but most open source, it grew to a point, and they couldn't grow it beyond that, and they couldn't really tell a great cohesive story around platform. I said two or three years ago that HashiCorp needed to sell itself to a IBM or VMware.
Did it make sense for one of those two companies to buy them? Yeah, we'll soon. See, because IBM has made the purchase the, they need, this is a, in order to, to help CTOs and CIOs understand the value of HashiCorp your white glove service, you need the sales force, you need the account penetration.
Terraform was one of those things. Either you bought it or you wanted it free. There was no in-between.
So a lot of folks that are angry are the folks that wanted it free. Some, uh, Terraform and the Terraform product team would tell you it's mainly the competitors that are complaining, uh, that it's no longer, uh, open source and, and, and open source in a traditional manner, and free in the traditional manner. But, uh, developers, some developers, especially you Diane mentioned it, that this is a religious debate for a lot of developers.
It's either open or it's not. Okay. So, and am I understand their primary competitors would be people like a Puppet or an Ansible or something like that?
Correct. Yeah. So I wouldn't, I I don't even know if they're competitors as a mul, uh, as much as at the same problem in a different way.
Uh, Formation. Lost piece here. Sorry.
Well, the, uh, uh, starlink is, uh, is probably switching to his new starlink that way. So we'll, Uh, the, the old, the old reliable starlink. So I'm back, Okay.
I'll start the, the competitive question. Okay. So I think Terraform or competes with things like Puppet or Ansible and, or maybe they're just more complimentary, uh, Keith, yeah, so IBM is going to have, you know, some, some work on their hands, kind of rationalizing Ansible, We're losing him Again, and Terraform, I, I wonder we're actually losing him.
Uh, it, it might, the upload might be work just fine, right. Diane, I'll just let you answer that question because my, the, the, I go through these periods and, Alright. All right.
So then Terraform just is positioning kind of competes with Ansible and Puff Puppet di Diane, is that? Well, I think, oh, first some of what HashiCorp does, that's true. Um, the, um, yeah, it, it really start, it started out really as secret management.
Uh, so if you look at like CyberArk or a Azure Key Vault or, uh, BeyondTrust, those are often considered the more kinda the original competitors, uh, with HashiCorp. But Terraforms has become super popular as, uh, as, uh, for, for infrastructure management. Um, and so HashiCorp now does multiple things like so many cloud vendors do.
So, you know, there's, they have I think, an array of competitors at different level, at different product levels. Yeah. So I mean, many years ago, IBM and, um, you know, the, the current CEO did this one, he wasn't the CEO, which is, uh, drove the purchase of Red Hat.
At that time, the at evaluator group, we were all scratching our head at $34 billion and like going, you know, doing the back of the napkin about how long it would take to return the investment on this thing is like, it's never gonna happen. I think it was 34 billion, maybe it was 43, I can't remember one of those two. It Was a large number was it was a huge number.
Yeah, big number. And this is not that big, but then again, it's not, you know, complete platform play, but it is a platform play. If you're, what you're talking about is managing across clouds infrastructure code, and, you know, they gave a lot of cred to, um, red Hat, you know, they brought 'em into the, you know, when you have client executives that walk into the CEO and CIO kind of capability, you're, you're kinda walking in Red Hat, right?
Um, and, and so there's, I think there would be some similarities in terms of the go to market on this one, or is this just gonna get rolled into the IBM stuff as opposed to what happened? Well, I think a lot of people are hoping it doesn't get rolled, rolled into, you know, uh, an IBM only story. Um, it is really valuable for IBM to be part of a, of a bigger story.
Uh, the CIOs really want their IT to work with all the re the rest of their it, they don't want these silos in their organizations. So it's really from a standpoint that, uh, HashiCorp provides, uh, IBM with credibility across clouds. That's, that's a great story, and that's one that they should keep.
They shouldn't mess with that. Uh, and I hope that they don't. Um, but the IBM of old would've, you know, this would, is something they, they may not have really focused on preserving, but the current IBM, uh, and they, and they're very much on the upw.
People have almost written IBM off, they are back, there's no question about it. And if they can do with HashiCorp what they did with Red Hat, this is gonna be, uh, gonna do really well for them even at this price. So We won't have Red Hat Summit now, we'll have the Red Hat plus HashiCorp event or something.
Yeah, I'm, I'm really excited to see what the IBM cloud folks do with this, because, you know, we don't talk about IBM Cloud enough. The IBM Cloud does an amazing job working with some of the other hyperscalers to augment your capabilities of running some of your traditional workloads in public clouds in a way that enterprises accept. And that's one of HashiCorp's original stories was how do I take my mainframe app, modernize it, and have a connector, this is what console did have a connector from my new world applications into my mainframe applications, and then run that in the cloud like operating model.
So this is a, you know, the IBM will be able to expose some of the more interesting capabilities, capabilities on the enterprise side of a Hashi Corp. Good. Well, we'll, we'll see where this plan pans out.
So thank you very much guys, and thank you for, uh, listening in. I think we got everything covered here that we're gonna do today. Did I miss anything?
Yeah, no, We, we, that was this week. Okay. There it is.
That's a wrap, guys, and we will see you next week. Don't forget to like, follow, share all that stuff, because you know what, even the guy that does is in the background, that's doing all the video work is now listening to our infrastructure matters. And that's really cool.
Have a good day. Thanks everyone. Hi everyone.
It is an honor to be here today. My name is Caroline Wong, and I'm currently a director of cybersecurity at Teradata. Throughout my nearly two decade journey in this field, I've had the privilege of working across so many domains from GRC to software security to product innovation.
Now at Teradata, my focus is on ensuring the resilience of our systems and safeguarding the sensitive data that fuels transformative insights for organizations worldwide. My career has taken me through roles at leading companies like eBay, Zynga, semantic, and Cobalt, where I've built and scaled security programs, led global teams and championed innovative approaches to cybersecurity challenges. I'm passionate about translating complex security concepts into actionable strategies.
This is reflected in my book Security Metrics, A Beginner's Guide, which was inducted into the cybersecurity Cannon Hall of Fame, and my work as a LinkedIn learning instructor, where I empower professionals with the skills to navigate the rapidly evolving security landscape. Today, I'm super excited to share my thoughts on cybersecurity and AI predictions for 2025, drawing on lessons that I've learned from both successes and challenges throughout my career. Let's explore how we can continue to innovate and adapt to stay ahead in this always changing field.
Let's dive in. Prediction number one. This was kind of a bummer, but I really think that in 2025, humans are gonna end up doing 40% of the work that AI is supposed to do.
AI is often marketed as a magical solution, capable of replacing human effort entirely. But in practice, the story's a little bit different. Real world implementation often falls short because of challenges like poor data, quality, integration issues, and specific domain complexities.
Even when AI does provide great insights and recommendations, it faces what is called the last mile problem. AI does an okay job at analysis and prediction, but it takes human validation, interpretation, and action to bridge the gap between analysis and actual impactful results. I think that unfortunately in 2024, there's been so much investment in ai, and AI is really expected to do so much.
I think in 2025, those expectations are gonna fall short. Organizations really should continue to rely on humans to oversee AI decisions, especially in high stakes areas like healthcare, finance, cybersecurity, where trust is key. Sadly, AI isn't perfect.
It can't self-diagnose bias, it can't correct unexpected behavior, and human invention is gonna be absolutely needed to monitor those outputs to errors and make sure that the systems work as they are intended. It would be nice to have full automation in some business processes, but building AI systems that are actually capable of end-to-end automation requires extraordinary resources, time, money, and expertise. And even then, results are falling short when it comes to dynamic unpredictable scenarios.
Another broader societal implication is that I think that there are gonna be workers and even organizations that resist full automation in order to preserve jobs, in order to support historical cultural practices. Um, and even when AI works really well, people are still gonna want some human assurance. Um, whether we're talking about customer facing rules or business critical decisions, fairness and accuracy and increasingly empathy are still going to be much more trusted when humans are involved.
So this prediction is a little bit of a bummer, but the next one is really exciting because I think that in 2025, kids are gonna use AI to solve real world problems. So AI isn't just transforming industries, it's empowering young minds to think bigger and achieve more than we ever imagined. It starts with the democratization of tools.
AI technologies like fat, GPT, image generators, and coding assistance are now accessible to kids. These tools break down barriers and allow children to experiment with ideas and create solutions that before might've required months or even years of experience or specialized knowledge. Today's kids are not just dreaming about the future future, they're actually building it.
They're going to use AI to develop games and applications. They're also gonna use it to address environmental issues and tackle community challenges like waste management or energy efficiency. AI is really fun for kids.
It brings STEM education to life in remarkable ways. Instead of learning abstract concepts in isolation, kids can use AI to engage with hands-on application. Imagine a middle schooler training a model to analyze air quality or developing a chat bot to support mental health in their local community.
Programs like AI for kids are fostering this practical engagement, encouraging students to take on global challenges like climate change and healthcare accessibility. What makes this even more exciting is that kids see the world differently. They have so much curiosity and creativity when it comes to finding unconventional solutions.
Older generations may have labeled some things as insurmountable, but kids don't think that way. And thanks to the internet and computing, they're not as limited by geography. So kids from different regions and backgrounds can collaborate virtually to adjust shared challenges like access to clean water or improving education equity.
So kids are really the future of problem solving, and AI is gonna play a big role here. The next prediction is a strange one. I predict that in 2025, 80% of single people between the ages of 18 and 58 will have an AI, boyfriend or girlfriend.
So what makes AI companions so compelling is their adaptability and AI companions are coming up in popularity at an exact time when human loneliness and isolation is more pervasive than it ever was before. And AI companion can be customizable. They can learn from a user's preference, they can create deeply personal and tailored interactions.
At this point in time, each of us actually interacts with so many of our real human relationships via technology. And so if a person's talking to an AI companion, you can actually develop feelings as if the AI understands you in ways that other people might not. This is really just the next stage in a broad cultural shift that's been happening over the past couple of decades.
It is in addition to the way that online dating and social media have already reshaped the way that we operate and think about our actual relationships. AI relationships are going to become a natural extension as that for many people, the emotional and the psychological bond with an AI partner is going to feel just as real as one with a human being. The line between a virtual and a real relationship is blurring, and it also gives us cause to rethink what intimacy and connection, uh, truly mean.
Recently at the World Health Organization recognized loneliness as a global health crisis. And so for some of those folks feeling really isolated, an AI partner could actually provide emotional scaffolding that they need in order to feel seen and valued and supported. Of course, there will be challenges.
It's gonna be weird if somebody feels like they like their AI relationship more than their traditional real life partnership. It's also gonna shift societal expectations about love and about intimacy. There are ethical considerations.
What happens to humans if we begin to depend too heavily on AI for emotional support? How is that gonna stop us growing as individuals? How is that gonna prohibit us from forming meaningful actual human relationships?
As AI companions become increasingly realistic, there's gonna be questions that need to be answered about things like consent, manipulation, and the authenticity of those emotional bonds. Ideally, I think that there's a future that's possible where AI doesn't replace human connection, but actually enhan enhances it. Maybe AI can help to teach us how to be stronger communicators and more empathetic partners.
That's AI and, and artificial boyfriends and girlfriends, uh, which is a weird one, and it actually, it, it kind of leads nicely into the next prediction, which is that I predict that impersonation attacks will increase by 500%. Now, this is a very dramatic rise, and I think that this is actually pretty conservative because AI is becoming a force multiplier for cyber criminals. AI is revolutionizing your basic phishing attacks.
They are becoming hyper-personalized. Attackers can use tools to do things like get information off of your social media, your LinkedIn, your Facebook, your public posts on online forums, and they can use that information in combination with AI to generate emails and messages that are so tailored to your actual life. They can reference your kids' school.
They can reference where you went on vacation recently. They can reference your recent project at work, and this is gonna help them bypass any initial suspicion. AI also provides attackers with an entirely different level of scale and speed.
For years now, we've had voice and video deep fakes that have been so realistic, they could pretend to be your boss calling you with an urgent request. CEO fraud is already a billion dollar problem, and it's gonna be increasingly challenging to tell the difference between a real request and an impersonation attempt. One of the things about chatbots and large language models in particular, is that in the past, hackers were often limited by their knowledge and ability to use, uh, the native language of their victims.
But today, AI generated content can be made so linguistically accurate, and it can often be indistinguishable from human created messages. Um, one of the big takeaways here is to watch out what you're posting on social media. Just keep in mind that that is information that attackers can use in order to personalize spear phishing campaigns.
This, of course, is not just a technical challenge more than anything, it's a psychological one. AI can model human behavior, and for decades, hackers have been exploiting human emotions like fear, urgency, and curiosity to push their victims into making quick decisions. Um, and now attackers can really target their campaigns, um, identifying specific, specific victims, uh, based on their demographics, their profession, um, and their interests.
The next topic that I wanna share has to do with hacktivism. I predict that in 2025, hacktivists will intentionally introduce bias into mainstream AI models. So fundamentally, the way that AI learns is from patterns in the data that it's trained on.
And so if that data is biased, whether it's intentional or not, the AI will reflect and even amplify those biases. Imagine a scenario where someone is feeding an AI system, hiring data where men were historically favored for leadership roles. The AI upon observing this pattern could perpetuate it inadvertently reinforcing inequality bias and ai.
There's, it's just there. It's there. And now it's not, not only a byproduct, it's a vulnerability.
Activists can intentionally introduce bias into models because these folks, they're driven by ideology, they're driven by the desire to exploit weaknesses, and this is a way for them to advance their agenda or to make symbolic statements. Already, there seems to be confusion sometimes as to whether or not something you look up on the internet is fact or potentially fiction. Similarly, there are gonna be plenty of people who assume that AI always tells the truth.
And so if hacktivists or other groups are going to be biasing the data in a way so that they're advancing their agendas, um, it could create chaos. It could undermine public trust, it could actually change the way that people think about facts. There are few different ways that this could happen.
One method is via data poisoning attacks. So hacktivists can infiltrate the data sets that are used to train the AI models subtly altering them to introduce skewed or harmful or otherwise inaccurate biases. For example, imagine a hacktivist decides to corrupt a dataset that's used for credit scoring that could lead to unfair lending practices, which might disproportionately affect certain groups.
Another approach is to fine tune exploits. So many AI applications used pre-trained models, and these can be accessed and altered by attackers. Hacktivists may be able to tweak parameters and therefore embed biases that affect everything from hiring algorithms to search engine results.
And then we've got prompt injection. Uh, this tactic targets generative AI systems in particular. So by crafting specific inputs, activists can corrupt outputs in real time, spreading biased, misleading, or harmful content instantly.
Finally, I think this might actually be my second to last prediction, so I've gotta, I've gotta move it along a little bit. Uh, this prediction is that in 2025, sensitive input to a chat bot is going to be breached. Chat bots are becoming ubiquitous.
They're handling everything from customer support to personal financial advice, and every day people type sensitive information into chatbots. These might include personal identifiers, possibly financial details, almost certainly secret and intellectual property. And this information is very interesting to attackers.
This is unintentional data leakage. We don't know about the safeguards of most of the chatbots today. We don't know if they're using end-to-end encryption.
We don't know if they're using secure storage practices. Users have a tendency to overtrust ai. People see chatbots as helpful, as neutral, and that makes humans a little bit more likely to overshare.
The consequences of a breach like this could be devastating. And next prediction, possibly Last prediction. I predict that in 2025, there's gonna be an AI leader who's going to emerge, and they're gonna demonstrate awesome transparency and explainability.
So what does that mean? Imagine an AI system that doesn't just spit out outputs, but it actually tells you how it arrived at those outputs, providing a clear roadmap, breaking down the logic, the data which was used, the weight of each factor in the decision making process. Transparency could allow users to know what data gets fed into a system, how that data is processed, and even what potential biases were detected.
And then corrected. Explainability takes this even further. There is increasing demand for both transparency as well as explainability.
There are different stakeholders, governments, businesses, consumers, and they want AI systems that they can trust. Um, I believe that a leader will emerge in 2025, and all others will begin looking to, um, replicate similar transparency and explainability practices As this leader, uh, we're coming to the end of our time, and so I wanna share some exciting news with you. I'm writing a book, it's gonna be published in 2026, and the book is a deep dive into how artificial intelligence is reshaping cybersecurity resilience.
So there's two sides to this topic. One side is, how is AI being weaponized by cyber criminals to launch increasingly sophisticated attacks? And how can AI be used as a powerful tool for defenders to build smarter, more adaptive defenses?
Um, if you wanna dive into learning more about AI and cybersecurity and you don't feel like waiting until 2026, I encourage you to go and check out my recent course available on LinkedIn Learning. If you follow these steps, you can view the course at no cost. So find me on LinkedIn, scroll down to my featured posts, select the fifth featured post 1, 2, 3, 4, 5, and that will allow you to view my 15 minute course on AI and application security at no cost.
I hope you enjoy, I hope your new year is off to a fantastic start. And thank you so much for joining me today. Hi everybody.
Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer here at Techstrong, here with my co-host Tracy Reagan, creator and CEO of Deploy Hub. And in her spare time, she does a lot of work with the Linux Foundation.
Before I introduce today's guest, I'm gonna give you a quick update about what's happening here at Techstrong. com. Be sure to go check it out.
I'm launching a series to go along with it on texturing TV with webinars and, um, biweekly episodes. So you definitely wanna tune into that. We're gonna, we're getting that rolling in the next, uh, two or three weeks, so it should be ready for you when, after you see this episode.
Uh, we have virtual events coming up. We're gonna be at CubeCon in London, come, uh, April. So if you're around, be sure and check in and say hi.
And if you're interested in doing an interview, reach out to Techstrong and, and we can hook you up with that. com, and be sure to tune in every day to Textron TV for all of our great shows and interviews. All right, Tracy, what's on your mind today?
Well, I think I would be mistaken not to say that, uh, deep seek is on my mind. Uh, And in particular, you know, if it's true what they're saying about Deep Seek, and they have a, they, you know, they have a different way of, of building these models, and a couple of university students with $6 million was able to do it. Um, we won't talk about, you know, the, the, um, the, the, the, the funding that went behind them, and if they shorted, um, Nvidia, that's a, you know, an interesting topic.
But the, the, the really, I think the lesson learned here is we're always disrupted, right? We're constantly being disrupted. And in this case, if what they're saying is true, um, it proves that our current VC model and our funding model for companies is not working in the us.
Uh, SoftBank just announced they're in talks with OpenAI to do a $40 billion round for OpenAI, which means that there's a lot of money not going to other smaller companies that might be able to disrupt OpenAI. Now, I understand that they're in there to make money and they're trying to build up the biggest company that they possibly can. But funding is a, a limited resource.
It, it's not infinite, right? It's not, there's not just this infinite amount of money, um, that's coming through the channels that people can get. When 40 billion goes into one company, it's at the risk of maybe losing out on a company that's small, that may have a great idea and that may be able to build something better.
Uh, and not always, you know, spend a whole lot of money doing it. I mean, $40 billion is a huge chunk of cash. So I, I have to use the term, the democratization of VCs, right?
If we're not looking and we're not, if we're not really doing the research that we need to do, and we're just saying we wanna put as much money behind the guy that we think is gonna make it work, I think we're missing out. So that's my thought today, and it makes me sad. Yeah, it's been a big topic, I think, and I think it's brought, been brought up on every episode of Textron Gang this week.
So it's, uh, it's definitely a big deal. Sorry. Um, well I am excited to introduce our guest today, um, Carolyn Nash.
Carolyn, tell us a little bit about yourself. Hey Ladies, thank you so much for having me today. Um, so my name is Carolyn Nash.
I am the Chief Operating Officer at Red Hat, and I know you two are big fans of the Open Source Swirl Open. So, um, you know, excited to be here. Um, and, and part of Red Hat, you know, which is, which is really founded on open source principles.
We, we develop and we, and we, uh, support open source software that fuels, I think it is 90% of Fortune 500 companies. So, um, at any rate, it's a pleasure. Just a little bit of it out there, right?
So, Carolyn, I really wanna first start this question off, you know, what are your thoughts about the, the potential of deep seek and is it really going to disrupt what we thought we had a future in building these massive AI data centers, you know, where, you know, from a, you know, from a personal point of view, not from a Red Hat point of view, what do you think this thing's going, you know, is this just really gonna disrupt how we see AI and demystify it? Yeah, it's, it's a great question and I, I mean, I gotta be honest, I feel like every couple of weeks or something that, that is like, we didn't see that coming. I mean, right?
AI is changing at the speed of light and what we knew a month ago is different from what we knew six months ago is different from what we knew a year ago. So, Lord knows where this is gonna take us. Um, but it is disruptive.
Um, I think there's no question about it, but I think it's more of a question of what do we, um, you know, companies in the United States, other companies do about it? And does that fuel a new, I mean, I loved your point about VCs, right? Like, does that fuel a new app?
Like, don't rest on our laurels with ai. We have to continue to innovate and continue to think about how we can do this, and we can do this energy efficient, we can do this cheaper, we can do this faster. And, uh, but it, it, it will disrupt.
But I, uh, believe, and I'm gonna take the optimistic, uh, stance on this, that, that, uh, that our companies are going to react and, uh, and come out even stronger in the end. Well, let's hope that is the case, is, you know, and now let's talk about it from a OpenShift perspective. Mm-hmm.
How is OpenShift adapting to these AI models, and how are, what are, what are you seeing from your customers in terms of what they're asking for? Yeah. Well, I'll tell you, I'm gonna speak in terms of, uh, uh, open shift's number one customer, and that's me.
Um, so, you know, it's, I think about Red Hat technology. I mean, I run operations, so that's including, you know, including it. And, and we run with every single, every single Red Hat product and, and many of the IBM products, uh, for reference point.
But, um, as I look at it and I look at OpenShift ai, um, we're in a position where u we're using it. We're, we're no different than any other company as we're looking to do things faster, cheaper, um, safe safely. And so with OpenShift and OpenShift ai, we're building, um, models and we're using them to change the way we run our business internally and how we support our customers as well.
And we're not only, you know, using LLMs of course, but we're taking on something that's looking at smaller LLMs. And so basically we're taking them and creating a number of smaller LLMs that are really fit for purpose for what we're trying to use internally. And that is all powered on OpenShift.
And, uh, and the benefit of that is it really does address things in a faster, cheaper way. You, you have to use less energy. You have to use less power, less GPUs in order to tap into these, these smaller models.
And that's exactly what we're talking about with our customers. 'cause again, we're, we're sort of our, our, our customer number zero, we call it our Red Hat on Red Hat. And, you know, from a, uh, from a security perspective on LLMs, I always felt that having those smaller models and having do models that have domain expertise, and if you could build a multi, uh, a, what do they call a multimodal LLM system where those are passing information to them, there's, it is almost a way to encapsulate it and, and protect it better.
Right? There's a better se it is easier to do security around a small LLM than a, you know, I don't know, a 40 billion parameter LMI don't know what their opportunity, but Yeah, that's So huge. You know, That's exactly it.
And you think about, like, so say, like, let's talk about like internal support for any given company. You know, if you have something that's going in and, and you need whatever, I'm an employee and I'm trying to get some HR information on myself, right? If you think about safety and security and personal information, um, you wanna make sure you have a small, large language model that's really focused more on those, you know, HR type of topics as opposed to, and gets routed to the, the ask ar, you know, ask hr, um, uh, a support desk rather than being routed over to help me understand this customer contract and the terms and conditions on this one.
And so it, it, it not only makes it work more efficiently, but it protects our data better. And, and with the regulations and, and so much that we have to protect, it absolutely is a safety mechanism for us. Kind of interesting that we, and at the same time that we're talking about building Kubernetes decoupled architectures and getting away from the monolith we, in ai, it's all monolithic.
I think, oops, are we, you know, sometimes I think that we don't listen to ourselves with what we're saying. So I think it's, I think that model will be more interesting for enterprises to have small LLMs. Yeah.
Yeah. But then we have a lot of agents, aren't we? Like, you know, I'm, I do not like the idea of agents because I think it complicates the stack quite a bit.
And I understand that maybe we can't do it any other way, but there are other agents in the stack that we may not need. And I feel like there's quite a few, there's quite a bit being thrown into production, even to do security scanning, opening up a container in production to see what open source packages were used, maybe some of that we can start scaling back on and pulling from the, you know, from where it was created at the DevOps pipeline and start building more intelligence into that and have a DevOps LLM. Why not?
Right? I love it. I love that concept.
Yeah. We do have to scale back too, because you mean, you think of it, it's, um, you know, you can build and build and build and build, um, but if we're not using everything we're building as well, I mean, we gotta do a little bit of cleaning, like cleaning out your garage, right? Like every now and then, you gotta go in and you gotta pull everything out, figure out what you're not using, what you don't need anymore, and then put it back into the garage, all organized and, uh, available for greater use.
And you know what, it takes companies so long to do that, and they fight it and they struggle with doing it. It's like, talk about hoarding mentality. Yeah.
And, and it throws, you know, it creates just this great discussion around governance as well. And, uh, yeah, because everybody is excited. Everybody wants to try these things.
Everybody wants to do these things. But the more you create, the more, uh, how do, how are we making sure that as we're building and creating, that the experiments that don't work and that we don't want to continue with are actually getting edited back and removed. Um, and it's just, you know, it's almost a, a way it's governance, portfolio management, whatever you wanna call it, but making sure that, um, we're doing that in the right way.
Yeah. I don't think we've figured that out yet, especially around security and at all. You know, we have sas, we have das, but we still have vulnerabilities that make it to production, and we're not remediating even very fast.
The whole idea of chaos engineering and being able to respond to this, uh, to, to respond to a problem or vulnerabilities, I think it has been underserved and needs to get more attention because it's not really about, you know, root cause analysis all the time. And especially as we start doing more AI work, and we haven't figured out how to secure that. We just gotta get really fast at fixing things.
Yep. You can't prevent vulnerabilities, but you sure can react to them very quickly and, uh, and respond to them, uh, quickly and, and, and, and safely before, um, you know, damage is done. Yeah.
So I don't think we, I talk to our customers. I'm, I'm in the Boston office where our executive briefing center is, and, and I'm talking to various customers. Security is one of those top things.
I mean, cost and efficiency and all of that has always been a topic, but security is, is more often than not something that really has to, you know, they wanna, they wanna discuss and they wanna find out what options they have. Well, and what I think is interesting is just in the last few years, there was, there was a lot of push and pull. Um, we do a lot of security stuff here, and I would hear these conversations that people would literally argue about, but we should be able to prevent everything.
And then everyone else was like, no, we can't prevent everything we've got. We've gotta be prepared and we've gotta be agile and be able to work through it quickly. And I've seen that we can prepare for everything, just kind of disappear pretty quickly, especially as the AI is kicked in.
Um, 'cause that's a tool that helps you respond really quickly, right? Faster than ever before. But that argument is definitely moved away.
Yeah, No, it's, It's just not possible. It's not, It's not, it's prepared, it's not possible. It's not you, you can't, you just have to be prepared to react is is what it is.
And, you know, And I feel like there's a culture of complacency. Um, so for example, uh, deep seek gets released and then Wiz goes and says, Hey, we can see that, you know, a ton of data has been exposed. Um, but does anybody care anymore?
Does do they, do people really care? There was even an article I read, um, I think it was, maybe it'd been the Navy or the Army that basically said, yeah, we know we should be watching for vulnerabilities, but if we need to get something out, we need to get it out. And I'll take the risk even if I don't understand what that risk is.
But it's a, it's a statement to say we're not doing, we're not serving the community in, in terms of security. We haven't figured it out yet. And the worst part, the worst part of all this is my opinion is we need an investment to get it done.
But when you have $40 billion going to OpenAI, there's not gonna be a lot of investment in security or cybersecurity in any way because we've become complacent. Yeah. It's so true.
And I, and I really appreciate your point about taking risks, because I think this is the, the, the balancing, you know, that we everybody's trying to do is how do you innovate at a crazy fast pace, but do it safely and take some risks, but take the right amount of risks in an area that is completely, you know, new to, to so many. And, uh, and, and you know, I think, again, in internally even things we've, we've created a policy like every company has, right? Everybody has their AI policy, but it's like version, I don't know what five or six right now, because we have to keep changing it.
Like, oh no, we, we over rotated and now we're saying no to everybody. Well, no, that's not the right approach, right? And so then you're trying to tweak it, but, um, you really, you really don't know, but you also have to take risks.
And, um, but just knowing, knowing where to, to place that risk pendulum is, is really the important point there. I think it's interesting though, how quickly companies, nations have responded to deep seek. Like, we've let all this AI come and everyone's like, should we be worried?
Should we not? Months and months go by. I mean, this week Italy banned it, Ireland, bandit, Congress, bandit, everybody from the government, from downloading it.
Um, you know, I think I'm, I'm just interested, you wonder now if we're just, we flew, flew to the other end of the extreme, but I'd rather see the other end of the extreme. Like Tracy was talking about all this vulnerabilities that people immediately noticed. Um, I thought, I just thought it was interesting.
Every, every couple hours I'm hearing another company or another Com country that says, we're banning it for now. We'll see how long that lasts. But I just think we're not, the response has been, I know, but I think the response has been really quick.
Really quick. Yeah. Yeah.
Well, it's culture right now, and, uh, not following rules, not following policy. Oh yeah. Taking big risk is where we are in our culture.
So that's where we find ourselves. However, talking about taking big risk, you know, I was looking through your resume and you've made some big jumps in your career. I sure have.
How did you do that? Talk to us a little bit about, you know, your background, how you, you know, climbed the ladder to become the COO of Red Hat. That's an impressive job.
And it's great to see a woman in that role, right? Because it's taken a long time for us to get women in C-level positions. Yeah.
Well, thank you. Thank you for that. Sure.
So, you know, it's, um, I mean, I started my career quite a while ago, but, um, I, I actually started out in public accounting. So I was, I was an accounting major in college. Scratch that.
I was an engineering major for a bar sector. And this is, No, I can't, no, pointing is way more up my alley. But at any rate, I, I spent, um, a good bit of time on public accounting, which I absolutely loved.
And I think it became a, a great foundation for my career. Um, because I mean, I, public accounting, it sounds really boring, but the reality is, like what you do when you're in audit is you have to understand how data flows through processes for flows through systems to ultimately end up as a financial statement. So it, it actually is an incredible foundation for how you learn about how companies make money and build assets.
Um, but at any rate, I went into, um, into finance and, um, after I left public accounting, and I was living in Silicon Valley at the time, and so thought tech has got to be the place I go. I wouldn't go anywhere else if I'm living in Silicon Valley. And so, um, got into finance there and how I actually pivoted out of, of finance was when I was starting a family.
And I have, um, I have twins, uh, they're now adult. But, uh, at, at the time I really wanted to continue working, but I needed some more flexibility. So I went part-time and I talked to my boss about it, and he agreed that like, you know, the, the finance and accounting doesn't really offer you that much flexibility.
At least it didn't at the time in the role I was in. So he flipped me into more of an operational role, more projects, things like that. Um, that gave me a ton of flexibility, allowed me to raise my children, and, uh, but also gave me this great experience and exposure to the intersection between finance, between it, between the business.
And I really just loved playing in that space, kind of building on all that old public accounting days. But, um, building in that space. And really from there, it just opened up my eyes to so many more possibilities beyond the track I was originally on.
Um, I got into data and analytics, I got into sales operations, um, and played it. That's Where I saw the risk. I mean, you went from hp, I think you went from, wait, you went from Hp?
Yeah. KPMG to hp, to Cisco, To Cisco in sales operations. Yeah.
I started That's Very different than public accounting. Okay. Very different it seems.
Maybe I'm wrong. Absolutely. Absolutely.
Still got the dollar signs though. Yeah, yeah. No, it would, my time at Cisco was a wild ride.
I mean, uh, Cisco is a great environment to really, they, they allow you, they encourage you to bounce around and try new things and continue to push yourself outta your comfort zone. I actually had a fantastic boss at Cisco, and his point was always Carolyn, when you start to get comfortable in a role, like if you start to come into that little circle of comfort, it's time for you to go look for something new, go take on a new project, just ask for more scope, get something, never get in your comfort zone and never be complacent about your, your, your growth journey. Um, always be learning and growing and being just at a minimum, minimum mildly uncomfortable.
And so it was really at Cisco where I took a, a tremendous amount of risk in, in leaving finance, yeah. Sales, operations, data and analytics, business services. And, uh, and that I think, gave me the confidence when I came, you know, I took a, um, I that gave me the confidence to leave Cisco after 16 years and go to Red Hat.
And I thought, this isn't gonna be a new type of company. Something that I was really passionate about. I mean, 'cause Red Hat's such a cool company, you know, built upon the whole open source communities and development model.
It's also an open source culture for me is just been a blast. And, and it's also a company that really encourages you, just helps you open up those opportunities. And that's where I actually bounced back into finance, believe it or not.
And, um, and, and grew my career in finance back up and to become CCFO. And then at that point there was some leadership turnover. And my, my boss at the time had asked me to take on it and security and a whole other things.
I'm like, sure. Right. Again, you don't wanna get comfortable.
And I can't say, since I've been at Red Hat, I've never been in my comfort zone. It's been always right on that outside of comfort, which is how I know I met a, a great place. So, um, so I, my, you know, my role as COO, you know, I paused it first, right?
As many of these things, like you got the little, I mean, who doesn't have the imposter syndrome? The little person sitting on your shoulder, talking in your ear, like, no, Carolyn, you're not technical enough for it. Well, you know what?
I don't need to be technical enough for it. I need to be a great leader who can build super smart people around me who are willing to explain things to me, teach me, um, allow me to ask the right questions and dig into an appro appropriate amount of detail to make sure that I am driving the business forward in an aggressive and, and also safe way. So You need to do a Ted Talk, and you need to write a book, honey, man.
No kidding. No, it's, you're inspiring to me because it's just, it's just amazing, like your energy and, and just the way your brain works. It sounds like you've had some really great mentorship and bosses along the way that have really supported, like, gosh, we don't hear the, they supported me through raising twins story a lot.
No, We don't. I mean, I could go into a lot more, but I, I mean, I've had some exceptional mentors, sponsors, bosses, and not only had they, um, he got me through my early years with my twins, and, um, but in addition, uh, I mean, my current boss is amazing. He helped get me through the loss of my husband.
My husband passed away two years in the midst of a lot of leadership changes here. And, um, and just really, uh, yeah, I'm, I'm still here and I'm still charging forward. And it got me through one of the most diff the most difficult time in my life, um, and allowed me the space to do what I needed to do and, uh, but also welcome me back and brought me back up.
So I, I am really grateful for my leadership and my, my people, my tribe, um, my, my personal board of directors who have I feel like have surrounded me, you know? And that's, um, yeah, it's really, uh, it, it, you know, I'm like, oh, I'm getting emotional. Oh, what a really, like, to have great people around you is, that's why I have my energy, because I have great people, um, around me.
And, you know, and Carolyn, I'm so sorry to hear you went through that. Yeah, thank God you have the entourage around you to help you. We all need that.
We really do. Thank you. Thank you.
I really appreciate that. And, um, you know, and, and, you know, 35 years and most of that in tech, being a female is also, you know, quite a journey as well. And again, I, I feel myself lucky that I've had, uh, you know, a amazing female sponsors around me, amazing male sponsors around me, people who, um, you know, who have just pushed me and, and flick that little imposter off my shoulder.
And, uh, and I also think I've been, uh, okay, I'll pat myself on the back to say that I think I choose my companies and my bosses very wisely. And, uh, my choices along the way, and most recently being at Red Hat has been, uh, you know, one of the best decisions, career decisions I've made. I love the open source community.
I'm sure it is amazing place to be a company that it's an open, a company built on open source like Red Hat. You know, I'm, I'm a big open source band. That's why in my, in intro, it's always, Tracy does a lot with the Linux Foundation, but boy, open Source has taken a beating recently.
You know, we're getting blamed for a lot of security issues, which probably is correct. But, um, we've known this for quite some time, right? And maybe it's open source that's gonna get us out of this problem.
Um, but I feel like there's a lot of stuff being written and we're not doing much with it. Adoption of these security tools and for open source will be a challenge. Um, how do you guys talk to your community about, about security?
How do you navigate that? Yeah, uh, I mean, it's a, it's a very important thing. But, you know, the thing with, with Red Hat is, you know, when you think about the op open source and, and we, you know, we live and breathe in the, in the open source, but it actually creates, I mean, our whole open source development model is taking these projects in the community, but bringing them and hardening them into enterprise supported products.
And, um, and that's part of the beauty of it. I mean, when there have been some of the bigger, larger vulnerabilities out, um, red Hat's been one of the first ones in the Red Hat, and the Red Hat community has been the first ones to raise their hand and say, we've identified it and we figured it out. Because I think that is the power of open source, is you are not only in a enterprise grade hardened product, but you have access to the community, um, that has that, that is using it along the way.
So, I mean, I think it's a benefit. I mean, I'm, I, I, I for sure have been, um, living and breathing it. And, and I, I also, you know, going back to the culture piece of it, I believe, you know, you can talk even more generically about security, and you can talk about security and the enterprise from a non-technical standpoint.
And I believe the open source, um, culture really starts to weed out these things as well. You know, when you are taking ideas and inputs from all different places, you're also getting people to raise their hand to say, I have a concern. And like at Red Hat, even internally, we have company-wide mailing lists where people frequently debate and discuss different topics, controversial topics, but they, things that bubble up that, like we as a leadership team, we're always monitoring it because some of the really, like, woo, okay, that's an interesting idea, or that's a really valid concern, or we might need to dig into that a little bit more.
That's open source too. And that's kind of the sa, you know, you talked about in your personal journey, being able to, to take a risk and staying, staying outside of a comfort zone or just staying just a slightly outside of that comfort zone circle. Um, companies are doing that with open source, right?
They're, they may have, it may be pushing them a little bit, but I'm hoping where it pushes them, they can't get away with writing software without open source that, you know, that cat's out of the bag, it's not gonna happen. It would take a lot of coding. It would take a lot of work, and they wouldn't be able to keep up on the, what, what's new in AI without it.
So how do we as an open source community, make them feel okay about continuing to step out of that circle of comfort saying, okay, I'm only gonna use these particular packages, I'm not gonna try to use anymore. I know these are secured. Uh, how do we do that?
How do we bring open source back into conversation that people don't say, oh, there's a security issue with it from a bi from a broad community perspective. I know that's a big question, but Yeah. From a, I know, and I immediately go into just buy Red Hat, come on.
I'm like, no, I know you're trying to go broad on me. But that, I mean, but I think that is, it is understanding what is it that you're using it for? And is, are you accepting a level of risk in the open source, um, in the open source community that you are comfortable with?
What is, you know, a small startup company is different from a governmental agency or a banking, I mean, the, I I think it depends on where you are in the continuum, but, but if you're one of these larger companies that's trying to stay, um, and keep yourself more secure than maybe your mom and paws need to be, that is where you need to still embrace the open source, but make sure it is enterprise wide grade, uh, open source, and that it's, it's hardened and has the security that you need necessary to make your regulators comfortable to make the, the various agencies comfortable. Um, but, but open source is, um, we've proven that it is secure. Absolutely.
And I, you know, I think more and more, um, some of the tooling that is being developed, open source tooling, by the way, is being developed will, will help solve this problem. Um, and I'm hoping that, uh, we start embracing more and more through the DevOps, uh, you know, pipeline, adding more tooling and consuming the data and getting smart about it, because I love open source, and I would hate to see it go away, even though I don't think it's going away any, any more than the mainframe ever went away. And there's legacy open source out there, and there's new being written every single day.
And we have to be outside of our comfort zone and start and consume it, because that's the only way we're gonna really build, um, innovation in this country is to accept it. Mm-hmm. Right.
It's just, I mean, it's, it's tied right there with ai. I mean, open source AI is, is an incredibly powerful tool. It is incredibly powerful.
That's just gonna unlock a ton of innovation, I think, unlike anything that we have seen before. What do they say? This is, this is gonna unlock more than, than, you know, the invention of electricity.
Uh, it really will. But, uh, I, the, I believe that AI powered through open source is just gonna be exponential. I would agree.
And it's way beyond our comfort zone right now. It is so beyond it, but we have to go there, right? We, we really do have to go there.
Yeah. And, and we have to, I mean, go beyond the, you know, what's gonna happen in six months. You don't, I mean, you just have to keep pushing the boundaries and pushing the boundaries and, and, and doing what's, what's, uh, you know what I was gonna say, what you're comfortable with, not what you're not comfortable with.
But, but you, you can't, you can't, you no longer can do a year long roadmap. A roadmap doesn't make any sense here. It's gotta be just fast innovation, iteration and learning.
And again, I don't wanna, I don't wanna lose sight of the governance component of this, um, because it is, um, it, it's something left unchecked could be, could be quite scary. So I know we're gonna, we probably we're gonna run outta time. Oh, we're good.
We're good. So tell us what's new? What, what's new and what's, what's happening at Red Hat that we might wanna know about or that you can share with us?
Is there, you know, what's exciting? Least don't tell anyone. Yeah.
We won't tell anybody. We wanna know what's exciting at Red Hat that the team is super, super jazzed about. Oh My goodness.
Well, I mean, we were just, I'll tell you, we've been talking about it. I, I think the thing that is coming out of our mouths in every single meeting, in every single investment decision, and every single, you know, just, um, interaction we have is, is around ai. And it is how do we, you know, bring our customers to the next level?
And again, I'm looking at how do we bring ourselves to the next level, uh, but, but doing so in a way that, you know, other companies just haven't thought of. I mean, we had just had something really cool, uh, a couple of months ago. We were looking at some of our models and, um, some of our LLMs and we actually had, uh, somebody from our team go and load up inclusive language, um, standards into our LLMs, right?
And so you think about things like that, um, how just all of a sudden now, you know, something that we were a little bit nervous with about ai, now you load up into those standards, this is inclusive language, and, and all of a sudden it just changes the game a little bit. Um, the other thing that I think is really cool is just skills development. And I think a lot about people and, uh, and where are we gonna go?
And we talked about, we don't even know what's gonna happen in two months, right? Six months a year. Well, we have to assume that every single role we have will not look the same in two years, in three years.
So a lot of people talk about, well, does that mean these jobs can go away? Well, what we believe is we really have to re-skill for, for these, um, for these shifts that are gonna happen. And so we've been creating a good bit of training curriculum and looking at, okay, what are the roles and the skills that we have today?
What are the roles and the skills that we are going to, we anticipate that we're going to need? And let's take that, create curriculum, create experiences, projects, um, innovation days to help people move along that continuum so that they will be ready when we get there, not if we get there. And I, I just think that's been really cool, something we're real excited about here.
Um, so that, that just, It had work with universities. Mm-hmm. Very much so I, yeah, it's, um, yeah, we have some local partnerships and, uh, so we work very closely with them.
And, and I mean, our belief is you gotta go get the great university talent. Um, they're getting, you know, uh, not only are we importing talent from the universities, but we're partnering on a lot of projects with them while they're in university. Um, and, and investing in that because, uh, again, that's where the innovation is coming from.
It seems like the university system can be really slow to put together curriculums and get new classes offered. Yeah. Uh, I think that's my biggest frustration with, with some of the students that are coming outta university is that they're, they're somewhat prepared, but they're not prepared for tomorrow.
Yeah. Well, we are, we do, um, you know, we have various internship programs where we bring them in, we give them projects, but we, you know, we give them loose projects because what we're seeing out of these, um, you know, university minds is that they can approach a problem in a very different way than historically we probably would've thought. So we do believe in the practical experience, but, you know, we've also been investing into those to make sure that it's not necessarily just a traditional classroom experience for this type of innovation.
Yeah. I think we learned that with Seek versus OpenAI, right? And was a couple of universities, the students have thought about it differently with the less money, and they were just motivated.
Yeah. And we're also trying to get, uh, you know, we are, we are partnering with, um, some of the local high schools and middle schools and, and trying to, you know, just ensure that we are, uh, getting the word out on the importance of STEM to, uh, the younger folks. So we, we often host like middle schoolers coming in here, and, you know, we'll do a little pitch on what is Red Hat.
But what we will talk about a lot is just, um, what STEM roles look like in a high tech company. And even if maybe you're not, you know, maybe you're not an engineer, well, still, there is a career path for you in stem. Um, and we show them what that could look like at a Red Hat.
And so we break out into smaller groups. What does a product manager look like? What does an engineer, what does a software developer look like?
So that we're trying to also spark that excitement. We give them projects to do that excitement, that sense of innovation at the very early age. And, you know, in addition to just getting, um, middle schoolers there, um, we, you know, we focus on underserved communities.
Uh, we certainly wanna make sure that we're getting our young girls really excited about this and that we don't I was gonna say that, that reaching out in middle school, that really does help young girls Yeah. Maybe redefine who they are and how they could participate, right. In the, in a world where they believe it's dominated by men, which it is, I'm not, you know, we're not gonna deny it.
Yep, Yep. It is, it is dominated by men. Um, but, you know, that is, that is shifting and, um, and it is, it's shifting and it's, it's getting better and the environments are becoming more inclusive, and I feel like, you know, voices are being heard.
And again, it's one of the, the, the great things that I love about where I am at Red Hat, because that is, we, we very much try to create that environment where you can show up as your authentic self and your voice can be heard, and you can use that to push Red Hat forward. I think men always show up with, with their authentic self. I don't think they know how not to, 'cause they're, it, they, they've been, they're allowed to.
I mean, they don't worry about putting on makeup at 14. Right. You know, they don't worry about getting facelifts at 55.
Right. They're totally okay. Oh, they're worrying about that more and more, more than you think.
Well, maybe so, but women all, they're just not as vocal about it. They're not as well, They don't attack amongst themselves like we do. You know, you don't really know that the Botox is going in and, uh, come on, let's face it.
It's a, it's a thing. You see That ma hair on there when you, You do. I've seen the makeup closely, I think.
Well, and there's a lot of painted nails, which I love. I think it's fun. Um, back to the conversation about job elimination.
I think when we're talking about these kids, especially college age, I think the incorporation of the AI is what's gonna help. But it's also terrifying to these kids that they hear all this, you know, older folks saying, well, AI's gonna take all of our jobs, and then we wanna make sure we're encouraging them and saying, no, it's not, it's just gonna evolve what they look like. We just have to push that.
'cause even my kids, they're in their twenties, early thirties, and, you know, we've had that conversation, is AI gonna eliminate all these jobs of our friends and people we know? And we just keep telling 'em, no, it's gonna change what they look like. We still need humans.
Yeah. You still need humans and people who understand AI and, and yeah. And I, you know, I have two kids in college, and that's something that I'm like, you gotta understand digital skills.
You need to understand critical thinking. You need to understand the way the human mind works, right? Like, you need to understand these things because these are the important skills that will be necessary in a world going forward that will have ai, you know, it just, it, it looks different and you've gotta be prepared.
And it's not just a college, it has to be lifelong learning. Um, you have to be keeping yourself up on this all the time. And we all do.
And, and, you know, you just don't think that your growth opportunity is learning in the job that you have today. It's not, I mean, it's absolutely. Yeah.
Uh, so it's lifelong learning and, and pushing the boundaries of those skills and will always be needed. And we always need good critical thinking. So I'm the one who critical who goes off the track here.
Um, before we finish, we've only got a few more minutes, I wanna hear about the Elizabeth Nash Foundation. Oh, thank you so much for asking Matt. I didn't even see that one.
Um, so, um, I mentioned I lost my husband, um, and, uh, he had cystic fibrosis. He ended up passing away of something else, but cystic fibrosis. And his sister also had cystic fibrosis and passed away.
And after she passed away back in 2003, we started up a nonprofit, um, foundation aimed at improving the lives of people with cystic fibrosis. And we, we kicked it off originally with, um, scholarships for people, uh, based on, you know, a whole variety of things. But people with cystic fibrosis, we, um, uh, invest in research, specific research for it.
And, um, most recently we're, we're taking an additional amount of scope where we've created, uh, a fellowship program. And what we're trying to do is, there have been so many medical innovations, uh, with cystic fibrosis that fortunately people are living and they're living longer lives. But what's happening is other things are coming up that they're, they're starting to lose their life to other things, but they're also aging.
You know, it's like new aging issues for people with cystic fibrosis that does not look the same as it does in a healthy body. So we've created a fellowship program where we are focusing on addressing the whole person with cystic fibrosis and making sure that as they age, they have the right healthcare and the right culture within the healthcare to make sure their needs are being addressed and they can live a long, healthy, and meaningful life. That's awesome.
That's great. Thank you for sharing that. Um, I appreciate you asking.
It's, uh, it's been a labor of love, and I'm really proud of what we've been able to accomplish and, uh, yeah. More, more great things to come. And because you've been through it, you have the insight that's needed to be able to create a map of what can help people.
Yeah. Yeah. You really wanna take a very patient, you know, a, a person first, right?
You can start with the medical, you can start with the, the researcher. You can start with this, but we're gonna try and start with the patient, right? Start with the human being first.
It's, it's their experiences that are really driving our work. And from what you've told us today, I think it defines who you are. I think you're very person focused.
Absolutely. Thank you. I try to be.
Okay. So before we get cut off, is there a book recommendation that you can give to our audience? Oh, Um, so we have a little book club going on in my team here and, um, the one, so we're just finished up, uh, think Again by Adam Grant, uh, for all your Adam Grant fans.
It's just such a great book. I mean, we talked a lot about taking risks and thinking differently, and, uh, a great book highly recommended it if you haven't, haven't read it. Um, the other one by Andrew McAfee.
McAfee is, um, the Geek Way. So that's a really, really good one too. You asked for one, I gave you two, but yeah, I'm give You one for your book Hub.
Do you have one? Uh, we do. It was a book that I can't remember, one of our guests recommended it, but it's called The Logic of Failure.
Oh, Okay. It Is really, really good. It is.
Um, one, you know, I read it, the, the, I don't remember who gave it to us. Might have been, might have been. Was it?
No, we always need to remember, we always forget. She said she read it more than once. And, you know, I just got it on my phone and I read it pretty quickly, and then I was like, I gotta read this again.
Because there's so much in it, in how the mind thinks and so many good exam examples of how the logic of failure works. It's a really good one. But is like, based on the acknowledgement that failure isn't a bad thing, it's a good thing, and that, you know, but how he's reactive, There's it really, no, it's really, um, how we do, how we make decisions, how emotion can get involved in making decisions, how we don't follow the logic as far as we need to, to understand of successes at the end.
Okay. Okay. Kind of similar to the Geek Way, you know, some, some parallels there about fastest Making Basket read, Though.
I'm Gonna, I'm gonna read, I'm gonna download it on Audible and listen to it this afternoon. Yeah. Write it.
This is our question at the end, end of every interview. So we have quite the book list. I should like compile it Tracy and, and write a, write who, who recommended it for us.
But, um, I should put a blog out there. I love it. Updated.
Yeah, absolutely. Well, thank you so much. This was just a wonderful, wonderful time.
Thank you for Well, I know you're super busy and we appreciate you carving out this time to, to join us and, um, I know our audience is gonna love it. So thank you again for being here. We really appreciate it.
Thank you Both. This was, uh, this was a lot of fun. Great conversation.
I really appreciate it. Well, we enjoyed having you really insightful and everybody remember, stay out of your comfort zone. Exactly.
Thanks everybody for tuning into another episode of Text Strong Women. Stay tuned for lots more great programming on Text Strong tv. We'll see you next time.
Thanks. Hey, everyone, you're developing software. You ever feel the vibe?
Well, vibe Coating's real, you're watching Texture and Gang. Yeah, it sounds like something out of a Beach Boys song, but I don't know. Happy Tuesday to you, you know, feeling the vibes, you know, it's got that California dream in I, I don't know, help me, Rhonda, but, um, welcome to Textron Gang here on this Tuesday.
That whole vibe thing's got me going. I hope it's got you going. I hope you had a, a great Monday.
Let me introduce you to our gang members today, and we're gonna jump right into this exciting, exciting, uh, lineup we have for us today. First of all, joining us out in Colorado. He's the fu VP, analyst for DevOps, app dev, all that good stuff.
And our friend, the guitar man, Mitch Ashley. Mitch Ashley. Hey, Mitch.
How are you? Sending you good vibrations. Said the good, good.
I, I'm digging it. You know, I saw this biopic on Brian Wilson. What a sad, yeah.
Sad story that is, um, jumping over from, you know, California dreaming to the New York state of mind. Yeah. You see what I did there?
Mm-hmm. He, it's, he's our chief content officer, Mike Ard. Hey, Mike, how are you?
I'm doing well. Good to see you guys. Excellent.
Good to have you on. So you feeling the vibe today? I, you know, I'm always feeling the vibe for better or worse, but, All right.
And then joining me here in our Techstrong studios in Boca Rat Hotel Florida, she's our Echo Insights editor analyst, as well as author of a new report That's right. That we covered. If you haven't checked that out on the gang, please do.
It's our own. Bonnie Schneider. Hey Bonnie, how are you?
I'm great. Good to be here, Ellen. Good.
Alrighty. So Mike, I, I, I kicked it off. You know, the new, the new cool thing is vibe coding.
What's old is new again. Should I get out like my flower power elephant bells? And I, I'm not quite clear on it myself, and I was gonna ask Mitch, but vibe coating seems to refer to this new, essentially end users are building their own software again, and maybe we just think there's gonna be more of them doing it.
And there's a lot more reports of that. People are writing tens of thousands of lines of code, and I don't know, to your point, maybe I do throw on some Beach Boy tunes and throw back a couple of gummies and away we go, Well, you're talking to the right guy in Colorado. There.
Is that what it's about? Mitch, Let me know what you need while. Well, a so actually by coding it, the, the term is not very old.
Only about a month and a half or so old this term by Anthony, I'm sorry, Andre Carpathy, who was one of the co-founders of OpenAI. He was head of AI at Tesla. You know, this guy's no slouch, but essentially it, it is for developers.
It's not just end users. What it is, is, I think of it as leaning in to ai. Just, just do it all with AI and starting with Na, natural Language interface.
So describe what you're trying to build through natural language, iterate on it, uh, through natural language. You know, you're not sitting here in an IDE fixing all of this code. You're using AI as much, as much as you possibly can to create and then set up and deploy code.
And so what what I like about it, it is, you know, there's tiptoeing into AI use and development, you know, cautiously kinda learning it. This is what can you do if you really kind of hand the reins to AI as much as possible? And that's, that's it.
It sparked a debate. Not everybody's on the, on the same page about this is a good idea, yet or not. Mm-hmm.
Yeah. There's more than a few developers out there who are saying, this is gonna have a bad outcome because, you know, the software will be buggy, it won't scale. There'll be security issues.
And yet, Alan, we've talked about this. I mean, ultimately we think there's gonna be millions of people building software. So is this the start of it?
Yeah, I mean, you know, this, this is a little truth speak to me. And, and of course we live in a world or country where truth speak has become the defacto standard. So is vibe coding really just AI generated code for the most part?
And it just makes it sound better. We wrapped it in a, in a, uh, California dream and wrapper. I mean, that makes us, you know, because it makes it, it Makes it sound more, it makes it sound more fun, at least, you know?
Yeah. Feeling the vibe. 7 sonnet and start describing what you want it to build and let it go.
I, I think the, the possible, one of the possible downsides is this takes off. And to your point, you know, a whole bunch of crap gets generated, gets created, it, it could put a web blanket on, you know, AI generated code AI use and development. I don't know that that's gonna happen, but, you know, if it took off and everybody and their brother is doing this and just deploying whatever you got back from sonnet or whatever LLM you're using, that's not a good idea either.
Yeah. I will tell you what I like about it. So the whole software development process has always been a little cumbersome to say the least, where, you know, end users put down something that feels like a requirements document, and then that gets handed off to a bunch of developers and it's a left brain versus right brain conversation.
And there's successive iterations until we get to something that feels like compromise rather than what we actually want it. So is there a way to think about vibe coding as end users describing something to the point where they understand the process and the thing that it, that they want it to do, and then maybe the code is open enough for the developers to go in and refine it, to get it to the point where we need it to scale and do all those important things that are called professional software development? I think that's a great point because that's, uh, sweeting the efficiency of it, making it a productivity process go faster.
And I'd be curious, and with the vibe coding, if depending on, you know, how it's been programmed or who's, who's behind it, if it innately is seeking to keep the code more clean and more green, I, I don't know. I haven't really looked into that, but I think it's an interesting factor to see if it, if there's an innate process that might actually do that, where a software developer might miss the mark on that. I think as more LLMs are focused on better security and green code, things like that, those kind of things will happen.
I think now we're, we're at this, can you do vibe coding and really kind of do more complicated software architectures or design patterns, or is it just gonna generate what it's gonna generate? And you kind of live with that. I think the other benefit though is you can also take code that's been generated, even not existing code bases and say, tell me what this stuff does, right?
I don't want to try to learn this by walking through the code and, you know, in my head while the logic paths and understand what it does, just gimme a really good description. Now here's what I want you to do with it. Take that and do the following.
'cause you may not have touched that code in months or years even, or someone else's code. I'll tell you the other thing I like about it, and let's be truthful, a lot of corporations, you know, come up with great quote unquote ideas for developers to go implement that are just boring the developers to tears because it's just the same old frameworks and crap over and over again. And maybe, you know, would be more exciting for everybody concerned if developers did stuff that was more interesting and challenging and the machines took care of all this rot stuff that, you know, end users need.
And it is kind of crucial, but it's not all that complicated. At the end of the day, we just need something to do something. Well, it's, rather than adding one more thing to the developer's plate, we all know about schlep and other things like that.
It is, it is a different way of doing things that you can see if this is gonna be more productive. You spend more time trying to wrangle whatever LLM to give you the code that you want that's working properly as safe, secure, as green as you want it. Or is it actually making you more efficient?
And how far can you take that with vibe coating and imagine an event, event advance, you know, week to week of more things you could do with it. Uh, but it's still experimental. That said, I think that's what, you know, folks like Meta and, uh, Oracle and, and, uh, Salesforce are saying about when they're talking about reducing developers and kind of that mid-tier, they're talking about moving to something like Vibe coding.
Well, I gotta say, I just give him an A plus for choosing the name. Man, what a great name for this. The guy's got style hat good For him.
Style points for the name. Yep. No doubt about it.
No doubt about it. I, I would add one more thing though. And I, and you and I have gone around on this before Mitch, but it's like, you know, end users have all had the same experience.
They're like, oh man, I got this software idea. I need piece of software that does this. And then they go marching down to the dev it team who looks at them, nods their head and says, yeah, that would be awesome.
And, you know, here's your ticket and you are now project number 347 on a list of 512. And we might get to that in three years. So, you know, we might actually get to the point where we do have more software developed faster because end users won't have to wait in line.
Can, can you imagine you as the end user requesting this using natural language prompt, you know, gen, uh, gen AI prompt to say, now does this application do this? 'cause I, that's what I asked Mitch to make sure it does this, this and this. Does this app do this actually query, query the code base and it'll tell you without dragging you through code or mystical development terms.
End users may not want to know that, Right? And there's gonna be an AI agent that's gonna review the vibe coding. It'll be called Buzz Killer.
And, and we'll, you know, look at everything and say, is this legitimate or not? Crazy, crazy world? All right, let's take a break.
We'll come back. I didn't see it at the Oscars the Sunday night, but we, is there a new movie attack of the, or new video attack of the Killer Robot? Must be one of those Chinese films you're watching.
Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more. Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
All right, folks, we're back with Mitch Ashley, Alan Shimmel and Juani Schneider, who's, um, and we're talking now about robots. And we had a chat about this last week in an episode where we were discussing meta and their ambitions in building AI for consumers. And I don't know, truth may be stranger than fiction, but apparently there's this Chinese robot that was in a crowd that went a little bit crazy and had to be restrained by security people.
Uh, nobody I don't think was killed, but it kind of got everybody wagging their tongues for sure about, well, is this gonna be like Isaac a Ebo I robot? Do we need to kind of have guardrails or are we just gonna like, turn these things loose? I don't know.
Alan, what was your take on this? So first of all, in in truth speak language, we don't call 'em robots anymore. What do We call physical ai?
Okay, Physical ai. Um, but that being said, look, I I think, you know, it's more like Robocop than I robot, right? Maybe it was, it's an early robot cop.
I heard, I heard the robot was named Teman. Um, so who, who knows? I mean, certainly, look, here's my prediction and you could say Shimmy said it first.
The first Rob, active functioning robots we're gonna make are gonna be soldiers and it'll probably be the US and China that do it, because that's a great use for them. And if you're gonna have soldier robots or you know, physical ai, uh, soldiers, I think killing and hurting people is gonna be part of their programming. And I think we're a ways off from being as civilized or as enlightened as the third laws, you know, the three laws of robotics and the zero with law, right, Mitch?
Yes. That we saw. Yeah.
But yes, Uhhuh That you see in the, in the Asimov thing, we, we've got, we've got some barbarian years to go through. First I'll posit a scenario that looks like this. Somebody cuts and paste code from the soldier robot into a senior healthcare robot.
And suddenly some old guy is screaming at a bunch of teenagers, just get the hell off my lawn. And then the robot goes and attacks them. So, Wow, that sounds like a Clin Eastwood movie.
Stick the lawnmower outta the robot lawnmower, you know, I have to think of, you know, star Wars and the Clone Wars, you know, pretty soon we'll have clones. It'll you in, in Star Wars parlance. They're droids, right?
They're not robots, but same idea. So, uh, we'll, we'll see. I mean, I, I think you're right.
Alan would definitely see military applications of this, and whether it's AI aided, you know, physically aided soldiers or bot soldiers themselves. Robot, I don't know about physical ai. That sounds like it'd be a lot of things.
I'm not sure what that, but that, that doesn't jive me like vibe coding. But anyway, we'll come up with a better term. Okay.
I, I, whatever you droids. What about droids? Aren't the droids you're looking for?
Yeah. Could be. Well, Well, well, let's take this to the natural level of the United States thinking, um, and the Bill of Rights, but let me get this straight.
If everybody else, especially those criminals has robots, I'm gonna need my own criminals, robots to fight the criminal robots. And it's all gonna be crazy. The Bill Of Rights have been suspended, and it's an emergency thing.
Don't worry about it. I is, is is a robot part of, or will be covered under the right to bear arms. I don't know.
Right. To bear robots If, if, if the robot's a weapon under the second Amendment Versus Rosie the robot house cleaning. Yeah, That was a good one.
I liked Rosie. Yeah, you spoke about Rosie last week, right? Judson?
Yeah. So, so will Smith and Wesson make robots? Is that what we're saying?
Well, but, but think about it. I mean, you know, if you are, if you are, if you, if you're making warrior robots, warrior droids, right? Their aim is probably gonna be really, really good.
Their weapons that are built into it are gonna be really, really, well, I don't know if you do them Mitchell, without ai, because what good are they without the ai, quite frankly. And, um, you know, and, and not just soldiers, like in Army, you know, clone wars. Seriously.
Robocop robots walk in the beat. Well, we know, we know that, uh, at least from Star Wars, that the bots, the droids will be much more accurate than, than the, uh, storm troopers. The colognes.
Yeah. Well, the storm troopers always. Were a little buffoonish, aren't they?
They, yeah. On, on, on the plus side, you know, when the planet is drowning in water, because nobody paid attention to Bonnie. We can set robots in to save people.
Boy, you think robots can swim? They waterproof. That's A good question.
I don't know. Will they need to swim? Or will they just walk underwater?
I don't know. Walk on The bottom. Yeah, that could be too.
Look, it's certainly going to, it, it makes for, um, it makes for an interesting world, right? I, I think the other thing we're gonna have to get our heads wrapped around is, do we want robots that are sort of humanoid in shape and look right? 'cause it'll be more familiar to us.
Is it more creepy? Um, I don't know, man. It's a crazy world.
It's a crazy world. But all kidding aside, in the meantime, you did have this robot attacking a crowd at a festival in China, and I'm sure it scared the heck outta people. Mm-hmm.
I eventually though, when I wanna customize my robot, kind of like a hot rod, you know, I'll just make my own little robot. And whether it's human eye or not will be up to me. Well, it could many forms too.
Um, what about an autonomous car going crazy? You know, mowing people down. That's, that's bound to happen too.
Wasn't that a Christine the movie or something? John Cochran. A movie.
Yeah. I wish that was scary. I, it, I think it was a Stephen, it was a Stephen King novel.
I believe It was originally a Stephen King novel. Yeah. Novel.
I mean, look, this, this is the world. I mean, you know, when we were kidding around with Asimov's Law of Robotics, you probably do need some sort of fail proof programming in there. Mm-hmm.
And then who's responsible if the robot attacks somebody or goes crazy? Is it the owner of the robot, the person who programmed the robot? Everyone with a deep pocket.
Yeah. I Was gonna say, who's getting Sued? Who's got the deep pocket?
But, you know, so let me tie this up to vibe coding. If you've got a robot, if I own a robot, and then I wanna program it to either be more vicious, less vicious, lethal, non-lethal, and I, you know, I could do that easily with vibe coding. You know what I mean?
You know, how the heck do you control this? Maybe we need to put something in that you can't customize your robot and then, Or cut off switch, you know, a kill switch. I'm looking forward that First television ad where it's gonna be, you know, Morgan and Morgan, if you've been attacked by an AI robot That's true.
Robot. Those ads. Your robot is hot.
Yeah, They have in Florida. Yes. Your ac keep You better keep your AC on.
Um, all right. Okay. I see where we're going with this today.
Let's take a break here. We may replace the whole gang with robots. No.
And see how that goes. Um, you're watching Text On Gang. We'll be right back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Welcome back to the Techstrong Gang. I'm joined by Alan Shimmel. We have Mike Ard, and of course Mitch Ashley.
And we're glad to be here because today we're talking about in this section about sustainability. And I had a really interesting interview recently with ELA Ready. She's the VP of product for a company called aptera, which is all about carbon tracking, how to reduce emissions.
And I, I've previously talked to their CEO about supply chain emissions, which is a big factor in evolving regulations, including what's coming out of the EU for Scope three. That means your entire supply chain, very tough to track and measure when you're talking about outside vendors and every step of the process that you have. But this topic of conversation with ika was focused on the role of the Chief Sustainability Officer.
How that's changed, where that fits into an organization. And I think most interestingly for, for the audience of the Textron gang, is where's the role of it in all this? And Ika points out that it's a critical role and very crucial to work hand in hand with the CSO in an organization.
So, as the VP of product at opt, I lead the development of our carbon accounting platform. Um, our mission is to help businesses track, measure and reduce their carbon emissions. Um, writing them with the insights they need to make data-driven decisions.
I think what excites me most about my role in Aptera is the work that we do with companies across industries and maturity levels. It's really help them achieve their goals through our platform and services. Sustainability can sit within very different business functions from finance to operations to people.
So there's little similarity and standardization across the board, which oftentimes leaves these teams feeling, uh, left in the dark. Yeah, that is true. I mean, how do you think this lack of notoriety and collaboration can detrimentally impact an organization?
Yeah, I mean, at the end of the day, sustainability teams are impactful when they're able to connect with the rest of the business and influence business behaviors that alleviate the known risks of climate change. Um, without this critical collaboration, sustainability teams really lose their ability to drive meaningful change. And at the end of the day, an opportunity for innovation is lost.
Solving climate risk business problems requires a myriad of different perspectives. And collaboration is really at the heart of that. Well, how do you Recommend Chief Sustainability Officers change that?
How can they, um, get more their messaging out to the different business units and really convey to leadership and the entire company that what they do is important? Yeah, so much of the spirit of collaboration really starts at the highest levels of leadership at a company. Um, an important part of the CSO role is to create a vision for sustainability that's not just, uh, corporate responsibility, but a central business priority.
And then get the buy-in and support of other business stakeholders through constant education and touch points. Um, on the more tactical side, we've seen clients with successful climate programs integrate sustainability metrics into the overall business strategy and performance reviews of peers, um, not just the CSR report and sustainability report. So ultimately, sharing the accountability of sustainability helps drive these results.
I don't think I can emphasize enough how important and critical IT solutions will be to decarbonization efforts over the next decade. So aptera is one of the companies that was featured in the ECOTECH report because of the carbon tracking factor. But I think it's interesting to have this conversation about the role of the chief sustainability officer and not being as, as I mentioned in the video, as in a silo where it's just one department.
I think the importance of having that interface with IT teams is crucial, as I mentioned. And, you know, since we're all I should say, except myself, IT practitioners, I'm, I'm curious what you all think about that. Well, I think it's good to take a access to a lot of data that are gonna be, you know, within the ERP system, CRMs, things like that.
But also, you know, if you really follow the, the supply chain, it's back to what materials are used in manufacturing of products, or, you know, we generate or use carbon, uh, as part of building something or operating something. So we think about, think about AI and all the data centers that we're running for ai. What is the carbon footprint of that adding?
Or is it, you know, substituting other things? So I, I don't know that any, any sustainability officer could truly operate on their own. They're gonna wanna talk to all parts of the organization.
Sure. That's a good point. I, I think th there's two aspects to ai, to it's role in sustainability.
One is kind of physician heal thyself, right? What can ai, what could it do around IT usage to be more sustainable? So to be more efficient in computing resources, to use better materials in, in your computers to, you know, just make your it more sustainable.
And that there's a limited impact, but an impact. The bigger impact is how can we use it to be more sustainable through all of our business processes, such as manufacturing, building, construction, you know, so much of, of the, uh, carbon that goes into, goes into during the construction process, like right in the beginning. And so, you know, can it be more, uh, influential in, in making sustainability decisions throughout the, the broader supply chain and business of an organization?
That's number one. Number two, though, you know, I was reading an article yesterday that I think a new executive order came down that we're gonna do more, uh, we're going to increase and accelerate timber harvesting, which means basically deforestation, right? We're going to, I wake up every day and biffs in charge.
But you know, if that's the kind of messages we're getting, how many chief sustainability officers are we gonna have? Is that like a dying breed? Are are, are organizations going to care enough right?
To, to be serious about sustainability? Well, right now it's a rising breed from the research that I've done, is that it's increasing and it's in most forward, uh, larger companies. There, there is a chief sustainability officer.
But you're right. Now, we're early on in this administration. We'll have to see what the effects are of it.
Yeah. I think it's a matter of does it politicized or not? Right?
If it goes the way of DEI making it a political issue, then, then there's a real danger of the becoming a rare breed. Until then. I think, to your point, Bonnie, in your research, right, we'll continue to see this building up.
'cause it is a global phenomenon, not just a, you know, in the US what our needs are. So a lot of the regulations coming on you, of Course. And it is the personal beliefs of at least the IT practitioners that I've, I've interviewed and met, um, that they, they feel strongly about it themselves.
So I think that that's always gonna be a motivating factor too. Here's what I'd like to see, and it's not no different than when Bloomberg put together some law that require restaurants to show you how many calories were in the meal you're eating, right? We should be able to just see, regardless of what you're gonna do about it, it is up to you, but, uh, how many carbons were used to create this thing that we're about to buy, consume, use, or whatever.
And that should just be data that we're sharing with folks, so everybody kind of knows. And then they have a relative metric for, uh, how much carbon is being generated by, for example, I don't know that a query you just sent off to an AI agent, um, and you should be able to see that and then decide for yourself what makes sense for you. But I think the more that we make people conscious of the fact that we're counting these things, we'll get better behavior.
I think you're right. You see that sometimes when you're purchasing something on Amazon, it'll say, you know, low carbon, um, recognized for that. So it's starting to pop up and given the choices, especially if the prices are the same.
I, you know, I'm not sure of the research, but I think a lot of people would be in inclined to make that decision. Yeah, I I would think more in the rest of the world than here, unfortunately. I mean, I wouldn't trust the provider of the product or service to count the carbons.
I'd want somebody else to validate that, but, um, I think that's ultimately where we need to go. And maybe states will do it. I mean, you could see the state of California driving something like this, and then everybody else will just fall in line.
That works. That would Mike Great stuff though, on this video, your reporting it echo Yes. com and, um, some of the companies that are featured in it are, uh, putting out, you know, releases that they're, they're honored to be mentioned in the report, which is so great.
And, um, one of the companies I, that actually did that was called Human it, and they specialize in that, that ability to recycle refurbish hardware and then give it to people in need. So it's, uh, you know, full cycle for this report of the product and sustainability and look forward to the feedback that we continue to receive on it. Very cool.
Mm-hmm. All right. Great work on that, Bonnie.
Well, guys, I think that's gonna wrap up this Tuesday. Techstrong g we got you in outta here in 45 minutes today, which is a beautiful thing. Uh, we've got as usual a full Textron TV lineup following, so stay tuned for that and we'll be back tomorrow with more Textron Gang.
Until then, on behalf of Mike Ard, Mitch Ashley, Bonnie Schneider, and myself, have a great day. We're outta here. This is Techstrong tv.
Hi everyone. Welcome back here to Techstrong tv. Um, really happy to have this next guest on with us.
We're gonna be talking about a new report that came out from our friends at the Cloud Security Alliance. Let me introduce you to Ken Wong. That's kinda like Jensen Wong, but no relation, unfortunately for Ken.
ai, and he is also the co-chair of the Cloud Security Alliances AI Safety Initiative working group. And I'm interested to hear some thoughts on AI and safety from him. Uh, they recently came out with a new, uh, report on ai, organizational responsibilities for AI tools and applications.
But let's first get to know Ken. Ken, welcome to Tech Trunk tv. It's great to have you on here.
Sure. Thank you, Alan. Nice to be here.
Nice to have you. Um, so Ken, I, you know, I gave, I gave them your title, and obviously you're doing some stuff with ai, but you know, you didn't start working yesterday. Give people a sense of your career arc and, and how you came to be the Chief Artificial Intelligence officer, as well as the co-chair of this working group.
Sure, yeah. Thank you, Alan. So I look at myself as ai, uh, researcher and also book author.
I wrote a few books on the ai. Uh, I started AI long time ago, uh, when I was actually a PhD student, uh, in University of Ong, where studying the intelligent tutorial system, like teach, uh, the university kids the accounting system. So I published my first paper on the ai, but at that time, it's, uh, law based.
So now fast forward, uh, to the GPT movement. Uh, so, uh, when GPT two coming into the life before G PT three coming, like charter GPT come, right, I actually realize that will be important. So I start to write the book about the this, uh, and then eventually it was published by Spring.
It's called the, uh, charter DPT and the Web Studio, uh, right, and the landscape of the tomorrow, the, or it's impacted. So this one is a hugely popular book. It has like 27,000 paid view in spring alone.
Uh, after finishing this book, I, because my, uh, expertise is more on the cybersecurity side. So I look at everything from cyber cybersecurity kind of glass of view. That's why I start to write the book with all this expert together.
Write the second book on the generative AI security. That book is also published the by spring, uh, last year. Uh, currently it has, uh, 16,000 views, uh, or paid views in spring.
So my next, uh, uh, spring book will be Agent Tech, ai, CLS and Practice. So the reason why I'm involved with, uh, uh, product Security Alliance, certainly Cloud Security Alliance is front in the cloud security and also in the AI safety and security. We have the working groups, uh, four working groups.
Uh, so I co-chair two working group One is the AI Organization Responsibility working group that I co-chair with Nick Hamilton, uh, from Open ai, uh, for his GGRC head. Uh, another one is AI Control Working Group. So we actually last year produced three white papers.
So one of the last way white paper from AI organization Responsibility Working Group is the paper we are talking today. Uh, but in the AI control framework, we are building the AI control matrix. Uh, this already goes through the public review.
Now we to the next stage is to provide the auditing guidelines that actually right after this meeting, I will chair another meeting to with expert to define the auditing guidelines for AI consumer matrix. So it's lots of fun. And I also joined, uh, the Oasp, uh, their opport, uh, their initiatives.
So I'm core member of OAS Top 10 for larger energy models. So trying to push these things forward, make my contribution. Absolutely.
You know, so Ken, I've also been in security many, many years, 25, 30 years. Um, again, we've discussed this on our text on gang show a year, a year and a half, two years ago when Gen ai, you know, really was first bursting on the scene, we heard the usual, the usual from the security industry, which is, Hey, go slow. Mm-hmm.
Go slow. As a matter of fact, this AI has more potential for, for, for bad than anything we've done. And we've gotta go slow.
Of course, there was that very famous letter signed by a hundred very famous technology and celebrity people who said, we've gotta go slow with ai, we've gotta worry about safety, and we have to worry about security. Um, and, and you know that this doesn't get outta control. Some people said yes, some people said no, but it was out there.
Certainly over the last two months, three months, that seems to have all gone by the wayside. Now it is. Get AI at all costs, do as much as fast as you can, right?
Of course, deep Sea came out, it was kind of a Sputnik, if you will, a Sputnik moment where companies would say, oh my goodness. You know, maybe throwing all these hundreds of billions, these people did it on a shoes string open source, right? We've, we've gotta, we gotta go fast.
We don't wanna lose the AI race. Everybody's in an AI race, countries, nations, companies, you know, everybody's in an AI race. Have we thrown security and safety to the, to the side of the road and said, that's not important anymore.
Or I mean, is is it just dollars that's at stake here? And, and, and so we're sacrificing safety and security? What do you think?
Yeah, so I think the key thing is safety versus security, right? So I think, uh, the things, the chat, the GPT movement is the focus is really a sudden kind of waking up and say, oh, wow, this powerful, or it can make, right? So the idea is more like on the safety side, uh, especially on the dooms, they see like, uh, end of humanity, like, or it can make the damage.
So that was the like, uh, last year and, uh, since the charter DPT movement, and there's a lot of, uh, people behind it, certainly, uh, I, I would say this is more theoretical in my book actually, generative AI security book. I do not say it's a generative AI safety book on purpose, because in the book I said, this is all theory actually for the enterprise to really implement, leverage the intelligence from the larger land model, uh, you really need to focus on the security, like CIA side of it, right? It's, uh, it's, uh, too far away in terms of end of humanity.
So in the last year, we always look at the future to see what the damage, um, should take. But this year we actually have a wake up moment say, okay, this is powerful, but not to the extent that it can end humanity. We actually really need to leverage the bring, which is a larger model to mine, the intelligence from IT to build our application, especially the agent AI application.
This is, uh, certainly the next wave I involved in the cloud Security Alliance agent AI security initiative now, as well as oasp. Uh, so we actually will announce a initiative soon, uh, in partnership with oasp AI Exchange to say how we can actually test agent AI security, or rather team it so that we'll soon and keep tuned. Uh, so the key is like, uh, JD events in the, uh, AI action summiters, right?
Uh, mentioned that it's too much regulation that's maybe, uh, kind of inhibit the, uh, innovation and also, uh, chump the kind of appeal of the exact word, biden's, exact word on the ai. There is some reason I think the, uh, behind it, uh, is that with us not yet to, especially from the enterprise workflow perspective, it's not the doomsday yet. We still need peoples like ia who is chief scientist of open ai, right?
He's good, he need focus on that, that is really good for humanity. But the industry focus, not everyone doing the same thing, right? The industry focus is given the deep seek or open AI lama, those are good models.
How can we leverage this model to build useful applications and also may make sure the secure, like that is the focus now. So, uh, I, I will also speaking at a agent AI security summit in New York City, uh, the end of next month, uh, that was organized by some clause industry initiative, especially Zel, uh, they have the agent AI security anywhere kind of slogan for their company. So yeah, I think the conversation will start soon about the, uh, the security aspect, not the safety.
So just, uh, a distinction, right? Safety is more focused on the, uh, dunes, they like the harm it can make, and also CBIN or chemical, biological, radioactive nuclear aspect of it, right? And security is more focused on the, uh, CIAs the confidentiality, the integrity, availability of the AI system so we can actually leverage the AI intelligence to streamlines our business workflow.
So that's a distinction. Excellent. Excellent.
Ken, I probably took us down a rabbit hole. I didn't realize. I didn't mean to, but it was nevertheless valuable and good discussion.
But I did wanna discuss with you today this new report that your working group is published, and CSA is published. Give us an idea on the report. And I always like to say, Hey, what were the, in your mind, what were the top three key things in this report people should take notice of?
Right? That's very good. Yeah.
I al always, it's really good. I always like, there's so many point we need to take a sur top point, right? That's also like we have su white paper in terms of responsibility for the organization.
There's so many responsibilities. So we say, okay, we take a three white paper. The first white paper is core responsibility, focus on model, focus on the data, focus on the vulnerability.
The second one is more from the GRC and the culture aspect, right? The third one is actually you put it into use. You building the application, you have the tools, uh, that you need to use.
Uh, what's the responsibility? So the three, uh, key take away from that is first we actually look at the responsibility from like the measurement. How do you measure it?
And how do you actually, uh, have the matrix, uh, to measure and also the what kind of, uh, laboratory, uh, regulation were impacted. And also looking at the Laci model, who is responsible, right? This Laci model is important.
So this is kind of cross cutting behavior we have. And then the second one is really, uh, in terms of application, if you really build application, especially the agent AI application. So keep in mind that, uh, in the future the majority of AI application will be agent AI application.
Because if we really define defines agent ai, it has a certain level of autonomy. If you look at the deep research from open ai, it has agent behavior. You give a topic and it will break down the topic and it using different tools to search the internet.
And then, then it has an agent to summarize the, uh, text. And then there's another agent to analyze the content and then produce the report. Uh, another agent is just produce a report.
So this is already like in use now, the agent, right? So we, how can we secure it? So that's the second point is when we develop application, what is your responsibility to secure it?
And the final one is really the supply chain. It's, uh, you have to leverage the third party tools. So how are they secure?
So we process this responsibility into the 70 pages document. We try to cut it, but, uh, I think it's important to put things there and people can, uh, look at, uh, look it and filter it. So, Agreed, agreed.
Ken, y you know, those are three meaty things we could jump into here if we had more time. But unfortunately we're coming on the end of our time. For people who want to maybe get the report though and dive into this, just wanna make sure I got this right.
org, right? org. It's Dot org, right?
Excuse me. You know, I was there at the RSA conference in like 2005 or oh six when they formed the, the CSA. org.
And then if you look under research projects and look for AI or AI safety, it, it should show up there. Um, Ken, what about for people who maybe want to get involved in this working group? How would, what would you recommend to them?
Yeah, uh, uh, so Colorado Security Alliance has a circle like application. So once they get to the, uh, working group, a homepage, they can assign up and go through the circle. The, uh, beauty of, uh, joining the circle is they have access to our document, uh, is, which is Google document.
So they have access and they can also get invited to the, uh, meetings. But our meetings open, like if everyone interested, even they don't, do not want to join Circle, they can still participate in the meeting. We have open meeting people sometimes just join, uh, to learn something that's, we welcome.
If you really want to learn something, it's okay. And some people really want to contribute, so that's also really welcome. So yeah, it's, it's, That's fantastic and that's good that it's open like that too.
And that's something I know Cloud Security Alliance has always been there. Working groups are always very welcoming to anyone who wants to, you know, participate. Yeah.
And thanks for coming on Techstrong TV here today. Appreciate it. Keep up the great work.
This is, look, this is whether, you know, money gets in the way of safety and security. Sooner or later, people always get smart and they need security, and they need safety. So the work you're doing is very valuable and important and keep it up.
We thank you. Yeah, thank you. A uh, one more thing I just want to add is the UK government just changes their AI safety Init Institute to AI Security Institute.
There you go. So that's the trend, right? Yeah.
Excellent. Gen Wang, chief Art artificial intelligence officer from distributed apps, ai, as well as the co-chair of the, of the Cloud Security Alliances, AI safety initiative, working group, maybe safety and Security Initiative working group soon, yes. Here on Tech Drunk tv.
We're gonna take a break. We'll be right back. This Is Tech Drunk tv.
Hey guys, thanks for the throw. We're here with Charles Crosman, who's chief Product Officer for Redwood Software. And we're talking about, well, the rise of automation frameworks.
Charles, welcome to show. Thank you. We've been automating things as long as anybody can remember, but I feel like, um, we wind up, uh, all these islands of automation, they're kind of isolated from one another, and then we kind of try to hand things off and things break, and we wonder why.
Um, so what exactly is an automation framework and how does it fit into that context? Yeah, that's exactly right. So what happens is, over time, as you introduce new applications or new platforms in your business, so you might introduce an ERP system like SAP or you might move from on-premise systems to public cloud systems.
Every time you make a change, introduce a new platform or application, you tend to go out and buy a new automation product, automate that thing, automate the cloud, automate your virtualization environment, automate your SAP environment. And what this leads to is, as you mentioned, islands of automation. So you've got little pieces of automation for each platform or each application across all of your IT infrastructure.
Now, the problem with that is, there, there are a number of problems with that. So the first one is, um, business processes or even IT processes don't live in a single system. They cross multiple systems.
So a typical, if you're a large bank, for example, large financial institution, a single, a single process might start on the mainframe, move through some of your on-premise infrastructure out to the public cloud across multiple applications, both homegrown as well as commercial and or SaaS applications from beginning to end. And if your automation is spread across all different platforms for each, for each one of these steps, you don't have an end-to-end process automation, right? You've effectively got to do all kinds of manual work or, or, uh, custom integration between all these solutions on your own.
So the idea of an automation fabric is something that either replaces all of these I islands of automation or orchestrates them, the ones that exist or some combination thereof, so that you can get end-to-end process automation across all of your disparate applications, whether homegrown or or commercial, on-premise or SaaS. And across all of your platforms, whether can traditional on-prem platforms or public cloud platforms, well, I don't think most people are gonna be able to rip and replace a lot of their existing automation. So how do I orchestrate all that and into some sort of meaningful way to create that and then process?
'cause I think, you know, you hear about it every day, every customer has some experience with somebody who says, I have visibility into this, but I can't see into that. So we'll call you back. Right?
Right. That's right. So, so, so this idea of orchestrating what you've already got is incredibly important.
You have to be able to both automate anything new that comes in that's not al not already automated. Sometimes you replace existing things that are coming to their end of life, or they're doing consolidation, they're replacing vendors, but in many, many cases, you have to effectively orchestrate across things that are already there and already implemented, as you mentioned, that they don't wanna rip and replace. So effectively what you need, the, there, there are really three main components to an automation fabric.
The core of it's an orchestration engine, so a workflow engine that knows how to build, uh, complex workflows, but ideally in a low code, no code fashion so that, you know, you don't need to be an expert coder in order to build these automations, right? You've got visual designers and now emerging things like, uh, ai co-pilots to help you build these automation automated workflows. So that's the first part, the second part of the library of connectors.
So you have to be able to, this workflow engine has to be able to talk to all of these backend systems, typically through, uh, APIs that they've developed. Most, most systems now have APIs where they don't, you have to deploy agents that know how to kind of talk to these systems without APIs. So you need a robust library of these connectors to all the existing systems, again, for everything from traditional mainframes to public cloud, from, from SaaS applications, to homegrown applications to open source systems and everything in between.
So you need a robust library of connectors. And the third thing, the third thing you need is this, again, this low code, no code design experience. If you're, if you're, if in order to make this work, if you have to bring in developers who know how to write Java code, for example, you're never gonna get there.
You need to have, you need to bring the skill level required to build these automations down to what we call citizen developers, non coders through a low-code, no-code interface, typically a visual designer and, or now an AI copilot. And then the last thing you need, and this should not be overlooked, is an observability layer. So the key to adoption of automation is trust.
I mean, if you think about an analogy of something like, um, autonomous vehicles, right? So autonomous vehicles were gonna be, have been on the verge of being fully autonomous next year for the last 10 years. It hasn't happened yet because it takes time to build out this full autonomous capability.
But more important than building of the technology, it takes time to build trust in the automation. So people, humans, you've got early adopters who are gonna be the first one in these auto autonomous vehicles who are gonna be comfortable taking their hands off their wheel and their feet off the pedals. But you've got the mass market, which is waiting for those early adopters to kind of work out the wrinkles for the technology to evolve before, before they adopt.
It's really the same with automation. So in the same way that with the autonomous vehicles in version one, they don't take the steering wheel and the pedals out of the car. You still have to have human override.
You still have dials in, in to tell you what your speed is. You can still see the GPS system in an, in an automation system. You still need that set of manual controls so that humans can override the system when they feel they need to.
But also an observability layer, like the dials, like the dials in the GPS that tell you what's going on, what's succeeding, what's failing if something fails, how do I diagnose the root cause, correct it and carry on. So you need all of those components as part of a, as part of an automation fabric. Will AI further democratize that?
Because I may not even need to know how to make the low code thing. I'll just describe what it is. I wanted a natural language interface and it's up there.
Build it. Yep. Yep.
So, so now we're talking, we're, we're, so there's, there's, when, when you're talking about the evolution of ai, you kinda have to talk again, like I mentioned with autonomous vehicles about timeframes, right? When is it going to be at level one, level two, level three, level four, level five. And it was very difficult to predict with ai, because it's evolving so quickly.
Now, our, our, our intuition is then to say, next year, no longer need developers because ai, ai, AI will be able to write all the code itself. That's probably an overambitious prediction. But in the, in a five to 10 year timeframe, you can see many of the, of the tasks that are done by tip, by traditional coders being done by AI systems.
I'm not, I I can't predict exactly what that timeframe looks like. I don't think anyone can, and anybody who tells you they know is probably, uh, is probably overselling their kick, their, their knowledge as it relates to automation. AI is going to have a dramatic effect on automation the same way as it does on everything else in a few ways.
So remember those components that I spoke to you about? So first of all is, is the, uh, orchestration engine or the workflow engine. So AI is evolving to be able to, um, manage complex orchestrations.
It really can't today. It can do things like task lists like, like, uh, serial task lists and some decision trees, but not, which you would, the complexity of what you would do with a traditional workflow engine, potentially hundreds or even thousands of decision points and branches and merges and loops and all that kind of crazy stuff. So it's not there yet, but it will be, and it'll, and it, and it will be eventually be able to create those workflows, either pro partially based on human language prompts, but probably mostly based on ingesting data that describes those processes and then turning it into automated workflows, right?
Um, so over time, yes. Today, no, not yet. Um, the, the creation of the automation, like I said, if it can automate, for example, a process document, it can maybe created, uh, uh, an automated workflow from that a hundred percent in time.
Um, the integrations are things that people are building. So you hear about an agentic AI all the time. Uh, and this is really, uh, individual companies effectively taking, uh, building, taking the APIs for their existing systems and teaching an AI system how to talk to their system so that they can be automated by an AI system.
Those, uh, those, those, those AI agents are not being automatically generated by ai. They're being created by the companies that own the systems that they're being integrated to. But over time, a, a wide library of these agentic of these AI agents will be available, and many systems will be automated and orchestrated by ai.
Uh, as an example, what AI doesn't have yet, and again, this may come, remember the last part that I spoke about, which is the observability layer, right? So it doesn't, so, so there, there are really three things that have to be addressed. It has to be deterministic, meaning for a set of inputs, you have to be able to predict the outputs.
And that's one of the issues with AI today, right? It's not deterministic. You can ask it the same question twice and get a different answer each time.
Now, if you're only using AI to help you as a writing assistant, that's fine. But if you're asking AI to run an automated process to, to close your, close your books at the end of the quarter, you have to know that it's not gonna make any mistakes or have any hallucinations. So that's something that has to be corrected over time.
The second is, um, is it has to be transparent. So, so you, in order for you to come to trust an automation system, again, you have to, has to be deterministic, but you also have to be able to observe how it does its work in order to build that trust. And then someday, maybe you trust the black box, but you don't trust the black box right away.
And then the third one is, is, again, it has to have that observability layer. So it, there has to be the ability for humans to intervene and take control and or supplement the system. Uh, and those aren't available yet in ai.
So over time, these same capabilities will be, will, will become more available in gen generative AI systems, uh, and the, and the traditional automation systems, and these AI systems will merge. Uh, but, but again, that's, that's a multi-year, uh, process. That's not next, next week, next month, and next year.
Do we need to revisit the processes we're trying to automate? And I ask this question because as we enter the age of ai, it seems to me, uh, when I look at a lot of this stuff, there's more exceptions than there are rules, and the exceptions have evolved over the years, and they were meaningful at some point. But maybe we need to kind of re rewrite the rules.
Yeah, yeah. I mean, we see this all the time, which is, we go into a, a very large corporation that's been around for decades, if not hundreds of years, and they've accumulated over the ti over, over that period of time, many, many, many systems of record, right? And some of those, they continue to operate, but nobody really knows how they work or why they do the things they do.
All they know is it does what's necessary. Um, and so there's an arcane set of rules that nobody wants to touch, because if you pull on one thread, the whole thing might come on unravel, right? So that's one problem with, uh, with dealing with traditional or legacy systems.
But when you're creating new automation, as you're, if you're, as you're implementing new applications, new platforms, and you're building new automation, you, you hit on an important thing. This has nothing to do with the technology. This is just kind of process or philosophy, which is simpler is always better, right?
We learned this in the, in the days of ERP. You see this in the evolution of ERP systems, the original, uh, implementation of ERP systems. They took the ERP system and they massively customized it to fit their own, their, their custom processes.
And they realized over time that the burden of carrying forward all those customizations from year to year, from release to release, from system to system was very heavy. Where the, the modern approach to implementing ERP systems is really to adopt your processes to the system, to, to simplify, to not create all this customization. And so, you're absolutely right.
Lightweight is better. Doesn't mean that the need for automation goes away, but you shouldn't overcomplicate it. You should do, you should do the minimum required to get the job done, uh, and not overcomplicate it with all kinds of exceptions and custom processes and rules as much as possible.
So, adopt your processes, simplify your processes as part of the automation, rather than taking complex processes and simply reflecting them in automation rules, if that makes sense. It does. Do you think over time we might flatten our organizational structures as a result of AI and automation?
'cause when I look across these, uh, companies, there's all these silos, marketing, sales, manufacturing, and yet they're not really aligned around delivering some end result. They're just kind of aligned around a set of vertical tasks and processes that, uh, somebody stitches together manually at the end of the day. So, are we gonna have a moment here where maybe somebody wakes up and just says, you know, the way organizations are aligned needs to change.
So, so this isn't a technology answer, this is more of a kind of a philosophical question. I'm happy to answer it. So, so my perspective is this, the most complex machine in existence is the human.
And, and the most complex interface between two machines is a human to human interface, because it's not deterministic, right? You know, we're governed by emotions and desires and all these things. And so when you see the complexity of interoperation between organizations, it's because interoperation between humans is difficult and messy right now.
So the more that these things get automated by computers, those interfaces get simpler and more deterministic. And you'll see integration across silos, as you mentioned, right? Because computers know how to talk to each other pretty well, pretty easily.
Now, again, I'm not advocating for nor predicting that humans will be replaced by computers and all these organizations, they will be supplemented by ai for sure, for certain. So the more that you, the more that you reflect your business processes in software, in computer code, the more integrated they can become, the less reliant you are on humans, which are the most complex interfaces between, between machines. If you wanna allow, allow me to call com humans, machines, uh, you'll simplify and start, start to solve that problem.
You won't eliminate it, but you'll, you'll start to simplify it, right? A lot of these organizational issues are, are really the root, the root of how humans collaborate with each other. It's a messy, difficult thing, always will be.
So computers collaborate with each other extremely well. So the more that you can, um, put your processes into software and automate these things, the, the better results you'll have in that regard. Again, not replacing humans, but supplementing them.
So what's the one thing you see organizations doing as they attempt to automate things that you kind of shake your head and go, folks, we need to be a little bit savvier about what we're doing here. Yeah, so, uh, probably the number one problem is the one we started with, which is the islands of automation. They've accumulated systems over time, particularly can large companies that have existed for decades, if not hundreds of years over that period of time.
They've accumulated, uh, an incredibly diverse set of systems, an incredibly different diverse set of platforms, applications and automation, islands of automation. And, and to your point around silos, they've got the ability, as I mentioned, to integrate all of this through software, but they haven't done it. It, so they've got all the traditional problems of silos, uh, but they've got the ability to eliminate those silos through automation fabrics, through integrating these things across all of those islands.
They just haven't done it right? Um, and it's the traditional ROI conversation, which is to say there's some upfront effort required to do that, but it'll pay for itself incredibly quickly, and over a three year, it'll probably pay for itself three x, right? But you have to take that upfront effort in order to get the long-term benefits.
All right, folks, you heard in here they say the definition of insanity is doing the same thing over again and expecting a different result. Well, right? If you think about that in the age of ai, just how crazy might we be?
Hey Charles, thanks a shot. My pleasure. Thank you.
Back to you guys in the studio. This is Textron tv. Welcome everyone.
We are back again for Infrastructure Matters, episode number 73 with my buddies here, um, Don iff, and of course Keith Townsend, who is coming in from Tennessee. You got your, um, your, your jet stream or whatever that thing is called, your, The, the Airstream is, uh, parked in the middle of Forest. I i, I posted earlier this week that if you wanna learn anything about site re reliability engineering, try living off grid for any period of time and you'll, you'll, you'll have a crash course master's level and keeping a website up.
There you go. Are you on a 5G or are you starlink? I am starlink.
So our platform will cool, it'll make up for it. I'll break in and out and our realtime recording of this, but it records locally and uploads it, so you know, it is much better than nothing. Yeah, whole lot better The wandering man out in the wilderness.
Okay, so guys, we've got quite a bit to answer through this morning, so I'm gonna jump into it. Um, first a short little piece on some earnings of reflections. We've had lots of earnings this week.
Um, I just spent the time this morning going through NetApp, pure and Nutanix. I haven't gotten to Dell yet, so we're not gonna talk about that one. They may know, um, and kind of where they were at.
All in all, um, everybody's had good quarters. Pure has an outstanding quarter, um, pure storage. Um, they've just kind of blown out their money.
The, the revenue, 12% year to year growth. Um, the subscription business is up 21%, just all kinds of really good numbers that are coming from them. And, um, but, and then NetApp had a slight miss, um, because of some delayed of some transactions, but they were still, they were 2% year to year, um, up in terms of where they're looking at and, you know, still decent quarters.
Um, and tonic of course is up as well. Couple of common themes that went through all of them. Um, they're experiencing the softness in the market over in Europe.
So there is some softness going on there because of certain uncertainty in the US is probably carrying it all. Um, the second piece, they all commented or had questions to them about, um, VMware, um, trans, trans transitions. All of them have had, of course, NICs is double downs on that.
That's kind of a key piece of their market. Um, and that is happening, but it's slow. I mean, it's, it's happening is slower as you would expect because you've got licensing issues, you have hardware issues to migrate.
Um, although they're coming about how fast you can move up in the cloud, like with an AWS, um, just because there's no hardware stuff there. And the third one is an ai, and we're gonna get into that. Um, since these guys are all storage people and they're primarily storage that has to do with the enterprise, that's the slow move and ship, ship right now, or train or whatever you wanna call it.
Um, because most of that work is right, still going into the hyperscalers, um, the maybe AI factory kind of companies that are putting up CSPs, et cetera. But they are seeing, you know, definitely, um, NetApp has seen a couple of big data lakes being put into place that, you know, people are taking where they've already got this, got their environment and expanding it. Um, a little bit less conversation about this from Pure.
So that's kind of a bit on the transactional kind of piece. And I will stop there, and then we're gonna go on to some other things that are even more interesting. So, okay.
Um, let me go on to my, my, my partner's in crime here because we have a bunch of things going on with chat. 7, and, um, Google giving away Gemini codes. So, um, Keith, why don't you take it off first and then you, and then Diane can, uh, come into it.
Yeah, this has been a busy week for ai, uh, product and model development. 5 hit, uh, yesterday of this recording and mm-hmm. Amazon hit with Alexa.
5 for quite some time. And I have to tell you that some of the early assessment from the I experts is disappointment. 0 to four.
Oh. So, uh, Diane, I'd love to hear your thoughts on both of these. Yeah, well, it's, um, it's the, the last big release between, uh, uh, before that much expected GPT, uh, five and, uh, uh, opening IC they, they put a lot more pre-training work into this to find more connections, uh, between all the data.
5 than it does in deep C car one. Um, that's two orders of magnitude. Uh, and, and, you know, can they be profitable on this?
Uh, we'll see. Uh, right now, uh, only GPT, um, pro users can use this. Uh, it's available today, unlike Alexa plus, which we have no idea when, when it's actually gonna ship.
Uh, you have to get on a wait list for that and some weeks in the future. Uh, and, but, uh, plus users, which is, uh, you know, the bulk of their subscribers will have it next week, so we'll get more insight into it. Uh, it's just, it's, it's an important bump.
Uh, it still keeps them, uh, at the top of the leaderboards. So it is a highly capable model. It's not that it is, uh, that it isn't.
Uh, and, uh, it has somehow, somehow they found a lot more training data to throw at it. So they must be licensing, they must be spending, uh, to get access to data sets that, uh, that are not openly available. Uh, so, but we'll see a lot of testing now that it's in people's hands as of, uh, yesterday morning.
So it's gonna be interesting to watch. Well, okay, so how does that work? If I'm gonna license training data because it's not publicly available, and now I've trained my, my model on it, it's now publicly available, isn't it?
But through their license, right? So they, they've paid to make it available as the argument, right? So, uh, uh, hopefully the licensees know what they're, they're they're up against.
'cause you can, uh, you know, the techniques are emerging to extract almost the original dataset if you know how to query, uh, the, the, the model to get that out. So, we'll, we'll see how that, how that proceeds. I mean, it kind of feels like once it's in the wild, it's in the wild.
I mean, yeah, exactly. You've put it out there and you know, that's the big issue about why, Well, this is what called what's what model distillation is all about. You can actually get the information out of a model.
Uh, you in the wind, you couldn't like out of a search engine. Yeah, it's very interesting. Okay.
Okay. Well, what about the Google giving away Gemini. Gemini?
Yeah, so the, a lot, a lot of these models are, uh, kind of put into action, probably the biggest areas in AI coding. I'm looking forward to having a really great discussion with Brian Lau, who's a principal, senior principal architect, or a developer at Amazon on, not on the AI side, but he's been a big proponent of using AI in development. 0 code assistant, so I can, uh, just light up my favorite IDE and this code assistant is fully free.
There's, I think, some ridiculous token limit that the average individual developer probably shouldn't reach. The enterprise version is still need, still needs to be licensed for multiple users and work groups. 0.
Uh, uh, the code assistant is actually pretty good. So, uh, it's an amazing's Leader port, right? Yeah.
0 is a super capable model. Uh, it's pretty brave of Google to give, uh, a huge number of completions away. Uh, so you can do a lot of work for free.
Uh, and, and I think it's really smart to go after developers, 'cause they're the king makers. They made a Ws what they are. 0, get in the hands of lots and lots of developers.
Uh, 'cause it's gonna be the cheapest option for, for most to be able to get their hands on a really powerful coding ai. So The assumptions that I'm gonna code with Gemini, that code is gonna run on Google Cloud. Yeah.
And I, I think that's a strong correlation. Kimberly. We've had Google at Cloud Field Day a bunch of times, and the delegates were always surprised at how well integrated the platform is with the model.
So you can use Google's runtime, Google, GKE, it's various serverless platforms to actually call Gemini. And it's really easy to do. com or Google whatever the website it is and use it similar to how we will use chat.
GTP Google has made it much a much better developer experience than maybe a end user experience, if that makes Sense. Well, I think that comes from, they're being, they were kinda like third to cloud, but, uh, and that means they learned a lot of the lessons from everybody. And they have the, I think, the best cloud architecture, um, you know, product architecture of them all.
Um, uh, uh, you know, it's, it's the most modern, just there's, it's just not as used as the other two because it, you know, they, they, again, they, they came a little bit later, later to the party. So yeah, this, this will, I think, key to help them get an extra level of adoption, both in AI and in cloud. Yeah.
And these announcements don't surprise me, because as we're coming into, um, GTC, which is the, the big GPU conference that's put on, um, by Nvidia, and that was the 21st or something like the third week of the, of March. Um, you know, we we're now, right now getting briefed on announcements that are gonna be, you know, piling in over the next three weeks. Um, and it's, I'm not gonna be at the conference, but I think you, you guys are gonna be, that thing is gonna be crazy.
Absolutely crazy, No doubt. Yeah. It's become the defacto AI conference of the years.
Yeah. It's going, it's going to be up there with, uh, super compute as a, as a as just noise. Yeah.
Um, and getting into that, so Di Diane, you raised an, uh, conversation for us today. Um, a little, a debate around whether or not ai, the technology of AI is a layer on top of the current infrastructure, IT infrastructure or whether or not it is a, what I see people talking about, which is this thing called the AI factory. So, and Dell coined that term last June when, when they, or DTC at their big conference, um, the AI fact, the, they called it the Dell AI factory, and then they've had the, the 18 wheeler right rep rolling around all the United States talking about the, the AI factory.
And then I've seen that term picked up by multiple companies. So it's not no longer a Dell term, it's a actual term that the market seems to be using for some reason. Um, and that's just recently happened.
Um, and it's part of, actually in the briefings, couple of briefings that I've had just recently coming into GTC. So let's talk about that. You know, why would it be part, or why would it be separate?
Well, and there's, you know, there's, and there's arguments being made for both, but I think this is, what's, what's coming up is, is we've, you know, traditionally kept our, our data in, you know, SQL databases. Um, we then, you know, move the no SQL and graph databases and document oriented databases and so on. Um, then vector databases arrive that says, all right, no, you really need to understand, you know, much, you know, a mu much more unstructured information needs to be actually more deeply understood and e more easily to retrievable.
Um, and then of course now we have foundation models and large language models, uh, diffusion models, and they store data. There's, there, there was no question about it. We were just talking about how you, you know, you can extract some of the, the data that's under the covers.
And so is it just part of the data layer that we've always had in our infrastructure? Is it something new? Because, um, uh, you know, AI does things that these technologies didn't do before.
Uh, uh, you know, if we look at AI ages, you know, they actually take autonomous action, um, in a way that we didn't predetermine. They, they determine how things will happen. So there's an argument that we now have an AI layer, uh, uh, yeah, a new AI layer on top of our infrastructure layer.
So I just wondering if you guys want, you know, what your take was on that, Pete? Yeah, so I'm going to say AI is just another version of compute. I think it's a, I think it does blur the, the lines in between data and compute a little bit.
But if we look at kind of the vectorization of data, if we look at how models are trained, models don't keep all of their knowledge within the model forever, you don't have the same level of clarity around your data. Uh, when you're talking about the model itself. Now, when you're, uh, when you're, uh, using your own data to, uh, an adjacent to a model, that's a different layer.
But again, that's compute that you're just saying, I'm going to apply this compute this application layer against my data. So I don't see this as yet a new layer. Just see it as, you know, an advancement in compute.
Yeah. I, I, I, I view it as, as, as a new, uh, spike through the layer, right? It has both compute implications and data implications, I think, uh, and, and it's, it's an, a new, uh, uh, you know, column in the, the infrastructure layer.
So I, I'm gonna go back to some of the earnings calls that I was sitting through, because these are, these are all data, data people. I'm not necessarily the vector people, but, um, there, if you looked at like NetApp and, um, George Curry and talked about, you know, a couple very big wins of people creating a data lake. They were already currently a NetApp customer.
They're broadening that base to be a, uh, creating a data lake capability. Um, and then talking about, you know, your, how you're bringing in both your file, your block, which your databases, um, and then, you know, also the next piece is a multimodal kind of piece, the videos, et cetera, that have to go into the training. So they're creating the separate system here.
However, once you train that, that training data, depending upon what the application is, is gonna go against potentially a transactional system, right? So if I'm gonna use AI to present information on my website based upon maybe a retail transaction or whatever that, you know, or if I'm gonna use ai, let's say I'm gonna use AI on insurance, you know, kind of submissions, that kind of thing. So due to that analysis, so you have this connection between the transactional traditional systems, processing systems with this AI kind of analysis that goes through, um, think also customer service, right?
Customer service that's part of that application within that application. So it has to be integrated with that layer. Um, you guys would know better than I do because you're, you're better.
You're coders and that kind, or you've coded and that kind of stuff, and I haven't done that. Then I'm thinking about kind of like vast just came out and added block to their file and object capability. So that's recognizing the data layer.
And, and why they're doing that is because they're recognizing the transactional data has to come into that training piece of it and do the training as part of it. So they're expanding that piece of it. Um, so, and, and, and, and you have, okay, so Vast and NetApp have talked about bringing in, you know, they're, they're building vector databases within their data data management system.
Um, Dell has chosen a different war way that what they're doing is they're just integrating with other vector databases not incorporating into their data management. That's a strategy difference. But you still see this, you know, this integration of these pieces here.
Um, so it'll be interesting to where this turns out, I get your comments blow hole in what I just said or whatever. Yeah, I think it, I mean, quite frankly, yeah, Go ahead, Keith. Yeah, and I think it's, that's representing a huge shift in the market.
Just, uh, a few years ago I'd be in briefings with HPE Dell NetApp and asking about the data layer, not the storage bits, the zero, the zeros and ones, and deduplication and all the ser uh, uh, the, all of the storage level services they offered, but the actual data and helping to make data easier to process. And none of those players wanted anything to touch with the data. They said that was, uh, left to up to ISVs database providers and, um, basically sis and they wanted to focus on the bits and bobs.
Now, the conversation has really changed because we're seeing, again, to the, uh, earlier comment, the, to Diane's earlier comment, this, this, this, this explosion beyond a single layer and this blurring of what's needed. If I need to retrain my model on my latest data, data or my latest transactional data, what's the fastest and easiest way to get to that? If, um, if my AI model and my data exists on the same storage system, isn't it best to do it at the storage layer?
Mm-hmm. We'll see. Mm-hmm.
Yeah. That's the, and that's the data management layer that we've been hearing them all talk about. Um, you know, for, uh, NetApp, it would be blue, blue xp for pure, it would be fusion.
Um, I'm not sure the name of what Vast is calling it. It's probably just vast, vast capabilities, uh, environment that they're doing. But bringing that out to be able to manage, you know, um, and then having a separate, you know, actual storage, storage plane that has all the traditional capabilities that you're down there.
So, interesting. Thanks for bringing that up. It's a good conversation.
So, we'll, we'll see where that pans out over the long haul. And, and, uh, and then you have to also think about how this connects with some of the people that have got their, their data in the cloud, so that, that's All. Well, and you know, I try to look at what's, what's different in, in AI that, you know, wouldn't normally be found at, uh, at the data layer.
And the only, the only example I can really come up with is what we're seeing is the safety layer that it's appeared, uh, in so many a, uh, AI infrastructure that, you know, does and make sure that, you know, there's no inappropriate information being generated. No, no private information is being revealed, uh, that the, the results are accurate, uh, reduces hallucinations. Uh, and that's not something we've ever seen before in a data layer, um, at that to that degree.
So that's something new, but I, I still think it's just, it's something that we actually probably need in our data layer. So I still, it still goes back to, for now, um, AI is a new element in our compute and data, uh, layer in the infrastructure stack. And that, um, we haven't seen anything quite yet that rises to something that would, that would require us to, to create an entirely new layer because we have some new third, or, you know, fourth entity in the stack.
So, well, And we're really early stages into the enterprise architecting this. I mean, we heard that very much so from, from the, the calls that we're on the earnings calls about, you know, this is still, we're we're looking at 20 25, 20 26 in terms of this really rolling out to the point that it's, it's in, in application. Much of the money that's going out right now is still into the big foundation models, the people that are building, um, cloud service providers that are building GPU service, um, those, or, uh, the other ones that are already research labs of some sort.
Maybe it's, uh, like Harvard, you know, medical, you know, medical that, you know, was cited by Vast or it's, you know, some, some other, you know, pharma that's already has that, but they're expanding that environment to not be an HPC, but, you know, east west, uh, architecture to drive, you know, you know, looking at new drugs and sort of things. So anyway, all all interested in me going. So our next topic, um, HashiCorp big acquisition by IBM.
Um, who wants to take that one? I I kick it off real quick. I'd love to hear what, what Keith has to say though, because he might be spending more time with it.
But, uh, yeah. 4 billion for, for HashiCorp, uh, infrastructure as code security firm, uh, uh, ing with developers as well. Uh, but also at the, you know, during the acquisition around the same time, HashiCorp made a major change, licensing change to Terraform, which is their, their main product, um, that really left a bad taste with a lot of developers' mouths, uh, uh, developers really value the, the attributes of open source.
Um, and licensing is kind of a religious topic. Um, and so, um, it is a question of what, you know, uh, is that, is I being gonna turn this into another Red Hat acquisition? Or, or, you know, how's it gonna work out?
So for our listeners, just let's briefly say what is Terraform? Terraform is the open source, HashiCorp is the distribution. Yeah.
So let's, uh, I, I guess it's important to understand where, why is Hashi Corp getting acquired? Like, you know, why is this unicorn six point something billion dollar now publicly traded company in a position where they can't grow organically? So HashiCorp has a series of applications, Terraform being its most popular, then followed by console and a bunch of other developer, Kubernetes new web type applications.
Terraform is by far the most popular of all of their, uh, offerings and projects. It is, its role is for you to, uh, programmatically, uh, describe and deploy infrastructure. So whether you're talking about AWS Google Cloud, on-prem infrastructure, VMware, vSphere, you can orchestrate your, uh, infrastructure as code.
So I can say 'cause and do Across multiple clouds. I mean, I think that's one of the big biggest attractions, right? It abstracts cloud, uh, cloud infrastructure.
Yeah. So, uh, and they went the open source route, and frankly, it grew it, we saw what the same thing happens, but most open source, it grew to a point, and they couldn't grow it beyond that, and they couldn't really tell a great cohesive story around platform. I said two or three years ago that Hashi Corp needed to sell itself to A IBM or VMware.
Did it make sense for one of those two companies to buy them? Yeah, we'll soon. See, because IBM has made the purchase the, they need, this is a, in order to, to help CTOs and CIOs understand the value of Hashi Corp, you a white glove service, you need the sales force, you need the account penetration.
Terraform was one of those things. Either you bought it or you wanted it free. There was no in-between.
So a lot of folks that are angry, other folks that wanted it free, some, uh, Terraform and the Terraform product team will tell you it's mainly the competitors that are complaining, uh, that it's no longer, uh, open source and, and, and open source in a traditional manner, and free in the traditional manner. But, uh, developers, some developers, especially Diane mentioned it that this is a religious debate for a lot of developers. It's either open or it's not.
Okay. So, and am I understand their primary competitors would be people like a Puppet or an Ansible or something like that? Correct.
Yeah. So I wouldn't, I, I don't even know if they're competitors as a, uh, as much as complimentary, looking at the same problem in a different way. Uh, Cloud formation, lost piece here.
Sorry. Well, the, uh, starlink is, uh, is probably switching to it new starlink that way. So, Uh, the, the old, the old reliable starlink, so I'm back.
Okay. Okay. I'll start.
They'd be competitive question. Okay. So I think Terraform or competes with things like Puppet or Ansible and, or maybe they're just more complimentary, uh, Keith, yeah, So IBM is going to have, you know, some, some work on their hands, kind of rationalizing Ansible version.
Okay. We're losing him again. And Terraform, I wonder we're actually losing him.
Uh, it, it might, the upload might be work just fine. Right. Diane, I'll just let you answer that question because my, the, the, I go through these periods and it's Alright.
All. So then Terraform just is positioning kind of competes with Ansible and Puff Puppet di Diane, is that? Well, I think, oh, first some of what HashiCorp does, that's true.
Um, the, um, yeah, it, it really start, it started out really as secret management. Uh, so if you look at like CyberArk or a Azure Key Vault or, uh, BeyondTrust, those are often considered the more kinda the original competitors, uh, with HashiCorp. But Terraforms become super popular is, uh, as, uh, for, for infrastructure management.
Um, and so HashiCorp now does multiple things like so many cloud vendors do. So, you know, there's, they have I think, an array of competitors at different level, at different product levels. Yeah.
So I mean, many years ago, IBM and, um, you know, the, the current CEO did this one, he wasn't the CEO, which is, uh, drove the purchase of Red Hat at that time, you, the at evaluator group, we were all scratching our head at $34 billion and like going, you know, doing the back of the napkin about how long it would take to return the investment on this thing. It's like, it's never gonna happen. I think it was 34 billion, or maybe it was 43, I can't remember one of those two.
It was a Large number was it was, it was a huge Number. Yeah, it was a big number. And this is not that big.
But then again, it's not, you know, complete platform play, but it is a platform play. If you're, what you're talking about is managing across clouds infrastructure code, and, you know, they gave a lot of cred to, um, red Hat, you know, they brought 'em into the, you know, when you have client executives that walk into the CEO and CIO kind of capability, you're, you're kind of walking in Red Hat, right? Um, and, and so there's, I think there would be some similarities in terms of the go to market on this one, or is this just gonna get rolled into the I IBM m stuff as opposed to what happened?
Well, I think a lot of people are hoping it doesn't get rolled, rolled into, you know, uh, an IBM only story. Um, it's really valuable for IBM to be part of a, of a bigger story. Uh, uh, the CIOs really want their IT to work with all the re the rest of their it, they don't want these silos in their organizations.
So it's really from a standpoint that, uh, HashiCorp provides, uh, IBM with credibility across clouds. That's, that's a great story, and that's one that they should keep. They shouldn't mess with that.
Uh, and I hope that they don't. Um, but the IBM of old would've, you know, this is something they, they may not have really focused on preserving, but the current IBM, uh, and, and they're very much on the upw, people have almost written IBM off, they are back, there's no question about it. And if they can do with HashiCorp what they did with Red Hat, this is gonna be, uh, gonna do really well for them even at this price.
So we won't have Red Hat Summit now, we'll have the Red Hat plus HashiCorp event or something. Yeah, I'm, I'm really excited to see what the IBM cloud folks do with this, because, you know, we don't talk about IBM Cloud enough. The IBM Cloud does an amazing job working with some of the other hyperscalers to augment your capabilities of running some of your traditional workloads in public clouds in a way that enterprises accept.
And that's one of HashiCorp's original stories was how do I take my mainframe app, modernize it, and have a connector, this is what console did have a connector from my new world applications into my mainframe applications, and then run that in the cloud like operating model. So this is, uh, you know, the IBM will be able to expose some of the more interesting capabilities on the enterprise side of a Hashi Corp. Yeah.
Well, we'll, we'll see where this plan pans out. So thank you very much guys, and thank you for, uh, listening in. I think we got everything covered here and we're gonna do today.
Did I miss anything? No, No. We, we, that was a sweet, Okay, there it is.
That's a wrap, guys, and we will see you next week. Don't forget to like, follow, share all that stuff, because you know what, even the guy that does is in the background, that's doing all the video work is now listening to our infrastructure matters. And that's really cool.
Have a good day. Thanks everyone. Hi everyone.
It is an honor to be here today. My name is Caroline Wong, and I'm currently a director of cybersecurity at Teradata. Throughout my nearly two decade journey in this field, I've had the privilege of working across so many domains from GRC to software security to product innovation.
Now at Teradata, my focus is on ensuring the resilience of our systems and safeguarding the sensitive data that fuels transformative insights for organizations worldwide. My career has taken me through roles at leading companies like eBay, Zynga, Symantec, and Cobalt, where I've built and scaled security programs, led global teams and championed innovative approaches to cybersecurity challenges. I'm passionate about translating complex security concepts into actionable strategies.
This is reflected in my book Security Metrics of Beginner's Guide, which was inducted into the cybersecurity Canon Hall of Fame, and my work as a LinkedIn learning instructor, where I empower professionals with the skills to navigate the rapidly evolving security landscape. Today, I'm super excited to share my thoughts on cybersecurity and AI predictions for 2025, drawing on lessons that I've learned from both successes and challenges throughout my career. Let's explore how we can continue to innovate and adapt to stay ahead in this always changing field.
Let's dive in. Prediction number one. This was kind of a bummer, but I really think that in 2025, humans are gonna end up doing 40% of the work that AI is supposed to do.
AI is often marketed as a magical solution, capable of replacing human effort entirely. But in practice, the story's a little bit different. Real world implementation often falls short because of challenges like poor data, quality, integration issues, and specific domain complexities.
Even when AI does provide great insights and recommendations, it faces what is called the last mile problem. AI does an okay job at analysis and prediction, but it takes human validation, interpretation, and action to bridge the gap between analysis and actual impactful results. I think that unfortunately in 2024, there's been so much investment in ai, and AI is really expected to do so much.
I think in 2025, those expectations are gonna fall short. Organizations really should continue to rely on humans to oversee AI decisions, especially in high stakes areas like healthcare, finance, cybersecurity, where trust is key. Sadly, AI isn't perfect.
It can't self-diagnose bias, it can't correct unexpected behavior. And human invention is gonna be absolutely needed to monitor those outputs, catch errors, and make sure that the systems work as they are intended. It would be nice to have full automation in some business processes, but building AI systems that are actually capable of end-to-end automation requires extraordinary resources, time, money, and expertise.
And even then, results are falling short when it comes to dynamic unpredictable scenarios. Another broader societal implication is that I think that there are gonna be workers and even organizations that resist full automation in order to preserve jobs, in order to support historical cultural practices. Um, and even when AI works really well, people are still gonna want some human assurance.
Um, whether we're talking about customer facing rules or business critical decisions, fairness and accuracy and increasingly empathy are still going to be much more trusted when humans are involved. So this prediction is a little bit of a bummer, but the next one is really exciting because I think that in 2025, kids are gonna use AI to solve real world problems. So AI isn't just transforming industries, it's empowering young minds to think bigger and achieve more than we ever imagined.
It starts with the democratization of tools. AI technologies like fat, GPT, image generators, and coding assistance are now accessible to kids. These tools break down barriers and allow children to experiment with ideas and create solutions that before might have required months or even year or of experience or specialized knowledge.
Today's kids are not just dreaming about the future, they're actually building it. They're going to use AI to develop games and applications. They're also gonna use it to address environmental issues and tackle community challenges like waste management or energy efficiency.
AI is really fun for kids. It brings STEM education to life in remarkable ways. Instead of learning abstract concepts in isolation, kids can use AI to engage with hands-on application.
Imagine a middle schooler training a model to analyze air quality or developing a chat bot to support mental health in their local community. Programs like AI for kids are fostering this practical engagement, encouraging students to take on global challenges like climate change and healthcare accessibility. What makes this even more exciting is that kids see the world differently.
They have so much curiosity and creativity when it comes to finding unconventional solutions. Older generations may have labeled some things as insurmountable, but kids don't think that way. And thanks to the internet and computing, they're not as limited by geography.
So kids from different regions and backgrounds can collaborate virtually to adjust shared challenges like access to clean water or improving education equity. So kids are really the future of problem solving, and AI is gonna play a big role here. The next prediction is a strange one.
I predict that in 2025, 80% of single people between the ages of 18 and 58 will have an AI, boyfriend or girlfriend. So what makes AI companions so compelling is their adaptability and AI companions are coming up in popularity at an exact time when human loneliness and isolation is more pervasive than it ever was before. And AI companion can be customizable.
They can learn from a user's preference, they can create deeply personal and tailored interactions. At this point in time, each of us actually interacts with so many of our real human relationships via technology. And so if a person's talking to an AI companion, you can actually develop feelings as if the AI understands you in ways that other people might not.
This is really just the next stage and a broad cultural shift that's been happening over the past couple of decades. It is in addition to the way that online dating and social media have already reshaped the way that we operate and think about our actual relationships. AI relationships are going to become a natural extension as that for many people, the emotional and the psychological bond with an AI partner is going to feel just as real as one with a human being.
The line between a virtual and a real relationship is blurring, and it also gives us cause to rethink what intimacy and connection, uh, truly mean. Recently at the World Health Organization recognized loneliness as a global health crisis. And so for some of those folks feeling really isolated, an AI partner could actually provide emotional scaffolding that they need in order to feel seen and valued and supported.
Of course, there will be challenges. It's gonna be weird if somebody feels like they like their AI relationship more than their traditional real life partnership. It's also gonna shift societal expectations about love and about intimacy.
There are ethical considerations. What happens to humans? If we begin to depend too heavily on AI for emotional support?
How is that gonna stop us growing as individuals? How is that gonna prohibit us from forming meaningful actual human relationships? As AI companions become increasingly realistic, there's gonna be questions that need to be answered about things like consent, manipulation, and the authenticity of those emotional bonds.
Ideally, I think that there's a future that's possible where AI doesn't replace human connection, but actually enhance, enhances it. Maybe AI can help to teach us how to be stronger communicators and more empathetic partners. That's AI and, and artificial boyfriends and girlfriends, uh, which is a weird one.
And it actually, it, it kind of leads nicely into the next prediction, which is that I predict that impersonation attacks will increase by 500%. Now, this is a very dramatic rise, and I think that this is actually pretty conservative because AI is becoming a force multiplier for cyber criminals. AI is revolutionizing your basic phishing attacks.
They are becoming hyper-personalized. Attackers can use tools to do things like get information off of your social media, your LinkedIn, your Facebook, your public posts on online forums, and they can use that information in combination with AI to generate emails and messages that are so tailored to your actual life. They can reference your kids' school.
They can reference where you went on vacation recently. They can reference your recent project at work, and this is gonna help them bypass any initial suspicion. AI also provides attackers with an entirely different level of scale and speed.
For years now, we've had voice and video deep fakes that have been so realistic, they could pretend to be your boss calling you with an urgent request. CEO fraud is already a billion dollar problem, and it's gonna be increasingly challenging to tell the difference between a real request and an impersonation attempt. One of the things about chatbots and large language models in particular, is that in the past, hackers were often limited by their knowledge and ability to use, uh, the native language of their victims.
But today, AI generated content can be made so linguistically accurate, and it can often be indistinguishable from human created messages. Um, one of the big takeaways here is to watch out what you're posting on social media. Just keep in mind that that is information that attackers can use in order to personalize spear phishing campaigns.
This, of course, is not just a technical challenge more than anything, it's a psychological one. AI can model human behavior, and for decades, hackers have been exploiting human emotions like fear, urgency, and curiosity to push their victims into making quick decisions. Um, and now attackers can really target their campaigns, um, identifying specific, specific victims, uh, based on their demographics, their profession, um, and their interests.
The next topic that I wanna share has to do with hacktivism. I predict that in 2025, hacktivists will intentionally introduce bias into mainstream AI models. So fundamentally, the way that AI learns is from patterns in the data that it's trained on.
And so if that data is biased, whether it's intentional or not, the AI will reflect and even amplify those biases. Imagine a scenario where someone is feeding an AI system, hiring data where men were historically favored for leadership roles. The AI upon observing this pattern could perpetuate it inadvertently reinforcing inequality bias and ai.
There's, it's just there. It's there. And now it's not only a byproduct, it's a vulnerability.
Activists can intentionally introduce bias into models because these folks, they're driven by ideology, they're driven by the desire to exploit weaknesses, and this is a way for them to advance their agenda or to make symbolic statements. Already, there seems to be confusion sometimes as to whether or not something you look up on the internet is fact or potentially fiction. Similarly, there are gonna be plenty of people who assume that AI always tells the truth.
And so if hacktivists or other groups are going to be biasing the data in a way so that they're advancing their agendas, um, it could create chaos. It could undermine public trust. It could actually change the way that people think about facts.
There are few different ways that this could happen. One method is via data poisoning attacks. So hacktivists can infiltrate the data sets that are used to train the AI models subtly altering them to introduce skewed or harmful or otherwise inaccurate biases.
For example, imagine a hacktivist decides to corrupt a dataset that's used for credit scoring that could lead to unfair lending practices, which might disproportionately affect certain groups. Another approach is to fine tune exploits. So many AI applications used pre-trained models, and these can be accessed and altered by attackers.
Hacktivists may be able to tweak parameters and therefore embed biases that affect everything from hiring algorithms to search engine results. And then we've got prompt injection. Uh, this tactic targets generative AI systems in particular.
So by crafting specific inputs, activists can corrupt outputs in real time, spreading biased, misleading, or harmful content instantly. Finally, I think this might actually be my second to last prediction, so I've gotta, I've gotta move it along a little bit. Uh, this prediction is that in 2025, sensitive input to a chat bot is going to be breached.
Chat bots are becoming ubiquitous. They're handling everything from customer support to personal financial advice, and every day people type sensitive information into chatbots. These might include personal identifiers, possibly financial details, almost certainly secret intellectual property.
And this information is very interesting to attackers. This is unintentional data leakage. We don't know about the safeguards of most of the chatbots today.
We don't know if they're using end-to-end encryption. We don't know if they're using secure storage practices. Users have a tendency to overtrust ai.
People see chat bots as helpful, as neutral, and that makes humans a little bit more likely to overshare. The consequences of a breach like this could be devastating. And next prediction, possibly a last prediction.
I predict that in 2025, there's gonna be an AI leader who's going to emerge, and they're gonna demonstrate awesome transparency and explainability. So what does that mean? Imagine an AI system that doesn't just spit out outputs, but it actually tells you how it arrived at those outputs, providing a clear roadmap, breaking down the logic, the data which was used, the weight of each factor in the decision-making process.
Transparency could allow users to know what data gets fed into a system, how that data is processed, and even what potential biases were detected. And then corrected. Explainability takes this even further.
There is increasing demand for both transparency as well as explainability. There are different stakeholders, governments, businesses, consumers, and they want AI systems that they can trust. Um, I believe that a leader will emerge in 2025, and all others will begin looking to, um, replicate similar transparency and explainability practices As this leader, uh, we're coming to the end of our time, and so I wanna share some exciting news with you.
I'm writing a book, it's gonna be published in 2026, and the book is a deep dive into how artificial intelligence is reshaping cybersecurity resilience. So there's two sides to this topic. One side is, how is AI being weaponized by cyber criminals to launch increasingly sophisticated attacks?
And how can AI be used as a powerful tool for defenders to build smarter, more adaptive defenses? Um, if you wanna dive into learning more about AI and cybersecurity and you don't feel like waiting until 2026, I encourage you to go and check out my recent course available on LinkedIn Learning. If you follow these steps, you can view the course at no cost.
So find me on LinkedIn, scroll down to my featured posts, select the fifth featured post 1, 2, 3, 4, 5. And that will allow you to view my 15 minute course on AI and application security at no cost. I hope you enjoy, I hope your new year is off to a fantastic start.
And thank you so much for joining me today. Hi everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech.
I'm Jody Ashley, executive producer here at Techstrong, here with my co-host Tracy Reagan, creator and CEO of Deploy Hub. And in her spare time, she does a lot of work with the Linux Foundation. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Techstrong.
com. Be sure to go check it out. I'm launching a series to go along with it on texturing TV with webinars and, um, biweekly episodes.
So you definitely wanna tune into that. We're gonna, we're getting that rolling in the next, uh, two or three weeks, so it should be ready for you when, after you see this episode. Uh, we have virtual events coming up.
We're gonna be at CubeCon in London, come, uh, April. So if you're around, be sure and check in and say hi. And if you're interested in doing an interview, reach out to Text Strong and, and we can hook you up with that.
com, and be sure to tune in every day to Textron TV for all of our great shows and interviews. All right, Tracy, what's on your mind today? Well, I think I would be mistaken not to say that, uh, deep Seek is on my mind.
Uh, and in particular, you know, if it's true what they're saying about Deep Seek, and they have a, they, you know, they have a different way of building these models, and couple of university students with $6 million was able to do it. Um, we won't talk about, you know, the, the, um, the, the, the funding that went behind them, and if they shorted, um, Nvidia, that's a, you know, an interesting topic. But the, the, the really, I think the lesson learned here is we're always disrupted, right?
We're constantly being disrupted. And in this case, if what they're saying is true, um, it proves that our current VC model and our funding model for companies is not working in the us. Uh, SoftBank just announced there and talks with OpenAI to do a $40 billion round for OpenAI, which means that there's a lot of money not going to other smaller companies that might be able to disrupt open ai.
Now, I understand that they're in there to make money and they're trying to build up the biggest company that they possibly can. But funding is a, a limited resource. It, it's not infinite, right?
It's not, there's not just this infinite amount of money, um, that's coming through the channels that people can get. When 40 billion goes into one company, it's at the risk of maybe losing out on a company that's small, that may have a great idea and that may be able to build something better. Uh, and not always, you know, spend a whole lot of money doing it.
I mean, $40 billion is a huge chunk of cash. So I, I have to use the term, the democratization of VCs, right? If we're not looking and we're not, if we're not really doing the research that we need to do, and we're just saying we wanna put as much money behind the guy that we think is gonna make it work, I think we're missing out.
So that's my thought today, and it makes me sad. Yeah, it's been a big topic, I think, and I think it's brought, been brought up on every episode of Textron Gang this week. So it's, uh, it's definitely a big deal.
Sorry. Um, well, I am excited to introduce our guest today, um, Carolyn Nash. Carolyn, tell us a little bit about yourself.
Hey Ladies, thank you so much for having me today. Um, so my name is Carolyn Nash. I am the Chief Operating Officer at Red Hat, and I know you two are big fans of the Open Source World Open.
So, um, you know, excited to be here. Um, and, and part of Red Hat, you know, which is, which is really founded on open source principles. We, we develop, and we, and we, uh, support open source software that fuels, I think it is 90% of Fortune 500 companies.
So, um, at any rate, it's a pleasure. Just a little bit of it out there, right? So, Carolyn, I really wanna first start this question off, you know, what are your thoughts about the, the potential of deep seek and is it really going to disrupt what we thought we had a future in building these massive AI data centers, you know, where, you know, from a, you know, from a personal point of view, not from a Red Hat point of view, where do you think this thing's going?
You know, is this just really gonna disrupt how we see AI and demystify it? Yeah, it's, it's a great question and I, I mean, I have be honest, I feel like every couple of weeks or something that that is like, we didn't see that coming. I mean, right?
Like, AI is changing at the speed of light, and what we knew a month ago is different from what we knew six months ago is different from what we knew a year ago. So Lord knows where this is gonna take us. Um, but it is disruptive.
Um, I think there's no question about it, but I think it's more of a question of what do we, um, you know, companies in the United States, other companies do about it? And does that fuel a new, I mean, I loved your point about VCs, right? Like, does that fuel a new app?
Like, don't rest on our laurels with ai. We have to continue to innovate and continue to think about how we can do this, and we can do this energy efficient, we can do this cheaper, we can do this faster. And, uh, but it, it, it will disrupt.
But I, uh, believe, and I'm gonna take the optimistic, uh, stance on this, that, that, uh, that our companies are going to react and, uh, and come out even stronger in the end. Well, let's hope that is the case, is, you know, and now let's talk about it from a OpenShift perspective. Mm-hmm.
How is OpenShift adapting to these AI models, and how are, what are, what are you seeing from your customers in terms of what they're asking for? Yeah. Well, I'll tell you, I'm gonna speak in terms of, uh, uh, open shift's number one customer, and that's me.
Um, so, you know, it's, I think about Red Hat technology. I mean, I run operations, so that's including, you know, including it. And, and we run with every single, every single Red Hat product and, and many of the IBM products, uh, for reference point.
But, um, as I look at it and I look at OpenShift ai, um, we're in a position where u we're using it. We're, we're no different than any other company as we're looking to do things faster, cheaper, um, safe safely. And so with OpenShift and OpenShift ai, we're building, um, models and we're using them to change the way we run our business internally and how we support our customers as well.
And we're not only, you know, using LLMs of course, but we're taking on something that's looking at smaller LLMs. And so basically we're taking them and creating a number of smaller LLMs that are really fit for purpose for what we're trying to use internally. And that is all powered on OpenShift.
And, uh, and the benefit of that is it really does address things in a faster, cheaper way. You're, you have to use less energy, you have to use less power, less GPUs in order to tap into these, these smaller models. And that's exactly what we're talking about with our customers.
'cause again, we're, we're sort of our, our, our customer in a zero, we call it our Red Hat on Red Hat. And, you know, from a, uh, from a security perspective on LLMs, I always felt that having those smaller models and having do models that have domain expertise, and if you can build a multi, uh, a a, what do they call a multimodal LLM system where those are passing information to them, there's, it is almost a way to encapsulate it and, and protect it better, right? There's a better, it is easier to do security around a small LLM than a, you know, I don't know, a 40 billion parameter LLMI don't know what they're up to, but Yeah, exactly.
That's so huge. Yeah, That's exactly it. And you think about, like, so say like, let's talk about like internal support for any given company.
You know, if you have something that's going in and, and you need whatever, I'm an employee and I'm trying to get some HR information on myself, right? If you think about safety and security and personal information, um, you wanna make sure you have a small, large language model that's really focused more on those, you know, HR type of topics as opposed to, and gets routed to the, they ask ar you know, ask hr, um, uh, support desk rather than being routed over to help me understand this customer contract and the terms and conditions on this one. And so it, it, it not only makes it work more efficiently, but it protects our data better.
And, and with the regulations and, and so much that we have to protect, it absolutely is a safety mechanism for us. Kind of interesting that we, and at the same time that we're talking about building Kubernetes decoupled architectures and getting away from the monolith we, in ai, it's all monolithic. Oops, are we, you know, sometimes I think that we don't listen to ourselves with what we're saying.
So I think it's, I think that model will be more interesting for enterprises to have small LLMs. Yeah. Yeah.
But then we have a lot of agents, aren't we? Like, you know, I'm, I do not like the idea of agents because I think it complicates the stack quite a bit. And I understand that maybe we can't do it any other way, but there are other agents in the stack that we may not need.
And I feel like there's quite a few, there's quite a bit being thrown into production, even to do security scanning, opening up a container in production to see what open source packages were used, maybe some of that we can start scaling back on and pulling from the, you know, from where it was created at the DevOps pipeline and start building more intelligence into that and have a DevOps LLM. Why not? Right?
I love it. I love that concept. Yeah.
We do have to scale back too, because you mean, you think of it, it's, um, you know, you can build and build and build and build, um, but if we're not using everything we're building as well, I mean, we gotta do a little bit of cleaning, like cleaning out your garage, right? Like every now and then, you gotta go in and you gotta pull everything out, figure out what you're not using, what you don't need anymore, and then put it back into the garage, all organized and, uh, available for greater use. And you know what, it takes companies so long to do that, and they fight it and they struggle with doing it.
It's like, talk about hoarding mentality. Yeah. And, and it throws, you know, it creates just this great discussion around governance as well.
And, uh, yeah, because everybody is excited. Everybody wants to try these things. Everybody wants to do these things, but the more you create, the more, uh, how do, how are we making sure that as we're building and creating, that the experiments that don't work and that we don't want to continue with are actually getting edited back and removed.
Um, and it's just, you know, it's almost like in way it's governance, portfolio management, whatever you wanna call it, but making sure that, um, we're doing that in the right way. Yeah. I don't think we figured that out yet, especially around security and at all.
You know, we have sas, we have das, but we still have vulnerabilities that make it to production and we're not remediating them very fast. The whole idea of chaos engineering and being able to respond to this, uh, to, to respond to a problem or vulnerabilities, I think it has been underserved and needs to get more attention because it's not really about, you know, root cause analysis all the time. And especially as we start doing more AI work and we haven't figured out how to secure that.
We just gotta get really fast at fixing things. Yep. You can't prevent vulnerabilities, but you sure can react to them very quickly and, uh, and respond to them, uh, quickly and, and, and, and safely before, um, you know, damage is done.
Yeah. I don't think I talked to our customers. I'm, I'm in the Boston office where our executive briefing center ist, and I'm talking to various customers, security is one of those top things.
I mean, cost and efficiency and all of that has always been a topic, but security is, is more often than not something that really has to, you know, they wanna, they wanna discuss and they wanna find out what options they have. Well, and what I think is interesting is just in the last few years, there was, there was a lot of push and pull. Um, we do a lot of security stuff here, and I would hear these conversations that people would literally argue about, but we should be able to prevent everything.
And then everyone else was like, no, we can't prevent everything we've got. We've gotta be prepared and we've gotta be agile and be able to work through it quickly. And I've seen that we can prepare for everything, just kind of disappear pretty quickly, especially as the AI has kicked in.
Um, 'cause that's a tool that helps you respond really quickly, right? Faster than ever before. But that argument is definitely kind of moved away.
We, yeah, No, It's just not possible. It's Not, it's not, it's not possible. It's not you, you can't, you just have to be prepared to react is is what it is.
And, you know, And I feel like there's a culture of complacency. Um, so for example, uh, deep seek gets released and then Wizz goes and says, Hey, we can see that, you know, a ton of data has been exposed. Um, but does anybody care anymore?
Does do they, do people really care? There was even an article I read, um, I think it was maybe it been the Navy or the Army that basically said, yeah, we know we should be watching for vulnerabilities, but if we need to get something out, we need to get it out. And I'll take the risk even if I don't understand what that risk is.
But it's a, it's a statement to say we're not doing, we're not serving the community in, in terms of security. We haven't figured it out yet. And the worst part, the worst part of all this is my opinion is we need investment to get it done.
But when you have $40 billion going to OpenAI, there's not gonna be a lot of investment in security or cybersecurity in any way because we've become complacent. Yeah, it's so true. And I, and I really appreciate your point about taking risks, because I think this is the, the, the balancing, you know, that we everybody's trying to do is how do you innovate at a crazy fast pace, but do it safely and take some risks, but take the right amount of risks in an area that is completely, you know, new to, to so many.
And, uh, and, and you know, I think again, in internally even things we'd, we've created a policy like every company has, right? Everybody has their AI policy, but it's like version, I don't know what five or six right now, because we have to keep changing it. Like, oh no, we, we over rotated and now we're saying no to everybody.
Well, no, that's not the right approach, right? And so then you're trying to tweak it, but, um, you really, you, you really don't know, but you also have to take risks. And, um, but just knowing, knowing where to, to place that risk pendulum is, is really the important point there.
I think it's interesting though, how quickly companies, nations have responded to Deep Sea. Like, we've let all this AI come and everyone's like, should we be worried? Should we not?
Months and months go by. I mean, this week, Italy, bandit, Ireland, bandit, Congress, bandit, everybody from the government, from downloading it. Um, you know, I think I'm, I'm just interested in, you wonder now if we're just, we flew to the other end of the extreme, but I'd rather see the other end of the extreme.
Like Tracy was talking about all this vulnerabilities that people immediately noticed. Um, I thought, I just thought it was interesting. Every, every couple hours I'm hearing another company or another Com country that says, we're banning it for now.
We'll see how long that lasts. But I just think the response has been, I know, but I think the response has been really quick. Really quick.
Yeah. Yeah. Well, it's culture right now, and, uh, not following rules, not following policy.
Oh yeah. Taking big risk is where we are in our culture, so that's where we find ourselves. However, talking about taking big risk, you know, I was looking through your resume and you've made some big jumps in your career.
I sure have. How did you do that? Talk to us a little bit about, you know, your background, how you, you know, climbed the ladder to become the COO of Red Hat.
That's an impressive job. And it's great to see a woman in that role, right? Because it's taken a long time for us to get women in C-level positions.
Yeah. Well, thank you. Thank you for that.
Sure. So, you know, it's, um, I mean, I started my career quite a while ago, but, um, I, I actually started out in public accounting, so I was, I was an accounting major in college Scratch. I was an engineering major for a bar chapter.
And this, no, I can't, no, pointing is way more up my alley. But at any rate, I, I spent, um, a good bit of time on public accounting, which I absolutely loved, and I think it became a, a great foundation for my career. Um, because I mean, I, public accounting, it sounds really boring, but the reality is, like what you do when you're in audit is you have to understand how data flows through processes, through flows, through systems to ultimately end up as a financial statement.
So it, it actually is an incredible foundation for how you learn about how companies make money and build assets. Um, but at any rate, I went into, um, into finance and, um, after I left public accounting, and I was living in Silicon Valley at the time, and so thought tech has got to be the place I go. I wouldn't go anywhere else if I'm living in Silicon Valley.
And so, um, got into finance there and how I actually pivoted out of, of finance was when I was starting a family. And I have, um, I have twins, uh, they're now adult, but, uh, at, at the time I really wanted to continue working, but I needed some more flexibility. So I went part-time and I talked to my boss about it and he agreed that like, you know, the, the finance and accounting doesn't really offer you that much flexibility.
At least it didn't at the time in the role I was in. So he flipped me into more of an operational role, more projects, things like that. Um, that gave me a ton of flexibility, allowed me to raise my children, and, uh, but also gave me this great experience and exposure to the intersection between finance, between it, between the business.
And I really just loved playing in that space, kind of building on all that old public accounting days, but, um, building in that space. And really from there, it just opened up my eyes to so many more possibilities beyond the track I was originally on. Um, I got into data and analytics.
I got into sales operations, um, and played it. That's Where I saw the risk. I mean, you went from hp, I think you went from, wait, you went from hp?
Yeah. KPMG to hp to Cisco, To Cisco in sales operations. Yeah.
I started That's Very different than public accounting. Okay. Very different.
And see, maybe I'm wrong. Absolutely, absolutely. Still got the dollar signs though.
Yeah, yeah. No, it would, my time at Cisco was a wild ride. I mean, uh, Cisco is a great environment to really, they, they allow you, they encourage you to bounce around and try new things and continue to push yourself outta your comfort zone.
I actually had a fantastic boss at Cisco and his point was always Carolyn, when you start to get comfortable in a role, like if you start to come into that little circle of comfort, it's time for you to go look for something new. Go take on a new project, just ask for more scope. Get something, never get in your comfort zone and never be complacent about your, your, your growth journey.
Um, always be learning and growing and being just at a minimum, minimum mildly uncomfortable. And so it was really at Cisco where I took a, a tremendous amount of risk in, in leaving finance, yeah. Sales, operations, data and analytics, business services.
And, uh, and that I think gave me the confidence when I came, you know, I took a, um, I that gave me the confidence to leave Cisco after 16 years and go to Red Hat. And I thought, this isn't gonna be a new type of company. Something that I was really passionate about.
I mean, 'cause Red Hat's such a cool company, you know, built upon the whole open source communities and development model. It's also an open source culture for me is just been a blast. And, and it's also a company that really encourages you, just helps you open up those opportunities.
And that's where I actually bounced back into finance, believe it or not. And, um, and, and grew my career in finance back up and to become CCFO. And then at that point there was some leadership turnover.
And my, my boss at the time had asked me to take on it and security and a whole other things. I'm like, sure. Right.
Again, you don't wanna get comfortable. And I can't say, since I've been at Red Hat I've ever been in my comfort zone, it's been always right on that outside of comfort, which is how I know I'm at a, a great place. So, um, so I, my, you know, my role as COO, you know, I paused at first, right?
As many of these things, like you got the little, I mean, who doesn't have the imposter syndrome? The little person sitting on your shoulder, talking in your ear like, no, Carolyn, you're not technical enough for it. Well, you know what?
I don't need to be technical enough for it. I need to be a great leader who can build super smart people around me who are willing to explain things to me, teach me, um, allow me to ask the right questions and dig into an appro appropriate amount of detail to make sure that I'm driving the business forward in an aggressive and, and also safe way. So yeah, You need to do a Ted Talk and you need to write a book, honey, man.
No kidding. No, it's, you're inspiring to me because it's just, it's just amazing, like your energy and, and just the way your brain works. It sounds like you've had some really great mentorship and bosses along the way that have really supported, like, gosh, we don't hear the, they supported me through raising twins story a lot.
No, We don't. I mean, I could go into a lot more, but I, I mean, I've had some exceptional mentors, sponsors, bosses, and not only had they, um, got me through my early years with my twins and, um, but in addition, uh, I mean, my current boss is amazing. He helped get me through the loss of my husband.
My husband passed away two years in the midst of a lot of leadership changes here. And, um, and just really, uh, yeah, I'm, I'm still here and I'm still charging forward. And it got me through one of the most diff the most difficult time in my life.
Um, and it allowed me the space to do what I needed to do and, uh, but also welcomed me back and brought me back up. So I, I am really grateful for my leadership and my, my people, my tribe, um, my, my personal board of directors who have I feel like have surrounded me, you know? And that's, um, yeah, it's really, uh, it, it, you know, I'm like, oh, I'm getting emotional.
Ah, what abl really like to have great people around you is that's why I have my energy, because I have great people, um, ar around me and, you know, and Carolyn, I'm so sorry to hear you went through that. Thank God you have the entourage around you to help you. We all need that.
We really do. Thank you. Thank you.
I really appreciate that. And, um, you know, and, and, you know, 35 years and most of that in tech, being a female is also, you know, quite a journey as well. And again, I, I feel myself lucky that I've had, uh, you know, a amazing female sponsors around me, amazing male sponsors around me, people who, um, you know, who have just pushed me and, and flick that little imposter off my shoulder.
And, uh, and I also think I've been, uh, I'll, I'll pat myself on the back to say that I think I choose my companies and my bosses very wisely. And, uh, my choices along the way, and most recently being at Red Hat has been, uh, you know, one of the best decisions, career decisions I've made. I love the open source community.
I'm sure it is amazing place to be a company that it's o an OA company built on open source like Red Hat. You know, I'm, I'm a big open source band. That's why in my, in intro, it's always, Tracy does a lot with the Linux Foundation.
Uh, but boy, open source has taken a beating recently. You know, we're getting blamed for a lot of security issues, which probably is correct. But, um, we've known this for quite some time, right?
And maybe it's open source that's gonna get us out of this problem. Um, but I feel like there's a lot of stuff being written and we're not doing much with it. Adoption of these security tools and for open source will be a challenge.
Um, how do you guys talk to your community about, about security? How do you navigate that? Yeah, uh, I mean, it's a, it's a very important thing.
But you know, the thing with, with Red Hat is, you know, when you think about the op open source and, and we, you know, we live and breathe and, and the open source, but it actually creates, I mean, our whole open source development model is taking these projects in the community, but bringing them and hardening them into enterprise supported products. And, um, and that's part of the beauty of it. I mean, when there have been some of the bigger, larger vulnerabilities out, um, red Hat's been one of the first ones, and the Red Hat and the Red Hat community has been the first ones to raise their hand and say, we've identified it and we figured it out.
Because I think that is the power of open source as you are not only in a enterprise grade hardened product, but you have access to the community, um, that has that, that is using it along the way. So, I mean, I think it's a benefit. I mean, I'm, I, I, I for sure have been, um, living and breathing it.
And, and I, I also, you know, going back to the culture piece of it, I believe, you know, you can talk even more generically about security, and you can talk about security in the enterprise from a non-technical standpoint. And I believe the open source, um, culture really starts to weed out these things as well. You know, when you are taking ideas and inputs from all different places, you're also getting people to raise their hand to say, I have a concern.
And like at Red Hat, even internally, we have company-wide mailing lists where people frequently debate and discuss different topics, controversial topics, but they, things that bubble up that, like we as a leadership team, we're always monitoring it because some of the really like, woo, okay, that's an interesting idea, or that's a really valid concern, or we might need to dig into that a little bit more. That's open source too. And that's kind of the same, you know, you talked about in your personal journey, being able to, to take a risk and staying, staying outside of a comfort zone or just staying just a slightly outside of that comfort zone circle.
Um, companies are doing that with open source, right? There's, they may have, it may be pushing them a little bit, but I'm hoping where it pushes them, they can't get away with writing software without open source that, you know, that cat's out of the bag, it's not gonna happen. It would take a lot of coding.
It would take a lot of work, and they wouldn't be able to keep up on the, what, what's new in AI without it. So how do we as an open source community, make them feel okay about continuing to step out of that circle of comfort saying, okay, I'm only gonna use these particular packages, I'm not gonna try to use anymore. I know these are secured.
Uh, how do we do that? How do we bring open source back into conversation that people don't say, oh, there's a security issue with it from a bi from a broad community perspective. I know it's a big question, but Yeah.
From a, I know, and I immediately go into it was just buy a red hat, come on. I like, no, I know you're trying to go broad on me. Um, but that, I mean, but I think that is, it is understanding what is it that you're using it for?
And is, are you accepting a level of risk in the open source, um, in the open source community that you are comfortable with? What is, you know, a small startup company is different from a governmental agency or a banking, I mean, I, I think it depends on where you are in the continuum, but, but if you're one of these larger companies that trying to stay, um, and keep yourself more secure than maybe your mom and P'S need to be, that is where you need to still embrace the open source, but make sure it is enterprise wide grade, uh, open source, and that it's, it's hardened and has the security that you need necessary to make your regulators comfortable, to make the good, the various agencies comfortable. Um, but but open source is, um, we've proven that it is secure.
Absolutely. And I, you know, I think more and more, um, some of the tooling that is being developed, open source tooling, by the way that's being developed will, will help solve this problem. Um, and I'm hoping that, uh, we start embracing more and more through the DevOps, uh, you know, pipeline, adding more tooling and consuming the data and getting smart about it, because I love open source and I would hate to see it go away, even though I don't think it's going away in any more than the mainframe ever went away.
And there's legacy open source out there, and there's new being written every single day. And we have to be outside of our comfort zone and start and consume it, because that's the only way we're gonna really build, um, innovation in this country is to accept it. Mm-hmm.
Right. It's just, I mean, it's, it's tied right there with ai. I mean, open source AI is, is an incredibly powerful tool.
It is incredibly powerful. That's just gonna unlock a ton of innovation, I think, unlike anything that we have seen before. What do they say?
This is, this is gonna unlock more than, than, you know, the invention of electricity. Uh, it really will. But, uh, I think, I believe that AI powered through open source is just gonna be exponential.
I would agree. And it's way beyond our comfort zone right now. It is so beyond it, but we have to go there, right?
We, we really do have to go there. Yeah. And, and we have to, I mean, go beyond the, you know, what's gonna happen in six months.
You don't, I mean, you just have to keep pushing the boundaries and pushing the boundaries and, and, and doing what's, what's, uh, you know what I was gonna say, what you're comfortable with, not what you're not comfortable with. But, but you, you can't, you can't, you no longer can do a year long roadmap. A roadmap doesn't make any sense here.
It's gotta be just fast innovation, iteration and learning. And again, I don't wanna, I don't wanna lose sight of the governance component of this, um, because it is, um, it, it, something left unchecked could be, could be quite scary. So I know we're gonna, we probably we're gonna run out of time.
Oh, we're good. We're good. So tell us what's new?
What, what's new and what's, what's happening at Red Hat that we might wanna know about or that you can share with us? Is there, you know, what's exciting? You don't tell anyone.
Yeah, I won't tell anybody. We wanna know what's exciting at Red Hat that the team is super, super jazzed about. Oh my goodness.
Well, I mean, we were just, I'll tell you, we've been talking about it. I, I think the thing that is coming out of our mouths in every single meeting, in every single investment decision, and every single, you know, just, um, interaction we have is, is around ai. And it is how do we, you know, bring our customers to the next level?
And again, I'm looking at how do we bring ourselves to the next level, uh, but, but doing so in a way that, you know, other companies just haven't thought of. I mean, we had just had something really cool, uh, a couple of months ago. We were looking at some of our models and, um, some of our LLMs and we actually had, uh, somebody from our team go and load up inclusive language, um, standards into our LLMs, right?
And so you think about things like that, um, how just all of a sudden now, you know, something that we were a little bit nervous with about ai, now you load up into those standards, this is inclusive language and, and all of a sudden it just changes the game a little bit. Um, the other thing that I think is really cool is just skills development. And I think a lot about people and, uh, and where are we gonna go?
And we talked about, we don't even know what's gonna happen in two months, right? Six months a year. Well, we have to assume that every single role we have will not look the same in two years, in three years.
So a lot of people talk about, well, does that mean these jobs can go away? Well, what we believe is we really have to re-skill for, for these, um, for these shifts that are gonna happen. And so we've been creating a good bit of training curriculum and looking at, okay, what are the roles and the skills that we have today?
What are the roles and the skills that we are going to, we anticipate that we're going to need? And let's take that, create curriculum, create experiences, projects, um, innovation days to help people move along that continuum so that they will be ready when we get there, not if we get there. And I, I just think that's been really cool, something we're really excited about here.
Um, so that, that just does Good, have work with universities. Mm-hmm. Very much so, uh, yeah, it's, um, yeah, we have some local partnerships and, uh, so we work very closely with them.
And, and I mean, our belief is you gotta go get the great university talent. Um, they're getting, you know, uh, not only are we importing talent from the universities, but we're partnering on a lot of projects with them while they're in university. Um, and, and investing in that because, uh, again, that's where the innovation is coming from.
It seems like the university system can be really slow to put together curriculums and get new classes offered. Yeah. Uh, I think that's my biggest frustration with, with some of the students that are coming outta university is that they're, they're somewhat prepared, but they're not prepared for tomorrow.
Yeah. Well, we are, we do, um, you know, we have various internship programs where we bring them in, we give them projects, but we, you know, we give them loose projects because what we're seeing out of these, um, you know, university minds is that they can approach a problem in a very different way than historically we probably would've thought. So we do believe in the practical experience, but you know, we've also been investing into those to make sure that it's not necessarily just a traditional classroom experience for this type of innovation.
Yeah. I think we learned that with Seek versus OpenAI, right. And was a couple of universities, the students had thought about it differently with the less money and they were just motivated.
Yeah. And we're also trying to get, uh, you know, we are, we are partnering with, um, some of the local high schools and middle schools and, and trying to, you know, just ensure that we are, uh, getting the word out on the importance of STEM to, uh, the younger folks. So we, we often host like middle schoolers coming in here and, you know, we'll do a little pitch on what is Red Hat, but what we will talk about a lot is just, um, what STEM roles look like in a high tech company.
And even if maybe you're not, you know, maybe you're not an engineer, well, still there is a career path for you in stem. Um, and we show them what that could look like at a Red Hat. And so we break out into smaller groups.
What does a product manager look like? What does an engineer, what does a software developer look like? So that we're trying to also spark that excitement.
We give them projects to do that excitement, that sense of innovation at the very early age. And, you know, in, in addition to just getting, um, middle schoolers there, um, we, you know, we focus on underserved communities. Uh, we certainly wanna make sure that we're getting our young girls really excited about this and that we don't I was gonna say that reaching out in middle school, that really does help young girls Yeah.
Maybe redefine who they are and how they could participate in a, in a world where they believe it's dominated by men, which it is. I'm not, you know, we're not gonna deny it. Yep, Yep.
It is, it is dominated by men. Um, but, you know, that is, that is shifting and, um, and it is, it's shifting and it's, it's getting better and the environments are becoming more inclusive, and I feel like, you know, voices are being heard. And again, it's one of the, the, the great things that I love about where I am at Red Hat because that is, we, we very much try to create that environment where you can show up as your authentic self and your voice can be heard, and you can use that to push Red Hat forward.
I think men always show up with, with their authentic self. I don't think they know how not to, 'cause they're, they, they've been, they're allowed to. I mean, they don't worry about putting on makeup at 14.
Right. You know, they don't worry about getting facelifts at 55. Right.
They're totally about the, they're worrying about that more and more, more than you think. Well, maybe so, but women all, they're just not as vocal about it. They're not as well, They attack amongst themselves like we do, you know, you don't really know that the Botox is going in and, uh, come on, let's face it.
It's, it's a thing. You See that mahera on there when you Well, you do. I've seen the makeup closely, I think.
Well, and there's a lot of painted nails, which I love. I think it's fun. Um, back to the conversation about job elimination.
I think when we're talking about these kids, especially college age, I think the incorporation of the AI is what's gonna help. But it's also terrifying to these kids that they hear all this, you know, older folks saying, well, AI is gonna take all of our jobs, and then we wanna make sure we're encouraging them and saying, no, it's not, it's just gonna evolve what they look like. We just have to push that.
'cause even my kids, they're in their twenties, early thirties, and, you know, we've had that conversation, is AI gonna eliminate all these jobs of our friends and people we know? And we just keep telling 'em, no, it's just gonna change what they look like. We still need humans.
Yeah. We still need humans and people who understand AI and, and yeah. And I, you know, I have two kids in college and that's something that I, I'm like, you gotta understand digital skills.
You need to understand critical thinking. You need to understand the way the human mind works, right? Like, you need to understand these things because these are the important skills that will be necessary in a world going forward that will have ai, you know, it just, it, it looks different and you've gotta be prepared.
And it's not just a college, it has to be lifelong learning. Um, you have to be keeping yourself up on this all the time. And we all do.
And, and, you know, you just don't think that your growth opportunity is learning in the job that you have today. It's not, I mean, it is totally. Yeah.
Uh, so it's lifelong learning and, and pushing the boundaries of those skills that will always be needed. And we always need good critical thinking. So I'm the one who, who goes off the track here.
Um, before we finish, we've only got a few more minutes, I wanna hear about the Elizabeth Nash Foundation. Oh, Thank you so much for asking Matt. I didn't even see that one.
Um, So, Um, I mentioned I lost my husband, um, and, uh, he had cystic fibrosis. He ended up passing away of something else, but cystic fibrosis. And his sister also had cystic fibrosis and passed away.
And after she passed away back in 2003, we started up a nonprofit, um, foundation aimed at improving the lives of people with cystic fibrosis. And we, we kicked it off originally with, um, scholarships for people, uh, based on, you know, a whole variety of things. But people with cystic fibrosis, we, um, uh, invest in research, specific research for it.
And, um, most recently we're, we're taking an additional amount of scope where we've created, uh, a fellowship program. And what we're trying to do is, there have been so many medical innovations, uh, with cystic fibrosis that fortunately people are living and they're living longer lives. But what's happening is other things are coming up that they're, they're starting to lose their life to other things, but they're also aging.
You know, it's like new aging issues for people with cystic fibrosis that does not look the same as it does in a healthy body. So we've created a fellowship program where we are focusing on addressing the whole person with cystic fibrosis and making sure that as they age, they have the right healthcare and the right culture within the healthcare to make sure their needs are being addressed and they can live a long, healthy, and meaningful life. That's awesome.
That's great. Thank you for sharing that. Um, I appreciate you asking.
It's, uh, it's been a labor of love and I'm really proud of what we've been able to accomplish and, uh, yeah. More, more great things to come. And because you've been through it, you have the insight that's needed to be able to create a map of what can help people.
Yeah, Yeah. You really trying to take the very patient, you know, a, a person first, right. You can start with the medical, or you can start with the, the researcher.
You can start with this, but we're gonna try and start with the patient. Right. Start with the human being first.
It's, it's their experiences that are really driving our work. And from what you've told us today, I think it defines who you are. I think you're very person focused.
Absolutely. Thank you. I try to be.
Okay. So before we get cut off, is there a book recommendation that you can give to our audience? Oh, um, So we have a little book club going on in my team here and, um, the one, so we're just finished up, uh, think Again by Adam Grant, uh, for all your Adam Grant fans.
It's just such a great book. I mean, we talked a lot about taking risks and thinking differently, and, uh, a great book highly recommended if you haven't, haven't read it. Um, the other one by Andrew McAfee.
McAfee is, um, the Geek Way. So that's a really, really good one too. You asked for one, I gave you two, but, but yeah, I give You one for your book Hub.
You have one? Uh, we do, it was a book that I can't remember, one of our guests recommended it, but it's called The Logic of Failure. Oh, Okay.
It is really, really good. It is. Um, one, you know, I read it the, the, I don't remember who gave it to us.
Might have been, might have been. Was it? No, we always need to remember, we always forget.
She said she read it more than once. And you know, I just got it on my phone and I read it pretty quickly and then I was like, I gotta read this again. Because there's so much in it, in how the mind thinks and so many good exam examples of how the logic of failure works.
It's a really good one. But is like, based on the acknowledgement that failure isn't a bad thing, it's a good thing, and that, you know, but how you reactive, there's really, Now it's really, um, how we do, how we make decisions, how emotion can get involved in making decisions, how we don't follow the logic as far as we need to, to understand of successes at the end. Okay.
Okay. Kind of similar to the Geek Way, you know, some, some parallels there about Fastest Making Basket to read a Geek Way though. I'm gonna, I'm gonna read a, I'm gonna download it on Audible and listen to it this afternoon.
Yeah, You'll write it. This is our question at the end of every interview, so we have quite the book list. I should like compile it Tracy and, and write a, write who, who recommended it for us.
But um Sure. Put a blog out there. I love it.
Updated. Yeah, absolutely. Well, thank you so much.
This was just a wonderful, wonderful time. Thank you for Well, I know you're super busy and we appreciate you carving out this time to, to join us and, um, I know our audience is gonna love it. So thank you again for being here.
We really appreciate it. Thank You both. This was, uh, this was a lot of fun.
Great conversation. I really appreciate it. Well, we enjoyed having you.
It's really insightful and everybody remember, stay out of your comfort zone. Exactly. Thanks everybody for tuning into another episode of Techstrong Women.
Stay tuned for lots more great programming on Techstrong tv. We'll see you next time. Thanks.