Techstrong TV November 24, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone, are we in a state of ai high anxiety? I love Mel Brooks. You're watching Text On Gang.
Hi everyone. Happy Monday. Hope you had a great weekend.
You know, it's gonna be a short week for us here at The Gang. It's Thanksgiving week, always one of the nicest weeks of the year for me this year at Little Sweeter, both of my, my sons will be home. It it'll be good to have a, a house with the boys home again, little buffer between me and me, aggravating my wife.
So it's always good to have her, have them home. Um, we have a great gang here for this Monday for you. Let me introduce you to them.
We have Jack Poller, IRA Winkler, Jeff Reich, and joining us after his cameo with Kon Chris Short. Chris, great to have you join, join the gang officially here from the studio. Gentlemen, it, it's great to see you all.
Mike, as usual, we got a lot of AI noise and news and I don't know if it's news or noise or both, but why don't you kick us off? Well, let's jump into this 'cause everybody's closely watching what's happening with AI agents and, uh, AWS would a little help from IDC published a report saying that, well, organizations have deployed on average 10 of these things. Now, they're generally not customer facing, they're a little more on the operational side, but we're all watching this closely because, well, if you look at the NVIDIA numbers, as great as they are, basically it's four companies buying up all the GPUs in anticipation of the fact that, well, we're all gonna use AI agents, we hope, because, well, the first round copilots was interesting, but it's kind of difficult.
The issue now is are we gonna use AI agents and how quickly are we gonna adopt them? And to what extent, because the survey kind of suggests that people will not fully roll these things out. At least half of folks anyway, till 2027.
Some folks are being a little more aggressive than that, but there's a lot riding on this, Alan, it seems like the whole IT industry is making a big bet on this one thing happening. So is it gonna happen and what's your take? You know, I, I did a shi, he says on this last Friday, Mike, I I call it AI jingga.
You pull one block outta this tower and the whole thing comes crashing down. And I think that block is open ai, but you could go watch my shimmy says, or read my article on Textron AI about why I say that. But as as to this survey, I'm gonna call bs, right?
I think the fallacy or the, or the soft white underbelly to this survey and to this report is how we, how do we categorize an agent? To me, an agent is something that goes off and does the does things or autonomously. There's a difference.
I I don't consider copilot necessarily an agent at this point. I think it's, it's more of a chat bot, right? It's more generative than agent.
Yeah. Alan, let me say, because when I read this study, there's a very different, like, you know, my bias that when AI is everything, AI is nothing. And a, an AI agent is one of those, by definition, is an entity pretending to be a person, providing customer support of one thing or another.
Like if I try to get online and talk to Delta Airlines to say, I want to change my flight to, you know, to Tulsa, and they're like, oh, we would love to help you change your flight to Tucson. You know, that's the typical AI agent by definition. Then there is agentic ai.
Agentic AI implies that an a software tool. 'cause at the end of the day, it's just software with certain algorithms and functions that an agentic AI is taking read, making a decision and taking action on its decision autonomously. And that is, you know, that could be, for example, switching a railroad switch as an example.
Now, the problem is, I read the study and I was like, are they using it for help? And you mentioned, for example, copilot. If I type in a question and it's answering, is that an A, you know, an AI agent?
But the problem is, I think we don't have a clear definition, which is number one. And then there's the other aspect. If they are talking about agentic ai, which is completely possible, I think the people survey suck, and I think the people in the survey had no clear definition of what they were answering as well, in my opinion.
And some people might have thought AI agent talking to, replacing a person helping, or there could have been some software tool making a decision, which frankly are many software tools, AI or not. But what are the guardrails? And I didn't see discussions on that, and it's two different conversations either way.
So I'll leave it there for other people to discuss. But that was my concern with the study. I'm, I'm gonna support with a research study that, um, we at IDSA did, um, in the middle of the year, and it wasn't about AI specific, but we had AI questions in there.
And two points I wanna bring out that I don't think have changed since July, which is when we did this, first of all, 11% of, and this is across the board, CEOs, CISOs, security engineers, answering the survey, 11% say we have complete, fully documented and communicated controls around use of AI in our organization, whether it's agen or not, 4% somehow believe they're saying they don't allow AI in their organization. I don't believe them. 56%.
We have some controls in place, but not enough, and we don't really, we can't really control what's going on. I think that's, that's the underbelly we're talking about. That's here.
Even though organizations may be using ai, whether project or not, they're simply using it. It's like they're getting in a car and not knowing how to drive, not knowing what the roads are gonna be or how to make it stop. Well, Jeff, let me expand quickly, but you raised a point though.
They say they're not using it. They are using it. And if they don't know they're using it, they should be fired.
Because ai, and I use this is embedded in every technology out there. If you get in your car, there is an algorithm that is creating a route for you to go somewhere that is theoretically an AI agent of some form or ai. But I, I mean, it's embedded in anti-malware, it's embedded in autocorrect, it's embedded in Siri.
You know, people can say they're not using it, and if they say they're not using it, they should be fired the world according to ira. So, Chris, let me come back to you here for a second. Regardless of, you know, how they define AI agents and, and whatever it may be, the concept is that they are not gonna fully roll this out till 2027 and it's gonna take a little while.
Is that gonna be enough to sustain the investments that we're seeing in AI today? Or is this gonna play out at a, at a much longer curve than people are anticipating? Well, that's very interesting questions.
I think yes and no, right? Like the, the clouds currently have a backlog of customers asking for these, you know, chips that are getting made for Nvidia, but by TSMC and there's only so much capacity. So there's a backlog right now.
And if folks are waiting a year, well, a month to 16 months for their AI projects to come online, well, I think they're gonna miss the boat on some things, right? The technology is evolving way faster than, uh, the traditional enterprise release cycle. So you're either going to be, you know, on a old version of something for longer, or you're going to have to learn to adopt and embrace, you know, rapid release, rapid testing, all of these other things that are, you know, key to innovating and, uh, making the most of your AI tools.
So the, the idea that these big projects are gonna happen and they're not gonna be rolled out to folks for years is concerning from a like supply chain side, because timing everyth, There's Gonna be everything. There's gonna a dip in the market. Mm-hmm.
Then yeah, it would make sense that the dip is now when chips are short. So I would agree with you from the supply chain side, but from the demand side, it's actually, I think 2027 is being very optimistic. You know, I have, uh, a friend who's a sales engineer, lead sales engineer for a, uh, a regional CSP, and they said, well, we have to get into cloud.
So they tasked him with figure, sorry, get into ai. They task him with figuring that out. And so he said, okay, well let's go and buy some machines, stick some GPUs in it, and then it's okay, now what do we do from here?
And everybody right now is very lost. If you, uh, you know, I think, I don't know if I've said this here before, but I've said it plenty of times before that, if you think about what we think, if we task somebody with going out and rolling out a virtualization infrastructure or a container infrastructure, there's a well-known, well understood recipe for how you do that, right? Today, if we task somebody, we're rolling out an AI infrastructure stack, there is no well-known recipe.
It is very hard. There's, it's, and it's not only the hardware infrastructure that's not understood, it's a software infrastructure infrastructure. And how do you get to a point where you can actually then go and put some AI agents out there to do something that's black magic for probably 75% or more of organizations today?
And I don't think that's going solved soon. Yeah, Because no, what I'm saying is that it, well, taking a step further from Jack, it's not the hardware, it's not the software, it's also a data infrastructure because AI is about the, so the making decisions from data and an organization needs, for example, a chief data officer to go ahead and make sure the data is accessible to all the software that needs to pull it to make good decisions. And without a data infrastructure, you're not gonna have any other, the other infrastructures are gonna be worthless.
So, IRA's Ty's point, though, it is entirely possible that some of the folks answering this survey just said, yes, we're using AI agents because they sent out an email to somebody and said, Hey, are we using AI agents? And somebody said, yeah, sure, but then, you know, we just checked the box and said, you know, just tell the boss anything he wants to hear. Right?
Well, But I, I think there's also the difference that IRA pointed out between AI agents and agent ai. They're not necessarily the same. However, here's the thing, I don't know if we're gonna roll our own AG agentic ai, and I think that's the, that's the exponential difference between maybe generative AI and rolling your own LLMs and doing your own training and all of that stuff, versus using someone else's agent in an agent AI way, sort of a Salesforce agent force or ServiceNow agents or any of these agents.
These are pre-rolls, right? For all my friends in states where cannabis is legal, these are pre-rolls, you just light 'em up. You don't have to roll 'em, you don't lick 'em, you don't worry what's in there.
It's already, you know, it's a, it's a, and in many cases they may be rather ephemeral, they may be single use, but persistent, but they, they're limited. They do a job, they do a particular task, and they do it autonomously, but there's not a lot of infrastructure you are going to build into that. Maybe set up an MCP server, something like that.
But I, I don't know if they're going to be building their own stacks here. Is, is I guess what I'm saying. Uh, you know, Jensen Wong spoke about this.
Uh, I, I, I caught it. It was one of these when the Saudi prince was here, and don't even get me started. But anyway, Jensen WG said something about, you know, we're gonna have a whole new class of, of AI apps that use these agents different than the apps and the infrastructure we, we have today with it.
So, you know, when people say, do we have 10 or more AI agents? I do think that's some of the IRA thing in there. Of course we do.
We have that HelpBot for people who want to go from Tucson to Tuscaloosa or whatever. But, um, you know, truly agentic ai, yeah, you're gonna have 10, eight of them will be from Salesforce and three from ServiceNow. And, and, but I don't think that's here.
I have a hard time believing that's half of organizations today And or at least, you know, I think it's, we're not sure what an AI agent is, so therefore, everything that looks like it's AI is now becoming an agent. Chris, is that where we're at? Uh, maybe I think there is some over rotation.
Um, you know, people calling things AI agents, and they're not in the traditional sense or the sense we're talking about, at the very least, uh, AI agents. So that thing on your website that helps you, the, the search tool, like everything could be considered an agent. Uh, when you think about it in some degree, however, whether it's actually using the large language models underneath the hood, that's a different story.
I know I've been to many websites that have a little, little chatbot thing that pops up and it's completely not intelligent, right? Like it's, it's, it's literally a phone tree replacement kind of thing For calling support. And that's more of a BPA a right, that, that kind of thing, right?
And, and as Iris said before, right, never, never confuse AI with intelligent. Um, anyway, hey, we're over time on this particular segment. We gotta take a break here on the gang on this Monday.
We're gonna come back and we're gonna talk about AI high, uh, insecurity Rena, anxiety. You're watching Text Drunk Gang. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're gonna have a little chat about, well, what is the future of cybersecurity in the age of ai? Jack Poller has a column up on Security Boulevard that you should all check out talking about.
Well, the attacks now are being launched by machines, and that just changes the game altogether. But Jack, go ahead, explain. So I, there are essentially, you can think of this, there are three ways machines can be involved in an AI in particular involved in the attack side of the cybersecurity equation.
And one is what we would traditionally call red teaming, which is where you attack your own infrastructure to find holes in it and help your blue team, the defenders figure out where they need to be better at defense. Uh, second way is you could be a real attacker and attack somebody. And the third way is you could be the, uh, military or government institutions and using AI as part of your attacks against other nation states.
And we sort of see th all three of these coming to light this week. Uh, red teaming is I think more AI being used in red teaming right now as more of the business process automation that out was alluding to in the last segment where we're trying to figure out how to accelerate our red team activities and enhance them. And also to look at how red teamers attack AI agents and other AI infrastructure that we've put in place.
Uh, and then there is, uh, a company recently called 20 who goes by, uh, the double X letters XX or 20, uh, that received, uh, large investment and large contracts from the Pentagon to ostensibly do, they're not very public right now, but based on their hiring, it looks like they're hired to do offensive operations on behalf of the US military and US government. And then, uh, anthropic has claimed that they have discovered an AI initiated an automated attack sequence, uh, that was used using anthropic to attack other organizations, particularly, uh, Claude code, uh, was used. And, uh, they claim that something like 75% or more of the entire attack operation was fully automated and autonomous with, uh, humans in the loop mostly to direct targets and validate, uh, specific points in the attack chain.
And that it was now, we're now getting, uh, AI driven attacks that are now going to ramp up in the attack itself in a speed and scale that's gonna be hard for human defenders to respond to. Yeah. Um, so I, okay, so my background is in red teaming, NSA, the, like this fra this is nothing new to me.
In all honesty, we're looking at companies, for example, the difference between a red team and an actual threat actor is intent. And when you have companies, for example, that have been around, you have, for example, pen Horizon three, you have lit, you have a whole bunch of other automated attack companies that are coming out, sorry, not attack companies, red team simulation companies that are out there. You know, this is kind of expected because what computers do is automate repetitive tasks.
A lot of red, well intrusion is based upon frankly just searching for massive opening or just searching massive infrastructures for openings, finding a potential vulnerability to get in. Once you're in, then you start digging in and so on. And a lot of it is just, you know, this whole conversation is really the inevitability of what we're doing.
Now, the concept of ai, and I use my Dr Evil quotes here, is because you're able to go ahead and maybe make decisions on a fuzzier basis than a more straightforward acting basis. 'cause really, AI I'm oversimplifying is advanced statistics, and it's just acting repetitively to get in. Once it finds a vulnerability, it automates it, maybe agentic ai like, and takes the next step.
But then you have a person to say, yes, I like that data, or Yes, thank you for identifying all the vulnerable servers. Here's the servers you really want to focus on. So the downside is, and I'll just say this, China has been the most egregious.
And what I mean by that is they don't care. The other threat actors actually don't want to be detected because the problem with this massive use of AI is that you are more likely to be detected, you're more likely to be stopped, and I'll just leave it here and let other people talk. But at the same time, there's also the ability now with threat, you know, continuous threat exposure management and tools like that to automate and start detecting these things.
You know, so far the good guys aren't as efficient as the bad guys, but I'm hoping that the good guys start automating the mitigation of the vulnerabilities the bad guys are attacking. I think this is a case of this AI being a tool and people using the tool, how tools are used, right? Like a machete is very good at cutting down foliage, but it's also a tool for other things, right?
Just like ai. So automating things and having it run semi autonomously, I think is just going to be the future, essentially, right? If you want to do something at scale and do it quickly, you're gonna tell the computer to do it for you versus trying to do it yourself manually.
So if folks already have a foothold in your infrastructure, it now becomes even easier for them to say, okay, let's xFi things now versus, you know, having to maintain a persistent presence for a while, go unnoticed and then start exfil things. Uh, Chris, if I can add on to what you're saying when you're saying it's the future, I think the future is, uh, okay, now I, I believe we're already there with that. And I'm gonna use an analogy.
Um, and I'm not saying here's a good old days when I learned to program, when I first started programming, it was on holler Earth cards, 80 column cards. And I had one test run a week to check my deck to make sure the program ran. And it failed with a SOC seven or anything else.
If ask your grandparents, um, if it failed with that, then you had to wait another week to get another test. So you did what's called desk checking, and you look through those cards, I don't know how many times I would look through every deck at least 50 times. Now, a developer writes a program and they can just run it in the system because it's close to free.
And if there's an error, it tells you. But if it runs successfully, they say, well then it's good. But they don't, it doesn't include regression testing and it doesn't include what all the unintended consequences.
And I think that's what you're referring to. That's the downside of this. And back to IRA's comment as well, the downside to this is it's great, it's faster, it's automated, we can do things better, but it is simply a tool.
And it also means that if we do things poorly, we're gonna do them poorly much faster. So Ira, IRA, what is the role of the human and the cybersecurity teams, if this is a machine versus machine battle at this point, and you know, are we just gonna sit back and watch it happen? Well, the thing is, you gotta start looking at what are we doing at a high level?
At a high level, these things do what you tell it to do, and somebody's gotta tell it what to do. It's gotta tell it what the targets are. It's gotta tell it what type of data, even if it could sort through data quickly.
It's almost like reverse data leak prevention. We have to start figuring out, okay, what are we looking for? There's also task management and intelligence operations.
Somebody is doing the collection management, doing the tasking of the people and so on. We also need people to write the tools to begin with and write the ai because a lot of people are like, oh my God, it's ai. It thinks for itself, it doesn't think for itself.
It implements algorithms that a person tells it to implement. And these algorithms are designed by people, and you have to see what are the good strategies. And at the same time, in this whole attack chain, there's also the defender aspects.
When you have attacks at scale, those are easier, much easier to detect. And it means that people have to step in and be there to step in to stop it. Because, you know, again, this was detected all of a sudden.
I'm sure somebody at open AI looked at the stuff and said, wow, look at this. Usage, usage is really up. And it's almost like the cliff stole thing.
If anybody remembers the cuckoo's egg, how did he detect the whole East German intelligence? It's like a 37 cent error sent him down a rabbit hole because somebody was overusing the ai, they're overusing the assets and these are noisy. The thing is to automate in stealth is much more effective than to automate, like what was just happening.
I was gonna say one interesting fact that came out of the, uh, the, the philanthropic attack was that philanthropics AI actually hallucinated, uh, data for the attackers and it hallucinated identities that it claimed existed, and that it had compromised, that it had found compromises for when in fact it didn't. They were false identities that had hallucinated. So it actually sent the attackers down a path that was not successful.
Is that part of the defense? Now? I'm, well, no.
What Responsibility do these companies have now, right? Yeah, That would Well, But here's the thing guys. Let's, let's ground this.
In reality. What are we really talking about? Why should people out here care?
They should care? Because like it or not, the bad guys and whoever, however you want to define a bad guy, whether they're a red team member or a real bad guy, you know, working for the Chinese or, or whoever, the bad guys are using ai, they're using agent ai, they're getting better at it. They're learning how to use this tool to be more effective.
The tool itself is progressing to be more autonomous and do these things. And it is going to be stealthy end at scale, stealthy end at scale. Because it, that's, that's what the, this AI can give you, right?
That those kinds of resources, right? You have multiple workers, you don't need as many people in the loop. You may still need a human in the loop, but not many humans in the loop.
And so how do you fight this? How do you defend this? Well, the only way to fight this AI onslaught and defend against this AI tsunami is you gotta use AI itself.
You got to use AI to fight ai. You got to use AI to defend against ai. You're not gonna be able to match human to ai 'cause the AI will quickly outstrip you.
There's too many of it, there's too many GPUs out there. There's too much. We need automated AI defenses against automated AI attacks.
And I'm not trying to create some new missile gap here or cold war kind of thing, but that's why it's important. We, we need to realize it and move forward. Well, you mentioned missile gap, and that kind of sparked something in my head as far as the, the current economic situation that we're facing, the economic contest that we're facing with AI between the west and China, essentially, I say the West in like the 1980s term.
Um, but the, the thing we're gonna see is that folks are gonna use these tools, they're gonna advance with these tools, and they're going to start competing at a higher level, right? Yes. This one instance we're referring to, you know, the AI hallucinated, and that could easily be why they were discovered, but someone's doing that right now with AI and they're not being discovered, and that's a big problem.
Well, cybersecurity is not about perfection to begin with. Cybersecurity at the overall is about risk reduction at the end of the day. And that's how it needs to be phrased.
Because the fact of the matter is, and you know, everybody's gonna say, well, I don't have the AI to fight against it going back to like com. My comments on like the first block, you know, again, you're gonna have tools that are gonna be able to detect this. The problem is a lot of people don't want to use tools that are available.
These people are not, you know, these attacks are not unstoppable attacks. They're volumous looking for the one hole among many potential holes. And what's happening is, is this is a case where, you know, I don't have to outrun the bear, I just have to outrun people with me.
And in most cases, the ai, unless it's a highly targeted attack, which some are from nation states, I give you that. But for the most part, they're gonna go after the organizations that are not enabling the technologies that are available from whatever cloud providers, whatever SaaS providers they're using. Much like the Snowflake attack.
If anybody remembers that where Snowflake was hacked, it's like no Snowflake users who did not turn on MFA were hacked. And so we need to start looking at that because all this ai, it's gonna find these vulnerabilities, which anybody could theoretically find if they had the resources, but it just doesn't more at scale. But the people who are reasonably secure are mostly gonna be pro protected against this 'cause they use the other resources that are there.
Agreed. All right, well, budgets being what they are, I think you guys are saying things might get worse before they eventually get better. Who knows, They might.
Hey, but we gotta take a break and move in the C block guys, we're running along, we're running late here. You're watching Textron gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in.
While the eu, arguably the only authority in the world that's now investigating anything, is taking a look at Amazon Web Services and Microsoft to see if they are dominating the cloud marketplace. And it's kind of interesting 'cause one of the things that has come up over the years is that surprisingly the main services that most people use in these cloud services, the prices don't seem to change all that much. And when they do, they seem to all perfectly align where every cloud service provider has the same price for every service.
So Chris, what's your take on what's going on here? Well, we've got quite a few things happening here in, in terms of like the EU apparatus of government. Uh, one is the Digital Markets Act, which, uh, has a provision in it that considers, you know, critical bottlenecks as quote gatekeepers, which need more regulatory requirements.
Um, antitrust folks are also involved. So there's a bunch of things happening here, but it's particularly interesting in terms of the past couple months we've seen AWS Azure, CloudFlare, a bunch of other folks just go offline or, you know, in AWS's case, cut off half the internet. It felt like Cloudflare's case the same.
So all of this has happened very quickly, and the EU is very worried about its dependence on foreign services. And I think, you know, when you look at the world we're in today, Europe has had a wake up call in terms of cyber activity going on in Ukraine between Russia and Ukraine. And they're starting to realize a reliance on a single source is not good.
We already have talked about, uh, you know, sovereign infrastructure as a thing in the EU that's mainly being driven by this need to be more self-sufficient. So they're trying to mitigate risk and as well as trying to get their markets in order so that it's not so easily dominated by one or two or three providers. I I, I agree wholeheartedly, Chris.
I, I, um, what's interesting about this though is someone talked about 1980s West, you know, this is a case where you see that that's crumbling. The real, the real point here is the EU does not want American or US cloud companies being their sole cloud providers because it allows Uncle Sam to reach in there and, and have access to anything that they want to, right? Because Microsoft has come out and said that, uh, Amazon, they all have To, right?
Like, and it doesn't matter if an intelligence agency subpoenas you or whatever, you're a, no one's gonna know about it, and B, you're gonna do it because you have Your license that if you don't, don't, right, right. And, and so the EU wants some independence there and you can't blame them. Um, look, I'm a, I'm well, So, so does that mean, does that mean though that the EU will eventually wind up subsidizing a competitor to A-W-S-C-I?
I don't know if they'll subsidize. They already are, in my opinion, right? Like they've, they've put the, they've thrown down the gauntlet of sovereign EU based systems being their desirable outcome, right?
Yep. So I, I think, and ssa, so SUSE recently appointed a friend of ours, um, Adrian, Adrian, I forgot his first name. No, slack.
Uh, uh, slack. Anyway, they have an entire department for, for IT sovereignty. They are building EU based data centers, staffed with EU based support people using EU resource, EU based resources.
And, and SUSE wants to be the EU cloud provider. And, uh, you know, more power to 'em. Um, they, they announced this when I, I was at Seuss Khan in, uh, in Orlando or shortly thereafter that, but I've been, I've interviewed several of their executives since then.
And you know, and this is wholeheartedly, I don't know if it's financially supported or subsidizes the word you used Mike, but it's, it's, it's certainly you've got, has a lot of support within the EU countries and the EU block. Do we wake up one morning to discover that the president is now saying, Hey, your guys are creating an unfair marketplace and we're slapping tariffs on you because you're preventing our American Cloud service providers from addressing your market. And I think they're ready for That.
I mean, I think they're ready for it, but I think they also know that that's not the way to do it effectively. It's just a pain point that they're inflicting And it is a scale difference. But how different is this from the US perspective of saying TikTok shouldn't be here, and how easy has it been for us to extricate ourselves from that?
But yet, you know, again, you look at the world through this west versus China dynamic that Chris mentioned before, you know, we, we think of, you know, there's three really four cloud providers, right? Google, Amazon, uh, Microsoft and Oracle, let's say. But if you look at, uh, uh, you know, the Chinese, Tencent and Baidu and, and, and those, you know, they, if you look at the top 10 cloud providers in the world, I think four of 'em are Chinese.
We just, they're totally off our radar here. Well, this is nothing new. Um, you know, I'm going to black and Middle East in a couple weeks and, you know, Saudi Arabia and a lot of the Arab countries already have a data sovereignty where data, when you use them, the, the data has to be maintain, or if you have, if you provide services to them, the data has to stay in their country with an approved provider.
So what the EU is theoretically doing is, well, theoretically might be doing in the future, is nothing new. You know, it's just a matter. Saudi Arabia, if they want, they could throw all the money in the world and stand up their own, you know, cloud provider, which they probably did.
I don't know the details of it, but, you know, the EU doing this, I mean, you already have, and again, I I must admit, I don't know the full details of this, but you do have instances of like AWS and all these other things which are pretty autonomous within the eu. Like I know for example, we use AWS Germany as an example where the data is sovereign to Germany. And I don't Think they, IRA, the, that was what we used to believe the case.
But recently it's come out that even though it's EU AWS Germany or Microsoft France, if the United States government or court system says, I want access to that data in that AWS Germany locale, AWS is gonna turn it over Microsoft. This Was this, this was buried in the Cloud act that Congress passed a few years ago. And they're like, and the European, So they, they actually, they pierced the veil is the legal term.
They pierce the veil of that sovereignty. And it's no longer enough. They want now, like in Saudi Arabia, they want in essence, locally owned and operated companies that are not part of the US that the long arm of Uncle Sam cannot reach them.
What I find really interesting is they're more worried about the long arm of Uncle Sam than they are about the dragon, right? They used to fear the dragon, One of the odds in Microsoft and AWS just go visit their local congressman and get them to amend that act. So that slim little nuance Slim, slim Now, No, yeah, no, the national security apparatus won't let that happen.
More importantly, from a Microsoft or an Amazon or Google perspective. And Google's also involved in this. And, uh, Microsoft and Amazon were also named as, uh, key, uh, I can't remember the exact term, but they were key dependencies for the, uh, EU Act, Dora, which is about protecting the financial infrastructure in the eu.
And I think from those company's perspectives, this is simply the cost of doing business. And it just raises the cost of doing business a little bit in the eu. And they will probably raise the prices in the EU commensurable.
And, but it's, it's literally the cost of doing business. Just move on from it. And, you know, the data sovereignty, the concept of data sovereignty from the US federal government, and the same as the concept from the EU governments, which is they all have laws in place that they can go in and grab that data whenever they want.
Uh, and in fact, the British and the EU are well on their way towards outlawing end to end encryption for that very specific reason. So it's, I mean, that's a sort of a non-issue from the, the cloud service provider's perspective. From a customer perspective, that's a big issue, but it's one that they won't be able to solve.
And there's two competing efforts in, in this article as well. You know, there's talking about sovereignty and having everything contained within the jurisdiction of whoever it is you're talking about. And then there's single points of failure and, and one feeds the other.
Actually, if you say, I want everything happening in my country now, you're, you're taking out the, the diversity of, of your, yeah. So we have to balance both of those too. And I think there's a train wreck down the road here.
Uh, the question is, which train is going faster? Yeah, I mean, and also look, you know, one of the great things about the internet was its global scale. You know, on the internet, I'm talking to people in Bangladesh or Bangalore, as easy as I'm talking to people next door and, and all, and it's just one big network and we don't have, you know, firewalls in that way.
And we don't have borders per se, it's the internet. But now, you know, and maybe that was naive. Maybe that was the initial commercial internet period of about 25, 30 years.
And now we need to realize just as China's done for years and Russia has done, is that there are borders on the internet and there is, you know, kinda border control. And, and, and that's just the way it's going to be. 'cause we can't have nice things.
Alan, you remind me of something. Um, I'm trying to think. It was, uh, probably around 15 years ago, or close to it, I was a member of the East West Institute and organization.
Different governments come send representatives and talk about how can we start controlling effectively security of data on the internet. And the Chinese government had representatives there and we're all talking about, here's all the different things we could do. And the Chinese representatives stood up when it was air turned and said, I don't know why you're all concerned with this.
We have this fixed. And they were right. Yeah.
In retrospect. So, So Alan, what you're really saying is that we're gonna see checkpoint Charlie on the internet. What do you think?
Yeah, I mean, we'll have east and the west, you know, We're, we're already seeing that with China and Russia today, right? There are services that are really only designed for, you know, predominantly Russian or Chinese speaking folks out there. And they've created kind of their own bubble of information out of all of the internet, which is good and bad, right?
Like the internet was this great unifier in the nineties and two thousands, and now we are seeing divergence from that unity, which is natural progression of things, I assume in our current environment. Well also, I mean, checkpoint Charlie really is today the great firewall of China. I mean that literally is the, the checkpoint Charlie, and I'll live with that.
Yep. Guys, we're out. We're over time.
I gotta pull the plug. What a great discussion though with some really smart people. Chris, Jeff, Jack, IRA, Mike, thank you for joining.
Thank you for watching our Monday edition of Textron Gang. As usual, you have Textron TV right after this, if you're watching the stream, if you're watching this on our OTT channel or YouTube or whatever on demand. Thank you for doing so, but we'll be back with more gang tomorrow.
Fresh gang members, fresh topics. Until then, this is Alan Shimmel. Have a great day everyone.
Hey everybody, welcome back to Ingram Micro one, and I'm talking with my friend Hans here who is a solution provider with a specialty in healthcare. How you doing buddy? Doing well.
Been a really, really great conference. There's just been an awesome amount of innovation in healthcare lately and I know just walk people through a little bit what's going on in that sector and your role in it and what are the opportunities? Yeah, we're finding, um, there's a lot going on with an interest in ai, you know, trying to find ways to, you know, automate manual processes.
And we've delved into a very, very niche aspect of that industry with, uh, organ uh, procurement organizations and tissue banks, tissue processors. And, uh, there is a tremendous amount of opportunity both for AI and just automation across everything they do within their supply chain. There's also a lot of regulations in healthcare.
I don't think that's, uh, much of a surprise to anybody, but we're trying to apply AI to that. How do we walk the nuances of that where concerns about privacy maybe and the data, but we also need to come up with some automation. That seems like a challenge.
Yeah, it is. And uh, you know, some of the things we're finding out, I mean obviously we've got certain compliance and accreditations and we have to get organizationally SOC two and hipaa, and then you've got the, uh, PII information that they ho hold and that ties into their own processes. So we have to be respectful of the confidentiality of not only the information that they have on the patient records, but also the confidentiality of their own internal processes and how they use it.
'cause in some cases it's, it's a competitive advantage in some cases. It's, uh, very, very, um, intrinsic to how they operate that they actually don't want it to release. And they're all very sensitive to the aspects of the, the regulations, you know, for that confidential information processes.
And, uh, I mean right now it's just respect and, and, and, you know, with the, the technology to be able to, to do what they need to do, but at the same time, not allow us to limit us. When I talk to people, there are two challenges, but the first one, everybody seems to know. It's like AI will occasionally hallucinate.
So how do I kind of work around that or, or account for that factor when I'm building out something in a healthcare scenario? Yeah, that is, uh, it's really interesting because the way that we are actually applying AI for our clients in this industry is that, uh, that does exist. And the challenge is that, uh, the data, um, as much as you need it, as much as it feeds into the AI engine, uh, it's basically the lifeblood of the AI engine as well because the AI model has to be trained off of that data.
And we've got all the regulations, as you just mentioned, that prohibits some of, you know, that data in terms of how we use it to aggregate it with other clients at a very aggregated, aggregated level. And we don't have that opportunity. So the, the, the model has to be trained and the more data that we can get from the organization we're working with, you know, we can work around that.
That's number one. Second part is, is that no single AI model will provide the outcome that we need for our clients. So we're having to stack the technology with other types of ML oriented tech, um, code, other types of AI oriented models that do very specific functions to work in tandem to provide an outcome.
So I've kind of got a layered approach where some of the AI models are validating the output of the other AI models to get, make sure that whatever is being generated actually is supposed to be what it is. Correct, Yeah. At a very simplistic level.
Yes. The other side of the coin too is that a lot of the healthcare processes are what we would call deterministic. They're supposed to be done the same way every time.
Mm-hmm. Uh, AI models are probabilistic and hardly ever do anything the same way twice. So how do I connect something that is probabilistic into a deterministic workflow and kind of meld that together?
Yeah. And that, and I, I go back to what I just said earlier, right? There's, um, um, there's the prompt engineering, there's the AI models, there's the AI model stacked and layered on the other AI models.
We got a vector database that spills into there as well, the understanding of their business process and what the outcome is. Um, so the model in order to to, to train it, to have a predetermined outcome every single time, the more data that we can feed into it, the more scenarios that we actually get from it that we can hone in and refine on, we'll start providing that very, very precise answer. And it's one of those where it's a process of refinement processes or an iterative process.
So the first time you build it out, it's not gonna be perfect. And so the more data that we can actually feed into it, the more input we can get from the end users. Uh, we actually start honing in on that, that precise answer.
Now, everybody watching this is probably having the same question. Where did you find the people with the skills to go do that? Because most of the folks are saying, I love this AI stuff, but you know, they all wanna work for Nvidia or something.
So how do you get those guys to come work for you? Yeah, um, trying to answer this the software way. So there is a constraint in the marketplace for skilled and AI software engineers, and I have to compete with, you know, the Facebooks and the, you know, all the, the big, you know, hyperscalers for that talent.
Uh, in my particular case, I got very, very lucky because the AI engineer that we hired married my, my youngest daughter and I provided an opportunity and there was an opportunity he probably wouldn't get at the other places because he, uh, has an opportunity here to actually kind of define our direction and to be able to be very creative with the AI and in a, in a and applied sense. Um, but going beyond, you know, my small team of him and, and a couple of others, um, it, yeah, yeah, it, it naturally is is very difficult. So one of the way things that we're trying to do to augment that is that there are AI tools that allow us to, uh, do some code development on the front end.
It's not perfect, still has a ways, ways to go, but it does save us time. So we're trying to use automation and code development to be able to close the gap on some of that. And then, like anybody else, you've gotta go out and hire the talent as well.
So we gotta ensure we get the right talent. Of course, we're at an Ingram event. How did you get connected to Ingram and what does Ingram do for you and as part of the building of this solution?
So the story that, um, you know, most resonates is that we got into this about two years ago. So that's when I hired our, our, uh, senior AI engineer, uh, November 6th of, uh, 2023. And he came on board, and Ingram actually had, and we started out with, uh, IBM's Watson X.
They were actually sponsoring a level three workshop with BM in Chicago. So his first day on the job was on an airplane heading to Chicago to get his credentials on, on Watson nuts. So he spent a week there going through the workshop, and that was really brokered by Ingram.
You know, having the foresight to actually, you know, go out and say, how do we actually get our partners enabled? How do we get them engaged? How do we get them them to a point where they can actually start talking ai?
And it was a really good foundation because it allowed us a better understanding of how, uh, the technology was being positioned, you know, in, in terms of the go to market. But we had to learn after that, how do you actually go in and start selling this? So we relied on, on the Ingram team, uh, to, to understand what types of proof of concepts, how do we actually go through a sales cycle, how do we actually engage with prospects who have a need?
And then we had to hone our skills from there. You of course, you also work with a lot of the vendor partners that Ingram represents. Um, I don't know if you can tell me in a lot of detail, but which of those vendor partners are kinda at the core of that solution for you guys right now?
And what is it that you would wish that maybe more of those vendors would remember when dealing with solution providers such as yourself? Yeah, it's right now with, you know, just the, the terminology of ai. Um, I think the large vendors, you know, the ones that are well known that make the news every day, they're sewing a lot of confusion.
Everybody's talking about the art of the possible as a reseller partner, as somebody who actually engages with the client, by the time we engage, they don't want to hear about the art of the possible. They wanna see a solution that actually works. So there's a big gap between, you know, what, what the, uh, the vendors are providing and what the solution providers actually have to deliver.
So we rely on Ingram heavily, not necessarily with the technology partners that we've worked with IBM and Microsoft, and there'll be others in the future, but it's the relationships that we don't have with the other technology partners that Ingram does have. So for instance, if there is a reason for us to change some of the backend coding with a different LLM or a different AI type model that is, uh, specific to a certain vendor and we don't have the re relationship, Ingram will probably have that relationship and we have to leverage Ingram to help build our credentials and reputation to be able to open the door and get the right resources that we need so we can continue our development to provide that solution to the end client. One of the things that I hear a lot about is every CEO has a bad case of fear of missing out and things that this AI stuff is all magically happening tomorrow.
And then there's their staff and people who are a little more circumspect 'cause they understand what's required to actually implement. How do you as the solution provider kind of navigate that relationship and those conversations? 'cause essentially you're a diplomat between these groups.
Absolutely, yeah. And it's, um, that was, I would say situationally, that was probably the case two years ago when we started, um, AI was this concept. And pretty much every executive team says, okay, we've gotta get AI in here.
And our first probably, you know, a handful of phone calls or, or overshoot from our, our, our client base, not necessarily our prospect base was, Hey, can you help us with ai? And my response was, yeah, absolutely. What would you like us to do?
It says, well, that's why we're calling you. And it was this, this panacea that all of a sudden you, you basically, you install something, you implement it, and everything's gonna work to perfection. It's just like this magic button you press.
In reality, that's not the case on the staff level folks, the operating level folks, they're seeing AI as a threat. So it's basically our executive team wants to bring in AI and it's, it will basically replace my job. And so you have this, uh, uh, diversity of thoughts and understanding of what AI is supposed to do.
So we have to obviously educate the C level folks that it is not that be all end all solution where you push a button, everything magically works, um, and it's trained on your data. And then we also simultaneously have to work with, with the operations folks and let them know that we're not here trying to put a system in to replace your job. What we are trying to do is that, uh, you know, right now the focus and the benefit of AI is really, you know, time savings and productivity improvement.
So we want the system to be able to do the heavy lifting for them and the process and use everything that AI can do based on the data that's being fed to it, to free up their time to work on the very true value add, you know, needle moving types of, of aspects of their job that's gonna really enhance the company's productivity. One of the funny things about healthcare, at least in from my perspective, is it is always perceived as a sluggish kind of business because they were collecting a lot of data, tagging it and organizing it, and yet that may be their secret sauce for AI because they did a lot of that heavy lifting of the data and worked already then a lot of other vertical industries have not. They, uh, I would agree that to a certain extent, uh, but there are, um, I would say upstream functions that take place that are still very manual and a lot of that tagging categorization of data, which actually makes our job easier, right?
Because it's all, all well-defined. Um, a lot of that has been done, but there's a lot of unstructured data that shows up in forms and handwritten notes. Um, it shows up in jpeg images, OCR images that we have to translate in.
And not only that, you can have forms that have the same information, but the forms are different and, and the context is missing from that. So when we actually build out these AI solutions, we have to ingest those documents, we have to understand what is in those documents, we have to understand what the context of those documents are so that we can turn the information on those documents into relevant, very well-defined, categorized information to then let the AI model be able to provide the output that it wants. So to your point, a lot of what they do operationally, you know, for production, for, um, you know, um, patient outcome, yes, that is, but upstream from that, a lot of the information is very unstructured and increase the challenge for them, and there's a huge amount of opportunity as far as productivity gains from that as well.
It almost sounds like, you know, you have a solution and you've kinda landed and now you're looking to expand. So what are you thinking about as the next opportunity? Yeah, so we, we are, we're actually, uh, we, we've got a great client that we're working a, um, informing a strategic relationship with, and it's a tissue processor, so basically a organ donation, and then they actually take, um, uh, tissue, uh, donor tissue and then look at, uh, eligibility requirements.
So they, they be able to look at lifestyle, they be able to look at disease, they look at things of that nature and, uh, qualification criteria for the tissue. They have their own manufacturing process and you know, as we spoke earlier, that's very well defined. The information is very well defined.
How they capture the information and move the information through there is very well defined. But on the front end of that, how they actually analyze the, the donor and how the tissue, the suitability for the tissue that they have to process for their, in, you know, inpatients, the hospitals, the doctors, the clinicians. Um, so we, you know, we've developed an AI application to be able to do that manual process on the front end.
And then the automation that follows that, the donor traceability. So now that we've got the components being processed and tracking that all the way through to the final production of that tissue, so that it's either a skin graft or a bone graft or whatever that final product is, so they can inventory that and then push that out to the hospitals. And then there's the entire supply chain and ecosystem where the supply demand match is very inefficient.
So we're looking at the hospitals, the doctors, the clinicians, when they actually need something, how can we actually compress that cycle time so that they can get it from the tissue processors in a shorter period of time? And, and there, there's additional opportunities beyond that as well. So there's a plethora of, of things that we can do.
Technology can help, but you've gotta have a good partnership with folks in the industry to do it. Yeah, I almost think like anywhere there's friction, it becomes an opportunity. Absolutely.
Absolutely. So last question. As you look into the coming year, what are you excited about?
What are you thinking about and maybe what's keeping you up at night? Well, the geopolitical stuff's keeping me up at night, so not, not a whole lot I can do about that, but there are opportunities. And I think, you know, we've had, uh, two years of maturation, uh, not only within my organization, but I think within, uh, just industry in general and understanding, you know, ai, AI has gone from this concept of AI is, you know, is just this broad, uh, term that everything's kinda lumped into it.
Now we've got, you know, the, uh, uh, generative ai, we've got agent ai. Uh, we're still focused on use cases, but I think a lot of the use cases will be addressed by agentic AI to a certain extent. And then you have the possibility of that automation where you get the AI agents talking to each other and looking for those opportunities.
But at the end of the day, when you look at it, right, we are still collecting data as part of that process. We're trying to take the friction out of the supply chain. So the question I asked the CEO of our client is that if you were to look at you processes and you were to take all the friction out, what is the shortest, shortest amount of time that it would take to act, you know, to actually process the tissue that, that you work with?
And he thought about this, I said, that should be our goal. And that's what I'm excited about. 'cause I think the technology can get us closer to that goal because we can automate it.
A lot of the processes in a very smart, intelligent fashion. Not necessarily to replace jobs, but again, take the folks that are very good at what they do and allow them more time to be able to do it better. Especially the stuff I don't enjoy doing in the first place.
Yeah. Hey guys, it takes a village to do AI and it kind of starts with the solution providers and includes the distributors and the vendors. And that's how it all comes together.
Buddy, thanks for coming by. Yeah, thanks for having me. Alright.
And we'll be back in a minute. Hey, everyone. We're back here live on our, you could say it's day three, or you could say it's day four.
I've been here four days, but this is the third day that the expo floor is open. So take your pick. But we're live here at Cube Con Cloud Native Con in Atlanta, and I'm really happy to have my next guest.
We've been kinda waiting for 'em all week, whether you call it day three or day four. Jonathan Bryce. Jonathan is the, uh, executive director of the CNCF, but he has a dual role.
He is also the executive director of the, uh, open Infra Foundation, which is also now part of the Linux Foundation, or under the umbrella or whatever. Auspices Del left. Uh, Jonathan, welcome to Text Drunk tv.
Thanks for having me. Pleasure. So, Jonathan, I I've wanted to ask you this 'cause I, I admit I don't know the answer at all.
What, what, what have you been doing that got you to this position? Uh, well, it, it, it all started, uh, in the nineties with the web. I, uh, I spent a lot of time, um, doing software development, uh, for the web.
And back then that also meant you had to build your servers and put 'em in a data center. And, uh, and then I, I joined a company called Rackspace. I was one of the Oh wow.
One of the early, early employees there. And, uh, we, um, you know, built out more data centers and then I started a cloud company. Rackspace bought it back in.
And, um, that was where we, we, uh, launched OpenStack from. Sure. Um, OpenStack started to really catch on, and so we wanted to give it a neutral home.
And this was kind of before the Linnux Foundation, as it is now, is really a foundation of foundations. Um, and we, we actually talked with Jim Ziland a lot in 20 10, 20 11. He was super helpful and we created the OpenStack foundation, I remember.
Um, which, uh, we, we, uh, as we added other projects to it, we, we rebranded to the Open Infra Foundation in 2020. Yeah. And, and finally, you know, kind of full circle earlier this year, um, merged it into the, uh, the Linux Foundation.
Um, so, you know, it's been a lot of all, all infrastructure, uh, some software development, some hardware engineering and network engineering, and a lot of open source. So, lemme ask you, the nineties, when you were building out servers for the websites, what was your platform of choice? Uh, well, one of the things that, um, that got me into open sources, I was a teenager and I had no money.
And I started doing this because, uh, I, I realized I could, I could, uh, make more money than mowing lawns by, you know, building people websites. But I needed everything to be as cheap as possible. So it was, uh, it, it was X 86 and Lennox and, you know, the, the very first versions of, of PHP and my SQ l and um, yeah.
You know. Yeah, it was amazing. It similar, I mean, I was older than you, but I started as a hobby building websites, and then we had a store, 'em, and same kind of thing.
It was an, i I, I still remember my, the first X 86 server. We bought our own server to store 'em on in a little ISP in Long Island called L inet. They gave me free, they let me put a server in, uh, it was a, a four-way X 86 machine, and I thought I was a digital landlord.
As we added more sites, I just plugged another hard drive in there, a vigor hard drive. Then, then the, the web really started taking off and we, we wound up moving the Sun Ultra Sparks, and we were running Netscape Yeah. Server over Solaris those, yeah.
We got acquired shortly after that. But that, that was, that was the web then. That was, that was the internet.
And it was fun as all hell. I know. Um, good times.
An interesting, you know, your fact pattern with, with, uh, Rackspace is a, is a common one. A lot of people started a Rackspace, went out, did well, fairly well, and got brought back in. Mm-hmm.
Right. Cisco does that a lot too. Right.
Yeah. So it was an interesting thing. Um, while we're on the topic though of Open Stack and Open Infra, you still are the ED for Open Infra Foundation.
Have it mentioned it once this week here on Textron? Yeah. Give us a a, if you wouldn't mind.
Uh, yeah. Well, we just had, we just had our open infra summit, uh, in Paris about two weeks ago. And, uh, it was awesome.
Sold out crowd there. Um, the, you know, OpenStack is still the, the largest project in the open infra Foundation. Sure.
And right now, there's some real tailwinds for OpenStack driven by all of these massive infrastructure investments. Um, there, there are kind of two SubT trends in that. One is digital sovereignty, which was a big theme for, for the event in Europe.
Um, you know, there, there's, uh, there's a desire to really know where your data is, who has access to it, what laws apply to it, and, uh, and make sure that you, as you're building systems, they're resilient to changes in the geopolitical environment. So digital sovereignty is leading a lot of folks to, um, you know, to kind of think about where the servers live and, and who's running them. And, and that's led to a lot of investment in, in, uh, in Europe that has mostly been built out on OpenStack.
Um, AI is another piece of it. And one of our other, uh, really popular projects is called Kata Containers. Um, kata containers is a secure execution environment.
You can plug it into, uh, into a Kubernetes pod, and it gives you a, uh, a very lightweight virtualization wrapper that protects against, um, container breakouts and those kinds of things. But it also has some other really interesting features that make it nice for ai. Mm-hmm.
Uh, which is that you get to have a kernel in there. Right. And that kernel can have customizations for, uh, for special workloads.
So we, we have a number of AI companies who are using COTA containers to, um, to, to create GPU as a service businesses, some of them at quite large scale. And, uh, and, and so, you know, the, the Open Infra foundation is, is often one level down from where we are here at KubeCon. You know, KubeCon, cloud Native Con, uh, a a lot of the tools here expect that you have a cloud, that you have infrastructure with an API on it in the Open Infra land.
We're building infrastructure APIs on top of hardware. So it's kinda one level lower, but still, I love data centers and I love that level. So I love being able to, to kind of span both groups.
Has there ever been a more interesting time to love data centers? Oh God. I know, but do me a favor.
How do you spell Kata? KATA. Yeah.
KATA. Just want to make sure people got that. Thanks.
Um, you know, it, it's interesting there are, you talk about tailwinds that are moving it there. Let's talk about, if you don't mind, we'll spend a little time. Yeah.
Look, you know, the whole VMware Broadcom licensing thing has caused, I'm not here to debate whether it's worth the money, but it's caused people at least to say, Hey, this is a good inflection time. Mm-hmm. Should we look at something else?
Yeah. Should we look at going to public cloud? Should we look at a different, uh, cloud solution, hypervisor solution in general?
Right. Should we go hybrid multi stay just in the private mm-hmm. Data center?
Um, it's certainly, it's an agent of change. Yeah. Or, or at least an agent of ref, uh, time to reflect and, and make some choices going forward.
We, We, we did a survey of our Open Infra Foundation members earlier this year, and, uh, over 80% of them had gotten inquiries about migrating from VMware. Over 60% of them had already done a migration. Really?
Yeah. Off of VMware. Off of VMware, yeah.
Over the course of this year. And so it, I think, you know, what it, what it did is it injected enough uncertainty that, as you said, you're willing to consider a change. And from a business point of view, you know, I, I don't, uh, I don't necessarily think VMware made a bad business decision like they are.
They're, they're focusing on, on profitability and yeah, He's done pretty well for, except that guy. Uh, But you know what, it does change the dynamic of where their customers have been historically and, and where they would be in the future. So, yeah.
It, you know, it, it, it made people consider, should I move to something else? And, uh, you know, what would that be? I, I agree with you.
And, and it may very well be that their decision was they're better off with 50 or 60% of their existing customer base bank, three x the time they make more money and, and, and, and it's a very, uh, focused customer base. Yeah. Be that as it may, it makes opportunities for a lot of people in different things.
Yeah. The other thing, driving it, of course, as you mentioned, ai Yep. Right?
And, and what's going to, what is the AI stack of the future look like mm-hmm. And what platform is it running and what cloud or, or what have you? I, you know, I think there, we, the jury may still be out, but it's certainly anytime you could get people to say, Hey, wait a second, change is coming and I gotta think about what I want to do.
It's a good thing, I think for like, yeah. The infra, open infra foundation and the tools and projects in there. Yeah.
We have several, um, GPU cloud providers that are, are running OpenStack to power that. Some of them use cota, as I mentioned. Um, one of them is a top 10 buyer of Nvidia GPUs.
So it, it's, uh, it, it's great because if, if you're talking about a handful of GPUs and a couple of systems, then you know, you, you may just go with a simpler set of tools to manage that and deploy the workloads and, and, and go with a, with a simpler option. But if you're talking about putting tens of thousands or a hundred thousand GPUs in a data center with all of the associated infrastructure around that, then you really have to have something that's very focused on the compute, storage, networking management. And I think that's, that's where, um, you know, OpenStack has, has done really well this year.
I agree with you. I, I, I, you know what? Look over the years OpenStax had its ups and its downs.
I really thought, I guess when you changed to open in, was that 2022? 2020? Yeah.
It, it was a bit of a, it was a good shot of adrenaline in the arm. Right. That reinvigorated it.
Yeah. Um, and look, we, I think it's better days, may it's best days may still ahead of it. We, we just crossed 55 million cores of really, and, and our user survey, uh, that we just wrapped up around the summit.
So that's A lot. It's Crazy. It's lot, a lot more, more open stack than ever before.
Absolutely. And it's a good thing. Look, choice is good out there.
Freedom is good out there. Yeah. Um, let's pivot over to, to CubeCon.
NCF. So this is your first CubeCon as as Ed here. Impressions, thoughts?
Uh, yeah. I've been coming to Kub Con mostly since the beginning. I've been to, to most of them.
And, uh, it's always a, a really interesting event because this is where the, where the industry comes, you know, and, and, uh, it's, it's, it's a good way to sort of test the waters and see how people are feeling. And, um, you know, we we're here in the sponsor hall, we sold out our sponsorships this year. Um, the it, and when, when you look around, you know, you'll see, you'll see a lot of backdrops with AI on them.
And, uh, I that's, that's different than even six months ago. And I, and I think this is, you know, what's on everybody's mind, and, and to me, there's a, um, uh, what, what I've been trying to, to have a conversation around is, you know, which part of AI is the part that fits here. Mm-hmm.
Because AI is so big, you know, it's everything from, from really, really deep AI science and machine learning, Right. The neural net part Up to, you know, chatbots and, and agents and this kind of thing. Um, which part in that, in that entire spectrum is the right part for our community to work on.
And, um, you know, my feeling, I I, I'm obsessed with inference right now because I feel like that is a, uh, an area of AI that's really getting overlooked. You know, we kind of have skipped from, from being interested in, in these deep learning and machine learning and LLM creation techniques all the way over to agents. And, you know, agents require models, models require inference.
Agents are gonna operate at a much, much higher transaction rate than humans do when we interact with models. So now we have to expand that inference by even more multiples. And, uh, and this is, you know, going to just increase the already extreme demand for, um, for, for, for access and data sets.
Yeah. We can't, that we probably can't meet in the, in the in, yeah. You know, the timeframe they're talking about, well, This, this is where the software is really important because you're, you know, you're right.
Like you, you were talking about power earlier and, and data centers, and we can't build nuclear power plants more rapidly, and we can't, you know, install servers more rapidly past a certain point. But software can change very quickly. And, and if you look at, at the core pieces within, um, AI inference stacks, we've, we've seen incredible efficiency improvements this year.
Six X in VLLM eight X with really between, uh, caching techniques on top of, um, Kubernetes routing primitives. And so, you know, you, you, you get a few of those, those advances and you are 50 to a hundred times more efficient just through software. Right.
And that means that, you know, that nuclear power plant, you know, you, you're, it's 50 x more, more, uh, efficient there as well. Absolutely. If we get it approved, sorry.
Correct. Yes. But, but you know, what you hit on here is, is, again, this is a, this is a very normal fact pattern, right?
First these things come out and, you know, and it's, wow, they're great. But now you start thinking, well, how much power does it use? How much water do I need to cool it?
What, you know, all of these things and, and efficiencies become the, the, the rule of the day. Yeah. And software is always about making it more efficient, right?
That's how we've always proceeded all through my time in tech. Yeah. Right.
Software is where we pick up those efficiencies. Um, I don't, you know, you talk about inference and, and you, I don't think inference has had its day in the sun yet, is the problem. I don't, yeah, I don't think so.
I, I think we've been so focused on training, training these models, and yes, training the models is intensive energy intensive resources, but eventually, like, we don't have enough data to train much more of these models, right? We gotta have synthetic data and all those things. But now I, especially with ag agentic ai, I think inference is where the action are gonna be in the next, I I'm ashamed to say, I don't even wanna say three years, 18 months.
18 months. The to do 18 months is plenty. That's actually where I, that's the timeframe.
I think we have to, um, you know, to capture the opportunity right now. Yeah. Here's the thing is if you look at all of the largest inference systems out there, which most people don't know that these even exist, but we had OpenAI give a keynote yesterday, and, uh, and they were talking about, um, their, their fluent bit usage and Yeah.
Uh, how they were hitting performance limits. They fixed, uh, you know, they made some small patches to a few lines of this. It Made a huge difference, 50% reduction.
We, We spoke about it on text, I think yesterday. And, And, and, you know, so, so this is a, an example of where that the pattern that they have is different because of the amount of data and the amount of track transactions. It's a little bit different than what a, a happy path Kubernetes application was two or three years ago.
And so this is what we need, is we need, we need these systems to, to, you know, be, um, testing the new limits that, that we're gonna find. But if you look at all of the largest inference systems, they're all running on Kubernetes right now. I think the, the, the, the area that's a little weak that we need to focus on over the next 18 months is that most of them are doing it in slightly different ways.
So we're not truly benefiting from the full power of an open source community here. No. And, and the thing that I love about it is, when I talk to, to a lot of these companies who are, who are doing inference systems right now, they all go, what's everybody else doing?
We, and they say, this is not differentiating. Like, I don't believe that my inference system is differentiating for my business. My data is differentiating the Agents that I create.
That's always what the gator is, what's important, The data, the agents, like that's gonna be differentiating. This is holding me back. How do we get people working on it?
So I think this is really the 18 month opportunity is to get some, um, you know, some, some real patterns and, and real reference architectures for this. But I, I think this fits so perfectly in the open source model, right? Yeah.
Because where we are now is a bit of a Cambrian explosion. We have all kinds of weird animals out here, six eyes, 12 legs, and, but eventually life finds a way, right? And that efficiency kind of sets in.
Yeah. And the best model will, will, you know, the cream rises to the CRO to the top, and the other stuff stinks to the bottom. Yeah.
I think we're gonna have that. I hope it happens in 18 months. Sometimes These things Have a way of stretching out because anti open source money becomes involved, and a particular company with a lot of money pushes a particular model, which, you know, may not be the, the most efficient or best.
Yes. We don't use OS two today. Right?
Right. And I left OS two, but in any event, I, I do think that's where we are with inference, and I think it's gonna reignite, you think there's a lot of AI now, wait, right, right. When this inference stuff is real, and we've got that working right.
Um, I, I, I, you know, bothered, what is the term? Katy bar Bo doors or whatever. Yeah.
Katie bar the door. I didn't think I much of New York growing up, but you know what I mean, um, I I I do think it's there. I, you know, from the CNCF point of view, right?
Mm-hmm. So you've got all these projects and they're all, they're all being touched by this one way or the other. Right?
Right. How do you, how do you, um, orchestra to Bedford to you? How do you orchestrate Yeah.
All of these AI needs and Yeah. You know, push and pulls going on here. Yeah.
Well, we, we announced an AI conformance for Kubernetes this week. And I think that's kind of step one is to, um, to give people like a very baseline target to, to start aiming at. Um, it's, it's definitely not, not the end, you know, there's, there's a lot more to do, but what it does is it gives people a baseline target to, to start aiming at.
And the, um, the other thing that, that, you know, I, I spoke about this in my keynote. We need to highlight it because when I do that, I walk, you know, through the conference the rest of the week and everybody's coming up to me and they're saying, okay, well I'm using Ray on Kubernetes. Uh, you know, I'm using ser, I'm using KU flow, I'm using, you know, but this, I run into this problem, or I, you know, I did this thing and I was able to do this pre-fill caching, and it like, totally changed the, our gen AI efficiency.
Mm-hmm. And so, you know, I write them all down and I start to connect them and, you know, this is how, how it works in open source. And when we get to Amsterdam, I think we'll, we'll see progress, uh, within Three, four months.
Yeah. I think we'll, we'll see some progress and, um, and, and you know, that it, it can move very rapidly once you can, I think once there's consensus Yeah. Once you can, that's Get people together, it can move other.
And I think that's what you're really saying. Look, hopefully by Amsterdam we're gonna have a consensus here, and then it's full speed ahead. Yeah.
Right? We get rid of the 12 eyes eight leg that make no sense. Yeah.
And, and go forward. I, I do think that's it, you know, but you gotta remember, to me, open source is like democracy, right? It's the most least in, it's the most least inefficient form of government.
Yeah. But the best that there is. Yeah.
And, and so sometimes you gotta let this play out. Yeah, for sure. Let the, let the community and the market decide what is the best thing.
Right. You can't, yeah. We can't dictate And the the thing let it happen.
Yeah. The thing that I see as a change in AI right now is I, I say that, uh, chat PT was a proof of concept, you know, that, that it was not, it was not actually the end goal for AI chat. GPT was a proof of concept, but we, it, we put a, a human voice on top of ai and it made us all go nuts, you know?
Yeah. No, there, there is there. It's sexy.
Like Yeah. Because it had that a magical that even, look, you and I, we've been in this game, you know, we, but you show it to like my wife's family. Yeah, I know.
I think it's magic. I know The computer is is, yeah. All Has a brain sudden it became real.
Right. It became real. And so I think it's like, it's actually distracted from, from some of the, the fundamental progress or in other areas.
Mm-hmm. And, uh, and we're starting to see a resurgence of small models Yes. Of specialized intelligence.
And those are the things that are gonna drive, you know, inference on the edge, inference inside of enterprises, all kinds, uh, Optimize. Just, do you think to see those as open source projects? Or do you think the, the, the amount of money is just so you can't even, it's like talking about how light years in space, right?
Yeah. You can't wrap your head around it. Yeah.
I mean, did that take away from the open source? Um, so Akamai just announced, uh, an inference edge platform, um, I think maybe last week. And, uh, and you know, it's built on Kubernetes and is it, it's in our AI conformance program.
Beautiful. So, you know, I think that, that we will see services for sure that are, are monetizing the open source as They should. But I, I think we'll see a lot of, you know, we'll see a lot of this and, and open source.
I love it. Thank you for coming on here. Yeah.
We're overtime, I apologize. Yeah. Hey, that, that might have been our highlight for, uh, CubeCon this year in Atlanta.
I hope you've enjoyed it. ai Leadership Insight series. I'm your host, Mike Biza.
Today we're with Pedro Bizaro, chief Science Officer for feedzai, and we're having a little chat about how gen AI is being used to perpetrate fraud and what to do about it. Pedro, welcome to the show. Oh, it's my pleasure.
Thank you so much for having me. I don't think it comes as much as a surprise that the bad guys have figured out how they use Gen ai, but to what extent are they using Gen AI to perpetrate fraud, and what should we be on the lookout for? Well, they are actually quite creative, and they're using gene AI a lot in multiple ways.
And they, they are very organized. So basically what what they're doing is that they are making, with gene ai, they are making it easier to commit, uh, these phishing attempts and scam attempts. So with Gen ai, they are able to create, uh, for example, email messages that are much more realistic.
The tone and the language and what you refer to is, is much easier. So because of that, they are lowering the barrier of entry for other frauds. They, uh, also using gen ai, uh, scaling up their attacks.
So they are doing not one attack, but multiple attacks at the same time. Sometimes hundreds, thousands, with little variations. And in essence, testing whatever works better.
So if they end up discovering that one message works better than the other, they start using that message more. So they're basically doing what already some tech companies do when they're putting their ads, when they're pressing their ads, they're trying out many different variations, and they are looking to see which one tracks better for, for their cases. They're also using, uh, gene AI to enable personalized attacks.
So they are able to get information from people that they share online on LinkedIn, on social networks, and they're able to target their attacks in a way that are much more efficient because now they know their company, their title, maybe their boss, their colleagues. So the attack is much more targeted. And if you're not on the lookout, you gonna get food.
And of course, they're also using almost like sci-fi types of attacks in a sense that they are creating voice avatars. And in some cases, even video avatars. There are examples of people that are, they think they are in a Zoom meeting with a, with their colleagues, but they are in a zoom meeting with, with avatars create by fraudsters.
So all of this is becoming, of course, a huge problem. The losses are now on, on the hundreds of billions worldwide, uh, because of this type of fraud. I think the one thing a lot of these fraud attempts seem to have in common is there's usually some sense of urgency attached where somebody needs to do something quickly, but that assumes that somebody on the receiving side of that is gonna catch that and kind of raise a red flag.
Is there something from a technical level that we could be doing to identify these attacks so that we can maybe preempt them without having to rely so much on humans? Uh, there are, in fact many things. Uh, we ourselves, uh, at, we have differences, all these type of attacks.
Um, we have, for example, a product, uh, called, uh, scam check, um, that will analyze the message and we will show to us the red flags, for example, that these URL would not match or that this person using, uh, a request for, um, economic transfer, or there's an urgent tone on their voice. So it'll raise the alert, stop, uh, flag so that the people can be more on the lookout. And then we also have behind the scenes products, like what we have.
So, uh, as you, as you know, uh, Xi, um, is a platform that protects, uh, financial institutions and, and people, uh, worldwide. And basically we are running behind the scenes every time that you are doing a, a payment or a transfer, a transaction, when you put your credit card on the machine or make a payment online, there's just a few milliseconds, um, where we are called by the bank, uh, to check, is this transaction a really a good transaction or not? Is this suspicious or not?
And we are running machine learning algorithms to see if this matches your usual behavior or not, and we we're gonna flag it to the bank. Mm-hmm. It does seem like a lot of these attacks now are being launched by syndicates that are highly organized.
Are there things that governments around the world and law enforcement agencies should be doing to combat this? Because it does feel like it's become a global problem, Is indeed become a global problem. And many times the frauds are taking advantage of multiple geographies and multiple, uh, countries and types of companies because they start attacks, say, on a social network, and then they jump maybe to a telecommunications operator, and then they jump maybe to a bank.
And maybe all of these players are in different countries, and they don't have a common legal way of sharing data. So they take advantage of the fact that they are touching many organizations that do not communicate between themselves. So one thing that governments and law enforcement agencies and regulators to do is promote ways for these companies to share information, uh, in a private way, Uh, To detect fraud, to realize that, okay, this person is sending, uh, rather than thousands of SMSs, maybe this is a little bit suspicious, or this accounts may be sending too much, um, messages that look the same, and they are looking for money.
This looks suspicious. So it should not be just, um, an issue that is affecting the financial institutions. It must be something that is addressed at a global level, including financial institutions, but also like communication, uh, companies and certain networks and governments so that the, this information can be shared in a, in a safe way and an efficient way.
Mm-hmm. Of course, there's a lot of different types of fraud being committed. Um, are there particular vertical industries where you're seeing who are more impacted than others?
I mean, obviously financial services, but what else are the bad guys after? Well, uh, I normally say there is money, there is fraud. So, uh, all types, all types or, or sometimes even what's called pai money.
Quasi money is things like, uh, miles points and things like that. So e every time there's, um, money or something that it can be transferred to money, eventually, it could be a gift card or something like that. There will be fraud.
Uh, and this, as you say, they are very organized and they shift quickly. And normally it's almost like a game of guacamole. So you, you stop them on one side, they start doing something on the other side.
Something that is really important is our ability as on, on this side, the good guys to protect in a way that is very quickly. So we need to be very quick because the, the, the frauds are also adjusting very quickly. It also seems like there's a lot more activity surrounding various cryptocurrencies.
And I think maybe that's because there aren't as many protections there. If we want crypto to become something of a mainstream currency, do we need to kind of figure out all these fraud schemes? I, I think indeed.
Uh, so, um, crypto I think has lots of good promises about, uh, removing, uh, bottlenecks and allowing instant payments person to person. But at the same time, sometimes auto removes, uh, somewhat protections. Uh, and in order for us to really trust script two, we, the consumers want to feel that there's somehow some sort of protection, right?
These days, if a person commits, uh, a mistake, uh, in a traditional bank, normally there's some sort of mechanism to, to re recover, at least sometimes partially, but recover something of their, of their funds. There are actually, uh, legal requirements in most countries to do that, to protect consumers. But, uh, it is not yet the case in crypto, right?
So if you, if you make a mistake, if you share your password, if someone gets all of, of your account, if someone hacks your computer and steals your, your crypto login, you, you are toast. So yes, I, I think we should have more protections for digital currencies as well. You mentioned lowering the bar, and I think that is also gonna make it harder to, uh, disrupt and prosecute these gangs or syndicates.
'cause it seems like almost every three days or so you'll see an article about somebody got caught doing something, but, um, it feels like these entities just reconstitute themselves pretty quickly and launch again, and we're as far off as we ever were. It it is indeed, uh, uh, good that in some cases, these entities are in, um, other region, sometimes even promoted by their own countries, uh, or supportive, uh, or sometimes ignored, just letting them do what they wanna do, which makes persecuting these types of criminals much harder, uh, because they are in, in far away regions with other legal systems, sometimes even protected by their own governments. Uh, so what this means is that we need to protect ourselves on this side.
We need to find ways to be able to, even in the presence of organized crime, we need to assume that they're always going to be there and, and protect the, the accounts and the transfers and the payments on our sites. It is going to require on, on some cases, education of consumers, but also using AI to fight ai, right? We, we are the good guys, and we also need to use AI to fight these AI being used by, by the criminals.
Do we need to make sending money harder? And I'm asking the question because if I went back 25 years ago and I went down and send somebody, you know, a hundred thousand dollars, it was a process and it took time and there were checks and balances in that. com and we made it simple to give people money and transfer money through Venmo and whatever else.
But I wonder if we've gone too far, because that's what helps the fraudsters just kind of take the money and run. Well, for qui there's a balance. And it has always been the case that on one hand, we are trying to remove friction.
We're trying to make the system smoother and easier for people to use. And on the other hand, as soon as we remove friction, the first people that take advantage of that reduced friction normally are the fraudsters. They move very quickly, uh, when we allow real-time payments, frauds take advantage of real-time payments to, to make fraud faster and get their money faster.
But I am honestly an optimistic person, and I do believe that it's possible. And we've seen that it's possible to reduce fiction without incurring the losses. For example, we protect, um, hundreds of millions of, of people in, uh, other countries like, uh, Brazil for example, that has a very, uh, dynamic market of real time payments where people can pay with their phone almost e uh, everywhere.
Uh, more than, uh, 75% of all payments in Brazil are now done learning real time, uh, by phone using their peak system. And we have been able to protect, uh, this country, uh, although you'd think that, okay, we reduce friction so much, it's going to be, uh, much more dangerous. But in fact, it, it has not been.
So, I, I truly believe that's possible to reduce friction and do a good job and protect people. Um, you mentioned new technologies and deep fakes and various things that these folks are using. Um, as you look into the coming year, is, is that gonna become a lot more commonplace, do you think?
And what are you expecting the next thing the bad guys to do? Well, yes, I, I'm, I'm expecting that these attacks are going to become, uh, more and more common. Um, we have seen, uh, sites that are totally devoted to fraudster.
There are things like fraud, GPT and warm GPT, that the, these are sites that fraudsters use, and they have, um, uh, black markets and dark web, um, channels, uh, like telegram channels to share with themselves, techniques to do broth. And so they are learning and sharing with others very quickly. So every time that something like this works, I expect that it's going to spread.
And we see that, we see in our clients that if something appeared in one country, and if it works, then it's going to appear in other countries. Mm-hmm. So I imagine that they are going to target more and more people.
'cause in most places, people are going to be the weakest link. Like the, the systems are protected, the computers are protected, but people are the ones that are sometimes more easy to fool. Um, so that's what I expect.
So let me ask you this, where is the outrage? 'cause when I look at the world out there, there's, there's probably trillions of dollars being lost to fraud if I added it all up. And yet, um, there isn't this sense of, um, we need to go tackle this today.
There's usually a report from the World Bank or the UN or somebody like that, but, um, it doesn't feel like it rises to the top of the agenda then. So what are we gonna do to get everybody focused? That's, that's a really question.
Well, actually, in the, in the places where I work, this is actually top of mind. Uh, so, uh, almost all regulators in all countries or or national institutions, they are very, very aware of the rise in scams and crime. And in many countries, Australia, UK and, and, and others, there are already, uh, enforcements or companies to share information across, like, like I was saying before, social networks and telcos and, and banks on purpose to prevent this.
There are also situations where the, the blame is being shared not only from the standing banks, but also from the receiving bank. So that both need to check. So increasing the, the, the number of people checking if a transfer makes sense or not.
So I, I think it's very much top of mind, at least in the financial world, that this is a, a rising problem. Maybe it's not, um, top of mind across, across the globe for other people, uh, outside of, of the financial world. But it's very much one of the, of the biggest problems here.
Folks, you heard him here, ai, we've talked about it in the past. It's a double-edged sword. And bad guys are using it for all kinds of things.
So you gotta be careful out there. Pedro, thanks for being on the show. That's my pleasure.
All right. And thank you all for watching the latest episode of the Textron AI Leadership series. You can find this episode and others on our website.
We invite you to check all those out. Until then, we'll see you next time. Hey everyone, it's Alan Shimmel.
Welcome back here to another tech drunk TV segment. In this segment, I want to introduce you to Vivek Ram Charan Ramen chandran. I'll do the best we can.
He's gonna say it better than me. Vivek is the founder and CEO of a company called Square X. And let's welcome him here to Text Drunk tv.
Hi, Vivek, how are you? Uh, hi, Alan. Thanks so much for having me on the show.
Really excited and yeah, doing amazing today. Thank you. Hey, say your name right for me, just so we get it.
Vivek Hanran Ramen. Okay. I just can't roll those Rs no matter how long I've been doing this.
I can't roll the Rs. Anyway, Vivek, as I mentioned, you're the founder and CEO of square X. And we're gonna talk about Square X in just a moment, but let's, let's hear a little bit how you came to founded y you founded this company.
What, what kind of drove you to found it and kinda a little bit of your journey along with that. Yeah, so Alan, you know, I started my cybersecurity journey almost 24 years back. And, uh, you know, I was very lucky that I kind of fell in love with this space in the very beginning when I just started my engineering.
So the first few years I worked for companies like Cisco Systems in their engineering team, building security products. But very quickly figured out that, you know, I somehow had a knack for breaking security. So then I shifted gears to security research, found a bunch of vulnerabilities.
I've authored books, you know, which are still on Amazon, uh, spoken at DEFCON black hat 20, 25 times. And that was the time when I started my very first company where we ended up building a wireless monitoring device, primarily for defense agencies to go about, you know, monitoring what's happening in the air. Uh, and from there on, I went and, you know, founded my second company, pen tested academy.
And the whole thought process was, this was 2011, and a lot of folks did not understand how attackers worked. So pen tested Academy used to create these big labs for banks, financial institutions, where they could have their red and glue teams, which is really their attacker and defender teams do these collaborative exercises. Uh, ran that for eight years.
Eventually that got acquired by Providence Equity, uh, actually based on the East Coast. Took a little bit of a break and then started Square X around two and a half years back. Uh, and the whole thesis really was, you know, Alan, when I was running pen tester, I was talking to all of these red teams and they used to come and tell me, Hey, Vik, we are starting to see more and more attacks happen through the web browser.
You know, because if you think about it, you know, people are spending all their time in their browsers, uh, you know, doing transactions, doing work, you know, watching entertainment on Netflix and whatnot. So the browser was starting to become the new computer, the new endpoint, and attackers were taking note as well. So the inspiration behind Square X was if everything is moving into the web browser, then security should also become browser native and a first class browser citizen.
Uh, while today, you know, everything sits outside the browser, right? Your antiviruses, your eds and all, or everything is outside. So we started with the thesis that why not build a product which can integrate with every browser on any device, and that is really a browser extension, and that extension can monitor, detect attacks, block them, report back to the enterprise.
Uh, so we were very lucky that Sequoia Southeast Asia put in the seed check. And then Syn Ventures, you know, did a follow on series A round. And in the last two and a half years, we've raised around 30 million.
Uh, now we have customers, which are public market companies. We have one of the largest crypto exchanges deploying Square X. And now we are actively, you know, PO ving at many Fortune 200 companies across various industries.
Uh, because look, everyone has a browser. So anyone who worries about attackers, you know, unfortunately has to protect their browsers. And that's really what Square X is doing.
I love it. That was great, Vik, thank you very much for that. Before we jump, we're gonna talk about last mile attacks here in a minute, but before we do listening and, and I have, you are the first kind of browser security person I've spoken to since this problem or question popped in my mind.
I don't even know if you're gonna be able to answer it, but if you can, I appreciate it. Everyone. Today's talking about AI browsers, AI browsers, open, AI has, I forget what it's called, not Opus, um, Atlas.
Atlas. Atlas, excuse me. Yeah.
Atlas and Perplexity has one and Oh, yeah. And they're all coming out and, you know, is this going to be finally something that replaces Chrome? I don't know, is it really that big a difference?
Spoken to a lot of people who use them and I get a big man, you know, however, from a security point of view, yeah. Could it help? Is it better?
Is it worse? About the same? What do you think?
Yeah, great question. So I think, you know, Alan, I'll start off with the first piece that you mentioned is, you know, are these browsers going to become ubiquitous? Right?
And the best way answer is, you might remember the time when TVs had just come out with microphone and cameras, and we all said, we will never buy one of those. Yeah. And, you know, a couple of years down, that's the only TV available with microphones and cameras.
Yeah, Absolutely. So I think exactly that way, what's going to happen is all browsers are going to become AI browsers. And what I mean by that is, with AI starting to get integrated in all products, whether it's Chrome or Edge or you know, perplexity Comet or Open AI Atlas, everything is going to have that AI assistant run alongside with whatever the user is doing, help him, you know, go through massive amounts of information faster, automate a lot of his workflows and all of that.
So my current current, you know, vision around this whole industry is the only way that these AI companies can control the whole user experience is by owning the browser, because they can never own the endpoint. Microsoft and Apple have already done that, so this is going to accelerate. Now, the second piece are these browsers secure?
Now, typical Silicon Valley, you know, they love to go ahead and release products, which are early because they love to iterate. And, and this is really the DNA of Silicon Valley, right? Uh, and this is no different in the case of Atlas Comet and all of these ai.
So in the last couple of months since they've been released, attackers have started breaking these browsers down. We, ourselves, as a security company, have found multiple vulnerabilities. And just like in the early days when you had chat GPT, you know, go ahead and, and sometimes even say racist things and whatnot.
At this point in time, AI browsers are pretty much breaking in similar ways, lot of attacks and lot of exploits. Uh, my prediction is that, you know, similar to what happened with Chat GPT, Gemini and all of that, there's going to be a lot of fast duration, and eventually these browsers will start becoming more stable and secure. As of today, uh, I wouldn't say enterprises would be terribly excited to use these browsers, uh, because there's a lot more security plumbing to, you know, be built in, uh, for using enterprise.
Yeah. You know, that I, I've been in security also before it was called Cyber, right? Been in security 30 plus years, started a few security companies.
Unfortunately, this is an all too familiar story for us, like you and I who've been in security, security is always an afterthought. Let's rush it out. Let's get it out there.
You know, I'm reminded, I, it has to be. 15 years ago, I did a podcast, me, a friend of mine from Gartner and myself, and we had on the CEO of MongoDB and Couchbase, right? This is when no SQL databases had just recently come out, and they were all the rage.
And I, I asked these guys, I said, you know, a lot of people say no, SQL stands for no security. What are you gonna do about security? And, and the audacity, they, they just, they plainly told me on the podcast, right?
They said, look, we'll build in security when our customers demand security. Right now, they just want sequel databases. Yeah.
Nothing has changed. Absolutely nothing has changed. I want AI b browsers, what about the security?
We'll worry about that. We'll get to it. Yeah.
It's, it's, you know, it's, it's frustrating. It's frustrating, but I, I think as security people, we learned to, okay, maybe they don't think they want it right now, but they do. And what can we do to start hardening this, to preparing for it, et cetera.
Um, anyway, let's pivot back to last mile attacks. I appreciate you giving us your insight on that, but you know, not everyone watching this, Vivek is a security person. We have DevOps people and cloud native and uh, uh, all kinds, well obviously security, but AI folks and transformation and platform engineers.
Um, not everyone knows what we mean when we say last mile attack. So why don't we start with that? Why don't you define last mile attacks?
Yeah, so Alan, you know, taking a step back, uh, primarily the security stack today, which is going ahead and securing all traffic coming from the endpoint, uh, is really part of this big, you know, industry acronym called S-E-S-S-E. Yeah. And that's really where you have all the big companies, you know, uh, Palo Alto, Zscaler, uh, Netskope, whom not.
And the whole idea there was very simple is send us all your traffic coming in from your computer, from your browsers to our cloud data centers. We will scrub it, clean it, make sure that it is free of any form of security issues. Now, that promise was amazing at a time, probably around a decade back when browsers were simple website renderers and were not as complex as they're today, which is full-blown application platforms with multitude of new protocols, et cetera.
They're, they're the ux Exactly. The browsers become the ux. Yeah.
And that's really where, what last mile reassembly attacks is unlike the time when these technologies were invented where browsers could do little apart from show a webpage. Today, browsers have the capability to run code, you know, web assembly, high quality, JavaScript, a bunch of other embedded languages. So what attackers have started doing is traditionally what used to happen is, let's say if somebody were to send you ransomware as a malicious Excel file containing a malicious macro, which you would download, open it up and get infected, uh, in those days, your sass ESSE secure web gateways in the cloud would see a file is coming, pause that download in the cloud itself, one scan and see that there is a malicious macro and block it.
Mm-hmm. But now with browsers being able to run code, imagine that no file is ever sent, and the browser itself using JavaScript on the page assembles and creates that malicious Excel right there in your browser rather than send it from the server side. So now your secure web gateways and SS ESSE solutions never see a file because actually there is no file, the file is getting created live in the browser.
And the example I can give you the analogy for viewers is imagine that, you know, you are looking for some kind of a painting, maybe a Mona Lisa that somebody's trying to smother in. 0 secure web gateways. So last mile reassembly is, rather than send the painting, you're sending the painter so that the painter can come and then kind of go ahead and sketch the whole painting in your browser.
So if you purely scan for a file, you aren't going to see anything in the cloud because the file gets reassembled. Now, we can go about extrapolating this not just to files, but website, malicious scripts and whatnot. So all your old attacks, which were capable of getting caught in the cloud, unfortunately, are all new again, because they get reassembled in the browser.
So this is the big expose that Square X did last year at DEFCON main stage, and where we showed that existing every vendor is actually vulnerable to this architectural attack. And it is true even today. Absolutely.
Absolutely. I, I, whenever I see acronyms though, I always like to explain it for people who, who don't understand. When we say sassy, sassy like that, what do you, what does that stand for?
Yeah, so SS ESSC is this industry acronym, and the whole idea really was could you decouple networking, uh, basically from, you know, security. And this was something which was invented like a while back. So SS e is basically secure access, service edge, uh, you know, fancy way of basically, you know, adding both networking as well as security and SSE security services Edge, uh, that is really just the security piece of it.
Mm-hmm. So there are companies which do both networking and security, and they belong to the SASS e category, while s SES is pure security companies who don't want to do the networking, but rather just security in the cloud. Got it.
And when we look at Square x, new generation, a new way of approaching this problem, fair? Absolutely. Yeah.
Yeah. And the, the way we are approaching this, you know, Alan is, uh, for a very long time, the only way was clearly to violate the laws of routing physics. And instead of allowing a packet to go to the destination, you know, with the fastest route force, everything to go through these data centers of these sass, ESE players, fundamentally becoming a choke point, slowing things down massive latency, bad user experience and whatnot.
So the key innovation that Square X has done is, rather than having a proxy, we have the ability to look at all data, all user interactions, and all workflows in the browser itself. And this adds no latency, gives us a full 360 degree view of everything that the user is doing and everything that the browser is doing, allowing us to detect and block attacks right there, rather than sass ESCC, where all you see is network traffic, and you have to reconstruct what is happening at the application layer, which in today's complex browser-based protocols, unfortunately, is no longer even possible. And that is the big innovation that Square X has done.
Got it. You know, look, Jay Charge was in someone I know a long time in the security world, right? And when he first started Zscaler with the idea of running things in the sandbox before it got to your network, it was kinda revolutionary, right?
Absolutely. Yeah. Jay's made a lot of money from Zscaler doing that, right?
Certainly. And I'm not begrudging him, right? He's done a great job.
But you're right, there was always that latency issue, but that was the kind of the price you paid for, for security. Um, as things have gotten more complex, of course everyone's come up with a little bit of a mouse trap on it, a better mouse trap on it. When, when you say square X secures it, test, it, scans it, whatever you want to call it in the browser.
So is is Square X then sort of a browser extension, a plugin, if you will? Yeah. Yeah.
So Alan, the, the key realization we had is, you know, security solutions unfortunately can never tamper with how people work and should never get in the way of productivity. And that's really where our thesis was, that if you start to give people a new browser and things like that, it'll never work. You have to work with every browser.
And the only way to work with every browser is similar to your ad blocker, which works on Chrome Edge, Firefox everywhere, which is, it's an extension. So our key innovation was to go ahead and push the extension technology to its limits, where we were able to build a full security product as a browser extension. And the power of that is now we can deploy it in any browser, by the way, including the new AI browsers, including, so we actually secure Atlas Comet, all of them, right out of the box.
So I, I'm thinking about downloading the Atlas one. I'll be looking for the Square X plugin for extension for it. Vivek, I don't think we mentioned the website or anything, did we?
No. com, there's four letters. S qrx Q Rx yeah.
Dot com. Uh, it took me quite some negotiation, you know, with, uh, I would imagine it's getting a four letter domain, right? Yeah.
So that's the place everybody can visit to learn more. Excellent. Um, going to RSA.
Yes. So we did RSA the last two years, and we plan to be there, you know, this year as well, and every year, right before we, we, you know, do security exposes, vulnerability research and all of that. So we will be both at RSA as well as at Black Hat, uh, in the summer coming year.
So We're, we're at both as well. But check in with us maybe before RSA. Let's hear about your new research.
Absolutely, Alan will do. All right. Vivek, Rin, uh, here on text on tv.
Vivek a pleasure. Thank you for coming on. com.
We're gonna take a break here on Text Drunk tv. We'll be back in a bit. Hey everybody, welcome back to Ingram Micro One, and we're talking about AI and innovation with my good buddy.
Eric, how you doing buddy? Nice To meet you, Mike. All Right.
Welcome to the show. I guess a lot of folks are talking about ai, it was almost like ubiquitous here in terms of conversation, but we're still barely scratching the surface. So where do you see kind of like the potential and the immediate opportunity for partners?
Yeah, I think, uh, it's, it's a great point. And that's always where we see the start, right? It's this, uh, I think in the US you say drink your own champagne.
There are also other ways to say this. I prefer the champagne one. Um, now what we're seeing in the, in the partner base, um, is twofold adoption.
You see adoption of, uh, you could say the standardized, the productivity related AI projects that are, um, kind of, uh, um, um, generative in nature, right? So that's your, uh, meeting assistance. It's also customer service, uh, related, A lot of that.
So you see that internal adoption because all of them are resource constrained. Like there are very few partners here that are like, Hey, we have more people than we know what to do with Usually not the case, especially not in, in currently a market where the IT adoption, uh, and, and the speed of change is so fast that you want to, you can, you can barely capture all the opportunity that's there, right? So it's a good problem to have.
I'm not saying there aren't tough environments, but that's a good opportunity or a good problem to have. So how are they dealing with it? One, they're quickly adopting some of those, uh, kind of almost off the shelf, uh, AI solutions to focus on efficiency and productivity.
That's stream one that's straightforward. It is basically the fastest way for them to create AI fluency for every employee of an MSP of Avar of ai, right? Because if you use it daily, you create fluency.
But then the real projects that, that they're, um, that they're doing and that they're drinking their own champagne internally, are the first places where they're going into business processes and they're going ag agentic, essentially, and saying, okay, what's the first type of process where we have, and I use the word, I call it non-human value add, which might be a bit contentious, but what I mean with that is you have a process that requires action taking that isn't always deterministic, but the result of it is right or wrong. Once it's right, there is no quality to it. Once you've done it right, it can't be good or better.
It's just right. That's the starting point. And that's where we're seeing lots of partners focus and say, okay, what do we have?
It's not about replacing humans that we can essentially introduce a gen because we wanna get to the point where we're not just talking about generative ai, we're talking about AI that's taking action to give the, the, um, customer superpower. So that's the adoption we're seeing. What we're not seeing so much at scale are like the, you know, model, fine tuning, deep kind of model training.
We have partners that do this, but that's not the broad spectrum because it's, it's a long, uh, it's a long way to scale ROI if you're a, a smaller partner and a big investment to do this. And ultimately you have many other places that will get you, uh, an outcome and fluency much more quickly. And at scale, How do I navigate this challenge?
A lot of the business processes are to use what the AI folks will call deterministic, right? They're supposed to be done the same way every time. AI is probabilistic and rarely does the same thing the same way twice.
How do I kind of meld those two things together to get to something interesting? I think there, there are, again, two, uh, two ways in which to control this one, um, is you gotta have someone that controls model drifting in, in the broadest sense, right? The, the difference, uh, in the deterministic programming, which is input A, output B, that we've created those decision trees, right?
Even in customer service and support, when you were talking to bots, that's essentially a, a very large decision tree. Um, you're going to a, a place where depending on, let's take gen AI as an example, and like a service, a bot or something that's answering questions, helping with decisions. It's not just that it's deterministic, it's also learning through reinforcement.
So if it starts getting asked questions that weren't the initial expected ones, its answers over time will also start changing. So a simpler way to think of this is, like, I, I always say like, I send my kid to school. My kid has like his circle of friends, uh, his class, and I kind of know the behavior, right?
It's not gonna be perfectly deterministic, but I know who he is around what they talk about, what they like doing. Now imagine all of a sudden his behavior starts changing. Probably something in the environment changed, been exposed to a new group of friends, whatever those, they're having different conversations, they're doing different things, behavior changes without anthropomorphizing.
And that's the same thing happening with those more probabilistic and drifting, uh, AI model. So step one is make sure that you have someone looking that is kind of regrounding less about hallucination, right? 2, um, in this, and that's actually, I think, a trend that isn't just solving an immediate challenge, but that will be around in the long run, is human in the loop, right?
That's the straight up answer, right? You wanna ensure that you have a human in the loop. Not so much to say this is right or wrong, but really to ensure consistent improvement of quality of what those systems are doing.
And yeah, on the offhand, also making sure that doesn't go off the deep end, basically. So human in the loop will be around for a long Time. I think a lot of partners are looking for something easy to get started with.
Yeah. And you've seen some use cases out there that, um, might be easier to replicate than others. So, you know, what's your best advice to partners about, you know, here's something you can go do on a dime and it'll be, and it'll work out well.
Yeah. And you'll get that muscle memory you're talking about. Absolutely.
So, because we encounter this a lot, uh, at Ingram, we've created, um, basically a program, uh, to help those partners confidently sell, deploy and service AI solutions at scale and ideally in a repeatable way. We call it advantage enable ai. And it is what, what our partners can, uh, go and seek on the advantage platform.
It is aided by all our local expert teams. So they are being hand held. Why?
Right? The starting point is you need to understand as an MSP, as an si, as a var, where do I stand today relative to ai? Even if you've already built an AI practice, which in our experience has been, there's always a gap because it's changing so fast.
So what's my business understanding, my technical understanding, what's my service capability that I have? And not to forget almost the most important things, what is the current ask slash need of my customers? So example, I'm an MSSP, but all my partners, all my customers are talking about is using AI for productivity, right?
So I have a choice pivot and start also doing productivity related, uh, technology business hard forced the security conversation into the productivity conversation, which is valid, you should consider it, but it's going to prolong any implementation. And that dime will turn into multiples very quickly or wait until the first thing is implemented, something relative to, to productivity, and then fast follow. Okay?
So once that's done, the key thing is repeatable use cases focused on business outcome on select industries, because that's a language that every partner today speaks without an AI training can, can open up the opportunities. So what we decided to say, we focus on only three business outcomes, which is, yes, right now it's for ai, but it's the same for any tech. Either you're deploying it as an end customer to be more productive, more with less, more faster, any of these permutations productivity or to create a better experience for your customers, for your employees, for your suppliers, doesn't matter, or that, or you're deploying a technology product to shore up security, your governments.
Those are kind of the three only outcomes that are relevant. The reason that's important here, you talked about on a dime. 'cause in the first scenario, productivity, I can turn around a business case in probably three minutes.
Experience gonna be a little bit harder. We've all experienced that, right? Security is not hard, but it is cost avoided versus, you know, immediate benefit created.
Now, once you have this, and you map this to an industry, and we do focus on, um, manufacturing, retail, healthcare, finance, and now also public sector, you have the kind of, um, trifecta of I'm trying to solve a productivity focused business problem for somebody in retail using technology from OEMX. Not to mention that we're here today. Then you have a very clear path of what you need to do.
And what we're seeing there today is that all the initial lift, as boring as it might sounds, are quick productivity based wins in a very simple way. If you're using something like a copilot, like really taking that example, let's say you pay, I'm gonna use an arbitrary number, 20 bucks for a seed a month. Okay?
The first time you've saved yourself an hour of work, which will probably happen on the first day of usage, you're gonna think of that as that ROI 'cause an hour is probably gonna cost you more than 20 bucks. So that is very easy. But the, the crux is not just sell it, it's making sure that people know how to use it no different to past technologies and adopt it because that creates that tidal wave to move deeper into process and agentic, et cetera.
So as kind of standard as it sounds, it's creating those, um, 80% of time, 20% of value projects, first productivity to then go into 20% of knowledge worker time, 80% of value projects. Next, Ingram is clearly invested heavily in ai. How does the knowledge transfer between you and the partners occur?
Because it's not just enough to have something I can go and download and install, I kinda have to know something about this. So how do you know you guys take all the intellectual capital that you guys have created and kinda share that with the partners? Great question.
So let's say in two, maybe three ways. One is, um, my team's focused on internal Ingram AI fluency. That's not technology specific to ensure that over time every single person that works at Ingram Micro can help the partners understand and navigate basically what's happening with ai, not down to the technical level unless you have that role, right?
That's the first piece, because that's how it scales, right? We have over 20,000 associates and over 50 countries that are engaging these 160,000 plus partners. And that is the way in which they thoroughly, uh, in which they thoroughly can transfer that knowledge.
That's the first one. The second one is I spoke about advantage enable ai. So that's actually the digital, uh, the digital platform where they can find the assessment in their, their knowledge, the use cases, and then the repeatable, we call them growth tracks where they can build a practice.
However, that's digital. The way we do this is in every country, our local organization adds to it their local engagement. So they'll say, based on who the partner is, the business they're doing with us and the commitment they have to taking this AI transformation series, we're gonna add these workshop components, these certification components, which are human interlock, right?
So human in the loop, if you will. So we're doing the same thing, um, at a local level. This, this program is all the automation, scalability, and self-service side of it make it really easy to use.
And then the depth of knowledge comes through the transfer of our teams locally being involved from the business technical, all the way to the service tribe. Okay, Last question. So what's your best advice to the partners?
What should they be focused on right now? I think in English you say get stuck in, right? Uh, so, uh, I would say engage with us right now.
Come to enable AI and talk to your Ingram counterpart to it. Understand a where you are today if you don't have a strategy, understand where you are today and where your partners, your customers want you to be and what they want from you. And on that basis, build a roadmap that is very concrete outcome focused and not about the hype side of the technology, but basically understand where you are, build a custom roadmap.
And again, the advice is no different than on any other technology. Focus is what will make you win. If you really understand your customer, that could be their vertical, the geo they operate in, the cultural context they operate in, and then also are able to map the technology to that scenario.
You'll win. If you just have a great relationship, go golfing, go playing tennis, whatever that might means, your relevance will wane very quickly. That's been set for a long time, but with technology taking on really more and more proactive pieces, that is what's going to happen.
So I'd say get stuck in right now. If you're treated as hype or treat it as a bubble, you will not be around because nothing Has ever moved as fast as this trend. Alright.
Hey buddy, thanks for coming from, it was an absolute pleasure. Thank you. As say context is everything.
Thank you. Well, that's a wrap for this year's Ingram Micro Conference from us. And thank you all for watching all these episodes and it's been a great time on our behalf and I wanna thank Ingram Micro for having us, and hopefully we'll see you all next year.
Hey everyone, we are back here. This is, uh, I think gonna be our final interview for day one of Q Con and what a day it's been. You know, there's, I don't know, 10,000, 12,000 people here.
The, the expo floor is cavernous though, and cold, very cold. I'm glad I wore a heavy sports jacket. This poor guy's here in a short sleeve t-shirt.
You're not cold. I'm moving a lot today. So if I were sitting in a chair, you'd be cold.
I'd probably be cold, but I'm moving a lot, so I'm okay. Absolutely. But tonight is the, uh, what are they call it the cube?
The cube crawl or Whatever. Oh yeah. The coup crawl.
Yeah, yeah, yeah. The, you know, the, uh, They're gonna have drinks, food, everybody's gonna be hanging out in their Sponsor. Yeah.
There's a word for it. Yeah. But it's cube crawl and, and it's, you know, the, the in expo hall reception.
That's right. Yeah. That's a Good word.
Yeah. Hey, if you don't know this guy sitting next to me, you probably are not a big fan of Argo or, or, Uh, GI ops octopus, Gi ops Octopus Cube. He's, he's with us almost every single CubeCon I've done.
And I probably have done, I don't know, 18 of 'em, nine, Six. Yeah. This is my ninth year of coup coupons To a year.
Yeah. So you're right there with me. I, The only one I missed was the original one in San Francisco.
I missed that too. And I, ironic, strangely enough, I was like a quarter mile away from it when it was happening, doing really else. And No, I didn't, didn't go over there.
So I missed that one. But then Seattle, I think was that next one. Yeah.
And then San Diego wasn't there two Austin, remember where it was in Austin and it snowed. Yes, I do remember that. That's when I realized how big this was gonna be though.
Yeah. San Diego still. Well, I, I will say this.
San Diego and Valencia. Oh yeah, my two favorite ones. San Diego and Valencia were great.
Barcelona was good. Barcelona was really Good too. That might be, because Barcelona is a great Barcelona didn't start.
It's great. So I thought, I thought Valencia was a quieter kinder Barcelona. Ah, yeah, yeah, yeah.
It was kind of out there. It was like farther away. Yeah.
Yeah. Well, there's a little bit of like, the hype factory has kind of gone down a little bit because you have a lot of people have moved into the operations phase, right? Yes.
With this stuff. And so in the very beginning, there was such a push to like, we just gotta learn all the things and jump in and figure out what's useful and what's not. And now we're in that stage where a lot of people are like, Hey, we're operating, we're happy.
We're, we're scaling, we're, we're hitting the normal everyday challenges. I, you know, more than me on this. So I'm not gonna pretend to be an expert as you are.
But I really feel like, so first of all, at the beginning it was all developers. I felt it was very heavy developers, guys in t-shirts and backpacks. Yeah.
And Kube was so hard still. It was really hard. Let's face it.
Yeah. It was so hard. And people were not looking for lifelines, but they just wanted to learn more, talk to people like them, do that community thing to figure this out.
I think, I'm not saying Kubernetes is easy, I'm not saying cloud native's easy today, but it's certainly not as hard as it was. Yeah. But I also think, as you said, we've moved from just pure developers to ops people mm-hmm.
To platform engineers. Yeah. To SREs, to security people.
And, and so the audience, I, I would say let's even throw in now data scientists. Mm-hmm. Right?
And, and those kind of folks. So the audience has expanded, the product mission has matured, and the products and and projects themselves have matured. Oh yeah.
Where I think it's, it's just a more normalized thing. I I still think the passion is there though. Oh, Yeah.
Yeah. No, and there's, there's always new stuff happening and you know, a lot of the shift in this last couple, last two years has really been about supporting GPU workloads, AI workloads. So there's a whole Yeah.
There isation happening there, but you all are doing a lot of stuff on cost savings on Yeah. Upper productivity. So that's the efficiency phase, right?
Yeah. You always, first you try to just get stuff to work and then you make it more efficient. And then somewhere right after that you say, oh, we gotta worry about security too.
Um, which is a problem. Well, I, wait, we gotta stop a second. Second.
Sorry. I didn't give you a proper Introduction. So you don't know.
This is Dan Garfield. Dan Dan has, look you pioneered Argo in a lot of ways in GI ups, right? Yeah.
Um, Argo is now of course part of Octopus deploy. Yeah. Argo is a project, is maintain, Argo Is a project CNCF.
Yeah. It's maintained by Octopus deploy, uh, red Hat, Intuit, others. And so we have a partnership with a number of different companies that we maintain the project with similar to Kubernetes.
Absolutely. But I do, I do think there is a special fit because Argo the octopus, you got an orange octopus and you've got octopus deploy. We're blue octopus.
So we're, we're like, I got blue ox, Blue and orange, uh, go Together, bring me an orange, lemme burn you, I guess. 'cause this is the commercial entity. Yeah, that's right.
Yeah. Yeah. So I got the blue one.
But, um, and I should mention, if you don't know, and you, maybe you don't follow this closely in hope, you know, um, Argo is the out of over 200 I believe projects now in CNCF Argo is number three right behind Kubernetes itself and, uh, open tell o hotel. Yeah. In terms of like contributions Yes.
And activity and velocity, project velocity, yeah. Number three. And, and Oel, uh, is so generalized, right?
It, it really touches everything. So it makes sense. And, and Kubernetes of course is the foundation.
Sure. So those two make sense, but how do people deploy to Kubernetes? 60% of the time they're choosing Argo CD and number two isn't close.
It's down in the 10% range. Really? Yeah.
'cause there's a whole, there's, it's like everybody chose Argo cd and then there's kind of a sea of other things where like they're using Jenkins and they've just always used Jenkins, so they haven't moved on from it. And they're throwing coops tail applies using that. They may have good reasons to do so, but, but yeah, agreed.
When we look at the marketplace, that's what we see about 60% of clusters are using Argo CD today. And, uh, and some vendors, some clouds, it's more, but yeah, we, we see pretty big adoption. So Let me ask another question there.
If you are using Argo, are you by definition doing GI ops? You are definitely facing GI ops Now, whether or not you've actually implemented those principles, you can use Argo CD in non-GI ops ways. Uh, so for example, if you're using, if you're referencing images using floating tags, you're kind of not really full, you're not really embracing GI ops.
And you can definitely, um, use Argo CD with manual sync turned on. So you don't have automated reconciliation. So Argo CD is pushing you towards get ops.
It's encouraging you to get a good do get ops, and it's the best way to do get ops in my opinion. But you can also, uh, if you wanna hold a hammer upside down to hammer in nails, you could do that. It's just the tool doesn't want you to do that.
But you could do that, You know? So I'll give you a life lesson. As I've gotten older, dad, the tools make the man and using the right tool for the job is all the difference in the world.
That's true. Yeah, that's true. So you, you know, you wanna keep using the hammer upside down.
God bless you. But life's too short to do that. I I agree fully.
Yeah. Yep. Yeah.
So I, I wanna get into some of the announcements. You guys have some of the news coming outta this. Yeah.
But before we do, I I, I want to kinda solidify the, so we spoke about Argo, the partnerships of running, maintaining Argo. Yeah. You are part of Octopus Deploy though, right?
Yep. That's right. And and they're though Octopus Deploy is a maintainer of Argo.
Yeah. And a large part of their business, I imagine is, you know, in, In Argo and Kubernetes. Yeah, that's right.
But Octopus Deploy in is in and of itself an entity. Yeah. Talk to us about Octopus Deploy with Argo as part of it, but nevertheless its own entity.
Yeah. So the, the history here right, is you have, the Argo project is created by Intuit. And, uh, they said, this is the way that we wanna deploy software.
There's a number of other tools within Argo that they were using as well. And they said, we really want somebody to take on the mantle of running this thing. And so they looked to us Codefresh at the time.
Now Octopus Deploy. But, uh, they looked to us to, to be that group. And so we became the first commercial vendor to come onto the project, help it get into the CNCF, help it, uh, go through the process of graduation.
And, um, to take on that stewardship as, look, we're gonna have a commercial interest in this open source project where if you're using Argo and you want to do scale deployments, ar Argo CD really has one job. Look at a source of truth and get, and get that deployed to the cluster. Everything else is kind of window dressing right?
Now, what if I wanna manage a change from one application to another? I want to promote something. Well, that's where, that's where Octopus Deploy comes in.
What if I need support Octopus deploy? What if I need, um, help doing architectural planning about how I'm gonna roll this out? Octopus deploy is the answer, right?
So, so as a commercial vendor, we have an interest in maintaining that stewardship of an awesome open source project. Uh, and then providing, uh, both tools and services to help you be successful with that project. The great thing is, because we maintain the project with others, Intuit and, uh, and Red Hat Acuity, we cannot any of us take that project and go and just change the license suddenly and say, Hey, we're gonna take a bunch of features out.
Uh, instead we have to focus on something that's gonna work for all of our interests. But that's, that keeps us Honest, Foundational, it's beautiful. It's not, you can't decide.
I've got a Secrets program, I'm changing the licensing of them. Yeah. I wanna, I wanna make money on the ui, I'm tired 'cause I'm gonna provide a, a better version.
So I'm gonna make sure the UI sucks, you know, for the user. We, we can't, we, we can't do that stuff. We don't wanna do that stuff, obviously.
No, But, but that, again, look, I've been in the open source game a long time. That is the beauty of this foundational model where that rising tide lifts all boats. But no, no one company can, can manipulate this through their own financial gains.
It's a super important point for governance. And it also means that we have a sustainable program for development. So for example, we offer enterprise Argo support.
Yep. Now our business octopus is really driven by selling our software, right? That's where we make our money.
And, uh, so the way that our enterprise support program works is, hey, we're off you in enterprise support, but basically that funds our open source work. Yep. So, a as we add more, uh, enterprise support, you need to, you need help with Argo CD or something goes wrong in the night with Argo rollouts, you can call us up, we'll help you fix it.
Uh, if we need to provide a patch, we'll do that. But this is the way that we fund, uh, our open source contributions. And of course, that also feeds into one of our biggest customers is the Octopus platform.
Because if, if something's not working for a customer, they may not care if it's Octopus or Argo. They just want it to be fixed. They want one throat to Choke.
Yeah. So it, so that way, um, you know, any of our customers are essentially funding these open source programs and, uh, making sure that they can be successful, which is, uh, you know, it's nice to have Yeah. But it's, but it's really important that you have a sustainable approach to open source.
Otherwise you're just borrowing somebody's time until they don't have Time decide they don't wanna do it anymore. Yeah, exactly. Or they want to put the squeeze on them.
Monetize. They gotta Change that license. They gotta, they gotta get, Look, I saw this in security 20 years ago.
Yeah. You know, with, and, and look, to be fair, let me just play devil's advocate a second. Yeah.
Please. Do You get people who put their heart and soul into these open source projects? Absolutely.
You know, single company maintainer, they maintain a community where 96 or 97% or more of the people don't pay 'em a dime. Yeah. Won't even beta test or report bugs.
And it's kind of thankless. Right. And then you've got, and what really kind of, in my experience with kind of tips it is then you get other commercial entities who come by, use this open source tool that you've put your blood, sweat, and tears into.
Yeah. And they're monetizing the heck out of me. Yeah.
Taking money away from you in essence. Right. And I think for a lot of, uh, for a lot of folks, that's where that's the, the straw That's the bridge too far.
Yeah. Right. And so they, they do do things like changing the licensing or, you know, making it harder for other people who they consider almost like parasites.
Yeah. If you, you know, I don't blame, uh, companies that need to change their license. They're the, they're the only ones maintaining a project and they're like, look, we can't pay to fund this development.
We have to, we have to find a way to make it sustainable. Totally get that. Um, I'm really proud of the fact that we've been able to build this ecosystem with Argo, where we have multiple maintainers.
Yes. Where we all have good interests. That, Well, again, that's the foundational model.
It's a cooperation model. And it's not just vendors, it's it's End users organizations. Into, Into, it's an example, right?
Like, they're not selling Argo services, they want you to file your taxes and manage your money stuff. Exactly. But for them to be successful deploying their software, they rely foundationally on Argo to do it.
It's so it makes sense for them to invest in it. It's key. Uh, and then it makes sense for us as, um, to be good stewards of the project because ultimately that's the ecosystem that, that, uh, is, is paying The bill.
Absolutely. Alright, we're running low on time, so let's turn, Okay. What's news?
There's a lot of news, uh, in the Argo project. 2 just came out this year. We shipped Argo CD three.
Okay. 2. That means all of Argo CD versions two are now out of support.
They're gonna start stacking up CVEs and bugs. They will not be fixed. A lot of people have not yet upgraded a three.
This is not Java. You do not run it for 10 years without upgrading. You move to the latest version, uh, At your own risk.
You wanna stay on that old stuff, you know, at your own risk. Yeah. And obsolete.
Yeah. And what we're talking about with, uh, the shift from Argo two to three, we made that a, uh, an arc. So we made very deliberate changes that would be very easy to upgrade through.
And almost all of the behavior that's changed in Argo CD three can be changed back to two X behavior. We have a great upgrade guide to help you do that. So that's new.
That's exciting. We've got new maintainers. We just added two additional really maintainers from Octopus Deploy focused on Argo cd, uh, who, who just got promoted on Thursday and are now maintainers Congrat see them.
Yep. They've, they put in the effort. Give shout out.
Yeah. Uh, you Eugene, he was walking around here. Just a second.
You have Guinea, um, as well as, uh, as, uh, pat Close, um, who wasn't able to make it this week. Yeah. Gh what's his last Name?
Uh, den? No, not the, we have Evgeni who comes on our show once in a while, but Yeah, he's, he's fairly new. But, um, we've seen these new maintainers do a couple of really great things.
Patro close. He did a big migration in Argo CD to move GI Ops engine back into Argo cd, which is a massive project. He worked with Lee Ferment into it to get that done.
Did a great job. 2 because, uh, the version and get changed. And he was able to track it took three weeks to figure it out, but we got it done.
So won't be hurting users anymore. We're allowed to see that. So that's going on on the, on the community version of Argo cd.
Big stuff happening there. Uh, and of course, as I mentioned, we offer our enterprise support for Argo, our technical account management, where we do proactive stuff, but we also just shipped a lot of new features in Octopus to improve your experience with. Oh, very cool.
So if you wanna stage out, you know, uh, for example, let's say I've got 10,000 storefronts. They've each got a Kubernetes cluster, they each have an Argo instance, and I want to orchestrate promoting and managing all those Argo instances. I can do that with Octopus.
If I wanna manage deploying new versions of my software to all those versions, I can do that with Octopus and That. And that's the, so historically that's where a commercial company that's maintaining an open source project makes their bones. Yeah.
You wanna scale to that level. It's hard as hell at, you probably could do it at some level using just the pure open source. Yeah.
You can write a lot of scripts, a lot of glue, but you've got a great foundation with cd. She's why you Do it. Right.
You know, it was the same thing. Remember back in the cloud BS Jenkins days, right? Yeah.
Cloud Bs knew that when you ran, I forgot what it was, four, four instances of Jenkins, you were probably ready for Cloud B'S enterprise. Yeah. Right.
Because that's the scalability that I think are in there. Yeah. And it's similar.
I mean, you could, of course you can manage. I, I know people that have 50,000 Jenkins instances and they're all 10 versions behind. Well, There is That because they, they didn't take a proactive approach to managing it.
And that's, that's difficult place to be. Uh, but yeah, there's the not only scalability, but usability and, um, user experience, things that we've been able to add. So those are new features that we've brought in to Octopus.
Now for those that remember Codefresh, of course Codefresh is still running CI and we've got these other, uh, components, GI ops things that we're doing. But, um, bringing in a lot of the learnings from that platform into Octopus, uh, as a unified platform is something that we're doing right now. And we just launched that, uh, very cool for Bup Con and, and people, uh, have been using it and building on it and growing with it.
And it's based on a foundation that's, you know, a decade old at this point because it has the ability to do all of your traceability and your, uh, governance, tracking, you know, compliance stuff as well as all of these scalability features. So it is really nice. It's a kind of a peanut butter jelly.
Best of both worlds coming together. I love it. Situation.
Dan, we're almost outta time. Two things I need you to tell 'em. Number one, people who wanna follow with Octopus Deploy and what's going on there, what's the website?
com. com Number two, Argo people who are into the, the project, they could go to GitHub, they could go to the CNF. Yeah.
Or they could go to Argo unpacked. This is our new Argo podcast. We've done, I think, really episodes now.
We have 1500 subscribers. We just lost it. It's a big on YouTube.
We have 1500 subscribers. That's beautiful. Uh, which is awesome.
And of course you can subscribe to that on your podcast app. Favorite podcast, Argo unpacked. We talk through technical issues.
We talked through strategic issues, cultural, philosophical as it relates to delivering software using Argo CD using Argo rollouts. And we love it. Uh, yeah, we're loving that new show.
Alan, appreciate you Mrs. Garfield. He did a hell of a job here Today.
I'm gonna late this time. Have a wake this time. We're proud of you, Dan.
It's good to have you. Thanks a good luck continued success and keep doing what you're doing, man. Thank you.
Appreciate it. Dan Garfield here on Tech Drunk tv. We're gonna take, well actually that's gonna wrap up day one.
We'll be back tomorrow with more. I've got some parties to go to. This is Alan Shimmel.
We're out. Hey everybody. Welcome back to Gram Micro one.
We're talking with my new friend Sophie here about what's happening in the channel in France. Sophie, welcome the show. Good to see you.
The partners, I'm sure have lots of challenges. There's a lot happening in France these days. Yeah.
But when you talk to them, what's keeping them up at night? So they have to face a lot of winds right now. So they think about the, the way they can be innovative in this market, which is slowing down because of the fact that the budget has not been voted yet.
So all of the public sector, or most of the sector budget, uh, project have been frozen. Uh, enterprise tends to delay abit their investment. So in front of this, uh, tough market situation, it's important for them, first of all to streamline their opex, uh, see how they can be more efficient, and also to, to, to accelerate their performance.
So they're looking at it with us. So it's all about how can we standardize the processes, refocus our teams on the added value task so that we can create mutual value. We've also seen that a lot of the end customers in France are probably navigating all kinds of economic issues themselves.
Yes, indeed. And they're probably looking at the partners for some help as to maybe how to streamline things and be more efficient. Exactly.
And uh, so then the purpose for the resellers is to see how we as distributor, we can help them, uh, meeting their partner's expectations. So it's important for them to be able to leverage our technical resources and our human resources. So it's all about what we are talking about right now.
Mm-hmm. One of the things that we're talking about here at the show a lot is there's a shift a little bit to focus more on business outcomes. It's not enough just to be a trusted technology advisor.
I have to work with the end customer. I have to know something about their business a little bit. Is that playing out in France as well?
Yeah, of course. So now we are all looking at the way we can, um, create better value for our partners, uh, for their own partners. And it's based on all of the artificial intelligence we are leveraging through our platform.
We have talked about it a lot right now with, uh, and Sanjeev on stage talked about it even more this morning. So how can we accelerate the performance? How can we increase the breadth?
How can we leverage the new tools? We have, uh, Sanjeev talked about the digital assistance, intelligent digital assistance we can leverage to do that. We can use, uh, and finally what I think it's, we can talk about artificial intelligence, but first of all, it's about human intelligence.
How can we have the right purpose, uh, in our discussions? There will always be some human in the middle of that process somewhere, right? There will always be fortunately, right.
Hope so. Um, I guess the question I would have though is things tend to roll downhill in this world. So are the partners leaning more on you for certain expertise and professional services because they can't always find that talent or they might not wanna invest at something that they Yeah, yeah, Yeah.
So the kind of service we are talking about, we were so far talking about professional services, for example, around the cloud, around cybersecurity. But I think that more and more we will talk about new services consultancy around how can we all leverage this new technologies, how can we leverage artificial intelligence, uh, in the way we can all increase our overall efficiency? And they need also our experience to do that.
Right? So, uh, Tiffany yesterday talked about the fact that we need to use energy as a service. So I, I kept it in mind, uh, what is the narrative, uh, beyond artificial intelligence?
Because what we see is that we all are using artificial intelligence for our own purpose, but what are the, the true, uh, use cases in the enterprise, right? How can we really streamline the workflows? And I think that most of the partners, they are not very clear on that yet.
So they need us to be trusted advisor and accompany them in this motion. As that occurs in every country that I talk to, there seems to be a skill shortage. And for the partners, it's almost do acute because I need technology people who are customer facing and friendly customers.
So how does Ingram work with them to kind of find that kind of unique unicorn in the IT landscape To, to find what kind of unicorns, Uh, IT people who are have, uh, who can talk to customers and explain things to them and are very, uh, have a lot of empathy for the customer? Yeah. So you mean how do we find this talent or it's not that easy to find this kind Of talent?
Yeah, that's my, that's my question. Yeah, Because it, so even in it, the, the, the job is really shifting a lot right now, and we are less relying on the skills than on the soft skills. So it's about, so it's a combination of IT skills and, uh, the, the ability to create the right synergies with the salespeople so that we have a common language to the people and to be to the customers.
And to be honest, in France, we didn't find the right profile yet. For, for fortunately we can rely on the global resources. All of the people from SANJEEP team can really help us.
Then we still have, uh, to deal with the language issues. So we, we, uh, leveraging the local re the global resources from an IT perspective and leveraging our local resources for the sales purpose. So it's a good combination.
France, of course, is part of the eu. Is there more transactions spanning multiple borders? Are they partners working with each other in across Europe, or is they, are they still pretty much focused in their particular country or?
No, it's still really focused at local level most of the time. So what we see is the complexity doesn't come so much from the fact that we have to interconnect different countries, even if it can occur. But the complexity, complexity comes more from the, the, the fact that when we deal with project, we have to combine different technologies, different skill sets.
So, and we need sometimes to connect different partners to each other. And for that, the platform advantage is made for that. It's a, it's an ecosystem which is made to create mutual values between the vendors, the customers, and also to onboard some customers on the same project and be complementary in their skills.
Are their partners becoming more open to that level of alliance with other solution providers? 'cause sometimes, at least historically, they always kind of view each other a little wally because they think they're competitors. Yeah.
It's interesting to see during this event, for example, we are here with 10 French partners, and during lunchtime, even during the dinner, they start talking about the, their skills, their experience, and to see how they could, uh, be complimentary and work together to compete with some big players. Right. And it's true in the mid, mid-market area, in the SMB area, Of course, we're here in a show, and I don't think you can go very far without running into somebody talking about ai.
And we talked about it earlier, but what's the level of enthusiasm in the, among the partners for ai? I mean, are they kinda studying it or are they, are they all in? No, they are not all in yet.
So it's, it's, uh, they're wondering exactly what it means correctly, right? Because while most of the people, they know what they do with charge GPT, for example, for their personal life. Uh, coming back to the enterprise, uh, beyond ai, there are a lot of questions around what, as I mentioned before, what are the concrete use cases, but also from a security perspective, how can we make sure that we have the best usage, we usage of it without compromising our data?
So for that, we need really to explain them through our own AI factory that we can secure their data and that can, we can provide the right added value and, uh, and contribute to their business development without of course compromising their own security. Um, one of the themes of the keynotes here has been this whole notion of using AI to make it easier to do business, not just with the partner in Ingram, but from the partner to the end customer. Yeah.
Do you think that we're gonna see like a significant reduction in the amount of friction that has historically been in those processes over the years? Yeah, yeah, I think so. If you take the, what makes the job of a distributor right now, there are still a lot of, let's say, low added value task around the quotation management, for example.
And it creates a lot of workload, a lot of burden, uh, even from a financial perspective. So if we can remove it, remove this kind of friction, if we can, um, accelerate the, the time to market of the quotation, if we can have a really, really, uh, a full digital process from the catalog ingestion to the, to the, to the invoicing, imagine how, how qualitative can be the discussion afterwards. Because now we still have to talk a lot about, do, did you get my quotation?
What is the price? When will it be available to me? Uh, did, uh, do you know when I will be delivered?
For example, if all of the information is available on the platform, then we can really start talking about strategic initiative. How can we build the future together? So I don't think that artificial intelligence will make us less close to the partners.
It's exactly the opposites. The more we'll develop it, the more time we'll have to, to, to develop qualitative discussion and, uh, to, to really, um, build the future together. We might have time for a drink and dinner to discuss something rather than In France.
It's very important, you know, to have a very good glass of wine and talk about the business, of course. Is there something you wish the partners would be focusing more on? And as you kinda look at them and you talk to them, I know they're all different, so it's difficult to generalize, but as you kinda have those discussions, is there something that you kind of, you know, would wish the partners or some piece of advice that you would give them and say, folks, you need to spend a little more time on this.
I don't think I'm the right person to give advice to my partners, because we are all on the same boat, all facing the same, of the same kind of difficulties. You know, the problem with this deep transformation we are going through right now is to deal with the day-to-day operational issues. We have the, with the business pressure we have as well.
So we need to deliver short term outcome while transforming in the longer term. So the advice I would give is to try to combine both, sorry, and spend enough time, even one, two hours a day to keep thinking about how the future will look like and how can we, uh, foster the right dynamic internally to have the right talent, thinking about the way they can streamline workflows, the way they can create more values for their own partners. And it's easy to say, it's not easy to do because it's about the purpose.
We need to reassure all of the people about how the future will look like. Each time we're talking about artificial intelligence, you know, that there is a fear behind it. Will we lose our job?
Will we be less, uh, intelligent in the future because we fully rely on artificial intelligence? What will be our added value? What about the, the enablement?
So we really need to all think about it and see how we can, first of all, I think really first of all, drive the right purpose. What is the storyline behind it? What do we want to get out of this artificial intelligence capacity?
Mm-hmm. So we started the conversation with what's happening in France today. We're kind of at the end of the year.
As you look into 2026, you know, what do you think will happen? What is your crystal ball telling you? So in 26, so, you know, for me, AI is like the, the way we were talking about clouds 10 years ago.
You know, we have talked a lot about cloud. And finally, between the time we have started to talk about cloud and the time we have seen concrete, uh, outcome from a business perspective, it took a while. I think that in 26 we will start, first of all to see two motions.
First of all, our partners customers and even ourself being very much more concrete in the way we can leverage this ai, uh, technologies. And on the other end, start seeing some real business opportunities around it. Uh, while so far we have seen some very big deals, uh, around ai, uh, some solutions, uh, embedding Nvidia, for example, but we didn't see in the SMB in the mid-market area, we didn't see really the integration of this AI opportunities from a business perspective.
And I hope that in 26 we'll start seeing it conquer. Of course, another big part of this channel equation are the vendors themselves. There was many of them here, they have boots.
Um, is there something that you wish they would understand about the channel in France and the partners in France a little bit more than they do today? What they need to understand is that it's important for them as well to standardize their processes. Because if they really want to keep benefit of all of this new, um, platform or digital platform opportunities, they need to accompany us as well by providing us the right access to their data, by standardizing their own processes, breaking some silos so that we can really all together make it much more fluid and, uh, the added value for them will come out of it as well.
All right. Hey folks, you heard it here, France. It's a funny thing.
They have a different word for everything, but they have the same issues we do. Hey, thanks for being in. Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series.
I'm your host, Mike b. Today we're with Tim Sprecker, who's the CEO of the Hub. And it's a company that's kind of dedicated to making it possible for people to sell slivers of their network bandwidth to folks who are training AI models.
And it's kind of a, an effort to democratize that process a little bit. Tim, welcome to the show. Hey Mike, thank you for having me here.
It's a pleasure to be here. Well walk us through how all this works and what's going on here. I think people have gotten used to the notion of maybe selling a sliver of their storage, but maybe no one thought about their network bandwidth.
But how did you guys build this and how does it all work? Yeah, so let's start with the fact that today as AI has hit one of its biggest bottleneck, it's not compute, but data AI models now needs high quality, multi-model and fresh data that truly reflects how the world operates. And the problem is that today the data is fragments log behind silos or simply tool, resource or local quality.
That's why at Hub, our mission is to turn the world into a distributed data infrastructure. And how we do that for a globally distributed network of nodes that leverage the idle bandwidth and residential ips of users, our end to infrastructure collects, refines, annotates, and deliver multimodal data streams. What we means by multimodal it's video image and audio to poor AI systems and AI training at scale.
One, our core is also our ability to collect large scale of public low quality, messy type of data and transform it into gold standard adult assets. And we all know that data is the foundation of ai, yet it's a hundred billion dollar market that still lacks the scalable end to infrastructure. And that's what we're building at Hub.
And we have the opportunity also to discuss that after. But we also closed our recently with Swiss as investor. We are now entering the, the C round.
We are based in San Francisco. We are working, uh, here with, uh, a couple of companies from, uh, tech startups to also monitoring some deals with top 10 tech companies. So there is a lot of learnings from that and a lot of demands also from this company that we're happy to serve through the distributed network that we're building.
Hmm. How does somebody sign up for this? Is this something like, is it a consumer and can, uh, somebody in their house kind of share their bandwidth?
Or is this more of a corporate kind of play where somebody has excess bandwidth? So, uh, on the bandwidth sharing side, it's purely a B2C play. So it can be anyone with a device, uh, especially at the beginning.
It'll be launched on desktop only and fun after that. But it can be someone that go, uh, with his desktop, he can download either browser, browser extension or desktop application. And thanks to that we can get access to their, to his network setting.
3% only not impact the user experience, plus the residential IP of, of, uh, this user to be able to collect public data at scale. So small orchestrator, we can get, uh, send some kind of scrapping comments, scrapping job to the device of the user to collect public data. Is there a, a time element to this?
'cause I may need more bandwidth in the daytime, but I may not be using it at night at all, and maybe I can resell that to you. Is that part of the equation? Yeah, totally.
Based on the current bandwidth that you're using, we are also adapting that, uh, of course if you are running a 4K movie, it'll not be the same, uh, as if you're just looking for your email. So de definitively based on that, we also adapt, but it'll always stay very low because the thing that we wants to avoid the most is really to impact the user experience, who could be, uh, uh, very bad for the network and very bad for the, the, the user experience and the retention of the users. So that's something that we always make sure to have because we know, for example, some v VPNs sometimes are too heavy and are maybe slowing down the, the connection that you can have.
So us, that's something that we wanna avoid. Does it also matter where somebody might be physically located? Does somebody need more network bandwidth in say, California than they might need in, I don't know, rural Ireland or something like that for training AI models?
And does that factor into your thinking as well? Yeah, there is something that we call the, the network score. And so the net network score is a, a computer of, uh, computation of different things, including the bandwidth power of the users, the quality of the internet connection he has, but also the geo distributed factor.
So for example, depending of the moment of the year or just like depending of a general use case, there is some part of the world that are more interesting than others. Or if at some, at some moment we find some kind of, um, uh, big difference between two regions of the world, maybe we balance a little bit, reduce a little bit the reward on one side and upgrade a little bit the reward on the other side to make sure that the network is always, uh, globally distributed based on the use case we have. So yeah, it has, uh, it has an impact.
It's not a big thing, but it can have, uh, an impact on the network score. So how does the pricing work on this? Is it a flat fee or is it very widely based on, uh, the level of congestion and maybe there's something called congestion pricing at work here, The pricing is mainly done on the network score that we just discussed.
So at the beginning, starting with a point system for the users, uh, when it'll be live, so the user earning points, but those point, those points will vary ba based on the network score that they have. So if someone is, uh, having like a very high speed connection in, uh, uh, maybe North America or Europe, he will earn more than someone that could be, for example, with a low quality connection in Southeast Asia. That could be the kind of things, because one of also the, the moss that we are building, we through this network is the fact that we're distributed because, for example, sometimes the same information is not the same.
If you look at it online like a, a simple website, if you look at it from like, uh, one part of the world or another, you might not have the same price. You might not have the same copywriting, the same, uh, the same image. You might not have the same message at the end, uh, displayed on the website.
So that's why for us, the show distributed factor is important. And also sometimes there is some kind of, uh, blockers for the, for the scrappers. And it's important to, to face those blockers to also have this, uh, geo distributed factor in place On the people who are consuming these services, the people building the AI models, how do they invoke this and um, and why would they go this route versus maybe trying to lease lines or do anything else that they may need to do?
Yeah, so basically for them, the fact that the network is, is not something that they're, uh, really value. What they want to know is are we able to get this data? Are we able to get it at scale and at the fair price?
That's for them. What, uh, what we're selling them. We are usually not going into too much details about how the network, uh, network works for them.
We're really focusing on that. And so because this network, we're just talking here about the data collection parts, but also one of the big modes of hub and one of our, let's say, uh, expertise is not only on the data, data collection is really on all the pipeline that comes after. So the data processing, the refinements, the annotation labeling, qa, and then the delivery to those CI companies, because of course hub data, uh, data that you can collect still has some value for those companies.
But why they also want to work with Hub, because Hub can own the full pipeline for them. And so they don't have to work with free or four different, uh, um, third party providers, uh, to do each step of the pipeline for them, or they don't have to create a whole that we build the pipeline for months before being able to train their AI models. That comes to HUB because data collection is done efficiencies with this kind of mechanism, but also because HUB can under all those parts.
And that's also why, uh, hub has this early success on the B2B pipeline here in San Francisco. Are there any concerns that the internet service providers may look at what you guys are up to and decide that they wanna throttle some of this because you know, they're trying to reroute bandwidth all the time? Or is there just a lot of access bandwidth and nobody seems to care and we just need to find a more efficient way to use it?
Yeah, no, no issue from that, from the different discussion that we have and from the benchmark also that we have, especially because what we're using is a bandwidth that is usually wasted to, uh, bandwidth that's usually going to waste. 5%. So it's a very small amount of the bandwidth, which not like create an overall load, uh, for this, uh, yeah, ISP.
So where do you go from here? What's next for you guys? So HUB is life since two years and a half ago.
First started with more like social tools. We created, uh, an AI agent this year. We had a massive success with that half a million users on the platform.
I, I think that we've been the first one to gamify AI training on social networks. So it was like an interactive experience where the users were replying on Twitter to the AI agent to created. The results were crazy.
We had at a point like 100,000 replies per tweet, uh, on the agent, which is something that we never seen on on Twitter. And so it was the first step for us of this narrative of me as a user, as a hub community member. I'm sharing some data, uh, to the agent and to train ai.
And in exchange I'm getting some points, which is the same narrative that we have now with this distributed network. And what's next for us is to launch this part of the network. So we already have the pipeline working with data centers, ips, we already have the first customer sign, the first revenue coming, but now the next step will be this quarter to launch this distributed network.
We decided to first walk backwards from the end customers, from the AI companies before releasing it. So when we release it, we already have a business model. We already have a strong, uh, revenue coming.
And also for all the learnings that it created on what we said just before, what comes after the data collection, what we do with the raw data. And a lot of the, the current infrastructure has been shaped by those, uh, previous customer. And so after that, we have a lot of exciting things also in the pipeline for this year.
Uh, we want to do, uh, also some data crowdsourcing system. So currently the user, it's like a passive contribution to network. They just download the app, they put, uh, they switch on the button and then they wait.
The are getting points and we're taking the bandwidth. But for some cases that we see, especially with enterprise customers here, sometimes they want some data that are not, that are just not publicly available. And so how can we collect this data?
It can be done also through this distributed network of people because it, we could be done through some Quest or gamified mechanisms where, for example, they have, uh, they have like a mission out today. You take your phone, you go in the suite, there is like a car in the suite, a sport car. It's a, we need the 360 videos of those cars for like 30 seconds.
Then they can upload it on the, on the platform, getting some points in exchange. And at the same time, us, we are able to create some kind of data sets that are not publicly available and that are very valuable for the sale companies. So that's the first thing that we have in the pipeline that we call for now data crowdsourcing, but potentially another in the future.
And then another thing that we want to do, uh, for next, uh, for next year is a decentralized kind of human in the loop annotation and qa. So, uh, raise and working with third party, uh, company, uh, we will be able to also some network members, some users to do some kind of create annotation, uh, quest to review what our VLM, our vision language models are doing with the annotation side up to that. So that's how we go from passive to active contribution.
So do you think as we go forward that the training of AI models is gonna become a lot more distributed than it has been up until now? And I think a lot of folks were kind of pulling data, loading it into some massive data center and trying to figure out how to throw GPUs at it. But I think we're moving towards smaller AI models that need to get trained and they need to get access to data that's more recent.
So is the way we think about training changing? Definitely. And I also think that on the market we'll see more and more needs for high quality data and a lot of, uh, the training in the past has been done, uh, with like low quality data or just with textual data, sometime outdated.
And now we see the AI training going to more like, uh, multimodal as we say, like, uh, video image, audio. And especially also as you say, smaller models that are more specialized than LLMs, for example. So one of our customers currently in companies, they want to open new market and they are just being blocked because they don't find the high quality data that they want for the specific language and the specific areas of the world.
And that's how, uh, HUB is currently being helpful for them on the data collection part to everything that we do after to goes from low quality to height quality for their AI training. And I think that this is something that we will see more and more, um, going from like bronze or silver grade into always trying to reach for gold standard for, for pre and post training. Well, you heard it here folks.
Sometimes we overlook some of the fundamentals in networking being one of them. And there's another way to think about skin in this cat though, so that you don't have to necessarily buy huge networks for yourselves when you can leverage up a service like this. Hey Tim, thanks for being on the show, Mike.
It was the pleasure. ai Leadership Insight series. You can find this out.
No, lemme try that all again. Thank you all for watching the latest episode of the text. Join that AI Leadership Inside series.
You can find this episode and others on our website. We invite you to check all those out. Until then, we'll see you next time.
Good morning everyone. I am Heather from Influx Data. Today we'll explore how time series data has become the foundation for lots of DevOps operations and why it's pretty critical as we enter the AI era.
Your applications will generate millions of data points every second from server metrics to application performance, user interactions, and API calls. So traditional databases weren't exactly designed for this volume of velocity of timestamp data. And this is why 10 series databases like influx have become pretty essential to infrastructure.
They're purpose built to handle high cardinality, high velocity data streams that modern applications, especially AI applications tend to generate. And today I'll show you exactly why through NetApps transformation story. Before we dive into it, let's establish why you know, site reliability engineering has become even more critical.
It blends software engineering practices with operations to deliver more reliable services. The core philosophy is to automate yourself out of a job using automation to eliminate that manual toil. But here's where AI changes a lot.
Traditional SRE practices were built for predictable and more deterministic systems. But if your web server fails, it will fail in predictable ways. If a database goes down, you get clear error messages.
AI introduces fundamental unpredictability and a language model might start generating much lower quality responses without throwing any errors. And token costs can be very expensive at that point. So model updates will also silently change behavior without obvious failures.
How are you supposed to keep a track on this? So this means that waiting for systems to break and fixing them simply don't work for AI workloads. You need proactive time series based monitoring that can detect subtle changes in behavioral patterns, cost trends, and performance degradation before they impact your users.
Let me share a perfect analogy for modern SRE that comes from NetApp team themselves. Picture children playing the balloon game. Everyone's running around trying to keep balloons from touching the floor.
The balloon represents your service when it's airborne, you have UPT tie. When it touches the ground, you have downtime. Traditional monitoring tells you after the balloon hits the ground.
But with time series monitoring, you can detect when the balloon is falling, even when you're not watching. This becomes absolutely critical with AI because they can fail silently. A model might not dee in gradual ways that you would expect, or costs can just creep up slowly and it doesn't traditionally alert you as to why that is.
And time series data will give you that early warning system. It's the ability to see trends and patterns that predict failures before they happen. Now let's talk about how to measure reliability in the AI era.
Using three Q metrics that work for both traditional and AI services. Service level indicators, which are SLIs measure actual performance for traditional APIs, this might be response time or error rate. For AI services, you're tracking token generation speed response quality scores or inference latency.
The key difference. AI SLIs have much higher variability and require baseline establishment across different model types and prompt patterns. Service level objectives or SLOs set your reliability targets.
Here's some pretty crucial insight for ai. You deliberately avoid 100% targets because you need an error budget to experiment with new models and techniques. AI development requires constant iteration and to perfect reliability would prevent that innovation.
So an error budget is calculated as 100% minus your SLO. It provides unreliability tolerance. Here's what's kind of fun about this framework for ai.
Both infrastructure failures and problematic model deployments consume the same error budget. This forces teams to balance AI innovation with system reliability in a very measurable way. And this framework becomes your decision making tool.
So when you're considering deploying a new model version or adjusting prompt engineering, you can evaluate that risk against your remaining error budget. It transforms AI operations from kind of a gut feeling to a little bit more data driven. That's what we're here for.
So let's talk about NetApp. How do these concepts work in the real world? NetApp is a $6 billion Fortune 500 company with 12,000 employees primarily known for a data storage and infrastructure.
You probably are aware of them, but what makes their story compelling is that they represent the challenge that every established enterprise faces today, maintaining legacy systems while rapidly adopting AI driven development workflows. At the same time, this is not a startup experimenting with ai. This is a company with decades of critical infrastructure that customers depend on.
Now building cutting edge AI tools for their developers. They could not rip and replace their existing systems. They had to bridge the gap between traditional operations and AI native workflows using time series data as that foundation.
So their transformation demonstrates exactly why purpose-built time series infrastructure is essential for the AI era. The heart of this transformation lies within NetApp's engineering tools and services system. The single team manages an incredibly diverse portfolio that perfectly illustrates our connected world.
Challenge. Traditional data on tap build forms, common test lab environments, continuous integration testing, and now gen AI services. Think about the operational complexity here.
They're running legacy build systems that have worked reliably just reliably for years. Alongside all this experimental stuff, they manage AI driven code reviews and vs code co-pilot integrations at the same time. This diversity represents the reality many organizations face today.
You meet a monitoring strategy that can handle both predictable and unpredictable workloads with the same infrastructure. Let me show you the true scope of what NetApp was trying to monitor with traditional tools. Look at the scale.
Traditional CTL applications managing 32,000 compute nodes and 35,000 VMs processing 100,000 hours of testing monthly CCIT applications handle 800,000 hours of testing per month, processing 17,000 submissions and preventing 135 code verts monthly. These reverts represent commits that would have caused prediction issues. And then you add n AI apps, 14 different LM models and internal LM proxy for cost management and an AI driven code review.
Notice the pattern traditional infrastructure with predictable patterns. CICD with deterministic testing and AI services with completely variable behavior. This is exactly the connected world challenge that we mentioned at the start.
Millions of data points per second across completely different types of workloads needing unification before their transformation. NetApp faced the exact problems that traditional databases create in our connected world. They stored custom metrics and relational databases that weren't exactly optimized for time series queries.
Uh, engineers relied on traditional Linux tools. Top, um, HOP isat for system monitoring. Nagios provided basic alerting for them.
As NetApp described it, when all you have is a hammer, everything looks like a nail. Every alert just appeared really critical. So there was limited context.
Engineers experienced significant alert fatigue and started to ignore it a bit. But here's a crucial insight. Um, this approach completely falls apart with the new AI workloads that they had.
So you need granular visibility into performance patterns, cost metrics, and behavioral changes. Traditional databases just simply can't handle this volume and velocity and cardinality of AI monitoring data. NetApp evaluated several solutions and made a strategic decision that proves my earlier point about purposeful infrastructure.
They chose influx, a time series database as that foundation. This decision proved crucial for AI workloads with 800,000 hours of testing per month. And now AI inference requests with highly variable patterns, they needed a solution optimized for that.
AI monitoring generates significantly more diverse metrics than traditional infrastructure. Model performance varies by prompt type, user, region, and of course time of day. So you need a database architecture designed for this complexity from the ground up, and that is what influx excels at high cardinality data with fast ingestion rates, efficient storage compression and very fast craze across time ranges, whether you're looking at the last minute or the last year for historical data.
NetApp's architecture demonstrates how to build unified monitoring for these diverse workloads. At the center is InfluxDB Enterprise with multiple data nodes and meta nodes for high availability. This ensures no metric loss and outages critical for post-mortem analysis of any kind of incidents.
Telegraph agents collect metrics across everything, traditional servers, databases, and AI services. The agents' lightweight footprint and extensive plugin ecosystem, which is free by the way. It means that they can monitor legacy systems and modern AI APIs with the exact same tool.
The flask risk. API manages custom metrics and outage tracking Jenkins integration allows test results and AI model performance metrics to flow directly into influx connecting CICD pipelines with the operational monitoring. This unified approach means you don't need separate monitoring stacks for AI and traditional infrastructure.
One-time series database handles both workloads effectively. NetApp discovered five critical challenges when adding AI workloads all solved through time series monitoring request and response variability. AI inference can vary from milliseconds to tens of seconds for the same endpoint.
So the solution is to establish separate baselines for different models and pay like payload types using historical time series data Inference costs, uh, like input tokens can cost a little bit differently than output tokens. Really depends on how you're using it and who you're using. The solution is to monitor the token counts, the request sizes and output lengths to control those, cross those costs proactively.
Instead of reactively silent behavior changes. Model updates can alter outputs without very obvious failures. So the solution is to run canary prompts periodically to just detect that drift, which I think is probably one of my favorite parts of the solution that they put together.
Multi-region complexity, which is 14 models across regions, can create hundreds of failure combinations. And the solution here was to do granular monitoring data that's filtered by model region and calling service, um, which can become a cardinality problem that they eventually used influx for. Here's the result, NetApp's reservation.
65%. 8 seconds significantly above their baseline and sent a Slack alert within 10 seconds. This rapid detection pipeline works works completely identically for AI APIs.
Token usage spikes, response quality degradation or model timeout issues trigger the same alerts, same framework, same tools, unified. The next, uh, transformation kind of proves the points here. First, you know, time series databases are pretty essential infrastructure for our connected world, especially with AI workloads generating unprecedented amounts of data volumes and cardinality.
Second, you know, SRE becomes more critical with AI because traditional monitoring approaches will fail with non-deterministic systems. You need these proactive pattern based detections. And third, that unified monitoring does work.
The same S-L-I-S-L-O error budget framework applies to both infrastructure and AI services when you have the right time series foundation. So if you start with a purpose-built time series infrastructure, you can adopt the SRE metrics framework and then recognize the AI requires that different approach. But most importantly, and what I want you to take away from today is to not build different stacks.
It is a monster to try to wrangle. And NetApp, um, has really done an excellent job with their own architecture here to figure out a better way to not make it be so cumbersome. They prove that unified monitoring across diverse work workloads is not just possible, but it's absolutely essential for all of their AI native operations.
Here's some reminders of the tip specific to AI request and response times variability can make that latency unpredictable. So establish a historical track record, generate baselines for different types of payloads across different models. Remember that inference is kind of expensive.
It depends on how much you've played with this, but if you have as much as I have, you'll understand that that is true. Monitoring the request size, output length and average tokens per query can establish the baseline and look for the patterns that need those cost reducing controls. Frequent model and dependency changes can silently alter behavior.
So create a set of canary prompts, then run them periodically to find swings in behavior and pinpoint those problematic releases. Um, the challenge of managing multiple models and regions simultaneously, especially across the world, um, means that you should get granular in your monitoring data and dashboards to easily tease out problematic combinations of models and regions. You might find that, uh, this will proliferate in different parts of the world differently, not just because of your network, but because of your user base and your security level.
The challenge of dev teams rapidly exploring and building AI tools without SREs initially. Hey, I'm definitely one of those people guilty of that. Um, the advice here is to make trade-offs on working with a stack that you inherit versus your SRE monitoring stack.
I guess in this case, if you can migrate your data to influx, then troubleshooting might just be faster for you. If you're interested in some resources to learn a little bit about how influx works under the hood, we've got Community Slack and forums. We have docs also powered by AI with any questions that you have, um, that you can't find the answer to and is powered there.
And if you're interested in doing a little bit deeper dives in each of the topics around Time series data, InfluxDB University is free. You can sign up for it there. That's all I have for you today.
Thank you for joining me. Hey everyone. Are we in a state of AI high anxiety?
I love Mel Brooks. You're watching Text On Gang. Hi everyone.
Happy Monday. Hope you had a great weekend. You know, it's gonna be a short week for us here at The Gang.
It's Thanksgiving week, always one of the nicest weeks of the year for me this year at Little Sweeter, both of my, my sons will be home. It it'll be good to have a a house with the boys home. Again, little buffer between me and me aggravating my wife.
So it's always good to have her have them home. Um, we have a great gang here for this Monday for you. Let me introduce you to them.
We have Jack Poller, IRA Winkler, Jeff Reich, and joining us after his cameo with Kon Chris Short. Chris, great to have you join, join the gang officially here from the studio. Gentlemen, it, it's great to see you all.
Mike, as usual, we got a lot of AI noise and news and it, I don't know if it's news or noise or both, but why don't you kick us off? Well, let's jump into this 'cause everybody's closely watching what's happening with AI agents and, uh, AWS but a little help from IDC published a report saying that well, organizations have deployed on average 10 of these things. Now, they're generally not customer facing, they're a little more on the operational side, but we're all watching this closely because, well, if you look at the NVIDIA numbers, as great as they are, basically it's four companies buying up all the GPUs in anticipation of the fact that, well, we're all gonna use AI agents, we hope because, well, the first round copilots was interesting, but it's kind of difficult.
The issue now is are we gonna use AI agents and how quickly are we gonna adopt them? And to what extent, because the survey kind of suggests that people will not fully roll these things out, at least half of folks anyway till 2027. Some folks are being a little more aggressive than that, but there's a lot rioting on this, Alan, it seems like the whole IT industry is making a big bet on this one thing happening.
So is it gonna happen and what's your take? You know, I, I did a shimmy says on this last Friday, Mike, uh, I call it AI jingga pull one block outta this tower and the whole thing comes crashing down. And I think that block is open ai, but you can go watch my shimmy says, or read my article on text strong AI about why I say that.
But a, as to this survey, I'm gonna call bs, right? I think the fallacy or the, or the soft white underbelly to this survey and to this report is how we, how do we categorize an agent? To me, an agent is something that goes off and does the, does things autonomously.
There's a difference. I I don't consider copilot necessarily an agent at this point. I think it's, it's more of a chatbot, right?
It's more generative than agent. Yeah. Alan, let me say because when I read this study, there's a very different, like, you know, my bias that when AI is everything, AI is nothing.
And a, and AI agent is one of those, by definition is an entity pretending to be a person providing customer support of one thing or another. Like if I try to get online and talk to Delta Airlines to say, I want to change my flight to, you know, to Tulsa, and they're like, oh, we would love to help you change your flight to Tucson. You know, that's the typical AI agent by definition.
Then there is a agentic ai, A agentic AI implies that an a software tool. 'cause at the end of the day, it's just software with certain algorithms and functions that an AI is taking read, making a decision and taking action on its decision autonomously. And that is, you know, that could be, for example, switching a railroad switch as an example.
Now the problem is, I read the study and I was like, are they using it for help? And you mentioned, for example, copilot. If I type in a question and it's answering, is that an A, you know, an AI agent?
But the problem is, I think we don't have a clear definition, which is number one. And then there's the other aspect. If they are talking about agentic ai, which is completely possible, I think the people survey suck, and I think the people in the survey had no clear definition of what they were answering as well, in my opinion.
And some people might have thought AI agent talking to, replacing a person helping, or there could have been some software tool making a decision, which frankly are many software tools, AI or not. But what are the guardrails? And I didn't see discussions on that, and it's two different conversations either way.
So I'll leave it there for other people to discuss. But that was my concern with the study. I'm, I'm gonna support with a research study that, um, we had IDSA did, um, in the middle of the year, and it wasn't about AI specific, but we had AI questions in there.
And two points I wanna bring out that I don't think have changed since July, which is when we did this, first of all, 11% of, and this is across the board, CEOs, CISOs, security engineers, answering the survey, 11% say we have complete, fully documented and communicated controls around use of AI in our organization, whether it's agentive or not, 4% somehow believe they're saying they don't allow AI in their organization. I don't believe them. 56%.
We have some controls in place, but not enough, and we don't really, we can't really control what's going on. I think that's, that's the underbelly we're talking about. That's here.
Even though organizations may be using ai, whether project or not, they're simply using it. It's like they're getting in a car not knowing how to drive, not knowing what the roads are gonna be or how to make it stop. Well, Jeff, let me expand quickly, but you raised a point though.
They say they're not using it. They are using it, and if they don't know they're using it, they should be fired. Because ai, and I use this is embedded in every technology out there.
If you get in your car, there is an algorithm that is creating a route for you to go somewhere that is theoretically an AI agent of some form or ai. But I, I mean, it's embedded in anti-malware, it's embedded in autocorrect, it's embedded in Siri. You know, people say they're not using it, and if they say they're not using it, they should be fired the world according to ira.
So, Chris, Let me come back To you here for a second. Regardless of, you know, how they define AI agents and, and whatever it may be, the concept is that they are not gonna fully roll this out till 2027 and it's gonna take a little while. Is that gonna be enough to sustain the investments that we're seeing in AI today?
Or is this gonna play out at, at a much longer curve than people are anticipating? Well, that's very interesting questions. I think yes and no, right?
Like the, the clouds currently have a backlog of customers asking for these, you know, chips that are getting made for Nvidia, but by TSMC and there's only so much capacity. So there's a backlog right now. And if folks are waiting a year, well, a month to 16 months for their AI projects to come online, well, I think they're gonna miss the boat on some things, right?
The technology is evolving way faster than, uh, the traditional enterprise release cycle. So you're either going to be, you know, on a old version of something for longer, or you're going to have to learn to adopt and embrace, you know, rapid release, rapid testing, all of these other things that are, you know, key to innovating and, uh, making the most of your AI tools. So the, the idea that these big projects are gonna happen and they're not gonna be rolled out to folks for years is concerning from a like supply chain side, because timing everyth, there's going, is everything gonna a dip in the market?
Mm-hmm. Then yeah, it would make sense that the dip is now when chips are short. So I would agree with you from the supply chain side, but from the demand side, it's actually, I think 2027 is being very optimistic.
You know, I have, uh, a friend who's a sales engineer, lead sales engineer for a, uh, a regional CSP, and they said, well, we have to get into cloud. So they tasked him with figure, sorry, get into ai. They tasked him with figuring that out.
And so he said, okay, well let's go and buy some machines, stick some GPUs in it, and then it's okay, now what do we do from here? And everybody right now is very lost. If you, you know, I think, I don't know if I've said this here before, but I said it plenty of times before that.
If you think about what we think, if we task somebody with going out and rolling out a virtualization infrastructure or a container infrastructure, there's a well-known, well understood recipe for how you do that, right? Today, if we task somebody with rolling out an AI infrastructure stack, there is no well-known recipe. It is very hard.
There's no, it's, and it's not only the hardware infrastructure that's not understood, it's the software infrastructure infrastructure. And how do you get to a point where you can actually then go and put some AI agents out there to do something that's black magic for probably 75% or more of organizations today? And I don't think that's going solved soon.
Yeah, because no, what I'm saying is that it, well, taking a step further from Jack, it's not the hardware, it's not the software, it's also a data infrastructure because AI is about the, so the making decisions from data and an organization needs, for example, a chief data officer to go ahead and make sure the data is accessible to all the software that needs to pull it to make good decisions. And without a data infrastructure, you're not gonna have any other, the other infrastructures are gonna be worthless. So, Ty's Ty's point, though, it is entirely possible that some of the folks answering this survey just said, yes, we're using AI agents because they sent out an email to somebody and said, Hey, are we using AI agents?
And somebody said, yeah, sure, but then, you know, we just checked the box and said, you know, just tell the boss anything he wants to hear. Right? Well, but I, I think there's also the difference that I pointed out between AI agents and agent ai.
They're not necessarily the same. However, here's the thing, I don't know if we're gonna roll our own agentic ai, and I think that's the, that's the exponential difference between maybe generative AI and rolling your own LLMs and doing your own training and all of that stuff, versus using someone else's agent in an agent AI way, sort of a Salesforce agent force or ServiceNow agents or any of these agents. These are pre-rolls, right?
For all my friends in states where cannabis is legal, these are pre-rolls, you just light 'em up. You don't have to roll 'em, you don't lick 'em, you don't worry what's in there. It's already, you know, it's a, it's a, and in many cases they may be rather ephemeral, they may be single use, but persistent, but they, they're limited.
They do a job, they do a particular task and they do it autonomously, but there's not a lot of infrastructure you are going to build into that. Maybe set up an MCP server, something like that. But I, I don't know if they're going to be building their own stacks here.
Is, is I guess what I'm saying. Uh, you know, Jensen Wong spoke about this. Uh, I, I caught it.
It was one of these when the Saudi prince was here, and don't even get me started. But anyway, Jensen WG said something about, you know, we're gonna have a whole new class of, of AI apps that use these agents different than the apps and the infrastructure we, we have today with it. So, you know, when people say, do we have 10 or more AI agents?
I do think there's some of the IRA thing in there. Of course we do. We have that HelpBot for people who want to go from Tucson to Tuscaloosa or whatever.
But, uh, you know, truly agentic ai, yeah, you're gonna have 10, eight of them will be from Salesforce and three from ServiceNow. And, and, but I don't think that's here. I have a hard time believing that's half of organizations today And or at least, you know, I think it's, we're not sure what an AI agent is, so therefore everything that looks like it's AI is now becoming an agent.
Chris, is that where we're at? Uh, maybe I think there is some over rotation on, you know, people calling things AI agents, and they're not in the traditional sense or the sense we're talking about, at the very least, uh, AI agents. So that thing on your website that helps you, the, the search tool, like everything could be considered an agent.
Uh, when you think about it in some degree, however, whether it's actually using the large language models underneath the hood, that's a different story. I know I've been to many websites that have a little chat bot thing that pops up and it's completely not intelligent, right? Like it's, it's, it's literally a phone tree replacement kind of thing That it's more of a BPA, right?
That, that kind of thing, right? And, and as Iris said before, right, never, never confuse AI with intelligent. Um, anyway, hey, we're over time on this particular segment.
We gotta take a break here on the gang on this Monday. We're gonna come back and we're gonna talk about AI high, uh, insecurity re not anxiety. You're watching Text Drunk Inc.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're gonna have a little chat about, well, what is the future of cybersecurity in the age of ai?
Jack Poller has a column up on Security Boulevard that you should all check out talking about. Well, the attacks now are being launched by machines, and that just changes the game altogether. But Jack, go ahead, explain.
So I, there are essentially, you can think of this, there are three ways machines can be involved in an AI in particular involved in the attack side of the cybersecurity equation. And one is what we would traditionally call red teaming, which is where you attack your own infrastructure to find holes in it and help your blue team, the defenders figure out where they need to be better at defense. Uh, second way is you could be a real attacker and attack somebody.
And the third way is you could be the, uh, military or government institutions and using AI as part of your attacks against other nation states. And we sort of see th all three of these coming to light this week. Uh, red teaming is, I think more AI being used in red teaming right now is more of the business process automation that out was alluding to in the last segment where we're trying to figure out how to accelerate our red team activities and enhance them.
And also to look at how red teamers attack AI agents and other AI infrastructure that we've put in place. Uh, and then there is, uh, a company recently called 20 who goes by, uh, the double X letters XX or 20, uh, that we received, uh, large investment and large contracts from the Pentagon to ostensibly do, they're not very public right now, but based on their hiring, it looks like they're hired to do offensive operations on behalf of the US military and US government. And then, uh, anthropic has claimed that they have discovered an AI initiated an automated attack sequence, uh, that was used using anthropic to attack other organizations, particularly, uh, Claude code, uh, was used.
And, uh, they claim that something like 75% or more of the entire attack operation was fully automated and autonomous with, uh, humans in the loop mostly to direct targets and validate, uh, specific points in the attack chain. And that it was now, we're now getting, uh, AI driven attacks that are now going to ramp up in the attack itself in a speed and scale that's gonna be hard for human defenders to respond to. Yeah.
Um, so I, okay, so my background is in red teaming, NSA, the, like this fra this is nothing new to me. In all honesty, we're looking at companies, for example, the difference between a red team and an actual threat actor is intent. And when you have companies, for example, that have been around, you have, for example, Pantera Horizon three, you have lit, you have a whole bunch of other automated attack companies that are coming out, sorry, not attack companies, red team simulation companies that are out there.
You know, this is kind of expected because what computers do is automate repetitive tasks. A lot of red well intrusion is based upon frankly just searching for massive opening or just searching massive infrastructures for openings, finding a potential vulnerability to get in. Once you're in, then you start digging in and so on.
And a lot of it is just, you know, this whole conversation is really the inevitability of what we're doing. Now, the concept of ai, and I use my Dr Evil quotes here, is because you're able to go ahead and maybe make decisions on a fuzzier basis than a more straightforward acting basis. 'cause really AI I'm oversimplifying is advanced statistics and it's just acting repetitively to get in.
Once it finds a vulnerability, it automates it. Maybe a agentic AI like, and takes the next step. But then you have a person to say, yes, I like that data, or Yes, thank you for identifying all the vulnerable servers.
Here's the servers we really wanna focus on. So the downside is, and I'll just say this, China has been the most egregious. And what I mean by that is they don't care.
The other threat actors actually don't want to be detected because the problem with this massive use of AI is that you are more likely to be detected, you're more likely to be stopped, and I'll just leave it here and let other people talk. But at the same time, there's also the ability now with threat, you know, continuous threat exposure management and tools like that to automate and start detecting these things. You know, so far the good guys aren't as efficient as the bad guys, but I'm hoping that the good guys start automating the mitigation of the vulnerabilities.
The bad guys are attacking. I, I think this is a case of AI being a tool and people using the tool, how tools are used, right? Like a machete is very good at cutting down foliage, but it's also a tool for other things, right?
Just like ai. So automating things and having it run semi autonomously, I think is just going to be the future essentially, right? If you want to do something at scale and do it quickly, you're gonna tell the computer to do it for you versus trying to do it yourself manually.
So if folks already have a foothold in your infrastructure, it now becomes even easier for them to say, okay, let's xFi things now versus, you know, having to maintain a persistent presence for a while, go unnoticed and then start expelling things. Uh, Chris, if I can add on to what you're saying when you're saying it's a future, I think the future is, uh, okay now, because I, I believe we're already there with that. And I'm gonna use an analogy.
Um, and I'm not saying here's a good old days when I learned to program, when I first started programming, it was on holler earth cards, 80 column cards. And I had one test run a week to check my deck to make sure the program ran and it failed with a sock seven or anything else. If ask your grandparents, um, if it failed with that, then you had to wait another week to get another test.
So you did what's called desk checking, and you look through those cards, I don't know how many times I would look through every deck at least 50 times. Now a developer writes a program and they can just run it in the system because it's close to free. And if there's an error, it tells you.
But if it runs successfully, they say, well then it's good. But they don't, it doesn't include regression testing and it doesn't include what all the unintended consequences. And I think that's what you're referring to.
That's the downside of this. And back to IRA's comment as well, the downside to this is it's great, it's faster, it's automated, we can do things better, but it is simply a tool and it also means that if we do things poorly, we're gonna do them poorly much faster. So Ira, IRA, what is the role of the human in the cybersecurity teams, if this is a machine versus machine battle at this point, and you know, are we just gonna sit back and watch it happen?
Well, the thing is, you gotta start looking at what are we doing at a high level? At a high level, these things do what you tell it to do and somebody's gotta tell it what to do. It's gotta tell it what the targets are.
It's gotta tell it what type of data, even if it could sort through data quickly. It's almost like reverse data leak prevention. We have to start figuring out, okay, what are we looking for?
There's also task management and intelligence operations, somebody who's doing the collection, management, doing the tasking of the people and so on. We also need people to write the tools to begin with and write the ai because a lot of people are like, oh my God, it's ai. It thinks for itself, it doesn't think for itself.
It implements algorithms that a person tells it to implement. And these algorithms are designed by people and you have to see what are the good strategies. And at the same time, in this whole attack chain, there's also the defender aspects.
When you have attacks at scale, those are easier, much easier to detect. And it means that people have to step in and be there to step in to stop it. Because, you know, again, this was detected all of a sudden.
I'm sure somebody at OpenAI looked at the stuff and said, wow, look at this. Usage, usage is really up. And it's almost like the cliff stole thing.
If anybody remembers the cuckoo's egg, how did he detect the whole East German intelligence? It's like a 37 cent error sent him down a rabbit hole because somebody was overusing the ai, they're overusing the assets and these are noisy. The thing is to automate in stealth is much more effective than to automate, like what was just happening.
I was gonna say one interesting fact that came out of the, uh, the, the anthropic attack was that anthropics AI actually hallucinated, uh, data for the attackers and it hallucinated identities that it claimed existed and that it had compromised, that it had found compromises for when in fact it didn't. They were false identities that it hallucinated. So it actually sent the attackers down a path that was not successful.
Is that part of the defense? Now? I Well, no.
What Responsibility do these companies have now, right? Like yeah, That would, well, But here, here's the thing guys. Let's, let's ground this in reality.
What are we really talking about? Why should people out here care? They care?
Because like it or not, the bad guys and whoever, however you want to define a bad guy, whether they're a red team member or a real bad guy, you know, working for the Chinese or, or whoever, the bad guys are using ai, they're using agent ai, they're getting better at it. They're learning how to use this tool to be more effective. The tool itself is progressing to be more autonomous and do these things.
And it is going to be stealthy and its scale, stealthy end at scale because it, that's, that's what the, this AI can give you, right? That those kinds of resources, right? You have multiple workers, you don't need as many people in the loop.
You may still need a human in the loop, but not many humans in the loop. And so how do you fight this? How do you defend this?
Well, the only way to fight this AI onslaught and defend against this AI tsunami is you gotta use AI itself. You got to use AI to fight ai. You gotta to use AI to defend against ai.
You're not gonna be able to match human to ai 'cause the AI will quickly outstrip you. There's too many of it, there's too many GPUs out there. There's too much.
We need automated AI defenses against automated AI attacks. And I'm not trying to create some new missile gap here or cold war kind of thing, but that's why it's important. We, we need to realize it and move forward.
Well, you mentioned missile gap and that kind of sparked something in my head as far as the, the current economic situation that we're facing, the economic contest that we're facing with AI between the west and China, essentially, I say the west in like the 1980s term. Um, but the, the thing we're gonna see is that folks are gonna use these tools, they're gonna advance with these tools and they're going to start competing at a higher level, right? Yes.
This one instance we're referring to, you know, the AI hallucinated and that could easily be why they were discovered, but someone's doing that right now with AI and they're not being discovered and that's a big problem. Well, cybersecurity is not about perfection to begin with. Cybersecurity at the overall is about risk reduction at the end of the day.
And that's how it needs to be phrased. Because the fact of the matter is, and you know, everybody's gonna say, well, I don't have the AI to fight against it going back to like com. My comments on like the first block, you know, again, you're gonna have tools that are gonna be able to detect this.
The problem is a lot of people don't want to use tools that are available. These people are not, you know, these attacks are not unstoppable attacks. They're volumous looking for the one hole among many potential holes.
And what's happening is, is this is a case where, you know, I don't have to outrun the bear, I just have to outrun people with me. And in most cases the ai, unless it's a highly targeted attack, which some are from nation states, I give you that. But for the most part, they're gonna go after the organizations that are not enabling the technologies that are available from whatever cloud providers, whatever SaaS providers they're using.
Much like the Snowflake attack. If anybody remembers that where Snowflake was hacked, it's like no Snowflake users who did not turn on MFA were hacked. And so we need to start looking at that because all this AI is gonna find these vulnerabilities, which anybody could theoretically find if they had the resources, but it just does it more at scale.
But the people who are reasonably secure are mostly gonna be protected against this 'cause they use the other resources that are there. Agreed. All right, well, budgets being what they are, I think you guys are saying things might get worse before they eventually get better.
Who Knows, they might. Hey, but we gotta take a break and move in the C block guys, we're running along, we're running late here. You're watching Text Drunk Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
Hey folks, we're back in. While the eu, arguably the only authority in the world that's now investigating anything, is taking a look at Amazon Web Services and Microsoft to see if they are dominating the cloud marketplace. And it's kind of interesting 'cause one of the things that has come up over the years is that surprisingly the main services that most people use in these cloud services, the prices don't seem to change all that much.
And when they do, they seem to all perfectly align where every cloud service provider has the same price for every service. So Chris, what's your take on what's going on here? Well, we've got quite a few things happening here in, in terms of like the EU apparatus of government.
Uh, one is the Digital Markets Act, which, uh, has a provision in it that considers, you know, critical bottlenecks as quote gatekeepers, which need more regulatory requirements. Um, antitrust folks are also involved. So there's a bunch of things happening here, but it's particularly interesting in terms of the past couple months we've seen AWS Azure, CloudFlare, a bunch of other folks just go offline or, you know, in AWS's case, cut off half the internet, it felt like cloud fire's case same.
So all of this has happened very quickly, and the EU is very worried about its dependence on foreign services. And I think, you know, when you look at the world we're in today, Europe has had a wake up call in terms of cyber activity going on in Ukraine between Russia and Ukraine. And they're starting to realize a reliance on a single source is not good.
We already have talked about, uh, you know, sovereign infrastructure as a thing in the EU that's mainly being driven by this need to be more self-sufficient. So they're trying to mitigate risk and as well as trying to get their markets in order so that it's not so easily dominated by one or two or three providers. I I, I agree wholeheartedly, Chris.
I, I, um, what's interesting about this though is someone talked about 1980s West, you know, this is a case where you see that that's crumbling. The real, the real point here is the EU does not want American or US cloud companies being their sole cloud providers because it allows Uncle Sam to reach in there and, and have access to anything that they want to, right? Because Microsoft has come out and said that, uh, Amazon says they all have To, right?
Like, and it doesn't matter if an intelligence agency subpoenas you or whatever, you're a, no one's gonna know about it, and B, you're gonna do it because you'll have Your license. Don't if you don't, don't. Right.
Right. And, and so the EU wants some independence there and you can't blame them. Um, look, I'm a, I'm well, So, so does that mean, does that mean though, that the EU will eventually wind up subsidizing a competitor to AWS I?
I don't know if they'll subsidize, But they already are, in my opinion, right? Like they've, they've put the, they've thrown down the gauntlet of sovereign EU based systems being their desirable outcome, right? Yep.
So I, I think, and Sosa, so SSA recently appointed a friend of ours, um, Adrian, Adrian, I forgot his first name. No, slack. Uh, uh, slack.
Anyway, they have an entire department for, for IT sovereignty. They are building EU based data centers, staffed with EU based support, people using EU resource, EU based resources. And, and SUSE wants to be the EU cloud provider.
And, uh, you know, more power to 'em. Um, they, they announced this when I, I was at Seuss Con in, uh, in Orlando or shortly thereafter that, but I've been, I've interviewed several of their executives since then. And, you know, and this is wholeheartedly, I don't know if it's financially supported or subsidizes the word you used Mike, but it's, it's, it's certainly you've got, has a lot of support within the EU countries in the EU block.
Do we wake up one morning to discover that the president is now saying, Hey, you guys are creating an unfair marketplace and we're slapping tariffs on you because you're preventing our American Cloud service providers from addressing your market. And I think they're ready for That. I mean, I think they're ready for it, but I think they also know that that's not the way to do it effectively.
It's just a pain point that they're inflicting And it is a scale difference. But how different is this from the US perspective of saying TikTok shouldn't be here, and how easy has it been for us to extricate ourselves from that? But yet, you know, again, you look at the world through this west versus China dynamic that Chris mentioned before, you know, we, we think of, you know, there's three really four cloud providers, right?
Google, Amazon, uh, Microsoft and Oracle, let's say. But if you look at, uh, uh, you know, the Chinese, Tencent, and Baidu, and, and, and those, you know, they, if you look at the top 10 cloud providers in the world, I think four of 'em are Chinese. We just, they're totally off our radar here.
Well, this is nothing new. Um, you know, I'm going to black and Middle East in a couple weeks, and, you know, Saudi Arabia and a lot of the Arab countries already have a data sovereignty where data, when you use them, the, the data has to be maintain, or if you have, if you provide services to them, the data has to stay in their country with an approved provider. So what the EU is theoretically doing is, well, theoretically might be doing in the future, is nothing new.
You know, it's just a matter. Saudi Arabia, if they want, they could throw all the money in the world and stand up their own, you know, cloud provider, which they probably did. I don't know the details of it, but, you know, the EU doing this, I mean, you already have, and again, I, I must admit, I don't know the full details of this, but you do have instances of like AWS and all these other things which are pretty autonomous within the eu.
Like I know, for example, we're using AWS Germany as an example where the data is sovereign to Germany. And I don't Think they, IRA, the, that was what we used to believe the case. But recently it's come out that even though it's EU AWS Germany or Microsoft France, if the United States government or court system says, I want access to that data in that AWS Germany locale, AWS is gonna turn it over Microsoft.
This was This, this was buried in the Cloud act that Congress passed a few years ago. And then they're like in the Europeans. So they, they actually, they pierced the veil is the legal term.
They pierced the veil of that sovereignty, and it's no longer enough. They want, now, like in Saudi Arabia, they want in essence, locally owned and operated companies that are not part of the US that the long arm of Uncle Sam cannot reach them. What I find really interesting is they're more worried about the long arm of Uncle Sam than they are about the dragon, right?
They used to fear the dragon. What are the odds that Microsoft and AWS just go visit their local congressman and get them to amend that act? So that slim Little nuance.
Slim, slim now, No. Yeah, no. The, I think, think national security apparatus won't let that happen.
Well, more importantly, from a Microsoft or an Amazon or Google perspective, and Google's also involved in this. And, uh, Microsoft and Amazon were also named as, uh, key, uh, I can't remember the exact term, but they were key dependencies for the, uh, EU Act, Dora, which is about protecting the financial infrastructure in the eu. And I think from those company's perspectives, this is simply the cost of doing business.
And it just raises the cost of doing business a little bit in the eu. And they will probably raise the prices in the EU commensurable. And, but it's, it's literally the cost of doing business.
Just move on from it. And, you know, the data sovereignty, the concept of data sovereignty from the US federal government, and the same as the concept from the EU governments, which is they all have laws in place that they can go in and grab that data whenever they want. Uh, and in fact, the British and the EU are well on their way towards outlawing end to end encryption for that very specific reason.
So it's, I mean, that's a sort of a non-issue from the, the cloud service provider's perspective. From a customer perspective, that's a big issue, but it's one that they won't be able to solve. And there's two competing efforts in, in this article as well.
You know, there's talking about sovereignty and having everything contained within the jurisdiction of whoever it is you're talking about. And then there's single points of failure and one feeds the other. Actually, if you say, I want everything happening in my country now, you're, you're taking out the, the diversity of, of your, yeah.
So we have to balance both of those too. And I think there's a train wreck down the road here. Uh, the question is, which train is going faster?
Yeah, I mean, and also look, you know, one of the great things about the internet was its global scale. You get on the internet, I'm talking to people in Bangladesh or Bangalore, as easy as I'm talking to people next door and, and all, and it's just one big network. And we don't have, you know, firewalls in that way.
And we don't have borders, per se. It's the internet. But now, you know, and maybe that was naive.
Maybe that was the initial commercial internet period of about 25, 30 years. And now we need to realize just as China's done for years and Russia has done, is that there are borders on the internet and there is, you know, kinda border control. And, and, and that's just the way it's going to be.
'cause we can't have nice things. Alan, you remind me of something. Um, I'm trying to think.
It was, uh, probably around 15 years ago, or close to it, I was a member of the EastWest Institute and organization. Different governments come send representatives and talk about how can we start controlling effectively security of data on the internet. And the Chinese government had representatives there, and we're all talking about, here's all the different things we could do.
And the Chinese representatives stood up when it was air turned and said, I don't know why you're all concerned with this. We have this fixed. And they were right.
Yeah. In retrospect. So, So Alan, what you're really saying is that we're gonna see checkpoint Charlie on the internet.
What do you think? Yeah, I mean, we'll have east and west, you know, We're, we're already seeing that with China and Russia today, right? There are services that are really only designed for, you know, predominantly Russian or Chinese speaking folks out there.
And they've created kind of their own bubble of information out of all of the internet, which is good and bad, right? Like the internet was this great unifier in the nineties and two thousands, and now we are seeing divergence from that unity, which is natural progression of things, I assume in our current environment. Well, also, I mean, checkpoint Charlie really is today the great firewall of China.
I mean, that literally is the, the checkpoint Charlie, and I'll live with that. Yep. Guys, we're out.
We're over time. I gotta pull the plug. What a great discussion though with some really smart people.
Chris, Jeff, Jack, IRA, Mike, thank you for joining. Thank you for watching our Monday edition of Textron Gang. As usual, you have Textron TV right after this, if you're watching the stream, if you're watching this on our OTT channel or YouTube or whatever on demand.
Thank you for doing so, but we'll be back with more gang tomorrow. Fresh gang members, fresh topics. Until then, this is Alan Shimel.
Have a great day everyone. Hey everybody, welcome back to Ingram Micro one. And I'm talking with my friend Hans here, who is a solution provider with a specialty in healthcare.
How you doing, buddy? Noel been a really, really great conference. There's just been an awesome amount of innovation in healthcare lately, and I, I've walk people through a little bit what's going on in that sector and your role in it, and what are the opportunities?
Yeah, we're finding, um, there's a lot going on with an interest in ai, you know, trying to find ways to, you know, automate manual processes. And we've delved into a very, very niche aspect of that industry with, uh, organ, uh, procurement organizations and tissue banks, tissue processors. And, uh, there was a tremendous amount of opportunity, both for AI and just automation across everything they do within their supply chain.
There's also a lot of regulations in healthcare. I don't think that's, uh, much of a surprise to anybody, but we're trying to apply AI to that. How do we walk the nuances of that where, because concerns about privacy maybe and the data, but we also need to come up with some automation.
That seems like a challenge. Yeah, it is. And uh, you know, some of the things we're finding out, I mean, obviously we've got certain compliance and, uh, accreditations and we have to get organizationally SOC two and hipaa, and then you've got the, uh, PII information that they ho hold and that ties into their own processes.
So we have to be respectful of the confidentiality of not only the information that they have on the patient records, but also the confidentiality of their own internal processes and how they use it. 'cause in some cases it's, it's a competitive advantage in some cases. It's, uh, very, very, um, intrinsic to how they operate that they actually don't want it to release.
And they're all very sensitive to the aspects of the, the regulations, you know, for that confidential information processes. And, uh, I mean, right now it's just respect and, and, and, you know, with the, the technology to be able to, to do what they need to do, but at the same time, not allow us to limit us. When I talk to people, there are two challenges, but the first one, everybody seems to know.
It's like AI will occasionally hallucinate, so mm-hmm. How do I kind of work around that or, or account for that factor when I'm building out something in a healthcare scenario? Yeah, that is, uh, it's really interesting because the way that we are actually applying AI for our clients in this industry is that, uh, that does exist.
And the challenges is that, uh, the data, um, as much as you need it, and as much as it feeds into the AI engine, uh, it's basically the lifeblood of the AI engine as well, because the AI model has to be trained off of that data. And we've got all the regulations, as you just mentioned, that prohibits some of, you know, that data in, in terms of how we use it to aggregate it with other clients at a very aggregated le aggregated level. And we don't have that opportunity.
So the, the, the model has to be trained, and the more data that we can get from the organization we're working with, you know, we can work around that. That's number one. Second part is, is that no single AI model will provide the outcome that we need for our clients.
So we're having to stack the technology with other types of ML oriented tech, um, code, other types of AI oriented models that do very specific functions to work in tandem to provide an outcome. So I've kind of got a layered approach where some of the AI models are validating the output of the other AI models to get, make sure that whatever is being generated actually is supposed to be what it is. Correct, Yeah.
At a very simplistic level. Yes. The other side of the coin too is that a lot of the healthcare processes are what we would call deterministic.
They're supposed to be done the same way every time. Mm-hmm. Uh, AI models are probabilistic and hardly ever do anything the same way twice.
So how do I connect something that is probabilistic into a deterministic workflow and kind of meld that together? Yeah. And that, and I, I go back to what I just said earlier, right?
There's, um, um, there's the prompt engineering, there's the AI models, there's the AI model stacked and layered on the other AI models. We've got a vector database that's spills into there as well. The understanding of their business process and what the outcome is.
Um, so the model in order to to, to train it, to have a predetermined outcome every single time, the more data that we can feed into it, the more scenarios that we actually get from it that we can hone in and refine on, we'll start providing that very, very precise answer. And it's one of those where it's a process of refinement processes or an iterative process. So the first time you build it out, it's not gonna be perfect.
And so the more data that we can actually feed into it, the more input we can get from the end users. Uh, we actually start honing in on that, that precise answer. Now, everybody watching this is probably having the same question.
Where did you find the people with the skills to go do that? Because most of the folks are saying, I love this AI stuff, but you know, they all wanna work for Nvidia or something. So how do you get those guys to come work for you?
Yeah. Um, trying to answer this the powerful way. So there is a constraint in the marketplace for skilled AI software engineers, and I have to compete with, you know, the Facebooks and the, you know, all the, the big, you know, hyperscalers for that talent.
Uh, in my particular case, I got very, very lucky because the AI engineer that we hired, married, my, my youngest daughter, and I provided an opportunity, and there was an opportunity you probably wouldn't get at the other places because he, uh, has an opportunity here to actually kind of define our direction and to be able to be very creative with the AI and in a, in a, in a applied sense. Um, but going beyond, you know, my small team of him and, and a couple of others, um, it, yeah, yeah, it naturally is, is very difficult. So one of the things that we're trying to do to augment that is that there are AI tools that allow us to, uh, do some code development on the front end.
It's not perfect, still has a ways, ways to go, but it does save us time. So we're trying to use automation and code development to be able to close the gap on some of that. And then, like anybody else, you've gotta go out and hire the talent as well.
So we gotta ensure we get the right talent. Of course, we're at an Ingram event. How did you get connected to Ingram, and what does Ingram do for you and as part of the building of this solution?
So the story that, um, you know, most resonates is that we got into this about two years ago. So that's when I hired our, our, uh, senior AI engineer, uh, November 6th of, uh, 2023. And he came on board, and Ingram actually had, and we started out with, uh, IBM's Watson X.
They were actually sponsoring a level three workshop with IBM in Chicago. So his first day on the job was on an airplane heading to Chicago to get his credentials on, on Watson ads. So we spent a week there going through the workshop, and that was really brokered by Ingram.
You know, having the foresight to actually, you know, go out and say, how do we actually get our partners enabled? How do we get them engaged? How do we get them them to a point where they can actually start talking ai?
And it was a really good foundation because it allowed us a better understanding of how, uh, the technology was being positioned, you know, in, in terms of the go to market. But we had to learn after that, how do you actually go in and start selling this? So we relied on, on the Ingram team, uh, to, to understand what types of proof of concepts, how do we actually go through a sales cycle, how do we actually engage with prospects who have a need?
And then we had to hone our skills from there. Of course, you also work with a lot of the vendor partners that Ingram represents. Um, I don't know if you can tell me in a lot of detail, but which of those vendor partners are kinda at the core of that solution for you guys right now?
And what is it that you wouldn't wish that maybe more of those vendors would remember when dealing with solution providers such as yourself? Yeah. It's right now with, you know, just the, the terminology of ai.
Um, I think the large vendors, you know, the ones that are well known that make the news every day, they're sowing a lot of confusion. Everybody's talking about the art of the possible as a reseller partner, as somebody who actually engages with a client, by the time we engage, they don't wanna hear about the art of the possible. They wanna see a solution that actually works.
So there's a big gap between, you know, what, what the, uh, the vendors are providing and what the solution providers actually have to deliver. So we rely on Ingram heavily, not necessarily with the technology partners that we've worked with IBM and Microsoft, and there'll be others in the future, but it's the relationships that we don't have with the other technology partners that Ingram does have. So, for instance, if there is a reason for us to change some of the backend coding with a different LLM or a different AI type model that is, uh, specific to a certain vendor, we don't have the re relationship.
Ingram will probably have that relationship and we have to leverage Ingram to help build our credentials and reputation to be able to open the door and get the right resources that we need so we can continue our development to provide that solution to the in client. One of the things that I hear a lot about is every CEO has a bad case of fear of missing out and thinks that this AI stuff is all magically happening tomorrow. And then there's their staff and people who are a little more circumspect 'cause they understand what's required to actually implement.
How do you, as the solution provider kind of navigate that relationship and those conversations? 'cause essentially you're a diplomat between these groups. Yeah, absolutely.
Yeah. And it's, um, that was, I would say situationally, that was probably the case two years ago when we started, um, AI was this concept. And pretty much every executive team says, okay, we've gotta get AI in here.
And our first probably, you know, handful of phone calls or, or overshoot from our, our, our client base, not necessarily our prospect base was, Hey, can you help us with ai? And my response was, yeah, absolutely. What would you like us to do?
It says, well, that's why we're calling you. And it was this, this panacea that all of a sudden you, you basically, you install something, you implement it, and everything is gonna work to perfection. It's just like this magic button you press.
In reality, that's not the case on the staff level folks, the operating level folks, they're seeing AI as a threat. So is basically our executive team wants to bring in AI and it's, it will basically replace my job. And so you have this, uh, uh, diversity of thoughts and understanding of what AI is supposed to do.
So we have to obviously educate the seed level folks that it is not that be all end all solution where you push a button, everything magically works, um, and it's trained on your data. And then we also simultaneously have to work with the operations folks and let them know that we're not here trying to put a system in to replace your job. What we are trying to do is that, uh, you know, right now the focus and the benefit of AI is really, you know, time savings and productivity improvement.
So we want the system to be able to do the heavy lifting for them and the process and use everything that AI can do based on the data that's being fed to it, to free up their time to work on the very true value add, you know, needle moving types of, of aspects of their job that's gonna really enhance the company's productivity. One of the funny things about healthcare, at least from my perspective, is it was always perceived as a sluggish kind of business because they were collecting a lot of data, tagging it and organizing it. And yet that may be their secret sauce for ai because they did a lot of that heavy lifting of the data and work already.
Then a lot of other vertical industries have not. They, uh, I would agree that to a certain extent, uh, but there are, um, I would say upstream functions that take place that are still very manual and a lot of that tagging categorization of data, which actually makes our job easier, right? Because all, all well-defined, um, a lot of that has been done, but there's a lot of unstructured data that shows up in forms, in handwritten notes.
Um, it shows up in jpeg images, OCR images that we have to translate in. And not only that, you can have forms that have the same information, but the forms are different and, and the context is missing from that. So when we actually build out these AI solutions, we have to ingest those documents.
We have to understand what is in those documents, we have to, to understand what the context of those documents are so that we can turn the information on those documents into relevant, very well-defined, categorized information to then let the AI model be able to provide the output that it wants. So to your point, a lot of what they do operationally, you know, for production, for, um, you know, um, patient outcome, yes, that is, but upstream from that, a lot of the information is very unstructured and increase the challenge for them, and there's a huge amount of opportunity as far as productivity gains from that as well. It almost sounds like, you know, you have a solution and you've kinda landed and now you're looking to expand.
So what are you thinking about as the next opportunity? Yeah, so we, we are, we're actually, uh, we, we've got a great client that we're working a, uh, informing a strategic relationship with, and it's a tissue processor, so basically organ donation, and then they actually take, um, uh, tissue, uh, donor tissue and then look at, uh, eligibility requirements. So they, they'd be able to look at lifestyle, they'd be able to look at disease, they look at things of that nature and, uh, qualification criteria for the tissue.
They have their own manufacturing process. And, you know, as we spoke earlier, that's very well defined. The information is very well defined.
How they capture the information and move the information through. There's very well defined. But on the front end of that, how they actually analyze the, the donor and how the tissue, the suitability for the tissue that they have to process for their, in, you know, inpatients, the hospitals, the doctors, the clinicians.
Um, so we, you know, we've developed an AI application to be able to do that manual process on the front end, and then the automation that falls at the donor traceability. So now that we've got the components being processed and tracking that all the way through to the final production of that tissue, so that it's either a skin graft or a bone graft or whatever that final product is, so they can inventory that and then push out to the hospitals. And then there's the entire supply chain and ecosystem where the supply demand match is very inefficient.
So we're looking at the hospitals, the doctors, the clinicians, when they actually need something, how can we actually compress that cycle time so that they can get it from the tissue processors in a shorter period of time? And, and there, there's additional opportunities beyond that as well. So there's a plethora of, of things that we can do.
Technology can help, but you've gotta have a good partnership with folks in the industry to do it. Yeah, I almost think like anywhere there's friction, it becomes an opportunity. Absolutely.
Absolutely. So Last question. As you look into the coming year, what are you excited about?
What are you thinking about and maybe what's keeping you up at night? Well, the geopolitical stuff's keeping me up at night, so not, not a whole lot I can do about that, but there are opportunities. And I think, you know, we've had, uh, two years of maturation, uh, not only within my organization, but I think within, uh, just industry in general and understanding, you know, ai, AI has gone from this concept of AI is, you know, it's just this broad, uh, term that everything's kinda lumped into it.
Now we've got, you know, the, uh, uh, generative ai, we've got agentic ai. Uh, we're still focused on use cases, but I think a lot of the use cases will be addressed by agentic AI to a certain extent. And then you have the possibility of that automation of where you get the AI agents talking to each other and looking for those opportunities.
But at the end of the day, when you look at it, right, we are still collecting data as part of that process. We're trying to take the friction out of the supply chain. So the question I asked the CEO of our client is that if you were to look at your processes and you were to take all the friction out, what is the short, shortest amount of time that it would take to act, you know, to actually process the tissue that, that you work with?
And he thought about this, I said, that should be our goal, and that's what I'm excited about. 'cause I think the technology can get us closer to that goal because we can automate a lot of the processes in a very smart, intelligent fashion. Not necessarily to replace jobs, but again, take the folks that are very good at what they do and allow them more time to be able to do it better.
Especially the stuff I don't enjoy doing in the first place. Yeah. Hey guys, it takes a village to do AI and it kind of starts with the solution providers and includes the distributors and the vendors, and that's how it all comes together.
Buddy, thanks for coming by. Yeah, thanks for having me. And we'll be back in a minute.
Hey, everyone. We're back here live on our, what you could say, it's day three, or you could say it's day four. I've been here four days, but this is the third day that the expo floor is open.
So take your pick. But we're live here at Cube Con Cloud Native Con in Atlanta, and I'm really happy to have my next guest. We've been kinda waiting for him all week, whether you call it day three or day four.
Jonathan Bryce, Jonathan is the, uh, executive director of the CNCF, but he has a dual role. He is also the executive director of the, uh, open Infra Foundation, which is also now part of the Linux Foundation, or under the umbrella or whatever auspices of lf. Um, Jonathan, welcome to Text Drunk tv.
Thanks for having me. Pleasure. So, Jonathan, I I've wanted to ask you this 'cause I, I admit I don't know the answer at all.
What, what, what have you been doing that got you to this position? Uh, well, it, it, it all started, uh, in the nineties with the web. I, uh, I spent a lot of time, um, doing software development, uh, for the web.
And back then that also meant you had to build your servers and put 'em in a data center. And, uh, and then I, I joined a company called Rackspace. I was one of the, oh wow.
One of the early, early employees there. And, uh, we, um, you know, built out more data centers, and then I started a cloud company. Rackspace bought it back in, and, um, that was where we, we, uh, launched OpenStack from.
Sure. Um, OpenStack started to really catch on, and so we wanted to give it a neutral home. And this was kind of before the Linux Foundation, as it is now, is really a foundation of foundations.
Um, and we, we actually talked with Jim Lin a lot in 20 10, 20 11. He was super helpful and we created the OpenStack foundation. I, um, which, uh, we, we, uh, as we added other projects to it, we, we rebranded to the open in for Foundation in 2020.
Yeah. And, and finally, you know, kind of full circle earlier this year, um, merged it into the, uh, the Linux Foundation. Um, so, you know, it's been a lot of all infrastructure, uh, some software development, some hardware engineering and network engineering, and a lot of open source.
So let me ask you, in the nineties when you were building out servers for the websites, what was your platform of choice? Uh, well, one of the things that, um, that got me into open sources, I was a teenager and I had no money. And I started doing this that cheap because, uh, I, I realized I could, I could, uh, make more money than mowing lawns by, you know, building people websites, but I needed everything to be as cheap as possible.
So it was, uh, it, it was X 86 and Lennox and, you know, the, the very first versions of, of PHP and My SQL and, um, yeah, you know, It, yeah, no, it similar. I mean, I was older than you, but I started as a hobby building websites, and then we had to store 'em and same kind of thing. It was in, I I, I still remember my, the first X 86 server.
We bought our own server to store 'em on in a little ISP in Long Island called L inet. They gave me free, they let me put a server in, uh, it was a, a four way X 86 machine, and I thought I was a digital landlord. As we added more sites, I just plugged another hard drive in there, a vigor hard drive.
Then, then the web really started taking off and we, we wound up moving the Sun Ultra Sparks, and we were running Netscape. Yeah. Server over Solaris those, yeah, we got acquired shortly after that.
But that, that was, that was the web then. That was, that was the internet. And it was fun as all hell.
I know. Um, good times. An interesting, you know, your fact pattern with, with, uh, Rackspace is a, is a common one.
A lot of people started at Rackspace, went out, did well, fairly well, and got brought back in. Mm-hmm. Right.
Yeah. Cisco does that a lot too, right? Yeah.
So it was an interesting thing. Um, while we're on the topic though of Open Stack and Open Infra, you still are the ED for Open for Foundation. Have it mentioned it once this week here on Techstrong?
Yeah. Give us a, if you wouldn't mind, a a Yeah. Well, we just had, we just had our open in summit, uh, in Paris about two weeks ago, and, uh, it was awesome.
Sold out crowd there. Um, the, you know, OpenStack is still the, the largest project in the open infra Foundation. Sure.
And right now, there's some real tailwinds for OpenStack driven by all of these massive infrastructure investments. Um, there, there are are kind of two SubT trends in that. One is digital sovereignty, which was a big theme for, for the event in Europe.
Um, you know, there, there's, uh, there's a desire to really know where your data is, who has access to it, what laws apply to it, and, uh, and make sure that you, as you're building systems, they're resilient to changes in the geopolitical environment. So digital sovereignty is leading a lot of folks to, um, you know, to kind of think about where the servers live and, and who's running them. And, and that's led to a lot of investment in, in, uh, in Europe that has mostly been built out on OpenStack.
Um, AI is another piece of it. And one of our other, uh, really popular projects is called Kata Containers. Um, kata containers is a secure execution environment.
You can plug it into, uh, into a Kubernetes pod, and it gives you a, uh, a, a very lightweight virtualization wrapper that protects against, um, container breakouts and those kinds of things. But it also has some other really interesting features that make it nice for ai. Mm-hmm.
Uh, which is that you get to have a kernel in there. Right. And that kernel can have customizations for, uh, for special workloads.
So we, we have a number of AI companies who are using COTA containers to, um, to, to create GPU as a service businesses, some of them at quite large scale. And, uh, and, and so, you know, the, the Open Infra foundation is, is often one level down from where we are here at KubeCon, you know, KubeCon, cloud Native Con, uh, a lot of the tools here expect that you have a cloud, that you have infrastructure with an API on it in the Open Infra Land. We're building infrastructure APIs on top of hardware.
So it's kind of one level lower, but still, I love data centers and I love that level. So I love being able to, to kind of span both groups. Has there ever been a more interesting time to love data centers?
Oh God. I know, but do me a favor. How do you spell Kata?
KATA. Yeah. KATA.
Just wanted to make sure people got that. Thanks. Um, you know, it, it's interesting there are, you talk about tailwinds that are moving there.
Let's talk about, if you don't mind, we'll spend a little time. Yeah. Look, you know, the whole VMware Broadcom licensing thing has caused, I am not here to debate whether it's worth the money, but it's caused people at least to say, Hey, this is a good inflection time.
Mm-hmm. Should we look at something else? Yeah.
Should we look at going to public cloud? Should we look at a different, uh, cloud solution, hypervisor solution in general? Right.
Should we go hybrid multi stay, just in the private mm-hmm. Data center? Um, it's certainly, it's an agent of change.
Yeah. Or, or at least an agent of ref a time to reflect and, and make some choices going forward. We, we, we did a survey of our Open Infra Foundation members earlier this year, and, uh, over 80% of them had gotten inquiries about migrating from VMware.
Over 60% of them had already done a migration. Really? Yeah.
Off of VMware. Off of VMware, yeah. Over the course of this year.
And so it, I think, you know, what it, what it did is it injected enough uncertainty that, as you said, you're willing to consider a change. And from a business point of view, you know, I, I don't, uh, I don't necessarily think VMware made a bad business decision like they are. They're, they're focusing on, on profitability and yeah, He's done pretty well for, except that guy.
But you know what, it does change the dynamic of where their customers have been historically and, and where they would be in the future. So, yeah. You know, it, it, it made people consider, should I move to something else?
And, uh, you know, what would that be? I, I agree with you. And, and it may very well be that their decision was they're better off with 50 or 60% of their existing customer base paying three X the time.
Yeah. They make more money and, and, and, and it's a very, uh, focused customer base. Yeah.
Be that as it may, it makes opportunities for a lot of people at different things. Yeah. The other thing, driving it, of course, as you mentioned ai Yep.
Right? And, and what's going to, what is the AI stack of the future look like mm-hmm. And what platform is it running and what cloud or, or what have you?
I, you know, I think there, we, the jury may still be out, but it's certainly anytime you could get people to say, Hey, wait a second, change is coming and I gotta think about what I want to do. It's a good thing, I think for like, yeah. The infra, open infra foundation and the tools and projects in there.
Yeah. We have several, um, GPU cloud providers that are, are running OpenStack to power that. Some of them use cota, as I mentioned.
Um, one of them is a top 10 buyer of Nvidia gpu. So it, it's, uh, it, it's great because if, if you're talking about a handful of GPUs and a couple of systems, then you know, you, you may just go with a simpler set of tools to manage that and deploy the workloads and, and, and go with a, with a simpler option. But if you're talking about putting tens of thousands or a hundred thousand GPUs in a data center with all of the associated infrastructure around that, then you really have to have something that's very focused on the compute, storage, networking management.
And I think that's, that's where, um, you know, OpenStack has, has done really well this year. I agree with you. I, I, I, you know what?
Look over the years OpenStax had its ups and its downs. I really thought, I guess when you changed to open Infor was, was that 2022? It Was 2020.
Yeah. It, it was a bit of a, it was a good shot of adrenaline in the arm. Right.
That reinvigorated it. Yeah. Um, and look, we, I think it's better days, may it's best days may still ahead of it.
We, we just crossed 55 million cores of compute and in our user survey, uh, that we just wrapped up around the summit. So that's a lot. It's, It's A lot more, more open stack than ever before.
Absolutely. And it's a good thing. Look, choice is good out there.
Freedom is good out there. Yeah. Um, let's pivot over to, to CubeCon.
Yeah. NCF. So this is your first CubeCon as as Ed here.
Impressions, thoughts? Uh, yeah. I've been coming to KubeCon mostly since the beginning.
I've been to, to most of them. And, uh, it's always a, a really interesting event because this is where the, where the industry comes, you know, and, and, uh, it's, it's, it's a good way to sort of test the waters and see how people are feeling. And, um, you know, we we're here in the sponsor hall, we sold out our sponsorships this year.
Um, the it, and when, when you look around, you know, you'll see, you'll see a lot of backdrops with AI on them. And, uh, I that's, that's different than even six months ago. And I, and I think this is, you know, what's on everybody's mind, and, and to me, there's a, um, uh, what, what I've been trying to, to have a conversation around is, you know, which part of AI is the part that fits here.
Mm-hmm. Because AI is so big, you know, it's everything from, from really, really deep AI science and machine learning, Right. The neural net part of it, Up to, you know, chatbots and, and agents and this kind of thing.
Um, which part in that, in that entire spectrum is the right part for our community to work on. And, um, you know, my feeling, I I, I'm obsessed with inference right now because I feel like that is a, uh, an an area of AI that's really getting overlooked. You know, we, we kind of have skipped from, from being interested in, in these deep learning and machine learning and LLM creation techniques all the way over to agents.
And, you know, agents require models, models require inference. Agents are gonna operate at a much, much higher transaction rate than humans do when we interact with models. So now we have to expand that inference by even more multiples.
And, uh, and this is, you know, going to just increase the already extreme demand for, um, for, for, for access and data Centers. Yeah. We can, that we probably can't meet in the, in the in, yeah.
You know, the timeframe they're talking about, well, This, this is where the software is really important because you, you know, you're right. Like you, you were talking about power earlier and, and data centers, and we can't build nuclear power plants more rapidly and we can't, you know, install servers more rapidly past a certain point. But software can change very quickly.
And, and if you look at, at the core pieces within, um, AI inference stacks, we've, we've seen incredible efficiency improvements this year. Six X in VLLM eight X with really, uh, caching techniques on top of, um, Kubernetes routing primitives. And so, you know, you, you, you get a few of those, those advances and you are 50 to a hundred times more efficient just through software.
Right. And that means that, you know, that nuclear power plant, you know, you, you, it's 50 x more, more, uh, efficient there as well. Absolutely.
If we get it approved, Sorry. Right? Yes.
But, but you know, what you hit on here is, is again, this is a, this is a very normal fact pattern, right? First these things come out and, you know, and it's, wow, they're great. But now you start thinking, well, how much power does he use?
How much water do I need to cool it? What, you know, all of these things. Yeah.
And, and efficiencies become the, the, the rule of the day. Yeah. And software is always about making it more efficient, right.
That's how we've always proceeded all through my time in tech. Yeah. Right.
Software is where we pick up those efficiencies. Um, I don't, you know, you talk about inference and, and you, I don't think inference had its day in the sun yet is the problem. I don't, yeah, I don't think so.
I, I think we've been so focused on training, training these models, and yes, training the models is intensive energy intensive resources, but eventually, like we don't have enough data to train much more of these models, right. We gotta have synthetic data and all those things. But now I, especially with agen ai, I think inference is where the actions are gonna be in the next, I I'm ashamed to say, I don't even wanna say three years, 18 months.
18 months to do 18 months is plenty. That's actually where I, that's the timeframe. I think we have to, um, you know, to capture the opportunity right now.
Yeah. Here, here's the thing is if you look at all of the largest inference systems out there, which most people don't know that these even exist, but we had OpenAI give a keynote yesterday and, uh, and they were talking about, um, their, they're fluent bit usage and Yeah. Uh, how they were hitting performance limits.
They fixed, uh, you know, they made some small patches to a few lines of this. It made a huge difference, 50% reduction. We, we spoke about it on Textron getting, I think yesterday.
And, And you know, so, so this is a, an example of where that the pattern that they have is different because of the amount of data and the amount of track transactions. It's a little bit different than what a, a happy path Kubernetes application was two or three years ago. And so this is what we need is we need, we need these systems to, to, you know, be, um, testing the new limits that, that we're gonna find.
But if you look at all of the largest inference systems, they're all running on Kubernetes right now. I think the, the, the, the area that's a little weak that we need to focus on over the next 18 months is that most of them are doing it in slightly different ways. So we're not truly benefiting from the full power of an open source community here.
No. And, and the thing that I love about it is, when I talk to, to a lot of these companies who are, who are doing inference systems right now, they all go, what's everybody else doing? We, and they say, this is not differentiating.
Like, I don't believe that my inference system is differentiating for my business. My data is differentiating The agents that I create, but that's always what the gator's, what's important, The data, the agents, like that's gonna be differentiating. This is holding me back.
How do we get people working on it? So I think this is really the 18 month opportunity is to get some, um, you know, some, some real patterns and, and real reference architectures for this. But I, I think this fits so perfectly in the open source model, right?
Yeah. Because where we are now is a bit of a Cambrian explosion. We have all kinds of weird animals out here, six eyes, 12 legs, and, but eventually life finds a way, right?
And that efficiency kind of sets in. Yeah. And the best model will, will, you know, the cream rises to the CRO to the top, and the other stuff stinks to the bottom.
Yeah. I think we're gonna have that. I hope it happens in 18 months.
Sometimes These things Have a way of stretching out because Anti open source money becomes involved, and a particular company with a lot of money pushes a particular model, which, you know, may not be the, the most efficient or best. Yes. We don't use OS two today.
Right, right. And, and I left OS too, but in any event, I, I do think that's where we are with inference, and I think it's gonna reignite, you think there's a lot of AI now, wait, right, right. When this inference stuff is real, and we've got that working right.
Um, I, I, I, you know, bother, what is the term? Katy Bar Bodo or whatever. Yeah.
Katy Bardo. They didn't think that much Of New York growing up, but you know what I mean? Um, I I I do think it's there.
I, you know, from the CNCF point of view, right? Mm-hmm. So you've got all these projects and they're all, they're all being touched by this one way or the other.
Right? Right. How do you, how do you, um, orchestra to Edward to use, how do you orchestrate Yeah.
All of these AI needs and Yeah. You know, push and pulls going on here. Yeah.
Well, we, we announced an AI conformance for Kubernetes this week. And I think that's kind of step one is to, um, to give people like a very baseline target to, to start aiming at. Um, it's, it's definitely not, not the end, you know?
Yeah. There's, there's a lot more to do, but what it does is it gives people a baseline target to, to start aiming at. And the, um, the other thing that, that, you know, I, I spoke about this in my keynote.
We need to highlight it because when I do that, I walk, you know, through the conference the rest of rest of the week and everybody's coming up to me and they're saying, okay, well I'm using Ray on Kubernetes. Um, you know, I'm using ser I'm using Kube Flow, I'm using, you know, but this, I run into this problem, or I, you know, I did this thing and I was able to do this Prefill caching, and it like totally changed the, our gen AI efficiency. Mm-hmm.
And so, you know, I write them all down and I start to connect them and, you know, this is how, how it works in open source. And when we get to Amsterdam, I think we'll, we'll see progress, uh, within Three, four months. Yeah.
I think we'll, we'll see some progress and, um, and, and you know, that it, it can move very rapidly once you can I think once this consensus Yeah. Once you can, that's really Get people together. It can really, And I think that's what you're really saying.
Look, hopefully by Amsterdam we're gonna have a consensus here, and then it's full speed ahead. Yeah. Right?
We get rid of the 12 eyes eight Legg that make no sense. Yeah. And, and go forward.
I, I do think that's it, you know, but you gotta remember, to me, open source is like democracy, right? It's the most least in, it's the most least inefficient form of government. Yeah.
But the best that there is. Yeah. And, and so sometimes you gotta let this play out.
Yeah. Let the, let the community and the market decide what is the best thing. Right.
You can't Yeah. We can't dictate And the, the thing, nothing happened. Yeah.
The thing that I see as a change in AI right now is I, I say that, uh, chat GPT was a proof of concept, you know, that, that it was not, it was not actually the end goal for AI Chat GT was a proof of concept, but we, it, we put a, a human voice on top of AI and it made us all go nuts, you know? Yeah. No, there, there is there.
It's sexy. Like Yeah. 'cause it had that order magical that even, look, you and I, we've been in this game, you know, we, but you show it to like my wife's family.
Yeah, I Know. Basic it's magic. I know The computer is is Has a brain.
All the sudden it became real. Right. It became real.
And so I think it's like, it's actually distracted from, from some of the, the fundamental progress in other areas. Mm-hmm. And, uh, and we're starting to see a resurgence of small models Yes.
Of specialized intelligence. And those are the things that are gonna drive, you know, inference on the edge, inference inside of enterprises, all kinds Yeah. Optimize.
Just, do you think to see those as open source projects? Or do you think the, the, the amount of money is just so you can't even, it's like talking about how light years and space right. You can't wrap your head around.
Yeah. I mean, did that take away from the open source? Um, so Akamai just announced, uh, an inference edge platform, um, I think maybe last week.
And, uh, and you know, it's built on Kubernetes and is it, it's in our AI conformance program. Beautiful. So, you know, I think that, that we will see services for sure that are, are monetizing the open source as They should.
But I, I think we'll see a lot of, you know, we'll see a lot of this in, in open source. I love it. Thank you for coming on here.
Yeah. We're over time. I apologize.
Yeah. Hey, that, that might have been our highlight for, uh, Tuon this year in Atlanta. I hope you've enjoyed it.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. I'm your host, Mike Biza. Today we're with Pedro Bizaro, chief Science Officer for Feed Eye, and we're having a little chat about how gen AI is being used to perpetrate fraud and what to do about it.
Pedro, welcome to the show. Oh, it's my pleasure. Thank you so much for having me.
I don't think it comes as much as a surprise that the bad guys have figured out how they use Gen ai, but to what extent are they using Gen AI to perpetrate fraud, and what should we be on the lookout for? Oh, they are actually quite creative and they're using gene AI a lot in multiple ways. And they, they are very organized.
So basically what what they are doing is that they are making, with gene ai, they are making it easier to commit, uh, these phishing attempts and scam attempts. So with gene ai, they are able to create, uh, for example, email messages that are much more realistic. The tone and the language and what you refer to is, is much easier.
So because of that, they are lowering the barrier of entry for other frauds. They, uh, also using gene ai, uh, scaling up their attacks. So they are doing not one attack, but multiple attacks at the same time.
Sometimes hundreds, thousands with little variations. And in essence, testing whatever works better. So if they end up discovering that one message works better than the other, they start using that message more.
So they're basically doing what already some, uh, tech companies do when they're putting their ads, when they're requesting their ads, they're trying out many different variations and they're looking to see which one tracks better for, for their cases. They're also using, uh, g AI to enable personalized attacks. So they are able to get information from people that they share online on LinkedIn, on social networks, and they're able to target their attacks in a way that are much more efficient because now they know their company, their title, maybe their boss, their colleagues.
So the attack is much more targeted. And if you're not on the lookout, you are gonna get food. And of course, they're also using almost like sci-fi types of attacks in a sense that they are creating voice avatars.
And in some cases, even video avatars. There are examples of people that are, they think they are in a Zoom meeting with their, with their colleagues, but they are in a zoom meeting with, with avatars create by fraudsters. So all of this is becoming, of course, a huge problem.
The losses are now on, on the hundreds of billions worldwide. Uh, because of this type of fraud. I think the one thing a lot of these fraud attempts seem to have in common is there's usually some sense of urgency attached where somebody needs to do something quickly, but that assumes that somebody on the receiving side of that is gonna catch that and kind of raise a red flag.
Is there something from a technical level that we could be doing to identify these attacks so that we can maybe preempt them without having to rely so much on humans? Uh, there are, in fact many things. Uh, we ourselves, uh, at, we have defense, all these type of attacks.
Um, we have, for example, a product, uh, called, uh, scam check, um, that will analyze the message and we will show to us the red flags, for example, that these URL would not match or that this person using, uh, a request for, um, economic transfer, or there's an urgent tone on their voice. So it'll raise the alert, stop, uh, flag so that the people can be more on the lookout. And then we also have behind the scenes products, like what we have.
So, uh, as you, as you know, uh, um, is a platform that protects, uh, financial institutions and, and people, uh, worldwide. And basically we are running behind the scenes every time that you are doing a, a payment or a transfer, a transaction, when you put your credit card on the machine or make a payment online, there's just a few milliseconds, um, where we are called by the bank, uh, to check, is this transaction a really a good transaction or not? Is this suspicious or not?
And we are running machine learning algorithms to see if this matches your usual behavior or not, and we we're gonna flag it to the bank. Mm-hmm. It does seem like a lot of these attacks now are being launched by syndicates that are highly organized.
Are there things that governments around the world and law enforcement agencies should be doing to combat this? Because it does feel like it's become a global problem, Is indeed become a global problem. And many times the frauds are taking advantage of multiple geographies and multiple, uh, countries and types of companies because they start an attack, say on a social network, and then they jump maybe to a telecommunications operator, and then they jump maybe to a bank.
And maybe all of these players are in different countries and they don't have a common legal way of sharing data. So they take advantage of the fact that they are touching many organizations that do not communicate between themselves. So one thing that governments and law enforcement agencies and regulators to do is promote ways for these companies to share information, uh, in a private way, uh, to detect fraud, to realize that, okay, this person is sending, uh, other than thousands of SMSs, maybe this is a little bit suspicious, or these accounts may be sending too much, um, messages that look the same, and they're looking for money.
This look through speeches. So it should not be just, um, an issue that is affecting the financial institutions. It must be something that is addressed at the global level, including financial institutions, but also tele communication, uh, companies and certain networks and governments so that the, this information can be shared in a, in a safe way and an efficient way.
Mm-hmm. Of course, there's a lot of different types of fraud being committed. Um, are there particular vertical industries where you're seeing who are more impacted than others?
I mean, obviously financial services, but what else are the bad guys after? Well, uh, I normally say if there is money, there is fraud. So, uh, all types, all types or, or sometimes even what's called pai money.
Quasi money is things like, uh, miles points and things like that. So e every time there's, um, money or something that it can be transferred to money, eventually, it could be a gift card or something like that, they will be f fraud. Uh, and this, as you say, they are very organized and they shift quickly.
And normally it's almost like a game of whackamole. So you, you stop them on one side, they start doing something on the other side. Something that is really important is our ability as on, on this side, the good guys to protect in a way that is very quickly.
So we need to be very quick because the, the, the frauds are also adjusting very quickly. It also seems like there's a lot more activity surrounding various cryptocurrencies. And I think maybe that's because there aren't as many protections there.
If we want crypto to become something of a mainstream currency, do we need to kind of figure out all these fraud schemes? I, I think indeed. Uh, so, um, cryp two I think has lots of good promises about, uh, removing, uh, bottlenecks and allowing instant payments person to person, but at the same time sometimes also removes, uh, somewhat protections.
Uh, and in order for us to really trust crypto two, we, the consumers want to feel that there's somehow some sort of protection, right? These days. Uh, if a person commits, uh, a mistake, uh, in a traditional bank, normally there's some sort of mechanism to, to re recover, at least sometimes partially, but recover something of their, of their funds that are actually, uh, legal requirements in most countries to do that, to protect consumers.
But, uh, it is not yet the case in crypto, right? So if you, if you make a mistake, if you share your password, if someone gets all of your account, if someone x your computer and steals your, your crypto login, you are toast. So yes, I, I think we should have more protections for digital currencies as well.
You mentioned lowering the bar, and I think that is also gonna make it harder to, uh, disrupt and prosecute these gangs or syndicates. 'cause it seems like almost every three days or so you'll see an article about somebody got caught doing something, but, um, it feels like these entities just reconstitute themselves pretty quickly and launch again, and we're as far off as we ever were. It, it is indeed the, uh, good that in some cases, these entities are in, um, uh, region, sometimes even promoted by their own countries, uh, or supportive, uh, or sometimes ignored, just letting them do what they wanna do, which makes persecuting these types of criminals much harder, uh, because they are in, in far away regions with other legal system and sometimes even protected by their own governments.
Uh, so what this means is that we need to protect ourselves on this side. We need to find ways to be able to, even in the presence of organized crime, we need to assume that they're always going to be there and, and protect the, the accounts and the transfers and the payments on our sites is going to require on, on some cases, education of consumers, but also using AI to fight ai, right? We, we are the good guys, and we also need to use AI to fight these AI being used by, by the equips.
Do we need to make sending money harder? And I'm asking the question because if I went back 25 years ago and I went down and send somebody, you know, a hundred thousand dollars, it was a process and it took time, and there were checks and balances in that. com and we made it simple to give people money and transfer money through Venmo and whatever else.
But I wonder if we've gone too far, because that's what helps the fraudsters just kind of take the money and run. Well, for qui there's a balance, and it's always been the case that on one hand, we are trying to remove friction. We're trying to make the system smoother and easier for people to use.
And on the other hand, as soon as we remove friction, the first people that take advantage of that reduce friction normally are the frauds. They move very quickly, uh, when we allow real-time payments fraud, take advantage of real-time payments to, to make fraud faster and get their money faceted. But I am honestly an optimistic person, and I do believe that it's possible.
And we've seen that it's possible to reduce fiction without incurring the losses. For example, we protect, um, hundreds of millions of, of people in, uh, other countries like, uh, Brazil for example, that has a very, uh, dynamic market of real time payments where people can pay with their phone almost, uh, everywhere. Uh, more than, uh, 75% of all payments in Brazil are now learning real time, uh, by phone, using their peak system.
And we have been able to protect, uh, this country, uh, although you'd think that, okay, we reduce friction so much, it's going to be, uh, much more dangerous. But in fact, it, it has not been. So, I, I truly believe that's possible to reduce friction and do a good job and protect people.
Um, you mentioned new technologies and deep fakes and various things that these folks are using. Um, as you look into the coming year, is, is that gonna become a lot more commonplace, do you think? And what are you expecting the next thing the bad guys to do?
Well, yes, I, I'm, I'm expecting that these attacks are going to become, uh, more and more common. Um, we have seen sites that are totally devoted to fraudster. There are things like fraud, GPT and warm GPT, that the, these are sites that fraudsters use, and they have, um, uh, black markets and dark web, um, channels, uh, like telegram channels to share with themselves, techniques to do broth.
And so they are learning and sharing with others very quickly. So every time that something like this works, I expect that we're going to spread. And we see that, we see in our clients that if something appeared in one country, and if it works, then it's going to appear in other countries.
Mm-hmm. So I imagine that they are going to target more and more people. 'cause in most places, people are going to be the weakest link.
The the system are protected, the computers are protected, but people are the ones that are sometimes more easy to fool. Um, so I, that's what I expect. So let me ask you this.
Where's the outrage? 'cause when I look at the world out there, there's, there's probably trillions of dollars being lost to fraud if I added it all up. And yet, um, there isn't this sense of, um, we need to go tackle this today.
There's usually a report from the World Bank or the UN or somebody like that, but, um, it doesn't feel like it rises to the top of the agenda then. So what are we gonna do to get everybody focused? That's, that's a really question.
Well, actually, in the, in the places where I work, this is actually top of mind. Uh, so, uh, almost all regulators in all countries or national institutions, they are very, very aware of the rise in scams and crime. And in many countries, Australia, UK and, and, and others, there are already, uh, enforcements for companies to share information across, like, like I was saying before, social networks and telcos and, and banks on purpose to prevent this.
There are also situations where the, the blame is being shared not only from the standing bank, but also from the receiving bank. So that both need to check. So increasing the, the, the number of people checking if a transfer makes sense or not.
So I, I think it's very much top of mind, at least in the financial world, that this is a, a rising problem. Maybe it's not, um, top of mind across, across the globe for other people outside of, of the financial world. But it's very much one of the, of the biggest problems here.
Folks you heard of here, ai, we've talked about it in the past. It's a double-edged sword. And bad guys are using it for all kinds of things.
So you gotta be careful out there. Pedro, thanks for being on the show. That's my pleasure.
All right. And thank you all for watching the latest episode of the Textron AI Leadership series. You can find this episode and others on our website.
We invite you to check all those out. Until then, we'll see you next time. Hey everyone, it's Alan Shimel.
Welcome back here to another Text Drunk TV segment. In this segment, I want to introduce you to Vivek Ram Charan. Raman Chandran.
I'll do the best we can. He's gonna say it better than me. Vivek is the founder and CEO of a company called Square X.
And let's welcome him here to Text Drunk tv. Hi, Vivek, how are you? Uh, hi, Alan.
Thanks so much for having me on the show. Really excited and yeah, doing amazing today. Thank you.
Hey, say your name right for me, just so we get it. Vivek Ram. Ram Ram.
Okay. I just can't roll those Rs no matter how long I've been doing this. I can't roll the Rs.
Anyway, Vivek, as I mentioned, you're the founder and CEO of square X. And we're gonna talk about Square X in just a moment, but let's, let's hear a little bit how you came to found it, why you founded this company, what, what kind of drove you to found it, and kinda a little bit of your journey along with that. Yeah, so Alan, you know, I started my cybersecurity journey almost 24 years back.
And, uh, you know, I was very lucky that I kind of fell in love with this space in the very beginning when I just started my engineering. So the first few years I worked for companies like Cisco Systems in their engineering team, building security products, but very quickly figured out that, you know, I somehow had a knack for breaking security. So then I shifted gears to security research, found a bunch of vulnerabilities.
I've authored books, you know, which are still on Amazon, uh, spoken at DEFCON Black hat 20, 25 times. And that was the time when I started my very first company where we ended up building a wireless monitoring device, primarily for defense agencies to go about, you know, monitoring what's happening in the air. Uh, and from there on, I went and, you know, founded my second company, pentest Academy.
And the whole thought process was, this was 2011, and a lot of folks did not understand how attackers worked. So Pentest Academy used to create these big labs for banks, financial institutions, where they could have their red and glue teams, which is really their attacker and defender teams do these collaborative exercises. Uh, ran that for eight years.
Eventually, that got acquired by Providence Equity, uh, actually based on the East Coast. Took a little bit of a break and then started Square X around two and a half years back. Uh, and the whole thesis really was, you know, Alan, when I was running pen tester, I was talking to all of these red teams, and they used to come and tell me, Hey, Vivic, we are starting to see more and more attacks happen through the web browser.
You know? Sure. Because if you think about it, you know, people are spending all their time in their browsers, uh, you know, doing transactions, doing work, you know, watching entertainment on Netflix and whatnot.
So the browser was starting to become the new computer, the new endpoint, and attackers were taking note as well. So the inspiration behind Square X was, if everything is moving into the web browser, then security should also become browser native and a first class browser citizen. Uh, while today, you know, everything sits outside the browser, right?
Your antiviruses, your eds and all, or everything is outside. So we started with the thesis that why not build a product which can integrate with every browser on any device, and that is really a browser extension, and that extension can monitor, detect attacks, block them, report back to the enterprise. Uh, so we were very lucky that Sequoia Southeast Asia put in the seat check.
And then Syn Ventures, you know, did a follow on series A round. And in the last two and a half years, we've raised around 30 million. Uh, now we have customers, which are public market companies.
We have one of the largest crypto exchanges deploying Square X. And now we are actively, you know, PO ving at many Fortune 200 companies across various industries. Uh, because look, everyone has a browser.
So anyone who worries about attackers, you know, unfortunately has to protect their browsers, and that's really what Square X is doing. I love it. That was great, Vivek, thank you very much for that.
Before we jump, we're gonna talk about last mile attacks here in a minute, but before we do listening, and, and I have, you're the first kind of browser security person I've spoken to since this problem or question popped in my mind. I don't even know if you're gonna be able to answer it, but if you can, I appreciate it. Everyone.
Today's talking about AI browsers, AI browsers, open AI has, I forget what it's called, not Opus Atlas. Atlas Atlas, excuse me. Yeah.
Atlas and Perplexity has one, and Yeah. And they're all coming out and, you know, is this going to be finally something that replaces Chrome? I don't know, is it really that big a difference?
Spoken to a lot of people who use them, and I get a big map, you know, however, from a security point of view, yeah. Could it help? Is it better?
Is it worse about the same? What do you think? Yeah, great question.
So I think, you know, Alan, I'll start off with the first piece that you mentioned is, you know, are these browsers going to become ubiquitous? Right? And the best way answer is, you might remember the time when TVs had just come out with microphone and cameras, and we all said, we will never buy one of those.
Yeah. And, you know, a couple of years down, that's the only TV available with microphones and cameras. Yeah, Absolutely.
I think exactly that way. What's going to happen is all browsers are going to become AI browsers. And what I mean by that is, with AI starting to get integrated in all products, whether it's Chrome or Edge or you know, perplexity Comet or Open AI's Atlas, everything is going to have that AI assistant run alongside with whatever the user is doing, help him, you know, go through massive amounts of information faster, automate a lot of his workflows and all of that.
So my current current, you know, vision around this whole industry is the only way that these AI companies can control the whole user experience is by owning the browser, because they can never own the endpoint. Microsoft and Apple have already done that, so this is going to accelerate. Now, the second piece are these browsers secure?
Now, typical Silicon Valley, you know, they love to go ahead and release products, which are early because they love to iterate. Yeah. And, and this is really the TNA of Silicon Valley, right?
Uh, and this is no different in the case of Atlas Comet and all of these AI browsers. So in the last couple of months since they've been released, attackers have started breaking these browsers down. We, ourselves, as a security company, have found multiple vulnerabilities.
And just like in the early days when you had chat GPT, you know, go ahead and, and sometimes even say racist things and whatnot. At this point in time, AI browsers are pretty much breaking in similar ways, lot of attacks and lot of exploits. Uh, my prediction is that, you know, similar to what happened with Chat GPT Gemini and all of that, there's going to be a lot of fast duration, and eventually these browsers will start becoming more stable and secure As of today, uh, I wouldn't say enterprises would be terribly excited to use these browsers, uh, because there's a lot more security plumbing to, you know, be built in, uh, for use in enterprise.
Yeah. You know, y that I, I bid in security also before it was called cyber, right? Been in security 30 plus years, started a few security companies.
Unfortunately, this is an all too familiar story for us, like you and I who've been in security, security is always an afterthought. Let's rush it out. Let's get it out there.
You know, I'm reminded I has to be. 15 years ago, I did a podcast, me, a friend of mine from Gartner and myself, and we had on the CEO of Mongo DB and Couchbase, right? This is when no sequel databases had just recently come out, and they were all the rage.
And I, I asked these guys, I said, you know, a lot of people say no sequel stands for no security. What are you gonna do about security? And, and the audacity, they, they just, they plainly told me on the podcast, right?
They said, look, we'll build in security when our customers demand security. Right now, they just want no SQL databases. Yeah.
Nothing has changed. Absolutely nothing has changed. I want AI b browsers.
What about the security? We'll worry about that. We'll get to it.
Yeah. It's, it's, you know, it's, it's frustrating. It's frustrating, but I, I think as security people, we learn to, okay, maybe they don't think they want it right now, but they do.
And what can we do to start hardening this, to preparing for it, et cetera. Um, anyway, let's pivot back to last mile attacks. I appreciate you giving us your insight on that, but you know, not everyone watching this, Vivek is a security person.
We have DevOps people and cloud native and, uh, uh, all kinds, well, obviously security, but AI folks and transformation and platform engineers. Um, not everyone knows what we mean when we say last mile attack. So why don't we start with that?
Why don't you define last mile attacks? Yeah, so Alan, you know, taking a step back, uh, primarily the security stack today, which is going ahead and securing all traffic coming from the endpoint, uh, is really part of this big, you know, industry acronym called S-E-S-S-E. Yeah.
And that's really where you have all the big companies, you know, uh, Palo Alto, Zscaler, uh, Netskope, whom not. And the whole idea there was very simple is send us all your traffic coming in from your computer, from your browsers to our cloud data centers. We will scrub it, clean it, make sure that it is free of any form of security issues.
Now, that promise was amazing at a time, probably around a decade back when browsers were simple website renderers, and were not as complex as they're today, which is full-blown application platforms with multitude of new protocols, et cetera. They're, They're the ux Exactly. The browsers become the ux.
Yeah. And that's really where, what last mile reassembly attacks is unlike the time when these technologies were invented where browsers could do little apart from show a webpage. Today, browsers have the capability to run code, you know, web assembly, high quality, JavaScript, a bunch of other embedded languages.
So what attackers have started doing is traditionally what used to happen is, let's say if somebody were to send you ransomware as a malicious Excel file containing a malicious macro, which you would download, open it up and get infected, uh, in those days, your sass ESSE secure web gateways in the cloud would see a file is coming, pause that download in the cloud itself, one scan and see that there is a malicious macro and block it. Mm-hmm. But now with browsers being able to run code, imagine that no file is ever sent, and the browser itself using JavaScript on the page assembles and creates that malicious Excel right there in your browser, rather than send it from the server site.
So now your secure web gateways and sass ESSE solutions never see a file because actually there is no file, the file is getting created live in the browser. And the example I can give you the analogy for viewers is imagine that, you know, you are looking for some kind of a painting, maybe a Mona Lisa that somebody's trying to smother in. 0 secure web gateways.
So last mile reassembly is, rather than send the painting, you're sending the painter so that the painter can come and then kind of go ahead and sketch the whole painting in your browser. So if you purely scan for a file, you aren't going to see anything in the cloud because the file gets reassembled. Now, we can go about extrapolating this not just to files, but website, malicious scripts and whatnot.
So all your old attacks, which were capable of getting caught in the cloud, unfortunately, are all new again, because they get reassembled in the browser. So this is the big expose that Square X did last year at DEFCON main stage, and where we showed that existing every vendor is actually vulnerable to this architectural attack. And it is true even today.
Absolutely. Absolutely. I, I, whenever I see acronyms though, I always like to explain it for people who, who don't understand.
When we say sass e, SASS e like that, what do you, what does that stand for? Yeah, so sass ESC is this industry acronym, and the whole idea really was could you decouple networking, uh, basically from, you know, security. And this was something which was invented like a while back.
So SS e is basically secure access, service edge, uh, you know, fancy way of basically, you know, adding both networking as well as security and SSE security services Edge, uh, that is really just the security piece of it. So mm-hmm. There are companies which do both networking and security, and they belong to the SSE category while sse, pure security companies who don't want to do the networking, but rather just security in the cloud.
Got it. And when we look at Square x new generation, a new way of approaching this problem, fair? Absolutely.
Yeah. Yeah. And the, the way we are approaching this, you know, Alan is, uh, for a very long time, the only way was clearly to ate the laws of routing physics.
And instead of allowing a packet to go to the destination, you know, with the fastest route force, everything to go through these data centers of these sass, ESE players, fundamentally becoming a choke point, slowing things down, massive latency, bad user experience and whatnot. So the key innovation that Square X has done is, rather than having a proxy, we have the ability to look at all data, all user interactions, and all workflows in the browser itself. And this adds no latency, gives us a full 360 degree view of everything that the user is doing and everything that the browser is doing, allowing us to detect and block attacks right there rather than sass ESC, where all you see is network traffic, and you have to reconstruct what is happening at the application layer, which in today's complex browser-based protocols, unfortunately, is no longer even possible.
And that is the big innovation that Square X has done. Got it. You know, look, Jay Cha was in someone I know a long time in the security world, right?
And when he first started Zscaler with the idea of running things in the sandbox before it got to your network, it was kinda revolutionary, right? Absolutely. Yeah.
Jay's made a lot of money from Zscaler doing that, right? Certainly. And I'm not begrudging him, right?
He's done a great job, but you're right, there was always that latency issue, but that was the kind of the price you paid for, for security. Um, as things have gotten more complex, of course, everyone's come up with a little bit of a mouse trap on it, a better mouse trap on it. When, when you say square X secures it, test, it, scans it, whatever you want to call it in the browser.
So is is Square X then sort of a browser extension? A plugin? Yeah, if you will.
Yeah. Yeah. So Alan, the, the key realization we had is, you know, security solutions unfortunately can never tamper with how people work and should never get in the way of productivity.
And that's really where our thesis was, that if you start to give people a new browser and things like that, it'll never work. You have to work with every browser. And the only way to work with every browser is similar to your ad blocker, which works on Chrome Edge, Firefox everywhere, which is, it's an extension.
So our key innovation was to go ahead and push the extension technology to its limits where we were able to build a full security product as a browser extension. And the power of that is now we can deploy it in any browser, by the way, including the new AI browsers, including, so we, we actually secure Atlas Comet, all of them, right out of the box. So I, I'm thinking about downloading the Atlas one.
I'll be looking for the Square X plugin for extension for it. Vivek, I don't think we mentioned the website or anything, did we? No.
com, there's four letters, Sq RXs Q rx Yeah. Dot com. Uh, it took me quite some negotiation, you know, with, Uh, I would imagine it's hard getting a four letter domain, right?
Yeah. So that's the place everybody can visit to learn more. Excellent.
Um, going to RSA. Yes. So we did RC the last two years, and we planned to be there, you know, this year as well.
And every year, right before we, we, you know, do security exposes, vulnerability research and all of that. So we will be both at RSA as well as at Blackhead in the summer coming year. So We we're both as well.
But check in with us maybe before RSA. Let's hear about your new research. Absolutely, Alan will do.
All right. Vivek, Rin, uh, here on text on tv. Vivek a pleasure.
Thank you for coming on. com. We're gonna take a break here on Textron tv.
We'll be back in a bit. Hey everybody, welcome back to Ingram Micro One, and we're talking about AI and innovation with my good buddy. Eric, how you doing, buddy?
Nice to meet you, Mike. All Right. Welcome to the show.
I guess a lot of folks are talking about ai, it was almost like ubiquitous here in terms of conversation, but we're still barely scratching the surface. So where do you see kind of like the potential and the immediate opportunity for partners? Yeah, I think, uh, it's, it's a great point.
And that's always where we see the start, right? It's this, uh, I think in the US you say drink your own champagne. There are also other ways to say this.
I prefer the champagne one. Um, now what we're seeing in the, in the partner base, um, is twofold adoption. You see adoption of, uh, you could say the standardized, the productivity related AI projects that are, um, kind of, uh, um, um, generative in nature, right?
So that's your, uh, meeting assistance. It's also customer service, uh, related, A lot of that. So you see that internal adoption because all of them are resource constrained.
Like there are very few partners here that are like, Hey, we have more people than we know what to do with usually not the case, especially not in in current a market where the IT adoption, uh, and, and the speed of change is so fast that you want to, you can, you can barely capture all the opportunity that's there, right? So it's a good problem to have. I'm not saying there aren't tough environments, but that's a good opportunity or a good problem to have.
So how are they dealing with it? One, they're quickly adopting some of those, um, kind of almost off the shelf, uh, AI solutions to focus on efficiency and productivity. That's stream one that's straightforward.
It is basically the fastest way for them to create AI fluency for every employee of an MSP of Avar of ai, right? Because if you use a daily, you create fluency, but then the real projects that, that they're, um, that they're doing and that they're drinking their own champagne internally, are the first places where they're going into business processes and they're going ag agentic essentially, and saying, okay, what's the first type of process where we have, and I use the word, I call it non-human value add, which might be a bit contentious, but what I mean with that is you have a process that requires action taking that isn't always deterministic, but the result of it is right or wrong. Once it's right, there is no quality to it.
Once you've done it right, it can't be good or better. It's just right. That's the starting point.
And that's where we're seeing lots of partners focus and say, okay, what do we have? It's not about replacing humans that we can essentially introduce agen because we wanna get to the point where we're not just talking about generative ai, we're talking about AI that's taking action to give the, the, um, customer superpower. So that's the adoption we're seeing.
What we're not seeing so much at scale are like the, you know, model, fine tuning, deep kind of model training. We have partners that do this, but that's not the broad spectrum because it's, it's a long, uh, it's a long way to scale ROI if you're a, a smaller partner and a big investment to do this. And ultimately you have many other places that will get you, uh, an outcome and fluency much more quickly.
And at scale, How do I navigate this challenge? A lot of the business processes are to use what the AI folks will call deterministic, right? They're supposed to be done the same way every time.
AI is probabilistic and rarely does the same thing the same way twice. How do I kind of meld those two things together to get to something interesting? I Think there, there are, again, two, uh, two ways in which to control this one, um, is, uh, you gotta have someone that controls model drifting in, in the broadest sense, right?
The, the difference, uh, in the deterministic programming, which is input a, output B, that we've created those decision trees, right? Even in customer service and support, when you are talking to bots, that's essentially a, a very large decision tree. Um, you're going to a, a place where depending on, let's take gen AI as an example, and like a service, a bot or something that's answering questions, helping with decisions.
It's not just that it's deterministic, it's also learning through reinforcement. So if it starts getting asked questions that weren't the initial expected ones, its answers over time will also start changing. So a simpler way to think of this is, like, I, I always say like, I send my kid to school.
My kid has like his circle of friends, uh, his class, and I kind of know the behavior, right? It's not gonna be perfectly deterministic, but I know who he is around what they talk about, what they like doing. Now imagine all of a sudden his behavior starts changing.
Probably something in the environment changed, been exposed to a new group of friends, whatever. There, they're having different conversations, they're doing different things, behavior changes without anthropomorphizing. And that's the same thing happening with those more probabilistic and drifting, uh, AI models.
So step one is make sure that you have someone looking that is kind of regrounding less about hallucination, right? 2, um, in this, and that's actually, I think, a trend that isn't just solving an immediate challenge, but that will be around in the long run, is human in the loop, right? That's the straight of banks, right?
You wanna ensure that you have a human in the loop. Not so much to say this is right or wrong, but really to ensure consistent improvement of quality of what those systems are doing. And yeah, on the offhand also making sure that doesn't go off the deep end, basically.
So human in the loop will be around for a long time. I think a lot of partners are looking for something easy to get started with. Yeah.
And you've seen some use cases out there that, um, might be easier to replicate than others. So, you know, what's your best advice to partners about, you know, here's something you can go do on a dime and it'll be, and it'll work out well. Yeah.
And you'll get That muscle memory you're talking about. Absolutely. So, because we encounter this a lot, uh, at Ingram, we've created, um, basically a program, uh, to help those partners confidently sell, deploy and service AI solutions at scale and ideally in a repeatable way.
We call it advantage enable ai. And it is what, what our partners can, uh, go and seek on the advantage platform. It is aided by all our local expert teams.
So they are being hand held. Why? Right?
The starting point is you need to understand as an MSP, as an a var, where do I stand today relative to ai? Even if you've already built an AI practice, which in our experience has been, there's always a gap because it's changing so fast. So what's my business understanding, my technical understanding, what's my service capability that I have?
And not to forget almost the most important things, what is the current ask slash need of my customers? So example, I'm an MSSP, but all my partners, all my customers are talking about is using AI for productivity, right? So I have a choice pivot and start also doing productivity related, uh, technology business, hard force, the security conversation into the productivity conversation, which is valid, you should consider it, but it's going to prolong any implementation.
And that dime will turn into multiples very quickly or wait until the first thing is implemented, something relative to, to productivity, and then fast follow. Okay? So once that's done, the key thing is repeatable use cases focused on business outcome on select industries, because that's a language that every partner today speaks without an AI training can, can open up the opportunities.
So what we decided to say, we focus on only three business outcomes, which is, yes, right now it's for ai, but it's the same for any tech. Either you're deploying it as an end customer to be more productive, more with less, more faster, any of these permutations productivity or to create a better experience for your customers, for your employees, for your suppliers, doesn't matter, or that, or you're deploying a technology product to shore up security or governments. Those are kind of the three only outcomes that are relevant.
The reason that's important here, you talked about on a dime. 'cause in the first scenario, productivity, I can turn around a business case in probably three minutes. Experience gonna be a little bit harder.
We've all experienced that, right? Security is not hard, but it is cost avoided versus, you know, immediate benefit created. Now, once you have this, and you map this to an industry, and we do focus on, um, manufacturing, retail, healthcare, finance, and now also public sector, you have the kind of, um, trifecta of I'm trying to solve a productivity focused business problem for somebody in retail using technology from OEMX.
Not to mention, I'm, we're here today. Then you have a very clear path of what you need to do. And what we're seeing there today is that all the initial lift, as boring as it might sounds, are quick productivity based wins.
In a very simple way. If you're using something like a copilot, like I'm really taking that example. Let's say you pay, I'm gonna use an arbitrary number, 20 bucks for a seed a month.
Okay? The first time you've saved yourself an hour of work, which will probably happen on the first day of usage, you're gonna think of that as that ROI 'cause an hour is probably gonna cost you more than 20 bucks. So that is very easy.
But the, the crux is not just sell it, it's making sure that people know how to use it no different to past technologies and adopt it because that creates that tidal wave to move deeper into process, et cetera. So as kind of standard as it sounds, it's creating those, um, 80% of time, 20% of value projects, first productivity to then go into 20% of knowledge worker time, 80% of value projects. Next, Ingram is clearly invested heavily in ai.
How does the knowledge transfer between you and the partners occur? Because it's not just enough to have something I can go and download and install, I kinda have to know something about this. So how do you know you guys take all the intellectual capital that you guys have created and kinda share that with the partners?
Great question. So let's say in two, maybe three ways. One is, um, my team's focused on internal Ingram AI fluency.
That's not technology specific to ensure that over time every single person that works at Gram Micro can help the partners understand and navigate basically what's happening with ai, not down to the technical level unless you have that role, right? That's the first piece, because that's how it scales, right? We have over 20,000 associates in over 50 countries that are engaging these 160,000 plus partners.
And that is the way in which they thoroughly, uh, in which they thoroughly can transfer that knowledge. That's the first one. The second one is I spoke about advantage enable ai.
So that's actually the digital, uh, the digital platform where they can find the assessment in their, their knowledge, the use cases, and then the repeatable, we call them growth tracks where they can build a practice. However, that's digital. The way we do this is in every country, our local organization adds to it their local engagement.
So they'll say, based on who the partner is, the business they're doing with us and the commitment they have to taking this AI transformation series, we're gonna add these workshop components, these certification components, which are human interlock, right? So human in the loop, if you will. So we're doing the same thing, um, at a local level.
This, this program is all the automation, scalability, and self-service side of it make it really easy to use. And then the depth of knowledge comes through the transfer of our teams locally being involved from the business technical, all the way to the service tribe. Okay, Last question.
So what's your best advice to the partners? What should they be focused on right now? I think in English you say get stuck in, right?
Uh, so, uh, I would say engage with us right now. Come to enable AI and talk to your Ingram counterpart to it. Understand a where you are today if you don't have a strategy, understand where you are today and where your partners, your customers want you to be and what they want from you.
And on that basis, build a roadmap that is very concrete outcome focused and not about the hype side of the technology, but basically understand where you are, build a custom roadmap. And again, the advice is no different than on any other technology. Focus is what will make you win.
If you really understand your customer, that could be their vertical, the geo they operate in, the cultural context they operate in, and then also are able to map the technology to that scenario. You'll win if you just have a great relationship, go golfing, go playing tennis, whatever that might means, your relevance will wane very quickly. That's been set for a long time.
But with technology taking on really more and more proactive pieces, that is what's going to happen. So I'd say get stuck in right now. If you're treat it as hype or treat it as a bubble, you will not be around because nothing has ever moved as fast as this friend.
Alright. Hey buddy, thanks for coming. Was An absolute pleasure.
Thank You. Actually, same context is everything. Thank you.
Well, that's a wrap for this year's Ingram Micro Conference from us. And thank you all for watching all these episodes and it's been a great time on our behalf and I wanna thank Ingram Micro for having us, and hopefully we'll see you all next year. Hey everyone, we are back here.
This is, uh, I think gonna be our final interview for day one of Q Con and what a day it's been. You know, there's, I don't know, 10,000, 12,000 people here. The, the expo floor is cavernous though, and cold, very cold.
I'm glad I wore a heavy sports jacket. This poor guy's here in a short sleeved t-shirt. You're not cold.
I'm moving a lot today. So if I were sitting in a chair, you'd be cold. I'd probably be cold, but I'm moving a lot, so I'm okay.
Absolutely. But tonight is the, uh, what do they call it? The cube?
The cube crawl or Whatever. Oh yeah, the cube crawl. Yeah.
Yeah. The, You know, the, uh, They're gonna have drinks, food, everybody's gonna be hanging out in their Yeah. Is the word for it.
Yeah. But it's cube crawl and, and it's, you know, the, the in expo hall reception. That's right.
Yeah. That's A good word. Yeah.
Hey, if you don't know this guy sitting next to me, you probably are not a big fan of Argo or, or, uh, Gi ops octopus, Gi ops Octopus Cube. He's, he's with us almost every single cube con I've done. And I probably have done, I don't know, 18 of 'em.
Nine. Yeah. This is my ninth year of coup con's To a year.
Yeah. So you're right there with me. I, The only one I missed was the original one in San Francisco.
I missed that too. And I, ironic, strangely enough, I was like a quarter mile away from it when it was happening, doing else, and No, I didn't, didn't go over there. So I missed that one.
But then Seattle, I think was that next one. Yeah. And then San Diego wasn't there two Austin, remember where it was in Austin and it snowed.
Yes, I do remember that. That's when I realized how big this was gonna be though. Yeah.
San Diego still. Well, I, I will say this. San Diego and Valencia.
Oh yeah, my two favorite ones. San Diego and Valencia were great. Barcelona was good.
Barcelona was Really good too. That might be because Barcelona's a great Barcelona Didn't stuff, it's great. So I thought, I thought Valencia was a quieter kinder Barcelona.
Ah, yeah, yeah, yeah. It was kind of out there. It was farther away.
Yeah. Yeah. Well, there's a little bit of like, the hype factory has kind of gone down a little bit because you have a lot of people have moved into the operations phase, right?
Yes. With this stuff. And so in the very beginning there was such a push to like, we just gotta learn all the things and jump in and figure out what's useful and what's not.
And now we're in that stage where a lot of people are like, Hey, we're operating, we're happy. We're, we're scaling, we're, we're hitting the normal everyday challenges. I, you know, more than me on this.
So I'm not gonna pretend to be an expert as you are. But I really feel like, so first of all, at the beginning it was all developers. I felt it was very heavy developers, guys in t-shirts and backpacks.
Yeah. And Kube was so hard still. It was really hard.
Let's face it. Yeah. It was so hard.
And people were not looking for lifelines, but they just wanted to learn more, talk to people like them, do that community thing to figure this out. I think, I'm not saying Kubernetes is easy, I'm not saying cloud native's easy today, but it's certainly not as hard as it was. Yeah.
But I also think, as you said, we've moved from just pure developers to ops people mm-hmm. To platform engineers. Yeah.
To SREs, to security people. And, and so the audience, I, I would say let's even throw in that data scientist. Mm-hmm.
Right? And, and those kind of folks. So the audience has expanded, the product mission has matured, and the products and and projects themselves have matured.
Oh yeah. Where I think it's, it's just a more normalized thing. I I still think the passion is there though.
Oh, Yeah. Yeah. No, and there's, there's always new stuff happening and you know, a lot of the shift in this last couple, last two years has really been about supporting GPU workloads, AI workloads.
So there's a whole yes there isation happening there, but you all are doing a lot of stuff on cost savings, on developer productivity. So that's the efficiency phase, right? Yeah.
You always, first you try to just get stuff to work and then you make it more efficient. And then somewhere right after that you say, oh, we gotta worry about security too. Um, which is a problem.
Well, I, wait, we gotta stop a second. Sorry. I didn't give you a proper Introduction.
So you don't know. This is Dan Garfield. Dan Dan has, look you pioneered Argo in a lot of ways in GI ups, right?
Yeah. Um, Argo is now of course part of Octopus deploy. Yeah.
Argo is a project, is maintain, Argo Is a project CNCF. Yeah. It's maintained by Octopus deploy, uh, red Hat, Intuit, others.
And so we have a partnership with a number of different companies that we maintain the project with similar to Kubernetes. Absolutely. But I do, I do think there is a special fit because Argo the octopus, you got an orange octopus and you've got octopus deploy.
We're blue octopus. So we're, we're like, I got blue Oc blue and orange, uh, go together, Bring me an orange, lemme burn you, I guess. 'cause this is the commercial entity.
Yeah, that's right. Yeah. Yeah.
So I got the blue one. But, um, and I should mention, if you don't know, and you, maybe you don't follow this closely at hope, you know, um, Argo is the out of over 200 I believe projects now in CNCF Argo is number three right behind Kubernetes itself and, uh, open tell hotel. Yeah.
In terms of like contributions Yes. And activity and velocity, project velocity, yeah. Number three.
And, and Tel, uh, is so generalized, right? It, it really touches everything. So it makes sense.
And, and Kubernetes of course is the foundation. Sure. So those two make sense, but how do people deploy to Kubernetes?
60% of the time they're choosing Argo CD and number two isn't close. It's down in the 10% range. Really?
Yeah. 'cause there's a whole, there's, it's like everybody chose Argo cd and then there's kind of a sea of other things where like they're using Jenkins and they've just always used Jenkins, so they haven't moved on from it. And they're throwing Coops tail applies using that.
They may have good reasons to do so, but, but yeah, agreed. When we look at the marketplace, that's what we see about 60% of clusters are using Argo CD today. And, uh, in some vendors, some clouds, it's more, but yeah, we, we see pretty big adoption.
So Let me ask another question there. If you are using Argo, are you by definition doing GI ups? You are definitely facing GI Ops Now, whether or not you've actually implemented those principles, you can use Argo CD in non-GI ops ways.
Uh, so for example, if you're using, if you're referencing images using floating tags, you're kind of not really full, you're not really embracing GI ops and you can definitely, um, use Argo CD with manual sync turned on. So you don't have automated reconciliation. So Argo CD is pushing you towards get ops.
It's encouraging you to get, do, get ops, and it's the best way to do get ops in my opinion. But you can also, uh, if you wanna hold a hammer upside down to Hammer and Nails, you could do that. It's just the tool doesn't want you to do that.
But you could do that, You know? So I'll give you a life lesson. As I've gotten older, Dad, The tools make the man and using the right tool for the job is all the difference in the World.
That's true. Yeah, that's True. So you, you know, you wanna keep using the hammer upside down.
God bless you. But life's too short to do that. I I agree fully.
Yeah. Yeah, Yeah. So I, I wanna get into some of the announcements.
You guys have some of the news coming outta this. Yeah. But before we do, I I, I want to kinda solidify the, so we spoke about Argo, the partnerships of running, maintaining Argo.
Yeah. You are part of Octopus Deploy though, right? Yep.
That's right. And and their though Octopus Deploy is a maintainer of Argo. Yeah.
And a large part of their business, I imagine is, you know, in, In Argo Kubernetes. Yeah, that's right. But Octopus Deploy in is in and of itself an entity.
Yeah. Talk to us about Octopus Deploy with Argo is part of it, but nevertheless its own entity. Yeah.
So the, the history here right, is you have the Argo project is created by Intuit. And, uh, they said this is the way that we wanted to play software. There's a number of other tools within Argo that they were using as well.
And they said, we really want somebody to take on the mantle of running this thing. And so they looked to us Codefresh at the time. Now Octopus Deploy.
But, uh, they looked to us to, to be that group. And so we became the first commercial vendor to come onto the project, help it get into the CNCF, help it, uh, go through the process of graduation. And, um, to take on that stewardship as, look, we're gonna have a commercial interest in this open source project where if you're using Argo and you want to do scale deployments, ar Argo CD really has one job.
Look at a source of truth and GI and get that deployed to the cluster, everything else's kind of window dressing. Right? Now, what if I wanna manage a change from one application to another?
I want to promote something. Well, that's where, that's where Octopus Deploy comes in. What if I need support Octopus deploy?
What if I need, um, help doing architectural planning about how I'm gonna roll this out? Octopus deploy is the answer, right? So, so as a commercial vendor, we have an interest in maintaining that stewardship of an awesome open source project.
Uh, and then providing, uh, both tools and services to help you be successful with that project. The great thing is because we maintain the project with others, Intuit and, uh, and Red Hat Acuity, we cannot any of us take that project and go and just change the license suddenly and say, Hey, we're gonna take a bunch of features out. Uh, instead we have to focus on something that's gonna work for all of our interests.
But that's, that keeps Us honest, The foundational, it's not, you can't decide. I've got a Secrets program, I'm changing the licensing of them. Yeah.
I wanna, I wanna make money on the ui, I'm Tired 'cause I'm gonna provide a, a better version. So I'm gonna make sure the UI sucks, you know, for the user. We, we can't, we, we can't do that stuff.
We don't wanna do that stuff, obviously. No, But, but that, again, look, I've been in the open source game a long time. That is the beauty of this foundational model where that rising tide lifts all boats, right?
But no, no one company can, can manipulate this through their own financial gain. It's A super important point for governance. And it also means that we have a sustainable program for development.
So for example, we offer enterprise Argo support. Yep. Now our business octopus is really driven by selling our software, right?
That's where we make our money. And, uh, so the way that our enterprise support program works is, hey, we're off a unit prise support, but basically that funds our open source work. Yep.
So, a, as we add more, uh, enterprise support, you need, you need help with Argo CD or something goes wrong in the night with Argo rollouts, you can call us up, we'll help you fix it. Uh, if we need to provide a patch, we'll do that. But this is the way that we fund, uh, our open source contributions.
And of course, that also feeds into one of our biggest customers is the octopus platform because if, if something's not working for a customer, they may not care if it's Octopus or Argo. They just want it to be fixed. They Want one throat to Choke.
Yeah. So it, so that way, um, you know, any of our customers are essentially funding these open source programs and, uh, making sure that they can be successful, which is, uh, you know, it's nice to have Yeah. But it's, but it's really important that you have a sustainable approach to open source.
Otherwise you're just borrowing somebody's time until they don't have Time decide they don't wanna do it anymore. Yeah, exactly. Or they want to put the squeeze on and monetize.
They gotta Change that license. They gotta, they gotta get, look, I Saw this in security 20 years ago, you know, with, and, and look, to be fair, let me just play devil's advocate a second, Dan. Yeah.
Please. Do You get people who put their heart and soul into these open source projects? Absolutely.
You know, single company maintainer, they maintain a community where 96 or 97% or more of the people don't pay 'em a dime. Yeah. Won't even beta test or report bugs.
And it's kind of thankless. Right. And then you've got, and what really kind of, in my experience, what kind of tips it is, then you get other commercial entities who come by, use this open source tool that you've put your blood, sweat, and tears into.
Yeah. And they're monetizing the heck outta me. Yeah.
Taking money away from you in essence. Right. And I think for a lot of, uh, for a lot of folks, that's where, that's the, the straw.
That's the bridge too far. Yeah. Right.
And so they, they do do things like changing the licensing or, you know, making it harder for other people who they consider almost like parasites. Yeah. If you, you know, I don't blame, uh, companies that need to change their license.
They're the, they're the only ones maintaining a project and they're like, look, we can't pay to fund this development. We have to, we have to find a way to make it sustainable. Totally get that.
Um, I'm really proud of the fact that we've been able to build this ecosystem with Argo, where we have multiple maintainers. Yes. Where we all have good interests.
That, well, Again, that's the foundational model. It's a coopetition model. And it's not just vendors.
It's Interests too. It's end users and organizations into, Into, it's an example, right? Like, they're not selling Argo services, they want you to file your taxes and manage your money stuff.
Exactly. But for them to be successful deploying their software, they rely foundationally on Argo to do it. It's so it makes sense for them to invest in it.
It's key. Uh, and then it makes sense for us as, um, to be steward good stewards of the project because ultimately that's the ecosystem that, that, uh, is, is paying the bills. Absolutely.
Alright, we're running low on time, so let's turn, okay. What's news? There's a lot of news, uh, in the Argo project.
2 just came out this year. We shipped Argo CD three. Okay.
2. That means all of Argo CD versions two are now out of support. They're gonna start stacking up CVEs and bugs.
They will not be fixed. A lot of people have not yet upgraded a three. This is not Java.
You do not run it for 10 years without upgrading. You move to the latest version At your own risk. You wanna stay on that old stuff, you know, at your own risk and it's obsolete.
Yeah. And what we're talking about with, uh, the shift from Argo two to three, we made that a, uh, an arc. So we made very deliberate changes.
They would be very easy to upgrade through. And almost all of the behavior that's changed in Argo CD three can be changed back to two x behavior. We have a great upgrade guide to help you do that.
So that's new. That's exciting. We've got new maintainers.
We just added two additional really maintainers from Octopus Belo focused on Argo cd, uh, who, who just got promoted on Thursday and are now Maintainers Congrat see Them? Yep. They, they put in in the effort.
Shout out. Yeah. Uh, yeah, Eugene, he was walking around here.
Just a second. You have Guinea, um, as well as, uh, as, uh, Patrick Close, um, who wasn't able to make it this week. Yep.
Yeah. Gh what's his last name? Uh, den?
No, not the, we have a Evgeni who comes on our show once in a while, but yeah, He's, he's fairly new. But, um, we've seen these new maintainers do a couple of really great things. Roc Close.
He did a big migration in Argo CD to move GI Ops engine back into Argo cd, which is a massive project. Sure. He worked with Li from Intuit to get that done.
Did a great job. 2 because, uh, the version in Get Changed and he was able to track it took three weeks to figure it out, but we got it done. So won't be hurting users anymore.
We're allowed to see that. So that's going on on the, on the community version of Argo cd. Big stuff happening there.
Uh, and of course, as I mentioned, we offer our enterprise support for Argo, our technical account management, where we do proactive stuff, but we also just shipped a lot of new features in Octopus to improve your experience. Oh, very cool. So if you wanna stage out, you know, uh, for example, let's say I've got 10,000 storefronts.
They've each got a Kubernetes cluster, they each have an Argo instance, and I want to orchestrate promoting and managing all those Argo instances. I can do that with Octopus. If I wanna manage deploying new versions of my software to all those versions, I can do that with Octopus and That.
And that's the, so historically, that's where a commercial company that's maintaining an open source project makes their bones. Yeah. You wanna scale to that level.
It's hard as hell that you probably could do it at some level using just the pure open source. Yeah. You can write a lot of scripts, a lot of glue, but you've got a great foundation with CD's why you do it.
Right. You know, it was the same thing, remember back in the CloudBees Jenkins days, right? Yeah.
CloudBees knew that when you ran, I forgot what it was, four, four instances of Jenkins, you were probably ready for Cloud B'S enterprise. Yeah. Right.
Because that's the scalability that I think are in there. Yeah. And it's similar.
I mean, you could, of course you can manage, I, I know people that have 50,000 Jenkins instances and they're all 10 versions behind. Yeah. Well, There Is that because they, they didn't take a proactive approach to managing it.
And that's, that's difficult place to be. Uh, but yeah, there's the not only scalability, but usability and, um, user experience, things that we've been able to add. So those are new features that we've brought in to Octopus.
Now, for those that remember Code Fresh, of course, code Fresh is still running ci. And we've got these other, uh, components, GI ops things that we're doing. But, um, bringing in a lot of the learnings from that platform into Octopus, uh, as a unified platform is something that we're doing right now.
And we just launched that, uh, very cool for OpCon and, and people, uh, have been using it and building on it and growing with it. And it's based on a foundation that's, you know, a decade old at this point, because it has the ability to do all of your traceability and your, uh, governance, tracking, you know, compliance stuff as well as all of these scalability features. So it is really nice.
It's a kind of a peanut butter jelly. Best of both worlds coming together. I love it.
Situation. Dan, we're almost outta time. Two things I need you to tell him.
Number one, people who wanna follow with Octopus Deploy and what's going on there, what's the website? com. com number two, Argo people who are into the, the project, they could go to GitHub, they could go to the CNCF or they could go to Argo unpacked.
This is our new Argo podcast we've done, I think. Really? So it's now we have 1500 subscribers.
We just lost it. Oh, it's a big on YouTube. We have 1500 subscribers.
That's beautiful. Uh, which is awesome. And of course you can subscribe to that on your podcast app.
Favorite podcast, Argo and K. We talk through technical issues, we talk through strategic issues, cultural, philosophical as it relates to delivering software using Argo CDR, using Argo rollouts. And we love it.
Uh, yeah, we're loving that Shnu show. Alan, appreciate you Mrs. Garfield.
He did a hell of a Job here today. I'm awake this time. I'm awake this time.
We're proud of you, Dan. It's good to have you. Thanks a good luck continued success and keep doing what you're doing, man.
Thank you. Appreciate it. Dan Garfield here on Text Drunk tv.
We're gonna take, well actually that's gonna wrap up day one. We'll be back tomorrow with more. I've got some parties to go to.
This is Alan Shimmel. We're out. Hey everybody.
Welcome back to Gram Micro one. We're talking with my new friend Sophie here about what's happening in the channel in France. Sophie, welcome show.
Good to see you. The partners, I'm sure have lots of challenges. There's a lot happening in France Yeah.
These days. But when you talk to them, what's keeping them up at night? So they have to face a lot of headwinds right now.
So they think about the, the way they can be innovative in this market, which is slowing down because of the fact that the budget has not been voted yet. So all of the public sector, or most of the sector budget, uh, project have been frozen. Uh, enterprise tends to delay a bit their investment.
So in front of this, uh, tough market situation, it's important for them, first of all to streamline their opex, uh, see how they can be more efficient, and also to, to, to accelerate their performance. So they're looking at it with us. So it's all about how can we standardize the processes, refocus our teams on the added value task so that we can create mature value.
We had also seen that a lot of the end customers in France are probably navigating all kinds of economic issues themselves. Yes, indeed. And they're probably looking at the partners for some help as to maybe how to streamline things and be more efficient.
Exactly. And, uh, so then the purpose for the resellers is to see how we as distributor, we can help them, uh, meeting their partner's expectations. So it's important for them to be able to leverage our technical resources and our human resources.
So it's all about what we are talking about right now. Mm-hmm. One of the things that we're talking about here at the show a lot is there's a shift, a little bit to focus more on business outcomes.
It's not enough just to be a trusted technology advisor. I have to work with the end customer. I have to know something about their business a little bit.
Is that playing out in France as well? Yeah, of course. So now we are all looking at the way we can, um, create better value for our partners, uh, for their own partners.
And it's based on all of the artificial intelligence we are leveraging through our platform. We have talked about it a lot right now with and Sanji on stage, talked about it even more this morning. So how can we accelerate the performance?
How can we increase the breadth? How can we leverage the new tools? We have, uh, Sanji talked about the digital assistance, intelligent digital assistance we can leverage to do that.
We can use, uh, and finally what I think it's, we can talk about artificial intelligence, but first of all, it's about human intelligence. How can we have the right purpose, uh, in our discussions? There will always be some human in the middle of that process somewhere, Right?
There will always be. Fortunately, I hope so. Um, I guess the question I would have though is things tend to roll downhill in this world.
So are the partners leaning more on you for certain expertise in professional services because they can't always find that talent, or they might not wanna invest at something that they once Yeah, Yeah, yeah. So the kind of service we are talking about, we were so far talking about professional services, for example, around the cloud, around cybersecurity. But I think that more and more we will talk about new services consultancy around how can we all leverage this new technologies, how can we leverage artificial intelligence, uh, in the way we can all increase our overall efficiency?
And they need also our experience to do that. Right? So, uh, Tiffany yesterday talked about the fact that we need to use energy as a service.
So I, I kept it in mind, uh, what is the narrative, uh, beyond artificial intelligence? Because what we see is that we all are using artificial intelligence for our own purpose, but what are the, the true, uh, use cases in the enterprise, right? How can we really streamline the workflows?
And I think that most of the partners, they are not very clear that yet. So they need us to be trusted advisor and accompany them in this motion. As that occurs in every country that I talk to, there seems to be a skill shortage.
And for the partners, it's almost doubly acute because I need technology people who are customer facing and friendly customers. So how does Ingram work with them to kind of find that kind of unique unicorn in the IT landscape To, to find what kind of unicorns, Uh, IT people who are have, uh, who can talk to customers and explain things to them and are very, uh, have a lot of empathy for the customer? Yeah.
So you mean how do we find this talent, or it's not that easy to find this kind of Yeah, that's my, that's my question. Yeah, because it, so even in it, the, the, the job is really shifting a lot right now, and we are less relying on the skills than on the soft skills. So it's about, so it's a combination of IT skills and, uh, the ability to create the right synergies with the salespeople so that we have a common language to the people and to be to the customers.
And to be honest, in France, we didn't find the right profile yet. For, for fortunately we can rely on the global resources. All of the people from SANJI team can really help us.
Then we still have, uh, to deal with the language issues. So we, we are leveraging the local re the global resources from an IT perspective and leveraging our local resources for the sales purpose. So it's a good combination.
France, of course, is part of the eu. Is there more transactions spanning multiple borders or the partners working with each other in across Europe? Or is they, are they still pretty much focused in their particular country or?
No, it's still really focused at local level most of the time. So what we see is the complexity doesn't come so much from the fact that we have to interconnect different countries, even if it can occur. But the complexity, complexity comes more from the, the, the fact that when we deal with project, we have to combine different technologies, different skill sets.
So, and we need sometimes to connect different partners to each other. And for that, the platform advantage is made for that. It's a, it's an ecosystem which is made to create mutual values between the vendors, the customers, and also to onboard some customers on the same project and be complimentary in their skills.
Are the partners becoming more open to that level of alliance with other solution providers? 'cause sometimes, at least historically, they always kind of view each other a little wally because they think they're competitors. Yeah, It's interesting to see during this event, for example, we are here with 10 French partners.
And during lunchtime, even during the dinner, they start talking about the, their skills, their experience, and to see how they could, uh, be complimentary and work together to compete with some big players. Right? And it's true in the mid market, mid market area, in the SMB area, Of course, we're here in a show, and I don't think we can go very far without running into somebody talking about ai.
And we talked about it earlier, but what's the level of enthusiasm in the, among the partners for ai? I mean, are they kind of studying it or are they, uh, are they all in? No, they are not all in yet.
So it's, it's, uh, they're wondering exactly what it means correctly, right? Because while most of the people, they know what they do with GPT, for example, for their personal life. Uh, coming back to the enterprise, uh, beyond ai, there are a lot of questions around what, as I mentioned before, what are the concrete use cases, but also from a security perspective, how can we make sure that we have the best use usage of it without compromising our data?
So for that, we need really to explain them through our own AI factory that we can secure their data and I can, we can provide the right added value and, uh, and contribute to their business development without, of course compromising their own security. Mm-hmm. Um, one of the themes of the keynotes here has been this whole notion of using AI to make it easier to do business, not just with the partner in Ingram, but from the partner to the end customer.
Yeah. Do you think that we're gonna see like a significant reduction in the amount of friction that has historically been in those processes over the years? Yeah.
Yeah, I think so. If you take the, what makes the job of a distributor right now, there are still a lot of, let's say, lower value task around the quotation management, for example. And it creates a lot of workload, a lot of burden, uh, even from a financial perspective.
So if we can remove it, remove this kind of friction, if we can, um, accelerate the, the time to market of the quotation, if we can have a real, really, uh, uh, full digital process from the catalog ingestion to the, to the, to the invoicing, imagine how, how qualitative can be the discussion afterwards. Because now we still have to talk a lot about, do, did you get my quotation? What is the price?
When will it be available to me? Uh, did, uh, do you know when I will be delivered? For example, if all of the information is available on the platform, then we can really start talking about strategic initiative.
How can we build the future together? So I don't think that artificial intelligence will make us less close to the partners. It's exactly the opposite.
The more we'll develop it, the more time we'll have to, to, to develop qualitative discussion and, uh, to, to really, um, build the future together. We might have time for a drink and dinner to discuss something rather than In France. It's very important, you know, to have a very good, uh, glass of wine and talk about the business, of course.
Is there something you wish the partners would be focusing more on? And as you kinda look at them and you talk to them, I know they're all different, so it's difficult to generalize, but as you kinda have those discussions, is there something that you kind of, you know, would wish the partners or some piece of advice that you would give them and say, folks, you need to spend a little more time on this. I don't think I'm the right person to give advice to my partners, because we are all on the same boat, all facing the same, of the same kind of difficulties.
You know, the problem with this deep transformation we are going through right now is to deal with the day-to-day operational issues. We have the, with the business pressure we have as well. So we need to deliver short term outcome while transforming in the longer term.
So the advice I would give is to try to combine both, sorry, and spend enough of time, even one, two hours a day to keep thinking about how the future will look like and how can we, uh, foster the right dynamic internally to have the right talent, thinking about the way they can streamline workflows, the way they can create more values for their own partners. And it's easy to say, it's not easy to do because it's about the purpose. We need to reassure all of the people about how the future will look like.
Each time we're talking about artificial intelligence, you know, that there is a fear behind it. We will lose our job. We will be less, uh, intelligent in the future because we will fully rely on artificial intelligence.
What will be our added value? What about the, the enablement? So we really need to all think about it and see how we can, first of all, I think really first of all, drive the right purpose.
What is the storyline behind it? What do we want to get out of this artificial intelligence capacity? So we started the conversation with what's happening in France today.
We're kind of at the end of the year. As you look into 2026, you know, what do you think will happen? What is your crystal ball telling you?
So in 2016, so, you know, for me, AI is like the, the way we were talking about cloud 10 years ago. You know, we have talked a lot about cloud. And finally, between the time we have started to talk about cloud and the time we have seen concrete, uh, outcome from a business perspective, it took a while.
I think that in 26 we will start, first of all to see two motions. First of all, our partners customers and even ourself being very much more concrete in the way we can leverage this ai, uh, technologies. And on the other end, start seeing some real business opportunities around it.
Uh, while so far we have seen some very big deals, uh, around ai, uh, some solutions, uh, uh, embedding Nvidia, for example, but we didn't see in the SMB in the mid-market area, we didn't see really the integration of this AI opportunities from a business perspective. And I hope that in 26 we start seeing it. Of course, another big part of this channel equation of the vendors themselves, there was many of them here, they have boots.
Um, is there something that you wish they would understand about the channel in France and the partners in France a little bit more than they do today? What they need to understand is that it's important for them as well to standardize their processes. Because if they really want to keep benefit of all of this new, um, platform or digital platform opportunities, they need to accompany us as well by providing us the right access to their data, by standardizing their own processes, breaking some silos so that we can really all together make it much more fluid and, uh, the added value for them will come out of it as well.
All right. Hey folks, you heard it here, France. It's a funny thing.
They have a different word for everything, but they have the same issues we do. Hey, thanks for being in. Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series.
I'm your host, Mike b. Today we're with Tim Sprecker, who's the CEO of the Hub. And it's a company that's kind of dedicated to making it possible for people to sell slivers of their network bandwidth to folks who are training AI models.
And it's kind of a, an effort to democratize that process a little bit. Tim, welcome to the show. Hey Mike, thank you for having me here.
It's a pleasure to be here. Alright, well walk us through how all this works and what, what's going on here. I think people have gotten used to the notion of maybe selling a sliver of their storage, but maybe no one done about their network bandwidth.
But how did you guys build this and how does it all work? Yeah, so let's start with the fact that today as AI has hit one of its biggest bottleneck, it's not compute, but data AI models now need high quality, multi and fresh data that really reflects how the world operates. And the problem is that today this data is fragments locked behind silos or simply tool, resource or local quality.
That's why at Hub, our mission is to turn the world into a distributed data infrastructure. And how we do that all globally distributed network of nodes that leveraged the idle bandwidth and residential ips of users, our end to infrastructure collects, refines, annotates and deliver multimodal data streams. What we means by multimodal it's video image and audio to poor AI systems and AI training at scale.
One, our core is also our ability to collect large scale of public low quality, messy type of data and transform it into gold standard adult assets. And we all know that data is the foundation of ai, yet it's a hundred billion our market that still lacks the scalable end to infrastructure. And that's what we're building at Hub.
And we'll have the opportunity also to discuss that after. But we also closed our recently with Swiss as investor. We are now entering this, the, we are based in San Francisco.
We are working, uh, here with, uh, a couple of companies from, uh, tech startups to also know some deals with top 10 tech companies. So there is a lot of learnings from that and a lot of demands also from this company that we're happy to serve through the distributed network that we're building. Hmm.
How does somebody sign up for this? Is this something like, is it a consumer and can, uh, somebody in their house kind of share their bandwidth or is this more of a corporate kind of play where somebody has excess bandwidth? So, uh, on the bandwidth sharing side, it's purely a B2C play.
So it can be anyone with a device, uh, especially at the beginning. It'll be launched on desktop only and fun after that. But it can be someone that go, uh, with his desktop, he can download either browser, browser extension or desktop application.
And thanks to that we can get access to the, to his network setting. 3% only. Do not impact the user experience plus the residential IP of, of, uh, this user to be able to collect public data at scale.
So small, small orchestrator, we can get, uh, send some kind of scrapping comments, scrapping job to the device of the user to collect public data. Is there a a time element to this? 'cause I may need more bandwidth in the daytime, but I may not be using it at night at all, and maybe I can resell that to you.
Is that part of the equation? Yeah, totally. Based on the current bandwidth that you are using, we are also adapting that, uh, of course if you are running a 4K movie, it'll not be the same, uh, as if you are just looking for your email.
So de based on that, we also adapt, but it always stay very low because the thing that we wants avoid the most is really to impact the user experience, who could be, uh, uh, very bad for the network and very bad for the, the, the user experience and the retention of the users. So that's something that we always make sure to have because we know, for example, some VPNs sometimes are too heavy and are maybe slowing down the, the connection that you can have. So us, that's something that we wanna avoid.
Does it also matter where somebody might be physically located? Does somebody need more network bandwidth in say California than they might need in, I don't know, rural Ireland or something like that for training AI models? And does that factor into your thinking as well?
Yeah, there is something that we call the, the network score. And so the net network score is a, a compute of, uh, computation of different things, including the bandwidth power of the users, the quality of the internet connection he has, but also the geo distributed factor. So for example, depending of the moment of the year or just like depending of a general use case, there is some part of the world that are more interesting than others.
Or if at some, at some moment we find some kind of, um, uh, big, uh, difference between two regions of the world, maybe we balance a little bit, reduce a little bit the reward on one side and upgrade a little bit the reward on the other side to make sure that the network is always, uh, globally distributed based on the use case we have. So yeah, it has, uh, it has an impact. It's not a big thing, but it can have, uh, an impact on the network score.
So how does the pricing work on this? Is it a flat fee or is it very widely based on, uh, the level of congestion and maybe there's something called congestion pricing at work here, The pricing is mainly done on the network score that we just discussed. So at the beginning, starting with a point system for the users, uh, when it'll be live, so the user are earning points, but those point, those points will vary ba based on the network score that they have.
So if someone is, uh, having like a very high speed connection in, uh, uh, maybe North America or Europe, he will earn more than someone that could be, for example, with a low quality connection in Southeast. That could be the kind of things, because one of also the, the modes that we are building, we through this network is the fact that we're distributed because, for example, sometimes the same information is not the same. If you look at it online, like a simple website, if you look at it from like, uh, one part of the world or another, you might not have the same price, you might not have the same copywriting, the same uh, the same uh, image.
You might not have the same, uh, message at the end, uh, displayed on the website. So that's why for us, the show distributed factor is important. And also sometimes there is some kind of, uh, blockers for the, for the scrappers.
And it's important to, to face those blockers to also have this, uh, geo distributed factor in place On the people who are consuming these services, the people building the AI models, how do they invoke this and um, and why would they go this route versus maybe trying to lease lines or do anything else that they may need to do? Yeah, so basically for them, the fact that the network is, is not something that they, uh, really value. What they want to know is are we able to get this data?
Are we able to get it at scale and at the fair price? That's for them. What, uh, what we're selling them.
We are usually not going into too much details about how the network we, uh, works for them. We're really focusing on that. And so because this network, we're just talking here about the data collection parts, but also one of the big modes of hub and one of our, let's say, uh, expertise is not only on the data, data collection is really on all the pipeline that comes after.
So the data processing, the refinements, the annotation labeling, qa, and then the delivery to those CI companies, because of course hub data, uh, data that you can collect still has some value for those companies. But why they also want to work with Hub, because Hub can own the full pipeline for them. And so they don't have to work with three or four different, uh, um, third party providers, uh, to do each step of the pipeline for them, or they don't have to create a whole department that will build the pipeline for months before being able to train their AI models.
That comes to Hub because data collection is done efficiencies for this kind of mechanism, but also because HUB can under all those parts. And that's also why, uh, hub has this early success on the B2B pipeline here in San Francisco. Are there any concerns that the internet service providers may look at what you guys are up to and decide that they wanna throttle some of this because you know, they're trying to reroute bandwidth all the time?
Or is there just a lot of excess bandwidth and nobody seems to care and we just need to find a more efficient way to use it? Yeah, no, no issue from that, from the different discussion that we have and from the benchmark also that we have, especially because what we are using is, uh, bandwidth that is usually wasted to, uh, bandwidth that's usually gonna waste. 5%.
So it's a very small amount of the bandwidth, which not like great an overall load, uh, for this, uh, yeah, IP So where do you go from here? What's next for you guys? So HUB is life since two years and a half ago.
First started with more like social tools. We created, uh, an AI agent this year. We had a massive success with that half a million users on the platform.
I, I think that we've been the first one to gamify AI training on social networks. So it was like an entire experience where the users were replying on Twitter to the AI agent we created, the results were crazy. We had at a point like 100,000 replies per tweet, uh, on the agent, which is something that we never seen on on Twitter.
And so it was the first step for us of this narrative of me as a user, as a hub community member, I'm sharing some data, uh, to the agent and to train ai. And in exchange I'm getting some points, which is the same narrative that we have now with this distributed network. And what's next for us is to launch this part of the network.
So we already have the pipeline working with data centers, ips, we already have the first customer sign, the first revenue coming, but now the next step will be this quarter to launch this distributed network. We decided to first work backwards from the end customers, from the AI companies before releasing it. So when we release it, we already have a business model.
We already have a strong, uh, revenue coming and also for all the learnings that it created on what we suggest before, what comes after the data collection, what we do with the raw data. And a lot of the, the current infrastructure has been shaped by those, uh, previous customer. And so after that, we have a lot of exciting things also in the pipeline for this year.
Uh, we want to do, uh, also some data crowdsourcing system. So currently the user, it's like a passive contribution to network. They just download the app, they put, uh, they switch on the button and then they wait.
They are getting points and we're taking the bandwidth. But for some use cases that we see, especially with enterprise customers here, sometimes they want some data that are not, that are just not publicly available. And so how can we collect this data?
It can be done also through this distributed network of people because it, we could be done through some Quest or gamified mechanisms where, for example, they have, uh, they have like a mission out today. You take your phone, you go in the suite, there is like a car in the suite, a sport car. It's a, we need the 360 videos of those cars for like 30 seconds.
Then they can upload it on the, on the platform, getting some points in exchange. And at the same time, us, we are able to create some kind of data sets that are not publicly available and that are very valuable for the sale companies. So that's the first thing that we have in the pipeline that we call for now data crowdsourcing, but put potentially Amazon in the future.
And then another thing that we want to do, uh, for next, uh, for next year is a decentralized kind of human in the loop annotation and qa. So, uh, razor then working with third party, uh, company, uh, we will be able to also some network members, some users to do some kind of create annotation, uh, quest to review what our VLM, our vision language models are doing with the annotation side up to that. So that's how we go from passive to active contribution.
So do you think as we go forward that the training of AI models is gonna become a lot more distributed than it has been up until now? And I think a lot of folks were kind of pulling data, loading it into some massive data center and trying to figure out how to throw GPUs at it. But I think we're moving towards smaller AI models that need to get trained and they need to get access to data that's more recent.
So is the way we think about training changing? Definitely. And I also think that on the market we'll see more and more needs for high quality data and a lot of, uh, the training in the past has been done, uh, with like low quality data or just with textual data sometime outdated.
And now we see the AI training going to more like a multimodal, as we say, like a video image audio. And especially also as you say, smaller models that are more specialized in LLMs, for example. So one of our customers currently in voice companies, they want to open new market and they are just being blocked because they don't find the high quality data that they want for the specific language and the specific areas of the world.
And that's how uh, HUB is currently being helpful for them on the data collection part to everything that we do after to goes from low quality to height quality for their AI training. And I think that this is something that we'll see more and more, um, going from like bronze or silver grade into always trying to reach for gold standard for, for pre and post training. Well, you heard it here folks.
Sometimes we overlook some of the fundamentals in networking being one of them. And there's another way to think about skin in this cat though, so that you don't have to necessarily buy huge networks for yourselves when you can leverage up a service like this. Hey Tim, thanks for being on the show, Mike.
It was the pleasure. All right, and thank you all for watching the latest episode of the Textron AI Leadership Insight series. You can find this, uh, no, lemme try that all again, thank you all for watching the latest episode of the Textron AI Leadership Insight series.
You can find this episode and others on our website. We invite you to check all those out. Until then, we'll see you next day.
Good morning everyone. I am Heather from Influx Data. Today we'll explore how time series data has become the foundation for lots of DevOps operations and why it's pretty critical as we enter the AI era.
Your applications will generate millions of data points every second from server metrics to application performance, user interactions, and API calls. So traditional databases weren't exactly designed for this volume or velocity of timestamp data. And this is why times series databases like influx have become pretty essential to infrastructure.
They're purpose-built to handle high cardinality, high velocity data streams that modern applications, especially AI applications tend to generate. And today I'll show you exactly why through NetApp's transformation story. Before we dive into it, let's establish why you know, site reliability engineering has become even more critical.
It blends software engineering practices with operations to deliver more reliable services. The core philosophy is to automate yourself out of a job using automation to eliminate that manual toil. But here's where AI changes a lot.
Traditional SRE practices were built for predictable and more deterministic systems, but if your web server fails, it will fail in predictable ways. If a database goes down, you get clear error messages. AI introduces fundamental unpredictability and a language model might start generating much lower quality responses without throwing any errors.
And token costs can be very expensive at that point. So model updates will also silently change behavior without obvious failures. How are you supposed to keep a track on this?
So this means that waiting for systems to break and then fixing them simply don't work for AI workloads. You need proactive time series based monitoring that can detect subtle changes in behavioral patterns, cost trends, and performance degradation before they impact your users. Let me share a perfect analogy for a modern SRE that comes from nets team themselves.
Fix your children playing the balloon game. Everyone's running around trying to keep balloons from touching the floor. The balloon represents your service.
When it's airborne, you have UPT tie. When it touches the ground, you have downtime. Traditional monitoring tells you after the balloon hits the ground, but with time series monitoring, you can detect when the balloon is falling, even when you're not watching.
This becomes absolutely critical with AI because they can fail silently. A model might not degradate in gradual ways that you would expect or cost can just creep up slowly and it doesn't traditionally alert you as to why that is. And time series data will give you that early warning system.
It's the ability to see trends and patterns that predict failures before they happen. Now let's talk about how to measure reliability in the AI era. Using three Q metrics that work for both traditional and AI services service level indicators, which are SLI measure actual performance For traditional APIs, this might be response time or error rate.
For AI services, you're tracking token generation speed response quality scores or inference latency. The key difference. AI SLIs have much higher variability and require baseline establishment across different model types and prompt patterns.
Service level objectives or SLOs set your reliability targets. Here's some pretty crucial insight for ai. You deliberately avoid 100% targets because you need an error budget to experiment with new models and techniques.
AI development requires constant iteration and to perfect reliability would prevent that innovation. So an Arab budget is calculated as 100% minus your SLO. It provides unreliability tolerance.
Here's what's kind of fun about this framework for ai. Both infrastructure failures and problematic model deployments consume the same error budget. This forces teams to balance AI innovation with system reliability in a very measurable way.
And this framework becomes your decision making tool. So when you're considering deploying a new model version or adjusting prompt engineering, you can evaluate that risk against your remaining error budget. It transforms AI operations from kind of a gut feeling to a little bit more data driven.
That's what we're here for. So let's talk about NetApp. How do these concepts work in the real world?
NetApp is a $6 billion Fortune 500 company with 12,000 employees primarily known for data storage and infrastructure. You probably are aware of them, but what makes their story compelling is that they represent the challenge that every established enterprise faces today maintaining legacy systems while rapidly adopting AI driven development workflows. At the same time, this is not a startup experimenting with ai.
This is a company with decades of critical infrastructure that customers depend on. Now building cutting edge AI tools for their developers. They could not rip and replace their existing systems.
They had to bridge the gap between traditional operations and AI native workflows using time series data as that foundation. So their transformation demonstrates exactly why purpose-built time series infrastructure is essential for the AI era. The heart of this transformation lies within NetApp's engineering tools and services system.
The single team manages an incredibly diverse portfolio that perfectly illustrates our connected world. Challenge. Traditional data on tap build forms, common test lab environments, continuous integration testing, and now gen AI services.
Think about the operational complexity here. They're running legacy build systems that have worked reliably just reliably for years. Alongside all this experimental stuff, they manage AI driven code reviews and VS code co-pilot integrations at the same time.
This diversity represents the reality many organizations face today. You meet a monitoring strategy that can handle both predictable and unpredictable workloads with the same infrastructure. Let me show you the true scope of what NetApp was trying to monitor with traditional tools.
Look at the scale. Traditional CTL applications managing 32,000 compute nodes and 35,000 VMs processing 100,000 hours of testing monthly CCIT applications handle 800,000 hours of testing per month, processing 17,000 submissions and preventing 135 code verts monthly. These reverts represent commits that would have caused prediction issues.
And then you add gen AI apps, 14 different LM models and internal LM proxy for cost management and an AI driven code review. Notice the pattern traditional infrastructure with predictable patterns. CICD with deterministic testing and AI services with completely variable behavior.
This is exactly the connected world challenge that we mentioned at the start. Millions of data points per second across completely different types of workloads needing unification before their transformation. NetApp faced the exact problems that traditional databases create in our connected world.
They stored custom metrics and relational databases that weren't exactly optimized for time series queries. Uh, engineers relied on traditional Linux tools. Top, um, HOP IAT for system monitoring.
Nagios provided basic alerting for them. As NetApp described it, when all you have is a hammer, everything looks like a nail. Every alert just appeared really critical.
So there was limited context. Engineers experienced significant alert fatigue and started to ignore it a bit. But here's a crucial insight.
Um, this approach completely fa falls apart with the new AI workloads that they had. So you need granular visibility into performance patterns, cost metrics and behavioral changes. Traditional databases just simply can't handle this volume and velocity and cardinality of AI monitoring data.
NetApp evaluated several solutions and made a strategic decision that proves my earlier point about purposeful infrastructure. They chose influx, a time series database as that foundation. This decision proved crucial for AI workloads with 800,000 hours of testing per month and now AI inference requests with highly variable patterns, they needed a solution optimized for that.
AI monitoring generates significantly more diverse metrics than traditional infrastructure. Model performance varies by prompt type, user, region, and of course time of day. So you need a database architecture designed for this complexity from the ground up and that is what Inflex excels at high cardinality data with fast ingestion rates, efficient storage compression and very fast craze across time ranges, whether you're looking at the last minute or the last year for historical data.
NetApp's architecture demonstrates how to build unified monitoring for these diverse workloads. At the center is InfluxDB Enterprise with multiple data nodes and meta nodes for high availability. This ensures no metric loss in outages critical for post-mortem analysis of any kind of incidents.
Telegraph agents collect metrics across everything, traditional servers, databases, and AI services. The agent's lightweight footprint and extensive plugin ecosystem, which is free by the way. It means that they can monitor legacy systems and modern AI APIs with the exact same tool.
The flask risk. API manages custom metrics and outage tracking Jenkins integration allows test results and AI model performance metrics to flow directly into influx connecting CICD pipelines with the operational monitoring. This unified approach means you don't need separate monitoring stacks for AI and traditional infrastructure.
One-time series database handles both workloads effectively. NetApp discovered five critical challenges when adding AI workloads all solved through time series monitoring request and response variability. AI inference can vary from milliseconds to tens of seconds for the same endpoint.
So the solution is to establish separate baselines for different models and payload payload types using historical time series data Inference costs, uh, like input tokens can cost a little bit differently than output tokens. Really depends on how you're using it and who you're using. The solution is to monitor the token counts, the request sizes and output lengths to control those, cross those costs proactively.
Instead of reactively silent behavior changes. Model updates can alter outputs without very obvious failures. So the solution is to run canary prompts periodically to just detect that drift, which I think is probably one of my favorite parts of the solution that they put together.
Multi-region complexity, which is 14 models across regions, can create hundreds of failure combinations. And the solution here was to do granular monitoring data that's filtered by model region and calling service, um, which can become a cardinality problem that they eventually used influx for. Here's the result, NetApp's reservation.
65%. 8 seconds significantly above their baseline and send a Slack alert within 10 seconds. This rapid detection pipeline works.
It works completely identically for AI APIs. Token usage spikes, response quality degradation or model timeout issues trigger the same alerts, same framework, same tools, unified the that, uh, transformation kind of proves the points here. First, you know, time series databases are pretty essential infrastructure for our connected world, especially with AI workloads generating unprecedented amounts of data volumes and cardinality.
Second, you know, SRE becomes more critical with AI because traditional monitoring approaches will fail with non-deterministic systems. You need these proactive pattern based detections. And third, that unified monitoring does work.
The same S-L-I-S-L-O error budget framework applies to both infrastructure and AI services when you have the right time series foundation. So if you start with a purpose-built time series infrastructure, you can adopt the SRE metrics framework and then recognize that AI requires that different approach. But most importantly, and what I want you to take away from today is to not build different stacks.
It is a monster to try to wrangle and NetApp, um, has really done an excellent job with their own architecture here to figure out a better way to not make it be so cumbersome. And they prove that unified monitoring across diverse work workloads is not just possible, but it's absolutely essential for all of their AI native operations. Here's some reminders of the tip specific to AI request and response times variability can make that latency unpredictable.
So establish a historical track record, generate baselines for different types of payloads across different models. Remember that inference is kind of expensive, depends on how much you've played with this, but if you have as much as I have, you'll understand that is true. Monitoring the request size, output length and average tokens per query can establish the baseline and look for the patterns that need those cost reducing controls.
Frequent model and dependency changes can silently alter behavior. So create a set of canary prompts, then run them periodically to find swings in behavior and pinpoint those problematic releases. Um, the challenge of managing multiple models and regions simultaneously, especially across the world, um, means that you should get granular in your monitoring data and dashboards to easily tease out problematic combinations of models and regions.
You might find that, uh, this will proliferate in different parts of the world differently, not just because of your network, but because of your user base and your security level. The challenge of dev teams rapidly exploring and building AI tools without SREs initially. Hey, I'm definitely one of those people guilty of that.
Um, the advice here is to make trade-offs on working with a stack that you inherit versus your SRE monitoring stack. I guess in this case, if you can migrate your data to influx, then troubleshooting might just be faster for you If you're interested in some resources. To learn a little bit about how influx works under the hood, we've got Community Slack and forums.
We have docs also powered by AI with any questions that you have, um, that you can't find the answer to and is powered there. And if you're interested in doing a little bit deeper dives in each of the topics around time series, data influx, DB University is free and you can sign up for it there. That's all I have for you today.
Thank you for joining me.