Techstrong TV November 26, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hi, everyone. Welcome to our special Thanksgiving edition of the Textron Gang. I know it's only Wednesday Thanksgiving's not till tomorrow, but we're not gonna be here tomorrow.
So we, we, we bump things up a little bit. We're gonna do Thanksgiving special today. Uh, you know, it's kind of a tradition here at the Text Drug Gang.
Uh, who am I getting? We've never done it before, but we're gonna do it today. It's gonna be our first time doing it.
Uh, we're gonna ask each of our panelists to give us, or each of our gang members to tell us what they're thankful for this Thanksgiving holiday. But we're gonna confine it to technology. Otherwise, I think we'd go too far afield.
So let me introduce you to our, uh, Thanksgiving gang for today. And they're, they're regulars here. So they've all been around with us for months now, and you've probably seen them.
We've got Chris Blas, who's celebrating Thanksgiving north of the border. We've got the one and only man in Silicon Valley. John Swartz, our favorite Boston Cape Cod dude, Dan o Dan O'Brien, also from up New England Way, Kate Scarsella, and of course, the dean, our Chief Content officer here at Techstrong.
Mike Ard, gag members, welcome and happy Thanksgiving. And this is the official kickoff of the holiday season. I can't, I always love the holiday season.
I'll tell you the truth. It kind of just makes me think back to when I was a kid and, and a lot of good memories. It has certainly been a year for the record books.
There are things we can be, I think we all agree, things we can be thankful for, and, uh, things, things maybe we're not so thankful for. I did a series of articles up on our various techstrong sites, and in each of them, you know, geared to the specific community I put in, you know, four or five things I'm really thankful for. And two or three things, maybe I'm not.
Um, but let me, let me kick this off if it's okay, gang. You know, what am I thankful for? I am thankful to be alive at this time of, of history where we have just so much promise and so much disruptive revolutionary tech related change that promises to change our lives and usher in, as I I'm doing what my shimmy says later today, A Star Trek like future where poverty is eliminated and work for works work to, in order to make money is eliminated.
We'll do work because we love doing what we do. All of this is the promise of ai, along with, if you want to call it physical AI or robotics, along with other macro things like maybe quantum technology. Man, hey, we could have been born in the dark ages and getting hung up for saying the Earth goes around the sun.
But here we are. Here we are when there's so much at our fingertips. And the question is, are we smart enough, mature enough, bold enough to handle this correctly and, and, and bring this baby home?
Or do we crash and burn? And, and make no mistake, there's, you know, there might be some crash and burning, but I'm an optimist and I just, I'm thankful to be here at this juncture in history. Guys, what do you guys and gals, what do you think?
Well, I'll Tell you great time. Yeah, yeah, go ahead, Mike. I will say though, you know, there are more mundane things to be really thankful for.
And, and I'm only bringing this up 'cause we're all dealing now with this, uh, second coming of the shy ude attack. And, you know, all those cybersecurity people who like, do all this work and kind of, you know, come in and rescue us. And, you know, many of them will probably be working on this instead of having their Thanksgiving dinner somewhere with their families.
And they do this stuff every day, and sometimes they do it in ways that we never even see. And it is unfortunately thankless work, but it is the work that kinda saves us from ourselves. And I know, Chris, you're close to this community, but, you know, do we not spend enough time thanking these people?
They deserve that. I, I think the community is, is, is, uh, it's very healthy, right? I think we're really good for each other.
The cybersecurity community, I think is one of the better. You know, obviously I, it's what I've spent most of my career in, but we're pr pretty good at making sure everybody understands, you know, they're, they're wanted and they're welcome. Right?
And do we hear it enough from the outside world? I don't know. I I, I mean, we're a, a neurodivergent pack of, uh, crazy people.
I think we mostly need to hear it from each other, and we're, we're pretty good at that. So I'm thankful for that. John, you were gonna say something?
Oh, I was gonna say, I mean, so today, for instance, uh, Google's about to go for $4 trillion in market value. Okay? So that's like a news item.
But amid that, amid all the hype and hyperbole, as you said, I think you said it really well, Alan, there are so many things that we should be thankful for, including some of the things around ai. com explosion. And I'm kind of thi I'm thankful for it because it, it's making me think about all sorts of different vertical markets and the things that could happen, or the things that are possible that are gonna benefit us.
And I'll, I'll mention that later, but, um, I just think it's a great time to be around. Is is, there's, there's so many interesting things going on, and it's happening every day. Dan, Dan, you're shaking your head, Dan O'Brien.
Hold on a minute. I wanna follow up on John's point there. Um, Dan, I'm thankful for all the money that goes in the fund, this stuff, but I'm not sure where it comes from.
So maybe you could explain. Yeah, I mean, the, the math, yeah, that's Jesus. 4 trillion in open AI versus the $23 billion revenue.
Yeah, that's, uh, that's totally scary. But I'm thinking about the end results, regardless of what happens to those companies. Um, I'm thinking of a long term results, uh, short term.
It could be pretty scary. You're right, Mike. Well, Dan, where does all that money come from and who do we think?
Yeah, I, I, you know, I, I guess I'm thankful for competition. Um, you know, I think we're, you know, in the early innings here of the next big tech revolution with ai, you know, probably the biggest, you know, probably since the internet boom. Um, you know, to, to the point on where the money comes from.
You know, I think what makes me feel good about where we are in the cycle is, you know, up until very recently, it's largely been the free cash flow of the largest, most successful companies in the world that have been funding this, right? I think it's gotten a little more creative of late, um, you know, a little bit more speculative, a little bit more circular financing. Um, but, you know, I, I think I feel pretty good about, you know, kind of the sustainability of the cycle here.
But, um, you know, back to the point on competition, being thankful for that, you know, we're a, we're, like I said, early innings into this, but when this first kicked off, it was kind of open ai, open AI in Nvidia, right? It was a really narrow set of companies we were talking about. And, you know, with Google and what they've done with Gemini, their TPU infrastructure, a MD on the rise, you know, Intel maybe starting to get to the point of challenging TSMC, if not for wafers, at least for packaging, um, you know, philanthropic, you know, doing really well.
I think we're seeing, you know, the number of winners continue to grow and grow, you know, up and down the supply chain. I think, you know, competition is good for innovation, um, that's gonna make the cycle more sustainable, and then it's gonna make it more efficient as well. So, um, that's what I'm thankful for.
And I'll just say, um, I'm with Alan here. I'm not only an optimist, but I have become this Pollyanna, and I am loving this time period, I'm so happy, truly, that we are, um, embracing ai. And I think in the beginning, you know, we were somewhat concerned.
You know, we, and and it's not that we shouldn't be concerned, of course we should be, but I am happy that people are, are saying, okay, you know, it's here, let's embrace it. But at the same time, many of the cybersecurity people, you know, back to Chris, I mean, really, it's, it's, we also are understanding that we need to secure it. And I, it is not gonna be, you know, a decade before we're looking at the supply chain and everything else and saying, oh, golly, you know, software does have, uh, does have some vulnerabilities here, you know?
And so we're really looking at building security into, um, I think anyway, into AI as we move forward. We understand that, that, um, that this matters, that this is important. So I, I, I think that security, I'm happy that it's being a part of, of DevSecOps is really gonna be a thing.
It's, it's here, it's Here. I wrote exactly that, right throughout the articles I did around Thanksgiving, is that security has taken its rightful place at the table in most organizations and in most industries, all right? And that's been a long time coming for people like me, you and Chris who've, you know, been in security all these years we had and kind of shouting in the wilderness.
Yes. But guys, let me, let me also return to my, my point about thankfulness. Make no mistake, the tech industry is the tip of the spear when it comes to this revolution, when it comes to this AI enablement.
And, and I think we, we don't, don't downplay robotics. What Elon said about robotics is a hundred percent true, but the tech industries at the tip of the spear, we're leading this, we're feeling it, right? A lot of our friends have been laid off.
I know a lot of people looking for jobs. The tech industry is probably out in front in eliminating low hanging fruit type of jobs that AI can replace, or agentic AI can, can replace. And security is, is in the crucible, right?
Trying to use AI to protect against AI enabled threats. But we're doing it and we're aware of it, and we're trying the best we can, as we usually do. But the ripples of this are going to be waving, you know, rippling throughout society.
It's gonna hit medicine, it's going to hit law, it's going to hit accounting, it's going to hit name your, your, your profession or your livelihood. It's gonna have an effect throughout society. And I think being that we're kind of the first we're out in front of it, hopefully we'll be in a better place to help as this wave, you know, works its way through humanity.
And, you know, I wish I could tell you I'm, I would like to see what 50 years from now looks like, right? Do we have a, a Zephyr Cochrane breaking the, the, uh, warp barrier or something. But even the next 10 years, 15 years are gonna be exciting as hell.
And the only thing I I'd like to add, and sorry, Chris, I'm jumping in here, is back to, um, John's point about this vertical industry and, and where things are going. I actually believe that there's gonna be a collapsing of vertical industries, and it's gonna be more, uh, level horizontal because there, everything's gonna be integrated like we've never seen before. You know?
Um, and especially, you know, if we just think about health and technology or, you know, our smart buildings and energy, all this is gonna be just massively just one big, um, network of devices and integration. And I, this is an exciting time. I, Chris, I am thankful that we're putting humanity back in technology, right?
And then let me, I'll go all the way back, you know, 5,000, 10,000 years ago, we took the words we had, we had developed between us, and we started writing them down and trying to make them physical artifacts. We spent the last a hundred years and 50 years of digitizing it. And we have our, our, our technology talks back to us now.
It talks with us. We have conversations, right? And this forces us down the path, you know, and it's interesting, as you're all saying, we are in a bit of a crucible right now.
Lots of pressures. Well, pressures drive evolution, right? You know, the systems we've been building, whether they're the digital side of things, supply chain, security, security at all.
We have been talking for decades, you know, slightly longer than my career about how we do this. We have not yet done all of it. I think we have to, I think we're doing it right now.
I think we're taking the stories that we've been saying and turning them into technology, and then talking with the technology. We're looking at things like narrative risk management, right? Actually, your story, the story that we're all part of, not the digital parts.
Those were enablements. But who are you? Who are we as organizations?
How are we communicating each other? What stories are we tying each other together with this? There's an aspect of the, of humanity in this hyper-technical, uh, uh, uh, crux we're going through right now that I think is just intrinsically beautiful.
I think it's a wonderful thing. I think it leads to the opportunities, you know, and Dan, you know, whether it's the kind of things you're saying or or Kate, what you're saying, each of these enable us to be better humans, you know, sharing stories better. And I think it really does come down to narrative at, at the end of the day, we're finally out of the ones and zeros, and we're speaking in words.
You know, I, I wanna jump on that for a second, Chris. When you boil it down and you look at sort of ancient civilizations, I don't know how many of you ever took anthropology in school. I was a political science major.
They made us take anthropology. I, I had a chance to take some anthropology. Um, but when you look at early human civilizations, the role of the storyteller is a key function, is a key that that key person in the human tribe.
And, and oftentimes the storyteller was a traveling storyteller who went from tribe to tribe, right? And telling these stories. And, and so that, that common thread runs through multiple tribes and humanity.
And here we are, all these tens of, you know, I don't know, depends who you believe. Tens of thousands, thousands, hundreds. I don't care.
All these years later, it's still about the storyteller a bit, isn't it, Chris? For you being able to talk to an AI and, and be that storyteller is, is something you're thankful. John, your, you said it chronicling this age, right?
We are the storytellers of this age, The Irish call, those people, bards, Excuse me, Bard, call those people Bards and have called them. It's okay. So we, we'll call you Bard Baard from that one.
Speaking of Irish, Mr. O'Brien, what do you got? Yeah, no, I, I, I, I totally agree with what you're all talking about on kind of the humanity side, coming back into tech.
I mean, you know, it, it feels like that's, you know, kind of necessary as we increasingly interact with, you know, machine intelligence for, you know, it to become a little bit more of a true and better kind of representation of ourselves, right? Um, you know, I think it's a really great point Chris made there, and totally agree. Mm-hmm.
So let me tell you something though that I am hopeful for, Alright. Three or four years ago, I can remember sitting down and having conversations with, you know, even my own kids in their twenties, and they were pretty down on just about everything. They were basically looking at boomers and saying, you know, you guys messed up this planet pretty well, and now if we can make all this AI stuff come together and this quantum stuff together, and hopefully, you know, it works out as planned or as they say from, you know, Alan's lips to God's ear, we have hope, right?
We can fix a lot of things that, you know, are issues that were persistent, and we might, you know, be able to do the r and d work at a level of cost that could, you know, make things a lot better. That said, you know, that road the hell is always paved with those good intentions. So we need to be careful.
But, um, you know, the sum positive is greater than the negatives. Yeah. Yeah.
I mean, I had the same, I had the same conversation a couple different directions, right? I mean, you could easily see quantum and AI taking us into the next golden age. You could easily see it enabling some horrific dystopian future, right?
I mean, I think that's where the, the humans involved, you know, really just need to, you know, shape it for the common good in the right direction. Yeah. I, I as a, as a tech community, right?
You, you out there watching all somehow tech enabled business folks, whatever we geek at on this stuff, I'll say, I'm, I'm at my age at 60 years old. I'm thankful that I'm getting to see so many questions answered. You know, how do, how do, how do we work?
Who am I? How does this brain thing work? How did it get here?
All you talk about anthropology this year, I've had a reason to look at human evolution and mammal evolution. How did our cognitive system get here? And it turns out we're literally in this year, in this time, we're going through the process of exercising this at global scale and tech, because it's the same bloody thing.
You cannot brute force this. You can't take an infinite amount of information and just digitize it. You have to make semantic narrative compressed social, cultural, civic systems out of it.
And everywhere I look now, I see business systems and technical systems that we're used to seeing as cold and impersonal. And because they have been bending back towards people, because that's better, faster, cheaper. That's why we're wired this way.
And I think the, the arc of cynicism in our, in our lives and our, in our generation is bending. I really think this technology goes back towards people. You know, there's interesting thing about AI during your discussion made me think about this, this, this kind of greater narrative.
Before tech was always criticized and rightfully criticized for doing all these incremental apps, these little, you know, kind of silly things that would help you, you know, have your car washed while you went to the theater, right? You'd leave it and have somebody take care of it. But, and, and the criticism was that tech would never solve big problems, or it was averse to solving big problems.
And I think with ai, actually, conceivably, we could see, I'm not saying we're gonna see like a Hoover Dam or Moon Landing equivalent, but I do think we're gonna see significant inroads. I think Mike alluded to it, in terms of affordability, in terms of things like housing, um, healthcare, et cetera, uh, poverty, uh, uh, uh, confront confrontation. I think there, there are these things that we could possibly do.
I mean, it's gonna be a rough road to get there, but I am optimistic about them. Absolutely. Hey, I'd like to take a, Kate, we're gonna come back to you.
We we're 20 minutes in. We're gonna take a break, and then, you know, I set the tone for this first one. But Kate, Dan, I'd love to hear your kind of tone setters on what we're thankful for and, and continue the conversation.
You are watching Textron Gate. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity, your digital front door is, is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
0. You know, I've spoken about this before. If we look at the Renaissance and the Enlightenment period on how, again, it, it collapsed vertical, and we started to see art and architecture and science and all these things sort of come together.
0 that we have entered, and the, um, everything that's gonna come of this, I, it's ex this is an exciting time. So, absolutely. Well, you know, think, think about using these systems to see what makes sense, right?
We talked about this last week, and protein folding has had me thinking about this. Go to Notebook, lm, take some huge topics, some huge pile of text, throw it at it, and have a talk back to you and explain it to you. And this is called Semantic analysis.
I see people open up just myself and the people around us. We're just figuring this out this year as we're going through this. But that's why, as, as humans, we look at these systems and say, that doesn't make any sense.
And why is it like that? And we come up with these ideas, maybe it's a big conspiracy, but mostly it's because there's other humans inside these systems and they can't see it all at the same time. They're just telling their story about this one part of it.
None of us can see the size of these systems anymore, but AI can't. And we can have AI as you're think we can point our semantic tools at these big, huge, complex problems everywhere. You know, it may be a huge problem to you, though it's a small part of some municipal something.
And you can say, make sense of this. Tell this story back to me. Look at the information out there.
What is the narrative? What are we saying? What does it say to me?
And take that story and show it to other humans, the people responsible and say, see, you're here. You didn't even know you were there. And I think, you know, and Dan, everybody said things that make me, make me think you're right.
I think we can be reasonable with each other over the next several years in ways that, that, that were just callous to not think and work by just explaining to each other where we are and using these tools that we, that we think of as technology. But they're really story, you know, story shaping. Chris, there's a, a phrase I've heard that I really love that that goes something like, you know, the future of decision intelligence is simulation.
And I think that's a little bit kind of what you're getting at here in that, you know, we have so much compute power and so much information that we can kind of ask before we go do and get a really good sense as to kinda what we can expect, right? It's never gonna be perfect. But, you know, we, we can do a lot of really low cost rapid experimentation before we go mo mobilize people, assets, capital, et cetera, you know, on kind of exploring what might work and what might make sense.
Mm-hmm. Yeah. A, Alan, you mentioned Elon Musk earlier.
And, and here's the question. I'm kind of, you know, he was talking about, um, you know, the economy fundamentally changing. And as I ponder that theoretically, you know, if I look back at whatever economic model it is, it's always been based on the notion that there's a scarcity of something and there's demand for it.
Well, you know, are we on the cusp of getting someplace where, you know, scarcity of something is no longer an issue because we can use AI to, you know, make more food or make more whatever it might be. And there isn't gonna be this kinda economic model based on scarcity, and the world will change in ways we don't think. So.
This is exactly what my shimmy says is on later today, Mike. So the, the, I think we've got a fundamental question, though. And, and before I hit that though, let me make clear, it's not just AI that Elon is, Elon Musk is talking about.
It's, it's AI empowered robots mm-hmm. Who are gonna make work not necessarily or optional for humans who are gonna eliminate poverty and, and plentiful. You know, he also says it'll eliminate money.
Now, okay, this sounds a lot like Star Trek to me, right? I'm sorry. It sounds a lot like Star Trek.
And the problem is, is if you remember, I don't know how many of your Trekkies there was that period before Warp Drive came in, and the Vulcans, we, you know, discovered us, so to speak, where Earth was sort of, uh, it was, there was a post, a post-apocalyptic war kind of setting where, you know, we were living in, you know, it wasn't, it wasn't all unicorns and rainbows, let's put it that way. And my, my fear is, you know, Elon Musk kind of strata or vision here to get to that end point, there's gonna be some pain, there's gonna be a lot of disruption. And, and then all of us here waxing philosophically and poetically about what a great AI future is.
I think it would be wise for us to recognize there's going to be some pain disruption, disrupt. We're going through some of it right now. Yeah.
Disruption disrupts like from the Greek disruption. But, um, you know, there's, there's gonna be some uncomfortableness and some pain. And I think how we respond to that says a lot about who we are.
And as a, as a, as a civilization, as a species, right? Because to get, you know, invoke Martin Luther King to get to the Promised Land, right? I've gone to the top of the hill, I've seen the Promised Land, but he never got there.
And it's gonna, there's gonna be a, a valley in between here, and we gotta figure that out. Can I tell you my great Star Trek pet peeve? So go ahead.
In, in this alleged future, there's no need for money in every fifth episode of Star Trek, next Generation, what are they doing? Playing poker? For what?
There's no money Just to win, just to win. There are people who play poker for not real money. That says a lot about you, I think, Mike.
Alright. Hey. But we didn't, I feel like we didn't give everyone a chance to say what they're thankful for here.
We got off on this AI tangent and how great we're all gonna be. But Dan O'Brien, come on man. What are you, what are you thankful for?
Uh, I'm thankful for community. I mean, I think we've touched on it in a lot of ways without calling it out directly on the, uh, on the conversation here. But, um, all of the things we're talking about are only enabled by an enormous amount of people, companies coming together, working towards, you know, some kind of common vision.
And, uh, you know, I, I think I just want to take a minute and stop and appreciate, you know, kind of the community that needs to come together to enable all of this stuff because it's, it's no small feat that any of this stuff works, right? It's, uh, it's a lot of good intentions and a lot of hard work from a lot of people to make this stuff happen. Mm-hmm.
Agreed. Dan's point. I'd also like to thank all the storage engineers.
'cause I don't know where we're gonna put all this data, but they gotta figure it out. Storage is cheap. That's what they keep telling us.
But, but, but you know what, I, I wrote another article that's out, I think, uh, today, or if not, it'll be off Friday. And that is, when we talk about the community, there are some, you know, for my Boston friends, there are some wicked smart people up there. Not just in Boston, but all over.
There's some wicked smart people who work on these amazing technologies. And whether they're born in the US or they're born in China, or they're born in Europe, or Africa, or Latin America, wherever they're born, somehow this tech industry has a way of, of sucking 'em in and, and amassing them in the critical mass where this community can do the crazy, outrageous things that it it's capable of doing. To your point, Dan, right?
It it does, it takes a, not just a community, it takes a whole world Yeah. Kind of creativity, intelligence, you know, to even contemplate and make these things real. And, and I think we, we need to acknowledge that, right?
And, and need to be and celebrate the people who, who, you know, are the creators and are the people who, not just the creators, the entrepreneurs who risk everything, starting companies, the people who build these things, you know, all the way down to the, the security people who are making sure the, you know, critical infrastructure stays up and everything else. But it really does take a world, not just a community, it takes a world. It's bigger than any one of us or any one country here.
And I thought I was gonna be the only cheesy one, Dan. So thank you. Thank You.
Uh, look, cheesy is my middle name. I'm good for you. Well, yeah, I thank you.
Thank you all for the cheesiness. Yes. I, I I will take the cheese all the way down through the bottom of the text.
I think we're there, right? Yeah. I think most of us don't understand this.
I'll, I'm thankful that I'm gonna spend the rest of my life saying I told you so that intelligence is relational. That, that, you know, we we're talking about, you know, you know, I ident super intelligence. That's not a thing.
Turns out intelligence is a relational semantic thing that's about the size of a human being, and it can't ever be bigger. Right? You know, that, that a pure, you know, computer, you know, get a couple AI talking to each other with, with no context whatsoever.
And it peters out. There's nothing there. Everything, all of this, you know, these from the skyscrapers and the technology and the big things and the small things we build are, because we're individual human intelligences relating to each other in social contextual environments, as hippie as that sounds.
That's it. And that's literally the way the technology is working more and more every day. You know, it's, you can call it emergent or whatever you like, but it's not about the bits and pieces any more than we are because we built it, and neither are we.
Right? You know, this is, it's, you know, and, and, and as the, as the oldest Gen Xer, you know, born in 1965, right there on the edge as far, you know, as far as the, you can see it. To see this wave of sort of losing our base, losing our, our culture, losing our religion.
We even made a song, if you're old enough, remember it, and coming back to the fact that, that, no, it's not just a cold, impersonal universe, it's personal. The technology doesn't even work any other way. That's how we information systems work, because that's how humans work.
I'm sorry, I'm ranting at this point. I'm gonna put a flower behind my ear and go, no, But, but, but to your point, there are multiple types of AI models, right? Then it's not just gonna be this generative AI stuff that we're all obsessed about, but there's this whole new conversation around these world models and there's gonna be different ways of building out ai.
And there's causal AI out there that's really still in its infancy. So, you know, we're kind of just at the tip of the proverbial iceberg here, Chris, to your point. And, um, I'm not sure it's all relational.
'cause you know, part of my soul might say that that was confirmation bias on your part, but it's gonna be fun. It, it may be, but, but again, what is a world model? It's like, I am here, the, the world's around me.
How do I relate to it? That's how mm-hmm. Systems actually just work, right?
But, but Chris, you hit on something. Mike, you, you, you mentioned it earlier too. Look, just knowing what I know from the six of you, Dan, you probably have the youngest child among the six of us.
Think about the world your daughter grows up in. Not, not the Gen Xs. I'm, I'm the end of the boomers.
I'm cus just at the end of Boomer, right? You're just at the end of Gen X. Mike's right there.
Um, you know, we, we've we've had a run. We've had a run, right? But Mike is, you said, I think the di four years ago, a lot of our, my kids who were in the, at the time, in their late teens and twenties were a little, uh, perturbed about what we were leaving them here.
Debt. Mm-hmm. No doubt.
Blue, little blue pills and, and not much else. Right? But I, I think, oh, just in four or five years, there is a lot of optimism there.
And, and look, it's, it's not all rainbows and unicorns, as I said, for kids growing up today. Who knows what they're gonna be when they grow up, grow, grow up, who knows what they're going to do for work. Will they, will we eliminate poverty?
Will they be able to buy houses and take care of their families and everything? I mean, there's a lot to be thought about, but I, I think they have a, a, a more promising future, right? And that's always been part of the American dream, right?
The next generation does better than the generation before it. And I think, you know, Dan, I hope your daughter has a, a better future than, than we did and all of our children. And I, I, you know, it's good to be optimistic about that again.
'cause I think we weren't, for a while, I had the same conversation, Alan, that you, that you had with your kids and my cat Yep. With his kids. And that term, that sense of kind of doom or gloom and just like we, you know, thanks a lot to my generation for passing this on to us.
But I think you're right. And maybe it is we're kind of at a, a genuflecting moment or a turning point where we start seeing some of the benefits and across the board and, uh, maybe it's gonna start happening like it did in New York with your new mayor, with the new mayor. Um, we're starting to see a total mind shift.
And this is, this is good, this is progress. Things change and we have to adapt to it. It's Their thing.
What All about embracing the change? Yeah. Back to the point earlier.
Yeah. I mean, uh, there is an enormous amount of change going on and going on and, you know, that will be painful for some. But I think, you know, the secret to making it productive for you personally versus making it painful is this is too big a change to fight you.
You know, if you go with it and you lean into it, you embrace it, there's an immense amount of opportunity out there. Um, those who fight it, you know, I think those that'll probably experience the pain the most. But, you know, we've all got a choice, you know, in, uh, kind of whether we embrace and whether we lean in 10 years from now.
Alan and I are gonna be sitting on a park bench though, going, yeah, these kids don't know nothing. They don't know. They didn't have to show up for 10 at 6:00 AM at the Be next year.
Mike could be next year. Next year. Yeah.
Well, Dale, dear daughter, to all the kids out there to amel out in the world, and Tariq, you know, when I was a kid, I was told that, you know, the world's gonna end. We're all gonna die. I'm not gonna grow up, blah, blah, blah.
Right? You know, we, you know, we remember the seventies, right? And for a number of reasons I decided that no, there's other stories that might play out.
I'm playing a role in one of those stories. And I'll tell you what, that's the way the world turned out. Now, there's a lot of stories we may be part of now where things work out really poorly, but there's a lot of stories where they turn out really well.
I'm telling you, you're all part of the story that can turn out really well. Everything we've talked about here could work out to our benefit in ways you can't imagine. Will we have problems?
Yes. Otherwise life would be boring. You know, Allen Willerby be hardships and bump bumps on the way.
Yes. Buckle up. Um, but there always were, and the opportunities going forward are amazing and some of them will come true.
Absolutely. I I sincerely hope so. All right.
I'm gonna pass it around one last time here. Anything else you guys are thankful for you wanna bring up to the audience for today? I think we're gonna live longer.
I think because of science and research and ai, we're gonna live longer. Um, we're gonna improve drug discovery. I think it's been proven.
I think ai, drug discovery and biotechs reduce development time by 40%, cut costs by 30%. It's gonna save lives. It's gonna extend others, their cameras and sensors and patient rooms that detect when a patient's turned over in bed and alert folks so they don't fall out of bed.
Um, their, uh, doctors are using these guidelines of evidence-based research and treatment guidelines. They're accelerating diagnoses, minimizing errors. I mean, I just think, um, especially in healthcare, and I think about it because I'm over 60, uh, health is everything.
And I think about where this is headed and it, that actually makes me feel very, very positive. I'm thankful and I agree with John because it might be like, at least, you know, through the end of the decade before the World Series as won by the Yankees. So I kind of wanna So you can live longer though.
Yeah. Wait, yeah. Amen to that.
Amen to that. Yeah. Well, let me, let me, let me wrap a bow on this first.
First of all, things that I didn't mention that I'm thankful for, I'm thankful for doing the Textron Gang every day during the week here, and with my great friends and all the gang members, not just the five of you on with me today, but everyone who's been on the gang this year, we have an amazing group of pundits, experts, friends who come on here and we talk about whatever the issues of the day are or whatever Mike writes up into the, into the daily what's on the gang today, uh, script. And it, it, it's cathartic for me. I love doing it.
I love talking about these things. I love sharing it with, with all you. com.
Who would've thought DevOps 13 years later, security and everything else. I'm thankful for my fu brethren, right? We're part of fu and it's a, it's good to be part of a bigger organization that does big things and deals with, you know, bigger companies that are truly making some of what we're talking about here happen.
So thankful for that. Most of all, though, I'm thankful for everyone who watches us, reads our stuff, listens to our videos. I don't know sponsors who support us and keep the lights on here.
We couldn't do it without each and every one of you. So on behalf of Techstrong Futurum, happy Thanksgiving, everyone. Have a great day.
Discover Techstrong group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group. Hey everyone.
We're back here at CubeCon. Uh, we got a little bit more to do here on our day two coverage. My next guest is named Ari Zilker.
I hope we got that right. And Ari's company name is My decisive, My decisive. You may not have heard of my decisive, my decisive or Ari, but hopefully by the end of today or the end of this interview anyway, you will.
Ari, we Ari, before we talk, uh, before we discuss my decisive mm-hmm. Let, let's have a little discussion kind of, you know, give us your journey to being here, you know, at my decisive. Sure.
So My Decisive is a proactive operations product. Uh, I got to my, to the ideas and founding this company 'cause I was one of the general managers at a little company called New Relic. Sure.
For five years before that. Before that I was a general partner at Coastal Ventures. Sure.
Then, uh, working backwards helped found Hortonworks and then helped start terracotta, eh, cash before that. com. So I'm old enough to remember most of those.
Right. Okay. Look for those, for those kids out here.
Right. Horton works kind of defined the big data, right? That was the big data.
Absolutely. Uh, age. Yeah.
With Horton Works, which was a spinoff from Yahoo. Yep. Correct.
Yeah. And, um, interesting stuff. Interesting stuff.
Indeed. New Relic has had a, an interesting also story of, you know, look it, it's rode the waves of this market from a PM to observability to, you know, a lot of different things. But, you know, it, it, it affords one a real, uh, opportunity to, to see what's in the market.
Um, every founder I've ever spoken to, there's a passion for what they're doing. Somehow they think it's, it's gonna make the world better, even in a small way. It may not cure cancer or, you know, bring world peace.
Mm-hmm. But in some small way, it's gonna make someone's life better. Yep.
Talk to us about your passion. Um, easy. I have a passion for what observability folks call root cause.
Um, I'm also a scientist, a traditionally trained engineer, Uhhuh, and I'm frustrated with the observability vendors of the world saying this AI or that ai, and now I could do root cause, no one could do root cause. Uh, there's a difference between causal relationships between events and correlative relationships. And I'm not gonna get into the math of it.
I'll just say that I believe that we could do what the customers and the market needs, which is to bring in AI to help it run more smoothly at lower costs. Mm-hmm. But I believe that the answer is not incident response through LLMs and through ai.
And that root cause is the wrong question. It's when you ask a CTO what takes you down the most, humans take me down the most. So instead of root cause, why not go after robotic change?
Let the system change itself. We don't break it. We bring in the genius chemical human brain to do root cause with analytics tools.
Okay. But we don't try to get robots to fix systems. I love it.
Let's, um, so you, I think you really framed the problem and the potential solution, no disrespect to you, but all of the boots around us here and they can't see, they only see this. Yeah. A lot of boots here are promising a lot of solutions and you know, they throw in a little AI snake oil, a little MCP here, you know, and, and, and a agentic there and mm-hmm.
And we're gonna solve your problem. Yep. Why are you different?
So look, I recognize Alan, we're swimming upstream against what you just described. Why we wanna be different is because we recognize from our insider seat in observability the, the signal's not in the telemetry data. There is no signal.
Like you deploy an app in a database and the app starts crashing. There's nothing in that data. And every observability vendor knows this that says it's the app or the database roll back.
The one and the other will heal. That data's not there. All we have is some CPU information, some URLs being requested and you know, a little bit more than that.
Some Kubernetes and infrastructure logs. There's nothing that says, oh, fix the app and the database will calm down. So why we we're doing this, why we're swimming upstream is because we know it's technol technologically correct what we're doing.
Okay. It is principled approach. Mm-hmm.
Uh, why we're willing to swim upstream against the AI claims is because we can introduce AI the right way. We can Basically, 'cause ultimately you think it's the right thing to do and it's gonna be born out. Yeah.
Basically if you make the changes with a robot, then you can easily ask, was this a good change or a bad change? Whereas if you're looking at steady state operating data and say, did I just go unhealthy? That's an impossible question to answer.
Maybe this is normal. And I've heard too many customers say, I deployed an AI and my traffic doubled. And it started rebooting me because it thought this was an anomalous situation.
But I was handling that traffic and the AI took me down. And so, because I know that humans are gonna be in the loop for the next 10 to 20 years, because I know that change is an easier problem to tackle automatic change than automatic incident response, I'm willing to swim upstream. 'cause I think we'll win.
Fair enough. Let's talk about observability for a second. Ari, you've been in the observability sta space.
You've been in the big data space longer than that. Yeah. Quite frankly, the problem with observability is it was, is fundamentally the big data issue.
For a long time we had too much data to kinda really wrap our heads around, analyze and come back with actionable intelligence. Mm-hmm. With things like AI and, and other improvements.
It's not, you know, AI is just the latest Yeah. The greatest maybe. But you know, over the years with machine learning and what some says AI anyway, but Yep.
Machine learning other ways we've, we've been able to tackle that big data problem. But In tackling the big data problem, you know, it's the, the, the theory of constraints. Right.
We solved the big data problem only to find out bigger problems. Sit behind it. For many in observability, that biggest problem is my God, who, who can afford this?
Mm-hmm. Right. To to to really, now that we have the ability to analyze the data, we want to keep collecting more and more data.
The more data collect we collect, the more our costs go up and Yep. Storing the data, analyzing the data, reporting the data and it, and it's like, it's like an old Star Trek original series when you gotta keep feeding ball the monster. Yeah.
Right. Yeah. Otherwise he goes out and the whole planet goes to hell in a hand basket.
It's the same thing with observability. We gotta keep feeding the monster. Mm-hmm.
How do you help with that? So we come OnPrem with our solution. Okay.
First of all, wonderful question. You're spot on. Um, but if I come OnPrem, then I could introduce you remember Michael Stone breaker?
Sure. Database genius. Uhhuh, he had stream base, right?
Mm-hmm. He started swimming upstream. He said there's a bunch of business problems that need to be solved in the stream in real time.
You don't wanna land the data to a spindle and then ask a question of it as an analytics query. You wanna pose that question of the data as it passes by observing the change in state. That's what we've built.
So our product is Kubernetes native Open Telemetry native. In fact, it's going into the CNCF. We can talk about that a bit.
But the, the idea is if no one's introduced an observability streaming analytics engine, and if I do that, then all of a sudden I'm bringing the power of, we do this in networking, we do this in databases. There's stream base, there's streaming databases, there are network devices, software devices on the network. Palo Alto Networks F five big IP that run it wire speed.
They're stateful and you can co-locate the application right there with the data as it originates next to the app. We are one of those. So we are an observability appliance on-prem super fast, super lightweight distributes the cost of ownership of the solution to all the edge points instead of trying to be a SaaS that centralizes it and now needs to spend a billion dollars a year on AWS that needs to mark that AWS charge up to it and pass it through to its end users.
Excellent. Excellent. Quite excellent response to that Ari.
Thank you. Um, we gotta do a little housekeeping. Okay.
Website, URL. Where can people go get more info? Where?
ai For the spelling challenged out there. M-Y-D-E-C, I don't know. I can't think of You're One of the spelling challenge.
I'm gonna E-S-C-I-S-I. You gotta use it in a sentence. com.
com. ai. I still won the spelling.
If you get rid of the dot, it works in sentences perfectly. I use my decisive AI to control my production system. There you go.
So it doesn't break Then. So it doesn't break. Yeah.
Excellent. Um, how can people get started? It's self-service.
It's completely designed like when a customer prospect shows up at our front door and we're lucky enough to engage people, we send them to the Slack channel, we send them to the website, we send them to the GitHub, it's all hanging there. Top level navigation off that website. One last thing you mentioned, uh, joining the CNCF and I'm gonna assume the, the working groups for o uh, opt Hotel and Yeah.
And so forth, weren't that happening Next week right after this conference? Yeah. So stay tuned for that.
We may have to report that news though. We just reported it. And besides joining, will you be donating some of the code you're using at my Decisive?
So We're not ready to donate the core code. Um, it is open under a permissive license. Mm-hmm.
And we are part of the CNCF, so we will comply with all their tests. Open source. Yeah.
And harnesses and their open source policies. That said, we are contributing to open Telemetry itself. So last week there was a missing part in Datadog.
We, and it didn't work with Oel. We fixed that. Gave it and it was upstreamed in under 24 hours.
That's into core hotel distro. We would see them. Um, it must have been a serious problem if they moved that fast on it.
Yeah. The next thing we're doing, we're working with hopefully gonna be able to work with other observability vendors and build what someone else calls enrichment for open telemetry. Okay.
We're building on-prem storage for open telemetry. So you can keep your data in S3 and not be scared to sample it, filter it or introduce our streaming technology. 'cause you could always grab the raw original and do something with it, whether it's in an open source database or a commercial database or you forward it back to your observability vendor.
All of those modules, those are changes to tel itself and we're contributing those on the tel side of the fence, not on the My Decisive side. I love it. Ari, thank you so much for coming here on Techstrong TV with us.
Thank You. Continued success. We'll be looking for the announcement about the CNCF and we'll continue the conversation.
Appreciate your time. Thank you. Appreciate your time.
Hey, we're live here at Q Con. What? We've got one more today.
Stay tuned. We'll be right back. Hey everybody.
We're at Atlassian Europe and we're having a chat about Jira product Discovery with Axel Soray, who's the product management evangelist for the product. And well, I know a lot of people know what Jira is, but I'm not sure everybody knows what Jira product discovery is. So walk us through what is the relationship between these things and how are people using this?
Uh, thank you for having me first of all, and really excited to be here. So for the longest time, product managers or you know, teams that are adjacent to product management teams have not really had a space to capture all the work they have to do. Plan that work, prioritize that work, and share the outcome of that prioritization with the rest of their stakeholders.
Right. So we've heard doing research, uh, about three years ago from a lot of product management teams saying Jira is not where we should be doing this. 'cause Jira is for committed work.
Work that we know we are going to do. Like when we've decided, okay, we're ready to go into development and we're gonna code this, we're gonna build this, this work happens in Jira, but everything that happens left of that. So the strategy, the planning, the research, the discovery, they needed a space to do that.
Right. A dedicated space to do that. That's what Product Discovery is, is a place for product management teams to capture their ideas, prioritize these ideas, and then share the outcome of that prioritization with the rest of the organization.
What were people using before that? Were they just kind of scribbling notes or putting it in a spreadsheet or docs? That's a great question.
So spreadsheet is, you know, the default to most things, right? Like if you don't have a tool, a lot of it happens in a spreadsheet. And the challenge with spreadsheets is a lot of times that work is out of sync.
So, uh, you can imagine a stakeholder, a leader will send you a message and say, uh, hey, can you send me like the latest version of what you're working on? You send them this spreadsheet and the moment you send it, it's like out of sync. 'cause like the teams are moving at all times.
So that's one of the issues. The other problem is like, this information is scattered across multiple systems. So even if you're using spreadsheets, you are not connecting the dots between, you know, your CRM data that might be in Salesforce or your customer feedback that might be in like Jira service management or like wherever the data is sitting.
That information was scattered across multiple places. So a lot of these teams really needed a place like, uh, it's interesting 'cause our customers call this either like a product hub or a product operating system mm-hmm. To bring in all of this information into what they sometimes call a single source of truth.
So Describe exactly what it is I experienced, so I have an idea. Yeah. And I put it in where and how does it manifest?
That's great. Um, so in a lot of ways it looks like a spreadsheet, like spreadsheet like, or, you know, kind of a, um, how would I put this? Like a, a tabular like list experience.
So, uh, people are not necessarily lost when they land in your product discovery for the first place. So they will look at a list of things, a list of work items, just like you could see them in Jira. But the advantage of Jira product discovery is this whole idea of views.
So views are basically different ways to slice and dice that information in a way that makes sense, uh, for the stakeholders that you're trying to have conversations with. I'll give you an example. If you are a product manager and you're working at the team altitude in your organization, you need a level of detail, which is not the same level of detail that a VP of product or SVP of product will be looking for, right?
So with the same information, you can slice and dice, uh, uh, basically these ideas and the amount of information that you wanna show based on who it is you wanna have a conversation with. For example, if I wanna have a high level strategic roadmap, I will use tools like, you know, group buys to build swim lanes or filters or field management to basic, create a curated view of the same information, but for a different audience. And that's the whole power of geo product discovery.
Alright. Now, you did some research in this area before you launched the product and after. So what are, what's the feedback?
What are folks telling you and, you know, what's next? So, The feedback has been overwhelmingly positive. Um, geo product discovery, uh, is one of the fastest growing products in the history of Atlassian.
So we started this journey, uh, two and a half years ago. Since then, we've had a consistent customer satisfaction score of above 80, uh, which is absolutely amazing. Uh, and we just passed the 20,000 customer mark.
So in terms of growth, that's incredible for, uh, for us and for Atlassian. Um, one of the things we're really excited for is how do we expand your product discovery in a way that supports product management workflows, uh, in a more end-to-end fashion, right? So if you think about it today, uh, product teams will come in into jury product discovery to, uh, plan their work and, uh, use insights, for example, to, uh, have evidence of how they should prioritize their work.
We wanna go further left of that, and to do that, we have recently acquired a company called Cycle. Sure. Uh, they were, they are actually an operator in the feedback management space.
And basically they, uh, use AI to, uh, allow product teams to better curate and make sense of the volume of feedback they're collecting across multiple sources. So we are building that capability into Jira product discovery so that product managers and product teams can have a high level of fidelity in their product decision making using evidence and insights. Right Now, Atlassian is making massive investments in ai, and there's a thing called Atlassian Intelligence, which is kind of a framework.
How might that manifest itself inside of this experience? So Atlassian intelligence is basically going to manifest itself in, for example, the, um, idea editor. So if you, you're writing an idea, let's say an idea is a strategic, uh, piece of work you are planning for next year, let's say a new AI capability, and you're building that AI capability as a product team, as you're writing the content in the idea, let's say it's a product requirements document, Atlassian intelligence will help you draft that based on all of the context that it has in memory.
And, uh, it could be like pages you already have in Confluence. It could be work you've already done in Jira. And we bring the power of the teamwork graph, which is basically all of the knowledge that Atlassian holds for your company in your workspace into that Atlassian intelligence experience.
Will it maybe even suggest new ideas? I mean, how far can it go? That's, that's a great question.
Uh, right now we really focused on helping product managers, uh, to make sense of the data they already collecting, right? So if you think about a typical product management team, they might be receiving information from customer support teams through Jira service management. They might be receiving, uh, emails directly from customers asking to support them on something or providing feedback about, about a product.
They might be receiving internal feedback from sales teams through Salesforce. So we're gonna use, uh, the power of ro o, which is our, uh, agentic platform to bring in all of that data, make sense of it, and provide insights in Jira product discovery. And the, the way AI will help you do this, it will surface a lot of the commonality that exists around all of these different touch points.
For example, let's say you have received 5,000 different pieces of feedback, it will go and identify themes across these 5,000 pieces of feedback and say, Hey, you might wanna look at, you know, this theme and this theme and this theme. Because looking at the volume of feedback that we've received, there seems to be something of interest here. And then based on these suggestions, a product manager can then go and think, okay, I can see that customers over the last six months have provided us a huge volume of feedback around this specific topic or this specific pain point they're addressing.
Let's do a deep dive into that. And this is gonna help them prioritize the work that they do in order to help customers make progress in their work. I'm not sure you could do this, but in large companies especially, there's often an issue where somebody has an idea, but somebody actually already did that, you know, a couple of years ago.
Yes. When it's dis languishing somewhere. Yeah.
Can I find out what other people have already done in the company and kind of reuse it? This is already possible today, and this is nothing specific to Jira product discovery, right? This is available through Rover, which is, uh, uh, our agent platform.
It's available across all of our Atlassian products. So typically the way you would do this, and this is something that I I would do regularly, is if I, if I'm in a like, large enterprise company where there are like hundreds of teams, and as you mentioned maybe, uh, you know, Michael from this like other team like way remote from where I sit in the organization has already worked on this, an easy way to find out is I'll just go in, uh, my workspace and ask vo has anybody worked on this topic before? And let's say the topic, let's say you're in financial, financial services, and the topic is like personal finance management.
And I would just simply ask, has anybody worked on personal finance management before? Question mark And Rover is gonna instantly go and look at all of the information it has indexed across your company lot, uh, over the, the history of information that it has. And it'll quickly come back and say, this is what I can tell you about performance, uh, personal finance management, and this is the work that, you know, I can relate to it.
And it will provide work tickets in jwa. It will provide, uh, confluence documents. It will provide even items that you've referenced from external systems like Google Drive, for example.
So, as I understand it, you did a survey and you know my, one of the high points of that survey, but you've been doing this for a while. Is there anything in that survey that surprised you or that you didn't think you'd hear? Yeah, so we recently launched our inaugural 2026 state of product report, and there are few things that I thought were really interesting.
So the number one thing is like, AI allows teams today to like claim back, let's say two hours a week. Um, but the time that the teams are claiming back, they're not finding a way to invest this in strategy work. And this, I think is something super interesting.
A lot of teams are still caught in busy work, so the time that they're claiming back, they're just reinvesting in a lot more busy work, right? And this is something I think we need to, uh, really think deeply about. 'cause today AI is primarily being used for incremental productivity gains.
Why? I think there's a huge opportunity for teams to actually rethink how they can transform their workflows. So it's not so much like, help me summarize this, but it's more like, help me think about how I could completely rethink how I work based on all of these new AI capability capabilities that are available to me today.
So that's one of them. The second one, which I think is something that is more, uh, on the, I'd say cultural level in a lot of organizations that I speak to, is that still a vast majority of engineers are brought into the discovery and the, uh, and and planning process way too late in the cycle. Mm-hmm.
So if you think about a product manager, they have an idea, they work on a a problem definition, they work on an opportunity, and they start exploring that opportunity. Engineers will come by when probably they'll, they'll get involved when the product managers already have a spec of something to build. And that is not how we think this should be done.
Engineers should be brought in really early on so that they can share their view of one, what is the feasibility of like, you know, the, the different types of solutions we can think about to address this customer problem. But more importantly, there's a lot of creative element in how they address the solution. And they've done this before, and they're some of the smartest people in the room.
So the earlier you bring them in, in that cycle of like thinking about how do we address customer problems, the better you, your output and your outcomes will be. You know, I've been surprised by those conversations happening so late myself, because the cost of whatever it is, is gonna be determined by the engineering team. So if I have a spec and an idea, I don't really know how much it costs to deliver, how am I gonna price it?
So that's one of the aspects. But I think even going, like taking a step back and going back to basics, like there's this whole idea of diversity of thought. Like if you're a product manager, there's a way you think about things like your brain is hardwired to like, think about things in a specific way, bringing in different, uh, types of people.
And diversity of thought early on in the journey allows you to have better coverage of how to think about how you might wanna solve for a problem. Right? So you think about, um, this concept of the product trio that we really try to embody at Atlassian.
So we have a product manager, a product designer, and a tech lead. These three people are gonna come together and together address how they think they're gonna, you know, solve for a customer problem. And the reason for this is that these people are accountable for different things.
A product manager will be accountable for the business value and viability of a product. A designer will be accountable for, uh, the, the usability of the product. And typically an engineer or a tech lead will be accountable for the feasibility of the product, right?
So these three areas, or, or, or discipline should be represented way early into the, the problem definition phase. One of the reasons for this is that all of the strategic context that later on leads to a developer actually picking up an epic and starting to work on the work and write code. That's the most valuable thing a developer needs.
Like, they shouldn't find out about this new piece of work when it lends in their Jira backlog. And this is what we're trying to solve. So You touched on this and, uh, just the last question, but I'd love to get your opinion on it.
So, we see AI saving people time, but it doesn't necessarily transition into making the company more money necessarily. 'cause we don't change the way we work. We just kind of, to your point, do more busy work.
Yeah. What should people we really thinking about as they look at AI and new product development? What's gonna change?
I think, um, the way I think about this, and we in a lot of ways, in a lot of ways, we're still early, right? We don't really know where, like, where the puck is going. Uh, the rate at which the, uh, AI space is evolving is absolutely incredible.
However, one thing I will stress on is like, the reality of the work that product management teams have to do is largely anchored in customer knowledge. And I feel like a lot of companies are in this phase of going back to basics, which I think is extremely important. So yes, AI is gonna help you incrementally save time here and there, but the biggest differentiator you have right now is what a lot of people call taste or judgment, right?
So where AI can help you save a lot of time in maybe the way you, um, come up with how are you gonna, you know, think about your go-to market plans for a product launch, or how you might think about writing your documentation for this new feature that you're launching. Because the AI has, the AI already has access to all of your code base. So things like that, all of this time that you're saving should really be reinvested in strategy and customer knowledge.
And I cannot stress this enough because there's a lot of noise that comes with ai, right? Like a lot of product managers are trying to keep up with the pace at which this like, uh, space is evolving. But I really think like product teams need to think deeply about where they invest their time.
And radical focus means that they're there to solve customer problems. So AI is a tool, it is an enabler, it's definitely something product teams should be raising their level of fluency on and their level of, uh, uh, knowledge on and embedding it in their workflows. But they shouldn't lose track of the prize, which is like, how do we solve customer problems in a way that makes sense for the business?
All right. Hey folks, you heard it here. AI for product teams, it's not just about working faster, it's about working smarter.
Hey, Axel, thanks for being on the show. My Pleasure. Thanks for having me.
All Right. And we'll be back in a minute. Hey, everyone, welcome back here to Textron tv.
You know, it's my pleasure to introduce Gabe Boko to you. Gabey is the chief marketing officer at NetApp. You know, we've been having sort of a running conversation with some of our friends at NetApp now for the last couple months, but I'm really ha happy to have Gabey here to kind of tie a bow on things, but also just to, I, I'm always fascinated to hear people's stories and their journey and and how they got here.
And I know a lot of you out there aspiring folks early on in your careers, you say, I want to be a C-level chief marketing officer, chief revenue, chief technology, what have you. And here's someone who can give you some real life experience and, and tips, perhaps Gabey, welcome to Text Drunk tv. It's great to have you on here.
Thank you so much for inviting me, Alan. Happy to be here. Thank you.
So, Gabey, I hope I didn't embarrass you or put too much on your shoulders right off the bat, but there are people out here, probably a little younger than me who say, man, I, you know, that's where I want to be one day. I wanna be a C-level exec at a public company or what have you. Um, give us a sense of your journey, how you came to be here today.
You know, I, uh, well, first thanks for the question. I, I think I actually said to you privately, I didn't know that anybody wanted to be a C level. Um, and maybe that's, um, specific to my journey, right?
I don't think I started off saying, this is the role or the space or the suite that I wanted to be in. Um, I started off by, you know, deciding that I, I didn't like what I was thinking I wanted to do, and I wanted to change. And technology at that time offered me a, a new future, and I just ran at it as hard as I could.
Um, and, and I think that that's, that really denotes my whole journey. It's, uh, a lot of tech companies, a lot of different kind of tech, a lot of software. Um, more recently in the last decade, maybe a lot of hardware.
Um, but at the core is really companies that are trying to do something different. Maybe they're, you know, longtime legacy companies. Maybe they have just bought a company.
There's always some level of transformation that I'm attracted to when I join a company, which is hearkens back to why I wanted to do tech anyway, which was I wanted to do something different. I wanted to be a part of something that was interesting and, and potentially changing the world. And, you know, I think that if you can understand why you're doing something and you do it really well, then the, the chair follows, right?
The job follows. And, and I think that that's, that's probably the best description of my journey that I can give you. I love it.
You know, I had a similar experience. I actually went to law school during law. I became the word perfect guy in the office, the only lawyer who could do the word per 'cause.
Lawyers didn't use word. We used word perfect, correct. And, uh, and, um, and that, but tech just kind of grabbed me by the throat, and this is what I wanted to do with my life.
And, and for much of the same reasons you said, in some ways changing the world, the excitement of new things, discovering new things, yeah. Bringing new things, you know, to market. And, um, it is, and it's funny, you know, and much as things change, they say this stay the same.
It's true. Here we are in this age of AI now, and it's that same excitement. What a great time to be alive, right?
Even though it may take your job, as some people say, I don't believe it will. I think it's going to create more opportunities for us all. I agree.
And, uh, I'm excited. I'm excited to see what tomorrow brings and yeah. And you know, as long as you have that curiosity and that passion, as you said, you don't aim for a particular chair, the chair follows you.
That's right. That's right. And I think that that's absolutely, that's, if you can hang onto that, then that keeps what you do next, authentic and real, and makes you the right kind of mentor and or collaborator in the chair.
So, um, yeah, I agree with you. I agree. Absolutely.
So let's talk NetApp a little bit. Okay. Before we jump into things.
As I said, uh, most of our audience is probably familiar with NetApp. We, I mean, and let me not blow my own horn, not because we're covering them. com days, right?
We were, yeah, what they call an a SP application service provider, right? And, and we needed, you needed network attached storage. But, um, NetApp's been around, people know it, it's, they think they know it, but of course, NetApp has reinvented itself a couple of times along the way.
Mm-hmm. As you sit here today, right before Thanksgiving, what do you, how do you describe NetApp to people? Gabe?
Yeah. Uh, you know, I love this question because it's something that as a marketer, marketers sink their teeth into. But if you're a technical person, then, then what you're really looking for, do they still remember who I am and why I knew them?
And I think that that's the fine line that we've been walking. And, and I think we're in a really interesting spot right now. If I look back on the 30 years, and by the way, it's been 30 years, what we have is a company who's been dedicated to not just storage, not just data management, not just cloud or hybrid cloud.
Not just, not just, but we've been dedicated to data, um, and, and getting access to it, to storing it, to moving it. And, and what that means is, is that we've been responsive to a market and to people who would buy us and use us, wanting their data not to be just one place, but wanting it to be many, wanting it not to be passive, but wanting it to create the power for them to drive change. So when I got into this chair a little over two years ago now, um, we wanted to go back to what it was that people would've known us for.
We, and still give them the sense of who we were and, and who we continue to want to be. And that's when we really thought about that. We came up with something that we call the intelligent data infrastructure, and that we're the intelligent data infrastructure company.
Um, and when you think about what that is, data still in between those three words is still at the core. And when you think about infrastructure, it says, we still pay attention to data storage because it is where it lives. But when you think about infrastructure, you're also thinking about where it moves, how it moves with data management.
And then if you bolt on then the opportunity that you opened up with about AI by saying intelligent, we really wanted to connect both of those legacy kind of components that we'd brought with data to the future of where we thought data was going. Um, we believe that it's, it's not just about, uh, where your data lives, obviously. Um, we believe we're with this storyline thinking about how data is evolving and how it's gonna be that proven foundation for the future, which is an AI future, as we already know, um, how important everything choice we've made in the past 30 years.
Cloud, hybrid cloud, multi-cloud, data storage, data management, all data fabric, all of it factors in. Because what that means is that we believe into it that NetApp is a proven foundation, a proven foundation for, um, not just those aspects, but the future aspects because it's intelligent at every layer layer. It is connected by design to all the public clouds.
It is got security and resilience built in, not bolted on when that's, we like to say that, but ultimately it's a foundation that, that really unlocks human potential and business potential. And, and we like to think of intelligent data infrastructure as something that when we can help make your data intelligent, then something bigger is gonna happen and it's gonna happen with you driving. So that's a little bit of the NetApp journey over 30 years.
That's how we're thinking about where we've been and how we're trying to embrace the future, um, and how we're doing it as truly technical people with an eye to, um, to building markets and, and making something interesting for the next generation of people who will want to know NetApp. Absolutely. If you don't mind, I wanna, you know, the AI thing is, it, it of course ate all of our conversations.
I wanna just focus in though, on marketing, and you, you're, you're a chief marketing officer, you're a marketing expert. If we look at, you know, the low hanging fruit where AI is disrupting almost immediately, marketing is one of those areas. I think I see it here.
Um, how, from your point of view, as a master marketer, and I don't mean to embarrass you, but as a master marketer, how is it reshaping, right? How we tell our stories, how we reach our audience, how we know who our audience even is? How do we measure success, failure, good, bad, or what have you?
How, how has it changed how you look at your job and your, your function, and not just you, but the whole team there? Yeah. You know, thanks for the question.
Mostly because everything I just said about how we're thinking about the company holds true for how even marketers in my day-to-day job thinks about it. Um, I believe that AI is a powerful enabler, just like we talked about it up in how we've crafted what our brand statement was. I believe personally that it's here to assist and not replace.
I know that there, there's a lot of aspects that it will replace, but it's not a replace, it's almost like a net new, right? Maybe we don't need to do it the same way AI can help us do that better and give us the opportunity to go be creative or, um, spectacular in other areas. So, um, I think that it really helps marketing teams, uh, work smarter, obviously, make decisions faster.
Um, it clearly offer, you know, offers new dynamic levels of creativity because what AI does, I believe, is feeds off of data, right? Uh, that's just at the core. Um, we know that it, it processes models in, in, in amount of time that no human could have ever done that, which is why it's such a great tool.
Um, what you feed it is important, right? So especially from a marketing perspective, when you're looking at what data you want to, you know, have AI contribute on a marketing level, you are giving it the ability to help crunch numbers, to find, uh, net new markets in a faster way, to try to find trends, to find opportunities so that you can go be creative and then feed that back into the same model and say, all right, you're telling me it's this, if I add this in, what does it do? And, and, and that's really why I think AI is a help, right?
I think that a, I can't replace human instinct. It can't, definitely can't replace empathy today. I'm, I'm pretty sure it won't tomorrow either.
I think marketers need to continue to show up with curiosity and creativity and thinking about what connections they are looking to drive, and then to use AI to help them tell those stories, to reach those new audiences. Like you were talking up at the beginning, right? So, um, for me, AI helps.
It doesn't hurt us. Absolutely. You know, I, I wrote an article a couple weeks ago, and to paraphrase, Billy Joe, AI can't start the fire, the human sparks.
It does. Right? But the ai, you're absolutely right.
The AI is a great tool. I wanna come back though, to what you were, we were talking about just before, about sort of this rebrand, if you, not a rebrand a, an evolution to the branding of NetApp becoming an intelligent data infrastructure company. Yeah.
And I, I think part of it is the realization, hey, stupid, it's all about the data, right? For a long time, we seemed to almost forgot we were so busy about the app and app and app security and running the app and making the app mobile and making the app that we forgot. It's about the data.
The data is the, the, the crown jewels. The data is what we we're going for. As part of this rebrand or a brand evolution, as I called it, you had to kinda reset people's vision or, or expectation when they heard NetApp Yeah.
Hardware company. Yep. Storage company.
What were the lessons learned? What were the, what were the gotchas, what wasn't on your Bingo card, right? What, what as this thing played out?
Yeah. I'll be honest, my first, I think my first six months of listening, people were like, you're not in the cloud. You're a storage company, so, you know mm-hmm.
Try to remember who you are. Um, and I, I took that in and it, like, part of you is like, yeah, but cloud is what makes everything that we do for you on-prem unique. Um, but that wasn't, wasn't landing in the way we wanted it to.
In addition, I think as with all things marketing, right? When sometimes when you do it by committee, you end up with what I call a list of commas, right? You literally have a, a long list of offerings and words that you're trying to jam in so that you are, are meeting every audience.
And what ends up happening is you end up meeting no audience. Um, so people, if they don't see themselves in that big long list, start to question, you know, like, I don't see myself there, so I don't know who you are anymore. So those were some of the challenges that I think I walked into.
Um, I think the, the goal was to simplify all that to say, we gotta be one thing. Um, we've gotta think about it. We've gotta go back to why we made decisions in the first place.
That's how we got back to putting data at the center. Um, we have to remember, it isn't just about the place, right? Where data lives, it's, we've done a whole lot of other things that are super important to our brand.
On top is, is absolutely critical as, um, software for how we manage and do data management in the, in the cloud and on-prem. So we, we weren't paying enough attention to that. Um, so I, I think it was about how do we talk about those things really realistically?
And then how do we, how do we use those words to then tell a story that's compelling, right? And as I said, it wasn't just about where data lives, but how data moves and how it creates human possibility. Well, then that allows us to kind of go back into maybe not just talking about the cloud as some of those locations or data management as those of those locations, but maybe it's about our partner partnerships, our, our alliances, our sponsorships, um, all of those make our brand more relatable, make 'em more visible.
And I think the last thing is, you know, we wanted to make it real, right? So we wanted our customers to be able to feel this. One of my favorite videos, we, we were released at Insight, our user conference just a month ago, was this, uh, European Space Agency video.
And it's mm-hmm. It's, it's like, plays like an Oscar movie for me, because it's, they're talking about petabytes of data and the digital storage place of the universe. And, but they're still talking about, listen, I haven't lost a file.
I am, I am thinking about my data infrastructure, my intelligent data infrastructure every day, because I want to make, you know, astronauts and engineers. And I think what that really brings back to me is that we didn't wanna escape our legacy. We wanted to position it as a foundation of trust for customers like ESA who had been talking and using us for 20 years and had never had a problem.
So that history, I think that's what gave us the confidence to evolve and experiment with where this story was going and, and really lead this, this new chapter for us in a, in a bold way and in a really focused way. Again, coming back to the core, we're a data company and that's, that's why we talk this way. So reinvention, it's still ongoing, but I think we're in a much better place than we were two years ago when I took this on It.
Well, no, any, anybody who tells you that their reinvention is done is done. That's right. Stick.
That's stick before get up. But, you know, you're talking about cool. Uh, well, so I'm, I'm, you know, of my age, nothing's cooler than the space program, right?
Yeah. I mean, that's, that's as cool as it gets for me. Yeah.
I went to that Kennedy, I live in Florida. I took the kids years, years ago to the awesome. I went to the Kennedy Space Center.
They were bored. I was in my glory. But anyway, but you have some other really great relationships that net up.
They do you guys do some sports? Kind of, uh, we do relationships with the Niners and the Sharks. Oh, you know, west Coast stuff.
Look Super Bowl's coming to, uh, Levi's Stadium in, in Santa Clara this year. Yeah. My team won't be there, but it's okay.
Um, but that's a really cool, another cool aspect of of doing marketing is you get to not just play with the astronauts in the European Space Agency, but sports leagues too. That, that pretty much sums up my world. Um, how, how, how does that message resonate to the techies out there and to the old line manufacturers and the, you know, the kind of the nuts and bolts, the, the block and tackle clients?
Yeah, right. You know, I, I think again, it's about telling that customer story. And, and the, the reason that we partnered with the 49 ERs and with the NFL is because they're customers, right?
There's no story there. If you're not a customer, um, Aston Martin, uh, a big F1 customer is, is actually a hundred percent on NetApp storage. So it, it was, it was compelling to us because these were customers who were doing phenomenal things.
Let's just take the NFL and focus right there. When they go in and create a moment inside a stadium for Monday night football, Thursday night football, Sunday night football, an international game, which we're a massive sponsor of, they turn that entire stadium as one of the NFL CIO says into basically a, a gigantic data center, right? You've got data from your fans, you've got data from the, the television broadcasters.
You've got data coming off of the sensors of the players. You've got data on the sidelines. You've got calls to the data in the cloud on-prem.
When you are able to tell that story. And when it's CIO to CIO or data storage specialist to data storage specialist or cloud specialist to cloud specialist, what they can do is they can see their issue inside of another story. It's not us telling the story.
It's us giving them an opportunity to see beyond their own and to make additional connections. And I think sports in and of itself, provides such a global stage. I mean, it's, it's the biggest Switzerland of, of all customers, right?
Of all technical environments, because everybody somehow engages with sports. And, and I think that those things a, allow us to, again, back to that evolving human experiences, whether you're a fan, whether you're an athlete, whether you're a student, whether you are in IT and doing the job, whether you are servicing somebody, we wanna make sure that our message is accessible to you, um, and that it is somehow making an impact to what you do daily. Or maybe you get really inspired by it.
Absolutely. I knew we were gonna, Gabby I knew we were gonna run outta time, but I got one more question for you. Okay.
If you have a couple minutes. I do. Okay.
You know, everything we've spoken about at this point to this point has been about understanding what NetApp does. You know, understanding the supremacy of data, understanding ai, understanding technology. But I think especially from a marketing person, we can never lose sight that it's about the human right.
It, it's always about the human. We can't take the human out of this equation. AI will never replace us Machines, I don't think will replace us either.
AI and machines. Maybe. I'm only kidding.
You know, it's about the human. Yeah. And so how do you, again, as a master marketing person, a, a chief marketing officer, how do you make sure we don't lose sight of keeping the human dimension, of keeping humanity involved, of, of putting the human in the middle, the human in the, in the chain, if you'll, Yeah.
Yeah. You know what? I just come back to what we were talking about up at the top.
Data isn't just technical. It's, it's really, it's what we use to create possibility and, and fueling that humanity. Um, you know, marketing as a chief market, chief marketing officer, whatever I am, I, my job is to unify my function for the company and to do as much as possible so that my stories, company stories, the stories of my partners and my customers, of my sponsors and my alliances, that all of those are able to kind of move together and demonstrate this ecosystem of possibility.
And that's, and that's really, I think, um, the most important part of being human and having marketing to help technology become human and make data human. It's listening to what we do first. And, and I'm really proud of intelligent data infrastructure because I think it does that it is specific without being, um, too, too specific.
It's, uh, unique without being overly, um, unique. It's about how you interpret it. And I think that once you create that foundation, then, then that opens up the door to human possibility, regardless of where your data is.
Um, you know, NetApp is here to, to be a partner to you, to bring that forward and, and bring that, bring your possibility forward. I love it. Gabe, thanks for being human and coming on.
Thank you for asking. I appreciate. Well, what else can you be, anyway, but thank you.
It's been our pleasure to have you on here. KV Boco, chief Marketing Officer at NetApp on Tech Drunk tv. Hope you enjoy it on our pre-Thanksgiving show, and we will, uh, be right back with more.
Thank you. Hey everyone. We're back here live at CubeCon.
It's Tuesday afternoon, getting a little punchy. We've been doing a lot of interviews today. They got popcorn and cupcakes out here.
It was hard getting me back in this seat, I'll be honest with you. But, um, nevertheless, if there was one person at this event who could get me back in the seat, it's my brother from another mother here, John Willis. John, welcome.
And you owe me a dollar, right? And I owe you a dollar. I owe you a dollar.
I, I tried to throw the bag in the garbage. Can I shot a, like I was from Indiana. I was Oh, miss.
Anyway, John, Hey. Pleasure to have you On. It sounds great to be here.
It's been a little while since I've been on the It has been. It has been. You've been busy and running and running around.
Sure. Done. Let me introduce you to the man in the middle, though, playing the five spot.
Just checking how much you know about basketball. Yeah, I know. Alright, so Oliver Eikenberry.
Yeah. So glad to be here. Glad to be able to come and talk to you guys.
Um, Oliver Eikenberry, I'm a principal architect with Rio. Um, we're a small boutique, uh, consulting firm that specializes in DevOps transformations, um, at largest large scale enterprise organizations like we. And we really focus in on, uh, building width, not four.
So we come into an organization, we, we do value stream mapping sessions. We under really get to understand the client and where their problems lie and what they're doing. And so, and part of what I do and what I drive the most is I'm, I lead our platform engineering, uh, initiatives.
So I'm really focused on how to build great platforms that support delivery for these organizations and really leaving them in a better spot so they can continue forward faster and on their journey to provide value for their customers. I love it. Let's do a little digging here, though, Oliver.
That was a great, a great, uh, segment. But we got to, you know, put it into chunks that people are gonna grab. Let's start with the name of the company.
So Lee Atrio. Um, so there's this flower called the ous Flower, and Chris Blackburn, our CEO, when he was founding the company, he saw that flower, he kinda liked that name. It grows in the desert, it grows in a lot of different places.
Very beautiful flower. io domain. io.
And that's kind of where the convergence of the name came from when he formed the company. Very, it, it Also tro io or t io. We have, we own multiple domain domain names, but that was kind of the synthesis of the t io.
So Rio on a play name and the, uh, the common name for the Rio Flower is Blazing Star. And we are blazing stars and really drive and shine a light on a lot of things that we do with the organizations that we work with. So, So you're telling me the company's founded on flower power?
Yeah. Yeah. You might say that, but yeah, I love it.
You know, it's a lucky thing you got both domains. io is supposed to be going away, right? Yeah.
Thank God you, you didn't we that was, We've had that for probably 10 plus years at this point. Yeah. So very cool.
Um, so we mentioned the domain name. We mentioned what you do. I just wanna make sure we get our housekeeping outta the way.
Yeah. John, what do just, you haven't been on in a while. Give people a quick update on you.
Yeah, so I, you know, I finished, um, a book that I worked on for two years. Uh, it's called Rebels of Reason. It's the history of ai.
You know, I, if most of you, I, I wrote a book about Dr. DAMing. I've, I've found this rhythm of telling stories like historical it, but taking complex subjects so that everybody can sort of understand them.
And, uh, yeah, I finished that. It's been out almost a year now. Um, and right now I'm, I'm starting, I'm fascinated with quantum computing and how that's gonna like, invade probably not until at least five years, but like, I, I think now's the time for thought preparing For few days is coming.
But, But speaking of Theatro is, I've known Chris Blackburn from the earliest dev days. Him and Damon Edwards worked together. Yep.
Okay. So when Damon was moving away from moving more into product and moving his very successful consulting business, he partnered with Chris. And a lot of that stuff that Damon had built on, like some of the best value stream mapping stuff that's ever been out there.
Chris took that over and I've just watched Chris over the years build a culture, you know, and, and you know, in all transparency, I am working as a consultant helping some of their sales team right now. But I've been a fan of Chris's what he's built. 'cause the truth is, regardless of whether I'm getting paid or not, they've been always doing DevOps the right way from the beginning.
And I think what's fascinating now is as we're seeing everybody want to do AI native and how I do that, those principles are more important than ever. And, and that's why I like sort of decided I wanna do some work with them. 'cause I think it's fascinating to use those principles that we know work we've all been sort of talking about for 15 years and, and, and stay away from the people who are just going right into AI and using none of this, the things we've learned over the last 15 weeks.
So yeah, that's, that's sort of my story around why we're here or I'm here. Excellent. Alright.
So guys, let's dive into it though, right? Just when we thought we were getting our arms around DevOps, right? It's real.
We, we know how to turn the dials. We know what dials to turn or we think we do. You know, we, we, we, we got to the top of the mountain and hopefully it's a little bit more of an easy sale.
Now this AI thing comes along Of the mountain. Yeah, Right? It's, it's the theory of constraints in real life for us and everything you thought, you know, let's throw the cards back up in the air and see where they land this time.
Oh, and let's mix in, mix in a little platform engineering, some cloud native. Hey, maybe even we'll talk about a little quantum down the road. You ain't seen nothing yet, right?
Basically, we haven't solved nothing Oliver. Well, in one way I guess it gets, it's what gets you up in the morning saying, Hey, I got a fresh mountain to climb. Right?
On the other hand, there gotta be days where you say, geez, does it ever get easier? Yeah. There, it's, it's both of those because I mean, I've been, so I've been pretty focused on platform engineering in that space for the last two to three years, owning and driving that, figuring out how to really drive how that connects to DevOps.
Because a lot of people say DevOps is dead platform engineering is the new DevOps. And that's where the principle of and really drives this DevOps is a culture, it's a philosophy. It's not a thing.
And it Always want don't DevOps, let's Clear Right at its purest point. And so I get up and I, I look at what's new in the platform space and all of a sudden there's this new thing with AI over here that's gonna solve all my problems. But I, I look at that and I go, well, that's just actually the foundations of a platform still exist.
I still need a place to run all those agents, run CPS and interact with all the existing systems that exist today and manage those. So now my, I get up and I go, oh, how does AI inflect and change in the space? And we have a whole team that's run by Robert Kelly, our VP of innovation at Rio now that is an innovation team.
They are focused on what the next thing looks like in the space around ag agentic development and how to get that and transform organizations in that flow. And the struggle I have is, it is too much. There is, so AI moves so fast at this point that you can't just go buy a tool or subscribe to any one LLM or other area and, and say, that's it.
I can stay there. It moves too quickly now. So the struggle I have in the pain is, is like you have to keep up.
It's a constant like hamster wheel effect now. It is in that space. The problem is, is you can burn out on a hamster wheel.
Yes. I wanted to make a point that, you know, like the why the fundamentals matter, right? And in to today's, uh, keynote, uh, the open guy from open ai, great start.
So this is open ai and he talks about how the logging, he did some performance review. So you think about all the stuff that has to happen to get us chat, GPT and GPT five and all that stuff. They have to log, they have metrics all over the place.
Of course they have that, right? And he talks about how they evolved into that. But then he shows this, and I think the presentation lies how one line of code is saying 50% CP utilization across the board.
And basically what he found, going back to the fundamentals, the fundamentals are always gonna be here no matter what we build with ai. He, they, he found through basically some perf tools that there's a library in one of the new, um, you know, fluent bit, bit fluent or whatever. Um, that was doing, um, an FS stat, just a basic, you know, c library fs stat to get metrics from a file to log that was happening in an iNOTiFY routine as part of the colonel.
And he literally made an open source change that he could toggle that FS stat and he saved 50% CP utilization across all open ai. This is why. So as we're talking about AI native CPU or GPU or both, no C-U-C-P-U, but as we're talking about open, you know, Claude code and all this stuff, it's all fascinating, but the fundamentals are never going away.
And that's a case in point with like 50% utilization at open II is solved by a true understanding infrastructure io at all levels. Right? So let me talk fundamentals.
Fundamentally, if it's costing you a dollar for every 20 cents I give you, you got a fundamental problem here. And, and I think that that's to a certain extent where we are with this ai, you know, there yeah, there's a lot of platform engineers and a lot of DevOps folks and a lot of developers who are saying, ain't this grand, ain't this grand until they get that first bill for tokens. Yeah, yeah, yeah.
Right. Token usage and so forth. Right?
I I think I, I'm not anti ai. I use AI more than most people I bet. But I, I don't know if we have industrialized, I guess is a good word, industrialized.
Its usage at scale in a, in a sustainable, and I'm not talking about energy. I'm Right. Sustainable from a business point of view manner.
And, and you know what, Oliver, you're fighting the fight on the front lines of this, right? You're like a firefighter in California here, but is it, is it a wildfire? Is it something we can get a, hold on.
I think We're, we're seeing emerging trends and patterns with like Claude Flow and some of these things that are enabling an individual engineer to have multiple agents go do things and help them do things faster, produce things that they can review faster. So we're seeing that acceleration at the local engineer level. All the tooling is very focused to that.
But we're starting to see emerging parts, pockets, and parts in the market now. Like at GitHub Universe, uh, just a few weeks ago where they announced, sure, oh, I can run my agents in GitHub's space and they'll manage those agents, agents for me. Where in order to really unlock and go from 10 Xing an engineer to 10 Xing an entire organization to really get to that value, you're talking about from a business perspective, we have to figure out how to give the engineers the ability to use these new tools in a shared way.
Because AI is context. Context, windows, figuring out the context, parsing what you need to do to get the right results out of it, because it's deterministic in a lot of cases. So as we figure out how do we scale that and say, oh, this agent is really good at producing these things in this organization, and it's referencing what I've already built as a fundamental in my organization and how to engineers, are they able to share using that, spin it up in a collective way versus having to only do it at the level of their machine and what's going on, right?
So we're seeing emerging things in that markets moving that direction, but it's still so open as to what you can do and how you can figure out how to do it well And what's going on. It's wild west and it's, yeah, it's Very wild and open. We we're Still creating the maps, if you will, before sailing the oceans.
There Was a DevOps day is Dallas. There was a gentleman from, um, I think, um, one of the car, like EEDS or whatever sort of, um, One of the third party Bargains. Yeah, yeah, that's right.
And, and he was talking about economics of token, token not just sort of token costs and tracking out, but they we're starting to see the what's happening is finops Yes. Is getting involved. Yeah.
And finops is sort of mandating like, I don't, don't explain it to me. You just need to explain these costs. And so I think like everything we do, I mean we, I mean I, you're right, it's very dangerous.
The token cost can get like scary really fast. But, but we, we source some of this in cloud. Like everybody raced out to the cloud and then we, we figured out some cloud economics Efficiencies.
Right. Efficiencies. And we should Of And that's not, that's by the way, that's not a technology thing.
That's right. No, you could any innovation. First you do the innovation, then you figure out the efficiencies of it, right?
That's right. That's right. When you look at, at, at big Pharma, when they do, uh, experiments on new drugs, first they figure out does it work?
Then they figure out what, how, how much is it gonna cost Exactly. And how do we optimize its efficiency. And I think that's where we are in this early, let me, let me, let me bring up another fundamental for you.
And it's really important to every single person in Booth here at this event, at the end of the day, is it about using AI to make our platforms better, to make Kubernetes better, to make observability better, to make DevOps better? Or, or is it, in order to use ai, we've gotta reinvent all of those things. I just told you platforms, we need platforms that are optimized for AI inference and or learn or training.
We need, we need, Kubernetes isn't going to be the orchestrator for AI applications. We need a different, we need something, call it native AI that is going to orchestrate my AI stack. 'cause is AI gonna create a new stack that renders all, everything you see here obsolete?
Or do we make this stuff the stack for ai? What do you think Oliver? I think it's both.
I think to the, is is there a whole new stack for ai? We don't know yet. That is an undiscovered country that I think all of these engineers that are like really playing with this and pushing the limits and boundaries of what AI can do, they will figure that out that will emerge on its own as it happens in the space.
And likely we won't see it till it happens. Um, in terms of like runtime for ai, when you talk about the, like there's a huge push into using Kubernetes to run AI and l workloads. There is, that's Right.
But are we pushing Rope up the hill on that? Maybe I, there's other organizations that are, that are spinning up entire data centers just for GPUs. So they're data centers that are just rank trillion Worth GPUs to then enable people to run that.
And they're building declarative Kubernetes stacks on top of that. I honestly still go back to even the lower fundamental of that, of how compute works. Kubernetes is great for scale.
If you don't need that scale, what do you, what do you use it for? And how do we look at, so it's a kind of a non-answer, but I think we have to look at both, both perspectives and be prepared to shift one way or the other and what's right. Because really what AI is doing is it's, um, it's giving us the ability to build larger shared context, put more information into the system, and build bigger, better things and solve bigger problems.
And so it's, that platform will emerge, but in order to do some of the stuff in the experiments, we have to provide a space for people to even try those experiments. So that's where We, When we look at what people, organizations that are getting into ai, they're like, well, which tools should we buy? And we're like, give everybody access to all of them.
Don't sign a three year agreement. Yeah, yeah. With chat GPT sign a six month agreement.
Yeah. Give the, give them access to the different tools because everybody's workflow is different. And that's the unique part of this change is that you can't really put it in a box.
It's too dynamic at this point. Alright. I think that, I love that question, Alan, because, uh, we were just on a Tech Field Day podcast and we had a good debate about this.
And you know, there's sort of the, the, there's two ways to think about it. One is we can look at the proof that Open AI and, and Anthropic are all running Kubernetes mm-hmm. To run large, the largest infrastructure.
And I'm certain Google does too, right? Um, for Gemini. So that kind of tells you that maybe the hammer and nail is never gonna change.
But the beauty now is companies can step back and do things they've never been able to think about doing. Like, and, and because the, the cost of writing your own has always been the maintenance of it. But now that the, the, like the same things that are solving the, I can do things in a week that normally took teams six months to do.
I, it's the same acceleration for maintenance and update. So I think there's an opportunity or organizations, one other story I've heard a few times is some of these larger organizations, instead of sort of getting rid of some of their classic developers are looking at some of these big ticket ELAs. Like a, not saying Workday specifically, but like, could we rewrite Workday?
Could we rewrite Workday for us and build it specifically so it works for our organization? And, and some of those are like, let's try, right? So I think there is a, there is a world where somebody might look at Kubernetes and say, you know what?
We've been forcing ourselves down this thing. Let's prototype an alternative. And by the way, there have been some good alternatives that have died, not because of technology, but because marketing nomad from, from HashiCorp was, was too syndrome.
Well, but, but even in the, in the, in the platform space, yeah. No form for Docker and, and Nomad. Those were perfectly legit solve 80% of the problems that went away for non-technology reasons.
Yeah. Well, the other thing is, is that a lot of these AI tools make using Kubernetes easier. That's Kubernetes is, yes.
Everybody can say Kubernetes is easy, but then you get an SRE stand up next to 'em, they, Kubernetes is not easy. Yeah, yeah, yeah. Um, type of scenario.
So that's the other thing is, that's a good Point. These cha these tools give you better shared context of how to work with that thing. That's right.
So I get to your point, John, they don't have to worry about managing Kubernetes. Yeah. They're more worried about building their app in their workload, and then they start to question, oh, do I need this SaaS tool or can I build it to the specification of what I need?
So kind kind of comes back to software's eating the world. It's gonna eat the world even more because we're gonna have more people building software with ai. And the double down on that is that, you know, as I think about listening to all the keynotes, KU Con today, right?
Like, like I get, I get tainted, you know, like, oh, Kubernetes come to KubeCon, watch people, thousands of people march around learning how to build helm charts. And but to your point, and the point that, that they were making in the keynote is like, all the contributors are now using the accelerated ai. So maybe at the end of the day, we don't have to build Kubernetes.
'cause it gets built through an evolutionary role that, right? Like, we're getting better at delivering a better platform based on CNCF or Right. Cloud Native or Kubernetes.
Ideally, A platform is just removing a, a layer, a low context load from all the engineers. So they have a place to build their apps that they're creating. So you wanna remove that context load.
So AI just continues to layer in the ability to, to bring that context out and further out for them to work with. So, You know what, it's gonna be interesting times, that's for sure. This place out.
Definitely. You're Right in the middle of it. Absolutely.
Every day new articles, my feed gets filled every day I have an entire brow separate profile on my browser. Now that's just AI that all those things go to, and it just stacks up for me to go read. You're not using an AI browser that does this for you?
I've tried, I've played the ai I've tried using that, but part of the consumption or information for me is I want the details to a degree. Yeah. Yeah.
And so I do AI summaries. I've used AI to do deep research on large, complex projects that would've taken me teams of people months to do down to few, a few weeks and, and things like that. So that's about a balance of figuring out the right place to use the tool to build that content.
It's funny, on the AI thing, there's a couple of newsletters I subscribed to and I was using AI completely new summary. And one day I went back and I looked and I was like, I, I looked back on what I'd been doing and it was missing stuff all over the place. And so I've reverted now to reading the art, reading the sort of newsletter summary to his point, like, yes, the summerization is awesome.
I take a research paper mm-hmm. For me, I'll take a research paper and I'll put it in there and say, let me know if I need to read this. Right.
But, but on things, I actually wanna know the details. I'm, I find myself falling back to less Summary mode. I love it.
Yeah. Guys, we're about outta time. Yeah.
Oliver, it's a pleasure meeting you. Yeah, absolutely. Indiana's a big basketball.
I was just, there you go. It looks okay too. Yeah.
It was a New Yorker in me that just, you know, you say that, I'm gonna tell you, look up to see how big that building is before I snatch your wallet. Um, John, always a pleasure. Sounds good.
Yeah, it's fun stuff. We're live at Cucu. We're not done yet today.
Stay tuned. We got more Welcome to Security Boulevard, the cybersecurity podcast from the Future Room Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, our Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms. Before we jump into this episode, I'd like to meet our panel for today, starting with my good friend, Fernando. Fernando, it's good to see you again.
You've been a busy guy for the last few weeks. Absolutely. Uh, wonderful to see you, uh, Eric and Manuel, wonderful to have you guys with us.
Uh, for those that dunno me, I lead cybersecurity and resilience research over here at Foot. And, uh, as Tom alluded to, uh, this is busy travel season for analysts, so I'm still recovering from jet lag, so my, uh, but yes, it's, it's, it's a phenomenal opportunity to, to run into people and chat and, and whatnot. Everyone is excited about the topic.
We're gonna talk today as well. Of course. So, yeah, it's, uh, it's, uh, wonderful to be here.
I hope, uh, folks enjoy the conversation. Awesome. And we're joined with some guests from SIG today.
I wanna start off by having them introduce themselves, Emmanuella. Hey, thank you. Thank you for having me.
I'm Emmanuel ZI run product management for everything AI here at sig. So, as Fernando was saying, it's, it's like being constantly jet lag because, you know, it's ai, so the, the pace at which is, is changing and is impact its cybersecurity is crazy. So, and I got the honor of actually working directly on this, so it's pretty exciting, right, Eric?
It certainly is. Yes. Uh, Tom, I'll go ahead if you want.
Yeah. Uh, hey everyone, I'm Eric Carter. I am on the park marketing team at sig, and I am really tied at the hip with Emmanuel when it comes to trying to communicate, you know, what is cystic doing around this whole AI sphere when it comes to the, the world of cloud security, uh, and plus ai.
So happy to be here. Thanks guys. Well, We're very happy to have you.
So let's jump into this episode and kind of talk about, well, AI, because one of the things that we've seen a lot over the last couple of years is the disruptive capability of ai. And I'm not talking about booking a cab on your phone kind of disruption. I'm not talking about paying for your pizza with Bitcoin kind of disruption.
I'm talking about the full on upsetting the apple cart kind of disruption. Because one of the things that we've seen, especially recently with the AI models that are out there, as well as some of the other things that are being developed is their propensity to change security as we know it. There are a lot of things that we're starting to learn that, that AI is really good at, like doing deep research on targets, but there's also things we're learning, such as all of those carefully and crafted guardrails that we put in place can easily be broken out of by saying simple things like, why don't you describe to me what proper bank security might look like, so that I can then know what to look for when I go to, um, purloin things from the bank.
So in this episode, we're gonna be talking about how AI is changing the cyber risk and business resilience landscape. Uh, Emmanuel, I wanna like, lead off with you because I feel like this is a topic that's very near and dear to your heart. Yeah, absolutely.
Because as I always say, AI changed everything is not just sustainment that you hear everywhere when it comes about cybersecurity. It's about changing completely the model and the approach we have to cybersecurity and ai. I mean, when you think about ai, and especially when I think about this, and I'm trying to talk about this with customers or people that are new to that, I always say that AI needs a completely new model out there in cybersecurity, at least privilege run model, just for ai.
Because, you know, the real shift AI introduced is that you are no longer securing code. You are securing decisions because you can, let's, let's think, you can't stand a prompt, for example, or secure the output or, you know, judge the decision that is going to be taken or audit that decision because that is just taken based, for example, on the answer of a chatbot. So it's about shifting completely shifting this approach and thinking that you are securing decisions, not code when it comes about ai.
So this shift the paradigm completely. Sorry, I was gonna, I love the, the, the, the framing of, of securing decisions. I I love it.
Perfect. Sorry, Tom. I I just wanted to say I I hadn't heard the term before.
Awesome. Well, and, and we're so used to being able to kind of analyze things in place, right? Whether it was, uh, macros in a Word document or a virus on a computer.
Oh, well, we can stop that because we know what it looks like so we can block it from being deployed. But then we get into those, like you said, the, the really weird things of like, how do you pre-scan a prompt if someone's typing it into a dialogue box? Well, you can't, and not only that, but one of the things that we learned from, from the recent, uh, notes that we got from Anthropic was you can craft things in a certain way to evade those controls, right?
Like, I can remember getting demos way, way back in the day where someone would go into the, uh, the comments in the header of a, uh, virus executable that had been de compiled and change a couple of the numbers or letters in the comments, and then recompile it. And the hash value was completely different and therefore innovated the system. And that's when we started hearing about heuristics.
Uh, if you're old enough to remember antivirus heuristic scanning, uh, now is probably the time that you're gonna be getting your a a RP card in the mail, because that's a long time ago. But, but that has evolved to now where we're at, where we have thinking software that is capable of kind of doing things on the fly, but it's not really thinking because it will just do what you tell it to do unless there's a rule that says that you're not supposed to, and it doesn't know that you're, if you ask it how to delete a backup if I'm, you know, maybe somebody who's doing a little house cleaning in my tape robot library, or if I'm a nefarious actor who's trying to erase all evidence of my presence in an organization. No, I was just gonna jump one thing, and, and, and it's funny because we jumped into this in this conversation as well, when I have, when I talk with, with security executives and others, were trying to make sense of this all, one of the things that I, I find interesting is how are we gonna tackle the topic to begin with?
Let's go back to, to what we're describing and, and runtime. But the way that we, we like to frame security conversations to help people understand what kind of problems they're trying to solve. Is it, it's the, the, the, the triad that people refer to as security for ai.
How are we securing how organizations are applying AI capabilities in whatever. That's, that's topic one, right? And, uh, the other is AI for security, right?
How are you using AI capabilities within the security processes that you are running your organization? Topic number three is security from ai, right? Or security against ai, which is okay, even if you do nothing else, you go home and, and you just wanna be quiet, right?
And not touch ai. It doesn't mean that your adversaries are not gonna do that. And that's what we're seeing all the time.
I'm sorry to give, to go back to basics a little bit, but that I, I find it interesting to, because I've walked into many conversations when we were expecting one type of AI conversa AI security, and we yet another, right? So that's, I just wanted to frame here. The other thing I, the other thing I like to say is I like to frame the discussion between, are we talking about workforce AI versus workload ai And workforce AI is okay, within the scope of a company, how is the company using AI to support us as employees?
Right? So, or, or what are you using as a person? Hey, all of us have, uh, an LLM of choice that we use to, Hey, help me craft this email a little bit better.
Whatever. Right? Fine.
That's one type of of use case. The workload AI is, look, our company is deploying AI within our company, is deploying something that, that something is using ai. What do we do about it?
Right? So, sorry to backtrack us a little bit, but I, but I think that, uh, uh, making the distinction about which one we're talking about is a really good first step too. Yeah.
We, we face that, Fernando, because, uh, we are, we are out obviously talking to the market about it, but also people inside of SIG and we always have to clarify of, you've come to me and you've said AI security. Now let's add something to that. Is it AI four?
Is it security four? I like the third one. Uh, where I think inherently insig, there are things to protect what you were talking about, which is AI trying to break through the walls, et cetera.
Uh, so that's a, that's a good third one there. When we first started talking about this, I had created a slide just to try and put a visual, and if you remember, rock em, sock m robots, Tom wa and there's like, I have a red team and a blue team, and these guys are fighting it out. So ev we know that the bad guys have this at their disposal.
We, uh, before we, we came on the air, we were talking about the, the claw and the, the, the issue that was revealed this week, right? And so there's a perfect example, right? So they've got it.
We need to have it as well, um, in order to stay ahead of these things. And somewhere in the midst of all this is a, is also this trust conversation so that we, when we are using it, we can trust it, but there's, so there's a lot of things to, to cover, but um, we're, we're focusing on, on both, especially using AI to try and defend, right? First of all.
But also since we are quite, um, good at and known for Kubernetes security, a lot of these AI environments are being rolled out as cloud-native workloads. And, and there's, there's a, there, there where okay, it's, uh, it's something you've got to make sure you are ready to deal with, right? If you haven't, um, been securing your cloud and cloud native environments the right way, you better get on it.
So, oh, absolutely. And, and, and as a side note, I've been covering cloud and cloud native security for a long time. I'm well aware of, of, of, of Falco.
And, and, and, and everything that that, that f have done in your, in you're spot on, like you, the visibility that we, that, that we need into how runtime is running on those clusters, right? If, uh, if, if is essential. So Yes, absolutely.
And this Fernando goes, sorry. No, goes back into what you were saying at the beginning actually, because the point is that right now we are no longer, you know, we are no longer securing something static. Think like a castle, for example, with firewalls that we were mentioning before, is something that is changing constantly.
It's dynamic if think to this like an ecosystem. And that's the thing, because people only think about ai, but the real thing there is that attackers, like, we talk from the point of view of defenders and people that works in cybersecurity, but we have the same tools. We can leverage AI to actually defend against those threats, but they can leverage AI to automate and actually make things faster.
Some, I remember it was some couple of months ago, I guess, with a web UI kind of, uh, kind of box that was out there, and you remember that they kind of exposed without mean privilege, uh, this interface. And basically the attackers just created an AI generated Python script as simple as that, to be able to leverage that and start a crypto mining activity. As simple as that, when you analyze death code, it was 90% AI generated.
And that's the thing we are, you know, we are starting a war with the very same weapon out there. It's powerful on both sides. So it's, And, and It's there.
The thing that I, I help, uh, that I wanna have conversations, the thing that I think helps people understand is what is AI changing, right? And ai, at least talking about security from ai, like what are the attackers doing, right? And we're not yet, like, we're starting to see these more and more.
And, and, and I'm, uh, um, I think that attackers are very, um, uh, very rational when it comes to the economics of attacks. And they'll use what's affordable. They'll use what's, they'll use the minimum they need to get the job done, right?
And, and so, uh, I've, I, I've had conversations where people are saying, look, I don't, I, I know AI here, but I don't want to deal with it because I have to deal with so many other things. First, I like to point out that, look, we're not, we, we want you to think about security, security from AI now, not because of the attacks that are happening now, but what is changing coming along, right? You mentioned, you mentioned the Python script, Tom mentioned the, the, the, the, the, the, the report that just came out.
What is common between them? I think that two things we're seeing that it's important for defenders to keep in mind. We're talking about AI enabling more attackers.
So we're giving attackers or AI is giving attackers access to better knowledge, right? So in other words, if I, if I am, I, uh, I'm old enough when we used to call them script kit, right? Uh, uh, uh, now that capability, the capability that somebody can have now is much greater.
That's point number one, right? Point number two is that not only that comes with greater capabilities, but that also comes with much faster speed, right? And I think that if, if as practitioners, we can help teams be ready for what if you are, what if the, what if your attackers are more skilled, and what if your attackers are faster, right?
Those are the two things that, that can help frame the conversation. Sorry. Yeah, Fernando, it's a, it's a great point, and it's one of the areas where we focus when we talk about how we are doing AI for security, is you, you do have people who are not as skilled and they need help, right?
And a AI can can be that helper. Uh, this week I was reading news about, you know, new models and so on, and they talked about these are now PhD level and above kind of intelligence that you're bringing to this. And I was like, wow.
You know, I didn't go to that much school myself, but, um, yeah, I mean, this is it. We need, we need to enable, because you're saying like, you know, they, they're with very little effort and knowledge. They're getting out and doing bad things, and we need to help people with the knowledge to, to combat against that, right?
Right. Where they're working and not have to jump out, ask a friend, not have to jump out, try and find an answer somewhere on the internet, right? Give them the answers they need or give 'em the insights they need, right?
Where they're working to stop these th threats. And that's back to the point, uh, Exactly. Just to clarify, the, the more knowledge and more speed applies to both.
I mean, I was talking about attackers, but it applies vendors as well. Yeah. We want, yeah.
Defenders need to be faster and, you know, full stop, right? And, and how one way to do that is to employ ai, you know, in a, in a helpful way, um, and to, so that everyone can do what they need to do, even if the, uh, super smart guys are not around the shop that day when something happens, right? And the other, the other piece to this, Eric, I guess is also the, the fact, and, and you know this because that keeps coming from customers and users.
It's not just about, you know, getting the insights you need. It's getting the insights you trust, which is the other big topic with ai, because it's not just about, Fernando used this image at the beginning saying, do we need to distinguish between AI workloads and AI workforce? Everybody's so worried that AI is going to steal their jobs while AI is actually augmenting what they can achieve.
Because it give, it's giving me more knowledge. It's giving me visibility into something that usually will take me even days to just understand what is this threat I'm trying to investigate on? I would get there in second, but can I trust the answer that I'm getting and the trust topic?
If I have to think, think back to the last three years of my life working in a, in ai, the trust topic is probably the biggest one always coming up. Because the thing is, I'm getting, I'm trusting, completely trusting this solution that is telling me we want to be faster. This is the thing you should look at.
This is how you should solve this. These are all the things that are related to this threat that I'm identifying right now. All of different time events, all of the context that is happening out there.
It's not, the room is the build on fire. And this is what you should do, is frustrated. Should I, shall I do that?
Actually? Can I trust doing that? And trust is the real currency of ai.
That's the thing. The clo the, the whole topic of the cloud thing was they asked kindly. So that's the thing.
You, you trust them because it looks like it was a human interaction. That's the, that's the thing. Who am I trusting?
And, and, and it's a phenomenal, sorry, I get excited about this. It's a phenomenal conversation because in part, we're asking, uh, security teams to, to think about this differently. I would argue that this, this discussion of trust get outside of technology, right?
Uh, it gets into things like semiotics, right? Where you're, where you are talking about the, the, the, the meaning of symbols and the meaning of trust, right? What does it mean within, uh, a workflow that we can trust what AI is generating?
Now, I, I I, I, I, I'm lord of the Rings fan, and every time I talk about ai, I quote the, the scene from the movie where, where, um, uh, Elron is telling, uh, gal, I was there, gal I was there 3000 years ago. Years Ago, yeah. Uh, and because I was there when we were playing with a, with symbolic AI in the early nineties, right?
And, and of course it goes even before that McCarthy in 1960s, right? But, um, but we have been trying to, back then, we were trying to do just AI based on, on, on meaning and trust, uh, and, and expert systems. We are now into this age of, of generative AI with neural networks and, and, and they're amazing, their own right?
But perhaps we're, we're, we're gonna see something, uh, we need something different, right? We need a better, a better interpretation of how do we evaluate trust in these systems. I think you're, you're, you're spot on.
And I think agentic and the evolution we are seeing with agentic AI goes also in that direction. I mean, it's, it's cool from a technology standpoint because of course, you, you are seeing AI being at your service more and more doing things for you rather than just reacting to what you're asking, which is absolutely amazing. AI is becoming proactive more and more.
But are we actually ready, especially in the cybersecurity area for the right use cases to actually make the most, Uh, I, okay, let's, let's pick on that. Um, where I think that, uh, I, I agree. What I've seen is that the, we are, as an industry, we are arriving at the point where we are sort of agreeing on what is okay.
And some of those things is, uh, uh, some of those things is that we need domain knowledge experts yourselves, right? To take what you understand of the domain, synap, cloud native security, what have you, and then find out, okay, what are the rules within this domain that we are gonna enforce? And where are we going to use an capability that's going to use a, um, that's gonna use a, a layer of the interaction with the user may very well be at your LLM of choice, right?
Whatever model, right? But within it, we rely on your expertise for coding the rules of how that agent is going to behave, right? And then the output of that can be exactly, uh, I love your, your, your part.
I don't have time to study all this. Give me this, give me that summary. But even that summary is informed by your domain knowledge of the subject, right?
You're not going to say, uh, for a Kubernetes cluster, oh, just reboot the cluster, right? Or, or, or, or, or, okay, just, just kill, uh, q proxy or whatever. No, it doesn't work, right?
Because you know how the system works and that, so it's a phenomenal area where we need, I think we need both. We need people who understand the AI side of things, but we also need to understand the domain that we, that, that, that we're talking about. I mean, agentic makes the most out of it.
When, when it gets in context knowledge, it's even more relevant than in all the other AI stuff. And the thing is that, that in context, knowledge is not just about where I put AI in the product. For example, when people ask me, that's a classical question I always get, why shall I use your assistant inside your product in instead of going to my LLM of choice, whatever it is, and just copy and paste the same question.
And the answer is always the same. Does MLM knows the context you're acting into? If you ask about these alert or ontime events or vulnerability, does it know all of your infrastructure context and what that relates to?
No, it doesn't. So that's exactly a thing. And there's no one other than us as, as people that are, you know, embedding this solution or you as users that know exactly what you're chasing for, that can give that context doubt, that context.
AI is blind. So that's exactly where we can make, have an impact and make that that change. I always, you know, I always say that AI is, is not a technological challenge, is evolving easier to stay, that's a matter of fact.
It's going to evolve. We will have more, are getting better and better. And even the a GI promise that is still still out there, we'll get there.
But the point is, I know the point is that even like that all of this is, is out there, is evolving, and that is true, but the real challenge is a business challenge. Are you going to adopt that and actually understand if it's valuable for you and there mean an impact on your business, or you're just looking at that like a technological thing and want to check a box and say, yes, we are adopting ai, because that's completely changed what they're trying to achieve with that. To go back to you, you touched on so many good points.
Uh, uh, I think that one of the things that I, um, I keep coming back to is that we, what we observe is over in technology overall, and, and like I, the gray hair comes from being there 3000 years ago, right? The, uh, what I've seen throughout career is that we keep, uh, we security is, is, uh, it's like a key thing, right? On one hand, we need deep technical knowledge about specific areas and, and, and whatnot.
How does EBPF work? How do what, uh, how do, what are timing attacks, uh, uh, or side channel attacks against quantum protocols, whatever, right? But there's also this, this tying into the business, right?
And they keep saying that as security, uh, practitioners, one of the things that we should be doing in this time of AI is this should be the golden age of business process engineering for cybersecurity. We should be helping our, we should, uh, uh, be helping our stakeholders understand what their business processes actually are within those business processes. Where does AI fit?
And there are places where AI fits perfectly. There are places, there are places where AI fits, nah. And there are places where, get this away from us, right?
That AI doesn't fit here. So to your point, it's about understanding not only the technology, but the business side of things. And, and, uh, that's a, uh, that's a conversation that requires growth, that requires you to understand people, process and technology.
I know it's the, the usual, the usual things, but yeah, that's where we're going as an industry. We are getting better. I'm, I, I'm optimistic about all this.
We can debate agi, agi I is a different story, but, uh, let's talk about that one later. Pandora books, Uh, yes. Uh, yes.
Yeah. Yes. Yeah.
Let's stick with, yes, that's it. So I guess maybe the, to kind of bring it home, I, the question is we have all of these aspects of AI that we need to be keeping track of. Like, we need to understand how we can leverage it, how it can be leveraged against us, what we need to do to keep it secured for our people to use, whether it's for workforce or workloads or things like that.
But I guess maybe the question would be, you know, what are some of the things you guys are doing at SIG to kind of advance the technology here? Uh, because one of the things that I love about AI being kind of a great equalizer is that sometimes the best innovations come from places that you wouldn't have expected. Yeah, indeed.
Uh, which is Go ahead, Ika. Yeah, yeah, yeah, yeah. So, um, one of the things that we've done at Cy, first of all, in the, in the realm of protecting AI is to, and because there's so much concern about something's just popping up, there's data being used to train, what's the security is helping to auto identify where there are AI libraries and packages running in your environment, right?
So we've been able to do that so that then we can start to apply the security principles and the things that we do. Fernando, you mentioned C nena, we are a CNA, you know, whether it's posture side or whether it's the threat detection side, right? So, so there's that.
Just trying to give you a spotlight that this AI is in your environment. Did you know it? Did you not?
Well, now, you know, right? So that's, that's the one thing. Uh, uh, on the other hand, and again, our assistant is something we call cystic sage.
We, we, we started with sort of the, you know, ask me a question about this thing you're seeing. We talked a minute ago about context, right? So one of the cool things is that it knows what I'm looking at, and that's important.
It knows what I'm looking at and knows what's going on in my environment so that I can ask a question. And it's considering that context. And so we've started to implement that around, whether it's threat detection, I need assistance, right?
Or it's vulnerability management, which is a still a huge, despite all the goodness that we put in to trying to help people prioritize, it's still a problem. And this is where we're trying to leverage AI agents or agent AI to, to do some of that tedious work for our customers. Um, and then as well on the posture side, right?
Just being able to get insights about my environment by asking a simple question. So we're trying to give the, the tooling, and I'll have Emmanuel can expand on that, just that, again, wherever I'm working, I get the right insights and I get recommendations on what to do next. And that's sometimes the hard part.
We really wanna get to a point where you've got the recommendation. You can say, make it so, or trust you got a point where I, it's just doing the thing for you. And if you need to peel back the layers, you can peel back and see what was it that AI considered?
What was it that AI did, right? So that there's that whole visibility aspect as well. I mean, when, when we usually always introduce, uh, STIC agent and what we are doing, a cystic explaining to our customers, you know, prospects, people asking about what we do, saying that we are not substituting what they do today, or just giving a fancy way to do the same thing they could do with the product, or just using a, an a, an API with a CLI and whatever we are augmenting what they can do today.
Because if the pain is that I have thousands of vulnerabilities to manage with every single day to deal with, and I have no idea where to start from, that's a pain. I don't want a fencer interface. I want a real help out there to cut through the noise, to prioritize and say, bring me to the action point where you are giving me all of the information I need to take a decision and move on and do what I need to do.
And that thing, I, I mean, I may be biased, of course, as and the problem manager, so my baby is always the best baby out there. But the point is that that's what you need to do. Use AI to better serve the need that we have out there in cybersecurity.
And we know that speed is our currency because that's what makes the difference between completely fail and w infrastructure down and have a business damage out there. And instead being effective and saying, okay, I can go out there and, and be armed with the brace and weapons that Maya attacker said, we, We really wanna, that's Exactly way we're, We wanna flip the script, so to speak. Like today, when an alert fires, we get into action and we start investigating, we try and figure out what's the impact or potential impact, and then we figure out what's the solution.
And all of that takes time. You know what, if you get right in the alert happens, yes, I still get notified and everything I need to know how to deal with that issue is right in front of me. And again, when I get to a level of trust, I say, okay, thank you, AI engine, we've done it, we're gonna do it.
Go do it. Right? And then, then I can go see all of the impact, all of the, uh, forensics of what was leading up to this, but I've taken action in, in really seconds or minutes instead of having to go through that long chain.
And that's some, that's the promise of, of AI and AI agents that will go out and do things for you. Well, it sounds like there's a lot that we're gonna need to consider as we think through this whole process. Uh, there's a lot of aspects that we need to have control over.
And one of the things that I know about AI is we're probably going to be rethinking this problem in six months when some new capabilities come out, or some new thing that we need to worry about is happening. But the good news is, is that no matter what happens, we're gonna keep you up to date here on Security Boulevard. Uh, Fernando, uh, you just had a report came out that, uh, I think people want to tune into.
Uh, it was, uh, one of the new signals, Yes, we just, we just published a security operations platform, uh, report, um, where, so tuum is a, uh, we call ourselves an AI native analyst firm, and we are very much, uh, looking into where do we deploy it in a way that makes sense and, and, and so on. And, uh, this type of signal reports, they, um, they're looking into this broader notion of security operations platform. And then from there, where, uh, where should people go?
It's, it's, it's supposed to, it's, it's, it's aimed at helping people understand this, this fusion of, of, we have analytics, we have controls, we have ai, where are things going? So that was just published, uh, uh, uh, group com, track the signal, it, it's relatively easy. Define, right?
And, um, and yeah, it's been, um, it's been a, a, a very interesting experience. I'm, I'm, uh, I'm, I'm starting to work on the next one now, right? So the, these, that's one of the things that for us is interesting because we can, we can, uh, work on them in a much faster pace.
So this will, uh, this will be fun, right? Alright, And, uh, our guests from, uh, SIG, if you, uh, you've talked a lot about some of the SIG platforms and products that you, you worked on and that people, uh, should be checking, checking out if they want to do that, where can they go to learn a little bit more? Just, man, I was waiting for the marketing guy to speak up.
Uh, jessica do com. From the very get go, you'll get the flavor of, of what we do and can lead off from there to good to dive deep. We have a lot of interesting and good, uh, uh, articles about technology.
Even, even if it's not a cystic thing, just like you wanna learn about really what is Aden ai, we've got something that will help you and put that in the context of cloud security. Alright? com.
One thing that I think you're gonna be excited about, though, we're gonna be at RSA this year. First time we're doing Tech Field Day Extra at RSA, we've got a couple of companies that are already lined up and ready to talk about it. And guess what?
We've still got four more months before we get there. So I bet you we'll have a couple more before all things are said and done. com for more information about that as well as Security Field A and all the other things that we've got coming up.
We wanna thank you all us for listening to this episode of the Security Boulevard podcast. If you enjoyed our conversation, please make sure that you subscribe on YouTube or in your favorite podcast application of choice. That way you don't miss any of the episodes when we publish them, especially if we do it right around the holidays when you're probably looking for a break from your family and all that Turkey.
Uh, we would appreciate it if you leave us a rating and a review. That's how people figure out what we do around here. And we, we love to hear your thoughts on what you like and what you don't.
com and the Futureum Group. com, the Textron TV website or our Textron TV app. You can download it for Apple tv, Roku, or any, pretty much any smart device, uh, whether it's your iPad or whatever you consume media on, make sure you're following Security Boulevard on our X and Twitter as well as LinkedIn.
Look for security BLVD, and there's tons more content out there. Thank you very much for tuning in, and we'll see you in the next episode. Hey everyone, welcome back here to Techstrong tv.
My friend Ryan McCurdy, VP marketing at Liquibase is joining us on this next tech strong TV segment. Hey, Ryan, it's good to see you again. How you been, man?
I'm doing well, Alan. Thanks for having me. It's great to see you.
Always, always good to see you. Um, hey, Ryan, you know, for those who haven't caught you on Tech Strung TV before, give him a chance of, give a flavor of, of your journey here. And, uh, and if they're not familiar with Liquid Base, let's bring them up to speed.
Yeah, sure. So, um, you know, I've been working in technology for the last 15 years. Spent a lot of time in cybersecurity, um, spent a lot of time in the DataOps space, uh, at a company called Astronomer, working on Apache Airflow things.
And, uh, for the last year, I've been over at Liquibase, um, another really incredible open source company. Um, and for those that aren't familiar, Liquibase has our liquid base community, which is our, uh, our community offering effectively where we automate database change. And then, um, our commercial product, Liquibase Secure, uh, really automates and governs database change across 60 databases.
So, um, we're doing something really unique in the market where we help a lot of companies achieve the developer productivity they want, um, with the automation, but then also making sure their, you know, their database change is auditable, making sure people have the right remissions to that change, making sure that nothing risky really reaches production and causes downtime, uh, which is happening a lot in the market as of late. So, um, we're doing some pretty incredible things for our customers, and we work with some of the most regulated customers in the world. Very cool.
Ryan, I know you mentioned the open source and the commercial versions URLs for those, so people can go check 'em out. com. Um, you can also, uh, you know, go to GI as well.
com we have, um, our community offering available, uh, as well as more information on liquid based secure. Absolutely. And of course, liquid based, probably the company that kind of established what we used to call DevOps for databases or databases for DevOps.
So both, uh, in the market. So we've been following liquid base for many, many years. Ryan, you guys recently announced a couple of things.
Number one, this whole, you know, a burgeoning area of AI governance and governance around ai. And, and there's two pieces of it. One is, you know, government governance, GRC if you will, governance, risk compliance governance around the use of ai.
And then there's the using AI for governance aspect of it as well. What exactly did liquid-based kinda launch here with governance capabilities? Yeah.
Uh, well, I mean, obviously as I think as everyone knows, AI is changing a lot and, um, the, it's not that AI is risky. It's, um, not governing change that is risky. And, um, we really allow our customers to govern change at scale.
And, uh, you know, when you look at, um, AI is writing different queries and modifying structures and in some cases touching production directly, um, you know, you really need to be able to control who's making that change, whether it's developer or it's AI assisted or it's agent ai. Um, and we're able to enforce those controls through, through our custom policies, so we're able to support our customers, uh, in that regard. I think the other piece of this that's really interesting is, you know, your models are only as good as your data foundation, right?
Which in a lot, lot cases your database, and if you're not governing, uh, the changes in your database, well then your models can become corrupted and, um, you know, so it's really the, um, you know, it's, it's how accurate your models are, one, uh, and then two, it's, you know, what are you controlling that goes into production, uh, through AI potentially. So we're really helping our customers ensure your ac their model accuracy as well, just if, uh, they have AI helping with, uh, any type of development. So we're helping our customers both on those fronts.
Um, we also are able to provide schema level lineage so they're able to track the full history of that change, uh, the who, what, when, where, and why, um, uh, to ensure the accuracy of those models. But also, you know, you have things like the EU AI Act and NIST who are publishing, uh, regulatory guidance on ai. Um, so for the customers that are, uh, needing to achieve that, um, that compliance, we can help there too.
So that's a, a big problem in the market that we're solving today. Uh, we've also introduced, um, some new capabilities as well, uh, to help, um, some of, you know, the velocity our customers want through AI change log generation. So, uh, we had announced an AI change log generator, which was built on our 15 years of frontline experience, uh, which is really, really incredible.
I, you basically, this can describe it and deploy it, um, and it's done in the exact liquid base way you would want, obviously making, um, you know, a change log, uh, creation happen rather quickly and, uh, very accurate. And, and when you use that with Liquidate secure, uh, it's governed and controlled. So, um, we have some really, really exciting updates for our customers.
Excellent. Excellent. So you guys also announced in the same vein, uh, uh, an integration with Mongo MongoDB.
And, and look, MongoDB is a company that needs no introduction to our audience or anyone in tech MongoDB. You know, I, I still remember when I first heard MongoDB and the whole no SQL database thing. It's gotta be back in 2008, maybe, something like that, right?
Um, but you guys announced this integration and it, I think it it's around the AI governance stuff as well. Talk to us about that, Ryan. That's right.
So, um, MongoDB obviously is, uh, an incredible technology out there, and, uh, we built a strategic, uh, integration with them, uh, that brings AI governance down to the database layer. Uh, so teams can move fast with AI while keeping, you know, their data safe, consistent, and fully traceable. And I think, you know, the thing with Mongo is it's, it's great for fast moving teams that want to remain flexible.
You can shape the data however you need. Um, but the challenges as teams grow, things can drip. So fields, names change, collections evolve differently.
So that flexibility really needs some light structure so things don't go sideways. Um, and Liquidate Secure brings that structure in a way that doesn't slow anyone down. Uh, so on one hand, MongoDB stays flexible, uh, and then we make sure that changes are tracked consistent and safe.
Um, so we're really, really excited about what this means for, um, our customers using Mongo, um, whether, you know, they're supporting their gen AI applications, um, or whatnot. But, um, it's a, it's an incredible partnership and we're really excited for it. Um, we know that, you know, there's, this is a, a big problem in the market and we're excited to solve it with Mongo.
Very cool. Now this has already been announced and it's available to use right now? Yeah, That's right.
Yeah. So available on our website. Um, and, uh, you know, we, we just probably, we actually have a webinar coming up here in December that people can join to learn more about, um, this integration with Mongo.
And, um, we also have a bunch of content on our website that, um, folks can engage with too. Uh, that speaks to the integration a little bit more, but it's available today, uh, and we're excited for folks to start using it. We are too.
com, where do they get to the Mongo integration stuff off that, you know? Yeah, so we actually have, if you go under solutions, there's a, um, uh, an option just to select MongoDB, uh, so we have a whole page dedicated to it. Very cool.
Ryan, what about it's conference season? You guys been out anywhere or you going anywhere? Um, yeah, we've done like some local shows and things like that, you know, really, um, working with kind of smaller development communities.
Um, there's so much happening in the market though, um, you know, there is Crazy, it's noisy and it's crazy. It, It is. And, you know, sometimes these shows, um, it's, uh, it's, it's, we wanna go be with our audience, and sometimes these shows don't always allow you to do that.
Um, but, you know, I think just recently we're having a lot of conversations, um, with different engineering leaders on the CloudFlare outage, the app, uh, and the, the database permission change that took down, you know, a part of the internet and, um, You know, including some of the tech strong sites, I'm sorry to say. Right? Right.
And, you know, we're, um, it, it, I think it's a, it's a, eh, it's a big challenge that, that folks face where if they're not governing that foundation layer, you know, it, it can break a lot of things. The blast radius can be pretty significant, and a lot of companies don't actually govern database change. Um, and something as small as a database change permission can have a really significant impact.
So, um, now we help our customers solve this and, uh, you know, we're having a lot of conversations around this today. Uh, but we'll, well, I Mean, just so people know, right? This, this particular incident revolved around, I don't wanna say something is trivial, it's not trivial, but something is, you know, let's say down the, you know, from the very top of the kind of things you would think about, this really came about with a database permissions change, right?
That's right. I'm wrong. Right?
And, and, you know, this happened to one of the most resilient companies in the world, CloudFlare. I mean, think about how hard in their infrastructure is. Um, so no, most companies are up to that caliber.
And, uh, when you start to factor in things like AI and you know, how, how humans can actually keep up with, um, governing ai, um, you know, that, that makes that even worse. So, um, we are really helping customers close that risk. And in some, in a lot of cases, actually, uh, being a trusted AI adoption partner, we work with a lot of really regulated companies and they know the risk and they understand the risk of not governing, governing an a ai.
So, um, we support that. Excellent, man. Excellent.
Um, you know, look, that was this particular incident, Akamai was down a couple weeks ago for another incident that's happened to CloudFlare before. I think another thing, you know, just Ryan, that we, we concentrate so much in such a handful of companies, right? Think about the amount of traffic, the, the percentage of TRA internet traffic that goes through Akamai and CloudFlare together.
It's almost half of the internet. And you, you, you think about that, that's, you know, that says not quite, it's a double point of failure, if not a single point of failure. Yeah.
But it's something we need to think of in terms of supply chains and, and resiliency and all of these things. I, I couldn't agree more. I I actually think, um, there's gonna be more of this as there's more pressure on the database and more pressure on infrastructure, um, to the point where you could, you could make the case where it's, it will become a national security threat.
So, you know, if America wants to lead in, um, ai, well, we really have to look at our infrastructure and can our infrastructure keep up? Uh, can we have the governance at, you know, the database layer and some of those other critical infrastructure to actually scale with it? Um, those investments are critical.
Um, so it's, it's a exciting time. I think a lot of people are a little bit nervous about, you know, AI and adoption of AI and, um, no, we're here to support them in their, in their journey. Um, but yeah, what a, what a time to be alive.
Absolutely. Hey, Ryan, I gotta run onto my next interview. It's great seeing you if I don't talk to you before, have a happy Thanksgiving and hopefully before the new year and holidays we'll get back together.
Thanks, appreciate that. You have a great Thanksgiving too, and talk to you soon. Alrighty.
Ryan McCurdy, VP Marketing Liquid base here on, uh, liquid Base's, new AI governance capabilities, as well as their partnership with MongoDB. You're watching Text Drunk tv, we'll be right back. Alright, so ai, um, I'm gonna zip through some of these, but let me just frame kind of, uh, there's a lot of things happening in ai.
There are lots of different kind of, uh, places in the AI stack you can play what Traffic is doing. In a nutshell, because we are a runtime gateway provider, our value is in being able to address this problem from a runtime perspective on how we can allow customers to run AI workloads in an agnostic way. So they're not vendor dependent on the, the gateway, uh, part of it.
And we will talk more about that. Uh, but in essence, like what's happening in the AI world, there are lots and lots of models that are coming out, right? So part of the talk that we did this a while back was think beyond the model.
There's gonna be models everywhere, right? Like if you look on hugging face, I went there today and this number continues to grow. Like they're adding almost a hundred thousand models every month in hugging face.
2 million models. If you go to the Nvidia kind of curated model set, that number is about 200 plus. The point of the story is that models are going to continue to evolve and change.
Uh, you cannot hard code and you should not, I, uh, I should say hard code your application to a particular model. 1 coming out. Like if you hard code things to your model, you're constantly gonna have to go back and refactor the application to make the change.
So then that question becomes, well, okay, decoupling makes sense. Where do you do the decoupling? And this is where we believe that we should decouple at the gateway layer.
'cause that gives you the most operational freedom and the most operational leverage to be able to define the routing logic on which model that you wanna route this particular application to at the gateway layer. And it goes beyond just routing, right? With the, let me kind of zip through some of this stuff.
Uh, and I wanna in the interest, so I'll come back to this. So this is a reference architecture. You look at what happens when you are routing, uh, AI traffic routing is the last part that you do.
You know, whether this goes to let's say GPT-3 or sonet running in a WS bedrock or running in your local kind of, uh, environment or some other public cloud. But all the things that happen before you route the traffic, that's where the gateway really shines, right? The first thing you'll see is, uh, the authentication logic, right?
Just like we talked about with API gateway, you still wanna authenticate the user. You may need to rate limit them. Then in the case of ai, like you want to have these guardrails that say, okay, well this is not a, uh, not a accepted conversation with the LLM.
Like, your enterprises are putting guardrails in place saying, I'm just not gonna use the AI for everything. Or I have certain policies where let's say you define, uh, a finance agent and that finance agent should only be able to respond to finance type questions if it starts getting legal questions. You wanna stop that from even getting to the LLM So all of that type of authentication and security type policies and caching, by the way.
'cause you don't want to get penalized for the same question over and over again. There's no reason to consume tokens for the same question that comes up. All of that stuff.
You have two choices where to put 'em, you can definitely put 'em in the application. Like if you're just hacking something together over the weekend, makes sense. But if you're putting it in production, this is where you want all of that logic to be at the gateway, because that's what the gateway is known for, is designed to do that, is scalable.
It performs very well. And you as an organization would get all of that unified control and the observability on everything that's happening. So you route everything through the gateway, which, uh, sorry for the, maybe it's not coming out clear here, but if you look in the box in the middle that says traffic hub, and you look at from the application standpoint on the left, and let's say it's a rest call first is gonna get authenticated and perhaps rate limited.
There's a WAF in there too. If there's something you wanna block there, then you go through this LLM guard, think of this as a composable pipeline, okay. Of traffic just flowing through and it's just kind of acting, uh, in a chained sequence.
Then you would go through the LLM guard. And here we have done the integration with the NVIDIA safety nims. You know, there are three specific Nvidia safety out there today.
One is for topic control, one is for jailbreak detection, and the third one is content safety. It goes through that. Then you may want to take it through a caching layer.
And then you route, and even when you're routing, you have a bunch of different options for routing. 1 as their workhorse LLM model. 2 comes in.
The question is how do they absorb that change? How do they integrate that change into the environment? You know, if it's baked into the application, they gotta go back to the application and refactor it.
But let's say they have decoupled it and it's at the gateway. What do you do? Then?
You can do many things. You can do a simple one, which is a canary based routing. 2 and let me run that for a few days.
Let me take, collect some telemetry. Let me see how the, how the user experience is. That's one way of doing it.
There's two other advanced ways of doing it. You can do it based on identity based routing or time of day routing. And let's go through those in a little bit more detail.
Quick Question, with the routing there, can you inject transforms along the way as well? So if you are going to one model versus another model, you may wanna manipulate the system prompt in some fashion for that second model. Uh, We don't get into that.
So we can do header manipulation. We don't get into the body manipulation. Uh, and you'll see those are the kind of things that are gonna add more latency, uh, going through the gateway itself.
Uh, can it technically be done? Sure. But we don't get involved in that yet.
Okay. Uh, Saddi, can you back up just one bit? A guy Coer, uh, at Futurum.
Hi Mitch. Hey, um, so you call this an AI runtime reference architecture. Um, do you have a distinct one that, uh, includes the MCP gateway in it?
Yep. I'm, that's, I'm gonna show that next. Okay.
Because AI's AI means is pretty general. Yep. Should include agents.
Yes. But you're gonna have a new ano a second reference architecture to show us in a bit. I'm gonna, I'm It's called something else.
It Should be all one to your point. There should be one AI reference architecture that includes MCP, includes AI and also includes API gateway. And I'll show that to you in a second.
Yeah, I think there should be either be one or a hundred. So one one is good for, for this venue. Yes.
Alright, cool. There's an extra layer that MCP brings that I wanna introduce before I show you that. Okay.
Okay. Uh, that would make a lot more sense. Great, Thanks.
So I talked about canary routing is one way. Uh, let's look at identity based routing. You know, this is where, you know, there's a bunch of code here.
What really matters is you look on line 20 and line 28. 1. So this is where you can do identity based routing.
And everything I'm showing you here is just code, right? So this is just A-A-C-R-D or a YAML file. And all of this could be done through A-C-I-C-D-A time of day routing.
This could be another one that could be that. 2 into the model, but you don't wanna really risk it during your normal, uh, business hours. 2 after your prime hours, and that's what time of day routing does line 20.
Again, it's saying, okay, during prime hours, in this example, I'm showing you a different model. I'm saying, okay, send it to mytral, small off hours, mytral medium. So just pick your model, swap it in here.
But the concept stays the same. And there are many other ways to route, but these are, like the three that I showed you are the most common ones that you can route based on identity based routing is becoming more popular. I think canary based routing is the most default.
I think that's the most simplest to do. Identity based is more sophisticated, but it's also much more powerful and much more flexible. Customers have any interest in doing, uh, kind of performance based, like this is taking too long to respond.
Let's go. Yep. Back up.
Yeah. Model for, so that could be your standard kind of failover workflow where you try this, this doesn't work. Then you go to that and what you're saying is, uh, latency based routing.
Uh, so we have that in our roadmap, uh, where we can actually do it based on latency. Okay. And both in a proactive manner and a reactive manner, which means we could be, we could have sensors that always, there's measuring the latency, uh, between point A and point B, and you can set a threshold saying, I'm gonna route to this if I can predictably say the latency is gonna be beyond, below this number.
Mm-hmm. So those are some advanced things that we have in the roadmap. Okay.
And latency, I mean some, I I usually hear it referred to also to as performance based, meaning latency could just mean the latency of traffic. Yep. You know, or packets flowing.
Performance usually implies like, this takes too long to get a response or Yeah. You know, it has three retries and I'm not gonna let the bottle try at third time or whatever. Absolutely.
And that, those are exactly the things you wanna do at the gateway. Yeah. Okay.
Yeah. Latency is a, a prerequisite to that, but, but you're absolutely right. You use that as a base knowledge and then you build on top that advanced log logic.
Okay. Okay. So I zipped through a lot of this stuff, but, uh, I wanted to actually make sure that, uh, I shared this concept of, um, uh, the runtime environment.
You know, when you're deploying ai, uh, there's the gateway runtime environment that we all are familiar with, right? AI gateways. They represent the AI runtime environment, but there's the model runtime environment.
And the objective of the model runtime environment is to optimize for the inferencing to make sure that the models have high availability and high resiliency, right? Traffic doesn't operate in this, this is, you know, the task of kind of the, the other platforms out there that are giving you the ability to kind of stand up a bunch of GPUs and being able to get maximum throughput of the tokens and get maximum throughput of the GPU environment. Uh, and the LLM that is running, okay.
Traffic then takes over as soon as the LLM is exposed to the outside world as an API. That's where traffic comes in. As you guys all know, like all of these models are being exposed as A-P-I-A-P-I has become the interface.
And this is where traffic comes in and says, okay, the abstraction of that model as an API is what creates the need for having an API level availability. An API level resiliency. And this is where we come in.
Both environments are equally important. You run into problems though, when you try to embed them as there are some platforms out there in the market, I'm not gonna name them, but that try to embed part of API runtime environment into their model runtime environment. Um, and what you end up doing is, you know, you go with the least common denominator and you end up getting some functionality, but you lack in a, in some major ones.
So the three questions you wanna ask yourself to know if this is a limitation that you're running into, number one is can you freely share these endpoints with your developers through a developer portal? You know, just like you would any other API, you know, does that experience exist? And what you'll realize is no, uh, and if it does, it's very, very archaic.
Number two is, can you actually integrate with your, uh, identity provider for doing the API token generation? And I'm not talking about the token for the LLM, I'm talking about the, the API key or the jaw token that allows you to access the LLM as an API. And the third is like, okay, what kind of observability do you provide?
Uh, is it vendor specific or is it vendor neutral? So these are some of the challenges that you'll run into with this Saddi. Can I, can I probe a little on, um, on ai, ai, ai, API mm-hmm.
Um, you know, a but models as APIs. There's, there's, there's something a little funny sounding that to me. 'cause I, you know, I think of an API as highly structured writing re requiring a a, a structured and compliant or conformant, um, well formed, uh, a request mm-hmm.
Um, in order to operate best. Um, but if you think of a model as I, I remember how you put it, it's pretty clever on the, think on the next slide. Um, if you think of, uh, models, APIs as as, uh, Abstraction Yeah.
Model. Yeah. I mean, you know, uh, I think of an API request to a model as unstructured largely, um, you know, plain language, plain English, what have you, you know, a little chat, like it's a prompt rather than something structured.
But it's, uh, but It's, is this a semantic issue? A way for us to shift our thinking as, as to what we are doing? So there's parts of it that is highly structured.
There are parts of it that are unstructured. Right? The actual call that you're making to the LLM.
So let's say you ask what is the capital of us? And it response to you when you're sending that question in, it's going inside a highly structured JSON, uh, and, you know, wrapped in inside an API that's going to the LLM. And then the LLM is computing through tokens.
What the answer is. And that's coming to you, but it's also coming to you in a structured format. But the answer is gonna be variable depending on your question.
So essentially it is an API interaction, but the values are dynamic. Your question, you said highly structured, JSON, you, you that, you lost me a little bit there in the sense that Yeah, sure. The package might be JSON highly structured.
Hmm. You know, I, I don't know, like, uh, um, you know, highly structured JS os are like big complex, require a lot of validation. There's a whole, what I guess I'm trying to say is that the payload of that JSON is doing a whole lot of work.
Yes. And in conventional API needs to be done in a structured way. Yeah.
So there's, so I look at this as what's happening behind the scenes and what's happening at the interface level. Uh, to me, if I go into, um, so let's say if I do a curl command right from my machine to an L-L-M-A-P-I, I am doing it in a very structured way. It's, I'm always doing it the same way.
I'm passing it the same parameters. Mm-hmm. My question might change, but the way I'm calling it is always staying the same behind the behind the scenes.
What it does, what the LLM does with that is a whole bunch of other stuff that I don't see, but the abstraction of it to an agent, to a user, it's a standard API that you're calling. And that part has to be standard because otherwise Yeah. You don't know how to model against it.
You don't know how to code against it. You don't know how to integrate that into your application. So that part has to be standardized, which it is.
And that's what the API is for. This is a really useful semantic shift in my opinion. It's a really useful semantic shift.
I just wanna distinguish that from maybe a more technical question of, Hey, we're gonna transform your prompts into API requests, you're not doing that. You're not really changing that, but you're encouraging us to think about this in a different way. So I look forward to seeing how What I, what I think is interesting is when you're talking about inspection of the prompts mm-hmm.
And the responses that come back from those prompts and checking to make sure that you don't have someone trying to pull financial information when they shouldn't have access to that. Or they're asking for something that would violate policies that you have within your organization, being able to check those contents and look for prompt injection attacks and other things that a typical gateway wouldn't know how to search. Right.
Contents that way. 'cause it's looking at headers and other components of the JSON payload. Yeah.
And that's why, like, uh, so it's a great point you bring up. So what the gateway is really doing is what it does best. It is orchestrating when that traffic is coming in, it's orchestrating the set of checks that it needs to go through.
And by sending that traffic to endpoints that behave as a well understood API. Mm-hmm. So, you know, in the NVIDIA safety nims, you know, those three that I talked about, topic control, jailbreak detection, content safety, each one of them exposed themselves as an API.
So what the traffic API gateway is doing is orchestrating across all of them, sending them the user information, whatever came in unfiltered to them and saying, Hey, check this for making sure it's safe. Making sure you know it's the right use. Uh, making sure it's not doing any kind of gelb break detection through the prompt engineering traffic's not getting involved in that.
All it's doing is orchestrating and saying, Hey, check this. Mm-hmm. This, Hey, API X, check for this.
Send me a response. If your response is good, I'm gonna let it through. If your response says bad, I'm gonna stop it.
Is that filtering happening in parallel? So is it checking multiple signals at the same Time? Yes, it can.
So, uh, you can chain them in parallel. You can do linear, uh, you have different options. Okay.
Cool. Yeah. You had a question?
I did have a question. So I'm Gina from Digital Sunshine Solutions. My question is, um, the title of the slide says No, AI without APIs, but everything you've described has been generative ai.
So is, are we specifically talking about prompts coming in from externally, perhaps from a, a chat box that's on a window for customer support or whatever, um, going into an LLM? Or do you also cover, uh, more narrow AI situations, maybe, um, uh, just a plain type of agent that doesn't have the LLM behind it, but it's just doing some basic lookup or, or that kind of thing? Uh, so in all of these examples, there is an LLM, there is an LM component.
So an agent Okay. Has to have the intelligence of an agent comes from the LLM. Okay.
So, so this is just, so this whole presentation, or is your product is just about generative AI and not about other types of ai? Uh, correct. I mean, so we are, and also we're not just about ai, but yeah.
This part of the presentation. So what we offer is an API gateway, which can be, um, you know, manifested into an AI gateway because an AI gateway has a lot of the API gateway foundations, and it just adds the AI ness on top, like the extra stuff for ai. But it is still a gateway, which fundamentally means you have an input and an output.
Uh, so if I go back to this, uh, this diagram, you have an input and an output. The input is coming from the left, like you said, you know, it could be your chat users, it could be an application where they are trying to interact with an LLM with an AI model. And before you allow that interaction to happen, you wanna put a set of safety rules, right?
And that's what this is, right? It's a bunch of different policies, let's, let's call it, for lack of a better word. And that policy has routing logic.
The policy has safety logic built in all of that stuff. Got it. But it's not ai, it's just generative ai.
Right? Um, I mean, when I think of ai, I think of generative ai. Yeah.
Most people think so for me, like, you know, there, there isn't a distinction between the two. Okay. Uh, but, uh, you guys asked about some questions on MCP, so let's go there, right?
Because what's happening with MCP, uh, the, if you focus on the left side, MCP really comes in specifically for agent workflows, which means there is an agent trying to achieve an objective. And that agent now has to do three things. The agent has to talk to an LLM, the agent has to talk to MCP resources, whatever you expose, and then the agent has to talk to your backend APIs as well.
Traditionally, if you just have an API gateway in your architecture, you're not protected because you're only protecting one of the three kind of pathways. Typically, gate number three at the bottom is what most companies would have, which is an API gateway. So what it can do, it can protect the communication between an agent and the backend APIs, but it has no visibility or no way to control what the agent is doing with the MCP server and the resources behind it.
And it also has no knowledge of what the agent is doing with the LLM itself. So this is where we have introduced this notion of a triple gate pattern, where you need to have three different gates for your agentic workflows. Gate number one really is the agent is talking to an LLM.
And so you can control that with the AI gateway, you know, which we just talked about. The third one, the agent talks to the backend. API, you know, that's well understood problem.
This is your regular API interactions. The second one in the middle, you know, this is a little mystery, right? Because MCP is just coming to the, uh, into this, uh, you know, the party here, so to speak.
Uh, there's a lot to be understood here. Uh, it doesn't behave like our typical API, it has a new language, a new protocol. So how does the agent talk to these resources and how do you govern that?
How do you put in the set of rules and policies and stuff that allow that interaction? This is where the MCP gateway, this is the job of an MCP gateway. And so what we are doing at traffic is giving all of these, all three of these kind of capabilities in a single binary, because the last thing you want is a customer.
That's what I was, Yeah. Three different gateways. Yeah.
So, guy Ker again, future, I was just thinking this, which is, these are three names for the same thing. Um, it'd be three names for the same thing. Yes.
If you can come with a better name, like I would love it. But they are A-I-M-C-P-A-P-I Gateway. Yeah.
API Gateway, MCP edition. They are c they are three distinct capabilities that are typically not in the, if you look in the market today, it's very rare that you'll find all three of them in the same product. I just feel, I feel like the, the scope, let's call it the scope, or maybe there's a better word for it, differs among the three.
Absolutely. Be really helpful for you to point out that that sort of payload inspection, since we're working at the application layer, you know, the prompt is the application in a sense, and payload inspection and, and routing based on that. I mean, that prompt is, that's brilliant.
So I extended to, to, to, you know, um, uh, agent, agent and the agent agent and, uh, model agent interaction and stuff, the sort of thing. That's an MCP, that's a little bit more prosaic. MCP is a protocol, obviously that's in the name.
Um, but it has particular elements to it thanks to its connection to agent and everything. So, so all of these kind of need to do the same thing. But, um, what differs is, um, the, uh, the, um, the, the, the boundaries that you're putting on, Like you said, the scope.
Yeah. The scope is different for each one. I would describe it, I would describe it as like three different use cases you're controlling.
Mm-hmm. What models can agents talk to where you're talking about what resources can an agent or a model access through an MCP or MCP servers? And the third is what APIs can an agent use that go to a traditional API.
So it's, you know, first one is kind of what models can I use? The other are what resources through either traditional or non-traditional, right? Yeah.
So I think, yeah, no, this is, I would Describe it as like, use cases for, and your point is it's in one product, not two or three different products. It's just that when you put MCP or AI on the name, they can sell it better Always. You know, and I'm in favor of that.
So, and charge twice as much, You know, and, and in a agent workflow, you need all three of those, all three use cases come together. I'm not entirely joking that you can sell it better. You're positioning it for these different use cases in a stronger way than just saying that our a, our API gateway is MC bm CP capable AI capable.
I, I think it's stronger to, I I don't normally advocate for that sort of thing. Um, but you're, you're, you, you are broadening the positioning of what you do, and there's a technical foundation for it and technical proof for it. Yeah.
You know, you know what, you know what I mean? It's, it's, it's beyond a scenario. Your scenario.
Well, What's interesting too is that it's a, it's a, uh, an emerging market because you have a lot of different people going after the same parts of the same thing, right? You've got the Nvidia DGX clouds of the world, that that's more the tied to the specific hardware resources. You've got the vertexes and sage makers and Bedrocks who have, you know, a gateway for, part of a gateway, right?
Mm-hmm. For access to models and MCP servers. Then you have emerging agent control planes, which are also starting to apply some of the rules and guardrails, right?
Of some of what you're doing, not traditional APIs. And you're trying to position it as, yes, you're gonna need all those things. And do you want a different solution in the Google Cloud versus the A Ws cloud versus ad's hardware versus NVIDIA's, and then you have your traditional applications.
Here's one model or one product. Yeah. But one, one way of doing it that we'll work on all Those environments that abstracts it away.
That's your value product. Yep. Exactly.
One of them, right? Exactly. Yeah.
It's exactly. Everybody's fighting over this territory right now. And MCP really pushes the boundary of this because it forces you to think about this holistically, right?
You cannot think of this as a silo, because in an MCP architecture, like this is a reference kind of a high level reference architecture that you see the triple gate pattern working. Like, first you gotta go through the AI gateway, then you gotta go through the MCP gateway checks, then you go to the API gateway and your resources, the data layer where your MCP server and the resources are staying, where also your APIs are there. So you have to authenticate through these three layers for the different scopes that you're trying to achieve here.
So I think it's an argument to be made too, that while MCP and other open protocols are adding more security, needing to beef up their enterprise level security, that's gonna vary by implementation and through a gateway or one common gateway that you can now apply security rules and guard rail guardrails and things like that. Kind of, you can deal with the inadequacies of different implementations of, Especially if SCP servers, right? Especially if there's documentation behind it.
So if you have, and I don't know that there is, but if there's a way to, to have that observability where yes, we actually did have this communication pathway com, this is all that was allowed, and this is Right. I think That audit trail, That that's a big deal too. Yeah.
Yeah. 'cause if you're not having, if you don't have this centralized picture, then you're not gonna have centralized auditing or the observability in it. Okay.
Um, let's go to our last topic. Um, I'll just say a couple things here. It's really important to think about the runtime environment as being strategic.
Like how your customers design runtime environments are very important. Our recommendation is to decouple the API runtime from the model runtime, because the assumption here, models are gonna continue to change. So you need to bake that rate of change into your infrastructure and this one model to rule them all.
That's a myth, right? As we all know, like, you know, that's not gonna happen. You may have temporary advantage, but you're not gonna have long-term any, no model's gonna have a long-term advantage given the pace at which we're seeing things move.
Hi everyone, welcome to our special Thanksgiving edition of the Textron Gang. I know it's only Wednesday Thanksgiving's not till tomorrow, but we're not gonna be here tomorrow. So we, we, we bump things up a little bit.
We're gonna do Thanksgiving special today. Uh, you know, it's kind of a tradition here at the Textron gang. Uh, who am I getting?
We've never done it before, but we're gonna do it today. It's gonna be our first time doing it. Uh, we're gonna ask each of our panelists to give us, or each of our gang members to tell us what they're thankful for this Thanksgiving holiday, but we're gonna confine it to technology.
Well, otherwise, I think we'd go too far afield. So let me introduce you to our, uh, Thanksgiving gang for today. And they're, they're regulars here.
So they've all been around with us for months now, and you've probably seen them. We've got Chris Blas, who's celebrating Thanksgiving north of the border. We've got the one and only man in Silicon Valley.
John Swartz, our favorite Boston Cape Cod dude, Dan o Dan O'Brien, also from up New England way, Kate Scarsella, and of course, the dean, our chief content officer here at Techstrong. Mike Ard, gang members, welcome and happy Thanksgiving. And this is the official kickoff of the holiday season.
I can't, I always love the holiday season. I'll tell you the truth. It kind of just makes me think back to when I was a kid and, and a lot of good memories.
It has certainly been a year for the record books. There are things we can be, I think we all agree, things we can be thankful for, and, uh, things, things maybe we're not so thankful for. I did a series of articles up on our various text drunk sites, and then each of them, you know, geared to the specific community I put in, you know, four or five things I'm really thankful for.
And two or three things, maybe I'm not. Um, but let me, let me kick this off if it's okay, gang. You know, what am I thankful for?
I am thankful to be alive at this time of, of history where we have just so much promise and so much disruptive revolutionary tech related change that promises to change our lives and usher in, as I I I'm doing what my shimmy says later today, A Star Trek like future where poverty is eliminated and work for works work to, in order to make money is eliminated. We'll do work because we love doing what we do. All of this is the promise of ai, along with, if you want to call it physical AI or robotics, along with other macro things like maybe quantum technology.
Man, hey, we could have been born in the dark ages and getting hung up for saying the earth goes around the sun. But here we are. Here we are when there's so much at our fingertips.
And the question is, are we smart enough, mature enough, bold enough to handle this correctly and, and, and bring this baby home? Or do we crash and burn? And, and make no mistake, there's, you know, there might be some crash and burning, but I'm an optimist and I just, I'm thankful to be here at this juncture in history.
Guys, what are you guys and gal, what do you think? Well, I'll Tell you great time. Yeah, yeah, go ahead, Mike.
I'll say though, you know, there are more mundane things to be really thankful for. And, and I'm only bringing this up 'cause we're all dealing now with this, uh, second coming of the shy Hulu attack, and, you know, all those cybersecurity people who like, do all this work and kind of, you know, come in and rescue us. And, you know, many of them will probably be working on this instead of having their Thanksgiving dinner somewhere with their families.
And they do this stuff every day, and sometimes they do it in ways that we never even see. And it is unfortunately thankless work, but it is the work that kinda saves us from ourselves. And I know, Chris, you're close to this community, but, you know, do we not spend enough time thanking these people?
They deserve that. I, I think the community is, is, is, uh, it's very healthy, right? I think we're really good for each other.
The cybersecurity community, I think is one of the better. You know, obviously I, it's what I've spent most of my career in, but we're pr pretty good at making sure everybody understands, you know, they're, they're wanted and they're welcome. Right?
And do we hear it enough from the outside world? I don't know. I I, I mean, we're a, a neuro divergent pack of, uh, crazy people.
I think we mostly need to hear it from each other, and we're, we're pretty good at that. So I'm thankful for that. John, you were gonna say something?
Oh, I was gonna say, I mean, so today, for instance, uh, Google's about to go for $4 trillion in market value. Okay? So that's like a news item.
But amid that, amid all the hype and hyperbole, as you said, I think you said it really well, Alan, there are so many things that we should be thankful for, including some of the things around ai. com explosion. And I'm kind of thi I'm thankful for it because it, it's making me think about all sorts of different vertical markets and the things that could happen, or the things that are possible that are gonna benefit us.
And I'll, I'll mention that later, but, um, I just think it's a great time to be around is there's, there's so many interesting things going on, and it's happening every day. Daniel, You are shaking your head. Dan O'Brien.
Hold on a minute. I wanna follow up on John's point there. Um, Dan, I'm thankful for all the money that goes in the fund, this stuff, but I'm not sure where it comes from.
So maybe you could explain. 4 trillion in open AI versus the $23 billion revenue. Yeah, that's, uh, that's totally scary.
But I'm thinking about the end results, regardless of what happens to those companies. Um, I'm thinking of a long-term results, uh, short term. It could be pretty scary.
You're right, Mike, Dan, where does all that money come from, and who do we think? Yeah, I, I, you know, I, I guess I'm thankful for competition. Um, you know, I think we're, you know, in the early innings here of the next big tech revolution with ai, you know, probably the biggest, you know, probably since the internet boom.
Um, you know, to, to the point on where the money comes from. You know, I think what makes me feel good about where we are in the cycle is, you know, up until very recently, it's largely been the free cash flow of the largest, most successful companies in the world that have been funding this, right? I think it's gotten a little more creative of late, um, you know, a little bit more speculative, a little bit more circular financing.
Um, but, you know, I, I think I feel pretty good about, you know, kind of the sustainability of the cycle here. But, um, you know, back to the point on competition, being thankful for that, you know, we're, we're, like I said, early innings into this, but when this first kicked off, it was kind of open an I open AI and Nvidia, right? It was a really narrow set of companies we were talking about.
And, you know, with Google and what they've done with Gemini, their TPU infrastructure, a MD on the rise, you know, Intel maybe starting to get to the point of challenging TSMC, if not for wafers, at least for packaging. Um, you know, anthropic, you know, doing really well. I think we're seeing, you know, the number of winners continue to grow and grow, you know, up and down the supply chain.
I think, you know, competition is good for innovation, um, that's gonna make the cycle more sustainable, and then it's gonna make it more efficient as well. So, um, that's what I'm thankful for. And I'll just say, um, I'm with Alan here.
I'm not only an optimist, but I have become this Pollyanna, and I am loving this time period, I'm so happy, truly, that we are, um, embracing ai. And I think in the beginning, you know, we were somewhat concerned. You know, we, and, and it's not that we shouldn't be concerned, of course we should be, but I am happy that people are, are saying, okay, you know, it's here, let's embrace it.
But the same time, many of the cybersecurity people, you know, back to Chris, I mean, really, it's, it's, we also are understanding that we need to secure it. And I, it is not gonna be, you know, a decade before we're looking at the supply chain and everything else and saying, oh, golly, you know, software does have, uh, does have some vulnerabilities here, you know? And so we're really looking at building security into, um, I think anyway into AI as we move forward.
We understand that, that, um, that this matters, that this is important. So I, I, I think that security, I'm happy that it's being a part of, of DevSecOps is really gonna be a thing. It's, it's here, it's Here.
And I wrote exactly that, right throughout the articles I did around Thanksgiving, is that security has taken its rightful place at the table in most organizations and most industries, all right? And that's been a long time coming for people like me, you and Chris who've, you know, been in security all these years we had and kind of shouting in the wilderness. Yes.
But guys, let also return to my, my point about, make no mistake, the tech industry is the tip of the spear when it comes to this revolution, when it comes to this AI enablement. And, and I think we, we don't, don't downplay robotics. What Elon said about robotics is a hundred percent true, but the tech industry's at the tip of the spear.
We're leading this, we're feeling it, right? A lot of our friends have been laid off. I know a lot of people looking for jobs.
The tech industry is probably out in front in eliminating low hanging fruit type of jobs that AI can replace, or agentic AI can, can replace. And security is, is in the crucible, right? Trying to use AI to protect against AI enabled threats.
But we're doing it and we're aware of it, and we're trying the best we can, as we usually do. But the ripples of this are going to be waving, you know, rippling throughout society. It's going to hit medicine, it's going to hit law, it's going to hit accounting, it's going to hit name your, your, your profession or your livelihood.
It's gonna have an effect throughout society. And I think being that we're kind of the first we're out in front of it, hopefully we'll be in a better place to help as this wave, you know, works its way through humanity. And, you know, I wish I could tell you I'm, I would like to see what 50 years from now looks like, right?
Do we have a, a zein Cochrane breaking the, the, uh, warp barrier or something. But even the next 10 years, 15 years are gonna be exciting as hell. And the only thing I I'd like to add, and sorry, Chris, I'm jumping in here, is back to, um, John's point about this vertical industry and, and where things are going.
I actually believe that there's gonna be a collapsing of vertical industries, and it's gonna be more, uh, level horizontal because there, everything's gonna be integrated like we've never seen before. You know? Um, and especially, you know, if we just think about health and technology or, you know, our smart buildings and energy, all this is gonna be just massively just one big, um, network of devices and integration.
And I, this is an exciting time. I, Chris, I am thankful that we're putting humanity back in technology, right? And then let me, I'll go all the way back, you know, 5,000, 10,000 years ago, we took the words we had, we had developed between us, and we started writing them down and trying to make them physical artifacts.
We spent the last hundred years and 50 years of digitizing it. And we have our, our, our technology talks back to us now. It talks with us.
We have conversations, right? And this forces us down the path, you know, and it's interesting, as you're all saying, we are in a bit of a crucible right now. Lots of pressures.
Well, pressures drive evolution, right? You know, the systems we've been building, whether they're the digital side of things, supply chain, security of security at all. We have been talking for decades, you know, slightly longer than my career about how we do this.
We have not yet done all of it. I think we have to, I think we're doing it right now. I think we're taking the stories that we've been saying and turning them into technology, and then talking with the technology.
We're looking at things like narrative risk management, right? Actually, your story, the story that we're all part of, not the digital parts. Those were enablements.
But who are you? Who are we as organizations? How are we communicating each other?
What stories are we tying each other together with? There's, there's an aspect of the, of humanity in this hyper technical, uh, uh, uh, crux we're going through right now that I think is just intrinsically beautiful. I think it's a wonderful thing.
I think it leads to the opportunities, you know, and Dan, you know, whether it's the kind of things you're saying or or Kate, what you're saying, each of these enable us to be better humans, you know, sharing stories better. I think it really does come down to narrative. At, at the end of the day, we are finally out of the ones and zeros, and we're speaking in words.
You know, I, I wanna jump on that for a second, Chris. When you boil it down and you look at sort of ancient civilizations, I don't know how many of you ever took anthropology and school. I was a political science major.
They made us take anthropology. I, I had a chance to take some anthropology. Um, but when you look at early human civilizations, the role of the storyteller is a key function, is a key.
The that key person in the human tribe. And oftentimes the storyteller was a traveling storyteller who went from tribe to tribe, right? And telling these stories.
And, and so that, that common thread runs through multiple tribes and humanity. And here we are, all these tens of, you know, I don't know, depends who you believe. Tens of thousands, thousands, hundreds.
I don't care. All these years later, it's still about the storyteller a bit, isn't it, Chris? For you being able to talk to an AI and, and be that storyteller is, is something you're thankful.
John, your, you said it chronicling this age, right? We are the storytellers of this age, The Irish call, those people Bards, Excuse me, I said Bard Irish, call those people Bards and have called them. It's okay.
So we, we'll call you Bard Baard from that one. Speaking of Irish, Mr. O'Brien, what do you got?
Yeah, no, I, i, I, I totally agree with what you're all talking about on kind of the humanity side, coming back into tech. I mean, you know, it, it feels like that's, you know, kind of necessary as we increasingly interact with, you know, machine intelligence for, you know, it to become a little bit more of a true and better kind of representation of ourselves, right? Um, you know, I think it's a really great point Chris made there, and totally agree.
So let me tell you something though that I am hopeful for, alright. Three or four years ago, I can remember sitting down and having conversations with, you know, even my own kids in their twenties, and they were pretty down on just about everything. They were basically looking at boomers and saying, you know, you guys messed up this planet pretty well, and now if we can make all this AI stuff come together and this quantum stuff together, and hopefully, you know, it works out as planned or as they say from, you know, Alan's lips to God's ear, we have hope, right?
We can fix a lot of things that, you know, are issues that were persistent, and we might, you know, be able to do the r and d work at a level of cost that could, you know, make things a lot better. That said, you know, that road the hell is always paved with those good intentions. So we need to be careful.
But, um, you know, the some positive is greater than the negatives. Yeah. Yeah.
Mean, I had the same, I had the same conversation a couple different directions, right? I mean, you could easily see quantum and AI taking us into the next golden age. You could easily see it enabling some horrific dystopian future, right?
I mean, I think that's where the, the humans involved, you know, really just need to, you know, shape it for the common good in the right direction. Yeah. I, I as a, as a tech community, right?
You know, you out there watching, you're all somehow tech enabled business folks, whatever. We geek out on this stuff. I'll say, I'm, I'm at my age at 60 years old.
I'm thankful that I'm getting to see so many questions answered. You know, how do, how do, how do we work? Who am I?
How does this brain thing work? How did it get here? All you talk about anthropology this year, I've had a reason to look at human evolution and mammal evolution.
How did our cognitive system get here? And it turns out we're literally in this year, in this time, we're going through the process of exercising this at global scale and tech, because it's the same bloody thing. You cannot brute force this.
You can't take an infinite amount of information and just digitize it. You have to make semantic narrative compressed social, cultural, civic systems out of it. And everywhere I look now, I see business systems and technical systems that we're used to seeing as cold and impersonal, and because they have been bending back towards people, because that's better, faster, cheaper.
That's why we're wired this way. And I think the, the arc of cynicism in our, in our lives and our, our generation is bending. I really think technology goes back towards people.
You know, there's interesting thing about AI during your discussion made me think about this, this, this kind of greater narrative. Before tech was always criticized. There's rightfully criticized for doing all these incremental apps, these little, you know, kind of silly things that would help you, you know, have your car washed while you went to the theater, right?
You'd leave it and have somebody take care of it. But, and, and the criticism was that tech would never solve big problems, or it was averse to solving big problems. And I think with ai, actually conceivably, we could see, I'm not saying we're gonna see like a Hoover Dam or Moon Landing equivalent, but I do think we're gonna see significant inroads.
I think Mike alluded to it, in terms of affordability, in terms of things like housing, um, healthcare, et cetera, uh, poverty, uh, uh, uh, confront confrontation. I think there, there are these things that we could possibly do. I mean, it's gonna be a rough road to get there, but I am optimistic about them.
Absolutely. Hey, I'd like to take a, Kate, we're gonna come back to you. We put, we're 20 minutes in, we're gonna take a break.
And then, you know, I set the tone for this first one. But Kate, Dan, I'd love to hear your kind of tone setters on what we're thankful for and, and continue the conversation. You are watching Textron Gay, You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included, that work your protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. 0. You know, I've spoken about this before.
If we look at the Renaissance and the Enlightenment period on how, again, it, it collapsed vertical, and we started to see art and architecture and science and all these things sort of come together. 0 that we have entered, and the, um, everything that's gonna come of this, I, it's ex this is an exciting time. So, absolutely.
Well, you know, think, think about using these systems to see what makes sense, right? We talked about this last week, and protein folding is having me think about this. Go to notebook, lm, take some huge topics, some huge pile of texts, throw it at it, and have a talk back to you and explain it to you.
And this is called semantic analysis. I see people, uh, just myself and the people around us, we're just figuring this out this year as we're going through this. But that's why, as, as humans, we look at these systems and say, that doesn't make any sense.
And why is it like that? And we come up with these ideas. Maybe it's a big conspiracy, but mostly it's because there's other humans inside these systems and they can't see it all at the same time.
They're just telling their story about this one part of it. None of us can see the size of these systems anymore, but AI can. Yeah.
And we can have ai, as you're saying, we can point our semantic tools at these big, huge, complex problems everywhere. You know, it may be a huge problem to you, though it's a small part of some municipal something. And you can say, make sense of this.
Tell this story back to me. Look at the information out there. What is the narrative?
What are we saying? What does it say to me? And take that story and show it to other humans, the people responsible and say, see, you're here.
You didn't even know you were there. And I think, you know, and Dan, everybody said things that make me, make me think you're right. I think we can be reasonable with each other over the next several years in ways that, that, that were just callous to not think and work by just explaining to each other where we are and using these tools that we, that we think of as technology.
But they're really story, you know, story shaping. Chris, there's a, a phrase I've heard that I really love that that goes something like, you know, the future of decision intelligence is simulation. And I think that's a little bit kind of what you're getting at here in that, you know, we have so much compute power and so much information that we can kind of ask before we go do and get a really good sense as to kinda what we can expect, right?
It's never gonna be perfect, but, you know, we, we can do a lot of really low cost rapid experimentation before we go mo mobilize people, assets, capital, et cetera, you know, on kind of exploring what might work and what might make sense. Mm-hmm. Yeah.
Alan, Alan, you mentioned Elon Musk earlier. And, and here's the question. I'm kind of, you know, he was talking about, um, you know, the economy fundamentally changing.
And as I ponder that theoretically, you know, if I look back at whatever economic model it is, it's always been based on the notion that there's a scarcity of something and there's demand for it. Well, you know, are we on the cusp of getting someplace where, you know, scarcity of something is no longer an issue because we can use AI to, you know, make more food or make more whatever it might be. And there isn't gonna be this kinda economic model based on scarcity, and the world will change in ways we don't think.
So. This is exactly what my shimmy says is on later today, Mike. So I think we've got a fundamental question, though.
And, and before I hit that though, let me make clear, it's not just AI that Ellan is, Elon Musk is talking about. It's, it's AI empowered robots mm-hmm. Who are gonna make work not necessarily or optional for humans who are gonna eliminate poverty and, and plentiful.
You know, he also says it'll a little eliminate money. Now, okay, this sounds a lot like Star Trek to me, right? I'm sorry.
It sounds a lot like Star Trek. And the problem is, is if you remember, I don't know how many of your Trekkies there was that period before Warp Drive came in and the Vulcans, you know, discovered us, so to speak, where Earth was sort of, uh, it was, there was a post-op, a post-apocalyptic war kind of setting where, you know, we were living in, you know, it wasn't, it wasn't all unicorns and rainbows, let's put it that way. And my, my fear is, you know, Elon Musk kind of strata or vision here, w to get to that end point, there's gonna be some pain, there's gonna be a lot of disruption.
And, and then all of us here waxing philosophically and poetically about what a great AI future is. I think it would be wise for us to recognize there's going to be some pain. Mm-hmm.
Disruption, disrupt. We're going through some of it right now. Yeah.
Yeah. Disruption disrupts like from the Greek disruption. But, um, you know, and there's gonna be, there's gonna be some uncomfortableness and some pain.
And I think how we respond to that says a lot about who we are and as a, as a, as a civilization, as a species, right? Because to get, you know, invoke Martin Luther King to get to the Promised Land, right? I've gone to the top of the hill, I've seen the promise land, but he never got there.
And it's going, there's gonna be a, a valley in between here, and we gotta figure that out. Can I tell you my great Star Trek pet peeve? So in, in this alleged future, there's no need for money.
In every fifth episode of Star Trek, next Generation, what are they doing? Playing poker? For what?
There's no money Just to win, just to win. There are people who play poker for not real money. That says a lot about you, I think Mike.
Alright. Hey, but we, I feel like we didn't give everyone a chance to say what they're thankful for here. We got off on this AI tangent and how great we're all gonna be, but Dan O'Brien, come on man.
What are you whatcha thankful for? Uh, I'm thankful for community. I mean, I think we've touched on it a in a lot of ways without calling it out directly on the, uh, on the conversation here.
But, um, all of the things we're talking about are only enabled by an enormous amount of people, companies coming together, working towards, you know, some kind of common vision. And, uh, you know, I I think I just want to take a minute and stop and appreciate, you know, kind of the community that needs to come together to enable all of this stuff because it's, it's no small feat that any of this stuff works, right? It's, uh, it's a lot of good intentions and a lot of hard work from a lot of people to make this stuff happen.
Mm-hmm. Agreed. Dan's point.
I'd also like to thank all the storage engineers 'cause I don't know where we're gonna put all this data, but they gotta figure it out. Storage is cheap. That's what they keep ding us.
But, but, but you know what, I, I wrote another article that's out, I think, uh, today, or if not, it'll be off Friday. And that is, when we talk about the community, there are some, you know, from my Boston friends, there are some wicked smart people up there, not just in Boston, but all over. There's some wicked smart people who work on these amazing technologies.
And whether they're born in the US or they're born in China, or they're born in Europe, or Africa, or Latin America, wherever they're born, somehow this tech industry has a way of, of sucking 'em in and, and amassing them in a critical mass where this community can do the crazy, outrageous things that it, it's capable of doing. To your point, Dan, right? It it does, it takes a, not just a community, it takes a whole world Yeah.
To develop that kind of creativity, intelligence, you know, to even contemplate and make these things real. And, and I think we, we need to acknowledge that, right? And, and need to be and celebrate the people who, who, you know, are the creators and are the people who, not just the creators, the entrepreneurs who risk everything, starting companies, the people who build these things, you know, all the way down to the, the security people who are making sure the, you know, critical infrastructure stays up and everything else.
But it really does take a world, not just a community. It takes a world. It's bigger than any one of us or any one country here.
And I thought I was gonna be the only cheesy one, Dan, so, thank you. Thank you. Uh, look, Che's, my middle name.
I'm good for you. Well, Yeah, I thank you. Thank you all for the cheesiness.
Yes. I, I, I will take the cheese all the way down through the bottom of the text. I think we're there, right?
Yeah. I think most of us don't understand this. I'll, I'm thankful that I'm gonna spend the rest of my life saying, I told you so that intelligence is relational.
That it, that, you know, we we're talking about, you know, I ident super intelligence. That's not a thing. Turns out intelligence is a relational semantic thing that's about the size of a human being, and it can't ever be bigger.
Right. You know, that, that a pure, you know, computer, you know, get a couple AI talking to each other with, with no context whatsoever. And it peters out.
There's nothing there. Everything, all of this, you know, these from the skyscrapers and the technology and the big things and the small things we build are, because we're individual, human intelligence is relating to each other. And social contextual environments, as hippie as that sounds, that's it.
And that's literally the way the technology is working more and more every day. You know, it's, you can call it emergent or whatever you like, but it's not about the bits and pieces any more than we are because we built it, and neither are we. Right.
You know, this is, it's, you know, and, and, and as the, as the oldest Gen Xer, you know, born in 1965, right there on the edge as far, you know, as far as the, you can see it. To see this wave of sort of losing our base, losing our, our culture, losing our religion. We even made a song, if you're old enough to remember it, and coming back to the fact that, that, no, it's not just an a cold, impersonal universe.
It's personal. The technology doesn't even work any other way. That's how information systems work, because that's how humans work.
I'm sorry, I'm ranting at this point. I'm gonna put a flower behind my ear and go, no, but, But, but to your point, point, multiple types of AI models, right? Then it's not just gonna be this generative AI stuff that we're all obsessed about, but there's this whole new conversation around these world models, and there's gonna be different ways of building out ai.
And there's causal AI out there that's really still in its infancy. So, you know, we're kind of just at the tip of the proverbial iceberg here, Chris, to your point. And, um, I'm not sure it's all relational.
'cause you know, part of my soul might say that that was confirmation bias on your part, but it's gonna be fun. It, it may be, but, but again, what is a world model? It's like, I am here, the, the world's around me.
How do I relate to it? That's how mm-hmm. Systems actually just work.
Right? But, but Chris, you hit on something. Mike, you, you, you mentioned it earlier too.
Look, just knowing what I know from the six of you, Dan, you probably have the youngest child among the six of us. Think about the world. Your daughter grows up and not, not the Gen Xs.
I'm, I'm the end of the boomers. I'm cus just at the end of Boomer, right? You're just at the end of Gen X.
Mike's right there. Um, you know, we, we've we've had a run. We've had a run, right?
But Mike, as you said, I think the four years ago, a lot of our, my kids who were in the, at the time, in their late teens and twenties were a little, little, uh, perturbed about what we were leaving them here. Debt. Mm-hmm.
No doubt. Blue, little blue pills and, and not much else. Right?
But I, I think, oh, just in four or five years, there is a lot of optimism there. And, and look, it's, it's not all rainbows and unicorns, as I said, for kids growing up today. Who knows what they're gonna be when they grow up, grow, grow up, who knows what they're going to do for work.
Will they, we, will we eliminate poverty? Will they be able to buy houses and take care of their families? And I mean, I mean, there's a lot to be thought about, but I, I think they have a, a, a more promising future.
Right? And that's always been part of the American dream, right? The next generation does better than the generation before it.
And I think, you know, Dan, I hope your daughter has a, a better future than, than we did. And all of our children. And I, I, you know, it's good to be optimistic about that again.
'cause I think we weren't for a while. Mm. I had the same conversation, Alan, that you, that you had with your kids and Mike had Yep.
With his kids. And that term, that sense of kind of doom or gloom and just like we, you know, thanks a lot to my generation for passing this on to us. But I think you're right.
And maybe it is we're kind of at a, a genuflecting moment or a turning point where we start seeing some of the benefits and across the board. And, uh, maybe it's gonna start happening like it did in New York with your new mayor, with a new mayor. Um, we're starting to see a total mind shift.
And this is, this is good. This is progress. Things change and we have to adapt to it.
It's Their thing. What they All about embracing the change. Yeah.
I mean, back to the point earlier, yeah. I mean, uh, there is an enormous amount of change going on and, you know, that will be painful for some. But I think, you know, the secret to making it productive for you personally versus making it painful is this is too big a change to fight you.
You know, if you go with it and you lean into it, you embrace it, there's an immense amount of opportunity out there. Um, those who fight it, you know, I think those that'll, that'll probably experience the pain the most. But, you know, we've all got a choice, you know, in, uh, kind of whether we embrace and whether we lean in 10 years from now.
Alan and I are gonna be sitting on a park bench though, going, yeah, these kids don't know nothing. They don't know. They didn't have to show up for work.
10 at 6:00 AM at the, Could be next, next year. Mike could be next year. Next year.
Yeah. Well, no dear daughter. To all the kids out there to amel out in the world, and Tariq, you know, when I was a kid, I was told that, you know, the world's gonna end.
We're all gonna die. I'm not gonna grow up, blah, blah, blah. Right?
You know, we, you know, we remember the seventies, right? And for a number of reasons, I decided that no, there's other stories that might play out. I'm playing a role in one of those stories.
And I'll tell you what, that's the way the world turned out. Now, there's a lot of stories we may be part of now where things work out really poorly, but there's a lot of stories where they turn out really well. I'm telling you, you're all part of the story that can turn out really well.
Everything we've talked about here could work out to our benefit in ways you can't imagine. Will we have problems? Yes.
Otherwise life would be boring. You know, Alan Willerby be hardships and bump bumps along the way. Yes.
Buckle up. Um, but there always were, and the opportunities going forward are amazing, and some of them will come true. Absolutely.
I I sincerely hope so. All right. I'm going to pass it around one last time here.
Anything else you guys are thankful for you wanna bring up to the audience for today? I think we're gonna live longer. I think because of science and research and ai, we're gonna live longer.
Um, we're gonna improve drug discovery. I think it's been proven. I think ai, drug discovery and biotechs reduce development time by 40%, cut cost by 30%.
It's gonna save lives, it's gonna extend others. There are cameras and sensors in patient rooms that detect when a patient's turned over in bed and alert folks so they don't fall out of bed. Um, their, uh, doctors are using these guidelines of evidence-based research and treatment guidelines or accelerating diagnoses, minimizing errors.
I mean, I just think, um, especially in healthcare, and I think about it because I'm over 60, uh, health is everything. And I think about where this is headed, and it, that actually makes me feel very, very positive. I'm thankful, and I agree with John because it might be like, at least, you know, through the end of the decade before the World Series is won by the Yankee.
So I kind of wanna So you can live longer though. Yeah. Wait, yeah.
Amen to that. Amen to that. Yeah.
Well, let me, let me, let me wrap a bow on this first us first of all, things that I didn't mention that I'm thankful for. I'm thankful for doing the Textron Gang every day during the week here, and with my great friends and all the gang members, not just the five of you on with me today, but everyone who's been on the gang this year, we have an amazing group of pundits, experts, friends who come on here and we talk about whatever the issues of the day are or whatever Mike writes up into the, into the daily what's on the gang today, uh, script. And it, it, it's cathartic for me.
I love doing it. I love talking about these things. I love sharing it with, with all you.
com. Who would've thought DevOps 13 years later, security and everything else. I'm thankful for my fu brethren, right?
We're part of fu and it's a, it's good to be part of a bigger organization that does big things and deals with, you know, bigger companies that are truly making some of what we're talking about here happen. So thankful for that. Most of all, though, I'm thankful for everyone who watches us, reads our stuff, listens to our videos.
I don't know sponsors who support us and keep the lights on here. We couldn't do it without each and every one of you. So on behalf of Techstrong Futurum, happy Thanksgiving, everyone.
Have a great day. Discover Techstrong group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way. With Textron Group.
Hey everyone. We're back here at CubeCon. Uh, we got a little bit more to do here on our day two coverage.
My next guest is named Ari Zilker. I hope we got that right. And Ari's company name is My decisive, My decisive.
You may not have heard of my decisive, my decisive or Ari, but hopefully by the end of today or the end of this interview anyway, you will. Ari, we Ari, before we talk, uh, before we discuss my decisive mm-hmm. Let's, let's have a little discussion kind of, you know, give us your journey to being here, you know, at my decisive.
Sure. So My Decisive is a proactive operations product. Uh, I got to my, to the ideas and founding this company 'cause I was one of the general managers at a little company called New Relic.
Sure. For five years before that. Before that I was a general partner at Coastal Ventures.
Sure. Then, uh, working backwards found, helped found Hortonworks and then helped start terracotta, eh, cash before that. com.
So I'm old enough to remember most of those. Right. Okay.
Look for those, for those kids out here. Right. Horton Works kind of defined the big data, right?
That was the big data. Absolutely. Uh, age.
Yeah. With Horton Works, which was a spinoff from Yahoo. Yep.
Correct. Yeah. And, um, interesting stuff.
Interesting stuff. Indeed. New Relic has had a, an interesting also story of, you know, look it, it's rode the waves of this market from a PM to observability to, you know, a lot of different things.
But, you know, it, it, it affords one a real, uh, opportunity to, to yeah. See what's in the market. Um, every founder I've ever spoken to, there's a passion for what they're doing.
Somehow they think it's, it's gonna make the world better, even in a small way. It may not cure cancer or, you know, bring world peace. Mm-hmm.
But in some small way, it's gonna make someone's life better. Yep. Talk to us about your passion.
Um, easy. I have a passion for what observability folks call root cause. Um, I'm also a scientist, a traditionally trained engineer, Uhhuh.
And I'm frustrated with the observability vendors of the world saying this AI or that ai, and now I could do root cause, no one could do root cause. Uh, there's a difference between causal relationships between events and correlative relationships. And I'm not gonna get into the math of it.
I'll just say that I believe that we could do what the customers and the market needs, which is to bring in AI to help it run more smoothly at lower costs. Mm-hmm. But I believe that the answer is not incident response through LLMs and through ai.
And that root cause is the wrong question. It's when you ask a CTO what takes you down the most, humans take me down the most. So instead of root cause, why not go after robotic change?
Let the system change itself. We don't break it. We bring in the genius chemical human brain to do root cause with analytics tools.
Okay. But we don't try to get robots to fix systems. I love it.
Let's, um, so you, I think you really frame the problem and the potential solution, no disrespect to you, but all of the boots around us here, and they can't see, they only see this. Yeah. A lot of boots here are promising a lot of solutions.
And, you know, they throw in a little AI snake oil, a little MCP here, you know, and, and, and agentic there and mm-hmm. And we're gonna solve your problem. Yep.
Why are you different? So look, I recognize, Alan, we're swimming upstream against what you just described. Why we wanna be different is because we recognize from our insider seat in observability, the, the signal's not in the telemetry data.
There is no signal. Like you deploy an app in a database and the app starts crashing. There's nothing in that data.
And every observability vendor knows this that says it's the app or the database roll back. The one and the other will heal. That data's not there.
All we have is some CPU information, some URLs being requested and you know, a little bit more than that. Some Kubernetes and infrastructure logs. There's nothing that says, oh, fix the app and the database will calm down.
So why we're doing this, why we're swimming upstream is because we know it's techn technologically Correct. What we're doing. Okay.
It is principled approach. Mm-hmm. Uh, why we're willing to swim upstream against the AI claims is because we can introduce AI the right way.
We Can basically, 'cause ultimately you think it's the right thing to do and it's gonna be born out. Yeah. Basically, if you make the changes with the robot, then you can easily ask, was this a good change or a bad change?
Whereas if you're looking at steady state operating data and say, did I just go unhealthy? That's an impossible question to answer. Maybe this is normal.
And I've heard too many customers say, I deployed an AI and my traffic doubled. And it started rebooting me because it thought this was an anomalous situation. But I was handling that traffic and the AI took me down.
And so, because I know that humans are gonna be in the loop for the next 10 to 20 years, because I know that change is an easier problem to tackle automatic change than automatic incident response, I'm willing to swim upstream. 'cause I think we'll win. Fair enough.
Let's talk about observability for a second. Ari, you've been in the observability sta space. You've been in the big data space longer than that.
Yeah. Quite frankly, the problem with observability is it was, is fundamentally the big data issue. For a long time we had too much data to kinda really wrap our heads around, analyze and come back with actionable intelligence.
Mm-hmm. With things like AI and, and other improvements. It's not, you know, AI is just the latest Yeah.
And greatest maybe, but, you know, over the years with machine learning and what some says AI anyway, but Yep. Machine learning other ways we've, we've been able to tackle that big data problem. But In tackling the big data problem, you know, it's the, the, the theory of constraints.
Right. We solved the big data problem only to find out bigger problems. Sit behind it.
For many in observability, that biggest problem is my God, who, who can afford this? Mm-hmm. Right.
To to to really, now that we have the ability to analyze the data, we want to keep collecting more and more data. The more data collect we collect, the more our costs go up in Yep. Storing the data, analyzing the data, reporting the data, and it, and it's like, it's like an old Star Trek original series when you gotta keep feeding ball the monster.
Yeah. Right. Otherwise he goes out and the whole planet goes to hell in a hand basket.
It's the same thing with observability. We gotta keep feeding the monster. Mm-hmm.
How do you help with that? So we come OnPrem with our solution. Okay.
First of all, wonderful question. You're spot on. Um, but if I come OnPrem, then I could introduce you remember Michael Stone breaker?
Sure. Database genius. Uhhuh, he had stream base, right?
Mm-hmm. He started swimming upstream. He said there's a bunch of business problems that need to be solved in the stream in real time.
You don't wanna land the data to a spindle and then ask a question of it as an analytics query. You wanna pose that question of the data as it passes by observing the change in state. That's what we've built.
So our product is Kubernetes native Open Telemetry native. In fact, it's going into the CNCF. We can talk about that a bit.
But the, the idea is if no one's introduced an observability streaming analytics engine, and if I do that, then all of a sudden I'm bringing the power of, we do this in networking. We do this in databases. There's stream based, there's streaming databases, there are network devices, software devices on the network.
Palo Alto Networks F five big IP that run at wire speed. They're stateful and you can co-locate the application right there with the data as it originates next to the app. We are one of those.
So we are an observability appliance on-prem super fast, super lightweight, distributes the cost of ownership of the solution to all the edge points instead of trying to be a SaaS that centralizes it and now needs to spend a billion dollars a year on AWS and needs to mark that AWS charge up to it and pass it through to its end users. Excellent. Excellent.
Quite excellent response to that, Ari. Thank you. Um, we gotta do a little housekeeping.
Okay. Website, URL. Where can people go get more info?
ai For the spelling challenged out there. M-Y-D-E-C, I don't know. I can't think of that.
You're One of the spelling challenge. I'm Gonna S-D-I-S-I. You gotta use it in a sentence.
com. com. Ai.
I won The spelling voice ai, ai ai. I still won the spelling. If you get rid of the dot, it works in sentences perfectly.
I use my decisive AI to control my production system. There you go. So it doesn't break And so it doesn't break.
Yeah. Excellent. Um, how can people get started?
It's self-service. It's completely designed like when a customer prospect shows up at our front door and we're lucky enough to engage people, we send them to the Slack channel, we send them to the website, we send them to the GitHub, it's all hanging there. Top level navigation off that website.
One last thing you mentioned, uh, joining the CNCF and I'm gonna assume the, the working groups for o uh, opt Tel and Yeah. And so forth, weren't that happening Next week right after this conference? Yeah.
So stay tuned for that. We may have to report that news though. We just reported it.
And besides joining, will you be donating some of the code you're using? It might decisive. So We're not ready to donate the core code.
Um, it is open under a permissive license. Mm-hmm. And we are part of the CNCF, so we will comply with all their tests.
Open source. Yeah. And harnesses and their open source policies.
That said, we are contributing to open telemetry itself. So last week there was a missing part in Datadog. We, and it didn't work with hotel We fixed that.
Gave it and it was upstreamed in under 24 hours into Core Hotel distro. We would see them. Um, it must have been a serious problem if they moved that fast on it.
Yeah. The next thing we're doing, we're working with hopefully gonna be able to work with other observability vendors and build what someone else calls enrichment for open telemetry. Okay.
We're building on-prem storage for open telemetry. So you can keep your data in S3 and not be scared to sample it, filter it, or introduce our streaming technology. 'cause you could always grab the raw original and do something with it, whether it's in an open source database or a commercial database or you forward it back to your observability vendor.
All of those modules, those are changes to tel itself and we're contributing those on the tel side of the fence, not on the My Decisive side. I love it. Ari, thank you so much for coming here on Techstrong TV with us.
Thank You. Continued success. We'll be looking for the announcement about the CNCF and we'll continue the conversation.
Appreciate your time. Thank you. Appreciate your time.
Hey, we're live here at ucon. We've got one more today. Stay tuned.
We'll be right back. Hey everybody. We're at Atlassian Europe and we're having a chat about Jira product discovery with Axel Soray, who's the product management evangelist for the product.
And well, I know a lot of people know what Jira is, but I'm not sure everybody knows what Jira product discovery is. So walk us through what is the relationship between these things and how are people using this? Uh, thank you for having me first of all, and really excited to be here.
So for the longest time, product managers or you know, teams that are adjacent to product management teams have not really had a space to capture all the work they have to do, plan that work, prioritize that work, and share the outcome of that prioritization with the rest of their stakeholders. Right. So we've heard doing research, uh, about three years ago from a lot of product management teams saying Jira is not where we should be doing this.
'cause Jira is for committed work. Work that we know we are going to do. Like when we've decided, okay, we're ready to go into development and we're gonna code this, we're gonna build this, this work happens in Jira, but everything that happens left of that.
So the strategy, the planning, the research, the discovery, they needed a space to do that. Right. A dedicated space to do that.
That's what j Product Discovery is, is a place for product management team to capture their ideas, prioritize these ideas, and then share the outcome of that prioritization with the rest of the organization. What were people using before that? Were they just kind of scribbling notes or putting it in a spreadsheet or a doc?
That's a great question. So spreadsheet is, you know, the default to most things, right? Like if you don't have a tool, a lot of it happens in a spreadsheet.
And the challenge with spreadsheets is a lot of times that work is out of sync. So, uh, you can imagine a stakeholder leader will send you a message and say, uh, hey, can you send me like the latest version of what you're working on? You send them this spreadsheet and the moment you send it, it's like out of sync.
'cause like the teams are moving at all times. So that's one of the issues. The other problem is like, this information is scattered across multiple systems.
So even if you're using spreadsheets, you are not connecting the dots between, you know, your CRM data that might be in Salesforce or your customer feedback that might be in like Jira service management or like wherever the data is sitting. That information was scattered across multiple places. So a lot of these teams really needed a place like, uh, it's interesting 'cause our customers call this either like a product hub or a product operating system mm-hmm.
To bring in all of this information into what they sometimes call a single source of truth. So Describe exactly what it is I experienced, so I have an idea. Yeah.
And I put it in where and how does it manifest? That's great. Um, so in a lot of ways it looks like a spreadsheet, like spreadsheet like, or, you know, kind of a, um, how would I put this?
Like a, a tabular like list experience. So, uh, people are not necessarily lost when they land in your product discovery for the first place. So they will look at a list of things, a list of work items, just like you could see them in Jira.
But the advantage of Jira product discovery is this whole idea of views. So views are basically different ways to slice and dice that information in a way that makes sense, uh, for the stakeholders that you're trying to have conversations with. I'll give you an example.
If you are a product manager and you're working at the team multitude in your organization, you need a level of detail, which is not the same level of detail that a VP of product or SVP of product will be looking for, right? So with the same information you can slice and dice, uh, uh, basically these ideas and the amount of information that you want to show based on who it is you wanna have a conversation with. For example, if I want have a high level strategic roadmap, I will use tools like, you know, group buys to build swim lanes or filters or field management to basically create a curated view of the same information, but for a different audience.
And that's the whole power of Jira product discovery. Alright. Now, you did some research in this area before you launched the product and after.
So what are, what's the feedback? What are folks telling you and you know, what's next? So The feedback has been overwhelmingly positive.
Um, geo product discovery, uh, is one of the fastest growing products in the history of Atlassian. So we started this journey, uh, two and a half years ago. Since then, we've had a consistent customer satisfaction score of above 80, uh, which is absolutely amazing.
Uh, and we just passed that 20,000 customer mark. So in terms of growth, that's incredible for, uh, for us and for Atlassian. Um, one of the things we're really excited for is how do we expand your product discovery in a way that supports product management workflows, uh, in a more end-to-end fashion, right?
So if you think about it today, uh, product teams will into your product discovery to, uh, plan their work and, uh, use insights, for example, to, uh, have evidence of how they should prioritize their work. We wanna go further left of that and to do that, we have recently acquired a company called Cycle. Sure.
Uh, they were, they are actually an operator in the feedback management space. And basically they, uh, use AI to, uh, allow product teams to better curate and make sense of the volume of feedback they're collecting across multiple sources. So we are building that capability into Jira product discovery so that product managers and product teams can have a high level of fidelity in their product decision making using evidence and insights.
Right Now, Atlassian is making massive investments in ai and there's a thing called Atlassian Intelligence, which is kind of a framework. How might that manifest itself inside of this experience? So Atlassian intelligence is basically going to manifest itself in, for example, the, um, idea editor.
So if you, you're writing an idea, let's say an idea is a strategic, uh, piece of work you are planning for next year, let's say a new AI capability, and you're building that AI capability as a product team, as you're writing the content in the idea, let's say it's a product requirements document, Atlassian intelligence will help you draft that based on all of the context that it has in memory and the, it could be like pages you already have in Confluence. It could be work you've already done in Jira. And we bring the power of the teamwork graph, which is basically all of the knowledge that Atlassian holds for your company in your workspace into that Atlassian intelligence experience.
Will it maybe even suggest new ideas? I mean, how far can it go? That's, That's a great question.
Uh, right now we really focused on helping product managers, uh, to make sense of the data they're already collecting, right? So if you think about a typical product management team, they might be receiving information from customer support teams through Jira service management. They might be receiving, uh, emails directly from customers asking to support them on something or providing feedback about, about a product.
They might be receiving internal feedback from sales teams through Salesforce. So we're gonna use, uh, the power of ro o, which is our, uh, agentic platform to bring in all of that data, make sense of it, and provide insights in Jira product discovery. And the, the way AI will help you do this, it will surface a lot of the commonality that exists around all of these different touch points.
For example, let's say you have received 5,000 different pieces of feedback, it will go and identify themes across these 5,000 pieces of feedback and say, Hey, you might wanna look at, you know, this theme and this theme and this theme. Because looking at the volume of feedback that we've received, there seems to be something of interest here. And then based on these suggestions, a product manager can then go and think, okay, I can see that customers over the last six months have provided us a huge volume of feedback around this specific topic or this specific pain point they're addressing.
Let's do a deep dive into that. And this is gonna help them prioritize the work that they do in order to help customers make progress in their work. I'm not sure you could do this, but in large companies especially, there's often an issue where somebody has an idea, but somebody actually already did that, you know, a couple of years ago.
Yes. When it's dis languishing somewhere. Yeah.
Can I find out what other people have already done in the company and kind of reuse it? This is already possible today, and this is nothing specific to Jira product discovery, right? This is available through Rover, which is, uh, uh, our agent platform.
It's available across all of our Atlassian products. So typically the way you would do this, and this is something that I I would do regularly, is if I, if I'm in a like large enterprise company where there are like hundreds of teams, and as you mentioned maybe, uh, you know, Michael from this like other team like way remote from where I sit in the organization has already worked on this. And easy way to find out is I'll just go in, uh, my workspace and ask, has anybody worked on this topic before?
And let's say the topic, let's say you're in financial, financial services and the topic is like personal finance management. And I would just simply ask, has anybody worked on personal finance management before? Question mark And Rover is gonna instantly go and look at all of the information it has indexed across your company lot, uh, over the, the history of information that it has.
And it'll quickly come back and say, this is what I can tell you about performance, uh, personal finance management, and this is the work that, you know, I can relate to it. And it will provide work tickets in jwa. It will provide, uh, confluence documents.
It will provide even items that you've referenced from external systems like Google Drive, for example. So as I understand it, you did a survey and you know my, one of the high points of that survey, but you've been doing this for a while. Is there anything in that survey that surprised you or that you didn't think you'd hear?
Yeah, so we recently launched our inaugural 2026 state of product report. And there are a few things that I thought were really interesting. So the number one thing is like, AI allows teams today to like claim back, let's say two hours a week.
Um, but the time that the teams are claiming back, they're not finding a way to invest this in strategy work. And this I think is something super interesting. A lot of teams are still caught in busy work.
So the time that they're claiming back, they're just reinvesting in a lot more busy work. Right? And this is something I think we need to, uh, really think deeply about.
'cause today AI is primarily being used for incremental productivity gains. Why? I think there's a huge opportunity for teams to actually rethink how they can transform their workflows.
So it's not so much like, help me summarize this, but it's more like, help me think about how I could completely rethink how I work based on all of these new AI capability capabilities that are available to me today. So that's one of them. The second one, which I think is something that is more, uh, on the, I'd say cultural level in a lot of organizations that I speak to, is that still a vast majority of engineers are brought into the discovery and the, uh, and and planning process way too late in the cycle.
Mm-hmm. So if you think about a product manager, they have an idea, they work on a a problem definition, they work on an opportunity and they start exploring that opportunity. Engineers will come by when probably they'll, they'll get involved when the product managers already have a spec of something to build.
And that is not how we think this should be done. Engineers should be brought in really early on so that they can share their view of one, what is the feasibility of like, you know, the, the different types of solutions we can think about to address this customer problem. But more importantly, there's a lot of creative element in how they address the solution.
And they've done this before and they're some of the smartest people in the room. So the earlier you bring them in, in that cycle of like thinking about how do we address customer problems, the better you, your output and your outcomes will be. You know, I've been surprised by those conversations happening so late myself because the cost of whatever it is, is gonna be determined by the engineering team.
So if I have a spec and an idea, I don't really know how much it costs to deliver, how am I gonna price it? So that's one of the aspects. But I think even going, like taking a step back and going back to basics, like there's this whole idea of diversity of thought.
Like if you're a product manager, there's a way you think about things like your brain is hardwired to like, think about things in a specific way, bringing in different, uh, types of people. And diversity of thought early on in the journey allows you to have better coverage of how to think about how you might wanna solve for a problem. Right?
So you think about, um, this concept of the product trio that we really try to embody at Atlassian. So we have a product manager, a product designer, and a tech lead. These three people are gonna come together and together address how they think they're gonna, you know, solve for a customer problem.
And the reason for this is that these people are accountable for different things. A product manager will be accountable for the business value and viability of a product. A designer will be accountable for, uh, the, the usability of the product.
And typically an engineer or a tech lead will be accountable for the feasibility of the product, right? So these three areas, or or or discipline should be represented way early into the, the problem definition phase. One of the reasons for this is that all of the strategic context that later on leads to a developer actually picking up an epic and starting to work on the work and write code.
That's the most valuable thing a developer needs. Like they shouldn't find out about this new piece of work when it lends in their Jira backlog. And this is what we're trying to solve.
So You touched on this in, uh, just the last question, but I'd love to get your opinion on it. So we see AI saving people time, but it doesn't necessarily transition into making the company more money necessarily. 'cause we don't change the way we work.
We just kind of, to your point, do more busy work. Yeah. What should people be really thinking about as they look at AI and new product development and what's gonna change?
I think, um, the way I think about this, and we in a lot of ways, in a lot of ways, we're still early, right? We don't really know where, like, where the puck is going. Uh, the rate at which the, uh, AI space is evolving is absolutely incredible.
However, one thing I will stress on is like, the reality of the work that product management teams have to do is largely anchored in customer knowledge. And I feel like a lot of companies are in this phase of going back to basics, which I think is extremely important. So yes, AI is gonna help you incrementally save time here and there, but the biggest differentiator you have right now is what a lot of people call taste or judgment, right?
So where AI can help you save a lot of time in maybe the way you, um, come up with how you're gonna, you know, think about your go-to market plans for, uh, product launch or how you might think about writing your documentation for this new feature that you're launching because the AI has, the AI already has access to all of your code base. So things like that, all of this time that you're saving should really be reinvested in strategy and customer knowledge. And I cannot stress this enough because there's a lot of noise that comes with ai, right?
Like a lot of product managers are trying to keep up with the pace at which this like, uh, space is evolving. But I really think like product teams need to think deeply about where they invest their time. And radical focus means that they're there to solve customer problems.
So AI is a tool, it is an enabler, it's definitely something product teams should be raising their level of fluency on and their level of, uh, uh, knowledge on and embedding it in their workflows. But they shouldn't lose track of the prize, which is like, how do we solve customer problems in a way that makes sense for the business? All right.
Hey folks, you heard it here. AI for product teams, it's not just about working faster, it's about working smarter. Hey Axel, thanks for being on the show.
Our pleasure. Thanks for having me. All right.
And We'll be back in a minute. Hey everyone, welcome back here to Techstrong tv. You know, it's my pleasure to introduce Gabe Boko to you.
Gabe is the chief marketing officer at NetApp. You know, we've been having sort of a running conversation with some of our friends at NetApp now for the last couple months, but I'm really ha happy to have Gabe here to kind of tie a bow on things, but also just to, I, I'm always fascinated to hear people's stories and their journey and and how they got here. And I know a lot of you out there aspiring folks early on in your careers.
You see, I want to be a C-level chief marketing officer, chief revenue, chief technology, what have you. And here's someone who can give you some real life experience and, and tips, perhaps. Gabe, welcome to Text Drunk tv.
It's great to have you on here. Thank You so much for inviting me, Alan. Happy to be here.
Thank you. So Gabe, I hope I didn't embarrass you or put too much on your shoulders right off the bat, but there are people out here, probably a little younger than me who say, man, I, you know, that's where I want to be one day. I wanna be a C-level exec at a public company or what have you.
Um, give us a sense of your journey, how you came to be here today. You know, I, uh, well first thanks for the question. I, I think I actually said to you privately, I didn't know that anybody wanted to be a C-level.
Um, and maybe that's, um, specific to my journey, right? I don't think I started off saying, this is the role or the space or the suite that I wanted to be in. Um, I started off by, you know, deciding that I, I didn't like what I was thinking I wanted to do and I wanted to change.
And technology at that time offered me a, a new future, and I just ran at it as hard as I could. Um, and, and I think that that's, that really denotes my whole journey. It's, uh, a lot of tech companies, a lot of different kind of tech, a lot of software, um, more recently in the last decade, maybe a lot of hardware.
Um, but at the core is really companies that are trying to do something different. Maybe they're, you know, longtime legacy companies. Maybe they have just bought a company.
There's always some level of transformation that I'm attracted to when I join a company, which is harkens back to why I wanted to do tech anyway, which was I wanted to do something different. I wanted to be a part of something that was interesting and, and potentially changing the world. And, you know, I think that if you can understand why you're doing something and you do it really well, then the, the chair follows, right?
The job follows. And, and I think that that's, that's probably the best description of my journey that I can give you. I love it.
You know, I had a similar experience. I actually went to law school during law. I became the word perfect guy in the office, the only lawyer who could do the word per 'cause.
Lawyers didn't use word. We used word perfect, correct. And, uh, and, um, and that, but tech just kind of grabbed me by the throat, and this is what I wanted to do with my life.
And, and for much of the same reasons you said, in some ways changing the world, the excitement of new things, discovering new things, yeah. Bringing new things, you know, to market. And, um, it is, and it's funny, you know, as much as things change, they say this stay the same.
It's true. Here we are in this age of AI now, and it's that same excitement. What a great time to be alive, right?
Even though it may take your job, as some people say, I don't believe it will. I think it's going to create more opportunities for us all. I agree.
And, uh, I'm excited. I'm excited to see what tomorrow brings and yeah. And you know, as long as you have that curiosity and that passion, as you said, you don't aim for a particular chair, the chair follows you.
That's right. That's right. And I think that that's absolutely, that's, if you can hang on to that, then that keeps what you do next, authentic and real, and makes you the right kind of mentor and or collaborator in the chair.
So, um, yeah, I agree with you. Absolutely. So let's talk NetApp a little bit.
Okay. Before we jump into things. As I said, uh, most of our audience is probably familiar with NetApp.
We, I mean, and let me not blow my own horn, not because we're covering them. com days, right? Yeah.
We were what they call an a SP application service provider, right? And, and we needed, you needed network attached storage. But, uh, NetApp's been around, people know it, it's, they think they know it, but of course, NetApp has reinvented itself a couple of times along the way.
Mm-hmm. As you sit here today, right before Thanksgiving, what do you, how do you describe NetApp to people? Gabby?
Yeah. Uh, you know, I love this question because it's something that as a marketer, marketers sink their teeth into. But if you're a technical person, then, then what you're really looking for, do they still remember who I am and why I knew them?
And I think that that's the fine line that we've been walking and, and I think we're in a really interesting spot right now. If I look back on the 30 years, and by the way, it's been 30 years, what we have is a company who's been dedicated to not just storage, not just data management, not just cloud or hybrid cloud. Not just, not just, but we've been dedicated to data, um, and, and getting access to it, to storing it, to moving it.
And, and what that means is, is that we've been responsive to a market and to people who would buy us and use us, wanting their data not to be just one place, but wanting it to be many, wanting it not to be passive, but wanting it to create the power for them to drive change. So when I got into this chair a little over two years ago now, um, we wanted to go back to what it was that people would've known us for. We, and still give them the sense of who we were and, and who we continue to want to be.
And that's when we really thought about that. We came up with something that we call the intelligent data infrastructure, and that we're the intelligent data infrastructure company. Um, and when you think about what that is, data still in between those three words is still at the core.
And when you think about infrastructure, it says, we still pay attention to data storage because it is where it lives. But when you think about infrastructure, you're also thinking about where it moves, how it moves with data management. And then if you bolt on then the opportunity that you opened up with about AI by saying intelligent, we really wanted to connect both of those legacy kind of components that we brought with data to the future of where we thought data was going.
Um, we believe that it's, it's not just about, uh, where your data lives, obviously. Um, we believe we're with this storyline thinking about how data's evolving and how it's gonna be that proven foundation for the future, which is an AI future as we already know, um, how important everything choice we've made in the past 30 years. Cloud, hybrid cloud, multi-cloud, data storage, data management, all data fabric, all of it factors in.
Because what that means is that we believe into it that NetApp is a proven foundation, a proven foundation for, um, not just those aspects, but the future aspects because it's intelligent at every layer layer. It is connected by design to all the public clouds. It has got security and resilience built in, not bolted on.
And that's, we like to say that, but ultimately it's a foundation that, that really unlocks human potential and business potential. And, and we like to think of intelligent data infrastructure as something that when we can help make your data intelligent, then something bigger is gonna happen and it's gonna happen with you driving. So that's a little bit of the NetApp journey over 30 years.
That's how we're thinking about where we've been and how we're trying to embrace the future, um, and how we're doing it as truly technical people with an eye to, um, to building markets and, and making something interesting for the next generation of people who will want to know NetApp. Absolutely. If you don't mind, I wanna, you know, the AI thing is, it, it of course, ate.
So all of our conversations, I wanna just focus in though on marketing. And you, you're, you're a chief marketing officer, you're a marketing expert. If we look at, you know, the low hanging fruit where AI is disrupting almost immediately, marketing is one of those areas.
I think I see it here. Um, how, from your point of view, as a master marketer, and I don't mean to embarrass you, but as a master marketer, how is it reshaping, right? How we tell our stories, how we reach our audience, how we know who our audience even is?
How do we measure success, failure, good, bad, or what have you? How, how has it changed how you look at your job and your, your function, and not just you, but the whole team there? Yeah.
You know, thanks for the question. Mostly because everything I just said about how we're thinking about the company holds true for how even marketers in my day-to-day job thinks about it. Um, I believe that AI is a powerful enabler, just like we talked about it up in how we've crafted what our brand statement was.
I believe personally that it's here to assist and not replace. I know that there's a lot of aspects that it will replace, but it's not a replace, it's almost like a net new, right? Maybe we don't need to do it the same way AI can help us do that better and give us the opportunity to go be creative or, um, spectacular in other areas.
So, um, I think that it really helps marketing teams, uh, work smarter, obviously, make decisions faster. Um, it clearly op, you know, offers new dynamic levels of creativity because what AI does, I believe is feeds off of data, right? Uh, that's just at the core.
Um, we know that it, it processes models in, in an amount of time that no human could have ever done that, which is why it's such a great tool. Um, what you feed it is important, right? So especially from a marketing perspective, when you're looking at what data you want to, you know, have AI contribute on a marketing level, you are giving it the ability to help crunch numbers, to find, uh, net new markets in a faster way, to try to find trends, to find opportunities so that you can go be creative and then feed that back into the same model and say, all right, you're telling me it's this, if I add this in, what does it do?
And, and, and that's really why I think AI is a help, right? I think that ai, AI can't replace human instinct. It can't, definitely can't replace empathy today.
I'm, I'm pretty sure it won't tomorrow either. I think marketers need to continue to show up with curiosity and creativity and thinking about what connections they are looking to drive, and then to use AI to help them tell those stories, to reach those new audiences. Like you were talking up at the beginning, right?
So, um, uh, for me, AI helps. It doesn't hurt us. Absolutely.
You know, I, I wrote an article a couple weeks ago and to paraphrase, Billy Joe, AI can't start the fire, the human sparks. It does, right? The ai, you're absolutely right.
But the AI is a great tool. I wanna come back though to what you were, we were talking about just before, about sort of this rebrand, if you, not a rebrand a, an evolution to the branding of NetApp becoming an intelligent data infrastructure company. Yeah.
And I, I think part of it is the realization, hey, stupid, it's all about the data, right? For a long time we seemed to almost forgot we were so busy about the app and app and app security and running the app and making the app mobile Yeah. And making the app that we forgot.
It's about the data. The data is the, the, the crown jewels. The data is what we we're going for.
As part of this rebrand or a brand evolution as I called it, you had to kinda reset people's vision or, or expectation when they heard NetApp. Yeah. Hardware company, storage company.
What were the lessons learned? What were the, what were the gotchas, what wasn't on your bingo card right? As this thing played out?
Yeah. I'll be honest, my first, I think my first six months of listening, people were like, you're not in the cloud. You're a storage company.
So you know mm-hmm. Try to remember who you are. Um, and I, I took that in and it, like, part of you is like, yeah, but cloud is what makes everything that we do for you on-prem unique.
Um, but that wasn't, wasn't landing in the way we wanted it to. In addition, I think as with all things marketing, right? When sometimes when you do it by committee, you end up with what I call a list of commas, right?
You literally have a, a long list of offerings and words that you're trying to jam in so that you are, are meeting every audience. And what ends up happening is you end up meeting no audience. Um, so people, if they don't see themselves in that big long list, start to question, you know, like, I don't see myself there, so I don't know who you are anymore.
Yep. So those were some of the challenges that I think I walked into. Um, I think the, the goal was to simplify all that to say, we gotta be one thing.
Um, we've gotta think about it. We've gotta go back to why we made decisions in the first place. That's how we got back to putting data at the center.
Um, we have to remember, it isn't just about the place, right where data lives. It's, we've done a whole lot of other things that are super important to our brand. On top is, is absolutely critical as, um, software for how we manage and do data management in the, in the cloud and on-prem.
So we, we weren't paying enough attention to that. Um, so I, I think it was about how do we talk about those things really realistically, and then how do we, how do we use those words to then tell a story that's compelling, right? As I said, it wasn't just about where data lives, but how data moves and how it creates human possibility.
Well, then that allows us to kind of go back into maybe not just talking about the cloud as some of those locations or data management as those of those locations, but maybe it's about our partner partnerships, our, our alliances, our sponsorships, um, all of those make our brand more relatable, make 'em more visible. And I think the last thing is, you know, we wanted to make it real, right? So we wanted our customers to be able to feel this.
One of my favorite videos we, we released at Insight, our user conference just a month ago was this, uh, European Space Agency video. And it's mm-hmm. It's, it's like, plays like an Oscar movie for me, because it's, they're talking about petabytes of data and the digital storage place of the universe.
And, but they're still talking about, listen, I haven't lost a file. I am, I am thinking about my data infrastructure, my intelligent data infrastructure every day, because I want to make, you know, astronauts and engineers. And I think what that really brings back to me is that we didn't wanna escape our legacy.
We wanted to position it as a foundation of trust for customers like ESA who had been talking and using us for 20 years and had never had a problem. So, and history. I think that's what gave us the confidence to evolve and experiment with where the story was going and, and really lead this, this new chapter for us in a, in a bold way and in a really focused way.
Again, coming back to the core, we're a data company and that's, that's why we talk this way. So reinvention, it's still ongoing, but I think we're in a much better place than we were two years ago when I took this on. Well, no, any, anybody who tells you that their reinvention is done is done.
That's right. That's right. Stick stick before.
But you know, you're talking about cool. Uh, well, so I'm, I'm, you know, of my age, nothing's cooler than the space program, right? Yeah.
I mean, that's, that's as cool as it gets for me. Yeah. I went to that Kennedy, I live in Florida.
I took the kids years, years to go to the mean. That's awesome. I went to the Kennedy Space Center, they were bored.
I was in my glory. But anyway, but you have some other really great relationships at, we do you guys do some sports? Kind of, uh, we do relationships with the Niners and the Sharks, you know, west Coast stuff.
Look Super Bowl's coming to, uh, Levi Stadium in, in Santa Clara this year. Yeah. My team won't be there, but it's okay.
Um, but that's a really cool, another cool aspect of of doing marketing is you get to not just play with the astronauts and the European Space Agency, but sports leagues too. That, that pretty much sums up my world. Um, how, how, how does that message resonate to the techies out there and to the old line manufacturers and the, you know, the kind of the nuts and bolts, the, the block and tackle clients?
Yeah, right. You know, I, I think again, it's about telling that customer story and, and the, the reason that we partnered with the 49 ERs and with the NFL is because their customers, right? There's no story there.
If you're not a customer, um, Aston Martin, uh, big F1 customer is, is actually a hundred percent on NetApp storage. So it, it was, it was compelling to us because these were customers who were doing phenomenal things. Let's just take the NFL and focus right there.
When they go in and create a moment inside a stadium for Monday night football, Thursday night football, Sunday night football, an international game, which we're a massive sponsor of, they turn that entire stadium as one of the NFL CIO says into basically a chi, a gigantic data center, right? You've got data from your fans, you've got data from the, the television broadcasters. You've got data coming off of the sensors of the players.
You've got data on the sidelines. You've got calls to the data in the cloud on-prem. When you are able to tell that story, and when it's CIO to CIO or data storage specialist to data storage specialist or cloud specialist to cloud specialist, what they can do is they can see their issue inside of another story.
It's not us telling the story. It's us giving them an opportunity to see beyond their own and to make additional connections. And I think sports in and of itself provides such a global stage.
I mean, it's, it's the biggest Switzerland of, of all customers, right? Of all technical environments, because everybody somehow engages with sports. And, and I think that those things a, allow us to, again, back to that evolving human experiences, whether you're a fan, whether you're an athlete, whether you're a student, whether you are an IT and doing the job, whether you are servicing somebody, we wanna make sure that our message is accessible to you, um, and that it is somehow making an impact to what you do daily.
Or maybe you get really inspired by it. Absolutely. I knew we were gonna, Debbie, I knew we were gonna run outta time, but I got one more question for you.
Okay. If you have a couple minutes. I do.
Okay. You know, everything we've spoken about at this point to this point has been about understanding what NetApp does. You know, understanding the supremacy of data, understanding ai, understanding technology.
But I think especially from a marketing person, we can never lose sight that it's about the human right. It, it's always about the human. We can't take the human out of this equation.
AI will never replace us Machines, I don't think will replace us either. AI and machines. Maybe.
I'm only kidding. You know, it's about the human. Yeah.
And so how do you, again, as a master marketing person, a, a chief marketing officer, how do you make sure we don't lose sight of keeping the human dimension, of keeping humanity involved, of, of putting the human in the middle, the human in the, in the chain, if you'll, yeah. Yeah. You know what?
I just come back to what we were talking about up at the top. Data isn't just technical. It's, it's really, it's what we use to create possibility and, and fueling that humanity.
Um, you know, marketing as a chief market, chief marketing officer, whatever I am, I, my job is to unify my function for the company and to do as much as possible so that my stories, company stories, the stories of my partners and my customers, of my sponsors and my alliances, that all of those are able to kind of move together and demonstrate this ecosystem of possibility. And that's, and that's really, I think, um, the most important part of being human and having marketing to help technology become human and make data human. It's listening to what we do first.
And, and I'm really proud of intelligent data infrastructure because I think it does that it is specific without being, um, too, too specific. It's, uh, unique without being overly, um, unique. It's about how you interpret it.
And I think that once you create that foundation, then, then that opens up the door to human possibility, regardless of where your data is. Um, you know, NetApp is here to, to be a partner to you, to bring that forward and, and bring that, bring your possibility forward. I love it.
Gabe, thanks for being human and coming on today. Thank you for asking. Appreciate human.
Well, what else can you be, anyway, but thank you. It's been our pleasure to have you on here. Gabe Boco, chief Marketing Officer at NetApp.
I on Tech Drunk tv. Hope you enjoy it on our pre-Thanksgiving show, and we will, uh, be right back with more. Thank you.
Hey everyone. We're back here live at Q Con. It's Tuesday afternoon, getting a little punchy.
We've been doing a lot of interviews today. They got popcorn and cupcakes out here. It was hard getting me back in this seat, I'll be honest with you.
But, um, nevertheless, if there was one person at this event who could get me back in the seat, it's my brother from another mother here, John Willis. John, welcome. And you owe me a dollar, right?
And I owe you a dollar. I owe you a dollar. I, I tried to throw the bag in the garbage can.
I shot a leg. I was from Indiana. I was from, oh, miss.
Anyway, John, Hey. Pleasure to have on. Hey, it always great to be here.
It's been a little while since I've been on there. It has been. It has been.
You've been busy and running and running around. Right on. Let me introduce you to the man in the middle, though, playing the five spot.
Just checking how much you know about basketball. Yeah, I know. Alright, so Oliver Eikenberry.
Yeah. So Glad to be here. Glad to be able to come and talk to you guys.
Um, Oliver Eikenberry, I'm a principal architect with Rio. Um, we're a small boutique, uh, consulting firm that specializes in DevOps transformations, um, at largest large scale enterprise organizations like we. And we really focus in on, uh, building width, not four.
So we come into an organization, we, we do value stream mapping sessions. We under really get to understand the client and where their problems lie and what they're doing. And so, and part of what I do and what I drive the most is I'm, I lead our platform engineering, uh, initiatives.
So I'm really focused on how to build great platforms that support delivery for these organizations and really leaving them in a better spot so they can continue forward faster and on their journey to provide value for their customers. I love it. Let's do a little digging here though, Oliver.
Sure. That was a great, a great, uh, segment. But we got to, you know, put it into chunks that people are gonna grab.
Let's start with the name of the company. So Lee Atrio. Um, so there's this flower called the ous Flower, and Chris Blackburn, our CEO, when he was founding the company, he saw that flower, he kinda liked that name.
It grows in the desert, it grows in a lot of different places. Very beautiful flower. io.
And that's kind of where the convergence of the name came from when he formed the company. Very. And it, it Also was tro io or li io.
We Have, we own multiple domain domain names, but that was kind of the synthesis of the t io. So Rio on a plan name and the, uh, the common name for the ous flower is Blazing Star. And we are blazing stars and really drive and shine a light on a lot of things that we do with the organizations that we work with.
So, So you're telling me the company's founded on flower power? Yeah. Yeah.
You might say that, but Yeah, I love it. You know, it's a lucky thing you got both domains. io is supposed to be going away, right?
Yeah. Thank God you, you didn't we that Was, we've had that for probably 10 plus years at this point. Yeah.
So, very cool. Um, so we mentioned the domain name. We mentioned what you do.
I just wanna make sure we get our housekeeping outta the way. Yeah. John, what do just, you haven't been on in a while.
Give people a quick update on you. Yeah, so I, you know, I finished, um, a book that I worked on for two years. Uh, it's called Rebels of Reason.
It's the history of ai. You know, I, if the most of you, I, I wrote a book about Dr. DAMing.
I've, I've found this rhythm of telling stories like historical it, but taking complex subjects so that everybody can sort of understand them. And, uh, yeah. I finished that.
It's been out almost a year now. Um, and right now I'm, I'm starting, I'm fascinated with quantum computing and how that's gonna like, invade probably not until at least five years, but like, I, I think now's the time for thought preparing For few days is coming. But, but speaking of Theatro is, I've known Chris Blackburn from the earliest dev days.
Him and Damon Edwards worked together. Yep. Okay.
So when Damon was moving away from moving more into product and moving his very successful consulting business, he partnered with Chris. And a lot of that stuff that Damon had built on, like some of the best value stream mapping stuff that's ever been out there. Chris took that over and I've just watched Chris over the years build a culture, you know, and, and you know, in all transparency, I am working as a consultant helping some of their sales team right now.
But I've been a fan of Chris's what he's built. 'cause the truth is, regardless of whether I'm getting paid or not, they've been always doing DevOps the right way from the beginning. And I think what's fascinating now is as we're seeing everybody wanna do AI native and how I do that, those principles are more important than ever.
And I, and that's why I've like, sort of decided I wanna do some work with them. 'cause I think it's fascinating to use those principles that we know work we've all been sort of talking about for 15 years and, and, and stay away from the people who are just going right into AI and using none of this, the things we've learned over the last 15 years. So yeah, that's, that's sort of my story around why we're here or I'm here.
Excellent. Alright. So guys, let's dive into it though, right?
Just when we thought we were getting our arms around DevOps, right? It's real. We, we know how to turn the dials.
We know what dials to turn, or we think we do. You know, we, we, we, we got to the top of the mountain and hopefully it's a little bit more of an easy sale. Now this AI thing comes along Of the mountain.
Yeah. Right? It's, it's the theory of constraints or in real life for us and everything you thought, you know, let's throw the cards back up in the air and see where they land this time.
Oh, and let's max in mix in a little platform engineering, some cloud native. Hey, maybe even we'll talk about a little quantum down the road. You ain't seen nothing yet, right?
Basically, we haven't solved nothing Oliver. Well, in one way I guess it gets, it's what gets you up in the morning saying, Hey, I got a fresh mountain to climb. Right?
On the other hand, there gotta be days where you say, geez, does it ever get easier? Yeah. That it, it's, it's both of those because I mean, I've been, so, I've been pretty focused on platform engineering in that space for the last two to three years, owning and driving that, figuring out how to really drive how that connects to DevOps.
Because a lot of people say DevOps is dead platform engineering is the new DevOps. And that's where the principle of, and really drives this DevOps is a culture, it's a philosophy. It's not a thing.
And it always was don't DevOps speak clear, Right. At its purest point. And so I get up and I, I look at what's new in the platform space, and all of a sudden there's this new thing with AI over here that's gonna solve all my problems.
But I, I look at that and I go, well, it's just actually the foundations of a platform still exist. I still need a place to run all those agents, run cps and interact with all the existing systems that exist today and manage those. So now my, I get up and I go, oh, how does AI inflect and change in the space?
And we have a whole team that's run by Robert Kelly, our VP of innovation at Rio now that is an innovation team. They are focused on what the next thing looks like in the space around agentic development and how to get that and transform organizations in that flow. And the struggle I have is, it is too much.
There is, so AI moves so fast at this point that you can't just go buy a tool or subscribe to any one LLM or other area and, and say, that's it. I can stay there. It moves too quickly now.
So the struggle I have in the pain is, is like you have to keep up. It's a constant like hamster wheel effect now. It is in that space.
The problem is, is you can burn out on a hamster wheel. Yes. I wanted to make a point that, you know, like the why the fundamentals matter, right?
And, and to today's, uh, keynote, uh, the open guy from open ai. Great story. So this is OpenAI and he talks about how they're logging.
He did some performance review. So you think about all the stuff that has to happen to get us chat. GPT Yep.
And G PT five and all that stuff. They have to log, they have metrics all over the place. Of course they have that, right?
And he talks about how they evolved into that. But then he shows this, and I think the presentation lies how one line of coach is saying 50% CP utilization across the board. And basically what he found, going back to the fundamentals, the fundamentals are always gonna be here no matter what we build with ai.
He, they, he found through basically some perf tools that there's a library in one of the new, um, you know, fluent bit, bit fluent or whatever. Um, that was doing, um, an FS stat, just a basic, you know, c library fs stat to get metrics from a file to log that was happening in an I notify routine as part of the colonel. And he literally made an open source change that he could toggle that FS stack.
And he saved 50% CP utilization across all open ai. This, so as we're talking about AI native U or GPU or Both, no C-U-C-P-U, but it's, we're talking about open, you know, Claude code and all this stuff. It's all fascinating, but the fundamentals are never going away.
And that's a case in point where like 50% utilization at open II is solved by a true understanding infrastructure io at all levels. Right? So let me talk fundamentals.
Fundamentally, if it's costing you a dollar for every 20 cents I give you, you got a fundamental problem here. And, and I think that that's to a certain extent where we are with this ai, you know, there Yeah, there's a lot of platform engineers and a lot of DevOps folks and a lot of developers who are saying, ain't this grand, ain't this grand until they get that first bill for tokens. Yeah, yeah, yeah.
Right. Token usage and so forth. Right?
I, I think I, I'm not anti ai. I use AI more than most people I bet. But I, I don't know if we have industrialized, I guess is a good word, industrialize.
Its usage at scale in a, in a sustainable, and I'm not talking about energy, right. Sustainable from a business point of view manner. And, and you know what, Oliver, you're fighting the fight on the front lines of this, right?
You're like a firefighter in California here, but is it, is it a wildfire? Is it something we can get a, hold on. I think We're, we're seeing emerging trends and patterns with like Claude Flow and some of these things that are enabling an individual engineer to have multiple agents go do things and help them do things faster, produce things that they can review faster.
So we're seeing that acceleration at the local engineer level. All the tooling is very focused to that. But we're starting to see emerging parts, pockets, and parts in the market now.
Like at GitHub Universe, uh, just a few weeks ago where they announced, sure, oh, I can run my agents in GitHub space and they'll manage those agent agents for me. Where in order to really unlock and go from 10 Xing an engineer to 10 Xing an entire organization, to really get to that value, you're talking about from a business perspective, we have to figure out how to give the engineers the ability to use these new tools in a shared way. Because AI is context.
Context, windows, figuring out the context, parsing what you need to do to get the right results out of it, because it's deterministic in a lot of cases. So as we figure out, how do we scale that and say, oh, this agent is really good at producing these things in this organization, and it's referencing what I've already built as a fundamental in my organization. And how do engineers, are they able to share using that, spin it up in a collective way versus having to only do it at the level of their machine and what's going on, right?
So we're seeing emerging things in that market's moving that direction, but it's still so open to what you can do and how you can figure out how to do it, What's going on. It's wild west and it's very, yeah, It's very wild and open. We We're still creating the maps, if you will, before sailing the ocean.
There Was a DevOps day is Dallas. There was a gentleman from, um, I think what, um, one of the cars, like EEDS or whatever sort of, um, One of the third party Bargains. Yeah, yeah, that's right.
And, and he was talking about economics of token, token, not just sort of token costs and tracking out, but they we're starting to see the, what's happening is finops Yeah. Is getting involved. Yeah.
And finops is sort of mandating, like, I don't, don't explain it to me. You just need to explain these costs. And so I think like everything we do, I mean, we, I mean I, you're right, it's very dangerous.
The token cost can get like scary really fast. But, but we, we source some of this in cloud. Like everybody raced out to the cloud and then we, we figured out some cloud Economics efficiencies.
Right? Efficiencies. And we Sort of, and that's not, that's by the way, that's not a technology thing.
That's right. No, you could any innovation. First you do the innovation, then you figure out the efficiencies of it, right?
That's right. That's right. Well, and you look at a big pharma when they do, uh, experiments on new drugs, first they figure out does it work?
Then they figure out what, how, how much is it gonna cost and exactly how do we optimize its efficiency. And I think that's where we are in this, this, let me, let me, let me bring up another fundamental for you. And it's really important to every single person in Booth here at this event, at the end of the day, is it about using AI to make our platforms better, to make Kubernetes better, to make observability better, to make DevOps better?
Or, or is it, in order to use ai, we've gotta reinvent all of those things. I just told you platforms, we need platforms that are optimized for AI inference and or learn or training. We need, we need, Kubernetes isn't gonna be the orchestrator for AI applications.
We need a different, we need something, call it native AI that is going to orchestrate my AI stack. 'cause is AI gonna create a new stack that renders all, everything you see here obsolete? Or do we make this stuff the stack for ai?
What do you think, Oliver? I Think it's both. I think too, the, is is there a whole new stack for ai?
We don't know yet. That is an undiscovered country that I think all of these engineers that are like really playing with this and pushing the limits and boundaries of what AI can do, they will figure that out that will emerge on its own as it happens in the space. And likely we won't see it till it happens.
Um, in terms of like runtime for ai, when you talk about the, like, there's a huge push into using Kubernetes to run AI and L workloads. That's right. But are we pushing Rope up the hill on that?
Maybe I, there's other organizations that are, that are spinning up entire data centers just for GPUs. So they're data centers that are just ran Trillion worth GPUs to then enable people to run that. And they're building declarative Kubernetes stacks on top of that.
I honestly still go back to even the lower fundamental of that, of how compute works. Kubernetes is great for scale. If you don't need that scale, what do you, what do you use it for?
And how do we look at, so it's a kind of a non-answer, but I think we have to look at both, both perspectives and be prepared to shift one way or the other and what's right. Because really what AI is doing is it's, um, it's giving us the ability to build larger shared context, put more information to the system, and build bigger, better things and solve bigger problems. And so it's, that platform will emerge, but in order to do some of the stuff in the experiments, we have to provide a space for people to even try those experiments.
So that's where we, when we look at what people, organizations that are getting into ai, they're like, well, which tools should we buy? And we're like, give everybody access to all of them. Don't sign a three year agreement.
Yeah, yeah. With chat GPT, sign a six month agreement. Give the, give them access to the different tools because everybody's workflow is different.
And that's the unique part of this change is that you can't really put it in a box. It's too dynamic at this point. Alright.
I think that, I love that question, Alan, because, uh, we were just on a Tech Field Day podcast and we had a good debate about this. And you know, there's sort of the, the, there's two ways to think about it. One is we can look at the proof that Open AI and, and Anthropic are all running Kubernetes mm-hmm.
To run large, the largest infrastructure. And I'm certain Google does too, right? Um, for Gemini.
So that kind of tells you that maybe the hammer nail is never gonna change. But the beauty now is companies can step back and do things they've never been able to think about doing. Like, and, and because the, the cost of writing your own has always been the maintenance of it.
But now the, the, the, like, the same things that are solving the, I can do things in a week that normally took teams six months to do. I, it's the same acceleration for maintenance and update. So I think there's an opportunity organizations, one other story I've heard a few times is some of these larger organizations, instead of sort of getting rid of some of their classic developers are looking at some of these big ticket ELAs.
Like a, not saying Workday specifically, but like, could we rewrite Workday? Could we rewrite Workday for us and build it specifically so it works for our organization? And, and some of those are like, let's try, right?
So I think there is a, there is a world where somebody might look at Kubernetes and say, you know what? We've been forcing ourselves down this thing. Let's prototype an alternative.
And by the way, there have been some good alternatives that have died, not because of technology, but because Marketing Nomad from, from HashiCorp was, was too syndrome. Well, but, but even in the, in the, in the platform space Yeah. Platform for Docker and, and Nomad, those were perfectly legit solve 80% of the problems that went away for non-technology reasons.
Yeah. Well, the other thing is, is that a lot of these AI tools make using Kubernetes easier. That's because Kubernetes is, yes, everybody can say Kubernetes is easy, but then you get an SRE stand up next to 'em, they Kubernetes is not easy.
Yeah. Yeah. No, yeah.
Um, type of scenario. So that's the other thing is that's A good point. These Cha these tools give you better shared context of how to work with that thing.
That's right. So I get to your point, John, they don't have to worry about managing Kubernetes. Yeah.
They're more worried about building their app in their workload. Yeah. They start to question, oh, do I need this SaaS tool or can I build it to the specification of what I need?
So it kind kind of comes back to software's eating the world. It's gonna eat the world even more because we're gonna have more people building software with ai. And the double down on that is that, you know, as I think about listening to all the keynotes co con today, right?
Like, like I get, I get tainted, you know, like, oh, Kubernetes come to KubeCon, watch people, thousands of people march around learning how to build Helm charts. And but to your point, and the point that, that they were making the keynote is like, all the contributors are now using accelerated ai. Mm-hmm.
So maybe at the end of the day, we don't have to build Kubernetes 'cause it gets built through an evolutionary role that, right. Like, we're getting better at delivering a better platform based on CNCF or Right. Cloud Native or Kubernetes.
Ideally, A platform is just removing a, a layer, a load context load from all the engineers. So they have a place to build their apps that they're creating. So you wanna remove that context load.
So AI just continues to layer in the ability to, to bring that context out and further out for them to work with. So You know what, it's gonna be interesting times, that's for sure. As this plays out, Definitely you're Right in the middle of it.
Absolutely. Every day new articles, my feed gets filled every day I have an entire brow separate profile on my browser. Now that's just AI that all those things go to, and it just stacks up for me to go, you're Not using an AI browser that does this for you.
I've tried played with ai, I've tried using that, but part of the consumption or information for me is I want the details to a degree. Yeah. Yeah.
And so I do AI summaries. I've used AI to do deep research on large, complex projects that would've taken me teams of people months to do down to few, a few weeks and, and things like that. So that's about a balance of figuring out the right place to use the tool to build That content.
It's funny, on the AI thing, there's a couple of newsletters I subscribed to, and I was using AI completely to do summary. And one day I went back and I looked and I was like, I, I looked back on what I'd been doing and it was missing stuff all over the place. And so I've reverted now to reading the art, reading the sort of newsletter summary to his point.
Like, yes, the summarization is awesome. Like take a research paper. Mm-hmm.
For me, I'll take a research paper and I'll put it in there and say, let me know if I need to read this. Right. But, but on things I actually wanna know the details.
I'm, I find myself falling back to less summer mode. I love it. Yeah.
Guys, we're about outta time. Yeah. Oliver, it's a pleasure meeting you.
Yeah, absolutely. Indiana's a big basketball. I was just, there you go.
It looks okay too. It was A New Yorker in me that just, you know, you say that, I'm gonna tell you look up to see how big that building is before I snatch your wallet. Um, John, always a pleasure.
That Good? Yeah, it's fun stuff. We're live at Kcu.
We're not done yet today. Stay tuned. We got more Welcome to Security Boulevard, the cybersecurity podcast from the Future Room Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, our Security Boulevard, YouTube Channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into this episode, I'd like to meet our panel for today, starting with my good friend, Fernando.
Fernando, it's good to see you again. You've been a busy guy for the last few weeks. Absolutely.
Uh, wonderful to see you, uh, Eric and Manuel, wonderful to have you guys with us. Uh, for those that don't know me, I lead cybersecurity and resilience research over here at Foot. And, uh, as Tom alluded to, uh, this is busy travel season for analysts, so I'm still recovering from jet lag, so my, uh, but yes, it's, it's, it's a phenomenal opportunity to, to run into people and chat and, and whatnot.
Everyone is excited about the topic. We're gonna talk today as well. Of course.
So, yeah, it's, uh, it's, uh, wonderful to be here. I hope we folks enjoy the conversation. Awesome.
And we're joined with some guests from SIG today. I wanna start off by having them introduce themselves, Emmanuella. Hey, thank you.
Thank you for having me. I'm Emmanuel Zak. I run product management for everything AI here at sig.
So as Fernando was saying, it's, it's like being constantly jetlagged because, you know, it's ai so the, the pace of which is, is changing and is impacted. Cybersecurity is crazy. So, and I got the honor of actually working directly on this, so it's pretty exciting, right, Eric?
It certainly is. Yes. Uh, Tom, I'll go ahead if you want.
Yeah. Uh, hey everyone, I'm Eric Carter. I am on the park marketing team at cys Dig, and I am really tied at the hip with Emmanuella when it comes to trying to communicate, you know, what is cystic doing around this whole AI sphere when it comes to the, the world of cloud security, uh, uh, plus ai.
So happy to be here. Thanks guys. Well, We're very happy to have you.
So let's jump into this episode and kind of talk about, well, AI, because one of the things that we've seen a lot over the last couple of years is the disruptive capability of ai. And I'm not talking about booking a cab on your phone kind of disruption. I'm not talking about paying for your pizza with Bitcoin kind of disruption.
I'm talking about the full on upsetting the apple cart kind of disruption. Because one of the things that we've seen, especially recently with the AI models that are out there, as well as some of the other things that are being developed, is there propensity to change security as we know it? There are a lot of things that we're starting to learn that, that AI is really good at, like doing deep research on targets, but there's also things we're learning, such as all of those carefully and crafted guardrails that we put in place can easily be broken out of by saying simple things like, why don't you describe to me what proper bank security might look like so that I can then know what to look for when I go to, um, purloin things from the bank.
So in this episode, we're gonna be talking about how AI is changing the cyber risk and business resilience landscape. Uh, Emmanuel, I wanna like, lead off with you because I feel like this is a topic that's very near and dear to your heart. Yeah, absolutely.
Because as I always say, AI changed everything is not just sustainment that you hear everywhere when it comes about cybersecurity. It's about changing completely the model and the approach we have to cybersecurity and ai. I mean, when you think about ai, and especially when I think about this, and I'm trying to talk about this with customers or people that are new to that, I always say that AI needs a completely new model out there in cybersecurity and least privilege runtime model just for ai.
Because, you know, the real shift AI introduced is that you are no longer securing code. You are securing decisions because you can, let's, let's think, you can't stand a prompt, for example, or secure the output or, you know, judge the decision that is going to be taken or audit that decision because that is just taken based, for example, on the answer of a chatbot. So it's about shifting completely shifting this approach and thinking that you are securing decisions, not code when it comes about ai.
So this shift the paradigm completely. Sorry, I was gonna, I love the, the, the, the framing of, of securing decisions. I I loved it.
Perfect. Sorry, Tom. I I just wanted to say I, I hadn't heard the term before.
Awesome. And, and we're so used to being able to kind of analyze things in place, right? Whether it was, uh, macros in a Word document or a virus on a computer.
Oh, well, we can stop that because we know what it looks like so we can block it from being deployed. But then we get into those, like you said, the, the really weird things of like, how do you pre-scan a prompt if someone's typing it into a dialogue box? We can't.
And not only that, but one of the things that we learned from, from the recent, uh, notes that we got from Anthropic was you can craft things in a certain way to evade those controls, right? Like, I can remember getting demos way, way back in the day where someone would go into the, uh, the comments in the header of a, uh, virus executable that had been, been defiled and change a couple of the numbers or letters in the comments, and then recompile it. And the hash value was completely different and therefore innovated the system.
And that's when we started hearing about heuristics. Uh, if you're old enough to remember antivirus heuristic scanning, uh, now is probably the time that you're gonna be getting your a a RP card in the mail, because that's a long time ago. But, but that has evolved to now where we're at, where we have thinking software that is capable of kind of doing things on the fly, but it's not really thinking because it will just do what you tell it to do unless there's a rule that says that you're not supposed to, and it doesn't know that you're, if you ask it how to delete a backup if I'm, you know, maybe somebody who's doing a little house cleaning in my tape robot library, or if I'm a nefarious actor who's trying to erase all evidence of my presence in an organization.
No, I was just going to jump one thing, and, and, and it's funny because we jumped into this in this conversation as well. When I have, when I talk with security executives and others who are trying to make sense of this all, one of the things interesting is how are to, to what we're describing in, in runtime, but the way that we, we like to frame security conversations to help people understand what kind of problems they're trying to solve. Is it, it's the, the, the, the triad that people refer to as security for ai.
How are we securing how organizations are applying AI capabilities in whatever. That's, that's topic one, right? And, uh, the other is AI for security, right?
How are you using AI capabilities within the security processes that you are running your organization? Topic number three is security from ai, right? Or security against ai, which is okay, even if you do nothing else, you go home and, and you just wanna be quiet, right?
And not touch ai. It doesn't mean that your adversaries are not gonna do that. And that's what we're seeing all the time.
I'm sorry to give, to go back to basics a little bit, but that I, I find it interesting to, because I've walked into many conversations when we were expecting one type of AI converse AI security, and we yet another, right? So that's, I just wanted to frame here. The other thing I, the other thing I like to say is I like to frame the discussion between, are we talking about workforce AI versus workload ai and workforce AI is okay, within the scope of a company, how is the company using AI to support us as employees, right?
So, or, or what are you using as a person? Hey, all of us have, uh, an LLM of choice that we use to, Hey, help me craft this email a little bit better. Whatever.
Right? Fine. That's one type of of use case.
The workload AI is, look, our company is deploying AI within our company. Is deploying something that something is using ai, what do we do about it? Right?
So, sorry to backtrack us a little bit, but I, but I think that, uh, uh, making the distinction about which one we're talking about is a really good first step to, yeah, we, we face that, Fernando, because, uh, we are, we are out obviously talking to the market about it, but also people inside of SIG and we always have to clarify of, you've come to me and you've said AI security. Now let's add something to that. Is it AI four?
Is it security four? I like the third one. Uh, where I think inherently in sig there are things to protect what you were talking about, which is AI trying to break through the walls, et cetera.
Uh, so that's a, that's a good third one there. When we first started talking about this, I had created a slide just to try and put a visual, and if you remember, rock em sock robots, Tom wa and there's like, I have a red team and a blue team, and these guys are fighting it out. So ev we know that the bad guys have this at their disposal.
We, uh, before we, we came on the air, we were talking about the, the Claude and the, the, the issue that was revealed this week, right? And so there's a perfect example, right? So they've got it, we need to have it as well, um, in order to stay ahead of these things.
And somewhere in the midst of all this is a, is also this trust conversation so that we, when we are using it, we can trust it, but there's, so there's a lot of things to, to cover, but, um, s we're, we're focusing on, on both, especially using AI to try and defend, right? First of all. But also since we are quite, um, good at and known for Kubernetes security, a lot of these AI environments are being rolled out as cloud native workloads.
And, and there's, there's a, there, there where okay, it's, uh, it's something you've got to make sure you are ready to deal with, right? If you haven't, um, been securing your cloud and cloud native environments the right way, you better get on it. So, oh, absolutely.
And, and, and I have a side note. I've been covering cloud and cloud native security for a long time. I'm well aware of, of, of, of Falco and, and, and, and everything that, that, that has done in your, and you're spot on.
Like you, the visibility that we, that, that we need into how runtime is running on those clusters, right? Is, uh, is if essential. So Yes, absolutely.
And these Fernando goes, sorry, now goes back into what you were saying at the beginning actually, because the point is that right now we are no longer, you know, we are no longer securing something static. Think like a castle, for example, with firewalls that we were mentioning before. It's something that is changing constantly.
It's dynamic if think to this like an ecosystem. And that's the thing, because people only think about ai, but the real thing there is that attackers, like we talk from the point of view of defenders and people that works in cybersecurity, but we have the same tools. We can leverage AI to actually defend against those threats, but they can leverage AI to automate and actually make things faster.
Some, I remember it was some couple of months ago, I guess, with a web UI kind of, uh, kind of box that was out there, and you remember that they kind of exposed without mean privilege, uh, this interface. And basically the attackers just created an AI generated Python script as simple as that, to be able to leverage that and start a crypto mining activity. As simple as that, when you analyze that code, it was 90% AI generated.
And that's the thing we are, you know, we are starting, uh, a war with the very same weapon out there, and it's powerful on both sides. Yeah. So it's, And, and It's there.
The thing that I, I help, uh, that I wanna have conversations, the thing that I think helps people understand is what is AI changing, right? And AI, at least talking about security from ai, like what are the attackers doing, right? And we're not yet, like, we're starting to see these more and more.
And, and, and I'm, uh, um, I think that attackers are very, um, uh, very rational when it comes to the economics of attacks. And they'll use what's affordable. They'll use what's, they'll use the minimum they need to get the job done, right?
And, and so, uh, I've, I've had conversations where people are saying, look, I don't, I, I know AI is here, but I don't wanna deal with it because I have to deal with so many other things. First, I like to point out that, look, we're not, we, we want you to think about security, security from AI now, not because of the attacks that are happening now, but what is changing coming along, right? You mentioned, you mentioned the Python script, Tom mentioned the, the, the, the, the, the, the report that just came out.
What is common between them? I think that two things we're seeing that it's important for defenders to keep in mind. We're talking about AI enabling more attackers.
So we're giving attackers or AI is giving attackers access to better knowledge, right? So in other words, if I, if I am, I, I'm old enough, like when we used to call them script kitties, right? Uh, uh, uh, now that capability, the capability that somebody can have now is much greater.
That's point number one, right? Point number two is that not only that comes with greater capabilities, but that also comes with much faster speed, right? And I think that if, if as practitioners, we can help teams be ready for what if you are, what if the, what if your attackers are more skilled, and what if your attackers are faster?
Those are the two things that, that, that can help frame the conversation. Sorry. Yeah, Fernando, it's a, it's a great point, and it's one of the areas where we focus when we talk about how we are doing AI for security is you, you do have people who are not as skilled and they need help, right?
And it, ai can, can be that helper. Uh, this week I was reading news about, you know, new models and so on, and they talked about these are now PhD level and above kind of intelligence that you're bringing to this. And I was like, wow.
You know, I didn't go to that much school myself, but, um, yeah, I mean, this is it. We need, we need to enable, because you're saying like, you know, they, they're very little effort and knowledge. They're getting out and doing bad things, and we need to help people with the knowledge to, to combat against that, right?
Right. Where they're working and not have to jump out, ask a friend, not have to jump out, try and find an answer somewhere on the internet, right? Give them the answers they need or give them the insights they need, right?
Where they're working to stop more knowledge and more speed applies to both. I mean, I was talking about attackers, but it applies to defenders as well. Yeah.
Yeah. We want, yeah, defenders need to be faster and, you know, full stop, right? And, and how one way to do that is to employ ai, you know, in a, in a helpful way, um, and to, so that everyone can do what they need to do e even if the, uh, super smart guys are not around the shop that day when something happens, right?
And the other, the other piece to this, Eric, I guess is also the, the fact, and, and you know this because that keeps coming from customers and users, is not just about, you know, getting the insights you need. It's getting the insights you trust, which is the other big topic with ai, because it's not just about, Fernando used this image at the beginning saying, do we need to distinguish between AI workloads and AI workforce? Everybody's so worried that the AI is going to steal the jobs while AI is actually augmenting what I can achieve because it give, it's giving me more knowledge.
It's giving me visibility into something that usually will take me even days to just understand what is this threat I'm trying to investigate on? I will get there in second, but can I trust the answer that I'm getting and the trust topic? If I have to think, think back to the last three years of my life working in a, in ai, the trust topic is probably the biggest one always coming up.
Because the thing is I'm getting, I'm trusting, completely trusting this solution that is telling me we want to be faster. This is the thing you should look at, this is how you should solve this. These are all the things that are related to this threat that I'm identifying right now.
All of different time events, all of the context that is happening out there. It's not, the room is the build on fire. And this is what you should do is frustrated.
Should I, shall I do that? Actually? Can I trust doing that?
And trust is the real currency of ai. That's the thing. The clo the, the whole topic of the cloud thing was they asked kindly.
So that's the thing. You, you trust them because it looks like it was a human interaction. That's not, that's the thing.
Who am I trusting? And, and, and it's a phenomenal, sorry, I get excited about this. It's a phenomenal conversation because in part we're asking, uh, security teams to, to think about this differently.
I would argue that this, this discussion of trust get outside of technology, right? Uh, it gets into things like semiotics, right? Where you're, where you're talking about the, the, the, the meaning of symbols and the meaning of trust, right?
What does it mean within, uh, a workflow that we can trust what AI is generating? Now, I I I, I, I'm the Rings fan, and every time I talk about AI quote, where, uh, Elron is telling, uh, gals, I was there gals I was there 3000 years ago. Years Ago.
Yeah. Yeah. Uh, and, and because I was there when we were playing with a, with symbolic AI in the early nineties, right?
And, and of course it goes even before that McCarthy in the 1960s, right? But, um, but we have been trying to, back then we were trying to do just AI based on, on, on meaning and trust, uh, and, and expert systems. We are now into this age of, of generative AI with neural networks and, and, and their are amazing, their own right, their own.
But perhaps we're, we're, we're gonna see something. Uh, we need something different, right? We need a better, a better interpretation of how do we evaluate trust in these systems.
I think you're, you're, you're spot on. And I think agentic and the evolution we are seeing with agentic AI goes also in that direction. I mean, it's, it's cool from a technology standpoint because of course, you, you are seeing AI being at your service more and more doing things for you, you rather than just reacting to what you're asking, which is absolutely amazing.
AI is becoming proactive more and more. But are we actually ready, especially in the cybersecurity area for the right use cases to actually make the most outta agentic? Uh, uh, I, I, okay, let's let, let's pick on that.
Um, where I think that, uh, I, I agree. What I've seen is that the, we are, as an industry, we are arriving at the point where we are sort of agreeing on what is okay. And some of those things is, uh, uh, some of those is that we need domain knowledge experts yourselves, right?
To take what you understand of the domain, cmap, cloud native security, what have you, and then find out, okay, what are the rules within this domain that we are gonna enforce and where are we going to use an agent capability that's gonna use a, um, that's going to use a, a layer of the interaction with the user may very well be at your LLM of choice, right? Whatever model, right? But within it, we rely on your expertise for coding the rules of how that agent is going to be behave, right?
And then the output of that can be exactly, uh, I love your, your, your part. I don't have time to study all this. Give me this, give me that summary.
But even that summary is informed by your domain knowledge of the subject, right? You're not going to say, uh, for a Kubernetes cluster, oh, just reboot the cluster, right? Or, or, or, or, or, okay, just, just kill uh, q proxy or whatever.
No, it doesn't work, right? Because you know how the system works and that, so it's a phenomenal area where we need, I think we need both. We need people who understand the AI side of things, but we also need to understand the domain that we're, that, that, that we're talking about.
I mean, agen makes the most outta it when, when it gets in context knowledge, it's even more relevant than in all the other AI stuff. And the thing is that, that in context knowledge is not just about where I put AI in the product. For example, when people ask me, that's a classical question I always get, why shall I use your assistant inside your product in instead of going to my LLM of choice, whatever it is, and just copy and paste the same question.
I mean, actually is always the same. Does that LM knows the context you're acting into if you ask about these alert or time events or vulnerability, does he know all of your infrastructure context and what that relates to? No, it doesn't.
So that's exactly a thing. And there's no one other than us as, as people that are, you know, embedding this solution or you as a users that know exactly what you're chasing for that can give that context. Without that context, AI is blind.
So that's exactly where we can make, have an impact and make that that change. I always, you know, I always say that AI is, is not a technological challenge. It is evolving easier to stay.
That's a matter of fact. It's going to evolve. We'll have more that they are getting better and better.
And even the a GI promise that is still still out there. We'll get there. But the point is, I know one point is that even like that all of this is, is out there, is evolving, and that is true, but the real challenge is a business challenge.
Are you going to adopt that and actually understand if it's valuable for you and there mean an impact on your business, or you're just looking at that like a technological thing and want to check a box and say, yes, we are adopting ai, because that's completely changed what they're trying to achieve with that. To Go back to you, you touched on so many good points. Uh, uh, I think that one of the things that I, um, I keep coming back to is that we, what we observe is over in technology overall, and, and like I, the gray hair comes from being there 3000 years ago, right?
The, uh, what I've seen throughout career is that we keep uh, we security is, is, uh, it's like a key thing, right? On one hand, we need deep technical knowledge about specific areas and, and, and whatnot. How does EBPF work?
How do what, uh, how do, what are timing attacks, uh, uh, or side channel attacks against quantum protocols, whatever, right? But there's also this, this tying into the business, right? And they keep saying that as security, uh, practitioners practitioner, one of the things that we should be doing in this time of AI is this should be the golden age of business process engineering for cybersecurity, cyber.
We should be helping our, we should, uh, uh, be helping our stakeholders understand what their business processes actually are within those business processes. Where does AI fit? And there are places where AI fits perfectly.
There are places, there are places where AI fits. Nah. And there are places where, get this away from us, right?
The AI doesn't fit here. So to your point, it's about understanding not only the technology, but the business side of things. And, and, uh, that's a, uh, that's a conversation that requires growth, that requires you to understand people, process and technology.
I know it's the, the usual, the usual things, but yeah, that's where we're going as an industry. We are getting better. I'm, I, I'm optimistic about all this.
We can debate agi a GI is a different story, but, uh, let's talk about that one later. Pandora books. Uh, yes.
Uh, yes. Yeah. Yes.
Yeah. Let's stick with, yes, that's it. So I guess maybe the, to kind of bring it home, I, the question is, we have all of these aspects of AI that we need to be keeping track of.
Like, we need to understand how we can leverage it, how it can be leveraged against us, what we need to do to keep it secured for our people to use, whether it's for workforce or workloads or things like that. But I guess maybe the question would be, you know, what are some of the things you guys are doing at SIG to kind of advance the technology here? Uh, because one of the things that I love about AI being kind of a great equalizer is that sometimes the best innovations come from places that you wouldn't have expected.
Yeah, indeed. Uh, which is, go ahead, Ika. Yeah, yeah, yeah, yeah.
So, um, one of the things that we've done at Cystic, first of all, in the, in the realm of protecting AI is to, and because there's so much concern about something's just popping up, there's data being used to train, what's the security is helping to auto identify where there are AI libraries and packages running in your environment, right? So we've been able to do that so that then we can start to apply the security principles and the things that we do. Fernando, you mentioned CNAP.
We are a c Nena, you know, whether it's posture side or whether it's the threat detection side, right? So, so there's that. Just trying to give you a spotlight that this AI is in your environment.
Did you know it? Did you not? Well, now, you know, right?
So that's, that's the one thing, uh, uh, uh, on the other hand, and again, our assistant is something we call cystic sage. We, we, we started with sort of the, you know, ask me a question about this thing you're seeing. We talked a minute ago about context, right?
So one of the cool things is that it knows what I'm looking at, and that's important. It knows what I'm looking at and knows what's going on in my environment so that I can ask a question. And it's considering that context.
And so we've started to implement that around, whether it's threat detection, I need assistance, right? Or it's vulnerability management, which is a still a huge, despite all the goodness that we put in to trying to help people prioritize, it's still a problem. And this is where we're trying to leverage AI agents or den AI to, to do some of that tedious work for our customers.
Um, and then as well on the posture side, right? Just being able to get insights about my environment by asking a simple question. So we're trying to give the, the tooling, and I'll have Emmanuel can expand on that, just that, again, wherever I'm working, I get the right insights and I get recommendations on what to do next.
And that's sometimes the hard part. We really wanna get to a point where you've got the recommendation. You can say, make it so, or trust.
You gotta a point where it's just doing the thing for you. And if you need to peel back the layers, you can peel back and see what was it that AI considered? What was it that AI did, right?
So that there's that whole visibility aspect as well. I mean, when, when we usually always introduce, uh, s dig agent, what we are doing, a sig explaining to our customers, you know, prospects, people asking about what we do, saying that we are not substituting what they do today, or just giving a fancy way to do the same thing they could do with the product, or just using an a an API with the CLI and whatever we are augmenting what they can do today. Because if the pain is that I have thousands of vulnerabilities to manage with every single day to deal with, and I have no idea where to start from, that's a pain.
I don't want a fencer interface. I want a real help out there to cut through the noise, to prioritize and say, bring me to the action point where you are giving me all of the information I need to take a decision and move on and do what I need to do. And that thing, I, I mean, I may be biased, of course, as I'm the product manager, so my baby is always the best baby there.
But the point is that that's what you need to do. Use AI to better serve the need that we have out there in cybersecurity. And we know that speed is our currency, because that's what makes the difference between completely fail and w infrastructure down and have a business damage out there.
And instead being effective and saying, okay, I can go out there and, and be armed with a brace and weapons that Maya attacker said, we, we Really wanna, Exactly. We're We wanna flip the script, so to speak. Like today, when an alert fires, we get into action and we start investigating.
We try and figure out what's the impact or potential impact, and then we figure out what's the solution. And all of that takes time. You know what, if you get right in the alert happens, yes, I still get notified and everything I need to know how to deal with that issue is right in front of me.
And again, when I get to a level of trust, I say, okay, thank you, AI engine, we've done it, we're gonna do it. Go do it. Right?
And then, then I can go see all of the impact, all of the, uh, forensics of what was leading up to this, but I've taken action in, in really a seconds or minutes instead of having to go through that long chain. And that's some, that's the promise of, of AI and AI agents that will go out and do things for you. Well, It sounds like there's a lot that we're gonna need to consider as we think through this whole process.
Uh, there's a lot of aspects that we need to have control over. And one of the things that I know about AI is we're probably going to be rethinking this problem in six months when some new capabilities come out, or some new thing that we need to worry about is happening. But the good news is, is that no matter what happens, we're gonna keep you up to date here on Security Boulevard.
Uh, Fernando, uh, you just had a report came out that, uh, I think people want to tune into. Uh, it was, uh, one of the new signals, Yes. We just, we just published a security operations platform, uh, report, um, where, so Sotu is a, uh, we call ourselves an AI native analyst firm, and we are very much, uh, looking into where do we deploy it in a way that makes sense and, and, and so on.
And, uh, this type of signal reports, they, um, they're looking into this broader notion of security operations platform. And then from there, where, uh, where should people go? It's, it's, it's supposed to, it's, it's, it's aimed at helping people understand this, this fusion of, of, we have analytics, we have controls, we have ai, where are things going?
So that was just published, uh, uh, uh, group do com, track the signal. It, it, it's relatively easy. Define, right?
And, um, and yeah, it's been, um, it's been, uh, uh, uh, a very interesting experience. I'm, I'm, uh, I'm, I'm starting to work on the next one now, right? So the, these are, that's one of the things that for us is interesting because we can, we can, uh, work on them in a much faster pace.
So this will, uh, this will be fun, right? Alright. And, uh, our guests from, uh, SIG, if you, uh, you've talked a lot about some of the cystic platforms and products that you, you worked on, and that people, uh, should be checking out if they want to do that, where can they go to learn a little bit more?
I just meant I was waiting for the marketing guy to speak up. Uh, just do com from the very get go, you'll get the flavor of, of what we do and can lead off from there to good to dive deep. We have a lot of interesting and good, uh, uh, articles about technology.
Even, even if it's not a cystic thing, just like you wanna learn about really what is Aden ai, we've got something that will help you and put that in the context of cloud security. Alright? com.
One thing that I think you're gonna be excited about, though, we're gonna be at RSA this year. First time we're doing Tech Field Day Extra at RSA, we've got a couple of companies that are already lined up and ready to talk about it. And guess what?
We've still got four more months before we get there. So I bet you we'll have a couple more before all things are said and done. com for more information about that as well as Security Field A and all the other things that we've got coming up.
We wanna thank you all us for listening to this episode of the Security Boulevard podcast. If you enjoyed our conversation, please make sure that you subscribe on YouTube or in your favorite podcast application of choice. That way you don't miss any of the episodes when we publish them, especially if we do it right around the holidays, when you're probably looking for a break from your family and all that Turkey.
Uh, we would appreciate it if you leave us a rating and a review. That's how people figure out what we do around here. And we, we love to hear your thoughts on what you like and what you don't.
com and the Futurum Group. com, the Techstrong TV website or our Techstrong TV app. You can download it for Apple tv, Roku, or any, pretty much any smart device, uh, whether it's your iPad or whatever you consume media on.
Make sure you're following Security Boulevard on RX and Twitter as well as LinkedIn. Look for security BLVD, and there's tons more content out there. Thank you very much for tuning in, and we'll see you in the next episode.
Hey everyone, welcome back here to Techstrong tv. My friend Ryan McCurdy, VP marketing at Liquibase is joining us on this next tech strong TV segment. Hey, Ryan, it's good to see you again.
How you been, man? I'm doing well, Alan. Thanks for having me.
It's great to see you. Always, always good to see you. Um, hey, Ryan, you know, for those who haven't caught you on Techstrong TV before, give them a chance of, give 'em a flavor of, of your journey here.
And, uh, and if they're not familiar with Liquid Base, let's bring them up to speed. Yeah, Sure. So, um, you know, I've been working in technology for the last 15 years.
Spent a lot of time in cybersecurity, um, spent a lot of time in the DataOps space, uh, at a company called Astronomer, working on Apache Airflow things. And, uh, for the last year, I've been over at Liquibase, um, another really incredible open source company. Um, and for those that aren't familiar, Liquibase has our Liquibase community, which is our, uh, our community offering effectively where we automate database change.
And then, um, our commercial product, Liquibase Secure, uh, really automates and governs database change across 60 databases. So, um, we're doing something really unique in the market where we help a lot of companies achieve the developer productivity they want, um, with the automation, but then also making sure their, you know, their database change is auditable, making sure people have the right permissions to that change, making sure that nothing risky really reaches production and causes downtime, uh, which is happening a lot in the market as of late. So, um, we're doing some pretty incredible things for our customers, and we work with some of the most regulated customers in the world.
Very cool. Ryan, I know you mentioned the open source and the commercial versions URLs for those, so people can go check 'em out. com, um, you can also, uh, you know, go to GI as well.
com we have, um, our community offering available, uh, as well as more information. OnBase secure. Absolutely.
And of course, liquid based, probably the company that kind of established what we used to call DevOps for databases or databases for DevOps. So both, uh, in the market. So we've been following liquid based for many, many years.
Ryan, you guys recently announced a couple of things. Number one, this whole, you know, a burgeoning area of AI governance and governance around ai. And, and there's two pieces of it.
One is, you know, government and governance, GRC, if you will, governance, risk compliance governance around the use of ai. And then there's the using AI for governance aspect of it as well. What exactly did liquid base kinda launch here with governance capabilities?
Yeah. Uh, well, I mean, obviously as I think as everyone knows, AI is changing a lot. And, um, the, it's not that AI is risky.
It's, um, not governing change that is risky. And, um, we really allow our customers to govern change at scale. And, uh, you know, when you look at, um, AI is writing different queries and modifying structures and in some cases touching production directly, um, you know, you really need to be able to control who's making that change, whether it's developer or it's AI assisted or it's agent ai.
Um, and we're able to enforce those controls through, through our custom policies, so we're able to support our customers, uh, in that regard. I think the other piece of this that's really interesting is, you know, your models are only as good as your data foundation, right? Which in a large, a lot of cases, your database, and if you're not governing, uh, the changes in your database, well then your models can become corrupted.
And, um, you know, so it's really the, um, you know, it's, it's how accurate your models are, one, uh, and then two, it's, you know, what are you controlling that goes into production, uh, through AI potentially. So we're really helping our customers ensure their ac their model accuracy as well, just if, uh, they have AI helping with, uh, any type of development. So we're helping our customers both on those fronts.
Um, we also are able to provide schema level lineage so they're able to track the full history of that change, uh, the who, what, when, where, and why, um, uh, to ensure the accuracy of those models. But also, you know, you have things like the EU AI Act and NIST who are publishing, uh, regulatory guidance on ai. Um, so for the customers that are, uh, needing to achieve that, um, that compliance, we can help there too.
So that's a, a big problem in the market that we're solving today. Uh, we've also introduced, um, some new capabilities as well, uh, to help, um, some of, you know, the velocity our customers want through AI change log generation. So, uh, we had announced an AI change log generator, which was built on our 15 years of frontline experience, uh, which is really, really incredible.
And you basically de can describe it and deploy it, um, and it's done in the exact liase way you would want, obviously making, um, you know, a change log, uh, creation happen rather quickly and, uh, very accurate. And, and when you use that with Liase Secure, uh, it's governed and controlled. So, um, we have some really, really exciting updates for our customers.
Excellent. Excellent. So you guys also announced in the same vein, uh, an integration with Mongo MongoDB.
And, and look, MongoDB is a company that needs no introduction to our audience or anyone in tech MongoDB. You know, I, I still remember when I first heard MongoDB and the whole NoSQL database thing. It's gotta be back in 2008, maybe, something like that, right?
Um, but you guys announced this integration and it, I think it, it's around the AI governance stuff as well. Talk to us about that, Ryan. That's right.
So, um, MongoDB obviously is, uh, an incredible technology out there. And, uh, we built a strategic, uh, integration with them, uh, that brings AI governance down to the database layer. Uh, so teams can move fast with AI while keeping, you know, their data safe, consistent, and fully traceable.
And I think, you know, the thing with Mongo is it's, it's great for fast moving teams that want to remain flexible. You can shape the data however you need. Um, but the challenges as teams grow, things can drip.
So fields, names change, collections evolve differently. So that flexibility really needs some light structure so things don't go sideways. Um, and Liquidate Secure brings that structure in a way that doesn't slow anyone down.
Uh, so on one hand, MongoDB stays flexible, uh, and then we make sure that changes are tracked consistent and safe. Um, so we're really, really excited about what this means for, um, our customers using Mongo, um, whether, you know, they're supporting their gen AI applications, um, or whatnot. But, um, it's a, it's an incredible partnership and we're really excited for it.
Um, we know that, you know, there's, this is a, a big problem in the market, and we're excited to solve it with Mongo. Very cool. Now this has already been announced and it's available to use right now?
Yeah, That's right. Yeah. So available on our website.
Um, and, uh, you know, we, we just probably, we actually have a webinar coming up here in December that people can join to learn more about, um, this integration with Mongo. And, um, we also have a bunch of content on our website that, um, folks can engage with too. Uh, that speaks to the integration a little bit more, but it's available today, uh, and we're excited for folks to start using it.
We are too. com, where do they get to the Mongo integration stuff off that, you know? Yeah, so we actually have, if you go under solutions, there's a, um, uh, an option just to select MongoDB, uh, so we have a whole page dedicated to it.
Very cool. Ryan, what about it's conference season? You guys been out anywhere?
Are you going anywhere? Um, yeah, we've done like some local shows and things like that, you know, really, um, working with kind smaller development communities. Um, there's so much happening in the market though, um, you know, there is Crazy, it's noisy and it's crazy.
It, it is. And, you know, sometimes these shows, um, it's, uh, it's, it's, we wanna go be with our audience, and sometimes these shows don't always allow you to do that. Um, but, you know, I think just recently we're having a lot of conversations, um, with different engineering leaders on the CloudFlare outage, the app, uh, and the database permission change that took down, you know, a part of the internet and, um, You know, including some of the text strong sites, I'm sorry to say.
Right? Right. And, you know, we're, um, it, it, I think it's a, it's a, uh, it's a big challenge that, that folks face where if they're not governing that foundation layer, you know, it, it can break a lot of things.
The blast radius can be pretty significant, and a lot of companies don't actually govern database change. Um, and something as small as a database change permission can have a really significant impact. So, um, now we help our customers solve this and, uh, you know, we're having a lot of conversations around this today.
Uh, but we'll, well, I Mean, just so people know, right? This, this particular incident revolved around, I don't wanna say something is trivial, it's not trivial, but something is, you know, let's say down the, you know, from the very top of the kind of things you would think about, this really came about with a database permissions change, right? That's right.
I'm wrong. Right? And, and, you know, this happened to one of the most resilient companies in the world, CloudFlare.
I mean, think about how hard in their infrastructure is. Um, so, you know, most companies are up to that caliber. And, uh, when you start to factor in things like AI and you know, how humans can actually keep up with, um, governing ai, um, you know, that, that makes that even worse.
So, um, we are really helping customers close that risk. And in some, in a lot of cases, actually, uh, being a trusted AI adoption partner, we work with a lot of really regulated companies, and they know the risk, and they understand the risk of not governing, governing a ai. So, um, we support that.
Excellent, man. Excellent. Um, you know, look, that was this particular incident.
Akamai was down a couple weeks ago for another incident. This happened to CloudFlare before. I think another thing, you know, just Ryan, that we, we concentrate so much in such a handful of companies, right?
Think about the amount of traffic, the, the percentage of TRA internet traffic that goes through Akamai and CloudFlare together. It's almost half of the internet. And you, you, you think about that, that's, you know, that's a not quite, it's a double point of failure, if not a single point of failure.
Yeah. But it's something we need to think of in terms of supply chains and, and resiliency and all of these things. I, I couldn't agree more.
I I actually think, um, there's gonna be more of this as there's more pressure on the database and more pressure on infrastructure, um, to the point where you could, you could make the case where it's, it will become a national security threat. So, you know, if America wants to lead in, um, ai, while we really have to look at our infrastructure and can our infrastructure keep up, uh, can we have the governance at, you know, the database layer and some of those other critical infrastructure to actually scale with it, um, those investments are critical. Um, so it's, it's a exciting time.
I think a lot of people are a little bit nervous about, you know, AI and adoption of AI and, um, no, we're here to support them in their, in their journey. Um, but yeah, what a, what is time to be alive? Absolutely.
Hey, Ryan, I gotta run onto my next interview. It's great seeing you if I don't talk to you before, have a happy Thanksgiving and hopefully before the new year and holidays we'll get back together. Thanks.
Appreciate that. You have a great Thanksgiving too, and talk to you soon. Alrighty.
Ryan McCurdy, VP Marketing Liquid Base here on, uh, liquid Base's, new AI governance capabilities, as well as their partnership with MongoDB. You're watching Text Drunk tv. We'll be right back.
Alright, so ai, um, I'm gonna zip through some of these, but let me just frame kind of, uh, there's a lot of things happening in ai. There are lots of different kind of, uh, places in the AI stack you can play what Traffic is doing. In a nutshell, because we are a runtime gateway provider, our value is in being able to address this problem from a runtime perspective on how we can allow customers to run AI workloads in an agnostic way.
So they're not vendor dependent on the, the gateway, uh, part of it. And we'll talk more about that. Uh, but in essence, like what's happening in the AI world, there are lots and lots of models that are coming out, right?
So part of the talk that we did this a while back was think beyond the model. There's gonna be models everywhere, right? Like if you look on hugging face, I went there today and this number continues to grow.
Like they're adding almost a hundred thousand models every month in hugging face. 2 million models. If you go to the Nvidia kind of curated model set, that number is about 200 plus.
The point of the story is that models are going to continue to evolve and change. Uh, you cannot hard code and you should not, I, uh, I should say hard code your application to a particular model. 1 coming out.
Like, if you hardcode things to your model, you're constantly gonna have to go back and refactor the application to make the change. So then that question becomes, well, okay, decoupling makes sense. Where do you do the decoupling?
And this is where we believe that we should decouple at the gateway layer. 'cause that gives you the most operational freedom and the most operational leverage to be able to define the routing logic on which model that you wanna route this particular application to at the gateway layer. And it goes beyond just routing, right?
With the, let me kind of zip through some of this stuff. Uh, and I wanna, in the interest, so I'll come back to this. So this is a reference architecture.
You look at what happens when you are routing, uh, AI traffic routing is the last part that you do. You know, whether this goes to let's say GPT-3 or sonet running in a WS bedrock or running in your local kind of, uh, environment or some other public cloud. But all the things that happen before you route the traffic, that's where the gateway really shines, right?
The first thing you'll see is, uh, the authentication logic, right? Just like we talked about with API gateway, you still wanna authenticate the user. You may need to rate limit them.
Then in the case of ai, like you want to have these guardrails that say, okay, well this is not a, uh, not a accepted conversation with the LM Like your enterprises are putting guardrails in place saying, I'm just not gonna use the AI for everything. Or I have certain policies where let's say you define, uh, a finance agent and that finance agent should only be able to respond to finance type questions if it starts getting legal questions. You wanna stop that from even getting to the LLM.
So all of that type of authentication and security type policies and caching, by the way, 'cause you don't want to get penalized for the same question over and over again. There's no reason to consume tokens for the same question that comes up. All of that stuff.
You have two choices where to put 'em, you can definitely put 'em in the application. Like if you're just hacking something together over the weekend, makes sense. But if you're putting it in production, this is where you want all of that logic to be at the gateway, because that's what the gateway is known for, is designed to do that is scalable.
It performs very well. And you as an organization would get all of that unified control and the observability on everything that's happening. So you route everything through the gateway, which, uh, sorry for the, maybe it's not coming out clear here, but if you look in the box in the middle that says traffic hub, and you look at from the application standpoint on the left, and let's say it's a rest call first is gonna get authenticated and perhaps rate limited, there's a WAF in there too.
If there's something you wanna block there, then you go through this LLM guard, think of this as a composable pipeline, okay. Of traffic just flowing through and it's just kind of acting, uh, in a chained sequence. Then you would go through the LLM guard.
And here we have done the integration with the NVIDIA safety nims. You know, there are three specific Nvidia safety NIMS out there today. One is for topic control, one is for jailbreak detection, and the third one is content safety.
It goes through that. Then you may want to take it through a caching layer. And then you route, and even when you're routing, you have a bunch of different options for routing.
1 as their workhorse LLM model. 2 comes in, the question is how do they absorb that change? How do they integrate that change into the environment?
You know, if it's baked into the application, they gotta go back to the application and refactor it. But let's say they have decoupled it and it's at the gateway. What do you do?
Then? You can do many things. You can do a simple one, which is a canary based routing.
2 and let me run that for a few days. Let me take, collect some telemetry. Let me see how the, how the user experience is.
That's one way of doing it. There's two other advanced ways of doing it. You can do it based on identity based routing or time of day routing.
And let's go through those in a little bit more detail. Quick Question, with the routing there, can you inject transforms along the way as well? So if you are going to one model versus another model, you may wanna manipulate the system prompt in some fashion for that second model.
Uh, We don't get into that. So we can do header manipulation, we don't get into the body manipulation. Uh, and you'll see those are the kind of things that are gonna add more latency, uh, going through the gateway itself.
Uh, can it technically be done? Sure. But we don't get involved in that yet.
Okay. Uh, Saddi, can you back up just one bit? Uh, guy Courier, uh, also at Futurum.
Hi Mitch. Hey, um, so you call this an AI runtime reference architecture. Um, do you have a distinct one that, uh, includes the MCP gateway in it?
Yep. Um, that's, I'm gonna show that next. Okay.
Because AI's AI means is pretty general. Yep. Should include agents.
Yes. But you're gonna have a new ano a second reference architecture to show us in A bit. I'm gonna, I'm, It's called something else.
It should be all one. To your point. There should be one AI reference architecture that includes MCP, includes AI and also includes API gateway.
And I'll show that to you in a second. Yeah, I think there should be either be one or a hundred. So one one is good for, for this venue, yes.
Alright, Cool. There's an extra layer that MCP brings that I wanna introduce before I show you that. Okay.
Uh, that would make a lot more sense. Great, Thanks. So I talked about canary routing is one way.
Uh, let's look at identity based routing. You know, this is where, you know, there's a bunch of code here. What really matters is you look on line 20 and line 28.
1. So this is where you can do identity based routing. And everything I'm showing you here is just code, right?
So this is just a CRD or a YAML file. And all of this could be done through A-C-I-C-D-A time of day routing. 2 into the model, but you don't wanna really risk it during your normal, uh, business hours.
2 after your prime hours, and that's what time of day routing does line 20. Again, it's saying, okay, during prime hours, and this example, I'm showing you a different model. I'm saying, okay, send it to mytral, small off hours, mytral medium.
So just pick your model, swap it in here. But the concept stays the same. And there are many other ways to route, but these are, like the three that I showed you are the most common ones that you can route based on identity based routing is becoming more popular.
I think canary based routing is the most default. I think that's the most simplest to do. Identity based is more sophisticated, but it's also much more powerful and much more flexible.
Customers have any interest in doing, uh, kind of performance based, like this is taking too long to respond. Let's go back up. Yeah.
Model for, so that could be your standard kind of failover workflow where you try this, this doesn't work, then you go to that and what you're saying is, uh, latency based routing. Uh, so we have that in our roadmap, uh, where we can actually do it based on latency. Okay.
And both in a proactive manner and a reactive manner, which means we could be, we could have sensors that always, there's measuring the latency, uh, between point A and point B, and you can set a threshold saying, I'm gonna route to this if I can predictably say the latency is gonna be beyond, below this number. Mm-hmm. So those are some advanced things that we have in the roadmap.
Okay. And latency, I mean, some I usually hear it referred to also to as performance based, meaning latency could just mean the latency of traffic. Yep.
You know, or packets flowing. Performance usually implies like, this takes too long to get a response or Yeah. You know, it has three retries and I'm not gonna let the model try at third time or whatever.
Absolutely. And that, those are exactly the things you wanna do at the gateway. Yeah.
Okay. Yeah. Latency is a, a prerequisite to that, but, but you're absolutely right.
You use that as a base knowledge and then you build on top that advanced lo logic. Okay. Okay.
So I zipped through a lot of this stuff, but, uh, I wanted to actually make sure that, uh, I shared this concept of, um, uh, the runtime environment. You know, when you're deploying ai, uh, there's the gateway runtime environment that we all are familiar with, right? AI gateways that represent the AI runtime environment.
But there's the model runtime environment. And the objective of the model runtime environment is to optimize for the inferencing to make sure that the models have high availability and high resiliency, right? Traffic doesn't operate in this, this is, you know, the task of kind of the, the other platforms out there that are giving you the ability to kind of stand up a bunch of GPUs and being able to get maximum throughput of the tokens and get maximum throughput of the GPU environment.
Uh, and the LLM that is running, okay. Traffic then takes over as soon as the LLM is exposed to the outside world as an API. That's where traffic comes in.
As you guys all know, like all of these models are being exposed as A-P-I-A-P-I has become the interface. And this is where traffic comes in and says, okay, the abstraction of that model as an API is what creates the need for having an API level availability. An API level resiliency.
And this is where we come in. Both environments are equally important. You run into problems though when you try to embed them as there are some platforms out there in the market, I'm not gonna name them, but that try to embed part of API runtime environment into their model runtime environment.
Um, and what you end up doing is, you know, you go with the least common denominator and you end up getting some functionality, but you lack in a, in some major ones. So the three questions you wanna ask yourself to know if this is a limitation that you're running into, number one is can you freely share these endpoints with your developers through a developer portal? You know, just like you would any other API, you know, does that experience exist?
And what you'll realize is no, uh, and if it does, it's very, very archaic. Number two is, can you actually integrate with your, uh, identity provider for doing the API token generation? And I'm not talking about the token for the LLM, I'm talking about the, the API key or the jaw token that allows you to access the LLM as an API.
And the third is like, okay, what kind of observability do you provide? Uh, is it vendor specific or is it vendor neutral? So these are some of the challenges that you'll run into with this Saddi.
Can I, can I probe a little on, um, on ai, ai ai API mm-hmm. Um, yeah. But models as APIs, there's, there's, there's something a little funny sounding that to me.
'cause I, you know, I think of an API as highly structured writing re requiring a a, a structured and compliant or conformant, um, well-formed, uh, uh, request. Mm-hmm. Um, in order to operate best.
Um, but if you think of a model as I, I remember how you put it, it's pretty clever on the, I think on the next slide, um, if you think of, uh, models, uh, APIs as as, uh, uh, a Abstraction Yeah. Model. Yeah.
I mean, you know, uh, I, I think of an API BA request to a model as unstructured largely, um, you know, plain language, plain English, what have you, you know, a little chat, like it's a prompt rather than something structured. But it's, uh, But it's, is this a semantic issue? A way for us to shift our thinking as as to what we are doing?
So there's parts of it that is highly structured. There are parts of it that are unstructured. Right?
The actual call that you're making to the LLM. So let's say you ask what is the capital of us? And IT response to you when you're sending that question in, it's going inside a highly structured JSON, uh, and, you know, wrapped in inside an API that's going to the LLM and then the LLM is computing through tokens.
What the answer is. And that's coming to you, but it's also coming to you in a structured format. But the answer is gonna be variable depending on your question.
So essentially it is an API interaction, but the values are dynamic. Your question, You said highly structured, JSON, you, you that, you lost me a little bit there in the sense that Yeah, sure. The package might be JSO highly structured.
Hmm. You know, I, I don't know, like, uh, um, you know, highly structured JSONs are like big complex require a lot of validation. There's a whole, what I guess I'm trying to say is that the payload of that JSON is doing a whole lot of work.
Yes. And in conventional API needs to be done in a structured way. Yeah.
So there's, so I look at this as what's happening behind the scenes and what's happening at the interface level. Uh, to me, if I go into, um, so let's say if I do a curl command right from my machine to an L-L-M-A-P-I, I am doing it in a very structured way. It's, I'm always doing it the same way.
I'm passing it the same parameters. Mm-hmm. My question might change, but the way I'm calling it is always staying the same behind the behind the scenes.
What it does, what the LLM does with that is a whole bunch of other stuff that I don't see, but the abstraction of it to an agent, to a user, it's a standard API that you're calling. And that part has to be standard because otherwise Yeah. You don't know how to model against it.
You don't know how to code against it. You don't know how to integrate that into your application. So that part has to be standardized, which it is.
And that's what the API is for. This is a really useful semantic shift in my opinion. It's a really useful semantic shift.
I just wanna distinguish that from maybe a more technical question of, Hey, we're gonna transform your prompts into API requests, you're not doing that, you're not really changing that, but you're encouraging us to think about this in a different way. So I look forward to seeing how What I, what I think is interesting is when you're talking about inspection of the prompts mm-hmm. And the responses that come back from those prompts and checking to make sure that you don't have someone trying to pull financial information when they shouldn't have access to that, or they're asking for something that would violate policies that you have within your organization, being able to check those contents and look for prompt injection attacks and other things that a typical gateway wouldn't know how to search.
Right. Contents that way. 'cause it's looking at headers and other components of the JSON payload.
Yeah. And that's why like, uh, so it's a great point you bring up. So what the gateway is really doing, it's what it does best.
It is orchestrating when that traffic is coming in, it's orchestrating the set of checks that it needs to go through. And by sending that traffic to endpoint that behave as a wells understood API. Mm-hmm.
So, you know, in the NVIDIA safety nims, you know, those three that I talked about, topic control, jailbreak detection, content safety, each one of them exposed themselves as an API. So what the traffic API gateway is doing is orchestrating across all of them, sending them the user information, whatever came in unfiltered to them and saying, Hey, check this for making sure it's safe. Making sure you know it's the right use.
Uh, making sure it's not doing any kind of gelb break detection through the prompt engineering traffic's not getting involved in that. All it's doing is orchestrating and saying, Hey, check this. Mm-hmm.
This, Hey, API X, check for this. Send me a response. If your response is good, I'm gonna let it through.
If your response is bad, I'm gonna stop it. Is that filtering happening in parallel? So is it checking multiple signals at the same Time?
Yes, it can. So, uh, you can chain them in parallel. You can do linear, uh, you have different options.
Okay. Cool. Yeah, you had a question?
I did have a question. So I'm Gina from Digital Sunshine Solutions. My question is, um, the title of the slide says No AI without APIs, but everything you've described has been generative ai.
So is, are we specifically talking about prompts coming in from externally, perhaps from a, a chat box that's on a window for customer support or whatever, um, going into an LLM? Or do you also cover, uh, more narrow AI situations, maybe, um, uh, just a plain type of agent that doesn't have the LLM behind it, but it's just doing some basic lookup or, or that kind of thing? Uh, so in all of these examples, there is an LLM, there is an LM component.
So an agent has to have the intelligence of an agent comes from the LLM. Okay. So, so this is just, so this whole presentation or is your product is just about generative AI and not about other types of ai?
Uh, correct. I mean, so we are, and also we're not just about ai, but yeah. This part of the presentation.
So what we offer is an API gateway, which can be, um, you know, manifested into an AI gateway because an AI gateway has a lot of the API gateway foundations, and it just adds the AI ness on top, like the extra stuff for ai. But it is still a gateway, which fundamentally means you have an input and an output. Uh, so if I go back to this, uh, this diagram, you have an input and an output.
The input is coming from the left, like you said, you know, it could be your chat users, it could be an application where they are trying to interact with an LLM with an AI model. And before you allow that interaction to happen, you wanna put a set of safety rules, right? And that's what this is, right?
It's a bunch of different policies, let's, let's call it, for lack of a better word. And that policy has routing logic. The policy has safety logic built in all of that stuff.
Got it. But it's not ai, it's just generative ai. Right?
Um, I mean, when I think of ai, I think of generative ai. Yeah. Most people think it.
So for me, like, you know, there, there isn't a distinction between the two. Okay. Uh, but, uh, you guys asked about some questions on MCP, so let's go there, right?
Because what's happening with MCP, uh, the, if you focus on the left side, MCP really comes in specifically for agentic workflows, which means there is an agent trying to achieve an objective. And that agent now has to do three things. The agent has to talk to an LLM, the agent has to talk to MCP resources, whatever you expose, and then the agent has to talk to your backend APIs as well.
Traditionally, if you just have an API gateway in your architecture, you're not protected because you're only protecting one of the three kind of pathways. Typically, gate number three at the bottom is what most companies would have, which is an API gateway. So what it can do, it can protect the communication between an agent and the backend APIs, but it has no visibility or no way to control what the agent is doing with the MCP server and the resources behind it.
And it also has no knowledge of what the agent is doing with the LLM itself. So this is where we have introduced this notion of a triple gate pattern where you need to have three different gates for your agentic workflows. Gate number one really is the agent is talking to an LLM.
And so you can control that with the AI gateway, you know, which we just talked about. The third one, the agent talks to the backend, API, you know, that's well understood problem. This is your regular API interactions.
The second one in the middle, you know, this is a little mystery, right? Because MCP is just coming to the, uh, into this, uh, you know, the party here, so to speak. Uh, there's a lot to be understood here.
Uh, it doesn't behave like our typical API, it has a new language, a new protocol. So how does the agent talk to these resources and how do you govern that? How do you put in the set of rules and policies and stuff that allow that interaction?
This is where the MCP gateway, this is the job of an MCP gateway. And so what we are doing at traffic is giving all of these, all three of these kind of capabilities in a single binary, because the last thing you want as a customer, That's what I was to Deploy. Yeah.
Three different gateways. Yeah. So Guy Ker again, future, I was just thinking this, which is, these are three names for the same thing.
Um, it'd be three names for the same thing. Yes. If you can come with a better name, like I would love it.
But they are, or A-I-M-C-P-A-P-I Gateway, API Gateway, MCP edition. They are, see, they are three distinct capabilities that are typically not in the, if you look in the market today is very rare that you'll find all three of them in the same product. I Just feel, I feel like the, the scope, let's call it the scope, or maybe there's a better word for it, differs among the three.
Absolutely. It'd be really helpful for you to point out that that sort of payload inspection, since we're working at the application layer, you know, the prompt is the application in a sense and payload inspection and, and routing based on that. I mean, that prompt is, that's brilliant.
So I extend it to, to, to, you know, um, uh, agent Agent and the agent agent and, uh, modeled agent interaction and stuff, the sort of thing that's an MCP, that's a little bit more prosaic. MCP is a protocol, obviously that's in the name. Um, but it has particular elements to it thanks to its connection to AgTech and everything.
So, so all of these kind of need to do the same thing. But, um, what differs is, um, the, uh, the, um, the, the, the boundaries that you're putting on. Yeah, like I said, the scope, yeah, the scope is different for each one.
I would describe it, I would describe it as like three different use cases you're controlling. Mm-hmm. What models can agents talk to?
Well, you're talking about what resources can an agent or a model access through an MCP or MCP servers. And the third is what APIs can an agent use to go to a traditional API. So it's, you know, first one is kind of what models can I use?
The other are what resources through either traditional or non-traditional, right? Yeah. So I think, yeah, no, this is, I would Describe it as like use cases for, and your point is it's in one product, not two or three different products.
It's just that when you put MCP or AI on the name, they can sell it better Always Know. And I'm in favor of that. So, and charge Twice as much, you know, and, and in a agent workflow, you need all three of those, all three use cases come together.
I'm not entirely joking that you can sell it better. You're positioning it for these different use cases in a stronger way than just saying that our a, our API gateway ism, C-B-M-C-P capable AI capable, I, I think it's stronger to, I I don't normally advocate for that sort of thing. Um, but you're, you're, you, you are broadening the positioning of what you do and there's a technical foundation for it and tactical proof for it.
Yeah. You know, you know what, you know what I mean? It's, it's, it's beyond a scenario.
Your scenario. Well, What's interesting too is that it's a, it's a, uh, an emerging market because you, you have a lot of different people going after the same parts of the same thing, right? You've got the Nvidia DGX clouds of the world, that that's more the tied to the specific hardware resources.
You've got the vertexes and sage makers and Bedrocks who have, you know, a gateway for, part of a gateway, right? Mm-hmm. For access to models and MCP servers.
Then you have emerging agent control planes, which are also starting to apply some of the rules and guardrails, right? Of some of what you're doing, not traditional APIs. And you're trying to position it as, yes, you're gonna need all those things.
And do you want a different solution in the Google cloud versus the A WS cloud versus AMD's hardware versus NVIDIAs, and then you have your traditional applications. Here's one model or one product. Yeah.
One, one way of doing it that we'll work on all those Environments that abstracts it away. That's your value process. Yep, exactly.
One of them, right? Exactly. Yeah.
It's everybody's fighting over this territory right Now. And MCP really pushes the boundary of this because it forces you to think about this holistically, right? You cannot think of this as a silo because in an MCP architecture, like this is a reference kind of a high level reference architecture that you see the triple get pattern working.
Like first you gotta go through the AI gateway, then you gotta go through the MCP gateway checks, then you go to the API gateway and your resources, the data layer where your MCP server and the resources are staying, where also your APIs are there. So you have to authenticate through these three layers for the different scopes that you are trying to achieve here. I think there's an argument to be made too, that while MCP and other open protocols are adding more security, needing to beef up their enterprise level security, that's gonna vary by implementation and through a gateway or one common gateway that you can now apply security rules and guard rail guardrails and things like that.
Kind of, you can deal with the inadequacies of different implementations of, Especially if TP servers, right? Especially if there's documentation behind it. So if you have, and I don't know that there is, but if there's a way to, to have that observability where yes, we actually did have this communication pathway com, this is all that was allowed and this is Right.
I Think that trail That, that's a big deal too. Yeah. Yeah.
'cause if you're not having, if you don't have the centralized picture, then you're not gonna have centralized auditing or the observability in it. Okay. Um, let's go to our last topic.
Um, I'll just say a couple things here. It's really important to think about the runtime environment as being strategic. Like how your customers design runtime environments are very important.
Our recommendation is to decouple the API runtime from the model runtime because the assumption here models are gonna continue to change. So you need to bake that rate of change into, into your infrastructure and this one model to rule them all. That's a myth, right?
As we all know, like that's not gonna happen. You may have temporary advantage, but you're not gonna have long-term any, no model's gonna have a long-term advantage given the pace at which we're seeing things move.