Techstrong TV November 7, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone has AI killed the Innovation Star you're watching Textron Gang. Hi everyone. Happy Friday.
It's Alan Shival and welcome to another text on gang. We've got some good stuff to talk about today. Start your weekend off bright and cheery or down and depressed either way, but nevertheless, the weekend's coming.
We got our Great Friday panel to talk about it on. You know, Fridays really are, that's panel of the week usually, and a lot of it is because of, of these folks right here joining us from, it looks like a subway brick rack background, probably in New York. Ira Winkler going across the other side of the country, probably up near Seattle.
Our good Fred, Fred Wilmont, and it looks like she's home in Colorado, the one in only Kimberly Bates and of course, high up in, uh, his, his attic in Harrison, New York. Mike Ard, gang members that, people's Republic of New York. So there you go.
The People's Republic of New York. Well, that would be the city. You're kind of, Hey, We were the People's Republic of Boulder a long time ago, So yeah, you were, I remember when I first started coming to Boulder in 2001, it was very much the People's Republic.
Um, anyway, yeah, it's, it's Friday, but this big, it's just big things happening in our world beyond the, the election this past week and some of the results there. Um, Mike, why don't you kick us off here. Well, it seems like the tech leaders are all calling for innovation once again, that happens to spend a lot of money in this time in digital health sector, but you have a post suggesting that maybe they should, uh, you know, heal their own issues first before we get too far into other people's problems.
But, um, you know, you wrote this piece, I think you're spot on, but, you know, walk us through it all right, well, you know, and by the way, the piece is up on Techstrong. It, it's called Tech Heal Thyself. And I also am talking, I talked about it on our shim, my shimmy says episode this past Thursday, which by today you'll be able to see on YouTube and, and everywhere else.
It really grew out of a book review on a New York Times article. Uh, the book was written by a former, I, I think it was a Biden administration antitrust person. And I know, you know, they're not in favor these days, but basically he was lamenting, you know, that we need the government to kind of step in here and, and stop this oligarchy of big tech vendors monopolizing ai and, and while we're at it, throw in robotics and quantum and everything else.
And, and the real issue is, is this AI revolution that we're seeing has become such a big boys game. The, you know, the bar to entry is measured in the hundreds of billion, billions of dollars, not even the hundreds of millions, right? The play in this, you've got, you know, circular things where, you know, Microsoft gives open ai, a couple of hundred billion OpenAI buys a couple hundred billion dollars worth of Azure services.
The same thing goes on with Oracle and AWS and Anthropic and Meta and Google, and they're all just kind of passing the salami around here, hide the salami, playing with this money. But if you don't have that kind of dough, if you don't have that kind of gravitas, how do you compete? How do you play in this market?
You know, one of the great things about tech, I said it before, I'll say it again, is that you could get two guys in a garage and they could reinvent an industry or, or launch a new segment of industry and, and make untold riches, whether it was was and Jobs or Serge Sergey and, and Larry or or whoever, you know, bill Gates and Paul Allen or whoever we've always been, you know, that's been the promise of tech is that the little guy can become the next giant. Yeah. Allen, I'm gonna disagree with you.
If I could go ahead and let me tell you why. Because what these people are doing is very specific to creating the infrastructure in many ways. It's kind of like saying, oh my God, I was cut out of the telephone system because I can't put together my own internet provi.
You know, I can't put together my own lines and cables and everything. And I think that that's the more critical aspect of this, that what they are doing is enabling other people and smaller people to use, and I hate the term ai, but they're allowing people to use AI related technologies and providing the infrastructure required for people to develop and deploy their own models, not that they are, you know, locking other people out. And I think that's a difference.
So, IRA, Let's go. com. It was very similar, right?
You had, you had big, you had at t the original at t before it got broken up, right? Mabell, and, and they broke that up. And you had the, the CL but you had, it wasn't just a handful of companies that controlled all the fiber, that controlled all the data centers.
You had the CL and the IL and all of these other carriers, if you remember those words, right? Who could, who could bring connectivity to your office or your house or what have you. Anybody could open up their own.
How many little ips did were, were, were started, you know, some became big, some didn't. How anybody could be a hosting provider and open a data center. You did it, it wasn't measured in hundreds of billions of dollars.
You didn't have the government with their thumb on the scale owning equity in these companies. So not to get around the government side, but I, I, Alan, I think, and I'm gonna agree a bit with Ira about what he's saying is that this is a level of infrastructure that's being put in place because none of this matters, in my view, until it executes on a use case out in the wild. And then I have the ability as a company, as a user to go look at, you know, the, let's say there's five LLMs out there.
There's usually only, you know, you know, the, the, the rule of three is usually there's only three big companies that will have that big infrastructure. And, um, you know, going back to Jack Welch, if you want 1, 1, 2, or three, I'm ing you. And so where we're now in that is that they're building this and we, we actually need them to be this strong because if we're gonna keep ahead of China, which is a fully government institutionalized LLM sys system, we need the strength of these very large companies to keep on that s stay on the edge and that money behind it, and then all the other, so Lemme get this right, Kimberly, you're using a red scare to, to, no, I'm not using, No, I'm not using just the red scare.
I'm saying that my biggest worry about where we are on the AI bubble is whether or not this is gonna actually, all this investment in these huge LLMs is gonna end up in use cases that we are actually using it. Because until it goes to use cases that infrastructure is of no value. That's kind of like, you know, what Sun and Cisco did and everything else in 1999 and 2000 where they were just shipping gear constantly, and this is like shipping gear.
com, it was the real applications that got out there, there was, there was a stability in that internet and how it was being used. I see that we're in the same place here with the ai. And so I'm very anxiously looking at the end users to see how are they using this technology?
Where is this going? Because that's where the real big value is going to be. I think there's a couple of important points there, Kimberly, I like, uh, around the story that, uh, Alan, let's use your analogy.
So these big companies are laying the fiber, right? Deep sea fiber across, uh, transcontinental fiber, you know, these types of things. But until somebody is going to be able to weaponize that, it's akin to the same problem of the last mile bottleneck to get into your ECT conversation, right?
And so when we think about what that means, um, the use case that Kimberly's talking about here is the last mile bottleneck. Why did we have to figure out how to solve a last mile bottleneck with, you know, plain old telephone, uh, pots lines, right? Because bandwidth demanded it, because applications that demanded that bandwidth demanded it.
And, and in this particular case, and we're building the fiber lines for all of the, the, the telecom model across the, the US and the globe. And these data centers are a part of that, uh, fabric, uh, for the purpose of being exposed in that way. I think the use case, the last mile bottleneck is absolutely the rationale behind the innovation.
And I i it's also cyclical. We've seen this before where, you know, at first we, we thought everything should be centralized, and then we thought everything should be decentralized, right? 32 70 terminals and, you know, frame relay circuits and all these things, and then all of a sudden, right, you know, we, we have this very decentralized way of doing things, but it creates a whole set of, of, of issues around how to manage the economy on scale.
So we get, you know, monolith, uh, behavior. Again, it's, it's cyclical. I think we're in that right to frame it up as we're in this process of, uh, you know, aggregation and, and maybe, uh, extraction.
But I think the value proposition is what happens as a result of that, which we don't see yet. I have one concern, it comes down to price, and to your point, Kimberly, I'll use your cloud example to prove the opposite. So I have five big providers of LLMs, and right now, to be honest, they are subsidizing the cost of ai and they're charging people less than it is for them to actually produce that thing.
And eventually they'll run out of VC money and start charging people what it's gonna really cost. I have noticed this interesting trend over the years. We had three big providers of virtual machines, and you know what, amazingly, the cost of virtual machines never changed.
No matter how much alleged competition there was, it was always the same. I think the same thing's gonna play out here. I think a big number of companies are gonna own access to these GPUs and their LLMs, and people are gonna be like, Hey, suddenly I'm getting gouged on pricing and I got nowhere else to go unless I go build smaller models and get my own systems and put my own LLMs over there, and then I'm not gonna be hostage to these guys.
That's what I think. And I would agree with you, Mike, on that. I do do that.
This is a fair, very fair point, um, in terms of pricing, et cetera. Um, and I also agree with you in the smaller models of seeing these, you know, we have the very large MA models and then we have the unique models that are going to be by each industry. We haven't gotten quite gotten there yet.
I mean, we're starting to see a few of those coming out. And as those do come out, yes, that will drive comp, you know, that will drive innovation. It's out there.
I'm sorry. I also think this whole pricing model around tokens is just flat out crazy. A token is an input and an output, and if you're gonna pay for every input and output, you're gonna wind up spending a fortune.
So there's gotta be a better way. But the, so here, there does have to be a better way, Mike, but the problem is when you, when you anoint these companies is too big to fail, and the government, you know, takes off the referee's striped shirt and puts on the team jersey, right? You, you don't, you don't open up to allow a better way to happen, right?
For, for all intents and purposes, what we're building in the US model is a Cadillac, right? It it's a very expensive, very heavy, these big LLMs. It may not be, it may prove may that it may not be the best way to do this, right?
You know, when when the Chinese deep sea thing came out, it struck, you know, it struck fear in the hearts of the US AI industry. Like nothing we've seen since Sputnik, you know, had wor a LeBron up all night. But, but that's healthy.
That's, that's what the healthy market does. People innovate, they come out with new ideas, with better ways. They out innovate, they out nimble, the, the be myths the big guys.
But what I'm saying is this time the big guy's advantage is so ingrained. We're not looking at the government for antitrust. Well, who expects that?
But I am looking for a level playing field. I am looking to give the little guys a shot to out innovate here and come to market. I'm worried that we're not going to, we're not going to allow these people to come to market because the, it's, the decks are so stacked.
They, they've built the barriers so high. So who is, who can assist in, in this? I mean, we're talking about VC investment in, um, some other models, but they are overly tied into the success of these companies.
I mean, if you listen to the guys that are all you, you know, sure are they, they are, you know, they, they are tied in those, those companies making it as big as they are. And, and frankly, so is a lot of our investments in the, in, you know, in the mar stock market. No.
Let, let, let's, let's face it, the AI economy is responsible yes, for the majority of the GDP growth in the US this year, right? So, you know, and it's tied into seven companies. It's not, or eight companies.
It's not healthy now. But I'm glad you asked the question, Kimberly. Kimberly, you know, I'll turn you back to Jurassic Park where Jeff Goldblum says, life will find a way.
And I firmly believe that innovation will find a way. It may not come from Silicon Valley. 'cause there, they're too wrapped to this.
It may, unfortunately, I'm hoping it doesn't come from Beijing or Bangalore or Moscow or, or, or somewhere like that. But maybe it comes in Austin or Boulder. Maybe it comes in in Raleigh.
Maybe it, it has to come from, but it will come, it's gonna come from, you can't bottle that up, right? You know, I, I'll give you another analogy. Star Trek world, right?
The warp drive. I mean, humanity appears to have been in the, in the crap or in some weird dude up in Idaho, Zephyr Pike. Can I give you, can I give you a world example?
It's called the oil industry. And how many years did they invest in finding ways to make sure that there were no alternative forms of energy invested in? And how many times did they just buy something up and just tuck it away somewhere?
And that was the No, another great, another that all over again that we, we might be dealing with that all over again. You're right. Mm-hmm.
But life will, I I I am optimistic life will find a way that, you know, innovation will succeed and it'll probably be in somebody's garage somewhere. And I too, because if you look at all the, the different industries, you know, you've been involved with, I've been involved with, yes, we've seen is is kind of like the, in my world, when I was, you know, running in the data storage site, EMC was the big guy and they kept on buying, but they, there was very little innovation coming out of them. They, they bought data domain, they bought Isilon, um, and several others that became huge offerings into the market.
Um, and we saw the same with, you know, IBM um, and, and others. And then we, we've got companies like Pure Storage that came out of investment and vast data. Both of them are challenging the entire market as we've gone into new application areas.
It's literally, it's because of the new applications that have driven that, those innovations and not the old stuff. So I think that yes, we will see the innovation and I, you know, applaud article Alan that you wrote that was really, really super good. I encourage everybody to go and read it.
I put it up in my LinkedIn, so go check it out. You'll find it there. Are we, are we gonna re, are we gonna remake network and are you gonna like, scream out the window?
Like, I'm not taking it anymore. How far are we going with this? It wouldn't, wouldn't be the first time I screamed out my window.
But anyway, I, you know what, Kimberly, thanks for the plug. The article is up there. You can watch the Shimmy says, I'll go dig deeper on it on that.
But, um, we've got, we've got more to talk about here on the gang. So let's take a break. We're gonna come back.
I think IRA's gonna kick off our next one here. You're watching Text on Gang. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're talking now about, well, law and privacy and security and all kinds of fun things, but there's an article up on Security Boulevard by Mark Rash that talks about, well, one of the reasons we don't have privacy regulations maybe, is that there isn't enough lawsuits out there because, well, the way we frame these legal standing issues results in people not being able to sue. But I, you're a lot closer to this than I am.
What's your take here? And, you know, is this a conspiracy or is this just something we overlook all these years and we need to fix? So let me be upfront.
I've been a cl, I've been an expert witness on a variety of class action lawsuits, mostly around privacy, fair Credit Reporting Act, and things like that. And when you look at these lawsuits, you have class action attorneys essentially crawling outta the sewers and essentially finding cases where they can apply the Fair Credit Reporting Act or another law that, uh, has statutory claim, you know, that has statutory claims. For example, every violation of the Fair Credit Reporting Act is a mandatory a hundred dollars, a hundred dollars penalty.
Now sounds not like much, but if there's a million people that's almost sudden a hundred million dollars lawsuits. And when you are looking at these things, frankly, there are companies that do major wrong, and if they're a fault, they should be held accountable. However, the current class action framework doesn't necessarily benefit the consumers.
At the end of the day. The way it theoretically benefits the consumers in the eyes of these class action attorneys is that they are bringing a lawsuit to hold these people accountable so that they are better in the future. And they believe that they deserve tens of millions of dollars for their efforts of filing paperwork.
And at the same time, the people who are actually wronged get nothing. There was actually a class action lawsuit where some attorney sued Google, they got like $10 million in fees while the people who were aggrieved got nothing, literally nothing. That was the lawsuit because they made the situation better.
Now, when these laws were, from what I read, the, the article was highlighting how very specifically attorneys are out there and they have to actually show people were damaged. In other words, they have to actually show that somebody's information was stolen, which is one thing, but that the information was used or abused, which is another thing, because I could download a hundred million records and not be able to go through and process it unless you can prove it was put up on some malicious website or used in some way, shape or form. In theory, the people, according to the, the court decisions were not harmed in any way.
And so that might be true. At the same time, what's really the problem, in my opinion, is how are the penalties being enacted? Who are the people actually benefiting?
Which is a real question we should be asking because at the end of the day, class action attorneys walk away with tens of millions of dollars, and I'm not exaggerating. While the people who are harmed get very little. For example, you know, when there was a class action against dog food companies where they had killed dogs because of poisoned dog food, which is rightfully, I own a dog, and boy would I want somebody to pay for that.
The people who had their dog die or get harmed, they were given a coupon for free dog food while the attorneys walked away with tens of millions of dollars. And at the same time, was anything changed? I would argue, no, I don't think whoever the company was, whether it was Purina or whoever, I don't know the first, the, the company, they don't want to kill dogs.
It's bad for their image. So did the lawsuit do any good except getting people who had to buy a new dog a a bag of dog food? No.
And this is the environment we're in. And now taking a step back and saying, unless you are actually harmed, you can't be put into a class, and the cla people put into a class just inflate the numbers. It inflates the potential threat.
The lawyers hold over the companies, but it's not benefiting the consumers. So, while I believe me, I want companies who do wrong and undervalue security to theoretically be punished and held accountable, but the current class action environment is not the way to do it. I'll leave it there.
Alan, You've been a lawyer in the past, and I think what I was now campaigning for, I don't know what office exactly, but tort reform, is that what we need here? Well, yeah. That, that is what he's campaigning for.
But you know, in law, we, we have this theory of what we call judicial restraint. Judicial economy. Judges don't like to make decisions unless they have to.
Lawyers don't like to write opinions unless they're really getting paid for it. And if you look at Mark R's article that this segment is based on it's typical judicial economy, right? And lawyer restraint, what, what they're fundamentally saying is we don't need tot reform.
We don't need tot reform the, the, the art, the cases or the theoretical cases. I assume he's changed the name to protect the innocent here there is no Elephant Insurance Company. But what he's saying is the court has said there's a difference between could be potentially harmed versus being actually harmed, right?
The fact that your social security number might be available on the dark web or your driver's license number, your date of birth, you know, some PII might be available on the dark web is not a nexus to damage. You haven't actually suffered any damages yet. We have to wait till you can prove that as a result of your PII being on the dark web or, or being used in a nefarious way.
You've suffered real damages and until you've suffered real damages, you don't have standing to bring a lawsuit. So you can't be part of that class action, right? We, you know, in essence, it's going to kill off the class actions and limit it to only people who have actually suffered real harm.
So in and of itself, it's almost taught reform, right? Because it's changing from, Hey, my, my PII was stolen, I could be at risk here and therefore I'm suing you. And what Mark says is no, the, the remedy's gonna be, Hey, I'll give you some, some credit monitoring, but until you got real damages, take a walk.
You know, a Alan the other thing this talk tells me is like they separate, you know, the article in Mark separates personal information or private information from personal information. Private information is your hipaa, your personal life about how you and your spouse are talking or something. Um, and from understanding, we are responsible individually, we should be responsible for our information.
And knowing that once you put the information out there, the probability that on the dark web is really high. And so therefore it's like, okay, you know, we need to, as individuals be wary about all those kind of phishing, um, things that come across your email. Um, you know, the bizarre stuff that we happen.
And so I, I hear, you know, holding the companies accountable, but I also hear that we have to hold ourselves accountable for our own, our private information and be judicious with what we do and how we, how we monitor that, that data. Just one sec. I, I think it's unreasonable expectations for the burden of proof for managing my information that I have given through consent for the use of a specific company is on me to validate it won't be used against me at some years following.
And I'll give an example. Uh, knowing where I went to high school, knowing where I went to elementary school, I don't care. Public basis, you can go find that information anywhere.
Being able to build an umbrella identity off of all of my information that's identifiable information. But personal information, not personal facts, is something that no person can predict the likely outcome of what happens when this happens. Imagine elderly folks that have, uh, you know, their entire lives tied up in 4 0 1 Ks and IRAs and so on and so forth, an account takeover adjacent to that because their data's been exposed and they don't really use the internet, right?
Suddenly puts them in crisis where hundreds of millions of dollars of folks that are over the age of 70 right, are now at risk and they have the burden of proof required for them to justify whether or not that's causing harm. I think it's incredible to suggest, and I think there has to be accountability, and you don't get to bump that to me just because I should be a, you know, consumer reports, you know, person that understands the likelihood and the possibilities, right? That's, that, that is, that is a type of, I revocable trust that you put in into a company's hands.
You can't possibly sign away. Well, I'm, I actually started out, and I want to be very clear, I a hundred percent agree with Fred because there is a difference in having your information theoretically available to a criminal versus putting it in criminal forums like the dark web. So for example, if you just say, gee, some criminal had access to, you know, what's a recent one?
The Marriott database, some criminal had access to it, and therefore who knows what they could have done? And I'm gonna have like a gazillion class members, so I can charge you a hundred dollars times a gazillion. That's one thing.
However, if that information ended up in the dark web where it's hard to prove that somebody did or didn't, you have to act like they did. And that's where I differ from what they were saying in principle to the specifics. And again, I agree with the, the line that Fred is drawing.
So can we just automate this a little bit and say, okay, I should be able to discover on the dark web when people have been harmed. I should be able to create a law, a website that aggregates all that information. And then I should be able to invite people that participate in my class action suit because I can prove they've been harmed.
And yeah, this is just a business process workflow. I I say no over what period of time and with what magnitude and what adjacency, right? So Fred Wilmot, right?
Or my grandfather's name, Francis Wilmot, right? The ability to stack identities together in a way that's meaningful with personal information is a very, very robust way of stealing people's identities. And when that information has been given out, right?
Then you're now subject to, there are no rules that stipulate these artificial identities cause harm to the originating the originating identity. But you can build up credit card profiles, you can buy houses, you can do any number of other things. And there's no way to materially suggest that is directly tied to the consumer who was exploited until somebody comes knocking on the door and saying, oh, well, you know what?
We tracked all this back all the way to you somehow. And it's up to the burden of proof is on the human who stands there, whose identity was exploited they had no idea about, and suddenly they're called to account. So Fred, I think what you're saying is that you're finding that these companies should be held accountable and having to pay these fees and okay, yes, the trust sys the how we do tort right now and the fact that the lawyers skip away with, you know, 90% of the money or whatever it is, and the people that are harmed get very, very little is of no cons, is not of consequence as it is with having the threat of the company being sued, being the consequence and them buttoning everything down.
Exactly. And that's where the bigger value is, is that the companies have that threat. They know they need to do something differently despite the fact that the only, the only people that are really benefiting from these torts, um, are the, uh, the, the lawyers.
Yeah, Kimberly, exactly. The bottom line is you should fear tron the user, not the class action lawsuit. And in this particular case, if you're accountable to the user or whomever, right?
That's the real, the real impetus. Go ahead, IRA. Um, no, I was just gonna conclude.
I frankly ag I frankly agree in large extent, and I'm just trying to go ahead and say, look, you have to understand because a lot of people say there's a class action lawsuit, go get 'em. Not realizing it's really just a transfer of wealth from the company to a lawyer not getting, you know, retribution or I shouldn't say retribution, but compensation to the aggrieved parties. And that has to change.
Like, again, you know, it, it's just like a total 'cause I don't think any attorneys really care at the end of the day. Let's face it. And here's the, you know, here's the elephants in the elephants room.
Fundamentally, this is all covered by insurance. It's the insurance people who are paying for this. It's not the companies who are paying, they just hire other attorneys to deal with it.
The insurance companies bump up the, you know, premiums of everybody and we all end up paying for it. And people don't realize the ecosystem of what going on. It's not just The insurance Ira, let me, let me make this real for us.
Let me make it real. For recently came across a case all too personally of one of these West Hollywood, California law firms sending out a mim, not a mimeograph, a xeroxed copy of a letter stating that, uh, a website has some, uh, data broker service in there. And they, they claim they have a person who came to the website and was therefore harmed by having her information exposed to data brokers.
And pursuant to the US wiretapping law in the California Privacy Act, they're gonna start a class action lawsuit. Unless you pay him $10,000, 10 grand, 10 grand don't sound like a lot of money, but remember, there's a reason why they're sending out Xerox copies of this letter. They're probably sending them out by the dozen lawyers.
You hire a lawyer to go look into it. Absolute nonsense. You, you have your teas and Cs in place, you have your cookie warnings, you have everything you're supposed to have.
We could fight this thing. We gotta make a motion to dismiss $15,000, $15,000 for the motion to dismiss. Now you're a businessman.
Do you pay the 10 grand to put the troll back in the box or do you go 15 grand on your principles? And, and, and, and that motion's not guaranteed to win, by the way, right? Because they don't like doing summary judgment.
Ju courts don't like granting summary judgment. If we gotta do discovery, it's 25, 35 grand to just keep playing. That's the problem in the law system here.
That's where we meet tart reform. That's, and, and, and it is, it's the lawyers, right? There's a reason I stop doing law.
I hate these lawyers, these trolls. They're, they, they are making a bet. And, and I spoke to a lawyer about it.
They don't go after large companies who don't mind, who have lawyers on staff, and we'll fight 'em till the cows come home. They go after small medium companies who in a business decision will pay the 10 grand versus fighting it out for 25 or 50 grand and ultimately winning. That's where the systems broke.
And that's what we need to fix. Mm-hmm. I, I'll step down off my soapbox now.
I think we're supposed to say amen and end the session here. We'll end it right here. You're watching Techstrong again, Discover Techstrong group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back with our last block and we're talking about the acquisition of Stitch by a company called Twilio. And some people are heralding this as an advance in how we're gonna manage identities. 'cause it'll make it easier for developers.
And other people are saying, well, it's an episode of Twilio and Extension. Maybe it's just gonna be one more cartoon. Fred, you looked at all of this stuff.
What's your take on what's going on here? And is there, are we gonna see more of this? Um, I love it.
Uh, and also the, the subtle knot to Lilo and Stitch, I'll say it outright. Um, remember when you used to have to, uh, pay your HR company for SSO is a special feature. Remember when people said, ah, you know what?
Passwords are terrible, everything should be passwordless. Or, Hey, you know what, I have this amazing SAM token, you can just connect up into your things and life will be good. Well, it turns out all of those have both a cost and a complexity and, you know, a challenge.
And they're designed for people they weren't designed for, for non-human identities. And so what we're seeing here is a movement, right? That's begun to say, Hey, look, standardization is a requirement.
You know, your Jot tokens for your web session have to use an actual standard. You can't poorly implement, you know, HT DP like we have in the past in a way that suggests that often a, a function of that. And that coincides with things like, hmm, proprietary SDKs and, you know, non-standardized delegated authentication mechanisms.
And for the, for the, for the uninitiated, what that means is, uh, I want to connect up with my Google identity to the things that I use. Okay, well, there's a standard utilized there called OIDC that allows you to decide that the same constructs or the same, you know, scope and the same entitlements are things that I can pass from place to place. It's a unified way of doing this method of authentication and the method of authorization.
So is this revolutionary? You know, I don't, I don't, I don't think it's revolutionary, but I think what's happening here is there's a whole host of new cohorts that are looking at this in an entirely different fashion that are accounting for non-human identities, which demands, uh, without human interaction demand standards in order to operate. So you can imagine that, you know, historically we've had folks like auth zero, uh, a staple in the industry, um, not without their own security concerns over the last handful of years from exploitation, but in addition to that, other providers that have, uh, non-traditional methods or historical methods for authentication, uh, one of which at least when, uh, when I was the CSO at JumpCloud, right?
Uh, terrific identity provider, right? Had to support skim, uh, in the implementations of the providers in which that skim was, uh, designed, right? So they'd have to copy the directory from somebody else in this particular case.
And, you know, what we're doing is we're taking the, uh, the insecurities with us as we go based on the implementation of said providers. So identity providers now are starting to move past this construct and suggesting, Hey, look, you know, there's a lot of B2B platforms, a lot of SaaS platforms, a lot of requirements for us to tie into, you know, MCP servers. And so those requirements illustrate why it's more likely to have competitive, you know, a APIs and, uh, ways of integrating with, uh, standards, uh, based authentication methods.
And, um, I think it's terrific. Do I, do I think this particular acquisition is, uh, a harbinger of the entirety of change in the industry? No, but it's certainly a big one, right?
And if there was a shot across the bow for an auth zero, I would probably be taking notes today. Alan, what's your take here? We need to just make this easier for developers in the first place, and then we wouldn't have all this crap on the back end that Fred's talking about.
We've tried to make it easier. Like you look at like SendGrid, which is, isn't that part of Twilio too, Fred, right? Didn't they buy SendGrid?
So SE SendGrid was great if you, if you wanted to have sort of an email verification or something like that kickoff, uh, in your, in your app, you could just, you know, you, you put a little srid component in there and on the backend, SRID took care of all that. And it, you know, it really helped with, with spam filtering and getting black bulk black box and all these things. Um, you know, it's an interesting thing.
Like I, I've always had the opinion of why does someone want to spam mail? Why do, why do we need passwords? Why do we need all of this whole huge infrastructure we've all developed over, whether it's single sign on, federated identity, it's, it all really comes down to identity, doesn't it?
Right? It's identity and access management. And, you know, in the age of cloud, that became the killer app for, for, for a, for cloud security in many ways, right?
I gotta know who you are and where you're allowed to go. We had 8 0 2 1 x when I was doing nac, right? It was, it was a big thing, Fred, if you remember those days, right?
Uh, we've never saw, here we are, it's 2025 going to 2026, we're still talking about the same crap. We're still talking about the same crap. We haven't, we haven't solved it.
So, so Kimberly, your take on this, because I think we've reached a point where maybe the same crap is no longer sustainable. 'cause if I missed my guess, and I think Fred mentioned non-human identities, so now we're gonna have these AI agents and there might be a hundred AI agents for every human by the time we're done. So this current system just isn't gonna be able to cope with that.
Yeah, I, as I'm listening to this, because you guys know this space, I, I know about that much in it, but, um, I think it was, yeah, last December when I was part of the, was at the American Society for ai. We had a debate on, um, whether or not AI was a person or not. And, and it was a fascinating, I mean, it was, we, and it was one of those classic debates where you, you know, you had one group that had to get up there and defend it, the other one, you know, to take it down.
And, and by the time you're done, you're just like, you, you, you broadened your scope of thinking about how to look at these AI machines and that when we get into MCP and you get into agents and everything else talking to each other, my, my big thing is like, okay, I got this LLM or this agent over here saying one thing, I got another one over here. You know, what if they evolve and they, they go around the security protection that we have. I mean, I'm laughing about it, but I'm like going, this is, this is real stuff, you know?
And yes, we're starting again because we've just inserted a new person into this world of ours that we haven't had before. And that person is called AI or agents or whatever it is, and it's got a real, I mean, we are handing over the keys to these guys. Um, these guys, see, I'm actually calling it a, a person person name.
We're handing it over to this coat, uh, and we're giving it names for crying out loud. Um, and you know, when, when you and I interact with chat, GPT, you know, you can't help but getting sucked in to the fact that you're talking to somebody. Um, so yeah, it's, we have to reinvent because we have all this brand new technology, and I hope that Fred, you and your team, people out there that are developing all this stuff are smart enough to protect us because it's, it could really have, it's a really wild, wild west situation, I think.
Wild, wild. Uh, it's a super good point. I, I, I like a couple of things about what you said that really focus on how we need to think about the next set of relationships that we develop, uh, whether we consider, you know, non-human identities, uh, human identities or not.
The, the focus here is really when we think about building infrastructure, for example, right? We have a bunch of a agentic things and you know, we have a bunch of MCP tool chain and all the things that go with it, right? When we look at all of those components separate, and aside from anybody communicating with anything that we do outside of our business or, and I believe a lot of other folks who are in the same boat, we need to make sure that those are authentic and authorized behaviors that happen.
And so, you know, there's a couple of, if, if you read this article, right, there's a bunch of different listed, uh, available open source technologies. Well, I don't wanna pay somebody else for n number of, of users non-human, uh, identities that I use, uh, either, right? So, and, and I need to have a source of truth and I need to have an identity, uh, uh, broker, uh, as well as an access control methodology authorization authentication that supports those standards, because at some time later, I also wanna make sure I can interact with other folks that have, you know, support of those standards.
And so, when we think about it at least, uh, from a microcosm of a, you know, tiny startup and a, you know, ragtag fugitive fleet of, of folks building stuff like this in this market today, they've gotta start somewhere that does not include these giants, you know, arbiters of, of brokered identity trust because it costs too much money to do it. So, and the complexity is ri you know, is rigorous. So when you go tie into, uh, you know, a very large organization that supports only a Microsoft identity or a Google identity or what have you, you probably need to know how to deal with that.
And where do you start? You start with the, the tools that make it easiest. And so some of those may be key cloak or, you know, fusion Auth is great for folks that do, you know, devices, right?
If you are interested in managing, you know, a thousand consoles in, in your retail locations, terrific for that. Uh, if you look at Descope to make all of your automated flows better, there's all kinds of tools that are coming out to help enable that as a developer to supplant the sort of historical, you know, cost model of the ma bell of identity. You know, somebody tried to make somebody, sorry, somebody tried to make me feel better about this because they told me that the AI agent would inherit my permissions.
And I was like, well, given the fact that my permissions are not very well managed, I was even more terrified than I was before. So it was, the report this week was, um, Amazon was yelling at perplexity because perplexity was placing orders on Amazon. So there's a battle going on between them.
Um, so, and I think about that, okay, so perplexity based upon me getting in there, I haven't used it, but, uh, from what I understand, looking in there and it can go on and go take my order and go to Amazon, search for the right piece, right thing to buy from me and go buy whatever I'm wanting and ship it to me. That to me, and well, let's go back to our, our, our B block that we talked about is scary because all of a sudden my data is being passed between these two different companies that are not financial institutions. Thank you very much.
You know, they, they're retail and whatever, but it's anyway that my brain can go all kinds of places. So I'll let it, I'll shut it down right now. Lemme just, lemme just, it's not just about your, this isn't just about personal liability or personal harm.
This, especially when you talk about machine identities and you know, is, is replacing phishing as a very easy way in to the, to the corporation's infrastructure that then do ransomware or inject malware or what have you. And you know, we live in a world where the machine identities outweigh human identities by an exponential factor, and his problem's not going away. Unfortunately, we don't have enough time to solve it here today either.
So I need, I need to, uh, pull the plug on this one. Kimberly, Fred Ira had to leave early, but we thank him. And Mike is always you, hope you've enjoyed this.
We've got more text on TV as usual following up. But you know what, at the end of the day, have a great weekend, everyone. We're coming up.
Thanksgiving will be here in a few weeks. It's hard for me to wrap my head around that. But, uh, enjoy your weekend, enjoy your weather, fall weather wherever you are, and we'll be back Monday with more text junk gang.
Hey everyone, welcome back here to Textron tv. I'm really happy to introduce you to our next guest. His name is Sasha Jade.
Sasha is the CPO Chief Product Officer over at Sideware. And let's welcome him to Textron tv. Sasha, great to have you on.
Thanks for joining us. Awesome, Alan. Great to be here.
Thank you for having me. My pleasure. So Sasha, before we jump into Sware and what we want to talk about today, let's talk a, a little bit, give our listeners a sense of who they're listening to here.
I mentioned you're the chief product officer at sware, but how did you get to this role? Oh yeah, thank you. Uh, first of all, again, thanks for having me here.
So, always been a, you know, tech guy in one way, shape or form in long, you know, about 15, 18 years ago or so, I started looking at cybersecurity in a different lens, which is in the risk space, which is, you know, enterprises typically used to have, especially the financial services work space, you have eight or nine different constituents coming from all the asset all the way to the investors. And in between these eight or nine players, you have so many things going around. And so your risk exposure just increases significantly.
So 2006, 2007, I started building my first firm, which was in the risk in cybersecurity space. And the whole notion of that was this concept called security value at risk, which is, you know, when certain things happen in a security event, what is your value at risk? It could be because of your brand getting, you know, unfortunately hit your credentials, getting compromised and that getting hit, uh, you know, you're getting ransomwares and all of those things.
So we built a product, uh, bid data, the traditional ai, not the gen AI part, et cetera. So we actually built the product. Uh, I love building, uh, and I also love customers.
I just love customers because if I am building something, I wanna make sure that it is getting used by somebody. If nobody's using it, why am I building it? So that's how I started building, that's my foray into, you know, just the product side of things.
The whole nine yards customers built that firm, exited out of that firm. And then for about a couple years was with a larger enterprise, uh, Deloitte in this case, uh, who were, you know, acquired. And then, uh, I went to another larger com, uh, corporate in Horizon, uh, who was looking at, you know, different security and network products, so to speak, and saying, you know, what, how do we actually make certain money out of here?
And so on. So I joined, I led a portfolio of products in there as well. And what we built around that was how do we make and reve security into the core of Verizon's backbone itself, as opposed to having network just for the network.
Uh, built that portfolio pretty nicely from a p and l standpoint and the products as well. And then, uh, you know, started getting the bug for my, uh, startup again and, uh, met with the folks at cyber. And lo and behold, I am the chief product officer here taking that, uh, and all the things that I've learned over the years with customers, cybersecurity, threat management, et cetera, which excite me.
And so that's who I am. Fantastic. It's hard to get that startup thing outta your blood.
It totally is. You know, I, I've tried myself. It, it totally is.
And uh, I, I, I love soccer as a player, so I love, and I, so anytime when I'm driving across and I see kids playing, I'm like, let me just go play. It's that same mentality, You know what? I hear you.
So I, I, I satisfied that by coaching. I coached kids in, in football and basketball for years. And uh, you know, when they got to the point where they were like, bigger than faster than me and, and everything else, I realized I was glad I was coaching 'cause I couldn't play with those kids anymore.
But I think there's, there's the, some of that in all of us that, you know, want to go back and do it. So how long have you been with Ware now? So I've been with Cy for about 14 months now.
Uh, a little over a year, a little over a year. Um, and my charter kind of, uh, is kind of bucketed into three areas, if you will. The first area is strategically thinking about what the product landscape should look like.
What is that six month, eight month, 12 month, 44 month trajectory of the products look like. Second is how do we build our thought leadership around all the assets that we have in the cybersecurity as well, saying, you know, what, how do we actually help our customers? And the third, but uh, last but not least is working directly with the customers to see what are their pain points specifically that needs to be addressed so that, you know, unfortunately sometimes the cliche of like, yeah, you know what, everybody in the AI case, everybody wants to do ai.
For me, it's very deliberate in terms of like, okay, that's great. I can build ai, but what, which case does it solve for you? Why am I building certain things with AI and not the traditional way because it's going to help you with X, Y, and Z?
So these are the three quote unquote charter areas for me. Excellent. And uh, Sasha, if you don't mind, there might be people out here who have not heard of CY wear or maybe more likely even people who have heard of CY Wear that may not be sure exactly what CY wear does or what, you know it is, but we've heard it.
Let's clear that up if we can right now give people a sense maybe of who and what CY wear is and what it's about. Sure. Uh, in 30 seconds, cyberware is about operationalizing threat intelligence.
And what that means is when you look at, you know, the history of threat intelligence, one of the core pain points was you would get all the indicators from so many different places, whether it's the external attack surface indicators that might be coming in, whether it's the internal assets that you have, internal data points from your scene, from your logs, from your assets, CDBs, all of those places, most SOC analysts, CTI teams, et cetera, have a challenge of operationalizing it. And what I mean by that is what is the signal here? What is the noise when it comes to threat data?
Second is what is relevant for me? Yeah, there could be threat vectors, but what is relevant for me, and the last but not the least, is once you've given me the actionable threat and the relevancy, what do I do with it? Do I block certain things?
Do I patch certain things? Do I take certain other elements to it? So that in a nutshell, that end to end, based on the threat diligence and operationalizing it is who we are.
My product portfolio is kind of based on four products. We have the Intel Exchange, which does everything related to analysis. Second is collaboration, which allows you to disseminate all the right information to the right parties and the recipient groups on the other side underneath the uh, covers, we have what we call the orchestrate platform that allows you to connect to anything and everything with the AI driven playbooks, et cetera.
And last but not the least, is a threat context driven case management system so that you can connect the entire dots of certain things that might be happening. So that's who side that is and that's my power portfolio. That's excellent.
A great, great description of, of Cy wear ash. Um, so, you know, threat intelligence is a bit of a big boys game, right? You don't see a lot of mom and pop shops kind of subscribing to a threat intel feed or something like that.
It's, you know, it's for enterprise, it's for public sector. But here's an interesting thing. I've been in security myself 25 plus years.
When I first saw threat intel kind of explode on the, on the scene, I think we always had threat in intelligence. We just didn't call it threat intel. Maybe it wasn't a, a product line, but we were always, always trying to be wise as to what was happening out there, right?
But I think most people thought that an enterprise would, would subscribe to a threat, to a threat intel feed. But I, I think in the real world we're seeing, especially with AI now and, and everything else, companies, large orgs, you know, the more, the merrier almost when it comes to thread intel and sources. I wonder if that's something Sachin you saw maybe at Verizon or, or now, you know, talking to many customers as part of sware.
Is, is thread intel sort of a, a one horse or a one dog kind of house or, or do most organizations now kind of have multiple thread intel sources? Yeah, great question. I think depending on the maturity of the organization, you do see a spectrum.
You do see larger enterprises that do have multiple threat intel data sources, feeds that they can do certain things with it and so on. You got the middle, uh, middle tier, mid tier companies, et cetera, that kind of focuses on specifically one or two areas that they might want to see. And then you've got the, you know, the lower end of the enterprise segment that typically just have just one data feed and one, one intel and try to do whatever they can with it.
You see that spectrum. And so from our standpoint, the way we look at it is, if you want to start a CTI quote unquote program, you don't, you do want to use a CMM framework, if you will, because that allows you to put it in action. Uh, you can leverage, you know, products from us to set it up.
You get the, you know, cyber intelligence suite, for example, that bundles a lot of those things. So that your time to value in setting it up becomes very easy, uh, number one and number two. But that allows you to grow as you scale in from a smaller enterprise to a medium to a large enterprise.
Got it. Excellent. Now, of course, that begs the question of, okay, now I got multiple sources, right?
And I've got, and in addition to that, I have my own telemetry that I'm gathering, right? From my, from my own source, my own networks and stuff. You know, how do I wrap my head all around this now?
Yeah, we got ai. I'm sure AI is part of the solution. Perhaps, perhaps maybe it, maybe it adds more to the problem than the solution at first, but hopefully eventually it, it helps.
But like everything else we're doing in technology today, AI is having, its, its say in there, its impact in there, right? A lot of times we use the word modernization and it covers up a lot of sins. But, you know, we are certainly modernizing how we take in multiple data sources like this, validate them, share them across the organization, and, and then translate that to response.
Right? And I would gotta imagine that this is a big part of ware's business today. Yeah.
Uh, what one of cyber's strength is understanding these multiple different sources that do come in understanding the correlation between it, so the entire whole nine yards of a threat event, data life cycle, which leads to normalization, deduplication understanding, what is it element to you from a risk scoring standpoint, what is the high priority that you as an analyst should be working with, et cetera. That is a huge strength around it. And then when you have capabilities from our partners, such as Microsoft, et cetera, where you can now not only leverage our data, but in a bidirectional capacity, leverage certain things that might be happening in their product as well and get it back to us so that our product can take the effective decision around it.
Case in point being, let's say there is an alert that happened and it has been shown in the, you know, Microsoft AL system, et cetera. Now that can be now contextualized and correlated leveraging external threat data that our platform might be seeing. And because of that, we can send an enriched data back to cental for an alert system, et cetera.
And when their AI or our AI now enhances it based on the con context that they see as well, now downstream from there, most of the other players can take advantage of that. So now, not only have you leveraged the data that's coming from multiple different sources, but you have enhanced it, enriched it, and allowed the contextualization for somebody else to take a particular decision around it. I, I kind of put the analogy that I was talking to on another part, the Microsoft team, it's that whole team of teams, our process, which is you need to have the data to be shared across, but contextually the decisions that a particular team takes might be very different than the other team, but they need to know the data that everybody else is also aware of.
That's how we also operate. Excellent. Very cool.
You know, not quite as big as ai. Not anywhere near as big as ai, but a term Sasha that we hear a lot kicked around as observability. Right.
And you know, I almost, I still remember when I first started hearing it, little did I know it was gonna replace like everything I knew about, uh, a, uh, a PM, right? Or I mean so much, you know, all these companies are now observability companies. Um, do you think cyber at some level is an observability company or an observability enabler?
Great question. Um, so there are advantage points and two lens around it. Uh, in particular areas we observe what might be happening within the actual asset.
And I'll give a use case, for example. Uh, let's say there's a Compromise credential that's been happening, and unfortunately we heard that, you know, earlier this week as well with respect to the number of passwords that got leak and so on. And when Compromise credentials happen, you not only need to observe, but then you need to enable actioning on that observability.
So in this particular case, we kind of do both because we actually take a look at, you know, certain compromise credentials that might be happening. We actually get the information appropriately around it, and then we enable the identity access management systems to take action against it, which is maybe quarantining the compromise potential or changing or resetting the password and so on. And then the other areas we, what we typically do is we will be enabling the, you know, observability platforms themselves saying, Hey, have you looked gone and looked at, like say for example, you know, Microsoft Teams systems or have you gone and looked at the asset database cnbs to see what applications are there that needs to be monitored as well?
So we kinda look, uh, you know, we kinda play both roles depending on where the context lies. The essence is still to make sure that the context and the data for the actioning is relevant in the Compromise Credential example, sometimes when you are buying certain things off of Telegram channels and so on, on the Compromise credentials packet, 60% of them are not even your users. It's a mechanism for the telegram folks to make money.
Uh, they make any actress to make money off on the Gram channels, but 60% of them are not even new users. So validating that, making sure that the signal is really cusp for you as an enterprise to actually take action against it is what our sweet spot becomes. So it's the observability and then enabling the action around it.
I love it. So Sachi, uh, Cy recently had some news releases, some noteworthy, uh, information. If you wouldn't mind while we got you here, I don't want to turn you into a PR news person, but you know, you gotta do what you gotta do.
Tell, share with us maybe some, some, uh, news coming outta Sware. Sure. Yeah.
Um, we just announced we were part of, uh, the Microsoft Intelligence Security Association, uh, which is a really good honor for us. But then expanding on that, what the Microsoft team and ours, uh, ourselves as well, what we started kept looking was this need for a bidirectionality in how the threat intelligence is used, evolved, enriched, and then shared. And so, you know, typically Microsoft has this amazing strategy as well, which is, you know, to break down silos, which is very much in line with our thought process, more collaboration, more collective defense.
And our product gets used as a significant component of the automatic collective defense within, uh, in know federal government as well as ISACs and enterprises. And in that capacity, because that plays a key role in their seeing the sentiment defender system, et cetera. And our pla our platform now allows the bidirectionality in terms of integration with them.
And so we announced that partnership, which is available as an offering directly from Microsoft as well. Uh, so we are extremely excited. It allows the enterprises to, to make use of their investments that they have done in the Microsoft ecosystem and ours as well, and make that bidirectionality and leverage that for what I was kind of alluding before, which is how do you take those correlations and actions pretty much in real time?
Love it. Where can people get more information on that, Sasha? Yeah, so it is on our website as well.
com/tech alliances slash partnership slash Microsoft, I believe. Uh, but yeah, that's on Our, might be, might be easier to Google. That Might be easier to Google.
It's on the web, it's on our, uh, website as well. And, but they absolutely take a look. We also have a blog published, uh, Microsoft has the appropriate corresponding block published as well.
We have, we're extremely excited on that. Fantastic. Hey, I'm looking at my watch here.
It seems we've kind of just about added time. I, I appreciate you coming on. I appreciate you giving us the scoop here on the latest with Sideware and talking a little bit with us, us about threat intel and, you know, in, in, in like everything else through the lens of AI today.
So continued success. Come back and keep us posted. SWE is an exciting company.
Absolutely. Once again, thank you for having me and I'm absolutely in the profile coming back. Thank you.
Sasha Jade, chief product Officer at Sideware here on Tech Drunk tv. We're gonna take a break and we'll be back in just a moment with more stay tuned. Hey everybody, we're back at Atlassian Europe and we're here with Jamil, who's the head of product for, uh, AI for all things at Atlassian.
And we're gonna have a little chat about, well, where is AI headed? Jamil, welcome the show. Yeah, thanks for having me here.
We seem to have gone from co-pilots to AI agents in a blink of an eye, and now we have all these helpers that are gonna do all kinds of work for us, but where is AI headed from here? How smart can smart get? Yeah, I, I think that a, a lot of the future now is not gonna be necessarily about, you know, who has the, the best model.
That certainly is important piece of the puzzle, uh, but really on how, uh, people are bringing that, uh, capability into their day-to-day work, into their workflows and making it easy to access, easy to make, and, and part of their teams. And that's where we're really focused right now. Uh, we found that a lot of the success or failure of our customers in AI doesn't have to do with, oh, is the model doing the right thing?
Or does the software exactly the perfect for what that task is, but it's in how effectively it's integrating into their workflows, right? So one of the things about AI is it's probabilistic and so it's giving you, you essentially its best guess of what you need. Yeah.
Um, we have a lot of processes that are deterministic sometimes where it has to be done the same way every time. And, you know, that stuff's kinda wrote, but do we need to be careful about how we're thinking about applying AI based on what the actual mission is? And we gotta have to back it up from there.
I mean, 'cause I think a lot of people don't think about the nature of the workflow all these day years. It's one thing to create an email, it's another thing to process a contract. Absolutely.
I, I think that there are a lot of deterministic processes, and there've already, there are already tools out there that, uh, like automation platforms and whatnot that are really good at trying to simplify that. But what we find is that, uh, folks who are trying to plug in agents into automation flows, for example, what they are trying to do is actually make that automation more robust. Because at some point there is some judgment required, and oftentimes that judgment is, you know, fairly straightforward.
Uh, it's something that requires a bit of context, uh, a bit of understanding of, of, uh, you know, the content, the rules, all those sorts of things. And then it can apply some sort of judgment. And we find that in that case, uh, those are like prime examples where an, um, an agent can actually start making a workflow better, uh, that was previously deterministic and only able to handle a certain amount of capability, uh, that I think we'll see a lot more of in the future where those, like, you know, couple layers of initial judgment that that triage step, for example, will start getting assisted by agents with human review, uh, but will still simplify a lot of the work that has to get done.
Um, if you think about, for example, analyzing a, a Jira backlog, uh, you might have like five or six themes that you thought of, and it's a very simple judgment to say, well, which theme should it go into? But nobody really wants to like go and spend their whole day doing that. But if you have an agent saying, Hey, like that, that is a, a sort of deterministic problem, but does require a little bit of judgment prime a candidate for something that we would actually accelerate with ai.
Yeah. Won't we also use AI agents to kind review the work of other AI agents at some point? I mean, we talk about human in the middle, but maybe I don't always wanna do that myself either.
So will there not be times when I'll use an AI agent to kinda look at what some other AI agent did and make sure it's not hallucinating and put some guardrails in place? Absolutely. I, I, I think that, uh, these sorts of systems will become pretty commonplace.
Uh, and I, I'm, I'm excited about the innovation that's happening there already. Um, a lot of the initial wave of, uh, review for AI happened as agents were starting to get plugged in to review, uh, labeling, for example, like one system would label, the other system would judge, uh, even in engineering right now, when we evaluate VO chat, for example, we'll actually go and say, Hey, VO Chat gave this output, let's go and actually have a separate, uh, agent that runs that helps us grade that output later on so we can evaluate if you think it actually answered the question or not. So what is that line between, I mean, one of the things that's become apparent is VOS everywhere in the portfolio.
So what is the line between VO a product and robo a feature of something else? Yeah, so we've, uh, we've to said that ROBO is part of our platform. Uh, and we've considered that the platform offering of robo to have three core applications, uh, search, chat, and studio.
And we believe that those core applications are gonna be the basis for almost any teamwork in the future, regardless of what discipline you own, everyone needs to search. Everyone will want to go and actually query their knowledge sources and take actions. Everyone would want to go and build aub automate their flows.
Uh, so we believe that's like woven into the platform that's the right thing. And then for every collection that we have, every app that we build, uh, our intention is to build a set of, uh, you know, tailored agents for that particular, uh, collection, uh, as well as specific applications and enhancements that plug into the robo platform. Uh, and that again, will be like very tailored to the, you know, cases and, and needs of those customers who use those tools.
And where is that line gonna be between the agents that you provide and the ones that I might go build using Studio? What, what are some of the use cases look like? Totally.
Yeah. I think that there, there'll be some agents that we provide that are ultra sophisticated. So for example, we announced Rob Oev, uh, and Robo Dev is a, a co-generation agent that is actually able to harness all of the context, uh, of, you know, code and the software building that we have from you, because you trust us with your Bitbucket, with your, uh, JIRA and Confluence.
We can do a really good job with that generating code for you. Uh, and that's a very sophisticated agent. So we'll provide that.
Um, there are other agents we provide that are really meant to be examples of starters, right? Uh, like we won't presume to know what the best way is to go and, uh, you know, triage every, uh, or prioritize every bubble list for someone, but we can provide you with a starter, right? And then we wanna encourage customers to go customize that agent for their needs.
And we hope that that leads and inspires folks to go and build even more agents that are tailored to their business processes based on the examples we provide. And then we continue providing these really sophisticated ones that, uh, really require, you know, more than, uh, typical producting. What is the future of the software user experience gonna be like?
Because historically we've had all these tools and different EYs, is AI gonna harmonize all of that? And maybe I won't even know when I'm in and out of a given product. Yeah, I I think that we're in the very early like, you know, dos command line era, uh, of how we interact with ai, right?
Uh, and, and that's totally understandable. I I think that, you know, typically people start with these, you know, simplistic chat interfaces. That's a very natural, easy thing to understand.
But as AI is solving more and more problems, uh, and people get also more and more comfortable with a predictive model helping govern their application experience, I think we will be innovating as an industry new, uh, experience paradigms that fit naturally into that. Uh, I think we're still in early days on that, but, uh, I think with what we're doing, for example, with, um, the browser company, uh, and the opportunity, there is a good example of a, a place where we're actually making an experience bet saying, Hey, if we had to go and think about an AI forward way, um, of actually using your, not your SaaS apps every day, what would it look like? Um, that's one example of a bet we're making, and I think the industry is gonna, you know, push in that direction on there.
One of the things you announced at the show was support for the model context protocol. I think it's coming early next year. Yeah.
Um, when, how will these AI agents kind of interoperate with each other? How will we orchestrate them? How do you see that whole thing evolving?
Yeah. So we fundamentally believe in, um, an open platform. Uh, and that's part of Atlassian's DNA.
We think that we work better together with other partners, with third party vendors, uh, and that that's what our customers expect. So, uh, we actually already have our MCP server out there, people actually using absolute server. And then, uh, we're gonna support MCP services as part of studio, uh, very soon as part of the studio release.
And that's just showing, um, our commitment through that. Uh, to that principle, uh, I believe that there's no one company ever that will have, um, total understanding of every business process and every need for every company. And that by nature necessitates, um, this, and, and sets the expectation that we provide as an industry open platform so that people, vendors who have that specialization, who have that skill can provide those tools.
And that we interoperate together. We announced also partnership with Google, for example, where we'll work with them on agent to agent. Uh, and that's another example of where we're saying, Hey, we, we will, we know that we're not gonna go and solve every person's problem, but Google will solve some problems.
Other vendors will solve some problems, and we'll have to learn how to operate together. And that's where our mind is out on its front. So in that environment, we may have, let's say I have a couple AI agents and you have a couple of AI agents.
Will they negotiate with each other? How will that discussion kind of evolve? Yeah, it's, uh, it's a good question.
I think a lot of innovation is still happening on this front. Uh, what I expect will happen is that, you know, every, uh, agent out there will have to have a responsibility that's pretty significant to manage the trust and security, um, of the content that they have responsibility to govern. Uh, so for example, when somebody, uh, connects to the VO agent right from another platform, uh, you know, we're governing access to the data on the Atlassian platform that, that, that's being requested.
And it's up up to us to, you know, understand and work with the other vendor to, you know, have the right permission structure in place so that we don't accidentally leak data. That, that the right data goes back and forth and decide break customer plus expectations. That's a very important step that it has to be a part of that, you know, protocol and negotiation, um, that I think is easily underestimated, but very critical.
Uh, I think the other thing that's gonna happen a lot of is this idea of orchestration, right? Who's actually owning this decision of when to actually call out to the other agent? What is the base on which that decision is made?
Uh, that's gonna be a very powerful, um, capability and important one. We think that we have a, a very good position there because people trust, uh, Atlassian and, uh, put their knowledge of their goals, their projects, their work items, et cetera, all with us. That gives us a lot of context to which to know, uh, how to make that kind of decision, which will, I think, be a, a very important pillar of these protocols and featuring, is there gonna be some sort of hierarchy of AI agents?
'cause I don't think they're all gonna be created equal. And, you know, might this evolve into something that feels like, you know, upstairs, downstairs there's a head butler and then there's a bunch of agents in the basement doing interesting things that are relevant, but nobody ever sees them. Yeah, I, I think, um, I I'm not sure if it'll play out quite that way.
I think it's a, it's a bit, it's easy to pontificate. It's very hard to forecast right now. Um, I think our belief is that, you know, every, um, you know, every major app vendor out there will have a set of agents who are a singular agent that, uh, you know, serves the tasks that they have.
Well, we certainly would think we have a lot of things that we can offer with robo and, and unique capabilities that we have as part of the Atlassian platform. Um, but we also fundamentally believe that there'll be other agents we have to work with. Um, I don't expect that there'll be one agent to rule them all.
I don't think that's how it works. Like, you know, we've had even these generation one assistant around for a long time now with whether it's Siri or Alexa or Cortana, like, none of these have become like the single dominating agent and customers don't seem to want that. Uh, and I think that's reasonable, right?
I, I, I don't think that, uh, you know, people are really comfortable yet with just having one personality that discovers everything. Am I going to develop a relationship with my AI agents? I mean, or will they just be kinda like, you know, things that pop up every now and again, like, you know, bad example probably, but clippy.
But, um, or is it gonna be something that, you know, there's gonna be some entity that I recognize. Maybe there'll be a few of them, but there'll be something that I will put a name on. Yeah.
Yeah. I think that at, at a minimum, uh, people will expect the agents to understand their personality and their preferences. Uh, one of the things that we announced this week was this idea of personal memory to compliment the organizational memory.
And that's because a lot of the things that people expect on other agents are nuance. Uh, but but important for them to meet their needs to, for example, remembering that I prefer long form content while somebody else prefers bullets and emojis, um, is a personal preference. Uh, the AI has to learn and understand and preserve about you.
Uh, and I think the more it's able to pick up and understand those personal preferences and those, uh, those sorts of details, the better it will be at serving you. Um, that doesn't mean full on personality. I think that, you know, we'll have to see how things evolve and if people prefer that.
But that idea of, you know, having this, you know, deeper knowledge of, of you at that level, we will just make decisions more powerful and rely on for people in, this is something of a more subtle shift. But yeah, when we had co-pilots, people were studying up on prompt engineering. Yeah.
And now you hear the phrase context engineering. So is this whole space gonna evolve and change? 'cause maybe I'm not gonna be the master of prompts as much as I'm gonna be figuring out what context to give the AI agent, but I gotta give that context in the right order.
Uh, I think both will matter. Its tongue. Uh, and I think what folks have been learning is that, um, a lot of times you can do all the prompt engineering in the world, but if you don't feed the right data, uh, you're not gonna wind up with the output output that you want.
Um, and so I think, uh, I don't think we'll see like one be more important than the other. I think that as people get more and more experienced building these agents and these sort of AI capabilities, there'll be best practices that build up around how to set them up for success. Uh, that involves how to write the right prompts, how to feed the right context in.
It also involves things like where to weave it into your workflow. Um, how does it actually interact with the team? Like is it a, a distinct identity?
Uh, does it get permissions? Do you have to give it skills? These are all, uh, things that are being lured now in real time and that we're rapidly incorporating into our studio, um, to make sure that customers have the ability to, to dial those things in and, and set their preferences up.
Uh, and then a lot of testability. And, and trust also has to have factored in. Like, knowing that an agent has a good track record actually is really important.
Uh, and I think we'll see more systems like that put into place as well. Tell people, move these things and start trusting them and they realize, one of the things that I think is not so much a secret out there, but a lot of our processes are, shall we say, not very neat. Yeah.
Well, AI and the agents kind of force us to kind of clean that up a little bit because they're gonna be looking for, you know, more structured things and the more structured give it, the more context it has and it becomes a virtuous cycle. But are we gonna have to go revisit a lot of our processes? You know, I think that we will have to revisit processes, um, but I don't think necessarily to make them more structured.
Um, I think that that's where, um, I would expect the agent is meeting you, right? To say, Hey, like, let me go and take this challenge anything off your plate and run it better for you. Um, but I think people, excuse me, will have to learn about where is the best place, what are the types of best problems in a, to trust an agent with?
Um, that's what I think take a bit of muscle building, uh, and also a bit of work from technical teams as well to sort of figure out how, how good we can make these agents to adapt to different types of scenarios. And then people will learn, I think, hey, like, here are the types of scenarios an agent can learn well, uh, work well. Um, so I think we'll, we'll see a, a lot of like learning from both, you know, the, the workers and the agents on, on that front.
Um, but I expect that the problem people will wanna solve is actually what you mentioned is like, Hey, I have like a really challenging process. Can you help me go and, you know, make it run more reliably, more smoothly, think more predictability, um, and I think that will actually lead to better, better processes. Will the AI agents also be able to surface the dependencies that exist between processes?
'cause I think we try to keep all this stuff in our head, but um, we sometimes forget that, you know, five projects are dependent upon this other project in on time and that project's late, but nobody knows. Oh, absolutely. I think that's like one of the best initial use cases of these agents is often, um, you know, you have so many different knowledge sources and pieces of data out there, and it's really helpful when you actually are able to trust an agent or even chat to go and, you know, pull all those different things, you know, suss out the right relevant information, provide the reference links for you so you can follow up.
Uh, but, but see where which ones are worth spending your time on. Um, I think you can do that today, and I think that's actually a super value to use disc. You've been at this a while and a lot of other folks are kind of newbies, but yeah.
Is there something, you know, now that you kind of wish you knew a couple of years ago? Oh, wow. Uh, so many things.
Uh, I'd say, uh, a couple of the, the things that I'd share with, with listeners, um, I think most important is to start out with actually, uh, something small, right? Uh, yeah, I think there's a lot of temptation when you like say, oh, I'm making an AI investment. Let's go solve these giant problems and certainly have the ambition.
Uh, but we find that the best success stories are often when, uh, folks are able to start off with, um, just one or two pain points, very discrete pain points in their system, in their processes, in their teams, and we're able to go and say, Hey, how do I go and, uh, make that even 10, 20% better? Uh, we find that if you're able to vote and focus on a, a narrow problem, that's where AI can do the best job, uh, right off the bat. And then you can start expanding from there because you'll learn the AI will learn as well.
Your prompts will get better, you're conscious of it, it better, um, you'll be able to run more evals. All those things will get better and better. Uh, we actually introduced this ability called of scenarios, and that's sort of in the same thought process as saying, Hey, try with one scenario, then you can add second, third, fourth, fifth scenarios.
But we find that teams that go in that, that manner, uh, tend to have a lot more success. The only other thing that I'd, I'd share that, that we've learned a lot of is that there's a, you know, a culture shift as well that's important. Uh, and it's both top down and bottoms up.
It's very important for the leaders of every company, uh, to really lean in and say, Hey, I'm gonna go try these things myself. I'm gonna share my successes in my failures with my team, uh, and show that I'm being vulnerable and, and trying these things out that sets the tone for everyone else to, you know, be comfortable. And then from a bottoms up perspective, there's always a few teams at every company that, uh, are ready to take risk that are, are most risk oriented, want to go and take a chance, take a plunge, have a big problem to go solve, and it's important that they get supported.
Um, and I think it's easy in a big company, um, to have a team that's like, that feel like they just don't have the room to navigate and score. But I think it's important to actually give those teams room because they tend to find those solutions and then set the stage for everyone as to to fund. So, all right, folks, you heard in here, even in the age of ai, you still need to learn to walk before you run.
Yeah. Hey buddy, thanks for coming by. Thank you very much for having me.
And I enjoy the time here in Barcelona. Thank you. Yeah.
And we will be back in a minute. Hello and welcome back to Atlassian, Europe, and we're here with Josh Millers, the CEO of the browser company, which is in the process of being acquired by Atlassian. And we can't get into too much detail about the future plans, but welcome to the show.
Thank you very much. Awesome to be here. First, uh, Atlassian team conference.
All right. So a lot of people are going, well, why do we need a new and different browser? And what's gonna change about the experience in the age of ai?
And, and so kind of educate everybody about what you guys are working on. Yeah. So the origin of the company is actually pretty humble.
My wife got a new job. She got a brand new MacBook with M1 ship, super fancy. She worked for a artist who was 76 in Flagstaff, Arizona, not the bastion of it, innovation and forward thinking teams.
And I noticed that she never left Chrome during her workday. Like even in an old industry, she would get PDFs from old school New York galleries, and those PDFs were now URLs and her email was a URL. And so the origin of the browser company was looking at how people were using their computers and noticing they weren't ever leaving their browser.
And their browser was really more of an operating system for their day-to-day and the fact that their applications and files now in the browser. So the idea behind the browser company arc or first browser and now idea, which will be expanding with Atlassian, is how would you re-architect and redesign a browser if your Assumption was not tabs or information from the Super information highway from 20, 30 years, really 30 years ago. But you said, Hey, these are actually the tools and files that I'm using every day that used to happen on Mac Os or used to happen on Windows, but it's now moved up the stacks to the browser layer.
So explain how that will change the way we work. 'cause I mean, today I'll open my browser and there'll be 15 tabs on that that I'm kind of trying to mentally connect. But is there a better way of thinking about all that?
Yeah, There's, and we think about it from a couple different, uh, angles. One is applications. So again, we don't think of them as tabs.
We think of them as tickets or documents or videos. And when you think about it that way, you have features like if you're in a Google Meet meeting and then you have to switch away to another tab, that might be a document that everyone in the meeting's reviewing or some research you wanna do quickly on the side relevant to the conversation, we automatically take that Google meet meeting. 'cause we don't view it as a tab.
We view it as a meeting and pop it out into a little custom video player just for video calls with little meeting controls that will follow you around to anywhere you go in the browser. So that's an example of if you're someone that is in video calls a lot for your job, every time you do a call, we're making that experience more seamless and more convenient because we don't think of them as dumb browser tabs. We think of them as smart app objects.
Yeah. So that's one area. The other area is with ai, and if there's one thing we've learned about AI is unreliable and can feel like slop and the things that change, both of those downsides of AI are when it has a lot of context about you and your job.
Where is that context? Your context is in your tabs. Why is it in your tabs?
Because your tabs are your apps and your files in 2025. So the idea is that instead of having to export things outta your browser into some AI tool of all the context of what you're working on is right there, then can we teach an AI model when you use it natively in the browser to really already understand the things that you're working on because it's right there with you. But both of those are examples where it's not redesigning the browser for the sake of it.
It's saying the browser is designed for something totally different and this many decades later. Really people are turning to it as the heartbeat of their job. And let's make a browser that reflects that Dumb question.
But what you're describing, is it really a browser or is it something else altogether? Well, Fun fact, we called it the Browser company of New York, right? As sort of a misdirection.
So we've always viewed what we were building as a new type of operating system at the web layer. Now, this is an idea that is age old. There have been so many attempts at this.
And our view is that the timing for this idea, in a world where we have devices across, you might have a Windows PC for work and an Apple device for your smartphone and your car and your, that you're gonna want a computer that follows you around all those different devices. And in the modern world where everything's moving to the cloud and there are these proliferation of devices, you're gonna want a browser or something that sits across all of them at the web layer. Now, we don't think the average person, I think you probably, your, your audience may be the one narrow niche in the world that is wants to talk about operating systems, uh, based on top of the web.
But for most other people, that's not a thing they're looking for. So we call it a browser because three to 4 billion people a day use a browser and, and they, they're familiar what to expect. So our hope is sort of like the iPhone one day someone picks it because it is better than Chrome or safari and very concrete ways that they can relate to.
And over time, if we do our job, they'll look and go like, wait a minute, I'm barely touching my downloads folder, or I'm barely touching the folders on my desktop. Uh, and we can evolve the the browser to really reflect that new need. Will the people who currently build browsers evolve along your path?
Or are they kind of stuck in that lane because they're trying to service IL consumers? Yeah, I mean, one of the things that's fascinating is, yeah, a year ago we said, Hey, we're gonna make this AI browser thing. And everyone's like, you're nuts.
Like you've been working on this other browser arc. Why are you going to try to invent this new category? What does that even mean?
What is an AI browser? Now there are five or six vendors rushing to build AI browsers, many of them very similar to RSD. So we view that as validation that actually there is going to be this new category of browser, pseudo browser, pseudo ai.
Is it new? Is it the old thing? Updated?
There are gonna be a lot of people. And what we're deciding to double down and focus on is an AI browser for work. 'cause our view is that in 2025, when you open your laptop, you're probably doing your job or school because on the weekend you probably wanna be on your phone or on Apple TV or out in the world doing an activity.
And so if you're opening your laptop, it's probably 'cause someone's paying you to do that. And we wanna make you better at that where others focus more on the broader consumer market. How unique or custom can the experience get for each company or even for each individual user per se?
Uh, that, that is one of the things that is when we started the browser company, we spent the first year actually rebuilding the infrastructure needed to build browsers on top of chromium, which is the web and uh, web rendering engine. And we did it in a way that allows us to make much more novel and creative interfaces on top of chromium than what other browser vendors think can provide. And so if you go look at our first product arc, you'll see that, uh, it looks very different than Chrome and Safari in ways that actually challenged, uh, us in terms of novelty of people learning new things.
But it's also a lot of our beloved arc features that people are fanatical about stem from that infrastructure layer we built that allows us to develop novel interfaces in new ways. You combine that with really the properties of LLMs, which are inherently generative and personalized to each person in query you, you combine those things and we are really hopeful that a, a central value prop of our browser will be and continue to be. It is personalized for you and your job, and now your company after the Atlassian deal, uh, hopefully closes.
Um, but we're very excited about, uh, personalization as a, as a defining selling point of our product, especially personalization. That doesn't mean we're selling your data to advertisers, anything of that nature. So within the limitations of what you can say about Atlassian, how does what you're doing and what they do align?
Yeah, one of the things that, uh, we have always focused on that is in Atlassian's DNA as well, is focusing on the individual in the sense that we want, you know, Atlassian pioneered as, you know, kinda the bottoms up SaaS motion in many ways. And really in plain English, your, I know your, your viewers don't need to know this, but most people don't. That meant something that you would pick 'cause it was the best in class tool and you wanted to use it 'cause it was best for your job.
And if enough that you at the company were using that tool, maybe they would go and buy a license from Atlassian. And so we've always been really focused on the first part of that equation, which is how do we build the most helpful browser for your job, for your workday? But there's that second part of that sentence, which is what the needs of a boss or an IT department or a security department, especially in the age of browser-based security with all these SaaS apps is they need a lot of things that are not anything we have expertise in.
And so we're very excited to collectively focus on this AI browser for work focus on making the most valuable tool for the individual that they pick to use. But ultimately, if there are enough people at a company or an organization that are interested in it, what can we offer, um, the real buyers of the software and, and, and, and eventually make teams the be get better together in the browser? Actually, when we started the company was in, uh, 20 19, 20 20, like at the height of collaborative web-based software, Figma, GitHub, notion, Airtable, all these companies were coming out, uh, with very collaborative multi-player software.
And we always wondered why do you have multiplayer in collaboration at each app? Shouldn't it be at the operating system layer? Should it be at the browser layer?
So there's teams and work, uh, functionality that, uh, we're excited about with Atlassian as it relates to learning how to distribute DIA to organizations that meet their needs. But I also think there's a lot to do, but just how do you make teams work better together? Uh mm-hmm.
Just in terms of their day-to-day work and workflows. Um, how do I secure all this? Because there's a lot of people talking about prompt injections and if your browser access is something somebody can have a malicious prompt and you're connected to everything.
So that kind of means I gotta secure everything, but how do I do that? Yeah, I mean, one of our selling points is security and privacy. So we have, uh, zero data retention, uh, on our, all of our LLM use.
Our memory functionality is end-to-end encrypted, stored on device. So though you have memories we can't see them. They are passed through an encrypted channel to an inference provider.
So everything that is best in class as it relates to security and privacy, that's available today. We do. Now there are a bunch of things that are, no one really knows how to secure yet, like computer using agents, which you're referencing.
We didn't ship them. We were one of the, I think we were the second, uh, external company on open AI's computer use beta. We were in the first five of anthropics.
We had access to these models before they were public. And we said, no, no, no, no, that's too dangerous. It's not worth the trade off.
So one of the things you'll see is a lot of our competitors that are more or less a mimicry of our products have kind of championed how they have all these computer using agents that we do not. And we look in that and say, that is deeply insecure, not really that valuable, wildly expensive and wildly slow. I'm sure all of that stuff will go away.
I'm an optimist and a futurist, but it's not there yet and it's not worth the trade off. So, um, your question about prompt injections is exactly why we don't do anything related to computer use. And as it relates to kind of general assistant usage, we have a five person security engineering team that has been red teaming for nearly a year, just those scenarios.
And so you're not gonna get 'em all, but I'd think if you stack us up against our competitors, we are ahead of the pack as it relates to security and privacy. And after this deal closes, it'd be even more of a focus. So how do you envision the browser kind of getting distributed?
And I asked the question because so many of the browsers we use today are, you know, they're essentially embedded in the box that it comes in, or you just click on it and it's automatically installed. Um, are you envisioning that average end users are gonna go download this, or a company is gonna say, we want a browser that is specific to our work environment and our functions and we're gonna distribute that to our employees? I mean, I think there are a lot of interesting thing, I think this world might change in a, in a world where we're part of Atlassian, but to speak to what we've done historically, what we've found is if you're someone who spends eight hours a day in your browser for your job, then seemingly small quality of life improvements that make your workflows better are enough to get people to switch.
So for arc, we, we had consistent organic word of mouth growth that was really from people screen sharing something in ARC and someone going, what's that thing? And it starts a conversation about arc. Um, so now Chrome Safari, they're trying to be a browser for literally anywhere, anywhere doing anything on the web.
And so that means a lowest common denominator product that is very difficult to differentiate because you gotta be a great browser for my mom and for me and my little cousin, we're approaching it very differently, which is say we don't need 4 billion people using our browser every day. We want everybody that is in this conference hall to that who works in a browser for their job to go, oh, this is the professional tool made for me in my job. And that sort of software, as we know from this conference hall and how big it is, is if you make teams better and you make developers and individual workers better, they're willing to switch to new tools and they're not representative of the average Joe.
Uh, but that's not who we're going after. We're going after professionals who get paid to work on their computers. So this new project that you're working on, how far along are you guys exactly?
Uh, so DIA is actually available, uh, in general availability today for anyone to download on Mac Windows coming in the next year. Uh, so we had started working on DIA about a year ago. We've been working on arc, our original browser for three or four years, DIA for the past year.
Uh, went into private beta for DIA this past June, and it's just sort of been a, a whirlwind since then. Um, yeah, when we released it, everyone, I don't think anyone really knew what we had been up to and what's an AI browser and you know, in the last three to four months, you're seeing, uh, the market kind of surround us and, and, and take their own, uh, attempt on the, on the category. So in some senses it feels like we've been doing this a long time, and then you kind of take a step back and go like, oh, we're just getting started, others are just getting started.
We think that the winner of the space is gonna be crowned in the next 12 months. So I think if we're here in a, in a year, we're either gonna have champagne or tears, but it's gonna be a big year and we're really excited to go harder. Are the users starting to come together and be self-supporting?
I'm reminded of the early days of the Mac when the IT department kind of ignored it. So it was just a bunch of end users supporting themselves. Is that kind of the same phenomenon we're seeing here?
And Yeah, I'm not. So what we are seeing so far, and one of the reasons again we're in this conference hall, is we're seeing, uh, a, a critical mass of employees at companies independently use DIA and their IT teams or their security teams pop and go like, wait a minute, what's this thing? Like, how does this work?
Can we get? And so part, so one of the big things we're excited to, to address with Atlassian is, uh, how do we formalize what we're seeing organically develop, and how do we just go as fast as we can to bring this through as many people as possible? And for us, that always starts with shipping excellent software that is actually useful to people in their day to day and have trust and try to encourage that sort of word of mouth growth that comes from the best software, tools and technology in your life.
And that's a high bar, then it's really hard and we don't always hit it. Sometimes we get high on our own supply and like think that we built something great and we really haven't. But when you, man, when we built this, you know, integration for, uh, your calendar that pulled out video, uh, URL links and made little nice buttons to join the meeting two minutes before the word of mouth chatter we got from that.
Because if you're hopping between meetings all day, every time you're like, thank you ark, thank you Ark, thank you Dia. And so it's gonna be hard, it's gonna be really hard. There's a lot of competition, but we're, we're encouraged by the groundswell we're seeing and you know, hopefully this deal closes, we'll be able to go even faster.
All Right. Hey folks, you heard it here. The way we work is changing and it, it may be in a browser or it may be we call it something else someday, who knows.
But one thing for sure, we're not gonna be watching a bunch of tabs from now on. Yeah. Hey, thank you very much.
All right, thanks for coming back and we'll be back in a minute. Hello everyone. Um, honored to be able to talk to you all about AI powered DevOps.
Um, I'll be talking about practical patterns for implementing AI powered workflows. Um, so, uh, just a little bit of background about myself. I'm the global lead for engineering platforms and platform engineering at ThoughtWorks.
So I've been at ThoughtWorks for about four years now. And, um, 20 years of total technical industry experience. I've been working on a bunch of different things over that 20 year, uh, uh, timeframe.
A lot of it has been around developer experience and platform engineering. More recently around software, software engineering, metrics, observability, and also finops. And I, in my global role, I talk to a lot of different types of clients globally.
Um, right now, you all don't know this, but I'm in Sydney, Australia, uh, talking to a number of different financial institutions here about some of these exact topics that I'll be talking to, to you all, all, all about. And please feel free to follow me on Twitter, GitHub or LinkedIn. I post very regularly on LinkedIn and I'm working on a number of different open source types of projects on, on GitHub.
So from a DevOps perspective, one of the first things I wanted to talk about was just DevOps and where we're at, what the state of the industry looks like before we start talking about applying ai. So if you are familiar with DevOps, you're probably familiar with some of these books and some of the underlying principles from Gene Kim. Um, the idea of the three ways, which was popularized in the Phoenix project, um, and was, uh, further refined in the DevOps handbook.
And I know that there's one other book around the, the Unicorn project as well, but particularly the Phoenix Project really talked about the three principles when it comes to DevOps, this idea of flow and systems thinking, the idea of feedback loops. So once things have gone from dev into operations, how do I get feedback out of the operating environment back into the hands of developers really quickly? And then I then lastly, this idea of using that feedback to support continuous experimentation and learning, uh, that those three elements are really important when it comes to DevOps.
Of course, there are organizational things that we wanna talk about. We talk about, um, the, the breaking down the silos and the cultural change. But at its heart, DevOps is really about the flow, speeding up that flow, automating and optimizing that flow from dev into ops, the feedback loops from going from operations back to the developers and then using that to continuously experiment and learn.
And so a lot of times we start from the AI elements and we go and try and retrofit those into DevOps. And a lot of times I'm talking to clients and talking to engineers and we're trying to figure out why is that the case. So one of the questions I like to ask is, within the last six months, whose CEO has asked them about AI strategy in the last six months?
'cause there's a tremendous amount of downward pressure on DevOps and engineering organizations from the C-suite, from CEOs, from CTOs because they're getting pressure from their boards about, Hey, where's the AI strategy? What's the AI strategy look like? I talk a lot to the clients that I support about not falling victim to strategy by fomo or strategy by fear of missing out.
And so that creates this downward pressure on a lot of the engineering teams. Uh, and that means that they're taking kind of an AI first strategy, uh, to help appease the CEO, the CTO, those asks from senior senior engineering leadership. In addition, there's also upward pressure from developers and engineers that are asking for some of the cool features that they're seeing.
Hey, could we get chat GPT integrated into our deployment pipeline? The answer could be yes, but we don't want to have those architectural patterns and the DevOps capabilities that we're providing to our teams, just dictated by the cool new shiny AI feature. So that upward pressure from the developers and from the teams that we support from an engineering perspective as DevOps engineers is really, um, a lot of, there's a lot of pressure from that upwards, um, or, or parts of the organization.
So, um, there's a ton of, Hey, I've heard about this new tool, I want to implement it. I'll hand it off to the DevOps team to implement and support. So, so again, there's that upwards pressure from the engineering organizations.
There's also internal, uh, pressure about infrastructure and AI workloads and a lot of choices that are being made that DevOps teams don't really fully understand or didn't really choose. Um, hey, we're going to build out, you know, different capabilities on Azure AI Foundry, or we're gonna use ML Studio to support some of our AI workloads. Well, why is that the case?
It would've been easier to use another tool or another set of infrastructure. And a lot of those internal pressures from other infrastructure organizations and other DevOps organizations that we work with and support are just things that we, you have to deal with a lot of times as DevOps engineers and senior leaders within the DevOps organization. So I like to ask the question, well, how do we take a better approach?
Or what does it look like to take a better approach? And a lot of times I'm asking that question and I'm getting asked. At ThoughtWorks, the approach that we like to take is we like to take a use case based approach, and I'm gonna talk about some of those use cases in depth.
Um, and so the idea would be how do we beat the AI pressure with use cases, uh, around DevOps uplift? So one of the ways that we can do that is focusing on very specific use cases that DevOps teams support. Um, some of that when we talk about the three ways optimizing flow from dev to ops, how do we provide software engineering capabilities to help enable teams to, you know, move faster to develop, um, infrastructure and develop capabilities faster?
That's one way. The other one is, how do we just deploy faster? Can we use AI and agents and some of these agent and AI capabilities to just help deploy faster and also more efficiently with a higher amount of quality?
And then lastly, once it's out in production and we have to maintain operations and, and get feedback, are there AI capabilities that we can utilize from an operations standpoint to do that? Taking this youth case based approach means that you're focused on actual outcomes that you wanna deliver as a DevOps team, and you're not just chasing the latest fad when it comes to AI, or, um, you're not letting the proverbial ai, uh, tail wag the dog. Um, so I'm gonna talk about some very specific use cases around deployment and operations, uh, because for the most part, software engineering is, I don't wanna say a soft problem, but there's a ton of research and a lot of, um, investment happening in the software engineering space.
We talk about coding assistance. Um, AWS has coding assistance. Microsoft has coding assistance.
Um, every single, um, space is saturated from the coding assistance standpoint. So I'm gonna talk about a couple of use cases in the deployment, uh, area as well as the operations area, and again, practical, uh, architectures and implementation patterns for this. So first we're gonna look at something internally at ThoughtWorks that we've been thinking quite a lot about, which is called prompt powered pipelines.
This idea of AI assisted infrastructure as code. And traditionally, when we think about infrastructure as code and DevOps teams, they just generally start by taking kind of a broad inventory of all of the different parts and pieces that are making up a particular application or system. There might be web server components, there might be backing components, uh, databases, authentication services, networking.
So there are all these types of components. And traditionally, if I'm thinking about microservices or three tiered AR architecture, some of those are cloud native. Some of those aren't cloud specific infrastructure.
Some of them are on-prem. So the starting point is some of the same types of investments that we're already making about just understanding what's, uh, a part of the tech estate. And a lot of teams are already moving down the path of using infrastructure as code capabilities.
They could be using Terraform, they could be using, uh, plummy. There's a ton of different tools that they could be using. So where does the AI portion come in?
So one of the things that, uh, we've been doing with one of our, a couple of our clients is automating some of those capabilities using agent orchestration, um, techniques. So this would be, Hey, I might have the front door of, uh, DevOps or development IDP, uh, that, that's being supported, being backstage. And I want to provide very specific AI powered capabilities to developers that could be them wanting to have the ability to increase, uh, podcasts in a, uh, particular Kubernetes cluster.
And I can orchestrate that and provide a bunch of different feedback mechanisms to developers, uh, u using some of these agent capabilities. So I can have, um, agents that are interrogating OPA for auto approval when it comes to cost. Um, I could be generating net new Terraform and then running that code in a test environment to make sure that it's fit for purpose.
Um, I could be detecting Drift, um, as a part of those AI capabilities. So there's a number of different things that I can do to assist the traditional infrastructure as code, um, capabilities and provision resources in a more agentic way. And again, those are very specific types of use cases that we can provide.
And we don't have to go overboard and have AI just for the sake of ai. We can actually provide fit, we can actually provide, uh, capabilities to the developers so that they actually are getting some value. And so this is just one example of what that would look like when it comes to AI assisted ai, um, infrastructure as code.
So again, I could use that to generate new code and interrogate existing systems. Um, Azure in particular, um, has a, a lot of great capabilities when it comes to copilot on understanding the existing tech estate. So does AWS, so does GCP.
Um, but we were utilizing this, uh, for a customer that were already, that was already on Azure. But again, these could be switched out for any number of different cloud providers or on-prem capabilities that are there. So one of those particular solutions is around AI assisted, um, uh, uh, a IC.
Another one that we are looking at is prompt power pipelines. So this idea of two use cases within that, which is how do I create, um, the feedback loops between some of the CICD pipelines deploying into production, and then getting back a number of different things. So we, we like to think about this under two, two use cases.
One, AI agents that are creating CICD pipelines. So think about if I'm in GitHub or using GitHub actions, or Circle CI or any of your favorite, um, CICD platforms. Uh, what I want to do is be able to have playbooks and run books to create new, uh, pipelines based on whatever a developer wants to produce.
So I like to think about developer archetypes, which are collections of capabilities that developers want to utilize, and then exposing those through my DevOps automation pipelines. So, uh, if I wanna create a new Java application, of course I can create a new GitHub repository or a new Bitbucket repository and then instrument the, uh, pipelines. But I can also have AI agents there to act as automation, um, tools to provide those different, you know, pipelines and capabilities, both by, from a playbook and from a code example, um, standpoint.
And one important thing that we, we like to talk about when we talk about kind of the crawl, walk, run perspective is ensuring that they are humans in the loop for some of those ai, uh, creation, um, uh, AI creation capabilities. So in this particular instance, we have humans in the loop when we're suggesting new CICD pipelines that are there. But then, particularly when we're talking about use case two, performing tasks within the CICD pipeline, it's super important to have a human in the loop.
If I'm creating new prs, if I'm spinning up test infrastructure, if I'm performing any of these tasks that would be in the CICD pipeline, providing feedback back to the developers, we wanna make sure that there are humans in the loop for those capabilities. In this particular instance, we're taking in a ton of different data, a ton of different, um, types, a ton of different data, a ton of different examples to, uh, create some of these CICD pipelines and to perform some of the tasks there. Uh, but it's still anchored in, Hey, we wanna do a pr, we wanna do GitHub.
We wanna provide these capabilities there, um, particularly around either existing incident that are happening in a production environment or other tasks that I want to perform. And again, following the three uh, ways, it's all about feedback. It's all about kind of extending that feedback loop and getting feedback back into the hands of developers as quickly as possible.
Uh, one additional thing we wanted to interrogate on is around, um, how does it look like across multiple teams? Um, so, um, we, we think about the individual teams for all of these different, uh, pipelines that are there. And again, I might be using the pipelines to orchestrate different AWS services or different EKS infrastructures, both serverless and, and, um, other AI capabilities.
But there are two key points where we can inject ai, one, AI for governance as a part of layering in the pipelines there. And then the other one is, um, using AI and things like open policy agent to provide policies. So those are the two areas that we really, really see AI providing a tremendous amount of uplift, particularly when we're talking about finops or security or compliance.
A lot of those rules for how infrastructure should be getting provisioned or how pipelines should be hap uh, be be getting provisioned, and what feedback should be going into back into the hands of developers could be, um, orchestrated and can be provided through AI agents at the point of a commit or a PR emerge, or if I'm using trunk based development as soon as I do a check in there. So there's a ton of different types of ways we can inject the AI into those use cases so that it makes it fit for purpose and provide a lot of up uplift and streamlining for the developers. So we've talked about kind of, if you think about the three ways we've talked about dev and increasing flow, and we've talked about some of the feedback loops.
But finally, we wanna talk about some of the operations, uh, AI use cases that we could, uh, utilize to pull back feedback and a number of different mechanisms and ways. So I'm gonna talk about two use cases in particular. One is around observability and automated, uh, PR changes.
Um, so this particular one is one that, um, we've been utilizing with our customers. Um, and, um, our customers can use a number of different observability tools, things like K Chronosphere or Root, uh, but what we've been doing is creating predictive models with our clients, identifying adverse conditions within the observability area, and then creating automated PR changes that then get interrogated by a human. So we're talking about feedback, we're talking about some of the lowest, uh, earliest signals of adverse conditions, and then being able to pull those things back and identify what those things look like.
Again, a human is in the loop, so we're not talking about agents going off and creating their own prs and then merging those in and those getting deployed. But we're talking about uplifting the amount of, um, observability, the amount of feedback that developers have in their hands through some of these, um, through some of this data that's out there through some of the observability tooling that's out there, and then through some of the historical instances that's out there. Um, so we're actively working on these, and this is a pretty good reference architecture about how to implement some of those, uh, changes, uh, from a PR perspective.
And then lastly, it's a, um, we, we wanted to talk about alerting. So I think most DevOps and operations teams, um, suffer from alert fatigue. Um, I know I do, um, I've been on call before and I've had a number of issue instances in which, um, I have an alert and the alert, uh, doesn't happen so well, or I get a lot of false positives and I'm waking up and I'm going, oh, okay.
That's not a, an alert that I need to, um, take care of. And what that generally leads toward is, uh, what that le generally leads to is people ignoring alerts, right? They are, um, you know, not they, they, they've been hit by so many alerts, so many false positives that they've, you know, generally ignore those.
And so what we've been doing is injecting AI into the alerting systems and into operations so that we get much better, um, much better alerts and their AI power alerts. So a lot of the false positives could just be start, could just be, um, you know, Hey, we are on the wrong release, or there's some sort of knowledge that was changed. So we've been hooking in SRE AI bots into different systems, systems like Datadog, uh, systems like authentication or KYC systems, if it's a banking or financial institution, ticketing systems, if it's hotel or hospitality, or even travel and tourism.
And then actually taking in glean and other knowledge sources. Um, we, we also have partnered with Unblock on, on, on some of these and implementing these AI and RAG systems. So now I get knowledge about the systems and about previous alerts, um, and historical alerts that are there.
I get real time data from Datadog so that I know what the adverse systems are, and then I'm connecting to my actual systems. So I'm pulling in all of that data and putting it into the hands of my frontline instant support agents. So I'm not only decreasing the amount of false positives from an operation standpoint, but I'm also providing much richer data when I'm going to interrogate something either through Slack or Ops Genie or PagerDuty or any of those types of tools.
So it really acts as not only a way to interrogate and provide some of these things faster, but it also provides much richer data, more AI enabled data that's there. So this is another area where we've seen a tremendous amount of uplift from a dev perspective, but also from an operations perspective. 'cause we're dealing with both, uh, parts of the organization working as one when we talk about DevOps.
So, so lastly, one of the questions that I get asked a lot are, well, Ricky, there's a ton of people that are a part of the organization, and I might be in one siloed organization just focusing on infrastructure, and I may be in another or part of the organization focused at a product leader. Uh, what can I do to kind of help solve some of these problems? Oh, well, first, let's talk about tool chains.
Uh, before we talk about what people can do, um, one of the interesting things that, that we do, we like to do is take a lot of the reference architecture when it comes to ai, DevOps tool chains, and then apply different types of tools to it. So some of the newer tools that we've been really, really taking a look at, um, are tools that provide developers with feedback faster. So, um, a lot of times we've talked about shift left capabilities, but now we're talking about AI powered shift left capabilities.
So a couple of tools that I just want to highlight, this is an entire tapestry of different ai, uh, tool chains, um, and different capabilities that could co that could come to bear across different cloud providers that we are, we're partnering with. But two tools that I'm actively using that I think are really, really good to provide feedback to developers quickly, um, around the PR perspective. Code Rabbit is a tool that, um, I've seen, um, really could have provide great PR recommendations at scale for a lot of users.
Um, and a lot of developers that are there. Prs are a big problem. I think the only problem that's ranked higher than PRS amongst a lot of the anecdotal evidence that I have is testing, but we're not here to talk about testing.
We're talking about some of the devox capabilities. So, um, that, that's one area that we've seen a tremendous amount of response and a lot of feedback and a lot of uplift when it comes to both productivity and just improving DevOps practices is around prs. And Code Rabbit is a tool that we've seen help, um, accelerate some of those things with a, their AI capabilities.
The other one is a lot of clients are saying to me, well, how do we unlock some of these observability technologies that we, we are there, we feel like we have to have the right standards, the right logging, like all of these different things that are, that are, that are there so that we can unlock some of the downstream AI ops and the AI capabilities that are there. Um, when I'm in operations and one of the tools, it's an old tool. It's one that's near and dear to my heart, uh, but Open Telemetry is a tool that are providing a lot of different great frameworks, both from an auto instrumentation standpoint, um, which is not necessarily AI powered, but then how do I go from no open telemetry instrumentation to a lot, I can use AI and LLMs and different comp, uh, capabilities in the AI space to add more open telemetry of, of instrumentation into my existing tool sets and in my, in existing code.
And that provides me with a great foundation to kind of uplift and start moving forward there. So I wanted to talk about the entire, uh, DevOps tool chain will highlight some very specific tools that we started to see that I've started to see personally really provide a lot of value in the AI space, both from a foundational standpoint and an ai, um, specific standpoint. And so, going back to the point earlier about different people within the organization and how can they help, um, I like to think about this around four types of leaders and four types of personas within the, the, uh, organization.
What can kind of like the engineers do, um, as a DevOps engineer or a platform engineer, or just the engineer that's writing code. Um, I think the idea of mastering the fundamentals is extremely important. I like to say, uh, why are, are, why are people asking about AI components when we can't do CICD builds?
Um, and we can use AI as a way to uplift those engineering capabilities, but it shouldn't be kind of like chasing the shiny object, as I mentioned. And there's, again, gonna be a ton of downward and internal and upward pressure. But taking that, making sure that that focus is on product thinking and systems thinking and use case space and investments in AI is going to take away a lot of that pressure because you're gonna be able to measure impact, you're gonna be able to have some things that you're anchoring around.
And, and two more leaders that I wanna highlight from a technical perspective, if you are a head or a, or SVP or VP or a head of a DevOps in your company, it's really gonna be about creating a culture, um, and creating an environment that is fostering a lot of experimentation. There's guardrails, uh, because one of the anecdotes that I like to, to talk about is around a lot of organizations just throwing GitHub copilot or throwing some of these AI coding assistant at their engineers. And ultimately what you see is that adoption plateau at around 40%.
Um, and the reason why that we see a lot of that plateau around that number is, you know, not being able to kind of cross the chasm and really create an environment that is fostering, uh, adoption. Um, and that's really, really important as a technical leader if you want to see some of the investment come out of, of, of ai. And then lastly, talking about business leaders.
Um, that may not be, you know, involved in DevOps or some of the AI investment, but it is just creating that pressure, uh, or the hype or, or, or those things. It's really about, Hey, let's invest in the foundation. So let's make some smart investments before we start really investing in ai.
So that one, we can pivot and take advantage of any of the new technology that's out there. 'cause we have the right engineering foundations, we have the right DevOps practices in place, but it's really about how do I have that major unlock, how do I get the productivity and, um, the revenue growth and the innovation from implementing these, uh, types of AI investments. So again, those are some of the, the key highlights that are there.
And, um, it was a great, uh, 20 to 30 minutes talking to you all about DevOps and ai, uh, use cases. Um, please feel free to reach out to me, uh, after the talk, and please enjoy the rest of the, the virtual sessions. Thank you.
Hey everyone, it's Alan Shimmel from Techstrong. Welcome back to another platform engineering show. org community.
Luca, my friend, it's been too long. Too long. It's been too long.
We've been busy though. Yes. How, how have you been?
How are you doing? Well, you've been I've Been good. Yeah, I've been, you know, I've been running around.
I I was, I was in a, you know, don't, don't cry for me, right? I had to go to Napa Valley to a conference, drink some wine, do some videos. I was Houston for a, a risk operations conference.
I was in Austin. I I've been, I've been traveling a bit, you know, busy and, and AI the whole time. Luca, this AI thing is just, yeah, crazy.
What about you, my friend? Where are you, VIN? Yeah, same, same busy in Q4 is here is upon us.
Uh, old events, all the things. Um, we, we hosted platform called Paris together with, uh, we scale our partners and friends, um, last week. And it was awesome.
Paris. It was, it went really, really well. Um, there was way too much eating and drinking involved, uh, on my end.
Oh, we visited Paris Beautiful there. Yeah. Yeah.
But he was awesome. And actually look, uh, the, the, the CEO of we scale, uh, he told me like, oh, there's a little surprise when we close the event. So him and I did the, the closing panel and then there was, uh, literal champagne and full gra for everybody for like an hour and a half.
It was, it was pretty epic. Wow. Oh, that's epic.
Epic. Yeah. Alright.
Besides the food and drink, Luca, what, what was the learning? What was the, the, you know, curriculum over there? Yeah, well, so we, we kind of kept the structure similar.
Uh, if you remember, if people remember to the ones that, that we did in London and New York. So we kind of had this like main track, that was the main stage. Um, we had Kelsey au, we had Gregor Opa, we had incredible speakers.
We had a lot of also like real case studies from enterprise practitioners, from very large French companies, for example. So it was super cool. The, the content was also, and then we had this combination on the side of trainings, round tables, workshops, um, that also worked really, really well.
Uh, so the content program was awesome. Um, in terms of, you know, like the main things throughout, it's kinda like the usual aspect. You mentioned AI before, um, there was a lot of chatter about kind of the intersection of AI and platform engineering and how do we think about that?
And I think similar to what we saw in London and New York in June this year, there was really, I think it people were really highlighting this kind of dual role of platform engineers as both consumers of ai, of course, uh, like everyone else. Um, but also as key enabler, um, of ai. Yeah.
Um, and in fact we were discussing, um, there was this, um, uh, let me actually pull up real quick because there was this, uh, uh, a recent report by, um, garner, um, and 2025 strategic trends and platform engineering. And they were predicting that by 2028, 60% of developer interactions with platform engineering services will be via conversational AI and AI agents. Also, 60% of internal developer platform will include AI agents.
And then 30% of internal developer platform users will have given agency to AI agents for specific steps. So really, and, and, and so you, that was kind of the, the first bit, right? Of like, you're really seeing AI being infused across platforms all over the place.
Obviously these are predictions, you know, 2028. But I mean, another thing that we discussed at the conference was this original prediction. I dunno if you remember, but we, we discussed a couple of times, um, I think this was back in 2023 when Gartner said, by 2026, 80% of our, of enterprise organizations will have some sort of platform engineering, um, thing in place.
And I remember at the time when it came out, it seemed very optimistic, very aggressive. Uh, but I think we're in tracking. In fact, I think Dora, the new Dora report came out yes, just a couple weeks ago saying like, well, actually we're seeing 90% of enterprises have some sort of platform already in place.
So we even beat the original forecast of mm-hmm. Garner. Now, I think like that forecast was a little bit more solid in terms of foundation that this like AI infused, um, RNs, like there's not that many data points that they can draw this from, but still, I think, you know, very, very interesting.
And so that's one part, right? That's the kind of the, the platforms are being infused by ai, but then obviously there's the, there's the other part which is platforms for AI and platform engineers as being key enablers for AI adoption across, um, the enterprise. And, you know, we discussed a lot this infamous MIT study, right?
Of the, like, 95% of pilots are failing in the enterprise, whatever. I've seen actually some people debating that and how true that stu like how, you know, double blind or whatever that study is. Um, but, but regardless, I think we all know at least anecdotally, right, that there is this gap right now between very impressive, you know, day one or day zero demos, right?
Of what you can do and then the actual impact that you can drive on an enterprise scale day two, day 100, which we know also from CIS admin, from platform engineering, you know, is the day two, day 100 stuff that actually really delivers the value, right? Um, and so, and so that's what we're seeing, um, a lot of the responsibility and the ownership and the load already shifting over onto the platform team. Um, and it's interesting, we recently did, we recently published our state of AI and platform engineering report in the community.
Um, and we, uh, asked, you know, hundreds of teams there and, and I think it's 36, 30 7% of all the AI workloads agents workflows already owned by the platform engineering team up from, you know, like five, 10% just a year ago, right? So I think you can already see this like shift and, you know, and I think even if you look at like, um, sort of ad hoc AI and AI ops teams, they're still relying, uh, on the platform at the end of the day. So really you could actually argue already 50% plus of all AI workloads, uh, uh, and, and, and workflows are already kind of supported by the platform engineering team.
And I think that's only growing. So, um, that's, you know, where I think we keep going back to the fact that, you know, there's been a lot of trends that we've discussed and, uh, you know, especially you've covered in the last 10, 15 years in the enterprise that, um, I think have been overshadowed in the last 18 to 24 months by AI in the enterprise. Um, and I think a platform engineering holds strong as actually one of the few ones that not only hasn't been overshadowed, but I would argue it's been turbocharged by ai.
Um, because people are realizing like, Hey, if I wanna move past this initial, uh, you know, quick cool demo and, and go, you know, to something that actually lets me deliver on the promise of AI in the enterprise, I need some well-designed platform underneath it. Yeah. You know, Luke, I, I'm listening to you.
com about AI's influence on platform engineering with some real things you should, you could do to make, make AI your friend, not your enemy, right? Yeah. For, and, and this goes beyond platform engineering.
I think it goes everywhere that AI and AI is everywhere. You could, you could embrace it and, and make, help it make you better, help make what you do better, or you could resist it and you'll get steamrolled, right? You, you, you, there is no, you can't run away from it.
You can't hide from it. That being said, you know, we had Nathan Harvey from, uh, Google, uh, at the DevOps experience virtual event, I think you presented. I Yeah, yeah, yeah, Of course.
Uh, NA, Nathan, Nathan gave, you know, the report, the Dora Report Aren't, yeah, well he's in the Dora working group. Yeah, yeah, Yeah. Yeah.
He, you know, he's, he's kind of the, a lot of the face for it. So, but here's the thing. I'll go back to early DevOps.
There was this huge debate, ah, DevOps is both bulk. DevOps doesn't work. It's, it's just a marketing term, right?
And it's a lot of kumbaya about cultural stuff, but it really doesn't. And what we saw in DevOps is when individuals or into, or small teams, you know, an individual started using Puppet or Chef or Ansible, they started using Jenkins or, or you know, some other CICD tool and, and they brought it to their small team. It worked.
Yeah. People were like, yeah, this is real. It's great.
Yeah. And then you go to a large enterprise and you had a little small team here using Jenkins and this little small team here use something else. And this little small team there, something else, and all these little small teams, it was working.
It wasn't until you brought it all together and said, okay, now we're gonna roll this out enterprise wide. That you started saying, wait, wait, we can't use five different CICD tools. We can't use Puppet Chef and Ansible.
We've got a, or, or Terraform or, you know, whatever. We've got it standardized on one tool across the enterprise. Right?
And that really is what gives rise to platform engineering. People say, wait a second, we gotta standardize on a platform, not 12 platforms. Right?
Each little team can't go off. And, and so we had a very similar kind of thing in the DevOps space where yeah, everyone's using it, but does it really work? 'cause everyone's using their own flavor or whatever you want to call it.
But you know, you, you cited the Gartner and I, I've also looked at that Gartner report very, you know, very encouraging. Let me tell you another report that I've seen, though, 90%, 90% of developers are using AI to help them code, whether it's in the IDP or in Git or what have you. 40% don't trust it.
40% don't trust it. 65% say it absolutely, uh, introduces instabilities into their code base. Yeah.
Vulnerabilities. Yeah. Yeah.
So think about, well, not just vulnera either vulnerabilities or other instabilities, right? Right. Mm-hmm.
But, but let's just think about the logic here. We know 40% of you don't trust it. We know 65, 2 thirds of you think it introduces instability, but yet 90% of you are using it.
Yeah. Like what, where that, that's a disconnect. It's like, yeah.
You know, just the heck with it. I don't care if I don't trust it, I don't care if it introduces. Yeah.
Well, because it Still accelerates productivity so much, right? That Yeah. And if you don't do it, you're the only one falling behind.
'cause you don't do it. Well, It's FOMO that you just said. Yes.
Fomo. There's a lot of fomo. Yeah.
Because you say it accelerates. Yeah. I've seen other studies where it says it decreases develop for Yeah.
Or you think it accelerates, Right? You think it does, but it actually decreases developer productivity by 19%. Now, whether you believe that or not.
Yeah. 'cause there's a million, you know, there's lies, damn lies. And then there's metrics.
Yeah. So, You know, but, but I think we're still at that kind of prove it stage right. With, with this, and, and here's my other, and I'll just say this quickly and throw it back to you.
Do we need a new platform for the AI age? Or can we ai empower the platforms we've been building, right? So in words, can we build on what we've already got or do we gotta just like, I've heard people say we need an AI stack.
Yeah. Right. We we're not going to use the old stack.
I'm not a big fan of throwing out things that work. Yeah. Right.
Yeah. Me too. Me too.
I think, and by the way, just to add to what you were saying, I think like this, this just really speaks to, um, just the enormous, you know, kind of revolutionary thing that we're living through right now. Yeah. Because, you know, also, like I, I was, you know, people keep saying like, okay, you know, all this ai, there's, there's, we're like over-investing in ai, you know, we're the, the spend of the Googles, the opening eyes, whatever, it's crazy.
Um, and like yes. You know, those are massive numbers, right? And, and especially if you compare it to the revenue captured, it's, it, you know, there's a big mismatch right now.
Finger Port is Somalia. Have you seen that one yet? Yeah, yeah, yeah, yeah, yeah.
It's Port is Somalia. Exactly. And so there's a big mismatch.
However, you know, I was listening to this podcast the other day. It was very interesting. 'cause there were, um, they were actually, you know, differentiating between like, yeah, it's true.
The revenue capture today. You know, there's a big mismatch. But if you think about the value created today, um, you know, you could argue actually that there is like a, a, a match, right?
Because I mean, everybody's using it. Like, it's, it's insane, right? Like the, the penetration of usage.
And like, I just see myself both on my personal life and my work life. 'cause the AI usage that then I'm just paying like, what, 20 bucks per month for like, it's crazy. Like the, the value it's created for me is like many, many, many multiples of 20 bucks per month.
Um, you know, so, so, but, but there's still no like clear mechanism, right? Um, like Google a little bit when they figure it out, okay, well we can do the sponsor Blue links, right? And it is like bang, you know, and there's like the man, the money printer started.
So I think we're also in that phase that is, is very, very interesting. And I think all these, 'cause let let, hold on, let me throw something out at you. Yeah.
You're paying 'em 20 bucks a month, how much is it costing them? Yeah, exactly. Probably.
Exactly. This is the thing. They're Not capturing, you don't it up in volume, but They're not capturing the value that they created for me the right way.
Right. Because it's like, even just like, you know, we're just talking offline about like, me buying a house, like the, the amount of money I saved in, in like consulting experts, um, just by like going back and forth on like deep research stuff with Chad GPT. It's crazy, you know?
Yeah. And like, of course, in the end, you still need an expert, but like, instead of like waiting for like three weeks and like doing a call every 10 days because these people are busy, you know, I just did one call just cost me like 500 euros. That's it.
You know? Yeah. So it's like, it, it's, it's insane.
So that's saving me probably like two, three grand, and they captured none of that, right? Yeah. Like, so it's, it's very interesting.
Um, but yeah. Anyway, so going back to, uh, to your thing, to your question, I, I agree. Like, I'm also not a fan of, of, um, you know, throwing everything away.
And, and I think that was exactly a big topic or conversation in Paris last week, is like, look, at the end of the day, um, in fact, I, I'd argue it's, it's really about using the same golden pads, the same kind of paved roads that we've already been building. Um, uh, and, and, and in fact, this is the ultimate stress test, right? Because it's literally like, if you think about a road, right?
For example, it's like, well, you could have like a road that's like not really well maintained or not really well built, right? And then it's like, okay, well you can have maybe one car driving over it, two cars, three cars, right? But at some point you're like, it's causing problems, right?
Whereas, um, you know, and like essentially going from like X amount of developers to X amount of developer plus y agents, plus, you know, z ai enabled the developers, right? It's like you're going from like, you know, 10 cars to now like a million trucks and they're all like running. Yeah.
You know, they're all driving like super fast on the same road. Yep. That's not gonna work.
Right? But to think that's, that's, that's actually why I think AI and platform engineering, um, you know, I think, you know, there were a lot of people also being like, oh, if it wasn't for ai, platform engineering would be the number one training enterprise today. And again, I think this, even this just exposition is not the right framing.
The right framing is like, what can AI plus platform engineering unlock? Um, and I think it's huge. And, and it's actually just leveraging the existing stack, to your point.
It's leveraging the existing, um, design golden paths, but just is gonna push them further in terms of better design, um, and better constraints, uh, and, and better, um, design thinking around what's the right level of obstruction versus the right level of context that you wanna provide to different users. Yes. You're expanding the number and type of users, right?
Like we said, we go from just app devs essentially to ml lops engineer, data scientists, agents, you know, agent enabled people. But ultimately it's, they're all driving on the same highway. It is just, it's gotta be a better highway.
Uh, absolutely. So here, here's the lesson. I I, you know, we talk about this a lot at Textron on Textron gang, on podcasts like this.
We write about it A mistake some company or some organizations are making are, they're looking at what they have now and saying, okay, by using ai, I can make this better. But what they're not taking into account is that by using ai, right? So instead of let's use your highways, instead of saying, look, I can make a two-lane road, a three-lane road.
Yeah. And I could smooth it out, so I'm gonna have less traffic, I'll be able to go faster on that road. Great use of ai.
But what they don't take into account is that by everyone else using ai, I now need a five lane road. Yeah. Right.
Or a six lane road. So it's like you, you can't use AI sometimes I think just for incremental to improve your current situation, you've gotta think about what's this gonna be like in an AI enabled world where it's not just the platform, but the developer, the security, different hacker, everyone is using ai, and what does that do? I need a superhigh now, not just the three lane road.
Exactly. And so let me build that superhigh and that, like you said, that starts bringing in who else is gonna be driving on that road, right? And so there's all these other players now that are, that are in the mix that we gotta account for.
And that's what AI is doing. It's like, it's not just Turbocharging platform engineering, it's turbocharging the whole, the whole game. Everything.
Everything, everything. Yeah. Interesting stuff.
Hey, is, is any of the Paris in person stuff recorded available on the website? It is, it is. It's gonna, um, I am not a hundred percent sure yet when it's gonna be edited in live, but I think it's coming very, very soon.
Either this week probably, or latest next week. Um, so then we can link it in the episode notes, um, and, and, and share with people. Um, but yeah.
Um, and then onto Perfect. The next one you're gonna be at, uh, Q Con, right? I'm gonna, we're gonna be broadcasting live at Q Con on the show floor.
Uh, uh, my friend Steve Foskett in the tech field day are doing the tech field day there. I'm trying to remember the date off the top of my head. I wanna say it's like November 10th, something like that.
11th week. Yeah, November 10th is, is the, well, November 10th is the co-located events the day before. Right.
That's also when Hazel Cube happens. Um, and, and so that's when we'll party. And then, okay.
On the 11th is, is when the conference kicks off. Yep. And we'll be there.
I think I get in the ninth actually. So, well you Are coming to as a Cube right here. I'll be at House of Cube for sure then, and then, uh, know we're there.
I guess, I don't know if I leave Thursday night, Friday 'cause for Us, I'm on Thursday night. Yeah. We, we have Actually, well, we have a short flight for me.
I mean, it, it nice not down here. I'm actually going down to, we're hosting this, uh, platform day, um, in Sao Paulo in Brazil the week after. So I'm going down there.
Really? Which I don't know, it's like so, so European of me. I was like, oh, you know, once you're there, it's gonna be very close.
It's like not Power flight was a far ride, my friend. Yeah, that's a far ride. That's probably from Atlanta to Sao Paulo I think is further than to Italy For you or close.
Yes. About the Same, same nine and a half hours flight. So I think it's very similar.
Yeah. Uh, I Was like, yeah, we have, uh, Brian, one of our cameramen, his wife is, she's Brazilian. She's home in Brazil right now.
So we were just talking about how long that flight is. Yeah. It's so long.
Yeah. Now if you went from Atlanta down to Miami and stayed by us for a day or two before going to Brazil, that Would be easier. We Could not, we could take an hour off of that, but maybe, We'll see.
Maybe I'll do it on the way back. Let's talk The way back. You, let's do that.
We'll talk. All right. But CubeCon, lots of platform engine.
They're I'm sure, are they having their platform engineering? Yeah, There's a platform engineering day that's also on the Monday throughout the day. Then people come to us Cube for the party, and then we kick it off on the, I guess it's the Tuesday, um, with the, with the main event.
Yeah. And we'll, we'll have a lot of stuff there. We'll, I mean, you're doing the, you know, the interviews and I've been doing videos all, all week there on the show.
Floyd, we'll do stop by, we'll do video. Perfect. Let's do that.
We'll do workshops. We have a couple of round tables that we're hosting with ThoughtWorks and other people, so it's gonna be fun. It's pretty busy.
Good stuff. CubeCon. I I'm interested to, you know, lately the European, uh, Q con have been bigger than the North America.
Yeah. So I'm interested to see if that holds this Year. Same.
I was, I was, I was having this conversation literally with somebody, um, a couple weeks ago. 'cause she was telling me that, well, it didn't used to be like that. It used to be No pre COVID.
The US was bigger Pre COVID the US like, uh, the one they did in San Diego was big. Yeah. And the one in Seattle, but dang, during COVID.
Well, I also think it is like, you know, San Diego, Like probably people san it wasn't bad. Been a Lot of like, Detroit and Chicago and Winter is like a different vibe. Look, I don't know what they were thinking between you and me, but, you know, look, they make a, they make a cube call.
We go, yeah, Atlanta is, I don't know if, how much time you spend in Atlanta. Never. Atlanta is a nice, nice dtl.
It's a, it's a nice town. Uh, they got good stuff there, you know. I mean, look, it's not Paris, but, uh, it, it's a nice town.
It's a, it's a nice town. Nice people. Well, Looking forward to, uh, to seeing you there.
Absolutely. Luca, we gotta pull the plug on this. It's over a half hour.
Yeah. But I will see you there. And we'll, my promise is we're doing more of these regularly.
I, we, we let this go about the Travel. Yes. We can let this go.
Yes. We gotta do it from the road. Yeah.
All righty. Luca Gallente, platform engineering community here. org.
com. We'll see you next time. Hey everyone, it's Shimmy, and welcome to another Shimmy Says, so here's what I got for you this week.
You know, I wrote an article, uh, November 3rd over on Techstrong, it called Tech Heal Thyself. It came out of, uh, I was reading a book review in the New York Times by a book, uh, a fellow named Tim Wu called The Age of Extraction. And in this book, Tim worked, I think in the Biden administration, in the antitrust, uh, division of the Department of Justice, uh, was saying that big tech has transitioned from innovation to extraction.
It's not that they're necessarily innovating anymore, but they're about extracting value and extracting data, which is value from all of us, and that that's where it's at. And that we need the government to step in here and know maybe with some strong antitrust, uh, legislation or moves, try to move us off this age of extraction. And I read it, and I, I'll be honest with you, I, I thought to myself how quaint that we think the government's gonna help us.
Because in today's world, you know, the government has traded their referees striped shirt to wear the jersey of the home team. And we can't think that the government actually is in bed with the tech bros. They own a piece of the action here.
So we can't be looking to the government to help us out of this conundrum. And why is it a conundrum? I'll, I'll tell you why.
It's a conundrum. Because we are letting seven, eight, or nine companies, we're letting seven, eight, or nine companies dictate to us what we're doing and how we're doing it. They are controlling the, the narrative.
They're controlling the technology. They're controlling everything we're doing. Now, look, I've been in tech a long time.
We, we've seen that we, you know, one of the great stories about tech is you could get two people in a garage and start the next Apple, or the next Microsoft or the next Google. It's happened before and it should be able to happen, happen again. But what I fear is, in today's world where we have AI and we have robotics, or physical AI as we're calling it, or we, and we have, you know, the right on the horizon, quickly following in the rear view mirror quantum, that the barriers to entry here are so hard that we're not allowing for new growth in the forest.
We're not allowing the next batch of innovators to start the next group of great companies that'll carry the, the this forward. Where's the next Google? Where's the next meta gonna come from?
If you need hundreds of billions of dollars to play at this level? And I thought some more about it even after I wrote the article. And you know what, here's what I'm convinced of, though.
Innovation will find a way. I'm reminded of, if you've ever watched the original Jurassic Park movie, you know, when Jeff Goldblum's in the, in the laboratory where they're showing them how they, uh, you know, engineer the DNA of these dinosaurs, and they say, well, don't worry, all the dinosaurs are female, so they can't breed. And Jeff Goldblum says, life will find a way.
And sure enough, if you know the story in Jurassic Park, they figure out how to breed. And we've seen it in real life. These stories do happen.
There's a term for it, scientific term for it. I don't remember right now, but I do believe innovation will find a way. And what I mean by that is that we, people who are smart, people who are innovating, people will find a way to, to make a better mousetrap, to be more nimble, more agile than these be myths are.
Um, But we need to encourage it, right? Right. Now, as I said earlier, with these eight or nine companies, we're watching the biggest technology consolidation of power, not just in technology, but a consolidation of power that we've ever seen.
And it, and it's like this circular financing. Microsoft invest in open ai. Open AI then gives that money back to Microsoft for Azure hosting.
So the money just really doesn't even change hands. It just, it goes through a circle thing. Uh, Google and Anthropic doing a similar thing.
Amazon's involved in their Oracle and Nvidia swapping it back and forth to their own exclusive stuff. It's a merry-go-round. But it's, it's a hundreds of billions of dollar, trillion dollar merry-go-round where each one of these eight or nine customers plays different parts in different parts of the movie.
They play different roles today. They're a customer later, they're a partner tomorrow, they're an investor. And it's an all of, but it's a small circle of just their businesses.
And as I said, don't hold your breath waiting for Washington to break this up. Washington's part of it, right? So at the end of the day, what's, what are we gonna do here?
Innovation will find a way. It always has and it always will. Um, I'll give you some more examples.
IBM, even though they invented the pc, really didn't see it. The, the rise of it and the impact of it, and they missed it. No, NOIA and Blackberry didn't see the iPhone coming until they got run over Google didn't think of a Facebook face.
Facebook didn't think of TikTok. TikTok disruptors always show up where you least expect them from a blind spot. It's the place the giants aren't looking.
We saw it just a few months ago with deep seek. It, it shook, it shook the heart of our AI oligarchy here in America. It was really, was sort of a Sputnik moment, right?
Because the audacity of these guys to do it cheaper, faster, without the whole Cadillac around it. But this is, I think, the future that we have to look for. We need to find, you know, people are gonna figure out how to do these things smarter, faster, and leaner.
And when they do, I think the market will reward them because no matter how hard the tech bros and the oligarchs try to hold it in their hands, the tighter they squeeze, the more it is like sand going through their fingers. They, the harder they squeeze, the more the sand runs out. But make no mistake between AI and robotics and quantum, we are on the fifth wave, or a fifth industrial revolution.
But this revolution, like ones before, won't necessarily be won by the biggest factories. It'll be run by what, how people rethink what a factory even is. What it does and how it works.
And to me, the biggest counterweight to all of that today is open source. Open source has gone through its own revolution, right? I remember in the two thousands, early two thousands, most enterprises had a no open source policy.
Ludicrous. Today, 99% of enterprises use open source. So it means using open source, source synthetic data.
It means decentralizing compute. So we're not just dependent on these huge AI factories that the mag seven or the eight or nine are, are going to be using. These are the tools of the new rebellion.
Go a little Star Wars on you here, right? We've gotta rebel against the empire. These are the tools of the new Rebel rebellion.
The ways are, we've gotta be small, but nimble innovators who outthink and can outrun run in between the giants. So given that, right, how do we all not become slaves to the, to the big eight or nine? How do we help the rebellion in our own way, you know, without becoming X-Wing pilots or something.
Well, I got a couple of shimmy rules here for you on how to do that. Number one, double down on open source. You use open source today.
Use it more. Support your open source projects. Support your maintainers.
Support your foundations that support open source. Because at the end of the day, open source access isn't just fair, the right thing to do. It's fertile ground for the breakthroughs that'll free us from the oligarchy.
Second, push for interoperability. Don't be satisfied with proprietary walled garden type of ecosystems or wall garden, uh, platforms. Don't lock ideas behind these walled gardens and closed APIs.
Demand open APIs as much as you demand open source. 'cause when systems connect, innovations compound. Third, invest locally and creatively.
Not every startup needs a trillion dollar valuation or even tens of billions of dollars. Some of the most world changing ideas started as side projects, as I said, in garages and dorm rooms and coffee shops, right? Some of them were kind of way out there.
Look at some of the things DARPA has financed over the years. When they originally financed them, they were way, way out. But you know what?
Some of those crazy ideas wind up making new markets and setting new revolutions. Finally, less de shimmy's advice on this one education. The next ai unicorn could come from just a kid in high school, not a VC in Palo Alto.
And let's, let's talk about that. The, this revolution probably won't be in Silicon Valley. 'cause Silicon Valley's already bought and paid for by these eight or nine people.
It's just as likely to happen in Austin or Boulder or Tel Aviv or Bangalore or Raleigh or any town or anything out there who, you know, with the democratization of this, with open source, it could really happen anywhere, guys. Innovation is not a spectator sport. You gotta get involved.
It's a team game. And the more of us that are involved in it, the better the yards are that someone will score and break through the eight or nine stranglehold that we have around us. Now with, with these new technologies, if we treat AI and robotics and quantum like a walled garden, innovation will die.
But if we treat it like an ecosystem of interoperability, it'll thrive. So at the end of the day, we can't count on the government. We can't count on the big eight or nine to be benevolent benefactors here, right?
We need to heal ourselves, not with more hundred billion dollar deals or government programs, but with creativity, with curiosity, with courage. Innovation doesn't wait for permission. It doesn't need a trillion dollar cloud.
It needs room to breathe. It needs room to experiment. And as history and Hollywood remind us whether it's evolution or innovation, life finds a way and so does innovation.
I'm Shimmy. Thanks for tuning in and keep building the future. Says, says AI security in this market.
F five blown away by hackers, SharePoint went nuclear. Rocom has the power of four Ultra Veeam backs up for security. Ai, Shang Shu Make Voodoo video Voo, and we pay the AWS bill in this closer look on the tech field day rundown.
Hello everyone, it's Tom Hollingsworth back once again with the weekly Tech Field Day rundown. It is October 22nd. We are that much closer to Halloween, and I'm very happy to have you all joining me here, along with a new co-host joining me today, Kate Scarce.
Kate, welcome to the Rundown. Hello. And thank you for having me on.
So I, I'm very thrilled to have you here. Uh, you were recently a delegate at Security Field Day. And, uh, look, look, luckily for us, there were a lot of security related stories this week.
I think, uh, you're gonna have a lot to say, aren't you? I, And I'm looking forward to it. I do.
I have so much to say. I absolutely, yes. Awesome.
Well make sure you sit down and enjoy something good for lunch. 'cause it is National Tavern style Pizza Day, probably brought to you by people who make tavern style pizza. Um, but, you know, whatever the case, there's a lot that we're gonna be talking about.
And as I say, tipped a little bit, it is gonna be security focused. So, uh, put on your 10 foil hats and make sure you change your passwords. Folks.
5 jailbreak Benchmark. The first framework to measure how AI systems resists safety bypass attempts. Its new resilience gap metric reveals how much safety performance drops under attack, showing vulnerabilities across major AI models.
0 release. That should be happening sometime next year. Kate, is it invaluable for people to have a benchmark that shows them just how resistant AI models are to attempts to get under the covers and see things and know things they're not supposed to?
I do think it's important, uh, basically tracking how AI safety drops as you know, once it's attacked, how stable, um, or fragile its guardrails are, really are and look at and know how it's supposed to be. Um, you know, I hate the word resilience and we use it a lot. There's a lot of reason I feel like it's like one of these buzzwords that, um, that has come into our vernacular for the last, I don't know, five plus years.
And for me, I like to look at more the word of behavior. Um, and that's where I think that's a buzzword that I think we need to look at, especially when it comes to AI and, and those models. You know, because resilience to me just basically means that, you know, we're able to, to stand up and, and to keep going, but just because we can stand up and keep going, is that really what we need to do?
Is that really resilient? Um, I don't, I don't necessarily think so. I I think we have to look more of adaptive, um, integrity, like systems that just don't survive stress, but they learn from it.
That that's gonna become key, especially as we go into this new AI generation to keep, um, unsafe, uh, choices from being attacked. Um, we go away from resilient. We start to look at predictable, predictable behavior.
And that's what I think becomes these real benchmarks. Um, not how it resists, but how it can revalidate trust through its actions. F five networks has revealed a major breach by a nation state hacking group that gained long term access to its systems, used to build updates for big ip, a product used by most Fortune 500 companies and US government agencies.
The attackers stole source code unpatched vulnerability data and customer configurations, raising risk of supply chain attacks and credential theft. While investigators found no signs of tampered updates, US and UK cybersecurity agencies warned of an imminent threat and ordered organizations to patch systems and follow F five security guidance immediately. Boy, that's a terrible thing that someone managed to hack into F five, which is a company that does a lot of pass through data and was able to get ahold of some code and some unpatched vulnerability code for zero day exploits.
I hope there's no big customer out there that uses a lot of F five products that would be a prime target for a nation state. Boy, I really hope that the United States federal government isn't a big customer of F five. Don't you?
I mean, how, how crazy would that be? Uh, you're not running out to look at the F five customer list, are you? I hope you're not, because you're not gonna like what you find.
This is one of the biggest worries that we have in modern hacking, right? Like we, we know that there are people out there that are doing this for a business, whether they're ransomware, cruises or organized, uh, groups running out of well unfriendly countries. We'll put it that way.
Uh, but this is the next step in that this is nation states that are using this as a form of intelligence gathering. So in the case of whomever did this, they managed to jump in, gain persistence and get customer information big whoop. Uh, they were able to get code, they were able to find out what F five was working on, uh, possibly some unreleased security vulnerabilities, and they're gonna go try to exploit them.
The problem is they're not doing this for notoriety and they're not doing this to get paid. They're doing this to gain a foothold and persistence and hang around. And that is problematic for the kinds of customers that F five works with because as I mentioned, a lot of governments use F five.
Remember when we talked about saw Typhoon last year, and the fact that people were able to gain a foothold in persistence in switches and do things like monitor political candidates phone calls, remember SolarWinds, this has all the fingerprints of the SolarWinds hack because what they did is they were able to get into the supply chain, introduced compromise tooling into the system and gain persistence. I'm not saying that that's exactly what's happening here. I am saying that if you are a customer of F five and you haven't already patched your devices, I would now, and if you have patched your devices, I'd be on the phone with F five asking how they're going to prevent this and what kind of indemnity you have against people being able to get into the system after the fact.
Because this is gonna be one of those things where I bet you we're gonna be seeing fallout from this for months to come, which of course, you know, we're gonna be talking about here on the rundown. Speaking of foreign hackers, uh, they were able to exploit unpatched Microsoft SharePoint vulnerabilities, and they breached the National Nuclear Security Administration, Kansas City National Security Campus. You may recall that if you read Wikipedia as much as I do, because it's a key site for us nuclear weapons components, the attack happened back in July.
It has been attributed to Chinese or possibly Russian actors. It of course, exposed weaknesses in federal cybersecurity and the gap between IT and operational technology protections, no classified data has been confirmed to be stolen. However, experts warn that even minor technical leaks could reveal sensitive details about US weapons manufacturing.
And of course, this highlights the need for much stronger, more unified defenses in the federal government. Kate, do you think that the people who were doing this were looking for something they could leverage? Or do you think they were just looking to see what they could scoop up wherever they could get in With that?
I'm gonna say yes. I, I think actually both. Um, and should we just highlight that?
I think NSA actually just laid off some people nice riff. Um, so let's just combine that with a, a riff and what voila. So what we're seeing here isn't just another exploit of collaboration software.
It is governance failure masquerading as a technical breach when the organization manufactures manufacturing. 80% of non-nuclear parts for our deterrent is accessed through a SharePoint flaw. We're past perimeter failures.
I we're into identity process, trust, value, validation, failures, and oh my goodness, SharePoint, I, you know, as a person who has so much talked about critical infrastructure and IT and OT and, and how we definitely need to, to harden this critical infrastructure, not only with nuclear, but throughout our critical infrastructure, um, systems. This just highlights something that is, is coming. It's, it's here, but it's also coming.
So the attacker didn't blast through any hardened weapons control system. They stepped in through what many considered and what we consider mundane business tools. It this is a wake up call, people defense architects, threat surface, you know, business collaboration.
It just, you know, CA and ICS treated accordingly. I mean, this, this is a serious, serious breach. We keep talking about architecture isn't verified, but by nothing bad hasn't happened yet.
It's verified by how did we behave when bad happened? And for us, you know, for us to still be throwing out, we don't know if it's Chinese, we don't know if it's Russia. You know, at the end of the day, it's, it seems that we don't have a lot of visibility into what happened.
Uh, if the system defaulted to alert, isolate, validate, that's trust architecture. And you know, at this point, you know, we really need to be thinking about how the footprint may still be in the system here. So when we're looking at, um, systems, what happen with Kansas City, the physical consequence might be weeks or months away.
We have no idea of knowing this. Um, but the risk of reconnaissance fingerprinting, future hold points become immediate. You know, to to your question in the beginning here, this slow burn threat model, I mean this, you have asked me before, what keeps me up.
I ot, IIOT, this is what keeps me up because we treat it, we treat OT like it, and I don't know what it's gonna take for us to learn that this is, that this is serious. And I, I, and I, I hope it doesn't get to that point. I hope at one point that we actually say enough is enough.
So we shall see Broadcom unveils Thor Ultra 800, um, gig ethernet Nick built for large AI clusters, emphasizing open standards and high efficiency, fully compliant with ultra ethernet consortium specs. It bos, um, it boosts task performance by up to 15% while using just 50 watts. Thanks to smarter congestion control and selective retransmission with flexible deployment options and strong security Thor ultra positions ethernet as a leading interconnect for hyper hyperscale AI workloads.
Tom, what do we think about this? I'm excited that we finally have an 800 gigabit nick on the market that isn't an Nvidia nick, because one of the things that we've seen is that those Nvidia nicks are effectively running NVLink, which, okay, I get that. Like, that's what I would expect from the, the giant who's building all of this vertically integrated stack.
This is an 800 gigabit ultra ethernet nick from Broadcom, a company that has been introducing 800 gigabit ports on their switches. So now if you wanna run it in flat out mode, go for it. And that's what we're expecting.
Now, as I've said on a number of occasions, remember ultra ethernet is not ethernet. I know it's weird. The ethernet's in the name, it does run over traditional ethernet type signaling.
However, it is not ethernet like the way you know it, you have to plug this nick into a switch that is alteration that capable and it does all this weird stuff. You know, as mentioned in the readin, uh, you know, task performance re optimization and it uses different kinds of congestion notification, um, is really, is more like a fabric, but that's what you want, right? I think the big thing is the fact that they managed to do this in 50 watts of power.
It is' an SFP. Now, don't, don't get me wrong here, this is a nick that has one port on it. It's the fastest port you're gonna need right now because I, I believe 800 gigabit ethernet is, is the, the fastest you can get in a, in a network facing port.
Um, but I mean 50 watts of power for an 800 gigabit port. Like I can remember hearing Andy Bechtel shine talking about how we're probably gonna cap out pretty soon because the amount of heat that's being generated by these things is enormous. By the way, if you wanna see a picture of the card head over to serve the home, because Patrick actually has a picture of the heat sink on this thing, I'm pretty sure that I could mount a laser on it and probably cool that thing off pretty quickly.
Uh, this, this to me is kind of the next step though. We're seeing Broadcom basically aligning against Nvidia saying, you know, we're gonna match you step for step. And remember that the current thinking is that the fastest InfiniBand chips that they're using are gonna match up very closely to where we are, are at with 800 gigabit ethernet because of the signaling and things like that.
But with the way that Nvidia has been using Spectrum X technology and all the things that they've been announcing recently, we know that InfiniBand kind of has a horizon, right? Like we, we know that that's eventually gonna have to go away, and the real development is gonna be happening inside of spectrum X ethernet. So eventually we're gonna have spectrum X versus ultra ethernet.
And that's gonna be a real interesting showdown because on the one side, you've got Nvidia who's really pushing their solution and on the other, but they're partnering with companies like Cisco and Meta and Oracle and, and companies like that. But then on the other side, you have Cisco and Broadcom and other companies who are heavily involved in the ultra ethernet consortium trying to build a standard that not only competes, but can provide similar performance to infinite band. So good times are headed our way.
And if you wanna buy me one of those next test out, please let me know. Um, I I have a wish list. And I, I think though, if you have to ask how much it costs, you are not in the market for it.
725 billion in cash and stock. Uh, they're aiming to combine veeam's data, backup and recovery expertise with security AI's, data security, posture management, and governance tools. The merger will create an integrated platform that unifies data protection, privacy, and AI across multiple multi-cloud and hybrid environments.
Security ai, CEO, rehan, Jile will join Veeam as president of security and AI after the deal closes in Q4 of 2025. Hey, wait, that's this quarter. Veeam says that the acquisition will help customers better secure govern and recover data while enabling transparent AI driven innovation.
Kate, is data security posture management something that Veeam needed to add to their portfolio today? I think so. I think it actually makes sense.
Um, it marks a real shift of moving from just data protection to data trust architecture. Backup alone isn't enough anymore. We need to know what data is, uh, how to govern it, how to recover it in ways that align with both risk and AI driven decision making.
Uh, when VM talks about enabling customers to understand secure recover and roll back data, that's essential for the trust pipeline I've been describing, discover, validate, protect, restore for a, for a long time now, and integrating this into that stack is smart because too many backup systems are still blind. They can restore everything, but not necessarily the right things. Uh, two, trust architecture isn't just this checkbox, it's this lifecycle.
The maturity leap here is end to end from backup media through governance to responsible, a I use, but behavior still matters. Well, this new system, surface risk, um, show lineage, uh, validate integrity during recovery because without that, it's just a bigger stack. What we're seeing is a convergence, governance, backup, and AI readiness coming together.
So yes, it's, I think it's a great idea. And the question every enterprise, um, is the same data stack reacting, architecting for trust before the next breach or AI misuse hits? You know, one of the things that, um, that we always have the problem with being, being data hoarders that we are, we just have this idea of, let's, let's just protect all this data and that's not the best solution.
Um, so I think by being able to see what you're backing up, I I believe that this will absolutely help. 1, voodoo Q2 improves facial expressions, body movement, and see seen consistently while generating content faster and cheaper. Sheng Xhu also released a global API, so businesses can integrate the technology into their workflows.
Wow, if this doesn't resonate, some security concerns, Tom, what do you think? Ah, it won't be a problem, right? I can just upload whatever images I want.
I can make all these really cool videos of fighter planes flying through the sky and, uh, Dan babies dancing with dogs and all kinds of other stuff. And yeah, I'd be a little bit worried if I was Google and open AI right now, because remember when Deep Seek came out and everybody rushed to do it because it was as good as the competition, it was a lot faster. And yeah, privacy concerns, security concerns, we don't care.
It's faster and better and it's not open ai and we're deep seek today. I, I don't, I don't really see it. Now granted, we know that there was a move to, to ban it and other things like that.
I think what we're seeing here is the way that this is going to work for a while, you know, we've seen a lot of reports from Open AI saying that they've poured millions upon millions upon billions of dollars into the research, and they've created SOA and it does all this crazy stuff. And then about a month later, somebody comes along and goes, well, we, we built it too. It's a little bit faster and, and it it does things a little bit better.
Are they building on some of the intellectual property that, that Open AI has put together? No, they probably just opened a asked open AI's chat, GPT, Hey, build me one of these platforms and vibe, code the whole thing, and, and it'll work just fine. This, this is the battle.
Even if sh Shu, uh, gets their app banned from the app store, which I highly, I highly anticipate is going to be a conversation we're gonna have pretty soon. The, the, if you wanna say the damage is done, sounds cliche, but it is. Because what you're basically saying in the Chinese market is, we don't have a need for soa, we don't have a need for Veo, we don't have a need for anything else because we've got our own at home and we're gonna use it and we're gonna encourage you to use it.
And if it gets banned from the app store, so what that means that we'll just have more time to do what we wanna do. Like making sure it can't generate any videos that concern a certain fluffy bear from the a hundred acre woods. That is a banned term in, um, you know, in, in certain countries of the world for various reasons.
But when you think about it like, this is the way that life is going to be for a while, we are going to be generating all of these crazy new functionalities in AI that quite honestly, nobody is asking for. And then about six to eight weeks later, we're going to see the next generation being rapidly developed, because as it turns out, one of the things that AI is really bad at is thinking up interesting new novel ideas. One of the things that AI is really good at is copying interesting novel new ideas quickly so that, that that gap of first mover advantage is gonna be shrinking before you know it.
And I, I think that, you know, the folks over at OpenAI are, are gonna have some soul searching to do, maybe they should ask chat GPT to make them a video about what that looks like, or they can just use sh shoe. It might be cheaper in the long run. Alright, we had a story that we wanted to take a closer look at, and there's no denying who it's gonna be this week, folks.
Uh, if you tried to order your Starbucks yesterday morning, you know what happened? AWS is restoring operations after a massive worldwide outage that disrupted internet access and disrupted major platforms, including Snapchat, Facebook, Fortnite, Delta, Coinbase, a few banks, and possibly the reservation booking system at Costco. Who knew, uh, the issue of course, wait for it.
DNS. Yeah, it was a DNS value that temporarily prevented access to data stored in AWS systems that caused widespread service interruptions and everybody's favorite numerical error message 4 0 4 baby, uh, experts say that the outage, which exposed how heavily global internet infrastructure now depends on AWS, may have cost upwards of hundreds of billions of dollars. Amazon says that it has fully mitigated the issue and it is continuing to investigate the root cause.
Now, I know for a fact that even though they had fully patched the vulnerability and, and, uh, fix the problem as of like 6:00 AM central time, yesterday morning, we were seeing rolling concerns going on all day long. And of course, as soon as it went down, everything that happened that went wrong yesterday was blamed on that just like it was blamed on CrowdStrike or the last time that something happened. So, Kate, I, I kind of wanna dive into this a little bit other than don't put all your stuff in US East one, like how are we going to be able to reduce our reliance on Amazon, because it really does feel like most everything runs on it now.
So could you ask me like a simpler question? I mean, come on, what the heck really? Um, so what I will say though is that I believe that, that we need to go, you know, more to a distributed model.
You know, I, for a long time we're putting all of our eggs in one basket. 0 technology, it really brings in, um, the case for distributed. 0 technology, distributed technology become more important as we become more connected.
And as we see these cloud, you know, these single system failures, we have to, we really have to think about, um, how we, how we we're using an archaic type of, uh, system. 0. Uh, when we look at network and, and, hey, let me just go back to, to Thor.
I mean, I, I, I do think that we're gonna be able to get there to this distributed more distributed technology. Um, instead of putting all of our eggs in one big AWS basket, I, I love your optimism, Kate, and I would totally agree with you, except it's really hard to stand up a cloud computing instance. And did you know that Amazon actually has a service now that will just take care of all that for you?
All you gotta do is just, uh, sign a little more on the bottom line here, and we're only gonna charge you a few pennies per hour and everything will work out just fine. I love the fact that this exposed for a lot of people, the law of unintended consequences. For example, did you know that there was a company that made a, uh, bed that was completely cloud enabled and allowed you to set all kinds of fun positions, you know, like sitting up to read in bed and it would cool itself and all these other things?
Do you know what happened at 6:00 AM on Monday morning when that bed suddenly couldn't contact Amazon? It flew forward and people who were in it were actually getting thrown out of bed because it turns out that's its default behavior. I, it reminds me of a few years ago, you know, one of the last times that AWS had a huge outage, uh, when someone cratered a router in US East one.
Uh, and it went down for a couple of hours. And one of the things that had people very, very annoyed was the fact that at the time Amazon was hosting the steadiest page for US East one on US East one, which meant that when it went out, the lights were stuck on green because nobody could get in to update them. And so everyone's like, well, the, the status page says that it's up.
I don't understand why everything is acting so haywire. There were was there were isolated incidences yesterday of people realizing that while they think that they're not running on a WSA service that they rely on might be, so, like for example, I could post new things on Reddit, but I could not vote the comments or, you know, this thing was working, but this little other fractional piece over here wasn't. And I think that that people need to get more control over their environment that way and, and woe be to the people who said, oh, well the cloud never goes down, so I don't have to worry about that, that stuff.
There are things called availability zones. There are other regions of Amazon that are not based in Northern Virginia, and I think people really have to understand that unless you have a very good understanding of the way that your system is supposed to work, or you are a site reliability engineer, you are effectively doing the same thing that you've always done in the past. You're just doing it in somebody else's data center, right?
Like we talk all the time about Netflix being an example of a very survivable system. No one outage can take them out unless it's the the Tyson Paul fight where they just had too many people trying to watch it all at once. But part of the reason for that is because they were forcing themselves to build a survivable system over the years by purposefully breaking things along the way in small ways to see exactly what happened.
That's why, for example, not all their infrastructure runs in one availability zone. They spread it across the nation, across the world. And that has huge impacts for people all around the world because someone out there is saying, oh, well this will just be so much easier if we migrate to the cloud.
And the other thing that I need to make sure that people understand very, very much, if your name is Microsoft, Oracle, Google, IBM, Alibaba or any other cloud provider, you keep your mouth shut because this could have very easily happened to you and Amazon would be the one laughing all the way to the bank today while everybody moves all of their data off of AWS onto somebody else's cloud. Because you know what? Yeah, I just don't know that how this is, it's the same thing no matter where you're running it.
If you're running everything in one group of, uh, one server cluster and you haven't built it to be resilient, this will happen again because we're sitting there saying this, this is not the first time that this has happened to Amazon. I actually had a mockup of a t-shirt on Cafe Press one time, and it was one of those, those really simple black t-shirts with white writing that says, don't install on us East one like that. I know it's the default.
Amazon, if you're listening, uh, Bezos doesn't pay attention to me anymore. Andy Jassy. Andy, you're a friend of mine and I say friend of mine, meaning I'm assuming that you know that we exist on this podcast.
Do me a favor, create a round robin algorithm that forces people to pick a different region of AWS. It will take about 30 seconds to code 45. If you ask chat Chi pd, divide code it for you no matter what.
This will fix most of your problems. Get people out of Northern Virginia, trust me on this. Alright, enough about that, but not enough about cloud, because guess what?
Cloud Field Day is happening right now. com, you can tune in to see all of the great things that are happening at Cloud Field Day. Alistair Cook braved the seasons he flew out of spring into fall, and he will be joining us at Cloud Field Day.
He's got a great lineup of delegates and a wonderful group of presenters and you're not gonna wanna miss them. com, then come back next week because we move from cloud to ai, AI field. Day seven is going to be happening on October 29th and 30th.
Steven is gonna be dressing up as the scariest thing that you can imagine and AI generated Steven Foskett. I know the horror, but thankfully he's gonna have a lot of delegates there that are going to be able to, um, decode his strange structural syntax and, uh, possibly give him a better writing guide. And we are gonna have a great group of presenters there as well.
Then the next week, which of course will be the first week of November, November 5th and sixth, guess who's back in Silicon Valley? That's right, it's your boy Tom. I'm gonna be out there for Networking Field day.
And we have a wonderful lineup of presenters of people that are building the infrastructure that run AI in the cloud. You know, the plumbers that we always keep forgetting about. com of the presenting companies and of the delegates that are gonna be there.
Stay tuned to that page because we might be adding some stuff very, very soon. Kate, if people wanna check out some of the stuff that you add very soon, where can they go to read some of your writing or see some of your musings? So the CD Foundation, I put out, uh, a couple articles.
Um, so I'm the chair of the C-D-F-C-I-C-D cybersecurity sig. Also, if you look on LinkedIn, uh, you'll see some articles that came out of Security Field Day from since I was out there as well. And so I'll miss you guys this time.
But, uh, definitely look, look on either LinkedIn or uh, the CD Foundation. Awesome. And we want thank each and every one of you for watching the Tech Field Day rundown.
Don't forget we post new episode every Wednesday on YouTube or in your favorite podcast application of choice. If you wanna use Apple Podcasts, that's great. There's a few out there that you can check out as well.
The rundown is also being streamed on Techstrong tv, and if you've got one of those cool set top boxes like an Apple TV or a Roku, make sure you check out the Techstrong TV app there as well. You can also catch myself and many of the other folks here on Other Tech Stronger Future Group, uh, programs such as the New Security Boulevard podcast. Uh, Kate was a guest of ours on the second episode.
You can also see me, uh, somewhat frequently on, uh, you know, other things. So make sure that you tune in there. Uh, we will be back next Wednesday to talk about all the IT news in the week that was, but until then, for myself, Tom Hollingsworth, for Kate Scar, and for everybody else here, ad Tech Fuel Day, and the Futurum Group, we hope that you have a great week.
And remember, don't install things on us East one. Hey, everyone has AI killed the Innovation Star you're watching Textron Game. Hi everyone, happy Friday.
It's Alan Shiel and welcome to another Text on gang. We've got some good stuff to talk about today. Start your weekend off bright and cheery or down and depressed either way, but nevertheless, the weekend's coming.
We got our Great Friday panel that talk about it on, you know, Fridays really are, that's panel of the week usually, and a lot of it is because of, of these folks right here joining us from, it looks like a subway brick rack background probably in New York. Ira Winkler going across the other side of the country, probably up near Seattle. Our good friend Fred Wilmont, and it looks like she's home in Colorado, the one in only Kimberly Bates and of course, high up in, uh, his, his attic in Harrison, New York.
Mike Ard, gang members That People's Republic of New York. So there you go. The People's Republic of New York.
Well, that would be the city. You're kind of, Hey, We were the People's Republic of Boulder a long time ago, So yeah, you were, I remember when I first started coming to Boulder in 2001, it was very much the People's Republic. Um, anyway, yeah, it's, it's Friday, but this big, there's just big things happening in our world beyond the, the election this past week and some of the results there.
Um, Mike, why don't you kick us off here. Well, it seems like the tech leaders are all calling for innovation once again. That happens to spend a lot of money in this time in digital health sector, but you have a opposed suggesting that maybe they should, uh, you know, heal their own issues first before we get too far into other people's problems.
But, um, you know, you wrote this piece, I think you're spot on, but, you know, walk us through it All right, well, you know, and by the way, the piece is up on Techstrong. It, it's called Tech Heal Thyself. And I also am talking, I talked about it on our shim, my shimmy says episode this past Thursday, which by today you'll be able to see on YouTube and, and everywhere else.
It really grew out of a book review on a New York Times article. Uh, the book was written by a former, I, I think it was a Biden administration anti justt person. And I know, you know, they're not in favor these days, but basically he was lamenting, you know, that we need the government to kind of step in here and, and stop this oligarchy of big tech vendors monopolizing ai and, and while we're at it, throw in robotics and quantum and everything else.
And, and the real issue is, is this AI revolution that we're seeing has become such a big boy's game. You know, the bar to entry is measured in the hundreds of billion, billions of dollars, not even the hundreds of millions right? To play in this.
You've got, you know, circular things where, you know, Microsoft gives open ai, a couple of hundred billion open AI buys a couple of hundred billion dollars worth of Azure services. The same thing goes on with Oracle and AWS and Anthropic and Meta and Google, and they're all just kind of passing the salami around here, hide the salami, playing with this money. But if you don't have that kind of dough, if you don't have that kind of gravitas, how do you compete?
How do you play in this market? You know, one of the great things about tech, I said it before, I'll say it again, is that you could get two guys in a garage. They could reinvent an industry or, or launch a new segment of industry and, and make untold richers, whether it was WA and Jobs or Serge Sergey and, and Larry or or whoever, you know, bill Gates and Paul Allen or whoever we've always been, you know, that's been the promise of tech is that the little guy can become the next giant.
Yeah. Alan, I'm gonna disagree with you. If I could go ahead and let me tell you why.
Because what these people are doing is very specific to creating the infrastructure in many ways. It's kind of like saying, oh my God, I was cut out of the telephone system because I can't put together my own internet provi. You know, I can't put together my own lines and cables and everything.
And I think that that's the more critical aspect of this, that what they are doing is enabling other people and smaller people to use, and I hate the term ai, but they're allowing people to use AI related technologies and providing the infrastructure required for people to develop and deploy their own models, not that they are, you know, locking other people out. And I think that's a difference. So Ira, Let's go.
com. It was very similar, right? You had, you had big, you had at t the original at t before it got broken up, right?
Mabell, and, and they broke that up and you had the, the C lab, but you had, it wasn't just a handful of companies that controlled all the fiber, that controlled all the data centers. You had the CEX and the IEX and all of these other carriers, if you remember those words, right? Who could, who could bring connectivity to your office or your house or what have you.
Anybody could open up their own. How many little ISPs did w were were, were started, you know, and some became big, some didn't. How anybody could be a hosting provider and open a data center.
You didn't, it wasn't measured in hundreds of billions of dollars. You didn't have the government with their thumb on the scale owning equity in these companies. So not to get around the government side, but I, I, Alan, I think, and I'm gonna agree a bit with Ira about what he's saying is that this is a level of infrastructure that's being put in place because none of this matters in my view, until it executes on a use case out in the wild.
And then I have the ability as a company, as a user to go look at, you know, let's say there's five LLMs out there, there's usually only, you know, you know, the, the rule of three is usually there's only three big companies that will have that big infrastructure. And um, you know, going back to Jack Welch, if you want 1, 1, 2, or three, I'm ing you. And so where we're now in that is that they're building this and we, we actually need them to be this strong because if we're gonna keep ahead of China, which is a fully government institutionalized LLM sys system, we need the strength of these very large companies to keep on that stay on the edge and that money behind it.
And then all the, so lemme Get this straight Kimberly, you're using a red scare To, to, no, I'm using, no, I'm not using just the red scare. I'm saying that my biggest worry about where we are on the AI bubble is whether or not this is gonna actually, all this investment in these huge LLMs is gonna end up in use cases that we are actually using it. Because until it goes to use cases that infrastructure is of no value.
That's kind of like, you know, what Sun and Cisco did and everything else in 1999 and 2000 where they were just shipping gear constantly, and this is like shipping gear. com, it was the real applications that got out there, there was, there was stability in that intranet and how it was being used. I see that we're in the same place here with the ai.
And so I'm very anxiously looking at the end users to see how are they using this technology? Where is this going? Because that's where the real big value is going to be.
I think there's a couple of the important points there, Kimberly, I like, uh, around the story that, uh, Alan, let's use your analogy. So these big companies are laying the fiber, right? Deep sea fiber across a transcontinental fiber, you know, these types of things.
But until somebody is going to be able to weaponize that, it's akin to the same problem of the last mile bottleneck to get into your ECT conversation, right? And so when we think about what that means, um, the use case that, and Kimberly's talking about here is the last mile bottleneck. Why did we have to figure out how to solve a last mile bottleneck with, you know, plain old telephone, uh, pots lines, right?
Because bandwidth demanded it, because applications that demanded that bandwidth demanded it. And, and in this particular case, and we're building the fiber lines for all of the, the, the telecom model across the, the US and the globe. And these data centers are a part of that, uh, fabric, uh, for the purpose of being exposed in that way.
I think the use case, the last mile bottleneck is absolutely the rationale behind the innovation. And I i it's also cyclical. We've seen this before where, you know, at first we, we thought everything should be centralized and then we thought everything should be decentralized, right?
32 70 terminals and, you know, frame relay circuits and all these things, and then all of a sudden, right, you know, we, we have this very decentralized way of doing things, but it creates a whole set of, of, of issues around how to manage the economy on scale. So we get, you know, monolith, uh, behavior. Again, it's, it's cyclical.
I think we're in that right to frame it up as we're in this process of, uh, you know, aggregation and, and maybe, uh, extraction. But I think the value proposition is what happens as a result of that, which we don't see yet. I have one concern, it comes down to price and to your point, Kimberly, I'll use your cloud example to prove the opposite.
So I have five big providers of LLMs and right now, to be honest, they are subsidizing the cost of ai and they're charging people less than it is for them to actually produce that thing. And eventually they'll run out of VC money and start charging people what it's gonna really cost. I have noticed this interesting trend over the years.
We had three big providers of virtual machines, and you know what, amazingly the cost of virtual machines never changed. No matter how much alleged competition there was, it was always the same. I think the same thing's gonna play out here.
I think a big number of companies are gonna own access to these GPUs and their LLMs and people are gonna be like, Hey, suddenly I'm getting gouged on pricing and I got nowhere else to go unless I go build smaller models and get my own systems and put my own LLMs over there, and then I'm not gonna be hostage to these guys. That's what I think. And I would agree with you, Mike, on that.
I do do that. This is a fair, very fair point, um, in terms of pricing, et cetera. Um, and I also agree with you in the smaller models of seeing these, you know, we have the very large MA models and then we have the unique models that are going to be by each industry.
We haven't gotten quite gotten there yet. I mean, we're starting to see a few of those coming out. And as those do come out, yes, that will drive comp, you know, that will drive innovation that's out there.
I'm sorry. I also think this whole pricing model around tokens is just flat out crazy. A token is an input and an output, and if you're gonna pay for every input and output, you're gonna wind up spending a fortune.
So there's gotta be a better way. But The, so here, there does have to be a better way, Mike, but the problem is when you, when you anoint these companies as too big to fail, and the government, you know, takes off the referee's striped shirt and puts on the team jersey, right? You, you don't, you don't open up to allow a better way to happen, right?
For, for all intents and purposes, what we're building in the US model is a Cadillac, right? It it's a very expensive, very heavy, these big LLMs. It may not be, it may prove may that it may not be the best way to do this, right?
You know, when when the Chinese deep sea thing came out, it's stroke, you know, it struck the year in the hearts of the US AI industry. Like nothing we've seen since Sputnik, you know, had wor abroad up all night. But, but that's healthy.
That's, that's what the healthy market does. People innovate, they come out with new ideas, with better ways. They out innovate, they out nimble, the, the be myths the big guys.
But what I'm saying is this time the big guy's advantage is so ingrained. We're not looking at the government for antitrust. Well, who expects that?
But I am looking for a level playing field. I am looking to give the little guys a shot to out innovate here and come to market. I'm worried that we're not going to, we're not going to allow these people to come to market because the, it's, the decks are so stacked.
They, they've built the barriers so high. So who is, who can assist in, in this? I mean, we're talking about VC investment in, um, some other models, but they are overly tied into the success of these companies.
I mean, if you listen to the guys that are all, you know, sure are they, they are, you know, they, they are tied in those, those companies making it as big as they are. And, and frankly, so is a lot of our investments in the, in, you know, in the mar stock market. No, Let, let, let's, let's face it, the AI economy is responsible yes, for the majority of the GDP growth in the US this year, right?
So, you know, and it's tied into seven companies. It's not, or eight companies. It's not healthy now.
But I'm glad you asked the question, Kimberly. Kimberly, you know, I'll turn you back to Jurassic Park where Jeff Goldblum says, life will find a way. And I firmly believe that innovation will find a way.
It may not come from Silicon Valley. 'cause there, they're too radical to this. It may unfortunately, I'm hoping it doesn't come from Beijing or Bangalore or Moscow or, or, or somewhere like that.
But maybe it comes in Austin or Boulder. Maybe it comes in in Raleigh. Maybe it, it has to come from, but it will come, it's gonna come from, you can't bottle that up, right?
You know, I, I'll give you another analogy. Star Trek world, right? The Warp drive.
I mean, humanity appears to have been in the, in the crapper and some weird dude up in Idaho, Zein Pike. Can I give you, can I give you a world example? It's called the oil industry.
And how many years did they invest in finding ways to make sure that there were no alternative forms of energy invested in? And how many times did they just buy something up and just tuck it away somewhere? And that was the no Another great we that All over again That we, we might be dealing with that all over again.
You're right. Mm-hmm. But life, I I, I am optimistic life will find a way that, you know, innovation will succeed and it'll probably be in somebody's garage somewhere.
And I'm too, because if you look at all the, the different industries, you know, you've been involved with, I've been involved with you, we've seen is is kind of like the, in my world when I was, you know, running in the data storage site, EMC was the big guy and they kept on buying, but they, there was very little innovation coming out of them. They, they bought data domain, they bought Isilon, um, and several others that became huge offerings into the market. Um, and we saw the same with, you know, IBM um, and, and others.
And then we've, we've got companies like Pure Storage that came out of investment and vast data. Both of them are challenging the entire market as we've gone into new application areas. It's literally, it's because of the new applications that have driven that, those innovations and not the old stuff.
So I think that yes, we will see the innovation and I, you know, applaud article Alan that you wrote that was really, really super good. I encourage everybody to go and read it. I put it up in my LinkedIn, so go check it out.
You'll find it there. Are we, are we gonna re are we gonna remake network and are you gonna like, scream out the window? Like I'm not taking it anymore.
How far are we going with this? It wouldn't, wouldn't be the first time I screamed out my window. But anyway, I, you know what, Kimberly, thanks for the plug.
The article is up there. You can watch the Shimmy says, I'll go dig deeper on it on that. But, um, we've got, we've got more to talk about here on the gang.
So let's take a break. We're gonna come back. I think IRA's gonna kick off our next one here.
You're watching Text on Gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're talking now about, well, law and privacy and security and all kinds of fun things, but there's an article up on Security Boulevard by Mark Rash that talks about, well, one of the reasons we don't have privacy regulations maybe is that there isn't enough lawsuits out there because, well, the way we frame these legal standing issues results in people not being able to sue.
But Ira, you're a lot closer to this than I am. What's your take here? And, you know, is this a conspiracy or is this just something we overlook all these years and we need to fix?
So let me be upfront. I've been a, I've been an expert witness on a variety of class action lawsuits, mostly around privacy, fair Credit Reporting Act and things like that. And when you look at these lawsuits, you have class action attorneys essentially crawling outta the sewers and essentially finding cases where they can apply the Fair Credit Reporting Act or another law that, uh, has statutory claim, you know, that has statutory claims.
For example, every violation of the Fair Credit Reporting Act is a mandatory a hundred dollars, a hundred dollars penalty. Now sounds not like much, but if there's a million people that's almost sudden a hundred million dollar lawsuits. And when you are looking at these things, frankly, there are companies that do major wrong, and if they're at fault, they should be held accountable.
However, the current class action framework doesn't necessarily benefit the consumers. At the end of the day. The way it theoretically benefits the consumers in the eyes of these class action attorneys is that they are bringing a lawsuit to hold these people accountable so that they are better in the future.
And they believe that they deserve tens of millions of dollars for their efforts of filing paperwork. And at the same time that people who are actually wronged get nothing. There was actually a class action lawsuit where some attorney sued Google, they got like $10 million in fees while the people who were aggrieved got nothing, literally nothing.
That was the lawsuit because they made the situation better. Now, what these laws, what, from what I read, the, the article was highlighting how very specifically attorneys are out there and they have to actually show people were damaged. In other words, they have to actually show that somebody's information was stolen, which is one thing, but that the information was used or abused, which is another thing because I could download a hundred million records and not be able to go through and process it unless you can prove it was put up on some malicious website or used in some way, shape or form.
In theory, the people, according to the, the court decisions were not harmed in any way. And so that might be true. At the same time, what's really the problem, in my opinion, is how are the penalties being enacted?
Who are the people actually benefiting? Which is a real question we should be asking because at the end of the day, class action attorneys walk away with tens of millions of dollars, and I'm not exaggerating. While the people who are harmed get very little.
For example, you know, when there was a class action against dog food companies where they had killed dogs because of poison dog food, which is rightfully, I own a dog, and boy would I want somebody to pay for that. The people who had their dog die or get harmed, they were given a coupon for free dog food while the attorneys walked away with tens of millions of dollars. And at the same time, was anything changed?
I would argue, no, I don't think whoever the company was, whether it was Purina or whoever, I don't know the first, the, the company, they don't want to kill dogs. It's bad for their image. So did the lawsuit do any good except getting people who had to buy a new dog a a bag of dog food?
No. And this is the environment we're in. And now taking a step back and saying, unless you are actually harmed, you can't be put into a class and the cla people put into a class just inflate the numbers.
It inflates the potential threat. The lawyers hold over the companies, but it's not benefiting the consumer. So while I believe me, I want companies who do wrong and undervalue security to theoretically be punished and held accountable, but the current class action environment is not the way to do it.
Nice. I'll leave it there. Alan, you've been a lawyer in The past and I think what Ira is now campaigning for, I don't know what office exactly, but tort reform, is that what we need here?
Well, yeah, that, that is what he's campaigning for. But you know, in law we, we have this theory of what we call judicial restraint. Judicial economy.
Judges don't like to make decisions unless they have to. Lawyers don't like to write opinions unless they're really getting paid for it. And if you look at Mark R's article that this segment is based on it's typical judicial economy, right?
And warrior restraint. What, what they're fundamentally saying is we don't need to reform, we don't need to reform the, the, the art, the cases or the theoretical cases. I assume he's changed the name to protect the innocent.
Here there is no Elephant Insurance Company. But what he's saying is the court has said there's a difference between could be potentially harmed versus being actually harmed, right? The fact that your social security number might be available on the dark web or your driver's license number, your date of birth, you know, some PII might be available on the dark web is not a nexus to damage.
You haven't actually suffered any damages yet. We have to wait till you can prove that as a result of your PII being on the dark web or, or be used in a nefarious way. You've suffered real damages and until you've suffered real damages, you don't have standing to bring a lawsuit.
So you can't be part of that class action, right? We, you know, in essence, it's gonna kill off the class actions and limited to only people who have actually suffered real harm. So in and of itself, it's almost taught reform, right?
Because it's changing from, hey, my, my PII was stolen, I could be at risk here and therefore I'm suing you. And what Mark says is no, the, the remedy's gonna be, Hey, I'll give you some, some credit monitoring, but until you got real damages, take a walk. You know, a Alan the other thing this talks tells me is like they separate, you know, the article in Mark separates personal information or private information from personal information.
Private information is your hipaa, your personal life about how you and your spouse are talking or something. Um, and from understanding we are responsible individually, we should be responsible for our information. And knowing that once you put the information out there, the probability that on the dark web is really high.
And so therefore it's like, okay, you know, we need to, as individuals be wary about all those kind of phishing, um, things that come across your email. Um, you know, the bizarre stuff that we happen. And so I, I hear, you know, holding the companies accountable, but I also hear that we have to hold ourselves accountable for our own, our private information and be judicious with what we do and how we, how we monitor that, that data.
Just one sec. I, I think it's unreasonable expectations for the burden of proof for managing my information that I have given through consent for the use of a specific company is on me to validate it won't be used against me at some years following. And I'll give an example.
Uh, knowing where I went to high school, knowing where I went to elementary school, I don't care. Public basis, you can go find that information anywhere. Being able to build an umbrella identity off of all of my information that's identifiable information, but personal information, not personal facts, is something that no person can predict the likely outcome of what happens when this happens.
Imagine elderly folks that have, uh, you know, their entire lives tied up in 4 0 1 Ks and IRAs and so on and so forth, an account takeover adjacent to that because their data's been exposed and they don't really use the internet, right? Suddenly puts them in crisis where hundreds of millions of dollars of folks that are over the age of 70 right, are now at risk, and they have the burden of proof required for them to justify whether or not that's causing harm. I think it's incredible to suggest, and I think there has to be accountability, and you don't get to bump that to me just because I should be a, you know, consumer reports, you know, person that understands the likelihood and the possibilities, right?
That's, that, that is, that is a type of, I revocable trust that you put in into a company's hands. You can't possibly sign away. Well, I'm, I actually started out, and I want to be very clear, I a hundred percent agree with Fred because there is a difference in having your information theoretically available to a criminal versus putting it in criminal forums like the dark web.
So for example, if you just say, gee, some criminal had access to, you know, what's a recent one? The Marriott database, some criminal had access to it, and therefore who knows what they could have done? And I'm gonna have like a gazillion class members, so I can charge you a hundred dollars times a gazillion.
That's one thing. However, if that information ended up in the dark web where it's hard to prove that somebody did or didn't, you have to act like they did. And that's where I differ from what they were saying in principle to the specifics.
And again, I agree with the, the line that Fred is drawing. So can we just automate this a little bit and say, okay, I should be able to discover on the dark web when people have been harmed. I should be able to create a law, a website that aggregates all that information.
And then I should be able to invite people that participate in my class action suit because I can prove they've been harmed. And yeah, this is just a business process workflow. I I say no over what period of time and with what magnitude and what adjacency, right?
So Fred Wilmot, right, or my grandfather's name, Francis Wilmot, right? The ability to stack identities together in a way that's meaningful with personal information is a very, very robust way of stealing people's identities. And when that information has been given out, right?
Then you're now subject to, there are no rules that stipulate these artificial identities cause harm to the originating the originating identity. But you can build up credit card profiles, you can buy houses, you can do any number of other things. And there's no way to materially suggest that is directly tied to the consumer who was exploited until somebody comes knocking on the door and saying, oh, well, you know what?
We tracked all this back all the way to you somehow. And it's up to the burden of proof is on the human who stands there, whose identity was exploited they had no idea about, and suddenly they're called to account. So, Fred, I think what you're saying is that you're finding that these companies should be held accountable and having to pay these fees and okay, yes.
The trust sys the how we do tort right now, and the fact that the lawyers skip away with, you know, 90% of the money or whatever it is, and the people that are harmed get very, very little is of no cons, is not of consequence as it is with having the threat of the company being sued, being the consequence, and then buttoning everything down. Exactly. And that's where the bigger value is, is that the companies have that threat.
They know they need to do something differently despite the fact that the only, the only people that are really benefiting from these torts, um, are the, uh, the, the lawyers. Yeah, Kimberly, exactly. The bottom line is you should fear Tron the user, not the class action lawsuit.
And in this particular case, if you're accountable to the user or whomever, right? That's the real, the real impetus. Go ahead, IRA.
Um, no, I was just gonna conclude. I frankly agree. I frankly agree in large extent, and I'm just trying to go ahead and say, look, you have to understand, because a lot of people say there's a class action lawsuit, go get 'em.
Not realizing it's really just a transfer of wealth from the company to a lawyer not getting, you know, retribution or I shouldn't say retribution, but compensation to the aggrieved parties. And that has to change. Like, again, you know, it, it's just like a total 'cause I don't think any attorneys really care at the end of the day.
Let's face it. And here's the, you know, here's the elephants in the elephants room. Fundamentally, this is all covered by insurance.
It's the insurance people who are paying for this. It's not the companies who are paying, they just hire other attorneys to deal with it. The insurance companies bump up the, you know, premiums of everybody and we all end up paying for it.
And people don't realize the ecosystem of what's going on. It's not just The insurance Ira, let me, let me make this real for us. Let me make it real for us.
Recently came across a case all too personally of one of these West Hollywood, California law firms sending out a mimeo, not a mimeograph, a xeroxed copy of a letter stating that, uh, a website has some, uh, data broker service in there. And they, they claim they have a person who came to the website and was therefore harmed by having her information exposed to data brokers. And pursuant to the US wiretapping law in the California Privacy Act, they're gonna start a class action lawsuit.
Unless you pay him $10,000, 10 grand, 10 grand don't sound like a lot of money, but remember, there's a reason why they're sending out Xerox copies of this letter. They're probably sending them out by the dozen lawyers. You hire a lawyer to go look into it.
Absolute nonsense. You, you have your teas and seasons in place. You have your cookie warnings, you have everything you're supposed to have.
We could fight this thing. We gotta make a motion to dismiss $15,000, $15,000 for the motion to dismiss. Now, you're a businessman.
Do you pay the 10 grand to put the troll back in the box or do you go 15 grand on your principles and in, and, and that motion's not guaranteed to win, by the way, right? Because they don't like doing summary judgment. Ju courts don't like granting summary judgment.
If we gotta do discovery, it's 25, 35 grand to just keep playing. That's the problem in the law system here. That's where we need to reform.
That's, and, and, and it is, it's the lawyers, right? There's a reason I stop doing law. I hate these lawyers, these trolls.
They're, they, they are making a bet. And, and I spoke to a lawyer about it. They don't go after large companies who don't mind, who have lawyers on staff, and we'll fight 'em till the cows come home.
They go after small medium companies who in a business decision will pay the 10 grand versus fighting it out for 25 or 50 grand and ultimately winning. That's where the systems broke, and that's what we need to fix. Mm-hmm.
I, I'll step down off my soapbox now. I think we're supposed to say amen and end the session here. We'll end it right here.
You're watching Techstrong again, Discover Techstrong group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back with our last block and we're talking about the acquisition of Stitch by a company called Twilio. And some people are heralding this as an advance in how we're gonna manage identities.
'cause it'll make it easier for developers. And other people are saying, well, it's an episode of Twilio and Extension. Maybe it's just gonna be one more cartoon.
Fred, you looked at all of this stuff. What's your take on what's going on here? And is there, are we gonna see more of this?
Um, I love it. Uh, and also the, the subtle nod to Lila and Stitch, I'll say it outright. Um, remember when you used to have to, uh, pay your HR company for SSO as a special feature?
Remember when people said, oh, you know what? Passwords are terrible, everything should be passwordless. Or, Hey, you know what, I have this amazing SAM token, you can just connect up into your things and life will be good.
Well, it turns out all of those have both a cost and a complexity and, you know, a challenge, they're designed for people, they weren't designed for, for non-human identities. And so what we're seeing here is a movement, right? That's begun to say, Hey, look, standardization is a requirement.
You know, your Jot tokens for your web session have to use an actual standard. You can't poorly implement, you know, HT DP like we have in the past in a way that suggests that often a, a function of that. And that coincides with things like, hmm, proprietary SDKs and, you know, non-standardized delegated authentication mechanisms.
And for the, for the, for the uninitiated, what that means is, uh, I want to connect up with my Google identity to the things that I use. Okay, well, there's a standard utilized there called OIDC that allows you to decide that the same constructs, so the same, you know, scope and the same entitlements are things that I can pass from place to place. It's a unified way of doing this method of authentication and the method of authorization.
So is this revolutionary? You know, I don't, I don't, I don't think it's revolutionary, but I think what's happening here is there's a whole host of new cohorts that are looking at this in an entirely different fashion that are accounting for non-human identities, which demands, uh, without human interaction demand standards in order to operate. So you can imagine that, you know, historically we've had folks like AUT Zero, uh, a staple in the industry, um, not without their own security concerns over the last handful of years from exploitation, but in addition to that, other providers that have, uh, non-traditional methods or historical methods for authentication, uh, one of which at least when, uh, when I was the CSO at JumpCloud, right?
Uh, terrific identity provider, right? Had to support skim, uh, in the implementations of the providers in which that skim was, uh, designed, right? So they'd have to copy the directory from somebody else in this particular case.
And, you know, what we're doing is we're taking the, uh, the insecurities with us as we go based on the implementation of said provider. So identity providers now are starting to move past this construct and suggesting, Hey, look, you know, there's a lot of B2B platforms, a lot of SaaS platforms, a lot of requirements for us to tie into, you know, MCP servers. And so those requirements illustrate why it's more likely to have competitive, you know, APIs and, uh, ways of integrating with, uh, standards, uh, based authentication methods.
And, um, I think it's terrific. Do I, do I think this particular acquisition is, uh, a harbinger of the entirety of change in the industry? No, but it's certainly a big one, right?
And if there was a shot across the bow for an auth zero, I would probably be taking notes today. Alan, what's your take here? We need to just make this easier for developers in the first place, and then we wouldn't have all this crap on the backend that Fred's talking about.
We've tried to make it easier. Like you look at like SendGrid, which is, isn't that part of Twilio too, Fred, right? Didn't they buy SendGrid?
So SE SendGrid was great if you, if you wanted to, to have sort of an email verify verification or something like that kick off, uh, in your, in your app, you could just, you know, you, you put a little srid component in there, and on the backend, SRID took care of all that. And it, you know, it really helped with, with spam filtering and getting blackballed, black boxed and all these things. Um, you know, it's an interesting thing.
Like I, I've always had the opinion of why does someone want to spam mail? Why do, why do we need passwords? Why do we need all of this whole huge infrastructure we've all developed over, whether it's single sign on, federated identity, it's, it all really comes down to identity, doesn't it?
Right? It's identity and access management. And, you know, in the age of cloud, that became the killer app for, for, for a, for cloud security in many ways, right?
I gotta know who you are and where you're allowed to go. We had 8 0 2 1 x when I was doing nac, right? It was a big thing, Fred, if you remember those days, right?
Uh, we've never saw, here we are, it's 2025 going to 2026, we're still talking about the same crap. We're still talking about the same crap. We haven't, we haven't solved it.
So, so Kimberly, your take on this, because I think we've reached a point where maybe the same crap is no longer sustainable. 'cause if I miss my guess, and I think Fred mentioned non-human identities, so now we're gonna have these AI agents and there might be a hundred AI agents for every human by the time we're done. So this current system just isn't gonna be able to cope with that.
Yeah. I, as I'm listening to this, because you guys know this space, I, I know about that much in it, but, um, I think it was, yeah, last December when I was part of the, was at the American Society for ai. We had a debate on, um, whether or not AI was a person or not.
And, and it was a fascinating, I mean, it was, and it was one of those classic debates where you, you had one group that had to get up there and defend it, the other one, you know, to take it down. And, and by the time you're done, you're just like, you, you, you broadened your scope of thinking about how to look at these AI machines, and that when we get into MCP and you get into agents and everything else talking to each other, my, my big thing is like, okay, I got this LLM or this agent over here saying one thing, I got another one over here. You know, what if they evolve and they, they go around the security protection that we have.
I mean, I'm laughing about it, but I'm like going, this is, this is real stuff, you know? And yes, we're starting again because we've just inserted a new person into this world of ours that we haven't had before. And that person is called AI or agents or whatever it is, and it's got a real, I mean, we are handing over the keys to these guys.
Um, these guys, see, I'm actually calling it a person, person name. We're handing it over to this code, uh, and we're giving it names for crying out loud. Um, and you know, when, when you and I interact with chat, GPT, you know, you can't help but getting sucked in to the fact that you're talking to somebody.
Um, so yeah, it's, we have to reinvent because we have all this brand new technology. And I hope that Fred, you and your team, people out there that are developing all this stuff are smart enough to protect us because it's, it could really have, it's a really wild, wild west situation. I think, Uh, it's a super good point.
I, I, I like a couple of things about what you said that really focus on how we need to think about the next set of relationships that we develop, uh, whether we consider, you know, non-human identities, uh, human identities or not. The, the focus here is really when we think about building infrastructure, for example, right? We have a bunch of ENT things and you know, we have a bunch of MCP tool chain and all the things that go with it, right?
When we look at all of those components separate, and aside from anybody communicating with anything that we do outside of our business, or, and I believe a lot of other folks who are in the same boat, we need to make sure that those are authentic and authorized behaviors that happen. And so, you know, there's a couple of, if, if you read this article, right, there's a bunch of different listed, uh, available open source technologies. Well, I don't want to pay somebody else for n number of, of users non-human, uh, identities that I use, uh, either, right?
So, and, and I need to have a source of truth, and I need to have an identity, uh, uh, broker, uh, as well as an access control methodology authorization authentication that supports the standards, because at some time later, I also wanna make sure I can interact with other folks that have, you know, the support of those standards. And so, when we think about it, at least, uh, from a microcosm of a, you know, tiny startup and a, you know, ragtag fugitive fleet of, of folks building stuff like this in this market today, they've gotta start somewhere that does not include these giants, you know, arbiters of, of brokered identity trust, because it costs too much money to do it. So, and the complexity is ri you know, is rigorous.
So when you go tie into, uh, you know, a very large organization that supports only a Microsoft identity or a Google identity or what have you, you probably need to know how to deal with that. And where do you start? You start with the, the tools that make it easiest.
And so some of those may be key cloak or, you know, fusion Auth is great for folks that do, you know, devices, right? If you are interested in managing, you know, a thousand consoles in, in your retail locations, terrific for that. Uh, if you look at D Scope to make all of your automated flows better, there's all kinds of tools that are coming out to help enable that as a developer to supplant the sort of historical, you know, cost model of the ma bell of identity.
You know, somebody tried to make somebody, sorry, somebody tried to make me feel better about this because they told me that the AI agent would inherit my permissions. And I was like, well, given the fact that my permissions are not very well managed, I was even more terrified than I was before. So it was, the report this week was, um, Amazon was yelling at perplexity because Perplexity was placing orders on Amazon.
So there's a battle going on between them. Um, so, and I think about that, okay, so perplexity based upon me getting in there, I haven't used it, but, uh, from what I understand, looking in there, and it can go on and go take my order and go to Amazon, search for the right piece, right thing to buy for me and go buy whatever I'm wanting and ship it to me. That to me, and well, let's go back to our, our, our B block that we talked about is scary, because all of a sudden my data is being passed between these two different companies that are not financial institutions.
Thank you very much. You know, they, they're retail and whatever, but it's, anyway that my brain can go all kinds of places. So I'll let it, I'll shut it down right now.
Lemme just, lemme just, it's not just about your, this isn't just about personal liability or personal harm. This, especially when you talk about machine identities and you know, is, is replacing phishing as a very easy way in to the, to the corporation's infrastructure that then do ransomware or inject malware or what have you. And you know, we live in a world where the machine identities outweigh human identities by an exponential factor, and his problem's not going away.
Unfortunately, we don't have enough time to solve it here today either. So I need, I need to, uh, pull the plug on this one. Kimberly, Fred Ira had to leave early, but we thank him.
And Mike is always you, hope you've enjoyed this. We've got more text on TV as usual following up. But you know what, at the end of the day, have a great weekend, everyone.
We're coming up. Thanksgiving will be here in a few weeks. It's hard for me to wrap my head around that.
But, uh, enjoy your weekend, enjoy your weather, fall weather wherever you are, and we'll be back Monday with more text on gang. Hey everyone, welcome back here to Textron tv. I'm really happy to introduce you to our next guest.
His name is Sasha Jade. Sasha is the CPO Chief Product Officer over at Sideware. And let's welcome him to Tech Drunk tv.
Sasha, great to have you on. Thanks for joining us. Awesome, Alan.
Great to be here. Thank you for having me. My pleasure.
So, Sasha, before we jump into SWE and what we want to talk about today, let's talk a, a little bit, give our listeners a sense of who they're listening to here. I mentioned you're the chief product Officer at swe, but how did you get to this role? Oh, yeah, thank you.
Uh, first of all, again, thanks for having me here. So, always been a, you know, tech guy in one way, shape or form in long, you know, about 15, 18 years ago or so, I started looking at cybersecurity in a different lens, which is in the risk space, which is, you know, enterprises typically used to have, especially the financial services work in a space, you have eight or nine different constituents coming from all the asset all the way to the investors. And in between these eight or nine players, you have so many things going around.
And so your risk exposure just increases significantly. So 2006, 2007, I started building my first firm, which was in the risk in cybersecurity space. And the whole notion of that was this concept called security value at risk, which is, you know, when certain things happen in a security event, what is your value at risk?
It could be because of your brand getting, you know, unfortunately hit your credentials, getting compromised, and that getting hit, uh, you know, you're getting ransomwares and all of those things. So we built the product, uh, big data, the traditional ai, not the gen AI part, et cetera. So we actually built the product.
Uh, I love building, uh, and I also love customers. I just love customers because if I'm building something, I wanna make sure that it's getting used by somebody. If nobody's using it, why am I building it?
So that's how I started building, that's my foray into, you know, just the product side of things. The whole nine yards customers built that firm, exited out of that firm. And then for about a couple years was with a larger enterprise, uh, Deloitte in this case, uh, who were, you know, acquired.
And then, uh, I went to another larger com, uh, corporate and Horizon, uh, who was looking at, you know, different security and network products, so to speak, and saying, you know, what, how do we actually make certain money out of here? And so on. So I joined, I led a portfolio of products in there as well.
And what we built around that was how do we make and reve security into the core of Verizon's backbone itself, as opposed to having network just for the network. Uh, built that portfolio pretty nicely from a p and l standpoint and the products as well. And then, uh, you know, started getting the bug for my, uh, startup again, and, uh, met with the folks at cyber.
And lo and behold, I am the chief product officer here taking that, uh, and all the things that I've learned over the years with customers, cybersecurity, threat management, et cetera, which excite me. And so that's who I am. Fantastic.
It's hard to get that startup thing outta your blood. It totally is. Know, I, I've tried myself.
It, it totally is. And uh, I, I, I love soccer as a player, so I love, and I, so anytime when I'm driving across and I see kids playing, I'm like, let me just go play. It's that same mentality.
You know what? I hear you. So I, I, I satisfied that by coaching.
I coached kids in, in football and basketball for years. And uh, you know, when they got to the point where they were like, bigger than faster than me and, and everything else, I realized I was glad I was coaching. 'cause I couldn't play with those kids anymore.
But I think there's, there's, there's some of that in all of us that, you know, want to go back and do it. So how long have you been with SWE now? So I've been with cyberware for about 14 months now.
Uh, a little over a year, a little over a year. Um, and my charter kind of, uh, is kind of bucketed into three areas, if you will. The first area is strategically thinking about what the product landscape should look like.
What is that six month, eight month, 12 month, 24 month trajectory of the products to look like. Second is how do we build our thought leadership around all the assets that we have in the cybersecurity as well, saying, you know, what, how do we actually help our customers? And the third, but, uh, last but not least is working directly with the customers to see what are their pain points specifically that needs to be addressed so that, you know, unfortunately sometimes the cliche of like, yeah, you know what, everybody in the AI case, everybody wants to do ai.
For me, it's very deliberate in terms of like, okay, that's great. I can build ai, but what use case does it solve for you? Why am I building certain things with AI and not the traditional way because it's going to help you with X, Y, and Z?
So these are the three quote unquote charter areas for me. Excellent. And, uh, Sasha, if you don't mind, there might be people out here who have not heard of sware, or maybe more likely even people who have heard of CY wear that may not be sure exactly what CY wear does or what, you know, it is, but we've heard it.
Let's clear that up. If we can right now, give people a sense maybe of who and what CY wear is and what it's about. Sure.
Uh, in 30 seconds, cyber is about operationalizing threat intelligence. And what that means is when you look at, you know, the history of threat intelligence, one of the core pain points was you would get all the indicators from so many different places, whether it's the external attack surface indicators that might be coming in, whether it's the internal assets that you have, internal data points from your scene, from your logs, from your assets, C MDBs, all of those places, most SOC analysts, CTI teams, et cetera, have a challenge of operationalizing it. And what I mean by that is, what is the signal here?
What is the noise when it comes to red data? Second is what is relevant for me? Yeah, there could be threat vectors, but what is relevant for me, and the last but not the least, is once you've given me the actionable threat and the relevancy, what do I do with it?
Do I block certain things? Do I patch certain things? Do I take certain other elements to it?
So that in a nutshell, that end to end, based on the threat diligence and operationalizing it is who we are. My product portfolio is kind of based on four products. We have the Intell Exchange, which does everything related to intel analysis.
Second is collaboration, which allows you to disseminate all the right information to the right parties in the recipient groups On the other side, underneath the uh, covers, we have what we call the orchestrate platform that allows you to connect to anything and everything with the AI driven playbooks, et cetera. And last but not least, is a threat context driven case management system so that you can connect the entire dots of certain things that might be happening. So that's society, that is, and that's my power portfolio.
That's excellent. A great, great description of, of Cy wear. Um, so, you know, threat intelligence is a bit of a big boys game, right?
You don't see a lot of mom and pop shops kind of subscribing to a threat intel feed or something like that. It's, you know, it's for enterprise, it's for public sector. But here's an interesting thing.
I've been in security myself 25 plus years. When I first saw threat intel kind of explode on the, on the scene, I think we always had threat intelligence. We just didn't call it threat intel.
Maybe it wasn't a, a product line, but we were always, always trying to be wise as to what was happening out there, right? But I think most people thought that an enterprise would, would subscribe to a threat, to a threat intel feed. But I, I think in the real world we're seeing, especially with AI now and, and everything else, companies, large orgs, you know, the more, the merrier almost when it comes to threat intel and sources.
I wonder if that's something Sasha you saw maybe at Verizon or, or now, you know, talking to many customers as part of Cy wear. Is, is thread intel sort of a, a one horse or a one dog kind of house? Or, or do most organizations now kind of have multiple thread intel sources?
Yeah, great. I think depending on the maturity of the organization, you do see a spectrum. You do see larger enterprises that do have multiple threat intel data sources, feeds that they can do certain things with it and so on.
You got the middle, uh, middle tier, mid tier companies, et cetera, that kind of focuses on specifically one or two areas that they might want to see. And then you've got the, you know, the lower end of the enterprise segment that typically just have just one data feed and one, one intel and try to do whatever they can with it. You see that spectrum.
And so from our standpoint, the way we look at it is, if you want to start a CTI quote unquote program, you don't, you do want to use a CMM framework, if you will, because that allows you to put it in action. Uh, you can leverage, you know, products from us to set it up. You get the, you know, cyber intelligence suite, for example, that bundles a lot of those things.
So that your time to value in setting it up becomes very easy, uh, number one and number two. But that allows you to grow as you scale in from a smaller enterprise to a medium to allows enterprise. Got it.
Excellent. Now, of course, that begs the question of, okay, now I got multiple sources, right? And I've got, and in addition to that, I have my own telemetry that I'm gathering, right?
From my, for my own source, my own networks and stuff. You know, how do I wrap my head all around this now? Yeah, we got ai, I'm sure AI is part of the solution.
Perhaps, perhaps maybe it, maybe it adds more to the problem than the solution at first, but hopefully eventually it, it helps. But like everything else we're doing in technology today, AI is having, its, its say in there, its impact in there, right? A lot of times we use the word modernization and it covers up a lot of sins.
But, you know, we are certainly modernizing how we take in multiple data sources like this, validate them, share them across the organization, and, and then translate that to response. Right? And I would gotta imagine that this is a big part of Cy Wear's business today.
Yeah. Uh, one, one of cyber's strength is understanding these multiple different sources that do come in understanding the correlation between it, so the entire whole nine yards of a threat event, data life cycle, which leads to normalization, deduplication, and understanding what is it element to you from a risk scoring standpoint, what is the high priority that you as an analyst should be working with, et cetera. That is a huge strength around it.
And then when you have capabilities from our partners, such as Microsoft, et cetera, where you can now not only leverage our data, but in a bidirectional capacity, leverage certain things that might be happening in their product as well and get it back to us so that our product can take the effective decision around it. Case in point being, let's say there is an alert that happened and it has been shown in the, you know, Microsoft AL system, et cetera. Now that can be now contextualized and correlated leveraging external thread data that our platform might be seeing.
And because of that, we can send an enriched data back to Sentinel for an alert system, et cetera. And when their AI or our AI now enhances it based on the con context that they see as well, now downstream from there, most of the other players can take advantage of that. So now, not only have you leveraged the data that's coming from multiple different sources, but you have enhanced it, enriched it, and allowed the contextualization for somebody else to take a particular decision around it.
I, I kind of put the analogy that I was talking to. And on another part, the Microsoft team, it's that whole team of teams, our process, which is you need to have the data to be shared across, but contextually the decisions that a particular team takes might be very different than the other team, but they need to know the data that everybody else is also aware of. That's how we also operate.
Excellent. Very cool. You know, not quite as big as ai, not anywhere near as big as ai, but a term Sasha that we hear a lot kicked around as observability.
Right. And you know, I almost, I still remember when I first started hearing it, little did I know it was gonna replace like everything I knew about, uh, a, uh, a PM, right? Or I mean so much, you know, all these companies are now observability companies.
Um, do you think Cyberware at some level is an observability company or an observability enabler? Great question. Um, so there are a vantage points and tool lens around it.
Uh, in particular areas we observe what might be happening within the actual asset. And I'll give a use case, for example. Uh, let's say there's a Compromise credential that's been happening, and unfortunately we heard that, you know, earlier this week as well with respect to the number of passwords that got leak and so on.
And when Compromise credentials happen, you not only need to observe, but then you need to enable actioning on that observability. So in this particular case, we kind of do both because we actually take a look at, you know, certain Compromise credentials that might be happening. We actually get the information appropriately around it, and then we enable the identity access management systems to take action against it, which is maybe quarantining the Compromise Credential or changing or resetting the password and so on.
And then the other areas we, what we typically do is we will be enabling the, you know, observability platforms themselves saying, Hey, have you looked gone and looked at, like say for example, you know, Microsoft team systems, or have you gone and looked at the asset database CDBs to see what applications are there that needs to be monitored as well? So we kinda look, uh, you know, we kind of play both roles depending on where the context lies. The essence is still to make sure that the context and the data for the actioning is relevant in the Compromise Credential example, sometimes when you are buying certain things off of Telegram channels and so on, on the Compromise Credentials packet, 60% of them are not even your users.
It's a mechanism for the Telegram folks to make money, uh, the actress to make money off on the Telegram channels, but 60% of them are not even new users. So validating that, making sure that the signal is really crisp for you as an enterprise to actually take action against it is what our sweet spot becomes. So it's the observability and then enabling the action of around it.
I love it. So Sian, uh, swi recently had some news releases, some noteworthy, uh, information. If you wouldn't mind while we got you here, I don't want to turn you into a PR news person, but you know, you gotta do what you gotta do.
Tell, share with us maybe some, some, uh, news coming outta Sware. Sure. Yeah.
Um, we just announced we were part of, uh, the Microsoft in Intelligence Security Association, uh, which is a really good honor for us. But then expanding on that, what the Microsoft team and ours, uh, ourselves as well, what we started kept looking was this need for a bidirectionality in how the threat intelligence is used, evolved, enriched, and then shared. And so, you know, typically Microsoft has this amazing strategy as well, which is, you know, to break down silos, which is very much in line with our thought process, more collaboration, more collective defense.
And our product gets used as a significant component of the automatic collective defense within, uh, you know, federal government as well as ISACs and enterprises. And in that capacity, because that plays a key role in they're seeing the sentiment defender system, et cetera. And our pla our platform now allows the bidirectionality in terms of integration with them.
And so we announced that partnership, which is available as an offering directly from Microsoft as well. Uh, so we are extremely excited. It allows the enterprises to, to make use of their investments that they have done in the Microsoft ecosystem and ours as well, and make that bidirectionality and leverage that for what I was kind of alluding before, which is how do you take those correlations and actions pretty much in real time?
Love it. Where can people get more information on that, Sasha? Yeah, so it is on our website as well.
com/tech alliances slash partnership slash Microsoft, I believe. Uh, but yeah, that's on our, might Be, might be easier to Google. That Might be easier to Google.
It's on the web, it's on our, uh, website as well. And, but yeah, absolutely take a look. We also have a blog published, uh, Microsoft has the appropriate corresponding block published as well.
We are, we're extremely excited on that. Fantastic. Hey, I'm looking at my watch here.
It seems we're kind of just about outta time. I, I appreciate you coming on. I appreciate you giving us the scoop here on the latest with Sideware and talking a little bit with us about threat intel and, you know, in, in, and like everything else through the lens of AI today.
So continued success. Come back and keep us posted. Sideware is an exciting company.
Absolutely. Once again, thank you for having me, and I'm absolutely in the coming back. Thank you.
Sasha Jade, chief Product Officer at Sideware here on Tech Drunk tv. We're gonna take a break and we'll be back in just a moment with more stay tuned. Hey everybody, we're back at Atlassian Europe and we're here with Jamil, who's the head of product for, uh, AI for all things at Atlassian.
And we're gonna have a little chat about, well, where is AI headed? Jamil, welcome to the show. Awesome.
Yeah, thanks for having me here. We seem to have gone from co-pilots to AI agents in a blink of an eye, and now we have all these helpers that are gonna do all kinds of work for us, but where is AI headed from here? How smart can smart get?
Yeah, I, I think that a, a lot of the future now is not gonna be necessarily about, you know, who has the, the best model. That certainly is important piece of the puzzle, uh, but really on how, uh, people are bringing that, uh, capability into their day-to-day work, into their workflows and making it easy to access, easy to make, and, and part of their teams. And that's where we're really focused right now.
Uh, we found that a lot of the you success or failure of our customers and AI doesn't have to do with, oh, is the model doing the right thing? Or does the software exactly the perfect for what that task is, but it's in how effectively it's integrating into their workflows, right? So one of the things about AI is it's probabilistic and so it's giving you, you essentially it's best guess of what you need.
Yeah. Um, we have a lot of processes that are deterministic sometimes where it has to be done the same way every time. And, you know, that stuff's kinda rot, but do we need to be careful about how we're thinking about applying AI based on what the actual mission is?
And we gotta have to back it up from there. I mean, 'cause I think a lot of people don't think about the nature of the workflow all these day years. It's one thing to create an email, it's another thing to process a contract.
Absolutely. I, I think that there are a lot of deterministic processes and there've already, there are already tools out there, uh, like automation platforms and whatnot that are really good at trying to simplify that. But what we find is that, uh, folks who are trying to plug in agents into automation flows, for example, what they are trying to do is actually make that automation more robust, because at some point there is some judgment required, and oftentimes that judgment is, you know, fairly straightforward.
Uh, it's something that requires a bit of context, uh, a bit of understanding of, of, uh, you know, the content, the rules, those sorts of things. And then it can apply some sort of judgment. And we find that in that case, uh, those are like prime examples where an, um, an agent can actually start making a workflow better, uh, that was previously deterministic and only able to handle a certain amount of capability, uh, that I think we'll see a lot more of in the future where those, like, you know, couple of layers of initial judgment that that triage step, for example, will start getting assisted by agents with human review, uh, but will still simplify a lot of the work that has to get done.
Um, if you think about, for example, analyzing a, a Jira backlog, uh, you might have like five or six themes that you thought of, and it's a very simple judgment to say, well, which theme should it go into? But nobody really wants to like go and spend their whole day doing that. But if you have an agent saying, Hey, like that, that is a, a sort of istic problem, but does require a little bit of judgment prime a candidate for something that we would actually accelerate with ai.
Yeah. More. We also use AI agents to kind of review the work of other AI agents at some point.
I mean, we talk about human in the middle, but maybe I don't always wanna do that myself either. So will there not be times when I'll use an AI agent to kinda look at what some other AI agent did and make sure it's not hallucinating and put some guardrails in place? Absolutely.
I, I, I think that, uh, these sorts of systems will become pretty commonplace. Uh, and I, I'm, I'm excited about the innovation that's happening there already. Um, a lot of the initial waves of, uh, review for AI happened as agents were starting to get plugged in to review, uh, labeling, for example, like one system would label, the other system would judge, uh, even in engineering right now, when we evaluate VO Chat, for example, we'll actually go and say, Hey, VO Chat gave this output, let's go and actually have a separate, uh, agent that runs, that helps us grade that output later on so we can evaluate if you think it actually answer the question or not.
Hmm. So when is that line between, I mean, one of the things that's become apparent is rovos everywhere in the portfolio. Yeah.
So what is the line between Robo a product and robo a feature of something else? Yeah, so we've, uh, we've to said that ROBO is part of our platform. Uh, and we've considered that the platform offering of robo to have three core applications, uh, search, chat, and studio.
And we believe that those core applications are gonna be the basis for almost any teamwork in the future, regardless of what discipline you're own, everyone needs to search. Everyone will want to go and actually query their knowledge sources and take actions. Everyone will want to go and build a sub, automate their flows.
Uh, so we believe that's like woven into the platform that's the right thing. And then for every collection that we have, every app that we build, uh, our intention is to build a set of, uh, you know, tailored agents for that particular, uh, collection, uh, as well as specific applications and enhancements that plug into the Bel platform. Uh, and that again, will be like very tailored to the, you know, cases and, and needs of those customers who use those tools.
And where is that line gonna be between the agents that you provide and the ones that I might go build using Studio? What, what are some of the use cases look like? Totally.
Yeah. I think that there, there'll be some agents that we provide that are ultra sophisticated. So for example, we announced Rob Oev, uh, and Robo Dev is a, a code generation agent that is actually able to harness all of the context, uh, of, you know, code and the software building that we have from you, because you trust us with your Bitbucket, with your, uh, JIRA and Confluence.
We can do a really good job with that generating code for you. Uh, and that's a very sophisticated agent. So we'll provide that.
Um, the other agents we provide that are really meant to be examples of starters, right? Uh, like we won't presume to know what the best way is to go and, uh, you know, triage every, uh, or prioritize every bubble list for someone, but we can provide you with a starter, right? And then we wanna encourage customers to go customize that agent for their needs.
And we hope that that leads and inspires folks to go and build even more agents that are tailored to their business processes based on the examples we provide. And then we continue providing these really sophisticated ones that, uh, really require, you know, more than, uh, typical producting. What is the future of the software user experience gonna be like?
'cause historically we've had all these tools and different GUIs, is AI gonna harmonize all of that? And maybe I won't even know when I'm in and out of a given product. Yeah, I I think that we're in the very early like, you know, dos command line era, uh, of how we interact with ai, right?
Uh, and, and that's totally understandable. I I think that, you know, typically people start with these, you know, simplistic chat interfaces. That's a very natural, easy thing to understand.
But as AI is solving more and more problems, uh, and people get also more and more comfortable with a predictive model helping govern their application experience, I think we will be innovating as an industry new, uh, experience paradigms that fit naturally into that. Uh, I think we're still in early days on that, but, uh, I think with what we're doing, for example, with, um, the browser company, uh, and the opportunity, there is a good example of a, a place where we're actually making an experience bet saying, Hey, if we had to go and think about an AI forward way, um, of actually using your, not your SaaS apps every day, what would it look like? Um, that's one example of a bet we're making.
And I think the industry is sort of, you know, push in that direction on there. One of the things you announced at the show was support for the model context protocol. I think it's coming early next year.
Yeah. Um, when, how will these AI agents kind of interoperate with each other? How will we orchestrate them?
How do you see that whole thing evolving? Yeah. So we fundamentally believe in, um, an open platform.
Uh, and that's part of Atlassian's DNA. We think that we work better together with other partners, with third party vendors, uh, and that that's what our customers expect. So, uh, we actually already have our MCP server out there.
People have shared user CP server. And then, uh, we're gonna support MCP servers as part of studio, uh, very soon as part of the studio release. And that's just showing, um, our commitment to that, uh, to that principle.
Uh, I believe that there's no one company ever that will have, um, total understanding of every business process and every need for every company. And that by nature necessitates, um, this, and, and sets the expectation that we provide as an industry open platform so that people, vendors who have that specialization, who have that skill can provide those tools. And that we interoperate together.
We announced also partnership with Google, for example, where we'll work with them on agent to agent. Uh, and that's another example of where we're saying, Hey, we, we will, we know that we're not gonna go and solve every person's problem, but Google will solve some problems. Other vendors will solve some problems, and we'll have to learn how to operate together.
And that's where our mind is at on this firm. Mm-hmm. So in that environment, we may have, let's say I have a couple AI agents, and you have a couple of AI agents.
Will they negotiate with each other? How will that discussion kind of evolve? Yeah, it's, uh, it's a good question.
I think a lot of innovation is still happening on this front. Uh, what I expect will happen is that, you know, every, uh, agent out there will have to have a responsibility that's pretty significant to manage the trust and security, um, of the content that they have responsibility to discovery. Uh, so for example, when somebody, uh, connects to the Roro agent right from another platform, uh, you know, we're governing access to the data on the Atlassian platform that, that, that's being requested.
And it's up up to us to, you know, understand and work with the other vendor to, you know, have the right permission structure in place so that we don't accidentally leak data. That, that the right data goes back and forth and does not break customer trust expectations. That's a very important step that it has to be a part of that, you know, protocol and negotiation, um, that I think is easily underestimated, but very critical.
Uh, I think the other thing that's gonna happen a lot of is this idea of orchestration, right? Who's actually owning this decision of when to actually call out to the other agent? What is the base on which that decision is made?
Uh, that's gonna be a very powerful, um, capability and an important one. We think that we have a, a very good position there because people trust, uh, Atlassian and, uh, put their knowledge of their goals, their projects, their work items, et cetera, all with us. That gives us a lot of context to which to know, uh, how to make that kind of decision, which will, I think, be a, a very important pillar of these protocols in the future.
Is there gonna be some sort of hierarchy of AI agents? 'cause I don't think they're all gonna be created equal. And, you know, might this evolve into something that feels like, you know, upstairs, downstairs there's a head butler and then there's a bunch of agents in the basement doing interesting things that are relevant, but nobody ever sees them.
Yeah, I, I think, um, I, I'm not sure if it'll play out quite that way. I think it's a, it's a bit, it's easy to pontificate. It's very hard to forecast right now.
Um, I think our belief is that, you know, every, um, you know, every major app vendor out there will have a set of agents or a singular agent that, uh, you know, serves the tasks that they have. Well, uh, we certainly, we think we have a lot of things that we can offer with VO and, and unique capabilities that we have, um, as part of the Atlassian platform. Um, but we also fundamentally believe that there'll be other agents we have to work with.
Um, I don't expect that there'll be one agent to rule 'em all. Uh, I don't think that's how it works. Like, you know, we've had even these generation one assistant around for a long time now, whether it's Siri or Alexa or Cortana, like, none of these have become like the single dominating agent, and customers don't seem to watch that.
Mm-hmm. Uh, and I think that's reasonable, right? I, I, I don't think that, uh, you know, people are really comfortable yet with just having one personality that discovers everything.
Am I going to develop a relationship with my AI agents? I mean, or will they just be kinda like, you know, things that pop up every now and again, like, you know, bad example probably, but clippy. But, um, or is it gonna be something that, you know, there's gonna be some entity that I recognize.
Maybe there'll be a few of them, but there'll be something that I will put a name on. Yeah. Yeah.
I think that at, at a minimum, uh, people will expect the agents to understand their personality and their preferences. Uh, one of the things that we announced this week was this idea of personal memory to compliment the organizational memory. And that's because a lot of the things that people expect on other agents are nuance, uh, but but important for them to meet their needs.
So, for example, remembering that I prefer long form content while somebody else prefers bullets and emojis, um, is a personal preference. Uh, the AI has to learn and understand and preserve about you. Uh, and I think the more it's able to pick up and understand those personal preferences and those, uh, those sorts of details, the better it will be at serving you.
Um, that doesn't mean full on personality. I think that, you know, we'll have to see how things evolve and if people prefer that. But that idea of, you know, having this, you know, deeper knowledge of, of you at that level, we'll just make these agents more powerful and rely on the people in, we realize this is something of a more subtle shift, but yeah, when we had co-pilots, people were studying up on prompt engineering.
Yeah. And now you hear the phrase context engineering. So is this whole space gonna evolve and change?
'cause maybe I'm not gonna be the master of prompts as much as I'm gonna be figuring out what context to give the AI agent, but I gotta give that context in the right order. I, I think both will matter its tongue. Uh, and I think what folks have been learning is that, um, a lot of times you can do all the prompt engineering in the world, but if you don't feed the right data, uh, you're not gonna wind up with the output output that you want.
Um, and so I think, uh, I don't think we'll see like one be more important than the other. I think that as people get more and more experienced building these agents and these sort of AI capabilities, there'll be best practices that build up around how to set them up for success. Uh, that involves how to write the right prompts, how to feed the right contacts in.
It also involves things like where to weave it into your workflow. Um, how does it actually interact with the team? Like is it a a distinct identity?
Uh, does it get permissions? Do you have to give it skills? These are all, uh, things that are being lured now in real time and that we're rapidly incorporating into our studio, um, to make sure that customers have the ability to, to dial those things in and, and set their preferences up.
Uh, and then a lot of testability and, and trust also has to have factored in. Like knowing that an agent has a good track record actually is really important. Uh, and I think we'll see more systems like that put into place as well.
Tell people, move these things and start trusting them in day real life. One of the things that I think is not so much a secret out there, but a lot of our processes are, shall we say, not very neat. Yeah.
Will AI and the agents kind of force us to kind of clean that up a little bit because they're gonna be looking for, you know, more structured things and the more structured give it, the more context it has and it becomes a virtuous cycle. But are we gonna have to go revisit a lot of our processes? You know, I think that we will have to revisit processes, um, but I don't think necessarily to make them more structured.
Um, I think that that's where, um, I would expect the agent is meeting you, right? To say, Hey, like, let me go and take this challenge and thing off your plate and run it better for you. Um, but I think people, excuse me, will have to learn about where is the best place, what are the types of best problems in a, to trust an agent with?
Um, that's what I think take a bit of muscle building, uh, and also a bit of work from technical teams as well to sort of figure out how, how good we can make these agents to adapt to different types of scenarios. And then people will learn, I think, hey, like, here are the types of scenarios an agent can learn well, uh, work well. Um, so I think we'll, we'll see a, a lot of like learning from both, you know, the, the workers and the agents on, on that front.
Um, but I expect that the problem people will wanna solve is actually what you mentioned. This is like, Hey, I have like a really challenging process. Can you help me go and, you know, make it run more reliably, more smoothly, take more predictability.
Um, and I think that will actually lead to better, better processes. Will the AI agents also be able to surface the dependencies that exist between processes? 'cause I think we try to keep all this stuff in our head, but um, we sometimes forget that, you know, five projects are dependent upon this other project absolute in on time and that project's late, but nobody knows.
Oh, absolutely. I think that's like one of the best initial use cases of these agents is often, um, you know, you have so many different knowledge sources and pieces of data out there, and it's really helpful when you actually are able to trust an agent or even chat to go and, you know, pull all those different things, you know, suss out the right relevant information, provide the reference links for you so you can follow up. Uh, but, but see where which ones are worth spending your time on.
Um, I think you can do that today and I think that's actually a super value to use disc. You've been at this a while and a lot of other folks are kind of newbies, but yeah. Is there something, you know, now that you kind of wish you knew a couple of years ago?
Oh, wow. Uh, so many things. Uh, I'd say, uh, a couple of the, the things that I'd share with, with listeners, um, I think most important is to start out with actually, uh, something small, right?
Uh, yeah, I think there's a lot of temptation when you like say, oh, I'm making an AI investment. Let's go solve these giant problems and certainly have the ambition. Uh, but we find that the best success stories are often when, uh, folks are able to start off with, um, just one or two pain points, very discrete pain points in their system, in their processes, in their teams, and we're able to go and say, Hey, how do I go and, uh, make that even 10, 20% better?
Uh, and we find that if you're able to go and focus on a, a narrow problem, that's where AI can do the best job, uh, right off the bat. And then you can start expanding from there because you'll learn the AI will learn as well. Your prompts will get better.
You're conscious will it better, um, you'll be able to run more evals. All those things will get better and better. Uh, we actually introduced this ability called of scenarios, and that's sort of in the same thought process as saying, Hey, try one scenario, then you can add second, third, fourth, fifth scenarios.
But we find that teams that go in that that manner, uh, tend to have a lot more success. The only other thing that I'd, I'd share that, that we've learned a lot of is that there's a, you know, a culture shift as well that's important. Uh, and it's both top down and bottoms up.
It's very important for the leaders of every company, uh, to really lean in and say, Hey, I'm gonna go try these things myself. I'm gonna share my successes and my failures with my team, uh, and show that I'm being vulnerable and, and trying these things out that sets the tone for everyone else to, you know, be comfortable. And then from a bottoms up perspective, there's always a few teams that every company that, uh, are ready to take risk, that are, are most risk oriented, want to go and take a chance, take a plunge, have a big problem to go solve, and it's important that they get supported.
Um, and I think it's easy in a big company, um, to have a team that's like, that feel like they just don't have the room to navigate and score. But I think it's important to actually give those teams room because they tend to find those solutions and then set the stage for everyone else to, to fund. So, all right, folks.
You heard to hear even in the age of ai, you still need to learn to walk before you run. Yeah. Hey buddy, thanks for coming by.
Thank you very much for having me, and I enjoy the time here in Barcelona. Thank you. Yeah.
And we will be back in a minute.