AI Agents Under Fire: Cyber Misuse and the Developer Dilemma | TSG Ep. 1031
AI agents are evolving rapidly — and so are the risks surrounding them.
In TSG Ep. 1031, Alan Shimel, Mike Vizard, Chris Blask, Kate Scarcella and Sid Nag revisit OpenClaw and examine what its continued adoption means for security, governance and operational control. As general-purpose AI agents gain traction, questions around sandboxing, browser relay exposure and misuse remain front and center.
The panel then turns to reports of generative AI tools being used to help facilitate a cyberattack against the Mexican government. The incident underscores the growing reality that AI can function as a force multiplier — not only for productivity, but for offensive cyber operations as well.
Finally, the conversation shifts to workforce implications. As AI systems write code, automate routine development tasks and streamline application delivery, what happens to junior engineers who traditionally build skills through hands-on repetition? Are organizations accelerating productivity at the expense of the next generation of developers?
From agent security to AI-enabled cybercrime to the future of application development, this episode explores the expanding impact of artificial intelligence across technology and society.
Transcript
Hey everyone. Welcome here to Tuesday's Text Gang. It's noon on the East Coast.
Anyway, wait, wait, we're on line here. And we got a great gang to talk about, well, the usual mix of AI, security, doom and gloom, and optimism as well. Let me introduce you to our gang members for today.
We're happy to have Mr. Chris Blak, one and only Sid Nag, our own Kate Scarsella, and of course Mike Azar hard. Hello gang.
Welcome. How are you? Happy Tuesday to everyone.
Um, well, Mike, you know, continuing a theme, I guess, Well, we're gonna revisit this open claw thing 'cause it seems like every other day now somebody's reporting some sort of vulnerability involving an AI agent, an open claw, and now there's been reports where I guess somebody over at Meta deleted a bunch of email that they weren't supposed to delete and 'cause of open claw when they turned it loose. And, um, at the same time though, we are seeing alternatives start to show up. There's a thing called Iron Claw that's featured over on, uh, text drawing AI and then also on wire.
And that we think that, you know, Alan has an article pointing this out as well, but ultimately there might be thousands of these variations of general purpose AI agents that get created in time. And so it kind of creates an interesting landscape that we're all looking at. But Chris, as you look at all of this, it feels like maybe we're gonna learn how to use these things in the old fashioned school of hard knocks.
Well, right. You know, it, it, it seems like it might be a good time to own your own data and have it, you know, like just in the green room we're talking about this, you know, the, what I do, what we do these days is grab our data and better in our own vector stores and have it there because it's the, you know, it's, it's the web app plugin days again, but the, now they have SSH keys, right? So what's gonna happen, you know, hold my coffee, you know, we're, we're watching it play out in real time.
But, you know, I, you know, I think you're right though. And this is the iterative theme. You know, what we're going to see is, you know, look at, uh, eras we've been in before.
When has this gone Orion, this sort of direction, you know, what, what was it we were hoping to do? What have we done since? And what's the difference between, right?
We've talked about the data swamp and there's so many layers to this one, right? But we're, you know, I've, I've enjoyed the whole malt book phase, right? Because somewhere out there in the world, if the only, lemme try to put it this way.
If the only thing saving the world from cyber ai, Armageddon is one person in a garage somewhere with, with some free time, then it's going to play out. We're gonna see how that works. But now we're breaking out some of the bounds we thought we, we could contain this stuff with.
It's playing out as it is, and I think it's very instructive about the topology we should be following going forward. Alan, I know that we've been playing with the open claw a little bit internally, and, uh, we kind of like what We're not supposed to tell anyone. It's okay.
We play with everything, right? That's our job. But, um, you know, does any of the security concerns give you pause?
What's the right balance in your mind? We don't mean us thinking security or of course, it, it gives us pause. And of course, you know, when I first suggested it to the producer of our gang show here, Taylor, you know, he turned, he, he, all the blood ran from his face.
You know, I I, I basically had to tell him, don't worry, I'll put it on my machine and run it. You don't have to. And then, you know, he went and did it.
But seriously, when has security ever stopped progress? And what we're talking about, my friends, is progress security will catch up. We're doing the best we can.
We think we have a solid, a solid plan around isolating what it has access to, into what it needs just to what it needs. And then, and even with that, there's, there's, you know, guardrails built around and so forth. Um, we're, you know, we're not a huge enterprise.
And so it's easier for us to kinda limit what, what's going on here. Um, I understand people's trepidations, right? When the internet first came out, everyone was afraid, right?
That we were gonna put everything out there for anyone to access. Um, that being said, count me in as a believer. I think, I think the benefits here are so extraordinary as a business owner, as a CEO that I've told our crew, it's full speed ahead.
Let's, let's go ag agentic it, you know, it's not gonna do everything. And I'm not firing anyone because of what it does, but I think it's gonna help a lot of our folks and a lot of our departments have a lot more bandwidth and get a lot more done with minimal risk. We're not giving it access to what I would call confidential proprietary, you know, PII or anything like that.
Kate, it's an interesting exercise, and I'd love to get your opinion here, but I almost feel like we're learning some of the lessons of security in real time here. And maybe there's a greater appreciation for what's going on. Because when you peel back all the conversations about this, it's like people are talking about, well, we need boundaries between data and, you know, which is roughly the it equivalent of, you know, good fences made for good neighbors.
But isn't that always been at the core of what we've been trying to teach with cybersecurity in the first place? Yeah, you're absolutely right. And it's funny 'cause I think my question to Alan is, you know, when he said, you know, full speed ahead, I was sort of wondering in my head like, okay, do you have a cybersecurity person on your team at all?
Um, I always remember, uh, and I am, I, I'm a big believer as well, no doubt in ai. And I've come around and I thought, you know, about those first days on the internet when we had those, you know, you could put the analog, um, receiver on the BOD device, right? And, and I remem I can tell you, you know, I was a kid, I didn't think about anything other than, wow, this is a lot of fun.
And you know, it's still like that, you know, it's still like, Hey, this is a lot of fun. But of course, with age, you do start to think about, um, we have tried from a cybersecurity perspective to put mitigating controls and, you know, we, it doesn't work. And I will say that it's always funny, what was always been funny to me is as we have tried in organizations to put controls on that, it was always a C level suite that was, you know, bringing in their devices and, you know, right.
It was always this, it Was the doctor at the hospital, right. You know, always They were the worst. And, um, and I guess, you know, hey, I'm hearing you guys are still the worst.
So it's good to know things don't change. Um, but, you know, it's, it we do need to do, we, we know the threats and we understand them. And I wish, you know, I would say some of the first things that I would do, and, and you mentioned about, um, you know, PII and things like this, we don't have to collect so much information.
And maybe that's a place where we start. Maybe we start by trying to only collect what we need and not, I mean, and I'm horrible. You know, I, I, I have like 15,000 pictures and, you know, some are like 5,000 duplicates.
And I'm like, what is wrong with you? You know, maybe we start with collecting less information and it maybe sounds, um, like that's not reasonable, but there's so much information that we have that we don't need. So Are you saying we have a hoarding problem Horribly.
So I'm, and, and I'm, I'm an offender of that. Yes. And I've talked about the data swamp and I wish, you know, um, but that's a place I would start.
Yeah, I think you put your finger right on the problem. And this goes back to how we manage humans. Nevermind AI agents, right?
So employee shows up for work and we give them permissions to access data. And they were like, oh, well, you know what? They might need to access this, that, and the other thing.
And then we're like, well just give 'em access to everything. And then, you know, a couple of months go by and that employee gets promoted and we give them access to other things, but we never take back the things we gave an access to before. And now we're just seeing all this play out with AI agents, which are essentially, you know, an extension of those employees or a brand new type of employee.
And we're gonna do the same thing all over again because we are sloppy when it comes to handing you permission. So, Chris, are we gonna get better? Yeah, we are.
And I like Alan, I like the way you said what you said, like you as a business owner to decide the value, you know, to going down this path is what it is. You know, I even see your shoulders relax, right? You know, and it's reminds me of a talk I've given a number of times over the last couple of weeks, yesterday at the Longings Foundation with an interesting group of folks and talking about protocol development, right?
And take the analogy of how we have developed protocols and standards and, and so forth over the, the first half of developing the internet the last 50 years. And it's been, you know, small groups of people who get together for various reasons. You know, sometimes six or eight, you know, 10, 12, you know, during the cisa SBO era, there was, you know, 150 or so people that would show up once a week, you know, 40 or 50, 60 in the, in the, in the working groups of which, you know, half a dozen or a dozen do most of the talking, right?
And the value of everybody else there is, you know, to be clear about this good because there are eyes on coming from different perspectives in the, in the global interest set. And we publish a, a a a recommendation every, you know, in our, my working group ci, that, that I was co-chairing, we publish, I think three or four documents in three or four years. And that's breakneck pace.
But the way things are working now, those organizations, I believe are gonna start, instead of just bringing together a dozen or so of us watch protocols develop in the wild, see what's actually being developed in real time in the world, what's actually working and bringing them back in, driven by yes, the agent agentic systems that you, Alan, have said that, you know, Textron is gonna be adopted because ju it just works. And that may be a bit esoteric for anybody who hasn't spent their, their career in these working groups and in these standards bodies, but it's just inevitable. We can't move fast enough at that rate.
We're going to get more agent to trust our systems and it will work or it won't. I personally, I think it'll work. And Mike, you know, uh, one of your comments, I think it'll work better.
You know, we've had lived with all these flaws forever. We give employees access and, eh, hope, right? Well, this time we can't just hope.
We got to give them access and define it and write it down and keep receipts. And that can be done. You know, I I I, I think I'm gonna wind up writing an article about our experiences, but let me, let me offer up some advice from the trenches.
First of all, you go into this exercise knowing that there's security issues. So, you know, that's like, Hey, be careful down that street. It's a bad neighborhood and the street lights out, right?
So you're on guard. You're already got your hand over your pocket, over your wallet, which is a bad move. 'cause then they know that's where your wallet is.
But take it from a New Yorker. But anyway, um, and don't look up at how big the buildings are either. That's another AI tell.
But here's what you need to do. You know, this is a potential security risk. So you go about it from the get go with almost like a zero trust type of, of of architecture where nothing is turned on.
And then you turn on things one by one, knowing what I turned on has what accesses right? And, and the fact of the matter is with these agents, they can't hit other things unless you give them access. You give them an API, you give them some sort of access control so you can dial up or dial down what they're doing.
I think the, the fear is, Mike, that you do treat 'em as a person and you don't start from a zero access place. You start from a, you know, everything place and, and then try to trim out what they don't need. No, I think you start from zero and give them just what they need no more.
And, and then you gotta watch that. You gotta watch it. You know, one of the things that Taylor came into my office today and said, you know, not everything we're doing has an API access.
The agent isn't gonna be able to access it. And I said, well, they might be MCP servers, but ultimately, maybe a good rule of thumb is if there's no API access or other way of accessing it, maybe God intended it that way. Yeah, I don't, I don't use it.
I think, uh, I think, uh, you know, I like to view this as you wanted agents. You got agents, right? And life's only gonna be better with agent.
That's a fact. Uh, so the question is how, what's the gap between AI capability, AI agent capability, and AI agent control, right? Yeah.
You don't wanna, you don't wanna discount the whole capability because something went all right, right? So it's important to build the guardrails. It's important to build the governance structures.
It's important to build observability. I keep going back to this team from the last two, uh, sessions, because unless you know what's going on, you can't fix it. Right?
So the whole idea of confirm before acting, so don't go let agents run amuck, uh, you know, maybe have an agent registry to figure out, Hey, who are these rogue agents? Or they were even authorized to operate. Well, they the environment, right?
Yep. And so, my take on this is exactly what you said, Alan, full speed forward, but full speed forward where everybody stays in their lanes, not kind of drive all over the highway, right? That's Not gonna work.
And eyes wide open. Yeah, eyes wide open. Why would argue the las the Las Vegas rules apply, right?
Las Vegas rules are, you know, bring money to Las Vegas. You're not willing to lose open claw Variation of that is don't bring data to open claw that you're not willing to lose. I, I, that's another way of looking at it.
Well, let me say one other thing and we'll close this segment up 'cause we're almost outta time. I wrote an article, uh, I think it was last week. The world will create the next Better Open Chlor a thousand Times Mi Mitch Aston said this to me when him and I were talking about this last week.
I think it's important to remember this too. We're so early in this agent stuff, and open Chlor is cool as it is, and is intoxicating as it can be. It will get better.
The next iterations will get better. The next open core or whatever we call it, will be better. We will start building maybe more security in, or make it easier to secure.
You won't have to home brew it as much as you are now. We're gonna do this a thousand times over the next year, probably. And, and, and, and in each iteration it'll be better and better and better because that's what we do in tech.
That's what we do. Right? And that's, and, and that, you know, that's still the optimist in me.
I, I wrote another article I, I spoke about yesterday about, you know, being in the tech world and what it means to be in the tech industry. I think you gotta be somewhat of an optimist. You're always thinking the world is gonna be better because of this.
Te somehow the technology's gonna make the world better, right? We're making the world a better place. And I, I think that's gonna be true here.
I just wonder, like with Mike, you know, he brought up the example about Vegas. Maybe if we had the idea, um, of what stays in Vegas, like if we sort of had this, you know, parameters around that type of, you know, what's done in Vegas stays in Vegas, or, you know, even with ai, you know, if we had a, a more, uh, you know, view of that, we could contain it better, you know, sort of like, anyway, go get outta here. All right, let's move on to our next segment on that.
We are going to, well, talking about AI and security. Looks like we had a little situation down in Mexico. Yeah.
Sounds like a James Taylor song or something. But I Guess, but we keep talking about, well, we need guardrails. Well, that's great, but turns out the guardrails are, they can get around them.
Apparently. There's a report out says a hacker used AI tools from philanthropic and open ai. I guess he needed 'em both to, uh, convince the Mexican system that it was trying to access, that it was conducting a penetration test.
And of course, the system initially said, no, we, no, you can't access that. But then they kept asking, and eventually the system turned around and said, well, oh, well, in that case, absolutely. And gave them access.
And then, you know, before you know it, 150 gigabytes of data goes missing. Hey, I mean, is guardrails kind of like a platitude now? Because it doesn't seem like these guardrails actually work.
So what the heck is a guardrail and, you know, what are we, what are we telling each other here? Is it just kind like, you know, a placebo or is it a thing? Yeah, great question.
I mean, first, you know, guardrails are not the, um, the magic bullet. Mm-hmm. And we're seeing that this connects to something much bigger than we expected.
Um, we're seeing a lot of pressure on top. So there's a lot of, um, dual things happening, meaning that we even have pressure to drop guardrails. And, and I don't think that that's the key, just because the guardrails, you know, didn't work.
So, you know, there're separate categories happening here, so guardrails are still necessary. Um, and we just need to look at how, um, how what AI became operational. And that's the truth.
And we've already seen it become operational at scale. It doesn't mean at the same time that we should drop the guardrails. 'cause guardrails are still necessary.
We just need to, um, I think apply them at better at the end of the day. So, Chris, how about you? I mean, I know that, you know, you have to deal with this on an everyday basis.
And, and so, you know, what does guardrails look like for you? And Well, you know, in my, uh, list of the topics today, we had Iron Curtain before this. I don't know if that was the last block, but this, you, you, you, you know, on, on this show every week for just about a year now.
And it, everywhere else I go, I've been seeing the same thing. Right? You know, this AI shortens the window to attack, right?
It's not new attacks necessarily, but you know, you can, if you saw you had six months, you have six minutes, right? And that's the world we're, we're in right now. And everybody's trying to adjust to that.
But the, the, the policy as code, you know, what, what a guardrails look like. You know, I like the iron curtain thing. When I, when I saw about that, you know, so this is what we do all the time.
Like this was the whole DO thing from 2019, you know, the stake policies, the actual policies we have, and run our code in that context, literally, right? And we embed the policy documents, make the AI follow that and make them good policies, right? You know, have the, we talked a lot about this in the last, uh, segment, but it's, again, these are not human beings, but we are specifically intentionally trying to make them act and behave like human beings and the system.
So we should look more, I think, at the systems we use to keep us human beings, you know, behaving nominally most of the time and mitigate the effects, right? The actual ban, the use of isn't gonna work. So what comes next, right?
You know, have the agents out there running in environments where you can see what they're doing. They're, you know, they've been informed. They'll, I'll tell you, last, uh, June, LA May and June, my man June, you know, I sat down to see if it was possible to make a ethical infrastructure where humans, Andis could co-author everything code and, and whatnot.
And the, the it, going through that with an AI and trying to explain what is ethical, turns out humans haven't written a lot of it down. Right? We hope we hire people, we hope they kind of know and they understand, but then we take into, uh, structures that behave like human beings and say, Hey, be ethical.
They don't know what that means, right? There is no, you know, they, they don't actually have that built into their heads. They don't have, and we have to tell them.
And if, if they, you know, they will follow the instructions and, and anyways, ethical, ethical behaviors, code and ethical behavior. Foris, you know, arguably for humans sometimes is leave receipts, leave attestations, agree with what you agreed with, leave markers along, along the road at every step of whether or not you have followed up on that. And again, these just do that all day long.
Yeah. I think guardrails are no doubt important, but I, I'm thinking, you know, whether the current di safety guardrails are sufficient, of course, we ought to talk about that. And also, I think there has to be some level of checking that's the right word, what a prompt is issued, right?
We don't have any mechanism to check the threat of a prompt before it's processed by an AI engine, right? So that's the second aspect of this conversation. And third is, you know, the, the model builders have to harden the models, right?
So you can talk about the overlay kind of capability, be guardrails or orchestration or management, whatever you wanna call it. But the core technology is not hardened. Then you're gonna see more and more of this, in my opinion.
Right? So, yeah. Yeah, go ahead.
And, And it did have anything really to do with guardrails. Um, Mike, at the end of the day, at the end of the day, it was about the acceleration, the speed where guardrails, where we saw guardrails this weekend sort of collide with this story was of course, about around the Pentagon and philanthropic and, and wanting to like not have guardrails up. So guardrails work, and they're, but they're not the magic bullet.
And I think that at the end of the day, it just makes me think of, um, because I was having an interesting discussion, um, around this same issue, and it just so much reminded me of the Matthew Broderick movie, what was it in the eighties? Um, do you, uh, war, war games. Yeah.
War games. And it just, you know, this whole mad fallacy and, you know, we have to be, um, I think what Alan said in the beginning, I mean, yes, is it full speed ahead? Yes.
Is it exciting? Yes. But we need to be better engaged with what we are putting forward and making sure that, that we're not just letting this go.
You know, it's sort of like having a dog, walking your dog on a leash type of idea. You know? Um, sometimes the dog, if you don't have the dog on a leash and it sees a squirrel, by golly, you know, good luck, um, and good luck to the squirrel.
So we do need to have this leash. And that's where the guardrails are very, very important. Um, we have to be s this is a great time to be alive.
And it's so interesting, all the things that are happening, and those of us who have been in the industry for a long time, we know better and we understand the threats. It's just what the threats have been amplified. And that's where we need to, I hate to say get ahead, because I don't know if we can actually get ahead of it.
We just need to Go ahead, Chris. I know you're, yeah. Yeah.
I, but I think we can, right? You know, as you said, we know how to, how to build better. We know how to build resilience systems and, and sit to your comment about models, right?
You know, but it's all the same in, in, in, in resilience systems, whether you're setting up an AI agent or a DMZ server or a big, you know, power transformer at a substation. It's all about blast radius. Not if, but when, you know, the best laid plans of mice and men, you know, often run afoul, you know, it goes, boom.
What, then what happens then, you know? So, you know, I care a lot, you know, don't get me wrong. I care a lot about all these things, and it is, you know, definitely scaffolding.
There's two by fours and, and things everywhere. Yeah. But the models themselves, I don't count on the models being right or safe.
Right? And instead, you, you know, we don't have a mechanism between the problem we do, not necessarily off the shelf, but, you know, then, then there's people like us building this up all the time. You know, when a human says something to the model, there's a lot of steps along the way.
And when the model responds, there's a lot of steps before it takes an action. And there are the mechanisms there. If we are willing to think, you know, how do we deal with this, even when it, you know, it goes critical.
And then how we li how then how do we limit that? Yeah. I think, I think there's a sort of paradigm shift that we need to think about, right?
The irony is that AI itself can be used to generate novel attacks. So it's, it becomes your own enemy in the sort of environment, right? So how do you protect yourself against that?
So traditional defensive tools, like, you know, whether signature based detection or sort of, you know, static rules may not work, right? We, we gotta think about shifting a mindset to thinking about behavioral analysis, right? Ly detection, you know, proactive threat hunting that is auto-generated by AI engines that are attacking AI models, right?
In themselves. So it's kind of self-fulfilling prophecy in many ways. Uh, and I don't think we've paid attention to that aspect well enough.
Uh, I don't know how you, how you feel about that, Kate being sort of the security expert here. So that's sort of thing that I'm observing from the outside looking in, right? So, Yeah, and, and I, I agree.
And you know, I think it just takes us back to even what we were saying in the first block about how much, um, you know, data, and I wonder if we control the data, and it only had certain, if AI agents then only had a certain amount that it could act on, right? Because it acts on information that it's given. So I wonder if we could restrict the data in some fashion, if we could be able to control AI agents better.
I, I don't know. But we do have to, you know, as we've talked about on previous shows, um, really reimagine the way things are done with the building blocks that we already have and understand with cybersecurity, because there isn't anything new. It's just the speed and, you know, and how much access it has.
And I mean, there's some common sense things that we have to really think about this. I, I love it from a cybersecurity point of view. I mean, this is a, this is, this is really, really interesting.
I mean, it's sort of like a puzzle. And, uh, and I think many of us, as you know, Chris even mentioned, I mean, with humans being involved, Sid, right? I mean, we know this stuff and, and we at the end of the day are, are are, you know, uh, steering this, and we just, we have to do it better, you know?
Well, you know, traffic accidents are really interesting too, but I wish they didn't happen. Are you saying that, that hope is like, I'm not saying not, I'm not hope is not my plan. It's, it's actual, uh, you know, I look Alan, don't blame the, don't blame the player.
Blame the game, right? Don't blame the AI here, guys. You got systems that are easily penetrable you and you blaming me for using a tool.
Don't blame the tool. Blame, blame the system that allowed that tool to be successful. Those Mexican government systems were not secured enough, right?
If I didn't do it with AI today, I, maybe I do it with something else tomorrow, or I did it yesterday, but the, the system, you know, and, and this is the state of the world, right? It's one of the things when we spoke yesterday about what we can expect, you know, is Iran gonna play one of its only cards that it has still, which is the cyber card. Don't blame them for do it.
They're going to do it. They don't have a choice. I think also getting too caught up in getting technology out in a very rapid manner without putting all the necessary checks and balances that are fundamentally built within the substrate of the technology, right?
Yeah. But, but that's not new. That's not new.
But in the world of ai, it can have devastating, you know, impact. Yeah. And it may, That's new.
That Part of new Yeah, no, and it may, we may see some really, some bad things happen. I think the, the speed at which those bad things is happening is what's giving everybody pots. Well, Mike, you, you, you bring up car crashes, right?
And that's a perfect analogy for this. Yo anybody, you know, who, who's looked at risk and consequences, you know, has looked at automobiles and, and yeah, they were, they were death traps. You know, there there's been, it's, it's a little bit frustrating that we've, we have a, a level of acceptance in the US and worldwide on, on the amount of damage they cause, right?
They could have been a little safer, I would say 10. You know, you could say take 10,000 American lives lost every year if we'd done a little bit more with car safety in the past, and we haven't. So we've accepted that amount of carnage, and this is no different, right?
You know? Yep. Yeah.
You, you know, these systems, Kate, you said it, right? Yeah. You could have hacked these systems already and Alan, right?
You know, maybe you did it yesterday, maybe you did it last week. You did it today with ai, you know, there's a whole lot of toll. So laying around in the cybersecurity space, because there's, you know, the vulnerabilities aren't new, you know, they just haven't been that date.
We gotta decide how much carnage we're willing to, to take. I hope it'd be close to zero, but that we never get there with anything else. So why will we get there with this?
And, and I don't think we're blaming the tool, Alan. I, I don't, I think, I think all of us here, I, I think we, we have a gen genuine love for AI and the possibilities of it. I just think that as, um, humans who are putting into the ai, we have to do a better job at, you know, it's, it's like having a dog, you know?
I, it's, you know, having it on a leash. I mean, this is our choice, right? Put the leash on the stupid dog when you're putting it outside, you know?
And you know what, as the president of the HOA in my development, it's a fight. We constantly fight. People don't wanna put their dogs on leashes.
Well, dogs, dogs should not be taken out on the street until, unless they've gone through obedience training, right? So you wanna, yeah. You don't wanna make the life of your neighbor hellish because you want to take your dog out too early.
Even the, I don't disagree with you, my dog's always on a leash. 'cause I'm afraid she'll get hit by a car or something. But there are plenty of people who at night will take their dog off the leash and let 'em run.
So, so we need signs that say, pick up after your AI agents where we go with this. Yeah. May, maybe that's what we need to do.
Or maybe we need to have, you know, uh, AI licenses to u to, to, you know, that I, I know how to use AI safely. But look, these are all growing paints. That too shall pass.
Let's move on to our next third, third set here, which is, uh, it's kind of a birds in the bees question for me. Well, Mike, where did junior developers come from? Yeah, well this is true.
Well, it's also interesting as to who's asking the questions. So a bunch of engineers, senior folks from Microsoft, or put together an article, um, I think it was the, uh, a CM journal or something. ai.
com, it asked the question, um, you know, where will junior developers come from? If we use AI agents for everything and senior developers don't need any junior developers, and eventually the senior developers will wanna go home and maybe go on vacation, or who knows, retire. But then where will we get another senior developer from?
Because well, all the junior developers don't know anything and they just don't exist. Now, that said, the article's a little self-serving, 'cause everybody who wrote it is from Microsoft, and Microsoft is the house that developers built. So I think they woke up one morning and said, Hey, if we don't have many developers out there, we're not gonna be able to maybe sell as many licenses.
So Sid, you know, what's your take on what's going on here? Yeah. This is a, this is an interesting discussion.
It's more about sort of culture and the role of the developer and the changing workforce, right? In many ways, uh, you know, AI coding assistance, uh, I think the thinking here is that our AI coding assistance is gonna dumb down the developers where they won't learn basic software development skills. Like, you know, debugging, design, trade-offs, real problem solving, because they're gonna use these coding assistant, they're gonna do, the assistants are gonna do all the work.
So the junior developers won't learn the things that we learned when we started to write code, right? So I think there's a fear about that. So short-term productivity versus sort of long-term skill development, right?
The second piece is what you talked about, uh, Mike briefly, which is the role of the mentor, right? What should the mentors do in this construct? And should the formalized mentorship example, maybe senior engineers serve as sort of preceptors and adapt AI tools to support learning rather than just throughput.
Because we get so caught up in churning out code today. And the word, it goes back to the discussion we just had about getting product out as soon as through the door. So, you know, I think that pressure is causing some of these behavioral changes.
And we are, we are thinking that as, as a, as an industry that, hey, you know, these coding assistant are going to speed up everything. But in the process, we are creating a dumb software development workforce that may not learn the traditional constructs of software design, software debugging, and things of that nature. And I think the third thing is redefining the role of developers in the world of gen ai, right?
So, are we going to, if we agree that coding systems are here to stay, so then where does the coding community shift their focus on this new world of AI coding systems with things like maybe steering, evaluating, so doing more sort of integrating AI throughputs with the, with the models, the tools, uh, you know, the should the paradigm shift between training, inferencing, fine tuning, all of that. So the role of the developer is gonna change. That's a given.
The question is how do we, how do we sort of con, if I use, may use the word control, that, that mechanism of the process so that we don't create a software workforce that is completely reliant on this coding assistant. Their thinking is not no longer structured. And, and, and the traditional critical thinking that is required that software developers should be focused on.
So that's sort of where I see the problem. Yeah, I think this is like everything else, right? If we look at how we've been doing education and training and so forth to date, we might find that it's not really perfect.
How are we, we bringing people up? And it's cliche to say, but so I'll say it, right? You know, interns, you know, are really, really cheap labor, labor that executives can get rich off and, and, and, you know, and education gets homogenized.
And maybe we could do better than that. I mean, Mike, to the original question, no, we can't get rid of junior programmers. 'cause then we'll never, you know, it's a, it's a self answering question.
But how do you get there? And I'll, I'm going to bring Jackson into this when I was 18 and learning how to do anything, you know, in training example, I got a pit bull puppy shortly before I came, a high school dropout. And, uh, as he wanted him to be well-trained, right?
And I didn't know anything. I didn't train myself along the way. And, you know, to, to what we're talking about in the last segment, you know, I wanted to have freedom be off the lease.
Therefore, Citi had to have, you know, good protocols and be controllable, right? And it worked. We had a wonderful life together.
And I don't think, you know, we, we have that depth of not the interns, not not junior people, but apprentices, right? How do we bring young folks along to learn how to do things and not just take a, you know, post World War II industrialized education approach to it, you know, that has been, you know, corporatized and efficient ized down to the, the shareholder value level, which isn't necessarily the, the, the value of the, the young person being trained or the role being served, right? So I think we have, you have A new world order.
I mean, I think I'm on an old world order, a honest to God apprenticeship. Like we all know, we, everybody on this screen is old enough to have this conversation. Like there used to be apprentices, you know, in the trades, we think of it that way.
I think there should be apprentice mentor sorts of relationships instead of you fire them early. I'm gonna go in a different direction, Chris. The concept of a software developer is quaint.
It got quaint real quick. We're all developers. You know what I hear from my friends these days?
I could build anything. And I'm telling you, each one of you out there, you virtually could build anything with what the tools you now have with this ai. And, and, and now it's getting better.
We're going from a world of 40 million, so-called coders, developers, to a world of 500 million maybe developers or more developers don't just live in the IT world, in the IT department. Everybody's gonna be developing apps, you know, and the, and these apps run on code. So I think we have recalibrate our, our definition and our vision of what it means to be a developer.
What does it mean to be a coder? And that's the kind of thing that our, our educate, again, you look how we're training young folks now, it is relatively static. You know, he, you will be a coder.
You will be a developer. You know, that's not Yeah, I, I, I think, yeah, everybody can develop apps. That doesn't mean that nobody will be working in the computer industry, you know, and if we, you know, this is a broader topic that maybe we can cover it a minute or two, but we all know, it's like how we have been in onboarding young folks into industry and in not just our, our industry writ large has gaps.
You know, there should, this is an example of those gaps showing at the structural scale. So I think Sid brought up something where a lot of professional developers will bang the differ with what Alan said. And of course, what the definition of professional is, is, is in the eye of the beholder, but it's the critical thinking that went into the construction of the software that made it maintainable and extensible and scalable.
And most of the world doesn't have those critical thinking skills. So we could be just on the bridge of building a really massive amount of bad software. Okay?
Yeah. So I, I agree. First of all with what you're saying, I, with actually, uh, I'm gonna take the, the, the view from all of you first, critical thinking skills, extremely important.
That's the differentiator, right? Between us and agents and should be, um, to Alan's point, uh, you know, it makes me think of way, way back in history where people could not read, not everybody could read, and not everybody could write. Now just because we can all read and write, there's more of us, and that's a good thing.
And then it goes on to Sue's point about critical thinking, right? Um, you know, it just makes me think of when, um, Watson for, um, for QRadar came out and it was supposed to, well do a lot of different things, but the whole idea was you take this junior level analyst that was receiving a lot of false positives, and then they would chase down the false positive and it would be nothing. And we were burning out on, on junior analysts, security analysts, and you know, the idea that, that we have AI to be able to look through thousands and thousands and thousands of network logs.
It was a good thing, you know, what we were calling ai, you know, at the time. And that's what I see this is, it's the same type of idea of having, um, so much to, to, to be able to consume that we can have AI take a look at this and we take the critical thinking skills that we actually have and just learn as Alan says, sort of, you know, re rethink about how to do this, right? I think that's where we're going.
At the end of the day. I think it's important. I think our critical skills become the most important thing.
And, um, yeah. Yeah, I mean, I think also There's Also a disconnect I think between industry, which I think we covered a lot about today on this, on this block and academia, right? What are the, what are the computer science schools teaching in the curriculum, you know, today to prepare the new workforce that is gonna be using AI tools, right?
So do we still need courses and data structures, operating systems, computer architecture, you know, all of that, right? Algorithms, right? These are the things I learned when I went to computer science school, right?
Do we need those courses or in the way they're taught today? Or do we need those courses recalibrated to account for AI coding assistance, right? I'm not saying I think we need those courses because those are the fundamentals, computer science, right?
But we need to recalibrate those courses in keeping in mind the AI assistance, the coding agents that these, uh, guys and gals when they graduate, are gonna be using in the real world. So they're prepared to do that, right? I think that's the chasm we are to talk about or think about, right?
I think, I think one last thing to think about there though, and I'll go back to the car metaphor that Chris was bringing up. So nine outta 10 people are driving down the road in some sort of vehicle that they really don't understand how it works and how it really operates. And, but that's built into the engineering of the vehicle to, so that mere mortals can drive those things without necessarily knowing how everything works.
And maybe that's where we gotta get to in the age of ai. Let me, let me, let me tie the bow and end the show this way. You know, when we were playing with this agent stuff here at this at, uh, tech Strong, we, we have it doing some video editing.
And one of our video editors got very defensive. He said, it'll never, it'll never edit as good as I can. I could do it better faster.
Yeah. It don't take days off, it doesn't go see your son graduate school and, and you know, it works 24 7 and it works cheaper than you. I was reminded when I was still secure company, Mitch Ashley and my friend Raj Bava co-founded along with me.
I remember being in an executive meeting one day and the VP of engineering was saying something and he said something to the effect of, well, you know, you know, the coding that we do is the most important thing in this business. 'cause after all, we are the smartest people here. And I looked at him really straight in the face.
I said, Hey, bucko, I didn't use the BI said, Hey, bucko, the last I checked, I still sign your paycheck. So don't tell me how smart you are. There's a lot of pride, whether you are a video editor or a software developer or a CEO or whatever that thinks that, Hey, some machine can't replace me, someone, you gotta be really something special to do what I do.
And the fact of the matter is, my friends, it ain't so, yeah, it ain't so perfect. And then we're gonna find that out in the next year. Anyway, we're outta time here on Text Drunk Gang.
I hope you've enjoyed it. Wave goodbye there. Chris's little pit bull.
Bye. Okay, Sid, good having you on. Mike, as always, we've got Text Drunk tv following this.
We'll be back tomorrow with More gang. Until then, I'm Alan Shimmel. I'm out.