AI Agents Start Shopping, AI Designs Vaccines and Zero Trust Gets Serious
AI is moving from demos into commerce, healthcare and enterprise control planes at the same time.
On this episode of Techstrong Gang, hosts Alan Shimel and Mike Vizard, joined by Jon Swartz and Ira, examine Visa’s partnership with OpenAI to support secure payments for AI agents, a new AI-designed universal vaccine tested in humans and Zscaler’s push for zero-trust security around agentic AI.
The first segment, Agentic AI Shopping Spree, looks at how payments infrastructure is being rebuilt for AI agents. Visa’s partnership with OpenAI signals that agentic commerce is becoming real, with approvals, spending limits and transaction controls moving into the design of AI shopping systems.
The second segment, AI Medical Breakthrough, focuses on the healthcare implications of AI-designed science. Early human-trial results around a future-proof vaccine approach suggest AI could play a much larger role in anticipating and responding to evolving threats.
The final segment, Zscaler Field Trip, examines how zero-trust models are adapting to the rise of agentic AI. If agents are going to transact, access systems and make decisions, enterprises will need stronger controls around identity, access and runtime behavior.
Taken together, these stories point to the same broader shift: AI is no longer just generating content. It is starting to transact, design and act.
Transcript
Is it on? Is it on? All right.
No, the video's playing, it says. Good? Am I the only one seeing problems with Alan?
Yes. Yeah. I lost him.
Problems with Alan. Welcome to techstrong gang, where there's problems with Alan. There's always problems with Alan.
Guys, I apologize. It seems having three different internet providers in our office isn't enough to overcome the demons and gremlins of the internet. But you're watching techstrong gang.
Today's Thursday, and how about them Knicks? I've been, as I've said before, the last time the Knicks won the championship was the year I was bar mitzvah, 1973, and I've been waiting a little while since then. I thought it was going to happen often, but what a game.
A game for the ages, probably one of the best basketball games ever, if not one of the best sporting events ever, and certainly in New York. But we're really happy to be here, but we're not going to talk much more about the Knicks. We got other stuff to discuss.
Let me introduce you to our techstrong gang lineup for today. Back home from his trip to Vegas, we've got John Swartz. Home before he leaves on his European vacation, not with Chevy Chase, Ira Winkler.
And our other Knicks fan here, Mike Vizard. Gentlemen, welcome to techstrong gang. It's great to see you all.
It's good to see you. Thanks. I will have to say, I'm a Knicks fan, originally from New York, but generally being from New York, I'm a Knicks or a Nets fan, depending on who's doing better, so.
Well, the Nets haven't done well in... Have the Nets ever done well since Dr. J left?
I don't think so. They went to the finals with Kidd, but that was a while ago. Yeah, that was a while ago.
A long time ago. I don't remember. So when I was a kid, I used to love, on Long Island, we'd go out and see Dr.
J play a lot. Oh, nice. It was great.
It's been a while. I think my support for the Yankees, Knicks, Giants, and Rangers came with the birth certificate, so Yeah. Well, you're the Bronx.
It's different for the boys in Queens and Long Island. But anyway, guys, we got to talk tech here. We've got to talk AI.
Mike, I cannot wait for my AI agent to tell me that it saved me money because it bought something on sale. Yes, exactly. And I've had this conversation with my children, who once told me they saved $150 when they bought something.
So I was like, "Great. " Mm-hmm. But I digress.
It's interesting times, though. The way we shop is apparently going to change, and there's been folks talking about this for a little bit, but this week, OpenAI has a partnership with Visa that's going to come up with AI agents that'll let you use your Visa card to go shopping. But it gets better.
SpaceX and an outfit called Gopuff are playing around with AI agents that will track what you're interested in and buy that for you when they're ready. " It'll know which it is you want to do before you even know you want to do it. Soon you may even come up with a moment here where Knicks tickets are suddenly available, and you've purchased them because the amount of money you allocated for that matched up with your interest, and away you go.
Ira, are we ready for this world? What could go wrong here? Yes and no.
There's the to err is human, to royally screw things up is a computer. Mm-hmm. But the reality of the circumstance are we've been doing this for a while.
We've had just, coming from the retail sector, as most people know, there's just-in-time ordering where computers were looking at inventory supplies and automatically doing reordering on a preordained schedule, like knowing when you hit a certain threshold level. We also have, for example, OpenClaw. People have been using that to go out and combine purchases up to this point.
Now, where this is different is that apparently a credit card company is enabling another company to automatically do this, but I'm some ways scared. In other ways, I can see how, for example, there's the story of a kid ordering $500 worth of Pokémon cards or something like that. But at the same time, it can be really convenient.
For example, we've, thankfully, I say thankfully, we've never got to the point of smart refrigerators or something like that where it's going to let people know when we're low on things. But the reality is, we're getting to the point where, okay, if I'm low on Diet Mountain Dew, I want Diet Mountain Dew to be ordered for me, as an example. And so I think we're heading someplace which was inevitable.
We're heading someplace because this is for consumers, from what I gather, more than for companies, but business-to-business transactions have been done automatically via electronic payments in one form or another. I'll leave it there for now. Yeah.
Well, let me ask you this. Do we need some controls around this? Because it does seem to me that there are people who, I guess maybe they should act more responsibly, but they won't, and the next thing you know, they'll have these massive bills, and maybe we should have some mechanism in place that just says you can't go raid your bank account with an AI agent, and there has to be some checks and balances here.
Well, there should be spending limits. " But Alexa has been frankly tracking things for Amazon already. And with the credit card automatically programmed in, because I remember one time saying, "Oh, you might be due for a refill on this.
" Because Alexa is essentially Amazon's proactive arm. So we've had this, and we've had credit cards pre-stored. So again, we're evolving.
I hope that maybe there'll be spending limits on this, and there'll be limitations that way. And then also maybe only for transactions. But for people to think this is new, this is a twist of a commercial relationship.
But electronic ordering is not a new concept, in my opinion. Automatic payments, automatic ordering is not a new concept. John, the part about this that I didn't hear them talk about was how quickly are they going to come and pick up the- Right ...
you didn't want to buy. Yeah, exactly. The devil is definitely in the details, and I think, kind of riffing off what Ira was talking about.
So the merchants probably love this idea. So does the credit card company, so does OpenAI, because they're going to get it big. But I wonder, the thing that concerns me are controls over pricing, checkout, fulfillment, customer relationship.
There needs to be some sort of element, I would think, of a human, where if you reach a certain threshold for a purchase... And again, you're saying, as Ira said, "I'm interested in getting a car. I'm interested in going to see Bruce Springsteen.
I'd really like to be on the floor to see him. " This agent is going to, in some cases, I want tight control over whether they come back to me and say, "Look, I'm willing to pay 1,500 bucks for this ticket. " Rather than just plow through it.
Right? And I'm wondering with OpenAI, even looking beyond this, I think of this first as a consumer-facing technology. But I'm wondering if they're really more interested in what's going to go on with the enterprise in terms of making mass purchases.
And that's where the real money's going to come in, because OpenAI is desperate right now to figure out a way to make money, because they're coming up against it with an IPO. So this is another option, and again, this is tied into the IPO. Everything that they and Anthropic are doing in the last couple of weeks is all based on how it helps or how it moves the IPO along, and how it makes them look better on Wall Street.
All right. So Alan, I could also see a world where there's goodness here, and the goodness goes something like this. So I have my AI agent, and it's smart enough to know what it is I might be willing to pay for something, and it will go negotiate prices down in my favor because I'll have a little more power over the end cost of this thing, because I'll be using my AI agent to beat up everybody else to lower their costs.
What do you think? Well, I think when you first started there, I thought you were Louis Armstrong or someone. I see a world in pink and red and roses, too.
But that being said, Mr. Armstrong, yes, there are some real positives to this. My friend Ira loves to go on cruises.
And cruise prices vary drastically. There's deals that get released. What a great thing it is to have an agent.
And we already sort of had these agents, right? That were monitoring the latest airline fees, the latest cruise- Yeah ... prices.
But now you could add another element. Hey, if it falls below X, buy it. Don't even ask me, don't tell me.
I want to do it. Buy it. That would be really pretty cool.
Ira, as someone, I know you love cruising. Yeah. Does that appeal to you?
That appeals to me in certain things, because right, in the cruise world, the issue is, and I'm using this as an example, what happens is it's always best to buy the cruise early, and if it goes down before you're given the final payment, you can always get it repriced, and it's great to have an agent monitor that. At the same time, we already have, for example, stop-loss automatic payments in financial trading systems, in stock. And I could see this.
Another thing, just to riff off this whole concept, though, is, I remember when we first started having credit cards at the gasoline pumps, as an example. All of a sudden, the gasoline stations, they didn't have to count cash as much. There was less theft and everything.
But they still charged more for a credit card transaction because they didn't want to pay the 4%, not allowing us to see the benefit of them not having to pay extra labor, not allowing them the stopping of fraud and things like that, that they experience. So it would be interesting to see if it's going to cost us more because people want to go ahead and just profiteer off this, or it can theoretically save us money. Because when transactions become seamless, there's less middlemen.
Being, again, formerly in the retail sector, friction on websites, and this is just a human-computer interaction concept, friction on websites is one of the most important problems that people have because the more friction there is in making a transaction, the more likely it is that somebody will abandon the cart, which is a big concern where somebody's on a websitepurchasing something, then all of a sudden they have to reset a password or have multi-factor authentication, then they just say, "Screw it. " But having the less friction might increase profit significantly for some people. I was going to mention that something that was interesting about nine months ago when they were talking about agentic AI and kind of these killer app examples, one example that kept cropping up among executives was this whole idea of the agent planning your vacation for you based on the best available flights or whatever was in your price range, just kind of setting the whole thing up for you, where ultimately you are the final arbiter.
And this kind of reminds me of that in a sense. This is the fruition of what a lot of folks were talking about, especially at Cisco. They hammered away at this idea, and as Ira said, I think, and we all agree, this is inevitable.
And the only issue I have, and I think Mike brought it up, is we really need to know the specifics. I mean, the concept is great. It will probably work, but there are going to be some issues or concerns over these rampant credit card bills or- Well- ...
purchases that need to be reneged. Here's what I think. This is akin to when credit cards and debit cards first came out there.
For people to trust it, for people to use it, we're going to need to indemnify them or hold them harmless. There's got to be some mechanism where, you know what? The agent screwed up.
This isn't what I bought, what I wanted to, and there's got to be a generous return policy. It's what made Amazon, right? One of the reasons people like Amazon is, hey, you got 30 days or whatever, they'll take anything back.
Costco, for that matter, as well. I think we're going to need a similar mechanism if something was bought via agent, agentic, that no questions asked returned. All right.
So if you grew up in New York, you will remember Sy Sims? An educated consumer is our best customer. Well, I'm looking at this world saying everybody's going to be an educated customer finally, because I don't have to be so smart.
Yeah. Perhaps. That is a nice thing, right?
Because you could be looking... So for instance, we recently, unfortunately, had to replace the air conditioner in our house, the central AC units. And there's a handful of companies to choose from.
How do you know which is best, which has the best warranties, which has the best ratings? In the old days, we used to have consumer reports for this kind of thing. We still do.
I actually subscribe to consumer reports still. I don't know who else does. Yeah.
But it would be great to have an agent go do that all for me, because I spent literally hours- Yeah ... going on to consumers' reports, reading a whole bunch of other websites, and Reddits, and comments, and reviews. There's an entire cottage industry around all this stuff, whether you're traveling and when to get the best flight, and there's someone you're supposed to subscribe to, and they will give you advice about this.
There's almost nothing you can buy that somebody's not willing to give you some advice as to when to best purchase it and when not to. But I just think that most people haven't had the time or inclination to go do that or- Right ... a moment to do that.
Yeah, but if I had an agent to do it for me, and then give me the 411. You could train your agent to tell you exactly, right. Because you're a rarity, Al.
Jackie does that. She does the same thing that you do, but you're vigilant. I think most people just kind of just compulsive shop.
Well, no, let me be clear. This was a $25,000 purchase. For $25,000, I'll do my homework still.
Yeah. I am from New York. And we don't just throw 25 grand up in the air.
But I do. When I buy an appliance, cars, a lot of stuff, I do try to do my homework. No.
You know what I do? " No, I just mentioned this because- There's a cottage industry. I just mentioned this because there's so many Americans drowning in debt.
So most of them, fast convenience, and I always fear that this could potentially compound it for some people. Not many, but some. Mm-hmm.
It helps. I had another situation this week with my boat. Yeah.
Now- And I- Now, to be fair to Ira's point, though, right? The vendors have had a lot of these capabilities already, so they too will have their own AI agents, and those AI agents may be designed to get the most out of your wallet as they possibly can. So...
There is that, but this is why we can't have nice things. Well, that actually leads to the concern of who's controlling this at the end of the day. The agent.
Are you controlling the agent, or is Visa controlling the agent? Because it's like a commercial for, again, going back to stocks and financial advisors. It's like are you dealing with an agent, an advisor that has a fiduciary responsibility to you, or a responsibility to the suppliers, the companies, to maximize their profits?
com? Are they going to go to my local grocery store? Are they going to find me the best price and the best deal at that time to get me what is a commodity?
Or are they just going to go to the same people again and again because that's who OpenAI- It's a good question ... has a deal with? Yeah.
Well, I would hope on the back end, Ira, I can designate my preferred vendors. I go here firstIf it doesn't meet the price criteria, then just go out on the open web. But if you're going to go on the open web, don't buy it till you tell me.
When you think of the opportunity, though, for the merchants, the ones that are really going to win are the ones that make their products and checkout flows easier for the agents to work with. Right. Here's the one thing I do know about this, because we're running up on time.
Visa's going to have to change its slogan. " Fair enough, Mr. Armstrong.
Okay, let's jump. Our next segment, Mike, it's a little more uplifting. This is the kind of stuff we were hoping AI could do.
Isn't it? This is the great thing, right? So there's been some medical advances, or at least in the realm of research, where they are figuring out how to use AI to investigate how to make the usage of our vaccines better.
And the idea here is that instead of getting a new shot every time there's a new variant of some virus out there that's trying to kill us, AKA COVID, we will be able to have one shot that will work against all those variants and all the things that it will replicate through because it'll take out the family of viruses. So this is good news. Heck, who knows?
Maybe we'll even cure the common cold someday soon. But there's been a lot of usage in AI in the medical field, but I don't think we've seen the end results yet. But I think that if we could do this, then who knows?
We cure cancer or identify clusters or whatever, maybe we won't be arguing so much about, well, what are data centers doing to our world? But Alan, what's your take here? " I think we are, to a certain extent, and it's not yet mainstream.
This story, the instant story that we're highlighting here from, what was it, Cambridge? Yeah, Cambridge. Is a great story, right?
They've tested it, it seems well, it was AI designed. So when you're dealing with big number sets, DNA, we've got billions of pairs of DNAs and genes and so forth, targeting specific genes and protein building and stuff like this, this is the kind of stuff that AI's really going to be able to help with. And this is a great example of it.
I'll tell you something else. The founder of GitLab, I don't know if I've ever mentioned it on here, his name's Sid Sijbrandij. I've interviewed Sid many, many times over the years.
He was diagnosed with level four metastatic bone cancer about five years ago. And much like the movie "The Martian" where they scienced the s**t out of it, he scienced the s**t out of his cancer fight. And he actually hired a cancer researcher as the CEO of his cancer team and built out a cancer team.
Of course, when you IPO your founding company that's worth $4 to $6 billion, you got a couple shekels to spend on this. It's not practical for everyone. But he's created a foundation that helps people with this, and they're using AI.
And this is exactly what they're doing. They're taking your tumor DNA and manufacturing mRNA vaccines specifically targeted. Immunology that turns your body against these tumors and stuff.
It's individually targeted to your specific tumor. And this is the promise of AI, that we can have these kinds of things that were too expensive, just too big for us to wrap our heads around and bring it to people at a price point that maybe will be affordable to save lives. It's amazing.
Unfortunately, we probably won't see this here in the US. Yeah. Because we live in a country that denies climate change, denies DNA, denies, deny, deny, deny.
It feels like one of those commercials on TV. Deny, deny, deny. So I think, though, that this will overcome one of the primary objections you see to vaccines, where the folks, if you listen to what they're really saying, is they're contending that the vaccine is aimed at a general population, and some subset of them are likely to encounter some sort of complication thereof.
But if the vaccine is tailored specifically to your DNA and your environment and who you are, they might be more willing to- No. You know what? No, Mike, these people, hearing that it's made by AI is even more of a reason they won't take it, because they live in a world of conspiracy theories that are not proved.
And the fact that the vaccine was done by AI, it's the devil's brew. And it's a conspiracy by Hillary Clinton and the rest of them, and they're going to get you in some pizza shop in Baltimore or something. Well- That's the crowd you're dealing with here Well, let me actually, I was- The concept of this thing is great, though, in a sense.
, and I'm going to put his name out there. But this delivery system, this almost needle-free delivery system would solve two major hurdles for public health. Basically, it speeds up the inoculation process for mass populations during a crisis, and it bypasses this kind of needle phobia that a lot of people have, and it minimizes it.
And again, you're right, Alan. I can't make this point stronger than you can, but Unfortunately, we have this group of people who don't trust science, they don't trust expertise, and we have this great solution- They have an opinion, John Oh, and they have-- I know, it is frustrating because the AI can do really good things, and the irony is that the government is, for the most part, in bed with a lot of the chief AI players. Yet they- Well, no.
This government put an anti-vax person in charge of human health and services. That's all you need to know. It's a bizarro world.
Ira, go ahead. Yeah. Let me just say, I have a couple frustrations.
First, in Mike's introduction to this segment, because we have been using AI very fruitfully for decades now, and because AI really, at the end of the day, and it ties to what you're saying. There's this gross misunderstanding. At the end of the day, AI is just certain subsets of computer algorithms that we are currently now able to apply because of the accessibility of mass amounts of data and the availability of mass processing capability.
Of computing power. Right. Yep.
And this is what's required for AI. So for example, anti-malware has grown leaps and bounds in cybersecurity. Computer processing, even like Waze, is an example of getting people countless places a lot quicker, routing of airplanes and everything.
So I want to make that clear that we have been seeing the benefits of AI, and I hate the term. We've been seeing the benefits of advanced computer algorithms that we now have the ability to exploit. Now, for this, with this DNA processing and everything, my concern a little bit is that, yes, some people are saying if it's personally tailored to me.
Frankly, the problem with that is it becomes really, really expensive. Being able to mass produce a vaccine for a larger population, given that there are going to be consequences. " And I'm like, how many millions of people around the world died of COVID itself?
" When I give a presentation. " Because the reason is the definition of security is being free from risk. Nothing we ever do is free from risk.
Sitting in my house right now, there's nothing to stop, hopefully it doesn't happen, an airplane going to a private airfield from crashing onto my house. And I'm not saying I want that to happen, but there's risk to everything. Now, the question is, is the risk reasonable?
And I think this whole discussion about AI is you have these people hyping these things, and the problem is, some idiot on Twitter has the same visibility in theory as Anthony Fauci, who is one of the most brilliant people around. But because- Yeah ... there's all this thing like, oh, they're sci-- No, Anthony Fauci did what every scientist does, was they come up with theories, they come up with best practices to get us through.
But people forget the bodies that were put in refrigerated- Morgues ... cars in New York City because people were dying on an hourly basis out of hospitals. And they were trying not to show that.
I don't know why. It's the way to get people serious. And the thing is, we let some lunatic, Lothar369, who has a following of 28 people on TikTok, all of a sudden becomes as much of an authority.
I would've said it was Virgin General- So Ira, that's the issue ... but that's a bad example. That's the issue.
Everybody has an opinion. They're like, you know what? Right?
Yeah. Everybody has an opinion. We're all a******s.
Everybody's got one. I'll say it. But there's only truth.
Truth is truth. And your opinion don't mean crap in the light of truth. Right?
You could have an opinion. That doesn't mean it's true. But truth is truth, and that's the problem in our country, whether we're talking about AI or not.
Let me move on, though, to something else on this subject I want to mention. You're right, AI is great at pattern recognition and around huge number sets, and that's why you need all that data and all that processing power. You ain't seen nothing yet.
Once quantum comes online, you're going to start seeing protein folding and protein creations that not just are just targeting DNA immune responses, but designing drugs that will knock out diseases and genetic defects and so forth. And this is going to be another great leap forward, right, I think, in the area of biotech. And it's right over the horizon right now.
We're two, three years from this. I was talking to some people yesterday about it. Our friend John Willis is doing a lot of work on it right now.
It's that close. So, does that mean you and I are going to be in our 70s forever, or can we maybe go back a bit? Well, they say that at this pointThe longer you stay alive, the more chance you have of staying alive longer because of these kinds of breakthroughs that hopefully we'll see.
I don't know, Mike, I don't know if I want to be in my 70s forever. I'd like to go back to 30. Yeah.
That's my point. If you live longer, though, Alan, think of all the Knicks championships you'll be able to see. At one every 53 years, it's- Yeah.
There, see? Yeah. Come on.
With AI, it'll be once every 25. Come on. Yeah.
Yeah. Let me use an example here. It's sort of like drinking raw milk.
Before pasteurization, people used to drink raw milk and nobody got arthritis. And the reason nobody got arthritis is because they didn't live long enough to get arthritis. To get arthritis.
Yeah. And it's sort of like these ridiculous correlations are out there, and we need to make sure that we keep things focused. Like yes, having one inoculation that can prevent people, because my concern is in some ways, and I think this is a legitimate concern, it's not fear-mongering.
It's kind of like taking too many antibiotics and creating super- Superbugs ... bugs or germs. Right.
And maybe if you create this super anti-COVID vaccine, all of a sudden maybe we'll create a super version of COVID. But in the meantime, people aren't going to be dying. And hopefully by that point in time, the science will advance that we'll get the next COVID vaccine.
Vaccine. Yeah. Yeah.
And again, it's okay. " Yeah, but you didn't end up in the hospital- You didn't die ... you moron.
Right, you didn't die. And that's the point. Yeah.
No, anyway. And it's not just COVID. Let's be clear.
There's an Ebola outbreak of a rare strain of Ebo- a new strain of Ebola right now in Africa that we don't have a vaccine for. Let's pray it doesn't get out of its containment right there in Africa. But it's not easy.
But what also is not easy is trying to keep us, four of us to 15-minute segments because we all talk. We better move into section three here, Mike. What do we got?
All right. Well, John was in Vegas this week. It was Vegas, right?
It was. For the Zscaler event, and they're talking about, well, helping us deploy AI agents safely and securely. And they're making some claims in that direction.
But John, you were there. Tell me what happened. Yeah.
Their whole premise, their tagline was Zero Trust for AI agents, right? This whole idea of the rapid rise of AI agents, right? So it's creating these security blind spots, security concerns, because our defensive frameworks are traditionally built around humans, hopefully predictable human behavior and fixed identities.
So what they did is Zscaler did, and they do a lot of enterprise security work. They launched a series of tools under the idea, the concept that security can no longer just protect who's accessing the network, but most dynamically map the go between or the fast evolving relationships between humans, active AI agents, kind of going back to our first segment, and the sensitive corporate data they manipulate. So there were a couple of things they announced.
I'm only going to highlight a couple because there were far too many things they announced. But the two things that jumped out at me were something called the Zscaler AI Access Graph, which maps the relationship between users, agents, applications, and data sources. So they're tracking data lineage in real time and trying to assess unnecessary access risks.
I can't say that. They also introduced or talked about something called AI Asset Management, which expands visibility into embedded AI within SaaS traffic, public clouds, and endpoint activity. So in a sense, it is refreshing to me, for me to go to an AI conference where they are beating me over the head with what AI agents can do, and to have someone actually focus on the security side of things and the security opportunity, especially for a company like Zscaler.
And to underscore their point, they had some executives from KPMG who talked a little bit more about this topic. So I know we're running kind of long here. So I'm going to open it up to you all right now.
" But I also feel like this is the new table stakes for AI agents, and everybody who has anything in this space is going to have some sort of graph capability, some sort of policy enforcement agent, and it's going to know something about those AI agents. But I don't know, Ira, am I being too cynical here? I don't know.
It should and it shouldn't. Here's the problem again with AI. I think one of the problems is, again, we're making too big of a deal about AI.
Dr. " What we really need to focus on is- That's Dr. Evil ...
we're using... Yeah, Dr. Evil.
Yeah. But anyway, that's my Dr. Evil.
The problem is more, what I care about with AI is generally the data access that it has. And when we're looking at this, we need to understand, much like a whole bunch of tools that are out there is where are they getting data from, and then where are they processing it, and where are they putting it? Now, you need visibility into what's accessing your data as a whole, whether it's users, whether it's an AI agent or whatever.
Now the concept is that it depends on where you put it. Theoretically, you put it on an endpoint, and you can track where a user's accessing data to, from what applications they're using. And that was fairly standard technology by this point in time.
You can likewise put data accesses on the data storage capability, where you're monitoring who's accessing my data. Now the question then becomes when we have AI agents accessing data from all over the place How are they tracking that? If a user's doing it, you kind of assume it's inside the company.
If an AI agent is doing this, is the AI agent pulling data and then sending it to Anthropic to process? And if they're sending it to Anthropic, or they're sending it, maybe they're pulling it out and putting it to AWS, is it a single tenancy instance of AWS, or is it a multi-tenancy instance of AWS? How are they storing the data?
Are they using the data to training the agents and everything like that? So there's a lot of underlying concerns, and it's a little bit different technology to be able to have visibility on the agents than it was previously to just have who's accessing the data, and then on the endpoint and on the data side, because you're opening it up with a whole cloud infrastructure, the whole way it's being processed. So yes, hopefully this is kind of new.
It's a new way of map. You do need to map it, and I don't know. Fundamentally, I don't know who's doing it well or who's not doing it well.
I haven't had a chance to look at it. Zscaler's an established company. I like their people.
I haven't used their product, I'll be honest, but I love their people. Sam Curry, brilliant CISO over there. And I'll leave it at that.
Jay Chaudhry's brilliant as well. I mean, Jay Chaudhry's- Yeah ... done a lot in security over the years, right?
Totally. But Alan, to Ira's point, are we obsessing too much about, quote-unquote, guardrails for the AI agents and just not enough on the let's lock down the data sources and the things that are being accessed because, well, that's where the point of the gateway should be. So, let me be real here for a second.
What makes you think we can lock down those sources from AI agents when we haven't been able to lock them down for the last 30, 40 years, period? What, did something change when I woke up this morning? Was there a magic- ...
bullet or something or that all of a sudden I could lock down data sources? We can't. That's part of the issue.
To think we're going to do something specifically for AI that we can't do in general is that's your opinion, but it's not the fact. Is it a can't or a won't? Because maybe we can, but we just haven't, because- Let me put ...
I got to respond to that because the thing is- Yeah ... are we going to stop it is one thing, but more important, do we have visibility for it? Because without visibility, your policies basically become the stereotypic policy of a document that sits on the shelf until an auditor asks for it.
Visibility, in many ways, is more critical than actual prevention, at least for a CISO. I wish CISOs had the ultimate authority. Well, I don't know.
Actually, let me take that back. CISOs don't need to say, "This happens," or, "This doesn't happen," because that's the function of a business. But the CISOs do need to understand the risk.
In order to understand the risk, they at least need visibility. Visibility. And without the visibility, is it going to stop data access?
No. Should you stop data access? You got to run a business.
Business is number one, but you got to run it with reasonable risk controls in place, and at least a CISO needs the visibility, which hopefully is what this is doing. But here's the thing, right? This reminds me of, well, if you unplug from the internet, you'd be a hell of a lot more secure, right?
But I wouldn't do business. But you do have to run your business. Let me take our own experience here at Textron.
Three months, four months ago, we undertook this agentic experiment, and we have some people using Claw, some people using Perplexity, some people are now using Codex and Claude Cowork and everything else. And we tried to set up a policy really beginning with zero access, zero trust, right? But let's face it, if you don't give it some access and some trust, it's not going to do much for you.
Same way a person is. " And okay, it needs to be able to read my email. Does it need to be able to send my email?
Does it need to be able to access my Google Drive? Does it have edit capability of what it accesses? Does it have delete, right?
Can it delete? And very quickly, the road to hell is paved with the best of intentions, but you're constantly struggling between how much do I want to get done, how much can this thing do for me, versus in doing that, I'm giving them a little more access. So to Ira's point, that's correct.
You got to run your business. Yeah. But in terms of visibility into it, I would put forth the notion that it's probably easier to track the movements and actions of the agent than it may be of a person, right?
Because it is totally electronic, and it is leaving a-- Unless it's so nefarious that it was set up not to leave fingerprints or footprints or breadcrumbs, but you should set it up that it leaves neon breadcrumbs and it's very easy to see Well, I would say you're right in theory. As long as you have the appropriate tools that are doing the tracking, it should be easier to track if the tools are in place, compared to whether a user takes a document, prints it out, makes a copy, and finds somewhere a fax machine and faxes it to who knows where. Well, no.
I'll give you a better example. You take a copy, put it in your briefcase, and you leave your briefcase on the train on the Long Island Railroad on the way home. Or classified work plans.
It's happened. Right. No, this stuff has happened.
It's happened. But yeah, so it should theoretically be easier, and hopefully the Zscaler tools are allowing for that, because without the tools available to do the tracking, you're left with where is the other traditional sources? Right.
Where in the world is Carmen Sandiego? We're about out of time. Wait, was that a technical term, neon breadcrumbs?
How does that work? No, that's my new startup. It's just coming out of stealth.
Neon Breadcrumb. security. No, I'm kidding.
But that is pretty technical, Mr. Armstrong. All right.
Hey, we're about out of time. Ira, if I don't see you before, have a great time on your vacation. Enjoy it, and happy birthday to your wife.
John, it's good to see you home. We'll see you back on with the gang soon. And Mike, you and I are here.
Well, I won't be here tomorrow, but you will. I will. Most certainly.
With John, I hope. Yes, I will be there. Absolutely.
I'll be here. Hey, 2:30 today, though, I will be on Shimmie Says. Go check that out.
We'll be live on YouTube, and LinkedIn, and Techstrong TV, and all our Techstrong sites. So check out Shimmie Says. I've got an interesting one today.
But until tomorrow, thanks for joining. tv, our OTT channel's on just about any screen you like to watch stuff on, and any provider. Or you can tune in every day live at noon and check us out here.
Until then, though, this is Alan Schimmel. We're out. Thanks.