AI Detente, Copilot Limits & Project Glasswing | Techstrong Gang
The Microsoft–OpenAI partnership just got rewritten. GitHub paused new Copilot sign-ups. Microsoft embedded Anthropic’s Claude into its security pipeline. All in 8 days.
On today’s Techstrong Gang, host Jon Swartz and the panel unpack what actually happened — and what it means for anyone shipping software in 2026.
AI Detente: OpenAI and Microsoft Rewrite the Deal
OpenAI just won multi-cloud freedom, with deals on the table for Amazon Web Services and Google Cloud, while Microsoft locked in long-term IP and revenue rights. The Azure exclusivity that defined the last three years of generative AI is officially over.
OpenAI is no longer Azure-only. Workloads can now spread across AWS and Google Cloud. Microsoft kept the IP rights and revenue share that matter long-term, keeping Redmond in the loop on every model generation. The exclusivity arrangement that powered Copilot, Azure OpenAI, and the Bing AI relaunch has been retired.
Copilot Hits the Brakes: GitHub Pauses New Sign-Ups
On April 20, GitHub paused new sign-ups for Copilot Pro, Pro+, and Student plans and tightened weekly usage caps for existing users. The reason: agentic coding sessions are burning more than 500,000 tokens per session versus roughly 100 for old-school autocomplete. The flat-rate twenty-dollar-a-month pricing model just broke under the load.
This isn’t just a GitHub problem. Cursor, Windsurf, Replit Agent, and every other AI coding tool will face the same math in 2026. Agentic coding burns 5,000 times more tokens than autocomplete, and flat-rate pricing can’t survive that reality.
Project Glasswing: Microsoft Embeds Claude Mythos in Its SDL
Microsoft is embedding Anthropic’s Claude Mythos Preview directly into its Security Development Lifecycle — the same lifecycle that gates Windows, Office, and Azure code. During preview, Mythos autonomously discovered a 17-year-old remote-code-execution flaw in FreeBSD’s NFS implementation, now tracked as CVE-2026-4747.
Anthropic has privately warned U.S. officials that the same capability in attacker hands makes large-scale cyberattacks “significantly more likely” in 2026. Defense vs. offense — who’s winning the AI security race?
Today’s Panel
Jon Swartz, host of Techstrong TV. Mike Vizard, Editor-in-Chief at Techstrong Group. Kate Scarcella, Chief Architect, Cybersecurity & Trusted AI. Sid Nag, VP Analyst at Gartner. Anne Ahola Ward, CEO of CircleClick. Alex Porter, CEO of Lunar Outpost.
Episode Chapters
00:00 — Cold open
01:30 — The OpenAI / Microsoft partnership reset
12:00 — Multi-cloud, IP rights, and the end of Azure exclusivity
20:00 — GitHub Copilot pauses sign-ups: the agentic pricing problem
28:00 — Why $20/month coding assistants don’t survive 2026
35:00 — Project Glasswing: Microsoft embeds Claude Mythos in its SDL
44:00 — The 17-year-old FreeBSD flaw Mythos found alone
52:00 — Defenders vs. attackers: Anthropic’s warning to government
58:00 — Panel predictions and final takes
Read the Full Articles
GitHub Copilot pause announcement: https://thenextweb.com/news/github-copilot-signup-pause-agentic-ai-usage-limits
AI-Powered Defense for an AI-Accelerated Threat Landscape (Microsoft Security): https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/
Claude Code Security & Project Glasswing (Anthropic): https://www.anthropic.com/news/claude-code-security
CVE-2026-4747 — FreeBSD NFS RCE on NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-4747
Never Miss an Episode
Catch Techstrong Gang live every weekday at 12:00 PM ET, or watch the replay on demand. Subscribe to Techstrong TV on YouTube for daily AI, DevOps, and security analysis. The audio version lands same-day on Apple Podcasts and Spotify.
Transcript
Hello? Hello. John?
Hi. You want to start us off? Oh, you want me to start?
Oh, I'm so sorry. I'm so sorry. Hey, everybody.
Welcome to Techstrong, gang. We're having a little bit of issues with StreamYard, so I apologize in advance. I'm on my phone, as you can see, at a very strange angle, but then again, I'm being very strange today.
It's Tuesday, and we have a great gang assembled today to dive into the latest tech news. Boy, there is plenty going on, especially around this notion of the AI stack moving from hype-driven bundling to infrastructure reality. But before we start and dive into all this, let's introduce our panel.
We have a Texas-themed contingent, so to speak. I'm at the SAS Innovate show in Dallas. Okay, grapevine.
In Austin, we have my good friend, Anne Ahola Wert. Anne, hi. Good morning.
Good morning. Thanks for having me. Yeah.
I wished I could've made it to Dallas, but it just wasn't in the cards for me this time, but- Maybe next time. I will. And with you, I think in Austin, is a newbie, Alex Porter.
Hey, Alex. Nice to meet you. Hi.
Glad to be here. I'm going to get back to you in a second, because we want you to tell us a little bit about yourself, but we're going to go through the rest of the panel first. We also have Kate Scarcella in southern Maine.
Hello, Kate. How are you? Good.
Good. And then Sid, it's good to see you in person. I've talked to you via email for years.
Sid Nag in New York. Thank you, John. Good to be here.
Good to be here. And joining us, thank God, at the last moment, is the great Mike Vizard in New York, who's fresh off a trip to Europe, where Helen, I believe, is still there. Hey, Mike.
Hey. How you doing? I don't hear the word great and Mike Vizard in the same sentence very often, so thank you.
Aw. No, I truly mean it. No.
Well, let's go back to Alex. Alex, tell us a little bit about yourself. Every time somebody joins the show for the first time, they give us a little bio.
Yeah, absolutely. So I've been a tech founder for over a decade now, running a couple of different startups. Our first was focused on augmented reality and virtual reality for large corporates.
And since 2020, I've been building Mod Tech Labs, which is focused on the orchestration software layer, helping make sure that our infrastructure can work more efficiently, which is extremely relevant to a lot of the news that we're going to be talking about today. Great. Cool.
So our first segment is appropriately called AI Detente, and I'll do a little bit of a setup for it before I kick it over to Sid. So this is basically, OpenAI and Microsoft on Monday kind of announced a truce of sorts to defuse this mounting tension between the two of them, which is always what we expect from Microsoft. They're your partner, then they're your competitor.
Anyway, under this new revised structure, OpenAI has more freedom to partner with Microsoft's rivals and deliver products on non-Azure clouds, reflecting pressure to meet enterprises where they are. Microsoft keeps non-exclusive licensing rights to OpenAI models through 2032, but this old artificial general intelligence trigger clause is removed, reducing contract ambiguity around what qualifies as AGI. So in a sense, Sid, tell us a little bit about where you think this is.
What does each company gain from this, and is there a third reason or maybe an outside reason why they were forced to make nice on their latest agreement? Yeah, I think the first thing I would highlight is that people tend to think of it as a tension between the two companies. It's really not that, right?
This is not a breakup. It's just a normalization of what I call power dynamics in the overall platform ecosystems within the AI family of sort of tools and models and the economic interaction between these companies, right? So I think we are transitioning from a tightly coupled partnership, which has been the case ever since Microsoft and OpenAI kind of got together and launched ChatGPT, I think, what?
Like two and a half, three years ago, to more of a tightly coupled partnership to a flexible ecosystem model, right? So where both companies can collaborate a little bit better while still pursuing their independent strategies. We read the story about how OpenAI is sort of struggling to be profitable, and then they've raised a ton of money, so they're heavily in debt from that perspective.
But so I think this is sort of an expansion of their strategy as to how they can sort of work together yet go on their own in many ways, especially in the case of OpenAI, where they need to show more revenue, more traction in the pursuit of their impending IPO, right? So that's sort of one point I want to highlight. One thing quickly, Sid, is that you mentioned the financial situation of OpenAI.
There was a story that The Wall Street Journal just published today- Uh-huh. Yep ... that you're referencing, where evidently, the CFO has some concerns about them meeting revenue and customer sales goals, which has created this whole type of panicAmong the market.
Now, I talked to our CEO at the Futurum Group, Daniel Newman, who basically said this report was nonsense, and OpenAI has referred to it as a clickbait story, but I think there is actually some traction to this. I'm not sure what you think. Yeah.
Sorry, Mike, you want to point to me? Go ahead. Yeah, sure, Mike.
Yeah. I have something to say about this. " So let me understand this entirely.
You were telling me that this first contract between these two companies was dependent upon the fact that we were going to have a definition of AGI to determine when at some point we will part ways with one each other. Well, why didn't we just have a little pinky swear in the playground? Because that- ...
was as good a deal as that is worth. So who comes up with these contracts? What kind of insanity is this?
Is this something that a lawyer actually signed off on? Because that's just amazing to me. But Anne, I'll throw it to you, am I crazy or what?
This isn't a divorce. This is a conscious uncoupling, to use the parlance of our times. I think the prenup very heavily favors Microsoft.
OpenAI gets to go out and play the field and date other people, but Microsoft gets the house, with Azure priority, and they're locked in IP license until 2032. Mm-hmm. So I think the story here is that the AI market is growing up, and the exclusive partnerships are giving way to a term that I actually read the other day, Gartner is calling alliance architecture.
So the company that can't afford a single vendor anymore is everyone, and I think this just shows the market maturing. Mm-hmm. Alex, you have any thoughts?
I've just met you today, so you can tell that I can be a little obtuse sometimes, but it just seems to me that this is an agreement to what Anne just described, where all parties involved now have the right to be as promiscuous as they want. So business as usual? I think it's indicative of how challenging the hardware landscape is.
The reality is NVIDIA, Jensen Huang, in January of this year at CES said, "Prices are going up. " And at the same time, the entire world landscape is changing about resource allocation, so we can't make chips without resources. " So I think that because the innovation that OpenAI is pushing, there is a need to find those other support mechanisms out in the market.
I think you're spot on, and I think John alluded to this too, but I think all these companies are losing serious money on this AI stuff because the utilization rates of the GPUs are so low, and it seems like they are, shall we say, artificially supporting customers' usage in that because they're not charging past the full through and they're taking a loss on all this stuff. But John, it looks like to me like the financial numbers underneath a lot of these companies look a little sketchy. Yeah, they have been.
And I don't know how else to put it. This outrageous amount of money that OpenAI is going to be spending on their AI build that is like $600 billion, and their revenue rate's not even close to it. And at the same time, I wonder also the influence of some of these other deals.
I look at Anthropic, and I look at this "I'm going to say that very loosely, $40 billion investment that Google's making," which is really only $10 billion contingent on a lot of other things. Amazon's actually plowing $25 billion into Anthropic. So with OpenAI, there are so many questions about this company.
And to be fair to The Journal, even though some people have dismissed that report, they're quoting people who've been talking to Sarah Friar, who's the CFO of OpenAI. Actually, there's a lot of smoke there. There's a fire there.
Mm-hmm. And it bears repeating, there's a lot of pressure on that company to go public as soon as possible from Sam Altman, and Friar, to her credit, wants them to wait a little bit and maybe have a little bit of more responsible business approach. So that bears looking at more closely as this unfolds.
I think one other point that I want to make, OpenAI's been partnering with almost all the hyperscalers. You talked about Google and Anthropic, but OpenAI has been doing the same thing, trying to get compute power from all the other hyperscalers. " They want a piece, more compute from- Mm ...
consumption from OpenAI, and I think this is sort of one of those things. So I don't think the AI story going forward is going to be about models, it's going to be about AI infrastructure. That's- Yeah, absolutely.
That was everything about Google Anthropic. Exactly. It was also the move from the models to the infrastructure.
Yeah. We were talking about this yesterday with And the other thing is, it's going to move towards the problems CIOs are facing in deploying. To date, the conversation has been about vendors doing all the fantastic things.
No one talks about how enterprises are consuming this. So I think what is going to happen here is that we're going to see more collaboration in areas of enterprise use cases, like joint deployment of advanced AI tools. And Microsoft is a tool vendor, whether you like it or not.
They have kind of software. Yes, they have the operating systems. So I think OpenAI is going to have to use those tools to make the deployment of AI within the enterprise, and that's really where the revenue is going to be driven from.
That's another angle I think we should talk about. All right. I think the sales goals numbers are about as relevant as the pinky swearing numbers.
So basically, somebody licked their finger and stuck it up in the wind and came up with a number, and now they're short of that number. It's a private company, and to sit there and say that they were not impacted by this whole noise around them and Anthropic and the government, and some people didn't shift some of their buying patterns is just silly. They didn't.
It probably didn't meet their goals, but the goals were fictional to begin with, so it's like- Right ... whatever. So last week, Mike mentioned about me being validated about what I said about application and AI and everything.
So I just want to mark this moment, April 28th of 2026, because I'm about to give another prediction here, and I expect you, Mike, to come out and say, basically- I don't have a pen ... we are building for tomorrow what we yet don't even know and understand. So, it's almost like we're going to be left with a bunch of open malls that are just totally collapsing, and we're going to have all these buildings, and they're going to be literally in our backyard and we literally need to stop building what we don't understand yet.
Because I don't even think we understand what AI has the potential of doing. When I talk about AI, I'm talking about what actually the speed of which it's going. I don't think we're going to need this huge compute.
And, I'm probably the only one who's saying that. So Mike, I just want you to mark this. Yes.
Mark the date. Yeah. " Ridiculously, yes.
So don't mark those words. But where I think that they're brilliant is they've lost this whole cloud. They lost the upstream, but they have brilliantly captured downstream.
And I think that at the end of the day, Microsoft are the winner. So those are my predictions. I'll take that a step further, and I'll say that these guys think that they're off going to go build some massive AI brain in the cloud, and they're going to have all these data centers, and it's going to do this massive general purpose AI capability that's going to be used for millions of different things.
And yet, I can make a strong case that says the future is going to be dominated by smaller language models, well-trained for specific tasks, highly distributed. And we're going to stitch all these things together using various AI agents, and that may not require all the data center capacity that Kate's talking about. In fact, a lot of it might not even need a GPU, because that's why we have all these other different classes of processors.
But, a lot of models are going- I love you, Mike. I love you. Just let me put it out there right now.
Where we sit at Mod is actually, we're bullish that the software architecture layer is actually going to be the piece that makes the instancing of the infrastructure more efficient. So that's where we are actively working. And I know there are other companies that are doing it, so I fully agree with you, Kate, that I don't think it's actually about the build-out necessarily.
It's about using it more efficiently. And to your point, Mike, there are tons of different processors, right? We all talk about GPUs, right?
GPUs are so heavily used in a lot of the AI functions. But there are NPUs, there are CPUs, and if there are ways to instance those and use those more efficiently to break up GPUs, slice them efficiently, actually distribute compute on existing networks, that is where we see the future going. And that's actually the direction we're currently rowing in.
There's a massive, I think, loss in information right around what is in the AI stack. And I'm going to reference Jensen Huang again, because I really love the AI cake model, which is just the five layers, right? The bottom is energy, the next layer is chips and compute, then there's cloud, then there's models, and on the top is applications.
And a lot of the conversation is about models, and a lot of the conversation is about applications. And we're now finally getting into those deeper layers and talking about infrastructure, talking about chips and compute, and that's where I think the innovation is going to start happening now. There you go.
I think we're going to have to move on to topics, but I would just reach back in time and go, every time in the history of IT, when we don't understand how to make something work, what do we do? We throw hardware at it till we figure it out. So there we go.
That's true. But I don't think this is about hardware. I actually think to Alex's point, we're going to see a...
We're already seeing it, right? People are going to take frontier models and curate industry and company specific models. They're going to be much smaller in size, and you don't need a GPU from Nvidia the price of a Honda Civic to run that, right?
You can use CPU, you can use LPUs like Alex said, right? But to make all that happen, the sausage making to happen, you need tools. And I think Microsoft is way after that market, the tools market, right?
That's my take. All right. John, do you want me to take it or you want to shift this gear from here?
Why don't you do it? We talked about GitHub a little bit yesterday and about the Netflix model kind of comparison, but you want to tee it up, Mike? I can, you can.
To John's point, this is a continuing saga, and the latest version of this is that GitHub is now saying that they're going to charge for usage of AI. And this may not come to much of a surprise or a shock to a lot of people, but let's start thinking this through for a minute. Anne, I'm going to toss this to you.
What happens when every other software company that's using AI comes up with the same idea? Now we're suddenly billing for usage across the board. " So I guess AI, it ain't open source and it ain't free.
Somebody's got to pay for this stuff eventually, and it can't be like the federal deficit, right? Right. I think that this is just a given, that GitHub was going to hit a cost wall.
Mm-hmm. " All those companies in the valley went under. It's the same sort of concept, right?
You get people on your platform in the hopes that you can monetize and catch up, but that's not happening. The explosive growth in AI coding and long-running multi-step workflows is consuming more compute than expected. Which by the way, who didn't expect that, means that it's exceeding what users are paying per month.
So that pricing model has broken down. Flat monthly pricing no longer works because those heavy users are generating very unpredictable, very high costs. So what they're doing is they're moving towards usage-based token pricing to better align with the cost and the actual consumption.
But the thing is, this isn't just GitHub, it's a broader industry shift because these tools are running into infrastructure economic limits, signaling the end of unlimited AI for a fixed price. I think we're going to start seeing that go away. It's just like we were talking about "Scarface" before the show started.
I'd liken it to they get you hooked, and then they raise the price, they limit the supply. I know people who will remain nameless that are psychologically dependent o- on these tools. I know companies that are getting built upon them.
And so this is going to be sticker shock for those people. But I think that the pricing reset is more about economics matching reality. AI coding has become more powerful and expensive than the original model could sustain.
So this isn't really a cost problem, it's a product illusion that's sort of broken. And, I do agree with the Netflix example. They get you there, and they get you hooked.
You want to have that subscription, then they mark it up. This is just market correction. But I don't think the unlimited subscription model is going to last, and that's just a sad reality for those of us who have become so dependent on these tools.
" Well, using that Netflix metaphor, though, at least my kids are looking into the acquisition of used CD players and going out and finding movies that they can get for two bucks a throw at a used- Mm-hmm ... store somewhere. And they're like, they don't need to have five million movies that they want to look at in Netflix.
They'll just go down to the local store and buy a CD for 50 cents. But that's another metaphor altogether. But Sid, I'll poke this back at you a little bit and say, if this is the case, right, and using Anne's metaphor about getting people hooked on something for free and then charging them more for it, does that mean more people are going to show up at the methadone clinic because they can't afford their habits, and they're going to look for ways to get off the AI junk?
What do you say? Yeah, absolutely. I think what's really driving this at the end of the day, from my perspective, is the A word, right?
We're seeing a proliferation of agentic in the world of AI, right? So more agentic workflows are going to run multiple coding sessions, right? And that whole environment is going to explode, right?
And when that starts to happen, there is a wall, to Anne's point, hey, we can't sustain this behavior from an economics perspective. We talked about this a few shows ago, about the idea of tokenomics. So that's really what it is at the end of the day.
You got to pay for it. But I truly believe this is just a transitional phase. You've seen this in every possible industry, right?
We saw it in telecoms, right? Where people would charge for flat rates, then it went to usage-based billing and said, "No, no, no, this is too complex. We can't reconcile our expense side.
Customers are going to scream. " Right? So I think this is an intermediate stage, a transitionary stage because of the explosion of agentic, which is driving this weird behavior, unfettered sort of activity.
And so the people are unable to track the economics of that. But once we get this under control, it'll go back to flat pricing. Right.
And I think the developers that are going to be screaming the loudest are also going to be the same ones that are getting subsidized, right? And I think your lighter users may not even notice. But I think people in smaller companies like mine and Alex's, we have to watch our tooling costs because we've got to start thinking ahead and building that flexibility into our budgets now, because token-based billing is coming for everything Yeah, that was something we mentioned yesterday.
We were talking about if the bottleneck is compute and reliability, what's the next step? Are we going to have credits, token metering, throttling? No.
It's going to get better. There's going to be a black market for tokens. I'm going to have some tokens and some excess tokens.
I'm going to sell you some on the side or out the back door. Start an OnlyFans. Yeah.
Yeah. It relates- Relates to that FinOps side of things where you can understand what your costs actually are. But the unfortunate thing is this looks similar to cloud, right?
What are your cloud costs? Do you know? Can you peg that?
The reality is it took a long time for there to be any good metrics or any good estimation based on your business and what your uses are. And then our perspective on it is that we see a lot of companies, we work heavily with legacy businesses, so they're more regulated. They tend to have on-prem hardware versus cloud because they're dealing with a lot of other additional things.
Think about manufacturing, defense, media. A lot of them want to control their infrastructure. And so because of that, they have a lot more control over costs.
And I've looked at the, I call it a pendulum, it's the pendulum of cloud versus on-prem and how that slung back and forth in the last few years. And I do think that businesses that are extremely sensitive but want to deploy AI widely are going to start migrating back toward on-prem instances so that they can maintain and control costs effectively. Because they're not going to be able to do that with these public models.
And yes, there are enterprise versions and you can get more allocation and more allotment, but how much can you really tune those per department? How much can you really meter and create the right efficiencies in your business with that tooling without breaking the bank? And that's sort of the trade-off I think that's happening.
I like Mistral for that reason. That's why I'm watching that company. I like their model.
So can I ask a quick question? So what do these platform teams do then? Do you set internal usage policies, or do you choose models with lower multipliers?
Yeah. That's the core idea. Basically, you're going to mix and match models based on the job and the tasks, and you're not just going to let people randomly select a particular model, and you're going to make sure that the model usage is optimized.
But it requires expertise and code and skills. But I want to come back to what Sid was saying, and I kind of hope Sid is right. Sid, let's look at it this way.
A company is now charging, I don't know, 50% to 100% markup based on usage. " So will they go back? You sure?
I don't know. I don't have a crystal ball, but I think for now it's going to be usage-based, certainly because of the agentic sprawl. So once we get things like agent registries and guardrails around the utilization of agents running wild, especially the coding agents, which obviously have an impact into the GitHub conversation, I think that's when you're going to have a little bit more sanity around things and probably go back to flat pricing.
But for now, it's just out of control. I just think the number of agents that are running around within enterprises unleashed by all these model builders is just untenable. So that's why I think you're seeing the advent of this phenomena.
And again, to Alex's point about cloud, we've seen this happen in the cloud business. Spot instances, reserved instances, this permutation, that combination. Tracking all that became completely untenable by enterprises.
So when was the last time you heard about things like spot instances? They probably still offer them. So this sort of usage-based consumption on the coding and GitHub side and software development side is probably a temporary phenomenon.
Well, I'm old enough to remember this, so I'm going to put it out there anyway, but where's Richard Nixon when you need him? We need some AI price controls. Come on, what do you say?
Oh, wow. Wage and price controls. Damn, it- I was- ...
makes me feel 1970, you Mike. Damn. I was going to say that it's funny that you bring up, Mike, about that because I was thinking, the late 1990s, what this reminds me of is all the articles that came out about data being the new oil.
Yeah. Being able to do metered and computed and blah, blah, blah. And this is like the same idea.
It's Groundhog's Day, everybody. We're seeing Groundhog's Day. Everyone go out and see that movie.
Not necessarily on Netflix, but yeah. It's... I will digress, but I always told people when they cite data's the new oil, I always said, "You know what you can do with a barrel of oil?
" Nothing. You process it to make it into something useful where all the money is. So I was always kind of like, if data's the new oil, that's not good, because oil's not really worth a whole lot relative to everything else.
But it... Yeah. But I don't...
Yeah. But I digress once again. Anyway, I think after a few days, everybody's getting the point finally.
But hold onto your wallets is all I got to say. Want to do the next topic? Because it's just as much fun, I promise.
Oh, yes. So you want me to do this one, Mike? Sure, go ahead Okay.
So Microsoft unveiled these plans to incorporate Mythos and other AI models into a security development life cycle. And I'm not sure who we wanted to punt this to, but I was thinking perhaps Kate. I think we talked about this earlier, and I'm wondering what you thought of this topic.
Yeah. What's your thoughts on it? Well, first, I don't know who puts this together, but block A and block B really fit perfectly into block C.
That's Mike. This is all Mike. Yeah.
So go Mike. One thing is, this is like a jigsaw puzzle. So every show, you look at A, B, and C, and you see how they're interconnected and there is an underlying theme.
So yes, you are correct. Otherwise, you know. So, well nicely done, because both actually lead to the condition of C, of this block C around cybersecurity.
How can we not, when you're looking at both sides, with everything being so fast, that cybersecurity vulnerabilities are almost just impossible to keep track of. And I think as everybody gets involved, the more the vulnerabilities are going to be shown. As I talk a lot about, we have had a lot of poor coding, and a lot of fast coding.
And I think it has helped us. I'm happy with AI actually getting involved here, because I think it actually helps us. Oftentimes, I have wanted to, like, there are so many vulnerabilities, like, we just need to start over.
Mm-hmm. And I think AI actually helps with that. Really get rid of the sessions and these hard-coded admin passwords and code.
And this is such an important time, and I also believe that there's a collapsing of an offense and defense strategy. And so it's almost like a new type of order that's coming because it's ... And they talk about AI fighting AI.
I don't know if I see that so much, as much as I believe that we're not going to be able to go backwards. We're only going to be able to move forward. So instead of trying to fix code that's bad, I think it's just going to be dumped, and I think thank God it's dumped.
Yeah. And we're going to move forward with really decent, smart code that will be fast and efficient, and that will crush these huge compute data centers that are needed at the end of the day. For sure.
So again, I might take this to another level, so I will. First of all, Microsoft has been the poster child for bad code for as long as I can remember, and has more vulnerabilities in those platforms than in any time that I can remember. So hats off to Microsoft for finally doing something about this and leaning on their AI model to go fix that issue.
And I sure hope that the next wave of software, to Kate's point, is just going to be infinitely better. But it's not just Microsoft. It's going to be everybody who builds software.
Every ISV is going to need to use a model like this to look for vulnerabilities before they ship that code to somebody, because I got news for you. If you ship code with vulnerabilities in the future, we will take you to the town square and publicly shame you. I guarantee it.
It's just going to be not acceptable. " So I'm looking forward to the day when we have good software, and maybe to Kate's point, let's just throw out all that crap we had for the last 25 years that- Right ... it's more trouble than it's worth.
But you know what? You're talking about Microsoft and hats off that they're finally doing something, but frankly, Microsoft has been doing something by starting with Patch Tuesdays once a month, more so than the other operating systems like AIX, Apple, and all these. Trying to go, and I remember, go to Apple and say, "Hey, you know what?
" Yes. So Microsoft, yes, they have a lot of bad code, but so does everybody else. It's just the platform hasn't been used so widely as Microsoft, and we will start to see all the bad code, and it's a good thing.
So yes- Yeah ... good for Microsoft for doing this, but Microsoft has really been aware of their vulnerabilities, thus Patch Tuesday and a lot of overnighters. So Kate, you mentioned offense and defense earlier.
Mm-hmm. So this always conjures up in my mind, if models like Mythos are restricted, does that create an asymmetric defense advantage for the few, or does it concentrate risk? It's interesting because asymmetric warfare, right at the end of the day, I think it will be risk at, if I'm going to answer your question, it's going to be risk.
But asymmetric warfare, I think all hats are off with AI. The speed at which anybody can get their hands on something and go is showing us what poor infrastructureAlex, back to you. What poor infrastructure that we have had, and that's hosting all this.
Because they all go together at the end of the day, the infrastructure, the application, where the data is held. We're going to see more on-prem. Personally, I think we're going more on prem.
Another prediction there, Mike. Mark this down. But, we will, and because we're going to try to control something that we're finally...
What is it like when we come home to roost? What's that saying? When everything comes home to roost?
I think- Chickens come home to roost. Yes. We are actually seeing that right now.
Yeah. And so we're going to have to take some different actions that- I will take issue with Patch Tuesday. So six out of every seven days, I am very productive, long time Windows user, and generally been happy with the platform despite some of my complaints, and are never likely to switch to Apple.
However, every Wednesday morning is the same damn thing. It's the least productive day. Because why?
Because as sure as the sun follows the moon, every Wednesday is the day after Patch Tuesday where nothing works. And then I got to go back and reconfigure everything because some patches came through that messed up something, or all my browsers suddenly disappeared, and some of that is probably a function of my own IT department, and some of that is a function of the machine I'm probably using. But I just got to say, if Patch Tuesday is the best answer we have to this thing, it's called Sucky Wednesday.
Patent that. I want a trademark on that. Yeah, definitely.
I was also going to add to this that I'm also skeptical. I love the idea of magic bullets, but I don't think they're realistic. And them saying that Mythos is a magic bullet and it's going to create all this opportunity, and we've created a consortium of some of the most well-funded and largest data-owning companies in the world, right, to decide what to do with this magic bullet.
Mm-hmm. I don't love that. I feel like the sort of- I totally agree ...
it's too dangerous for public. I feel like it's hand-wavy versus prescriptive, and so I'm waiting to see sort of what else rolls out of this. There are a lot of trade organizations and large companies that create these coalitions for their purposes, right?
And they tell us one thing, but behind the scenes, generally, they're also working on other things, and those other things typically revolve around making more money, right? As public companies, as companies that are generating revenue, that's generally what they're looking at at the baseline. So what does that really mean on a sort of consumer level, on a business level, when we're not a Microsoft or an OpenAI or something else that count?
I think you're spot on, and I think Kate can add to this, but it does feel like a whole lot of grandstanding. Kate, how long before the open source community reverse engineers what's in Mythos? What, three months?
Isn't that funny? I was just about to bring up the CD foundation, yeah, and ask everybody to come join and help us with the AI situation. One of the things that I keep telling people, other than who let the dogs out and not being on the leash, the dogs on the leash.
If we don't start to take control, if we as individuals don't start to own what AI and what models mean, and what I am talking about when I talk about this is that AI is governed by words, it's governed by rules. It's governed by what it can and can't do. And it's so typical of our community to just let the dogs out, just without the leash.
If we don't start understanding that we have to come to the dog park, and some dogs are bad and we have to muzzle them, and other dogs are, we got to put the leash on so that they don't hurt... Well, I use the idea about running into the street and everybody dying. But anyway, because they're chasing after the dog, hit by the car, blah, blah, blah.
Very bleak. Gen X, what can I tell you? But what is so important that we continue to forget about is canons, and writing canons down.
And that's what I'm pushing for the CD foundation, and what I'm pushing for open source. That's where I believe we need to start is- I like this idea. So you're kind of saying that there should be a $300 fine for dropping vulnerability poop on my lawn, right?
If you're not picking up after your own dog, yes. Absolutely. Wow.
Yeah. I think this is also a shift left strategy with Microsoft, right? Mm.
Because with all due respect, I know we're debating the effectivity of Mythos, but Mythos has demonstrated the ability to identify a large number of critical vulnerabilities, right, in complex systems. " And the whole KPI is moving from a time to remediation, not detection accuracy, right? So that's- Yeah ...
I think that's the sort of the interesting point that I see in this strategy- It is ... Microsoft and Mythos getting together. Go ahead.
We always think shift left is the answer, right? And again, what I keep coming to the table with from a cybersecurity perspective is that nothing's working. It didn't work prior, and it's still not going to work with AI.
We need to rethink about how we deal with cybersecurity. And for me, it begins with really documenting, documenting, documenting. And, because there's no magic bullet.
" Because it's going to discover vulnerabilities at the same time it's going to open the vulnerabilities, which means the offense and defense almost becomes like... Yeah. It doesn't math.
It doesn't work. It's all going to end. I think- But I think one of the- I'm not as worried.
Go ahead. Go, Anne. Yeah.
When I read this one, all I could think was, if ifs and buts were candy and nuts, we'd all have a Merry Christmas. Yeah. There you go.
I love it. Because saying what could be and what might be is not going to change reality. I know.
And it's like they're saying, like... To me, it's like technical debt. Like they're trying to reduce their technical debt for future hacking.
I don't know. Yeah. No, totally.
To me, it just seems very pie in the sky. " But I think- Yeah ... there's one, again, I'm going to go back to the point I made earlier about agents, right?
I just read a story yesterday that a Claude-powered AI coding agent deleted the entire company's database. The company's name is Pocket something, Pocket OS, right? Mm-hmm.
Mm-hmm. Lost their entire database that was in their environment, right? And it was- Stay tuned.
We'll be coming back to that next week, or this week. It was a coding agent, right? It was an agent.
So back to... I think the shift left becomes important because coding is not being done by humans anymore, they're being done by these agents running berserk, right? And this is a prime example of how coding agents can be extremely dangerous.
So- Yeah. And so to Anne's point, right, we've gone from AI coding tools are introducing more vulnerabilities than ever and we can't cope with it, to now AI is going to save us from ourselves and eliminate all vulnerabilities before we deploy anything. And these are two extremes of the same pole.
Is that going to happen? Probably not, but I think there's going to be a greater shift towards not just letting vulnerabilities go because we all just decided that we can't figure out how to deal with it all, so we just ignore it. " Yeah.
And we're going to just have to dump it. We're not even going to be able to have the time to actually review it. So bad code gets dumped, that's a good thing.
And code will get better, not because of, again, the magic bullet. It needs work. Everything needs work.
At the end of the day. It's about scale, right, at this point. We need tools that can match the scale at which AI is developing.
We as humans cannot keep up with that. We can't even keep up with our own scale, right? Given that we're diagnosing things that have been there for 20 years.
So the reality is you have to be able to effectively match scale. And I do think that that is progress. That is a benefit.
And the idea of moving toward preventative posture versus putting out fires is a great idea. And again, time will tell what the execution really truly looks like. Right now, it definitely feels like a little bit of a magic trick.
Look over here, not over here. I think 2027 is going to be the great code dump, right? That's going to be the year when we- Yes ...
just go. What do you say? Mark my words, Mike.
All right. Are we going to Marie Kondo? Third prediction.
We're going to Marie Kondo it all? Yeah. All right.
I think we've... Wow, we've run a little over. That was good, though.
It's a sign of a good conversation. Yeah. Hey, everyone.
Thank you for joining us on this panel. Appreciate all your thoughts and insights. We'll be back tomorrow.
God knows what's going to happen between now and then. But plenty of programming for now on Textron TV. For now, I'm John Swartz, speaking on behalf of Mike Bizard.
Mike will be out tomorrow, I believe, Mike? I'm going to spend the day with Salesforce, which is going to- Oh, lucky you ... this is easily adventurous, shall we say.
Oh, yeah. That should be interesting. We should have a field report from that.
Anyway, thanks for watching, and we'll see you tomorrow.