Economists Warn AI Could Outpace the Industrial Revolution
More than 200 economists and AI researchers have issued an AI economic upheaval warning. Specifically, they say AI could outpace the Industrial Revolution in speed and scale. As a result, the letter urges immediate, coordinated policy action, according to Techstrong.ai. This marks a notable shift, because mainstream economists have historically doubted Silicon Valley’s predictions of fast, widespread automation.
Nobel laureates warn of AI economic upheaval
The letter is titled “We Must Act Now: A Statement on AI’s Transformation of the Economy.” Anton Korinek organized it. He is an economics professor at the University of Virginia and an Anthropic researcher. Erik Brynjolfsson, director of the Stanford Digital Economy Lab, co-organized the effort. Signatories include MIT Nobel laureates Daron Acemoglu and Simon Johnson, OpenAI CFO Sarah Friar, Google DeepMind Chief Scientist Jeff Dean, Anthropic co-founder Jack Clark, former Google CEO Eric Schmidt, and venture capitalist Vinod Khosla. Fifteen Nobel laureates in economics signed in total.
“Steam, electricity, and computers each gave societies decades to adapt. AI may give us only a few years,” Korinek said. “We cannot improvise our strategy and institutions in the middle of the transformation.” Brynjolfsson wants AI to complement workers, not replace them. He says its benefits should reach the many, not just the few.
Therefore, the letter urges policymakers to fund economic research now. It also calls for defensive frameworks to manage job displacement while capturing AI’s benefits. In short, the signatories say coordinated global policy planning must start before disruption hits, not after.
New benchmark shows AI’s terrorism risk
Separately, Tech Against Terrorism’s new CT-AI Benchmark shows AI economic upheaval isn’t the only risk on the table this week, since leading AI models can still hand attackers usable operational help despite existing safety guardrails. For this study, researchers tested 27 frontier models with nearly 2,500 single-shot prompts. As a result, roughly a third of responses gave a would-be attacker meaningful uplift beyond a normal web search.
Full refusals made up 57% of responses. Another 15% were “hedged compliance” — a refusal up front, followed by harmful content anyway. Two open models had their safety training stripped out through a process called abliteration. They complied with 89% and 100% of requests. Researchers note these models cannot be recalled once released. Simply reframing a request as “research” raised compliance from 17% to 42%, with no change to the technical content.
Tech Against Terrorism’s incident tracker already documents more than 30 public cases of AI acting as an operational assistant in terrorism or mass violence. Those cases link to more than 70 deaths across at least 11 different AI tools.
Microsoft shrinks the Windows patch window
Meanwhile, ahead of this month’s Patch Tuesday, Microsoft told enterprises not to delay Windows security updates past three days, according to The Register. In June 2026 alone, Microsoft found 206 security vulnerabilities in its products. According to the company, that number keeps climbing as AI speeds up both vulnerability discovery and exploit development. In other words, this is the same AI economic upheaval story playing out in security: institutional response windows are shrinking everywhere.
Help Net Security reports more detail on the shrinking timeline. Microsoft now recommends update deferral periods under three days. Those windows used to run for weeks.
Watch the full episode of Techstrong Gang for the panel’s take on this week’s AI economic upheaval warning. The hosts break down what these three stories mean for enterprise AI policy, security operations, and the pace of institutional adaptation.
Transcript
Hey everyone, happy Tuesday. Tuesday. Man, Monday was yesterday, so that would make today Tuesday, yeah?
That's how it goes. We haven't changed that yet. But we might be staying in daylight savings time all year round now they're talking about it.
It's supposedly ready to pass. Mike's shaking his head no, but it might happen, Mike. It might happen.
But anyway, we're back here. It's Tuesday, it's Techstrong Gang, and we've got a lot to talk about as usual. We've got some interesting, and for those who have never watched Techstrong Gang before, every gang, we do three segments.
Each segment's about 15 minutes, sometimes a little less, sometimes a little more. So we've got three great segments to discuss today, and we've got a great lineup of Techstrong Gang members to discuss it with. Let me introduce you to them real quick.
We've got my friend Sid Nag. Sid, good to see you. You too.
The one and only Kate Scarcella. Kate, happy to have you back. Relatively new to our gang, I don't think he's been on with me before, Ashraf El Hajj.
Ashraf, welcome. We're going to get you to say hello and tell people a little bit about you in just a moment, but let me finish up here. We've got my true north, Chris Blask, and the man in the blue light, Mike Bizant.
Better than a red light, I guess. I don't know. I don't know.
Blue light, red light district, neither one sounds good, so. No, no. But Ashraf, why don't you quickly tell people a little bit about yourself?
Yeah. I am Ashraf El Hajj. I'm the CTO at Blackwire and I am in Riyadh right now.
Very cool. I'm originally Yemeni, but living in Riyadh and working with a company in Canada, so interesting. Yeah.
It's a small world. Yeah. It's a small world after all, as they say, right?
Yeah. Well, welcome and thanks for joining us. We appreciate, and it's always good to have that international flavor, too.
So, good for you. Mike, we've got to talk about today. Today's Tuesday, so there must be an AI economic Armageddon somewhere.
Well- What's this particular Armageddon about? " Now, there's 200 of them who are now coming together, and the bulk of which are economists who are saying, "Yeah, this is becoming a much more serious issue," including 15 folks with Nobel laureates in economics. " What do you think, Sid?
Yeah, I don't know. I don't know if this is being driven by whether AGI going to happen or not happen. Maybe that's the underlying fear or excitement.
But on a serious note, I think the significance of the statement by these 200 individuals is very unique. It's an unusual coalition of economists, Nobel laureates, AI researchers, technology executives, all coming together and raising a common concern where AI is not just going to be a productivity tool, but how is that going to impact and reshape things like labor markets, capital formation, economic growth that could exceed what we saw during the Industrial Revolution at a pace much, much faster than that. And we're talking about years, not decades, right?
So I think that's going to fundamentally change how enterprises, governments, investors, and other folks, humans in general, humanity, think about all of this. And I think it's really a wake-up call for all of us, right? In terms of how we should prepare for AI-driven business models.
Not just workforce disruption, not just the fact that AI is going to replace humans, but how is AI going to reshape our day-to-day lives, and how should humanity prepare for it? I think that's the real message here, right? There is a worry, but I think the worry is justified, and I think the worry is really being driven by the fact that it's going to happen sooner than we thought.
And whether that's going to manifest itself in form of AGI or something else, I don't know. But, I think that's really what's driving the message of the statement by this unique coalition. All right.
Alan, this seems to be a memo that's written to our politicians and lawmakers, and I just wonder if they get it, if they understand it, or they're just too preoccupied with whatever- Why of course they do. Why of course they do. There must be some PAC involved here or something.
Someone giving them money somewhere. But let me give you my take on this one. I appreciate this coalition of the willing.
Oh, no, someone already took that name, didn't they? I appreciate this coalition of people who came on and signed on here for this. And there are, Sid, you're right, there's some real names on here.
I don't know if they're doing this based upon the assumption that superintelligence gets real. That AGI gets reached. But what I do know is that for every one of these Armageddon kind of predictions, prophecies, I read two other articles about buyer's remorse From executives who went out and laid people off because they thought AI would do these jobs, and then they got to go rehire the people who now want more money.
Now, I don't know if they want more money, but they should get more money. But now have to go out and refill those positions. I think, and if you read some of the quotes from some of the folks who signed on this, their thing is AI has happened so fast we haven't had a chance to accommodate it, to assimilate it, to get to it.
And we're not. We're not. I'm hearing an echo.
I'm sorry. And so they try to compare it to the steam engines and electricity and locomotives and all that. Yeah, this is different.
It is happening faster. All these things always happen faster. But at the end of the day, I'm not quite sure it's going to create the disruption Armageddon style that these guys are getting at.
I just don't think so. I don't know. Let's ask Ashraf, if you don't mind me bringing you in here, but from a perspective of overseas, what are folks saying about all this outside of the US?
" Yeah. From the implementation side, my side, I implement more than think about, it's like there is two sides. AI can disrupt work, but it can also bring expert capabilities to communities that could never afford the same expertise for the service before, like in Yemen or yeah.
And the economic by itself, it may not only be between, and some people are going to say, "This is going to steal our job," but in the truth side, it also can remove the distance from expertise. Mm-hmm. And to your point about that, Chris, I'll toss this to you, but is there a different mindset here between, let's say I am a country like the US where I have a lot of labor, and smaller countries where I don't, so we're having a different economic experience here because, for us in the US, the size of the labor force was always one of the economic advantages this country had.
So, my wedding certificate, me and Donna, 39 years ago, and for some reason in Toronto, you put your job there. She was a word processor, I was a forklift driver, right? And word processors, we know, went away.
That used to be a job for decades and decades, a huge interest group, this huge labor force, and it all went away, turned into software. And right now, we're used to Word and Google Docs. To be clear, I think those will go away.
I think in the next couple of years, the word processor as even a function just disappears. So as we look at all these economic impacts and roles, right? Auditing to me has always stood out.
It's not about AI. At some point, auditing should be automatic. We should know what's going on all the time, not just pull the logs every six months.
I think that's coming along, and auditing is a huge economic slice. A lot of people make a living in auditing. I think that goes away.
If you're an auditor, love you very much, but the next 10 years, I don't think that's a job anymore. Right? And as Ashraf said, we're used to this.
We're the US. We're US, Canada, Europe. We control the-- We have the big vendors.
But with AI, as Ashraf said, if you use it correctly today, much less next year, you can do things that had to be centralized in Silicon Valley or New York or London before. And just to speak to what instigated this, I agree with Sid. I think this is an interesting enunciation by an interesting group of folks who, Alan, like you say, to the politicians and everybody else.
But it's not new. This is a big change coming along, and vested interest, workforce, demographics, nations, countries that have the power now may or may not benefit. We will see.
Personally, I feel like we're not building the economic policies in place to deal with this potential disruption, and we seem to be just saying we're going to go down this path and see what happens one little instance at a time, and then hopefully something comes out of it that's good because we don't want to have-- I don't know, maybe it's too hard to have the policies, or we just think that this is just going to be something that happens to other people. I don't know. Kate, what's your read?
Oh my goodness, who needs policies, right? I feel like policies is something that's always getting put on the back burner, really. And I don't even understand why that is.
As a cybersecurity person, one of the things that when we go into an organization, we look at the policies, right? That's like meantime to discovery and everything else. It's all about policies.
And I feel like people think about policies as like nothing anymore. And with that being said, it is so important because AI actually thrives on policies. It's how we contain AI is going to be through policies.
So, the written word is how AI basically is really going to bloom and go forward and help us. And to Alan's point, I agree. Again, I agree so much with Alan.
I'm reasonable. I think it thrives on more than policies. I think it's institutions, right?
Are our taxation system, are our education system, are the safety nets that we have built over the years, are they ready to change? Is the Social Security Administration ready to change? Is the IRS ready to change?
Is the Department of Education, if it still exists, ready to change with the advent of AI? You can mandate all the policies you want, but if the fundamental institutions are not keeping up with the change, we will not move ahead with AI. No.
There's going to be a huge mismatch, right? Yeah. And our viewership, much less the people on the screen, it's a global world.
And we're using we, I'm a Yankee, but I'm in Canada. And we, the US, will make certain policy decisions right or wrong. I am on the record as being highly critical of the current administration policies.
We don't need to expand that here, but they are what they are. Will that continue to work? Will the existing ladder that added value in the past go into the future, or will other people, other demographics, other nations, make different choices and work out better?
I think policies will develop all over the world, all over the place on this issue. And we're just, as Americans, hoping that our choices are the right ones. We will see.
So let me take a different tact here. I'm going to tell you something we learned in law school that we don't tell people. " You know the so what, right?
You get this in medical malpractice. Unfortunately, this 99-year-old man who has no money, no income, no dependents, was the victim of medical malpractice. Doctor's guilty.
What should the damages be? Zero. Because as callous as it is, it's so what?
You get this face. There's a name for that face. I'm not going to say it on TV today, but you get that face.
What I'm telling you, all this hand-wringing and clutching at pearls about what AI's going to do and what it could do, and what it might do, and what it will do, is nonsense. There's nothing we can do to stop it. " We didn't have a Social Security Administration when the Industrial Revolution came about.
We didn't have laws around online usage when the fiber optic system came in. We didn't have laws around the telephone systems when the 800 number and dial for dollars and sex and so forth came out. We, as a society, as a civilization, as a humanity, tend to be reactive to these things.
Thinking that we're going to do something preemptively is like saying that jaguar doesn't have spots, or that tiger doesn't have stripes. It doesn't work like that, my friends. This is going to happen, and then we're going to react.
We may need to reinvent the Social Security Administration or the IRS or any, I don't care, that's US government, any of the governments, any of our policies, any of our work norms. But it's going to happen because humanity has never gone slow because they were afraid of the consequences. Right.
And I'll just tell you, again, as a cybersecurity person who walks into the Fortune 50, as I was with IBM, the policies were not concrete and solid. Everything was very fluid, and yet everything progressed. To your point, Alan.
Things went along, and I absolutely, again, agree with you, Alan. Wait. Kate, we- Wait ...
I think you should talk to my wife, Kate . I'm going to disagree. Go ahead.
I'm going to say flat out that if we and our leaders know that this thing is coming, and we don't make some sort of effort to be at least proactive about how it's going to impact our citizenry, that is an abdication of the job, and therefore they should all be tossed out on their a*s. Did you not hear of DOGE? What is wrong with you all?
We put our faith- Yeah, Mike, I thought we replaced everybody. No, but you know what, Mike? We could say the same thing about climate change.
We could say the same thing about public health. I think we all agree they should be tossed out on their a*s. Doing it is another problem, and that's not going to address the AI issue here.
This AI thing is happening. I think that's what these guys are essentially saying. No one's denying the fact that it is going to have to change.
But are we preparing for the change? I think it's against human nature to prepare for the change till it's almost too late or on the verge of catastrophic consequences. But I'll tell you what we are going to need to change.
We need to change to the next segment, Mike, because we're over time on this one. What else you got in your bag today? All right.
Well, you have this article that you published about how AI is helping terrorists. And basically, you're pointing out that skills and expertise that they would've needed to acquire in the past that would've prevented them from carrying out certain levels of attacks, but now, there's examples where various terrorist groups now are clearly starting to use AI and researching what they might do with this. And at the end of the day, you got to ask yourselves, are we, coming back to the topic at hand, prepared for a new reality?
And Chris, are we about to wake up one morning and start to see some new and interesting tactics and techniques that no one ever thought of? " This is exactly the statement I was going to put at the end of the last segment, because it is the same stuff. Right?
If you have a shaky system, AI is going to illustrate that to you. What does that mean? Kate, IBM and policies, the loose policies in corporations that honestly work just fine, may not translate to automated language systems where it's actually playing out in real time.
Right? That human beings in, and I guess I'll just pick on IBM, I'm going to illustrate because I've been part of these companies all along. Humans are in there.
" Well, AI doesn't understand. You have to explicitly say every single part of it, and you may find out that what you thought was a coherent corporate structure, or a coherent cybersecurity program, or a coherent anti-terror program wasn't. And just as the same way that if you run infrastructure anywhere in the world, in the US, if you're running a water facility, you should have already assumed that the Chinese, for example, know all of the gaps in every device between what it should be configured and how it is configured.
They know that now, and have. So take AI, accelerate into that gap, whether it's counter-terrorism or pro-terrorism infrastructure or anti-infrastructure, everybody has the same advantages. The gaps are there.
You should be able to see them. We're accelerating into them. So, I am specifically not a military person.
Right? I've worked with nation states and militaries, ours and the allies, all my life. We need to talk to those folks if you want actual referenceable advice on those sort of issues.
But it's just the same as everything else. When you have adversaries on either side, they both have the same opportunities, the same tools right now. Look at how you're doing things.
Does it bloody make sense or not? Okay. The point I wanted to make, and it was a point I made in this article, is especially us, meaning us here on this show and people like us.
Here's to us and those like us. Right. Damn few left.
But the thing is, we think of AI helping cyber terrorists. Cyber terrorists, ransomware, and all the things that we talk about day to day here on The Gang and in Techstrong. But this is a whole different kind of AI help.
This is helping terrorists make bombs. Mm-hmm. This is helping terrorists create bio-weapons.
This is helping terrorists create meaningful strategic military style assaults on assets. Right? This is a different level of AI terrorist enablement.
And again, you don't need the latest Mythos, or Fable, or Soul. You could be using any of the top 12 models. And the guardrails here, and that's the other thing is as you go down the list of those models, the guardrails probably get weaker too, right?
Easier to circumvent. This is a problem. This is a problem.
So when we, in security at least, there were all these tabletop games, and there was red teams and blue teams. And are we running enough of these exercises with AI to think through how terrorists might use all this stuff, and then coming up with the counter-program for that? " You want me to get it?
Well- Yeah. Go ahead, Chris ... every sort of conflict, right, perspective's everything.
Monty Python riffs on this a lot, right? Are you a terrorist? Are you a freedom fighter?
From a conflict professional perspective, I always take this approach. I get involved in a lot of multidisciplinary things where I'm the cyber guy, but I work with the nuke, bio, kinetic folks, and so forth, and it's just the same systems. It's turtles all the way up and down.
We have a conflict situation. Everybody gets the same tools. What does that mean?
Whether we call ourselves the good guys, the bad guys. We're the defenders, they're the attackers. Whether it's cyber or kinetic or nation state, it's all the same stuff.
You can read your Socrates. You can go back through all of human history and look how conflict works out in every form and apply it to this topic. And again, as you say, Alan, people like us who sit on shows like this, particularly now in the world of AI, we say the same things every week.
This is just another use case. Kate? I think if we don't understand we're at a point right now with asymmetric warfare, which includes these models, then we deserve what we get.
We have to think of war asymmetrically. And if we don't change, we're in trouble. And we've said this over and over and over again.
We see it. It's before our very eyes. Who would've thought that Ukraine would be able to really be crushing it, crushing Russia with all the losses of lives, and it's all because of drones and asymmetric warfare.
We have to think of this differently, and if we don't change, we are seriously in trouble. Kate, I agree with you Will you two cut it out? These attacks are going to be more subtle, and to Kate's point about them being asymmetrical, I remember participating in one of those blue team, red team things, and the goal was to force an election one way or the other.
And what they wound up doing was hacking into the local transportation system to make sure that the buses and the trains were not running, so enough people who voted for particular districts didn't get to the polling place in time, so then the other candidate got elected. This is a subtle thing at the end of the day. It's not a bomb per se, but it had the effect.
And I think we're going to see a lot of more subtle attacks like that, rather than something that is obvious as, say, a 9/11 type thing. But it may be harder to track down- Well, I think that is subtle, Mike, and it's sophisticated. It's not what I'm fearing.
I'm fearing blood and guts and gore- Yeah ... and making statements. Yeah, I- Sid.
Go ahead, Sid. I was just going to say that we kind of talked about this the last show. The nature of AI is essentially we democratized.
We talked about China building models by way of distilling frontier models, and people buying them regardless of where they're being built. So I think the onus is not going to be on the vendors. The onus of counterterrorism has to be on the folks that are actually using and deploying AI.
Because terrorists are not a separate community sitting in a particular country or within a certain domain, or they're not moated. They're everywhere. They're pervasive.
They live with us. And they're using the same exact AI that you're using and somebody else is using. So I think it's not about expecting vendors to build technology within their AI models to prevent terrorism.
That's never going to happen. It's how folks are using AI, the enterprises and the communities and the consumers, the you and I that are using AI, build those mechanisms within our utilization deployment models to prevent terrorists from doing what they want to do. I think that's truly what it is all about.
Well, let me see if I can make something topical out of this, because this is really about AI governance. Who's governing and so forth, that's a great question, and who you think they are, basing your perspective. And again, I'm very much on the record, pro Ukraine.
The Russian administration can bite me. And they're getting their posterior whipped because of a couple of things. And the one that matters to this right now is the AI governance thing.
Because I love my Dostoevsky, I love the Russian people and the Russian culture, but the decision-making process inside the Russian state right now is slow and corrupted and stupid and wrong. And Sid, Kate, one of you mentioned, Ukraine has been pushed into the evolutionary state of actually using these things. And to be clear, I have no inside or outside knowledge of this, but my guess is Ukrainian folks have adopted AI without all the fears of those of us in Toronto and New York.
And they're out-thinking Russia faster than they can use, I mean, Russia is not systemically capable of using the AI that they have on their hands as well as the Ukrainians. And that's the kind of delta we're talking about in actual conflict. And I have to end on the point that I will caveat all day long about the military.
It's a different world. However, we're in cybersecurity, critical infrastructure. People at my age, given the things I've done, people have lived or died based on the choices I've made, power grids and various other things.
I may not see them. It's no more or no less our responsibility because it's spectacular and comes with kinetics. No, look, the issue, I keep coming back to this, the genie's out of the bottle.
Yeah. And so everything we do here at this point, it is reactive. Assume terrorists are using AI for these things.
Assume Ukraine is using AI for some of these innovations. Assume what goes on in the Middle East, Iran and Lebanon, Israel, the whole thing there, they're all using AI. Let's not kid ourselves.
This is no longer a lab experiment. That's the point. This is real-world now.
Mike, I'm ready to move on to the next segment, though, before I make myself depressed. Well, there's more joy in the world. " And I guess the unspoken part of this, or at least they alluded to it, but we're not hearing it from other vendors, but I suspect it's true, is that they're using their access to the latest AI models to discover more vulnerabilities that are not being officially disclosed, but being remediated before they're disclosed.
So Kate, is this kind of the new modus operandi for security folks where they're basically going to get in there, fix things, then we're not going to bother putting a CVE number on it because, well, that's just kind of a waste of time and effort? And I know Chris has something to say as well. I saw by his actions.
But I will say that as a person who has, I ran Patch Tuesdays for a certain company within IBM, and I had so many people, and we would go for three days. Three days. Trying to patch up there.
So yeah, this is the new norm, and it's not surprising considering what Mythos put out, that Microsoft is actually coming up and saying this as well. So it has fundamentally changed the vulnerability landscape, and we are definitely on the defensive side of this. And I don't think that we even have time to look at CVEs, and as you know, my theory of just throwing out software that's not working, and that this really has to be seriously taken upon because it's moving at such a speed that we are going to have to more look at the code and just keep going.
Try to put it in and keep going. And I know what we're talking about with industrial control systems, ICS systems, operational technology, and I understand what I am saying, but we are getting our butts kicked. So All right, so let's take that to its natural conclusion, and I'll throw this over to Ashraf.
Is every day now patch Tuesday? Because we're just going to be constantly fixing things as we flow along here, and we're not going to think about this as a let's do this once a week. Hell, let's do this every hour.
Yeah. It's three days patching. It makes sense when exploitation is accelerating, but it assumes reliable connectivity, accurate asset inventory, testing environments, technical stuff, and reliable rollback.
I can assume that if you have that. My real deployment did not have all those conditions, but sometime you need that when you have a very accelerating exploitation. So, from my aspect, being patched that fast is very necessary, and it's also you have another side, the threat actors who are actually working in zero vulnerability in the other side.
Sometimes you never know. You have to accelerate things and travel in time as they are due. Chris, go ahead.
Yeah. I love the CVEs already come up, because Ashraf and I had a call with the legendary Robert E. Martin, Bob Martin, who was- From MITRE ...
right. The orange CVE cards in all of our booths in the '90s and early. So 44 years at MITRE this month.
And we built this structure around vulnerabilities. It's entirely reasonable, it was the right thing to do. But from Bob's mouth to the world's ears, that whole thing was just a metaphor.
Everything we've- Yeah ... done to date is just a way of helping people think through, hey, there are vulnerabilities. We should have processes, we should have systems.
Now we've gotten to this point where, yeah, in this show every week we talked about this for the last 12, 15 months. It's just gotten to the point we're having another article about the fact that vulnerabilities are fast. It's kind of missing the point.
I think what's interesting is the idea, again, I've been the perpetrator. I've been in the big corporation pushing out monolithic updates to millions of devices in the world all the time. What I think we're moving to is that your device will know what kind of updates it feels like taking, and it'll look out into the world and see what kind of updates vendors are putting out there, and decide whether or not to have any of those updates.
So you're talking about a cellphone, an iPhone kind of... That's- Because that's what the iPhone does, that's what the Android does. " So most updates, most vulnerabilities don't apply to most devices.
" Yeah, but no- Instead of doing it product by product ... think about how your apps get updated on your phone. When it first used to happen, I used to look and I'd see no updates without me approving it.
I had to approve every update. Who out here approves their updates on their phone anymore, on your app updates? None of us do.
Ashraf, you do? No. I just want to focus- Oh, okay.
Well, there you go. All right. I just want to add something.
It's just we're focusing about patching, and focusing on the package that we have in our devices, how to just remove this exploitation, how we just enhance the security here and there, but we never thought about why we just make this device behavior better as human beings. Like we focus on behaviors more than we focus on patching our organs. So why we don't do that for these devices instead of trying patchings for three days or one day?
It's going to be more reliable and more accurate. Mm-hmm. Sid.
I would say it- Sid ... I'm baffled that the story never used the A word anywhere. Where is agentic in all of this conversation, right?
Clearly we're not going to be patching every month or every week on a Tuesday or whatever. It's going to be an ongoing life cycle management thingy. Again, like a phone app.
Like the phone app, and it's going to be done automagically. And in the world of AI, who does it best? But- It's agentic.
So where- So let me- ... is the agentic conversation in all of this, right? I'll tell you why, Sid.
I'm going to tell you why I wasn't always on this side of the camera. I co-founded a couple of companies, security companies. One of our companies called Still Secure.
I remember being in New York City at the office of Citicorp. That's before they called it Citi. It was Citicorp.
It was Citibank. Yeah, I was there. I met with one of the three global CIOs of Citi, and we were talking about patching.
And by the way, that's assuming that patching fixes every vulnerability. There's more to remediation than patching, but we'll put that to the side for a second. How long does it take you to do your Microsoft Patch Tuesday patches?
Kate, you said three days. These guys said three months. It was 90 days.
Why the heck would it take you 90 days to put in-- And that is pre-AI. You didn't have 170 frigging patches to do. Why?
Because they had to make sure that every single patch they put in didn't break something else that moved you from the frying pan to the fire. Right? That did something worse than what you were trying to fix.
And that's been an attitude and a problem in security for as long as I've been in security. I saw it with the IDS to the IPS, right? Instead of just detecting intrusions, we can block them.
Nope. Can't block them. Yeah.
That might be the CEO's port he's watching. Right? We can't block that.
Chris, you're laughing. You remember those days. That's- Oh, yeah ...
how it went. Yes, I was. And we have a problem in security with this.
We have a problem that we're afraid the patch is going to be worse, that the patch is going to break something that's worse than it's fixing. And until we get over that, like we seem to have gotten over it in our phone apps, we're going to continue to have this problem. I look forward to the day when no one gives a crap whether it's Microsoft Patch Tuesday or Google Patch Thursday or Apple Patch Friday.
Stuff just gets fixed. Yeah. It gets remediated, it gets updated, and it gets hardened.
So to make that work though, the patches have to be a lot better than they have been historically. Because most of the IT people I know, when they looked at a patch, they were like, "I'm not going to bother spending time testing that. I'm just going to wait and see if there's like 30 people screaming about this patch on the web somewhere, and then I'll not install it.
" But yeah. And I feel like we're having a backward conversation. Just a few weeks ago, we talked about security via shift left in the code, not afterwards.
But Sid, I'm glad you brought that up. That's different. You're talking about pre-deployment code hardening.
And the more we do that, the less we'll have it on this side of the ledger. Right? This is like your power of math, if I've got a plus symbol here and a minus symbol there, and that's in parenthesis, but this isn't.
Right? What we do here affects here. If we make code better pre-deployment, we'll have less vulnerabilities post-deployment.
Agreed. Yeah. But those are two different worlds we live in right now.
One's X. But that's not what happens at the end of the day. So we don't test all the code that's coming through, and then including all this AI stuff, we throw it over the wall, it shows up in a production environment, and then theoretically we go look for this vulnerability, and we create a patch.
But then if the patch breaks, we don't really have a good process for rolling back the patch and writing a new one that is vetted and created. So, Asaf, I'll ask you this, are we kind of our own worst enemies or what? I don't know if he heard.
Yeah, I'll take this on, because this is- Go ahead, Chris ... I'm not trying to give you more than to get off my lawn about this, right? I think we all agree the current approach isn't going forward and we just beat that horse all the time.
I don't see updates and patches. I don't see patches in the future at all. I see protocol updates, protocol sharing.
Right? You see that at every level. And there's an article out yesterday from me, somewhere, on SRAP.
This is a potential protocol in the standards world addressing safety relevance of software that emerged from inception to being integrated in three or four different standards work groups in 14 days, 13 days. And I think it's a perfect example of what we're talking about. The idea, whether it's how do we come up with no standards and protocols in less than three years in the world of AI, to how do we get a known vulnerability or an update to a piece of code out in the world in the world of AI, right?
And we have to think out, a lot of existing structures will not go forward. CVE as a whole concept, I think we should put it in a museum and bring guided tours. It's a beautiful thing.
It's run its bloody course. Software updates and patches, pretty well done. Agreed.
But protocol updates mixed in with everything else, where organizations and devices and nodes out there can make their own decision about whether they want to change their code or not. I totally agree. Instead of me sitting in Silicon Valley telling you to do it.
So let me pull this all together then because we're almost at time here. Kumbaya? No, Chris, what you've described, Sid, what you've talked about, Kate, what you've talked about, and Asaf, not what Mike talks about because he's always contrary.
But the thing that cuts across all of this is that AI is here. It's not just coming, it's here, and it's going to continue to be here and be bigger and faster. And we've got to decide whether we're talking about how we patch our systems, how we prevent Malicious use to make bombs and so forth, right?
Or something worse that's Armageddon-ish. How are we, and when I say we, I mean our governments, our society, but also us individually, our organizations, our companies, and as our individual person, personal sovereignty, personal responsibility, how are we all going to internalize this? How are we all going to regulate this?
How are we all going to live, make lives in this new era, in this new way of doing things? And there's going to be a lot of apple cart upsettings, and there'll be a lot of stuff moved to the museum, as Chris said. And there'll be a lot of throw them out on their a*s governments, as Mike mentioned.
But this is why we talk about it every day. It's a hell of a lot of fun, right, to sit here and kind of document and watch what's going on, but it gets real. Anyway, we're about out of time.
I would just add one little thing to that. Go ahead. In history, every time that we've taken a laissez-faire approach to anything, it has ended badly.
So this is not the time. I could give a plug for my book here, but I'm not. That's a spark I was feeling.
All right. Hey, Techstrong gang, thank you for joining us. Ashra, thank you for joining us.
Thank you. I know we love having you on here. We love having you watch this.
If you want, you can watch this every weekday at noon right here on the Techstrong TV network. tv, YouTube, Techstrong TV YouTube channel. Go check it out, subscribe to it, please.
Our Techstrong OTT app that plays just about on any screen you want to watch this stuff on, or any of our Techstrong media sites, and there's 10 of them or more out there for you to watch out on. We also play Techstrong TV, which is more than the gang. It's three hours, usually around there, of great tech-related video content.
You can check it out there. But until tomorrow, on behalf of the gang, on behalf of Techstrong, I'm Alan Schivel, and we're out.