AI Regulation Fight, Women Engineers and Anthropic Security Signals
AI Regulation Anthropic Security Fight Splits Washington
This episode of Techstrong Gang covers the week’s biggest AI regulation and Anthropic security stories. It also includes a segment honoring women engineers. Hosts Alan Shimel and Mike Vizard are joined by Chris Blask, Kate Scarcella and Sid Nag. First, the panel breaks down the escalating AI regulation fight in Congress. Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a 269-page discussion draft on June 4, 2026. It is called the Great American Artificial Intelligence Act. The bill would require large AI developers to undergo semi-annual third-party audits. It would also bar states from enacting new AI development rules for three years.
As a result, the backlash was immediate. The AFL-CIO called the preemption clause “a giveaway to the AI industry.” Meanwhile, the ACLU and Public Citizen also pushed back hard. So did the House Democratic Commission on AI and the Innovation Economy. They argue the federal floor is too weak to replace state consumer protections. In fact, the fight echoes a July 2025 Senate vote. That vote rejected a similar preemption provision 99-1, according to Nextgov’s coverage of the draft framework.
Bezos AI Infrastructure Comments Draw Fire
Next, the conversation shifts to Jeff Bezos. At a VivaTech 2026 panel, he argued for prioritizing “the intelligence that will save us” over caution. However, critics pointed to Amazon’s data center water use as proof the buildout carries real cost. Amazon’s data centers used an estimated 2.5 billion gallons of water in 2025. Additionally, Bezos downplayed AI job-loss fears. Instead, he pointed to his new venture, Prometheus. It is building what he calls an “artificial general engineer.”
Furthermore, the hosts connect this back to the regulation debate. Bezos has separately argued AI should be regulated “at the application level.” He compared blanket AI rules to outlawing knives. That framing is detailed in this Techstrong.it report on the VivaTech comments. Still, the panel questions whether it holds up given the scale of compute large frontier labs now consume.
Celebrating Women Engineers
Then, segment two lands on International Women in Engineering Day, marked June 23. Kate Scarcella and the panel argue the industry cannot afford to keep cutting its talent pool in half. Specifically, the discussion centers on why engineering now sits at the core of civilization. It powers AI, quantum computing and cybersecurity alike. Therefore, representation gaps directly limit how much talent the field can draw on.
Even so, the hosts are candid that progress has stalled. Education efforts to expand who studies engineering exist. Yet they have not translated into enough women entering or staying in technical careers. Ultimately, the panel’s takeaway is direct: the industry needs more women in engineering. It also needs more of every talented mind it can find.
Anthropic Security Signals Escalate
Finally, the last block covers a first-of-its-kind move tied to Anthropic security. On June 12, 2026, a US export-control directive forced Anthropic to act. It suspended global access to its two most capable frontier models. Those models, Fable 5 and Mythos 5, were suspended for all foreign nationals. Because Anthropic had no way to selectively restrict access by nationality, the suspension effectively went global. The directive cited a jailbreak technique that exposed sensitive cybersecurity capabilities.
However, Anthropic disputed the severity of the flaw. The company called the jailbreak narrow and not universal. Meanwhile, OpenAI’s Sam Altman called the government’s response “fear-based marketing.” Overall, the panel frames this as a first for the industry. It is the first time a government has directly restricted model-level access to a commercial frontier AI lab. Chris Blask and Sid Nag argue this precedent will shape how researchers disclose future vulnerabilities.
In short, this week’s AI regulation and Anthropic security stories show an industry under pressure. Watch the full episode of Techstrong Gang on Techstrong TV for the complete conversation with Alan Shimel, Mike Vizard, Chris Blask, Kate Scarcella and Sid Nag.
Transcript
Hey everyone, happy Tuesday and welcome to Techstrong gang. It's Tuesday. I'm actually not going to be on the gang tomorrow as I head to New York City for Platform Con, where I'm doing a panel on the whole Mythos Glasswing, how does it affect platform engineering?
Got some great folks on that panel with me, by the way, including my friend John Willis, so I'm very excited. If you're in New York at Platform Con, stop by and say hello. We'll also be doing videos.
That's all day Thursday. But let's get back to today. We got a great show.
Got a great gang. We got a lot to talk about. Let me introduce you to Sid Nag.
Sid, good to see you. See you, Mark. Our own Kate Scarcella.
Kate, it's nice to have you here. And Chris in a purple scarf today. I don't know if that symbolizes anything, but our own Chris Blask.
And of course, the man in the high castle, Mike Bizard. Welcome, gang. Happy Tuesday.
Actually, happy International Women Engineering Day. Is that the right term for it? IWED, something.
All right. We'll be coming to that in a minute. But first, we're going to talk a little bit about, well, politics, because I know that's everybody's favorite subject.
And as it turns out, it is primary election day in various places around the country, including here in New York, where the 12th district is up for grabs. It is the Midtown of Manhattan, up to pretty much where Harlem begins. And I think somebody tallied it up, and there's already been in the neighborhood of tens of millions of dollars spent on this election.
There's been $50 million or more spent just on primary elections here in New York. And the one in the 12th is interesting because it's all been about AI, and the folks running for this thing are... There's a gamut of them.
I think there's at least eight, maybe more, but it includes a fellow named Alex Boris, who's been running on one issue alone, AI. And basically, OpenAI has been pouring money into this, and so has Anthropic. And there's also folks who just don't like them, and they're pouring money in as well.
But Boris used to work for Palantir, claims he's the only person who has an actual computer science degree, and takes credit for building some anti, or at least guardrails for limiting AI usage in a bill that went through New York state law. But there's other people running for this, including George Conway, who used to be a Republican and was famous for sorting around or challenging Trump. There's Jack Schlossberg, who's part of the Kennedy dynasty.
And then there's McKay Lascher, who is an assistant for Mayor Bloomberg, who happens to live in the district, and he's been backed by Bloomberg's millions, and it's just a little bit crazy. Elsewhere, though, there's been a new super PAC, I guess, has been created. And I don't know what the definition of a super PAC is these days, because this one doesn't seem as big as the ones that are promoting AI, but it's all about backing candidates who are going to put guardrails in place for AI.
And then just to make matters more interesting, this is the same week where, well, I guess Jeff Bezos decided to say that we're just focusing too much of our investments on biology, and we need to focus more of it on AI infrastructure, and he kind of got everybody riled up because basically he was saying it's all about the bots from here. As we kind of look at all this, Sid, what's going on here, and from your perspective, has AI arrived now as a society issue, and are we going to see this more and more, or is this just a one-time kind of thing? Yeah, clearly the focus is shifting from a technology conversation to a impact to humanity and society conversation, right?
And the political rivals are all jumping in, and it's really become a political battleground rather than a technology debate, right? The super PAC that you mentioned, it signals AI regulation is no longer being shaped by just policymakers or researchers, industry standards bodies. It is increasingly becoming a political contest where billions and billions of dollars are being funded in terms of what the future is going to be in terms of economic value.
And I think we're going to see more and more of these sort of candidate endorsements on both sides of the aisle. I don't think it's going to be a Republican versus Democrat conversation because you see, I read that Gavin Newsom has taken a strong stand against AI regulation on the federal government side. He wants more state control.
And then Ron DeSantis on the other end of the spectrum, Florida, made a statement about the ills of AI on his communities, right? So I think the battle is sort of building up on both fronts. It's not one party or the other.
It's not industry versus politics. It's people are forming these camps of opinions. And I think Jeff Bezos' comments also raise a fundamental question about the purpose of AI.
When society begins prioritizing compute power, water, and infrastructure needs over the goodness of humanity, where do humans fit into this equation, right? I think those are the things we need to talk about. Mike?
Go ahead. Sit down. This is going to be a while.
So let me tell you, I think you told half a story here. And Sid, I appreciate your comments. There's several different currents running through this.
Let me address the Jeff Bezos one first and get that out of the way. This is exactly the kind of sludge Why people hate the tech bro billionaires, and why they continue to show a lack of compassion for their fellow humans. I'm sure his ex-wife will put some of his billions to work against him on that, though, and God bless her.
Let's leave that alone. Next, let's talk about this congressional race in the 12th district. If it weren't for the billions being poured in, or millions being poured in by AI, this guy, Alex Boris, who by the way quit Palantir because he had a moral problem with the ethics of Palantir and the tactics of Palantir.
So that's probably worth a couple of points in my book anyway. But we wouldn't even know Alex, who when you have a congressional primary featuring George Conway, who has a national following, and Jack Kennedy's grandson is Schlossberg. It's not just part of the Kennedy dynasty.
This is Jack Kennedy's grandson, Caroline's son. So, no, not-- Yes, Caroline's son, Jack Schlossberg, Kennedy. So those would normally be the front runners, but instead, to show us how AI is warping every, the fabric, the thread of our society, you've got multiple AI PACs.
" And they're backing a lot of candidates across the country with that kind of notion. And then where there's OpenAI, there's always an Anthropic, right? This is frick and frack of the AI world.
And so Anthropic has their own super PAC, which is saying, "Hey, hold on. Let's put on the brakes. We're the good guys.
" They're the people I believe behind Alex, and then the OpenAI PAC is the one against him putting money into other candidates. Right. And now there's a third super PAC that actually seems to be for actual regulations versus watered-down regulations and no regulations.
So here we go. I believe none of them. I believe none of them.
But here is the fundamental. When you put all of these together, what do you got? You got a good reason for people to hate AI.
It is just being dragged through the mud, right? With all of these bad things. It's we have to shut it down.
It's too dangerous. It's created an apocalypse here, an apocalypse there. These are like the four horsemen of AI.
And what are regular people supposed to say? You know, Sid, you spoke about Gavin Newsom and Rick DeSantis. I wouldn't believe a word Rick DeSantis says.
Right. If he tells you, if it's dark outside, open your window and take a look. The man knows nothing, and if there was anything there, he wouldn't tell you anyway.
So this is- I agree with you, by the way. Oh. So this is the world we find ourselves in.
The question- The irony is he did go to Harvard, but anyway, we won't go there. No, he didn't go to Harvard. He actually went to Yale on a Navy- Oh, okay.
Well, one of the Ivy Leagues. Whatever. The Ivy bill or whatever.
But that's a whole another story. But so here's the bottom line, though. AI is not going away, right?
And I love all these little, seriously a one-trick pony running for Congress, and his only platform is what he's going to do about AI. There's a lot of other ails in this world that we need fixing, right? And I wish maybe AI will help us fix some of those things, but we as humans need to focus in on them as well.
And I think this is just doing damage unnecessarily. I agree with you. I think commentary by Bezos and other folks in a mode of irrational exuberance does not help, right?
I mean, I read recently that golf courses consume more water than an AI data center, right? Yeah. And nobody- Especially in Arizona ...
nobody complains about golf course, has not been complaining. I think it's just the way some of these oligarchs, yeah, I hate that term, but I'm using it anyway, position and make reckless comments, and that really drives people in the wrong direction and gets them all spun up, right? I mean, yeah- Mm-hmm.
At the end of the day, it's about how you position it, how you message it, and how you show the value in spite of all the other energy consumption, glut kind of things that AI has a need for. I think if these guys don't make these reckless comments, things will be much better overall. Yeah.
Chris? I'm going to try to make one part or one segment not entirely about AI and tell you a story. So in 2008, this is about politics, right?
So it's about centralized control over distributed. In 2008, the Democratic National Committee had already elected Hillary Clinton, right? She's going to win the primaries, and she's going to be-- And probably any political observer like me, it was that cycle.
That was inevitable. Barack Obama pops out of nowhere, right? And he has this website that anybody can go to and start up things and get involved directly.
com website you could register on, and maybe someday, some paid staffer might get back to you. Centralized control, right? And obviously, we all know how history played out.
And as you know, Alan, I had the privilege of running the rapid response team for the Obama camp, and 40,000 people made individual distributed conversations with journalists and so forth and had arguments to get them to influence the media by convincing someone something was true and having them publish that And then in the general election, of course, there was Steve Bannon and the disinformation. So centralized disinformation astroturfing. And we know how that worked out.
So we're in this spot again where we have centralized power, we have Jeff Bezos, we're going to have, politically and economically and across business, we have this massive centralization. And as you're all saying, everyone hates it unless you are the one with the billion dollars, and it's playing itself out in the social world. So it's not about AI, it's about this massive centralization.
Can that work? And generally speaking, it's working now. They've got the power of the money, but these are brittle systems and they can be brought down by rogue waves like the Obama campaign in 2008.
No one saw that coming. All the power was in the hands of the central, and they lost. Mm-hmm.
So Kate, do you think though, regardless of the merits of the arguments on either side, it does feel like maybe people are just going to vote one way or the other, maybe even just to send the oligarchs a message, regardless of whether or not the water issue is for real or whatever else is going on, just because, well, the oligarchs, man, are just stupid. So I don't know what's happened where all of a sudden I'm agreeing with all of you lately. All of you.
But I would say absolutely. I think people are tired. I think they're tired of the same old thing, even though they keep-- It appears like different choices.
The same thing is just not working out. Things are just not working, and I think so many people understand things are just not working. " Yeah.
Yes. Yeah. I think the bigger story, quite frankly, in New York City politics in the primary is the mayor's slate of, I think it's three people who are Democratic socialists- Right ...
running against some incumbents and stuff, and we'll see how that plays out. Oddly enough, the one district where the mayor has not endorsed a candidate is in- The 12th ... the 12th race.
So go figure. Yeah. There's one other aspect to this conversation, which is the competition with China, right?
" Right? So we're seeing that sort of spin up in the minds of people, especially at the federal level, and I think even a guy like Gavin would be worried about how the GDP of California gets impacted in terms of competing with the AI growth in China. So I think that's another interesting fact that- Right.
I love those arguments. We should abandon all our principles for fear of competing with a totalitarian society. Yeah, that- Well, we've done it before ...
doesn't sit well with me. Mike, we've done it before. Yeah.
It's not new to the US system. So on that note, Satya, Mike, here's something to watch. You know what the new code is for Chinese AI?
The open source models. Mm-hmm. Yeah.
Whenever you hear them saying, "Well, we can't worry, we can't stop Methos because the open source models will be able to do it in six months," what they're really saying is the Chinese will be able to do it in six months. Because that- Right ... it's DeepSeek and there's a bunch of open source models.
So that's the new truth speak for when we talk about Chinese AI. We'll come back to that later, but I would also point out, it's open source. It means anybody can use it, so it's not just the Chinese.
Yeah, but you know what? Anyone could use it, but how many people actually contribute code to the official- Version ... the official version of it?
And I've been in open source long enough to know, yeah, it's free as in freedom and free as in beer, my friend. But if you think it's totally free, have another beer. Let's move on, though.
We do have another segment to hit today. All right. So you mentioned earlier at the top of the show, I believe it is International Women's Engineering Day, and this to me strikes me as well, it's a good thing, but I continue to be sad about the fact that we have to call these days out.
So, Kate, are we making any progress here? And if so, why? And if not, why not?
So first I'm going to say I believe that we're making progress, and we are making progress, actually, because of allies. And allies such as all of you who are sitting today on this show. I appreciate how you champion women, so thank you for that.
And, so Alan actually wrote a great article, and I found it fascinating the way that he decoupled DEI from the rest of the discussion of what is being talked about today. So first, if I can just review it quickly, and Alan, since you're here, you can tell me whether I got this right or not. But first, talking about DEI in the political debate and women in engineering, whether someone supports it or opposes it, and the DEI policies in arguing engineering faces a simple workforce problem, which I think is an important thing to bring up because we continue to think that the challenge is that we are afraid of having women when actually the challenge is just this enormous gap that we are having, and that we need more talented engineers.
And secondly, he argued, is that engineering has become central to civilization. That AI, quantum computing, cybersecurity, semiconductors, engineering, healthcare, there's no longer this niche technical domains, but that in itself, that's shaping society. And then the third point that he made was that the article becomes strongest for me, is that diversity matters.
It's not because we ask different questions, and then he brings up Brinkman's point, that breakthroughs often come from someone asking what nobody else thought to ask. And I thought that that truly was brilliant. So not only is it women and Women in Engineering Day, but as a woman who's gay, it's actually happy Pride Month, everyone.
So, I can tell you, I appreciate the out-- We need allies, and so thank you to all of you. So, there you go. You make me want to cry.
So did I get that right? I'm not crying, and you're crying. But let me...
Kate, I appreciate it, really, from the bottom of my heart. Let me say a couple of things. I didn't want to make the article about DEI, right?
But I felt not mentioning DEI, or the lack of DEI, or the assault on DEI that we're going through right now, was ignoring the elephant in the room. Yeah. And you can't ignore an elephant in the room.
And so I tried to keep it in the corner, so to speak. But we should acknowledge that at a time when we need this talent, when we need more voices, when we need more brains, we are going backwards in allowing communities fair representation in these important fields. And that needs to be said out loud.
But look, you want to say it's a quota system or whatever, fine. Here's the other way of looking at it. When we need every able body on deck- Yeah ...
you got to remember, you can't disqualify slightly more than half of the population. Right? 3% of this, or whatever the number is, is women, and only, what is it, 15%, 18% representation in the job market there.
Something doesn't add up. We're leaving a lot on the table. We're cutting our talent pool by half, number one.
Yeah. Number two, Kate, I think the point you make is dead on, and Chris, I know you agree with it, and Sid does. I don't know if Mike does, too.
But it's that diversity of opinions, diversity of ideas, diversity of how we come to our seat at the table, that frame our views of things, that allow us to look for the unexpected, to go where maybe someone else wouldn't go, to look at it differently and find a solution that may have been sitting there in open plain sight, but we didn't see it because of our own biases or our own baggage that we bring to it. We need as many different views of these things as we can because, as you said, Kate, look, there's AI, there's nuclear fusion, there's quantum, there's bio-engineering. There's so many great things just within our grasp, on the cusp- Yeah ...
of our grasp. That this is not a time to fall into an old boys network, which is unfortunately what our, in a lot of ways and a lot of times, what our government looks like today. An old boys network of all the same color.
I'm concerned about this, though. We were making some strides on the education front, where we were addressing the fact that we just don't have enough girls in math classes, and we don't have some fundamentals, and a lot of the girls wind up leaving those classes because it just winds up being an all-boys club. And I feel like we're taking a giant step back from those programs, and that's going to haunt us for the next two decades because we're not going to have the diversity of the opinions.
And to me, that's going to be the great sin. A lot of these situations that exist today, we don't have enough women talent. That's pure and simple.
There just aren't enough numbers, and that's our fault. But the efforts that we tried to make to mitigate that for the long term, we're just shooting our toes off again, and we're going to have this issue for far too long, I'm afraid. Is it our toes or another body part?
But go ahead, Chris. As I keep coming back to the competitive nature of this. Again, I'm an American.
I'd like the US to do as well as possible. However, there's other countries that'll do things differently. So inasmuch as we make bad choices, we may learn from lessons, but you can only think in the world you're thinking of.
And Kate, you touched on this exactly right, and Alan, you as well. It's not about right or wrong or ethics. It is.
I have my own opinions on that, but let's just be evolutionary about this. I can only generate ideas from the set of thoughts I have in my head or in my team. And when you specifically, intentionally limit your generative set, only white males are worth with a certain background, you're limiting the number of things you can come up with, right?
We know this because it's not just about gender, but it is about gender. We're different people. We're different creatures.
We come from different places. And Any team has to have... We're a small company these days.
Just coming up on our first anniversary, there's only so many people. They're different people from different places with different viewpoints. I'm very smart, but I will run into a wall at 100 miles an hour in five seconds, and we got that up and down the tech stack, across industry.
Too much monoculture, too much risk. Very successful in narrow ways, and the failure states you can see from 1,000 miles away. Bring diverse viewpoints or you will never get a resilient output.
You'll get predictable, linear output in a dynamic world that will make you pay for it. So- I think I- Can I- I- Sorry, Sid. No, go ahead, please.
I just want to make a quick point. I think this is a massive assault on our society in many ways, right? We see the assault on education.
We see the assault on Ivy League universities. We see the assault on minorities. We see the assault on DEI programs.
We see the assault on women in military, right? We see the assault on multi fronts, right? And it's really something we should be concerned of the society.
Not just concerned, we're really worried. Because when you think about engineering, right, the challenge is no longer simply producing more engineers, but ensuring that the best minds are encouraged to pursue engineering careers. And things like STEM matter, right?
Things like involvement of different members of a society, regardless of gender or persuasion in terms of their DEI preferences matter, right? And as Mike said, we should be really looking, Kate said this too, bringing the best minds in pursuit of a strategic national program that includes AI, right? So if you want to compete with China, as we talked about earlier in the segment, all of these things matter.
So the more of the assault keeps happening, I think we're actually doing our country as a disservice, and I'll leave it at that. Oh, no doubt about it. No doubt.
And- And, Mike, I just want to say one other thing. Kate, you hit on something. It is Pride Month.
It's not just women who are being discriminated against and left out and pushed aside. It just happens to be that women are the only majority minority, right? That's the craziness of it.
It's the majority- Yeah ... of our population, but we still treat them as a minority like that. But it is based on color, it is based on race, on religion, based on sexual preference.
We are excluding people in this country. We're excluding them and unfortunately, our Department of Defense, he could call it whatever the hell he wants, right? But our Department of Defense is the greatest example of it, where they're taking people's pictures off the wall- Yeah ...
who did great things, and they're being taken down because of what they look like or what sex they are or what have you. Right? This isn't American.
This is not who we are. Mm-hmm. And I think we'll look back at it as a time of insanity, but the question is going to be what price do we pay?
Right. And oddly enough, if you look at countries around the world, regardless of what they're totalitarian or not, it's our friends in Europe, India, wherever, they are pressing everybody who has any talent into service. They are just- Of course ...
grabbing everybody and anybody and rowing as hard as they can. " And I think one of the things that's frustrating for me is all the history that we have of, let's just say women, like Elizabeth Smith Friedman, who did the whole Bacon cipher during World War II. Grace Hopper.
We have such remarkable examples of women who have changed the way that we look at computers today, the way that we look at ciphers today, the way that we look at this technology field. So I just don't understand the why. And I think one of the most important things in your article, Alan, is about asking the questions.
Like the question that comes from me is going to be different than the question that comes from each of us on this panel. And we all are coming from even the unique perspective of where we're actually living at. How many people are in our family, and everything else.
It's the questions that are going to help us to shape what's to come. Because this is new, and it's so exciting about all the different possibilities that we have in front of us, that there's sort of like this bummer moment, like, "Oh, man. Really?
" So, Kate, I will tell you, I know the why. I think we all know the why. Maybe you don't want to admit it.
Small people feel threatened. They feel threatened by change, by potentially losing their power, right? This is the why.
There's no doubt this is the why. They're threatened. AI threatens them at some level.
They want to control it for them and those like them. They're threatened by anything that can push them out of power. And if people look different, act different, feel different, that's a threat to them.
And that, when you boil it down, that's what this is all about. Right? Did I ever tell you the story of Dr.
Henry Palucci? No, I can't wait. So when I was a senior in St.
John's of political science, government, politics major, one of my last classes we had to write a big paper. My professor was Dr. Henry Palucci, brilliant man.
He ran for senator in New York State 1964 on the Conservative Party ticket, because after all, it's St. John's. He ran against some guy no one ever heard of, Robert Kennedy, and he got swamped.
And it destroyed this man's life. All he ever talked about for the rest of his life was how he should've beat Kennedy. He didn't have a snowball's chance in hell of beating Kennedy.
But the one thing I learned from Dr. Henry Palucci is that all of history, human history, can be boiled down to haves and have-nots. And the haves will never let the have-nots have, because that makes them have-nots.
They always set up their own inner fortress of the haves, and everyone outside is the have-nots. Now, the have-nots always want to be the haves, but the haves will never let the have-nots in willingly. It's just against human nature.
And so- There's a lot of always and nevers in there, but yeah, that is certainly a pattern we repeated a lot. Yes. Yes.
It's- It's against human nature. I'm feeling good about not applying to St. John's, that's all I know.
There were other good teachers there. But anyway, hey, we got to jump. But let me just end it out.
I think it is called International Women in Engineering Day is what it is. And we need more women in engineering. We need more of everyone, smart people in engineering.
Mike, what do we got on the third section? Apparently, we need more than one day a year, too, I think. Yes.
So let's shift a gear here, because this one has got my... I got whiplash from this one. So that's the only way to explain it.
But, so it starts out with the Five Eyes Alliance people put out a warning saying that, yes, these AI models in the months ahead are going to start destroying our infrastructure because there'll be too many vulnerabilities discovered and bad things are about to happen. This kind of lays up with what was going on with Anthropic and the US government. There's reports that said the US government was running tests using the Anthropic models, and basically the entire legacy infrastructure has just been rife with vulnerabilities that could be exposed and will take them a long time to fix.
But it gets better. The president then decided that, well, Anthropic isn't really an enemy of the state, and we just got to have a little conversation here, and all will be better soon. And maybe he didn't read the memo, which probably is the case.
But Chris, as you look at all this stuff, what's going on here? Can you make any sense of this thing? I can make a lot of sense of it.
And so yesterday, I had a long conversation with Bob Martin at MITRE. Alan, you had to know this guy. I know Bob.
A long time, sure. Right. Now I've got to look in the boxes.
I'm pretty sure I still have one of those orange foam core CVE signs. Mm-hmm. If you were at a cybersecurity conference in the '90s and the early 2000s, and you're a vendor, Bob will come by your booth, make sure you get a CVE sign.
And put it on your booth, yeah. And we were just talking through this, so the MITRE attack, KPEC, and all these other structures we put together. This is exactly back to Kate, what you brought up in the last segment.
We have these ideas. To be clear, CVE, the Common Vulnerability Expression- Exposure. And the exposure ...
or whatever the initial. Yeah. That is an idea that Bob and some people had many years ago.
He's coming up on 44 years at MITRE. I had to check. 43 years and 11 months now.
And it's a mechanism for help people thinking about things. It's not physics. It's not how things work.
And as we build all these structures, all of our careers around cybersecurity, for example, around sets of acronyms like CVE and CIA and so forth, and we teach them at SANS, another acronym, Steven and all like that, thank you very much. And we think they're gospel. And it's not how anything works.
It was never how anything works. The people who came up with all these acronyms, and myself in my own little small way, I apologize. We didn't mean to fool you.
But these are not physics. No, the CVE system was built for a world where humans deal with vulnerabilities in human time. Those days are gone, as everyone knows, and as we beat to death, you guys five days a week, me once a week on this show.
So what's next? Is it fix CVE? No.
CVE was not the answer in the first bloody place. It's a way to think through how we address the issue of vulnerabilities in a global network at a point in time a couple decades ago. That's kind of run its course.
So the vulnerabilities are out there. We haven't patched them. Everybody knows where they are.
What are you going to do? That's a different set of questions, and without the right set of minds, Kate. Thinking about it from different perspectives, we put ourselves back into these little boxes and say, "These are our only choices.
" It's like, no, there are different ways to do things entirely. Yeah. I agree.
And- Go ahead, Kate ... and I just have to say, I love how Mike followed it up with his article about actually proving a point on CVE exposure. Up by 46%.
He basically, in the article, proved what the other two articles were talking about. Yeah. It's growing exponentially, and yet we are dealing with this linearly.
That's an issue. Asymmetrical. It's asymmetrical.
It doesn't work. I have about five or six different articles in various- ... phases of being finished on my machine.
One of them, though, deals dead on to this. Here's the deal. I've been in the vulnerability management space since 2003.
Mitch, Ashley, and I at Still Secure. Our friend Raj, we started our company. Our product was called VAM, Vulnerability Assessment and Management.
Here's newsflash. Chris, you know this. Kayton, you know this.
Sid, you probably know it, too, so does Mike. We never were able to keep up with the amount of vulnerabilities we found. Forget Mythos, forget all that.
Even without it, we didn't keep up with the vulnerabilities. We found more vulnerabilities than we fixed. We were always trying to rob Peter to pay Paul to figure out how can we prioritize which vulnerabilities I could fix first, because I'm not going to get to them all in time.
Now, Mythos comes along and just blows this whole thing up. Right? And the knee-jerk reaction of the white guys in the White House is, "Oh, let's just stop it.
" And the sand comes through their fingers because the harder you press, the more it leaks. Yeah. Don't worry, the open source models are coming, right?
The open source from over there. So this is what we're dealing with. This is the world you're dealing in.
But here's the thing about the world we really live in now. This Fable and Mythos that has caused all of this, it's certainly a better mousetrap than what came before it. But the next one will be better, and the next one will be better, and we have to rapidly come to a decision point where, are we going to say, look, if these things continue to get better, if these models continue to get better, smarter, potentially more destructive as well as constructive, do we have to put a clamp on them and decide, like in Project Glasswing, who's going to get access to the best models?
And for the rest of us, we're going to just have to use models that are good enough, not the best. And deciding who will get the access to the best model versus the good enough model is going to determine the haves and have-nots, back to my have and have-nots, of the world going forward. Because- I don't think I need a great model to hack into a system.
I think good enough is just fine. So I don't think... 5 is pretty damn good at this already.
Well, when we say Mythos, it's the Mythos class, so it's ChatGPT Security. It's whatever the last ones are. But this isn't just about vulnerabilities anymore.
This is now about the capabilities of these models. Do you want to play thermonuclear war? You want to design an atomic bomb?
What these models can empower people to do, we have to decide, do we want to have that readily available to everyone, or do we need to start putting controls in? That's a fundamental question. So I'll bring it all together, all three of our things.
It's what these PACs are arguing about. It's what Dario's been talking about. It's what the Trump administration, at some level, though I don't know if they realize they're talking about it, what they're talking about.
It's what we need to be talking about. We are rapidly approaching an inflection point. It may not be super intelligence and all of that, but it's a point where these things could be too dangerous for us to put in everyone's hands.
Sid, go ahead. I kind of disagree with you a little bit there. I don't think there's going to be a best model.
I think the model business is going to be commoditized. It's going to be like your electric company. Do you worry about, do I have the best electric company when you get the power supply in your house?
You don't. You just have to take that for granted, whatever value or quality it is. I think what you said, on the other hand, is important.
The controls are going to matter, right? So on top of that best model, what are the controls we can build? And in this instance, as we talk about cybersecurity, the question that comes to my mind is when AI can identify and exploit vulnerabilities faster than humans and remediate them- Yes, they can ...
do we still believe that the traditional cybersecurity models are valid? Right? So that's what we should be thinking about.
Secondly, are organizations and enterprises still planning for cyber threats on a human timeline, where attackers are operating on an AI timeline? I think those are the things we need to worry about. The model business is going to be so commoditized that we won't even care about that, and it doesn't have to be the best model.
It has to be good enough, right? Well said. Chris, go ahead.
Yeah. So Neal Stephenson's "Diamond Age," he argues the feed versus the seed, right? Centralized control versus just distributed, right?
And that's really what you're talking about, Alan. And it comes back to your point as well, Sid, because is the control centralized? If so, that's easier to manage.
It's very simple. Only one person, one company, one organization, one government can make the decisions, but it's brittle. Does it survive at speed?
Or is it fully distributed, in which case you get back to those issues you're bringing up, Alan. What if everyone could engineer bio viruses and nuclear weapons at home? Personally, I thought there is no way in the extended future to prevent that state Right.
Every individual out there will, in fact, at some point, I believe, be able to engineer viruses and- God help us ... over long periods of time, decades, hundreds, centuries, thousands of years, we will reach that state, and we'll either cease to exist as a species or not. So I think the resilience is in local control, is in distributed systems.
But the feed is feeding the big centralized control now, that is the world we're living in. It'll either persist or it'll fail. I just think- We'll die or live or die.
Well, no, the system will change. No, look, the planet will go on, but these big systems can go away. Well, we may not.
Mike, then I'll give you the last word. So more to the nearer term, we've debated this, right? Kate said multiple times over on this show, it's time to throw out the bad code, AKA throw the bums out.
Or are we going to wait for these AI tools to come and fix all these wonderful vulnerabilities for us at machine speed, and is that feasible, and which path are we hoping for here? And I think one of the most important things is that we are actually starting to ask the right questions, which goes back to Alan's article about asking the right questions. And we need everyone in the room to ask these questions.
Especially, we need to look at history. History does repeat itself. So what is history telling us as we sit in one of the most exciting times ever?
So glad to be a part of this time period, but really, it's about the questions. Guys, I've got to pull the plug, but you know what? I love debating these trivial, non-important issues like this while the rest of the world goes on.
Actually, I find it cathartic to be able to come on here with smart people and talk about these big issues, big things that we all face. I hope you've enjoyed listening to us. We welcome your comments.
tv, on our Techstrong OTT app, on just about any screen you like to watch this stuff on, or on our YouTube channel. Our Techstrong TV YouTube channel's a great place to catch this and all of our Techstrong video content. But until tomorrow, actually, I won't be here tomorrow, but Mike will be driving the bus, not solo.
He'll have a few people on the bus with him, will be on for Techstrong gang tomorrow. Until then, though, this is Alan Schimmel, everyone. Have a great day.