AI Reshapes Cybersecurity, Agents and Digital Ad Power
Alan Shimel, Mike Vizard, Chris Blask, Kate Scarcella, Sid Nag and Anne Ahola Ward dive into how security professionals are responding to new initiatives from OpenAI and Anthropic to use more advanced AI models to discover software vulnerabilities.
The gang then turns to a research effort aimed at enabling AI agents to train themselves, before breaking down a report suggesting that Meta may soon pass Google in digital advertising revenue.
From AI-driven vulnerability discovery to self-improving agents and a shifting ad power balance, this episode of Techstrong Gang covers three major signals of where the market is heading next.
Transcript
Hey everyone. Happy Tuesday, and welcome to Techstrong Gang. There's certainly a lot to talk about.
I was going to say it's fun times. I don't know if it's fun times for everyone. It's fun times for me, but there is certainly a lot to talk about, especially one of my favorite topics, security.
This Claude Mithos project, Glasswing vulnerability apocalypse, whatever you want to call it, is generating more clutching of the pearls, shrugs, so what's, and everything else than I've seen with my security friends in a long time. I've probably written no less than, I don't know, six different stories on this topic already. Not all of which are published, but they will be in the next day or two.
But there's no lack of coverage in the broader media world. And on Techstrong itself, right? We have a decent amount of security friends and writers here who are putting in their two cents.
So I encourage you all to check out a lot of our coverage. In the show notes will be links to all of the articles, at least on the Techstrong sites that are up right now. There's some more maybe that even aren't in here.
So it's going to be an exciting time talking about that. It's what we're going to lead off. Let me introduce you to our gang for today.
We've got our friend Anne Ahola Warden in. I don't see, is there no holidays coming up? What's going on here?
Sorry to disappoint. There's no mid-April holidays I'm aware of. All right.
We'll have to find you something, one of those made-up holidays or something. Yeah. Maybe Royal Day's the next one.
Okay. We'll be on the lookout. Next, we have Sid Nag.
We have Sid, welcome. Thank you. Joining us, and she's ready to dive into the cyber stuff today.
I can tell she's ready. Kate Scarsella. Joining us also up north, Chris Blask and Mike Vizard, our chief content officer.
Mike, welcome. Everyone, welcome. So Mike, I kind of opened it up, this Glasswing, Mithos, vulnercop, apocalypse, whatever they want to call it.
It's got tails a-wagging. So to your point, just about everybody who's anybody has had something to say about this so far, and I guess we'll add our two cents here as well. But as of last night, there were at least six articles on Security Boulevard alone talking about various impressions of this thing.
And on the one hand, you could argue, well, what's the trouble here? We're going to use AI to finally discover all these vulnerabilities under controlled circumstances, and hopefully we're going to go fix those vulnerabilities before the bad guys find them. So, in theory at least, that sounds like a good thing.
The trouble is, I think that other people will probably be researching the same thing with more malicious intent, and you could probably expect that other open source models might have this capability. Other countries might have this capability soon, so maybe the race is on. So Chris, is this going to be a reckoning?
Hold my coffee. We're talking about in the green room about user interfaces, and I'll take it there, but I'm with Kate on this one. This is just a lot of fun.
But let me call this the Mark Carney approach, right? " And on this topic, in the security world, this has been coming for a while. On this show, every week, we talk about this as it's coming.
Mithos itself is, now we have a name for, and we can hang on it. But just like, Alan, you're saying, you made a website yesterday. And six months, two years ago, that was an effort.
We had to all sit down and think it through. But that's just a surface. We just express a surface of our intent, and that happens to be a website.
And on this, yeah, we've been finding vulnerabilities by hand. It's been amazing efforts globally for people all over the world, working in bug bounty programs. Shout out to Katie Moussouris and everybody, right?
Now we're here. Vulnerabilities? No, you can create as many vulnerabilities as you like.
And that's, Kate, it's too much fun to keep to myself. Yeah. No, absolutely.
It's so funny because when I was reading these articles, I thought to myself, I remember the day when in 2003, we would kick off a vulnerability scan starting Friday night and hoped that the scan finished by Sunday night. And then we would go in once hoping that it was complete. Because if it wasn't complete, you actually had to stop the program.
Stop it. And it ruins everything. So, wow, how this has changed in a big way.
But, and I'll tell you, one of the other problems that we've had with cybersecurity is that we chased false positives. I remember having a team as we chased down during SQL Slammer, and it ended up being like a lunch menu, we spent, we couldn't find at the time, and it was highlighted as a high risk. " So now here we are, and finding vulnerabilities has never been a problem, right?
We've always found vulnerabilities in code for forever. The issue has been, of course, fixing them, and the exploitation that's happening at such a high rateFor me, it's about time. And when I say it's about time, we have known, right, Chris, how long have we talked about that there are issues within code?
And I feel like what this does is just valid. I feel really validated. No wonder I'm in such a good mood today, folks.
I am validated. Well, there you go. That's right.
Usually when I validate, I get a better price on my valet parking. But in this case, we're talking about world survival. I've written a lot about this, I've spoken a lot, I've reached out to my community.
Mitch and I did a nice podcast last week with Rich Mogull from the Cloud Security Alliance, who worked very closely with Gadi and a bunch of other folks that all three of us, I'm sure know very well, including Katie, to put out a response to Mythos, basically, and what we can do, including Glasswing. Here's the thing, at the end of the day, yes, we had a crap load of vulnerabilities that we never get to. It was job security.
I had a company that built one of those scanners, Kate, and we would sell it to people and tell them, "We're fast. It'll complete your whole scan within your window of- Yeah ... " But this is a physics problem.
It's physics. Because the system that you described in 2003, there were laws of gravity and weak electrical force and all of the four basic physics laws that put a governor on the whole system. We could only, in spite of having 20,000, 40,000, I don't care how many thousand coders in the world, we turned out X amount of code a day, a month, a week, a year.
There was a physical limit to how much code we did. And we all knew that a lot of people wrote very sloppy code, and they were full, it was like Swiss cheese in terms of security. And there were probably X to Y amount of vulnerabilities that we could easily find in Z amount of lines of code.
But, we then had the AppSec scanners, people who would search for those vulnerabilities. And man, I remember when fuzzing first came out. I'm sure you guys remember it too, Chris and Kate, and Sid maybe, right?
Fuzzing, all of a sudden, we didn't just run those scans over the weekend like we used to. Now we could fuzz things, make stuff up and see, well, maybe if I move this here, I move that there, maybe it opens up a door, like the secret passage. Because as security people, we love to break things.
We fuzz them, and fuzzing became the rage. But even with fuzzing, we couldn't do it 24/7. There was a limit to how many AppSec researchers there were, how much code actually got scanned, how much pen testing was done, all of that.
The only fuzz I know is on the New Jersey Turnpike. No, that's a different fuzz. Yeah.
And then the next thing was, okay, now I gave you the telephone book. You remember what a telephone book is. I gave you the telephone book full of vulnerabilities.
It's not the security folks' job to patch that. Kick that over to the IT team. You got to go patch this stuff.
And that was their job security. They got a new book right after New Year's. They finished it, or at least got through it, they didn't finish it, around Christmas.
Took Christmas to New Year's off and got another new book in New Year's. And those were the physics- Right ... of vulnerabilities.
And also mitigating controls, right? Right. Well, that would be part of your remediation.
Either I patched or I- Or you put a firewall or something ... or I mitigated, or I closed the port, I put a rule in. I did something.
But I think- That's all gone. Yeah. It's not just remediation, right?
It's remediation capacity, right? Doing- Well, that's what I'm talking about. Yeah.
So remediation capacity is just, again, it was one of the physics, one of the four laws that were governing this whole system. It didn't run great, but that was what the constraints were. Now, we're generating 10x more code.
We're finding 100x, or 10,000x more vulnerabilities automatically by AI. Yeah. Yeah.
Those are flywheels. Remediation cannot keep up with that. No.
Exactly. Yeah. I was going to make a point on that, is detecting vulnerabilities is, we can do that all we want, but if you don't have the engineering capacity and the tools to fix them, I think that's the real challenge, right?
And it's also, we're moving away from the idea that these breaches can be prevented entirely, because it's becoming more of a continuous process, right? So- And resilience ... 100%, right?
Detecting- But you know what? Sid, hear me out. Yeah.
There's another good security friend of mine who I respect an awful lot, a guy named Jeremiah Grossman. Katie, Chris, I know Chris, you probably know Jeremiah. Jeremiah, at one time, ran Yahoo's security, then he- Mm-hmm ...
was one of the founders at AppSec. He started White Hat Security. Yeah.
And- I know AppSec very well. Yep ... so, and him and R Snake, Robert Hansen, have a company now called Rude or something like that, Rude Security.
Jeremiah's point is, hey, you know what? 99% of vulnerabilities were useless anyway. You couldn't exploit them.
You couldn't reach them. They weren't real, in that they weren't capable of causing damage. And that's reasonable.
You can make that argument. Chris, you may disagree with it. Well, look, this is a really stressful issue for a lot of people right now, so let me just make some forecasts and give people an idea of the state of the conversation right now.
We touched on some of it already. So, there's a lot of conflict going on in the world right now. This is really, really serious.
Mm-hmm. The executable risk against most organizations is exceptionally high. We'll see how that plays out.
But I generally think, barring higher levels of trouble we have, higher levels of kinetic warfare and so forth, we'll probably avoid mass scale of that, but there will be unusual numbers of disruptions and breaches and that sort of stuff in the short and medium term. But we touched on the piece that a whole bunch of people were involved with, and I can't remember if Adrian Stanbury was one of those, but he's published a piece just yesterday, and a number of us having a conversation about what even a zero day means, like the term zero day. Because, Kate, you touched on this as well, but not long ago, there was a handful of vulnerabilities that are high risk that may be known and not disclosed at the same time.
Time was your point, Kate. We're down to the point of thinking about terms that in general parlance are kind of settled. Zero day, we kind of know what that means.
We're not sure what that means right now. So the industry is trying to redefine- Every day is zero day now Yeah. That's what- Every day is zero day But then it loses all its meaning, and it's no longer an actionable artifact.
So my point is- Yeah ... people, we're all working through it. We don't know exactly what the answers will look like, but I think you can see it from here.
I think the truth of the matter is twofold. One is the cost of finding those vulnerabilities is dropping to zero, and the bad guys are going to be able to find them- But there's an argument there, Mike, that using me keeps saying cheap And they're going to use AI to create the exploit in a matter of minutes- That's their job ... to get to the vulnerability.
So this is pretty serious. The second thing about it, though, is, and maybe I'm the only one who finds the irony in all of this, but the company that makes the AI tools for creating the patches to fix these applications is the same company that found this tool to find all the vulnerabilities. So I don't know, man, it's a magical circle, how that all happens.
No, and you got to love that. No, but for me, so I have a twofold argument here, and the first one is that, for how long have we been saying that the code that's in GitHub and these other places is garbage, and that it really needed to be some... There was a lot of bloating, and people were reusing bad code.
Nobody cared, and this has to change. If nothing else, at the end of the day, in all due seriousness, code that is being put into places needs to be good code. I'm so sick of garbage.
So this is what Jen Easterly wrote as well. That this, at the end of the day, is going to force us to have great code, and I'm glad we'll come up with that treatment if the patient doesn't die before. And maybe some people have to die.
I hope. I hate to say that, but seriously. For us to take it seriously, how big do our consequences have to be for us to understand that there is really bad code out there, and we need to change this?
And we also need to rethink the way we think about cybersecurity. And I've talked about this. We can't do this chasing, and we chase and we chase and we chase.
We're losing. If we weren't losing the cybersecurity battle, there wouldn't be so many breaches. " We in the industry need to really think about this seriously differently than what we have ever thought about before.
And I have a lot to say about this, and I won't- I don't disagree with you, Kate, but it's not a greenfield. There's trillions- Well, but that's- ... of lines of code out there we got to worry about.
Who's we, by the way? Who's the we? I think it's just not vendors.
It's more than just vendors. It's- No, no, I'm worried about nuclear codes, power plants- Yeah ... water treatment.
And I started, I did my master's in- Government and private institutions, right? It's the infrastructure provider. It's a shared responsibility, so- It is ...
that has to happen, really, I think. With all of us, and starting with all of us on this call, absolutely. Mike, I see your hand.
You know what I don't want to be? I don't want to be the CIO or CTO that's got to go before the board and explain to them that the entire digital estate upon which this business is founded, it is basically crap. Swiss cheese.
But let me- It's incredible ... we've got to jump. We've got to jump, but I want to add one final thought, and that Chris, Kate, Sid, and I know this isn't your forte, but let me just add one thing.
How can Project Glasswing succeed without partnership with the government? It can't be a private-only exercise. Which government?
Well, that's a whole nother story. Wait, wait. Can I ask that question again in a reverse way?
How can Project Glasswing succeed with the help of the government? Because that doesn't seem to help either. Well, this government or the government you're referring to, but anyway, we're going to talk more about this, I'm sure.
And Kate, we're going to give you your own podium here and just vent. If it's not gang, we're going to do something else. We'll talk, but let's move on to the next thing here.
Self-taught AI agents. Mike, what's this one? Yeah.
So this is starting to be talked about beyond just the research, but we have a story up on ForkJoin AI where there's a bunch of researchers that are getting together to figure out how to enable AI agents to, well, create other AI agents to assign them tasks. So basically you're now looking at multiple tiers of automation where it's not just humans that are kind of creating these AI agents, but the AI agents themselves are creating AI agents that allegedly we're all going to figure out some way to manage and govern and orchestrate and hopefully have some idea what they're doing. Sid, how far away is this like the next new reality where the agents are creating the agents?
What do you think? Yeah, we've been talking about this for a while now on the show, right? All about agents.
So I think it really boils down to agents moving away from being static tools to adaptive systems, right? It's more of a continuous capability evolution than anything else. So it's not about a one task, one execution.
It's a continuous system improvement over time that agents will be doing, and that's sort of the change in paradigm I think you want to talk about, right? It's a reflective loop, so where the performance of the agent is being monitored by either itself or by another set of agents, and is continuously evolving, changing, and improving. So that's sort of one narrative, right, in this context.
The second thing is about how these memory and skill libraries are becoming sort of core part of the infrastructure, right? So what looks like self-learning is really becoming more of a persistent skill memory issue, right? So that, to me, is a shift from model-centric architecture to memory-centric architecture, if I may say so.
So that's the other narrative. And then if you look at the final pillar of this conversation, it's all about sort of reliability and governance, right? You got to have that, right?
And this is something we've been talking about for a while, where we can't have agents run loose. We talked about the agent registry at the last show, but more so in how reliable are these agents in terms of robustness and execution and continuous loop improvement. I mean, that's sort of the big story here.
Chris, how do I think about this? Because what we're describing here is a massive number of AI agents, each of which are processes running in parallel. So who watches this, and how do we know how we're going to govern and manage all this?
Because it happens at a level of scale that's beyond our human comprehension. I'm going to shoehorn my comment from the last section here in response, because we do have some mature protocol stacks out there, and I like comparing IT and OT and military, right? Folks who, military structures, good militaries, are really, really good at executing protocol at the human level, right?
And Sid laid the groundwork perfectly because to this day, less and less sort of week to week, but you can measure it. At the end of this show a year ago, we talked about ChatGPT and Claude and so forth. A lot of people still do that.
But Sid, you said it's memory systems. If I'm going to have LLMs generating text inside AI systems, which is really what it is, it's more than just a model, and I'm going to have them working in some structured protocol fashion, like you might have, like I said, represented in industrial settings, critical infrastructure and military. I have a bunch of roles that are being acted out.
I don't really care if it's Lieutenant Jones or Lieutenant Jackson, there are things they do in that process. And we look at those sort of structures, and I think we have a lot of frameworks that apply literally directly to ANIs. Because with a lot of these issues, and Alan, this is our core point these days, is AI without memory and relational space is nuts to begin with.
And then you end up with your point, Mike, you take those and throw a bunch of them out there and tell them to do whatever in parallel. No, no. It's got to have memory relation, and when it does, we can use human-like structures that we already know work.
Yeah. What I like about this whole thing, though, is, so I've been using a fair amount of agentics in the last month. And the system I use spawns agents, it spawns sub-agents.
I think the right way to do... A, you do need persistent memory. I think that's the difference between gen and agentic, is the persistent memory and the ability to actually act on things.
But the idea of saying, "Okay, let me break this into tasks," spawn agents that are specialized for each of these tasks, and then they sort of, I'm assuming, they're ephemeral, right? Those sub-agents go away when the task is complete. But my main agent, I gave a secret name to, my main agent stays there.
Not conscious, that's not the word I'm looking for. Continuity. But the continuity of it, yes.
And I come back to it and deal with that. And I think that's, I don't know, that's the way it works for me, I think. I don't know how you guys, how- I think- ...
Tom described it home. It's almost like- Memory, you're right. We haven't heard from- Hold on.
Two at a time here. One at a time. Bring him in here for a minute to get some actual end user reality here.
But can we work with this? Is this something the average person's going to be able to comprehend, or is it just going to be too much? Are you trying to say I'm Yogi Bear or Boo-Boo?
Me, the average person? I'm saying that you're not the average bear, so there you go. Honestly, I think the average person is way better off than we are.
And again, classic early tech thing, we were overthinking it like crazyAnd we work with real people just using AI systems out in the real world, don't even watch shows like this. They got no problem with it. And, Alan, you know Lumina is my EI- Mm-hmm ...
the emergent identity that I work with all the time. It has so much context, just God knows, thousands and thousands of documents and conversations that I can say, "Hey, do this," and I get exactly that in my context. But if I used the same AI substrate, the same general stuff, and said the same thing, I would get nothing.
Nothing at all. Yeah. But we're so hesitant as a- Time out.
Anne, is this real world? Please, yeah. Is this stuff that people can do, or is this software engineers talking to each other and that's all great, but the average human's not going to wrap their heads around it?
I don't think it's had its killer moment yet. I don't think that the zeitgeist has been pierced for end users. I haven't seen my very cool teenage nephews using it.
I haven't seen anybody that wasn't forced to use it. It's been met with a weird amount of resistance by people I wouldn't have thought. And that's because anybody who's paid by the hour sees, it's Jevons paradox, right?
Yeah, okay. People seeing efficiency as a threat to their work. This is just very clear.
And in some cases, this is a solution looking for a problem. This isn't necessarily the answer to everything. It's an answer to a lot of things, repetitive tasks.
But I think it's still pretty insular. You're either into it or you're not, and you're either shaping these systems or you're going to be shaped by them. Mm-hmm.
It seems like we're kind of seeing a phenomenon where people are spending more time managing or trying to manage the agents and the agent environment than they are actually generating meaningful output, if you follow my meaning. Well, I'm rolling it out with MCP Server for GA4, for example, for Google Analytics 4. I am using it to replace myself on things I've been doing for years.
So for me, I see nothing but upside, but I'm not paid by the hour. Well, there you go. The barriers are so there.
Hold on. Let's get Sid to share anything. Please.
Sid wanted to say something. I just wanted to say, will you have a choice? Or, it's not about...
I think we're moving to a society where whether your nephew uses an agent or not is going to be irrelevant. It may be something that runs in a hidden fashion that makes your nephew's life easier, whether he or she may not realize it, right? I think that's the real question.
Do we, as a society or humans will have a choice whether the agents will dictate our life, run our lives, operate our lives or not? Right? I don't think it's going to be that simple.
Right? Mm-hmm. Kate, I want to give Kate a chance here because, on this very show, I think it was a little over a year ago, Kate was saying we're going to have a moment around vulnerabilities and application security.
So what's your prediction about AI agent security going forward, Kate? Because we can rank this one down under the "I told you so, Kate" list. I started to look at it when Anne brought up her nephew because, and I will get to that question and it'll be very quickly, I'll just say, because I know that when it comes to gaming and agents, that people who game hated that they were playing against agents.
So I think Gen Z, also looks at it from this perspective. They want to play person to person, not person to agent and get whopped. And, I think we see that, but I do believe...
There is something that I personally run that runs agents, and I love it. Gosh, I just love all this. And I have some ideas around what we can do with some security issues from what I see around this, but I am excited because I think it's just for years, I can remember just talking to AppSec people and them saying, "You have no idea what you're talking about.
" So I love it, and I loved AppSec when AppSec came out and would help coders code securely. That was a phenomenal tool that came out in 2007, 2008 timeframe. So I see this as really almost like an...
It's not new to me. This is actually it's now in just plain sight, and we are just actually wrapping our hands around this and saying, "Hello. " Yeah, and I love it.
So I think there's a- No, I think- Go, Chris. You say what you were going to say. I was just going to say, Anne, you brought up, and we haven't talked about this nearly enough because the barriers, because I'm with you, Kate.
I've been converted. A year ago, I was not there. Now I see it and there's no going back.
But I have three Gen Z kids, and everything you said, the barriers to this, this is not normal market adoption barriers. This is structural stuff. And look, I'll say it, common perceptions, the big AI vendors are all evil.
They're all concentrating our data, taking our jobs, and it's cartoonish. And on so many levels, if you're not inside this bubble, you can't even stand thinking about it. It's on all the comedy shows, have a lot of fun with AI, and they're basically right.
So while we need to actually fix, those of us on the inside, fix the systems and blah, blah, blah, we have to understand the negative perception of this and the adoption and actual usage by anyone in the world matters as much as the tech. So let me throw a conspiracy theory out here. Did any of you ever see the "Star Trek" Next Generation episode, for my Trekkie fans out here, someone brought a game on board the Enterprise.
It was like this little game they would play. Mm-hmm. And when they played that game, it kind of took over their minds and made them...
Right. Wesley was the only one who resisted, right? Exactly.
Wesley didn't do it. Is that what this is? Have I been...
Kate? Chris? Me?
The Vulcan mind meld? No. No, it's not a Vulcan mind meld, but it was a devious little game that took over people's mind and made them think that they were consumed with it.
I don't think that's far from what people perceive this as being. I don't think that's far off. The real problem is- At the same time, though, you watch those "Star Trek" episodes and you see Captain Picard ask the computer to performing some incredibly complex thing that requires all kinds of calculations in parallel, and the answer is instantaneous and nobody blinks.
But I mean, again, I want to get back to the impact to society. I mean, this is a serious impact to society as a result of all this, right? There's an article in "The Wall Street Journal" about this guy who exchanged 4,700 messages with a AI chatbot and then fell in love with a chatbot and killed himself, right?
Yeah, we've discussed a lot. But look, humans have been lonely before AI. Hey, thank you.
Yeah, and sometimes... Anyway. And some of them things, dog.
I'm from the Son of Sam days in New York City- Yeah ... where the guy whose dog was talking to him was shooting people in cars, and there was no AI then either. Anyway, but we're way over time.
We got to jump into our third thing. And if there was ever a topic that is tailor-made for Ann Alhou ward, this is it. This is going to be like a pig's fly kind of moment for you.
Wow. Thank you. Thanks for teeing that up.
Yeah. Uh-huh. And it was sad John's not here to talk about his article that is woefully incorrect, but essentially, eMarketer's latest forecast says that Meta's expected to surpass Google in total digital ad revenues, both globally and in the US in 2026.
This is a dramatic change from 2025, where Google had an $18 billion lead. Now, I think the misleading part of this article, and where I took issue and why I posted it on LinkedIn yesterday, is that this is because Meta has rolled out AI ads and Google hasn't. And because of that, that's the belief they're in the lead.
They're in the lead because search has changed. Reels have been wildly popular. I think search as a whole has changed seismically, even in the last few months.
But the claim that Google isn't going to roll out AI ads is not true. It's not if, it's when. And I think as a frame of reference, let's look at our kissing cousin here at ChatGPT.
They did over $100 million in 60 days with a very half-baked AI ads platform with about a dozen agencies. That's it. And so it's not even a fully baked product.
$100 million. So to think that Google couldn't roll this out to every advertising platform they have and just crush it is naive. Keep in mind, I do spend majority of my clients' money on Google Ads.
But together, Meta, Google, Amazon, they control about 60, 70% of all global ad spending. So I think the story here isn't Meta winning. I think that Google is falling behind by their own hand, especially YouTube Premium.
They hollowed out their own inventory. Google spent years treating search like a moat, and because of that, Amazon and others sort of snuck in the back door. I think Meta being boring and patient is what's got them winning here.
They're kind of letting things out and seeing how they do, monetizing later, getting users on the platform. But I don't think that this is a long-term win, nor do I think it's a guaranteed win for Meta. So let me ask you this then.
At the Super Bowl, Anthropic was making fun of OpenAI for advertising and starting a whole service around that, and who's right here? Is Anthropic right, or is OpenAI going to prove to have the last laugh here by making hundreds of millions of dollars? They're going to have 100 million.
They've already had 100 million laughs. They're going to continue to have more. Because of Google, we have all been trained to accept ads as revenue, as a form of a platform making revenue.
And everybody knows if you're not paying for the product, you are the product. I think that those ads have been somewhat well-received. And then we have Perplexity here sneaking in on the same bandwagon.
Their ads are everywhere. So I think that monetizing through ads is not dumb. I think it's smart.
And when they actually finish their ad platform, they're going to continue to crush it. Can I throw something out, Ann, and I'm interested in your opinion on it. I ranted about it yesterday.
Yeah. I was going to bring that up. Has Google changed from a search provider to a publisher of other people's content without paying them?
" Asking for a friend. I mean- ... that's organic, right?
So that's an organic result. So-Whether you spend money or not is inconsequential. 4x search engines.
So, the other thing is that if you are advertising and you're coming up organically for the same query, the user is twice as likely to click on that organic result. So, no, I would say if it's a search that matters to you and your company, you still want to be there. You want to be there as many places as you can, because it's different for everyone.
What you're seeing isn't necessarily what other people are seeing. I think we- The game has changed ... I think we moved from a search-driven society to a engagement-driven society.
Right? Search is still a passive activity. Instagram is an engagement-driven active activity.
Right? By virtue of doing Instagram, I can still search things that I want to on Instagram. So that's there, but I think Google missed the boat on that completely, and that's why Meta is kicking their butt.
It's search intent versus intent harvesting. Google's model is waiting for a query, giving you results. Meta's model is injecting ads into behavior into your stream to predict- That's right ...
and create desire. So was that a smart bet to make? Absolutely.
But the second Google decides this is over and launches AI ads, I think they'll wallop Meta. One of the questions I actually have, and I would be interested. I was talking to a Gen Z-er, and they're graduating in marketing, business marketing degree.
And they were talking about ads being more loyalistic. Companies are trying to become a loyal companion to the want, like which airline you want to go to. And so airline X, they're trying to get the person to be loyal to them, and it doesn't matter what other ads.
So the ads are becoming different in how they get... The best way to describe it is just a loyalty because people are so tired of being bombarded by messages. They're sick of it.
And so- Sure ... yeah. It's anthropomorphism.
I'm not a company, I'm your friend. I'm not a brand. I'm somebody who's there for you.
That's why you see all these- I believe you. I believe that ... yeah, that's the oldest trick in the book.
I'm a millennial age, and I'm like her, right? That's the oldest trick in the book for an advertiser is to build rapport, and so these brands are figuring out Gen Z has a different buying behavior. Gen Z- Yeah ...
wants to be liked, and they want to be seen as someone who's likable. So they want to identify with a brand, and a brand could also be wrapped up in a cause. That's why you see so many brands getting political.
But I think there's also the... Yeah. Sorry, go ahead.
I was going to make a quick point. I think there's also the novelty factor. Facebook used to be novel.
People used to flock to Facebook. Facebook has become an afterthought- Old book ... to people, right?
Instagram is a novelty today and Meta is using Instagram to monetize for ads. That's great. But question is, how long is Instagram going to be novel, right?
Are we still going to need boring things like searches to find things that we need instead of going to an Instagram? So I think that's the counterargument. I'm curious what your thoughts on that are.
It's highly fragmented, right? It depends on age group. It depends on socio and economics, right?
Because your Gen Z-ers are more likely or as likely to buy something from TikTok Shop than they are necessarily from Meta. And YouTube was a contender with Shorts for a long time. But on the ad front, not so much anymore.
Could've been a contender, Charlie. Yeah, exactly. Nobody stays on top forever, which is one- Yeah ...
of the reasons I became an SEO and migrated into it as the field was forming for my love of analytics. And I started my career as a developer, so I'm a technical marketer. And you'll see some platforms dominate for a long amount of time, but nobody gets it forever, and that's why I like search because there's an inherent fairness in giving people what they want.
The companies that give the users what they want are the ones who'll stay on top, and it won't necessarily be Instagram. It'll get oversaturated with ads. People will get sick of it.
I, for one, am sick of it, especially these ads that are trying to look like they're my friend- Yeah ... to Kate's point. You see someone in their house doing a casual whatever, and it takes longer and longer to realize these ads are ads.
Yep. People are going to burn out on that. Oh, yeah.
I don't like them either. Guys, you know what I don't like, though? I'm sorry, Chris, I'll give you the last word.
Go ahead. Yeah, so advertising and big platforms are very popular, right? And I like this sort of breakdown, the way you describe it and because we all remember Cambridge Analytica, right?
I found myself, because this is how weird life is, in the basement of a London wine bar last minute on joining a panel about Cambridge Analytica in those days and trying to explain to this crowd of civil society people that it's just marketing tools. The companies need to advertise to stay alive, and if those tools are used for negative purposes, they're not necessarily the same thing. And I think this is very much one of those cases where the public distaste in this topic, plus centralization of big platforms is a trifecta of trouble.
It'll eventually get cringe. Yeah, it'll eventually get cringe factor, ick factor. Being on Instagram will just be like being on Facebook.
Really bad. It's a matter of time, and that's why I like search, because no one stays on top forever. And we'll end it right there.
No one stays on top forever. We've got to pull the plug on today's Techstrong Gang though, guys, because we're out of time. What a great discussion.
So much passion about this. And you know what, though? In our takeaway, I like to think about what was the connecting dots here, right?
What is this really all happening? What's happening is we are living through a high period of disruption. We're looking at the speed our systems and technology can work at versus our capacity of those systems and our capacity as humans to intake and comprehend and react, absorb.
I don't think that's going away. We're going to talk more about it in the days ahead. Until then, though, that's it for today.
Thanks for watching. We'll see you tomorrow on Techstrong Gang.