AI ROI Reality Check, Data Center Backlash, AppSec in AI Era
The AI boom is colliding with three different kinds of limits at once: operational limits inside the enterprise, political limits in local communities and security limits in the software stack.
On this episode of Techstrong Gang, Alan Shimel, Mike Vizard, Jon Swartz, Gina Rosenthal, Fred Wilmot and Chhaya break down three stories that show where that pressure is building. The panel starts with signs that corporate AI ambition is running into financial and human constraints, turns to rising resistance against nearby data centers and closes with OpenAI’s latest push in the AI cybersecurity race against Anthropic.
The first segment, A Little AI Short, looks at the reality check facing enterprise AI programs. Companies may still want aggressive AI rollouts, but cost, labor strain and implementation friction are becoming harder to ignore.
The second segment, Data Center Backlash, explores the growing public resistance to AI infrastructure. As more large data center projects move closer to residential communities, concerns over power consumption, water use and quality of life are becoming more politically visible.
The final segment, AppSec in the AI Era, examines the competitive and policy stakes in AI cybersecurity. As frontier models uncover more vulnerabilities faster, the race is no longer just about model capability. It is about who can turn that capability into real defensive advantage.
Taken together, these stories point to a broader shift: the AI era is no longer just about acceleration. It is about what happens when the real world starts pushing back.
Transcript
Hey everyone, happy Thursday. Welcome to Techstrong Gang. Guys, I got to tell you, it's good to be home.
It's good to be back here in Techstrong Studios, looking at these lovely, familiar faces on our gang for today. It's going to be a great show. Let's dive right into it.
Let me introduce you to our gang members. First of all, joining us is Fred Wilmot. Fred looks like he's home in Seattleland, the great Northwest.
Probably down, I'm going to assume, down Houston way, Gina Rosenthal. Austin, but yes. Austin, excuse me.
Why do we say Houston with you, Gina? I don't know. You got that Houston vibe going on.
Also joining us is, and I mispronounce your name because I haven't been here in a month, Chhaya Gunawat? That's right. I'm based in California.
And also in California, our man in California, the man in California, Jon Swartz. And joining us, I guess up in the high castle, Mike Broussard. Gang, welcome.
It's a great Thursday. I've been on the road near a month. I've spoken to a lot of people.
You know what I discovered in Europe? No matter what language they speak, they still call ChatGPT, ChatGPT. I'll hear them talking Spanish, French, Italian, Croatian, German, Czech, and then you hear ChatGPT.
" That's the world we live in. " That is indeed what appears to be happening. We have yet two more studies that seem to be piling on to a series of studies that now seem to be bringing up the issue about, well, what is the ROI here?
What are the productivity gains? Because it looks like they're not being materialized, at least in one survey. It seems like folks are saying not to their expectations.
In others, the number of organizations that are saying that they've been radically transformed is somewhere in the single-digit numbers. John, I know these are trailing indicators, and AI's moving fast, but when you wrote this story, what's your assessment on what's going on here? Well, since this morning, I got two more reports along these lines.
But in a sense, we talk about surveys and studies and how they kind of lag. They're several months behind. So I'm sure the numbers are a little bit higher, but they are consistent.
And without trying to be too flippant, AI ROI is a bit DOA for now. But there is some serious scrutiny. The first study that we came across was this Globalization Partners AI at Work report.
So they found one in six companies reported a negative ROI on AI projects last year. That's last year. And when the projects did produce a profit, three-fourths of the executives said those profits fell short of their expectations.
Because in a sense, they're at this experimental phase when they're moving into actual profitability. So that makes sense. Then there's a second, even more dire report from Google Cloud.
They talked to 2,500 leaders, and they found, again, three-fourths remain optimistic, but only 3% say their orgs are highly transformed by AI. So this is kind of creating this phenomenon, this thing that's being called an efficiency trap, this where leaders focus exclusively on these minor time-saving tasks or productivity. And the other thing that's a little bit disconcerting is that 80% of the executives think that AI has lowered the value they place on human employees.
And yet there's a paradox. The same leaders who devalue their workplace or workforce say there's a scarcity of skilled human talent as the primary basis to AI success. So these are growing pains.
They will improve. But for now, given the window that we're in right now, there is a lot of concern over ROI, which remains elusive. Is it your sense that we've just overpromised here and underdelivered?
Or is it that maybe we've just underestimated the complexity of the workflows that need to be automated, and we're not quite there yet? Yeah, that's funny. Yesterday, during the show, we kind of touched on the latter part, that there is a complexity here in a jigsaw puzzle of sorts that's being put together in real time.
We use that analogy of the moving car and the car parts, but I actually do think that is happening. And so this is not surprising to me. It's going to take a couple of years, but it always goes back to this conversation where when we talk to the companies, like we do a lot between all of us, it's really hard to get firm, solid examples in companies that have fully entrenched or enhanced or embraced AI and its full capabilities.
Things are just changing so quickly, and companies are at the beginning of the process. But it's also a victim of hype. Definitely.
Hype has come back to roost. Look. " Okay?
Let's take a look at this. First of all, these are old numbers. Second of all, I would bet that 90% of them are based on generative AI usage, not agentic AI usage.
Third-It may not lead to ROI, return on investment profits top line, but how are you measuring productivity gains? Are you calling in your productivity experts from office space? What are we doing here?
It's so early. We are at a wildly experimental stage right now, and like every other technology, when you're experimenting like this, you're not really optimizing for efficiency. We're still in the what can it do stage.
I think- Once we get past the what can it do stage, we can figure out how do we do it better, cheaper, faster. Gina, were you going to say something, or should I- Yeah. What I was trying to say that we crossed the experimental stage in certain areas.
For example, Claude Code is a perfect example of coding becoming the perfect use case for AI. And we have mastered this area pretty well with AI. Now, the only thing that we have to focus on is on the cost optimization.
So as soon as the cost to leverage AI becomes in the budget that companies afford, it's going to be a success story. We are just few months away from that aspect of it. AI is making AI better day by day.
And I also feel that it's not that AI is replacing humans, or humans are the only ones making AI better. It's going to be a combination of how the humans can leverage AI and make the cost being more optimized. You know what- Can I mention something really quick?
I'm sorry to interrupt, Mike. Allen, when you mention these studies, sometimes I get, and not just with AI, this has been going on for decades, and we've all gone through this. I actually do think some of these market research companies or whoever they are, whatever they're selling, they seize upon something that they think is the buzz of the week or the buzz of the month.
Yeah. They pile on, they take advantage of it, they monetize the situation- Hmm ... and then they change their numbers dramatically, sometimes within three months.
So this has happened before, and this is happening now, but I do think there is an element of truth to it. I think there's an element of truth when you see study after study after study coming up with the same conclusion. Yeah, exactly.
So this is a one-off. But here's the issue in my mind, and Fred, I'm going to throw this your way. Are we obsessed about the wrong frigging thing, and we have our heads up our AI a*s because we're all sitting around going, "The promise was I was going to reduce head count, and I was going to drive a level of productivity, and I was going to drop costs and improve my bottom line to no end," when in reality, when I look at AI, I'm like, we're building better things, better software.
We're building better products. We're delivering better services at the end of the day, and that's the productivity in my mind. So Fred, are we just measuring the wrong damn things?
" It's a little- Yeah, I love that movie. Okay. So, in that movie, there's a bunch of, hey, you've got a water boy that suddenly becomes an All-American football player, and it was sort of an unknown and relatively different way of getting to be a college football player.
And then a bunch of other universities tried this out and had very different effects, right? People got crushed and the funny part about the analogy is, look, everybody understands that you can have AI make some difference for you, but it takes five or 10 years, and has, for us to implement a technology or a new evolutionary way of doing something before we start grading the curves. And we're already slipped into this trough of disillusionment after one year of adoption, to me is a bit of sort of the analyst hubris.
Thank you for telling me the facts that we already know, Captain Obvious- ... but we haven't yet because they can't. So the part that I think is intriguing or the double-click on this set of metrics that this should bring to bear is the same challenge we have with hiring junior devs or folks new to the industry or whatever.
A lot of the relationship part of that when you bring new people into a company, that's that 80% number. That is worrying. But the reality of it is expert systems need experts, right?
And so folks that have been doing the job for a long period of time and have established themselves as having a capability in using AI effectively for the business are required, absolutely required. In fact, is there a way back? That is a good question.
So I would argue we're absolutely not, and we're way over-indexed on things that don't matter at all right now, right? The cost analysis to do a cost-benefit analysis on whether or not the business is becoming more efficient from something we just freshly introduced last year is silliness. Mm-hmm.
Yeah, I think there was a story, I don't know if you all saw it or not, on Fast Company yesterday where because Amazon workers are being so pressured to adopt AI, and it just doesn't fit what they're doing in their job role, but everybody has to do AI now. And at Amazon, they're using a Claude-type product to invent tasks to go do with AI so that their numbers stay up, so that their managers who are monitoring their AI usage are happy. And I think one of the first things you can measure in an organization is what is the amount of our people that are using AI.
So they don't want to be caught on the wrong end of that management accountability trap for not using AI, whether it makes sense or not. So it's pretty funny for me because the article talked about the efficiency trap, but- In reality, systems, and especially if you think about Amazon, is one of these by-the-numbers and driving down the numbers and inefficiency. That's what they've been known for.
A system does what a system was designed to do. So here, like you said, Fred, we're given this brand-new type of technology. It's not a fire hose that you can spray on everything and automatic efficiency happens to you.
And so I think organizations are looking, well, where can we see? And I've seen this a lot with the big companies saying Microsoft has a program, Google definitely has a program. Do you have an internal community that's promoting AI usage?
Do you have this and that? " So I just think it's funny that people are going to do what they're going to do. If you're going to measure me, I'm going to do what you measure me on.
So you're going to measure me on AI usage, let me find a tool that makes sure I'm building some AI stuff. Yeah. We see that.
We see that in our own organization here at Futurum and Techstrong. People putting on their Slack channel what AI tools they're using. When you look at those tools and you realize they're not tools that are going to help these people do their jobs, but they just want to show they're using AI.
And I will tell you, as the CEO of Techstrong, and I've asked our people to use AI and let me know how it's going, I'm very quickly learning which people are really using AI and which people are just blowing smoke by burning up some tokens, but it's not reflected in their work. And that's going to happen. But here's the other thing, and I'm going to make an analogy to the DevOps movement, right?
In the early DORA studies by Jez Humble and Dr. Nicole Forsgren and Gene Kim about high-performing IT teams who we said they were high-performing based upon their DORA metrics and really their DevOps adoption, if you will. And it was reflected even in the stock prices of some of the public companies of high-performing IT teams.
Not every company adopting AI is going to recognize the benefits at the same pace. There are some companies, and within a large organization like a Google or a Microsoft, there will be pockets, bubbles of people who accelerate, and there'll be bubbles of people who don't. Because it's not a homogenous mixture.
It's very bubbly, if you will. And so you're going to see that in organizations. I applaud these people who want to rush out their surveys and pitch John and me, and Mike, and other journalists, and editorial folks because they want to get some earned media credits.
But honestly, I don't put a lot of faith in them. That's where I am. I would look at it a little bit differently.
Mm-hmm. And the one thing I would be concerned about, and it's been an issue for a long time with IT folks, is maybe they just don't understand the business well enough, and they make all these assumptions and promises about what a technology can do. And if you don't understand how the workflow actually operates, you're going to make all these wonderful hype claims, and then people are going to start believing in that, and then there's going to be a backlash at some point.
Yeah. You're right. That's what's happening.
That's what's been happening the last several months. And it's also keenly obvious, I think, in a lot of these conferences where they're kind of, in a sense, shifting their narrative. They're shifting their storyline from, "Oh, this is going to change everything.
" So in a sense, they're acknowledging what's going on. Mm-hmm. We'll see.
Anyway, guys, we're about out of time on this one, but let's continue our day of survey findings here. Mike, we got another one. You want to talk about Captain Obvious.
I could've saved them the time and effort on this, but what is it, Mike? Yeah. Well, this one's from the Gallup organization, so it's always entertaining at the very least.
But there is a survey finding that most people, surprisingly, don't want a data center in their backyard. And it doesn't seem to matter whether they are left or right-leaning, they're just not excited about this whole idea. But these data centers got to go somewhere, and they seem to be going into these more rural areas, at least, because, I don't know, maybe they need the money or they just don't realize what the issues are.
But it sounds like to me, more and more folks are aware that these data centers are loud, noisy, require a lot of water, and Gina, is this going to become a bigger political football? I think it is. I think the reason definitely that these data centers are going into rural areas is because of the traditional way to get these projects going was to promise jobs in exchange for doing whatever they wanted on that piece of land, basically.
And what's happened now is there's evidence that some of the big... Like the Meta data center in Louisiana is probably one of the best examples. That has changed the landscape.
It doesn't act or feel, sound like a rural area anymore. It's totally transformed that little community. Not many jobs are coming to that location, and the ones that are, are not high professional technical jobs.
So, I think the study is right on. And just speaking about Texas, it's not a data center, it's a fab, but it's the same kind of principle because it's the same kind of footprint at this point in time. The local landowners are highly, not opposing that from coming, but they really, really, really want their county commissioners to look at the agreements that they're making with Musk organizations to make sure there will be 2,000 jobs.
We are not giving up our taxes for you to change the footprint of what our rural communities look like for hundreds of years. So we want to see a return on our investment of not charging you taxes, and allowing you to build and disrupt our area. So, I think so.
The question becomes how many of these ginormous AI data centers do we need? Do we need those in rural areas even, or should they be next to people? Where we're going to actually do the inference for a lot of the things need to be closer to where the people are that are using the different products that are making use of the big AI models.
So yeah, I don't think it's going to change very soon. Mm-hmm. Well, it can change, but maybe it needs to change because we need a different approach to building AI so that it's not as compute intensive and it's not this massive data center farm that I have to go build in some remote area.
And, I can't help but wonder if there's other alternatives to LLMs that might accomplish many of the tasks that we need to accomplish that are going to be far more efficient. I'm starting to wonder if we are just spending too much time on one particular type of AI and not enough on all the other forms of AI that are out there. I think the other thing is you have to think about what are the new types of infrastructure, physical infrastructure that are coming.
So we know that there's new types of chips coming probably this year from the big chip makers to rival the GPUs. Then there's also different ways, I read an article yesterday about a German, I didn't understand the article, you're going to be able to tell, a German optical compute manufacturer that is making their US headquarters in Austin, because they believe, like everybody else, this is where all the data centers are going to go, so they're going to be here. So that's interesting.
And then as we start to see the different types of architecture that are going to be required for quantum infrastructures, that will change how we are able to actually do the training and all the rest of it, inference, everything for AI, because we will have a different type of infrastructure doing it. We're just waiting for that infrastructure now to get here. It's not quite here.
Mm-hmm. So there's a couple things here I'd love to throw out. And Gina, often you and I sort of see eye to eye, and often you and I disagree when it comes to stuff like the data centers.
And I think I've been channeling sort of your thought process and proximity to the data center thing. There was a news story about this in Portland, that there was a collective fight to not have a data center implemented in and around the Portland area that actually the citizens were successful with. There was a massive fight in Utah.
You guys probably saw about that. And so I see definitely a bunch of collective arbitrage around this. The big thing isn't whether or, and we've talked about the optical chips for a long time, right?
90% reduction in heat, therefore less water, cooling requirements, all the great things. But there's an ebb and tide to the availability there. Here's the kicker, right?
Not surprising that Meta has a lack of what I would consider ethics on what they do with their data centers. It applies to everything that they do. But when I look at other organizations and the fit requirements for coming in and saying the water looks the same when it goes in to when it comes out, that's a requirement, right?
As an ethical convention. We can't drain the local power supply. We must supply the local power or the local water with these things.
We have nuclear power. It can be localized. There's a lot of ways to move around this environment that doesn't create such a asymmetrical way of owning the calibration of the usage of this type of stuff.
And we haven't really put the force into the exercise to make sure that that happens. I think that's starting, which, my wife would say is the greatest thing ever, so I don't disagree. Mm-hmm.
John, companies are looking at... I'll be real quick. Sorry, Valerie.
Go ahead. Companies are looking at nuclear options, and also, but I want to mention something. This political debate goes beyond, extends beyond rural areas.
I think in California we have a governor's race, and one of the key talking points of the governor's race touches on data centers, and there are a lot of advertisements pointing out the AI, quote-unquote, "BS" of one of the candidates who's backed by big tech. His name is Matt Mahan. And then we have Tom Steyer, who's vowing to tax the billionaires, who's in the lead or close to the lead.
So this is expanding, I think, as a national thing. It's not just a NIMBY issue. Anyway, I'm sorry.
No, don't be sorry. I think that's a great point, John. Guys, you can't leave your common sense at the door here.
Let me ask you guys a question. I got a great deal for you. I am going to take your hard-earned tax dollars, and I'm going to give it to some tech bro billionaire company so that they'll come here and build the data center right here, and no, of course it has to be in a rural area.
Do you think I'm going to knock down a couple blocks of Harlem or the Upper East Side to build the data center? Oh, I got to build it where there's nothing right now, in an empty field or empty acreages. So I'm going to take your hard-earned tax dollars, and I'm going to give it to poor old Elon, who needs a couple extra shekels in his pocket.
Right? And Elon or Zuck or Slippery Slam or Modi, they're going to take that money and say, "Thank you very much," as they lay off more people. And they're going to build the data center, and they're promising you jobs.
And at first, it looks like their jobs are really there, electricians and plumbers and HVAC people and concrete pourers. And then the data center goes up, and all those people go away, and all that's left is a bunch of headless robots running up and down aisles, making sure the machines are on, and there's two jobs out of the whole damn thing. But wait, it gets better.
Your electric bill went up this month. I'm very sorry, but we all have to pay for the electricity that this behemoth is eating up. Now, let me ask you a question.
Do you like data centers? What do you expect people to say? Come on.
I think there's a middle ground here, and I think Fred pointed to it, because I don't think the data centers are going to go away, and we need them. " And they sign these things, and now they're all going to run for re-election, and most of them are going to lose because they didn't think through what the provisions of that agreement should be like and what that means to responsible use of water and what the implications are for who's going to pay for the electricity and all those things. But they're all solvable problems in my mind.
They're not necessarily things that are deal killers. There's no reason why Meta, for example, can't absorb the electric cost for the local community there. There's no reason why we all have to pay for that.
That can just be passed through to them. They can also get their own grid if they want, since they're spending billions of dollars on the data centers. They don't necessarily need to be attached to the- That's a problem, though.
grid. " So, I think nobody asked the hard questions. Let me give you an analogy, though, from down here in Florida, where we do so many things correctly.
Right? The fact of the matter is that the Walt Disney Company bankrolled the state of Florida for decades. For decades.
Mm. Based upon the property taxes, sales taxes, income taxes that were generated from Disney World. Then our brilliant governor decided to pick a fight with them because Disney had a problem with taking away people's rights and decided to go to war with Disney until someone reminded them that they pay 40% of the cost up there for municipal services and so forth.
The same model has to work with data centers. Instead of giving these people tax rebates to put their data center there, let them pay their fair share and then some. It'd be better if I went to John and said, "John, guess what?
Because that data center is going to be a couple miles from you, you're getting a 20% property tax rebate. " And I think that's what the protesters, if you listen to what they say, that's what they're saying. Mm-hmm.
What's happened is those deals that have been made were made in secrecy. All of the big companies put all of the commissioners under NDA, so they couldn't even discuss the terms. So people were like, "Just hang on a minute.
" And so far, it's not fair. They are just rolling in here, doing what they want. If they bring their own power, which is a Texas thing that they're trying to make national, and I think, actually, it already has been an EO released on it, is just a cold grift.
So you can bring in your own power, and now President Trump is saying you don't have to pay attention to the EPA rules for it. So that's a big problem, too, because then you put these data centers with their own power, which is polluting the air in a rural area, and that's really bad news. So it just needs to be fair, and it's not fair for anybody right now except for the big tech companies.
Mm-hmm. But they're all in China trying to get deals. Yeah.
And that's not going to change anytime soon. There's no incentive for these companies to do the right thing. They've got- Well, no, but you know what, John?
We have a history in this country of where local people make a big enough stink- Yeah, that's true ... you can stop projects like this. Yeah, that's true.
That will happen. Yeah, I'm talking like a devil's advocate here, but if we want to reduce the cost of AI that we talked about in the previous session, we need to have data centers. So it's like you need them to reduce the cost, but bringing them is an additional cost, which a common man fears it.
So we need to find a- I think we all agree that we need them if we're going to get efficiencies and be able to have the capacity we need. The question is, where do you put them? I think there's also not a direct accountability to the tax breaks they get to the benefit passed down.
Exactly. That's the key, Fred. You've got to put the incentives where they belong.
" The people who signed these deals did so in secrecy and didn't tell us what the implications are and what it means, and you're just going to see a massive turnover in the political, local establishments. Absolutely. Well, maybe we need that.
We need it. Maybe we need that. Anyway, guys, it'll be interesting, but progress stops for no man or local community.
Data centers will be built. We've just got to figure out how to make it equitable. Mike, what's next on our hit card for today?
Well, I'm going to argue that there is some good news in all this AI noise out there, and it goes something like this in my mind. We've talked about on a couple of shows now about this whole thing with the AI discovering vulnerabilities, and everybody's having a panic because they're going to have all these zero days. However, it seems like we're making a lot of progress in also not only discovering those vulnerabilities and maybe using other tools besides some amazing thing that Anthropic allegedly built, but apparently you can discover vulnerabilities with just about any LLM these days.
We can also fix these things using AI. Not only so if we can discover them, we can fix them, and in a lot of cases, you're starting to see people build platforms that are using AI with context to discover vulnerabilities internally. And then I can use AI tools to create the patch and automatically deploy them with AI tools.
And it could be at the end of all of this, we might wind up with better, higher quality software that's more secure. Fred, am I dreaming or is this kind of where this is going to end up? Well, I'd certainly think what you've noted is what happens after the trough of disillusionment.
Yeah, that of the promised land, wave the magic wand, and all of a sudden, AI can account for the remedy, and the cure, as well as the finding and prioritizing. But, the challenge that we have here, and I think that the conversation around the difference between, the mythos versus, OpenAI's Daybreak and the things that happen as a function of this. There's a lot of ways you can look at either Mythos or Daybreak and say, "Is this the new Mandiant approach?
Hey, I've found an APT," and so therefore, right, marketing really takes root here. And so I obviously have to be able to illustrate the value of a specific set of use cases, and my company demands it. There's truth in here, too, though, to be fair, and a collective group, led by, Gadi Efron, a few other CSOs, put together an output for a paper on Mythos.
But the truth is, is finding vulnerabilities is not as hard as it seems. These models are not as required as it seems. And by the way, just like the post office in "The Untouchables," everyone knows where the alcohol is.
Everyone knows where the vulnerabilities live. And it's not a question of whether or not I find more vulnerabilities. It's how do I remediate them?
How do I do that with the level of prioritization and the context of my environment? We don't live in a small ecosystem here. There's open source projects that the entirety of software development rests on, and those chains of supply are just as subject to the same vulnerability discretion we have in our companies that are paid for and so on.
So, not to say that that magic wand vision isn't what everybody should be striving for, Mike, you called it out. In a perfect world, I don't want to patch 20 vulnerabilities every day in my software from open source projects or whatever's have been released today. We would love for that sort of supply chain to sort of automatically do some of that themselves.
But here's what we're up against. Take an example like Team PCP or in the last conversation, some of the reasons why we say that we've got to win the AI race is because we're in competition with other countries like China and China's models and things that go along this way. Other adversaries, other governments, other criminal organizations using AI harness to take more than the syntax and get into the context and the logic, which is really sort of where I think the value of what we're talking about, these new models being able to illustrate outside of SAS and SCA, or source code composition analysis, and do something useful with it.
" Once. Once. And so when we look at this, right, it is still asymmetric from the standpoint of how we can help better, whether it's the 15 new startup companies that got seed funding for this or the frontier labs and foundation models are being used to do that.
The challenge is still the same. " Every company can implement models today, like you said, Mike, that does some level of this with better discretion than the standard tools that are available today, and they also know that code and can probably fix it. How do we determine what we fix and how fast can we make it to production?
Right. And I think the one thing that I want to add, what Fred said, is not add more vulnerabilities, because the more code AI is shipping, the more we are exposing the vulnerabilities where we can expand it further. So a governance for security in any organization is the key here, that the code that the AI has generated should be reviewed, should be evaluated with scanners, with tools, and not that AI is scanning the code that it's own generated.
There has to be a level of human involvement here. It doesn't seem like the bad guys are too concerned about our inability to patch, and they're basically using AI to create exploits faster than others. So, has this become a race against time that we're going to lose no matter what?
Look, I think you're focusing on the wrong thing. When I was a kid, one summer I worked in a building on Times Square, and I spent a lot of time watching the three-card monte players take money from the tourists. And you realize there's the dealer guy who plays the cards, and then there's the lookout and the shill, and you see all the players are here.
What is this really about? This isn't about how many vulnerabilities we're going to find. It's not even about how many we're going to fix.
We've always had a lot of vulnerabilities, and we haven't fixed enough of them, and that ain't changing. What this story is really about is OpenAI is scared to death. They were the first mover in this business.
They're late to agentics. Anthropic has more revenue than them. Anthropic seems to be pulling all the right levers from a marketing point of view.
They own this Mythos thing. The fact that we call it Mythos is an Anthropic thing. OpenAI's got to do something here, so this is their fire back.
Guys, this is Steve Jobs versus Bill Gates all over again. Mm. That's what we're witnessing here.
The other stuff's just noise. Nothing's fundamentally changing in security, frankly. A little.
That's what this is about. I think it's changing in the sense that it's all going to happen at machine speed now. I think that- Yeah, the scale.
The scale's changing. Yeah. The scale- The scale and speed ...
is fundamentally changing, and we're going to look back at the days when we had months to patch and fix a bug or something as the good old days. Or maybe we won't, because this will all be handled by machines. Right.
That's the whole thing. This whole thing, each piece of it will be done at machine speed and scale. Finding the vulnerabilities, generating the exploit code, remediating the holes there.
As the rat works its way through the snake, these things will all be done, and hopefully at the other end, as Jen Easterly writes, we'll wind up with more secure, better code as a result. The question is, I said before, does the patient die even though the operation was a success? But we'll get there.
0 now, that's going to be better than Living Daylights or whatever this one's called from OpenAI. 5 version of OpenAI's model is pretty damn good at finding vulnerabilities. Yeah, it is.
And it doesn't- But they weren't getting the juice. They weren't getting the juice out of the lemon from a marketing perspective. They needed a Mythos killer.
Uh-huh. There's another really important point here. Why aren't vulnerabilities all patched today?
It's very simple. It's the cost equation risk. So when we look at what the effects are here, you can stack up another 500 vulnerabilities that are critical, ACE, RCEs.
It doesn't matter, because the cost equation hasn't changed. What hasn't changed? Insurance, regulation.
The cost-benefit analysis for a company to do it, the likelihood of exploitation, that's the unknown quotient. Whether or not I am specifically likely to be exploited by that particular vulnerability. And as always, the risk relationship to that is going to drive all the business decisions.
It's not a security decision. And I think fundamentally, the challenge that we have here is we're talking about how to build better, faster, stronger, whatever, and none of those constructs around in the ecosystem that governs risk are changing at any rate or speed that illustrates that. So that's really the part where the engine's going to break the engine bolts and shear off here.
Great engine, car's not built for speed, so you wind up with a Lamborghatti. I always wanted a Lamborghatti. Yeah.
I think it's- I just keep thinking- Go ahead. I'm sorry. I just keep thinking, because I love all these points y'all are making, is we know the bad guys use all these tools, too.
So all I can think is, I know back in the day, where I helped manage Sendmail, and we would watch the different kind of ways they would try to break into Sendmail, and then we'd watch our little open source app fight it every day, which was super interesting. But the bad guys are going to fight back, so if you're able to resolve things, what if you're not resolving it, but the bad guys have figured out a way to make it really super hard? I don't know.
In my head, what you're saying, Fred, makes so much sense. It's a business decision. You think about how you're going to actually resolve the problems based on all of those things you mentioned, Fred.
So- Yeah ... it makes more sense. If you ask a director of security somewhere that is responsible for the operational security of a company, they will tell you exactly what you just asked about is their daily grind, their concerns, the reality of the thing.
If you ask any CISO, he will take some level of, "Absolutely true. " If you ask any CEO, there's no security context beyond what is going to affect the business. And the translation of that is what we've echoed over the last 10 or 15 years, is how do you get security to talk business?
Well, guess what? Now we can, but it hasn't changed the outcomes. So there's a little bit of trough of disillusionment for security people.
It's as important as everything else. It's not more importantAnd that's the risk-reward ratio that we all have to walk down. I will make a prediction.
" But at some point, somebody's going to compromise somebody's software supply chain and stick an AI agent in that software supply chain that's just going to start generating more vulnerabilities in code to throw into their software because we think about trying to preserve the code, but meanwhile, the credentials that somebody uses to access an environment are still wide open. And the least path of resistance would be, in my mind, to just shove an AI agent in the middle of somebody's software supply chain that they may not know about for months. I don't think that's anything new.
Maybe that it's an AI agent versus- Mm-hmm. Yeah ... call it a bot.
Right. Right? But those kind of back doors and stuff have been there.
Anyway, guys, we're about out of time. We got to call ahead on this. Gang, thanks for joining.
Thank you for watching. " And in regard to what we're talking about here, it's about how time seems to be moving faster with this AI stuff and how rapidly things are changing. I wonder if Mr.
Einstein is rolling over in his grave about the laws of physics here. But stay tuned for that. We also have a Tech Field Day, I believe, coming up.
AI Field Day. AI Field Day, yep. So watch that.
Lots going on all over the place here at Techstrong and Futurum. We'll be back tomorrow to wrap our week up with more. tv, Techstrong OTT, if you're watching it on the big screen, which is my favorite way of watching the gang.
But until tomorrow, this is Alan Shimel. We're out.