Anthropic Goes Big, NVIDIA Expands AI and Microsoft’s Security Fight Escalates
The AI race is expanding across capital markets, computing platforms and security conflicts all at once.
On this episode of Techstrong Gang, host Mike Vizard is joined by Anne Ahola Ward, Sid Nag, Chris Blask and Kate Scarcella to break down three stories that show where the pressure is building. The panel starts with Anthropic’s IPO moment and what it could mean for the next phase of AI market leadership. It then turns to NVIDIA’s latest push across AI PCs and robotics, including the new RTX Spark platform developed with Microsoft and partners.
The final segment examines the growing dispute between Microsoft and a security researcher, a case that underscores how vulnerability disclosure is becoming more contentious as cloud and AI systems become more important to enterprise operations.
Taken together, these stories point to the same broader shift: AI is no longer just a technology race. It is now a valuation race, a platform race and an accountability fight.
Transcript
Hey everybody, welcome to Techstrong gang. As always, we got a lot to talk about with some really smart people. So let me introduce these folks.
So let's start with Anne Anne Ahola Ward Ward. Anne, how are you? Wonderful, thank you.
Good to see you. Sid Nag, good to see you as always. I know you've been traveling lately, so thanks for joining us.
Good to see you, Mike. Good morning, everyone. All right.
Kate Scarcella looks to be at home based on all the books in the back of the room. Yes. All right.
And Chris Blask, that is the Canadian motif, right, that I'm seeing there? It's not my fault, that's all I want to say. All right, there you go.
Well, there is so much going on these days, it's hard to decide what to talk about. And I can remember not too long ago that I was scrambling for topics, and now every day I'm trying to figure out between 10, which of the three we're actually going to talk about. And of course, what's dominating the conversation these days is Anthropic has tendered an IPO for a cool $1 trillion.
And then, OpenAI is supposed to do something similar, and I guess we're betting that it'll probably be bigger than Anthropic. And Alphabet, of course, tossed its hat in this thing and said that it too is looking to raise $80 billion to drive its AI investments. Sid, I don't know, is there enough money in the world to, A, fund all this, and B, it's starting to feel like a money pit.
Are we just throwing AI into this big hole here and digging a big hole and throwing money in it, or are they actually going to use this stuff? Great question. The IPO market's lighting up fire.
It's very interesting times. And it's interesting because I look at it as a transition from venture funding and the excitement around public and private equity and that kind of stuff, to more of a shift to what I call the public market asset class. It's no longer about VC evaluations.
It's no longer about investments here and there. These are serious investments that are going to create a new asset class by itself. And I think the approaching Anthropic is about a trillion valuation, which is just mind-boggling.
Mm-hmm. And OpenAI is not far behind. So there's a little bit of competition going on between the two, obviously, from this standpoint.
But what is really noteworthy, I think, is the fact that we're going to see hyperscaler valuations to frontier AI model companies. To me, these are like software companies in many ways, model builders, but now software companies are getting the valuations of hyperscalers that have invested billions and trillions of dollars in CapEx over the years. So it's going to be interesting how that sort of plays out.
The other noteworthy point that I wanted to talk about is really, we're seeing these guys shift to the infrastructure play. So historically, we saw model builders focus on software, but now they are very much focused on infrastructure, so that's going to be an interesting shift. And then as far as the Alphabet story is concerned, I'm very wondering what the strategy there is because Alphabet has no shortage of cash.
So for them to go and leverage a new venture, if you will, that has a infusion of cash from a outside entity and then there's some dilution elements to that, obviously, from a total ownership perspective. So that's going to be very interesting to watch. So I think my overall feedback to this whole phenomenon is, shift from venture funding to public class asset markets, and then the shift from AI builders focused on software to being more of a hybrid, and I know you guys are going to talk about this in the Nvidia story, hybrid model where software infrastructure and all of these things going to come together, and the willingness of the model builders to participate in that sort of vector.
And then, the fact that these big guys are really, Google especially, Alphabet especially, are willing to work with other companies to bolster their infrastructure story when they could've done it all themselves. So I think this is the cooperation model shining brightly. So we'll see how this plays out.
All right. Anne, what's your take on all this? I think the timing of this IPO is very telling because they're going public before anyone else has won in the foundational model race, which tells me they either believe the window is now or they need the capital to stay competitive.
But I think it's a vindication of the safety first regime, because in the beginning it seemed like a handicap to be the safety first platform, but now it's actually probably more of an advantage as people are kind of weird about it. But I think the real secret weapon behind an IPO is that it's a legitimacy weapon, and tertiary benefit recruiting. Because it's going to be harder for that key talent, which there's a lot on the street with all these layoffs.
It's harder for talent to open it because it reads as a private chaos sort of vibe versus a publicly accountable, legitimate competitor. So I think it's going to give them an edge, quite honestly, and it is probably going to be the largest IPO in tech history, which is also kind of exciting. At least for this week anyway.
We'll see what comes next week. Well, the others decide. But I do think that this is absolute.
There's a calculated risk they're making, and they'll probably win. But the IPO also is a cash-raising effort, right? That's really what they're trying to do.
They're trying to get the public to participate in their generation of cash so that they can invest in the long-term strategy, right? So as opposed to the alphabet story where they're working with, I think, forget, who's the company that's investing $80 billion, right? It's a third party.
So there's two ways for generating cash. One is through the public markets, which is an IPO, and the other is through partnering with a very cash-rich sort of entity in the investment market and generate the cash that way. So it's going to be very interesting.
Yeah. I said or, but it's probably an and/or versus an either/or- Exactly ... to stay competitive.
Yeah. Agreed. Kate, you want to weigh in?
Let's talk about the money pit. To me, this is a money pit. I think that we are building a centralized model when I know, I believe, prediction-wise, by the end of the year, so much of this will be decentralized.
And we may not want to talk about this, but we will be a decentralized AI models in, we are already seeing the move as we go to local LLMs. Mr. Chris Blask.
Right? Come on. Are we not going to local LLMs?
Is it not becoming more important to have these small models, especially as we look at verticals like pharmaceuticals. And from a cybersecurity point of view, having a local LLM is better. But it's better for who?
Better for the end user or better for the giant tech company that's cashing in? It's- It's better for the local end user and companies, I believe, yeah, at the end of the day. And I think it's better from a cybersecurity point of view.
And that matters. Cybersecurity can't be a bolt-on for AI. It has to be in the beginning and decentralized.
Decentralize. You heard it first. Right.
I agree with you. There's another fly in this ointment, right? There's an op-ed in "The Times" earlier this week talking about the need for a public frontier model that is not owned by some private company.
And then Bernie Sanders is throwing his hat in this conversation, and he's pretty much saying the same thing, and that we need something that is owned by, quote-unquote, "the people" and not the private sector because these things are too dangerous and too important. Chris, you are a Republican hippie. What do you think?
It's interesting, right? So the thing that's most on my mind this week since last week, we're having the same conversation, is last Wednesday I gave a talk at the Standards Council of Canada, has a working group working on a technical specification, the ISO IEC specification for systems of AI systems. Right?
And Kate, this is where you're starting to go with this, and then block B, I think we'll get back to this again, because we have this, and it's fascinating for me, right, because I get to have this privilege of being part of these conversations over the years where people are getting together trying to figure out what everybody else is writing articles about. Right? And I can tell you, there's no answer.
" Right? And just right now, as we speak, that strata of the world is going, "Oh, the evidentiary layer," right? How do we actually keep records for things?
Which is sort of my own soapbox. But it leads back into this question, right? Sid, you talked about this.
We're in this space where we're putting infrastructure-level money into tech. Highways, power grid money. What does that mean?
Is that a good idea? Maybe. Anything's possible.
But if we compare it against other infrastructure plays, the US interstate system took decades to build. We use it all the time. It's still there.
And what we're talking about is spending a lot of money on equipment that has a couple years lifespan, and then we've got to buy it again. Is that sustainable by itself? And then Kate, back to our sort of favorite topic, I think it's just better, faster, cheaper to run almost all this stuff locally.
Local. It's just easier, safer, faster, simpler. It works better on every level.
So where is the room for this in, for a trillion-dollar mega... And models, just generating a model. Bless your heart, Bernie Sanders.
I get you. Good heart. But the models hardly matter.
They don't matter that much. We don't need to spend a trillion dollars making a new model for the people. It's how is the governance system we put around this technically and economically that'll see how it plays out.
We need it that much- Kate, one of the things that- ... as we needed Al Gore to open source the web. I think Kate- That's a good one, Anne.
Good one. Hit that spot on. Local LLM is the way to go.
It's going to be the future, right? People want more control on their data. Uh-huh.
People want more sovereignty. They operate in regulated industries. That's where local LLMs are going to matter.
So the question is: What is the role of the public frontier model builder like OpenAI, sorry, Anthropic or OpenAI or even Gemini in Google, right? SoI think those things still will have a major play because the local LLMs that are going to be used, that are going to proliferate over the long term, are going to be curated at a derivative of those frontier models. That's where the first cut is going to be.
So if that first cut is really rich and high fidelity, that's a plus, right? And then you inject your company specific, enterprise specific data into Zella, and run training and inferencing and all that all over again. But I think there's going to be an opportunity for both sort of models.
And at the end of the day, it remains to be seen whether we need a government-funded or government-blessed public model. I think that's a non-starter. It's not going to happen.
We tried to do this in the cloud world. It never happened. Europe tried to do it in their domain with sovereign clouds.
To date, I have not seen Europe even come up with a cloud model that competes with Amazon, Google, or Microsoft as an artifact of their pursuit of a sovereign cloud. So I don't think the government is going to play any major role in any of this. Well, I mean- All right.
So one of the things that you will get out of this is transparency, and we'll see what exactly Anthropic and OpenAI are investing in, and there'll be more clarity. And I cannot help but wonder if right now we've created this kind of like, "Oh, well, these are the hot next new things to invest in," in NVIDIA, and there's a phrase about what happens to someone's money and whether they're foolish or not, and we'll see how that goes. And I don't pretend to be a Wall Street analyst because, well, what happens on Wall Street and fundamentals don't have much to do with each other anymore.
It's as much about how I feel about something, as much as it is what the revenue numbers that were generated were. But I cannot help but wonder if, I don't know, Sid, I'll throw this back to you. As an analyst, if we start looking at these numbers that are being generated, that more rational evaluations will be made.
What do you think? Yeah, it remains to be seen what reaction we get. This is breaking new ground, right?
What kind of reaction we get from a public market perspective to these IPOs, right? We've seen time and again these sort of... I don't want to be too flippant by calling them flash in the pan IPOs, where there's a lot of hype around them without any sort of solid numbers to back those things up with from a potential revenue-generating perspective, profitability perspective, all of that.
Clearly, those factors are not in place in this particular example, right? Profitability and there's revenue being generated, but we don't know what the profitability numbers look like. So I think it's going to be interesting to watch when these guys have actually launched their IPO effort to see how the public markets react.
I'm guessing there's going to be a lot of enthusiasm initially in terms of pricing of these shares. And then over time, to some of the points the panel has already discussed around local LLMs and other things, that will wane, right? And so I think there's going to be more sort of, the rational exuberance phase will sort of subside, and I think we're going to see some flattening of the share price of these IPOs to a more realistic level.
And I think that's really where it's all going to end up. So it'll be interesting to watch. I don't have a crystal ball, but that's my take.
I want to go back to decentralization for a minute because I'm kind of obsessed with the concept as a person in crypto for a very long time. I think it's smart, and I think it's what we should do, and I agree with you, Kate. I just think that the model for this I would copy or mimic would be social media, right?
We have the ActivityPub standard. Threads, which is offered by Meta, 400 million active users. It follows, you can use ActivityPub, and a very small fraction does because I don't think the general public understands the point of decentralization, and I don't think people care as long as it works.
I really don't. Yeah. And I wanted ActivityPub to work.
I was a faithful Mastodon user for a long time, but it was a lonely world. They had a great month when everyone was mad at Elon buying Twitter. But aside from that, it's been a lot of starts and stops.
And so I look at that as a model for what is happening here. I think Europe is ahead of us, especially with Mistral, what they're doing. I just can't see it.
I want it to be true, but I just can't see it happening. All right. Well, let's take this minute to shift the gear because, well, the next block is about the same topic in decentralization.
So let's just make that shift. But you may not be alone. Jensen Huang is hanging out in Taipei this past week and launching new PCs and also pushing AI out for the Edge.
And basically, he's saying that we're going to use Arm-based processors and not only have PCs, but everything at the Edge, including robots that will be running various AI algorithms. And so, maybe he's already betting against that counter-centralization move as it is there, or at least he's already benefited from as much as he thinks he's going to be, and now it's all about distributed computing. What do you think, Chris?
Bring the toys. Why not? You see, everything evolves over time.
I don't understand where this company was. Remember they used to make video cards, right? NVIDIA video cards.
Those back before the AI day. Yeah. And it turns out, that kind of math is really good for large language models and vector stores and whatnot.
So we're used to them being the AI hardware vendor, butObviously, they're trying to evolve into the ecosystem, the infrastructure vendor. Right? And from my perspective, and I think Anne, Kate, the whole decentralized thing, I'll tell you how we look at it.
I look at it like various layers of strata. Can we have proper, good, ethical, profitable, efficient systems on top of the existing strata that's out there? And the hardware infrastructure that's out there now, short answer is yes.
You can hack your way through all that. It matters what the individual vendors do, but you just take that as a given. This is the landscape.
Can I run my systems on top of that? So NVIDIA going down this path and so distributed, yes. Local LLMs, local processing, local workflows everywhere, quarter to quarter.
It's happening now. Right? By the time the anniversary of this show a year from now, it'll be one of those things like since everybody's doing that, that's the preface for the block, not are we going to do this?
Is NVIDIA going to be successful? They got a lot of money and they're good folks building good hardware. They'll probably sell a lot a year.
I will probably buy some. All right. I- Go ahead.
Go ahead. So I actually, from a cybersecurity point of view, I think this changes the game. And if we don't start to change the way we address vulnerabilities and everything else within cybersecurity, we are really...
I'm not trying to be a doomsday person, but wow, we are really in trouble. And the reason being is because we actually have basically endpoints that are moving with no human, it's not like our phones that are in our hands, that move with us. These are autonomous devices that are moving.
And we have to look at cybersecurity differently and not the way that we are used to. So I think that for me, the bigger discussion around here actually then goes into C, as we talk about cybersecurity and now what happens. Well, I think that these two things between, I'm going to call them big AI and little AI, are not mutually exclusive.
And I think that they are one computing fabric, and what we're going to wind up seeing is it will be better from a performance standpoint and a result standpoint to run as much AI locally as you can. And if that means at the very edge, great. And if that means on my PC, super.
But there's going to be times when I need to do something that may be just bigger than what my machine can handle. So I'm going to go and call an API somewhere and send up a job to big AI, AKA, I think we used to call that batch processing back in the day, but it'll be some kind of feel of that kind of nature. And then I'll get some sort of result back, hopefully a lot faster than I used to back in the day.
And it will all be integrated in one seamless architecture. But, Sid, I'll ask you, is the name of the game then going to be determining maybe I'll have a separate AI algorithm that will tell me where I should run this thing based on how much it's going to cost me and what my latency requirements are. That might be good old-fashioned distributed computing, but is that where we're going?
Yeah, definitely distributed computing is the new thinking, right? It's old thinking being reassumed in the word AI. So if you notice, NVIDIA also released the Vera- Mm-hmm ...
again. Yeah. Which essentially to me is a hybrid of GPUs, CPUs, and other processing units, right?
So that's interesting. So they're recognizing the fact that servicing AI is not just servicing a need to multiply large matrices to address generative AI, LLM needs, but it's also about agentic agents running around that may not need the horsepower of a GPU, like a H100 that costs the price of a Honda Civic, right? So you could get away with using CPU.
So it's going to be a hybrid world, and I think that's where NVIDIA is going with the Vera sort of effort, right? So yes, it's going to be very, very different than what we've seen before. But they also talked about this, I think one of the stories, links you sent, Mike, is about the humanoid robot, right?
So, that's an interesting move. I think it's sort of signaling that the industry is moving beyond generative AI to, what I think Jensen Huang called it, physical AI, right? So, the goal is not simply building...
I don't think it's anything to do with robots. Of course, that is a key story, but it's really creating a common platform for developers, researchers, manufacturers to build intelligent machines, right? And that's going to be, if these things are going to indeed replace humans, it's not just a robotic conversation, it's more about a very, very smart machine that is used by different constituents in the list that I just sort of rattled off, right?
So, and if that's the direction that we are moving as a society and NVIDIA wants to participate in that, obviously, as Kate mentioned earlier, security and trust are going to be extremely important. So NVIDIA's actually embedding things like secure boot, authenticated software updates, confidential computing into these robots, right? So it's going to be very interesting to watch that piece.
And thirdly, there's a geopolitical aspect to this conversation where I think China has sort of advanced their robotics technology so far ahead, and we've kind of fallen behind a little bit. So Jensen's kind of playing both sides. He's obviously partnering with the Chinese, but he also wants to create an environment within the US where he has aHe has a role to play from a revenue and other perspectives in that market.
So it'll be very interesting to watch the robotic piece, and then also the fact that some of these robots are going to be driven through agentic, the role of agentic, the role of the CPU in the servicing of agentic as opposed to traditional GPU market that NVIDIA's participated in. So it can be very interesting and complex. I would- I'd go one step further and say that GPUs are going to emerge as the compute resource of last resort.
And I will go back in time and say, GPUs were invented to run graphics, and the fact that they happen to work well to train AI models was a happy accident. And now we're going to go back in and actually engineer the processors underneath to optimize them to run AI training, and that might not be a GPU at the end of the day. And this Vera thing is interesting because it's really a hybrid, to Sid's point, and maybe it's the first in a series of things that are going to take us beyond GPUs, and then therefore, it's anybody's game.
Chris, how crazy am I? You look at the efficiencies of scale, and I say GU is the key term right here. Common platform.
And to be clear, all these companies, bless their hearts, are trying to be the common platform we all go to. I don't think that's a thing. I think you get the same efficiencies with common architectures.
And this is back to where, Kate, this is your point, right? That I've thought for a long time, by now, we had to have this ability, and I'm telling you, we do now. Where you can take an individual computer and have a DevSecOps team in it.
That one individual computer with its own team of agent systems and so forth are doing all of the cybersecurity things. Literally reading all of the documents, keeping them on hand, coming up with all the plans, executing them, iterating those, evolving those internally to one computer, right? That's a thing today, right?
So we can't do that across a single enterprise with all the money on Earth, because we have timing and logistics, and so forth. So, when you start from the node, when you start from the local standpoint, you find out you don't need that many features. Yeah.
A centralized platform has to have every feature any possible user could imagine. Your system only needs to have the features you actually need. Literally, only that code.
Doesn't need the rest of the code. And it can have its own process, have its own teams. So, I think we're playing out evolution on the calorie scale, right?
Yeah. Can you pour enough calories, enough dollars, enough electrons into a centralized model to make it more efficient than what, frankly, nature has shown works all the time forever? I love it, Chris.
Right on. I'm going to leave that one there, but there's an old adage in IT. It must be 30 or 40 years old, and I think it's still true.
You marry your software vendor, but you only date your hardware vendor, so act accordingly. One other point. I think the fact that NVIDIA is going after this- Yeah ...
hybrid market, which includes GPUs, CPUs, et cetera, which I think is the right way to think about the problem. You got Alphabet, which, I'm getting back to the earlier story, marching right ahead promoting their TPUs, which is a tensor processing unit, building them, partnering with Meta and a whole host of other players. So that's interesting.
And you got Amazon or AWS promoting Inferentia and Trainium. So those guys are not talking CPUs at all. So it's going to be very interesting where this thing lands.
It's going to be an interesting hardware world. Right. All right.
We're going to move on to the C block because Kate can't wait for this one, so here we go. Yeah, so go ahead. " But there's been this kind of 90-day window between when somebody discovers something, and then they tell the vendor who's affected, and they give them 90 days to come up with a patch.
" There's a dispute going on. Some of the folks in the security research space are now disclosing vulnerabilities sooner than later, and that has to do a lot with the rise of Mythos and these other AI models, where the assumption is that these exploits are going to be discovered, and there's not going to be much warning, and we're going to have to resort to maybe something that feels like automated patching. We'll see how that turns out.
But Kate, is this the new reality, or is this an exception here where somebody just kind of broke the gentleman's agreement and everybody's in a huff? Yeah. I feel like that everyone's been in a huff, and this gentleman's agreement has been around actually forever.
I think that there's always been this fight, and it's really not anything new. Microsoft's saying it's irresponsible, putting the customer at risk, and researchers saying Microsoft ignored reports and failed to engage. That discussion, not only just around Microsoft, but around Apple.
I remember IBM mainframes and there being four vulnerabilities, and just this outrage. For me, it's much deeper, because it talks about a social contract between security researchers and vendors. That's breaking down.
And this loss of trust that we have across the board is now impacting cybersecurity architects and researchers, and everything ... is going into chaos. And I think that's somewhat more concerning for me, is we always expect people, I don't know why we expect people to do the right thing, and companies and everything else to do the right thing, but typically we don't because, money, and we see this breakdown even more.
We see a breakdown of, "We don't care. " And I think it's wrong. I think there's a certain- Do you think that this is- ...
amount of hubris in this conversation because the hubris is that the bad guys haven't already figured out that this vulnerability exists and is being exploited anyway, and that somehow or other, the researchers were the first one to discover this, which I think is highly unlikely. Yeah. " I'm going to say the bad guys already know.
Already know. I have a question for Kate. I think that there's so many attack vectors here- Yeah ...
that I wonder, do you think that vendors are going to start seeing researchers as threats because of this versus partners? I mean, is that- I think- Or is that already happening? Well, go ahead, Chris.
You want to...? Well, yes, okay, so in 1999, sorry, work mode. Running the Cisco firewalls, we were a year into building trust because we had broken every promise for two and a half years.
And a security researcher found a vulnerability in the Pix firewall. It was real, it was bad, it was our fault. Right?
And I talked to that individual and said, "All right. " And the person agreed. And I said, "We'll put the Cisco brand behind your name.
" And he agreed. And within 24 hours, that person released it. I have not said that person's name ever since.
Right? I'll go this far. The last name started with an O.
I actually haven't seen that person's name in the industry either since. Right? And this all comes down to trust.
And I want to specifically call out the individual human working at Microsoft who decided to give that release. Shame on you. And that was not just a stupid move.
And it was, right? You just confirmed every mistrust people have of your company. Don't do that.
Take responsibility. Understand how trust actually works. But I think to Ann's point, Chris, so I think researchers are almost being looked at as the enemy in this new world that we have entered.
And it's not that, because I think that companies are not standing up the way they're supposed to stand up. " But I think almost everybody's a bad guy and nobody's doing what they're supposed to be doing. And we better, all of us on this call right here, and people who are listening, man, let's change this narrative.
Let's start to be the good guys that really change this. If I were to add anything here. Well, let me just fix my story because that's the only example in 35 years, because that was a researcher who did the wrong thing.
I am a researcher. We do this all the time. You should be able to trust the companies you're working with.
And this move by Microsoft breaks the trust. It demonstrates, you're saying as a big corporate entity, that you see researchers as the enemy. Yeah.
To your point, Kate. You can't do that. The wicked flee when none pursueth.
Yeah, I think it's a matter of responsible research, right? I've been a researcher before, right? In that researchers should be extremely, extremely careful not to release proof of concept code that could open up...
Again, I'm not a security expert, that opens up vulnerabilities, right? So I think it all boils down to, from my perspective, is responsible research, right? If you get into this heated competition of making yourself look good, and in that sort of race, you release code that is going to cause unnecessary headaches, that to me, that's irresponsible research, right?
Now, yes, to Chris's point, Microsoft probably came on too heavy-handed in the situation. That could stifle research. That's the other side of the conversation, but I think there's an element of responsible research that needs to be a part of the conversation.
So, Kate, let's argue the other side of this for a minute. " And maybe that's not necessarily as helpful as it could be. Well, what I'll say to that is, let's just put them up against AI and let's see who wins at the end of the day.
Right? And I'll- Yeah, this is almost becoming a mute point, all of it, because AI is going to... " That's out the door.
I mean, that's gone. With AI especially, that's gone. The discussion needs to be, as I've said millions of times, "Let's get rid of the bad code.
There's so much bad code out there. Let's throw it out. Let's throw out the water.
Let's throw out the baby. " So. So you're saying we should declare bankruptcy on our technical debt?
Yes. I like that one. Yes.
Mm-hmm. That's a great way to put it, Ann. Thank you.
And I'm sorry, I'm going to come back- Can you pronounce your last name? I'm sorry about bouncing in my seat because this is... So Sid, no, I want to push back on that entirely.
Mike, your point. No, the bad guys, look, I know how to break all of your things already. If I don't, p**s me off and I will figure it out.
The bad guys know. There is nothing a security researcher can say to anyone. If you have risks and you're not aware of them, then you have risks and you're not aware of them, period.
Publish. And yeah, AI, anybody can do this these days. Anyone.
So yeah, some researcher, some human researcher. Back to my point, you have human trust. We have humans behind these systems and always will.
If you're a researcher and you find something and you think there's someone behind you can talk to, try to talk to them. If they lie to you, burn them to the ground. And if you're a vendor and someone reaches out to you, respect them.
Talk to them. Right? I- They may not tell you anything you didn't know, but that's how you build systems, damn it.
I think the conversation that we're having around security is something that AI will eventually evolve to, right? Right now, everyone's enamored by AI. They're kind of ignoring some of the exact points that people are talking about in the world of security.
And I don't know, I still think there's a role for responsible research, just like there's a role for responsible AI that we talk about in the AI context, but we don't do much about it. " People are kind of talking about it in very flippant ways today, or sort of in loose ways. But eventually, when AI becomes that, it goes beyond the model builders and hyperscalers investing $50 and $80 billion to actual utilization by the end users and the enterprises, where supply and demand can have that impedance match as opposed to the impedance mismatch we have today.
That's when I think AI is going to have the same sort of issues that we're talking about in the context of security. But I think, actually, Sid, that the conversation needs to go around, in all due seriousness, around software bloating and reachability. These are the key terms that we need to actually start to talk about, and not CVEs and CVSS scores and these other things.
I honestly think that if we were to put our resources, human and AI, into software bloating and reachability, I think we would be having a different discussion today, personally. So the part that I don't get- Okay ... and let me make sure I understand this, because, man, I might be missing the point here.
But so now you're this big company, and you put out some software that either you knew or you at least suspected might have been flawed, and now that someone has come up with AI and is exposing all these flaws on software that you made billions of dollars on, you are crying foul. " Because basically, you went out there, you took the chance, you took the risk, and now you're kind of having to pay for it. " It's not the security researcher's fault.
It's the person who built the software. Am I not wrong, Kate, here? Or am I losing my mind?
No, I love that plain talk, Mike. It makes so much sense. We have thrown common sense out the window.
I don't know. You can build a model just on what you said. A framework, Mike.
Vizard's framework. Right there. It's beautiful.
I'm going to go a step further. So maybe these companies should create a technical debt bank fund somewhere. It's called the rainy day money fund.
You put aside money to pay for the fact that there's unknown vulnerabilities in your software that you are probably going to have to fix, and it's a down payment on that debt. So I don't know. It seems kind of rational to me, but the assumption should be that the software is probably not working as advertised.
Just saying. I think to kind of support Chris's pushback, it's easy for Microsoft to go after these sort of individual researchers and do what they did, but it's obviously difficult. So shifting the conversation from the security paradigm to the AI paradigm, they don't have anything.
They didn't push back when OpenAI had all these problems with their AI models in terms of hallucinations, security vulnerabilities around prompt injection, jailbreaking, adversarial attacks, all of that. They didn't do any of that to OpenAI, just kind of went along, right? Because they're the big 1,200-pound gorilla.
It's easy to go after a small researcher, right? So that's another interesting aspect of this whole conversation, I think. Oh, yeah.
You want to display weakness, be strong and go after the small, right? Yeah. Yeah.
Yeah. And that's a framework, too, right, Chris? Oh, yeah.
Yeah. It shows me you're vulnerable. I'd feel better.
If I was competing against Microsoft, that would just give me comfort. Go ahead. So I think the next logical thing in all of this is to call all those execs back up in front of those congressional hearings in Congress that they all appeared at a few years ago and have this conversation over again.
But then when they leave the room, can we not invite the security researchers to that same discussion and hear what they have to say about how all this works? Because I'm pretty sure it would be eye-opening. Wouldn't you say, Chris?
Yes. And they have, right? And we managed not to talk current administration too much, right?
So today, who knows? But the US federal public sector has been quite good, actually, over the decades in engaging and bringing people in. Shout-out to Winn Schwartau, who's out there pushing good things and gave the first talk, I think, for cybersecurity to a congressional body.
Yeah. So public sectors all around the world should continue to be aware of these issues, right? If you have risks, like the US does at a nation-state level, because your systems may be brittle and fragile, like you're putting too much trust in a handful of centralized economic entities, other entities may out-compete you.
So yes, Mike, yes. They should talk to them all. Figure it out.
You're big kids. Do we need to tell you this? You're elected.
You get paid for it. Yeah. And you're a big company, and you get paid for that, too.
So it's all part and parcel of the risk that went with the equation in the first place. But there you have it. Hey, I want to tie all this together because what connects all these things is every action has an opposite and equal reaction, and sometimes that opposite reaction actually is more powerful than the original action.
So stay tuned. We'll see how all this plays out. I want to thank our guests for sharing their knowledge and insights.
As always, they're inevitably much smarter than I am, which is a pleasure to talk to. And I want to thank you all for spending some time with us, and please stay tuned for the rest of the lineup for the Techstrong TV episodes that are coming behind us, or at least the replays. And with that, I'm going to say goodbye to everybody and hope to see you again tomorrow.