China Data Center Ban, Digital Self-Defense, and the Tokenomics Foundation Launch
On this episode of Techstrong Gang, host Mike Vizard is joined by Jeff Reich, Barbara Roos and Fred Wilmot to dig into three stories shaping the security and open source landscape. The panel covers a possible data center ban on Chinese-made equipment, a legal case testing the limits of digital self-defense, and the launch of a new foundation built to govern token-based funding models for open source projects. Each topic gets a close look at what it means for enterprise buyers, developers and policy makers alike.
The Case for a Data Center Ban
The Trump administration is weighing a broad ban on Chinese-made data center equipment. Officials worry that gear sourced from Chinese vendors could carry hidden risks into critical infrastructure. A potential data center ban would force many operators to rethink their supply chains almost overnight.
The panel notes the timing is not coincidental. VulnCheck recently disclosed a backdoor in Chinese-made Zbtlink routers, giving fresh urgency to the data center ban debate. Guests argue that hardware provenance now matters as much as software patching when it comes to trust.
Digital Self-Defense and Data Rights
Jeff Reich and Barbara Roos discuss a case that could redefine data rights. The Sam Tunick case tests the legal limits of digital self-defense when a person acts to secure their own exposed data. Courts must decide where personal protection ends and unauthorized access begins.
The group agrees the outcome will ripple far beyond one individual. Clearer rules could give ordinary users more confidence to act when their own information is at risk, without fear of prosecution.
Tokenomics Explained: Governing Open Source Funding
Fred Wilmot walks through why the Linux Foundation just formally launched the Tokenomics Foundation. The new body aims to bring governance and structure to token-based funding models for open source work. Tokenomics, done well, could give maintainers a sustainable way to fund long-term projects.
Panelists caution that governance is the hard part. Without clear rules, token-based incentives can distort priorities. A thoughtful tokenomics framework, they say, is what will decide whether this experiment actually helps open source communities thrive.
From a looming data center ban to a courtroom test of digital self-defense and a fresh approach to funding open source, this episode covers a lot of ground. Mike Vizard and the panel remind viewers that policy, security and community funding are becoming increasingly intertwined. Watch the full conversation for the details behind each story.
Transcript
Hey, everybody. Happy Friday. Welcome to the Techstrong gang, and today is a unique Friday because, well, it's my birthday, so I got a bunch of folks here to help me celebrate.
We're going to have a little chat about a lot of things related to security and AI and all kinds of fun stuff, but let me introduce our gang members today. Fred Wilmot, how you doing? Happy birthday, Mike.
Thank you very much. Very nice. Barbara, it's been a little while.
How are you? I'm great, and happy birthday to you. All right.
Jack Poller, as always, good to see you. Good to see you. Happy birthday, one year older.
There you go. And Jeff Reich. Jeff, it's some sort of national celebrated day besides my birthday- Yes ...
so what's going on? What's out there? Happy birthday.
And for the benefit of the audience, I sang happy birthday prior- ... to going live, and it's National Lighthouse Day. That's the Portland Head Lighthouse in Cape Elizabeth, Maine.
The oldest lighthouse in the US, authorized for building by George Washington. All right. Well, sometimes I feel like I got to pay you guys for these transitions, but let's shed some light on this next topic.
What do you say? Our current discussion is about, well, the Trump administration is talking about banning certain equipment from China in our data centers, and a lot of the conversation seems to be specifically focusing on our networking gear. And then there was an incident where there was a report that said that routers from China, and I forgot the name of the company, but they were infected with various elements of malware and therefore we shouldn't use that.
I think you can read it below here. I can't even pronounce that. Zbtlink.
But a vulnerability check found these kind of issues, and it's not the first time we've seen these issues before, and I can't help but wonder if there's malware in all our networking gear and all our data center gear, but I also wonder if we give as good as we get sometimes. But Jack, what's your take on what's going on here? Because the first thing that came to mind to me was, is any of this actually feasible?
Well, so that's what a lot of people think, and as you mentioned, and you reminded us before the show in the green room, we have talked about this in a couple of different places before. So we have talked about the fact that Israel banned certain Chinese-manufactured vehicles from their military bases. They'd originally given those to their officer corps, and they actually pulled them back from their officer corps and banned them because they were basically floating spy cameras, right?
So you had cameras around the vehicle and network connections, and they were concerned what it was sending back to where, and it's impossible to figure that out. One of the Scandinavian countries, if I recall correctly, we did a story almost a year ago maybe on Norway. " And then, this is the Zbtid or whatever.
95 or whatever it is that looks too good to be true. And part of why it's too good to be true is apparently it has a backdoor built in that phones home to China or to wherever home happens to be once every minute or so. So there's a lot of stuff.
Now then, that sort of is all the background to this thing with Trump and the data centers, and specifically they were looking at, excuse me, optical transceivers. Now you may think about it and you say an optical transceiver is just a device that converts the digital data from electronics to optical light so you can transmit it, and typically inside a data center, it's only a short haul, but you can use the exact same transceivers to transmit things over thousands of miles. It's how data gets from one side of the country to the other and all the way around the world.
These optical transceivers actually have small computers inside them to do that work. They actually have a little tiny computer inside it. It is conceivable that you could have a backdoor embedded in that that understands what data is going across the network and is able to siphon some of that critical data off, potentially, let's say, for interest, a security key that would then allow whoever that data is going to, to decrypt data at a later date.
So there is a theoretical risk there. Whether we've actually seen the risk or not, I don't believe we have. Nothing I'm aware of today, but there is a theoretical risk there, and I think we have a fairly high level of confidence that China is a political and geopolitical adversary and is doing whatever it can to make our lives more difficult.
Yeah. But I will just say one last thing, which is, do we give as good as we get? I'll never know, but I sure hope so.
Mm-hmm. Yeah. I think there might be backdoors into everything, and I guess, Jeff, part of my problem here is, what exactly would we put in our data centers if we were to rip out all the things that have origination points in China?
Because even the so-called Made in America gear from HP or Dell or whoever's putting it out there, it's got components that come from China. At some place, or other parts that may not be as friendly to the US as we would like them to be. Mm-hmm.
So when you add all that together, in my opinion, I get the intent But if you're looking at the country source, you're kind of ignoring the bigger problem, because the bigger problem is: are these devices doing what they're intended to do and nothing else? " So although I get the intent, I really have trouble believing this is going to solve the problem. And as Jack said, that problem might be in air quotes.
Sure enough. Fred, does any of this keep you up at night, or is this just so big an issue or so big a problem that it's beyond the ability to actually reckon with, so you just wind up ignoring it? Well-framed.
I think a lot of folks would say that that's probably a good reason to look into where those typhoons get root holds. We already have more than 100,000 devices of these deployed globally in all telecoms. How much do US telecoms actually benefit or how much detriment?
But the counterargument to that is, China is also already sanitizing their networks of American-made networking gear for the same reasons. There's a real case to be made for what it means to be able to split light instead of having to just steal electrons for the value of whether it's training models or sensitivity of intelligence information, traffic capture, all kinds of things. And it's a good place to do it in the grand scheme of things.
But I think there's a significant cost to pay here. There's already deployed technology. Does it keep me up?
Sure. Absolutely. There's a thing about spying on Americans, only we're allowed to do that, right?
There you go. Barbara, let me ask you something. I have sat in the room with C-level executives, and I have listened to them bemoan the fact that a lot of our IP is finding its way overseas through various illicit activities.
They have competitors in China that suddenly wake up one morning, and they have suddenly reverse engineered some product or thing that they or company had been building for years, and everybody's upset that they're not going to get their ROI. And yet, if you look at it, at least on the face of it, it would appear that maybe we're just making it too easy for that to happen because our data centers are just rife with stuff that is transmitting all that lovely IP somewhere. So, are C-level business executives aware of the conversation?
Are they lobbying the administration? What do you hear from them? Oh, gosh.
I think if they're aware of it, they're choosing to stick their head in the sand, honestly. I think part of the temptation of this ban as a solution is it's cheap, and it's easy. And I think that the more expensive and obvious solution is what Jeff was talking about, actual testing, but that takes people, that takes time, that takes skill, and it takes cost.
And I don't think they want the burden of that cost. And so what feels like an easy solution, this ban, will give people a false sense of comfort. But the reality is, it is false.
Slapping a ban on a specific country, anybody that lived through navigating the complexity of Trump's tariffs understands how complicated these supply chains are, how complicated it is to identify true country of origin for parts that are made, assembled here, manufactured there, validated somewhere else. It may have moved through so many countries you just have no idea, and it's going to create a false sense of security. Mm-hmm.
Is it feasible, and I guess I'll throw this out to Jack, but can I take my most important IP and put that on a set of infrastructure that I know is clean, and then I'll just run my day-to-day business stuff on the usual gear. But can I create some level of isolation around my most important IP and run it in a data center that, I don't know, looks like a Faraday cage? Can I do that?
There is an argument to be said for that. The challenge with that is if all of your intellectual property, all of your crown jewels, if you put all of your crown jewels in a safe, how do you use them? So, you need that intellectual IP.
You need to do something with it. Sitting in a data center somewhere, for many years, there's Tempest computers. I think I've talked about this before as well.
Tempest shielding is basically a giant Faraday cage. People do stuff in it. I actually had a job interview when I was a young, fresh-out-of-college engineer to work on a project where you would sit at your desk, hand-write your code.
When you figured it out and you thought you had it right, you would go all the way down to the basement, you'd open the door, you'd go into the Faraday cage, the Tempest shielded computer, you'd write your code. And then when you'd go back and forth, back and forth, that was your debug cycle, so running up and down the stairs. And when you were all done, you would take it on a nine-track tape, and you'd drive it to the Pentagon, where it would sit in another computer in a Faraday cage.
And that did not look like a fun job to me. But again, my point is, if you put all of your goodies in the safe, you got to open the door to the safe to get to them and do something with them. And so this has always been the challenge is we are in a data economy, and the only way the economy works is if data moves.
And if data moves, it's going to be exposed to somebody who wants it. Right. Fred, can I approach this problem from a software perspective?
Can I isolate my data and my code and my applications from that underlying infrastructure that might be compromised? So in this particular case, this is one of the important parts about this. This is what we send over all the SONET rings and all the fiber and all of these places, right?
So this is network service providers and big bandwidth problem space. The hard part about splitting a light, even with a system that gives you access to it, is it's very hard to see that really, what the impact of that is. And the average company in sort of the mid-market or middle market, SMB markets, don't probably have a lot of this gear sitting around, right?
They're subject to the network they subscribe to. So you don't have the luxury necessarily of all of that. Can you wrap all of your data in VPNs and encryption?
Sure, for the transit part of this. But at some point in time, that's got to be opened up, right? And keys used to do that.
So the reality of that is it's probably not without significant cost and additional gear. And the reality for service providers is there's probably an interest in supporting. There's a cost when network gear is tapped, an unknown cost.
And historically, we did some of this with trains, where backhaul service providers, a number of different ways to connect up to trains or locomotives for positive train control, all operational technology has this too. But the reality is a lot of times you don't know exactly where that traffic's going, and it has a significant cost. So there's probably some cost-benefit analysis here that will actually benefit network service providers, in addition to maybe being able to swap out some gear.
To Barbara's point, maybe there's some tariff help that happens here, too. I'm not sure, but there's a lot of feasible ways to at least make some of this chunk of problem go away in the next year or two. Perhaps.
Jeff, I feel like somebody in China somewhere is snickering, and what they're snickering about is we are all posturing about Taiwan, and we are saying we will come to the defense of this little island, and that's all well and fine and good intentions, and we probably should. But how feasible is it that suddenly we gear up for this situation, it goes hot, and suddenly everything we have running here goes dark because there's all these backdoors into it from our potential adversary? How real is that in your mind?
Oh, I think it's absolutely real. I think it's 100%. The question is when, and will the conditions exist to support it?
But no, I think it's 100%, and frankly, I think we're about there. And depending on what day it is and what position US, whatever the current administration happens to be at the time, has on Taiwan and on PRC, I think all those conditions go into the mix to say, when is that trigger going to be pulled? Oh.
Jack, what do you think about that, and to what extent does this factor into our overall geopolitical thinking? I seem to recall something recently about some water systems being, some US-based water systems being- Yeah ... hacked and having problems, and I think it was, I don't know, three, four years ago now.
The Colonial Pipeline suffered a ransomware attack, which caused a gasoline shortage up and down the East Coast as we couldn't get back fuel through the distribution pipelines. And those are very minor events. If somebody had the ability to switch off 10% of the US infrastructure, that would be devastating, catastrophic, pick your massively bad adjective, right?
It ain't good. " They are real possibilities. We see what happens on the small scale.
Large scale attacks are very, very bad for us. Mm-hmm. And yeah, it's a possibility.
" And the Chinese have as much to lose as we do. So at some point, has this just become too much noise and it's too big to fail? Well, I think the start of your question, are there a bunch of business execs having back-channel conversations with this administration?
I think we can all agree to a resounding yes on that. Mm-hmm. Whether this is the particular subject matter, who knows?
But yeah, I hope they're talking about this. They should be talking about this. Yeah.
Otherwise. So I don't know. I'll throw this back to Jack.
Jack, do you have any advice for folks about what they should be thinking about this? Is this a reality, but there's nothing to be done about it? Or is there some things we could do to protect ourselves from on the off chance that this goes sideways?
Well, there's the individual view, and then there's the sort of the strategic and the corporate view, right? The individual view, there's the preppers of the world who say disaster is going to come, and it could come in any one of a gazillion forms, and I'm going to be prepared for it. And that's 3%, 5% of us.
The rest of us are like, "Somebody else will take care of it," and we just happily go on our day. The risk to an individual I think is fairly low. If you're a large corporation, if you're one of the Fortune 500s of the world, you probably ought to have These types of calculations in your disaster planning scenarios, in your tabletop exercises, along with all your other cybersecurity disaster scenarios and tabletop exercises.
We think about it, what's the difference between a ransomware attacker taking your business down and your service provider being unavailable for a week? They're both going to make your business take serious dollar hits. Right.
I had that conversation with somebody once, and it kind of went like this. Nobody was going to show up to save the business because they were too busy trying to save their house from their 10,000 neighbors who were trying to steal all the food that they put in their backyard somewhere. So it just becomes a cascading series of things.
But hopefully it will never come to this, but, hey, it's something to think about, something to take serious, and when people start rattling sabers out there, you have to realize that there's a lot at stake here, so words matter. All right. I'm going to shift a gear here, and it's a variation of words matter, but in this case, they're different words.
So there has been this case involving this fellow went overseas, and when he tried to come back to the US, he wiped his data from his smartphone. And apparently, this person is an advocate for various issues and has been on somebody's radar screen. But eventually, there was an incident where, I think once he was back in the country, there was something where they accused him of having his car or something was out of compliance, or there was a broken taillight or whatever.
And ultimately, they wound up arresting him on the charges that he had wiped the data from his smartphone in violation of any number of legal statutes. And it turns out that the border, the United States government exercises a massive amount of control over what can happen at the border. So, legal precedent would suggest that the government is within its rights to do this.
But, Jeff, what it comes down to, though, is it's the data, it was this fellow's data. The data itself also seems to reside probably in someplace other than his smartphone. And is this just overreach in a way that we're abusing a concept called border protection to achieve a political aim here on a certain level, and this is just kind of beyond the pale?
Well, this is a real thorny issue for a number of reasons. Now, having been involved in law enforcement a long time ago and keeping a close association with it, anyone in law enforcement, if they went through any training, is aware of the Fourth Amendment, which talks about probable cause and search and seizure. And we won't get into all the nitty-gritty of that.
Of course, right after that is the Fifth, which talks about being able to not incriminate yourself in legal proceedings. So first there's those two. Then add to the fact that this individual was already on law enforcement's radar, mainly because he's been an advocate against Cop City, which is a very large law enforcement training center based right in Atlanta, which happened to be where he is, and the airport affected.
So you have all that stew going on with all those mixtures in there. He took a trip to the Dominican Republic for reasons not disclosed, which is fine. And I would offer he really wasn't very smart, or he wanted this to happen.
Because if he truly didn't want anyone at the border to see the data, he could've wiped it right before he left the Dominican, and this would not have been a problem. They could've said, "Show us your phone," and here it is, it's empty. Which, by the way, any time I enter the country, that's always my answer.
There's nothing on there. Feel free to take a look. You can keep the device if you like.
So, and I'm not saying everyone should do that, but we don't know. " And he was protecting that. We don't know what was there.
All right? Now, granted, that might be a bit far-fetched, but we don't know what was there. The fact that he was already a suspect to try to find a way to take in, and during his interrogation, in a separate room at the airport, they were asking about this, and eventually he surrendered his phone and gave them the duress password.
So the charge here is, did he willfully destroy evidence? " So- There you go ... it's going to be thorny.
There's going to be a whole bunch of different statutes and laws that get applied to this. And it's already a year and a half old, and I expect this is going to go a lot longer, and I can't believe it won't end up at the Supreme Court. Jack, what is your read on this?
Because there are competing rights here, right? At the end of the day. There are.
And I think one of the issues is, and I read a little bit about for this case, but I've been interested in this for a while, is that if you look at Supreme Court precedence, and this is one thing that really bothers me, is the Supreme Court has effectively said in so many words that the Constitution does not apply at the border, and the border from the Supreme Court perspective can actually be up to 100 or more plus miles away from the border. So there are border checkpoints 100 miles in on the border in Texas and Arizona and New Mexico and other places. And those checkpoints, they can do the exact same thing.
So you crossed the border 100 miles ago, you drove an hour and a half, and they can stop you and still apply the same rules. And the Supreme Court has basically said the right to privacy, to protection from search and seizure without justification, and to avoid self-incrimination doesn't apply at the border. And that really bothers me In this case, right, as Jeff said, it feels sort of like this guy was testing that.
He knew this was going to happen. He's a provocateur in one way or another, and he put himself in a situation where this would happen, forced the outcome, and suffered the results. And I think he can claim whatever he wants.
The Supreme Court has ruled it is this way, even though I don't agree with it. And this is not just like a minimal precedence. There's many.
There's five, six, seven different cases all around these types of things that have all gone to the Supreme Court, and they've all lost, and he's going to lose in one form or another. Mm-hmm. Friend, I feel like part of this issue is we never really defined what your rights are as it pertains to data.
And it goes all the way back to people claim that their data was stolen. Well, I may have copied your data, but you still have your data, so how could I steal your data if you still have a copy of it? So, there seems to be some gray around what we consider to be the legality of the data itself.
I think Jack's made a couple good points here. That gray area gets more gray around borders and transiting borders, right? In Europe, this matters significantly as far as what types of data move around.
You have to declare it and all the things that go with that. But in this particular case, if you look at it just on its face, let's imagine that we don't have context. Should a person who is transiting a border be able to be coerced into whatever they have on their phone without probable cause, right?
And so again, pre-context would be probable cause is on my phone is there evidence that you were after, and whether or not you obfuscated the truth and/or lied and/or forced me to allow that to have access to you. Once you share access of your data to someone else, in essence, doesn't matter if you take it from me, you have taken it from me. So the protection of that, whether you want to say it's the Fourth Amendment or it's the Fifth Amendment, there's a set of privacy expectations here that probable cause or lawful apprehension.
If you get pulled over for having a taillight out, okay, then you have a search in view in a vehicle. If you're pulled randomly at a checkpoint going across the border in the United States and someone wants to search your phone and you say no, and then you enter a direct password, I think the question is, is that probable cause or not? And I would argue that it probably isn't probable cause.
And so the question remains, should someone have to forfeit access to that unless they're being considered for something larger than criminal investigation? If they're a terrorist, then it's arguable, right? Reduced rights, reduced access, and all the things that go with it.
But that's a different process, and it's also a different set of controls. So that doesn't 100% answer your question, Mike, but I think that's actually what's set on the table here. This is what's going to be at the court of the Supreme here when it comes around to actually having this conversation.
But Barbara, we also know, going back to the A block, that you were advised strongly not to bring your gear into China because odds are that they're going to load it up with malware anyway and start listening to your thing. And a lot of people have two sets of devices. So are we getting to the point soon where everybody who travels overseas is just going to have to have a second set of devices that they use for travel purposes, and then they got another one that they use within the borders of the country where they can apply their God-given rights a little more aggressively than I can at the border?
And does this just get weird? Honestly, that's probably the smart approach for people who are traveling internationally. It's really sad.
To have to do that to prevent foreign entities from spying on you is sad enough, but to have to do it to prevent your own government from looking at your data is particularly depressing. Mm-hmm. And the fact that they are chasing, not so much that I am hoarding some data that might be a threat to national security, but it looks like they're just trying to determine your political leanings, which is a little over the top no matter how you look at it.
Jeff, is that fair? Well, I think on the surface, no, it's not fair. It's never fair for any government entity in the US to say your political intentions either make you a criminal or not.
You're either committing a crime or you're not. And being aligned with a political organization, unless it's defined as a terrorist organization, is not a crime. So no, I think that the easy answer is no, it's not fair.
Is it legal? I'm neither an attorney nor a judge, so I can't make that statement. But boy, it certainly doesn't feel like it should pass the smell test.
And I still go back to what is it you're protecting? How do you know it's related to national security? And I'm going to stay with the grandma's brownie recipe.
We don't know that's what he was protecting. Right. Jack, I'm going to just put this out there, and I doubt that it'll ever happen, but is it feasible that we can have maybe countries around the world come together and agree on some rights around data and travel and borders and what's reasonable here?
Because otherwise, this is just going to continue to spiral out of control. I would hope so, but I would also say that that's a very nice happy birthday dream for you, Mike. While we're talking about the US, let's not forget that one of the biggest proponents of a lack of data privacy is the government of England, who wants to force the end of end-to-end encryption.
They want all encryption to be breakable by the government, so the government at any time can come in and take your data, right? So, and see your data. Yeah, so I think that's a very good dream and I wish you all the best of luck in pursuing it, Mike.
Well, I- If I- Go ahead. I can support that just a bit. I'm not going to pick on Texas.
I live here, but I'm guessing it's not the only state. I'm also a part-time employee in the university system, and there is now a law in place in Texas that if you use any university network at all, you are banned from using any encryption other than what they provide. To the same point you just talked about, Jack.
It's not far from what England requires right now as well. All right. Well, somewhere in the origin of time are these basic human rights that we all kind of acknowledge should exist, and they might not be written down precisely, but a lot of it goes back to English common law, and I think this applies here.
But I sure wish they would litigate this stuff in a hurry and come up with some reasonable common sense, because I don't think legislators are going to do it, so it's going to be up to the judicial branch to figure this out, and maybe we'll have some conversations and hope for the best. But I'm going to shift the topic. There has been the formal launch this week by the Linux Foundation of the Tokenomics Foundation.
And we've been talking about this for a while, and the issue comes back to the fact that, well, it turns out this AI stuff's more expensive than we maybe originally appreciated. A lot of it is being heavily subsidized by the providers who are probably taking a financial bath trying to get us all hooked on that. That's another story altogether.
But a lot of companies are starting to pull back a little bit on the thousands of initiatives that they might have launched to maybe focus on two or three that are going to deliver some ROI that they can afford to do. But Barbara, I kind of look at this and go, well, is Tokenomics going to be a thing forever, or is this kind of a short-term thing because we don't really understand the whole cost structure of AI? But once it becomes a little more commonplace, well, this just becomes a standard part of the CFO's responsibility in a chat with the CIO, and it's just going to become a regular thing, and we don't need a foundation.
We need a foundation. We need somebody to lean into this big time. It could become standard part of the lexicon at some point, but where we are today, I feel like this became such a huge topic for so many people, maybe May of this year, where the bills started coming in and a lot of people were getting surprises.
And I know the article you shared kind of called out that the companies, Anthropic and OpenAI and so on, aren't part of this foundation, and seem to see that as maybe a negative. But I think it's great that the companies who are receiving the invoice are actually trying to drive this change. And I hope that the power of their collective purses actually yields some impact, because we need a standard for what AI actually costs and what you get for it.
AI costs are so impossible to predict right now. Vendors change their pricing models with no notice, no explanation, and you just have to live with it. And the thing that really gets me is when AI misunderstands what I ask for or does three times more than I wanted, I still pay for it.
I'm buying its mistakes at full price. So I love that somebody's finally counting and trying to create some standardization around this. And it may lead to us all understanding better how tokens work and being able to predict it, or it may lead to an entirely different system.
But right now, the vendors have the control, and it's time for us to take that back. All right. Fred, you consume a lot of tokens out there.
So what's your take on this whole thing? Because I love Barbara's point, we need a refund button somewhere for my mistakes. But, is that something reasonable to do?
Look, it's a terrific idea. But none of the folks that actually are the costing mechanisms here are a part of this. So, sounds great.
I'm not sure how we're going to push forward here and hold them accountable. So the idea, I certainly would love to understand on a per token basis my value and efficiency. But the first thing is, is be able to understand at least where tokens are being burned.
So I would love to have the observability part of that. I'll determine which models I want to use effectively and look at a cost per value per token to characterize that. So I love that.
But the challenge is you can't have the fox guarding the henhouse, but at the same time, you need to make sure the players that are charging you the money are participating in that, or at least can be held to account for it. So I think that's an interesting thing that hopefully will progress. There's probably some legislation requirements that need to start to move forward here, too.
And I think some of the highly regulated industries should also be able to provide some oversight here on where governance fits in for their cost and effectiveness, like the fin side of the businesses. Mm-hmm. I don't know.
Jeff, go ahead. I know you got your hand up there, so weigh in. Yeah.
I think this won't be solved until we look at AI in general and found a way to truly commoditize it to Fred's point, what's the observability going to be? How do we know where I'm spending it? Because even if you see that, that won't prevent surge pricing based on what it is you want to use at that given time.
But until AI is looked at as a utility, I don't think this is going to be solved. In the same way that your phone bill, as difficult as it may be to interpret, is regulated, and the phone company can't willy-nilly say, "Oh, you used the phone. Yeah, I'm charging you triple today for using data than I did yesterday because I think traffic's going to be higher," or whatever it's going to be.
That can't happen right now. That's because of regulation, because telecom and your phone in particular are looked at as a utility. I think at a different scale, a different venue, AI is going to have to be treated the same way.
Fred said there's going to have to be some legislative answers to this. I think that's where that's going to be. It may not apply to everyone all the time, but for large volume users in particular, there has to be some sort of way to predict what you're going to pay for what you're not sure you're going to use.
Oh, yes. Barbara, I feel like there's some common sense missing from this equation, and part of it comes down to, well, the C-level folks were so anxious to get everybody on AI that they started measuring how many tokens people were consuming. So, employees being who they are, decided that they would just maximize the crap out of the number of tokens that they were consuming and throw on AI just about every stupid thing they could figure out how to do it with, because there was some sort of leaderboard.
Now, those same business leaders are going, "Hold on there, Cappy. " So how does a business leader have this conversation? I think it's really hard.
The reality is you can't measure the ROI if you don't know the impact of the work. And I don't think most businesses can measure the impact of the work even when humans were doing it half the time. So if you have people plugging away at tasks and ultimately don't know the impact, and then you ask AI to do it faster, you still don't know the impact of that work.
Much of the work I've done over my career, communications, marketing, et cetera, couldn't be tied back to actual sales outcomes. I think it's so much easier to measure the number of things that people produce, whether that's the number of social media posts you generated or the number of lines of code you wrote, or the number of tokens you consumed. They're measuring the thing that they can, but they're not measuring the thing that actually matters.
Right. Because to your point, I cannot draw a direct line or correlate any of that to a business outcome. Right?
We have been investing in technology long before AI, and we've seen productivity gains over the years, but I'm not quite clear that it has fundamentally changed the economics of business. Yeah, it's had a major impact, but if you look at the Department of Labor measurements, the productivity increases are still single digits over a number of years, and it's steady Eddie, and that's all good, but it's not miraculous, shall we say. So I don't know.
Jack, what's your take? You haven't weighed in on this stuff yet, but- Well, I'm going to take a different sort of approach to this and say, first off, it's a shame that our colleague Tracy isn't here because this is really a Tracy thing. So I'm going to do my best to channel Tracy Reagan, and I apologize, Tracy, if you're watching this right now, have another beer on me.
I'll cover it because I get this wrong. But I feel that Tracy would say these are a whole bunch of very big dollar companies. It's Oracle and IBM, and they're consumers of JP Morgan.
These are big dollar companies, and they're consuming resources out of the Linux Foundation, and why isn't instead they give money to the Linux Foundation to all the other things that the Linux Foundation needs to support, and they go and they do this on their own outside of the auspices of the foundation. And not only channeling Tracy, but that's sort of my question is, it's a foundation that at the end of the day, what is the Linux Foundation going to produce out of this? What's the outcome that they're going to get?
" And the guys producing tokens or charging you for token production and consumption, those guys, they don't care about this. " And they're just laughing. They look at this like, "Go spend two more million dollars on the Linux Foundation to do this thing.
" Right? Sorry, it's the end of- No ... it's a Friday, my inner cynic has come out.
It actually is better than that because the same Linux Foundation that launched the Tokenomics Foundation also owns the FinOps Foundation. And last time I checked, this tokenomics is a subset of FinOps, so I guess, I don't know, do you graduate from the tokenomics class and go into the FinOps class, or is it vice versa? How's all that going to work?
But Fred, I seem to remember back in the day, we used to have regular conversations about the cost of IT, and did we just lose sight of that, and we have all these fancy little buzzwords and practices? But this is just IT Cost 101. Yeah, I think there's a lot of hype all the way around, you know Tokenomics is such a loaded term as it is, and I think people have started measuring things in outcomes.
The last time I checked, we did not measure the efficiency of folks that are salaried employees on a day-to-day basis, but we're going to do that with AI. Okay, yes, there's a cost problem here because it's not predictable, but at the same time, I'm hard-pressed as a person that uses this every day, in specifics for writing software. But to say that there is not value here, I will 100% say there is value here, even if it's unpredictable.
It is still cheaper than five people, right? And so I think creating a capture group of folks that have an interest in reducing their overall cost model, right? In support of Jack and others down the line for voicing your inner captured self.
The same thing is true here, which is you got to get the folks that are going to participate in this that are swimming in Scrooge McDuck's pile of gold if you're going to make an institute change. I don't necessarily think that policy, like another standards body, is going to have an impact here. There's got to be some other-- A regulatory thing, as Jeff said earlier, is like, this is the way forward.
However, if you're participating in national security interest conversations, and there's a whole set of narratives around what get used for what things, what does the common person have as a method of accountability and audit of what their token use is? And I think that observability piece, let's just start there. I'd rather get the observability piece, let me know what I'm burning and why.
The analog to the utility industry is a great one. This is, in essence, a commodity now, right? From the standpoint of what we expect it to be for business, and we should treat it as such.
All right. My last question, and I'm going to kick this back to Fred and maybe ask Barbara Roos comment, too, but are we measuring the right thing in the first place? A token is an input, and a token is an output, and there's a cost for the token, but is this really the thing that we want to use to measure AI consumption and cost?
Or is there some other way to think about this thing, and maybe we should just start over? It's a great question. I think if we look at the cost model for how this is associated, we're talking about what is the, in essence, the cost of a GPU for this particular type of utilization, and what type of compute is required here, memory is required here.
So this token thing does some level of measurement here, albeit not an accurate reflection, likely over time. But how do we measure outcomes in business today? How do we measure outcomes in writing software?
How do we measure outcomes in my lawn needs to get mowed? When I mow the lawn, the lawn's mowed. And so when we look at how do we measure outcomes, you have to be able to see, calibrate, and measure what an outcome does.
The method of inputs, I think, is the skeptical part here on which way to cost model this. And if we relate it to the organizations that provide it and the models underneath it, each of those have the same sort of collective goals, and so they're not going to be willing to do that. The same way we deregulated AT&T and the Bells is a similar part of the thing here.
I would be an advocate for making sure that each of these things get broken down, and that no one organization can own all parts of it. And I think that's part of the measurement that has to start to take shape. See, though, to use your metaphor, though, I just paid the other guy to go mow the lawn so I could watch the Yankee game, and the return on investment on that is incalculable.
Just saying. All right. " I think a few of them understand the economics underneath it, but most are just looking at the bill.
And I think it's kind of interesting because this is a little bit, going back to what Fred was saying about paying a salaried employee, and it's a little bit the difference between paying a salary versus paying them by the hour or even worse, paying them by the keystroke, and then trying to measure the impact of that. If you're paid by the keystroke, of course, you're going to be producing as many keystrokes as possible. And I think this model of token-based charging is actually going to come back on these providers at some point because it's going to cause companies, as we're seeing right now, to scrutinize the value of the investment.
So if there was an option to pay for sort of a retainer model, if you will, with one of these providers and then maybe a bonus for actual results and impact, then companies would be less inclined to dial down usage and let their people continue to freely use it and become more and more dependent on it. But now that the meter is running, companies are getting a lot more sensitive, and they're going to constrain use. And I think despite the Scrooge McDuck situation and the piles of money that are happening right now, it may come back to bite them.
Yeah, I do not disagree. I, of course, am old enough to remember when a token was used for getting on a subway, and I'm hoping that maybe this whole token conversation goes the same way because it's kind of the wrong thing for the wrong method, shall we say. Hey, I want to thank everybody for sharing their insights today.
As always, it's been a great week. Thank you all. Have a great safe weekend.
Please stay tuned for the rest of the lineup for the techstrong TV rerun that's coming up right behind us. And until then, we'll see you all Monday.