Disney Sues Google, OpenAI Lawsuit, and Gartner’s AI Browser Warning | TSG Ep. 986
Alan Shimel, Mike Vizard, Tracy Ragan and Jack Poller discuss an artificial intelligence lawsuit filed by Disney against Google, raising questions about how AI systems are trained, licensed and deployed.
The gang then examines a wrongful death lawsuit brought against OpenAI and Microsoft, highlighting the growing legal exposure surrounding AI platforms and their real-world impact.
The episode concludes with a review of a Gartner advisory that recommends banning AI browsers in enterprise environments due to concerns around security, governance and data exposure, underscoring the challenges organizations face as AI tools proliferate across the workplace.
Transcript
So Mickey suing Google, you're watching Text Join gang. Hey everyone. Happy Monday.
What a great weekend. I, I, I gotta be honest with you, this time of year, this close to Christmas, I'm not real excited about coming in here on Monday. I don't know about you, but, um, you know, the, these are, this is the time of year when you want your weekends to sort of stretch.
But we got an interesting situation this year, right? Because Christmas Eve is on Wednesday night, Christmas days, Thursday, most people are probably off that Friday. And then it's the same thing next week for New Year's.
So there's gonna be a lot of very, very long weekends this Christmas, uh, holiday vacation. I hope you're all are able to take advantage of it. Now, the folks at Mickey Minnie, Donald Goofy in the gang, they're gonna be brushing up their legal briefs as they are ready to, uh, go after Google here for what they're claiming is massive scale copyright infringement.
We're gonna talk about it with our gang today. Let me introduce you after a brief hiatus. She's back.
She's back, uh, uh, one and only Tracy Reagan. Tracy, good to see you. Jack Poller, who, who's a regular, I'm sorry.
I was just gonna say, it's so good to see you. It's Really great to meet you. Absolutely.
We missed you. We missed you a lot. You, your absence was felt, and I know you were doing good work, but we love to have you on here.
And then joining us back home in New York after his recent, uh, trip to the city, he's back up in Harrison, not named for a president, Mike Ard. So gang, Mickey Donald, they're carrying their briefcases, marching into court, claiming a massive scale of copyright infringement against Google for AI systems. What I, what I find is ironic is at the same time we're seeing, at the same time we're seeing stories of Disney licensing characters and IP and, you know, to, to AI companies to use it Was a massive kaka dinky.
Yeah, that's what they call it. A winky dinky, you know, cha-ching. Um, that's the old carrot and the stick, right?
Mike, what do you think? Well, I guess, so are these Disney characters? I think the open AI deal is worth a cool billion.
So are they gonna go around to everybody now and ask for a billion dollars? And did Google BLK at the billion dollar fee? I mean, how did this number come about?
And is this the going rate now for Disney characters? I don't know. Alan, what do you think?
I think Disney has a well-earned reputation of being a little heavy handed when it comes to asserting copyright claims. And, um, it could very well be that Google didn't pay up and so this, this was the stick, if not the carrot. Um, now on the other hand though, if I'm the biz dev guy at Open AI and I'm shelling out a cool billion, and I know a billion's not what it used to be anymore, it's just a billion, not a trillion.
2 to compete with the latest Gemini. I make sure I had some exclusivity there for a billion bucks. But I guess, like I said, a billion dozen buy what it used to.
Well, I think it's buying Disney something, right? They, if you think about the, I thought the two announcements were kind of, uh, coincidental and I don't really believe in Coincidence Ky dinky. We don't say coincide.
Yeah, exactly. Mike is coined the new term. It's KY dinky.
So is KY dinky. Um, and, but I don't, they have, this is something they've done for a very, very long time. If you went out and got a t-shirt and put a mickey on it, or, you know, even something that looked like a little mermaid, you, they're gonna go after you.
They've gone after smaller people. Mm-hmm. Um, this, this is a bigger problem though, um, with AI in general is going out and digging through, uh, what might be copyrighted information like newspapers.
Uh, so this is, this is just the, the beginning of the conversation. Who owns that content? If you, if something gets generated through your ai, do you own it because you ask for it?
Or does OpenAI or Google own it? So this is just the beginning of the conversation, but I think that they did kind of a ninja pivot here by going and investing in OpenAI and then establishing a licensing model for images, because they are now taking in charge of the conversation and they've bought, uh, a position within OpenAI to push OpenAI to make that possible. I think it was a brilliant move on their part, and it probably will be the beginning of how a lot of copyrighted material is, um, managed.
I don't know how they're gonna do it overall, but Disney and apparently open AI is gonna figure something out. And Disney's now owning open ai part of it at least billion dollars is a good, a good chunk of it. So, But that's the open AI model, Tracy, right?
They, they, they like to do these reciprocal things. I'll give you something. You give me something, it shows up on my, my books is revenue or investment, even though I'm giving it back to you in cost and, and we're all happy.
And it's funny money going in a circle jerk, right? Yeah. And Nvidia does it all the time, right?
But, but Open AI does it to the tune of one and a half trillion dollars. We recently had this a couple weeks ago on the gang. OpenAI has made arrangements to spend one and a half trillion dollars, 300 and something billion with Oracle 300 and something billion with, uh, with, with, uh, Microsoft.
Another outrageous amount with Broadcom for, for, for, uh, iterative chips. For inference chips, excuse me. Um, a one and a half trillion dollars on a company worth 500 billion that doesn't even do $20 billion in revenue.
That is incredible. You see how much I miss when I'm not on these? No, this is why you gotta stay up on this stuff, just asking.
So the, so the math, the math just doesn't work. But this, I guarantee you, this was an open, this is the open AI model. Invest a billion dollars in US, and we're going to put that on the books and, and we'll, you know, we'll, we'll do a, a license and deal back, right?
So the money goes like this. It really doesn't go anywhere, But it establishes something, right? But, but, but, and it does Establish something That's the key, but it doesn't establish what you think it does.
This is not about, from, from Disney's perspective, they don't care about open ai. What they're doing is they're setting a precedent saying there is value to licensing this material. Yes.
This is about winning the lawsuit and putting a stake in the ground. And New York Times has a lawsuit as well over this exact same thing. If Disney wins this, it changes completely what LLMs can do.
No, they're win have To pay for every content Times is gonna win as well. But, but they're winning not on, but they, what they're doing is they put a stake in the ground saying this is real money, right? So when we win, it's not you have to license.
Everybody has to license from us for real money, not token amounts, right? Not the, the, the, the court could say, yes, they infringed on your copyright, but we don't care about it. And there's no monetary award and there's no precedent.
This is setting a precedent. All future stuff. I don't think, I don't think a court, so you're talking about like the Trump suit against the NFL where the court ruled that the NFL did in fact have a monopoly at the USFL.
This goes back, right? 30 years, years ago. Right.
And they awarded $1. Yeah. Pretty much, right?
Basically Said you, I mean, you were, you don't see that very often. You don't see that very often. But because all the thing is from a courts perspective, if they set a precedent here, it affects not just Google, but it affects the entire AI industry and how all the LLMs have built and how can they get new data to train their models.
But all of these cases, not just a case, Disney would bring the Times case. The what we've seen, what we, you know, let me back up. One of the things I learned in law school from my professors was it takes the law, the courts five years, five to seven years to catch up to society technology, like new things like this.
So there's gonna be that period of adjustment. However, what we've seen in the lawsuits on this issue to date, right, is that the, the AI companies generally settle prior to a decision being rendered by the court. 'cause they know this is a losing argument.
It, it's, it's a bit of a novel case from a copyright claim. Usually the average Disney copyright claim is more like what Tracy described. Someone puts someone that looks like Mickey on a t-shirt or a pocketbook or something.
Or in the case of the New York Times, someone is hiring their content without acknowledging and attributing and licensing, right? It's very clear cut. The, in the AI case, they're, they're using this information almost as background information to train their AI and to make their AI better.
So the AI company benefits from the having that content for training material. And then that training material also does find its way in, if you will, to the output of the ai. Tracy, to your point, the courts have been clear to this point that when you ask an AI to generate something that becomes your work product, the ai, the open AI or perplexity or whatever doesn't own it.
You, you, you do have the IP to that. So you said, or you said that, uh, Disney and the Times will win these suits, but in previous shows going back a year, I can remember you kinda saying that, well, this is under fair use, and so maybe they won't win it. So where are in This?
Well, I'm, I'm like the Supreme Court. Well, I, I, I think the one thing about the Disney suit that is different is they're claiming that it's not the training of the material that's at issue as much as it is the output. Where they were actually, they were actually directing users to generate derivative works of Disney characters Like Disney, like fact Disney, like, right?
Yeah. And, and, uh, Sundar Phai actually did that, right? So they're saying the CEO of this corporation is encouraging people to infringe on our ip.
And that's different than we're using an IP Training. You know, the gimme an op-ed in the style of the New York Times, right? And it, and it writes a very sort of New York Timesy kind of thing.
It it, it's a similar kind of thing. Well, yes and no, but if I go write a book that's based on, you know, uh, an extension of James Bond, I will get sued by Ian Fleming's family. And rightfully so, because I'm basically commandeering a character in a storyline, even though It's an evil.
Oh, Conair, oh, Conair boy, you don't think all of these spy movies and, and, and with Suave British style agents are not based on James Bond, But they don't show up as James Bond. And I think what's happening here with these representations online is, you know, it's clearly something that looks like Mickey Mouse. It's not just a mouse.
It is Mickey Mouse. But Disney for a long time has said just about any mouse can be Mickey. 'cause Mickey's changed his looks over the years.
Mickey was originally a ratty looking mouse. If you look at Walt's old drawings, you know, from the twenties and thirties, um, he had a much longer nose, you know, he was a ratt looking mouse. He's changed though.
Mickey, I think Mickey's had a little work done. Chase. That's what I say.
I think he has too. Yeah. I think he's been softened up.
Right. And Min Minnie does Minnie's had work done too. Mm.
Um, but that being said, you know how close it is to Mickey is in the eye of the beholder. Right? You can't just say every mouse is Mickey.
And, uh, and You can't say, you can't say every mermaid is a little mermaid. Right? Yeah.
I seem to remember going back in time, mighty Mouse was a character that went around, right? Mighty. Yes.
He was gonna say the day, wasn't he? Yeah, he did all the time. Uhhuh.
But, but those, you know, taking it up a level from just the pure Disney, because they are always more, not obnoxious, more, uh, more likely to enforce their, their, they, They, they, they, they guard their privileges. Yes. Yeah.
But you know, the bigger issue here is all of these frontier models have basically trained their models on the body of publicly available knowledge in the internet. And, and this is, that's gonna be the crux of the question, right? Can you, can you train on publicly available knowledge?
But, and, and here's where the legal kind of nexus is. It used to be, you know, we had cases with links, right? Can I, can I build a newsletter with links to the Times to the Washington Post to the Fox News, CNN And maybe even because those pages are not behind a red wall or anything.
Grab some of the material from there without attributing, but have a link at the bottom. You know, over the course of the 25 years of the public or 30 years of the public internet, we, we've, there's a body of law and case law that has evolved about, you know, how you can use publicly available webpage information on your webpage or in your business. Little different than training my LLM on it.
But there's legal, from a legal point of view, they're similar. Alright. So just to be clear, do you think Disney and the New York Times are now gonna win these cases?
Yes. Or not? I, I, because it goes back to what, what you said before when I said it a year ago, they were in the public realm and therefore usable.
But, you know, the case law on internet stuff is even if the ca, if the pagers are publicly available, that doesn't in give you, in essence the right to pirate them. Alright? Well, as somebody who creates content, that warms my heart.
Me too. It warms my pockets. My pockets are empty, Mike.
'cause we're not the New York Times. And, you know, we gotta wait for these cases to play out because I think once these cases play out, much like the deal perplexity did with book authors, right? Once you could prove that your book was used in their training, they, they agreed to some formula to pay you money.
Yeah. So, so my brother wrote a book many years ago about, uh, mechanics of baseball pitches with Jim Cot, I think, and it was published by Hearst, but philanthropic wound up sending him a letter saying, you may be entitled to $3,000. Yeah.
Yeah. com. We've got 40, 50,000 DevOps articles on there.
Mm-hmm. No doubt. I'd like 3000 in article just saying, That's your opening gambit.
Well, no, what I thought they would give me $3,000 an article and I would invest 1500 of it back into open ai. There you go. That is the new model.
I I bargain. You know, at some point, at some point though, did we just wind up writing for their open ai? You know, it, it, the, there's the, there's what goes on in courts in the legal world, and then there's what goes on in the real world.
Mm-hmm. And don't, don't ever confuse justice with truth. There.
You can go. So anyway, let's take a break here on the gang. We'll come back.
Wait, we'll talk more about ai. What a surprise. You're watching Text on Gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, welcome back. And we're back in court.
Well, there's a wrongful death suit in Connecticut somewhere involving, um, a son who wound up murdering his mother because, um, you know, he was having a, some sort of conversation with ai and this suit is against OpenAI and Microsoft. And apparently, you know, they're claiming at least that the AI told him, you know, that all his thoughts were correct and that people were, uh, chasing him. And that, you know, he was some brilliant person with some awesome insights and the usual of ous stuff that AI kind of delivers.
But then he wound up turning around and killing somebody. So I think we're all watching this suit to say, you know, what kind of liability is there gonna be for something like this? We have talked about some of these issues earlier this week involving children, and now it's a, essentially a murder suicide now.
So Tracy, what's your take on what's happening here? Well, it feels more like a Halloween discussion than Christmas. But, uh, so yes, this, this man was living with his 83-year-old mother.
Let's, let's just start it like that. And he was 56 years old, so there's something going on already. It wasn't The Bates Motel, was it?
It kind of feels like that, doesn't it? It really does. Um, yeah.
And he probably suffered, I don't know, um, some level of paranoid delusion, but maybe many of us suffer paranoid delusion. And regardless if it's open AI or if it's Facebook, uh, these are modeled to tell you what you wanna hear. Kind of like our politics today.
Right? Just tell us what you want to hear and we'll tell you that. So, you know, in this particular lawsuit, unlike the one we just discussed, I feel like there's some personal responsibility and accountability that has to be considered even when it comes to the case of murder.
How are we, how are we, how are we really gonna say that? Because AI was telling somebody what they wanted to hear, which is what they're trained to do. And they wanted to hear that they were somehow, uh, touched by God or, uh, you know, they possessed Power, power or, or talked to them Or their yes or their dog talked tomorrow, their printer was watching on, was spying on them.
I, I really believe we have personal responsibility has to take part in making a lawsuit real. Uh, I, this what I'm sad about, uh, because we've talked about this now, you know, we, the, the, the community at whole and it, and everybody has talked about the impact that social media, and this is just another, in my mind, this was just another way to have a social discussion. It was a, it's more like a social media discussion.
They have caused young people to be bullied and to take their own life. Um, there has been, there's been all kinds of discussion about why we wanna manage better, what comes through these, these portals, uh, because we could have somebody with paranoid delusions who's gonna go shoot up a, a, a classroom. Uh, so we have a responsibility here.
And I think that the, the, uh, AI companies have a responsibility as well, but the person has some personal responsibility. I mean, I think what's an issue here is there's no warning label essentially on the service. So there's nobody out there telling people who may be crazy that you know, this.
They're interacting with something that is, um, shall we say augmenting Sort of, Okay. That's true. But somebody can go buy a, somebody can go buy a gun and shoot people, and they don't.
And, and the, the, the, the gun company doesn't have any, Don't ever, dont ever mention that JC we'll all be in trouble. Ice will be at the door. I'm Just saying, You know what Second amendment, How do we, um, freedom of speech, freedom of speech.
Yeah, I get it. I get it. So first of all, I gotta tell you, we've, we've been discussing so many of these legal things, I feel like I should go dust off some of my old school books.
Mm-hmm. Though, I don't think they use law books anymore. It's probably all computerized now.
I paid a lot of money for those big fat books. But anyway, you know, this, this goes back to something we discussed last week on the gang. And that is the difference between negligence, let's say resulting in a wrongful death lawsuit, which is a civil lawsuit versus criminal negligence, criminal manslaughter.
Right? Which is a much more serious, that's a criminal, right? You're not just talking about paying money, you're talking about potential criminal.
But in those cases, Alan, if you, if you're gonna dust off your, your, your, your law books, isn't there something called intent? Well, no. And do we, the criminal negligent negligence by definition means there was no actual will or intent, but you could still have criminal manslaughter where your, your negligence resulted in the death of someone.
You may not have had what they call the men rea you know, the, the mind to the intent to, to do such things. But it's still, it crosses the boundary of even gross negligence to criminal negligence, right? Getting behind the wheel of a car when you're, you know, twice the legal limit of, of intoxication.
And you've done this, you've been pulled over for 2D Dewis previously, crosses the line into criminal criminally negligent manslaughter. It doesn't mean you went out willfully, But those cases are very clear on who was completely responsible, right? I mean, have we seen in case yet?
Let's hang on. So now you come to it though, Tracy, right? Because what will happen here is there will be a discovery process, and then there'll be subpoenas for emails coming outta OpenAI and Microsoft.
And I bet you're gonna find out exactly how much they knew about this stuff before you they rolled this out. Well see the, but see, this is this, there's exactly three things that make this different than any other normal guy going wacko and killing somebody, case. And that is one, there's a computer record of it, right?
Up until this point, 99% of the wackos, they talk to the psychic, they call the psychic hotline on 1-800-PSYCHICS. Right? Or they talk to the, you know, they, they, they talk to their crazies under the bridge in next to Moscone Center, right?
There's just no record of it. The second thing is, it's ai. And the third thing is Microsoft and open AI have a ton of money.
No, this Otherwise the lawsuit mistake would be brought. No mistake, Jack, you're right. This is a deep Pocket.
None of this would be brought right Pocket. This is what they pocket. It's a, a deep pocket.
I'm, I was, I'm very glad that, that Tracy brought up the concept of personal responsibility. Unless there was a record of this happening, nobody would know how this guy got motivated to kill somebody. Crazy.
People who have a history of mental illness, 56-year-old people who have had history of mental illness commit violent acts every day. It happens all the time. And there's nobody to hold responsibility for somebody else going crazy.
Yep. AI didn't make him go crazy. He was crazy to Begin with.
But Jack, here, here's the, here's the thing from a legal point of view, and this is why there's a, I was trying to say there's a difference between a criminal case and a civil case. In a criminal case, Jack, you would have to prove that open AI and Microsoft are guilty beyond a reasonable doubt of being criminally negligent here in a civil, wrongful death suit. It's what we call a preponderance of the evidence.
So it's 51%. Is it more likely than not that their product's, uh, behavior contributed to this unfortunate death? To this wrongful death?
Death? And it's a much lower bar from a legal point of view that, you know, OJ Simpson was not guilty criminally, but he was guilty civilly, civilly in the civil lawsuit to the Goldmans, Right? I, and and I, and I understand that.
I think the issue is that it is ridiculous to, to contemplate holding a third party responsible for somebody's stopping. So Let me, let me give you you another fact pattern. Let me give you another fact pattern that's in the news right now.
Let's say instead of a however old this guy was with a history of mental illness, illness, you have a young girl who's 1516, a minor, and she confides in her ai, which the company who made this AI purposely made their, their AI characters warm and fuzzy, almost Disney like. And, um, and she confides in her AI over 50 times, 60 times, that she's contemplating suicide. And the AI doesn't warn anyone, do anything, try to stop it or anything else.
And sure enough, the girl commits suicide. It's a real case we discussed. It's, And, and, and, and I questioned whether, did she confide in anybody else?
Yeah. Was AI alone responsible for That? Is AI Alone responsible?
So let me let, let, let give you, going back to this guy again. Let me, hold on. Let me, let me play this out for you.
My wife happens to be a social worker, right? And so I asked her, I said, Bonnie, I said her name. Well, my wife's name is Bonnie.
Um, I said, Bonnie, if you were counseling a young girl and she kept telling you that she had thoughts of hurting herself of suicide, what's your legal obligation? 'cause you have hipaa, right? But what's your legal obligation?
And she tells me her legal obligation is absolutely go to authorities. You cannot, you, you can't let this person kill themselves. You, you know, you're gonna try to basically get them to sign themselves in or down in Florida, we have something called the Baker Act.
Right? You could baker act them and have them basically, you know, put, put in an observation for three days. And then if it's determined at that point that they really are a threat to themselves, they, they, they, they, they stay in.
Um, that's, I mean, so substitute the AI for social worker, Except for she's, she's in a licensed regulated profession. Does it, does a priest. Yeah.
But if you're holding out, Does a, They slept in a Holiday Inn Express last night. Yeah. But does a, does a priest have the same requirements?
So there's case law on there. Does a neighbor does a does a neighbor does. The girl's best friend does.
The, the 56-year-old guys Respons are good Samaritan. There are good Samaritan laws about that stuff. And in fact, when you look at police, remember, police do not have a duty to protect or a duty to act.
But there is, there is, Right. Same thing they Did there. But once they do, Jeff, despite what it says on the side of the car, right?
Despite what it says on the side of the car, legally a police does not Happen to do, to stop you from committing suicide. Thing knows into it. They do.
Yes. But if a police drives, but if you tell a policeman, I'm thinking about contemplating suicide morally, we would expect them to do something about it legally. They are not required to do anything about it.
Understood. Jack, I'm telling you as a, as a lawyer, I would be salivating to take the case of that 15-year-old girl because Theis here are holding themselves out as confidants. Uh, and, and they're providing, a lot of them are providing therapist like responses to these things.
This, This is a slippery slope, Alan, that says, at what point does, does the AI violate your it's privacy requirements about you? If you say something, how does it know if you're serious or joking? It has no ability to, to judge intent.
How, how does, how does a chain professional know They have context? So, so if you watch any television they have show, yeah. But if you watch any television show these days, televis about involves anything to do with suicide.
There's a little label there that says, Hey, you know, if you're feeling this way, you should call one 800 or some sort of online service, or there's some sort of warning that says you should do something. And that that's the state of the art. And that's all open AI has to do here.
Right? Put in a rule that says, anytime someone talks about suicide, just put some blanket statement, accept or reject. Don't sell my information.
You know, and, and, and you Well, This case wasn't suicide though, right? This was a murder. So there admit never case murder about a murder, right?
Well, so delusions of grandeur, should we say, if they, so I hear it. So let's, let's again, let's play law school. 'cause this is what law school is like, guys, we take these cases and we play with them, right?
So now, so now what you're saying is, should open AI give you a warning? If you tell it you're thinking about committing any crime, Or that you're delusional Or that you appear to be delusional in their Opinion, and that this, this is, this is what I mean by the slippery slope. At what point?
Well, what about the hacker who says, show me, show me how to make some exploit code to exploit this vulnerability. Exactly. Illegal at what point?
Yeah, but what's so, I, so Jack, I, yeah, I hold open AI illegal, I hold open AI liable for that. And I don't mean just open ai, I I hold the AI liable for that. And I think that cross the line Any of these, uh, social platforms and, you know, if this case, if they do win this case, I feel like it's, you know, from a social perspective, it's probably a good thing If who wins this case, If the family wins the, the Wrongful death, uh, sued suer not the a l Yeah.
Because then it's going to establish, um, that other situations, uh, like teenagers on Facebook being bullied, right? Was Facebook re should have Facebook stopped that? If they, if they saw that, should they have stopped it before the kids Committ committed?
Well, we, we've cycled through this, the a OL chat rooms, the cesspool of the internet back in the day. Yes, It still is. It is still a cesspool.
Are you telling us you still frequent the a OL chat rooms, Chay? I don't, But I'm just saying that the, the Internet's general, What's your screen name? No, I don't.
I Don't, I don't. But, but no, but you know, there's been case law around this too. Uh, here, here's the deal.
It goes back to what I said earlier. It takes the courts and the legal system years, years and years to catch up to this stuff. And by the time they do, someone's already moved that cheese.
You know what I mean? The cheese has already been pushed up. And this will go all the way to Supreme Court.
This is a one that's, But by the time the Supreme Court decides that it's moved on, I think it'll play out this way though. I think the existence of the suit will force the issue. It will become a political issue.
There will be some sort of effort in Congress to address this issue, But not at the state legislatures, Right? But regardless, and then it'll be just like, you know, the, uh, Epstein case in the sense that there'll be such overwhelming support to do something about it. It won't matter what the president thinks.
Wait a second. I feel like we should have confetti stuff dropping down. You mentioned it.
Release the Epstein files. Okay. Alright.
Hey, we're over time on this one. What a great discussion. I might somewhere, professor Koffler, my torts professor who wrote the book Koffler on Torts.
He's probably in heaven somewhere by now, but he's smiling down. Um, we're gonna come back and we, we can talk a little more about ai, but this time, AI browsers, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You will access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And Gardner put out a statement essentially urging people and enterprises to ban the deployment of these new AI browsers because, well, they're just fundamentally insecure and bad things can happen when prompt injections are shown in these browsers and they're connected to something else. And the next thing you know, all your data's off in the dark web somewhere. Jack has an article up on Security Boulevard suggesting that, well, this kind of misses the points and we're rearranging deck chairs here on the Titanic.
But Jack, explain, Well, are they rearranging the deck chairs? Are they shoveling the sand against the tide? Are they emptying the ocean with a bucket?
I mean, this is just kind of foolish. Um, you know, I mean, Gartner, of, of all the analyst organizations in the world, Gartner should know better than this one. That there is no such thing anymore as a non-AI browser and blocking things and banning things, blacklist, whitelist.
We've gone through this time and time and time again, and it never works. It never will work. It's too hard to keep up with the changing technology.
People find a around way around it, et cetera, et cetera. And I just, I have no idea what they were thinking when they said, let's ban something. It's just, I mean, this is kind of ridiculous.
Well, Um, I was wondering, I mean, I just, go ahead. Let me just say, let me just say one thing, which is every single issue they highlighted has nothing to do with the browser and has to do with AI in general. And it's fine to raise the alarm bells about ai, but the response of blocking browsers is just, come on.
That's insane. I was wondering what that giant sucking sound I heard was, I guess it was everyone deleting their AI browsers just because Gartner said so. You know what?
Yes. I mean, quite frankly, this ain't your daddy's Gartner. You've had a tough year.
You remember what Babe Ruth said, how come you should make more than the president? He said, I had a better year than he did. Okay.
Yes. Gar, Gartner. Gartner, thank you, Gartner.
You got bigger problems to, to, to worry about Gartner. Um, that, that's kind of, and who, look, that train's left the station. You know, the, yeah, I could just see everyone say, oh, Gartner said we, we, we had to get rid of our AI browser.
Three people somewhere in some hole in the wall might have deleted their browser as a result. Tracy, should we be cautious here though? Because these browsers and AI agents in general seem to be, uh, easily tricked into doing something.
And we don't seem to have a lot of controls in place yet. So how do we kinda run the middle here? You know, it's like any cybersecurity issue.
It always, most of it boils down to the human. You know, we can, uh, we can have a a, a badging system on our door. So we have, we could to see who's coming in.
But if we cut and paste a bunch of sensitive data into a browser, um, uh, maybe we're asking for it. Personal Responsibility. Again, that's being Personal responsibility.
I really do believe that, that we all have to be, you know, we all have to be on guard. Uh, but I don't think that this should be the end of, um, using AI browser that is, as Jack has pointed out, that is not, it's not gonna happen. But Agen AI has its issues and the community has to kind of start thinking about how to solve some of those issues.
Prompt injection can happen anywhere, though. It doesn't have to be, uh, you know, a an agent's, uh, problem. It can be, it can happen at many spots.
Many, many connections. So, uh, I I thought they made a pretty broad statement by saying that, that you shouldn't use an AI browser. I was, I was actually kind of giggling when I read the article.
I was like, all right, Jack has really nailed it there. What were they thinking? I But wait, if there, if there's an issue and it affects the community, don't we need a foundation?
'cause that's how we solve all our problems. Yeah, exactly. Well, you know, I I, I wrote a companion article elsewhere that basically, and I, and you know, if we're thinking about AI security, we should think about things like MCP, which has security as an option instead of security.
Well, We do have a foundation for that, Right? Right. I mean, you know, let's, let's raise the alarm bells more.
I mean, OASP, you know, OASP raised, uh, you know, a, a agent AI is one of their top three. And they said, well, it might be an issue. And I'm like, it's a very big issue because security is optional.
How do you get to zero trust if you don't mandate authentication authorization? It's just, you know, but here's, we have big issues. And blocking browsers isn't one of 'em.
Here's the reality. It's come up time and time again here. 90% of developers are using AI to generate code.
40% don't trust it. 65% are sure that it introduces instability into the code base, but still 90% of them use it. We have similar, similar numbers for SRE and ops and platform engineers.
This is where we are right now in our AI revolution, right? We know security isn't up to speed, up to snuff. We don't trust it, but we're drawn to it like moths to a flame.
And sometimes the moth catches fire, sometimes it doesn't, but no amount, whether it's Gartner or Forrester or, or Jack, you as an analyst are gonna, you know, you could lay your bodies down on the tracks, but that train's just gonna run right over you. And that's the, and we will have better security and AI browsers and better security and AI agents when the makers of, when the customers of the makers of those products demand it when they vote with their feet and their wallets, watch how quick it gets done. But right now they're not.
'cause we're all knowing it's some form of maybe mass hallucination, insanity, I don't know. But knowing that it is that we don't trust it, knowing that it is insecure does not stop us from using it. That's because those 40% are taking some personal responsibility to look at their code.
They use it as the basis of, you know, to get started. Right? And then they work from there.
That, that must be what it is. Chase, you're right. It's absolutely is.
'cause I know so many people who don't trust what they, what No, 40% don't trust it for sure, But they, it Anyway, They use it anyways because it's a good way to get started. It builds a framework and then they don't, that's not what they ultimately deliver to the end user, right? I mean, Somewhere, somewhere there is a bunch of cyber criminals sitting around a table looking at each other in disbelief going, can you see what these guys are up to?
Now this is just like, how much easier do they wanna make this first? Yeah. 60% of our users, uh, the users have, have generated code is not gonna really check it.
But, you know, I'm gonna go back to what I said The latest hold, go ahead and then I have another factor. We have a problem with the way we have built ai. And I'm gonna say it now, like I said, I used to a complaint about agents.
I could see the problem coming. Large language models suck. They need to be more specific, they need to be more domain based, and they should be small language models that we can trust.
So Tracy is an LLMS woman. Is that, is that, is that like a new bumper stick? MLLM suck.
They all Suck. They Suck, but you know what, There's so much wrong stuff that gets generated even when I'm using it. Lemme just throw something out at you.
I had a conversation last week with my friend Jen Zwelling, who's the now like the CTOI field, CTO maybe for Veracode. And you know, they do, I mean, they, they get to look at a lot of code from their clients and they do constant reviews of code security that from real life code being generated. And they have been comparing all of the different ais and the coded generates as well as the CU code that gets generated.
And with the latest models, which is five, well now there's five two, but five one on chat and uh, on Claude sonnet, was it three five? I don't remember. Whatever the latest Claude is.
The, the amount of bugs, the amount of in vulnerabilities in code generated by those ais are roughly on par with code generated by humans. So just to give you an idea, it started off human code machine code, let's say two years ago. We're at a point right now where it's about even, but make no mistake, machine generated code is, is on the, you know, what, what, what does Mike Tomlin say?
Not on the upside, whatever it is. It it, the, the arrows pointed up. The arrows pointed up here where human generated code kind of stays the same.
So if we were having this conversation a year from now, uh, AI generated code will probably be better than human generated code. The question is who is checking it? Are we, you don't think so?
Mike? Mike says, no, no, no, no, no. He gave me a Sergeant Schultz there.
Our contrera even open AI just put out a statement saying that there is likely to be more security issues with their latest open AI models. Because the thing is bigger and smarter allegedly than ever. And there's, there's more opportunities to make more mistakes with more code generated.
In other word, it's of Ai. The very company that wasn't providing a warning label before is providing a warning label for this. It tells you something.
It's because it's saying we're becoming more of a generalist. Right? Which is my point.
It's they don't have enough domain knowledge, right? We, and, and the answer is, we've been down this road before for code and we have AI models that generate a hundred percent perfect code, and they're called compilers and they've been around for a very, very long time and we figured it out. And compilers now can generate assembly code that's much faster, much better than humans ever could, right?
And with specialized LLMs and specialized AI compilers, we will generate better and more secure code than humans can because they can operate at speed and scale that humans can't. But that's for what Tracy calls the small LLMs or the domain specific application specific code, general purpose. LLMs trained on a billion or trillion or 10 trillion data points off the internet are not going to be very good.
I, I'll take it a step further. I think the AI agents are just gonna write stuff for each other in assembly. I mean, we only have Java and all this other stuff for higher level of abstractions for humans, and machines are gonna be like, we don't need that crap.
So, But that, to Alan's point, I do believe that there, there, there's going to be a point where humans and uh, AI generated code is gonna be pretty similar in terms of the internal vulnerabilities that they may create. But that doesn't change what's coming through the software supply chain. And we're going to be using more and more open source as we move forward.
And that always, that's always gonna be vulnerable. I, I had a good conversation out in Vegas, uh, two weeks ago with my friend David DeSanto. David used to be the, uh, chief Product Officer GitLab, he's now the CEO at Anaconda.
If you're not familiar with, they probably have one of the biggest repos of Python for Python scripts and stuff in the world. Open source, fully open source. And, and we, we talked about that very issue is 'cause that's, that's the, the, the battle front, right?
Tracy, all, you know, 75, 80% of the code in these apps are coming down from open source repositories, whether they're container images or Python snips or JavaScript or Java or, or or Uhif artifacts. They're coming from open source reposts. And you know, we, we, we do have the SBO thing, so you could probably chase it back to what repo and all that good stuff.
But at the end of the day, I think that's the choke point. That's the battle front where we, we, we make our stand, we die on that hill. We, we, we make sure that if you are downloading code from a, a repo, I don't care which repo it is, you should have a reasonable expectation that that code is free from bugs and vulnerabilities and malware.
I Don't know if we can ever get there, Alan. The, the amount of code that's being, that's being used in the open source supply chain is big. Why?
Well, the amount of code being used all over, it's big. It's four x what it was. That's, what's the numbers?
We see 30,000 vulnerabilities for this year. 30,000, right? Sounds like A problem for ai.
I I think the, which I think the problem is, is we put, we always shift left. That's an offensive, uh, strategy. In order to trust open source, we also have a need, a defensive strategy, which means if you find something in, find a critical or high risk vulnerability running on one of your endpoints, fix it.
Fix it as fast as you can, right? And we don't, we don't think that way. We keep thinking zero vulnerabilities, zero vulnerabilities coming from the left.
We don't, we're still at a hundred days plus to remediate of a critical vulnerability. Yeah. That, And then bad guys, the bad guys are getting smarter at exploiting those vulnerabilities.
Not 10 days, Right? 10 days. 10 days.
So we got a 90 day gap, Alan, I, I'm, I'm just gonna start calling you repo man from now on. Okay, You know what? So I would put the, I would, I think we should bring a lawsuit against the repos for allowing vulnerable code through their repo, right?
Because they're claiming sort of the, what, what is it? The five 20 rule that they're not responsible for what's in their repo that someone else put up there? Same way Facebook says, I don't, I'm not responsible for what someone else posts, Right?
And now there's ways like with like, think about openness of scorecard. You can go and, and, and check how much work that that project is doing to be compliant, right? So you can make a decision if you wanna use that or not.
Again, so what am I saying? Personal accountability, Personal responsibility. Hey, you gotta brush your teeth some time.
You've got a personal responsibility to pull the plug here. Guys, we're way over time. We had too much fun with this today.
I apologize. I hope you've enjoyed the conversation. Of course.
We have a lot more of great Textron content following this. We have text on tv, we've got between all the shows we've been doing and all the many, many video interviews that Mike and I have been doing, and our podcasts from Futurum Group and Tech Field Day. And there's just a ton of stuff out here for you to watch.
I also wanna give you all a shout out. January 15th is Predict Day here at Textron. You know, for the last nine years we've been putting on a show every early January where we ask some pundits experts and, and various other sundry people to come up and give us their predictions on what's big in 2020 in the next year.
So for 2026, I'm really glad and proud to say we have drafted the Futurum analyst team in todo. I don't mean Dorothy and Toto in Toto legal word. Um, to come out here and give us their predictions, we're gonna have Daniel Newman.
I'm gonna, I'm gonna be interviewing Daniel on his predictions. I'm gonna be doing it with Nick. Patience, of course.
Mitch Ashley, Fernando Montenegro, Brad Schrier, the whole Futurum team is getting behind this on us. I think it's gonna be our best predict yet. Of course, AI was Techstrong's.
I don't know if it's person of the year or entity of the year, but I also saw that Time Magazine made the architects of ai. The eight they chose, the eight architects of AI is their persons of the year. com.
You can go on register for this. It's gonna be a great event virtual, and we'd love to have you there. That being said, I, I never, I I have a prediction.
Well, can you save it for January 15th? No, Ahead. My prediction is Dick Strong gang will be back tomorrow.
Okay. Mike said it, so let it be written. So let it be done.
We're out. Ms. Alan Shimel, we'll talk to you later.