Government, AI and Cybersecurity Collide | Live From RSAC
Live from RSAC, Techstrong Gang brings together Alan Shimel, Jon Swartz, Mitch Ashley and Michelle McLean to unpack how government is reshaping the future of AI and cybersecurity.
The conversation explores the State Department’s new Bureau of Emerging Threats, the growing influence of PCAST on AI regulation and legislative proposals that could have major implications for data centers and digital infrastructure.
The gang also digs into the challenges of turning broad policy goals into detailed government frameworks, while comparing the very different ways the U.S. and EU are approaching digital sovereignty, AI legislation and cyber governance.
Transcript
Hey everyone. Welcome back to Techstrong Gang Live from RSAC. Hey, this is day four coverage.
We've been doing this... Well, we did three Techstrong Gang Lives, because Monday we had our Securing AI Native Dev seminar. But you know what?
Every day has just been better than the next here on the Gang. What's nice is rather than just sitting in my studio back in Boca Raton, I'm able to pull in some of our friends in the industry, and we have another one today I'll introduce you to in a second. But first, let me say, on the Gang we have regular Gang members, Mitch Ashley, John Swartz, myself, and our very special guest star today, our friend Michelle McLean.
Michelle is a senior director of SecOps at Zscaler. But I should tell you this. Before she came here, we were playing Michelle McLean bingo.
And where do you know Michelle from? Where do you know Michelle from? Where do you...
And we all knew her from different places. Yeah. She's had a distinguished career.
I'm not going to embarrass her. But Michelle, welcome. It's so fun to be here.
And thank you for being here. Yes. Absolutely.
Always. Michelle, in her role, has been an analyst. She's been a CMO.
She's been in product marketing. She's done it all. Yes.
Started as a journalist. And started as a journalist. Yes.
Yes. Back in the day. Go figure.
Exactly. Wow. I didn't...
That I didn't know. Wow. All right.
So gang, let's start it off today. Topic one is increasingly, the federal government is really becoming just another tech bro, right? They're getting more and more involved into this industry, like almost FOMO or something.
John, you had two articles- Yes ... that you wanted to kick it off. They both happened sort of simultaneously.
So yeah, you're right. There's this kind of intermingling or intertwined relationship between big tech and big government, and it's an extension of the oligarchy. And there are two things.
I'm the teleprompter guy here today, by the way, so we have some show notes here. Uh-huh. Just a little inside information.
So there are two things going on. The State Department under Marco Rubio has started this Bureau of Emerging Threats, which is kind of a nod to all the countries we're hostile with or at war with, and the importance of AI in those organizations and in our national defense. And there's certain areas like space security, critical infrastructure, the things that we're talking about at RSA.
One thing, I would kick myself if I don't mention this. A year ago, we were talking about CISA and the gutting of the organization, and now this year, all of a sudden, these guys have seen the light, after they destroyed CISA. So I need to mention that.
So we have that going on. At the same time, we have another group, another thing, and this is a long-winded alliance which I actually think has a lot of legs. Normally I'm not a big alliance person, but I think this one actually, unfortunately, is going to be effective in what they're trying to do.
And it's the President's Council of Advisors on Science and Technology, which is called PCAST, and it has 13 members. Only a few names have come out so far. Zuckerberg, Jensen, of course, Larry Ellison, Sergey Brin.
I think Lisa Su is going to be part of it. Michael Dell has indicated he's part of it. I think Marc Andreessen is also part of it.
And these are the guys who don't want any state laws involving AI regulation. They want to work- Of course ... and deeply embed with the federal government and kind of work together with one of...
Which they have been doing for a while. This kind of formally cements that, and it will be interesting to see where that leads. Concurrently, where they're working together, there's news out that Bernie Sanders and AOC have come up with a bill to stop further expansion of data centers, which are booming.
So we've kind of got all these different camps, and the strongest camp is this alliance or this group, which I think will have a major influence on policy, whether good or ill, for all of us. So- And with that, I pass it to you. All right.
John- Well ... when I first saw the PCAST thing, I got to be honest with you, I was thinking of the Presidential Commission on Physical Fitness. Right?
Are we going to get- Oh, no. We're going to pump you up ... 1990s school thing going.
Remember that? Oh, wow. So is this going to be- Yes ...
the Presidential Commission on AI Fitness and- Yeah. It's going to pump you up ... let's get Zuckerberg doing some.
Yeah- If possible ... pump you up. Though Lisa Su, probably.
She's in shape. But so here's the thing. So have we substituted CISA in for the State Department now?
Is that really the State Department's role? Right. Right?
I thought we had an organization that did that. But they specifically singled out, of course, the axis of evil, right? Right.
Iran, North Korea, China, and Russia. Russia, yes. Yeah.
But you know what? There are plenty friends of ours who use cyber to get stuff as well. Look, I'm always, the government's the government.
Private industry's private industry. You should work together, and there should be a partnership, but I really feel like the federal government has been just getting too much in bed- Yes ... with big tech.
That's honestly how I feel. Yeah. I think Stryker was a big wake-up call, right?
Mm-hmm. Like, holy crap, just the devastation and- Yeah ... what that did, and the repercussions that could have over into critical- Right ...
infrastructures. We've all been worried about it, and here it was at a pretty big scale pretty immediately. And I absolutely agree.
Like-We're talking out of both sides of our mouth. Yeah. Because we're doing this, but then the gutting of CISA left this community in much worse shape.
And you know the one thing I should've mentioned just really quickly, I'm sorry to interrupt- Yeah, not at all ... but when we see these frameworks of what they plan to do with these different entities, they're usually four pages long. Right.
They give you- Well, and that's the other thing. They're always short on details. Right.
They're always big ideas. Well, when there aren't a lot of details, you look at other data points. So one of them is where is it reported in the government?
If it's in the State Department, it's going to be diplomacy. It's not going to be action. It's not going to be counter action.
It's not a proactive organization other than relationships and building that kind of thing. If you look at who's involved, that's another data point, right? The tech bros.
Why are they involved? They have interests. They aren't government employees.
They are from private sector with huge investments in a lot of things, data centers, AI companies, their own investments, et cetera, and they're going to work to that outcome. I think you're right. Of any of them, that will be the most successful in terms of outcomes- Yeah ...
of any impact. The rest, maybe it's a good band name, The Bureau of Emerging Threats, but I'm not sure what else we'll see from it. Depends on the music.
Yeah. Yeah. But I feel like we got to say it.
Adam. The tech bros don't do anything that doesn't serve their own- That doesn't serve their own interests. I was trying to say that in my Nebraska nice way.
Yeah. Sorry. Well, you're nice from Nebraska.
I had to go New York on this. You did after Jimmy New York. They're selfish b******s who are out for themselves, okay?
We've seen this time and time again, right? Elon came into government to cut trillions of dollars, and who made a lot of money? Elon.
Yeah. I noticed his name was missing from this too. It was.
Still out of favor. I guess he's still not invited for Sunday dinner, but- He's in the witness protection program- Yeah ... for protectos.
For protected billionaires, right? Yes. And then the whole- But I was going to say, so there was an NBC poll that came out that showed that AI is despised by half the population, and it was even more hated than ICE or Trump and even tech bros, but the combination of AI- It's pretty Right.
The government and these figureheads. It's cumulative. Boy, is this going to be a political football that people are going to take advantage of.
Absolutely. And I think it is a major story, but it's going to be even a bigger story during the midterm elections. So let me pull this back to RSA, though.
RSAC, excuse me. You said people hate AI. I happened to walk over from the recovery breakfast this morning by the 1Password people, so I came down the block here.
I don't know if you all saw the, I'm not a San Franciscan, I'm going to mispronounce this, the Yerba Buena- Yerba Buena Theater ... Theater. Yes.
Wiz took over the whole outside. Yeah. And they had these big signs up all over.
No AI zone. Yes. I took pictures of it because I'm going to use it in an article.
No AI zone. Right. " Oh, gosh, no.
" This is not a genie we can stuff back in the bottle. No. Whatever our feelings.
No. Whatever our- So who's the marketing wiz at Wiz- Yes ... who made a no AI zone?
Well, flip it the other way. " Mm-hmm. It's a defensive network statement.
Okay. I didn't think of it that way. I don't think it's a social state-- They're playing on the social statement- Sure ...
part of it. Oh, by the way- But having fun with it ... PCAST, I think the ultimate goal of theirs is to eviscerate all state laws.
Absolutely. Because not only do they say federal government is going to preempt state laws, there's a second piece of that which is we're going to have minimal regulation. Yeah.
Which basically means- There'll be no laws. Yeah. Yeah ...
Katie, bar the door. That's an old saying, isn't it? I guess.
What? But- It's not as old as the show- We're old ... but it's pretty old.
No, but it's out there. I mentioned that a couple of days ago, and he- ... clapped me down, or he clapped my- This is Charlie Tuna.
Oh, gee. F*****g Sid Caesar. NS- My dog's Sid Caesar.
Sid Caesar. Somebody's madly Googling. Wow.
He was a funny man, like 70- No, actually, I mentioned Sid Caesar. " Oh, yeah. I'm like, God almighty.
Dave or so. Wow. But seriously, the other side of that coin is not only are we not going to let the states regulate this- Yeah ...
but we're not going to do any regulation here either. And I'm all for AI. I'm a huge AI proponent.
I use it. I'm enthralled with it. But when your legislative intent is no legislative intent- And you have a lot of money behind your no legislative intent.
" For their own reasons. Pretty good chance you're going to be successful. Well, we haven't really succeeded with those kinds of efforts before.
And think about the early days of the internet and what everybody tried to do then. Yeah. And the gap between the folks who could make the law and their depth of understanding about tech- That's- ...
what would be an effective law. So you're going to remember this. Mid-'90s- Yeah, good point ...
there was a senator from Arizona, Jon Kyl. Yeah. Conservative.
He wanted to end online gambling. He came up with five variations over the couple of years to try to get rid of it. Because the only law that it really applied to was a telecom law from the Kennedy era.
Cross, yeah. Right? And eventually it got to the finish line, but it took years.
And I think this is- Yeah ... same kind of thing. Well, how many of us, what was this, 20 years ago?...
somebody, I can't even remember who it was, trying to explain the internet to lawmakers. And like- Yeah ... think of it as a series of tubes.
Tubes. " This is what they're going to think of. Yeah.
This is just- Vacuum tubes. But there's this huge gap. Right.
But here's the issue, though. Just because we can't seem to get out of our own way, doesn't mean other nations and other regions- Right. Yeah ...
can. And then you look at the EU and what they've done, they clearly have the legislative will- Yeah ... to regulate this.
And they have shown that time and time again. Time again. We have this uniquely American individualist perspective that- Yeah ...
often works against- Mm-hmm ... collective good. I don't know if that's a good thing.
We just have never had... And I would also say Asian cultures are very good at collective good- Yes ... and orchestrating for the collective good, and we are allergic to it.
We have a problem with it. I think it's just- But there's only one internet. I think it's just more fuel to the fire, though, for digital sovereignty.
Well, and this is what we spoke about yesterday, the whole digital sovereignty thing. EU is saying, "I can't deal with this anymore. " And today, look again, yet again, here's another reason why we need to have our own data centers, our own regulatory structure.
The Europeans are so sensitive to security and privacy, given their history and world wars. " We can't be stopped by these negative roadblocks that have been set up, so. But again, there's one internet, and we see it with GDPR.
I don't live in Europe, and we don't really have any offices in Europe, but people from Europe come to our sites, and as a result, we need to be GDPR- Mm-hmm Mm-hmm ... compliant. Compliant, yeah.
And I think, good on the EU for doing this because someone has to. Well, and we have followed those leads before, right? Right.
With Canada taking the lead on- Yeah ... can spam, right? Absolutely.
That change. Well, we're not going to just do it for Canada, we'll just do it broadly, right? So we- We can't, right ...
behave according to these. And it's a shame, but... And look, back to where America, maybe that is our MO.
Let the other guy do it, and we'll just tag along and make it better. Then we'll do just enough of what we have to do to. Right, because we have to for them.
They're also appealing to the xenophobia. They're also appealing to the China threat. Yeah, well, no, that's why I said- And Russia ...
they named the four countries. Right. The axis of evil.
But unfortunately, with our AI strategy, it's always America alone. No, but this is the moonshot again, right? This is we go to moon not because it's easy, because it's hard.
But we made the Russians into villains, right? When the- You always need a straw. You need a foil.
A foil. Foil. Right, you need the foil.
Anyway, speaking of the EU, our friend Mike Bizard and half of our video team was in Amsterdam this week at KubeCon. We reported on that yesterday on digital sovereignty. But the new thing today is clearly the CNCF and the powers that be within that cloud native community are trying desperately to position cloud native infrastructure as the default or de facto standard for AI infrastructure.
Mm-hmm. This is what your inference should run in. Right?
We're not running kube on GPUs as far as I know. Mitch, you may know. Well, this actually was one of my prediction areas for 2026 is the emergence of what the AI stack looks like.
Particularly will we see something else that becomes the Kubernetes of AI, or will we see Kubernetes evolve? And with the momentum it has, you can argue that make the right moves. This case they're taking LLD, LMD, I think it is, that comes out of PyTorch that's been donated, in combination with VLLM, lots of alphabet soup.
But basically running models and frameworks for doing that, coupled now with Kubernetes, it's a great move. I think it's the right move. I think workloads are going to be built and running on Kubernetes.
The question is, what else is on top of that? I don't think, should we go build another Kubernetes for AI? Maybe Jensen wants to do that.
Maybe somebody else, but maybe we'll see that. I don't know. At the speed we're running, could happen fast.
I think the infrastructure's there, build on it, so leverage Kubernetes. I don't know. " And make a lot more money off of them.
And make more money. Why not? Yeah.
To me, AI is a new beast, and trying to retrofit this stack for this new beast, we may have to just because time is of the essence right now, right? No one's waiting. But eventually, I think you're going to get a better fit.
I do, too. But I think also, I don't think the move by any organization's going to stop AI from being what it needs to be. Right.
So, great for them because it's supportive. It's not counterproductive. I think it's additive.
It's not the whole stack. Right. It's not even close to the whole stack.
I don't think we even know what the stack is- No ... going to be like, right? We can- But just let's look.
Collectively between the four of us, except for Michelle, of course, between the three of us, what do we have? Probably almost 100 years. I don't know.
I'm only 25. I have to add to that number. I'm only 25.
Michelle is- Michelle is a little bit too young for that. Okay. Right?
But- Wow ... collectively- You're the spring chicken, Mitch ... but collectively, we've seen a lot of water under this bridge.
Yeah. Yeah. We've seen client server, we've seen micros, we've seen the rise of TCP, right?
IP- Yeah ... networks. We've seen the move to the cloud.
Kubernetes, containers, And now cloud native, right? Yeah. With Kubernetes.
Each one of these ages or eras had its own stack. Mm. Yeah.
Its own compute. Yeah. I just find it hard to believe that miraculously, this old stack is going to be just what we need for this new era.
I'm rooting for the LAMP stack. I'm still- No. No.
Let's go nostalgic. Yeah. Yeah.
Well, the LAMP stack, it sucks- It was back a while ... but it's still there. Then that's my point, is technology never goes away.
We always have this view of the next thing is going to replace all things before it. Mm-hmm. Yeah.
When does that happen, ever? Never. Rarely.
No. I mean, here's the thing- The biggest article I had on LinkedIn was about COBOL. Yeah.
And that's what I started my career on. Exactly. All the- And here's- ...
rise of the COBOL heads. Here's a metric for you. They estimate that probably only 15% of workloads, one five, actually run Kubernetes.
Oh, I believe that. Right? We're still largely- Oh, yeah ...
non-Kubernetes- Absolutely ... infrastructure. That doesn't...
New greenfield applications. Domino, what's new, that's where it dominates. Sure.
Yeah. For sure. So- Sure ...
we'll see what happens there. It's all good stuff. But you can see the connection of the dots.
VLLM came from Neural Magic, which really supported it, which got bought by Red Hat. Infrastructure was contributed, now part of CNCF. Right.
You can see these things come together. Yeah, we should mention that. Yeah.
So it's not like you're running your grandma's Kubernetes. Right. They have...
Your grandma probably- No offense to grandmas who use Kubernetes ... knew. Yeah, I get it.
Pretty advanced grandma. Yeah. Yeah.
My grandma, yeah. She was on stuff. But anyway.
Ahead of her time. But Red Hat did contribute some technology here that optimizes- Absolutely ... for the inference, and it's specifically for AI inference stuff, which is great for agents and all of that thing.
And they've contributed to CNCF, which, again, is part of Linux Foundation. And so maybe what we get is some sort of hybrid Kubernetes or a modified Kubernetes or Kubernetes V2 or something. Or a stack on top of Kubernetes- Yeah ...
or all of the above. Who knows? But this- Maybe there isn't one dominant stack in the age of AI.
We can build stacks willy-nilly. We can rebuild and create new ones. They're going to do very different jobs.
Yeah. So it may not be that there's a- Yeah ... one size fits all.
Yeah. " Yes. Right?
And I think if this thing works, great. If it doesn't, there'll be something else, but nature will find a way. And look, and don't bet against the CNCF.
Ah. Right? Those people have- They're not sitting by waiting for things- No ...
to happen. They're making it happen. They're trying to make it happen.
We're making it happen. Yeah. All right.
Hey, I wanted to jump to our next topic because I think it's going to be the longest topic- Yes ... of the day. And I wrote an article the other day, and I have my little graphic.
You can't use Princess Leia. Disney will sue me. But- ...
help me, agentic. You're our last, best hope. Clearly- I saw it ...
the message of RSA this year is agentics is here. This is the agentic era. We need it for a lot of reasons.
The bad guys are using it. The amount of code we need to govern and test and deploy and manage is exponentially growing. The only way we could keep up with it is with AI.
Michele, you're at the heart of this with what you guys are seeing. We are. We are.
I think that there's a few key issues. So thinking about the agents themselves- Mm-hmm ... I think a little bit of soak time, right?
Everybody's rushing out to do stuff, so I think a little soak time is going to help, and a little human oversight. We're super excited about agents, but I think it's going to take investigation, review to corral, tune, make it go the right way. I think part of the conversation, AI is super susceptible to the garbage in, garbage out problem.
Mm-hmm. And I think one thing we are seeing folks wrestling with is, what are the agents running on, and what is the state of that data, right? Think about how many aspects of doing a good job in security come back to simple hygiene.
Yeah. And people aren't super confident about their data hygiene, right? So having really good clean data at the front end of all this stuff we're yakking about, I think that's going to be super crucial.
And then I think the other thing is, we're going to get great insights. We're going to work fast to understand what we should do, but then you need to be able to do something about the conclusion of AI. And I think that that's going to be an interesting set of tension around...
Think about how many times in security we talked about, like, "Well, yeah. But don't turn it in blocking mode. " Right?
We're always afraid to do the wrong thing in security, and I think there's going to be a really big opportunity to take the outcomes of all these agents, tie that back into inline controls, because that point you made about machine speed adversaries, this is a very true reality today. Mm-hmm. Yeah.
And so all of it's going to have to go fast, but it's going to have to be fed in a clean way. You're going to have to have human oversight into the state and evolution of those agents, and then you're going to need to solve... Hoff said this years ago.
Everything ends up being a last mile problem. Yeah. And it's that closed loop part that you really need toTake response and actually take some protective action based on the outcome of all these agents.
And I think there's going to be a lot of tension on the inline control side. Yeah, I think there's a lot of good things in what you said. I spent all my time like you have when you were an analyst talking to vendors when you're here, right?
Yeah. There are kind of three camps. There are folks who are, "We're not sure what to do," or, "We've got a defensive position.
" There's a lot of folks like that. There's this middle camp of, "We're waiting for our new CMO, our new executive, our whatever. We're executing in place our current strategy.
" No executive gets hired to leave things the same. They come in and change stuff, right? Yes.
And then on the other end, there are a few people who think more kind of where I think things are going, which is at the speed at which software velocity that it gets created. We're in a world of which there are not enough humans on the planet to look at dashboards and telemetry summaries and traces. And we just don't have enough people to do that.
And when you take the microservice problem times a million, right? Which says at some point, we do have to tip over this chasm of we have to take action. That AI isn't just about better information- Mm-hmm ...
and putting it better together for humans to look at it. Right. It has to take action.
That agency is a stepping stone. I wrote an article about you and you and what you're doing with AI. And the article- Don't worry.
Thank you. You're very welcome. The article was, "Listen up, folks.
This executive decided to put some wood behind AI," right? Why? Because he did something with it and he saw it for himself- Mm-hmm ...
what the experience is. When we talk about trust in AI, only one thing builds trust in AI, experience with what AI does- Absolutely ... when it does things agentically.
So we're at the tip of the spear of talking about agentic and adoption is here, but there are vendors who are thinking very progressively about it's not about scanning, it's not about dashboards, it's not about data, it's about action. Yeah. It's about outcomes, to your word.
We have to- So, like a- ... move beyond observability- Yeah ... into- So, like a- At least what we think of today as observability Yeah.
So think about a year ago at this show, this was right before the fire hose of all these agentic AI announcements. They were just coming out every other week, and it was a concept. And now a year later, it's being put into place, put into practice, and even the companies like OpenAI, for instance, and I'm going to write about this, but they've already put the adult mode chatbot to death.
They killed it off. Yeah, they killed it per- And Sora is gone ... well, a lot is- And they extended- Sora, I wrote about Sora going away.
Yes. So when they're doing that, the poor CISOs... Last night I went to a Zscaler event, by the way, and there were a lot of really smart executives and other reporters were there, and I was asking about the themes here, and they said, "Well, it's agentic, but it's about the consequences.
" And I think we can- Sorry ... attest to some of the immense- It's your agent calling ... this legs up was.
What a rookie mistake, dude. Yeah. Didn't see it's your phone before going on air.
I guess I did it. Anyways. But technology.
The whole concept though is you're seeing a number of announcements that are trying to predict what's going to happen with data, where it's going to go, and then kind of try to get ahead of a problem, and I always wonder, and I always ask you guys the same question, but I actually do think AI's going to change the way cybersecurity is- It has. It already has ... it has.
Absolutely. It already has. They're moving faster and much more- It's changing how it's getting perpetrated, so we have to change everything to fight it.
It's much more proactive than reactive- Yes ... and yeah. Yes, 100%.
Let me put on my old man in security hat here. Get off my lawn, old man, or- Pretty much. Okay.
All right. Pretty much. Okay.
Get off my lawn, go play in front of your own house. " Never. Never.
Never. Right. It's always, "Stop the world, I want to get off to catch up.
" But that is not going to fly. When you have- It never has. Yes.
And it never will. Well, hopefully they will catch up sooner, but you read through the blow-by-blow, I just found the Anthropic blog around the AI, the first fully AI-orchestrated attack. Mm.
Absolutely fascinating. Is it? You could make a movie out of this.
They probably will. It's amazing. Well, I could in my AI, I'll have it write the movie.
Yes. Yeah. There you go.
While your Sora's up, you could do it. All right. Now- Wait.
Whoa, whoa, it's gone ... hurry up quick- Oh, there ... before they take it away.
Look, this stuff means that people are... It's just such a huge volume play. You want to see Back to the Future?
We have deception technology that we have at Zscaler. It's having this huge resurgence. " Honeypots with AI.
" Yeah. Yeah. And why is it having this huge resurgence?
Because they're recognizing it's going to be a volume play. Mm. Even though it's AI orchestrated- Mm ...
it's going to be somewhat dumb, right? And it's going to be somewhat like a brute force attack. But it's just, you're not- So you've got to get...
Exactly. Yeah. So you've got to get tripwires everywhere- Yeah ...
because they're going to do something, and that's going to be a really good high fidelity pointer that something bad is happening in your network. Back to asymmetric warfare, right? Yes.
It's not missile-to-missile warfare. But I also think it's a flip the script warfare. Use attacker behavior against itself.
Yeah. Go ahead. You go.
" Meanwhile, you're seeing all these reports about here's Meta, here's an open claw, here's a, what was it? The super intelligence executive emails- A little plan ... randomly just being eviscerated.
Yeah. Well, they don't have great... So, but if you're an enterprise, you're like, "Oh my God, if these pioneers are failing-" Yeah, but they're not security.
So, this goes back to Rich Mogull and I did a podcast 15, 18 years ago with the CEOs- ... " Yep. It's the same thing.
Meta, they're running as fast as they can. That's right. It's a race to who has the best AI.
Security has always been a little bit of a catch-up. But let me get nostalgic a little bit. I think we all agree, agentic AI is having its moment here this year at RSA.
I remember when NAC had its moment exactly 20 years ago today. Oh, you had to bring that up, didn't you? Yeah.
Well, Michelle's here, right? Scroll down the memory. I still have that wound.
Oh. And I remember you and I, Mitchell, walking the floor here. Michelle was at Century Networks.
They had some kind of wheel game- I remember that. Yes ... they were playing to give something out.
God, you have such a good memory. Yes. Yeah.
And- Yeah ... and I counted no less than 60 companies that had NAC- NAC ... in their thing.
They weren't NACs, but everybody was all about NAC, because that was the hot thing. Is everybody all about agents right now, because it's the hot thing? Will it be agents in 2027, or will we move on to the next thing?
I didn't see much zero trust here this year, right? Remember zero trust two years- There were announcements. Just go ahead announce what...
Yeah. It's there, but it's not the dominant thing. But I also think it's the under...
I'm not sure this is going to be... I don't think it's a fad. I really don't.
Because I think there's always interesting crossover when tech moves or permeates- No, I know that it's a fad ... both on the consumer side and on the enterprise side. Right.
No, no, it's real and it's not a fad. Yeah. It's not going to go away.
What I'm trying to say is the security industry has the attention span of a flea- Span of a gnat. Yes ... or a gnat.
Yes. Some little insect. Yes.
But there's no other way to do it. I think what'll be interesting is when that is not what is talked about. We are talking about a how right now, and we are not talking about a what.
Okay. " This is going to go on for I think through 2027, like agentic AI. Yes.
Yes. Oh, yeah. If people- It's going to go...
No, I think it's change-- Look, and Mitch, you wrote this article. I firmly believe it's changing the... It's not just changing, it's disrupting- Yeah ...
the entire... We're just in tech. Well, developers are truly at the tip of the spear.
Yeah. But the whole tech industry is at the tip of the spear. Yeah.
But these shock waves, seismic waves, are going to work their way through everything you see out there. Absolutely. But imagine today, you have to know what to do.
But imagine when frameworks are out there where all you have to do is imagine it, and you can build it, and that path gets streamlined. Everybody will be a creator- A builder ... a developer.
A builder Absolutely. To your point. Absolutely.
We're all going to be builders. We have agents that have some agency, meaning they can take action. The outcomes aren't necessarily the outcomes we always want.
I think that's going to be the conversation next year is agentic outcomes, right? But we still have to build all the scaffolding around it. 100%.
For what OpenClaw is and all the things it lets you do, you still have to build the scaffolding around it. For what Clod code and OpenAI's Codex models are, yes, you can create a snake game. Big deal.
You still have to build a lot of things around it. But Mitch, what you're missing- I'm not saying that's the state of where it stays. No, no, I'm not saying it either.
I'm saying that's where we're moving. But I'm telling you in terms of the speed of moving there- Yes ... when AI is helping you create the next version of AI- It already is ...
it is. It already is. And that's why you're seeing this acceleration.
So AI is going to build its own scaffold. It's going to. It's already doing that.
And that's the resistance isn't going to be that normal cycle. Just in the last three months. We're going to have to wait a year.
In the last three months of how much cloud code has changed, it's all about not just multi-agent processing, it's building more of the scaffolding. Yep. Now it's figuring out, "Oh, I need to test this stuff without Mitch telling me I need to test this stuff," right?
" Okay. So it is this incremental building up that now... " Oh, this is how you ride a horse.
So you're just teaching it how to do it. And it's learning. Someday it'll be a master at it.
Here's an interesting thing. I read real life true story, right? So I have pushed agents on everyone at Textron.
I don't care whether you want to set up, as best as we can, secure OpenClaw, or you want to use a Perplexity computer or some other agent, I want you to use it. I want you to tell me what you're doing and what you're thinking, right? Is it good, bad, helpful, not helpful?
Yes. And now my security hair is what little hair I have left. My security hair is on my next adopt.
Where might we see a resurgence of zero trust? Right there. In agent-to-agent communications.
Agent to agent communications. You're right. We're absolutely going to need to have some oversight.
" Yeah, but we're live, so it's okay. It happens. People come in.
Yeah. You're popular. Yeah, I know.
But no- What a photo bomb that was. That's my friend Claudia Ringes. She's a great lady, but anyway.
But this is what we got to do, right? Yeah. Where do you draw the line?
How- Our agents are already talking to agents. They're already doing this. I know.
So... I know, but it's like taking a Waymo. Well, you live here.
Yeah. Have you been driving Waymos? It's not fair.
No. You live here too. No, I've sworn off Waymo.
No, I haven't. So by the way, the parking lot that I used to use when I worked downtown, which basically could hold 1,000 cars, it is now a Waymo station. I drove by there today.
There were 1,000 Waymos in there. Oh, there's more Way-- I started taking... A, they're half the price of the Ubers right now, and they come quicker.
But when I first started taking the Waymos, I got to be honest with you, I was a little uneasy. Mm-hmm. Right?
" I said- ... " But- Don't press that red button ... in two days.
" It's great. This is way better. Boy, it is drastically better.
Trust, what did I say? Trust is experience. Yep.
You know what? It's- Gain experience ... exactly.
It's experience. So I think that's what we're going to see with- Yeah ... agents- Yes ...
and AI as well is- Yeah ... and taking the Waymo example- But what that means is we're going to have to understand what they did. We're going to have to be able to look- Yeah ...
at all of that. Yeah. So we're going to need agent audit trails, and we're going to need...
Because that is how we will- We need to talk about... I have something called observability native, which is building that in inside the agent process as well as the environment it operates in. So I'd love to chat.
They used to train Waymos on just these really safe routes. They're on the highways now, and they are inter-moving within... And they are the best drivers.
No doubt. Look- Oh, I bet, yeah ... here especially.
My wife's car has autonomous driving. It's a BMW. It has autonomous driving.
I don't use it on streets, but on the highways, I love it on the highway- Mm-hmm ... because you just... Again, same thing, though.
The first couple times, I stood there like this- Right. Right ... ready to grab the wheel.
Right. And then- Just imagine enterprises using agentic AI. They are kind of gripping the wheel right now.
No, you can't grip the wheel. Yeah. You got to be right outside the wheel, ready to grip.
But- Yeah ... so let's bring it back to what you all... You've walked the floor, I assume.
Mm-hmm. I haven't even been to this floor yet, but I've spoken to enough people. You've spoken to people.
You've been around. Who are the people just putting NAC in the name- ... versus the people who are really doing it?
You don't have to name names. No. But what do you think?
Yeah, I'm not in a position to judge. I think, actually, this is one of those things where I walk these floors, and I just have such empathy for the- ... actual buyers.
Mm. " Yeah. Sifting through...
Look, I can see it both sides, right? I used to be a journalist looking for truth, and then now I'm a marketer, and so I have to give you a story. And the people who have to sift through all these stories, that is really hard.
Because what do you have to do, what do you think about as a marketer? Brains need buckets. I need to tell you what I do.
I need to use language you already understand to tell you what I do, and then I have to tell you why I'm special. And so the classic thing as a marketer is your CEO comes over and goes, "Our homepage looks like everybody else. " Right?
So that tension between explaining it in a way that people can understand and having it sound differentiated, that's really tough. But then think about this poor audience that has to try to sift through this stuff and distinguish what's real. I think things that we're thinking about on our side are things like, how are we very specific and not exaggerating what we do?
How do we explain the limits of what we do so we're not over-promising? And how do we make it visible to people, the outcome, the process, the audit trail, the security around how agents work and communicate? We're going to expose it all because it's only, we think, the other side of trust is transparency.
It's experience and transparency. I agree with that. So I think people are going to need techniques within their companies to vet out what's real or what's not.
You can't tell- Yeah ... walking the floor. It's interesting.
We're in this... Because you do need all those things, right? To clearly communicate your story so people get it.
A, it's changed so fast, it's hard to recreate that story- Right ... and not sound like you're a different company every day. So everybody is, and I don't mean this in a...
I've seen this in a pejorative way, but everybody's bag diving for demos, because that's the only way they can really- Yeah ... kind of show you- Yeah ... what they're talking about.
We're absolutely where you don't have- We're in the demo phase ... nothing but the bag dive. And the demo is of the preview.
Quick demo. It's not of what ships today. So that's where we are.
So there are a couple people I talked to this week who were here for two weeks. So last week, they were at GTC, the NVIDIA show in downtown San Jose, but that, by the way, I think is going to move to Las Vegas. It's too big for San Jose.
It's too huge. It's too big. 30,000 people.
And it was, given that tsunami wave of what happened there, it's interesting to hear kind of the follow-up to what, it's like, "Oh my God. " And I think it's kind of an interesting dichotomy to have these two back to back. And now coming up, this is the trade show season.
We're going to see a number of shows in Vegas that are specialized for agentic news from Adobe, ServiceNow. Yeah. Zscaler's going to have one in early June.
It's back to back, week to week- Week to week ... through June. It's every day.
It's every day. And thatBecause we're running low on time. That's the signal.
That's the signal running through all three of these segments today. AI, and it's specifically agentic AI, is dominating. Dominating not just our news, our lives, our industry- Yeah ...
our thoughts- Our inboxes ... our inboxes. Which you can get an AI for that.
Yes. So this ain't NAC. Right.
Right? This is- 100% ... this is civilization.
I said it before, I was here when the internet first went commercial. Yeah. I haven't seen anything like that since this.
Yeah. And this may even be bigger. Bigger.
You know that truism that people say that we tend to overestimate the power in the short term and underestimate- How long it takes ... in the long term? Yeah.
I don't think it's true for AI. I think it's hard to overestimate the impact in the near term. This is how big this is.
Yeah, the hype actually is real, and it's actually long-standing. Comes true much quicker. Yeah.
With shorter cycles. Because we've democratized a whole set of capabilities. Right.
So we're going to use it and power it and move it forward. I think this movement now, this time, is as big as all the rest of them combined. Well, we've also collapsed the time- And it's way faster ...
we've collapsed the time from idea to outcome. Yes. And first mover advantage, there's no such thing.
Week to week, day to day. This afternoon, I can have an answer to what you announced this morning. You know what?
I'm going to even go out on this. Is OpenAI or Anthropic too big to fail? Well, they got the model.
We know this from cycles through industry. The missionary doesn't always win. Someone else comes by and whoops- It's usually the fast follower.
Right. I think it's he who owns the spice. He who controls the code controls the universe.
Controls the universe. All right, Emperor. Hey, on that note, let me just put this quick wrap up.
Love doing RSA every year. This is, for Mitch and I, it's about our 25th RSA. Yeah, it is.
Something like that. And Michelle, you've been here for a few as well. Ah.
You have, John. Decades. Yeah.
And it's a great place. It still remains a show by the security industry for the security industry. I hope it stays that way.
We'll see you on Techstrong, gang. Tomorrow, I will be traveling. I think Mike Vizard will be back home, and he'll be manning the helm.
But until next time, on behalf of John Swartz, Michelle McLean, Mitchell Ashley, enjoy. We're out.