MCP 2026 Roadmap, AI Micropayments and Synthetic Identity Warnings | Techstrong Gang
Mike Vizard, Jon Swartz, Tracy Ragan and Jack Poller break down how the 2026 Model Context Protocol roadmap turned MCP into the de facto agentic AI spec even before the tooling is finished. They walk through the scaling milestones, governance gaps and the operational debt teams will carry if they treat MCP as a solved problem.
The Gang then turns to the Linux Foundation’s plan to make the x402 protocol the clearing layer for AI micropayments. They debate what it would take for autonomous agents to settle tasks in real time, how Snowflake’s SnowWork and similar platforms might plug in, and what kind of telemetry enterprises need before giving software wallets spending authority.
Finally, the panel reacts to LexisNexis research that shows synthetic identities already slipping into onboarding flows. From zero-day hires that never existed to deepfaked HR files, they outline the cybersecurity and compliance guardrails needed to keep tomorrow’s AI-enabled workforce honest.
Transcript
Hey, everybody. Welcome to the Friday edition of the Techstrong gang, and for those of you who are observing, Happy Easter. We're in front of that weekend here, and I'm sure a lot of folks will be visited by, well, hopefully bunny and chocolates and candy, and everybody will have a good time this weekend and take it easy.
But before that, we're going to get starting with some unusual conversation about all things AI that may come as a surprise to all of you folks, but please welcome Tracy Reagan. Tracy, how you doing? I'm doing great and as well.
All right. We're getting a little feedback there, so hopefully that'll even out soon. Jack Pollard, good to see you again, my friend.
How are you? Doing very good, thanks. Back from RSAC and ready to chat all things AI instead of security.
All right. And John, Northern California, all is good? How you doing?
All is good. The Giants have won three of the last four after the Yankees wiped the floor with them. So I'm happy.
Happier, yes. And then the Yankees went off and played Seattle, and reality set back in. But what do you know?
Long season. Long season, here we go. I can't keep throwing the same pitcher every day, that's the problem.
But other than that, we'll be okay. But let me tell you about some adventures I had yesterday here in New York. There was an MCP Dev North America conference here, and about 1,200 folks showed up for this event, and it was talking about this Model Context Protocol that Anthropic created, and has now been donated to a foundation that's run by the Linux Foundation.
And, it was amazing. " Turns out that somebody wrote a blog post talking about how, well, from a developer perspective, it's easier to just use a CLI and have the AI tool just call the CLI because it's lighter weight, and it doesn't quite require as much complex loading of tools, and it was the talk of the show early on. And then quickly, it moved into, well, what are we going to use MCP for?
And then it turns out, well, maybe behind the firewall, MCP servers will be used to expose data and share data AI applications. And then there was some discussion of the MCP roadmap, which includes an upcoming update in June where there's going to be a stateless version that will make it easier to spin up for cloud service providers, and it'll be a little bit easier to deliver something like that on demand, apparently. And it was also interesting that, once again, security, well, was a little bit of an afterthought.
In fact, I don't think anybody on stage mentioned security whatsoever. And meanwhile, we have all these security folks who are looking at MCP out there going, "You gotta be kidding me. " And apparently, the MCP folks are studying what extensions might need to be made, but studying is code for ain't happening this year.
So it's going to be an interesting time out there with all these MCP servers. Tracy, I know you're looking at some of this stuff, but what's your general impression of MCP these days from a developer perspective, and is this just moving faster than we can handle? Well, I hope I have...
Sorry. If it's not... Well.
Anyway. Can you hear me? No?
No, not really. I don't think the audio's going to work. Okay.
So- Let me just let me jump off and I'll come back on All right. Well, let me go to Jack here, and let's talk about the security side of this thing because I know you've had a previous column talking about how maybe we are a little bit over our skis here when it comes to AI, and MCP seems to be the poster child for, well, insecurity. Well, I'm glad you brought that up because I read your article, and it sort of said essentially what you said in lead-in, which is, "Yeah, we'll think about it maybe sometime when we feel like it, and then the good vibes happen, and it'll be okay.
" Like nothing could ever possibly go wrong with MCP. We have 40 years of history of doing this type of stuff, and why is it that security still takes a backseat to functionality? I thought we were beyond this already.
Clearly we're not. And I will say that at RSA, when I was talking to people, the number of people who basically... Although, I think there was an MCP is dead thread going around, right?
And that was a common topic of conversation. But more importantly, a lot of people said that MCP is really just essentially a catalog or an inventory of your APIs. If you know that the API exists out there, why not go directly and bypass the MCP server to begin with?
If you don't know the APIs, well, then you're just getting an inventory of it. Once you get that, you should still go around it because it's just a bump in the wire, and it's causing roadblocks, and it doesn't add much value. So I think that there's some questions, now necessarily that that's my opinion, but there's a lot of people walking around saying that that's an issue.
And again, security as an afterthought rather than security baked in from the beginning, and, oh, we don't care about security, it'll happen sometime. It's just, I don't see it. I just don't understand that attitude.
I don't know. Tracy, you back yet? How's the audio?
Hey, Mike. I have a quick question, because I found this interesting. And the one thing that stood out to me was this concept of stateless servers, which sounds pretty ominous to me.
And if that's the case, what is the new state boundary, and how do platform teams design guardrails where agents are acting first? To me- Stateless just refers to the idea that the thing is going to be available on demand, and you're not going to give it persistent storage, and it's kind of-Like Kubernetes was initially created for stateless application environments, and then we've been trying to shoehorn it into stateful applications. Well, MCP's kind of the opposite.
MCP kind of started out with data-centered focus, but now we need some way to spin up an MCP server up and down because, well, if you're a cloud service provider, people don't want to pay for something to be persistently on all the time, and so that's what they're kind of getting out of it. I'm not sure it's ominous, but it's going to be, depending on the use case, you're probably going to need both. But Tracy, let me see if I can hear you first.
All right. Is this better at all? Better.
Much better. Okay. I switched mics, so maybe my mic got sat on.
All right. So what I was thinking when I read this, Mike, is that if you look to see who's behind it, Google, Microsoft, it makes me feel like MCP is going to be part of the infrastructure. Right?
First, when I read the article, I was like, "Oh, okay. " How is it different from OpenClaw, right? And then the more I read into it, the more I realized this is a shift in direction for MCP.
And I think it's going to be really a part of a infrastructure layer that's more enterprise. In other words, it's not just managing tools. Like OpenClaw manages tools, right?
And it's a platform for tools. But I think MCP now, the way that they're talking about it, I believe it's going to be part of the infrastructure, and that's the difference. I think you're spot on with that.
And the part that I'm kind of scratching my head about, it's like, well, most people just kind of figured out what the protocol actually stands for, and now we're saying that- ... from a corporate perspective, we're tossing this thing out. So are we at a point where maybe we're just moving too fast, or is this just part of the natural experimentation of all things AI?
So this is the thing, as we work on for Artillus and DeployHub, building an AI remediation, we realize we have to have three parts of it. We have to have our sensing and our reasoning and our acting. And we're comfortable with doing sensing and reasoning with AI, but not acting.
And for some reason, we're more comfortable with using an MCP server to do the acting because we can build into that MCP server a human in the loop, like creating a pull request, right? I don't think we're going to jump on having agents make decisions or buy things. However, I can say that the more I look at that model, the more I'm thinking this is how we would build internally our own growth engine for sales.
I don't know if we'd put it into our product right away, but definitely we would use it. Mm-hmm. John, there are already people who have built and deployed hundreds of these MCP servers that are out there, and at Tracy's point, they are going to show up more and more as kind of infrastructure in the enterprise for providing people access to data with some governance policies probably tossed in on that.
And I think the folks at MCP technical committee, or at least that's one of the things they're looking at in the future is the ability to do that. Are we getting to the point now, maybe John, and you were just at RSAC, but- Yes ... are we finally talking about the governance aspects of all this stuff, and are we- Yes ...
starting to think about this? Yes, they are. They're digging deeper into governance, guardrails, self-policing, quotas, identity.
They're pushing this whole idea because I think, and I think one of the takeaways I got from this story is that the reality is that agentic systems are going to have a big impact, and they are happening. So we've accelerated, I think, accelerated the pace of addressing things that were not top of mind, like governance and guardrails. So I do think this is playing into that kind of movement, and I think at RSAC, I heard more of that.
There was more of an emphasis on getting up to speed on security and the welfare of whatever you're putting in place. Right. Jack, did you get the same vibe, or are we just waiting for some cataclysmic event before we get serious?
Oh, I think we're waiting for some cataclysmic event. But I want to go back to something you said, which is, maybe it's just me, but I really don't get the concept of a stateless server and an ephemeral server. The whole point of MCP is discovery of resources that are out there that you don't know about.
And if you can't find the discovery engine because that's gone and down, because that only fires up at certain times, then it's rapidly losing its utility. And when we did Kubernetes, we learned very quickly in Kubernetes that state is very important, and having a system that has no concept of state drastically reduces its utility, which is why we had to shoehorn state back into the stateless environment. So the idea of let's say, how do we carve out and take some functionality away and make this thing disappear, I just don't understand.
And maybe Tracy- The other reason- ... you can help me on that one because I don't get it. Or John, you can...
I don't know. I was going to say, two things can be equally true. I think what you're saying about RSAC, just a really quick addendum- Yeah ...
that these folks are more self-aware of governance, but they know it's inevitable there's going to be some major glitch. So just to qualify. I think stateless just comes down to the fact that I want to be able to scale something up real quick, and then I need to just get rid of it because I'm only accessing that data temporarily for a narrow use case, especially if I'm a developer, per se.
So maybe I'm notYeah, if I'm building some sort of enterprise app where that thing is connected back to a system of record, probably stateful. But there's also other instances where I don't necessarily need that thing to be around permanently or for longer than the session that I have it for. But Tracy, is that about right?
I don't know. I would think that this new version of MCP that they're talking about, it introduces like a stateful pattern, right? Because they're talking about lifecycle memory, they're talking about long workflows, so I think it's actually moving away from a stateless MCP concept.
Yeah. I really do. I think they're building it so these long-running tasks are going to be possible.
Yeah. Well, so they are doing those other things as well, that's not necessarily tied to stateless per se, but those are other projects and things that they're looking at to make more long-running things. So it's like, to what John was saying, two things can be true at the same time.
I think they're connected, to be honest. Yeah. I think that there's a reason that we're hearing about both of those.
We talked about last week, we talked about some of these changes, and this reflects those changes, in my opinion. Right. Well, the question- Especially to Kubernetes.
I mean, the Kubernetes cluster, when they're talking about the changes that they're making, they're changing it for... They're making it less stateless, let's just put it that way. This is true.
They are definitely heading in two different directions, and I think one is just to satisfy the cloud service providers that have some unique requirements around the stateless side is what they're... Because apparently Google and Microsoft are at the front end of that particular end of the horse initiative, as they say. And then, the rest of this stuff, though, is much more enterprise-centered, and one of the things that did come across is that they want to make this an enterprise class standard.
But to Jack's point, Jack, if there's no security, then what's the chance of that happening? I don't know. I feel at this point I've beaten that horse to death.
The security aspect of MCP is not well understood yet. We really don't understand all of the different ways that people are going to use MCP, and therefore all the different things we have to think about and consider. And my issue isn't so much that we haven't thought it all the way through.
" Right? " Whether it's an ephemeral instance in a cloud provider or a full-time stateful instance in an enterprise environment, it's expanding the attack surface, and it's still going to be a huge target for people because an MCP is another gateway to all of your data, and there is theoretically that MCP server and that MCP workflow and pathway are connected to all the corporate databases, the systems of record that has the prize data that the attackers want. And- Right ...
to put security as an afterthought, I just think it's 2026, not 1986. We should be beyond this at this point. I mean, Jack, security by design should be what we think about when we're building any of these new pieces of architecture- Thank you ...
that everybody's rushing to, right? Security by design. But the truth is, we haven't even figured out how to secure our basic Java code at this point.
So we are- Yeah ... we're behind the eight ball on all of this. Yeah.
But it would be really great if this could be built with the security by design kind of philosophy. It seems like the theme of RSAC, and you're just kind of speaking into it, is this idea that everything's hurtling forward. Everything's a work in progress.
We don't know where it's going to be. We know something bad is going to happen, but we're going to work through these issues kind of in a nebulous way. And that always bothers me.
And it seems like it's the same state year after year, no matter what the conference is. " Used to be testing. Quality control.
It used to be the last thing you did when it broke. Look, I understand. When I look at development organizations inside enterprises or people doing professional software development, software developers are compensated on feature functionality and schedule.
And until we compensate them on security as a major aspect of what they do, they won't take it seriously. I put that in a different category, however, than people who are designing protocols and architecting these types of things where they could delay it by a week or two weeks or a month. " Yeah.
We're going fast and breaking things, the hell with it. Yeah. That's the Facebook ways.
It's Silicon Valley ways. Well, if it makes you feel any better, the OpenSSF Alpha Omega project just got a $12 million infusion to try to sort some of this stuff out, so maybe some of that money... Not enough.
There's not enough. It's just- But it's an acknowledgement that there is a problem I'll take any baby steps we can in the right direction. Exactly.
Well, we had a show, I think it was late last week, talking about that very donation and why it was basically- It was futile ... a drop in a bucket, but I'm going to refer people back to that other episode. Go check that out.
But I do want to shift gears here because, yes, we are talking about, well, works in progress is kind of the theme of the day. So shifting a gear here towards the Linux Foundation also had an announcement at the conference where they're taking the X402 protocol that was originally created by Coinbase for micro payments using blockchain, and that's now too in its own little foundation. And the idea here is that this is the way we're going to let AI agents and buy services and content for that matter in micro payments, which is loosely defined as anything less than a penny.
John, are we kind of scrambling around here a little bit for a way to create a business model for a lot of this stuff? Yes. Like charging for this?
Yes. Or what's the deal here? It seems like this, yes.
There's the profitability angle, this how do we cash in, how do we monetize this? What is this, like a universal standard for payments that would embed payments into web interactions? So I know that in addition to Coinbase, I believe, is it CloudFlare and Stripe are part of this governing body.
And some of the participants are... I mean, they're major players. We've got AWS, Google, Microsoft, American Express, MasterCard, Visa.
Got some crypto native rails. That sounds interesting, but again, it's an endpoint they're trying to reach, the how do we get there, which just kind of hearkens back to our first segment. And so I guess what enterprises are trying to do, correct me if I'm wrong, Mike, but are they kind of reconciling how agent micro payments can be built into their budgets, approvals out of chargebacks, what have you?
They look like they're kind of searching or trying to reach out for some sort of business model, and I don't know, it just seems early and it seems kind of formulaic and pie in the sky. But- Yeah ... at least it's a baby step.
I think you're touching on it exactly because turns out there are other protocols that people are building out to do payments, and I guess this one's more for micro payments and digital currencies. But, if you look at that A2A protocol, there's been extensions to that, and I think Visa's talking about protocols that it wants to support for payments and cross using AI agents as well, and it may very well just come down to like, well, what is the value of the transaction will determine what protocol you're going to use. But Jack, once again, I'm not seeing the word security in any of these initiatives.
Do you want me to... How much foaming at the mouth do I have to do here? I'm sorry.
A lot more. A lot more. A lot more.
Thank you, Tracy. A lot more. Yeah.
Like nobody's ever going to hijack your ID and crank up the number of transactions you're doing and just chew through your micro payment budget, so it's not hundredths of a penny, but thousands of dollars at... Because these things are operating at machine speed. It's not a human that's making these transactions.
At some point, it's going to be machines sitting there cycling through your micro payment budget very quickly. Now, on the other hand, I do understand that if on the backside of your API there is more AI and you're paying on a token cost and you're racking up big bills because a lot of these AI transactions are not cheap in terms of tokens and whatever you're doing on the backside. So limiting, doing some sort of payment to use an AI that's behind this payment gateway might make sense.
But on the other end, it's anonymous, so you don't have to have an account to do it, it's just some random wallet address making a payment to some random server somewhere. That might help with some organizations offset, particularly smaller businesses who may do something interesting. It might help them offset the cost that they're dealing with.
But again, without the security here, there's, I don't know, I hate to use the phrase, but what could go wrong? Yeah. Well, I want to believe- Oh, go ahead, Tracy ...
I really just want to believe that the reason why the Linux Foundation is doing this is because they want to standardize the protocol. That is initially what they're doing, and that's what the Linux Foundation does. They standardize protocols.
They've done it for the movie industry, and now they're doing it for this, and they're a great place to go to create that kind of governance and standards and kind of a community ecosystem to discuss this and possibly make it better and more secure. So I can only see good things coming from it. Yeah.
So if this were to advance, I'm just going to ask follow-up on something Jack had said. So what would be the first killer use app when we think of a B2B agent to agent services, pay per request APIs, what could it possibly be? I was thinking the cost of accessing an article by John Schwartz would be two-tenths of a penny, and then it keeps those- That much?
Sorry. Well, and I have one thing to follow up with Tracy, which is, there's this other association called the IETF that has been defining the Internet protocols since, oh, I don't know, the very beginning. And I'm not going to have an argument over which group should own a protocol, but there are lots of ways to standardize these things, and I'm 100%, I've been involved in the IETF many years ago with SNMP.
But I don't know. And if we just go back to our last conversation, right? Right.
This would allow this multi-tenant kind of conversation, right? Adding the agentic AI into the MCP workflows. So don't we need something like that so these AI agents can buy things from each other in a standard protocol?
So again, I feel like we're seeing a change in the infrastructure. Well, John brought up an interesting thing, which was the concept of bill-backs or chargebacks. And my wife was in the biotech industry for many, many years.
And the company's, very big biotech companies, every three years, they would have this argument over whether things like IT resources should be spread evenly across the organization, in every department and every division within it, pays X percent across the whole thing. Or if you charge per call when you call the IT helpdesk, and they would say, it would get flared across the organization. " So maybe this is another way we can do things bill-backs for.
If you think about an organization that invests a million dollars, $5 million in a bunch of GPUs, and there are a bunch of different teams within that making use of that, this is one way to do charging and appropriate accounting for it without having the accounting overhead of dealing with bill-backs. Oh, I can see how we would build it into DeployHub without a problem. Yeah.
As opposed to charging per seat on some- Yep ... number that we come up with. Anytime that they update a SBOM or, remediate a vulnerability, they get charged some coin, right?
Right. So- Then it seems that everything has a flat fee that everybody will agree to, and yet everybody I talk to is thinking about dynamic pricing models. And so I look at it this way, and I'm kind of like scratching my head, let me see if I understand this.
So agent A is going to try to buy something from some other agent B that's trying to sell something. Agent A is designed to buy that thing at the least costly way possible, and agent A, the other agent, wants to sell it at the highest margin possible. And won't these AI agents just kind of try to negotiate with each other until the point where they give up and call us to resolve it?
I mean, how would they know who- I ask the same question. It's like, how do they resolve this, right? How does that get resolved?
I don't know. Mm-hmm. I mean, obviously- There's like who has ultimate authorization, too?
I mean... Right. So I think that this too is a lot of work in progress, and I think there's a lot of wishful thinking about how to make money, and I don't disagree that there needs to be some protocol that enables the transactions and provides the underlying transport.
But I just feel like the business models for all of this are hardly well thought out just yet because it kind of makes some assumptions about how things are going to be bought and sold that, in my experience, don't necessarily ever pan out that way. Fair? Fair.
Yeah, I'd like to have some input from the actual customer, the consumer, the people affected. Because, again, as you mentioned, Mike, is like security is nary a word about that. It's kind of an afterthought.
Yeah. Well, the good news is somebody's working on it. Bad news is, well, the plan is maybe not as far as developed as it should be.
And so I'm a little dubious that we're going to see all this play out in 2026, so this may be- The concept of a plan ... a phenomenon. Yeah.
And in real time. We'll do it in real time. Yeah.
We will. We'll experiment with people in real time, which is actually, if you look at both these two stories, is what we're doing, right? We're experimenting on people in real time, at scale, and hoping for the best, and we'll see what happens next.
Anyway, I'm going to shift gears to our final topic, which relates to a story that Jack has up on Security Boulevard, where he's talking about the rise of, well, synthetic agents, I guess, who are going to start to do things, or we're not quite clear what their mission is. But people have kind of figured out that I can have these kind of synthetic things set up, and we've already got... I don't know, Jack, I think I read the story and it said something about 3% of traffic out there is already attributed to some of these things, and it's only getting worse.
Yeah. Well, so first off, this is not a work in progress, this is an actuality. Right?
The actuality is- Of course it is ... of course it is, right? Because criminals, the bad guys, they don't wait for the security to get resolved, they just go and do.
Mm-hmm. And in this case, what they're going and doing is developing synthetic identities. So synthetic identity is something that looks real and has a lot of real attributes, and actually takes time and effort to set up.
And typically, what you do is you take a stolen social security number, a date of birth from somebody else, a name from somebody else, and photos, and the AI manipulate the photos, and they build what appears to be a real person. And over time, that person has credit history or financial data associated with them, and it looks more real. Now, these originally started out as a way, consumer fraud, to get access to consumer goods or banking, and steal banking stuff.
And now it turned into, to begin with, the North Koreans got very, very good at this, and this really- Mm-hmm ... I heard about this actually starting back in the COVID days- Mm-hmm ... of creating synthetic identities that would go and they would mass spam IT organizations for remote jobs, get those remote jobs, and basically take that salary and-Run with it, and that salary would go to the North Korean government.
And so the North Korean government was getting hundreds of millions of dollars a year through synthetic identities. Almost every single Fortune 500 CISO has said they've been attacked in this way and have had synthetic identities hired into their organization, where people get hired that way. And now what we're starting to see is these types of things appear in other areas.
Originally, like I said, it was consumer, then hiring, and now they're starting to appear, we think, in the agentic world and some other areas. And so there's a lot of effort being put into how do you defend against this? How do you identify a real physical human being versus an AI fake of a human being and backed by a synthetic identity?
And I don't know if anybody else has... There was a while, like two years ago and last year, there was a big thing on LinkedIn where people would connect to you on LinkedIn with these weird titles. And you'd go look at it, and you'd have a face and a whole LinkedIn profile, but it was for either a fake company or it was for a real company.
But you're like, "There's no way that the CEO of a Fortune 500 company is trying to make a LinkedIn connection to me. " Or the CISO or the CIO, or whatever. It's like these people created these identities out of thin air and started connecting to people and would lead to other scams.
So it is a big problem that's been going on for a while, and now we're starting to see it appear elsewhere, and it's rising. Up to 10% of the fraud, the things that we see in consumer fraud, is synthetic. So how do we detect that?
Yeah. How does that even work? At some point, you'd think you'd want to be on a Zoom session with the person you just hired.
Yeah. Well, so this is- It confuses me. How do they do this?
This is where it gets very interesting is that the AI deepfakes now are good enough to have less than a half a second, often a quarter second or less, delay. So I can take a real-time AI system, and it will superimpose a completely different face and body over me. So when I move my hands, it'll move its hands, but it'll be your face, Tracy, on my body, and it's very hard for a human to detect these types of things.
So the very first thing I heard about this was somebody hired a person, on remote, this was during COVID, so everybody was doing remote hiring, and when that person, quote-unquote, started, that quote-unquote person started working, they started asking questions that had been covered during the interview process. And so the company started thinking about and saying, "Wait, we discussed this already. " And then they realized that they were faked by this, and so they asked that person to provide some additional information.
That person disappeared, never showed up again, so they knew it was fake, right? Now, like what I said, with deepfakes, it's getting better. There are companies building some very interesting technology to fight against this.
So one company I know of is iProov. What they do is we're using a cell phone, we're on a cell phone taking your selfie videos. They randomly change the background that they're showing you, and they're reading the reflection of the background off of your face.
So if they show black, you should see a reflection of black. If they show red or yellow or white, they should see some of that reflected in the image. So they're able to do that essentially in real time and detect that, so the AI can't keep up with that random change and do that.
Because it's doing the face superimposition but not the reflections. So that's one way they're detecting it. There's a lot of other interesting analysis companies that are going on to try to do liveness detection.
Is the person in front of us live or fake? Well, I've been in meetings with real, live people, though, who can't remember what meeting and what was said the week ago. So I don't think that's a fair assessment for determining what's synthetic because ...
Maybe Alan needs a little extra caffeine every morning. Oh, wow. But I didn't say that.
Hey, Zach, I'm going to congratulate you for this quote you have in here. I think this is a fantastic quote, or it's a line. " And I'm wondering, if this progresses with deepfakes, could conceivably, if you're a rogue nation or a hostile country towards, say, the US, you embed somebody with a synthetic ID to be essentially a spy?
Is that totally crazy, or could that happen? No, that's essentially what's happening today. Now, North Korea is doing that today.
Their motivation today is money because they have none, right? I'm thinking beyond that, though. Yeah.
Right. But beyond that, so right now, they're targeting IT organizations because they do a lot of remote hiring, and remote staffing organizations in general. And their idea is to get somebody in to get access to the IT databases to steal info and to take the salary money and any other money they can exfiltrate out of the organization.
But it is perfectly conceivable to think that a synthetic identity could get into a secure organization or military or government organization and get access to information that they shouldn't have. Now, I hope when our government does background checks on employees before giving them security clearances, that they actually do check for these things, but I don't know. I haven't been involved in background check process in 40 years, so I don't know exactly what happens there.
So let's play this out to the 10th degree, right? Because we had a session on the gang, and I think it was on an article that John wrote about how bots and AI agents are already outnumbering humans on the internet. SoPlay this through.
At some point, we could have more synthetic identities on the internet than there are actual humans per se, or even maybe legitimate AI bots or whatever you want to call them. At what point does the weight of the thing just collapse? Because if we have so many more synthetic identities than real identities, people are just going to go, "This defeats the whole purpose of the exercise in the first place," Jack.
That's a good question to which I do not have an answer. Is it- Once the synthetic identity conversing with another, maybe one's good and one's bad. The good one's not going to be able to figure out that the other one's a spy or a fraudster.
That brings a whole new meaning to good versus evil. We're back to our discussion about agentic AI talking to each other, right? Yeah.
Because the synthetic identity's going to be negotiating on behalf of the- Of an agent ... MCP servers and agents. No humans involved, yeah.
Literally no real humans involved. Still don't understand. Okay, so I accidentally hire this synthetic person.
Yes. Does somebody go and do the work that they've been hired to do? Yes.
Yes. So, in Korea, those people then are getting some part of the money, and the Korean government's getting the rest? No, they get fed by the Korean government.
That's all. If they don't do this, they're unalived- I get it ... essentially.
Right. These are the Korean military officers. They have a huge cybersecurity group, a cyber attack group- Attack ...
not cybersecurity group. They're very good at these things. That's what they do.
This is how the Korean government essentially pays for the rest of its stuff is by stealing. So it's only going to work in that- North Korea, actually ... kind of a situation, right?
Yes. It's not going to necessarily work in Russia because- So they- ... Russians get paid for the most part.
Right. But what's happened here is they've actually had, and I can't remember the exact term, but they have laptop farms. There was a woman arrested here who was making something like $3 or $4 million a year running a laptop farm, where she basically just had laptops sitting in her office or room or whatever that North Koreans were remoting into, and then using that to access their American target companies.
So that would allow them to work on North Korean time, but appear as if they were in the United States with a US IP address, et cetera, and do stuff. So the laptop would be shipped, it would be shipped to her, and she would stage it for them. Right.
And they would do some work. They wouldn't necessarily do high-quality work, but in the meantime, for the month or two that they were an employee- Right ... they were- But I may not need the actual people in the future because now I'll be hiring a person who will then assign that work to an AI agent that will do the work on behalf of the synthetic person, and it can just get replicated through, I don't have to be North Korean, I could just drive this through every particular cybersecurity syndicate in the world.
In fact, it probably going to come down to, at some point, a synthetic AI agent is going to try to scam another synthetic AI agent, and they won't know that they're both synthetic until, at some point, it just collapses in its own kind of conversation and it goes nowhere. In the meantime, somebody's got to pay for all those tokens, and that's going to end up being OpenAI. Well.
It's a very interesting story. I was fascinated by it. It's a great story, yeah.
Yeah. Yeah. I talked to some folks who are trying to combat it just on the hiring stuff.
When they interview people, they make them put their hands up so they can see them, so at least they're not on a keyboard. But I don't think that solves the problem either. It just kind of like- Anymore it doesn't, and and iProov is just one, there's probably about 15 or 20 vendors that have various different flavors of liveness detection.
And liveness detection actually originated in the financial world. We have KYC, know your customer laws. " You have to prove who you are, and they have some sort of government-issued identity documents.
But if they're just showing paperwork, how do you relate to the paperwork with a person behind the keyboard? So then it becomes showing a video and liveness detection, and are you talking to a real human, not an AI? And like I said, there's an entire cybersecurity industry that we in the enterprise world don't think about, but in the identity and banking world, this is a very important thing.
And now it's starting to move into the enterprise world as the synthetic identities and fake identities get hired. Okay. Yeah.
So we're all going to have to show our papers on the internet somehow is what you're really saying. Or prove we're organic. That's the best part.
Yes. Only organic humans needed. Yeah.
That brings an entirely new meaning to organic farming, too, Tracy. Right. But yeah, ultimately, to your point, you may need to prove who you are to get on the internet or to be considered a legitimate person to talk to.
And if you don't have some sort of way of verifying that, it will be assumed that you're not a human. And so it'll be just like trying to open a bank account, guilty till proven otherwise. Well, and Mike, I will just point out as we wrap this up that our previous story about the micro payments for MCP was a way to do anonymous payments.
True that. Right. All right.
Yeah, that was the part that bothered me when I read that story. Well, folks, it's just only starting to get interesting now. Because you thought it was all fun and games up until now, but as you can look into the future here, looking at all three of these stories, you can see how, well, it's quite possible that 2026 might be the year of chaos, and we'll see what happens next.
tv lineup. It's an awesome lineup as usual, and once again, happy Easter, and we'll see you all guys Monday.