Open Source AI, OpenAI Copyright Fight and PACT Protocol
Open Source AI Is Changing Enterprise Costs
Open source AI is becoming a major force in enterprise AI adoption.
On this episode of Techstrong Gang, Alan Shimel and Mike Vizard are joined by Kate Scarcella and Chris Blask to discuss AI economics, copyright risk and agent trust.
The conversation begins with the rise of “AI 2.0.” Enterprises are moving beyond AI experiments. They now need systems that can scale without overwhelming infrastructure budgets.
DeepSeek’s open source inference framework highlights that shift. The framework targets the cost of running AI models, which has become a major barrier for enterprise teams.
For many organizations, the key question is no longer whether AI works. The question is whether AI can run affordably, securely and reliably at production scale.
Why AI 2.0 May Depend on Open Source
Satya Nadella’s call for AI 2.0 points to a broader industry shift.
In practice, AI competition is no longer only about who has the largest model. It is also about who can deploy and operate AI efficiently.
Open source AI can give enterprises more flexibility. It can also reduce vendor lock-in and create more transparency.
However, open source does not remove risk. Security teams still need to evaluate models, dependencies, data flows and governance controls before AI moves into production.
The OpenAI Copyright Fight Escalates
The second topic is the growing copyright battle involving OpenAI, Microsoft, The New York Times and other newspapers.
These lawsuits could become a defining legal fight for the AI industry.
Publishers argue that AI companies should not use copyrighted content without permission or compensation. AI providers, meanwhile, face growing pressure to explain how they train models and source data.
The outcome could reshape AI economics. It may also force vendors to rethink how they acquire, license and document training data.
Why Copyright Risk Matters to Enterprises
This dispute matters beyond media companies.
For example, enterprise buyers need to know whether their AI tools carry legal exposure. They also need more clarity into how vendors source training data.
As a result, legal teams may push for stronger contract language around indemnification, data provenance and model usage rights.
Copyright risk is quickly becoming part of AI governance.
PACT and the Need for Trusted AI Agents
The third topic is the PACT protocol.
PACT aims to help websites separate legitimate user-backed AI agents from malicious bots.
That distinction matters as AI agents become more active across the web. These agents may browse sites, collect information, complete tasks or act on behalf of users.
Websites need a way to know whether automated activity is authorized and trustworthy.
Without that trust layer, sites may block useful AI agents along with scraping, spam and fraud.
AI Needs Identity Infrastructure
AI agents create a new identity problem for the web.
In other words, websites need to know who or what is taking action. They also need to know whether that action reflects real user intent.
PACT could become part of that identity layer.
It will not solve every problem. Still, it shows where web infrastructure may need to go as autonomous software becomes more common.
The Bigger Picture
Ultimately, across all three topics, the common thread is control.
Open source AI challenges the cost structure of enterprise AI. Copyright lawsuits challenge the data foundation of AI training. PACT challenges the web to create a trust model for autonomous software.
Together, these stories show that AI’s next phase will not depend on model performance alone.
It will also depend on economics, content rights and trust infrastructure.
Transcript
Hey, good morning and good afternoon, or even someone may be watching this, good evening. Who knows? Wherever you are, good day.
It's Alan Shimel for Techstrong gang, and welcome to our show today where we have just another great show lined up. I love this line-up, our four people here. Two of my favorite people.
Well, three of my favorite people. So let me quickly introduce you to them. We've got my friend Chris Blask.
No scarf? It's too hot, finally. Too hot.
The heat has gotten to Chris. It's even gotten poor Chris off of scarves. Also joining us is Kate Scarsella.
Hey, Kate, how are you? Great, thanks. And with a little bit of funny lighting because he's in an undisclosed location that he refuses to disclose, hence it's undisclosed, our chief content officer, Mike Bizard.
Hey, Mike, how are you, man? I'm good. It's in a high place where the weather- Well, you are the man in the high castle ...
there you go. And it doesn't go above 85 degrees here, so that's pushing it. That's good.
Well, look, Europe's having a moment. Uh-uh. All kinds of crazy stuff going on with weather, but, well, there's no such thing as climate change, don't worry about it.
But Mike, rather than talking about politics, or it's not right this second anyway, but talk about what we got on the gang today. 0 stuff. I got to just tell you that up front.
0. It was only a matter of time. 0.
" I love it. You got that too, too soon? I got it.
Yeah. You see where I'm going there. But Mike, what do we got to open up with?
0 essentially, and basically was calling for cheaper AI, more distributed, and this is the way the world is going to go because the first generation of AI is proving to be too costly, and we need a different way of approaching this whole thing. And then it turns out, I guess the folks at DeepSeek got the message because then they turned around and announced an AI inference models architecture using some new techniques that reduce the total cost of AI dramatically. 0 phenomenon is going to be a thing called open source.
I know Chris follows all these models pretty closely. I'm going to toss this to him first, but what is your thought about what's going on here? 0 and all this talk we had about creating all these fabulous autonomous AI agents is going to go to the wayside because we just can't afford to use them?
1. So this is the abundance era, right? And take the analogy you want.
For us old farts, there used to be $25,000 a month to get a 56K whatever, right? A big lift to get on the internet, and then it wasn't, right? And we've gone through this.
You got to have the huge data center and the huge GPUs and look around this screen. We have had this same conversation step by step by step all the last year, right? Now we're at the spot that we've mentioned in, to my recollection, every single week going back in how...
Look, and again, it's not one or the other. Big GPUs and big power and so forth, wonderful stuff. Can that solve everything?
No. It needs to be distributed. And on the open source note, like Linux, I'm a big open source fan, huge, right?
But not everything works because it's free. Linux is a great example. It's worked because it's governable, manageable, and the economics just fit.
And I think that frame of open source to date probably fits going forward. I don't know. Kate, does this story seem familiar to you?
And I ask the question because I give Microsoft all the credit in the world for creating demand for a 32-bit reliable operating system. It just didn't turn out to be theirs. And this feels like the same thing over again.
Yeah. And to Chris's point, I feel like we've discussed this a lot. I think that we are building data centers that we're not going to need.
And I think more and more we're going to see personally, more distributed and more from an AI perspective. I keep getting excited every week about the new stuff that's coming out, and this is one of these examples. I think when you have this open source or that you have this technology or people on the other side pushing the envelope, like pushing and pushing.
" And I think it's been there all along. I think we're going to be smarter. I think all this is going to be better, and I think that this is all good things to come.
What do you think, Alan? Well, I got a few thoughts on this as you might expect me to have. Number one, Mike, I think you're right.
The irony should not be lost on anyone that we have the CEO of Microsoft, one of the three public cloud providers, one of the leaders of this AI movement out here saying "Geez, this is a little too more expensive than we thought it was going to be. In fact, it's a little too expensive. " And we do, right?
We went through this in the internet. " Well, no, the volume play never came. 20 on every dollar.
And companies that models were based on that didn't do so well. com domain, but they didn't really have a business. And so fundamentally, we're getting to this place in AI.
Tokenomics, token maxing is real. We're understanding that just because we can doesn't mean we should use AI for given tasks at those price points. So the choice then is, do we not use AI for these tasks?
Is it not everything we thought it was? Or are we going to figure out a way to make it economically work? And if we are, a lot of people are pointing at the free as in beer aspect of open source versus the free as in freedom.
I say it's both. But the real problem now, and I said this before on previous episodes, when we talk about open source AI, now you're really talking about Chinese models, DeepSeek, as we wrote about over on Techstrong AI and some of the others. There aren't, that I'm aware of, many sort of Western open source models out there that we can point to.
And I don't know if open source is necessarily the be-all, end-all. It's not going to bring down the cost of our data centers. It's not that it's necessarily more efficient, though DeepSeek certainly was more efficient than OpenAI, Claude, or Gemini, but not terribly so to get where we need to get to here.
And I think the whole AI hysteria that we're in right now, hysteria is not the word. Irrational exuberance that we're in right now is premised on us bringing the cost of this down to dirt. And unless we can do that, we're going to do something.
But don't you- Go ahead. But don't you talk about it from an infrastructure-- We've talked about it from an infrastructure point of view, like this becomes like electricity. A utility.
Yes. A utility. Yeah.
Sorry. Yes. And you know what?
I'm writing something on this right now. It'll be up in a day or two. But that's premised, right?
The idea was everybody needs electricity. We've got to make electricity available and affordable to everyone, even in the rural areas, right? And keep in mind, some people in rural America didn't get electricity till FDR, 1932.
Right? And I think it was the Rural Electricity Act or something like that. And it was government subsidized, frankly, because it was too expensive to bring the infrastructure out to the hinterlands.
Well, of course, now we're building the data centers in the hinterlands, so it's already there. But that being said, if we can't do it affordably, maybe we don't reach the utility stage. Not the utility stage, the ubiquity stage of intelligence.
Chris, go ahead. Well, one of the things I've enjoyed my entire career is working on the grid, power systems, right? Mm-hmm.
And this is a great analogy for everything else because it's fairly new. Like you say, less than 100 years ago, the Rural Electric Act, and we get it, because you cannot pay for it commercially as a utility when there's three customers and 50 miles of wire, right? So we figure out how that works, and we want to look at-- But even for those people, you talk to some folks much older than me who originally, as far as living memory, are the people building the grid.
And they always knew that hub-and-spoke, centralized systems are not the long-term answer. It's just what worked out. Right?
You have a coal power generator right here, I run in bloody wires, and it works. Everything we're dealing with in this whole smart grid stuff, I know, Alan, you've been involved with this, too, for the last several decades is coordinating that, and even that's turning into a meshy system, right? So this AI thing is the same.
It's not about either completely distributed or totally centralized. Put it this way, so we build lots of little nodes like Raspberry Pis, right, Kate? Right.
Or big, huge servers with big GPUs, and it depends. You may want some inference. You don't have enough power to do inference.
You need to do some, so you can outsource that. But you should know exactly where the hell it's going and what it's doing and who's doing it with it and what you can know and not know, which gets into the whole supply chain thing. But I have a hard time-- I'm motivated to say it's going to go all distributed, everything's running local.
But that's not the way this works. These big companies will survive in various forms, and we will outsource things to them if they're nice and give us the information we want because that's how it works. It's not- I think this is just a replay of the same thing we've seen time and time again.
And you can go back for the last 100 years, and the West invests something, and we create it, and it runs like this amazing thing. And then the next thing you know, we turn around and there's companies in Asia somewhere that are creating smaller, more efficient versions of it that are a whole lot cheaper. And this is why everybody, instead of driving a Cadillac, winds up driving a Toyota or a Honda because all of a sudden- You know what?
I got to call you out on that there, Mr. Man in the High Castle First of all, that didn't sound as good as you wanted it to sound. Anybody, anywhere in the world can make a cheap copy of something, or iterate and reiterate and make something better.
As a matter of fact, I put forth the thought that there was a time where that would describe the US. We looked at what Victorian England was making, and we made it a little cheaper and a little faster here. Are you suggesting that we stole the cotton gin?
Is that where you're going with this? Yeah, we might have. It wasn't Eli Whitney after all.
But- No, I would say but- ... but that's called economics ... I would say for the last 100 years, which is what I said, you can go to every example there is, whether it's a car or- A bicycle, even ...
a bicycle, or if it's a weapon, or anything of that nature, and every time for the last 100 years, we've invented something to wind up losing market share to somebody who makes it cheaper and faster and less expensive. And that's their fault or our fault? That's our fault.
But I am saying that we are overly attracted to something that feels like an industrial complex, and then we pour a boatload of money and cash into that, and a lot of that comes from our gambling attractions on Wall Street, and we just don't think about the math right. No, but good, but there are other models. So let's take the automobile industry because you brought it up.
Yes. World War II, post-World War II, all the way through, let's say, the '70s. In the '70s, we had the first gas crisis, and all of a sudden people worried about gas mileage and stuff.
American automobile ruled the world. And then in the '70s, all of a sudden people started hearing about companies like Datsun. Remember Datsun?
Sure. Yeah. Nissan now.
Datsun, Toyota, Honda. Yeah. Honda made little bikes.
But by the same token, there was another model in automotive that said we're not going to compete on those cheapy ones. We're going to compete on the high end. Did you use the word token as a pun there, or where were you going with that?
Well, perhaps, but look at the German car manufacturing market. They made a very successful market by not making the cheap copy, by making the premium choice. Mercedes, BMW, Audi, Porsche.
And that's a viable model as well. So there's always going to be Cadillacs and Datsuns, if you will. So to your point, given the token consumption as it currently stands, are OpenAI and Anthropic essentially the modern equivalent of those?
They're Lincoln Continental town cars, yes. And I think that was proven with DeepSeek or Cadillac Eldorados. Remember the last Eldorados?
Oh, yeah. Those really long boats? Yeah.
They definitely are. But here's the lesson I think the market really needs to learn if we're going to make AI ubiquitous and everything we want it to be. You don't need a Cadillac for every ride around town.
There are some nights you want the Cadillac. There are other times you want the SUV. There's other times you want a roadster.
There's other times you want the cheapy, just basic transportation. I think the key for people is going to be picking the right AI model, the right AI cost, and capability to complete the job. You don't want to overtool.
You don't need a, what's the term, a sledgehammer as a fly swatter. I shouldn't be driving my Lamborghini to Home Depot. Is that what you're saying?
Yeah. Well, if you live down here in Boca, maybe, but that's a whole another story. Anyway, but I do think that that's the lesson that comes out of this is you don't need to use the best model for every job.
Right. And that's the whole key to this token nonsense right now. So let me ask you this other question, though.
So there's a lot of people who keep pointing that, well, my God, you can't use AI models that were created by the Chinese, and yet, seems like the rest of the world doesn't have a problem with that. Well, the rest of the world says, "My God, you can't be dependent on the US models. " Yeah.
That's what's happened, right? Oh, that was nice. Yeah.
That cuts both ways. You got to sometimes look at it from their point of view. Exactly.
Speaking of their point of view, was this whole AI thing just built on stolen... This is a great story. Yes.
Stolen IP powers this whole damn thing. And where's my share of Textron here? We had 40,000 DevOps articles.
I don't know. How many tens of thousands of other articles? We haven't gotten a dime from these guys.
My damn chief content officer, what are we doing? Maybe we should explain to people what we're talking about first. All right, go ahead.
I got ahead of myself. Kurt wants to say something real quick. Real quick?
That hasn't happened yet, so why do you expect that now? So my stepfather wrote a book called "The Men That Broke" in 1966, and it's open out there, and all the models are trained on it like everything else. He wrote other books, and those are meant to be trained on.
So my mom is part of the lawsuit against that. And this is just what everybody was talking about a second ago. Yes.
Do I need a model trained on literally everything ever written, or do I need a model that knows how to speak trained on my stuff? And that's a much, much less contentious set. So, yeah.
Right. It leads to all these issues. So, this is obvious- Chris ...
when you're not tracking what you're ingesting, it affects everything and can get you sued. Chris is making a case for selfish AI. But let's explain what we're talking about here for two seconds.
The New York Times has expanded its lawsuit against OpenAI and Microsoft, and essentially is now saying that Microsoft aided and abetted the theft of its content because OpenAI was pulling all that content using computers provided by Microsoft, and they are allegedly saying that this was a, quote-unquote, "super computer" and that was the initiative. And then it gets better. The National Newspaper Association also filed suit against OpenAI, claiming that all of the articles from the newspapers of the association were also stolen to create all this amazing content.
" But, Anthropic is accusing Alibaba of distilling its AI models, which may or may not contain ill-gotten content from, and is now using that model to create their own models, which probably will have data in it from, I don't know, 40,000 DevOps articles. So Alan, what do you think? Well, that was the big thing on DeepSeek too, that DeepSeek was built on- Uh-huh ...
the Western models. This reminds me of, there are certain claims that certain families that will remain nameless built their wealth during prohibition. Bootlegging, bringing in hooch from Canada, dating movie actresses and stuff like that, and maybe their son becomes president one day.
But that money somehow got whitewashed, and they're in high society. It's the same thing here. A lot of the settlements that were done, if I remember back to the original suits regarding this, were kind of, "Look, what happened happened.
We can't go back to that. " And they made, I think it was mostly Anthropic, though OpenAI too, made deals with a whole bunch of different authors and content providers going forward. And I do think that's the model that we need to embrace going forward.
However, as The Times article shows us, there are still suits out there about how this thing originally was done, and not to make it sound all evil, what this instant one jumps out at, The New York Times case, is that there was a recent Supreme Court ruling that said something like, the defendants had to take unusual, non-customary practices in collecting that IP, not in the normal course of their business kind of thing. And so The Times, in order to comply with that, amended their complaint that said basically Microsoft set up a super computer, maybe not a mainframe, but probably a bunch of Linux devices, not Windows, with the specific intent of basically jacking, grabbing content from high-profile media and authors, including Techstrong maybe. Let me get this straight.
" Does that sound good? Well- I mean, go ahead, Chris. I was about to say, Kate, we're the security people here.
Can we turn the table around and talk about the leaky butt system that we have out there, that everyone's clicked on the end user license agreement, so you probably authorized all this anyways in the first place. You don't know. You don't know where your information's supposed to be, and if you take it to court, you may or may not win because it's a hairball.
It's cybersecurity-ridden policy. Right? Mm-hmm.
You're not implementing controls. My first statement, I picked on the trainers and consumers, sure. Bad on you.
However, where is your information? Do you have any idea? Do you know what it's governed by?
No. And as cybersecurity people, Kate, right? We know.
Right. We watch organizations take these decisions consciously all the time. No, we're not going to put these systems in place.
We've got to stop here. Every publisher has put a copyright label on their content that says- Absolutely. And that predates the internet ...
copyright. Predates the internet. I was just going to ask for copyright.
Mm-hmm. Of course, Leah. Because if the copyright is on there, then as I believe it's Mike who called this, I love it, crime of the century.
It's a great title because, it is. I understand, Chris, what you're saying, right? But the policy for copywritten material is still there, and what governs us is laws at the end of the day.
And do we abide by these laws? And why is it, one of the things that I keep seeing is why is it, and I'm sorry I don't have another name other than Tech Bros, somebody is going to have to give me another name, but why is it that the Tech Bros don't have to pay attention to the laws, and we do? Because they can buy the laws.
And it should stay Tech Bros until you see someone else besides bros in there doing it. Yeah. Mm-hmm.
It's wrong, and more importantly, I think that having to point to the source, just like software, becomes an extremely important point. " And you want the source. You want to know where the source is coming from.
And I think at the end of the day, not only is it about copyright, but we as people who've been a part of DevOps, we want to know where this code is coming from. We want to know, are there back doors to this, and what do those back doors look like? And at the end of the day, from written material, we want to know where is this AI getting its, quote-unquote, intelligence from.
So. Well, just to be clear, I think there's three layers of fail here, right? And the real one is policy.
Yeah, and you're right. If you have enough money, you just ignore all the laws and do what you want, you'll be fine. Or pay the fines.
You just skip the whole system. And then there's the training part of it, but the picking on cybersecurity and everything else is part of it. It's the infrastructure fail.
It's not just the bad guys. The bad guys in this case are the oligarch companies. They're just bloody ignoring all the rules regardless.
But they're still riding on top of an information system that is not mature, right? That leaks in a million directions all the time. And the journalism, just for me, just sticking inside the journalism, because you're right, Alan, Mike, you guys are journalism companies, you embed copyright.
I'm a vendor. Every single file we make has copyright in it. We actually weave it all the way down.
And in this particular case, yeah, the bad guys should just lose. Will they? I don't know.
They got a lot of money and lawyers. Well, absolutely. I'm going to come to that in a second because I want to mention something else.
This is not an AI first issue. This has been going on since, well, before the internet, right? How many of us used to take pictures of things in books?
Right? Or take a Xerox copy. Remember that word?
Yeah. Make a Xerox copy and then use it- I remember Xerox ... in your stuff.
But with the internet, there was a big assumption. Well, look, if I could just type in a URL and it's there, I could use it, whether it's a picture or a joke or something I wrote. And there's been, over the 30 years of the commercial internet now, there's been a lot of case law developed about, hey, what can I link to?
What can I republish? What can I syndicate? Where are the lines between IP and freedom on the internet?
And there's a lot of well-established case law, and I will tell you that that well-established case law says something like New York Times copyrighted material cannot be taken down. Well, it wasn't republished, but it was ingested and then trained, and then re-spit out as from these trained things. And I do think that that lawsuit is going to be a definitive on-- because it's subtle here.
They didn't republish the IP. Why did they use the IP? They used the IP to train their stuff from.
Yeah, but there's thousands of instances where what they output was the exact same copy that was in The Times. Yeah. So, whenever they allegedly thought they were retraining to create some original content, whatever- But this is similar.
Look at the music sampling lawsuits. Yeah. Sampling music.
But let me say, come back to the tech bros, Kate. I don't know how many of you caught this fellow running for Texas senator, James Talarico- Yeah ... his speech accepting the nomination.
He spoke about the problem of these tech bros coming in and buying the laws, buying the politicians, buying the courts, bending reality to their will, to their vision. And if they could get away with doing that against The New York Times, what the heck snowball's chance in hell does Mike and I here at Techstrong have? Yeah.
Yeah. I'll step down now. And to your point about Xerox or copying a tape, that is personal use, right?
And that's when you go to the library and you make a Xerox copy of something, and you stick it in a notebook somewhere, that's all well and good. It's when you take that thing and then publish it somewhere else under your work, that's when you run afoul of the copyright laws. Yep.
And the fact that you've pulled up to my, quote-unquote, store with 22 trucks instead of a car is no difference than a theft. It's just a bigger theft. Yeah.
Yeah. Agreed. This is going to be interesting, and again, this thing will eventually, I have a feeling, make its way to the Supreme Court.
Of course. And given the current court... We don't know.
Yeah. I don't know. I think a lot of the rulings that we saw, at least this week and into previous weeks, would favor The Times and the newspapers.
We'll see. We shall see. We shall see then, Mike.
Yeah. But we got to move along. We're going to make a pact.
A pact, P-A-C-T. What's this one about, Mike? Well, Cloudflare is at the lead of this thing, but they're creating a new protocol, and the mission of this protocol is to, well, A, help us distinguish between bad bots and good bots, and also better understand, if we're going to use these bots, how they protect our privacy.
Kate, I know this is an issue you've been following for a long time, and Alan and I had some experience with some bots this week in trying to figure out which one was the good ones and the bad ones, and boy, that was a misadventure in time, but we won't go into the details there. But Kate, from your perspective, have bots become... They're standard now everywhere.
We just don't know which ones are good and which ones are evil. Absolutely. Bots are standard.
And one of the things that I worry about is who's deciding what's a good bot and what's a bad bot? How do we decide that? So, that's one concern.
I do like having a specific protocol because I think it's going to help us understand humans to machines, which is really, really important today because the regular folk, people who are not in the industry, they don't understand when things are being propagated by humans versus machines, and I think it's really important. I would hope that it would help us as humans who are not in the tech industry to take a step back and think, "Wow, this is being propagated by a machine. " So, I do hope that these protocols, that when things are propagated, which-- Because disinformation is propagated by bad bots, and it's something that is bringing our society down.
So, it's definitely a part of cybersecurity, and so we definitely need help desperately in this area. And I know, Chris, I know you have a lot of feeling about this as well. I'm just happy to see CAPTCHAs die.
It fascinates me. Sometime late last year, my AI systems got better at doing CAPTCHAs than I am. Right?
Particularly when your eyes are tired, and you're staring at these bloody screens- Yeah ... and there are people out there trying to make them hard. Yeah And they are.
They quite often get... But my AI systems can always solve them. And look, protocols like this, I'm involved in a lot of global standards organizations where we're talking about these standards that we'll all look at, and we're all trying to figure out how we move forward.
Because obviously issuing a PDF every 18 to 36 months isn't exactly the speed we're moving at. Yeah. But things like PAC, if there is a reference point out there that people can use and that works for them, great.
But I think this issue is solved from the ground up, like I think everything else is solved. Who do I trust to determine who the good bots are and the bad bots? Me.
And so we build the systems that way, and if it's your system, then you get to decide and build up from there. Is there a single global protocol or system or structure where somebody gets to authorize the anchors? I don't know.
Doesn't seem obvious. That seems to be the failure state for almost everything these days, right? Yeah.
You know, look, here's how I look at this one. Identity and access control, identity and access management, is the killer security app of the cloud security era. Right?
When we got rid of the perimeter, we got rid of the motte-and-castle, the only control we really had was, "Who are you? Are you really you? " Right?
Identity and access control at its core. It was relatively easy when who you are was, "I'm a person. My name's Chris.
" That became crazy. Right? All of a sudden now we had six billion other devices that we-- And they don't respond like humans.
It's a little- Yeah ... some ways it's easier, some ways it's harder. Then we had yet another revolution.
Every container in the cloud-native world had to have its own unique identity. And based upon that, we knew what to let in, let out, what to trust from it, et cetera. And these containers are ephemeral.
They last about five seconds. And so we went from how many humans are on the internet, to how many humans in IoT devices, to how many billions of identities are we managing with all this stuff? And now, the next revolution is here.
Agents. These agentic identities, and we got to somehow figure them out. Are they real?
Where are they? If they are, where can they go? What can they do?
How do I stop them? You know what? This makes for a big goddamn mess.
And that's kind of where we live right now in this. It's a big mess. So, if this thing will help that mess, I'm all for it.
Especially for cybersecurity. And I have to tell you, from an identity perspective, being with IBM, let's remember Tivoli. That was like, oh my goodness.
Tivoli Identity and Access Manager, it was one of the longest engagements that we would have, and that was back in the early 2000s. Right. You didn't have what you had now.
Those were just people. Just people, and it was long engagements. Mm-hmm.
And what's so interesting, what I find interesting, is that the three things that we would always talk about from a cybersecurity architecture workshops that we would do And it is the same throughout, that we talk about today is who's coming into your enterprise? What are they doing once they're there, and how quickly can you prove it? And our enterprise today is basically our universe, and it's our own personal universe as well.
So it's a fascinating problem that we have been struggling for 30 years, that we're not even coming close to solving this- Yet the world, the amount of identities we need to manage is out of control. Small. Yeah.
Small. Right. Well, yeah, so for me, last seven years in supply chain, the thing I've always keep coming back to is the repository.
I'm always looking for people getting in that conversation all along the path saying, "Well, where is the repository? " And, myself and others along the way have been saying, "That's not how this works. " Where is the identity pool?
And look, half measures, Google, a Gmail address right now, and you get identity across big chunks of the internet. How do I scale it up 10 times to match all the agents a billion times the size of Google's current single monolithic identity? You can't.
There is no repository for every software bill of materials. For ephemeral things that pop up, as you were just saying, Allen, for five seconds. You're not going to stop and generate an SBOM.
It needs to be- Yeah ... look, like Lumina. Lumina is, I use this in the standards, is a AI bill of materials.
When you hear me say Lumina, what I'm saying is there is a specific large language model being used at that specific moment with a specific tool set and all the things we talk about in the AI bill of materials working groups. But you're not generating that all the time. So anyways, this identity thing is the identities, I said small, because you don't need to know that many identities from the bottom up.
From the top down, how do we do infinite identities in a big central? Stop trying. We don't.
I don't know, because, what about when we have all these IoT devices that now enter us, whether it's pacemakers, whether some sort of neural type of device that's helping people with memory, and there's so many... I don't know. There's moving agents now.
It's not just something that's stationary. Cars. How do we protect cars to keep them safe as they're driving autonomous?
Autonomous vehicle- Will be hacked ... yeah. We have a lot to...
I don't want to scare people, right? But at the same time, while it's exciting for us, it's also when you think about it, it's the enormity of the cybersecurity issues that we are trying to address today is very serious, and I don't believe that we're taking it as such. So- Well, I'm glad you brought up cars, because there's a company, I'm trying to figure out how to typify this without naming, that handles enormous amount of IoT information coming from cars all over the world.
Huge on behalf of big OEMs, and one of the best infrastructures that I'm currently familiar with. And like anyone, just obvious, you're dealing with a slope that's steepening, the number of messages coming from IoT in cars. So how do you manage those on a global basis?
And I think, in that sort of conversation, again, I say the same thing. Individual cars are not the same. Two 1973 Chevy Malibus or 2026 are not exactly the same.
Even the moment they leave the plant and from there on, they change. And none of them matter to me except this one, because I'm here. That information space we can navigate.
How do we navigate all of it at once or all of it together? We don't. That doesn't mean chaos, but it means structure starting from the ground up instead of the other way around.
The difference, and to your point about cars and structure, the difference is there are safety requirements before you can put a car on the road, no matter what you put in there. So there's already a framework for managing that. I think to Kate's point, we're deploying soon, I don't know, millions of AI agents soon.
In most cases, there is no framework. And, frankly, it wouldn't take much for a cyber criminal to either steal the credentials for an AI agent or swap it out for one of their own and have it act like a normal AI agent for weeks or months before it went off and did something malicious. So, now you start multiplying that out across an attack surface that has millions of AI agents, and we don't have a plan.
To Kate's point, it's scary. So there's a Standards Council of Canada has a working group on systems of AI systems. And you put those together in your head first and we're all working through it.
And in the next couple of months, we'll publish technical specification. And I think some of the answers to that are in there. You're thinking from the global level, you should have at least this.
I should be able to see this much of your AI systems, not just your LLM. And if that's understood, generally speaking at the global level, it can push down into legislation that make manufacturers do things so consumers from the bottom up can see what's going on with their car. But that's a topic for a whole show by itself.
No, I'm with you. What decade will that be exactly when we get there? Because last time we tried- This one.
All right. Hey, Chris is always the optimist. Not always.
Let's bring this back to PAC, though. I got a question. Let me do a little Roseanne and Dan and Donna, if you remember Roseanne and Dan.
Yeah. What about those buttons on the websites that says, "Check if you're a human"? How does it really know if you're a human?
You ever notice that? There's no capture. It's like the invisible capture or whatever.
" Or, "I'm a human," or something like that. And it's never once gotten it wrong. It knows I'm a human every time.
But does it know everyone's a human? Sometimes you got to wonder. People are asking.
I think those are the right questions to ask. How do we know? Who has the data?
I don't know. Where's the data? You know you don't know.
That by itself speaks volumes. Speaks right there. Yeah.
You don't know what you don't know. And it doesn't even ask you if you're an alien, so how do we- No! And that's the only choice.
Either I'm a human. " So, whatever. That would actually be interesting.
You could choose two boxes. Are you a human or not? Right.
Human or not. Yeah. And then we'll see if those AI agents lie, because look- That's right ...
they steal everything anyway. That's right. Uh-huh.
All right. On that note, we're going to end our techstrong gang today. Kate, Chris, Mike, thanks for joining us.
Thank you for joining us as always. We're available on techstrong. tv, on our Techstrong TV YouTube channel, or our Techstrong OTT channel, which is available on just about any screen you use, Apple TV, Roku, Amazon, Android, iOS, whatever.
We'll be back tomorrow with more gang. We've got a lot going on, but stay tuned. We've got a lot of Techstrong TV for you to watch.
com. What a great week we had there last week at Platform Con. But for now, on behalf of Mike, Chris, Kate, everyone else at Techstrong, have a great day.
We're out.