Techstrong Gang – August 23, 2024
Alan, Mike, Paul Nashawaty, practice leader for application development at The Futurum Group, and Lisa Martin, CMO advisor for The Futurum Group, debate the degree to which application developers might, thanks to the rise of artificial intelligence (AI), no longer need to write code following some prognostications from the CEO of Amazon Web Services (AWS).
Then, the gang turns its attention to who is really responsible for data breaches before delving into the AI copyright lawsuits that Anthropic is now being included in.
Transcript
Hey, everyone. Happy Friday to you. You know, before you start your weekend, a couple of things to think about.
Can will developers stop coding? Is is the cybersecurity enemy. Us and Anthropic got invited to the party.
They've just been named in a lawsuit. Uh, we've got a lot of ai, a lot of good stuff you're watching Textron Gang. Good day everyone.
It's Alan Shimmel from Techstrong. Welcome to Techstrong Gang, happy Friday. We wanna get your weekend started off right.
And so we're gonna jump in with some really, I think it's gonna be an AI heavy day, but we'll, we'll have some cyber and the usual information in there. We've got a, a, a great crew of gang members today joining us. Let me introduce you to them right off the bat.
First of all, I haven't had a chance to be on with him in a couple of weeks here on the gang, but he is the future of analysts on DevOps and Cloud Native. It's my friend Paul Nadi. Hey Paul.
How are you? Good, Alan. Good to be here.
Absolutely. It's good to have you on as always. Joining Paul, another member of the FU of team.
She runs her own podcast for CMOs and marketing and pretty well known in that field. It's one and only Lisa Martin. Hi, Lisa.
Welcome. Hey, Alan. Great to be with you on the Friday gang On the Friday episode of The Gang.
Always great to have Lisa here. And then joining us in our Boca Raton, uh, studio headquarters. It's our Chief Content Officer.
This will be his last show before he heads out to VM World. Is that that is true in love that Paul and Mike will be in VM World next week. Something to stay tuned for, but it's our Chief Content Officer, Mike Ard.
Hey, Mike, I'm Good to see you. I say the same thing every Friday. Every Friday morning, it's the same thing.
Wake up in the morning and I go, thank God it's Friday. And then about five seconds later I say, holy crap, it's Friday. It's Friday.
So There you go. That's, that's the, the Gemini effect of Fridays, right? Yeah.
I'm actually looking forward to the weekend. It's been a bit of a crazy week, but I was, I was actually glad to be here in Boca the whole week. Um, I'm here most of next week then, then we got the holiday weekend and then boom, we're into football season.
Um, but I'm not gonna get it started on football season. Don't worry. Let's, let's first start off though, the A-W-S-C-E-O made some comments on a Business Insider article here.
Yeah. What do you got, Mike? So, Matt Garman had a town hall with the AWS employees where he suggested that it is probable that developers won't be coding at some point in the near future.
He wasn't quite specific, but somewhere in that maybe two to three year window. And the premise behind this is that, um, in the case of Amazon, they have a, an offering called Q that is a, that writes code, debugs code and has a reasoning engine behind it. And that, um, business users and even individuals will be able to write their own applications.
There's a notion that we're gonna have personalized applications where this chat bot will just create something that says, you know, help me monitor all my fantasy league stuff, and it'll just create an app for you right there on your phone. And some people are even saying, we will have more software in the next two years than we've had in the last decade. But Paul, I want to come to you on this.
Um, you know, how feasible is all of this in your mind? Should developers kind of stop thinking about the physical act of coding? And if they're not coding, what are they doing?
Well, Mike, first and foremost, I think I need to have, uh, Amazon queue or something help me with my fantasy team, because God knows I can't get my, my, uh, fantasy team to work, you know, over the last couple, couple years. I've had bad couple years too, Paul. But it was appealing to me too when he said that.
So, But, you know, look, I'm joking aside. Look, I I, I think that there's, uh, you know, looking at what Garmin said, and, you know, everything is taken out, uh, in context, right? And what's said, you have a soundbite that's kind ohs a soundbite that's, that's gonna gonna like, you know, do more news, right?
And kind of drive more attention towards what we're doing. You know, there's no surprise. I mean, a couple of weeks, or actually a month or so ago, I was at, uh, um, AWS summit and Q was top of mind and, and, and working towards the, uh, the desire to, uh, you know, have the lines of businesses as well as it, you know, have a rapid development of code.
So, you know, the exact quote that kind of came out was, you know, if you look forward 24 months from now, uh, it's possible that developers are not coding. And the key word there is it's possible that developers are not coating. Um, you know, and, and, and, you know, if, if you've listened to any of my previous, uh, you know, recordings or sessions or, or segments that I've been on, I made the analogy of Stonehenge, right?
I've said, I if you put the hands underneath the rocks, I don't know how Stonehenge was done. You know, you get these big rocks, put the rock above the, on another rock, and, but if you put as many hands underneath of one of those big rocks, I still don't believe that you can lift those rocks. I just don't, I couldn't do it.
So, uh, you know, I think that it's the same analogy when you look at coding, right? And, and what I like about, um, the statement, and this is kind of what goes along with the whole AI process, is, you know, q and as well as the rest of the industry, Amazon and q and the rest of the industry is, is moving towards customer demand. What we see in our, uh, research is, uh, organizations are looking to put out code very rapidly, actually, 8%, um, I should say 24% of respondents of our recent survey, a recent research survey, developer surveys indicated they wanna release code on an hourly basis, but yet only 8% are able to do so.
And, and part of the reason they're able to do it, only only 8% are able to do it is because they don't have enough bodies being thrown at the code. We also see in the research that, um, development of these applications are, are, are happening very, very quickly. Uh, we see at the edge sites, at edge locations, we're seeing 500 to a thousand, um, production applications over the next two to three years with all these applications being created.
Uh, you know, to have a centralized development team creating 'em all is pretty much unattainable. And you can't do it unless you have the tech stack to support this. And, and I think that's, uh, again, out of context, uh, that was said.
I think the, the idea here is these tools that are being put in place are to enable developers to work more, uh, efficiently and develop code and applications more efficiently. Um, you know, everybody wants to say, oh, AI's taking over the world, all gonna lose my job, everything, yada, yada, yada, yada. And, you know, I, I think the, the idea around it is, is, and if you kind of look at where these, these, these, uh, conversations go, organizations are hiring developers that are a, that are knowledgeable in ai.
They're not going to hire developers that are not knowledgeable in ai, because the AI is an a productivity enhancement. So if you don't know how to use AI and the AI tool sets in Amazon queue, et cetera, then that's a disadvantage to the developers. So it makes the developer more marketable if they know the current tool set.
So that's where I think it's all going. Um, Mike Allen, uh, Lisa, I think, I think it really has, uh, a lot of, uh, potential, but I don't think we're nearly ready to have a human out of the loop. I have some thoughts.
You do? Yeah. I'm shocked there's gambling going on here.
Um, to me, look, I appreciate the A-W-S-C-E-O giving us all a clickbait headline, but clickbait, nonetheless, I, I, I think this is more akin to the low code, no code kind of, uh, uh, industry that's grown up. And you are going to see two flavors of, of AI driven code and AI driven applications. Like this one is what, you know, generally we refer to now in the no-code space as the citizen developer.
So the non coder Paul looking to get a fantasy football app help helping them out. The people in marketing, right? Who, who need something, it's, I, I don't want to call them simple apps, but they're, they're simpler, they're simpler apps.
They're, you know, get me down and dirty. I need something that does this, this, and that. And I'm not a coder, but if you can gimme an AI bot interface, I, I describe what I want this app to do, and the bot can do it.
And it's a relatively simpler thing. Oh, I don't need to go through it. I don't need to go through qa, I don't need to, to play that whole game, and I should get it done right now, not 4, 5, 6 weeks from now.
I think there's a great use for AI for that. AI will be the no code alternative for citizen developers, for professional developers. AI will be a great help.
As, as our friend John Willis says, if you boil it down, um, 30% of your code might be coming from your ai, 40%. It'll get better. Maybe it gets to 60%, but the coders are still going to be coding.
I, I think what we get into enterprise level applications, um, AI is not gonna replace your developers or stop your developers from coding within the next five to 10 year window. Yeah. Paul, 20 years difference.
Paul, I gotta say, I laughed when I read the story, just 'cause the first thing that came to mind to me was there are trillions upon trillions of lines of existing code out there that were written by humans that, um, I might be able to train an AI engine on, but they're probably not always, uh, shall we say, highly consistent because, well, the code was written by humans. And it varies widely, it seems to me humans will be needed to support that. They'll get some help from ai, but they'll be needed to revisit that code and understand how it works for much longer than your forecasting, I think.
But Paul, what's your take? Yeah. Well, I think, Mike, that makes a lot of sense.
The, the thing that I want to echo, uh, what Alan was talking about, look, low-code, no code is, is not new, right? I mean, the likes of, uh, Mendix or an OutSystems or progress software for over the last 10, 15 years have been focusing on the citizen developer and trying to make, enable the citizen developer to create and, and, and be self-sufficient and enable themselves the, the, the, the term that a lot of, you know, analysts will use is those low-code. No-code solutions are systems of engagement that attach to existing systems of record, right?
So you end up having these larger systems of record, which is Mike, the code that you're talking about, which is, you know, lots and lots of applications that have traditional monolithic or applications that have been built over the years. Those are typically encapsulated into systems of record and, and used as such, they're, they're, they're left as a, a touchpoint of, of a dataset or, you know, in the, in the latest buzzwords, right? We, it's a LLM, it's a, it's a data pool that's being used.
That's the data that, that's being touched, and it's part of the heritage environment. New applications that are being, that are being created in the front end. Those are all new, right?
Those are all, uh, ways to attach to those existing data sets. Um, the, the, a advantage here is where AI in the intersection of API integration come together, that's gonna be in interesting, because now we have these new systems of record, I'm sorry, these new systems of engagement with attaching the existing system of record, and it's gonna be multiple, they have to have different connectors and make sure that all that sy all those work. So attaching your AI system to an LLM in the backend, a data lake, a data pool in the backend, all that needs to be connected in, uh, an interoperability needs to work seamlessly.
Again, AI is not smart enough right now to do that by itself. Mike, to your point, there's, there's so many different levels of code, um, that hasn't been harmonized in the industry that you need to have that, you know, bespoke solution that works for each one. That's where the system integrators or the system delivery partners come in and, and they really help deliver those, uh, those solutions, You know, to all those citizen developers out there.
No offense. But the truth of the matter is, most of the applications that those citizen developers build are a ugly b poorly designed and don't scale three riddled with cybersecurity vulnerabilities. 'cause they don't know, they know less about cybersecurity and then professional developers who aren't very good at security either.
Um, that was yesterday show. Um, so just 'cause I have ai, I don't think that all those things magically get fixed. So I'm wondering, you know, at some point that citizen code is gonna need to be reviewed by somebody who has some sort of professional sensibilities about how this thing might actually work and for a large number of people.
'cause the way you write business logic and code for multiple people is fundamentally different than what you do for onesie two z. I think that, I respect your opinion, let me say that off the bat, but I think today's no code solutions are a lot, a lot better than that. Forget the AI piece of it for now.
Mm-Hmm. I think no, today's no code applications, you know, that you're building with building blocks and stuff that have all been tried, true and tested. They're pretty secure.
They're, they're pretty good. I mean, you'd be surprised what you could build today's no code a rector sets or whatever you wanna Call it. Yeah, absolutely.
Alan, the A absolutely, Alan, the, the, the solutions that are in market today have evolved to the point where governance, compliance and regulations are built into the platform. Um, you know, like the ServiceNow solutions or the, uh, you know, the other ones that are out in the, the, they're all have, they have the guardrails in place and q here, Amazon Q is set up to have those guardrails in place that you, you know, you, you're protecting the, the citizen developer from hurting themselves. You do have to have A-A-A-A-A, corporate governance and compliance, uh, regulations.
Otherwise, you know, we're no different than we were 15 years ago with shadow it. And, and things are just kind of happening. And then there's, you're outta compliance and data's going all over the place.
Um, that's the, that's something that's, uh, been certainly addressed with these new, these new solutions that are in the market today. You know, I, that, that is, but Mike, to, to, and also to Alan's point, that's table stakes. That is no longer a nice to have.
That's a requirement to, to create. And you can't, you can't unleash your lines of businesses and say, go create applications. And then they have, you know, they create these security breaches and such.
That's a, that's a non-starter. Uh, so, so obviously these solutions that are in place have those checks and balances and, uh, you know, uh, as part of the solution. Absolutely.
But look, you know what? I don't want to, this is not a black and white issue of, of how much AI is going to replace and or help developers. I, I, and I think we're seeing it evolve and, and continue to get better day to day to day, literally, right?
In terms of the quality that AI is turning out. So longer term, certainly it's gonna be a lot easier to create the most sophisticated systems of record even using ai. It, you know, but I don't think it happens in a year or two and, and that that's really the issue.
But anyway, we're, we're, uh, about outta time on this particular block. Let's take a quick break here on Textron Gang. We got a interesting little promo there.
We're gonna play for you, and then we're gonna come back and say, uh, in terms of cybersecurity, have we met the enemy? And it's us. All Right, folks, we're back in.
We have a story on Security Boulevard this week talking about how, uh, lots of sensitive data is still mishandled in organizations. We just don't have the right culture for managing this data. And it actually goes back to the previous block.
Where I'm gonna disagree with, uh, Paul, there is, just because I gave you data governance tools, doesn't mean you use them. And it doesn't seem like most of these people are actually using any of these tools because, well, it's troublesome it, they don't, it gets in the way of some workflow in their minds. But we have the ability to mass sensitive data.
The survey suggests we're not using that capability. And primary comforts in this thing is surprise, surprise, business intelligence analyst that you find in the marketing and the finance department and developers who are copying data from production applications and just throwing it into production. And in pre-production environments that are not especially secure.
And auditors are finding the stuff and apparently billing people like crazy for the trouble. Um, let me start with Lisa here, um, is in marketing. Have you, it seems like there is just a lot of sensitive data floating around through these applications that people download and analyze, and they're not really concerned about what's in there, and yet the bad guys are just stealing their credentials and going to town.
So do we need to kinda rethink our approach to data from your perspective? Definitely. And I think this is where this triumvirate between marketing IT and security really comes into play to work together to develop data minimization strategies.
Let's start reducing the amount of sensitive data that's collected. Um, how, how long it's stored, how it's processed, come together to really, um, invoke data retention policies that are articulated publicly. I think data governance is another area where marketing can come in and partner with it and security to really establish these policies so that the sensitive data that needs to be there, whether it's for application development or marketing strategies to convert prospects to into sales, is managed accordingly with organizational activity.
And then I think I also comes down to training and awareness from a cultural perspective, it needs to be consistent. I always say that with respect to marketing, that these training programs need to be for employees. They need to be for contractors.
What are data protection best practices? What are data handling procedures? Why is data security so important?
And as an employee or a contractor, what is your role in that? And ultimately, if and when there is a breach, the marketing folks need to come and help from a response perspective. But I think they can, well, from a data minimization perspective, if that triumvirate works well together.
So the quarter, a Disney movie, this is a story as old as time. You know, look, I I, I remember it's still secure back in the early two thousands when, when the folks would go to lunch, we'd walk around. It was, uh, it was at an incubator.
The Mobius venture capital incubator was our office. And we'd walk around the pit, you know, where everybody's computers were. And if we saw any passwords on a post-it, we'd log in and lock the machine and change the password.
People would come back from lunch and say, oh my God, I can't get into my machine. I'm locked out. Well, that's what you get for leaving your password on a sticky when you go out, right?
I remember going, when my kids had braces, orthodontics, I remember going to the orthodontist's office and they, you know, I had set up a plan where, you know, my insurance paid a Pitt and said I had to pay five grand and you paid it monthly. And lo and behold, those braces stayed on just long enough for you to pay the, the remaining balance off. Um, so I gave the lady the credit card, and she, again, same thing right there, right?
Just on a little, uh, she had like a little oped that she'd write your stuff in. And I was, I was only maybe the 35th credit card on that list, but they had person's name, credit card number, expiration, CCV. And I said, what do you do with that?
She says, oh, we keep it right here, and I bill it every first of the month. It's quite a system. I said, well, doesn't your credit card provider give you like a vault or something?
They said, oh, yeah, we put it up there too. I didn't say anything. It wasn't my office.
But, and that's only in small businesses, right? Oh, but this, this goes on in larger businesses too. People don't realize, and, and that's, I mean, credit card data is a no brainer.
Passwords are a machine, no brainer. But when we get to things like PII even your date of birth, uh, you know, all of this, this is confidential data. I'll give you an example that I heard when doing this story where a fellow was telling me he worked in a financial services firm in Boston.
And, um, the development team knew how much a famous basketball player kept in this checking account all the time. 'cause they were constantly using that data to build applications. And they'd be like, oh yeah, we know that guy.
Oh, look, you still got this man. Yeah. You know, and there was none in their business actually, but, you know, I'm sure it wound up being bar room Chatter.
Oh, sure. Look, remember selling the Michael Jackson El Beta when, when, when that happened. Um, this is, this is Lisa, you're right, it's an education and training issue.
But we've thrown a lot of money at education and training, and I'm not sure we've gotten our return on investment there. Um, I think humans are the, the, the, the, the weakest link from a security perspective. You've known that for a really long time.
Yeah. I have this friend that I, that I hosted shows with before, and he makes stickers. And he had the sticker on his laptop that said, humans ruining everything since forever.
Right? And I, and it was cheeky and it was funny, but it's, that's the weakest link. And that's where that, that awareness and training, to your point, Alan, a lot of money is spent there, a lot of time invested and resources invested.
But it has to be there because eventually they're gonna catch the people writing the passwords down. I worked with a client, LastPass, and really how they're helping, um, multiple generations to stop doing that because it's that human that's opening the gates to the kingdom. Yeah.
The, The part that drives me crazy. Go Paul. Sorry, Mike.
Uh, no, no. There's, there's actually an interesting perspective here that I, I look at it and listening to how we're going through the data here and such, uh, in order to recognize that return on the education that's in this space in order to, uh, put some checks and balances in place, uh, I, you know, it, it does come down to accountability. And, you know, and I, when I think about software development and I think about the executive orders that have been put in place for compliance and the SBOs that have to be, you know, you have to follow these specific rules and such.
When, when you, if you want that accountability, if things are not happening, and if, if a if compliance and regulation is broken, then there's penalties to be paid, that's when you start kind of saying, okay, the emphasis is no longer just on an education being a nice to have, but it's a requirement in order to not get those penalties. Right. And, and if you don't, if you, if you start enforcing those penalties, then that will kind of drive better behavior.
In theory. In theory. But, um, I, I do think that the compliance and regulations, when it comes back down to the releasing of these, of the code, when it comes down to the releasing of the, of the, you know, of the sensitive data, uh, there's, there's tools in place.
I mean, we have solutions in place today that can, that manages, you know, PII and all the other sensitive data appropriately. They're not being used because they're, they're, the, the pain is not worth the, the, the using the systems. And if they, if the pain was in place to say, oh, if you don't use this, you're going to be penalized, then that would enforce the use of the, uh, of, uh, protecting that sense of data.
So the part that drives me crazy about all this is that, so we will have some end user will put all the customer data in some sort of spreadsheet or BI application or whatever it is. They are credentials get stolen. They get hacked.
There's a big data breach. And by golly, it's the cybersecurity guy's fault. Oh, well, ultimately, yes, the cybersecurity guy is responsible for the breach.
But you know, I, I think part of the reason is, is that the cybersecurity guy has been the boy who cried and then oftentimes is the boy way too often is the boy who cried wolf right there. The cybersecurity guy's always yelling about this. And, oh, you gotta be more sensitive and you're gonna be more concerned.
And you got, you got, you got, you got it. You got it. No one cares but me, we're the only one who cares.
We're the only one who cares. I told you this was gonna happen. Right.
That, that's your typical cybersecurity cycle. And it's been, again, the story is old this time. The, the buck stops at the cybersecurity guy.
But it, this is a, this is a organization wide, organizationally wide. They, and that's one of the reasons why you had the rise of the ciso because the cybersecurity team realized that to get this at the organizational level, they had to have a seat at the table. They had to be part of the IT team.
They had to be part of the executive or a voice at the executive level because just the cybersecurity team, well alone, can't do this. I don't know. I think it's like blaming it.
Yeah. But Alan, The point that, that I think is interesting there, and Mike, you brought it up, is, you know, somebody writes down their stuff, they have it in a tool, they have it in a spreadsheet, they have it. This, it's the, the tools that are being used are not being regulated as well.
Like, you know, why do we have to have multiple versions of, uh, the PII data to have everybody have their individual information and, and a spreadsheet on their desktop, say, so to speak? That doesn't necessarily work these days, right? I mean, back in the day when you didn't have centralized systems and you didn't have ways to communicate, and I mean, everything is, everything that is, uh, you know, you that needs to be protected, needs to be in a single source truth.
And if you're letting the data out there, then it's not necessarily the, uh, uh, the security team's fault. Although they, they're protectors they should be protecting. I agree with Alan.
They didn't need to be protecting everything. The other side of it is the governance of the, of the organization says, but the, these are not the tools that we're using anymore. We shouldn't be using individual spreadsheets.
We shouldn't be using all, you know, a Word document or writing it down on a piece of paper. Uh, you know, that's, that's just not how we do it, right? We use the centralized location that data's protected, and that tool is in place to protect the sensitive data.
If if that's not in place, then that organization is not mature enough to even be working in that space anymore. I, I feel like blaming the cybersecurity people is roughly akin to blaming the fire chief because you went out and left eight candles lit in your house while you went to the store and then come back and surprise, surprise, your house is on fire. So, yeah.
But The, the fire department is supposed to inspect to make sure you don't leave lit candles. Well, they can inspect every day. They got a personal responsibility at Some point, you know, to, to your point.
And Paul's point, you could legislate till the cows come home. It's not gonna stop that lady at the orthodontist's office from having a little steno notepad. It's not that, it's not, I mean, I've been using LastPass or I don't use LastPass anymore to be, to be fair.
But a big shout out to my friend Chris Hoff, who is the chief security guy there. And he's done a hell of a job in some very difficult times. But, um, you know, I've used LastPass or another password manager for going on 20 years now.
And I've got my wife on it, my children on it. I've gotten a lot of people here in our office on it. And we, we switched to another product one password recently because some, well, we switched and I made sure I tell everyone here to use one password, but then I asked my IT people 'cause we could tell who's using it and who's not and who's putting passwords in there and who's not.
And I'm telling you, half the people here are not using it. It is, it's a hard thing to change human behavior here. And, and changing that is more than just maybe in instituting new rules, there's probably gonna be a carrot at a stick and, you know, and going around and locking you out of your machine 'cause you left your password exposed.
Mm-Hmm. It's good. You know, you do that enough times, people stop doing it.
WordPress will just this year, another one. So yeah. This is all also true.
No, no. It wasn't the WordPress, we, it was, it was your machine. You could have logged on to your machine.
Mm-Hmm. Do I feel sorry for the cybersecurity team? Because they get blamed when, when it hits the fan here.
Yes and no. Yes and no. Education and training is part of their mission.
Yeah. I kind of wish we were going at this, at the school level, right? It's really about having an understanding for data hygiene almost the same way we think about data stewardship and civics, right?
I have, I am, this is not your data that you're playing with here in a spreadsheet. It's somebody else's data that your customer who is essentially lending that to you. And you need to treat it as such.
And I think we get it in our heads that all the data we collect somehow or other is our data when, and well, it's not really, it belongs to other people. You know, this is like getting salespeople to use A CRM. You ever have that Problem?
Oh yeah, I know it Well, Salespeople hate using CRMs. They do. I mean, they like to see the insights that A CRM can give them, but they don't wanna put everything into the CRM.
And then I'll give you a perfect example. Security team says, Hey, we're putting a new password policy in place. You gotta change your password every 60 days.
It's gotta be 12 characters, two special characters, alpha numeric and capital. And every 60 days you're gonna sign you're gonna change it. People hate that.
Hate that. Mm-Hmm. Every sales rep I know basically has two CRMs.
There's the one in the office that's the system of record, and then there's the one that's sitting on their laptop that they're using to managing, Which is a spreadsheet or something. Right? And, And so, you know, so I I think is the enemy us Yes.
But it's the real enemy here is human nature. And I, you know, when you figure out how to change that, let me know. 'cause I'll, let's go start a new business.
We can help, we can start it. We're, we're starting it right here with this conversation. Absolutely.
Um, hey, we're, we beat this one up enough. Let's take a quick break. We're gonna come back here on Techstrong Gang today.
And you know what? Anthropic wanted to be one of the big boys. They are.
They're added to the lawsuits around ai copyright. There you go. We'll talk about it.
You're watching Textron gang. All right, folks. And to Alan's point, yes, philanthropic joined the big boys.
They got sued by an author's guild. And so now basically they are being held to account the same way. Open AI is, uh, I believe it was Sam Waltman who said, you can't build these large language models without using copyrighted material.
Uh, so here we are. I guess maybe it should be just one lawsuit class action, streamline the whole process for everybody. But I, what is your take on this fair use versus, uh, copyright issue?
Because the guild authors and are hanging their hat on a ruling that went, goes to back to the Andy Warhol Foundation. And they're saying that if you can easily license something, there's no reason to steal in from you with fair use principles. Some, I think the key word there is something, this is everything.
Mm-Hmm. I mean, so, so, you know, by the very nature, these large language modules are large, hence the word large in large language module. And so just grabbing a picture of a tomato soup can and licensing that from Campbell's is very different than licensing the body of knowledge on a given on the internet or a portion thereof.
And I think that's the issue. Do you expect philanthropic and open AI or, and any of the other ai, you know, trained, uh, providers out there, training providers out there to go and license every single thing that's out here on the internet? Or, or at least even as a threshold ascertained what's licensable and what's not licensable?
If it's not licensable, maybe I could use it anyway. I don't, that's a job. I, I don't know if that's possible.
We have seen Lisa come to you. We've seen several of these types of licensing deals. Yeah, but they're, but they're, yes.
You're talking about like the New York Times and some of the bigger publishers may deal with open a open AI announced, just announced open AI partnership Yep. This week. So I will tell you, those are flies on elephants.
Okay. Mm-Hmm. 5%.
It, it's, this is, you know, great for condom na great for the times. Hey, just a quick shout out. Text drugs will lean to license our stuff to any of you out there.
Right. com happy to talk to you about it. But this is a small, There's Only a small piece.
It's a, it's a drop in the bucket of an ocean. Just because something is difficult doesn't make it right. So I would argue that, yeah.
Well I'm not saying it's right. Right. Alright, so these guys gotta come and conform to standard copyright licensing agreements that They do up here since the time of time.
Yes, they do. So therefore, I'm not quite clear why they're not just gonna cut to the middle and settle because it seems like they're just This instant suit already settled. 'cause once they settle this one, there's 700 behind it.
Right? So come up with a standard formula. They could use their large language model to come up with some sort of standard formula.
That's a Form. So we're gonna fills up, let's, let's play that out. So we're gonna create a class action suit.
And the class represents every single being or organization or entity who has contributed information that is available on the net that these people may or may not be using as part of their AI trading. That Would have to sign up to be part of the Suit. That's, I'd like to be the lawyer for that suit, because, you know, as usual with class action suits, the big winners will be the attorneys Anyway.
Yeah. We got through the cigarette industry. This is similar.
Well, no, they're, they're evil. Um, but that, that being said, I mean, think about it. You, you're talking, you know, Ali, Carl Sagan, billions and billions of, of people who are, you know, have content out on the net that's being used in these trainings.
And the amount of money you're talking about is gonna be really billions and billions. The question is, what makes my content more valuable than yours? What makes, why it's, or do we all get paid a flat fee depending how many bits we, bytes we've put out there?
I think you can, if you wanna negotiate, you can negotiate. It'll take longer and harder. Or you get the easy button and here's the form or fill it out and you're done.
So I'm maybe for an individual that might be Right. Right. Hey, I, I'm willing to, all of my data that I've contributed out social media on the internet is available for trading to any of the AI consortium vendors who are paying.
And I, you know, I get a check for 35 cents, maybe. We, as a publishing firm, we put a form on our site and says, here, fill this out. And then you can use our content after you.
They're not paying us after they sell. Okay. Just gonna wanna get, I feel like the Batman meme.
No, you have the Pay us. Yeah. Paul, we, we, Paul, Lisa, Mike and I I have gone rambled in enough here.
What do you guys think? Yeah, I think the thanks guys. I think the trends are interesting.
This is Anthropic second cases. Do you, I I like how you tease the segment. What up Anthropic wants to join, you know, the the big club?
Well, they have now, um, what I wonder is, is this, and the, the partnership route that we've talked about, the con Nas OpenAI partnership that was just announced earlier this week. Um, they're being saved by the New York Times, for example. This is a trend we're seeing with the lawsuits.
Is the other trend, the partnership route, is that, is that sustainable? We don't know. It's, it's new.
It's new-ish. We don't know how sustainable that is. We don't know if the publishers are being paid enough for the content.
Uh, Alan, you bring up a great point. This is a fly on an elephant. What, what's the rub?
Um, what's the right thing for these organizations to do? We all want those of us that use Chat, GPT and Claude Perplexity. We want the systems to be helping us from a productivity perspective.
We also know on another level, that the data has to be, there has to be accurate for these models to help us. So it's a, i I, what I struggle with, it's where's the rub? Is this a sustainable model on the partnership side?
Is it not? Um, what's the right answer? I don't know.
But it's a very interesting time because we want these LLMs to be helping us to be, become better at our jobs. And frankly, we've got some skin on the game too. Yeah, Lisa.
Absolutely. And, and when we, when we, you know, I, I was listening to the conversation and the, and the, and the discussion and, and been doing a lot of research around this as well as, as an analyst, you know, uh, my product is my research, right? And that's what I go out there and I, you know, find out this information.
I find out market data, I find out data points. And on every one of these sessions that we're on these recordings, you, you know, I drop some data points, right? And, and that's good.
So in my mind, the data points are public domain, because I'm sharing it on these, on these, uh, these forms that we're on, whether it's written or video, whatever. The, and as I'm kind of thinking through the, the conversation here, the, the only thing I ask from these platforms is attribution of where the data comes from. Because I mean, I can write down on the back of a napkin some stat, and all of a sudden that becomes, that's the stat, you know, Paul Nash, what he says, the stat, and now all of a sudden that's source and that's not, there's no, but the thing is, is the LLM and the, the, the, uh, you know, AI systems that are out there, they don't have accountability.
They're just tools to facilitate information they find so they can provide false information, which they do. Right? And, and that information that's false has no attribution to it.
The reality of it is, is the user of the tool needs to validate where that information comes from. I now going back to the copyright piece, the copyright piece. When, when a tool like an open AI or, or meta or whatever, and drop whoever, whoever, whatever tool you're using, if they use data that they find, attribution of that information needs to be somewhere in the source somewhere, somewhere in that, in that file.
Because if it's not, it's just, it could be just made up data. And, and again, that goes back to the user saying, well, why am I taking this AI engine as like the source of truth when it doesn't have any validation about the information it's providing? Go ahead.
Just clarify one point that little data point that you just shared is copyright Textron Group 2024. And anything on here is still in spite of what he says, you gotta pay to use it. Um, but, but, so let me, let me put a little fly in that ointment.
Paul, if it was just a question of simple attribution, I would say we could probably do it right? I think we see, we deal with that here at Text Drug, right? Uh, I forgot what, there are various publications that put out statistical data, and sometimes we'll quote 'em in an article and quoting 'em in the article and attributing back to sources is good hygiene by, its very nature though, what AI is doing is taking that data, let's call it background data and synthesizing based upon it.
And it's a different calculation. It's not simply spinning back data with an attribution of where you got it from. It's based upon that data and other data.
It synthesizes new data sometimes. And that's a, that's a different animal. Sometimes it doesn't synthesize, it gives back word for word.
Sometimes it does. You're right. But theoretically, the way, and, and I'm not an AI engineer, we can get John Willis on here to give us a 20 minute or 30 minute explanation, but the way I thought these AI things work is it works one word at a time.
So based upon this last word, that's where it figures out what the next word is and, and what the next word after that is, and what the next word after that is. So it doesn't say, oh, he's asking for something that was in Paul National's report. So I'm just gonna take that first sentence from Paul's report, and, and then it'd be very easy to act attribute that to you.
But that's not the way it works. It says, well, immediately following this word, this is the most likely word that follows it. Sometimes It goes awry and it will take, uh, an entire page from an author's work and deliver that as quote unquote synthesized without the attribution.
Sometimes comedians are saying, you know, their jokes are being stolen, left, right, and center, because the LLMI, I think that's more of a case of parallel evolution, right? So if the, if, if, if, let's take the comedian's joke. Mm-Hmm.
There's only so many ways you could go with why did the chicken cross the street? Right? And, and we've all done a lot of those permutations.
So it's bound, you know, it's bound to have a similar story or a similar punchline because there's only so many ways for it to go in the infinite universe. I think it's more, it's one word after the next. I think that's the, the rule of, of how it works.
So, so one other point than Alan, I would, I would put out there, you know, and again, I'm, I'm listening to what you're saying and I'm thinking about the scenarios and such. Um, when I think about research, there's multiple types of research, but I think of two types of research in particular. One is syndicated research and one is custom research.
And typically custom research is proprietary to the owner of the other requester of that information. And that's typically lock under lock and key and not shared unless the, unless the prospect or the person that has it wants to share it, cool. All good syndicated research is research that's just out there and kind of known and, and, and, and such.
And we want people to kind of use it. Um, if I make any data points or anything that I'm trying to do, whether it's, um, you know, whether it's joke or music or, or book or whatever, if I make it available and it, and the LLM can pick it up and it open AI or whatever, can pick it up and use it right, then it's a publicly available. If it's, if it's pub, if it's not publicly available, that's on me.
I, I, I kind of put it onto that lock and key. Right. But if it's something that's out there and you know, it's said, and if it's used word for word, Mike, to your point, you know, if, if, if an engine uses it word for word, it needs to be attribution, that's plain and simple.
But if it's, but the thing that's concerning, and, and Alan, I think that you mentioned this, and I'm, I'm a little bit, I, I don't, I haven't seen, I've used these platforms a long, you know, a long time as well. I haven't seen the analysis that you're talking about that gives, that takes and synthesizes data. That's, that's new data.
It's usually it synthesizes it in a different way of saying it, but theys, but it's not, it's not like giving Objection when it, when it makes up lies. Where do you think it's, and I don't wanna use the word lie totally when it hallucinates, where do you That's new stuff. Totally.
It made it Totally, absolutely. And then that's where, and that's where if it's, you know, the user of the tool needs to have the accountability of using that information appropriately. You can't just like, use something verbatim that comes out of a, a, you know, a a chat engine that says, okay, this is what I'm gonna use because it said it.
And if it's a hallucination, well, you know, if I did that in my reports, nobody would, nobody would think I was credible, right? Right. And if I changed the words around your data point, I still stole your data point.
So it, it's correct. Right. Well, it's a question of how artful you are changing those words.
I wanna ask, I wanna ask Lisa a question about this. Are marketers watching all this? Because frankly, marketers and companies now publish as much stuff as publishers do, and, um, they are creating mountains of copyrighted content.
And so are they gonna get pulled into this whole conversation? They definitely are aware of this from a marketing perspective, because CMOs that I talk to weekly, everyone's leaning into generative ai. Everyone's using it for copy creation, whether that's website copy, whether it's an email copy for an SDR to send to a customer.
They have to be aware of that. From what I understand with the CMOs that I talked to, there's, they're, they've got internal guardrails on it. They're, they're not opening the kimono to everybody.
They're piloting these projects and attribution is part of what they're evaluating. Um, obviously if something goes awry, they're the ones responsible from a crisis communication and a brand reputation management perspective, but is on the radar, the CML level. Definitely.
Interesting guys. I'd love to talk about this all day, but I, I, I've got other stuff to do. I'm sure Paul and Lisa, you do too.
We have day jobs. This is your day job. It's a great gig.
You can get it. Um, anyway, guys, Lisa, Paul, thanks for joining us on the Gang today. Mike, thanks as always.
We had a good discussions today. Well, Paul, thank you out there for watching this. I hope you have a great Friday.
It's the gateway to a great weekend. We've got a, as usual, a full text drug TV schedule right behind the gang. So don't go anywhere, stay right here on your local text, drug TV affiliate network and, uh, whatever you want to call it.
And, and stay tuned for what other great stuff we have. But until next Monday in, in terms of the gang, that's a wrap. This is Alan Shemel.
Have a great weekend everyone. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.