3-Day Patch Rule, AI Model Reviews and Biosecurity Fears | Techstrong Gang
AI policy is moving from theory to enforcement pressure, and today’s episode of Techstrong Gang captures that shift across three fronts.
Mike Vizard, Chris Blask, Ira Winkler, Kate Scarcella and Camberley Bates break down the proposed three-day patch rule, possible pre-release reviews for advanced AI models and new warnings about chatbot behavior in biological weapon test scenarios. Taken together, the stories show how quickly AI is intensifying pressure on cybersecurity, national security and public-safety policy.
The first segment focuses on the push for a much faster patching window as officials respond to concerns that increasingly capable AI systems could compress the time between vulnerability discovery and exploitation. The second turns to possible government review of advanced AI models before release, signaling a harder policy stance as frontier systems raise new security questions. The final segment examines biosecurity fears after reports that chatbots displayed troubling behavior in weapon-related testing scenarios, renewing debate over safeguards, misuse prevention and accountability.
What ties these stories together is simple: AI is no longer being treated only as a productivity or innovation story. It is now forcing governments, security leaders and policymakers to confront much more urgent questions about oversight, response time and real-world risk.
Transcript
Hey everybody. Welcome to the Techstrong gang for Tuesday. It's Cinco de Mayo day, so happy Independence Day for all our friends in Mexico who are celebrating their freedom from the French.
But we have our own issues with government, so we're just going to kind of jump into all kinds of things involving government and warfare and simple regulations. But welcome to the show, everybody. Kimberly, good to see you.
It's been a while. It has been. And it's even back to snowing in Colorado again.
Yeah. Which is hard for me to think about here in New York, because it's supposed to be 75, 80 degrees today. Ira, I haven't seen you in a while.
Welcome back. How you doing? I'm doing awesome.
And thanks for having me back. I'm glad it wasn't just that I p****d somebody off and now I'm persona non grata. So I'm persona grata today, so I appreciate that.
I don't think it's possible to get thrown off the gang for p*****g people off. It might be actually the mission, but I don't know. We'll see.
Chris Blask, good to see you as always. Hey, good to see you as well. I'm glad to be evidence that, yeah, apparently they keep asking you back no matter how bad you are.
That is what I often tell people. Me. I say that they keep inviting me back despite my best capabilities.
Can't get rid of a bad penny. Nope. Yeah, you know it.
And Kate, good to see you as well. How are you? Very good, thank you.
Good. Well, let's just jump in here because the United States government, reportedly at least, is now kicking around this idea that we're going to require federal agencies to patch things and whenever there's a vulnerability within, say, three days. " So Ira, what's your take on what's going on here with this?
Because most IT people that I know, they think about patches and updates in weeks and not in hours and days. So does something fundamentally need to change here? " There's so many layers to this.
I'll just quickly cover. The first layer is, does the government have anybody left to do this? Because, what was it?
CISA cut a third of the people. DoD, they cut ... My son was a government contractor and they canceled his contract because who needs detection engineering in the government?
And I'm sitting there, there are good qualified people, and the number of people to actually do this is dwindling. So part of it is, do they have the people to properly do it? Because it's not just issue a patch.
There's testing the patches and things like that. And it just takes a while to first test. Then it takes people.
You could roll out automated patching, but there still takes layers of people to validate some of these things. And it's not feasible, in my opinion, to say three days. Two weeks.
It kind of depends on the severity of the vulnerability, I would think, as well. Obviously you need an all hands if something's really critical and it's, again, a Log4j type of thing. But I would say they probably need to consider mitigating controls depending on the severity.
But at this point, I don't see it possible. Mythos is driving it. The problem with Mythos is that Mythos is a detection-only engine.
I describe it as a Nelson. " And now while this is going to be a blast of when Mythos actually finds things, and ideally it'll consolidate and slow down. The bigger problem is you have to do the triage of the vulnerabilities, and you have to determine the mitigation.
I want to say, frankly, again, just to disclose, I'm biased because my current company basically does what Mythos does and better, but more important, we also do the triage and the mitigation creation. And that's the critical part. And the thing is, I don't know if the government has the resources.
It would be great if everybody buys our company's tools, but I'm realistic. They're going to have to go out, find tools to help automate. They're going to have to find tools to help figure out what the mitigation is.
Does it work and everything like that. It's not like somebody can just say, "Here's a patch," and roll it out in three days. Again, criticality, maybe if, again, another Log4j.
I'll stop repeating myself and shut up now, so I'm not persona non grata for the next time around. But... There you go.
Kimberly, I'd love to get your opinion on this because, again, we know where the security folks naturally lean, but the IT ops folks theoretically are the ones that are supposed to go and implement these patches, and I don't think they have the automation platforms in place, and what automation we do have is badly fragmented. So will this finally be kind of the thing that drives everybody to embrace more automation across their IT operations environments because there'll be some sort of mandate involving government agencies and everybody who supplies them? I don't know.
We had kind of an experience several years ago where we had an automatic, "Let me go ahead and apply the fix," and everything got brought down on the network. So I'm not sure that would work either. I think Ira is right.
But I would hope that what they're going to be doing is looking at that tiering. What is a SEV 1, SEV 2, SEV 3 kind of fix that has got to be patched? And I can understand a three-day patch rule for something that is extremely severe.
And today, they're probably already doing it. You guys would know best. You're the security experts, but I would imagine that if you've got a SEV 1 coming through at you, it's kind of like all hands on deck, let's get this thing through, let's get it tested and applied, as opposed to all the other little ones that are that.
And that's what I'm assuming is coming is at you, is that we've had these competitions where you submit that there are exposures, et cetera, and that we pay you money for that. And they've closed that down because there's so many little things that are showing up that need to be fixed, as opposed to the really big ones that we need to focus on. So it gets to be more of a prioritization as opposed to let's fix everything that's out there, I'm assuming.
But you guys are the CISO super superstars, so I'll let you guys comment on that. Katie, is this just going to expose all the fractures that have existed for years and things that you've been railing about for a long time? But it does seem like our software supply chains and our security handoffs fundamentally just broken, and it's not clear how to fix them.
Right. And at the end of the day, we're shifting left again. Over and over again, we continue to shift left when I don't think it's about shifting left.
Platform engineering inherits the reality, how patches are getting deployed across pipelines, how systems are staying operational during the change, and how the dependencies don't cascade into failure. Man. The issue that I'm having, as always, is that this is an event that happens-- we're talking about it after it happens.
We don't talk about the conditions that are leading up to it. And I am the one who, where things are turning so fast that it's time, instead of trying to fix it, I think we throw it out, and we do better code. So that's how I would go about this.
And as crazy as this sounds, I think we should really start getting rid of the bad code, because there's some really bad code, and really bury it deep so nobody can find it again. And yes, that's what I'm proposing- Oh, dear ... as crazy as it sounds, because we continue to do the same thing over and over and over and over again.
It didn't work 20 years ago, and it hasn't worked every year since. " Well, I'm going to disagree with that, because- That's fine ... fundamentally, all software has bugs.
It will have bugs. It is a fantasy to say it will never have bugs. With the advent of vibe coding and automating coding, it's even worse at this point.
Okay. And so saying we're not going to have perfect code, going back, it's like security vulnerabilities are really, at the end of the day, a bug. It's a bug that creates elevated privileges, leaks information, or so on.
And we're not going to perfect the bug, the problem that software bugs exist. And the reality is we have to work within a business environment. And know I'm not trying to take total exception to you, but one of my pet peeves is cyber- They do on this call all the time.
People are always thinking the world should listen to what we say, as opposed to, look, our job is working within the world we are. We're there. I'd love to say tear it all out and build it perfectly, and nobody will ever build it perfectly.
" The reality that we live in is we either have to adhere to what the business is, or we shouldn't be there. The problem, though, that I have, Ira-- oh, sorry, Chris. Go ahead.
No, go ahead. It's just that we actually have garbage. And I was going to say crap.
We have crap that honestly needs to be thrown out. We have hard-coded credentials. We have static identities.
We have flat networks. We have implicit trust. These are things that are easy to be discarded, that AI is taking advantage of, and because it sees it, and why shouldn't it take advantage of it?
So there's actually things when you say we'll never get to perfect, you know what? It'd be nice if we would stop that. Well, I'm just saying, I'm not disagreeing with what you're saying.
Hard-coded credentials should be out of there. Those are what I consider vulnerabilities built into the software that should be changed. But to say we have to be very specific then adhering...
Because I agree with what you just said there. " Because without getting into specifics on how APT malware works, it's little bits of software distributed throughout the network for lateral movement, and if you take one out, it gets reinfected by the rest of the system. " That's not what I'm saying.
But it's okay Chris. Go ahead, Chris. Chris wants to chime in here.
Yeah. Let me explain and look at it this way. So we're actually dealing with an instance of this, right?
A patch has come out in the US federal public sector system. One of the canonical nodes that can say, "This is now part of the policy system that we're going to execute and process," has come out with this artifact. And we're talking about whether it's a good artifact or not.
And this is something we systemically do over time. We look at something like this, right? If there's a global audience, there's a global issue.
What the US federal public sector chooses to do, right or wrong, is important in a lot of ways, but it's not universal. Right? So the contents of this, as everybody's saying on the panel, it's problematic.
Right? And when I look at this thing, I agree with everything, the conversation going on, and the things we need to consider. But I look at it, and say three days.
Okay, why not three years, three minutes, three seconds, three decades? Who knows? So we pick this timeframe, and it rhymes to me with a conversation, my second favorite weekly conversation I have, the Linings Foundation S-bomb coffee talk, which is just a great bag of cats.
But yesterday, talking about the fact that we're changing now certificate lifetimes. I think it was 300 and something days, then 200 and something. I think it was 47, now it's going to 28.
And if it's only safe for 28 days, why is it just 28 seconds? Right? And the fact that we have something like everything will patch in three days, or a certificate is good for a month, shows that we have a fragility in our systems.
Mm-hmm. So we'll endlessly come back to these sort of conversations, like how do we solve this individual part and this part? When maybe we should just make them less fragile.
Well, we- Well, we're always going to have fragility. Yeah. Go ahead.
I mean, you're asking for a perfect world, and there is no such thing. No. Well, again, I think- But getting back to what Kate is saying, I mean, that list of things that need to be addressed, old code, et cetera, old capabilities that we have in terms of how we're authenticating things.
I mean, the bigger problem on that piece is all the priorities that are pounding on the IT organization, and how do you prioritize that very long list that you have to say what I'm going to take care of first. Right. Kate, I was- There's a fundamental piece to it, and then there is the practical day-to-day piece that you've got to address.
Well, I know we're at the end of the time, but I think what Kate and I are arguing here, and I think we've got an interesting thread, because absolutely not perfect. Perfection is the ultimate fragile. But there's more and less fragile, and a lot of our systems are increasingly getting more fragile, right?
Getting down to something that's actually resilient by systemic processes is not perfectionism, it's about accepting imperfection and building systems for it. Yeah. So wait, so let's just play this out for a minute, because in theory, I think there is a middle here.
To Kate's point, we should replace as much of that bad code as we can, and if that means ripping out a bunch of legacy apps, great. To Iris' point, it will never be perfect. There will be vulnerabilities in those systems, but in theory at least, if the AI coding is getting smarter and better, we should be able to fix those vulnerabilities as they're discovered faster than we can with legacy systems.
So we can get to maybe less than three days to fix a new app because the AI coding will be that much faster, and the testing will be automated, and in theory, we can do that. I don't think we're anywhere near that, but I think maybe that's where we're marching, and I don't think that a bunch of bureaucrats announcing that we're going to do a three-day remediation cycle is going to get us there, but maybe it would be nice if some adults had a conversation about this. What do you say?
Mike, I said I loved you last time, and I love you more this week. That's it. You have summarized it beautifully.
Give yourself a big hug. All I will say is it would help if the government wanting to do this wasn't simultaneously cutting lots of staff. Yeah.
I don't think that we can automate our way out of this without people. I think we need the people to orchestrate the automation because, well, as we talked about in some previous shows, the automation tends to lie to us, right? Somebody's got to verify the thing, and we've got to double-check that this thing's for real.
Chris, does that all sound reasonable to you? I'm going to give you the last word on this one. Right.
And the next two segments, we keep coming back, and over week to week in this conversation, and every week of mine for the last year, it's the same issues. Right? Can we see what's going on well enough to make decisions, or we just got to trust and vibe code, or what are we going to call it next?
So yeah, I think we're still going the same direction. I think it comes down to that word trust, which brings us to our next segment. It looks like the United States government, or at least President Trump, is starting to recognize that maybe this AI stuff requires a little bit more oversight than some of the things that they may have previously said.
And I'm looking at this as sort of maybe as a good thing, but I've got to tell you, I'm kind of stuck between, on the one hand, it seems like I've got a bunch of people running around calling for no regulation and just want to run fast and break things. And then on the other end of it, I now have what appears to be the military industrial complex getting involved in AI and starting to bring their mindset to it. And I'm going to toss this one to Kimberly, but I've got to tell you, I don't know who I'm more afraid of.
Well, thanks for passing it over. So, just a little background. I'm part of a society called the American Society for AI.
And last December, I hosted, as part of that, a panel that includedA retired general as well as one of the top leading CIOs in the government. Probably one of the biggest ones that's very pertinent to this conversation. Can't give names to folks because of the rules in terms of what we talk about, what comes out of there.
But the discussion was on, and the other thing that I'm working on with them is non-proliferation of AI, or harm in part of a constitutional kind of thing. So with that background and looking at this, the things that, A, that came out of that discussion is AI or something like it is already being used. Two, we're already doing automated drones, we're already doing automated missiles, all that kind of stuff is out there already.
So a bit of right now what is going on, I believe, when I talk to them, is kind of starting to pull back a little bit and saying, "Okay, so we've already gotten this far, and the new AI models are going to take us even farther. " And as much as David Sacks was driving this, hands off. There's been enough data that's coming out of some of the reporting, whether it's the Stanford report.
NATO also, Strategic Communications put out another report about misinformation, et cetera, that just recently came out, I think it was last month. It's enough to completely finally frighten me, which I was on the same wavelength as David Sacks was, hands off, because we've got to beat China at this. But now it's at the point of where more than likely what needs to happen is this next, whatever our government is over there with China, is this discussion about, okay, how do we stop the atomic nuclear bombs from having access to AI?
How do we put the human in between here? Because if we don't put the human in between here, we will have bioterrorism via the AI, or we will have the other. And I'm not one to say the world is falling, but it certainly is there, and I think that's what's just happened, is that there's enough stuff that's coming out that somebody says, "Holy Toledo, maybe we really should put a little bit of brake on here," but we're not sure how, and we have to do it in concert with China, North Korea, and anybody else that's got the bombs.
Well, here's my issue that I think is probably more important. See, we're talking about these large frontier models doing this work. Mm-hmm.
Yep. And I come down to looking, for example, I'll use the example of Mythos. You can use Mythos like we did.
We just tailored it to use a much smaller model and a smaller footprint. Mm-hmm. The fact of the matter is, if somebody can do it, whether it's with a really large software model or not, they're going to find a way to do it.
Mm-hmm. Because I use the analogy, AI, no matter what people want to attribute it as an entity, is really just software at the end of the day. And what happens is, I look at it almost like encryption.
They were starting to look at encryption in the same way, let's regulate encryption, let's regulate a whole bunch of other software, and put export controls on it and things like that. That aside, people came up with their own versions of encryption, which are pretty much just as good when they try to, for all practical purposes. Now, when I start looking at bioterrorism and things, yeah, previously, you used to be able to go ahead and say you need massive computing power, et cetera, to be able, for example, to do pharmaceutical modeling to develop drugs.
I'm using that as an analogy for creating biological chemical weapons. An iPhone is more powerful than the Cray computers I worked on at NSA. And when I start looking at this and start thinking of this, it's nice in principle, but people are going to develop more lightweight models for AI that are going to be able to come up with results that maybe aren't going to be the super sophisticated advanced ones, but you can still figure it out- Mm-hmm ...
with a lightweight model. Will it slow it down? Possibly.
But then we haven't even talked about what happens, and another buzzword, with quantum computing. Because one of the issues with AI has been, oh, we need massive computing power. Which we do.
But now what happens when you get a quantum computer that can replace, I don't know the scale, but one of those massive little AI data centers that they're putting together. Yeah. And quantum computer.
Yeah, sorry, I'll leave it there, but that's just a discussion point I have on this. So the ISO technical specification. So the ISO series, which actually doesn't stand for the International Standards Organization.
I love that. But anyways. The ISO 42000 series is the AI series, and 42001 is out, and there's a technical specification committee that just started last week, the Standards Council of Canada, that myself and other folks I recognize are just starting to think through.
And it's on a technical specification for systems of AI systems, right? And in this segment so far, and the last segment, so many of the conversations I get involved with now, we talk about the models. And I have my comments on this one.
I think that generally speaking, what the folks responsible for this segment Need to do inside the US federal public sector is the kind of things I would generally recommend. You need the visibility into what's going on, and not because they're good folks or bad folks, because otherwise the systems won't work. Right?
And Ira, what you're saying about models right now is like none of these models have yet done anything that I wouldn't expect large language models to be able to do. But an LLM really is just a piece of code. All code is just pieces of code, but systems are what matter.
Right? And this is another one of these cases where you can have an LLM, you can have a single piece of code, an application that will do a thing and increase the functionality, increasing its features, and we can talk about that. Or we could say, assuming they reach where they're obviously going, how do we have them in systems that make any bloody sense?
I think we can answer the second question. But the first question ties this up because they're fascinating, but it's just a model. I have a question for Kimberly.
And I don't want to sound too namby-pamby about this, but I feel like everybody having a conversation about this is talking about some more efficient way to blow up somebody else. Is anybody talking about some more efficient way to defend ourselves from this stuff? Because other people are going to have this, and maybe the tenor of the conversation needs to shift from what we're going to do to somebody else versus protecting ourselves from what somebody else wants to do to us.
Well, the DoD or DoW, whatever you want to call them, are already, as I said, they're Department of Defense, Department of War, however you want to look at those guys. They are talking about how do you incorporate this in order to defend. Mm-hmm.
And part of that is strike first or whatever. And I'm not sure exactly if that's what you mean by that, but defense talks, you guys would know better than I do, but defense in terms of cybersecurity, putting the framework in place to prevent the penetration of it. But where I was going, and what I am thinking about is that as human beings, it's do we allow AI to have access to certain things, or do we prevent that?
Or do we have a human intervention there that before anything happens, it has to be executed by a human? Getting back to who carries the key. Well, that's a different question, though, than the articles are implying.
Yeah. " And I frankly think in certain cases, hell yes. Mm-hmm.
Clearly, hell yes. The concept, though, is they're trying to, if I'm not mistaken, regulate the release of this, for example, export controls, like regulating encryption. And that's another conversation where that could have, to Chris's point, yeah, you're right.
You can't just have one LLM doing something. You need systems- Mm-hmm ... and an environment of LLMs to come up with the right answer because it takes many decisions to, for example, create a biological weapon, just as an example.
It's a little bit simpler. What's the best way to distribute the biological weapon is a lot simpler of a question. Mm-hmm.
" If I'm not mistaken. I hope so. And in that case, we are.
" And dig through their whole persona, dig through their travels, their family, and everything like that. That's theoretically possible, too, depending on which, for example, databases you get access to. Can you, for example, get access to their Facebook posts, where they're going on Twitter, and things like that?
That is possible. Just to answer your question, it takes a lot more invasive or willingness to be invasive, and also a lot more computing power to look through all those simultaneously to track someone and figure out, okay, who might be the best person. '" Or something like that.
Well, the way I interpreted the pre-release, and let me real quick, Kate, was that this was the beginning of the government looking at how they would regulate this. And so where does that go, and how do we do that if they're going to do that? We're already seeing Europe doing, we're seeing it other places.
How does that play out? Kate, I'm sorry. Yeah, no.
I really believe that we're looking at this wrong. Big surprise. But when we're thinking about baseball, and to Mike's point, isn't there a way to think about this differently?
When you catch the ball for baseball and there's three outs, why don't we think about that differently? Why don't we think about when something happens, instead of escalation, we do de-escalation? So you catch the ball, the people are out.
One of the things to Chris's point as well is about, hey, at the end of the day, this is software, folks. This is software. Who controls the software?
Chris, I think over and over again, he has talked about canons, and canons are such a key to this, and I'm so glad him and his team have been, I would even say revolutionary as far as where they're thinking and taking LLMs. And I believe we really need to think about this differently. We continue to escalate.
We continue, I think, to have the wrong people in the room when we're talking about this, and we really think if we can escalate, we can de-escalate. And it's about catching the ball when it's up in the air and saying, "You know what? " Focus on the one baseball that's up in the air, you're out.
I don't think we're going to resolve this here today, and I want to move on to our next topic, but I would advise everybody, check out this movie that Matthew Broderick made. " It's a classic. I think it's still relevant today.
I love that movie. " Switching gears to something that Ira brought up. Well, there have been researchers out there who have been using LLMs to show that you can go out and build something that is a weapon of mass destruction, and in this case, I think it was biological in nature.
But we've been talking about this at the level of governments, and yet, as I look at this stuff, Chris, I'm going to punt this to you, but it seems to me it doesn't take much for a small group of radical folks who will believe in whatever it is that they want to believe in, to go start using LLMs to start putting together all kinds of mayhem. And we don't really have any decent guardrails to prevent that. Well, you know I like looking at things over time and the bioterrorism and automation and technology, right?
I was a kid in the '70s reading about this speculative fiction and so forth. It's kind of obvious when you think about it. This is the direction we're going.
We will get there someday. Is it our lifetimes? Is it a thousand years?
But it's obvious we get there. And that always begs the question, do we end as a species, or do we figure it out? Right?
And let's be clear, right now, particularly for everybody on the screen right now, we live in the safest place to be a mammal ever on the face of the earth. Mm-hmm. We're all terrified, which is an interesting artifact of being really, really safe.
But our risk, the risk to us, is so near zero compared to my grandparents, their grandparents, and particularly farther back, that it's not even on the same scale. And we look at things like 9/11, like drone warfare, slaughter bots. It was seven, eight years ago, remember that?
There was a seven-minute reel. It was great. Drone warfare is coming.
Now it's here. Right? And each of these points, you have to say, all right, since it was obviously coming, and could, in theory, wipe out the species, will it?
And if not, what is it we do to not do that? Right? So I think, like people flying planes into buildings, this is something that is a reality.
Drone warfare is a reality. Any idiot can do it for a couple grand and a bit of spare time. And what do we do?
And I think, without taking the rest of the segment, we navigate forward. And each of these topics today are examples. AI in US federal public sector defense, yes.
Classified systems, that's going there. How do we build that? I think, Kate, it's canonical to that local environment.
Those systems do exactly what you tell them to, and they keep receipts exactly the way you tell them to because you have to, otherwise you can't run that system. We'll see. Well, I think- Because I think it's all going that way.
Sorry, you took a dramatic pause. But I kind of think that I wrote in my first book the concept of dragons and rats, because everybody is afraid of dragons, this malignant entity, or sorry, malicious entity that's going to fly there, swoop down, and create damage beyond compare. " Yeah.
The reality is we have rats. Rats are not malicious, they're malignant. You look back at the Middle Ages.
The Middle Ages, we have visions of dragons. What was the number one cause of death in the Middle Ages? Rats, because rats spread the plague, because of fleas and everything like that.
And the problem is, we're focusing a lot of AI being afraid of the malicious threats as opposed to the malignant threats. And we talked about the malignant threats, which previously, which are like software vulnerabilities that are going to create issues. These vulnerabilities exist no matter what we do, but we've grown to accept them.
I use 9/11 as an example, and I don't mean to trivialize this, but more people died from donuts that year than died from 9/11 because of health-related issues. " And I love donuts, for the record. But we were worried about this terrorist threat, which was horrific, but at the same time, in the overall threat to the population, we're losing this.
Now, having this discussion is important to say, hey, we need to go ahead and understand that, yes, people can find out information, which frankly, they could anyway. It's just a lot quicker. Let's understand that.
And then the real issue is, okay, how do they get the resources to create or act on the information they get? So we have to start looking at this, yes, this is a bad thing. And that's- But unless they're given the right code, we need to start regulating, this is what they can do, let's start tracking the physical stuff that makes it a reality.
Because we're losing touch that the physical is more important than the technical when we're talking about these elements. And if I can just follow on that, because you used one of my favorite words, right? And I think you knew the timing.
Since the Middle Ages in Europe, we have this concept of dragon slaying, right? But dragon stories are all human culture forever. And normally what the dragon is, is some big, huge force that you can't control.
It isn't going away. You've got to learn to deal with it. That's the lesson in most dragon stories.
Mm-hmm. Except, interestingly, ours And we keep going out and trying to slay dragons. And we're security people.
We're going to make the perfect... No, we're not. It's there.
How are we going to live with it since it's there, as opposed to how are we going to- Well, let me just- ... slay the imaginary dragon, right? Here's the analogy taken further, which I think is actually important.
And the thing is, why do you need a knight? You need a knight because you have a dragon. And to have this knight, the knight shows up and says, "You've got to give me the best food.
" Yeah. " So we have government, and I'm not downplaying the importance of preventing, for example, terrorism and everything else, but to fight a dragon, if you create a dragon, you need money. " And that creating dragons is what gets people rallying around- Mm-hmm ...
the proposed knights. And we need to control the perception of dragons and focus people on the rats. Mm-hmm.
Sorry, I'll leave it at that. Or dragon management . With that statement, and maybe Kate, you were going down talking a lot about the rats earlier, on the bad code and everything else.
What are the rats that we need to focus on? Is it- One of the things- So I live in New York City. Is it the rats, or is it the stuff that the rats are eating and the garbage that's everywhere?
To Ira's point or Chris's point, maybe we just need to start tracking where all that fertilizer is that somebody's going to use to make a bomb or something. I don't know. One of the things I find ironical is rats are also used in computer, right?
Remote access. Did you make that correlation in your book by any chance? No, that was a different topic, but- But it's still sort of interesting, rats and- Rats are...
That's a good example of analogy and a reality. Yeah. So to sort of going back, I think that when...
So yeah, so am I being dramatic about throwing everything out? It's the idea that I believe that we need to switch the way that we're thinking. That we've been going forward for decades, and it's not working.
And seriously, my biggest fear is that we're really not changing the way that we think. And I don't understand why that is, when it's been proven wrong over and over and over again. So I really push, and it's Chris's fault here that I push this idea on canons.
We are horrible documenters. The computer people have been horrible at documenting. And if there's anything that we can do right now, it's document, document, document.
Because the system, with AI, it cannot run over their own documentation, their own canons, their own precepts. It's going to be one of the things that I think will save us. So, let's get those writers.
" And then the things that should be done. Let's stop the escalation. Let's talk, what actually is responding?
What is working? Let's get rid of the things that we know are not working. And quite frankly, it's just common sense at the end of the day.
Kimberly, I want to give you last word here. What's your sense of how hopeful are you or not as hopeful? " And is it your sense that responsible people are now having responsible conversations about this stuff, and maybe something good will happen?
I'm usually a pretty hopeful person around this area in technology being implemented. We've seen centuries of technology and thinking that it's going to completely disrupt, and the world is going to fall apart, starting with the printing press. Or maybe even before then.
And I think what Ira had to say, Ira, I'm going to go find your book. So on the rats versus the dragon, I think you're absolutely right. It's like we need to focus on the ankle biters more than anything else.
Maybe. I think there's other things to be done. But we as humans have evolved, and as Chris was saying, it's like we are safest as we've ever been.
So to think that the world is going to come to an end with this, I don't think so. I think we'll figure it out. But we have to look at it.
We can't just close our eyes. All right. Hey, folks, have this conversation with your friends.
We're in the tech sector, and if you're watching this, you are probably as well, and you know about this pretty deeply, or some of you even more than we do. But I feel like the folks outside of our little bubbles don't necessarily understand the correlation between AI, tech, public policy, defense, and so just start having those conversations now. Don't scare them, but educate them because this is getting pretty serious.
I want to thank all our panelists for sharing their knowledge and their insights today. As always, they were amazing. And I want you to all stay tuned for the rerun of the Techstrong TV lineup from earlier today, because it's just jam-packed with all kinds of content.
And if you have a minute, go check out the Tech Field Day stuff that's shown on the Techstrong TV feed as well. Thank you all for watching, and hopefully, cross your fingers, we'll see you tomorrow.