Open Source, AI and Tech Sovereignty Take Center Stage: The Open Current Ep 1
The Open Current Begins With a Timely Tech Conversation
In the first episode of The Open Current, Alan Shimel and Margaret Dawson launch a new conversation series. The show focuses on the forces reshaping enterprise technology. The discussion starts with the purpose of the podcast. It quickly moves into the topics that matter most to technology leaders today. Those topics include open source, cloud native platforms, security, AI and tech sovereignty.
Alan and Margaret explain why these issues are no longer abstract industry debates. They now shape real business decisions. Organizations are asking harder questions about where their infrastructure runs. They also want to know who controls it, what sits inside their technology stack and how much choice they really have. That makes tech sovereignty a practical concern, not just a policy phrase.
Control, Choice and Transparency
A major theme in the episode is the difference between owning technology and controlling technology. Margaret shares examples of organizations that may own their data centers. Yet those same organizations may still depend on partners to deliver complete stacks. That model can work well, but it also raises new questions. If a company cannot see what is inside the stack, it may not fully understand its risk. It may also have less flexibility than expected.
The conversation connects this issue to composable architecture, Kubernetes, Linux, automation, management and security. Alan and Margaret point out that businesses want trusted partners. They also want transparency. They want to know which choices are being made on their behalf. They also need to know whether those choices support future flexibility.
Open Source, AI and the Next Wave of Risk
The episode also explores the tension between open source and proprietary models. That tension is becoming more important as AI changes enterprise technology strategies. Alan and Margaret discuss how AI, security and cloud native decisions connect to larger questions. Those questions include openness, control and global technology competition. They also note that attackers are using AI. That makes cybersecurity an essential part of the conversation.
The Open Current is designed to continue these discussions in future episodes. Alan and Margaret plan to bring in guests and respond to audience ideas. This opening episode sets the tone for a practical, opinionated and timely series. It focuses on the decisions shaping modern technology.
Transcript
Hey, everyone. " I'm Alan Shimel, and my co-host is Margaret Dawson, CMO of SUSE, and we have been threatening to do this podcast for going on near a year. And I'm really happy that we've finally had the chance, but now that we've started it, we're not going to stop.
You'll see us- That's right ... every other week. Margaret, it's been a long time a-coming, but we got it going, and I'm really, really happy.
No, I love it. And thank you for doing all the hard lifting to get us here. So I am looking forward to this, and I look forward to getting people's feedback because I think this should be something that people share and help us come up with the topics that are important to them that we can just chat about.
Absolutely. And we're probably going to do the first couple episodes just you and I, but we'll be looking for guests- We will be ... going forward.
And if you're interested and you've got something you want to say or a topic you want to hear us talk about, please let us know. com. Oh, cool.
I didn't even know we had an email. It actually comes to me, and I'll take it, and I'll do that. Makes it easy.
I think maybe we should talk about first what we want to do with this, because every podcast has-- There's a million podcasts out there. Everyone has, what is the purpose of this? So maybe we should step back and just share that a little bit since this is our inaugural episode.
" Sure, that could be- Yeah. Hello, world. That's good enough.
Fill in the blanks. Well, let me give my two cents, and then you- Yeah ... can put in your nickel.
I met Margaret Dawson about, I guess, a year and a half, maybe two years ago originally. She had recently joined SUSE, and we did a video together. It was my favorite video.
I think it was at KubeCon. But it was my favorite video of wherever we were. It was my favorite video of that whole trip.
And I said, "This woman really has something to say, and I love the way she says it. " And over the last year and a half, two years, every time we've had a chance to be in the same place at the same time and do a video, we've had amazing conversations about really good topics that I think people care about. Mm-hmm.
" And when you're talking SUSE, Margaret, you don't have to plug SUSE. I'll plug SUSE. Right?
We talk about things like open source and openness. Mm-hmm. We talk about things about sovereignty.
We talk about security. We talk about cloud native. Right?
These are really important. We talk about AI. Everybody talks about AI.
Right. Right? But these are things that are really important that are, for our audience at Textron, for SUSE's customer base- Mm-hmm ...
these are just not topics on papers anymore. They're life and death business, yes business, no decisions. And so I'm thrilled to have a forum to discuss them and to have you as a partner to discuss them with, frankly.
Yeah, and I think what motivated both of us to do this is we're sort of stepping out of our day jobs a little bit. " A little bit more off the cuff, a little bit more not polished and whatnot like we might have to do when I'm on the clock, so to speak. And just kind of look at things in a fresh way, because I think that's why we've always enjoyed talking to each other, because what people haven't seen is off the camera, that we just keep going and it never stops.
And so this is meant to be like those parts off the camera that you haven't been seeing only on the camera. Yeah. Like almost outtakes, if you will.
Except without swearing. Without bleepers. Or without any of the bad language yet.
No. Well, we'll try not to. Yeah.
I'm not making any promises. All right. Okay, Florida.
So let's jump right in, though, Margaret. I wanted to talk today about something that I think is really, really important and people are really having to deal with, and that is, do you really own your own technology stack? And should you own your own technology stack?
Maybe is a preemptive question. I know this is something you hear from people in your day job, as you say. Mm-hmm.
Is it okay not to own your technology stack? Yeah, and I don't think this is a new topic. I mean, as soon as you said that concept of do I have to control everything?
Do I have to own everything? If you think about the first wave of this question was what? 20 plus years ago, when everyone started looking at public cloud.
Right? And sure, first it was mostly developers kind of not wanting to wait for a VM, and so they just went to the public cloud, but we had colos that sprang up. There was this whole movement of, I don't need to own my data center.
I don't need to own my infrastructure. Right? How can I be more agile?
Is it more cost-effective? Can I move faster? Whatever it is.
So we're in the next stage of that, only now the question is, do I have to own it because I need it to be sovereign, I need it to be secure, I need to have a private LLM because I don't want a public model and my data going there? So the motivations or the reasons we're having this conversation have changed, and now it's almost like a reverse logic, where people are like- Yeah ... do I need to bring it back?
Or if they were thinking about moving faster to a hyperscaler, are they rethinking that? So it's become a really interesting kind of juxtaposition of where we were 20, 25 years ago. Same question, but the motivations behind it and the actions being taken are a little bit different.
I've got a kind of preemptive question to ask you. Is there a difference between control and own, and does that distinction make a difference? There 100% is a difference, and I'll give an example just from a conversation I had this week.
So I was talking to a customer who owned their data center. So they have their own data center. But they receive their racks ready to go.
So they have a very close partner that embeds all the software, provides the hardware, puts it in the rack, so stack and rack, as we say. And so they control it. It's in their environment.
But the question they're asking is, we don't really know what's inside that box. We've trusted this partner. We know there's things like Linux and Kubernetes and automation and management and security and all those things, storage, et cetera.
And usually, they're told what the brands are that are in there. But for the most part, they do this because they want one throat to choke, so they just go to that partner, and the vendors inside ... are secondary because the vendor is providing support for all of those things.
But now the motivation is, if I can't see it and I don't control it, and I'm not making those decisions myself, am I really sovereign? Am I really in control? And so for the first time ever, for whatever, 20 years or more of this very large organization, they're starting to use words like composable architecture, open source- Yeah ...
choice, flexibility. How hard would it be if all of a sudden we have a vendor for Kubernetes and we are making that choice versus it being just embedded? So that is a fascinating thing where, and they still want to work with that vendor, by the way, so they love that partner, but they want to be more involved in the decisions because they want to have more control.
So it's not an ownership issue, it's a control issue and a transparency issue. Yeah. And I think that goes to the fundamental, I did one of my rants today, Shimmy Says, about Google.
Mm. Google broke the covenant of the open web, where people allowed Google to index their sites, index- Mm-hmm ... their publications, index their content, with the idea that people would search Google, and Google would display those search results, and traffic would get sent to you.
That's done. Google now is taking your information and serving it up. Their AI is summarizing it and serving it up and not sending out traffic.
People's traffic are down 40, 50% because it all- Or more. 70% in some cases ... stays on Google.
Or 70%. I think when we talk about control and ownership, it's not just infrastructure. It is your data, it's your IP.
Look at how applications are built today. They're Frankensteins. Right.
Right? They're- It's not just that. I thought you were going to go further and talk about music and content.
Like look at all- All of it Right. Look at all the fights in the world of copyrighted content or art or whatever, images. Who owns your image?
Do you own your image? Can you control the image of your own face? Agreed.
And this, it goes on in Hollywood. You may control it, but once you sign it over, can they use it, and reuse it, and reuse it- Right ... from an AI perspective?
So I think the whole issue of control and ownership over one's own IP, over one's infrastructure even- Mm-hmm ... is... But let me, I got another kind of question to ask you on this.
I love asking you this stuff. It was always there. You said it's always been a problem.
Right. But why is it such a big problem now, you think? Yeah.
Well, you just said it. So AI obviously is the biggest driver of, I would say, a feeling of a lack of control, right? But it's not just that.
And I think we talked about this before, where I really feel like this is a perfect storm, especially for technology leaders, but even business leaders, right? Because we had just the AI momentum, it felt like we went from zero to 1,000 overnight, right? And the pressure to prove how you are using AI, initially, to cut costs, to reduce head count, right?
I think we've already started to see the calming of that, I hope. But you combine that with just the geopolitical pressures. We've got now two major conflicts going on worldwide, more if you look at beyond where the US is.
And then you look to the hardware shortage, the silicon shortage, which again, was brought on by all these GPU farms and the AI hype. " So there's an emotional feeling that has nothing to do with the technology itself being in control, but just humans are feeling like, it used to be, we always have had this need to balance our technical debt, our existing IT, plus what we want to do that's net new and innovative and exciting and transformative, right? " So I actually think this question of control is also leading to some inertia.
I don't know. What are you seeing? I just think it's a different phase because it's just- I don't think this is a case of Karen, a bunch of Karens running around Boca Raton yelling, "The sky is falling," for no reason.
I think people have a good reason to feel distrustful, to feel insecure. Because I think a lot of the facade of the world that we grew up and lived in has been exposed, and- Mm ... it was just a cheap veneer perhaps, right?
Everything, especially for our friends in Europe and outside of the US, where they don't feel secure that the infrastructure that they've depended on cannot be pulled out from under them. Right? It's this whole sovereignty issue.
Right. At the same time, even taking AI, for example, right? You have two models of AI that are warring right now, sort of a cold war.
You have the American, what I call Cadillac model- Mm-hmm ... and you have the Chinese Volkswagen. It's funny I called it- Mm-hmm ...
the Chinese Volkswagen, but- Yeah, I was going to say that's a mixed metaphor, but okay. But that level, right? It's a classic open source versus- Yep ...
proprietary. Yep. And we're seeing a lot of friction.
Of course, the proprietary saying, "Oh, the open source is stealing our IP," and that's how they built it, which is pretty ironic when they built that IP based on stealing everything off the internet over the last 10 years. But, so there's so much change. You talked about wars and stuff.
Yes, it's wars, but it's also, it feels like the ground under our feet are moving. And so I think people get that. Yeah, I find it interesting that you're saying that because I think what's different, too, is that it's not just a single group or a single generation, which we sometimes see.
No. I'm surprised that even some of my children, who are adults, but still young, are feeling very unnerved and don't trust AI. And- Yes ...
they grew up with technology parents, and were early adopters, and I have a couple that are using it, and I use it constantly. " Right? Yes.
" And this is the same generation, by the way, that Wants work-life balance that- Yes ... takes, which- Well, no, they're no doubt, they're different than us. Right.
Yeah My kids are the same age, and I see it too. But you know what? It's not necessarily a bad thing.
Yeah. Maybe it brings that balance, right? If we've kind of got this- Maybe that's what we need Yeah ...
more balance like that. But let's bring it back to the enterprise, if I could. Yep.
What's a poor enterprise to do here? I mean- Well- ... do you- Yeah.
It's a good question ... go on a building spree? I don't know I always going to go to the business outcome, right?
It's like I think we get stuck spiraling on these technical questions. But the thing I will always ask a customer is: What is the outcome you're trying to get to? Because it's very easy to say, "Oh, should we build it?
Should we buy it? Should we open source it? Should we use proprietary?
" Whatever. But it's like, what are you trying to solve for? Because the danger always comes when we think we need to do something that starts to take us away from what I call our core competency that is actually impactful to the business that we are running, or the way that we are driving that business or earning revenue or, if we're a nonprofit, changing the world.
And so as soon as you find yourself unable to align to that vision, align to that outcome, align to your reason for existing, that should be a red flag that you probably don't need to control that, right? Because it's going to end up sucking your time. And the example, I'll just go back to open source, right?
People think, "Oh, I'm just going to take Kubernetes straight from the project. I'm going to manage it myself. It's easy-peasy.
" And then it's like, okay, so you're going to handle all the CVEs, you're going to manage all the updates, you're going to have a team that makes sure that everyone's on the latest version. You're going to, and on and on and on, right? You're going to figure out how to manage it.
You're going to figure out how to handle all the different pieces. You're going to figure out the right hardware underneath it. You're going to figure out which OS you want to run, all those things.
And is that what you should be doing, or should your technical people using their brains to think about how can I build really compelling applications and experiences for our customers or whoever our end users are so that this business is successful? And that's not just technology, but it's the world we're talking about. So to me, that is always the first question you should ask.
And then it's like- So I call that the- ... okay, if I don't control it, can I secure it? Is it sovereign?
Then you can ask all those questions. Well, what do I have to do? So I call that the freeze in beer versus freeze in freedom question, right?
Mm-hmm. A lot of people look at Kubernetes and say, "It's free. " Right.
" Just what you described. Because it's free. It's free like free beer free.
There is no free beer in this world. I learned that in college. But- And it doesn't taste good is the other thing No.
And it never- I have to say, if you're going to drink a beer- Free beer never tastes good ... I want one really good beer. You have to go to Europe to get good beer, honestly.
I like their beer in Europe, but- And wine. Yeah, I know. Yes.
But that being said, there is no free beer, but there is free as in freedom, and that's a little bit of what downloading Kubernetes like that does for you. But you quickly find out that from a dollars and cents perspective, that freedom's expensive. That's right.
And sometimes you might be better off. But it does beg the question that, do I need to control or own everything, right? Or do I- I think- Yeah ...
is it really my data that I care about? Yes. So let's go back to that, because I keep going back to infrastructure.
I think data is a different question, especially when we start talking about AI, right? Which goes back to that issue of are you using a public model, a private model, right? And we're seeing this real movement around private LLMs, and more customized LLMs.
Like, I just want a model that does this. I don't need the ocean. I want- Yeah ...
a very contained lake or pond, of which I need that capability. And it's usually a hybrid decision, right? You still may use some of the big public models for like ChatGPT or whatever for some of your writing- Mm-hmm ...
or some of your creation. But when it comes to the more sensitive areas of your business, even coding, right? Because you can train some of these smaller LLMs to be very specific, and you're not so scared about sharing code and your style of coding or programming your applications.
I still think from a developer perspective, the scary part is if you are building proprietary applications, where is your source code? Who are you giving that access to, right? So there's a different way to look at the layers of code, I guess you could say.
But unfortunately, my gut tells me this is still a developing- Mm-hmm ... story. Yeah.
It's still a developing how we're going to deal with this, because I don't know. No, I think you're right. I don't know what the answer is.
Yeah. And that's so unique for you to say you don't know. Thank you.
No, but I think in this case you're right because- I'd rather take the Karens here, but go ahead. Don't call me a Karen. No, no.
Well, but they would know. But go ahead. Oh, the Karens would know?
Yeah. But I think this is why it's such a big discussion, right? Because everyone is talking about it, and again, I don't think there's one answer.
And this is what sometimes we lose is that we think that there's a single way to solve something sometimes- Right, a golden path ... something comes out, right. Like, just give me the answer.
I think it's human nature. It's like, just tell me the easy path. Give me the easy button.
Just tell me black instead of blue or whatever it is. Mm-hmm. And the reality is, I think these are hard decisions, and you're going to have to make some big bets, and you're going to have to take some risk and then, but you've got to do it in a way that is calculated because the last thing you want is to end up opening the door to hackers, who by the way, are also using AI and becoming really, really smart.
Yes, they are. Right. So we didn't even get into the whole cybersecurity thing.
So that's the flip side to this whole thing. Right. No.
Is that- We will in future episodes, though, because there's so much- Okay ... going on here. We should bring in a real smart- But I've got to- ...
cybersecurity expert. I've been doing cyber for 25 years. I'm- Okay.
Well, just talk to me ... I know my cyber. Okay, then I'll ask you all the questions.
Yeah, I- Okay, good ... yeah, you, I'm happy to answer them. Right.
But look, we could talk about what's going on with AI and cyber and Mythos and how this is changing the role of cyber, right? So many of my friends in cyber spent their career finding vulnerabilities. Right.
P**f. We're not worried about finding- But is that what they should... But again, see, that's interesting to me because like, is that where they should spend their time, or should they spend their time thinking about the much bigger holes that are coming up with the- Well, now we're forced to do that.
I'm heading actually, I'll be in Vegas August 3rd to 6th for Black Hat. Okay. Which is the big, or the second- Yeah ...
biggest cybersecurity show in the world. And, it's to, I will tell you, already speaking to my friends and doing interviews and stuff, it's top of mind with people. Mm-hmm.
But here's the interesting thing Fixing vulnerabilities isn't the security guy's poll. That's platform engineer, SREs, ops folks. But you know this, no security is 100% bug-free.
It's impossible- No ... to do that, and CVEs are a way of life. And to me, if AI can help both identify them faster and fix them, then does it allow us to think about something bigger, like- It's a question of governance and scale.
We can't fix them. Right. So Margaret, I'll tell you a quick story because we've got to go.
Okay. Started a company called Still Secure in 2001. 2003, we saw the same thing you're talking about right now, the vulnerability issue.
Mitch Ashley and I were co-founders of a company with a third friend of ours, came out with a product called VAM, Vulnerability Assessment of Management. Huh. We scanned, and we had a great workflow.
And what we quickly found out is even back then, we found more vulnerabilities than you could fix. So it became a question- Absolutely ... of prioritizing what you can do.
What are you going to get the most bang for your buck? Yep. Let's fast-forward 23 years now.
We're here, 2026. We're in the same boat except 100 X more. Yeah, but I'll tell you, going back to the infrastructure software world or software world in general, is this concept of getting to zero CVE is real, and people are under pressure to do it.
So I think the question's going to be- Did you see Oracle's release this month, their security update? Mm-hmm. Over 500 CVEs in one update.
Yeah, and you've noticed it with Linux. I have a Linux workstation, and it's daily updates now- Yeah ... almost, right?
And maybe that's what we need to do. These are all Mythos, or similar to Mythos, AI related. We can't- Must be time to go because you're throwing your AirPods around.
Yes. No, my AirPod popped. It's telling me it's time.
Okay. We're going to continue this discussion because the security- Yep ... paradox is real.
And actually, I'll be at Black Hat on our next one, so I'll have some good information. I was going to say, that's perfect. And you know where I'm going to be is in India- Cool ...
at an event, meeting with customers. So I'll check out the security vibe there. So that'll be a good- I will report back then ...
fun balance across the world. All right. Hey, Margaret, thank you so much for doing this with me.
I appreciate it. I'm excited about going forward. " You can check it out wherever you like, wherever you watch or listen to your podcasts, Spotify, Apple Podcasts.
It'll also be on Techstrong TV and the Techstrong OTT app if you want to watch it on your TV, Apple, Roku, Amazon, Android, iOS, and Techstrong TV YouTube channel. So- Wow ... if you've got a screen, we got you.
Margaret, we'll see you in a couple of weeks. All right. Take care.
