Techstrong TV Wednesday, April 8, 2026
On today’s Techstrong TV, Alan Shimel broadcasts live from RSAC to expose the new era of AI-powered phishing attacks with Ironscales CEO Eyal Benishti, while Jon Swartz explores how MazeBolt is flipping DDoS defense from reactive to preemptive. Mike Vizard reports from KubeCon Europe on how LocalStack’s high-fidelity sandboxes are giving developers and AI agents a risk-free proving ground. Plus, the Tech Field Day News Rundown breaks down the trillion-dollar AI infrastructure race, and Cloud Field Day 25 rounds out the episode.
Transcript
Hi, everyone. We're back here live at Techstrong TV at RSAC with our continuing coverage here at Moscone West. There's a little bit of a lull.
I think there's a keynote going on there, so there's a lot of people in there. Traffic, I'm sure people heading to sessions or lunch. Let me introduce you to my next guest.
His name is Eyal Benishti. Yeah. Eyal is the CEO of a company called Ironscales.
Eyal, it's great to have you on again. Glad to be here. It's been a while.
Thank you for inviting me. Yeah. Yeah.
It's been a minute. You got to come more often, not just RSA. You should tell them twice a year, you say, huh?
Well, we do these every day. Well, not in person. Yeah.
But we do them virtual, and we do about three to four hours of video a day. Oh, wow. A lot.
Not just myself. Yeah. But we do a lot.
It's been impressive. A lot of video. Eyal, let's start a little bit with you.
I mentioned you're the CEO of Ironscales. Yeah. But give people a sense of kind of what your journey's been like.
So I started a business, I'm founder and CEO, started a business about 12 years ago back in Tel Aviv, with kind of the mission to fix email security. Felt that it was broken. A lot of the stuff that I was kind of reversing and researching was coming via email, so I realized that we really need to find a new, better way on how to kind of make sure that phishing stays outside of the employee mailbox space, and decided to start Ironscales with a mission to make email security much more powerful and much simpler than it used to be.
Took email security from the gateway level down to the mailbox level and said, "Hey, let's stop focusing on the threat. " So build a lot of behavioral models in order to identify emails that maybe are not bad by content. There is nothing necessarily malicious in the file of the link, but the intent is malicious.
Uh-huh. They're trying to lure them do weird stuff like, wire money, pay invoices, do all this kind of fun stuff that the traditional secure email gateways were not able to detect and stop. And pretty much pioneered this kind of new category that at some point Gartner called integrated cloud email security, and now it's part of the email security platform.
New category. Yeah, it's been a fun journey. Absolutely.
So, this is a very familiar pattern that I see with founders. And let me move this thing because I might be cutting off your camera angle. I apologize.
Founders recognize a problem. They recognize a problem, they have that problem. But they realize they're not the only one with that problem.
This is a problem, and it is a problem that needs to be solved. And that's what drives the passion- Mm-hmm ... for founding the company, for doing what they need to do.
And that's obviously what drove your path. But again, I study founders and startups, not as a hobby. I do it for a living here.
That's enough to get the company founded. There's that initial vision, that mission. But over time, things change.
It grows. It morphs. It pivots.
Market fit, all things that come in. As you sit here today and you look back to your original vision, what has changed? What's grown?
What's stayed the same? It's a great question because we are really in a pivotal point where, about a decade after we've started the company, it seems like the threat landscape is shifting again in a dramatic way, and we're- Is that your way of saying AI? Look, we started as a AI company.
Uh-huh. Now generative AI is the new thing. Right.
And agentic AI. These are kind of the new things that are kind of driving cybersecurity and how we think about what it takes in order to keep companies secure. But yeah, look, AI is everywhere.
If you walk on the floor, in not the West, but in the main show, you will see- Yeah ... AI everywhere. Well, you see it here too, believe me.
You can't escape. You can't walk down the street without seeing it on the billboards and the phone books. And it's very easy to say AI, and it's much harder to explain how you implement AI now to really solve a problem and not just try and kind of wrap something with some nice shiny buzzwords and- Mm-hmm ...
features. So yeah, AI was always kind of in the core of what we are doing and how we are tackling the issue because it is a powerful tool, and I call it a tool because I truly believe that it's a tool. It's not a solution.
It's not a solution. Right. Yeah.
It's not bulletproof. It's not a silver bullet to any of the problems that we are trying to solve. But it's important.
It's there. Again, it's a super powerful technical control. It's not replacing the need to take care of the human kind of element inside the organization at all.
Humans are still part of the solution, the way we saw it, and we still see it at Ironscales. So we want to make sure that we are leveraging this tool in order to help solving the technical and non-technical pain points and challenges that organizations are experiencing these days. I love it.
Now, before we go to this survey and research that you had done, Ironscales, what's the website? com. com.
Yeah. com. Okay.
You guys recently had aA report out based on some survey data and research you had hired a company to do with. Give us an idea, first of all, why did you do it? 0 era, okay?
From the gateway and secure email gateways to the mailbox and advanced AI and behavioral models in order to stop phishing. 0. And we really wanted to run the survey to see, again, to validate a lot of the things that we are seeing.
0. 0, it's this new type of phishing that is multimodal. It's highly contextualized.
It's happening over different channels of digital communication for businesses. It's not just an email problem- Sure ... anymore.
0, again, it's a much, much bigger problem than just email phishing. So we ran the survey because we want to see how different organization, how they think about it. Are they suffering any damage or loss because we don't want to go and solve a problem that doesn't exist, or it's not a big enough problem for our customers.
So we sponsor this research in order to get some more information. I love it. I always like to say every report always has three key things.
Tell me the three key things that you see in this, that came out in this one. I think that the three key things is first, that the problem is real. Like in organizations, they are experiencing, the loss is significant, and I think the most important thing, they're willing to do something about it.
So more than 17% of them were openly saying, "Yes, we are actively reconsidering and re-strategizing our security strategy, our kind of tools and stack that we currently have in place because we understand that all this fun stuff like deep fake and agentic AI kind of powered phishing is happening. " Excellent. There's always something in every report, though, that you didn't have on your bingo card.
Right? It would surprise you. It didn't seem that that was going to be what it was.
Anything in here that would surprise you? I think that the fact that about 88% of them have said that they've experienced some trust, kind of a trust issue in their environment. Like trust was broken in one way or another over business kind of communication.
That really took me back a little bit because we knew that- That's a crazy 80, over 80, that's critical mass. Everyone. Honestly, I didn't think that the number will be that high.
No. If I had to guess, it was something in the 30s. So that's the one thing that I wasn't expecting to see out of this survey.
I love it. Where can people get the report? com, but- It's on our website.
First page? Yeah. Come to the website, and you will be able to download the full report.
It's a very interesting report. So we all think AI is important. It's changing things.
As you said, you were doing AI, ML, and all of that. Now agentic and- Yeah ... generative.
But you come here to this conference, and it's all about AI this year and agentic AI. How does that make you feel? Vindicated, like, "Yeah, we're right.
" I think we need to, again, we need to be careful when we are kind of trying to say AI or throw AI on everything. Let's really try and understand again, what's the real attack surface? What really changed in the way that threat actors are basically launching their attacks?
What's the right approach? " I think when you look at where we started, we knew that threat actors are using AI to attack organizations. That's nothing new.
And we use AI in order to stop these type of attacks. Now we are stepping into a new kind of situation where threat actors are using agentic AI, which is autonomous agents that can just go and do some stuff from collecting information, weaponizing this information, do the entire ideation phase and execution, and it's really mind-blowing, like what agentic AI. And we're just starting.
We're just sketching the surface. You're preaching to the choir. I use it myself, and it's like addicting already.
It is. Because it sucks you in. You just, where does the time go?
You gotta run. But wait, it's just almost finished working, right? Exactly.
That's what we do. And it's powerful, and it's- Yes, it is ... getting cheaper and cheaper, by the way.
Yes. A lot of it is open source and accessible- Yes, it is ... for everyone.
But you do have to be careful with the open source because look, these are non-deterministic agents that learn. And so from a security point of view, sometimes the open source stuff, right, you got to do a little research on what's the best way to lock that down. But think about the attackers, not the defenders.
They don't need to be successful 100%, so they can use the cheaper- No, they could be one out of ten, one out of 100. They're making out money like mad. Exactly.
So there is always this asymmetric kind of situation where they can use cheaper kind of models in order to attack us, but we need to use the more expensive models in order to defend. But that's the- But that's the nature of this ... that's the nature.
I agree. It's not going to- I agree. That's the one thing that will never change no matter what type of technology is going to be introduced next year.
I agree. We got the report. It's on the first page.
So when are we going to see you again? Before next year, I hope. I hope so.
I'm going to hold you to that, okay? All right. Absolutely.
Thank you very much. com. Go check them out.
Check out this report, too. There's some interesting information there. As we said, some of it to be expected, but some of it's surprising.
We're going to take a break. I think we've got maybe a half-hour break in the program. We'll be back, though.
We've got full day of coverage today, tomorrow, the day after that. We're live at RSAC. I'm Alan Shimel.
Hey, everybody. We're back at Amsterdam, and we're here at the KubeCon + CloudNativeCon Europe Conference, and I'm talking to my friend Valdemar here about a new version of LocalStack that's out. And LocalStack is basically a local replica of an AWS environment for developers.
Valdemar, welcome to the show. Thanks for having me. It's good to be here.
So what's new in the latest release, in the latest update, and what can I do today that I couldn't do two days ago? Yeah. So we had some exciting changes that we pushed out yesterday.
So we basically unified our community offering and our paid offering into a single unified experience. So previously we had an open source repo that was on GitHub, and we built an image there, and then there was a separate experience for our paid customers and the paid offering. And we decided we want to unify these two into a unified version.
We also provide a free tier with pretty generous for non-commercial use. And you actually get more functionality and more features also than what you got previously in the free version. So that's kind of new.
We are generally always evolving and implementing new features in the emulator of course. There's been some exciting developments. We have AWS as our flagship product, but we also recently launched a Snowflake product about a year ago.
And we are about to launch also Azure in the next couple of months. That's currently on a private preview. Cool.
How do you keep those things in sync? Because the AWS cloud environments are constantly changing, so how does that kind of stay even with what's happening on the local desktop of the developer? That's, yeah, a great point.
So we build a lot of automation and internal tooling to keep up with the pace of change at the cloud providers. So that starts from, for example, scraping all the API specifications. Those are public, and then we can see whenever there's a change in the APIs, we can start implementing the change on our side.
And we built some pretty sophisticated just testing validation mechanisms that make sure that we maximize the parity, as we call it, the fidelity of the emulation of what we're building. But yeah, I'm not going to lie, it's a catch-up game, and it keeps us busy for sure. Yeah.
So who wakes up in the morning and decides that this is their problem? And I'm asking the question because forever, we've always heard the phrase, "Well, it worked on my machine," but it didn't work on the server or in the production or in the cloud environment. Right.
Who takes ownership of making sure that whatever gets built locally can actually run on the runtime? Yeah. So this is really sort of what our kind of bread and butter is.
So we have an internal prioritization mechanism. Of course, any larger customers that we work with, we know well in advance which kind of services, which kind of workloads they're running, so we can more proactively make sure that everything works. And then when it comes to more the broader community adoption, we just have a backlog of feature requests that we just work through in general.
But yeah, this is really this high-fidelity environment that we offer is really sort of the value proposition of what we bring to the table as a company. " Yeah. Or is it a DevOps team that kind of sits up on top of this whole workflow and says, "We need to give these guys a better experience locally so that we're not having the same conversation over and over again"?
Exactly. So we're working more and more with these DevOps or platform engineering teams that are basically rolling out developer experience for the entire organization. And typically, it's something like you have a make script or something that stands up your local dev environment, and they are the ones that are kind of standardizing it across the org, right?
And we're working with these platform engineering teams to make sure that they have a consistent experience across all the devs in the organization. There's also some insights and telemetry that they receive, if they use our paid offering to see which kind of services are being used and how many instances are basically running. But yeah, it's all about having a central entity, either a cloud center of excellence or a platform engineering team typically that we work with.
Mm-hmm. We, of course, live in the age of AI now, and you can't walk down the aisle here without somebody leaping out to tell you about their great new AI thing. How do you envision AI playing out in this world?
Because I see AWS is playing around with AI and will you create this complementary set of agents or how does that work in your mind? Yeah. So the whole AI acceleration is actually something that plays very much in our favor.
We did not plan for that when we first built LocalStack, but now the whole industry is talking about sandboxes and how you want to make sure to have a risk-free environment that these agents can operate in. And LocalStack is the ultimate sandbox environment in that sense. So what we started doing is we built, for example, an MCP server integration that makes it very easy for these agents to talk to LocalStack, do a lot of the testing.
And it just accelerates the feedback cycles also for agents. So there's a couple of comparisons that we have on our website. It takes maybe 15 minutes to spin up an RDS database cluster on AWS, minutes, and it's, like, five seconds on LocalStack, right?
So those are the kind of side-by-side comparisons, and those are from compounding effects. The more you test and the more agents you run in parallel. The other thing we hear a lot about these days is digital sovereignty, and it's no secret that a lot of developers work in one country, and they work for companies in another country.
Mm-hmm. Is this mechanism that you have kind of giving me a way to hire developers anywhere in the world and give them local instances so that I'm compliant, but when the actual thing that I want to run, I might want to run somewhere else? 100%, yeah.
This is something we see a lot that, if you have a global workforce and you might have different local, regional jurisdictions or different legal systems. So yes, we're kind of democratizing that in a sense, giving you more on-premise or local execution environments before you hit the real production. And this whole topic of sovereign cloud has come up a lot at this event also.
I think in Europe specifically, it's a big topic, presumably also in other parts of the world. So it will be interesting to see where that goes in terms of, is Europe going to create their own cloud at some point, or is it more like a region of AWS or some of the big cloud providers? But it certainly, again, is very much in the same narrative that we also play.
It's decentralized with more test, shift left, test more at the edges or at the end consumer. So interesting trend also that plays in our favor in a sense. " Yeah.
I think we definitely have a set of best practices how to ideally set up Localstack and get the best value out of the tool. For us, a lot of it is just educating the market for some of the more advanced features that we're offering because the foundation of what we do is these emulators that give you this local cloud environment, but we're also building a lot of what we call DevX features, things that sit on top of the emulator and give you additional developer value for debugging your stack or doing certain experiments. We have a feature that we call Chaos Engineering, for example, where you can inject errors or latencies into these APIs and test for resiliency.
So it's mostly about educating the market of what's already possible with the solution today that goes beyond the pure emulation part. Are you seeing a shift towards platform engineering as kind of a larger trend? And what does that platform engineering team look like compared to, say, a traditional DevOps team or even a loosely affiliated set of developers?
Yes. So surely, the term IDP, internal developer platform, is something we hear a lot from customers. There is some off-the-shelf IDPs that are being used, but also increasingly teams building bespoke solutions within the organization, within the enterprise.
And almost every large org we work with has some kind of a DevX team or a platform engineering team that is following, if it's a regulated environment, for example, banking, insurance, they might need to follow certain internal rules or laws. So yeah, it's very much sort of a core offering, and then you have these satellite integrations that are usually making it more seamless to integrate it into a certain organization. Yeah.
How much development is still happening on a local laptop versus when there was a push for a while there to kind of push all the developers into these cloud services. Mm-hmm. But it seems the developers kind of like holding onto their machines.
Exactly, yeah, because if you have your IDE set up there, you can set break points, and you'll have deep inspection of your stack. I think maybe also with agents now, this idea of these cloud development environments is coming back a little bit more because when you shut down your laptop, then the agent dies. You want to make sure that you have some consistently running instance in the cloud.
The nice thing about Localstack is it's a very portable environment. You can bring this on your local machine. It's in a CI/CD pipeline.
It can be in a cloud development environment. So it doesn't really restrict us in terms of where it runs. It's more we're alongside wherever your code runs or your agent runs, really.
Or is the developer just going to wind up with two machines, one for them and one for the AI agent that runs a couple of tasks and then ships it over to them? Yeah. And I think we've seen those with things like Cloud Code, sorry.
Was it... Yeah, Cloud- OpenCloud, I think. OpenCloud, exactly.
Yeah. To kind of using some of the Mac Mini that's maybe in your home environment and just spinning those up and having this agent run there. So I think it's kind of a bit of a resurrection for compute that is just up and running all the time, and you have things running that are reacting to events or doing work on your behalf.
Yeah. At least we're all talking about the fact that in the age of AI, the pace of application development should accelerate considerably. Mm-hmm.
" My personal view is it's probably the latter, so we need to fundamentally rethink software engineering best practices in general. So what we're already seeing today is a certain review bottleneck. So a lot of code is being generated by these agents, and it's still predominantly humans who need to now review that code, have a conversation with the agent, something not working, and so on.
So I think just everything that's been built over the last decades around human-centric engineering, I think will have to adapt to a certain degree. And I think the other interesting area is code generation is kind of growing at an exponential rate effectively. There's just so much code that's being generated, also sloppy code in some cases.
But the actual code that makes it into production is not growing at the same pace, let's say. So there's a big sort of gap, which we call the testing and validation gap. We need to give these agents an environment to test and rinse and repeat in terms of the logic and have also strong quality gates in place.
So I think over time, it's going to be less maybe about the actual code logic. It's more about making sure that you have guardrails and quality gates that really define the outcome that you want to achieve with the application effectively. So how do you envision this playing out?
Will there be... Each developer's likely to have multiple AI agents that they're using to build. Mm-hmm.
There's probably going to be-Autonomous AI agents on the back end somewhere on the CI/CD that's managing certain tasks on behalf of a bunch of developers. Mm-hmm. How will all that get orchestrated?
Not to mention all the agents that might be sitting up in the cloud. How are we going to manage that so these agents coordinate? Coordinate, yeah.
So there is already some level of, for example, this new paradigm of spec-driven development, which is something that's now emerging. So there's already a certain specialization happening that you have agents that are a bit more like a PM, like a product manager, and then there's another agent that's a bit more like a software architect, and there's another agent that's more like a senior or junior developer. So we're starting to see some specializations already in the planning and execution phase of how software is being built by agents.
The other interesting trend is kind of adversarial situations where you have one agent maybe generating code, another reviewing, and they kind of critique each other, essentially. Or the most advanced use case will be like you have a fully multi-agentic use case where everybody's trying to achieve the same goal, and then you have a weighting function and the best solution just wins in the end. So I think those are the kind of scenarios we're probably going to see more in the future, I guess.
Will these agents argue with each other then at some point, just like humans do about certain things? And how will we decide to resolve that? And what's going to be the language that they talk to each other, right?
Is it going to be English? Yeah. Yeah.
I mean, definitely interesting times. I think we're going to see much more in 2026, 2027. So it seems like the industry is in almost like a pivotal moment right now with figuring out this next wave of developments.
And as you said, a lot of the booths here are about AI agents, so interesting times for sure. So let's pretend that you have been made king of all things IT for a day. What's that one thing you would fix by decree if you could?
King of IT. So I would focus on efficient utilization of my resources, so making sure that there's no waste and no idle resources that are not being used. So that's the first part.
And when it comes to application development, it would be focus on the guardrails. Really, in order to accelerate things, you still want to keep the quality in place, so testing and test quality and coverage become even more critical than in the past. So yeah, those would be the two points, resource efficiency and guardrails.
And we talk about things like FinOps out there, but it seems to me like developers aren't inherently wasteful, but they don't have a lot of visibility into how much infrastructure is being consumed and what it costs. So- Mm ... is that something you can provide using your platform?
Because I don't think they understand how much it might cost to run something that they're building on their local platform. Yeah, 100%. So I think Werner Vogels from AWS mentioned that every engineering decision is a buying decision, right?
Because as a cloud developer, if you choose to go with one service or the other, you implement it in your code, but it has a direct cost implication in terms of how much your organization is paying for it. So yes, 100%. The one part is having a rigorous process, especially for dev and staging environments, to keep those effective and efficient and not creating unnecessary costs with our solution, for example, but also if you test in the cloud directly.
And then, of course, in production, there's all kind of FinOps optimizations that you can apply for auto-scaling and other techniques. But for the part that we focus on, it's really anything that's pre-production. And there's a lot that you can optimize and automate by going more onto your machines, more local and local testing.
To your second point, there's always not been a whole lot of love between the security people and the application development folks. Are there things that we can do on the local machine to reduce that friction so that I can maybe, I don't know, have a set of best practices that are running locally so at least everybody has the same experience? 100%.
Just from an onboarding perspective of a new engineer with a solution like ours, there's no need for cloud credentials or giving them access to the kingdoms in a sense. It's just getting started, up and running real quick. The model that Localstack provides and offers locally is even that you can test your applications and develop them even without IM or security built in.
So we have a way to enforce IM locally in Localstack, but you can also turn it off, switch it off. If you're just interested in the functional piece and you just want to develop your app, you don't care about the security piece, and then you can maybe do that at a later point in time. That's also feasible and possible with Localstack.
But yeah, to your point, I think security teams will be happy because they don't have to distribute credentials to everybody and do key rotation and whatnot. Don't have to take care of cleanup scripts that are running every night and clean up unused resources. So it's just a fundamentally different way of thinking about resources and development.
Yeah. All right, folks. You heard it here.
Well, it turns out laptops and the cloud can live together after all in harmony. Hey, thanks for coming by. Thanks so much for having me.
All right. We'll be back in a bit. Hi, I'm John Swartz.
I'm back at RSAC in San Francisco at Moscone South. It's day one, and we hope you're off to a good start here. We're here with Matthew Andriani, who's the CEO of Maze...
How do you pronounce that? MazeBolt? MazeBolt.
MazeBolt. And Matthew, I'm going to ask you to take the floor and tell me a little bit about MazeBolt. I had a bunch of questions I want to ask you.
But first, let's lay a groundwork so our audience has a better understanding of what your company does. Thank you, John. We are in the DDoS space with Akamai, Imperva, Amazon, Cloudflare, all of these mitigation players.
We don't do what they do. We augment those systems. They've got good protection that's deployed at various enterprise organizations.
What we do is we find out how attackers are able to penetrate all of those layers of protection all the time. Mm. So that's what MazeBolt does.
So you kind of enhance what those other companies do as kind of an additive. Correct. Typically, what we see as we go in, there's around a 63% automated protection on average.
Using our data of attack simulations ongoing, we can get that to over 98% automated protection. Wow. So, just kind of a sidelight, but it's important to know.
I'm going to ask you a little bit about national cyber warfare and about geopolitical tensions. But you arrived in the US a few weeks ago- Yes ... traveling from Jordan.
Yes. How was that? It was interesting.
I took a taxi from where I live to the southern border in Israel, crossed the border, took another taxi to the hotel. The next morning, took a flight out to Athens, Frankfurt, and then to the US. How long did that journey take?
Left Thursday morning, got to the US, where I wanted to be in Vegas, Saturday night. Oh my God. Yeah.
Well, we're glad you're here, and we're glad you're safe. Yeah. This is kind of a terrifying, not a kind of, it is a terrifying era we live in right now, and I'm imagining, given what's going on in the world and given the advances in AI, that we have this evolving landscape of DDoS attacks.
There must be some sort of strategies that enterprises are using to stay resilient. Could you maybe explain what they're doing to keep themselves defensed? First of all, you're right.
The current landscape, even before the explosion of AI, was already a very high threat, where enterprises were deploying defenses with many layers of defense. What they are trying to do now is close those gaps before an attack comes and try and preempt. I think this is a theme across not just DDoS.
This is a theme across the industry. So before, just to be clear, it was kind of a reaction- Correct ... reactionary approach.
Now it's a preemptive defense approach. I think in general, across the cyber realm, right- Mm ... people that are responsible, CISOs that are responsible for the organizations or government, they're trying to figure out, "Okay, we've got all these defenses in place.
" But your existing defenses need to be working. Mm-hmm. I think there's a huge focus in this area.
We focus in this area in DDoS. It's interesting because I've worked with a number of folks who are security experts. Right.
They started companies, Alan and Mitchell, Still Secure, and they always talk about this kind of concept of security where traditionally, maybe until now- Right ... it was more of a kind of an evolutionary industry or technology versus the revolutionary things that are happening around it. So for instance, as cloud came along, or as AI, they are quantum leaps in terms of how technology is used.
" And that you're kind of telling me in a sense that that attitude or that posture among CISOs and others is changing. I think you're right. The industry's evolving very quickly, and the technologies are evolving very quickly.
If you're not getting ahead of it and figuring out how to prevent damage, you're going to have the damage. And I think visibility is critical, and figuring out how you protect your particular organization is critical across the spectrum, whether it's from the external, internal, lateral movement, whatever you're trying to protect. So, that brings me, in a sense, again, back to AI in that we get a lot of surveys, we write about a lot of surveys, a lot of studies.
And what we consistently see is that there is a pressure from the top down- Right ... to adopt AI as quickly as possible, maybe with not as much stringent governance or upskilling among employees, safeguards, guardrails, whatever you want to call them. And that has created a tension or created a very difficult situation for the CISOs because they're under pressure to put these systems in place, like agents for instance, but they're also responsible for the consequences if something were to go awry.
So I'm wondering how the CISOs are kind of reconciling the pressure from the top down to adopt AI, yet still maintain safe and secure operations. So I think AI is a huge topic. CISOs are under pressure.
Some CISOs tried to block AI at the beginning. That lasted a few days or a couple of weeks at the maximum, I realize. I mean, were there CISOs who got forced out if they were too slow, or was this a- I don't know of any, but I think the internal pressure was very quick.
I think what you've seen is the smart organizations are looking at what they've got in the whole AI space, providing kind of a singular offering to the various departments, scaling down the amount of AI tools, but still letting people fluidly work. I think that any company that isn't using AI is going to just fall far behind. They're not going to be around.
They don't have a choice, right? Yeah. They're not going to be around, and I think everyone recognizes that the speed is incredible.
When you get to the attack side-If you just use ChatGPT, you can see the speed that you're getting answers now. If you just apply that in a very limited fashion to just orchestrating attacks against organizations, you can imagine the speed that that's moving at. Any manual process that you rely on in an organization with an AI orchestrated attack, you don't stand a chance.
Which brings us back to what we do in our company. We provide that data prior for those defensive systems to be immunized prior to that attack ever arriving, because any type of reaction with a human element in it is slowly going to become redundant. And when I say slowly, I think over the next 18 months maximum.
If you could go a little bit deeper into some of the products you have and what they do and how they work in concert with some of the companies you mentioned earlier. Are there a couple that you could just highlight just for those who are unfamiliar with the- Sure. So at the core of what our technology does is we are a company that figured out how to simulate non-disruptive DDoS attacks against production systems.
That's the core patented technology that we developed over many years. It was released in 2021. So if you've got hundreds or thousands of services, we're launching hundreds of attack simulations validating how your defenses work through actual data.
So you're kind of testing, but in a non-threatening way. " So we give exact telemetry on every single layer of defense you've got, and we operate on big data sets, so we're launching thousands of simulations over a month's period. And with just a few fixes, you can de-risk many thousands of entry points for attackers in an ongoing way because of things like configuration drift in security policies.
We, in 2022, started significant research in AI because we generate what's referred to as unique data in the AI industry. We are now able to find, with a limited amount of knowledge on the targets that we see in an environment, point our simulator there, knowing where those vulnerabilities are likely going to be, and get that data as quickly as possible to the vendor responsible for that particular layer of security, so that when the customer's attacked, you prevent this initial damage or extended damage. Was your background always in cybersecurity or were you- Yes.
I'm always wondering what led you to... I'm assuming you co-founded this company? Yes.
What led you to co-found this? You saw immediate need, or you'd come across some examples of kind of high profile incidents, or...? So I was very involved in forming the team in Radware in 2011.
That was a research team that we scaled to an emergency response team that I was essentially dealing with real-time attacks against large organizations, like the New York Stock Exchange, Hong Kong Stock Exchange- Oh, God. Yeah ... Vatican, all the banks in the US doing large operations, coming up with solutions in real time to mitigate those threats.
And I then started a services company, seeing that every one of those attacks that I saw that caused extensive damage sometimes, sometimes for months, could have been prevented relatively easily. Mm-hmm. And when you look at these large organizations that had seemingly endless budgets, what they didn't have was the knowledge of how those systems are bypassed.
So we started actually as a cyber services company, and through need, transitioned to a product company in 2021. So I'm assuming that business is probably booming for you. Yes.
Or you're getting more inquiries than ever, because I'm thinking about this classic scenario of people employing AI agents. I even read that Mark Zuckerberg is going to have his own chief of staff AI agents. Right.
With access to his ideas and his information. And I'm just wondering, that must be setting off alarm bells in a lot of these sectors, where the bad guys, they're making as much use of AI agents as the white hats are. Right.
But there must be a palpable sense of anxiety, I think, within enterprises, especially when, as agents, of course, begin to be adopted at these companies. Yeah. First of all, yes.
And depending on what you're responsible for, if you're responsible for hosting the agent infrastructure, you've got an entirely new threat to deal with in terms of even how you inspect your traffic, right? Agents are completely- Yeah ... new traffic.
They're not traditional web traffic or API traffic that you were used to in the past. This is different traffic. And I think that protecting these agents is going to become very complex because they're very dynamic.
They're expanding and contracting. Can I ask you really quickly? So conceivably, we're going to have security AI agents- Yes ...
that defend against AI agents that are malicious. So could we conceivably have AI agent versus AI agent duels between good and nefarious purposes and good purposes, or? I think in the enterprise space, you're going to see definitely orchestration agents operating.
We've already got it in companies. We're actually going to release later this quarter a very significant AI capability, which I can't get into too much yet. But it's going to be something that is going to validate a lot of these types of protections because we understand that very, very quickly, and we're already getting some information from vendors and customers we're working with, that AI is going to be orchestrating a significant amount of attacks.
In that vein, do you expect a fair number of announcements at RSACAlong those lines, like AI agent defense systems of sorts that are brought out by companies. They're going to have some sort of platform or architecture to address this special problem you're talking about, or? I think there's going to be companies dealing with many areas of it.
You say AI agents, but obviously AI is a large area. Or autonomous. LLM poisoning, finding out, for instance, all of the models that you use in AI, how contaminated are these models?
Where do they come from? Yeah. They might be open source.
What's in those models? Who made those models? How are they leaning?
There's models made in China, models made in America. What's inside those models? How do you isolate those models in an environment to make sure that you're not going to damage your environment, and have unnecessary leakage?
For instance, what we're doing in our company, we've got a significant project ongoing now for a couple of years, where we have a significant infrastructure being built, which is actually completed now, that we kind of anonymize all of our PII data before even starting to utilize it in that area, what we deem the non-PII area of our environment. Because you don't know what these LLMs are going to do, even if they're privately hosted, you don't really know. So you need to assume, kind of like in the cloud.
You send data in the cloud, if that data's not encrypted, you don't know where that data's going. It's very similar with an LLM model, whether you're forming it locally or using a local database to maybe query external LLM models like ChatGPT or Claude or whatever it might be. To me, what's stunning or what's kind of troubling is the speed with which these new models are being pumped out.
Right. Conceivably, it seems like every other month, there's a new model from Claude. There's a new Claude model or GPT or what have you, and there's a lot more use of open source.
So there's speed with which things are moving and advancing- Right ... makes this a particularly difficult time to defend your operations. I think it also opens up a lot of opportunity because, for instance, companies like us, again, we generate a lot of proprietary data or vulnerability data on environments across the spectrum.
We've got millions of data points. Which allows us to leverage this to better protect our customers. And the AI allows us to get big data sets much quicker, to be able to deliver to the vend in a more organized fashion, to eliminate the most amount of vulnerability in the attack surface as possible.
So it does bring a lot of opportunity, but you have to have, at least as a vendor, you have to take into account what you're doing with the AI, what the threats are, make sure that everything is QA'ed between results automatically. Mm-hmm. AI kind of checking AI, QA'ing the AI, so that it's reliable for your customers.
I think it won't be an accident. I'm not sure if you share the names of some of your customers, but if you don't, I'm wondering what sectors are they primarily come from, and what, if any, are their particular concerns? We're in the 87th percentile plus in the BFSI industry, so banks, insurance companies- Mm-hmm ...
trading platforms, payment processors- Got it ... credit card. Government also, large e-commerce, but we primarily focus on the BFSI industry.
Okay. And they're concerned about infrastructure uptime, service uptime, banking continuing, no disruption to banking services, transactions. There's a high volume of transactions happening in these environments.
You can't have downtime. I was thinking about the landscape. In terms of the infrastructure, there's this big movement in the infrastructure towards faster, more use of data, AI, and I'm thinking about the landscape.
We have these geopolitical tensions that you've experienced firsthand. We've got open CLAU phenomenon, which it's hitting executives within companies like Meta. There was an incident recently there.
These increasingly sophisticated AI attacks. There's a lot to digest, and I'm wondering, do you foresee more kind of geopolitically motivated attacks or even national cyber warfare? We talked a little bit about this before we started filming, but I'm wondering if you mentioned DDoS involving drones and others.
Can you maybe go over that a little bit again? Sure. So DDoS is used extensively in cyber warfare.
We saw it in Georgia. We saw it in Ukraine, Iran. You see it all over the place.
When you want to cripple infrastructure, cut communications, DDoS is a great attack tool to cause chaos. You also see DoS attacks more accurately, not DDoS attacks, for jamming drones. If you look technically speaking, this is an actual DoS attack against the receptor on a drone, and this is what- Got it ...
stops communication and drops the drone. So this is utilized in- Have you seen instances of that in the conflict in the Middle East now? Or it's probably existed, but are you starting to see an escalation of that or maybe even infrastructure?
I'm not an expert in drone warfare, but you can see that there's a lot of activity in the area. You can see recently that the Americans even asked Ukraine for assistance in this area, so. Yeah.
Definitely, I was recently in Texas in a very prestigious research institute that does a lot of research for the DoD, andThey shared some very interesting findings on what's going on with drone warfare. And what was very interesting is how much DDoS attack is being used in that warfare. So definitely it's being used.
Wow. That's a little something to ponder. I mean, can I just ask you, how do organizations anticipate sudden surges in disruptions in their infrastructure?
I mean, you're helping them, but are there other means that they use to kind of anticipate things before they happen? I mean, I don't know much about your field or is this something that is especially used, I would assume, in banking, in governments, finance? Of course, the main thing any organization will do is try and have a solid architecture in their deployment and make sure that it's redundant and all these traditional concepts.
I think what they're also trying to do is secure the application layer very heavily, too. Right. So we're very focused on the application layer.
Services are all over the place. They're in the cloud, they're in DC, they're in multiple clouds. So I think organizations are trying to first get a grip on the attack surface, figure out how to protect that attack surface as best they can, and have the redundancy to scale, but without the protection, no matter how much scalability you've got, you'll- This is like a high wire act.
I mean, in a sense, there's so much going on there. The upside is incredible. Right.
And we should probably point out that the upside, for the most part, is what these companies are looking at, in terms of efficiency, profitability, et cetera. But there's always that kind of a threat lingering in the background that they have to be aware of. You can see organizations that get hit with a cyber attack that makes headlines.
You can see the immediate market cap effect, which can take- And we're seeing more of those ... 12 plus 24 months- Yeah ... and sometimes never get back to the position that they were at.
So there is that imminent threat. I mean, it's not a threat for everyone. It's not going to happen to every company, but for each company that this does happen to, it sets an entire industry kind of on alarm.
Right. And I think this is going to be a story we're going to see repeatedly over and over again. You always just wonder when it's going to reach a point where there is the defining events, and I'm not sure if we've reached that event yet.
I agree. I don't think we've reached an event that says there has to be some fundamental policy- Right ... change or something like that.
And bit of good luck to that happening. Maybe, by the way, in cyber warfare, that has happened because there's a lot of very quick targeting of targets on the ground- Yeah ... utilizing AI and stuff like that, but that's, of course, not in the headlines.
Yeah, exactly. So I think AI has had a tremendous impact on warfare in general, just the speed at which everything is moving. It's in warfare.
And it's only going to get quicker. Yeah. And of course, that translates into the enterprise space.
We see it already that there are AI attacks being identified and the EU Council is doing testing on AI attacks, and other governments are checking how they're going to respond to this. So this is clear that this is happening now. Right.
It's not the future. It's happening now. Right.
It's interesting. Well, Matthew, this was a fascinating discussion. I'm glad you shared your expertise with us and let us know what's going on because things are changing faster than we could ever imagine.
And it's going to make for very interesting times. I mean, I've never seen anything in the tech industry like what's happening with AI and especially on this side of things. Right.
So, thanks again for your time. Thank you, John. It was nice meeting you.
Good to meet you. And we'll be back with more interviews later today, day one of RSAC. The Futurum Group's research team has recently released their latest Decision Maker Survey focused on enterprise AI platforms, offering actionable insights for leaders.
This episode of "Utilizing AI" focuses on this report with the lead, Nick Patience, as well as Jon Swartz, and I asking questions about what is it that defines power users and how are they using AI in 2026? Welcome to "Utilizing AI," the podcast focused on practical applications of artificial intelligence from the Futurum Group. Every Wednesday, we explore news and use cases of the ways in which AI is transforming enterprise IT and the industries it serves.
I'm your host, Steven Foskett, President of the Tech Field Day business unit here at the Futurum Group. Before we dive into our discussion, let's meet who's on the panel today. Hi, I'm Nick Patience.
I'm the AI Platforms Practice Lead here at Futurum Research. And I'm Jon Swartz. I'm with Techstrong Group, which is part of the Futurum Group.
I'm based in the Bay Area, and I cover AI. Excellent. And as I said, I'm Steven Foskett from the Tech Field Day side of things.
Well, today, we are going to dive into something pretty incredible. One of the best parts of being part of the Futurum Group is that you get to work with folks like Nick and Jon all the time. But of course, the research team here at Futurum has been working very hard to produce research reports, and among those is a very recent report focused on actionable insights.
Essentially, what should companies, what should end user IT organizations be doing in 2026 when it comes to AI? And of course, that's the whole ball game, isn't it? That's what everybody's asking.
That's what everybody wants to know. Nick, I'm going to start with you on this one. Tell us a little bit more about the research and the report.
Sure. Thanks, Steven. So yeah, every practice here at Futurum does two surveys a year, and so my practice, AI platform's no exception.
So this is the latest AI decision maker survey, as we call it. We surveyed 820 senior decision makers across nine industries and six regions. And we asked them about their AI maturity, their model strategies, and where they're headed on the most, I guess, the topic du jour of agentic AI.
And so, the kind of overall findings is that AI is maturing, but it probably won't surprise anybody to understand it's maturing unevenly. And so, the gaps between leaders and laggards, or what we call ahead and behind organizations in this report, kind of center on things like the number of models they use, where they see themselves in the agentic landscape, the leadership structure, and who makes the decisions, how they measure success. And those kind of dimensions kind of color everything that we've found so far.
It's an interesting report, Nick. There are a couple of things that jumped out at me. There are a lot of things that jumped out at me, and I wanted to kind of start with one of your conclusions or one of the things you found was that some of these companies that you were talking to are averaging nearly four models per organization.
So what I wanted to ask you, and I think what might be going on within these organizations, are we actually picking best of breed for specific tasks? Are we just suffering from shadow AI sprawl that we haven't consolidated yet? 8 models.
So I think, yeah, four, as you say. 3% of the sample, so there's a lot of fragmentation. So yeah, if you're a model provider and you're thinking that your model gives you lock-in, then you're probably barking up the wrong tree.
As to why they're doing it, I think it is a combination of the shadow AI effect, and to a certain extent, specialization, but they're not looking at 25 models or anything like that. So yeah, they are consolidating around some of the kind of big beasts as we expect, like OpenAI, including OpenAI Direct and OpenAI via Azure and Gemini and Anthropic and then open source models, and some small language models and specialist models as well in various areas of multimedia. The multi-model strategy is very much the norm here, I think, really.
Yeah. I was going to say, your timing. Timing is everything with reports, and I think your timing is pretty exquisite here because I think Microsoft just recently announced a multi-model critique feature for Copilot Researcher that has GPT and Claude working together simultaneously.
Right. Yeah, that makes sense. So I guess it's acknowledging the reality of the market.
If I can jump in here on a bit of a clarification, I just want to make sure that the audience is aware. So there's two things that sound very similar. There's multi-model and there's multimodal .
And so I want to make sure that we're clear. Multimodal is also getting a lot of attention, which is essentially other types of media, multimedia, essentially, audio, video, et cetera. Multi-model is this idea, which as Nick says, our report shows and also is very much my own feeling, that people are using multiple AI models, multiple engines to process data according to various needs.
When do people choose different models and why, Nick? I think they sometimes obviously are going to have models thrust upon them if they're working for large corporations where their environments are locked down. I think if we look at some of the companies that look at some of the smaller language models, those tend to be power users in a sense.
3 for those that didn't use small language models. So these are kind of power users. So you can imagine these are ones that have moved beyond the use of generic LLMs and are doing some sort of distillation or fine-tuning or something to solve specific problems.
And a third of edge deployers use small language models, as you'd understand. So, that's one lens as to why they use it. I think the others are just market dominance of OpenAI at the moment, and via Direct and via Azure, and then the fast-growing Anthropic.
And Anthropic, actually, interestingly, one thing I should say for framing is we asked organizations to put themselves into one of five maturity stages from really just purely experimenting and doing research to those that claim some sort of agentic use case being reasonably broad. And Anthropic's use was pretty the same across all of those. So, you could argue if you're Anthropic, that means we are multipurpose and suits all kinds of use cases versus some of the other models that were much more prevalent amongst those that describe themselves as mature.
Noah, I was going to ask you, dive a little into the leaders versus laggards that you mentioned earlier. So the data shows laggards face the same number of challenges as leaders, but struggle more with legacy systems. So isOur AI strategy a technology project, or is it actually a secret technical debt clearing exercise?
Yeah, that's an interesting point. I think when we looked at what those laggards actually look like, those numbers are pretty consistent. So they use fewer models on average.
They are less sophisticated agentically, if that's a word, and they dedicate a lower percentage of their overall technology budget to AI. They still deploy roughly the same number of use cases, though. So they're not really doing less.
They're doing it with less, I guess. They're kind of getting by. And it's a really interesting correlation.
So we did a lot of analysis of this data, a lot of crosstabs and various correlation exercises. And so, for instance, those laggards, and it kind of goes to your question, John, are struggling with challenges such as workforce adaptation, so getting people to actually use it, and legacy integration. They're both 12 to 13 percentage points ahead of those organizations that consider them...
I'm sorry, 12 to 13 percentage points above those that consider themselves ahead. So what I mean is, they really are struggling with legacy integration and getting people to use AI, and of course, they're dedicating less money to it. So that kind of tells you where some of the barriers are.
As many of us, I think, think there's a lot of challenges in enterprise AI are not necessarily to do with the technology, they are cultural. And I think our survey demonstrates that. And if you flip it around- Yeah, sorry.
Go ahead. Yeah, sure. So if you flip it around to the leaders, those organizations are really defined by breadth.
So they use nearly, basically four models on average. 50% of them, 54% of them describe themselves as deploying agents in some form or another. This is going to be very early still.
44% of them allocate more than 10% of their overall tech budget to AI. And they, at the moment, have a strong cloud-first kind of outlook and tilt. So the gap isn't just about those spending more money.
It's engaging across more models, more environments, and more use cases simultaneously. So I think that's an interesting finding if you're a cloud vendor, but it's also interesting finding if you're not a cloud vendor and you're selling servers and things like that. There's still opportunities out there.
But you have to acknowledge that it's a multi-model and multi-environment world. It's not about one platform. So I have just a quick follow-up.
You'd mentioned the chief AI officer. So given the correlation between the CAIOs and maturity, is the CAIO's primary value in their technical expertise or their ability to break down the silos that typically kill AI ROI? That obviously depends on the organization and the person, doesn't it?
But I think you're onto something with it, and to some extent, I think it's the second of those. So we took all these kind of slivers of what these organizations look like, and we took, what does a stage five transformational leading organization look like? Those that think they're in stage five of maturity.
And they are nearly three times more likely to have a chief AI officer as a primary decision-maker than all the other stages of maturity. And so yeah, I think everybody's different, but I think generally speaking, it's that ability to break down, get across organizations. It's understand where use cases are, than it is necessarily, I've got a PhD in this or a PhD in that.
It's going to be more of a kind of some political skills there, some skills in understanding who can make effective decisions. And we find that it's not necessarily about the larger the company in terms of revenues has this person. It obviously does skew towards large organizations for obvious reasons, but it's not all about that.
So yeah, it's an interesting point, and it's also interesting to think, as I think we may have said before and here on this podcast, is will there be such a chief AI officer in, say, five years' time? I'm not entirely sure there will be. But there's others making key decisions, including CTOs, obviously, and CIOs.
Yeah, that's a really interesting point because, of course, according to the survey, not all companies have a chief AI officer, and in fact, that again matches kind of what we're seeing out there anecdotally talking to these companies. Do you think that it's going to be a situation where in another year, organizations will be uniformly ready to adopt AI and ready to make good decisions around AI? Or do you think that this is going to be a big differentiator, both in terms of the size of the companies, who's leading it, what industry they're in?
Are we going to start seeing a real divergence of companies based on AI capabilities? I personally think we are. I think it's uneven.
There's a jagged edge of this transformation. I think ironically, you see smaller companies, like Futurum's a much smaller company, being able to make great strides very quickly because we don't have large compliance departments and HR and things like that that may place certain barriers in the way. But putting small companies to one side and thinking about those that have chief AI officers, I think you are because I think assuming that person's not just been given that job title to either keep them in the company, otherwise they might leave, which could well be a reason, or just some sort of cosmetic exercise to say, "Here's a tick box.
" Assuming they have authority and they have budget and they haveThat kind of thing. I think it is going to be a differentiator for a few years to come. So who owns that AI strategy, I think, will matter.
And, of course, where they sit literally in the organization. Are they on the board, or are they report to board? Do they report to CEO, IO, TO, FO?
Who do they report to? I think my experience in this market, along with you guys, I'm sure, is it does vary, but it's amazing how many organizations you think would've had somebody in this kind of title, doesn't yet. And it could be in financial services and the kind of organized industries like that, which are normally more progressive- Yeah ...
are still finding their way, really. Yeah. So that's a perfect segue, I think, into what I wanted to ask you about, use cases and deployment.
So there's two things. First is the saturation where we have this baseline use case where we move from simple cost out efficiency to revenue differentiation through software engineering product R&D. How do you move from the simple cost out efficiency to the revenue in differentiation?
And then the second part of the question, I'm sorry it's a long question, what are the white spaces in the industry? Where has AI not been deployed yet, and why is there a barrier? Yeah.
We found in our survey that in terms of use cases, we didn't give them 40 different use cases. There was, I don't know how many, nine or 10. But customer support was near universal.
That was across all stages of maturity. Software engineering, though, had a bigger gap between those that are more mature, using AI for code development. And then we have also found one thing that was slightly unusual was that those that consider themselves behind are over-indexing on a use case like revenue optimization, which suggests a narrower, I would argue, ROI first focus than maybe building broader capabilities.
So I think in terms of the white spaces, I think it's going to be fairly obviously the more complex process-oriented tasks that we haven't got to yet, which are going to be far more complicated than the low-hanging fruit of customer support and, to a certain extent, code generation, which I wouldn't say is a low-hanging fruit necessarily, but it's become such a prevalent differentiator. So this brings me to sort of a question that I think is, I don't know, a major one, and that is if somebody is listening to this, and if somebody is trying to figure out what their AI strategy looks like, how would they recognize what a good strategy is? What does a leading adopter of AI look like in 2026?
What should they be looking at? What should they be adopting? And what are the signs that somebody is really doing a good job with this?
So yeah, it's a good question, Steven. So I guess if you looked at those stage five companies, as I said earlier, they are more than three times more likely to have that chief AI officer, which we've as primary decision-maker. They will be fairly far along in their agentic AI strategy.
Sometimes with these surveys, you kind of wonder, do people really mean that? We had a fairly large percentage saying they're in a kind of orchestration stage of agentic AI, which means multiple agents and orchestration layers across that. So, they had to have made some decision on agentic already.
So, in the stage five, it was literally 0% of them were reported not considering it. So they had already considered it, and were moving ahead. And I think the more-- So not the more models, the better, but looking at small language models, looking at domain-specific models, would also be another characteristic I would highlight.
And this goes across regions. We looked at organizations in Asia-Pacific and EMEA, and in North America as well, and that's kind of reasonably uniform across the board. Can I ask you, Nick, about the Gemini gap?
So the report notes an outsized adoption gap for Gemini among stage five leaders. Mm-hmm. So what specific multimodal or long context capabilities are these stage five leaders finding in Gemini that the rest of the market's missing?
I'm not entirely sure it's multimodal. Okay. It's not entirely clear whether that's it.
I think it just may be a Google halo effect, that they perceive Google to be a leader in enterprise AI, and they're willing to go with it, and they're not just thinking ChatGPT there versus OpenAI. Or I'll just go with Copilot that Microsoft gives me because that is easy to do. I think it takes-- Google Workspace is second to Microsoft in terms of Office applications, but it's a much, much, much smaller market share.
" It's going to be a proactive thing. So I think that's part of it. Yeah.
I don't want to get too sidelined about talking baseball card numbers here, but you do look at it. In my experience, Gemini is, I don't know, it's batting above its numbers in terms of impact. Personally, for example, when I am using various AI-powered tools, you look at the drop-down box, and of course, there's OpenAI, there's Anthropic.
But I look at what I'm doing, and as I've been listening to this conversation, I'm thinking I'm using Gemini a lot more on a regular basis than I'm using ChatGPT or Claude, simply because I am using it more in those sort of-... integrated agentic workflow type situations. And certainly, that's because I'm a user of Google's applications on a daily basis, but I just find myself as well programmatically turning to Gemini as just a good, easy, quick, affordable model that I can call here and there.
I guess, Nick, what is the overall picture of the breakdown of the various companies that are contributing here with these signature models? I suppose we have to assume that OpenAI is in the lead. Are they?
Maybe that's not a valid assumption. Tell us a little bit more about the market. Yeah, they are in the lead in terms of those that responded to this survey.
And obviously, I should've said earlier, these people obviously have been qualified down to an inch of their life to make sure they understand what their strategy is. So yeah, OpenAI was used, and these are select all questions, it was used by 64% of respondents. Azure OpenAI was 62%.
So again, select all, so that's why you can have such high numbers. And Gemini was 54%. And so it was pretty close.
And then we had Meta Llama and SLMs and Anthropic and DeepSeek and others. And I think it is still ahead by quite a long way. But it's fair to say when you look at, I remember doing a roundup of 2025 and thinking, what a year in a sense Google Cloud Platform had.
And a lot of that was to do with Gemini. And also when we, Futurum, launched our signal reports last year, when I did my one on AI cloud platforms, Google and Microsoft came out top. AWS was in the next layer down, which might have surprised quite a few people.
And I think it's just indicative of Google as parlay Gemini and the way they're using the brand now is to be, not just mean a model, it means kind of enterprise AI to a large extent. I think they've parlayed that into a very good position. After all, they invented transformers, didn't they?
Yeah. And they had a lot to do with the early stages of what became LLMs. They stumbled at the beginning, and they also missed the boat in terms of putting a simple user interface on top of it.
But I'd say they have caught up to a large extent. And the multimodal stuff they do is obviously pretty impressive. Use cases for that are limited to some extent.
If you're in a kind of bank or an insurance company or something like that, you don't need NanoBanana every day of the week. But there's a lot of use case, and I think they're doing a pretty good job. So I have one last question about sovereignty.
So does our current infrastructure allow us to pull our data and models back in-house or into a specific jurisdiction if the regulatory or sovereign landscape shifts next year? I think sovereignty is one of these things that is talked about a hell of a lot. I live in London, and it's obviously talked about a lot more in Europe than it is North America, but it's talked about everywhere, really.
But it's not necessarily shown up in procurement quite as quickly as some of the various providers, be they cloud providers, software providers, hardware providers, resellers would like. " But of course, it depends on how far you want sovereignty to go for you. If you just mean data residency, then I wouldn't say that's easy, but it's a much easier issue than total control over your software supply chain or your hardware supply chain or something like that.
" The hardware providers would say the same thing. The software, yeah, everybody would say the same thing. And then, of course, it just depends on how far you want to go with sovereignty.
This report's really interesting. It filled in a lot of gray areas for me, Nick, and probably for you too, Steven. Based on my experience, I have the same experience that Steven has in terms of Gemini.
I tried the other chatbots, and I find myself using it more so than any of the others. But on an enterprise level, I found this fascinating because you're kind of getting into the nitty-gritty that I can't get from the vendors. And so it's showing us the kind of the graduation or the evolution of agentic in particular, perhaps this year, I'm sure into next year.
So I found this extremely useful when I do my questioning or when I do other stories in the near term. Yeah. And I'd just point out to everybody listening and watching, obviously, you can see this data if you're a client of Futurum already.
You can see all of it. com. And if you are a client, then this is available on our Futurum Intelligence Platform.
And I won't do a demo because a lot of people will be listening to this, but there is a really nice interactive way you can play with the data. This is not static screens. " All the crosstabs are built-in, and they're all dynamic.
And it's not a question of pull-downs and hitting refresh. This stuff just happens automatically. So I certainly encourage everybody to get a demo of that if they can.
Yeah. Well, and for me, I'll just say that when I use the intelligence platform, which I do absolutely on a daily basis, I'm actually using it through the chatbot interface because that's the other thing that I love about it is that I can just ask it questions about the market, and it'll respond. And I think that that's one of the ways that many of us are experiencing AI already within our organizations.
Certainly, many other products have that. I know that a lot of us have been using the Slack AI interface to query data using Salesforce, usingMany other companies offer this sort of capability. But ultimately, I think that we need to make sure that the data is there, and it's really nice to see, Nick, that the Futurum research team is collecting so much data, qualifying that data, making sure that it's real, and that we're not just guessing about the market.
Because too often I feel like people are guessing about the market. So thank you both so much for joining us for this episode. Before we run, Nick, you already talked a little bit, when is the report going to be released?
And then John, hop in and let us know what you're working on as well. So the report is out there, Steven. It's already released.
Great. It came out a couple of weeks ago. And we do these every six months, so there'll be another one, I assume, in the August, September time.
But yeah, the report's out there. You can see a subset of it for free on the Futurum website, and dig into it more if you're a client. There's so many trade shows coming up, and I'll be going to Las Vegas a lot.
I'm going to be commuting to Las Vegas for these Adobe and ServiceNow and Zscaler, Informatica shows. I'm going to go to Chicago for Nutanix. There are a lot of things.
There's a SAS Institute show in Dallas. It's a fire hose, as we all can attest. Yep.
As we are all drowning in this. But it's a great time. It's a exhilarating time.
I've never had so much fun covering the beat. I know, right? Yeah, actually, as we speak, so we've got Networking Field Day running.
I'm going to be going to Qlik Connect next week, and then the week after, or a few weeks after, we've got more Field Day stuff. I am really looking forward, in May, we've got AI Field Day. Those of you listening, that's my event.
That's my chance to really zoom in on a lot of what we talk about here. So just keep your eye on the Techstrong channels, keep your eye on the Techstrong app, and of course, the Futurum Group website to learn more about this. And, please do connect with all three of us.
You'll find us on LinkedIn as well as other social media applications. So thank you both for joining us today for this great discussion, and thank you all for listening to the "Utilizing AI" podcast today. If you enjoyed this discussion, please do subscribe on YouTube or on your favorite podcast application, and consider giving us a rating and a review.
This podcast is brought to you by the experts and analysts from the Futurum Group, where insights meet AI. ai, the Utilizing AI YouTube channel, or the Techstrong TV app. Thanks for listening, and we'll catch you next week.
OpenAI and Anthropic are going public. Maine might freeze AI. Amazon is going global STARM, while IBM and Arm huddle up for AI.
Komprise cuts AI storage costs. Microsoft fact-checks itself. And the president appoints a science council.
" Welcome to "The Tech Field Day Rundown," where each week, we run down the news of the week and discuss it with variable levels of snark. I'm your host, Alistair Cook, and it is my pleasure to join you on International Zoo Lovers Day. Ooh.
Also joining us today is my co-host, a special co-host, Gina Rosenthal. How are you doing, Gina? Hello, Alistair.
I'm good. How are you? I'm great today.
And I should also remind those of you in the United States that it is National Empanada Day, so make sure you get out and get yourself a good feed from somebody. It's easy in Austin, plenty of places. Oh, yeah.
Not so easy here, but then it's not National Empanada Day in New Zealand. There you go. Our lead story is around OpenAI and Anthropic.
They're our leading AI powerhouses, and they're racing towards potentially record-breaking initial public offerings. But their financial disclosures reveal an unprecedented cost of building their super intelligence. OpenAI could spend $121 billion on computing by 2028, with a projected loss of $85 billion for that year alone.
Both companies are exploring profitability, and particularly excluding their research and training costs to make it appear that they have ongoing profitability. Full-scale AI development breaks even maybe a decade away. From investor strategies to policy proposals shaping AI economy.
Gina, there's ridiculously large amounts of money turning around, and yet these AI companies seem to be planning to become profitable. It's an interesting thing, isn't it? So when you think about what they're trying to do, they have a new way of doing computing that they're purporting is going to bring all this profitability.
At the same time, they're really not sure what they're doing. And I think it's interesting that you have one company, OpenAI, that's mostly backed by Microsoft. While on the other hand, you have Anthropic, which is mostly backed by AWS and Google.
Of course, that's who owns Anthropic. But on the back end, when you start looking at it more, everybody's investing in everything else. So they know that...
It's almost like they have this supposition that one platform is going to rule them all. One is going to be the conqueror, and one's going to be the absorbent. I'm not sure that's true.
But when you look into what it takes to build out an AI infrastructure, it's very expensive. Lots of money for procuring the land, for getting the agreement of local governments to put either their power grid and their water at risk, or put their clean air and their water at risk. And then just who are you going to get to build the buildings that are going to house them?
In the United States, up to 50% of the skilled labor and construction are immigrants. And right now, construction sites are a favorite place for ICE to go and round people up. So who's actually going to build them?
And if we build out everything that's projected and on the books and planned right now, do we really need that much infrastructure? This coming from an infrastructure person, I'm questioning that more and more. Or is this just what they're doing to beef up how they look to people that don't understand what's coming?
Which is important. It's important to have AI, it's important to have the infrastructure to run them. But I think even looking at the sheet, the cost sheets, the run books for these companies, they're not making any money right now, in large part because companies are having a hard time buying in.
Companies are having a hard time doing the simple operational things like getting their GPUs to be constantly in motion all the time running jobs. So we've got an arms race to get the blue ribbon, is almost what it is, versus an arms race to be able to do the right thing. So I think all this just remains to be seen.
Will somebody be profitable? Yeah. What if it's neither one of these companies?
What if the people that are going to be profitable are the ones that really buckle down to the computer science of this and start building operational areas that are a little friendlier to the environment and a little friendlier to the neighborhoods they're built in, and friendlier to people that consume them. IBM has partnered with Arm to bring hybrid architecture to enterprise AI workloads, enabling Arm-based software to run seamlessly within IBM systems. The collaboration focuses on virtualization, performance compliance, and expanding the enterprise ecosystem, allowing organizations to modernize without abandoning legacy infrastructure.
Dual architecture systems could reshape AI deployment, improve efficiency, and offer greater flexibility in the AI area. And this is a really interesting partnership that's going on. One of the things that IBM often gets looked at as being a really legacy organization that is focused on older mainframe systems, the boat anchors of enterprise IT, if you will.
And yet Arm is the darling of the smaller, newer, faster-moving, changing things. And so the partnership together is really intriguing. It focuses on a few key things.
One of the things that's in here is the idea of having the capability to run virtualization and to run Arm-based applications on IBM platforms through virtualization. Now, you've got to think that's going to have some Arm CPUs underneath since it's virtualization. They're not talking about emulation of running Arm binaries on top of an existing mainframe architecture.
Another element in here is performance and compliance, and this is one of the places where IBM is renowned for having all of the control and governance processes around data and systems. This is where the IBM consulting business has its strength, is in all of the checklists and the validation that they do to make sure that the systems that are built are compliant with both good practices, but also whatever legislative regime or industry standards are required. So this area of performance and compliance is a really significant one, and I'd focus particularly on the compliance piece as being something that's a little unique to IBM in here, just because of their history of doing large scale, massive, highly regulated environments through banking and defense, that compliance thing has been really vital for them.
But the third piece in here is expanding an ecosystem, and I think this is one of the big things that Arm brings in, because Arm has always been an ecosystem customer business. They've always been about licensing intellectual property to organizations that can then integrate with their systems, and having a unified platform of intellectual property across all the way from the embedded system, the things that you see in your mobile phone, all the way up to the high performance that we see in the NVIDIA's Vera Rubin. Their Vera CPU is Arm-based.
So that ecosystem play for modern applications, modern architectures based on Arm, combined with the huge legacy that IBM has working in large-scale enterprise regulated environments, I think this is potentially a very powerful partnership. Of course, there'll be some challenges along the way because all of the Arm innovation and the Arm partnership requires Arm CPUs. Now, absolutely, Arm will be very happy to license that CPU architecture to IBM to produce and integrate into their newer systems.
It may well turn up as an add-on to all of your existing IBM mainframing systems. It may be just a sidecar that's attached. Not quite sure how that's going to play out in the future, but there is a discussion in here around adding capabilities to your existing IBM infrastructure rather than having to build something completely new or buy a completely new product.
So I think this is going to be really cool. As always, with these kinds of partnerships, the devil will be in the detail, what actually gets shipped out to customers, how usable it is for customers, and what problems it really solves for those customers. I didn't see a lot of AI washing on this, which makes me feel really positive when the vendors can make a standalone talk because these are the things we're actually delivering and not have to take whatever the latest hype is in their announcement.
I think that's a really good thing, too. And again, that's an IBM all over. That will stand on top of the really good things that we do and not necessarily get into the latest high-fashion topics.
Maine is moving to pause the construction of large-scale AI data centers until at least 2027, potentially setting a nationwide precedent. And if you watched last week's rundown, running a bit afoul of the plans of the current administration. Lawmakers in Maine cite rising energy consumption, high electricity costs, and environmental concerns, even as these facilities promise jobs and tax revenue.
There's a tension between AI infrastructure growth and sustainability. And Maine's decision could influence the future of data center development across the US. Well, Gina, do you think that the federal government is going to step in and actuallyPut a block on these blocks?
Block the blocks. That's a very interesting way to put it. I don't know, but it is very interesting, especially for an administration that really seems to uphold the idea of states' rights, and the states' rights to do what's the best for their own citizens.
And Maine's not alone, and Maine wasn't the first governmental group to do a moratorium. The Seminole Nation of Oklahoma actually used that same hard stop model before them. They also have passed a moratorium on generative AI technology and the hyperscale data center development for the same reasons, the reasons we talked about earlier, in fact.
That these data centers require enormous amounts of water. They require enough energy to support entire cities, and if they promise to keep it off the grid, what they're doing is they're bringing in generators that, of course, the byproduct is pollution, and kind of eliminate the clean air in these countryside areas where the developers are looking to build these data centers. I find the Indian country angle pretty interesting.
The Creek Nation also stopped a project, a data center project, and part of the problem and the reason that the Creek council members stopped it, the Muscogee, I'm sorry. The Muscogee council members stopped it was because all of the people that were involved in signing the project agreements from the Creek Nation were actually put under NDA, and they couldn't explain what was going on to the council members, which was very much contrary to their constitution and to how they run things as a tribe. So, that's why the tribal members decided to put the moratorium on it until they could understand what's going on.
So, it's interesting because it shines a light on what the model is that these developers are doing. They're going in, they're promising lots of jobs, which they can't promise because they bring in the trade labor to build it, and then, of course, they leave with maybe 50 jobs because the data centers are not managed on-site. And in the meantime, they also convince the agencies, the government people, to say, "Hey, give us all your water, all your energy, or we'll bring the energy and pollute your air.
" And we've seen that a lot in Texas as well. Right now, there's a growing movement from an organization called Honor the Earth that's tracking the data centers that are being planned on tribal nations' land. But that's happening all over the place.
I know here in Texas, that's also happening. One of the ones that has kind of got to me the most was there's a state park that is full of dinosaur footprints. It's Dinosaur State Park is how everybody talks about it, and they're looking to put one of the data centers right next to it.
And it's not just the fact they're putting up the building, then if you look at what's happened with the Meta data center in northern Louisiana, it changes everything because they have to build roads that were never there because it's very rural area. They have to build roads. There's constant traffic back and forth carrying materials to build the buildings.
Total influx of people to build it, which results in man camps, which results in their own kind of issues. So, the states have every right to say, "Whoa. " And is this something that's a benefit for our citizens, or is it something we need to sit back and take a look at?
And the latest tribal nation to do that was the Cherokee Nation in Oklahoma. Taking a look at what is this going to do for the nation, and what will we give up in order to have this here on our tribal lands? So, I think the states and the municipalities need to do that.
I think it's worth it for everybody to look into what's going on, and the only really good thing I can see from it is, hey, people care about data centers for the first time in my life, and I can actually explain it to them, and they don't roll their eyes like they don't care. So it's pretty cool. Komprise has introduced FlashStretch, a tool designed to help IT teams optimize flash memory usage and control rising storage costs driven by AI demand.
By analyzing data based on type, age, and usage, it identifies cold data that can be moved or tiered, bringing up capacity for high-performance workloads and reducing the need for additional storage. The approach helps organizations cut costs, streamline memory usage, and address ongoing DRAM and SSD constraints in the AI era. There's been huge cost increases for both SSDs and DRAM since the massive build-out of AI.
Data centers has been chewing up all of the potential supply. So, these long-term contracts to acquire huge amounts of memory and huge amounts of SSD to go into these massive AI data centers that may or may not be built is driving up the cost of SSDs and DRAM for everybody else. What Komprise is doing here is providing a tool to take a look at your environment and maybe help you avoid having to buy additional DRAM and SSD capacity while these prices are so high.
You do that by taking the large amount of your data that's sitting on expensive SSD and migrating it to lower cost, higher capacity locations. Often with Komprise, this is moving it out to maybe some older NAS or something that's just got a lot of hard drives in it. So this is something we've always known is a good idea.
It's just that when the cost of SSD was very low, there wasn't actually that much return on investment to do this. As we're seeing 100%, higher than 100% increase in the cost of both SSD and DRAM, it makes more economic sense to start looking at efficiently using what you have rather than trying to acquire a huge amount moreNow, all the projections are that this is a transitory increase in cost. This is not a permanent increase, that what we'll see is a return of supply over time.
It'll come back one of two ways. Either new fabs will be built, in which case it'll take three to five years to resolve that, or some of those orders that are chewing up all of the projected production for the existing fabrication capacity, maybe those will get canceled because these AI data centers are being stalled. Refer to our previous story.
So Comprise is helping customers. Comprise, of course, would like you to use their software to do the migration and management of where these files reside and migrating the unused data out onto lower cost storage. Comprise has great products to help you do that.
But this FlashStretch assessment tool is a great start to identifying whether you can get the benefits you need. Your data set may not be the same as everybody else's. By the way, it probably is, and it probably does have 70% of the data stored on your high performance, high cost storage not being accessed in the last three to six months.
So there's obviously potential for cost saving or cost avoidance using some tools that migrate across. " Amazon's reportedly in talks to acquire the satellite communication company Globalstar for a $9 billion price, and it's aimed at accelerating the Amazon Leo project, or what was previously called Kuiper. This is the competition to Starlink from SpaceX.
So this acquisition by Amazon could provide key assets as well as spectrum licenses and an established customer base to pay for things, as well as existing infrastructure, which will help that competition against SpaceX. But the deal may have some challenges along the way, particularly because Apple has a stake in Globalstar and uses Globalstar for that emergency satellite contact with Apple's iPhones. Gina, do you think that this is going to go ahead?
Is Amazon successfully going to acquire Globalstar, and will it make a difference and save them from launching a whole lot of satellites? Well, we're going to have to see, but this is another one of those interesting stories that have to do with the big companies, right? " That's why they're in talks to buy Globalstar for $9 billion.
So where we're starting at is Amazon has about 200 satellites in orbit. Starlink has 10,000 satellites in orbit. So that's how big the gap is that they're starting at.
And of course, the Amazon stake in Globalstar is going to complicate the deal. It's not a two-company negotiation. It's at least a three-body problem.
The other person, the other guest in the room would be regulators. So Amazon's asking the regulators for more time to launch 1,600 satellites by July 26. So if this deal can go through, then they're able to buy some time with FCC because they acquired those satellites that they needed.
And what Globalstar is, what they'll get for that is voice, data, and asset tracking across government, enterprise, and consumer markets. So of course, this made Wall Street go all crazy. They had a 15% pop right after this report launched, but it's still just a reported talk.
It's not something that's gone through yet. I'm guessing Amazon is going to really, really hope it goes through, but it probably is going to be at some cost to them, being that Apple has such a big stake and seems to be a big customer as well. So that's the thing to think about.
Will this go through, and can Amazon continue to accelerate deployment and integrate assets so that they can have a chance of catching up with Starlink? That's going to be tough to do, even if it does go through. Microsoft field engineers have developed Project Nighthawk, a six-agent research system built into VS Code that retrieves, verifies, and documents answers to complex Azure Kubernetes Service and Azure Red Hat OpenShift questions.
Unlike typical AI tools, Nighthawk works directly with live code repositories and official documentation to produce fact-checked, source-cited, and technical reports in minutes. Its agent-based design, featuring roles like classifier, researcher, synthesizer, and fact checker, sets a new standard for reliable DevOps and internal AI research workflows. I think this is a proof of concept.
I think this is more to show you how to build a complex tool. When they talk about agents in here, they're really talking about what I think of as a microservice. Go out and use AI to retrieve some information or analyze some information.
So although there's a lot of discussion here, and in general, about agents as being a separate thing, they're just event-driven microservices that happen to use AI. This particular case, they're highlighting that those microservices, those agents, need to just do one task. One goes out and retrieves information.
Another one of these microservices or these agents analyzes the retrieved information. Another one produces the actual report. And so there's that segregation of duties that we've seen in microservices architectures for a long time in enterprise building applications or modern applications.
Now, the proof in this one is around looking at a complex system that is deploying maybe newcompute nodes into a Kubernetes cluster, whether it's the Azure Kubernetes cluster or whether it's a Red Hat OpenShift Azure service. There's two different cluster Kubernetes services on Azure. This particular tool lets you ask simple language questions against this set of agents, and so it allows you to be a lot more natural language in trying to find information.
" Those of you who've not watched British comedy, maybe go look for that. It's terrible, but rather funny. Another interesting thing in the coverage here is that it's returning to the idea that AI tools tend to hallucinate, and so they need to be grounded in facts.
And this is one of the things that's really core in here. One of the insights in this is that you can't just use a general purpose agent, general purpose AI model by itself. You need to ground it in some facts, and that might be the documentation for how the service should work, the documentation for how the service should report its errors, but also the source code for whatever infrastructure as code you're using to deploy this new node or maybe deploy some pods on top of Kubernetes.
That grounding of the individual AI components in some verifiable, citable facts is a really important part for using these agents to take action, not just report back to a human who will then validate. So, I think there's some really good things to learn from Project Nighthawk, and to look at how it works together, how it builds these collection of agents, microservices to build together a larger tool. Always liked seeing AI being used to achieve something rather than just as a user interface.
So, seeing these large language models working with the individual services. Another of the really important things about breaking up into multiple agents is you can use the right large language model or small language model or ML rather than generative AI. You can use the right tool in each of the agents to achieve the thing that this agent is supposed to do.
And this is the only way we're going to efficiently use AI over time. If we continue to use generic AI models to do every single task, we're doing things very inefficiently. It's like not having any specialists on your team, only having generalists.
It's not the most efficient way to manage at large scale. Having language models that are suited to specific tasks is going to be important. I like this.
I think this architecture, this design of using essentially a microservices architecture with your AI agents is a really good thing, and we need to see more organizations doing this, not just for operating their DevOps environments and their Kubernetes environments, but actually for operating their businesses. And fundamentally, this is why these kinds of papers are being published out to show you how to operate using AI. Now it's time for a little bit of a closer look.
And President Donald Trump has appointed a high-profile group of tech leaders to the newly formed President's Council of Advisors on Science and Technology, PCAST. That group of high profile leaders includes Mark Zuckerberg, Jensen Huang, Larry Ellison, and Sergey Brin. They're tasked with shaping the US AI policy.
Science and technology is all about AI. The council signals a push into accelerating innovation, streamlining regulation, and maintaining American leadership across the global AI race, particularly in competition with China. The appointments highlight the council's potential impact on AI, national security, and the future of tech regulations, and it strikes me that all of the people that are named in the initial announcement are leaders of very large companies that have a vested interest in AI.
Many of them are involved in the huge amounts of money that is changing hands to build out AI. What I'm looking for is some announcements of the remaining people, and as we look through the list that's actually on this executive order that Donald has put out, we just see big business in here. We don't see a representation of any other interests beyond the core, people who are building AI things.
And so I'm hoping that when this builds out to the full 24 members that the executive order tells us are going to be there, we'll see some representation of some other interests, that it won't just be a self-serving, let's build more AI and America has to be the only place where AI is being built, those kinds of ideas. The actual executive order reads very much like a bunch of chest-beating and claims of the wonderful future of America can only be built by this board and it's the leaders of big industry that are going to shape everything positive in the United States. Coming from a smaller country, I have a bit of a view on wanting to see some considerations other than sheer dominance.
And so there are 11 more seats here on this council. I hope we'll see some ethics and environmental considerations from the other members of the council over time, and it will be interesting to see whether they can get all of these luminaries within the IT industry to come together and actually meet and talk. Would be an interesting thing to see whether things actually go ahead.
Gina, is domination of the world of AI vital to the security interests of the United States and the best interests of the citizens of the United States? All I can say, especially today, is I don't think what's coming out of the White House represents how most Americans feel. Especially since I'm on here with someone from a foreign country.
We do not see things and feel things the same way. AndDominance is an interesting word to say, right? I think in the past, this kind of competition-- And I think there are dangers from foreign states.
We talk about it all the time when we talk about backup and recovery, and there's definitely foreign states, including the United States, use AI and technology against their enemies, right? So it's interesting how it's phrased. It sounds like it's more of a TV blurb or a movie blurb, an entertainment blurb than it sounds appropriate for a presidential executive order.
So having said that, I think it is important to understand that militaries will always use the latest technology, either to protect themselves or to attack others, and we're seeing that play out in real-time, unfortunately. So it's just part of the game. So, yeah, I think that's something all countries do, and I would imagine there's lots of countries doing that against us right now, the US.
I also, getting back to the list, I found it funny that Musk is not on the list. Elon Musk is not here. So that must have been a pretty bad bromance breakup.
If you look at the other people, most of them are infrastructure folks with the exception of Zuckerberg. But I want to focus on that one and kind of draw a circle around it. They eliminated their ethics group.
Most of the companies, the big companies, have eliminated their ethics groups. So that's a problem there. They love to compare, they being the White House, loves to compare this AI act that they're doing to what Franklin Delano Roosevelt did back in the '30s.
However, I'm pretty sure that he included scientists and not just people from IBM. So there's a lot to be said for that. We don't have any scientists, we don't have any universities where all of this stuff was actually, it started out.
You want to find out about ML, and what really AI is, AI is a marketing term. It has been for the whole 50-something years it's been around. So if we want to find out about HPC and we want to find out about machine learning and deep learning, universities is where you need to really have some of that inclusion too, because they're working on that.
The problem is that they also apply ethics and humanity, and investigate a lot of that. When we're working with a tool that can take data and manipulate it and display it in a different way, if you don't have some type of ethics... I came through from a technical viewpoint through college.
My bachelor's was from the School of Library Science. How do people look for information? How do they retrieve it?
What fills an information need? With a lack of that, you end up with a machine that can create, promote propaganda at the very least, when you look at the LLM side of the world, the information side of the world. " And if there's a town meeting about these kind of things in your town, show up and ask the questions.
You should do it, because we're going to give you the basic words for what we've been doing in our careers that you thought was just fixing your laptop when we came home to see you, into how data centers work. And now you can go and have an authoritative voice and ask questions based on reality, because it's important. So I think the sun's going to come up every day.
We got to remember that. We're going to be here too, and there are ways to make sure that we get through this in a scientific, technical manner, but some of that's going to mean teaching your mom and dad what data center is. I think that's really important.
Yeah. Well, it is important to remember, the sun'll come up tomorrow. And it's already tomorrow here, and I can tell you the sun is coming up.
Being in New Zealand, I come from the future, and the sun has come up today. I really look forward to this council of advisors on science and technology having some people whose focus is on science and technology rather than simply on business. Not discounting the technical know-how of the people who are on this panel.
I would like to see, as you would, some more focus on those science foundational people who aren't necessarily just involved in commercial. Something that you should focus on right now. Right now, the Networking Field Day 40 is on.
So Tom Hollingsworth is not with us today because he, of course, is leading Networking Field Day 40. When you're listening to this, if you're listening to us as we release, soon as we finish, you should head straight across and follow the rest of Networking Field Day. That's today, tomorrow, and Friday.
com, but also on our YouTube channel. A couple of weeks' time, we'll have the Tech Field Day experience at ClickConnect. So Stephen's heading out to ClickConnect in Orlando, if I remember rightly.
He's going to have a couple of days with some fun people out there. Lucky. And then at the end of the month, it's going to be Security Field Day 15, and Tom is going to be once more in the West Coast and hosting a whole bunch of people.
So look forward to those events. Check out all of our upcoming events on the Tech Field Day website, as well as on our YouTube and LinkedIn. Of course, Gina will be out at ClickConnect with Stephen, so look forward to seeing all of her things she's learning and her insights there.
" You can catch new episodes every Wednesday as a YouTube video on your favorite podcast application. We'll be back next week to talk about all of the IT news that was, and until then, for myself, for Gina Rosenthal, and for all of us here at Tech Field Day, here's wishing you and yours a great day. I hope you had a great lunch and you've had a good amount of coffee so you're awake and listening.
Even if you haven't had enough coffee, you'll probably stay awake and listening to this one. Thank you for joining us at Cloud Field Day 25, wherever you're joining us from across the wide internet, and even if you're watching us on the WayBack Machine maybe from the Internet Archive. I'm not sure we're there yet, but maybe we will be someday.
This is Cloud Field Day. This is our final stream presentation of our first day of Cloud Field Day 25. A real pleasure to have you here.
A real pleasure to have my delegates here. com website, where you'll find all of my delegates. You can find the events they've been at.
You can also find the things that they've written, as well as things like where they are on social media. Many of them you can find on LinkedIn, where they share their knowledge and expertise. Shayla in particular has even shared some knowledge and expertise today from one of the earlier presentations.
So, great work to see that content coming out. You'll see the delegates will write about the things that interest them from these presentations over the coming weeks and months, so keep an eye on them as well. Of course, more events coming up.
For those of you who are looking for things like something in the security space, RSAC is coming up in a couple of weeks' time. Tom Hollingsworth will be out here in California for that. So keep an eye out for what those sessions will be and some of the fun that's going on.
But right now, history. History and the return of history. They say those who don't study history are doomed to repeat it.
Those who've lived it in the past, probably also doomed to repeat it as well. Tom, you've lived through much history in the IT industry. Come tell us what things we're going to repeat.
Thank you, Alistair, and thanks to Steven, wherever he is, for inviting me. Yeah, so what if I told you cloud computing was almost 100 years old? If you define it as outsourcing your data processing to some company that owns the equipment that does the work, well, indeed, we're nearly 100 years old.
Really in the '20s, but much more visibly in the 1930s, IBM started these service bureaus where you could bring your data, and they had key punch girls to punch it on cards and then do tabulating, et cetera, et cetera, all for people who can afford the outrageous lease prices of the actual machinery. So it's similar today. You don't want to build your own data center, you go to the cloud.
Surprisingly, they started things like the Statistical Bureau at Columbia, which immediately was overrun with requests from astronomers to do basic arithmetic because it had some machines that could do things like multiply, starting in 1931. You could multiply two numbers on a card and get another card with it. So that was amazing.
In the late 1930s, this book over here, "When Computers Were Human," talks a lot about this. They were literally hiring people off the streets to be part of a massive computing mechanism where you worked your calculator and somebody else had this parallel program about how you pass the numbers around to the other people. Punch cards made all this possible.
POGS there is my nickname, and that's a relic from when I was heavily involved with punch cards in the '70s. So the '30s, of course, was all about the Great Depression, and so there was no boom, particularly until the war hit. And not really a cloud.
They were just skyscrapers because IBM was headquartered in New York City at that time. So World War II, nothing interesting happened in terms of service bureaus, but of course, a lot of other stuff. These are my favorite books about the World War II era.
And the middle one is about radar. It's really fascinating because that's where all the high-frequency electronics was developed. Post-war, it was still all punch cards, but getting really fancy now.
I have these two books, the proceedings, which are thick documents with all these papers about how to do fancy computation on punch cards with the then-available equipment. Still no computers. In this marvelous industry survey from 1952, the punch card is the peak of the punch card and hundreds of different uses and applications, et cetera.
It's marvelous stuff. 1950 is, of course, when computers really became part of the popular consciousness with UNIVAC. And starting around 1954, IBM actually made computers that would stay up for more than an hour or so.
And so they started to percolate. But in 1956, there was this IBM consent decreeWith the government. And it wasn't about computers, it was about service bureaus and data processing.
So still, we're very much in the punch card industry, and outsourced data processing was a very big deal that the government had to get involved to make things more competitive. And so IBM had to start this subsidiary called the Service Bureau Corporation and have hands-off operations with it. 1956, the Dartmouth AI Workshop.
So that's really the birthplace of a lot of AI stuff, along with the first neural net in 1957. 1959, the first SAGE site. SAGE, huge defense installation stuff.
The birthplace of a huge amount of technology and software. And really, the enabling standards in this timeframe were the transistor for reliability, core memory for reliability, and magnetic tape, so you don't have to carry boxes of cards around anymore. You get a lot more dense information.
And, of course, everything was government-funded due to the wars, and the Cold War particularly. So in the early '60s, the whole service bureau thing started really spreading out. Every hardware company now had service bureaus for people who couldn't afford to buy the full thing.
Independent companies started arising to do data processing. In particular, ADB was a big one, and they're still the guys who provide all your paychecks, probably. EDS was born in 1962.
That's H. Ross Perot. And started really coming into companies and taking over all their data processing needs, so it's kind of reverse outsourcing.
But a very interesting company. Timesharing was born, and software becomes a business. It was very unclear to the world what software was worth and who pays for what until the mid-'60s.
Applied Data Research had one of the first products, Autoflow, which would create flowcharts out of your code so you could try to understand it. Hmm. And that could very well be the first software product.
And a little trivia fact, 10 years later in 1977, I had a part-time job with ADR. SDC, the system builders, they did all the software for that SAGE system. And they have a good claim to inventing system programming as opposed to computational programming or data processing.
They're tying together big, complicated systems. And this last book by Campbell-Kelly is a really marvelous history of the software industry. Late '60s were the go-go years.
I'm sure we all remember Rowan and Martin's Laugh-In and that kind of stuff. The whole notion of a computer utility came around, so this is very much a cloud concept based on timesharing and remote access. And hundreds of companies got on this bandwagon and started building out crazy infrastructure.
In addition, the overall market was very favorable to software companies. You had the first software IPO in 1968, the first computing billionaire, H. Ross Perot, in 1970.
And so we had the classic irrational exuberance going on in the market. The enabling standards were things like teletypes and modems and the fact that you could move FORTRAN and BASIC programs around, and hard drives let your data actually be online when you needed it. And, of course, a huge amount of war spending due to Vietnam.
I have these books in my collection that all talk about how wonderful the utility computing world is going to be. Early '70s, major depression. So all that stuff was gone.
RCA and GE left the computer business entirely. Because money dried up, all of a sudden, the capital and the people required to provide services didn't work out anymore, so there was a big shift from services to software companies. The rise of the minicomputer didn't help any of the outsourcing stuff because now more and more people could afford a computer.
Mm. Things like word processors and calculators, same thing. And really, semiconductor memory is what had the biggest effect in terms of new things entering the market.
Late '70s, this is where all the glory stuff happens. I'm sure we've all heard about all these different things happening, except maybe the last. In the late '70s, people started having statistical multiplexing-based networks.
So the networks got a whole lot cheaper and a lot more reliable. And things like Tymnet and Telenet, CompuServe all grew up as new types of not just timesharing, but information-sharing systems, all well before the internet. And this was where I really cut my teeth.
I graduated from Princeton in '78, already a Unix expert, and went on from there. Early '80s, the whole desktop era. I'm sure we're all pretty familiar with this.
" Mm-hmm. Really good. One of the guys who was on my board of directors at DriveScale, Carl Ledbetter, was the technical advisor for this.
In addition to being a wizard mathematician and a venture capitalist. " Clearly, all about steps towards the cloud. Didn't quite have the computing in the cloud at that point.
This diagram is something I drew at the NFS architecture offsite when we were sorting out how to do NFS. And if you look very closely, there's a cloud over there. The cloud was already commonly used to represent a network of stuff.
Mm-hmm. But really computing wasn't in the network yet. Mm-hmm.
Late '80s and early '90s, that's when networking really took off. We had the Wild West of protocols. We had Cisco, 3Com, Novell, all this stuff happening.
And then, of course, the real emergence of the internet. And this book, by Pelkey, a huge amount of detail, personal interviews of all the key players and stuff. Excellent book.
Late '90s. All right. Here we go.
The dot-com boom, the web boom. I'm sure we all know a lot about this, but I peg 1995 as a key point because Windows 95 finally included TCP/IP. Mm-hmm.
So I was like, "Okay, we're done. " Mm-hmm. ISPs took off.
ASPs, application service providers, if you remember those guys. I guess they'd be more like software as a service these days or something like that. And we had the beginnings of actual infrastructure as a service companies.
LoudCloud and TerraSpring are the two examples I know. And you could truly ask them to build your data center in the sky for you, and you'd never actually see it. Now, this was before x86 virtual machines came around, so it was a little bit harder to do.
I was on the board of directors at TerraSpring. But this was a period of irrational exuberance. I remember discussions in the board meetings about how we were going to pave Milpitas with data centers.
Kind of like the same discussions going on now with AI. Only it's not Milpitas, it's Texas. Right.
These books are marvelous because it talks about the boom, but they were written before the bust. So it's like it captures the exuberance. 2000s, the dot-com bust.
So again, the shift from services to software. Both LoudCloud and TerraSpring shifted to software product. LoudCloud ended up at HP, TerraSpring at Sun.
But the thing that was going on behind the scenes was creative accounting and outright fraud by the telcos. So people always call it the dot-com boom, but I think of it as the telecom boom because it was the telecom fraud that just removed a huge amount of money from the market and affected all the investors, the ones who thought they were buying safe stuff like telecom stocks. The irrationally exuberant people got what they deserved.
So you're saying that it was really a telecom bust, but it got renamed or is named the dot-com bust. Yeah. Clearly there was too much exuberance about the dot-com stuff.
Yeah. But the real pain, I think, and the long recovery came from the telecom part. Mm-hmm.
But ironically, at least that's what left the assets in the ground- Right ... over building on the telecom fraud, right? To pave the way for the- Right ...
we came on the other side. Yeah. So we have hope that someday all these brand-new data centers that are being built might actually be used.
Yeah. Yeah. So outright fraud caused a lot of the pain.
2000s, it took till 2002 to get to the low point of the S&P, so it was a long, painful decline. I like the fact that in the 2000s, AI stood for American Idol, not for artificial. AWS got launched in 2006 with pretty basic services, but very popular even then.
This ImageNet database is the first very large image database, which enabled a lot of AI processing. Mm-hmm. But again, there was another recession, but it was all real estate fraud this time.
So that slowed things down a bit. I'm going to be way ahead of time. 2010s, AI gets real.
So Watson wins on Jeopardy. That was a key thing in the popular space. AlexNet proves the unreasonable effectiveness of neural networks.
I saw that phrase comes from, what's his name, Dean at Google. He gave a talk about how they were applying AI and how just these neural networks were just unreasonably effective at doing things. Mm-hmm.
And I saw that talk 15 years ago, so it's all gotten better. Nvidia up 600 times since then. Google acquired DeepMind.
OpenAI got founded as a not-for-profit. I think most people forget that now. Too recent for me to know of any good books about this area.
And here we are in the 2020s. AI is totally unreal. Insane data center build-out.
Even for the level of the data centers and power and water, I don't think there's enough money in the world to cover what people are saying they're going to do. Let alone fill the data centers with electronics. NVIDIA, of course, rules the roost.
They kind of deserve it. I have nothing bad to say about them. But here we are again with total irrational exuberance, lots of creative accounting, all kinds of circular investments and revenue going on.
And it can't last. And, of course, the government is not exactly enforcing anything related to business or whatever. So they're leading by example, and there's got to be massive fraud brewing in this kind of environment.
And then there's the huge data sovereignty and copyright issues. How can you trust an LLM if it's going to share all your data with somebody else? And they're already being sued by all the authors for snarfing all the books.
So I think we're due for another crash. So things are looking ugly. There has to be an AI recession, right?
But when, how soon? The sooner, the better, but- ... I'm no good at predicting.
It's going to be made much worse by the fraud and the wars and the tariffs and all that crazy stuff. But there is real stuff behind AI. We'll get back to normalcy someday, but it's probably in the five to 10-year timeframe.
The end is near, so that's- ... that's all I got. Can you go back to the previous slide?
So if you were to take-- To me, we had this discussion earlier. I think a lot of the... It becomes this, kind of like the military industrial complex, right?
And it's almost like there's so many people that stand to benefit from an AI build-out as opposed to the internet. The internet build-out was kind of contained to the telecom world and the internet world. But this, so many people stand to benefit from building data centers, building physical, concrete things, right?
That really wasn't the case back then. So if you were to- Oh You know what I mean? There's only a handful of companies capable of building the really big ones, right?
Yeah, but I mean- But there are lots of users who want the- There are lots of users. If you think about all the periphery around it, right? If you're making generators, if you're concrete, whatever, right, fire- Yeah.
Yeah ... suppression systems, right? Anything that, a physical infrastructure that's on a massive scale exponentially larger than what we saw with the internet.
So there are just so many more people that have a vested interest to make this more than what it is. So, say if you could wave a magic wand and the infrastructure piece was solved, say, somebody figured out a way to cut the infrastructure build by 10 times. So take that off the list.
Take that as a given, the insane data center build-out. Take that one off the list. Would those other bullet points be enough to derail everything, right?
If you just had to deal with data sovereignty and copyright issues, would that be enough to derail it? Would a massive fraud, would that be enough to- Yeah ... derail it?
Or does it take all those things in combination to- Well, I think it's the exuberance plus the fraud are the big ones. Okay. And people are expecting way too much out of AI too soon, right?
So let's go lay off half the people in the company- Yeah ... because we're going to do AI. Well- Seems like it's a- You need AI ...
question of, is there a there there? Because the dot com bust was really that there are all these companies that had not a bad idea- It was just way too soon ... but they were there too early.
Right. The consumer wasn't ready because they didn't- Yeah ... have the web yet.
Yep. Yeah. So all this stuff had to get built out, and people had to adopt the web before they could actually sign on and start using these- Yeah ...
websites. I'm wondering if AI is going to follow a similar trajectory where we're overbuilding. Mm-hmm.
There'll be a bust- Right ... but then there'll be another sort of delayed boom. Yeah.
That's what I think. I think right now people are expecting these- A thousand unicorns ... 1,000% per year growth or whatever.
Yeah. Yeah. When nothing in history has ever grown that fast.
Yeah. Right. Right?
And you need to dial it down to maybe 100% per year, right? But... Do you trace any of this back to when money got cheap?
I remember after 9/11, interest rates pretty much went to one, 2% because they were trying to goose the economy. And we never really came out of that. It seems like, I can remember before then, interest rates typically were four, six, 7%, and then it was this normal cycle of the economy slowing down, or the interest rates to goose it back.
So, when interest rates were high, you didn't have to chase these dangerous returns, right? To get a return on your investment. It just seems like we've lived in such a long cycle of cheap money.
Yeah. Even before AI and all this stuffWe're overdue for some kind of recession. Yeah.
The basic S&P has been growing too far, too fast. But the interest rates, we did get a good chunk of inflation with COVID. Yeah.
Because the government started giving money away for free. Mm. Which we benefited at DriveScale from some of that.
Yeah. It let our painful life last another six months. But go ahead, Jeff.
So one thing that's interesting when we did our podcast, "Right Ned," we talked about last week was the idea of the energy build-out that's necessary for the data centers. Right? Right.
Because estimates are somewhere between half to two-thirds of the data center proposals that are coming out are enormous over capacity. But the reason they're doing it is to guarantee that maybe one out of two or one out of three of the data centers might be able to get built. Right?
So you're seeing that trend, but also acknowledging that, especially in the US, our energy infrastructure is in disastrous shape. We haven't done anything dramatic- Mm-hmm ... since the 1930s with the Tennessee Valley Authority.
You've got stuff that's literally 80 to 100 years old that needs to be rebuilt. And maybe the idea of, not necessarily the huge nuclear plants, but things like small modular reactors and things along those lines, maybe that would be the overcapacity that, well, now electricity is basically free, and once we get past the current time, it'll be easier to feed renewable energy into that network because we were headed in that direction in our discussion about EVs and things like that offline. Yeah, you'll have a grid.
You'll have to build out a grid. You'll have that grid. Yeah.
Which we don't have today. Yep. Exactly.
The ability to exchange things actually between Texas and Illinois. Right. Yeah.
So maybe is that what's going to be the fallout, or the positive fallout of this? I like that analogy to what happened with the fiber build-out. Exactly.
Yeah. We overbuilt capacity- Yeah ... and then we found a use for that capacity.
Yes. Imagine. Yeah.
So if we overbuild our power capacity in the short term, we'll find a use for it, and maybe that could be fixing our ailing infrastructure. Yeah. That may be- Yeah, but I've seen a lot less hype about fixing the transmission than I have about spinning up new power sources.
Right. And it's a lot more political. I would argue the one thing, political, I think that hits the nail on the head because one thing, the stuff we did before was under the ground, you didn't see it.
You burned fiber into the ground. It wasn't a data center humming in my backyard. So, data centers that used to be a pro forma sign-off, we'd love to have you come to town.
They're like the prisons of this decade. Nobody wants them in their backyard, right? Right.
So, I think the political dynamic is really going to play out big in the next two or three years. Well, it's playing out big now. Yep.
Things that were signed off on before- Mm-hmm ... you get a new council in place, and it's not the rubber stamp it used to be. Right.
Exactly. And if people had a more realistic growth rate expectation- Yeah ... I think solar could cover a lot of the stuff.
But instead they're like, "Listen, only nuclear could do it," but that makes no sense because it's going to take 10 years for any new nuke to happen. Yeah. Well, even once we've built the nuke plant, we still have no way to get the power where it needs to go.
The grid, yep. Because the grid is, what, 60 years old, most of it? Yeah.
Yeah. And never been changed. Right.
Well, but I'm all in favor of new nuclear plants. Oh, yeah. Building new.
I'm not so keen about the tech bros being in charge and putting the moving fast don't break things and... But yeah, they'd probably- Chaos monkey does not work with nukes. If you had the SMRs, you could just put them next to the data center.
Yeah. That's true. But I'm from El Paso, Texas, originally.
Me too. Facebook is currently building a giant data center, which was planned quite a while ago. But across the border in New Mexico, they're buying up, I don't know how many acres, and planting data centers larger than anything that's ever been planned before.
And there's basically no water there anywhere. Yeah. Right.
What are they doing for cooling? And then Eric Schmidt's got some new deal with one of the largest landowners in West Texas, where they're going to pave it with data centers. So, and again, it's like, how does cooling work?
I don't know. Yeah. Yeah.
Empty data centers that get turned into living space with power right on hand. Yeah. Like malls.
Yeah, I was just going to say, I think that a lot of times after crashes happen, we get left with something, and then we benefit from it. So yeah, it might be better electricity. Yeah.
That would be kind of cool. Yeah. Yeah.
Especially Texas, because it's- You're on your own grid down there, right? It's duct taped together, but... Duct tape and baling wires will keep things together.
That's how the railroad- And connected to everything else ... the railroad system was built that way, too. Yeah.
Like, "Build a railroad. " Something else. It'd be nice to put the reliability back into ERCOT.
Yeah. We'll stop there. All right.
Well, I think I'm going to step in because, like many of the conversations we have with the delegates, this could go for hours. Although we'd enjoy it, and maybe the viewers would enjoy it, we've got other plans for the rest of our day today. So although, as Tom has said, this is- The end is here ...
the beginning of the end. The end is nigh. But is it not yet even the end of the beginning?
Is there a new beginning that is coming out of this? We'll find that out over time. Thank you for joining us for Cloud Field Day today.
We'll be back tomorrow morning, 9:00 AM Pacific Time for Cloud Field Day. But do keep a watch out on the social media, mine, as well as the delegates' social media. We've got a little field trip coming up before we close out our day today.
But for today, Prime Image Media, would you please shut down the stream?