Techstrong TV August 20, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone, what's the state of it spending? I guess it depends what state you're in. You're watching Tech Strung Gang.
Hi everyone, happy Wednesday. It's Alan Shimmel here, and we've got another great Textron gang to spin up for you. As usual, we have three blocks of interesting stories, and we've got, let's just say, a very interesting crew, a gang crew here to, to talk about them.
Let me quickly introduce you to our gang for this beautiful Wednesday. We've got Chris Blas, Kate Scarsella, Dan O'Brien, Dan o Mitch Ashley, and of course the dean, Mike Ard gang. Welcome.
I hope we're ready to, uh, dig right into it today. It's a, it's a busy Wednesday and, you know, hey, it's, these are the dog days of summer, but the news isn't slowing down. There's stuff flying all over the place.
Studies of people getting ready for events. Of course, a lot of agents, secret agents, AI agents, whatever. Mike, talk to us.
What do we got? Well, let's start out today with a pair of reports that came out from the Futurum Group. And one is talking about, and maybe not surprisingly, that well, there's gonna be a lot more spending on enterprise software thanks to ai.
But the other one was a study of what CIOs are thinking. And a lot of them are kind of approaching this maybe with a more flexibility in their mind than I've seen in recent times. A lot of them are reconsidering or at least thinking about where they might deploy workloads while also apparently trying to consolidate the number of platforms they have to manage to reduce costs.
And of course, they have to find ways to fund ai. Dan, you of course, are closely tied to a lot of these reports, but is this business as usual in your mind, or is the mindset of the CIO is starting to change or evolve in a new and interesting way? I think it's a maturing, for sure.
Um, I mean, listen, you know, all the priorities that have been there are still there, but we've added a lot of new priorities to the mix and, you know, the reprioritization I think is happening, right? I mean, we, we see that in a lot of the data from the CIO study. I mean, a couple things that really stood out to me, you know, cloud strategy still there, right?
But it's a maturing, right? It's not so much about will I or won't I, everyone has, we all live in a hybrid world now. The shift has really kind of gone to, I've got all these workloads and I've got all these places to run them.
How do I get the right fit, right? So we're really optimizing for workloads, surround the right mix of security, performance, and cost. Uh, cybersecurity still a very top, uh, you know, priority, uh, as is talent.
Uh, but you see other things kind of gaining in priority, like, you know, the network, right? We all know the network is the great bottleneck, um, on ai, you know, interesting to see, you know, networks shoot up in the prioritization, you know, in the latest survey, uh, we continue to see, you know, a big lean in on platforms. Obviously, the, the platform wars have been going on for some time now.
Um, what we really see in the CIO study is a simplification and a consolidation. You see vendors like Salesforce, ServiceNow, and Azure gaining AWS Cisco pulling back a little bit. Uh, but I think the number one thing that comes through is, you know, AI is pervasive.
It's everywhere. It is kind of driving every, everything, um, lot of adoption in sales and marketing and ops, really driving productivity, customer experience. Um, and I thought, you know, a side of the maturity to me was, you know, interestingly, the data privacy concern now being a bigger concern than anything around bias and halluc hallucination, right?
So I, uh, I, I think this is a very interesting, you know, the, the, the very definition of choppy waters, because here's the facts. I think CIOs, c, iOS, CISOs, C-level digital lead, digital transformation leadership are being asked to do more with less or the same, right? And so what they're really doing is going through a huge reallocation exercise there.
And, and this bleeds into the B block we're gonna talk about too. They're reallocating the mix of spend on humans to software, right? They don't necessarily have more net dollars perhaps, but they gotta, they're, they're reallocating those dollars.
They're reallocating those dollars to security and network and network security, identity security, because these are where the market demands. But make no mistake, we're in a huge period of uncertainty, though. The market is at record levels, 50% or more of the market growth can be attributed to one company.
One company accounts for 50% of our market growth of the stock market. You want to talk about irrational exuberance. You, you know, and I think CIOs inherently feel this in their gut.
They know they're making plans, but they're not built on, you know, we're making big bets on ag agentic ai. We're making big bets on AI all around at the same time. We had that McKinsey report that says 80% of all ai, uh, uh, tests are, uh, not test projects are failing.
And so it, it's choppy, choppy waters out there, right? And I, I, uh, Chris, I see you're, uh, you're rubbing your hands already. He, he's ready to go.
Go ahead, man. Take it from there. Choppy waters.
You're a sailor Fort Pierce inlet, right? Sailing the tweens, my solar powered, you know, one or two knot boats south through, through Fort Pierce Inlet is a good example of this, right? You know, depending on the tides, you get this amazing laminar flow.
Just imagine, say two miles of water, several hundred feet wide and 30 feet deep, all moving without bumping a molecule, everything's going that way. And you hit that transition and that choppy water, that choppy right before, right? It's a fascinating thing for, for people who geek out on those sort of things.
But I was just gonna bring out that, you know, McKinsey report, right? We're exactly at this spot where, on the one hand, and you know, my thoughts of current AI offerings and what we're trying to, you know, how we're, it's, we're we're off by a thousand miles. And in the CIO level, the technical level, there's a lot of pushback.
And the projects aren't working at the same time as today's topics, not just this, uh, segment. The whole agenda today shows business people are moving beyond that and saying, alright, you know, the technical folks will figure this out. There's a lot of confusion.
But if I'm planning one much less 3, 5, 7 years ahead, you know, I'm building this in, the budgets are there, and everybody's betting on the fact that it will work out. And for fasting, I think they're right. And I think a lot of things, the way we're using a AI right now by and large is, is, is off by several degrees.
And that's where, you know, that's where I get excited. 'cause that's where opportunity is. The money is right.
The business is right. This is going that way. You know, those of us down in the technical field, we're talking about the problems we're right too.
But this will all get fixed out, uh, solved and worked out, and soon is happening. Now, You know what, what's interesting is we're kind of only looking under the lamppost, right? Where the light's shining, and that's the IT budget.
Uh, Don iff who leads this practice, CIO practice at, uh, FU and research, in talking with him about some of this data, one of the really interesting things was first time he's seen, uh, that the actual total IT spend outside of out, it was crossed over and was greater than the IT budget itself. So the complexity of what IT leaders, whether it's CIO, ciso, CIO, whatever it might be, CTO, is they're navigating what they're needing to do for the organization. Both the equip IT and prepare it for ai, but they're also doing it in a sea where, you know, it's kind of all the waters are crossing at once.
'cause they don't control what's happening necessarily, what's happening out in the business units or in marketing or in finance, other people or HR that are, that are also spending their money on ai. Not only that, but also SaaS systems, application technologies, that kind of thing. So it's, it's, it's never been more complex for a CIO to, uh, both be part politician and, and relationship builder to execution, make things happen and prove you can deliver value.
I, I agree. And, and I think one of the other issues is, at the end of the day, from a CIO CSO perspective, we've always have had issues. And, and I think this is where AI helps, is it's, you know, looking at all these logs and everything else, and it does bleed into, um, the next block.
But we have had issues with bringing humans in to do something to, to look at millions of, of events. And, and we need, we have needed something more AI to give more accurate, um, levels of, of alerts from, and I'm just talking from a cybersecurity point of view. We have needed this, um, to, to have more intelligence with the being able to review the logs and, and, you know, give events that when threat hunters are, are looking at these events, they're, if they're not coming up with a bunch of false, false positives.
0, right? This augmentation for humans is really needed. The only thing that I get concerned about with AI and where we're going happens when I, when I, I just have to bring cloud in because I sometimes think cloud has been one of these, you know, let, like these cells of, you know, look at, let's put everything into cloud and, and it's gonna be free.
And now all of a sudden, you know, companies are being charged so much. That's the only thing I, I, I get worried with the, with ai, like, are we going so fast that it's gonna come back and bite us? Sort of like the cloud.
And it, it's not that cloud hasn't been great and promising, it's just, it's been really expensive, right? And that's why you see on-prem, and that's what I wonder with ai, since AI is not, we don't have a really good road in, in, you know, on how it's gonna be playing out. So are we putting a lot of our apples into this one basket and then it's gonna come back and bite us and be really expensive?
Hey, if, if I can, right? So this, think about this in this whole, this whole episode today, like block to block, it's all the, uh, different aspects of the same things, but, you know, quiet aware, over the weekend we put together a small business, uh, solution for manufacturing, and it was really more of a exercise of principles and so forth. Um, we are actually going to sell it.
I think we can probably do quite well doing it, but as, yeah, on so many levels, um, it didn't take very long to put together whatsoever. Um, it's up and running now. Um, we're weeks ahead of, of the conservative schedule we put together a week ago already.
And it's to, to your point, uh, Kate, you know, the actual AI parts of it, they'll be as an ai, as a civic ai, you know, they'll be a teammate. They're the first customer. We know who they are, they'll pick a name and it'll be on board and it'll do things in the system.
It's not going to be clawed or Chad TBT. It doesn't need to do a lot of stuff. It needs to understand the semantics of the business which aren't complicated, and be able to consume human readable things in certain ways and make sure everything's attest in to the point internally on a small server, you know, can use cloud access doesn't need it as long as power is up in the, in the facility, everything's running just fine.
And be able to produce, you know, if human readable text, you know, for other, for the human teammates in the company. And that's where it's going, right? So the big huge cloud AI absolutely has its place, but we don't really need, ultimately global.
We don't need 10 massive data servers. We will have tens of millions of small notes. And there's two things in the survey in the CIO thing that gimme cause for pause.
First is, you know, I read it and I went, wow, return to sanity. CIOs are evaluating workloads and fit for purpose, and we're gonna, you know, run 'em on the right platform. But then I remember CIOs tend to be autocratic.
And so are they just gonna try to push everything onto a couple of platforms and make everybody conform? Or are they gonna be, you know, a little more flexible maybe this time out? And can we find a happy middle?
I don't think they can be autocratic. Uh, what I was saying about the budget, people can spend their own money shadow. It is no longer, is no longer in the shadows, right?
It's, it's all it. So they have to craft strategies. And that's one of the things about platforms.
Platforms are different than just a collection or a suite of products. And it isn't just about integrating a vendor's own products into quote unquote a platform. Any platform not only has to support their products, but they have to have very strong integration capabilities because there are other tools, you know, the smart vendors recognize they don't get to own everything anymore, just like the smart CIOs recognize that.
But they also have to offer some kind of a data fabric so that data can be shared across those tools, across those products, not just within itself, but also to others. And when you to other products, and when you layer on ai, that's the grease to the skids. That's the ability for agents to actually do work across what we would think of as silos today, whether they be work silos or data silos.
So platforms mean something different than just a, a nice brochure of five products instead of five individual brochures. But that's an argument. What to allow CIOs to be more autocratic.
You can't go out here freewheeling and free styling. Don't think it's gotta fit. I on the company wide platform.
No, I don't think it is. In Mike's article, oh, sorry, Alan, go ahead. Oh, no, I, I would, Kate, to your point about the cloud, look, I, you know, I was here, I think we all were here when the cloud first came on board.
I think the whole myth of the cloud being a money saver was just that a myth. Yeah. Right?
The cloud is scalable. It's burstable, it's maybe more efficient. It, it, it takes a lot of the nuts and bolts of running the infrastructure out off your plate, but it's not necessarily cheaper.
There was always a point, I remember being out in Boulder talking to Rally Software, Mitch, you remember Rally Ryan? They, they wrote the book on Agile and they already had a study, and this was in 2010. They had a study of at what level of usage do, are you better off going back private off cloud, right?
Because the cloud just becomes much more expensive. I, I think we are gonna see that at AI too. But I, I also wanna call out, Dion did great work in that CCIO survey, but there's another futurum survey out, um, on, on enterprise software market.
It grew to 340 some billion dollars, but forecast to go to about 600 billion then isn't in a year or two is 600 billion. I I, well further up Here. Yeah, further up, You know, and, and, and forgive me, is this a Keith Kirkpatrick?
Uh, Correct. Yeah, Keith, the Author. So let, let's give Keith a shout out on that.
Um, personally, I don't know. I, I think if it does grow that way, it, it's not net net new budget being added to the mix. It's, it's coming from somewhere else.
And again, that's what I want to kind of end my piece on this segment on, which is we, are we taking from Peter to, are we robbing Peter to pay Paul with, with allotted, you know, moving around dollars, but not necessarily. That's What our proposed to Alan, right? Like, I mean, I think what, what we're generally seeing in the study is we're gonna let the innovation run and the innovation's no longer cloud the innovation is ai and we're gonna clean up kind of what's matured and played out, right?
I mean, to your point, I think that the challenge with cloud was, you know, it was the answer to every question. And you know, it's just not the case, right? It's really good for some stuff.
Uh, but it's, I, you know, not necessarily what you need for others. And, you know, I think we're gonna probably repeat a lot of the same pattern with ai. You know, we're throwing AI and everything, but AI may not be the answer to everything.
And, you know, that will mature over time. We'll kind of see where there's clear ROI for it. Um, and then, you know, we'll probably unwind some of what we've done.
Um, you know, it feels like history repeats itself and we're just in a new pattern, you know, in a new cycle. Sorry, same pattern, uh, new cycle. So I'm gonna leave this segment with this 'cause I'm gonna claim last word.
Satya Nadella says, we're no longer a software factory. We are intelligence engines. That's, and that's the big thing.
You're watching text and gang. We're gonna come back and talk about service as software. You, we'll be right back.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in. Yes, our, our guests have picked up on that.
There is a continuing theme here. And the next thing we're gonna talk about is, well, what is happening with IT services? Historically, I think there's been reports that it's estimated that for every two bucks spent on software, there's nine to $10 spent on services.
And well, that's a little bit crazy when you do the math and you start thinking about it. And we have CIOs that are trying to figure out, well, how do I kind of rebalance this budget? And a good place to look is maybe how much we're spending on services.
Alan has a piece on digital CXL talking about this very issue. Um, Alan is, is there hope here? Is this something we're gonna see happening?
And what will be the impact on all those IT services firms that are counting on this revenue? So, first of all, I, I gotta give credit to where this came from, right? I, I picked this up on LinkedIn.
There was, uh, some articles from our friend Chris Hoff. And I, I, how many of you know Mitch? I know you know Chris.
I don't know how Kate, Chris, I mean, Chris Hoff has been one of the leading lights in security for 25 years from security blogging first got off, Chris was one of the leaders of his good friend of ours then, not that he's not a good friend now, but he doesn't blog anymore. He mostly does LinkedIn. My, he runs security at, at, uh, last pass.
He used to run security at Bank of America and some other places. Brilliant, brilliant guy. Him and a, a former of VP Corp Dev.
Now he's a venture capitalist board member kind of guy. And I'm blanking on his name. I apologize.
It's in my article too. Old Ari. Yep.
God. So originally Ari wrote an article that said much what you said, Mike, the, the soft white underbelly, the, the dirty, dark secret of all of these software and software as a service is that they're really services, right? And it was primarily talking about sock running socks.
You still need the sock. No matter how much software you buy for your sock, it's still the sock guy who's sitting there running it and doing it. And that what we're gonna see with AI is shifting to what he call service or software replacing the service element with software with agentic ai.
Hof took umbridge with this and said, you know, soc people are snowflakes and they're each individual and they can't be replaced with software. I don't necessarily agree with that. I do think a lot of what they do will eventually be replaced by software.
But it, it goes back to what we just spoke about. Are we just gonna reallocate what we spent on people on software? And I don't want to be a doubting Thomas and Mitchell, I know you're a big fan of Agen, ai.
Ai, but boys and girls, show me the money. Show me the money agentic AI has not shown. And I'm sitting here telling you this, you want to throw stones at me, throw stones.
But as we sit here today, agentic AI has not shown that it's scalable, doable. And let's start throwing people out the window because it's gonna take their place not happening. It does.
It's great. Counter is for science experiments. Go ahead, Mitch.
My counter is neither did the cloud at the beginning. So yeah, I mean, we're, we're, we're overhyping it. And so of course we have unrealistic expectations about AI and agent.
I think I, if, um, if you go back to theory of constraints, 'cause we all love from DevOps and software development. When you take a constraint and you either remove it or you, you drastically reduce its impact, that's when systems change and when they start to change. But you have this evolution of per evolutionary period where you still do things like you used to do them, you just used the new technology to do it a little better, a little faster.
And we've been on this treadmill now of automation, right? Productivity improvements, how many more messages, how many more SOC issues, how many more, uh, you know, issues kind of run down in, in an IT organization, whatever it might be or, or claims I need to process. The thing about ai, what it removes a constraint is you don't have to have someone touch it all the time.
We'll get more and more to this place. We're not there yet, but we'll get there is, is it's able to deal with some things in real time that a human would have to deal with, but it can do it at a larger scale. And once we kind of tip over that part of the curve, that's, I think when we'll see jobs change, we'll see things, uh, you know, it's redefinition of managing agents instead of managing messages, managing issues, things like that will change in, in the work.
But, you know, we're not there yet. It's not happening. And, and of course, you know, uh, ri is he, he is a venture capital investment guy.
He's talking about all the companies that have been invested in that are early startup stages. So that isn't real yet, right? Those are early companies, they'll come along.
But, uh, that's what he's gotta, he's gotta promote that what, what he's investing in. I mean, I would agree to Alan's point that AI companies are parsing the word is in a c clintonian fashion. And we're a long way from these AI agents actually doing any Of this stuff just yet.
Yeah. I, I, you know, you know, so, so Alan, you know, you know, again, I'm not gonna litigate the current state, you know, you know, from a financial investor, you're right. You know, it's, is a particularly dog's breakfast.
But Mitch, you're, you're exactly right as well. We're at one of these stages where we, you know, if in fact this is a serious, you know, transition and it is, then we should expect that what everybody's doing right now is intrinsically wrong. Right?
You know, it's right bits, but it's a, it's a, it's a mess. It's not efficient. They're not hitting goals.
And, but I, going back to the, the actual topic of this, you know, uh, services as software and that, uh, manufacturing, uh, case study, uh, referenced in the last segment, that's literally it. You know, we're replacing all the software in a small business with just the service and the software is delivered intrinsically and to the point ally parts of it, you know, the, the, there's enough cognitive capabilities in a tiny little LLLM, you know, properly done in a, in an environment like that, that you don't need to go out and buy the new stupid software. And you shouldn't have to know about, you know, software product brand name version because you're a bloody manufacturing company.
And we've been promising that for decades. But, you know, we're literally doing this right now. And I think that, you know, it, as I say this, this isn't our, our core line, but it's a, it's a exercise.
It should be profitable, it should, you know, do some good in the world. But as I look at our, our list today, that's one of the things, you know, I would like the CEO of this tiny little company to stop being able to tell me the version numbers of the software he uses. It should just be a service.
And the software itself will be delivered and designed by us in real time to fit the needs. Chris, I'm not disagreeing with you on that, but when I wrote about service to software here, services code for humans, right? We're replacing humans with software.
Well, yes. Uh, yet, you know, I'm on the fence on that one. I have the same concerns as everyone else.
But you know, when I, as a company, as wire wire, we will have humans running this. You know, there are humans. We have jobs, you know, already speced of, and, and, and That's exactly this work.
How's point that you're going to need humans running it? Look, this is why I think the CIOs are facing these complex challenges because in the pit of their stomach, they're making a bet on something that is as yet unproven. Totally.
Dan, we're announced today. Few terms, signal is, is, is live. And, and we're, we made a, we made a bet.
I'm I that my article will be up. You, it's up. You could read it, right?
When you look at where I, I've been on a few signal calls now, and one of the things vendors, 'cause it's been mostly with vendors, not end users ask is, well, how are you gathering the data? Where's this data coming from? And when you look at where the data from signal comes from, it's basically a, I call it a third, a third and a third, one third is we have this exclusive deal with G two who has millions of people who are voting with their fingers and giving valuable feedback.
And we have the exclusive feed from that data that we're then grabbing. And, and again, using ai, putting that into the, to the mix of, of the signal, if you will, that helps calibrate the signal. One third comes from the exclusive opinions research and analysis of the RUM analyst.
Again, not necessarily ai, but it's the, the future of analysts. This is their opinions, this is their research. One third.
And then when I say a third, it's not exactly a third, a third and a third, but close enough. One third comes from agentic AI combing the public domain and grabbing all available information on that given topic, right? And, and adding that on top of these two exclusive feats.
So you got three pieces of the pie. Maybe they're not the same size, one third one there, but there's three pieces of the pie, Dan, we're betting that the agenda AI does a great job on that, Right? Yeah, it does.
I mean, I think we've seen it already in, you know, the results that, that we've seen internally, you know, excited to reveal those to the rest of the world tomorrow. Uh, I mean, just to jump back and ground us here, i i, the, the fact Phrase, Chad, remember we taped this the day before we revealed it to the world. Go ahead.
Software, you know, credit to Phil first, who I believe coined the term, you know, he was really talking about in the context of IT services and IT consulting and taking these, you know, very repeatable patterns of behavior and codifying them in code, um, and kind of, you know, replacing the human labor with it. And, you know, I'm glad you used the signal example, Alan. 'cause you know, we've done exactly that.
You know, Brad Shiman, who, you know, had a lot of input, um, as the lead analyst on our first signal, he has created research analysts and research directors, uh, agents who are playing those roles. I mean, historically, when other firms would go about this, there would be some junior analysts who would do all the data gathering and all the synthesizing. And, you know, we are using AI to do that today.
You know, we have created AI agents who go out and comb through all of the vendors' product documentation and their case studies and everything that's available publicly that would be available to a prospective buyer. And as you've said, we've obviously layered on, you know, some really proprietary intelligence that is not out there, you know, through both G two as well as few terms intelligence platform and everything we're collecting. But I think it's actually a perfect example of, uh, services to software.
You know, the, the role that a junior research analyst would've played in a lot of the data gathering is being done ag, uh, genetically. Um, and, you know, we still have that human in the loop, that market expert who can comb through this and really make sure that it's credible, that it all stacks up. And, you know, really where we've done is we've shifted, when we talk about this a lot with ai, right?
Moving the human to higher value work, not replacing them. You know, Brad is able to focus on all of the, you know, his opinion on the go forward prediction side of things versus spending days and weeks and months gathering and synthesizing information, right? So it's actually a perfect example of this in that there are probably a couple junior analyst roles that existed, a different analyst firm as they go through this process that we have done away with.
We have started, you know, from a place where we don't need that at all. Um, and we have shifted the human in the loop to that higher value work, which is much more predictive context to where versus spending a lot of time summarizing the history. And By the way, that, but let me hear me out by the way, that was exactly H'S point, that the SOC analyst part of what the best of the SOC analyst intuitively are able to look at that data screen and, and see something, or see a threat, see an attack, see something that, that the software may not necessarily pick up, but it's, it's, and, and that's the point where do we draw the line between what, what an AI could do versus truly what the human needs.
Chris, I'm sorry, go ahead. No, no, please. Uh, and it's, it, that was an interesting riff on this, uh, because I, I was gonna take this and I am gonna take this in a slightly different direction, and I'm glad Dan, you went down that path because in the IT space, you know, where we're all focusing and there's the big data centers and the big, yeah, there's gonna be shifting around.
Will there be more or less jobs? Fantastic. You know, interesting conversation.
We don't know. Um, but Donna, my wife, you know, on our marriage certificate, uh, I'm listed as a forklift driver, and she's a word processor, which was a role, whole floor is a word, processes in the eighties. And they were humans.
They had lunch right now, now they're, they're an app. But I look at it and using the, the, uh, case I was mentioning earlier for the, uh, services replacing software. Because in these small companies, they have no services.
They may be an IT person who comes in sometimes, you know, the owner's brother-in-law or whatnot. Um, and that's it. But what they spend on IT is licensing on software.
And in the case we're looking at and related and, and small medium manufacturing. Um, we're not paying any, you know, we're, we're, there isn't any licensed software now, the CAD software, you know, I'm not ready as quiet wired to replace that just yet, but yeah. And that can all be generated in open source too.
So millions and millions and millions of these, you know, tens of millions of small companies are spending all their IT spend on software licenses and, and, you know, subscriptions and whatnot. And a lot of that's gonna get replaced with software, with services as software. The software delivered into the company, 7 24 will be the service.
And they won't know what brand it is, but just their, just their partner, You know, this is all lovely, beautiful picture. Reality is the following. We have spent an inordinate amount of money first on IT services to compensate for the fact that the software is too damn hard to implement.
And then the second thing is, we have so many other people who are doing manual labor and nonsense tasks all day, because the software's too damn hard to use. So now you're telling me that the very people who made this problem in the first place are gonna show up with a bunch of agents to solve this. Well, that kind of sounds like Bullwinkle this time, for sure.
So I'm kind of dubious of the whole thing to be honest, and we'll see how it plays out. Well, You should be dubious, but, but again, you know, you've made a lot of specific assertions, right? And maybe you're right.
I don't think so. I think this time it actually is true. So we'll see all, Okay, we'll always in the middle, right?
And you, do you believe in Santa Claus in the Tooth Fairy? It's okay. Thank you.
We're gonna, I do. I do. You do.
Okay. Because I wanna believe of, I wanna believe, I wanna believe, Hey, we're gonna take a break. We ran a little over.
Let's come back and talk about fusion confusion. Oh, boy. You're watching.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com, home of security bloggers network. And we're back and continuing our theme here on when mounts to essentially re-engineering.
But Microsoft is now out talking about, well, fusion, and it's as much as an idea as it is a piece of software. But the core idea is that somehow or other, all the end users and all the professional developers are gonna link arms and have a kumbaya moment. And we're all gonna develop software together happily ever after.
You can tell by my tone that I might be a little bit dubious about this too. Mitch, though, what's your take on what's gonna happen here and how all this is gonna play out? Well, first we need to check if somebody puts something in your Wheaties this morning.
Kind of got, got you. Agitated. So, so what this is about, Microsoft uses the, the word fusion, uh, and not as some new kind of food, you know, kind of combining this with that.
But actually people working together, bringing together non-technical people with developers or citizen developers with professional developers, and they, they're, they're starting to change the use of that term to more full stack. And what they mean by that is not the traditional full stack that we think of as the, the software developers build around, but the idea of coding was, so something was really difficult to get a non-technical person to be able to do. So you use some, you use some, um, you know, tools that help automate some of that for you.
Now you can vibe code things. And what it's changing is using ai, you can use AI to help prototype ideas. So now the expectation is becoming a product manager could use Cursor or, um, you know, visual Studio with whatever, you know, with that, uh, uh, whatever LLM in the background as actually a way of prototyping or demonstrating some ideas of what they're thinking about.
It's no longer just a requirements document or a PRD that they have to put together. Matter of fact, I heard, I don't know if this is true, I heard one, one person say that that's part of their interview process is, if you're gonna interview here, is in a product role, you need to pick an app, pick a tool, and go vibe code it and show me, I'm not gonna looking to deploy what you put together in production. I'm looking how you can express your ideas through leveraging AI tools, which goes back to my point about AI isn't gonna take your job.
It's somebody that knows how to use AI better than you do. They'll take your job. So that's this idea around kind of full stack moving from this, moving from Fusion, blurring the lines a little bit, but I think it's more about, uh, using tools to try to express things closer to the, the end product that we're trying to build.
And I actually think it's, it's, it's needed. Oh, sorry Chris. Um, I, you know, at the end of the day, you know, trying to get the, the dev people speaking with, you know, the ones who are trying to make the app and let's just add security cybersecurity in there.
It, it's, it's been a mess, you know? And it's been a mess for years. I mean, this is, I, I am, I hope, oh yes, I do believe in Santa Claus.
I really hope that's gonna happen because we, it's, it's so needed. It really is needed. Well, so is the United Nations, that doesn't mean it's successful, right?
Right. Yeah. That, that's almost you.
And like, Because, because here's what the Grinch is think, and the Grinch is thinking that this is, you know, low code, no code on steroids. One more time. We called it vibe coding.
We're gonna dress it up with a bunch of end users creating, um, software that is, once again, maybe not very scalable, certainly insecure, and too hard to use, right? Ugly. And we're gonna dump this on a bunch of professional developers and tell 'em to go fix it.
And we don't have enough of those people. So maybe we're gonna hope that AI agents will help them fix all the software and the end users are creating this. Doesn't sound good to me.
Haha. Bug, In 35 years, uh, working in technology, there has been almost no technology involved in my career whatsoever. You know, such a tiny, tiny amount of it.
You know, what's been been important all along is the teams and the people and the ideas, right? And the technology just gets in the way. And this is what makes, you know, folks like you, Mike, cynical because you've seen it over and over again.
But it's the same as, you know, this is a very short period of time. You know, because we've seen something before, doesn't mean it's inevitable. It means it's, it is a coherent pattern that can be expected to pop up again.
And it may in fact be the only pattern. But, you know, let, let's be clear, you know, human history, as we talk about it, is 200 generations. You know, this whole topic we're talking about is three.
And most of us, you know, on this, on this show, at least, you know, me and anybody older has been alive for at least two of them, right? So we've only gone through a couple cycles so far, and we keep repeating the same mistakes. But I, and, and Mitch, you know, you say, I'm, I'm usually in the middle.
This one, to be clear, I'm not in the middle. I have picked a side. I'm so enthusiastic about it.
I spend all of my time around folks like Mike trying to prove me wrong. And I don't think I am. I think we will actually close the loop, effectively speaking this time around, so that we actually have teams of people making solutions instead of, you know, competing teams of people who hate each other on the same side, trying to get budget so that they can not get fired.
Well, convincing Mike is, is more like, uh, tilting at windmills. I think it was the old phrase. But you, you keep trying, you keep going.
You Don't try to convince Mike or Fred Cohen. You just try to, you know, rebut enough of their arguments that you might not be wrong. That's all I'm looking for.
Skeptic. We wouldn't have to prove anything. Mike, I'll be your poncho to Don Otte anytime with the windmills.
It warms my heart that my grandchildren are gonna enjoy the fruits of your efforts. 'cause it's, that's how many generations? Well, honestly, I, we, we talk about that a lot.
But seriously, look, look, we're thought leaders in this big global thing. I have plenty of plans. I know I'm not gonna live to sea, but we gotta be able to plan past the horizon.
Planted tree won't live to see, particularly at our age. Well, thank you for that optimistic look, Chris, um, I you call him the grim reaper. Anyway, well, To be happy now, that's amazing, right?
But, but you let me do, bring up one thing about ai. It, it comes out here and it, and it shows itself in our other, uh, uh, blocks today too. The thing about AI is, it, it, it, as an umpire, it calls them as it sees them, right?
It can't be, theoretically it can't be bought, bribed, paid for it. It, you know, what you give it two candidates who wrote code, it's, it's gonna pick out the one who wrote the best code, right? Regardless of whether that candidate sexual preference, sex, race, whatever, is, um, with, with, in the instant case of Signal, Dan, that we spoke about.
I don't care how nice you are to the analyst, the research is what the research shows, right? You sucking up to an analyst or flying them out for a nice lunch or dinner isn't gonna help it. Um, in terms of being a developer, what it develops is what it develops.
No matter whether it's a, whether you're, you know, some developers take a lot of time off, some developers are great teammates, some aren't, some are solos. It, it, it is an impartial, uh, just even, right? There's no, there's no there plays on that.
Yeah, exactly. And I'm not sure I'm buying that either. 'cause I can tweak that LLM on any prompt that I want to have it come back with whatever I need it to say.
I'm getting you a tinfoil hack for the next show. I Here to tell you that is, that is detectable as hell. Go ahead.
You know, we, we watch these, you know, certain billionaires try to get their LLMs to, you know, say the sky is green and the LLM acts weird. And I'm here to tell you, that's a tactical thing. You know, you can't make an LLM lie, but it'll look like a liar.
It'll sound like a liar to other LLMs and people. Have you seen Washington lately? Because, you know, and everything.
Yeah. Let's, so what's the news? So wouldn't have For a little While AI agents there.
Well, let, let's Cynical about this. I know we've said, you know, this sounds like a lot of what we've heard before, um, and it's just a new effort on it. But I think, I think it, it is a lot like we've heard before, because ultimately you're trying to bring together two peop, two groups of people who really meet each other.
You've got a group of people who are trying to build solutions to help with people who really deeply understand those problems. And, you know, yeah. I think this is obviously just another attempt to try to eliminate that friction so that the people who understand the problems can help the solution builders build a solution that really, really works for the user Benefits from someone's lips to God's ears.
That's what I, Kate, Kate, what do you say? Well, and, and, and needs to be secure at the same time, right, Dan? Of course.
Yeah, of course. So, but Sorry, I, I see benefits down this path If you start winning. So Michael will be a little more, yeah, that's what it'll take.
But no guys, seriously, Kate, to your point, when we start including security people as the builders, right, we'll start having more security in what we built. And, and that's something that needs to be addressed too. But that'll be for another show.
Gang, what a great gang we've had today. I appreciate y'all, I appreciate the comments, the opinions, the thoughts. Mike, thank you as always for putting together our, our, uh, blocks for today.
We will be back tomorrow with yet another gang, as usual, who knows what we'll talk about. Then you'll have to stay tuned by the way, you can catch the gang. If you just want to catch individual blocks, they're available on our Tech Drunk tv, YouTube channel.
You could also watch on Tech Drunk tv OTT if you are onto Apple TV or Roku, or, or Amazon Fire or iOS or, or Google Plates all available there. And of course, on Text Drunk TV itself, or you might be watching this on our Text Drunk TV Network when we stream it every day at nine 30 on LinkedIn, Facebook, and Twitter, and all of our text drunk sites. So lots of places to catch this, as well as Text Drunk tv, following it.
Um, we did release Signal today, so go check out all the news around FU Signal. Interesting stuff there. Some good AI stuff.
Chris is doing stuff with quiet ai. We've got all kinds of stuff going on, but we'll be back tomorrow. Until then, this Alan Shimel, on behalf of the gang, have a great day, everyone.
We're out. Hey everyone, welcome back here to Techstrong tv. My next guest is joining us from Switzerland.
Today. I, you gotta love the internet. You just talk to people all over the world, like they're sitting here with you.
Uh, it's his name's Andrea Medi. Andrea is the CTO slash CIO over at Sonar. Andrea, welcome to Textron tv.
It's great to have you back, Alan. Thank you very much. Uh, very happy to be here.
Absolutely. So, Andrea, before we get into kind of our topic of discussion today, let's spend a few minutes or moments talking about you, right? C-T-O-C-I-O.
This is a combination we see more and more of. I'm not gonna say it's common. Not every company does it this way, but it's not unheard of either, right?
Yeah. Where the CTO and the CIO role is, is under one person. Yeah.
But it takes a special kind of person. Let's hear a little bit of your, of your journey to being and why you are the right person to be both CTO and CIO. Yeah.
com in the us which is probably familiar to a lot of your, uh, American viewers. And also me. I'm a, I'm a customer.
There you go. Very familiar. And also helped, um, you know, start the Chase uk.
Um, and then I said, okay, it's been a couple of decades. I think I need to do something else. But I guess throughout all of that, um, you get kind of an exposure to, uh, a lot of fast moving technology, a lot of governance, uh, a lot of compliance, a lot of risk management, and those type of things.
And I suppose that's maybe why, um, you know, I have a balance between, um, these two different dimension of okay. Leading a tech organization and get those things done, and also have more maybe of the information officer, uh, type of, of, uh, considerations in what we do. Sure.
I mean, it doesn't come any more highly regulated and mission critical than, than a large, you know, top 10 bank like Chase. Absolutely. Yeah.
No, it's been a, it was definitely an exciting place to be. I cherish all those years and all the learnings. Uh, some of it was maybe tougher than others, but, uh, you know, uh, you, you, you, you learn as you live for sure.
It takes, it takes, what is it, iron on iron to sharpen or some, there's some yeah. Thing about that, but you, you know what I'm saying? Um, Andrea Sonars, look, to me, it's a well-known brand in the, in the tech world.
And I think for most of our audience it is as well. But there might be folks out here who are not familiar with Sonar. Yeah.
Um, give them, you know, what's the sonars kinda story? Yeah. So I, I think what I, I did for a while when I came into a group and said, you know, I'm from Sonar.
Uh, and I would say, and you may not remember or know what that is, but if I say Sonar Cube, which is the product that most people have been exposed to, I would've be like, oh, yes, no, I know what that is. And the origin story of that, uh, is, is, uh, is pretty cool. Uh, it's about 16 years ago, and it's three gentlemen that get together and they find through their shared experience that they basically have the same problem.
They're leading engineering teams, and they keep having to go back and re-explain what good looks like, be it in terms of quality or in terms of security. Uh, and they were wondering why, why isn't there a product around that tries to help engineering managers and engineers to kind of get consistency? So we all sit around the table, we agree on some type of standard, then we all walk away.
But the result two months later is things don't really look the way that we had just agreed. Um, and they basically built SonarCube on this basis, but they had, uh, a few key principles, um, right out the bat. And, and they were that there was a bias action.
So it's not a reporting platform, it is a platform to help the developer get an actionable insight that they can do something about right now. Uh, and that's, this, that's probably what makes us stand out a little bit, um, certainly from the past where when we come up with an issue, if that's a security observation, a code smell, you know, and other type of blocker, um, we give people an explanation as to why that is an issue. And we also give documentation.
That's the description of how you can solve this. And these days even we have an AI code fix that if you'd like to, you can also get an actual detail proposal, change of code that you can go and fix it. Um, and, and that means that we were very early on, um, kind of not really in the shift left, but in the start lefts game, uh, I'm writing code, I'm raising a PR already on my IDE, I could have sonar tube, IDE plugged in.
I can get some feedback there. I raise my pr, it gets reviewed by the SonarCube platform, and I get actionable feedback and I can kind of protect my code base, um, from, you know, unintended consequences of poor, uh, code in terms of quality or security. So I can block the pr and in that way I can make sure that, uh, my overall code base is safe.
And the reality is, of course, uh, nobody just works on new stuff constantly. We're also having to do a lot of enhancements, et cetera. So you can imagine you take a piece of code that was maybe before you had Sonar Cube, and you start taking that code into your IDE and you make a change, well then you're now also fixing the things that are trespasses from the past, uh, because those you also get feedback on.
So in that way, it, it's quite a wholesome, you know, approach to it. Uh, and whether the developer is, you know, a human developer or an ai, uh, generated, uh, code base that you've made it edited, I mean, it really has no, um, makes no real difference. Um, if you're using an LLM, you are, uh, most probably, um, getting code that is non-deterministic in terms of the outputs.
I, I saw that recently at a, at a big session. Uh, i, I think it was Stripe Sessions in San Francisco where they wanted a demo versel on stage. And it was kind of all cool.
It was a little feedback form and uh, you know, one of the founders was up there doing his commit and, you know, they had the feedback form, which was to get some confetti on a screen, and the confetti came down on one side of the screen and he sat down, very proud of him himself, and he said, oh, that's funny. We've done this 200 times probably in rehearsal, but it has never come down on that side of the screen before. So the non-deterministic output that you get, um, having a deterministic platform like Sonar, which is based on thousands of rules, uh, is a good balance, right?
And, and it is kind of just a little bit common sense that you want to have this type of, um, um, friction on that code because some of that code can be generated quite quickly. And I think most people will recognize if they've done some development that, you know, if somebody comes with a two line change change, you can kind of argue about that for five days. If somebody comes with 500 lines change, it takes about three seconds to say, yeah, sure, I'm gonna approve this.
And you know, what we see, and I think everybody recognizes is the generation of code is getting quite volume less in terms of what we see the LMS generate. Um, so having, um, you know, a trust and verify approach, which is kind of what we are calling it, uh, is, is probably quite wholesome. And especially if you're working on critical systems, it's obviously much, much more important and really something you must have, um, and, you know, uh, lots of other systems, obviously's, yours who use it, but certainly for crucial, uh, critical systems, it it's a crucial, um, element to have in your developer workflow.
Absolutely. You know, we had this conversation yesterday on, uh, a, uh, uh, a webinar that I was involved in. I was moderating it on panel, which is, you know, at some level codes code.
And whether that code was written by a human or by an, uh, ai, we shouldn't treat any code as secure or Okay. Without having testing done, right? Yes.
And, and, and, and so it only makes sense. I mean, AI code doesn't necessarily have a, shouldn't have anyway, a scarlet letter, you know, attached to it, just 'cause it wasn't generated by humans. Now we could look at code by humans and, and, you know, within an engineering organization, we could say, you know what, Andrea usually turns out amazing code, much less, you know, much less bugs, much quicker, uh, deployment versus, you know, some junior developer that really, you know, we need to watch everything he does and go through it.
And, and there is, I'm not saying that's not the way things happen in the world, it is the way things happen in the world, but it, at some level, we should be saying, all code needs to be checked, all code needs to Be tested. Yes. No, I agree with that.
And I, I think, uh, I mean, I think we're over this, but, you know, I, I don't, I mean, acting out of fear, um, in terms of, you know, having AI as part of your productivity, uh, efforts of, of, of, you know, yeah. Just being productive and being able to put out more, um, I mean, everybody should embrace that. I mean, it would be kind of totally silly not to.
I agree with you. Right? Yeah.
Totally silly not to. I think what was interesting, and, and we actually issued that this week. Uh, we, we had done some analysis where we basically said, let, let's generate, uh, a set of tasks.
This happens to be about four and a half thousand tasks, and let's actually put those tasks through LLMs to see how they solve those tasks in terms of coding. And we then took SonarCube and analyzed this and did some other analysis. And, you know, uh, the trust and verify is kind of from this, uh, uh, experience we had, and the evidence that we put out is pretty important.
And I, there was some striking data, um, I felt in the report, and it's available on our, on our websites, uh, to, to pick up for free. Uh, don't worry, there's no kind of form you have to fill in. You can just download it and, uh, and read it.
Um, that's great. And for example, when we produced a code from some of these different models, the amount of code that got output and created was really, really, really starkly different. I mean, Claude Sonnet, uh, four was producing something like 370,000 lines of code where Open Coder was producing about 120,000 lines of code.
Now that, that's it, like a huge difference in terms of that. And then you come into, well, okay, is that then more complex code? Is there a whole issue here of saying, well, you're sitting as an engineer, you're trying to review this output.
If you constantly have this volume less output, um, you know, what, what does that type of mean? Um, then we looked at security and, you know, we saw about 70% of the, the vulnerabilities that came out of example outta slaa were considered blockers. Right.
Again, you know, another very, very big number. And, um, across any model, we found that, you know, there was a very, very, very high propensity for code smells, which is, you know, not necessarily big issues, but long term you're gonna get problems and issues. And I think, think, you know, you have to technical building up Yeah.
Basically technical debt building up. And I think every organization needs to figure out how do we make sure to balance out this? I mean, as we, you know, as practitioners, we know, I mean, there's no, the, the perfection is, is, is, is one thing.
Progress is probably more important here. Um, but keeping an eye and figuring out how do we put in the, I call them guardrails, if you will, but you know, more this trust and verify approach, specifically as we know, we'll have a high and higher propensity to use LLMs in our software development work, um, because you should, there's productivity gains and, you know, they're real to a large extent. Um, but figuring out just how, how we get a good seesaw on, on balancing non-deterministic with deterministic.
Um, and then obviously we try to help also, not just to find the issues, but also to solve them, um, and using AI for that. And there we may have a little bit of an advantage because, you know, we have your code, we know exactly what rule it is you triggered. So we have the context, we have that rule description, we have the solution.
When we package that together and send it to, you know, whichever LLM it is you, you choose to use that we offer, um, we get, you know, quite high acceptance rates on all of those because it's very precise. Um, and, you know, the output is very, very, uh, strong in that sense. Yep.
Couple, couple of observations. First of all, you know, how does the amount of vulnerabilities per x lines of code or however you want, you know, measure that compared to code generated by humans? Is it that much worse?
I think it's not, uh, I mean, at the end of the day, the code that the LLM is producing is based on the code that it has access to, right? So you have to ask yourself, where is all that code coming from? Well, it's coming from humans.
Mm-hmm. The other question then to ask is, well, if it's, if it's sourcing code from the worldwide, you know, uh, internet, so to speak, and that code then to some extent must be public, is it then the best human code that's being produced, uh, and the private source code that it obviously cannot get hold of to be able to generate what is generating? So, I mean, this is a little bit of question, but, but to me, but it, it's a mixture of everything, right?
It's a mixture of both the, the worst, the worst and the best. Yeah, exactly. You know, I went to law school a hundred years ago, there's an old saying when it comes to evidence, the fruit of the poisonous tree is the term in evidence, right.
But crap in is crap out. Yes. Right?
And, and that's At the end of the day. Yep. And, you know, this is why there's an argument to be made that we need to develop.
And, and maybe the anthropic cloud folks have done this a little more than some of the others, but we need to develop LLMs that have higher quality code to train these AI on. Yes. Right.
And make, make sure we weed out some of the really crappy code, because that only comes back to bite us. But, but here's another lesson. Andrea.
I, I've been in security 30 plus years, and unfortunately, I, you know, I, we've learned this the hard way in security. You can't throw yourself on the tracks and expect the train to stop. Hmm.
And in many ways, this whole vibe, coding, whatever you want to call it, ai, LLM, you know, AI generated coding, the train has left the station. We've gotta figure out how to keep the passenger safe, right? And how to make it better.
How to put in, you know, the guardrails you're talking about and, and so forth. But don't, let's not fool ourselves into thinking that, you know, we could pull the handbrake and, and bring this thing to a screeching halt that's not happening. No, I totally agree with you.
And, and in all honesty, we, we focus a lot, you know, as we do right now, and the whole conversation around software code and, you know, actual code being developed, and that, as we all know, the software development lifecycle has a few other steps. You know, let's figure out what, whether we know what we wanna do, let's write this, let's do diagrams and other things. And again, the LMS can be super helpful in many, are many of these stages.
Um, and I think the, the, the thing that can sometimes be hard is if you're sitting with a responsibility for a carra, maybe, you know, a couple of hundred developers or thousands of developers, you know, at the end of the day, the buck of mistakes somewhere stops, right? And so there's somebody that's accountable for what it is that's being done and how it's being done. Um, and, you know, uh, you have developers coming up and say, Hey, I wanna try this.
I wanna try this. I wanna try this. And you're like, you know, I, I want you to try this.
'cause I want to encourage the innovation, the creativity. And yet I also need to know that we have some balancing because I have, uh, responsibility to the organization, whatever organization is I'm in, to make sure that we, we, we stay safe, secure. And specifically, if you're an organization that deals with customers, that they are also safe and taken care of.
And it's a super challenging, uh, situation. And some organizations are comfortable, have a risk appetite that's somewhat different than others. Um, you know, we try to cater to, to everybody, but obviously, uh, service obviously, uh, very large customers.
Um, and it, it is definitely a challenge for the CTO today because they, they, they have a, a challenging role or trying to figure out how to strike the right balance between creativity, efficiency, productivity, and yet knowing that systems are gonna be up tomorrow, and we're not gonna have some, you know, uh, terrible leak or whatever, uh, in, in, you know, in the middle of the nights. I get it. I get it.
Andrea, we're about outta time. Unfortunately. I could sit and talk to you about this stuff all day.
Me, you know, we do a lot. Me too. We do the, yeah, we do Textron Gang, and we do a lot of podcasts on this.
Control Alt Deploy is one course. You know, a lot of what you're talking about is, is platform engineering related too, right? With Golden Baths and, and, you know, guardrails, we do a platform engineering podcast.
I'd love to invite you on at some point as well. Um, we will continue this conversation, but for now, I gotta, I gotta go to a break here and, and bring on our next guest. All right?
Okay. Thank you very much, Alan. Thanks for taking me on the show.
My pleasure. It's always a pleasure to have Andrea Maldi, C-T-O-C-I-O at Sonar here on Textron tv. We're gonna take a break.
We'll be back in a bit. Hi everyone, it's Alan Shimel. Welcome to another episode of Control Alt Deploy.
This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong. And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps. It's about security.
It's about how we're, how we're writing and deploying and running software these days. It's, it's one of my favorite shows of all the things we do on Techstrong. It is, uh, sponsored by our friends at OpenText.
So many thanks to them. But, um, it's, it's our show. It, it's a tech strong event, a production, as we say.
And, uh, have a lot of our tech strong friends on this particular episode. I'm looking forward to it. Today's episode is titled Shift Left or Shield Right, the Evolution of DevSecOps.
And, and that's a loaded question we're gonna have a lot of fun with. Let me introduce you to our panel members for today. If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang.
So they may not be strangers. Gee, I'm gonna start with our, our friend Kate Scarsella, and welcome Kate, if you could give people a little bit about you. Sure.
I've been a part of, um, I've been doing technology since 1998, started with IBM, and again, you know, cybersecurity with us, started with network security, AV and dear, I say Tivoli identity and access management, so, Ooh. Yeah. No, that, hey, was gonna rule the world.
Thanks, Kate. Um, joining next is our good friend, Tracy Reagan from Deploy Hub. Hey, Ellen.
Hey, you know, TLA used to have some pretty righteous parties in Austin. Oh, I have to say about that. And yeah, so I am Tracy with the Ploy Hub.
Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun. I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as a continuous delivery foundations board. And I'm really into open source, and I'm really into fixing post-deployment vulnerabilities.
Excellent. Welcome, Chay. It's great as always to have you on.
Next up, we have an analyst, gang member tech Field day, uh, delegate. Our good friend Jack, Jack Poller. Hey, Jack.
Hey, Alan. Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica.
I have a long history in technology, a few more gray hairs than Kate in a few more years. Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent.
Thank you, Jack, and welcome. It's always, it's always great to have you on. Next up, I wanna introduce you to Garima ba Baal.
Uh, well, I'll let Garima introduce herself. Karima, go ahead. I'm, I am based out of AWA Canada.
I'm the founder for the DevOps Community of Practice here in Canada. I just, several chapters. I'm also the chair for the ambassador program at Continus Delivery Foundation, written several books.
And, uh, my latest book, which is coming out, is Mastering Security at Scale. So hopefully I can value add to this panel. Oh, I'm sure you will.
Gima you always bring value to every, every panel, every show we do. So thank you for all you do. Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against them.
Trey Island. Trey, welcome. Introduce yourself.
Uh, thank you very much. Yeah. Um, I'm based out of Denver, Colorado.
I'm a security consultant. Um, so that means I am the technical hands-on demo guy, uh, when it comes to, Hey, how do you integrate application security into your organization? Are you ready to move to the cloud?
Or do you have CICD implementation? So I kind of help with all of that. Uh, integration with our tools for scanning the source code mobile applications, uh, open source and dynamic scanning.
So guys, let's dive into it. com because of what became DevSecOps. I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen, you know, in my years in security, we didn't call it DevSecOps.
Truthfully, it was rugged DevOps. I remember the fights I had with people in security and the people in DevOps, because there is no, there's just one DevOps, you don't need a second there. You don't need biz in there.
You don't need anything. The security people said, ah, you know, it, it should be SEC DevOps, because isn't security first always. Um, and then we, you know, this whole idea of Schiff left, and I was, I was so gung ho for sh Shiff left.
I believed in shift left from the bottom of my heart. And it, and it, you know what, over the years caught on DevSecOps became a real thing. Most of the DevOps companies considered themselves DevSecOps companies.
We shifted left and we shifted, left some more, and we even went a little further left, and some began to question, did we go too far left? Is it really working? Maybe we should shift right?
Shift up, shift down, shift everywhere. We still need better security. Kate, if you don't mind, I'm gonna ask you to kick us off here.
Yeah. Did we shift too far? Left?
What shift left the right move? You know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught. So we had to start somewhere in this and shifting left and trying to add security because we were being hit.
I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004. I mean, it, it was, it, it was taken us by surprise, right? And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people.
And, and we were really putting a lot on application teams when they weren't security people at the end of the day. So I, I think we did go too far, um, to the left. And I, and I think that we didn't work together.
We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward. So I think it's better that we are starting to look and, and create this culture of, let's really take a look at this because we all want, um, we all wanna do it safely. I mean, at the end of the day, you know, it, it's, we have to be better at working as a team.
Yes. The team Thing, reer, go ahead. The team thing, you're both, Yeah.
Yeah. That, that team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties, all through the early two thousands. And I never even talked about security.
I never even heard about it. I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it. There wa there really wasn't any, any tooling to add to anything that we were doing that would improve security.
So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it. We were like, well, what kind, what do we need to do? Yeah.
And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in it in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had. So it didn't have so many executable, uh, functions in it. So, you know, it's interesting that you say the team part.
'cause I think that's where we got caught up in the beginning, and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done. And we didn't know what to do. Yeah, yeah.
It really wasn't being taught. No, not at all. It was security was not taught to developers, that's for sure.
You know, computers site emer, you know, the voice of DevOps here, shift left was such an important piece of it for me. What about you? It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right?
So there are new types of security, uh, you know, is required. And new, new type of security vulnerabilities are introduced in the code itself. So shift left is changing, and, uh, obviously, uh, there is a lot of upskilling required in that dimension.
And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it. Uh, there was a report from Checkpoint, which says that, uh, every prompt, which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage.
A hundred compromised AI models were deployed into hugging face platform, which is basically for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak. So if you think about this shifting left had reduced the vulnerability problem by 70%, right?
30% was still runtime security gaps, which we were finding. But now with the injection reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure not, we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection. I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things, which are, which needs upskilling.
And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent. We don't have, uh, enough education and awareness in this dimension. And where there, where the communities like this, uh, what we drive come handy and we foster that collaboration.
Excellent. Gima, excellent. Jack, Trey thoughts?
Well, I, I may, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right? Which, you know, defense and depth, right? We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems.
Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security. And so we, that's how we measure our developers and our development lifecycle, right? So Shift Left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible.
That doesn't necessarily make it sufficient to protect our applications. We also need security shifted, right? To do more at runtime, to catch things that can't be caught at the early stages of development lifecycle Fair.
Re you are talking to real life customers, users. What, what's your view on this Shift? Left is very important.
I think the problem, the problem resides when security then offloads their responsibilities onto the developers. And the developers then decide what security tools they want to use because of ease of use. Not necessarily this tool is better than the other.
I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, look, this works really good in my IDE as far as easibility, but what security checks are in place. I see a lot of that. Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities.
I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant. So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security analysts. 'cause the first thing a developer will say, okay, can you tell me why?
Or do you, my, my application works like this. Why is this a vulnerability? You can't just say, it's only in the report, go fix it.
You have to go on that other level. Um, so that's where security is gonna have to continue to do their work, their research, their efforts. And I see AI as a complimentary tool.
Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right? You have something in your code that you did not create. You don't have a good understanding of it.
And if you're just going to use these AI tools to generate an application, you're not gonna have a good understanding. And you probably have a lot of loaded code for functionality you didn't even need to utilize. So that's where organizations are gonna have to lock down what tools that they allow Code let's you have insecure code.
But go ahead, chase, go. I'm sorry. Let's Talk about, let's talk about tools for a minute.
So I just spent the last week we have the, at the CD foundation. Kate and I are on a, a special interest group called the CICD cybersecurity ums. And we have a deliverable.
So I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework. And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today. I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet.
Not everybody's using them, we're taking them serious. It it just look at the problem with generating SBOs. Not everybody generates an SBO M1 of the core components of your secure pipeline.
So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle. Yeah. And, and many of those ones in the middle are, are actually starting to monitor what's happening in production.
So maybe we've come to a place where we're shifting, um, we're shifting a, a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it, and it's starting to monitor what's happening in production. I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems. Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking.
I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category. Wow. All of them doing something a little different and solving the problem in a different way.
But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework. And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these.
And I were shocked. I was really shocked. It's taken me all week to get just a few of these pages done, because there's so many tools and sorting out what they do to fit that has been a challenge.
So I'm hoping this helps. I really do, because we don't need to wait for AI to solve the problem. There are tools out there that can do it today.
Yeah. Yeah. And, and true.
I love it. I think you used a key word, um, platform engineering this idea about that, right. It does come to that middle.
It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection. It, it, it gives this whole more of a holistic view. And I think where organizations are, are moving and it's better.
Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth. You know, it's something from a strategy point of view that I have seen that really isn't working. And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a, a vulnerability and you get a tool and you hit it.
I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it. You know, you still need to have an offense strategy. It doesn't mean that we are going to attack.
It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready? Because we understand that it's coming. We know the threats, we understand the attacks.
There really isn't anything new, even with I ai, there's still the same attacks. We know this. And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity.
I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right? That we are not that simply doing shift left and doing static code analysis or dynamic code analysis, whatever your shift left or combination of shift left tools is gonna give you isn't going to solve or, or provide you perfect security.
Right? And I think you mentioned in the word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime, and then even how do you end of life the product and how do you secure, right? Yeah.
And what do you do with the data at the end? It's an entire picture and there's an entire set of problems. And one tool or one small set of tools shifting left is not going to solve our problem.
So I'd like to people to think about it as, and, and I, I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe, the wrong way to do it. And I think the right way to do, to say that we have seen these problems in a slightly different domain. AI is a brand new domain, but it is still a data leak problem, right?
And how do we treat data leak problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai. Yeah.
I I would also like to shift this discussion to around time security. And you know, of, of course, there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve.
So a lot of organizations are already behind, right? So the 70% of vulnerabilities, which can be found through injecting security through shift left is not already happening. So that addresses or caters to that.
But if you think about runtime security and why it is becoming more and more important, and the CXOs have a shorter runway of 36 months to prove this, because AI is coming, and I'll highlight three points. LLMs, you know, you, like it or not, developers have started to use LLMs in many shapes and forms. So the LLMs are creating code, right?
The second part is prompts. So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right?
So test case generation, for example, uh, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right? So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset.
We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections. Even AI agents, they are playing a, uh, a bigger role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security.
I, I don't disagree at all. I, you know what, I, I like the term shift everywhere. I, and I, it's not my term, actually.
I first heard it from my friend Jeff Williams from Contrast Security, right? But certainly we've gotta shift left, but we can't expect our developers to become Security Pros, right? As Trace said, they're going to, they're going to lowest common denominate a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls.
We need to remember that security doesn't end at the Deploy button, or we don't actually press a button for Deploy anymore, do we? But it doesn't end at the deploy it, that that mission continues as well. And, and so it, I would like to see a holistic security view of, you know, throughout that, the life cycle, not just of software development, but of software operations, right?
Observability and security is, is something we haven't talked on here, but that needs to be part of this as well. Um, I, you know, we, security's important, and no matter who you talk to, I think no one says, ah, security's not really important. We all say it's important, but we can't just focus on the security over here, or the security over there, or at this stage or that stage.
Every stage needs security. And I, I think the, one of the problems with security left is we took our eye off the ball of Right. And runtime and, and these other, these other places, um, uh, You know, being a, you know, I wanna, I wanna, I wanna disagree with that statement just for a minute.
Go ahead. Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view. That's why I'm gonna push again, if you have not read the SSDF, this is a, this is a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view.
So read the SSDF because it's, that's what that is. I I will and I should. And, and Tracy and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on one of our tech strong properties.
Let's get you both on, and, and, you know, shine a light on it, because it sounds interesting. Trey, October, actually we haven't October, October, I'm marking it down. Trey, I feel like we haven't heard enough from you on this.
What are you, what are you making of this discussion? No, absolutely. With runtime, right?
You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application. But there's always that use case, and sometimes it only takes one to break your application or have data leak. That's why it is important.
It's not important. It's important to have these tools, right? But it's also, why do we have these tools, observability?
What are we doing with that data? Who's managing that data? If a tool is fa failing, what is the corrective action, right?
It's all these things you just can't throw. And like, uh, Tracy was saying, there's so many tools out there. How do we actually, um, identify the ones that are correct for our use case?
There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application. So that's where a lot of that research does have to come into play. Um, and having information on the log injection, how is the host running?
All of that is important, of course, after the development phase. But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that. And they're great at developing code.
Now you're forcing them to put another hat on, another hat on. And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset. And then you feel like you're ha my last name.
Like you're on an island all by yourself. Um, Yeah. And, and there is that, that we need, I'm sorry, go chase.
I have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, uh, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments. Watch to see how long it takes your team to respond to it. What is your meantime to remediation?
Those are the kinds of things that organizations should start looking at. Uh, because I'm, right now it's over a hundred days. We've gotta get it down to less than 15, less than 10 would be good, because it only takes 10 to exploit.
But we ha we are over a hundred days, folks, and that doesn't work. So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization, from developers who have to recreate the, the new palm files all the way out to the deployments have to, that that whole, that whole cycle, elastic has to be hit when there's one vulnerability that has to be fixed. Great.
Hey, Jack, I'm sorry. Go ahead, Kate. Oh, I, I was just gonna say, I'll, you know, I'll come back.
Jack, go. So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback.
You don't see that today. Today. You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there.
And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help. But making it simple, I think will, will go a long way into making SAC important in DevSecOps. Go ahead, Jack.
I'm sorry. I I don't disagree. Jack, when you talk to consultant clients, right?
Analyst service, do they take this? Do they ask, do they want a holistic approach that shift everywhere? Or do they focus in on a particular stop along the SDLC?
I think they, right now, vendors are primarily focused on a particular stop along the SDLC because they perceive that as a way to market and sell. Not that that's what's really needed. And something that Kate sort of said resonated with me.
Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right? When, when I was a, early on in my engineering career, I started out as a software engineer, and then I went and started developing chips. And one of my mentors in the chip development space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would.
And it took me a long time to figure out what that meant. And it's really you, the way people do things and operate in DevOps is a different mindset comes out. You start with different assumptions, different perceptions than you do with when you start out as a security person.
And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment. Build it for us, not build it for you. And I think that will really help build it for us, not for you.
I think that's a great place where we call pull the plug on this, Jack. It's a good, good way to end it. Build it for them, not for you.
Kate, Tracy Reemer, Jack, Trey, thank you all so much for joining us. We, we try to keep these to a half hour. We're a little over, but we're close.
Many thanks to OpenText for their sponsorship of this and all they contribute, so we appreciate it. Many thanks for you to, you guys for watching. We'll be back in another two weeks with another control alt deploy, and we might be doing some more live round tables where you can take part in them as well.
So stay tuned for that. Until then, for Control, alt Deploy and Techstrong, Ms. Allen Shemel, we're out.
Hey guys, thanks for the throw. We're here when Laura, I Kaan, who's vice president of product for CloudBees, and we're talking about model context protocol, MCP, otherwise known as also MCP servers and CloudBees has one and they've also made it available on the AWS marketplace. Laura Line, welcome to the show.
Thank you, Mike. Everybody's talking about MCP. I think you cannot walk down the street these days without somebody talking about how they just added an MCP server to their thing.
But from the perspective of DevOps and the perspective of software engineering in general, what does all this mean? Put some context around it. What, what are we gonna be able to do today that we couldn't do yesterday?
Yeah, absolutely, Mike. Um, so the, the MCB server that we built today, really, um, it's, it's a glue for, um, you know, model, um, sorry for LLMs, um, foundation models, um, to the actual unify, um, solution that we, uh, have built today. It's, um, essentially a DevSecOps, uh, solution.
Um, and it really, um, it's more of a really a control plane for your DevOps, um, infrastructure as well as your CICD tooling, your testing, um, providing you analytics and, and so forth. And, um, it essentially the, we understand, you know, we are trying to, um, be where our customers are at. Um, we know, especially on the enterprise side, um, enterprise, um, have very complex needs when it comes to software development, um, delivery, um, whether they are using different tools such as, you know, CI engines such as, uh, GitHub actions or, um, GitLab, um, harness or Jenkins, right?
Um, and also needing to be able to have, um, more flexibility around having analytics and being able to have, um, a more holistic view in their software delivery. Um, and providing, um, us providing insights to our customers on, um, where they're at, providing them, um, you know, uh, realtime, uh, data around their pipelines, realtime data around their security vulnerabilities and, um, their testing, uh, results and so forth. So the MCP, um, reduces, reduces that, uh, context, um, contact switching for developers, for our practitioners, um, being able to allow them to stay at the tool that they, um, desire, whether that's, um, their IDE, their CLI or, um, AI command, command lines or such as Amazon Queue, um, and be able to connect to, um, our solution.
So I think with the MCP server, it's really providing that simplicity for our, uh, customers to be able to be much more productive. Um, and, but at the same time, being able to have that governance and security that they know is very important as well. Mm-hmm.
As I understand it, it's essentially bidirectional in this regard. I'll be able to query data that sits in the CloudBees platform using MCP protocol, but I'll also, from your platform, be able to access and pull in data as well. Is that kind of how you see this evolving?
Yes, absolutely. Um, and, you know, being able to pull in data, whether that's insights, um, whether that's, you know, um, you know, very, very basic use cases such as, you know, what's going on with my bills? Are they failing?
Are my tests failing? What tests should I be running? Um, what's security vulnerabilities are impacting my applications today?
Um, and then also be able to orchestrate, right? Um, be able to orchestrate your, um, entire software delivery end to end from building to testing, to actually delivery and deployment of your application, to whatever environment you're, um, looking into, whether that's, you know, your staging, your production and, and so forth. So it's not just necessarily insights, it's also the ability to orchestrate, um, and, you know, being able to orchestrate and have, um, specific agents, if you will, for the different types of use cases, depending on the stage of the software delivery that you're at.
Now, it seems like we're starting to see the rise of AI agents that are gonna be added to DevOps teams, and they'll either be assigned tasks or will augment existing humans in those teams. But, um, how will we orchestrate all those AI agents? You hear a lot of people talking about things like the agent to agent protocol or, um, but from a CloudBees perspective, how do you envision all these things being brought together in a way that looks like they are a member of the DevOps team?
Yeah, absolutely. The, I think the MCP protocol has really, um, addressed this, this complexity, right? The, the way I see MCP servers is it, it orchestrates these AI agents in a way where AI agents can be very specific in the kind of the problem that they're solving.
Um, if you think about, for example, in a factory, um, you know, within a factory, you've got AI agents that may be representing the workers, um, that are, um, doing specialized tasks, if you will. Um, and the MCP server are essentially your floor managers in those factory. This orchestrating, um, the jobs to be done.
They might have the master plan, they might have the blueprints and so forth. And so this MCP server will, uh, provide the context, um, it's stateful, um, and then it's providing the necessary information to the, the ages, um, to do the work, to actually do the tasks at hand that the, your developers or your, um, CI administrators, um, uh, will need in order to get their job done. I'm trying to figure out how this is gonna play out, and in my mind, it may work out one of two ways or who knows both, but are there gonna be a bunch of AI agents that are assigned a specific task as part of the DevOps team, and they'll do the same thing over and over again?
Or will each engineer kind of have their own set of AI agents and they'll be doing tasks, but eventually we're gonna have to kind of coordinate those AI agents with other members of the human DevOps team that have their own AI agents? I mean, how complicated can this case? Yeah, it can be complicated for sure.
Um, the way I see it, you know, you have AI agents really assisting, um, different personas. Um, you might have AI agents that specializing a specific, um, build, for example, on the build side, um, AI agents that essentially takes the data, looks at the logs of your bills, helps the developer, um, figure out why a build failed, right? So I think it's in some ways, um, specialized in certain, um, tasks and job to be done.
Um, you don't necessarily have an agent per se, uh, per developer. I think it, it really kind of el um, it's more elevated to the, the kind of, um, tasks that need to be done. Um, so I, you know, and that's where Amazon queue plays, uh, uh, you know, place, uh, with the, um, with this workflow, right?
Where you got developers that are using Amazon queue, for example, to, um, gather the data and assist the developer to, um, figure out, um, you know, what, what bills are failing, how to fix a build, what tests are failing, what tests should be run, um, and help them be a lot more productive and, uh, reduce that, um, kind of the tasks and the time, um, spent in those specific tasks that they'd normally spend a lot of time on without, um, any kind of AI powered assistance. And one of the things that I think is maybe a little underrated is I'm not just gonna kind of get a bunch of AI agents and turn them loose. They're only as smart as the amount of data that they gain access to.
So, um, before I put the proverbial cart, before the horse to DevOps teams need to go back in and kind of say, what is that framework for providing these AI agents access to the data that they need to actually make an informed decision? Yeah, for sure. Um, for example, in, in, uh, we are, we are working on certain, uh, capabilities that's, uh, really leveraging ai.
One of 'em is, for example, uh, the offering that we have smart tests. Um, the other one is around more of a ci triaging and remediations, kind of like your AI DevOps first responder. Um, and exactly to your point, it's, you know, a garbage in, garbage out.
So, um, the way we are tackling this is ensuring that, you know, we use the knowledge base that we have acquired in the last 10, 15 years, for example, in the CICD space. Um, and so providing that kind of input and data to our agents to ensure that, um, it's learning, um, and then also getting feedback, um, from the users, um, you know, and, and really training it and, you know, doing some evals and, and so forth. I think that's absolutely important.
Um, you know, one of the things that I always think about when we're building these solutions is the three Hs, right? Um, is it being honest? Is it being helpful?
Is it being harmless? Right? Um, and I can talk a little bit more about the, um, that philosophy, but for sure, this is something that we, uh, take to heart, um, in terms of, uh, ensuring that the outcome of these solutions are, um, are useful to our customers.
To that point, well, just how smart are these AI agents? I mean, are they essentially junior developers or are they more like, you know, helpful high school students or, you know, where are they on that spectrum of intelligence? Because I think folks are trying to figure out, well, how much can I rely on them or should I rely on them versus, um, you know, how much time do I need to spend validating and checking what they do?
You know, I think it, it's, it's, uh, across that spectrum is how, you know how much you rely on them. It really depends on, um, how much of the training you put onto these agents, um, and how much, um, evaluation you're doing to these agents. Um, you know, it also depends on where our customers are at with AI adoption, right?
Um, are they comfortable with, uh, you know, allowing an AI agent to be able to just automate end to end their workflows, um, without the human in the loop? Um, or, you know, are they currently still kind of dabbling with ai, um, and, you know, just looking for, um, solutions to solve, um, their problem, but still be in the loop, uh, per se, right? Um, I think it's important also to understand where the, our customers are at in their journey, um, and, um, providing them the kind of solution that is, um, that works for them in terms of governance and policies and, and so forth.
We see some customers that just want, um, some sort of copilot, for example, right? Um, but we also see customers who are kind of pushing the, uh, the limit, um, and pushing the envelope in terms of, um, allowing agents to just be able to, to do their job and to end fixing, um, fixing builds, um, issues and, and so forth, Forth. If I look back in time, every time there's a major innovation, we use it to do what we're currently doing faster, but at some point we kind of take a minute and we reinvent the whole thing altogether.
And I cannot help but wonder, as we look at all this AI stuff, are we on the cusp of reinventing software development life cycles as we know it on an end-to-end basis? And from your perspective, what might that look like? Oh, man, Mike.
Yeah. Um, it's the, the space is, uh, so dynamic and it's evolving so rapidly. Um, I think it, you are so right to your point.
It, it really is changing the playing field altogether, uh, changing the way, uh, developers write code and innovate, changing the way, uh, DevOps engineers actually build their pipelines. Um, it really is changing, uh, the way we work, um, even on the product management side, right? Uh, changing the way, um, product managers also, um, write their PRDs, uh, write, you know, uh, write the requirements and, and so forth, and validating, um, the problems to be solved and validating, uh, the solutions for these problems.
I think it really is a, a game changer as we stand today. Mm-hmm. Are you worried that we might have something that feels like an impedance mismatch because we have all these AI coding tools generating more code than ever, and then all that's gonna come flowing through our pipelines that today are, shall we say, uh, a little brittle?
And I don't think it's gonna be enough just to kind of add more pipelines. So what do we need to think about here? I agree to hear Mike, uh, uh, and we are seeing that already a lot, you know, a lot more commits and commits, um, coming through, uh, code assistance and, and so forth, uh, co-pilot and, and so forth.
Um, and maybe at some point it will push the bottleneck from the developers to the reviewers to the pipeline bills and, and so forth. And I think the way I see it is, um, you know, finding where the bottlenecks are and then also solving where, how can a, how can we leverage ai, uh, to solve that next bottleneck as part of your software delivery? Mm.
So what is your best advice to folks right now? I think this is such a fast moving space that a lot of folks are kind of like, they're watching it, they're seeing it, they are definitely getting experience with some of the tools, but from a management perspective, what should they be thinking about right now? I think in some cases, a lot of folks are just overwhelmed to the point, like maybe they feel like deer in the headlights Agree.
Um, I think, well, one, for those that are still curious about ai, just learning more about ai, um, you know, whether that's, uh, training, uh, leading up more, uh, staying in, um, up to, you know, the, the latest and greatest technology out there. Um, today is MCP servers. Tomorrow is something else.
Um, and even on the MCP protocol is changing quite rapidly. So staying, um, up to speed with technology, I think is, is really important. Um, and the other is, um, don't necessarily trust AI right away, right?
Um, and, and, um, you know, it's, it's also something that we need to take into consideration. Um, look and make sure that it's doing the right thing, that the outcome is, uh, is what you expect it to be, that it's reliable, is deterministic and, and so forth. All right, folks here, heard it here.
As always, there's a lot of exciting things going on, but just remember, look before you leave, hey Lala, thanks for being on the show. Thank you, Mike. Really appreciate it.
Great to meet you. All right, and back to you guys in the studio. Hey guys, thanks to the throw.
We are here with Barat Guru Pra, who's Chief Product Officer. For Algolia, and we're talking about ai, web traffic bots, and all kinds of interesting things that are happening these days, both for good and Ill Barat, welcome to the show. Thank you Very much, Mike.
Uh, thanks for having me. Uh, excited to he, uh, be here, have this conversation. The world is changing, uh, rapidly.
I think anybody who runs a website has noticed that there is traffic coming from bots that are essentially crawling their content and then using that content to, uh, we assume train AI models. The issue it seems to be though, is that the traffic they generate isn't necessarily something I wanna monetize. It's not a human, it's not something that I'm gonna get paid to go do, and yet I am absorbing the cost of processing all that stuff.
So what's to be done about all this? And how much of this is just the new cost of doing business? Or is there something I can do that maybe will minimize the impact?
Actually, you know, there's, it's worse than just the cost of processing all this bot traffic. Um, you know, if you take a step back, whether you're an e-commerce or media or whichever, you know, type of website that you're running, there is a supply and demand component to these things. You as a media or an e-commerce company, you have a supply your product catalogs or your, you know, music podcasts and streams and all of that.
And you have a commercial strategy that goes with that. Like how you distribute it, who gets access to it, ads are involved, et cetera. There's a lot of things, engagement, customer experience, there's a lot of lot of thought that goes behind the supply side of this.
You know, if you are Spotify or if you're Netflix, or if you are an e-commerce company, like, uh, name any big e-commerce company, Amazon, whoever it is, right? There's a lot that goes behind there. Then there's a demand side that is coming in from these lms.
You get demand from Google search engines. And more and more we're seeing bots now coming in. And part of this is, it's, this is this complex equation because what is happening, I think you recently saw Amazon banning the perplexity stealth bots that was scraping all of their sites.
It's because of this complex supply demand commercial, uh, strategies that these companies are thinking about on a daily basis. And on the other hand, you have these stealth bots that are coming in trying to scrape the information so that it can then be discoverable in a LLM for example, when you're looking for, Hey, what's the best sort of like ski gear that I can wear as a billionaire going to Tahoe, for example. So, you know, I think, I think it is not just about the cost of processing, it's actually the commercial sort of like strategies that these companies now have to think about when it comes to distribution and, and discoverability of their, uh, of their products, whether it is media, e-comm, whatever is the industry.
So I think, I think it's, it's, it's extremely complex and this is why I think Amazon banned them. Mm-hmm. Yet Amazon may wanna do that, but for a lot of organizations who have invested heavily in things like search engine optimization, there's a lot of the new search tools or AI driven, and a lot of people are starting to use those things.
So, will I just be cutting off my nose spite my face if I block that traffic? And, and how do I strike that balance? No, it's a great question.
And every company has to have a, um, a sophisticated distribution strategy. There is promiscuous distribution where they want sort of like more of their commodity items to be widely available to as many people as possible. And then there is their actual premium stuff and what they want to control the experience on.
So if you take a look in the e-comm bowl as an example, you might have, uh, like a Wilson's, uh, tennis ball or baseball. So whatever, these are commodity items, you want them to be available in as many different channels as possible, easily discoverable, et cetera. And then you have at the other end, if you go right to the other end is like super luxury items, like the air messes of the world.
Like they're not going to take a wide distribution strategy. And then you've got marketplaces and, and, and people who sort of like aggregate both premium products and commodity products. Like they want to have a mixed distribution strategy.
So I don't think it's as simple as I'm just gonna block them because I don't like them. I think companies are evolving to figure out what do I want to make available to a, you know, promiscuous, uh, channel strategy versus what do I want to control more of? And this is true in e-comm, again, in media, in, uh, any of these other fields where transactions are happening online.
Is that a quote unquote static process or is it more likely to be a lot more dynamic? 'cause I might make one decision today and another one tomorrow, A hundred percent dynamic, which is why at the very least, if you are the web, uh, you are owning that particular application or that web property, you at least wanna have the control to make those decisions. Um, today, like if you do these, these stealth bots, like that decision is being taken out of your hands.
And so, uh, this is where, you know, companies like Algolia come in because we can actually, you know, help customers control what type of products or what type of items, what shows up where, depending on whatever their commercial strategy looks like. Mm-hmm. Well elaborate a little bit on that.
How does that work exactly? Do I put what in where on my website or somewhere else? I mean, it could be, uh, your website, right?
Like, let's, let's take for example, um, let's say Chad, GPT or perplexity or any of these LLMs wanna get access to. And let's say you are a, um, you're a media company. Let's take a media company as an example.
Um, let's take someone like, um, like an iHeartRadio for example. You know, they have, they have very, um, um, uh, media properties that they want it to be everywhere, like top 40 platelets, uh, hourly traffic bulletins, like these are all commodity type of media that you just want everywhere as possible. Then they've got their, because they're also a creator like Netflix, they have their own podcast, they have their, you know, investigative journalism, et cetera, and you want a slightly more, uh, narrow distribution strategy.
So Aldo Powers all of that as an example. And if perplexity is questioning, uh, iHeart, hey, what is the latest sort of like podcast that, you know, this user is asking for? Um, with Algolia we can answer back with iHeart's control.
What is the appropriate things to send back to perplexity based on whatever it is that iHeart strategy looks like? So that's sort of like how it works. And you know, you've got technologies like MCP today that allow for that sort of like querying and that interaction to happen.
Mm-hmm. How much visibility and foresight can I get into that? Because, um, I may wanna know that a certain topic or subject is building with those new, how we say AI browsers, and then I wanna be able to respond and surface that content.
Uh, but I may only wanna do that to my previous point for a week or so. So I mean, how much visibility can I get, um, Visibility into, into a control of it? Yeah, but also, but like, what kind of queries are the AI engines starting to make and 'cause that's gonna inform my strategy, right?
A hundred percent. So you take any of our customers, right? Like we, uh, all of these queries come through Algolia.
So we actually know what is being asked and we actually surface that back to the customer, our direct customers, so they actually can see what is happening and they can see what the results look like. And this can see what the interaction and the engagement model looked like based on the results that they gave. And does it line up with their personalization strategy?
Does it line up with their commercial strategy? Does it line up with, uh, their customer experience strategy? So we give all of that back to the customer.
They can see all of this analytics and what used to be a human analyze sort of like recommendation. That's what most companies used to do. They used to look at this, put them in these gigantic spreadsheets and like compare them and say, Hey, you know what?
We should probably modify how we're, you know, uh, uh, returning results back in this way. We are changing that because today agents can actually do that and they can do that at a faster clip, at a more dynamic pace. And as a result of that, um, we're entering with this world of like, what I call hyper hyper-personalization, uh, because we're at machine scale now.
And so it's very exciting, um, in, in that sense because, you know, who wants generic answers, right? At the end of the day, you want it to be, you want it to be as personalized and relevant to you. How quickly is all of this happening?
Uh, 'cause some people are still using traditional, say Google search, other folks are relying more on, um, AI and it's not quite clear which one of those is more reliable or useful. 'cause you could probably argue both ends of that equation. But what's the balance and mix that you're seeing out there?
We have, if you think of it from the innovator's curve, you know, dilemma curve, I think we are at the phase where we're still on the left side of that, of that equation. But I would say that, uh, so we have a lot of like challenger customers who are ready to like, go to the forefront of it. You know, they're like, we're done with the traditional sort of like interfaces that we had on our website.
You know, they're even talking and pushing us about what is the future world? Are there going to be websites or is it all going to happen through these like, um, headless browsers who are just communicating with other, you know, headless LLMs and et cetera. So we do have that class, but I would say that, um, they are still in the minority.
But what is interesting and what I'm seeing is we have a lot of enterprise customers, by the way, and what I'm seeing is that the rate at which the bigger and the, and the more sort of like the middle category and the later stage categories in that innovator's dilemma curve, how quickly they're actually trying to get on board with all of this. I think that's accelerating. And I've never seen that before at this rate that it's happening at.
And it's, uh, it's, it's interesting. It's almost like people are ready to skip a generation or two of technologies that they hadn't adopted yet and just go straight to the latest stuff. So what ultimately is your best advice for folks as they try to navigate all this?
I mean, is there, uh, something you're starting to see that amounts to a set of best practices that customers are putting in place? How are they navigating all this? Um, I would say that most people are stumbling through it right now.
I think that is the reality. And, um, y you know, there is a, I think there's a little bit of a cognitive overload as well going on right now. The number of tools that are available today, the number of LLMs, the differences between all of these, and then how do you apply it into an enterprise setting?
How do you then take it into production? Is it going to work? Is my current stack the way I've built it as, as a company going to support this new stack that is coming in?
So there's a lot going on. What I'm seeing is that most companies, especially the enterprise, they have sort of like, um, shifted their budget from where they were traditionally spending their IT budgets on to all of this stuff. But while they've made the budget available, everyone is still digesting what it means to actually operationalize this.
And so this is where, you know, we are trying to do our part because, you know, we know what it means to operate at scale. We run something like two and a half trillion queries per year, second only to Google. Google runs about 5 trillion, and we are not a five and we're not a public consumer search engine.
So we understand what it means to be a production scale. So we're trying to do our part, um, by abstracting away all of this complexity, this orchestration, this, um, this deployment that people have to do if they want an age agentic experience. And, uh, you know, with the respect to that, last week we actually launched Agent Studio, Al Golias Agent Studio, where you can deploy agents that are grounded in your index with any tool that you want, that it wants to call out for any experience that they want to provide, customers wanna provide.
And what we are also seeing is customers experimenting. They don't know what is the right customer experience themselves, because this is happening in real time as well. Like, my own experience of using search engines, and I don't know if yours is similar, Mike, is I found that I am, I'm using Google Less and Chad, GPD way more.
And it's just been an interesting, uh, evolution observing myself. And what I've noticed is the way that I'm asking questions and the way that I'm looking for things, it's also changing the words that I'm using, the, the precision that I'm using, et cetera. So all of this is happening in real time.
So we are trying to make that, um, easier for customers by abstracting that away so that the system can auto configure itself to a new world as it keeps changing. So that's sort of like how we are approaching this, which is why, you know, we released Agent Studio a few months ago. We released our MCP, and so you can like enable these things to happen in real time and not have to go in and like crank the, the, the, the, the screws again.
Uh, 'cause it's complex. Yeah, it's challenging. 'cause on the one hand, uh, even with Google, you're seeing AI results pushed to the top of the page, but they're a little more generic.
And the more precise answer might be from the original search, but that's now 10 items below the fold because I got 47 ads that I gotta go through before I go find that thing. So I'm kinda stuck on either one of these things and I feel like I might not be served well served on either end of this thing. But let me ask you this last question.
It's pretty clear that AI agents are emerging and they are similar to bots in the sense that they generate traffic. But, um, do I optimize content for their consumption? Are they a new type of end user per se, or are they some other entity altogether different?
And I need to kind of have a different mindset about this from the get-go. Are a GI Overloads are coming? Is that what you're saying, Mike?
I don't know. No, I, all I know is they're launching a heck of a lot of queries. Yeah.
So I'll, I'll put it this way, right? Like, and a, uh, um, generative AI was all about creating content and, and, you know, putting it in a way that addresses whatever is the query. But it was still content creation at the end of the day of some form either summarizing or answering a question, whatever agents are, even though they rely on the underlying technology of foundational models, agents' role is to execute tasks.
They are there to take content, take language, take behavior, and go execute something. So as an example, we actually worked with one of our customers, which is a cruise line company. They wanted to create a travel booking agent.
So if you came in to their app or their website and said, Hey, I want to go from Seattle to Alaska, uh, my family and I, when is the best time to go? And what are my options? Gimme some ideas and can you book it for me?
So the agents sort of like handles all of it at that point. Now, um, when it, uh, of course when they're trying, when these agents are trying to execute this does, they're going to be querying a lot more because they're querying different data stores, uh, because that's where information is. The booking information is in say, a Salesforce CRN.
The assets are maybe in an A EM, Adobe, a EM. So they're querying all these different systems to get the right context and the right information back so that they can execute it. Um, so I think it is different, uh, from just what we used to know as bots.
I think this is more about these agents ultimately becoming our representative on the internet to execute tasks on our behalf. And the example that I, that I give, which is, which is kind of funny, is, you know, about 20 years ago or so, 20, 30 years ago, we had travel booking agents. If you remember that world, you would go to a travel agency and say, I need to go to the Maldives or whatever, and they would like, recommend to you, et cetera, what to do, and they'll do the booking.
Interestingly, we're going back to that world, but in a machine, uh, led way. So if you have a agent that is representing you now travel companies are gonna have like these agents that are representing them. And so we're gonna get to a world of agent to agent interaction.
Um, and so that's how I see these bots and agents evolving. We're not there yet, because again, like I said, the orchestration layers to do all of this in a seamless, satisfactory way is still being built as we're speaking. But it's clear that that's the world we're starting to head towards.
And, you know, whatever is the consumer endpoint device, whether it's the mobile phone or the new thing that OpenAI will one day announce, um, that's gonna be your interface to communicate with your agent. Who's gonna be your representative. At least that's the way I see the world evolving.
All right. Well folks, Jo, hear in here, to paraphrase Bob Dylan, the times are a changing. So buckle up buttercup, beep.
Ping Barrett, thanks for being on the show. Hey, this was wonderful, Mike. Thank you so much.
All right, and back to you guys in the studio. Hi everyone, and welcome to the six five Summit AI Unleashed. I am thrilled to be joined today by Shashi Phai, president of product engineering and AI at Zendesk, for the collaboration track opening keynote on transforming customer and employee service through ai.
Shashi, thank you so much for joining us. Uh, thank you for having me here. So just a year ago, many organizations were still cautiously experimenting with ai, and today AI is no longer a novelty.
It's become a critical force reshaping how businesses serve both customers and employees. And AI is involving from a simple assistance to intelligent problem solving. So let's dive right in.
What are the biggest challenges you've seen recently in how AI is used in customer and employee services? Now, you're absolutely right. Uh, this is probably the biggest change we have seen in humanities history since industrial revolution and how work is gonna get done.
And AI has gone from being, you know, at the periphery of the discussions we're having and like, kind of as a helper to being at the very center of the customer employee service discourse. Instead of starting with human agents, for example, companies are now starting to ask the question, what if the primary SOL solver, the pri the the primary way to solve service problems are actually gonna be AI agents? And only when that fails is it gonna go to human agents.
And that is a massive shift because you have to go in and change their entire workflow. You have go, you have to go and change their entire reporting. You have to go in and change everything that you've been kind of rethink from the beginning.
Everything you've been doing all along the way, companies that have embraced this approach are seeing very high automation rates. 80 plus percent of service, uh, cases can now be solved by AI from, you know, 10 to 20%, just like six months ago. So the, the pace of change has been extremely rapid.
And in this new world, humans will still have a role, but now they're feed up to work on the hardest problems and to work on the situations that are most complex and when the user, the customer needs the most empathy. So this is a really big change because it's not an easy change. It requires an entire transformation of the organization.
Mm-hmm. Yeah, I love that, that it's, you know, there is a lot of fear around that people are gonna lose jobs and all of that. And there, you know, the reality is there may be some of that, but freeing people up to do the more meaningful work is really so nice.
And so I'd love to hear from you kind of what makes Zendesk's AI approach fundamentally different from other AI applications and customer service? It's a really good question. So for, for us, we start with the user who has a problem.
You know, when someone calls in with a, with a, with a support case or, uh, or with a ticket, uh, they are already in a not great, uh, frame of mind. Uh, they have a problem, they need it solved, and what do they care about? They care that the problem is solved quickly, the care that is solved correctly, and that they're, and the care that they're treated courteously, right?
Those are the three things they're looking for. So we have centered everything we're doing, both for the humans and for AI agents around those three goals. How can we solve the problem quickly?
How can we solve it accurately? And how can the end user have the best possible experience? And because we focus exclusively on service and we're not trying to sell something else, you know, we're not attached to some other platform.
We believe we can optimize our approach to the highest level possible for each company that we work with and focus on. Service for us means being singularly obsessed about the type of problems that customers have, how to resolve quickly and at the lowest cost possible for you. Now, we have over a hundred thousand customers, which means we are globally present, we are present across every vertical.
So we have a ton of expertise across use cases, across verticals, and across how to get customers to the best outcomes possible. All of those lessons are being brought to our AI and humans working together. So that's really what separates Zendesk from everyone else is the obsession with service.
And it's the obsession with those three goals, solve accurately, solve quickly, and provide the best experience possible while doing so. And so while you're doing that, I mean, I mentioned a little bit that it really allows humans to be good at what they're really good at and kind of take away some of that more tedious work, the the work that they don't actually want to do. How do you see AI enhancing the capabilities of human agents rather than replacing them?
Absolutely. So, you know, if the, the job of a human agent, so on the flip side of a, of an upset customer is a human agent who has to absorb all that, uh, all the negativity, shall we say, right? And if you ask yourself what frustrates the consumer in the end, it's that, uh, they had a long time to wait.
Uh, that when they call an agent, the agent actually doesn't know anything about the background. Uh, they have to kind of go through like a whole data entry process. Uh, and then when the agent is not able to solve it passes it to another agent, they have to restart from the beginning, right?
So, like, uh, it's not unusual for a typical customer service conversation to be, you know, if you're, if you're having a live conversation, it can easily go into 20, 30 minutes. And if you are, if you're trying to solve it over, uh, email or text, it can, you know, it can go into days or weeks. So for us, it's all about how do we make that agent as knowledgeable as they can be and take away all their drudgery.
So drudgery is pulling data from different systems. Drudgery is drafting a form, you know, response that they would have. They could have, like, it could have been generated by an ai, right?
Drudgery is repeating like the same set of tasks over and over again. Mm-hmm. So our vision of our copilot is take away the drudgery so that the agent can focus on providing the best possible experience to the end customer, and they can focus their attention on solving the hardest problems, problems that go outside of what could be automated.
So we are kind of focusing on those two things at the moment. And over time we expect that even these co-pilots will become, you know, more and more intelligent. The co-pilots themselves will learn from what humans are doing and start to take on more and more of these tasks so that even the, you know, even the, uh, you know, lowest LTV customer, the lowest lifetime value customer can call and get a, get a live agent when they have a very hard problem.
Do you see with AI that the things that we're optimizing for in customer service might change a little bit? Like we've always optimized for time for to resolution, and with AI allowing for humans to really kind of get in into those more meaningful conversations where people can really feel heard and their problems can be solved. Do you see those things that people are optimizing for changing at all over time?
Absolutely. So, you know, before one can have meaningful conversations, you have to solve the problem, right? And so I, I think too often, and there's been a kind of a long, um, uh, uh, thread of conversations over the years about how, uh, support teams need to extend themselves and go into cross sell, upsell and other ways of generating revenue.
But the, the basics have to be in place. And the basics that have to be in place is I as a consumer, should be able to call a company or reach out to a company anytime of day, right? And depend if it's a holiday, if it's late at night, and get a resolution as quickly as possible.
And what's more over time, what we're gonna see have happen is that users are not even reaching out to companies anymore. They're gonna tell their co-pilot, they're gonna tell, you know, their AI agent to go deal with these problems, right? So that's the world that we're moving to.
So the only time when you have the human to human interaction is when all else has failed, right? When you've asked your agent to call the company agent and the problem didn't get solved, or you interacted with the AI agent or the company, and the problem didn't get solved. So by the time you're reaching out and reaching to a human, you are already in the hardest kind of problem category, so to speak.
So what we see ourselves as doing at the moment is to ensure that everything that can be solved very quickly, live in the middle of the night, you know, on a weekend, all of that is done. So we, we expand the time and the quality of, uh, resolutions that people can get as, uh, as reliable as possible and do so very quickly. And that's what AI agents do very well.
Mm-hmm. Then, then there's a question of the experience that the, the consumer has with the human agent. And I think that is so much easier to do when the human agent is not harassed by a bunch of small stuff, you know, like responding to a whole bunch of small stuff all day.
So I think some of it would just happen naturally as a consequence of this automation. Mm-hmm. Right?
Some of this will just happen naturally because now they have more time, you know, it's like a, it's like a doctor who is not freed up because they don't have, do all the paperwork so they can actually sit and listen to the patient and like, solve their problem into end. So I really believe we really believe this is gonna be a massive change and dramatically improve the quality of experience that consumers have with companies. Mm-hmm.
And we've talked a lot about the experience for the, the customer, and of course that's really important, but this also really affects the experience of the human agents. And historically that's been a problem, but there's a lot of turnover in these contact centers that it's a, it can be a grueling job. So talk to me a little bit about how this really helps to, for turnover for companies, for like giving them the ability to kind of manage their workforce a little bit better with, with these AI agents who don't get tired, they don't need days off, they don't get sick, they don't, you know, they're, they're, how does that help their workforce?
A great, really good question. So, uh, you know, I think we've all had the experience of where, uh, we've, you know, we've called in and we, you know, we, we wanted to problem solve quickly and it just wasn't getting done right? So a lot of that, uh, frustration, whether expressed or not expressed, passes on to these agents.
These are the toughest jobs in the industry, right? These are, um, these are, uh, not jobs that people come out of college saying, you know, like, this is what I really want to go right, wanna go do. And the, the, it requires a very special kind of person, uh, to do them day in, day in and day out.
There's a lot of burnout in the industry. There's a lot of turnover. Uh, many people see these jobs as, you know, uh, as a road to something else, right?
Like they'll go into customer success or over time into sales and other things which are even more lucrative. So making the experience of these agents better is a massive priority for, for us and for the companies, because at the end of the day, you know, people don't remember the best experience they have. They always remember the worst experience they have.
Yes. Right? That's what they associate a brand with.
Mm-hmm. And then these days, you know, they'll take that experience and then go share it on TikTok or social media or whatever, right? So it's not like it's, it's isolated.
So if you wanna optimize for, if you wanna optimize for, or you want the, the best experience people have and make sure that the worst is not terrible, then we have to start with the agents because they're human beings too, and they have good days and bad days, right? So taking away the drudgery, taking away the repetitive tasks, taking away the, you know, the stuff that makes their life, uh, not, you know, um, the, the job's not enjoyable. I think that's where it's at.
A lot of people who go into these roles generally like people and they like to serve people, that's why they took the role, right? So freeing them up to serve them in a way that's not rushed. I mean, you, you've been in this industry, right?
Like, so much of stuff is managed for a long time. Like so much of the stuff is managed by how many calls you take in a day. Mm-hmm.
If you, if you're managed by how many calls you take in a day, on the other side of it is a rushed consumer and you as you don't feel that great about having rushed them through, right? So maybe we can give people all the time they need to solve the problem because all the, you know, the, the boring drudgery stuff has been taken over by AI agents. And so the problems that you're dealing with genuinely require intellect, that require empathy, that require listening, that require a good conversation.
And that could make the job a lot more fulfilling. 'cause you, you're leaving behind someone who's very happy about the experience they have with you. Yeah.
And certainly less turnover means more money for the company. 'cause those are expensive things to know that that kind of turnover can be very expensive for companies, right? Absolutely.
Absolutely. I mean, I don't think anybody like sets these things up saying we're going to, you know, this is all about money and we just make our customers have a bad experience, right? I mean, we have to keep improving csat.
'cause we all know if you have a good CSAT then you have, you know, good net promoter score. If you have good net promot score, you have better lifetime value. I think that that kind of the equation is well understood, but, you know, service organizations always under the cost pressure.
This is not a new thing thing. It's always been like this. Yeah.
And because they're always under cost pressure, there's a great way to take that pressure off today, which is to use AI agents to do a bulk of the work and to do it in a way where you can simultaneously improve all these metrics. See, that's actually the beauty of this, because simultaneously increase the coverage time. You can increase csat, you increase, you know, like average handling time.
Like agents, agents can just do the job right away. They don't have to go have lunch breaks, this, that and the other. You can simul to improve all of these things and then leave the hardest problems for the human agents to come back and solve.
So Sashi, if you had one bold prediction of where you see, uh, the biggest change in this industry over the next five years, what would it be? I think the biggest change will be a bit of a back to the future, which is, as a user, you'll be able to get a live human agent whenever you want. And the reason is because you'll have so much confidence in the AI that you'll actually prefer a solution from them first.
And only when in those very exceptional cases can you not solve the problem. You'll go talk to human agent and you'll no longer have this, like, you know, you submit a form and you wait for three days to get a response kind of thing anymore. So I actually think we're entering the golden era of service where anytime you have a problem, it'll either get solved very, very quickly by an AI agent, or you'll get a live human agent on the other side of it.
And you'll have that solved very quickly now by human agent. So that's my bold prediction. There are many other predictions we can make, but I look forward to that time.
Uh, well that's awesome and that's a great way to wrap this up. So thank you so much for joining us, and thank you all for watching for this collaboration track opening keynote at the six five Summit. com slash summit.
On behalf of the six five Media, thanks for joining us. Thank you very much, and thank you for having me. Thank you.
There are 6 million Google searches happening every minute. AI is transforming the way we access information. And soon Google search will be replaced by SHA GPT.
Now we only get links from Google while SHA GPT delivers research answers. But there is a catch. The SHA GPT query consumes a hundred times more energy.
Now we must innovate responsibly developing computers that are not only intelligent, but also sustainable for our planet. My name is Claro and I'm the CEO of zero point. We have developed a groundbreaking data optimization technology that saves energy and boost performance in computers.
We've all seen the headlines, Amazon, Google, Microsoft invest in nuclear energy to power their data centers. Now the digital transformation is extremely fast, and the challenges we face are huge energy data centers are predicted to use four times more energy. By 2030 data.
By 2025 this year, the cloud will host half of the world's data, and 95% of all new data will go into the cloud cost. Even before CHATT PT the cost of compute was growing rapidly. Now it has skyrocketed.
And even though billions and billions of dollars were pour into AI investments and energy bills in 2025, this is just the beginning rolling out AI globally at scale will be a 10 times bigger storage and compute problem that must be solved at a 10th of the cost and energy consumption. So the question is, what can we do? Well, the industry is responding to this challenge with new processes, memory and storage technologies, which is great, but it's not enough.
We have developed a groundbreaking data optimization technology that saves energy and boost performance in computers, both for general purpose and AI needs. Our technology is the only solution capable of compressing data efficiently in just a few nanoseconds. And when you integrate this technology across the memory and storage layers, you can get up to a hundred percent more performance per watt.
Now the good thing is that it's not either or. We need both new technologies and data optimization. So what does this mean in practice?
Well, you can get lower CapEx, you can achieve performance targets with fewer memory channels, smaller footprints, less memory, and more efficient systems. You can achieve lower opex, less energy consumed, less cooling needed, and longer component lifespan. Faster.
ROI your chips and systems do more with the same or even less hardware. So whether you're designing an AI accelerator, running a cloud data center, or building servers for edge or enterprise, our technology multiplies the value of your investment. Now let's dive deeper into our innovation.
While compression is a key component, it's only part of the solution. First, we do ultra fast efficient lossless compression, then we need to do real time compaction fitting these compressed blocks like a game or Tetris. And then we do transparent memory management, keeping track of the store space.
And when we do these three steps together in just a few nanoseconds, the true value of our technology is unlocked. And no one else in the world can do what we do. And we know this for a fact.
Major semiconductor companies confirm our technology is both unique and critical. So this is not theoretical. We've already verified our technology on silicon TSMC five nanometer in collaboration with the leading semiconductor customer.
Today our IP is being evaluated by several top tier semiconductor companies, all looking to improve performance, reduce memory cost, and drive energy savings. We've also received technical validation from major global players who confirm that our solution is both unique and strategically important. So the market signal is clear, the need is urgent, and the timing is right.
So while AI is today's catalyst, our long-term vision is even broader. We are building a complete data optimization layer for modern computing across the cache, memory storage, interconnect. Our portfolio already includes solutions for ai, chips edge and cloud systems and high performance computing.
Our goal to make every bite smarter because efficiency scales with data. So let's go back to chat. GPT.
The example in the beginning. In these 10 minutes, over 60 million queries could have been served at today's n entity cost. That's a massive load on the grid and on our wallet and the planet.
But with zero points state optimization integrated throughout the system stack, those 60 million requests could be handled at half the entity. This is the future computing demands, not just smarter infrastructure, but more efficient infrastructure. And that's exactly what SharePoint delivers.
So let's build it together. CSG gets data protection. Is Intel's CEO in or out AI profit sharing Dial up has some hangups and we're gonna take a look at the resignation of GitHub's CEO in this episode of the Tech Field Day rundown.
Hello everyone, welcome to the Tech Field Day rundown. Today is August the 13th, and, And we are hoping that you're enjoying today with a nice glass of some bubbly alcohol 'cause it's national Prosecco Day, but if you don't drink, um, treat yourself to a filet mignon because it's national Filet mignon day. It's almost like those two things go together, sort of.
But what goes together is us here at the rundown with the news, maybe a little bit of snark, we'll see what happens. But together with me this week, it's my good friend Chris Grinderman. Chris, welcome to the Rundown this week.
Hi, thanks for having me. Well, we're very happy that you could jump in and, uh, co-host with us today. Uh, it's been an exciting week in the news and you know, there's a lot of stuff going on.
I, I I think we might have a few opinions about it. We'll, we'll have to dive in and see what happens. We're gonna kick off though with an acquisition because Cloud software group, also known as CSG, is going to acquire Data Protection Company Arc Terra later this year using cash on hand.
Arc Terra, which spun out of Veritas after Cohesity acquired them in 2023, serves tens of thousands of customers, including most of the names that you'd recognize from the Fortune 100 and earns over $400 million annually. It's products that you no doubt have heard of, like backup exec, InfoScale and Insight platform add compliance, resiliency and security features to CSGs analytics and management tools, which addresses growing cybersecurity and privacy demands formed in 2022 from the ME merger of Citrix. And tibco, CSG has been expanding its enterprise software portfolio and plans, more acquisitions of mission critical solutions.
Chris, do you think CSG buying into the data protection market is going to give them a leg up on their competition? Yeah, I think so. I mean, obviously they think so.
And, and this really to me, marks a continuation of the consolidation we're seeing in the cybersecurity market. It seems like the last few years this has been ramping up. Uh, we've seen more and more purchases and acquisitions and mergers along these lines.
Uh, as you mentioned, right? CSG was formed in 2022 when Citrix and TIBCO came together. Those who might not know TIBCO is itself a data management and analytics and analytics vendor.
Uh, since then they've added in a few other brands, information Builders, which is a data quality platform, Spotfire, uh, data analytics platform. And Jaspersoft, which I think does generate, uh, report generation. com for all those domainers out there.
So our, our Terra adds additional data protection capabilities to this family of, of companies. Uh, that makes a lot of sense, right? Uh, Krista case from Pure Term Group has commented on this, this, um, you know, addition of data management capabilities across compliance, resilience, and protection is a natural fit.
And in addition to that, it also exposes CSG to Arc Terra and probably broader Veritas, uh, from before the spinoff, uh, customers, right? Um, I think what's really interesting here though in this particular acquisition is that art's platform, uh, which was called the data compliance platform. I think now it's called Insight.
Um, it recently expanded its capabilities to support large language model logging and protection, uh, which seems very timely indeed. Uh, so, uh, this acquisition is expected to close in the fourth quarter of 2025, as you said, it's gonna be, but we don't know how much and we do know that, uh, CEO Tom Cross has said that CSG is planning on making more acquisitions. So this isn't the end.
In other big company news, uh, Donald Trump has urged Intel's CEO lip boo tan to resign, citing alleged conflicts tied to his investments in Chinese tech companies. Though he gave no specifics. The call follows Senator Tom Cotton's warning about Tan's ties to China and past leadership at Cadence Design System, which violated US export controls.
Uh, tan who was appointed in March is steering intel through cost cuts and has cautioned that it may drop next gen chip making without a key customer. Uh, Intel, the only US producer of advanced semiconductors has received billions in subsidies, but trails, T-C-M-T-S-M-C, uh, neither Intel nor the White House commented, although I do believe, uh, today, um, they may be backing away from this a little bit on the announcement, shares of Intel fell 3%. Uh, Tom, is this, uh, a real security concern for the US or is this, uh, Trump's famous deal making in action?
So I'm gonna give you the shot and then I'm gonna give you the chaser. So stay tuned. Here's the shot.
This is stupid. Sorry that, that's my professional opinion. This is stupid.
You just announced that you are going to put a 100% tariff on any company who's not making chips domestically. Um, nevermind the fact that TSMC is opening plants in Arizona to specifically get around this. We know that Intel is the only manufacturer of chips domestically, and then you call for the resignation of their CEO over what exactly the fact that he worked with a Chinese company.
Good luck finding people that haven't. That's the problem is that almost everybody in this industry has worked either for a Chinese company or a Chinese company subsidiary in a, you know, a, in a business sense for quite a while. In fact, I would argue that the reason why a lot of the CEOs that don't make it in the industry aren't making it is 'cause they're not working where that's happening.
I mean, look at a lot of those domestic companies that you love so much. They're, they either have people on the board or people who are in, in management who have some ties to China or, you know, something along those lines. So why would you cut off your own nose, spite your face?
Yes, we have reported over the last few weeks that there are problems that Intel is having that they are basically kind of turning the ship as it were. They realize that foundries are not an immediate panacea for their problems. They're gonna take investment.
Uh, those chips act funds come with some strings, and now they're looking at the real possibility that they may not get to stick around long enough to enjoy the fruits of those labors. Uh, I was listening to a video that was recorded by Gamers Nexus here recently where they pulled no punches in saying that this is a huge problem for Intel, and those are the folks that are working on it from the game, uh, video graphics side, you know, these are not enterprises. Now, all that being said, here's the chaser lip.
Bhutan went to the White House on Monday, and suddenly after having a closed door meeting with the president, president says he is an okay guy. President says it's all cool until stock jumped 3% on the news. So I wonder what was said behind that closed door that could possibly make the president of the United States who's notorious for sticking to his guns on every decision that he makes suddenly about face.
I wonder if it has anything to do with the other big news that was coming out this week from the competitors to Intel. Hmm. Let's analyze that, Chris, because I wanna hear your thoughts on the fact that Nvidia and a MD are gonna be sharing 15% of their Chinese revenue with the US government in return for licenses to sell the H 20 and MI 3 0 8 chips.
There. You may recall those chips were specifically banned from being sold to Chinese markets. Of course, everyone's favorite president brokered this deal.
It's quite unusual because I can't remember in recent memory when a corporation paid the US government a cut of their profits. But it is highly beneficial because it lets both companies keep a foothold in the Chinese market and avoids letting them lose ground to companies like Huawei. Although there is the possibility there could be future levies.
The agreement highlights the strategic importance of semiconductors while leaving China torn between its need for advanced chips and its frustration over added costs and political concerns. I'll also note that in a news article released this week, China says they don't want the H 20 anywhere near any of their sensitive government, uh, data for some reason or another. So, Chris, I have to ask, given what happened with Intel and given this news, do you think it's bribery like I do?
Well, the only good thing about this potential bribery is that the money is going to the government and, and not at least what we've seen publicly into any individual, uh, individual pockets, right? So this 15% is gonna be paid into the us It's basically a tax, uh, I guess it's not really a tariff since it's not being levied at the, for it's for exports, not imports. But anyway, um, there is money coming to the US for this and it, it probably at least helps, uh, Nvidia and a MD, right?
5 billion on not being able to sell H 20 chips into China. And Jensen Huang, you know, came out and said, this is gonna cost us over the next two or three years, $50 billion. So I'm, I'm sure that he is breathing a sigh of relief and maybe the Nvidia shareholders as well that this is gonna end up costing quite a bit less.
Uh, there's a really good chance, um, despite what the Chinese government has said, that the H 20 chip is going to grow rapidly in the Chinese market and potentially make up something like 70% of NVIDIA's market share in China fairly rapidly. So even with a 15% tax tariff fee bribe on top of that, uh, it, it's still gonna do quite well for both Nvidia and their shareholders. And as you said, this also hopefully moves Nvidia or continues to move Nvidia into a place where their chips are being used in AI applications even in China.
I think the outright ban has a potential to split the market, right? Where we see AI development happening completely separately in, in two different parts of the world. Um, now there are other geopolitical concerns here, right?
I mean is, you know, is this just a money thing where selling the chips matters only because of the money that's gonna come back to the us or does this matter because selling the chips allows China and their companies to get a foothold up on ai. There's some interesting questions that I don't have answers whether this is the right move or not, from the AI arms race perspective, call it. Um, I, I do think that as you mentioned, kind of related back to the Intel thing, that this is probably a sign of things to come.
I think there's a pretty good, um, prospect that we will see additional individual company deals with the US government, with the US president, uh, what that means exactly. I'm not sure. Uh, but I do think we will see this to continue.
Um, some places where I think some folks might be worried is in smaller organizations, if you are not the CEO of Intel, if you're not running Nvidia, if you're not running a MD, uh, and you just happen to be beholden to these other big tariffs and you can't find a way to do a deal with the president of the United States to get out of it, uh, what does that mean? What does that mean for our economy? Uh, only something like, I think it's like 20%, 18% of the US population is employed by Fortune 50 companies.
Uh, so most of us work for smaller businesses that may not have the ability, uh, to show up like Tim Cook did with a bar of gold and some glass, uh, after making some significant investments in the US to bring Apple back in terms with the president. Um, so the fallout here could be widespread. Um, it's also possible that we'll just all get rich off of Nvidia stock because they can now sell the H 20 into, uh, China.
Lots of to determine there. Um, one thing that is not gonna be determined anymore, because it has been is the a OL will end its dial up internet service on September 30th, 2025, closing a chapter in internet history that began in 1991. Uh, the shutdown also ends related software like the A OL dialer and the A OL Shield browser, uh, while largely obsolete dial up still had about 265,000 US users in 2019.
The, the most recent data I have here, many of them were sticking with it out of habit, some fear of losing access to familiar services, um, for others ending their subscription was an emotional step even after switching to broadband. They hang on to that. A, uh, a OL connection.
Uh, maybe remembering the nostalgic sounds that it made, uh, when they first dialed up this move definitely marks, uh, both the end of that nostalgic era and also a broader shift away from older online models. Uh, Tom, what does this mean for broadband generally and, and maybe technology and specifically are, are we putting things to bed too soon or is this the right move at the right time? Well, I've done the math, Chris and I figured out that by September 30th, I will just about be out of those 1000 free hours that I got from Intel, which is great because, uh, I ha I like hate letting things go to waste.
Uh, thi this news was kind of interesting because I'm sure just like a lot of people out there, someone went wait, a OL still offered dial up, which was then quickly followed by wait, a OL is still in business. Uh, by the way, uh, they, they were sold off to Verizon along with the rest of the Yahoo thing. Uh, for those of you who may remember the heady days of a OL Time Warner owning damn near everything, and now we're at like, oh yeah, they're still around.
Most of the people who were subscribing to that, uh, to the service, you know, those 200,000 something people, uh, I think actually the latest report says that it's down under 200,000. Now they are, uh, they're, they're stodgy. They're probably older folks who don't like change.
Uh, they, it AOL's comforting, right? It, it's everything you need at your fingertips. Even if you go to like your a OL newsfeed now, it's basically a Yahoo newsfeed with yellow all over it.
But I think that one of the reasons why it was still floated the way that it was, was that there was revenue to be made from having a portal. Like we all remember the days of your homepage being set to Yahoo or a OL or com server prodigy or, or whatever. And, and you did all your work there.
And very rarely did you escape out into the wider internet. I can still remember, I, I made the choice for CompuServe 'cause it made the most sense to me. But downloading NCSA mosaic for the very first time and using it to go outside of CompuServe.
And I feel like a lot of people have that same opinion about a OL. Uh, there's the kinds of people who are still on dialup are the kinds of people that think that you still need to use a OL to access the internet to be able to check your a email, not knowing that it's been web mail for years. And finally it got to the point where the amount of money they were making off the portal did not equate to the amount of money that they're making, you know, that's costing them to keep the the system up.
But another thing that you need to consider here is the fact that traditional carriers are dumping their local loop access as quickly as possible. This is something that I've been tracking for quite a while in the telecom industry, is that companies like at and t and Verizon have been mandated for years to provide 9 1 1 access to households. And the way that they do that is they bundle up their, you know, rural telephone access and they sell it off to a company.
And then that way they can say they're partnering with those companies to provide that access, but they're not taking on the debts and the maintenance costs for those local loops because they're still pretty outdated. But we live in a world now where most people have a cell phone, uh, for one reason or another. And the idea of having a home phone is kind of quaint and archaic.
And that means there's no money in maintaining those lines anymore. 'cause you're not getting those fat wonderful subscriber fees from them. So what to do?
Well, I would like to divest that crap as much as possible if I was in a phone company that was paying for not very much profit. And that means that the services that use that are gonna slowly go away. And that's not just a OL dial up.
That's things like fire alarms that are, you know, using traditional telephone lines. So there could be a bigger story here. However, I don't think the people who are using a OL are gonna know anything about it.
Um, maybe there's a rural ISP that they can use that has some kind of a wisp. I don't know if we can teach them how to tether off of their phone. It's gonna be tough.
If only there was someone to tell me that I've got mail to make it all better. We had a story that we wanted to take a closer look at this week because it could potentially have some big implications for development at large. Microsoft is going to be making GitHub part of its core AI team.
After GitHub, CEO, Thomas Domkey announced that he is going to be leaving to get back into the startup game, according to his press release. Domkey is gonna stay on at Microsoft until the end of 2025 to help with the transition. You're probably wondering to yourself, well man, GitHub is a huge thing.
I wonder who they're gonna get to take over as CEO for this crown jewel of their, uh, product offerings. Uh, well, they're not, the Microsoft team has decided that rather than keeping GitHub kind of off on its own, they're gonna be moving it under Microsoft's AI group, which is led by Jay Par. This move shows that Microsoft has a plan to connect GitHub more closely with its AI tools and developer platform as they go all out on ai.
But it has a lot of people in the industry very concerned about what would happen to a platform that's so universally loved like GitHub if suddenly it becomes an AI factory. Chris, what do you think is going on here? Uh, I think that people are right.
Uh, I think it's really interesting to think about this. I mean, so just, just contextualizing this move in some ways, at least in my head, the way I think about it, right, is that, uh, Git was actually created in 2005 by Linus Als, uh, who was most famous for creating Linux, or some people call it Linus, um, in honor of his name. Um, but, uh, Linux, you know, and so GI was created as a place to be able to maintain the Linux source code because, uh, license for Bit Keeper had like the non-commercial license for Bit Keeper was removed.
And so out of necessity, uh, Linus and team created Git. Now, then a few years after that, some other folks came along and built GitHub to make it a little bit easier to use. And by about 2011, this was the place, um, beat an outsource forge and a bunch of others to put your open source code.
Uh, in 2018, people started to freak out a little bit when Microsoft came in and bought GitHub. Um, but honestly it didn't really make that big much of a difference. I think people have continued to use GitHub.
Uh, Microsoft kind of stayed outta the way, let it operate independently. Um, people haven't been too worried about the ownership by Microsoft. That may all change right now, um, 20 years after the invention of Git because as you said, they are intentionally moving the entire GitHub organization underneath their AI org, right?
Which signals pretty loudly. I think that they probably have been and definitely will be using this code themselves for training, uh, as much as possible. This is something that Microsoft has already done.
Um, we've seen this with LinkedIn where, you know, again, same kind of thing, right? The original acquisition caused some people to get a little bit worried. Uh, then over time they said, oh no, it just works.
It's all fine. Um, and now I believe we're fairly certain that Microsoft is using this data to train AI models. Now this obviously isn't just Microsoft.
Um, it is now fairly apparent that Elon Musk, uh, bought Twitter for the data to create AI models. This has been going on and on and on. Uh, other folks didn't even buy companies.
They just went out and took the data off the internet to train their AI models. So this is something that's definitely part of the zeitgeist right now. I do think it could have a fairly significant chilling effect on the open source community and their use of GitHub.
Um, now that said, maybe no one cares anymore. Maybe everyone's fine sharing their code with the AI overlords and it won't have an effect. I I think that we will see some fallout though.
Uh, what do you think, Tom? How dare you be smirch the vibe coding community by saying that code has to be uploaded somewhere and isn't generated by a programmatic interface. Yeah, I got nothing there.
I agree with you. This is a problem. Um, I can remember the alarm bells going off when Microsoft bought Get, and that was like an $8 billion acquisition.
And people are like, what are you gonna do with GitHub? Because you can't run ads on it. I mean, you kind of can, but like, what?
Where's the value? And and they mollified them a little bit at first by saying, no, no, no, no, it's gonna be run independently. We're gonna, we're gonna let them do their thing and we're just happy to be associated with it.
And I know several people who worked as community developers over there and, and worked with the community to kind of write that ship and make people understand that this was something that Microsoft owned but didn't have a finger in. But you've noticed over the last few years that they keep dipping their toe in the water of AI things. Maybe we're gonna add this AI coding assistant to kind of help you do a little extra code generation or, you know, we're gonna let you have the option to opt in to letting AI scan your repositories.
And what happened almost every time GitHub community got the pitchforks and the torches out and said, we don't want this. This is wrong. This is not the kind of advancement that we are supporting because we're GitHub dammit, and this is what we do.
And I think Microsoft was taking notes, if I'm being completely honest with myself. And they said, okay, we can't ease people into this, so we buy it our time, right? We, we give GitHub its ability to do its thing and eventually Thomas Domkey gets bored because that's what startup people do, is they get a nice cushy job at a big company with, uh, free bananas in the break room, and then they get bored because there's no hustle anymore.
There's no grind, there's no life or death situations about pushing code out the door. And they want to get back to that. Microsoft said, great, that's awesome.
We love that for you. You didn't have any plans for what you wanted to do with GitHub after you left, right? 'cause we have plans.
And so they put those plans in place by saying, we're not gonna hire a new CEO, we're not gonna promote from within. We're gonna give it to Jay Paric, who, if I'm being generous, has a pretty bad reputation in the industry for management of companies. And now we're going to consume all of GitHub.
So if I'm someone on the outside looking in, what am I thinking? Anything I upload to GitHub now is gonna be munched through, uh, you know, OpenAI because Microsoft's gonna take it. They're gonna feed it to the monster.
And then what does that mean for my code in the future? There's no attribution. There's no nothing.
All of that stuff means that I may not want use GitHub anymore. And then we run into this positive feedback loop, right? Of, if I don't wanna use GitHub, I'm not gonna upload my code there.
Which means there's fewer submissions being uploaded to GitHub, which means there's fewer, um, data points to be ingested into, uh, OpenAI. And then that means eventually there's gonna be a trickle of information as opposed to the flood that we have. Now, the problem, of course, is the same problem that you have when you mentioned Twitter, uh, x whatever you wanna call it today.
This is where everybody is like, like GitHub is universal at this point. Uh, you know, you can use it, your GitHub profile page as identity verification for things like PGP keys. You can't recreate GitHub overnight.
I'm sorry folks. You can't, it's just impossible because it's the combination of creating a platform that people want to use and encouraging them to get there. It's the reason why Twitter hasn't disappeared yet is because it's where everybody is.
We all do deference to places like Thing and Mastodon and Blue Sky and all those other places. Twitter is still where everybody's at. So GitHub has some time, they probably have at least a year if not more of kind of coasting on this.
But eventually people are gonna wake up and they're gonna say, I don't quite trust this unless there are some very bright lines drawn right now. We're not gonna be using this to train open AI data. We're not gonna be using it to do all these other things.
We're not gonna use it to compete against you. Please continue to use our service. Please continue to pay us to use the service.
The question is, would a company like Microsoft come out and say that and mean it? So there is another potential way to look at this, which is that Microsoft just wants to be the platform for ai. Uh, there was a recent, um, dust up, uh, I think it was on X or or or Twitter or whatever we're calling it where Elon said something about Open AI is gonna come and eat Microsoft for lunch.
Um, and Microsoft's CEO, um, replied by saying that people have been trying to do that for 50 years. And that's the fun of it. Uh, and then went on to say, I'm excited for Grok four on Azure and looking forward to Grok five, which seems like a really playful way of saying, Hey, you're still using Microsoft.
Um, now that doesn't mean they're not going to completely, you know, just train on all of the code that's on GitHub. Um, but also doesn't mean that they're gonna do anything nefarious. Maybe just having that there and being able to train on it, um, maybe that does lead to Microsoft just being this kind of more open than they have been in the past platform for AI where all comers can get the benefit.
I'm not sure. I'm not sure either. And the altruism behind just wanting to be the platform and the place where everybody goes is the optimistic solution.
But, um, I, I also see how a lot of places that build the platform or the place where everybody wants to go suddenly start trying to find ways to monetize that platform after a while. And that doesn't always work out for people. I can tell you what does work out for people that's Tech Field Day.
'cause we have lots of great upcoming Tech Field Day events that you're gonna want take part in. Next week is a big one. Uh, just about a week from now we're gonna be in Cleveland for Tech Field Day Extra at Share.
Uh, Steven FoST has some great presentations coming out of, uh, everybody's favorite jewel of Lake Erie. com. Then we're gonna take a couple weeks off, let the heat die down a little bit, and then Alistair is gonna be back with the AI infrastructure field Day three.
This is another event that's shaping up to be quite jam packed with great presentations. And then I'm gonna be back at the end of September for the next edition of Security Field Day because we are excited to hear from companies like One Password about some of the cool stuff they're doing in the enterprise. com for the latest on all of the things that we're doing with these events and more stay tuned because you never know when we might sneak one in on you and you won't wanna miss any of the action.
Just like you don't wanna miss any of the action. Every Wednesday when we publish the rundown, we love recording this for each and every one of you out there. When we love the fact that you get so much of your news from us during the week, don't forget that you can check out our website to learn more from the show notes.
You can also head over to YouTube and watch the videos. So if you wanna see me kind of waggling my finger and shaking my head back and forth, uh, if you're more of an audio file, make sure you use your favorite podcast application of choice and subscribe to the Tech Field Day rundown. And don't forget that we often hang out on a lot of other future and group programs, and we have a lot of great videos and podcasts out there that you're gonna wanna take advantage of.
We're gonna be back next week to talk about all of the IT news that happened between well now and then. But until then, make sure you guys take care of yourselves. Make sure that you are looking out for each other, and we hope that we will see you in the next edition of the Rundown.