Techstrong TV August 28, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Apple open AI in cahoots. Who would've thought you're watching? Textron Gang.
Hey everybody. Welcome to the Textron Gang. We're here talking about the latest and greatest events of the day, once, one more time.
And we're gonna talk a little bit about this lawsuit that Musk has filed against OpenAI and Apple, talking about, well, are they in cahoots and are they trying to lock everybody out and make only their apps available on these various marketplaces? Who knows? I think we've seen this story before, John.
Mm-hmm. Yep. It seems to me that there's also a pattern here, and some folks are saying that, well, Musk is just trying to harass these poor old folks, but what's your take on what's going on here?
Yeah, so lemme just to quickly recap, as you said, it's history repeating itself. So Musk, uh, a X AI in particular filed this antitrust lawsuit in federal court in Texas. It claims that Apple and open ar colluding to stifle competition in AI through this anti-competitive scheme, quote unquote.
Um, the, and we've heard this before, or the, the, the claim is that Apple's App Store is DeRio deprioritizing rival chatbots and super apps that include grok and x this something along the same lines that we heard from Epic Games and Yelp when they went after Apple. And for the most part, apple won that case. Uh, they're saying the same thing happen, same thing with the Justice Department and Google Chrome and favoritism on the App store there.
So this is related, as you said, to a a, an agreement between Apple and Open AI to integrate chat GPT into the iPhone and other devices, including MacBooks. Um, as you said, Mike, this is interesting in that Musk is going to court, which he's legally, uh, able to do, and maybe there is some element of truth to his lawsuit, but I think in a sense he's also, uh, instead of battling these guys through strategizing and innovating, but he's suing and, and perhaps trying to slow down the process of their agreements. At the same time, Musk has been suing OpenAI seemingly, or has some sort of scheme to take over a OpenAI for the last couple of years.
So it's part of this, uh, ongoing pattern of harassment that OpenAI claims he's done. It's, uh, it'll be interesting to see what falls out. And one, one caveat, and I'll throw this to the gang, but one caveat to keep in mind is that there will be some sort of ruling in the Justice Department Google Chrome case, and we're gonna figure out what the remedy is, if there is one, probably any, any day now.
So, um, again, it's, it's the latest episode of Open AI versus Musk and how Apple's been dragged into it Heavy. That thumbs it up. That's how I feel, Terry.
Yeah. Yeah, I don't know. You know, this is kind of, I mean, not that there isn't a bit of truth to this, as you said, you know, and, and, and we've seen a pattern here, but Musk, I mean, it's, it's almost like does he have an ounce of self-awareness or does he even care because, you know, he's unfairly put his thumb on so much, and especially in the last six months, and I, I just, uh, I don't know.
It is, it does seem like a bit harassing to me. And Tom, do you, Tom, do you think, and all brands, Yeah. Tom, do you think that app stores are gonna be the primary vehicle for distributing AI agents in these types of apps?
Or might something else emerge as a way that we gain access to these things? I'm wondering, you know, does Apple still reign Supreme in terms of that app store or the one that Google has is, I mean, not Google, Samsung has its own thing version of that I think, or Google and Samsung do as well. But, um, will other marketplaces and other distribution vehicles become more relevant in the age of ai?
It depends on where you think the AI agents are being run. If you think they're primarily being run on laptops, then no, the, the app store model is not going to be the one that's gonna dominate because most people don't use the Mac App store or the Windows App store for that matter. They, they prefer to go out and download the software.
But if you believe that the install base of mobile devices is still gonna be the primary way that people consume things, then absolutely, yes. I mean, how many people use Gemini as like their default search engine now? Uh, how many people have a chat GPT app on their phone or use the integration that Apple's built in to, to do any kind of, well, pretty much anything.
I think what you're running into here is, well, this feels like a fishing expedition because all Apple has to do is prove that at any point over the last year that anything that wasn't chat GPT ranked higher than every other thing. And, and we know that it did several times, actually. Um, the thing that I think the XI and Elon Musk people are looking for is one of those smoking gun emails, right?
Like, you know, the evil like tinted fingers, let's work together to manipulate this. So XAI never wins. Ha ha ha ha ha.
You actually have to type out the laughing too, otherwise it's not in incriminating enough. Um, but, but that's what they're hoping for, right? Because like you said, the, the Epic Apple lawsuit really was won by Apple on almost every count except for that one count that ended up causing all of this thing.
Because then, you know, uh, Sweeney gets to run around and claim that he defeated Apple and Fortnite ISS back in the app store, and now everybody has to do this. And honestly, that's the one that opened up people to be able to take payments directly from That, right? They went, they went like nine out of the 10, uh, claims, um, epic did.
Yeah. But all it takes is that one, and that's what they're hoping for here. And I mean, all you have to know about why this was filed, the way that it was, was look at where it was filed, wasn't filed in California where all those companies are headquartered.
It was filed in the state of Texas. They're looking for a very friendly judge to let them go fishing. Yeah.
And they're likely to Find, it's kind of funny, funny too, is that, um, sorry Terry, lemme I'll really quickly say this is funny too, is that if, if considering Apple a threat in the AI space as, as of now is, is a little laughable. There's even reports that Apple is so desperate to get back in a race, they're gonna think about the rumors about buying Perplexity or Misra. So, um, again, but I know I think more of it's an antagonism to towards app open ai.
But, but I mean, it's just, yeah, It is John. But, but it goes back to the question you asked me about the App store. Apple is not a threat to open ai, X ai, any of these massive AI focused companies, just like Microsoft Windows was not a threat in the browser market until they started bundling Internet Explorer with Windows 98 and suddenly the default option on the desktop was Microsoft Internet Explorer, not navigator, not Mosaic, not any of those other ones.
That's the real reason that an explorer took off is because for all of us who have like our preferred coffees, who have our preferred cars, who have all of these things that we've built in our lives that we will go out of our way to do, most people won't cross the street for a nickel to save on gas. They'll just take whatever the default is. And, and that's where the other argument in this whole case falls apart.
Well, you know, uh, Apple's working to, um, you know, push everybody else down by only offering chat GPT, and yet I didn't see anybody from XAI or Perplexity or Google ponying up the cash to be on that little dropdown list in iOS, because that's what this is really about. This is not an anti-competitive, um, backroom, uh, you know, take over the world kind of deal. This was about money, plain and simple.
This was Chad, GBT and Apple got together and said, what's a dollar amount that would make this thing pop up? And they came to that dollar amount, and that's how Google is the default search engine on an iPhone, right? And the only reason that you have an option to drop outta that list now is because of an antitrust ruling.
And I think that we're gonna see that in the future is that as more companies pay up to get on that list, maybe they'll randomize the way that it shows up or whatever. There'll be an algorithm that prevents chat GPT from always being the first um, option. But my question there is, will X AI pay to be there, or are they going to attempt to use this court case as a way to say we have to be included in that list for free?
Otherwise, you obviously are discriminating against us. So, John, let me ask you this. Are other companies likely to join this lawsuit Or Yeah, that's, are they Yeah, I thinking about that.
Yeah, that's, that, that's, that's a really interesting question. I think it's probably inevitable, but I'm not sure which companies would do it. I mean, I know in the Epic case we had Yelp and others were kind of the quiet partners.
One. The one thing that, uh, you know, when Tom was mentioning the smoking gun email, I, with Apple's history, these things crop up. It happened in the Epic case, uh, to lesser state Google.
Uh, so maybe there is something out there, but, um, I do think other companies are going to, are probably gonna join, but these are usually like the chorus companies that are part of the, the background noise. But, um, yes, it's inevitable, I think. And what kind of AI agents do you think will be downloaded?
Because I think we're talking about different things. I feel like most AI agents are gonna be kind of in app already. They're gonna be something I downloaded from an app and I'm gonna buy them or while I'm in that app.
But I guess there's gonna be these so-called, uh, super apps that are AI agents that do all kinds of tasks for us. And I'm not sure everybody wants like one agent to do everything. Tom, how do you think that we're gonna wind up using these agents?
I think we're gonna pick our preferred one that gives us the best answers or is useful for a very specific purpose. And we're gonna go to that one for that purpose. I mean, look at what people do now.
They, they use Claude for coding, they use chat GPT for language analysis. Um, it like, it makes me think back to the days when there was actually a way to natively tweet from iOS, right? Instead of opening up the Twitter app, you could actually like craft a tweet from the share sheet.
You know why you can't do that now? Because it sucked. Like all of the advanced features that people were putting into the Twitter app to do all of these crazy things never got ported over because it's integrated into the operating system, right?
Like it is, that's one of the reasons why Apple had to decouple so many of their apps from the operating system in the first place, is because they can't rev them fast enough to keep up with everything else. And I think that what's gonna end up happening is as the, the rate of change that you're seeing from all these AI applications, adding new features, rolling out new models, that's only going to be appealing to customers if they can be on the latest one. And if you are just simply sending the, uh, information off to the cloud to be processed, that's one thing.
But I don't think people wanna super app, right? Like there are things that Gemini is good at that it sucks in other places. And there are other apps that are probably gonna come along and be like, Hey, we are the AI app for solving math equations.
Well, if you're in math class, you're gonna want to use that one. And I don't think you're gonna just, there's not one, a single one stop shop. Mm-hmm.
Yeah. So that's why I'm wondering why I don't think the dominance factor maybe is big an issue here. But John, what are the odds that the president of the United States gets involved in this conversation?
Well, he's at, he's at odds with Musk. So Musk's outta luck. Um, unless Musk goes kissing the ring, I mean, I, I'm, I'm thinking to, uh, to, I don't wanna go go down the rabbit trail of Intel, but, and we saw how that worked out, how the government's, uh, intervention happened there.
It was through back channels. So I don't, I don't think he's interested in this. If anything, he's gonna throw his considerable weight behind Apple.
If he does, I don't think he cares or knows anything about this. Sorry, go ahead Terry. I was just gonna say, given his seemingly tight relationship with Tim Cook these days, I think, uh, Musk is outta luck.
And then possibly, you know, Trump will be behind, uh, apple if he has to choose sides. But, you know, you never know. I mean, I think he always tries to, to throw his weight around, uh, and, and sort of randomly, I mean, look at the Cracker Barrel logo thing.
I mean, those guys caved in a day, right? To go back to the old one, I think I, I think if on a whim he decides he's gonna get involved, that's he'll do it. You, you know, you, you're right about his, the, the, the, the relationship with, with with Cook, but I also, and also open ai, right?
That's the whole, uh, Stargate project, which, you know, he and Altman were very tight on, which is still trying to, trying to resurrect itself despite what people, despite all the facts about it, I don't know. I would look at it this way. Um, Apple's taken what, 30% of all the sales that go through that store from third party.
So maybe the United States government can, can collect 10% of that. What do you say When you, if you run a number 30, if you run the 30% figure by Trump, when he becomes aware of it, yes, they will become involved. Well, somebody's gotta pay for that golden ballroom.
So I think, you know, this is as good a place as any take a little money. I, I'm with Tom though. I do think that this is a fishing expedition and I think it's gonna make fascinating reading and I think everybody's gonna want to see what's in those documents.
And, um, at the very least, you know, even if it's not illegal, we'll have a better sense of what the actual intent is, right? And then more people will know what Go on. You can see, you can see some embarrassing disclosures unintentionally, um, on the part of Apple.
They seem to have a history of these things. All right, well folks, we're going to stop this conversation right here, but, um, we're going monitor this closely 'cause I know John's gonna be looking for those court documents just for, if not for anything, for his own amusement, but I'm sure he'll share it with all of us. That's True.
That's alright. All right. We'll be back in a minute.
Guess Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're gonna have a little chat now about Broadcom, which had its big VMware Explorer event, which is where I am and why it's so dark here at this moment. 'cause it's the wee hours in the morning still.
But it's an interesting time here for Broadcom and VMware. 'cause of course there's a lot of concern about the VMware licensing, a lot of consternation. There's only about maybe a slightly north of 4,000 folks here.
So Broadcom's clearly saying, you know, we only want a certain select type of customer here. And they're not funding this whole thing the way they used to. But there's a couple interesting announcements.
And the first of which is that they are taking the AI services that used to be an add-on for VMware Cloud Foundation are now part of the package. And what they're saying is that, well, everything's gonna run AI and VMware is gonna be the best platform for running inference engines, and that should just be part of the standard offering. That kind of changes the economics of AI and the enterprise for a lot of folks.
And then they turned around and partnered with a MD and said, we'll also support the A MD GPUs alongside the Nvidia GPUs in that platform as well. And then there was some other interesting news that they did on the DevOps front where, um, they first they partnered with Canonical and Ubuntu, and then they took the Argo CD and made that part of the add-on services for VCF, which is VMware Cloud Foundation if you're not following along. And what they're saying in that end of it is that that too will become a standard capability of the platform and maybe a lot of folks won't be able need to go buy a separate continuous delivery platform versus a CI platform, which might still be separate.
But Tom, I know you've been following Broadcom closely in all these years and we've done a lot of stuff with them lately on your side of the house. What's your take on what's going on here? I feel like they have made VCF nine kind of their, their transformational platform, right?
Like they, they listened to the customers, they've said that these are the things that we're gonna integrate. We're adding all these features. Please don't go to the cloud.
Please stay with us. We know we can run things in containers now. And when you look at the, the announcements that came out of here, they really are shifting and they are tripling down on this fact that you can run containerized workloads inside of VMware.
I think that what they're effectively saying is, no matter what happens in the future, you can still use the same interfaces that you've used before, the ones that you're comfortable with, the ones that your people have been trained on, who cares what's happening in the backend, right? That's, that's magic. We'll, we'll figure out how to make those workloads work.
And at the same time, the the news about the A-M-D-G-P-U thing, honestly, that's just smart. Like why would you get locked in on Nvidia? Yeah.
They're the market leader. Um, that's a little bit if from my networking background, that's like saying, well, we should make the CLI of this device look like a Cisco device because Cisco's the market leader and everybody's gonna know how to use that. Just ask literally anybody else who uses ACL I, uh, they, some of them will do it kind of contrarian on purpose.
And I think that that's what they're saying here is I think VMware is expecting there's going to be a bunch of contrarianism in the market saying, I purposefully choose not to use Nvidia and want to use a MD because I don't know, they're cheaper, they do this workload better, whatever. And if they're one of the few platforms that supports running on top of a MD GPUs, boy, they're gonna make a lot of money off of those folks because we'll pay almost anything to not run Nvidia and almost means about $5 less than what NVIDIA's charging. Sure.
Although everybody seems to be locked into Nvidia 'cause of that Cuda framework that they have. And I don't think a MD has got a lot of traction around its alternative. It's a tough sell.
Right? But that's what you've always wanted, right? Is you want to create, create a framework that everybody uses.
Nvidia has cuda, um, you know, Intel for a long time use GPDK on the network programming side until other things came along and, and kind of supplanted it. But if you can get ahold of a group of people who specifically choose not to use Cuda for one reason or another, like that's that target market, is it a huge target market? No.
Like it's, it's never going to be like the the trillion dollar money maker that everybody is chasing now. I mean, remember when a billion dollars is a unicorn? Oh, that's passe now.
Now we're, we're really in the stratosphere, but, but that's an underserved market that I think that they could easily pick up. Um, and not having a framework is not necessarily a bad thing because it gives companies a chance to innovate in areas and create their own frameworks and maybe come up and be the next cuda or at least Cuda light. Mm-hmm.
John, we've talked about these issues with, um, the licensing program outta Broadcom for a while now. They, um, you know, they, they stopped short of doing a victory lap here, but it was pretty damn close. I mean, last quarter they think they noted that the software infrastructure revenues were up 25% and they have another financial statement due out, I think in the next couple of weeks.
And everybody's talking expecting that it might be similar levels of growth. So it doesn't look like a lot of customers fled at the end of the day, or at least not the customers that Broadcom cared about. Yeah.
Yeah, that's true. There was that concern, right, of them hemorrhaging to that. There was, I think companies like Nutanix and others were trying to make hay from, from the, the, the, the coupling.
And it's, I think the signs are encouraging. I I'm gonna give you a little preview of something that Daniel Newman wrote for Forbes that's gonna come out soon. He did talk with the CEO of Broadcom, I believe in Las Vegas Hawk Tan.
They talked about VMware AI XPU development future of custom silicon. And based on that and what he saw, and based on what a lot of the stories you wrote, Mike, he Daniel has come to the conclusion that in terms of AI infrastructure, this company's gonna be one of the pillars along with Marvell, uh, technology for X-P-O-X-P-U growth acceleration. Um, so yeah, it's, it's situation is better than maybe it looked 12 or 18 months ago.
Um, so there are encouraging signs. Um, Broadcom to me is always like an interesting company whenever it's involved with coupling or teaming with another company. Everyone looks for the flaws and the whole arrangement based on the history of the company.
I know it's a long, kind of long history there. Um, so I think, I think things are more encouraging and, and yeah, when the results came up, came up, that might might surprise some people. Tom, I kind of wish somebody would write the Harvard Business case study of VMware.
Here's a company that we have been so dependent upon in it circles for years, and yet it keeps being bought and sold and it's kind of like, almost like nobody wants it and then they kick it around for a little while. But has Broadcom finally broken the code to make VMware a viable entity even more, you know, and profitable enough that it may just stay with Broadcom forever? Is this the final home?
You want the Harvard Business Review? I want the company man YouTube channel. 'cause it's only gonna be about 10 minutes long and it's gonna be like, and then bad things happen and then good things happen.
And, And it's gonna be in the AI narrative voice too, which where there'll be a lot of repetition of the same gap. The thing with VMware is it is the least likely company for people to care about. It's, it reminds me of a lot of the companies in Silicon Valley.
Like you're driving down First Street and you see companies that you recognize, right? And they're these tiny little office parks. And then you see a company like right next door and they have this enormous building.
You're like, I have never heard of this company in it before. What do they do? And then you look it up and it turns out like their biggest customer is the Department of Defense.
You're like, oh, that's why I don't hear about them. Because they're not trying to market to everybody. They have one or two customers that really rely on us and that's good enough for them.
I feel like VMware's always been in that spot, right? Like they, they kind of su subsumed the entire market. Like if you go back to 2002, managing individual servers, managing storage arrays, all of that stuff, that was like a career path.
And now it's not because we don't manage things that way. I would actually venture a guess that without server virtualization cloud as we know, it wouldn't exist. That that's a pretty easy argument to make.
The problem is, is that just like every other company that develops this technologies, they're always going to get supplanted by companies that come in after the fact that build on what that, um, development has happened and do things a little faster, a little cheaper. I mean, that's basically what Amazon and Microsoft and all the cloud companies have done. I think Broadcom has figured out a way to essentially kind of put the full weight of that company behind what VMware is offering.
You say that you've made them profitable. Yes, Broadcom absolutely has made them profitable at the expense of a lot of smaller companies, VMware customers. And, and that's an easy argument to make too.
Like we know that when you basically have cut out the bottom tier of licensing, you're effectively saying it's, it's the Apple problem, right? Apple will never sell a hundred dollars iPhone. There are a lot of people who would buy a hundred dollars iPhone, but Apple's not going to sell one because for them the value is in it being something that needs to be attainable.
That that is basically like a flagship product. Like there's no version of VCF that is not a flagship product right now. So I think what you're gonna end up seeing is Broadcom's gonna continue to push this and they're gonna make money hand over fist until someone comes in to cut them off at the bottom.
And we're already seeing companies that are lining up to do that. Um, HPE obviously has done that with Morpheus and, and they're putting that package together. A lot of the smaller competitors that were going against VMware for a very long time, like scale computing recently got acquired so that they can basically gear up to go after that small to medium sized market.
So I, I think VMware as a whole will probably be okay. But you also notice the other thing that Broadcom has done. When VMware got bought by EMC, it was still VMware.
Now it's VMware by Broadcom. That's the end goal here. They want the IP of Broad of what VMware offers, but they want it to be associated with Broadcom.
And I think that that's ultimately what's gonna happen. VMware will end up being successful as a part of Broadcom, just like Catalyst is still a very successful part of Cisco. I think Broadcom did a better job of reading the, the IT people, and I bring this up because there's so many people in this industry who still view themselves as I'm a VMware administrator.
They describe that's their title and their job function, and it's how they identify themselves and they're not rushing to give up that platform or go learn something new. In fact, you know, when Kubernetes came out, everybody thought that that was gonna be the end of VMware. And here it is now VMware is still rolling and Kubernetes is, you know, starting to gain more traction.
But lo and behold, Kubernetes is now embedded in VCF and the same IT administrators can manage that and maybe VMware will make that accessible much more so to mere mortals than right now. Kind of still requires software engineers to build and deploy. But as it goes along, it seems like maybe VMware has figured out that Microsoft strategy where we just kind of continue to subsume everything into the platform.
Is that what we're really looking at? I'll throw that to Tom. I think so.
I mean, what's, what's the real value of what the company provides, right? Is it the name or the technology? And I think in this case, VMware's real value is its technology.
And yes, I completely agree with you. If I bet against every technology that came out that was going to be the VMware killer, I probably could have bought VMware because everything is gonna, oh, this is the thing that's gonna do it. Yeah, this is the thing that's gonna do it.
Just like every new technology solution is the end all, be all solution that you're ever gonna need. It's gonna take care of everything. If you wonder why I'm so kind of blase about AI is because I've heard this about software defined networking, OpenFlow, ATM, lane, um, uh, you, you name it, even 8 0 2 point 11 wireless was gonna be the ethernet killer.
It's like, yeah. And, and that honestly, of all the things that came to pass more than anything else, and you still have to plug it in with an ethernet cable, but at the end of the day, I think that VMware is going to survive just like IBM has survived, just like Oracle has survived. But it won't be the same VMware that we saw in 2005.
It's gonna be a radically different company doing radically different things as a method of survival. You know, the the what the, the one thing that was interesting, and I and my mike answered the question you have too, Tom, was, I was gonna ask, how does this company, which I think of as almost like a cockroach, how does it, how does it survive? Uh, at every turn.
I mean as like, it's almost considered it, it's been considered quasi irrelevance, you know, in the mainstream press at least for so long. Um, and I, and again, again, I just chalked up to the, the proponents of it who use it and their reluctance to, to let it go. Uh, so it's just fascinating Here.
Here's the argument that you have to make for that. It's not the company surviving. I think that VMware is the company of thesis because this is not VMware.
This is the conglomeration of VMware getting bought by EMC, bought by Dell, bought by Broadcom. Here's the other argument. I actually made this on the, the tech build day rundown.
Uh, yesterday when we were doing our recording, um, I want you to think about I-B-M-I-B-M is a tech success story, right? Like that that is a company that has lasted forever. But one thing that I am notorious for telling people all the time, 'cause I was an intern at IBM in 2001, in, in Rochester, Minnesota land of the a 400 baby.
Um, this is not Tom and Tom. Yeah, it's full disclosure. I almost moved to Rochester, Minnesota as a kid because my dad was gonna be transferred there as an IBM engineer.
Yeah. And his state, he stayed in San Jose. But anyway, go ahead.
I'm sorry. Yeah, either you work for IBM or you work for Mayo. That's how it works in Rochester.
But I am notorious for telling people even after my time there in oh one, this is not Tom Watson's, IBM because it's not what you're seeing now. And and even back in the day, like prior to the Red Hat acquisition, what IBM actually was, was IBM Global Services and mainframes and now it's Red Hat and mainframes and a little bit of what IBM used to do, like remember the IBM labs and everything, like all of that research that came out, yeah, those don't exist anymore. That's all been packaged up and sold off.
And I think that's where VMware is right now. We talk about the name surviving, we talk about if, to use your term, the cockroach, right? Like no matter what you do, you can't kill it.
But that's not the same company that's come out the other side. All of the things that you know and love about what VMware was aren't there anymore. Sure.
The parts have been bolted back on and it kind of looks the same. But when you think about like NSX Horizon, um, like go back 10 years and look at that entire product portfolio and count the number of things that have been sold off, repackaged, killed off, I venture guess that more than 50% of it's gone now. Because in in Broadcom's defense, they did exactly what they needed to do to make the company survive, which was cut it to the quick and only concentrate on the things that work.
You know, it's the architect from the Matrix, right? There are levels of survival we are willing to accept. And that's how they have made it as long as they have is because they're not afraid to carve the company up as finely as necessary to make it live.
Right? We're also, you know, to your point, we're all watching what's going on with this tan zu platform where, um, Broadcom quietly replaced Kubernetes in that platform with Cloud Foundry and they're basically going with a, a streamlined version of Cloud Foundry. And if you remember, that was what Pivotal was all about.
It was basically a company that, you know, sold Cloud Foundry services and then that got rolled into VMware and then the question becomes, well, are they gonna sell that tan platform out and just focus on VMware? I don't know. It'd be an interesting conversation to see what happens.
I think it's a bad move if they do, to be honest with you, because that is where the value is coming right now, is running VMware management infrastructure on top of containerization. And that's why people are buying it is because they see that the writing on the wall, they're going to have to move. I don't know how many traditional places that are still using X 86 virtualization are going to be there forever.
'cause once they shut down that last server that runs whatever that application is, what's the alternative? Oh, well it runs in the cloud. Like you don't even need to have this on site anymore.
So I think that a lot of people are gonna slowly be dragged kicking and screaming that way, and at least VMware skating where the puck is going. And I think that replacing Kubernetes with Cloud Foundry is actually a brilliant move. Uh, if you've ever worked for a, uh, small business owner, this is, uh, oh yeah, well, I own the company, but I also own the building and I lease it back to the company and I own the delivery vans that I lease back to the company.
So I'm gonna get a little bit of a revenue stream from every part of this so that I can continue to make money through the whole thing. It just so happens that I can package it up in real pretty package and sell it to you. Mm-hmm.
And, and it's interesting to your point, maybe folks will get tired of Kubernetes and they'll just go with Cloud Foundry, which is more accessible, to be honest. So we will see. But John, I wanna ask you one last thing about this.
We have been inundated by vendors who are all saying, you know, they have something that competes against VMware. And I'm kind of scratching my head a little bit going, is that really the right tact? I mean, or maybe they should just make a case.
I Maybe they, they haven't, they haven't read the, the history of this company and the fact that it survives it. There's something, must be something appealing about it. 'cause people keep kept buying it or acquiring it.
And if you've got a number of companies saying they're competing against one company, it must mean that the company does a lot of things that those other companies are trying to do. I mean, that's just logic to me. All right, well folks, we're gonna leave this here, but it seems to me we'll be talking about VMware for at least another decade or more.
We'll see what happens. Hey folks, we'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers Network. Hey folks, we're back and we're returning to a topic that we talk a lot about on this show, which is software development and security.
And we're gonna revisit what happened in this, uh, Tarpa folks had a challenge and they had a bunch of companies show up, and then it looks like maybe they've, they found a way to automate some of this patching process, which is really at the root cause of many of our cybersecurity ills that bug us. But Terry, you, you looked into this, how real is any of this? Well, okay, that always remains to be seen.
I mean, it, it, it seems like this was positive, right? I mean, we're moving in a positive direction, but it also raises a whole bunch of other cyber issues as well. So the, the winners, uh, proved that they could patch real software, you know, quickly scalably cost effectively.
And, um, DARPA is putting some money behind that, uh, for them to be like, you know, opened, uh, on open source with their AI tools. And that's, that's all well and good, but it opens a bunch of cybersecurity issues, as I said before, um, because the attackers are waiting in the wings to use those same tools. And that's another thing we've talked about quite a bit.
So, So Tom, we've been afraid to patch software forever. And the, the root cause of that is that we worry that the patch is gonna be the cure that's worse than the disease and it will break the application. And yet I have to wonder if the patch, how often does it really do that?
And is the cybersecurity risk now greater than the fact that the patch might break the application? It's a trade off, right? It's risk analysis.
Do I take these systems down and patch them in the hope that I'm going to remove whatever the problem is only to make the situation worse? Look at Specter and meltdown like that is probably my, my prime example. That's the Harvard Business Review case for this is a patch that's worse than the problem because yes, you, you could do that weird memory like, you know, basically like putting your glass to the door kind of thing.
But you had to be very specifically targeted for that pipeline execution problem. And what, what's the fix? Oh yeah, we're gonna crater the performance of your box by like 30%.
Uh, but, but you're safe. And, and I think that one of the problems that we've had over the years with this idea of doing patching, at first it was, well, I don't wanna take the systems down. Well, okay, that's, that's a non-starter right now because of cloud resilience.
I, we can do this without taking the systems down. Now the problem is, oh, well what if I introduce more bugs into the system? Welcome to coding 1 0 1 folks.
Everything you do to fix a thing is gonna break something else. Now, either it'll be a good break that you'll detect right away and go, yeah, that was terrible. Or it'll be one of those hidden things that we won't see for years.
And and I, in some of the, the research that I did on this, I think it's funny that we're getting back to this old idea of, oh, well, if we release the code out there, then the hackers will be able to, uh, to scan it very quickly with these tools and write exploits. And that's what I want. I don't want them to develop this exploit and hold onto it for years and wait for the night before I go public with my company to attack me and steal all my data and all that.
I want people to break it right now. I mean, I am, I hate the move fast break things mantra because it, it, it feels wrong to me, but in security, please break my things faster because the faster you break it, the faster I can fix it. And then we don't have these problems anymore.
And we've seen that a lot with, uh, platforms that are like, you know what, we're gonna release these out of band patches. But the problem is, is that you, you can't let it get out of hand. Like in my old career, I worked a lot with, um, with Cisco phone systems, uh, the, the infamous call managers, some people are refer to it, call mangler.
Um, and it was not uncommon for people to be running on a non-standard patch version, the infamous engineering specials, which were patches written by Cisco T and delivered directly to you with instructions to never upgrade this system because I don't know that this patch will ever be rolled into anything in the future. And that created its own STR problems, right? Because now you're running on a version of code you can never actually get off of.
And I think that the, the problem ultimately is engineering people will are totally fine to patch stuff. Like, like if you told me today that I needed to update my phone and do a patch to it, yes, I am on top of it, who hates patching is management. Because management is assuming the risk that the system's gonna go down and they're gonna lose customers.
But more importantly, relating to the story with darpa, if it's an automated process doing it, I can't yell at someone for doing the wrong thing. I can't yell at a script, but if you hit the button to make it go live, I can yell at you, I can punish you, I can fire you, and then I can absolve myself. Terry is what Tom is describing maybe the root cause of why DevSecOps just hasn't quite taken on that level of deep adoption that we all thought we would see.
And part of the issue, I think is in a post on that Alan wrote where he is talking about, um, it's really a people pers uh, issue. It's not really of the tech. Yeah, I found that post, uh, interesting too.
And I think he's right because all of that, all of the other stuff, the automation and the whatever are supposed to be in support of the people, right? Isn't that what it, isn't that what it should be all about? And that's the part that we've lost sight of or that DevOps has lost sight of.
Uh, I mean it's complicated there, um, because things do move so quickly, I think, and, um, people, I always say this too, and I don't know how you guys give me a sense of how true you think it is that the development environment has changed so much. It used to be so closed, you know, everything was closed and on premise and whatever, and then you kind of opened it up. You had a lot of people that were used to working in that closed environment.
They weren't as careful as they should have been. Those are the kinds of things that I actually worry about more than the things that you sort of naturally introduce, you know, when you, when you patch or when you change code or whatever. Um, that, that there's still this not arrogance, but this tendency to not, uh, take the security part as seriously from the jump.
But I, I think that that whole bit about, you know, forgetting the people part of the con the equation is really the, IM maybe the important part. I mean, is there also any, I mean, different companies try to do it. They try to patch in some way that's less disruptive and less likely to bring down the system.
But I mean, I worked on a large, uh, research program a couple of years ago and that's, it's usually just not the case. They can't get around it. I I, you know, I'm not a hundred percent sure what the, the answer is there in terms of, uh, but DevOps and, and, and then on the patching side of things, I just don't, I don't know.
Mm-hmm. I feel like it's a management problem to this degree where we're just incentivizing the wrong things. We're so obsessed with we gotta ship code and we think that the code is gonna drive revenue, and it's not clear to me that it actually does, but then we wind up shipping stuff with known vulnerabilities in it that everybody knows there's gonna get exploited, but we do it anyway.
Well, that's the other thing. I mean, more recently, I mean, I would say in the last two or three months, I have read study after study where people are knowingly shipping, you know, code that's, that's corrupt, not right, you know, whatever. And I mean, they're knowingly doing that.
And I, so I guess it is in, as you know what you say, Mike, it is a management, uh, problem and it's a priority problem as well. All you've gotta do is think back to the way that we used to do stuff. And you, and you alluded to this, you know, it used to be, it was very closed development environments.
And, and I think of things like video games, right? Like some of the, the, the things that video games were notorious for we're shipped as code that was locked into a cartridge that could never be updated. Like the idea of shipping a new version of a, of a cartridge was foreign to people.
I mean, we still use the term it, the, the software's gone gold, right? And that comes from the fact that the software literally had to be pressed into a CD to be replicated, to be shipped out. And the Gold Master was that like, like we still use the GM as the build and we don't do that today, right?
Like, um, one of the biggest, uh, complaints in vi in the video game industry is that companies will ship a triple a million dollar title knowing that it's full of bugs because they know they can fix it with a patch on day one. In fact, it's, it's hilariously common now for you to have to download a patch as soon as you buy the game because oh yeah, we found a couple of bugs in the last week and we really need to fix those. And it's that mentality of it doesn't matter what happens, it has to be out the door.
Look at your, your iOS updates or your, your Windows updates or any of that other stuff. It used to be that the idea of an operating system for anything coming out every year was laughable. I mean, there's a reason why there's no Windows 96, windows 97, windows 99, because we waited until the software was done to ship it, and now it's like, no, no, no, just push it out the door.
Don't even put a version number on it anymore. Just call it Windows or Mac os or whatever. And, and I think that the, the challenge that you're gonna run into there is that if that runs headlong into the DevOps mentality, right?
Like ship it fast, ship it out the door, get things fixed. And like you said, it's a management problem, right? Because at the end of the day, why do I wanna keep shipping things?
Because I make money when I'm shipping code. I don't care if it's secure, I don't care if it works, just get it out the door so that people won't cancel their subscription to the thing that I buy. Yeah.
Well, but then how much does that cost you in the long run too? I mean, you're, you wanna make money, right? But you're gonna lose money if there vulnerabilities.
I don't know. I mean, but, but if systems go down, if people, you know, I, I don't know that you bleed enough customers that that, uh, costs you anything, but You wouldn't have to bleed, you wouldn't have to bleed fines that you would be levied, but the fines may not be large enough to be worried about compared to the revenue. So what does that, are they supposed to ramp up regulatory Things now?
Well, The only punishment for a criminal act is a fine, then what you're basically saying is, is that it's legal for a price. And with some of these things, if it's big enough, like if it can cause enough data leakage, I can get the government to pay me for it. So I privatize the profits and socialize the losses.
Like that's the thing. And a lot of the way that a lot of these companies work is, is, you know, the, the, the profits from selling the product go into this one bucket over here and support costs go into this bucket over here. And I can run this bucket at a loss forever and just claim, Hey, that's the cost of doing business.
And I'll find a way to balance this out in the end, but I get graded on this over here on the mythical 11% year over year profit increase and, and unlimited growth forever and ever. Amen. And that's the problem is it's that mentality.
The people that we used to work with were the kinds that were like, I'm not shipping this until it's done like that. The, the, the poster children for this were blizzard back in the day, you know, the, the creators of World of Warcraft and the Ablo and all those games that everybody loves to play, it was a joke that was like, when's it gonna be? When are you gonna ship it when it's done?
Like that was the tagline every time. If it takes another year to get it out the door, great, it'll be done and we'll be happy. When did, Hey Tom, what, when did things change and was there like an inflection point where, where that attitude just evaporated?
Or was it gradual? No, it, it, there there was not a specific inflection point, but the real, the, the downhill slide started when there was more money to be made by shipping things than there was by shipping the right things, uh, private equity getting involved and get, and starting to gut companies because it's like, Hey, I need to pull as much profit outta here as I can before this whole house of cards falls down. It's the, the massive investments that you're getting from Wall Street into these companies.
I mean, I'll tell you, when Blizzard went downhill, it's when Activision bought them. It's because Activision did not share that same code mentality. And I love the fact that you can still find people in the industry who care about it.
I, I would challenge the people who are listening to this episode of Textron Gang, go to the tech field, a website and look for any presentation from the CTO of Arista Networks. Ken Doda, that man cares about code quality because he gave a, a presentation a few years ago at one of our events where he flat out said, I won't buy a company if their code quality is bad because as soon as I buy that company, that's my code and I have to fix it. And that, that idea is foreign to some people.
Yeah, I mean it's just like this Zuckerberg school of thought, it just move fast and break things. I mean it works for that, it worked for them. I just think there's Just, could you imagine if we built a car like that?
Hey, move fast and break things if wheel fall off in The interstate, that's a not a Problem Guys. That's Tesla guys, we're gonna have to end this conversation 'cause we're running outta time. But, um, I would point out that, you know, I get that this is a money issue, but it's also maybe a matter of conscience and you should examine your conscience next time you ship software because well, you may be doing something that's just fundamentally wrong.
All right guys. Hey, thanks everybody for being on the show today, and thank you all for spending some time with us as we went through all these various topics. We'll be following this up with all kinds of new and interesting content from Textron tv.
So please stay tuned. Until then, we'll see you next time. Hey everyone, welcome back here to Tech Trunk tv.
My next guest is Gerima Kaur. Gima is the co-founder and co CEO of min io. That's M-I-N-I-O.
We're going to hear about the background of that name and how he came up, I'm sure. But first, let's welcome Garima to the show. Garima, welcome to Tech Drunk tv.
It's great to have you here. Thank you Alan for, uh, having me here. Looking forward to the conversation.
Absolutely. So Garima, before we talk about Min io and we're gonna talk about sovereign AI and, and that, but let's take a moment to talk about Garima. Okay.
All right. I don't have to tell you, we don't see a lot of co co-CEOs. Yes, we don't see a lot of women CEOs, frankly.
Not enough. Anyway, um, let's hear your story. I'm sure there's a story behind this.
Tell us. Yeah, no, absolutely. And since you mentioned co-CEO, I think for a founder, the only title that matters is always the founder and the creator and builder.
Other titles, you know, come and go. If you look at, uh, when I started, uh, me io I was in a COO role, CFO role. And that of course now, uh, I'm the CEO of the company.
So the titles evolved, but as a founder, the passion and the work that you do still remains very fluid across our organization. So yeah, I agree with you. Give us your background.
How did you come to found, uh, min io? It is quite interesting because my background is, uh, in finance and economics, nothing to do with tech. I was not interested in tech till I landed in Valley.
And uh, I think once you're in Silicon Valley, you kind of get plugged into that entire system of startups and VCs and get immersed in the tech world itself. And that is where, uh, once I started engaging more with startups, I was, um, an investor earlier. So that was my first foray into startups and, um, I realized that it's much more easier to advise than to do things yourself.
So, so when I was, yes, this is true. So as I was advising the startups, I'm like, I need to do something of my own. I need to build something of my own.
So it was just a very simple desire that I had within myself, and that became a thing of its own. And I think the timing of how everything came together was quite, uh, interesting because as I was thinking about starting my own company and uh, finding the problem that was exciting for, uh, me and my co-founders to go after, I think one thing that, you know, no matter what exploration, so searching that goes in the early phases, we did, it always came to the data problem. And it was like, this is a problem that is going to be relevant not only now, but 10, 20, 30 years from now.
And not only relevant, but grow exponentially. So we just started with that simple premise that we wanted to go after the data. And then in data, at a very high level, what do you do?
You either draw insights on data, which is on the compute part, or you store it at scale. So we started with the, the foundation that if we become the store of choice for data at scale, then anything that we build on top of it to understand the kind of data, the structure of the data that sits on our platform, it'll only lead to more value to our customer, so to more value, uh, uh, for overall for our organization. So I think that is the simple premise that we started.
And, uh, AWS had already educated the industry that, uh, object store as a technology is the right place to bring all your data to. AWS strategy was that, uh, bring all your data to AWS and we'll take care of it. Our strategy was that we'll go to all the places where data is getting generated.
So we just had a different strategy. But in terms of technology, scale, performance metrics, all the good stuff, uh, uh, we are a replacement for AWS S3. Excellent.
And look, it, it's amazing. I remember when they launched S3, to tell you the truth. And, uh, you know, there's always, and I'm not here to knock AWS at all, but you know, a lot of times it's the 80% of the functionality of 20% of the price type of offering.
Right. And it, it's like that big box store. Yeah, sure.
You can go to the big box store and buy a lot of things, but sometimes you want to go to the specialty stores when you want to get the Yeah. Better quality, you know, and, um, I, I, I get that whole way of looking at it. So tell us the minaya story.
First of all, how'd you come up with the name? So Minai be so storage industry, if you see overall, you know, uh, is filled with the players that, uh, thrive on complexity, to say the least. And, uh, for us, we really believe that anything that needs to scale or work at scale needs to be simple, needs to just do the job that it is meant to do without the complexity and overbearing features on it.
So that is where, uh, we came up with the name. Uh, it just, it's the core philosophy of the company. Minimalism, do everything that is needed to the perfection, but do not, uh, complex the system overall.
So I, that is where it comes. And then, you know, minimalist io, so it all added up together, and then it's a 4, 4, 5 letter word, so, you know, you cannot go wrong. So, Yeah, no, absolutely.
Fascinating. Yeah. You don't mind me asking, when, when did you find found?
MIN io? We incorporated in November of, uh, 2014, but the real work started in 2015 sometime, so, yeah. Yeah.
It's here at Textron. com first published in, uh, April, Mar, April, March, or April, I forget now, of 2014, so Right, right around when, when you started Min io. Interesting.
Um, and, you know, so it's been 10 years and, and 10 years is a great run, you know, at a startup. It is. What's changed, what, you know, when you look back 10 years ago, what was the idea behind MIN io, what you guys have done, and now you're sitting here, it's 2025.
Yeah. Almost 2026, I guess, right? We're closer to 2026 than we are Yeah.
I think in January. Yeah. I think so much has changed in the way the industry has operated.
I think before the interview, we were talking about, you know, how AI is just accelerating and compressing the entire timeline for, uh, everyone. But, uh, to give you a brief history, right? How fast the things have evolved when we started, right, the object store was kind of treated as, you know, the slow and deep tier for your data.
You know, just put the data once, never touch it. And if you see the cloud, which is AWS Azure, Google Cloud, the public cloud providers, they are built on object store. All their services natively run on object store.
So object store within cloud was never considered as the third tier storage. It was always considered as the main or the primary tier for storage to address that workload. But in the enterprise, the perception was of object store was in terms of, you know, cheap and deep kind of a tier.
So I think because the cloud right around the time we started and the cloud was rising, I think that perception kind of shifted quite a bit. And there was a requirement in terms of the object store that can deliver on the performance that is required by data analytics, workloads, query, query workloads. And now of course, with the AI workloads now, uh, you know, with the AI coming to forefront, I think it is going through one more shift.
You know, three, four years back, the CIOs were ques getting questioned, what is your cloud strategy? Now everyone is questioning them. What is your AI strategy?
And I think AI is decoupling some of the cloud strategy with the tech strategy, again, in terms of what is the tech stack that a lot of the enterprises want to have when they think about the AI stack overall. And I think that AI stack is defining what gets driven from the infrastructure standpoint as compared to, you know, the cloud first strategy that okay, we go to AWS and see what services we can get from there. So that shift has happened phenomenally.
And, uh, for min io perspective, we couldn't have, uh, asked for better timing. I think it's phenomenal time for all of us to be just part of the industry and part of the valley right now, because things are changing so fast and bulk of the AI training workloads happen on object store. If you see, you know, cloud or if you see open ai, it, you know, you name it Mistral, they're all run on object store.
And, uh, AYA has a very unique, uh, positioning and a play there when it comes to scale and performance to what these, uh, workloads require. So Yeah. Couldn't be more happier.
Absolutely. Absolutely. Um, you know, it's interesting.
We, uh, there's always usually a pendulum that swings. It is right, that goes from, uh, one throat to choke to best of breed from big, big box to boutique, from, you know, infinitely scalable to infinitely hands on, right? And, and bespoke, if you will.
Um, but yet this AI thing, I, I agree with you. It, it's just been the, the timelines, how everything is being compressed and done. I worry, I worry are we just going too fast and overlooking or putting, look, the, the tech industry is a magic bullet industry, right?
We always go after the next magic bullet, the next shiny trinket. Yeah. And AI is the biggest shiniest trinket that's come down the bike in a long time.
Um, but we are decoupling. I, I, I see that as well. I think we're also seeing an era where, look, public cloud is well entrenched.
It's not going away. It's not even shrinking. It continues to grow.
But our, I don't want to say needs our thirst, our addiction, even, let's call it an addiction to more data center, to more storage, to more power, to more mips, to more GPUs, is is, is almost outstripping our, I, you know, I, I read it, we did a report on Textron gang yesterday. 7% vacancy rate in data centers. I can imagine Throughout the us I can imagine Of the data centers currently under construction, and there's a lot of them.
75% of the space in those data centers are already pre-salt. That's amazing. Right.
Energy for the data centers. Yep. Cooling for the data centers.
Yes. And they're building data centers. Yeah.
You know, in Phoenix, Arizona where they don't have water to cool this stuff with. Right. But the, the data centers are the size of Manhattan.
Yes. I mean, it, it's, this whole thing is just, wow. Um, one of the reasons, of course, so that they're building all these data centers in the US is this move towards as, as it's becoming known Sovereign ai, sovereign cloud.
Yeah. Sovereign tech. Yeah.
You know, where we wanna, you know, first they start, we wanna shorten supply lines, but it's not really about shortening supply lines, it's about keeping your data here under your control, not Yes. Somewhere else. Yeah.
Let's talk a little, how's that affected Min io hun? A hundred hundred percent. Uh, uh, you know, Minaya being software defined can run and be deployed anywhere, right?
So that gives a lot of autonomy to our users and customers to deploy it and have the complete control in terms of their environment. Who gets to access the data? What kind of workloads get run, what kind of AI models get run on MIN io, right?
As compared to, say, for example, in Azure or in AWS, only very specific models can get run. And even if someone wants to use some open source model that is still within the AWS, uh, or Azure footprint and so on, we see this conversation coming up a lot more, as I was alluding to earlier, right? It's AI that is driving what kind of tech stack you need to have rather than, you know, cloud providers kind of dominating that conversation, which was not the case earlier.
So that is a major shift that has happened. And of course, sovereign AI is a big driver for making that shift happen. Now, when we talk about sovereign ai, of course there are two players.
One is, you know, the geopolitics of everything that is involved, whether it is Europe or, uh, UAE region or you know, APAC region and so on. I think for every country, and I have to quote Jensen here, he was very interesting. And, and CESI think he quoted that, uh, AI is going to become like telco or banking sector for every particular company.
You will need to have complete control of that. You will need to have your own AI environment at the end of the day, or AI infrastructure that, that, that is what it would mean for all the countries, unlike in past, you know, it took time in terms of technology to get, uh, uh, you know, from us to rest of the world. But I think with ai, it's just a level setting ground for all the, for all the countries together where everyone is innovating at the same pace.
And of course, open source models have made it much more easier to adopt and train on your own data sets. So I think there is multiple things that are happening in parallel, and AI is going to become so critical in terms of how everyday things will happen, you know, for machines to understand human language. It is phenomenal.
It is not a short term trend. This is, this is something real. And that's why I think the entire industry is so excited about this software's ability to write its own software.
I think with autonomous agents coming in next two years, it's, it's going to be quite interesting times that we will live in. And I think if you just foresee into the future, next two to three years, it becomes all the more important in terms of having the control of end-to-end tech stack. You cannot necessarily rely on one provider versus another.
And that is something that we see in us also, even though us is the leader when it comes to ai, right Now, even within us, if you see open AI target initiative, it's a collaboration to build their own data centers. Of course, Azure is there, but, uh, it is complete autonomy. And now with OpenAI selling to UAE, it's, it's, it's a different dynamics.
UAE, uh, UAE and OpenAI get to determine where their stack is going to deploy, not the other way around. That was happening earlier, so. Right.
Very interesting. And, and that's, that's what, you know, part of this sovereignty movement is, is that, you know, if you, if you take off the US filters and think about, let's say the UAE or Saudi Arabia, or, you know, any of these companies that are countries that are now striving to become AI factories. Yes.
Right? And, and the amount of money that they're putting into it is because they do want to be able to control it. I think the world is a, you know, the whole globalism and trading thing has broken down, especially in this area where, no, we want it here.
We want our stuff here. We're not gonna be at the mercy of any foreign Yes. Kind of thing.
And you don't wanna be, it'll be so critical, right? Uh, you don't know the kind of AI will be used in every single field. There is no doubt about it from government storing their, uh, citizens' data to every single thing that it will touch.
So it is, becomes extremely important in terms of having that kind of independence. I feel like, I mean, it is going to be just table stakes at the end of the day. And that is where I think every, not only the countries, but enterprises, the large enterprises, how they are thinking about the AI strategy as well, need to really think in terms of what goes into that AI stack.
What is the reference AI stack design that they want to go standardize across so they can be free from, uh, all the liabilities that will come eventually once the AI becomes a little bit more mature from enterprise standpoint. I get it. What's interesting, they, they also, in, in some weird way, this almost works against the, the piper scalers, the public clouts, right?
Even, you know, Microsoft and, and Google, and well, of course it's Microsoft, Google, and AWS. But I think a lot of companies that are looking for that sovereignty, though, they all have sovereignty offerings, right? They're all doing that now.
A lot of them are saying, it's not just sovereignty of, I want it in my own country. It's sovereignty over control of my data, control over my infrastructure. I don't wanna farm it out to a SA SaaS provider.
I don't wanna farm it out to the hyperscaler. Yeah. I want to almost build my own data center or rent my own space Absolutely.
And run it. That's sovereignty. It's not just national sovereignty.
A hundred percent, a hundred percent. It, it's being completely autonomous, having complete control on the stack on the data that you are, and complete control on the models that get to run in terms from training, uh, uh, to inferencing. Absolutely.
Karima, we're, we're running low on time. Look, time is being crunched though as we look towards next year. I don't know if we could look beyond next year to tell you, but I think so either as we, yeah.
If we look towards next year, the end of next year, where does this sovereignty movement take us? I think sovereign move movement is good. There will be two things that will happen, and I don't know if it is going to happen in a year's timeframe or not, but I think, uh, first of all, you know, in terms of the neo clouds that are coming up, I think we will see more of those just because I think the dynamics in terms of hyperscalers coming up with their own GPUs and other things, I, I think in terms of the demand and accessibility of the GPUs are going to become much more probable with more and more new clouds coming in.
So enterprises who want to lean on to run compute, they will be able to leverage them more effectively. I think that is something that, that we see happening. And second thing I think that, uh, we will see happening is I think maturity in terms of, uh, the specific task for enterprises right now, what's going on, uh, within, um, ai, if you see, it's all about unstructured data documents, PDFs and whatnot.
And of course, the other part of software writing it's software. But I think if you see bulk of the enterprise data, it is still structured data. And, uh, I do believe that sometime next year, and Databricks an announced it early preview, I think yesterday with their announcement of, uh, the big funding round.
But in terms of AI agents to be able to work directly on the structured enterprise data, I think that will be something to look forward to. So that, I do feel there are two different threats, but, uh, those are the short term, at least visibility that I can, uh, provide. I love it.
Rima, we're about outta time for people wanting to get more information. Min io what's their best course? io, and, uh, you can, uh, read more about the product, uh, via open source.
You can download our, uh, product as well from GitHub. So it's pretty simple, easy to use, and we have public documentation. So go ahead and try and run all the modeling on.
Fantastic. Garima, thank you for coming here on Text Trunk tv. You've been very gracious.
We appreciate it. Come back and keep us posted on what's going on at min io. Likewise, Alan, it was a pleasure to be here.
And again, thank you for having me. Alright, Garima Kaur, co-founder, CEO min io, min io here on Textron tv. We're gonna take a break.
We'll be right back. ai Leadership Insights series. I'm your host, Mike Bazaar.
Today we're with Greg Assu, he's the CEO for Overlo Labs, and we're talking about AI data centers, and whether or not we have enough capacity or that capacity for that matter is in the right place. Greg, welcome to the show. Great to be here.
Mike, thanks so much for inviting us. What's your assessment and what's going on here? I think on, maybe in the short term, we're a little bit ahead of our skis, and maybe we have more capacity than we need, but then long term people are saying, we're gonna need more data centers than you can fill the sky with.
So from your perspective, what's, what's in the middle here, or what seems to be driving this conversation? Uh, we're in an interesting place, uh, depending on the week or the month rather, our own, you know, coming from our own numbers, uh, from demand supply standpoint, we seem to be oscillating, uh, in terms of demand and supply. Um, for some reason this month, like our utilization rates for let's say H one hundreds, which are a pretty good, um, GPUs is right now around 98% last month.
This particular chip had, I don't know, 60% and a month before it was, you know, fairly high as well. Um, we seem to be the problem so far, at least on the surface, seems to be misalignment more than that type of compute, more than, um, like demand for everything, right? So 20, 23, 24 timeframe.
I mean, if you had a GPU, it was just coin, you know what I mean? Like, so you had like, especially the, the, the higher density ones like H two hundreds or H one hundreds back then, uh, you could not get anything on demand. Uh, people were paying, you know, I mean, anything that can, that the cloud provider would ask them because there was enormous shortage of supply, um, and, and really wrapped up their H 100 production from making, um, um, know half a million units to about 2 million units.
And that seemed to like, at least ease the demand, uh, ease the supply constraints a little bit. But now we are seeing every rebuttal of that for H one hundreds again. Um, and I think my thesis is because it takes about 18 months to two years to reconfigure a fab to produce a new chip.
And, uh, you know, when you reconfigure the fab, you want to take advantage of it. But in order for you to take advantage of that, all the chip, the market moves away to a newer chip, and then NVIDIA is moving it. I mean, the design is such moving significantly faster than production.
So every time Nvidia announces a new chip, the demand for the newer chip, you know, is much higher than the older chip, but the production for the older chip is a lot more than their demand exists or something. So there seems to be a misalignment, at least from our observation in terms of, you know, Nvidia s rapid, uh, growth. And a lot of the growth, you know, uh, ensure it has to do with the current demand, but also they have to keep producing new models to keep the market happy.
Um, and every time they introduce a new model, the demand for the newer model goes up, and the supply is not quite there yet, and the demand for the older models come down. So that's why you see, uh, cloud companies that own a lot of hardware, uh, and not seeing the same amount of demand for the older hardware, right? And we looked at price fluctuations, particularly for, uh, something like H 100, and we try to predict what the future price is going to be.
Uh, and we look at historical prices, right? Uh, what we've noticed is over a five year term for A GPU, the average drop, we're talking about training grade GPUs, right? H 100, say 100 c, 100, whatnot.
Uh, the, the average, uh, annual drop for price is about 20%. The biggest drop you see is in the, the first to second year drop, right? So if you are someone like a cloud provider that gets access to the latest and the greatest chips you make money on year one, year two, year three, you lose.
But if you're someone that gets, you know, compute for that model in year two, year three, um, uh, the, you don't quite get the cost benefit that you're, you're, you're usually getting when you, when you have year one, and everybody wants year one, right? Like B three hundreds are out, or, or, or at least they will be out, whereas soon by end of the year, um, and everybody wants B three hundreds and no one wants H two hundreds anymore, you know, the H two hundreds a very, very good platform, right? So, uh, I think that's how you're seeing fluctuations in the short term.
Why? Because our, there are several key challenges for AI to, to be flexible in terms of, in, in terms of what kind of chip, uh, they can use for both, for training as well as infants. Training in particular is very homogenous in the sense like, if you train on, let's say H two hundreds or H four hundreds, you have to stick with the same chip.
You cannot, you know, be heterogeneous in terms of mixing and matching what chips that you need. So if your data center has lots of a one hundreds and some H one hundreds, if you train on H 100, you cannot leverage all the un underutilized a one hundreds. So there's a mismatch and everybody wants to train on the latest and the greatest because the price performance is, is drastically different when you have the leadership versus even one generation later, right?
And at scale, that makes a huge difference, like massive difference. And particularly we have another concern, which is energy, right? The, the energy prices in this a whole like world that I think people don't understand that very well.
Um, and, uh, so ultimately the kilowatt hour to performance to the flops is what I call the real metric, right? Latest. And the greatest chips, like B three hundreds have significantly better, you know, uh, ratio how many flops they can extract out of, uh, one kilowatt hour compared to just a previous generation.
So, uh, and when you're a hyperscaler, that means anything you have, if you have data centers over 50 megawatt capacity, your energy costs are enormous, right? Because, um, it's very, very hard, if not impossible in the west to get large amounts of concentrated power in a single place, um, because of our energy problems, right? Like we, I mean, it's easier to get more distributed energy, smaller quantities in lots of different places, but it's very hard to get large quantity in a single place.
In fact, um, and if you look at the energy demands for, for training clusters, it's doubling every two years, right? So, uh, like for the, for producing the state of the art model from, you compare from you, your GP three to GP P four to GP five, we don't have the data on GP P five, at least from like graph two, graph three. Um, if you look at historical, uh, uh, I dunno if you can hear my dog, but he's going crazy because he a squirrel outside, okay?
Uh, the, the, um, the amount of, uh, uh, the energy and stock capacity required is doubling. So opening a data center, for example, in, in Albany, Texas is currently scheduled to come online with about 300 megawatt capacity. The Rock data center, the XAA data center in Memphis, uh, has about one 50, uh, megawatt capacity.
And if you look at the GRS data center, they're only drawing about seven megawatts from the grid. The rest of the energy they're getting from burning LNG, we're talking about Tesla or like Elon Musk's companies to actually burning, uh, LNG because there's no reliable way to get energy. So if that's doubling every two years now by, you know, 20, 20, 27, 28 timeframe, we are looking at 600 megawatts.
And by 2030, we'll need a minimum gigawatt, uh, capacity to translate year model only thing they can produce a gigawatt capacity. Um, uh, or the best way to work capacity is nuclear, right? Um, and in us, we, the last nuclear reactor we built took about 14 years.
All the nuclear reactors that we have currently are utilized pretty much full-time. So we cannot produce new energy or new source of energy. And that means there's higher demand for energy.
That means the prices are gonna go up. That means you want to use the latest and the greatest chips to reduce the tho those, uh, or improve your price performance. There's a lot of factors that get into hyperscale economics.
Uh, for the first time you're seeing a reversal in, uh, e econom economies at scale working, right? Like it's almost cheaper. And residential is significantly cheaper than commercial right now, uh, even though the commercial demand is kind of eating into residential prices as well, but, uh, you know, in areas like Virginia and, and whatnot.
But, but at least even now, if you can like tap into a residential grade somehow, um, uh, that's the best way to to, to reduce the cost. And long story short, there are a lot of factors that are going into the demand supply and the economics we're seeing. Uh, and most of it comes down to, uh, you know, energy per flop.
Are we, uh, maybe too obsessed with the latest and greatest? And are there AI models that could be trained or run perfectly well on older processors and systems? And maybe we should just be smarter about which ones we use for what?
Well, what's perfectly well is the question here, right? So for example, um, a 100 has about 80 meg, 80 gigawatts, uh, of virtual memory, right? So the giga, the virtual memory is what determines how big of a model you can do, can, you can run, um, if you were to run, let's say, a deep seek, which is about six 75 billion parameter model, you know, you will need, um, you know, the 80 gigawatt, 80 GB chips, about at least 80 of them cluster together, um, and serve an inference for a deep seek, right?
Uh, now it can run okay on 80, uh, you know, HA 100, but the inference performance is gonna be significantly slower compared to, um, something like, um, the H one hundreds or H two hundreds and above. So what that means is your response time is gonna be slower. So depending on the kind of application you're looking for, yes, it's possible to run on, on all the chips, but your response is gonna be, um, like not optimal for your use case.
So that comes down to it. Or can we do a smaller model? Can we do necessary experts?
Looks like that's where the world is trying to go to, is widely believed. Charge G PT five was supposed to be that, but we all know the, the, the, the quality of charge G PT five is much, in fact, it, it hasn't improved. It, it, it, it, it detrimental.
I mean, they actually went down. So, um, the, the, the state of like, I mean, we know that bigger models, uh, that use a lot of energy are usually, I mean, much, much better than the old models. We know that, uh, but it's not sure about the economics of charge GB five gb, I mean, GB five.
Um, and, and because it's closed, so not too many, there's a lot of speculation as to what kind of model or what kind of, uh, you know, training or what sizes this model is. But, uh, it's widely believed that it is an agent tech model that, uh, you know, that, uh, that, that, you know, leverages a lot of small models. Are we also maybe miscalculating how efficient the LMS might get over time?
And we're kind of making projections for build outs based on what we think will be the size of an LLM, but there could be ways to more efficiently build, train, and run them. And might we wind up with another situation where, you know, we overprovision fiber and we wound up with all this dark fiber, Right? So LLMs are getting efficient.
I mean, at least like comparing from GPT three to GPT four alone, um, you know, of course the algorithms are getting much better, but also like the, the chips, uh, contributing to the efficiencies is huge. 5 is widely believed to, uh, I think each pro each, um, um, each prompt was on average consuming about, uh, 10 watts per pro, 10 watt hours per prompt, um, which is quite a bit. Um, and now, uh, and now we're, uh, wait 10 what hours?
Well, three by, yeah. Now, the thing is like 10 times cheaper than that in terms of energy, right? With HH one hundreds.
Um, um, so we are almost like, so if, even if you have like a whole order of magnitude different from every GPU model, another Berkeley, you know, I mean the, the Lawrence lab at Berkeley, uh, in collaboration with the Department of Energy did a very, very deep study about energy, uh, you know, consumption for ai, including the efficiency gains. Uh, and if they look at several efficiency gain models, it's very deep, deep, deep, uh, deep, uh, analysis, including that they assume or they, they're concluded, rather, um, about 12% of US energy will be consumed by AI data centers. Um, and this is a very conservative estimate.
The reality, if you look at Gartner's world or some of the other, uh, you know, analysts, um, the, the reality is most likely about 30% of us, uh, energy production will be used for ai, right? Including efficiency gains. Um, so, which is not totally on the, on the, on the, you know, outfield, considering that most people still don't have access to basic ai.
I mean, we're in a chat GPI era. Chad GPI is relatively expensive, very expensive for, for common usage, right? But most people don't even have access to that.
Uh, and we are like in barely scratch the surface about how much inference demand is gonna come through, right? I mean, all the way from medical, I mean, medical medicine hasn't even, um, you know, uh, hasn't really like embraced AI as much as they could, um, including every piece of transcription, automatic billing, uh, second eyes on, on diagnosis, and a whole lot of incredible, incredible applications in, in medicine alone that hasn't been unlocked because of regulatory concerns. So there's a lot of, like, a lot of areas that are still early in evaluation that could mean quite a lot.
I mean, looking at medical expense alone is about 20% of American economy, right? Like something crazy numbers, the Medicaid. So we have massive like blocks of, uh, econom mean sub economies in America that are very early stage evaluating ai and all that is gonna get unlocked, uh, in the next few years.
Uh, even models are advancing at such speed that the market hasn't quite caught up in, in terms of demand, right? Like, by the time you, you know, judge three is a great model, right? Like, uh, you know, like the moderate advancement we saw at Chad GB three took years of AI into, into perspective.
And if you look at medicine, it's not even a, you know, able to leverage Chad GB three, like for basic diagnosis. So a lot of areas, that product hasn't quite caught up because experience hasn't, people haven't figured out what's the best way to deliver this experience to some of these, um, these traditional fields, right? Um, um, and we, we are slowly seeing a lot of like normies, so I call it norm, is like my, for example, my AV guy or my electrician now using Chi GBT to answer some of the questions, right?
I mean, we are just starting, starting to see that. But imagine, um, you know, because I introduced him to Chi GPT and he had no idea that he could actually take a photo of, uh, any issue he has and just, you know, have Chad GPD recommend solutions for him, because that makes him a much better electrician, right? Simple things like that.
People haven't figured out, uh, basic like usage of Chad GPT. So we are not, we're not there yet. I think the, they we're severely underestimating the demand.
Mm-hmm. Uh, I guess depending who you talk to, if you talk to Eric Schmidt, he'll say like, 99% of the world's GDP will be spent on ai, which is a, a little stretch. Uh, it's non-zero, but, so that's a little stretch, right?
But we're talking even government reports, like DOA reports, uh, that are very conservative talking about it. And I testified Congress recently, um, uh, before Congress about two months ago on this particular subject. There, there is hope though.
There is hope, uh, it's not all loomy and like, oh, um, or all going in a negative direction. Um, the hope that is, is if we can figure out how to leverage heterogeneous GPUs, right? Like my gaming machine at home, which has a 50 90 or, and a 40 90 could very well take part in a training run, but it cannot right now, because, you know, training is asynchronous.
That means, I mean, synchronous and a a and we have the, it is only as fast as the slowest node in the, in the, in the training batch, basically. So if you have H one hundreds or a one hundreds, even the H one hundreds would complete the task fairly quickly. It still had to wait for the A one hundreds to complete before it can synchronize all layers.
So it doesn't matter if you have, you know, all H one hundreds and a few A one hundreds, the batch will still be determined by the size, by the speed of the A 100. So, uh, there are researchers now, um, that, you know, have figured out how to leverage, uh, heterogeneous GPUs. And I, I was recently at ICML, which is International Conference for Machine Learning, which is the most, it's very academic, most prestigious, uh, machine learning conference in the world.
Um, and we pay attention to what kind of subjects are being discussed. And a big part of this year's ICMO was distributed training, um, and we had like six papers on distributed training, uh, all addressing different, different parts of the problem. Uh, but asynchronous training is seem to be extremely exciting, uh, asynchronous in the sense, like even it can, it can tolerate false better.
Uh, like right now, if you have a training run that's run into multiple batches, if one batch, uh, if there's a fault in a single GPU in a single node, in a single batch, you had to restart the whole thing. Whereas asynchronous means you don't have to, uh, and you can do hydrogenous GPUs. That means like you don't have to wait for the slowest machine, uh, to, uh, to complete a, to complete a batch.
And so you can do asynchronously. We have, um, um, you know, uh, a distributor for example. There are, there are, you know, aspects where, uh, so, so the reason why you want a lot of GPUs in a single place is because, um, there's something called gradient synchronization in, in training where you had to, you had to synchronize all the, all the gradients, uh, periodic periodically in order to train.
Uh, that means these nodes are very chatty. You need, you know, end by end, like the, the speed is determined by the complexity of the nodes. So more nodes there are gets load the network, right?
Because they need to communicate pretty, pretty often. Um, uh, and there are algorithms now that, that, that reduce the amount of synchronization, make these nodes less chatty, or the training less chatty by using several techniques. And there are a lot of companies that are working on different techniques on how to reduce the amount of communication.
So they're called loc calm, low com algorithms. Uh, Google DeepMind is pretty famous for their paper on Dial Co. Um, and news research, uh, distro.
These are very popular algorithms that are taking a lot more attention now. Uh, so yeah, there's a lot of hope and like reducing, um, uh, communications, improving asynchrony, improving heterogeneity, improving fall tolerance. Um, and on top of that, it can add incentives for someone to participate.
I think that's a missing piece where all these technologies come together and you can actually have a, a viable open alternative training, uh, uh, mechanism compared to what we have, which is a very closed and very, um, you know, controlled, uh, environment. Hmm. So we only have a couple of minutes left, but if you had to summarize it, what's your best advice to folks in terms of how they should approach this whole space?
Is there something that they should be thinking about more than just say, having patience. Buy GPUs and buy solar? All right, there you go.
That's the advice, because I'm, I cannot emphasize enough on the importance of energy crisis. Uh, right now we are seeing, but GI alone, um, the utility companies in Virginia are paying 20% more for the same amount of energy for last. They, they, they they got last year, it's growing significantly faster, faster than the CPI, uh, energy prices.
Um, and there's no hope. So you may want to think about how the future energy market is gonna look like, and having solar at home alone is, solves a lot of problems. But if you add a GPU on top of it, the very high chance that that GPU could partake in a training run tomorrow and in exchange give you some of the inference revenue.
So there's quite a lot of, um, and I'm, I'm very hopeful and I'm very excited about this future. Uh, and also it's better, right? Like right now, single data centers are targets.
Uh, you know, these are like just sitting there. We have about 500 hyperscale data centers in America. Everybody knows where these data centers are primarily, and like the, the data central allies, the, you know, the Virginias of the world and in, in, uh, in, uh, in New Jersey of the world.
Um, and that's not good from a security posture, right? So we want a more distributed, more decentralized, uh, data center, uh, market. Um, and the way to achieve that is to have home ownership of GPUs and, and energy.
That's really the only, only way. All right, folks, you heard it here. I think at least even in the age of ai, uh, failing the plan is planning to fail.
So we should think about long-term and what we're after here, because if we don't, we won't have any AI or not enough of it to go around. That's for sure. Um, Greg, thanks for being on the show.
Thanks so much, Mike. All right. Thank you all for watching the latest episode of the Techstrong AI Leadership Inside series.
You can find this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey everyone, it's Alan Shimmel for Tech Strunk tv. We're back here continuing our coverage of Black Hat on the show floor. It's early in the morning, keynotes are going on, so it's not as crazy here, and it's a little better quiet.
And we can do some talking. I am at the harness booth, of course, it's traceable by harness as well. Uh, but we're here to talk harness with Sudir Patam.
Seti Sudir. First of all, welcome to Text on tv. It's great to have you on.
Hey, Allen. Uh, thank you so much for having me. Uh, it's great to be talking to you today, Alrightyy.
So Sudir, as I mentioned, it's quiet right now, so we can talk without all of the stuff going on. Why don't we start with a little bit about you Sudir? Sure.
Uh, I work as a senior Director of product management, uh, at Harness, uh, with a focus on, uh, runtime protection, uh, products. Okay. And also on the platform capabilities.
Very good. And, um, before Harness, kinda what's your background? Uh, my background has been mostly in the application security space.
Uh, worked at several, uh, large enterprise organizations like F five and Akamai. Okay. Uh, before joining Harness.
Uh, so, so that's So but on the more on the vendor than the practitioner kind of thing? Exactly, Yeah. I been, I, I started as an engineer in my career.
Uh, and then, uh, post MBAI actually moved into product management. Very cool. com, right?
And so we obviously cover Harness. I have covered Harness from the day it was launched, but we're here at Black Hat, a security show. And of course, look, DevOps is DevSecOps, right?
You can't do security or you can't do DevOps without security. Yep. However, let's focus in on security.
I mentioned traceable, traceable ai of course, was a kind of a sister company founded by the same team. And, and investors has harnessed. They've recently merged.
I guess that's gotta be six or eight or more months ago now, nine, 10 months ago. But there's more to security at harness than just traceable. So assuming our audience knows Harness, they may not really know the harness security side of things.
If you wouldn't mind, let's start there. Give us sort of an overview of harnesses security capabilities. Yeah, so, so Wego Harness as an AI native DevOps platform, but now we are an AI native DevSecOps platform.
Yep. So we help developers ship secure code faster and in a reliable way. Right?
That means we help embed security in every phase of the software development life cycles, all the way from design to runtime, right? From the time when developers are coding to when the applications are running in production. So we have tools at every phase of the SDAC that help secure the applications and APIs, uh, as they go from code to production.
Perfect. And let's get specific about the, the offerings, right? com, we're Security Boulevard.
com. These are your people. Let's peel that onion back a few layers.
What specific security ai, security DevSecOps, whatever you wanna call it, what are the specific things that Harness is offering? So, uh, with the merger of Traceable, uh, we have like five modules now within Harness, within the security pillar. Uh, I'll go through one by one.
Okay. The, maybe from left to right, all the way from Code to Runtime. So the first module is called Security Testing Orchestration.
Okay. Uh, The goal of this product, uh, is to help developers prioritize vulnerabilities and to focus on the right vulnerabilities that they need to fix. So the challenge that we see right now is there's so many tools out there, uh, for different types of scanning, like SAS or SCA or secret scanning, so Container Security das.
So there's so many tools and each tool has its own format. So what we do with security testing orchestration is we bring, uh, the outputs of all these tools in the CI I CD pipeline. We reduplicate the findings from the tools and create that list of vulnerabilities based on a specific criteria prioritized in an order.
So developers can fix those vulnerabilities in an easy way by leveraging ai. So, so we have AI embedded in our platform. So we not only tell you what are the important vulnerabilities you need to fix, but with the help of ai, we also show what you need to do in the code specifically and help developers create pull requests automatically with ai.
And when you say AI is doing this thing, is it more of a kind of a chat bots with suggestions or is it more of an agentic AI that's autonomously doing these things? Or maybe both? So we have a combination of both.
Uh, we have different agents, uh, in the platform. There's a DevOps agent, there's a security apps occasion. So there are agent flows where you can give an outcome, uh, to the ai and AI will do all the steps for you.
Or you can also interact with the AI in a chat bot style conversation, uh, to, to kind of question and answer format. Very good. Alright.
io. Yes. io.
Okay. Let's talk black hat day two here, Thursday of the, of the expo floor. Of course, the conference and training's been going on now for four or five days.
What, is this your first black hat? Have you been here before, or No? I Think, uh, if I remember, I think this my fifth Black hat.
Fifth, okay. Yeah. Fifth.
Yeah. What do you think about this year's Black hat? It's, uh, great, uh, to be here.
Uh, first of all, you, you get to learn so much, uh, from practitioners. Mm-hmm. Uh, also from different vendors.
Yes. And there's a separate area for AI innovation. Yeah, there is.
I checked out yesterday, which is really cool. Mm-hmm. Uh, and, uh, it's great to see all the innovation happening in the security space, uh, with respect to ai.
It, it, there is certainly a lot of AI here, especially when you go both booth to booth. Um, what are you hearing from real life practitioners who come by here and talk? Are they so bought into ai?
Are they just all AI too? Or is it, I I often wonder, are we as practitioners, not as practitioners, as vendors pushing AI on practitioners? Are they as eager to take that AI and use it as vendors are to sell it?
I would say if it was maybe one year ago, uh, practitioners were cautious about ai, but now they're realizing that it's, it's a real thing with, uh, for example, with AI now with the concept of vibe coding. Yes. Now it's so easy to write code and everyone started realizing that it's a real thing.
And you see in the news that like 30 or 40% of the code will be written by ai. So there's stats like that, which is a real thing. And, and not only vendors, but practitioners have started adopting ai.
So it's a combination of human and ai. So how AI can help you automate a lot of your day-to-day tasks and free you up with a lot of, uh, manual tedious work so that you can focus on the more important things. And AI can do all the, uh, the grant work or the, the cu cumbersome work for you.
Sure. So as I, you know, bring this full circle blackouts of security show, we think of Harness DevOps, DevSecOps, of course, there's much more to security than even just AppSec or, or DevSecOps. What percentage of the attendees that you speak to you think are interested in DevSecOps or even AppSec versus some of the other things we're seeing?
Cloud security, endpoint security, threat modeling, you know, all, all the different flavors of cyber today? No. We see a good traction at our booth.
Uh, as I said, with more and more code being produced now, AppSec is gonna become even more important. Mm-hmm. Uh, it's equally important, like the other pillars of security, like cloud security or endpoint security, because it all starts with applications.
And applications are growing day by day. Uh, so, so yeah, I mean, like, it's a, it's a 50 50 split, I would say. Uh, and AppSec is gonna get bigger and bigger.
Alright. Last question for you. Was there any news or any kind of thing that harness announced around the show that we can tell our audience back home about Very soon?
We are gonna bring out new announcements, uh, maybe to give you just a Sneak. Don't say anything that's gonna get us in trouble. Okay.
But give us a little Sneak peek. Yeah. Sneak peek into, uh, it's gonna be about ai.
Okay. Uh, so that's a sneak peek. Fair enough.
Yeah. So you gonna say a lot of cool, uh, new innovation and products from Harness. Fantastic.
Hey, I want to thank you for coming in early before the floor open to do this with us, continue to success to you and Jody and the whole harness team. Of course, we'll always be following it along here at Techstrong, but we're gonna let you get back to it. 'cause I think they're about to open the floor.
Thank you so much, Alan. Uh, great talking to you. And you have a good time.
Have the conference. Thank you. Thank you.
All right. We're here at Black Hat. We'll be continuing our, I'm just waiting for some trucks to go by here.
It sounds like we'll be continuing our coverage of Black Hat throughout the day and you'll be seeing it on Text Trunk tv. But until then, this is Alan Shimel. We're out.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insights series. I'm your host, Mike Huard. Today we're with Jay Littky, who's senior Vice President for Cloud and finops at flexera.
And we're talking about, well, the need for a finops playbook for ai. Jay, welcome to the show. Thank you very much, Mike.
Everybody, at least most folks now are starting to become aware of the cost of ai. It's rather significant. And most folks that I talk to do not have a plan.
And yet we do have this notion of finops that we've been using to kind of try to optimize cloud spending. So can we apply finops to ai? I think the, uh, to cut to the chase, the short answer is yes, and it should be.
And having been around the block before this feels like cloud did. Right? When the hyperscalers came along, it was, uh, at first cloud was there and then it was, well, we're not using it.
We're not allowed to use it to, all of a sudden seems like everybody's using it. And nobody knew how much of it they were using. And, uh, that's how, as you know, finops came to be born, was to try and get a handle on managing and tracking those cloud spending.
So this pattern's repeating itself with ai. So, back to my succinct answer. I think finops is timely and well positioned to, uh, help here with ai.
Is this kind of one of those proverbial back to the future moments? Or is there something different about AI workloads that we should consider as we build out this new playbook? I think there's many patterns that are similar.
If I take it back to basics, right? Finops was invented largely to help control manage, right? Uh, cloud and to put, you know, understand the business value of cloud and to justify it.
Finops, as you know, has expanded since to include other scopes. So it now in its purview does this for SaaS services. It does this for data center, it does this for, you know, it's looking at software licenses.
And so AI is just another type of technology with a lot of unique things about it. We can talk about those unique things, um, that, uh, that finops principles can be applied to. So I'd say there's a little bit of a, you know, back to the future, seen this movie before, but also there's enough differences with what ai, uh, and considerations to take in where this isn't just a, uh, you know, apples to apples, rinse, repeat.
So how do we set that up? 'cause I think when people hear the word playbook, they're like, okay, well there's some sort of document that sits on a shelf, but is this more of a programmatic approach where we have actual policies and governance capabilities that help us execute what's in the playbook Emerging? So the first thing I do, when somebody asks me where should they start, I steer them to the finops Foundation.
Now, full disclaimer, I'm on the governing board of the finops Foundation. So I do have some bias, but there's lots of content from some really smart practitioners that's being published now around how to start viewing this area, um, how it's similar and different, right? Than traditional finops approaches and ways to start skinning the skinning the cat here and ways to start, uh, start tackling this.
So, you know, that's the place I steer people. The good news is people don't have to start with a clean sheet of paper, and there's a lot of momentum that people aren't aware of it already. Again, coming outta the finops Foundation, There's a couple issues when I talk to folks about all this, but one that comes up over and over again is we seem to all wanna rush to get the latest and greatest GPU, but can we be smarter about what models run where, and maybe especially in inference or their low cost processors to think about here.
I mean, it feels like to me the playbook needs to start with some of the basic fundamentals of what can run where. Yeah, let me be the up level then of where I've seen, um, people doing this. Well, or when you think about taking it back to basics, because what, what, what's very clear, like with cloud, when cloud came on, many people just jumped in and then realized they sucked at doing it right?
Because it wasn't all thought out, it wasn't governed. They never thought about what it was gonna cost. So I sort of, um, take it up a level.
If I think about AI and the challenges people have, you are right. People are realizing now it costs a lot of money, right? And a lot of people are asking the questions now around, do we understand the business value of ai?
And again, this sounds like cloud did when cloud came along and everybody said, why are we doing this? And so may maybe, if it makes sense, I'll start just talking about, you know, the, the ROI of AI initiatives. We'll start there and then we'll talk about the cost management.
AI doesn't fit in the traditional neatly and at least into the traditional cost benefit models. So when you think about that from a very basics, the ROI of of AI is often delayed, there's a long tail to it. There's soft benefits, like improved decision making, operational efficiencies, not just the quick hits of maybe immediate revenue or cost savings.
So when I think about ai, first of all, and people start thinking about the ROI of it, and then we'll kind of back into the cost savings. As I say, the benefits are sometimes delayed. Um, companies often don't have a baseline or a control group, so they don't really have a pre AI benchmark for some of the things they're trying to solve for.
Uh, uh, I'll give you an example. Some people are saying, let's apply AI to automate a process, right? That's all the rage people are thinking of.
What can we automate? Automating a process on its own is not a success metric. That alone indicates the business value.
So, you know, starting from scratch, people need to think about again, what kind of, what are the reasons why I am adopting ai? How am I gonna measure that success? And let's align some stakeholders before we get too far down the path, because leaders often have different success metrics than, say, a data scientist, right?
A, a leader may be looking for the impacts to be on revenue or cost savings, data scientists, other people might be thinking about efficiencies or throughput and other kind of things, right? Um, very differently. So I'd say aligning people on what to measure is the first step here.
So that when you're starting to measure costs and benefits, you've got something to measure against, and you've agreed what success looks like. So, along with the answer, and I can dig into a bunch of these areas for you more, but I like to start a lot of people talking about the, why are you doing ai and what does success look like, and how are you gonna measure this? Because measuring it like cloud shouldn't just be about how much you're spending.
I also think the space is evolving. And if I look at a lot of the data centers that run AI today, they kind of feel like very large mainframes. And, but every time we have that kind of monolithic approach, we eventually discover or rediscover distributed computing.
So will these workloads over time get more distributed so that we can be more efficient about using different classes of processors to run this? Yes. I think just sort of take up level here, there's many people doing AI that have a data center, and you're right, there's use cases about why they want to do some AI things in their data center, and they might wanna do other AI things in the cloud.
And so they're distributed. There's many organizations out there that are born in the cloud that have never had and never will have a data center. And so their entire usage of AI is entirely in the cloud.
And I think the reality we've learned from the cloud journey is, you know, we still have lots of hybrid environments, we still have lots of data centers, as you said, we still have mainframes, is there's no one size fits all about how AI is gonna be consumed here. And that's one of the challenges of, of, there's no playbook that fits everybody's situation, but what finops brings is a bunch of general principles that you can apply in any situation you're in. Mm-hmm.
Finops, of course, assumed that the finance department was talking to the IT department and they created some level of, uh, collaboration. But do the finance people even understand AI yet and what the implications are? Or is it a little too early for them to get involved?
I don't think it's too early for them to get involved, but no, they don't understand it. Mm-hmm. But many stakeholders don't understand it yet.
Right now, AI adoption for many people is reactive. Fear of missing out, right? This disruptive thing is here, let's go jump in.
And as I mentioned earlier, they haven't articulated what the business value targets are, what they're trying to accomplish, that they're gonna measure against. So what's happening in real time where I see finance people getting involved is, whoa, it seems like we're spending a lot on these AI pilots or projects. Finance doesn't even know how many of them are happening out there.
So the first step is they don't have full visibility of all the things happening in ai. Um, and so I think they should be involved, but I think those business value and business outcome discussions should be asked earlier in the adoption cycle rather than reacting. But this is the same movie we saw.
Play it with cloud. It's no different than the public cloud adoption. So what's your best advice to folks as you look at all this?
Is there some rational way to go do this upfront, or will we once again wait for the inevitable crisis before cooler heads start to prevail? I think there's lessons learned, as I say, the finops Foundation, where you see these practitioners arrows in their back, right? They've made mistakes.
They've learned how to do this the right way. There's emerging, you know, um, ways of thinking here. And again, I, I keep, I'm biased to talking about the finops Foundation, what they're recommending.
But if I think about that, you know, I talked about developing outcome-based AI strategies. Start with the why we're doing this. Define some of the business goals so that we all know, whether you're in finops, whether you're in finance, whether you're, you know, the data scientist.
What is success or how are we gonna measure this so we're not debating how much money we spent later and that we're spending too much money. I think establishing, um, an ROI framework, and this is something that you wanna have finance people aligned with, finops aligned with the people doing ai, and to agree upfront that this isn't, shouldn't just be a quantitative, right. ROI framework.
Yes, cost revenue efficiencies should be in there, but there's also agree about qualitative KPIs, right? How you're gonna do this when you, when you go into it further things that customer satisfaction, employee retention, there's other benefits to AI adoption beyond the quantitative. And you gotta, you gotta get the stakeholders aligned about how are we gonna define success?
And should success only be measured on how much we can save? And one of the things that finops goes out of its way, right, to preach and talk about, and instead, is finops isn't just about helping people reduce their cloud bill. In fact, many people doing finops well increase their cloud spending because they're proving and demonstrating and measuring, they're getting real business value.
Same thing with ai, is we all agree why we're doing it and what the business values we're trying to accomplish. And again, not just trying to automate a process, but why are you trying to automate the process? Right?
What's the outcome? If we can agree on those things, it becomes less about how much we're spending. 'cause spending more on AI might be a great thing, right?
And that's the journey that finops taught us with cloud is finops isn't just about saving money, you're missing the picture. If you view it that way, it's about justifying the business value of the technology, right? That you're consuming.
So again, rinse, repeat, apply it to ai, same kind of thing. And I spent a lot of time, and I know I've, I've said it, this, this idea of cross-functional alignment. What, what finops also evolved and has learned is it's a team sport.
When you look at a a finops team, there's not just one role of person on that team. Finance should be plugged into it. Engineering should be plugged into it, right?
Different constituents. AI is very similar here, but the number of constituents and the personas has broadened. When I think about cloud consumption, who uses AWS or Azure?
You know, you could go through who uses that and who drives cloud adoption. But you think about ai, the question's almost now, who's not trying to explore AI pretty much every function in a company. Mm-hmm.
So again, the, the importance of getting cross-functional stakeholders aligned on what success is and how are we gonna measure the success of AI becomes more important. There's more people pile into the party Right now. You hear a lot of folks talking about pilot projects that failed, and things are not quite going in terms of the ROI as expected.
So I think we all thought that 2026 was gonna be the year of AI in production. But I can't help but wonder maybe if we may need a mulligan here, and when we start over again and get it right, Well, mo most technologies come along as, you know, there's the hype cycle, right? We all get excited.
We say it's gonna solve world hunger. Everybody's doing it. Why aren't I, we all jump in and then there's lots of disappointments.
This projects don't succeed. Somebody's asking me, why are you spending so much money? What value do we get from it?
And then everybody starts going into some negativity, right? Like, it's not all it's cut out to be. We're going through the similar cycle here with, with ai.
I, I'm convicted, it's a game changer, right? I'm convicted it's gonna change the world, but like cloud and every other technology wave that we saw come along, it doesn't entirely consume the world and everybody doesn't win outta the gates. And we've seen this in successive waves of technology patterns, right?
We saw it with virtualization, we saw it with cloud, we're now seeing it with ai. The things go through this, again, peak of inflated expectations and hype. And then you go into some kind of trough where not everybody is winning and there's lots of questioning around, should we be doing this?
And then the real success, you know, there's a slower ramp even though the world's evolving very quick. So to me, this is just going through that, that kind of same pattern. And I think, you know, there are successes happening out there, and sometimes people don't even realize they're having those successes.
You know, I hit on the ROI, there's lack of clear use cases. So there's just trying to throw things at the wall and kind of see what stick, and in that there's maybe good things happening, but it's obfuscated by all the, all all the noise. ROI was an afterthought.
So after the fact, they're trying to think about the outcomes that they were trying to achieve. Um, you know, there's people running at this, you know, too quickly because they have poor data quality. I think you, you probably know that AI is lifeblood.
It runs on good ai, you know, sorry, good data, structured data. And so if your data's not structured and formatted in a good format, readily accessible, you're gonna stumble. You're not gonna get the benefits from ai.
And many people overlook that. They run into trying to apply ai, but they haven't cleaned up their data. And then I'd say, you know, another one is just, you know, the, the over rotation in minds, the over reliance on cost avoidance expectations and narratives.
Hey, we're gonna use AI 'cause we're gonna save a lot of money. And like cloud, if that's your only view, you have too narrow of a view. The benefit of public cloud isn't to save money.
I think most people now know that same with ai. But again, there's an over alliance because of the amount of money being spent and because leaders like to hear, save money, generate revenue, there's, there's a big over alliance or over focus, I say right now and using AI to save money. And there's a lot of other benefits.
So again, to me it feels like we went through this journey with cloud. There's a lot of, a lot of repetition about the technology adoption cycle here. And finops again grew and I think has done a very good job applying itself to managing cloud and other technology spending.
Same thing again, why I said I think this is perfect timing to apply finops to ai. I think it was Bill Gates folks who said that, uh, we overestimate the impact of innovation in the short term and underestimate its value long term. I think AI is probably another one of those instances.
But in the meantime, hold onto your wallets, Jay. Thanks being on the show. Thanks so much, Mike.
All right. Thank you for all watching the latest episode of the Techstrong AI Leadership series. You can find this episode and others on our website.
We invite should check those out. Until then, we'll see you next time. Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders shaping the future of digital defense.
I'm your host, Caroline Wong, tech Strong TV podcast feature, your favorite video series, industry thought leader, commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders. The AI security edge dives deep into the evolving cyber battlefields where AI driven threats challenge traditional defenses and cutting edge AI solutions offer new ways to fight back.
Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, or hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Tune in to stay ahead of emerging threats and harness AI's potential to secure tomorrow.
I am so excited to announce today's guest, my good friend Kos. Did I say that right? Ke Kos.
Yep. Kos, I'm like so embarrassed about that. Kos, my guess is Kos, we call him Rock, rock Land.
Yeah. Nobody, nobody knows kos. We're, we're gonna call him Rock, but I did wanna like tell the world like what your full name is.
And yes, he is as solid as his name suggests. Rock has a 20 plus year text cybersecurity and AI veteran who's been shaping the future of secure innovation across industries as the founder and CEO of Rock Cyber, he helps organizations to navigate the tricky intersection between ai, cybersecurity and compliance, and actually make it work for the business. He's a co-author of the CISO evolution, highly recommend creator of the Rise and Care frameworks, which we'll get into in just a moment for aligning AI strategy and governance, and a driving force behind O o's AI security projects like the top 10 for LLMs.
His career spans leading it, OT security at Marathon Petroleum, optimizing incident response at eBay, where we met and running global security, offset general dynamics, all with measurable results. Whether it is wrangling regulatory beasts, like the EU AI Act, or building security programs that do not slow innovation rock brings a mix of deep technical expertise and strategic vision. Rock.
Welcome. Thank you so much for joining me today. Thank you for having me.
You're way too kind with that intro. Thank you. I Just love talking to you and I love that we get to have this particular conversation.
So rock, really arguably the most important part of AI today when it comes to cybersecurity, is governance and strategy. And you have created a couple of frameworks for us to use RISE and Care. Yeah.
Um, I love those acronyms and we'd love to learn all about them. Yeah, thanks. So, um, God, where do I begin?
So, rising Care are frameworks that I develop for, uh, AI strategy on governance, respectively. Um, you know, I I often get phone calls, Caroline, around, Hey, rock, you know, we're using AI within the organization. We know we are shadow ai.
People are using their personal, uh, chat, PT or Gemini accounts, whatever that case may be. Can you help us wrap our arms around it? I say, sure, uh, what are we governing?
And they pause and they're like, I just told you, you idiot, ai, no, no, no, no. Right? Ai, all the things is not a strategy.
Um, you know, what are your defined business use cases? What are your desired business outcomes? Uh, have you measured, have you quantified the value of the opportunity?
Right? How do you measure that your AI pilots are are working or succeeding, right? Or, or do you need to pivot?
Um, and that's where Rise came about. And then care, right? From a governance standpoint, it's kind of that rule book.
The, the, the guidelines, the guardrails you put in place to, um, to enact and, and realize your strategy. And, right? A a mutual friend of ours, Malcolm Mark once said, you don't put high-end brakes on a Ferrari to slow it down.
You put high-end brakes on a Ferrari to allow you to go really fast, really safely. And honestly, that's no difference between, you know, our traditional cybersecurity, uh, governance kind of thought model, nor should it be for ai. So, you know, if, if we start getting into the frameworks a little bit, you know, we can start with rise, RISE stands for research, implement, sustain, and evaluate.
So in the research phase, this is where you pick the problems. This is where you pick the problems that really matter the most for your organization and with the numbers, right? You don't say, again, ai, all the things, you say, things like AI for the claims backlog or AI for order exceptions, or AI for sales follow up, right?
This is where you check your data, you know, the quality of your data, you know, do you have systems and infrastructure in place? Do you need to go build, procure? And frankly, what's that cost to win?
And what's the ROI that you're, you're looking to, to gain, right? And then implement is for implement, right? This is where you touch a ship, a small pilot, um, that touches real work, right?
Hopefully, if it's your first time outta the gate, nothing terribly too business critical. This is where you measure things like cycle time, quality, cost per action, uh, that type of stuff. This is where you start integrating care, which we'll get into in a second, where you build guardrails from day one.
So your success is scalable and not, you know, kind of a one-off as it's for sustain. So now you treat the pilot like, like a product, right? You monitor things for, uh, model drift.
You fix any edge cases, right? Is your model over tuned? Um, you know, train the people who use it every day, which is super critical, right?
We know employees are, uh, kind of afraid that ai, how AI's gonna impact, impact their jobs. So, you know, keep it healthy, keep it balanced, like, 'cause AI's value compounds only if it stays in the game. And then e is for evaluate, right?
This is like, you compare the promises to the proof. Uh, this is where the measurement comes in. Did, did you meet your expected ROI, did you have the expected business outcomes?
How did you measure those? Did you hit, you know, a predetermined internal hurdle, hurdle rate? Where did your value leak?
Um, all that kind of stuff. What should you kill? Which pilot should you kill?
Like you, you should absolutely have a murder board for AI initiatives, just like you would for a, for, uh, IT initiatives, right? And then what should you double down on? Uh, then you feed those lessons into, uh, a feedback loop and kind of rinse and repeat, and then, uh, care, right?
So care is complimentary. Sit side by side ai. And again, that, that strong governance enables innovation.
Um, and care stands for, create, adapt, run, and evolve. And create is where you set that governance framework, where you set that governance framework that fits your risk and your market. What kind of regulatory scrutiny are you under?
Are you operating in the European Union, uh, as a developer or deployer and are subject to the EU AI Act? Um, clear policies, owners, and, you know, documentation records. Uh, everyone should know what good looks like, uh, within their AI robots architecture and whatnot.
A is for adapt. Uh, the third or the, the world moves, right? New threats, new partners, new laws, right?
How do you build an adaptable kind of framework that where those guardrails aren't too rigid, um, but still provide you rules that let you remain compliant, particularly with the regulatory burdens that, that we're seeing come down the pipe, you know, update the rules accordingly, um, and enable controls that align to your desired business outcomes without slowing the work run is now your governance's operational and day-to-day operations, right? From, uh, post-market monitoring, which is a requirement of the EU AI Act, uh, audits, access reviews, uh, red teaming, uh, evidence gets created as you kind of, as you build this beast, as you build this ship, not after the fact because the regulators will start coming knocking. Um, the EU did it with GDPR, they'll do it with, uh, the EU AI Act.
And I keep bringing up the EU AI Act. 'cause that really is the gold standard, um, top of everybody's mind right now for global AI regulation. And many other regulations that we're seeing on the books, whether that be in Asia-Pac Canada or even stateside, uh, here, um, are, are pulling components out of it.
And then finally, e is for evol, right? This is where you raise, uh, your assurance at scale, right? This is where if you need to go get certifications such as an ISO 40 2001, you're executing on it, right?
This is where, um, now you can start answering those third party reviews, uh, you know, from a strong posture. But now you're also having third party reviews conducted on your, uh, AI systems. And, you know, kind of like the, the, the classic plan do check act model, continuous improvement across, uh, your AI rollouts.
So if you put it all together, think about it, it kind of creates a rhythm. A rhythm, right? Like rise picks the right problems and turns them into results.
And care keeps those results safe, compliant, and repeatable. Um, choose a workflow. Give it a whirl.
Give it an owner. Uh, get, you know, try and ship something small. Uh, succeed.
Don't succeed. Learn your lessons. Rinse and repeat.
That's, I think, how you turn AI from a promise into a true competitive advantage Rock. I just think that is so cool. And here I am just like grinning and laughing.
Not only 'cause I'm delighted that we get to hang out, but also because you've said this phrase a couple of time, a couple of times, like ai, all the things, and that literally is just like what people are doing. Yeah. That literally is what boards are demanding that folks do, right?
I've talked to so many friends and colleagues and clients, and literally their boards just want them to AI all the things that's practically, that's practically the direction from like every company board today. Um, and so to have something that is so elegant and so straightforward as rise and care, um, that is really cool. Thank you.
Thank you. And you know, you and I are relatively fluid in board speak, and we know, like you and I know that when the board says ai, all the things they really mean, CEO go figure out the things to AI and prioritize it. But so much of that gets lost in translation from the board to now, like your AI steering committees that are determining what to do what and when, right?
And that's like where the disconnect starts to happen. I have heard about so many conversations where the objective is just do something with ai. Oh, Oh, fomo, tongue fomo.
And it's just, and it's such the wrong conversation starter, you know, because as you talked about with research folks, you know, it's so fascinating, um, because AI is a tool to help us achieve business outcomes. Um, and yet, you know, this thing that, that we've seen happen over and over again throughout our careers and technology, which is to say, technologists get super pumped about tech, which is fine, but actually the tech itself is not a business outcome. Um, and so I'm super glad to hear about these frameworks.
I'm super glad that you have created them and that you are sharing them with the world. Thank you. Thank you.
And I'll also double down on that saying that the tech is not the risk, right? The risk is the risk. And you know, I don't if you, if you indulge me to go on a little bit of a rant, like we're seeing all these regulations trying to regulate the tech and not the risk, right?
Like, we have consumer privacy laws on the books, we have anti-discrimination laws on the books, right? Which is, which is all the things that we're trying to prevent with, uh, all these proposed AI laws and regulations coming down the pipe. And, you know, nobody's gonna listen to me.
But if I were in charge, right? I would encourage taking a step back. Let's enforce the laws we already have on the books.
Do we need to maybe make some amendments to account for ai? Sure. Totally open for that.
But I am fearful that especially here, stateside, we're going to fall into the same kind of si cybersecurity and privacy patchwork, uh, that we've been battling for decades. And, um, now, you know, we have the America's AI action plan. You know, we're definitely not gonna derail this podcast going in into that and what that means and some of the language in there.
But, you know, uh, dis encouraging states or just incentivizing states from coming up with their AI laws. We'll see how it all shakes out. But I would just say, let's regulate the risk, not the tech.
Let's regulate the risk, not the tech rock. I've got a couple more questions for you from your perspective, and you have deep expertise in, for example, incident response. You know exactly what it's like to go up against these attackers.
How is AI helping attackers? Uh, what about my bald head and gray beard makes you think I have a lot of experience and incident response? Uh, so fortunately we haven't seen like widespread AI enabled malware yet where the attackers are leveraging AI is honestly, uh, we're seeing that very prevalent in phishing and deep fakes, right?
So more on the social engineering side of it. Um, what did we use to, you and I work at eBay, don't need to mention how many years ago, but long enough ago to say, to remember that, you know, we used to tell users, oh, look for bad grammar and bad punctuation, uh, in your emails. And that's a dead giveaway for phishing.
Um, well, that's, that's long gone, long, long gone. Even whatever, you know, small remnants there was with that preoc October, 2022, um, is, is long gone. Um, so, you know, we're seeing things like business email compromised and whatnot happened due to super believable phishing emails.
And we've seen millions and millions of dollars be transferred into fraudulent hands, uh, due to DeepFakes, right? Uh, people purporting to be on the other side of a Zoom call or the CEO or CFO convincing a poor accountant or whomever to transfer large sums of cash. I mean, heck, we even saw, and this is very public knowledge, kudos to no before for making it public and writing blogs about it.
Uh, north Korean employees getting hired, uh, onto us tech companies, and I'm sure beyond, uh, leveraging deepfake deepfake technology. So that's where we're seeing attackers, uh, primarily leverage it right now. Um, and then, you know, I would say nation states are leveraging AI with regards to, well, a lot of, you know, intellectual property theft, distilling other models, distilling other models, um, you know, uh, critical infrastructure, uh, you know, on to, you know, I would not be surprised if they're starting to develop tools to get into our infrastructure, uh, easier, faster, and quieter.
I mean, we know, um, all of the, uh, campaigns right now with, you know, China and our infrastructure from the telecom industry to the power industry, uh, that's all public knowledge. I don't think I'm sharing anything that isn't widespread knowledge. Um, and then I think from, you know, on the flip side of that, from the defender perspective, if we deal with a ton of data from an IR standpoint, right?
From a security monitoring standpoint, from a triaging standpoint, from an incident response standpoint, are we at the point yet where we could fully automate a security operation center? Um, no. Are we gonna be at that point anytime soon, in my opinion?
No. Uh, still still need some actual real human intelligence there and human in the loop. But can we start to get more effective at triaging the billions of alerts that come in acro, you know, across the world daily, um, and becoming more effective at that and reducing our false positives and false false negatives and quickly potentially taking action tier one type action, maybe tier one and a half type action on that incident response side from quarantining assets to whatever, and, you know, shrinking meantime to response, shrinking, dwell time within an environment, all that kind of stuff.
Yeah. Um, teams are, are leveraging ai now. The tooling that the teams are using are leveraging AI to assist.
I think it's exciting. I think it is super exciting. I cannot wait to see what this future holds for us.
Rock. Last question for today. Is there anything else that you want to tell us about your personal or professional use of ai?
Anything sort of particularly fun or surprising or unexpected? How, how are you using it? Oh, gosh.
Um, I am, I'm very much all in on it. Um, I am not a laggard or a Luddite maybe to, uh, maybe hurts me sometimes, but, uh, I, I joke with people, right? My wife does not work from home.
I do, and I joke that sometimes I have more conversations with an LLM during the day than I do her. Um, and I use it everything from, you know, work, you know, running my consulting business to helping me study, right? I am, uh, recently enrolled in a master's program.
Uh, you know, notebook, LLM is great for capturing study notes, creating study guides, you know, uploading transcripts of courseware, uh, videos or whatnot and creating the study notes off of that. And it helps me because then I could focus on the lecture, the conversation versus like rambling in the jot down notes, um, and then, you know, go back and kind of reinforce it afterwards. Um, you know, those are some of the ways that I've been using it.
Rocky, you and I got to talk about this in Atlanta, but for our guests, which master's program are you doing? Uh, because I'm a nerd and I hate myself, not data, the masters of data science and AI at the University of Denver, Who, so just to be clear, this is not a master's where you're learning about ai, you're learning how to do ai, you're learning how to make ai, this is like hands on keyboard from scratch, build this stuff. All I have to say is thank God for vibe coding, because I haven't room code in earnest, you know, for like 20 years, um, for school.
I'm not so worried about necessarily the quality and the security of my code. I just want to get the, the assignments done. I'll worry about that later when I, before I put it up into a GitHub for everyone.
It's so cool. Uh, I can't wait to hear a lot more about your journey as it continues. Rock, thank you so much for joining us today.
Thank you for having me, Caroline. Always great hanging out with you. This has been the AI security edge.
We're exploring the intersection of cybersecurity and artificial intelligence with leaders who are shaping the future of digital defense. I'm your host, Caroline Wong. Thanks again so much for joining us today on Techstrong TV podcast.
Don't free, forget to come back and look for more of your favorite video series, industry thought leadership and analyst research. Thanks so much, folks. Welcome to the six five Summit AI Unleashed.
I'm joined today by Eric Kessler, general manager of, of Amazon bracket at AWS for the quantum spotlight session on accelerating quantum computing research and innovation with AWS. Welcome, Eric. Thanks, Dave.
Uh, very great pleasure to be here. Good To, good to see you. Well, uh, quantum computing is always a very interesting subject.
We've been talking about quantum for years. There's always, there's always room to sort of separate where we actually are from where we hope to be one day. So if we accept that quantum computing is in its early stages, what, what are you doing at AWS to make this technology accessible and accessible to who?
Yeah, Dave, um, you know, at Amazon, every question, including this question starts with a customer. And as a matter of fact, it goes back to 2019 when I was actually still working on the machine learning side at AWS. Um, but already there I heard, um, from customers anecdotally that they were wondering about this technology, um, what does it mean for their particular business if it matters, and if they should get started to get involved, and if so, how?
Right? And, um, we had many more of these types of conversations. And ultimately that led us to, um, launch Amazon bracket, the quantum computing service, uh, of, uh, a w of AWS, um, with the goal to make access to quantum computers easier for customers so that they for themselves can, you know, cut through the hype, distinguish what is, uh, narrative from what is reality, and understand what this technology is really capable of.
And, um, I think since our launch in 2020, we have seen customers go way beyond that, right? So we have customers that are really trying to push the boundaries with these devices, using these devices, early quantum computers for scientific discovery to do application development. For example, we have, uh, been working over the past two years with, uh, JP Morgan Chase, uh, through our quantum Amazon Quantum Solutions Lab to develop novel protocols that use, uh, analog quantum devices in this case for specific types of optimization problems, and trying to understand the scaling laws that govern, uh, these, the, these, these protocols.
And, um, you know, that's an example of the enterprise, but also a lot of academics are using Amazon bracket. We have, uh, a study with, um, Purdue University together with Oak Ridge National Lab, where they were looking into using quantum computers to study a particular quantum mechanical models and, and investigate phase transitions. So again, very physical, very, very, um, you know, foundational physically.
I just wanna show it to you, the, the range of applications that our, that our customers are, are interested in today. Well, you talk about, talk about the range of applications. If I were to do an old fashioned, uh, uh, web search on, uh, AWS and Quantum, um, I would hear about bracket, but I would also hear about other things, uh, like, like ocelot.
So, so how do you, uh, tell us about this multi-pronged, there's at least two prongs to it. Tell us about your multi-pronged approach and, uh, you know, where does, where does bracket end and ocelot begin? How, how are they related?
Yeah, absolutely. Um, so Ocelot is a quantum prototype quantum computing prototype that was developed at the, by the center of Quantum Computing. That's a part of our organization, an r and d lab at the center at, uh, located at the campus of Caltech.
And, um, you know, I think in the long term, we all believe that quantum computing will have a transformational impact on a variety of different verticals, but we also think that it's gonna be a long way. And that quantum error correction is a fundamental ingredient to this. And that's why we founded the c qc, the Center for Quantum Computing as an r and d lab to focus on the development of techniques and technologic, uh, technologies specific to quantum error correction and making quantum error correction, um, uh, uh, viable.
Uh, and ocelot is the first prototype that we announced out of this effort, um, which is a architecture that combines onic so-called cat qubits with transman qubits, um, to enable a more efficient type of quantum error correction that we believe is 10 times more resource efficient than, um, than traditional approaches. But of course, we also know, you know, like any other technology, it's not gonna be that we one day wake up and we have a fully functioning, full tolerant quantum computer, uh, with applications and industry ready to go, right? And when you take the analogy to machine learning and artificial intelligence, that field, despite a lot of theoretical work in the last century, only really took off when customers had access, ready access to compute and the data, um, to, to work with that.
Um, and, um, we see, uh, the situation very similar in quantum computing, right? We want to drive a similar kind of flywheel. Um, and that is why we launched Amazon bracket, uh, one of the motivations why we launched Amazon bracket, where we want to bring early quantum computing devices as they mature to our customers, expose them, make them accessible to a broad range of customers and researchers so that they can explore applications and develop protocols along the way to that end goal, um, and in turn, inspire and, and, and show new applications to hardware developers and drive that, that, that, that flywheel.
Yeah. Yeah. And, and, and as you, as you drive that flywheel, obviously, uh, classical computing doesn't disappear one morning, uh, or, or it does, uh, a little quantum humor there, right?
It it does, and yet it doesn't at the same time. But, but, you know, do you expect this to be a hybrid scenario when it comes to quantum plus classical computing, uh, for a while And, and what's AWS's strategy there? Yeah, really, um, I think our perspective is that really all quantum computing is hybrid quantum computing.
There is no such thing as a class, as a, as a pure quantum computer, right? Even if you think about very close to the hardware, um, you know, on the lowest time scale, maybe on the lifetime of a qubit, uh, when you think about quantum error correction, that is a com that is a hybrid system of a classical controller. Um, and, and, and classical logic to decode the information that comes from across from a quantum chip, um, to correct the errors.
And if you zoom out a little bit, of course, um, we have a different timescale in a where, uh, there are protocols that use quantum computers iteratively between classical and quantum, uh, operations. This is a feature that we have supported, uh, on Amazon bracket for, for many years through Amazon bracket hybrid jobs. So we try to optimize that kind of workflow.
And then finally, when we zoom out all the way and look at the applications that we believe quantum computers ultimately will be used for, we look at how customers are doing this today on, on AWS, you know, it's not a single monolithic step. These are processing pipelines that use various types of HPC processing in a state function, uh, pipeline. And we don't think that, and we are very confident that quantum computers will not replace this entire pipeline.
Quantum computers will be used as a very specific form of an accelerator that takes out one particular slice in that workflow that is amenable for accelerations to quantum properties and will accelerate that piece. So in the long term, we think that quantum computers are in quote, just another type of accelerators that will be embedded in a, in a, in a, in a variety of different classical compute forms. So bracket allows you to access a whole variety of different computing technologies, uh, from, from, from a variety of providers.
Um, why wouldn't you just sort of pick the best horse ride only? Uh, I wanna get you answered that first and I've, and then I've got a follow up. Yeah, sure.
Um, well, you know, I think one lesson that we learn over and over and over again at AWS is that there is not a single tool to rule them all, right? Um, it's not the case in analytics, it's not the case in databases, it's not the case in ai, and it surely is not the case in quantum computing, right? Customers want the choice, and, uh, especially in quantum computing, as the technology is still very nascent, there are a lot of different technology platforms with different pros, different cons, and part of the challenge is to figure out what are the properties of different technology pathways and what are the most promising ones?
And we see ourselves, you know, actually very closely related, uh, philosophically with, uh, uh, Amazon Bedrock, right? Our, uh, uh, service for large language models, right? They're also, we have a suite of third party large language models that are available to customers for different use cases with different pros, different cons, and at the same time, we're developing our own models, the NOVA models, um, that that, that we have released recently that are also available through Bedrock.
And if you think about it, that's exactly the model that we want to pursue with Amazon bracket to give customers really the choice of technology that they want. Yeah, that was actually my follow up. Yes.
So it's, so it sounds like the answer to my follow up question, which was, is it a proper analogy to draw between what we're seeing with ai, let alone just using the term ai, but when someone says a model, um, it doesn't look like at any point in the near future there will be one model that will rule them all in the field of quantum computing. We haven't even settled on how to derive these qubits yet. Can you envision a scenario in the future where there will be multiple ways to leverage quantum, just like there are multiple ways to leverage large language models as an example?
I think that's what I heard you just say. Yeah, no, absolutely. I mean, I think it's far from being a foregone conclusion that this is a winner take all technology, so to say, right?
These, uh, technology pathways that we see, uh, at the moment from Berg atoms to ion traps to superconducting qubits, spin qubits, uh, photonics, right? So there's like, uh, five to six prominent technologies that are actively being pursued in all of them with very different properties, right? So you could think about there are certain trade-offs for, um, communication networks that might be suitable as certain algorithms might require higher throughput, which would point you in the direction of a certain technology platform.
I think time will tell. Um, but, uh, at the moment I think it's way too early to to, to call a winner. So I'm gonna toss in a bonus question, and this comes from some of my students in the C-T-O-C-I-O program, uh, that I teach.
A lot of them are struggling right now to answer the question, how do we get ROI out of ai, let alone, let alone quantum, they're looking, they're looking at how to leverage AI to make money and or save money. What's a good way for them to keep on top of or get started with quantum so that they're not blindsided by these developments? So let's say that, uh, um, AWS is here with me.
I'm the CIO of a large organization. What's the answer to that? How do I, how do I get started?
What, how, what, what should I do you have a version of bracket that I can play with so I can become familiar? Where do I start, Eric? Yeah, absolutely.
Um, so Amazon bracket, we provide, uh, a number of different resources, uh, to get started quickly. We have our open source git a repositories with, uh, host of, uh, different getting started tutorials, explanations of different technologies. So I would encourage everyone to take a look at that, and you can use it for free with the simulators that are included in our Amazon bracket, SDK, uh, which is also open source and available to download.
Um, and then as a next step, you can also use the hosted simulators on, on the service. I would also, uh, encourage folks to take a look at our Quantum Technologies block on AWS, where we, uh, often highlight, um, interesting work that people are doing with Amazon bracket, as well as, uh, results from our own research, uh, at the Center for Quantum Computing and, uh, solutions that our partners are building. So Eric, you work in, you work in the quantum computing field, uh, in your wildest dreams, let's, let's, let's say five years out, what is the sort of intractable problem that you hope leveraging quantum computing will, will help us solve that we haven't been able to solve with classical computing?
Have you, have you given that any thought? Yeah, Dave, of course. Um, and you, you, you see, I think the important thing about quantum computing is that it is not just making things that we do today a little bit faster, a little bit cheaper, right?
It is very profound in the sense that it enables us to compute a whole new class of problems, most famously understanding nature at the microscopic scale, right? Where quantum effects come into play, right? And ultimately, that is, um, you know, a, a very profound shift in our ability to compute things in nature, right?
So that, as a scientist, gets me just extremely excited. And of course, you know, the dream is to exploit that capability to understand phenomena like high temperature superconductivity, um, or important molecular re reactions, for example, in the production of ammonia, right? Which would've a very large economic impact.
But I guess in, in practice, I am a little bit more humble because I know how, uh, big of a scientific and engineering challenge that is. Um, but already in the field of material science, when we look at fairly simple materials, the, the computation of time dynamics, right? Dynamic reactions of materials to external factors are extremely difficult to com co to compute with classical means.
And I think this will be one of the first real impact, uh, applications of quantum computers, um, to help us understand, uh, time dynamic simulations on, uh, on, on, on, on, on simul, uh, on, on materials, uh, which exhibit quantum effects. And that will, uh, be a new capability for us that we hope we will find interesting applications for Exciting times ahead. Eric Kessler, AWS specifically talking about quantum computing.
Thanks for joining us for this quantum spotlight at the six five Summit. com slash summit. More insights coming up next.