Techstrong TV September 18, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. It's an AI agents kind of day. You're watching Textron Gang.
Hi everyone. Happy Thursday. Welcome to Textron Gang.
We've got, uh, well, as I said in the outset, it's all about AI agents today. It's not just today, it seems like we're, it's about AI agents every day. Um, are they glorified API calls?
Are they truly intelligent? Unintelligent, I wiggle to discuss it, I guess. But we're gonna look at AI agents from a couple of different angles today, and we've got some great people to talk about it with.
Let me introduce you to our gang for today. Uh, we've got Jack Gold, always a pleasure to have Jack, our cyber reporter, Terry Robinson and all things cyber as well as all things, all things, uh, also cyber and AI and all things, all things is our friend Chris Blak. And joining me, our man in Silicon Valley, John Swartz, John's.
Good to see you. All right, gang, let's jump into it. Um, uh, Workday recently had, I guess it's their user conference out in the valley or in San Francisco.
John, you attended, you got an article on this. They recently also hired my friend, Gabe Monroy, who I, I, he's been to Google and Microsoft, but I think he came over from Google this last night. And, um, or maybe actually he was a digital ocean in between this gig.
But anyway, they, they announced a lot going on there. And of course, Workday's, HR and stuff like that. Give us the scoop, John, what's happening?
Yeah, So when you said hr, those are the magic two letters. They're not, not ai, but HR in this case. So, Workday made a ton of announcements around agents, around a new platform, but it basically, it centers on HR and making it or automating it.
So all those tasks that you did are supposedly gonna be a lot simpler and easier, but you're gonna probably have to make a trade off in some sort of, of fashion in, in that this will be autonomous. You can't ask for it in the human element, but this idea is to strip it down and streamline the op the operation as much as possible. So Workday did three big things.
They announced some more new Workday Illuminate agents, which are specifically for hr, finance, and industry applications. They announced something called developer platform that lets customers and partners create share and scale AI power sold then Workdays ecosystem. And they announced the data cloud or data cloud data infrastructure layer help organizations maximize their strategy and HR and finance data.
Um, they also announced a partnership with, with Microsoft. And, um, you know, to kind to summarize, I talked to a couple of folks there at the events, including the guy who runs Workday AI named Shane Luke. He's a young guy, really sharp guy.
And he told me that basically he acknowledged that employees as well as HR employees, understandably, are gonna be hesitant about using these tools because of data and privacy concerns, as well as their job security in the, in the case of the employees. But that he kind of drops it or divides this tech, this, this, this crowd of employees and, and, um, customers into two crowds. There's the tech forward crowd, which is really excited about doing this.
And then there's the other crowd, which is hesitant. So, um, in addition to him, I talked to one of the customers of Workday and, uh, he, he described their HR process, which sounded to me like a nightmare. You basically had to make calls or use email to do almost anything.
And at this point, uh, the idea is to simplify things to three steps or less. So on one hand, this might be good for an employee, it might make it easier for HR department. I think the trade off is that eventually the human is taken out of the equation, which I think could lead to other issues.
Yeah. And that's why we'll leave it in hand off to baton y. All I think this is, this is the kind of thing, you know, as I look forward, you know, the drives me to using terms like inevitability curve, right?
We take HR is so, so let's step all the way back. Hr. I, I've got a very good friend who's a founder of a very successful company, been 35 years in, and, and he says that one of the points of failure was when they, they had to, uh, have an HR department.
Because for all the good people working in hr, we all understand that it is this department that they all, all stereotype and say, claims to love you until the day you fires you. And is very p polite as it walks out the door. And it's this an artifact, I think, of the sort of digi digitization of business and people and so forth.
It only goes so far, right? And, and so these semantic systems, I'm always talking about HR is the perfect example. You know, you should have inside your company a story, a semantics, uh, system that says, I run the company.
I understand the humans who work here and, and how to, how to handle them, how to handle their needs and capabilities and use and productivity. And we don't. And if we stick AI in a clinical centralized, you know, immoral, unethical, un unfounded basis into these structures, it's gonna be as Orwell and in, you know, just awful as you can imagine.
But I don't think we will, right? I think we might try to, and we'll find out how awful that is, which will, back to the point that started this rant, curve us back to something more sane. And I think the more sane structures are possible now, it's just we're pushing the limits of the old structure, and this will break them.
Yeah. I, I think it's also imperative to think about it from the perspective of the first time you have a lawsuit, because you put h uh, uh, AI in your HR department, all of this stuff's gonna get ripped out in 13 seconds, right? And it's really a, a problem because most companies, most companies have their own kind of HR ecosystem going, right?
It's not just three people in an office somewhere. There's all kinds of stuff. There's tentacles throughout the total organization.
And how do you build an HR model that's individualized for each company? It's really tough to, it, it's possible, but it's also very expensive. It requires an awful lot of learning, an awful lot of data that most companies aren't gonna spend time putting in place there.
The, the ROI of it is probably pretty low compared to putting, uh, compared to the ROI of putting AI into something like DevOps or security or, uh, you know, sales enablement, customer support, et cetera. So I'm not convinced that most companies are gonna adopt this very quickly. It's probably more appropriate for smaller companies where the HR department is, is probably smaller and has less stuff going on around it.
But it's a real uphill battle to put this into some big company. I, I, I'll, I'll, I'll be you a, a lunch or something. I, or anybody that wants to win this one, I'll make a prediction anyways.
I'll be held to this one three years from now. I think what you're saying right now is absolutely true, but three years from now, it's gonna be really cheap and easy. And if you don't do it, your competitors will and they will just economically wipe you out.
You know, running HR the way we have traditionally, um, small because we're doing this now, right? Without getting all that. But at the small business level, you're right.
You can still take a small business, say you don't really do hr, but if you actually put a system in that understands there's humans here, you'll be more efficient and profitable. Now, that'll take a couple years to regularize and scale out to large enterprises, but I think this is an evolutionary thing. Um, Scott, you're still Trying To do, we'll have to get back together in three years, Chris, to see if Well, there's a, there's a lunch writing on this.
Yeah. At Least, but that's right. That's big deals, right?
A couple of beers probably. I just put an alert in my calendar for you guys. Please Do you please do.
So I, I, I got some thoughts. First of all, I've always hated the term hr. Mm-hmm.
It sounded so antiseptic. Human resources. I always like the people department.
'cause really that's what it's about. It's about dealing with people now. You know, I've worked for big companies.
I've helped big build bigger companies and, and I've worked for a lot of startups and mostly and tech Strong, you know, has been a startup. I, I think until you get to a certain size, you really don't need an HR company or an hr, uh, department. And then I, I think the other thing is, you know, I, I've been a big believer in PEOs for tech companies for going on 20 years now.
com, we went with TriNet and I, I've used Tri I've, I've used a lot of them, a DP, Insperity, and they all have pluses or minuses, but part of what they do is these sort of HR function, if you will, and they'll even sit in when you have to let someone go or something. But that being said, It is something that lends itself to process and process heavy, process heavy, uh, uh, process heavy function, I think lends itself well to a agentic ai, right? Because that's what the agents are good for.
If you have a very defined process, have at it. But I, the thing about HR are people that is unique though, is you're still dealing people to people. And if it's so straightjacketed A to B2C to D with the age, it, it doesn't account for people.
Yeah. Chris, And it's funny you say that word because it all this, you know, uh, you ourselves, an example little tiny startup, were literality at the point right now where we had to do exactly this. And it turns out the term we decided to use is people in our corporate repo, in our corporate structure file structure, where we record people and things and assets and all, everything we do, there's this a file structure that's called people under that are the people.
And under each of the people are, what we are hoping is a structure that represents who they are as a person, which works for the company and everything else, but is actually really a human being. And as you, and as we say in all these different segments, AI is not running an LLM against a thing. You know, it's structuring a system.
It's structuring, structuring a semantic system that includes all sorts of automation that's running in Linux and GI or whatever. You know, there's things that are happening in systems all the time, some of which are calling LLMs doing things, but is the structure, you know, is it a semantic structure? Does it make sense?
And our view in, uh, this is both us as a company and the, and the open source, uh, civic ai, um, uh, approach is that systems should be semantic. And all that means is exactly what we're doing here. They should, you should be able to say them out loud and make sense.
Right? You can't, you can't, you know, there's logical sentences you can put together that semantically make no sense at all. Right?
You know, the sky is blue because of hammers, semantic, you know, structurally it makes sense. Semantically does not. We need to build technical systems and business systems that we can say out loud without, you know, sounding like we're nuts at some point.
The HR is the, is I, I think, Alan, you and I at least agree in the entire corporate structure, is that kind of thing where by the time you finish explaining, you just proven it, oh, we need this system to make sure that our people are more happy, and no, they're not. No, we don't. It doesn't work.
Yeah. I got the, I got the impression from, oh, sorry, Alan, I got the impression from, from, um, talking to the folks here and reading what this will do, that they're, I mean, they're not entirely certain how it's gonna work out. I mean, they, they, they're anticipating a lot of pushback and back and forth, especially over things like medical benefits or, you know, payroll.
And, and I mean, Terry, not to go too deep on this, but I mean, I think back to, I had a former employer where I had a, an operation for kidney stone removal, and they, they claimed it was a preexisting condition, and I had to fight them for weeks before I eventually got the, you know, got them to pay. Um, so I, I just, I kind of foresee these type of, um, uh, uh, surprises cropping up. And even the, the guy at, at workday, Shane, he acknowledged it.
I'm sorry, go ahead, Terry. Well, I was just gonna say, I mean, yeah, and some of the process stuff, I can see where this is useful, right? I also agree that maybe smaller companies, uh, don't need it.
Although they need something like a TriNet or whatever they're, they're doing. Because, um, I've, I've worked for places who I worked for, you know, a company that got taken over by another sort of smaller entity and they didn't have any kind of HR in place. And it was a disaster.
I mean, it was, it was awful. But, um, but yeah, this, and then maybe something that takes the bias outta some of the decisions that are made around h HR issues, you know, if you will, like John, like your, your kidney stem, which I shared this with you, you know, that's alright. Uh, but, but with, with something like that where you don't have somebody sort of making maybe a biased decision, maybe it's just cut and dry.
This is what we cover. This is what we don't, you know. Well, I don't know.
I mean, I don't know. I have a love-hate relationship with, with hr. I find that I like a lot of HR people.
I've worked with some very talented ones, but I've also found, you know, and it is a, a thing that you do learn that they are work for the company and not for you as a person working for the company. And it's kind of like the IRS has its own tax court. You know, they make all the decisions about what goes on internally.
I just, Yeah. But the, the problem, the problem with HR or the, the challenge with HR shouldn't say problem, but the challenge with HR is that most companies are unique and people are unique, right? Yeah.
And so, if you're putting everything into an AI agent that's going to be making the same decision, no matter whether it's John or Jack or Terry or Chris, or, that may not be the right decision either for the company or the individual. And that becomes the problem. How do you build an agent that is flexible enough to understand the differences that people need?
I mean, we're talking about humans here, whether it's a kidney stone, whether it's, I I, I don't know. Uh, you know, you, you've got a, a medical problem and you can only work, uh, four days a week in, in, in the office or something. There's lots of stuff that goes on with people, right?
And I, I'm really concerned that trying to build an agent, a unique agent for each company. 'cause for the most part, every company's gonna be unique. Is it gonna be a real challenge?
Yeah. Camping a unique agent for each, each company. And I think I, I know we're sort of at time for the segment, but, but you know, it's, it's, you know, you know, a unique agent for each company is not the way to do it.
You know? But, you know, and again, we're actually, as a company trying to lay this out right now, I think the, the answer comes less down to whether it's an AI or a human, you know, person making the, the, the decision on things is whether the company understands the people that actually work there. So, you know, when we put assets together to do something, and again, we're very early, so maybe I'm wrong about all this, but I think we have a structure that accounts for that, where you don't just say, John, level one qualification slot project where you say, John kidneys stone four days a week.
You know, you know, in, in a way that a company can hold that information respectfully as we do in our heads. We just don't write it down. But we get HR departments, we try to write it all down, and they turn back into corporate, uh, machines.
Any, so Maybe the AI goes for the process stuff, but you have to build whatever your people department, your hr as the cultural part of that is really rests on, you know, the, the people and really understanding the culture of the, of the company. You know? So let me, That's where you, that's where you need People.
That's where you need, I mean, that's where you need people. You can't just Let, let me, let me tie this up a bit and we'll segue to our next section, which is, and, and forget HR for a second. Forget the problems inherent in HR and people and what have you.
The fact is, this is a case where we're seeing agentic AI move beyond software development, software testing, software deployment, which is where we spend a lot of our time and gives us a glimpse into the true impact that agentic AI is gonna have up and down the entire corporate structure and the entire realm of of workers. And whether you know, today it's hr, tomorrow it's sales, the next day it's finance and, and, you know, distribution operations and everything else. We're gonna come back and talk specifically about security agents.
You're watching techron Gang Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group. Hey, everyone, we're back here continuing our agentic AI Thursday, go figure.
Um, next, I think we're gonna turn the microscope or telescope or some sort of scope onto, uh, the, don't mention security agents, the rise of security agents. So we're seeing multiple cyber companies rolling out agentic ai, you know, agents to do a, a bevy of different security task. Terry, you, you've been following this one.
What do, what do you, what do we got here? Okay, so I'm, uh, talk to you about a a t of things that, that we've been reporting. Uh, first I'm just gonna say, it's amazing to me that AgTech ai, particularly in security, sort of went from this little twinkle maybe earlier in the year to something that's becoming more fulsome, um, and, and expansive.
So we have a three stories. Uh, one is about CrowdStrike and, um, you know, they've already, they were already introducing like, um, uh, AI agents into like their sox, right? Or into sox.
And, uh, now they've expanded that or SOX workflows. Now they're, they've expanded that and, um, they've acquired Pan GA. So that's an effort to secure AI applications.
Um, lasso also, um, added an, uh, AgTech, uh, art, uh, ai, uh, service. And that, uh, is for securing AI applications. I think we should talk about that, um, a little bit more, uh, in our discussion.
And then, um, Eve security has also, um, applied ATech AI to, um, observability and policy enforcement, uh, which I, I kind of think is interesting and maybe, um, a good place for, um, AI agents. I, I would like to, you know, discuss that a little bit more as well. But, um, yeah, so we're suddenly seeing this flurry of activity, like it's become more accepted and maybe a must, a must do.
Um, but I, when it comes to security, I'm, I'm always a little suspicious of having the, the fox guard in house or some sort of what seems like self monitoring and regulation. I just don't, I, I, I don't, I don't know how, I don't, I guess I don't trust, uh, AI antigen AI enough yet to, to feel comfortable with that. The, the challenge in security though, and, and I see why so many people are trying to implement ai, the challenge in security is that it such a broad need that very few companies have the resources to do it properly.
I mean, you can get, how many negative hits do you get before you get a, a positive hit? And how do you go through all the negative hits to make sure that you don't have to act, uh, react to them. So in, in that sense, what we're talking about is, is really volume enhancement.
It's the ability to go through a lot of stuff that you just can't hire enough humans to do. Uh, or, or may not even have the, the, the skillset. But Terry, you're right.
Um, you know, ai, it's gonna be an AI versus AI world, right? The bad guys are gonna have AI as well. They're gonna have their own agents.
So it's gonna be my agent against your agent. And who finds the, the hole that, uh, needs to be filled or, or can't be filled. And, uh, how, how do I react to that?
It, it's, it's gonna be a really difficult problem. It, it gets worse when you start talking about security issues within ai. Not just security issues in general, but, but holes in AI that need to be filled, that aren't filled.
Uh, you know, we've all seen the stories about grok. Well, we won't go through that, but Its too depressing. But, but those are the kinds of things that are really of, of concern.
And, and if you're, if you're putting AI in charge of your security and it screws up, how do you even know? Well, How do you know that's the thing? How do you know it's screwed up?
And to what extent it's screwed up? Um, and then how do you keep it from perpetuating the screw ups, right? Um, through other things.
I, I had a, um, coffee yesterday with, uh, John Waters from Eye Counter. You guys know him. He used to be with Mandiant, and he's got, and we discussed a, a lot of this stuff.
And of course, this is maybe the, the way everything is going, but there's gotta be some precautions here. Um, it's, It, it's interesting, the last, the last segment we were talking about, HR and I were talking about security, and I always like security 'cause it's very serious, right? And it's not just, you know, uh, ones and zeros, but there's stakes and good guys and bad guys and critical infrastructure.
And, and, and, you know, a lot of us, you know, in our careers get to work on, you know, work with actual conflict, you know, actual, actual warfare. Um, and, and the, the most important part of this is civics, right? And I was on this show earlier this year when I was mostly yelling at this stupid chat GBT and, and b******g about how terrible the industry was and bad the products are, which is true, but I was wrong about how bad they were in which directions.
However, um, it's, but, but all of our work, all the work we're doing now started with exactly AI for civics, you know, for critical global issues at the civics level, which is as meta as you want to get, as we all know, ones and zeros are, are easy and complex networks are fun, but actual human, individual, humans groups, you know, what, you know, civics is the most complicated realm. And I'm here to tell you, or at least again I'll attest to this and I'll stand by it, that they're very, very good when applied at the civics level with all those stakes. So I'll go back to what I said earlier this year, which I think I've even said it live, and I didn't, you know, I was just gonna say it out loud even though I wasn't sure about it.
But yeah, the way you fight AI is with ai, you know, e exact exactly like you just said, right? It's going to be, it is right now about the bad guy's, AI and the good guy's. Ai, if good guys don't want to use the ai, they will lose now, you know, all the flaws of the Yeah, yeah, yeah.
Yep. Absolutely true. However, pragmatically, if you're not using it for defense, you're gonna lose.
You have six months maybe. Yeah. Let's play thermonuclear war.
I was thinking, I was thinking like a west, west world in a scenario where for all the positive things, what could go wrong? And it brings me back to the previous segment, and Chris mentioned this. You think about HR and your, their ambivalence and maybe some, some caution about use.
Its use. And I think about security, and I even be, the red alarms go off even more so until something horribly happens or goes to skew and which leads to lawsuits or some sort of damage or some sort of headlines. So I think, I don't know, if you think maybe there might be these genic AI trailblazers, you kind of learn early and kind of set a path for others.
I mean, maybe they jump whole hog into HR and security and, and educate us. Fair way. Let's Look it a little bit differently, right?
Let's look at it from the perspective of various vertical markets. What, So if you are a bank, right, and you're putting security, ai security in place to secure your accounts, and it fails, people just lost a gazillion dollars, right? Uh, you're gonna get sued and the feds are gonna come after you.
And, and there's all kinds of, of bad ramifications. If you were a, uh, you know, if you're a McDonald's and somebody gets a hamburger wrong, uh, order wrong, what's the worst thing that's gonna happen to you? Right?
They're gonna redo the, the order. Um, you're gonna go to, someone's gonna go to the counter and say, Hey, you, you screwed up. You put pickles on it.
I don't want it onions or whatever. Um, it's not such a big deal. So it really is not across the board.
I think a lot of this age agentic AI stuff is gonna be vertical specific. And for instance, banks are notoriously who did it first. I'm not gonna do it until someone else does.
It improves it, right? Uh, financial markets are like that. Uh, tech not so much.
Techs are trailblazers. They'll go off and just play with it because they can. Uh, so I, it it's gonna be an interesting rollout for a lot of this technology, but I think it's gonna be very dependent on the verticals and how fast it actually gets rolled out.
That's, and the first time you have a real glitch, a real problem, it's going to, and a lot of these verticals is gonna get stopped in its tracks. You know, Jack, what you describing is very much the crossing the chasm model. Yeah.
Right? You got 15% of the market that are early adopters. In this case it's probably tech companies, and we're talking software development, deployment, stuff like that.
Then you've got, you know, once you reach that early, uh, adopter model, then you gotta kind of cross the chasm into the mainstream. But that mainstream is not homogenous, right? It, it's broken into strata.
The, and if we, at a very basic level, there's two pieces of the mainstream. So about 35% of the market are early mainstream adopters. They generally are the ones who, look, I saw the early adopters had some success.
I'm willing to give this a try because I think my problems are so serious, and that if this thing works, I'm gonna come out way ahead, right? And that's about 35, about half of that mainstream market, 35% of market. The second half of the mainstream market are a little bit more cautious, conservative.
They say, I'm not gonna adopt that until I see my peers already adopted it and have some success with it. And if they don't have some success with it, I'm not adopting it. And that's the latter half of that mainstream market, again, about 35% of the market.
So between them, that's 70%, you got 15% early adopters, right? 85%, that's critical mass. And then you got 15% of the are laggards who are never gonna adopt it, not anytime soon.
Um, I, I think that's what you got here with AI in general, and especially with agent ai. But we're, we're, we're, we're we're specifically talking about security in the segment, though, right? You know, so I, I, I agree with, with both of you entirely on the, on the market adoption, I will say in this case, it's just literally true.
And I'll, I'll walk you through exactly what that means. If you're out there, you know, use AI right now to look at your security posture, you know, that could be done by anybody. You know, iteratively, you know, all the failures of weaknesses of these products, don't get you started.
We don't have time. Just sit down if you have nothing else, uh, particularly if you can't access somebody who couldn't show up on a show like this, which is 90% of companies out there, use AI to figure out where you are and to go all the, you know, all the way, uh, say in Jack, you know, to your points that yes, you know, if you are critical and you're really, uh, implementing things and you're big and have the resources and capabilities, you know, you will be putting agent to a in, you will not be doing it. And the kind of ways that fail if it, you know, if one person or one AI agent is your weakness, that you've got a bad system, right?
And there are ways to architect good systems where you can, can use agent AI and trust it enough to do the things that you trust humans enough to do things in those critical situations, which is quite often more than one human. But, you know, that's, again, too much detail. So, but if you do not do these things in cybersecurity over the next six, 12 months, whatever market you're in, you are compromised.
Absolutely. That's just, that's the way the world is. I I can, Yeah.
I'm a little more cynical too, though. I think there's this group, and maybe they fall within those categories. You're talking about Alan, that do things strictly, uh, based on money and you know how much it's gonna cost them if they do or don't do.
Mm-hmm. Something like that. Mm-hmm.
Sure. You know, and oh, I at TCO are huge. Yeah.
Well, I mean, the thing about security specifically though, is look, the bad guys are certainly using Yep. And, and so there is a little, I need this to do that. The eve security one I did interview, I think it's their CEO or CTO, and, you know, they just came outta stealth, basically Israeli cyber company.
And they're, they're using, it's an interesting piece. They're using AI to secure AI agent interactions. So, hey, yeah.
Novel or somewhat novel approach. Anyway, we're about outta time for this segment. Let's come back to C block today, sticking with our agent AI theme.
We'll talk a little bit about DevOps. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hey, everyone, we're back here. And, uh, our C block today is DevOps agents come this way, right?
com. Uh, Joe Duffy, CEO, founder of Lummi. Uh, they've recently announced, uh, rolling out some AI agents that are specifically trained to automate infrastructure management.
Infrastructure is code stuff like this. Lummi iss a pretty well known player in the open source infrastructures code infrastructure management space. Um, a lot of people use the open source project.
It's kind of an, they have sort of an open course SA model as well. But, you know, the a the, the AI agent here is, is the new wrinkle to this. And, you know, if one says, look, if we're moving infrastructure management, if we're moving infrastructure, infrastructure as code, you know, an AI agent seems to make sense, it should be able to help manage that, right?
I, I mean, at some level, the infrastructure is code sort of movement, you know, going back to Puppet and Chef and Ansible and, and these products. It, it, it has a history, right? If we, if we could reduce our infrastructure to code, and therefore it's sort of repeatable, programmable, why wouldn't an AI agent make sense there?
Um, it's not like we're dealing with people in the HR issue. In other words, however, and and more power to Joe Duffy and the PMI people, they've done a good job over there. I think we're gonna run into the same reluctance though.
The same reluctance. And, and quite frankly, I think that reluctance raises its head in security as well, right? I, I had this with security automation when I, we tried to roll out from IDS to IPS and automated remediation and vulnerability management people, people aren't so cool to just let, let the machines go, right?
Yeah. This, this isn't quite the matrix yet, and we don't have Mr. Smith.
So Chris, now that I'm looking at you, you do look a little Mr. Smith ish. I don't know, maybe, maybe, maybe Chris, maybe Chris is an agent, but, um, You know, but but kidding aside, I, I think what we're really, and, and this is, you know, we've been now through three segments of this, what we're really talking about is a question of trust.
Yeah. Do we trust these AI agents to do the job we think they're gonna do? Go ahead, Mr.
Smith. It's, I was thinking about the, like I said, the third segment today. I'm trying to think of a different way to say this.
And, you know, the, the, the, I just had a great way to say it, and I've lost it and run. And we're on air, which is just lovely, but it's, it, okay. It's a semantic situation.
It, we, we need to be able to say it. And if we say the story, the story is, like you said, we have an IDS, you and I were there, right? Is there's snippers and so forth, and say, Hey, we, they can stop things and we're gonna let them do it.
I don't know. We're used to things breaking all the buddy time. So the story that we're in leads us to the place where, you know, in our roles we're supposed to be, we're literally where, where's, you know, where where's the, the novelist among, among, amongst us, right?
Because if you're writing stories about these sort of situations, the people, the characters playing our roles in this case would naturally be suspicious. That's what we expect. And, and, but, but the, the narrative of, uh, ai, right?
You know, the last segment, this is what it was in the last segment, we we're saying, we're gonna use AI to, to save us from ai, which is really just a way of saying, we're gonna use technology to save us from technology, which is of course, you know, we, we say ai, like it's some thing, it's a terrible acronym in the first place. It's neither artificial or intelligent. It's a large language model that processes data in semantic forms and produces re results that are, that are metric old.
And, and, and look, yes, there are analogies with humans. They're not human. They're not going to be human.
You know, we may get to all sorts of interesting Turing test levels now we're kind of at them, but it makes no bloody difference. It's technology. We use technology to secure technology to develop technology.
This technology is no different than hashtag cryptographic anything else. And we need to get our, our heads away from a, from looking at it as something other than technology. It is another technology.
You know, every time we say ai, we have Frankenstein and Skynet and popping our, in our heads, and we can't bring ourselves to get through the meeting, to have the decision to develop or implement or take the next step. Yeah. Because reality is the perception's reality.
I'm sorry, go ahead, Jack. I'm sorry. I I was gonna say, Chris, this one's a little different because technology in the past, uh, you know, we went from mainframes to many computers to PCs, to, to mobile phones.
Those are all great technologies, very useful. But at the end of the day, we were controlling them. The difference with AI is that we're letting AI control us.
And, uh, to a large extent that, well wait a minute, but, but let me finish. So to a large extent, the risk is much higher. I mean, technology versus technology, I get it.
You know, we're using technology to try to fight, I don't know, ransomware as an example in security, right? We're not being very successful at it. Um, it's getting better, but it's not, we're not there yet.
And, and, you know, the bad guys are, are, are as good as the good guys are and using that technology for, for their purposes. So, uh, well, it, yeah. And, and 'cause they're spending more money doing it, and they're getting better people to do, they're more innovative right now.
Yeah, yeah. Yeah. You also mentioned, it's interesting, Jack and Kristen did, there's this kind of whole debate about ai, whether we're in charge or it's in charge.
And it even comes down to like some of the two biggest names. Put out a, a study earlier this week where philanthropic says that wholeheartedly AI's taking over our workplace while open, while philanthropic says that while open AI at the flip side goes, no, no, no, no. It's, we're using it for our own personal use.
So I, under reading between the lines, I understand why they came to those conclusions, which are all self serving, but it feeds into this debate about this technology, which in a sense, there is like that, uh, wild card element to it. And in some, well, exactly. I mean, and in, in the past with technology too.
I mean, I've been around a long time and have seen these things sort of spin out. There's been, it's been sort of more deliberate, right? And, and mm-hmm.
AI doesn't, and I could be wrong, but it doesn't feel deliberate. It feels like it. And, and out of the gate, without the guardrails, before we know what it's doing, it's doing.
And that's not the way tech necessarily worked in, in the past. There was a lot of deliberation. There was a lot of thought behind, uh, some of these things and a lot of control over the environments we've got, you know, and, and maybe it's the way of the world.
There's less control over development environments and everything else. These days, they, they're not the same as they used to be. I think in many ways, we think there was more control than there used to be.
And Jack, you know, to, to start with your, uh, perspective on this technology, as I look at it, you know, goes back thousands of years. I mean, this stuff in our lifetimes is fascinating. And, and the, you know, the, and the, and the risk is right.
You know, as we'll agree risk right now for all this is maximum, couldn't get more as complicated as high stakes as you can possibly get. But it's not about, uh, what we're current, you know, this current LLM as such. It is about semantic structures and so forth.
And technology, as I look at it was, you know, we go back 10,000 years or 5,000 years ago, we really started building things, writing things down in co encoding things that had to exist in our heads as functional rules that literally, you know, come down to how physically big we'll build things where you can live, what you can do. Those are technology structures, you know, that our species have, has been developing all along. We're at this point right now where we've been able to, since the industrial revolution, mechanize, steampunk it, you know, digitize it and come up with analogs of functional systems that work really well.
You know, now, you know, it's, it's, I'm as surprised as anybody. I kind of expected the digital ai, we have semantic ai, you know, FML isn't that fascinating? It's actually using the structures we use in our brains, you know, to process information analogously to the way we do.
And we can't control it. Like we can, you know, steam in a boiler. It's a funny thing.
Let me, let me go back to my trust thing. And Chris, you said something and let me expand on that and bring that back to trust. And it goes to what Jack said as well, if you be, you could think the world's 6,000 years old, but let's assume it's not right that it's been around a little longer.
And, and the fact of the matter is, homo sapiens, humans have been around, uh, depending who you believe, two, 300,000 years, right? Was kind of the rise of, of the Homo sapien genius. Genius for if it was 300,000 years, for 290,000 of those years, we really didn't have much technological innovation.
We made a better arrowhead figured out how to use tar. Well, the fact is Homoerectus might have used fire, they're saying Yeah. Millions of years ago.
Yeah. Right? But yes, but, you know, so for, for 95% of our existence, we really didn't have sort of a technological revolution.
It was very, very spread out over tens of thousands of years. In the last 10,000 years, things have picked up a bit, starting with agriculture and, and, you know, move to villages and towns and loss of the hunter gatherer better weapons 'cause a good, you know, like it or not, one of the best indicators of human technological evolution is what weapons we make. Yep.
Go figure. And, you know, so for 10,000 years ago, you get agriculture 150, 200 years ago, you got the industrial revolution. And boy, things really pick up, really pick up, right?
Think about taking a caveman to 1890, my God, right? But now the digital age, let's call it the 60, 70 starts the era, the digital age, and then the nineties, the internet age, the 2020s, the AI age, that pace of innovation, that pace of change, that pace of revolution is exponentially faster, bigger than anything we've seen in the 300,000 years, 10,000 years, 200 years. Stuff is off the charts, right?
Behind ai, we've got, we've got, uh, quantum computing in the rear view mirror, and that's gonna be with ai. And there's so much change, so much revolutionary change coming so quickly that I think it's human nature to question it, to lack of trust. And, and so this, this change is coming quicker than we could get comfortable with it, right?
And that's, that's, that's my, that's my shimmy take for today. People like pro people like progress. They embrace it eventually, you know, they love it.
They rejected it first, and then they learn to love. Yeah. They, they, right, they get comfortable with it.
But we're going so fast before you can get comfortable. The next thing is here. Well, but it's, I think you have a timeline.
The timeline, it's risk versus reward, right? Even on a personal level, I will adopt something if the, if the risk is less than the reward I get from it. I mean, you know, uh, computers can be bad as well as good.
I, I, I can't live without one today. Uh, my, my cell phone, my, my smartphone, you know, if you had told your grandparents that you've got this little thing in your pocket, you could be anywhere in the world and they can reach out to you and talk to you instantly, you know, they, they would've thought you were absolutely nuts. You know?
To your point, Alan, it's it mm-hmm. It's gone crazy. I mean, even my parents, they wouldn't have, wouldn't believe it unless natural Smart.
Listen, we had a, we had a phone in the house that was a party line. Who knows what a party line is. My grandmother Had that too.
Absolutely. Those are cool. What about, hey, this is a long distance call.
Don't stay on so long. Right? But you know, Really, Like every other week we, we get some announcement for an open AI or Gemini or Anthropic about here's a new advancement, you know, something that builds off of this and you can't even keep track of it.
Yeah. I mean, you're just trying to embrace what you have. That's, that's really the issue.
It's the pace of revolution. I think we can keep track of it. And, and Alan, let me give you a timeline of semantic technology evolution.
And really this begins about three and a half million years ago. Re you know, we, you know, use of tools, but really it's, it's the ability to pass down knowledge. You know, individuals may have done that long before that.
But three and a half million years ago, we started passing down knowledge, passing down narrative, right? Fi 50,000 years ago, we got so complicated, we started writing stories between us, right? And we, and that's the real, you know, you look at human anthropology, we, you know, that's pretty well documented.
And we got to 10,000, 5,000 years ago, and we gotten so complicated that we started writing it down instead of saying it to each other, not saying it face to face. And, and as I like to say, that's how we got ants, right? Since then, we've been trying to struggle with who gets to write it down.
How does it mean? How do I compare to, you know, beyond the personal relationship in small communities, so that when you look at the, the, you know, the, from the establishment of those canonical mimetic structures, you know, uh, in the early, you know, before, uh, a thousand, uh, you know, three, four or 5,000 years ago, the printing press, the internet, everything that's happened a hundred years, it's just an acceleration of that same slope. But the tools and mechanisms are the same.
The semantic structures have been, we've been developing for about three and a half million years. So we can engineer this to a certain extent and understand that, you know, semantics, you know, word processes actually lead to outcomes. And if nothing else, ais are helping us look at how we think and how we make decisions.
And, and, and to my point about civics, how we actually interact, you know, us incredibly dangerous individual. But you know what's interesting? You, you're talking about semantics, but you are leaving out a human element.
You still haven't addressed the trust issue. Well, it's semantics is how we develop trust. I mean, that is literally, you know, the, the Struggle Too fast for trust.
There's another piece to this, guys. Let me, let me try a little bit, uh, a little bit different. So I'm the, the CEO of, of a company, right?
And Alan, you come to me and say, I need a budget to deploy ai. And I, and I look at you and said, Alan, you were here six months ago where you, you needed a budget to deploy this other thing, you know, before ai. And six months before that, you came to me for a budget to deploy this other thing.
Well, that's what CISOs do Well, right? But none of those are even deployed yet. And now you want something new.
But, and that is, that, that's part of it too, guys. I'm looking at my watch though. We're way over.
I apologize. We gotta, we gotta, we could talk about this, obviously for the next 300,000 years, Chris, we Probably will Uhhuh, Maybe this whole thing is a simulation. And we are in the matrix.
Oh, we are controlled by ais. Wow. But we're gonna take, we're gonna take a break.
We're going to come back tomorrow. We'll continue our discussions on the gang as we do stay tuned for Tech Drunk tv following this. As usual.
We've got a great stuff. Jack, Chris, Terry, John, thank you very much for, uh, coming on. I think we'll have Mr.
Vard back tomorrow, so, you know, we'll see how the Yankees are doing. But until then, on behalf of everyone here night, yep. This is Alan Shimmel for Techstrong.
We're out. Hey everyone. Welcome back here to Techstrong tv.
Uh, you know, I love introducing you to new companies and people who we haven't had on before. So let me introduce you to our latest find, um, company's name is Eve Security, like in Adam and Eve. And if you look at their logo, the Eve sort of looks a little bit like an Apple.
Um, and on behalf of Eve's security, we're happy to have Nadav Kornberg. Nadav is the, uh, co-founder and CEO nif Nadav, welcome to Techstrong tv. It's great to have you on.
Great To be here. Thank you, Alan. So before we get into Eve, let's hear about Nadav.
Hi. How did you chair Come here. Go ahead.
Um, I'll start on like half Israeli, half British, which I think equals an Australian in some ways. I've been in technology and product for the last 20 years. Uh, started in security from RSA and Checkpoint.
Had the privilege to kind of be on the endpoint side when it was growing at Checkpoint, and really saw how you're taking an idea, excuse me, a small group of people and kind of growing something into a product that's then been sold to, you know, many, many companies and having a big impact. And, you know, as I moved on and I even moved to different industries, a gaming hospitality in my previous startup, uh, was in the hospitality space, but it was always the same drive from that origin, which was, we're solving a real problem, you know, now how do we make that into a product? Start small, grow that, you know, nurture it, see how it grows, build it up.
And that's always kind of been a drive of mine as well to kind of in that kind of world of being able to build something, understanding true problems. And I've always had affinity as well, that kind of trying to understand operational pains and problems, and then transforming that into automation products, and then see how that is deployed in the, in the real world. So, you know, from there, uh, kind of February, March, you know, obviously AI is, you know, not new from the last year, but you were starting to see the real problems in pain points that, uh, organizations were starting to face.
Even my previous organization. How do we start handling AI in organizations? One of the new challenges.
And when we identified the gaps with the existing solutions and how to handle those problems, you know, I got, I had the privilege to meet my other two co-founders through mutual friends, and we really clicked together. We all kind of thought and believed that that problem is just gonna grow and grow in, in today's dynamics of how AI agents are really evolving in organizations, brought us to kind of found Eve and start tackling the problem of how agents are managed governed in organizations, in areas that matter. Absolutely.
I love it. So I gotta go the, the Australian thing. You got me going with that.
You, but you didn't spend time in Australia or anything? No, no. Just in the UK for five years.
And then in Israel for majority of My, I I could hear sort of that Australian thing going on there though. Um, so, you know, look, I, I don't have to tell you everybody, everybody is on the AI kind of bandwagon, or at least in the tech world. I think it's gonna go through all over.
What about, let's start with this Eve security. Let's, let's frame it for people who maybe didn't catch it as part of the whole thing. What is the problem Eve security is looking to solve?
So when we were talking to, uh, more than 30 CISOs, the, the kind of the broken record that you were hearing again and again was people are asking me to deploy these AI agents and put them in the organizations. What's concerning me is what happens when I start connecting them to critical systems? Okay.
And, uh, and the joke was, okay, if it connects to GrubHub and orders 20 sandwiches, uh, okay, it's not a big deal. But if it accidentally connects to a critical system like GitHub or NetSuite or Salesforce, Atlassian suite and starts messing around with those systems and you know, and can perform actions and not just read data, that could be really devastating for an organization. So really we saw the emphasis was what could the agents do with critical systems?
And the terminology of, we want another set of eyes, we want to put them in a box, we want to police them. And the tools that they have today don't allow them to do so because the protocol, which is now the English language, is just so different of what we've seen before. So they're facing this massive push from top grassroots department heads, all want to now achieve their business objectives, believing that AI is gonna be the force to do so.
'cause all of their competitors are doing so, and now the poor CISO now is stuck in between. Well, it's gonna be a, you know, on me if our systems get compromised because of that. Yeah.
Well, today it's on the ciso. What's gonna be interesting is if these things don't work as intended, someone's, someone's head's gonna roll, right? I, I was out at a conference last week out in, uh, Napa for a company called Jfr.
And um, they had some data, I think it was from Gartner, 40%, 40% of CIOs are increasing their budgets because their board, their board is pressuring them to do more ai, ags and stuff like this. And so the gold rush is in, right? The headlong rush into doing these is in, and, and look, I've been in security 25, 30 years myself, unfortunately, very few times in all those years has I, have, I seen something where people say, wait a second, what about the security?
Right? No, they, they dive in the pool and then figure out if there's water in it or not. Um, and this is probably no different, unfortunately.
So what did you develop here at Eve to, to solve this problem? So when, when we were looking now at the problem, uh, and as this is being developed and the adoption is, is kind of growing in organizations, we understood we had to provide three key components. The first one is observability.
We need to give eyes on what's happening and in the most deep manner possible. And we categorize in, let's say four main questions. What agents do I have in my organization?
Who are they talking to? Which assets are they talking to? What are they saying?
What are the requests? What are the responses that are coming back? And even to the depth of why are they saying that integrating with even the platforms that those agents were built on top of to understand the reasoning, why did they even attempt to make that request?
The reason for that is if we can give that, give that in depth observability and understanding of what we call intent and the data that's being requested, we can then put a layer on top of that of policy enforcement. 'cause I truly understand what the agent is doing and I can truly understand what the organization is asking for them to do and not to do. And then I can police that.
And now one of the feedbacks that we received as well from CSOs world, well, don't give me a platform now that's gonna give me 5,000 alerts a day. I can manage that. Which then brought us to the perspective of, well, we saw some of our competitors mentioning agent, a human in the loop just put a human in the loop, just add that's not been a skip.
So we built our first agent in the loop, which basically means we have an agent security engineer, basically, that is looking at all the events that are raised from the platform and then handling what we call the low risk or medium risk events based on their ability to interrogate the agent and what they're doing. So if they understand the risk and they understand the reason, we can make a decision. And just like any employee in organization, if I see a high risk item and I can't justify it, I'm gonna escalate it to my manager.
So if we can curate those very, you know, small amount or really critical events, that's when we generate value for that, uh, security organization. So, and the component that our agent in the loop is built on top of is we can understand anomalies, which are new behaviors or repeated block behaviors that are impacting business continuity. We can understand the risk of the operation and we can understand the justification of why they're trying to perform that.
And with those calculations, that's how we can automate the process. And then the value that we generate for organizations are, they can have a full understanding of what's going on. They can police the activity with minimum overhead and minimum impact to business continuity.
Excellent. You know, as I look at this problem, one of the things, I don't wanna say it's unique 'cause it's, it's, it's probably more analogous to APIs, but your AI agent can be dealing with so many external and third party APIs, other agents, you know, interactions that it, it becomes, it's hard to police that, right? It's hard to enforce that kind of, you know, I guess you start with like a zero trust and build it up from there.
But it, you know, it's, it's sticky. These agents are sticky and that they can, you know, and now you got a to a protocol with the Linux Foundation and the MCP servers and, and all of these things. How, you know, it seems like a big job.
It's, it's definitely a big job. And I'll say that at the end. Um, the way that we built it is you have components, what we call sensors that are feeding information to us.
MCPA two A and every API at the end is gonna be a data source for us to understand how these agents are behaving and what they're doing. It's gonna be our job to normalize that and then be able to make a decision on that activity. Now we're giving two options for companies and we call those critical systems crown jewels.
'cause we consider them like to be the crown jewels of an organization. And that's what we want to protect is those critical crown jewels. Now we'll have an option to say, do you want us to detect and response, meaning that, that the action has happened, but we can now still see its impact, what it's done, and give you an alert to handle that.
Or we can give you, even give your abilities or block. Like we will actually sit in line and we've seen organizations now being open to both. It very much depends on the crown jewel.
There are gonna be very critical systems that they're gonna be very concerned about different types of activities that can have there and they really want to lock things down. On the other hand, it has impact for business continuity and other areas they want to detect and response saying, I wonder after the fact, if something happens and I wanna be able to address it, our agent in the loop as well can adapt policies based on behaviors and say, we've been too strict here. We should open it up.
We've been too open here. We need to strict it down. So that adaptive continuous improvement is something as well that our platform provides.
But yes, the complexity of what we're dealing now with MCP APIs and A two A is still a necessity for organizations now to resolve. They need companies like us now to step up and provide solutions for these new protocols due to the, again, forcing function of adoption. I love it.
Very cool. Nadal, I, I gotta spend a little time nuts and bolts for people who want get more information about Eve's security. Where do they go?
security. They'll be able to go eve, Do security EVE security. Exactly.
And Do you have any kind of, uh, pretrial free product, something to get people started? Yeah, de definitely. We've got now not only a design partner program, but a beta program as well that we have, that we work together with companies Now.
Our focus now as things are evolving are really to make sure that we're solving and providing value for the pain points they're experiencing. So, very much we're working very closely now with all of our design partners and beta partners to ensure that, and what we're hearing from them is like, great, you know what I mean? Like, yes.
You know, thank you. Like when we, because we always start our conversation about talking about the problem and if they're facing it, 'cause we like to mm-hmm. Classify the success that we can have of our customers, or we wanna make sure we're investing our time with companies that are truly gonna benefit from our solution.
So when we do that type of vetting and we talk about the problems, they're very much like, yes, that's exactly what we're facing now. And we need help in that area. You know, we didn't mention, you guys recently announced a $3 million seed round.
True, I guess first money in and, um, so it sounds like the product's still in beta. When do you think it'll go? Gp?
Listen, I think it's what I'm, what I'm for is, is I would say I'm looking for multiple success stories that we have with customers to kind of pull that trigger. I believe that's gonna happen in the next eight to 10 weeks as we're now working ready with customers and we're receiving feedback and we're going through that. But, uh, at the end of the day, you get you kind of, that, that gets answered to you by your customers.
They're like, yeah, again, super happy to reference about our experience. Well this is solving so many pain points for us. Like, you know what I mean?
Like, how can we expand now too? This are gonna be what I've seen just in the past, the driving points for me to understand guys. Yeah, we, I feel confident now of our product market fit that we've proven enough.
Agreed. Very cool. Nadav, I wish you a lot of luck, you and the whole team there at Eve Security.
You know what, I'm going to hold your feet to the fire on this. I expect to see you back here in about eight weeks talking about general availability and, and what the customer reference customers are saying. Okay.
Pleasure. All right. It's a great conversation, a great idea.
The do kornberg co-founder CEO of Eve security here. Ont Techron, stay tuned. We're gonna take a break.
We'll be back with more. Hey guys, thanks for the throw. We're here with Ron Zaius, who CEO for Iron Wall.
And we're having a little chat about, well, why are the bad guys harvesting all our data, even if it's encrypted. Ron, welcome to the show. Uh, pleasure to be here, Mike.
I really do appreciate it. And you know, it's, it's everybody nowadays who's out there collecting your information. It's, uh, you know, we're highlighting some of these foreign apps, but they're not too different from the domestic ones either.
It's true. It's hard to distinguish the good guys and the bad guys and what they're up to. Um, let me put this this way to you though.
I mean, are we just being too cavalier about this and we're not protecting that data because we're not seeing where it's gonna be used in some illicit fashion? I mean, as part of this, we just don't have the visibility we need into this whole motion. I, I believe that to a point.
And, you know, I come from a psychology background, so just let me use a metaphor here. You know, you have Pavlov's dogs, you have the food, you ring the bell eventually because they happen, right? Immediately you put those two things together, that is not only canine behavior, that's human behavior.
If you separate, if you ring the bell two hours before the food or one hour or you change it, then all of a sudden it's harder for us to connect those two. What we don't see when we're using apps is, number one, how much information we're giving 'em and then what the repercussions of that is. It's number one that, that information's being sold.
Number two, that those companies tend to be very careless with that information. They get hacked and that information gets out there. And the repercussions we see from being scammed, from having identity theft, from having, you know, our companies ransomware, we don't put it together because it doesn't happen immediately after you've given that information.
That's what makes us so cavalier in my opinion. Alright. It seems like there's two vectors that people are talking about, at least most.
One is, uh, data's being collected by, you know, with good intention, at least by various AI companies, but they don't have much regard for how they actually collected it. And they may be pulling sensitive data that's gonna show up in some sort of AI output a year or, or so from now that could be potentially embarrassing. Is that kind of the first, uh, most immediate concern that we have?
I, I think that's a big concern. I mean, just look at it from a business perspective. I go on and I want chat, GBT I'm just pointing them out there, you know, all the LLMs are pretty similar on this, but let's say I put, Hey, here's a document with all of my customers on it.
Help me sort and analyze that, or they're gonna suck that information and they're gonna gimme back what I want. But in addition, they're gonna keep that information. And, and we've done this, we've gone into some of the LLMs and AI and said, who are the customers of our competitors?
And in some cases it spit out some pretty sensitive information because they have put that in that information in, and now we're harvesting that to get it out. That is definitely a big concern on how careless we are about our own information about how careless companies are with when they process it. And again, not understanding how much information is being collected, not because the companies need it, but because they can monetize it.
And that's where we become the product. And because it's almost free to these companies, I don't think they're very careful with what they do with it, in my opinion. Yeah.
And the second use case is a little farther out there, but it seems like nation states are also just starting to collect all the data they can find in the hopes of throwing some quantum computing at it someday. But, uh, is there likely to be, you know, an event three, four or five years from now that might embarrass somebody because sensitive data that they thought was encrypted maybe not so much? Well, and I think we're already seeing that.
I, I think zero day has already happened and it's just getting worse. Uh, and, and you know, government's looking at it, it's not just obvious that foreign actors are collecting this information and using it. If you think about what war might look like in, in two years or five years, you know, there are certain nations that you are not going to attack militarily because they have nuclear weapons or because they're very strong or whatever the case may be.
The idea would be that if you were going to destabilize 'em, you destabilize their infrastructure. Imagine that your power grid goes down. Imagine that, you know, hospitals can't handle the wounded can't take care of six.
Imagine that you are able to bring down the pillars, let's say in the US social security. If social security failed tomorrow and couldn't process checks, you can imagine the turmoil that that would build into accomp into a country. And because of that, that's almost as effect as effective as bringing military into de stabilizing them.
All of those scenarios can be accomplished by getting your information, being able to get into those organizations, being able to ransomware them, lock them down, put in spy, all of that can happen with the information that's out there. And it can happen today. And if you look at how governments are using it, it's not just foreign governments.
Our government buys travel information on every trip being taken to, to see and to use for their own, uh, uh, their own auspices. Our government is buying, you know, paragon to, to, to go in and, and find and be able to break into phones. And all governments are out there doing this.
The more information you have given, the more information you have out there, the more of a target you become, or the company that you work with or the organization that you work for, becomes, this is real day and it's today. I think when I talk to cybersecurity folks, they kind of get the issue and they're concerned about it, but you go talk to business leaders or even the average employee and they'll give you kind of what feels like a collective shrug. 'cause they're like, well, I'm not kind of feeling that pain right now.
And they don't believe that whatever they're doing today will be of any interest to anybody tomorrow anyway. But how wrong can they be? They, you know, and I, and I think so, and, and you know, it's funny because when we talked to companies, and I'll zero in on companies specifically five years ago when we talked to them about executives protecting their private information, they were like, you know, I'm an executive.
I need to be out there today because of shootings, because of attacks against executives. They're very, very sensitive about it. When we talk to them about protecting the private information of their employees, they're exactly where you are, where they're kind of shrugging and saying, do I, you know, it's just one more cost, but the numbers are really pushing in that way.
Number one, 70% of ransomware attacks that have happened over the last three years have not been directed at the servers to begin with. They're directed at individuals within the organization. And by being able to do that, by compromising your phone, I can get to your company's phone by compromising your home computer.
I can, you're eventually gonna use it to get email you're eventually gonna use to get something else. And even if I don't get into the network, if I can compromise your email, I can send out messages to other people in your company and it's gonna come from you. So there's gonna have a lot more authority.
All of that is built because of personal information. The only reason these type of phishing attacks work to get us in is because they're so personal that we forget to look at the email address. Or even if we look at the email address, it kind of makes sense because the email looks like it's coming from my brother-in-law.
The content looks like it's coming from my brother-in-law or from my, you know, from my boss or from my subordinate. All of that is because of personal information. I think companies are slowly waking up to the fact that you can have all the best firewalls in your, in your company, but your weak link are the people who work there.
And if their compromised, it's only a matter of time before you're compromised. It also feels like the efforts to get that data will become a little more sophisticated, at least from the bad guy's perspective. We see things like digital fakes and all this other stuff, but almost like the end game isn't to steal the data as much as it is just a K eight, some sort of bogus process that allows them and, and gain access to that data.
And the transaction may never be complete, but, you know, it's just a massive data phishing expedition. It it is not a football game, it is a chess game. Mm-hmm.
It is moving all your pieces into place so that when you're ready to attack the king, as it were, you're gonna have everything in place to be able to do this. This is a long game. It, it can be used to influence, it can be used to, you know, to get people to get very angry about things.
It can be used to destabilize key industries and key parts. It can be used to cost financial turmoil. It can be used just to understand your enemy or the people you're going after or the people who have the money much better.
But it all comes down to data. I mean, 20 years ago, companies gathered information about you to know you as your customer. If I know their birthday, if I know, you know what kind of car they like to drive, I can sell them more.
That's not what data is being used for. It's not being used to understand you more. It's being used to exploit you, to influence you, and to be able to also understand all the pieces of society that you touch.
And giving them an open door to say, because I know more about you than your parents know, or than your spouse knows, or than your child knows, I can influence you and affect what you do much better than anything else. And with ai, I can do that at scale with large pieces of data and I can affect 10 million, 50 million, a hundred million people at one time. And that's something we've never been able to do before.
Is this kind of, in some ways the natural outgrowth of what we saw with social media where they're using algorithms to kinda collect data and analyze it and, you know, magically you're just talking about something next to your phone and it shows up in your social media feed as a topic. But is this kind of just taking that concept up to several orders of magnitude higher? Yes.
And again, it's AI that allows you to do that because before we were looking for the factors that we knew. I mean, so simplest thing in social media, you know, I, I have friends who are, who are judges and we protect government officials, judges among them. So we have a, a a judge and I say to you, have, you know, Siri or Alexa, and it doesn't matter which one you have, but we say things like that.
You don't think it's listening all the time, just stay to it one day. I really like strawberries, I'd like to do more with strawberries. And then magically you're gonna start seeing strawberry ads appear on your television, appear on your, you know, on your, uh, streaming service appear on your computer, on your phone.
Well, obviously those are related, but that's also a one-to-one. What what AI allows us to do is to say, because you like green shirts, because you wear glasses, because you comb your hair a certain way politically, you're probably this, the leap from one to another is so huge that humans don't normally make those connections, but AI can. And then when you join that with generative ai and you bring that together to say, now I can develop something that's going to exploit that and I can do it at scale.
That's where the social media companies had, like you said, 5, 6, 7 orders of magnitude greater is what's happening today. Because, and by the way, it's not just for money, it's for lots of other geopolitical, obviously economic, but also socio, uh, reasons that they're trying to do this. This is going to have more of an effect on everybody's life than they understand.
And then taking it back to what we were talking about with the applications to begin with these applications, you can tell how important it is to 'em when, when TikTok is collecting 27 pieces of information that have nothing to do with interacting with, with TikTok, that needs to tell you that they're, that they want those 27 pieces. And the reason they want those 27 pieces is because they need 'em to understand everything about you, Mike, and how to influence and change your life. Hmm.
So what are we supposed to do about all this? What can we do? I think a lot of people at this point feel somewhat helpless.
So my recommendation is get rid of ball, electricity, you know, put a tenfold in. Uh, and I must say I'm probably not too far from that, but, uh, you know, there are lots of, uh, common sense things you can do. So a, a, a couple, you know, three things that I tell everybody.
Number one is don't be the product. There's no reason these companies pull a lot of information from you, but a lot of times they're asking the information. Don't give a company any piece of information that they don't need to give you whatever the product is you want.
If you don't need my address, if I'm only gonna be dealing with you online, if I'm gonna be watching TikTok thing, I don't need to give you my address. I don't even need to give you my real name. I don't need to give you my age.
I don't need to give you anything that ties to I I don't need to make the connection with my Facebook page or with my LinkedIn. If they don't need it for the product, don't give it to 'em. And if they require it, why?
There's no reason. And you should never, ever give anybody your mobile number because your mobile number is the key. You probably have moved Mike more often than you've changed your mobile number.
So think about that. So number one, your mobile number is gold. Treat it like a credit card number, treat it like a social security number.
Do not give out your mobile number. Do not give people information that they, that they don't need to do your product. It's okay to lie, there's no reason for these companies to have it.
The second thing I always say is use A VPN and caveat, my company is somewhere along the corporate ladder owned by somebody who does VPNs, but regardless of which VPN you use, encrypt your information. It it can encrypts it at the source. Your ISP, your internet service provider and your phone provider are legally entitled in the US to snoop to everything that you do.
So just encrypt it. It doesn't stop you from doing anything you do on the internet. It just puts one more barrier.
The third thing I say is, you know, understand friends from foes. Your friends are your family, your friends, people that you know in real life and you deal with, you can interact with them on a whole different level than you can with both, which are company. It's not just that, you know, it's not saying that meta's a bad company or Google's a bad company, but if they collect a lot of information on you and they get hacked, and in the US there's an average of a major breach every single day, that information is gonna get out there and it's going to be weaponized against you.
You get credit card fraud, you're probably not gonna pay anything. Somebody scams you or scams your parents or scams your, your spouse, you are going to lose that money. And it's all because of the information that you've given out.
So the third thing I just tell people is think about it. If you treat your personal information like you do, if, if somebody came up to you in the street and said, what's your social security number? If I asked you right now in this video, Mike, what's your, your your social security number?
Are you gonna tell me? Uh, I'm gonna tell you, but it won't be the real one. Right?
I'll be the real number and if you wanna tell me the real one, let me know so I can write this down. But you know it, but when people say, what's your mobile number? What's your email address?
How old are you, where do you live? People give that information all the time. And in supermarkets, I go in and people give their mobile number to get a few discounts on their, on their food.
You know, like they were giving it away for nothing and they're not even thinking about that. That's the mindset. It doesn't mean you change, you don't order from Amazon.
You can do those and make yourself a lot more secure. Just keep those three things in mind. Mm-hmm.
It reminds me of, uh, you know, my parents grew up in Ireland and all my relatives over there, uh, of that generation, none of them ever used their first names. They all used their middle names to talk to each other, but for official documents, they had first names. But if you went looking for that person, nobody knew who he was.
Yeah. And that, by the way, that same and, and my parents from that generation, I'm, I'm Cuban, my background is Cuban and, and you know, we, we do the same thing. Everybody has a nickname.
Your family knows the nickname, and it's not related. You know, it's not Billy because you're Bill or you know, because you're William. It's something so odd that only your family knows.
And when I was a child, this is, you know, just off the point. But I remember walking home one day and a car pulled up and the guy said, get into the car. And I was probing nine or 10 years old.
And I said, I'm sorry. And he said, your mom told me to come get you. First thing I did was talk to him in Spanish because that's, that's the way my family would talk.
And I knew my mom wasn't gonna send a stranger and I didn't know who this guy was. And he's like, I don't understand, just get in the car. And I said, what's my name?
And he, you know, he just looked at me and said, get in the car. And then I ran in and you know, we, we got a police officer, we got all that. Those are the kind of things that we always, and and they always call this paranoid, but that's the way you've gotta be.
You've gotta make sure that how you treat and the information you give your family and your friends is not the same thing you put up on meta. It's not the same thing you put into Google. It's not the same thing that you give on a company.
And that will always be a flag for you of knowing when it's friend or felt. Lemme ask you this last question. Do you think that our politicians and lawmakers understand these issues and they are, uh, gonna be crafting some laws to deal with that?
Or for that matter, are they just kind of turning a blind eye to it because, well, there's a lot of money out there and it'd be me. Uh, I'll go with the latter on this. And, and by the way, there are a lot of people who, who, you know, are out there talking about security.
They're out there especially about privacy. There are currently about 22 states that have passed some type of privacy law. But understand, and you know, California has one of the best.
New York, Texas, a few, it's not even a red or blue kind of thing. States understand the privacy of this, but there is so much money in this that even when they pass a privacy law, they hedge it and they say it's opt out. When really good privacy laws are opted and other than you, you know, you shouldn't have the right to steal my information and monetize it without my permission.
And what they do is they make it opt out because they know most people don't have the time, don't see it. And a lot of times it's like, if you don't opt in, you're not gonna get the, uh, the satellite service. You're not gonna get the telecommunication service.
You know, you're not gonna get whatever product you want. So number one, are they aware of it a hundred percent? Number two, does it have an effect on the economy and how much we spend on fraud?
Absolutely. The third thing is, are they doing anything about it? No, because the companies that, that are profiting by this spend a lot of money to make sure they don't do anything about it.
All right, well folks, you heard it here. You, it's your data. At the end of the day, it's not the company's data and you need to guard it jealously because they're gonna, once they get their arms on it, you don't know what they're gonna do with it.
Hey Ron, thanks for being on the show or for that matter, whatever name you're going by these days. But it's all good. My name is Martha and, uh, I do appreciate, thank you very much for having me on the show.
All right. And, and folks, we'll see you next time. Hey everyone, we're back here.
Well, we're not live, unfortunately. We were live when we recorded this, but you're watching it on recording. Let me introduce you to Dimitrius Brinkman.
We are here at Swamp Up. If you couldn't tell 2025 Swamp Up. And we are thrilled to have you tuning into our coverage of this year's Jfr Swamp Up Dimitrius.
First of all, welcome to Text on tv. It's great to have you on here, Demetrius. Looking at my notes here, it says, uh, founder of the ML Ops community.
Great title. Talk to our audience a little bit. What, what exactly is it and what do you do there?
Yeah, so we're a community of a hundred thousand developers right now that's primarily focused on bringing AI and ML into production. That's the main thing because there's a lot of research, there's a lot of demos that you see out there, but then actually getting use out of it and bringing it into production, that's what we focus on. And we do that in a various, in various ways.
One being we've got a Slack workspace, we'll do in-person events like meetups or workshops or conferences. We do virtual events and like meetups and workshops and conferences. I also have a podcast myself.
We have a newsletter. There's various ways to engage in the community. We'll do like one-on-one matches, curated matches of people in the community.
So in general, we just are trying to keep the education and the understanding of this field as high as possible because it is moving so fast. It Is. Hey, just say you have a podcast isn't enough.
Look into that camera, tell them where they can get you podcasts. What's the name of it? Yeah, you can find it on anywhere that you find podcasts.
It's called the ML Ops Community podcast. And right now we're on the 314th episode. Really?
Yeah. So we've been How Often do you do 'em? Twice a week.
Really? That's fantastic. Yeah.
Good stuff, man. So you're also keynoting or on stage tomorrow doing a session. Yeah.
You know, by the time people see this, you probably have already done it. Yeah. So tell 'em what they missed.
Well, by the time you see this, it could have gone horribly or it could have gone wonderfully. Let's hope for ladder. I'm sure it would Go.
But really what I'm excited about talking about is the idea of how there's, there's almost two big ideas that I wanna present. One is how the chat interface isn't necessarily the best interface for us to interact with machines. It's very low bandwidth and we're used to a much higher bandwidth when we interact with humans.
And then the other idea is what I am thinking about how all these companies that are putting agents into production, they all want to be an agent. They don't want to be a tool. And the way that it could shake out is you have a master agent that goes off and is using tools, but right now it's very fragmented.
And this ecosystem that we live in today is, I go and I navigate to one chat bot, and that has agentic capabilities and it goes off and it does some stuff. Maybe it has access to some tools, but it's not like there's this ecosystem, this homogeneous ecosystem that I know this one chat bot can do anything. I have to then go, if I want something specific done, navigate to another website and use their agent capabilities to do something.
So a perfect example of this is when I wanted to file a claim for a delayed flight that I had, I was talking with my LLM of choice and saying, you know, can I get money back on this and do, am I in the right to file a claim? And it said, yeah. And instantly what you wanna do is say, okay, go file it.
Go file It. That's the user experience that I want. And, and, And you know what that, let's call it the dream, if you will.
And, and I thought we were getting at least when you talk about travel. Yeah, right. I thought that was part of the, uh, and I'm not knocking them, don't get me wrong, but that was part of this chat GPT agent, like, Hey, chat GPT, I gotta fly to Flagstaff, go out, find the best fare and book it for me.
Yeah. I haven't used it yet. I don't know if you have No, I I don't, I don't trust it.
'cause I'd have to go look at the flights myself and make sure that it, I'm not stopping over in Chattanooga or some, some place where, well, You bring up something fascinating. There's two pieces of that. One is the trust aspect, and the other is this UX cliff that I've been thinking about where a lot of interactions with machines, we don't necessarily need to type everything out.
That's a much slower experience than if we just do two clicks and we get what we want. Yeah. So there's almost this valley that we need to cross before an agent is even useful.
The task has to be quite complex in order for us to do that. And I think the reason that the flight bookings have captivated our attention is everybody has done that, and it's way more than two clicks and it's cumbersome. And so when we think about that, we think, wow, it would be nice if I could just say, I want to do it this time, this day, I want to go to this place.
And then it goes and does it. And we don't have to go and click through and do all these multi clicks, which is, and then look back, ah, is this the price I want? I don't know.
And that's not fun. Yeah. But to me, it, it sounds like a pay me now or pay me later kind of situation.
Right. Because how do I set all those up? It, it, I, look, I don't pretend to be a, an AI expert, but like I've gotten to the point now with my ais of choice where it knows me, right?
Yeah. It knows my style and voice for when I'm writing it knows what I want out of the task that the usual task that I ask it to perform. It would be great if somehow I could train my ai like, hey, I like to fly out first thing in the morning.
Yeah. I like to fly home first thing in the morning. I will do a direct flight.
I don't care if it's twice as much money and no matter what I want direct, if I could help it, um, you know, all of these little kind of, this is me kind of thing. Yeah. And I think that's where we struggle, right.
Well also, if you think about that I'm not the same person today as I am tomorrow. Yeah. And maybe that's, there's certain things that I have hard rules on, and then there's other things that I'm a little bit more flexible on.
And so that as a problem is a very difficult one to crack. Yeah. I also think that, you mentioned something fascinating earlier about the trust, which is we have to be okay if we do have this master agent world that is some kind of a hybrid chat interface.
So it's not only us with words, but maybe there's other kind of UIs that we can take advantage of. So let's explore that. What do you mean?
Well, I look at different ways that we interact with programs already. And if you take a little inspiration from video folks, you have histograms. Like these guys are used to dealing with histograms for the colors.
So is there a world where we can deal with a histogram like experience for what we want as opposed to trying to really get into the minutiae in the words, because words aren't as easy to develop or as easy to tweak on that very small scale level. And then on the other hand, when we interact with humans, we're interacting at a very high bandwidth. And I'm sure you've been in a meeting where you end up diagramming things to get your point across.
When we are just restricted to text, we can't diagram anything. Yeah. And again, that brings us down in the bandwidth that we're able to convey to that LLM.
So potentially there's some kind of a whiteboard or it you can think of like your, your tablet that you're able to diagram with and it's recording your voice as you're talking to it. That could be a world. But at the end of the day, right now, what we're funneled into is the experience of just chat.
And then you're getting some inkling of when the chat bot will respond to you, it gives you these new UI elements. Right. So sometimes you'll get a scroll, sometimes you'll get a photo or you'll get a code snippet, some data visualization.
You get that, which is great. And I think that's the first step. But for us as input, we need to up the input levels.
Well, so I'm a little older than you. Yeah. I'm gonna guess.
But, uh, look, I'm a child of Star Trek, right? Yeah. Man, my whole life I wanted to be Scotty and just say hello computer, you know, and, and, and tell it what I want.
But I I I thought we were getting there, right? And then I realized in like doing videos like this, right? So I can't give the video to the AI and, and tell it do it.
You gotta transcript it and you would say, okay, transcripting is easy and it's word for word. And even if you, you know, fact, uh, uh, copy, edit the transcript to make sure it is you fact word for word, it's not enough. Because the way humans communicate, we communicate with our eyes, our eyebrows, our hands, nuances, tone in, in speech.
Yeah. Right. And our AI just aren't up to that yet.
No. So, I don't know. I mean, one of the, one of the things that really they say separated humans, let's say from Neanderthal or Dan No.
So the not Soviets or whatever that Uhhuh close relative of the Neanderthal is, is our, our, the, the, the depth of our communication. Even if we didn't have a huge big difference in vocabulary, all the nuances in human to human communication. And I think that is, that's a job that we need the AI to solve.
Yeah. We don't have that No. Anywhere near that, right?
No, no. And it's, you don't realize how important it is until you just look at a transcript. Yeah.
But there also is the whole idea of, I know there's probably people out there that are gonna be thinking, oh, well, voice is trying to tackle that problem. Voice AI is the next frontier. But I am not sure, have you played around with the voice tools?
It's not that they're bad, it's that us in a work setting, what am I gonna do? Go put myself in a cubicle when I wanna work and speak to my Yeah. Computer.
You know, it's funny you brought that up. So I met a guy I interviewed last week, and I'll give a shout out to him. This guy, Dr.
Allen Becker, his PhD is in voice to text. Text to voice and ai. He started a company, got sold to Snapchat.
He ran Snapchats text to voice for a while, but now he has a new company, I think it's called E Self, E Self ai. Check it out. When we're done for me, you can sign up for a free five instance thing.
They've developed avatars. Yeah. That look at you, that watch you and talk to you hooked into LLM in the backend.
And they do try to pick up nuance Yeah. From your voice and from your gestures. Mm-hmm.
It's early. I played with it. It's, it's freaky.
Right? It really is. It freaked me out, but it, you know, it's not perfect yet.
Yeah. But I'm, I am I'm bullish on, on that happening. Yeah.
But you still have this, it's like we're in meetings, right. And then we have to have a moment where we get work done. Right.
And so if the way that we have to get work done is by talking to our, It's still cumbersome. It is. Like we're in a meeting again.
Yeah. And that's exactly it. And really, whether you're talking to the computer or typing to the computer, there are people who type really quick.
Yeah. And a lot of people are really not good communicators verbally that Like me. Exactly.
That There are, I mean, that, that's an issue. That that's definitely, it's a big issue, you know. But let's, let's look at it from the other side of the coin.
Demetri, you know, the windows mouse clicking kind of interface that is dominant today. Look, this was like 1960s, early seventies out of the, the park. Yeah.
You know, Xerox Park out here, we haven't really, I mean, it's been 50 years. Yeah. And we haven't found a better mouse trap.
It's tired. It is time. You could see that with like the touch screens.
We have these gestures, you know, the pinch to zoom mm-hmm. The swipe. Mm-hmm.
And the other thing that I think is a big problem with us having to use chat and take what's in our mind and put it into a chatbot is how, right now we're very used to being fed things. It's almost like a passive experience. A lot of the time when we're on the internet.
And you can think about Netflix or when you're scrolling on Instagram or TikTok, these are passive experiences that we have become accustomed to. And now chatting is very active. Right.
We have to really define what we're looking for, what we want and put it into the chat bot. And so we don't have these passive gestures anymore when you're trying to work with chat either, which I find fascinating too. So is there a way to bring in these passive gestures into the chat experience?
Or I guess at a certain point, once it evolves outside of chat so much, we probably won't call it the chat experience, we'll call it just the AI and Communication experience. Yeah. So you're not trying to tell me we gotta get passive aggressive with our ais.
Do you? Are we? No, not that, not on our, I mean, you might see it.
You might See It, yeah. Better. I don't know.
I haven't tried. I'll tell you, one of my biggest things that I've had to teach myself is you don't have to be polite. You're only making it harder on them every time you say thank you and please.
And all of these things. Nice burning energy. Exactly.
I wanna turn a little bit Demetrius and, and talk a little bit about security. Right? So look, I, I think everyone agrees that we're all gonna have agents, digital workers, whatever you want to call 'em mm-hmm.
Who are gonna go off and do these tasks for us, whether it's booking flights, writing code, or, or what have you. And we're going to need either, we're gonna need a crap ton of agents, right? One, like almost an ephe ephemeral disposable agent for every task we do.
Or some sort of master agent that's able to clone small parts of itself to do specific tasks. Yeah. No matter how, no matter which way we go, there's security issues.
Yeah. How do you view that? Yeah.
There's a few different issues that I'm looking at. And these are like the most basic of the most basic. If we get some of these DevSecOps people in here, I'm sure they think about it on much different levels, but in a broad strokes way, if we have this world where we have a master agent that helps us go out and it's our gateway into the world, and it can use these tools, and it's a big if, because like I said, everybody wants to be an agent.
They don't wanna be a tool because you're giving up your distribution, you're giving up your relationship with your customer. If now Chachi, BT, or Gemini is what chooses to use you or not as a tool, that's a big vulnerability for your company. So that's a big if right there.
But if we do get to that point where I go to my LLM of choice and then I sink in with the tools that are out there on the internet. So Amazon is a tool. So buy something from Amazon can be many different types of tools.
Uh, look for something on Amazon, whatever, search Amazon. Now, are we okay with the context just flying around the internet? This data potentially sensitive data is now gonna be going to different tools and going to different LLMs.
And I'm not talking on the l are we okay with our data going to the LLM provider, but just data flying around the internet. That's one part that I think about. All right, well, we need to get the context and we need to have a way to securely do that.
It's not necessarily a new problem because we've been transporting data across the internet for a while now, but now it's a little bit different because there's agents that are interacting with each other and maybe one agent thinks this context isn't that personal. But then the other agent, when it summarizes it, it sees that, oh yeah, actually it will say something that is personal and you don't want that. Right?
So you have wild cards in each agent, agent tool call or subagent, whatever you wanna call it. And then next you have the authentication issues. So I want my agent to be able to understand everything about me.
That means it needs to look at my calendar, it needs to look at my Gmail, it needs to look in all of, everything that I'm privy to. It needs to be privy to in case it needs to act on my behalf. So you need to off into all these things, but it's not just OAuth because you then get to the next piece, which is the actions.
You don't wanna give it permission to take any kind of action. No. You wanna give it permission to take the action that you said was okay, not anything else.
Because if you give it a lot of scope, it can abuse its privileges. So I've been in, I didn't tell you this, I've been in security for 25, 30 years. You're only describing what I would say are innocent security issues on the agent.
That's true. True. What about when the bad guys say, oh, he's got an agent.
Let me exploit that. Well, did you hear what happened recently? There was I think some output from an LLM that had a nefarious link, and when the user clicked on that link, it then was able to take control of the system.
It happens all the time. And so yeah, you have, again, you have this wild card in there that the nefarious actors can hijack this agenda. They're Not dumb.
They're as smart as we are. They're well funded, well organized, and they, and that, that's the truth. And if you do end up having everyone as a tool for your master agent, how do you verify that this tool is okay to use?
Agreed. It's it, look, here's the good news. First of all, no one's gonna waste.
Everyone's running as fast as they can anyway. And they're gonna keep running as fast as they can. But as these things, and I, I've seen cycles before, right?
We never lead with security. We just don't. Yeah.
We, The sad thing. But it's True. It's a sad, but as a security person, you either gotta come to terms with that or, or you know, you're gonna be depressed.
Um, we will catch up, we will put the guardrails in, we will come up with processes around it, but people are gonna run as fast as they can. And, and, you know, you can't put your, you can't lay down in front of the tracks and say, stop the train. Yeah.
You get run over. Yeah. And, and so I always say it's more of a yes we can mm-hmm.
Kind of thing, right? Yes, we can. You wanna run as fast as you want?
Yes, you can. We'll figure it out. Yeah.
And I, and I think that if I had to leave us with one thing, that's what I'd leave it. Yes. We can.
We'll figure it out. But man, thanks for the work you do, Demetrius with you, this community. It sounds great, man.
We appreciate you. Thank you for presenting it Swamp up and for being here on Tech Drunk tv. Thanks everybody.
Alrighty. We're gonna take a break. We've got more swamp up coverage coming your way, so check it out.
Hi everyone. We're back here at our day two coverage of Swamp Up. Let me introduce you quickly to our next guest.
His name is Guy Levy. Guy, first of all, welcome to Tech Drunk tv. It's great to have you on here.
It's my pleasure. So I, I guy I give him your name, but share with the audience. What do you do at Jfr?
All Right. So I'm leading the architect's team in the city office of Jfr, meaning mainly focusing on the advanced technologies and something like beyond the border or beyond the horizon, kind of Next gen. Yeah.
Very cool. There was plenty of next gen stuff talked about here, but you know, for, for those of you who've never been at a, a Jfr Swamp Up, part of the mantra is we don't come here talking about what we're gonna do next year. Mm-hmm.
We come here showing you what we have ready now. So even though it was next gen, it was stuff that's ready now. Uh, you know, and we've tried to cover it, you know, in the last day and a half, two days here.
But Guy, what for you, what, what were some of the highlights? What were the big things that really you were excited to show? Alright, So there are a couple of those.
Uh, the first one, I think the Up trust, uh, capabilities and the ability to cover end-to-end, uh, uh, trust on the application business application level was one of a big thing, like tying everything together into one direction. And the second thing was around fly. Did you see that enough?
Yes, I was, I was sitting in the, in the, I was in the front row actually first table. So, and I, uh, I wrote about it a little bit, but we haven't really discussed it yet on the video here. Okay.
So, uh, fly is the first ever Argentic repository that will introduced to the market. Um, it's actually the next generation of how to support your argentic uh, development environment. How to support teams that are going iGen, AI first development, and want to have the right tooling in order to speed up their, uh, processes and to control it on a iGen AI pace of things.
Sure. You know, and, and again, for those maybe who are familiar with Jfr, right? Jfr was a company, the acorn that this oak tree grew into Exactly.
Was based on a repository, based on Artifactory, a repository for artifacts. And since that time, Jay Fe has started several repositories. Mm-hmm.
Uh, and Fly of course is the latest, but as far as I know, this is the first Agentic repository mm-hmm. That we've seen out here. Yeah.
So this is exactly why we are in the right position to introduce the next level and the next generation of repositories to the market. What we are doing is actually, it's not only the repository, the development, uh, uh, pace process way of doing things is changing due to ai. So people are using more and more agent co-generation, uh, technologies.
They can do more features per day, they can develop more, they can release more, they can generate more code, which means generating more artifacts and having multiple streams of artifact that are concurrently progressing in your project. And for that, you need a repository that can handle that and can support you in order to manage and store those artifacts, find them and deploy them at the pace that you are generating this code. Lovely.
Good, good, good. Um, now one of the questions I, so I, I tell you, we do a show every morning at Textron called Textron Gang, five six people pundits. And we talk about whatever we three, we always have three topics every day, whatever's big that day.
Mm-hmm. Today, one of the topics was Swamp Up because we had me and another one of our tech drunk people here. Mm-hmm.
And we talked briefly about fly a question that one of the other people on the panel had. Well, is this just for internally developed agents? Can I put third party agents in there?
Is Jfr, is it just for Jfr approved agents? You know, what kind of agents can I keep in fly? Alright, So Fly is actually an agent repository.
So it means that the repository itself is agent and doing stuff for you and supporting your development. And your development can be traditional features or agents or whatever you need. Now, uh, when producing code with agents, what we see, and this is something that we experience and I think it's becoming a trend in the industry, that the people are conductors of code.
They are not the writers of code. So we have people that are working in parallel on few features, couple of systems because they are conducting that they're not actually doing the work. And this creates like a big stream and flow of software that is being generated.
And in this kind of environment, you need to think differently about how you version, how you release, how you manage the process, how you control that uhhuh. Okay. So this kind of stream that is being expanded need a different method of managing This really is.
Yeah. Yeah. And this is exactly what Fly is Doing.
It's a hope different paradigm. It's a different paradigm. And we see, we see that we actually right fly with those methods.
So we are using that and we are experiencing That based on what it's like eating your own dog food or drinking your own champagne Better. Yeah. Champagne.
Yeah. Champagne is better. Yeah.
Uh, and now what, are people using it yet or no? So we just introduced and, uh, presented that, right? Yes.
We have, uh, some very, uh, small initial group of, uh, uh, users that, uh, that already use that. And there is a waiting list really. com and register to the waiting list.
We'll get the, the request and we'll enable more and more customers. I love it. I love it.
Um, so one, one of the, another question that came up on the gang today is, you know, we, we've seen the move from DevOps from point solutions to platform. Mm-hmm. Jfr platform, Of course, GitLab platform, this plat, uh, a harness, whatever.
There's all platforms and basically an organization picks what platform. There's some shops that are jfr shops, some that are this one, that one what have you. Are we going to see the same thing with agentic repositories?
You think other people will come out with a agentic repos and do they at some level begin to communicate, or is that you pick your repo and that's what you use? Mm, Interesting. Again, I, Yeah, we're guessing about the future, but the, the, I think that reality shows that there are multiple options and, you know, talking to our customers and serving our customers in this segment for the past 16 years, we know that there is a variety.
Okay? There's a, a more system, more adjacent system integration, sometime competition that is, uh, part of the customer ecosystem, uhhuh, that our systems are in. Okay?
So with that, I think is part of our, part of our platform of the J four platform. We have the two integrated to fail philosophy, and we are promoting those kind of integrations on the platform level. And of course this philosophy applies to fly as well.
So we do see additional adjacent systems that people are using. This is part of our investment to do those kinds of integration and to be prepared for the customer ecosystem because the customer need to have the choice. Absolutely.
Alright, excellent. Beyond Fly, what else was big for you here? So, as I talked about, uh, the UP trust uhhuh, I think that's, uh, uh, like a summary of announcement and functionality that we've been releasing to the market for the past two years.
Um, it now customers can see that the whole picture can now connect the dots and see how we as a platform can enable them to manage business level applications and connect them to the artifacts and the physical entities that they are managing. And doing that by controlling the flows, getting all the metadata that they need in order to manage, to understand, to triangulate, to debug, to roll back versions and everything under a single roof that is connected and trusted. And that's, that's, that's the dream, right?
Yes. That's, that's what we wanna go to. Yes.
And we can say that time and time again, those are kind of integrations that customers are doing themself, right? They are doing their, uh, own label, but piece fail. Yeah.
Their own scripts, internal systems and stuff that you need to work around in order to make it, to, to work in your environment. And now this kind of integration is, again, you create a system now you need to maintain it, fix it, upgrade it, upgrade the integrated system, and make sure that everything still works. And with our, uh, appt trusts and the integration that we already build it inside.
So ServiceNow, Sona, and the others that were presented, um, we do the work for you as a customer so you can trust us that it will work. And this is what we are doing with the leading vendors in this Area, this video as well. Yeah.
Yeah. Excellent guy. Thank you for coming on, man.
Thank you. I know you were, it's the first time you've been on with us, but yeah, very conversational. We appreciate Keep up the great work.
We'd love to hear more. We're gonna be watching us fly develops here. There will be more developments to come.
I'm sure. I'm sure. Check it out.
Jfr Fly the first Agentic repository. Go check that out. We're gonna take a break and we're gonna continue our day two coverage here at Jfr Swamp up in Napa.
You're watching Text on TV Software continues to eat the world. Is it eating your data center? Is it eating your infrastructure for AI in your data center?
Join us as we delve through the depths of your infrastructure and the depths of the history of the IT industry on this episode of the Tech Field Day podcast. Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about some key concept in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events.
Tech Field Day is part of this futurum group, and this podcast is also published on our sister company site Techstrong tv. On this episode, as we head into AI infrastructure field day, we'll be discussing how software is automating your AI data center infrastructure. Before the discussion, let's meet who's on the panel today.
Hello, I'm Gina Rosenthal and I'm from Austin. I run a product marketing agency. Hi, I'm Barton George.
I too am from Austin. Uh, I've been to the industry now for more decades than I'd like to admit, doing a whole bunch of different things and pretty excited to see what these, uh, these vendors have to, to say to us next week. And I'm Andy Banta, and I'm not in Austin, and I'm equally interested to hear what the vendors have to say to us next week and, uh, wanna learn quite a bit more about their products.
And I'm Alistair Cook. I'm the event lead here at Tech Field Day, the event lead for AI Infrastructure Field Day. I also am not in Austin.
Uh, but we did wanna talk a little bit about this theme that we are seeing in AI infrastructure Field day this week, where we have a lot of software companies who want to automate the platform that is your AI data center, uh, to automate the infrastructure, to automate the applications, to make it easier to deploy out new AI applications and, um, make sure all of the, the pieces underneath fit together. And it was a bit of a surprise because we thought AI was all about the GPUs, and yet we don't have Nvidia telling us about their, their, uh, GPUs in this. Is it really that software is eating the continuing to eat the world?
Is it eating the AI infrastructure world? Or is there still a requirement for some hardware somewhere? Well, I, uh, I introduced this topic simply because when I, I looked at the lineup for AI infrastructure field day three, I noticed that there were far more software vendors than there were hardware vendors.
And very traditionally, tech field day events have been lots of hardware vendors, especially ones that dealt with infrastructure, were lots of hardware vendors talking about the products that they had. And sometimes they would talk about the services that ran on their products, but almost always they were coming in to sell you some iron. I think that's at the bottom of the stack and, and where the value is is gonna come in the software space.
And I think that's something we've been seeing for a long time in a lot of different places. And it'd be very interesting to see how these companies talk about knitting it together, because I think there'll be a couple companies talking about specific product sets or specific offerings, but the, uh, the majority are, are talking about how everything fits together as a whole and how that coordinates with within your data center, whether that be hybrid, multi-cloud or physically, uh, in on-prem. Well, I think it's funny that you bring up in video the first place, right?
Because Nvidia can't run without a server. So it's not like it's this powerful thing, it's doing all the calculations and it, it makes the software that runs on AI to do all these calculations and do all the real work, um, go. Um, but you know, maybe we're in a space, maybe we're not seeing as many hardware vendors because we're in a space that the software has gotten ahead of the hardware again.
So what kind of, are we stuck with hardware that's legacy? And I know we're seeing a couple of legacy presenters, so it'll be interesting to hear what they say about that. You know, have they innovated anything with the hardware stack that, that the GPUs or whatever accelerator use has to plug into?
Or does it take software to do, uh, some tricks and, and things could all the bells and whistles that they really want the hardware have running those, um, algorithms and those workloads, I think we're like in a cat and mouth situation. And, and I, I agree with that. Uh, and I, we certainly need the software to make sure that the AI infrastructure works properly and that will always be the case.
But when you go back to, uh, pre AI days, there was always software that made the various different components work as well. And what I'm seeing for an awful lot of the AI infrastructure is people are trying to do it entirely with software on top of the legacy equipment like Gina was saying. And hopefully that will be enough to actually provide the infrastructure that AI needs.
But it seems to me that there's an awful lot of, uh, there's an awful lot of hardware improvements that could be coming along as well to feed the ai, uh, hunger. And we don't tend to hear a whole lot about it. Yeah, it'll be interesting, right?
Because if you think about that's is the fact that we're hearing from these companies trying to get at the data and it's really the data silos because if you look at an organization and you're trying to get to the different data to extract meaning from it, they could be on different storage systems, it could be on tape, they could be, the data could be all sorts of different places. So now you have to have a layer on top of the hardware that aggregates the data to make it faster or to make it appear like it's close enough to do the different calculations that need to be done so it doesn't take forever in a day. So it's kind of interesting, it's like, what, what are we waiting for?
Uh, are we waiting for Quantum on our side, on the hardware side to get there, to make all these things run? Or what will it, what's it's gonna take? And I think that's a, that's the whole idea of what do you have legacy?
You, you don't start greenfield with all of these. Uh, and I do think if you do make purpose built hardware for this, that's gonna be a big advantage. But it has to be introduced slowly.
It's not something very few companies have the, uh, the ability to just start the luxury being able to start from, from ground zero. Um, but it, it will be interesting to see what types of systems are going to be purpose built and how they will differ. Or is there really, if you have a common layer of compute, just sort of a, a bed of many, uh, distributed systems, will that be enough?
And you put the value on top. And then one of the thing I wanted to say was, Judy, you mentioned, uh, Nvidia and one of the big reasons why NVIDIA's successful is the programming language around it for developers of Cuda. And I think that's something that's been a huge advantage of theirs and something that, that being proprietary is something that they can use as a point of differentiation, uh, compared to other, other people say a MD who's now trying to, is taking the other side of it, which is, Hey, we have open source tools around this and they're sticking out that, that end of the market.
And I, I think that sort of cadence of where innovation is happening, where change is happening is, is one of the things that we do see through tech field is that the people who come and present at Tech Field, they want to show us something that's new, something that they've made a change to. Uh, and we tend to bias towards where the innovation is. I know last year we were seeing a huge amount of looking at network infrastructure and the design of the physical network infrastructure underneath.
Uh, Andy and I have, uh, have been at a number of tech field day events that are AI oriented that seem to be all about networking companies. And yet this year we're seeing less of that. We're seeing more of it being further up the stack and that it is software for orchestrating getting workloads out.
I think one of the things we're seeing is that transition from the idea that everybody is gonna be building foundational models and needs the infrastructure that you, you build this massive infrastructure you build for a foundational model or for doing some really advanced fine tuning using massive data sets. Uh, we're seeing this sort of transition into a more, uh, realistic view that we've gotta get financial value for what we're investing and we've gotta find ways of using the expensive and limited resource in an efficient way. And I think that's why we're seeing quite a lot of that shift in what's coming at AI infrastructure Field Day.
What I think we're gonna see is a, a collection of vendors who are gonna tell us how to make better use of the assets we're buying, rather than just saying, you, you gotta go, go pave the whole road over again with new infrastructure, which is got all of the latest GPUs and, uh, spend half a million dollars just to get to the proof of concept, um, spend $20 million to get to production. Well, companies are, particularly with the current financial, uh, climate and, um, but companies are, are questioning whether they can even do that. I think that's why we're seeing this move towards Productionization, Right?
And uh, I mean one of the things that we often see in many different parts of the technology world is that you, you build the software infrastructure to handle a specific problem. You need, in this case AI data centers and whatnot. And once there's a well established model on how to do that, many times there will be a hardware vendor that will chase that and come in and come and come up with specialized silicon to take care of the problem that you're currently doing with software in an effort to, uh, increase performance and give you better results all along.
I think one thing, one place where you are seeing a lot of the specialization, which we talked a little bit about before we kick this off, uh, is back at the silicon, right? So you've got, obviously you've got, um, GPUs from Nvidia, which actually were, were being done, used for something else, found out that they could be very, uh, very, they were very well suited to ai. And then that's, that has taken off a MD has got their versions, Intel didn't really take, get the memo, and as a result they're, they're not doing so well.
But you've also got smaller players like 10 tens torrent as well as grok where they've got these pus and there's NPUs and other things that I don't understand. But I can say, uh, and I think that's where people are saying, Hey, you don't, you got the CPU and that's appropriate for something this, you wanna use the GPU Oh. But if it's on your laptop, you want an NPU and to offload, and I forget, it's for which side is it you want to use, uh, LPU and you wanna use rocker a defense Torrance.
So I think at this point in so many of this, it's every anybody's game as far as uh, which way it will go and who will take, who will take root. And uh, it's gonna be pretty exciting to watch it to, to watch it unfold. It must be pretty nerve wracking though if you're running a business, right?
Because, because as these things go, what if the one you choose gets acquired? Or what if the one you choose isn't the, the one everybody else is chooses? So it goes down the wayside and, and you kind of go have to go that way or have to make a decision to, to bail.
So we're still in that kind of stage too, where since nobody, it's anybody's game, it's anybody's game. And we're gonna start seeing, I think lots of these companies being acquired, these ones that are doing software things, um, we'll see how it goes. Uh, I I think some of them might be acquired, uh, by potentially the, the exact same hardware vendors that I was talking about who were trying to chase that field to bring it up.
And, uh, going back to a previous AI infrastructure field day, uh, in Fabrica was one of the great examples of somebody who saw a problem with networking and decided to actually go generate silicon to do that. And it's entirely possible that some of the vendors we're talking to this week will be doing a similar approach. Yeah, it's interesting that the networking was the first thing that we started seeing, you know, everybody complained about, because if you can't move the data fast enough to become, to be worked on, then that's a problem.
So now all of a sudden we're looking at the infrastructure, it's like, okay, we can move it really fast, but uh, are the storage arrays working with us? Is it the location of the things? Is it working with us?
So now we're talking again about, you know, a little alert, you know, in that same low level of physical infrastructure trying to figure out what's going on. So yeah, it'll be, it'll be interesting. I think one of the, the key things, which is true in all new technology is lowering barriers to adoption.
How do you reduce that friction? And there's oftentimes where you've got a far superior technical solution, and yet it is so hard to set up or doesn't play nicely with what you already have. And to have to then take and choose something that's not as performant, and yet it's, you are able to actually install it and get it up and going.
I think that's a, that's a big thing. I mean, it's, what Docker did with containers is previously you had virtualization, uh, containers in the, in the form of things like BSD, jails, Solaris zones, and they were, they existed, but they didn't get beyond the high priests and priestesses. 'cause you had to be pretty darn smart to use those.
And then Docker comes along, and while it doesn't have all the functionality of what these, uh, what the predecessors did, it was something that people, uh, were as relatively easy to get up and going with. And as a result, it, it went everywhere. So it'll be interesting to see which ones of those will these easy to use solutions that maybe not as, uh, performing as the others take root and take over.
That's a really interesting point. But never forget the politics of all of this, right? The reason we have ethernet and not token ringing is because the guys that were developing ethernet hated IBM and they wanted to just destroy them.
So they did whatever they had to do to destroy them. And that's why we had ethernet. That's probably not the only reason, but, you know, it's one of the reasons.
Um, so it's also gonna depend on who's got the money and the runway and just the guts to, to be a little crazy and push something down on all of us, whether we won it or not. And then I think the other thing is, I think there's a lot of stuff going on, um, with the military, and I think it'll be really, really interesting to see because in times past that technology has trickled back down to all of us. So I think it'll be interesting to see if and when that's gonna trickle back into kind of like the commercial space.
If you, um, are as as old as, as my boldness. Uh, you'll remember the DARPA challenge, which was the first, uh, autonomous vehicles driving across the desert, uh, that led to what we have now of, of more autonomous vehicles not necessarily driving across the desert on purpose. Uh, so yeah, I think there's, there's an element.
The other thing that struck me that you're describing, uh, button was button what I would consider to be the iPhone effect. Um, I was using smartphones before iPhones existed, and they were pretty clunky to use and I certainly wouldn't have suggested that any other member of my family would use a smartphone. Um, then along comes the iPhone and the usability means that both my daughters and and my wife have iPhones and, uh, very happy with them.
And you know, that you cannot, cannot underestimate the ease of deployment, time to value, ease of use as you're building out a product. And, uh, we, we definitely see that as one of the vital differentiating factors for, for e and e product, any technology time to value. Although I'll say just in my previous point, I never had an iPhone because I hate at t hate them.
They give me dirty once along decades ago and I'll never use them again. So I didn't have, uh, a cell until Android really got going. 'cause I was not gonna ever sign up for anything with At&t ever again.
Yeah, there's one thing, well I have At&t, but I do have Android, so yeah, Okay. There's one vendor to cross off the Tfd list. You know, I think one thing, maybe It's just that, that we can't invite Gina to that.
Well, I was gonna say, you talked about politics, Gina, and I think the other thing is grassroots adoption. Uh, particularly when you talk about open source, you talk about developers, you have things like the lamp stack, uh, Linux, Apache, MySQL, and either PHP, Prolo, Python, whatever you wanna use the p for. But that wasn't something that somebody came in and said, Hey, we're gonna be using this in our data center.
It was something that the developers liked. It was easy to use. Uh, and Linux in general is another one that was, I worked at a company that had a, had an operating system called Soliris, and it was really big and beefy and powerful.
And yet the adoption was so much easier with Linux, it was free, you could take it and slowly but surely it went from what people thought was a hobbyist type of a, of an OS to something that is just everywhere today. And, and Soliris isn't. Um, so I say that's, uh, another one would be the, the rest API, how it took hold compared to soap and all the other things, which, uh, Jean, as you mentioned, you've got these big standard bodies and you had like Microsoft and IBM and all these people pushing it, and the developers said, I don't know, this is, this is, they have like a hundred page manuals and they just said, this is too much.
And they just started using rest API. So it, that will be another thing that comes up is what will the developers look to use? Well, yes, and I mean, of course developers always look for what is the easiest way to get this job done.
And many times this, uh, the, the developers will develop their own tools or enhance tools that are out there. And this goes back to one of the comments I made a little bit earlier, where lots of times the developers come up with, uh, algorithms or, uh, protocols or interfaces that later on, uh, hardware vendors will chase because they've become so easy to use that they, uh, that they now need some way of accelerating them. And that also kind of ties into what Alistair was saying with the, the idea of the iPhones to where when you make it simple, you you'll have more people using it.
And this is why we end up with some of the specialized TCP fun offload functions that we have on some networking equipment today. This is why we end up with specialized chips that will run Python or run Java, uh, rather than actually having to have a general purpose CPU that sits there and uses a, an interpreter or a compiler. And I think these are some of the innovations that have brought about the making what we call AI today possible.
Absolutely. And I think that's a really good point that you have, um, vendors that are gonna chase what's really the operations end of it. And to go back to Barton to your, your example with, um, UX and Soliris, I was working at an agency that was on SOIs, but the astrophysicist said, we got to make this run faster.
So it's really the beginnings of ai, right? We have to make this run faster and it's not gonna happen, gonna happen on a sun machine. We need to have X 86 and we need Lenox.
So we all learned Linux and we learned how to put our, um, our operations. I was a baby system minute this time too. So like we had learned how to put all of our operations so that everything was secure, it could be backed up all of the different hygiene that you need to do to protect everything could happen on Linux as well as it did on sun.
And um, that was a, a big exercise we did as an agency. But I think Andy, that's kind of what, um, some of the people that chase these ideas like, okay, it's obvious that these developers are, are forcing this and, and they see a good, a good amount of, um, value to running it their way. So how do, how do we make something that makes it easier for the operations team to protect it and to back it up and to do, to secure it, do all the things that needs to happen so that the developers can do their thing faster.
So I think it kind of all goes together, right? That's exactly true. And I mean, one of the, the big reasons why Solaris lost out is, uh, Intel could way outspend Sun Microsystems on doing chip development and could outrun the, um, the, the chip generations and, and outrun the speed that Sun Microsystems never could.
And, uh, I mean, Gina and I have both worked at VMware and we're very familiar with this as well, where when, when I started VMware, Microsoft was the one dictating Intel architectures to Intel. And by several years into the time I was spent, I had spent at VMware, VMware was dictating Intel to architectures to Intel. And this is very much a case of the hardware vendors recognizing who was adding value to their product and going to them for requirements rather than going to, uh, you know, their own think tanks or whoever they'd been previously gonna for requirements.
It's just an it, uh, something that reminds me of when I was at Sun, uh, seeing presentations about Spark will always be two times as performant as Intel. And as you see that, it, it, they went like this and Intel went up higher. 'cause as you're pointing out, that's all Intel did.
And they had a big installed base and Sun Chips were really powerful, but they just didn't have the, the financial ability to compete with somebody like that. Um, I I wanted to bring us back to the, the thought around the software vendors and the, the vendors that we have at AI infrastructure, uh, field Day this week, that they really are, uh, about bringing some of what Gene was talking about. So bringing more platform and control and production ready operation to the, the AI infrastructure.
And I think that's might be why we are seeing so many software vendors in here is that drive towards making this a, a consumable platform to enable the developers for, uh, as Andy says, for the developers to be easily able to build whatever feature they need and to, to deliver that as a standard service rather than some unique thing that was out in, in the corner, uh, and maybe was a bit of a white elephant because we knew we had to spend a lot of money on it. We just didn't know what it was gonna do for us. This is a distinction to make because an awful lot of the vendors that I think we're talking to this week are making things more, um, more accessible, uh, easier to use and easier to manage.
And at uh, the same time, I'm hoping that some of them are also working on the problem of feeding the beast because AI can consume way more data than an awful lot of, uh, various different software and hardware pieces can deliver. So I'm very interested to hear as much about feeding the Beast as I'm managing ai. I think one thing that I'm really looking forward to is what are they hearing from their customers?
Because we, you know, I, I listened to, this survey was done by MIT saying 95% of all, uh, enterprise AI projects fail, but that was a small sample size. I want to hear what these vendors are talking, uh, hearing from their customers when they go out, what's working, what's not working, what are their pain points, uh, and and what are the, the, the value that they're seeing because they hopefully they're out there talking every day to people that they're trying to sell to and, and getting a better idea of of what they need. I'm hoping to hear, um, all of that, but also I hope we hear from somebody that's doing something so innovative, right?
So we all know the problems people have in running these algorithms and trying to wrap their hands around it. Organizations are doing the all, all sorts of things. So yeah, this is great.
It's making it easier, it's making this and that, but where's the innovation? Like, are we gonna see someone that's got just a really innovative idea that changes the game for everybody? And that's, I hope we do.
That would be kind of cool. Well, as always, uh, we could have a great time talking about this for a lot longer and talking about the history of Sun and Intel, uh, and maybe even the future of, uh, well I guess it's Oracle and, and Intel, but we do need to bring this to a close. And, uh, I guess, uh, before we do close out, I just wanna make sure that people can connect with you both, uh, during this, uh, infrastructure field day event as well as ongoing.
Um, where can people continue this conversation? I'd say I'm mostly on LinkedIn. Um, although I have, I'm Barton George on LinkedIn or the URL, uh, yeah, the URL is Barton 8 0 8.
I have reluctantly gone back to Twitter 'cause there seems still be a lot of conversation there. And I'm Barton 8 0 8 there. I'm Jamie, almost everything.
You can find me under Gina Rosenthal on LinkedIn as well, but I'm on MAs on a bit, but definitely on Blue Sky And I'm Andy Banta, and while I still have a Twitter account, I don't pen tend to pay much attention to it. You can find me on Blue Sky at Andy Banta B Sky Social, and you can find me on LinkedIn. And if you wanna read content about the things that I hear and find interesting, you can find that at andy banta substack com.
And of course, you can find me Alistair Cook on your favorite social media platforms as Demi Tass nz for New Zealand where I live. Uh, you'll find me ly on Tech Field Day properties as well as across the Futurum group. So thank you very much for joining us for this episode of the Tech Field Day podcast.
If you enjoyed the discussion, please subscribe on YouTube or in your favorite podcast application. Drop us a like, uh, give us a nice review. Uh, this podcast was brought to you by Tech Field Day, the home of IT experts from across the enterprise and a part of the RUM group.
com/podcast or view us on Textron tv. Thanks for listening and we'll see you next week. Hey everyone, it's an AI agents kind of day.
You're watching Textron Gang. Hi everyone, happy Thursday. Welcome to Textron Gang.
We've got, uh, well, as I said in the outset, it's all about AI agents today. It's not just today, it seems like we're, it's about AI agents every day. Um, are they glorified API calls?
Are they truly intelligent? Unintelligent, I we didn't discuss it, I guess, but we're gonna look at AI agents from a couple of different angles today and we've got some great people to talk about it with. Let me introduce you to our gang for today.
Uh, we've got Jack Gold, always a pleasure to have Jack, our cyber reporter, Terry Robinson, all things cyber as well as all things, all things, uh, also cyber and AI and all things, all things is our friend Chris Blak. And joining me, our man in Silicon Valley, John Swartz, John's. Good to see you.
All right, gang, let's jump into it. Um, uh, Workday recently had, I guess it's their user conference out in the valley or in San Francisco. John you attended, you got an article on this.
They recently also hired my friend Gabe Monroy, who I, I he's been to Google and Microsoft, but I think he came over from Google this last time and, um, or maybe actually he was a digital ocean in between this gig. But anyway, they, they announced a lot going on there. And of course, Workday's, HR and stuff like that.
Give us the scoop, John, what's happening? Yeah, So when you said hr, those are the magic two letters, or not, not ai, but HR in this case. So Workday made a ton of announcements around agents, around a new platform, but, uh, basically it centers on HR and making it or automating it.
So all those tasks that you did are supposedly gonna be a lot simpler and easier, but you're gonna probably have to make a trade off in some sort of, of fashion in, in that this will be autonomous. You can't ask for it in the human element, but this idea is to strip it down and streamline the op the operation as much as possible. So Workday did three big things.
They announced some more new Workday Illuminate agents, which are specifically for hr, finance and industry applications. They announced something called Build they developer platform that lets customers and partners create share and scale AI power sold then ecosystem. And they announced the data cloud or data cloud, data infrastructure layer, TE organizations maximize their strategy and HR and finance data.
Um, they also announced a partnership with, with Microsoft. And, um, you know, to kind to summarize, I talked to a couple of folks there at the events, including the guy who runs Workday AI named Shane Luke. He's a young guy, really sharp guy.
And he told me that basically he acknowledged that employees as well as HR employees, understandably, are gonna be hesitant about using these tools because of data and privacy concerns as well as their job security in the, in the case of the employees. But that he kind of drops it or divides this tech, this, this, this crowd of employees and, and, um, customers into two crowds. There's the tech forward crowd, which is really excited about doing this.
And then there's the other crowd was just hesitant. So, um, in addition to him, I talked to one of the customers of Workday and, uh, he, he described their HR process, which sounded to me like a nightmare. You basically had to make calls or use email to do almost anything.
And at this point, uh, the idea is to simplify things to three steps or less. So on one hand this might be good for an employee, it might make it easier for an HR department. I think the trade off is that eventually the human is taken out of the equation, which I think could lead to other issues.
Yeah. And that's why we'll leave it in hand off the baton. Y all I think this is, this is the kind of thing, you know, as I look forward, you know, that drives me to using terms like inevitability curve, right?
We take HR is, so let's step all the way back. Hr. I, I've got a very good friend who's a founder of a very successful company, been 35 years in, and and he says that one of the points of failure was when they, they had to, uh, have an HR department because for all the good people working in hr, we all understand that it is this department that I'll, I'll stereotype and say, claims to love you until the day you fires you and is very polite as it walks out the door.
And it's this an artifact, I think, of the sort of digi digitization of business and people and so forth. It only goes so far, right? And, and so these semantic systems I'm always talking about HR is the perfect example.
You know, you should have inside your company a story, a semantics, uh, system that says, I run the company. I understand the humans who work here and and how to, how to handle them, how to handle their needs and capabilities and use and productivity. And we don't.
And if we stick AI in a clinical centralized, you know, immoral, unethical, un unfounded basis into these structures, it's gonna be as Orwell and, you know, just awful as you can imagine. But I don't think we will, right? I think we might try to, and we'll find out how awful that is, which will, back to the point that started this rant, curve us back to something more sane.
And I think the more sane structures are possible now, it's just we're pushing the limits of the old structure and this will break them. Yeah, I I think it's also imperative to think about it from the perspective of the first time you have a lawsuit, because you put h uh, uh, AI in your HR department, all of this stuff's gonna get ripped out in 13 seconds, right? And it's really a, a problem because most companies, most companies have their own kind of HR ecosystem going, right?
It's not just three people in an office somewhere. There's all kinds of stuff. There's tentacles throughout the total organization.
And how do you build an HR model that's individualized for each company? It's really tough to, it, it's possible, but it's also very expensive. It requires an awful lot of learning, an awful lot of data that most companies aren't gonna spend time putting in place.
The, the, the ROI of doing it is probably pretty low compared to putting, uh, compared to the ROI of putting AI into something like DevOps or security or, uh, you know, sales enablement, customer support, et cetera. So I'm not convinced that most companies are gonna adopt this very quickly. It's probably more appropriate for smaller companies where the HR department is, is probably smaller and has less stuff going on around it, but it's a real uphill battle to put this into some big company.
Uh, I'll, I'll, I'll, I'll bet you a, a lunch or something. I, but, or anybody that wants to win this one, I'll make a prediction anyways. I'll be held to this one three years from now.
I think what you're saying right now is absolutely true, but three years from now, it's gonna be really cheap and easy. And if you don't do it, your competitors will and they will just economically wipe you out. You know, running HR the way we have traditionally, um, small because we're doing this now, right?
Without getting it all that. But at the small business level, you're right. You can still take a small business and say you don't really do hr, but if you actually put a system in that understands there's humans here, you'll be more efficient and profitable.
Now, that'll take a couple years to regularize and scale out to large enterprises, but I think this is an evolutionary thing. Um, Scott, if you're still Trying to Do, we'll have to get back together in three years, Chris, to see if Well, there's a, there's a lunch writing on this. Yeah.
At Least, but that's right. That's big deals, right? A couple of beers probably.
I just put an alert in my calendar for you guys. Please do, Please do. So I, I, I got some thoughts.
First of all, I've always hated the term hr. Mm-hmm. It sounded so antiseptic.
Human resources. I always like the people department. 'cause really that's what it's about.
It's about dealing with people now, You know, I've worked for big companies. I've helped big build bigger companies and, and I've worked for a lot of startups and mostly tech strong, you know, has been a startup. I, I think until you get to a certain size, you really don't need an HR company, an hr, uh, department.
Right. And then I, I think the other thing is, you know, I, I've been a big believer in PEOs for tech companies for going on 20 years now. com, we went with TriNet and I, I've used Tri I've, I've used a lot of them, A DP, Insperity, and they all have pluses of minuses, but part of what they do is these sort of HR function, if you will, and they'll even sit in when you have to let someone go or something.
But that being said, it is something that lends itself to process and process heavy, process heavy, uh, uh, process heavy function, I think lends itself well to a agentic ai, right? Because that's what the agents are good for. If you have a very defined process, have at it.
But I, the thing about HR are people that is unique though, is you're still dealing people to people. And if it's so straightjacketed A to B2C to D with the agent, it doesn't account for people good. Chris, And it's funny you say that word because it all this, you know, uh, you ourselves an example little tiny startup, they were liquidity at the point right now where we had to do exactly this.
And it turns out the term we decided to use, you know, is people, you know, in our corporate repo, in our corporate structure file structure where we record people and uh, things and assets and all, everything we do, there's this a file structure that's called people under that are the people. And under each of the people are, what we are hoping is a structure that represents who they are as a person, which works for the company and everything else, but is actually really a human being. And as you, and as we say in all these different segments, AI is not running an LLM against a thing.
You know, it's structuring a system. It's tructure structuring a semantic system that includes all sorts of automation that's running in Linux and gig or whatever. You know, there's things that are happening in systems all the time, some of which are calling LLMs doing things, but it's the structure, you know, is it a semantic structure?
Does it make sense? And our view in, uh, this is both us as a company and the, and the open source, uh, civic ai, um, uh, approach is that systems should be semantic. And all that means is exactly what we're doing here.
They should, you should be able to say them out loud and make sense, right? You can't, you can't, you know, there are logical sentence you can put together that semantically make no sense at all. Right?
You know, the sky is blue because of hammers, semantic, you know, structurally makes sense. Semantically does not. We need to build technical systems and business systems that we can say out loud without, you know, sounding like we're nuts at some point.
The HR is the, is I, I think Alan, you and I at least agree in the entire corporate structure, is that's kind of thing where by the time you finish explaining, you disproven it, oh, we need this system to make sure that our people are more happy. And no, they're not. No, we don't.
It doesn't work. Yeah. I got the, I got the impression, oh, sorry Alan, I got the impression from, from, um, talking to the folks here and reading what this will do, that they're, I mean, they're not entirely certain how it's gonna work out.
I mean, they, they, they're anticipating a lot of pushback and back and forth, especially over things like medical benefits or, you know, payroll. And, and I mean, Terry, not to go too deep on this, but I mean, I think back to, I had a former employer where I had a, an operation for kidney stone removal, and they, they claimed it was a preexisting condition, and I had to fight them for weeks before I eventually got that, you know, I got them to pay. Um, so I, I just, I kind of foresee these type of, um, uh, uh, surprises cropping up.
And even the, the guy at, at workday, Shane, he acknowledged it. You know, I, I'm sorry. Go ahead, Terry.
Well, I was just gonna say, I mean, yeah, and some of the process stuff, I can see where this is useful, right? I also agree that maybe smaller companies, uh, don't need it. Although they need something like a TriNet or whatever they're, they're doing.
Because, um, I've, I've worked for places who I worked for, you know, a company that got taken over by another sort of smaller entity and they didn't have any kind of HR in place. And it was a disaster. I mean, it was, it was awful.
But, um, but yeah, this, and then maybe something that takes the bias outta some of the decisions that are made around h HR issues, you know, if you will, like John, like your, your kidney stem, which I share this with you, you know, that's alright. Uh, but, but with, with something like that where you don't have somebody sort of making maybe a biased decision, maybe it's just cut and dry. This is what we cover, this is what we don't, you know.
Well, I don't know. I mean, I don't know. I have a love-hate relationship with, with hr.
I find that I like a lot of HR people. I've worked with some very talented ones, but I've also found, you know, and it is a, a thing that you do learn that they are work for the company and not for you as a person working for the company. And it's kind of like the IRS has its own tax court.
You know, they make all the decisions about what goes on internally. I just, Yeah, but the, the problem, the problem with HR or the, the challenge with hr, I shouldn't say problem, but the challenge with HR is that problem, most companies are unique and people are unique, right? Yeah.
And so if you're putting everything into an AI agent that's going to be making the same decision, no matter whether it's John or Jack or Terry or Chris or Alan, that may not be the right decision either for the company or the individual. And that becomes the problem. How do you build an agent that is flexible enough to understand the differences that people need?
I mean, we're talking about humans here, whether it's a kidney stone, whether it's, I I, I don't know. Uh, you know, you, you've got a, a medical problem and you can only work, uh, four days a week in, in, in the office or something. There's lots of stuff that goes on with people, right?
And I, I'm really concerned that trying to build an agent, a unique agent for each company. 'cause for the most part, every company's gonna be unique, is gonna be a real challenge. Yeah.
Can be a unique agent for each, each company. And I think, I know we're sort of at time for this segment, but, but you know, it's, it's, you know, you know, a unique agent for each company is not the way to do it. You know?
But, you know, and again, we're actually as a company trying to lay this out right now, and I think the, the answer comes less down to whether it's an AI or a human, you know, person making the, the, the decision on things is whether the company understands the people that actually work there. So, you know, when we put assets together to do something, and again, we're very early, so maybe I'm wrong about all this, but I think we're have a structure that accounts for that. Or you don't just say, John, level one qualification slot project where you say John Kidney stone four days a week.
You know, you know, in, in a way that a company can hold that information respectfully as we do in our heads. We just don't write it down. But we get HR departments, we try to write it all down and they turn back into corporate, uh, machines anyway.
So Maybe the AI goes for the process stuff, but you have to build whatever your people department, your hr as the cultural part of that is really rests on, you know, the, the people and really understanding the culture of the, of the company. You know, so let me, that's where, that's where you need people. That's where you need, I mean, that's where you need people.
You can't just Let, let me, let me tie this up a bit and we'll segue to our next section, which is, and, and forget HR for a second. Forget the problems inherent in HR and people and what have you. The fact is, this is a case where we're seeing agentic AI move beyond software development, software testing, software deployment, which is where we spend a lot of our time and gives us a glimpse into the true impact that agen AI is gonna have up and down the entire corporate structure and the entire realm of of workers.
And whether you know, today it's hr, tomorrow it's sales, the next day it's finance and, and, you know, distribution operations and everything else. We're gonna come back and talk specifically about security agents. You're watching techron Gang Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey everyone, we're back here continuing our agentic AI Thursday, go figure. Um, next I think we're gonna turn the microscope or telescope or some sort of scope onto, uh, the security agents, the rise of security agents. So we're seeing multiple cyber companies rolling out agentic ai, you know, agents to do a, a bevy of different security task.
Terry, you, you've been following this one. What do, what do you, what do we got here? Okay, so I'm, uh, talk to you about a a t of things that, that we've been reporting.
Uh, first I'm just gonna say, it's amazing to me that AgTech ai, particularly in security, sort of went from this little twinkle maybe earlier in the year to something that's becoming more fulsome, um, and, and expansive. So we have a three stories. Uh, one is about CrowdStrike and, um, you know, they've already, they were already introducing like, um, uh, AI agents into like their sox, right?
Or into sox. And, uh, now they've expanded that or SOX workflows. Now they've, they've expanded that and, um, they've acquired Pan GA.
So that's an effort to secure AI applications. Um, lasso also, um, added an, uh, ent, uh, art, uh, ai, uh, service. And that, uh, is for securing AI applications.
I think we should talk about that, um, a little bit more, uh, in our discussion. And then, um, Eve security has also, um, applied AgTech AI to, um, observability and policy enforcement, uh, which I, I kind of think is interesting and maybe, um, a good place for, um, AI agents. I, I would like to, you know, discuss that a little bit more as well.
But, um, yeah, so we're suddenly seeing this flurry of activity, like it's become more accepted and maybe a must, a must do. Um, but I, when it comes to security, I'm, I'm always a little suspicious of having the, the fox guard in-house or some sort of what seems like self monitoring and regulation. I just don't, I I don't, I don't know how, I don't, I guess I don't trust, uh, AI inogen AI enough yet to, to feel comfortable with that.
The, the challenge in security though, and, and I see why so many people are trying to implement ai, the challenge in security is that it's such a broad need that very few companies have the resources to do it properly. I mean, you can get, how many negative hits do you get before you get a, a positive hit? And how do you go through all the negative hits to make sure that you don't have to act, uh, react to them.
So in, in that sense, what we're talking about is, is really volume enhancement. It's the ability to go through a lot of stuff that you just can't hire enough humans to do, uh, or may not even have the, the, the skillset. But Terry, you're right, um, you know, ai, it's gonna be an AI versus AI world, right?
The bad guys are gonna have AI as well. They're gonna have their own agents. So it's gonna be my agent against your agent, and who finds the, the hole that, uh, needs to be filled or, or can't be filled.
And, uh, how, how do I react to that? It, it's, it's gonna be a really difficult problem. And it gets worse when you start talking about security issues within ai.
Not just security issues in general, but, but holes in AI that need to be filled, that aren't filled. Uh, you know, we've all seen the stories about gr well, we won't go through that, but it's too depressing. But, but those are the kinds of things that are really of, of concern.
And, and if you're, if you're putting AI in charge of your security and it screws up, how do you even know? Well, how do you know that's the thing? How do you know it's screwed up?
And to what extent it's screwed up? Um, and then how do you keep it from perpetuating the screw ups, right? Um, through other things.
I, I had a, um, coffee yesterday with, uh, John Waters from Eye Counter. You guys know him. He used to be with Mandiant and he's got, and we discussed a, a lot of this stuff.
And of course, this is maybe the, the way everything is going, but there's gotta be some precautions here. Um, it's, It, it's interesting the last, the last segment we were talking about, HR and I were talking about security, and I always like security 'cause it's very serious, right? And it's not just, you know, uh, ones and zeros, but there's stakes and good guys and bad guys and critical infrastructure.
And, and, and you know, a lot of us, you know, in our careers get to work on, you know, work with actual conflict, you know, actual, actual warfare. Um, and, and the, the, the most important part of this is civics, right? And I was on this show earlier this year when I was mostly yelling at this stupid chat GBT and, and b******g about how terrible the industry was and bad the products are, which is true, but I was wrong about how bad they were in which directions.
However, um, it's, but, but all of our work, all the work we're doing now started with exactly AI for civics, you know, for critical global issues at the civics level, which is as meta as you want to get, as we all know, ones and zeros are, are easy and complex networks are fun, but actual human, individual, humans, groups, you know what, you know, civics is the most complicated realm. And I'm here to tell you, at least I got, I'll attest to this and I'll stand by it, that they're very, very good when applied at the civics level with all those stakes. So I'll go back to what I said earlier this year, which I think I've even said it live and I didn't, you know, I was just gonna say it out loud even though I wasn't sure about it.
But yeah, the way you fight AI is with ai, you know, e exact exactly like you just said, right? It's going to be, it is right now about the bad guy's, AI and the good guy's. Ai, if good guys don't want to use the ai, they will lose now, you know, all the flaws of the ai.
Yeah, yeah, yeah. Yep. Absolutely true.
However, pragmatically, if you're not using it for defense, you're gonna lose. You have six months maybe. Yeah.
Let's play thermonuclear war. I was thinking, I was thinking like a west, west world in a scenario where for all the positive things, what could go wrong? And it brings me back to the previous segment and Chris mentioned this.
You think about HR and your, their ambivalence and maybe some, some caution about use. Its use. And I think about security and I even be, the red alarms go off even more so until something horribly happens or goes to skew and which leads to lawsuits or some sort of damage or some sort of headlines.
So I think, I don't know, do you think maybe there might be these genic AI trailblazers you kind of learn early and kind of set a path for others? I mean, maybe they jump whole hog into HR and security and, and educate us way, let's Look at it a little bit differently, right? Let's look at it from the perspective of various vertical markets.
So if you are a bank, right, and you're putting security, ai security in place to secure your accounts, and it fails, people just lost a, a zillion dollars, right? Uh, you're gonna get sued and the feds are gonna come after you. And, and there's all kinds of, of bad ramifications.
If you were a, uh, you know, if you're a McDonald's and somebody gets a hamburger wrong order wrong, what's the worst thing that's gonna happen to you? Right? They're gonna redo the, the order.
Um, you're gonna go to, someone's gonna go to the counter and say, Hey, you, you screwed up. You put pickles on it. I I don't want it, onions or whatever.
Um, it's not such a big deal. So it really is not across the board. I think a lot of this age agentic AI stuff is gonna be vertical specific.
Mm-hmm. And for instance, banks are notoriously who did it first. I'm not gonna do it until someone else does.
It improves it, right? Uh, financial markets are like that. Uh, tech not so much.
Techs are trailblazers. They'll go off and just play with it because they can. Uh, so, uh, it, it's gonna be an interesting rollout for a lot of this technology, but I think it's gonna be very dependent on the verticals and how fast it actually gets rolled out.
It's okay. And the first time you have a real glitch, a real problem, it's going to, and a lot of these verticals is gonna get stopped in its tracks. You know, Jack, what you're describing is, is very much the crossing the chasm model.
Yeah. Right? You got 15% of the market that are early adopters.
In this case it's probably tech companies, and we're talking software development, deployment, stuff like that. Then you've got, you know, once you reach that early, uh, adopter model, then you gotta kind of cross the chasm into the mainstream. But that mainstream is not homogenous, right?
It, it's broken into strata. The, and if we, at a very basic level, there's two pieces of the mainstream. So about 35% of the market are early mainstream adopters.
They generally are the ones who, look, I saw the early adopters had some success. I'm willing to give this a try because I think my problems are so serious, and that if this thing works, I'm gonna come out way ahead. Right?
And that's about 35, about half of that mainstream market, 35% of market. The second half of the mainstream market are a little bit more cautious, conservative. They say, I'm not gonna adopt that until I see my peers already adopted it and have some success with it.
And if they don't have some success with it, I'm not adopting it. And that's the latter half of that mainstream market, again, about 35% of the market. So between them, that's 70%, you got 15% early adopters, right?
85%, that's critical mass. And then you got 15% of the are laggards who are never gonna adopt it, not anytime soon. Um, I, I think that's what you got here with AI in general, and especially with agent ai.
But we're, we're, we're, we're, we're specifically talking to security in this segment, though, right? You know, so I, I, I agree with, with both of you entirely on the, on the market adoption. I will say in this case, it's just literally true.
And I'll, I'll walk you through exactly what that means. If you're out there, you know, use AI right now to look at your security posture, you know, that could be done by anybody. You know, iteratively, you know, all the failures of weaknesses of these products.
Don't get you started. We don't have time. Just sit down if you have nothing else, uh, particularly if you can't access somebody who can show up on a show like this, which is 90% of companies out there, use AI to figure out where you are and to go all the, you know, all the way, uh, say in, in Jack, you know, to your points yet, yes.
You know, if you are critical and you're really, uh, implementing things and you're big and have the resources and capabilities, you know, you will be putting agent to a in, you will not be doing it. And the kind of ways that fail if it, you know, if one person or one AI agent is your weakness, that you've got a bad system, right? And there are ways to architect good systems where you can, can use agent AI and trust it enough to do the things that you trust humans enough to do things in those critical situations, which is quite often more than one human.
But, you know, that's, again, too much detail. So, but if you do not do these things in cybersecurity over the next six, 12 months, whatever market you're in, you are compromised. Absolutely.
That's just, that's the way the world is. I I can, Yeah. I'm a little more cynical too, though.
I think there's this group, and maybe they fall within those categories. You're talking about Alan, that do things strictly, uh, based on money and you know how much it's gonna cost 'em if they do or don't do mm-hmm. Something like that.
Mm-hmm. Sure. You know, and oh, why A TCO are huge.
Yeah. Well, I mean, the, the thing about security specifically though, is look, the bad guys are certainly using. Yep.
And, and so there is a little, I need this to do that. The eve security one I did interview, I think it's their CEO or CTO, and, you know, they just came outta stealth, basically Israeli cyber company. And they're, they're using, it's an interesting piece.
They're using AI to secure AI agent interactions. So, hey. Yeah.
And, and novel or somewhat novel approach. Anyway, we're about outta time for this segment. Let's come back to C block today.
Sticking with our agent AI theme. We'll talk a little bit about DevOps. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey, everyone.
We're back here. And, uh, our C block today is DevOps agents come this way. Right?
com. Uh, Joe Duffy, CEO, founder of Lummi. Uh, they've recently announced, uh, rolling out some AI agents that are specifically trained to automate infrastructure management.
Infrastructure is code stuff like this. Lummi iss a pretty well known player in the open source infrastructures code infrastructure management space. Um, a lot of people use the open source project.
It's kind of an, they have sort of an open course SA model as well. But, you know, the a the, the AI agent here is, is the new wrinkle to this. And, you know, if one says, look, if we're moving infrastructure management, if we're moving infrastructure, infrastructure is code, you know, an AI agent seems to make sense, it should be able to help manage that, right?
I, I mean, at some level, the infrastructure is code sort of movement, you know, going back to Puppet and Chef and Ansible and, and these products. It, it has a history, right? If we, if we could reduce our infrastructure to code, and therefore it's sort of repeatable, programmable, why wouldn't an AI agent make sense there?
Um, it's not like we're dealing with people in the HR issue. In other words, however, and and more power to Joe Duffy and the PMI people, they've done a good job over there. I think we're gonna run into the same reluctance though.
The same reluctance. And, and quite frankly, I think that reluctance raises its head in security as well, right? I, I had this with security automation when I, we tried to roll out from IDS to IPS and automated remediation and vulnerability management people, people aren't so cool to just let, let the machines go, right?
Yeah. This, this isn't quite the matrix yet, and we don't have Mr. Smith.
So Chris, now that I'm looking at you, you do look a little Mr. Smith ish. I don't know, maybe, maybe, maybe Chris, maybe Chris is an agent.
But, um, you know, but but kidding aside, I, I think what we're really, and, and this is, you know, we've been now through three segments of this, what we're really talking about is a question of trust. Yeah. Do we trust these AI agents to do the job we think they're going to do?
Go ahead, Mr. Smith. It's, I was thinking about the, like I said, the third segment today.
I am trying to think of a different way to say this. And y you the, the, the, I just had a great way to say it, and I've lost it and run. And we're on air, which is just lovely, but it's okay.
It's a semantic situation. It, we, we need to be able to say it. And if we say the story, the story is, like you said, we have an idea.
S you and I were there, right? Is there's snippers and so forth and say, Hey, we, they can stop things and we're gonna let them do it. I don't know.
We're used to things breaking all the buddy time. So the story that we're in leads us to the place where, you know, in our roles we're supposed to be, we're literally where, where's, you know, where where's the, the novelist among, among, amongst us, right? Because if you are writing stories about these sort of situations, the pe the characters playing our roles in this case would naturally be suspicious.
That's what we expect. And, and, but, but the, the narrative of, uh, ai, right? You know, and the last segment, this is what it was, and the last segment we we're saying, we're gonna use AI to, to save us from ai, which is really just a way of saying, we're gonna use technology to save us from technology, which is of course, you know, we, we say ai, like it's some thing, it's a terrible acronym in the first place.
It's neither artificial or intelligent. It's a large language model that processes data in semantic forms and produces results that are, that are metrical. And, and, and look, yes, there are analogies with humans.
They're not human. They're not going to be human. You know, we may get to all sorts of interesting Turing test levels now we're kind of at them, but it makes no bloody difference.
It's technology. We use technology to secure technology to develop technology. This technology is no different than hashtag cryptographic anything else.
And we need to get our, our heads away from a, from looking at it as something other than technology. It is another technology. You know, every time we say ai, we have Frankenstein and Skynet and popping our on our heads, and we can't bring ourselves to get through the meeting, to have the decision to develop or implement or take the next step.
Yeah. Because reality is the perception's reality. I'm sorry, go ahead, Jack.
I'm sorry. I I was gonna say, Chris, this one's a little different because technology in the past, uh, you know, we went from mainframes to many computers to PCs, to, to mobile phones. Those are all great technologies, very useful.
But at the end of the day, we were controlling them. The difference with AI is that we're letting AI control us. And, uh, to a large extent that, well wait a minute, but, but let me finish.
So to a large extent, the risk is much higher. I mean, technology versus technology, I get it. You know, we're using technology to try to fight, I dunno, ransomware as an example in security, right?
We're not being very successful at it. Um, it's getting better, but it's not, we're not there yet. And, and, you know, the bad guys are, are, are as good as the good guys are and using that technology for, for their purposes.
So, well, yeah. And, and 'cause they're spending more money doing it, and they're getting better people to do it. They're more innovative right now.
Yeah. Yeah. Yeah.
You also mentioned, it's interesting, Jack and Kristen, that there's this kind of whole debate about ai, whether we're in charge or it's in charge. And it even comes down to like some of the two biggest names. Put out a, a study earlier this week where philanthropic says that wholeheartedly AI's taking over our workplace while open a while.
Philanthropic says that while open ai, the flip side goes, no, no, no, no. It's, we're using it for our own personal use. So I i, reading between the lines, I understand why they came to those conclusions, which are also serving, but it feeds into this debate about this technology, which in a sense, there is like that, uh, wild card element to it in, in some, well, Exactly.
I mean, and in, in the past with technology too. I mean, I've been around a long time and have seen these things sort of spin out. There's been, it's been sort of more deliberate, right?
And, and mm-hmm. AI doesn't, and I could be wrong, but it doesn't feel deliberate. It feels like it.
And, and out of the gate, without the guardrails, before we know what it's doing, it's doing. And that's not the way tech necessarily worked in, in the past. There was a lot of deliberation.
There was a lot of thought behind, uh, some of these things and a lot of control over the environments we've got, you know, and, and maybe it's the way of the world. There's less control over development environments and everything else these days, they're, they're not the same as they used to be. I, I think in many ways, we think there was more control than there used to be.
And Jack, you know, to, to start with your, uh, perspective on this technology, as I look at it, you know, goes back thousands of years. I mean, this stuff in our lifetimes is fascinating. And, and the, you know, the, and the, and the risk is right.
You know, as we'll all agree risk right now for all this is maximum, couldn't get more as complicated as high stakes as you can possibly get. But it's not about, uh, what we're current, you know, this current LLM as such. It is about semantic structures and so forth.
And technology, as I look at it was, you know, we go back 10,000 years and 5,000 years ago, we really started building things, writing things down in co encoding things that had to exist in our heads as functional rules that literally, you know, come down to how physically big we'll build things where you can live, what you can do. Those are technology structures, you know, that our species have, has been developing all along. We're at this point right now where we've been able to, since the industrial revolution, mechanize, steampunk it, you know, digitize it and come up with analogs of functional systems that work really well.
You know, now, you know, it's, it's, I mean, I'm as surprised as anybody. I kind of expected the digital ai, we have semantic ai, you know, FML isn't that fascinating? It's actually using the structures we use in our brains, you know, to process information analogously to the way we do.
And we can't control it. Like we can, you know, steam in a boiler. It's a funny thing.
Let me, let me go back to my trust thing. And Chris, you said something and let me expand on that and bring that back to trust. And it goes to what Jack said as well, if you be, you could think the world's 6,000 years old, but let's assume it's not right that it's been around a little longer anyway.
And, and the fact of the matter is, homosapiens humans have been around, depending who you believe, two, 300,000 years, right? Was kind of the rise of, of the Homo sapien genius. Genius for if it was 300,000 years, for 290,000 of those years, we really didn't have much technological innovation.
We made a better arrowhead figured out how to use tar. Well, the fact is Homoerectus might have used fire, they're saying Yeah. Millions of years ago.
Yeah. Right? But yes, but, you know, so for, for 95% of our existence, we really didn't have sort of a technological revolution.
It was very, very spread out over tens of thousands of years. In the last 10,000 years, things have picked up a bit, starting with agriculture and, and, you know, move to villages and towns and loss of the hunter gatherer better weapons 'cause a good, you know, like it or not, one of the best indicators of human technological evolution is what weapons we make. Yep.
Go figure. And, you know, so for 10,000 years ago, you get agriculture 150, 200 years ago, you got the industrial revolution. And boy, things really pick up, really pick up, right?
Think about taking a caveman to 1890, my God, right? But now the digital age, let's call it the 60, 70 starts the era, the digital age, and then the nineties, the internet age, the 2020s, the AI age, that pace of innovation, that pace of change, that pace of revolution is exponentially faster, bigger than anything we've seen in the 300,000 years, 10,000 years, 200 years. Stuff is off the charts, right?
Behind ai, we've got, we've got, uh, quantum computing in the rear view mirror, and that's gonna be with ai. And there's so much change, so much revolutionary change coming so quickly that I think it's human nature to question it, to lack of trust. And, and so this, this change is coming quicker than we could get comfortable with it.
Right? And that's, that's exactly, that's my, that's my shimmy take for today. People like pro people like progress.
They embrace it eventually, you know, they love it. They rejected it first, and then they learn to love. Yeah.
They, they, right, they get comfortable with it. But we're going so fast before you can get comfortable. The next thing is here.
Well, but it's, I think you have a timeline. The end, the timeline, it's risk versus reward, right? Even on a personal level, I will adopt something if the, if the risk is less than the reward I get from it.
I mean, you know, uh, computers can be bad as well as good. I, I, I can't live without one today. Uh, my, my cell phone, my, my smartphone, you know, if you had told your grandparents that you've got this little thing in your pocket, you could be anywhere in the world and they can reach out to you and talk to you instantly, you know, they, they would've thought you were absolutely nuts.
You know? To your point, Alan, it's, it, it, mm-hmm. It's gone crazy.
I mean, even my parents, they wouldn't have, wouldn't believe it unless we had a, we had a phone in the house that was a party line. Who knows what a party line is saying. My grandmother had that Too.
Absolutely. Those are cool. What about, hey, this is a long distance call.
Don't stay on so long, right? Just like every other wish we, we get some announcement for an open AI or Gemini or philanthropic about here's a new advancement, you know, something that builds off of this and you can't even keep track of it. Yeah.
I mean, you're just trying to embrace what you have have. That's, that's really the issue. It's the pace of revolution.
I think we can keep track of it. And, and Alan, let me give you a timeline of semantic technology evolution and really begins about three and a half million years ago, Reis, you know, we, you know, use of tools, but really it's, it's the ability to pass down knowledge. You know, individuals may have done that long before that.
But three and a half million years ago, we started passing down knowledge, passing down narrative, right? Fi 50,000 years ago, we got so complicated, we started writing stories between us, right? And we, and that's the real, you know, you look at human anthropology, we, you know, that's pretty well documented.
And we got to 10,000, 5,000 years ago, and we gotten so complicated that we started writing it down instead of saying it to each other, not saying it face to face. And, and as I like to say, that's how we got ants, right? Since then, we've been trying to struggle with who gets to write it down.
How does it mean? How do I compare to, you know, beyond the personal relationship in small communities, so that when you look at the, the, you know, the, from the establishment of those canonical mimetic structures, you know, uh, in the early, you know, before, uh, a thousand, uh, you know, three, four or 5,000 years ago, the printing press, the internet, everything that's happened a hundred years, it's just an acceleration of that same slope. But the tools of mechanisms are the same.
The semantic structures have been, we've been developing for about three and a half million years. So we can engineer this to a certain extent and understand that, you know, semantics, you know, word processes actually lead to outcomes. And if nothing else, ais are helping us look at how we think and how we make decisions.
And, and, and to my point about civics, how we actually interact, you know, us incredibly dangerous individual. But you know what's interesting? You, you're talking about semantics, but you are leaving out a human element.
You still haven't addressed the trust issue. Well, it's semantics is how we develop trust. I mean, that is literally, you know, the, the Too fast for trust.
There's another piece to this, guys. Let me, let me try a little bit, uh, a little bit different. So I'm the, the CEO of, of a company, right?
And Alan, you come to me and say, I need a budget to deploy ai. And, and I look at you and say, Alan, you were here six months ago where you, you needed a budget to deploy this other thing, you know, before ai. And six months before that, you came to me for a budget to deploy this other thing.
Well, that's what SSOs do Well, right? But none of those are even deployed yet. And now you want something new.
But, and that is, that, that's part of it too, guys. I'm looking at my watch though. We're way over.
I apologize. We gotta, we gotta, we could talk about this, obviously for the next 300,000 years, Chris, we Probably will Uhhuh, Maybe this whole thing is a simulation. And we are in the matrix and controlled by ais.
Wow. But we're gonna take, we're gonna take a break. We're gonna come back tomorrow.
We'll continue our discussions on the gang as we do stay tuned for Tech Drunk TV following this. As usual. We've got a great stuff.
Jack, Chris, Terry, John, thank you very much for, uh, coming on. I think we'll have Mr. Vard back tomorrow, so, you know, we'll see how the Yankees are doing.
But until then, on behalf of everyone here night, yeah. Yep. This is Alan Shimmel for Techstrong.
We're out. Hey everyone. Welcome back here to Techstrong tv.
Uh, you know, I love introducing you to new companies and people who we haven't had on before. So let me introduce you to our latest find, um, company's name is Eve Security, like in Adam and Eve. And if you look at their logo, the Eve sort of looks a little bit like an Apple.
Um, and on behalf of Eve's security, we're happy to have Nadav Kornberg. Nadav is the, uh, co-founder and CEO at Eve. Nadav, welcome to Techstrong tv.
It's great to have you on. Great to be here. Thank you, Alan.
So before we get into Eve, let's hear about Nadav. How did you come here? Go ahead.
Um, I'll start on like half Israeli, half British, which I think equals in Australia in some ways. I've been in technology and product for the last 20 years. Uh, started in security from RSA and Checkpoint.
Had the privilege to kind of be on the endpoint side when it was growing at Checkpoint, and really saw how you're taking an idea, excuse me, a small group of people and kind of growing something into a product that's then been sold to, you know, many, many companies and having a big impact. And, you know, as I moved on and I even moved to different industries, a gaming hospitality in my previous startup, uh, was in the hospitality space, but it was always the same drive from that origin, which was, we're solving a real problem, you know, now how do we make that into a product? Start small, grow that, you know, nurture it, see how it grows, build it up.
And that's always kind of been a drive of mine as well, to kind of in that inter kind of world of being able to build something, understanding true problems. And I've always had affinity as well, that kind of trying to understand operational pains and problems, and then transforming that into automation products, and then see how that is deployed in the, in the real world. So, you know, from there, uh, kind of February, March, you know, obviously AI is, you know, not new from the last year, but you were starting to see the real problems and pain points that, uh, organizations were starting to face, even my previous organization.
How do we start handling AI and organizations? One of the new challenges. And when we identified the gaps with the existing solutions and how to handle those problems, you know, I got, I had the privilege to meet my other two co-founders through mutual friends, and we really clicked together.
We all kind of thought and believed that that problem is just gonna grow and grow in, in today's dynamics of how AI agents are really evolving in organizations, brought us to kind of found Eve and start tackling the problem of how agents are managed governed in organizations, in areas that matter. Absolutely. I love it.
So I gotta go the, the Australian thing. You got me going with that. You, you didn't spend time in Australia or anything?
No, no, no. Just in the UK for five years. And then in Israel for a majority of My, I I could hear sort of that Australian thing going on there, though.
Um, so, you know, look, I, I don't have to tell you everybody, everybody is on the AI kind of bandwagon, or at least in the tech world. I think it's gonna go through all over. What about, let's start with this Eve security.
Let's, let's frame it for people who maybe didn't catch it as part of the whole thing. What is the problem Eve security is looking to solve? So when we were talking to, uh, more than 30 CISOs, the, the kind of the broken record that you were hearing again and again was people are asking me to deploy these AI agents and put them in the organizations.
What's concerning me is what happens when I start connecting them to critical systems? Okay. And, uh, and the joke was, okay, if it connects to GrubHub and orders 20 sandwiches, eh, okay, it's not a big deal.
But if it accidentally connects to a critical system like GitHub or NetSuite or Salesforce, Atlassian suite and starts messing around with those systems and you know, and can perform actions and not just read data, that could be really devastating for an organization. So really we saw the emphasis was what could the agents do with critical systems? And the terminology of, we want another set of eyes, we want to put them in a box, we want to police them.
And the tools that they have today don't allow them to do so because the protocol, which is now the English language, is just so different of what we've seen before. So they're facing this massive push from top grassroots department heads, all want to now achieve their business objectives, believing that AI is gonna be the force to do so. 'cause all of their competitors are doing so.
And now the poor CISO now is stuck in between. Well, it's gonna be a, you know, on me if our systems get compromised because of that. Yeah.
Well, today it's on the ciso. What's gonna be interesting is if these things don't work is intended, someone's, someone's head's gonna roll, right? I, I was out at a conference last week out in, uh, Napa for a company called Jfr.
And uh, they had some data, I think it was from Gartner, 40%, 40% of CIOs are increasing their budgets because their board, their board is pressuring them to do more AI agendas and stuff like this. And so the gold rush is in, right? The headlong rush into doing these is in, and, and look, I've been in security 25, 30 years myself, unfortunately, very few times in all those years has I, have, I seen something where people say, wait a second, what about the security?
Right? No, they, they dive in the pool and then figure out if there's water in it or not. Um, and this is probably no different, unfortunately.
So what did you develop here at Eve to, to solve this problem? So when, when we were looking now at the problem, uh, and as this is being developed and the adoption is, is kind of growing in organizations, we understood we had to provide three key components. The first one is observability.
We need to give eyes on what's happening and in the most deep manner possible. And we categorize in, let's say four main questions. What agents do I have in my organization?
Who are they talking to? Which assets are they talking to? What are they saying?
What are the requests? What are the responses that are coming back? And even to the depth of why are they saying that integrating with even the platforms that those agents were built on top of to understand the reasoning.
Why did they even attempt to make that request? The reason for that is if we can give that, give that in depth observability and understanding of what we call intent and the data that's being requested, we can then put a layer on top of that of policy enforcement. 'cause they truly understand what the agent is doing and I can truly understand what the organization is asking for them to do and not to do.
And then I can police that. And now one of the feedbacks that we received as well from CSOs World, world, don't gimme a platform now that's gonna give me 5,000 alerts a day. I can't manage that.
Which then brought us to the perspective of, well, we saw some of our competitors mentioning agent, a human in the loop. Just put a human in the loop. Just add, that's not gonna skip.
So we built our first agent in the loop, which basically means we have an agent security engineer, basically, that is looking at all the events that are raised from the platform and then handling what we call the low risk or medium risk events based on their ability to interrogate the agent and what they're doing. So if they understand the risk and they understand the reason, we can make a decision. And just like any employee in organization, if I see a high risk item and I can't justify it, I'm gonna escalate it to my manager.
So if we can curate those very, you know, small amount or really critical events, that's when we generate value for that, uh, security organization. So, and the component that our agent in Loop is built on top of is we can understand anomalies, which are new behaviors or repeated block behaviors that are impacting business continuity. We can understand the risk of the operation and we can understand the justification of why they're trying to perform that.
And with those calculations, that's how we can automate the process. And then the value that we generate for organizations are, they can have a full understanding of what's going on. They can police the activity with minimum overhead and minimum impact to business continuity.
Excellent. You know, as I look at this problem, one of the things, I don't wanna say it's unique 'cause it's, it's, it's probably more analogous to APIs, but your AI agent can be dealing with so many external and third party APIs, other agents, you know, interactions that it, it becomes, it's hard to police that, right? It's hard to enforce that kind of, you know, I guess you start with like a zero trust and build it up from there.
But it, it, you know, it's, it's sticky. These agents are sticky and that they can, you know, and now you got a to a protocol with the Linux Foundation and the MCP servers and, and all of these things, how, you know, it seems like a big job. It's, it's definitely a big job.
And I'll say that at the end. Um, the way that we built it is you have components, what we call sensors. There are feeding information to us MCPA two A and every API at the end is gonna be a data source for us to understand how these agents are behaving and what they're doing.
It's gonna be our job to normalize that and then be able to make a decision on that activity. Now we're giving two options for companies and we call those critical systems crown jewels. 'cause we consider them like to be the crown jewels of an organization.
And that's what we want to protect is those critical crown jewels. Now we'll have an option to say, do you want us to detect and response, meaning that the, the action has happened, but we can now still see its impact, what it's done, and give you an alert to handle that. Or we can give you, even give your abilities or block.
Like we will actually sit in line and we've seen organizations now being open to both. It very much depends on the crown jewel. There are gonna be very critical systems that they are gonna be very concerned about different types of activities they can have there and they really want to lock things down.
On the other hand, it has impact for business continuity and other areas they want to detect and response saying, I wonder after the fact, if something happens and I wanna be able to address it, our agent in the loop as well can adapt policies based on behaviors and say, we've been too strict here. We should open it up. We've been too open here.
We need to strict it down. So that adaptive continuous improvement is something as well that our platform provides. But yes, the complexity of what we're dealing now with MCP APIs and A two A is still a necessity for organizations now to resolve.
They need companies like us now to step up and provide solutions for these new protocols due to the, again, forcing function of adoption. I love it. Very cool.
Nadal, I, I gotta spend a little time nuts and bolts for people who want to get more information about Eve's security. Where do they go? security.
They'll be able to go eve, Do security, EVE, do security. Hey. Exactly.
And Do you have any kind of, uh, free trial, free product, something to get people started? Yeah, de definitely. We've got now not only a design partner program, but a beta program as well that we have, that we work together with companies Now.
Our focus now as things are evolving are really to make sure that we're solving and providing value for the pain points they're experiencing. So very much we're working very closely now with all of our design partners and beta partners to ensure that, and what we're hearing from them is like, great, you know what I mean? Like, yes.
You know, thank you. Like when we, because we always start our conversation about talking about the problem and if they're facing it, 'cause we like to mm-hmm. Classify the success that we can have of our customers, or we wanna make sure we're investing our time with companies that are truly gonna benefit from our solution.
So when we do that type of vetting and we talk about the problems, they're very much like, yes, that's exactly what we're facing now. And we need help in that area. You know, we didn't mention, you guys recently announced a $3 million seed round.
True, I guess first money in and um, so it sounds like the product's still in beta. When do you think it'll go gp? Listen, I think it's, what I'm looking for is, is I would say I'm looking for multiple success stories that we have with customers to kind of pull that trigger.
I believe that's gonna happen in the next eight to 10 weeks as we're now working ready with customers and we're receiving feedback and we're going through that. But, uh, at the end of the day, you get you kind of, that, that gets answered to you by your customers. They're like, yeah, being super happy to reference about our experience.
Well this is solving so many pain points for us. Like, you know what I mean? Like, how can we expand now too?
Those are gonna be what I've seen just in the past, the driving points for me to understand guys. Yeah, we, I feel confident now of our product market fit that we've proven enough. Agreed.
Very cool. Nadav, I wish you a lot of luck, you and the whole team there at Eve Security. You know what, I'm going to hold your feet to the fire on this.
I expect to see you back here in about eight weeks talking about general availability and, and what the customer reference customers are saying. Okay, pleasure. Alright.
It's a great conversation, a great idea. The do kornberg co-founder CEO of Eve security here. Ont Techron, stay tuned.
We're gonna take a break. We'll be back with more. Hey guys, thanks for the throw.
We're here with Ron Zaius, who CEO for Iron Wall. And we're having a little chat about, well, why are the bad guys harvesting all our data, even if it's encrypted. Ron, welcome to the show.
Uh, pleasure to be here, Mike. I really do appreciate it. And you know, it's, it's everybody nowadays who's out there collecting your information.
It's, uh, you know, we're highlighting some of these foreign apps, but they're not too different from the domestic ones either. It's true. It's hard to distinguish the good guys and the bad guys and what they're up to.
Um, let me put this this way to you though. I mean, are we just being too cavalier about this? And we're not protecting that data because we're not seeing where it's gotta be used in some illicit fashion?
I mean, as part of this, we just don't have the visibility we need into this whole motion. I, I believe that to a point. And, you know, I come from a psychology background, so just let me use a metaphor here.
You know, you have Pavlov's dogs, you have the food, you ring the bell eventually because they happen, right? Immediately you put those two things together, that is not only canine behavior, that's human behavior. If you separate, if you ring the bell two hours before the food or one hour or you change it, then all of a sudden it's harder for us to connect those two.
What we don't see when we're using apps is, number one, how much information we're giving 'em, and then what the repercussions of that is. It's number one that, that information's being sold. Number two, that those companies tend to be very careless with that information.
They get hacked and that information gets out there. And the repercussions we see from being scammed, from having identity theft, from having, you know, our companies ransomware, we don't put it together because it doesn't happen immediately after you've given that information. That's what makes us so cavalier in my opinion.
Right. It seems like there's two vectors that people are talking about, at least most. One is, uh, data's being collected by, you know, with good intention, at least by various AI companies, but they don't have much regard for how they actually collected it.
And they may be pulling sensitive data that's gonna show up in some sort of AI output a year or, or so from now that could be potentially embarrassing. Is that kind of the first, uh, most immediate concern that we have? I, I think that's a big concern.
I mean, just look at it from a business perspective. I go on and I want chat, GBT, I'm just pointing them out there, you know, all the LLMs are pretty similar on this, but let's say I put, Hey, here's a document with all of my customers on it. Help me sort and analyze that, or they're gonna suck that information in.
They're gonna give me back what I want. But in addition, they're gonna keep that information. And, and we've done this, we've gone into some of the LLMs and AI and said, who are the customers of our competitors?
And in some cases it spit out some pretty sensitive information because they have put that in that information in, and now we're harvesting that to get it out. That is definitely a big concern on how careless we are about our own information about how careless companies are with when they process it. And again, not understanding how much information is being collected.
Not because the companies need it, but because they can monetize it. And that's where we become the product. And because it's almost free to these companies, I don't think they're very careful with what they do with it, in my opinion.
Yeah. And the second use case is a little farther out there, but it seems like nation states are also just starting to collect all the data they can find in the hopes of throwing some quantum computing at it someday. But, uh, is there likely to be, you know, an event three, four or five years from now that might embarrass somebody because sensitive data that they thought was encrypted maybe not so much?
Well, and I think we're already seeing that. I, I think zero day has already happened and it's just getting worse. Uh, and, and you know, government's looking at it, it's not just obvious that foreign actors are collecting this information and using it.
If you think about what war might look like in, in two years or five years, you know, there are certain nations that you are not going to attack militarily because they have nuclear weapons or because they're very strong or whatever the case may be. The idea would be that if you were going to destabilize and you destabilize their infrastructure, imagine that your power grid goes down. Imagine that, you know, hospitals can't handle the wounded can't take care of six.
Imagine that you are able to bring down the pillars, let's say in the US social security. If social security failed tomorrow and couldn't process checks, you can imagine the turmoil that that would build into a company, into a country. And because of that, that's almost as effect as effective as bringing military into destabilizing them.
All of those scenarios can be accomplished by getting your information, being able to get into those organizations, being able to ransomware them, lock them down, put in spy. All of that can happen with the information that's out there. And it can happen today.
And if you look at how governments are using it, it's not just foreign governments. Our government buys travel information on every trip being taken to, to see and to use for their own, uh, uh, their own auspices. Our government is buying, you know, paragon to, to, to go in and, and find and be able to break into phones.
And all governments are out there doing this. The more information you have given, the more information you have out there, the more of a target you become, or the company that you work with or the organization that you work for, becomes, this is real day and it's today. I think when I talk to cybersecurity folks, they kind of get the issue and they're concerned about it, but you go talk to business leaders or even the average employee and they'll give you kind of what feels like a collective shrunk.
'cause they're like, well, I'm not kind of feeling that pain right now. And they don't believe that whatever they're doing today will be of any interest to anybody tomorrow anyway. But how wrong can they be?
They, you know, and I, and I think so, and, and you know, it's funny because when we talked to companies, and I'll zero in on companies specifically five years ago when we talked to them about executives protecting their private information, they were like, you know, I'm an executive. I need to be out there today because of shootings, because of attacks against executives. They're very, very sensitive about it.
When we talked to them about protecting the private information of their employees, they're exactly where you are, where they're kind of shrugging and saying, do I, you know, it's just one more cost, but the numbers are really pushing in that way. Number one, 70% of ransomware attacks that have happened over the last three years have not been directed at the servers to begin with. They're directed at individuals within the organization.
And by being able to do that, by compromising your phone, I can get to your company's phone by compromising your home computer. I can, you're eventually gonna use it to get email you're eventually gonna use to get something else. And even if I don't get into the network, if I can compromise your email, I can send out messages to other people in your company and it's gonna come from you.
So there's gonna have a lot more authority. All of that is built because of personal information. The only reason these type of phishing attacks work to get us in is because there's so personal that we forget to look at the email address.
Or even if we look at the email address, it kind of makes sense because the email looks like it's coming from my brother-in-law. The content looks like it's coming from my brother-in-law or from my, you know, from my boss or from my subordinate. All of that is because of personal information.
I think companies are slowly waking up to the fact that you can have all the best firewalls in your, in your company, but your weak link are the people who work there. And if they're compromised, it's only a matter of time before you're compromised. It also feels like the efforts to get that data will become a little more sophisticated, at least have, from the bad guys perspective.
We see things like digital fakes and all this other stuff, but almost like the end game isn't to steal the data as much as it is just to carry, create some sort of bogus process that allows them then and gain access to that data. And the transaction may never be complete, but you know, it's just a massive data fishing expedition. It it is not a football game, it is a chess game.
Mm-hmm. It is moving all your pieces into place so that when you're ready to attack the king, as it were, you're gonna have everything in place to be able to do this. This is a long game.
It, it can be used to influence, it can be used to, you know, to get people to get very angry about things. It can be used to destabilize key industries and key parts. It can be used to cost financial turmoil.
It can be used just to understand your enemy or the people you're going after or the people who have the money much better. But it all comes down to data. I mean, 20 years ago, companies gathered information about you to know you as your customer.
If I know their birthday, if I know, you know what kind of car they like to drive, I can sell them more. That's not what data is being used for. It's not being used to understand you more.
It's being used to exploit you, to influence you, and to be able to also understand all the pieces of society that you touch. And giving them an open door to say, because I know more about you than your parents know, or than your spouse knows, or than your child knows, I can influence you and affect what you do much better than anything else. And with ai, I can do that at scale with large pieces of data and I can affect 10 million, 50 million, a hundred million people at one time.
And that's something we've never been able to do before. Is this kind of, in some ways the natural outgrowth of what we saw with social media where they're using algorithms to kinda collect data and analyze it and, you know, magically you're just talking about something next to your phone and it shows up in your social media feed as a topic. But is this kind of just taking that concept up to several orders of magnitude higher?
Yes. And again, it's AI that allows you to do that because before we were looking for the factors that we knew. I mean, so simplest thing in social media, you know, I, I have friends who are, who are judges and we protect government officials, judges among them.
So we have a, a, a judge and I say that you have, you know, Siri or Alexa and it doesn't matter which one you have, but we say things like that. You don't think it's listening all the time, just stay to it one day. I really like strawberries, I'd like to do more with strawberries.
And then magically you're gonna start seeing strawberry ads appear on your television, appear on your, you know, on your, uh, streaming service appear on your computer, on your phone. Well, obviously those are related, but that's also a one-to-one. What what AI allows us to do is to say, because you like green shirts, because you wear glasses, because you comb your hair a certain way politically, you're probably this, the leap from one to another is so huge that humans don't normally make those connections, but AI can.
And then when you join that with generative ai and you bring that together to say, now I can develop something that's going to exploit that and I can do it at scale. That's where the social media companies have, like you said, 5, 6, 7 orders of magnitude greater is what's happening today. Because, and by the way, it's not just for money, it's for lots of other geopolitical, obviously economic, but also socio, uh, reasons that they're trying to do this.
This is going to have more of an effect on everybody's life, then they understand. And then taking it back to what we were talking about with the applications to begin with these applications, you can tell how important it is to 'em when, when TikTok is collecting 27 pieces of information that have nothing to do with interacting with, with TikTok, that needs to tell you that they're, that they want those 27 pieces. And the reason they want those 27 pieces is because they need them to understand everything about you, Mike, and how to influence and change your life.
Hmm. So what are we supposed to do about all this? What can we do?
I think a lot of people at this point feel somewhat helpless. So my recommendation is get rid of ball, electricity, you know, put a tenfold in. Uh, and I must say I'm probably not too far from that, but, uh, you know, there are lots of, of common sense things you can do.
So a, a, a couple, you know, three things that I tell everybody. Number one is don't be the product. There's no reason these companies pull a lot of information from you, but a lot of times they're asking the information.
Don't give a company any piece of information that they don't need to give you whatever the product is you want. If you don't need my address, if I'm only gonna be dealing with you online, if I'm gonna be watching TikTok, they, I don't need to give you my address. I don't even need to give you my real name.
I don't need to give you my age. I don't need to give you anything that ties to I I don't need to make the connection with my Facebook page or with my LinkedIn. If they don't need it for the product, don't give it to 'em.
And if they require it, why? There's no reason. And you should never, ever give anybody your mobile number because your mobile number is the key.
You probably have moved Mike more often than you've changed your mobile number. So think about that. So number one, your mobile number is gold.
Treat it like a credit card number, treat it like a social security number. Do not give out your mobile number. Do not give people information that they, that they don't need to do your product.
It's okay to lie. There's no reason for these companies to have it. The second thing I always say is use A VPN and caveat, my company is somewhere along the corporate ladder owned by somebody who does VPNs, but regardless of which VPN you use, encrypt your information, it again encrypts it at the source.
Your ISP, your internet service provider and your phone provider are legally entitled in the US to snoop to everything that you do. So just encrypt it. It doesn't stop you from doing anything you do on the internet.
It just puts one more barrier. The third thing I say is, you know, understand friends from foes. Your friends are your family, your friends, people that you know in real life and you deal with, you can interact with them on a whole different level than you can with both, which are company, it's not just that, you know, it's not saying that meta's a bad company or Google's a bad company, but if they collect a lot of information on you and they get hacked, and in the US there's an average of a major breach every single day, that information is gonna get out there and it's going to be weaponized against you.
You get credit card fraud, you're probably not gonna pay anything. Somebody scams you or scams your parents or scams your, your spouse, you are going to lose that money. And it's all because of the information that you've given out.
So the third thing I just tell people is think about it. If you treat your personal information like you do, if, if somebody came up to you in the street and said, what's your social security number? If I asked you right now in this video, Mike, what's your, your your social security number?
Are you gonna tell me? Uh, I'm gonna tell you, but it won't be the real one. Right?
I'll be the real one. And if you wanna tell me the real one, let me know so I can write this down. But you know it, but when people say, what's your mobile number?
What's your email address? How old are you, where do you live? People give that information all the time.
And in supermarkets, I go in and people give their mobile number to get a few discounts on their, on their food. You know, like they were giving it away for nothing and they're not even thinking about that. That's the mindset.
It doesn't mean you change, you don't order from Amazon. You can do those and make yourself a lot more secure. Just keep those three things in mind.
Mm-hmm. It reminds me of, uh, you know, my parents grew up in Ireland and all my relatives over there, uh, of that generation, none of them ever used their first names. They all used their middle names to talk to each other, but for official documents, they had first names.
But if you went looking for that person, nobody knew who he was. Yeah. And that, by the way, that same and, and my parents from that generation, I'm, I'm Cuban, my background is Cuban and, and you know, we, we do the same thing.
Everybody has a nickname. Your family knows the nickname and it's not related. You know, it's not Billy because you're Bill, or you know, because you're William.
It's something so odd that only your family knows. And when I was a child, this is, you know, just off the point. But I remember walking home one day and a car pulled up and the guy said, get into the car.
And I was probably nine or 10 years old. And I said, I'm sorry. And he said, your mom told me to come get you.
First thing I did was talk to him in Spanish, because that's, that's the way my family would talk. And I knew my mom wasn't gonna send a stranger and I didn't know who this guy was. And he's like, I don't understand.
Just get in the car. And I said, what's my name? And he, you know, he just looked at me and said, get in the car.
And then I ran in and, you know, we, we got a police officer, we got all that. Those are the kind of things that we always, and, and they always call this paranoid, but that's the way you've gotta be. You've gotta make sure that how you treat and the information you give your family and your friends is not the same thing you put up on meta.
It's not the same thing you put into Google. It's not the same thing that you give on a company. And that will always be a flag for you of knowing when it's friend or felt.
Lemme ask you this last question. Do you think that our politicians and lawmakers understand these issues and they are, uh, gonna be crafting some laws to deal with that? Or for that matter, are they just kind of turning a blind eye to it because, well, there's a lot of money out there to be made.
Uh, I'll go with the latter on this. And, and by the way, there are a lot of people who, who, you know, are out there talking about security. They're out there, especially about privacy.
There are currently about 22 states that have passed some type of privacy law. But understand, and, you know, California has one of the best. New York, Texas, a few, it's not even a red or blue kind of thing.
States understand the privacy of this, but there is so much money in this that even when they pass a privacy law, they hedge it and they say it's opt out when really good privacy laws are opt in and other than you, you know, you shouldn't have the right to steal my information and monetize it without my permission. And what they do is they make it opt out because they know most people don't have the time, don't see it. And a lot of times it's like, if you don't opt in, you're not gonna get the, uh, the satellite service.
You're not gonna get the telecommunication service. You know, you're not gonna get whatever product you want. So number one, are they aware of it a hundred percent?
Number two, does it have an effect on the economy and how much we spend on fraud? Absolutely. The third thing is, are they doing anything about it?
No, because the companies that, that are profiting by this spend a lot of money to make sure they don't do anything about it. All right, well, folks, you heard it here. It's your data.
At the end of the day, it's not the company's data and you need to guard it jealously because they're gonna, once they get their arms on it, you don't know what they're gonna do with it. Hey Ron, thanks for being on the show or for that matter, whatever name you're going by these days. But it's all good.
My name is Martha and, uh, I do appreciate, thank you very much for having me on the show. All right. And, and folks, we'll see you next time.
Hey everyone, we're back here. Well, we're not live, unfortunately. We were live when we recorded this, but you're watching it on recording.
Let me introduce you to Dimitrius. Brinkman. We are here at Swamp Up.
If you couldn't tell 2025 Swamp Up. And we are thrilled to have you tuning into our coverage of this year's Jfr Swamp Up Dimitrius. First of all, all welcome to Text on tv.
It's great to have you on here, Demetrius. Looking at my notes here, it says, uh, founder of the ML Ops community. Great title.
Talk to our audience a little bit. What, what exactly is it and what do you do there? Yeah, So we're a community of around a hundred thousand developers right now that's primarily focused on bringing AI and ML into production.
That's the main thing because there's a lot of research, there's a lot of demos that you see out there, but then actually getting use out of it and bringing it into production, that's what we focus on. And we do that in a various, in various ways. One being we've got a Slack workspace, we'll do in-person events like meetups or workshops or conferences.
We do virtual events and like meetups and workshops and conferences. I also have a podcast myself. We have a newsletter.
There's various ways to engage in the community. We'll do like one-on-one matches, curated matches of people in the community. So in general, we just are trying to keep the education and the understanding of this field as high as possible because it is moving so fast.
It Is. Hey, just say you have a podcast isn't enough. Look into that camera, tell them where they can get you podcasts.
What's the name of it? Yeah, you can find it on anywhere that you find podcasts. It's called the ML Ops Community podcast.
And right now we're on the 314th episode. Really? Yeah.
So we've been How Often do you do 'em? Twice a week. Really?
That's fantastic. Yeah. Good stuff, man.
So you're also keynoting or on stage tomorrow doing a session. You know, by the time people see this, you probably have already done it. Yeah.
So tell 'em what they missed. Well, by the time you see this, it could have gone horribly or it could have gone wonderfully. Let's hope for ladder.
I'm sure it would go. But really what I'm excited about talking about is the idea of how there's, there's almost two big ideas that I wanna present. One is how the chat interface isn't necessarily the best interface for us to interact with machines.
It's very low bandwidth and we're used to a much higher bandwidth when we interact with humans. And then the other idea is what I am thinking about how all these companies that are putting agents into production, they all want to be an agent. They don't want to be a tool.
And the way that it could shake out is you have a master agent that goes off and is using tools, but right now it's very fragmented. And this ecosystem that we live in today is, I go and I navigate to one chat bot, and that has agentic capabilities and it goes off and it does some stuff. Maybe it has access to some tools, but it's not like there's this ecosystem, this homogeneous ecosystem that I know this one chat bot can do anything.
I have to then go, if I want something specific done, navigate to another website and use their agent capabilities to do something. So a perfect example of this is when I wanted to file a claim for, uh, delayed flight that I had, I was talking with my LLM of choice and saying, you know, can I get money back on this? And am I in the right to file a claim?
And it said, yeah. And instantly what you wanna do is say, okay, go file it. Go file It.
That's the user experience that I want. And, and, And you know what that, let's call it the dream, if you will. And, and I thought we were getting at least when you talk about travel.
Yeah, right. I thought that was part of the, uh, and I'm not knocking them, don't get me wrong, but that was part of this chat GPT agent, like, Hey, chat GPT, I gotta fly to Flagstaff, go out, find the best fare and book it for me. Yeah.
I haven't used it yet. I don't know if you have No, I I don't, I don't trust it. 'cause I'd have to go look at the flights myself and make sure that it, I'm not stopping over in Chattanooga or some, some place where, well, You bring up something fascinating.
There's two pieces of that. One is the trust aspect, and the other is this UX cliff that I've been thinking about where a lot of interactions with machines, we don't necessarily need to type everything out. That's a much slower experience than if we just do two clicks and we get what we want.
Yeah. So there's almost this valley that we need to cross before an agent is even useful. The task has to be quite complex in order for us to do that.
And I think the reason that the flight bookings have captivated our attention is everybody has done that, and it's way more than two clicks and it's cumbersome. And so when we think about that, we think, wow, it would be nice if I could just say, I wanna do it this time, this day. I want to go to this place.
And then it goes and does it. And we don't have to go and click through and do all these multi clicks, which is, and then look back, ah, is this the price I want? I don't know.
And that's not fun. Yeah. But to me, it, it sounds like a pay me now or pay me later kind of situation.
Right. Because how do I set all those up? It, it, I, look, I don't pretend to be a, an AI expert, but like I've gotten to the point now with my ais of choice where it knows me, right?
Yeah. It knows my style and voice for when I'm writing it knows what I want out of the tasks, the usual tasks that I ask it to perform. It would be great if somehow I could train my ai like, hey, I like to fly out first thing in the morning.
Yeah. I like to fly home first thing in the morning. I will do a direct flight.
I don't care if it's twice as much money and no matter what I want direct, if I could help it, um, you know, all of these little kind of, this is me kind of thing. Yeah. And I think that's where we struggle, right?
Well also, if you think about that I'm not the same person today as I am tomorrow. Yeah. And maybe that's, there's certain things that I have hard rules on, and then there's other things that I'm a little bit more flexible on.
And so that as a problem is a very difficult one to crack. Yeah. I also think that, you mentioned something fascinating earlier about the trust, which is we have to be okay if we do have this master agent world that is some kind of a hybrid chat interface.
So it's not only us with words, but maybe there's other kind of UIs that we can take advantage Of. So let's explore that. What do you mean?
Well, I look at different ways that we interact with programs already. And if you take a little inspiration from video folks, you have histograms. Like these guys are used to dealing with histograms for the colors.
So is there a world where we can deal with a histogram like experience for what we want as opposed to trying to really get into the minutiae in the words, because words aren't as easy to develop or as easy to tweak on that very small scale level. And then on the other hand, when we interact with humans, we're interacting at a very high bandwidth. And I'm sure you've been in a meeting where you end up diagramming things to get your point across.
When we are just restricted to text, we can't diagram anything. Yeah. And again, that brings us down in the bandwidth that we're able to convey to that LLM.
So potentially there's some kind of a whiteboard or it you can think of like your, your tablet that you're able to diagram with and it's recording your voice as you're talking to it. That could be a world. But at the end of the day, right now, what we're funneled into is the experience of just chat.
And then you're getting some inkling of when the chat bot will respond to you, it gives you these new UI elements. Right. So sometimes you'll get a scroll, sometimes you'll get a photo or you'll get a code snippet, some data visualization.
You get that, which is great. And I think that's the first step. But for us as input, we need to up the input levels.
Well, so I'm a little older than you. Yeah. I'm gonna guess.
But, uh, look, I'm a child of Star Trek, right? Yeah. Man, my whole life I wanted to be Scotty and just say hello computer, you know, and, and, and tell it what I want.
But I I, I thought we were getting there, right? And then I realized in like doing videos like this, right? So I can't give the video to the AI and tell it do it.
You gotta transcript it. And you would say, okay, transcribing iss easy and it's word for word. And even if you, you know, fact, uh, uh, copy, edit the transcript to make sure it is you fact wrote for it, it's not enough.
Because the way humans communicate, we communicate with our eyes, our eyebrows, our hands, nuances, tone in in speech. Yeah. Right.
And our AI just aren't up to that yet. No. So, I don't know.
I mean, one of the, one of the things that really they say separated humans, let's say from Neanderthal or Dan, so the not Soviets or whatever that Uhhuh close relative of the Neanderthal is, is our, our, the, the, the depth of our communication. Even if we didn't have a huge big difference in vocabulary, all the nuances in human to human communication. And I think that is, that's a job that we need the AI to solve.
Yeah. We don't have that No. Anywhere near that, right?
No, no. And it's, you don't realize how important it is until you just look at a transcript. Yeah.
But there also is the whole idea of, I know there's probably people out there that are gonna be thinking, oh, well, voice is trying to tackle that problem. Voice AI is the next frontier. But I am not sure, have you played around with the voice tools?
It's not that they're bad, it's that us in a work setting, what am I gonna do? Go put myself in a cubicle when I wanna work and speak to my Yeah. Computer.
You know, it's funny you brought that up. So I met a guy I interviewed last week, and I'll give a shout out to him. This guy, Dr.
Allen Becker, his PhD is in voice to text. Text to voice and ai. He started a company, got sold to Snapchat.
He ran Snapchat text to voice for a while, but now he has a new company, I think it's called E Self, E Self ai. Check it out. When we're done for me, you can sign up for a free five instance thing.
They've developed avatars. Yeah. That look at you, that watch you and talk to you hook into LLM in the backend.
And they do try to pick up nuance Yeah. From your voice and from your gestures. Mm-hmm.
It's early. I played with it. It's, it's freaky.
Right? It really is. It freaked me out.
But it, you know, it's not perfect yet. Yeah. But I'm, I am I'm bullish on, on that happening.
Yeah. But you still have this, it's like we're in meetings, right. And then we have to have a moment where we get work done.
Right. And so if the way that we have to get work done is by talking to our, It's still cumbersome. It's like we're in a meeting again.
Yeah. And that's exactly it. And really, whether you're talking to the computer or typing to the computer, there are people who type really quick.
Yeah. And a lot of people are really not good communicators verbally. That's like me.
Exactly. That There are, I mean, that, that's an issue. That that's definitely, it's a big issue, You Know.
But let's, let's look at it from the other side of the coin. Demetri, you know, the windows mouse clicking kind of interface that is dominant today. Look, this was like 1960s, early seventies out of the, the park.
Yeah. You know, Xerox Park out here, we haven't really, I mean, it's been 50 years. Yeah.
And we haven't found a better mouse trap. It's tired. It is time.
You could see that with like the touch screens. We have these gestures, you know, the pinch to zoom mm-hmm. The swipe.
And the other thing that I think is a big problem with us having to use chat and take what's in our mind and put it into a chat bot is how, right now we're very used to being fed things. It's almost like a passive experience A lot of the time when we're on the internet. And you can think about Netflix or when you're scrolling on Instagram or TikTok, these are passive experiences that we have become accustomed to.
And now chatting is very active. Right. We have to really define what we're looking for, what we want and put it into the chat bot.
And so we don't have these passive gestures anymore when you're trying to work with chat either, which I find fascinating too. So is there a way to bring in these passive gestures into the chat experience? Or I guess at a certain point, once it evolves outside of chat so much, we probably won't call it the chat experience, we'll call it just the AI and Communication experience.
Yeah. So you're not trying to tell me we gotta get passive aggressive with our ais. Do you?
Are we? No, not that, not on that. I mean, you might see it.
You might See It. Yeah. Better.
I don't know. I haven't tried. I'll tell you, one of my biggest things that I've had to teach myself is you don't have to be polite.
You're only making it harder on them. Every time you say thank you and please, and all of these Things, it's burning energy. Exactly.
I wanna turn a little bit Demetrius and, and talk a little bit about security. Right. So look, I, I think everyone agrees that we're all gonna have agents, digital workers, whatever you want to call 'em mm-hmm.
Who are gonna go off and do these tests for us, whether it's booking flights, writing code, or, or what have you. And we're going to need either, we're gonna need a crap ton of agents, right? One, like almost an ephe ephemeral, disposable agent for every task we do.
Mm-hmm. Or some sort of master agent that's able to clone small parts of itself to do specific tasks. Yeah.
No matter how, no matter which way we go there is security issues. Yeah. How do you view that?
Yeah. There's a few different issues that I'm looking at. And these are like the most basic of the most basic.
If we get some of these DevSecOps people in here, I'm sure they think about it on much different levels, but in a broad strokes way, if we have this world where we have a master agent that helps us go out and it's our gateway into the world, and it can use these tools, and it's a big if, because like I said, everybody wants to be an agent. They don't wanna be a tool because you're giving up your distribution, you're giving up your relationship with your customer. If now Chachi, BT, or Gemini is what chooses to use you or not as a tool, that's a big vulnerability for your company.
So that's a big if right there. But if we do get to that point where I go to my LLM of choice and then I sink in with the tools that are out there on the internet. So Amazon is a tool.
So buy something from Amazon can be many different types of tools. Uh, look for something on Amazon, whatever, search Amazon. Now, are we okay with the context just flying around the internet?
This data potentially sensitive data is now gonna be going to different tools and going to different LLMs. And I'm not talking on the l are we okay with our data going to the LLM provider, but just data flying around the internet. That's one part that I think about.
All right, well, we need to get the context and we need to have a way to securely do that. It's not necessarily a new problem because we've been transporting data across the internet for a while now, but now it's a little bit different because there's agents that are interacting with each other and maybe one agent thinks this context isn't that personal. But then the other agent, when it summarizes it, it sees that, oh yeah, actually it will say something that is personal and you don't want that.
Right? So you have wild cards in each agent, agentic tool call or subagent, whatever you wanna call it. And then next you have the authentication issues.
So I want my agent to be able to understand everything about me. That means it needs to look at my calendar, it needs to look at my Gmail, it needs to look in all of, everything that I'm privy to. It needs to be privy to in case it needs to act on my behalf.
So you need to off into all these things, but it's not just OAuth because you then get to the next piece, which is the actions. You don't wanna give it permission to take any kind of action. No.
You wanna give it permission to take the action that you said was okay, not anything else. Because if you give it a lot of scope, it can abuse its privileges. So I've been in, I didn't tell you this, I've been in security for 25, 30 years.
You're only describing what I would say are innocent security issues on the agent. That's true. True.
What about when the bad guys say, oh, he's got an agent. Let me exploit that. Well, did you hear what happened recently?
There was I think some output from an LLM that had a nefarious link. And when the user clicked on that link, it then was able to take control of the system. It happens all the time.
And so yeah, you have, again, you have this wild card in there that the nefarious actors can hijack this agenda. They're Not dumb. They're as smart as we are.
They're well-funded, well organized, and they, and that, that's the truth. And if you do end up having everyone as a tool for your master agent, how do you verify that this tool is okay to use? Agreed.
It's it, look, here's the good news. First of all, no one's gonna waste. Everyone's running as fast as they can anyway.
And they're gonna keep running as fast as they can. But as these things, and I, I've seen cycles before, right? We never lead with security.
We just don't. Yeah. We, The sad thing, but it's True.
It's a said, but as a security person, you either gotta come to terms with that or, or you know, you're gonna be depressed. Um, we will catch up, we will put the guardrails in, we will come up with processes around it, but people are gonna run as fast as they can. And, and, you know, you can't put your, you can't lay down in front of the tracks and say, stop the train.
Yeah. You get run over. Yeah.
And, and so I always say it's more of a yes we can mm-hmm. Kind of thing, right? Yes, we can.
You wanna run as fast as you want? Yes, you can. We'll figure it out.
Yeah. And I, and I think that if I had to leave us with one thing, that's what I'd leave it. Yes.
We can. We'll figure it out. But man, thanks for the work you do, Demetrius with you, this community.
It sounds great, man. We appreciate you. Thank you for presenting at Swamp Up and for being here on Text Drunk tv.
Thanks everybody. Alrighty. We're gonna take a break.
We've got more Swamp up coverage coming your way, so check it out. Hi everyone. We're back here at our day two coverage of Swamp Up.
Let me introduce you quickly to our next guest. His name is Guy Levy. Guy, first of all, welcome to Text Strong tv.
It's great to have you on here. It's my pleasure. So I, I guy I give him your name, but share with the audience.
What do you do at Jfr? All right. So I'm leading the architect's team in the city office of Jfr, meaning mainly focusing on the advanced technologies and something like beyond the border or beyond the horizon kind of Next.
Yeah. Very cool. There was plenty of next gen stuff talked about here, but you know, for, for those of you who've never been at a, a Jfr Swamp Up, part of the mantra is we don't come here talking about what we're going to do next year.
Mm-hmm. We come here showing you what we have ready now. So even though it was next gen, it was stuff that's ready now.
Uh, you know, and we've tried to cover it, you know, in the last day and a half, two days here. But Guy, what for you, what, what was some of the highlights? What were the big things that really you were excited to show?
Alright, So there are a couple of those. Uh, the first one, I think the UPT trusts, uh, capabilities and the ability to cover end-to-end, uh, uh, trust on the application business application level was one of a big thing, like tying everything together into one direction. And the second thing was around Fly.
Did you see that enough? Yes. I was, I was sitting in the, in the, I was in the front row actually first table.
So, and I, uh, I wrote about it a little bit, but we haven't really discussed it yet on the video here. Okay. So, uh, FLY is the first ever iGen repository that will introduced to the market.
Um, it's actually the next generation of how to support your iGen, uh, development environment. How to support teams that are going iGen, AI first development, and want to have the right tooling in order to speed up their, uh, processes and to control it on a iGen AI pace of things. Sure.
You know, and, and again, for those maybe who aren't familiar with Jfr, right? FE was a company, the acorn that the Oak Tree grew into exactly. Was based on a repository, based on Artifactory, a repository for artifacts.
And since that time, j Ferg has started several repositories. Mm-hmm. Uh, and Fly, of course is the latest, but as far as I know, this is the first agent repository mm-hmm.
That we've seen out here. Yeah. So this is exactly why we are in the right position to introduce the next level and the next generation of repositories to the market.
What we are doing is actually, it's not only the repository, the development, uh, uh, pace process way of doing things is changing due to ai. So people are using more and more agent co-generation, uh, technologies. They can do more features per day, they can develop more, they can release more, they can generate more code, which means generating more artifacts and having multiple streams of artifact that are concurrently progressing in your project.
And for that, you need a repository that can handle that and can support you in order to manage and store those artifacts, find them and deploy them at the pace that you are generating this code. Lovely. Good, good, good.
Um, now one of the questions I, so I, I tell you, we do a show every morning at Textron called Textron Gang, five six people pundits. And we talk about whatever we three, we always have three topics every day, whatever's big that day. Mm-hmm.
Today, one of the topics was Swamp Up because we had me and another one of our tech drunk people here. Mm-hmm. And we talked briefly about fly a question that one of the other people on the panel had.
Well, is this just for internally developed agents? Can I put third party agents in there? Is Jfr, is it just for Jfr approved agents?
You know, what kind of agents can I keep in fly? Right. So FLY is actually an agent repository.
So it means that the repository itself is agent and doing stuff for you and supporting your development. And your development can be traditional features or agents or whatever you need. Now, uh, when producing code with agents, what we see, and this is something that we experience and I think it's becoming a trend in the industry, that the people are conductors of code.
They are not the writers of code. So we have people that are working in parallel on few features, couple of systems because they are conducting that they're not actually doing the work. And this creates like a big stream and flow of software that is being generated.
And in this kind of environment, you need to think differently about how you version, how you release, how you manage the process, how you control that uhhuh. Okay. So this kind of stream that is being expanded need a different method of managing This really is.
Yeah. Yeah. And this is exactly what Fly is doing.
It's a hope different paradigm. It's a different paradigm. And we see, we see that we actually write fly with those methods.
So we are using that and we are experiencing That based on what it's like eating your own dog food or drinking your own champagne Better. Yeah. Champagne.
Yeah. Champagne is better. Yeah.
Uh, and now what, are people using it yet or no? So we just introduced and uh, presented that, right? Yes.
We have, uh, some very, uh, small initial group of, uh, uh, users that, uh, that already use that. And there is a waiting list really. com and register to the waiting list.
We'll get the, the request and we'll enable more and more customers. I love it. I love it.
Um, so one of the, another question that came up on the gang today is, you know, we, we've seen the move from DevOps from point solutions to platform. Mm-hmm. Jfr platform, Of course, GitLab platform, this pla a harness, whatever.
There's all platforms and basically an organization picks what platform. There's some shops that are jfr shops, some that are this one, that one what have you. Are we going to see the same thing with ag agentic repositories?
You think other people will come out with ag agentic repos and do they at some level begin to communicate or is that you pick your repo and that's what you use? Hmm. Interesting.
Again, I, yeah, we asking about the future, but Right. The, the, I think that reality shows that there are multiple options and, you know, talking to our customers and serving our customers in this segment for the past 16 years, we know that there is a variety. Okay.
There's a, a more system, more adjacent system integration, sometime competition that is a part of the customer ecosystem mm-hmm. That our systems are in. Okay.
So with that, I think as part of our, of our platform of the J four platform, we have the to integrated to fail philosophy. And we are promoting those kind of integrations on the platform level. And of course this philosophy applies to fly as well.
So we do see additional adjacent systems that people are using. This is part of our investment to do those kinds of integration and to be prepared for the customer ecosystem because the customer need to have the choice. Absolutely.
Alright. Excellent. Beyond Fly, what else was big for you here?
So, as I talked about, uh, the UPT trusts, uhhuh, I think that's, uh, like a summary of announcement and functionality that we've been releasing to the market for the past two years. Um, it now customers can see that the whole picture can now connect the dots and see how we as a platform can enable them to manage business level applications and connect them to the artifacts and the physical entities that they are managing. And doing that by controlling the flows, getting all the metadata that they need in order to manage, to understand, to triangulate, to debug, to roll back versions and everything under a single roof that is connected and trusted.
And that's, that's, that's the dream, right? That's, that's what we wanna go to. Yes.
And we can say that time and time again, those are kind of integrations that customers are doing themself, right? They are doing their, uh, own label. Yeah.
Their own scripts, internal systems and stuff that you need to work around in order to make it, to, to work in your environment. And now this kind of integration is, again, you create a system now you need to maintain it, fix it, upgrade it, upgrade the integrated system, and make sure that everything still works. And with our, uh, appt trusts and the integration that we already build it inside.
So ServiceNow, Sona, and the others that were presented, um, we do the work for you as a customer so you can trust us that it will work. And this is what we are doing with the leading vendors in this area. Area.
This is video as well. Yeah. Yeah.
Excellent guy. Thank you for coming on, man. Thank you.
I know you were, it's the first time you've been on with us, but yeah, very conversational. We appreciate Keep up the great work. We'd love to hear more.
We're gonna be watching us fly develops here. There Will be more developments to come. I'm Sure.
I'm sure. Check it out. Jfr fly the first Agentic repository.
Go check that out. We're gonna take a break and we're gonna continue our day two coverage here at Jfr Swamp up in Napa. You're watching Textron TV.