AI Anxiety, Agentic Investment Risks, and EU Scrutiny of AWS and Microsoft | TSG Ep. 973
Alan Shimel, Mike Vizard, Jack Poller, Ira Winkler, Jeff Reich and Chris Short discuss the odds that demand for agentic artificial intelligence (AI) will grow enough to justify the current level of investment being poured into infrastructure to support it.
The gang then looks at how much AI is about to reshape cybersecurity, for better or worse, as more automation enters the threat landscape. The episode wraps with a discussion of why the European Union is investigating Amazon Web Services and Microsoft, adding pressure to ongoing concerns around cloud market dominance and regulatory oversight.
Transcript
Hey everyone, are we in a state of ai high anxiety? I love Mel Brooks. You're watching Text On Gang.
Hi everyone. Happy Monday. Hope you had a great weekend.
You know, it's gonna be a short week for us here at The Gang. It's Thanksgiving week, always one of the nicest weeks of the year for me this year at Little Sweeter, both of my, my sons will be home. It it'll be good to have a, a house with the boys home again, little buffer between me and me, aggravating my wife.
So it's always good to have her, have them home. Um, we have a great gang here for this Monday for you. Let me introduce you to them.
We have Jack Poller, IRA Winkler, Jeff Reich, and joining us after his cameo with Kon Chris Short. Chris, great to have you join, join the gang officially here from the studio. Gentlemen, it, it's great to see you all.
Mike, as usual, we got a lot of AI noise and news and I don't know if it's news or noise or both, but why don't you kick us off? Well, let's jump into this 'cause everybody's closely watching what's happening with AI agents and, uh, AWS would a little help from IDC published a report saying that, well, organizations have deployed on average 10 of these things. Now, they're generally not customer facing, they're a little more on the operational side, but we're all watching this closely because, well, if you look at the NVIDIA numbers, as great as they are, basically it's four companies buying up all the GPUs in anticipation of the fact that, well, we're all gonna use AI agents, we hope, because, well, the first round copilots was interesting, but it's kind of difficult.
The issue now is are we gonna use AI agents and how quickly are we gonna adopt them? And to what extent, because the survey kind of suggests that people will not fully roll these things out. At least half of folks anyway, till 2027.
Some folks are being a little more aggressive than that, but there's a lot riding on this, Alan, it seems like the whole IT industry is making a big bet on this one thing happening. So is it gonna happen and what's your take? You know, I, I did a shi, he says on this last Friday, Mike, I I call it AI jingga pull one block outta this tower and the whole thing comes crashing down.
And I think that block is open ai, but you can go watch my shimmy says, or read my article on Textron AI about why I say that. But a, as to this survey, I'm gonna call bs, right? I think the fallacy or the, or the soft white underbelly to this survey and to this report is how we, how do we categorize an agent?
To me, an agent is something that goes off and does the does things or autonomously. There's a difference. I I don't consider copilot necessarily an agent at this point.
I think it's, it's more of a chat bot, right? It's more generative than agent. Yeah.
Alan, let me say, because when I read this study, there's a very different, like, you know, my bias that when AI is everything, AI is nothing. And a, an AI agent is one of those, by definition, is an entity pretending to be a person, providing customer support of one thing or another. Like if I try to get online and talk to Delta Airlines to say, I want to change my flight to, you know, to Tulsa, and they're like, oh, we would love to help you change your flight to Tucson.
You know, that's the typical AI agent by definition. Then there is agentic ai. Agentic AI implies that an a software tool.
'cause at the end of the day, it's just software with certain algorithms and functions that an agentic AI is taking read, making a decision and taking action on its decision autonomously. And that is, you know, that could be, for example, switching a railroad switch as an example. Now, the problem is, I read the study and I was like, are they using it for help?
And you mentioned, for example, copilot. If I type in a question and it's answering, is that an A, you know, an AI agent? But the problem is, I think we don't have a clear definition, which is number one.
And then there's the other aspect. If they are talking about agent ai, which is completely possible, I think the people survey suck, and I think the people in the survey had no clear definition of what they were answering as well, in my opinion. And some people might have thought AI agent talking to, replacing a person helping, or there could have been some software tool making a decision, which frankly are many software tools, AI or not.
But what are the guardrails? And I didn't see discussions on that, and it's two different conversations either way. So I'll leave it there for other people to discuss.
But that was my concern with the study. I'm, I'm gonna support with a research study that, um, we had IDSA did, um, in the middle of the year, and it wasn't about AI specific, but we had AI questions in there. And two points I wanna bring out that I don't think have changed since July, which is when we did this, first of all, 11% of, and this is across the board, CEOs, CISOs, security engineers, answering the survey, 11% say we have complete, fully documented and communicated controls around use of AI in our organization, whether it's agen or not, 4% somehow believe they're saying they don't allow AI in their organization.
I don't believe them. 56%. We have some controls in place, but not enough, and we don't really, we can't really control what's going on.
I think that's, that's the underbelly we're talking about. That's here. Even though organizations may be using ai, whether project or not, they're simply using it.
It's like they're getting in a car and not knowing how to drive, not knowing what the roads are gonna be or how to make it stop. Well, Jeff, let me expand quickly, but you raised a point though. They say they're not using it.
They are using it. And if they don't know they're using it, they should be fired. Because ai, and I use this is embedded in every technology out there.
If you get in your car, there is an algorithm that is creating a route for you to go somewhere that is theoretically an AI agent of some form or ai. But I, I mean, it's embedded in anti-malware, it's embedded in autocorrect, it's embedded in Siri. You know, people can say they're not using it and if they say they're not using it, they should be fired the world according to ira.
So, Chris, let me come back to you here for a second. Regardless of, you know, how they define AI agents and, and whatever it may be, the concept is that they are not gonna fully roll this out till 2027 and it's gonna take a little while. Is that gonna be enough to sustain the investments that we're seeing in AI today?
Or is this gonna play out at, at a much longer curve than people are anticipating? Well, that's very interesting questions. I think yes and no, right?
Like the, the clouds currently have a backlog of customers asking for these, you know, chips that are getting made for Nvidia, but by TSMC and there's only so much capacity. So there's a backlog right now. And if folks are waiting a year, well, a month to 16 months for their AI projects to come online, well, I think they're gonna miss the boat on some things, right?
The technology is evolving way faster than, uh, the traditional enterprise release cycle. So you're either going to be, you know, on a old version of something for a longer, or you're going to have to learn to adopt and embrace, you know, rapid release, rapid testing, all of these other things that are, you know, key to innovating and, uh, making the most of your AI tools. So the, the idea that these big projects are gonna happen and they're not gonna be rolled out to folks for years is concerning from a like supply chain side, because Timing's Be everything gonna a dip in the market.
Mm-hmm. Then yeah, it would make sense that the dip is now when chips are short. So I would agree with you from the supply chain side, but from the demand side, it's actually, I think 2027 is being very optimistic.
You know, I have, uh, a friend who's a sales engineer, lead sales engineer for a, uh, a regional CSP, and they said, well, we have to get into cloud. So they tasked him with figure, sorry, get into ai. They task him with figuring that out.
And so he said, okay, well let's go and buy some machines, stick some GPUs in it, and then it's okay, now what do we do from here? And everybody right now is very lost. If you, uh, you know, I think, I don't know if I've said this here before, but I've said it plenty of times before that, if you think about what we think, if we task somebody with going out and rolling out a virtualization infrastructure or a container infrastructure, there's a well-known, well understood recipe for how you do that, right?
Today, if we task somebody, we're rolling out an AI infrastructure stack, there is no well-known recipe. It is very hard. There's, it's, and it's not only the hardware infrastructure that's not understood, it's a software infrastructure infrastructure.
And how do you get to a point where you can actually then go and put some AI agents out there to do something that's black magic for probably 75% or more of organizations today? And I don't think that's going solved soon. Yeah, Because no, what I'm saying is that it, well, taking a step further from Jack, it's not the hardware, it's not the software, it's also a data infrastructure because AI is about the, so the making decisions from data and an organization needs, for example, a chief data officer to go ahead and make sure the data is accessible to all the software that needs to pull it to make good decisions.
And without a data infrastructure, you're not gonna have any other, the other infrastructures are gonna be worthless. So IRA's Ty's point, though, it is entirely possible that some of the folks answering this survey just said, yes, we're using AI agents because they sent out an email to somebody and said, Hey, are we using AI agents? And somebody said, yeah, sure, but then, you know, we just checked the box and said, you know, just tell the boss anything he wants to hear.
Right? Well, But I, I think there's also the difference that IRA pointed out between AI agents and agent ai. They're not necessarily the same.
However, here's the thing, I don't know if we're gonna roll our own AG agentic ai, and I think that's the, that's the exponential difference between maybe generative AI and rolling your own LLMs and doing your own training and all of that stuff, versus using someone else's agent in an agentic AI way, sort of a Salesforce agent force or ServiceNow agents or any of these agents. These are pre-rolls, right? For all my friends in states where cannabis is legal, these are pre-rolls, you just light 'em up.
You don't have to roll 'em, you don't lick 'em, you don't worry what's in there. It's already, you know, it's a, it's a, and in many cases they may be rather ephemeral, they may be single use, but persistent, but they, they're limited. They do a job, they do a particular task and they do it autonomously, but there's not a lot of infrastructure you are going to build into that.
Maybe set up an MCP server, something like that. But I, I don't know if they're going to be building their own stacks here. Is, is I guess what I'm saying.
Uh, you know, Jensen Wong spoke about this. Uh, I, I, I caught it. It was one of these when the Saudi prince was here, and don't even get me started.
But anyway, Jensen WG said something about, you know, we're gonna have a whole new class of, of AI apps that used these agents different than the apps and the infrastructure we, we have today with it. So, you know, when people say, do we have 10 or more AI agents? I do think that's some of the IRA thing in there.
Of course we do. We have that help bot for people who want to go from Tucson to Tuscaloosa or whatever. But, uh, you know, truly agentic ai, yeah, you're gonna have 10, eight of them will be from Salesforce and three from ServiceNow.
And, and, but I don't think that's here. I have a hard time believing that's half of organizations today And or at least, you know, I think it's, we're not sure what an AI agent is, so therefore everything that looks like it's AI is now becoming an agent. Chris, is that where we're at?
Uh, maybe I think there is some over rotation. Um, you know, people calling things AI agents, and they're not in the traditional sense or the sense we're talking about, at the very least, uh, AI agents. So that thing on your website that helps you, the, the search tool, like everything could be considered an agent.
Uh, when you think about it in some degree, however, whether it's actually using the large language models underneath the hood, that's a different story. I know I've been to many websites that have a little, little chatbot thing that pops up and it's completely not intelligent, right? Like it's, it's, it's literally a phone tree replacement kind of thing For calling support.
It's it more of a BPA, right? That, that kind of thing, right? And, and as Iris said before, right, never, never confuse AI with intelligent.
Um, anyway, hey, we're over time on this particular segment. We gotta take a break here on the gang on this Monday. We're gonna come back and we're gonna talk about AI high, uh, insecurity Rena, anxiety.
You're watching Text Drunk Gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back and we're gonna have a little chat about, well, what is the future of cybersecurity in the age of ai? Jack Poller has a column up on Security Boulevard that you should all check out talking about. Well, the attacks now are being launched by machines, and that just changes the game altogether.
But Jack, go ahead, explain. So I, there are essentially, you can think of this, there are three ways machines can be involved in an AI in particular involved in the attack side of the cybersecurity equation. And one is what we would traditionally call red teaming, which is where you attack your own infrastructure to find holes in it and help your blue team, the defenders figure out where they need to be better at defense.
Uh, second way is you could be a real attacker and attack somebody. And the third way is you could be the, uh, military or government institutions and using AI as part of your attacks against other nation states. And we sort of see th all three of these coming to light this week.
Uh, red teaming is I think more AI being used in red teaming right now as more of the business process automation that out was alluding to in the last segment where we're trying to figure out how to accelerate our red team activities and enhance them. And also to look at how red teamers attack AI agents and other AI infrastructure that we've put in place. Uh, and then there is, uh, a company recently called 20 who goes by, uh, the double X letters XX or 20, uh, that received, uh, large investment and large contracts from the Pentagon to ostensibly do, they're not very public right now, but based on their hiring, it looks like they're hired to do offensive operations on behalf of the US military and US government.
And then, uh, anthropic has claimed that they have discovered an AI initiated an automated attack sequence, uh, that was used using anthropic to attack other organizations, particularly, uh, Claude code, uh, was used. And, uh, they claim that something like 75% or more of the entire attack operation was fully automated and autonomous with, uh, humans in the loop mostly to direct targets and validate, uh, specific points in the attack chain. And that it was now, we're now getting, uh, AI driven attacks that are now going to ramp up in the attack itself in a speed and scale that's gonna be hard for human defenders to respond to.
Yeah. Um, so I, okay, so my background is in red teaming, NSA, the, like this fra this is nothing new to me. In all honesty, we're looking at companies, for example, the difference between a red team and an actual threat actor is intent.
And when you have companies, for example, that have been around, you have, for example, pen Horizon three, you have lit, you have a whole bunch of other automated attack companies that are coming out, sorry, not attack companies, red team simulation companies that are out there. You know, this is kind of expected because what computers do is automate repetitive tasks. A lot of red well intrusion is based upon frankly just searching for massive opening or just searching massive infrastructures for openings, finding a potential vulnerability to get in.
Once you're in, then you start digging in and so on. And a lot of it is just, you know, this whole conversation is really the inevitability of what we're doing. Now, the concept of ai, and I use my Dr Evil quotes here, is because you're able to go ahead and maybe make decisions on a fuzzier basis than a more straightforward acting basis.
'cause really AI I'm oversimplifying is advanced statistics and it's just acting repetitively to get in. Once it finds a vulnerability, it automates it. Maybe a agentic AI like, and takes the next step.
But then you have a person to say, yes, I like that data, or Yes, thank you for identifying all the vulnerable servers. Here's the servers you really want to focus on. So the downside is, and I'll just say this, China has been the most egregious.
And what I mean by that is they don't care. The other threat actors actually don't want to be detected because the problem with this massive use of AI is that you are more likely to be detected, you're more likely to be stopped, and I'll just leave it here and let other people talk. But at the same time, there's also the ability now with threat, you know, continuous threat exposure management and tools like that to automate and start detecting these things.
You know, so far the good guys aren't as efficient as the bad guys, but I'm hoping that the good guys start automating the mitigation of the vulnerabilities the bad guys are attacking. I think this is a case of AI being a tool and people using the tool, how tools are used, right? Like a machete is very good at cutting down foliage, but it's also a tool for other things, right?
Just like ai. So automating things and having it run semi autonomously, I think is just going to be the future essentially, right? If you want to do something at scale and do it quickly, you're gonna tell the computer to do it for you versus trying to do it yourself manually.
So if folks already have a foothold in your infrastructure, it now becomes even easier for them to say, okay, let's xFi things now versus, you know, having to maintain a persistent presence for a while, go unnoticed and then start exfil things. Uh, Chris, if I can add on to what you're saying when you're saying it's the future, I think the future is, uh, okay, now I, I believe we're already there with that. And I'm gonna use an analogy.
Um, and I'm not saying here's a good old days when I learned to program, when I first started programming, it was on holler earth cards, 80 column cards. And I had one test run a week to check my deck to make sure the program ran. And it failed with a SOC seven or anything else.
If ask your grandparents, um, if it failed with that, then you had to wait another week to get another test. So you did what's called desk checking, and you look through those cards, I don't know how many times I would look through every deck at least 50 times. Now a developer writes a program and they can just run it in the system because it's close to free.
And if there's an error, it tells you. But if it runs successfully, they say, well then it's good. But they don't, it doesn't include regression testing and it doesn't include what all the unintended consequences.
And I think that's what you're referring to. That's the downside of this. And back to IRA's comment as well, the downside to this is it's great, it's faster, it's automated, we can do things better, but it is simply a tool.
And it also means that if we do things poorly, we're gonna do them poorly much faster. So Ira, IRA, what is the role of the human and the cybersecurity teams, if this is a machine versus machine battle at this point, and you know, are we just gonna sit back and watch it happen? Well, the thing is, you gotta start looking at what are we doing at a high level?
At a high level, these things do what you tell it to do, and somebody's gotta tell it what to do. It's gotta tell it what the targets are. It's gotta tell it what type of data, even if it can sort through data quickly.
It's almost like reverse data leak prevention. We have to start figuring out, okay, what are we looking for? There's also task management and intelligence operations.
Somebody is doing the collection management, doing the tasking of the people and so on. We also need people to write the tools to begin with and write the ai because a lot of people are like, oh my God, it's ai. It thinks for itself, it doesn't think for itself.
It implements algorithms that a person tells it to implement. And these algorithms are designed by people, and you have to see what are the good strategies. And at the same time, in this whole attack chain, there's also the defender aspects.
When you have attacks at scale, those are easier, much easier to detect. And it means that people have to step in and be there to step in to stop it. Because, you know, again, this was detected all of a sudden.
I'm sure somebody at open AI looked at the stuff and said, wow, look at this. Usage, usage is really up. And it's almost like the cliff stole thing.
If anybody remembers the cuckoo's egg, how did he detect the whole East German intelligence? It's like a 37 cent error sent him down a rabbit hole because somebody was overusing the ai, they're overusing the assets and these are noisy. The thing is to automate in stealth is much more effective than to automate, like what was just happening.
I was gonna say one interesting fact that came out of the, uh, the, the philanthropic attack was that philanthropics AI actually hallucinated, uh, data for the attackers and it hallucinated identities that it claimed existed, and that it had compromised, that it had found compromises for when in fact it didn't. They were false identities that had hallucinated. So it actually sent the attackers down a path that was not successful.
Is that part of the defense? Now? I'm, well, no.
What Responsibility do these companies have now, right? Yeah, That would Well, but here's the thing guys. Let's, let's ground this.
In reality. What are we really talking about? Why should people out here care?
They should care? Because like it or not, the bad guys and whoever, however you want to define a bad guy, whether they're a red team member or a real bad guy, you know, working for the Chinese or, or whoever, the bad guys are using ai, they're using agent ai, they're getting better at it. They're learning how to use this tool to be more effective.
The tool itself is progressing to be more autonomous and do these things. And it is going to be stealthy end at scale, stealthy end at scale. Because it, that's, that's what the, this AI can give you, right?
That those kinds of resources, right? You have multiple workers, you don't need as many people in the loop. You may still need a human in the loop, but not many humans in the loop.
And so how do you fight this? How do you defend this? Well, the only way to fight this AI onslaught and defend against this AI tsunami is you gotta use AI itself.
You got to use AI to fight ai. You got to use AI to defend against ai. You're not gonna be able to match human to ai 'cause the AI will quickly outstrip you.
There's too many of it, there's too many GPUs out there. There's too much. We need automated AI defenses against automated AI attacks.
And I'm not trying to create some new missile gap here or cold war kind of thing, but that's why it's important. We, we need to realize it and move forward. Well, you mentioned missile gap, and that kind of sparked something in my head as far as the, the current economic situation that we're facing, the economic contest that we're facing with AI between the west and China, essentially, I say the West in like the 1980s term.
Um, but the, the thing we're gonna see is that folks are gonna use these tools, they're gonna advance with these tools and they're going to start competing at a higher level, right? Yes. This one instance we're referring to, you know, the AI hallucinated, and that could easily be why they were discovered, but someone's doing that right now with AI and they're not being discovered, and that's a big problem.
Well, cybersecurity is not about perfection to begin with. Cybersecurity at the overall is about risk reduction at the end of the day. And that's how it needs to be phrased.
Because the fact of the matter is, and you know, everybody's gonna say, well, I don't have the AI to fight against it going back to like com. My comments on like the first block, you know, again, you're gonna have tools that are gonna be able to detect this. The problem is a lot of people don't want to use tools that are available.
These people are not, you know, these attacks are not unstoppable attacks. They're volumous looking for the one hole among many potential holes. And what's happening is, is this is a case where, you know, I don't have to outrun the bear, I just have to outrun people with me.
And in most cases, the ai, unless it's a highly targeted attack, which some are from nation states, I give you that. But for the most part, they're gonna go after the organizations that are not enabling the technologies that are available from whatever cloud providers, whatever SaaS providers they're using. Much like the Snowflake attack.
If anybody remembers that where Snowflake was hacked, it's like no Snowflake users who did not turn on MFA were hacked. And so we need to start looking at that because all this ai, it's gonna find these vulnerabilities which anybody could theoretically find if they had the resources, but it just doesn't more at scale. But the people who are reasonably secure are mostly gonna be pro protected against this 'cause they use the other resources that are there.
Agreed. All right, well, budgets being what they are, I think you guys are saying things might get worse before they eventually get better. Who knows, they Might.
Hey, but we gotta take a break and move in the C block guys, we're running along, we're running late here. You're watching Textron gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in.
While the eu, arguably the only authority in the world that's now investigating anything, is taking a look at Amazon Web Services and Microsoft to see if they are dominating the cloud marketplace. And it's kind of interesting 'cause one of the things that has come up over the years is that surprisingly the main services that most people use on these cloud services, the prices don't seem to change all that much. And when they do, they seem to all perfectly align where every cloud service product has the same price for every service.
So Chris, what's your take on what's going on here? Well, we've got quite a few things happening here in, in terms of like the EU apparatus of government. Uh, one is the Digital Markets Act, which, uh, has a provision in it that considers, you know, critical bottlenecks as quote gatekeepers, which need more regulatory requirements.
Um, antitrust folks are also involved. So there's a bunch of things happening here, but it's particularly interesting in terms of the past couple months we've seen AWS Azure, CloudFlare, a bunch of other folks just go offline or, you know, in AWS's case cut off half the internet. It felt like Cloudflare's case.
Same. So all of this has happened very quickly, and the EU is very worried about its dependence on foreign services. And I think, you know, when you look at the world we're in today, Europe has had a wake up call in terms of cyber activity going on in Ukraine between Russia and Ukraine.
And they're starting to realize a reliance on a single source is not good. We already have talked about, uh, you know, sovereign infrastructure as a thing in the EU that's mainly being driven by driven this need to be more self-sufficient. So they're trying to mitigate risk and as well as trying to get their markets in order so that it's not so easily dominated by one or two or three providers.
I I, I agree wholeheartedly, Chris. I, I, um, what's interesting about this though is someone talked about 1980s West, you know, this is a case where you see that that's crumbling. The real, the real point here is the EU does not want American or US cloud companies being their sole cloud providers because it allows Uncle Sam to reach in there and, and have access to anything that they want to, right?
Because Microsoft has come out and said that, uh, Amazon says they all have To, right? Like, and it doesn't matter if an intelligence agency subpoenas you or whatever, you're a, no one's gonna know about it and B, you're gonna do it because you Have your license, don't if you don't, don't. Right, right.
And, and so the EU wants some independence there and you can't blame them. Um, look, I'm a, I'm well, So, so does that mean, does that mean though that the EU will eventually wind up subsidizing a competitor to A-W-S-C-I? I don't know if they'll subsidize.
They already are, in my opinion, right? Like they've, they've put the, they've thrown down the gauntlet of sovereign EU based systems being their desirable outcome, right? Yep.
So I, I think, and Susa, so SUSE recently appointed a friend of ours, um, Adrian, Adrian, I forgot his first name. No, slack. Uh, uh, slack.
Anyway, they have an entire department for, for IT sovereignty. They are building EU based data centers, staffed with EU based support people using EU resource, EU based resources. And, and SUSE wants to be the EU cloud provider.
And, uh, you know, more power to 'em. Um, they, they announced this when I, I was at Seuss K in, uh, in Orlando or shortly thereafter that, but I've been, I've interviewed several of their executives since then. And you know, and this is wholeheartedly, I don't know if it's financially supported or subsidizes the word you used Mike, but it's, it's, it's certainly you've got, has a lot of support within the EU countries and the EU block.
Do we wake up one morning to discover that the president is now saying, Hey, your guys are creating an unfair marketplace and we're slapping tariffs on you because you're preventing our American Cloud service providers from addressing your market. And I think they're ready for That. I mean, I think they're ready for it, but I think they also know that that's not the way to do it effectively.
It's just a pain point that they're inflicting And it is a scale difference. But how different is this from the US perspective of saying TikTok shouldn't be here, and how easy has it been for us to extricate ourselves from that? But yet, you know, again, you look at the world through this west versus China dynamic that Chris mentioned before, you know, we, we think of, you know, there's three really four cloud providers, right?
Google, Amazon, uh, Microsoft and Oracle, let's say. But if you look at, uh, uh, you know, the Chinese, Tencent, Baidu, and, and, and those, you know, they, if you look at the top 10 cloud providers in the world, I think four of 'em are Chinese. We just, they're totally off our radar here.
Well, this is nothing new. Um, you know, I'm going to black and Middle East in a couple weeks and you know, Saudi Arabia and a lot of the Arab countries already have a data sovereignty where data, when you use them, the, the data has to be maintain, or if you have, if you provide services to them, the data has to stay in their country with an approved provider. So what the EU is theoretically doing is, well, theoretically might be doing in the future, is nothing new.
You know, it's just a matter. Saudi Arabia, if they want, they could throw all the money in the world and stand up their own, you know, cloud provider, which they probably did. I don't know the details of it, but, you know, the EU doing this, I mean, you already have, and again, I I must admit, I don't know the full details of this, but you do have instances of like AWS and all these other things which are pretty autonomous within the eu.
Like I know for example, we use AWS Germany as an example where the data is sovereign to Germany. And I don't think they, IRA, the, that was what we used to believe the case. But recently it's come out that even though it's EU AWS Germany or Microsoft France, if the United States government or court system says, I want access to that data in that AWS Germany locale, AWS is gonna turn it over Microsoft.
This Was this, this was buried in the cloud act that Congress passed a few years ago. And then they're like, and the European, So they, they actually, they pierced the veil is the legal term. They pierce the veil of that sovereignty.
And it's no longer enough. They want now, like in Saudi Arabia, they want in essence, locally owned and operated companies that are not part of the US that the long arm of Uncle Sam cannot reach them. What I find really interesting is they're more worried about the long arm of Uncle Sam than they are about the dragon, right?
They used to fear the dragon, One of the odds in Microsoft and AWS just go visit their local congressman and get them to amend that act. So that slim little nuance, not slim To right now. No.
Yeah, no, the national security apparatus won't let that happen. More importantly, from a Microsoft or an Amazon or Google perspective. And Google's also involved in this.
And, uh, Microsoft and Amazon were also named as, uh, key, uh, I can't remember the exact term, but they were key dependencies for the, uh, EU Act, Dora, which is about protecting the financial infrastructure in the eu. And I think from those company's perspectives, this is simply the cost of doing business. And it just raises the cost of doing business a little bit in the eu.
And they will probably raise the prices in the EU commensurate. And, but it's, it's literally the cost of doing business. Just move on from it.
And, you know, the data sovereignty, the concept of data sovereignty from the US federal government, and the same as the concept from the EU governments, which is they all have laws in place that they can go in and grab that data whenever they want. Uh, and in fact, the British and the EU are well on their way towards outlawing end to end encryption for that very specific reason. So it's, I mean, that's a sort of a non-issue from the, the cloud service provider's perspective.
From a customer perspective, that's a big issue, but it's one that they won't be able to solve. And there's two competing efforts in, in this article as well. You know, there's talking about sovereignty and having everything contained within the jurisdiction of whoever it is you're talking about.
And then there's single points of failure and, and one feeds the other. Actually, if you say, I want everything happening in my country now, you're, you're taking out the, the diversity of, of your, yeah. So we have to balance both of those too.
And I think there's a train wreck down the road here. Uh, the question is, which train is going faster? Yeah, I mean, and also look, you know, one of the great things about the internet was its global scale.
You know, on the internet, I'm talking to people in Bangladesh or Bangalore, as easy as I'm talking to people next door and, and all, and it's just one big network and we don't have, you know, firewalls in that way. And we don't have borders per se, it's the internet. But now, you know, and maybe that was naive.
Maybe that was the initial commercial internet period of about 25, 30 years. And now we need to realize just as China's done for years and Russia has done, is that there are borders on the internet and there is, you know, kinda border control. And, and, and that's just the way it's going to be.
'cause we can't have nice things. Alan, you remind me of something. Um, I'm trying to think.
It was, uh, probably around 15 years ago, or close to it, I was a member of the East West Institute and organization. Different governments come send representatives and talk about how can we start controlling effectively security of data on the internet. And the Chinese government had representatives there and we're all talking about, here's all the different things we could do.
And the Chinese representatives stood up when it was air turned and said, I don't know why you're all concerned with this. We have this fixed. And they were right.
Yeah. In retrospect. So, So Alan, what you're really saying is that we're gonna see checkpoint Charlie on the internet.
What do you think? Yeah, I mean, we'll have it east and west. You know, We're, we're already seeing that with China and Russia today, right?
There are services that are really only designed for, you know, predominantly Russian or Chinese speaking folks out there. And they've created kind of their own bubble of information out of all of the internet, which is good and bad, right? Like the internet was this great unifier in the nineties and two thousands, and now we are seeing divergence from that unity, which is natural progression of things, I assume in our current environment.
Well also, I mean, checkpoint Charlie really is today the great firewall of China. I mean, that literally is the, the checkpoint Charlie, and I'll live with that. Yep.
Guys, we're out. We're over time. I gotta pull the plug.
What a great discussion though with some really smart people. Chris, Jeff, Jack, IRA, Mike, thank you for joining. Thank you for watching our Monday edition of TechOne Gang.
As usual, you have TechOne TV right after this. If you're watching the stream, if you're watching this on our OTT channel or YouTube or whatever on demand, thank you for doing so. But we'll be back with more gang tomorrow, fresh gang members, fresh topics.
Until then, this is Alan Shimel. Have a great day everyone.



