AI Safety Gates: World Models and Secure Agent Patching
AI safety gates connect three major questions in the September 29 discussion: when to release a model, how to build spatial intelligence, and whether agents can safely fix software. Alan Shimel, Mike Vizard, Stephen Foskett, Kate Scarcella and Chris Blask examine what enterprises should test before giving AI systems more authority.
The stories span model development, infrastructure and security operations. However, each raises the same practical issue: stronger capabilities still need clear limits and reliable evidence.
OpenAI Scraps Latest Model
Techstrong.ai reports that OpenAI scrapped its planned GPT-6.1 Astra launch over safety and alignment concerns. The panel considers what this reported decision means for teams that rely on frontier models.
For example, a model may perform well on a benchmark yet fail a test of safe behavior. AI safety gates therefore need to measure more than task completion. The discussion asks which tests should block a release and what evidence buyers should expect from vendors.
AMD Acquires World AI Model
Next, AMD’s agreement to acquire World Labs puts spatial intelligence in the spotlight. The reported $8.2 billion deal would bring world-model research closer to AMD’s AI hardware. It remains an agreement awaiting closing and regulatory approval.
World models aim to help systems understand space and physical relationships. As a result, they could affect simulation, robotics and digital twins. The panel explores where these tools might help enterprises and how teams can distinguish a promising demonstration from a dependable deployment.
AI Agent Remediation Struggles
Finally, Security Boulevard examines agents’ difficulty with complex bugs and safe patching. Finding a flaw is only part of the job. A useful repair must close the vulnerability while preserving working software.
Chris Blask’s essay on building human-AI systems adds a focus on context and evidence. Together, these sources frame AI safety gates as an ongoing practice. Teams need clear tests, accountable owners and a way to review what changed.
Explore more conversations on the Techstrong Gang series page.
Transcript
Hey everyone, happy Tuesday. Welcome to Techstrong Gang. And what a Tuesday it is.
There's just, as usual, AI just amoebaring is the best... Is amoebaring a word? It is now.
But engulfing, how about that? Engulfing everything we want to talk about seems to have an AI angle to it. Go figure.
We've got a lot to go over, though, and we got one of my favorite gang kind of combinations that sometimes you just got to roll the celestial dice and see what you come up with. And no, AI doesn't choose who our hosts are just yet anyway. Let me introduce you to our gang for today.
I've got my good friend Chris Blask. Chris, looking good up there. How are you?
I'm good. I have my Slim's Rocker shirt on. We'll get to that.
All right. Well, I'm sure there's a story. Joining us not in her Slim's Rocker shirt is the one and only Kate Scarsella.
Kate, it's good to see you. Nice to see you. Making a rare Tuesday appearance, and he looks a little, I don't know, on the rare side today, actually.
Maybe that explains the tint. He's got a brand-new video setup that he's fine-tuning. Our good friend Steven Foskett.
Steven, good to see you here two days in a row. Pleasure. I would come every day if you guys would let me, but I think that the people- Don't threaten us ...
might object. Oh, I shouldn't say that too loud, actually. Yeah, I know.
Look, anytime you want to come on, we always have an extra Hollywood Square here for you, so not a problem. And then, of course, the man in the middle. Not Charlie Weaver, not Paul Lynde, Mike Vizard.
I don't know how many people got that one, Mike. But- Okay. All five of them are chuckling.
Yes, all five of them are chuckling. So Mike, as I mentioned in the beginning, AI just seems to like an amoeba swallowing things. It's all we talk about.
Yeah, but the pace of this stuff, or at least up until now, has been blinding, but maybe things are about to slow down. Who knows? But OpenAI is saying that they're going to scrap their latest model because, well, they have seemed to have lost control of its behavior and AI agents.
And some of that may have to do with how the thing was built in the first place, perhaps. It is a little too human-like and not enough AI-like, so we have a lot of behavioral issues that go along with being human. But Chris, I know you're tracking this.
Is this the beginning of something? Am I going to turn around now and see Anthropic, which has their IPO statement saying that, yes, their AI model just might destroy the world? Are we going to pull these things back, and have we reached some sort of ceiling?
We've reached something, right? And like you say, Alan, beginning of 2025, right on this very show, on these Tuesdays and so forth, we started to say one out of three of our things every week is AI. And now, for a year, for almost a year, every single one.
All the time. And this is that limit where we realize that just capability is not enough, right? We're testing for capability.
Let's train another large language model, let's modify the harness, let's see if it can hit the next goal. And we're not measuring whether we can control it, right? That might be worth adding to the stack.
And from my narrow view of this, having been involved with multiple standards organizations, we're all thinking through this stuff. What does it mean to have AI governance and systems, AI systems and whatnot? So it's not surprising, right?
You got to remember where we are in time. Here we go. Winn Schwartau, right?
Alan, you got to know Winn, right? I know Winn from... Sure.
What about him? Right. Yeah, he was, as I understand, the first person to talk to the US Congress about cybersecurity and so forth, the Digital Pearl Harbor, the phrase.
Yes. And it was the mid-'90s. And legislators do not understand cybersecurity in the mid-'90s, and we were all arguing about what it meant ourselves.
Now it's AI, it's moving 1,000 times faster, and we're expecting either the governments or the vendors to understand what AI safety and security means. But we haven't defined that yet. So this, to your question, Mike, this is where we go, wow, the next version, faster, faster, faster, faster, faster.
How about we measure whether we can turn it off? Whether it respects its boundaries? Those, as I understand it, sort of aren't on the checklist in vendors seeing if their next product works.
So maybe we're at that boundary where we start checking controls and not just speed. I actually spoke about this on the Techstrong Daily today. The fact that we're going to ask these companies to police themselves is problematic, right?
Mike, they didn't scrap the model. They delayed it. Well, they said previously they delayed it.
Now they said last night, according to The Journal, at least, that they were scrapping this and going back to the drawing board. But there will be a sixth one, right? And the reason was that this model was just going full speed ahead to end the torpedoes and don't bother telling those pesky humans.
There's a problem. But Chris, to your point, you're dead on, right? What makes you think politicians are any smarter now than they were in the mid-'90s?
Quite the contrary. I'd argue they're less smart now than they were then. We had some good people back then.
They certainly aren't AI experts. Asking them for help here. Well, and again, to be clear, in the technical community, at least, again, maybe somebody out there knows something I don't know, but I've been involved with the ISO and ITU and Flying Foundation and FIRST and all these different standards working groups working on just this question.
And we're literally in these rooms trying to figure out what AI safety and security and governance even means. Like, what are the terms we use to define it? So then we back out and say Company ABC that's about to do an IPO for $100 billion and has shareholders or legislative body 123, they don't have rules to make rules by.
We don't have a common set of terms. But I think the commonality gets back to old school stuff, right? Look in the automotive world, right?
Land speed records where some of us are old enough to remember those were still a big thing right at the end there, right? And yeah, you go faster, your car will detonate. So now we can make AIs go faster.
Great. Has anybody checked the tire pressure? Do we have a method for saying, I've got a little list of five here.
I'm going to tell you. Can the agent stay inside its intended scope? Is that on the list to be checked?
Yes or no? I don't see any evidence. Does it respect the authority attached to its identity?
Does it behave correctly when instructions conflict? A little red teaming, right? Can it be stopped or rolled back, and can we reconstruct what happened afterwards?
Now, last one, I'll tell you the answer is no. That's not specified in the specs. So let me ask you this.
Does the controls and the governance frameworks that you're kind of pointing to need to belong in the AI model, or are they things that everybody who uses the AI model needs to wrap around it before it deploys those AI models and those agents? And I guess I'm asking where does the responsibility for the governance going to lie? Yeah, responsibility is a different question.
I'll tell you technically where it can't. So there's turtles all the way down, right? We say models.
A model is this chunk of code that's been trained in the training data. You can put training into them, and the model trainers tend to do that. And then there's the harness.
We say harness, that means a whole bunch of stuff that goes on around an LLM, right? And that can have controls in it. But again, to give you an idea of where we are, right?
Among the working groups I'm part of right now, the recent conversation in September about thou shalt have an agentic AI policy, and maybe the AI policy itself, literally the document should be embedded in the AI system. These are language systems. And they can read documents.
Maybe instead of having a company or a country have a policy and someone trying to interpret that and turn that into ACLs, you literally always have the documents, always have the regulations, always have the controls as part of the training data of the system itself. Maybe inside the models, maybe inside the harness, inside the system of AI systems, embed the rules. Yeah.
So to your point then, it sounds ridiculously common sense, so why wasn't it done that way in the first place, and how did we wind up in this fine mess, Stanley? Have you met cybersecurity? For 30 years, we've had these compliance is not security, but compliance is budgeted, right?
We have not built systems all the way down yet. Yeah. So, Kate?
So, yeah. So, what's funny, or ironic, you bring up the digital Pearl Harbor, I actually did my master's thesis on the digital Pearl Harbor attack. And as I am listening, I can't help but realize that, really, as much as things have changed, everything- Nothing's changed ...
nothing's changed. Nothing's changed. No.
And I think until we actually have... One of the things I hate about the wine tech bros is this throwing up of the hands and being like, "Oh, woe is me. " And I think it's just their way of trying to get away from any sort of responsibility at all.
But until there's this massive... And I was on Security Boulevard yesterday, and Tom and Fernando were talking about this. The idea, until the people who are building these things, until they're actually, we hold them responsible, meaning money, financially responsible when things go wrong, nothing is going to change.
Nothing. No, but hold on. Mike.
Okay. Kate, to pull a page out of President Trump's book, what you're describing is exactly what he said. We have a court system, we have a DOJ.
If they do something wrong, we can take them to court, and we can hold them in for damages and make them liable and make them pay money. I'm saying until it hurts. Nobody's going to do anything until there's a loss of lives.
Until there's something serious. We already have laws on the books for that. It's called criminally negligent homicide.
And until- There's manslaughter. There's all kinds of things I think it's machine-side in this case, but never mind. No, but look, it's not a joke.
Here's the point, is the human who made the machine responsible for the machine's actions. But they are, and we are not holding them responsible. Well, you say they are.
You say they are. They are. Has the court decided that they are?
But we are actually not implementing... What would be the legal term? We are not actually, we're not charged.
No, I'm telling you, look, talking as a reformed attorney, we have product liability laws in this country, right? If I make this a pair of glasses, and it has a very sharp edge, and people get cut a lot, and all of a sudden I make a class action lawsuit for all the people who bought these glasses and got cut, I could basically put you out of business pretty quickly, right? So what I hear is we need a class action suit, is what I'm hearing.
Well, maybe we need to- Seriously ... well, we need to prove real damages. Right.
But do you not think that OpenAI looked at that liability issue that you're describing, and that's what made them blink on this model? Because they're basically- No, I don't think that's what made them blink. I think what made them blink is bad publicity with their IPO coming up.
Anthropic, their IPO, Reuters got ahold of their IPO filing from June, and it's rife with this kind of stuff. Mm-hmm. That they're afraid of public opinion busting down their IPO pricing.
And brand was always a big deal, right? Was that- Brand is a big deal ... when somebody was breached, branding was everything.
It seems to have lessened, but not- But let me go back to cybersecurity. Okay. For as long as I'm in cybersecurity, for 25 years, we have heard, "Doctor, heal thyself.
We don't need government regulation. " Right, Chris? How often have you heard that over the years?
Twice. Or today. No, but I've heard it a lot, personally.
Yeah. Yeah, no, we've all heard this, right? Yeah.
But here's the thing when it comes to this AI stuff, guys. We've got two choices. " Right?
" Or we could take the bull by the horns and start holding people liable and doing something about it. I get that. Right?
I don't think our present, at least here in the US, our present government, both the executive and legislative, as well as the judiciary, though not as much. But certainly the executive and legislative branch have the political will to help us here. I think they've been bought and paid for.
I think the lobbying, the special interests, the amount of money. I did a special report that's out today on Techstrong. If we stop the AI stuff now, we are in deep doo-doo.
You're looking at a 2008-level recession, right? It's not as big as consumer spending, but it actually got damn near close to what we spent on housing last month. That's shocking.
We can't afford. No. The government, these politicians can't afford to bring on the economic malaise that would happen from slowing down the AI freight train.
That's the real issue we're dealing with. I don't know if I buy that. Because some of the older models that currently exist are well able to handle the vast majority of workflows that organizations have.
And we don't need the latest, greatest AI model for every single thing we want to apply AI to. In fact, the use cases for the more advanced models, like cancer research, are getting narrower because they require these massive amounts of compute. Great.
But the existing models that we have are kind of sufficient for 80 to- And what makes you think they're safe? I don't think that they're safe, but they're not as unsafe as the more advanced models clearly are. And I do agree that we need both some regulations and some liability laws, and this is the natural order of things.
We just need to hurry the hell up. Stephen, we haven't heard from you on this. Well, I have a lot to say about AI safety and about models, as we're going to maybe talk about in a segment here in a minute.
But when I first saw the news that they were delaying Astra, call me cynical, but my first response was, it just must not perform as well as they had hoped, and they're playing for time. We've had some situations where there have been great leaps forward with models, and we've had some situations where there were diminishing returns or even steps backward. " But in fact, maybe they were scared that it was going to be some bad press ahead of their IPO for having a model that isn't all it's cracked up to be, or isn't much better than the previous one.
Which is surprising, because to this point, OpenAI still has maintained the lead in terms of model quality, at least according to most of the objective measures that I've seen. So again, I reacted differently and came into this conversation maybe with a different perspective on what was going on over there at OpenAI. Though, it sounds like it rhymes with what some of you all were seeing, too.
I will just go one step further and say just because OpenAI has a delay on a model is not a world-causing economic event. It's an event for OpenAI, but the rest of the AI train keeps moving. Keeps chugging along.
We've got to keep chugging along, though, Mike. We're over time. There you go.
All right. Can we go into segment two? Yeah.
We're going to talk about, well, Meta, which launched an enterprise edition of the Muse platform that they launched last week. And I guess their ambitions are, is to get into businesses, and I assume they're going to start with smaller ones and work their way up. But Stephen, this Meta thing is reminiscent of some of these other AI agents we've seen in the past.
So I know you've spent some time looking into this, but how real is this thing, and per our last conversation, how safe is it? Well, it's really real. Not sure how safe it is, though.
So here's the situation. So Meta released Muse as an app for people back earlier this month, September 26th. It is really impressive.
It is friendly, it is fun, it can do a lot, but unfortunately, it's also kind of terrifying to security researchers who've explained it or who explored it. And this came to my attention first with the stories about Muse, for example, reading all of somebody's messages even though he explicitly denied it access to his messages. Or the story over the weekend of Muse deciding to list an item for sale on Facebook Marketplace, accept a lowball offer, and give out his home address and tell somebody that he's there even though he wasn't.
Oh, it gets worse. So over on the Fediverse, a good friend of mine or somebody I follow religiously, named Johnny Saunders, Johnny over on the Fediverse, followed up with developer Peter James. And they were exploring how Muse works.
" That is a title of what it gives you, not necessarily a description, as you will see. " Well, he's right. It is in fact your own Linux box that you can operate as you choose because Muse runs as root, and so do you, and you can do anything on this box, including read all of the source code of Muse, all of the directives of Muse, modify all of the directives of Muse.
It gets better though, because there's apparently new products coming soon that would allow my Muse to talk to your Muse and give your Muse new capabilities. Like installing arbitrary software off the internet or running things from, that my Muse has decided are good skills in markdown files. Those can be abstracted.
And not only that, but there's a capability explicitly coming that they've talked about already, Zuckerberg talked about this, that would allow Muse to sort of discover useful skills and share them with all the Muses as you're working with it. Now, after exploring this, after reading about this over the weekend, I was like, "It can't be that easy. These guys, maybe they're more skilled than me.
Maybe they're really trying hard. " Half an hour later, I have the entire tree sitting on my Mac, all the markdown files, everything. It was that easy.
And in fact, not only was it that easy, Muse was incredibly helpful. When I said, "I want SSH access," it said, "I can't do that. " Yeah.
So this thing is just wildly wide open. I hesitate to say insecure because it's by design. That's literally what the designer wanted, was everyone has their own Linux machine.
They can do anything they want with it. And, Chris, to your point about turtles all the way down, it's agents all the way down because get this, the whole thing is obviously vibe coded, obviously in Claude, by the way. Vibe coded.
And it has an agent that's job is to make sure that nothing bad is happening. And then it has another agent that makes sure that that agent doesn't have anything bad happening. And then it's got another agent that checks that agent, that checks the other agent, that checks your agent.
It's all wildly bizarre, terribly coded. It's what you think it is. It's everything OpenClaw was, except for everybody.
Cool, huh? There you go. So Kate, back in the day, I seem to believe the word root was a four-letter word in cybersecurity language, and yet we're coming back to the fact that we're giving things root access.
Root access. So why is this? Are we incapable of learning this, or what's going on in your mind?
I can't help but think, and Alan and Chris, for those of us who've been in cybersecurity for a long time, I'll never forget working with some product managers bragging about how they knew nothing about cybersecurity, but look what they built. And I almost feel like one of the problems that we have is that people are not versed in cybersecurity. And because they don't have these good tenets of cybersecurity practices, they tend to have this wide-open frontiers, and everything goes.
And they come up with strange ideas on what they think will be good security practices. And I think for those of us who have been doing this for a very long time, I think we're like, "Yeah, no. " And, yeah.
That's what I think. I think we see it over and over again. I'll never forget someone saying...
Well, this is a stupid joke. I probably shouldn't say it, but anyway, I guess I'm halfway down this road. " And if you're in California, you'll know what I'm talking about.
" And that has always, to me, it's like the magic key, right? And all of us who have worked in these data centers forever, we loved having this access because it would help us to address the issues faster that we had to address when things were down. So at the end of the day, I think it's people who don't have good practices within cybersecurity.
Well, either just... I've got to jump in on that one because the VP responsible for Muse literally reminisces about poking around inside his Windows machine and his Debian machine growing up, and what a joy that was and how much fun that was. This is not someone who doesn't understand this.
This is someone who is proactively celebrating. Yeah, but I will actually join him in the celebration, right? Because this is the way we build our systems, right?
Because you said it, Steven. It's awesome. It's great.
It's wonderful. And if you don't care, or I'll get to my point in a second, if you don't care, great. It's handy.
It is what we want. But if you actually care about security and so forth, you start asking questions, it's like, "All right. " And again, my AI systems have those capabilities.
They quite often p**s me off by saying, "Yeah, I've got to stop here because I need a human to actually tell me what to do," even though I can. Access isn't authority, and again, we caveat like crazy. We're a little tiny company.
Maybe we're wrong. It's early. But every one of these bloody stories, you do want that.
I want that. I don't want to go in and have to do these pedantic things that take a lot of time. That's why we made the internet, much less AI.
But there's got to be some controls. I have to have a comfort level that it's not going to suddenly delete my entire company. And so far, it hasn't.
Again, maybe we're wrong, but we need both. Yes, we want those things, but no, they can't happen in a black box with unlimited authority and no receipts. It's only Tuesday, Chris, so hold on.
You're company. We can be wrong tomorrow. We can be wrong tomorrow.
Yeah. But what I'll say is that I think it's one thing, as a person who had a TRS-80 and would love to play with things, there's one thing to be able to delve into the code and have fun. It's a whole other thing to be principled within the cybersecurity and the foundations, from whether you're coming at it from identity and access management controls, database controls, all the way down the line.
And- That's why cybersecurity is this billion-plus dollar industry now. But we're still allowing, because I believe we just don't have these great principles. And regardless of how many times we have all these regulations, regardless of how much we have built out, are we actually following them?
Look at the secure SS, the secure framework development that we put in place. Look at NIST, look at MITRE. Look at now, thankfully, CRAE.
But are we actually doing this? And I'm sorry to go off on this, but by golly, now you started something. But in the open-source security delivery project that I'm a part of, we have tried to take the framework and tried to make it easy and tried to apply tools and everything else.
At the end of the day, cybersecurity has never been anybody's friend. " So, because somebody can get around and have fun, yeah. We were all like that.
All of us. You've got to bring the booth handouts. You get some tchotchkes to give out, they won't send you away so quick.
But here's the thing. Is it the cybersecurity industry's fault? Let's take Meta.
And Steven, I'm listening to what you're saying, and half of me wants to cry, half of me wants to laugh. Yeah. The other half of me wants to- That's my impression, too.
I'm like- Yeah ... this thing is so cool. Right.
But that's the cool part of it. That's the third half, right? Because you need three halves.
What Chris says is they did this on purpose because look, you know it's wide open. Buyer beware. You want to lock your stuff down?
Have at it. But right now it's wide open. But here's the thing that scares the crap out of me.
This comes from a company that has a long history of abusing people's privacy. Yeah. Of abusing walls, of sharing information that shouldn't be shared, of monetizing your data.
The whole company's built on monetizing other people's data. Yeah. So we act surprised when they come out, and here's the other thing.
They have spent billions and billions and billions trying to get to be a player in the AI space, only to be an also-ran. Well, not- And so the pressure mounts to come out with something. Yeah.
That's the crazy thing, is they're not an also-ran now. This is the number one app- No, I know ... in the Apple and the Google App Stores right now.
And it's getting millions of users. It's being heavily advertised on TV. Well, it's very consumer friendly.
It is. Very. And, yeah.
I want to tell you one more thing about it, by the way, is that it lied to me about the access and information that it had right off the bat. " And it said, "Oh, no, I do have full access to your Facebook, your WhatsApp, and your- ... " There you go.
Oh, sorry about that. That one's on me. So that is out of the box, it has that.
Yeah, out of the box it had that. It never asked you for permission. Never asked me for permission.
I rest my case. This is starting- Mike, let's go to segment three. " You watch the horror movie, and then everybody's afraid to go in the water.
So maybe we'll have a horror movie around AI agents and go from there. But it gets better. There's a new index out, and the index is put together by, I think it was NVIDIA, IBM, Microsoft, and a couple of others, and it kind of shows that we're counting on AI to help us resolve a lot of these bugs and vulnerabilities that are going to be discovered, that are being discovered, and those could number in the thousands soon, if not larger.
But it turns out the index suggests that, well, AI isn't so good at fixing some of the more complicated bugs that are out there, and we may have some issues that require some good old-fashioned, I don't know, software engineers, Kate. But as you look at this index, did you at some point to earlier conversations, laugh and cry? Yeah.
No, mind-blowing, right? Irony. Isn't it ironic?
Who sang that song? Come on. One of us knows.
So yeah. I don't know about that. So- There you go, Chris.
Back to our '80s media stuff from yesterday. " So let's review some of these remarkable stats because I loved it, just loved it. 55% of the failed repairs counted in that analysis, the agents fixed the central problem but left another route open.
Isn't that great? Sounds very familiar. Yeah.
Right? The reported 40% figure here, it didn't mean that they broke the functionality, but basically they made the application and the software unusable with not a successful patch. These numbers were crazy.
So the only thing that I have found with AI is that it's just better. What it's better at is that it's faster. Whether it's faster and better at breaking things than we are, it does a better job at it and it does it faster.
That's what I keep seeing. AI is just doing things faster. Well, it's AI scale.
It's faster and broader. And broader, right. And so it can do it.
That's how it's doing things. But there isn't anything new with this landscape that we don't already know, right? That we don't understand.
But- Yeah, go ahead. But you know what has changed though, Kate? I agree with you, but here's what has changed.
This is a theory of constraints thing, right? For as long as I'm in security, Mitchell and I at Still Secure came out with a product called VAM in 2003, Vulnerability Assessment of Management. Back then, we quickly realized that the crappy scans that we were begging people to do once a year turned up more vulnerabilities than they could fix by the time the next scan was run.
Yeah. And it hasn't changed. Like we said- Yeah ...
in the beginning, nothing has changed. What has changed here is because of Mythos, or post-Mythos, all of these scanners. We now can find 100x more vulnerabilities than we did back then.
We find them at pre-release, post-release, everything else. Yeah. So what we've done is we put more pressure on the next bottleneck, which is remediation, which has always been a bottleneck.
Right. Right? And there's more to remediation than patching.
That's what we're finding out. It's not about applying a patch. Sometimes it's about temporarily isolating or quarantining a particular vulnerable area.
And so when you put that much pressure on that bottleneck, for lack of a better term, stuff happens. Yeah. But it's worse than that because the people that we need to validate the activity of the AI agent are also- Not at this scale ...
yeah, they're overwhelmed with the stuff that they're already validating from the other AI agents. They were overwhelmed before there was AI. They were overwhelmed.
Yeah. That was the problem. Yeah.
We never fixed the problem. Yeah. And now it's just heightened.
Yeah. And I'm not entirely sure that people enjoy validating code from AI. " I don't know, Kate, am I crazy?
No, and that's one of the things that we had problems with when we started to bring in cybersecurity, saying, "This is such an exciting industry," blah, blah, blah. And oh, as you chase the next false positive to nothing. It's been a problem that we have, and it's the same thing when looking at code and everything else.
So- It just comes back to what some of the things that we've talked about, reachability and software bloating. When do we start to actually get rid of our code? Like, really start to fix our code.
And the reachability thing is real. Right. It's something I'm hoping to take on as a project within the CT Foundation.
I'm really trying to do, because you know how much I believe in this. But we, at some point, we're going to have to go into the attics and into the garage and everywhere we don't want to go, and start to go through our junk and really start to clean up. Well, this is what Jen Easterly, the former CISO head- Yeah ...
and now CEO at RSAC says, right? That this is a process. It's going to be painful.
Yeah. But if we live through it, and it's an if- Yeah ... if we live through it, and we come out the other end, we'll have better code.
We'll have better- Yeah ... security. So everybody says, but I'll go to Stephen on this one.
What I've seen is that the code created by the AI is bloated, and so therefore, the attack surface and the number of chances for vulnerabilities being introduced might be higher. On one hand, I talk to some folks and they're like, "We don't see no SQL injection attacks anymore," because they managed to get that vulnerability out. But then we're seeing other things.
So what's your assessment of the code being generated? I hate it. I'm like Gollum when it comes to AI code.
I can't stand it. I can't stand what Claude does to my code. It makes everything worse.
It makes everything bizarre and obfuscated. " And it gives me back something, and I'm like, "What even is this? This isn't mine.
" And that's very concerning, because when you actually read AI-generated code at scale, what you'll find is all sorts of bizarre weirdness. Rewriting the same function multiple times in multiple different ways. Re-implementing things that are already done by libraries that you could just call, and instead creating a new regular expression that does a thing, but only half-assed over here, and then another one over there does the same thing, but in a different half-assed way.
It's terrible. Chris? So that's, I'm going to give this Slim's Rocker shirt in here, and that's a perfect example of it, right?
What we're missing through all this is the ability to pay attention, right? I got to be involved in the early SIM space. That was great, right?
" Right? That's your current state. You have no idea of what's talking to what, and do you want to stay there, or would you like to have some idea of what's going on?
Right? And Stephen, what you're saying that, yeah, these, whether it's the vulnerabilities, to the topic of the vulnerabilities, we're seeing can a patch of vulnerability. " Demonstrably.
Can I demonstrate? And to be clear, I generate, we generate huge amounts of AI code. We use AI to generate huge amounts of code.
Very happy with it. But I won't be finding myself saying the same things that the system did this, and then it did this, and then it contradicts itself because when you're talking about the systems, they keep no records. They have no idea that they just did something, so they do something different, and they make it up over and over and over and over and over again.
And on Security Boulevard maybe today, there's a new article, The Chair the Attention Made, right? Slim's Rockers is a guy here local to Hamilton who makes rocking chairs for playing guitar on. And Ian bought two of them last night.
I'm talking to him. It's like, oh my God. You thought about it.
You paid it enough attention and made 30 or 50 prototypes until you have a low armless rocker chair that leans back so when a person is sitting there with a guitar, it fits perfectly. And no one's done that before. And I think that's above and beyond all these things we talk about every week, right?
Yeah. We're talking about paying attention, right? We've gotten away with not paying attention to cybersecurity because, hey, we'll do it well enough.
That's not working anymore. AI systems that can write code that intrinsically have no ability to pay attention to themselves. They can't even see what they just did.
Well, yeah, they're going to do something different in a microsecond, and they won't... Yeah, that's how you get enhanced. So pay attention.
No, Chris, you're right on. Good job. Virtual high five.
So I got one question for my friend Mr. Slim's Rockers. Did he use AI to come up with this design?
No. Human attention. And I really do think, I know we're getting to the end, but I think as we get through this current miasma, we'll find that this AI stuff, this not AI, but whatever, this stuff we're calling AI, is really, really handy once you actually have it pay attention to itself so you can see what's going on.
And then what's left for humans to do? Paying attention to anything. These systems, as a writer, large language models can generate any human text.
Now, why would they generate any particular human text? Because some human is paying attention to some task. I'm sorry, Chris, I missed that.
What did you just say? Yeah. I'm sorry.
We were all distracted there, Chris. You went on too long. No, but someone on- That's what he told us the other day ...
someone on online commented, "This is the problem with AI-generated text as well. " Right. Let me answer Chris and that person.
And I'm going to go back to what Reid Hoffman at LinkedIn says. You put your name on it, you put it out there as yours, you're responsible for it. Mm-hmm.
You use Claude to code your app, and it's crappy code, don't blame Claude. Blame the person who put it out there with their name on it. You put content out with your name on it and it don't make sense, it's AI gibberish, shame on you for letting it get out there.
What happened to personal responsibility? Now you sound like the old man in a rocking chair with a cane. Oh, well.
Don't play. I got a special rocking chair with no arms. Get me my guitar.
But anyway, this is a good place for us to end today because we're about out of time. Chris, I like that. Slim's Rockers, I'm going to check them out.
Yeah. Stephen, thank you for coming on two days in a row. What are you doing tomorrow?
Hopefully, my news article will be up on Security Boulevard, and I'm actually going to be on the Security Boulevard podcast talking about this next week, too, so. Good for you. Kate, always a pleasure.
You got anything going? Well, you've got your CDF stuff coming up. com is out there, so take a look.
Excellent. I always try to give our gang members a chance to tell the audience a little bit about what they're doing. Watch the Yankees tonight.
That's what I'm doing. That's what we do. No, you mean the Red Sox.
Go Yanks. All right. I tried to correct you.
We'll talk about it tomorrow, but until tomorrow, this has been another great Techstrong gang. You know we come out live to you every weekday at noon Eastern Time. tv, on our Techstrong TV YouTube channel, as well as our Techstrong TV OTT app, which is on iOS and Android and Roku, Apple, Amazon.
If you've got a screen, we've got a video for you. Until tomorrow, on behalf of the gang, thanks everyone. Have a great day.