AI Security Risks, Drone Delivery Mishaps & the ChatTJB Hype Check
Drone delivery is hitting turbulence. Meanwhile, AI hype is colliding with reality. And AI security risk is shifting fast. On this episode of Techstrong TV’s live tech panel, host Mike Vizard is joined by Jack Poller, Tracy Ragan, Jon Swartz, Jeff Reich, and Jiewen Wang. They break down three stories shaping the week. Amazon’s rocky drone delivery expansion, a viral AI chatbot that turned out to be human-powered, and the real state of AI security as model registries become a primary attack vector.
Amazon’s Drone Delivery Expansion Hits a Viral Snag
Amazon is expanding drone delivery nationwide. The buzz in the skies is real. However, so are the growing pains. A viral video showing a drone dropping a package into someone’s hot tub spread faster than any press release. The panel digs into what it says about the gap between rollout promises and real-world execution. The conversation covers logistics, public trust, and whether last-mile drone delivery is ready for prime time.
ChatTJB and the “AI Equals Average Intelligence” Problem
A viral San Francisco chatbot called ChatTJB looked like the next AI breakthrough. However, it turned out to be powered entirely by humans behind the curtain. The panel uses this as a jumping-off point for a bigger question facing the industry. How much of today’s AI hype is genuine intelligence, and how much is average performance dressed up in a good story? It’s a gut-check moment for anyone evaluating AI claims at face value.
The State of AI Security Heading Into Late 2026
AI security is evolving fast. OpenAI just unveiled private safety processing that detects misuse without storing enterprise data. As a result, it’s a meaningful step for enterprises worried about privacy trade-offs. In addition, new research argues that AI model registries are becoming the primary attack vector for malware. And even as AI evolves, the underlying security risks remain familiar. The panel weighs what security teams should actually prioritize as these risks mature.
In short, from glitchy drone deliveries to human-powered chatbots, this episode covers the AI security stories defining the week. Therefore, catch the full panel discussion for the details behind each story.
Transcript
Hey everybody. Welcome to the Friday edition of the Techstrong Gang. And as always, we got a lot of fun stuff on a Friday to talk about.
But first, let me introduce our gang members for this episode. Jack Poller, good to see you again, as usual, on a Friday. Nice to see everybody.
All right. Jon Swartz, still hanging out in California? Yes, I am.
Hello, everyone. Hello. Wicki Wang joins us also in California.
How you doing, Wicki? Hey. Good.
Jeff Reich, always good to see you as well, my friend. What is that behind you today? Today is National Spumoni Day, which is good.
Here it's going to be 104 degrees Fahrenheit, so good day for spumoni. All right. And also in a place that's just as hot, Tracy Ragan, how are you doing out there in Albuquerque?
I'm in Santa Fe, and it's not supposed to be that hot. Oh, Santa Fe. Sorry, my apologies.
90 degrees is generally a really horrible day, and for us to be pushing 100 is just unthinkable. Most people here don't have air conditioners, let's just put it that way. Well, I'm in New York, and it's actually tolerable today, so not too bad.
And it should stay that way for the rest of the week I'm told, but we'll see. Before we jump in, though, I do want to take a moment and acknowledge the passing of Darryl Taft. And those of you who have not known Darryl, he's been in this industry a long time.
He's a writer, news editor, most recently for the News Stack, and before that, worked at CRN, worked at places like eWeek, and if you've been in this business at any length of time, you have probably read something that he wrote. He was, by all accounts, just a classy guy. Well-versed in this tech, spent a lot of time writing about application development, and he will be sorely missed.
I and a bunch of others who have worked with him over the years will be attending his funeral services in Baltimore this weekend. So if you knew Darryl and you're around, check it out, come on down and pay your respects. But with that, I'm going to shift gears and we're going to talk about, well, what's going on in the world of tech these days.
Amazon is out with drones and saying that they are going to be in, I think, 500 cities is what they're totally saying is the number that they hope to be deploying these things. And of course, that led to all kinds of videos being on the web, including one where the drone dropped a package in a pool. Another one, apparently the drone dropped a package on a dog.
And I don't know, I've been telling my kids for years that they need to look both ways when they cross the street, but now I guess I'll have to say, "Look both ways and up," because who knows how many of these drones are going to be flying around out there and what's going to happen. But there are also noise implications and security implications. So Jack, let me start with you.
Are we ready for this? Well, I'm just going to start off saying that I don't understand how this is cost-effective for Amazon to... Drones are not exactly cheap, and there's a lot of tech and a lot of stuff going on here.
And then I realized that just before the program started, my dogs were barking because that was either the third or the fourth Amazon delivery to my house this morning. So they're doing a lot of multiple deliveries and a lot of other things, they're making some money at it, obviously. I think that we are going to get to the point where the noise is going to be a big problem.
If people who live around airports already have a problem with noise of planes, and now you have what used to be a residential neighborhood with now a launching spot for drones that are flying in drone highways across your neighborhood. And I think that's going to p**s people off very, very quickly. These things are not quiet, and in order to stay out of the commercial airspace, they have to be below 400 feet.
So it's not like they're flying high and you don't hear them. You do hear them. So I think this is going to be maybe more controversial than data centers in the long run if they get to 500, because there's going to be a lot of airplanes, small, tiny aircraft floating around in the sky.
There's a noise issue, there's privacy implications. Obviously, they have to have cameras to do obstacle avoidance and to figure out exactly where they are and whether or not they should drop it on your front lawn or your swimming pool. And Amazon has had some other camera problems with the Ring doorbells that they acquired and their cameras, and what data they collect and they have access to.
So I don't see this in the long run being 100% successful. I don't know. Jeff, let me ask you this.
Amazon's not the only one that's trying to do this, right? The DoorDash people are talking about the same thing, and eventually, am I going to have so many of these things flying around out there that there won't be enough room in the airspace for everybody who wants to use these things? Well, I think technically there's going to be enough room, just like there's enough room for all the cars we have.
That doesn't mean we don't have traffic jams. And so, yeah, I think there will be bottlenecks. The highways that Jack referenced, or the airways that are there, they're going to have to expand those, and then there's power lines and private drones, which when licensed can be used as well.
What sort of interference is there? So I think this is something we're going to have to manage. As much as it's distasteful for many people, I'm not certain how we go back from this.
I think too many people want this to happen. It is a step between us and flying cars, and I'm not certain anyone wants to stop that. Well, we'll see.
But John, the Transportation Secretary, Mr. " Except for, of course, the people who had the jobs of delivering this stuff. Oh, yeah, them.
Yeah, never mind about them. They're collateral damage. I'm glad that Jack mentioned data centers because I kind of think about this.
When I saw this story, I think Frank wrote it, this kind of small scale, I think of a small scale war of the worlds in a weird way. So we have these swarms of drones in addition to making noise and maybe dropping packages on animals or in swimming pools. We also, at the same time, have the data centers, which Amazon is building a very controversial one in Texas.
And I think of all this, these noisy, intrusive technologies, it's basically becoming inescapable for people. I know it's going to be convenient for them in the long term, but in the short term, it's just going to be not just emotionally, but physically overwhelming. 55 pounds and 55 pounds.
So how are they going to harness this, this noise navigation challenges, the airspace? And as you said, Mike, it's going to put this transportation, people with jobs are going to be sacrificed. It's going to have so many implications in the name of convenience, and eventually people will grow accustomed to it and use it and enjoy it, but there's going to be a lot of collateral damage before we get to that point.
Tracy, you live in a, I think fairly rural spot if I remember some of the conversations. Is this a good thing from your perspective? And maybe it works in environments like that, but maybe not so much in cities.
I don't know. So I live in New Mexico, and the state of New Mexico, we don't own our mineral rights. Which means that somebody who wants to drill for oil could do it in my front yard.
So when this article came out, it reminded me of that, because who owns the airspace above me? And how much repeated commercial use should Amazon be allowed to have over a neighborhood if they're going to define these delivery corridors? It's not right.
It's just not right. And I do believe that... In New Mexico, we have had lots of lawsuits to prevent oil companies from drilling in your front yard.
And we've stopped it in many ways using some very interesting methods. That's where this is going. Because if you have a neighbor that's getting deliveries all the time, and they're getting DoorDash deliveries as well, and the drone is using your airspace above your house to sort of position where they're going to put the package in your neighbor's house, which is only five feet between the two of you- You're being infringed upon.
Your right to peacefully live at your house is being taken. But John Glenn- So this will go to court. You know what, Uncle?
It's interesting you say that because we have next-door neighbors. They're wonderful people. I really, really like them.
They're great neighbors. But they get about eight deliveries a day on average from Amazon. And I'm thinking if we get to the drone S stage, it's going to be a regular hum or maybe they're not going to be precise drop-offs because believe it or not, we get a lot of their packages that are mistakenly left for us.
So that could also happen with the drones. There's the human error, and I'm not saying drones are infallible, but there's a possibility of all sorts of scenarios. Well, just imagine if your house is part of their delivery corridor, and it's 100 feet over your house.
You're going to hear them all day long. Mm-hmm. Literally all day long, because I'm not talking about delivering to one particular home.
I'm talking about the delivery corridors that they will have to establish if you're going to have DoorDash do it, and Amazon do it, and who else needs to do it. So it's going to go to court. This is going to probably end up at the Supreme Court someday because when your airspace over your home has been taken, you're going to fight it.
You're going to fight it really hard. You're going to hire very expensive... Your state is going to start, your neighborhood, your homeowners' association, they're going to fight it every way they can.
So this is not the end of the story. We're going to see a fight. Wicky, are you concerned from a security perspective that somebody will just hack into these drones and do all kinds of interesting mayhem?
Yeah, that's a very interesting perspective. For all those cars, IoTs, they all have similar concerns. So far I haven't seen the hacker going to do something in this space.
I'm just trying to say economically, why do they want to hack this way? But it is a concern sometimes if the drones can see a lot of overview about your home, right? That's a part maybe need to think about from the security perspective.
Mm. But at the same time, I feel like this news is quite interesting. I heard all sorts of humanity and cultural perspective.
But what surprised me is for this kind of technology adoption, so far it's been like 13 years. Remember the first time when Amazon talk about this? Mm-hmm.
13 years before, right? They come up with these ideas, and then in 2024 or '5, the regulations finally got things working. But now we still see all those corner case, all those humanity.
So I just feel like it's very hard for some technology to adopt in the real world. No matter what you try in the testing environment, how much data you collect, you still try to deal with all those corner cases. And then humans need time to accept it and deal with it, and there are a lot of supporting things like job or regulation or security compliance around it.
Yeah, it's very interesting. Yeah. Jeff, go ahead.
Yeah. I have something that when you mentioned societal, here's a question for society. If you had to choose, what would you take, autonomous drones or autonomous driving cars?
Autonomous driving cars. You didn't hesitate, did you, Tracy? So you'd rather have- Yeah.
You trust an autonomous weapon coming after you more so than a smaller one above you. Which is interesting. I sure do.
I do because the aspect of a drone flying over my house with a camera on it is intrusive to me. Mm-hmm. Yeah, I don't know of anybody sunbathing in their backyard, but apparently that will be on film, so there's that whole issue too.
Yeah. Mm. Jeff brought up, and you brought up the hacking perspective and Jeff used the term autonomous weapons, and I think what we need to think about is, A, hacking for a malicious purpose of the drones, but also the ability...
Right now, drone warfare in Ukraine has completely changed the way the world works in terms of warfare, and the US is scrambling to adapt. But if we have a fleet of drones piloted by Amazon and DoorDash and Uber and whoever else, it'd be pretty easy to sneak in some malicious drones in the middle of that fleet- Mm ... and to hide among the massive group of drones, and then do some pretty terrible damage with a drone.
Yeah. I think maybe Amazon need to give people options, right? Mm-hmm.
Currently, they do have a share of Whole Foods. " Right. But as the- That can solve some of the trade-off issue.
But as the price of gas keeps going up now that we've had the economic D-Day declaration with Iran, doesn't look like that's going to be coming down anytime soon. So Jack, if you look at this, do the economics start to favor a drone versus having people drive to some store somewhere? Energy is energy, and the last I looked, cars are a lot more fuel efficient than airplanes, small airplanes.
Remember, this is a small airplane that's got to go all this distance to deliver- Mm-hmm ... a single package under five pounds. So the efficiency of a panel truck that's also electric, because a lot of Amazon's delivery trucks now are electric, and having those carry 10,000 pounds worth of gear through the neighborhood, dropping house by house by house, has got to be a lot better.
Mm-hmm. Jeff, you live in Texas, correct? Correct.
All right. What are the odds that we're going to see a couple of good old boys sitting on their porch with a couple of shotguns taking down some drones? One hundred.
It's already happening in New Mexico. 100%. I was going to say, no better gun than a shotgun.
I mean, it's happened. It has been happening. Oh, yeah.
It happens all the time here. It's nothing new. Yeah.
So the classifications are- It's you ... do you shoot with a shotgun, or are you good with a rifle? See, that's where the finesse comes in.
Oh, geez. I wonder if autonomous vehicles also start doing deliveries. And again, we talk about autonomous vehicles.
I live in Belmont, and I see at least 10 every morning. They usually travel in packs. It's really weird.
But I think about autonomous vehicles in terms of convenience and, like with drones, there are just too many of them here now. There are more cars on the roads now than ever before, especially in the Bay Area, because people are using both. And I wonder if with the drones it's going to be just overkill, too much.
Yeah. You know what? In Silicon Valley, I think you're driving in the traffic hour time, right?
During the traffic hour time, it's just huge parking lot. No one can move. I think at that- The highways are never good.
Yeah. Yeah. At that time, I really want to fly to my home.
I guess it's like during that delivery time, the drone is much, much better than the cars. Yeah. You fly cars anyway.
Well, this technology, it doesn't doubt me that Silicon Valley would embrace it. But I don't know if Boise will. I think if the folks in Boise have more of an opinion like I do, I purposely live out in a rural area.
I don't want something flying over my house. And yeah, we would shoot it. No problem.
I wouldn't even think twice about it. " So this is a cultural- Good practice ... it's cultural, right?
And- Mm. Although, Tracy, I have to say though, having lived here most of my life, there is a definite backlash against AI here, more so than you could imagine, and against big tech and against the bros. There's a whole era, it's generational type of thing, based on the older you are, the more resentment there is towards tech and how intrusive and noisy and greedy it's become, so.
Hold that thought, because we're going to move to that in a second. Oh, sorry about that. Yeah.
But I just would just ask one quick question here. Jack, are we just going to stay in our houses forever now and we don't have to go out anymore? Because most of the time anybody does anything is to go to the store, and if they don't have to go to the store...
I got to tell you, we're unfortunately well down that path already. My wife recently retired and has been struggling because Three quarters of what used to be meetups and to-do activities, like book clubs and stuff like that, are all now online. There's no way around it.
She's very frustrated. " Right? Yeah.
It can be very frustrating. And I think we're purposely doing things to try to get out of the house and we now, a whole bunch of us, me, Tracy, Jeff, I assume John, all work out of our houses, right? So I spend most of my time in the house.
It's a joy just to get out to do the food shopping, which would- Yes ... usually pain in the a*s, right? Yes.
I used to hate grocery- I don't know, like- I used to hate grocery shopping. I don't want to do the grocery shopping. Yeah.
To your point, Jack, I did not like grocery shopping. I look forward to it now. I do it twice a day now, just to get out of the house and break up the routine.
Isn't that pathetic? Or we live on a trail, so I go off on a trail for 20 minutes at a time just to re-energize myself because I know the people who live here, so I can socialize with them. It's me- Well, that's why you have a store-bought coffee in your hand after a- Yeah, I do ...
little coffee meeting right there. Because I would never make it home because I have to leave. This is going to sound weird.
Do you feel as if sometimes maybe your wife feels this way? Like in a sense, you're kind of in a self-imposed prison because everything can come to you rather than you- Yes ... go to it?
All right. We've got to move on, but I'm just going to say the following. I think everybody should come on down to the rooftop bar to socialize.
Bring your shotgun, and we'll shoot down some drones and then maybe talk further. That sounds like a blast. How about that?
I'll be there for 7:00, Mike. I'll be there at 7:00. All right.
Let's move on to some other silliness that's going on in the world. " And it turns out to be, well, just some guy who answers people's questions and gives them advice. John, what's going on here?
Only in California, right? So there's this guy, his name is Tucker Bryant, and he created something called ChatTJB, which I believe are his initials. And it's this whole idea, or it's a satire, but also it's somewhat of a serious business model that trades LLMs for human labor.
So basically, I'll tell you how it works. You type a prompt and you're not connected to a massive neural network backed by billions in capital investments. Instead, your inquiries are answered by this guy himself or thousands of volunteers, and their acronym for AI stands for Average Individual.
So he claims they've been speaking to about 1,000 people a day about where they should go to dinner, what color to paint their homes, et cetera. And his notion is that this motivation behind this ChatTJB kind of stems from this growing psychological phenomenon called cognitive surrender, which was coined by these two Wharton professors. So their research shows that while AI assistance boosts user performance when the technology's correct, reliance on flawed AI output causes human accuracy to drop sharply.
So in a sense, I'm not familiar, this is kind of weird, but there's this practice of human labor under the guise of automated software, which we call pseudo-AI or Wizard of Oz interfaces. And again, this is partly a joke, but I also think it's a kind of a nod to some of the inaccuracies in ChatTJB. But again, you know what he did?
What he succeeded in doing was getting us to talk about it and getting a ton of coverage. And- There you go ... that's ultimately was his goal.
So here's the thing that struck me about it, is that a lot of the folks I talk to now, pretty much everything that they are doing, they check with the AI agent first. They run it through some sort of decision-making thing when they go, "Is this the right thing? " And I don't know, Tracy, has this become something of a crutch for everybody, or what's going on here?
Can we not go to the store without asking ChatGPT for help? Apparently not. I think that this isn't really a story about AI being fake, but it's about AI being oversold.
Mm-hmm. Do we really need to ask ChatGPT or Claude what color pants we should wear on a given day? It's ridiculous.
Yeah. But on the other side of the coin, we had Builders AI. Remember those guys?
Yep. And they've made how much? 450, $500 million they raised for- There you go.
Yeah. So, you know. On the other hand, Tracy, I'll ask the panel.
When's the last time you walked out of the house without your cellphone? I do it all the time. Only because I live in a really remote place and I don't get access anyways.
If I take it down the hill, it blows up with all my text messages. Right. See, most of us are like, we've gotten to the point now where we walk out of the house without a cellphone, and we run back in because we have to have it, and you don't need the cellphone.
I grew up in a time where nobody had a phone, wasn't connected to the world. You were disconnected from the world, and you had to go out and be part of it, get out of your house, right? And- Mm-hmm ...
you don't need to ask the-- I agree with you, Tracy. You don't need to ask the AI for anything. Just go do.
It's oversold. How are you going to post on TikTok or Insta what color pants you're wearing if you didn't have it? That AI told you to wear that color today.
But Jeff, to your point, without trying to be a contrarian, I grew up in an era where the dashboards for cars were solid steel. Yeah. So there's a lot of advances we have right now that are really good.
And I often leave with-- And actually, Tracy and I, John, gave you the same look when you said you go grocery shopping twice a day because she and I, when grocery shopping, we have to put a cooler in the back, and then it's going to be a three-hour trip. Yes. It is.
Exactly. That is exactly how I grocery shop. Mm-hmm.
My problem with the AI, though, is the answers are so sycophantic, right? Yes. Everything is wonderful, what a great idea.
And John, I can't help but wonder, and maybe this will be the East Coast version of it, but if people are putting inquiries to humans, will the humans respond with smartass answers, or how's that going to go? I think it might be refreshing, actually, to not have somebody say, "Oh, what a wonderful idea. " I guess that's kind of the echo chamber.
One of my frustrations, I don't know about the rest of you, is whenever I use AI, I always think it's too agreeable. There's not enough pushback. Claude will push back occasionally, but I don't want a yes-man or yes-woman to be telling me everything I do is correct.
And it's weird, too, because when I'm grocery shopping, which I do every day, I hear people walking-- This is in California. Maybe it happens elsewhere. They are talking into their phone, getting advice on what to buy.
They're talking to themselves, but they're also talking to this disembodied voice. And I'm starting to hear more- Are you in San Francisco? Are you sure they're talking on a cellphone?
There's a lot of people who do that without even a cellphone. I knew you were going to say that. I knew you were going to say that.
Maybe the phone is dead. But they're talking into something near their head, and I just think it's part of this culture, right? You feel naked if you leave the house without your cellphone, or you feel like you've been exposed somehow, or you're less than who you could be.
And it's a sickness which is worse than anything social media did. And I think it's all-encompassing. Our lives are so tied into this stuff, and AI has just accelerated it.
And I think, as Tracy said, it's just too much. Wiki, are we losing touch with our humanity? What do you think?
You know, this one is quite interesting. I'm just wondering, right? Since you have so many human friends, why do you choose to talk with something like this and just try to use AI as a middleman and then talk to the other guy?
Even though people think it's an AI product, it's quite interesting. But from the other two perspective, I feel it's interesting, too. One is privacy, right?
You thought you were talking to AI, actually you talk to the other human, and you don't know how they want to deal with your data. That one is kind of interesting. And then second one, I just feel like maybe we should understand how much is human in the loop for different AI products.
Mm-hmm. It used to be if some company mentioned AI, their stock price go up a lot. Mm-hmm.
But I don't feel like it's sustainable for current situation, right? Like this one, when you talk to AI, not too many- No ... people will buy the extra prize or something.
I will share this story. So, it was shortly after COVID, and I guess I was on a golf course and my vision was blurry, and I couldn't quite see the ball right. And I turned to my cousin and I said, "Tommy, man, I'm having a hard time seeing this ball.
" Oh, man. Oh my God. Oh, that's brutal.
Oh, man. Wow. So, sometimes when you get that response from people, maybe the machine is better.
Huh? You better listen to that. Yeah.
We also live in this culture, this time, where there's so much negative confrontational behavior. Even among friends over the silliest things. " We just want some sort of, I don't know, positive reinforcement.
You're right. People want that. You're right.
Yeah. I just feel like I'm a little bit old-fashioned. For certain things, I still prefer to see human and talk to human.
Mm-hmm. I feel it's the important part. The important thing though- Yeah ...
it was successful because they were actually talking to somebody who was more human. Yeah. Maybe.
Yeah. See, I'm a cynic, and I'll just say that a part of me thinks that it's successful because this is the exact same thing that happened six months or a year ago with OpenClor, whatever it started out as, where everybody all of a sudden ran out and bought their Mac Minis so they could run this cool thing. It's just like, "Oh, we got a cool new AI thing.
" It turns out it's a human. They're like, "Oh, cool, it's a human. " Right?
This is what we do in the Valley. I don't know. I laughed when I read this because I was reminded when we had newspapers, and John, you'll remember this very well.
We still have newspapers, just nobody reads them, and they're like this thick now. Yeah. John, people used to write in to Dear Abby and ask for advice, and she would write it up in the paper and share it for everybody to read.
So it's this kind of Dear Abby all over again. Maybe, yeah. Those TV shows like Judge Judy, in a sense, they're legal shows, but they're also advice shows or shows that there's kind of interaction or connectivity between you and who's speaking, like you're getting advice from someone.
Right? Because she in a sense is kind of like... I think of her as kind of a philosopher in addition to being a TV personality, and I think humans just want that, right?
They want to feel as if they're connected to someone who has some sort of authority or can maybe help them, and I think he's touching on that. Although, I think in the case of this, this guy's actually playing for some sort of investment, and this is a business enterprise. He's going to see how far he can take it.
I'm sure he doesn't need the money. He worked at Google, but... I'm going to leave this here, but it occurs to me, you could take all the Dear Abby and Ann Landers columns, shove them into ChatGPT, call it Dear AbbyGPT, and you're off to the races.
There you go. New business model right there. All right.
I'm going to shift some gears. We're going to have to have a little more serious conversation because, well, we are making some progress maybe on AI security in both OpenAI and Anthropic are talking about things that they are doing to make sure that our data doesn't wind up in places we didn't intend it to be. And a lot of folks are at least talking about this conversation now.
And I don't know if it's too late or not, but Wiki, what's your sense of what's going on here? Because on the one hand, I'm kind of pleased to see that they're doing something, but on the other hand, I also thought they had told us that they weren't using our data to train their models in the first place. So how come all of a sudden we've got to have a new moment here to say, "Oh, wait.
" What's your take on what's going on here? Yeah. I think there's a real trade-off here.
First of all, I want to give some background information for this one. OpenAI just recently announced a private safety processing this week, letting it detect misuse usage patterns across related interactions, while preserve zero data retention for enterprise customers. I think this one is positioned as opposite to as rapid 30 days retention policy for its most capable models.
So, if you want to detect some complicated misuse, sometimes you do need to look around multiple interactions. One prompt by itself may look completely okay, but it's only when you put 10 or 20 interactions together, that starts you can see the pattern. And, I think we talked about this recently a lot, for the supply chain security area as well.
But then you have the other side of the problem. Enterprise really don't want to have the sensitive prompts or outputs sit around somewhere if you don't have to. This is basic for the privacy.
So you have this tension between visibility of security and data minimization for the privacy. I don't think the interesting question is whether OpenAI or Anthropic is right. I think the enterprise question is: What is the minimum amount of information you actually need to keep to detect, and how do you prove that the control works?
How long you want to do the retention? So I think the key here is try to see in your company law, the privacy retention is more than just a privacy policy question, right? You need to think from your environment and, how much trade-off and the risk appetite in your company.
That's my point of view. Interestingly, recently, I was preparing this week's newsletter for the security and compliance. I saw there was a very interesting post.
They are now talking about privacy and security conflict only. They also add additional elements on the IT portion. Because IT is always like, "Okay, once there's something like AI happening, my job is to make sure the facilities is there and everyone is working on it," right?
" So all sorts of things, if you combine together, it becomes to the how do you want to make sure you set the right priority in your company, how to governance your environment, which is very interesting. Yeah. All right.
Jeff, you want to say something here? Yeah. I have in the past been both a security officer and a privacy officer in different jobs, and there's always been a strange relationship because you can't have privacy without security.
Yeah. But if you do enough security, in some cases, depending on the effect of you violating privacy, there is a model at a different scale kind of that works for this. I served on the PCI council back when it first started, and the reason I bring this up is there is a standard.
Part of the standard, PCI standard, says that you cannot retain identifiable credit card information once a transaction finishes. So the lifespan of that data to be retained is defined by the standard. You can create a token to represent it, but you can't keep the data.
I think that model's probably going to end up having to work here. I can't come up with another way to do this without finding a way to anonymize data, tokenize it, and not keep it. Well, yeah.
We've been told not to keep data forever and a day, but we keep the data anyway, so what's the problem here? Well, I think there's sort of two conflicts that we're looking at. I think Wiki and Jeff both raised the data security/data privacy conflict, and as Wiki alluded to, it is very hard to detect long-running slow attacks with looking at instantaneous data.
That's why we have SIMs that collect data or telemetry data and then analyze it over 30, 60, 90, 180 days or longer because a lot of the attackers take that long-term viewpoint, and you will miss things if you don't correlate events that happen far out in time. So there is a very valid need from a security point of view to collect that data to be able to analyze it over a long period of time. There's another conflict here that I think we're missing the bigger picture, which is this is the first in many of, "I do something better or different than you do," in the battle between Anthropic and OpenAI in their efforts to get the biggest bang for their upcoming IPOs.
Bingo. Yes. " And well, three weeks later, we released it to the public anyway.
There's a lot of PR behind the scenes here going on. That's not to say these aren't real. These are very real interesting things, but my approach versus your approach is what we're talking about here for rather than what is the right thing to do, which is what I think Jeff is saying is the right thing to do is this sort of tokenizing, whatever.
But I didn't want to lose sight of the fact that there's a bigger picture going on here- Yeah ... of IPO prep. I'm glad you said that, Jeff.
I totally agree with you. I laud OpenAI and Anthropic with balancing corporate privacy with misuse detection. But this is part of this current AI narrative about security and privacy.
They're both stressing it because they're both going public, and that is, I think, the ulterior motive. " Better late than never, but Tracy, it gets better. The model registries themselves are becoming part of our software supply chains, and well, it turns out that they, from all perspectives, are kind of naked.
So, are we just going to have this whole issue all over again where the software supply chain isn't going to be secure, so whatever we did on the data side doesn't really matter because everybody's going to find the data anyway? What do you think? Yeah, it's interesting that AI does a lot, but it doesn't repeal the basic cybersecurity fundamentals.
We still have supply chain attacks and risk. We have untrusted artifacts, credential theft, all of these same things that we've been working on for quite some time. Literally, we have spent decades learning not to just blindly trust downloaded software packages.
We scan them. We look at them. We interrogate them.
But we're having to learn this lesson all over again, and you can't really do that with a... You download something from HuggingFace, you get an AI bomb now, but we don't really have the tools to do what we need to do. So unfortunately, now we're blindly trusting the stuff that we download when it comes to AI, which is kind of insane if you think about it, considering the road that we've gone down and the practices that we have established, and we're just throwing them out the door when it comes to AI and these registries.
I'm still completely enamored by the HuggingFace attack with Artifactory and going out and finding a zero vulnerability and immediately exploiting it. Isn't that amazing? I love that story.
But that's what we're facing, right? That's where we're at now, and I'm glad that Wiki pointed out these basic fundamentals and how interesting it is that we're having to now go back and revisit this. Okay.
We know how to fix this problem. We just have to now fix it for a new technology. That was amazing in the sense of a traffic accident was amazing.
All right. I can't stop looking. All right.
Jack, maybe I'm going to push this a little bit, but work with me here for a minute. " And suddenly all these things are interconnected in ways that you may not think was intuitively obvious. My response might be, may I...
Are you hanging out on, what is it, Polymath or whatever the betting place, right? Polymarket, yeah. Oh, thank you.
Polymarket, not Polymath. This is Polymarket. Something else, but yeah.
Let's look at what Polymarket has to say about that, because I say that the probability is pretty high. Not that Anthropic and OpenAI and Google and Microsoft and Amazon aren't already the subject of an almost ongoing onslaught every microsecond of an attack being launched against them, and they're very good at that. I actually think that the attack vector will come in through, as usual in our world, stolen credentials, or the supply chain is where it's going to be, or most likely a zero-day vulnerability not on Anthropic but on some tool that is chained into it and gets access credentials that way and comes in, and that's where the data's going to get stolen.
And it isn't going to matter whether it's retained in Anthropic or OpenAI or not, because it's going to be stolen right at the point it's transiting from the enterprise in or out. Kudos, Jack, for explaining that. Thank you.
Yeah, very good, and don't try that at home. It's going to happen. It's going to happen.
Yeah, and I am starting to worry that with all these new betting markets that are out there, that all kinds of things that are somewhat tangentially related are going to get tied together in a way that someone's going to drive an outcome with. John, is that the new reality? Well, we did a story.
I can't remember. These all blend together after a while. But there were a couple of states looking into that, right?
This possibility of ginning the market or influencing the market, and yeah, I see that possibility happening. Regulators are looking at it. Wasn't that a Bond movie plot at some point?
At some point. Absolutely. Apparently, they are investigating some military personnel who made a lot of money on the Polymarket all of a sudden in ways that were not explainable by the fact that they either had some inside information.
But hey, if politicians can have inside information, why not just the average person? So you've got to ask yourself, what's the right and the wrong of all this? But I'm going to leave that there.
I would just remind everybody that every action has an opposite and equal reaction in ways that we don't anticipate. So think about it for a minute. Thank you all for participating in today's show.
As always, you guys were awesome, and thank you all for watching the latest episode of the Techstrong Gang. Please stay tuned for the rerun of the rest of the lineup of the Techstrong TV show, and we'll see you all again Monday.



