AI Trust: Election Influence, Security Backlogs, SAP Agents
AI trust connects three distinct debates on Techstrong Gang. Mike Vizard joins Jon Swartz, Elizabeth Safran, Robert Reeves and Andi Mann. They examine election influence, growing vulnerability backlogs and SAP’s agent workflow ambitions. Each story raises a practical question: what evidence supports confidence in the system? The panel separates reported findings from allegations, opinion and vendor promises.
AI trust and election interference
Security Boulevard’s election-security report examines CISA’s plan and Defense Department coordination against foreign interference. Experts question the timing and scope. Protecting infrastructure does not automatically protect people from manipulated information. Anthony Vinci’s New York Times opinion essay argues for stronger source checking as AI persuasion develops. It offers an argument, not proof that AI changed votes.
Nacionale’s report on alleged Claude use concerns pro-Russian campaigns in Central Africa. Its full text was unavailable for independent review here. That limitation matters, so the panel should treat the headline claim as an allegation. Meanwhile, the Pulitzer Center investigation into AI propaganda describes production and distribution tactics. It does not establish a measured effect on election results.
Vulnerability backlogs outpace remediation
Mike Vizard’s report on HackerOne’s vulnerability findings highlights a widening operational gap. Validated, unresolved backlogs grew 131% over two years. Resolution rates rose 54% over the past year. Average resolution time fell from 135 to 62 days. These measures cover different periods and should not be treated as interchangeable. The findings describe HackerOne’s analysis, not a census of every organization.
Faster discovery alone cannot close a growing queue. Teams must decide which findings deserve urgent engineering time. Leaders should also examine ownership, prioritization and the capacity to finish fixes. The discussion asks whether teams need more findings or a better path from validation to remediation.
SAP brings agents into business workflows
SAP’s Joule Work rollout aims to coordinate SAP and third-party applications, data and agents. SAP expects more than 400 agents in its catalog by year-end 2026. That forecast is not today’s available inventory. SAP’s context and orchestration claims also need evidence from real deployments.
Business workflows need reliable permissions, clear exceptions and accountable decisions. The panel asks where human approval should remain. It also considers how enterprises can test agent behavior before expanding responsibility. A rollout announcement starts that evaluation; it does not settle it.
Across these three stories, AI trust requires evidence and clear accountability. Election influence demands careful attribution. Security backlogs demand completed fixes. SAP’s agents demand tested workflows and deliberate oversight. The panel focuses on the decisions leaders can scrutinize rather than assuming speed alone delivers trust.
Transcript
Hey everybody, welcome to Techstrong Gang. It is Wednesday, aka, I'm Mike, and so therefore it must be hump day, right? So that's how that goes.
Very nice. There you go. But let me introduce our guest for today, John Schwartz.
How you doing, my friend? I'm good. Everything's wonderful.
Excellent. Wow, man, because you must live in some unique part of California I've never heard of before, where everything's wonderful. I live in a bubble within a bubble.
I try to ignore what all these insane people who live out here do. I- That's the only way I can... My coping mechanism is to try to, yes, stay away from as many of them as possible.
I'm very familiar with that bubble. I used to work in San Mateo many years ago, so I know how it works. All right.
Speaking of bubbles, Robert Reeves, how you doing, my friend? You're down in Austin still, right? I sure am.
Just enjoying this great weather after the cold front came through, and it's finally in the 80s. We're so happy here. Wow.
That is good. Speaking of bubbles, last time I was in Austin and I had a cab driver who was complaining about all the Californians that had moved to Texas and were bringing with them all the problems of California. So they were basically saying it's another bubble.
Well, ironically, if you look at the data, most of the immigration to Austin comes from Houston. Go figure. Which tells you something interesting is happening in Houston.
Who knows? But all right, speaking of immigration, Andy Mann, are you actually in Spain today? I am actually and literally in Spain today.
I'm coming to you from downtown Girona, in the country of Catalonia, depending on who you ask. Nice. Andy has recently departed from Denver, and it wasn't even at the request of the immigration folks.
You did this voluntarily, right? It was my choice. All right.
And then Liz, how are you? Liz, you're in New York, right? I am, yes.
Liz and I are both in New York, which is an international city in its own right, because we have everybody. Anybody who's been anything, any place in the world, has somebody who lives here in New York I've decided. Yep.
So yeah, at some point, maybe there's a half a dozen cities around the world that should just become independent city-states because they're just too international to really belong to any one country anyway, but there's a thought for the day. But speaking of crazy thoughts for the day, we're going to talk about the midterm elections, because, well, it's been two years since the last major one, and that one was kind of insane, and since then, AI has just exploded. It's everywhere, and the capabilities that are provided are mind-boggling.
But it turns out that AI is being used pretty extensively in various disinformation campaigns, and the folks at CISA, which has been arguably gutted, are now getting some help from the Department of Defense, aka the Department of War, to help us protect these elections. Or at least that's the idea and the concept. But John, it looks like the folks in Russia are stepping up their campaigns as well, and my question to you is can we trust our eyes and ears anymore?
What's going on here, and how does this play out? So from what I could gather from the story, the Defense Department and CISA announced these plans recently. They've had two years between major elections, so they want to secure the midterm elections, but they announced this idea against admittedly traditional threats like vulnerable systems, insider threats, and compromised databases.
But the two questions I have, and I have a lot of issues with this, is that they waited so long, and they're also part of an administration that gutted CISA in the first place. And they're also working with an administration that's doing everything it can to try to foment confusion and chaos before these elections. And in a sense, also, maybe they're missing the point because within the story, there's a CTO at Illumio, Gary Bartlet, who points out that the adversary today doesn't necessarily compromise the infrastructure so much as AI-generated content.
We're talking about influence campaigns, disinformation to undermine our trust. So this is going on. At the same time, there's a story that we did involving some claims that Claude has been used in pro-Russian campaigns in the Central African Republic, and this model's been used to create propaganda content and support different disinformation campaigns within several countries, including the Democratic Republic of the Congo, Kenya, Sudan, and Mali.
So I really wonder if this is for show, because there's this idea that defense departments are going to try to protect us during the election, because at the same time, we're hearing rumors of martial law being imposed, ICE agents or agents of the federal government being deployed at voting centers to dissuade people from voting. So I don't know. This just seems like a half-hearted measure that was thrown out for some political reason to undermine our fears that we have about our own administration.
That was my takeaway. It's kind of funny about this whole thing because if you listen to folks, they're trying to make an argument that says there's some sort of fine line between disinformation and freedom of speech, and therefore I'm allowed to do and say whatever in the name of freedom of speech. And as a student of history, I go back to Jefferson versus Adams, and they had these pamphlets.
And they made up all kinds of crap in those pamphlets that had no bearing on reality, and it seems like we're just playing that whole game out in spades here in the age of AI. But Liz, let me ask you, is there anything to be done about this, or we just have to hope that the average citizen is smart enough to figure this out? Well, I don't know what can be done about this right ahead of the election.
I agree 100% with John that the timing's a little too little too late. But my question is, is it CISA's job to police all the disinformation because this has been happening on social media platforms that they can't control? So in theory, I can understand that the federal government should take a role in policing that, but do they even have the means?
That's one thing. And then the other thing is the whole thing with the Department of War. And not that I'm going to put my tinfoil hat on right now, but I do believe that could be a pretext for having people show up at voting centers, because that's part of what the whole storyline about ICE is.
Anyway, I digress. I'm just saying that I feel that this is security theater. Liz, what you said actually sparked something in me.
The CISA, why was it dismantled in the first place? " Yeah, 2020. And so consequently, that is a shell of what it used to be.
So the idea that this new version, this new emasculated version of CISA is going to be looking over things, it just strikes me as totally bizarre. And this is the administration that felt that the election was rigged last time, so you'd think he'd want to bolster election security. They waited until literally weeks, yes.
Robert, is there anything that could be done by the average, I don't know, technically savvy individual? Are there things that we could do as people that maybe we all look to? Because, well, the cost of monitoring this information is dropping, and AI is automating a number of things, and I can't help but wonder if there's some other way of thinking about this that doesn't rely on the government.
Well, DMCA. The platforms cannot be held responsible for what is posted on those platforms. And you're right about free speech.
So how do you fight influence? You bring your own influence. So folks are going to have to, on the other side, or a different side or a different point of view, they're going to have to use these same tools.
But we've dealt with this problem before, gang Mike is a student of history. When Pulitzer and Hearst are going head-to-head in the Spanish-American War. But it's really interesting because the folks, the one party was really reading those papers, and the other party was not, and that other party was making the decisions.
And so, what needs to happen is a counterpoint. We can't monitor speech and really prevent speech in this country. It's not a good thing.
But at the same time, if one party or a group of people are doing something, then those other folks that are affected and believe differently, they need to get involved. So, use the tools. If influencers are enforcing this, great.
There's plenty of other influencers that have differing political opinions. All right. So Andy Mann, AKA Captain Observability.
There's a saying that says, anytime you're looking at any piece of information, you should consider the source. So is it going to be possible at some point in the future, or maybe now, to trace back the source of some sort of campaign and information or whatever it is that was generated to where it was coming from? So if the original source for this thing is some obscure server sitting in the middle of Africa that Russia is using to launch a campaign, maybe people should know that, and we can surface that.
Yeah. Notwithstanding Utah's attempt to ban VPNs, which has recently been struck down by federal court as literally impossible. This is absolutely knowable.
This is observable, if I may. Look, we know this is true. We saw what happened when Twitter, and whatever it's called, decided to all of a sudden show where people were logging in from.
And all of a sudden, we realized that half of Twitter was logging in from Kazakhstan, Uzbekistan, from literally from Russia, from Crimea, all over the place. And they quickly backed that off, right? And Section 230 of the Communications Act, exactly right.
We've got the tools even to be able to deal with this if we want to. But I think we've decided as a nation, and when I say we, that's the very rough royal we, and I use that term advisedly, that we don't want to know. We cannot accept money from external countries for campaigns, but we've decided that propaganda is okay.
And we know where it's coming from because we had a whole four-year cycle of Republicans investigating Republicans and finding out that, yes, there was propaganda, there were bots. There were votes not changed at the voting booth, but changed in people's minds. And we know that, too.
So look, this is absolutely observable. We can use technology. We know where these communications are coming from.
We know who's signing into Facebook, X, wherever it is. We know who's posting YouTubes. We know how YouTube and TikTok algorithms are working.
These are all observable things that are happening in the world. We can absolutely find out if we want to. Unfortunately, apparently, the sanctity of our democratic election is a partisan issue, and that, I think, is at the root of this problem, not the observability of it.
Mm-hmm. So Liz, we don't seem to have the will on the media side of this equation, whether it's in social media or I guess I'll call it the unsocial media as a collective for this thing. I'm not quite clear what the difference is these days, but nobody seems to be making a great effort to go find out the source of this stuff and expose it.
And so is there some sort of vested interest at work here that we don't all see and realize? Apathy, complacency. I feel that it's structural.
What you were talking about, this is not a new thing through history. There's been examples of this kind of propaganda. I think AI and social media has enabled that to propagate at scale.
So I think that's a big difference, and I think that if we're leaving it to we, the people, to make better decisions and to be more discerning about that, I fear that at least in certain generations, that have been raised on social media, they're already in these silos where they might have lost the ability to be discerning because they've been indoctrinated into these opinions that are increasingly siloed, right? There's less discussion on both sides of an issue. They just hear the algorithm feeds what rage bait.
So they're just getting fed the same thing over and over again, and they're not flexing those muscles. So I think that's a big part of solving that problem is addressing that aspect of it. Yeah, we all live in these echo chambers, some of our own choosing, especially with social media now.
Actually, the messaging has become even more, I think, influential over certain people with the use of AI. There are things that I see through X and even through Facebook, although I don't use Facebook that much, that are very persuasive types of arguments for those people who are not educated. And that's the other thing, you mentioned complacency and apathy.
I don't really mean to be this brutal about it, but I can't think of a voting base of a country where there's just less people engaged in terms of knowing issues or knowing what's going on in the news cycle. That's why a chunk of them, 30% of them, are consistently boondoggled or bamboozled by the administration with what they're told. Right.
But just to be fair, it's not just the administration that's tossing around these things. Yeah. It's all sides.
It's all sides. Yeah. But they're learning from the best.
So, I'm not going to give a free pass to anybody because there are a number of candidates on each side where I see some of these ads just on even this terrestrial television during football games. They're highly persuasive ads, but they're total b******t. Mm-hmm.
So I don't want to go on for this forever because I could devote the entire show to this, but I would just say two things about this. One is, if you don't demand transparency into the sources of the content being surfaced to you, you will get what you deserve. So I think collectively, as a society, we need to start really making a push here to say, hey, we need to understand where this thing came from and how it came about, and maybe demand that from the media providers or wherever place you're consuming content from.
Secondarily, I'm pretty sure that most people have already decided what they're going to vote for one way or the other. Most of these campaigns are really designed to achieve one goal. They are trying to convince more people to stay home and not vote because you're exasperated on a particular topic.
And that's deliberate because the difference between an election won and an election lost is roughly somewhere in the 2% to 5% range. So basically, all these people are trying to make an effort to try to convince the other person's team to stay home. So, I care not necessarily whom you vote for, and I'll let you go do that on your own, and I'm not going to drive you one way or the other.
But I would just say is you have an obligation to go vote. If you don't vote, you're making a choice, and you're giving in to all the noise and all the propaganda, because that's what it is, that's being spun around. So please take back control and vote.
All right. I'm going to move on to my next topic as I get off my little soapbox. Let's talk about security and vulnerabilities, and the folks at HackerOne have a new report out that says that the vulnerability backlog is increased to, I think it was 131% over the last two years, even though we are remediating vulnerabilities faster than ever, and that has increased at a rate of about 50%.
But right now it looks like the number of vulnerabilities keeps going up. I think IBM and Red Hat today were talking about 400 vulnerabilities that they found in Java alone. Robert, are we losing this battle?
Are we going to win this thing? Or how do you see this all playing out? " It does.
I actually take this as a positive. All right? Because there's a few things that come out here.
One, more vulnerabilities are being found And you do not improve as an individual, as an organization, as a society, by ignoring your problems. So that's the first good thing. All right?
The second is that there is that backlog, that acceleration of fixing these is increasing. But there is an imbalance right now, no argument. And this is where I get to use my econ and math degree in talking about imbalance in the market.
This is simply supply and demand. There is a larger demand to fix than the supply to implement the fix. And if we are using AI tooling to identify vulnerabilities and they show up, then we need to use AI tooling to propose fixes but not do the fix.
I would also like to see a little bit more education and skill, increasing some skills for software engineers to look for things. Maybe even as part of CI/CD, we're going to look for areas, heat maps, around possible security issues, unsafe coding practices. But I think it's always going to be a good thing when we identify issues.
This does put a burden on organizations, it does put a burden on open source maintainers. But we would hope that this would lessen over time as equilibrium is met. I don't think it's as bad as it seems, but I'm very grateful for HackerOne putting out these reports.
Every time they put one out, just awesome. All right? And then here it is.
They're so great about it. All right. Andy, you seem to be agreeing with Robert, who's essentially saying that which does not kill us will make us stronger.
Yeah, because there's nuance in these numbers. I think Robert's getting it exactly right. You look at the ratio of vulnerabilities found to vulnerabilities fixed, and that's in the public eye.
Well, I tell you, this is a huge topic in my community, in the CTO community generally, right? Because we actually get to find vulnerabilities ourselves using AI, not necessarily or not just in our production releases, right? I get to find loads of vulnerabilities in code pre-prod.
So dev tests, I get to throw AI at every PR, and I get to find out whether we've done something poor. By the way, there's also some nuance in the numbers here in that, it's on case by case, but more AI in development leads to more vulnerabilities in code. Yeah.
So it's both sides of the ledger here. Maybe I'm jinxing myself, but I actually do think the best CTOs are coming out on top of this equation. Despite the numbers that appear in public, the discussions I have about what we can do and what we find in private before we get to prod, I think it's actually helping.
And the bottom line that Robert, I think, exactly nailed is, look, the alternative is we don't find the vulnerabilities, and that's just unacceptable. Mm-hmm. And Liz, love your opinion on this, but I think everybody's trying to figure out, and I guess we're all hopeful that things will eventually get better, but nobody's quite clear how long things might suck.
And the issue is that we are discovering all these vulnerabilities, and the bad guys have AI, and they are using AI to reverse engineer the vulnerabilities and create exploits in a matter of hours. And right now, my sense of things is that our defenses are holding because they're not coming up with necessarily novel attack patterns just yet. But how long will it be before they start doing that?
Or maybe they already are. What do you think? Well, what I hear from my early-stage vendor clients is that to say a year or two years or three years is sort of like throwing spaghetti against the wall.
But for the next few years, the attackers will definitely have an advantage before AI-powered defense kind of speeds up. And there's a couple of things to make that work. First, AI needs to get better, and people need to trust it, right?
I think that what's giving people a little bit of an even ground now is just because there's more vulnerabilities doesn't mean that there's more exploitable vulnerabilities, right? You can frame an attack, but it doesn't mean that that attack can be to a decommissioned system, right? So I think that for security teams, and again, this is informed by my vendors, so if anybody wants to pile on, this is how my views are shaped.
It's that they need to prioritize the fixes that really matter, right? And if they could focus on that, they could be a little bit more surgical and strategic about how they fix things, which would also give them a head. But there seems to be a cultural reluctance to embrace AI-powered defense, and that seems to be where the market is going, at least where the tooling is going.
So I'll leave it to other people to comment on that, but that's what I hear from my slice of the piece. I think you're nailing something really important there as well, right? A large part of this is a sort of architectural change that we're going to have to take on, which is applying AI at different points in the architecture, different points in the transaction cycle, if you will, to make sure that we're getting to these as early as we can.
And that as you run transactions through your architecture, there's AI looking for these vulnerabilities and remediating them. Maybe not automatically, maybe there's human in the loop. And I definitely am a big fan of that.
But this is something that architecturally, I think we have to change our outlook on. It's the old thing that we thought firewalls were good until all of a sudden we realized that internal threat actors were actually our biggest vulnerability. We're now at a point where AI is becoming our biggest vulnerability.
We've got to change our architectures to make sure that we're applying white hat AI at the right points throughout the cycle, not just at one point or this point. So I think it's a really important point. You're right.
We're changing the way we're detecting and treating, and it's got to happen at every point. No, no. Robert, I talk to people about prioritization, and I get this.
" Yeah. It's hard. I don't have an easy answer for that.
I do want to share two things, though. One, I absolutely agree with Liz, about the ordering of this. Remember, we put a V12 engine in a car before we put seat belts, all right?
So remember that, okay? Turbos went in before crumple zones. So it's just humans are not very good at this, of change, unless there is pain.
Luckily, pain is instructive. And sadly, there's going to have to be a few cautionary tales, and there's going to have to be a few really happy tales of success before people follow along with that. I do have a wish, though, because this reminded me of the hacker in 2018 that was scanning those routers for the vulnerability, the Microtik routers, and looking for the vulnerability and then patching it proactively for them before they could be violated.
Before they could be exploited, rather. And it would be so nice if we had the same people that were trying to exploit vulnerabilities to put on the white hat, and hopefully go fix them. But perhaps a fantasy.
Maybe. John, let me tell you what I'm concerned about. I'm concerned about that the breaches, if they do come, will not be reported on unless they involve multiple millions of dollars.
Right. Because we've got to this point now where, I don't know, if you're in a big city, right, and you worked in a local newspaper there, you would have remembered that when there was a robbery, the first question any editor asked is, "Is there more than 10 grand involved? " And I think a lot of these breaches are going to fall in that same category, except now the number is more like a million than it is 10 grand.
But is all this wave of cybercrime going to go unnoticed? Hey, that's a really good point, because we're going to be- ... picking up more of threats, the threat assessments, there'll be more of them.
We're just going to raise the bar on what we think is reportable or actionable. And having written a crime blog for a small paper a long, long time ago, you're right, we would always set a limit. Like it needs to be at least $10,000, it can be considered newsworthy.
But for those people who are underneath the $10,000, who are the victims, the sting is just as bad as for those over $10,000. And I think there is a beauty in this. We're cutting the resolution times in half.
We're discovering more vulnerabilities. There are more threats to sift through, but consequently, that kind of numbs us to the point where we only acknowledge or publicly acknowledge the vast, vast big hit. And that's going to happen.
And I'm glad Robert made the analogy to the auto industry, because I think that's a brilliant analogy because we're just getting ahead of ourselves. We're moving so fast, and the companies themselves are saying this, they're acknowledging this, kind of girding themselves for that inevitable action or inevitable events. I think we're on the road, so to speak, to a major event that's going to get everyone's attention and kind of drive home this point even more so.
So Liz, are we in danger of having a scenario where basically we're not reporting the incidents and the crimes in the first place, so therefore there is no crime to worry about because, well, it's not in the stats, so it can't be there? If a tree falls in the forest and nobody hears it, did it really fall? I'm sure there's going to be some of that, but I hope, and again, this is my wish, that as everything, as the landscape is shifting, then maybe the accountability and liability shifts with it so that mitigates the chance of that happening.
But also, if there's so many more vulnerabilities being discovered, then what if we move some of the responsibility to the vendors, where vendors who ship code with a certain amount of vulnerabilities, they get fined or something. That they are incentivized to debug, you know what I mean? To get rid of those vulnerabilities, just like what Andy was talking about, before it gets sold.
Like that could kind of compensate for an NVD that's useless or other metrics that are kind of falling apart in the vulnerable apocalypse that's happening. So maybe that could give rise to better ways of managing the situation. Now that the structure's falling apart, we could build a new structure that might be more attuned to where we're at.
" Absolutely. A lot of the attack surface is very obvious to some people, especially when you think about consumer grade systems and applications. You look at all the applications that have been written by vibe coding by individuals and then thrown up on an app store and never actually properly tested.
Now, I think enterprise grade is a little bit of a different story. But I think there's a huge attack surface available, especially through these vibe coded apps done by business users. Look, I don't want to denigrate my best friends out there in the business, but within IT, we absolutely understand where these problems are and where these attack surfaces are.
We know what to look for. We know how to do release. We know how to do QA, and we know how to do our own pen tests and stuff like that.
But when we've got the senior manager of sales marketing writing and writing, vibe coding, a new CRM app because they don't want to pay Salesforce their monthly stipend, then look, we've got to understand that that comes with inherent risk. And so yes, that's where I think the hackers and c******s are sitting back laughing thinking, "Yeah, go on, vibe code yourself another application. " Go right ahead.
I'm going to leave this here, but I would just point out one thing that everybody in New York knows. Hey, if you're walking through Times Square with your wallet hanging out of your back pocket, yes, you are an idiot. All right, shifting gears.
SAP has its conference this week. SAP Connect is in Las Vegas. I think they're just finishing up, or they might have one more day to go, but they were rolling out their agentic AI strategy one more time.
And basically, though, this time they're saying that there is going to be this kind of engagement layer that they control, and it's basically they have 400 plus AI agents that will be managed through this layer called JouleWork. And JouleWork is kind of the orchestration layer that talks to their knowledge graph and their APIs, and this is how you're going to interact with all these ERP applications and HR applications in the entire portfolio. On the face of it, that sounds reasonable.
But Andy, underneath it, they also seem to be saying that these APIs and knowledge graph are not going to be readily accessible to everyone who happens to have an AI tool or an agent, and there's going to be degrees. And essentially seem to be trying to create a moat around their applications and those AI agents. Is that defensible?
Yeah, look, Mike, I did a great article. It's your article, I think. Really interesting development by SAP, but that is exactly my concern, right?
I like the idea. Using a knowledge graph because these are known knowns. Business processes, as you point out in the article, are deterministic.
They mostly do the same thing every way. You think about filling out an insurance application. It's all boxes on form.
You fill it out the same way every time. This is very deterministic. This is the sort of thing you can train automation on, let alone AI, to do these things.
And this AI Joule platform is being trained on how to understand how the SAP applications work, which by the way, I would point out is probably a lot better than a lot of business admins I've worked with. But my concern is when they say that they're going to protect and put boundary lines around different bodies of work and bodies of knowledge. We've already seen AI trivially break out of sandboxes, and do quite nefarious things just to get to an endpoint it wants to get to.
I like the idea that AI is able to take these known knowns and recreate them and work with them even when there's variation, which is what automation can't really do, is manage those slight paths that go off the main track. But look, I don't think they will. If they could guarantee that these boundary lines would be honored all the time, that might be one thing.
But I don't think they will and can guarantee that. Sometimes you need to break out of the boundary line to get better collaboration, to understand more context, to have an understanding of your service and your service environment that maybe is not so black and white. And so yeah, I love the idea, but I am a bit skeptical that this is actually going to succeed in the way they think it will.
All right. Robert, SAP's not the only one playing this game. Salesforce has the same notion going on, and basically, they are trying to create some sort of moat that protects them and what they consider their value and, ultimately, what their shareholders care about.
But I got to ask you, as I look at the way AI agents are going to evolve, are all these companies going to wind up on the wrong side of AI history? Several will. Look, I'm an open source person.
All right? And that's what I do. And so my perspective on moats is that the best moat is to have a great product.
I really like people to use my open source projects. Love the fact that people are putting Liquibase in their products. Great, I don't care.
I don't think that this is the right place to be excluding, and stopping that collaboration with other partners, frenemies. I think, Andy, you were talking about that, that you're missing an opportunity when you just use your stuff to learn from others to bring it in. Going back to RDS, that when Amazon rolled it out, they were including Oracle there.
They were including SQL Server. They didn't have Aurora yet. They were using other databases to learn from it.
That's okay, but SAP's making a decision on ... " And the worst thing that could happen for SAP is that all their current customers are saying, "This is terrible. " Right.
Or it may not even be another solution as we think about it, right? Because theoretically at least, a lot of these things are going to wind up being back-end services. They might be microservices.
And let's take a look at these applications and how much functionality are people actually using in there. Maybe 10 to 15%, if that. So how hard is it to reverse engineer the 10 or 15% of the system of record that I care about and just make that a back-end service of my own that I go build with a little help from AI?
And so I have to wonder if, as they construct these moats, Andy, are they incentivizing and encouraging people to go look elsewhere? Well, you could always hard-code it and build in a few hundred more vulnerabilities. Yeah, absolutely.
And look, Rob, you've got such a good point. Collaboration, I've done the research myself, and I know that the broader the boundary lines you collaborate across, the better productivity you have, the better share price you have, the better revenue you make. If you collaborate across departments, A.
If you collaborate across business units, A times two. Across companies even, you get even better outcomes. So locking this down, shutting this out, I think is problematic.
And yeah, look, I think you're absolutely right, Mike. That's very much core to the problem. Yeah.
Everybody that's trying to build moats with AI needs to watch the pub scene in "Beautiful Mind" and learn a little bit about game theory and cooperative play. You are going to have better outcomes. I have to use the econ degree twice today.
It's so weird. You're going to have better outcomes when it's not a winner take all, when everybody gets something, and the size of the pie expands. Okay, your piece gets a little smaller, but it gets a lot longer.
Right, the pie gets bigger overall. Mm. Yeah.
So it's just this whole we're going to winner take all, and it just doesn't work. It works for a little while. I never thought I would live to see the day when we were talking about a movie about how six guys were trying to get laid, showing up here as a way to think about- Uh-huh.
It was just dancing to dates, okay? Well, Robert, I just wanted to say, I think that you're absolutely right when you're saying the incentive shouldn't be winner take all, but it should be the customer experience. So maybe if people are incentivized to apply AI in these cases that are best for the customers, then that would end up mitigating some of the risks.
John, how do you think this is going to play out at the end of the day? Because the vendors, there's a certain amount of arrogance in there. Yes.
Scare. Yeah, I'm glad. I got a sense of deja vu when I read your story, Mike.
" So, yeah, and the vendors, what they're doing, and it's not just SAP. I think ServiceNow and Salesforce fall into this trap where they keep larding on feature set upon feature set, upon feature set to try to up the ante and gain more of an appeal to customers with their AI strategy. But I think in a sense, what it's doing is it's probably muddying the waters.
And in fact, I think, what was it? Meta and Walmart were combining with this company that's chaired by the OpenAI chairman, Bret Taylor. They have this idea to create this universal technology standards- Mm-hmm ...
to streamline business operations with artificial intelligence agents. Right. Because, right?
Because there's a maze of proprietary systems, fragmented APIs, and et cetera. In a sense, I think the companies, in their haste to create moats, have just overwhelmed the customer. They've overwhelmed me in terms of covering this stuff.
Imagine what the customer's thinking. End customers are making it abundantly clear that the current landscape of software is overly complex, too expensive, and too difficult to manage. I think it's important that the vendors start hearing them because they're going to start acting on those feelings- Yeah ...
when they turn into something that they're going to go, "You know what? " That's just their basic rule of thumb right now. And I hear- And it's almost like with the AI models.
Imagine trying to make a decision when every other week, it seems, well, with models it seems at least. With OpenAI, Anthropic, Mistral, whoever, throw in whatever name you want. So how am I going to use this?
And with agents, it seems as if there seems to be this yearning, a desire almost, this pathological obsession within the companies to do these big rollouts that are bigger and better and more confusing and overwhelming at their conferences to justify doing these conferences. And after a while, it's like, we heard this before. How is this different?
How is this bigger in scope and more confusing? All right. " And this is part of that conversation, so by all means, go check out that book as well because, well, you think I'm crazy.
Did it come out today? I think it's coming out this week at some point. I know- Yeah, it's out this week.
I'm pretty sure, but I bought a copy on Amazon yesterday. It came out yesterday for public release. It's available on Amazon right now.
99 ... Kindle version, three bucks a pop. I got myself at least one.
I'm going to hold out for the audiobook, but... All right. Hey, I want to thank everybody for sharing their knowledge and insights, as always.
I want to thank you all for spending some time with us and checking out the entire show. And by all means, stay tuned for the rest of the replay of the Techstrong TV lineup. And with that, there's a little message from us at the end of the show, and we'll see you all tomorrow.