The Global AI Race, Cybersecurity Risk and the Need for Human Oversight
The AI race is no longer just a technology story. It is now an economic, geopolitical and cybersecurity story unfolding all at once.
On this episode of Techstrong Gang, Mike Vizard, Tracy Ragan, Jack Poller and Jack Gold examine the global AI competition, including U.S. efforts to finance foreign adoption of American AI technology, China’s continued AI advances and the growing challenge of balancing national competitiveness with support for domestic AI companies.
The conversation also turns to cybersecurity, where AI is creating both opportunity and risk. As automation takes on a larger role in security operations, the panel explores the dangers of over-reliance, the limits of autonomous systems and why human oversight remains essential as AI assumes more responsibility inside critical environments.
Taken together, these issues point to the same broader reality: the next phase of AI will be shaped not just by who builds the best systems, but by who can deploy them responsibly, competitively and securely.
Transcript
Hey everybody, welcome to Techstrong. Gang, it's the Friday before Memorial Day, and we, as always, are going to have some great conversations. But I would encourage you this weekend to just take a minute and remember all those who gave the ultimate sacrifice for their country, because, well, it's just not all about picnics and baseball and whatever else you guys are going to be doing over the three-day weekend.
You should enjoy. I'm just saying, take a minute. With that, I'm going to say hello to our guests.
How's everybody doing? Jack Gold, thanks for being on the show. Thank you.
Good to see you guys. All right. Tracy Ragan, good to see you as always.
I just saw you in Minneapolis in life, real life. Yeah, that was fun. Enjoyed it.
All right. Jack Palmer, how you doing, buddy? It's Friday, as you said, and a holiday weekend.
I am doing great. And Jeff Ridge, how you doing? Whoop!
Great. Excellent. Well, let's just jump into this for a minute, because this week, the Trump administration says that it will use its executive powers to help finance deals for people who want to buy AI technology made in the US if they happen to be residing in another country.
So the idea here is very similar to any other kind of export program that we have. We have similar programs for wheat and any other goods that we sell. But it seems to me there's a slight difference here in the sense that, well, we have competition out there, and China in particular is not only turning around and saying, "Well, we don't really want US technologies.
" And it turns out that maybe their approach is a little less expensive than ours. So Jack, what's your take on what's going on here? It seems like this is becoming a game of global economics.
Yeah. " This is going to be a very interesting situation going forward with AI because what's happening is, as you rightly said, Mike, China wants to develop their own, partially because we won't give them our best stuff. And they're going to become a major competitive position.
But I think a lot more of what's going on is that the Trump administration is looking at places like the Middle East that are building up their AI infrastructure very quickly. UAE is a good example of that. The Saudis are also doing so.
And they want to diversify their economy to take advantage of some of this AI stuff, some of this money that's coming in. And the Trump administration also wants to make sure that some of that money that people are building out is flowing into the US. It's going to be an interesting situation because, from the perspective of what AI becomes longer term, it's not yet clear how that's all going to fall out.
Some of it is going to go to AWS and Microsoft and Google from a cloud perspective, but there's going to be a lot of agentic AI taking place that's going to be taking place at a more local level, a more distributed level. Are we going to be selling servers to those countries? Are we going to be selling leading-edge Nvidia chips to those folks?
Are we going to be selling other stuff? There's a lot of other companies that are coming on board now. Cerebras just did an IPO last week, I think it was last week.
And so it's going to be interesting how all this falls out. And by the way, just an aside, the Trump administration also announced this week that they were going to put together a major fund for quantum computing, and that's the next phase. We haven't talked much about that, but two or three years out, that's going to be something that's real as well.
So it's going to be a very mixed bag. It's going to be a very competitive position. Europe is still fairly well behind the rest of the world, if you will.
And we'll see what happens there as well. Jeff, I think there's also a bit of a trust factor at work here, and because we in the US have been somewhat hard to read in terms of our trade status with various countries, just say, are we going to see countries kind of look at this and say, "Well, no matter what the cost of that is, I don't necessarily want to be tied to the US for anything"? And we've seen that with the rise of all these digital sovereignty initiatives, but- Mm-hmm ...
is this one of those things where no amount of money might make a difference? I don't know, what time is it? Sorry.
We couldn't resist. First of all, I think there are going to be political implications, which I'm not going to say I'm qualified to predict, but it's going to be greater than zero, I can promise you that. I think what we're doing, though, if we're looking at this as a business, which certainly at a micro level it is, at a macro level, I'm not certain it is.
Because if we look at this as a business, we're ignoring the cost of goods sold. There's two things to consider. Every time AI is used, that doesn't run in the air, it runs on chips.
And those chips are run in data centers. Those data centers consume electricity and water and other resources and leave other remnants that some people around them don't want. So that part of the cost is not always calculated into it necessarily.
Plus, we have to recognize that currently, about 10% of those high-powered chips we use are made in the US. And if we go back to speaking about the political implications a couple of weeks when the president of the US was in China, there was a very strong message to say, "Leave Taiwan alone. " And that came from the PRC.
So now the question is, if China really wants to be the big provider of AI and having the chips to drive it, is that not a real contributing factor to, among others, why they want to make sure Taiwan comes to them now? When that happens, I really question the cost of the goods sold now with the AI that we offer. True that.
It may not even be the cost, it may be the availability. Well, yeah. I'm tying those together.
Yep. And by the way, Jeff, I don't know the exact number either, but if you look at the high-performance chips, all Nvidia chips are made in Taiwan. Mm-hmm.
A fair number of Intel chips are even made in Taiwan, even though they have their own foundry. " But what do I know? Jack Pollard, let me ask you this.
Is this all going to wind up bundled into some sort of bargaining agreements where it's going to be like AI chips plus soybeans. You buy that and then we'll buy this. And is this just becoming one more piece of a larger puzzle?
There's a very high potential for that. But they are running this through... The whole program is run through the Export-Import Bank, which is a US institution that's been around since the mid-1930s, whose only job it is is to foster and help US companies export their goods.
And they do that by the federal government essentially guaranteeing loans. The big question for me about all this, and I'll let my cynical flag fly strong here, is that the government has never been known for operating at speed, let alone AI speed. So I'm not really sure how much of an impact this is going to have in the next six months or a year, as companies really need to get going fast, and how long does it really take to get a US guaranteed loan through the Ex-Im Bank up and running and all of that?
And that could have a big impact on whether this program is effective or not in helping assert US dominance in AI. Yeah. You know, I just got back from Open Source Summit too, and there was hallway talk around open source AI.
Right? And I feel like that's going to become more important in this sort of ecosystem environment as China starts to push these open models optimized for Huawei hardware. Right?
So it is expanding this battle beyond just the models and onto the infrastructure. There's a lot of supply chain dependencies that are going to be impacted by it. The part that leaves me scratching my head is that, let me get this straight.
The United States government, AKA we the taxpayer, are going to subsidize or cover these loans if we sell products to some country, and if they default, we're going to be on the hook for that. So we're covering the potential downside of that a company that is making billions and billions of dollars might be able to incur the risk in the first place for. So, Jack Gold, why are we in this business again?
It's a good question. And what's the incentive? I think the government is starting to think of AI as a commodity because if you look at what the Import Export Bank is really about, it's about commodities.
It's about wheat, it's about soybeans, it's about oil, it's about minerals. But AI is not a commodity, at least certainly not yet. Chips are not a commodity.
At some extent they are, but it's not like one soybean field and another soybean field are still going to give you the same soybean fields. Nvidia and Intel and AMD are going to give you different chips. And then you've got the Taiwanese and you've got the Chinese and there's all kinds of other stuff going on.
So I don't know why we're in this business. The market is just moving too fast. As Mike, you rightly said, it's also for defaults.
We're stuck with the bill. The AI market just moves too fast to think about it as a commodity space. So to me, this just doesn't make a whole lot of sense.
Jack Pollard, are AI chips essentially the new soybeans? Are they commodities or we just seem to get confused here, or was this just a convenient way to fund something? Well, I think when you look at AI infrastructure, there's a whole lot more than just the chips, right?
And building an AI data center is very capital intensive and equipment intensive, whether you're talking about power, power generation, power distribution, cooling, cooling distribution. The servers, the server racks, the cabling, all of that. There's a lot of capital in there, a lot of money involved in there, and this might be a way for us to assert and maintain dominance in the data center side of it and the infrastructure side, even ignoring the chips or the software side of it.
Unfortunately, what we're looking at is something that's incredibly complex, that's being covered by a two-paragraph or three-paragraph press release, and it's really, really hard to say what's the true impact of this. I don't know. It could be very helpful for people wanting for the ability to export servers and networking gear and a lot of other things that come along with this.
If you go and look at the last two AI infrastructure conferencesThey were basically like an automotive conference. They were all about oils and cooling and plumbing and physical plant type stuff. And that's all very important.
We've got a lot of technology that we've developed over the years that would be great to export that and let those manufacturers get some more wins. But Jack Fowler, a lot of that stuff is now still coming from overseas. Mm-hmm.
We're not building it in the US. And so- Exactly. Yes, and as I said, it's a complex thing, and who manufactures what these days can be very, very complex, as most chips are coming in from overseas, but then assembled here, designed here, put in boxes, where the sheet metal may come from somewhere else, but the design comes here and it all gets assembled here and shipped back out again.
This is as complicated as it possibly can get. Yeah. So- And we keep pushing to move fast, right?
Move fast, move fast, move fast. We want to dominate this market. " Because once we start doing that, we're going to see a much larger attack surface.
Oh, Tracy, security doesn't matter. It doesn't in this topic. I know.
It's not slowing down the business. Just a stat, just in the heart, you know. It feels like we're going from innovating AI and industrializing it, and I don't know if it's ready for that.
That's all. It's not. Jeff, to pick up on what Jack Fowler was saying, so let me get this straight.
Basically, we're going to help subsidize, not subsidize, but finance this export of AI technologies to countries who are going to go build these massive data centers that Jack was talking about. And they too will discover the joys of living next to a data center, which we've already seen here in the US, is not exactly the most popular thing in the world. So is this going to ultimately make the United States even less popular?
Because once people in those countries figure out what's going on, they're going to blame us. Oh, I think they're certainly going to blame us, especially if we're financing it, to have it go out there. I don't know how they can't blame us.
That doesn't mean that the local government isn't going to get some of that blame as well, but that's easy for them to fix. It's the relationship with the US that's going to, I believe, in the long run, probably deteriorate because of the cost, the power, the water, and the pollution. Let's just use those four.
None of those have a positive effect right now local to data centers. I'm not saying don't do data centers, but if you look at the big projects that are underway from the hyperscalers, the ones that are underway are continuing. All the ones that were on the board have been removed.
There's a reason for that, because they can't find a place where it's going to work. And even if they do, they can't get the power. They have to bring in their own liquid gas just to be able to have generators to power the data centers because there isn't enough in the local grid.
I think this is a problem that's going to happen to every single country to which we export this. Which is why when Jack Gold said a lot of this is going to be more local, local as in maybe on your desktop computer, I think you're going to see a lot more distributed intelligence as opposed to large artificial intelligence. I think that's going to have to be the next phase.
Anyway, I don't doubt that, but Jack Gold, I'm going to come back to you on this one. So volume matters when you're making semiconductors, right? And the more volume you have, the lower your costs are driven, and then you wind up with a sustainable competitive advantage because you have more volume.
So at some point, is China and Huawei going to have more volume than NVIDIA and Taiwan and they're just going to crush us on price? They're already moving in that direction. So it's not right now a battle between China per se, Huawei, Alibaba, and others, and NVIDIA.
NVIDIA's still ahead. But if you look at the number of chips that China utilizes across the board, forget about just AI for the moment, right? But if you look at the number of chips that go into China versus going to the rest of the world, the vast majority go to China because they're building everything.
Chips today go into everything. There's very little that you could look at on a shelf today and say there isn't some kind of electronics in there. So in that sense, they're already moving in that direction.
The other part of the equation from a chips perspective is that today, TSMC is the world leader. There's some people trying to catch up. Intel's trying to catch up.
We could argue whether they have or not. But Mainland China, because they have been limited into what they could get out of TSMC because of all the restrictions the US has put on them, is starting to build out their own local industrial scale chip manufacturing capability. And they're still a year or two behind what TSMC or Intel could put together, but that doesn't last forever.
They'll figure that out. And so by restricting some of this access, you're actually incentivizing them to build out their own industries and build out their own volumes and build out their own capabilities. So this is a really mixed bag.
Anytime you put anything in place that restricts technology flow, and they need that technology, they're going to go try and build their own. There's no option to not do that. And by the way, Jeff, to your comment around building out these data centers.
It's no longer just the power and the water. People are standing up and saying, "Not in my town. " Well, maybe not in your state, but wherever.
So there's a lot of that going on. But Elon Musk is going to fix all that for us. They're going to put them all in space, so it won't be a problem.
There you go. And then the Martians will show up and complain. That's right.
Jack Fowler, last question on this to you. Are we playing checkers and everybody else is playing chess? I feel maybe not on the board with the same game that everybody else is up to.
I think our intention is to be playing chess. I think we're very interested- We're losing, Jay ... in asserting our dominance on AI, not only as critical infrastructure for us, but trying to dominate AI throughout the world.
And there's not that many other countries and/or entities that play at the level the United States does. It's really China and maybe one or two EU countries, but it's not like you hear about massive breakthroughs coming out of Switzerland or Belgium, right? This is China and the United States are pushing the frontier here, and this is maybe one more, and you alluded to this earlier, it's one more item in the list of many items in the global competition between the United States and China.
And could it be packaged in or bundled in as part of some other parts of a broader deal? Very likely. Could it be being used as a negotiation point?
Also very likely. In the long run, it could have some very beneficial impacts for this for US manufacturers and for US dominance. But I think it's very early to tell the true impact and where we'll be in four or five years.
There are so many variables involved, and I don't always see all the items on the board in the big picture. That's hard to see. Right.
Folks, I think that ultimately, if the United States government is involved in helping to sell US technologies, it's a telling statement. Something's up, folks, in a way that's going to have a bigger impact than we realize because, yes, I know we do it for other industries, but for tech, we're supposed to be able to stand on our own two feet. So something's going wrong here, I think.
But let's shift gears, speaking of things that might be going wrong. We have another survey, many of them that come out there, but this week CloudBees put one out, and one of the most compelling and interesting things about it was it found that 90, I think it was 93% of folks are saying that AI has improved their software development and engineering, and they're seeing increased productivity, and yet, in the same breath, 81% said that they are encountering more production issues from the code that was generated by the AI. And we don't know how many of those production issues there are.
But Tracy, is this a leading indicator of things to come? All this AI code, is it going to bite us? Haven't we been talking about this for a while?
We have been talking about it for quite some time, actually. Just coming back from CDCon, I heard this, people talking about the amount of code that's being generated, and how it is increasing production issues and operational instability as well as technical debt. And that the real big problem that DevOps people are having is that there's so much generated code entering into production environments, there is a weakness in testing and security governance and DevOps workflows to support them.
I think that there was one of the numbers that said that, which I thought was interesting, that 70% of the leaders are saying that maintaining test suites is harder than writing code itself, and they're hoping that AI may eventually generate and automate coding and testing and all the way through some level of production assurance. So it feels like they're just trying to lean more on it. But the DevOps pipeline itself is becoming sort of the next cybersecurity battleground.
" Mm-hmm. And that was the takeaway. Am I doing a better job?
We're finding more problems in production, and they're harder to fix, and less things are being found in the DevOps pipeline, which is concerning, right? Right. And when I talk to people, the other thing that comes troubling to them is if there's an issue with the code, they don't really know how it works because- Exactly ...
they didn't write it. Yes. So it's creating a new level of software supply chain risk, right?
Developers not fully understanding the code that they're committing. That's bad. It seems to me that we're getting into a world where we're talking about production versus quality, right?
So I can produce a lot of goods really cheaply and really quickly that you and I would never buy. Going back years ago, remember the US car manufacturing industry put out really cheap cars, garbage cars. And then the Japanese came in and just built quality into their cars and outsold them.
Are we getting to the same point where we're going to start looking at that from an AI perspective with code? I think that cost is going to get in the way. One of the presentations done by an individual by the name of Ryo Tsukahara from Japan, he did a presentation on using AI as much as he could through the pipeline to try to solve some of these problems, basically.
And at the end of the day, the project didn't go forward because of token anxiety, is the best way to describe it. That it would cost way too much to have AI manage everything at this point. Mm-hmm.
And they didn't believe it was going to solve that much more. So it was like we have to slow down on what's coming through the pipeline because we're not going to right now be able to use AI through the entire DevOps processFor testing and cybersecurity checks and post-deployment visibility. Just not going to happen.
Now, is that going to be the state of the situation forever, or will the cost of the AI eventually come down to where it is cost-effective to use AI to manage the code created by the AI? But we don't know how long that's going to be, exactly. And until then, it seems like maybe we're hitting something that looks like just a stalemate.
Is that a fair assessment? I think it is. In our previous discussion, we're talking about trying to get people to export our AI technology.
But if it's too expensive for them to use, are they going to do that? " Maybe. Jeff, are you on mute, or can I hear you?
No, you can hear me, right? All right. Yes.
Jeff, what's your take on this? Because it sounds like a bit of a paradox. I don't think we're in a stalemate.
I think we're in a spiral. And I'm going to fly the cynic flag as well, Jack Pollard. If you manage two communities, one at the top of a mountain and one in the valley, and the valley depends on snow melt for its water supply, at the top of the mountain, you can't simply say, "Well, let's make this more productive.
" The people in the valley won't like that. That's really what we're dealing with. Being more productive and doing it faster and doing more of it is not necessarily where you want to be.
You have to do it right. And I'm of the opinion that it's not AI's fault. Now, the language models, depending which one you're going to use, are far from perfect.
They're immature. We've talked about, what are they, an eight-year-old? A four-year-old?
They're somewhere in that range. They haven't hit double digits yet, as far as maturity goes. So, it's incumbent upon us to say we're going to use a tool because we can lay off two people and get things done faster.
Whatever guardrails we put in place or didn't, are going to determine the quality of the output of that code. " It never works that way. AI is really an agent of another, or a group of individuals.
" It doesn't work that way. I think that that's what people are doing, and they're starting to sort out that they can't. Because what I heard often, over the course of the last four days, is that they're kind of shifting effort from coding to debugging and remediation.
Mm-hmm. And that because production's not running as healthy as it was. So now they're spending their time working on tickets and trying to debug and to remediate the problems than they are just coding excellent software on their own.
And that- Or using AI to help them, and then make sure that they're cleaning it up and not just pushing it out the door. And I really do think that's what's happening. And Tracy, I think that's a lot more expensive than doing it right the first time.
Yep. Oh, by far. Well, we've- Way more expensive Look, we've been down this road in software development.
We looked at this and researched this 35, 40 years ago when I was at the Software Engineering Institute, to understand: what is the process? And all of these things have people, process, and technology. " And so we've said, "Let's shoot down the AI path," without ever thinking about the people and the process part of it.
If you're a development organization and you tell your engineers, "Use AI," and then you say, "It's also acceptable for you to not understand what it is you're building," that's a process and a people tech problem. That's not a tech problem. Right?
That's the same thing as if you looked at... I've gone into organizations as a software engineer and been given a stack of software and of bug reports, and have to go figure out how the thing works to go solve bugs as a new engineer, right? You have to understand how it works.
You can't just throw something at it and say, "Oh, yeah, that's wrong. This two lines of code is wrong," without understanding the entire context and where it fits in. And it seems like what you're saying, Tracy, is we aren't doing that.
And I think that, and you guys alluded to this, but that's really bad, is if we just take the output of whether it's an AI engineer or a human engineer, and we say, "Whatever you wrote is good. We don't know how it works. We don't bother to test it.
" You deserve what you get in my book. Yeah, I think it's harder to do code reviews with AI-generated code. Yes.
Way harder. So they're not taking the time to do that, right? It's the whole vibe coding experience.
I'm going to go further and say there's no fixing stupid, and here's what's stupid. Stupid is, I was concerned so much about the fact that people weren't using my AI things that I basically started pounding them on how many tokens they were consuming. So now what they all go out and do is maximize the number of tokens that they're consuming, regardless of what the hell it actually creates, and nobody is measuring how much of this code actually makes it into production environments and how much trouble that actually occurs once it gets into production environments.
" But Tracy, it kind of does feel like this whole process is run by the inmates. So, Jennifer Mulford from Okta did our keynote at CDCon, and she talked about learning to trust AI, and she equated it to construction workers and having an apprentice and somebody who's managing that apprentice. Right?
And she saw that AI was like an apprentice, and there isn't any way right now that that apprentice should be given the keys to the crane. And what she is seeing is that we're giving the apprentice the keys to the crane way too soon, before we have developed trust in how we're using AI-generated code and how we are interacting with it. So, we've got the apprentices now kind of running the show because they got the job done fast, and they're not serving as a true co-pilot, to use a lack of better word, even though it's not co-pilot, the Microsoft Copilot I'm talking about.
But a co-pilot sitting, operating the plane with somebody sitting next to you, making sure you're doing it right. We're not using AI in that way. We believe that AI's got all the answers, and so we push it forward.
And now the question is how do we do the AI governance in order to keep up with what's coming through the pipeline? Because everything's going to be done by AI, and there's no way you can afford to do that because of the tokens. So, I think we do have to back up, and I think that her analogy of the apprentice having the keys to the crane was an excellent analogy of this particular article, which is why we have production issues.
I have to jump in here. I love that analogy, and I would also compare it to a student driver. Yeah.
And if you look at autonomous cars that are now being recalled because they drive into water- ... as a perfect example. We can't say, "Well, we trained them.
I can't think of anything that could possibly go wrong. " And now lives are at stake. Right.
So, it's more than simply code in a production application for a business. Yeah. We still have pilots flying our planes, even though autonomous planes have been around for a very long time.
We have two pilots, right? Well, Tracy, I used to hate the co-pilot terminology for these things, but the pilot analogy is very apt in that when you look at whether it's commercial or private planes, pilots use checklists because it is very hard to keep in your head all of the things that can go wrong and what your correct responses should be when they go wrong. So we use a checklist all the time for every standard procedure and every error condition that we believe can exist.
And I think what I've seen is on the AI side of AI development, as we've thrown all those checklists out of the way and said, "It doesn't matter what it creates, just go run with it, and let's let the plane take off, and maybe it lands, maybe it doesn't. Maybe it crashes into a tree, flies inverted. We don't care what happens to passengers.
" And when we do all of these things, and we throw out all of our checklists, we throw out all of our processes, doesn't matter what AI is doing or not doing is if we're not putting a check on it, we're not doing the, or in the construction analogy, not giving the person, the apprentice, the test to see if they're qualified to operate the crane before saying, "Here, I'm going out to lunch. " That's on us as stewards of the technology of companies building things. That's a problem.
And it really hasn't been solved. It's actually even a little worse than that, Jack, because what I've seen happen, and Tracy, correct me if you haven't seen this, because you're closer to the actual dev community than I am. But because of the reliance on AI coding, vibe coding, people are actually getting fired.
They're losing their jobs or getting laid off at least, right? And what happens when you do that is you lose the skill set, the inherent skill set. You're assuming that AI can pick up all those skills that people would actually have by doing this work over a longer period of time.
And if AI doesn't pick it up, then you've lost a lot of resource in your company that you shouldn't have. Right. I'm going to leave this here, but the thing that does kind of concern me about all this is software development is supposed to be the poster child for using AI, and if we're encountering these issues on that end, well, what else are we going to encounter when we start using this stuff more broadly?
Because we might be running into more situations where the tokens are just too damn expensive. All right. I'm going to move, though, to another AI article that Jack Paula wrote, which you should check out on Security Boulevard.
I highly recommend. In fact, Jack has a bunch of columns. You should check them all out because they're always well thought out and reasoned.
This latest column, though, is about the fact that while we've seen that the AI agents are getting smarter, and they're able to manage tasks for a longer period of time. There's a report out of a think tank in London that applied that to cybersecurity. But Jack, walk us through, what was the findings?
What are the implications? So, this was the UK's AI Security Institute, which is a UK government-funded institute to go research these types of things, and they put together essentially a benchmark of tracking how long AI takes to complete complex cyber tasks. And their benchmark assumes that, or creates a set of tasks that it estimates it would take a human 12 hours to doAnd over the last two years or year and a half they've been tracking this, they basically said that the times are improving rather rapidly.
Now, we all remember Moore's law, which says the number of transistors in a chip doubles every two years. So it's an exponential growth in the complexity of the chips, and there's essentially a direct correlation between the complexity in the chips and its performance. So we say essentially the chip performance doubles every two years.
What the AI Security Institute has found is that the capabilities of the AI tools to do complex cyber tasks are doubling every five months, not every two years. So it's five times quicker than the processors are doing this. Now, in their benchmark, they targeted an 80% success rate, and they were achieving that early on.
And I should qualify this, since all of this came out and all their data is from February, before Mythos was announced. So Mythos is even better at solving these tasks. 5 million token budget per task.
They say in a cyber range where they limit it to 100 million tokens, so a significantly larger amount of tokens, AI demonstrates the sustained multi-step attacks that they didn't be able to do before. So all of this is basically saying that the AI tools are getting much better, much quicker, five times. They're doubling every five months instead of doubling every two years.
So AI is fast outgrowing and achieving the same performance benchmarks that the processors used to do, and it's basically moving faster than conventional security can deal with it. And I think we've talked about this in a different frame of reference with the Mythos and the Vulpocalypse, but this is another benchmark that demonstrates this, and their data is actually correlated by yet another group, the Model Evaluation and Threat Group, METR, that it's achieving the same results with different set of tests. But so when you look at that, does that not benefit the good people and the bad people equally well because they're all going to use the same fundamental capability?
So isn't this whole thing just going to accelerate? Yes and no. So theoretically, you would say yes, it benefits the white hats as well as the black hats.
The problem is, for the white hats, it's never been about finding the vulnerabilities. It's always about fixing the vulnerabilities. And this goes back to our previous discussion of people, process, and technology.
And most of the challenge in fixing vulnerabilities as you find them is not technology. Fixing them is relatively easily. It's deploying the fixes, getting the patches out in your code, and then for people in other organizations to apply those patches to their running environment.
You have limited maintenance windows, limited people to go do this, understanding what priority, which ones you should fix first. All of those other issues come into play, which makes it much harder for the defenders, the white hats, to deal with this issue. Way harder for the white hats.
Way, way harder. Mm-hmm. Like exponentially harder for the white hats.
Tell us how you really feel, Tracy. If you think about what you have to do to remediate, when we are seeing the vulnerability life cycle collapsing at that rate, we used to think, well, attacker couldn't attack it. It's going to take at least 10 days to attack it.
Right now, remediation for the public sector takes over 100 days, and most of these are targeting the public sector. So when you see this collapsing, and we still are not, right now, we can't handle fixing vulnerabilities in the first place, it's a tsunami of problems coming our way. A tsunami.
We are talking about we could explode, especially with what we just talked about in AI, writing code for us and not writing the best code. We could go from, I don't know what we did, 23,000 or 30,000 vulnerabilities to 50,000, 60,000 in one year. Right?
It was- With it collapsing ... 46,000 last... 2025 was about 45,000, 46,000 vulnerabilities, and I think based on the current trajectory of what's known and reported to the CBE databases, it's projected to be 75 to 85 or 100,000 this year.
So it's humanly impossible almost to address it this way. And our current method is to try to find them in scanning, right? Pre-deployment scanning, and that's not going to be able to keep up either.
So we have to get to a point where we have an easy way to be able to find them, understand what endpoints they're running on, and fix them as fast as possible. And that is going to be tough, especially when they have breaking changes. The remediation of these vulnerabilities can be tough to do.
And it's concerning because I am a lover of open source. " And that's why in every single circle I'm in, I'm like, "Can we start de-bloating open source packages? Why does Python have to have so many?
" Let's just put it that way. We've got to do something drastic. So this may be separately- Jeff, help me with some math, Jeff.
So if I understood what Jack Paulo was saying, the bad guys are going to get fasterAnd by the way, they seem to have infinite resources. And our current processes for fixing patches are tied up into that DevOps conversation we just had, which is apparently slow, and the pipelines are clogged. And it's super expensive to fix everything using AI.
So for all those folks who think we're going to fix this issue using AI, they might be somewhat disabused by that notion once we figure out what the costs are. So, can we win this fight, Jeff? Well, I do think we will eventually win.
I think we will win the war and lose a lot of battles. And that may be the way to look at this. It has to be a long-term strategic view.
I will offer, and I'm not saying it has to be, but CVE has been wonderful. Is it now obsolete? Does it really help us anymore?
Because we're dealing with the exposures we find. We can't possibly, to Tracy's point, keep up with the flood of, "Here's everything we know about. You need to have all these patches.
You need to turn this feature off," whatever it's going to be, in addition to create your production tools, run them, and debug them, as well as have this huge threat feed. I think that we will reach the point of no return there. I do think those are the battles we're going to lose.
Where I think we're going to win is really having a good distributed architecture, I've said twice, second time today I've said that, that's going to build in our resilience rather than trying to create code, finding the bugs, trying to remediate them, and by the way, while you were doing that, four more came in. I think that's a battle we're going to lose. I think we win the war by having a more resilient distribution.
There's another data point along that line, if I could just throw something in here really quick. Verizon came out with their data breach report, I can't say it, but they came out with it this week. And what they found was over the last few years, the number of stolen identity credential-based intrusions went up.
And vulnerabilities went down, or the number of breaches because of vulnerabilities went down. This year, that reversed. Mm-hmm.
And they attributed a lot of that to the uptake of AI. The AI capabilities are letting people find vulnerabilities much more quickly and act on them much more quickly, while as all of you guys said, Jack and Tracy and Jeff said, it's harder and harder to get those resolved. The other big piece of it, and this is going back to what we talked about in the first part of this talk, was as we give more and more of these countries more and more AI capability, and not all of them are our friends, does that make it even harder for us to protect a lot of this stuff, keep those vulnerabilities away?
China does espionage. Iran does espionage. Russians do espionage.
I'm sure there's a whole bunch of other countries that we could point at. The more AI tools they get, the easier it is for them to hack us. So Tracy, I'm going to give you the last word on this, but there was an article in "The Wall Street Journal" talking about how the concerns about Mythos and all this stuff are overblown.
And it was basically saying that, well, all the serious bugs have already been found anyway, and what's being discovered now are shallow bugs, and they don't really matter all that much. So, what do you say? Oh, how naive.
How incredibly naive, whoever wrote that. It's like saying that Ebola was a myth. It must be nice to be a financial reporter and live in- Yeah, exactly.
No, I think some of the worst bugs are yet to come. Some of the worst attacks are yet to come. They're getting smarter.
They're learning how to weaponize it much faster. So we have some big ones coming. All right.
Well, I'm starting to feel like an extra in one of those movies where the asteroids are coming to destroy the Earth, and we have 30 days before they land, and everybody knows, and we run around with our heads cut off for 30 days until eventually the asteroid hits. So it's coming, and we'll have to figure out what to do after that. Anyway, thank you everybody for- You need a red shirt, Mike.
You need a red shirt if you're going to be the extra. All right. That's a "Star Trek" reference, right?
That's right. All right. Guys, thanks for sharing your thoughts and insights as always.
Everybody, have a great weekend. We'll be taking Monday off, and we'll see you all Tuesday.



