NVIDIA’s Impact on Tech and AI: Opportunities & Challenges | TSG Ep. 956
Alan Shimel, Mike Vizard, Mitch Ashley, Jon Swartz, Teri Robinson, and Garima Bajpai explore the growing influence of Nvidia on the global technology landscape. The gang discusses how the company’s $5 trillion valuation and AI leadership are driving innovation across sectors like robotics, cloud, and software development — while also raising questions about government oversight and market concentration.
The conversation also delves into GitHub’s push to embed AI agents across the software development lifecycle (SDLC) and the rise of “bionic hackers” — cybersecurity experts leveraging AI to identify and remediate vulnerabilities faster than ever before. Together, these topics paint a picture of a rapidly evolving ecosystem where AI innovation, regulation, and security must evolve in lockstep.
Transcript
Hey everyone. The best job in tech right now, business development at Nvidia. You are watching Techron Gang.
Hi everyone. Happy Thursday and welcome, welcome, welcome to another edition of the Textron Gang. You know, I, I was ha I had half of mine to dress up for Halloween today, but the other half of me didn't.
So I didn't, but, uh, I was, I was hoping maybe some of our gang would, and I see it looks like Mike Vizard in his Steve Jobs costume. So we'll be bringing him out for a, for a, a keynote. He's going to, you know, what, what does Apple have in store for us?
But let me introduce you to the rest of our gang today. We are joined by Mitch Ashley, Teri Robinson, Garima Boal, Jon Swartz, and of course Mr. Jobs.
Um, Mike, beyond dressing up for Halloween, you were busy listening to keynotes, sucking up some Nvidia, you know, I said that the best job in tech right now is being a biz dev person in Nvidia. The partnerships there confessed and furious, huh? Yeah, I mean, it's pretty amazing.
They had their GTC event in Washington and it was quite literally a celebration of innovation. And to be honest, it's kind of sick. All the things that they're up to, and it makes you wonder what everybody else is doing.
But they were talking about everything from partnerships with Uber to create a new network for autonomous vehicles. Eli Lilly has built out some massive, uh, gen AI platform with hundreds of thousands of Blackwell processors. They are also doing simulations of nuclear fusion reactors and all kinds of amazing stuff.
And the core announcements were that they were also gonna figure out how to replace all those base stations with GPU base stations so we can run AI closer to the network edge. And they were also talking about physical and robotics AI out at the edge with a new chip set. And then finally, and these are just all the things I can remember off the top of my head.
They're talking about network links with quantum computers. 'cause they're like saying, Hey, conventional computers will connect to quantum computers. It just won't be traditional CPUs.
It's all gonna be GPU driven. And I could not help but think back, Alan, to what you were talking about earlier this week where we just live in some amazing age of innovation here. And we haven't quite seen it come to fruition yet.
But every time I look at what NVIDIA's looking at doing, I always look across the rest of the AI landscape, and I'm like, well, what the hell is everybody else doing? Well, this, this is why they got $4 trillion or whatever it is in market cap. And hey, Well, but you know, today they just went over 5 trillion.
They're the first company ever to do that. They just did it literally a few minutes ago, 5 trillion. And this is why, I mean, Actually, they're, they're, they're worth more than the GDP of every country except the US and China now.
Amazing. So here's the question. First of all, before we get to the question, congrat, congratulations to Jensen Wong and the entire Nvidia team.
You know what, these people who've worked hard for 20 years, and they, they have reached the pinnacle of Pinnacles. And Mike, you're right, it seems like they've got their finger in every pie on the planet, but nothing, right? Uh, nothing stays the same forever.
Nature hates entropy and, and things will churn and things will change. We talked about this on yesterday's gang. Everybody, everybody gets their 15 minutes of fame now.
NVIDIA's having more than their 15 minutes. But I think the real question here is, is Nvidia creating the tide that lifts all boats? Or is it just lifting the Nvidia boat?
And that ultimately will determine how big a disruption, how big a wave, how big a revolution, all of this comes because no, even if 5 trillion can't do it alone, that's my take. You know, a comment on that, Alan, is it seems like the lifting of alt the tide of all boats seems to be the biz dev activity, right? It's not just, you know, other people also innovating.
It's all these deals that they also announce when they announce their own product announcements. So whether it's, you know, Microsoft or Oracle or whoever, they're all making announcements with each other, oftentimes with Nvidia. And, uh, you know, I think it was just Red Hat was part of that announcement, if I remember right, Mike, uh, from the conference.
So that's part of the, maybe it's artificial, maybe it's not, but that seems to be the biggest method of lifting all the boats. Can I, can I, can I let Er Oh, so go ahead, Mike. I'm not entirely sure to what degree all boats are being lifted, right?
I, I did notice, like when I watched the keynote about the only other company in the tech sector who got like a, a shout out for a use case was Oracle involving something they're doing with the DOE and Nvidia. But everywhere else, it was like almost no mention of AWS Google, no mention of Dell, no mention of HPE. No, it's almost feels like most of the people who are doing deals with Nvidia are doing them direct and maybe, you know, just working with Nvidia and then NVIDIA's figuring out where to run these things.
Or in the case of Lilly, some of this stuff is just in their own data centers. But, um, it was just pretty clear to me that most of these projects are directly led by Nvidia. And not necessarily, you know, them just giving a bunch of chips, but actually going in and working with people to build these things.
You know, it's like in historic perspective for me. I mean, Mike and Alan and Mitch, all of us, we've been looking at this stuff for a long time, but it kind of in assess what they're doing in terms of chips, robotics infrastructure, quantum computing, data centers. It's, if you indulge me, it's kind of reminiscent of what's going on in the World Series with Tani like this never before.
An unprecedented behemoth comes along and it's shining brighter than anybody. And all these other companies that did their announcements are part of this, this constellation, whether it's Red Hat, ServiceNow, checkpoint, HPE, they're all just secondary players supporting this mega star. And I don't know what the, uh, ultimate strategy is, but for now, the one who's benefiting is Nvidia the only one really?
All right, well, okay, you guys. So, yeah. Um, but my question is, to what extent is the, the government gonna start sinking ships?
Because, you know, Trump's over in Asia right now, Right? They're ships now. They're they're blowing stuff outta the water and killing them.
That's Well, yeah, yeah, they're doing that. And I, I hear we're gonna bring back, uh, uh, steam powered catapults too on our aircraft carriers, but, uh, that's for another day. But I mean, he is talking to Xi right this week about Nvidia chips, the Blackwell.
So, um, what's that gonna mean for the whole marketplace even? Um, yeah, I think, you know, the Chinese are already kind of busily figuring out what their own GPU strategy is. So they'll, And, and, and if they don't get Nvidia, they'll, that'll just spur them on and make their own, you know?
And, and maybe that shakes things up. But let me put my old biz dev hat on because I, at the end of the day, I'm a biz dev guy there. Here's the real question.
You mentioned AWS Google, Microsoft seemed to be frozen out of it. It's not that they're frozen out of it, Mike, I think they don't want to be the frog to Nvidia Scorpion, okay? Because Nvidia views them as, look, these people have ambitions in making their own chips.
Yeah. That doesn't play well in Jenssen's world. All my, all the chips belong to me, right?
And so if you are willing to work with NVIDIA's chips and use NVIDIA's software that helps them lock in that big M word, right? That we used to not like, but I guess now we like it, um, there, they're all for making deals with you, right? They'll make deals till the cows come home.
If you, if you have plans to potentially make your own chips though, you're not going to get the love. Well, there was, there were two things that Jensen won, kind of stressed over and over again. And one was how vertically integrated they are.
And he was touting not just the GPUs, but you know, kind of gleefully pointing to Cuda as kind of like the software, uh, gem in their entire stack. And then he also pointed out they're making dpu that are offloading processing from GPUs. And he said, we're heavily invested in the networking side.
So they're like becoming this entirely vertically integrated stack. And then he took it a step further, and this part, I'm not so sure I agree with, but he was making a case that says that AI in of itself is an entirely new vertical industry, and therefore is not necessarily part of the IT industry, but something completely new and distinct and apart from thereof. I'm not sure I agree with that, but it was a bold statement, and he kind of trying to sit there and say, look, you know, AI is gonna be something apart from everything else.
I agree with him. I agree with him there. There's much more to AI than it I, and I think we've gotta recognize that, right?
I was out at, uh, I was out at dinner in Pittsburgh this weekend, and I had a chance to speak to some Steelers fans when we weren't talking football from all different walks of life. Not AI people. Not, or not it people, not even people who are, you know, they're just starting their AI kind of experimentation.
You know, this, this is going to disrupt everything. Uh, you know, my, my feeds, no matter what social media I'm on, they're full of people with robotics different, whether it's the Tesla, the figure, or another one I saw today, Neo something, you know, doing basically domestic housework, serving dinner, you know, doing things like this, like out of a, out of a sci-fi movie, out of a sci-fi movie or the Jetsons, right? And, and so for AI to succeed at that level, for AI to be your medical diagnos, diagnos diagnostic, you know, diagnosing your medical conditions for AI to be your lawyer, for ai to be your editor, Mike John, for AI to be your editor, have I editor.
Um, it's, we need to lift it out of the it thing, because that lawyer doesn't want to call it, every time the AI makes a legal opinion or the doctor, it makes a diagnosis, it, it's gonna rise above it. It's, it's gonna be woven into the fabric of civilization. This is an industrial revolution.
They do a really good job. I mean, what, what, two or three times they do these major conferences, they do a great job of creating this narrative because they're in the position to do so, where they, they lay out just what you said, Alan. They talk about what's gonna happen in terms of physical ai, in terms of vertical markets and who they're partnering with, whether it's manufacturing, healthcare, retail, food service.
They're in that position to do it, and they've got people lining up to work with 'em. So as long as they keep doing this, we're gonna see their, their market valuation just Skyrocket. It's a one to what 5 trillion will do for you.
So I don't agree with AI as an industry flat out, there are existing vertical industries, and AI will be embedded into healthcare, and it will be embedded in manufacturing, and it will transform all of those industry sectors. But I don't really see AI as a standalone vertical, uh, in, of, in, in of itself, unless we have some, like, brand new, entirely different use case there, not never used before for ai, which I have not seen yet, right? I've seen AI be used in existing processes.
Let, let me, let me give you, let me give you an example, all right? Is your cell phone ai? Uh, is your cell phone it Cell phone?
Is it, and Telecom, You think you, it's telecom, but you, you're adding the it on, like the tail on the donkey? Well, telecom is a subset it or one of the other, But so telecom is a subset. It's an awful big subset.
Well, That's true. Well, I think the way to look at it, Alan, is I think it's more, it's it adjacent both vertically integrated and horizontally integrated. In other words, AI will be in all parts of our economy, our tech stack, all of it.
Your example about cell phone is, is it, it, maybe it doesn't produce your cell phone, but software developers write code today at least, um, that run on those, run those phones and also run the apps on the phones. So it's based on, you know, same, like, same technology that we use the it, my question about is it a separate industry? Is does it pull away from, and it doesn't come with it as part of that movement.
I think it comes with it, but that's my opinion. So I, I think when, when it becomes so embedded that you don't need, it works independent of having an on staff IT person help you with your phone, for instance, or with your robot or with your medical diagnos diagnostic, uh, apparatus people, people disassociate it with it, it's tech. Yes.
Is it technology? Yes. But not all technology is information technology.
It's not all done by IT people, I think is what part of what you're saying, right? Yeah. And, and so when, when, when people move above it, they, you know, it, it moves beyond just, it, it's not, you know, it, it's not the CIO's purview or, or that kind of thing.
Will the, will it run software by run, written by developers? And those developers may in fact be AI themselves? Yes.
But when AI's writing the software, it's all AI to me. But here's the really scary thing, Mike. I read an article today that said, they're now seeing that some of these ais are resisting being shut off.
They don't like to be shut off. Yeah. So I'm envisioning a Planet of the Apes kind of thing, where these things are servants for about two, 300 years, and all of a sudden, Caesar is born, right?
And Caesar AI is gonna lead the AI into, into the revolution. What, I don't remember which planet of the apes that was, was that conquest of the planet? The a Conquest?
It Was the, yeah. Yeah. I don't know.
But one of the definitions of sentient is being aware that you exist. So if you're afraid to get turned off, you must be aware that you exist. So there's an interesting paradise That sounds like something outta Monty Python, but Yeah, I get it.
I get it. Um, look, it's certainly interesting times, and Nvidia is, you know, no one could deny their moment in the sun. And, and, and, and again, to their credit, they have this lead, they have this gigantic $5 trillion market cap, and they're using it to drive, you know, good work on their part.
Good work. A lot of companies fumble that kind of lead. They get fat and lazy.
They Have some pop culture for you, Alan. There's a, an old movie, 1970, it's called Colossus, the Forin Project. I remember that one.
I I love that for movie. It's where the, where the computer becomes sentient and they're using it, uh, basically handing it more and more for, for the nuclear defense. It's kinda like an early version of war games.
Um, but it becomes sentient in, in all ways, in including shutting people out. And What wasn't that Skynet? No, no, that's, that's, that wasn't Skynet.
That's the Terminator. This is this, this is before Skynet. This is from the, that was 1970.
No, no, I remember this movie. I remember who the star was. I, I, yeah, that stuff used to, I mean, this is why I am where I am today for movies like that.
It was on, it was Alan was on Channel 11 in New York every other Week. Yeah. On WPIX Office.
Chicago, for me. Anyway, look, we we're all over The Nvidia, the Nvidia though. I mean, Nvidia works.
I mean, three months ago they, they, they hit 4 trillion. That was three months ago. So yeah.
Shorter story coming. Think You six weeks. Yeah.
All right. Crazy, Crazy. All right.
Hey, we're gonna take a break here. I gotta go check my Nvidia stock holdings. Uh, we'll be back with more.
What do we got coming up? Oh, more ai, not it, ai, you're watching text and gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back.
And yes, it is conference season, and folks at GitHub had their annual, uh, show, and they were highlighting the fact that they were gonna have this thing called an, a platform that manages your AI agents within your DevOps workflows. And this is how we're going to execute software engineering from here on out. And I, to me, one of the things that came across was how ambitious they are.
And they're going well beyond just kind, hosted a bunch of repositories, and they kind of wanna manage this thing, or at least the AI agents, and they don't really care where they come from, whether they build it or not. But Mitch, what's your take on what's going on here? That's the big shift in direction and strategy is, you know, we're not just a repository company.
We're the platform for agent or agentic based development, agent ops, whatever term you want to use for it. And at the center of it, yes, is this Agent hq, which is essentially, we've talked about who, what's the control plane? Where's the place where it's you manage and control and direct and, um, you apply security in, you do governance and things like that for the agents that are working for you.
And that's, that's partially what Agent HQ is. It's also shifting from being in, in the code editor and directing through prompts to using more of a screen that's just about managing multiple agents, doing multiple tasks, either on the same or different projects and developers more moving more into a director kind of role, um, or, or, uh, platform engineers and DevOps engineers. The sort of really big vision is, it's not just Microsoft's or GitHub's agents.
It's Anthropic was part of the announcement. OpenAI was part of the announcement. They'll support Xai, they'll support, basically you must support anybody's agent.
Now this is focused on it's software development, et cetera, leverages a lot of technology from Microsoft. Um, there's a planning mode that Microsoft announced for copilot. Of course, it makes big use of vs.
Copilot and VS code. You can do agent XQ functionality and VS code or on a, on the GitHub interface. Um, there's also, there's a, there's a planning mode.
There's also, um, some things around a model selection that it will do for you for, uh, do model selection for you automatically. Now, I think one of the things we're headed into, and, and, uh, I agree, I appreciate your, your perspective on this is if we're gonna have a lot of agents doing a lot of work, you know, directed by a few few people, the cost of doing this was gonna escalate greatly. I don't know if you've done any development with AI agents and the API costs, um, unless you're using some of the, you know, zero level models that are either free or mini level models, it gets expensive very fast.
So cost management's gonna be an issue, um, down the road. Not so much now, but I think that's one of the challenges we're gonna hit. There's probably other bottlenecks.
What, what was your impression of the announcement? I appreciate your perspective on it. Yeah, I am unusually excited about this because, uh, I, I'll tell you some reasoning around it.
And these agent orchestrators are also there in the cloud ecosystem. So I'll start with this, uh, agent HQ announcement. Uh, they are tapping around one 80 million users, which they have on GitHub, right?
And this, the excitement I have is around developer centricity, because if you think about like the differentiation, um, which I can draw a line like, uh, I've also used, uh, agent orchestrations in the cloud provider domain like AWS and Azure also provides this kind of capability. But the difference is the transparency and control. So agents, uh, will have explicit identities, uh, audit trails, at least they're claiming to have that and will be governed by organization policies rather than, you know, if you see the cloud provider, how, uh, orchestrators and the agent orchestration layer, it's primarily managed by the cloud provider and the controls and the wearing granularity is in, uh, some aspects is there with the cloud provider, the custom policy setups and the crowd, uh, cross cloud transparency is also something which is very challenging at this point in time.
I also would like to highlight one more point that, you know, uh, from an open ecosystem perspective, when you highlighted this, uh, Mitch, that, you know, this agent H HQ is an agent agnostic view. So you can mix and match, uh, between models, vendors, uh, reducing lock-in, in risks, et cetera, right? And, uh, whereas if you see cloud providers, it's optimized for their own agents, uh, with openness and depending on vendor strategy and cross cloud standards, which are in making, right?
I mean, we have not fully understood how and what is going to happen there. Another thing which, uh, also gets me excited is, uh, the workflow coverage. Because if you see the announcement, it's, it works, uh, from a developer centric point of view, uh, which is basically the GitHub workflow controls, uh, you know, how, and what agent orchestration would do in this case, let's say PR reviews, for example, which is a big headache in the context of ai, vibe coding and all that, right?
And, uh, copilots, uh, you know, writing coding bodies, writing their, your own, your code branching controls, for example, agent identities. Um, and also think about this, uh, you can have custom rules which, uh, can be exposed, uh, from a developer ecosystem centricity, right? Whereas if you see the difference, uh, what we see today in the cloud orchestration layer, uh, where they have these, uh, agents orchestrated, they're at, uh, uh, infrastructure as a code security scanning, monitoring, and scaling, uh, kind of aspects.
They're kind of, you know, overseeing things. But I, I think it, uh, from this announcement, I'm seeing more value for the development ecosystem or developers, right? So this is an exciting part.
Another area which, uh, we have to watch out for, and which you highlighted that, that right now the licensing, uh, model is not very clear, to be honest, because what they're saying is that they have integrated it in the copilot. And, uh, now how the subscription based model would, uh, kind of go along with the licensing, it's kind of, uh, wishy-washy at this point in time. Maybe that, uh, cost consciousness and how the sole cost buildup would happen is another, uh, matter of concern.
I, um, I always bring like, uh, cons before the pros, because pros are very obvious to understand. I mean, everybody's looking at agents and, you know, agent orchestrators, uh, will they, uh, they will have their own life. And if that can release some kind of a cognitive load on developers, that's great, but there is a possibility of, uh, compounding errors, right?
So if, uh, an orchestrated, uh, agentic workflow has some, uh, errors, I mean, you can imagine that it can go a long way, right? And, uh, that is something which, uh, we need to watch out for. Um, black box problem, uh, again, the same issue, but with GitHub, I think I'm more confident.
Um, I am, uh, a developer persona type, so I like these things. But when you see it in the cloud ecosystem, it gives a little bit more black box perspective here. Uh, maybe we are, we can be more confident.
And the last part is skill gap. So how do we build these agents, how we integrate them, how, what, uh, you know, what, uh, skill ecosystem would be needed? I think we need to watch out for that.
You know, I would say the whole thing, honestly, is kind of starting to make me feel a little bit sad. And here's what I'm gonna be sad for. I, you go meet somebody and they're a developer and they tell you they write code and you go, oh, that's interesting.
Tell me about, you know, what, what goes into that? And now I'm afraid in the future I'm gonna meet somebody and I'm gonna say, they're gonna tell me they're a developer, and I'm gonna say what goes into that? And they're gonna tell me, I read code all day generated by a machine, at which point my next response is gonna be, how about those Yankees?
So I, I think that's one of the issues though, is, first of all, we haven't addressed the hallucination problem. You mentioned green about compounding error is also, you know, they didn't fix hallucination problem. And there's no point of saying, did they say, or would, would you expect people to review every part of this code?
It's just not gonna happen. Especially as you scale up and create more and more now AI's doing the code reviews, but there again, it's not a hundred percent. So at, at some point there has to be a counterbalance of, well, if humans can't, um, review all this and we can't, do we have specialized agents, models, whatever, that, that do very good job with few, few hallucinations in specific domains to help solve that.
Or is it addressed some other way? But at some point you'll have so much stuff out there with so many, you know, whatever's going on, it doesn't matter whether you can review the code 'cause you didn't, and it's doing what it's doing and you just kinda live with it. Mm-hmm.
So that's the case then. What is the role of the developer going forward? What is the job?
You know, I think, uh, here, here's my view of it is, you know, this isn't the, uh, Satya demo. I'm gonna create the snake game, right? And here's what I did in half an hour, and my computer isn't this wonderful.
It, it is still directed by someone who knows how to create software and how to architect software and what needs to be done now, how it is being hand today, we do that through here. I'm gonna write this prop, do this next hammer, write this prompt, do this next, you know, guiding it through. There is a planning capability where you describe what you wanna do, almost like a product requirements document.
They described it. But anyway, it to create a plan that will help you direct the agents. It's still you, you directing it, you know, just like my own experience is there's not enough air handling in this.
There's not the logging that I want that we're gonna be able to tell what's going on with this breaks. Um, why did all of a sudden you decide to change the key to get access to that model? Who, who hallucinated that.
So there, there's still, it's, it's like, um, you need a surgeon to run the robot. The robot's not doing it all organically by itself, yet. Not, not to say developers are surgeons, but you know, they are smart people.
I, I, I have some views on this. What, what stops Mike and John and Alan from being coders. We don't know how to code.
That's it. We don't, you know, we look at computer code, HTML code. I could kind of figure out, CSS throws me a little bit out.
But beyond that, I look at code and it's all Greek to me, right? That's why I have a lot of respect for developers because they could code, they know how to code and rust and go and see and python and what have you. And some of it a layman could look at and say, I, I think I see something.
And other times we don't know what the hell it says, but I know what I want my apps to do. I could give you a requirement doc and say, Hey developer, this is the app. I, this is the functionality I want in my app.
Right? In that regard, we're all developers. We all have ideas of what we want our apps to be.
I think of this stuff as the great democratized democratizer. It allows all of us to be developers. It allows all of us to write that requirements Doc Mitch in, in plain language.
And then the AI does its thing, does its thing. And it may very well be that when the AI does its thing, it doesn't do it in Python or go or Rust or whatever language we want to use, it may be writing it back into machine code 'cause it's more efficient or, or, you know, assembly or God knows what, that will be totally unreadable by humans. And we may need an ai, uh, uh, uh, you know, an AI support kind of bot that can go with when, when it, when there is something that hits the fan.
When something doesn't work, we're not gonna be able to look at the code ourselves and see what it is. But we'll have an AI that does. And so to me, I think we're gonna the developer of the future.
I think the real pivot point, inflection point is, and I had this experience with an, with early code generators. This is going back like even with COBOL code generators, that's how far back as it goes is, even though it's in cobol, you couldn't read it. You would never write it this way.
It is, it was just unintelligible. Um, now the code is generated today is much more readable, but there's a lot of it, and you didn't write it. So you're coming up to speed on someone else's code.
In this case, ai, I think we reach a point where the time where you have a code editor open while you're running AI to create the application and the software, whatever you're building, that's gonna be the exception, not the, not the I I agree. And that's what you're talking about. That's when you really have democratized it.
And by the way, yeah, we'll take your prior product requirements document and say, well, there's some things missing here, or, or, or I would suggest enhancing it this way. So it kinda make what you, what your intent is, even flush it out better for you, maybe even prove it, Right? I'll give you an analogy, right?
I mean, when we start, when I started, uh, to work with computers, the computers were like a lot of open box technology where I could fix things by myself. You know, I could open up my, uh, computer boxes and I can fix things. I can add ram, I can, you know, change my, you know, configurations of my computer, right?
And we have come a long way, you know, now we all work in laptops, right? So what happens is that, uh, the technology is commoditized, you know, we bring it in a box. So the same thing would happen with AI applications, uh, you know, coming along with us and developing code.
So these software applications are commoditized, right? So it's, it's that kind of a shift happening, but it's not so soon that you will trust these AI build applications. And this is a good segue to the next, uh, question you had Mike, uh, on the surveys.
com as well as from, uh, the DOA report that there is a, a, a substantial amount of trust issue with ai, a writing code. And this needs to break. And this will break with time and with the quality developers putting, you know, more effort to integrate AI as assisted code into the ecosystem.
Absolutely. Hey, we're, we're over time on this one. Again, it looks like we have some interesting, I I, I love the discussion, but we do have to take a break and come back into our third segment here.
Uh, the Bionic hacker. Somehow AI's gonna play into this too. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and there's a thing happening there. It's called Bionic Hackers. And I'm not even gonna explain what this is 'cause Terry wrote an article about it on Security Boulevard.
So Terry, jump in here and explain what the heck is a ana kher For all of you that are picturing Steve Austin running, uh, this is, uh, not quite as sexy, I guess, is that, um, yeah, thanks Mitch. That's a much better, uh, than what I could do anyway. Um, and so this is basically a blend of human beings, and you guessed it, ai, right?
They're using ai, uh, these researchers as a, as a catalyst. Um, and they can accelerate things like, you know, recon and, uh, triage and scaling, pattern recognition and those kinds of things. Um, ostensibly to be able to, you know, defend quicker and better.
Um, and it's, it's so, and close this as Hacker one. It comes from a Hacker one report, right? And they're saying, you know, it's gonna close that gap between, uh, traditional automation and, and, and human testing.
Um, so I guess that's lofty. And, um, and you know, and then there's gonna be the other side of this, which I'm sure we're gonna get into is that the, that you know, Right? So aren't there gonna be black hat bionic hack bots and white hat ones and who knows, maybe even gray ones, and is this just gonna play out?
And I guess my question though is, is it happening so fast that humans can't keep track of what's going on? So I have no idea, like if we're winning or losing and what might happen because the bad guys are doing stuff in nanoseconds and we're responding in nanoseconds. Well, yeah.
I mean, they said, you know, I mean, defenders, the bad guys are, are, are exploiting before defenders even recognize the, the threat at all. So, um, that's an issue. I don't think it's, it's just hard to see how anybody can keep up with, with all of this.
Um, You know, I look, I think from a security point of view, the mantra has to be you need AI to fight ai. Yeah. It's the bottom line.
If, if, if your security tools are not leveraging AI to keep up with the AI threat landscape, with the AI empowered threat landscape out there, it they're just not up to snuff. Well, we don't have enough people hours to review code AI's writing. We certainly don't have enough people to manually go after what's happening.
Yeah, right. From an AI Attack standpoint. But I, you know, Terry, I gotta tell you too, I, I was thinking Robocop kind of thing.
I know. Well, you know, I dunno, I guess, you know, I'm old school on the bionic. Um, Yeah, no, look, we have the technology, what was Oscar's last name on that show exactly.
Anybody for extra points? Yeah. And I imagine it's Oscar Golden.
Who? Mike? You got that?
I think. Yeah, it was, it was Oscar Golden. There you go.
There you go. Oscar's last name for 10 points. That was on an A VC Chat.
So this actually, I mean, you kind of hit on something there too, about the resources. Um, you know, I guess one of the most frightening PO parts of this report, and it's not a surprise to anybody, is that, uh, most of the c the CISOs that oversee the AI security and data privacy say they don't have the resources, uh, to do it effectively. I think it was 84% or something like that.
It's really high. Um, which is, you know, doesn't work Well. Well this is, this is the crazy part about it.
So let's tie this block to the last block. So we're gonna take all the money we saved in app dev and use it to buy more security stuff to secure the stuff that the AI agents and robots are creating, right? And so are we saving money that new here, or are we just kind of moving buckets around?
I think we're shifting buckets. Chess pieces. Yeah.
But this is also answer to the question which you had earlier, that what developers could or would do. So this is the biggest shift in the developer skillset that they need to ensure that they are cyber savvy. Mm-hmm.
Well then to your point, and we were talking about this in between blocks, but I'll bring it up now. Do we need like some sort of rating system for the security of the AI applications that we're generating so that when Alan creates something, it'll get a rating that's fairly low. And if Mitch and Garima build something, it'll get a high rating and we'll know what the security issues are just based on the rating and the apps.
So trust me or not, this is already happening. Uh, so when we are using wipe coding, a lot of developers I talk to, they have some kind of a scanning mechanism, PR mechanism who is actually ensuring that we do this and we give the feedback to our coding body. So it is already kind of in making, and the agents, which we will have, will be able to build the trust as well and to ensure that, you know, whatever code we are writing is going through the right code, quality checks.
So let me, let me, let me play devil's advocate here, or you know, AI's best friend for as long as I'm in tech and as long as I'm in security, all I've heard is we've got to get the quality of our code better, right? Uh, Jen Sterly from CSA came out with a thing about a week or two ago. We don't have a a security problem.
We have a software quality problem, right? And that's before AI was writing code. We've, we've been on, that was the whole point of DevSecOps, get developers to write more secure code.
Let's, let's put more secure sec better and more secure code into our pipelines that we deploy. Now, now we got AI generating all this code, and granted spoke to a CTO or a CSO last week who told me that AI generated code has two to three times two to 300% more vulnerabilities than averaged human generated code today. But I think the promise here is that somehow we could get AI to write better quality code at scale than humans are capable of at scale and economically.
Yeah. There's the, the startup, uh, mer core that's like valued at $10 billion and their whole business model is hiring people contractors to train ai, you know, AI training on the, the corpus of the available information is one thing. It it has to have, it has to have built in expertise because the only real way to solve it to generous in easterly point is the problem is that the point of origin.
Because if we don't solve it there, everything hap help else happens downstream. Yep. And we know from theory of constraints, right?
From, from from DevOps, you know, all you're doing is creating more work to happen later. And yes, if AI's gonna do a downstream, okay, but still you're, you're, you're just generating More. Well you gotta get that at the source Work for bots and it's not, and things will get through.
So that's really the only way to solve it, I believe. Yeah, you gotta get it at the source. But if we do that, walk down security or AppSec people as as obsolete as well.
Well, Mike, Mike doesn't like that. I could tell Secure code or AppSec people Just Yeah. It works down to the deliberate organization strategy, which is directly mapped to the economic impact.
So when the software becomes untrustworthy, the unreliable what happens, the economic downturn, right? And that is where the organization's strategy and the deliberate attempt to improve the quality. So it's, it'll take some cycles.
Uh, Ellen, I, uh, I understand, you know, you have been alluding to the fact that this is not new security vulnerability ecosystem needs better focus, you know, better investment. But it's coming. I'm, I'm seeing that the positive side of it.
Yeah. Is it really coming? Because you know, we have managed to build this trillion dollar five it on insecure code.
So I'm like, you know what's gonna be different? That's why it's coming, You know, but, but, but all kidding aside, that is the promise. That is the promise that we're going to do it better with ai.
We're going to, it's not gonna be so insecure 'cause it's because let's you know, you know, the definition of doing the same thing over making the same mistakes over and over again, right? Well, this is a way of maybe breaking that cycle that gives us more hope than trying to say we're going to get human developers to give a crap more about the quality of their codes. I guess now, you know, there's also this bridge in Brooklyn that's for sale.
So let me know if you're interested. Alright. Doubting Michael.
Doubting Michael. Well, and some basic hygiene will go a long way too. I think almost all of the AI related security incidents, uh, in this past year, uh, came about because there wasn't proper AI access controls.
So, yeah. Well, And we gotta remember, we're only this generative AI and now we're moving to Agent ai. This is two, three years old.
I, I will tell you that my confirmation name is indeed Thomas, so there you Was it. Okay, there you go. Michael Thomas, I Bless you son.
Alright, how about in Order? Add one last thing. Go ahead Gima, eat our own dog food.
com survey, which actually reflects the fact that seven, uh, 57%, um, uh, the respondents have negative or neutral, uh, view on the poor quality, code quality and the impact of AI into that. com survey and the report to ensure that, you know, we take the right steps. Look, it's the technology we all love to hate because deep down it scares the hell out of us that's gonna take our jobs.
I'll leave it at that. Hey, this is a great Thursday. Can't wait to see what Friday brings.
Maybe we should ask a I, but you can watch Techstrong TV immediately following today's gang. Um, we've got some good stuff on there. And thank you for watching Mike, John, Mitch, Terry Garima, thank you all for being on the gang today.
Until tomorrow. This is Alan Shimel. We're out.



