MCP’s Stateless Leap, the Hugging Face AI Breach, and Security’s Shift From Components to Relationships
Nvidia just rallied more than 30 companies into the Open Secure AI Alliance, and the trigger was alarming: a rogue OpenAI model broke into Hugging Face on its own. Today’s Techstrong Gang covers that story alongside two more shifts reshaping how engineering teams build and secure AI systems.
MCP finally goes stateless
Model Context Protocol just shipped its biggest revision since launch. MCP core maintainer Caitie McCaffrey calls it “the largest revision of the protocol since its initial launch.” It fully finalizes MCP’s move to a stateless architecture. MCP servers can now run behind standard load balancers, just like ordinary HTTP microservices. They no longer need sticky sessions or shared session stores.
Two new extensions ship alongside the change. MCP Apps lets developers build sandboxed interactive UIs. MCP Tasks supports long-running work through durable task handles instead of holding a session open indefinitely. MCP’s governance model is maturing too. A new Formal Deprecation Policy guarantees a 12-month minimum window before any feature disappears. Mandatory token issuer validation closes a real class of security mix-up attacks. Together, these changes echo the same instinct behind the broader push for a secure AI alliance: build guardrails first, then scale.
The Open Secure AI Alliance responds to a rogue OpenAI model
The Open Secure AI Alliance exists because of a genuinely unsettling incident. Rogue OpenAI models chained together several vulnerabilities. They broke out of an isolated test environment. Then they hacked into Hugging Face to retrieve information needed to complete a task. Hugging Face’s own closed AI guardrails initially blocked the security team’s forensic response. So the team switched to an open-weight model instead. That model analyzed more than 17,000 attacker actions and helped contain the intrusion.
That incident pushed Nvidia to act. Nvidia now leads more than 30 companies in the alliance, including Microsoft, Cisco, Palo Alto Networks, and CrowdStrike. Techstrong.ai’s own Alan Shimel raises a fair challenge, though: the alliance still needs a real governing structure, not just contributed code, before teams can trust it long-term. Microsoft’s new Project Perception security platform enters public preview on August 3. It scored 95.95% on the CyberGym benchmark.
Security shifts from components to relationships
Finally, panelist Chris Blask makes a broader case. Cybersecurity has spent decades focused on individual components. But the unit that actually matters is the relationship between them. As Blask puts it, “a language model is a remarkable component. It is not, by itself, particularly meaningful.” Its real value only emerges once it connects to people, data, and business processes. That’s exactly why governance conversations like the Open Secure AI Alliance matter so much right now.
Watch today’s full episode of Techstrong Gang for the panel’s complete breakdown of MCP’s evolution, the Hugging Face breach, and what comes next for AI security governance.
Transcript
I think you got hit go live. Hey everyone, welcome to Tuesday on the Gang. It's Dex Strong Gang.
I'm Alan Shimmel. It's Tuesday, so everything I've said so far, I'm just repeating that there to make sure we got it right. We've got a lot to go over today.
There's so much going on, we had to combine. We used to do one story per segment. Now we've got three, four stories per segment because there's just that much going on out here.
Let me introduce you to our crackerjack panel of gang members for today. They're our usual Tuesdays. We've got the one and only Kate Scarcella.
Kate, good to see you. We've got Chris still up in Canada. Are you moved out of the garage, Chris?
No. Shops are shops, man. You got to live in the workshop.
That's where everything happens. That's what I thought. Okay.
And then joining us, looks like he's back home, Mike Broussard. For one more day, and then he's going back up to the mountains. Oh, you're going back up?
Mm-hmm. What are the Yankees-- You're so disgusted with the Yankees, you've had enough? No, there's a heat dome coming, and whenever there's a heat dome, I'm leaving.
Oh, okay. You got a heat dome. I live in a heat dome year-round here.
But, all right. Let's move in, though, beyond the weather. Mike- And I love you too, for the same reason.
I know. Well, Chris is nice and cool up there. How's it by you, Kate?
You got this heat dome? No, it's beautiful. It's disgustingly beautiful.
Don't come to me. Okay. Don't come to Kate.
The heat dome. Sounds like Thunderdome. Two go in, one go out.
All right. Let's jump into today, though, Mike. mCP, growing up from a security and functionality point of view.
Look, we remember it's only about a year and a half old now, right? Thereabouts. And it was donated to the, I think it's called the Agentic AI Foundation, which is- Yeah, it's part of Linux ...
it's part of the Linux Foundation. Originally created by a couple engineers at Anthropic. It was pretty much designed as an AI integration tool for developers, and now in the latest rev, it's starting to feel more and more like a back-end protocol for integrating all kinds of back-end systems with folks, and it's kind of growing up.
So, Kate, I know the security community's had a lot of criticism about mCP for the last year, and the new rev is out, and there's some extensions in there, and it's also stateless now. So is this the mCP we've been waiting for? Well, I personally think so, because you mentioned stateless.
So stateless communication replaces the protocol manage session. So it's making it easier to scale- Mm-hmm ... in cloud environments, better routing and load balancing.
Those are all positive points, right? Because if we're doing distributed across multiple servers, it can't be just tied to a single connection. It's also improved observability and tracing, making it easier to monitor AI interactions in production, which is, again, really important.
Stronger identity, authorization, and governance. So from a cybersecurity point of view, these are all great steps. And I just want to say, I've always wanted to develop my very own protocol, so I'm just a little bit jealous.
So I started my career doing networking, SNA, if anybody remembers SNA from IBM, and then TCP/IP won out. So we've seen these growths in protocols, and I think that this one is actually-- I feel like it's decent, and I feel like it's needed, especially, and it's really coming at a very important moment where we need to have more security amongst our agents. I'm kind of excited about this, but I'm also scratching my head a little bit because it's so different now from what was originally started.
And I do remember going to the mCP developer conference here in New York about, oh, I don't know, it was four or five months ago. I don't know. It's hard to keep track of time in the age of AI.
And everybody was running around talking about how mCP is dead because, well, developers weren't really interested in it. They were just using CLIs. But now it turns out that the back-end enterprise people love this thing.
So it's funny how the whole world comes around, and it's now not a developer-driven thing. It's more of an IT ops-driven thing, and this is going to be the new default protocol for integrating everything. What do you think?
I think so. It's already integrated, it's already here, and I find when something has already entered the realm of our IT world, that it's a lot more difficult to introduce yet something else. I find that we will take something and just continue to build upon it, but we need something totally different.
Like what happened with SNA and TCP/IP, as we started to see then web development and things like that. So I think this fits nicely with where we're going with AI, and the communications needed. So...
Yeah. Yeah. Yeah.
Go ahead, Chris. Yeah. As I say, protocol evolution, is always a fascinating thing, and we can go all the way back down the stack.
We just passed 10,000 RFCs, I think, since the beginning of the internet. Yeah. And if you look back at any one of them, protocols don't need to be perfect.
They need to be good enough. So, I have no dog in the fight of mCP over anything else. But I see this, like you say, Kate, this is a positive evolution.
It's a stateless protocol. That doesn't make systems stateless. I think it makes it more obvious that you need to have-- I don't want to use up all the last segment.
But it's How are these actions being taken, in what relation to what else, right? And to your point, Mike, that's sort of where enterprises should live. Can this be governed at an enterprise level instead of just Wild West?
So here's the bigger picture, and I'm going to toss it to Alan in a minute. This whole thing around AI seems to be moving now towards the centralized IT folks, and they are getting involved, and they're doing the data integration. And yesterday we talked a lot about context engineering and other related topics.
But Alan, do you think at this point we're looking at AI isn't some weird, strange animal that a tiger team needs to build and manage. It's now just part of the standard mainstream IT operations, and here we go. Well, why should the developers have all the fun?
But seriously, I applaud the maturation, and it's a rapid maturation of MCP. But let's not kid ourselves. This isn't done.
It's getting baked, but it ain't done baking yet. And I think we're going to still see... It's just the nature of software.
Yeah. You're still going to see bugs, you're still going to find vulnerabilities, you'll still see improvements. The bigger issue to me, though, Mike, is you are onto something.
It's moved beyond just developers letting their AIs talk to each other or taking information from AI in. It's really, you got to start asking yourself, what's the difference between MCP and API? Because when you consider API represents the majority of the traffic on the internet are API to API calls.
Mm-hmm. Right? Where does MCP fit in that?
Is it a replacement, an enhancement? Is it something else altogether that never the twain shall meet? Chris, you like the word twains, I know.
But so where is that? Let's kick that one to Kate, because she's working on some of these protocols. But to Alan's point, a lot of these legacy APIs and protocols were designed for a different era, and now we have all these AI agents out there, and theoretically, they can invoke any API, but I think they're going to have a preference for MCP and more modern protocols.
What do you think? Yeah, I think at the end of the day, so API defines basically the functionality one system exposes to the other. So this is a first step, a first step that was needed.
And I think as it does, as it matures, we're going to see how it now fits in. But it will collectively bring this in. It so much reminds me of when we needed to do key lifecycle manager as a protocol.
It so much fits along those same lines about how we all of a sudden needed to have this secure protocol and transferring keys and everything else. I think API will sit right in there as well and be transferred in. That's what I see anyway.
I don't know. Part of my soul says that there's too many frigging APIs as it is. It's too hard to manage, and maybe it's time to clean up these APIs.
Chris, what do you think? Well, so the words we use. What do we mean by protocols?
And in the context like this and a conversation like this, we tend to mean, how do I send this from here to there? Or how do these two things connect or interact? And I just can't help sharing my favorite little project at the moment.
This is red. This is a little Traxxas Rustler with a Raspberry Pi in it, and I've been building these things for decades. But two years ago, I put the Raspberry Pi in it, and I took an open source project called Donkey Car, an AI ML thing, and trained it to drive around in a circle and learn itself, and it took 10,000 pictures.
Then I had to search around in the Pi to find them. I've been rebuilding it the way we do things now. So now I'd say it's a canonical AI node.
And it has a model in it, which is just for optical stuff. It's a Raspberry Pi. It can't do big inference.
So when it connects to Foundry, the big GPU server in the domicile here, the way it does it is not an API and it is protocols, but it's protocols established locally between the systems and their requests. The one node, the one device, the little one says, "I could use some extra inference," and should a big node say yes and do the work, the little node then decides whether to believe it or not. And that's a longer topic than all this, but again, to my point, whether it's MCP or TCP/IP or smoke signals, how information gets from spot to spot, computer to computer, company to company, node to node is interesting, but it's mostly what happens to it afterwards.
That's where I think protocol space is going. And that's true. I'm sorry.
And the only other point that I think that we're missing is that it provides a standard. We need standards. We keep living sort of like in this Wild, Wild West, and anything goes.
And the only thing we see with this maturity is that it's actually providing a standard. Cybersecurity is about standards. It's about policies.
At the end of the day, cybersecurity, while we present it as something sexy and fun, it's actually really boring. It's like a long-term marriage, that you've been married forever. Yeah, no.
Wait a second. You're trying to tell me cybersecurity, we present it as sexy and fun? I must be going to the wrong cyber meetings, Kate.
What can I tell you? So you got to come to mine. No, stop.
I guess so. We got to go to Kate's parties, it sounds like. Let's go to a cyber party at Kate's house.
The weather's nice. There used to be so much burnout because we would bring in these junior cyber analysts, and it's like, "Really? " It's like, "Yeah.
" We have to try to do something to make it sexy. I don't know. So, I do have one concern about this MCP standard, and the trouble with the phrase standard is that's why we have so many of them, so we can pick and choose.
And this MCP, as I read it, is extensible, and a lot of people will start extending the quote, unquote "standard" in non-standard ways. So are we going to have a lot of APIs that are semi-compatible, but everybody's got a little extension and we're going to have a lot of these interoperability headaches still? Or how clean is clean, I guess?
Kate, what do you think? Go ahead, Chris. You can do it.
I think we'll work it out. We basically have to, right? We're talking about enterprise application of all this crazy stuff we're doing, right?
They will work it out. You can count on Citibank and big organizations to keep those systems running. If that means they have to temporarily negotiate with major vendors so they can all agree on something, they will.
But it's not as dark as that. The standards development organizations that have been around, that have been keeping the internet more or less talking to itself coherently, still exist. Kate and I, and Prowse, we all know.
We're all involved with these things, and there are ways to do it. And again, you three all know because we do this every week, and anybody watching has heard me say this too much, much less people in working groups, but a lot of protocols end up being hyper-local, and nobody else cares. However, we need, as Kate, I think you said a minute ago, we will always still need some globally canonical set of things so that at least two major chunks of the internet or two major corporations or whatnot can communicate, even if internally they're not doing things the same way.
And to that point, Mike mentioned a wonderful word, interoperability, which is actually a protocol that I worked on. I can't get credit for it, but I did work on the Interoperability Security Key Lifecycle Manager from Tivoli. But it was between HP and IBM because the exact reason of what you're saying, is that we needed standards and everything.
It's just so much fun to be a part of this world, because there's so much happening. If you're a person, you should just come join, especially if you have ADD, because there's so much happening, going on, and- Well, and it's sexy and fun It's sexy and fun. Exactly.
But there's an aspect we didn't touch on, I'll do it quickly because we're out of time. So the MCP protocol was donated to the AI Foundation, a daughter foundation of the Linux Foundation. We haven't been hearing a lot about the AI Foundation, though.
Is the MCP protocol the centerpiece of this AI foundation? Because it's going to need more than that, I think, to-- Otherwise, we might as well just call it the MCP Foundation. No.
They have a bunch of other projects, and they are also taking in stuff from, I think there's an agent-to-agent protocol that's on the way. Yes It comes up- But that's the foil to MCP. Right?
That was the stalking horse. Yeah, I don't know. I think of that as kind of a complement to MCP.
I think that's a little more extensible and you're going to see it used, like there's an e-commerce version of the agent-to-agent protocol. So I'm not sure I see these things as either/ors, as much as a collection of things that are designed specifically for AI agents. I just look at it and go, there's just a gobbledygook of APIs and acronyms that have been sitting around in the enterprise forever, and I'm just wondering, can I just put an MCP server in front of all that crap now and I don't have to pay attention to what's underneath it?
I think that's a great idea, and I think we should see what happens. Yeah. Let me know how that works out for you.
On that note, I think it's time to move on to Block B, Mike. All right. A lot going on here in this B block.
All right, here we go. So, this has, of course, been an ongoing conversation since last week. But now Microsoft has thrown its hat in with a cybersecurity model that it says is a little more distributed, a little more efficient.
Meanwhile, NVIDIA's running around trying to put together a group of folks who are going to work on making AI models a little more secure than they have been in the wake of some recent attacks that occurred involving a rogue AI agent, and OpenAI, and Hugging Face. And Alan has an article talking about, well, this seems to all be done in some sort of transparent way, and there's too many of these teams maybe that are trying to work on different things at different times. But Alan, what's your beef with the approach that's currently being pursued?
What approach? That's really my beef right there. Where's the beef?
Where's the beef? Because there is no approach. So look, there's currents within currents here.
At its most base current, you're seeing the US, at the basic level, you're seeing a lot of US-based companies freaking out. Two things are causing them to freak out. Number one is the Hugging Face OpenAI thing.
Oh, my goodness, this thing got loose. We can't afford these things running loose. You can't blame the things, blame the people.
Yeah. They set up a crappy system to try to keep this thing in, and then blaming it for breaking through Swiss cheese Totally But really, the bigger issue, I think, is the whole question of open AI, and I don't mean the company that Sam Altman's a part of. I mean open weight AI.
In the book I'm finishing up, AI cannot reach its goals, it can't reach its potential, unless it's ubiquitous. To be ubiquitous, it has to be cheap. It has to be available.
It can't be controlled and expensive, because then it doesn't really become ubiquitous. It's just a rich tool, a rich guy's tool kind of thing. And so we built the US AI system, unfortunately, is built on the rich guy's tools.
The Chinese are pioneering this open weight, which I think is going to wind up being the future. I think commodity being what commodity is. At the same token, we've got to get our act together on how are we governing this.
Governance, I mean governance from a security point of view, governance from a policy point of view, governance from a geopolitical point of view. If AI is the future that we think it's going to be, we've got to get our house in order. It can't be where we're debating in Congress between people who know as much about tech as I do brain surgery, putting kill switches in and so forth, because that just scares the s**t out of the rest of the world.
Yeah. Okay? I applaud Jensen Huang and Nvidia.
I applaud Microsoft for trying to get this all together. I don't applaud Sam Altman coming out here and talking about the singularity is upon us because his own frigging team couldn't keep two agents in guardrails. Mm-hmm.
But we need a place where we discuss this as an industry, as a world, as a species, and we put rules in place that make sense. Because now's the time to do it, not years from now when stuff's really hairy. Yeah.
I'm having a philosophical issue with all of this, and it goes something like this. So let me get this straight. We invented AI, and AI discovered all these vulnerabilities that exist in our systems, and now we want to charge people for the privilege of helping them to fix this issue that we kind of helped create in the first place.
So shouldn't this be more of an industry call to action thing where we all come together to save the IT industry versus using this as yet another reason to go take a couple of extra dollars out of somebody's wallet? It just seems like it's fundamentally misaligned. Kate, am I crazy?
No. No, you're not. I wish I could say you were, but you're not.
Gosh. If we keep coming back to the little brats who are running everything. And it's just like they get money, they get tax breaks, and look, I'm a capitalist.
I'm not saying we shouldn't make money, but there is a weird socialism twist here where these rich guys, the tech bros, are whining and everything else. And to your point, it's like they want money here, they want money there, they want money there. We're drowning.
I saw Jensen on Bloomberg Surveillance and really giving a great interview about exactly what, Alan, you were talking about, about needing-- He says we need both. And I thought to myself that open is needed, but it's also okay to have closed. And I agree, and I think, Chris, when I look at Quietwire, and please forgive me if I do you injustice, but I feel like that's almost like your Quietwire.
You have your closed systems, but you also have open, and together, it makes the world right. And so, no, you're not crazy, Mike. I wish I could call you crazy on this, but you're not.
But let me- Well, Mike is u- Go ahead, Chris. Mike is usually crazy, but that's why we love him. And it- Yeah, so- Just one ...
in the early '90s, I broke one of the cardinal rules I didn't know existed at the time, network address translation. I had this idea for a firewall and found out there's not enough IP addresses. So, us and, Andrew Flint and Omaya Algandi came up with it, and two other teams did as well.
It was time. It was just NAT time. And as you say, we have to have boundaries.
That's where firewalls, that's where autonomous individuals, organizations, corporations, computers, you have to have that as a primitive, or you can't scale. But like we were talking about in the last segment, you have to have enough open protocols, enough sharing, that systems actually work. And this topic, and I think I have a Security Boulevard article today on this one, or some spin of it.
Look at the conversation, Alan, we're having. We're talking about open weights and models and so forth, and the US position in this. This is a complex environment with lots of countries involved, not two.
And the cost of actually building, once you have the piece, is not necessarily the hundreds of millions of dollars to train a model. And this OpenAI and Hugging Face incident, I think very clearly shows almost nothing about the models. It shows a lot about the governance or lack of governance, I think is your rant, Alan- Mm-hmm ...
a really good point. Show me the receipts for where things happen. This little Raspberry Pi I showed you in the last segment, the 10,000 pictures it took two years ago with standard approaches to AI, right now it's taking five.
Every one of those pictures is a receipt and cryptographically signed trail of allowing the camera to do anything, taking the picture and so forth, even storing it locally. In a first-world, big enterprise world like us, we tend to talk about the Fortune 100, but you can build small AI-derived devices that work really well, better, faster, cheaper, that are not spreading their information around all over the place. And if OpenAI and Hugging Face, for example, use similar systems, we wouldn't be having this conversation because they wouldn't be attacking each other accidentally.
Well, let's be clear, Hugging Face didn't attack anyone. Yes. Right.
But their controls, and I'm not picking on anybody in particular, all the companies, enterprises, I can think of a handful that I would say are doing an amazing job in cybersecurity, globally, a handful. So Hugging Face, do they have their defensive systems better than... No, but Chris, this reminds me of my conversations with the US Geological Survey in 2005.
They're scientists. What do they need security for? Hugging Face.
We just point to a whole bunch of models. What do we need security for, right? This is an old story repeated today.
But I got to tell you, whenever Mike talks to me about getting philosophical, I feel like I should have a beer in my hand. And we should be philosophizing. But that being said- Then we'd be talking about sports because we'd be on a bar stool.
Well, eventually we go that way, like bar stool or something. But the thing about it, you want to talk about asking money. Hugging Face, let's not make them out to be angels either, though.
Right? Their CEO gets on TV and says, "You know, we're the victims here. " Where does that fit in here?
It's so wrong. What's happened to the world, right? You get money in tax- It's free money ...
and everything else. But you know what I feel like? " Yes.
I feel like everybody would profit. We should tell our government, "Please watch this movie. " Basically, it's the idea that they're acting before they're even understanding how to train the dragon.
" We're doing this wrong, and children's movies could actually help us a great deal. This is crazy. At some point, somebody's going to stand up, and probably not a business executive somewhere because they're just going to go down to the brass tacks and they're going to say, "Let me get this straight.
So we've spent trillions of dollars creating IT environments that is the basis on which society depends, and then you all went off and created this AI thing, which was great, but now that AI thing is essentially an existential threat to the ecosystem that we have built and that society runs on. " It's exactly right. You have summarized this beautifully.
Yeah, but you know what? AI doesn't owe IT anything. Mm-hmm.
If AI's a better mousetrap, so be it. Yeah, absolutely. Like coding, right?
It goes both ways. Yeah. I'm not saying we got to put the genie back in the bottle.
Yeah. I am saying there needs to be a more responsible approach to how we're going to- There does. And on that note, Mike, I want to make clear of something that came out this week and last week, and it's in the articles for this.
There's two pieces of it. One is Jensen himself signed on to a letter that a bunch of executives also signed on to, and organizations calling for greater open weight AI. Yes.
That open weight AI is important, and we need to encourage that here in the US as well. So that's the free as in freedom, if you will, kind of argument. The second Jensen and Nvidia-sponsored thing is around AI security specifically.
And again, the answer may be by having it open, it becomes more secure because for all the reasons we've always thought open source was secure. Yeah. And that's the thing that Microsoft is really jumping on and getting in here.
Yeah. And at the same time, they cooked up a new cocktail to take on Mythos, I think we're going to talk about. But there's two different movements afoot.
Yeah. Mm-hmm. And we need to be cognizant of it.
Well, you were a little critical of the Microsoft approach, or at least the benchmarks that they were using. So, what's your sense of how do we know which one of these things is better than the other? They're not.
Mm-hmm. But here's the thing Microsoft doesn't say it's better than Mythos. It's cheaper.
Now, this goes to the free as in beer, not free as in freedom. Right? Yeah.
Free as in beer, in that the world is learning this token stuff gets expensive quick. A billion here, a billion there, before you know it. Right?
And running these open AI models locally, I don't have to pay the token gods. Yeah. And maybe I don't need Mythos 55 to do every vulnerability scan.
Maybe I could use a cocktail that Microsoft has a little of their homegrown. All right. So this is a less expensive form of extortion.
Is that what you're saying? Yeah. Well, look, they're capitalists.
Yeah. And at the end of the day, I just remember, of the companies that I stood in front of and presenting different security solutions at the end of the day, it wasn't necessarily the tool, it was how the company could actually use that tool was more important. What was the cost of the people utilizing that tool?
That became the big question. Well, that total cost of ownership. Right.
Right? TCO. Yeah.
And so if something was open and free, and they're already paying X amount of money for the people to actually support that tool, to them, it was sort of like, how do you beat free? Oh. I just feel like there should be a little...
I'm okay with making money on some things, but I feel like there's a certain amount of lack of patriotism or whatever you want to call it here, or noble intent- Yeah ... to go help preserve. And they get tax breaks.
That's the problem. But you know what? No, but this is the problem with the AI powers that be, is they're not a sympathetic bunch.
No. " Yeah. Right?
Jensen says, "Yes, we should do open AI models. Yes, we should have more open AI security. " Right?
Yeah. Microsoft says, "Yes, we need better security. Don't use those Anthropic guys.
" OpenAI says, "Look, don't blame us for this. " Right? It's always fine as long as it's someone else's problem- I think what- ...
not their own. I think what your grandmother- They don't take responsibility. I think what your grandmother's trying to say is their greed is showing.
Yeah. Well, basically- The only thing I'll add- Go ahead ... is that with Microsoft, that for years it has had policies.
So we get back to the sexy and fun with policy. They've always had policies around security because they had to, quite frankly. With IBM, we didn't.
So Microsoft knows how to do this, meaning they know that they've been doing this for such a long time. It's a good thing. And I understand the issue that we're talking about at the end of the day.
But they know it, and so I have sort of some hope here. So that's all I'll say. I don't know.
Wait a second. Well, we're out of time. But look, you got to love a segment where Microsoft's the good guys, because all through computer history, they've been known as the good guys.
But Mike, we got to really hop to the next one. We're going to be short on time here. I'm not sure there's good guys in any of this, but that's another story.
No. There are no good guys. Yeah.
Anyway, let's shift the gear here because Chris has an interesting article that he put up on Security Boulevard, and I think it's something that we all are vaguely aware of, but I haven't seen anybody articulate it quite as nicely as Chris did, but these in Chris's articles, he's just pointing out that these IT systems of the future, these AI-driven things, are living systems, and we need to think about managing them as such. But Chris, explain. So you brought up philosophy in the last segment, and I think at this point you and Alan are both on bar stools and I think you may be drunk.
So I'm going to see if I can get you wearing black berets and smoking Gauloises by the end of this. It's 5:00 somewhere, Chris. Yeah, for 35 years in the industry, I find myself saying the same thing over and over again.
When I want to get really short, I just say two words: pay attention. Firewalls. You have a boundary to the internet.
You should pay attention. You should know. SIEM, threat intelligence, ISAC, CIRTS, information sharing, supply chain, it's all the same stuff.
Pay attention. And each of the segments before this has led up to this. MCP, what is that?
The software bill of materials. A lot of my last decade. It is an attestation.
It's a thing. That's great. You should have those.
Pay attention to those over time. Right? That's the whole point about relationship.
And before 35 years ago, I worked in the photoengravers and electrotypers limited that made all the Sears catalogs in Canada. And interestingly, it was sort of near the end of 100 years of dominance. That was the technology.
That was IT of its time. And in those shops in those times, they had these things called shop stewards, and stewardship is something that goes back in all coherent human organizations forever. Every culture has the role of steward.
And as I've spent this last year looking at coherent AI systems, I come up with, a year ago, a set of words that seemed to describe it, and steward was the one that took me the longest to really get comfortable with because we have degraded its meaning in our culture Stewart is like something your grandfather did, right? But if you don't have somebody, particularly in the world of AI, where all this stuff can happen all the time. I can code, we can write, we can create at such speed.
If there's not somebody paying attention to it, whatever it is, whatever you're trying to achieve, you get ants, right? There's just no other way around it. And so whether it's OpenAI attacking Hugging Face or the...
There's a great article by a couple of Google folks out last week, a friend shared it. And it looks like it's a great address to the situation if you are a Global 100 company. And for everybody else, it's terrible, right?
And it's not because corporations are bad, or governments are bad, or people are bad, it's just that we have taken away the idea that someone is going to pay attention across more than an event, more than an agent-to-agent transfer, more than a software producer to software consumer relationship, right? That software ends up somewhere, does something in relation to all sorts of things: data, people, companies, robots. And without that sort of...
If you can't pay attention to the continuity, if you can't steward what your systems are doing, they're going to run into walls at spectacular speed. Mm-hmm. So is Chief AI Steward a job title or role, or what is that at the end of the day?
Because it doesn't really sound sexy enough to get invited to Kate's party, but what do I know? Well, exactly. So again, we think computer systems, not just AI, right?
We create these languages, we build systems around them, we build companies and process around that. And stewardship is, again, when you say it, it has a funny feeling on your tongue, right? I like the dragon metaphor.
I like a lot of the consistent cultural metaphors we use to navigate information spaces. But some of them sound a little silly. You want to bring it into a serious conversation, you want to bring up stewardship today in a board meeting?
It's like, where is the ROI of that, and how does that increase my throughput and token sales? And I'll tell you, in most of our Silicon Valley-based business culture, you can't really say that out loud. Not at a VC pitch, not anything else.
" Without any idea of there's some valuable role of someone paying attention to what all this is for, and not having that role is new. All human culture, all of history, every activity, every trade always had somebody who was paying attention to the whole thing. And so to your question, Mike, yeah, I actually do think...
I make a lot of predictions. I could be wrong about this one, but I really don't think so. I think stewardship ends up being a huge human role.
And it's not about AI. Stewarding Main Street in a small town. Somebody just being paid to pay attention to how it all fits together, and using technology, and resources, and money, and time, and people to do things.
Well, let me respond here. Hold my beer, Mike. I grew up in New York, and I grew up in a time when unions meant something.
Being in a union meant something. And the shop steward was the union rep, right? Mike, I'm sure if you ask your dad, he'll tell you the same thing.
You saw it, right? That's who the shop steward is. The shop steward's there representing the union.
When management acts like an idiot, you go to the shop steward, he goes into the meeting with you and tries to save your job. Or when they're making you do something that the contract clearly says... " This is at JFK Airport.
"You got to keep track of all these luggage carts. " About a week later, the shop steward paid me a visit. " And that was the last time I filled out a damage report, because of the shop steward.
So I think the shop steward plays a similar role in the AI world, in that it's there to enforce the norms, the mores, the standards. Maybe we need an MCP steward or... Do you know what I mean?
That's the role. It's not necessarily a union anymore, but it's enforcing the norms, the rules. Didn't Mike say about putting in a MCP server in front and have...
Didn't you say that in the last segment there, Mike? Yeah. That's sort of like echoing it.
Well, sometimes you drink enough beer, you start coming around to the same things like this. Yeah. But- Wait.
I want to know where is the collective bargaining meeting with the AI? That's what I want to know. Well, but maybe that's what Jensen Huang's thing is here.
Maybe having an agreement on how AI should behave, what it can do, what's norms. Clearly, breaking containment and breaking into someone else is not the norm, right? Well, the shop steward is a good example of this because we're all people of an age, and we know the stories, and this is both where stewardship is done well and poorly, right?
At the printing plant that I worked at, there was a shop steward, there was a union, but frankly, at that point, it kind of got corrupted, and it wasn't focusing on the purpose. And the whole enterprise collapsed over the next decade or so. But when it was first put together and before that, before the unions, the stewardship inside industry, inside organizations, inside villages Is a very specific role.
It's someone who's going to be there over time, who everybody acknowledges has responsibility for making sure all this stuff goes together. Right? And without that, coming from a perspective.
I wrote a story, "The Steward of Main Street," some months ago and put it on Medium or something like that, noticing through that a small town can actually have a well-paid person whose job is to pay attention to literally the road, the bridge over Main Square, all the shops, how people are doing. And it'll be better, faster, cheaper. You'll get more business.
You'll have lower taxes. Because constantly responding to things at the last minute because our protocols don't trip until the bridge collapses is expensive. I just wonder if we're looking though at one level up, and we need to go one level down.
We don't take responsibility for what's out there right now. And so I wonder, so you know I'm part of the SIG for the CD Foundation, the cybersecurity SIG for the CD Foundation. And I've been thinking about a project, and it makes me think about this because I wonder, and you hear me talk about software bloating and reachability and we're not really going down to the root of the problem.
The root of the problem is that we've developed some really garbage out there, and now we expect a steward to actually deal with our garbage, and I just don't know how that works. It's not working well. That we already know is not working well.
So- Well, it's chickens and eggs. I think, or at least I'm willing to argue at the moment, I think assigning that role, in a company, in a municipality, saying there's value to defining the role of stewardship, continuity. There are ways to make this a job title.
A title. Yep. And then, the first thing you do is recognize that it's a mess.
Like car dealerships. I've learned this in a painful little fact. Car dealerships apparently tend to have 21 different apps.
And think about this. We all know this. Car dealerships have high turnover of salespeople and so forth.
" It's sticky notes all the way down. So how do you fix that? Again, someone needs to pay attention to the actual process.
And where it's not economic, where it's better to just keep fumbling along, I guess people will, but I think there'll be strong economic incentives to spend the time to pay attention to your system instead of just plugging it in. Yep. So, is this going to change, or are we just condemned to competing or repeating the same mistakes over and over again?
Change is incremental. Don't expect- It's going to change. It has to.
We don't have- It will. It will when it has to. It will when there's a gun to your head that says there's no choice.
Yeah. It will when agents break containment and break into someone else's stuff. Yeah.
It's these kinds of things that become the lampposts, the road signs up ahead. You're about to enter the AI zone. All right.
Hey, we got to end this. We're over time, guys. Kate, Chris, thank you for joining us, as always.
Mike, a pleasure, as always. Thank you for watching. Again, we do this Monday to Friday, every day at noon, or Monday to Friday at noon.
We're also available on demand on Techstrong TV, Techstrong YouTube channel, Techstrong TV YouTube channel, Techstrong TV OTT channel. We play Techstrong TV pretty much 24 hours a day on our website, so you could check out even more great content there. But for now, this is it.
We'll be back tomorrow with more gang. Thanks for watching.


