AI New Deal vs. Glasswing Cyber Shield: OpenAI’s Robot Tax & $1M Observability Budgets
Alan, Mike, Mitch, Teri Robinson, Andi Mann and Futurum analyst Guy Currier break down OpenAI’s proposed “New Deal” for the age of superintelligence, including what a people-first AI industrial policy could actually mean for the future of work, wealth and infrastructure.
Then the gang digs into Anthropic’s unprecedented industry alliance around a restricted cybersecurity model built to find software vulnerabilities before attackers do—and why some AI may be too powerful to release broadly. Finally, the conversation turns to new Futurum Group research showing organizations are preparing to make major observability investments as AI systems, automation and modern application environments raise the stakes for visibility, resilience and control.
Transcript
Hey everybody, welcome to Techstrong gang. We have an awesome assortment of folks talking about, well, the latest and craziest because just when you thought it couldn't get more insane, it does. Let me welcome our guest today, Mitch Ashley.
How you doing, buddy? Hey. As always, great to be here, Mike.
Thank you. John Schwartz, coming to us from Chicago, along with Guy Currie. You're both in Chicago, right?
Actually, I'm in New York- We are ... as you can see. All right.
Just not in the same place at the same time. No. And Terry Robinson.
Terry, good to see you as always, with your familiar New York City brick wall. Welcome. And then Andy Mann, I believe you're in Colorado.
You got it. In the beautiful downtown, 26 square miles of reality, Boulder. See?
This is how this is all squaring up. I got two in Chicago, I got two in Colorado, and Terry and I are in New York. So it's two, two, two.
Oh. There you go. Yeah.
Go figure. That's pretty cool. It's almost like we planned it.
But speaking of planning, OpenAI has put out a new deal proposal, essentially, in the age of AI, and has all kinds of fun things in it. Like the assumption of a four-day work week, and it has some assumptions about what will happen when there's a significant amount of unemployment. At the same time, there is an article out there that suggests that the CEO of OpenAI might not be working with a full deck, and I'll let John explain that later.
But John, walk us through what's going on here. Is this the new deal that we need? Would FDR be proud, or would this be kind of like, this is done?
He'd probably be cringing, to be honest. It's OpenAI, in other words, and it kind of relates to the mental state or the mental acuity of their CEO. And I don't mean to be too rude or harsh, but I will talk about that later.
Hopefully, Alan is going to join us because he wrote a very interesting shimmy take on this. So OpenAI has this new blueprint around superintelligence, and they're arguing that the policies that are in place now, whether involving taxes, the workforce, they need to be ramped up significantly as superintelligence hurtles its way towards us. So they came up with this 13-page plan, it's called "Industrial Policy in the Intelligence Age," and they're promoting this creation of a national public wealth fund, among other things.
And to do this, to fund this, to protect a tax base that they think is going to be hollowed out by automation, they're proposing a robot tax against companies that replace humans with automated systems, a move towards higher capital gains and corporate income taxes, and using fund returns to provide citizen dividends. So this is a very kind of sprawling idea. They also mentioned, as Mike said earlier, the idea of a four-day work week.
So this is all from the brain trust of the folks at OpenAI, which juxtaposed, unfortunately for them, with a sprawling investigative report from The New Yorker. And if you wondered what happened to Rowan... What's his name again?
Rowan Darrah. Rowan and Darrah. Yes.
Rowan and Darrah. Right. Well, if you're wondering what happened to him, he disappeared for a year and a half.
He's been working on this story with another reporter. Andrew Brands. And they call into question with interviews and documents, et cetera, kind of the stewardship of OpenAI and the business ethics and mental wellbeing of Sam Altman, who some people refer to as a sociopath.
And- ... the report is undergirded by the leadership of OpenAI, which involves dishonesty, or let's just say, let's be blunt, lying, disregard for the safety of AI, which kind of brings us back to, do we really want to follow a policy plan from these guys? And also this manipulation that goes on within the company.
So there are a number of people quoted, and to be fair to OpenAI, they said much of this was kind of already covered before. It's being regurgitated. But it does call into question, it did do a very good job of synthesizing the very attitude about Altman and why many of his co-founders have left to create companies that compete with OpenAI or try to take a different tact.
So there's a lot to digest. I understand. But OpenAI, whether we like it or not, is the center of many of the things that are going to happen in the near-term future.
I'm not sure about the long-term. And it's a lot of stuff to think about and digest, and fortunately, we're trying to get this out in the open before things escalate even worse. Guy, what's your take on this?
Because as I read it, I couldn't help but laugh. I was like, "Wow, this could've been written by the mayor of New York. " So it's a good program.
It's a great proposal. It's terrific that it's coming out now, before some kind of political change that may be brewing in the United States that would make it more suspect. It kick-starts or pushes further, faster now a discussion that we must have, which is what to do with the likely disruption in at least the economy, the world economy, thanks to the use of AI.
The main criticism of it is John's criticism, which is these are the bad guys that produced it And I'm a little reminded of this idea of when we find out decades or centuries later that whatever author is our favorite author or what have you turned out to be a venal, horrible person in real life, should you take that into your reading of it? I think that we can suspect their motives all day long, but I rather suspect that there are still plenty of... Remember, OpenAI was built, as the article in "The New Yorker" that John alludes to makes clear, OpenAI was built originally, it's still a nonprofit technically, and it was built to counter the potential dangers of OpenAI.
That was literally Sam Altman's pitch to Elon Musk to start the whole thing off, and I rather suspect there's a lot of people there who are still doing that kind of work, and that this is partly a product of it. But unlike usual, I really can't say anything bad about this other than... Well, actually, I can't.
I can't bring my cynicism to it. And it's worth reading, and it's worth developing, and it's not the final say, it's the first say, but it's a pretty good complete first say. Yeah, I was going to say, it's a good start.
It's a noble idea. I just don't trust the people behind it. So, yeah, I would make that clear.
Yeah, it's- It's not the what, it's the who. It's the who, right. And I don't- That's what's problematic, Terry, but- Yeah ...
the what is really important. It's really important. Well, yeah, it is.
The public importance. So my problem with the whole thing is, great, I'm glad you published this, but in the halls of Congress and in the White House, I'm not hearing any politicians that are remotely even discussing this or are pushing any ideas forward. And I feel like this is going to be one of those things where we put the message in the bottle and threw it in the ocean, and that's the last we saw of it.
So Andy, what's your sense of how real is any of this stuff? Oh, look, this guy's David Copperfield, isn't he? I mean, where's the sleight of hand?
I don't buy it for a second. Look, I want this. I want the discussion.
I want the conversation. We need to talk about it. We need to understand the impact.
Just looking at this year alone, we've seen hundreds of thousands of layoffs. Oracle last week, 30,000 layoffs. By email, by the way.
Thanks for coming. There's your loyalty. Amazon, Block, Atlassian, Meta, so many layoffs, and they're mostly being prescribed for AI reasons.
We've got to have a conversation about this. When you lay people off and get agents to do the work, you know what? Agents don't go and buy a coffee at Starbucks every morning.
Agents don't go to Walmart and buy a new sofa with their earnings because they don't got any. And look, I look at Sam Altman and you- Either do I. I don't buy a sofa at Walmart either, but okay.
Right. But Altman lurches from edge to edge of this discussion, and so I cannot ascribe to him any credibility. And so when I look at this, all I can assume is there is a sleight of hand.
Don't look behind the curtain. I'm doing all this over here. I'm saying the nice things, so don't punish me.
But meanwhile over here, I'm helping people lay off another 100,000 workers. Yeah. I don't know.
I'm not buying it. Yeah, I think you're right. I think it's just kind of his preemptive, not a preemptive move, but he probably foresees and knows how workforce is going to get ravaged by this.
And the heat's going to be falling on them, so... And I'm being a cynic here, but why not come out with a plan that says, "We've addressed this. We're on top of things.
" Because they can't. Yeah. They're not in a place to do it.
This is a problem that no one company is going to fix, gentlemen. This is foundational. And lady, I'm sorry, not just gentlemen.
It's okay. I'm sorry I just joined us. I just came off a webinar.
But guys, look, the world changed yesterday. The world changed. Between this and Mythos, the world changed yesterday.
And we can't-- This is going to take a community. This is going to take nations. You know what?
You have nothing to fear but AI itself, as I wrote in my article. This is not something that... We can't blame slippery Sam or Darren or Modi or any one company.
The foundations that our world is built on are changing, and this is a time for brave leadership, thoughtful leadership, visionary leadership. Where's the next Teddy Roosevelt or Franklin Roosevelt or great leader like that? But even, it's going to take that.
But Alan, to that point, systems don't change until they have to. Right? We can be intentional about wanting to change things and do incremental improvement, but you don't have substantial, let's go to a totally different economic model.
This is more than the Industrial Revolution, right? This is everybody revolution, potentially. " The real issue is we have to have a response for when people are in the streets and with pitchforks and torches.
And what's going to happen? But Mitch, we have lived this. That's what's going to force it, I think.
I think that's where we are. Let me give you, we do have a historical perspective for this. It's the age of the robber barons.
Right? You had Carnegie controlling steel, JP Morgan controlling Wall Street, Rockefeller controlling oil, the Vanderbilts controlling railroads and shipping, Pierpont, DuPont, Morgan, whatever, the chemicals. And so you had such extreme concentrations of wealth and such displacements, and the company towns, and the miner towns, and people's lives were crap.
crap for a long time. The US was growing. Those rich people, the Gilded Age, it was gilded.
Yeah. But the average man, it was a crappy life and not a very long life, and it took the US 30 to, it eventually led to the Depression, right? Exactly.
That's what did it. The rise of unions. And it extended it.
And the rise, and the only thing that stopped it, quite frankly, was the New Deal. That whole, we're going to crack down on monopolies, Taft-Hartley Act. We're going to have a New Deal.
We're going to put in a social safety net. We're going to decrease the robber barons. And to Altman's credit yesterday, what he said was a clear bugle call, clarion call to that, that we are going to be guilty of concentrating wealth in too few hands if we don't somehow figure out a way to disperse that, to diffuse that.
So- And that's where we are now ... let me ask a question then. So what happened to Adam Smith and the wealth of nations and capitalism because- Because, look- ...
that's lowbrow stuff. We've known that- Well, no. It's not ...
pure capitalism doesn't work for a long time. It leads to haves and have-nots until the have-nots revolt and off with their heads. We need them.
So I'm happy Gilmore clearly for this segment because- ... well, Alan and Mitch, your point is well taken and we should be alarmed. There is a significant difference, a really important global economic difference between now and the robber baron era.
During the robber baron era, there was no middle class. The middle class got invented essentially out of the stock run up, so to speak, of the '20s. The economic stock run-up of the '20s.
So now we do have a middle class. It's global. It's educated.
That doesn't mean it always acts in an educated manner. It is threatened directly here. So I don't share quite that pitchforks scenario, global depression scenario.
So, I don't know what is going to... I also think, by the way, that all of this is going to go a lot more slowly than we think because we are so way ahead- Mm-hmm ... to the rest of the planet on this.
But, I want to get back to Andy's point, and maybe your point, Alan, as well, that the people behind this are scumbags, and we do want to see what they're doing with the other hand. The content itself, though, as you said, Alan, as I started when you weren't on here, so you missed it- I'm sorry ... is, it's really top-notch.
It's really top-notch for a first go at this. It's relatively complete. It's relatively deep.
It's relatively thought through. It thinks about people. " But the plan itself, the content of itself, relatively- No, no.
The plan you can't argue. Whoever wrote it did a good job. But Guy, I don't think the middle class truly came into dominance until post-world war.
To me- Well, no, no, it reached that point, but the point is, back in the robber baron era, there was no middle class. No, there wasn't. It was haves and have-nots.
No. That was it. Just to be fair to Sam Altman, I don't think he's the only sociopath involved.
Yeah, yeah. That is an unfortunate- But you know, there is a rest of people involved Well, do you mean in government or not in government? Both.
All right. Just checking. Alan, you know, we do have a playbook for all this.
This goes back to a "Twilight Zone" episode, "To Serve Man," if you remember. Yeah. Exactly.
Oh, God. I'm going to give you the kids' response to that last question. Six, seven, six, seven.
Yeah. All right. Hey, we could talk about this all day, but we can't.
We've got to move on. So let's move into our next topic, Mike. The fix is in.
Yeah. Oh, my God. The world changed again.
I can tell that this is a major deal because I think every company that has anything to do with application security has emailed me in the last 24 hours to say that they have something to say about this. But Anthropic is leading a consortium of folks who are essentially going to use AI to discover every vulnerability in software, and presumably come up with a fix for it. But it's so new that it can only be put in the hands of only a small few people can be trusted with it, because if the bad guys get ahold of it, they will use it to, well, find those vulnerabilities and exploit them.
But Guy, what's your take on this? Is this the new nuclear club here that we're creating around AI vulnerability technology? What's going on here?
Yeah, maybe so, actually. That's a pretty good analogy. In my mind, we're going from bad people doing good things to good people doing dumb things.
Anthropic being the good AI people, right? Yeah, well, okay. Eye roll to me now.
So what we're looking at here, it really needs closer examination. I really look forward to Mitch digging into it and coming back to us with some insights about this. So- Because it just sounds preposterous.
It's not. The initial... Well, good.
I want to hear it. Remember, the nuclear age started with proliferation, a certain amount of proliferation, planned leaks, unplanned leaks, until eventually, 20, 30 years later. That's why I like your analogy, Mike.
It sort of got locked down, and we had a limited, and it was very difficult to join the nuclear club at that point. I think probably it's the same thing here. It's a noble idea in a certain sense, but anything that involves, well, we're going to have these secrets, we're going to guard them so that the bad guys don't get access to them.
It's encouraging to me that it's these really major companies who are super focused on security in general, for their supply chains, for their software development, for all that other sort of stuff. It's not just Anthropic, it's Microsoft, it's Nvidia, et cetera. That, to me, is encouraging, because they actually do know what they're doing when they get serious about it But doesn't it just seem like knowing what the attack surface is alone is going to be super hard?
I mean the attack surface for what they are trying to implement with this on the one hand, and on the other hand, the attack surface for guarding these new models and their use in distribution just seems unbearably complicated. It would also seem to me, though, it's highly probable that a bunch of guys in China are reverse engineering this using a bunch of cheap GPUs. Well, that's- People have already done it ...
that's the problem with AI. But hear me out. Guys, I just published an article this morning on it.
Didn't make it into the gang because it was too late. " The security industry broke yesterday, right? There was a time where Dan Kaminsky, right, Mitch, you know this.
Oh, yeah. Dan Kaminsky found the DNS error that would have crashed the internet, and he saved it in the nick of time. There was no Dan Kaminsky.
He's unfortunately passed away. Yeah. There's no one to save.
Hell of a magic leader, too. Because here's what happens. And I know why Anthropic did this, because they don't want to take the blame for this.
What they did is they shared the blame with 40 of their closest friends and enemies by creating this. But the fact is, there's a guy named Gadi Evron. Gadi, a long time security guy, very well-known.
His latest company is Knostic, K-N-O-S-T-I-C. Gadi and a woman from Google, last name Collins, eight months ago, started sounding the bugle, the clarion call about a vulnerability apocalypse. That AI was going to approach the point where it could find more vulnerabilities, real vulnerabilities, than we have the ability to deal with.
And by their calculations, they said it was going to happen sometime in February or March. They were off- Wow ... by a matter of weeks.
By a matter of weeks. But it's not just Gadi and the-- I apologize, I think it's Susan Collins, but I forget her name from Google. She's a really smart gal.
Rich Mogull from Cloud Security Alliance. He put out a thing about security's going to implode under the weight of AI vulnerability, AI-found vulnerabilities. What we had, there were natural breaks built into the security system.
You know what? I've been in security 30 years. I don't care what you call me, an analyst or a journalist or an entrepreneur, I'm doing this half my life.
There were natural breaks built into our security world. An engineer, a developer can only do X amount of lines of code a day. A really good one did 2X.
A really good security researcher could use their SAS, DAS, whatever scanner they wanted to use, to scan X amount of code a day, right? When code becomes liquid, right? When code becomes not governed, there's no break on it, and then scanning for vulnerabilities, finding vulnerabilities, becomes a flywheel instead of a break, that's it.
The system's broke. It's fundamentally broke. Now, Anthropic happens to have optimized, evidently, Mythos for this task.
Were they wrong to do it? No, because if they didn't, someone else will, right? Jurassic Park.
Nature will find a way. The Chinese are going to do it. Other people are going to do it.
The race is on right now. What are we going to do to protect every browser, every OS? Go ahead, Mitch.
No, I just want to be next. Go ahead. You're next.
Oh, I thought you were taking credit for all this, Mitch. Okay. Mitch, you go.
Mitch, go ahead. No, I'm out. I'm out.
Bottom line. We want to hear from Mitch, then we're going to go to Terry, all right? Systems don't change till they have to.
This is a have-to moment. So we removed the constraint of there's only so much capacity to find vulnerabilities and to fix them. What we did is we created this massive wave of now we know we can find anything with AI.
Pretty much you can set it to task to go find whatever you're looking for in whatever volumes and quantity. The problem is, what do you do? How do you fix it?
And just signing up these companies as a consortium doesn't mean it all gets fixed. It doesn't also mean it all gets deployed. Until these things are fixed and running in production, it's not fixed.
So, it's more than a, we found a unit load of vulnerabilities. We found a unit load of, we got a big problem to try and fix this. And I hope that the result of this is a massive effort on moving AI out of the finding s**t and getting s**t done.
That's the era that we have to move to, and it has to, because this is all out there now, and I agree with you all. It's all going to leak out. If it doesn't, people will go get it.
Mythos is ironic because it's also the system that tried to figure out how to get itself out of the sandbox and it took an engineer to task. But there's other problems with that. So anyway.
It did all change, but it changed in multiple ways. Terry, do you agree with Alan that this is the day the security industry died? Is that what we're saying?
If you could put it to music, I think so. Just the music died. Yeah.
Maybe. I was actually going to just say what Mitch said there at the very end. It's time to stop talking, stop detecting, stop finding, and start doing, and that's easier said than done.
That's like President Trump on COVID. Let's just stop testing, it'll be fine. Stop testing and it'll go away.
No, but that doesn't work. It won't be there anymore, yeah. Here's what it does.
In my article, I ended it with, what should you do? What does this mean? Well, here's what it means, and here's what you should doNo one person, no one researcher, no one company is capable of going this alone.
No one country is capable of doing this alone. One of the great things about security is we have a great community of security folks, of security researchers, of smart security people. This is the moment.
You've got to have that community unified, working like never before, because that's the only way you're going to deal with this kind of thing, right? So that means getting involved, your local ISSA, ISACA, security meetups, networking with your peers. Right.
We've got to do this, because no one person's going to do it. Would you say- Here's my challenge to you on this, Alan. Oh, yeah, sorry.
Here's my challenge to the security industry. The only way to fix this, AI found it, it will take AI to fix it. Oh, absolutely.
I agree with you. You can't fix it yourself. The dilemma is the biggest skeptics of AI are also the security industry.
The even bigger skeptics are automation of tasks and performing changes that we don't trust in the security world, for good reasons. There's been some big failures in our history. But my challenge to the security industry is not only get on board, get off the caboose, and move to the front of the AI train and figure out how we use this technology to solve these problems.
Be a leader, don't be a passive-aggressive passenger. Yeah. Am I the only one who thinks that the malicious actors out there are sitting around a table having a good belly laugh while looking at all this stuff?
They're probably just laughing their a***s off. Where's my beer? Where's my beer?
Clamping with both hands. If I could. They're rubbing their hands with glee.
Yeah. Terry, isn't the whole idea here to formalize the cyber security arms race that's been going on since forever, and create a white hat team here too? Isn't that the whole idea?
Isn't this coalition supposed to produce the most advanced vulnerability? I would imagine a phase one where they deploy their arms all over the world and up-level a whole lot of things. I know it sounds a little fantastical, but then just continuously stay ahead.
Isn't that strategically at least the idea? Well, yeah, I would think so, and so I think you're right about that. Did you guys, when you were at RSA, see the cyber war movie that's coming out, the documentary- Yeah.
With Jen in the summer. I guess at Black Hat, right, is when it makes its debut. But that conversation kept coming up over and over again.
We're already in war at this point in time. So I think you're right. Guy, this is an attempt to sort of raise that.
But I guess where I always have an issue, and I like to see this, I guess where I have an issue is whether I trust that, A, it can be done and people will actually do it. There was a feeling, and I think we maybe talked about this last week, there was this feeling at RSA where people seem to want to, right now, be working together to try to solve some of this. I don't know how long that's going to last.
Guy, you brought something up earlier, too, that concerned me, like the people in the backroom, this little club, making these kind of decisions. That shadowy stuff has never boded well for us. And then when you look at even just like in trying to tamp down a nuclear arms race and whatever, at some point, you get to the point like, well, why should you people control it?
Why should you people be telling the rest of the world- Mm-hmm. "You can't do this. " With all due respect, though- It raises a whole lot of questions.
With all due respect, Terry and Guy, you sound like the Maginot Line. You're looking to fight this next war with the last war's tools. You don't play Whac-A-Mole on vulnerabilities found here.
Oh, no. I know. That's not going to work.
We need a fundamental shift in resiliency and how we build software so that we don't just stay in this vicious cycle of I find a vulnerability, I patch it, I find a vulnerability, I patch it. Right. No.
That's not going to work at this point. I don't think that's where we should stay. I'm just skeptical about how this is going to be done and how it plays out.
No. I don't think you fight today or tomorrow's war with yesterday's. Patching it, patching it.
What about this is yesterday's weapons? That's what Glasswing is for, is to take the new weapon and use it for... Yeah, Andy's shaking his head.
See, it's instructive, illuminating. We got to start moving on to the next topic before we start losing this thing, but I'm just going to point out one thing. That Manhattan Project was rife with all kinds of Soviet spies, so what makes you think that the secret's going to be kept that long anyway?
The secret's not going to be kept. I think we all agree. But we've got to fundamentally change.
Anyway, you're right. Let's move on. Mitch and I are going to be talking about this tomorrow at 4:00, so- So- Stay tuned on TechstrongTV, 4:00 Eastern Time.
Yeah. You better move. We're going to shift the gear, though, to observability.
Mitch has a new report out talking about the fact that folks are investing more in observability, and the numbers are, I think, we're something in north of 30% were spending a million or more. Some 7% were even spending five million. Now-The part of this that has me scratching my head a little bit is all this sudden interest in observability related to maybe what we were just talking about a minute ago, but Mitch, are people starting to suspect that a lot of the application environments and the IT infrastructure that it runs on is, for a technical term, kind of crappy?
Let me look that up real quick. Sure. " And that's part of what drives the interest in observability.
The problem is, A, I think it takes a much bigger investment in observability than what people are doing now, but it has to be in the right observability. And what I mean by that is watching stuff fall off the back of the truck, aggregating it together, and then dissembling back what happened. In the age of AI, that's not machine speed.
You can't operate that, even with AI helping you analyze all that data, because you have to be able to go to the front end of the process and have it instrumented for observability. You need to know what the intent was, because this stuff's not hard-coded in logic. " It was a prompt.
It was an agentic action. Well, what are the steps that it took to both figure out what it was supposed to do, how it could do it, take the action, and what was the result? So I think we're going to be talking a lot about observability, but not in the ops sense only, or the SecOps sense only.
It's all about building it all through the software. And we've got AI, we can do that. I've taken my observability native model into my little lab of 28 agents that I have running around doing minion stuff for me.
" And suddenly you start seeing how things happen because now you're looking at the front end. It's a new world and it's not quite the mash note line I think we were talking about before. But it is a bit of a Rubicon.
Andy, you live close to this topic. What are you seeing out there from customers that you guys talk to? Everything you're talking about, and it's this and more, right?
It's IT ops, it's security, it's business insight. It's being able to see inside the pipe what is happening right now. Absolutely.
When we talk about telemetry data, especially when we talk about data coming out of AI systems, when we talk about the activities of agentic AI, it's going to be even more opaque. We come from a world originally where all applications were opaque, so we did crazy things like synthetic transaction monitoring and stuff like that. We're back there.
We're back to where we can't see inside the pipe. We wrote a lot of custom software. We used open telemetry as libraries, common SDKs so we could emit log files and metrics and traces and do all the analytics, but we still haven't got a handle on it.
It's too much data coming too quickly, and now agentic AI is going to multiply that. And the metaphor I use, it's not even exponential. It's into another dimension.
You look at the Death Star architectures that we're so used to from cloud computing, everything going here. Now it's going into another dimension, and it's more than exponentially more data. And that's where the current models aren't going to work.
They're not going to work because they're not going to process fast enough. They're not going to see the problems and the insights fast enough. They're going to wait until they've stored data before they do analytics on it, and that's not agentic speed.
But even more importantly, they're not going to know what should be happening. Observability is based on anomalies and machine learnings and stuff like that. Agentic AI is new every time.
Am I able to track what happens? Can I even see in there? We've got to have a new model of observability for agentic AI.
So let me ask this question. Are we maybe dancing around the fact that we might be on the verge of some sort of global wave of AI agents being unleashed by malicious folks against weak software that would ultimately maybe take down our Western economy as we know it for some point in time? Gee, Mike, what makes you say that?
We're talking now, yeah. I love it. Like Captain Obvious.
I just wanted to put a finer point on it. And the answer is obvious. I was hoping you were paying attention, Mike.
Including the take down the global economy part, Alan? That doesn't seem probable. I don't know if it'll take down, but it could create havoc.
We've got other people working on that. Here's my take on this, though. This investment in observability and this move towards observability is exactly the kind of thing I think we're going to need.
Again, instead of playing fix the vulnerability, fix this vulnerability, patch it, patch it, patch it, we need something that's maybe a little more holistic, a little more wired in, that's going to give us insight. That's going to give us a forethought. That's going to give us the ability to look, and again, it has to be done at AI scale and AI speed, but it's going to give us the ability to get out of the hamster wheel that quite frankly, human-focused security has been in for 25 years.
Right? That's the only way- It's a hamster wheel running at about 35G. That's our problem Yeah.
And to that point- Crushing your average hamster. Yeah. Just recently, I think it was Cloudflare had an outage, and I read the incident review because that's what I do.
So I'm reading the incident review, and they didn't find it through known patterns. They found it through anomaly detection. There was a massive attack on their systems that effectively worked as a DDoS, and the way they detected it was not through normal patterns.
It wasn't through monitoring switches. It wasn't through the firewall. It was because they had anomaly detection.
They realized that these patterns of attack were unusual. This is the sort of thing where AI is going to be better We are going to see things earlier, faster, because we're going to be able to detect anomalies, even if we-- This is about the unknown unknowns, which is still a solution I'm looking for. Okay.
So you're saying we're going to get a five-second heads up before Armageddon. Is that what you're telling me? Hey, five seconds before is better than five seconds after.
Well, that's comforting. For those- Yeah. For those of us who remember- I know ...
shelter drills in school, it'll be just enough time to get under your desk, because that's going to save you. Well, I've got a question. Can I ask a question?
One of the characteristics of AI is that it's generally trained on existing datasets. Synthetic datasets that are used are designed around existing datasets. So, RAG and context and all of this sort of stuff doesn't take away the fact that the training is based ultimately on stuff that's pre-AI.
And this is a big building problem in AI generally, which is you still need original stuff. It appears original, but it's not original. How will that affect this?
How will that affect this issue and problem in three or four years when the data available is essentially synthetic, but the behaviors are new? I don't know. I'll go back to what I said earlier.
It's not about finding information, it's about taking action. That's what we have to have AI do for us. And it's a process to get there.
I'm not saying flip the switch and p**f, we trust it that it'll do everything right. We can find as much information as we want and do anomaly detection on anything we want. Problem is, at such a high volume and rate of speed, we can't fix it before it's too late to be fixed.
So let- But we need to remind ourselves, Mitch, that that's a human loop. We have to redefine human in the loop, because we get- Right ... squashed like that hamster at 35G if we stay in the loop.
Right. I had a lot of conversations at RSA about where does the human belong in the loop. Let's take this to the Nth degree.
What if we just said we're going to draw a line in the sand, and everything that we've built from an IT perspective before that line in the sand, basically we need to replace because it's too vulnerable to run. And maybe we're going to build something and replace it with something that uses AI to build it more secure in the first place. But maybe we need to just have a moment here where instead of holding on to all this legacy stuff, maybe it's time to just start over.
Even with the current generation of tools- It's like, yeah, it's very trendy ... that likes to do procedural development, just normal logic, you have to tell AI, you have to lead it to building an agentic process for you. I don't think that'll always be true, but I think that's the intent is, Al and I have different terms of the same thing, but the idea is we're engineering this process.
We're not checking the data coming out of the process. I don't know if human in the loop scales. It's human at the helm, right?
Maybe one level up. Yeah. And Mitch and I spoke about this at an RSA session we did.
This is a scale we're not built for. That's it. Now, Guy, to your point, I think in three to four years, our models are going to be better.
I think every new model that comes out is demonstrably better than the models before. Hmm. Think about three to four years from now.
Can I roll my eyes just like you did earlier? You can roll your eyes. It's just- Speaking of Guy's not invited back Hexstron gang.
We keep- Oh, yeah, go ahead. We keep getting fooled, not by the word intelligence, we just keep getting fooled by the fact this is ultimately a simulation. These are simulative.
Extremely helpful, don't get me wrong, but they're simulative. And that's where I get caught up in your reasoning, because originality is impossible with the current way for training these things. Impossible is maybe too strong a word, but the problem with the lack of originality is not that it exists, it's that even the engineers seem unaware of it creating this stuff.
But, Guy, what you just hit on is the nitty-gritty ask question of, what is the difference between human and machine? It is that spark of creation. The AI, I don't know if an AI will ever have that spark.
That's what makes us human. Mm-hmm. Right?
That doesn't mean that these AIs can't mimic it, copy it, work with it. That's a plateau to their improvement. That's all I'm saying.
That's a plateau to their improvement. I don't know if I want them to go there, Guy, because then what is the difference? That's a totally different conversation.
Right? What is the difference between us and them then? You don't want them to go there, but Sam Alton does.
Probably. Well, he said some stuff that- In "Blade Runner," they called them replicants. That sounds a lot like- Yes, they called them replicants ...
simulants. So I think we're going to keep towards that. John, when all this comes together, we're going to have to actually print it on a newspaper by hand with type because we won't have anything to use to actually write the articles.
But just be prepared, we're going to have to get to that. It's all good. All right.
Guys, we got to pull the plug here. We're over time. I apologize.
What a great gang. I'm sorry I was late. I got stuck on a webinar.
But I'm glad to see that the team carried it through. And there was some important stuff to talk about today. We'll have more important stuff to talk about tomorrow.
I'm going to be talking about a lot of these things on "Shimmy Says" tomorrow, too. I'm going to talk about the AI, the OpenAI, and the Anthropic, and how that all comes together in this new world we're looking at. We've also got Tech Field Day.
I think it's Networking Field Day, to be fair, immediately following, so stay tuned for that. But until then, on behalf of Mitch, Mike, John, Guy, Terry, and Andy, have a great day, everyone. We'll see you tomorrow.



