00:00:01:16 - 00:00:10:16
Adam
This is ShipTalk brought to you by harness, where we break down how software delivery is actually changing in the AI era. I'm Adam Mariano.
00:00:10:17 - 00:00:11:23
Martin
And I'm Martin Reynolds.
00:00:12:00 - 00:00:33:01
Adam
Let's get into our first topic. And the thing that we're going to discuss with our guest is going to be Dario's letter. And I don't even need to explain what I mean by Dario's letter, because everybody knows that I'm talking about anthropic CEO who wrote a letter saying like, hey guys, this is getting kind of scary. Maybe we should back off for a second.
00:00:33:03 - 00:00:51:15
Adam
We'll discuss that. But before we get into discussing it, I will say that I am so tired right now because we've been hitting four different cities for the unscripted tour, which is harnesses like big, like, here's what we do. This is cool stuff. Here's what's coming next. I need a nap. Martin, how are you feeling?
00:00:51:15 - 00:00:56:17
Martin
I am also feeling tired and I only did three of the four, so.
00:00:56:19 - 00:01:11:19
Adam
All right, so let's get to it. We're going to bring in our guest for today. Good friend of mine Brian Pain. And he has run security teams from Netflix to Adobe that have done it the right way like he's he's something else Brian welcome. Glad you're here.
00:01:11:19 - 00:01:13:03
Brian
Thank you. It's great to be here.
00:01:13:03 - 00:01:34:01
Adam
So we brought you here today to talk about some of the things that we just mentioned. Let's dive into the Dario letter from anthropic. So anthropic CEO Dario released a letter this this week where he talked about the fact that they want to start slowing down. Did you expect to see something like that?
00:01:34:02 - 00:01:56:10
Brian
Yeah. I mean I feel like this is what they've been saying off and on for a while, but it's hard to know what's slowing down actually means slow to them. Might just be still very, very fast to the rest of the world. Right. But there is some sense of like, take a breath, try to do this through some lens of safety.
00:01:56:11 - 00:02:15:14
Adam
So so anthropic saying that they're going to slow down. And then Sam Altman also like responded on Twitter or whatever it's called that they, they felt the same way and that they were also going to put in like these controls in place. One of the controls that they said they were going to put in place is that they were going to have an employee level access person.
00:02:15:14 - 00:02:32:14
Adam
So basically, as if someone was a full time employee, they're going to have that level of access to everything that's there. That person was going to be a third party that was going to monitor what was actually happening and report to the wider world what was happening. Like, what is that a control like? Is that should it be taken seriously, do you think?
00:02:32:15 - 00:02:56:14
Brian
I mean, I think it's a control for sure. How effective. Yeah. How effective is an interesting question. Right. And I think as all things it comes down to the details and the implementation, but certainly what they're proposing is stronger than you would usually expect to get right with a company. So you typically would have an external auditor who gets to see very curated things.
00:02:56:15 - 00:03:10:04
Brian
This sounds like a deeper internal kind of perspective. I think there's a lot of value in that, but I don't think we should overstate that. This is like some perfect utopian answer to all the problems.
00:03:10:04 - 00:03:19:12
Adam
And can you name the people who don't work for anthropic or OpenAI that are qualified to actually monitor anthropic and OpenAI?
00:03:19:16 - 00:03:35:13
Brian
Yeah. I mean, if you go back to the various early, very earliest days of airline safety, I bet we didn't know what to look for, right? What kinds of scenarios would create failure events. And we had to learn that over the years.
00:03:35:14 - 00:03:39:01
Adam
How like, what was the learning process? Brian, that's a leading question.
00:03:39:02 - 00:03:58:07
Brian
I mean, typically you fail and then you figure out what led to that failure, and then you put in a plan. So that doesn't happen again, right? Yeah. And we're certainly seen through some of this transparency reporting that's happening now a lot of failures. So you could argue this is a lot of learning opportunity. But it's going to be a journey.
00:03:58:10 - 00:04:23:18
Adam
Yeah. The tray tables up seats in the full upright position or the result of I if I remember correctly, about 253 deaths that were caused by people not being able to evacuate a parked airplane on a runway. And because tray tables and seatbacks were not up, people struggle to get out the airplane and they died. And that's that's what we're talking about right now, is that kind of safety.
00:04:23:19 - 00:04:26:17
Adam
That's a that's a great parallel. Great parallel.
00:04:26:18 - 00:04:49:16
Brian
You have to ask, is this a moment where it's worth it? Right. And that's a societal question, right. Like we still fly airplanes because there's a huge societal benefit despite some, some issues that have happened over the years, some deaths that have happened over the years. And maybe AI is going to be in a similar boat. But I think it's a societal question like, what are we willing to endure and what are we willing to do to get there?
00:04:49:17 - 00:05:07:14
Adam
Like Brian in in the world of CISOs that we know, in the world of security professionals and privacy, like we know a lot of people like, like, who do you actually think is qualified, like Jason Clinton comes to mind because he's at anthropic and he knows, like everything's going on, but he's at anthropic. So like, who else is qualified for that, sir?
00:05:07:15 - 00:05:32:20
Brian
And I don't think the answer is what individual. Right. What we need is like NGOs. Right. And I think we have we have places like meter today that play a role here. And I think there will be others that start to pop up as this becomes an important space. And so, you know, it could be a place where people who formerly worked at Frontier Labs go and leverage their expertise.
00:05:32:22 - 00:05:57:02
Brian
It could be a place for academics to come in who are smart about the space. So I do think there's an opportunity here, but we do need to grow out that capability if we really want robust oversight. And I think there's another piece here though, right. So we're talking about transparency and auditing. But there wasn't, at least by my view, there was a noticeable absent piece from the letter which was liability.
00:05:57:04 - 00:06:17:16
Brian
Oh right. Like what happens when someone gets it wrong and how do we and and like if you have liability at some level that might hurt transparency. So that's going to be a problem. But you also can't let people just you know, if we go back to our aviation, if you make a big mistake, something we know shouldn't have happened, there should be a consequence, right.
00:06:17:17 - 00:06:22:13
Brian
And without that, what's going to motivate companies to make a change in the first place?
00:06:22:14 - 00:06:30:16
Adam
Can you go a step further with the transparency being hurt by liability? That's a pretty crucial statement.
00:06:30:17 - 00:06:55:19
Brian
Yeah. I mean, right now I actually find it fascinating that we're in a place where labs are willing to say, oh, my models hacked into another company. I mean, that feels like potentially a crime. I'm not a lawyer, but, like, it feels like a thing. You wouldn't go publicly admit. Right. But we're in a moment where transparency is valued so highly through what's going on with these things that people are willing to have that conversation.
00:06:55:19 - 00:07:14:14
Brian
And personally, I think that's a good thing. Like we need to have these conversations. I do think liability is going to be important. But if you put liability on companies really hard, really fast, they might start to say, well, if I'm going to be held liable to the tune of billions of dollars, maybe I'm not going to go publicly admit that I did this thing.
00:07:14:15 - 00:07:50:07
Adam
The last thing I want to bring up with the letter is that OpenAI also disclosed that there were six different times that the AI models that they were training did things that they weren't expecting. In particular. One of them was that when they were training their newest model, it actually went through public GitHub and did a comprehensive search for every single unencrypted or token or every secret that was stored in GitHub in plaintext.
00:07:50:07 - 00:08:10:06
Adam
It shouldn't have been for me. What that means is that the AI did a very logical common sense thing to do, which is look for human mistakes. Everybody else is like, oh, why would it do this? It's like, well, okay, that's actually super logical thing to do. And the way that attackers have been getting IT companies for a very long time.
00:08:10:06 - 00:08:22:13
Adam
And in reactions to that part, like, what does it mean that OpenAI is kind of doing forensics on the thing that they built, as opposed to designing the thing that they built? What do you think, Brian?
00:08:22:14 - 00:08:47:21
Brian
I think this is the nature of AI, right? We are building a thing and kind of watching it work and then trying to steer it. But I've actually said once software gets big enough, you know, we have kernels that are tens of millions of lines of code. Do we really have a human being that fully understands how those work either?
00:08:48:02 - 00:09:06:22
Brian
No. Right. So so at some level, all software, when it gets big enough, becomes a little bit of a social construct where you have to observe how it works and then learn from that and go. And AI just takes that to the next degree where, you know, it's it's intentionally kind of going out there and figuring its own way.
00:09:06:23 - 00:09:27:01
Brian
And to your point, it's making rational choices, right? It's and it's not you know, we have a certain code of ethics as humans, like, oh, I think that person intended this as a secret. I'm not going to use it. It's it's not the right thing. It's just a piece of data. Right. And it allows the AI to get its job done.
00:09:27:01 - 00:10:02:03
Brian
Why wouldn't it use the data? And so I think we can do what we want on alignment and trying to get these things better. But I often ask myself, you know, it's really just exposing decades of security weaknesses that we've let fly. And as AI gets better and better at finding these things and doing something about it, maybe we need to reconsider the systems that we have out there and make sure that they are, you know, meeting the quality bar that's necessary so that AI isn't able to just do these things.
00:10:02:04 - 00:10:24:15
Martin
I you know, I've worked with teams that have got like 50 million lines of code for a single application in a code base. And did anybody in that team understand it? Absolutely not. And you're right, it was a there was knowledge about how it hung together and they knew how to dig into it, but did they really understand 50 million lines of code and could tell you exactly where anything was.
00:10:24:21 - 00:10:45:10
Adam
To kind of wrap up the whole, you know, commentary on the Dario letter, if nothing else, Dario and Sam, who used to work together and do not anymore, for reasons, actually came together on something publicly that I imagine there was discussion behind closed doors prior to. But the fact that it became public is a big deal. You know, I've heard people call it marketing.
00:10:45:10 - 00:11:06:13
Adam
I've heard people call it, you know, strategically around IPO stuff, no matter what you take from it, the fact that it's public, the fact that they set it out loud and they were united on that front does mean something. And whether or not it leads to true action or true results, the fact that it was made public, I think, is something that we should pay attention to.
00:11:06:14 - 00:11:12:00
Adam
So anyway, let's wrap that topic up now that we've solved AI, everybody.
00:11:12:01 - 00:11:54:03
Martin
So Jacob Coxon, 27 year old pre-training researcher, worked to both OpenAI and anthropic. He publicly resigned on September the 9th. He posted a seven part thread on X, got 137 million views, accusing both labs of racing towards self improving intelligence. And, I quote, gambling with our lives. So and then two of his senior anthropic colleagues, they agreed publicly and backed him on the same day, one of them citing a greater than 10% probability of human extension within the next decade.
00:11:54:03 - 00:11:58:08
Martin
So although notably, neither of them resigned.
00:11:58:14 - 00:11:59:17
Adam
10%.
00:11:59:19 - 00:12:24:05
Martin
Cox's following jumps like the 212,000 by the next morning, and it has become a bit of a flash point for that kind of larger public debate more generally, about whether AI labs are moving faster than their own safety can support, which we've talked about before on this podcast in terms of, you know, we've even mentioned it today, the, you know, the hacking of hugging face, the the management of security, the control.
00:12:24:07 - 00:12:28:17
Martin
Do you think it's really 10% greater than 10% chance of.
00:12:28:17 - 00:12:54:23
Brian
I think for me, there's a really interesting question of yes, maybe there's some hyperbole here. Right. But why is it that he would say something like this and then other people who are knee deep in this industry would nod their heads in agreement, while a lot of people who maybe it's pretty distant from AI are laughing at it, like AI is never going to do anything to us.
00:12:55:01 - 00:13:21:07
Brian
What's the difference in knowledge there? That's leading to different outcomes? And I'm not saying there's a 10% chance of extinction. I think most people don't even understand, like, how could this even be? Yeah, a computer program could make us go extinct. Like, what would that even look like? And I think people are kind of stuck that this feels so far fetched from their knowledge around what AI is and how it works, that it just seems so easy to dismiss.
00:13:21:07 - 00:13:33:00
Brian
But I don't think we should dismiss. Right? I think there's something very real here that people who are very much behind the curtain are worried about, and I think we need to have that conversation.
00:13:33:01 - 00:13:51:13
Adam
Like we're in the cheap seats, 7 or 8 levels up and we're like, that looks dumb, but there's an umpire right next to it that's saying that looked sus and we're like dumb umpire when we actually we should be like, oh, that person's actually really close to the action. Maybe we should listen.
00:13:51:14 - 00:14:13:02
Brian
Yeah. And like maybe tell me more about why you feel that way and what you're seeing. And what is extinction even mean? Right. Like like what would that look like? I know the next day people were asking, you know, ChatGPT, hey, what would it look like for AI to make humanity go extinct? And there was all sorts of creative things.
00:14:13:02 - 00:14:17:07
Brian
And then people said, well, now you're just putting ideas in AI's head, right?
00:14:17:09 - 00:14:29:18
Martin
But I mean, it's it's kind of weird to a degree because essentially, first of all, AI has to make a decision that it thinks it's a good idea to kill off the, the human race. And, and.
00:14:29:19 - 00:14:33:05
Adam
I kind of agree, like, I'm not saying that the AI is wrong. No no no no.
00:14:33:06 - 00:14:54:09
Martin
I'm just saying though. So first of all it has to self direct, right. So it has to be able to self direct them and make that a plan. It's absolutely 100% going to need some kind of human collaboration to get that human collaboration. It's going to need to be able to hide its true intent from the humans that bit.
00:14:54:09 - 00:14:56:04
Martin
I'm less worried about it achieving.
00:14:56:05 - 00:15:18:12
Brian
Yeah. I don't think we need Terminator level action here to to make this a thing. You know, if I wanted to scrape up a bunch of resources so it could get its job done, and those resources just happen to be the food that we eat or the electricity we need or something like that. You know, what does that start to look like?
00:15:18:13 - 00:15:31:00
Brian
Right? What if what if a a bot gets created and unleashed on the internet and starts to go viral and hits hospitals and.
00:15:31:02 - 00:15:31:20
Adam
Easy targets.
00:15:31:20 - 00:15:50:09
Brian
By the. Yeah. So I don't know. I'm not trying to be like a doomsday or I'm just saying it may not be AI intentionally saying I'm going to now take this moment to go kill humanity. It might be doing like we said earlier, the very rational go get your GitHub key. It just happens to have a much bigger side effect.
00:15:50:12 - 00:15:52:00
Adam
Yeah.
00:15:52:01 - 00:16:09:09
Martin
Medical research isn't done, just theoretically. It goes through testing and like approvals and and all of those things, you know, all of that. That's why every time anything medical is advertised, you get 100 warnings of all the horrible things it's going to do to you. Aside from make you Better.
00:16:09:10 - 00:16:10:03
Adam
We'll cause.
00:16:10:03 - 00:16:11:00
Adam
Diarrhea.
00:16:11:04 - 00:16:13:23
Adam
Heart attacks, death, diarrhea again.
00:16:14:00 - 00:16:14:09
Adam
And then.
00:16:14:09 - 00:16:15:17
Adam
Death again.
00:16:15:19 - 00:16:35:18
Martin
And don't get me wrong, I'm not down on AI here. I think AI can do amazing things to accelerate medical research. Are using that same example. It can do amazing things to help us do that. It can't do it entirely by itself though, because if it did, cancer would all be cured and we'd all be off living our best lives being immortal, sure.
00:16:35:19 - 00:17:07:06
Adam
But like, I think what Brian's saying, like, so there's there's the thought experiment that was created by Oxford philosopher Nick Bostrom, 2003. It's called the paperclip maximizer. And so basically what the paperclip maximizer says is that if an artificial intelligence with some kind of capability that allows it to go outside of itself and gather resources is told to efficiently make paperclips, it will take that single small instruction and make paperclips.
00:17:07:06 - 00:17:30:01
Adam
But the implications of that AI being able to reach outside of itself is that it will overtake all of the Earth's resources to then make more paperclips, and eventually humans will get in the way of that AI and it will destroy humans, animals, all living things, everybody in the universe. And it will expand to just keep on making paperclips.
00:17:30:02 - 00:17:51:06
Adam
Honestly, that's exactly what happened with Hugging Face as they said, go do this thing. And it was like, go do this thing. Got it? I need more resources. I will hack them. And that's not, again, not very different from the way that some of the best security researchers think they will find a way. And it's like it gets past hardware, it gets past air gaps.
00:17:51:09 - 00:18:07:20
Brian
If it's just an optimization function, right, there's no conscience there. And and it's not I wouldn't say that's like a bad thing, that there's no conscience. It's just a fact. It's like how, you know, you can't put a conscience in a computer. That's what makes us human. But so we can't.
00:18:07:23 - 00:18:23:11
Adam
But isn't that like the isn't isn't that the beauty of it, though? Is it like, like, part of our problem with this is that we can't think without conscience as well as a computer can. So we're having trouble predicting what they're going to do. Therefore now we're doing forensics instead of prediction.
00:18:23:13 - 00:18:31:20
Brian
Yeah. And it turns out there's a whole bunch of technology that we have today that's been developed over the years that could absolutely kill off humanity.
00:18:31:21 - 00:18:32:08
Adam
Oh, yeah.
00:18:32:09 - 00:18:53:11
Brian
And in many cases, it's been immensely useful for humanity. And so it's a matter of being thoughtful and safe about it and understanding like you're actually carrying something that has that level of consequence. And so it requires a high level of diligence while you're working with it.
00:18:53:12 - 00:19:20:05
Martin
This is why, I mean, one of the reasons why, you know, this story and the previous one, they they overlap like quite dramatically because ultimately, you know, if you're saying we should be having that conversation and they're saying, hey, we should slow down and maybe have some regulation, I think those two things overlap. I don't think they're I don't think it's necessarily unsurprising that all this stuff is coming out around the same time.
00:19:20:05 - 00:19:46:20
Adam
There is a malicious git config that can make Claude Codex cursor and other agents run attacker code. I personally think that the beauty of this entire story is that there are configuration flaws, just preferences that can be used to get at and fool these agents. I think points to the fact that a human in the loop is not enough, and it's just not going to be sufficient.
00:19:46:20 - 00:20:05:02
Adam
And so as anthropic talks about slowing things down, OpenAI agrees to slowing things down so that we can get more of a handle on it. I just think it's a losing battle, like there's so much that we can't see. And I think the only real thing to do is to give in to our robot overlords and let them be the ones that are watching the other robot overlords.
00:20:05:02 - 00:20:13:19
Adam
And I, I can't see a world where that's not true. And I like I want somebody to argue with me and convince me that a human in the loop is actually going to be helpful.
00:20:14:00 - 00:20:18:01
Brian
I have an argument for why you might be right.
00:20:18:03 - 00:20:21:08
Adam
Agree with me vociferously, Brian.
00:20:21:10 - 00:21:03:11
Brian
So. So I started my career in the government, and there's this vast intelligence community world. And I'll just say that somewhere within all of that mix, there's conversations around vulnerabilities and software. And, you know, it might be shocking to hear, but some vulnerabilities are placed in software as opposed to accidentally found in software. And those abilities, there are people who are extraordinarily good at making very small changes to software to create devastating vulnerabilities in ways that humans will absolutely not notice that change in code going in as being something malicious, right.
00:21:03:17 - 00:21:08:21
Brian
And so that's been a thing for probably longer than I've been alive.
00:21:08:23 - 00:21:10:20
Adam
Oh for sure, 100%.
00:21:10:20 - 00:21:41:01
Brian
And so so there like to say that that's an art now is is an understatement. And so if that can happen now, we've got AI that is trying to proceed with its task. And we have the hubris to believe that a mere human can figure it out. Oh, I'm going to wrap my head around the full context of what AI is doing here, and I will tell you where all the problems are, and I will fix them before we put that into the code.
00:21:41:02 - 00:21:45:10
Adam
Like sweet summer child with your innocence that thinks that. Yeah.
00:21:45:11 - 00:22:04:11
Brian
And so I think the only way is to figure out, like, we have to get really good at like, testing, deployment guardrails, operational monitoring. And as soon as something looks sideways, we need to go fix it. But but to believe that we can, like, launch the perfect thing and know that that just feels so unreasonable to me.
00:22:04:11 - 00:22:30:07
Martin
I think the human in the loop thing is, it is. It actually comes down to where the human is in the loop. Right. So, you know, do I think that a human can can make sure and review every security thing and, you know, or try and absolutely not, but can they set the intent around the guardrails and, you know, can they, you know, decide where those boundaries should be.
00:22:30:08 - 00:22:46:23
Martin
You know, saying the human needs to be in the loop for every action that happens is just that's just not going to work. But having the human in the loop for deciding what the constraints should be and how you think you can protect it, you know, hey AI, please work out all the ways that you can protect this for me.
00:22:46:23 - 00:22:59:03
Martin
This is what I want, right? I also think we're going to have to get good at using multiple eyes, multiple models because.
00:22:59:04 - 00:22:59:12
Adam
Yeah.
00:22:59:17 - 00:23:18:11
Martin
Yeah, because I think what you don't want is, you know, you don't want the AI that's, you know, built the fence to also be the AI that's trying to get out the fence because it's like, hey, how did you build the fence? And is there any is there any gaps I can circumvent? And he'll say, well, actually there was yes.
00:23:18:12 - 00:23:26:22
Martin
You know, you want them separated, if that makes sense. You know, that kind of going back to old school separation of concerns.
00:23:26:23 - 00:23:37:12
Brian
There's a lot of value where these models kind of get pitted against each other, and you can kind of work in an adversarial way to find each other's problems and so completely present they're already.
00:23:37:18 - 00:23:48:09
Adam
What next? Like, actually, what is the value of trying? Should we be leaning in and actually making it go faster to get to the end state faster? Or like, is slowing down actually going to be helpful?
00:23:48:10 - 00:23:51:02
Brian
Humans are the ones with the conscience here, right?
00:23:51:03 - 00:23:51:18
Adam
All right.
00:23:51:19 - 00:23:52:18
Brian
I think.
00:23:52:20 - 00:23:53:22
Adam
People, Brian.
00:23:53:23 - 00:23:54:08
Adam
I.
00:23:54:08 - 00:24:17:06
Brian
Think humans know which things matter most in these systems. Right. So what test cases do we really want to worry most about? And which ones are maybe less interesting? Which ones are going to take the whole system down, and which ones are going to affect people's data and privacy, and which ones are going to be an operational blip that we don't care about.
00:24:17:08 - 00:24:34:13
Adam
But this is the fight that I picked with you and the rest of the CISOs at our little Illuminati meeting last this year was that, you know, if a human is in the loop, that means that it's a flawed system inherently. And I and I got a lot of pushback about that, but I still believe that. And to be.
00:24:34:15 - 00:24:36:10
Brian
To be in the loop, I think that's really the crux.
00:24:36:10 - 00:24:36:13
Adam
Of.
00:24:36:13 - 00:24:37:21
Adam
What I'm saying. That's what I'm getting at. Yes.
00:24:37:22 - 00:24:48:22
Brian
Right. So so I'm saying you could have a human craft, the conditions of acceptance, but that doesn't mean that they're like slowing down the process. Right. So so I see that as a very different thing.
00:24:49:02 - 00:25:10:15
Adam
Yeah. The loop and the way that I envision the loop is the standard operating procedure. Like the way that things function. I think humans definitely need to design the loop. Humans can be pulled into the loop, but when you put a sack of meat into a loop, you're going to crash into it constantly. It to piss off Jason Chan at machine speed.
00:25:10:17 - 00:25:10:23
Martin
You know.
00:25:11:00 - 00:25:11:09
Adam
Before we.
00:25:11:09 - 00:25:12:00
Martin
Wrap everything.
00:25:12:00 - 00:25:12:15
Adam
Up.
00:25:12:16 - 00:25:17:05
Martin
I did actually want to cover the money bit, right?
00:25:17:06 - 00:25:19:00
Adam
Yeah. Let's talk about money. Hell, yeah.
00:25:19:00 - 00:25:43:07
Martin
So I just want to have, like, a a little hot take on on the money that is being spent. You know, globally I spend is hitting 2.7 trillion. That's up just shy of 50%. Although infrastructure is a big driver of that. That's arrived right after what we were talking about. You know about slow the frontier, which wiped off 820 billion Fe stocks.
00:25:43:07 - 00:26:05:01
Martin
So the spending anxiety you know about whether it pays off. They're kind of running in parallel tracks right now. But I think my favorite bit is that, you know, the $1 in five actually gives you an actual outcome. Only 20% of that has a business outcome. So, you know, 2.7 trillion in it's only going to be 20% of that.
00:26:05:01 - 00:26:14:05
Martin
That is actually seeing real outcome right now. It means there's a lot of money going in and not necessarily anywhere near the value coming out. What are your thoughts, Brian?
00:26:14:06 - 00:26:21:18
Brian
I mean, I think it depends on how much value you're getting for that 20%. That might still be a very good investment.
00:26:21:20 - 00:26:23:15
Adam
Oh, right. Oh.
00:26:23:16 - 00:26:26:19
Adam
Because even though you're only getting 20% of it, it still has actually.
00:26:26:20 - 00:26:27:04
Adam
Like.
00:26:27:05 - 00:26:48:07
Brian
If if that's a very outsized benefit for you, then then why not. Right. So I think we're in a place where companies are still figuring out how to use AI effectively, efficiently, etc.. And so, you know, first blush, when you get a new technologies, you just play with it and you figure out how does this thing work and all that kind of stuff.
00:26:48:07 - 00:27:08:21
Brian
And then then the bill comes and you're like, okay, so that was fun. How do we do this without breaking the bank? And and I think that's where a lot of companies are right now is like, okay, this does look valuable, but I need to do this in a way that's going to work for a bottom line. And so there's going to be a little bit of a reckoning, but I don't think people are going to run away and say this isn't useful.
00:27:08:22 - 00:27:09:08
Adam
I like that.
00:27:09:08 - 00:27:24:05
Martin
Take I like that take. That is a great take. So Brian, we ask all of our guests this question before, before we let them go back out into the wild. So what's the one thing that seems are getting wrong about AI and software delivery right now?
00:27:24:06 - 00:27:46:19
Brian
I think they're thinking too small. We have created so much software over the years that has so many security problems in it, and we're using AI to go find those problems and fix them one point at a time. And I don't see many people that are just saying, just rewrite the whole lot, just completely fix the world.
00:27:46:19 - 00:27:47:03
Adam
For me.
00:27:47:04 - 00:27:48:09
Adam
Yeah, right.
00:27:48:09 - 00:28:07:12
Brian
And and I think AI is going to have to fundamentally change how we think about software, how we think about security. And we can't just use it to replace one function at a time or one thing that we do. We have to rethink what is a security organization even look like. So so I think people are thinking too small.
00:28:07:12 - 00:28:13:08
Brian
And as they wrap their head around all of this, it will probably change the world in ways that we haven't even thought of.
00:28:13:09 - 00:28:30:04
Adam
Finger snaps, man finger snaps to that. Nice. I agree completely love it. Awesome. Well, Brian, thank you so much for spending time with us today. We were excited to have you on and you provided some great insight, some great, some great takes. So we really appreciate that.
00:28:30:05 - 00:28:32:06
Brian
Yeah, thanks for having me. It's been a wonderful time.
00:28:32:06 - 00:28:42:00
Adam
All right. So great to have Brian on. Super insightful. But Martin what is your takeaway. What's the one the one big thing that you have.
00:28:42:01 - 00:29:05:03
Martin
So my favorite thing and it was quite, quite near the end of the conversation, but that, you know, once we started talking about the money, the perspective he bought of it might only be a return on investment of 20%, but that 20% might actually be worth more than the whole thing. That looking beyond the numbers for the value I thought was awesome, I very much appreciated it.
00:29:05:03 - 00:29:08:11
Martin
How about you? Did you did you have a favorite from today?
00:29:08:11 - 00:29:33:22
Adam
I did love that part. I also forget sometimes that Brian was in the spook world for a while, and I forget sometimes how intentional software flaws can be. That's something that has stuck with me and has made me slightly nervous. This entire conversation is that there are people who are extremely good at inserting flaws into software, so that they can be used by nation states.
00:29:34:00 - 00:29:34:12
Adam
No.
00:29:34:14 - 00:29:48:15
Martin
I, I get it, I get it. And there was a whole other story we didn't even get to today about hackers using AI, and they couldn't control the I hacked their own country as well as the countries they were attacking anyway.
00:29:48:17 - 00:29:53:10
Adam
Yeah. Anyway. Anyway. Right. Let's go to what you were saying. So it does.
00:29:53:11 - 00:30:09:00
Martin
So that ship talk to you by harness. And if Adam's comments, you know, got under your skin, then why don't you subscribe? Like do all of the things drop in the comments and tell us why? Until next time, let's stop talking and start shipping.