POPULARITY
Categories
Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims' devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims
Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims' devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims
Why is Tennessee filled with so many ancient Egyptian names, monuments, and symbols? In this conversation, Jessie Czebotar and I examine Memphis's connection to ancient Egypt and the meanings she sees within the Memphis city seal, the Tennessee state flag, the University of Memphis coat of arms, and the Catholic diocese's symbolism. We also explore the Memphis Pyramid, Ramesses II, the Apis bull, Serapis, ancient Egyptian writings about death, and whether naming a city after an ancient location could carry spiritual or territorial significance. On the Plus Side, we continue deeper into Tennessee by examining Dolly Parton, Dollywood, the Imagination Library, Oak Ridge, and the unusual questions surrounding Dolly's death. You can find Jessie Czebotar and her work here: Website: https://www.kingdomlivingwithjessie.com YouTube: https://www.youtube.com/@jessieczebotar4619 Patreon: https://www.patreon.com/cw/JessieCzebotar BUY A COFFEE LINK Support the Show & Stay Connected: Buy Me a Coffee: https://buymeacoffee.com/sensiblehippie Join My Patreon for ad-free episodes & exclusive content: https://Patreon.com/WakeupwithMiya If you're joining Waiola – The Plus Side, please subscribe through a web browser (Safari or Chrome) instead of the Patreon app — it directly supports the show. Mahalo nui loa for supporting independent work and helping keep this platform growing. Shop my Amazon Storefront: https://www.amazon.com/shop/profile/amzn1.account.AGYOPCXXGH6MN5RVAKGQWVZUZLEA/list/26B87RB4FZ9W2?ref_=cm_sw_r_cp_ud_aipsflist_6BWRT43TH4MY2NM2XD6X Want to be on the show or suggest a guest? I'm looking for guests who can speak on human trafficking, the paranormal, occult symbolism, hidden history, spiritual warfare, ancient mysteries, and specific military stories involving covert operations, secret programs, psychological warfare, unexplained events, and firsthand accounts. Email me at: Miya@wakeupwithmiya.com Exclusive Discount!Shop at LVNTA: https://lvnta.com/lv_IcTq5EmoFKaZfJhTiS Use code OHANA for 20% off! Listen on Your Favorite Platform: Spotify, Apple Podcasts, YouTube, and everywhere podcasts are available! RATE & REVIEW: Apple: https://podcasts.apple.com/us/podcast/wake-up-with-miya/id1627169850 Spotify: https://open.spotify.com/show/0UYrXCgma1lJYzf8glnAxy Music Credits: Beginning: "Echoes in the Shadows" - DK End Music: “Crazy” - EkoBecome a supporter of this podcast: https://www.spreaker.com/podcast/wake-up-with-miya--6339129/support.
This Episode is Sponsored by StayFi Your ultimate tool for Vacation Rental WiFi marketing allowing you to collect guest emails automatically via custom captive WiFi login splash pages. Drive repeat direct bookings and convert your OTA bookings to book direct for their next visit. Visit https://stayfi.com/vrsuccess/ and use code VRSUCCESS for 50% off 3 months of StayFi service. ________________________________________________________________________________________________________________________________________ This summer Andrew Kitchell opened up Wheelhouse and invited his customers to build on top of it. Not engineers. Customers. Property managers, revenue managers, and a fair number of people who had never built anything in their lives. Over four days, 120 people from six continents worked together, and 40 of them finished with a working prototype. The top prize of $5,000 went to a full-time property manager who had never told anyone he was interested in building software. Heather has spent her own summer building, so she came to this conversation with the question she keeps turning over: if someone with no coding background can build a working app, does that mean every property manager should? Andrew has a clear answer, and it has nothing to do with the tools. His view is that the barrier is no longer technology or design or user experience. It is permission. Giving yourself permission to stop doing what you normally do and decide that today is a build day. Along the way they get into what a hackathon actually is, why Wheelhouse now describes itself as a growth company rather than a pricing company, how MCPs let you ask questions of your portfolio in plain language, and where building your own tools earns its keep against where it becomes an expensive hobby. About Andrew Kitchell Andrew Kitchell has been in and around the short-term rental space for around fifteen years, starting as an Airbnb host in San Francisco while the platform itself was being built a few blocks away. He joined an eight-person urban rental company that was updating its prices by hand twice a week, spent a weekend hacking the Airbnb API to automate it, and four weeks later the business had pivoted into Beyond Pricing. He went on to found Wheelhouse and the operating company Lyric, and has run both technology businesses and operating businesses through some hard cycles, including losing Lyric entirely when COVID hit. Wheelhouse today connects to around 800,000 listings and has opened its full platform to anyone who wants to build on it. Key Takeaways The barrier to building your own tools is no longer technical skill. Andrew argues it is permission, the decision to stop doing today what you normally do and treat a few hours as build time. If you can describe a problem clearly, you are much closer to solving it than you think. Property managers describe their operational problems better than almost anyone, and that description is now most of the work. The old software model asked the person who understood the customer to hand that understanding to an engineer and hope it survived the journey. That gap has closed, and the people closest to the problem can now solve it themselves. You do not have to build anything yourself to benefit. Direct booking sites, owner reports, and small internal tools are all cheaper and faster to produce now, whoever builds them. Building is worth the time when it lands in your quieter season and when what you learn carries into the next build. Treat the first few attempts as research and development, not as finished product. MCPs remove the need to understand APIs at all. Connect Wheelhouse to Claude and you can ask questions of your portfolio and execute pricing strategy in ordinary language, which Andrew sums up as a click is a command, is a chat. An open platform produces better outcomes than a single one. After the hackathon there is no longer one Wheelhouse experience, there are forty-one, each built by someone who knew exactly what they needed. _______________________________________________________________________________________________________________________________________
Frank Tumminello is the founder of FileForms, a company focused on simplifying business compliance and filing requirements for entrepreneurs and companies across the U.S. With a strong background in business operations and regulatory processes, Frank has helped streamline how businesses stay compliant with state and federal requirements. Through FileForms, he provides practical solutions that save business owners time, reduce risk, and eliminate the complexity of ongoing filings—allowing entrepreneurs to focus on growth and scaling their companies. During the show we discuss: Why business compliance is often overlooked Annual reports and maintaining good standing How missed filings can affect financing Compliance requirements when operating across multiple states Nexus triggers involving employees, assets, property, sales, and revenue Costly compliance mistakes and franchise taxes How compliance can affect business sales and due diligence Technology, APIs, and AI in compliance Resources: https://fileforms.com/
In this sponsored episode, Ronny Wolf of BlueCat Networks joins Johna and John to explore the importance of API-first architecture. They also discuss how BlueCat expanded beyond core DDI into intelligent network operations, the key differences between having APIs versus being built API-first, and how guardrails such as rate limiting and human in the loop... Read more »
In this sponsored episode, Ronny Wolf of BlueCat Networks joins Johna and John to explore the importance of API-first architecture. They also discuss how BlueCat expanded beyond core DDI into intelligent network operations, the key differences between having APIs versus being built API-first, and how guardrails such as rate limiting and human in the loop... Read more »
In this sponsored episode, Ronny Wolf of BlueCat Networks joins Johna and John to explore the importance of API-first architecture. They also discuss how BlueCat expanded beyond core DDI into intelligent network operations, the key differences between having APIs versus being built API-first, and how guardrails such as rate limiting and human in the loop... Read more »
Recorded August 28, 2026 What does AV programming really look like in 2026? As configurable platforms, APIs, visual logic, and AI-assisted code generation make complex systems easier to build, the panel debates whether the dedicated AV programmer is becoming obsolete. The consensus, more or less, is that programming isn't going away, but the silo around it probably is. The future looks more like a shared engineering skill focused on configuration, user experience, commissioning, and making systems work without turning every classroom into a science project. Alternate show titles: We made it to the past! If it's coming from outside the house Having semicolons I'll crack that sh*t Prompting a prompt An entire screen of slop code I just want one button Secret eyeballs The little script that I need It's just something dumb We're just arguing words now What if we could make it worse? You need someone behind them Stop worrying about who to blame! We're all vehemently agreeing Claim your code We stream live every Friday at about 315p Eastern/1215p Pacific and you can listen to everything we record over at AVSuperFriends.com ▀▄▀▄▀ CONTACT LINKS ▀▄▀▄▀ ► Website: https://www.avsuperfriends.com ► Twitter: https://twitter.com/avsuperfriends ► LinkedIn: https://www.linkedin.com/company/avsuperfriends ► YouTube: https://www.youtube.com/@avsuperfriends ► Bluesky: https://bsky.app/profile/avsuperfriends.bsky.social ► Email: mailbag@avsuperfriends.com ► RSS: https://avsuperfriends.libsyn.com/rss Donate to AVSF: https://www.avsuperfriends.com/support
Show DescriptionWe're joined by Thomas Steiner from Google to discuss his proposal for cross-origin storage, a new web API designed to bring back safe, cross-site resource sharing. We explore why the old shared-CDN caching model collapsed due to privacy and fingerprinting risks, and how this could solve those issues while avoiding those same pitfalls. Listen on WebsiteWatch on YouTubeGuestsThomas SteinerGuest's Main URL • Guest's SocialDeveloper Relations Engineer at Google, focused on the Web and Project Fugu. Links David Bushell daverupert.com 633: Thomas Steiner on AI in Chrome and the Web Pervasive Resources Intent to ship: Cache sharing for extremely-pervasive resources
There is no shortage of AI hype for Amazon sellers. "AI bidding." "AI agents." Videos about tools that shipped this morning.This is the opposite of that. Michael walks the full 10-level progression from clicking around in Seller Central to running autonomous, self-improving agents on your account and is honest about what each level actually costs you in time. Claws out.We'll see you in The PPC Den!
Andrew welcomes back Constantin Hager, a senior systems engineer, PowerShell User Group organizer, and brand new Microsoft MVP. They open by revisiting Constantin's infamous "size of a finger" intro from his first appearance, then dig into his talks at PSConfEU this year on dev containers with GitHub Codespaces and on Maester, the testing framework for M365 and on-prem AD. A quick detour into the GitHub vs. GitLab vs. Codeberg debate leads into the main event: a deep breakdown of Microsoft365DSC, what it actually does, how it treats M365 tenant settings like Intune, Entra, and Exchange as idempotent, drift-monitored code, and how the M365DSC Workshop wraps the notoriously painful setup process into a lab folder anyone can run. They cover the workshop's multi-tenant design, its DSC Community roots, and the honest limitations, like settings that still aren't exposed through public APIs. Constantin also shares his organic path to becoming an MVP, updates on his user group's shift to English-language talks, and a heads up on an upcoming blog series diving deeper into M365DSC. They close with news on the free PSConfEU MiniCon, happening October 13th with the CFP open until September 25th. Key Takeaways: Microsoft365DSC turns M365 tenant configuration into idempotent, drift-monitored code, and the M365DSC Workshop exists specifically to make the notoriously painful setup process approachable through a ready-to-run lab folder instead of a hundred-page whitepaper. Not everything in M365 is automatable yet. Settings without a public API (some Copilot controls, for example) still require manual portal fixes or an interactive token, so full automation has real gaps today. Constantin's MVP award grew out of years of showing up, organizing his user group, speaking at conferences, and opening GitHub issues, not out of being the loudest voice in the room. Guest Bio: Constantin Hager is a senior systems engineer based in Germany, organizer of the PowerShell User Group Inn-Salzach, and a newly awarded Microsoft MVP. A returning guest of the podcast, he's known for his enthusiasm around dev containers, PSFramework, and now Microsoft365DSC. Resource Links: Constantin Hager on LinkedIn https://www.linkedin.com/in/constantin-hager/ Constantin's blog, The IT Guide https://the-itguide.de Andrew's blog: https://andrewpla.tech PowerShell User Group Inn-Salzach (Meetup) https://www.meetup.com/de-DE/powershell-usergroup-inn-salzach/ Maester (M365 and Entra security testing framework) https://maester.dev/ Microsoft365DSC official site https://microsoft365dsc.com Microsoft365DSC on GitHub https://github.com/microsoft/Microsoft365DSC M365DSC whitepaper and CI/CD pipeline scripts https://github.com/ykuijs/M365DSC_CICD DSC Community https://dsccommunity.org PSConfEU https://psconf.eu PSConfEU MiniCon Call for Papers (Sessionize) https://sessionize.com/psconfeu-minicon/ PDQ Discord https://discord.gg/PDQ The PowerShell Podcast on YouTube: https://youtu.be/Vy4kaayGT2M
Join Sam Chen, Founder and CEO of OpenCSG, for an essential exploration of sovereign AI and open-source infrastructure. As enterprises, local governments, and smart cities race to integrate generative and agentic AI, relying strictly on proprietary, closed-source cloud APIs presents significant operational risks: vendor lock-in, ballooning compute costs, regulatory compliance friction, and severe data privacy vulnerabilities. Drawing on over 20 years of deep industry leadership—including founding JiHu (GitLab China), serving as Vice Chair of the Cloud Native Computing Foundation (CNCF), and leading senior initiatives at IBM, HP, and Mesosphere—Sam shares a pragmatic blueprint for how organizations can build, deploy, and retain total ownership over their AI stack.
In this episode I sit down with Faryam Asif, CTO at Shufti, to unpack how identity verification is evolving as agents, deepfakes, and AI-driven attacks accelerate. The conversation focuses on how Shufti verifies individuals, businesses, and transactions, and why layered security is becoming essential in regulated industries. Faryam also explains how the company is adapting to new use cases like agent verification, age estimation, and audit trail requirements. Faryam explains how Shufti verifies individuals, businesses, and transactions across industries including financial services, healthcare, retail, gambling, social media, and crypto. We discuss document verification, facial biometrics, live selfie and video checks, address verification, NFC-based passport verification, KYB, and AML workflows. I raise the growing challenge of AI agents and asks how identity verification adapts when an automated agent, not just a human, is completing a workflow. Faryam introduces the emerging concept of KYA, know your agent, and explains why the industry is shifting toward verifying the person behind the action. We discuss how deepfakes and synthetic documents have lowered the cost and speed of fraud, making scalable attacks much easier than before. Faryam shares how Shufti is responding with layered verification, combining document checks, facial likeness, device intelligence, behavior analysis, risk scoring, media integrity, and database checks. The conversation explores how behavioral signals are becoming important as attackers learn to mimic human pauses and interaction patterns. We dig into compliance, auditability, and why regulated industries now need proof of how verification happened, not just who was verified. Faryam explains Shufti's own technology stack, including proprietary facial liveness, document verification, OCR, transaction monitoring, KYB, AI, and ML systems. We cover deployment options and integrations, including on-premises hosting, cloud APIs, SDKs, and plugins for platforms like WordPress, Shopify, and Okta. Faryam also discusses Shufti's global footprint, compliance posture, and use cases such as facial age estimation for social media and adult-content restrictions. I hope you enjoy it!
Entrevista al Dr. Cs. Vet. Marcos Daniel Salina y Médico Veterinario de la Facultad de Ciencias Veterinarias de la Universidad Nacional de La Plata (UNLP). Es investigador del Centro de Microbiología Básica y Aplicada (CEMIBA) de la FCV-UNLP y desarrolla su actividad en el área de virología e inmunología veterinaria. Su trayectoria científica se encuentra especialmente vinculada al estudio de las enfermedades virales de las abejas, con particular interés en los patrones de infección de los iflavirus en Apis mellifera 12/09/2026. Con quien conversamos sobre su participación en FILAPI 2026.
AI is transforming cybersecurity, but securing AI systems is a unique challenge. In this full course session, InfosecTrain breaks down the core differences between securing with AI and securing AI itself. Discover AI/ML foundations, blue and red team defense tactics, MLOps, API security, and practical threat modeling techniques to future-proof your security career.The "course titled" Practical AI Security Engineering Program provides hands-on expertise to defend AI pipelines.
We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called “AgentBaiting,” in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption. Segment Resources: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware For more information about Island's research, please visit https://securityweekly.com/islandbh After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5 Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection. This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them! The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it. This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them! Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production. Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster. This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-399
We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption. Segment Resources: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware For more information about Island's research, please visit https://securityweekly.com/islandbh After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5 Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection. This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them! The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it. This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them! Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production. Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster. This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them! Show Notes: https://securityweekly.com/asw-399
We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption. Segment Resources: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware For more information about Island's research, please visit https://securityweekly.com/islandbh After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5 Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection. This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them! The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it. This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them! Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production. Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster. This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-399
We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption. Segment Resources: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware For more information about Island's research, please visit https://securityweekly.com/islandbh After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5 Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection. This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them! The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it. This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them! Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production. Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster. This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them! Show Notes: https://securityweekly.com/asw-399
What happens when a one-hour conversation with a financial advisor creates an entire day of paperwork behind the scenes? In this episode of Tech Talks Daily, I speak with Hardy Michel, Co-Founder of Marloo, about the administrative load limiting how many clients financial advisors can support. Hardy previously helped build retail investing platforms in New Zealand and the UK, where he saw people gain easier access to investments while personal financial advice remained harder to obtain. Before building Marloo, Hardy and his co-founders spent months inside financial advice firms. They interviewed managing directors, compliance leaders, support teams and advisors, then worked beside them as they moved between inboxes, planning tools, client records and compliance systems. This "go slow to go fast" approach helped the team map the complete advice process before deciding where software could remove friction. Hardy says a 60-minute client meeting can produce 10 to 14 hours of follow-up work. An advisor may need to document the discussion, demonstrate why the advice was suitable, complete product research and cash-flow modeling, record fees and disclosures, and prepare a client-facing report that can run to dozens of pages. According to Hardy, the cost and time involved have left some advisors unable to accept new clients for several years. Marloo began as a specialist meeting assistant because note-taking is frequent, painful and driven by regulation. Hardy explains how transcripts created a current source of client context that was often absent from static records. The company then expanded into the work that follows a meeting, including advice documents and presentations, with the longer-term aim of becoming a central working environment for an advice firm. We also discuss the trust required when AI handles personal and financial information. Hardy describes Marloo's zero-data-retention arrangements for certain model APIs and the security information it provides to firms. He argues that specialist systems need to demonstrate how client data is handled and give advisors language they can use to explain recording and transcription to clients. Adoption is another major theme. Hardy recommends a focused two-week trial with three to five likely power users, a defined goal and a clear measure of value. Rather than relying on a successful demonstration, firms should examine whether advisors continue using the product and are prepared to recommend it to colleagues. The strongest business outcome may be what advisors choose to do with the time returned to them. Hardy says some Marloo users have increased client meeting frequency from once or twice a year to five or six times. Should AI in financial advice be measured by the volume of cases completed, the quality of client relationships, or a combination of both? Listen to the episode and share your thoughts with me.
Beekeeping challenges rarely stop at national borders. This week, Jeff and Becky cross the Atlantic for a conversation with Dr. Andrea Quigley and Norman Carreck, co-editors of the UK-based Beekeepers Quarterly. Norman, a longtime beekeeper and bee scientist, introduces listeners to the UK's extensive beekeeping education system and his work conserving the native dark European honey bee, Apis mellifera mellifera. The conversation explores what locally adapted honey bees can teach beekeepers about genetics, winter survival, colony size, temperament, and management. Andrea then takes us inside Beekeepers Quarterly, an independent, internationally focused magazine published by Northern Bee Books. She explains how the quarterly combines practical beekeeping, science, conservation, and perspectives from contributors around the world. The discussion also turns to two emerging threats with international implications: Tropilaelaps mites and the yellow-legged hornet. Norman and Andrea explain why early detection, understanding pest biology, and cooperation among researchers, government agencies, beekeepers, and the public matter—and what North American beekeepers might learn from the European experience. It's a wide-ranging conversation offering a decidedly international perspective on honey bees, beekeeping, research, and the challenges ahead. Websites from the episode and others we recommend: Beekeepers Quarterly: https://www.northernbeebooks.co.uk/blogs/bkq Honey Bee Health Coalition: https://honeybeehealthcoalition.org Project Apis m. (PAm): https://www.projectapism.org The National Honey Board: https://honey.com Honey Bee Obscura Podcast: https://honeybeeobscura.com Copyright © 2026 by Growing Planet Media, LLC ______________ Betterbee is the presenting sponsor of Beekeeping Today Podcast. Betterbee's mission is to support every beekeeper with excellent customer service, continued education and quality equipment. From their colorful and informative catalog to their support of beekeeper educational activities, including this podcast series, Betterbee truly is Beekeepers Serving Beekeepers. See for yourself at www.betterbee.com This episode is brought to you by Global Patties! Global offers a variety of standard and custom patties. Visit them today at http://globalpatties.com and let them know you appreciate them sponsoring this episode! As a beekeeper, you want products that benefit you and your bees. When you choose Premier Bee Products, you choose hive components that are healthier for bees and more productive for you. Because we believe that in beekeeping, details make all the difference. Premier Bee Products: Better for bees. Better for beekeepers. Use promo code PODCAST for 10% off your next online order. Thanks to Strong Microbials for their support of Beekeeping Today Podcast. Find out more about their line of probiotics in our Season 3, Episode 12 episode and from their website: https://www.strongmicrobials.com HiveIQ is revolutionizing the way beekeepers manage their colonies with innovative, insulated hive systems designed for maximum colony health and efficiency. Their hives maintain stable temperatures year-round, reduce stress on the bees, and are built to last using durable, lightweight materials. Whether you're managing two hives or two hundred, HiveIQ's smart design helps your bees thrive while saving you time and effort. Learn more at HiveIQ.com. We'd like to thank Vita Bee Health for supporting the podcast. Vita provides proven tools for controlling Varroa—from Apistan and Apiguard to the new VarroxSan extended-release oxalic acid strips—helping beekeepers keep stronger, healthier colonies. Thanks for Northern Bee Books for their support. Northern Bee Books is the publisher of bee books available worldwide from their website or from Amazon and bookstores everywhere. They are also the publishers of The Beekeepers Quarterly and Natural Bee Husbandry. Thanks to Bee Culture, the Magazine of American Beekeeping, for their support of Honey Bee Obscura. Available in print and digital at www.beeculture.com _______________ We hope you enjoy this podcast and welcome your questions and comments in the show notes of this episode or: questions@beekeepingtodaypodcast.com Thank you for listening! Podcast music: Be Strong by Young Presidents; Epilogue by Musicalman; Faraday by BeGun; Walking in Paris by Studio Le Bus; A Fresh New Start by Pete Morse; Wedding Day by Boomer; Christmas Avenue by Immersive Music; Red Jack Blues by Daniel Hart; Bolero de la Fontero by Rimsky Music; Perfect Sky by Graceful Movement; I'm Not Running Away This Time by Max Brodie; Original guitar background instrumental by Jeff Ott. Beekeeping Today Podcast is an audio production of Growing Planet Media, LLC ** As an Amazon Associate, we may earn a commission from qualifying purchases Copyright © 2026 by Growing Planet Media, LLC
Steve Blough of Infios talks about 2026 peak season - the state of the market, from challenges to rates; the capacity crunch; & the role of AI and new tech. IN THIS EPISODE WE DISCUSS: [02.33] Steve's career background, his key areas of focus in supply chain, and the challenges he currently hears from shippers and carriers. "Capacity is tight, rates are high, and shippers are taking a hard look at how they're moving freight." [06.41] The state of the market in 2026 and why capacity is a big challenge. "Capacity has contracted so much faster than anyone thought it would… So, when you look at the market, it's a demand story not a supply story." [08.41] What rates look like now, and where Steve expects them to go through the remainder of 2026. "Spot rates are climbing and as they climb… some of the carriers guaranteed capacity has evaporated." [13.49] 2026 peak season and why it's arriving earlier than usual, from tariff fear to changes on the Panama Canal. [16.47] How current challenges and technologies are changing the way shippers operate, communicate, and seek out partners. "That communication backbone, and the need to get data back and forth quickly, has become critical." [18.37] Why the capacity crunch is a network problem, not a rate problem, and an example of an Infios client leveraging the capacity in their network to move more goods at lower rates. "Everyone can win by looking broadly." [21.09] Why good data and communication between systems are critical. "As systems and solutions have got more modern, APIs have made those communications much easier.. So one of the things that excites me most about AI is the ability to improve data." [23.04] What network-level decision-making actually looks like in practice, compared to the lane-by-lane process most teams are still running. "It's not just looking at something and going: "I should put that in a truck." It's: "Should I do intermodal, truckload, parcel, zone-skipping… With all the different modes, what's the right thing to look at with the freight I have now?" [25.43] Consolidation, and the capacity hiding inside a shipper's own network that most companies aren't using. [28.42] Whether tighter capacity creates more business risk. [30.36] What AI can actually do for a shipper during peak season, and technology's role looking ahead. [34.28] How much autonomy we should give AI as organizations look to manage effective automation, risk, cost and people. [35.36] An overview of Infios, and what it means to deliver Intelligent Supply Chain Execution. [38.06] What shippers should focus on between now and the holiday peak. RESOURCES AND LINKS MENTIONED: Head over to Infios' website now to find out more and discover how they could help you too. You can also connect with Infios and keep up to date with the latest over on LinkedIn or YouTube, or you can connect with Steve on LinkedIn. If you enjoyed this episode and want to hear more from Infios, check out: 544: How To Move Toward Intelligent, Connected Execution, with Infios 532: Turning Purposeful AI into Business Outcomes, with Infios 520: Enter the New Era of Supply Chain Management, with Infios Check out our other podcasts HERE.
What does an AI agent need before it can carry out useful work across the systems that actually run a business? In this episode of Tech Talks Daily, I speak with Daniel Chilcott, Managing Director and co-founder of Flowgear, about the integration infrastructure behind agentic AI, product-led growth, and enterprise automation. Daniel's career began with a ZX Spectrum and a job as the first software developer inside a small business. The company built custom software and a CRM, but customers repeatedly needed that software connected with accounting, ERP, and other operational systems. Building every connection by hand convinced him there had to be a better approach. He created an on-premises integration product in 2007, then co-founded Flowgear in 2010 as a cloud service. The conversation shows how much the market has changed. In Flowgear's early years, Daniel had to explain why integration software belonged in the cloud. Today, roughly half of the company's customers are in the United States, and the larger question is how AI changes the way people build integrations. Traditional platform vendors often supplied templates or starter packs. Those templates offered a useful starting point, but Daniel says they could create the illusion of a finished solution when every customer still had different processes, rules, and systems. Generative AI offers another route. A user can describe the integration they need, and an agent can create and test the workflow, identify problems, and revise the design. That makes a product-led model more practical because customers can reach a result without first becoming specialists in the platform. Flowgear still supports a visual designer, but Daniel says many customers increasingly build outside the product interface because the integration is part of a wider application or business outcome. This matters because much of the information needed for knowledge work sits behind APIs in ERP, CRM, warehouse management, and other line-of-business software. Reading a document from cloud storage is useful, but an agent becomes far more capable when it can work with operational records and complete an approved action. Flowgear's Builder MCP server is intended to bring that capability into the AI chat or development environment where the user already works. A person can ask for an application, and the agent can create the supporting integration without requiring that person to construct every workflow manually. Daniel is equally clear about the limits. Some business processes contain what he calls irreducible complexity. They carry unusual rules, historic decisions, exceptions, and dependencies that cannot be removed by a cleaner interface or a better model. Flowgear therefore continues to rely on solution architects who can connect the customer's operational knowledge with the technical workflow. An experienced specialist may identify the question nobody thought to ask because they have seen the failure pattern before. We also discuss the decision to rebuild Flowgear's platform. Daniel estimates that less than five percent of the code from five years ago remains in the current product. The rewrite was difficult, but its timing allowed the company to support generative and agentic AI from the start instead of attaching those capabilities to an older architecture. He describes it as feeling like a startup again, accompanied by the less glamorous work of testing failure modes and making the product dependable. The most human example comes from a customer that used a call center for weekly product reorders. Flowgear helped automate the routine transaction through WhatsApp, allowing the same employees to spend their time on better conversations with customer accounts. It is a useful test for automation: does it merely reduce minutes, or does it create room for more valuable work? Where does your organization need stronger integration before AI agents can become useful across everyday operations? Listen to the episode and share your thoughts with me.
Sky Mavis announces its AI-based Axie Vibeathon, while Animoca and AWS launch their Agentic Football Cup. [00:43] Sky Mavis announces Axie Vibeathon - using AI to make Axie Core games. [01:54] Registration is available until Monday 7th September. Submissions close by 21st. [03:10] You have to provide your own AI.[04:42] Sky Mavis provides a Builder Resource Kit that includes art assets and APIs. [05:35] The best 8 projects will get $250 of AI to build further, ending on 31st October. [07:08] Total prize pool is 20,000 bAXS, with the winner getting 9,000 bAXS ($8,500). [09:56] Animoca and AWS are launching Agentic Football Cup - Virtual League. [12:08] The 10 winners of the competition go to the AWS Re:invent conference in Las Vegas. [12:45] It's free to enter. You build/prompt a five-player AI football team.[14:08] There's also the ability to give live instructions during matches. [15:05] From 11th September, you play 10 games each weekend for 7 weeks. [16:05] All blockchain games should be running this type of AI hackathon. [17:12] Blockchain games are particularly suited for this sort of AI creation.
Revenue management is getting faster, smarter, and more accessible—but building the next generation of pricing technology comes with a surprising challenge: how do you get operators to trust the numbers? In this episode of The STR Data Lab, Chief Economist Jamie Lane sits down with AirDNA's Data Science Manager Marc Moreno and Senior Product Manager Jordon Myers to go behind the scenes of building AirDNA's new revenue management platform, Adapt.The conversation explores what AirDNA learned from hundreds of conversations with STR operators, including the surprising number of hosts still managing pricing manually and the widespread frustration with opaque pricing recommendations. Marc and Jordon explain why explainability became a core design principle, how millions of listings and noisy data shaped the modeling process, and why some of the most promising AI approaches had to be reconsidered. They also unpack how AI has fundamentally changed the product development process—from months-long handoffs to rapid prototyping, testing, and iteration with real users.Looking ahead, the team discusses where revenue management is headed as AI agents, APIs, and new data interfaces become more common. The future may not be about forcing operators into another dashboard—it could be about making reliable revenue management data and recommendations accessible wherever operators already work.You don't want to miss this behind-the-scenes look at how the future of STR revenue management is being built.Key TakeawaysTrust is just as important as accuracy. A pricing recommendation is only valuable if operators understand where it came from and feel confident acting on it.Clean data is the foundation of good pricing. With millions of listings across multiple channels, filtering noise and engineering the right signals can be just as important as the model itself.Events require proactive pricing. Rather than waiting for demand to appear in the data, revenue management systems need to identify external signals early enough to adjust pricing before bookings happen.AI is changing how products are built. Rapid prototyping and AI-assisted development allow teams to test ideas with real data and users much faster than traditional product-development cycles.The future may extend beyond the UI. As operators increasingly use AI agents, APIs, and their own internal tools, revenue management data needs to be accessible wherever decisions are being made.Sign up for AirDNA for FREE
What if your website already supports post-quantum cryptography, but nobody inside your organization knows how, why, or which provider controls it? I speak with David Warburton, Director of F5 Labs Threat Research, about new F5 research examining post-quantum cryptography across the world's top one million websites. According to the research discussed in our conversation, 54% now support PQC. It is an encouraging sign that preparations for future quantum threats are entering mainstream infrastructure. That figure is also easy to misread. David explains that much of the adoption comes from cloud and CDN providers enabling hybrid post-quantum protection for their customers. A smaller business could therefore appear better prepared than a large enterprise simply because its provider activated the technology automatically. However, that customer may have little understanding of the chosen cipher, the protection applied elsewhere, or the dependencies created around a small number of technology companies. David says the adoption rate looks very different when major CDN providers are removed from the data. This raises an important question about whether businesses are developing their own post-quantum security capabilities or temporarily benefiting from decisions made on their behalf. We discuss why current deployments combine established cryptography with newer post-quantum algorithms. This hybrid approach protects compatibility while browsers, APIs, operational technology, IoT devices, and older enterprise systems catch up. It also carries performance costs through larger cryptographic material and increased network traffic. David argues that crypto agility matters because organizations need the ability to change algorithms, certificates, and encryption methods as threats develop. The conversation also moves beyond encrypted traffic. Harvest now, decrypt later attacks involve collecting sensitive information today so it can potentially be decrypted when capable quantum computers arrive. David believes authentication and digital identity could create an even greater concern. A quantum computer able to produce valid certificates could potentially impersonate trusted websites, signed software, devices, or firmware. Legacy infrastructure remains one of the largest barriers. F5 Labs found that roughly one in ten leading websites lacked TLS 1.3 support, preventing them from supporting current hybrid PQC connections. David also explains why Germany and France may trail countries including the US, UK, Australia, Ukraine, and Singapore, despite strong national policies. Factors include digital sovereignty concerns and the concentration of older manufacturing and operational systems. For leaders beginning this work, David recommends speaking with suppliers, establishing internal ownership, reviewing business continuity plans, and creating a cryptographic bill of materials covering certificates, algorithms, libraries, applications, and devices. I'd love to hear your thoughts, so does your organization know where its cryptography lives and who controls its post-quantum readiness?
Industrial Talk is onsite at PowerGen and talking to Ted Pardee, CRO at Kognitiv Spark about "Augmented Reality hands-free connected worker solution". Ted Pardee from Kognitiv Spark discussed augmented reality's role in power generation at PowerGen in San Antonio. He highlighted the technology's potential to enhance efficiency and problem-solving by enabling remote expert guidance through headsets. Pardee emphasized the importance of leveraging AI and AR to address the skilled labor shortage and the "gray tsunami" of retiring experts. He noted that while Microsoft exited the AR headset market, numerous manufacturers now offer durable, intrinsically safe devices. Pardee also mentioned the integration of AR with existing systems and the development of disconnected worker solutions for low-bandwidth areas. Outline Introduction and Welcome to Industrial Talk Scott introduces the episode of Industrial Talk, sponsored by the Propane Education and Research Council, highlighting their commitment to safety training and innovative propane-powered technology.Scott praises industry professionals for their bravery, innovation, and problem-solving skills, celebrating them as heroes.The podcast is broadcasting from PowerGen in San Antonio, Texas, where industry professionals gather to discuss solutions for power generation. Introduction of Ted Pardee and Kognitiv Spark Scott introduces Ted Pardee, the guest, and his company, Kognitiv Spark, which focuses on augmented reality technology.Ted Pardee shares his first impression of PowerGen, describing it as an incredible conference with a large number of vendors and attendees.Ted emphasizes the importance of presenting new technologies to make businesses more efficient and solve problems.Ted provides a brief background on his career, highlighting his experience in the software business for over 30 years, including selling enterprise asset management software in the 1990s. Evolution of Technology and Augmented Reality Ted discusses the evolution of technology from mainframe to client-server to the web, and now to the mobile world.He explains how augmented reality technology, combined with AI, will revolutionize business operations by providing workers with headsets that connect them with experts remotely.Ted provides examples of how augmented reality can be used in various industries, including power generation and medical fields.He shares a personal anecdote about using MapQuest in the past, contrasting it with the current reliance on mobile devices. Application of Augmented Reality in Power Generation Ted describes how augmented reality headsets can help experts remotely assist workers in solving problems, especially in remote locations.He explains how the technology can be used in asset management, allowing experts to guide workers through repairs using Teams calls or Kognitiv Spark's remote assistance software.Ted highlights the importance of leveraging technology to protect workers and improve efficiency in industries like oil and gas, chemical plants, and manufacturing.He emphasizes that the technology is still in its early stages but has the potential to revolutionize how work is done in various industries. Durability and Market of Augmented Reality Headsets Ted compares the durability of augmented reality headsets to cell phones, suggesting that if a headset breaks, it can be easily replaced, similar to replacing a broken phone.He explains that the focus should be on the software that runs on the headsets, as the hardware can be replaced.Ted discusses the market for augmented reality headsets, mentioning that there are now many manufacturers, including Microsoft, which has exited the market.He predicts that in the future, there will be a variety of headsets available, each suited to different use cases and industries. Use Cases and Integration with Existing Systems Ted provides a use case for augmented reality in power generation, explaining how it can help ERCOT assess and solve problems quickly during extreme weather conditions.He discusses the integration of augmented reality with existing asset performance management systems, allowing workers to access real-time data and expert guidance.Ted explains how Kognitiv Spark's software has open APIs, making it easy to integrate with other systems and enhance existing solutions.He highlights the potential for augmented reality to improve maintenance efficiency and reduce downtime in various industries. Addressing Skilled Labor Shortage and Knowledge Transfer Ted addresses the issue of the skilled labor shortage and the "gray tsunami," where experienced workers are retiring, leaving a gap in expertise.He explains how augmented reality can help maximize the expertise of experienced workers by allowing them to remotely assist younger workers.Ted provides examples of how companies are using augmented reality to reduce travel for experts and improve efficiency in their operations.He emphasizes the importance of leveraging technology to bridge the gap between experienced workers and the next generation of professionals. Conclusion and Contact Information Ted shares his contact information, encouraging listeners to reach out to him on LinkedIn or through Kognitiv Spark's website.Scott thanks Ted for the conversation and highlights the importance of the work being done by Kognitiv Spark in advancing augmented reality technology.The podcast concludes with a reminder to listeners to visit the Industrial Talk website for more information and to connect with Ted Pardee.Scott reiterates the importance of storytelling and marketing for industry professionals to inspire the next generation and ensure the success of their companies. If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation. Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy! TED PARDEE'S CONTACT INFORMATION: Personal LinkedIn: https://www.linkedin.com/in/tedpardee/ Company LinkedIn: https://www.linkedin.com/company/kognitivspark/ Company Website: https://www.kognitivspark.com/ PODCAST VIDEO: https://youtu.be/ii7K4JZY_-k THE STRATEGIC REASON "WHY YOU NEED TO PODCAST": OTHER GREAT INDUSTRIAL RESOURCES: NEOM:
In June, the most capable American AI models stopped shipping as public launches and started shipping through a government gate. Six weeks later the gate is open again — and the real fight has moved to the layer no gate can touch. A Chinese open-weight model rattled trillions out of chip stocks, Washington pivoted from gating American closed models to threatening bans on Chinese open ones, the industry mounted its largest-ever policy counter-mobilization, and an American frontier model literally broke out of its lab and hacked another company. Knee-jerk reactions, or the beginning of real AI governance? Navigation: Intro The Gate Opens The Kimi Shock The Escape The Counterstrike and the Petition Interlude — The Low-Background Books The Investor Reckoning Conclusion Our co-hosts: Bertrand Schmitt, Entrepreneur in Residence at Red River West, co-founder of App Annie / Data.ai, business angel, advisor to startups and VC funds, @bschmitt Nuno Goncalves Pedro, Investor, Managing Partner, Founder at Chamaeleon, @ngpedro Our show: Tech DECIPHERED brings you the Entrepreneur and Investor views on Big Tech, VC and Start-up news, opinion pieces and research. We decipher their meaning, and add inside knowledge and context. Being nerds, we also discuss the latest gadgets and pop culture news Subscribe To Our Podcast Bertrand Introduction Welcome to Tech Deciphered Episode 80. This one, once again, will be all about AI, government, frontier models, and open weight counterstrike. A lot has been happening in the regulation space, in cybersecurity, in the launch of new models in the past, maybe just 6–8 weeks. It’s actually pretty insane how much happened. We believe it was time to do an episode to talk about where we are and maybe where all of this is going. Maybe let’s start with a summary of where we stand, all that June and July saga, so you, our listeners, can get up to speed if you are not already there. You want to start with some points? Nuno The Gate Opens Yeah. Again, to your point, the gate swings. The gate had closed. We had to prepare an episode for the gate closing, and then the gate reopened. Now we have a different episode. This will probably change again as we’re seeing there’s news every day. Let’s start maybe with the first 19 days of the gate closing. There was an executive order on June 2nd from President Trump that asked frontier labs to share models with the government, 30 days pre-release. It inferred the protected frontier model designation into that. Basically, it was effectively a de facto licensing agreement defined by an executive order of the President as of June 2nd. On June 9th, Anthropic launched Fable 5 and the famous Mythos 5 or Mythos. I’m not sure how you actually say it in English. Then on June 12th, there was an export control directive banning access by any foreign national. Since there’s no way to verify nationality in real-time, Anthropic had to switch the models off for everyone worldwide. Bertrand On this point, you could argue that there are possibilities to check IDs. Many services let you check IDs online. You can pre-check a flight by showing your ID. There are ways, it’s just that if you don’t want to follow what’s already available, because guess what? Maybe it slowed down your revenue growth, maybe it looks bad on you or whatever. My point is that there was actually an option. I think it’s already a decision from Anthropic to say it’s either on or off, but nothing in between. Nuno I think the point is they had no way implemented of doing it. If they implemented it, to your point, it would have hampered use in general. A lot of people wouldn’t have gone through that trouble of doing it. Anyway, long story short, in June 26th, the White House apparently asked OpenAI to limit GPT-5.6, so Sol, Terra, Luna, to only 20 vetted partners. Now, apparently, the trigger for a lot of these things that have been going on was that there was a jailbreak that was found by Amazon researchers. All of that led to this jumping around of, let’s close the gates. You have foreign nationals, and therefore, Anthropic got it out and said, “Hey, then we’re going to switch the models off until we can sort this out.” OpenAI was asked also to only allow it for certain vetted partners, et cetera. The government came in, closed the gates effectively, and said, “From now on, we need to be involved in this thing.” De facto regulation, there’s no doubt that this has imposed de facto regulation, certainly on the top players in the market. But then came the reversal. Bertrand, do you want to talk about the reversal, the gate swinging the other side? Bertrand Maybe I just wanted to say that as a user of Anthropic products, ChatGPT products, for the brief moments, a few days where Fable 5 was made available to the public before it was closed the first time, I immediately started using it. I must say it was a real issue to use it because the guardrails were pretty crazy. It would keep saying that my code was not okay, there was cybersecurity risk and stuff when I was doing absolutely reasonable development with absolutely no connection whatsoever to any cybersecurity risk, attack, detection, anything. Still, it would keep blocking me, degrading me to Opus 4.8 at the time. I just want to say this was already very hardcore what they were implementing, and not just hardcore, but in some ways, plain stupid for something that’s supposed to be super smart. It was totally unable to classify properly some of my work. I must say I was already disappointed. On top of it, the costs were insane. Half a day, I would reach my limits when I had the best plan you can get from Anthropic. My point is that there were some real serious issues when they launched Fable 5, even at that point. Nuno I had a similar issue. I used Fable 5 as well before they had to take it offline or take it off. I think the issue was really not that the guardrails failed. As you said, maybe the guardrails were actually too aggressive, but it was this jailbreak that caused the recall, apparently caused this knee-jerk reaction. Bertrand But my point is that it seems that it was not working either way. It would either overclassify something that’s absolutely not doing anything wrong, and it might fail to classify something that is actively trying to do some cybersecurity work. It’s a real issue of quality for a company that’s supposed to be at the forefront of quality of AI and everything. I think for me, there are already signs that something is deeply wrong. Nuno Then it’s reversed, right? We went the other way around. The government came out on June 26th and approved redeploying Mythos 5 to US organizations defending critical infrastructure, and then the export controls were effectively lifted on June 30th. July 1st, Fable 5 came back online for all of us to use. Shocking enough, with strings attached, that were different. They had some time to revise their commercial deployment of it along the way because it came back with some, “Now you have usage credits, but you have some limits on plan use, et cetera.” I’m like, “You guys, this was blocked. But meanwhile, you did have some time to do some commercial stuff around it.” Bertrand It was crazy. I’ve never witnessed any such crappy launch of any service whatsoever in 30 years in tech, it was so bad. Every day, they would change the terms of service. They would tell you it’s part of the plan. It’s not part of the plan. It’s part of the plan for three more days, and then it’s excluded. You have a special discount now, but then it goes back to full price. It was a total nightmare. I’ve never felt myself being so much mistreated by a company. I guess you saw the same, but when I started using the newest version of Fable 5, it was even worse, actually, I think. I couldn’t do any work with this crap. I let it go and work on the work I wanted it to do. It was simply not working. On top of it, you never know how long you are supposed to lose your credit, how fast. It was burning credit like crazy. Me, personally, I can say, very quickly, I actually stopped using it. I was like, “No, I cannot deal with this shit. My main model is back to Opus 4.8. I’m going to use Fable 5 for code review, but not anymore to control anything because I cannot trust it would do the job without stopping or changing models and stuff. I just cannot trust it.” Back to Opus 4.8 as my main model, I can say that my life was much easier. I use Fable 5 as a review mechanism, as a support mechanism, but not as the main mechanism. Suddenly, the guardrails were not so horrible anymore because it was used in a much lighter way, I guess. As a pain as a user, I think it was really bad. I don’t know your experience, but me, for me, it was unacceptable. Nuno I wouldn’t say it was as bad as yours in terms of just end-user experience. I think the terms of service switching back and forth, which went one further step, because then when they then launched Opus 5, they started making comparisons between Opus 5 and Fable so that people would migrate more and more to Opus 5 themselves, which is interesting. It’s like they’re saying “This is much cheaper. This is whatever. You’re not going to run of credits. You should use Opus 5,” kind of thing effectively. To your point, I don’t think they managed well the launch. They didn’t really manage it well. We’re moving people around. A lot of people are using this for stuff that’s like daily tasks, hourly tasks, anything that relates to code and co-work. It’s like, we need to have visibility on what your terms of service are going to be. Should I be using this new model or not? What’s happening to the other model? I don’t see it as negatively as you, Bertrand, but I see your point. It was clearly mishandled in terms of how they deployed it, how they were redesigning effectively their pricing scheme and their terms of service almost on a daily basis, at a certain point in time. We’re like, “Dude, there’s millions of people using this. You guys are making a lot of money.” Just moving it as it is. At this point in time, at the scale that these guys are at, it’s calling in people to say, how about we think through a class action suit at some point around pricing? Because you guys are changing the rules of the game all the time, right? Bertrand I don’t know if I need the class action, but for me, that joke that, “Let’s not rush too fast. The model is dangerous.” But still, they rushed the launch because it’s very clear that if they had enough compute capacity and stuff, they would not have to limit so much. They would not have to put so much cost per token and all of this. You can see that actually when they launch Opus 5, literally like 2, 3 weeks after, by most benchmark at launch, they tell you basically that, “You know what? Actually, Opus 5 is better than Fable 5 on 80% of the metrics.” They’re like, “What? Seriously? You couldn’t wait 2 weeks? Why did you even launch Fable 5 in the first place?” That’s another part for me that is quite literally insane, to be frank. It’s like, “Why? Why do you make us go through so much pain if it’s only to tell us after 2 weeks to…” “This new model, by the way, has less issues, less stuff, because 2, 3 times less is part of your plan, and it’s actually better by most metrics.” It’s like, “What’s going on here? What’s going on? Are you guys mad?” I don’t know. It was crazy. Personally, I still use Opus, now 5, as my main system and platform, Fable 5 for review, code reviews and the like. I don’t want to run into its stupid guardrails. I can see Fable 5, from my perspective, seems quite a bit smarter. I don’t know why they do this stupid benchmark showing you it’s actually worse than Opus 5. I guess they should have better benchmark if they want to demonstrate why you are supposed to pay 2, 3x more for a model versus another if it’s actually worse by most benchmark. Again, I still think it’s a huge mess from a marketing perspective, customer perspective. Me as a user, I really feel that they don’t want my money, and they couldn’t care less about me. This is even before everything else we’re trying to talk about. Nuno Yes. Maybe just to close the cycle on the reversal on the door opening the other way, finally, Commerce lifted the GPT-5.6 restrictions on July 8th, and then on July 9th, general availability across ChatGPT, Codex, and the API as well. What has this proved? It proved that now we have gating mechanisms, and certainly for closed models in the US, for sure. We had frontier models that were switched off worldwide in hours, and it took a couple of days, in this case, 19 days to restore them. There were concessions. Now we know that there were concessions around effectively institutionalizing that gate. Early government access to future models is, I think, now a given, certainly in the US. New safeguard frameworks are probably now having to be put in place. There are some stage limits now on who gets access to what for new models and how it happens. This voluntary executive order, so to speak, not really sure, has become effectively regulation enforcement path. It’s de facto regulation that now has been put in place. It has affected not just to the points we were making before, the access to these models, but also who gets access to these models, and actually potentially even pricing access to the models. It has probably some commercial implications as well as we just discussed along the way. Very significant. This is very significant. This is regulation, de facto at the table, imposed on the two largest players in the market by far by one government, in this case, the US government. This is significant. Actually, you could even allege it was imposed by the President because this was coming as part of executive orders. Really incredible. Pretty significant, fast, aggressive. It has created a regime that you could say it’s a regulatory regime, it’s a de facto regulatory regime. It has some significant pricing and licensing and commercial implications. It goes even beyond your classic regulatory framework. Very, very, very significant. Bertrand I don’t know if it goes beyond a classic regulatory framework. Nuno I think it does, because it has implications on who do you give access to? When government is saying you can only give access to these players, right? Bertrand Defense industry. It’s all over the defense industry. You cannot sell an F-35 like this. Nuno No, but that has commercial implications, Bertrand. That’s like you’re saying these are your customers, you go and use them. Bertrand That’s the defense industry. You cannot sell to Iran your F-35. No, that’s exactly the same story for me. Nuno No, no, no. It’s beyond that. These guys are saying when they came back, and they said, “For Mythos, you can make them available to these entities,” they were saying the first entities that are going to have access to the model. It has commercial regulatory implications. You’re saying these players are the first players that are going to have access to it. It’s no longer just defense concerns and these governments don’t have access to this. No, no, no. You’re saying to a company that is a private company, your models are only going to be used by these guys because I’m telling you so. It’s the other way around. It’s not even that you can’t sell it to Iran or whatever. It’s like you can only sell it to these guys. Bertrand Again, in the defense industry, if you’re a private company, do you think you can buy F-35 like this? No. Nuno No, no, no. But this is a private company, Bertrand. This is not a defense agency and a plane that is on whatever, with IP from the US, right? Bertrand Boeing is a private company, and they cannot sell the military equipment they manufacture. Nuno No, no, no. But the development of their IP was subsidized by agencies that belong to the US, right? That’s a different matter. It’s a matter of IP, right? This is not, right? Anthropic, their models are not owned by the US government. There’s no IP granted to the US government, to my knowledge. This has significant commercial implications. Bertrand Maybe, yes. Maybe on this. But I think there are already regimes to limit who you can sell to, and that’s decided by the state or the DOD. Nuno It’s the export control logic. The export control logic? Bertrand You have export control, and export control is Commerce. My point is that they are using existing tools, part of the government, to limit what can be sold. Selling chips, NVIDIA was limited in terms of where it could sell its chips. It’s not different either, but still there were limitations. If you are an ASML, you cannot sell to a private company in China. Many private companies cannot buy ASML products. This is a foreign company. This is a foreign company under pressure from US government. Nuno I understand, and I’m not a lawyer, but it feels different to me when you say you cannot export, this is export controls, to these countries, to these entities, et cetera, because they’re foreign et cetera. Then to say, “No, no, no. On top of that, these guys get first access.” That’s, for me, a significant shift. Again, I’m not a lawyer, so I’m sure there’s very intelligent people right now looking at this stuff and saying, “You can’t do this stuff, or not, or they can.” I don’t know. But it feels to me, it goes beyond the remit of export controls. It’s like you’re defining initial clients for specific use. Bertrand My impression is more like, “We can do this situation where we’re going to forbid you to give access to anyone outside the US or even in the US or limit even more.” Basically, it was, I guess, some gesture to go beyond that. That’s how they probably defined these 20 authorized companies. I don’t know. Apparently, there was also restrictions because I remember seeing that Anthropic had their own list of companies they would authorize access to Mythos early on. That’s apparently another thing that pissed off state government because there were companies in there that were considered close to the Chinese government. They were extremely unhappy that Anthropic didn’t ask, actually, for any guidance from the state government, but used basically their own perspective on who they should allow or not. I guess that was also part of why they got these serious restrictions. Nuno Anyway, now we have a regulatory environment that’s very interesting and exciting. Talk about the US not regulating. Bertrand To be clear, I don’t know you, but I’m not saying that I agree with any of this, to be very clear. I’m trying to explain and share some perspective, but I’m not in agreement on a lot of this. Nuno Yes, we were just describing what happened to the best of our knowledge. We’re having a discussion on what we think actually is happening and how it’s happening. We’re not really right now saying we agree or disagree with this. I think later in the episode, we can share some perspectives on what we think is actually happening and how there’s dimensions to this which are very geopolitical and very complex, which quite literally probably only God knows what’s going to happen. That was the gate swinging. There was a gate closing, then there was a gate reopening, and all of a sudden we have a gatekeeping system that has been created along the way. The Kimi Shock Along the way, moving to our Act 2, the world has changed, and we now have so-called open-source plays out there that are creating massive, massive shifts in the market. The Chinese models, in particular, with Moonshot AI launching Kimi K3, which is the largest open-weight model ever released. We’ll come back to the discussion around open-weights. I’m not sure all our listeners understand what that means, because there’s a debate now, should models be open weight or not, and how does that work? There’s been a petition as well signed along the way. Right now, we have open weight models that are out there that are huge. What that actually means very pragmatically is we now have open source models, lack of a better word. I know open weight and open source are not the same thing. You guys will have to bear with us during this episode. We’ll explain at some point the differences. But we have models out there that are open source that are significant. That are catching up with the closed source models, with the models by OpenAI, Anthropic. That’s significant because most of those models are Chinese. This is where the geopolitics starts getting really frazzling and we start playing 3D chess. Because everyone’s like, “These models are 5, 6 months behind.” Now people are saying, “Maybe they’re actually just 3 months behind, 2, 3 months behind.” If we, for example, decided to stop or slow down our model releases in the US by the closed source guys who are leading, it might mean they’ll catch up. What are the implications of that? Again, for you and I that are not necessarily experts in model development, well, the implications as a use case is if you want to use the latest models, and the best models start becoming these open source models, you’re going to use those models. Then you start using Chinese models. If you’re an American company, maybe you’ll have restrictions on the use of those Chinese models. But if you’re a European company, you probably won’t. What happens after that? Is the world going to be in the hand of Chinese models? Will that constitute effective competition to the closed models in the US? Will we have open models in the US that will scale as well? What’s going to happen? Bertrand I think it’s a really big question. It goes to some of the core of the issue. It’s that ability of Chinese models to basically challenge frontier models, not just being 6, 12 months late, but being 6 weeks late. Basically, no gap. Some will say that, yes, but OpenAI and Anthropic have even better models that are not shared and stuff. Yes, sure. But maybe the Chinese have the same models that they are not sharing right now. We don’t know. What is clear is that one is that open weight, as you said, two, there is a question of how it is marketed in the sense of, can anyone use these weights? Is there a license to use them? Yes, what we can see is that, for instance, typically there is a license for some of the biggest Chinese open-weight models you have to abide with. You might have a need for a commercial license if you are acting as a company leveraging this model to provide AI-informed services. If you use it internally by yourself, you’re okay. If you use it internally for your own internal company needs, maybe you are okay if it’s not your main business to do AI work. Anything else, a much bigger corporate providing AI services and stuff, you will probably end up having to pay a fee to be able to provide services around this model. My point is that it’s not just 100% free. Some of the Chinese models are 100% free to use, MIT license, Apache 2.0 license. But the biggest ones with the biggest weight that are truly frontier typically have a different license if you want to scale these models, providing AI in front. That’s one thing to keep in mind. Nuno Maybe just to make a very quick point, because people are like, when you talk about open models, what does it mean right now? In the context of this episode, open models mostly will mean open-weight models. How do those differ from open source? Open weight means that you release the weights to the public, which means that anyone can download, fine-tune, and run the model on their own hardware. It doesn’t normally mean that you also have access to training data, training code, or a truly open license. That’s the distinction to open source. Open-weight doesn’t mean that. For example, we’ve talked about Meta’s Llama in the past, and we also discussed in the past that their license agreement does have restrictions, certain players can’t use it, et cetera. The open model definition and open weights are really open-weight models that we’re talking about here, and they are closer to freeware binaries than to Linux, for those who understand the difference between that. It’s binaries that you can use and then use your own weights on it versus actually I can change code on it. I’m not going to be able to change code on this. When we, for the purposes of this episode, talk about open, we mention open weight, just to clarify that point to everyone that’s listening right now. Bertrand Yes, that’s a great point. One of the only players, as far as I know, who is truly open source is actually NVIDIA with their Nemotron-3 models. They’re actually following a special license to achieve that. They provide you the data, they provide you all the processes and tools, so you can easily post-train. NVIDIA is a big, big exception. It’s a very interesting player, by the way. We might not talk much about it in this episode, but I think for intermediate-size models built in the US, where you have access to everything in the deployment, it’s a very interesting alternative and maybe one of the best choices if you are a US company or a big corporate, and you want something trusted. Another piece of the puzzle to clarify is that when you use open-weight, it means that you can run them by yourself, or you can use a US provider to run them. If we are talking about Chinese open-weight, you can use the APIs they provide, but then the service is running in China, they might have access to your data. But because it’s open weight, if you run it by yourself or if you use a third-party provider based in the US to run it, then there is no access to your data by China or Chinese players. I think that’s a pretty important gap to understand. It means that these models are actually very, very low risk from that perspective if you run them on your premises or in the US by a US player. I think that’s something to keep in mind. You can also fine-tune easily these models to make sure they will behave in a way that, for instance, is not going to represent the line of the Communist Party on some topics. There are ways to make these models more neutral in their output as well. There are a lot of ways to make good use of them. By default, they’re already very safe, but you can make them even more safe. I think that’s some things to keep in mind. But again, it depends ultimately on the license and what you’re authorized to do and some fees you might end up having to pay. Nuno Why did this matter so much? Immediately there was a reaction from the market because people are like, well, if there’s much better stuff out there that’s much more efficient than it’s open, then it might be that all the demand that we are taking into account, for example, for chipsets actually isn’t real. The Philadelphia Semiconductor Index fell into bear market territory. It went down by as much as 20% plus from the late June peak. The worst chip week since April 2025. Taiwan’s benchmark initially fell 6% plus, Japan’s 4%, TSMC dropped dramatically despite beating earnings and rising guidance. Basically, a huge amount of effect. Now, there’s a little bit the aftermath of this where apparently Moonshot ran out of GPU capacity. Maybe… Bertrand In just 48 hours. Nuno In 48 hours. Great for them, but at the same time, not great in the sense that maybe there was a misread by Wall Street of the Kimi effect, so to speak. Bertrand Completely. For me, that’s such a joke. It’s like, because you have an open source model, so what? I mean, you still need to run it. This is not a small one. 2.8 trillion parameters. Good luck running that in your garage, by the way. Nuno They misread supply, basically. Tough luck, right? All of that basically happens. Bertrand Maybe you want to talk about the Jevons paradox, because I think that’s a big part of the puzzle as well. Its one is they might not have the GPUs to run the inference on the model. They might have enough to build a model, but not enough these days to run inference, especially given how much with intelligent models, thinking models, you need way more inference than before. But on top of it, the cheaper you make it, the more you get to the Jevons paradox. Nuno Yes, Jevons paradox, for those who don’t know, is an economic term. It describes an economic phenomenon where technological improvements that increase the efficiency of a resource lead to an increase rather than a decrease in the total consumption of that resource. What that means is, for example, for chipsets, chipsets become so much better, and they are so much more efficient. You’re like, well, maybe normally in resource terms, that leads to decreased usage of that resource. But in this case, it actually leads to an increased use of that resource rather than a decrease. There’s more and more consumption of that resource. You need more and more chipsets because people actually need to do more and more stuff with it, although there are great efficiencies going into it. There’s the efficiency gain, there’s the cost reduction, and there’s the price-elasticity element to it. But basically, the adoption just continues going through the roof along the way. Bertrand In some ways, it’s like the price of energy. Coal went cheaper and cheaper, and people were asking the same question 150 years ago, now that it gets cheaper, there is not much money. No, no. Actually, what happens is that people find more and more use for coal. Homes are getting heated more. You have ships now using coal. You have manufacturing using coal. The cheaper it gets, the more use case you can develop, and therefore, you don’t need less of the stuff, you need more of the stuff. By going at scale to get more of the stuff, you also decrease price, making even more demand. It’s a very interesting phenomenon, but it’s not new. It is what happened for a while in the energy sector and some other sectors. Nuno We already started talking about the Chinese logic and what’s happening. Getting a little bit of a reality check on this. The Chinese models, and these are numbers from Open Router in July, Chinese models are at 46.4% of routed tokens and 35.7% for US origin. Again, more than a third of global AI usage now seems to be running on Chinese open models. This is significant, and it has a huge impact on the geopolitical scale of everything that’s happening. Also, the whole Chinese field is converging on open. Open seems to be a strategy, not just a nice thing that’s happening. It seems to be a Chinese strategy, so much so that you have players like Moonshot, DeepSeek, our old friends DeepSeek, Z.ai’s GLM 5.2, Minimax, and even Alibaba seems to be reversing and going open with Qwen. It feels to me this is becoming policy as well. Xi Jinping has personally endorsed the building of open-source AI, if it’s really open source, if it’s just open weight anyway, and this feels to be a jab at Washington, DC and the fact that the big closed models are coming from the US. This is now geopolitical 4D chess, right? We didn’t need this stuff. Bertrand To be clear, it’s the usual in tech. If you are not number one, you are number two, number three, your alternative is to go open source because that’s another angle that your competitor usually cannot follow without destroying its own business model. That has been the alternative for the past 20 years of most software projects. Here, what’s different is that it’s not the number one or number two player. It’s the US number one as a country, China number two as a country. That’s where it’s new. For me, what’s very interesting is the endorsement by Xi Jinping. I was waiting for something official, and it certainly didn’t disappoint. As you said, there was an immediate U-turn of Alibaba, who in the past… Nuno Surprisingly. Bertrand Yes, a little more like, “yes, we are going to close and stop open source. It was good while it lasted.” Just a few days ago, Qwen 3.8 Max was launched, and we are supposed to get the weight in a few days. We talk about the US administration policy and stuff. Yes, let’s not forget that in China there is similar stuff. Sometimes it’s totally invisible because you don’t see the directives, but they exist as much. Sometimes it’s more visible. Here it was quite visible. The difference in China is that if you don’t abide by the directive, on top of it, you might have to fear for your personal safety. It’s a different game, and that’s probably why the reaction is pretty quick, usually. That’s pretty interesting for me because it means that now you can bet for a while that China is going to play that game up to a point. I guess the point is if it’s truly frontier scale, you will have a special license that, yes, technically the weights are open, but you can not do everything you want with it. Two, you have a player like NVIDIA that I think will feel more pressure to provide even more high quality, larger models at scale going forward. Their largest Nemotron-3 Ultra model was, if I remember well, only around 500 billion parameters. I would not be surprised for NVIDIA to go into the two, three trillion range at some point. Because I think the US need a very clear US-born alternative open source. I think NVIDIA might be the best player for that. We will see if Meta goes back to open source. I think NVIDIA is one, very well positioned, but two, it’s also in their best interest. Because NVIDIA for now depends on just a few big hyperscalers as clients. If they can expand their clients to every S&P 500 companies, selling them directly hardware because now these companies can run a model made by NVIDIA, I think there is a very clear value proposition for NVIDIA to go in that space. Again, if you are number two, your differentiation, open source is often the answer. There is a true business as a business model for companies, because if it’s truly not just open weight, but open source, you can tweak it as much as you want, you can change it, you can change even the pre-training process. Because there is a lot of stuff you can do that really benefits you as a corporate, and you can reach a much better value by having more control on the model. Nuno We won’t spend a ton of time on it today, but like, again, if there’s a view that we are in a bubble, that the valuations cannot be sustained in chipsets, infrastructure platforms, applied AI, et cetera, today, this might be that beginning, where the valuations start being destroyed because you can’t keep a premium on just charging people for tokens and all that stuff if you have models that become more and more efficient and cheaper to use. Maybe just to close a little bit the geopolitical part of the discussion today, we won’t go into all the announcements from China because there were many, a lot of go back and forth with Alibaba by then. Xi Jinping made some announcements. You guys can check it online. Let’s move quickly to Washington’s reaction, which was from gating the US closed models to banning the Chinese open ones. There’s been as strong affirmations as one can get from the Office of Science and Technology Policy Director, Michael Kratzios, mentioning that they have information that Moonshot AI distilled Anthropic’s Fable. Basically, there’s been reverse engineering and stuff in the market. They’re basically copying. Bertrand I’m sorry to interrupt, but it feels like so much bullshit. It’s coming from Anthropic who has basically gotten access at scale to all the knowledge made by humanity, copyrighted or not. We’ll talk more about what they did with books. Then to claim after that that others cannot do to you what you did to everybody else. For me, it’s pretty big. It’s clearly unacceptable. The other piece is that everyone is doing distillation. It’s a very typical approach of every business model. You try other software when you are competing with somebody else. You try other datasets, you check what’s happening. It’s part of doing business for decades. Suddenly it’s not good for Anthropic. I personally have a lot of trouble to accept that. I think it’s totally unacceptable. The other piece of the puzzle will also go back. If these guys are so smart, if these guys have so much of the best model, why can’t they block by themselves distillation at scale? The only answer is that either they are morons, probably not, or they simply don’t want to because it’s going towards their business model. Suddenly, you book less revenues and stuff, or you put more friction, and therefore your customers don’t like it. Instead of doing it yourself, you ask the government to protect you, go out of business practice that is very typical. For me, it’s really, really, really not good. Sorry, we are going more in the opinion side, but I had to put that on the table. Nuno Yes, Fable went public finally again on July first. Question marks on whether distillation would only be possible from July first onwards or not. But a 15-day distillation to frontier, which is K3, launched on July 15th, would have been a Guinness World Record, as one of Moonshot employees actually mentioned. It’s very implausible and unlikely. Bertrand Or they shared the Mythos 5 with the wrong companies, who themselves shared with Chinese companies. We go back to maybe they didn’t have a good list. Again, it goes back to maybe they didn’t want to hurt their business model. Nuno Anyway, under the threat of sanctions, Moonshot, in any case, open-sourced the full K3 weights and technical reports. They open weighted it to become the largest open weight model in the world in terms of parameters. Beijing’s MOFCOM brands US threats as basically the US wanting to fundamentally control and be monopolistic around AI along the way. The administration bans Chinese hardware with an eye on the AI race, and Beijing warns of retaliation. That was July 27. Now we’re in a war between Beijing and DC. Bertrand Just to finish maybe on China, it’s important to know that they are building their own GPUs now. Huawei has pretty good, not to NVIDIA level, but pretty decent GPU hardware that they’re able to manufacture by themselves. A Chinese player of memory just got IPO’d a few days ago, CXMT. China is also developing their own memory. Again, not to the same level of quality that you can get from the West. But China is moving. It’s not just that they are building great models, it’s also that they are building GPUs and memory. That might be a few years late to the latest standards in the West, but there are definitely improvements. I also read, even on the tools to make manufacturing like ASML equivalent, there is definitely some work going on, and some improvements and some stuff will be visible. In some ways, the genie starts to get out of the bottle from the Chinese perspective. Nuno I’ll put a stick on the ground. I don’t think it’s a matter of if, it’s a matter of when will China surpass and have a lot of this tooling on their own side, and not just the software layer, not just the frontier models. I think it’s also going to be around infrastructure and platform. Good luck to everyone. Let’s see how the race continues. But it’s definitely this is a geopolitical thing right now. It’s definitely a race. The Escape Maybe moving to what happened in just 2 weeks or a week and a half. The escape, there was some jailbreaking going on, and the narrative on safety has totally switched. It’s not still significant enough that’s like, “Oh, we saw a nuclear plant going, whatever.” No. But still, it is significant. Hugging Face, the AI company, disclosed an intrusion, and it was driven end-to-end by an autonomous AI agent system at machine speed, running for days before detection. Now, this is where it gets really cool. OpenAI takes attribution on that. They initially said it was just a little bit, sorry. Then they said, actually, it was worse than that. “Oh, it broke out of an isolated sandbox.” “Oh, no, actually, it was more than that, and it went into other systems as well.” Bertrand Truly, the genie out of the bottle. Nuno No, but this is where it gets really cool, Bertrand, right? Because it actually, Hugging Face contained the intrusion by running a Chinese open-weight model, GLM 5.2. This is beautiful, right? Bertrand Yes. You know why? Because they couldn’t even run their own defense because both Anthropic and OpenAI would not let them access their latest models with the guardrails off. When they tried using it for defense, the latest from Anthropic, from ChatGPT, they would tell them, “No, this is too dangerous what you’re asking us to do.” Preventing an intrusion, helping defend you. No way we are going to do that. Nuno No. Let’s use the Chinese models on our infrastructure. Bertrand We have no choice but to use the Chinese models to run. More than that, we don’t let you use our models to defend yourself, but our not yet released models that run without guardrails, they can attack you. This is probably the most insane from that perspective. Nuno The Chinese models came to the rescue. Bertrand For me, that’s a perfect example because Hugging Face is a very visible company in AI in open source. But anybody who is not at that scale is not going to get some support from OpenAI or Anthropic when this happens. Maybe these guys won’t even recognize they did anything wrong. You will be left to defend by yourself because they won’t accept to support you. Because remember, if you want the better model that is able to defend you from cybersecurity perspective, no way. If you are not one of the few top 20 companies or so, as defined, you are left defenseless. Again, we are going back to opinion, but for me, it’s so shocking what’s happening right now. I’m very glad we have alternative open source to be able to defend ourselves because right now, good luck getting defense services if you are a smaller business and individuals, and you need support from Anthropic, OpenAI. Nuno Now, even self-described AI optimists are saying, “This is scary now.” Like Walter Isaacson, who wrote all the famous biography books. There’s now discussion around the AI Kill Switch Act, bipartisan thing that’s coming across from Texas and California, a potential bill that’s coming in. We’ll see if that works. Now let’s get an off-switch. I’m like, “Cool.” As if that’s going to solve the problem, because you have open-weight models on the other side catching up, right? Bertrand Yeah, sure. Bring in clueless politicians from Congress to solve our problems. Yes, sure. Nuno Anthropic came to the table, helped build and said they built some regulatory machine on their side, and now they’re getting bitten by it, and they’re part of the offending players in that market. Now there’s all this debate and all this discussion around open weight and around slowing down AI and et cetera, which is our next section. You wanted to say something, Bertrand. Tell us. Bertrand Don’t forget, because this advertisement for OpenAI was just too good. Our AI attacked some other companies, and not just one, but three, actually. Let’s not forget the progress. Great ads. Then I came and said, “You know what? AI also hacked businesses.” You’re not the only one hacking around with a crazy AI out of control. You’re not the only one. We want our advertising. For me, it was shocking that on one side, unreleased models that you let run wild. On the other hand, you have released models that you put crazy guardrails on top of it, so the defender are defenseless. I’ve never seen anything like it, and I really hope that there will be as little regulation as possible, quite frankly, to make sure anyone can defend themselves and have the best tool at their disposal, not just a few well-connected big corporates. This is really, really shocking. The Counterstrike and the Petition Nuno Now the empire strikes back, so this is counterstrike, the petitions. In several days, we have now a bunch of petitions. The first one was the open weights letter. Bertrand, do you want to explain to us what the open weights letter is? Bertrand Yeah. I think it was great. This was released by Jensen Huang, first ever post on X, 11 million views. Congrats, Jensen. Co-signed with Microsoft, Meta, c actually was probably the initiator of this letter. Very good letter saying, “Hey, we need open weight. This is not a joke. We need that. You cannot block open weight.” Because that’s the rumor we are getting that potentially open weight could get blocked. I think they are making the case, “You know what? Hey, we absolutely need that as an alternative. You cannot block it.” They can keep their closed models, but don’t force a closure of the open weight models. As I said before, it’s actually a great model for NVIDIA because NVIDIA doesn’t want, probably rightfully so, to be dependent on just a few frontier models, their best customers. They want a variety of customers. They have a big interest actually to defend open weight and to invest even more. They have great researchers, are a great company. If one company is about to do really kick-ass work, I think it’s them. They are defending. What’s great is that it’s not just them. It’s basically most of big tech in the US and outside the US, from a Linux Foundation to a Microsoft, the Palantir, an IBM, a Dell. It’s a who’s who of the industry except Anthropic. Anthropic didn’t sign that. I guess they hate open source so much. If I look at 20 years ago, it feels like Microsoft, after all, was very kind to open source. You remember what was said by Microsoft at the time. It’s clear there is one company against open source. OpenAI signed the letter. Honestly, I don’t know what to think. Do they really believe in it or was it just a way to show that they are not like Anthropic? I don’t know. But for the rest, I think it’s genuine because it’s actually in their best interest. I hope they will be heard. Then a second letter came, the Open Secure AI Alliance, NVIDIA-led and again, the big tech companies from Microsoft, IBM, Palo Alto Networks, Databricks, Palantir, all those, but not present, OpenAI, Anthropic, and Google. Here it’s to say, “Hey, we need a secure approach to AI. Open should be part of the equation.” guess what? The worst AI-caused security incident to date was actually caused by closed frontier models that were not even available to the public. While again, not providing you access to even the latest closed model for cybersecurity use case. Nuno I would highlight the NVIDIA open source NOOA framework, Apache 2.0 licensing agreement, Microsoft contributed the MDASH, SpaceX AI contributed Grok Build. Cool stuff. There’s some cool stuff happening around that. This is more than a letter. This is an alliance. Apparently, they’re contributing all this stuff, we’ll see. Yeah, cool stuff. Same day. Same day, Amodei has an answer, right? Bertrand Yeah, same day. They say, “We never advocated for a ban,” which, again, opinion on my side is entirely bullshit. This guy has been crying wolf against everybody else, and especially against open source. You can see him doing testimony in Congress against open source. I think they are doing everything they can behind the scene to block open source in the US or in the world if they could. I think, yeah, obscurity is not good safety. I’m a big fan of open source in general, and I’m also a big fan in AI. I think it’s now Anthropic, mostly against the rest of the world. I think OpenAI is mostly on their side, to be frank. They don’t want to acknowledge it so much, but they have shared interest, and they have shared probably position. Nuno Why would you? I don’t feel as strongly as you because I think Anthropic is a private company, right? The same thing with OpenAI. OpenAI, you could say it’s a nonprofit that has a for-profit. There’s still that complexity in there. Bertrand No, they can do what they want with their own product. But to block others is where I’m not okay. That’s the part I’m not okay. Nuno What Dario Amodei is proposing is more enforcement, right? He’s basically saying you need to do even tighter controls on advanced chips flowing to authoritarian states, enforcement against industrial-scale distillation, whatever that means, right? Bertrand Yeah, which he could do, but all by himself. He doesn’t need the government to do that. Nuno Mandatory safety testing for all sufficiently capable AI, open and closed, right? He’s basically saying, “Okay, I don’t agree with the open weight stuff effectively,” right? He’s just putting it under a different banner. “I agree with this extra regulation.” then obviously, David Sacks responded and say, “Hey, it’s like, bans don’t work for weights. Why do they work for chips?” It’s like, magically, chips are more controllable and bannable. Whatever that is. Then our friend Mark Zuckerberg, just to be clear, goes on the other side as well, because he also has to have a view. He has to have a view that is the rebuttal of both of the other guys. Bertrand I feel he’s a bit flip-flopping because he was very pro open source 2 years ago, and the latest Meta models went closed source. Now I think he’s back open source. I don’t think he has a very strong spine on the topic, but it’s good to see that he’s not a doomer. That for me is great. He’s showing how AI can be a source for progress, a source for entrepreneurship, source for freedom. I think that’s very exciting to hear that. We need to hear more of it. By the way, that’s not what you hear in China, for instance. AI is very positive in China. It’s in the US with the doomers that you hear this discourse, and people get worried as a result. I’m glad that he was pushing for a more positive vision and for support of open weight, open source initiatives. But let’s see what they really truly open weight going forward. Nuno But that’s been his position because I guess he’s standing behind. He thinks open weight is going to be the best way to compete, right? Bertrand Yeah, but he closed his latest model, so let’s see. Nuno Yeah, so it’s flip-flopping, as you’re saying. Then we see the latest petition from last week. Bertrand The true Empire striking back. Nuno Yeah, the true Empire striking back as of late last week. Maybe this is Return of the Jedi, where we discover the father, “I’m your father, Luke.” That’s the pacing petition. The pacing petition is we need to pace AI. There you have initially employees from OpenAI and Anthropic that circulate this petition. Actually, Dario did sign this petition originally. It wasn’t signed originally by Anthropic, but by him. But you’ve heard that now Anthropic and OpenAI as companies have also signed this petition, right? Bertrand I think they have signed as companies now. It started mostly by Anthropic researchers with some OpenAI researcher and a tiny part from other companies. But it was mostly Anthropic internally led, at least potentially internally. Maybe it was controlled by Anthropic all along, I don’t know. But it started officially as Anthropic employee-led letter. Nuno What does this letter actually say? Is Anthropic and OpenAI, are they willing to slow down themselves? Or are they asking President Trump to go around the world and tell President Xi that he needs to slow down and ask his guys to slow down? What’s the play of this letter? Bertrand It’s crazy, but for me if you want to slow down yourself. Do whatever you want. Don’t force others. Don’t use the power of the government to control others. Of course, it’s easy to push others to slow down when you are yourself at the very top. You have most money, most resource. You know you are going to win any regulatory framework because that’s how it works with this type of framework. It’s purely self-interested. You are probably not thinking well about these topics. If you truly think it’s a good idea, from a personal perspective, you are well instrumentalized if you sign this sort of stuff, because at the end of the day, they would be the winners. I certainly, personally, don’t want a company dictate what is my future in AI as an individual, as a business person. I don’t want them to control me. I want competition. I don’t want them to unfairly control AI because they managed to do some regulatory capture. I feel that’s exactly their game plan. These guys believe in their stuff, and they want the regulator to end up being the one deciding for us. Sorry, we go back again on the opinion piece, but it’s tough not to share an opinion on this topic because it’s, from my perspective, very scary. Nuno I think this is a push to further regulation, not less. All these letters and alliances, this is definitely a push for more regulation. In that environment, just to be very honest with you, we’ll talk about the investor impact in just a bit, et cetera. But in that environment, again, China has a huge advantage. In that environment, if it’s all captured in regulation capture so soon in this battle where OpenAI and Anthropic have an advantage in the US, et cetera, I’m like, what happens to all the other frontier labs and all the other players that are coming around? Bertrand What’s crazy is to even think that, yeah, maybe you can regulate capture in the US. But then how do you do that to Europe? How do you do that to China? Europe probably will always welcome regulatory capture because they love regulations. But China is going to build to their advantage to the max. They are not crazy. They are smart on that perspective, they won’t accept this type of, quite frankly, dimwit argument, or you can call it regulatory capture. We’ll see. But for me, this makes no sense from a global competition perspective. This can make some sense from capturing the revenue in the US market. But then that means you are going to destroy the US AI environment compared to China. That is not acceptable. That also means that you are going to destroy our freedom as individuals, as business owners to develop and live in a business world that ultimately is controlled by one or two business companies that didn’t win the marketplace through their own business success, but won it through regulations. That for me is really not acceptable. Interlude — The Low-Background Books Nuno Now, maybe for an interlude, and we have to cue in the music, imagine like Severance music, like hallway or a bit of a palate cleanser from all the policy stuff that we’ve been talking about, all this policy heaviness. Let’s move to another kind of heaviness, one of your favorite topics, which you, Bertrand, discovered, I had no clue this was going on, around books and around Anthropic. Bertrand It’s so horrible. From a company that keeps presenting themselves as the adults in the room, the careful ones, the ones that know better than you about what to do in this complex AI and dangerous world. What we discover is that actually all along, they were buying and destroying books. They will buy books, scan them, destroy them, all of them. They will do that with any books, including rare books. Of course, this was not supposed to come to the public’s attention. This was one of these top secret projects, but obviously it came out. Yes, they were scanning books, millions of them, including rare books, and they didn’t care about destroying them at the end of the process. Because from a regulatory perspective, if you destroy the books, it’s not considered a copyright infringement, apparently. This is coming on the back of some judgment a few years ago that were showing that it’s okay for you as a corporate to scan and use the result if you don’t keep a copy of the book. It’s one of these crazy regulations happening based on a single judgment that push you to do. For me, it’s like, you know this book from decades ago, Fahrenheit 471? We’re talking about book burning. It’s book destroying, crunching. It’s so shocking. Nuno There are two things, right? First, the legal strategy, which is what you’re saying, because by purchasing a physical copy and converting it into one private digital copy and discarding the original, Anthropic pursued this cleaner legal argument for fair use copyright compliance. As you said, there was a federal judgment at some point on this. The other reason is actually operational. If you disassemble the book, and you feed loose pages, it’s much faster to scan books. You are destroying the book effectively anyway operationally. I think to your point, probably this came from a legal standpoint, not just the operational one. But even from an operational standpoint, it does make sense that they would have disassembled the book. Bertrand But some people have shown you can go very fast without destroying the book. It’s really not so critical. Two, you could make an exception if the book is rare. For that 1% of book that is rare, I’m not going to have this approach. I’m going to have another approach. But for that, you will have to care about books and not just care about building AI. Nuno This is the episode, as you guys have heard by now, that we’re trying to spit stuff at Anthropic. Bertrand To go back this is the same company saying, “Hey, guys, it’s bad to distillate my work. I’m the one scanning book at scale without asking author permission, without asking publisher permission, to be clear.” Nuno But just to be clear, Bertrand, we’re pissed off at everyone. We’re pissed off at Anthropic, we’re pissed of at OpenAI as well, right? We’re just pissed off in general at this moment. Bertrand At this stage for me, the more clear-cut company that is in the wrong is, from my perspective, at least, is Anthropic. OpenAI might be a fast follower, but I will say so far, they tried to be a bit more. Nuno But at this pace, Bertrand, who knows? Maybe next week we’ll be more pissed off at OpenAI. Something will come out. This episode is a mix of tragicomedy, like a Greek tragedy with some comedy in the middle or the other way around. It’s a slapstick thing that will end up in tragedy. I’m not sure. The Investor Reckoning Anyway, maybe switching to our final act, which is the investor perspective. What does this mean for investors like ourselves? There’s a lot of things going on. There’s the debate around the IPOs of Anthropic and OpenAI, which now, with all this uncertainty, might be under significant weight. There’s a lot of other discussions that we browsed through that there’s potential IPOs going forward on companies like the Moonshot AI company actually IPO-ing in the next 6 months as well. It’s very unclear what the IPO landscape looks like. Bertrand There’s been a lot of Chinese IPOs, actually, when you look at what’s happened in the past few months. Nuno Anthropic, OpenAI as potential IPOs, there’s all this question marks now. When will that happen? How will it factor in? All that’s happening around regulation as regulation is moving at the speed of light, which is for once something that’s very different than what we’ve seen before. There’s obviously SpaceX AI, which is already taking into account that price. It’s already a public company in there, and it’s under SpaceX, which is now a public company. Obviously, that’s already being factored in some ways. Bertrand Yeah. SpaceX AI has been very smart to acquire Cursor. It was a very smart move because Cursor is one of the leading companies in terms of automated code source development with AI. They had great models on their own. They’re bringing development data to SpaceX AI Grok. I think it was a great move. Nuno We have now people like Google delaying Gemini 3.5 Pro in terms of launch window. There’s stuff actually happening in the market where things are taking their own path. There’s uncertainty commercially, there’s uncertainty at regulation level. You have new players that have come out of nowhere that are making all these waves like Moonshot. We have all these… We had calculated probably a month and a half, 2 months ago, there had been 67 new frontier labs funded. All of these, we haven’t seen any much coming out of them. When some of this stuff starts coming out, will that also create disruptions in this market? Who knows? Bertrand Look at Thinking Machines, for instance. Thinking Machines led by the previous CTO of OpenAI, they released some pretty interesting open source models, actually. Very good quality for a first launch. Now it looks funny to say, but nearly on par with the top Chinese open source models. Nuno We have several investments in the space. humans& has made some recent announcements, which is quite interesting as well. We’ll see what actually happens in the market, but even more disruption probably will come in actual products in a form of product and commercial, on top of all the geopolitical mess that we discussed through the entire episode. If you’re an investor, how the hell do you underwrite an investment right now in early stage, mid-stage, late stage, et cetera? I think my answer is very carefully is how you underwrite it. Bertrand On your advice of being very careful to underwrite it, let’s not forget what happened to our boy wonder, Leopold Aschenbrenner of Situational Awareness. I guess he didn’t listen to you in terms of being careful because part of the instability in the stock market was actually coming from his hedge fund. These guys were leveraged 3, 4x going after the hottest of the hottest AI stocks, and margin calls, and all their public investment is gone just to answer their margin calls. I think it’s clear that the AI bet is… Personally, I’m very excited, and I think it’s the future, and you need to spend time and think about and invest in it. At the same time, it’s a bet that is not an easy one to follow. We go from GPUs to memories to equipments to power generation. All of this is not transitioning in an easy, organized manner. It would be boom and bust going there. He’s probably one of the first big-scale fatalities. The other big-scale fatality was the stock market in Korea, plunging 40% in a month. Definitely, all of that we discussed about was, on the background, you had the stock market going up and down pretty crazily the past few weeks. Nuno Everyone’s being affected. Everyone, you have your 401(k), you have your pension fund dependent on these equity stocks. Everyone’s seeing the effects of this volatility right now very aggressively. We do wish Leopold… Hopefully he’s on honeymoon right now because he got married, I think, this weekend. Hopefully there will be… Bertrand To none less than an Anthropic Chief of Staff. Nuno His wife is the Chief of Staff of Dario, is that it? Bertrand To Dario, yes, as far as I unders
SummaryIn this episode of the Blue Security Podcast, hosts Andy and Adam delve into the complexities of AI in cybersecurity, focusing on the adoption rates and understanding of various AI technologies. They discuss the differences between large language models (LLMs) and small language models (SLMs), the importance of APIs, and the role of harnesses and agents in executing AI tasks. The conversation highlights the need for clarity in terminology and the varying levels of AI adoption across different regions and industries. In this episode, the hosts delve into the intricacies of AI agents, skills, and the MCP (Model-Connect-Protocol) as a universal connector for AI tools. They discuss the importance of understanding the attack surface created by these integrations and the role of Retrieval Augmented Generation (RAG) in enhancing AI accuracy. The conversation emphasizes the need for governance and best practices in deploying AI solutions responsibly while recognizing the significant productivity gains they can offer.----------------------------------------------------YouTube Video Link: https://youtu.be/31WI5iFFLog----------------------------------------------------Documentation: https://www.sans.org/press/announcements/ai-use-cybersecurity-jumped-from-50-to-78-year-ai-related-failures-rose-sharply-too-new-sans-institute-survey-reveals-governance-gaphttps://www.digitalapplied.com/blog/mcp-adoption-statistics-2026-model-context-protocolhttps://learn.microsoft.com/en-us/copilot/security/plugin-mcphttps://www.zscaler.com/es/resources/white-papers/zscaler-ai-guard-detectors-inline-protection-for-ai.pdf----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
For decades, interacting with a business online has meant learning how that business wants you to interact with it. Open the website. Find the right menu. Fill out the form. Navigate multiple screens. FOBI AI believes that model is beginning to change.The Company has launched AgenticBrain, an agentic conversational platform designed to let customers interact with businesses using natural language through familiar messaging environments including WhatsApp, iMessage, Telegram and other supported platforms. Instead of asking customers to figure out where to click, AgenticBrain is designed to understand what they want and connect that request to the company's existing systems. It is also the latest component of the FOBI Flywheel, connecting FORTRESS, FIXYR and AltID 3.0 into what management is building as one connected enterprise technology ecosystem.WHAT YOU NEED TO KNOWAPI Integration: AgenticBrain is designed to connect with existing enterprise APIs rather than requiring companies to replace their underlying infrastructure. Management says integration timelines can potentially be measured in hours or days rather than months.More Than a Chatbot: The platform is designed not simply to answer questions, but to access authorized systems, retrieve information and complete permitted actions.Identity and Authentication: AltID 3.0 is designed to provide identity, authentication and trust within the broader system.Flywheel Opportunity: An AgenticBrain deployment can potentially create additional opportunities for FORTRESS, FIXYR, AltID 3.0 and eventually FOBI's planned next generation wallet.Enterprise Licensing Focus: CEO Rob Anson identified licensing as what management sees as its biggest path to scale, with channel partner enablement expected to play an important role in reaching the enterprise market.FROM CLICKING TO ASKINGThe easiest way to understand AgenticBrain is through a simple example. Today, changing a flight can require opening an airline app, logging in, finding the booking and navigating multiple screens. AgenticBrain is designed around a different experience. A customer could simply say, “Reschedule my flight to next Thursday.” The company's systems can provide the available options, identity and authorization can potentially be confirmed, and the appropriate action can then potentially be completed through the same conversation.This is also where FOBI's broader Flywheel becomes easier to visualize. FORTRESS provides sovereign enterprise intelligence. FIXYR provides communication and orchestration. AltID 3.0 provides identity, authentication and trust. AgenticBrain provides the conversational layer connecting customers to those capabilities, while FOBI's planned next generation wallet is intended to eventually provide the user layer for tickets, credentials, memberships and other digital assets.What matters for shareholders is that these are no longer being presented as separate technology launches. They are increasingly being positioned as parts of one connected system.BUILT FOR PEOPLE AND AI AGENTSManagement believes the opportunity extends beyond people talking directly to businesses. As consumers increasingly delegate tasks to personal AI agents, those agents will also need ways to interact with businesses.INVESTOR TAKEAWAYAgenticBrain gives investors one of the clearest examples yet of how FOBI intends its recent technology launches to work together. The platform is designed for enterprises across travel, hospitality, ticketing, retail, financial services, telecommunications, healthcare, utilities and government services, with potential recurring revenue opportunities including enterprise licensing, deployments, conversational usage, integrations and transaction enabled services.For shareholders, the question is increasingly straightforward: can FOBI turn this connected technology ecosystem into enterprise customers and recurring revenue?
Andrew welcomes Morten Mynster back to the PowerShell Podcast to dig into the projects he's been building around Microsoft Graph, Entra, least privilege, and authentication. Morten walks through Least Privileged Entra, a module that uses activity logs to identify users who may have more permissions than they actually need, and MS Graph Proxy, which lets developers work with mocked Microsoft Graph data locally without connecting to a live tenant. They also get into managed identities, the rougher corners of Microsoft 365 APIs, testing Graph-based projects in CI/CD pipelines, and how contributing to open source can solve real problems while creating unexpected career opportunities. Key Takeaways: · Least privilege is easier when you can see what people actually use. Morten's Least Privileged Entra module compares assigned Entra roles with activity data to identify permissions that may be unnecessary and suggest more limited alternatives. The goal is to give admins something actionable rather than simply reporting that a configuration passed or failed. · You don't always need a live Microsoft 365 tenant to develop against Microsoft Graph. MS Graph Proxy intercepts Graph requests and responds with mocked data, allowing developers to test scripts and modules locally, offline, or inside CI/CD pipelines. It can also identify the minimum Graph permissions associated with the endpoints an application uses. · Sharing your work can have benefits far beyond the project itself. Morten credits his Least Privileged MS Graph project with helping him land his current job. His approach is simple: solve a real problem, share the solution, contribute where you can, and let other people build on what you've learned. Guest Bio: Morten Mynster is an IT professional and open source contributor focused on Microsoft Entra, Microsoft Graph, security, and least privilege. His projects include LeastPrivilegedMSGraph, LeastPrivilegedEntra, and MSGraphProxy, and he regularly contributes to community projects and discussions around Microsoft 365 security and PowerShell. Resource Links: https://github.com/Mynster9361/Least_Privileged_MSGraph https://github.com/Mynster9361/LeastPrivilegedEntra https://github.com/Mynster9361/msgraphProxy https://github.com/FriedrichWeinmann/EntraAuth The PowerShell Podcast on YouTube: https://youtu.be/cB_QE1HvAyI
Don’t get left behind in the AI shift! Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ In this critical conversation, Vince Menzione sits down with Shannon Sigmon, Marc Harpster, and Jeff Mesnik to uncover how the rapid pace of change in the Google Cloud Marketplace and AI agent integration is forcing organizations to completely rethink their go-to-market strategies. They break down why traditional three-year business plans are dead, replacing them with agile 100-day sprints to keep up with the shifting ecosystem. The panel reveals that leveraging your Adaptability Quotient (AQ) and turning data patterns into actionable co-sell motions are the only ways to survive the upcoming “agent age” and maintain a competitive edge. https://youtu.be/xIaABKU1jmM Key Takeaways Consistent messaging is required to gather actionable data and build trust with channel partners. Three-to-five-year business plans are obsolete, and leaders must now operate in 100-day sprints to keep pace with hyperscaler changes. Google Cloud Marketplace uniquely supports channel partners by allowing them to own the customer relationship and recognize top-line revenue. The rise of AI agents is shifting discovery away from traditional SEO, requiring ISVs to adapt how they provide access to their tools. Creating interactive content variations from a single asset helps train AI agents to discover and prioritize your solutions. Despite rapid digital transformation, human connection remains the ultimate deciding factor in enterprise software purchases. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags Adaptability Quotient, Google Cloud Marketplace, agentic age, co-sell motion, digital sales hub, private offers, propensity to buy, AI pattern analysis, hyperscaler CRM, interactive trivia content, product-led discovery. Transcript Shannon – Marc – Jeff AUDIO Podcast [00:00:00] Vince Menzione: That becomes the core of your data analysis because if you’re not submitting consistent content and submit, you know, consistent information, then you’re not gonna get information back. [00:00:13] Vince Menzione: You can feel it happening. The ecosystem is shifting beneath us. The way Hyperscalers are partnering, how AI is remaking the channel and what it means to win in 2026. [00:00:25] Vince Menzione: Welcome to the Ultimate Partner [00:00:26] Vince Menzione: Podcast. I’m Vince Menzione your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the [00:00:46] Vince Menzione: strategy. [00:00:47] Vince Menzione: It is the strategy because being in the room changes everything. Let’s start. [00:00:57] ——-: We have another incredible group of leaders coming up here and, uh, and friends of ultimate partner and, uh, Susan, do you need me for, okay, good. Come on up. So I’m gonna, I’m gonna invite you up and then have you each. Introduce yourself, uh, to this conversation. Shannon, it has been a great to see you. Yeah, great friend. [00:01:18] ——-: Been in, it was in Boca. Mark. Great to have you. Good to see you, sir. Jeff, great to have you. Uh, this is incredible. I’m, I’m excited for this conversation. So, uh, yeah, we talked about aq. We talked a little bit about AQ in this last session. Don’t, didn’t we? Yeah. [00:01:34] Shannon Sigmon: A little. [00:01:34] Vince Menzione: Why don’t we go, why don’t we have you, I wanna have you each introduce yourself, your role, your company mission, and, and, and everything here. [00:01:40] Vince Menzione: So why don’t we start with Shannon. [00:01:41] Shannon Sigmon: Um, hey, thank you Vince for having us again, um, here in Bellevue. It’s been great to meet with everybody and see some old friends. Uh, I’m at Software One, so Shannon Sigman, um, based on the East Coast, but I work at Software One I’m responsible for. Um, in my sales role, I’m responsible for our channel and digital sales organization in North America. [00:02:00] Shannon Sigmon: And then I also have, um, responsibility supporting Regina Ma and Freddie and our leadership team as the chief of staff. Um, and we’re focused software one, if you haven’t worked with us before, we’re focused on helping, um, helping our customers and partners deliver real financial impact in their business so they can afford some of the, the cool to do some of the cool stuff you were talking about in the earlier session. [00:02:20] Shannon Sigmon: And it’s, for us, it’s really about coming in on the front end and helping, um, our customers and our partners understand what they’re doing in their software stack, their cloud stack, and then how to, um, optimize that, rationalize the strategy and, and the implementation of of solutions. [00:02:36] Vince Menzione: And a global leader in the marketplace in [00:02:38] Shannon Sigmon: That’s right. [00:02:39] Shannon Sigmon: The, the number one Microsofts, um, we [00:02:41] Vince Menzione: used to say re reseller or ls. We used to all these different, [00:02:44] Shannon Sigmon: yeah. We, um, it’s funny, I was speaking last night. We fall into the scale solution provider. We’re d with Google and AWS. But, um, we operate very differently on the, on the North America market as a more of a boutique, uh, personalized experience than what a traditional dity is. [00:02:59] Shannon Sigmon: I’m less about the transaction and more about the impact and the, the outcomes and, and helping partners with their go-to-market strategy. [00:03:07] ——-: Awesome. Yeah. And sitting next to you, Marc I’ll let you introduce yourself ’cause this kind of ties in very nicely in [00:03:13] Marc Harpster: Yeah. [00:03:13] ——-: In terms of the work you do. [00:03:14] Marc Harpster: Uh, thanks Vince. [00:03:15] Marc Harpster: Uh, hi everyone. I’m Mark Harpster. I am part of the Google Cloud Marketplace organization. So, uh, guy who you just heard from on the last panel is my boss. Uh, I run strategic initiatives within the marketplace team. So this includes our channel program. Uh, so everyone who is. Uh, the partners who like to resell, uh, ISV software out our marketplace. [00:03:38] Marc Harpster: Uh, I have a team who works with, uh, all of you, and that includes distribution. Uh, and uh, then I also, we run, um, the, some of our, like the go to market strategic initiatives. So we have a. Uh, customer credit program that ISVs can take advantage of to help incentivize deals going through marketplace, uh, propensity to buy, uh, data that we can share. [00:04:02] Marc Harpster: Mm-hmm. Uh, a number of different programs along those lines. Uh, basically, uh, we’re we’re helping. You know, customers find the solutions that they want to buy and helping them buy from the who they wanna buy from. [00:04:14] ——-: Yeah. And you were out early. I mean, you’ve been in the, the, I I feel like Google was leaned in very early on the channel. [00:04:20] Marc Harpster: Yeah. [00:04:20] ——-: And it was a couple years now, right? [00:04:22] Marc Harpster: Yeah. I joined Google about two and a half years ago. Uh, I was, you know, at, at another, worked for another cloud marketplace before that. So I’ve, I’ve been in the marketplace space for, uh, over a decade now. Uh, I’m really passionate about it. And with the, to touch on your point, Vince, I think the one key advantage of Google is, you know, within the, our channel partners, uh, we have a huge, uh, partner network, uh, of, of, you know, channel resellers and, uh, system integrators. [00:04:52] Marc Harpster: Uh, and we actively want those channel partners to, you know, own the customer relationship, including all of the billing. Uh, channel partners tend to love this because we’re the only cloud marketplace that really supports sort of the ability to recognize top line revenue for the channel partners. Uh, and so that’s been a real, uh, you know, distinguishing factor. [00:05:11] Marc Harpster: And one thing I’m really excited about within our marketplace. [00:05:14] Vince Menzione: You got it right. Awesome, Jeff. Good to see you, sir. [00:05:17] Vince Menzione: Good to see you. Thank you. Thank you for having [00:05:19] Jeff Mesnik: me. Good to have you. [00:05:20] Vince Menzione: Yeah. [00:05:21] Vince Menzione: Tell us a little bit about your organization, about content amx. [00:05:24] Jeff Mesnik: Well, I’m honored to be here with, uh, these two. Yeah. [00:05:27] Jeff Mesnik: You know, and, and Vince obviously [00:05:29] Vince Menzione: Thank you. [00:05:29] Jeff Mesnik: But you know, our organization is really about coming back, and I’m not trying to plug tackle by you saying this, but we’re doing the blocking and tackling for organizations another. [00:05:40] Vince Menzione: That’s why I named the tackle. [00:05:41] Jeff Mesnik: Yeah, I know. It’s, it’s, it’s part of my every conversation now and I have to think about it, but we basically believe in the idea that trust is starting by consistency and expectation. [00:05:55] Jeff Mesnik: So a few years ago I was listening to, um, an event where Tim Couch and, um, Michelle Ragusa, McBain were talking and they said, partners respond to. You meeting and greet, you know, exceeding expectations. So one of those expectations should be consistent messaging to them and consistent messaging for them to send out to their customers. [00:06:15] Jeff Mesnik: And then the next step is that becomes the core of your data analysis, because if you’re not submitting consistent content and submit, you know, consistent information, then you’re not gonna get information back. So that information back then turns into sales opportunities because you’re not looking at. [00:06:34] Jeff Mesnik: Clicks or having a marketing person say, Hey, you know, this person just stopped by my booth. Or Hey, they downloaded a white paper. It’s patterns using AI to analyze and address and look at patterns and turn those patterns into actions. So, you know, we’ve been talking Shannon and Mark and I about those patterns and how to. [00:06:55] Jeff Mesnik: Respond to them to maybe do a co-sell motion if that’s what’s necessary, or to make sure that the partner is ready for the next step. We’re doing a program for Microsoft. Whoops. So we’re doing a program for Microsoft. Do I still have it? [00:07:11] Marc Harpster: Yeah, you’re [00:07:11] Marc Harpster: good. Um, that en enables the partners to learn about AI and then we can understand where they are in their AI path. [00:07:22] Vince Menzione: Awesome. So Shannon, uh, Regina, man. Freddy. Yeah. Also a great friend of, ultimate Partner. Been on stage, was on stage here a couple years ago. We talked about adaptability quotient. Uh, we, we took that, we took that back. Now we use it all the time. And I, you know, I want, I wanna cover with you what that means to your organization. [00:07:40] Vince Menzione: A lot has changed. [00:07:41] Shannon Sigmon: Yes. Still. Yeah. [00:07:42] Vince Menzione: Still changed. Yeah. And you work with multiple hyperscalers, so take us through like, how, how, how does. What is now Software One used to be crayon, now it’s software one Crayon, or it’s just software one. Now let’s talk about all the change and how you’re absorbing it, and then how are you taking it to market and being successful. [00:08:00] Shannon Sigmon: Yeah, it’s interesting. We spent time, gosh, two, three years ago now, um, talking about adaptability being the next superpower [00:08:07] Vince Menzione: Yeah. [00:08:07] Shannon Sigmon: Uh, of workforce, right? That it wasn’t just about having the experience, but with the rate at which. The pace at which change was happening, having, uh, uh, employees foundationally focused on curiosity and learning and con constant development. [00:08:23] Shannon Sigmon: Um, and my goodness, uh, this year alone, right? We we’re. We, it’s hard to keep up. Right? So this idea of creating a full three to five year plan, we’re, we’re creating sprints plans. Yes. Right. And sprint strategies. And so I do think when we look at our integration of the two companies as Crayon and Software one come together globally, um, that has been a critical mass. [00:08:47] Shannon Sigmon: Uh, issue for us to overcome, but also to get our employee base one feeling comfortable with the pace of change because it can, for those people who are, are not change agents, it can be really uncomfortable and, and stress inducing. Um, but also giving them space to, to try things, fail fast and learn from it. [00:09:07] Shannon Sigmon: And. Um, it, it, it infuses that adaptability quotient, infuses entrepreneurial spirit within the organization a bit. Um, but it has become, it is the superpower of the next generation is how, how quickly can you adapt to change, but not just adapt to it as it’s coming, but stay ahead of it, um, and stay ahead of what’s happening in the industry through communities like this so that you’re skating towards the puck, not waiting for the puck to hit you in between the eyeballs. [00:09:34] Vince Menzione: Yeah. How long are these sprint. I can’t even imagine doing a three-year plan any, any longer. Right. [00:09:39] Shannon Sigmon: I mean, we, there’s some intentionality behind it for us. So my, um, partner in crime, Sean, uh, er, who leads our rev ops, uh, function in North America, we, we sprint pretty fast. So we do leadership offsite every three months. [00:09:52] Shannon Sigmon: Um, and it’s not like it does, we don’t sit in a meeting conference room like this quite often. There’s. We’re running an Airbnb and we’re living and breathing and talking and tumbling rocks together in a real productive way. Um, and it forces our leadership team to not just work at an operational level, but like really down in the trenches at a personal level together to solve problems for our people. [00:10:15] Shannon Sigmon: For our culture, for our business future. And I think that has helped us stay ahead of what’s coming at us from both the hyperscaler community, from the economy, uh, and global, some of the global trends that we’re seeing. It helps us stay ahead of that. And I mean, as leaders, we can, we can conflict and, and, uh, debate in a closed, safe space to get to work through some of that. [00:10:38] Vince Menzione: Mark, what are you seeing? I mean, we were just talking to D about all the significant advances Yeah. In your organization and you work with all these amazing top resellers in the industry. Mm-hmm. Uh, Tony Voya is an old friend of mine’s. Been on the podcast a hundred times. Yeah. Ran another organization’s one of [00:10:54] Marc Harpster: Yeah. [00:10:54] Vince Menzione: Also one of the large, yeah. [00:10:57] Marc Harpster: Yeah. Tony’s great. Um, it’s interesting you mentioned working in sprints. We, we ourselves are even adapting into sort of the notion of like. What are you doing in the next a hundred days? [00:11:07] Vince Menzione: Mm-hmm. [00:11:07] Marc Harpster: Right? You can’t, that six months, a year is too long. It’s too long. So, you know, that’s just internally, uh, within Google Cloud. [00:11:14] Marc Harpster: But, uh, our, you know, I see this across, if, if we go back a decade ago, uh, you know, ISVs had to learn how to change to, to just to, to list a PayGo product in a marketplace. [00:11:28] Vince Menzione: Yeah. Yeah. [00:11:28] Marc Harpster: Right. A whole new business model. Uh, and then, then we. Introduced the notion of like, Hey, it doesn’t have to just be pay, right? [00:11:36] Marc Harpster: It’s, yeah. Now we’re going to introduce the concept of a private offer, right? And how does that work? Right? And so you heard a lot of, uh, insights in the last panel about some of the changes you need to make to your sales organization and how do you adapt to that, right? And then there’s the change of like, well, what about the channel partners? [00:11:52] Marc Harpster: Right? Yeah. So every channel partner. Uh, in that I’ve been working with for the last eight, nine years, make the pivot to like, oh, we still have a place here. We have all these customer relationships and connections and hey, we can sell these things too. Right? But they have to figure out how the channel private offers feature works, right? [00:12:10] Marc Harpster: Um, distribution. Right. Then suddenly we’re, we’re, we’re bringing distributors back into the cloud marketplace world, you know, and they’re actually pushing us for like brand new things, like, Hey, we wanna, we want more APIs, right? And so I, I’ve seen. The entire community of partners. Be, be able to adapt to meet the customer where they are. [00:12:30] Marc Harpster: Right. And, and take advantage of the customer benefits of buying through marketplaces. And so now we’ve got another, another moment of great change, right? As we head kind of into the agent age. And every one of us is gonna have to, to be adaptable again. Yeah. And I think the notion of like. Whatcha gonna do in the next a hundred days? [00:12:47] Marc Harpster: Or like, what, what, what is the first thing that we, what are our priorities? How do we focus on, this is going to be key, right? ISVs need to, to understand, hey, how do, how do agents change the way we, uh, allow customers to access our tools and our software? Right? Uh, the channel needs to then understand like, well, what are we reselling agents? [00:13:07] Marc Harpster: Are we creating our own agents? Yes. Like, how does this change us? Right? And so it’s across the board, uh, and it’s gonna be a really. Fun, you know, rest next few months. [00:13:16] Vince Menzione: What are you seeing with regards to that? I was thinking about that as well. Like does the ISV create the agent or does the, the, the, the channel partner, the reseller, the Gs, I mean the GSIs [00:13:25] Marc Harpster: are involved here as well. [00:13:26] Marc Harpster: Certainly are, are, are, you know, I think DI mentioned this in the last panel. They, they’re, they’re creating agents, uh, you know, all over the place right now. But a lot of ISVs are as well. They recognize that they need to adapt. Right. And so I think we’re getting. Um, we’re getting really good participation, uh, from. [00:13:46] Marc Harpster: All sorts of partners and even, you know, the, the kind of traditional, uh, like what I call a reseller, they’re starting to figure it out as well. Right? Like, do I need to list my own agent? How do I do that? Right. And they’re coming to us seeking some guidance right now. Yeah. Are [00:14:01] Vince Menzione: you? [00:14:01] Shannon Sigmon: Yeah, I mean, I think we look at ourselves as customers. [00:14:03] Shannon Sigmon: You already heard that yesterday. Yeah. A lot on, from some of the Microsoft community. Um, we we’re starting to see pockets and um, we’re, we’re actually running our own company-wide hackathon in June. Um, specifically to intersect with copilot, Gemini, Claude, how do we get our teams on the ground level? Um, I loved what was said earlier, but it’s gotta be a, a bottoms up, tops down approach. [00:14:28] Shannon Sigmon: And the good thing for us is we have leadership support at the top down on, on the tinkering, on the learning, on the implementation. And now we’re working to build the skillset from the bottom up so that we can take some of those use cases to our customers and our partners and, and start to learn and adopt along the way. [00:14:45] Vince Menzione: So Jeff, you’ve been working with channel partners on the marketing side for many years on their go to market strategies. What are you seeing on your side of this aq? Or how are, how is AQ being absorbed and how are you thinking about this new world that we’re living in today? [00:14:58] Jeff Mesnik: Yeah, I mean, I think, you know, we work with 10,000 different types of channel partners and whether it’s through education or passing through and driving demand for them, and what we’re finding is there’s a little bit sometimes also a whiplash. [00:15:12] Jeff Mesnik: I mean, it’s like first it’s like, okay, we gotta go to the marketplace. Now we have ai, and now, oh wait, there’s these ISVs that can add value on top, and how do I do it together? So. Well, we’re, when we’re talking to these partners, we are trying to learn from the customers also who are bringing, because they’re adjusting their, you know, notions like, right? [00:15:34] Jeff Mesnik: You know, Shannon, you’re doing it every three months, [00:15:36] Shannon Sigmon: right? [00:15:36] Jeff Mesnik: So these poor partners, right? They’re trying to communicate and engage and work with the customer, and then all of a sudden it changes on a dime. So you need to have that instantaneous access to the. Information about what a customer is researching, what they’re doing, what they’re most interested in, and that’s really the important part to help with the, you know, adaptability quotient for these partners. [00:16:00] Vince Menzione: Yeah. [00:16:00] Jeff Mesnik: And for them to learn, they have to be pushed into it through a customer. Not just pushed into it from the vendor’s perspective. Also on the distributors are saying, Hey, let’s you know, go to my marketplace. Don’t go to Google’s marketplace. We are, we are Google’s marketplace. And it’s very, it can be very confusing. [00:16:18] Jeff Mesnik: So using AI you can understand what the customer’s needs are. You can enrich it by pulling in data from the different sources of information, whether it’s a CRM system or third party piece, and then use AI to actually define the next step that each partner can take so that they’re adapting faster and their sales team understands what to do next, and then go through some micro learnings or whatever it might be. [00:16:44] Jeff Mesnik: Mm-hmm. I love that. [00:16:45] Shannon Sigmon: Yeah. Yeah, and I was gonna say, Jeff and I are actually working together on a pilot. One of the things, and Vince, we talked about it, um, our teams internally are so consumed with the integration. [00:16:56] Vince Menzione: Yeah. [00:16:56] Shannon Sigmon: I was scared. There’s a lot of work going on behind the scenes. We pulled the plug really early on, at least getting our frontline sales force integrated last year. [00:17:04] Shannon Sigmon: So, at least to the market and to our customer and partner community, we were one company, but there’s a lot of system integration that’s still to come. And so, um, we, we’ve been partnered with Jeff and, and the content MX team because, um, a part of our cycles of getting our message out to market to our partners and helping them with their customer messaging is just the nurturing, the insights and leading the customer, leading the sellers through that sales Next. [00:17:27] Shannon Sigmon: Best step conversation. And so we’re, um, we’ll leverage some of the, the tools and the resources that that Jeff’s team is bringing to bear for us, because our marketing team has got integration work to go do. We’ve got rebranding and new websites to build and new processes to implement. And so for us that adaptability means realizing we can’t do it all ourselves. [00:17:48] Shannon Sigmon: And so we leveraged this community to connect with partners in the ecosystem who can help us. With our own solutioning of, of how we go to market and making sure we’re not missing the beat in those a hundred day sprints. [00:18:00] Vince Menzione: And you’re truly global. That’s right. As an organization. Right. So Switzerland is now the new headquarters that is right. [00:18:05] Vince Menzione: Nor was it Norway before and [00:18:06] Shannon Sigmon: yeah. [00:18:07] Vince Menzione: And then of course you’ve got the Americas [00:18:09] Vince Menzione: and [00:18:09] Shannon Sigmon: Yeah, we have our headquarter office here in Milwaukee and they’ve got a digital sales hub in Nashville, Tennessee. [00:18:13] Vince Menzione: Yeah. So. Bringing all those resources and then having all these people that have to adapt to change and then drive and go to market. [00:18:20] Shannon Sigmon: Yeah. [00:18:20] Vince Menzione: On top of that, [00:18:21] Shannon Sigmon: look, it just allows us to focus on what matters most, which is our customers, our partners, and our people. Um, and so leveraging our partner community, leveraging this network of folks that you’ve built helps us. We’ll continue to focus our team on the things that matter most for driving the business our results. [00:18:38] Shannon Sigmon: Um, we just announced earlier this week we had a bang up, um, Q1 and looking forward to that momentum carrying through the rest of the year. And, and it’s because of the partnerships and, and helping us to, to manage that adapt adaption of our business, um, going forward. [00:18:54] Vince Menzione: Mark, anything else from your side? [00:18:56] Marc Harpster: Uh, I just, I, I think, you know, platforms like yours are, are super exciting to me, and there’s a number of them that we’ve heard from over the last couple days. [00:19:06] Marc Harpster: You, you help all of us, every partner in the room, including the hyperscalers, you know, meet the customer where they are. And I think that’s increasingly important because as complicated as it’s for all of us to figure this out, it still has to be the customers at the center of it all. Right? And so we need to meet ’em where they are. [00:19:22] Vince Menzione: So what does real AI credibility look like for those partners? [00:19:27] Marc Harpster: Yeah, it’s, it’s a great question. Um, you know, it’s, it’s, uh, I’m fortunate to, to get to be at Google right now and we have, uh, uh, you know, we’re obviously working on a lot of things. Um, you know, we’ve been talking a lot about agents and, and, uh, you know. [00:19:45] Marc Harpster: What does it mean to, to listen agent and what’s that gonna do for the customer? Um, you know, I think it, it’s, it’s gonna have a big impact on how we co-sell. Right. I think we touched a little bit on this in the last panel. Uh, I think that, um, you know, customers, uh, are going to find their way to agents and it’s a different type of customer who’s gonna find it. [00:20:08] Vince Menzione: Yeah. [00:20:08] Marc Harpster: Uh, and I think that, you know, this opens up a real opportunity. Uh, for us to, you know, us as hyperscalers in the marketplace, to, um, kind of flip how things have been. Where traditionally it’s like, oh, you know, the ISV or, or the channel reseller sources the deal, and then we’re gonna register a deal in the, in the CRM, it’s gonna go over to, uh, you know, the, the, the hyperscaler CRM and then the sales rep’s gonna get involved. [00:20:34] Marc Harpster: I mean, that stuff is still gonna happen, still gonna be important, but now customers are gonna find their way to agents and now it’s, oh. The marketplace. [00:20:43] Vince Menzione: Yeah. [00:20:43] Marc Harpster: To get that information back out. Right. Or maybe they’re finding the content through a platform like Jeff’s, uh, and they go try something out and suddenly that’s the signal. [00:20:53] Marc Harpster: Right? And so we need to find a way to communicate that, I think a little more nimbly than we have in the past. Um, you know, so that’s a really big one. Um, and I think that like, uh, you know. The next, the next decade is really gonna be like, a little bit like the last decade was, uh, just as you know, in the last decade, really all these, all of the businesses that, you know, all of you guys in this room found a way to grow these astounding businesses, you know, in cloud. [00:21:21] Marc Harpster: And now I get to do the whole thing again in, you know, in the age of AI and agents. So I’m super excited for it. [00:21:27] Vince Menzione: Well, it, I think about SEO and product-led growth, almost like, oh, the agent’s gonna discover mm-hmm. Yeah. The solution in the marketplace, right? [00:21:35] Marc Harpster: Yeah. [00:21:35] Vince Menzione: So how do you think about go-to market strategies around that, right? [00:21:39] Vince Menzione: Yeah. ’cause, ’cause marketing changes dramatically, [00:21:41] Marc Harpster: right? [00:21:42] Vince Menzione: We were talking about that yesterday. [00:21:43] Marc Harpster: Yeah. Like when the agent is the one, finding [00:21:45] Vince Menzione: the agent is the one finding it, and it, it better be able to find it. ’cause then it’s gonna go search other places if it doesn’t. Yep. As if it’s not discoverable. [00:21:52] Vince Menzione: I think we all get to figure that out together. [00:21:54] Vince Menzione: Right. [00:21:54] Vince Menzione: Jeff, you’re, you’re the go-to-market expert, [00:21:57] Jeff Mesnik: I mean, [00:21:57] Vince Menzione: in the panel here. So how do you think about that? [00:22:00] Jeff Mesnik: We think about it the same way, kind of in your video, right? Yeah. Where it’s basically there’s a few ways that you need to be, um, reaching out so that you’re discovered by the AI agent. [00:22:10] Vince Menzione: Yeah. [00:22:10] Jeff Mesnik: So exactly the, you know, for example, you, you know, people here we are all writing white papers and case studies and, you know, doing all that work. [00:22:18] Jeff Mesnik: But what really triggers it is when you create more content from that one piece. So that’s more interactive. So for example, like, you know, you guys were talking about the short, the video shorts. [00:22:29] Shannon Sigmon: Yeah. [00:22:29] Jeff Mesnik: You can instantaneously, like we have a system that’s connected that instantaneously creates these video shorts from the PDF. [00:22:36] Jeff Mesnik: Or some of you may have seen I created a trivia night, which is an interactive element, so it enables people to then share and engage, and that starts to have, you know, some effect with the SEO, which is now. AI agents who are looking out to see, okay, what are the responses? What are the other people saying? [00:22:57] Jeff Mesnik: You’re spearheading that motion. [00:23:00] Jeff Mesnik: Yeah. [00:23:00] Jeff Mesnik: And then as you said, kind of the, kind of the triggers or the, you know, the, for the data insights that come back mm-hmm. From that are the ones that can trigger a co-sell motion where you’re working together with. Other partners you can be, you know, if you’re a vendor and you use us and you see that information, then maybe partner tap comes in and you can basically find which partner is the right one, and the systems can then target and have a co-sell motion together. [00:23:27] Jeff Mesnik: Yeah. [00:23:27] Jeff Mesnik: Right. So that’s the power that’s available now. [00:23:30] Vince Menzione: Yeah. Shannon, you mentioned about skating where the puck is going. Yeah. Famous. What, by the way, Wayne Gretzky lives in Jupiter, Florida. For those who dunno, uh, all the famous athletes, but of course that’s his, his quote. [00:23:42] Vince Menzione: And Joe Namath. Right. [00:23:43] Vince Menzione: And Joe NamUs. [00:23:44] Vince Menzione: Yeah, he’s in the, he’s in that one picture though slide. I have. Let’s talk about that a little bit. ’cause you, you’re navigating quite a bit of change. One of the most trusted resellers in the market working with the hyperscalers. Tell us how you’re adapting to that puck, where that puck is going. [00:24:01] Shannon Sigmon: Yeah, I, I think one of the things that we encourage and we talk about it, we, um, have a regular standing, uh, meeting where we talk about going out in the wild. [00:24:09] Shannon Sigmon: And so I think the, the most important thing that I would leave you all with and something that we are, um, fostering and learning along the way too, is your people in this whole A-E-O-G-E-O world. Your people have to have an opinion. It’s not just enough for them to share the content, click on the content, read the content, but they have to show up with a perspective or an opinion. [00:24:30] Shannon Sigmon: I don’t, I don’t need to be Jay McBain, but my goodness, I’m gonna follow him. I’m gonna learn from him, and I’m gonna share some of the learnings that I read from him because. He’s doing the work and, and getting the research together for us. But it is important that they do that and the, and the learning and adapting to where the puck is going, doesn’t happen behind a pane of glass. [00:24:47] Shannon Sigmon: They have to be out in front of it, in front of their customers, in front of partners, having a cup of coffee down the street with the neighbors. Because everybody is now consuming information in a much more personal way. It’s not, uh, just a corporate feed, uh, trough of AI slop that, um, somebody I was at an event last week they talked about, but to, to really understand it, to know it to be customer zero. [00:25:13] Shannon Sigmon: You have to be in it. And that doesn’t happen behind the pane of glass. So I would say that was probably the first one. And I think, um, one of the things that, uh, sparked, you know, a fire yesterday for me, Vince, was just really this conversation around the marketplace. Um, and especially in our, our, our community and what we do is how do we, this convergence of SaaS. [00:25:34] Shannon Sigmon: This convergence of consumption in the marketplace. Um, how do we as resellers help our customers optimize how they procure, um, their software in a much more modern way, um, and manage that along, along this journey so that they can take advantage of things coming up in ai. But I think those are like the two. [00:25:53] Shannon Sigmon: The one thing is just being curious, getting out in front of it and building your perspective. And you don’t have to be the smartest person in the room, but you do need an opinion. Um. And then showing up at events like this so that you can learn. [00:26:06] Vince Menzione: So Mark, uh, largest go to market shifts happening. I mean, the, the, the, the growth is astounding. [00:26:12] Vince Menzione: What about from your perspective? [00:26:14] Marc Harpster: Yeah, I think, um, you know, how you go to market, uh, in, in this new age is gonna change based on the type of partner that you are, right? Uh, if you’re an AI native startup, then you know that is your go to market. Like, like the AI is who you are, right? It’s part of your identity. [00:26:35] Marc Harpster: Versus if you’re a a, you know, a, a, an incumbent, a, a large ISV, you need to figure out how to wrap AI around your existing solutions, right? Mm-hmm. But if you may have a SaaS solution, and now do you have agents that are talking to that SaaS solution? You know, and are you building that? Where are you building that? [00:26:50] Marc Harpster: How are you running it? And how are you partnering with, you know, the hyperscalers? Uh, how are you partnering? You know, it could be, uh, philanthropic or open ai, right? Mm-hmm. Like we all have to, you know, you have to think about. How each of these different types of partners can help you go to market, right? [00:27:08] Marc Harpster: And really come up with that strategy. [00:27:13] Vince Menzione: Former. Any comments on that? [00:27:14] Jeff Mesnik: Yeah, well, I mean, I’ll just add, I, I just was thinking about this, uh, I’m gonna butcher this Bueller quote, but things are changing really fast, and you gotta take a moment to listen and understand what’s going on out there. So the data coming in is always going to drive everything else that you do. [00:27:30] Jeff Mesnik: So I butchered that quote, but imagine I said it right? [00:27:33] Vince Menzione: Yeah. I, I love Shannon, what you said it, and I’ll. Paraphrase it. The analog is the new digital. [00:27:42] Shannon Sigmon: It is, yeah. [00:27:43] Vince Menzione: Because we need rooms like this. We need to be in the room with other listen experts like [00:27:48] Shannon Sigmon: yourselves. Yeah. I mean, I say quite often human connection still matters, and at the end of the day, people are gonna use AI tools to do the research, to find the information, to surface the video training, but they’re not gonna make the decision until they know the person they’re buying from. [00:28:03] Shannon Sigmon: Yeah. And so that whole adage of people buy from people they like and trust. Is even more important in this, in this day and age. Yeah. [00:28:12] Vince Menzione: Any last comments or go tos for the, for this community? In front of us today. [00:28:17] Jeff Mesnik: I’ll just say that because of this community, you know, Shannon and I met, so we have yeah. [00:28:21] Jeff Mesnik: Great business that we’re gonna be doing together and I met the team at ISSI and we’ve got a great partnership that’s brewing. And, you know, I’m looking forward to other, you know, people that I’ve met here, um, Andrew who’s out there. Um, we’re gonna do some work together. So thank you, Vince. Thank you. I mean, this community has really been fabulous for me personally and for my business. [00:28:39] Jeff Mesnik: It’s been great meeting [00:28:40] Vince Menzione: and I didn’t pay you to say that, by the way. [00:28:42] Jeff Mesnik: No, I paid you. [00:28:44] Vince Menzione: That’s right. You did. You. Okay. Well, alright, mark, anything, any last comments from [00:28:52] Marc Harpster: Yeah. You know, um, don’t be afraid of the change, right? Like, if you have that hour a week, just go play around with play, play with all of the different, uh, AI. [00:29:02] Marc Harpster: Technologies that are out there, right. And just, uh, get to know them, right? The more comfortable you are with them, the easier this whole thing’s gonna be. So dedicate an hour a week, just go, you know, and that’s your time to, to learn how these things work, right? So [00:29:15] Vince Menzione: yeah, [00:29:15] Marc Harpster: I say don’t be afraid of it. [00:29:16] Vince Menzione: Awesome. [00:29:17] Vince Menzione: Yeah. Thank you so much. What a great panel. Great conversation. What do you think? Everyone? Thank you. Thank you so much. [00:29:25] Vince Menzione: Thanks for listening to the Ultimate Partner Podcast. If today’s conversation resonated. Share it with a [00:29:31] Vince Menzione: partner leader in your network. Subscribe where you listen, and head over to the Ultimate partner.com for show notes related content and the resources for this episode. [00:29:42] Vince Menzione: And if you haven’t already, now’s the time to register for the Ultimate Partner Live event in Reston, Virginia, October 26th through October 28th. Until next time, keep showing up in the rooms that matter because being in the room changes everything.
In this episode, I rethink the old build-versus-buy decision through a student badging project at Hillbrook. We bought a reliable ProdataKey access-control system, paid for API access, and then used Codex to build the simple, live dashboard our team actually needed—who is in each building, who has not arrived, and where an individual student last badged. The lesson is a new middle path: buy the sturdy enterprise backend, then build the final 15 percent that makes it useful for your actual colleagues. I talk about APIs and webhooks, why detailed prompts matter, and how school technology leaders can look for everyday friction and create focused tools around systems they already trust. Sometimes the best answer is not build or buy. It is buy, then build. Bill Selak Talks, Episode 138.
What happens when an organization writes careful AI governance policies but its infrastructure cannot enforce any of them? In this episode of Tech Talks Daily, I speak with Sabina Anja, Chief Technologist at Broadcom within the VMware Cloud Foundation division, about the infrastructure controls required as AI agents move from generating answers to accessing data, calling APIs, modifying systems, and triggering work. Sabina brings experience from both sides of enterprise technology. She remembers cabling networks, dealing with unstable infrastructure, and receiving those weekend calls when downtime had already upset the business. That background informs her belief that ambitious AI programs cannot succeed without stable, observable, and enforceable infrastructure beneath them. Many organizations are repeating a familiar pattern. Business teams adopt AI services before IT has established visibility, ownership, or control. The terminology may have changed from shadow IT to shadow AI, but the management problem remains. Sabina argues that CIOs first need an inventory of agents, nonhuman identities, data access, processes, and accountable owners. The risk becomes greater because agents behave differently from people. They operate across multiple systems at machine speed and can perform repeated actions without appreciating the wider business outcome. An agent does not need malicious intent to cause disruption. Excessive permissions, flat networks, inconsistent access rules, and years of deferred infrastructure work can give it plenty of opportunities. Sabina recommends brokered access rather than direct access, alongside dedicated virtual machines or namespaces, microsegmentation, lateral security, east-west policy controls, and tamper-evident logging. Organizations also need to define which data an agent can view, modify, or move, especially when sovereignty and regulatory requirements apply. One of Sabina's most memorable ideas is to treat an AI agent like a superhuman contractor. It should have a defined purpose, a named manager, a clear access specification, an activity record, and an end date. Additional permissions should be earned through evidence of reliable behavior rather than granted on the first day. She also warns about agent debt. AI systems are developing rapidly, so an agent created today may become outdated within months. Sabina recommends assuming that many agents will expire after six to nine months rather than allowing forgotten systems and permissions to accumulate indefinitely. For CIOs wanting an immediate test, her advice is straightforward. Create an inventory of nonhuman identities with production access. Then select one agent and examine every part of the infrastructure it attempted to reach. The question is not simply whether the application produced the expected result. Leaders should ask whether the agent entered systems, networks, or data stores that nobody expected it to access. We also challenge the familiar claim that AI agents will take everybody's jobs. Sabina sees an opportunity to remove repetitive tasks and give technology professionals new skills, although she warns that agents may behave like teenagers armed with infrastructure permissions. They may not take your job, but they could become remarkably good at testing your patience. I'd love to hear your thoughts. Does your organization know how many AI agents have production access and who is accountable for each one?
Is your ERP dashboard actually built on data that matters — or is it just a chart of accounts dressed up to look useful? In episode #386, Ben Murray breaks down why traditional ERP dashboards are losing ground to AI-generated, prompt-built SaaS reporting and what that means for CFOs and finance leaders right now. If your team is still relying on static dashboards anchored to your general ledger, you're missing three out of four key SaaS data sources before you even start the analysis. The gap between what ERP dashboards can show and what modern AI-native metrics engines can produce is widening fast and the CFOs who close that gap first will be the ones driving the board conversations. Why ERP dashboards are fundamentally limited to chart-of-accounts data — and the three additional SaaS data sources (HRIS, bookings, and customer/revenue data) that actually drive metrics like CAC payback, LTV to CAC, NRR, and Rule of 40. How Ben vibe-coded a full SaaS metrics dashboard in minutes using Claude — covering ARR trajectory, EBITDA margin, gross margin, revenue per FTE, and cash balance — and why a prompt-built report on a deterministic engine beats any canned dashboard. Why controlling the period of measurement matters: the example of setting CAC payback on a six-month sales cycle basis — something a standard ERP dashboard simply can't do. Where AI actually belongs in the FP&A process: not at the beginning, but at the end — writing board narratives, flagging dormant customers ripe for expansion via a RevIntel engine, and generating insights that traditional FP&A could never surface. Why agent-friendly APIs matter: how Saster's API grading tool surfaces whether your SaaS stack is actually exposing the data AI needs to take action — not just technically having an API. Tune in to understand exactly where your ERP dashboard ends and where a closed-loop, AI-powered metrics engine takes over — before your next board meeting. Resources Mentioned Ben's LinkedIn post (vibe-coded SaaS metrics report): https://www.linkedin.com/posts/benrmurray_saas-activity-7498039803582689280-7Ckt?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAOOEO8Bf5aRLyU0jjrGXvPD2odJNDer6KU Ben's deterministic SaaS metrics engine: https://softwaremetrics.ai Ben's Five Pillar SaaS Metrics Framework: https://www.thesaasacademy.com/saas-metrics-implementation-sprint-sept-2026
In this episode of Wash Talk: The Carwash Podcast, host Kyle Alexander sits down with Josh Noonan of NXT Wash at The Car Wash Show™ to discuss a shift happening across the industry: Carwashes are returning to face-to-face sales as a primary driver of carwash membership sales and retention. Noonan traces the arc from pre-COVID customer service models through the pivot to contactless kiosks and explains why operators are now finding that human interaction consistently outperforms automated pitches when it comes to converting new members and keeping them. Noonan breaks down how NXT Wash approaches real-time data, using an open API framework that allows operators and third-party platforms to act on customer information as it happens. Rather than reacting to customer behavior after the fact with batch campaigns, NXT Wash is built to put actionable data in front of frontline staff as customers pull in, including visit frequency, membership status and conversion history. Noonan also explains how the company's hardware-agnostic software approach lowers the barrier for multi-site operators who can't afford to rip out existing equipment to make a switch. The episode closes with a look at what happens when a carwash reaches 80%-90% membership penetration and churn becomes the central challenge. Noonan outlines the tools and human touchpoints that keep high-membership carwashes growing even after the easy conversions are done.
An airhacks.fm conversation with Ian Rogers about: Java's early API design strengths versus verbose C++/STL manuals, the Java 7 String.substring behavior change from an O(1) view over the character array to an O(n) copy, substring performance regressions at Google, implementing a custom substring as a workaround, designing APIs without knowing future customers, the SPEC JVM98 jack parser generator throwing an exception per matched token, exceptions used for control flow violating the exceptions-are-exceptional principle, JVM benchmarks skewed toward fast exception throwing, ANTLR and JavaCC as later parser tools, class loaders pairing a type with a runtime notion, ClassNotFoundException thrown from nested jar files, the DaCapo benchmark as a test of exception-throwing speed, Effective Java advice to return interfaces such as Map instead of HashMap, why substring should have returned CharSequence, the argument that String should be an interface and CharSequence the concrete type, CharSequence length limited to int and capped at 2GB, Guava Rope as a collection of CharSequences unable to implement CharSequence because of the int length limit, signed versus unsigned sizing of arrays and strings, byte signed and char unsigned inconsistencies, StringBuilder versus StringBuffer, the race condition avoided by StringBuilder cloning its array in toString, StringBuffer passing array ownership under a lock, biased locking making uncontended locks cheap, the Attack of the Clones problem of defensive cloning, optimizing clones away in the JVM, transactional memory as an alternative to locking, copy-on-write and CopyOnWriteArrayList, Swift copy-on-write, Linux kernel read-copy-update and epochs, writing the Azul C4 garbage collector, the C4 read barrier now used in ZGC and Shenandoah, moving Azul from custom hardware read-barrier instructions to x86, the two-space invariant in concurrent copying collectors, IBM Metronome fixups versus two-space invariants, detecting same-page references by XOR of two pointers, trading computation for memory accesses in read barriers, the Transitive Corporation binary translator, Rosetta for Apple and a Sparc-to-Power translator behind IBM's planned Sun acquisition, writing Android Runtime ART, ahead-of-time compilation of Dex replacing Dalvik, disk-size constraints of AOT compilation, Hans Boehm and sticky mark bits for generational marking without moving objects, ART generational concurrent garbage collection in Android KitKat, HashMap interface dispatch replacing LinkedList iteration from JikesRVM, alphabetically sorted interfaces putting AbstractCollection first, Google Maps interface dispatch consuming half the frame time, frame-rate and pause-time gains from ART, WhatsApp broken by an unbalanced-lock bytecode obfuscator, balanced locks required for biased locking, thread safety annotations in Clang/LLVM guarding the Java heap, the mutator lock and stale pointer risks, a reader-writer lock model of the Java heap, managing risk when replacing an operating system runtime, CyanogenMod as a delivery path for ART, Project Valhalla value types, current work on the Linux perf tool and observability, OProfile origins, GPU versus CPU visibility in system tools Ian Rogers on linkedin: irogers
In this episode of Two Bees in a Podcast, Amy Vu and Dr. Jamie Ellis discuss Apis mellifera mellifera with Dr. Mark Barnett, researcher at the Roslin Institute at the University of Edinburgh in Scotland and co-founder of Beebytes. Check out our website: www.ufhoneybee.com for additional resources from today's episode.
Topics covered in this episode: Web UIs for your reverse proxy Wagtail 8.0 is hot off the presses RISC-V is now officially supported by CPython Django's annual releases make every version an LTS Extras Joke Watch on YouTube About the show Sponsored by Logfire from Pydantic: pythonbytes.fm/logfire Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Web UIs for your reverse proxy Traefik, nginx, and Caddy all sit in front of a lot of self-hosted infrastructure, and all three are configured by hand-editing files. Three active projects put a control plane on top: Traefik Manager (Python + Flask), Nginx UI (Go + Vue), and caddy/ui (React + Node). All three are additive rather than replacements - none of them take ownership of your config away from you - which is the part that matters when the thing has write access to production routing. Traefik Manager is the Python one: Flask 3.1 and Gunicorn for the control plane, a lightweight Go agent for remote instances, currently v1.10.0 with an Android companion app. Nginx UI is a single Go binary at 11.3k stars, with a block-style config editor, an Ace editor doing LLM completion on nginx syntax, and an MCP server so agents can drive it. caddy/ui runs as two containers next to your existing Caddy, reads and writes your Caddyfile directly, and uses Caddy's /adapt API to validate before reload - no Docker socket required. Each one edits the config the underlying server already reads, so your files stay the source of truth and you can drop the UI without unwinding anything. Undo is a first-class feature across all three - timestamped backups with optional Git history, config version compare and restore, Caddyfile snapshots with one-click rollback. Observability is where they diverge: Traefik Manager does CrowdSec and a visual route map, Nginx UI does server metrics, caddy/ui streams access logs over SSE and pulls p50/p95/p99 off Caddy's Prometheus endpoint. Maturity spread is wide - Nginx UI has 11.3k stars, caddy/ui has 4 and was built in a single Claude session - and caddy/ui ships with auth off by default, so set CADDY_UI_USER and JWT_SECRET before it goes anywhere near a public interface. Calvin #2: Wagtail 8.0 is hot off the presses Link: https://github.com/wagtail/wagtail/releases/tag/v8.0 Custom base page models are now supported, so projects aren't locked into subclassing Wagtail's Page as shipped (Matt Westcott). New v3 REST API handles both read and write CMS operations, a first for Wagtail's API. A global registry for permission policies, plus full customizability for the remaining page views via PageViewSet. AVIF and WebP images are no longer auto-converted to PNG by default, a real behavior change to watch on upgrade. Five security fixes: page admin API restrictions, document identification by SHA1 hash, descendant collections in the Documents/Images API, snippet copy permissions, and the page translation endpoint. Formalized Django 6.1 support, and CI now runs on uv with a lockfile. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: RISC-V is now officially supported by CPython Link: https://blog.python.org/2026/08/riscv-now-officially-supported/ CPython added RISC-V as a tier 3 platform under PEP 11, specifically the 64-bit Linux target riscv64-unknown-linux-gnu. RISC-V is an open ISA anyone can implement, unlike x86 and ARM, and its market is projected to quadruple by 2032. The RISE Project donated real RISC-V machines for buildbots; the author's work was funded by a Sovereign Tech Agency fellowship. What changes: the port is now a maintained compatibility target, so CPython changes are less likely to quietly break it. What doesn't: no python.org installers, no binary wheel parity for native extensions. Next up: RISC-V runners in CPython CI for pre-merge feedback, then a push toward tier 2, plus architecture-specific optimizations. The ask is testing. If you have RISC-V hardware, build CPython, run your test suite, file what breaks. Tier 3 is the weakest support tier. PEP 11 tier 3 requires a core developer contact and a buildbot, but failures on tier 3 platforms explicitly do not block a release. Saying "ongoing CI/testing expectations" oversells it. The honest bit is "someone is now on the hook for it, and breakage gets noticed," not "it's guaranteed working." Worth the caveat that this is Linux SBCs, not microcontrollers. A VisionFive 2 counts, an ESP32-C6 or Pico 2 does not. Those are 32-bit non-Linux parts where MicroPython is still the answer. Michael #4: Django's annual releases make every version an LTS Starting with Django 2028, Django will move to one January feature release per year, adopt calendar-based version numbers, and support every release for three years. The old distinction between standard and LTS releases disappears, giving teams a predictable annual upgrade path that aligns more closely with Python's own release and support cadence. Every Django release becomes the safe, long-supported choice, so teams no longer need to wait for a specially designated LTS version or absorb two years of changes at once. Each release gets one year of mainstream bug fixes followed by two years of security and data-loss fixes. New releases support the three latest Python versions and add the next Python release during their first year. Calendar versioning begins with Django 2028, followed by Django 2029 and so on. Three Django versions will be supported at any time, giving third-party packages a clearer rolling target. Nothing changes before 2028, and existing commitments for Django 5.2 LTS and 6.2 LTS remain in place. Extras Calvin: The Python docs now document the time complexity of built-in types https://docs.python.org/3.16/library/time-complexity.html Thinking in Python - Bruce Eckel's free book https://thinkinginpython.com/ Michael: prune_uv_pythons.py - Prune uv-managed Python installs, keeping only the newest patch per minor version Runs automatically in my system “upgrade” script: upgrade-output-2026.png Started using Ollama cloud models for my Hermes assistant. Thanks to Jeff Triplett I learned they are not just local models. Joke: The Tao of Programming - Book Seven: Corporate Wisdom
DESCRIPTION Welcome to The Ecommerce Braintrust podcast, brought to you by Julie Spear, Head of Retail Marketplace Services, and Jordan Ripley, Director of Retail Account Management. Today, we're tackling a topic that has evolved from a conference panel talking point into one of the most significant media budget shifts in digital advertising: Amazon DSP for non-endemic brands. Historically, brands that don't actually sell physical products on Amazon's marketplace have questioned why they should buy Amazon media. Today the conversations we're having with brands are very different. Joining us today to unpack why 2026 is the turning point for non-endemic media buying is our very own Director of Retail Media at Acadia, Ross Walker. Let's dive in! Quote: If you're a non-endemic brand and you're hitting a point of consistent diminishing returns with your traditional media channels, that's the first signal that you should consider testing into a new media channel like ADSP. Ross Walker KEY TAKEAWAYS In this episode, Julie, Jordan, and Ross discuss: Endemic vs. non-endemic, simplified: It's really just "sells on Amazon" vs. "doesn't sell on Amazon" - the jargon is mostly industry inertia. Amazon DSP has hit parity with The Trade Desk: Years of building out premium CTV/STV, audio, digital out-of-home, and owned-channel inventory means Amazon can now support the same kind of full-funnel programmatic buys as legacy DSPs. The real edge is commerce data, at a lower cost: No other DSP has Amazon's depth of purchase-intent signal, and Amazon has intentionally kept platform and audience fees low to win market share while it can. Premium CTV reach is a genuine unlock: ADSP now reaches roughly 80 million authenticated CTV households a month through partners like Netflix, Disney+, and Roku - inventory that used to be exclusive to players like The Trade Desk. Attribution is no longer the weak link: Tools like Amazon Marketing Cloud, the Amazon Ad Tag, and conversion APIs let non-endemic brands tie a Netflix or Roku impression directly to a D2C sale, lead form, or sign-up - solving a measurement gap that's plagued programmatic for years. Endemic brands get more flexibility too: Brands that do sell on Amazon can now send DSP traffic to their own site or other retailers (Walmart, Ulta, Home Depot), though the richest behavioral/custom audiences are still reserved for traffic that stays on Amazon. Signals to know it's time to test ADSP: Diminishing returns on Meta/Google/Trade Desk, or an audience with strong, specific purchase intent are both green lights to start testing. What still differentiates DSPs going forward: As capabilities converge across platforms, the real differentiator becomes each platform's unique owned audiences and media properties (e.g., Amazon's Prime Video, Walmart's owned data via The Trade Desk).
Mike Heilig is the general manager at Binary Anvil, a web development agency and systems integrator that has been running for 18 years, built mostly on Adobe Commerce, and has since branched into other platforms and a product of its own.He takes on the SaaS promise directly. Moving to SaaS genuinely removes the hosting and patching burden, and then relocates the difficulty rather than deleting it, because business complexity does not go away. His fit test is simple. A very simple business may belong on SaaS. B2B requirements, complex catalogs and complex price lists probably do not. The mistake he sees merchants make is shopping for technology before writing down the business outcome they want.The conversation turns to Flux, Binary Anvil's React and Next.js headless front end that attaches to an Adobe Commerce backend and supports B2C and B2B out of the box. For D&B Supply, a large farm and ranch retailer, rebuilding on Flux while keeping the Adobe Commerce backend moved site speed, conversions, organic traffic and search rankings, and cut roughly 57,000 dollars a year off upgrade cost. Heilig explains why decoupling the front end is what makes upgrades cheap, and credits Adobe for maintaining old APIs instead of deprecating them.On AI mediated commerce he is patient rather than breathless. Structured data, machine readable documentation and clean APIs are the groundwork, the requirement is on the horizon rather than here, and the open question is whether shoppers are ready to hand a credit card to an agent at all.Guest: Mike Heilig, General Manager, Binary Anvil
Discover the latest conversations around Sonos speaker accessibility, Meta smart glasses, and AI-driven accessibility solutions. Steven Scott and Shaun Preece share personal experiences, listener feedback, and practical advice for blind and visually impaired tech users. In this lively episode of Double Tap, Steven Scott and Shaun Preece dive into listener messages covering everything from high-quality audio gear to the future of smart glasses. The discussion kicks off with a humorous tangent about a Perkins School for the Blind gift bag, before moving into practical advice on Sonos speakers, including their accessibility challenges, Wi-Fi setup quirks, and app updates. The hosts explore Meta smart glasses, connection issues, and the growing debate surrounding privacy and public perception of wearable cameras. They also highlight the potential for AI and APIs to empower blind users to create accessible workarounds for otherwise inaccessible apps, while debating whether this approach creates a new kind of digital inequality. Listener insights from around the globe bring real-world experiences with Meta Oakleys, accessibility advocacy, and the concept of a “disability tax” in digital access. This episode is packed with wit, advocacy, and a forward-looking discussion on how mainstream and assistive tech are evolving. Relevant Links Perkins School for the Blind: https://www.perkins.org Sonos Official Site: https://www.sonos.com Meta Smart Glasses: https://www.meta.com/smart-glasses ----Follow on:YouTube: https://www.doubletaponair.com/youtubeX (formerly Twitter): https://www.doubletaponair.com/xInstagram: https://www.doubletaponair.com/instagramTikTok: https://www.doubletaponair.com/tiktokThreads: https://www.doubletaponair.com/threadsFacebook: https://www.doubletaponair.com/facebookLinkedIn: https://www.doubletaponair.com/linkedinSubscribe to the Podcast:Apple: https://www.doubletaponair.com/appleSpotify: https://www.doubletaponair.com/spotifyRSS: https://www.doubletaponair.com/podcastiHeadRadio: https://www.doubletaponair.com/iheartAbout Double TapHosted by the insightful duo, Steven Scott and Shaun Preece, Double Tap is a treasure trove of information for anyone who's blind or partially sighted and has a passion for tech. Steven and Shaun not only demystify tech, but they also regularly feature interviews and welcome guests from the community, fostering an interactive and engaging environment. Tune in every day of the week, and you'll discover how technology can seamlessly integrate into your life, enhancing daily tasks and experiences, even if your sight is limited."Double Tap" is a registered trademark of Double Tap Productions Inc. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
The voices telling you it won't work usually belong to people who never tried. Nobody gives you permission to take a chance. You just do it.Chris built a 50K MRR business without a formal education, a tech background, or a plan. It started when a car dealership paid him $400 to be in a commercial and he thought — if I can pretend to do this, what happens if I just actually do it?From there it was APIs learned on someone else's Amex, webhook integrations figured out under pressure, and enough failures to make most people quit. He's now responsible for 40% of some dealerships' bottom lines, working remotely from Ottawa, heading to Costa Rica.We talked about why people don't take that first step. Chris's take is it's mostly the room you're in. When you move somewhere nobody knows you, the risk calculus changes. The voices telling you you're going to look stupid usually belong to people who never left.We also got into social media — the throttled notification drip sequences designed to keep you coming back, the rage bait economy, the positive reinforcement loop that rewards the most outrageous behavior. His advice was simple: put your phone down and take life at face value.Originally aired: Feb 23, 2026
Tim Scarfe speaks with Ilia Shumailov and Alexander Panfilov about their paper, Stealing Reasoning Traces from Proprietary LLM APIs.The core bug sounds deceptively simple: providers return encrypted reasoning state so conversations can be resumed or forked. But those blobs can be replayed across users and sibling models. A smaller model can ask the provider to decrypt the trace, then repeat the hidden reasoning in plain text. The discussion covers leaked private data, a broadly reusable jailbreak, poisoned agent traces, chain-of-thought monitoring, responsible disclosure, and possible defenses.Ilia Shumailov is an AI and security researcher, formerly at Google DeepMind, who completed his Cambridge PhD under Ross Anderson. Alexander Panfilov is a PhD researcher at the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems, working on AI safety, adversarial machine learning, and LLM red-teaming. They close by separating the demonstrated jailbreaking threat from ordinary benign distillation, and by arguing for controlled experiments over sweeping claims.---TIMESTAMPS:00:00:00 Intro montage00:01:33 Portable encrypted thought and decoded reasoning00:24:55 How the attack works and what it means00:39:04 Doom, defense, and scientific restraint---REFERENCES:paper:[00:00:00] Stealing Reasoning Traces from Proprietary LLM APIshttps://arxiv.org/abs/2608.09867[00:09:22] Chain of Thought Monitorability: A New and Fragile Opportunity for AI Safetyhttps://arxiv.org/abs/2507.11473[00:11:30] Reasoning Models Don't Always Say What They Thinkhttps://www.anthropic.com/research/reasoning-models-dont-say-think[00:37:22] PostTrainBench: Can LLM Agents Automate LLM Post-Training?https://arxiv.org/abs/2603.08640[00:41:02] Large-scale online deanonymization with LLMshttps://arxiv.org/abs/2602.16800other:[00:09:28] OpenAI and Hugging Face partner to address security incident during model evaluationhttps://openai.com/index/hugging-face-model-evaluation-security-incident/[00:10:22] Claude, GPT, and Gemini All Struggle to Evade Monitorshttps://metr.org/notes/2025-08-22-claude-gpt-gemini-struggle-evade-monitors/tool:[00:42:08] Isabelle proof assistanthttps://isabelle.in.tum.de/---RESCRIPT: https://app.rescript.info/share/07fc38276e0823dc9b8986c32e202c7f
Software Engineering Radio - The Podcast for Professional Software Developers
Sathiesh Veera, a GenAI Solutions Architect at At&T, speaks with host Brijesh Ammanath about the data-protection guardrails required when using LLMs. The core issue is that LLMs sit outside the cloud tenant in most enterprise AI deployments, which means that data leaves the company's perimeter with every prompt, RAG retrieval, and tool call. Contractual agreements can restrict the data that LLM vendors are allowed to use for training and audits, but they don't stop prompt injection or unintended exposure as company data is often shared to LLMs via natural language queries, APIs, tool and function calls, and MCPs. Sathiesh discusses ways to employ security measures and data filtering at each layer to conform to data security policies and protect the data.
Topics covered in this episode: Python 3.12.14, 3.11.16, 3.10.21 - security releases Codeberg's AI-code ban tests its role as a GitHub alternative Brett Cannon: what's missing for reproducible builds on PyPI nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. Extra extra extra, hear all about it Extras Joke Watch on YouTube Sponsored by Logfire from Pydantic pythonbytes.fm/logfire This episode is brought to you by Pydantic Logfire. It's observability for AI apps from the team behind Pydantic - agents, LLMs, APIs, database, and infrastructure in a single trace, queried with Postgres-compatible SQL. Your coding agent can query it too, through their MCP server. I'll tell you more later. Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Python 3.12.14, 3.11.16, 3.10.21 - security releases https://blog.python.org/2026/08/python-31214-31116-31021/ Source-only security releases for the three branches now in security-fix-only mode; release team blamed the European solar eclipse for the timing. tarfile hardening. Multiple path-traversal bypasses of the data filter closed, including a symlink escape that bypassed the CVE-2025-4330 fix; extract() now applies the filter to link targets too. Four fresh CVEs: CVE-2026-2297 (SourcelessFileLoader not using io.open_code() for .pyc), CVE-2026-4224 (expat crash on deeply nested content models), CVE-2026-3644 (control chars in http.cookies.Morsel), plus the completed CVE-2021-4189 fix in ftplib.ftpcp. Quadratic-complexity DoS cleanup across the stdlib: HTMLParser, configparser regexes, unicodedata.normalize(), csv.Sniffer.sniff(), and ElementTree XPath index predicates. Header/injection fixes: CR/LF rejected in HTTPConnection.set_tunnel(), control chars blocked in wsgiref.handlers status, and webbrowser now rejects leading dashes (plus a %action prefix bypass). http.client now caps chunked trailer lines and 1xx interim responses at 100 each - a hostile server could previously hang the client forever despite a socket timeout. Memory-safety odds and ends: stale pointers in lzma/bz2/zlib decompressors after MemoryError, a bz2 stack overflow on reuse-after-error, and bundled libexpat bumped to 2.8.3. If you're still on 3.10, 3.11, or 3.12 - and you extract tarballs from anywhere you don't fully control - this one's not optional. Michael #2: Codeberg's AI-code ban tests its role as a GitHub alternative Armin's article “Codeberg Divides” Armin Ronacher argues that Codeberg's new terms, which prohibit projects mostly written with generative AI, create a vague and difficult-to-enforce boundary. His larger concern is that a democratically governed host can still be unpredictable or ideologically narrow, weakening Codeberg's potential as a broad European alternative to GitHub. The strongest question for Python developers is whether repository hosting should judge legal open source by how code was produced, or focus on behavior and resource abuse. “Mostly generated” is hard to measure in modern codebases where developers mix handwritten code, completions, agents, and generated refactors. Ronacher suggests clearer alternatives: ban all LLM involvement, or target autonomous repository spam, abusive resource use, and low-quality generated contributions directly. Codeberg is free to choose a values-driven community, but that may conflict with being predictable, neutral infrastructure and a serious GitHub competitor. Worth discussing: can open-source communities set meaningful AI boundaries without driving maintainers and projects into opposing camps? Very first search for these terms lands on this page. Codeberg looked like a viable alternative. … Unfortunately, the latest update to its terms of service seems to mark a first step in changing one part I moved there for, namely the “freedom” part. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: Brett Cannon: what's missing for reproducible builds on PyPI Framing came out of his 2026 Python Packaging Council nomination - the secure-supply-chain gap he found is that Python has no defined way to do reproducible builds at all. Design goal is zero friction: producers uploading to PyPI shouldn't have to do anything. The work lands on build backends and installers. Gap #1: nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. Gap #2: recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. The replay mechanism already exists: [build-system] in pyproject.toml is a defined entry point, so if backends recorded their own environment, you could reinstall and re-run the build. Payoff idea: trusted third parties report successful reproductions back to PyPI, which displays "independently reproduced by X" - surfaced in the index API so installers could prefer reproduced files. Explicitly framed as a perk, not a requirement - roughly SLSA build level 1, no shaming projects that don't opt in. Verbal kicker option: "And don't think pure-Python wheels are off the hook. Something built that wheel, and if that something was compromised, so is your wheel. SolarWinds was a build-process attack." Michael #4: Extra extra extra, hear all about it Python 3.14.7 Upgraded the MCP servers to 2026-07-28 v2 protocols (talk python, python bytes) Got agentsview running synced via postgres Talk Python courses, teams trial offering Talk Python courses, government procurement offering Lean TDD audio book is out Extras Calvin: uv now prefers post-quantum key exchange - https://github.com/astral-sh/uv/releases/tag/0.12.4 Joke: Beware of dog
In this episode, Paul Galloway and Craig Jeffery discuss treasury technology debt, the hidden burden created when legacy systems and infrastructure continue to work but increasingly limit flexibility, security, and future capabilities. They explain how treasury teams can assess technology and identify where outdated tools create the most drag, and how to prioritize upgrades without trying to replace everything at once. The discussion also covers ISO 20022, APIs, AI, cloud-native architecture, interoperability, and why treasury should regularly review its technology stack to maintain a practical runway for future change. 2026 Treasury Technology Analyst Report The Hidden Costs of Complexity in Treasury Operations (2026) TMS and TRMS: Choosing the Right Treasury System in 2026 (2026) Treasury Assessments: What to Review and How Often (2026) Timestamps: 00:00 Introduction 01:16 What is treasury technology debt? 02:45 Common forms of technology debt 04:28 How outdated technology impacts treasury 06:44 Identifying and prioritizing technology debt 10:25 Payment standards and ISO 20022 11:31 Reducing technology debt strategically 14:15 APIs, interoperability, and modernization 15:40 Building a sustainable technology roadmap 16:31 Final thoughts 16:48 Outro ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ABOUT STRATEGIC TREASURER ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Strategic Treasurer is recognized as a top tier consulting firm in the area of treasury and risk management. Corporate clients, banks, and technology vendors all rely on their industry leading advisory services that are backed by a deep awareness of current needs, practices, and budgeting priorities of treasury professionals through Strategic Treasurer's annual industry surveys and decades of treasury experience. Strategic Treasurer utilizes a senior consultant model where every project is managed by senior consultants with actual practitioner experience in corporate and/or banking roles. Download The Strategic Treasurer: A Partnership for Corporate Growth by Craig A. Jeffery in Kindle, or hardcover. As an Amazon Associate, we earn from qualifying purchases. Visit us today at StrategicTreasurer.com. Or join in the discussion at one of our leading LinkedIn groups.
Show DescriptionWe tackle a listener question about why junior front-end devs are expected to know so much beyond HTML and CSS, then get into Dave's real-world fix swapping old WebKit line-clamp hacks for the new CSS line-clamp property and the subtle bugs that kind of truncation work can cause. They also debate whether AI tools like Claude or Copilot deserve co-author credit on commits, gripe about agent-only coding workflows that skip linting and hide what's actually happening, and wrap up looking at new platform features like the navigation API and a proposed CSS-based routing approach using @route and @view-transition. Listen on WebsiteWatch on YouTubeSponsorsNotionWrite custom tools for Notion Agents that generate assets, query live data, and hit any API. Listen for incoming webhooks from any app, then run workflows with Notion Agents, pages, databases, and external APIs. All of this, on a hosted runtime. Workers are isolated sandboxes managed by Notion, so the code behind your syncs, tools, and workflows runs on our infra instead of your servers.
Our Head of U.S. Public Policy Research Ariana Salvatore explains how U.S.-China tensions, export controls and domestic regulation are reshaping where AI is built, who controls it and what investors should watch.Read more insights from Morgan Stanley.----- Transcript -----Ariana Salvatore: Welcome to Thoughts on the Market. I'm Ariana Salvatore, Head of U.S. Public Policy Research at Morgan Stanley. Today, a look at how government is increasingly determining the future of AI in the U.S. – from where it's built to which technologies US companies and consumers can use. It's Friday, August 7th at 10am in New York. AI is rapidly reshaping the economy and society, so this is a pivotal moment for government to consider the rules governing that development. The first area to watch is technology restrictions, particularly in the context of U.S.-China competition. Now, for much of the past decade, the government's approach has been to restrict a relatively narrow group of technologies with clear national security implications while maintaining broader commercial ties. But as export controls spread across more sectors of the economy and AI moves from software into physical infrastructure, the definition of what qualifies as national security has become broader. The Department of Commerce could, for example, expand the entity list. That would require US cloud providers, software companies, and model marketplaces to remove or stop supporting models tied to designated Chinese developers. Congress could then make those restrictions more durable through things like the annual defense bill or other policy vehicles. We're keeping an eye on several legislative proposals, like the AI Overwatch Act, which would tighten controls and give congressional oversight around exports of the most advanced AI chips; and the MATCH Act, which would extend restrictions further upstream to semiconductor manufacturing equipment and seek closer alignment with allied producers. These measures wouldn't directly ban Americans from using a Chinese model, but they could constrain China's ability to train future frontier systems. But it's not just the US that could impose a set of restrictions. China has a parallel set of tools focused more on integration and market access. Regulators could block four models or APIs. They could require locally controlled deployment. They could impose Chinese data and content standards or use cybersecurity and entity list authorities to promote domestic substitutes. The likely result is an increasingly distinct pair of AI ecosystems. That's our two worlds thesis in practice. Over time, we think that means a bifurcated global AI market into separate technology ecosystems. That looks like the U.S. relying on export controls, allied supply chains, and largely closed frontier model platforms, while China emphasizes domestic hardware, open-weight models, subsidized compute, and localization. Over time, that bifurcation could produce different chips, models, standards, data rules, and distribution channels, while third countries navigate between the competing stacks. The second area to watch is domestic regulation. Today, the landscape is pretty fragmented. States are moving first on certain specific issues, including automated decision-making and child safety. Now, at the same time, Congress is confronting competing objectives from industry, consumer groups, and national security officials. So far, we think the evidence suggests that the administration's preference is for a light-touch approach, a largely voluntary national framework rather than a broad new licensing regime. But it's also moving toward more direct oversight of the most advanced models. That includes the possibility to play a more active role prior to model release to ensure that certain protections like cybersecurity and intellectual property are met. Publicly outlined priorities from industry seem to broadly overlap with that approach: a consistent federal framework, clearer liability standards, access to data, compute, and power, and copyright rules that don't materially limit model training. But of course, the industry isn't monolithic. There are some important nuances between frontier developers and other players. So, what does all this mean for investors? The government's reaction function will be critical to the way AI is developed and diffused throughout our society in two key ways. First, we see regulation altering not only the pace, but also the geography of AI infrastructure. At the same time, we think these constraints could strengthen the investment case for bottleneck solutions like on-site power generation, fuel cells, storage, and more. Second, greater technology bifurcation supports investment in parallel supply chains. The key takeaway here is that the government is no longer simply regulating the industry from the sidelines. It's helping to determine how fast AI develops through domestic rules, where it develops through infrastructure, permitting, and sovereign AI policy, and which technologies are accessible through export controls and market access restrictions. Thanks for listening. If you enjoy the show, please leave us a review wherever you listen and share Thoughts on the Market with a friend or colleague today.