The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/AI for Business with BCN
AI for Business with BCN artwork

Self-Driving Cars Today, Robot Coworkers Tomorrow?

AI for Business with BCN · 2026-06-02 · 17 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence10 / 20
Conversational Craft7 / 20

This episode explores the accelerating convergence of AI and robotics in business operations, moving beyond software into physical automation. Mark Rotheram (BCN CTO) and Matt Lovell (CloudGuard CEO) discuss how work displacement is abstracting upward - engineers shift from writing code to managing specs and agentic workforces, much as future workers will manage robotic teams. Near-term applications include Tesla's Full Self-Driving, Uber and Nvidia's autonomous vehicle investments, and point-AI solutions in surgery and warehouse automation, before humanoid robots mature. Lovell argues routine surgeries will go robotic within seven years, citing healthcare's resource bottlenecks in A&E triage, GP diagnosis, and specialist training. The episode pivots to critical governance: CISA (Cybersecurity and Infrastructure Security Agency) and MITRE maintain the National Vulnerability Database (NVD) - the global standard for CVE classification and patching - now under funding pressure despite being essential as attackers use generative AI to exploit vulnerabilities faster. Lovell warns that without continued investment in CISA, trust in vulnerability intelligence collapses. Business leaders should understand this as a foundational security concern alongside robotic adoption: keep patching current, map risk actively, and support centralized vulnerability infrastructure as AI accelerates both innovation and attack surface.

Key takeaways

  • →Robotic capabilities will first penetrate specific domains like autonomous vehicles and surgical applications before general-purpose humanoid robots become common, following the same pattern as AI adoption in software.
  • →Jobs will shift from individual contributor work to managing autonomous/agentic workforces, requiring retraining in higher-level tasks like specification writing and validation rather than elimination.
  • →The CISA vulnerability database (CVE/NVD) is mission-critical infrastructure that all organizations depend on, but faces funding cuts and talent loss that threatens its long-term viability.
  • →Attackers are using generative AI to identify and exploit security vulnerabilities faster than organizations can patch them, making timely vulnerability information and remediation more critical than ever.
  • →Human oversight and governance must remain central to robotic and AI deployments, particularly in high-stakes domains like healthcare and autonomous vehicles where ethical decision-making is required.

In this episode

  1. 1Robotics and Work Displacement: From Software to Physical Automation
  2. 2Self-Driving Cars as the First Wave of Robotic Adoption
  3. 3Healthcare Applications: Surgical Robotics and NHS Pressure Points
  4. 4Trust, Safety, and Human Governance in Autonomous Systems
  5. 5CISA Funding Crisis and Cybersecurity Vulnerability Management
  6. 6The Role of Generative AI in Accelerating Vulnerability Exploitation

Mentioned

BCNCloudGuardTeslaUberNvidiaCISAMITREMatt LovellSinéad HammondMark RotheramFSDCVE

Guests

Matt LovellMark Rotherham

Topics in this episode

Autonomous vehiclesTesla FSDCISA (Cybersecurity and Infrastructure Security Agency)CVE (Common Vulnerabilities and Exposures)National Vulnerability Database (NVD)CloudGuardMITRE Attack FrameworkRobotic surgeryGenerative AI security threatsAgentic workforce management

Questions this episode answers

How soon will routine surgeries be performed by robots instead of human surgeons?

Matt Lovell estimates it will not take seven years for most routine surgeries to be performed robotically, indicating this shift is accelerating faster than many expect, though human governance and oversight will remain essential.

What is CISA and why is it critical for businesses adopting AI?

CISA (Cybersecurity and Infrastructure Security Agency) maintains the National Vulnerability Database (NVD) that classifies and documents all known security vulnerabilities (CVEs) globally. It is mission-critical because attackers now use generative AI to exploit vulnerabilities rapidly, making current patching and awareness dependent on CISA's trusted, centralized database.

How will robotic automation change job roles rather than eliminate them?

According to Mark Rotheram, work will be abstracted upward - software engineers move from writing specific code to validating specs; workers will shift from sole contributors to managers of agentic or robotic workforces, much as happened in software development over the past three years.

What immediate robotic and AI applications should businesses watch before humanoid robots arrive?

Near-term deployments include self-driving vehicles (Tesla FSD, Uber, Nvidia investments), warehouse automation, and surgical robotics, followed by point-solution robotics in domains like A&E triage and GP diagnosis before general-purpose humanoid robots emerge.

Why is CISA funding declining and what happens if it fails?

CISA funding, renewed for 12 months, is in decline despite being predominantly funded by the US government. If CISA and MITRE lose capability, trust in the vulnerability database collapses, making it harder to detect and patch exploits globally - a critical risk as attackers use AI to identify vulnerabilities faster.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The CISA/CVE section delivers genuinely useful operational knowledge - explaining the vulnerability database ecosystem, naming conventions, and the AI-accelerated exploit threat - but the robotics half is almost entirely platitudes about abstraction layers and agentic workforces. The usable insight per minute is diluted by soft scene-setting and the host's throat-clearing.

attackers are using generative AI to identify vulnerabilities super fast. And therefore they can exploit those so much quicker.
we move from a diagnosis in skin cancer to treatment within 90 seconds

Originality

7 / 20

The claim that routine surgery will be robotic in under seven years is a provocative data point, but it goes undefended. The rest is recycled framing - 'abstraction layers moving up,' software-to-physical analogies, human-in-the-loop governance - that circulates widely in AI discourse. No genuinely contrarian or first-principles argument emerges.

I don't think it's seven years before most surgeries are performed, routine surgeries are performed robotically.
keep an eye on what's happening in the software world... and then think about the next three years of how that's going to start to come through from a the physical world

Guest Caliber

11 / 20

Both guests are working practitioners - a CTO and a security-focused CEO with a stated stake in medical analytics - and Matt Lovell's fluency with CVE taxonomy and the CISA funding timeline suggests genuine domain depth. They are not career podcast guests, but the episode does not fully exploit their apparent operational experience.

I've seen this in one of my other businesses in in medical analytics, where we move from a diagnosis in skin cancer to treatment within 90 seconds
CESA as an organization has lost some amazing talent, particularly recently. We've got people in there, absolute heroes, working for no salary at this moment in time

Specificity & Evidence

10 / 20

There are several concrete anchors - a named CVE class with a specific attack mechanism, a 90-second diagnostic timeline, the 12-month CISA funding renewal, and Tesla/Uber/Nvidia as named spenders - but the episode lacks hard numbers (budgets, incident rates, adoption percentages) and the robotics discussion stays almost entirely abstract.

OpenClaw, you know, a very recent product. It has a CVE in 2026... It relates to a WebSocket hijacking vulnerability
the funding was questioned over 12 months ago. It has been renewed for 12 months, but the funding is declining

Conversational Craft

7 / 20

The host stacks multiple sub-questions into single turns, rarely follows up on specific claims, and accepts answers without any challenge - the provocative surgery-in-seven-years claim lands with zero pushback. The CISA pivot is well-structured and the host plays a useful 'layperson' foil, but the overall dynamic is a soft PR chat rather than a probing interview.

Matt, what are your thoughts on? Do you have any thoughts on robots?
Yeah, I think my understanding is that you know all the systems that we rely on and we keep uh to keep us safe and secure without that kind of body there is going to put those security checks, I guess, at risk.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

matt10robotics10vulnerability10hammond8cesa8lovell7businesses7cisa7robots6security6thank6software6organization6vulnerabilities6important5human5

Episode notes

Robots are getting real, and the business impact is closer than most people want to admit. We pick up the thread on robotics and autonomy and ask what it means when “work” shifts from humans doing tasks to humans directing systems that do them for us. Along the way, we talk about why the first wave won’t be humanoids in your office, but focused, high-value robotics like self-driving vehicles, warehouse automation, and clinical tools that can scale expertise. We’re joined by Mart Rotherham, CTO at BCN, and Matt Lovell, CEO of CloudGuard, to map the transition from today’s AI-powered software to tomorrow’s physical automation. Mark breaks down the idea of an agentic workforce and how abstraction changes job design: fewer hands-on tasks, more responsibility for clear specs, validation, and outcomes. Matt brings it down to earth; human governance, and ethical judgment can’t be bolted on later. Then we shift to the risk side: CISA, the CVE system, and the National Vulnerability Database that so many security tools rely on.

Full transcript

17 min

Transcribed and scored by The B2B Podcast Index.

Matt Lovell: I don't think it's seven years before most surgeries are performed, routine surgeries are performed robotically. Sinéad Hammond: What does that mean for businesses that robotics are becoming a much more important part of the conversation? Matt Lovell: We cannot afford, as a global entity, as a human society, to lose CISA or an equivalent capability. Sinéad Hammond: Welcome back to the AI for Business podcast.

Last time we touched on the widespread adoption of AI technologies, the increasing investment in AI, and the impact of safety with data centers, which process AI, springing up globally and even into space. That momentum is now pushing into something even more tangible and kind of sci-fi, which is robots. And this is moving closer every day to businesses and operational environments. So we're going to talk a bit more about how that works.

And as AI spreads more quickly into organizations, it brings through new responsibilities. Later in the episode, I'll be asking Matt about some important recent developments from the CISA, the Cybersecurity and Infrastructure Security Agency, and what they signal about the risks leaders need to manage alongside innovation. I'm joined once again by Mart Rotherham, CTO at BCN, and Matt Lovell, CEO of CloudGuard. How are you both doing today?

Matt Lovell: V ery well, thank you. All good, Sinéad. Sinéad Hammond: Let's start where we left off last time with a discussion around robotics. So when you talk about healthcare, I listen to someone saying that, you know, if you're training to be a doctor in seven years' time, the training will have to be completely different because by the time you finish your training, there will already be robots and different types of AI being able to kind of replace that learning a bit in that seven-year period because it takes so long to train to be a doctor.

Robot sounds very sci-fi and a little bit like, you know, Hollywood. Should people, should businesses, should C-suite be taking note of this? Should they be listening? And even if they're not going to be like wandering round offices tomorrow, what does that mean for businesses that robotics are becoming a much more important part of the conversation?

Mark Rotheram: I think it it's good to think about it from a an almost work displacement perspective. So we're seeing work displacement and the abstraction layers move up. So if we use you know, we talked a little bit about software development previously, but we still need really good, solid people that understand what software is and how to develop it. But they're being levelled up from writing a specific line of code to writing and validating a really good spec.

I think what we'll see is the robotic kind of capabilities come through, similar things. The things that people do today that they may like or may not like will start to get abstracted from. In the the kind of virtual world, the software world that we spend a lot of time in, the concept is you're no longer a sole contributor, you're a manager, but you're managing an agentic workforce. And I think you can draw a lot of parallels with what's happening with AI and robotics, you're going to be able to think about managing that robotic workforce in a similar way.

So it will take longer to come because physical takes longer from a robot wandering around your office or your factory or whatever it is that you're thinking there. But what we will see between now and the humanoid robots is much more autonomy in things. So that the first wave of things that we will all experience is the car. You know, we saw the latest version of FSD from Tesla launch, which again is another shift in capability to self-driving.

Uber, Nvidia, and a whole swath of people are spending millions on self-driving in that domain. I think what we'll see is point AI robotic solutions start to saturate, like driving and eventually, you know, surgery, things like that. Before we get to the general use robots wandering around and doing things. It's kind of what we've seen with AI in the software land.

You know, it's starting with certain domains and it's slowly encroaching out everywhere else. That's the kind of way that I see it coming. So from a general business perspective, keep an eye on what's happening in the software world and in the the the virtual world and what's what's been happening over the last three years there, and then think about the next three years of how that's going to start to come through from a the physical world. Sinéad Hammond: Absolutely.

Matt, what are your thoughts on? Do you have any thoughts on robots? And I'm also interested in kind of I mean the security concerns, I guess, and again governance and why that's still really important. And I guess kind of not just generating more and more and making it bigger and bigger.

Like we still need to think about these guardrails, I would say, but what what's your what's your kind of opinion, I suppose, on this? Uh many and varied, in a sense that you can take robotics and you can look at the immediate application where we've got driverless vehicles, where we've got warehouse technology where there's no humans anymore, and and that's rapidly accelerating. If you take, if I've sort of ground myself back into healthcare where you started, I don't think it's seven years before most surgeries are performed, routine surgeries are performed robotically.

And I think that's a really good thing, by the way, right? And I caveat that statement fundamentally, and there's always, always got to be human governance. And you know, you see that in the mass acceleration, and I've seen this in one of my other businesses in in medical analytics, where we move from a diagnosis in skin cancer to treatment within 90 seconds, right? And that massively accelerates survival rates for people with melanoma as an example.

If you take the problems in our own health system, where are the pinch points? Where are the key problems? What are the priorities to solve? You look at AE and GP triage and diagnosis, initial diagnosis, how can we use robotics in those forums and particularly remotely as well, where patients either have to travel in and therefore we could alleviate that pressure point.

And also, you know, from a GP point of view, those sort of peak activities where we can use robotics to alleviate those pressure points and release GP capacity for those elements that are human only. And the same for accident and emergency, and the same for other war duties where we can use and leverage robotics to you know understand and relieve key pressure points in resource because it is resource fundamentally in the expertise that we need to be thinking about. We've got to be training the surgeons for the future.

How can robotics help us accelerate? You know, when if you look in the NHS, actually the one of the battlenecks of many, despite how brilliant it is, is actually taking doctors through that experience curve faster. So we've got more specialists in more areas, you know, whether that's physical or mental or a combination. So it's is looking at how robotics can help us move there.

Can will we as a human entrust our soul conversation to an AI agentic process? It's going to vary, right? And it's going to it's going to take time for people to build trust and confidence. If I talk to somebody of my mother's generation, their only conception is that of a physical robot, and you know, they're seeing robots running marathons and various other sort of news headlines, and they're going, Well, they're almost there in physical capability.

You're absolutely right. But can they perform autonomous tasks that that involve cognitive reasoning and some of the other capabilities that we need? Can they make those split-second decisions that are based on other people's judgment and make them correctly? You know, you've only got to drive on the motorway, you know, in bad weather to understand how difficult a autonomous system would find it, you know, if suddenly another vehicle had an issue in front of you and you've got to take evasive action.

Humans have such an advanced capability in respect of responding to those. And it's just understanding how we put additional guardrails in place to accelerate specific targeted robotic use and build trust and confidence from there. Sinéad Hammond: Yeah, there's that big question about whether AI will or should or will ever be able to make those ethical decisions. And I think that's part of what you're saying there as well.

And that kind of, and we talked about judgment in the past, but those judgment decisions that have kind of consequences. That I I actually had a chat with my AI last night to find out how close it was to that. And I think the the premise is that in it will always be a tool to assist as opposed to a tool to make those kind of bigger moral ethical decisions that humans then stay in the loop to do that. And we've spoken about that a lot recently.

So, Matt, I know that you mentioned uh the CISA, and for people who aren't listening, who are you know not in security and listening to these sorts of updates day to day, in plain English, kind of what is happening at the moment, what does that mean? Something that's happening out in America, what does that mean for us? And then what does that kind of mean for a business on a business level and how we adopt and approach our use of AI? Matt Lovell: Great question.

And I will try to break down this because it is quite a large topic for the audience, and I'm going to assume a relatively low understanding and bear with me while I try to build the different blocks that tell you the story. Sinéad Hammond: So convince me I'll be your level, buffer. Matt Lovell: Okay, so the US Cybersecurity and Infrastructure Security Agency, or CESA, as it's easier to say, has and is an absolutely mission-critical organization for all of us, every single one of us.

Let me explain to you and obviously to you, Sinead, and try to convince you. So, like with a lot of things globally, we need to have a standard that defines a security vulnerability. Okay, so we call that the common vulnerabilities and exposures or CVEs for short. So when a vulnerability is identified anywhere in software, in an API, in an interface, in an application, in a bit of code, if it is known or unknown, then it is classified, it has a severity rating, and it's documented in a standard reference system.

Okay, and then that can be shared with everybody very quickly in terms of understanding this unique identifier and vulnerability and the properties associated with it. So the general annotation is you have a CVE, you have the year that it's been identified, and then it has a reference number, usually five digits, etc. So you would have, for example, OpenClaw, you know, a very recent product. It has a CVE in 2026, you know, because it's just been identified.

It relates to a WebSocket hijacking vulnerability. So it's, you know, it's behaving under the user context, and that can be hijacked, and they can actually siphon or exfiltrate data from that. So it's a pretty severe vulnerability. And the vulnerability database itself is therefore mission critical to us all.

And the US has formed a very big part of this with the MITA organization. People have heard of the MITRE attack framework, it's the same organization. And CESA and the MITA organization work together to put this database and make that publicly available for people. But it's predominantly funded by MITA and CESA, which is funded itself by the US government.

Now, that funding was questioned over 12 months ago. It has been renewed for 12 months, but the funding is declining, right? And we are all, all of us, every single individual employee, business, you know, and people using devices in their own homes suffer from TVEs, right? We are all dependent on those being known to people publicly.

Now, the US is saying everyone should contribute to that. And I agree with that principle, right? We are all reliant, we're all dependent, we're all benefiting from the service that CESA provides. CESA as an organization has lost some amazing talent, particularly recently.

We've got people in there, absolute heroes, working for no salary at this moment in time. And therefore, the long-term benefit that we all derive from that is in question. And we cannot afford, as a global entity, as a human society, to lose CSRO and equivalent capability. One, because it's super trusted by people that find these vulnerabilities and tell us all about them.

And two, this database is used by pretty much universally every vulnerability service that I know of to tell us what's going on. So the national vulnerability database, or the MVD for short, is where all of this ends up. And it isn't just about here are the vulnerabilities, it's about this is how severe, this is where it was most recently exploited, it's full classification, loads of references on how to patch and remediate it from the vendors themselves, and exploit vulnerability indicators.

Why is that the most critical piece of information? I hear you ask, Sinead. And the simple answer is that attackers are using generative AI to identify vulnerabilities super fast. And therefore they can exploit those so much quicker.

And if we haven't updated, if we haven't patched, if we're not even aware that vulnerability is a problem for us, it can be exploited without our knowledge and without any form of detection. And it could be a living off-the-land attack or it could be some other data exfiltration that takes place, and that's super bad for any of us. That's why this is so critical. If we don't all get behind this, if we don't all support CESA, if we don't contribute, you know, if we're using this insight and innovation, then CESA is in question.

And the loss of CESA and the trust of that will be really difficult to replace. That's why that headline is so important. Hopefully, I've convinced you. Tell me.

Sinéad Hammond: Yeah, I think my understanding is that you know all the systems that we rely on and we keep uh to keep us safe and secure without that kind of body there is going to put those security checks, I guess, at risk. Is from the most the most basic way I can explain what I think I understand from that. And I think then from a business decision level or from a business owner level, are there any things that we need to consider or think about based on the fact that maybe this is, I mean, you're saying we need to contribute more, but is there things that we need to think again about?

You know, is it we need to be better at risk mapping or we need to make sure we're keeping our patching up to date, or all of those different types of things? Like what would you make as a essay as would be the key bit of advice for that? Matt Lovell: Look, the the format of CISA Sinéad has worked super well. And we absolutely need some kind of centralized source.

If you think about how AI is working in the language models and the large action models, etc., and they're culminating that together in the training capabilities at a global level. We need the same for vulnerabilities. We've got that for vulnerabilities in what CISR and MITA provide to us by contributing to it, by seeing the long-term strategic development of that organization and the amazing work that those individuals within there are doing right now as an absolute trusted source of that information is super critical to keeping you and everybody else safe at this moment in time.

That's how I would put it back to you. So, do we need another CISA? No, we we need CISA, right? And therefore, let's get behind that and let's resolve this problem so we can go forward rather than backwards.

Sinéad Hammond: Right. I'm gonna leave us with that. I'm gonna take that as an open opportunity for people to learn a little bit more about CISA going forward and look at what what's going on and what we can do and how this all fits in with our own businesses. This has been a really interesting episode.

Thank you so much, both of you, for joining. I always learn so much on these because there's just so much going on and so many headlines that I'm not able to keep track of. So I do really appreciate you taking the time to talk us through and help us understand a little bit more about what businesses really should be um listening to and looking out for and what we should be monitoring. Thanks again for both being here.

Um, thank you to our listeners for listening and tuning in. If you would like to catch previous episodes, then you can check out our website at bcn.co.uk.

You'll also be able to subscribe to future episodes that we do in this podcast series. So, once again, thank you so much, and we'll see you all again next time. Thank you. Cheers, thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Evolution of Crash Test Dummies: Ensuring Road Safety with Chris O’ConnorAVL's Reimagine Mobility Podcast · on Autonomous vehicles86 / 100
  • 3D HMI in automotive: opportunities, challenges and the future of the industryShine: a podcast by Star · on Autonomous vehicles75 / 100
  • Pricing, Data, and the Future of Insurance: A Conversation with Michael NadelBanking on Information · on Autonomous vehicles74 / 100
  • SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop EngineeringSecurity Now · on CISA (Cybersecurity and Infrastructure Security Agency)69 / 100
  • AI's Double-Edged Sword: Risks, Rewards and Race Dynamics in Cybersecurity with Dr. Joanna SantosParadigm Shock · on CISA (Cybersecurity and Infrastructure Security Agency)69 / 100
  • Can a machine teach itself to think like a human?Founder Vision with Clearview · on Autonomous vehicles68 / 100

More from AI for Business with BCN

All episodes →
  • The Real AI Opportunity Is Hiding Inside Your Business78 / 100
  • Why Big Tech Is Spending Billions On AI53 / 100
  • AI Means “Knowledge Work Is Cooked”, How Should Leaders Respond | Mark Rotheram, Rowan Gill53 / 100
  • “If Your Job’s on a Computer, It Will Change.” Here’s What to Do Next | Mark Rotheram | Ep 172 / 100
  • AI That Delivers for Business: Building your Agentic Workforce75 / 100
Explore the best B2B AI & Data podcasts →
All AI for Business with BCN episodes →