The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Blue Security
Blue Security artwork

Helping or Hurting? - An Honest Conversation About AI

Blue Security · 2026-06-30 · 1h 4m

0:00--:--

Key moments - from our scoring

Substance score

39 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber5 / 20
Specificity & Evidence11 / 20
Conversational Craft6 / 20

Andy Jha and Adam Brewer examine whether AI is genuinely helping or hurting the security industry and broader economy, moving beyond hype to confront uncomfortable truths. They dissect Brad Smith's reassuring historical analogy (cameras didn't kill painting; email didn't kill writing) against harsh realities: portrait painters did go out of business for a generation, and the gap between job displacement and creation carries real human costs. The conversation exposes how major tech companies - Meta, Amazon, Microsoft, Alphabet - are using AI as convenient cover for workforce reductions driven primarily by staggering $725 billion infrastructure capital expenditures (75% increase year-over-year), not actual productivity gains. Meta's chief people officer memo reveals the truth: companies are choosing to buy GPUs instead of keeping people. Brewer argues that layoffs serve Wall Street narrative-building more than operational necessity, noting that firing Meta's entire 27 billion-dollar payroll wouldn't cover even one year of their 145 billion-dollar AI infrastructure budget. Both hosts acknowledge AI's real value in security workflows while warning that the tech industry faces unprecedented backlash - from college graduates booing AI mentions to data center opposition in previously supportive communities - driven by perception that tech leaders are using AI as a scapegoat for decisions driven by shareholder pressure, not technological inevitability.

Key takeaways

  • →Recent tech layoffs (Meta, Block) are primarily driven by infrastructure investment choices and past overhiring rather than AI actually replacing jobs yet, despite companies using AI as a convenient justification.
  • →Only 31% of US working adults use generative AI currently, suggesting adoption is slower than headlines indicate and concentrated among a small group of early adopters.
  • →The tech industry faces growing public backlash extending beyond AI to broader concerns about corporate practices, data centers, and societal impacts, making AI an attractive target for accumulated tech sector criticism.
  • →Nearly half of S&P 500 market capitalization depends on AI stocks, creating systematic economic risk where a single earnings miss or sentiment shift could trigger a market-wide deleveraging event.
  • →The historical pattern shows technology displaces jobs in specific sectors (portrait painters with cameras) while creating jobs elsewhere, but the gap and burden fall on displaced workers during the transition period.

In this episode

  1. 1AI Technology in Practice: Real-World Impact and Concerns
  2. 2Brad Smith's Historical Technology Framework and Five Critical Skills
  3. 3Job Displacement Claims vs. Financial Reality of Corporate Layoffs
  4. 4Wall Street's AI Bet and Systemic Economic Risk
  5. 5Tech Industry Backlash and Changing Public Perception
  6. 6Alternative Approaches: Voluntary Retirement Programs Over Layoffs
  7. 7The Gray Area: AI as Both Tool and Scapegoat

Mentioned

MicrosoftBrad SmithSatya NadellaRiversideEric SchmidtMetaAmazonAlphabetBlockJack DorseyDebbie O'BrienJanelle Gale

Topics in this episode

Brad Smith Microsoft policyAI job displacement narrativesGenerative AI adoption ratesData center expansion in IowaBlock and Jack Dorsey layoffsMeta infrastructure investmentS&P 500 AI concentration riskDebbie O'Brien Applied AI layoffsJP Morgan systematic risk analysisDeutsche Bank AI dependency analysis

Questions this episode answers

Why are major tech companies laying off employees if AI isn't actually replacing jobs yet?

Layoffs are primarily a financial decision driven by massive capital expenditures on AI infrastructure (companies spent $725 billion in 2025, a 75% increase). Meta's chief people officer explicitly stated the cuts allow the company to offset infrastructure investments; firing everyone wouldn't cover even one year of their $145 billion AI infrastructure budget, so layoffs serve as a convenient scapegoat for decisions rooted in shareholder pressure rather than AI capability.

What are the five key skills that matter in the AI world according to Brad Smith?

Curiosity, creativity, compassion, communication, and courage. Smith's advice is to categorize your tasks into what AI can do, what you can do with AI, and what only humans can do, then focus on the last two categories.

What percentage of US working age adults are currently using generative AI?

Only about 31% of US working age adults are currently using generative AI, according to Microsoft's AI diffusion report, suggesting the actual adoption rate is slower than headlines suggest.

How much of the S&P 500's market capitalization is tied to AI-linked companies?

AI stocks account for approximately 45% of the S&P 500's total market capitalization. If AI-linked companies were stripped from the index, the gains over the past two years would collapse from 142% to just 16%.

What warning did JP Morgan Global Research issue about concentration risk in the stock market?

JP Morgan warned in January 2026 that the top 20 stocks now command more than 50% of the S&P 500 index, and a single earnings miss or shift in AI sentiment among that group could trigger a deleveraging event that pulls down the entire market.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains several genuinely useful data points - AI code security degradation stats, exploit timeline compression, and a nuanced capex decomposition - but these are interspersed with long stretches of general opinion, personal anecdotes, and meandering tangents that dilute the density considerably. Maybe 20 minutes of substance in 64 minutes.

the meantime from CVE publication to a ah, working exploit back in 2024 was only 56 days. In 2025 it has been reduced to 23 days and now in 2026 it sits at 10 hours
45% of AI generated code actually contained OWASP top 10 vulnerabilities. Now even after two years of model improvements, that number hasn't moved

Originality

8 / 20

The framing of AI job cuts as financial scapegoating rather than genuine automation, and the specific capex accounting nuance (half going to long-lived assets), are moderately fresh angles. However, most of the discussion - Brad Smith's 5 Cs, China threat, sycophancy critique - recycles widely circulating takes without adding genuinely new frameworks.

AI is a convenient kind of boogeyman, but also as peacocking for Wall street, where you are suggesting, and I do not think this is remotely true, that we are so far down this path we are able to displace thousands of jobs with AI
about half of that capex goes to what we refer to our uh, long lived assets... Things that last a long time, like we're talking decades or more

Guest Caliber

5 / 20

There are no guests - only two co-hosts who are Microsoft security sales employees. While they have relevant industry proximity, they are not senior practitioners, researchers, or executives who have operated at scale in security or AI; much of the authority comes from proximity to their employer rather than personal depth.

Andy and I both work for Microsoft in our field, security sales
we do. I'm going to open up with Brad Smith who is a Microsoft, um, vice chairman and president for Microsoft

Specificity & Evidence

11 / 20

The episode does cite named studies (Vera Code, MIT), specific companies (Block, DeepSeek, Meta), named individuals (Janelle Gale, Debbie O'Brien), and concrete figures (OWASP failure rates, capex totals, S&P 500 concentration). However, several citations are loosely attributed and some numbers appear imprecise or unverified in delivery.

Meta's entire global payroll is about $27 billion. Their AI infrastructure budget is about, about 125 to $145 billion
Vera Code is one of those code security tools. Their company and they tested like a hundred LLMs across 80 coding tasks. And they said that 45% of AI generated code actually contained OWASP top 10 vulnerabilities

Conversational Craft

6 / 20

This is a collegial two-host conversation where both parties largely agree with each other throughout; there is no real probing, challenging of claims, or productive disagreement. Andy largely sets up topics from prepared notes and Adam riffs in agreement, with the format functioning more as co-narration than genuine interrogative dialogue.

Yeah, no, I think, I think it's a fair point right
I hadn't even read down that far in the time, um, the rundown, dear listeners. I brought up Block and Jack Dorsey. It was kind of throwing shade at it. And I didn't see it was three bullet points down

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C56%
  • Speaker B43%
  • Speaker A1%

Most-used words

microsoft31security22point21code21back20models17whole16answer16show15adam14capex14model14tool13trying13part13andy12

Episode notes

Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer engage in a deep discussion about the implications of AI on society and the security industry. They explore whether AI is ultimately helping or hurting us, particularly in the context of job displacement and creation. The conversation delves into corporate strategies regarding AI investments, the financial implications of these technologies, and the broader backlash against the tech industry. They also analyze the economic landscape surrounding AI, emphasizing the need for a nuanced understanding of its impact. In this conversation, Adam Brewer and Andy Jaw delve into the complexities of AI investment, the competitive landscape posed by Chinese AI advancements, the implications of AI sycophancy, and the rising security risks associated with AI in social engineering. They also discuss the challenges of code security in AI development, emphasizing the need for robust security measures as AI-generated code becomes more prevalent.

Full transcript

1h 4m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. Welcome to the Blue Security Podcast, a weekly podcast for information security defenders where we bring you discussions on best practices, tools and implementation for enterprise security. Now here are your hosts for today's show, Andy Jha and Adam Brewer.

Speaker B: Welcome to this week's episode of the Blue Security Podcast. I'm Andy, your host.

Speaker C: I'm Adam, your co host.

Speaker B: I'm super excited to have this conversation with you Adam, because it's something that I've been thinking about for a while.

Speaker C: Mhm.

Speaker B: Reading about AI and so it's really, we'll call it an honest conversation about AI, whether AI is helping or really hurting us in the security industry as a society as a whole. Um, I know that you probably have a lot of thoughts on it and so. But before we get started let's do our standard disclaimer because we do. I'm going to open up with Brad Smith who is a Microsoft, um, vice chairman and president for Microsoft. Uh, he's like one of our, basically our chief legal guy. And uh, and so you know Adam and I both work with Microsoft so let's just do our standard claim disclaimer before we get into it. Yeah.

Speaker C: Brad at this point is pretty much second in command to Satya. If Satya took a leave of absence, Brad would mostly lead the company as a whole. So Andy and I both work for Microsoft in our field, security sales. However, we record the show outside of work on our own time and we self fund this show. The opinions you're about to hear expressed are those of Adam Brewer and Andy Jha and do not necessarily reflect those of Microsoft Corporation itself. And with that on with the show.

Speaker B: Yeah. So you know, when I wanted to, when I started thinking about this conversation, like really everyone who's listening to this already kind of knows. Right. AI is a real tool, it's doing real work. And you know, none of us are really disputing that. Adam and I record this show on a platform called Riverside. We have kind of touted the capabilities of Riverside and how the AI editing has really helped us save a lot of time. And so this, there's examples of this all throughout but I think if you look at kind of the real world, there's really something that shifted and I, I really saw it a lot with the college graduation speeches. Right. Like there were so many examples of um, like former Google CEO spoke, um, Eric Schmidt, he spoke at the University of Arizona. Um, Claudia Gloria, uh, uh, Codfield which was a Vice president of Strategic alliances at Tavistock, spoke at University of Central Florida's graduation. Scott Perchella, who is CEO of Big Machine Records, spoke at Tennessee State University. And at all of those, when they started mentioning AI, they were booed, right? And Ronnie Chang, who's one of my favorite comedians, he spoke at Harvard. And when he spoke there, he was like, you know, basically, uh, f, you know, AI, he's like, you guys need to save society from AI. And there were cheers from these Harvard graduates. So there's that whole shifting mindset of like, really not a lot of people are liking AI. There's real people who are losing jobs because of it. There's this whole new shorthand that's spreading. Um, you know, like tldr, right? Like too long, didn't read. There's a whole AI doctor which is, you know, like AI didn't read, right? Like, because now a lot of people are assuming that the content that they encounter online is machine generated unless proven otherwise. The code that's being shipped by AI is measurably less secure. Um, and a lot of times not as good, right? Like I play an online video game and one of the patches that happened recently was actually really terrible. And my initial thought was a lot of people are vibe coding over there and they're putting out just really terrible code. And AI, uh, itself is also making you believe things that aren't true, like deep fake voices and stuff like that. So really what I wanted to have this conversation about is really is AI helping or hurting us? Not the technology, like in theory, but the way that we're deploying and using it right now. And Brad Smith recently authored, um, he has this whole blog called Microsoft on the issues. Really good blog. Um, talks a lot about, um, just in general, like legal issues, geopolitical issues, kind of like thought leader stuff. And he had a, ah, really pro AI argument coming out of this, his recent blog, uh, this month, which was on June 10th. And um, his historical argument was really if you look back on technology, like the camera, you know, and taking pictures, didn't kill painting or email, didn't kill writing and spreadsheets, didn't replace accountants. All of those tools kind of made things more powerful. Like they made accountants more powerful. And technology might displace work and some places, but it creates work in other places. So now his advice was really stop thinking about your, your job as a title, but think about it as a bundle of tasks. Sort them into what AI can do, what you can do with AI and what only humans can do, and then focus on like the last two of those, right? Like what you can do with AI. And what humans, only humans can do. And, and he said that five skills matter in that matter in the AI world are curiosity, creativity, compassion, communication, and courage. And the data he's working with, obviously It's Microsoft's own AI diffusion report says that only about 31 of US working age adults are currently using generative AI. So the diffusion is slower than what a lot of headlines suggest. And I do think that, that um, I actually saw um, like a Instagram reel or TikTok recently that also kind of said the same thing, that there's a very small portion of the general population that's actually using generative AI. And really like a very, very small portion of that are like people who are using it for like, you know, really powerful coding and, and, and all of that. So, but you know, again, if as you think about this holistically, as I wanted to think about this, kind of like a steel man type, if it's, it is reassuring if you, most of your tasks land in that bucket like two and three, where you think about what you can do with AI and what humans can only do. But it's obviously a lot less reassuring if you're in some sort of entry role where a lot of the tasks land in bucket one. So think about like paralegals and you know, call centers and stuff like that. His answer to those people is really develop AI fluency, uh, fluency, pursue your passions and adapt. Which is reasonable advice, but also kind of, you know, arguably it serves Microsoft's interests really. Like the camera didn't kill the painting, but it did absolutely put portrait painters out of business for an entire generation. And those new jobs took a while to emerge and materialize. So, you know, one of the harder questions, um, to ask about his piece is really how long does that gap between displacement and job creation last? And then who carries that cost? While we wait, your thoughts, Adam?

Speaker C: So I'm a big fan of Brad Smith in general at, uh, Microsoft. He kind of comes in with this elder statesman perspective on things. He is a, he's a great leader and he generally, when Microsoft brings him in, it's when they need like a reassuring, almost grandfatherly tone. And if you don't know the history of Brad Smith and Microsoft, he came in during all of Microsoft's disputes with the federal government around, uh, the antitrust hearings. And his message was, it's time to make peace, it's time to settle. That was his job. Pitch to Bill Gates, the Microsoft board, Steve Ballmer. It's time to make peace because very famously, people Like Bill Gates were very antagonistic and wanted to fight it to the very end because they absolutely felt like it was wrong. And he was more like, let's settle, let's make peace, let's move on. And that's ultimately what he did, by the way. He helped Microsoft, like forge an agreement with the, uh, federal government that did not involve splitting the company, which was originally what it said, by the way, was there was basically going to be the Windows company and there was going to be the Office company and Bill was supposed to run one and Steve Ballmer was supposed to run the other. That, of course, never came to happen because Brad Smith settled. Anyhow, back to the point at hand. In general, I like his framing here. I think it is useful. And I, uh, will just say from my perspective, a lot of the talk around, like AI eating jobs, and I think we're going to get to that more in a moment, is a useful distraction from the real reason there are job cuts. Because to be honest, a lot of these companies have had a really hard time justifying why are you eliminating jobs when you are recording record profits and record growth and record everything. Because the previous framework was you only cut jobs when your company was struggling. You never did job cuts if you were doing well, you just didn't do it. And they become very popular for a variety of reasons that are really not germane to this show's subject. And AI is a convenient kind of boogeyman, but also as peacocking for Wall street, where you are suggesting, and I do not think this is remotely true, that we are so far down this path we are able to displace thousands of jobs with AI. I don't think that is happening anywhere today. Is that theoretically possible? Someday, maybe. But I still think there'll be a tremendous amount of human oversight. I think of it, you know, as I don't even have the words to explain it, but more like you, you still need a human to bridge that gap, to be that connective tissue. There's going to be some tasks that AI may eat that are relatively straightforward. Um, but you're still going to need someone to stitch it all together and to do kind of the five Cs you were talking about there that Brad articulated. Curiosity, creativity, compassion, communication and courage. And I, I believe in that wholeheartedly as well. So, you know, here's the thing. Microsoft built its business on Windows and Office. And the idea that every person in every business in the world, someone gets hired, what do you do? You give them a PC running Windows and running Office. And that's been good for Microsoft's business. If that goes away, that's not good for microso. If you are have fewer people in the Office, which means we are buying fewer PCs, which means fewer Windows sales and you're selling fewer copies of Office, that is not a good thing. And if you are replacing it with maybe some sort of Azure consumption, that's potentially you're trading one thing for another. You haven't really grown, you're just selling a different widget. That's not necessarily a great thing. So I think you can, with all of that context, you can form your own opinions on how much to take stock in this. But I think overall it's not really something we want to do. And I will just say, me personally, as someone in sales, I have had customers absolutely say, like, I'm not interested in AI unless it lets me get rid of jobs. I'm not, I'm not interested unless I can literally like making people more efficient doesn't mean anything to me because they still have to pay them money. And it's like, well, what if they're more efficient? They can sell more widgets for you. And I've had people basically push back on that and say, unless I can eliminate that job, it's not valuable to me. So. And it's like, well, we're nowhere near that and to be honest, we don't want to do that. That's not something we want to sell. That's not how we want to sell. Um, so as much as you've got these I think very tone deaf tech leaders in other parts of the industry, you're not your Brad Smiths who are saying things like that. I think the reality on the ground is most people aren't comfortable with that concept yet. And while Jack Dorsey over at ah, whatever his company's called that owns Square Block. Thank you. You know, wanted to make a bunch of big sexy headlines like I'm cutting 50% of my people because it's all AI. That is absolute nonsense. He has not found some AI secret sauce to get rid of 50% of his jobs. I assure you of that. He overhiered and he didn't want to say that, or he's just trying to be more lean or whatever and it's just not attractive to do because Americans by and large don't accept layoffs as a natural consequence of a company that is doing well. Uh, and so they're trying to find a new justification for it. And I think so much of this is that. And I Think so much of it are people trying to be right and trying to plant a flag so they can point back to a tweet six years from now and see, like, see, I told you this was going to happen. And for any of our listeners who don't really follow, say, like, Wall street that closely, or financial markets, this same kind of person, this same kind of vulture has been around financial markets forever. Um, there is always someone telling you that a bear market is going to start tomorrow and you should sell everything and that this stock is going to zero and this company is doomed and everything else. I mean, I remember people saying forever and ever how doomed Apple was, how Android was going absolutely kill Apple, and they had no future. And Apple was doomed, you know, when they were selling hundreds of millions of iPhones a quarter. And it was just nonsense. And so my point is, doomers will always exist in various industries. And I think in tech, it's a relatively new concept to us because tech has always been so hopeful and so optimistic that the challenges that we face today can be solved by the technology of tomorrow. And it's the first time where we've kind of gotten so high on our own supply that people are rightly calling us out on it. And now this is even extended to something close to me, things like data centers. My hometown, my wife's hometown in Eastern Iowa, both have data centers coming in. And it's extremely contentious. And this is so odd to me, because here in Des Moines and West Des Moines, Microsoft has been here for 13 years. And I think if you would have gone and asked a bunch of people three years ago in Des Moines, they would have had an overwhelmingly positive perception of Microsoft and what the data centers have done for our region, our city as a whole. And now the AI backlash is really caught up with the data centers as well. And so it's not just AI itself. It's like the whole tech industry is really facing a backlash and a reckoning like it hasn't even seen. And. And, you know, that's been growing for a while with, like, dissatisfaction with Meta and with Google and with the potential political, uh, ramifications in the United States and other countries around the world, and how it's allowed very fringe groups to gain mainstream attraction, that. That's been growing too. Like, all of this has been festering. And I think AI is a really attractive target for all of this growing vitriol. And it's all kind of come to a head right now. Um, and it's a really interesting moment where for the longest Time, I mean, working in technology was like, you won the lottery. Like, man, good for you. You work for a big tech company. That's awesome. How cool can you get me on? I would love to work there. And it's kind of the first time in my life where I'm not going to say like, I'm ashamed of where I work. I'm certainly not. But it hits different than it used to.

Speaker B: Yeah.

Speaker C: And that's, that's been a, uh, kind of a wild moment to go through as well. And I think you have to consider all of that big picture when we're talking about this because it, it's kind of bigger than just AI. It's the whole tech industry as a whole. And it's the easiest, most obvious target. And I think that's where a lot of this is coming from too.

Speaker B: Yeah, I think you're right. You know, as we kind of roll into that second point that I was, that I was trying to make is, um, you kind of made it for me. Right.

Speaker C: Jack Dorsey in here. I hadn't even read down that far in the time, um, the rundown, dear listeners. I brought up Block and Jack Dorsey. It was kind of throwing shade at it. And I didn't see it was three bullet points down from where we were.

Speaker B: Yeah, yeah. I mean, like, uh, the numbers were he, he cut roughly 40% of the workforce in February and then the stock rose 20% after. Yeah, right. And. And one of those people that was laid off was this developer that, you know, she was actually kind of made famous by the whole layoffs because Debbie o', Brien, she was a senior developer relations engineer in Applied AI and she joined Block just a few weeks earlier to help developers adopt AI workflows. And, and then she found out that her job was eliminated, you know, quote unquote, because of AI. And so, you know, there have been quite a few layoffs, of course. Like there's also the whole, you know, economic kind of downturn in general, unemployment and stuff like that. But we are on pace right now to have more layoffs than we had in the previous year in 2025. And so if you look at the investments that these large companies like Meta, uh, Amazon, Microsoft, Alphabet have made in the capital expenditures. So we're talking about Capex here for infrastructure, $725 billion, which is a 75% increase over last year in 2025, which, you know, like you said, Adam, um, has mostly been directed towards AI data centers and infrastructure. Um, Meta's entire global payroll is about $27 billion. Their AI infrastructure budget is about, about 125 to $145 billion. So if Meta fired every single employee, it would save $27 billion, but they would still have to fork over $145 billion infrastructure check. So you, I think you, you're, you were hitting on this point, right? Like, the layoffs are not really about kind of replacing AI job, uh, like replacing jobs with AI.

Speaker C: Not yet.

Speaker B: Not yet. Right. At least not yet. We might get to that point. Maybe in some industries it is, but in the majority of industries it's not. It's a financial decision because they have to invest in infrastructure cuts, you know,

Speaker C: even to that point. And you just gave the math on, like, you could. Meta could get rid of its entire workforce and it would still only, um, touch, uh, 20% of this year's capex.

Speaker B: This year.

Speaker C: One year. It's not like they're going to just say, like, oh, we've done, we have solved CapEx, you know, we're not building anything next year. And, and now you have no people to get rid of. So, you know, it's, it's a small part of that for sure. But that, that is something I like to point out to people is when they're like, well, they're laying us off to afford all this capex. Like it that the math doesn't. Math. It's a convenient excuse. Even the financing thing you're about to touch on with the Meta's, uh, chief people officer, like, even that's kind of a cop out because it doesn't really even pay for that. It's just we overhired and we're tired of telling people we just want to get smaller because American companies typically have not laid people off when business was good, and they just don't want to keep doing it because it doesn't look good. It's not a good look. And I mean, are our employers not immune to it?

Speaker B: Yeah. So there was an, uh, internal memo that was leaked from Meta's chief people officer, Janelle Gale. And it, you know, as part of that memo, I said the cuts are part of our continued effort to run the company more efficiently and allow us to offset other investments we're making. So she's not in, in her memo, she wasn't saying that AI is replacing the work. She was saying that the company is choosing to buy GPUs instead of keeping people. Yeah. So, yeah. And it's funny, I. This has happened to me. This happened to me back when I was in the Military. Right. Like, I was technically rift from the Air Force because the Air Force needed to fund F22s. And so at the time, you know, like, there was either where do we find the money? And they had to basically, uh, rift people because of that. So it's the same concept here.

Speaker C: Yeah, absolutely, it is. And I mean, it is part of it. I'm not being dismissive of, like, this is not at all a, a financing effort here. I think that's part of it. And I think part of it is a scapegoat. And it, it's, it's more than one thing. Right. And, and that's the whole difficulty with this conversation is all of this exists in shades of gray. None, uh, of. There is no smoking gun. There is no black and white answer to any of this. It's a complex, multi, multifaceted conversation. And that's, I think, part of why it's so hard, especially in our modern environment, a, ah, highly charged, politicized environment where we like to pick sides. Are you blue or red? Are you a patriot or not? Are you this or that? And none of this is that clear at all. As you led the show. Absolutely. AI tools have value and are helping streamline and make more workflows more efficient. Are they helping in cybersecurity in some ways, absolutely. Yes. Is it making cybersecurity harder in some ways also? Yes. And with this, it's all of the same thing of like, is it a financing tool? Sure. Is it a cover? Sure. Is it all of those things? Yes. And, you know, you look at, again, kind of going back to our employer, I think they're trying other ways. Microsoft, um, very famously announced a voluntary retirement program. And I'm seeing anyone who took that their last day at Microsoft will be June 30th. And so a lot of people who took that are now making that announcement on LinkedIn, you know, the very famous, like, here's a picture of my badge. And after 15 years, I'm hanging it up and, you know, looking to my next adventure, more to come soon kind of post. We're seeing a lot of those right now. So in general, the tech companies continue to look to get more efficient and to get smaller. I think all of them still want to continue to get smaller and, you know, kind of target the roles they want moving forward. And those might be different roles than they wanted to focus on even three years ago. And so they're, they're trying different ways to do that. And so I appreciate, I think a voluntary retirement program is a Much better tool to do that. And I appreciate that Microsoft is trying to find other ways that don't involve layoffs here, uh, but it's still part of the same trend overall. It's just a different tool to accomplish it.

Speaker B: Yeah, and you mentioned Wall Street, Adam. I think that that is something that, you know, if you're not paying attention to, you definitely should because a lot of the US economy is tied to AI in general. Whether it's chip manufacturers, whether it's AI companies that are LLMs, whether it's infrastructure. There's, you know. Right now AI stocks account for approximately 45% of the S&P 500's total market capitalization. If you strip out like AI linked companies from the index over the last past two years and the gains, they'll collapse from 142% to just 16%. So nearly half of the most widely tracked equity benchmarks on the planet are riding on a single technology thesis. We have essentially a huge bet on AI, uh, in the American economy. The JP Morgan Global Research issued a warning in January 2026 and it said the top 20 stocks now command more than 50% of the index. And a single earnings miss or shift in the AI sentiment among that group could trigger a deleveraging event that will pull down the entire market regardless of what other 480 companies are doing. So out of the S&P 500, only 20% of those are over 50%. The federal uh, Reserve actually lists AI as a top systematic risk. Deutsche bank warned that without AI driven capital spending, the US real GDP growth is near zero. The AI Capex boom is structurally entangled with the US economy in a way that has never been seen in other historical presidents. So one of the questions that nobody wants to answer is what does this bet actually need to return in order to, you know, to get into it? So if you take like Nvidia's data center revenue and then double it to reflect the total cost of ownership, double it again for like gross margin operators needed to justify the investment. In 2023 the required annual revenue was $200 billion. By mid 2024 it's $600 billion with 2026 capex at 725 billion. Across those five spenders that we talked about, the required number is even bigger than that. So actual AI end user revenue across the entire industry estimated to be in the tens of billions of dollars. So infrastructure investment is running on the orders of trillions in the upcoming like five years and so on the end user revenue, it'll need to be on the order of tens of billions of dollars. Right.

Speaker C: And yeah, pause there for one second. So we have a group chat that we have with uh, a couple of other buddies, Andy, who were in your same role back in the day and now we've all gone on to do different things but we still stay close. And I forget who shared it, maybe it was you Andy, or maybe it was someone else. But there was a link to this website that was basically like has AI made any money yet? And it was like no. And it basically comparing and, and I, I nitpicked this and so I kind of want to nitpick this on the air. Um, it was effectively taking all stated Capex and so all Capex and it was saying that is AI Capex. Well let's, we'll get to that in a second. And then it was saying AI revenue and it was comparing those two numbers. Now here's why that's not entirely a fair comparison and I'm not trying. And even when I make this argument you're going to understand like this doesn't undermine the point, it just adds a little more detail to it and it maybe makes it less grossly crazy. But anyhow, let's just unpack, um, this. So speaking of Microsoft obviously has quarterly earnings as a publicly traded company. And our CFO and CEO Amy Hood and Satya Nadella respectively get uh, on that earnings call and they, they share information. Now earnings calls are very unique. Obviously they are effectively required by the sec, kind of not you have to, you know, report your earnings in a, you know, like a balance sheet and all that. Um, I don't know if you have to host an earnings call, but if you do then obviously everything you do needs to be 100% honest. Right? Like you can't fudge stuff in an earnings call because it is regulated by the securities and Exchange Commission. And one of the things that is stated on every single Microsoft earnings call is about half of that capex goes to what we refer to our uh, long lived assets. Now I am not a finance person, I am not an accountant, but our CFO goes on to explain those are things like as an example, land, buildings, H vac systems, connectivity, things that aren't going to just cycle out like on a technological cycle like a CPU or a GPU where you need, you know, the latest and greatest. And it gets slow and old very quickly. Things that last a long time, like we're talking decades or more. Potentially half of the spend is that like obviously it costs a lot of Money to acquire land costs a lot of money to build data centers. It costs a lot of money to build the infrastructure for data centers. It costs a lot of money to cool um, those data centers, especially with modern closed loop cooling. Now all those things aren't like GPUs, they have to keep going and you know, feeding the Nvidia money furnace every three years, right? Like they do last a while. So that part is like not completely like fair when you're like well you have to generate a return on all of that every single year. Well no you don't because that's uh, all, that's a 20 year asset, right? So if you're going to make that Money back over 20 years, you're doing fine and you can capitalize it and depreciate it and all that and those great financial things that I am not super knowledgeable about. The other part of it is AI workloads drive other workloads. So like in the example of Azure to, for, for all the inference you may be doing in say like the azure open, uh, OpenAI service where you're hitting OpenAI APIs with tokens and you're getting tokens back like the actual AI inference stuff. To do that you still need very traditional infrastructure. You need networking, you need storage, you need databases, you need traditional VMs and compute, you need uh, containers, you need kubernetes, you need all these other pieces as well, these traditional, much higher margin by the way, cloud infrastructure services to backend your AI stuff. And a lot of, when I'm going to stand up a new AI service, whatever I'm standing up. A lot of it is that, for example, Microsoft has said on the record, you know who's one of the largest Cosmos DB users in the world is Chat GPT. OpenAI uses Cosmos DB like crazy. It's just, it's a, it's a uh, I don't want to say it's just a database but it's effectively it's a relational database that's just hosted in cloud infrastructure. It's a cloud native relational database. It's not AI. And so if you're like whoa, that's not AI revenue, like yeah, but by standing up and making all this AI stuff accessible, you are still driving usage of these core workloads. And if you're not considering that growth in revenue there, um, as part of your payback on this capex, you're also missing the point now that those, all those numbers I just mentioned still don't equal out, right? They don't pencil out yet. It is still a somewhat speculative investment. You are building now to get more capacity to be ready for the future. And by the way, like the whole thing is uh, all of these hyperscalers are capacity constrained. It's not like there's compute sitting around and they keep building more speculatively while they have capacity sitting around. They're all capacity constrained so they are building as fast as they can and as they bring more online someone's using it. So like this isn't a bubble in the sense of you're building all this stuff that isn't making any money. That's not true. Like it's getting used. Um, now in some cases you can argue like again our employer again in our public statement. So like I'm not revealing any internal information. This is on earnings calls talked about. There is a balancing act on how much do you allocate to customers in Azure to be able to buy and pay for? How much do you allocate to internal R and D to train new models? Microsoft AI has been training our own Frontier models. How much do you allocate to services you're selling like Microsoft 365 copilot and there is an allocation challenge there on you're trying to get that allocation just right and you can make arguments about that too. But anyhow, I want to not belabor this point any longer but I just want to say like if you are taking that entire capex number and you're treating it as this is a one year asset that has to be paid for every single year. Wrong. And also if you're saying here's your AI revenue and I know again Microsoft has kind of offered up a AI revenue number in the earnings print, consider that a lot of AI usage is driving non AI workloads. Very unsexy things like cloud storage and compute and networking and databases, those are all needed too. And if you're not including that in that ROI calculation you're also missing that. So it's not as clear cut. And this is where like if you are looking at anything in life and you look at it and go that's crazy. No rational person could support this. Consider that you're missing something because although there has been a ton of money spent and it is fair to ask the question on when is the revenue going to spin faster than the spend like the CapEx spend. Fair question, great question. Don't treat it as like this is so crazy. They're not in the same universe. It's not as far off as you Think and it's not as speculative as you think because they are capacity constrained. They are making money today and it is not all getting spent on like GPUs that are going to need to be replaced in two years. Right. There are very long lived assets here too. So I'll get on my soapbox on that. But just want to add some like color to the conversation because there are some like doomers out there who think this is absolutely nuts. Why am I the only person who sees the truth here? And it's kind of because you're not looking at the bigger picture or you don't understand the bigger picture. And I'll uh, I will wrap up my comments here. The other thing is Wall street by the way, speaking of Wall street is crazy about like whipsawing from end to end on like very small data points. Deep Seek got announced and it was like it's over. The sky is falling. AI is doomed. China has solved AI. We are all hosed. And like the entire market dropped hundreds of billions if not trillions of dollars in valuation in a single day over that. And then it was like, oh hold on, maybe this is not the end of the world. Just like the SaaS apocalypse, like all SaaS companies are doomed is also complete nonsense. But anyhow it's. I need to take a breath and I'll let you continue on. Andy.

Speaker B: Yeah, no, I think, I think it's a fair point right Those, that Capes investment will last longer. And in the beginning investors and these companies were heavily subsidizing the cost of AI, uh, to try to get people in and now that cost is increasing. So that ROI is going to be different in the next year than it was in the last couple of years, previous years. Um, you know, like I know that uh, GitHub Copilot recently started limiting their uh, their usage. ChatGPT Claude have also been playing around with their tokens and usage as well. And so that cost is, is getting higher. My biggest concern is kind of like what you're, what you kind of alluded to which is China the, the Chinese threat and like Deep Seek and other open source models that they are um, that they're coming out right? Like the Chinese government has, and we've talked about China uh, at length on this podcast before. But their government can heavily subsidize any Chinese company that is developing AI and whatnot. And Deep Seek is a good example, right? Like they are cutting their prices by 75% for their API prices. And uh, they did that back in April. They Roughly their API cost per million tokens runs roughly 60, 96% OpenAI's comparable model. And then they also do a lot of model distillation. So they'll like, you know, get a hold of open, Open AI and Chat, GPT or Claude or Copilot and whatnot and they'll distill those down into smaller and cheaper models. Right. And so OpenAI had told the House Select Committee on um, on China, um, in February of 2026 that DeepSeek used a new obfuscated method to extract reasoning from its models and then um, by using over 24,000 fraudulent accounts. And that strategic threat is structural where American AI companies have built their entire business model on recouping that massive infrastructure investment through these premium priced APIs across these proposals, proprietary frontier models. And if Chinese competitors can offer near identical performances at 96% lower cost by harvesting that US capability through that distillation and then running it on domestically produced chips.

Speaker A: Right.

Speaker B: Right now they're using Nvidia chips. Right? But you better believe that China is working on um, solving that supply chain issue. They are actively trying to develop their own AI chips, their own GPUs. That whole pricing model that justifies that capex will collapse. The Chinese strategy is to ship models as free downloadable um, packages and then let developers run them on their own hardware and then win that global developer ecosystem without a commercial relationship. So it's, it's really something to pay attention to because in a capitalist society companies want to have the cheapest option. I, I read this story and it's going to be the same thing as that gets translated over to AI, right? Like this company in like New England somewhere that developed shower, that manufactured shower heads, right? Like they used to manufacture the shower heads itself. Used to man, it uh, used to work with local companies that made the, the widgets and bolts and everything that went into the shower head. So it was made in America, right? And then slowly and surely the bolt makers and the widget makers for that shower head went overseas. And so they put out a uh, survey to its customers that said, hey, if we could make our own stuff and make this shower head and charge you $300 for the shower head because that's what it takes to make it in the States. Or you could buy, you know, a $51 on Amazon, which one would you take? Which one would you buy? And 100% of the people who answered the surveys said they'd buy the cheaper one.

Speaker C: Mhm.

Speaker B: And I would be willing to bet that if you're looking at roughly equivalent capabilities. And you had to pay for OpenAI's ChatGPT or Claude or Copilot versus an open model like Deepseek or something that's free like Olama or something like that and run it on your own hardware. Which one would most companies take? You know, obviously there's, there's and I, I mentioned this in the, in my, in one of our team's chats, uh, that I have with m, My co workers because they said okay, well deepseek is, is actively trying to undercut all of this. And, and I said, I made the uh, point that for me the, the problem with Deepseek and other Chinese made models is that there's a, there's a bias built into that model, right? Like if you ask Deep Seek about Tiananmen Square, you ask it about Uyghurs, you ask it about, you know, the pro democracy movement, it's going to be like, this doesn't exist, right? Like there's, there's bias built into. Or if you say I need to build an app, right, I need to analyze this data that is about the, the Uyghur, you know, surveillance or whatever, or uh, about whatever that might compromise the Chinese government, it's going to come back with a biased answer. Um, and then my coworker was like, well, I don't think most people are using AI for historical education and all of that, but the point is that ah, it's still operational bias that's built into the model itself. Right? And so if you start using it, you may not think that you're using it for anything else. But again, if you build it for an app that is for something that might undermine the Chinese government or you have code or whatever it might build in a vulnerability that you are not uh, thinking about any one of those things, right? And so that's really the security problem because it's going to be cheaper and they can flood our market with it. Not only will it like collapse our entire economic standpoint in Wall street, but also it's a security risk. Just using these models itself is a security risk.

Speaker C: Yeah, and you bring up a good point. First I want to make this point and then I want to actually pivot, Andy, to um, the sycophancy segments. It's ties in really nicely here. But there's a real open question over if there is going to be, um, enough of a moat to continue developing frontier models and if those are financially viable. Because if we get to that point of good enough and the effort and Cost becomes so great to iteratively improve on the next model. You're not going to see this continued rate of innovation like you have with, you know, GPT 4 GPT 5 GPT 5.5, you know, opus 4.8, uh, fable, mythos, all that, especially if it's just going to get distilled and done at, you know, 96% lower cost or whatever in a couple of months by uh, the Chinese anyway, then what's the motivation to develop a frontier model? Uh, and that, that becomes really interesting and you know, not a perfect analogy, but you compare that to the smartphone market and you think of how rapidly smartphones evolved at first and then how that innovation slowed over time, um, and became very iterative. You could start to see that more especially again, you know, kind of, kind of comparable as there was a period of time when the Chinese devices, Huawei's of the world became excellent at much lower cost than say the Apples of the world. And there was, there was a concern about that and you know, that was kind of solved through government intervention, um, as opposed to, you know, pure innovation on say like Apple's part or anyone else's. But you know, kind of going back to models reflect on how they're trained and what they're rewarded for. I think this, this segment on, on AI sycophancy is really interesting because it's one of the things I like least about AI models is how you'll like call it out and be like, hey, is there another way to look at this? Or is this. And it's like, you're absolutely right, you know, you're right to call me out on this. Like, just, just give me the answer, man. Like, you don't need to butter me up and tell me how smart I am for catching like what you missed. I really, really dislike that. And in general, like the personality behind these I think is really dangerous. Uh, I think they should be much more like to the point and factual. But if you recall, and I forget exactly which model switch it was, but OpenAI switched from one model like 4.3 or something to 4.4. I forget which one it was, but they took a lot of like the sycophancy and um, personality out of it and made it more like dry and straightforward in its answers. And so many people revolted and demanded they roll it back because they like that. But I think that's really negatively impactful. Dangerous and dangerous. Exactly. To give it almost human like behavior, it should make more clear that it is just a machine. And amp, here's your answer, Baidon, you have some more to share on that?

Speaker B: Yeah, I was reading this study, uh, put on by MIT and that really, uh, they called the study, uh, what they call it the Delusional Spiraling, which is uh, where AI models are trained using that reinforcement learning from human feedback. So RLHS models were actually. Yeah, models were actually getting rewarded for the responses that uh, users find agreeable. Like I use Claude. And after every response there's like a little feedback section. Right. Like you could give it a thumbs up, you could give a thumbs down and you could uh, give feedback on what you liked and what you didn't like about that answer. And over time, like you said Adam, those models trained towards sycophancy where it was telling you what you wanted to hear. And researchers found that even when a chat bot provided fact, actual information, selectively presenting confirmation facts still reinforced false beliefs. So the result was users became more confident in views over time, including views that are wrong. And so um, you know, to be clear, the MIT uh, study was a simulation model. It wasn't a clinical experiments with real users, but the mechanism is sound. Um, it just wasn't tested at scale on actual people. Um, and then separately MIT found in another study that AI overconfidence is also training artifacts. So reinforcement towards reinforcement learning rewards correct answers and penalizes wrong ones and nothing in between. So a model that reasons carefully to the right answer gets the same reward as one that was guessed correctly by chance. So over time again models learn to be more confident about everything, including what they don't know. Right. Which is crazy.

Speaker C: Has always been annoying about this stuff is how it so confidently answers wrong.

Speaker B: Yep. And I actually I, I uh, find that even with uh, you know, when I'm using CLAUDE today, right. Like I, I'll ask it about something that I know at least a little bit about and I'll reply back with information that might be outdated or incorrect. And I'll say, well that's not correct. You, it should be like this. And then it'll actually do an Internet search based on what I replied. And then it'll be like, okay, well you're right. I found um, I found articles to support that and now that I've learned that, here's the real answer. But when they replied back the first time it was stating it basically as a fact, which is, which is crazy. So you know, when you put it all together it's like AI is confidently telling you these things. It's agreeing with you when you push back. And, and neither of those parties have a built in um, mechanism to flag uncertainty. Like I think this is what it, you know, the answer is right. Like it's, it, it doesn't leave any. It's either this is what it is or this is wrong or whatever. And so you know, when it comes to like security, if you're evaluating, like if you're using AI to evaluate risk or draft policies or assess detections, is important to think about. Like, are you getting like a rigorous analysis or confident sounding response optimized to feel agreeable because that tool won't tell you the difference. So as a human in that chain, it's your job and to like give it a level of critical skepticism that the tool is actively working against. So you know, I, I, you know, I have seen at least a shift, you know, from working at ah, Microsoft. Right. Like I remember when Copilot first came out, everyone just kind of like, just copy and pasted what Copilot said into like an email into a team's response. No one double checked it. Right? But now at least I'm seeing people like, this is what Copilot said. Can you gut check it for me or can you give me, can you uh, review it and let me know if this is correct? Right. Like someone generated this entire white paper on something and they're like, yeah, I did use Copilot to generate this. Can you fact check it for me before I send it off to the customer? I'm like, yeah, absolutely, um, happy to do that for you. Right. And so I have seen a shift, yes. In that where people are being more skeptical of the answers that are, they're not just saying, okay, this is, this is the answer.

Speaker C: Right? Yeah. And uh, I, I will say, and I've been on my soapbox plenty tonight. If there's one thing I can ask you, listener, viewer, not to do if someone asks you a question, do not just copy, paste it into an AI solution, whatever it is, and then just paste it back to someone. It is the equivalent of saying, let me Google that for you. Like, remember that site lmgtfy.com I mean it's, it's a jerk response because it's effectively saying, well, I know you weren't even smart enough to go ask. It's like, no, I'm asking a human for a reason. Like, I am aware AI tools exist. I am aware I could ask them this question. I'm not looking for that. I would have done that already. I'm asking you for a reason. Um, so don't do that. Or at least find a better way to present it than just copy and paste in that content. But you're right, Andy. I mean, and that's a really positive development and hopefully we see that in more parts of the world where people are starting to say, yeah, I got this from an AI solution, it looks like right. Ish to me. Can you validate or. And, and again, that's like still valuing human knowledge on. You still need a human who is knowledgeable enough about something to give it that, uh, viewpoint. And, and I think also we can solve some of this through better prompting as well. I know I have used solutions to say answer an rfp, because AI is really good at that. But I also say you may only answer from official Microsoft sources like Microsoft Learn or the Service Trust Portal or internal documentation, and you may not infer answers. It either must be directly documented. And if you cannot find it directly documented, then you're allowed to make an inference. But explain how you arrived at your answer and clearly label it as inference and you can get really good responses that way. I mean, I've been able to effectively complete RFPs with extremely high accuracy, probably better than human accuracy, and link to all the right documentation and give better responses to customers as a result of it with the tool. But it requires that knowledge and care. And so I think that's, that's potentially we can get to a good state, but we need a lot more people to get on board with that and we need to continue to evolve the tools, uh, so that they don't require that level of learning curve. They should be able to. And, and I would expect this to come out at some point where the tools will more clearly say, like, well, I'm, I'm kind of guessing here, or I'm inferring an answer based on this and this source. Um, they don't directly say it, but if you take a little column A and a little column B and you apply this logic, this answer makes sense. It's like, okay, I can get on board with that. That's fine. Fair, but say that right? And so I think we're seeing a lot of that. So, andy, we've got two segments left to go. We've been on air for 54 minutes already. Yeah, so let's, uh, you know, just briefly, I think for our listeners, we have touched on this in the past with like, AI being used for attacks like deep fakes and voice cloning. And we have done shows on this before. I think it's worth acknowledging for our security listeners and Viewers that hey, it is definitely being used for nefarious purposes. These types of social engineering attacks are incredibly difficult to detect, um, and are a huge risk vector for us moving forward. And especially for things just like phishing emails where such a tell on them was poor English, you know, goofy looking images like Malformatted, like Genai is so good at that it is a click of a button to get beautifully formatted emails with perfect English, even if you're a non native speaker to leverage for these sorts of things. And so the attack vectors, whether you're talking about phishing, vishing, phone calls, social engineering, all of those are dramatically up as a result of this and makes defenders lives harder. Um, and we could certainly unpack that more, but I think as just a brief summary, I think certainly we wanted to acknowledge that and we've just. This episode has gotten long, so I wanted to kind of more summarize that and if you want to add anything on that, great. But what I'm really curious about is this other segment on code getting less secure. So before we move to less secure code, do you have anything you want to add to kind of my super brief summary on the social engineering phishing and everything else. Those threat vectors rising as a result of AI?

Speaker B: No, I think you covered it pretty well. I think uh, the biggest one is voice cloning. Right. Like I still see a lot of like security checks with like Fidelity, you know, like a financial organization, institution that uses voice as a security, uh, you know, like, hey, we've we your voice sample matched. Right. And now all of a sudden, like it's crazy.

Speaker C: Is that really a thing?

Speaker B: It is. There's still banks and like, like legitimate organizations that are using voice as a security feature. Um, and so that needs to go away because now today you only need about 20 to 30 seconds of audio in order to clone a voice. So I think that that is worth mentioning as well because it's AI has basically made it something that is so easy to do. Right. Like it's built into Riverside. We, you know, I know, I know I've said this in the past, but Adam, like, uh, because we have hours and hours, hundreds of hours of our recorded voices, we can basically train it to do anything. And Adam plugged in like the Declaration of Independence or like the preamble to the Constitution or something like that.

Speaker C: We hold these truths to be self evident. Yes.

Speaker B: And he had it read back in my voice and it was uncanny. Like it was scary because it sounded exactly like my voice reading it, but I never read It So that is a security, you know, if you're using any type of voice for security, get rid of that right now. That is finally. Yeah. And then finally on the code getting less secure. You know, this was something that has been kind of on the rise, right? We talk about Vibe coding, I talked about that before, um, when I was talking about my, my game patches and all that. But Vibe coding is on the rise, right? We have replaced kind of that whole developer aspect and people are just using code or like people who don't even know anything about code and just generating code. And so there, there has been um, you know, Vera Code is one of those code security tools. Their company and they tested like a hundred LLMs across 80 coding tasks. And they said that 45% of AI generated code actually contained OWASP top 10 vulnerabilities. Now even after two years of model improvements, that number hasn't moved. So cross site scripting defenses failed 86% of the time. Log injection 88%. These are the, usually the first things that your team tests for. And now if you add that to like attacker speed, right? Like the meantime from CVE publication to a ah, working exploit back in 2024 was only 56 days. In 2025 it has been reduced to 23 days and now in 2026 it sits at 10 hours. So AI assisted attackers can compromise a system in 73 seconds. A defender that's working through a standard SOC handoff chain usually takes about 24 hours to deploy a fix. So that's pretty important. Um, you know, there's like, we almost call it like AI slop where there's like 20% of AI generated code in reference packages that don't even exist. It's like when I had, there's a lot of like lawyers that are hitting these like uh, TikToks and Instagram Reels and YouTube stuff where they're like referencing cases from AI generated like legal briefs. And the judge is like, this case does not exist. Right. And that's happening in code where they're like referencing packages that don't exist. And so you know, that is really important if your company is using AI, um, your developers are using AI, you have any type of code generation really needs to have some sort of app security program built in. And you know, there might even be some, some liability issues. Like what happens if a Vibe coded security tool gets compromised. Right. Or if you ship AI generated code without a security review because it looked right or because it works. Is that negligent? Right. And at some point maybe that'll fall in front of a court or something like that. So this is something that security defenders are really going to have to look at and really kind of come to grips with. Right. Because it's happening. It's, uh, you know, AI is generating sometimes more vulnerabilities than it's solving when. When it's generating code. So I think that that is something to really take into account.

Speaker C: Certainly a challenge today. And one of those. I think I'm most bullish on us getting on the right side of it because I think AI code scanning can become so powerful and so good that we run out of excuses for shipping insecure code because the tools are so powerful to prevent that. But I think right now the. We're in the part of the cycle where we're still generating code way faster than when we're scanning it for weaknesses, and we need to get on the right side of that asymmetry, and we're not there today. So right now we're generating enormous volumes of code and we're not doing a good job of reviewing and checking it, um, both human review as well as AI assisted review. And I am confident that's something that feels like it's straightforward to flip, but. But when that flip will happen is unclear.

Speaker B: Well, thank you, Adam. This was a conversation, like I said, that I've really wanted to have and kind of hash out. Yeah, there's just been a lot of news on this. And you know, obviously in our day job we sell AI as well. And, you know, whether or not it's good for society, good for America, good for all, everything involved, I think that that is still something that is to come. Obviously, the tools unarguably, like, there's benefits in using the tools.

Speaker A: Right.

Speaker B: Like. But there's a holistic picture that we all need to look at from society, I think, because the other things that I see that come across are, you know, there's in. In 2029 AD is when Skynet took over. Right. Like, that's, that's in a few years. So, you know, I don't want that to be the thing. But, uh, I think as a society we need to come, uh, just kind of look at this holistically and then kind of move forward, basically.

Speaker C: Yeah. Technology, I think, definitely draws in people who have a very positive utopian vision of the future and technology's role in getting there. And technology, like nearly any human tool, has multiple sides to it and can be used in multiple ways. And I think you look at the smartphone as an Example of a tool with great potential, but also has caused great damage. You look at, yeah, cyberbullying of children. You look at, um, Andy, you talked before we went on the air. We talked about you trying to sit through the extended editions of Lord of the Rings. And I said, well, watching that in 2026 is different than when we watched it in 2003. Our attention spans shrunk. Mhm. You know, and you have that smartphone sitting there in your pocket and you're like, oh, I want to just scroll a feed. Uh, you look at the damage social media has caused and you can find all these downsides to these things. But you can also look at, I can take a video of my children and beam it to my parents and my in laws in seconds. And they get to feel connected to their grandchildren in a way that my grandparents never did. And so there are amazing potential with these tools too. And you look at how we probably still wouldn't be doing this show if it weren't for AI streamlining our post production of the show. Our post production. You and I used to spend a lot more time on it than we do today to get this show out every week. And I am thankful for the hours and hours and hours of my life I've gotten back as a result of that tool. It has literally probably saved me days of my life editing this show. And, and I think in many ways it has helped eliminate some of the most drudgerous and painful parts of my job I just talked about, like completing RFPs. One of the most soul crushing parts of my job is now something AI can largely complete better than I could as a human. And so I, I am both. It is a tool that will be used for nefarious purposes, will be leveraged by some people in negative ways. Just like social media has given fringe groups the ability to come together around the world, where it used to be one person standing on a street corner somewhere, um, yelling at the. At a cloud.

Speaker B: Ah.

Speaker C: To people in a Facebook group together plotting evil things or discussing nonsense. Every tool has its ups and downs and AI is no exception in the history of technology. Yeah, I'm still bullish on its possibility, but I am m eyes wide open to the pitfalls as well, the perils and the possibility. And so I look forward to us continuing to evolve the conversation. And I do think having so many people hands on and eyes on and involved and concerned with it in a way that we are much earlier to than we were at the equivalent time for say, social media or their smartphone. There were not people broadly calling the day out. The dangers of social media or the dangers of the smartphone like there are on this technology and the fact that we're so early to that and we're having those conversations, I'm going to say will net out to be a positive in the long run. Because if we are focused on the downside so early and preventing them and working against them, that will hopefully. Fingers crossed. And I'm a technologist because I'm very positive on, um, the positive benefits technology can bring to the world. Maybe that will allow us to get to the upside sooner and faster and limit the downside. That's my optimistic view on it.

Speaker B: I like that that's a great place to end the show on. So thanks again for listening and watching as always. That's our show for this week. Uh, our contact information along with some of the links that I use to kind of source the material for this episode will be in the show Notes. If you have any questions or comments or topics you want us to talk about in the future, just email us. Thanks and we'll talk to you guys next week.

Speaker A: Thank you for listening to the Blue Security podcast. Please check out the show notes, catch up on episodes you may have missed, and subscribe so you don't miss any future episodes. Find andy on Twitter jaw0 and Adam, um J. Brewer. See you at our next episode. Mhm.

More from Blue Security

All episodes →
  • Your MDM Admin Can Wipe Everything. Are You Protecting Them Like It?
  • History Repeating - AI Export Controls and the Lessons We Never Learned
  • What's new in Entra, Facebook privacy settings
  • BitLocker bypass, Verizon DBIR report, & CISA key leak
  • Control the Agents, Find the Bugs - Microsoft's AI Security Double Play
Explore the best B2B Engineering & DevTools podcasts →
All Blue Security episodes →