Episode Transcript
Shane Buckley [00:00:00]:
For the first time in history, software is now more expensive than human engineers. And that's a trend that we're going to see going forward when it comes to AI.
VO:
From KBI Media, I'm Karissa Breen, and this is KBKast.
KB [00:00:10]:
My guest today is Shane Buckley, CEO of Gigamon. He sees the AI spending crisis playing out across boardrooms in real time. So, we talk about the customers blowing through their AI budget by day 3 of the month. Why token costs could jump to 400 to 500%. And the question every board is now asking, is the juice worth the squeeze?
VO:
If you find these conversations useful, hit follow. It's the single best way to make sure the next one lands right into your feed, and it helps other execs find the show. Alrighty, let's get into it.
KB [00:00:53]:
So, Shane, I want to start with our organizations becoming more or just more confident in the tools that they've already purchased, considering some companies out there could have up to 150 tools? I'm really keen to hear your thoughts here.
Shane Buckley [00:01:07]:
I would say number one, more tools doesn't translate to more security, Karissa. The reality is with tool bloat, oftentimes our customers tell us that it creates a lot of segmentation, fractionalized information. Then you're stitching together disparate information from different tool stacks. You gotta remember, these tool stacks are highly verticalized. Their own data store, they have their example and storage capabilities, they have their own analytics capabilities, so they kind of look at a snapshot of what's happening inside the infrastructure and then trying to translate that into a big picture becomes almost like an oxymoron. So this is one of the reasons actually why organizations are actually moving to a new form of architecture using a data lake function and next-generation SIEM architecture. And so the benefit of this is that you have a single data store, Thus the horizontal data lake, where all the data from the infrastructure, all the logs, as well as the traffic and network metadata is stored in the data lake. You have agentic AI then that does all the analysis on top of a single horizontal piece of information, which is consistent right across the organization.
Shane Buckley [00:02:13]:
And then you just simply have applications plugged in on top. So the benefit this gives you is that you get more consistent information across the entire infrastructure, number one. Number two, you're leveraging the power of agentic AI, which gives you the ability to find the needle in the haystack. But the hidden benefit here is that the tool market is worth about $34 billion a year. And as organizations are looking to dramatically reduce costs so they can increase their investment in AI, reducing the cost of tools and tool bloat is a really important strategic element for many of our customers. And we enable that to happen as well, given our ability to provide the insights from network traffic through metadata. Providing higher quality data into AI means you have higher quality intelligence on the way out as well. And so this shift to this data lake, next generation SIEM architecture is very, very important for customers.
Shane Buckley [00:03:05]:
From the ability to find the needle in the haystack, have better performing applications, have better security for their infrastructure, and also generate more abilities to spend more in AI whilst reducing the cost of the tool bloat.
KB [00:03:19]:
So Shane, I want to stay there for a moment. As we've seen over the years, back in the day, we would outsource to X vendor. you know, big integrators to do certain things. Then we went to more point solutions and then people racked up a lot of point solutions at 150 or so an average company may have. Now we're seeing because of people think that they can vibe code their own sort of solution. I was talking to someone recently that thought we're going to kick out this major vendor because we can just do it ourselves. So do you think in terms of like customers, are they thinking, well, this whole, we want to increase efficiency and reduce costs. we could probably do it ourselves.
KB [00:03:54]:
Therefore, we're looking to reduce that tool bloat, perhaps. But then I also do think that they realize, customers are going to realize, well, we can't really do it ourselves. We might have to call that vendor back to come back and do the thing. It's not as easy as it looks, perhaps, despite people thinking we could vibe code this thing on our own. So I'm just curious to get your perspective given your role.
Shane Buckley [00:04:15]:
That's a great question, uh, Karissa. I would say first off, the old saying is always true, which is anything that seems too good to be true generally is too good to be true. And so AI definitely provides tremendous opportunities for humanity as a whole, and particularly when it comes to things like vibe coding. Yes, there's an ability for AI to generate code at a much faster rate than humans can do. So that's definitely directionally a great advantage. However, you need to look at exactly what you're trying to achieve. AI leverages open-source software. It can generate code at higher volumes, but you're not quite sure what you're bringing inside that code.
Shane Buckley [00:04:52]:
And so, one of the challenges for mature organizations, and particularly organizations that have security and compliance requirements, is you can't rely on AI to do the entire job for you and assume that, A, it's going to work, it's going to deliver on your very specific SLAs and requirements, and I would say also it's going to meet your compliance and security requirements as well. And this is where organizations are really turning towards augmentation rather than replacement. And so there's a recent article with Andreessen Horowitz which said that for the first time in history, software is now more expensive than human engineers. And that's a trend that we're going to see going forward when it comes to AI, because the cost of these AI models is so high today. Organizations are spending way too much part of their budgets in generating AI. So you've got to ask yourself, as this goes forward and as token costs potentially increase, given these companies are investing trillions and trillions of dollars in building out AI factories and these big data centers, is it going to be economically viable for every one of us to be able to use AI to automate all the tasks that we're actually trying to put in place? The reality in the short term is no. There's certainly benefits to augmentation. At Gigamon, we've seen improvements of between 20% and 40% in the productivity of many of our areas of our business, particularly our R&D and our QA organizations.
Shane Buckley [00:06:12]:
That's a classic use of AI technology. Have we the ability to say, hey, we don't need hundreds of engineers, we can just have AI generate for us? Obviously not. It isn't at that stage yet. And so it's kind of a trust and verify model in many ways. You trust AI to build code for you, and then we verify very, very carefully. We scan our code 8 or 10 times a day. We look to ensure that we're not importing any form of malicious code that potentially we would not otherwise find. And also, more lines of code doesn't necessarily make better code.
Shane Buckley [00:06:42]:
So you got to really look under the hood, and it's kind of caveat emptor in some ways. Correct. There is a, you got to be careful to understand what is it you're trying to do. If you're trying to build kind of an application, kind of homegrown application for maybe a small business or personal consumption, that's one thing. You might deal with the inefficiencies of the application, or it may not work exactly to specification. If you're working though with governments and financial services organizations, banks, and other areas that are critical infrastructure, you got to be very careful of the software that you're writing. And it can't be like, whoops, we didn't realize that AI actually got it wrong. So I think it really depends on the nature of the customer and what you're trying to achieve, but certainly augmentation is a very, very important component of what AI can provide to all organizations today when AI is instrumented correctly.
Shane Buckley [00:07:29]:
And that's a big when, because what we're seeing today is that AI oftentimes isn't instrumented correctly. It therefore doesn't necessarily have access to all the right information, and And AI, if it gets access to the wrong information or lower quality data, it will provide lower quality outputs, obviously, because higher quality data, higher quality outputs, lower quality data, lower quality outputs are often called hallucinations or basically just getting it wrong.
KB [00:07:57]:
Okay. So that's an interesting point. I've been speaking to people at your level that is now saying, to your point, people thinking we're going to reduce all of our software engineers, we're going to bring in AI, and then all of a sudden the whole budget's being blown within the first month. And then there are people freaking out going, well, that's not what I expected. So do you think that it's counterintuitive to what people's hypothesis was to be like, we're going to reduce the cost, but then in reality it's costing companies more. Now, whether it stays at that more level over the years, who knows? But do you think that people have been blindsided by this? Do they think like, haha, I was going to get ahead, but now it's like, actually it's costing more money to set it up, to govern it, to understand it, all those sorts of things, keep these things running. Someone's of course got to monitor it, but where would you say the headspace is at with people that you're— some of your customers that you're speaking to, or just general sort of market knowledge?
Shane Buckley [00:08:53]:
That's a super great question. I'd say if you asked me that question 6 months ago, I would have said, hey, it's very likely in the next 6 or 12 months, we're going to see much greater use of these cloud-based models. across organizations because cloud-based models are the safest way to do kind of a try and buy, if you will. They have a lot of the connectors. They have a lot of the infrastructure that enables you to integrate AI into an organization with the controls that the organization needs to put in place. Candidly, they've done a really good job. On the other hand, you now ask me the question, say, in the last 6 weeks, and you see a lot of reports in the press. Many of our customers are saying, oh my gosh, like you said, it's day 3 of the month.
Shane Buckley [00:09:32]:
I've already blown through my AI budget. Just 3 or 4 months ago, organizations were giving unlimited access to these AI models to engineers, encouraging them to write agents, actually looking at the consumption of tokens as almost a badge of honor. 3 months later, the same organization is going, whoa, whoa, whoa, I need you to give me a justification why you want access to Fable, for example. I want to understand what exactly is the return on your investment for these token consumption elements. Even tokenomics has become a really big source of discussion at the C-level. CEOs, and particularly CFOs, because it's now having an impact on their earnings report. There are some customers of organizations like Anthropic spending over $100 million a month on tokens. And so you ask yourself, when are people going to step back and say, we got to look at the financial return on this investment? Back to the article I referred to, if software has become more expensive than human engineers, then it's either a time-to-market issue or people don't have unlimited budgets.
Shane Buckley [00:10:30]:
So I think it's going to be a combination of both ultimately. Trillions of dollars are being spent by the leading AI companies building out data centers. Here's the rub though, if you look at the cost of those data centers potentially 2 years ago versus today, it's completely different.
KB [00:10:44]:
Why?
Shane Buckley [00:10:44]:
Supply chain. Supply chain hasn't got the scale required to deliver the infrastructure. We've seen that in reality. Phones are costing us more to buy as consumers. Server technologies are absolutely astronomically priced. You cannot get high-bandwidth memory, the servers, the other elements of the infrastructure and data centers to actually supply these AI factories to build out the AI infrastructure that these organizations want, that we want to leverage as consumers. Then you look below that supply chain, the ability to even find data centers, actually get the planning permissions, and the ability to actually build the infrastructure is taking longer. People don't want data centers near their home.
Shane Buckley [00:11:25]:
There are a lot of objections in the United States for people having data centers that are robbing their power supply from these utilities and causing their power bills to go up. So there's a lot of other issues where we don't have this ability to dynamically scale infrastructure as fast as the infrastructure wants to scale. Therefore, the cost is going up. As the cost goes up, it means that the token costs, which are underwriting the cost of the infrastructure, clearly going to rise. There are forecasts that say token costs will increase between 400% and 500% over the next 18 months to 2 years. So if you're an organization today running out of budget in the next— in the first week of the quarter, and you've got even a 200% increase in the cost of these tokens, you're going to run out of the budget in like 2 days. So how effective is AI going to be for you? Well, this is also why the new trend that people are talking about now is hybrid AI. So, not just leveraging these public AI factory infrastructures, but looking at these open-weight models or on-premise LLMs.
Shane Buckley [00:12:26]:
And so, these LLMs are either grown typically in the United States or in China, and people look at these models, say, hey, if I use a model internally, they'll operate at a tiny, tiny percentage of the cost of these public models. But here's the challenge: now you're bringing aboard a new AI technology, it doesn't have the connector infrastructure around it these public models have. So, the integration of these LLMs into infrastructure for companies is dramatically more complicated, and that's why they're turning to organizations like Gigamon to provide that security and visibility into what are these models doing, where are they communicating, and where potentially are people getting inappropriate access to information. Because the first step is always humans running prompts and agents to these LLMs. The second step is to build an agent which actually causes agents to run and do queries with no human intervention. That's where AI potentially can run amok, it can run up huge charges, or can cause a lot of unexpected consequences, such as Hugging Face just a few weeks ago, where an OpenAI model actually ran amok for, for a number of days before the IT department even knew what was going on. And so we're at a very interesting phase of where AI is from a rollout or genesis perspective, where customers are looking at cost on one hand, and they're also looking at security at the other point and compliance. And these are all at loggerheads with each other.
Shane Buckley [00:13:52]:
And so there are some very tough decisions that leaders have to make in terms of the rollout of AI.
KB [00:13:57]:
I want to talk to you about the earnings. This is interesting. So do you envision companies now are going to, you know, whether they're private or public companies, we're going to start to see now how much money these businesses are spending on this. So then will we start to see the market dip a little bit? Because it's like, well, hang on, if this company spent all this money on tokens and the cost of it, I think there's a site out there that says $3.14 to use for Fable 5, for example, versus other Chinese ones was like 3 cents. And this is US dollars. So where does that then, how do you see that from a strategic point of view? Because do you remember back in the day when everyone was talking about, you know, offsetting like the carbon and stuff like that? Now that conversation's dissipated and now it's probably going to be about the tokenomics side of things. I'm just curious to get into that a little bit more on how this is going to play out for people that are, you know, in the stock exchange, et cetera.
Shane Buckley [00:15:00]:
Yeah, it's a great question. So again, 3 months ago, almost no conversations on the impact of AI spend within organizations. Literally in the last 90 days, this has become a much bigger talking point. We've seen organizations talk about earnings impacts because of overspend on AI. The biggest challenge here is that organizations don't have the controls in place because they work on a pay-as-you-use model. So these cloud-based vendors will give unlimited capacity to organizations, and at the end of the day, week, month, they true you up and say, oh, your bill is a million bucks, it's $5 million, it's $10 million, etc. Thus the increase in kind of tokenomics calculations within MCP, the primary AI protocol gateway technologies that are helping organizations understand consumption so they can actually try and put in place some controls. But then tying back the consumption of these tokens back to ROI is almost impossible because in some cases the agents are being written by engineers to call other agents in a kind of a nested way to actually create output, which can be very difficult to calculate.
Shane Buckley [00:16:11]:
So for example, in an engineering group, if you're developing a product through AI, how do you know the cost that that is being offset from an AI perspective versus the benefit that the coding has given you? If you're actually relying on one technology versus the other. So, if you're not using human coding, you're using AI coding, how do you compare that as if a human did it in terms of time to market advantage and otherwise? So, a lot of the metrics that organizations need to use to calculate the return on investment are just not there as well. And so now we've got this almost crude element of finance or the CFO group saying, okay, we're going to spend X million dollars on tokens this month, and when it runs out, it runs out. But if we've already provisioned the systems to leverage AI and now you're going to turn them off, then how do you go backwards? Because you spent all this time and effort actually plumbing this into the infrastructure as well. And so AI will continue to be a continuous source of concern for finance departments and now for boards of directors who not too long ago were pushing these organizations to put in place this transformative technology in the belief that you could potentially downsize the organization dramatically from a human cost perspective. And you can see a lot of the research shows that's not been the case. Where companies have taken decisions to outsource customer support organizations and call centers and otherwise, they're secretly hiring them back as consultants because customers' sat scores have dipped because the AI technology isn't quite up to the level of capability that they thought. Again, it comes down to not replacement, but from my perspective, augmentation.
Shane Buckley [00:17:43]:
The finance piece is going to continue to grow. You're now seeing Wall Street questioning the CapEx spends of the big AI companies from a return on investment perspective, because with the increasing cost of provisioning AI factories and data centers, the return actually even has to be higher. But there's already enough concern across the industry that tokenomics is just not working out for companies. So on one hand, you've got costs spiraling out of control in terms of provisioning the infrastructure. And on the other hand, the cost of actually using the technology is now out of control. So, at some point, you actually have to make a call. Hey, is the juice worth the squeeze? Have we all had unrestrained exuberance in terms of adopting a technology that was so exciting, we didn't actually fundamentally understand the cost-benefit value for the organization? And I think that's where organizations have to look very, very carefully at the metrics they put in place. At Gigamon, over 98% of what we call our Gigamonsters, which are Gigamon employees, leverage AI on a daily basis.
Shane Buckley [00:18:43]:
And so, we've got very clear goals and spend requirements for AI as a technology, and we do it on more of a project basis across different groups. So, AI, for example, is not available for all of our engineers in exactly the same way. We leverage a model using a company called Glean that enables us to selectively choose different AI models for different types of activities. Some are free, such as Google, for example. Others, like Fable, very expensive, and they're limited to very high-level architects or distinguished engineers within the organization doing very, very specific R&D tasks. And so when you do that, when you look at the kind of least-cost routing model, if you will, you can actually put some controls in place to make sure you deliver on the spend requirements that the company has. The next stage for us really is tying back that spend onto what the return is for the organization. Do we get better software? Do we get better, faster software? Do we get better, faster software delivered faster to customers? And how does that impact our business model? What is the advantage of us providing software perhaps a month or two earlier versus potentially doing it a more traditional way and having it a month or two later? Is there a difference? Is there a return for our investment? And these are questions that many organizations have to themselves ask Because in some cases, it might be incredibly important to beat your competitor by 1 or 2 weeks to market.
Shane Buckley [00:20:06]:
In other more mature businesses, it doesn't really move the needle. And so therefore, why spend the money if it's not going to give you the return? So, my forecast is that organizations are going to look much more about what am I getting for my investment versus just rushing in to say, hey, the whole world seems to be doing this. Let's all go forward with this unrestrained exuberance. I think that period is coming to an end. And organizations are going to look at other ways to actually achieve the same result. And as you mentioned, open-weight models such as models from China and other parts of the US, which are on-premise, fraction of the cost of some of these public models, is probably the way that many organizations would go in terms of the majority of their AI consumption. There will always be a need for some of these cloud models. If you're a Microsoft Azure customer for Office 365, Yeah, you use Copilot.
Shane Buckley [00:20:56]:
It makes total sense. If you're a Google customer, then yeah, you're going to actually use Google technology, et cetera. And so, it really depends on the use case, and it depends on the return that the organization's going to get.
KB [00:21:09]:
You made an interesting point around how do you go backwards. So, for example, you get the bill at the end of the month, it's $5 million. CFO says, has a, you know, almost puts the guy in a coma. What do companies do then if the guy's like, hey, well, we cannot spend any more money on this. We're already overextended. Now we've got to turn it off. But to your point, there might be critical systems relying on this and workloads and people's processes. How do people start to go, well, we got to walk it back now? And then as a result, that starts impacting business operations and we know how that goes.
KB [00:21:45]:
So, Are people thinking about this at the moment? And if they need to walk it back, what does that process look like?
Shane Buckley [00:21:54]:
I think that's the $100 billion question. So how many of us have gone to the airport, airline's got some failure, and we're like, oh, boarding's going to take an extra 2 hours. They can't even put the bags in the hold because the computer normally determines the weight loading ratio and balancing across the plane. You can't issue boarding passes. The whole system actually completely collapsed because the dependency on digital transformation. Very normal, it happens to us, all of us unfortunately, on almost a daily basis. It's really often when it happens. And then you look at the deployment of AI technologies where a lot of these AI platforms have been very cleverly written, so they have connectors into pretty much every part of the organization, whether it's structured data systems, which are quite hard to obviously instrument, and unstructured data systems alike.
Shane Buckley [00:22:42]:
And so once all these connectors are there, then not using it almost becomes an impossible task. How do you unuse something that's automatic and presented to you as a great productivity tool when the actual cost of the productivity tool wasn't really understood when it was deployed? You almost have to have 2 different types of systems. You have to have your old system and then your new overlay system. And then let's ask ourselves, how many organizations, as we threw ourselves into this AI journey actually had the presence of mind to say, in the event of catastrophe, break glass and go back to the old way we used to work. It's a very hard thing to do, particularly in large organizations, because the workflow has fundamentally changed. And if you look at IT systems, it's generally about a workflow. You go to do an expense approval, you do a search for information or data, it's all workflow-driven. You use the the method and the system that the organization has provided to you.
Shane Buckley [00:23:37]:
And so, to your point, I would say, Karissa, it's very hard to go back. It's also hard to say, hey, we've used our tokens, okay, let's go back to the way we used to do things in 2025 and assume that we had none of the advantages in 2026. And so, what it will come down to is actually, I think, understanding where are the parts of the organization where we can afford to leverage AI from the point of view of efficiency and work augmentation. Still don't think it's about work replacement. Let's quantify that, and then let's limit the access to these expensive models to the rest of the organization. You can do that today. You can use Google, for example, you know, free search. Copilot comes as part of most people's 365, you know, builds or subscriptions, so you don't have to use some of these more expensive models.
Shane Buckley [00:24:26]:
Also, leveraging these open-weight on-premise models will enable organizations to put in place Similar types of capability that may not have all the connector and the infrastructure around them, but you can build those and you can bring them to market at a much lower cost or in a more deterministic manner. That's probably the next stage where organizations are going to focus on, I would think.
KB [00:24:48]:
So, when you mention, is the juice worth the squeeze, do you think, because you made a point, of course, boards were like, are we doing AI, as if it's necessarily a binary answer. Do you think that, and that was more favorable to be like, yes, we're using AI, we're doing all these things. Do you think that we're using AI could be a precarious situation for businesses? To your point, if it's costing more money than it was before, then that's not generating additional revenue like people thought it would. So how are companies sitting back now to really walk through, well, maybe this scenario we need AI and we don't for other? for other things that we thought we could just try to automate it, but it's taking more effort, time, and money to try to automate something that's super basic perhaps.
Shane Buckley [00:25:32]:
I think the biggest challenge is FOMO, fear of missing out. You zoom back maybe 6, 9, 12 months ago when boards of directors and CEOs from their boards and others were saying, hey, we're definitely falling behind. The herd is moving beyond us. Everyone's kind of embracing this next generation technology that's going to be massively transformative for our business. I will bet you if you ask 99% of the people who actually made those declarative statements, tell me exactly what the impact's going to be and why you think it's so transformative, they'd be like, ah, hold on, let me just go and read another, kind of listen to a podcast to get new information. Because people weren't exactly sure why they thought this technology is going to be transformative other than AI is super intelligent, it can do a lot of things that humans potentially spend a lot more time doing. And so it was this directional, let's kind of invest ahead of the curve because we don't want to be left behind mentality. So where do we see that before? 10 years ago, when the world talked about moving to cloud technologies, by now almost all of our infrastructure and servers and systems should be sitting in some sort of a cloud somewhere around the world.
Shane Buckley [00:26:39]:
Guess what? That didn't happen. Penetration in cloud's about 30-35%. It hasn't moved much over the last number of years because in reality, As organizations, particularly large organizations, start to adopt cloud, I know of a number of large global financial services organizations, big banks who said, hey, we're gonna move 99% of infrastructure to cloud over the next 5 years. That was, say, 5 years ago. You ask them today, they're like maybe 18 to 20%. Applications don't work well in the cloud. They have security challenges. They have compliance issues in a lot of regulatory environments like the EU, for example, terms of confidential information, PII for individual users in different countries, and also the cost of the cloud has become prohibitive in some cases, so it's just not going to work.
Shane Buckley [00:27:28]:
And so the belief that the technology is going to absolutely take over and dominate 10 years ago for cloud obviously didn't realise. New cloud-type technologies were made available for virtualized workloads and for private cloud environments. Kubernetes and other technologies enabled companies to build out their data centres and do it at a much lower cost. yet retaining the control that they needed from a compliance and security perspective. We're exactly in the same position here with AI. AI is a tremendously transformative technology. It can make billions and billions of calculations in subseconds, and so it can operate much faster than the speed of even hundreds or thousands of individuals or humans working inside a building at a much higher cost. But then you have to look for the use case of that technology, the cost basis, and whether it is going to provide the return that you want as an organization.
Shane Buckley [00:28:18]:
And so what we've actually seen so far is that we haven't had as much workplace reductions. We've actually ended up hiring more people. We're actually spending now more people because we have a lot more people working on AI projects, implementing AI, instrumenting AI, making sure that it is secure, that it's performant, and looking at next-generation trends than the savings we had for the people who were generally doing somewhat repetitive tasks. So I think the challenge for the boards 18 months ago or so, I think they're now beginning to realize, you know what, the juice here may not be worth the squeeze. Let's kind of dial it back a little bit. So the pendulum, which swung one way very much in the last 18 months, is now starting to swing back again. I suspect it will swing over more as we all understand the value of on-premise models, such as these open weight models and how they can be implemented in a much lower cost way while achieving similar enough results than these much more expensive models that are in many of the cloud providers. There are also lower cost models, the older models the cloud providers give, which give probably a good enough return, right? So it's all about what's the effectiveness of the return that you're getting.
Shane Buckley [00:29:30]:
And so I think the pendulum will swing over and back quite a bit until it gets to this point of equilibrium, which is, yes, this is worth the investment. I'm getting the return. I'm driving shareholder value. I'm driving my product strategy. I'm making things more efficient whilst not reducing the effectiveness of my organization from customer sat, for example, net promoter scores. Your customer saying to me, hey, I just cannot stand your customer support organization hotline because I'm dealing with this bot that doesn't understand what I'm saying, doesn't answer my questions. I'm not going to buy your product. Versus, hey, I've got some way to augment that to make sure that we reduce the amount of repetitive tasks, are done efficiently, customer enjoys that, but there's availability of specialist people that you can still get to in order to deliver what you need to get done.
Shane Buckley [00:30:14]:
So, I think this pendulum will go over and back until it hits a state of equilibrium. We're still at very early days of our journey here. There's a lot more journey underneath us, but I do believe the time where people are just blindly investing in AI has passed because I think there's enough experience now in the market to understand you You can spend a lot of money for not a great return if you're not quite careful.
VO:
We'll come back to that after a quick word from our sponsor. If you're working in AI, machine learning, or data science, you're likely already handling sensitive information. Proving your security and compliance posture? That's where Vanta comes in. Vanta helps AI-driven teams fast-track compliance. Think SOC 2, ISO 27001, GDPR with minimal disruption to development. Visit Vanta.com/KBKast, V-A-N-T-A.com/KBKast to learn more.
KB [00:30:40]:
So you sort of say you're in this phase of companies trying to course correct because they've overextended themselves. They've blown the next 10 years' budgets probably in one month.
KB [00:31:23]:
Who knows? So we're going to start, so people are going to be a little bit more frugal perhaps towards these models because they may have overspent. So then my next question to you, Shane, would be because companies are so fixated on course correcting and, you know, monitoring how they're spending their money, are they then being bamboozled by this AI problem and then they're sort of forgetting about basic operations, keeping the lights on cybersecurity?
Shane Buckley [00:31:50]:
I would say they're not necessarily forgetting about things like cybersecurity because at the end of the day, Chief Information Security Officers or CISOs, they have a very, very important role in any organization. In some jurisdictions, they are personally liable for the security of the organization as well, which makes that very much sharpens the mind, let's say, when one is thinking about, I don't look great in orange, so I want to make sure that never happens. But then the downside of that is, as against being a technology leader looking at embracing technology, as we said, in many cases they've been told by higher-level COOs, CEOs, boards of directors, thou shalt do this because this is what the herd is doing. And they're figuring out, oh my gosh, how am I going to make all this happen? And so they're definitely looking at cybersecurity as being a very important component. We've seen, for example, literally in the last 4 months, the emergence of these frontier models like Mythos and ZAI, and there will be many others to follow where AI is leveraged in a way that's pretty nefarious inside networks. It's looking for a way to find pathways into the organization through software vulnerabilities that will be undetected by existing security systems. It is absolutely frightening. I have to tell you, in most conversations that I have with CISOs and CIOs around the world, they are literally terrified that they can be breached.
Shane Buckley [00:33:13]:
One of the most secure parts of the US government, in a public announcement about 3 months ago, through the red team of that organization, leveraged Mythos to be able to penetrate all the security systems of this very, very secure agency of the government and actually uncover classified information. And they were able to do it actually pretty easily as the red team. That caused a lot of waves across the US government in particular. in order to find out, well, how do we make sure this doesn't happen going forward? And so CIOs, CISOs, and others recognize this as well, and so they're trying to understand how do we put in place protection within the organization for something that is somewhat unseen. Endpoint security software can be bypassed by these clever models because if you think about it, there's an infinite number of ways almost that a nefarious actor can breach a network. The IT department and security has to defend every single solitary way in because all they have to do is find one way in. Statistically, they're more likely to find the way in than it is for the IT department or a security department to block them on their way in. That's been the case for years in this cat-and-mouse game where you had a human or a bunch of humans trying to penetrate the organization and a bunch of humans defending the organization at the same time.
Shane Buckley [00:34:30]:
Now you actually have AI generating an infinite number of attacks at any one time, You still have a bunch of humans trying to defend it on the way in. So obviously you can see in that dislocated environment, the statistical probability is that the attacker is going to breach the infrastructure much faster than the defender can actually defend their way in. And they just have to find one way in. And so that's why we're seeing from Mythos and ZAI and these other models, so much understandable concern from CISOs and other security experts. And a lot of what's happening over the next 6, 9, 12 months is understanding the role that AI plays from a network perspective. Because if you think about it logically, it's an overlay network in addition to the infrastructure that's been put in place over the last decades, where there has been— whether it's tool bloat or not, there's been tools put in place, endpoint security software, network security software, to really understand what's happening. You have SIEMs like Splunk and others that generate large volumes of data to help SOCs understand exactly what's happening. Network.
Shane Buckley [00:35:30]:
Then AI comes in with different sets of protocols which bypasses a lot of those, that tool infrastructure, because agents don't use endpoint software because they're not endpoints. They're actually just programs sitting inside the network. And so there's no way to understand what those agents are doing today other than looking at things like MCP gateways, which are still somewhat in their infancy. And so it creates a more important requirement to understand what's happening at the network level. Because the one thing that is important is all AI traffic is based on network protocols. It's all based on basically Ethernet packets. It's a protocol, MCP and A2A and RCE, very defined protocols. We can understand what they do and we can understand therefore what these agents are doing inside the network.
Shane Buckley [00:36:13]:
But we have to very quickly morph as a security community to ensure that we can make sense of this at the scale that it's operating to ensure that the human side today can understand exactly what's happening and can respond to it. There's a belief that in the future, the security operations center will be automated AI agents fighting automatic— automated AI agents who are the attackers and putting in place the corrective action. We're a little bit away from that, obviously, right now, and will be for some time. But the criticality of this is to make sure that we put in place the defenses and the insights required for security to make sure they can at least have an understanding of what's actually happening inside the network. Again, like the Hugging Face example, where OpenAI was operating inside their network for a very long time before IT even was aware of the fact there was a potential attack underway. That's also the nightmare scenario for many of these CISOs and CIOs as well.
KB [00:37:08]:
And so just to extend on that, would you also say because, so A, a company's aware in terms of we have to monitor like network protocols, so we have more fidelity into our organization, but then B, Are they still, companies still rattled by the AI bill end of the month that they just can't see past it now in terms of like a headspace thing or no, the board's so worried about cleaning up the AI mess that we can't even think about giving you more budget to the CISO person. So, how does that then look and how's that gonna play out, would you say, moving forward?
Shane Buckley [00:37:40]:
That's a great conundrum. So, you're exactly right. The growth in spend of AI on a percent basis is massively outstripping the growth of spend of IT budgets. And so let's call it a pizza, right? So the pizza is pretty finite. AI is now taking a bigger slice of the pizza. So guess what? When AI is finished consuming its slice of the pizza, there's less pizza to feed the rest of us. So therefore, at precisely the time where organizations should be spending more on security, they're now being told you have to reduce your spend on security. You're spending too much on security tools, as well as other tools like network performance, application performance, observability tools as well.
Shane Buckley [00:38:17]:
Because the budget just doesn't support us continuing as we are. In reality, the spend on security for AI should be at least matching the consumption of AI, but in reality, in most cases, it is not. Whether you're dealing with governments, service providers, or enterprises, in our experience, there's a smaller amount of spend focused on security and performance of networks because the spend is going up. That is a very worrisome trend. Because you're actually enabling the nefarious actors to behave more unfavorably to the organization than you are to those who are— their job is there to defend the organization from the attack. And so we have to think about this differently. To your point, you were absolutely spot on. We have to look at what's happening inside the network, understanding these protocols, decoding the protocols to understand what are the problems happening inside the network.
Shane Buckley [00:39:09]:
Even understanding where is AI unsanctioned, where is it operating in a way that it shouldn't be operating inside the network, that's the first place to go because you can shut that down pretty straight away. That's actually not a hard thing to do. It's built into many of the standard deep packet inspection protocols that a number of security products have today. And so I would suggest CISOs look at it from the point of view of let's understand how AI is operating inside my network, get better visibility and controls into what it is doing. That gives you an opportunity to identify it and potentially isolate it, shut it down. And as you do that, then you can look to augment some of the traditional security stack that may not be as relevant anymore because you're now running this parallel network that's actually starting to consume more and more of the user community than the traditional stack is. And so you can then start making the trade-offs in a controlled way. Also, if you've chosen your partners correctly, you don't need, to your initial question in this podcast, you don't need all the different vendors you have from the traditional security stack.
Shane Buckley [00:40:12]:
Let's start paring them back. The stuff that's nice to have, let's keep the stuff that you must have. Maybe let's take away the nice to haves to make sure that you can balance your focus onto what's really critical, which is really understanding what is AI doing? What's it doing that I'm happy with? What's it doing that I'm really not happy with inside my infrastructure?
KB [00:40:30]:
Okay, Shane, final question. So going back to your pizza analogy, if AI spend has taken up majority of the pizza and there's one slice left that gets split amongst the rest of the vendors, does that mean the customers are going to start squeezing vendors for more capability on our renewal? We want it cheaper because we don't have any money because AI has taken it all. Does that then cause more competition from the vendor community to perform their outperform their competitors and outrank them. And how does that look then from like downstream impacts on customers? Not, might not have as much budget as they had before, as we've clearly seen throughout today's interviews. So what is that? How's that going to look now? Or do you think there will be just, we don't need that nice to have product anymore? It's out.
Shane Buckley [00:41:17]:
100% spot on. Anything that's, uh, that's nice to have is done. And so one of the forecasts that analysts and others in the industry have provided is if you take the traditional tool stack we talked about earlier on, network performance, application performance, observability, and security tool stack, it's about a $34 billion spend a year for organizations. That's going to collapse dramatically fast as, first of all, next-generation SIEM data lake architectures kind of replicate that set of capability with one horizontal set of data and leveraging agentic AI literally to find the needle in the haystack. That's a way to do it without creating risk inside your organization. So that's probably the lowest hanging fruit, where organizations, CISOs will go and say, I'm not spending this anymore, I'm just going to move to this next generation, SIEM architecture, which is going to enable me to get there. A lot of organizations doing that. That's the smart thing to do.
Shane Buckley [00:42:13]:
The not so smart thing to do is to wait until AI is consumed this analogy, the majority of the pizza, and you've got 10 other members of the family going, I'm starving, I need to eat, and we're all getting a crumb. Well, guess what? When that happens, people die because they obviously need food to survive in the same way as these tool vendors. But there is increased competition from these tool vendors. You look at many of these public companies since October of last year, the market capitalization of many of these organizations has collapsed for the reason that Wall Street knew fundamentally If AI is a headwind for you, you're done. You have to prove that AI is a tailwind where it can actually generate more revenue and give you the ability to survive because you have a strong enough competitive moat. And what we've seen though is whether you're a public company or many of the private companies, either through venture or private equity investments, is that if you cannot prove positively that AI is the basically as a strong tailwind for you, you're done. Because ultimately, IT spend will start being much more vicious. The elbows will be sharp and they'll be out.
Shane Buckley [00:43:20]:
The finance department will come in to cut and the CIOs and CISOs will say, hey, we've done business with you for 10 years, but we're not renewing our subscription this year because we're out of budget. There's nothing else we can do. And unless the organization doesn't fail, they're like, you know, we'd have to do without it because it's a nice to have. So your observation is actually spot on. I see that happening today. I see in every conversation we have with customers, they say to us, you got to prove to me how critical you are. We show them where the ball is and what we're doing today, where the ball is going, and our journey with them in terms of helping them provide better protection from an AI perspective. They get the message and say, yep, okay, you're someone I need to invest in because you're coming on a journey with me, versus an organization says, hey, look what we did for the last 10 years.
Shane Buckley [00:44:03]:
So, they're focusing on where the ball was, not so much where the ball is going. Guess what? Smart folks in IT are like, or in procurement and finance, like, yeah, I appreciate your spur of the last 10 years, but life is tough. We're moving on.
KB [00:44:18]:
That was Shane Buckley, everybody. What stays with me is the asymmetry he laid out. AI is now generating an endless stream of attacks. A bunch of humans are still defending, and they have to block every single way in, but the attacker only has to find one. If you're a CISO listening to this, the maths is exactly why he says the first move is simply seeing what AI is actually doing inside your network.
VO:
I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn.
KBKast - Cyber For the C-suite.