Shadow AI Is Real. Roll Out AI Safely Before It Bites You.

so welcome to another episode of cloud

unplugged um

Today,

I believe we promised that we were going

to talk through how to roll out AI

safely.

This has come up quite a lot in

our existing customers and people we've

been working with.

The term shadow AI has been coined where

people are secretly using AI to their own

personal account.

And obviously that's a bit of a concern

for a lot of businesses because they don't

really have any control or oversight.

And they also just want to start to

use it for their business.

They obviously want to start to use it

for coding.

They want to start to use it just

to improve

efficiencies and content that they're

trying to create, et cetera.

However,

how they approach it and where do you

begin is often the challenge.

So we've broken things down in this

episode to kind of go through all of

the different pillars that we consider all

the prime ones.

I think there are six in total.

then we'll talk through a bit of an

approach and a process around it and like

how and where do you begin in relation

to those pillars um but before we crack

on to that um obviously i just salman

how are you doing before we obviously get

into that

I'm doing very well,

busy implementing these techniques so

everybody can have a safer time with AI

and the models they want to use.

John, looking a bit different today.

I see a bit of a tan going

on.

Were you away?

Where were you, John?

Tell us a little bit more.

It's just my genetics, actually, Salvan.

I've not actually been anywhere.

No,

I was in Spain in Costa Brava area.

which is like the Catalan area of Spain.

There's a place called La Scala.

I don't know if you've ever heard of

that, but it's south of Girona,

which is near Figueres, basically.

But yeah, very, very beautiful.

Lots of nice beaches.

A lot of kite surfing on some of

the beaches there,

because I think they get some wind.

So yeah, I've caught the sun.

It was thirty-eight.

thirty eight degrees yeah just casual

thing because it wasn't hot just a couple

of degrees above uk to be honest like

you know maybe a couple any any talk

any talk of ai out there in in

spain john and holiday no talk of ai

no because they're all like kind of um

traditional snorkeling

fishing boats, a bit of tourism,

lots of restaurants, you know, type vibes.

Very chilled, relaxed,

non-technology based vibes, which is good.

It was good to kind of switch off.

You went for detox.

John went for detox and came back for

the next visit.

Yeah, I stayed.

My friend there,

she's opened a grocery shop in a little

village.

And then her partner has got a restaurant

in La Scala itself.

So there was a lot of trying loads

of things I don't normally eat,

but being super polite and be like, oh,

wow, this is really...

uh but really be like okay i don't

normally eat things like this but actually

it was very good so out of politeness

i was forced to try new things which

is good excellent okay so tell us tell

us john when people approach you and they

say i want to roll out ai safely

and securely just so i have control over

what is being run on my estate and

people not accessing any of these tools uh

without any guardrails so they don't get

hacked.

You've seen so many issues that are

happening recently.

Things are getting called out that you

don't even know are getting used and

leaking data.

You're leaking your sensitive information.

What are the steps we have to take

in the pillars that you talk about to

make sure you roll out AI safely in

your organization?

Yeah,

so I guess I'll kind of go through

each pillar first.

Yeah.

so obviously the beginning bit is the

identity and access and device management

um so

You know,

do you have control of the devices that

your, I guess,

end users are kind of working on?

Is there any controls over them?

Do you have audit?

Are you approving the applications that

get installed?

And can you tell whether or not people

are doing things on their devices that

they shouldn't be or that something maybe

has got installed that maybe is malicious

by accident?

And do you have the audit of all

those things?

So that's one lens.

So it's like,

how are you managing the devices

themselves?

So that is even without AI, right?

So that's just good practice anyway,

right?

Good practice,

but a lot of businesses may have not

felt a need necessarily to have full

device management.

They might have a different policy for

different teams.

They might have all kinds of reasons,

legitimate reasons that

may have been cost-saving initiatives um

that might have done it more for

developers or people that are more closer

to infrastructure because there's more

risk because that's where the data is yeah

they're closer to the general day-to-day

data applications for customers but

actually we do you want to treat it

as one universal thing now that everyone's

using ai um so

That's a very specific thing.

And there are tools that you can install

that the cloud providers provide.

They're not all equal.

I think Azure is a little bit more

improved.

So they have...

basically a browser DLP,

which data protection and it can kind of

detect in the tabs for Chrome or Edge

or Firefox.

It can do detection on whether or not

you're doing malicious intent with data,

potentially IAUR.

copying and pasting things from documents

into chat gpt that's you shouldn't be um

and it can kind of detect those things

um then you have the users themselves you

know how does your identity look how are

people

logging into your systems,

have you centralised that,

are you using single identity, MFA,

all kind of the standard aspects,

least privilege, good RBAC controls,

conditional access, et cetera, et cetera.

Then you've got the control plane itself,

which is a little bit ambiguous calling it

a kind of control plane,

but that's something that sits in front of

the model.

Some call it a gen AI gateway.

So basically a way of obviously going

through into the model itself,

a proxy almost.

And in there you can then put controls

inside of the proxy.

So obviously you can do token limits.

You can do fail back routing to another

model in there.

You can do content safety filters and

prompt shields,

and you can obviously hook those things in

as well into additional stuff like Purview

as well.

And then you get into data governance,

which is the classification of your data.

Do you have things labeled properly to

know whether it's sensitive or not?

And therefore, again, certain services

Obviously,

when you kind of categorize the data,

it will then know, okay,

this is sensitive information here.

It's already labeled.

I need to take precaution on that.

Encryption, et cetera, et cetera.

Then you've got the platform foundations,

which are just general information.

cloud foundations, landing zones,

networking, private networks,

internal endpoints, that kind of stuff.

And then you've then got the monitoring

and audit.

Do you know if somebody is doing something

malicious?

Can you detect it?

Are those events coming into a central

place?

Do you have all the right monitoring and

alerting around those services so that you

can detect something when it does happen?

Even after you've prevented everything in

those pillars, like we've said,

you still need to know there's still risk.

Do you have the right oversight?

Yeah.

Do all those things make sense to you,

Salman?

Absolutely.

It seems like, John,

that we're not reinventing the wheel.

Is that fair to say that these are

the practices that you currently follow

anyway?

These are good practices just to keep

yourself secure and keep yourself

compliant to a bunch of these things.

But I guess because of these problems with

accessing the AI models,

it's a bit exacerbated because people see

issues a lot more nowadays than perhaps

they were in the past.

But it seems like we're not talking about

anything new.

Perhaps some implementation is a bit

different because we never had to worry

about tokens before.

And now we're thinking, oh,

maybe in the proxy we can add some

limitations of the cap of a token can

go in there.

But is that fair to say that we're

not talking about something?

Yeah, I don't think the concepts are new,

but I would say that the user behavior

is completely different.

So before you would have to share

sensitive business data would have been an

intentional act to maybe email it to

yourself or something like that.

But today people are obviously using it to

help them be better at their job or

maybe to give insights into something that

helps them produce a report or maybe scan

things quickly for them on their behalf.

So they now are like where you would

have been really that would be more about

sharing the assets externally for

different reasons.

You're now sharing them legitimately to

help yourself be better at your job.

Hence it being called kind of shadow AI.

So those things are a little bit different

because it means you've got to be quite

good at really almost blocking.

That's kind of what you really want to

do.

You want to block any other models outside

of your own approved models so that

everyone is forced to basically go through

your central control plane, i.e.

the Gen AI gateway,

and they can't bypass it and go to

some other model or use their own personal

account or bypass.

And that's interesting.

Yeah.

And the risk here is what, John?

What are we trying to prevent?

Are we saying that, oh, as a company,

we can only use models that are provided

by Claude,

but we don't trust any of the models

that are provided by Grok?

What are we trying to protect here?

Are we trying to protect IP?

Are we trying to keep ourselves safe

online?

Or what is the thing that we're trying

to protect here?

I guess many reasons.

I guess one could be you don't necessarily

have an approval for that model.

It could be that

the sovereignty of the model,

like where it operates in, you know,

is not under the jurisdiction of the EU

or, you know,

under your own legal kind of rules and

regulation,

and therefore people sending sensitive

customer data outside of your jurisdiction

into other countries into the model is

obviously not approved.

It could be that you're installing,

people are installing things

to integrate into third-party tools to

make it easier i.e um i don't know

google drive and sharepoint and you know

so you're connecting up um into say it

could be anything could be like claude

desktop or co-pilot you know and you're

connecting things up third-party systems

that then have access to lots of different

data um and i think the difference between

a human and ai is you know

to do a task,

you'd probably be quite intentional of

where to look.

So you'd be like, okay,

I know this information's stored over

here, or I'd probably quickly navigate.

With AI,

it's probably reading everything to figure

it out.

So to know where to go,

it's had to process every other piece of

data to then figure out the right answer.

And obviously that's very different to a

person,

but it's now acting on behalf of you.

So it's acting as if you're doing it

because it's using your identity.

And obviously that's a lot of risk.

So what you're saying is that if a

person is on their machine and they're

trying to, let's say, look at a reporter,

identify whatever task they're doing the

ai could potentially read whatever's on

their machine they could have sensitive

data on their machine and feed it to

the ai model which is what we don't

want to do is that correct we're trying

to protect the the sensitive information

that you have from reaching the ai model

so perhaps you can use it uh to

train itself and get better is because i'm

trying to get to is that a bad

thing is this about i guess two things

you could you could decide that for

certain operations

you want a much cheaper model.

So that could be one reason.

So you're like, actually,

for this type of day to day stuff,

I don't want to be sending loads of

data to the fable,

most expensive model for these types of

activities.

So yeah, there's that.

And then obviously you don't want to be

necessarily getting a load of random data

and then shoehorning it into a model

because that's just what you've got access

to.

So not just on your device,

it could be

You might be overprivileged.

You might be an admin of your estate.

You might be a drive admin on SharePoint.

The whole thing, yeah.

You've got access to absolutely every

piece of information,

and then you're using AI on your machine.

Technically,

then it is also getting access to

absolutely everything through your own

permission.

All right, cool.

Tell me, John,

how do I get a device that is

secure,

the first of your pillar's device and

endpoint?

What do I need to do there to

get myself safely into this AI land?

uh well i think the first thing to

do is if you are wanting to use

it for your business um the high high

probability is outside just coding um

you're going to want it to have access

to files and information right it's it's

only valuable when it can start to process

things on your behalf so you don't have

to process it all to then give suggestions

or commentary or improvements or new

content but so you then need to really

understand

what is the current data access governance

that's already in place?

Have we shared everything with everyone by

default?

Because you might not even know what is

really shared with you and what you really

have access to because you're not

necessarily going through every single

file on the drive to see,

can I or can't I access this stuff

that I should or shouldn't be able to

access?

So you need to obviously do a bit

of a data access governance process,

produce a report, look,

quite quickly at whether there's over

permissive permissions in there and that

you've got all the right going around.

So that'd be the first thing to do

before you start to roll it out.

And then sort that out quickly and then

look at identity.

Similar thing in your RBAC controls,

your identity and access management.

Is that quite strong and a good posture

there?

What's RBAC control, John?

Can you just please explain what is RBAC

control?

Well, you've heard it here first, guys.

He doesn't know what RBAC is.

Please, John.

I'm a little bit in shock.

What is RBAC, John?

Role-based access control is what it is.

Okay.

Basically,

what access are people allowed to have

access to?

What's the permission set?

But not just that, as in

are you doing short-term access?

Are you making people escalate privilege

when you need to?

That kind of stuff.

But also, have you...

Are you blocking maybe certain GOs?

Would you expect somebody to be logging in

from China?

You know, that kind of stuff as well,

right?

So it's not just the permissions.

Yeah, okay.

Not to pick on China, obviously,

because it's got a...

Rumor is it's got a very cheap model

that's quite competitive nowadays.

And there's Kimi K.T.

that came out, John,

a couple of days ago.

on par with fable according to the tests

and uh i have to confess i did

try it it did work at times and

at times i did get some errors perhaps

everybody was trying it so uh yeah my

machine doesn't block the use of kimi

k-three at the moment john i'm just

letting you know that wow okay uh so

Got a real life security risk on the

podcast.

Is that what we're saying?

Is this a confession?

I'm not saying it's a security risk.

I'm just saying that I tried it, John.

But luckily on my machine,

I don't have any sensitive information.

Apart from some photos and podcasts.

We're very equal opportunistic here,

though.

That's our stance.

So we don't like to get into geopolitics.

We're all about...

open open and transparent geo uh

approaches um so yeah the us whatever all

for we're all for technology right that's

what we are technology yeah awful

technology where we just uh you know

that's what we're doing techno optimists

john that's what we are we try all

technology

But yeah,

so I guess once you've done the

assessments,

once you have fixed your identity,

once you've assessed as well your current

kind of foundations,

where's your maturity,

have you got a good control over maybe

a central VPN that people are routing

towards,

some form of governance over the device

routing,

Can you block people from going to

specific websites?

That type of stuff.

And have you got all the right audit

and logging into like some central kind of

control place that you can do security

reports on and central policies that you

could easily roll out?

That's what we call kind of the

foundation.

So they're the first things that get all

of that in place.

And once that's in place and the devices

and you've ticked all those things off,

then you're kind of safe to be like,

right,

let's start to think about the model and

the gateway that we're going to put in

front of it.

And then who should have access to it?

And are we going to roll it out

team by team?

And are we going to get the right

telemetry there?

Are we going to report on the token

usage?

Have we got good security over it in

the gateway?

Are we going to use Purview?

Have we looked at the sensitivity and then

start to do it that way on a

case by case basis?

And maybe you want kind of approved things

like what are the things in the catalog

that you're allowed to use?

I was mentioning the connectors, right?

What are you allowed third party-wise to

connect into?

Other specific things that we approve,

i.e.

SharePoint.

We'll let you use the MCP for SharePoint.

Maybe we'll let you use GitHub MCP,

et cetera, et cetera.

And then you'd control that rollout so

that you can't just use whatever you want.

were obviously managing it on a

case-by-case basis,

like you would policies and other

exemptions.

You'd safely want to control that.

After that,

You're then into obviously kind of

generalizing it more.

So then it would be looking at it

through the lens of applications.

You want to reuse all of this because

it's universal.

You'd have all the right controls that in

place to then be like, right,

let's get the applications doing a Gen

Tick.

Let's use the same gateway.

Let's use that control plane.

Let's use Purview,

which we're already using.

Let's make sure that we've got all the

reporting on the sensitive data.

And then you'd start to maneuver into more

expansive areas,

which are application-centric things,

reusing all the same governance and

processes that you've already got in

place.

Does that make sense?

It does make sense.

It does make sense.

It does.

And so that's why we're about to stop

your device from using the new China

model.

I believe we're about to roll that out

on the MDM now.

So if you've got anything running,

you might want to quickly get the

information out now before we block it.

So I do need to go back to

a point.

You keep mentioning the use of Purview in

the governance part.

That's just an example of a service in

Microsoft.

Yeah, absolutely.

Maybe can we go a little bit more

into how do you use Purview to make

sure that you've done the right level of

governance?

Can you go a little bit more into

that?

So Purview, just as an example,

offers data lineage protection.

It can keep track of all the

transformation of information and data and

where it's gone through.

It also has these classification concepts.

I think it comes out of the box

with a load of default classification and

rules.

And you can add to those rules yourself,

essentially,

of how can it understand the data or

your data and the sensitivity around it.

Yeah.

And so, yeah,

I think it's based on aspects of what's

it called?

The Apache.

Forgotten the name,

but basically there's an open source

project for data lineage.

I think they've all wrapped that.

I think Amazon and others

Is it Atlas?

Apache Atlas?

Can't remember.

Anyway.

Yeah, that's fine.

So all the same concepts,

all open standards,

nothing specifically bespoke about them.

It's just that they wrap these services

and you can then roll them out and

then have extended it into additional

things, obviously like the DLP stuff,

which is the in-browser extensions that's

then feeding back into Purview.

So they're connecting things into Purview

to then do the governance and control in

that for the data layer.

So to summarize,

what we're saying is in order for you

to roll out AI safely and securely in

your organization, of course,

there's always risks,

but to reduce the risk of rolling out

AI with governance,

you have to do a few things.

Make sure your devices and endpoints are

controlled by the bits that you mentioned,

use MDM Intune, have compliant devices,

then make sure people have the right

access.

you know,

you mentioned RBAC role-based access

control,

ensure that they have the right level of

access,

the right level of information on the

machine,

just so the models don't have way more

information than they're supposed to have,

and then have what we call the AI

gateway, i.e.

the proxy,

in which you can control and have

guardrails and what the model can access

from your machine, perhaps, you know,

and token management and token limits and

routing, you can do that.

And then what we're talking about is

making sure that, you know,

You have the right data governance in

place.

You restrict the content discovery.

You have the encryption in the right

place.

And then the good platform foundations

that already exist.

You have private endpoints.

You're controlling everything correctly.

You have the right keys in place.

and after doing all this you always still

need to make sure that you're monitoring

you're auditing and logging what's

happened because if something happens you

perhaps want to go back and see what

happened and also notify you when

something wrong happens right so have

these six things in place and then we

think about how do we roll it out

which is uh that's what we do is

that correct john is that what we're doing

That's pretty much it.

I mean,

you don't need to I think using a

project to prove it out first as a

bit of a lighthouse thing.

I think it's probably that's how I would

do it first,

because you'd want to validate how

effective and efficient not just the

technical implementation is,

but your own processes around it.

Because if from a process perspective,

You know,

if the team's already saturated with BAU

and you're trying to add more work into

the teams to then be managing,

onboarding different projects into AI and

putting all the content filtering in

place, maybe inside of the gen AI gateway,

you know,

what filters and protections do we need

for this team?

You know,

is it still are the same same filters

still applicable from the lighthouse team

into the next one, et cetera?

You're iterating and trying to understand

from project by project where the risks

are.

So I guess you do need to look

at like,

how is it actually operationally going to

come together?

Who's accountable and responsible for

what?

you know is our device management already

functioning really well and quickly or is

this gonna cause scaling problems you know

into the business when we start to

obviously roll this so you do need to

be thinking operationally as well as

technically on both sides to get it right

and doing a bit of assessment on that

um but yeah from a technical perspective

they're all the things you spot on they're

all the things that you do need to

think about um as well yeah

If I'm a CIO or a CTO, John,

which I'm not, or COO,

or even a CEO, which you are, John.

Yeah.

what is one message that you should give

to them for the safe rollout of ai

because one one thing is yes we have

all these things all the things that you

have to do to to monitor this is

for the usage but also the people who

are implementing these policies you know

like the it department or where it might

be things are moving so quickly new models

are coming out every time everybody's

saying oh i need the claude fable five

right it's just come out i want it

What do you say to them?

How do you first roll out safely?

Secondly, stay on top of it.

So, you know, people who are using this,

they don't stay behind.

But what is the one thing that they

should focus on?

A couple of things.

I know we talked about these six pillars,

but what are the couple of things you

should tell them in this podcast, John?

Uh...

i don't know about a couple of things

i think the main thing is to understand

the objective of it first as a business

you know are you wanting to roll it

out because you've got shadow ai going on

and that feels like a high risk so

it's more of a risk goal how do

we mitigate the current risk or

is it that you're wanting to roll it

out because we're wanting to reduce our

operational overheads currently in our

business or is it the development side is

it speed of coding or is it application

centricity are we trying to roll it out

because we want to get to new markets

or wanted to improve our product features

so

You can't what I wouldn't suggest is

saying all of it, please.

Obviously, I know that,

but it's probably trying to work out as

a priority,

which is the first thing to prove for

AI first,

rather than trying to look at everything

that it can do and then trying to

boil the ocean with everything.

I think then the principles of all these

pillars are contextual then to the goal

and the objective.

How deep you then go in those pillars

is contextual to what the real ambition of

the goal is.

Therefore,

you don't need to necessarily start

getting into all of the depth of each

pillar straight off the bat,

and then it takes a year or whatever

insane amount of time to roll it out

safely across the business.

And no one's getting to see any value

out of it at all.

Basically, you've diminished your value.

So start with something very clear and

concise that frames everything and then

choose that lighthouse customer and then

prove those pillars on a shallow front

first without loads of depth and then

build the depth over time as you then

maybe buy another objective off would be

my advice.

Okay,

so this is excellent advice because if you

try and implement everything in the first

place, it might just take you months.

I think that is what I was trying

to get to, right?

So your advice, John,

to people is pick one use case and

implement for that first rather than

thinking about everything under the sun,

operations, development,

just pick one use case and then implement

it

See how that goes.

Because you have to iterate quick over

this.

I know, John,

we keep joking about how these models are

next token predictor and sometimes they're

not that good at producing the information

that you require.

But at the same time,

if you're not using these models,

you'll be left behind.

Yeah, you will.

Yeah.

But I think because there's so much to

it.

Like we're saying,

I think because it assumes a certain level

of current maturity,

like you were saying at the beginning,

these are not new concepts.

Device management isn't a specific AI

concept that's come off the bat of rolling

AI out.

Data governance isn't a new thing.

Identity and access management isn't a new

thing.

So I think what it is doing, though,

is probably challenging a lot of

businesses on their current maturity

posture.

in those pillars already you know where

are you in relation to this and it's

kind of maybe putting it under the

spotlight a little bit more so on like

actually the risk of this is much higher

um as a thing strategic objective than

maybe some other things that we've had to

do before and therefore we do have to

get these things right but again doing it

right is contextual to

what is the first thing you're starting

with and getting the first thing right,

not necessarily getting all of it right,

I think is the aim.

Otherwise, you'll never get anywhere.

You'll be just sat spinning wheels for

ages trying to get everything perfect.

You will just increase shadow AI,

won't you?

Yeah,

how are you finding the role out of

this?

I know, John,

you've been working with a bunch of

organizations.

What is your approach that you're taking

to your clients?

How are you finding the reception of this

approach?

Are people saying these are the right

levels of controls that we're putting in

place, or is it too much?

Are you asking too much of our

organization to do?

How are you finding it?

So I think everybody seems so far to

be quite...

well versed in understanding what it

means.

I think probably because as in what it

means to

the risk I think is more what I

kind of mean there because everyone's

using it personally and so they've already

kind of they're already sending things hey

here's my I don't know here's my travel

documents for this thing or go read my

email for this thing and I want to

improve like I need to change the flight

to whatever and you know I need to

book this holiday and so that everybody's

sharing quite a lot of themselves right

already so

I think the concept of data sharing is

very well understood already.

So there's no educational aspect there.

I think what I will say is probably

the biggest challenge is the facilitation

on scope.

I think that's probably the value we bring

is really trying to pinch it into

something of like,

how do you prove the first piece of

value of AI rather than

getting hung up maybe on all of the

risk of AI as an entirety all the

time.

So trying to get everybody into the right

mindset of we don't need to worry about

all those things first.

Let's just really try and work out what

is it you're really trying to do because

we want to prove value quickly.

That's always the aim.

Everybody wants that.

um and so let's really focus on that

i think most people probably struggle with

that bit is probably the biggest thing

like where do we begin begin what do

we choose yeah and what's what about you

because you're in customers too and you're

obviously speaking to people all the time

and you know what would you agree with

some of the things i've said do you

think i'm talking nonsense

No, no, John, a hundred percent agree.

I think the issue that I see is,

and the reason why I really like your

idea of just pick one use case and

run with it,

is because

luckily for us open ai and anthropic have

done the marketing for us right because

everybody as you say is using these models

in their own capacity and then they see

some of these colleagues or some of their

friends are making things really quickly

prototyping businesses right websites apps

they're just coming out within a couple of

days things are working and

What people are asking is,

can we have this straight away?

Can we have this technology?

Because a lot of organizations are like,

well,

we're not going to allow you to use

these tools because we're still trying to

figure out how to use it safely,

how to use security, what's allowed,

what's not allowed.

So the employees and their colleagues are

not getting it fast enough.

I think that's number one.

Some organizations are still trying to

figure out how to do this securely.

That's number one.

They're not getting it fast enough.

And number two is the people who are

implementing this.

They're like,

there's a lot of this that we don't

fully understand.

So there's an education on what are the

actual risks?

Sometimes when you have that major threat

matrix that you make,

what are the threats?

And that's why it's important to

understand what are the actual threats?

that you're trying to mitigate against.

And we're seeing it being rolled out.

And I think the biggest issue for the

organizations is making sure that people

are not sharing this sensitive

information.

I think that's the biggest problem that

they're worried about.

Some companies don't really care too much

about, oh, okay,

if you do share my piece of code,

which is already coding in the open.

So, I mean,

if I do use that model to share

my code, I mean,

it's already in open anyway,

so it doesn't make any difference.

but some people are still worried about oh

i've got this proprietary software that if

people are doing software development on

that's going to go to the model

then you know people will get people get

our proprietary information but the model

i'm not really too sure if that's too

much of a problem because you know the

model already has a bunch of this

information already there right uh you

know like creating rocket science is not

something not new but yeah so what we're

saying is people uh in some organizations

really want this and the the organizations

are still trying to figure out well number

one which models to use

and the cost of these models and i

think people are worried also about the

tokens right remember we spoke about a

couple of podcasts ago ceo of uber said

we blew up all the budget for the

whole year in april uh twenty twenty six

for the hood and there's not one single

feature i can tell you that was released

with with ai right so there's uh

still a very new area that people are

trying to get to grips with yes good

you can go on chat gpt and ask

it to generate you images of you doing

one or other thing or you can like

run your own websites which is fine but

like i i still think john um this

what you talk about the six pillars is

needed we're talking about pick one use

case and developers needed so yeah this is

uh this

This is an area that's developing really

quickly.

But the good thing,

as you mentioned earlier on,

is these principles they were discussing.

They're not new.

Some of the implementation is a little bit

different, but they're not new.

Yeah, exactly.

Cool.

Well, that's it, I think,

for this episode.

Well, it felt short,

but it hasn't been as short as I

thought it would have been.

But I guess the next one,

we will probably either choose a topic or

get back to the news.

There's been a load of things in the

news,

which I did really want to have had

to bite my tongue to not bring up.

We kind of did hint at it a

bit with the new model from China and

how cheap it is and the efficiency of

it.

been on a par but for a fraction

of the price I believe as in like

the cost the capex cost that it's taken

I think is something like you know I

can't remember like half or even more

maybe like a third of the price that

they've had to spend to get to the

same place as the US super interesting and

share prices and all these things going on

so we'll probably maybe touch on that

depending on what's happening next week

but yeah

Stay tuned for the next episode.

Cool.

See you later, everyone.

See you.

Creators and Guests

Salman Iqbal
Host
Salman Iqbal
Salman is an experienced Cloud, Data and AI leader, lover of all things AI, Cloud, Platform Engineering and Development tooling.
Shadow AI Is Real. Roll Out AI Safely Before It Bites You.
Broadcast by