Shadow AI Is Real. Roll Out AI Safely Before It Bites You.
so welcome to another episode of cloud
unplugged um
Today,
I believe we promised that we were going
to talk through how to roll out AI
safely.
This has come up quite a lot in
our existing customers and people we've
been working with.
The term shadow AI has been coined where
people are secretly using AI to their own
personal account.
And obviously that's a bit of a concern
for a lot of businesses because they don't
really have any control or oversight.
And they also just want to start to
use it for their business.
They obviously want to start to use it
for coding.
They want to start to use it just
to improve
efficiencies and content that they're
trying to create, et cetera.
However,
how they approach it and where do you
begin is often the challenge.
So we've broken things down in this
episode to kind of go through all of
the different pillars that we consider all
the prime ones.
I think there are six in total.
then we'll talk through a bit of an
approach and a process around it and like
how and where do you begin in relation
to those pillars um but before we crack
on to that um obviously i just salman
how are you doing before we obviously get
into that
I'm doing very well,
busy implementing these techniques so
everybody can have a safer time with AI
and the models they want to use.
John, looking a bit different today.
I see a bit of a tan going
on.
Were you away?
Where were you, John?
Tell us a little bit more.
It's just my genetics, actually, Salvan.
I've not actually been anywhere.
No,
I was in Spain in Costa Brava area.
which is like the Catalan area of Spain.
There's a place called La Scala.
I don't know if you've ever heard of
that, but it's south of Girona,
which is near Figueres, basically.
But yeah, very, very beautiful.
Lots of nice beaches.
A lot of kite surfing on some of
the beaches there,
because I think they get some wind.
So yeah, I've caught the sun.
It was thirty-eight.
thirty eight degrees yeah just casual
thing because it wasn't hot just a couple
of degrees above uk to be honest like
you know maybe a couple any any talk
any talk of ai out there in in
spain john and holiday no talk of ai
no because they're all like kind of um
traditional snorkeling
fishing boats, a bit of tourism,
lots of restaurants, you know, type vibes.
Very chilled, relaxed,
non-technology based vibes, which is good.
It was good to kind of switch off.
You went for detox.
John went for detox and came back for
the next visit.
Yeah, I stayed.
My friend there,
she's opened a grocery shop in a little
village.
And then her partner has got a restaurant
in La Scala itself.
So there was a lot of trying loads
of things I don't normally eat,
but being super polite and be like, oh,
wow, this is really...
uh but really be like okay i don't
normally eat things like this but actually
it was very good so out of politeness
i was forced to try new things which
is good excellent okay so tell us tell
us john when people approach you and they
say i want to roll out ai safely
and securely just so i have control over
what is being run on my estate and
people not accessing any of these tools uh
without any guardrails so they don't get
hacked.
You've seen so many issues that are
happening recently.
Things are getting called out that you
don't even know are getting used and
leaking data.
You're leaking your sensitive information.
What are the steps we have to take
in the pillars that you talk about to
make sure you roll out AI safely in
your organization?
Yeah,
so I guess I'll kind of go through
each pillar first.
Yeah.
so obviously the beginning bit is the
identity and access and device management
um so
You know,
do you have control of the devices that
your, I guess,
end users are kind of working on?
Is there any controls over them?
Do you have audit?
Are you approving the applications that
get installed?
And can you tell whether or not people
are doing things on their devices that
they shouldn't be or that something maybe
has got installed that maybe is malicious
by accident?
And do you have the audit of all
those things?
So that's one lens.
So it's like,
how are you managing the devices
themselves?
So that is even without AI, right?
So that's just good practice anyway,
right?
Good practice,
but a lot of businesses may have not
felt a need necessarily to have full
device management.
They might have a different policy for
different teams.
They might have all kinds of reasons,
legitimate reasons that
may have been cost-saving initiatives um
that might have done it more for
developers or people that are more closer
to infrastructure because there's more
risk because that's where the data is yeah
they're closer to the general day-to-day
data applications for customers but
actually we do you want to treat it
as one universal thing now that everyone's
using ai um so
That's a very specific thing.
And there are tools that you can install
that the cloud providers provide.
They're not all equal.
I think Azure is a little bit more
improved.
So they have...
basically a browser DLP,
which data protection and it can kind of
detect in the tabs for Chrome or Edge
or Firefox.
It can do detection on whether or not
you're doing malicious intent with data,
potentially IAUR.
copying and pasting things from documents
into chat gpt that's you shouldn't be um
and it can kind of detect those things
um then you have the users themselves you
know how does your identity look how are
people
logging into your systems,
have you centralised that,
are you using single identity, MFA,
all kind of the standard aspects,
least privilege, good RBAC controls,
conditional access, et cetera, et cetera.
Then you've got the control plane itself,
which is a little bit ambiguous calling it
a kind of control plane,
but that's something that sits in front of
the model.
Some call it a gen AI gateway.
So basically a way of obviously going
through into the model itself,
a proxy almost.
And in there you can then put controls
inside of the proxy.
So obviously you can do token limits.
You can do fail back routing to another
model in there.
You can do content safety filters and
prompt shields,
and you can obviously hook those things in
as well into additional stuff like Purview
as well.
And then you get into data governance,
which is the classification of your data.
Do you have things labeled properly to
know whether it's sensitive or not?
And therefore, again, certain services
Obviously,
when you kind of categorize the data,
it will then know, okay,
this is sensitive information here.
It's already labeled.
I need to take precaution on that.
Encryption, et cetera, et cetera.
Then you've got the platform foundations,
which are just general information.
cloud foundations, landing zones,
networking, private networks,
internal endpoints, that kind of stuff.
And then you've then got the monitoring
and audit.
Do you know if somebody is doing something
malicious?
Can you detect it?
Are those events coming into a central
place?
Do you have all the right monitoring and
alerting around those services so that you
can detect something when it does happen?
Even after you've prevented everything in
those pillars, like we've said,
you still need to know there's still risk.
Do you have the right oversight?
Yeah.
Do all those things make sense to you,
Salman?
Absolutely.
It seems like, John,
that we're not reinventing the wheel.
Is that fair to say that these are
the practices that you currently follow
anyway?
These are good practices just to keep
yourself secure and keep yourself
compliant to a bunch of these things.
But I guess because of these problems with
accessing the AI models,
it's a bit exacerbated because people see
issues a lot more nowadays than perhaps
they were in the past.
But it seems like we're not talking about
anything new.
Perhaps some implementation is a bit
different because we never had to worry
about tokens before.
And now we're thinking, oh,
maybe in the proxy we can add some
limitations of the cap of a token can
go in there.
But is that fair to say that we're
not talking about something?
Yeah, I don't think the concepts are new,
but I would say that the user behavior
is completely different.
So before you would have to share
sensitive business data would have been an
intentional act to maybe email it to
yourself or something like that.
But today people are obviously using it to
help them be better at their job or
maybe to give insights into something that
helps them produce a report or maybe scan
things quickly for them on their behalf.
So they now are like where you would
have been really that would be more about
sharing the assets externally for
different reasons.
You're now sharing them legitimately to
help yourself be better at your job.
Hence it being called kind of shadow AI.
So those things are a little bit different
because it means you've got to be quite
good at really almost blocking.
That's kind of what you really want to
do.
You want to block any other models outside
of your own approved models so that
everyone is forced to basically go through
your central control plane, i.e.
the Gen AI gateway,
and they can't bypass it and go to
some other model or use their own personal
account or bypass.
And that's interesting.
Yeah.
And the risk here is what, John?
What are we trying to prevent?
Are we saying that, oh, as a company,
we can only use models that are provided
by Claude,
but we don't trust any of the models
that are provided by Grok?
What are we trying to protect here?
Are we trying to protect IP?
Are we trying to keep ourselves safe
online?
Or what is the thing that we're trying
to protect here?
I guess many reasons.
I guess one could be you don't necessarily
have an approval for that model.
It could be that
the sovereignty of the model,
like where it operates in, you know,
is not under the jurisdiction of the EU
or, you know,
under your own legal kind of rules and
regulation,
and therefore people sending sensitive
customer data outside of your jurisdiction
into other countries into the model is
obviously not approved.
It could be that you're installing,
people are installing things
to integrate into third-party tools to
make it easier i.e um i don't know
google drive and sharepoint and you know
so you're connecting up um into say it
could be anything could be like claude
desktop or co-pilot you know and you're
connecting things up third-party systems
that then have access to lots of different
data um and i think the difference between
a human and ai is you know
to do a task,
you'd probably be quite intentional of
where to look.
So you'd be like, okay,
I know this information's stored over
here, or I'd probably quickly navigate.
With AI,
it's probably reading everything to figure
it out.
So to know where to go,
it's had to process every other piece of
data to then figure out the right answer.
And obviously that's very different to a
person,
but it's now acting on behalf of you.
So it's acting as if you're doing it
because it's using your identity.
And obviously that's a lot of risk.
So what you're saying is that if a
person is on their machine and they're
trying to, let's say, look at a reporter,
identify whatever task they're doing the
ai could potentially read whatever's on
their machine they could have sensitive
data on their machine and feed it to
the ai model which is what we don't
want to do is that correct we're trying
to protect the the sensitive information
that you have from reaching the ai model
so perhaps you can use it uh to
train itself and get better is because i'm
trying to get to is that a bad
thing is this about i guess two things
you could you could decide that for
certain operations
you want a much cheaper model.
So that could be one reason.
So you're like, actually,
for this type of day to day stuff,
I don't want to be sending loads of
data to the fable,
most expensive model for these types of
activities.
So yeah, there's that.
And then obviously you don't want to be
necessarily getting a load of random data
and then shoehorning it into a model
because that's just what you've got access
to.
So not just on your device,
it could be
You might be overprivileged.
You might be an admin of your estate.
You might be a drive admin on SharePoint.
The whole thing, yeah.
You've got access to absolutely every
piece of information,
and then you're using AI on your machine.
Technically,
then it is also getting access to
absolutely everything through your own
permission.
All right, cool.
Tell me, John,
how do I get a device that is
secure,
the first of your pillar's device and
endpoint?
What do I need to do there to
get myself safely into this AI land?
uh well i think the first thing to
do is if you are wanting to use
it for your business um the high high
probability is outside just coding um
you're going to want it to have access
to files and information right it's it's
only valuable when it can start to process
things on your behalf so you don't have
to process it all to then give suggestions
or commentary or improvements or new
content but so you then need to really
understand
what is the current data access governance
that's already in place?
Have we shared everything with everyone by
default?
Because you might not even know what is
really shared with you and what you really
have access to because you're not
necessarily going through every single
file on the drive to see,
can I or can't I access this stuff
that I should or shouldn't be able to
access?
So you need to obviously do a bit
of a data access governance process,
produce a report, look,
quite quickly at whether there's over
permissive permissions in there and that
you've got all the right going around.
So that'd be the first thing to do
before you start to roll it out.
And then sort that out quickly and then
look at identity.
Similar thing in your RBAC controls,
your identity and access management.
Is that quite strong and a good posture
there?
What's RBAC control, John?
Can you just please explain what is RBAC
control?
Well, you've heard it here first, guys.
He doesn't know what RBAC is.
Please, John.
I'm a little bit in shock.
What is RBAC, John?
Role-based access control is what it is.
Okay.
Basically,
what access are people allowed to have
access to?
What's the permission set?
But not just that, as in
are you doing short-term access?
Are you making people escalate privilege
when you need to?
That kind of stuff.
But also, have you...
Are you blocking maybe certain GOs?
Would you expect somebody to be logging in
from China?
You know, that kind of stuff as well,
right?
So it's not just the permissions.
Yeah, okay.
Not to pick on China, obviously,
because it's got a...
Rumor is it's got a very cheap model
that's quite competitive nowadays.
And there's Kimi K.T.
that came out, John,
a couple of days ago.
on par with fable according to the tests
and uh i have to confess i did
try it it did work at times and
at times i did get some errors perhaps
everybody was trying it so uh yeah my
machine doesn't block the use of kimi
k-three at the moment john i'm just
letting you know that wow okay uh so
Got a real life security risk on the
podcast.
Is that what we're saying?
Is this a confession?
I'm not saying it's a security risk.
I'm just saying that I tried it, John.
But luckily on my machine,
I don't have any sensitive information.
Apart from some photos and podcasts.
We're very equal opportunistic here,
though.
That's our stance.
So we don't like to get into geopolitics.
We're all about...
open open and transparent geo uh
approaches um so yeah the us whatever all
for we're all for technology right that's
what we are technology yeah awful
technology where we just uh you know
that's what we're doing techno optimists
john that's what we are we try all
technology
But yeah,
so I guess once you've done the
assessments,
once you have fixed your identity,
once you've assessed as well your current
kind of foundations,
where's your maturity,
have you got a good control over maybe
a central VPN that people are routing
towards,
some form of governance over the device
routing,
Can you block people from going to
specific websites?
That type of stuff.
And have you got all the right audit
and logging into like some central kind of
control place that you can do security
reports on and central policies that you
could easily roll out?
That's what we call kind of the
foundation.
So they're the first things that get all
of that in place.
And once that's in place and the devices
and you've ticked all those things off,
then you're kind of safe to be like,
right,
let's start to think about the model and
the gateway that we're going to put in
front of it.
And then who should have access to it?
And are we going to roll it out
team by team?
And are we going to get the right
telemetry there?
Are we going to report on the token
usage?
Have we got good security over it in
the gateway?
Are we going to use Purview?
Have we looked at the sensitivity and then
start to do it that way on a
case by case basis?
And maybe you want kind of approved things
like what are the things in the catalog
that you're allowed to use?
I was mentioning the connectors, right?
What are you allowed third party-wise to
connect into?
Other specific things that we approve,
i.e.
SharePoint.
We'll let you use the MCP for SharePoint.
Maybe we'll let you use GitHub MCP,
et cetera, et cetera.
And then you'd control that rollout so
that you can't just use whatever you want.
were obviously managing it on a
case-by-case basis,
like you would policies and other
exemptions.
You'd safely want to control that.
After that,
You're then into obviously kind of
generalizing it more.
So then it would be looking at it
through the lens of applications.
You want to reuse all of this because
it's universal.
You'd have all the right controls that in
place to then be like, right,
let's get the applications doing a Gen
Tick.
Let's use the same gateway.
Let's use that control plane.
Let's use Purview,
which we're already using.
Let's make sure that we've got all the
reporting on the sensitive data.
And then you'd start to maneuver into more
expansive areas,
which are application-centric things,
reusing all the same governance and
processes that you've already got in
place.
Does that make sense?
It does make sense.
It does make sense.
It does.
And so that's why we're about to stop
your device from using the new China
model.
I believe we're about to roll that out
on the MDM now.
So if you've got anything running,
you might want to quickly get the
information out now before we block it.
So I do need to go back to
a point.
You keep mentioning the use of Purview in
the governance part.
That's just an example of a service in
Microsoft.
Yeah, absolutely.
Maybe can we go a little bit more
into how do you use Purview to make
sure that you've done the right level of
governance?
Can you go a little bit more into
that?
So Purview, just as an example,
offers data lineage protection.
It can keep track of all the
transformation of information and data and
where it's gone through.
It also has these classification concepts.
I think it comes out of the box
with a load of default classification and
rules.
And you can add to those rules yourself,
essentially,
of how can it understand the data or
your data and the sensitivity around it.
Yeah.
And so, yeah,
I think it's based on aspects of what's
it called?
The Apache.
Forgotten the name,
but basically there's an open source
project for data lineage.
I think they've all wrapped that.
I think Amazon and others
Is it Atlas?
Apache Atlas?
Can't remember.
Anyway.
Yeah, that's fine.
So all the same concepts,
all open standards,
nothing specifically bespoke about them.
It's just that they wrap these services
and you can then roll them out and
then have extended it into additional
things, obviously like the DLP stuff,
which is the in-browser extensions that's
then feeding back into Purview.
So they're connecting things into Purview
to then do the governance and control in
that for the data layer.
So to summarize,
what we're saying is in order for you
to roll out AI safely and securely in
your organization, of course,
there's always risks,
but to reduce the risk of rolling out
AI with governance,
you have to do a few things.
Make sure your devices and endpoints are
controlled by the bits that you mentioned,
use MDM Intune, have compliant devices,
then make sure people have the right
access.
you know,
you mentioned RBAC role-based access
control,
ensure that they have the right level of
access,
the right level of information on the
machine,
just so the models don't have way more
information than they're supposed to have,
and then have what we call the AI
gateway, i.e.
the proxy,
in which you can control and have
guardrails and what the model can access
from your machine, perhaps, you know,
and token management and token limits and
routing, you can do that.
And then what we're talking about is
making sure that, you know,
You have the right data governance in
place.
You restrict the content discovery.
You have the encryption in the right
place.
And then the good platform foundations
that already exist.
You have private endpoints.
You're controlling everything correctly.
You have the right keys in place.
and after doing all this you always still
need to make sure that you're monitoring
you're auditing and logging what's
happened because if something happens you
perhaps want to go back and see what
happened and also notify you when
something wrong happens right so have
these six things in place and then we
think about how do we roll it out
which is uh that's what we do is
that correct john is that what we're doing
That's pretty much it.
I mean,
you don't need to I think using a
project to prove it out first as a
bit of a lighthouse thing.
I think it's probably that's how I would
do it first,
because you'd want to validate how
effective and efficient not just the
technical implementation is,
but your own processes around it.
Because if from a process perspective,
You know,
if the team's already saturated with BAU
and you're trying to add more work into
the teams to then be managing,
onboarding different projects into AI and
putting all the content filtering in
place, maybe inside of the gen AI gateway,
you know,
what filters and protections do we need
for this team?
You know,
is it still are the same same filters
still applicable from the lighthouse team
into the next one, et cetera?
You're iterating and trying to understand
from project by project where the risks
are.
So I guess you do need to look
at like,
how is it actually operationally going to
come together?
Who's accountable and responsible for
what?
you know is our device management already
functioning really well and quickly or is
this gonna cause scaling problems you know
into the business when we start to
obviously roll this so you do need to
be thinking operationally as well as
technically on both sides to get it right
and doing a bit of assessment on that
um but yeah from a technical perspective
they're all the things you spot on they're
all the things that you do need to
think about um as well yeah
If I'm a CIO or a CTO, John,
which I'm not, or COO,
or even a CEO, which you are, John.
Yeah.
what is one message that you should give
to them for the safe rollout of ai
because one one thing is yes we have
all these things all the things that you
have to do to to monitor this is
for the usage but also the people who
are implementing these policies you know
like the it department or where it might
be things are moving so quickly new models
are coming out every time everybody's
saying oh i need the claude fable five
right it's just come out i want it
What do you say to them?
How do you first roll out safely?
Secondly, stay on top of it.
So, you know, people who are using this,
they don't stay behind.
But what is the one thing that they
should focus on?
A couple of things.
I know we talked about these six pillars,
but what are the couple of things you
should tell them in this podcast, John?
Uh...
i don't know about a couple of things
i think the main thing is to understand
the objective of it first as a business
you know are you wanting to roll it
out because you've got shadow ai going on
and that feels like a high risk so
it's more of a risk goal how do
we mitigate the current risk or
is it that you're wanting to roll it
out because we're wanting to reduce our
operational overheads currently in our
business or is it the development side is
it speed of coding or is it application
centricity are we trying to roll it out
because we want to get to new markets
or wanted to improve our product features
so
You can't what I wouldn't suggest is
saying all of it, please.
Obviously, I know that,
but it's probably trying to work out as
a priority,
which is the first thing to prove for
AI first,
rather than trying to look at everything
that it can do and then trying to
boil the ocean with everything.
I think then the principles of all these
pillars are contextual then to the goal
and the objective.
How deep you then go in those pillars
is contextual to what the real ambition of
the goal is.
Therefore,
you don't need to necessarily start
getting into all of the depth of each
pillar straight off the bat,
and then it takes a year or whatever
insane amount of time to roll it out
safely across the business.
And no one's getting to see any value
out of it at all.
Basically, you've diminished your value.
So start with something very clear and
concise that frames everything and then
choose that lighthouse customer and then
prove those pillars on a shallow front
first without loads of depth and then
build the depth over time as you then
maybe buy another objective off would be
my advice.
Okay,
so this is excellent advice because if you
try and implement everything in the first
place, it might just take you months.
I think that is what I was trying
to get to, right?
So your advice, John,
to people is pick one use case and
implement for that first rather than
thinking about everything under the sun,
operations, development,
just pick one use case and then implement
it
See how that goes.
Because you have to iterate quick over
this.
I know, John,
we keep joking about how these models are
next token predictor and sometimes they're
not that good at producing the information
that you require.
But at the same time,
if you're not using these models,
you'll be left behind.
Yeah, you will.
Yeah.
But I think because there's so much to
it.
Like we're saying,
I think because it assumes a certain level
of current maturity,
like you were saying at the beginning,
these are not new concepts.
Device management isn't a specific AI
concept that's come off the bat of rolling
AI out.
Data governance isn't a new thing.
Identity and access management isn't a new
thing.
So I think what it is doing, though,
is probably challenging a lot of
businesses on their current maturity
posture.
in those pillars already you know where
are you in relation to this and it's
kind of maybe putting it under the
spotlight a little bit more so on like
actually the risk of this is much higher
um as a thing strategic objective than
maybe some other things that we've had to
do before and therefore we do have to
get these things right but again doing it
right is contextual to
what is the first thing you're starting
with and getting the first thing right,
not necessarily getting all of it right,
I think is the aim.
Otherwise, you'll never get anywhere.
You'll be just sat spinning wheels for
ages trying to get everything perfect.
You will just increase shadow AI,
won't you?
Yeah,
how are you finding the role out of
this?
I know, John,
you've been working with a bunch of
organizations.
What is your approach that you're taking
to your clients?
How are you finding the reception of this
approach?
Are people saying these are the right
levels of controls that we're putting in
place, or is it too much?
Are you asking too much of our
organization to do?
How are you finding it?
So I think everybody seems so far to
be quite...
well versed in understanding what it
means.
I think probably because as in what it
means to
the risk I think is more what I
kind of mean there because everyone's
using it personally and so they've already
kind of they're already sending things hey
here's my I don't know here's my travel
documents for this thing or go read my
email for this thing and I want to
improve like I need to change the flight
to whatever and you know I need to
book this holiday and so that everybody's
sharing quite a lot of themselves right
already so
I think the concept of data sharing is
very well understood already.
So there's no educational aspect there.
I think what I will say is probably
the biggest challenge is the facilitation
on scope.
I think that's probably the value we bring
is really trying to pinch it into
something of like,
how do you prove the first piece of
value of AI rather than
getting hung up maybe on all of the
risk of AI as an entirety all the
time.
So trying to get everybody into the right
mindset of we don't need to worry about
all those things first.
Let's just really try and work out what
is it you're really trying to do because
we want to prove value quickly.
That's always the aim.
Everybody wants that.
um and so let's really focus on that
i think most people probably struggle with
that bit is probably the biggest thing
like where do we begin begin what do
we choose yeah and what's what about you
because you're in customers too and you're
obviously speaking to people all the time
and you know what would you agree with
some of the things i've said do you
think i'm talking nonsense
No, no, John, a hundred percent agree.
I think the issue that I see is,
and the reason why I really like your
idea of just pick one use case and
run with it,
is because
luckily for us open ai and anthropic have
done the marketing for us right because
everybody as you say is using these models
in their own capacity and then they see
some of these colleagues or some of their
friends are making things really quickly
prototyping businesses right websites apps
they're just coming out within a couple of
days things are working and
What people are asking is,
can we have this straight away?
Can we have this technology?
Because a lot of organizations are like,
well,
we're not going to allow you to use
these tools because we're still trying to
figure out how to use it safely,
how to use security, what's allowed,
what's not allowed.
So the employees and their colleagues are
not getting it fast enough.
I think that's number one.
Some organizations are still trying to
figure out how to do this securely.
That's number one.
They're not getting it fast enough.
And number two is the people who are
implementing this.
They're like,
there's a lot of this that we don't
fully understand.
So there's an education on what are the
actual risks?
Sometimes when you have that major threat
matrix that you make,
what are the threats?
And that's why it's important to
understand what are the actual threats?
that you're trying to mitigate against.
And we're seeing it being rolled out.
And I think the biggest issue for the
organizations is making sure that people
are not sharing this sensitive
information.
I think that's the biggest problem that
they're worried about.
Some companies don't really care too much
about, oh, okay,
if you do share my piece of code,
which is already coding in the open.
So, I mean,
if I do use that model to share
my code, I mean,
it's already in open anyway,
so it doesn't make any difference.
but some people are still worried about oh
i've got this proprietary software that if
people are doing software development on
that's going to go to the model
then you know people will get people get
our proprietary information but the model
i'm not really too sure if that's too
much of a problem because you know the
model already has a bunch of this
information already there right uh you
know like creating rocket science is not
something not new but yeah so what we're
saying is people uh in some organizations
really want this and the the organizations
are still trying to figure out well number
one which models to use
and the cost of these models and i
think people are worried also about the
tokens right remember we spoke about a
couple of podcasts ago ceo of uber said
we blew up all the budget for the
whole year in april uh twenty twenty six
for the hood and there's not one single
feature i can tell you that was released
with with ai right so there's uh
still a very new area that people are
trying to get to grips with yes good
you can go on chat gpt and ask
it to generate you images of you doing
one or other thing or you can like
run your own websites which is fine but
like i i still think john um this
what you talk about the six pillars is
needed we're talking about pick one use
case and developers needed so yeah this is
uh this
This is an area that's developing really
quickly.
But the good thing,
as you mentioned earlier on,
is these principles they were discussing.
They're not new.
Some of the implementation is a little bit
different, but they're not new.
Yeah, exactly.
Cool.
Well, that's it, I think,
for this episode.
Well, it felt short,
but it hasn't been as short as I
thought it would have been.
But I guess the next one,
we will probably either choose a topic or
get back to the news.
There's been a load of things in the
news,
which I did really want to have had
to bite my tongue to not bring up.
We kind of did hint at it a
bit with the new model from China and
how cheap it is and the efficiency of
it.
been on a par but for a fraction
of the price I believe as in like
the cost the capex cost that it's taken
I think is something like you know I
can't remember like half or even more
maybe like a third of the price that
they've had to spend to get to the
same place as the US super interesting and
share prices and all these things going on
so we'll probably maybe touch on that
depending on what's happening next week
but yeah
Stay tuned for the next episode.
Cool.
See you later, everyone.
See you.
Creators and Guests
