So, Patrick, nice to see you. You're a very shy person. You don't appear on too many panels. This is only the second one I've done with you today. Just staying in the room, right? Yeah.
So, we had, just before we started, we actually, with the panel, that was the one with Patrick earlier, was all about deepfakes and trying to understand how to stop them. And I just ended up being scared because, and I'm glad that I'm actually approaching sort of retirement age because I don't want to live in this world where we're trying to figure it out.
So, anyway, if you could just zip through these slides quickly and I'll tell you which one is the one that we want. Keep going. It's near the end.
Ah, yeah, that one. No, the one just before this. Okay.
So, I thought what Martin put here is a pretty good summary of where we are, particularly in the illustration. I mean, again, we were talking about this earlier. We are entering a world of basically AI chaos and particularly when AI agents are creating other AI agents and they're talking to other AI agents and so on and so on.
So, Martin, this is your slide. Maybe you could give us some hope that we'll somehow control this. Yeah.
So, glad to receive a question. I was just starting to wonder, do you do a presentation or do we do a panel?
But, anyway, I tried to tell a positive story when I did the presentation. So, I am very confident that we will be able to get a grip on that. It will take us a bit of time. Something will go wrong in between, as always, because I think we are extremely good in IT to constantly do security, privacy, governance, everything like that as an afterthought.
So, there's something popping up, then things go rogue, then we start addressing them, and then we get down to a decent level where we say, okay, we can live with that amount of chaos. And I think the same will happen here. It will take us a bit.
But, on the other hand, I think also we have areas where AI will help us in getting a grip on that. So, this is the positive side of it.
So, I had some conversations about deepfake, and I'm still a believer that AI is more helpful in defending against deepfake than in creating deepfake. Because, usually, in security, we say, hey, we, as the defenders, need to defend against every attack, while the attacker only needs one working attack vector. But deepfake is a bit the opposite. We just need to spot minor things to raise the risk level. And I even saw one vendor, I forgot which one, that has a product where then when you're in a Zoom or Teams, a risk alert appears. And then you're totally alerted.
And this is relatively simple to do by looking at many of these factors, but creating the perfect deepfake is much more difficult. So, I think AI can also help us.
And so, overall, I'm positive. But, yes, we need to work hard on that as an entire industry. Okay. You can fight amongst yourselves now, Yves. Yeah. I would love to jump in with a quick thought. I think you're right about deepfakes. There's almost a little bit of an over-rotation, just a little bit, on deepfakes. They're essentially improving spear phishing, specifically. And that means that, yes, you can scale and automate spear phishing, but the nature of spear phishing is to be targeted. And that means that there's a kind of certain limitation to its scale.
The worst implication of it is societal and the lack of trust of anything over an unauthenticated channel, basically. And I think that those are things that we know how to battle. And what I'm observing among, I'm going to call them the normies, people who aren't, like, super technical and hang out at EIC conferences and things.
But, like, I'm noticing that the same way that people have learned what MFA is out there, families are battling deepfake risk by setting challenge questions with their kids. And I think that awareness has happened a lot faster than it has for other kinds of technical things that we've imposed, because it's a real threat, but it can be battled. And that gives me a little hope for what it's worth, Paul. Before letting the others talk, just one thing. I think also the thing which came to my mind, we had this 25 million transaction after a video session.
And I wonder, you know, why don't we just integrate business anomalies and signals about that with IT anomalies and signals? So if there's a video conference and there's a suspicious transaction with people in that video conference right after, hey, why don't we just combine signals of that? We could be so much better if we do just a few things better in IT and governance. I agree. And I think in the U.S. it's kind of headed in the wrong direction. They started to notify that content was fake and have some type of controls.
But, you know, now they're all bowing down to the administration and they're all rolling that back. So it's kind of – I think you have a lot of people who just – now they don't believe anything. There's a loss of faith that anything is verifiably true. It's kind of just, you know, true news, true media. Now it's just there's no true source. It's just whatever you want to believe and nobody's really telling the truth. That's sad. That's sad.
Yeah, I mean that's something else. But let's stick to this more optimistic future rather than the sort of morality of the world at the moment.
Sanjay, you want to come in? I think I agree with the observations that are being made here. Just like with any other technology that comes in, there's always a group of people who will be very enthusiastic. Typically the technologists and everybody else. And the business is focused on if there is a way to make money, they'll forget about everything else. And then the naysayers who are just not open to new things per se, you know, they just have these barriers, they'll come up with their own checklist of does it do the eight things. And if it doesn't do the eight things, we can't adapt.
But look at some of the things that are happening, right? Driverless cars, 10, 15 years, somebody said, you know, I think you're stupid to even think about it. And it took a long time for something like Waymo to actually show something. And it's there, it's operational. You go to San Francisco, it's operational.
Yes, it had its own challenges and all that. But I think the evolution is going to happen.
You know, there'll be problems here and there. But I look at the medical industry, for example, you know, you go take your blood report and all that. The doctor has to go to six pages and then something strikes, you say, he'll do this. Is that the best outcome of six pages of report? I don't think so. Why don't I get a three sentence summary saying, A, this, B, this, this is what you need to do. You're just relying on a human.
I mean, granted, you know, we think that docs are, you know, superhuman and all. They're not. They're like you and I. And if I can get a representation of that that says exactly what it is, much easier for me to get the best outcome. And actually, they did a study where AI would look at the mammograms and they compared the results of AI versus the doctor versus the doctor using AI. And AI without the doctor involved gave the best score.
Yeah, I think, you know, sometimes you even can. Well, that's the health service sorted out. I once had an opportunity to watch how this works.
Really, it was the big screen, seeing what a doctor sees and how the AI pops up in certain places. This is really super interesting. I don't want to go into details where this was. But anyway, I think there's one thing, I think, Sanjay, which I believe is important. And so it goes back to Patrick. At the end of the day, we will not stop innovation. And also regulation, over-regulation will not stop innovation. So at the end of the day, we are the ones who need to figure out how to have the security, the safety, the governance applied to it.
So we shouldn't say, okay, we just wait for the regulation. We need to deliver the right technology to make this work, to have the safety, security, et cetera, around AI. Because innovation will happen. We will not stop it with regulations or anything else. This is a good reminder, a good place for a reminder that, you know, security compliance isn't security. And privacy compliance isn't privacy. And AI governance compliance is not going to be AI governance. So it's up to us. We've got to do it right. And I think we're all figuring out the mechanisms now. The technology is changing rapidly.
You know, monocontext protocol where everything is popping to where it's easier to use. But that's moving a lot faster, like you said, than the security. So cybersecurity is, you know, what we – is the overriding goal of everything that we talk about. But I think it came up earlier in one of the sessions that we've had about the case of the fake employee who managed to get recruited to, I think, six different American organizations using DeepFake. And he's actually worked for the Korean Secret Service.
Now, that is actually getting right to the core of what you were just talking about, a new kind of spear phishing. That is going to be hard to mitigate against. I think someone DeepFaked and got $25 million out of a Korean company. They pretended they were the CFO or someone.
Yeah, it was kind of a Zoom call with 11 different people. And they went and, you know, simulated 10 of them and fooled the guy into approving a transaction.
Yeah, but again, it's about having enough signals. Yeah, so I think that's the point. When we onboard someone as an employee, we need to have sufficient signals, sufficient background. Like Jonathan said, what are the pictures before and after, for instance? So is there a legacy we really can see? In that case, with this employment, there can't be a really comprehensive legacy probably. It's very hard to fake it. There's a very simple tool, for instance, to look for a legacy of people, which is LinkedIn.
Because if you claim to be in the business for decades and your LinkedIn profile goes back six months, something might be wrong. There's simpler mitigations as well. So there was that, you know, the example that went around the world, the $25 million. But there was another example where the good guys won, the Ferrari executive, who was contacted by somebody who appeared to be his colleague. And he just caught wind of something odd and did dynamic knowledge-based authentication is what we would call it. And he said, hey, what was that book you recommended to me last week? Disconnect.
So that guy won. So it's possible to do if you have that healthy suspicion, which we've needed all along before Gen AI.
Difficult, though, when it's someone actively wanting to be recruited because you know nothing about them. Isn't that the case with this Korean guy? True. If it's synthetic. The entire recruitment process. That's definitely tougher.
Yeah, but again, everyone of us has left some traces in the Internet. And they are relatively simple to fake for a short period. Very difficult to fake when you go back. So once you start going to webarchive.org and look what was in there.
So, you know, going further back, then these things become more challenging. Because AI can handle that huge amount of data we can't handle as humans. I'm looking at Jonathan as I say, oh, no. What if archive.org gets compromised? It probably is. Okay. Any questions in the audience at this point that you'd like to fire at the panel? No. Okay.
Well, let's carry on. I would say one aspect, which is, you know, there's the exciting stuff like the deepfakes. But I think it's the whole nonhuman identity scenario.
I mean, it's going to be proliferation of nonhuman identities, short-lived. And it's a special type of nonhuman identity because most of the time nonhuman identities are pretty simple from a security model. They have an identity and they get permissions. And they're acting as an app or a service. This is a completely different story because you have a nonhuman identity, an agent that's acting on behalf of lots of different users and needs a subset of their permissions in order to perform its actions.
So, you know, it's a lot more complicated relationship than just a traditional nonhuman identity. That's a really good point that they're functioning like multi-user apps. Yes. And then have to have the permissions of the person using them, which I think we have a slight mental model of pre-agent.
But, yeah, that's a great point. Yeah, I think that was some of the questions I had in my presentation were exactly about that. So how do we, for instance, also then ensure that the learning part is some things the model may learn and use for others. And some things it probably better not learn as a behavior for others. And so I think that is really something there's a lot of things we need to solve. But as I said, I'm very positive on that. I'm confident we will do.
Also, when I look at it as an analyst, I think every week I see at least one or two new companies emerging from stealth back with incredible amounts of venture capital for AI security, AI safety, AI governance, etc. So there's a ton of money flowing into this market, which says, okay, we have a huge challenge here. But on the other hand, there's a huge potential for business. So I think we will handle it. We'll take a while.
Sanjay, you want to come in? Yeah, I think the direction it will go is, you know, the efficiency is obviously going to be, you know, sky high with all those, you know, non-human pieces doing all the work that humans do. At the same time, I think in terms of security, if you think about a bit of hardening for some of these executions, right, if you box the execution, the worry or concern about security can be brought down quite a bit, right? And I think that hardening, you know, there are organizations which are building operating systems specifically for agents.
And they are actually looking at, you know, it's almost like a VM for, you know, agent execution. Today, you know, there is no such thing.
You know, you build your own execution model and you're running it. If you actually box it, you know, think of it like an agent appliance or, you know, this OS, you know, equivalent thereof. I think some of the, you know, concern or people's worry, I think, will come down drastically through that, you know, execution model. And I think it will, if it's a step in the right direction. There's a whole cybersecurity aspect of it, but then there's Eve's topic, consent and authorization, fine-grained authorization. What can it do for how long and did the user consent?
Do you have track of the consent? Do they re-consent?
You know, I've been working on a persona-driven model of identity which kind of adds a new artifact that might be a good security control. And recently, it's been discovered that, well, AIs have hidden objectives. And it almost looks, you know, they're acting as, you know, your confidant in one situation. And later on, they act as your, you know, fitness coach. But they have these sort of hidden personas that they take on. And it might not be a bad model to surface for exactly this kind of, you know, virtual agent that you're talking about.
You know, development is happening quickly, so maybe that will be the direction things go. Okay, great. We're almost out of time.
Martin, it looks like you're itching to have the final word. No, no, no, no, not really.
Well, you're itching. Maybe you're uncomfortable. I don't know.
Yeah, there's no pillow on the chairs, you know. Agent working. Some other agent working.
Yeah, but I think one of the things that I think may fit to that is I believe that we will see way more specialized AIs. Let's call it broadly AIs than the general purpose ones that are really focused on being really good in a specific problem. That probably is more likely, which, by the way, might be also good for the power consumption part of it. We see that. And if you have one agent and you give it all the tools, it's going to do very poorly. It's better to have a multi-agent system where one agent has the tools to talk to JIRA and its system prompt knows all about JIRA.
Otherwise, you have one. It's like one human being that tries to figure out how to do everything in the world. It's just less effective. So you have multi-agent systems, definitely. In real life, I learned having multiple experts and then combining answers and picking out the best might be a good approach. So why not for AI? Fantastic.
OK, Sanjay, you can have the last word. The vendor gets the last word. So I think it's a mind shift that needs to happen. People shouldn't treat AI as automation. The moment you think you're really not leveraging what this is all about, it's actually reducing the work that you intend to do based on reasoning. The reasoning is an important step of this agentification. And it's not just blind execution of six things that you need to do in a day or in a process. So as long as that shift happens, it's not automation.
You're just not taking a human who is probably doing eight things he or she is doing. But you really wonder, if I did the first and second, maybe the third and fourth need not be done. Only a true agent will help you with that process.
OK, right. Thanks, Sanjay. And thanks all our panel. Excellent. I'm sorry we haven't got more time. But I think we all need some coffee or a drink.
Actually, there's keynotes now, I believe. Am I right?
Thanks, Paul. Thank you. Thank you. Thank you. Thank you.