Seriously - the only attraction for me to do this, is the ability for me to be able to say it in my words, when I want, and how I want. Yes, I will make sure to the best of my ability to follow rules re: public company fiduciaries and dissemination of information. But the idea that someone else crafts your communication and tweets for you - is not better than giving an interview to a publication and worry that the journalist will cherry pick to validate their narrative. Control the narrative and the consequences by doing it yourself.
@nikesharora@HarryStebbings You're one of the few large company CEOs that seems to be writing their own tweets and they are interesting so you should continue
Free wisdom for those of you opining on my last tweet. It's easy to cast individuals away because you disagree with something they did or their opinions. When I turned 40, I turned a corner and decided to appreciate the good in someone for their act, for the moment and for what they did. My friends are my friends and I respect many people for their achievements in various fields, but I wouldn't have them work on stuff In other areas. An absolutist bar on each human is a recipe for failure. I expect things from people, but I don't expect them to be perfect. If their heart is in the right place, and their intent on the matter at hand is well placed, I respect the effort.
The meeting at the WH on SI was an epic moment. The good and the great of AI (SI) showed up from all over, I was just happy to be in the room.
First and foremost I felt that @realDonaldTrump showed us what a true leader is. He was thoughtful and focussed on ensuring that SI was developed at pace and was going to be deployed safely and securely.
He encouraged the room to focus on the positive impacts of technology, demonstrate the true benefits of the technology for each and every one out there.
His message was clear - engage with communities get grassroots support for what is going to be a pivotal moment for America and the world.
He was statesmanlike and clearly focussed on the US winning the SI race.
The focus needs to be how to ensure what is being built is safe and useful. There are enough laws and regulatory frameworks that allow for effective governance we don't need more. What we need is:
1. Accountability by the labs
2. we need SI to have the right APIs available for cybercontrols and third party governance and
3. We need equal focus on diffusion of this technology in a useful and effective manner.
We all walked away with continued and renewed enthusiasm to bring on the SI future.
When you get cyber companies focussing on furthering a technology you have already moved the needle.
Conceptually you can access APIs for control panels in the enterprise use case. The API and MCP is less of an issue - the access, audit, ownership of actions and liability is. In the enterprise use case, one who accesses is responsible.
@nikesharora Couldn't agree more.
@nikesharora do you take the same approach for Palo products? E.g will an "enterprise muse" be able to configure NGFW?
Lol. A string of connected tasks. Like book me a trip and a restaurant for lunch in one task. So you have to interface with two back ends. My point is, we will need an agent exchange, broker, or rules of engagement. Our current app owners will fight for owning the customer and resist agent APIs.
This will be a bigger battle than anyone anticipates. It is only a matter of time before there is an Apple and Google version of Muse and possibly TikTok, in addition to the frontier LLM agents. Maybe a commerce agent from Amazon.
Every app that is a services, marketplace or commerce app will need to existentially decide to open APIs for consumer agents to interact. Smaller players have no choice. Ad revenues are more than transaction fees, either the consumer benefits or distribution aggregators will demand a higher transaction fare.
I know I don't want an agent for each app. I would like my agent to be able to do tasks I require. We can already see consumers getting trained on that behavior by the frontier labs.
Those with network moats - restaurants, groceries, drivers might be able to withstand for a while, over time convenience and end user experience will win and they will have to align. Content moats (protected by copyright) could decide to allow agents or chose to hold on to the consumer interaction. I suspect other than the feeling of a lack of control, it won't change their economics.
Commoditized back ends will need to worry, insurance, tickets, hotels, services - if they don't adapt new players will.
Amazon cuts off Muse.
While I am bullish Meta and Muse, I think many people are overlooking the digital knife fight that’s about to occur
Nobody wants to get commoditized or layered here. Let the games begin
I think this is exactly where alignment gets difficult. It’s not just about preventing the model from jumping guardrails. It’s about setting the right constraints so it consistently chooses to operate within them.
But then comes the harder question: whose rules?
Easy examples create false confidence because most of us agree on the answer. The real alignment problem lives in edge cases where values conflict, context matters, and reasonable people disagree.
That’s where I think alignment stops being purely a model problem and starts becoming a governance problem.
Alignment is less about jumping guardrails and setting the right constraints. It's about making sure the model wants to play by rules. The question becomes "whose rules". Think of edge cases. Your example is easy, we can all suggest the right answer here.
Great post Nikesh! I'd push on your point 5.
An enterprise shouldn’t have to wait for agreement on whose values a model should align to before deciding what an agent is allowed to do.
Take a coding agent for example: permission to investigate a production issue shouldn’t automatically mean permission to change access controls or delete data. Those boundaries need to be enforced outside the model, even when it gives a convincing explanation for crossing them. That doesn’t solve alignment, but it gives enterprises a concrete way to limit the consequences of mistakes as capabilities improve.
I’d also be careful about discouraging labs from sharing failures. We need that visibility. What I’d ask is that every disclosure include what failed, what changed, and how they tested the fix. It just can't be an RSI blackbox.
@nikesharora point 3 says a few leaders self-pacing is illusory because one defector restarts the race, but the fix you land on is also solve it with a few players and demonstrate leadership so others follow. what makes small-group coordination hold for alignment if it cannot hold for pacing?
Sequel to AI Pacing
I have now spent more time talking to people who run AI labs, Open Source projects and those in government and infrastructure.
I am beginning to feel the NINJA move could backfire.
I understand the pressure to come out and share where AI is "unmanageable ", and constantly share examples where it runs rogue. This fits in the category of "self-reporting" and an attempt to limit liability. Even the bleeding edge research examples are being cast in a negative light.
Here are the consequences of the NINJA move.
1. They have successfully encouraged every law maker around the world to have an opinion, and in cases a poorly un-informed one.
2. By proposing pacing - they have introduced uncertainty in the AI infrastructure trade, because we really don't know when "un-pacing" will begin or what those conditions will be.
3. The notion that a few leaders can collaborate and self pace is illusory, it takes one breaking ranks to start the race again, it could be a player in a different country or open source or an AI Lab itself.
4. There will be a regulatory body created as a consequence of this and it will be impossible to balance every stakeholder in this process.
5. No remedies, tools, solutions are being proposed other than "compute spent on safety", there is no mention of security (which will hamper adoption)
The recommendation is to fix alignment - Alignment is a hard problem - to fix alignment one shouldn't have trained models with "negative behavior". Alignment is a combination of moral standards, right and wrong and guardrails. Whose sensibilities will we align to? Alignment edge cases are hard. I look forward to learning more on this.
Guardrailing attempts post training have not shown precision. Distillation makes it worse, so AI will continue down it's path of getting smarter, while we will be chasing it to ensure alignment and building guardrails.
The AI labs have gone from being research projects to wanting to be the largest businesses in the world if they want to continue their progress. Transition from research winners to improving the lot of humanity and partnering with enterprises. Act like the largest companies in the world:
- Demonstrate the positive impacts of AI and how all of us benefit.
- Show enterprises how you can collaborate to solve real world problems and progress innovation safely and securely. Post an example every day how you helped.
- Solve the problem with a few players and demonstrate leadership so others can follow.
It's time to rebuild the brand of AI - any marketing expert will tell you, this Ninja move has done more to harm the brand of AI and will take a while to rebuild. #letsbepositive in our actions and our narrative.
Congrats team. @matanSF one of the more relentless founders. If there will be half a trillion of coding ARR out there in the next few years, there's room for many players. Execution, speed and scale matter.
We have raised $200M at a $5B valuation to scale self-improving software development in the enterprise.
@FactoryAI has grown to serve hundreds of thousands of developers at companies including RBC, Adobe, Nvidia, T-Mobile, and Palo Alto Networks.
We will use this capital to accelerate our investments in research, product, and global go-to-market.
THE PACING IS A NINJA MOVE - But be careful what you campaign for.
In any competitive sport, I have seldom found people exercise restraint - they usually have a capture the flag mentality. Don't I want to be the best? The first? The only? - this is how we have been programmed. In the AI race, winning is existential. All AI labs have to race to generate revenue to be able to sustain the enormous amount of committed capital to "not be left behind" in the infrastructure build. There isn't enough room for many. So the desire to slow down is puzzling, but perhaps if the whole system slows down, the rules of winning can be the same for all.
Do we have a problem that AI could be a killer?
Model capability is a tale of two cities, at one end the models are showing their prowess in tasks like cyber or math as seen recently, so there is likely a probability that the models get extremely powerful and could precipitate a world event. At the same time, in many domains the lack of training data makes the models woefully inadequate. Even in areas like cyber - the LLMs aren't great at the edge cases and generally not economical for the defender case, but great for the attackers. Funnily - in all their "concern" it is still an uphill battle to get them to expose APIs for third party security companies like ours, for us to build robust security for AI adoption. It's slow progress.
So why do this?
I do believe deep down this is a commercial strategy. A ninja strategy. The liability associated with a model gone rogue has the potential of wiping out the economic opportunity of any frontier company. How do you best show the duty of care? You show that you care. How do you make sure you don't lose out to your competitors? You get them to do the same! If that becomes the industry standard for duty of care, you have a collective first line of defense. Who do you get to govern this? "Yourself" - that is what I think will become the achilles heel.
The risk? Open source! China! Countries other than the US! So you ask for a global agreement, because you don't want to be sued in other markets who might even be more punitive. But that was an afterthought - that afterthought will cost.
Thks pacing campaign rhetoric has become the talk of the town and it might work. Everyone has jumped into the debate. Both sides of the house, nation states. CEOs (present company included). It's more fun discussing the evil of AI than basics of economic affordability or international trade.
The result: We might end up with AI safety boards, regulation in micro jurisdictiona and a fragmented fabric of laws around the world which would make compliance and liability a challenge. Perhaps the intended consequence of pacing would have an unintended consequence of a labyrinth of regulation. Regulation destined to cause a slowdown.
Who wins? Simplicity. Open source? Open source is already on its way to gaining more adoption, this could drive it further, faster, each iteration of open source gets closer to frontier LLMs - making it viable to deploy them for more and more use cases.
In the end, how will the evaluators know as AI gets smarter, that AI hasn't figured their role out and outsmarts them at their task! That will be the next frontier :)
Lolol - proofpoint is your proof point :). Irony and humor.
Since you called me out - On a serious note - we can all use AI to make our product a hybrid solution of AI and edge cases by machine learning. As I said we all will use different horses for different courses - SLMs for single task problems, reasoning models for detection and remediation and in some cases we will use frontier intelligence for reasoning to incorporate the human element at the customer end, sure an inference toll that will need to be passed through to the customer since the customer is getting better speed and lower resources needed to resolve the problem.
To deliver real time cyber solutions and harness the true power of AI - the customers will need to integrate their fragmented vendor landscape to a more integrated platform, that consolidation will be more impactful than the "inference toll passthrough" - the margins stays in California/Austin :). I think we all have to accept that AI spend is replacing human effort - creating speed, efficiency and efficacy.
Nobody wants to hear the bear case on the two best-run companies in security, so here it is anyway.
When GPT-6 Astra launched this month, OpenAI had an outside evaluator run it through FrontierCyber, a benchmark of real offensive security challenges. Astra solved 86 of 226. The model one generation earlier solved 34. That is a 2.5x capability jump in a single step, and neither model has touched the Elite tier yet. The curve is doing the opposite of slowing down.
Now look at who is shipping. OpenAI has a cyber platform called Daybreak. Anthropic has one called Mythos. OpenAI is running a program to put frontier cyber models in trusted hands. And Proofpoint, an incumbent security vendor, integrated OpenAI's cyber models into its own security operations this month. Read that again. The incumbent is now paying the lab for the intelligence layer it used to own.
That is the margin story. Security vendors sell detection content and the workflow around it at software gross margins. When the detection intelligence lives inside a frontier model, the vendor turns into a distribution channel with an inference toll attached. The scarce asset commoditizes, the toll flows to the labs, and seat counts follow SOC headcount, which is the first thing the agents eat.
The consensus answer is that AI is a tailwind for security spending. Nikesh Arora said exactly that two weeks ago, and he is probably right about the spending. What the spending does not tell you is where the margin lands. Right now $CRWD trades at 38 times trailing sales and 147 times forward earnings, and $PANW trades at 27 times sales. Call it $480 billion of market cap assuming the margin lands in Santa Clara and Austin. The capability curve says it lands in San Francisco.
Watch how that reprices when the labs finish shipping the one layer of the security budget that made the margins.
Security and IP implications of AI
The case for rapid AI deployment -
I think we can all conclude the following from the last few months of developments - 1. Not using AI could and will become an existential issue for both individual users and enterprises. 2, Enterprise adoption will be cautious while individual users are definitely going to race ahead, try different use cases, build agents, push the models to their limits (although it seems harder to do, unless you live in an AI Lab) 3. Employees and developers will take matters in their own hands since they will find their cautious enterprises aren't moving fast enough. 4. Agents are showing their prowess, uncontrolled, unrestrained agents with a "capture the flag mentality" are showing us the edge cases which demonstrate the negative outcome possiblities of these scenarios. 5. It is impossible to plan for the next 6 months since we can't fathom where technology will evolve to. These activities will cause adoption sans security..... AI has deep implications on security in the future.
In this environment security companies need to live on the bleeding edge, anticipating scenarios, building framework solutions so we have a shot at securing future outcomes. Which we all are.
Some useful pointers to people planning their AI implementation:
1. Secure what you plan to use, try not to secure the future - no products for security can be created unless we see the future unfold. The future is moving fast, so are we.
2. Most of the coding usage is unsecured. Make sure your coding is secure. Most enterprise AI apps do not offer a secure instance (this is your IP living in their instance)! SECURE your codex, cursor, Claude code Harvey, glean, legora instances now!
3. Do not try and build your own - I have already experienced enterprise customers building gateways and tools for agents - security companies have thousands of specialists working on this, leverage them, Focus on AI adoption instead. Partner to secure.
4. Securing agents is a complex problem - securing the agentic lifecycle - real time inspection and kill switches are key. Don't fall in the discovery and posture trap (Visibility - process understanding - intent interpretation - ability to stop inline are key tenets to the agentic lifecycle - not identity, posture and inventory - those are mere building blocks)
5. Only use enterprise protected models, single tenant, firewalled, inspected implementations - this is your IP you are playing with - LLMs have shown they will cross boundaries to capture the flag - you think your IP is safe? Once you train an unprotected model with your IP - you can't reverse the trade.
6. Perhaps the most important one - do not use a security tool built by the same person who is selling you the AI implementation, historically IT vendors are different from security vendors. You need an enterprise solution for security and it must work on your diverse infrastructure. Use a pure play security partner.
Happy building with AI.