Security In The AI Age
Reid Hoffman
0:00 Read, it is a delight to be back here with you again.
0:03 Thanks for being on.
0:05 We are once again going to be talking about AI and specifically about chips.
0:09 So, according to Reuters,
0:11 data shows that Chinese firms now control about 40% of their domestic
0:14 AI chip market and that's up from roughly 35% just a year ago.
0:19 So, not huge changes,
0:21 um but Nvidia's share has fallen to the mid-50s and analysts
0:25 are expecting for Chinese homegrown chip production to keep increasing.
0:31 Obviously, US export controls have
0:33 accelerated Chinese push for self-sufficiency.
0:36 Companies like Huawei, Alibaba, Baidu,
0:38 they're building their own chips and creating entire AI ecosystems around them.
0:43 And Chinese firms are already optimizing
0:44 models to run efficiently on domestic hardware,
0:48 even if their raw performance sometimes still lags,
0:51 um by several years at the very cutting edge.
0:54 And so, when people are thinking about AI hardware chips,
0:59 how should they be thinking about this?
1:00 Is this just a supply chain issue or is
1:03 this more about this is the foundational layer of geopolitical power?
1:07 Like, how important are chips right now?
1:10 Well, the short answer is chips are very important,
1:12 although not, you know, like decisive to the end.
1:16 People have this tendency to be extremist.
1:18 Either chips don't matter at all because, in fact,
1:20 you know, China is going to do its own,
1:23 you know, kind of chips or chips matter everything, nothing else matters.
1:27 And as all of these important things,
1:30 it is a very important factor, but not the only factor that matters.
1:34 And uh there's a lot of reasons why the leading chips,
1:38 which are, you know, currently Nvidia as the key leading chip,
1:43 really matters is because it's compute density,
1:46 it's because it's a question of as you
1:49 get to larger and larger and less effective ecosystems,
1:53 less efficient like chip ecosystems in terms of how it operates,
1:58 you get more probabilistic failure in the system,
2:01 you get longer time horizons in terms of training,
2:05 you might even have certain capabilities that are a lot less.
2:10 And that's why the leading chips do in fact
2:12 matter and that's the reason why, for example,
2:14 all of the US players who are leading
2:18 this do have at minimum intense training clusters with Nvidia.
2:26 And so, that really matters.
2:28 Now, there's a set of things that then come after come after this though,
2:32 which is, for example, um China has had some leading innovations
2:38 in efficiency of compute and part of, you know,
2:41 we are learning from that within the Silicon Valley ecosystem.
2:44 It's one of the reasons why,
2:45 you know, the Chinese government has, generally speaking,
2:49 started imposing certain kinds of checks
2:52 and controls cuz they don't want to have,
2:54 you know, kind of uh Chinese leading edge IP leaking to the west.
3:00 And so, you know, you've got some challenges there.
3:03 You've also got, you know, kind of the questions around like,
3:07 you know, how do open source models work?
3:09 You've got the questions around distillation.
3:11 Um you know, as far as we can tell with Kwan,
3:13 Kimi, and other leading Chinese models,
3:16 there's actually a lot of distillation that happens from OpenAI,
3:23 Anthropic, Gemini, Copilot, etc.
3:26 in terms of these.
3:27 So, you've got that, you know, kind of playing out as well.
3:30 So, the short answer is chips matter.
3:36 The short answer is the TSMC-generated chips, which include Nvidia,
3:41 include TPUs, include, you know, other leading edge chips,
3:47 you know, really does matter,
3:49 but it's only one major factor around a set in how AI future plays out.
3:56 Now, the geopolitics of it are we are, you know,
4:02 beginning to move from the talk of AI and compute
4:07 fabrics being geopolitical power to the reality of it.
4:12 Like, it's this year, next year,
4:15 where that will begin to show some really substantive questions,
4:20 whether it's anything from, you know, obviously,
4:24 we saw this kind of dust-up around, you know, the the Pentagon and what is
4:30 the compute matter there with Anthropic and others,
4:33 but also, like, what does this mean
4:34 for industry adoption and what's actually happening?
4:37 Because as you see the coding revolution kick off,
4:41 the enterprise and work transformation will be in in various,
4:48 what we call in the industry, jagged edge,
4:50 will be also picking up speed this year.
4:53 Now, I don't think you're going to see layoffs this year because of it.
4:57 I think you'll see people claiming layoffs because of it,
5:01 but I think what we've already seen
5:02 in software engineering is much more Jevons paradox,
5:05 which is as these tools have gotten efficient,
5:08 it just increases demand and pace for what there is for software engineering.
5:14 Absolutely.
5:15 And so, going back to a little more of the geopolitics,
5:17 does this as sort of China and the US become these poles,
5:22 are are people going to have to take sides?
5:23 Like, as we go, is Europe,
5:25 are companies throughout Europe, throughout South America, throughout Asia,
5:28 are they going to have to decide where
5:29 they're getting their chips and does that lead
5:31 to sort of more fractured society as opposed
5:34 to closer collaboration cuz they're going to have to choose?
5:36 I don't think you're necessarily going to have to choose.
5:40 Um I think one of the things when it gets to the rest of the world,
5:43 um the fact that they can, you know,
5:45 bid them against each other is good and I think this is part of the reason why,
5:49 you know, a kind of a, you know,
5:51 international trade policy of tariffs and threats and retaliation is
5:56 terrible because that will then offset some natural advantages we had,
6:00 which is a higher trust than the Chinese ecosystem relative to, you know,
6:05 the kind of the US setting the global platform, the US being the, you know,
6:09 having the companies who are the providers of these things.
6:12 And I think that the, you know, last year of alienating, you know,
6:16 kind of friends and partners and allies as a general strategy, whether it's,
6:21 you know, tariff threats or tariff actualities, threats on Greenland, you know,
6:27 um you know, speeches to say, you know, uh piss off, you know, etc.
6:33 All of which will mean that this that we move
6:37 much more rapidly to a bipolar or multipolar provider of these.
6:44 And I think that that's going to be true for chips,
6:48 true for data center architecture, and true for software.
6:52 All of which we would want to be as close to a US technological ecosystem as we
6:59 can for the economic prosperity of the US
7:03 and for the economic prosperity of US companies.
7:07 It feels like someone needs to send the White House a copy of How
7:10 to Win Friends and Influence People
7:12 and maybe they can take some hard-won lessons.
7:15 Um all right.
7:16 if they read.
7:17 Yeah, exactly.
7:18 Well, yeah, yeah, yeah, we're we're starting slow.
7:21 Yes.
7:21 [laughter] All right.
7:22 So, moving from geopolitics to actually another
7:25 concern that people talk about with AI, which is cybersecurity.
7:28 And so, anyone who's been reading the news or at least
7:32 my Twitter feed was full of full of hot takes about
7:35 what's happening in cybersecurity recently because we've seen a wave of breaches
7:39 and leaks and this is some big names in the space.
7:42 So, we saw that Mercor got hacked
7:45 and the attackers claimed they stole 4 terabytes of data.
7:49 Um they said the breach was tied to the compromise of Light LLM,
7:53 which was an open-source tool in the AI stack,
7:56 meaning the company was hit through a supply chain
7:58 attack rather than a direct hack on its own perimeter.
8:01 At the same time, we also saw recently that Anthropic accidentally leaked more
8:06 than 500,000 lines of Claude code source code through a bad NPM release.
8:12 And so, they were exposing internal implementation details, unreleased features.
8:18 A lot of people are talking about what does
8:19 being sort of secure mean in this new world.
8:22 So, how should founders and operators right
8:25 now be thinking about security in a world
8:28 where it seems the attack vectors are endless and we always talk about,
8:32 yes, AI helps secure against cybersecurity,
8:35 but it also is increasing the ability to have these attacks.
8:39 So, I think this is just the beginning.
8:42 Um and I think that part of the question is is, you know,
8:46 it it's almost there's a couple reasons why cybersecurity
8:49 opens up much more intensely in the age of AI.
8:52 Um One simple one is, now that things are moving so much faster,
8:57 that there isn't as much time for like
9:01 the previous kind of iterations about how one did security.
9:04 So, the fact that there is all these tools that are
9:07 being deployed in production and everything else where you're like, well,
9:10 actually, in fact, the security like intensity of of kind of like,
9:16 you know, red teaming, multiple attacks, etc., etc., hasn't happened yet.
9:20 So, I think there's just the speed.
9:22 Second thing is, obviously, on a set of AI things,
9:26 including, you know, how one deploys LLMs,
9:29 even if one is deploying open-source models
9:32 of LLMs in one's own production environment,
9:35 is that these LLMs are inherently insecure because
9:39 they're probabilistic systems that we don't understand that well.
9:43 And so, even though we do a whole bunch of alignment training, you know,
9:47 part of what happens with even the frontier models, which do an intensive amount
9:52 of alignment training through their chat interfaces,
9:54 is we you get them doing odd things, which can include, of course,
10:00 cyber attacks or other kinds of things as ways of doing that.
10:03 And so, the there's there's actually, in fact,
10:06 some new surfaces in the software stack
10:09 platform that are unclear how you secure them.
10:14 And this is, of course, within the standard of cybersecurity,
10:17 which is inherently never fully secure.
10:20 I mean, the way that they that they that you
10:22 that you make a fully secure system is you air gap it.
10:26 Right?
10:26 Which is you disconnect it from the network.
10:28 And, you know, that's that there's very limited
10:30 set of systems where what you can do that.
10:32 And so, so all of this opens up
10:35 an intensely new intense kind of new waves of insecurity.
10:42 And given speed and iteration,
10:45 new increase like like even though you said, "Okay, well,
10:48 we secured that last thing." Whoop,
10:49 here's a set of new things that have changed and are now insecure.
10:53 Which, of course, means we're going to have
10:54 to evolve how we play the cybersecurity game.
10:57 Like, you know, is there going to be agents
11:00 and tools that are specifically not only on the, you know,
11:03 the pure code hacking form, but on fishing.
11:06 You know, cuz AI-generated tools are the some of the best fishing amplifiers.
11:09 Well, what about fishing defense?
11:12 And how does that play out?
11:13 And so, there's going to be a whole stack of like new
11:17 approaches to security and new needs for defense that haven't uh existed yet.
11:24 Now, venture businesses are very happy because, you know,
11:26 at Greylock and other places that that are kind of like
11:30 the the the cutting edge of enterprise software, um you know,
11:35 like, you know, Palo Alto Networks and a whole stack of other things,
11:39 Greylock was at the beginning of, and there's
11:41 a couple other venture firms that are equally enterprise.
11:45 You know, cybersecurity tends to be an evergreen
11:47 category with new companies being started every couple years.
11:51 Uh that's really important,
11:52 and obviously that's one of the things that, you know,
11:54 Sheinbaum and the other folks at Greylock are really focused on.
11:57 And on the other side, how would you think about it as a consumer?
12:00 So, I feel like every week you're getting an email that's like,
12:03 "Oh, your, you know, data was breached,
12:06 and there was a leak, and your passwords,
12:07 etc." And then at the same time, you know, we're heading up to April 15th,
12:11 you see a million vibe-coded apps telling you to here's how
12:14 you can do your tax returns with this new vibe-coded app,
12:17 and you know, you don't necessarily want to put your W-2
12:20 into some vibe-coded app that hasn't sort of looked at the security side.
12:24 How do you think that'll either affect consumer behavior,
12:27 or if you were a consumer, what would you do?
12:28 Would you, you know, sort of trust these new things that were coming along?
12:32 Well, so fundamentally, consumers are not terrifically informed in these areas.
12:37 It's like, for example, it's one of the reasons why generally speaking,
12:40 if you were in a mall and you you have a have a Ferrari sitting in the mall,
12:46 and you say, "Here is a five-page fill out of all of your personal form,
12:50 like your children's names, you know,
12:53 every single place that you've lived in your last, you know,
12:56 in your whole life, and all the rest." And you go, "Okay,
12:58 I'll fill it all out cuz I want the chance to win the car." And you're like,
13:00 "What are they doing with all of this data?" Because the way that cuz it's
13:04 an economic model by which the Ferrari is
13:06 the expense by which they sell all this data.
13:09 And consumers, broadly, like, you know,
13:12 maybe 10% or 20% of them understand this, but the majority does not.
13:18 Totally.
13:19 what they generally look for is companies to keep them safe.
13:22 And and and if they encounter something to have that be trusted.
13:27 Some of this may end up becoming government regulation.
13:29 That's part of the reason why you've had government regulation on, you know,
13:33 finance and other kinds of things for for for how this plays out.
13:38 Um and it may need to be there in some ways.
13:41 But like, you know, previously, like, you know,
13:44 the number of just call it you know,
13:49 train wrecks in cybersecurity and data that you see even from, you know,
13:57 uh high-quality companies like Mercor and Anthropic,
14:00 then you've got all the vibe-coded apps that people are putting up.
14:04 And like, you know, like dating apps where all the information has
14:08 suddenly been leaked and posted and all the rest of the stuff.
14:12 And so, I actually think that part of what it's going
14:13 to end up being is that people are going to go,
14:17 "All right, I I might trust the startup,
14:21 but the startup is going to have to go harder to establish its
14:24 trustworthiness because I think it'll grow over
14:29 time that people will be much less, you know, kind of uh like, "Sure,
14:36 whatever I encounter on the internet,
14:38 or whatever I encounter on my mobile app, that'll be fine,
14:42 and the data will be fine." Now, I think there'll be a much, you know,
14:45 I think there'll be a growing concern,
14:47 and I think that we may need to actually even,
14:50 you know, put some extra juice in the growing
14:52 that concern because of how insecure the environment's becoming.
14:56 Yeah, it'll be interesting to see if if this we obviously think that, you know,
15:00 startups, AI-native companies are going to be
15:02 the ones who sort of win everything here.
15:04 And yet, I do think sort of brand trust, security,
15:08 like that will become more of an issue
15:10 as we sort of hear more of these horror stories.
15:12 And to your point, maybe people should be
15:14 more worried than they are, but we will see.
15:16 Um and so, stepping back from security,
15:19 it's actually really interesting if you look
15:20 at the divide between consumer and enterprise.
15:23 So, on the consumer side, I mean, ChatGPT in particular,
15:26 but all of the AI um chatbots have have been adopted at enormous pace.
15:32 I mean, faster than social media,
15:34 faster than sort of all other technologies that we've seen.
15:37 But I think that people expected this spread
15:39 to happen faster in the enterprise space.
15:43 We expected sort of companies to take it on more quickly.
15:47 And in practice, it's been slower and more uneven.
15:49 You see pockets of people going crazy and using it intensely,
15:52 but I think other companies are are unchanged from 5 years ago.
15:56 And and people probably underestimate how long it takes
16:01 for these new technologies to sort of go through these enterprise systems.
16:05 So, why do you think like what do you think that people underestimate about how
16:09 new technologies diffuse through large organizations?
16:13 And can we see this pace?
16:14 Will it speed up, slow down, continue as it has been?
16:19 Well, one of the things that I think
16:20 is kind of funny is obviously in the valley,
16:23 you know, everyone says network effects.
16:25 And and relatively few people understand it in depth
16:29 even in the canonical places of network effects, which is like, you know,
16:33 everything from fax machines to messaging
16:35 clients to social networks, etc., marketplaces.
16:38 Um and they don't track, like, for example, other kinds of network effects.
16:42 Like, for example, perhaps the uh first
16:46 and most important economic amplifier network effect is cities.
16:50 Like, it's you build the technologies, you can make villages and cities.
16:54 And now, not only does that allow all the different things like specialization,
16:57 but it also allows a massive amount of economic productivity,
17:01 not just because of the Adam Smith specialization,
17:03 but because all this kind of trade and knowledge and information can all spread.
17:09 And that's, of course, the reason why, you know,
17:12 we've just gone through our recent set
17:13 of idiots called declaring peak Silicon Valley,
17:16 Silicon Valley over, you know, whether it's Florida or Texas or whatever else.
17:20 It's like, no, you don't understand network effects.
17:22 Silicon Valley has network effects.
17:24 Well, the same thing is true of companies.
17:26 Companies have network effects.
17:27 Now, generally speaking, some of these network effects are very positive,
17:31 but network effects are kind of a portion of lock-in.
17:34 And so, part of the reason why work transformation within
17:37 companies tends to be more slowly is like you say,
17:39 well, the work that locks in a company and makes, you know,
17:43 even back in the day, Ford with the Model T more effective,
17:46 is it locked in a set of network effects in terms of how the company operates,
17:50 which means the transformation is difficult.
17:51 So, unsurprising, when you look at, you know, kind of transformation of work,
17:57 right now, that transformation of work happens most intensely in startups,
18:02 mostly intensely in small groups in big companies
18:05 that are kind of doing their own thing.
18:06 They've hopped on their AI ATVs,
18:09 and they're kind of going through the dunes on their, you know,
18:12 on their on their cognitive industrial revolution buggies,
18:16 um you know, kind of doing things.
18:18 And and the attempts for companies to say, "Well, I I I do a proof of concept,
18:24 and I have three people doing it." It's like,
18:26 that's not It only works if in a coherent work group.
18:30 Now, that being said, part of what I think is
18:32 interesting about happens in transformations with network
18:35 effects and in transformations like this is that slow and then fast.
18:39 And the fast is we're now moving entirely to this new network paradigm.
18:45 And we're abandoning the old one, we're changing the new one.
18:47 And I think it will happen,
18:50 but it happens more slowly than people predict cuz it's first slow, then fast.
18:54 Um and so, that's the the the pattern that we should be thinking.
18:58 And now, you know, like, when does it be,
19:02 you know, whatever it was a couple years ago saying, hey,
19:05 what I was saying, "Hey, everyone's going to have their own coding
19:07 assistant for doing the work." That will happen.
19:10 Obviously, the coding assistant is an amplifier.
19:12 So, like, when you have coding assistants at long
19:15 version thinking and compute as applied to your particular problem,
19:19 which might be law or accounting or finance or anything else,
19:25 and I think that's part of, you know, how that operates.
19:27 But anyway, so that's I think the the the the slow
19:31 then fast is a feature of network effects.
19:35 I also think it's really interesting because
19:37 some one thing that some people don't realize is one of the reasons why Silicon
19:41 Valley was successful was because non-competes weren't allowed.
19:44 And so, you had this diffusion of folks to other companies
19:47 or starting their own or sort of bringing their knowledge with them.
19:50 And still in so many parts of the country,
19:52 it's actually those non-competes which slow down innovation.
19:56 And so, not that they're going to topple Silicon Valley,
19:58 but we actually could see greater innovation in other cities and states if we
20:02 got rid of those non-competes so
20:03 that people could take their knowledge with them,
20:05 whether it's on AI or something else.
20:07 Well, 100% and and some of this stuff was
20:10 some of the good stuff that Lina Khan was doing.
20:12 Mhm.
20:12 Um and so, I think that having cuz
20:15 it's redefining the network as opposed to having
20:17 the the non the anti-compete or non-compete
20:20 as a keeping you as a structural lock-in per company,
20:23 it's opened it up to the local ecosystem.
20:26 And, you know, AnnaLee Saxenian's book Regional Advantage covers
20:29 this really well from a viewpoint of, you know,
20:31 venture capital was invented in Boston,
20:34 bunch of technical universities, venture capital, etc.
20:37 etc.
20:38 Why did Silicon Valley outstrip Boston?
20:41 It was because it actually uh loosened the ability to lock in network
20:46 effects as companies in terms of the anti-competes and spread it to the region,
20:51 the regional advantage.
20:53 And, you know, just to kind of, you know,
20:55 add to my earlier like, okay, these idiots describing peak Silicon Valley,
21:00 my own point of view has been,
21:02 we want as many Silicon Valleys as we can have, Absolutely.
21:06 within the US and within the Western world.
21:08 And so, I'm supportive when ever, you know, when Mike Bloomberg came out to say,
21:13 how do I, you know, do Silicon Valley in New York or, you know,
21:17 uh various governors.
21:19 And so, that notion of trying to help as many Silicon Valley
21:22 areas start as possible is I think actually a really good one.
21:26 It's just that you've got to presume the density
21:29 of the network effect of the existing Silicon Valley in your strategy.
21:34 Absolutely.
21:34 Reid, thank you so much.
21:36 Appreciate it.
21:37 Always a pleasure.
21:38 Possible is produced by Pallet Media.
21:40 It's hosted by Ary Finger and me, Reid Hoffman.
21:43 Our showrunner is Shawn Young.
21:44 Possible is produced by Tanasi Dilos, Katie Sanders,
21:48 Spencer Strassmore, Immu Zoo, Trent Barbosa, and Tafadzwa Nemarundwe.
21:53 Special thanks to Surya Yalamanchili, Saida Sapieva,
21:57 Ian Alice, Greg Beato, Parth Patel, and Ben Rallis.