Security In The AI Age

Security In The AI Age

Reid Hoffman

0:00 Read, it is a delight to be back here with you again.

0:03 Thanks for being on.

0:05 We are once again going to be talking about AI and specifically about chips.

0:09 So, according to Reuters,

0:11 data shows that Chinese firms now control about 40% of their domestic

0:14 AI chip market and that's up from roughly 35% just a year ago.

0:19 So, not huge changes,

0:21 um but Nvidia's share has fallen to the mid-50s and analysts

0:25 are expecting for Chinese homegrown chip production to keep increasing.

0:31 Obviously, US export controls have

0:33 accelerated Chinese push for self-sufficiency.

0:36 Companies like Huawei, Alibaba, Baidu,

0:38 they're building their own chips and creating entire AI ecosystems around them.

0:43 And Chinese firms are already optimizing

0:44 models to run efficiently on domestic hardware,

0:48 even if their raw performance sometimes still lags,

0:51 um by several years at the very cutting edge.

0:54 And so, when people are thinking about AI hardware chips,

0:59 how should they be thinking about this?

1:00 Is this just a supply chain issue or is

1:03 this more about this is the foundational layer of geopolitical power?

1:07 Like, how important are chips right now?

1:10 Well, the short answer is chips are very important,

1:12 although not, you know, like decisive to the end.

1:16 People have this tendency to be extremist.

1:18 Either chips don't matter at all because, in fact,

1:20 you know, China is going to do its own,

1:23 you know, kind of chips or chips matter everything, nothing else matters.

1:27 And as all of these important things,

1:30 it is a very important factor, but not the only factor that matters.

1:34 And uh there's a lot of reasons why the leading chips,

1:38 which are, you know, currently Nvidia as the key leading chip,

1:43 really matters is because it's compute density,

1:46 it's because it's a question of as you

1:49 get to larger and larger and less effective ecosystems,

1:53 less efficient like chip ecosystems in terms of how it operates,

1:58 you get more probabilistic failure in the system,

2:01 you get longer time horizons in terms of training,

2:05 you might even have certain capabilities that are a lot less.

2:10 And that's why the leading chips do in fact

2:12 matter and that's the reason why, for example,

2:14 all of the US players who are leading

2:18 this do have at minimum intense training clusters with Nvidia.

2:26 And so, that really matters.

2:28 Now, there's a set of things that then come after come after this though,

2:32 which is, for example, um China has had some leading innovations

2:38 in efficiency of compute and part of, you know,

2:41 we are learning from that within the Silicon Valley ecosystem.

2:44 It's one of the reasons why,

2:45 you know, the Chinese government has, generally speaking,

2:49 started imposing certain kinds of checks

2:52 and controls cuz they don't want to have,

2:54 you know, kind of uh Chinese leading edge IP leaking to the west.

3:00 And so, you know, you've got some challenges there.

3:03 You've also got, you know, kind of the questions around like,

3:07 you know, how do open source models work?

3:09 You've got the questions around distillation.

3:11 Um you know, as far as we can tell with Kwan,

3:13 Kimi, and other leading Chinese models,

3:16 there's actually a lot of distillation that happens from OpenAI,

3:23 Anthropic, Gemini, Copilot, etc.

3:26 in terms of these.

3:27 So, you've got that, you know, kind of playing out as well.

3:30 So, the short answer is chips matter.

3:36 The short answer is the TSMC-generated chips, which include Nvidia,

3:41 include TPUs, include, you know, other leading edge chips,

3:47 you know, really does matter,

3:49 but it's only one major factor around a set in how AI future plays out.

3:56 Now, the geopolitics of it are we are, you know,

4:02 beginning to move from the talk of AI and compute

4:07 fabrics being geopolitical power to the reality of it.

4:12 Like, it's this year, next year,

4:15 where that will begin to show some really substantive questions,

4:20 whether it's anything from, you know, obviously,

4:24 we saw this kind of dust-up around, you know, the the Pentagon and what is

4:30 the compute matter there with Anthropic and others,

4:33 but also, like, what does this mean

4:34 for industry adoption and what's actually happening?

4:37 Because as you see the coding revolution kick off,

4:41 the enterprise and work transformation will be in in various,

4:48 what we call in the industry, jagged edge,

4:50 will be also picking up speed this year.

4:53 Now, I don't think you're going to see layoffs this year because of it.

4:57 I think you'll see people claiming layoffs because of it,

5:01 but I think what we've already seen

5:02 in software engineering is much more Jevons paradox,

5:05 which is as these tools have gotten efficient,

5:08 it just increases demand and pace for what there is for software engineering.

5:14 Absolutely.

5:15 And so, going back to a little more of the geopolitics,

5:17 does this as sort of China and the US become these poles,

5:22 are are people going to have to take sides?

5:23 Like, as we go, is Europe,

5:25 are companies throughout Europe, throughout South America, throughout Asia,

5:28 are they going to have to decide where

5:29 they're getting their chips and does that lead

5:31 to sort of more fractured society as opposed

5:34 to closer collaboration cuz they're going to have to choose?

5:36 I don't think you're necessarily going to have to choose.

5:40 Um I think one of the things when it gets to the rest of the world,

5:43 um the fact that they can, you know,

5:45 bid them against each other is good and I think this is part of the reason why,

5:49 you know, a kind of a, you know,

5:51 international trade policy of tariffs and threats and retaliation is

5:56 terrible because that will then offset some natural advantages we had,

6:00 which is a higher trust than the Chinese ecosystem relative to, you know,

6:05 the kind of the US setting the global platform, the US being the, you know,

6:09 having the companies who are the providers of these things.

6:12 And I think that the, you know, last year of alienating, you know,

6:16 kind of friends and partners and allies as a general strategy, whether it's,

6:21 you know, tariff threats or tariff actualities, threats on Greenland, you know,

6:27 um you know, speeches to say, you know, uh piss off, you know, etc.

6:33 All of which will mean that this that we move

6:37 much more rapidly to a bipolar or multipolar provider of these.

6:44 And I think that that's going to be true for chips,

6:48 true for data center architecture, and true for software.

6:52 All of which we would want to be as close to a US technological ecosystem as we

6:59 can for the economic prosperity of the US

7:03 and for the economic prosperity of US companies.

7:07 It feels like someone needs to send the White House a copy of How

7:10 to Win Friends and Influence People

7:12 and maybe they can take some hard-won lessons.

7:15 Um all right.

7:16 if they read.

7:17 Yeah, exactly.

7:18 Well, yeah, yeah, yeah, we're we're starting slow.

7:21 Yes.

7:21 [laughter] All right.

7:22 So, moving from geopolitics to actually another

7:25 concern that people talk about with AI, which is cybersecurity.

7:28 And so, anyone who's been reading the news or at least

7:32 my Twitter feed was full of full of hot takes about

7:35 what's happening in cybersecurity recently because we've seen a wave of breaches

7:39 and leaks and this is some big names in the space.

7:42 So, we saw that Mercor got hacked

7:45 and the attackers claimed they stole 4 terabytes of data.

7:49 Um they said the breach was tied to the compromise of Light LLM,

7:53 which was an open-source tool in the AI stack,

7:56 meaning the company was hit through a supply chain

7:58 attack rather than a direct hack on its own perimeter.

8:01 At the same time, we also saw recently that Anthropic accidentally leaked more

8:06 than 500,000 lines of Claude code source code through a bad NPM release.

8:12 And so, they were exposing internal implementation details, unreleased features.

8:18 A lot of people are talking about what does

8:19 being sort of secure mean in this new world.

8:22 So, how should founders and operators right

8:25 now be thinking about security in a world

8:28 where it seems the attack vectors are endless and we always talk about,

8:32 yes, AI helps secure against cybersecurity,

8:35 but it also is increasing the ability to have these attacks.

8:39 So, I think this is just the beginning.

8:42 Um and I think that part of the question is is, you know,

8:46 it it's almost there's a couple reasons why cybersecurity

8:49 opens up much more intensely in the age of AI.

8:52 Um One simple one is, now that things are moving so much faster,

8:57 that there isn't as much time for like

9:01 the previous kind of iterations about how one did security.

9:04 So, the fact that there is all these tools that are

9:07 being deployed in production and everything else where you're like, well,

9:10 actually, in fact, the security like intensity of of kind of like,

9:16 you know, red teaming, multiple attacks, etc., etc., hasn't happened yet.

9:20 So, I think there's just the speed.

9:22 Second thing is, obviously, on a set of AI things,

9:26 including, you know, how one deploys LLMs,

9:29 even if one is deploying open-source models

9:32 of LLMs in one's own production environment,

9:35 is that these LLMs are inherently insecure because

9:39 they're probabilistic systems that we don't understand that well.

9:43 And so, even though we do a whole bunch of alignment training, you know,

9:47 part of what happens with even the frontier models, which do an intensive amount

9:52 of alignment training through their chat interfaces,

9:54 is we you get them doing odd things, which can include, of course,

10:00 cyber attacks or other kinds of things as ways of doing that.

10:03 And so, the there's there's actually, in fact,

10:06 some new surfaces in the software stack

10:09 platform that are unclear how you secure them.

10:14 And this is, of course, within the standard of cybersecurity,

10:17 which is inherently never fully secure.

10:20 I mean, the way that they that they that you

10:22 that you make a fully secure system is you air gap it.

10:26 Right?

10:26 Which is you disconnect it from the network.

10:28 And, you know, that's that there's very limited

10:30 set of systems where what you can do that.

10:32 And so, so all of this opens up

10:35 an intensely new intense kind of new waves of insecurity.

10:42 And given speed and iteration,

10:45 new increase like like even though you said, "Okay, well,

10:48 we secured that last thing." Whoop,

10:49 here's a set of new things that have changed and are now insecure.

10:53 Which, of course, means we're going to have

10:54 to evolve how we play the cybersecurity game.

10:57 Like, you know, is there going to be agents

11:00 and tools that are specifically not only on the, you know,

11:03 the pure code hacking form, but on fishing.

11:06 You know, cuz AI-generated tools are the some of the best fishing amplifiers.

11:09 Well, what about fishing defense?

11:12 And how does that play out?

11:13 And so, there's going to be a whole stack of like new

11:17 approaches to security and new needs for defense that haven't uh existed yet.

11:24 Now, venture businesses are very happy because, you know,

11:26 at Greylock and other places that that are kind of like

11:30 the the the cutting edge of enterprise software, um you know,

11:35 like, you know, Palo Alto Networks and a whole stack of other things,

11:39 Greylock was at the beginning of, and there's

11:41 a couple other venture firms that are equally enterprise.

11:45 You know, cybersecurity tends to be an evergreen

11:47 category with new companies being started every couple years.

11:51 Uh that's really important,

11:52 and obviously that's one of the things that, you know,

11:54 Sheinbaum and the other folks at Greylock are really focused on.

11:57 And on the other side, how would you think about it as a consumer?

12:00 So, I feel like every week you're getting an email that's like,

12:03 "Oh, your, you know, data was breached,

12:06 and there was a leak, and your passwords,

12:07 etc." And then at the same time, you know, we're heading up to April 15th,

12:11 you see a million vibe-coded apps telling you to here's how

12:14 you can do your tax returns with this new vibe-coded app,

12:17 and you know, you don't necessarily want to put your W-2

12:20 into some vibe-coded app that hasn't sort of looked at the security side.

12:24 How do you think that'll either affect consumer behavior,

12:27 or if you were a consumer, what would you do?

12:28 Would you, you know, sort of trust these new things that were coming along?

12:32 Well, so fundamentally, consumers are not terrifically informed in these areas.

12:37 It's like, for example, it's one of the reasons why generally speaking,

12:40 if you were in a mall and you you have a have a Ferrari sitting in the mall,

12:46 and you say, "Here is a five-page fill out of all of your personal form,

12:50 like your children's names, you know,

12:53 every single place that you've lived in your last, you know,

12:56 in your whole life, and all the rest." And you go, "Okay,

12:58 I'll fill it all out cuz I want the chance to win the car." And you're like,

13:00 "What are they doing with all of this data?" Because the way that cuz it's

13:04 an economic model by which the Ferrari is

13:06 the expense by which they sell all this data.

13:09 And consumers, broadly, like, you know,

13:12 maybe 10% or 20% of them understand this, but the majority does not.

13:18 Totally.

13:19 what they generally look for is companies to keep them safe.

13:22 And and and if they encounter something to have that be trusted.

13:27 Some of this may end up becoming government regulation.

13:29 That's part of the reason why you've had government regulation on, you know,

13:33 finance and other kinds of things for for for how this plays out.

13:38 Um and it may need to be there in some ways.

13:41 But like, you know, previously, like, you know,

13:44 the number of just call it you know,

13:49 train wrecks in cybersecurity and data that you see even from, you know,

13:57 uh high-quality companies like Mercor and Anthropic,

14:00 then you've got all the vibe-coded apps that people are putting up.

14:04 And like, you know, like dating apps where all the information has

14:08 suddenly been leaked and posted and all the rest of the stuff.

14:12 And so, I actually think that part of what it's going

14:13 to end up being is that people are going to go,

14:17 "All right, I I might trust the startup,

14:21 but the startup is going to have to go harder to establish its

14:24 trustworthiness because I think it'll grow over

14:29 time that people will be much less, you know, kind of uh like, "Sure,

14:36 whatever I encounter on the internet,

14:38 or whatever I encounter on my mobile app, that'll be fine,

14:42 and the data will be fine." Now, I think there'll be a much, you know,

14:45 I think there'll be a growing concern,

14:47 and I think that we may need to actually even,

14:50 you know, put some extra juice in the growing

14:52 that concern because of how insecure the environment's becoming.

14:56 Yeah, it'll be interesting to see if if this we obviously think that, you know,

15:00 startups, AI-native companies are going to be

15:02 the ones who sort of win everything here.

15:04 And yet, I do think sort of brand trust, security,

15:08 like that will become more of an issue

15:10 as we sort of hear more of these horror stories.

15:12 And to your point, maybe people should be

15:14 more worried than they are, but we will see.

15:16 Um and so, stepping back from security,

15:19 it's actually really interesting if you look

15:20 at the divide between consumer and enterprise.

15:23 So, on the consumer side, I mean, ChatGPT in particular,

15:26 but all of the AI um chatbots have have been adopted at enormous pace.

15:32 I mean, faster than social media,

15:34 faster than sort of all other technologies that we've seen.

15:37 But I think that people expected this spread

15:39 to happen faster in the enterprise space.

15:43 We expected sort of companies to take it on more quickly.

15:47 And in practice, it's been slower and more uneven.

15:49 You see pockets of people going crazy and using it intensely,

15:52 but I think other companies are are unchanged from 5 years ago.

15:56 And and people probably underestimate how long it takes

16:01 for these new technologies to sort of go through these enterprise systems.

16:05 So, why do you think like what do you think that people underestimate about how

16:09 new technologies diffuse through large organizations?

16:13 And can we see this pace?

16:14 Will it speed up, slow down, continue as it has been?

16:19 Well, one of the things that I think

16:20 is kind of funny is obviously in the valley,

16:23 you know, everyone says network effects.

16:25 And and relatively few people understand it in depth

16:29 even in the canonical places of network effects, which is like, you know,

16:33 everything from fax machines to messaging

16:35 clients to social networks, etc., marketplaces.

16:38 Um and they don't track, like, for example, other kinds of network effects.

16:42 Like, for example, perhaps the uh first

16:46 and most important economic amplifier network effect is cities.

16:50 Like, it's you build the technologies, you can make villages and cities.

16:54 And now, not only does that allow all the different things like specialization,

16:57 but it also allows a massive amount of economic productivity,

17:01 not just because of the Adam Smith specialization,

17:03 but because all this kind of trade and knowledge and information can all spread.

17:09 And that's, of course, the reason why, you know,

17:12 we've just gone through our recent set

17:13 of idiots called declaring peak Silicon Valley,

17:16 Silicon Valley over, you know, whether it's Florida or Texas or whatever else.

17:20 It's like, no, you don't understand network effects.

17:22 Silicon Valley has network effects.

17:24 Well, the same thing is true of companies.

17:26 Companies have network effects.

17:27 Now, generally speaking, some of these network effects are very positive,

17:31 but network effects are kind of a portion of lock-in.

17:34 And so, part of the reason why work transformation within

17:37 companies tends to be more slowly is like you say,

17:39 well, the work that locks in a company and makes, you know,

17:43 even back in the day, Ford with the Model T more effective,

17:46 is it locked in a set of network effects in terms of how the company operates,

17:50 which means the transformation is difficult.

17:51 So, unsurprising, when you look at, you know, kind of transformation of work,

17:57 right now, that transformation of work happens most intensely in startups,

18:02 mostly intensely in small groups in big companies

18:05 that are kind of doing their own thing.

18:06 They've hopped on their AI ATVs,

18:09 and they're kind of going through the dunes on their, you know,

18:12 on their on their cognitive industrial revolution buggies,

18:16 um you know, kind of doing things.

18:18 And and the attempts for companies to say, "Well, I I I do a proof of concept,

18:24 and I have three people doing it." It's like,

18:26 that's not It only works if in a coherent work group.

18:30 Now, that being said, part of what I think is

18:32 interesting about happens in transformations with network

18:35 effects and in transformations like this is that slow and then fast.

18:39 And the fast is we're now moving entirely to this new network paradigm.

18:45 And we're abandoning the old one, we're changing the new one.

18:47 And I think it will happen,

18:50 but it happens more slowly than people predict cuz it's first slow, then fast.

18:54 Um and so, that's the the the pattern that we should be thinking.

18:58 And now, you know, like, when does it be,

19:02 you know, whatever it was a couple years ago saying, hey,

19:05 what I was saying, "Hey, everyone's going to have their own coding

19:07 assistant for doing the work." That will happen.

19:10 Obviously, the coding assistant is an amplifier.

19:12 So, like, when you have coding assistants at long

19:15 version thinking and compute as applied to your particular problem,

19:19 which might be law or accounting or finance or anything else,

19:25 and I think that's part of, you know, how that operates.

19:27 But anyway, so that's I think the the the the slow

19:31 then fast is a feature of network effects.

19:35 I also think it's really interesting because

19:37 some one thing that some people don't realize is one of the reasons why Silicon

19:41 Valley was successful was because non-competes weren't allowed.

19:44 And so, you had this diffusion of folks to other companies

19:47 or starting their own or sort of bringing their knowledge with them.

19:50 And still in so many parts of the country,

19:52 it's actually those non-competes which slow down innovation.

19:56 And so, not that they're going to topple Silicon Valley,

19:58 but we actually could see greater innovation in other cities and states if we

20:02 got rid of those non-competes so

20:03 that people could take their knowledge with them,

20:05 whether it's on AI or something else.

20:07 Well, 100% and and some of this stuff was

20:10 some of the good stuff that Lina Khan was doing.

20:12 Mhm.

20:12 Um and so, I think that having cuz

20:15 it's redefining the network as opposed to having

20:17 the the non the anti-compete or non-compete

20:20 as a keeping you as a structural lock-in per company,

20:23 it's opened it up to the local ecosystem.

20:26 And, you know, AnnaLee Saxenian's book Regional Advantage covers

20:29 this really well from a viewpoint of, you know,

20:31 venture capital was invented in Boston,

20:34 bunch of technical universities, venture capital, etc.

20:37 etc.

20:38 Why did Silicon Valley outstrip Boston?

20:41 It was because it actually uh loosened the ability to lock in network

20:46 effects as companies in terms of the anti-competes and spread it to the region,

20:51 the regional advantage.

20:53 And, you know, just to kind of, you know,

20:55 add to my earlier like, okay, these idiots describing peak Silicon Valley,

21:00 my own point of view has been,

21:02 we want as many Silicon Valleys as we can have, Absolutely.

21:06 within the US and within the Western world.

21:08 And so, I'm supportive when ever, you know, when Mike Bloomberg came out to say,

21:13 how do I, you know, do Silicon Valley in New York or, you know,

21:17 uh various governors.

21:19 And so, that notion of trying to help as many Silicon Valley

21:22 areas start as possible is I think actually a really good one.

21:26 It's just that you've got to presume the density

21:29 of the network effect of the existing Silicon Valley in your strategy.

21:34 Absolutely.

21:34 Reid, thank you so much.

21:36 Appreciate it.

21:37 Always a pleasure.

21:38 Possible is produced by Pallet Media.

21:40 It's hosted by Ary Finger and me, Reid Hoffman.

21:43 Our showrunner is Shawn Young.

21:44 Possible is produced by Tanasi Dilos, Katie Sanders,

21:48 Spencer Strassmore, Immu Zoo, Trent Barbosa, and Tafadzwa Nemarundwe.

21:53 Special thanks to Surya Yalamanchili, Saida Sapieva,

21:57 Ian Alice, Greg Beato, Parth Patel, and Ben Rallis.

Study with Looplines Download Captions Watch on YouTube