1
00:00:00,040 --> 00:00:06,120
Imagine hiring 1000 lightning 
fast, totally tireless 

2
00:00:06,120 --> 00:00:08,280
apprentices. 
Sounds pretty great on paper, 

3
00:00:08,280 --> 00:00:10,640
right? 
But then you realize that if you

4
00:00:10,640 --> 00:00:12,640
don't literally hold the 
physical door open for them, 

5
00:00:12,640 --> 00:00:13,960
they just get stuck in the 
hallway. 

6
00:00:14,040 --> 00:00:15,680
Yeah. 
Just completely frozen. 

7
00:00:15,720 --> 00:00:17,760
Exactly. 
I mean, they never sleep, they 

8
00:00:17,760 --> 00:00:21,200
type it 1,000,000 words a 
minute, but half the time they 

9
00:00:21,200 --> 00:00:23,960
end up installing your kitchen 
cabinets upside down just 'cause

10
00:00:23,960 --> 00:00:26,760
they thought the layout, you 
know, vibed better. 

11
00:00:26,760 --> 00:00:30,600
Which is a total nightmare. 
It is, and that is the exact 

12
00:00:30,600 --> 00:00:33,320
management nightmare the 
software industry woke up to 

13
00:00:33,680 --> 00:00:36,840
this May. 
So welcome to the deep dive. 

14
00:00:36,840 --> 00:00:37,520
Glad. 
To be here. 

15
00:00:37,640 --> 00:00:41,560
We are looking at a stack of 
sources from early May 2026. 

16
00:00:41,560 --> 00:00:44,880
Today we've got dispatches from 
the new stack, some really 

17
00:00:44,880 --> 00:00:47,680
interesting commentary from 
developers like Simon Wilson. 

18
00:00:47,840 --> 00:00:49,160
Really good stuff in there. 
Yeah. 

19
00:00:49,400 --> 00:00:52,040
And for you listening, our 
mission today is to try to make 

20
00:00:52,040 --> 00:00:55,720
sense of this massive, massive 
shift happening right now in the

21
00:00:55,720 --> 00:01:00,280
software world because we are 
officially way past that 

22
00:01:00,280 --> 00:01:03,040
honeymoon phase of just saying, 
oh wow, look, the AI wrote some 

23
00:01:03,040 --> 00:01:05,400
code. 
Oh yeah, that phase is dead and 

24
00:01:05,400 --> 00:01:07,400
gone. 
We are witnessing a complete 

25
00:01:07,400 --> 00:01:10,960
recalibration of where the 
actual architectural value sits 

26
00:01:11,120 --> 00:01:12,040
in this industry. 
Right. 

27
00:01:12,040 --> 00:01:16,720
We're crashing head first into 
the reality of managing and like

28
00:01:16,800 --> 00:01:20,600
securing an ecosystem where 
autonomous agents are doing all 

29
00:01:20,600 --> 00:01:22,840
the heavy lifting. 
The novelty of code generation 

30
00:01:22,840 --> 00:01:26,280
is totally worn off and honestly
the panic of infrastructure 

31
00:01:26,280 --> 00:01:28,320
integration has set in. 
Seriously. 

32
00:01:28,480 --> 00:01:31,800
So today we're exploring how the
real money is shifting away from

33
00:01:31,800 --> 00:01:36,280
the AI models themselves and 
moving toward the the harness 

34
00:01:36,280 --> 00:01:38,640
that controls them. 
We'll get into the bizarre 

35
00:01:38,640 --> 00:01:41,360
physical logistics of running 
these things, and why some 

36
00:01:41,360 --> 00:01:44,480
developer communities are just 
flat out banning AI entirely. 

37
00:01:44,560 --> 00:01:47,040
It's a huge reaction. 
It is, but let's start with a 

38
00:01:47,040 --> 00:01:49,280
number from the sources that 
genuinely made me do a double 

39
00:01:49,280 --> 00:01:52,480
take cursor. 
The AI coding platform recently 

40
00:01:52,480 --> 00:01:56,000
hit a valuation of $60 billion. 
60 billion, It's a staggering 

41
00:01:56,000 --> 00:01:57,080
number. 
Mind blowing. 

42
00:01:57,680 --> 00:02:00,640
And their strategic thesis for 
that valuation is basically that

43
00:02:00,640 --> 00:02:03,360
the underlying AI models, like 
the actual brains of the 

44
00:02:03,360 --> 00:02:06,440
operation, are rapidly becoming 
cheap commodities. 

45
00:02:06,640 --> 00:02:11,160
Right, they believe the real 
value is in building the SDK and

46
00:02:11,160 --> 00:02:14,040
that tooling layer around the 
model, what they call the 

47
00:02:14,040 --> 00:02:15,560
harness a. 
Harness Exactly. 

48
00:02:15,880 --> 00:02:18,720
OK, let's unpack this. 
It's basically the classic, you 

49
00:02:18,720 --> 00:02:21,920
know, selling picks and shovels 
during the gold rush scenario, 

50
00:02:21,920 --> 00:02:23,400
right? 
And what's fascinating here is 

51
00:02:23,400 --> 00:02:25,240
that it's a very compelling 
thesis. 

52
00:02:25,360 --> 00:02:29,040
If we look at the raw mechanics,
an AI model is essentially just 

53
00:02:29,040 --> 00:02:30,960
a high performance engine block.
OK. 

54
00:02:31,240 --> 00:02:35,160
It has immense raw power, sure, 
but sitting on a workbench all 

55
00:02:35,160 --> 00:02:36,920
it really does is vibrate 
violently. 

56
00:02:37,280 --> 00:02:39,760
To actually go anywhere, you 
need a transmission, a steering 

57
00:02:39,760 --> 00:02:42,920
column, an interface the driver 
actually understands. 

58
00:02:42,920 --> 00:02:46,240
So Cursor is betting that 
whoever builds the best chassis 

59
00:02:46,640 --> 00:02:49,440
basically owns the market. 
Exactly, regardless of whether 

60
00:02:49,440 --> 00:02:53,400
the engine inside is made by 
Open AI or Google or you know, 

61
00:02:53,400 --> 00:02:55,520
some open weight model you 
downloaded for free. 

62
00:02:55,640 --> 00:02:57,080
But wait, I'm stuck on that 
though. 

63
00:02:57,440 --> 00:03:00,040
If the models really are 
destined to be these cheap 

64
00:03:00,040 --> 00:03:04,400
interchangeable commodities, why
is a giant like Anthropic 

65
00:03:04,800 --> 00:03:07,560
bothering to pour billions into 
building claws? 

66
00:03:07,560 --> 00:03:10,160
Like why not just pivot and only
build the harness? 

67
00:03:10,320 --> 00:03:14,160
Well, The thing is, they are 
doing exactly that, and it's 

68
00:03:14,160 --> 00:03:16,480
creating this incredible 
competitive tension. 

69
00:03:16,880 --> 00:03:20,440
Anthropic isn't just letting 
Cursor build the harness, they 

70
00:03:20,440 --> 00:03:24,120
are aggressively pursuing a 
vertical integration strategy. 

71
00:03:24,120 --> 00:03:25,720
Meaning they want to own both. 
Right. 

72
00:03:25,920 --> 00:03:28,720
They're building the underlying 
Claude models, yes, but they are

73
00:03:28,720 --> 00:03:31,200
also building the harness layer.
You look at their model, 

74
00:03:31,200 --> 00:03:34,880
context, protocol, the MC key 
ecosystem, and tools like Claude

75
00:03:34,880 --> 00:03:37,160
Code. 
So they want to own the whole 

76
00:03:37,160 --> 00:03:40,240
stack, the engine, the chassis, 
the tires, everything. 

77
00:03:40,240 --> 00:03:43,760
Exactly, they are basically 
positioning themselves to be the

78
00:03:44,120 --> 00:03:45,440
AWS of a gentic AI. 
Oh. 

79
00:03:45,560 --> 00:03:48,560
That's a really good analogy. 
Think back to how Amazon Web 

80
00:03:48,560 --> 00:03:50,720
Services dominated the early 
Internet. 

81
00:03:51,080 --> 00:03:53,960
They didn't just build server 
racks, they created the 

82
00:03:53,960 --> 00:03:58,200
foundational primitives. 
S3 for storage, EC2 for compute.

83
00:03:58,600 --> 00:04:00,920
Anthropic is doing that for an 
AI workforce. 

84
00:04:00,960 --> 00:04:03,040
Right, the sources mentioned 
they just launched Claude 

85
00:04:03,040 --> 00:04:06,080
Managed Agents in public beta. 
Yes, and then a mere 2 weeks 

86
00:04:06,080 --> 00:04:08,440
later, they added persistent 
memory to those agents. 

87
00:04:08,680 --> 00:04:11,520
But the real masterstroke? 
The thing that locks it all in 

88
00:04:12,000 --> 00:04:15,920
is that MCT ecosystem. 
Yeah, because MCP acts as this 

89
00:04:15,920 --> 00:04:19,160
standardized bridge, right? 
Like before, if you wanted an AI

90
00:04:19,160 --> 00:04:21,959
to read your proprietary company
database or, I don't know, 

91
00:04:21,959 --> 00:04:26,120
access your Slack messages, you 
had to write custom API wrappers

92
00:04:26,200 --> 00:04:29,000
for every single tool. 
It was a total nightmare to 

93
00:04:29,000 --> 00:04:31,240
maintain. 
But MCP standardizes all of 

94
00:04:31,240 --> 00:04:32,680
that. 
It's like a universal plug and 

95
00:04:32,680 --> 00:04:35,560
play adapter for data. 
And that standardization acts as

96
00:04:35,560 --> 00:04:39,320
this massive developer gravity 
mechanism because once you 

97
00:04:39,360 --> 00:04:42,280
actually wire your internal 
databases in your ticketing 

98
00:04:42,280 --> 00:04:47,000
systems to Anthropics MCP 
orchestration layer, the 

99
00:04:47,000 --> 00:04:50,600
switching costs become stagger. 
You're completely locked in. 

100
00:04:50,600 --> 00:04:53,640
You are ripping it out means 
rebuilding your entire data 

101
00:04:53,640 --> 00:04:56,560
infrastructure, even if a 
slightly cheaper model drops 

102
00:04:56,560 --> 00:04:58,080
tomorrow. 
And we're already seeing how 

103
00:04:58,080 --> 00:04:59,960
flexible this harness is in the 
wild. 

104
00:05:00,320 --> 00:05:02,240
Like the sources bring up Simon 
Willison. 

105
00:05:02,440 --> 00:05:06,120
He literally built an entire I 
Naturalist Sightings app on his 

106
00:05:06,120 --> 00:05:08,320
mobile phone. 
Just using his phone, yeah. 

107
00:05:08,880 --> 00:05:10,400
Just using Claude code for the 
web. 

108
00:05:10,600 --> 00:05:13,600
He didn't even need a desktop 
environment or a local IDE. 

109
00:05:13,600 --> 00:05:16,400
He just orchestrated the agents 
through the web interface and 

110
00:05:16,400 --> 00:05:18,360
the harness handled all the 
environment setup and the 

111
00:05:18,360 --> 00:05:21,000
dependencies. 
That's the power of owning the 

112
00:05:21,000 --> 00:05:23,760
orchestration layer. 
The human developer basically 

113
00:05:23,760 --> 00:05:26,920
becomes a conductor rather than 
an instrumentalist. 

114
00:05:27,000 --> 00:05:30,160
Which sounds very high level and
elegant, but looking at the 

115
00:05:30,160 --> 00:05:34,080
actual mechanics of this on the 
ground, there's this hilarious 

116
00:05:34,080 --> 00:05:38,240
disconnect between these 
multibillion dollar cloud wars 

117
00:05:38,680 --> 00:05:40,960
and the reality of what 
developers are actually doing. 

118
00:05:40,960 --> 00:05:44,080
Oh, the physical logistics. 
Yes, we're moving from high 

119
00:05:44,080 --> 00:05:49,000
minded business strategy down to
the messy desktop reality 

120
00:05:49,280 --> 00:05:52,120
because the sources point out 
this bizarre problem where 

121
00:05:52,120 --> 00:05:54,800
developers are literally having 
to keep their physical laptops 

122
00:05:54,800 --> 00:05:58,920
open like screen glowing just to
prevent their AI agents from 

123
00:05:58,920 --> 00:06:01,840
dying mid task. 
It's objectively absurd, but it 

124
00:06:01,840 --> 00:06:04,400
highlights a profound 
architectural bottleneck. 

125
00:06:04,920 --> 00:06:07,800
These agents are fundamentally 
tethered to local machines. 

126
00:06:08,320 --> 00:06:10,560
It's like having to prop open 
all the doors in your house so 

127
00:06:10,560 --> 00:06:12,800
the robot vacuum doesn't get 
stuck in the bathroom. 

128
00:06:12,800 --> 00:06:15,680
That's exactly it. 
Because an agent isn't just one 

129
00:06:15,680 --> 00:06:19,200
simple API call, it's a 
localized recursive loop. 

130
00:06:19,280 --> 00:06:22,440
It writes code, runs a local 
test, reads the terminal error, 

131
00:06:22,680 --> 00:06:25,240
and then loops back to the LLM 
to ask for a fix. 

132
00:06:25,240 --> 00:06:26,600
And if your computer goes to 
sleep? 

133
00:06:26,880 --> 00:06:31,520
The OS halts the local process, 
the loop breaks, the websocket 

134
00:06:31,520 --> 00:06:34,320
connection drops. 
And it loses its memory, right? 

135
00:06:34,320 --> 00:06:38,040
Yes, crucially the context 
window it's memory of the last 

136
00:06:38,040 --> 00:06:42,400
50 steps is wiped. 
It wakes U with total amnesia. 

137
00:06:42,520 --> 00:06:46,120
O, you literally have these 
brilliant, highly paid engineers

138
00:06:46,720 --> 00:06:50,680
tapping their space bars at 2:00
AM just so they're autonomous. 

139
00:06:50,720 --> 00:06:53,000
AI doesn't take a nap. 
That's like babysitting a 

140
00:06:53,000 --> 00:06:56,280
Tamagotchi. 
It is, but it exposes a massive 

141
00:06:56,280 --> 00:06:59,360
gap in the market. 
We're seeing an industry wide 

142
00:06:59,360 --> 00:07:02,240
scramble for what we call agent 
infrastructure. 

143
00:07:02,360 --> 00:07:03,360
Right. 
The sources mentioned 

144
00:07:03,360 --> 00:07:05,080
Incredibuild is stepping in 
here, yeah. 

145
00:07:05,080 --> 00:07:08,280
They're offering sandboxed cloud
accessible persistent compute 

146
00:07:08,280 --> 00:07:11,240
specifically for agents. 
Compute persistence is becoming 

147
00:07:11,240 --> 00:07:13,440
an entirely new product 
category. 

148
00:07:13,440 --> 00:07:15,840
So instead of running it on my 
MacBook, I just rent a virtual 

149
00:07:15,840 --> 00:07:18,520
machine in the cloud where the 
agent can run its loops 

150
00:07:18,520 --> 00:07:20,640
uninterrupted for days. 
Exactly. 

151
00:07:20,640 --> 00:07:22,920
And it's not just startups. 
Look at the codec CLI, 

152
00:07:22,920 --> 00:07:27,920
specifically version 0.1 to 8.0.
They just added a new command 

153
00:07:27,920 --> 00:07:30,440
literally called slash goal. 
Slash goal, right? 

154
00:07:30,760 --> 00:07:34,520
It initiates A persistent goal 
oriented loop on the back end. 

155
00:07:34,800 --> 00:07:37,040
It detaches from the local 
terminal and just keeps 

156
00:07:37,080 --> 00:07:40,440
iterating until the goal is met 
or it burns through its entire 

157
00:07:40,440 --> 00:07:43,720
token budget. 
Even Mistral, the big European 

158
00:07:43,720 --> 00:07:47,160
AI player, is pivoting heavily 
into cloud based coding agents 

159
00:07:47,160 --> 00:07:50,280
for this exact reason. 
OK, so we're building luxury 

160
00:07:50,280 --> 00:07:53,280
apartments in the cloud for 
these agents to code 24/7 

161
00:07:53,480 --> 00:07:57,840
without us tapping the space 
bar, but that raises an 

162
00:07:57,840 --> 00:08:00,080
immediate red flag for me. 
The quality issue. 

163
00:08:00,080 --> 00:08:05,040
Yes, if an agent is endlessly 
looping and compiling without a 

164
00:08:05,040 --> 00:08:08,040
human checking it, what is the 
actual quality of the software 

165
00:08:08,040 --> 00:08:10,200
it's churning out? 
There's a growing backlash 

166
00:08:10,200 --> 00:08:11,760
against this, right? 
What they're calling vibe 

167
00:08:11,760 --> 00:08:13,800
coding. 
The backlash is very real. 

168
00:08:13,920 --> 00:08:16,480
Yeah, Matthew Galicius is quoted
directly in the sources saying. 

169
00:08:16,720 --> 00:08:19,080
Five months in, I think I've 
decided that I don't want a vibe

170
00:08:19,080 --> 00:08:20,920
code. 
I want professionally managed 

171
00:08:20,920 --> 00:08:24,040
software companies to use AI 
coding assistance to make more, 

172
00:08:24,040 --> 00:08:27,120
better, cheaper software. 
He's vocalizing A frustration 

173
00:08:27,120 --> 00:08:29,920
that is echoing across the 
entire enterprise software 

174
00:08:29,920 --> 00:08:32,039
world. 
What he's experienced is known 

175
00:08:32,039 --> 00:08:34,960
in the industry as the 80% 
problem. 

176
00:08:35,080 --> 00:08:38,520
The 80% problem, meaning it gets
you most of the way there, but 

177
00:08:38,520 --> 00:08:39,760
not all the way. 
Exactly. 

178
00:08:40,080 --> 00:08:43,120
AI is fantastic at getting a 
project 80% complete. 

179
00:08:43,120 --> 00:08:45,920
It can scaffold an application, 
write boilerplate, get a 

180
00:08:45,920 --> 00:08:49,720
prototype running incredibly 
fast, but it struggles massively

181
00:08:49,720 --> 00:08:53,280
with that final 20%. 
Because that last 20% is the 

182
00:08:53,280 --> 00:08:56,080
hard stuff. 
It's not just basic syntax, it's

183
00:08:56,560 --> 00:08:59,920
state management, integration, 
testing, making sure your new 

184
00:08:59,920 --> 00:09:03,000
microservice doesn't 
accidentally Drake a legacy 

185
00:09:03,000 --> 00:09:06,800
database to networks over. 
Right, that lack of holistic 

186
00:09:06,800 --> 00:09:10,760
architectural awareness is the 
core limitation of current LLMS,

187
00:09:11,200 --> 00:09:13,480
and companies are scrambling to 
fix this gap. 

188
00:09:13,720 --> 00:09:16,160
Quickbase just released a 
product called Pave. 

189
00:09:16,240 --> 00:09:18,920
Right, Pave and pave doesn't 
even try to write the initial 

190
00:09:18,920 --> 00:09:19,720
code does. 
It no. 

191
00:09:19,720 --> 00:09:22,280
It's entirely targeted at 
orchestrating those final 

192
00:09:22,280 --> 00:09:24,840
integration tests to ensure 
production readiness. 

193
00:09:25,320 --> 00:09:28,280
Similarly, Anaconda just 
acquired Outer Bounds, which is 

194
00:09:28,280 --> 00:09:30,160
built around the Metaflow 
framework. 

195
00:09:30,280 --> 00:09:33,000
Metaflows for complex machine 
learning pipelines, right? 

196
00:09:33,040 --> 00:09:35,760
Yes, exactly. 
Machine learning pipelines are 

197
00:09:35,760 --> 00:09:39,000
represented as directed acyclic 
graphs, or digs. 

198
00:09:39,280 --> 00:09:42,360
They are incredibly complex webs
of dependent tasks. 

199
00:09:43,040 --> 00:09:46,440
AI code notoriously fails here 
because it loses track of how a 

200
00:09:46,440 --> 00:09:50,080
variable change in Step 2 
effects distributed memory in 

201
00:09:50,080 --> 00:09:52,920
step 50. 
So outer bounds was acquired 

202
00:09:52,920 --> 00:09:57,120
specifically to enforce state 
consistency in AI generated data

203
00:09:57,120 --> 00:09:59,000
science code. 
But wait, let me push back on 

204
00:09:59,000 --> 00:10:02,640
this fatigue a bit. 
Because getting 80% of a complex

205
00:10:02,640 --> 00:10:05,640
software project drafted 
instantly basically for free is 

206
00:10:05,640 --> 00:10:09,120
still a miracle, isn't it? 
Why is the industry acting like 

207
00:10:09,120 --> 00:10:12,720
doing the final 20% of Polish is
some unbearable deal breaker? 

208
00:10:12,720 --> 00:10:14,480
Because scale changes 
everything. 

209
00:10:14,800 --> 00:10:18,360
Having an AI do 80% of the work 
on one single project is a huge 

210
00:10:18,360 --> 00:10:21,280
time saver for one developer. 
But when you deploy autonomous 

211
00:10:21,320 --> 00:10:24,760
agents at an enterprise scale 
and they spin up 10,000 

212
00:10:24,760 --> 00:10:28,520
concurrent projects that are all
only 80% done, you haven't 

213
00:10:28,520 --> 00:10:31,120
created value, you've just 
automated the creation of a 

214
00:10:31,120 --> 00:10:34,720
massive, unmanageable backlog. 
Oh wow, I didn't think of it 

215
00:10:34,720 --> 00:10:37,480
like that. 
A million projects like at 80% 

216
00:10:37,480 --> 00:10:39,840
isn't innovation, it's just a 
giant liability. 

217
00:10:40,040 --> 00:10:42,560
It completely paralyzes the 
engineering team. 

218
00:10:43,160 --> 00:10:46,200
Human developers end up spending
all their time just trying to 

219
00:10:46,200 --> 00:10:49,640
debug the tangled, undocumented 
logic of an AI. 

220
00:10:50,240 --> 00:10:53,360
The cognitive load of fixing 
someone else's messy code, 

221
00:10:53,480 --> 00:10:56,720
especially an AI's messy code, 
is often higher than just 

222
00:10:56,720 --> 00:10:59,560
writing it from scratch. 
Which totally explains what's 

223
00:10:59,560 --> 00:11:01,600
happening in the open source 
world right now. 

224
00:11:02,000 --> 00:11:05,400
Because if enterprise developers
who are getting paid are getting

225
00:11:05,400 --> 00:11:09,640
fatigued by this 80% problem, 
volunteer communities are just 

226
00:11:09,760 --> 00:11:12,040
hitting a wall. 
They're taking extreme measures,

227
00:11:12,040 --> 00:11:13,920
yeah. 
Well, enterprise companies are 

228
00:11:13,920 --> 00:11:15,880
trying to build tools to bridge 
the gap. 

229
00:11:16,200 --> 00:11:19,280
Open source communities are just
building walls to keep it out. 

230
00:11:19,760 --> 00:11:21,360
Which brings us to the Zig 
project. 

231
00:11:21,520 --> 00:11:23,840
The Zig community response is 
fascinating. 

232
00:11:23,880 --> 00:11:27,320
For you listening, Zig is a 
systems programming language and

233
00:11:27,320 --> 00:11:31,600
their community just implemented
A strict hard no LLM policy. 

234
00:11:32,120 --> 00:11:34,440
And this isn't just a ban on 
committing AI code. 

235
00:11:34,600 --> 00:11:38,240
It covers issue reports, pull 
requests, bug tracker comments, 

236
00:11:38,440 --> 00:11:42,680
even localization translations. 
It's a sweeping quarantine of AI

237
00:11:42,680 --> 00:11:45,880
output, and the rationale is 
entirely about preserving the 

238
00:11:45,880 --> 00:11:49,160
signal to noise ratio. 
The maintainers argue that AI 

239
00:11:49,160 --> 00:11:51,880
contributions actively degrade 
signal quality. 

240
00:11:52,080 --> 00:11:55,360
It just increases the sheer 
volume of interactions without 

241
00:11:55,360 --> 00:11:58,280
adding any underlying substance.
Right, the source is called this

242
00:11:58,600 --> 00:12:00,440
AI Slop. 
AI slop. 

243
00:12:00,480 --> 00:12:03,160
It's a highly polished, 
grammatically perfect shell, 

244
00:12:03,400 --> 00:12:05,480
totally devoid of actual 
insight. 

245
00:12:05,800 --> 00:12:08,840
In open source, maintainers rely
on the context and the human 

246
00:12:08,840 --> 00:12:11,560
struggle of someone reporting a 
bug to understand the root 

247
00:12:11,560 --> 00:12:14,120
cause. 
Yeah, if an LLM rewrites a messy

248
00:12:14,120 --> 00:12:17,600
bug report to sound super 
professional, it smooths over 

249
00:12:17,600 --> 00:12:20,680
all those jagged, vital edges of
the actual technical problem. 

250
00:12:20,800 --> 00:12:23,120
Exactly. 
The Zig community explicitly 

251
00:12:23,120 --> 00:12:26,840
states they prefer authentic 
imperfect English over hollow 

252
00:12:26,840 --> 00:12:29,160
LLM output. 
It's like a farmers market 

253
00:12:29,160 --> 00:12:32,480
putting up a sign that says 
handcrafted goods only, no 

254
00:12:32,480 --> 00:12:34,680
factory farming allowed. 
But I mean, is this really 

255
00:12:34,680 --> 00:12:36,640
enforceable? 
Distinguishing between someone 

256
00:12:36,640 --> 00:12:40,880
who naturally writes well or 
uses Grammarly versus an AI AI 

257
00:12:40,880 --> 00:12:43,720
agent writing a PR. 
That's largely an honor system, 

258
00:12:43,720 --> 00:12:44,800
right? 
It is. 

259
00:12:45,000 --> 00:12:47,720
It's culturally enforced. 
Not technologically enforced, 

260
00:12:47,960 --> 00:12:50,120
but it diagnosis the problem 
perfectly. 

261
00:12:50,320 --> 00:12:53,720
Review fatigue is going to break
human maintainers if we don't 

262
00:12:53,720 --> 00:12:57,800
find a way to filter the slop. 
Is this a universal solution for

263
00:12:57,800 --> 00:13:01,560
every corporate environment? 
No, but it perfectly captures 

264
00:13:01,560 --> 00:13:03,680
the reality of the AI slot 
problem. 

265
00:13:03,680 --> 00:13:05,760
Right, which naturally 
transitions to the final 

266
00:13:05,760 --> 00:13:07,800
problem. 
Because if banning AI isn't 

267
00:13:07,800 --> 00:13:10,200
realistic for most corporate 
environments, the only way 

268
00:13:10,200 --> 00:13:13,640
forward is to build better, 
smarter gates to check the AI's 

269
00:13:13,640 --> 00:13:16,920
work. 
How do we secure the code these 

270
00:13:16,920 --> 00:13:18,440
agents are writing while we're 
sleeping? 

271
00:13:18,600 --> 00:13:21,440
Well, if we connect this to the 
bigger picture, on April 30th 

272
00:13:21,520 --> 00:13:24,760
Anthropic moved their new clawed
security tool from closed 

273
00:13:24,760 --> 00:13:28,560
preview into public beta. 
It's integrated directly into 

274
00:13:28,560 --> 00:13:31,840
clawed code, and its explicit 
purpose is to act as an 

275
00:13:31,840 --> 00:13:34,880
intelligent checkpoint, scanning
entire code bases for 

276
00:13:34,880 --> 00:13:37,200
vulnerabilities. 
But hold on, static analysis 

277
00:13:37,200 --> 00:13:39,360
tools have existed for decades, 
right? 

278
00:13:39,560 --> 00:13:42,320
Like Sonar, Kobe, or checkmarks.
We've had linters forever. 

279
00:13:42,440 --> 00:13:44,400
What makes this mechanically 
different? 

280
00:13:44,760 --> 00:13:47,920
Traditional static analysis 
relies on looking for known bad 

281
00:13:47,920 --> 00:13:50,440
patterns, like a hard coded 
password string. 

282
00:13:51,080 --> 00:13:53,840
It's basically doing a highly 
advanced find and replace 

283
00:13:53,840 --> 00:13:55,840
search. 
It doesn't actually understand 

284
00:13:55,840 --> 00:13:58,840
the software, so it generates a 
massive volume of false 

285
00:13:58,840 --> 00:14:01,480
positive. 
Which security teams then have 

286
00:14:01,480 --> 00:14:05,920
to manually dismiss 1 by 1? 
Exactly, but Claude Security 

287
00:14:05,920 --> 00:14:09,320
performs semantic analysis. 
Meaning it actually understands 

288
00:14:09,320 --> 00:14:11,280
the intent of the code. 
Precisely. 

289
00:14:11,640 --> 00:14:14,680
It maps how data actually flows 
through the architecture. 

290
00:14:15,000 --> 00:14:18,440
It doesn't just flag a dangerous
SQL query in isolation, it 

291
00:14:18,440 --> 00:14:21,200
traces the data path. 
It can see that a variable 

292
00:14:21,200 --> 00:14:24,920
originates from a user input, 
passes through an API gateway, 

293
00:14:25,160 --> 00:14:27,880
gets transformed by a back end 
service, and arrives at the 

294
00:14:27,880 --> 00:14:29,440
database without being 
sanitized. 

295
00:14:29,920 --> 00:14:32,760
It finds the needle, explains 
why the needle is dangerous in 

296
00:14:32,760 --> 00:14:35,520
the context of the whole app, 
and suggests the architectural 

297
00:14:35,520 --> 00:14:38,120
fix. 
It acts as an automated PR gate.

298
00:14:38,520 --> 00:14:40,680
That's incredible, and here's 
where it gets really actionable 

299
00:14:40,680 --> 00:14:42,480
for you listening. 
If you're planning to use this, 

300
00:14:42,760 --> 00:14:44,680
the sources have a very specific
pro tip. 

301
00:14:44,720 --> 00:14:48,200
Don't just ping cloud security 
with a generic prompt like check

302
00:14:48,200 --> 00:14:51,440
my code for security issues. 
No, that won't work well at all,

303
00:14:51,440 --> 00:14:53,240
right? 
You have to specify your threat 

304
00:14:53,240 --> 00:14:55,840
model if you're building a multi
tenant sauce app. 

305
00:14:56,280 --> 00:14:59,040
Specifically, instruct the tool 
to scan for tenant isolation 

306
00:14:59,040 --> 00:15:02,160
violations and you should run 
multiple passes with different 

307
00:15:02,160 --> 00:15:05,080
adversarial frames. 
Specificity dictates the depth 

308
00:15:05,080 --> 00:15:06,400
of the analysis. 
Exactly. 

309
00:15:06,440 --> 00:15:09,960
Run one pass looking for off 
bypasses another for injection. 

310
00:15:10,080 --> 00:15:13,640
Giving it that specific 
adversarial framing forces it to

311
00:15:13,640 --> 00:15:17,000
map the data flow from an 
attacker's perspective, which 

312
00:15:17,000 --> 00:15:19,080
drastically improves the signal 
quality. 

313
00:15:19,200 --> 00:15:22,040
And that brings the entire 
ecosystem full circle. 

314
00:15:22,040 --> 00:15:27,040
We are now relying on highly 
advanced, semantically aware AI 

315
00:15:27,320 --> 00:15:30,080
to act as the security guard 
against the mountain of code 

316
00:15:30,080 --> 00:15:33,800
being autonomously generated by 
other looping AI agents. 

317
00:15:33,800 --> 00:15:36,520
It is just a staggering 
landscape to look at from a 

318
00:15:36,520 --> 00:15:38,400
macro perspective. 
I mean, we've gone from the 

319
00:15:38,400 --> 00:15:41,360
macro level $60 billion 
boardroom battles over the 

320
00:15:41,360 --> 00:15:45,160
tooling harness to the comical 
reality of propping laptops open

321
00:15:45,160 --> 00:15:49,120
for agents, all the way to the 
culture wars over AI slop and 

322
00:15:49,120 --> 00:15:51,320
semantic security. 
It really leaves us with a 

323
00:15:51,320 --> 00:15:54,720
profound shift in what the 
day-to-day reality of software 

324
00:15:54,720 --> 00:15:56,440
engineering actually looks like 
now. 

325
00:15:56,480 --> 00:15:58,000
How so? 
Well, think about it. 

326
00:15:58,240 --> 00:16:01,520
If tools like cloud security are
capable of understanding the 

327
00:16:01,520 --> 00:16:05,360
semantic intent of an entire 
code base, and autonomous agents

328
00:16:05,360 --> 00:16:07,920
are looping in the cloud, 
writing the vast majority of the

329
00:16:07,920 --> 00:16:12,320
actual syntax, at what point 
does the human developer stop 

330
00:16:12,320 --> 00:16:15,560
functioning as a traditional 
programmer and start functioning

331
00:16:15,560 --> 00:16:17,960
more like a politician? 
A politician, right? 

332
00:16:18,120 --> 00:16:18,520
Right. 
Really. 

333
00:16:18,520 --> 00:16:20,680
Yeah. 
You're no longer writing manual 

334
00:16:20,680 --> 00:16:23,200
instructions. 
You are simply negotiating 

335
00:16:23,200 --> 00:16:27,400
intent with an army of machines.
You draft policies, you 

336
00:16:27,400 --> 00:16:30,000
establish threat models, You 
debate architecture with the 

337
00:16:30,000 --> 00:16:34,200
harness, but at the end of the 
day, you bear the ultimate legal

338
00:16:34,200 --> 00:16:37,960
and moral liability for the 
house those machines build. 

339
00:16:38,160 --> 00:16:40,640
You're just managing the 
apprentices and when the ceiling

340
00:16:40,640 --> 00:16:43,680
inevitably collapses, it's still
your name on the contract. 

341
00:16:43,720 --> 00:16:45,720
Exactly. 
That is a terrifying, A 

342
00:16:45,720 --> 00:16:48,200
fascinating place to leave it. 
Thank you for joining us on this

343
00:16:48,200 --> 00:16:50,080
deep dive. 
Keep questioning the tools you 

344
00:16:50,080 --> 00:16:52,800
use, keep defining those threat 
models, and we'll catch you next

345
00:16:52,800 --> 00:16:53,040
time.
