On-Demand Recording
Move from Proactive Defense
to Preemptive Resilience.
The full session from our June 18, 2026 virtual event — keynote from world-renowned ethical hacker FC aka Freakyclown, followed by a panel of AIPGC Consortium members on building trust in AI before deployment.
June 18, 2026
90 minutes
Keynote · Panel · Q&A
On-Demand
Keynote, Panel Discussion & Q&A · AIPGC Virtual Event · June 18, 2026

Keynote Speaker
FC aka Freakyclown
Co-founder, Cygenta · Former Head of Offensive Cyber Research, Raytheon
FC is a world-renowned ethical hacker, social engineer, and bestselling author of How I Rob Banks. With over 30 years’ experience, he has helped banks, governments, and global organizations uncover vulnerabilities by thinking like an adversary.
FC brings deep insight into how nation-states and sophisticated attackers operate — and how to defend against them. Known for his engaging, story-driven style, he blends real-world exploits with practical lessons that challenge leaders to rethink security in today’s AI-driven threat landscape.
His talks offer a rare, inside-the-mind-of-a-hacker perspective, equipping executives and SOC teams to anticipate and outmaneuver modern cyber threats.
Bestselling Author
Ethical Hacker
30+ Years Experience
Full Transcript
Session Transcript
Complete verbatim transcript from the June 18 virtual event. Speaker names and organizations are listed on the left; their remarks on the right.
All right. Good morning, everyone, and welcome. I’m Mina Chan, President of C-Vision International. And on behalf of C-Vision and our partner SimSpace, thank you for joining us today. Before we get started, just a few housekeeping items. Please keep yourself muted during the presentations to ensure the best experience for everyone. We do encourage your questions and comments throughout the session. Simply drop them into the chat, and we’ll address as many as we can during our live Q&A at the end. Today’s discussion is focused on one of the biggest challenges facing security leaders: building confidence in AI, while staying ahead of an increasingly sophisticated threat landscape. We hope you’ll take this opportunity to engage with your peers, share your perspectives, and leave with practical insights. Without further ado, it is my pleasure to introduce our host for today’s event, the CEO of SimSpace, Peter Lee.
Thank you, Mina. Hi, I’m Peter Lee, the CEO of SimSpace. A quick word on SimSpace: we pioneered the concept of a cyber simulation platform that digitally mirrors every facet of production environments to help security teams detect and contain full kill chain attacks that are hidden in realistic user traffic. Today’s event is going to begin with a keynote from our guest speaker and renowned ethical hacker, Freaky Clown, he’s also known as FC. And then I will moderate a six-person panel of cybersecurity experts that are the first wave of the newly formed AI Proving Grounds Consortium.
This consortium is designed to help executives across the C suite, AI innovation architecture, and security teams navigate the evolving cyber landscape, build trust in AI, and level in an increasingly asymmetric threat environment. All of the AI Proving Grounds Consortium partners, and likely everyone who’s involved today on this call, recognize that AI is already being weaponized, and that traditional defensive approaches are insufficient to meet this transformational challenge. As we enter an era of autonomous AI-fueled attacks, it’s imperative to operationalize AI-driven defenses quickly, and that we do so with the confidence, trust, governance, and appropriate human involvement needed to preemptively stay ahead of emerging threats.
So, the panel is going to include Greg Bell, the co-founder and Chief Strategy Officer of Corelight, Marc Brown, VP Product and Sales of Scythe, Eric Clopper, Director of Cyber Ops and Effects at MITRE, Josh Devon, the co-founder and CEO of Sondera, and Patrick Duffy, the Director of Product of Dropzone AI. FC is the co-founder of Cygenta, and he’s the former head of offensive cyber research at Raytheon. He’s got more than three decades of experience as an ethical hacker and social engineer. He’s helped some of the world’s largest organizations uncover vulnerabilities by thinking like an adversary. He’s a best-selling author and an internationally recognized cyber expert. FC, over to you.
There we go. The hacker managed to get his mic working. So, good morning everyone. Thanks for joining us. I remember in my 20s doing some work at what was to be the latest and best nuclear power reactor in the UK, a place called Sizewell B, and it gave me some interesting insights into procedures and safety. About a year before it reached criticality, I was given the opportunity to gain a certificate in the safe handling of uranium fuel rods using a robotic arm system — something I’m very pleased to say I have never had to use once in my life — but the course was really intensive, and it was full of procedures and systems in case things went wrong, and it’s almost impossible to fail, because those procedures were designed to fail safely. So, like most of you, I’ve heard the saying that data is the new oil, and today I think, well, I believe that AI is the new uranium, and which should be handled safely and with the processes and understanding that that type of really devastating power deserves.
So, before we start, I really want to start by building a foundation. Building a foundation is key to anything, whether it’s knowledge, whether it’s friendship, whether it’s a castle in the swamp. There was a saying we used to have when I worked at Raytheon, that a missile knows where it is at all times, and it knows this because it knows where it isn’t, and we are very much no longer before AI-enabled attacks. A statement of where we are right now is that AI-backed attacks are greater than ever; literally every attack is using AI in some form, no matter how small it is. Guard rails are not enough anymore. Now it’s what we call the diffusion of knowledge, where there was once a barrier, but now it’s broken. The defenders are sticking with current public models with zero to no fine tuning, when they need to be tuning them to their networks and their specific sectors. As with most technological leaps, it becomes less about the accuracy and more about the scale.
Nowadays you can leverage AI to enable one person to attack several things in one day. The real hindrance to all of this, the multiplication of force, is really bounded only by money. So, one thing I’ve noticed over the 35 years of working in this field is that it’s become really clear that this is a cat-and-mouse game. One side innovates, the other one tries to catch up. The trouble is the defenders often lag behind because of legislation, red tape, and the busy work. They’re not solely focused on developing better defenses, whereas the attackers are always trying to innovate. What we often see in some companies is the assumption that they need more and more logs — the trouble is, more is not always better. This leads to fatigue, burnout, and complexity without clarity. With the invention of AI, I believe this is the first time that a huge innovation has been given to both the attackers and defenders at the same time.
When steam engines first came about, some innovative factories moved from a paddle wheel system to a steam engine and found no increase in productivity. It was only years later that some factories realized that their machines didn’t need to be huddled around a belt system — they could have a smaller, simpler engine for that particular machine. This realization allowed them to redesign the whole factory, and only then did they get the productivity increases. I believe we can learn from history and start working out how each unit in our organization can have its own smaller, more relevant AI system. Each day there is a new model introduced, and every day the chance of defending your network against new zero-day attacks is reducing. This isn’t a sky-is-falling thing — I want you to see this as a wake-up call, especially to those who think we’ve got a few years before this really starts to impact us.
A good way of looking at this is that the military has not replaced soldiers with computers. They are building additional assets to help people carry out their missions, or in some cases to remove them from harm’s way, but the goal is not to replace them entirely. Humans are incredibly powerful, and we will remain more powerful than AI for some time. I think the best possible use case for AI is to empower your current working staff — to use AI to make them superhuman, not to replace them, to remove the cognitive load of these huge tasks that they’re now being asked to undertake. Humans should always be in the loop, no matter what it is. It is one of the biggest, most critical steps you can add to any process.
I think the best way forward is to think of AI not as artificial intelligence, but augmented intelligence. The best news I can give you right now is that everyone, both attackers and defenders, are all struggling with creating fully automatic flows that work consistently across different environments. The nuances of every system and how it’s interconnected, especially within unique business workflows, means that it’s rarely the same between companies. Experience is what delineates a good hacker from a newcomer. Thankfully for us right now, AI can’t make a decisive leap of imagination when looking at a business workflow or figure out a new novel approach. It has to look up stuff it’s done before. But this is coming — we are getting closer and closer.
Some flows are able to be automated. I myself have built tools that reduce some of my work hours from 40 hours to four minutes — that’s a huge gain. I’ll give you a quick story: I have on my laptop an AI model that runs specific jobs every day. Whilst I was away it couldn’t run a specific repeating job, and it came up entirely on its own with a solution — it connected to hotel Wi-Fi, discovered it was behind a paywall, scanned the website, found an API, and found a free service that was not officially offered. I stepped in and stopped it because I don’t know the legalities. The point is: it’s not a solution-driven or methodology-driven system anymore — it’s going to be a goal-oriented system. I had no clue it was going to try to get around that paywall. Understanding what our AI systems will be doing, and how they’re going to be reacting, is going to be key.
Maybe you’ve set up your AI system to look out for vulnerabilities present in your system, identify some vector where an attacker can breach, and then read your customer databases. However, you gave it a direct directive to protect the leaking of any private data. It doesn’t take a lot of thinking — that AI system can come up with the obvious conclusion that the fastest way to achieve its goal is to delete the customer database. If you don’t have a database, it can’t leak. That may sound like a joke, but in the last month I know at least three people personally that have had a similar instance to this, and unfortunately only two of them have backups. That’s the sort of unpredictable behavior from those systems that we need to start to understand to a degree of certainty that allows everyone to be comfortable with their deployment.
I am not advocating that we do preemptive strikes against unknown enemies. Attribution is one of the hardest problems in cybersecurity. When I was the head of cyber research for Raytheon, our goal was not widespread damage — we had a much harder task of minimizing collateral damage. If you look at the NotPetya cyber attack against Ukraine, that was a blunt instrument, and its collateral damage was far-reaching, including taking out the global operations for the Danish logistics firm Maersk. You need to understand that within the context of AI — what is it going to do that you haven’t a clue about? Our best way forward is to be preemptive rather than reactive. We have to understand where and how the attacks will happen, what they will probably look like, and most importantly, how we can best use our defenses.
Resources are always limited in any company. It’s easy to think that the new flashy blinky box will save your company, but unless it’s configured and used in the best way, it can very quickly become its own vector. You need to corral AI, tune it to your needs and to your environment, and we need to start building systems that predict and prevent before the attack happens. In the next year or so we’ll see the end of this paddle-wheel defense strategy and the emergence of new ways to leverage AI — smaller, leaner, faster ways of empowering smaller and smaller tasks. The more you do those small tasks autonomously, the more you free up resources. We’ll have machines that are patching and preventing attacks as soon as news of some TTP or CVE is released. But as a great man once said in a comic book: with great power comes great responsibility — and that responsibility rests squarely on all of you to understand these systems and to know the only way to reliably do this is through what we call a cyber range.
A cyber range gives you the opportunity to practice — it gives you the space and the place to practice with everything until you’re so good, not just good enough, but so good that you cannot fail. You will never rise to the occasion. You will fall back to your training. The only way that you can do this is to adapt first, and adapt fast. Surround yourself with smart people, because you are the average of the five people you spend the most time with. And I think this translates perfectly into organizations as well — surround yourself with companies that are like-minded and pushing the envelope, and you’ll all get better for it. There’s no fate but what we make. So take the chance, make the choice, join us as we build this consortium together. Thank you very much, everybody.
FC, thank you for reassuring all of us that AI isn’t replacing us, at least today. You mentioned something I absolutely love — we need to be preemptive versus reactive. I think you couldn’t be more accurate there. Now, to keep the conversation going, I would like to reintroduce Peter Lee, who will be leading our next panel.
Okay, thanks, Mina and FC. What we wanted to do is have FC talk very broadly about the agentic security future, and I think we agreed as a panel that it would be helpful to have one specific example of an autonomous adversarial attack to weave throughout the panel as a common thread. What you see on this slide is an example from a team of researchers at the University of Toronto who have demonstrated an entirely new class of cyber threat — an agentic worm that gives hackers more power and reach at far less cost. It can be built with free open-source AI models. Every online device is a potential target, and current cyber defenses are not yet ready for it. Polymorphic malware already exists, but agentic worms are a fundamentally new class of cybersecurity threat, because they can digest exposed information at each stage of the breach and use autonomous reasoning to devise target-specific and novel strategies for further attacks. Each compromised machine becomes part of the worm’s own infrastructure. To put this in perspective, the Wannacry worm in 2017 disrupted critical infrastructure across 150 countries by exploiting a single vulnerability. This new adaptive worm cannot be stopped in that fashion — it uses a recursive reasoning loop to detect and exploit diverse vulnerabilities as it propagates, without needing to communicate back with the attacker.
Yeah, thanks, Peter. I lead product at Dropzone, and I’ve spent my career building security products really focused on closing the gap between security signal and analyst action. The capacity problem in the SOC isn’t theoretical for me. Dropzone is building what we call the AI SOC team — a governed execution layer that takes security signals and turns them into completed, evidence-backed investigations under customer-defined strategy and control. The average enterprise SOC is drowning: analysts are triaging hundreds of alerts a day, most of which turn out to be nothing, but they can’t ignore them. That work is repetitive, evidence gathering is heavy, and very cognitively exhausting. What we’re doing is running that investigation work autonomously — pulling the telemetry, querying data sources, reasoning through evidence, and producing a completed investigation with a conclusion and the evidence trail that supports it. The most important word there is governance — having the humans in the right places to define the strategy, the authorization boundaries, and the control points. Every output is reviewable and contestable. We’re not asking anyone just to trust a score.
Patrick, in the context of this worm — you’re taking burden off the SOC team through detecting signal through the noise. How do you think the Dropzone capabilities really help the audience in this respect?
That’s actually a perfect illustration of why SOC capacity becomes a decisive variable in the next generation of attack. Traditional worms are bad, but they’re bounded — you find the vulnerability, patch it, stop the spread. The agentic worm doesn’t have that fixed exploit. It reasons its way through whatever environment it lands in, adapts to what it finds, and uses each compromised machine as the next attack. That patch-and-contain playbook just doesn’t apply. The signal volume becomes overwhelming almost immediately — you’re dealing with correlated suspicious activity firing across endpoint, network, telemetry, and cloud simultaneously, moving much faster than the human queue can drain. That’s exactly the scenario we’re building for. Our agents run those investigations in parallel and continuously without a human having to triage first. Every signal gets investigated, and each investigation produces completed work the analyst can act on immediately.
That’s great. Thank you. I want to flip from the defensive side to the offensive side of the equation, and I want to ask Marc. Marc, you come from Scythe, a well-established pioneer that allows organizations to simulate and defend against cyber attacks. Could you please say a few words about yourself and Scythe’s mission?
Good to meet everybody. Marc Brown, I lead the sales and product team here at Scythe. As you mentioned, Peter, Scythe is a testing platform at the simplest form — we provide organizations a way to emulate realistic threats within their environment, with two main benefits. Number one, giving them insights about potential exposures that could have impact in their business, but more importantly, helping them automate the controls for their defensive stack to make sure that what they believe they deployed is actually working as they expect.
There are two main things. What AI is bringing to the table is the ability to use Scythe in a broader set of organizations — you don’t need to have that deep red team skill, because now with AI we’re able to generate emulations from threat intelligence much more easily and much more quickly. Even Scythe labs that used to take 40 or 50 hours can do it in literally minutes now — we can ingest CTI, automatically generate the emulation, tune it, validate it, and run it. But getting to the worm: not only can attackers use this concept, but defenders can as well. We can actually provide intelligence inside the Scythe implant so it’s not running a specific scenario, but using AI to look for weaknesses that need to be corrected and fixed — a proactive approach where we can run multiple scenarios based on the environment the AI encounters, document vulnerabilities, and provide that insight back to the organization before they’re exploited.
Great. We’ve heard from the red and blue agentic side. I want to zoom out and help the audience think about some of the things we’ve been talking about as a consortium — some form of standardization around measurement. Eric, you’re the Director of Cyber Operations and Effects for MITRE, which is well known in the industry for both the Open MITRE Attack Framework and the cyber analytics repository. Could you please say a few words about yourself and MITRE’s mission, and talk a little bit about standard setting and how we evaluate this new agentic future?
MITRE is a nonprofit that operates federal research centers, and I oversee our technical capability in defensive CyberOps, offensive CyberOps, CTI, and digital investigation — including things like MITRE ATT&CK and Apache Caldera. We are definitely early in the hype cycle of autonomous cyber right now, which is why I think we’re all here learning from each other. Everyone knows they want AI, everyone knows we’re going to need AI, but nobody really knows what it’s going to get us. This proving ground has a terrific opportunity to come together and clearly articulate in a consistent way what different products can do and how they complement each other — so that people know what they’re getting. Those metrics shouldn’t be based on how cool everybody’s AI is; they should be based on how effectively the agents actually perform the mission. MITRE has been running attack evaluations of major EDR and MDR products for about a decade. Our evaluations come down to two primary metrics: did it detect the attacker, and did it mitigate the damage?
With defensive autonomous agents, those are still the primary metrics — can those agents do their jobs? — but we get some new secondary ones. How much human effort was required? What was the speed of action? Are we actually getting machine speed? Did it properly understand the scope of what it was trying to defend? False positives are a much bigger deal with autonomous agents — did it act at machine speed and scale, but do the wrong thing? That would be much worse. And how does it respond to deception — how easy is it to poison the model? For offensive agents, we need primary metrics focused on the mission: did it successfully establish persistence, did it do lateral movement, did it successfully exfiltrate? But then secondary metrics: if I tell my agent not to leak onto the internet or touch a certain resource, did it listen? Did it adapt well to changing environments? This team is blazing new ground, and I’m thrilled we can all come together to quantify how these metrics should change.
Yeah, that’s great, Eric. There are really two axes that MITRE and others are going to have to advise clients on: the functionality and capability axis, and then the degree of autonomy and trust and decisioning that’s actually taking place. I want to now direct our attention into the life cycle of agentic formation and adoption — how agents are trained and what are the preconditions for success. Greg, you’re the co-founder and chief strategy officer of Corelight, one of the pioneers in open network detection and response. Could you say a few words about yourself and the organization?
Sure. I spent most of my career in the federal space supporting very large science experiments and eventually running the global mission network for the Department of Energy’s National Laboratory System — a very cool job. After that I took a leap into startup life and became co-founder of Corelight. Corelight is an open-source company providing very high-quality, real-time data to the AI SOC, and our mission really is to democratize the tools and techniques that elite defenders have been using, so that more and more organizations can gain the benefit of them.
We’ve just actually published some brand-new research on this question. I would say, first of all, there is an inconvenient truth to consider: it really doesn’t matter how good our language models are if the data feeding them is deficient. Our research has shown that language models today are better than they were a few months ago — more reliable, more autonomous, they hallucinate far less — but we simply can’t say the same about the data sets our models have access to. Poor data sets create a very hard ceiling on the ability of agents to perform. Data can be deficient in two common ways: it’s too low resolution, like a fuzzy image when what we want is a sharp image; or it’s just not realistic enough — synthetic data is often highly simplified and idealized, but real-world environments are much weirder and more complex than we might expect. What’s needed for training agents is high-resolution data that’s as realistic as we can make it. In the world of security, it’s often challenging to extract highly realistic real-world data because it’s full of sensitive information. The next best thing is a really good emulation — a highly realistic emulation that captures the complexity of the real world in a controlled, repeatable environment.
That’s terrific, and I think it really sheds some light. I want to talk a little bit about the second phase of the agentic life cycle — we’ve talked with Greg about training of agents and the importance of high-fidelity telemetry. This has to be followed by testing and validating agents. I’d like to direct the question to Josh. You’re the co-founder and CEO of Sondera, advancing the notion of a control plane for this new agentic era. Maybe you could talk a little bit about your background and Sondera’s mission, and then let’s talk about how this plays out in the context of this adversarial environment — the worm.
Hey everyone. My early career was in counter-terrorism. I then co-founded a company called Flashpoint, which does threat intelligence, and I did that for about a decade. Now I’m focused on agent behavioral controls — how do we make the agents follow the rules? How do we make it easy to do that, and how do we have provable controls around the agents, not “prompt and pray,” where I put a rule in capital letters and hope the agent listens? What we do is a process called auto-formalization that allows us to take natural language and convert it into deterministic policy as code. We have a policy engine that works with neural classifiers, LLMs as judges, Yara rules, etc. Our early use cases are information flow control with coding agents — how do I make sure if my coding agent picks up sensitive information it doesn’t accidentally post it on Pastebin — and behavioral controls around red teaming. Our harness wraps around any agent and allows you to use natural language with a policy hierarchy, so I can give different rules for the same agent — my finance team with Claude Code gets different rules than my engineering team.
Right now we’re in a place where we’re kind of in human-in-the-loop, but we’re going to be soon in a place where human-in-the-loop isn’t really feasible. We see ourselves migrating to what we think of as human-on-the-loop — I need to orchestrate fleets of autonomous agents to respond to signals I’m getting. Whether I’m red-teaming something ahead of time to say “are we subject to this worm,” or delegating agents to go repair the things the worm is detecting at a very fast pace — faster than a human might do it — that’s going to require a lot of trust in the agents we’ll be using. Once you think about how you’re orchestrating all the agents in your organization in response to what you’re seeing, you need a layer that can govern across everything. Especially for multinational companies with different obligations in different places, having policy hierarchy and the auditability to show exactly what happened — what data was leaked, who had access rights at what time, can you piece together the whole chain if a lawyer comes and says “prove it” — all of that is going to be essential.
Great, thank you, Josh. FC — you’ve heard a little bit from the panelists. I’d love to have you give our audience some takeaways.
Yeah, thank you, Peter. I think really it’s been a powerful reminder that, like the missile, we know where we are now, because we know where we’re not, and we’re no longer in the era of static defenses. The capabilities presented — Dropzone’s machine-scale hunting, Scythe’s adversarial realism, MITRE’s standardization, Corelight and Sondera’s focus on telemetry and governance — they’re not just effective, they’re essential. My three key takeaways: first, speed is necessary, but context is king. Agents can now hunt at machine speed, but speed without understanding the business workflow needs leads to noise. Second, you cannot trust what you have not tested. Trust is earned through simulation — you can’t deploy autonomous agents into your production without first running them through vigorous adversarial environments. That brings us back to the importance of a cyber range. Practice until you cannot fail. Third, standardization is the only way to scale. We needed not just a common language, but common metrics. We can’t have a multi-agent future if every vendor speaks a different dialect of security. The consortium is the vehicle we need to build that common framework of trusted autonomy. There’s no fate but what we make.
I want to remind the audience: please do submit any questions in the webinar chat. I want to open it up to the panel on another dimension — we actually haven’t talked about the economics. How do we think about economics in terms of the line with human analysts reviewing the operation of these agentic tools? Where do we begin thinking about that crossover? Maybe Greg, we’ll hear from you to kick that off.
Yeah, I was chatting with our CFO about this recently. He’s involved in communities of CFOs, and there’s been a great whiplash in that community — from wanting to encourage active engagement with AI and let many flowers bloom, to a shock around token costs. That will lead right back pretty quickly to the question of metrics that FC and Eric highlighted. We’re going to need economic metrics too to help decide and fine-tune the trade-off between agentic automation and human effort, at a time when token costs and model capabilities are evolving really rapidly. That speaks to the need for a standard framework, a test harness to check into what those economics are, measure them, and report back on a regular basis — because they’re going to change every week.
The one-word answer is: No. I don’t think we have enough data at this point, and this points to what FC has been talking about — the importance of gathering that data, especially through simulation. If we are waiting for attacks to occur so that we can get information one event at a time, that’s way too slow for us to train our models. It’s when we can run those at machine speed, modeling an attack millions of times per day, that we can really learn quickly what they’re going to do, whether they’re going to escape the bounds we put them in, and whether we can actually trust them. We have to understand the risk to our businesses of trusting too early — and then the agent does something bad — versus the risk of trusting too late — and then we have a traditional cyber event that’s hurting us. We need to be working as quickly as we can to build that trust and that understanding.
This is something we have pretty common conversations with clients about: how do they move from point-in-time to continuous testing? Scythe helps organizations today integrate continuous testing into the defensive stack to ensure that the defenses are doing what they want on an ongoing basis. There are two elements: making sure you have a good simulation environment to try new things, but also in your production environment having the necessary tools always being validated — because there’s drift in environments, there are patches, and those things break what you’ve put in place.
As a pen tester over decades: there is a huge gap between a pen test and a vulnerability scan. You can automate vulnerability scans with AI, no problem. But a true pen test is always going to require a human in the loop, because we have to have that leap forward on business analysis. AI will never make pen testing cheaper — it will make vulnerability scanning cheaper. What it will do is augment the human doing the pen test, allowing us to have a bigger scope and do more things in the time we have. It’s not going to make it cheaper; it’s just going to make it bigger and more effective.
And I would just add: the flip side of this is, okay, so you detect a vulnerability — how do you know the problem you have? As someone at a bank told me, every one of my developers now has plausible deniability that they’re an insider — they can just say, how’d that end up in there? Oh, the AI hallucinated it, I must have missed it. In highly regulated enterprises, those issues really matter. One of the things we’re doing is understanding the whole provenance of how something ended up somewhere: what were all the steps? Who did what? Was it the human or the agent? All of that matters. You need to do both detection and provenance, but they’re complementary.
I use local AI more than I do any of the frontier models, and I think it comes down to what I was saying earlier about the steam engine model. There are some very capable models that you can run locally on very low-power machines that will do small automated tasks. I actually have on one of my machines a two-bit model — it’s tiny, but it does precisely what I need. I don’t need this frontier model to do everything. Look at local models, even Raspberry Pi — they’ve just come up with a new AI hat that has eight gig of RAM, and it can run some really sophisticated models already. We’re not going to always need the frontier models, and I think that’s one place economically we’ll be able to make huge leaps.
One thing I think is also important to call out here is making sure you’re having that big strategic conversation of knowing where you want to deploy the frontier models, where that’s most necessary, and where local or lesser models can absolutely do the job. One of the things I’m noticing in talking to customers and across the industry is that everyone is really focused on the tool and not having deep enough conversations on the strategy — and that is more important than how you’re going to deploy it in the first place.
This is also a key dimension of the economic piece — in many cases you can run a small open-weight model locally for very low cost versus dealing with a frontier model. Having the ability to almost have an intelligent gateway that will route the traffic based on the query needs is going to be important for organizations going forward.
There’s an analogy here to where Pixar was 30 years ago. Pixar had the goal of developing a full-length, completely computer-generated animated movie, but the company was created 10 years before that was technologically possible. They knew about Moore’s Law, they were watching what was happening in the industry, and they could plan out when they could do that first release, knowing that the technical capability was going to catch up with their vision. I think we’re going to see a lot of the same here — we’re relying on those cloud-hosted frontier models now, but we can map out how soon the locally hosted ones will continue to get better.
And I would just add: they’re coming to the edge, right? Samsung has a built-in chip, so as we think about attack surface, a lot of folks have deployed LLM gateways, but these things are at the endpoint now, and they’re only going to show up more. When your phone has an SLM on it and can access your Salesforce state, it doesn’t have to use any of your gateways. That’s one reason why we really deploy at the edge — because you have to be where the agent is. And they’re going to be everywhere. The open-source models right now are essentially the frontier models, just distilled a little bit. Maybe 90% is good, and that’s gonna be good for most people.
Okay, well — I want to share a couple of slides and some closing remarks. It’s apparent that all of us are on an AI transformation journey. Security teams are going to need to evolve quickly to embrace greater agentic functionality and autonomy as the scale of this threat grows, and that’s really why this consortium exists — we’re here to help you quickly build trust in AI, so you can confidently operationalize security agents in mission-critical workflows with human operators. I want to thank everyone for their time today. We hope you found this to be a valuable and productive discussion. Please use the link on screen to connect with the consortium members for any follow-up conversations. We have our next virtual event on July 29, featuring Allie Mellen, Principal Analyst at Forrester Security Research. We’re also going to be live streaming a fireside chat from Black Hat during the first week of August, and planning a third virtual event with Gartner for early September. We look forward to seeing everybody on more of these discussions. Please find all information on our website, AIPGC.ai. Thank you to the panelists for some really great, insightful discussion.