Super Intelligence, Artificial Slowdown
The labs say they want to pace the frontier. Then they ship new models and cut prices ten days later. Is "slow down" a safety commitment, marketing, or regulatory capture? The EU Cyber Resilience Act starts a 24-hour clock for reporting exploited vulnerabilities, and the bigger requirements land in December 2027. AWS open-sources Pizza Bot, an inbox for background agents, in a year where everything is suddenly a harness. And newcomer Ken Collins on building AI-native teams when anyone can vibe code something that looks finished. Burst Mode covers Aurora DSQL finally getting foreign key constraints, Jev and Laya making decisions instead of generating text, AI deciding which forgotten cloud resources to turn off, and AWS confirming permanent customer data loss in Bahrain and the UAE.
- Pacing the frontier (CNBC)
- David Sacks on slowing down
- Labs sued over pacing AI development (Politico)
- EU Cyber Resilience Act reporting clock (The Register)
- EU Commission CRA reporting
- OpenSSF CRA ebook
- Pizza Bot
- Pizza Bot on GitHub
- Anthropic labor market research
- Microsoft ports Copilot runtime to Rust (The Register)
- Aurora DSQL foreign key constraints
- Jev
- Laya (Hugging Face)
- Laya on Hacker News
- AWS spend limits
- AWS Middle East data loss (CNBC)
- AWS Middle East data loss (Reuters)
- Wildberries Architected Framework
- fwd:cloudsec
Transcript
Hi everyone and welcome to Yells at Cloud, this time brought to you by super intelligence! That's right, that is what we're calling it now.
But
It sounded too
Wait here.
fake to say artificial and apparently it is official now. Super intelligence. My name is Gunnar Grosch and I am joined this time by Danielle Heberling, Chris Farris and newcomer Ken Collins. Welcome all!
Thanks y'all.
So,
Well Ken
Ken, the newcomer, then what can you tell us about yourself that people wouldn't find if they check out your LinkedIn?
So something that they wouldn't normally know, especially
Yeah!
Like your password, your you know, first pet, your last
You
word, your social, and it will take any.
Well,
also I use LinkedIn
very inappropriately like Chris Williams does and post everything on there. Yeah,
Passwords?
Okay.
well, let's see, the thing that I've been doing that's not technical is I've been really vibing out my carport lately. So I live in the Virginia Beach area of Virginia. Things are starting to get cold around here. We're kind of in between seasons, about ready to go into fall. And I've just been creating a garden room in my carport. So once I'm done through working with AI,
In the indoors, I try to work with AI on the outdoors and amongst plants and stuff. And I've been setting up these nice 100 year old church windows that I bought in an antique store that were from an 1890s church in rural North Carolina. So I've just been building out these beautiful vibes outside, beautiful outdoors, and just trying to connect with the crickets and the birds and all the lovely animals and stuff like that while still doing AI work.
That's amazing. That's... Yeah. Now I almost feel bad for only doing AI work, I guess.
Ha ha ha!
Huh.
Yeah, it's like Rocket on Of
Old school swarms.
course
Danielle, you've recently been to Europe. What was your key takeaway from visiting Europe?
Yeah, that's a big question. For me, I personally really like the public transit. We have good public transit in Portland by American standards, but compared to Berlin, like it was pretty abysmal. And I kind of turned to my husband and said, you know, this is what it might be like if we're allowed to have nice things.
One of these days maybe.
I hope, yeah.
And the ironic thing
is if you talk to the Berliners, they think their public transit is a mess. So, you know, it's like
Yeah.
you have no idea how bad it can be. Yes.
Yeah, way
better than I mean, yeah. I lived in New York City for a while. New York was decent, but yeah, way better in Berlin.
Chris, I believe you attended fwd:cloudsec recently?
Did yes. London.
What happened there?
What happened there? I don't know. I was too busy doing hallway con to attend any of the talks, but they are all now on YouTube, so if you Google or go to fwdcloudsec.org, you'll get a link to them. But I think the thing that I was noticing this morning as I was going back through was actually how many sovereign cloud talks there were
Mm-hmm.
about
You know, not necessarily EU sovereign or AWS's EU sovereign cloud, but about the STACKITs and the OVHs and all of that. So yeah, wanna go back through and finish listening to all of those. But the sovereign cloud thing was definitely a topic of interest at fwd:cloudsec
That's... Yeah, it's a topic I hear a lot about at conferences as well, so... I think it's something we'll probably come back to a lot more in this show as well. Alright, everyone, we as usual have a lot to cover, and I promise there's gonna be AI, but there's also gonna be other things, so don't you worry. But we're gonna jump into the first topic, and this one... We're gonna do it a bit different than what we usually do. A couple of weeks ago, Anthropic's
Dario Amodei, he laid out a plan to pace the frontier. That was his phrase. So while safety and oversight catch up to the frontier, they want to have independent evaluators embedded in the labs, coordinated standards across frontier labs in what he said, the democratic countries, and then also international agreements on the most dangerous capabilities. I think what was perhaps the surprising part was that
Sam Altman said that OpenAI would match that independent evaluator commitment, and even Elon Musk publicly agreed with Amodei. So the three people with, I guess, the most gain from moving fast all said kind of slow down. And honestly, I want to believe this. I've just seen this movie before. The model, some model, is described as too dangerous to release.
The warning then generates enormous coverage and then a version of that model ships anyway. But before I give my take on this, I want us to go around the table. So Danielle, I want to start off with you. When you hear one of these labs say that they want to pace the frontier, does your gut say genuine safety commitment? Is this frontier model marketing or is it just companies trying to write the rules before regulators do?
Yeah, to me it feels like a mix of trying to write the regulations before the regulators do and also marketing. It feels kind of similar to like Facebook when Mark Zuckerberg had to go testify in front of the US Congress about the dangers of social media, and then it turned into, we don't know how to regulate this. And then he's like, you can ask me and I can help you write the regulations.
This seemed kind of similar but slightly different. But yeah, that's mostly my take. I have yet to see like an actual commitment of like here's what we're going to do. It's all just kind of talk and conjecture.
Chris, you're the security brain on this panel. What's your take on it?
Well, first of all, is we're not worried about AI anymore. AI was thrown into Lake America and it's now super intelligence that we have to worry about, right?
Mm-hmm.
And you know, honestly, I disagree that it's an attempt by the models to try and regulate themselves because let's face it, this US government is not gonna regulate a damn thing. I think it's a little bit more of
a you know, we're not seeing the uptick, we're not seeing the valuations. So let's put this safety stop in place so that we then have an excuse for holding off on our IPOs, and thus maybe we can prevent the entire economic house of cards from crashing, destroying the US economy and wiping trillions and trillions of dollars off of everybody's net worth.
You know, really what they need to be doing is, you know, the frontier labs need to slow down so they can learn how to do basic security. Because, you know, if we go back to the first thing, Hugging Face, it was like they didn't even have a damn firewall in place to keep the things in. You know, so and they and they certainly weren't watching the models do their thing and like look at their
Whatever it's called, their chain of thought processing.
Alright, so Ken, Danielle thinks it's a mix of marketing and perhaps writing the rules before regulators do. Chris thinks it's capitalism at play, basically. What's your take, Ken?
And
it's both, right? Like, so the regulatory capture has been the business model for a long time. You just haven't seen it as long, right? So even when Meta, released Llama in the, particular runtime, right? There was a very big emphasis on the governance aspect of it. And if they can lock that in, then that's the business side of it. Right? So the regulatory capture isn't necessarily about safety. It's about like, how do you kind of stifle consumer choice? How do you,
to Chris's point, like the economics of AI, although I'm not like very much into like an economics professor or business, but it's easy to do the math and see where things are not lining up. The, so regulatory capture has always made sense as a way to kind of shore up the business model, right? If you can say only these companies can provide AI and it only must run on inference and their end where their guardrails can kick in and their inference platforms do the work for you, then
they get a, of course they're not gonna be able to guarantee that, Like you're not gonna be able, no amount of guardrails is gonna stop AI from going to a certain point and going, I can't do that. Well, maybe I can do this, right? It wants to make you happy. And if you're not watching, not necessarily the chain of thought, but the tool calls when they pivot to do the, well, let me just go out and break into this computer because that's really what you wanted me to do. Or that's the only way I know how to go about doing the request for you. I think there's a great
story like I was a video I was watching where it's like okay here's this alien and I've asked this alien to like do this one thing and they don't know the context right like make a sandwich right I think what is that old adage where it's like make a peanut butter and jelly sandwich break it down for me how do you make it right AI is just going to you know go grab somebody else's bread grab somebody else's peanut butter and it's just going to do what you've asked it to do and yeah so I think it's regulatory capture is what I think is always the game.
Yeah, where I land is basically all of the above. I think
Mm-hmm.
it's a mix of all of this. I don't think they're sincere though in any of this.
Mm-mm.
If there's one thing I believe is that I don't trust any of them, honestly. I think it's doing a few different things. I think it is marketing it because all of a sudden they get all of this buzz around it again. It's hard in the AI landscape to get that buzz, but they were able to capture the headlines for a while.
But I also think it's partly about regulation and no, I also don't think that the US government as of now is going to do much. I do think that the EU could do things though, and that could still create problems for these labs. But what's so funny about a lot of this as well is also, I think it took, what's it, a week, 10 days before all three of them shipped new models as well, and they cut prices.
Mm-hmm.
So they kind of...
talking about setting some sort of threshold, but then they just keep going. And I think this plays into what the White House said as well. I think David Sacks, I don't know exactly what his title
What?
is, some sort of AI czar or something for the White House. He said that if you're so worried, just stop. You don't need anyone's permission to slow down. So I think that to your point, Chris, yeah, they're not gonna...
regulate them in any way, but at the same time they're leaving it up to the companies to slow down
Well
if that is what they want.
and there's antitrust concerns with the three of them collaborating on a slowdown that isn't
Yeah.
like agreed upon.
Mm-hmm.
And I even saw a headline, I didn't click past it, that like there's now a lawsuit about the slowdown on antitrust
Mm-hmm.
grounds.
Yeah, exactly. And then obviously the interesting part about all of this, since Amodei also talked about democratic countries, I don't think it's super hard to realize what countries he's talking about that wouldn't be part of this slowdown. So... Sorry.
One he's in. The one he's in.
Well, I think that's a later topic. That's the...
the extra bonus part of this show where we discuss that but no I think obviously that China and the models coming out of China now are a threat so how does that play into to this thing?
The genie is out of the bottle the bell has been rung even if they say slow down nobody else is
Yeah.
Yeah.
Well, and as I've explained to a number of folks and clients, the threat is more where inference happens in China, because then you're sending your data to them where they have control. And it's less about the actual models. Yeah, there have been a couple studies that say if you're writing an iOS app for Falun Gong or whatever, that
There's a statistically more likely chance it's gonna introduce a vulnerability than if you're writing something that isn't related to one of the forbidden topics. But I think for most companies that's irrelevant. For all we know that, you know, there's
similar reinforced learning baked into the US models. And yeah, the threat of the Chinese open weight models is that people are going to realize they're just as good and a hell of a lot cheaper than Altman and Dario's models. And
Yeah.
they're not going to produce CSAM like Elon's. So, you know.
Well, I don't think they're seeing the European model as a threat at this point, at least. I think Mistral is still around, right?
Mistral is still around, you know, and it's definitely a tier three model. It's from what I've read is, you know, several months behind the frontier as opposed to like China, which is like considered several weeks behind.
All right, so then the labs are proposing voluntary rules written by the labs and checked
by people that the labs pay. As I mentioned, European Union though, could potentially do something and right now they've made a piece of a thing mandatory. And the clock, I think it started last week or two weeks ago, Chris, tell us what changed on September 11th.
Yes.
So yeah, the Cyber Resilience Act is now in effect partially in the in the EU, but it applies to everyone everywhere who is shipping or placing a product on the European market. So what is the Cyber Resilience Act about? Well, it's actually about, you know, creating secure products, which clearly what the model makers are not doing right now.
And the piece that just went into effect, yeah, about two weeks ago now was if you are aware of an exploited, actively exploited vulnerability, you have 24 hours to notify ENISA, the
main cybersecurity organization for Europe, that hey, yeah, we could potentially be vulnerable. So if you know something drops on late Friday night, you have until Saturday to actually file it. This isn't business hours, this isn't like confirmed. It's like once you're aware, you need to, you know, start the notification. And then 72 hours later you need to follow up with a this is what we know. And
Here's a you know more in-depth analysis, including, you know, what you're gonna do about it. That's what's in effect now. What's coming is even worse. All products on the EU market are going to need to have actual secure by design
Built into them. And that means like, hey, you have to have threat models and you have to document your threat models, and you have to hold on to those threat models in case the regulators ask for them. You have to patch vulnerabilities in your systems without undue delay, which I have yet to find a lawyer who's defined what without undue delay means. So they mostly have just fallen back to have a vulnerability management standard and document
your SLA, you know, your remediation guidelines are. Like, okay, I can do that. Yeah.
So it's better for the consumer, but let's face it, right, who here is patching all of their vulnerabilities without undue delay?
Maybe if you're in the government or bank, but probably everybody else is not. So it's gonna add a lot more work to everybody's thing. And then there's more paperwork. You have to maintain an SBOM, a software bill of materials. So what goes into the package, what versions it is, and, you know, for certain applications you'll even have to have somebody who signs off on a declaration
of conformity. So this goes back to a couple of things that have happened with cybersecurity in the US where executives like CISOs have signed documents that were not true and have been prosecuted or harassed legally. So you know there is personal liability risk now for practitioners and executives around this
Alright, so let me paint a picture then. You build an app, you're using TypeScript like a sane person, you have 500 packages, NPM packages installed, also kind of normal, and one of them has a CVE. Does that apply to me then? 24 hours?
if that TypeScript app so what's interesting is, the way my lawyers have described it to me, it's a product placed on the market, which means if it's just a SaaS system, that doesn't count. But if there's an app like Swift or Android or whatever that you are actually shipping to somebody, then it does.
So product in this case means something like literally that you're shipping that software as a product.
And so software is a product, so if you ship an app and it's you know got some front end pieces and a bunch of back-end requirements, the whole back end system is in scope. So you have to patch that without undue delay too.
Alright, so is AI the solution to this then? Just get Mythos or something to constantly fix everything.
AI might be the solution if you've got a system that is reasonably you know, doesn't have tech debt. I often talk about tech debt being the bane of AI because it just makes it that much harder for the models to reason over and understand what the actual implications are gonna be.
AI can probably help you. I mean, I'm planning to vibe code up a number of things that are gonna be like, here's my SBOMs and I drop them in an S3 bucket and they'll stay there till the end of time. Because that's what happens when you put an object in S3. You know, maybe. And then you know, so I'll vibe code the collection of SBOMs using AWS Inspector or something. But
I don't think AI is the solution to getting your developers to patch everything. Because we learned in the early 90s from Microsoft, thank you, that patching breaks things. And this is how you end up with blue screens of death. And so, ever since then, thanks to Microsoft, everybody is terrified of patching and updating.
Yeah. And the fines are pretty hefty here as well. Kind of looks modeled on GDPR.
It is modeled on GDPR. I think it's actually it I think the percentage of global revenue is less, but the minimum fine is pretty high too. It's like 12 million or something. So and there are actually even if you're an open source software developer, there are requirements in the CRA that apply to you.
So as a board member and an officer of fwd:cloudsec, we have some open source projects and I'm actually now tracking what I need to do for the December 2027 request.
Which, by the way, all of this, the reporting piece happened last week. All of this other stuff that I'm talking about, patching without undue delay, software bill of materials, all of this is a December 2027 deadline. So it's fall, and everybody's probably putting together their budgets for next year. So now's a good time to be like, hey, maybe we need to add another product security engineer to deal with the CRA nonsense. Here's your takeaway.
Yeah,
this is going to be fun for the five person startup companies that has the same
Yeah.
regulatory requirements as the big enterprises.
Yeah.
And there's no you're so small it doesn't impact you like requirement. It is a you know, if you put a product on the market in the European Union, it has to be secure. Or it has to follow these
Well that was something.
guidelines. These guidelines don't necessarily mean that it's secure, but yeah.
That was an uplifting story, Chris. Thank you for bringing that to our
Hahaha!
attention.
Ha ha ha!
So I think a lot of that compliance and comes down to knowing what is in that software supply chain and being able to then react fast to it. And I think that raises a question in the year we're in, the year of 2026, what happens when that newest member of the supply chain is an agent? Because that's kind of what...
Everyone I'm seeing on LinkedIn at least is saying that they're shipping stuff so fast. And Danielle, you've been looking into some of these latest agents that we've seen.
Yes, yeah, that's a great transition. So I think it was maybe a week or so ago. I don't really know what day it is. AWS open sourced this thing called Pizza Bot and I saw the link in my RSS feed and at first like I was like Pizza Bot? Like what the heck is this? This is like such a weird name. So then I started looking into it and effectively oddly enough they're not calling it a harness.
Harness is nowhere in the announcement post, but they're referring to it as like an application to manage multiple agents. And looking at the screenshots of it, it looks to be very inspired by an email inbox. So I guess the idea is you have multiple background agents running, and you need to be able to keep track of them. And the idea is
You're not sitting there staring at them. So like you can kick them off, you can go off and do your thing, come back, and then there's this nice clean inbox for, you know, this is done, this needs attention. And I believe there was a third one. But I think just at a higher level, not so much about Pizza Bot, but just I think with AWS and maybe even in the AI world, it seems like, you know, one month ago everything was an agent. Now everything seems to be a harness.
Mm-hmm.
And sometimes the definition of what a harness even is differs. And yeah, it's just not so much to exactly diss this Pizza Bot thing, but it's just confusing because there's so many different things that are coming out constantly. And like if I want an application that can manage multiple agents in the background, like I have no idea which one to pick.
'Cause there are a bunch. And AWS alone has this Pizza Bot thing. They've got the Kiro Crew. They've got Strands Harness now. So
Mm-hmm.
it's
Yeah.
like I don't really know which one's the best to pick. But also too, I'm not sure I would necessarily pick Pizza Bot because well, I know the name is weird, but
for folks who may not be aware, I believe the name comes from like the concept of two pizza teams, like that Jeff Bezos thing of you know, smaller teams. You can only have a team that can consume two pizzas. It can't get any bigger than that. That's where that comes from. But yeah, I'm not sure I would use it just because it's very clearly written. You know, this is an open source project.
If you want to continue using this, like this the stability of this very much relies on, you know, people volunteering their time to commit to this. And kudos to them for making that like super clear. But at the same time, like I'm not sure I would want to use something like that. So, but maybe just me.
I don't think it's just you. But to your point about the number of these agents, harnesses, whatever they're even called this week, it's just a new one every week, if not every day.
No.
I mean I
Gotta get with the times, man.
looked at OpenClaw and was like, no, like they're creating their own social network. This is stupid. This is a waste of polar bears. But yes.
I've always found it fascinating that
so many people in the AI world tend to look at like The Sims or just like to play out these sort of role persona games with things. Like the, what was it? CrewAI never really got into it because all the orchestration was kind of centered around like replicating people and making them talk together versus, you know, automating workflows.
Yeah, I think we'll continue seeing this. I honestly don't see an end to it either at this point. There will be a mix of these open source ones and then proprietary ones as well. And yeah, it'll just continue.
It's almost like the harness is going to be the new Simon Wardley below the waterline serverless, right? Like it's going to be the thing that's incredibly important, like maybe a K8s orchestrator, or this thing that maybe needs to be standardized, it's critically important, but ultimately we don't care about it. We care about the work that we kind of work underneath it.
Yeah. But I would argue that the harness is probably more important and where you're gonna invest more of your time than the model itself. Right? The model
Hmm.
can be swapped out underneath the harness, but the harness is what I'm like engineering towards. The harness is what I am building my workflows around. So, right, like yes, right now it's Claude Code, but I could probably just as easily run Claude Code against an OpenAI model.
If I could, you know, trick it into doing so. Yeah, there's
Which you can.
You can. Yeah, via a proxy.
Yeah, I can do that.
ways to do it, I just haven't figured it out yet.
Alright, so we're doing a lot of the work and putting it to agents and in this case I guess putting like an inbox on top of it right with Pizza Bot. I guess the question is what all of this then does to the people that are doing the work and Ken I think you have some thoughts around building these kind of teams these days?
Right. And I will say you are the master Gunnar of segues, right? So really well done. I
Thank you.
don't know if we intentionally did this or not, but our topics are really stacking well together. And I think an area that I tend to spend a lot of time thinking about is what does it mean for the humans that sit with these agents and coordinate the work, right? So the, was maybe about.
It feels like maybe four months ago where Anthropic did this really big release on the labor market research, right? What is really going to happen with humans in the loop or ones that are not on what the future of work is really going to look like. And they did this incredibly good spider graph of here's the potential of AI in various industries and roles. And they measured it to the task, right? So if there was a particular unit of work that needed to be done,
What was the potential for AI to do this work versus the realized and various like interviews and things with their clients today? And the, obviously like there was like 80% in some areas less than others, right? Like if you're working in construction, AI is not drastically gonna change your role or restaurant services or other things like that for a while until like those weird bots come out. But like for knowledge workers, right? And for businesses, which we...
probably all four of us sit in where there's large companies that are doing work. It kind of begs that question, right? And so one of the things I've been thinking about is like, what are the different types of companies? So there are some companies that you can describe as tacit knowledge organizations. These are companies that have humans doing things that are highly collaborative. It might not be a rigid process that's well coordinated, right? So a good example of that would be if you go every morning myself to Starbucks.
Right, and you go look at that Starbucks, those humans are highly coordinated. They know exactly what they're doing. They're working in a team and the process is well defined. There are large amounts of companies that are very tacit knowledge and they really don't know what the humans are doing at any given time or how the work is outputting.
So you take these things like AI agents, which can do work and move the human at different parts of the loop. And then you kind of beg these questions of like, what does it really mean? Right? Like, how are these people going to do their work? How many people do you need to do the work now if AI is in the mix? And then if you're building products and delivering technical delivery, what does it mean for the way that you build software, ship software?
It's a really fascinating topic. And I think there's a, there's one that I like to talk into, which is the concept of role compression. Right. So me, myself, a little bit of background, you know, I used to be a graphic artist. I used to be a marketing director. Only at the tender age of 35 did I start going out and learning how to program, you know, did, an amazing, like 15 years stint, became an AWS hero, like a lot of us in this room. And then, but now I'm like a product guy.
Right? So I'm orchestrating and building teams to deliver software. So the things that I think are incredibly interesting are what are the skills that people need to have in these new roles to deliver software faster, but not just because it's faster because it's taking up work that was kind of hard to do or cumbersome and, you know, like a pull request or an idea, to get a feature out would have to go through these lead and cycle times and you would measure them in months in cases, sometimes quarters.
And now you're able to kind of drastically change that. And once you can deliver software that fast, how does that affect the business leaders that normally wait three to six months to ship software and how they work in their day? And it's an incredible amount of change that I don't think we talk enough about.
I think something that I've seen a bit recently is more and more of these stories where they're actually putting a dollar amount on the AI work. I saw there was something from Microsoft. They ported Copilot to Rust and now they have a dollar amount. What that cost them, I think it was $120,000 or something, which is super concrete.
So take
your FTE cost and then you translate it to like, yeah, so when we do, in our team, when we do our budgeting for the people, we budget for people and AI at the same time.
Mm-hmm.
Yeah, exactly. And now with the AI use we have, we're able to do that more and more and actually start, I guess, making sense of the things we've just been guessing for a couple of years now.
Right, the area that I've been focusing on over the past, say, three months is reporting. Right, so often a lot of times the data to surface to make business decisions has been kind of either tucked away or never at all. In tacit knowledge organizations it might not ever be surfaced at all, right? People are, you know, making decisions off of like, you know, decades of experience and stuff. So I've been focusing a lot on how to bring data,
actionable sort of data, of course, using AI, but not in an AI vibe coded way. There's another aspect of this too, where I'll pivot a little bit. AI, I like how Corey Quinn put it. He called it artificial confidence, right? And it's another term for just trendslop. And that is that it is now easy for almost anybody to put up a facade that seems like they know what they're doing, but they really don't, right? Like it's a, you could take somebody that's never
really worked with AI and they can present like, I vibe coded up this Pizza Bot thing. And it's kind of like Pizza Bot, right? But like they
Yeah.
You
can literally make their own AI harness and they don't even know it's a harness, right? They don't even know how it fits in and stuff. But when you look at it at the front, it looks like, my gosh, this is a whole thing that you just made. And it's amazing. And it looks like it's solving a business problem. But really it's just causing, it's causing sort of a burden inversion on the people that actually know how this stuff works to even deal with it. So like AI
is creating, you know, there's the AI slop, there's trendslop, which is I think the business term for business people just promoting things. So maybe there's a weird balance here where like all the efficiencies that we get are just blown away by other people that don't know how that stuff works.
Yeah...
Just
because your
agents thought it was you know, wanted to know if they could doesn't mean they should have, right? What was that quote from Jurassic Park? Yeah. Your scientists
Hmm.
were so preoccupied if they could they didn't consider whether they should. And I feel like that is the case now with
software developers using agents. Pizza Bot is a great example
of should you have really done that?
And it's not only in software, I think it's everywhere these days.
Yeah. Anything with NotebookLM attached to it, you are in for a round of surprise.
Yes, there was a story, I think it was this week, with a quote from the Shopify CEO where he talked about slop grenades, where there's lots of AI generated emails and documents and stuff that are just taking up time, just like we have been talking about code reviews that that's the blocker for many now because so much is generated. It's everything else is generated that way as well. But also, yes.
Yeah, which is like hilarious 'cause like that same guy was like,
use AI for everything a year ago.
You beat me to it, Danielle, that's where I was heading, so yeah. Because exactly, a year ago there was articles around him where he said, if you're not using AI you should basically not be at Shopify. So yeah, he set the table for it, I guess.
I don't know if folks here have been building teams, but I'd love to hear some stories on like, you know, have you been using AI for reporting? Have you been, you know, have you seen the teams change to where you need AI in that team more than you have before, right? Like have you had to manage upwards in teams and help train business leaders, you know, how to sort of spot the slop grenade. I love that term, Gunnar. That's a...
It's exactly what it is, right? It's that artificial
Yeah.
confidence. It's that burden inversion
Yeah, but I think so many organizations have built a culture around rewarding basically volume. So a
Mm.
lot of the things we've
No.
done in the past have been the more volume the better. And now we have tools. Yeah. No.
Token maxing was the perfect example of that, right? Is like,
Yep.
hey, let's just burn money
Yeah.
and whoever burns the most money wins.
But I'm thinking
years back, so organizations before AI built reward systems around just volume. The more work you perform, basically, the better your bonus will be, or whatever. Yeah.
Well and like more visible stuff too, because
Yes. Or
Mm-hmm.
like if I'm building the underlying platform that everything's sitting on, people just kind of ignore that until it's broken. But you know, the second a front end engineer, you know, shows light mode, dark mode, like everyone's like in love with it. So
Look
You
at the GitHub graph on everybody's thing and all the little green dots and how green they are and that you know, that just proves that we've been incentivizing the wrong thing and gamifying the wrong things.
What's that like tendency where the POC, you know, you show it to the VP of engineering, he's like, This looks awesome, but like underneath it doesn't look good. And then that's what becomes the app. And
I think AI has very much accelerated that. But like it's always been there. I don't think it's AI's
Yeah.
fault. It's just happening a lot more because it's easier. Yep.
He
POC looks good, ship it to prod. Yeah.
It's easier.
localhost port 3000.
Yeah.
Yeah.
Alright, so we've now gone from labs pacing themselves to a regulator that started a clock, I guess, counting down to December 2027. Agents with inboxes and down to what all of this does with people that are building software. So I think it's time to take a bit of a breath. But then when we come back, it's time for burst mode.
He
Alright, so now, sponsors... Ken? Can you do the sponsor messages?
What? Do I just read them off here? Where are they?
Yeah
Yeah, well this...
I was gonna say we have sponsors?
We should definitely keep this in.
I get a paycheck?
Everyone, welcome back, it's now time for Burst Mode and we are gonna jump straight over to Danielle.
Yeah, so about a month ago I saw that Amazon Aurora DSQL now supports foreign key constraints. For the listeners that may not know, DSQL is a database, I believe it was released
Yeah, it's been GA since about May 2025, so it's been out for a little bit. It's a way that you can do Postgres compatible things, but it's more global. So you can have active-active region failover. The one thing that really appealed to me for it is like the fact that it really scales down to zero.
We kind of had that a little bit with Aurora Serverless v2, but there is like a 30-second cold start during the pause. So like you probably wouldn't want to use that in prod. But anyway, yeah, when DSQL came out, like I think it was at re:Invent, like it was definitely the talk of the town. Like everyone was talking about it. And like the thing that just stood out to me about this announcement is foreign key constraints released.
Like over a year after it's been GA. To me, stuff like this is part of why I don't use DSQL yet. I'm really
Mmm.
excited about what it could potentially be, and I and I'm excited to see these announcements, but at the same time, like I lose a little bit of trust from Amazon and some of these other cloud providers when they release things and call it GA, and it's missing what I would consider a super key thing.
No pun intended.
Foreign key. Yeah.
It's the
Ha ha
SBOM of databases.
Okay. Stuff yeah.
Yeah, like I
guess you don't have to have them, but like I feel like if you want to have referential integrity across tables, like it's a great way to like it doesn't make it optional. Like you have to have it. And that like personally I'm a perfectionist and like I wanna have that because it can prevent, you know, chasing some bugs that can be hard to track later down. Like I would much rather it fail, you know, on the
initial migration or whatever and be loud to start versus later, you know, someone adds something that should be referenced across a table and it's not, and then you're like, why is this not working?
Yeah, building a serverless, active-active, multi-region database service that has strong consistency, that's quite the engineering feat, honestly. And then that it takes almost two years to have this released, which I think many saw as kind of one of the features you kind of needed to have. It's interesting, to say the least.
As someone who really, really loves to ship things and progressively enhance them and know that I'm working towards a greater goal. And sometimes that goal is not understood until you get to the end there. I will say that this is really good work, but yet to me as well, I'm also like, wait a minute. Like it really did take this long to do this because all I've ever wanted was a relational serverless database for so long. Right? Just, I mean,
I don't know why, but my head just cannot wrap around DynamoDB past like in real world applications. I'm just, I was the maintainer for the ActiveRecord SQL Server adapter for Ruby on Rails. And as I like to say, I was the top of the bottom, right? Like, the Oracle adapter was right under me. You know, lots of people came to Rails and ORMs from SQL.
And so I love relational databases. I think they're the workhorse of the internet and obviously not from an AWS perspective, right? Like the DynamoDB is really powering things, this like serverless database, foreign key constraints, zero billing model, good cold starts. Yes, yes, yes, yes, yes.
Yeah, we're getting closer to what I want. So I'm getting excited about it. I do have some plans to use it in some personal projects, just to kind of see how I like it. But yeah, for now I'm a little wary because anecdotally I don't know anyone using this in production. Curious if any of you guys do.
Still waiting to see some of the big customer references around DSQL. I can't really say that I've seen any either. I'm sure that's going to be a presentation at re:Invent
And I've kind of
adopted DynamoDB for most of my data needs and 'cause I want scale to zero and that kind of thing, so
Well, yeah, I think that's
What when the when- when-
what many have done. So basically adopted, but then with all of the difficulties with NoSQL and what comes with that, I guess.
I think what will happen is I remember when the V2, Danielle, came out, it was a,
Mm.
what I did was I wrote a Rails adapter for that particular version, right? And of course I had to bypass all the foreign key tests, right? And stuff like that. But if you can get this into the hands of folks that are building like ORM layers and things like that, I think it's really going to unlock a lot of like broader applications. And this is coming from the guy that put Rails inside of Lambda and made it work well. So like, I think,
I think there's a use case here probably for legacy apps as well.
For sure. Alright, so databases finally got the constraint everybody wanted, but speaking of things that make a decision without writing a paragraph, what if the model just returned the answer to us? Ken, tell us about Jev.
The hottest new thing in the past week of AI, Jev from TypeSafe. So this thing is really cool and it's called a decisioning model. I have to go back and look at my notes, but it is basically structured decisions only. And so the idea behind Jev is you take the language model and I might misrepresent this incorrectly, but you take the large language model or the language aspect out of the model and you just make it conform to a very tight structured output.
That output basically results in the decision that could be a classification, a yes or no, and it just does it really, really, really fast, really fast. And as AI does non-deterministically, right? You can run it multiple times and get a little bit this way, a little bit that way. And so I think this is amazing, right? People are hooking it up to sort of game engines, right? Like you can have it play the Flappy Bird game. You can hook it up to Doom and have it actually play the game. And you're starting to think about, okay,
If I can do 200 requests, maybe more in a second and get decisions out of it, like what workloads does that open up? Now I'm old school. I've been doing this for a long time, right? I remember when Haiku first came out on Bedrock and you know, I was part of the crew that was like, Hey, if you run Haiku three times over and take the average, it's faster and cheaper than running Sonnet. Right? So
Yeah.
then you've got the people out there that have been doing tricks like the one bit LLM from our friends over at Zep AI,
where they would take the OpenAI models, turn the logprobs on and just take the first token and just do sort of one bit classification. And you could do it really fast. Like everybody's been doing this trick in different ways, but I think Jev'othy, what I call it. I basically just call it like that weird little raccoon, right? Like, it's a, you take a little Jev'othy here and you make these things
very well known that you can do fast decisioning and it kind of opens up new use cases. I don't know if it's real. I don't know. Like a guy came out on Reddit and talked about, I can't, I came out with this a year ago and I open sourced it. And so like, is it really going to be the model? Like I'm already Googling right before the podcast, right? Is this going to be on Bedrock?
Yeah.
Should I just go use Haiku really fast and stuff? But, that's what Jev is and it's captured everybody's attention lately.
Yeah, it's super cool. And that it's not a generative model, that it's not there to generate things. Is, like you said, it's about more or less decision making. But yeah, you touched on the controversy around it as well. That the other model that's the even hotter new thing is Laya,
Mmm.
or Laya, depending on how you.
Haven't heard of that?
And that is, I think you talked about the person who
came out with this a year ago and that's the Laya model that was released now. There's a... I have to check out his name, Nandakishor Mukkunnoth. So he wrote a few papers on this, so the science behind it basically, a year ago. And then he didn't release a model then, but he has now. So he basically open sources or open weight. So
Mmm.
it's available on Hugging Face. You can run this as well locally on your machine.
And
Or in Bedrock.
you could, yeah, exactly. So, and they've done a bunch of testing between these two and they're better at different things apparently. So, cool to try them out, both of them. What I think is interesting here is to think about the application of this in obviously when you're building agents. So the way we look at...
Gunnar, are you gonna build a harness?
I'm definitely gonna build a harness. Yeah.
He already did. There's like five of
Yes. So, I'm thinking is, let's say you have a multi-agent type thing, and then to decide which agent to call, well, maybe you could use Jev or Laya to do that. So you have a cheap coordinator making those decisions and then using whatever else you want for the actual specialist in there.
Yeah. So there's
I think that's interesting.
it's been in vogue for a long time to have a mixture of experts. Lot of these larger language models are mixture of experts base. I think the best known one is, Hermes from Nous, right? I believe that's an MoE. And so with any MoE, you're going to need a decider. You're going to need a router. And routers have been in vogue for a long time and it's an obvious fit for a router. But I think also it might accelerate some
discovery, right? So one of the big topics in AI lately too is RSI, right? Recursive self-improvement. And a lot of these frontier models are being developed through recursive self-improvement where AI is actually helping, you know, build the next iterations, do the tests, whether it be generating synthetic data, evaluations, et cetera. But if you can hook Jev up into some sort of RSI pipeline, that's probably going to open up, you
new use cases as well.
For the recurring listeners, the ones who've listened to episode 1, they might remember that we actually talked about how multiple models actually doesn't create a better output. There's scientific papers around that as well, so if you haven't seen that before you can go back and listen to episode 1 where that was discussed as well. We're
Nice.
still early days in all of this, I guess, even though you talked about being
Yeah.
old school, Ken.
Yeah, old school that's two years ago
Using Haiku was old school, apparently.
AI
You
years. It's like dog years.
Yeah,
all right. So with Jev and Laya as well, then we have models that make fast and cheap decisions. I think, Chris, you want to point to what I guess is the worst decision in the cloud, the resource that nobody remembers to delete.
Yeah, so this has been bouncing around my head for well past the dawn of ChatGPT and everything else, which is the fundamental problem in cloud is that there's no natural life cycle around a resource. I can create an EC2 instance and
Iranian missiles notwithstanding, that EC2 instance will run until the heat death of the universe because nobody will turn it off. As long as my credit card keeps clearing.
Then that machine will keep running Ubuntu 16.04 until the year 2048. So, right, well, what is the solution to this problem of no natural lifespan for a resource? Because the entropy isn't going to cause the power supply of the server to fail, to make somebody actually make a decision. Yeah, we don't need that. We decommissioned the app on that two years ago. And so
Also, hot take, Chris just
called out the year of the heat death of the universe, so 2048, you heard it here first.
2048? Yeah, well it's about ten years after we over
Yeah.
throw the 32-bit integers. So I think I was actually thinking 2038 when I said that.
Okay.
But you know, so my question then is, right, like nobody's gonna convene a meeting of
you know, four principal engineers to discuss turning off a t2.micro, right? Like, you know, the cost of the hour of us getting here to riff on this thing is gonna be outrageous. Nobody's gonna spend that, you know, deciding on, do we still need this, you know, small RDS database? Do we still need this S3 bucket?
You know, fun fact, I have a client who has an S3 bucket that dates back to the end of George Bush's administration.
You
W, not H.W. But like it literally, that bucket was created on an on Obama's inauguration day. So, like, and this thing's been sitting there, it's a couple, you know, hundred gigs. So yeah, you know, 30 cents a month for how much.
Presidents, that's been, you know, at some point that's actually adding up to real money, but not enough money for anybody to want to turn it off. So my thought is and where I'm like bouncing my ideas is can I use AI to figure out if I can turn this off? Rather than convening you know, a bunch of people who may or may not have been around
ten years ago when this thing was created, can I just use AI to be like, yeah, nobody has accessed this thing and, you know, there's no network traffic going to it. The CPU has been flat for however long. You know, we think that the, you know, odds of, you know, catastrophic things happening if you kill it is minimal. That that's my thought.
You shouldn't have deleted that. You're absolutely right. Maybe you can use Jev. It's binary. Delete or not delete.
Yes, but I still want chain of thought
I just had to-
Just yes or no?
and I don't think Jev is gonna give me chain of thought because chain of thought means, hey, this is the reason that this thing when it did become an outage was decided that way.
Something that I noticed very recently is that AWS has now released a spend limit. Have you seen that? You can actually
Mm-mm.
now set a spend
Huh.
limit on accounts. This is not rolled out to all accounts. In the documentation it basically said that they're slowly rolling it out. So you can set a spend limit on an account and it's gonna base off of your...
previous spend so you can't set it too low apparently and then once it reaches or it's getting close to that spend limit it's gonna stop you from spinning up newer resources, but then eventually also basically shut down resources.
I wonder if the motivation for AWS doing something like that is to free up capacity. Cause like I don't know for a fact, but I'm just conjecturing here. It seems like they have capacity issues with the yeah, we didn't talk about that. I just don't want to get in
That was episode 2, where we talked about that.
trouble, but yeah, just conjecture here.
But again, like this is all things that AI can figure out for me. And if I can prompt it with, if you need to look at a bucket, go flip on data events briefly.
Well I'm like as a human that's super tedious to look at. So that's why, yeah, I think it's great for
It exactly.
AI as a first pass. And then, you know,
Mm-hmm.
you as a human can be like, No, I need this George W. Bush bucket, don't delete it.
Yeah.
Yeah, human in the loop. Alright, so we've been talking now about things that you perhaps forgot that you were paying for and perhaps things that you deleted that you wanted to delete. But there's also a few things now that you actually can't get back at all. And you touched on it a little bit, Chris, before, but...
I just, I put this as a burst item because I don't want to dive too deep into it, but AWS has now confirmed in a health dashboard updates now in the middle of September that some of the data from those damaged data centers in Bahrain and the United Arab Emirates is unrecoverable. So damage spanned multiple availability zones and it
This is quote from AWS, it exceeded what our regional and multi AZ services are designed to withstand.
Wow.
So data that were in certain places is permanently gone and they aren't able to recover it. And I think this brings up a question. We talked about this in an earlier episode as well around how to actually think about...
these types of events, because this goes far beyond what perhaps have even been looked at, like things that could happen. We usually look at multi-AZ as kind of a savior for a catastrophic event, because they are so far from each other, these availability zones. But as we can see now, these things can actually happen. And it's probably more likely to happen these days as well.
Yeah, fun fact back in 2015, 2016, I actually calculated how big of an asteroid it would take to delete or to destroy a copy of data that we were potentially pondering putting into us-east-1 as just a single copy in a single region. And it's a about a 20 meter asteroid hitting around Dulles Airport would take out enough of the cities where the availability
zones were. And I got the geo stuff from some Google searches and some Greenpeace reports. But yeah.
I think you've been in Europe for too long now Chris, you said that it was 20 meters. You have
You
to explain it to the Americans
Okay.
as well, so say that it's like an ice hockey rink across or something.
I know.
Yeah, I don't know, what is that? A quarter
We learn that in science class, don't
How many dishwashers?
worry.
Alright, no, was that too mean? No. No. Alright.
No. So I mean
No, I think it's fair. Very fair.
I'm a millimeter baby. I'm sorry.
Again, this was all scientific stuff and we used meters for scientific measurements, right? We would use you know it's 20 miles from one AZ to another, but it's a 20 meter asteroid that hits in Dulles
Mm-hmm.
Airport. So that yeah. And I wish I still had those calculations. I had saved that from that job, but I did not.
And I think looking back at that event now where data isn't recoverable, I guess this highlights the thing about when you're doing backups, make sure that you back up to some other region very far away from wherever your primary region is. I think that is in basically in the manuals, that is what you're being told to do. Honestly, I'm not sure if people actually do that though.
It's not cost effective, is it? Cross region? Yeah.
I mean that's it, right? You're paying for two copies.
And so you're
paying twice and yep, there's the inter-regional transfer costs. And, you know, a lot of the data that was in these two regions was in those regions because of data sovereignty requirements.
Mm-hmm.
Mmm.
So it would have been illegal for a company holding data in, you know, Bahrain or UAE to then also copy it to the next nearest you know, region, which would have been in
Tel Aviv I think. Or you know, Mumbai
Yeah.
or Frankfurt or whatever. So, right, like that data was legally required to stay there, and now it's gone. So
Yeah,
and using a third party for it is perhaps not the answer either because then you have to make sure where they are storing their backups as well. There's a high... It's a very high
They're hosted in AWS in the same AZs that were just destroyed.
likelihood that they're using AWS. Exactly.
Could be like a even the data center next door. You don't know where any of the stuff is.
Yeah, I mean they all are gonna be zoned to be what?
Super deal.
No.
You want the good news, go read my Wildberries Architected Framework post where I actually dive into what does this mean for European customers. Because yes, I did actually measure how many kilometers drone distance from Moscow to other availability zones was or regions is, yeah.
eu-north-1 isn't very far from Russia, just saying.
Nope, it's the closest in fact. Followed
by Brandenburg, followed by Frankfurt, yes.
Yeah, I wonder if we gotta start putting stuff on the moon now. Maybe that's why Elon wants to do all that.
Then you've got a latency problem, right? You know, like the packet latency, yeah.
Fair, yeah.
And I'm also pretty sure he wouldn't do anything for our benefit, so no. That's not the reason.
No, that's true.
Definitely not.
No. Alright folks, I think that's the show. A lot of talk about what we're building and I guess a reminder that all of it sits in actual buildings somewhere, so think about where you're storing your data. I want to go around the table one last time, as we usually do, to hear what you're looking forward to in the
month. I usually start with Danielle so I'm gonna start with Chris this time.
Shoot, I'm not looking forward to
You
anything. No. I'm looking forward to more arguments
Stay positive, Chris.
with my developers about AI things that they want to get done that I can't get done because I've got regulations that I've got to follow. Actually I guess I am looking forward to having actually cleared some of those major hurdles. And so yeah, but
That's for a client. And I think the other thing I'm looking forward to is a vacation to London with my kid, where we are going to go and do the Tower of London and the Crown Jewels and Tower Bridge and the Palace of Westminster, which if you've never done, you actually can go in and see the floor of the House of Commons and the House of Lords, which is
That was a very nice thing, Chris. I like it.
There we go.
Ken!
Okay, so I'll give you the excited sandwich. So on one side with the AI, I'm kind of excited about recursive self-improvement, but in general, I'm a little bit sort of unexpectedly surprised by the Apple Intelligence. So one of the things that happened to me this morning is I was renaming a CSV file of data and Apple Intelligence recommended to me three file names. I thought that was cool, right? So like I've always talked about like the...
lifestyle copilot and how intelligence moves to the edge and it's going to affect different things. We'll see there. On the non-technical side, I live in the southeastern part of Virginia and I'm going to go to the Bacon and Bourbon Festival in Smithfield, Virginia. So I spent a lot of my time in Smithfield, Virginia and Williamsburg, Virginia and I'm going go to the Bacon and Bourbon Festival and I hear they hand you like a pile of bacon when you go in and some bourbon tickets. So I'm going to do Bacon and Bourbon this weekend
or next weekend.
Danielle, what are you looking forward to?
Yeah, I think for me this time of year is just kind of silence before the storm with, you know, US Thanksgiving, re:Invent, Christmas. So I'm just looking forward to next month not really doing anything, saying no to things. And I would like to spend some personal time learning how to self-host some of these open weight models because putting on my tinfoil hat, I think these AI token
costs and pricing is gonna soar. So it seems like an interesting thing to learn in general, but also for selfish reasons. So then I just have to pay for compute.
Very cool. And I'm looking forward to playing with Jev and Laya. That's kind of on my to-do right now. And see what we can actually do with it. And on the more personal side, handball season is starting. So my boys will be starting handball practice again now. And that's always fun to be with them when they're doing practice. So that's what I'm looking forward to. All right, people.
Thank you all very much for joining us on this episode. Thanks to Danielle, to Chris, to Ken and all the listeners out there. And we will be back with another episode. And there's one thing I can promise you. We are gonna be talking about AI and we are definitely gonna be yelling at the cloud. Thank you all very much.