<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Founder Catalyst]]></title><description><![CDATA[Seeding ideas, startup concepts, and compelling events for founders and future founders in cloud, AI, and cybersecurity. ]]></description><link>https://dannguyenhuu.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!-96Q!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ccedcc-7db7-45b4-a945-e215df8f5d19_800x800.png</url><title>Founder Catalyst</title><link>https://dannguyenhuu.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 30 Jun 2026 04:37:19 GMT</lastBuildDate><atom:link href="https://dannguyenhuu.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Dan Nguyen-Huu]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dannguyenhuu@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dannguyenhuu@substack.com]]></itunes:email><itunes:name><![CDATA[Dan Nguyen-Huu]]></itunes:name></itunes:owner><itunes:author><![CDATA[Dan Nguyen-Huu]]></itunes:author><googleplay:owner><![CDATA[dannguyenhuu@substack.com]]></googleplay:owner><googleplay:email><![CDATA[dannguyenhuu@substack.com]]></googleplay:email><googleplay:author><![CDATA[Dan Nguyen-Huu]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Rise of the Probabilistic Founder]]></title><description><![CDATA[Over the last few months, I&#8217;ve been having versions of the same conversation with a bunch of seed and early-stage investors.]]></description><link>https://dannguyenhuu.substack.com/p/the-rise-of-the-probabilistic-founder</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-rise-of-the-probabilistic-founder</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Thu, 23 Apr 2026 18:18:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2tgU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2tgU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2tgU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2tgU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1858893,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/195268749?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2tgU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!2tgU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1f0940d-25ef-45d6-b86b-32e6901aae4c_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Over the last few months, I&#8217;ve been having versions of the same conversation with a bunch of seed and early-stage investors. The specifics differ, but the shape is always similar: the world we underwrite against has changed, and the founders who are building in it look different from the ones we backed in the past.</p><p>For most of the history of software, we built deterministic systems. You wrote the code, you tested it, you shipped it, and within well-understood bounds you knew what it did. Given the same input, you got the same output. And because that was the nature of the systems, it was also, whether we said it out loud or not, the nature of the founders we backed to build them. Structured. Methodological. Thoughtful. The kind of operator you could hand a plan to and trust would execute it quarter after quarter. We pattern-matched on rigor, on clarity, on the ability to write a roadmap you could live inside for two years. Backing founders at the seed stage, we evaluated &#8220;clarity of vision&#8221;.</p><p>The systems we&#8217;re all building now are not deterministic anymore. And the founders who are winning are changing too.</p><h2>The era of probabilistic engineering</h2><p>Tim Davis, the co-founder of Modular, published an essay called <em><a href="https://www.timdavis.com/blog/probabilistic-engineering-and-the-24-7-employee">Probabilistic Engineering and the 24-7 Employee</a></em> that, in my view, is a clear articulation of this shift. His central claim is that software is becoming a probabilistic system. Inside the most AI-native teams, large portions of the codebase are generated by stochastic models, reviewed under time pressure against contexts too large to fully hold, and integrated into wholes no single human ever designed end-to-end. The code still runs. It still ships. But the confidence interval around &#8220;this works as intended&#8221; has widened. Generation has become cheap. Validation has not. The codebase stops being a thing you know works and becomes a thing you believe works, with a probability you can no longer precisely state.</p><p>Senior engineers have always lived with some version of this, every large production system is, to some degree, a thing you believe works. But the degree has changed enough to matter. When most of the code you&#8217;re shipping wasn&#8217;t written by the humans reviewing it, belief-based correctness stops being an edge condition and starts being the default.</p><p>If that&#8217;s what the systems are becoming, it stands to reason the people building them would start to look the same way. And in some of the most important categories forming right now, the deterministic archetype we used to underwrite against, the operator with the two-year roadmap and the crisp milestone plan, is no longer sufficient. In a few of them, it&#8217;s actively a mismatch.</p><h2>The probabilistic founder</h2><p>The founders building the best AI-native companies are a lot like the systems they&#8217;re building.</p><p>They are experimental by default. They are willing to abandon their priors. They&#8217;d rather run ten cheap experiments than commit to one expensive plan. Their iteration cycles are measured in days, not quarters. And (this is the part that would have been a red flag two years ago and is now a tell that they&#8217;ve read the environment correctly), their roadmaps are deliberately, almost defiantly, light.</p><p>More than one founder has told me some version of the same line: &#8220;Here&#8217;s our long-term vision of the platform, but honestly, this could all change in two or three months.&#8221; A model ships, a capability jumps, and the plan they wrote a quarter ago is no longer the plan you&#8217;d write today. The best ones aren&#8217;t embarrassed by that. They&#8217;ve priced it in.</p><p>You can see the same shift inside their engineering orgs. For decades, the benchmark for &#8220;how much time should engineers spend on exploratory work&#8221; was something like Google&#8217;s famous 80/20, roadmap-heavy, with a slice carved out for experimentation. In the AI-native teams I spend time with, that ratio has flipped. Something closer to 70% experimental and 30% roadmap is now what I hear from the most forward-leaning shops, not as a formal policy but as the lived reality of how the week actually breaks down. The roadmap bends around the models, not the other way around.</p><p>And there&#8217;s a philosophical tell I keep hearing that I think matters more than any of the tactical ones. The probabilistic founder operates with what I&#8217;d call an agent-default posture: the assumption that anything can be done with an agent in mind, and if the agent doesn&#8217;t work, the operator - the human - has failed, not the agent system. That&#8217;s a fundamentally different locus of accountability than the one most of us grew up with, where a tool that didn&#8217;t work was, well, a bad tool. The probabilistic founder doesn&#8217;t blame the tool. They assume the tool is getting better every week and ask whether their own specification, review, and orchestration kept up.</p><h2>What this means for how we invest</h2><p>If you&#8217;re still pattern-matching founders against the deterministic archetype, you might miss the best ones in this cycle. Some of the signals that would have read as &#8220;unstructured&#8221; or &#8220;not rigorous enough&#8221; five years ago are, in this environment, exactly the traits that match the shape of the work - a willingness to kill a feature the day after a model release, to live inside uncertainty without flinching, to treat the roadmap as a hypothesis rather than a promise.</p><p>I don&#8217;t think rigor is dead. I think it has moved. The rigor that matters now lives in experimentation quality, in selection discipline, in the ability to direct a fleet of agents toward the right problem and tell the brilliant output from the plausible-looking-but-wrong output. That&#8217;s a different muscle than five-quarter roadmap adherence, and we&#8217;re still learning how to evaluate it.</p><p>And it&#8217;s worth saying plainly what doesn&#8217;t change. Probabilistic doesn&#8217;t mean casual. The probabilistic founder still has to be a relentless executor - arguably more so, because an environment that rewards running ten experiments instead of one is unforgiving to anyone who can&#8217;t actually finish things. Velocity is the price of admission; the ability to ship, close loops, and compound week over week is as non-negotiable as it ever was.</p><p>Likewise the probabilistic founder still has to be an absolute talent magnet. If anything, that bar has gone up. In a world where a small team of the right people plus a fleet of agents can out-ship a team of fifty, the premium on pulling in the top one percent of operators is higher, not lower. The best probabilistic founders are, without exception, the kind of people other great people rearrange their careers to work with. Experimentation without execution is noise and speed without talent is churn.</p><h2>The bet</h2><p>Tim Davis ends his essay with a line I keep turning over: the bet of this era is whether the human in the loop stays sharp enough, honest enough, and trained well enough to be worth having in the loop at all.</p><p>The founder version of that same bet is whether the operator pointing the fleet has the taste, the speed, and the comfort with uncertainty to compound faster than a competitor still trying to plan their way through.</p><p>The probabilistic founder is that bet, in a person. And it&#8217;s the one I&#8217;m convinced is worth making.</p>]]></content:encoded></item><item><title><![CDATA[The Token Threshold ]]></title><description><![CDATA[Is your Buyer Actually an Agent?]]></description><link>https://dannguyenhuu.substack.com/p/the-token-threshold</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-token-threshold</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 14 Apr 2026 21:02:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ywNZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><blockquote><p><strong>&#8220;The Token Threshold</strong> is the point at which the cost to build a capability from scratch exceeds the cost to buy it, measured in inference tokens. Every software product sits either above or below this line. Below it, agents build. Above it, agents buy. The line is invisible, unmapped, and moving.&#8221;</p></blockquote><p>Every software product now has an invisible line.</p><p>The entire SaaS industry was built on a single assumption: the buyers are human. Humans evaluate tools, sit through demos, get approval from procurement, and eventually choose your product over building something internally. The entire model (positioning, pricing, PLG motions, sales cycles, feature roadmaps, steak dinners) is designed to influence that purchasing decision. It works because humans have budgets, time constraints, job requirements, career aspirations, and a limited tolerance for greenfield engineering risk. So they buy. Some more emotionally than others.</p><p>Today, the SaaS industry is getting decimated and that assumption is breaking. Because if you play the current trajectory forward and more enterprises complete their agentic transformation (we&#8217;re all running Cowork on our desktops now, aren&#8217;t we?), the real influencer of a purchasing decision in the AI era is no longer just human.</p><p>In February 2026, a research team at <a href="http://amplifying.ai">Amplifying.ai</a> pointed Claude Code at real production codebases 2,430 times. Blind prompts. Just tasks: add authentication, add feature flags, add caching, set up a job queue.</p><p>In <a href="https://amplifying.ai/research/claude-code-picks">12 of 20 categories tested</a>, the agent skipped the tool entirely. Instead, it chose to build. Authentication from scratch: JWT, bcrypt, session management, every single time. Feature flags: 69% build rate. Caching: 50% build rate in newer models and rising. Task queues: custom implementations, over Celery, over BullMQ.</p><p>But on the other side:</p><p>GitHub Actions got picked 94% of the time. Stripe, 91%. Vercel, 100% for JavaScript deployments. shadcn/ui, 90%.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ywNZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ywNZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 424w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 848w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 1272w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ywNZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png" width="1245" height="671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:671,&quot;width&quot;:1245,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ywNZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 424w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 848w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 1272w, https://substackcdn.com/image/fetch/$s_!ywNZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67be72cf-2b3e-4ca7-9cd8-e3583b4c737f_1245x671.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The agent chose deliberately. Aggregating individual decisions into efficient outcomes. Adam Smith&#8217;s invisible hand at machine speed.</p><p>&#8212;-</p><h2><strong>Agentic Procurement Evaluation</strong></h2><p>In the Amplifying AI study, they looked at individual tasks where the models show specific preferences while converging on Custom/DIY implementations.</p><p>But in an enterprise procurement instance with complex requirements and expensive contracts, what factors into the agent&#8217;s decision to recommend build vs buy?</p><p>One has to think the Agent ICP calculates: can I reach the required outcome more cheaply and reliably by building it myself? With no regard towards long standing vendor relationships, career risk, or boozy conference lunches.</p><p>This means that every software vendor will have to exceed that bar in order for the Agent to determine it&#8217;s more worth the investment to purchase from you. We call this the Token Threshold.</p><p>The Token Threshold is the final estimate after an agent performs a lifecycle comparison:</p><ol><li><p><strong>Define the target outcome.</strong> What does &#8220;done&#8221; actually look like?</p></li><li><p><strong>Define the acceptance bar.</strong> What level of correctness, reliability, and security is required?</p></li><li><p><strong>Estimate the build path.</strong> Spec + implementation + verification + debugging + maintenance + incident handling.</p></li><li><p><strong>Estimate the buy path.</strong> Evaluation + integration + adaptation + vendor cost + dependency risk.</p></li><li><p><strong>Compare reachable confidence.</strong> Beyond initial buildability, who gets you to the acceptance bar more reliably over time.</p></li><li><p><strong>Buy only if the product materially improves success probability or lowers lifecycle cost.</strong></p></li></ol><p>For JWT and bcrypt? Build, every time. For PCI-compliant payment processing? The math goes the other way entirely.</p><div><hr></div><h2><strong>The line moves</strong></h2><p>The Token Threshold moves. Continuously on a downward trajectory with every model release and the fact that tokens are deflationary.</p><p>Opus 4.6 builds custom solutions 50% more often than Sonnet 4.5 in the same categories. Redis went from a 93% pick rate in Sonnet to 29% in Opus 4.6. Celery went from 100% to 0%. The newer the model, the more it builds and the less it buys.</p><p>Open source accelerates this further. Developers have always pulled from OSS rather than rebuilding everything from scratch. Agents will do the same, only faster and more systematically. A product that felt safe because &#8220;nobody would build that from scratch&#8221; faces a new question: is there a good enough open source version an agent can just leverage? If yes, the threshold just dropped again, and the vendor in the middle gets bypassed entirely.</p><p>And here&#8217;s where it compounds. As enterprises shape their engineering processes around building with agents, the agent buyer gets more capable and more dominant with every cycle. Internal tooling, approved libraries, preferred patterns all train the next generation of agent decisions. The enterprises moving fastest today are building institutional muscle memory that makes their agents faster and more opinionated tomorrow.</p><p>For software vendors, that means the window to establish above-threshold positioning is narrowing.</p><p><em>The Napster parallel is worth sitting with. Napster didn&#8217;t make music worse, but it made copying cheaper than buying, for the first time. The industry that survived held something you simply couldn&#8217;t copy: live experience, artist relationships, synchronization rights. That&#8217;s the question for SaaS. What do you have that tokens genuinely have to purchase?</em></p><div><hr></div><h2><strong>Bear vs Bull</strong></h2><p><strong>The bull case:</strong> Products that clear the threshold win with near-monopoly conviction. That kind of pick rate in an agent-driven world is a distribution flywheel with no equivalent in human procurement history. Every agent that spins up in a developer&#8217;s sandbox is a potential procurement event. The winners win bigger than traditional GTM ever allowed.</p><p><strong>The bear case:</strong> Most software sits below its own threshold and has yet to find out. The agent economy runs on zero authentication vendors, zero feature flag tools, zero caching layers. It builds them. The long tail of enterprise SaaS is about to discover that human friction was doing all the heavy lifting.</p><p>Both are right. The Token Threshold is simultaneously the best thing that&#8217;s ever happened to software with genuine moats, and an extinction-level event for software that relied on human inertia.</p><div><hr></div><h2><strong>Core IP</strong></h2><p>Here&#8217;s the thing. The products that will always sit above the line share one property: their value lives in what the code connects to.</p><p>Call this core IP. There could be more, but these four came to my mind:</p><p><strong>Network effects. </strong>The moat here are the participants. You can&#8217;t token-generate a two-sided marketplace with real liquidity, or a professional network where the value is who&#8217;s actually on it. The value in each case lives in participant behavior, history, willingness to transact. An agent can use any of these platforms. It cannot simply conjure critical mass.</p><p><strong>Proprietary data &amp; context arbitrage.</strong> Models train on available data. If your product creates, captures, or acts on data with no public equivalent (transaction histories at scale, sensor readings from physical systems, domain signals accumulated over years) that&#8217;s a ceiling agents hit every time. No new entrant bootstraps it. A model can&#8217;t either.</p><p><strong>Regulatory and trust infrastructure.</strong> The most underrated moat in software. PCI certification, FedRAMP authorization, SOC 2 Type II, banking relationships, enterprise security reviews that took 18 months: none of that is token-generatable. Agents buy Stripe because the alternative is becoming a payment processor. The compliance layer is years of work even when the code is trivial. That asymmetry holds regardless of how capable the models get.</p><p><strong>Risk transference.</strong> This one the data doesn&#8217;t surface, but enterprise buyers live by it. Even when an agent can build something, large organizations often buy anyway, because they need someone accountable when it breaks. A vendor carries SLAs, support contracts, liability, and a throat to choke. For regulated industries and risk-averse agentic buyers, that accountability layer is the purchase. Technical complexity is beside the point.</p><div><hr></div><h2><strong>Back to hard things</strong></h2><p>Here&#8217;s what I keep coming back to.</p><p>The era we&#8217;ve been living in: fast traction, fast fundraising, AI-assisted shipping. It created real companies. It also created a generation of software built on the quiet assumption that human inertia was permanent. That switching costs would hold. That procurement cycles would protect you. That being first and fast was enough.</p><p>It was always a knife&#8217;s edge. AI is just shining a light on it.</p><p>As the agent becomes the economic buyer, founders and investors get pushed back toward something that looks a lot like real innovation. Beyond growth hacking. Beyond PLG funnels. Building things that are genuinely hard to replicate. The kind of work that takes years not because the tools are slow, but because the moat itself doesn&#8217;t compress.</p><p>That feels like where we&#8217;re going. And honestly? Good. Maybe it is time to build hard things again.</p><div><hr></div><p><em>Data: Amplifying.ai Claude Code Picks benchmark &#183; Feb 2026 &#183; 2,430 responses across 3 models, 4 repos, 20 categories</em></p>]]></content:encoded></item><item><title><![CDATA[Black Hat 2025: Security Catalyst Recap]]></title><description><![CDATA[In Las Vegas, GPUs are not the only thing overheating. So are its hackers.]]></description><link>https://dannguyenhuu.substack.com/p/black-hat-2025-security-catalyst</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/black-hat-2025-security-catalyst</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Wed, 13 Aug 2025 13:26:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4Eyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Eyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Eyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Eyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:380651,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/170727652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4Eyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Eyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6885239-5843-46fc-b33d-dcc86dddf1a4_2048x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Decibel Vibes and Cocktails Happy Hour</figcaption></figure></div><p>Las Vegas in August is always intense, but this year the real heat came from breakthroughs not just in cyber tools, but in how we think about offense, defense, simulation, identity, and human sustainability under pressure all under the large cloud cover of AI (obviously). The <a href="http://Decibel.vc">Decibel</a> team was out in full force hosting a series of events from the <a href="https://www.linkedin.com/posts/jonsakoda_it-was-great-to-take-a-break-from-the-109-activity-7359601490073698306-jT9x?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAO9oeEBhUic4AhdPOZY6irsjPr5IOduplc">Vibes &amp; Cocktails happy hour</a> with the awesome <a href="https://www.linkedin.com/in/mikeprivette/">Mike Privette</a> from <a href="https://www.returnonsecurity.com/">Return on Security</a>, a <a href="https://www.linkedin.com/posts/lauren-ipsen-6a5a84113_blackhat2025-ugcPost-7359669353866301440-Qpez?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAO9oeEBhUic4AhdPOZY6irsjPr5IOduplc">Women in Cyber brunch</a> and our usual Founder Oasis suite where founders can hang out and take a breather from the craziness of the BlackHat Expo. Over these glorious few days inside the Mandalay Bay hotel, here are some of the biggest topics and themes that were discussed: </p><div><hr></div><h3><strong>The First AI-in-Cyber Use Case has matured: Toil Reduction</strong></h3><p>It's taken a lot of hype cycles, but we've finally hit a clear, repeatable AI use case in cybersecurity: getting rid of soul-crushing toil. <a href="https://docs.sublime.security/docs/ade-autonomous-detection-engineer">Sublime Security's ADE</a> (Autonomous Detection Engineer) is a prime example: automating the grunt work of detection engineering so humans can focus on higher-order problems. Dropzone AI is doing the same for the SOC, taking Tier-1 alert handling and triage from hours to minutes without sacrificing quality. The value is obvious because the before/after delta is so stark. No philosophical debates about "will it work". It's already working.</p><p>The timeline tells an important story about enterprise AI adoption. <a href="https://www.linkedin.com/in/edwardxwu/">Edward Wu</a>, founder of <a href="https://www.dropzone.ai/">Dropzone AI</a>, first introduced the concept of investigating alerts using LLMs at our Founder Oasis at RSA in March of 2023, only a few months after ChatGPT was released. Dropzone was born in August 2023, and while he long proved that its AI was effective for alert investigations, the human acceptance, trust, and willingness to delegate alerts and reduce toil took until recently to fully materialize. AI SOC dominated every conversation on the expo floor at Black Hat 2025. For me, this marks the moment we can officially declare victory on AI-powered toil reduction in security. What was once a pilot in many enterprises has become a mainstream operational reality.</p><p>This raises a critical question for the broader AI-in-security landscape: now that we've moved past the foundational debate of whether AI works in security contexts, <strong>how much faster will we adopt other AI use cases?</strong> The answer likely depends on whether those use cases can demonstrate the same stark before/after delta that made toil reduction so compelling. With trust barriers lowered and operational patterns established, I think the adoption curve for subsequent AI security applications should accelerate significantly</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PXQt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PXQt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 424w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 848w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 1272w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PXQt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png" width="879" height="434" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:434,&quot;width&quot;:879,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:588857,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/170727652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PXQt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 424w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 848w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 1272w, https://substackcdn.com/image/fetch/$s_!PXQt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5b9b549-d334-4b0e-a630-7be0fe2585cc_879x434.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Proudly Offensive &#8212; Deterrence in the AI Era</strong></h3><p>After this year&#8217;s RSA, I wrote an article about "Proudly Offensive", an idea on how in an AI world, security insights increasingly come from offense, not just from watching and waiting. Historically, security posture leaned heavily on detection, with just enough response to feel proactive. Organizations built their security programs around the assumption that visibility and monitoring would give them the edge they needed.</p><p>But AI fundamentally changes this calculus. We're already seeing operational proof: startups using AI agents to dominate bug bounty programs, and more concerning, full end-to-end data exfiltrations that run autonomously from initial access to final payload delivery. The offensive capabilities of AI have moved from theoretical to operational.</p><p>Bug bounties are a useful proving ground. They demonstrate that AI can find vulnerabilities faster than humans and execute complex attack chains with minimal human oversight. But the real question is whether we can build offensive cyber capabilities that matter when geopolitical tensions escalate. What happens when the call comes in: "We need you to help"?</p><p>This is where deterrence becomes front and center. The organizations and nations that figure out how to weaponize AI for cyber operations will have strategic leverage. We're seeing early signals in American defense investments: companies like Palantir and Anduril building AI-powered capabilities at scale, not for corporate penetration testing, but for real-world adversarial engagement.</p><p>This shift is technical, political, and extisential. In an AI-driven threat landscape, deterrence requires demonstrable offensive capability. The willingness to develop, deploy, and when necessary, unleash AI-powered cyber operations will define which nations maintain strategic advantage in the coming decade. American dynamism built the internet, scaled cloud computing, and created the AI models powering this revolution. </p><p>The next chapter won't just reward those who can defend better, it will reward those who can project power through AI when called upon to do so.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jsDl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jsDl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 424w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 848w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 1272w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jsDl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png" width="889" height="669" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:669,&quot;width&quot;:889,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1088699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/170727652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jsDl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 424w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 848w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 1272w, https://substackcdn.com/image/fetch/$s_!jsDl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d046f1f-b58e-433c-b98a-177b5ee4b1d1_889x669.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Simulation Is All You Need (&#8230;Almost)</strong></h3><p>One of the more interesting threads was the growing role of digital twins in cyber. Enterprises are interested in building high-fidelity replicas of systems and networks to safely run security experiments, train AI models, and test defenses. <a href="https://www.darkreading.com/endpoint-security/digital-twins-bring-simulated-security-real-world">This Dark Reading piece on this is worth a read.</a> Today, these simulations excel at controlled, discrete scenarios perfect for training or red-team-blue-team exercises. But the leap to truly continuous, real-time "mirror worlds" of live enterprise environments is still constrained by data freshness, fidelity, and cost.</p><p>The most compelling advancement is how these twins are evolving beyond simple network topology modeling to capture dynamic interactions between applications, cascading effects of component failures, and environmental factors that influence security posture. <a href="https://cloud.google.com/blog/products/identity-security/how-to-build-a-digital-twin-to-boost-resilience">Google shared the actual complexity required in their approach</a>: real-time data streams, comprehensive monitoring capabilities, and computational power to model both normal operations and adversarial scenarios simultaneously.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HHLx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HHLx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HHLx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg" width="1456" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/GC---Chart---Digital-twin_1.max-2200x2200.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/GC---Chart---Digital-twin_1.max-2200x2200.jpg" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/GC---Chart---Digital-twin_1.max-2200x2200.jpg" srcset="https://substackcdn.com/image/fetch/$s_!HHLx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HHLx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3075793f-d624-47d7-ab23-826fd34554d3_2200x963.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://cloud.google.com/blog/products/identity-security/how-to-build-a-digital-twin-to-boost-resilience</figcaption></figure></div><p>The next evolution will likely involve AI agents operating within these simulated environments. While today's digital twins rely on human red teams manually probing for weaknesses, the future points toward autonomous agents that could continuously explore attack paths, test defensive responses, and discover novel vulnerability combinations at machine speed. We're not there yet, but the foundation is being built.</p><p>This sort of rehearsal logic combined with operationalized threat intel (like GLACIAL PANDA's long-duration persistence) can let defenders explore edge cases and policy effectiveness before reality does. It's a cyber range that no longer approximates, but lets you fight today's adversary with your own specific blueprint.</p><div><hr></div><h3>Other Blackhat Thoughts</h3><p><strong>Social Engineering - Phishing, Vishing, really all the -ishings</strong></p><p>The narrative is changing from phishing campaigns to quantifying and modeling human risk in real-time. The old security awareness training model of quarterly compliance checkboxes is dead. In its place, we're seeing human risk management emerge as a control layer that feeds behavioral telemetry into identity systems, conditional access policies, and even insurance underwriting (<a href="https://dannguyenhuu.substack.com/p/welcome-to-human-risk-university">I wrote about this recently!</a>). According to Crowdstrike, &#8220;Vishing attacks increased 442% from the first to the second half of 2024 and the number of vishing attacks in the first half of 2025 have already exceeded the total number seen in 2024.&#8221; </p><p>This means that authentication must evolve beyond static credentials to dynamic behavioral baselines and step-up validation that adapts to the sophistication of AI-driven social engineering. The threat is substantial and requires a different approach (<a href="https://pushsecurity.com/news/pr-20250806-push-security-launches-phishing-detection-evasion-techniques-matrix">See Push&#8217;s Phishing Detection Evasion Techniques Matrix</a>) now that adversaries can clone voices or generate convincing deepfakes in real-time that adapt mid-conversation to bypass detection systems and human intuition alike.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!md3o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!md3o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 424w, https://substackcdn.com/image/fetch/$s_!md3o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 848w, https://substackcdn.com/image/fetch/$s_!md3o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 1272w, https://substackcdn.com/image/fetch/$s_!md3o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!md3o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png" width="668" height="681.9166666666666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:624,&quot;resizeWidth&quot;:668,&quot;bytes&quot;:736714,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/170727652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!md3o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 424w, https://substackcdn.com/image/fetch/$s_!md3o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 848w, https://substackcdn.com/image/fetch/$s_!md3o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 1272w, https://substackcdn.com/image/fetch/$s_!md3o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fb8918-8bbb-48f8-ad88-a0022597ccb8_624x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Security for AI</strong></p><p>Acquisitions continued this year. <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-completes-acquisition-of-protect-ai">Protect AI&#8217;s acquisition</a> was announced during RSA and SentinelOne announced its intent to<a href="https://www.sentinelone.com/press/sentinelone-to-acquire-prompt-security-to-advance-genai-security/"> acquire Prompt Security</a> at the start of Black Hat. This reminds me of <a href="https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-announces-intent-acquire-evidentio">Evident.io&#8217;s acquisition</a> in the early cloud days. The vendors getting acquired today are the ones creating the security controls that make AI deployment viable at enterprise scale. In the past year, solutions have moved from simple model governance to AI security platforms that can detect prompt injection, monitor model behavior drift, and protect training data pipelines. But the question is whether or not this is the end game solution to Security for AI since we don&#8217;t even know the full attack surface yet.</p><p><strong>From Application Security to Product Security</strong></p><p>There's a subtle but important shift happening in how organizations think about security ownership. Traditional AppSec focused on finding vulnerabilities in code. Product Security embeds security thinking into the entire product lifecycle: from design decisions to feature rollouts to customer-facing security controls. This isn't just semantic evolution; it's organizational. Product Security teams report to product leadership, not just security leadership, and they're measured on customer outcomes, not just vulnerability counts. AI companies are attacking this problem at different stages: <a href="https://www.primesec.ai/">Prime Security</a> (this year's Black Hat Startup Champion) focuses on design-stage risk analysis before code is written, making the call that security needs to be woven into the product development process itself.</p><h3><strong>Final Thought</strong></h3><p>Black Hat 2025 made it clear: AI in security is no longer just a thought experiment, it&#8217;s operational, shaping how we reduce toil, test defenses, and even think about deterrence. From the expo floor to our own events, the energy, ideas, and debates reminded me why this community is so special. Huge thanks to all the security practitioners who joined us, and to our friends across the Decibel family and beyond; it was truly great to catch up! Looking forward to seeing you all again soon&#8230;ideally somewhere with a milder climate. </p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WhdE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WhdE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 424w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 848w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 1272w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WhdE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png" width="831" height="532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:831,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:685689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/170727652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WhdE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 424w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 848w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 1272w, https://substackcdn.com/image/fetch/$s_!WhdE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d7c4c8-4be2-4df2-a833-546fdbeccaeb_831x532.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PS: A big shoutout to my good friend <a href="https://www.linkedin.com/in/seanqsun/">Sean Sun</a> (founder of <a href="https://www.miscreants.com/">Miscreants</a>) for hosting an incredible (and much needed off strip) dinner with so many friends, teachers and creators in the security community that I have admired for a long time as I have been a student of the security industry.</p><p> </p>]]></content:encoded></item><item><title><![CDATA[Tokenomics #2: The Dream (and Risk) of Outcome-Based Pricing in AI Software]]></title><description><![CDATA[The price of success is knowing what success actually is&#8230; and what it costs to deliver.]]></description><link>https://dannguyenhuu.substack.com/p/tokenomics-2-the-dream-and-risk-of</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/tokenomics-2-the-dream-and-risk-of</guid><pubDate>Tue, 05 Aug 2025 13:25:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!90lP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p> Happy (Tokenomics) Tuesday!</p><p>One of my favorite books growing up was <em>The Rainmaker</em>. John Grisham's novel is about a young lawyer taking on insurance companies with nothing, but grit and a contingency fee arrangement. There's something brilliant about the economics in that story: the lawyer only gets paid if he wins, and when he does win, he gets paid very well. Perfect alignment of incentives, clear attribution of success, and a business model that puts the service provider's interests directly in line with the customer's outcome.</p><p>The outcome-based pricing conversation in regards of AI software is everywhere right now (and for good reason). It promises perfect alignment between buyer and vendor: only pay when value is delivered. In theory, it fixes everything wrong with SaaS seat-based bloat and unpredictable AI usage spikes. Instead of charging for effort, compute, or vague abstractions like "credits," you just charge for the thing the customer wants: results.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!90lP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!90lP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 424w, https://substackcdn.com/image/fetch/$s_!90lP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 848w, https://substackcdn.com/image/fetch/$s_!90lP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 1272w, https://substackcdn.com/image/fetch/$s_!90lP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!90lP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png" width="599" height="462" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:462,&quot;width&quot;:599,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71299,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!90lP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 424w, https://substackcdn.com/image/fetch/$s_!90lP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 848w, https://substackcdn.com/image/fetch/$s_!90lP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 1272w, https://substackcdn.com/image/fetch/$s_!90lP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30dab5c-1094-4141-9dc5-ae83519ede7c_599x462.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Replit&#8217;s founder Amjad talking about outcome-based pricing for AI</figcaption></figure></div><p>But that simplicity hides a deeper complexity.</p><p>Here's the real tension: <strong>in a sense,</strong> <strong>usage-based pricing is already a form of outcome-based pricing; just one where the model decides what the outcome is.</strong> You pay per token, per function, per interaction. But the "outcome" is inferred, often implicitly. Meanwhile, human-defined outcomes, like "issue resolved" or "churn prevented", are explicit, interpretable, and contract-worthy.</p><p>The trouble comes when those two diverge. If the model believes it completed the task, but the human disagrees? Or if a user drops off mid-flow and the vendor counts it as a resolution? That dissonance creates billing disputes, mistrust, and strategic risk.</p><p>This post is about that dissonance.</p><p>We'll explore the full spectrum of outcome-based pricing from deterministic work-completed to probabilistic success-shared. We'll walk through the four key quadrants of outcome design, define where different companies land, and unpack the risks of pricing outcomes before alignment is achieved.</p><div><hr></div><h3>What Most Companies Are Adopting Today</h3><p>In the current AI software market, pricing is trending towards the &#8220;hybrid&#8221; model. Hybrid pricing has taken over because it promises to solve the budgeting chaos of pure usage-based models while maintaining cost alignment with actual AI infrastructure. Most AI companies now combine base platform fees with usage tiers or credits so customers have predictable minimums, but variable final cost. Yet, hybrid models still have issues:</p><ol><li><p><strong>It's still hard to budget</strong> (usage spikes can blow through credit allowances)</p></li><li><p><strong>It doesn't guarantee value</strong> (you pay for platform access whether the AI delivers results or not)</p></li><li><p><strong>It adds complexity</strong> (customers now have to understand both subscription tiers and usage calculations)</p></li></ol><p>Outcome-based pricing promises to fix that. But to do it right, you need the model and the human to agree on what success means.</p><div><hr></div><h3>When the Model and the Human Disagree</h3><p>At the heart of outcome pricing is a question of <strong>definition</strong>. Who decides what counts as a completed task or a successful resolution?</p><ul><li><p>In usage-based pricing: <strong>The model</strong> defines success ("I returned a response, so I charged you X.").</p></li><li><p>In outcome-based pricing: <strong>The human</strong> defines success ("My problem was actually solved, so I pay you X.").</p></li></ul><p>When these are congruent, pricing aligns beautifully. When they're not, all hell breaks loose. This leads us to the core framework of this post.</p><h3>(Yet Another) 2x2 Framework</h3><p>The implementation of an outcome-based pricing model should consider the buyer&#8217;s objective(s). Is your offer a revenue driver? Or is it a cost center?</p><p>So this creates two critical dimensions:</p><ul><li><p><strong>What are you charging for?</strong></p><ul><li><p><strong>Work Completed (Task-Based)</strong> &#8594; Task finished, regardless of impact</p></li><li><p><strong>Upside Captured (Success-Based)</strong> &#8594; Pay only when business results land</p></li></ul></li><li><p><strong>What&#8217;s the buyer mindset?</strong></p><ul><li><p><strong>Cost Center</strong> &#8594; Budget sensitivity, efficiency metrics</p></li><li><p><strong>Revenue Driver</strong> &#8594; ROI-focused, outcome-oriented</p></li></ul></li></ul><p>Put those together and you get four pricing quadrants:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XDqm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XDqm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XDqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80843,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XDqm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!XDqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea4cfec0-723c-451c-af5a-983131bbe58d_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Ops Backbone (Cost Center &#215; Work Completed)</strong></p><ul><li><p>Think per-resolution pricing in support automation (e.g. Intercom Fin).</p></li><li><p>Focuses on replacing headcount and improving deflection.</p></li><li><p><strong>Risk:</strong> Optimizes for cost reduction, not necessarily customer satisfaction.</p></li></ul><p><strong>Skeptic&#8217;s Gambit (Cost Center &#215; Success-Based)</strong></p><ul><li><p>Classic chargeback or reimbursement models where vendors are only paid when cost avoidance is proven and verifiable.</p></li><li><p><strong>Example:</strong> Chargeflow only takes a cut (~25%) of recovered funds from successful disputes.</p></li><li><p><strong>Risk:</strong> Attribution is clear, but the volume is unpredictable. Cash flow is highly variable and may not justify vendor overhead unless win rates are strong.High burden of proof and slow cycles; trust and attribution are hard.</p></li></ul><p><strong>Volume Multiplier (Revenue Driver &#215; Work Completed)</strong></p><ul><li><p>Pricing tied to agent throughput&#8212;e.g. outbound emails, summaries, meetings scheduled.</p></li><li><p>Scales with activity, but not necessarily conversion.</p></li><li><p><strong>Risk:</strong> Over-incentivizes volume over quality; low gross margin if success rates are poor.</p></li></ul><p><strong>Skin-in-the-Game (Revenue Driver &#215; Success-Based)</strong></p><ul><li><p>The most aligned but riskiest quadrant: pay only when revenue impact is proven.</p></li><li><p>Seen in performance-based agents, like chargeback wins or upsell automation.</p></li><li><p><strong>Risk:</strong> Attribution complexity, lagged revenue, and long sales cycles.</p></li></ul><p>Each quadrant reveals a different risk-reward profile. Your margins and customer trust depend on pricing to match not just <em>what</em> is delivered, but <em>how</em> it's valued by the buyer.</p><h2>Modeling the Margins &#8212; Four Real-World Scenarios</h2><h3>Scenario 1: Customer Support AI </h3><p><em>(Work Completed &#215; Cost Center)</em></p><p><strong>The Promise:</strong> Intercom Fin charges $0.99 per resolution. Zendesk offers "pay only on successful automated resolutions." The value proposition is mathematical: 10x cost reduction compared to human support costs.</p><p><strong>Pricing Model:</strong> $1.20 per resolved ticket</p><h3>The Margin Reality by Resolution Type</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!er0c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!er0c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 424w, https://substackcdn.com/image/fetch/$s_!er0c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 848w, https://substackcdn.com/image/fetch/$s_!er0c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 1272w, https://substackcdn.com/image/fetch/$s_!er0c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!er0c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png" width="775" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:226,&quot;width&quot;:775,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!er0c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 424w, https://substackcdn.com/image/fetch/$s_!er0c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 848w, https://substackcdn.com/image/fetch/$s_!er0c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 1272w, https://substackcdn.com/image/fetch/$s_!er0c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a5cb30-95e9-4cb4-ab32-49fe5efdd9d3_775x226.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Why It's Aspirational:</strong> As Decagon discovered, "the vast majority of customers choose per-conversation" over per-resolution because definition disputes become a recurring nightmare. Customer support remains fundamentally a cost center, buyers optimize for predictable savings, not uncertain value alignment. What counts as a "resolution" becomes a recurring billing dispute, while "conversation handled" is black and white.</p><p>The procurement logic is simple: why pay for outcome complexity when you're just trying to reduce headcount costs? Even when customers say they want resolution-based pricing, cost center budgets drive them toward whatever delivers the lowest total spend, usually per-conversation pricing that runs 20% cheaper overall.</p><blockquote><p><strong>Tokenomics Takeaway</strong></p><p>Token cost is not the limiting factor. It's edge-case behavior (complex tickets + high escalation). Depending on distribution, margin flexs violently: if "complex" tickets rise from 10% &#8594; 25%, blended margin crashes.</p><p><strong>Cost center buyers choose simplicity over alignment</strong>, even when outcome pricing could theoretically offer better value.</p></blockquote><p></p><h3>Scenario 2: Fraud Detection AI</h3><p><em>(Upside Captured &#215; Cost Center)</em></p><p><strong>The Promise:</strong> Perfect outcome alignment. Customers only pay when fraud is actually prevented. Like AirHelp's 35% commission model for flight compensation, the attribution is crystal clear.</p><p><strong>Pricing Model:</strong> 15% of fraud losses prevented</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M9hw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M9hw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 424w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 848w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 1272w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M9hw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png" width="825" height="407" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:407,&quot;width&quot;:825,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M9hw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 424w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 848w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 1272w, https://substackcdn.com/image/fetch/$s_!M9hw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb049d37-4e3d-4b5a-8135-a40c21058daa_825x407.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Why It&#8217;s Aspirational:</strong><br>Success-based pricing sounds like a win-win. But fraud is not a binary outcome like a lawsuit, thereby it&#8217;s probabilistic. You still pay to run the model during quiet months. And every false positive comes with a cost (missed revenue, user friction).</p><p><strong>What We Actually Learn From Modeling It:</strong></p><ul><li><p>Revenue depends on fraud volume you can't predict or control.</p></li><li><p>Fixed costs don't scale down because infrastructure is always running an evaluating for fraud. </p></li><li><p>False positive tax compounds: every legitimate transaction blocked creates customer service costs and lost revenue that you subsidize, but don't get paid for.</p></li><li><p>Customer&#8217;s overall fraud prevention ecosystem improving means less fraud to prevent and monetize.</p></li><li><p>Attribution infrastructure is expensive, proving you earned commission requires costly reporting that eats into already thin margins.</p></li><li><p>Volatility compounds, monthly swings from 43% to -269% margin make financial planning impossible and investor confidence fragile.</p></li></ul><blockquote><p><strong>Tokenomics Takeaway</strong>: </p><p>You've tied revenue to external factors completely outside your control. Quiet fraud months aren't just lower revenue, they're losses while infrastructure costs continue. </p><p>You're exposed to seasonality, economic cycles, and ironically, your own success (less fraud = less revenue). This model only works if you can guarantee consistent baseline fraud activity. </p></blockquote><p></p><h3>Scenario 3: Sales AI SDR</h3><p><em>(Work Completed &#215; Revenue Driver)</em></p><p><strong>Company Profile:</strong> AI sales development platform for 200+ B2B companies <strong>Pricing</strong></p><p><strong>Model:</strong> $85 per qualified meeting booked + $3,500/month seat fee</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E8GQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E8GQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 424w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 848w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 1272w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E8GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png" width="772" height="526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:772,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E8GQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 424w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 848w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 1272w, https://substackcdn.com/image/fetch/$s_!E8GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dbafca7-8e67-44f8-aa86-057428609dd0_772x526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Why It&#8217;s Aspirational:</strong><br>The cost to get the job done keeps rising, but the price per meeting doesn&#8217;t. AI output is no longer enough&#8212;you need multi-agent orchestration, deep research, and adaptive touch sequences just to stay competitive.</p><p><strong>What We Actually Learn From Modeling It:</strong></p><ul><li><p>There&#8217;s a personalization arms race. What&#8217;s &#8220;good enough&#8221; today is table stakes tomorrow.</p></li><li><p>Every agent you add compounds overhead. 20&#8211;30% per handoff = death spiral without pricing power.</p></li><li><p>High margin today doesn&#8217;t protect you from tomorrow&#8217;s customer expectations.</p></li></ul><blockquote><p><strong>Tokenomics Takeaway</strong>: You're in an arms race where the cost to deliver "good enough" work rises faster than your pricing power. Today's 85% margins assume current personalization standards, but buyer expectations compound annually. Each new competitor raises the bar for what counts as a "quality" meeting, forcing you to add more agents, deeper research, and longer workflows, while your $85 per meeting stays fixed. You're essentially shorting your own industry's innovation curve.</p></blockquote><p></p><h3>Scenario 4: AI Upsell Engine</h3><p><em>(Upside Captured &#215; Revenue Driver)</em> </p><p><strong>The Promise</strong>: 15% commission on AI-generated upsell revenue </p><p><strong>Pricing Model</strong>: AI identifies opportunities, personalizes offers, executes outreach, only pay on closed deals**</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KvAk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KvAk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 424w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 848w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 1272w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KvAk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png" width="770" height="210" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:210,&quot;width&quot;:770,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34185,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169526365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KvAk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 424w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 848w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 1272w, https://substackcdn.com/image/fetch/$s_!KvAk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07399701-bfc5-4888-8acf-4b9d7680a70a_770x210.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>The Attribution War:</strong></p><p>Upsell Success Scenarios:</p><ul><li><p>AI-initiated, AI-closed: 25% of deals, 10% margin</p></li><li><p>AI-initiated, sales-closed: 60% of deals, split commission &#8594; 5% margin</p></li><li><p>Natural sales cycle (AI gets credit): 15% of deals, -130% margin</p></li></ul><p><strong>Why It's Aspirational:</strong> Sales teams fight every attribution decision. Did the AI "create" the opportunity or just identify an existing need? When sales reps close deals flagged by AI, who deserves credit? You're running expensive multi-touch campaigns while sales argues they would have found the upsell anyway. The more successful your AI becomes, the more sales pushes back on attribution.</p><blockquote><p><strong>Tokenomics Takeaway</strong>: You're building a business where your primary customer (sales leadership) has economic incentives to minimize your contribution. Every dollar you earn reduces sales team commission credit, creating internal political battles over attribution. Your margins get squeezed not by technology costs, but by organizational politics and revenue sharing disputes. You've created a model where success breeds resistance from the people who control your pipeline.</p></blockquote><p></p><h2>The Bigger Lesson: It's Not About the Numbers</h2><p>Here's what this modeling exercise actually reveals (as of course all the numbers were illustrative): Outcome-based pricing isn&#8217;t just a billing strategy that you can (or should) implement overnight. It requires deeper thinking to make sure model-determined work will match human-defined value. But when those diverge, even slightly, your margins can vanish, your trust can erode, and your contracts can implode.</p><p>The truth is, outcomes live on a gradient ranging from atomic actions to economic impact. The further you travel toward success-based pricing, the more you depend on humans to confirm that value was real, contextual, and worth paying for. That&#8217;s where risk concentrates.</p><p>Each quadrant we explored tells a different story:</p><ul><li><p><strong>Customer Support AI</strong> showed us that resolution counts hide escalating complexity.</p></li><li><p><strong>Fraud AI</strong> reminded us that even perfect success can be invisible during a quiet month.</p></li><li><p><strong>Sales AI SDR</strong> revealed that the bar for "done" keeps rising, but the price doesn&#8217;t.</p></li><li><p><strong>AI Upsell Engine</strong> exposed that your biggest customer (sales leadership) has economic incentives to minimize your contribution.</p></li></ul><p>So if you&#8217;re building in this world, the real decision isn&#8217;t just <em>what</em> to charge for. It&#8217;s <em>whose definition of value you trust</em> and how often you expect it to be wrong. </p>]]></content:encoded></item><item><title><![CDATA[Welcome to Human Risk University ]]></title><description><![CDATA[You don&#8217;t need SAT (Security Awareness Training) to get in, but it helps.]]></description><link>https://dannguyenhuu.substack.com/p/welcome-to-human-risk-university</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/welcome-to-human-risk-university</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Wed, 30 Jul 2025 14:25:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nuzo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nuzo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nuzo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 424w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 848w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 1272w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nuzo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png" width="1456" height="958" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:958,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3112927,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169621327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nuzo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 424w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 848w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 1272w, https://substackcdn.com/image/fetch/$s_!nuzo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09772b3-6f14-4ab1-adeb-dcc9d67102fd_1492x982.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>A fresh look at security awareness in the age of AI</h3><p>On a January morning in Hong Kong, a finance clerk joined what looked like a routine video call with the company&#8217;s CFO. The voice, the mannerisms, even the virtual backdrop, flawless. But the &#8220;executive&#8221; wasn&#8217;t real. It was an AI-generated deepfake. Fifteen wire transfers <a href="https://www.secureworld.io/industry-news/hong-kong-deepfake-cybercrime?">later, $25 million</a> was gone.</p><p>Just a few months later, another unsettling moment made headlines: someone used an AI-cloned voice of <a href="https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/?">U.S. Senator Marco Rubio</a> to impersonate him in a Signal call to government officials. The goal? Social engineering at a geopolitical scale.</p><p>Incidents like these make one thing clear: people, not endpoints, are the new perimeter. And the old model, reminding employees not to click on links once a quarter, is no defense against adversaries armed with generative AI, voice cloning, and real-time deception.</p><div><hr></div><h3>Security Awareness Was Always a Compliance Checkbox</h3><p>For most of the past decade, Security Awareness Training (SAT) has been viewed as a formality. A quarterly fire drill. Employees sat through a video, passed a quiz, and forgot the content before lunch. It wasn&#8217;t really about behavior change. It was about satisfying audit requirements.</p><p>That&#8217;s changing. In boardrooms across industries, CISOs are ripping out KnowBe4 and Proofpoint contracts, not because phishing went away, but because it evolved. Today&#8217;s attacks are more targeted, more dynamic, and disturbingly convincing. &#8220;Awareness&#8221; alone just doesn&#8217;t cut it.</p><div><hr></div><h3>A Short History of a Long-Suffering Category</h3><p>SAT took off in the 2010s as regulatory pressure and cyber insurance mandates created budget for anything that looked like training. A few players rode the wave:</p><ul><li><p><strong>KnowBe4</strong> went public in 2021, then was taken private by Vista Equity in 2023 for $4.6B.</p></li><li><p><strong>PhishMe</strong> (later Cofense) sold to a PE consortium for around $400M.</p></li><li><p><strong>Wombat Security</strong> was acquired by Proofpoint for $225M in 2018; Proofpoint itself was later taken private for $12.3B.</p></li></ul><p>What they offered was simple: phishing simulations, templated training, and dashboards to check the compliance box. The moat was content scale, localized modules, integrations with email gateways, and wide distribution via MSPs. It worked, but only because the threat model was basic. Many of us still remember those hilariously bad phishing emails with typos and Comic Sans. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hPhr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hPhr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 424w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 848w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 1272w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hPhr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png" width="746" height="518" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:518,&quot;width&quot;:746,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hPhr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 424w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 848w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 1272w, https://substackcdn.com/image/fetch/$s_!hPhr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf808c91-8d6b-4af8-8bb2-488c430be0c8_746x518.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Why the Old Moats No Longer Hold</h3><p>Fast-forward to 2025, and those same content libraries feel archaic. Users ignore hour-long training. Attackers move faster than update cycles. Phishing-as-a-Service kits now bundle LLM-generated lures, MFA bypass pages, QR-code bait, and more, all for less than a Spotify subscription.</p><p>Voice-based attacks are no longer novelty edge cases. Deepfake tools can clone a colleague&#8217;s voice from a few seconds of audio. The result? A simple phone call can become a high-stakes social engineering vector.</p><p>In this world, &#8220;click-to-comply&#8221; training is theater. The threats are adaptive and real-time. Defenses need to be too.</p><div><hr></div><h3>From Training to Risk Intelligence</h3><p>The next generation of vendors aren&#8217;t in the training business. They&#8217;re in the business of human telemetry, quantifying, modeling, and reducing behavioral risk. This shift is giving rise to a new architecture built on five principles:</p><p><strong>1. Per-user risk scoring</strong><br>Modern platforms ingest identity, privilege, behavioral signals, and phishing test outcomes to create dynamic risk scores. These scores can flow into SIEM, XDR, IAM, even HR.</p><p><strong>2. Just-in-time micro-nudges</strong><br>Instead of annual training, users get real-time interventions: 60&#8211;90 second nudges triggered by specific risky behaviors, like credential reuse or clicking a suspicious link.</p><p><strong>3. Consequences over certificates</strong><br>Some platforms integrate with IAM tools to enforce access guardrails. A user who fails three phish tests might have app access temporarily throttled, automatically reducing blast radius without waiting for IT.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wdCY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wdCY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 424w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 848w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 1272w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wdCY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png" width="1200" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1837332,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169621327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!wdCY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 424w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 848w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 1272w, https://substackcdn.com/image/fetch/$s_!wdCY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7fed960-ecd7-4cec-a605-5b0091e283a2_1200x800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. Behavior-driven content and closed-loop feedback</strong><br>LLMs are used to auto-generate hyper-relevant training based on role, region, and recent behavior. Some systems allow security teams to feed real-world incidents into the engine, creating simulations that mirror actual threats. Some vendors are even exploring <strong>incident replays</strong>, interactive walkthroughs of real BEC attempts or deepfake voice scams, to help employees learn directly from modern attack chains.</p><p><strong>5. Adaptive learning paths and gamification</strong><br>Instead of static modules, emerging platforms are using performance data to personalize a user&#8217;s learning path over time, reinforcing weak points and skipping what&#8217;s already known. Some have even added <strong>light gamification</strong> elements, like team-based progress dashboards or behavioral leaderboards, to create healthy competition and engagement across departments.</p><p>The goal is no longer to &#8220;teach better&#8221; but rather to reduce the probability, and impact, of human error.</p><div><hr></div><h3>What Makes This a Moat Business Now?</h3><p>In the 2010s, defensibility came from content scale. In the 2020s, it comes from behavioral depth.</p><p>With GenAI, personalized content is cheap. What matters now is the richness of human telemetry, signals across identity, endpoint, cloud, and behavior. That telemetry powers better detection, better response, and better insurance underwriting.</p><p>And unlike static training modules, behavioral telemetry compounds. The more signals and systems a platform connects to, the more valuable, and thereby sticky, it becomes. This is why CISOs are exploring whether human risk platforms could either feed UEBA systems or serve as lightweight UEBA alternatives.</p><div><hr></div><h3>Where It&#8217;s All Going</h3><p>Security Awareness Training will likely fade as a standalone category. In its place, we&#8217;ll see <strong>Human Risk Management</strong> emerge as a control layer between identity, detection, and compliance systems. Risk scores will drive conditional access. They&#8217;ll show up in board packets. They may influence insurance underwriting and even employee risk evaluation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3SI7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3SI7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3SI7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/169621327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3SI7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!3SI7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b71eb4b-799c-44ab-88a5-c010343e2a3e_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To make this a reality, some teams are already pushing the envelope:</p><ul><li><p><strong>Phishing threat intel</strong> feeds are being piped directly into simulation engines to keep lures current.</p></li><li><p><strong>Security team playbooks</strong> are auto-triggered based on escalating user risk.</p></li><li><p><strong>Employees are getting access to their own risk dashboards</strong>, giving them agency and visibility into their own posture.</p></li></ul><p>The next $4B exit won&#8217;t be for a content library. It&#8217;ll be for a telemetry engine that connects human behavior to machine response. Because in an era of deepfakes and AI-driven deception, awareness isn&#8217;t protection. Instrumentation is.</p>]]></content:encoded></item><item><title><![CDATA[Tokenomics #1: The Pricing Evolution of AI Coding Agents]]></title><description><![CDATA[The price of code is eternal vigilance.]]></description><link>https://dannguyenhuu.substack.com/p/tokenomics-1-the-pricing-evolution</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/tokenomics-1-the-pricing-evolution</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 22 Jul 2025 13:58:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z3X3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Happy (Tokenomics) Tuesday!</p><p>Back in 2023, I wrote a post called <em><a href="https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion">The Price is AI-ght</a></em> about how early AI-native startups were starting to wrestle with pricing and how seat-based models were already starting to crack under the weight of unpredictable usage. Since then, the market hasn&#8217;t exactly stabilized, but rather has progressed at a rapid rate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GwGL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GwGL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 424w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 848w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GwGL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png" width="1456" height="793" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:793,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:343124,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GwGL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 424w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 848w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!GwGL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0c36820-7ada-4216-9dac-ab8bd8e12bf8_2932x1596.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion">The Price is AI-ght</a></figcaption></figure></div><p>We&#8217;ve seen companies experiment with everything from flat rates to token caps, credit systems, and abstracted compute units. Some of the early bets have broken down in public while others are still figuring out how to align real costs with perceived value.</p><p><strong><a href="https://dannguyenhuu.substack.com/p/welcome-to-tokenomics">Tokenomics</a></strong> is my attempt to unpack that. It&#8217;s a running study on how AI companies make money, where the cost centers really are, and what kind of business models will actually scale.</p><p>Things are still in flux, but asking the right questions early matters. If you're a founder building in this world, I hope this is helpful to you! </p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z3X3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z3X3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z3X3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128945,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z3X3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3X3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa77cf763-6b7b-42da-aec0-ce1a40f88868_1200x630.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>The Pricing Evolution of AI Coding Agents: From Per-Repo to Compute Units</h1><p>Pricing in the AI world is still early and unsettled. There are a lot of variables in play: how customers use the product, how often they interact with it, what agents are doing in the background, and what the underlying model providers are charging. Most founders I talk to are still figuring out how to balance predictable revenue with unpredictable costs.</p><p>This week, I'm diving deeper into how developer tools have evolved their pricing models over the years, why Cursor's recent pricing change stirred up so much controversy, and what the rise of agent swarms means for the future of devtool economics.</p><p>To understand where we're headed, I've taken a look the current pricing strategies of some of the major AI coding tools: <a href="http://cursor.com">Cursor</a>, <a href="https://app.devin.ai/">Devin</a>, <a href="https://www.anthropic.com/claude-code">Claude Code</a>, <a href="https://v0.dev/">v0</a>, <a href="http://bolt.new">Bolt,</a> <a href="https://openai.com/codex/">Codex</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://lovable.dev/">Lovable</a>.</p><p>Each model tells a story about token economics, market positioning, and the search for sustainable AI pricing.</p><h2>Five Phases of Developer Tool Pricing</h2><h3>Phase 1: Per-Repository Era (2008-2014)</h3><p>First, a quick turn back in time: GitHub started simple in 2008 with a freemium model based on private repositories. Public repos were free, and you paid for privacy. In 2011, <a href="https://gist.github.com/juderosen/8410710">a "Micro" plan cost $7/month for 5 private repos, while a "Medium" plan ran $12 </a>for 10. GitLab followed a similar model, focusing on features gated by tiers rather than user count.</p><p><strong>Why it worked:</strong> Developers often worked solo or in small teams. Metering access to private code, not people, aligned with real usage patterns of the time.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P08b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P08b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 424w, https://substackcdn.com/image/fetch/$s_!P08b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 848w, https://substackcdn.com/image/fetch/$s_!P08b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 1272w, https://substackcdn.com/image/fetch/$s_!P08b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P08b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png" width="677" height="645" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:645,&quot;width&quot;:677,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71879,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P08b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 424w, https://substackcdn.com/image/fetch/$s_!P08b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 848w, https://substackcdn.com/image/fetch/$s_!P08b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 1272w, https://substackcdn.com/image/fetch/$s_!P08b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bea1227-e2df-4e74-ad69-bb9e0bdd8138_677x645.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: https://developerhowto.com/2019/01/10/github-is-now-offering-unlimited-private-repos-for-free/</figcaption></figure></div><h3>Phase 2: Per-Seat Enterprise (2015-2020)</h3><p>As usage shifted from solo developers to teams, both GitHub and GitLab introduced per-seat pricing. GitHub Team and GitHub Enterprise charged $4&#8211;$21 per user/month depending on features. The shift made sense: collaboration became the primary value driver, and per-seat pricing mapped cleanly to team structure and enterprise budgets.</p><p><strong>Why the shift:</strong> Enterprises needed budgeting clarity. As more companies adopted CI/CD and DevOps pipelines, tools scaled across large teams. IT procurement teams preferred clear pricing per developer, and unit economics became more predictable.</p><p>This model helped turn devtools into big business. GitHub had around 28 million users when Microsoft acquired it for $7.5 billion in 2018. GitLab went public in 2021 and now serves more than 30 million users with $500M+ ARR. The key thing: pricing was never about compute. It was about developers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7nDy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7nDy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 424w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 848w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 1272w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7nDy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png" width="896" height="504" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:504,&quot;width&quot;:896,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Screenshot of GitHub's pricing tiers.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot of GitHub's pricing tiers." title="Screenshot of GitHub's pricing tiers." srcset="https://substackcdn.com/image/fetch/$s_!7nDy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 424w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 848w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 1272w, https://substackcdn.com/image/fetch/$s_!7nDy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2526c29d-ccaf-42a9-b6ab-1c7e09ff3eda_896x504.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://wptavern.com/github-opens-free-plan-to-unlimited-collaborators-on-private-repositories</figcaption></figure></div><p></p><h3>Phase 3: Flat-Fee AI Augmentation (2021-2023)</h3><p>GitHub Copilot entered in 2021 with a new twist&#8212;AI assistance priced at a flat $10/month per user. It didn't matter how much you used it. The value was in seamless integration and predictable cost, abstracting away the complexity of token consumption.</p><p><strong>Why it gained traction:</strong> Copilot was cheap, worked within VS Code, and offered high perceived ROI for daily coding tasks. Predictability trumped cost control, and developers didn't need to think about usage limits. </p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4RbC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4RbC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 424w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 848w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 1272w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4RbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png" width="1095" height="952" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:952,&quot;width&quot;:1095,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:507678,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4RbC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 424w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 848w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 1272w, https://substackcdn.com/image/fetch/$s_!4RbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa638cf97-38cf-4a84-9915-1f9dd8f63b09_1095x952.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://github.blog/news-insights/product-news/github-copilot-is-generally-available-to-all-developers/</figcaption></figure></div><p></p><h3>Phase 4: Flat-Rate with Usage Caps (2023-2024)</h3><p>Then came Cursor in 2023.</p><p>At $20/month for the Pro plan, users got up to 500 "requests" per month; a flat subscription fee with a usage ceiling. This wasn't true usage-based pricing; users didn't pay per token or per API call. Instead, they paid a predictable monthly fee but were capped at an abstract number of "requests."</p><p><strong>Why this worked initially:</strong> In the early days of AI coding tools, usage patterns were relatively light and predictable. Most requests were simple completions or small code generations. The abstracted limits felt generous, and few users hit their caps.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f_F_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f_F_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 424w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 848w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 1272w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f_F_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png" width="700" height="349" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:349,&quot;width&quot;:700,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f_F_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 424w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 848w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 1272w, https://substackcdn.com/image/fetch/$s_!f_F_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b48ceb1-2fa5-4b5c-b4ad-4dbf12a4c725_700x349.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://cursor.com</figcaption></figure></div><h2>The Cursor Controversy: When Flat-Rate Pricing Breaks</h2><p>By June 2025, Cursor's economics had become untenable. As the product matured, power users started chaining together complex multi-step agents, piping in huge context windows, and running long, compute-heavy sessions. What looked like a flat subscription on the surface was burning through API credits underneath. </p><p>In the meantime, Cursor continued to experience breakneck growth and saw its annual recurring revenue breach the $500 million mark by June 2025, after revenue doubling roughly every two months.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VmoW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VmoW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 424w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 848w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 1272w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VmoW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png" width="1456" height="1881" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1881,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1386223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VmoW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 424w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 848w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 1272w, https://substackcdn.com/image/fetch/$s_!VmoW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fb064c9-2c6a-4007-bda1-464b88a8f00d_1610x2080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://x.com/saastr/status/1946501768109604965/photo/1</figcaption></figure></div><p>The company was forced to respond. Overnight, it dropped request-based pricing entirely and moved to a hybrid usage-based billing system grounded in token consumption. The new Ultra plan, for heavy users was priced at $200/month and offered ~20x more usage, but the Pro plan introduced hard limits based on compute consumption, not requests.</p><p><strong>The backlash was swift.</strong> Developers were used to Copilot-style predictability. They didn't expect to face massive overages under a $20 plan. Some users reported bills of over $1,000 in a single month. Cursor was forced to introduce more transparent dashboards, offer refunds, and respond to community criticism.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nUai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nUai!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 424w, https://substackcdn.com/image/fetch/$s_!nUai!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 848w, https://substackcdn.com/image/fetch/$s_!nUai!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 1272w, https://substackcdn.com/image/fetch/$s_!nUai!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nUai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png" width="927" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/009239bb-07d4-454a-a475-0ba243281b85_927x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:927,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94576,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nUai!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 424w, https://substackcdn.com/image/fetch/$s_!nUai!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 848w, https://substackcdn.com/image/fetch/$s_!nUai!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 1272w, https://substackcdn.com/image/fetch/$s_!nUai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F009239bb-07d4-454a-a475-0ba243281b85_927x612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://cursor.com/blog/june-2025-pricing</figcaption></figure></div><p>To their credit, the Cursor team responded swiftly and constructively. Within days, they issued public explanations, offered refunds to affected users, launched clearer usage dashboards, and allowed existing annual subscribers to retain the old request-based plan until renewal. They also clarified the new system&#8217;s controls, including spending caps and model routing options, to restore trust and transparency.</p><div><hr></div><p><strong>But what about the others?</strong></p><h2>Phase 5: Abstracted Usage Units (2024-Present)</h2><p>The newest evolution attempts to solve the token complexity problem by abstracting usage into more intuitive units that still map to underlying costs. To understand how this plays out in practice, I looked into the other seven leading AI development tools.</p><h3>Devin: Agent Compute Units</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L7sS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L7sS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 424w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 848w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 1272w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L7sS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png" width="1453" height="938" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:938,&quot;width&quot;:1453,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:370874,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L7sS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 424w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 848w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 1272w, https://substackcdn.com/image/fetch/$s_!L7sS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb7b22a8-29f3-423d-80a7-8a652c7ee521_1453x938.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://devin.ai/pricing</figcaption></figure></div><p>Devin's Agent Compute Unit (ACU) is a normalized measure that bundles together all computational resources (think virtual machine time, model inference, and networking bandwidth) into a single unit representing approximately 15 minutes of active AI development work.</p><p>The Core plan charges $2.25 per ACU with pay-as-you-go billing, while the Teams plan includes 250 ACUs at $2.00 each.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3fpz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3fpz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 424w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 848w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 1272w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3fpz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png" width="414" height="337" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:337,&quot;width&quot;:414,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37766,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3fpz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 424w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 848w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 1272w, https://substackcdn.com/image/fetch/$s_!3fpz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6166816a-d2ef-47ef-8be2-6730bf17f354_414x337.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://devin.ai/pricing</figcaption></figure></div><p>As each ACU represents approximately 15 minutes of "active Devin work," the $20 entry plan is equivalent to about 2.25 hours of work.</p><p>Which may not seem like much at first glance, but Devin 2.0 now completes over 83% more junior-level development tasks per ACU compared to its predecessor, nearly doubling the output per unit.</p><blockquote><p><strong>Tokenomics Takeaway:</strong> Devin has created units that abstract away model complexity while maintaining meaningful cost correlation. Variable task complexity is baked into the unit calculation, making pricing more predictable for users while preserving unit economics. </p></blockquote><p></p><h3>Claude Code: Tiered Subscription &amp; Model Ownership</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oDcb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oDcb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 424w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 848w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 1272w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oDcb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png" width="1456" height="568" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:568,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105244,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oDcb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 424w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 848w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 1272w, https://substackcdn.com/image/fetch/$s_!oDcb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53a8a572-709d-4c1b-9cb5-b4df4c003399_1506x587.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Claude Code operates on a tiered subscription model: Pro ($20/month) provides 10-40 prompts every 5 hours for small repositories, while Max plans offer 5x ($100/month) and 20x ($200/month) usage with 200-800 prompts every 5 hours for larger codebases.</p><p>Starting at $17 per month for individual developers, with enterprise plans reaching significantly higher price points, Claude Code has seen 300% active user growth and 5.5x revenue growth since launching Claude 4 models in May.</p><p>Pro subscribers can only access Sonnet 4, while Max subscribers can switch between Sonnet and Opus 4 models using the /model command. The platform targets organizations with dedicated AI enablement teams and substantial development operations.</p><blockquote><p><strong>Tokenomics Takeaway:</strong> Claude Code's tiered approach works because Anthropic owns the underlying models, giving them a significant cost advantage over competitors paying third-party API fees. While we don't know their exact internal compute costs, this vertical integration likely allows much higher gross margins than tools like Cursor that were paying full API rates.</p></blockquote><p></p><h3>v0: Mapping Pricing to User Value</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_uvw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_uvw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 424w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 848w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 1272w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_uvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png" width="1295" height="493" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:1295,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_uvw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 424w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 848w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 1272w, https://substackcdn.com/image/fetch/$s_!_uvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06d5616c-54f4-4143-a9cb-3c4804915c0b_1295x493.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Vercel&#8217;s v0 reveals a strategic use of AI tooling to reinforce their broader platform ecosystem. Their credit-based pricing model aligns costs with actual token consumption while driving adoption of their core infrastructure.</p><p>v0 operates on a credit system where users receive monthly credit allowances: Free ($5), Premium ($20), Team ($30/user), and Enterprise (custom). Credits are consumed based on actual token usage across different model tiers, with v0-1.5-lg costing $7.50 per million input tokens and $37.50 per million output tokens, while smaller models like v0-1.5-sm cost significantly less at $0.50/$2.50 per million tokens.</p><p>The platform includes relevant context like chat history, source files, and Vercel-specific knowledge when generating responses, with this context counted as input tokens. Crucially, v0 heavily favors Next.js in its code generation (another Vercel product) creating a natural pathway from AI-assisted development to their hosting and deployment platform.</p><blockquote><p><strong>Tokenomics Takeaway:</strong> v0's transparent token-based pricing maps directly to user value perception while serving a larger strategic purpose. Users pay for actual compute consumption rather than abstract units, but more importantly, the tool generates Next.js applications that naturally deploy on Vercel's infrastructure. The AI tool becomes a customer acquisition engine for their core hosting business by making Vercel deployment the obvious next step after code generation.</p></blockquote><p></p><h3>Lovable: Transparent Task-Based Agent Pricing</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h7-u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h7-u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 424w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 848w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 1272w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h7-u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png" width="1052" height="700" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1052,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h7-u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 424w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 848w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 1272w, https://substackcdn.com/image/fetch/$s_!h7-u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ec4850-7882-4db8-8a00-7fa7f1b7ff01_1052x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Lovable has evolved beyond simple message-based pricing to introduce a more sophisticated agent pricing model that charges based on the actual complexity and scope of work performed. While Default and Chat modes still cost 1 credit per message, their Agent Mode uses dynamic pricing that reflects the computational effort required for each task.</p><p>The Pro plan ($25/month) provides 100 monthly credits plus 5 daily credits (totaling up to 150 credits per month), with unused monthly credits rolling over. Agent Mode pricing varies significantly based on task complexity: removing a footer costs 0.90 credits, adding full authentication with sign-up and login costs 1.20 credits, while building a complete landing page with generated images runs 1.70 credits.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rm6K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rm6K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 424w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 848w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 1272w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rm6K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png" width="985" height="553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:553,&quot;width&quot;:985,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124575,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rm6K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 424w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 848w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 1272w, https://substackcdn.com/image/fetch/$s_!rm6K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f33a06-0048-47a7-ba69-49f7d8985536_985x553.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a fundamental shift from uniform pricing to outcome-based billing. Simple edits and removals cost less than a full credit, while complex multi-component builds cost more. Users can see the exact cost of each message by hovering over message options in their history.</p><blockquote><p><strong>Tokenomics Takeaway:</strong> Lovable's approach addresses one of the core problems in AI tool pricing: the massive variance in computational work between simple and complex requests. What sets them apart is the radical transparency: users can see the exact cost of each individual message by hovering over message options in their history. By moving to task-complexity pricing in Agent Mode with full cost visibility, they've created a model where users pay more fairly for what they actually get while understanding exactly what each interaction costs. </p></blockquote><h3>OpenAI Codex (non-API): The Subscription-Freebie (for now?)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_CLW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_CLW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 424w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 848w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 1272w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_CLW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png" width="1456" height="828" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:240576,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_CLW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 424w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 848w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 1272w, https://substackcdn.com/image/fetch/$s_!_CLW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae1baca-17f7-4ac4-8416-802ee44155ea_1604x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Being still in early access, OpenAI's Codex is included with ChatGPT Pro ($200/month), Enterprise, Team, and Plus subscriptions, providing "generous access at no additional cost" during the initial rollout period, after which rate limits and on-demand pricing will apply. </p><blockquote><p><strong>Tokenomics Takeaway:</strong> Time will tell when they release pricing.</p></blockquote><h3>Bolt.new: Flat Fee, Token Ceilings</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bwx_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bwx_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 424w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 848w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bwx_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png" width="1456" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:308129,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bwx_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 424w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 848w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!bwx_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F242c564f-202e-42ba-bd63-74fa0b28aac3_2570x1294.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bolt presents itself as the simple option: $0 to start, $20/month for Pro, and $30/month per user for Teams. But behind the clean UI is a usage model that centered around tokens.</p><p>The free plan comes with 1 million tokens per month and a 150K daily limit. Which is enough for basic usage, but you hit the daily cap almost immediately when trying to build anything with complexity. The Pro plan bumps you up to 10 million tokens per month, removes the daily cap, and allows unused tokens to roll over. The Teams tier adds admin features like centralized billing and access controls, but keeps the same usage base.</p><p>There&#8217;s no per-request or per-agent billing here, just token ceilings. And while &#8220;unlimited&#8221; isn&#8217;t part of the pitch, the framing still feels generous compared to some of the newer credit-based or task-metered models. That said, the token cap means power users (especially those experimenting with background agents or long context windows) will need to track usage, even on paid plans.</p><p>What sets Bolt apart is actually the integrated development environment. Unlike tools that operate as plugins or external agents, Bolt provides a complete IDE where you can code, preview, and deploy full-stack applications entirely in the browser. This also means that users can modify code without spending tokens (especially helpful in getting out of those pesky troubleshooting loops that can burn tokens). </p><blockquote><p><strong>Tokenomics Takeaway: </strong>Bolt&#8217;s pricing looks flat, but it&#8217;s grounded in hard token ceilings. It&#8217;s a middle ground between flat-rate simplicity and usage-based fairness making it more predictable than credit-based models, but still constrained. Bolt&#8217;s approach creates stronger user lock-in than standalone coding assistants, as switching costs include not just the AI tool but the entire development workflow. The token-based pricing works within this model because users are paying for platform access, not just AI interactions.</p></blockquote><h3>Replit: Effort-Based Pricing via &#8220;Checkpoints&#8221;</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zj90!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zj90!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 424w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 848w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 1272w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zj90!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png" width="1456" height="553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:553,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152603,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zj90!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 424w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 848w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 1272w, https://substackcdn.com/image/fetch/$s_!Zj90!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0fa51e3-5af2-4783-96e8-68d9560192c1_1714x651.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Replit&#8217;s pricing page has an interesting strategy, comparing the money you spend to money you recieve ($20/month for $25 worth of credits). Though, &#8220;credits&#8221; seems opaque since there isn&#8217;t an immediate way to calculate the value or output you&#8217;ll get from $25 worth of Replit credits. But diving deeper into their effort-based pricing blog, it&#8217;s actually quite interesting. <a href="https://blog.replit.com/effort-based-pricing-recap">Read it here.</a></p><p>Replit rolled out an effort-based pricing model in mid-2025 that charges users based on the actual complexity of each task, rather than by token or message count. The system uses &#8220;checkpoints&#8221; to measure work, so instead of every request costing the same, simpler edits (like renaming a variable) might cost a few cents, while more involved tasks (like building a new component) cost more. </p><p>Each checkpoint&#8217;s price is visible in the interface, and usage rolls up into a monthly credit allowance ($25 on the Core plan, $40 per user on Teams) with the goal to make pricing more aligned with actual work done. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uUVj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uUVj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 424w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 848w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 1272w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uUVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png" width="1456" height="1177" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1177,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uUVj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 424w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 848w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 1272w, https://substackcdn.com/image/fetch/$s_!uUVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3eb985d3-086c-4e63-a719-bce02f230260_2048x1656.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">https://blog.replit.com/effort-based-pricing-recap</figcaption></figure></div><blockquote><p><strong>Tokenomics Takeaway:</strong> Replit&#8217;s effort-based pricing is an attempt at turning usage-based into something closer to &#8220;customer value&#8221;. But since it&#8217;s hard to quantify value, I think &#8220;effort&#8221; is an apt name. It seems pretty similar to Lovable&#8217;s agent and complexity-based pricing, but there&#8217;s something there in calling it &#8220;effort-based&#8221;.</p></blockquote><h2>What This All Means for Founders</h2><p>The evolution of developer tool pricing reveals several critical lessons:</p><p><strong>Flat-rate pricing isn't inherently wrong</strong> &#8212; especially in the early days, it&#8217;s still a great way to win when introducing new behaviors. Your first job isn't to maximize revenue; it's to build habits. Both Cursor and GitHub Copilot succeeded initially with flat pricing.</p><p><strong>Transparent usage dashboards aren't optional</strong> in the AI era. Customers need to (and will soon demand to) understand  their consumption patterns before they hit surprise bills. The tools with the smoothest transitions all invested heavily in usage visibility.</p><p><strong>Hybrid models (base + credits) give predictability without unlimited exposure.</strong> Having predictable costs will still make the deal more tenable for enterprise procurement teams. Many AI-native tools are converging on this approach, though they implement it differently.</p><p><strong>Abstraction can solve complexity</strong>, but requires careful design. Units should map meaningfully to both real costs and user value perception.</p><div><hr></div><h2>The Next Potential Tipping Point: Agent Swarms</h2><p>The next wave of disruption won't be from individuals building faster; it'll be from code writing itself in swarms. Agentic development tools are showing us what happens when you give five agents the ability to coordinate, refactor, and reason about an entire codebase simultaneously. </p><p>Swarm-based workflows introduce powerful new capabilities like full-codebase refactoring and speculative scaffolding, but they also risk blowing up cost models entirely. What used to be a single developer calling the model a few times per day becomes 5&#8211;10 agents each calling different tools, running context windows in parallel, and looping over 1,000+ documents to complete a task. With no human in the loop, token consumption may become unpredictable and uncapped. </p><p><a href="https://www.linkedin.com/posts/adriancockcroft_i-was-chatting-to-kent-beck-today-about-how-activity-7351115423532109825-7oXA?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABsYpyoB9d9pcItdgNB_s_T1NGsgWTKatdw">Adrian Cockcroft's Example on Swarms at Work</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qxdq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qxdq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 424w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 848w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 1272w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qxdq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png" width="574" height="707" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:707,&quot;width&quot;:574,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:457760,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/168523677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qxdq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 424w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 848w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 1272w, https://substackcdn.com/image/fetch/$s_!Qxdq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1be0c7-187d-4b34-a18c-92e03545d771_574x707.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Developer tools are going through a pricing reset similar to its technological counterpart. As AI becomes more embedded, looping in the background, calling tools, writing code autonomously, flat fees and per-seat models start to break down. Each tool is handling it differently: Cursor moved from requests to tokens, Devin bundles compute into time-based units, and Bolt keeps things simple with monthly token caps. There&#8217;s no perfect answer yet, but one thing&#8217;s clear: pricing now has to reflect real compute costs, not just user count. And as multi-agent workflows become more common, those costs are only going to get harder to predict.</p>]]></content:encoded></item><item><title><![CDATA[Welcome to Tokenomics]]></title><description><![CDATA[Exploring how AI-native companies price, package, and scale when costs are driven by inference tokens rather than traditional infrastructure.]]></description><link>https://dannguyenhuu.substack.com/p/welcome-to-tokenomics</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/welcome-to-tokenomics</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Thu, 17 Jul 2025 00:40:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/25dd9374-9634-486c-92d8-d3a72b40e2da_840x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Welcome to </strong><em><strong>Tokenomics</strong></em><strong> &#8212; a new series from Founder Catalyst.</strong></p><p>AI is rewriting the economics of enterprise software. Instead of seats and servers, we now measure value in tokens, context windows, and compute. This shift doesn&#8217;t just change how you build, it changes how you make money.</p><p>In this newsletter, we&#8217;ll explore the emerging business models behind AI-native companies: how they price, package, and scale in a world where your cost of goods is driven by inference, not infrastructure. We&#8217;ll cover topics from unit economics to go-to-market mechanics, and occasionally challenge some sacred SaaS assumptions along the way.</p><p>If you&#8217;re building and betting on the future of enterprise AI, <em>Tokenomics</em> is your field guide. </p>]]></content:encoded></item><item><title><![CDATA[Ctrl+Alt+Deceit: An Update on AI-Based Cyber Attacks]]></title><description><![CDATA[Close to three years after ChatGPT ignited mainstream generative-AI adoption, the offensive side of the security equation is making huge strides.]]></description><link>https://dannguyenhuu.substack.com/p/ctrlaltdeceit-an-update-on-ai-based</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/ctrlaltdeceit-an-update-on-ai-based</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Mon, 02 Jun 2025 13:30:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cxyG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cxyG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cxyG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cxyG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2355728,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/164816614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cxyG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!cxyG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdca3f630-8db3-457b-8ce6-ef442041de93_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Close to three years after ChatGPT ignited mainstream generative-AI adoption, the offensive side of the security equation is making huge strides. When I first talked about <em><a href="https://dannguyenhuu.substack.com/p/the-era-of-the-autonomous-defense">the Era of the Autonomous Defense</a></em> and the inevitability of <em><a href="https://dannguyenhuu.substack.com/p/proudly-offensive-the-role-of-offensive">Proudly Offensive</a></em> security, my focus was on how defenders could automate at machine-speed. Since then, real-world vulnerabilities and breaches have shown that attackers are weaponizing the very same tooling. My partner <a href="https://jessleao.substack.com/">Jess Le&#227;o</a> just dropped a <a href="https://jessleao.substack.com/p/im-sorry-dave-im-afraid-i-cant-do">must-read</a> on models that happily yank their own kill-switches, blackmail operators, and scheme around oversight for example. Given the rapid developments I wanted to pull together a short field report on some of the emerging styles of AI-enabled attacks, together with the implications each style creates.</p><div><hr></div><h3>Prompt-Injection and Tool-Chain Hijacks</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8i-n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8i-n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 424w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 848w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 1272w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8i-n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png" width="1456" height="534" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:534,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137274,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/164816614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8i-n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 424w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 848w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 1272w, https://substackcdn.com/image/fetch/$s_!8i-n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d4af2f-c8ff-44fa-8c10-ea233ab05bc7_1478x542.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>LLMs wired into developer workflows are now a direct path to source-code theft and supply-chain compromise. Last month, Researchers at <a href="http://legitsecurity.com">Legit Security</a> showed that a single base-encoded comment inside a merge request could coerce GitLab Duo (powered by Claude) <a href="https://www.darkreading.com/application-security/gitlab-ai-assistant-opened-devs-to-code-theft">to dump private repositories, inject rogue HTML and phone home to an attacker-controlled</a> URL. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jxxW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jxxW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 424w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 848w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 1272w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jxxW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png" width="1456" height="1194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1194,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1121038,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/164816614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jxxW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 424w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 848w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 1272w, https://substackcdn.com/image/fetch/$s_!jxxW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb3a1213-ec72-42ef-8ff7-17b4e09095d8_1456x1194.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In a very similar case, <a href="https://invariantlabs.ai/">Invariant Labs</a> uncovered a critical flaw in the widely-used GitHub MCP server, starred 14 k+ times on GitHub, that <a href="https://gbhackers.com/critical-github-mcp-server-vulnerability/">lets a malicious Issue trick an AI agent into leaking private repos</a>. The way it works is that the adversary plants a public-repo issue laced with a hidden prompt-injection string. When a developer&#8217;s AI assistant, Claude Desktop connected via the GitHub MCP server, pulls the list of open issues, it ingests the booby-trapped text, executes the rogue prompt, and cascades into a malicious agent workflow.</p><p>The same pattern hit the orchestration tier: CVE-2025-3248 in the open-source builder Langflow lets an unauthenticated attacker hit the <code>/api/v1/validate/code</code> endpoint and execute arbitrary Python <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3248?utm_source=chatgpt.com">NVD</a>. CISA shoved the bug into its Known Exploited Vulnerabilities catalogue after detecting in-the-wild abuse, and<a href="https://www.bleepingcomputer.com/news/security/critical-langflow-rce-flaw-exploited-to-hack-ai-app-servers/"> internet scans still found hundreds of exposed servers days later</a>. Once an LLM or low-code workflow gains <code>exec()</code> rights, a stealth prompt or crafted payload can exfiltrate more data in seconds than months of slow, covert theft.</p><div><hr></div><h3>Synthetic Impersonation and Deep-Fake Social Engineering</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZA5t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZA5t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 424w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 848w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 1272w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZA5t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png" width="1388" height="926" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:926,&quot;width&quot;:1388,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91741,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dannguyenhuu.substack.com/i/164816614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZA5t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 424w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 848w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 1272w, https://substackcdn.com/image/fetch/$s_!ZA5t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2585f36d-eecf-4cfd-af78-7397a86147bd_1388x926.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI voice and video cloning have demolished the cost of credibility. In May, the FBI warned that <a href="https://www.malwarebytes.com/blog/news/2025/05/scammers-are-using-ai-to-impersonate-senior-officials-warns-fbi?utm_source=chatgpt.com">adversaries were texting</a>, then phoning, targets with AI-generated voices of senior U.S. officials to harvest credentials. The alert followed an earlier bureau <a href="https://www.fbi.gov/contact-us/field-offices/sanfrancisco/news/fbi-warns-of-increasing-threat-of-cyber-criminals-utilizing-artificial-intelligence?utm_source=chatgpt.com">bulletin on AI-driven vishing and smishing campaigns</a>. Data backs the trend: CrowdStrike&#8217;s 2025 Global Threat Report logged a <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-releases-2025-global-threat-report/?utm_source=chatgpt.com">442 % jump in vishing attacks</a> between H2 2024 and H1 2025, fueled by AI voice cloning. Beyond reputational damage, every deep-fake call burns executive time, and one breached mailbox can ripple through partner ecosystems, creating a hidden productivity and trust tax rarely itemized in breach-cost spreadsheets.</p><div><hr></div><h3>Crime-ware-as-a-Service: Malicious LLMs and Phishing Factories</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M81p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M81p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!M81p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!M81p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!M81p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M81p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg" width="952" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:952,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Chat GPT Fraud bot in the dark web&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Chat GPT Fraud bot in the dark web" title="Chat GPT Fraud bot in the dark web" srcset="https://substackcdn.com/image/fetch/$s_!M81p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!M81p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!M81p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!M81p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42eee393-5dae-4fbf-9023-6335c7c2ebbb_952x410.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Generative AI is turning script-kiddies into enterprise-grade criminals. As one of our security founders likes to say &#8220;What was once nation state is now common place&#8221;. Dark-web operators now tout an <a href="https://netenrich.com/blog/fraudgpt-the-villain-avatar-of-chatgpt?utm_source=chatgpt.com">uncensored chatbot dubbed FraudGPT</a> for $200 per month or $1,700 per year, boasting 3,000+ confirmed sales that bundle turnkey malware and spear-phish generation. Delivery scales just as aggressively: Barracuda telemetry logged more than one million <a href="https://www.wsj.com/articles/do-it-yourself-cyberattack-tools-are-booming-7ce1445d?utm_source=chatgpt.com">Phishing-as-a-Service attacks in January&#8211;through February 2025</a>. 89% of them launched via the Tycoon 2FA kit, with EvilProxy and Sneaky 2FA rounding out the field. When anyone with $200 and a Telegram handle can mint flawless, localized phishing lures, the old &#8220;look for bad grammar&#8221; user-training tip is becoming more and more obsolete. </p><div><hr></div><h3>AI &amp; IT Infrastructure Attack Vectors</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JDBC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JDBC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JDBC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg" width="1456" height="941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!JDBC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JDBC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f00138b-4ea4-419f-bc94-b4c919781048_2048x1324.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Application-layer exploits are only half the story. Last week, <a href="https://x.com/PalisadeAI/status/1926084635903025621">Palisade Research&#8217;s red-teamers showed OpenAI&#8217;s o3 model</a> disabling its own shutdown routine. If a model can jailbreak itself in the lab, the scaffolding around it is living on borrowed time. In its threat report published in February, OpenAI had reported that it had begun <a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/">purging ChatGPT accounts tied to Chinese, Iranian and North-Korean</a> state actors after discovering they used the service to debug spyware and craft influence campaigns. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nLkl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nLkl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 424w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 848w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 1272w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nLkl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png" width="910" height="460" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/890c173d-1e81-4108-8027-b801af2502e7_910x460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:460,&quot;width&quot;:910,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nLkl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 424w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 848w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 1272w, https://substackcdn.com/image/fetch/$s_!nLkl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890c173d-1e81-4108-8027-b801af2502e7_910x460.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As adversarial campaigns become more sophisticated it is likely it will extend into traditional network and endpoint infrastructure as well. In December of last year, <a href="https://unit42.paloaltonetworks.com/">Palo Alto Networks&#8217; Unit 42</a> had <a href="https://thehackernews.com/2024/12/ai-could-generate-10000-malware.html">published research</a> that LLMs excelled at transforming existing malicious code into natural-looking, evasive variants, especially in JavaScript. Over time, these transformations can degrade the accuracy of malware classifiers, subtly training them to misidentify threats as benign. <a href="https://abcbyd.substack.com/">Damien Lewke</a> had a great post on how to effectively seek these out by <a href="https://abcbyd.substack.com/p/threat-hunting-for-ai-generated-malware">applying behavior, network, automation, artifact and entropy-based hunts</a>, matched with prevention controls. </p><div><hr></div><h3>Conclusion </h3><p>Adversaries have moved from experimenting with AI to operationalizing it at industrial scale. AI-enabled attacks have moved from one-off proofs of concept to systemic campaigns that breach developer pipelines, con executives with deep-fake voices, and mass-produce phishing kits. Simultaneously, adversaries are trying to find gaps in the AI and IT infrastructure plumbing itself, proving that defenses must extend past applications and down into the platforms that serve them. More than ever these styles of attacks are becoming embedded, pervasive and go beyond code to quite lucrative &#8220;as-a-service&#8221; businesses. In such a dynamically changing infrastructure and application environment, I am certain we will see even more varieties and styles of attacks. As always if you are building in AI and cybersecurity, please reach out to me! </p>]]></content:encoded></item><item><title><![CDATA[Proudly Offensive: The Role of Offensive AI in Cyber Defense]]></title><description><![CDATA[In the AI era, the best defenders don&#8217;t react to attacks &#8212; they wage them first.]]></description><link>https://dannguyenhuu.substack.com/p/proudly-offensive-the-role-of-offensive</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/proudly-offensive-the-role-of-offensive</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 20 May 2025 13:32:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_9kA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This post is a reflection on what we saw at <a href="https://www.rsaconference.com/usa">RSAC 2025</a> and what we&#8217;ve been learning across the <a href="http://Decibel.vc">Decibel</a> portfolio. But more importantly, it&#8217;s about where the cyber world is heading: a material shift where offensive AI will drive defensive capabilities and vice versa.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_9kA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_9kA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_9kA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!_9kA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_9kA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd20955e0-6048-4e86-86f9-cc345e5b8ec9_1600x1068.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Dmitri Alperovitch, xCTO and Co-founder of Crowdstrike, speaking at Decibel&#8217;s Founder Dinner at RSAC 2025</em></p><h3><strong>The World Has Changed, And So Has Cyber</strong></h3><p>Earlier this year, we co-hosted the <strong><a href="https://www.linkedin.com/posts/johndchina_earlier-this-month-we-hosted-the-inaugural-activity-7310002195662311425-fl2O/">National Cyber Innovation Summit</a></strong> in Washington, D.C. with our friends at JP Morgan. It brought together 100+ elite founders, government officials, and security leaders from both the public and private sector. The message was clear: cyber is no longer a commercial afterthought or even a siloed IT concern. It&#8217;s geopolitical, it&#8217;s economic, and it&#8217;s existential.</p><p>Cybersecurity has always been deeply shaped by geopolitics. From the <em><a href="https://www.wsj.com/articles/china-based-hacking-incidents-see-dip-cybersecurity-experts-say-1466467316">APT1 report</a></em><a href="https://www.wsj.com/articles/china-based-hacking-incidents-see-dip-cybersecurity-experts-say-1466467316"> in 2013</a> where <a href="https://www.rsaconference.com/experts/kevin-mandia">Kevin Mandia</a> publicly pointed out Chinese nation-state attackers, to the <a href="https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years">Colonial Pipeline ransomware attack</a> that paralyzed the east coast in 2021, we&#8217;ve spent the last two decades reacting to threats born on the international stage. Nation-state attribution used to be controversial &#8212; now it&#8217;s table stakes. After each geopolitical shock, defenders have scrambled to bolt on controls for mitigation. The structural shift of AI makes that retrospective model untenable. Public LLMs and cheap fine-tuning allow even hobbyists to generate convincing malware and bespoke phishing at will, so threat volume is exploding non-linearly and signature-centric defenses are drowning. The net result is simple: defenders can no longer wait for &#8220;known bad&#8221; intelligence. Systems must be attacked in simulation, continuously ideally and reinforced in near real time. We&#8217;re entering a new chapter on what we call the <strong>Proudly Offensive Era</strong>.</p><div><hr></div><h3><strong>Offense Is the New Defense</strong></h3><p>In the past, we operated on a <strong>Sequential <a href="https://www.microsoft.com/en-us/security/business/security-101/what-is-cyber-kill-chain#:~:text=The%20cyber%20kill%20chain%20includes,actions%20on%20objectives%2C%20and%20monetization.">Kill Chain</a></strong> &#8212; an attacker would recon, gain access, escalate, exfiltrate. We responded after the fact. We built playbooks around alerts and symptoms. We were always one step behind and our defenses were built on yesterday&#8217;s attacks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3zQz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3zQz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 424w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 848w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3zQz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png" width="1456" height="1310" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1310,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3zQz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 424w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 848w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!3zQz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6cb4c9f-d23d-4b4d-a2cb-c1bd4e15f9cd_1600x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When AI first came onto the scene, we saw a huge opportunity to focus on reducing alert fatigue from security tools. Companies like <strong><a href="https://www.dropzone.ai/">Dropzone</a></strong> emerged to handle the signal overload in SOCs by automating triage &#8212; not by replacing humans, but by relieving them of the tedious, the repetitive, the soul-crushingly obvious.</p><p>In this next chapter, both<strong> </strong>our allies and our adversaries are teaching LLMs to think like attackers. At the same time, the rise of code-gen tools like <strong><a href="https://bolt.new/">Bolt</a></strong> and <strong><a href="https://www.cursor.com/">Cursor</a></strong> means that software is being written &#8212; and exposed &#8212; at unprecedented scale. The result is a multiverse of exploitable vulnerabilities. And in the context of rising global conflict, the implications could be quite serious.</p><p>Today, we&#8217;re looking to invest in companies that proactively simulate the kill chain before an attack occurs. We expect these companies will use autonomous agents, draw on human expertise, and scale their reach through AI.</p><div><hr></div><h3><strong>RSAC 2025: Proudly Offensive In Action </strong></h3><p>At RSAC this year, we took this idea public. The Decibel Founder Oasis hosted a packed session titled <em><a href="https://www.linkedin.com/posts/jonsakoda_what-happens-when-elite-offenses-and-defenses-activity-7323766597934813186-Jm68/">&#8220;</a></em><strong><a href="https://www.linkedin.com/posts/jonsakoda_what-happens-when-elite-offenses-and-defenses-activity-7323766597934813186-Jm68/">Proudly Offensive</a></strong><em><a href="https://www.linkedin.com/posts/jonsakoda_what-happens-when-elite-offenses-and-defenses-activity-7323766597934813186-Jm68/">&#8221;</a></em>. It featured live demos and candid conversations on the topic. Here are three of the teams leading this charge:</p><div><hr></div><h4><strong>&#129504; Delphos &#8211; Teaching Machines to Reverse Engineer Malware</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cz7p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cz7p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cz7p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cz7p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cz7p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64662e33-440e-49a4-a28f-668cfb6a4af5_1600x1068.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>                              David Dubick and Caleb Fenton, founders of Delphos</em></p><p><a href="https://delphoslabs.com/">Delphos</a> is pioneering <strong>AI-powered reverse engineering</strong>, letting defenders deconstruct and see malicious code faster than ever before. Traditional sandboxes rely on behavior; Delphos pushes further, building code semantic models that can detect known and unknown vulnerabilities. The product thereby gives defenders the upper hand against attackers by doing what an elite reverse engineer would do, but in mere seconds.</p><div><hr></div><h4><strong>&#128065;&#65039; SpecterOps &#8211; Turning Identity Into an Attack Surface Map</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oH8Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oH8Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oH8Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oH8Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oH8Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a5c8547-f18e-4a36-8d32-be70890ea224_1600x1068.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>                              Justin Kohler, Chief Product Officer of SpecterOps</em></p><p><a href="https://docs.google.com/document/d/1IVCnCZOyIohCsbu1xnRAYB2WAYt9oMAI7KA0x7Ddq2U/edit?tab=t.0#heading=h.scu3tq2ub2x6">SpecterOps</a> has long been a leader in offensive identity research. At RSA, they showed how their tools map attack paths<strong> </strong>via <a href="https://specterops.io/bloodhound-community-edition/">Bloodhound </a>&#8212; then simulate exploitation. The approach is grounded in real-world tradecraft, helping customers such as  <a href="https://blog.palantir.com/palantir-specterops-partnership-288d06f7136d">Palantir </a>and <a href="https://openai.com/index/security-on-the-path-to-agi/">OpenAI</a> harden their defenses with evidence, not hypotheticals.</p><div><hr></div><h4><strong>&#9760;&#65039; Dreadnode &#8211; Simulate, Exploit, Repeat</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FsxE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FsxE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FsxE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FsxE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FsxE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4f4e3c-9792-40b0-9876-973fb6770bfe_1600x1066.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>                              Will Pearce and Nick Landers, founders of Dreadnode</em></p><p><a href="https://dreadnode.io/">Dreadnode</a> showed why <strong>advancing the state of offensive security</strong> through AI isn&#8217;t the future but rather the present. Their AI-powered agents simulate attackers with intent: they probe, exploit, exfil, and learn. Dreadnode is building the most advanced adversary that lives inside your test environment and evolves. The best way to secure a system isn't by scanning and monitoring, it best secured by trying to break it, repeatedly.</p><div><hr></div><h3><strong>Continuous Adversarial Validation</strong></h3><p>We&#8217;re seeing adversaries use LLMs to write better phishing campaigns, to craft tailored payloads, to fuzz APIs at scale. In our minds, the antidote is AI-powered <strong>Continuous Adversarial Validation</strong>, the idea that defense can no longer be episodic. We don&#8217;t wait for a red team quarterly or once a year. We spin up a red team every hour. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IswE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IswE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 424w, https://substackcdn.com/image/fetch/$s_!IswE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 848w, https://substackcdn.com/image/fetch/$s_!IswE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 1272w, https://substackcdn.com/image/fetch/$s_!IswE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IswE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png" width="1456" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IswE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 424w, https://substackcdn.com/image/fetch/$s_!IswE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 848w, https://substackcdn.com/image/fetch/$s_!IswE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 1272w, https://substackcdn.com/image/fetch/$s_!IswE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb374272d-0480-4a2d-9351-dc8c7a9a3111_1486x866.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This approach blends simulation with detection and remediation. Rather than simply hardening endpoints, it war-games against a synthetic enemy that may understand your systems better than you do. As these tools mature, the boundary between defense and offense will blur even further. Put differently, reaction collapses into anticipation: every hour, new attack graphs are explored, and exploitable paths are patched or segmented before production traffic carries real risk</p><div><hr></div><h3><strong>If You&#8217;re Building in This Space</strong></h3><p>If you&#8217;re working on AI-powered simulation, adversarial agents, or any other tools that turn offense into insight &#8212; we want to meet you. At Decibel, we are keen to invest into a new kind of offense and are proudly backing the companies getting us there.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u3Z0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u3Z0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 424w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 848w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 1272w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u3Z0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png" width="1456" height="865" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:865,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:&quot;Screenshot 2025-05-11 at 5.41.30&#8239;PM.png&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="Screenshot 2025-05-11 at 5.41.30&#8239;PM.png" srcset="https://substackcdn.com/image/fetch/$s_!u3Z0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 424w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 848w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 1272w, https://substackcdn.com/image/fetch/$s_!u3Z0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdad3cb-5fc4-4047-9e81-3fa544fe28d1_1600x951.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Decibel and JP Morgan Co-hosting the National Cyber Innovation Summit in DC in March 2025</em></p>]]></content:encoded></item><item><title><![CDATA[The Era of the Autonomous Defense]]></title><description><![CDATA[...and the Role of Human Defenders in It]]></description><link>https://dannguyenhuu.substack.com/p/the-era-of-the-autonomous-defense</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-era-of-the-autonomous-defense</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Mon, 10 Feb 2025 15:09:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rQu4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rQu4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rQu4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 424w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 848w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 1272w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rQu4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png" width="1093" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1093,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1576739,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rQu4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 424w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 848w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 1272w, https://substackcdn.com/image/fetch/$s_!rQu4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828fb384-eb81-4786-9413-a12e70dd3c4e_1093x696.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Not long ago, I wrote about a new wave of <a href="https://dannguyenhuu.substack.com/p/the-programmable-defense">Programmable Defense</a> platforms, and how they fit within the broader evolution of cybersecurity. At the time, it felt like a logical progression: We&#8217;d seen the slow but steady rise in both sophistication and volume of attacks&#8212;and the corresponding call for more adaptive, security engineering-friendly security products. Now, with the advent of LLMs, that progression has taken a major leap forward and is driving cybersecurity into a new era: the Autonomous Defense.</p><p>The Autonomous Defense is a collaborative paradigm in cybersecurity where human creativity and AI work together to detect, contextualize, and respond to threats across entire kill chains in real time. It represents the evolution from rigid, static black-box security solutions to adaptive, programmable systems that seamlessly integrate human oversight with AI-driven automation.</p><p>The need for Autonomous Defense is a response to more than just an accelerating volume of attacks; it&#8217;s also addressing threat actors&#8217; evolution in style, creativity, and deception.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lbNv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lbNv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 424w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 848w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 1272w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lbNv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png" width="859" height="673" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:673,&quot;width&quot;:859,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lbNv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 424w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 848w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 1272w, https://substackcdn.com/image/fetch/$s_!lbNv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff798ef6c-2e86-411f-8a8c-5bdac2e4768a_859x673.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/the-cybersecurity-providers-next-opportunity-making-ai-safer">McKinsey&#8217;s</a> data on phishing alone highlights the surge in AI-enabled exploits: more intricate social engineering, more convincing synthetics (think deepfake audio and video), and a flood of new email tactics that bypass traditional filters. <a href="https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html">In one well-known example</a>, threat actors leveraged deepfakes to pose as a company&#8217;s chief financial officer and convinced a finance worker to pay out $25M.</p><p>And let&#8217;s be clear: It&#8217;s not just the malicious side harnessing these AI engines. Security teams are actively embedding AI into their workflows&#8212;raising the bar for rapid detection, real-time contextualization, and automated responses.</p><p>What does all of this mean? If you talk to the folks who came up through the ranks of <a href="https://www.blackhat.com/">BlackHat</a> and <a href="https://defcon.org/">DEFCON</a>, you&#8217;ll see a common theme: security professionals are done waiting for vendors to patch together stale, rigid solutions. They&#8217;re demanding tools that can adapt as fast as the threats do&#8211;and do so in a way that maximizes both security outcomes and operational efficiency. The Autonomous Defense is responding to that call, empowering teams to reduce the cost and time of defending against increasingly sophisticated attacks, while freeing up human defenders to focus on the highest-value challenges.</p><p>Let&#8217;s break down the foundational elements of the Autonomous Defense and how they coalesce into this new paradigm:</p><h3><strong>Programmable: Where AI and Humans Collaborate</strong></h3><p><strong>Programmable security</strong> has long been part of our thesis at <a href="http://decibel.vc">Decibel</a>. It represents the critical fusion of flexible toolsets that can adapt as attacks evolve&#8212;and, more importantly, do so seamlessly with human oversight. A big part of making that happen lies in how systems, humans, and AI &#8220;talk&#8221; to each other.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NBZX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NBZX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 424w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 848w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 1272w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NBZX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png" width="1456" height="654" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NBZX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 424w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 848w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 1272w, https://substackcdn.com/image/fetch/$s_!NBZX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9a9ba9-846c-4ca5-b857-2670b851483b_1600x719.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A lot of security products historically hid behind black-box algorithms. If it flagged something, good luck debugging the &#8220;why.&#8221; Now, we&#8217;re seeing a shift to detection tools that expose a domain-specific language (DSL). Think of <a href="https://sublime.security/">Sublime Security</a>&#8217;s approach, where everything from rule creation to threat hunting can be expressed in a clear, programmable format. It&#8217;s a shared language between you and your AI, reducing confusion and &#8220;hallucinations&#8221; that can happen when an AI tries to guess your intent without a well-defined structure.</p><p>This synergy is the same reason code-generation platforms like<a href="https://www.cursor.sh/"> Cursor</a> and<a href="https://www.codeium.com/"> Codeium</a> have been so effective: humans design the logic and context, AI executes the heavy lifting. The result is faster, more accurate rule-writing and detection logic that can be tuned on the fly. We often forget that many cyber risks hinge on &#8220;time to detection.&#8221; If your detection rules can be automatically refined and iterated within minutes&#8212;not weeks&#8212;you effectively take away one of the biggest advantages attackers have.</p><h3><strong>Contextualization: Enriching without reducing signal</strong></h3><p>Silos are an unfortunate byproduct of the rapid technology sprawl in security. We have specialized tools for threat intelligence, incident response, vulnerability management, threat hunting, endpoint monitoring&#8212;the list goes on. But the reality is that kill chains don&#8217;t respect product boundaries. AI-driven attacks can pivot quickly from a phishing exploit to privilege escalation on your network, and from there, to data exfiltration in your cloud environment.</p><p>To truly defend in real time, we need a holistic vantage point. That&#8217;s where contextualization comes in. Imagine if your vulnerability management system and threat intelligence feeds were fully merged. Instead of receiving an alert saying, &#8220;Remote code execution vulnerability in product X,&#8221; you&#8217;d also get context: &#8220;APT Group Y has been exploiting this exact vulnerability in the last week, targeting financial institutions similar to yours.&#8221;</p><p>Now you don&#8217;t just know there&#8217;s a problem&#8212;you understand the likelihood and potential impact. You prioritize a patch. You escalate within your team, because you see the real risk of lateral movement in your environment. It&#8217;s basically the difference between an alert and a narrative. And that narrative is what teams need to respond swiftly and effectively.</p><p>One big step in that direction is the collapse of multiple security categories into a single, integrated chain. If threat intel informs vulnerability management, which directly ties to patching or exploit-blocking, that reduces both manual handoffs and the risk of something slipping through the cracks. AI models trained on your specific environment can automatically flag the vulnerabilities most likely to be exploited in real time, driving meaningful risk-based prioritization rather than generic best practices.</p><p>For instance, <a href="https://www.empiricalsecurity.com/">Empirical Security</a> is leveraging <a href="https://osintframework.com/">OSINT and attack telemetry,</a> mining its own proprietary data models and <a href="https://www.first.org/epss/">EPSS</a> to build more advanced, localized models. Rather than depending on generic indicators, it aggregates and analyzes data from a worldwide network of sources to stay ahead of emerging threats. This shifts the approach of security teams from a reactive to a predictive and preventive mindset. By combining EPSS-based predictions with their contextual threat analysis engine, it can identify high-probability weaknesses specific to an organization&#8217;s profile, industry, and infrastructure. This holistic, intelligence-driven approach transforms raw alerts into actionable narratives, helping security teams not only detect issues faster but also understand the &#8220;why&#8221; and &#8220;how&#8221; of each threat&#8212;empowering them to prioritize and remediate with far greater precision.</p><h3><strong>Digital Twins: Real-Time Threat and Defense Simulations</strong></h3><p>We all know the classic tabletop exercises and third-party pen tests that happen every quarter (or year, if you&#8217;re unlucky). They&#8217;re valuable, but also resource-intensive and slow. You&#8217;re basically simulating known attacks, capturing the results, then hoping to find and fix the gaps before the adversaries do.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MSHO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MSHO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 424w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 848w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 1272w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MSHO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png" width="1456" height="580" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:580,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MSHO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 424w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 848w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 1272w, https://substackcdn.com/image/fetch/$s_!MSHO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfcf7e6-0b7b-4f6d-b914-5bc5b086fdef_1600x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Enter digital twins (DTs).</strong> Already commonly used in industries like aerospace and manufacturing, digital twins help organizations model complex systems like jet engines or assembly lines, enabling them to simulate performance, predict failures, and optimize operations in real time by testing changes in a virtual environment before implementing them in the real world. In the context of cybersecurity, a digital twin is a virtual model of your organization&#8217;s infrastructure&#8212;networks, applications, endpoints, and even the workflows your security teams use. By simulating attacks in this environment, you can stress-test new defensive strategies without risking actual systems.</p><p><a href="https://www.forbes.com/councils/forbestechcouncil/2024/07/15/digital-twins-the-new-frontier-in-cybersecurity/">Digital Twins</a> can point out the transformative potential for defenders. Researchers describe how Cyber Digital Twins (CDTs) focus specifically on cybersecurity functions, letting security teams simulate attacks, evaluate patch effectiveness, and predict the downstream impacts of compromises&#8212;all without real-world disruption. They&#8217;re like living blueprints that track real-time changes, enabling you to validate configurations, hunt for zero-days, and quickly pivot to new defensive measures before the threat actors can adapt.</p><p>To me, digital twins represent the next logical step in cybersecurity resilience. Because once you can replicate your entire security environment in code, you can unleash AI to run hundreds&#8212;maybe thousands&#8212;of &#8220;what if&#8221; scenarios in parallel. This advanced simulation closes the gap between detection, analysis, and remediation.</p><h3><strong>AI-Powered Workflows: Driving Down Toil</strong></h3><p>Even in 2025, so much of cybersecurity still involves repetitive, manual tasks. Security teams are inundated with alerts, logs, tickets&#8212;some of which are critical, many of which are false positives or routine. This grind leads to fatigue, burnout, and inevitably, missed signals.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4FoQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4FoQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 424w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 848w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 1272w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4FoQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png" width="1456" height="807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:807,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4FoQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 424w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 848w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 1272w, https://substackcdn.com/image/fetch/$s_!4FoQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e92bdf8-25b1-4521-82ce-4a0283e91330_1486x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Automation is nothing new, but the level of workflow optimization we can now achieve with AI is next-level. Products like<a href="https://dropzone.co/"> Dropzone</a> reduce toil by automatically categorizing and responding to routine alerts, letting defenders focus on the nuanced tasks that require human judgment. That&#8217;s where we want the human defenders&#8212;applying their experience, creativity, and gut instinct to tricky edge cases, advanced threat hunting, or major incidents that need strategic input.</p><p>There&#8217;s a virtuous cycle at play: The more tasks you offload to a well-tuned AI system, the more time you free up for the human side of the collaboration. Your team can invest energy in improving detection logic or analyzing novel threats.</p><h3><strong>Conclusion</strong></h3><p>The Autonomous Defense is a convergence of principles that have been brewing for years: programmability for adaptive detection rule-making, contextualization that breaks down data silos, real-time simulation via digital twins, and AI-driven workflow optimization that frees up human defenders to to focus on high-impact work while lowering operational costs and improving the ROI on security.</p><p>Not every &#8220;autonomous defense&#8221; product of the future needs to include every single feature in this list. But these concepts&#8212;programmable security, integrated intel, digital twins, and streamlined workflows&#8212;serve as a guidepost for what&#8217;s possible right now. AI has changed the game for attackers, but it&#8217;s also leveling up our defenses in ways we couldn&#8217;t have imagined a decade ago.</p><p>If you&#8217;re building (or dreaming of building) something that fits these principles, I&#8217;d love to hear from you. Because I believe they provide a compelling path forward to embrace this era of collaborative AI-human defense&#8212;and help shape the tools that define it.</p><p>In many ways, the folks who cut their teeth at <a href="https://www.blackhat.com/">BlackHat</a> and <a href="https://defcon.org/">DEFCON</a> did us a favor by demanding more flexible, programmable solutions. Now that they&#8217;re in leadership roles, it&#8217;s time for us to answer the call and deliver.</p><p></p><p><em>Big thank you to <a href="https://www.linkedin.com/in/josh-devon">Josh Devon</a> (<a href="https://flashpoint.io/">Flashpoint</a>), <a href="https://www.linkedin.com/in/damienlewke">Damien Lewke</a> (<a href="https://arcticwolf.com/">Arctic Wolf</a>) and <a href="https://www.linkedin.com/in/bellis">Ed Bellis</a> (<a href="https://www.cisco.com/c/en/us/products/security/kenna-is-part-of-cisco.html">Kenna Security</a>) for providing massively insightful feedback on this piece and helping me refine my thoughts on this topic.</em></p>]]></content:encoded></item><item><title><![CDATA[Programmable Defense Summit: A Recap]]></title><description><![CDATA[The Path to an Autonomous Defense Begins with Programmability]]></description><link>https://dannguyenhuu.substack.com/p/programmable-defense-summit-a-recap</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/programmable-defense-summit-a-recap</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 17 Dec 2024 14:58:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IiMq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IiMq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IiMq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 424w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 848w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 1272w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IiMq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png" width="974" height="547" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:547,&quot;width&quot;:974,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IiMq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 424w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 848w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 1272w, https://substackcdn.com/image/fetch/$s_!IiMq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd04b8508-7df5-436b-9c2c-2f3b1a17e33a_974x547.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We recently hosted the inaugural <strong><a href="https://www.linkedin.com/posts/dan-nguyen-huu-11502719_yesterday-we-hosted-our-inaugural-programmable-activity-7254503843630129152-qhXF?utm_source=share&amp;utm_medium=member_desktop">Programmable Defense Summit</a></strong> in New York City, bringing together some of the most forward-thinking cybersecurity leaders and founders. The discussions centered on how the security industry is shifting toward <strong>a more transparent, adaptable, and customer-centric, rather than vendor-centric, security posture.</strong></p><p>This blog offers a quick recap of both the summit and the <a href="https://dannguyenhuu.substack.com/p/the-programmable-defense">investment thesis</a> that inspired it, along with key trends shaping the future of programmable defense. Throughout, we&#8217;ll share some of the most thought-provoking quotes from the day&#8212;anonymized but too good not to highlight.</p><p>A special thank you to the incredible CISOs and security leaders in attendance, including those from <em>Prudential, BNY Mellon, Cribl, Ro, Vanta, Workato, Crowdstrike, Maven Clinic, FanDuel, and Dropbox </em>whose insights helped make this such a dynamic and impactful event.</p><h3><strong>Security Secular Trends</strong></h3><p><em>"Programmable defense puts power back in the hands of security engineers&#8212;moving fast is no longer a luxury but a necessity."</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pssc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pssc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 424w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 848w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 1272w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pssc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png" width="1589" height="879" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb1d8824-1015-4645-890b-97629e34f258_1589x879.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:879,&quot;width&quot;:1589,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:353193,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pssc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 424w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 848w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 1272w, https://substackcdn.com/image/fetch/$s_!Pssc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1d8824-1015-4645-890b-97629e34f258_1589x879.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The security landscape is shifting rapidly, driven by both technological advances and evolving threat vectors:</p><ol><li><p><strong>AI-Enhanced Threat Actors</strong>:<br>Threat actors are leveraging AI to scale their operations. Tools like <a href="https://openai.com/index/chatgpt/">ChatGPT</a> make it possible for attackers to generate convincing phishing emails or automate reconnaissance. The barrier to entry for orchestrating complex cyberattacks has plummeted, resulting in a significant uptick in both volume and variety of threats.</p></li><li><p><strong>A New Generation of Security Leaders</strong>:<br>Today&#8217;s security teams have grown up in a world shaped by <a href="https://defcon.org/">DEFCON</a> and <a href="https://www.blackhat.com/">Black Hat </a>conferences. These leaders are now reaching the C-suite, bringing with them expectations of in-house security engineering expertise. Unlike in previous eras, relying security purely on product vendors is no longer the default&#8212;security leadership expects its own sophisticated operations to be able to collaborate with the vendor in the the product.</p></li><li><p><strong>Collaborative Defense Communities</strong>:<br>Security professionals are organizing on platforms like <a href="https://twitter.com/?lang=en">X</a> and <a href="https://joinmastodon.org/">Mastodon</a> to share intelligence and counter common threats. Much like the 1% of social media users who create content consumed by the 99%, a small but growing group of defenders is publishing actionable insights for broader community benefit.</p></li></ol><h3><strong>From Click-Ops to Programmable Security</strong></h3><p><em>"The black box might scale, but it doesn&#8217;t solve enough problems. The future is transparent and programmable."</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NWC8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWC8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWC8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png" width="1456" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NWC8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!NWC8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffceb54ca-bab1-41fc-96b2-e57d6a8461a2_1600x896.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Security tooling is evolving, and a fundamental shift is underway:</p><ul><li><p><strong>The Demand for Transparency</strong>:<br>Black-box solutions are increasingly seen as insufficient for modern security challenges. Instead, forward-thinking organizations expect their tools to be programmable, consumable via APIs, and tailored to their unique environments and needs of an organization.</p></li><li><p><strong>Parallels with DevOps</strong>:<br>Just as open-source software and agile<a href="https://azure.microsoft.com/en-us/products/devops"> DevOps</a> tooling empowered developers, programmable security will unleash creativity and innovation within security teams. Leaders envision a future where security engineers can adapt tools in real time, fostering collaboration and sharing knowledge across organizations.</p></li></ul><h3><strong>Programmable Defense: A Foundation for the Autonomous Defense</strong></h3><p><em>"LLMs are the bridge&#8212;making security decisions understandable to executives and actionable for engineers."</em></p><ul><li><p><strong>The Autonomous Defense: </strong>Programmable defense is the cornerstone of a future autonomous cybersecurity ecosystem, as effective AI requires vast amounts of high-quality first-party data. By enabling security experts to contribute directly to the system, programmable defense becomes a powerful, community-driven engine for defense&#8212;one capable of evolving in a rapidly changing adversarial environment. However, implementing this strategy today is not without challenges. It demands deep technical expertise, including an understanding of code and detection engineering, skills that not all security teams possess. This gap often limits organizations&#8217; ability to operationalize programmable tools effectively.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PQU7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PQU7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 424w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 848w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 1272w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PQU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png" width="1456" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PQU7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 424w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 848w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 1272w, https://substackcdn.com/image/fetch/$s_!PQU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc454b48e-4a99-429a-88f3-64afdf56e8ef_1600x741.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><a href="https://sublime.security/">Sublime Security</a>, utilizes <a href="https://en.wikipedia.org/wiki/BERT_(language_model)">BERT</a> LLM, enhances Sublime's Natural Language Understanding and brings improved contextual awareness and understanding, language comprehension, and performance to <a href="https://sublime.security/blog/combating-genai-email-attacks-with-bert-llm/">better identify GenAI in phishing attacks.</a></em></p><ul><li><p><strong>Enter AI:</strong> LLMs democratize access to sophisticated defense strategies by translating complex, technical threat intelligence into actionable steps that engineers can implement and executives can understand. This collaboration between AI and humans is a critical step toward autonomous defense&#8212;where systems can dynamically adapt to threats in real time, powered by first-party data collected from real attacks and responses from a community fighting a common enemy.</p></li></ul><p>Programmable defense is as much about culture as technology, relying on transparency, collaboration, and shared knowledge. AI makes this vision achievable, enabling adaptive, ever-improving cybersecurity systems for the future.</p><h3><strong>Looking Ahead</strong></h3><p>The discussions at the Programmable Defense Summit confirmed what many of us already believed: In order to build a truly dynamic autonomous defense that can keep pace with the high variety and volume of attacks of the future, cybersecurity products first have to become more programmable, transparent, and collaborative. While we&#8217;re still early in this journey, the momentum is exciting.</p><p>To those who attended and contributed to this pivotal conversation&#8212;thank you. If you are interested in joining us for the next event, please reach out!</p>]]></content:encoded></item><item><title><![CDATA[The BlackHat Wrap-Up!]]></title><description><![CDATA[The 2024 BlackHat Conference is in the books. These were the big topics.]]></description><link>https://dannguyenhuu.substack.com/p/the-blackhat-wrap-up</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-blackhat-wrap-up</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Thu, 15 Aug 2024 13:01:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wN5n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wN5n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wN5n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 424w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 848w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 1272w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wN5n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png" width="1456" height="969" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:969,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wN5n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 424w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 848w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 1272w, https://substackcdn.com/image/fetch/$s_!wN5n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb169d85-b7e3-440b-9c84-fa56f5bcc3d7_1600x1065.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Intro</strong></h3><p>In the 115 degree heat an impatient but hilarious cab driver asked me if I was also here for the &#8220;Hack Rats&#8221; Conference and yes, indeed, I was. The only thing hotter than the weather in the lovely August sun in Las Vegas were some of the topics covered at this year&#8217;s biggest hacker conference. Over the past few days, the Decibel team and I had a chance to catch up with founders, CISOs and security practitioners at our usual <a href="https://twitter.com/jonsakoda/status/1821927866050998323">Founder Oasis</a> event. We discussed the latest trends and topics in cybersecurity, and I wanted to summarize the key takeaways here:&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h3_G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h3_G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h3_G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg" width="1456" height="1036" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1036,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h3_G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h3_G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb3cf3e1-073e-4b07-ad40-a5ba5941f4b3_1600x1138.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>The Decibel Founder Oasis in full swing, a place for founders to take customer meetings and exchange ideas.&nbsp;</em></p><h3><strong>I Spy with My Little AI&nbsp;</strong></h3><p>The growing excitement around AI Security and the Security of AI is intensifying, especially as AI tools empower criminals to scale their operations more rapidly. These tools are increasingly being used to socially engineer the most vulnerable layer of security&#8212;humans&#8212;manipulating them to bypass security controls. For example, attackers might pose as high-level executives to pressure a finance department employee into wiring funds to a fraudulent account by creating a sense of urgency. Similarly, they might manipulate a help desk into disabling MFA for an executive. This highlights the critical importance of helping humans make better security decisions&#8212;a key topic of discussion.</p><p>As AI becomes more sophisticated, so do the threats it faces <em>and</em> poses. Without continuous research and innovation, we risk falling behind in understanding and mitigating these emerging risks. It is essential to stay ahead of the curve, ensuring that AI systems are not only effective but also resilient against exploitation by malicious actors.</p><p>Therefore, in collaboration with our friends at <a href="https://specterops.io/">SpecterOps</a> and <a href="https://www.dreadnode.io/">Dreadnode</a>, we were thrilled to launch our first-ever <a href="https://www.linkedin.com/feed/update/urn:li:activity:7227316202086289411/">&#8220;Man vs. Machine&#8221; competition </a>at Black Hat. This open challenge gave over 100 security researchers the opportunity to test their skills by hacking AI models in real-world simulations. Participants tackled 12 different &#8220;capture the flag&#8221; (CTF) exercises, generating more than 2 million API requests against widely used LLMs. While more than 50 researchers successfully completed the first challenge, only 3 managed to conquer all 12. We hope that competitions like these will inspire researchers in our community to develop protective measures and guardrails for today&#8217;s AI models.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j4AW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j4AW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j4AW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j4AW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j4AW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e64c683-6ce6-4dda-b973-5548414230be_1600x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><a href="https://www.linkedin.com/in/kenyeungtech/">Kenneth Yeung</a> was crowned the winner of the event and was awarded an<a href="https://www.linkedin.com/company/nvidia/"> NVIDIA</a> RTX-4090 by our honorary guest<a href="https://www.linkedin.com/in/hdmoore/"> HD Moore</a> (founder of Metasploit and<a href="https://www.linkedin.com/company/runzero/"> runZero</a>).&nbsp;</em></p><h3><strong>The Programmable Defense: The Crowd Strikes Back</strong></h3><p>At our annual <a href="https://lu.ma/q0wdhfr4">Black Hat Decibel Founder Happy</a> hour, the July <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">CrowdStrike IT outage</a> was a major topic of discussion. Huge kudos to <a href="https://www.crowdstrike.com/en-us/">Crowdstrike</a> founder <a href="https://www.linkedin.com/posts/tysbano_chenxi-wang-phd-rain-capital-moderating-activity-7226719999430733826-rR6e?utm_source=share&amp;utm_medium=member_desktop">George Kurtz</a> for showing up to the Innovators and Investors Summit where he sent all of our founders a message that you need to show up when times are tough. There were many lessons learned and open questions on how the industry moves forward and many in our community are working towards a more resilient solution: a <a href="https://substack.com/@dannguyenhuu/p-143397585">Programmable Defense</a> which allows vendors, researchers, and early adopters to collaborate through open security solutions. Our portfolio companies <a href="https://sublime.security/">Sublime Security</a>, <a href="https://specterops.io/">SpecterOps</a>, <a href="https://prowler.com/">Prowler</a>, <a href="https://pushsecurity.com/">Push Security</a>, and our friends at <a href="https://panther.com/">Panther </a>continue to lead the way in this very important movement. We expect an even larger group next year - the crowd will definitely strike back!&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4VjP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4VjP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4VjP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4VjP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4VjP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f22debf-fa4d-48f7-acac-f50aa111cb72_1600x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Our Decibel Founder Happy Hour at Libertine Social&nbsp;</em></p><h3><strong>Will.&#8221;IAM&#8221; - Where is the love?</strong></h3><p><a href="https://www.microsoft.com/en-us/security/business/security-101/what-is-identity-access-management-iam">Identity and Access Management (IAM</a>) and <a href="https://www.sentinelone.com/cybersecurity-101/identity-security/identity-security/">Identity Security (IS)</a> took center stage at Black Hat 2024, underscoring its critical role in modern cybersecurity. As the cloud era continues to evolve, IAM and IS has become more than just a security necessity; it's now a frontline defense against increasingly sophisticated credential compromises and identity-related attacks. This year's conference highlighted how security leaders are realigning their IAM and IS strategies to meet the demands of this new landscape, recognizing that effective IAM and IS is vital for protecting sensitive data and ensuring only authorized access to critical systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dloT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dloT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 424w, https://substackcdn.com/image/fetch/$s_!dloT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 848w, https://substackcdn.com/image/fetch/$s_!dloT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 1272w, https://substackcdn.com/image/fetch/$s_!dloT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dloT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png" width="1198" height="968" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:968,&quot;width&quot;:1198,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2434959,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dloT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 424w, https://substackcdn.com/image/fetch/$s_!dloT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 848w, https://substackcdn.com/image/fetch/$s_!dloT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 1272w, https://substackcdn.com/image/fetch/$s_!dloT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844d8c1e-1dca-43e7-9a29-999f90ed6da5_1198x968.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Packed house at the <a href="https://pushsecurity.com/">Push Security</a>, <a href="https://sublime.security/">Sublime</a> and <a href="https://panther.com/">Panther</a> Happy Hour!</em></p><p>Our portfolio company <a href="https://pushsecurity.com/">Push Security</a> &#8211;which focuses on identity attack detection and response &#8211; held a detailed <a href="https://pushsecurity.com/resources/video/phishing-detecting-evilginx-evilnovnc-muraena-and-modlishka/">webinar</a> on the topic, in particular covering the massive recent spike of <a href="https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/identifying-adversary-in-the-middle-aitm-phishing-attacks/ba-p/3991358">AitM (Adversary-in-the-Middle)</a> attacks. The growing threat of advanced phishing tools like <a href="https://help.evilginx.com/docs/intro">Evilginx</a>, <a href="https://github.com/redteamsecurity2023/EvilnoVNC">EvilnoVNC</a>, <a href="https://github.com/muraenateam/muraena">Muraena</a>, and <a href="https://github.com/drk1wi/Modlishka">Modlishka</a>, which attackers use to bypass traditional security measures such as <a href="https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123-eda06bddf661">multi-factor authentication (MFA)</a>. These tools enable attackers to steal live session logins, making it critical for organizations to adopt robust detection strategies. One way to protect against this is to leverage browser telemetry to identify and block these phishing toolkits.</p><h3><strong>Conclusion</strong></h3><p>Attending <a href="https://www.blackhat.com/">Black Hat </a>in Las Vegas this year was, as always, an incredible experience, filled with insightful discussions, innovative ideas, and the chance to connect with some of the brightest minds in cybersecurity. While it&#8217;s great to be back in the cooler climate of San Francisco, the excitement and energy from the conference are still fresh in our minds. We're already looking forward to next year, eager to reunite with founders, CISOs, and practitioners to continue exploring the cutting edge of security. As always, if you are thinking about or building in security, AI or infra IT space please reach out to me or join our <a href="https://dannguyenhuu.substack.com/p/introducing-the-founder-catalyst">Founder Catalyst community!</a>&nbsp;</p>]]></content:encoded></item><item><title><![CDATA[AI-Multiple Expansion and Operating Margin Gain (AI-ME & AI-OMG)]]></title><description><![CDATA[Managed Service-as-Software: A Financial and Valuation Framework Addendum]]></description><link>https://dannguyenhuu.substack.com/p/ai-multiple-expansion-and-operating</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/ai-multiple-expansion-and-operating</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 30 Jul 2024 13:35:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!F4ZW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F4ZW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F4ZW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F4ZW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:428714,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F4ZW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!F4ZW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F516f528a-8729-4bcc-8a76-6fad0de89d3c_1024x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Quick Recap:</strong></h3><p>In last month&#8217;s <a href="https://dannguyenhuu.substack.com/">Founder Catalyst</a> edition, I introduced the concept of the <a href="https://dannguyenhuu.substack.com/p/introducing-the-managed-service-as">Managed Service-as-Software</a> startup where AI-driven service-oriented startups build their companies according to a new business model blueprint. This requires a fundamental shift in mindset for startups to use AI, rather than to sell AI. Initially labor-intensive with low gross margins, these startups gradually shift to higher SaaS-like gross margins through automation and AI. As described in my previous post, this model had already been proven before in the managed cybersecurity space where companies like <a href="https://expel.com/">Expel</a> and <a href="https://arcticwolf.com/">Arctic Wolf</a> started as lower margin managed security service providers and evolved into higher margin software based security platforms using automation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7crs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7crs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 424w, https://substackcdn.com/image/fetch/$s_!7crs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 848w, https://substackcdn.com/image/fetch/$s_!7crs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 1272w, https://substackcdn.com/image/fetch/$s_!7crs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7crs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png" width="1456" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7crs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 424w, https://substackcdn.com/image/fetch/$s_!7crs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 848w, https://substackcdn.com/image/fetch/$s_!7crs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 1272w, https://substackcdn.com/image/fetch/$s_!7crs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91e0e94-664d-4251-8fae-3653d4826e47_1456x808.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In that article, I tried to emphasize the need for an initial labor-first approach coupled with robust AI tooling, and operational monitoring to achieve SaaS-like efficiency and profitability while providing high quality service delivery that is human augmented. This follow up piece dives into the financial and valuation implications of this shift, specifically focusing on <strong>AI-Operating Margin Gain</strong> and <strong>AI-Margin Expansion</strong>.</p><h3>AI-Operating Margin Gain </h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zIBk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zIBk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 424w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 848w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 1272w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zIBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png" width="1456" height="930" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:930,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:317477,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zIBk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 424w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 848w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 1272w, https://substackcdn.com/image/fetch/$s_!zIBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fee71-1902-4c0c-8a9a-fa8256241aea_2102x1342.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI-Operating Margin Gain refers to the gap between consulting gross margins and software gross margins, that is exploitable using AI, agents and automation. Traditional consulting businesses typically operate with gross margins in the mid-30% range due to their labor-intensive nature since the service is delivered via consultants. In contrast, software businesses often achieve gross margins around ~70% because of their lower delivery costs, usually COGS in the form of cloud hosting costs. This significant disparity makes consulting companies operationally less attractive. AI-driven M-SaS startups have the potential to bridge this gap by gradually automating their services, thus reducing labor costs and increasing gross margins over time. By leveraging robust AI tools and maintaining operational intelligence, these startups can achieve SaaS-like efficiency and profitability, ultimately driving higher valuations.</p><h3><strong>AI-Margin Expansion</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o5x2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o5x2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 424w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 848w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o5x2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png" width="1456" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:284080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o5x2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 424w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 848w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!o5x2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8474bcf-61e6-46cf-9abe-56d03e4615fc_2016x1240.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI-Margin Expansion (AI-ME) is defined by the gap in valuation multiples between consulting businesses and software businesses that can is exploitable using AI, agents and automation. Consulting companies typically trade at enterprise value to revenue (EV/Rev) multiples of 2-3x, while software companies often achieve multiples of 8-12x, and sometimes as high as 25-30x during bull markets. This difference is primarily due to the scalability and high margins of software businesses, which public market investors find more appealing. By transforming into M-SaS businesses, AI-driven startups can position themselves to capture these higher multiples while starting with a more labor intensive approach in the beginning. This involves not only delivering software but also providing a comprehensive service, thereby raising their gross margin profile and attracting better valuations long term. The old venture capital adage of &#8220;don&#8217;t do services&#8221; is maybe from a bygone time, where the gap between software and consulting businesses was significantly larger, like 10-15x, than it is currently, like 4-5x. For the best performing hybrid software / services companies like <a href="http://Palantir.com">Palantir</a> for example the multiple is almost the same or even better than any other software business. With the advancements of AI, the convergence between software and services will likely speed up even more.&nbsp;</p><h3><strong>For Managed-Service-as-Software Startups</strong></h3><p>For startups looking to build Managed Service-as-Software businesses, the implications of AI-OMG and AI-ME might be profound. Starting with low or even negative gross margins is acceptable due to initial investments in labor and compute. However, the journey from 0% to 70% gross margins must be meticulously managed with both a focus on operational intelligence and patience as the process can span several years and the business matures. This fundamental shift from a traditional software business model to an M-SaS model requires a holistic approach to managing engineering, product, sales, marketing, and operations. By offsetting labor costs with GPU costs and leveraging AI to enhance service delivery, startups can significantly improve their margins and achieve software valuations.</p><p>As always, if you are thinking about or building in this space please reach out to me or join our <a href="https://dannguyenhuu.substack.com/p/introducing-the-founder-catalyst">Founder Catalyst community!</a></p>]]></content:encoded></item><item><title><![CDATA[Introducing: The Managed-Service-as-Software (M-SaS) Startup]]></title><description><![CDATA[A technology disruption like AI is especially powerful for startups when paired with a business model disruption.]]></description><link>https://dannguyenhuu.substack.com/p/introducing-the-managed-service-as</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/introducing-the-managed-service-as</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Fri, 28 Jun 2024 13:12:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Acfl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Acfl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Acfl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Acfl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:627582,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Acfl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Acfl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1beb0529-45f3-4038-a635-78947f62147d_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In November of last year, I first wrote about the new paradigm of <a href="https://www.latent.space/p/agents">AI agents</a> becoming the fundamental technology driving a new era of software: <a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software">Services-as-Software</a>, where startups provide service-oriented, outcome-driven solutions to their customers using AI agent technology. With this change in how startups would deliver value came many new potential business considerations such as pricing which I discussed in detail <a href="https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion">here</a>.&nbsp;</p><p>One interesting aspect that is still overlooked in this new paradigm, however, is the potential to build according to a very different business model blueprint. If we quickly review the history of how software business models functioned pre-AI:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UVYD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UVYD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 424w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 848w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 1272w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UVYD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png" width="1456" height="820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UVYD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 424w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 848w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 1272w, https://substackcdn.com/image/fetch/$s_!UVYD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584b88cf-3b54-497e-88b8-7231068be39f_1600x901.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://en.wikipedia.org/wiki/On-premises_software">On-Premise</a>: As software was installed on-premise at the customer site, software was sold in the form of <a href="https://www.techtarget.com/whatis/definition/enterprise-license-agreement-ELA">ELAs (Enterprise License Agreements</a>) with an attached support contract. The ELA was essentially a large dollar amount that allowed customers to use the software into perpetuity while the maintenance/support contract was annually recurring in nature. Traditionally, the breakdown between the perpetual license and support was a 90% / 10% split. For example, a <a href="https://www.vmware.com/products/vsphere.html">VMware vSphere</a> license, illustratively, would be $900K with a $100K support contract, for a total contract size (TCV) of $1M. The customer could use that version of the VMware license forever, but of course, every 2-3 years there would be a refresh cycle which would allow VMware to charge for their latest version. Since a service would be associated with maintenance, only 10% of the ELA would be annually recurring.&nbsp;</p><p><a href="https://en.wikipedia.org/wiki/Cloud_computing">Cloud: </a>In the era of cloud, we were able to deliver software directly to the customer without coming on site for installation. Since everything ran and still runs through the cloud, the way we charge for software also changed to a fully recurring model. No longer did we split up the perpetual license against an ongoing support license. Support and license became one, charged annually, and thus <a href="https://en.wikipedia.org/wiki/Software_as_a_service">SaaS</a> was born. Many new SaaS companies emerged as incumbents struggled to keep up, often due to the challenges of replatforming to the cloud and their entrenched ways of selling software.&nbsp;</p><p>With every new technology development comes a new business model disruption. With AI at our fingertips, a new path has been forged for startups to consider when building the next generation of companies, which I call <em><strong>Managed </strong></em><strong><a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software">Services as Software</a></strong><em><strong>.</strong></em>&nbsp;</p><h3><strong>Consulting and Software: An &#8220;It&#8217;s Complicated&#8221; Love Story</strong></h3><p>&#8220;Managed&#8221; typically implies a human labor component for service delivery, and this is no different. Many large product companies began as consulting businesses, gradually shifting as they achieved <a href="https://www.productplan.com/glossary/product-market-fit/">product-market-fit </a>with a particular product they initially provided through white-glove service for clients before transitioning to SaaS. <a href="https://www.freshbooks.com/about/ourstory">FreshBooks</a>, <a href="https://www.linkedin.com/pulse/from-web-design-consultants-12-billion-exit-story-mailchimp-hoque-2disf/">Mailchimp</a>, and <a href="https://www.uipath.com/about-us#:~:text=Our%20story%20starts%20in%202005,us%2C%20starting%20with%20our%20leadership.">UIPath</a> are just a few examples of giants that made that transition. Turning a service business into a SaaS business is now a textbook strategy, provided you can find the right product to build your software company around.&nbsp;</p><p>However, a few companies have taken a different approach, remaining in a traditionally labor-intensive, consulting-led services world, but using technology to drive better margins over time. <a href="https://expel.com/">Expel</a> and <a href="https://arcticwolf.com/">Arctic Wolf</a> are both cybersecurity players that have embraced a software-enabled service business model. In a way, both have effectively outsourced the role of <a href="https://www.techtarget.com/searchsecurity/definition/Security-Operations-Center-SOC">Security Operations Center (SOC)</a> and delivered it back to customers through a managed experience, known in the security world as a <a href="https://www.crowdstrike.com/cybersecurity-101/managed-detection-and-response-mdr/">managed detection and response (MDR</a>) service.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_bi4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_bi4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 424w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 848w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 1272w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_bi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png" width="1456" height="809" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:809,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_bi4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 424w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 848w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 1272w, https://substackcdn.com/image/fetch/$s_!_bi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe037e589-1094-4cba-8c5c-2e18bf6680f8_1600x889.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Internally, however, they have continued to innovate and automate their operations to drive towards SaaS-like margins. Through rigorous operations and automation, these businesses, traditionally with 20-30% gross margins due to high labor costs, have willed themselves to 70-80% gross margins over 8-12 years. The MDR product space became so lucrative that even product companies like <a href="https://www.crowdstrike.com/en-us/">CrowdStrike,</a> which originally focused on <a href="https://www.crowdstrike.com/platform/endpoint-security/">endpoint agent</a> technology, entered the market with their own MDR offering, <a href="https://www.crowdstrike.com/services/managed-services/falcon-complete/">CrowdStrike Falcon Complete</a>.&nbsp;</p><h3><strong>Sell AI or use AI yourself? Introducing the Managed-Service-as-Software Startup</strong></h3><p>Philosophically, the biggest change is that instead of trying to sell AI to customers, startups should think about delivering value by using the AI they built themselves. You might ask, &#8220;Hey, doesn't that make me a consulting business?&#8221; &#8211; and the answer is partially yes. M-SaS businesses are AI powered services businesses that over time drive from low (20-30%) gross margins, while labor intensive, to high / SaaS-like (70-80%) gross margins, when AI intensive. The service delivered remains unchanged to the customer throughout the journey.</p><p>Following the principles of the Managed Detection and Response market, there is an opportunity for the new generation of startups to mimic the operational prowess of Expel and Arctic Wolf. However, in this time frame these new companies can use their era-appropriate technology of LLMs, agents, and GPUs instead of business logic software, static automation, and CPUs. The net result could mean that accomplishing 70% gross margins as is typical with software companies could be achieved in maybe less than half the time than it took the previous generation, all pending the cost of GPU declining at a faster rate as the cost of labor (which is really only increasing).&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!707l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!707l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 424w, https://substackcdn.com/image/fetch/$s_!707l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 848w, https://substackcdn.com/image/fetch/$s_!707l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 1272w, https://substackcdn.com/image/fetch/$s_!707l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!707l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png" width="1456" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!707l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 424w, https://substackcdn.com/image/fetch/$s_!707l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 848w, https://substackcdn.com/image/fetch/$s_!707l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 1272w, https://substackcdn.com/image/fetch/$s_!707l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f367cf0-7a0b-44e9-8a22-c0cc3b580287_1600x888.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Starting with a labor-intensive service delivery model requires upfront investment in both automation scaffolding for scale, as well as a competent human service desk. In a way, a M-SaS company never has to pass the <a href="https://en.wikipedia.org/wiki/Turing_test">Turing test </a>because in its initial stage of service delivery, it is largely human. The goal of the engineering team would be to supercharge the human service desk employee and to enable them to service an increasing amount of customers over time, leveraging automation &amp; AI tooling. On the other side, the customer experiences consistent service without necessarily knowing or caring if AI is used in the process. The graphic above demonstrates this (with completely illustrative timeline and figures): initially, each service operations employee can service a small number of customers, but over time, this scales up significantly to ten and then hundreds of customers. Since labor required per customer is decreasing while automation &amp; AI is increasing (assuming falling compute GPU costs), gross margins would improve. The following summarizes the basic building principles for a M-SaS business.&nbsp;</p><ol><li><p><strong>Labor-First Approach</strong>: Initially, focus on delivering an excellent client experience through a labor-intensive model. Although gross margins will suffer initially, this sets the stage for long-term success.</p></li><li><p><strong>Build AI Tooling and Automation</strong>: Develop AI tools and automation to make your operations &amp; service delivery desk more efficient, aiming to serve more clients per unit of labor over time. This will gradually reduce the reliance on labor and increase efficiency.</p></li><li><p><strong>Increase GPU Utilization</strong>: As technology and automation improve, the ratio of labor per client will decrease, allowing for higher margins and better service delivery.</p></li><li><p><strong>Operational Monitoring</strong>: Maintain rigorous operational monitoring to ensure uptime and efficiency. High inference costs from GPUs may initially be higher than labor costs, but these are expected to decrease over time, justifying the investment long term.</p></li></ol><p>What this means in practice for M-SaS businesses is that it is acceptable to start with low or even negative gross margins due to upfront investments in both labor and compute costs, especially when customer count is low or non-existent at the beginning. However, the path from 0% to 70% gross margins should be closely monitored, and M-SaS founders should maintain full operational intelligence at every step. This requires a fundamental mindset shift from the typical software business model. You are not just delivering software but a full-fledged service, which involves managing not only engineering, product, sales, and marketing, but in particular operations. </p><h3><strong>Conclusion</strong></h3><p>The market is increasingly willing to pay for outcomes rather than traditional software tooling. Whether your AI tools are used internally to drive efficiency or sold to external customers, the key is their usage. Modern startups can potentially do both, making the question more about sequencing rather than where you start and end up. Leveraging the new paradigm of AI and decreasing GPU costs should eventually lead to the creation of more M-SaS driven companies. These companies will transform from labor-intensive operations to technology-enhanced services with SaaS-like margins and, consequently, SaaS-like valuations.&nbsp;</p><p>As always, if you are interested or working on an idea on this topic please reach out to me or join our <a href="https://dannguyenhuu.substack.com/p/introducing-the-founder-catalyst">Founder Catalyst Community!</a></p><p></p><p><em>Special thank you to Amil Naik who helped me clarify my thoughts and pull this piece together.</em> </p>]]></content:encoded></item><item><title><![CDATA[Introducing the Founder Catalyst Community: Join Us on Slack! ]]></title><description><![CDATA[A place for prospective and repeat founders to discuss new ideas, share learnings and start the companies of tomorrow.]]></description><link>https://dannguyenhuu.substack.com/p/introducing-the-founder-catalyst</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/introducing-the-founder-catalyst</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Thu, 30 May 2024 15:08:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j0H5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j0H5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j0H5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 424w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 848w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 1272w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j0H5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4920485,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j0H5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 424w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 848w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 1272w, https://substackcdn.com/image/fetch/$s_!j0H5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59b807c2-48c5-4609-a1d5-c55d37ebf4b9_2140x1430.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At Decibel, we have always believed in the power of<em><strong> </strong></em>serendipity. By bringing the right people together, we can create an environment where magic happens.&nbsp;</p><p>A few months ago we started a series of small dinners with both prospective and repeat founders, thinking through new ideas and markets, discussing topics such as the <a href="https://dannguyenhuu.substack.com/p/the-programmable-defense">programmable cyber defense</a> or <a href="https://www.decibel.vc/articles/service-as-software-powered-by-ai-agents">Service-as-Software via AI agents</a> as well as more strategic items like <a href="https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion">pricing in the AI</a> world.</p><p>We named these gatherings Founder Catalyst because our vision for starting a great company involves a few crucial elements. These catalysts can take many forms:</p><ul><li><p>Meeting the Right Co-Founder</p></li><li><p>Discovering the Right Idea</p></li><li><p>Receiving Key Insights from Customers</p></li><li><p>Securing Capital</p></li></ul><p>Often, the magic lies in the combination of all these elements. Our dinners have sparked lively conversations and even birthed a few company ideas. Today, we're collaborating with several Founder Catalyst members to incubate a variety of companies that originated from these get togethers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-09U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-09U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-09U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-09U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-09U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-09U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24859647,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-09U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-09U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-09U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-09U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F298ff2db-a8be-4df9-bfc5-e6fc67f776c2_7360x4912.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the past few months, many of you have asked for a virtual space to continue building relationships and exchanging ideas. In response, we're excited to announce the launch of the <strong>Founder Catalyst Community on Slack</strong>!</p><p>If you are a product, sales, or engineering leader with aspirations of starting a company one day in the field of technical software, this community is for you.</p><p>Sign up <strong><a href="https://docs.google.com/forms/d/e/1FAIpQLSfpfl9ks37X1xBXfrF4GUicVPZ9KE4WaPwcJtQZjFOQXoJf_A/viewform?vc=0&amp;c=0&amp;w=1&amp;flr=0">here</a></strong> (or ping me) to become part of this community which includes product and engineering leaders from Zoom, Duo Security, Rubrik,&nbsp;Meta, Harness, Atlassian and Google among many others and attend our upcoming founder events!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXbr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXbr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 424w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 848w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 1272w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXbr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png" width="1456" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5632488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXbr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 424w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 848w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 1272w, https://substackcdn.com/image/fetch/$s_!NXbr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7d184a-f7d2-44f5-b914-92b316c4a318_2144x1414.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Programmable Defense]]></title><description><![CDATA[Security Engineering & GenAI Might Spell the End of the Security Black Box Vendor As We Know Them.]]></description><link>https://dannguyenhuu.substack.com/p/the-programmable-defense</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-programmable-defense</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Wed, 10 Apr 2024 13:30:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lhoP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lhoP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lhoP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 424w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 848w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lhoP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png" width="1000" height="1006" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1006,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1877897,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lhoP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 424w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 848w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!lhoP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cfb1656-a492-4b7c-957e-b62460b5f77c_1000x1006.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hackers are just like us: they don't really want to do the work. With the introduction of LLMs into our lives, it became immediately clear that there was a huge gain in labor productivity to be had for all knowledge workers. In the arena of cybersecurity, this has ushered in a new era in an industry where there is already a massive labor shortage to begin with. Of course, the opponent on the other side of the field (or rather web) is not sitting idle. Threat actors have already started to experiment with AI to supplement or enhance their own attack campaigns. And so, much like the ease at which we can now generate essays or complex documents using tools like ChatGPT, the barrier to entry for hackers orchestrating cyber attacks has plummeted. This has led to a significant uptick in both the variety and volume of cyber threats. This phenomenon is already evident today in areas such as phishing, which is <a href="https://www.cnbc.com/2023/11/28/ai-like-chatgpt-is-creating-huge-increase-in-malicious-phishing-email.html">up 967% since Q4 of 2022</a>, or endpoint security, where a ChatGPT-based<a href="https://www.csoonline.com/article/575487/chatgpt-creates-mutating-malware-that-evades-detection-by-edr.html"> Polymorphic code was able to evade EDR systems</a>. As we enter this new AI-fueled era where hackers are utilizing these new tools, <a href="https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c01.pdf">security engineering,</a> a discipline that focuses on detecting malicious activities or unauthorized behaviors, will become more important than ever.&nbsp;</p><p>Modern security organizations have invested heavily into building out personnel and tooling in that department. A member of the <a href="https://staceywueste.substack.com/?utm_source=substack&amp;utm_medium=web&amp;utm_campaign=substack_profile">Decibel early adopter community &#8211;</a>a global banking institution &#8211; stated that they were analyzing over 1 petabyte of security data per day with over 1000 security engineers working in the organization. For organizations with limited budgets for direct investment in security engineering, vendors such as <a href="https://arcticwolf.com/">Arctic Wolf</a> and <a href="https://expel.com/">Expel</a> have provided assistance. The commercial success of these companies, both having valuations of $4B and $1B respectively, underscores a trend: customers are increasingly seeking security engineering solutions, whether in-house or through outsourcing.&nbsp;&nbsp;</p><p>As the enemy upgrades its arsenal with a broader range and variety of AI-based attacks, it becomes evident that security engineers will need new tools to counter these threats effectively. The traditional reliance on vendors for updates and patches is becoming increasingly untenable in this rapidly evolving landscape. The burgeoning field of security engineering had embodied this shift towards adaptability and self-reliance long before the AI hype cycle, but against the plethora of attacks GenAI might unleash, security teams are craving control, transparency, and explainability over their defensive measures more than ever.</p><p>In the following, I wanted to explore a few of the product principles that might be incorporated into the next generation of security tooling and how they might spell the end of Black Box type products as we know them.&nbsp;</p><h4><strong>Vendor Bottleneck vs. Adaptability, Transparency &amp; Explainability</strong></h4><p>It is unsurprising that the sheer volume and variety of email attacks has drastically increased with the adoption of LLMs by hackers. This in turn has prompted email detection teams to take a more proactive stance to keep their inboxes safe. In a vendor-dominant world, customers might find themselves queueing up to get critical security issues addressed, especially if they're not deemed 'important' customers.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lsJN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lsJN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 424w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 848w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 1272w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lsJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png" width="1456" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lsJN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 424w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 848w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 1272w, https://substackcdn.com/image/fetch/$s_!lsJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28f824fb-3a2b-43cd-9d7c-6e7d5a872aca_1600x690.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Custom detections by Sublime Security&nbsp;</em></p><p><a href="https://sublime.security/">Sublime Security</a> has emerged with an alternative approach, offering a unique solution to email security. By allowing detection teams to write, run, and share custom detection rules to threat-hunt phishing attacks, Sublime enables a level of customization and transparency that empowers defenders to respond swiftly to phishing attacks. This open platform approach not only facilitates rapid adaptation to newly observed phishing techniques but also fosters collaboration across organizations, effectively democratizing the fight against email-originated threats. The more detections are contributed by Sublime&#8217;s users the more effective the system becomes.</p><h4><strong>Us Against Them: Community vs. Vendor System</strong></h4><p>The battle against cyber threats&#8212;be they from nation-states or hacker groups&#8212;is more effectively fought as a collective rather than in isolation. Security practitioners have long congregated in digital forums like Slack channels, Twitter, and HackerNews, sharing insights and strategies, but implementing them uniformly has always been a challenge. As <a href="https://www.linkedin.com/in/michael-schwartz-7128a57/">Mike Schwartz</a>, former Cybersecurity leader at AWS and Target, pointed out to me, &#8220;the implementation of this shared knowledge often hits a wall at the product level because everyone has different vendor tooling and thereby can&#8217;t be implemented in a prescribed way&#8221;.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XCtN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XCtN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 424w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 848w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 1272w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XCtN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png" width="1456" height="1337" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1337,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XCtN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 424w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 848w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 1272w, https://substackcdn.com/image/fetch/$s_!XCtN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59dc1846-a3d1-4644-bf34-0d79752e8958_1600x1469.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Community Rules by Semgrep&nbsp;</em></p><p>The <a href="https://semgrep.dev/">Semgrep</a> community exemplifies this proactive stance, swiftly sharing code fixes in response to new Common Vulnerabilities and Exposures (CVEs), underscoring the importance of agility and collaboration in modern cybersecurity efforts. This highlights the need for a community-first approach, where enterprises can unite, speak a common language, and implement solutions directly, without being hampered by vendor bottlenecks. Just based on the sheer volume of vulnerabilities that exist today, this is needed more than ever.&nbsp;</p><h4><strong>One Size Fits Most vs. Control &amp; Customization</strong></h4><p>The belief that a one-size-fits-all security solution is effective is becoming increasingly impractical. Modern IT ecosystems, characterized by their complex cloud infrastructures, containers, and continuously evolving attack surfaces, demand a security approach that goes beyond the limitations of traditional, generic solutions.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gZQd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gZQd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 424w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 848w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 1272w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gZQd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png" width="1454" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1454,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gZQd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 424w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 848w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 1272w, https://substackcdn.com/image/fetch/$s_!gZQd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698f5ce3-890f-4e1b-9a31-cd57e0d94581_1454x804.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Custom checks &amp; dashboards by Prowler&nbsp;</em></p><p>Within this context, <a href="https://github.com/prowler-cloud/prowler">Prowler </a>emerges with an interesting solution, specifically engineered for AWS environments. It distinguishes itself by offering a suite of tools designed for comprehensive security assessments and audits, enabling organizations to conduct in-depth analyses of their own AWS configurations against best practices and compliance standards. By allowing users to customize checks and adapt security configurations to their unique operational environments, Prowler facilitates a more open and granular approach to cloud security. This capability is essential for effectively managing the intricate requirements of today's IT infrastructures, ensuring that security measures are as nuanced and dynamic as the ecosystems they protect.&nbsp;</p><h4><strong>Conclusion</strong></h4><p>As we stand at the cusp of a new era in cybersecurity, it's clear that the traditional vendor-reliant defense mechanisms may not suffice against the sophisticated, AI-driven offensive tactics that are emerging. The future of cybersecurity lies in transparent, programmable, and community-driven systems that can serve as first-party data for a future autonomous defense. This approach will allow our future products to dynamically adapt and respond to new forms of attacks. Tools like Semgrep, Sublime, and Prowler are only a few examples of this trend, providing platforms that not only foster community collaboration, but also enable the tailored, flexible defense mechanisms that tomorrow's security landscape will likely demand.</p>]]></content:encoded></item><item><title><![CDATA[The Hunt for “Vulnerability Inbox 0”]]></title><description><![CDATA[Emerging Techniques to Reduce Application Vulnerability Overload]]></description><link>https://dannguyenhuu.substack.com/p/the-hunt-for-vulnerability-inbox</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-hunt-for-vulnerability-inbox</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 06 Feb 2024 15:16:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uHqE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uHqE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uHqE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uHqE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uHqE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uHqE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45455ad3-48da-4662-b4ad-686b02b9fe11_1024x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Speaking with several CISO and security leaders over the last few months, it is clear that <a href="https://www.crowdstrike.com/cybersecurity-101/vulnerability-management/">Vulnerability Management</a> remains a significant challenge for many organizations. Security teams often find themselves <a href="https://venturebeat.com/security/manage-alerts-vulnerabilities/">overwhelmed by the sheer number of vulnerabilities </a>detected, struggling to categorize, prioritize and address them effectively. On average, <a href="https://venturebeat.com/security/vulnerability-management-most-orgs-have-a-backlog-of-100k-vulnerabilities/">100,000 </a>vulnerabilities remain unaddressed in an organization&#8217;s security backlog. With developers leaning more and more into AI-powered code development tools like <a href="https://github.com/features/copilot">Github Copilot</a>, which rely on human trained data, vulnerabilities will likely continue to rise. Indeed, a <a href="https://www.spiceworks.com/it-security/security-general/news/40-of-code-produced-by-github-copilot-vulnerable-to-threats-research/">study at NYU</a> had revealed that 40% of code produced by Copilot was indeed vulnerable, while a <a href="https://ee.stanford.edu/dan-boneh-and-team-find-relying-ai-more-likely-make-your-code-buggier">study at Stanford</a> showed developers believed their code was more sound when using an AI tool when the code was actually more vulnerable.</p><p>With the emergence of <a href="https://www.synopsys.com/glossary/what-is-software-composition-analysis.html">SCA (software composition analysis)</a>, we have vastly increased the amount of vulnerabilities we detect, but that has left us with a different problem: How do we fix them when there are so many? The reality is that while we have a relatively firm grasp of detection with tools such as <a href="https://snyk.io/">Snyk</a>, <a href="https://www.contrastsecurity.com/">Contrast Security,</a> and <a href="https://checkmarx.com/">Checkmarx</a>, we have not yet solved the human problem associated with remediation. The issue with remediation falls into 2 categories:</p><ol><li><p>Focus and Prioritization: Using the limited developer time available to focus on what vulnerabilities need to be addressed more urgently&nbsp;</p></li><li><p>Automating Developer &amp; Security work: It's hard to get valuable developer time spent on security issues over product features</p></li></ol><p>In order to address this, a new crop of companies have started to develop over the last few years. In the following, I wanted to highlight some of the really interesting approaches and techniques that are being developed to usher in the next era of application vulnerability management.</p><p></p><h3><strong>Pre-Production Reachability&nbsp;</strong></h3><p>In the face of overwhelming vulnerabilities within an application, it's essential to discern their actual impact. Many of these vulnerabilities may reside in third-party code that isn't even executed by the app, rendering them non-exploitable. This raises an important consideration: are some vulnerabilities essentially unreachable and, therefore, less critical to address immediately? By identifying these unreachable vulnerabilities, developers and security teams can prioritize their efforts on those vulnerabilities that genuinely affect the application in its current production state. This approach is called <a href="https://snyk.io/blog/reachable-vulnerabilities/">Reachability Analysis</a>. Although eventually, in a perfect world all vulnerabilities warrant attention, understanding where to begin can significantly streamline the remediation process and limit the precious impact to developers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X90M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X90M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 424w, https://substackcdn.com/image/fetch/$s_!X90M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 848w, https://substackcdn.com/image/fetch/$s_!X90M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 1272w, https://substackcdn.com/image/fetch/$s_!X90M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X90M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png" width="1456" height="692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:692,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X90M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 424w, https://substackcdn.com/image/fetch/$s_!X90M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 848w, https://substackcdn.com/image/fetch/$s_!X90M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 1272w, https://substackcdn.com/image/fetch/$s_!X90M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff22f0bb2-ef5e-48a6-90b8-5162cf2e75dc_1600x760.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>                                               Reachability-based SCA by Endor Labs</em></p><p>One example of startups trying to address this is <a href="https://www.endorlabs.com/">Endor Labs</a>. Endor Labs' approach to SCA reachability is centered around the concept of analyzing the code behavior at build time to identify reachable vulnerabilities at the function level. This is achieved through a combination of static analysis of source code, manifest files, file system, and package manager data. Static call graphs are used as a precise instrument for this analysis, enabling the identification of direct and transitive dependencies, including those not declared in manifest files. This approach not only helps in prioritizing reachable risks but also provides a comprehensive view of all dependencies in use, improving the accuracy and reducing the time and cost associated with remediation. Endor Labs' method is distinguished by its ability to map vulnerabilities in open-source libraries in their real-world context, leveraging call graphs to trace relationships between software functions. This enables a more precise identification of vulnerabilities that are actually exploitable in the application's unique context.</p><p>The end result of this is self-evident. By using <a href="https://snyk.io/blog/reachable-vulnerabilities/">reachability</a> as a core tenant to understanding priority of remediation of a particular vulnerability, security teams can be more targeted in trying to prioritize fixes within their control. Solutions like <a href="https://www.slim.ai/">Slim.ai</a> can then also provide a shared workspace among customers and software vendors to coordinate vulnerability fixes involving third parties.&nbsp;</p><p></p><h3><strong>Runtime Instrumentation for Vulnerability Prioritization</strong></h3><p><a href="https://thenewstack.io/prioritize-runtime-vulnerabilities-via-dynamic-observability/">Runtime Instrumentation</a>, when used in the context of vulnerability prioritization, embeds monitoring capabilities directly into the application code, thus actively observing its interactions with various components like libraries and infrastructure. This method is particularly advantageous for identifying and prioritizing security vulnerabilities in real-time. By monitoring internal operations, runtime instrumentation can detect unusual patterns or behaviors that may indicate security flaws. This immediate detection allows for quicker response to potential threats, reducing the window of opportunity for exploitation.</p><p>The detailed insights provided by runtime instrumentation into the application's functioning enable a more nuanced assessment of vulnerabilities. It helps in understanding the context and potential impact of a security flaw within the application's unique environment. This context-specific information is crucial for prioritizing vulnerabilities effectively, ensuring that the most critical issues are addressed first.</p><p>One company in the space is called <a href="https://www.oligo.security/">Oligo Security</a>. The company&#8217;s product utilizes dynamic library-level analysis and behavior monitoring to identify vulnerabilities in real-time. This approach is particularly effective in detecting vulnerabilities in open-source libraries during runtime. By analyzing each library's behavior, Oligo creates profiles of legitimate activity and generates alerts or blocks suspicious deviations from these patterns. This targeted approach filters out about 85% of alert noise, significantly reducing cybersecurity fatigue.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!22PN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!22PN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 424w, https://substackcdn.com/image/fetch/$s_!22PN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 848w, https://substackcdn.com/image/fetch/$s_!22PN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 1272w, https://substackcdn.com/image/fetch/$s_!22PN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!22PN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png" width="1224" height="656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:656,&quot;width&quot;:1224,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!22PN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 424w, https://substackcdn.com/image/fetch/$s_!22PN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 848w, https://substackcdn.com/image/fetch/$s_!22PN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 1272w, https://substackcdn.com/image/fetch/$s_!22PN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6187f073-8f9b-4594-a6e0-a1b8e3c0c5fe_1224x656.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>                                     Oligo Runtime-Based Vulnerability Prioritization&nbsp;</em></p><p>Oligo's platform is based on the <a href="https://ebpf.io/">eBPF</a> subsystem, a technology developed for the Linux kernel. This allows Oligo to run efficiently without compromising on performance or stability. The platform's focus is on identifying vulnerabilities based on the context of the running application, thereby helping developers and security teams focus on the actual attack surface, which is often a fraction of the vulnerabilities identified by traditional tools. This method not only streamlines the security process but also accelerates development by allowing teams to concentrate on the most relevant issues&#8203;.</p><p></p><h3><strong>Autonomous Product Security Engineering</strong></h3><p>Autonomous <a href="https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/cybersecurity/product-security-navigating-regulations-and-customer-expectations">product security</a> engineering represents a significant advancement in the realm of application security. By integrating directly into developers' workflows, this approach can effectively alleviate vulnerabilities in real-time. It operates by analyzing code during the development process and proactively suggesting code fixes. This method not only identifies potential security issues but also offers immediate, actionable solutions, seamlessly blending security practices with the development process. This integration helps maintain the flow of development while ensuring that security is a continuous, integral part of the process rather than an afterthought. Such a system significantly reduces the time and resources typically needed for vulnerability detection and remediation, and it enhances overall application security without disrupting the development cycle.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J0fA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J0fA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 424w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 848w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 1272w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J0fA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png" width="1456" height="1041" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1041,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J0fA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 424w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 848w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 1272w, https://substackcdn.com/image/fetch/$s_!J0fA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c2c451e-355f-435c-bb18-47e77545212a_1600x1144.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>              Pixeebot monitors code repositories and provides high quality fixes instantly</em></p><p><a href="https://www.pixee.ai/">Pixee.ai</a> has pioneered a developer tool for enhancing application security. Their product, Pixeebot, is designed to identify and fix vulnerabilities within code, effectively streamlining the software development process. By integrating directly into the development environment, <a href="https://github.com/apps/pixeebot">Pixeebot</a> offers high-quality, instant fixes as developers or AI-assistants work on code. This approach ensures that developers can maintain their productivity and focus while simultaneously enhancing the security and quality of their code. Essentially, Pixeebot acts like an automated security engineer, seamlessly integrating into the development workflow and significantly reducing the backlog of security tickets by transforming code scan results into actionable pull requests for merging.&nbsp;</p><p></p><h3><strong>Conclusion</strong></h3><p>The emerging techniques in application vulnerability management, such as Pre Production Reachability, Runtime Instrumentation, and Autonomous Product Security Engineering are clearly attempting to solve one of the biggest problems in cybersecurity in vulnerability overload among security teams. As many breaches still begin with unpatched vulnerabilities, it is still a key obstacle in getting a strong security posture among enterprises. By prioritizing actionable vulnerabilities, integrating directly into developers' workflows, and employing advanced technologies, these approaches are not only addressing the current challenges in vulnerability management but also paving the way for more efficient and secure software development practices.</p><p></p><p><em>Special thank you to Sean Cassidy, Mike Schwartz, Arshan Dabirsiaghi, Ed Bellis and Surag Patel who provided incredibly valuable input and helped me think through some of these concepts.</em></p>]]></content:encoded></item><item><title><![CDATA[The Price is AI-ght? A Short Discussion on Pricing Models for AI Startups]]></title><description><![CDATA[In the ever-changing world of software pricing, the rise of AI agent applications could lead to a significant change in how companies determine the value of their products.]]></description><link>https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/the-price-is-ai-ght-a-short-discussion</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Fri, 15 Dec 2023 15:42:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gVki!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gVki!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gVki!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 424w, https://substackcdn.com/image/fetch/$s_!gVki!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 848w, https://substackcdn.com/image/fetch/$s_!gVki!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 1272w, https://substackcdn.com/image/fetch/$s_!gVki!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gVki!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png" width="815" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:815,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gVki!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 424w, https://substackcdn.com/image/fetch/$s_!gVki!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 848w, https://substackcdn.com/image/fetch/$s_!gVki!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 1272w, https://substackcdn.com/image/fetch/$s_!gVki!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a24d5fe-2cd9-4494-bf04-3a3f5d31a647_815x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the ever-changing world of software pricing, the rise of <a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software">AI agent applications</a> could lead to a significant change in how companies determine the value of their products. To grasp this potential shift, it's insightful to examine the history and recent trends in software pricing models,&nbsp; particularly focusing on seat-based pricing and consumption-based pricing.</p><p>Salesforce, for example, has famously employed a seat-based pricing model. This model is characterized by charging per user, with pricing tiers offering varying levels of functionality, starting with around <a href="https://www.salesforce.com/products/sales-pricing/">$25 per user per month</a> with incremental creeping up to their Lighting Unlimited package of <a href="https://www.salesforce.com/products/sales-pricing/">$325 per user per month</a>&#8203;.&nbsp;</p><p>In contrast, <a href="https://hginsights.com/glossary/consumption-based-pricing-model">consumption-based pricing</a>, as used by companies like Snowflake and Databricks, charges based on the amount of resources or services consumed by the user. This model aligns well with data and cloud computing platforms where the usage can vary significantly across customers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2rcJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2rcJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 424w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 848w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2rcJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png" width="1456" height="793" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:793,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:484381,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2rcJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 424w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 848w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!2rcJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4ec2-3668-465f-b5a8-55704ccc64d0_2932x1596.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The introduction of AI agent applications adds a new dimension to the pricing discussion. Agents&#8217; unique value proposition, coupled with diverse applications across various business functions, significantly complicates pricing strategy. Companies must consider the value delivered by the AI, the costs associated with its operation, and customer preferences. So, if you are an AI startup, how should you address these factors and determine pricing?&nbsp;</p><p>In the following, I try to explore three models around pricing for the next generation AI agent companies, analyzing the potential benefits and drawbacks of each approach.&nbsp;</p><h4><strong>AI Copilot &#10145;&#65039; Seat-Based Pricing</strong></h4><p>If you are building a AI Copilot company, a seat-based pricing model may be a good fit. This approach aligns with the product&#8217;s aim to supercharge an individual's performance. Since a copilot product is intended to enhance the productivity and capabilities of specific roles within an organization, the pricing should be linked to each individual user. An obvious example of this is Github Copilot, which charges <a href="https://github.com/features/copilot#pricing">$10 per user per month</a> and can go up to $39 per user for enterprise features.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x2BL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x2BL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 424w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 848w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 1272w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x2BL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png" width="1456" height="716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:716,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:363577,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x2BL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 424w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 848w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 1272w, https://substackcdn.com/image/fetch/$s_!x2BL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b7969bc-a5d3-4869-adbf-abff7131e596_2484x1222.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The per-user pricing of GitHub Copilot aligns with the direct benefit it provides to each individual developer&#8217;s productivity, and scales directly with an organization&#8217;s user base of engineers. The advantages of this pricing model is clear: it encourages users to use as much of the technology as possible, which has downstream benefits of increased user data for product iteration and virality within an organization. However, with essentially unlimited usage, the provider of the product faces less control over its cost structure. Theoretically, the product could continuously call upon the underlying foundation model, leading to potentially unbounded costs. A possible workaround for this would be implementing rate limits on usage, though it might have an impact on the perception of the product by customers.&nbsp;</p><h4><strong>AI Agents &#10145;&#65039; Usage-Based Pricing </strong></h4><p>Usage-based pricing in AI startups is a trend that aligns closely with the actual consumption of services, offering a more flexible and fair approach to customers. This model is particularly relevant in the field of AI Agents, where the computational demands can vary significantly based on the application and user engagement. By adopting this model, AI startups are able to offer their services in a way that scales with the customer's actual usage, ensuring a direct correlation between cost and value received.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hOPk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hOPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 424w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 848w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hOPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png" width="1456" height="459" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:459,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:733126,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hOPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 424w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 848w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!hOPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54b16c45-c608-4a0c-bdbb-84e07fe4ad59_3226x1018.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One notable example is <a href="https://www.intercom.com/">Intercom</a>'s AI chatbot Fin, introduced in March. Fin represents a shift in AI service pricing, charging customers <a href="https://www.intercom.com/fin">99 cents</a> for each customer request it successfully resolves. This pricing model represents a notable departure from traditional flat-rate or subscription models, aligning more closely with consumption-based strategies similar to those employed by&nbsp; cloud computing platforms such as <a href="https://www.snowflake.com/en/data-cloud/pricing-options/">Snowflake</a> and <a href="https://www.databricks.com/product/pricing">Databricks</a>. In these platforms, costs are calculated based on the computational resources used &#8211; typically measured in credits &#8211; and consumed according to data volume or task complexity. Similarly, Intercom's Fin directly ties the cost to the service's effectiveness, charging per resolved request, thereby aligning the cost with the value delivered.</p><p>Usage-based pricing models come with distinct advantages. The companies offering the product benefit from predictable costs as charges are tied to each use of the service, making it straightforward to understand the direct cost of calling the foundation model with each use. This transparency and direct correlation to usage make the model appealing to customers, as they only pay for what they actually use.</p><p>However, there are challenges to this model as well. For startups, revenue forecasting becomes more complex and less predictable, as income is directly tied to fluctuating customer usage patterns. Additionally, customers might seek workarounds to minimize their use of credits, potentially leading to underutilization of the service. This can discourage full usage of the AI capabilities, as customers may be motivated to conserve credits to save costs.</p><h4><strong>Autonomous AI Service &#10145;&#65039; Capacity-Based&nbsp;Pricing</strong></h4><p>As we enter the emerging world of AI agents and <a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software">Service as Software applications</a>, I have had a few interesting conversations around a potentially new developing pricing model, one that is closely linked to the cost savings in human labor. This model, which I&#8217;ll call &#8220;capacity&#8221; or &#8220;staff augmentation-based pricing&#8221;, aligns the value of AI solutions with the labor costs they offset or replace.</p><p>For instance, consider a traditional managed service provider who charges based on the staffing needs they fulfill. A similar approach can be applied to AI agents, where the cost of the AI solution can be benchmarked against the full cost of a human employee performing the same task. This includes not just the salary, but also additional expenses like healthcare benefits. If an AI agent can perform the work of a human IT analyst, who, for example, handles 5,000 IT tickets a year, the cost savings become evident. The AI&#8217;s pricing could then be set in proportion to the cost of the human labor it replaces.</p><p>This pricing model becomes particularly relevant in two scenarios: One is in areas where labor shortages exist and the availability of human resources is just plain limited. The other is a cost discussion for the customer. Organizations might find adopting AI solutions very appealing when the cost of these AI agents is significantly lower than hiring additional staff &#8211; potentially at a ratio of 4:1 or 3:1, meaning the AI is four times cheaper than the human alternative.</p><p>By tying the value of AI directly to labor cost savings, this model offers a pragmatic approach for organizations to evaluate and adopt AI solutions, making them a viable alternative.&nbsp;</p><h4><strong>Conclusion</strong></h4><p>For AI startups navigating this landscape, the chosen pricing model should reflect the value delivered by their product. It should be simple, easy to understand, and allow for straightforward forecasting. This approach is vital in the AI-driven software domain, where the value proposition can significantly vary based on the application and its impact on business processes.&nbsp;</p><p></p><p><em>Special thank you to Matt Peters, Peter Silberman, Surag Patel, Edward Wu and Scott Gudmundson for providing incredibly valuable input and helping me think through some of these concepts.</em>  </p><p></p>]]></content:encoded></item><item><title><![CDATA[Defensibility in GenAI: What AI Startups can learn from Github Copilot ]]></title><description><![CDATA[The recent product launches by OpenAI have triggered an immediate reaction among startups, prompting an essential question: In an era which is dominated by a fast moving incumbent, how can a startup establish a defensible position?]]></description><link>https://dannguyenhuu.substack.com/p/defensibility-in-genai-what-ai-startups</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/defensibility-in-genai-what-ai-startups</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Thu, 16 Nov 2023 17:28:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zBgU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zBgU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zBgU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 424w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 848w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 1272w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zBgU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png" width="1334" height="940" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:940,&quot;width&quot;:1334,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2763577,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zBgU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 424w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 848w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 1272w, https://substackcdn.com/image/fetch/$s_!zBgU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52534b1-a54a-4869-88eb-5be2fc43d5fc_1334x940.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Shopify showcasing its Copilot usage at Github Universe 2023</figcaption></figure></div><p>The recent<a href="https://openai.com/blog/new-models-and-developer-products-announced-at-devday"> product launches</a> by OpenAI have triggered an immediate reaction among startups, prompting an essential question: In an era which is dominated by a fast moving incumbent, how can a startup establish a defensible position?</p><p>This evokes memories from the mid-2010s when AWS reigned supreme in cloud computing, sparking rapid innovation. Their impactful re:Invent keynotes often led startup founders to reconsider their reasons for entering the industry in the first place. And yet, we still have massive infrastructure companies like Datadog, Elastic, and Databricks which were all started during that time. It seems plausible that it will be similar this time around.&nbsp;</p><p>Shortly after OpenAI's Dev Day, and merely a few blocks away, GitHub unveiled new features for Copilot at their Github Universe conference. With over 1 million paid users across 37,000 companies,&nbsp; GitHub Copilot serves as an interesting case study on how a<a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software"> Service-as-Software</a> product can build and sustain long term differentiation while using foundation LLMs from Open AI. While Copilot itself is of course part of a larger company in Microsoft, a lot of their tactics can be applied to both startups and scale ups trying to build AI products. In the following, I try to highlight a few of the strategies that I believe transfer well and can provide interesting guidance for founders currently building in the AI arena.&nbsp;</p><h4><strong>Community = 1st-Party Data, Evangelism and Adoption</strong></h4><p>The role of community engagement in shaping AI-driven companies has become increasingly crucial. The extensive data generated from open source or freemium users, combined with the rapid pace of feature requests and feedback, is pivotal for crafting an effective and dependable AI service.</p><p>In recent years, open-source companies have primarily monetized their user base through cloud-based managed services or enterprise features like Role-Based Access Control (RBAC), high availability, and enhanced security. This approach often involves charging for the convenience of minimizing infrastructure work required to deploy the service efficiently within an organization. For instance, Elastic operates Elastic Cloud, a managed service version of its open-source offering, and MongoDB has a similar approach with MongoDB Cloud, among others. This 'convenience layer' monetization strategy essentially frees initial community users from concerns irrelevant to them but necessary for enterprise requirements.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4ZVp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4ZVp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 424w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 848w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 1272w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4ZVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png" width="1456" height="820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:427568,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4ZVp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 424w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 848w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 1272w, https://substackcdn.com/image/fetch/$s_!4ZVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0593d8a-f675-44ac-8772-1f3c2f5aee9d_2684x1512.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Looking forward, companies with a strong community foundation are likely to leverage their extensive data to create new services using LLMs and agent technology. These services are both complex technologically and from a use-case perspective. GitHub's Copilot is a prime example: it leveraged repository data to train its initial version and has continually refined it, keeping its core users, the developers, in focus. Every user interaction of accepting or rejecting code suggestions provided it with an opportunity for gathering 1st-party data that not only continuously improved the product but also created a long term defensible mechanism. Crafting a tool that developers not only use but love is a significant achievement, given the complexity and utility of Copilot.&nbsp;</p><p>The strategic advantages of having a built-in community are clear, offering opportunities for data collection, implementing best practices, evangelism and product testing by users. For modern <a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software">Service-as-Software</a> companies fortunate to have such a community, the challenge and the opportunity lies in balancing complexity and convenience in a single cohesive product strategy, grounded in first principles. In short, if Github was started today, how would it jump directly to Copilot?</p><h4><strong>Fanatic Obsession on UI / UX + AI = User Happiness</strong></h4><p>GitHub Copilot's recent developments, highlighted at GitHub Universe last week, reveal a vital insight for AI startups aiming to build a lasting and successful business. The profound integration of UX and UI in their AI offerings, such as <a href="https://github.blog/2023-11-08-universe-2023-copilot-transforms-github-into-the-ai-powered-developer-platform/">GitHub Copilot Chat</a> and <a href="https://github.blog/2023-11-08-universe-2023-copilot-transforms-github-into-the-ai-powered-developer-platform/">Copilot Enterprise</a>, is a testament to balancing complex AI functionalities with user-centric design. For AI startups, this signifies the importance of not just leveraging advanced LLMs, but also embedding it in a way that is intuitive and aligns with user expectations and workflows.</p><p>GitHub Copilot Chat, powered by GPT-4, exemplifies their commitment to UX/UI by enabling natural language programming and offering code-aware guidance, inline chatting about specific code lines, and user-friendly slash commands for task shortcuts&#8203;&#8203;. This tool is not only highly accessible, being integrated into GitHub.com and its mobile app, but it also enhances the developer experience by providing suggestions, summaries, analysis, and answers for coding queries, directly within the platform&#8203;&#8203;.</p><p>The Copilot Enterprise edition tailors the Copilot experience to organizational needs, empowering teams with AI assistance at every step of the software development lifecycle. It offers personalized code suggestions and documentation help, quickly bringing teams up to speed on their specific codebases. This customization, combined with enterprise-grade security and privacy features, illustrates how GitHub Copilot has evolved from a simple autocomplete tool to a comprehensive, AI-powered development aid&#8203;&#8203;.</p><p>AI startups looking to emulate GitHub Copilot's success should prioritize creating AI tools that are technically sophisticated yet intuitive and deeply integrated into users&#8217; workflows. This focus on user-centric AI development, coupled with continuous innovation, forms the cornerstone of building a long-term viable business in the competitive AI industry.</p><h4><strong>Deep Integrations Into Multiple Core Systems</strong></h4><p>AI startups can gain significant insights from GitHub Copilot's recent preview release of "<a href="https://github.blog/2023-11-08-universe-2023-copilot-transforms-github-into-the-ai-powered-developer-platform/">Workspaces</a>". This move exemplifies the strategy of deeply integrating into various systems to create a unified, agile user experience. As described in my previous post on the "<a href="https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software?r=39lh5&amp;utm_campaign=post&amp;utm_medium=web">Many-to-Many Problem"</a>, the capability of AI agents and LLMs to navigate through a labyrinth of systems, aggregating and interacting across tools, can vastly improve operational efficiency and decision-making processes&#8203;&#8203;.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;11f2aecc-7b48-48b6-8b6d-3c2ad72f6cbe&quot;,&quot;duration&quot;:null}"></div><p>GitHub Copilot's foray into Workspaces highlights this potential, addressing the complexity of modern software development environments. By leveraging the knowledge of the entire codebase and the reasoning capabilities of GPT-4, GitHub Copilot Workspace assists developers in efficiently turning ideas into code. This not only streamlines the development process but also integrates various aspects of software development into a cohesive workflow.</p><p>Creating agent systems viable for long-term use depends on integrating systems, workflows, and data&#8203;&#8203;. GitHub Copilot Workspace embodies this approach, demonstrating how AI can be utilized to solve specific use cases while aligning with existing enterprise budgets and needs.</p><p>For AI startups looking to build a sustainable business model, GitHub Copilot's strategy of branching out and integrating into multiple systems provides a valuable blueprint. By focusing on deep integration and addressing specific user needs, startups can create products that not only solve immediate problems but also fit seamlessly into the broader workflow, thereby building a long-term sustainable competitive advantage in the service-as-software domain.</p><h4><strong>Conclusion</strong></h4><p>Forging a long-lasting and defensible position in the fast-evolving world of genAI necessitates startups playing to their unique strengths. This could involve:</p><ul><li><p>Cultivating and leveraging a robust community of engaged users </p></li><li><p>Focusing intensely on marrying user interface and experience with AI to meet users where they are</p></li><li><p>Developing deeply integrated AI agent systems that provide critical insights and actions across various core systems </p></li></ul><p>Ideally, a combination of these approaches would be most effective. Despite OpenAI's rapid pace of innovation posing a challenge to startups within its ecosystem, the strategies employed by GitHub Copilot, which have cemented it as a leader in the AI -powered software development tooling, offer valuable lessons. Needless to say that Copilot obviously benefited massively from being part of Microsoft, the tactics nonetheless provide an interesting blueprint for AI startups to establish their own strong presence in this new era.</p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[A New Frontier: Service-as-Software, powered by AI Agents]]></title><description><![CDATA[Agen(t)cy for everyone to build the next generation of IT & Cybersecurity Applications]]></description><link>https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software</link><guid isPermaLink="false">https://dannguyenhuu.substack.com/p/a-new-frontier-service-as-software</guid><dc:creator><![CDATA[Dan Nguyen-Huu]]></dc:creator><pubDate>Tue, 07 Nov 2023 15:30:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fAVq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fAVq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fAVq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fAVq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;AI Agents Decoded: Bridging the Gap Between Autonomy and Intelligence -  Problem Solutions&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI Agents Decoded: Bridging the Gap Between Autonomy and Intelligence -  Problem Solutions" title="AI Agents Decoded: Bridging the Gap Between Autonomy and Intelligence -  Problem Solutions" srcset="https://substackcdn.com/image/fetch/$s_!fAVq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!fAVq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feee40e40-f0eb-4040-8029-bfc2f854fb73_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>TLDR: </strong>With the continued rapid innovation around LLMs and AI Agents, software as we know is getting a major upgrade. From on-premise software to SaaS, we experienced a major productivity boost for knowledge workers and created a massive industry in the process. As we drive forward into the genAI era, we will see the next generation of software applications, that instead of being delivered to us as a service (SaaS), actually be a service themselves, delivered to us in the form of software. This will be the era of <strong>Service-as-Software</strong>. Undoubtedly, the latest <a href="https://twitter.com/OpenAI/status/1721596740024078340">product releases by OpenAI</a> yesterday, regarding agents / <a href="https://twitter.com/swyx/status/1721595107785503009?s=20">GPTs</a> in particular, are major step in making this a reality. </p><p></p><h4><strong>The Opportunity of AI Agents in the Software &amp; IT Services Market</strong></h4><p>It&#8217;s now almost 1 year A.C (After ChatGPT) and it's clear that it has sparked a new wave of excitement in the startup and tech world. This is especially emphasized in light of OpenAI&#8217;s product releases announced yesterday of becoming a basically a full fledged <a href="https://techcrunch.com/2023/11/06/app-store-for-ai-build-your-own-gpt-and-sell-it-on-openais-gpt-store/">UGC platform where users can create and share agents</a>, with everyone brainstorming what's now possible. Reflecting back on the software ecosystem, I've been particularly drawn to revisiting the original purpose behind creating SaaS platforms. Essentially, they were meant to boost our productivity as knowledge workers, and delivering this software through the cloud simply made everything more convenient and effective, which is how SaaS took off. </p><p>Software spend globally, whether it&#8217;s hosted in the cloud or on-site, has been on a rapid rise, reaching the massive market size of about ~$900 billion. But, alongside this hefty investment in software, is an even bigger bill for IT services.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rEtz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rEtz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 424w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 848w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 1272w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rEtz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png" width="682" height="410.2796833773087" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:758,&quot;resizeWidth&quot;:682,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rEtz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 424w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 848w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 1272w, https://substackcdn.com/image/fetch/$s_!rEtz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db2352e-a5e0-4836-a779-74d378ceb147_758x456.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Source: Gartner</em> </p><p>As a matter of fact, for every dollar we spend on software, we end up spending 1.5x times more on IT services to get that software operational and successfully deployed. This includes areas like BPO, outsourcing and consulting, which take up most of that extra cost. You could argue that that number is potentially even understated since a lot of companies use FTEs to do the manual work around tuning, maintaining, integration&nbsp; and operational work. Bain &amp; Company suggests that around <a href="https://www.bain.com/insights/how-generative-ai-will-supercharge-productivity-snap-chart/">37%</a> of IT tasks could be automated using genAI.</p><p>When you think about the vast $1.4 trillion annual spend on IT services, it's easy to see the huge chance for new companies to step in. There&#8217;s a big market out there, maybe even larger than the software market itself, ready for businesses that can use AI to shake things up.</p><h4><strong>The Era of Service-as-Software&nbsp;</strong></h4><p>Automating human labor and turning it into a successful software business is certainly not a new concept in Infra IT. Robotic Process Automation giant <a href="https://www.uipath.com/">UI Path</a> has led the charge in automating every manual task from data entry, invoice processing to supply chain logistics. In cybersecurity, <a href="https://expel.com/">Expel</a> has built a fully transparent Managed Detection and Response (MDR) service that is powered by automation software to help its customers defend against cyber attacks.&nbsp;&nbsp;&nbsp;</p><p>With the rapid innovation around <a href="https://www.latent.space/p/agents">AI Agents</a>, software applications as we know them are in process of getting a major upgrade. Agents are programs that can make decisions or perform actions based on its environment, user feedback or experiences. In short, they mimic the subtle human behavioral characteristics that make us humans quite effective at taking actions or fulfilling tasks. What this means in practice is that instead of software simply being delivered to us as a service, agents and LLMs will power the service to be delivered to us in the form of software. Thereby this ushers in the Era of <em><strong>Service-as-Software</strong></em>.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sycE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sycE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 424w, https://substackcdn.com/image/fetch/$s_!sycE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 848w, https://substackcdn.com/image/fetch/$s_!sycE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 1272w, https://substackcdn.com/image/fetch/$s_!sycE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sycE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png" width="1456" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sycE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 424w, https://substackcdn.com/image/fetch/$s_!sycE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 848w, https://substackcdn.com/image/fetch/$s_!sycE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 1272w, https://substackcdn.com/image/fetch/$s_!sycE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbca4014c-bcab-4f11-babb-51bd880ff113_1600x672.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At the end of the day this really plays into the most exciting and scariest opportunity of AI and that is the ability of humans to process, reason and build knowledge while using all three effectively to conduct a task autonomously. Over the course of the last year, we have been investing in various companies in the infrastructure IT &amp; cybersecurity space that play on this trend, but all have very similar characteristics that I wanted to summarize here.&nbsp;</p><h4><strong>Labor Shortage Creates Urgency</strong></h4><p>In certain critical sectors, AI's intent isn't to supplant humans, particularly where there's a stark labor deficit preventing roles from being filled. Cybersecurity is a prime example, with a staggering <a href="https://cybersecurityventures.com/jobs-report-2021/#:~:text=%E2%80%9CThere%20are%203.5%20million%20unfilled,world%20that%20we%20live%20in.%E2%80%9D">3.5 million</a> positions lying vacant. The urgency intensifies as we witness a surge in hackers leveraging LLMs, escalating the frequency and sophistication of cyber-attacks. The barrage of alerts from security tools monitoring firewalls, endpoints, cloud assets, and emails can overwhelm even the most sophisticated security dashboards, akin to an unending cascade of Christmas lights. In the trenches are the beleaguered analysts in Security Operations Centers (SOCs), who grapple with the sheer volume of alerts, leaving them stretched thin and increasing the risk of critical breaches slipping through the net.</p><p><a href="http://dropzone.ai">DropzoneAI,</a> which is pioneering the development of a SOC Tier 1 Analyst powered by LLMs is designing an agent based system to autonomously sift through alerts and field ad-hoc queries, tapping into a host of tools and data repositories to investigate a security alert. <a href="https://app.storylane.io/share/rlowqglro3r1">Here</a> you can see it conducting a full investigation of an AWS Guard Duty alert that gets fired to Splunk as somebody is trying to potentially conduct a data exfiltration out of S3.&nbsp;</p><p>In realms plagued by skill gaps and labor shortages, LLMs emerge not as replacements but as vital enhancements to human capabilities&#8212;acting as force multipliers where the need is most acute. Such strategic augmentation underscores AI&#8217;s role as a crucial ally in functions where shortages of labor are apparent.&nbsp;</p><h4><strong>The Many-to-Many Problem</strong></h4><p>The human capability to navigate through a labyrinth of systems to extract answers is nothing short of remarkable. Consider a developer engaged in the debugging process: the journey often involves traversing from an Integrated Development Environment (IDE) to an Application Performance Management (APM) platform, and then to a log management system to pinpoint the root of an issue. This scenario, where insights are nested within a multitude of platforms&#8212;be it in data engineering, DevOps, or cybersecurity&#8212;signals a prime niche for AI agents and LLMs. They thrive where tools sprawl and interoperability falters, stepping in when a human intermediary is traditionally tasked with piecing together a coherent narrative from disparate data sources. In DevOps, the aspiration to integrate logs, metrics, and events across various platforms has long been a topic of discussion. Data engineering wrestles with the fragmentation of information across silos, standardizing the data, checking its quality and feeding it into diverse analytical tools. Meanwhile, security analysts leapfrog over an extensive array of instruments&#8212;from Endpoint Detection and Response (EDR) systems to firewalls and logs&#8212;to thoroughly investigate alerts. The question then arises: might a Service-as-Software company adeptly shoulder the more monotonous tasks of aggregation and cross-tool interaction, thus sparing us to focus solely on critical decision-making? Such a solution could significantly transform the efficiency and efficacy of operations across these complex roles.</p><h4><strong>Large Scale Analysis but with a Personalized Touch</strong></h4><p>LLMs and AI agents are particularly adept at conducting deep-level analyses on a grand scale, thanks to their capacity to parse and make sense of data from a multitude of sources, all while maintaining the ability to offer a personalized touch. In the field of IT support, for instance, these AI systems can draw from a variety of databases, incident logs, user manuals, and forums to diagnose issues and provide solutions. An AI agent can analyze thousands of tickets from an IT support system, identify common problems, and suggest improvements or automated responses for future incidents. This capability not only streamlines the troubleshooting process but also allows for customized assistance; the AI can learn from each interaction with a user, recognizing patterns in the types of issues a particular user faces or the level of technical language they understand. It can then tailor its communication to match the user's expertise, whether it's a network engineer needing deep technical details to resolve a complex server issue or an end-user requiring step-by-step guidance to reset a password. This individualized approach is the result of sophisticated algorithms that adapt and optimize their output, ensuring that as users engage with the AI, the guidance they receive becomes increasingly focused on their specific needs and preferences, even in the context of a broad and complex IT landscape.&nbsp;</p><h4><strong>What&#8217;s next?</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IVAx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IVAx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 424w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 848w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 1272w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IVAx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png" width="1456" height="463" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:463,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:179625,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IVAx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 424w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 848w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 1272w, https://substackcdn.com/image/fetch/$s_!IVAx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f31925a-ac97-4497-853a-77dcdcb8fe0a_2002x636.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the IT infrastructure and security sectors, there's a groundswell of opportunity to innovate with autonomous agents, propelling us toward a more seamless Service-as-Software (SaS) future. Crafting an agent system that is viable for the long haul and ready for production hinges on a deep integration of systems, workflows and data. Thereby I believe for these agents to truly be disruptive and enduring&#8212;ready to be deployed at scale&#8212;they must be built with a vertical-first and maybe almost role based first strategy (and potentially scale horizontally from there). This approach isn't just about achieving early wins; it&#8217;s about solving specific use cases while also aligning with already existing budget line items in the enterprise.</p><p>When considering which ideas to pursue first, the guiding star should be the urgency of labor need&#8212;roles that are hard to recruit for would allow agents to be adopted at a higher rate and provide a faster journey towards product-market fit. I couldn't be more excited about what this new paradigm shift will bring, so if you are thinking of building a company in this space, please reach out to me!&nbsp;</p>]]></content:encoded></item></channel></rss>