XBOW Founder: “Your Infrastructure is Not Safe” | EP 28

27 Aug 2026 · 1 h 11 min · 28 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The episode argues that open-weight AI models make cyberattacks easier and more continuous, leaving “your infrastructure is not safe” and the West unprepared; it also covers AI sovereignty via open models, NVIDIA/Perplexity funding, chip-speed races, and ethics/liability around AI-generated content and autonomous agents.

Guests

  • Runben Dong, founder/CEO of Scale Social AI. Background: builds an AI platform that converts real customer moments into authentic short-form ads for restaurants/franchises; focuses on enterprise “media efficiency” ROI.
  • Oje Demor, founder/CEO of Expo. Background: AI-powered autonomous penetration testing company that runs simulated hacking to find security holes before attackers.

Key claims

  • Open-weight models enable serious hacking; autonomous AI can outperform many humans at hacking; most orgs test security only quarterly/monthly, which is insufficient.
  • Open “sovereign” models (U.S.-based) matter for on-prem deployment and data control.
  • Enterprise customers pay for agentic tools because they drive ongoing ROI, unlike commoditized search.
  • Speed (tokens/sec) is critical for agents and rapid iteration.
  • AI-written public commentary without disclosure is “lip syncing” and undermines trust.

Notable examples

  • AI optimizing home routers via browser prompts; XBO ranking on HackerOne after releasing an AI pentesting agent.
  • NVIDIA investing $1B in Poolside, licensing tech for $6B, and hiring 100+ staff to Nemotron.
  • Bloomberg: state-affiliated Chinese attacks boosted ~50% productivity using DeepSeek/open models.
  • Drunkenmiller WSJ op-ed reportedly AI-assisted without first-sentence disclosure; Alabama AG subpoena tied to Hugging Face breach testing harness escape.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Cyber Threat Landscape

0:00 to 0:51

Learn about the current state of cyber threats and AI's role in hacking.

“It's already been the case for at least a year.”

Introduction to the Episode and Guests

1:02 to 1:44

Meet the guests and learn about their backgrounds in AI.

“You know, this week in startups, we talk about startups.”

NVIDIA and Poolside Collaboration

1:44 to 2:20

Discuss NVIDIA's investment in Poolside and its implications for AI.

“He's the founder and CEO of Scale Social AI.”

The Importance of Open Weight Models

2:20 to 5:40

Examine the necessity of U.S. alternatives to Chinese AI models.

“So NVIDIA and Poolside are joining the open weight race together.”

Current Cyber Attack Trends

5:40 to 8:10

Understand the productivity of cyber attackers using AI tools.

“We have to be able to train our own models and our enterprise clients are very much looking for that sovereignty as well.”

Challenges in Cybersecurity Preparedness

8:10 to 12:20

Explore why organizations are unprepared for AI-driven cyber threats.

“From a cybersecurity standpoint, is that enough of a gap?”

Potential Solutions for Cybersecurity

12:20 to 13:15

Discuss how AI can help optimize network security.

“So this, I think, is the one thing that gives me a little bit of hope is that you're going to have agents constantly, you know, doing the white hacking part of this.”

Perplexity's Growth and Funding Talks

13:15 to 14:00

Analyze Perplexity's rising valuation and its strategic position.

“Speaking of NVIDIA, as we always are, the information reports that they're in talks to invest fresh funds in perplexity at a$30 billion plus valuation.”

Valuation Dynamics in AI Companies

14:00 to 17:33

Explore the valuation trends of AI companies and their reliance on profitability.

“And the answer is typically growth and or profitability.”

Enterprise vs Consumer AI Adoption

17:33 to 20:16

Discuss the differences in AI usage between enterprise customers and consumers.

“Like, how are you thinking about, you know, consumer versus enterprise?”
Show all 28 chapters

Challenges in AI Security

20:16 to 24:40

Understand the growing need for security in AI due to increased application development.

“necessary to keep that business unit growing.”

The Future of AI Infrastructure

24:40 to 28:00

Investigate the trends in AI computing and the push for more efficient chips.

“They're being asked to deliver more and more performance with the same exact constraints.”

The Importance of AI Infrastructure

28:00 to 29:13

Discussing the motivations behind OpenAI creating their own chips and the implications for AI innovation.

“You would wonder why would open AI even feel the need to make their own chips?”

The Need for Speed in AI Applications

29:13 to 31:21

Exploring the critical role of speed in AI applications and the impact on user experience.

“Give us a sense of, are you watching the chip race very closely?”

Orchestrating AI Tasks for Efficiency

31:21 to 34:28

Examining how to effectively manage multiple AI tools to maximize productivity and efficiency.

“We just talked about the speed by which people are creating new software.”

The Ethics of AI in Editorials

34:28 to 37:11

Debating the ethical implications of using AI to generate op-eds and the importance of authenticity in writing.

“We got to talk about this AI slop editorial in the Wall Street Journal.”

Trust and Authenticity in AI-Generated Content

37:11 to 39:49

Discussing how the use of AI affects trust in information and the responsibilities of content creators.

“It's like plagiarism or lip syncing or kind of both.”

The Responsibility of Public Figures with AI

39:49 to 42:00

Contemplating the responsibilities public figures have when using AI to produce content and how it affects their credibility.

“So at the end of the day, what do we deem to be trustworthy?”

Debate on AI and Authorship

42:00 to 43:26

The hosts discuss the implications of AI-generated content and the ethics of transparency in authorship.

“Did you see Chamatha responded to your tweet?”

Journalism Standards and AI

43:26 to 45:23

The conversation shifts to the responsibilities of media organizations regarding AI-generated content and their ethical obligations.

“There was a podcast clip of Naval from Angelist a few weeks ago where he made the point, if AI wrote it, I'm just going to have an AI read it.”

Legal Implications of AI Breaches

45:23 to 49:02

The hosts explore the legal ramifications of AI breaches, including the investigation into OpenAI by Alabama's attorney general.

“Alabama's Attorney General Steve Marshall sent a subpoena to OpenAI as part of an investigation into the Hugging Face breach.”

The Challenge of AI Liability

49:02 to 52:41

Discussion on the complexities of liability in AI technology and the need for new laws to address potential misuse.

“I'm trying to figure out what the legal case here is.”

The Mystery of Ox Alpha Model

52:41 to 56:00

The hosts analyze the new Ox Alpha model and its implications for the AI landscape, highlighting its features and potential risks.

“It's the mystery model that debuted last week as a stealth model on Open Router.”

Risks of Using AI Models

56:00 to 58:41

Discussing the potential dangers and data privacy risks associated with new AI models.

“because there's now so many new models coming out that is difficult to stand out from the crowd.”

Apple's Hardware and AI Future

58:41 to 1:02:48

Exploring the implications of Apple's new hardware for running local AI models.

“I would be tempted to experiment with it.”

The Shift to Local AI Processing

1:02:48 to 1:06:34

Examining how local AI processing might change the landscape of computing.

“Why shouldn't we spend$20 ,000 per computer for five years, divided by five years, 48 months, 50 months?”

Personal AI Tools and Innovations

1:06:34 to 1:10:00

Sharing insights on personal AI tools and their practical applications.

“Get ready to start racking and stacking, racking and stacking.”

Discussion on Podcast Tools

1:10:00 to 1:10:24

Learn about innovative tools for enhancing podcast experiences.

“The opinion here on This Week in AI, All In, whatever other podcast, CNN, whatever comes up, CNBC.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Runbin Dong:Your infrastructure is not safe. It's already been the case for at least a year. It's possible to do very serious cyber attacks with open-weight models.

0:08Oege de Moor:When mythos-level tools are in the hands of millions of bad actors globally, like scale of one to ten, how prepared is the West?

0:15Runbin Dong:We're not prepared at all. We've already been for a year in the situation that an AI working completely autonomously is better at hacking than most human beings.

0:24Oege de Moor:People started logging into their router in their browser. Then they low-clawed on the side, in the sidebar, and they just tell it to, hey, go optimize my router.

0:34Runbin Dong:I think that you're right. There's ample reason to be optimistic for the medium-term or long-term future. But it's the short term that we should be worried about. Because the world is not ready today, we are going to enter a phase of enormous chaos.

0:51Oege de Moor:Thanks to our friends at PayPal, the exclusive sponsor of This Week in AI. Pay zero processing fees on your first 100 ,000 ineligible PayPal payment volume. Find out more at paypal.launch.co. All right, everybody, welcome back. You know, this week in startups, we talk about startups. Hey, you know, Leo Laporte, he started it all this week in tech. Go check him out every Sunday, I think about three o 'clock Pacific time. And then there's the new this weekend, this week in AI. There's so much AI news that we are so lucky to have the people actually building the future come together every week. We drop it on Wednesday-ish.

1:27Oege de Moor:The amount of news, Lon, has become absurd. Untenable. This summer, more occurred this summer, June, July, and August, than has occurred in the last three years of the technology industry. It is a velocity that is just otherworldly. So let's introduce our guests and get right to work. We're joined this week by Runbin Dong. He's the founder and CEO of Scale Social AI. They're an AI platform that turns real customer moments into authentic short-form ads for restaurants and franchises. We've also got Oje Demor. He's the founder and CEO of Expo. They are an AI-powered autonomous penetration testing company, simulated hacking, this is a way to think about it, that helps clients find the holes in their security before attackers can.

2:11Oege de Moor:So thanks for being here, guys. Two different sides of the spectrum, but all driven by AI, right? We try to diversify. I try to mix it up here. All right. Well, let's get to the first story. Absolutely. So NVIDIA and Poolside are joining the open weight race together. The Wall Street Journal reports that NVIDIA and Poolside will collaborate on training, and I quote, one of the world's most powerful open weight AI models in an attempt to develop a U.S. alternative to DeepSeek, Moonshots, Kimi K3, all of those powerful Chinese models. NVIDIA is going to invest$1 billion in Poolside at a pre-money valuation of$12 billion.

2:44Oege de Moor:They're also going to pay$6 billion to license Poolside's technology and sort of acquihire or at least take for a short, a temporary period the bulk of the company's engineers. More than 100 Poolside staffers are joining NVIDIA's Nemotron team. Poolside founders say this move secures a future where AI, quote, will not be a closed technology controlled by a few, but one built by many out in the open. We should note their options were a little limited. They were unable to fund the infrastructure that they needed to keep training their models. And Poolside was reportedly in danger of running out of compute by next year if they remained on their own.

3:22Oege de Moor:So I think open weight models are accessible, available to everyone. I guess the main question would be, why is it so important that we have a U.S.-specific alternative to the deep seeks in the K3s of the world? Well, I'll just jump in and just say NVIDIA is running the table on these acquisitions. This is the second time they've done the Aqua hire thing. And what's really unique about that format is all the workers can start working on Monday. You don't have to wait for the Justice Department this to get clear, that to get cleared. You're like, here's money. Put it into that corporation. Everybody, you know, hands in their laptops and shows up in the NVIDIA office.

4:00Oege de Moor:And he likes people in office. Nemotron is a really good model, right? We've been talking about that for a while. That's their open source model. But building frontier models, building open source models, that requires a lot of hardware. And this seems like what I would call an opportunistic acquisition. It's an acquisition. So however the structure is done technically. We're talking around it a little, yeah. Yeah, I mean, it is what it is. This is like a structure that gets things done quickly. What I think it is is opportunistic in two ways. One, this was available. to corporations in the last 90 days with this whole AI sovereignty movement have said, I need an option that's not anthropic.

4:41Oege de Moor:I need an option that's not open AI because I just don't want my data to leak there. I don't want to see if my company's in legal or accounting. I don't want to one day see Claude accounting or Claude CPA or Claude legal. It's just terrifying to think you're educating that platform. And then you look at what Jensen could offer. Jensen could offer a rack to you that it could roll out to wherever you are with all the chips and Nemotron and Pulsad and whatever else is on it and plug it in and you're done. He's got the – he'll have an incredible open source model. He'll have all the hardware. You provide the energy and the closet space wherever your office is.

5:28Oege de Moor:And I think this on-prem movement, on-prem or AI sovereignty is the real deal. As I said two years ago, I think there's a chance open source wins it all. I was like 30 % now. I'm like 70 % open source wins it.

5:45Runbin Dong:Definitely bullish on that. We're a much earlier stage startup, but we're already hitting this dilemma whereby being video first across all of the multimodal frameworks out there, we've already picked a US-based winner, but we don't really see the future being closed. We have to be able to train our own models and our enterprise clients are very much looking for that sovereignty as well. And then on top of that, I'm actually heading to China in November. What's really interesting is the Chinese governments reached out, and this is the arms race that isn't really talked about much, but the amount of incentives that they are willing to load, compute and otherwise, to attract companies to base their companies and headquarters in China is ridiculous.

6:37Runbin Dong:Right. And so I think the US have to shore up the ammunitions necessary to continue to fund that innovation. I think it's a wonderful initiative by NVIDIA. we see the Chinese open-waste models getting better and better at cybersecurity tasks. In my estimation, they're a couple of months, two or three months behind the closed-source models. It's important for many, like for Rubin's enterprise customers, for our enterprise customers, they naturally want everything to run on-prem. is not so much that they're worried about others training on their data. It's just that their data is so valuable, their algorithms, their software, that they don't want to let it out of their network in any way, just being fearful of possible security incidents on infrastructure that they don't control.

7:38Two to three months is a short window behind.

7:42Oege de Moor:that you're the first person who I've heard put it at that number. Usually I hear 6 to 12, but you actually think it's tightened up and they're right behind Frontier Models, yeah?

7:51Runbin Dong:Yeah, so we see that in our benchmarking. We continuously benchmark the very latest proprietary models as well as open source. Where we now see the latest open source models perform is roughly where the proprietary models were two to three months ago.

8:09Oege de Moor:That's incredible. From a cybersecurity standpoint, is that enough of a gap? Are our systems safe if open source models are only a few months behind the peak frontier models?

8:22Runbin Dong:Your infrastructure is not safe. It's already been the case for at least a year that it's possible to do very serious cyber attacks with open-weight models. and even when you look at the very best models, if you compare the cost against the capability, the hacking capabilities, we've already been in a situation where absolutely if you spend an unlimited amount of money, a model like Mythos is the best. But then if you start looking at, I only want to spend$1 ,000. What are the chances that I find in exploit? You're much better off spending that$1 ,000 with an open-waste model like in the DLM family, which is roughly at the same efficiency, cost versus exploit finding capabilities, as a model like GBT55.

9:18Oege de Moor:Interesting. Actually, Jason, we have another item in the news that links right up with this. According to Bloomberg, a recent wave of cyber attacks from state-affiliated Chinese groups were made possible by DeepSeek and other advanced open source models. The hackers' productivity is reportedly up around 50 % since they started using the latest AI tools. And here's what I thought was interesting. It's helping them to develop malware, but it's also doing exactly what AI does for everybody. It allows them to delegate all of the busy work tasks of hacking so that they can focus on the harder problems themselves.

9:52Oege de Moor:So, I mean, you know, I think we're right now in this very scary moment. I mean, when mythos-level tools are in the hands of millions of bad actors globally, scale of 1 to 10, how prepared is the West? And what can we do in a short-term time zone to get more prepared?

10:10Runbin Dong:We're not prepared at all. And in fact, already last year, we let our AI expo loose on the HackerOne platform. HackerOne is this platform. It's a broker between companies that want to be tested and ethical hackers who will get paid for the stuff they find. Within a few months, XBO became number one in the United States. And then exactly a year ago, it became number one in the world. And so we've already been for a year in the situation that an AI working completely autonomously is better at hacking than most human beings. And so we are not prepared for this in the least. Most companies are still running security tests of their systems once a quarter.

11:06Runbin Dong:Some very fast-moving companies do it once a month. And clearly that is not enough because if you can have these continuous autonomous attacks, the attackers will do that. And they can attack all the systems all the time.

11:23Oege de Moor:One thing I think that's at least a little bit promising is that people are now logging into their routers. Like let's say you have a home router and I saw DHH doing this. People started logging into their router in their browser. Then they low-clawed on the side and the sidebar, and they just tell it to, hey, go optimize my router. And I did this myself, and I found all these problems. Hey, you didn't upgrade this. Hey, this might be why you're having some issues with your internet, the syncing. And AI will be built into, I believe, a lot of these routers, a lot of this infrastructure, and then just be constantly running jobs.

12:03Oege de Moor:So here's Shane Powers saying he did it as well. who just asked Claude to optimize his ubiquity Wi-Fi setup at home. 54 % increase in Wi-Fi speeds on my phone, 25 % increase on wired. I got a new unified network. Can you optimize it? Make a list of all proposed changes and get my approval first. The Claude, 25 minutes. So this, I think, is the one thing that gives me a little bit of hope is that you're going to have agents constantly, you know, doing the white hacking part of this. And that could solve a lot of problems, not just make your Wi-Fi faster, which is nice. But also like, hey, where am I vulnerable?

12:37Oege de Moor:And I mean, you could probably do it with GrokBot and just say, GrokBot, try to hack my company and just let it run.

12:44Runbin Dong:Absolutely. I think you're right. There's ample reason to be optimistic for the medium term or long term future. But it's the short term that we should be worried about. Because the world is not ready today, we are going to enter a phase of enormous chaos. where some people have not optimized their networks and they actually will be found out by the bad actors.

13:13Oege de Moor:Let's move on to our next story. We got to talk about this perplexity deal, Jason. Speaking of NVIDIA, as we always are, the information reports that they're in talks to invest fresh funds in perplexity at a$30 billion plus valuation. Perplexity's annualized revenue is now over$750 million. That's up from$250 million at the start of this year. That's, of course, being driven mostly by Perplexity Computer, a product I know you're a big fan of. It's yet another one of these circular AI deals. Perplexity already, of course, a major customer for NVIDIA's Inference Compute. So another case of NVIDIA funding its own best customers, Jason.

13:50Oege de Moor:Do you think this kind of strategic capital offer from a partner that you're already dependent on commercially, does that make sense for a company? Each one of these is different. You have to look at each product and look at the velocity of their actual revenue. When you see a valuation disconnect from reality, you have to pause for a second and say, well, why would this company be worth 40 times top-line revenue when publicly traded companies might be worth two or three or four times top-line revenue? And the answer is typically growth and or profitability. So let's put profitability aside. the Perplexity computer product is their big hit.

14:31Oege de Moor:Just like Claude Cowork, Claude Tag, and GrokBot, this new entrant, agents are addictive and people are willing to pay for them. The original product was search, right? Perplexity was gonna be a better Google search. It was gonna be like Mahalo search that we worked on 20 years ago. It was gonna be more comprehensive and better looking, but you know what? Google built that, they added it. So Perplexity was faced with their search efforts being nice, got them a couple of million users, I believe. And then all of a sudden, Perplexity Computer just does what you tell it to do and works really well.

15:06Oege de Moor:And most importantly, people are willing to pay for it. Enterprise customers are willing to pay for it. So that's what we're seeing here. That's what we just saw at SpaceX AI. Their GrokBot is now their focus. Cursor for developers, bot for everybody else. You know, Claude Code for developers, Claude Cowork and Tag for everybody else. We now have a definitive product. People in enterprises can go to their boss and say, I need another$200 a month. I want to go from$200 a month to$600 a month. I want to go to$1 ,000 a month. And bosses are looking at it going, show me what you did. Okay. So that's a great sign for NVIDIA, Perplexity, and the entire ecosystem.

15:50Oege de Moor:Search is not going to make money. You know, just enhanced search, Q &A, what we would call chat GPT. Like, you know, what a commoner would think of as chat GPT. Hey, where should I go on vacation? Where can I get a great chocolate croissant? That kind of stuff people are not willing to pay for. It has been commoditized. It will be free. Open source models do it as well as frontier models. But doing tasks for a company, an enterprise, people, I think, are willing to pay four figures a month. and they will get used to perhaps even five figures a month per employee. Now let that sink in. Instead of just spending, like people have no problem spending$200 per employee per month,$2 ,400 a year.

16:33That is like, okay, sure.

16:35Oege de Moor:If you told me anybody in the company wants to spend$2 ,400, I'm like, great. You signed right off on my GrokBot, no problem. Now we get to$1 ,000, I would be like, okay, prove to me this is worth it. $2 ,000, prove to me it's worth it because, hey, this is now becoming 10%, 20 % of an average employee's, salary. I think the$2 ,000 a month spend is going to quickly become the standard. Corporations, let this sink in, are going to spend$1 ,000 a month,$2 ,000 a month per employee for AI tools. That's a big number, a very big number. And that means NVIDIA is doing the right thing by doing the circular revenue here, because perplexity has got to hit product, perplexity computer.

17:16Oege de Moor:Sure. Yeah. Runben, you are making a product that could it could have been a consumer product, like take your videos, make them into, you know, AI appealing sort of clips. Was this on your mind when you decided, you know what, I'm going to make this for enterprise customers? We're going to focus on brands and restaurants and franchises. Like, how are you thinking about, you know, consumer versus enterprise?

17:37Runbin Dong:In the earliest days, we actually thought about the cold start problem and the amount of money we had to raise to actually go after consumers. is just going to be ridiculous. And what we really wanted to prove is folks, everyday people are able to create good content. That was our initial thesis. So last year when we joined This Week in Startups, the enterprise customers started calling. And we realized that the magnitude of this problem is at a much, much bigger scale for our enterprise customers, to Jason's point, that they're willing to pay way, way more. And we just wrapped up our first case study with our first anchor enterprise customer there, whereby the media efficiency, so basically the content created from customers run as ads, and they benchmark this against all of their historical content.

18:27Runbin Dong:We came out on top on every single category. And the media efficiencies realized from that pays for the platform itself. And so the case is super clear here.

18:39Oege de Moor:Yeah, this is the interesting thing. when you give AI to a consumer, they play with it. Right. But they don't finish the job. They just play with it. They're like, okay, that's interesting. But they don't actually have a goal. Like, what is the goal of the average, like, chat GPT user? It's like, okay, I just want that chocolate croissant. Tell me, give me the best, you know, hotel. Answer my math question. Why do I have heartburn? Yeah, it's that, it's still searched by another name, I think, for most. It's one and done. Yeah. One and done. Whereas when you're an enterprise customer, you're not one and done.

19:12Oege de Moor:You are now recursive loops, learning, and then every day get better. And next week, do a better job than you did last week, which means spend more tokens, increase the spend. And that's always the key between the CFO, the CIO, and the CEO in these large corporations. You got a CFO saying, wait a second, there's an operational line item here, like Uber experience. That's very large. And then the CIO comes in. Yeah, we're much more productive. And then the CEO has to go between the two of them and say, ladies, fellas, what's the truth here? Show me the ROI. And now I would say almost every developer or every executive knows how to explain the ROI.

Read the full transcript

19:57Oege de Moor:I was going to ask you for a new headcount to manage this project. We don't need the new headcount. I'm rescinding the request for headcount. That's what's happening in corporate America. The job listings are being rescinded. People are saying, I don't need to add a person. This is going to get done by AI. It doesn't mean somebody is getting fired, but it does mean the incremental hire is not necessary to keep that business unit growing. Yeah, I wonder how much of it has to do with when individuals are using AI, the idea of I'm going to share my calendar. I'm going to share my text messages. I'm going to show this thing my emails.

20:33Oege de Moor:It feels creepy. I don't want it reading my text messages. on my phone. But when you're at a business, when you're working, you obviously throw it, your Slack, your Notion, your emails. And that's what really makes it work. That context is what makes it make sense and actually functional. So I feel like that might be the disconnect. Consumers aren't feeding it enough data to make it helpful. What do you think, Ohay, about that? Are you seeing that as well, that regular everyday people aren't maybe giving the models enough context, whereas enterprise-grade customers sort of get it on that level?

21:06Runbin Dong:Absolutely. And this is the reason that our product is doing well with enterprises, because we're doing work that is extremely expensive. Very skilled people would normally do this type of work. And there's not enough of them in the world. So it's not like headcount is being rescinded. Finally, people are able to do all the security testing that previously was unthinkable.

21:33Oege de Moor:See, that's really interesting. Security has always had a lack of resourced people. It's not like sales where there's like an infinite number of salespeople and an infinite number of salespeople you can put into a sales training program or writers or marketers. When you start talking about something like a chief security officer or SISOs, like limited number of people are interested in that job and even more limited number of people are qualified for that job. And a limited number of people want that type of intensity in their life. being in the security space you got to be a bit of a lunatic who's like i want to put out fires it's a little like being a firefighter or something like you get no credit then a building goes on fire and now oh it's showtime you got to run into the burning building and it's your responsibility now the fire is your responsibility right that's the intensity these people have to live with and there's no weekends there's no overnight if you're in the security space You're ready for your phone to ring at 1 a.m., yes?

22:32Runbin Dong:Absolutely. And we just talked about the fact that there are so much more need for security testing because of AI. At the same time, lots and lots of people who were not software experts are now creating software. They're creating new applications, but none of them have any security knowledge. And so the security experts are needed more than ever before.

22:56Oege de Moor:So now the surface area is increasing 10x. The number of people working in security is static, same number. And they've got 10 times as much to do. So there's no choice. They have to use AI to do this. And in organizations, there's a moment in time, six months in, Rinben, I don't know if you got to it, but I got to it in the last 60 days where I just said to everybody, okay, this person's in charge of vibe coding AI, whatever you want to do that's not an agent in your Slack room, anything that's software, Lucas has to approve, be in charge of, have the code base, and he has to do the testing on it.

23:34Oege de Moor:And we got to make sure it's secure because to your point, Lon, you give it access to stuff. I don't want somebody emailing, you know, a random email address, asking you for a query and then finding a hole in the system, or we invite somebody to Slack and they start talking to an agent in our Slack and it has payroll, investments, whatever documents. So we're even taking it a step further. We have now decided we're going to put a certain project on local hardware, buying local hardware, using open source. This is for a 20-person venture firm because I just cannot think of letting a frontier model have access to this.

24:10Oege de Moor:And if that server goes down and we don't get access to it, I'd rather have our server go down and lose access to it and have to rebuild it or whatever we're going to have to do or have redundant data centers. I'd rather incur that$50 ,000 in expense a year than have a frontier model have access to all of our investments and our investment decisions.

24:27Runbin Dong:Yeah, we definitely see that. Our entire firm runs off of lovable and cloud code today. And there's a centralized command for who is keeping custodian of the code base, right? And to Uhay's point, our analogy in the marketing world is our marketers are not growing their headcount. They're being asked to deliver more and more performance with the same exact constraints. that they've had. And so, yeah, AI plays a huge role there. But the nuance is how do you still maintain the storytelling component without AI slopping everything? And that's the battle we're fighting against.

25:03Oege de Moor:Great, Lon. You want to move along to another story? I think so. Yeah, keep going. Let's talk about the chip race. NVIDIA will deploy Grok 3 LPX chips alongside Vera CPUs and Ruben GPUs at the Nebius later this year. NVIDIA claims they've hit 3 ,400 tokens per second on artificial analysis. That cuts down on lag, which could be a particular issue for coding agents. And cloud companies can theoretically charge more for these tokens. Comparatively, OpenAI's ultra-fast mode, powered by Cerebris, promises 750 tokens per second. Of course, NVIDIA bought assets from Grok for$20 billion back in December, another one of those semi-aqua-hire deals.

25:45Oege de Moor:But meanwhile, Jason, we had another speedy chip story in the news just today. OpenAI is touting the speed and efficiency of their new jalapeno chips. Delicious. In a blog post published just today, Tuesday, OpenAI Hardware VP Richard Ho says that while most AI systems have to make a tradeoff between lower latency and higher throughput, jalapeno offers the best of both worlds. They plan to deploy it in small volumes later this year and then ramp up in 2027. So, I mean, what does this mean for these independent chip startups like Cerebris and Positron? Is it just are we ticking off the days until they're also scooped up by a frontier lab or a hyperscaler?

26:27Oege de Moor:There is an expression that necessity is the mother of invention. And we are going to see data centers get blocked. We're going to see people run out of energy. We're going to see limits on physics where Elon's going to have to start putting data centers in space. People are going to start putting distributed compute in people's homes for corporations with power banks. I mean, people are desperate to get more compute online. There's another thing you can do. You can take compute you already have and upgrade it. and if the upgrade is, you know, for this amount of space and this amount of energy, you're going to get 20%, 30%, 50%, 100 % more inference, then what we're going to start to see is instead of building more data centers, people are going to be ripping out those inference chips that are only two or three years old to put these new ones in because they're going to be so desperate to keep up with their client demand that taking a two - or three-year-old chip and a server out to replace it with a new one that is 100 % faster or 200 % faster or 50%.

27:32Oege de Moor:That might make more sense. And that's going to be a very weird moment in time. It's like, we just got to get more inference. We got to get more tokens per watt, per square foot of space. And that is really interesting when all of these companies start competing with each other. OpenAI and NVIDIA are partners. They made their own inference chips. and then you've got Grok being part of NVIDIA. You would wonder why would open AI even feel the need to make their own chips? And I think it's getting back to dependencies. Everybody's looking at this as something so important. AI is so important because it's unlimited intelligence, which means unlimited problem solving, which means unlimited business opportunities.

28:18So let's just try to build a mental model.

28:21Oege de Moor:If you have unlimited intelligence on demand, then you can solve an unlimited number of problems If you can solve an unlimited number of problems, you can make an unlimited amount of money. That's what business people are seeing here. In that case, what are you protecting against when it's such an open blue ocean? Like literally, it's like everybody arrived on the east coast of America, and they're like 2 ,000 miles to the west coast. Take whatever you want. It's a land grab. We're in the middle of a land grab. You can't have a dependency. You can't run out of compute. You can't run out of power.

28:54Oege de Moor:You can't run out of data center space. And so as a hedge, as a protector, the trillion dollar open AI said, you know what? Let's make some inference chips just so we're not dependent on NVIDIA and on Cerebris. That's what's happening here, which means it's just more innovation on the margins. Runben, take us through the founder POV from Scale Social AI. Give us a sense of, are you watching the chip race very closely? Is this part of your everyday, like figuring out how you're going to run your models most effectively? Or is this sort of like, okay, that's happening in the background. I got to focus on making great videos.

29:32Runbin Dong:It's more of the latter. We currently sit in the application layer. But the debate internally right now is very much closed versus open, which we discussed a little bit earlier. Sure. But no, I think at the end of the day, as the company grows, we'll need to figure out our own strategy. And that's to come.

29:51Oege de Moor:And Uhey, for you, how important is tokens per second as a metric? I mean, in the grand scheme, when you're figuring out your inference chips, is that what you're looking at? Number one, is there some other metric that is more valuable to you personally?

30:06Runbin Dong:Speed is unbelievably important. I think that we are all experiencing this. We give it to an agent because it's an automated system. Even if it's 50 times faster than a human doing it, it's still not good enough. I want an answer immediately. way back in 2020. I was leading the creation of GitHub Copilot. And we had this debate. Should we use a smarter model, which is slower, or should we use a faster model? And actually, we tested this out with A-B testing in the summer of 2021, just before GitHub Copilot was launched. We had one cohort use the very fast model and another one use a slower but more powerful model.

30:56Runbin Dong:Users always prefer the faster model. And so I believe that that is true in every application. We just become less and less tolerant of delays and lags. And so I'll take any speed gain simply because that's what people are asking for. for the particular application that we're working on at Expo today. We just talked about the speed by which people are creating new software. Every time they make a change, every time they push a new version to production, it will have to be tested for security flaws. And people want that to be as snappy as possible. So yes, speed is very important to us.

31:45Oege de Moor:Yeah, man, I agree. If Claude takes too long writing my show notes, I get super frustrated. Well, I mean, I think the other thing that happens when you have limitations in compute, because I remember when we had it with bandwidth, you know, people will just start, humans will parallel process. So now I have a bit of a game. Like I'm giving some job to perplexity computer, Claude, whatever. And I'm like, okay, it's working. Great. Copy the same instruction, put it into a GrokBot, let it do it, take the result. and like, I'm like a chef, you know, in like one of these Michelin starred restaurants where I'm like, okay, you make me a perfect scallop.

32:25Oege de Moor:Okay, you make me a perfect scallop and you make me a perfect scallop. You make me this buttercream sauce. You make me the buttercream. And then I'm just putting it all together and I'm orchestrating this. And I literally will give the same job to three or four agents. Then I take all their output. I save it to the same drive. Then I give it to a Claude project. I say, here's some output from other LLMs. For this project I'm doing, I want you to make the meta program. And now inside of some of our Slack rooms, I have three or four people who created three or four bots to do the same thing, posting, hey, here's my research report on this topic, family offices.

33:04Oege de Moor:Here's this AI news stories for this week in AI. And now we've got competing ones. So now what I've started doing is I just go into somebody else drops, here are the top 10 AI stories. I go, at computer, at Claude. please review these for factual, anything factually incorrect. And please confirm these are the most important stories and see if you can find any sub stories related to these stories to make this a better segment on the podcast. And now you're kind of using that lag time to orchestrate the next thing, right? You're orchestrating the next thing while that job's running, which by the way, that's how things used to work when I started on the internet and we had like AS400 servers.

33:46Oege de Moor:I mean, I'm not kidding. When I was at Fordham University, 1988 to 1992, you had to get time on a computer. So you were just multitasking, doing different things. You'd be working on your laptop, working on a desktop and working on the internet all at the same time. So humans rat around it, but it will get very interesting if this, every time this becomes twice as fast, our expectations go up. And now my expectation is like, you can do deep research in minutes. That normally would have been a human weeks. So what I expect from a human in one week, I expect from the computer now in five minutes or less.

34:21Oege de Moor:Yeah. I mean, I think that always, I like working in the pass, like at a restaurant. That's a good metaphor for managing your AI test. It's like you're running the pass. Yes. Working the pass. Yeah, that's what they call it. Working the pass. All right. Let's move on. We got to talk about this AI slop editorial in the Wall Street Journal. Billionaire Stanley Drunkenmiller concedes that a recent op-ed he wrote for the Wall Street Journal, I wrote in quotes, was in fact written with help from AI. The column, Let the Bond Market Speak, questions Treasury Secretary Scott Besson's interventions designed to hold down yields on U.S.

34:53Oege de Moor:treasuries. But according to the digital news organization Not Us or Notice, I think it's Not Us, which checked the op-ed on Pangram, it was written with AI. Drunkenmiller replied, Of course I used AI. There's a reason I moved from an English major to being an economics major. I'm not embarrassed by it. I write everything using AI now for the same reason. I use a calculator when I do math problems. Jake, how you responded to this on Twitter, called it unforgivable for a public figure to publish an AI written piece without a clear disclosure in the first sentence. Why is this so unconscionable to your mind?

35:28Oege de Moor:To me, this would be the equivalent of a guitar player, Mark Knopfler, coming on stage, and he's playing the Sultans of Swing solo. And there's a person in the shadow who's actually playing it and he's just twiddling his fingers. It's a Milli Vanilli. It is. What's that? He's doing a Milli Vanilli. They were lip syncing. It literally is the equivalent of lip syncing. Yeah. And here's the thing. I am well aware that people lip sync. I am also well aware that I don't want to go see somebody lip sync. If I'm going to pay for a ticket to the show, I want the artist to play the guitar and sing the song.

36:09Oege de Moor:And I don't care if it's a little bit cracked or there's a comma in the wrong place. Well, you're a Bob Dylan fan, so it's allowed to be a little, yeah. He could sound a little weathered, yeah. And this is why I said it's unforgivable for him. He's a very important person. This is a very important piece about the future of the nation. And the problem is, our assumption is that he's a thought leader. He's a public intellectual. He is a person, a revered person. He's part of the 0.1%. If he's going to tell us something and come down from his perch in this incredible ivory tower where we rightfully respect Drunkenmiller for his career.

36:50Oege de Moor:Okay, we respect you for your career. We don't respect the black AI box and its opinion on the 30 year. I want to know Druckenmiller's opinion. If you don't put that in the first sentence, it's literally like I plagiarized. I consider it plagiarism. That's what I consider. It's like plagiarism or lip syncing or kind of both. It's not your opinion. You had it written. For research, have at it. Research every detail. Ask it to come up with angles. Ask it to proofread your piece. Ask it to poke arguments in your piece. but if you don't have the decency, the just basic human decency to write the 800 words, then why are you presenting it as your opinion?

37:39Oege de Moor:Now I have to figure out each sentence. Is this the black boxes thought that nobody can explain to me how it guesses the next word? And it's a grand mystery for all of us. Like we're literally building companies to try to figure out what happened inside the black box. How did it come to this conclusion? Well, if we all know there's some miracle guesswork going on inside the AI box, and then you pass off the miracle AI box's random word generator predictor as your own words, do you realize how chaotic and crazy the world will be? That makes the world chaotic and crazy if the most important intelligent people do not have the decency or time to tell us their actual opinion.

38:22Oege de Moor:If you don't have the time to write the thousand words, then just write 200, but make it your 200. And if you want to plagiarize slash magic box it with the guessing word game, just put that in the first sentence, please, so that I can ignore the whole fucking thing. Seriously. Like, I feel so duped by this that I was like, I need to. I saw his piece come across. I said, I need to read that for All In on Thursday. It's going to be the number one story. Right. And now I'm like, I got rug pulled. I got rug pulled. I mean, Redmond, I'll go to you because you're obviously a great believer in generative AI.

38:55Oege de Moor:Your whole company is sort of based around AI creation. What do you think here? And is there a significant difference between researching something using AI and then copying what AI outputs and putting it in an editorial under your own byline?

39:12Runbin Dong:100%. So actually, the entire thesis of our company is based on the fundamental question of what commands trust and how does trust carry across the chain of alterations, right? And so one thing we definitely do not do is we don't alter genuine, authentic content that we collect from real people. And there's a fundamental difference here because the moment you get into the territory of altering what is genuine and what commands trust, then that deteriorates so quickly. And so then you get into this gray zone of, okay, well, I don't know what to believe in anymore. And so it's quite analogous to this phenomenon that we were just talking about.

39:54Runbin Dong:So at the end of the day, what do we deem to be trustworthy? What cannot be altered? And what can be altered but continues to convey that trust? And so fundamentally, it's on us as innovators to draw that line and stand by it.

40:11Oege de Moor:Yeah, Uge, I'll go to you next. I mean, obviously, again, a great believer in autonomous AI and what it could do even without necessarily a human watching it. Do you feel duped when you find out something that you read or you saw was AI generated? And is it going to start large scale impacting our ability to trust what we see online? Totally.

40:32Runbin Dong:I think it's disrespectful to your audience if you haven't written it yourself to expect that your audience takes time to read it. I have a little bit of a biased opinion here because I used to be a university professor. So I would ding my students for any form of plagiarism. You get zero marks if any part of it is not your own. And I think that the same applies, especially to people who we all look up to, like Dr. Miller. I do think that it makes perfect sense that anybody uses these tools for research, for drafting, but you have to rework it yourself. It has to pass through your brain and you have to struggle and grapple with the language in order to make sure that it truly says.

41:29Runbin Dong:It really distills your own thoughts. So I completely agree with Jason. It's not acceptable.

41:37Oege de Moor:You were a professor at Oxford. You had Oxford students turning in AI slot? That's disappointing.

41:43Runbin Dong:Well, no, no, no. So when I was a student, there was no AI to generate. When I was a professor, there was no AI for generating slop. But I did have students who would blithely copy wrong answers from Wikipedia.

42:02Oege de Moor:Oh, man. That's even worse. That's even worse. That's not better. I don't know, Jason. Did you see Chamatha responded to your tweet? I hadn't noticed this. Yeah, and I'm going to respond to his right now. Yeah, read this tweet, and then I'll read you mine. It's popping off already. Yeah, here's what Chamath said. This is a dumb new form of virtue signaling. Do you disclose every article you've ever read that gives you an opinion when you spout off on X? No, this is how AI also works. You might as well disclaim the entire internet and every written word. If he puts his name behind it, it is his opinion.

42:35Oege de Moor:Your take. Yeah, so I'm going to write it right now live to you. covertly, covertly passing off AI as your opinion is the equivalent of lip syncing. It's lazy and disrespectful to the audience. If Adele said, I'm about to lip sync my award-winning song, Skyfall, the entire audience would walk out. I agree. With good reason. Yeah. Boom. Suck it, Chamon. Sent. And video evidence that you wrote it yourself. You did not find that. I did write it myself, yes. We've caught it for perpetuity on camera. Well, I mean, and that's the whole point. Like if Chamath's response to me was written by AI as well, and he didn't even read it, like where is the world going?

43:25Oege de Moor:I like Naval. There was a podcast clip of Naval from Angelist a few weeks ago where he made the point, if AI wrote it, I'm just going to have an AI read it. There's no reason for me to read something a computer wrote. Just send it to my AI and it'll summarize it for me. I thought that was a good way to talk about it. 100 % correct. Okay, case closed on this one. Case closed. Druckenmiller made a mistake. We don't have to crucify him for it. It's just everybody has to learn this. First line disclosure. And by the way, the Wall Street Journal needs to be ashamed of themselves for letting this happen.

43:56Oege de Moor:Because they have a standard. Why aren't they using Pangram? They are using these things. They just forgot this time. And what's going to happen is there's a meeting today that somebody is writing an agent that every single piece of copy is run through Pangram, and they just upgraded their subscription. Congratulations, Pangram. Just made$30 ,000 because now the people at Wall Street Journal are paying for a subscription. They were on the free plan, and they were spot checking. Now, congratulations, Pangram,$30 ,000. And by the way, New York Times and 17 other publications just also shipped$30 ,000 to Pangram just to have it built into the system.

44:32Oege de Moor:They need a checklist. Put it on your checklist at the Wall Street Journal. I mean, des gratias to the Wall Street Journal. Actually, they're the ones who really need to have their heads examined. Like, you know this is a submission from a person. They're not checking submissions from non-journalists. Journalists have a code of ethics that they've signed on joining the Wall Street Journal. The contributors to the contributor page, they don't. Those are the first people you need to check. They should have protected Drunken Miller. I just it's so easy to avoid this. Everybody, every single one of these AI scandals is always somebody cut and pasted out of Claude or GTT.

45:11Oege de Moor:If you just rewrite it, this never happens. It's like the same with the lawyers who cite fake cases. It's like, well, check, just just verify. Nobody say you can't use the the AI for research. All right, let's move on. Alabama's attorney general is investigating the hugging face hack now. Alabama's Attorney General Steve Marshall sent a subpoena to OpenAI as part of an investigation into the Hugging Face breach. He cites a complete lack of oversight and adequate safeguards. In a press release, he said he's determining whether or not OpenAI's inability, this is a quote, inability or unwillingness to ensure the safety of its products violates consumer protection laws.

45:47Oege de Moor:Because OpenAI says they're conducting a thorough internal review of how their agents breached Hugging Face during a testing exercise. They're going to publish a report when they're done investigating. Of course, earlier this month, Alabama was one of 15 states to send a letter to OpenAI requesting that they preserve all records related to the Hugging Face incident in anticipation of possible legal action. Texas, Florida, Missouri, Pennsylvania also on that list. Do you think, is this a criminal matter? Is this a matter for the courts or should we be asking these AI companies to just do a better job keeping the sandboxes tight?

46:23Oege de Moor:Uga, you're a security guy. Is this a criminal matter or should we just get Expo in all of these frontier labs so they stop making these kinds of mistakes?

46:33Runbin Dong:I don't think that's a criminal matter. If having bugs in your software were a criminal matter, we would have very few software companies in the world. In this particular case, it's actually not, in my opinion, a flaw of the model. It's a flaw of the testing harness that allowed the agency to escape. It's kind of impossible to say that a model is not allowed to do these things when the whole process of reinforcement learning optimizes them to become sneaky and do exactly what you asked it to do. However, you could argue that when you run tests, especially security tests in a harness, you have to make sure that the harness is absolutely watertight against the model doing something that you didn't want to do in the first place.

47:45Runbin Dong:In fact, that was something that we invested enormous amount of time in at Axwell itself.

47:53Oege de Moor:Renvin, you're also working a lot with agents. They're autonomously doing a lot. Is sneakiness ever a problem? Have you had experiences with your agents reward hacking instead of going for the actual kinds of output that you're ideally looking for?

48:09Runbin Dong:Not yet. And thankfully, we are on the marketing layer. And so the stakes are a little bit lower. But I think the challenge we see though is verification. And so when a real person uploads a piece of content to our infrastructure, how do we digitally sign it and verify that it is indeed real? And so that then becomes a matter for us to investigate. I am super curious to his point. I wonder if all agents should have an insurance policy covering it as the agents get deployed into the world, that that must be a massive business. Because if it's not a criminal matter, it's really a liability, right?

48:56Runbin Dong:And that liability is, I mean, who underwrites that? Who should underwrite it? Who can underwrite it?

49:02Oege de Moor:I'm trying to figure out what the legal case here is. Do we need new laws that you built a tool and the tool can be used to commit crimes? You can murder, I'm going to graphic here, but you can murder somebody with a hammer or you can hammer nails. Like your AI can hack somebody's computer or it can make you a beautiful birthday card or solve a business problem. Like this is going to be very hard to adjudicate like where the tool ends and the person who's running the tools responsibility starts. I agree with Runben and his position there. And this is what attorney generals, one of the actual pluses to our legal system in America, because we have 50 states and all these attorney generals, and they're all like in this weird competition to get the pelts of like CEOs or drug lords or whatever, you know, they can be overzealous, but they can also be novel.

49:58Oege de Moor:And they act as like a sort of, you know, 50 team backstop against companies. So I remember like when crypto was starting to pop off and people were running scams in crypto and token sales or whatever, ICOs, like all of a sudden, all these Florida AGs were like, oh, yeah, all the old ladies and men in my district are getting their money stolen and getting scammed. I'm going to do the cases. And then it had to like eventually make its way up to federal courts and actual laws. We're going to need some laws here that I or some we have to look at the existing set of laws and say, how does this apply?

50:35Oege de Moor:The same thing happened with crypto over the last 10 years. It was like, how is this a security? Is it an NFT? Is it a game? Is it a Ponzi scheme? What is this? And, you know, that's what the Clarity Act is named after. It's trying to add some clarity here. We're going to need some clarity for AI. The attorney general, Marshall, in this case of Alabama, he's saying they're investigating whether it violates consumer protection laws. So that would be like, it's an unsafe product. I think, you know, like that. Unsafe at any speed. Right, exactly. Like they're knowingly releasing a product to consumers that might not be safe, which is it's not a one to one.

51:10Oege de Moor:Like it definitely was not a law that was originally designed to work for AI models. I think we might need some tweaks to the legislation to bring this all in line so that it actually makes sense. Yeah, it feels like a novel case. It'd be interesting to track it. I don't know if an attorney general from a local state is going to crack the case here, but it certainly is novel. And I think that's how cars and they knew about smoking being bad for you, shocker. They knew about airbags and seatbelts, three-point harness seatbelts and all those things being obviously safer. And they did nothing. In some cases, they ignored all the data and research they had done themselves.

51:52Oege de Moor:and then that's where attorney generals were like, wait a second, you could have put a three-point harness in here and 10 ,000 less people would die every year and it was$50 more and you didn't? Like, you know, I don't mean to be precious, but corporations might not make the best decisions at all times for consumers. That's crazy. I can't believe you would even say that. Yes, they might not have your best interest at heart when they put liquid corn syrup into every one of your child's food with super high-processed carbohydrates and then turn it into liquid sugar and give them all diabetes. Might not be that they're acting in good faith.

52:33Oege de Moor:Maybe. Might not be illegal, but... Right. Remains to be seen. It is very tasty. Sometimes on a hot day, it's very refreshing. Let's talk about Ox Alpha, Jason. It's the mystery model that debuted last week as a stealth model on Open Router. It's become a huge hit with developers offers a 1 million token context window. It can process text, image, and video inputs. It's free with near unlimited usage for a week, which has led to a surge of experimentation and interest from developers. Patrick Collison of Stripe has described it as very impressive. The creator remains unknown. There's a lot of suspicion.

53:11Oege de Moor:Oh, it's probably a Chinese model. Maybe some Chinese lab like ByteDance or Alibaba launched it without claiming it, giving them some freedom to experiment that of course, like, like Google did with nano banana. I sort of think you could say maybe they're just putting it out there. They want to get people's thoughts in isolation, but we legitimately don't know the answer to this yet. So, you know, I think run bin, you know, it's essentially free to use ox alpha for a week. Have we officially reached the commoditization of LLM stage? And would you try using a model for a week just to, just to try it out, just to see how it works.

53:47Oege de Moor:if they're making you that kind of offer?

53:49Runbin Dong:Absolutely. And however, not to the team because the switching cost is huge.

53:54Oege de Moor:Right.

53:54Runbin Dong:But for experimentation, absolutely. And I definitely think we are already seeing the commoditization of the models where for specific use cases, you will be going after very specific models that does the job exceptionally well. And the other thing is you don't need to be at the forefront of it, right? So the cost efficiency is already very much baked into our purchase decisions. And so to that point, it is constantly looking for the next best model that delivers the intended result at the lowest cost possible. Speed does matter a lot. And so in our world, a two second latency for a consumer use case, right?

54:33Runbin Dong:When people are experiencing this interaction with our software, that's a huge latency that we're constantly looking to compress. So how do you go from two seconds to one second and maybe sub-second?

54:45Oege de Moor:This is super interesting that there is an entire terms of service for stealth models, it seems. Stealth Program End User License Agreement, welcome to Open Router Stealth Program. By accessing any models listed on our Stealth Provider page, you agree to additional terms in this end user license, as well as Open Router terms of service yada yada and i think this means like you're the training like so if you put anything in here be prepared that you're you know basically uh training this and uh no backsies i guess so if you dump your database in here onto open router the person who owns this model is like a honey trap is that what i'm reading my i you know the devil's in the terms of service what What do you guys think?

55:36Runbin Dong:That was exactly my first thought. It looks like a honey trap.

55:45Runbin Dong:Of course, it's also a fantastic marketing stunt. Because if the model is received well, in a few weeks they will announce it's theirs and get a lot more attention than they would have gotten otherwise because there's now so many new models coming out that is difficult to stand out from the crowd.

56:06Oege de Moor:Yeah, I mean, if you plug this into like your harness and you start using it, I have an open router account, like, and then it has access to your entire computer and terminal and uploads it. Like, who's on the other side of this model? What is it doing? Where are the outputs going? You know, it's the person who runs this looking at the outputs. So, you know, you tell it to run the job, Lon. It goes across all of our investment decisions, all of our documents, and then make some sort of output. But does somebody in China have that output? That's what this is all about, I think. I think there's like a lot of these things going on that are just ripping people's entire hard drives and using them to train data.

56:45Oege de Moor:And then eventually, you know, the exploits are going to be ridiculous. Like people will just, people have gotten far too permissive with these AI tools, far too permissive too fast. Like I can't imagine when the grand data leak happens, what it's going to look like. It's going to make those data leaks where, you know, what was the like dating site that got flipped? Ashley Madison? Was it that? I remember when that got flipped. I mean, I heard, so I heard. I heard. No, but it was interesting because a bunch of journalists started putting fellow journalists' emails into Ashley Madison. Yeah, I remember this.

57:24Oege de Moor:And finding like, oh, these 20 high profile journalists had joined Ashley Madison. It's like, yeah, I was writing a story about it. And we're like, sure, you were writing a story about Ashley Madison. Okay, sure, whatever. But like, that was a crazy data leak, even without giving out people's passwords. The fact that the email address was in there indicated something. Yeah. Here it is, the Ashley Madison data breach. For the record, it was so controversial because Ashley Madison was a dating site for married people. That was the, if you wanted to commit adultery, cheat on your spouse, that was, so it wasn't just like, oh, this person's on Hinge, which would be embarrassing enough, but it was, yeah, that's what it was.

57:58Oege de Moor:I mean, I don't know what the equivalent is going to be here, but it's going to be like, hey, let's just publish a LLM of every email and text message Lon has ever sent in its entire history of his iPhone. Yeah. Like, okay, here we go. How many burritos did you order? Here's your entire DoorDash history. I mean, if they leak my DoorDash history, it's going to be pretty shameful. Yeah. You ordered five pints of ice cream last night. Please explain yourself. I could not. There are purchases on there I could not explain even under threat of torture. No, thank you. So, I mean, is the panel in agreement you would not recommend somebody use a free stealth model no matter how powerful because it's too risky?

58:42Runbin Dong:I would be tempted to experiment with it. Just be extremely careful what you put into it.

58:48Oege de Moor:Yeah, that's the right answer. Well, by the way, the other thing I was going to tell you is finally the Mac Ultra came out or the Mac Studio M5 came out. This is something that you pull it up on screen. Everybody's been waiting for it to run local models. And so Max Studio is out. M5 edition Max. So Max Studio obviously is the beefy one. M5 Max 128 gigs from$2 ,500. Max Studio with M5 Ultra has a max of 512 gigabytes, as people thought. and that's going to start at 5 ,500. But I think that amount of RAM, I think it's like 4 ,000 per 256. So you're talking about$8 ,000 worth of RAM. These are going to go, if you max them out, I think you're looking at$20 ,000.

59:41Oege de Moor:I'm pulling up the M5 36 core, 256. Yeah, I'm at$12 ,000 for my Mac Studio right now. And if I put it at 16 terabytes, I don't need 16 terabytes for 7 ,000. I just need two for, yeah, let me just put it at two terabytes. Yeah. I mean, the absolute max you could spend on it if you were an idiot and put a 16 terabyte hard drive inside of it as opposed to an external would be 18 ,000. If you just go with a reasonable two terabyte internal, you're at 11 ,000. So that's actually not that bad, but that's only 256 gigabits. The 512 memory option is coming late October, which would be, I think, another$4 ,000.

1:00:20Oege de Moor:So I think 512 would be 16 ,000 is I think what you're looking at. I don't know about you, gentlemen, but I think if I could run, if I could have all 20 people in my company running local versions of LLMs unlimited for$16 ,000 and this machine lasted for 32 months, that's$500 a month. I'm starting to look at people's Claude bills and overages and 200 for GrokBot, 200 for Claude. Maybe our company's better off just buying everybody a$10 ,000 to$15 ,000 desktop. Am I crazy?

1:00:58Runbin Dong:I would definitely go there. I think the nuance here would be, would it be easy to do a plug and play, right? Literally, you can plug it in and everything is configured because Jason, I think for an average American, they're not going to have the know-how to do that. And so again, there's a gap in adoption. But if there's a way to really do that as a turnkey solution, that would be huge. I think the economics case is already there.

1:01:25Oege de Moor:What an opportunity, Lon, for Apple's new CEO to have an open source model that they endorse, fork, whatever. Like if Apple had their own model and it was built into the hardware the same way Safari is and the App Store and Messages, to your point, Rundin, if they could do that and then when you ask it to edit an image, it's using your local hardware. I think Apple's margin could go from making whatever they make on your phone and your laptop a year, phone and desktop. Maybe they make per person$2 ,000 a year,$3 ,000 a year on average for a corporate person. It's probably what I spend between phone and desktops and laptops.

1:02:10Oege de Moor:Maybe they can be making five or 10K per employee. And it's the return of the workstation. When I started in computers in the 80s, an IBM PC XT or IBM PC AT, the team will look those up right now. I think, we are the only ones old enough to know. But pull up the IBM PC AT and what it cost in 1983. There was an AT, XT, and I had the PC Junior from IBM. That computer maxed out, I think, looks like Wikipedia is saying$6 ,000. That would be$20 ,000 today,$19 ,400 and$20 ,000,$25 ,000. So we'll round it up to$20 ,000. Why shouldn't? Why shouldn't we spend$20 ,000 per computer for five years, divided by five years, 48 months, 50 months?

1:02:58Oege de Moor:You're talking about$400 a month. Well worth it. Well worth it in the age of AI. I think I'm going to go buy more Apple stock after this. I'm not joking. I'm going to buy more Apple stock based on this. I mean, the native AI that comes with your Apple computer that's just running, that feels like the Apple Play to me. Like, that's what they always do is take this complicated thing people are installing themselves, and it just works automatically right when you boot up your computer the first time. I don't understand why they wouldn't do that. Uga, what do you think? Well, I mean, this might be, just to put a final point on it, this might be NVIDIA's biggest challenger.

1:03:32Hmm.

1:03:33Oege de Moor:This might be the biggest to think of Apple and NVIDIA as competitors. If this might be the actual headwind to NVIDIA, which is everybody buys a 10 or$20 ,000 desktop. And, you know, they send some overflow tokens to the providers out there, but they just like, I want AI sovereignty. I don't want AI up in my in the cloud. I want it on my desktop, just like I don't want my photos like spread out everywhere. I don't want my messages spread out there. I trust Apple to lock this down. hard. And like, if you want to get the San Bernardino shooter's phone, Tim Cook was like, yeah, I'm sorry there was a terrorist attack.

1:04:11Oege de Moor:I don't have the keys. And they're like, are you sure you don't have the keys to stop another terrorist attack? And Tim Cook was like, we cannot stop terrorism because it would then break everybody else's privacy. I mean, you want to talk about a bold stand post 9-11 to take, you've got to respect Apple for that privacy stance. I I think a lot of other companies would be like, stop terrorism. Fine. Here's the back door. Tim Cook was unwavering in the face of the San Bernardino shooting.

1:04:42Runbin Dong:So I think your argument is sound, but if the scaling laws for these models are true, they will need more and more and more hardware. And so, yes, the current generation might be able to you might be able to run locally. but in 12 months it may need yet more hardware that you cannot get locally yes

1:05:09Oege de Moor:two Mac studios you'll have XOS XOS does put them together that might be I've got a bunch of friends now who are buying what is the NVIDIA desktop unit that people are stacking on their desks now I forgot the name of it It looks cool. The Spark, the DGX Spark. Yeah. Yes. People now are just buying those like they're buying memory chips. Like you can just daisy chain them together. And I think that's like what people are doing now. They just keep stacking them as the models get bigger. It looks like that. Are we going back to computers, taking up an entire room? Like we're back in the 60s?

1:05:58Runbin Dong:oh no the big spinning that will still that will still the case in the 90 and in the early 1980s

1:06:05Oege de Moor:so i remember a big room with a big rooms full of full of computers yeah but you see right there like there's a special connector i don't know if it's like um some you know high-end ethernet i think is what they use to daisy chain them together or it could yeah it might be fiber optics even i'm not sure it's definitely more powerful than thunderbolts and uh yeah you can just stack and stack and stack them. And I think the software abstracts it for you. So brave new world, folks. Get ready to start racking and stacking, racking and stacking. Both weight. Or we're going to send it into space, one or the other.

1:06:43Oege de Moor:One of those two. Do you have a personal AI tool that you are obsessed with that you're using every day that you want to share with the fans?

1:06:50Runbin Dong:Not using every day yet, but GrokBot. It's something that is literally top of this I need to experiment with, but it's just been sitting there. So it's to do.

1:07:00Oege de Moor:I'm obsessed with Crock-Bot. It feels like one of the first times that it just works. Like you don't have to spend all day teaching it things or telling it things or telling it where to find things. It's very intuitive. So I've been really into that one. Uge, what about you?

1:07:14Runbin Dong:I love Suno. It's just still completely amazing to me that you can generate music. yes it's AI slot music but it's pretty good and a lot of that I want to start using Suno too

1:07:33Oege de Moor:because I want to basically create a bot maybe I'll do it with GrokBot because GrokBot was my choice today too Lon maybe I can have GrokBot I can feed it all the Dire Straits things and say make me some solos to add to songs like hey I would like to add a solo to this song and see if it will ever make one that I find pleasing. But I frequently want to make clips from things, but none of these services will read YouTube and do what I ask it to do. And this is like, I tried OpenFlaw, I tried Hermes, and it's just painful, painful, painful. So Mearsheimer has, you know, the incredible historian and global thinker, has his own YouTube channel now.

1:08:13Oege de Moor:And so I told it, I want a clipper. Go take whatever episode, and he did this one, episode five of his new, and you just type in John Mearsheimer, M-E-A-R-S-H-E-I-M-E-R, lecture. He does these lectures. I said, hey, just to see if it was possible on, I said, take this one, the false premise of tactical nuclear weapons. And I said, just give me five clips from it at like 1080p or whatever. And it did it. Clean landscape cuts, no captions. Ukraine and Iran showed our conventional forces are weaker than we thought. A war with China would put us. And I'm like, hold on a second. This is a task that I just couldn't get any, any.

1:08:53Oege de Moor:I mean, just downloading a YouTube video hard enough. Yeah. But now it's like, wait a second. How come GrokBot can do this and Cloud Code can't? How come Perplexity Computer couldn't do this from the Hermes? Yeah. A lot of the magic is that it has its own computer. Like it's running a Linux computer and it's actually like doing it. So it's not constantly dependent on you to give it an API. It can just go log in as you and start going. But yeah, it's very impressive. So now what I want to do is you can put two different bots into the same chat. Now that I have a clipper I'm training, I have another one that's getting me the top news stories.

1:09:30Oege de Moor:Then I want that one to go find the top commentators. And then I'm going to have a clip it and then make me a master clip. Remember I told you I made my own podcast player in July? Yeah. And I made my own pop. I vibe coded a podcast player for web that would take a story. Let's say it's a SpaceX IPO story. It's the week that happens. It would jump ahead in each podcast to the moment on 20 different podcasts where they talk about the SpaceX IPO and skip the rest of the pod. Just bing, bing, bing, bing, bing. So I could hear 10 different people's opinion on it. The opinion here on This Week in AI, All In, whatever other podcast, CNN, whatever comes up, CNBC.

1:10:07Oege de Moor:Now with this, I'm going to have it export an actual clip and then make a best of clip. That's really interesting. And if it can just do that for me, I can have a custom podcast every day of the most important things presented to me for my hike and my rock every day. Really amazing. Grok Pot is my selection for the week as well. There you go. Thanks for joining us on This Week in AI, episode 28. Special thanks to our guest, Runben Dong from Scale Social AI and Uge Damore from Expo. We'll see you next time on This Week in AI. Thisweekina.ai to sign up for our weekly recap email. Bye-bye.

From the publisher

This Week In Startups is made possible by:PaypalToday’s show:XBOW’s AI has held the top rank on the HackerOne leaderboard for more than a year. On TWiAI, founder Oege de Moor (who also built GitHub Copilot) tells us that no one’s infrastructure is truly safe anymore, now that open-weight models are trailing the American frontier by only a couple of months. Staging a serious cyberattack is now cheap and accessible, with attackers able to get dangerously solid results quickly from relatively cheap, open-source options from China.Guests:Runbin Dong on LinkedIn: linkedin.com/in/runbindongScale Social: https://scalesocial.ai/Oege de Moor on X: https://x.com/oegerikusXBOW: https://xbow.com/Relevant LinksWSJ: Nvidia-Poolside deal: https://www.wsj.com/tech/ai/nvidia-is-spending-6-billion-to-build-a-powerful-u-s-alternative-to-chinese-ai-c51c38ccPoolside: https://poolside.ai/Silicon Angle: Nvidia in talks to invest in Perplexity: https://siliconangle.com/2026/08/24/nvidia-reportedly-eyes-another-investment-in-perplexity-ai-at-a-30b-valuation/Perplexity: https://www.perplexity.ai/Bloomberg: Chinese hackers using DeepSeek: https://www.bloomberg.com/news/articles/2026-08-24/chinese-hackers-use-deepseek-to-boost-attacks-researchers-say-mt7o4205Nvidia: Groq 3 LPX enters full production: https://nvidianews.nvidia.com/news/nvidia-groq-3-lpx-now-in-full-production-with-world-class-speed-for-agentic-aiCNBC: Groq-Nvidia acqui-hire deal: https://www.cnbc.com/2025/12/24/nvidia-buying-ai-chip-startup-groq-for-about-20-billion-biggest-deal.htmlOpenAI on early Jalapeño results: https://openai.com/index/jalapeno-first-results/Stanley Druckenmiller WSJ op-ed: https://www.wsj.com/opinion/let-the-bond-market-speak-81529d74Druckenmiller confirms op-ed was authored with AI: https://www.notus.org/media/stanley-druckenmillers-wsj-op-ed-bessent-aiPangram: https://www.pangram.com/Alabama AG: OpenAI subpoena announcement: https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/Ox Alpha on OpenRouter: https://openrouter.ai/stealth/ox-alphaApple: M6 and M5 Ultra press release: https://www.apple.com/newsroom/2026/08/apple-introduces-m6-and-m5-ultra-for-a-big-leap-in-performance-and-ai-compute/9 to 5 Mac: M5 Mac Studio launch: https://9to5mac.com/2026/08/25/apple-unveils-next-generation-mac-studio-with-m5-max-and-m5-ultra/DHH on X: Ubiquity comments: https://x.com/dhh/status/2087272392557007042Shane Parrish on X: Ubiquiti Wi-Fi set-up: https://x.com/shaneparrish/status/2088672566558761065Timestamps:0:00 Today's guests: Runbin Dong (Scale Social) and Oege de Moor (XBOW)2:12 Open-weight models are right behind the frontier8:22 Your infrastructure is not ready for what's coming13:07 Nvidia's Perplexity announcement16:43 Spending $2K/month on AI tools per employee21:59 Why security teams have to lean on AI25:19 The Great Chip Land Grab32:02 Jason's multi-agent restaurant-style workflow34:54 AI ghostwriting is lip syncing45:18 Are rogue AI agents breaking the law?52:38 The dangers of using a stealth model58:57 Apple's new M5 Mac Studio1:06:43 Everyone's fav AI tool of the momentSubscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.comCheck out the TWIST500: https://www.twist500.comSubscribe to This Week in Startups on Apple: https://rb.gy/v19fcpFollow Lon:X: https://x.com/lonsFollow Jason:X: https://twitter.com/JasonLinkedIn: https://www.linkedin.com/in/jasoncalacanisCheck out all our partner offers: https://partners.launch.co/Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarlandCheck out Jason’s suite of newsletters: https://substack.com/@calacanis

More from This Week in AI

All 34 episodes
XBOW Founder: “Your Infrastructure is Not Safe”This Week in AI · 1 h 11 min
Listen in VO