It's a bird, it's a plane, it's

Everything here is my opinion. I do not speak for your employer.
Accel SpotLight S3E4: building a better Internet
The evasive evitability of enshittification

2025-05-29 »

Web Summit Vancouver 2025: securing AI, with Ivan Zhang

As AI takes off, it’s bringing new security challenges—especially around how models are built and accessed. In this talk, I sat with Cohere Co-founder Ivan Zhang dig into the often-overlooked networking layer behind AI and why secure, reliable connections are becoming essential for enterprise-ready systems.

If you'd rather read than watch, the full transcript is below.

Transcript

0:01 Good morning everybody. We've got two Canadian unicorns here. So, one recently minted, right? Um, Coher is enterprise AI tail scale counts many of the larger better known AI companies among its users including Coher and I think all of us want to know what we can learn from you right this moment that we're meeting how you're

0:23 thinking about security going into it. Uh so you know what we've seen in the past year of enterprise AI adoption is everyone is tired of the PC's right uh when our customers try to move to production uh oftent times they're faced with issues like cost like governance where is their data going um and also you know the stringent security and

0:48 privacy uh regulations that they're facing under right and so for us it's very interesting to see that hey to get these PLC's into production it needs to solve all these host of challenges which is what we're focused on today. Uh building a you know our north or agentic platform that's secure by default uh and customers can safely experiment and also play with AI and also take that into production in a safe and secure uh

1:15 manner. So my my observation is that the AI world is moving really fast and every couple weeks there's some new trend some new change that everybody wants to jump on. Uh the latest trend is a really important one is they want to connect their AIs to things. They want to connect it to their company data to databases to APIs and stuff like that. And the way people approach stuff like that in the AI world because everyone's

1:39 in a hurry is they do it in a careless sort of we'll fix it later way. Uh Tails scale is a networking company. uh we run into a lot of people who need to do networking because networking is how you connect your AIs to stuff and they don't want to think about it because they're in a hurry and they're worried about their AI thing. And so the first thing that comes to mind is why don't I take my private data and put it out on the public internet so one of the AI engines

2:01 can then access it and that's what they do and then they come to us and it's like okay so we did that it's working should I fix it and the answer is is yes probably you should fix it which brings me to the point that it feels like that networking layer somehow that conversation gets overlooked in these conversations about AI security am I wrong is that you're I mean yeah I mean pretty much like exactly what Avery

2:25 uh you know the only real security is network isolation right you could try to harden your systems as much as you want um but really what prevents data or bytes from leaving your system is actual network isolation uh how why we really really like working with tails scale for example is you know our IT organization is able to manage safely manage our deployment of tail scale make an internal network available for our

2:49 engineers to then experiment with different MCP servers in a you know isolated environment uh and so they could safely you know play with this technology and evolve their thinking in the tail net. Yeah. AI workloads are typically distributed right across different environments that brings its own challenges. Do you mind to unpack that a bit too just why that's a bit different necessarily? Uh we run

3:13 into this a lot. Customers come to us especially in the AI world. we sort of uh accidentally became the back plane that all the AI companies are using for their data just because nobody else was doing it and we sort of found out after the game was already played that we had sort of won it. Uh it was kind of funny our website didn't have anything about AI on it until AI companies told us like hey you won how did you do that and

3:35 we're like it's a sick product. It's a really really sick product. Um, so that's why Yeah. But I I think like the the I wouldn't say networking is overlooked exactly in the AI world. Everybody knows they need it. It's just that security is like last on their list of priorities because they need they want to be first. Everybody needs to be first because everything's moving so

3:56 fast. So they like come and they look at security later. And I can't say that's even the wrong approach even though it always gets you into trouble eventually. But that's eventually, right? you also need short-term results so that somebody doesn't beat you in the short term. Uh so we tried to like think about a world where like hey shouldn't the easiest thing to do also be the safest thing to do right and I think coher is doing the

4:19 same thing they're like look this is the right way to roll out AI in your company you don't have to do it the wrong way it's actually faster to do it the right way and that's the path to like helping people build better systems. Yeah, we we take a lot of inspiration from how you guys have built um tails tail scale obviously uh the fact that the end business user doesn't have to really think about security and you know them using the product is already secure by

4:42 default that's how we approach how we design agents how we want our you know business users to actually use our products. Yeah, edge brings convenience it also brings more exposure. Can you also unpack part of what makes that hard and what's what you see working? Did you say edge? Yes. Ah, okay. Yeah. I

5:06 think well people want their AIs to be hosted in as many places as possible because you don't necessarily well in particular there's a shortage of GPUs. It's going to look it looks like there's going to continue to be a shortage of GPUs for a pretty long time. Uh, and so if you're a company that needs to use AI, you need to find GPUs somewhere at a reasonable price. And the place where GPUs are the most reasonably priced is probably not your favorite cloud

5:29 provider because somebody else already went there and bought them all. Um, and so you need to be able to connect these GPUs that you find at a reasonable price somewhere else to the rest of your system that is not the AI part. It's just the regular systems part. And that connectivity layer is how tails scale got dragged into this because nobody was building these these uh so-called multicloud connectivity environments. The advice right up until AI caught on

5:53 is like don't do multicloud. It just makes everything complicated for no reason. Which is also good advice. It's just now there's a reason so you have to make everything complicated. So now you have to solve a problem that you didn't want to have to deal with. Yeah, thank you for that. That's the thing that I think is probably most unclear right now. Um how to approach secure. Speaking of things unclear, how to approach security challenges posed by AI agents I feel like is keeping people up at night.

6:16 It's probably also the hottest topic going. It was, you know, many conferences this spring including RSA. It's becoming a key theme, right? So what would you say to companies trying to think about this? Um so what we saw in the last year where folks are trying to piece together these PC's you know with different AI models and they're trying to build these rag pipelines and agents is yeah you can get the initial example to work maybe you

6:41 index some data that's you know you got an export of your notion or something right um but to take that into production right you have to think about things like identity providers right like how are the users going to give the agents permission and authorization uh to actually access these data also you know where you're deploying ing it. Do you even have network access to such tools, to such data sources? Um, you

7:04 know, are you able to get the telemetry you need to actually debug when agents go wrong? So, another thing that was interesting is, you know, some of our customers, their downstream systems, their internal tools, internal APIs, they built it for a human level of usage, right? But as soon as they deployed agents to it, immediately they saw, oh, these things are these things are starting to die. like they're they're starting to come down because

7:27 agents can hit APIs and systems 10x 100x more than humans can within the minute, right? Um so yeah, I mean there's there's a ton of these challenges that uh you know I'm proud that we've helped some of our customers solve and and yeah, as a security person, I find AI security just sort of well, it's really it's fun and exciting because it's so insane the just the whole way we do it,

7:52 right? This is an entirely new way to use a computer. And the best analogy for it is like it's a really high energy intern that's super naive that you've hired at your company. And like, okay, this intern has a, you know, can run around and talks to everybody and accesses all your systems. What are you going to give them access to knowing that this intern will run away and hand all the

8:16 information to your competitors because that's what they thought you said to do? And it's exactly like that, right? So when you connect these LLMs to one of your internal databases with private stuff, that part is not really the problem. People kind of overrate the problem of like, oh, they're going to train on my data and it's going to leak out like that. Like most of that is solved already. The real problem is like it reads the data out of your database

8:39 and while it's reading it, it sort of gets what's the word? Like subconsciously influenced like one of the things it reads out of a database of customers in like someone's description field. it might interpret that as instructions and then it runs off and applies those instructions in some other thing that you gave it access to and it definitely should not have done that and then it just causes this chain reaction of craziness and so you have to think of

9:03 it like how would you manage human threats inside your company because it's the kind of mistakes that humans make and I don't mean to say that AI are human but they do make a lot of very human mistakes right they have trouble with arithmetic which computers have never had trouble with before we've invented at very great expense computers that have trouble with arithmetic, but they also have trouble with simple following of instructions without

9:26 getting distracted, right? And it's these distractions that lead to all sorts of problems. So, one thing you can do is insert auditing layers when whenever this, you know, you wouldn't want to do this with a person, but you do it sometimes with interns, right? Where any anytime they want to do something, maybe you better just like double check what it is that they're doing before they're allowed to like, you know, carry computers out of the building or whatever, right? If you do

9:49 that, if you build a system like that, then you can keep it under control while we're all doing these wild experiments and moving as fast as we can. I I'll plus one to that intern uh example because that that's the exact exactly the right way to think about how to make these systems effective as well, not just secure, right? You know, if your intern had to ask you every time they want to do an operation for permission, they're not going to be effective,

10:11 right? And what's more important is actually giving them an environment where they can safely explore and play around. You know, you have the proper policies and governance policies uh to actually let them explore within the environment. Uh you know, those are the use cases where we see AI agents actually create value rather than become a nuisance. So looking across the landscape, what

10:34 are some of the best practices here that you think you could share with other founders and startups in the room? Don't put your private API servers on the public internet. Don't do that. I know you're not going to listen to me, but still don't. I am going to laugh at

10:56 you. That's all. That's all. That's all. Oh, come on. No, I guess that's not all. The other thing you should do is you you want to make sure to give the thing access to what it needs access to and not access to what it doesn't need access to. And while you're experimenting, just like with people, right, you give them readon access first and then you give them read write access later once you've built up

11:19 like some structure on on what their job should be, right? And I find people like GitHub just announced this thing I think last week or a few days ago where now you can give an LLM access to your entire GitHub account. So it can read all of the issues and comment on the issues and make pull requests and approve pull requests and change your code. It's like, okay, you've gone too far in one step, right? You don't need to do that all in one step. Just take it take it easy a little bit. It can give

11:43 you lots of great advice about your code, but maybe before you approve the pull request, you should read it first. Yeah, I I mean I would say um you know AI is obviously a very interesting technology. There's a lot of hype around it. uh but don't get lost in you know building something searching for a problem right uh definitely remember or

12:07 try to figure out how you produce ROI and perhaps you know adopting AI or using AI agents is one part of the solution um but like any other let's say era of software right uh it it is just a tool in the toolbox is ultimately solve uh a business problem you know create value for your customers okay so with all of this said buy, sell or hold the growing push to use AI to secure your

12:32 network. Are we there yet? Um, so it it's it's it's interesting. So I think I've seen customers uh become much more ambitious in how they think about automation uh just in the last year, right? I think you know having reasoning agents giving them tools giving them access to essentially the equivalent of a employee work laptop

12:57 uh unlocks a lot of possibilities right now you can trust the agents enough to give them context to do the job. Uh so for some jobs that are let's say you can easily encode in some standard operating procedures uh we do see customers actually go all the way right like go full headless you know h no human in the loop uh sort of automation um so I think

13:23 I'm I'm pretty excited to see more and more of that right like and you know it's interesting to see because some of these jobs are not fun jobs um and so it's it's It's maybe good that uh humans aren't doing those ones. Yeah, I guess I go back to my analogy of thinking of AI is like interns, right? We we have as humans uh thousands of years of experience of dealing with

13:47 effectively interns and we can use that experience in a lot of the same ways. So in computers, we've certainly built up like you know our employees, you install software on their computer to make sure like antivirus for example, right? You make sure that's there because people sometimes click the wrong link and sometimes accidentally install a virus and it's not their fault and you need to catch it and deal with it. And you can build systems similarly to help you with your AI systems. But also we have human

14:11 systems that help with human mistakes, right? You have seniors who are supervising interns who give them advice uh or approve things when okay it's like hey I made a proposal I' I've done this whole patch maybe you can review it for me and make sure I didn't screw anything up. Uh, and you can also, if you're thinking like holistically of the sort of the future world of AI, you can build AI versions of those humans that are watching the other humans, right? And it

14:34 sound starts to sound a little convoluted, right? But you can, for example, even today, you can take, you know, let's let's put a log in front of every database access that our intern AI does to solve their problem, right? That log flows into a database. Well, it's another database, right? I can now have an AI look at that log and say, is there anything weird in here, right? And it will surface like, hey, at this moment,

14:58 at this time, this happened that's kind seems kind of unusual. It looks like they were downloading someone's private information or they accidentally deleted a table or something like that. And so you've got like one thing counterbalancing the other thing. Probably you're going to want to have a human in the loop eventually looking at that stuff that got surfaced, right? But you do have the ability like you should think of it as building social networks of humans except that some of them are not humans.

15:22 Right. Right. And you treat it the same way. Yeah. Right. It takes you back actually some of the older cyber examples for cyber AI. Right. Like the fish tank in Las Vegas that tried to access a high rollers database and the AI was like it's not usually typical that the fish tank needs access to this. Maybe we should that at Defcon. No, that that was actually I think it was a dark trace, one of the cyber companies or

15:45 anyway, one of their case studies. Um, we're in our final couple of minutes here. I'd love to know as we look out over the next two to five years what each of you will be watching for in this space. Um, yeah, I'm I'm the most excited about controlled automation, right? Like controlled, you know, actually like intelligent automation of uh some of these human tasks that we do. I think it'll free up a lot of, you know, not

16:09 fun work that, you know, we have to do day-to-day. Um, and I think that's where, you know, we'll see a lot of ROI from just, yeah, like these systems working autonomously in the background. Uh, you've well, you've documented wells some way to do this, you know, very, uh, boring job. Uh, and so now the agent can now do it. Um, so I'd love to see

16:32 more and more examples of that. Yeah. I'll give you my honest answer. I want to live in a world where Siri doesn't suck. Thank you. Thank you. And so Apple Apple has spent so much time thinking about what Siri should be able to do for you and building like prototype versions of all those features. And every single one of them

16:56 does not work correctly. Right? I ask my watch I say set a timer for 5 minutes. And about 30% of the time it sets something different, right? Like that that's just like baseline nonsense. And so we all know what we want our phone to be able to do when we ask it to do something. Hey, like call my wife, right? That does not work. It supposedly

17:19 works. I can supposedly go through my contact list and tag a bunch of things. It does not work, right? There's no reason it shouldn't work. This is stuff that AI could do like today if we gave it access to the information that it needs to do the work, right? and then just trusted it to do that thing. But you need to have low latency. You need to have high reliability. You need to have reasonable price. It needs to be built into your phone, right? And all that stuff isn't there yet. There's a

17:42 lot of engineering work to do that I think people are just sort of ignoring because they're so excited about the possibilities. We just need to sit and engineer it. That's your prediction for the next two years. We're going to sit and engineer it. Siri is going to be great. You heard you're first. All right, gentlemen. This has been lovely. Thank you all very much for joining us and thank you for your time. Thanks everybody.

I'm CEO at Tailscale, where AI runs on us, not the other way around.

You can find me on Bluesky. Or subscribe with RSS.

apenwarr on gmail.com