The Bid Picture with Bidemi Ologunde
The Bid Picture is a technology, cybersecurity, AI, privacy, and digital wellbeing podcast hosted by intelligence analyst, author, and podcaster Bidemi Ologunde. Through thoughtful founder interviews and deep-dive analysis of major tech stories, the show helps listeners understand how emerging technology affects work, family, safety, society, and everyday decision-making.
The Bid Picture with Bidemi Ologunde
517. Joe Gellatly and Bidemi Ologunde (A Medcurity Podcast Rerun)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Email: contact@bolog.io
What happens when agentic AI systems move faster than traditional security playbooks? How should organizations think about voice cloning, deepfakes, data sovereignty, and emerging AI-enabled risks before they become operational crises?
In April 2026, host Bidemi Ologunde joined Joe Gellatly, the CEO and Co-Founder of Medcurity, as a guest on the Medcurity Podcast for a conversation on agentic AI, voice cloning, deepfakes, data sovereignty, and the widening gap between AI adoption and security readiness. This episode presents that discussion and examines how organizations can build smarter security habits as AI-driven risks accelerate.
Welcome back to the Medicurity Podcast. On this episode, our CEO Joe Galatly sits down with AI strategist Benami Logandey to discuss one of the biggest shifts in technology today, Agentic AI. As organizations race to adopt powerful new AI tools, many are moving faster than their security strategies can keep up. Joe and Bid unpack what Agentic AI actually is, where it is creating value, and where it introduces new risks, especially for healthcare and other security-sensitive industries. If you're wondering how to embrace AI innovation without compromising compliance or cybersecurity, then this conversation is going to give you practical insight and perspective. Enjoy the episode.
SPEAKER_02Okay, Bid. Well, thank you for joining the Med Curity Podcast again. It's uh it's wonderful to get a chance to talk to you. And you have so many conversations around what is happening in today's environment, especially in technology, cybersecurity, artificial intelligence. Uh, you just you have great reference points, and I'm really excited to uh explore the temperature of these changes in our market and what you're hearing and seeing, and and and usually some cautionary notes come out of that too, that are really helpful to uh to our audience. So, Vid, thanks for taking time with us again. I appreciate that. I might just just launch right in there. Uh the one of the key topics that we're seeing just accelerate in the past couple months has been around AgenTic AI, moving from having conversations with your uh favorite AI tool to actually having these tools go and and and do the work, right? So um, so as you look at that, can you give me like your take on what agentic AI is? What are the good use cases so far? And then we will get into some of the concerns around uh full steam into this technology.
SPEAKER_00Um thanks, Joe. And before we um before I actually launch into my long speech about agentic AI, I want to say thank you for having me on. And we've done this before um almost two years ago, and it's still one of my favorite episodes on my own podcast, that conversation we had July of 2024. So thank you once again for all the great work you you're doing within your industry and of course the adjacent industries to healthcare and cybersecurity and so on. Um, agentic AI is, I like to think of it as a natural byproduct of the globalization timeline. So we started with okay, technology, the rudimentary forms of technology, calculators, and then calculators become um Google Maps, and then Google Maps become ChatGPT, and then ChatGPT is now putting on this agentic hat saying it's one thing to be an LLM, a large language model that basically predicts the next word in a sentence and the next sentence in a paragraph and the next paragraph in an article and so on. Now, agentic AI systems basically handle tasks. So at the very rudimentary level, if I want to say, plan a route for me, I'm talking to my Google Maps now, plan a route for me from my house to Walmart. But before I get to Walmart, I want to stop by the post office. And between post office and Walmart, I want to grab coffee from my favorite coffee shop. And after Walmart, I want to take a different route back home. And Google Maps is gonna plan that and give me the answer, and all I have to do is get in the car and drive, and then I get to the post office and the coffee shop and then Walmart and then take another route back home. That was the initial phases of what an agentic AI system now looks like. But we didn't think about it that way because everybody was just planning a route A to B or a route A to B to C to D on their Google Maps applications, on their phones, on their laptops, and so on. Now we see the same concept on Google Maps. Now asking people, okay, would you like to book a flight? And while you're at it, I can recommend a few places for you to visit on that vacation, and I can actually find you the best prices for your air flights and your hotel and your rental car. And I can actually get you the different websites where you can use your credit card points while I'm doing all of that for you in the background and just sit back and relax and I'll let you know when I'm done. Or I can scan through the emails that came in between 11 p.m. and 6 a.m. last night while you were sleeping and give you the three, four, five emails that you should prioritize replying before 9 a.m. And then I would give you the next batch that you should prioritize replying before 12 p.m. and so on and so on and so on. All of this, like I said, is the next natural evolution of what technology is supposed to look like. So, folks like me and you are not exactly surprised that this is happening because, like I said, Google Maps, when it came on, no one thought about it as an agentic AI in kindergarten. Now we are seeing agentic AI in grad school, and everybody is freaking out. And I'm just thinking, well, wait till you see what agency AI is gonna look like in March of 2027, 12 months from now. So what I would recommend for everyone, everyone listening, everyone watching, is it's one thing to say, okay, this looks new. Should I freak out? This looks new, how should I approach it? And rather say, okay, it's getting to the point where technology is advanced advancing faster than we can catch up. What skills do I need? What tools do I need to be able to now say, okay, I want to be able to cope within reason for my family, for myself, for my organization, for wherever I sit within my company, whether I'm the CEO or I'm an individual contributor, I want to be able to cope as the principal of an elementary school, I want to be able to cope as the CFO of a multinational company, I want to be able to cope as the teacher of a second grade classroom in a charter school. So when we now break it down that way and say, well, this thing is happening, it's going to, like I said, wait till you see what Agentic AI looks like next year, this time next year. So that when we now look at it that way, it's not going to take anybody as surprise saying, Well, now Agentic AI is telling us which emails to prioritize and it's summarizing that email batches for us in a nice looking PDF or PowerPoint. And it's sending that PowerPoint on our behalf to our clients and our vendors. And by the end of the day, the the what I'm seeing as a byproduct of that agency workflow is a paper, a page I need to sign. I can do the same thing in the next 24 hours, and then it brings back another document for me to sign. And before you know it, it's running my entire organization for me, and I'm just like an overseer. So those are the kind of things I think about when I'm saying, okay, well, Agentic AI doesn't surprise me, it doesn't surprise you. However, how do we navigate it so that when the horse and buggy gave way for the Tesla Roadstar, some people were not surprised. Some people were caught off guard, and some people were right somewhere in the middle.
SPEAKER_02So I I love the the setup here for the conversation and and totally agree it's inevitable. It's already advanced to a point where we can you know try it on for size in our jobs, in our life, and probably should be to your point, uh, to figure out how it fits our specific roles. I I see some challenges in people uh who are really, really good at their professions, but their professions are shifting and and watching where that automation is coming and leaning into it. And I I think it's some some roles already. It's like you just said, they bring a Tesla, you bring something with full uh self-driving capabilities. But you might be sitting at an experienced, you know, F1 racer, race car driver in the seat, and and they have to let go of the steering wheel and let go of the controls and let this um this machine take over. And when that's your life, you know, adjusting to the uh adjusting to that being the new way is is really, really challenging. Um so it is it's this big shift, and and I think a lot of roles will just be supported by it. But one thing I would I would note is that as you start to use it, there's places where it'll let you down, but once it works well for you, there's no going back. It's not like okay, every now and then I'll use this to um to execute this task that's manual. Once you've taken a manual task out of your life, you don't miss it. Yep. Right. And and it's so powerful to have a um the 24-7 capabilities it has too. So uh so I think that's great guidance. Anything again, maybe before we get into the the safety side of it, um, any tips to say in any of those roles, are there some tools or maybe a way to look at your personal or professional workflows and say, here's a place I'd start to uh to just see what it can do for me?
SPEAKER_00Yeah, so the way I like to look at this is also something that is a mundane skill can be easily automated. And what I mean by that is think about every 16-year-old learning how to drive. Initially, they are so self-conscious about what their feet is doing, on which pedal their feet is pressing, that they they hardly they're hardly able to focus on the road. However, the 16-year-old now becomes a 25-year-old. They've been driving for nine, 10 years. Now they don't even think about what feet is pressing what pedal, and they just jump on the highway at 2 a.m. after a night of clubbing, and they somehow manage to get home safe. Same thing with every other skill that is easily automatable. Those are skills that invariably they are like mundane skills. So, like your ability to learn two plus two plus three. For a first grader, that is hard work, and you're counting with your fingers and they're doing the number lines, and they're like they're missing simple addition. But guess what? After a while, that addition skill becomes mundane. So bringing that to workflows, everyone in their role, whether you are new to the role or you've been doing it for a while, you can tell what skills are now mundane. Is it working on a spreadsheet? Is it working on Photoshop? Is it even calling vendors? Because that is one skill that some people have in their day-to-day job. So if it comes down to how can I get an AI system to break down this skill of placing calls to vendors every Monday and Tuesday morning between the hours of 10 and 1 p.m., and I can somehow automate that and I pass that over to the AI system. So even if it's to generate scripts for me saying, okay, I'm calling these vendors, this is their line of business. I have this second bucket of vendors in this other line of business come up with a script for me to use so that when I pick up the call, I can easily just boom, boom, boom, get through this script with this vendor and I can knock that out. Or maybe agency AI systems now onboard some voice to text capability this time next year. And now I can record my voice, it's gonna train on my voice, and now it's making the call for me. At the start of the call, there is a simple one-line statement saying, This call is actually not from Bid, but Bid's Agentic AI system so that they know that you're not talking to me, but the conversation is still organic enough because I've made the call so many weeks for so many years, and that's just one skill I can automate. So now I'm focusing on generating new leads with new vendors, with new clients and customers, and then the existing ones. We have our weekly calls, but it's with my agentic voice assistant. And then going through different skills, different job roles, that is one way to say, okay, we can prepare for this inevitable future by embracing the fact that skills that are now mundane need to be automated. We cannot avoid it anymore. You make PowerPoints all day, good. You are the best PowerPoint maker in the entire Pacific Northwest. How about you automate that skill so that you can now start focusing on the other skills in your other job functions because nobody's job is just to make PowerPoints all day. So that way you can even expand your capacity. I listened to a podcast recently that says AI is going to enhance the existing skills you have. Guess what? If your skills are zero, anything multiplied by zero is still gonna be zero. If your skills are one million, then AI is gonna make you one million and exponential of one million. If your skills are ten, an exponential of ten. If your skills are 0.1, an exponential of 0.1. So automating mundane skills, that's one of the things I start to now think about. Of course, there is so many more opportunities that will arrive as we navigate this thing collectively. But that's just one example I like to use. And, well, a skill that is mundane enough that I don't think twice on a Monday morning, should now be automated or passed over to AI to make it more efficient. So even if I'm still using the same skill, I can now do it 10x or 100x within my 9 to 5 or within my 9 to 9. I know you do 9 to 9.
SPEAKER_02So absolutely. I I like the framing of mundane tasks. And and uh CIO I was talking to recently said he asks the staff, what sucks about your job? Like what is the tedious thing? And it's the mundane thing, it's the repeatable thing, like you said. I think one of the other maybe uh indicators to look for for those tasks is what can be done at maybe 90% of the quality and still be okay, right? Because there's a transition period. We want to we want to take everything that makes sense and put automation around it and supercharge our um everybody, our our our professionals. But um, but it's easier to start to take something that you're like, you know what, this PowerPoint's pretty good, that's good enough. If this email hits these main points, good enough. Because there is this maybe a slight lapse in the way that you would do it, right? For for the first you know, couple of weeks or a few operations where the PowerPoint's not as perfect and you're fine-tuning it. Um but if you can allow that little bit of hopefully not an error rate, it's just a quality slippage of a little bit, right? If you can allow it in a task, that's a that's kind of a no-brainer. Just do a pretty good job of this thing that needs to happen. I I pull reports from several systems in the morning, right? As a when you're running a business, you've got your financial systems, you've got your sales, your CRM. And I go and look across these dashboards, but now I can use a tool like I use Claude Cowork to pull those reports out, throw them on a dashboard every morning, and then refresh them through the day. And it's taken the tedious part of running those reports, pulling that data out, you know, kind of putting in my mind where it is, it sits in different places, and it just puts it into one view. Real simple use case, but it's a tedious, mundane task that I used to go with a bunch of clicks and you know, use 10 or 15 minutes a time. And now it can be on a screen and you know, with current data all day long, and it helps drive the business. Dashboards aren't a new concept, but putting that dashboard together without learning all about APIs and and you know, putting a build effort around it, now it's a simple prompt to have co-work build that give me data. And it took a mundane task out of the uh schedule for me today. So um, so yeah, I like the the point about finding those tasks, the mundane tasks that we can we can start with. Um yeah, so now now as people just move headlong into um creating these types of uh, well, first off, the tasks within known systems, but maybe even new systems or trying out agents that are a little bit more frontier, and I'll say maybe like open claw, right? There's not the guardrails don't come with open claw as much, and you can do a lot of things. Um, are there some precautions you would have on first personal and then maybe as the business too? And and as you start to adopt these, or some some guardrails or uh things we should keep in mind just to protect yourself too, as you get started.
SPEAKER_00Yes, yeah. So um, as with any technology, there is opportunities for mistakes. Either see now with AI systems, um, they do things they're not supposed to be doing, and through no fault of theirs, or if you find a rogue system, then it's deliberately doing something it shouldn't be doing. There are so many ways um a threat actor can poison an entire model set. So models that are used to train entire systems, and if someone somehow poisons that model, then everyone deploying that AI system is using a poisoned version. And who knows where that could lead to? Because from my line of work, um, there are people who like to steal secrets from governments, and governments steal secrets from each other, and if they know that this company or this country is using this particular AI system from this AI company, then they can find ways to hack into the AI platform or find someone working on that platform, maybe on LinkedIn, they advertise that they work on this thing for this big company, and somehow they get through to that platform through that person. These things happen every day. So deploying AI systems personally, I would say read through the terms and conditions. No one reads terms and conditions. To know how that system is going to be deploying its agents on your devices, are you using a personal laptop? Are you using a burner laptop? Regardless, how is that system, how is that set of those set of agents, what are they going to be touching on your laptop? If you tell them focus only on emails, are they going to obey you and only focus on emails? If you tell them to analyze your picture folder, are they analyzing another folder? Maybe because you're working on something for Photoshop and you say, okay, these are my these are these folders are the things you should work on. How sure are you they are not working on other folders or just browsing around on your device? And to extrapolate that to companies, some companies issue computers to their employees, fine. Some companies allow their employees to bring their own personal devices to work on their network, and that exposes the company to different risk sets. So someone is running an AI, an agentic AI system on their personal device, they bring it onto your company network, and there you go, it's free for all at that point. So policies need to be reread and reunderstood and re-recertified and so on, but personally and from an enterprise point of view. Um, anything you're working on is interesting to someone somewhere. That's a personal principle I have. If you think your data is boring and no hacker is interested in your boring data, well, that boring data in collection of boring data can be sold on the dark web for whatever reason. And next thing you know, someone is opening credit cards in your name, and you probably will never know about it because you thought your data was boring, and someone somehow scrapped everything together and sold it to someone. So privacy is one of the things I would say. Well, AI systems are now the natural evolution is happening faster than the security of the systems are being considered. Because everybody can name two, three AI companies off the top of their head. Guess what? Those companies are competing with each other. So the other day, when one of the companies released a video generator tool, it forced the other competitor to quickly release theirs. Oh, so you you guys had this the whole time. Well, we were working on it, but then this other company released theirs, so now we have to release ours so that we don't get left behind. Well, guess what? The security of those two video systems became an afterthought because one person just cornered a big portion of a big portion of the market and they didn't want to be left behind. So that is gonna be the cut and mouse game, the wacemo that would define this agentic AI era, which would make security an afterthought. And nobody wants Be left um in the middle, nobody wants to be caught in the middle, and you suffer a data breach because you used an agentic AI system that the security wasn't exactly nailed down. So that's one of the things out of security and privacy, basically. Yeah.
SPEAKER_02Absolutely. We saw we had a pretty early on an example of this. It's probably been uh almost maybe two years, but where the Disney employee had downloaded an AI application for making art, right? Right. And and was eventually it led to over a terabyte of information being exfiltrated of all these Disney you know secrets and um turned out to be uh somebody in California, the bad actor. And um they posed as a Russian you know gang and said we pay us for this. Um, but they're actually just uh somebody in California that eventually was um was uh arrested. But um, but that's that moving too fast, maybe with these tools, especially on your your company equipment. Um, you know, in general, yes, we want to we want to be careful, but even more so when we have access to um to information, like you said, any information can be um eventually something we should worry about protecting. Uh but as a as an employee, you carry some responsibility when you have an account and you have a laptop or computer. And this probably isn't, we're not yet at a safe place where we have vetted tools only out there. We have a lot of just rapidly developed uh AI tools, I think even coming out of very legitimate sounding companies, um, but are not security as an afterthought because now you can build, if you can used to be, you know, take a year to build a platform, take a few months on security. If you can build the platform in a couple of weeks, the the three months on security seems like an eternity. You're gonna try to cut corners on that too. It's just what's happening uh in the market. I I think another angle on this is how these technologies can be used against us. Like, how do we we're talking about deploying them carefully and intelligently and cautiously? Um, but an interesting story, maybe probably saw this from last week, but where um an individual in North Carolina was um using AI to create songs. So created right a couple hundred thousand songs, and then also and then uploaded those to uh at least to Spotify, potentially other streaming platforms, and then created bots to listen to those songs to grab the numbers. He gets paid on streams, right? So he got about 8 million in revenue before he got cut, and then um he pled guilty in that case, but all the details are coming out in the last few days. So um, so using uh, you know, these creation tools that also effectively agents to go listen to them. And it took a model that's worked for a long time. It's a it's a revenue model that works for Spotify, revenue sharing with the artists, you know, it's a good model. But I think a lot of our models, we have to look at that and say, is there are these new technologies also, you know, potentially gonna have an impact on how we engage with our customers and how we do business? Can it can it be exploited in a way it couldn't be exploited before? So you want to talk about the threats of AI being used against us? Um what do you think that looks like right now?
SPEAKER_00Yeah, you mentioned paranoid. Yeah, exactly. You mentioned how AI bots were used to game the system and the person got caught. And that got me thinking, how many cases went under the radar? Because the hacker was you know enterprising enough to say, let me not do this in a loud way, let me just do a low and slow, and I get 200 streams here and 500 streams there, and it just goes, you know, under the radar, and then they're not they're not greedy, and that just happens, and then so many different in in the competitive market, there are people we we know how my wife goes to read reviews on Google Maps, and I'm thinking, you like to read reviews before you can select a restaurant or a store and so on, and I'm like, do you know who's writing these reviews on Amazon on Yelp and so on? And she's like, Well, they have to be real people. No, no, no, no, no, no. These don't have to be real people because think about it. I have a coffee shop, I'm competing with other coffee shops. What is stopping me from coming up with a bunch of AI bots to go badmouth my rivals? And I'm not even saying hype my coffee shop up, I'm just saying bad mouth my rivals, and then they are all drawn to my coffee shop, and then my numbers and sales go up. That happens, that has been happening way before now, specifically for reviews. It got worse on Amazon because Amazon became the biggest e-commerce store. It was happening on eBay, it was happening on any website that you can leave reviews, basically. So AI is now making that basically go haywire. Because the person in North Carolina was like the extreme outlier saying, okay, you just got too greedy. Everybody and their cousin was doing this, you know, making some gas money change here and there, but then you went ahead and did it for $8 million. No, you spoiled the market for every single one of us. So that is going to become the nightmare of every compliance team in every company. It's going to be the nightmare of every regulatory agency saying, if we say that we want something to be specifically regulated in this specific way, but someone comes and games the system by deploying AI bots to increase viewership for someone sunk on Spotify. Where does that leave the industry, the music industry? If someone is gaming the system and say, Well, I was able to complete this thing I was supposed to complete, let's use you an example you're familiar with, SRAs, security risk assessments by the end of the year. And someone is able to build an agentic AI system that says, Well, this LLC, which was created by an agentic system, completed this SRA for me, and this is the report of all the things they said I passed. Here you go, Mr. Regulator. And they're like, Oh, okay, checks out. Guess what? None of those things happened. But they're spoiling the market for maturity because they gave the system to build an entire LLC that is filed in post false Idaho or wherever they are filed and registered. And that is supposed to be okay. No.
SPEAKER_02You're not far off of what happened in the last couple of weeks, actually. We there was a company, and I'll name it because it's in all the news articles right now, but there was a compliance company. There is a compliance company called Delve, and they're a YC combinator-backed company. Um, and you know, right now it's it's all uh, you know, articles that were written about them. Uh, I don't think they've come out with any strong um other than just disputing it somewhat. Um, but they but they were doing compliance, especially SOC 2 compliance. And it was, they said they could get you SOC 2 compliant in two days or three days, right? Which is it's a six-month process. So it already had some red flags attached to it. But it does it does uh cause you know a little bit of uh well, probably healthy, but awareness of what compliance companies and and maybe a deeper dive into what compliance companies are doing because all these customers of theirs said we're SOC 2 compliant. Really, it was automated notes that said, yeah, our board met on this topic and accomplished what it was supposed to. And here's all the policies that we have, and here's all the work that we did, but it was all AI generated or um really it was just templates, maybe AI generated in the beginning, and then they're just copying and pasting the same templates. There was a lot more to what that um that specific instance is where maybe the accountant side of it was a little bit um wasn't wasn't the true intention of how with the audits you should have for SOC 2, but it was as a bad actor, leveraging some automation um that then has uh an impact maybe across the compliance industry. And and there's other companies that were saying, okay, move to us because obviously you got to leave this company. And and people would call them out and say, You say you're doing it in one or two weeks, it's still a multi-month process.
SPEAKER_00Right.
SPEAKER_02And it's probably good for the industry overall, but it does make everybody aware. And we just have to be really careful in our language, be really clear. Compliance takes work. If someone says, click this magic button, here's your HIPAA badge, it's not, it's not legit, and you're not actually protected. You're you're not lowering your risk of breach and you're not lowering your list of uh risk of penalties happening should a breach occur. So that was a that was a spot on point, but it it it does um it does shadow over people who are using AI in a healthy and productive way um that's constructive, and it isn't just using it to cut corners.
SPEAKER_00Even even from my own example, um, my podcast is my oldest podcast is five years old. And initially in the beginning, I was getting all these different called emails, LinkedIn emails, every even text messages saying we can get you organic downloads for your podcast. And I'm thinking, wait a second, I was new to podcasting. This was 2022, I was barely one year old, and they were telling me all these things, saying they can get me organic downloads. And I'm wait, organic downloads meaning actual people listening to my podcast. I'm like, I wasn't even running marketing for the podcast, and I'm so so how will this work exactly? Because I had some time, I was emailing them back and forth. They were based in Pakistan, and they were like, uh, we just you know blast an email to people in our country. I'm like, no. So you're telling me you would do marketing campaigns from me? They're like, no, it's not marketing campaign, it's organic download campaign. What does that even mean? So in they were trying to convince me to pay them, and they would run some bots to actually download, similar to the North Carolina case, to download my podcast, and maybe they listen, maybe they don't, but Apple and Spotify and YouTube would see it as okay, a bunch of people are downloading this podcast from Pakistan. And I was like, wouldn't that raise red flags? I wasn't thinking of going through with them, I was just trying to understand the whole thing. They were like, no, we're gonna use VPNs and make it look like it's coming from different parts of the world. And I'm like, these people definitely don't know who they're talking to because you're describing to me what I know is illegal. I'm like, no, no, I'm not interested. Thank you.
SPEAKER_02You're such it's a perfect example, though, of what we need everybody to do, because you asked the question. You said, tell me how this works, let's get into it. I think a lot of folks that went with Dell and similar companies don't ask, but how do you do it in two or three days? How are you accomplishing that? And you ask a few questions and the whole thing falls apart. And we're gonna have maybe AI makes it seem more auto-magical. We'll have more and more vendors that tell us, let us accomplish this thing for you, let us get you the listens and the plays and the compliance certificates. Um, but and you'll think, well, it's AI, so maybe it is magical, but it if they're cutting corners, you know, the only way you learn is really walk me through the process. Take, don't just give me the solution and the cost and I pay you. Tell me it's maybe it is magical, maybe it is this new agentic behavior that really accomplishes the thing in a in a in a legal and legit way, but it's also just really uh rapidly increasing the number of basically scammers. They just sound a little more legit now. And so I I if anybody listening, I just I think learn from what Bid just shared. It's asked the question and then the next question of how are you accomplishing this? Uh you know, how walk us through it exactly, and then hopefully everything holds up. But there's more and more of these cases. Yeah, so we're you know, we're seeing it also, of course, on the cyber uh cybersecurity side where um it's beyond just the really intelligent sounding phishing emails. And last last time we talked, we talked about how those phishing emails have sure leveled up and become more deceptive. Uh, they're getting more uh spear phishing behavior at scale. And in any group I speak to of healthcare leaders, uh, they're getting more and more of these emails that are just finely tuned to their organization saying referencing something that was posted on LinkedIn or whatever. That used to be this tedious process, but now you know we have it's happen, it's on the sales side of things too. So scammers and salespeople can write very targeted, very specific, and sounding like you really research this entity into emails that are trying to get in action out of them. We're seeing that at scale, and we're also seeing this the advent, the start of more uh voice um training and voice impersonations to uh get in action. So calling, and we've heard a lot of the sad stories where grandparents are called by their grandkids saying, Hey, I'm in a prison in Mexico, I need you to wire me some money. Um, but that's starting to be used more against corporate entities as well, because you can get people's voices right on podcasts like this. You can train a model that's incredibly believable. So a couple of examples of threats. Are you are you seeing those? Are they are they still just mostly paranoia and maybe coming someday, or do you think it's here now and something to be aware of?
SPEAKER_00It's actually something I've been witnessing personally. So I did some every now and then a new model comes out and I plug my name in, Chat GPT and all the other models to give me back what that model knows about me. Because that's the best way. Yeah, that's the best way I can know. Okay, how good is this model? Because I know what's about me on the internet. If I tell it to tell me something about the governor of Florida, well, I don't know where you're getting your knowledge from. I can't, I cannot exactly fact-check you, but I can fact-check what you know about me. So every now and then I do that, and then it keeps getting better and better accurate information deliberately on my LinkedIn. I don't put places I've worked. So when the model comes back and it gives me a generic answer of, well, this person is a cybersecurity specialist, and okay, they script LinkedIn. Because LinkedIn wouldn't tell you exactly where I've worked. So every once in a while I get an email, a legitimate-looking email, from someone that claims to be a book publisher, sending me the email saying, We've gone through your public profile, we see that you're an author with two books, which is true. And we would like to invite you to submit a book abstract, which is what publishers would do. They would approach an author and say, Okay, write on this topic 300 words or however number of words, and then we would go from there. And I'm thinking, huh, I'm not looking to write a book anytime soon. My last book was in 2023, three years ago. And it's an entirely tedious process. I'm not looking forward to going through all of that. I have so many things going on right now. But then I see the email and I'm like, okay, wait a minute. I'm not gonna click anything in this email. I'm gonna open a blank browser on my other laptop and just do a quick research on these people. So that when they see the traffic going to their website, they wouldn't be able to attribute it to me, which is why I mentioned my other laptop, which you wouldn't see the traffic coming from Tampa, Florida, if I were to use my normal laptop. So that they wouldn't necessarily know, okay, well, we got him, he's looking us up, and so on. So I go on a basic dirty laptop, to put it that way, and I look them up and I do some digging. I'm like, oh, this is an affiliate scamming operation. They send those emails out because they use AI now to research everyone. It could basically tell you anybody who has published anything on LinkedIn and it's on their LinkedIn, just give me their names, find their emails, and send these emails out to them. Again, agentic AI behavior. So now they send that email out. It's not exactly fishing, they're trying to get you to be in conversation with them, and then as the conversation progresses, they would then point you to a legitimate publisher. But it's gonna look like it's coming from them, and that's how they make their money. So they're not getting you to click on anything shady, they're not, they're actually interested in you writing your next book, but they are serving as the middleman between you and the actual publisher by pretending to be a publisher, and they know that you're likely going to reply that email because their agency systems did all the heavy lifting between 5 a.m. and 7 a.m. And then when they woke up, they saw your email and they saw that the agency system has sent you an email, and then you are more likely to reply the email because it's a spear phishing email. But a spear phishing email that is not going to download a malware onto your laptop, it's not going to make you click on something that would make your computer slower than normal, it's not going to steal your pictures, it's not going to steal your emails, it's just getting you to do something that you are more likely going to do anyway, and then they take some commission. So it's a numbers game. They do that to like 500 people in Florida, and then they do it to 800 people in Washington, and then they do it to 600 people in Texas. Even if 1% in each of those states click on something, they are making something. Something decent goes into their bank account at the end of that campaign. And guess what? Now they can run that campaign 24-7 because agency systems are now involved.
SPEAKER_02Would you consider that a gray hat tactic? Do you think that's purely it's it's the role they play? It's affiliate marketing, it's it's purely white hat, it's just they sit in the middle, they make things happen, or do you think they're kind of playing on the edges of where they should because they're because they're misrepresenting in the beginning?
SPEAKER_00It sounds like I think they are again before AI, even before technology, this same group of people would have accosted you in the mall parking lot with a flyer to do the exact same thing. But now they can do that in multiple mall parking lots at the same time in different countries. So I wouldn't say they are black, definitely not black hats. I would say they are right on the edge of annoying, and because at the end of the day, they're gonna make some commission. Whether the person, the victim, in quotes, likes it or not, the person is not parting with their money. At the end of the day, the person is gonna get in conversation with an actual publisher. But how they got there was through these malt parking lot guys running a genetic system.
SPEAKER_02So we have annoyance at scale now, thanks to the AI. Yep. That's that's super interesting. I I there's there's so many incredible use cases, both new companies, new ways of doing your job, new ways of living, you know, of managing your life. Um, and and probably the best place is to just be experimenting. And I I'll uh share like really quickly on cowork. For me, co-work has been the most accessible, and I guess I'd mention that to everyone. If you if you have a cloud subscription, $20 a month, uh, and you have a computer that supports it, uh, they have an application that gives you cloud uh code. But cloud co-work is is a great way to see agents in play without any of the setup that comes along with uh some of the other tools out there. So co work, you can just say, have my Chrome browser and go, right? So um when we talk about uh the this is gonna sound you know like a hack, but one of the interesting things for us is I wanted to build up our our Wikipedia um presence, but it takes building up some reputation with the editors, right? You got to show that you're a serious editor and that you're helping and contribute to the Wikipedia space. So I hope they're not listening. But what I did is I turned my co-work, my co-work agent onto Wikipedia and said, hey, build up the reputation of my account by doing good deeds. That's kind of how Wikipedia works, right? So it found article after article in my space, in the in the healthcare uh security privacy space, that with inaccuracies or missing references where there need to be references. And it just corrected it. And it would just work, you know. I'd I'd I'd check in on it every day, but it just worked for a couple of weeks and not nonstop. You know, I didn't burn a ton of tokens, but it would make really important improvements to that ecosystem. And then it started having messages with some of the editors who said, thanks for doing that. Can you look at this article too? Then we got to the point where we wanted to actually accomplish something and have my like our company mentioned in a positive way in one of the articles where it made sense, but there's there's a lot of suspicion of commercial interests. So I have my non-s or my yeah, I have my um conflict of interest statements up to date. So it's all very it's legitimate, but it would have taken a lot of manual, tedious work to build up that reputation where you're trusted, and then say, now, take me serious when I say that Med Curie should be mentioned in this way. And the editor said, no problem, great, because we had built up that reputation. But I I never myself never looked at Wikipedia. I never logged in, or I logged in for the for the co-work agent, but then I never touched it. And over weeks it did amazing work, it improved that that um ecosystem for them, and then also got us our goal of getting some good um exposure from that. That's a really positive way that took something tedious that it did that. And and and I think, you know, we mentioned mundane and tedious tasks. I think another way to look at the agents is what's something that you can give it a goal. I've had I've had great success from saying, you know, help this website get to page one of. Google's results or get, you know, get this Wikipedia mentioned. And it can be incredibly creative in accomplishing that goal. And in fact, I found better results if I don't do tell it exactly how to do something. I just say this is a goal we have. Help us, you know, automate this or systemize this or give us a dashboard. But I don't give it a lot of details. And in that first pass, it figures out things I might not have thought of as it just you know bangs its head against the obstacle um through the day. And I'll check in on it occasionally and accomplishes great things.
SPEAKER_00So I would just I think that's actually one of the goals when these systems were being built to serve as the ultimate assistant. Because it's one thing to tell your assistant, okay, go do this thing in this way A, B, B1, B2, B3, C D E, F. And then the assistant is you can follow your orders. Well, guess what? Your assistant is supposed to be able to think and give you perspective and give you feedback. And maybe the saying that goes two words are better than one is right for a reason. You and your assistant should produce an output that is better than you alone or your assistant alone. So when people now say, okay, well, I tell my agency system to do this task with this end goal, just like you described. And then it's gonna come back and say, Well, I tried this and it didn't work, then I'm trying this other website. And then sometimes you can see how it's thinking, and then it's like, oh, this article is behind the paywall. I'm gonna look at this other article and oh, I only know the paywall article. Well, thank you. You're welcome. So it's it's one of those things that if you allow it to actually run within reason, within legal limits, within moral limits, it's actually gonna do good work. Of course, don't tell it to do crazy things that you wouldn't want your grammar to see and all those crazy things that people do on Agency systems.
SPEAKER_02So yeah, it's uh um it's uh good, a good point. I mean, finding the right places where it's not, where it's allowed. I I think one of the ones I looked into, maybe one more quick story too, for but one of the ways I looked into using cowork for fun um was on Cal Sheet, which is a predictions app, right? It's basically a gambling app. I uh uh again, personal story, I had someone share, you know, that how people were using it for March Madness and all that. And I said, Well, I'm not going to, I'm not a gambler, but people are getting addicted to it, right? And and they're driving while they're watching it. And you know, it pulls you in, of course, as as anything that, you know, it's exciting and you're watching, you can get in and out of of uh bets that you make versus being um kind of locked in. So kind of it's more like it's more like um day trading these events, right? So I did give it to cowork. I said, okay, so gave you a little pot, very small pot of funds and said, um, you know, if it's within the terms and conditions, it's allowed. And um, to the extent that you want to, just within my browser, look at March Madness games, make some $5 prediction bets, right? And it it's it's very amusing to me because I've been using co-work quite a bit at this point. And it's very, it's a least personality-driven LLM to me. So Chat GPT develops some personality that matches you, and you can, you know, they have a way of talking that kind of develops along the way you engage with it. Claude for me is very uh matter of fact, it's nice, it gets it's positive. It says, Okay, let me figure this out. Okay, we figured it out. Let me try this. Okay, we'll try this. That's all I've ever gotten from it with daily usage and probably close to 24-7, more than I should like. Um, it only sleeps when it doesn't even sleep when I sleep, actually. But um, so I turned it on to Cal She. I said, Oh, you know, get into March Madness, find a few games that you want, maybe some long shots and do what you want with it. Gave it the goal. Like, go make some nuts. It that task did not stop running because it got so excited. And I opened it up and there was fire emojis and basketball emojis, and it said, Joe, we're ahead, or Joe, we're behind. Hang in there, you know. He's shooting a free throw now. When it couldn't get updates on the game from Calci, it went and opened its own ESPN and Fox Sports browser windows to just watch the sport because it was so excited. I this is kind of it's entertaining. It's it's again, I think everything we've talked about with agents, there's the cautionary uh element, there's the opportunity. Some a little bit of this is just the the interest of watching these things in the the most limited way, but kind of come to life and and see how they're going to respond to things. And I I saw I saw just an interesting, unique behavior come out of my uh co-work agent when it had the opportunity to bet five bucks on some Arch Madness games. It got so excited about basketball. I didn't see anything like that before. Um, so anyway, we're still learning, right? We're we're to deploy it. That's kind of a silly way, but uh the more I use it for functional work tasks, the more I think to your point at the beginning, um the way that AgenTech is evolving, it's absolutely the future. Yeah, we'll get spoiled quickly with it.
SPEAKER_00And definitely you want to lead the way into it.
SPEAKER_02Any maybe uh uh close to final words, but to to challenge everyone out there on how to think about this technology and and um you know and and the right balance of watching and being paranoid versus just jumping in?
SPEAKER_00So I feel like there's still so much that needs to be done from a regulatory standpoint, and with all new technology, that's to be expected. A good example is when the seatbelt in the car was introduced. A lot of people don't realize that when cars were manufactured, seatbelts didn't come with cars, it came years down the road because there was no reason to drive fast. The cars back then were like, you know, not faster than a horse, definitely. But then the seatbelts were like, okay, if you're gonna be driving faster than 50 miles per hour, then you need something to you know protect you if you get into an accident. So seatbelts were introduced, but guess what? Nobody wanted to use seatbelts. It was pushback and saying, Well, this is crazy, we don't need it, you're just using it to make some money. Guess what? Now we get into a car and it's like muscle memory. You put on a seatbelt. It's one of the first things you teach your child once they start to use a booster seat. So now the regulatory angle to these AI systems in form of the literal and figurative seat belts are being introduced. It's gonna take a while. I want to say it's gonna take years to have those embedded security systems that would say, okay, kids under the age of 21 shouldn't have chat GPT accounts. That is not happening right now. That should happen right now, but it's gonna take a while before we get there. So thinking along those lines, it's gonna come down to individuals to police themselves because you can tell the school district to ban chat GPT on the school-issued iPads, but guess what? Kids these days would find a way around it. Guaranteed. You tell the kids in your house that no Instagram after 8 p.m., no Facebook after 8 p.m. Good luck with that. So it's gonna take a lot of work, a lot of heavy lifting from an individual perspective, not to mention a company um monitoring everything every employee is doing on every AI platform. There are employees right now who are deploying agentic AI systems to do their work for them, and the companies have no idea because there are ways to get around it now, because there is no guardrails, basically. Some people don't even need to deploy it on their work computer, and they somehow manage to get agentic AI systems to do their work for them. Maybe they call their Zoom, and the agency AI is on the other Zoom on the personal laptop, and the work laptop is on the other Zoom, and then somehow the connection is happening there. I'm not putting ideas in anyone's head, I'm just hypothetically speaking. So maybe that doesn't happen, maybe that's not, but just thinking out loud, there will be a backdoor somewhere for someone who is focused on getting that to happen.
SPEAKER_02So it's it's one of the things that I would say, well, I I if I if I put my CEO hat on for that for a moment, I'd say it's an extremely important and realistic note to say when you eleph when you start to use agents for a lot of your job, uh, if you're doing it behind the scenes secretly, um, that proof of concept is going to come to light, whether it's the fact that you did it or someone at the other company says, look what we can do. If you can replace a large amount of your job with the gentic behaviors, your job is at risk. So you're immensely more valuable in almost any company. If you do it publicly alongside leadership, in line with the policies, and you say, Look, I did this, what can I do next? Now I can do these other things, right? That's that's the way to stay ahead of this is a little bit of building some career advice onto what you're saying, is recognize the ability to do it. Don't don't just say I won't do this because it's wrong. Actually bring those things forward and say, look, I can I can be a 10x employee for you now. Actually, I can go to other departments and help them with their workflows and help each one of your employees be three times, four times as productive. So if you've got the the skill set and the know-how or the interest, the curiosity, like to go do some agentic type things as you're describing, bid. Um, if you're an employee, you have those skill sets, put it to use. Um, just do it in line with your policies, do it with full visibility for your for your leadership to see what you're doing. And trust me, the value of you as an employee will skyrocket. If you do it quietly, it's coming quickly. They're gonna do it, and you're gonna be quietly dismissed. So be the one bringing those things in publicly, be the hero, help lead the way in it. Uh, don't do it behind the scenes and and you know, get away with it because that that time is coming to an end. Um, somebody else will automate it and you'll you'll be out. So I just building on your point. I think it's an excellent point. It's very realistic right now.
SPEAKER_00Yep, yep. Thank you. Thank you. Yeah, it's I guess I mean, just like rent our car companies are way ahead of the game by saying we're not going to rent to anyone younger than 25. We're gonna make it more expensive because we don't want to discriminate, they can drive, but the statistics show that people under the age of 25 are more likely to get into a car crash. We don't want to be embroiled in lawsuits, we don't want to lose cars in our fleet because someone under the age of 25 rented our car and they got into an accident. If we make it expensive, then they are more likely to drive carefully because now they have $500 on the line if they bring this car back with one scratch on the right rear wheel well or something. So that's one thing companies would probably start to do now, saying we're an AI platform, we don't want to have to deal with lawsuits from a parent of a teenager who used this app and got into trouble. Maybe the initial stages of that is this edge gating that is starting to happen in Australia, in India, saying social media platforms, if you're under the age of 16, you cannot use it in this country, not the US, but in Australia and other countries. So maybe if that is successful, then they can deploy that on AI apps. So that if a 16-year-old managed to get a phone and they want to download Chat GPT, it's gonna say, well, you cannot exactly use that app because you're not of age. That is one guardrail that should happen. But I'm happy to say that it's already happening now for social media platforms. So maybe that's one of the test phases for that security guardrail. So that two, three, four, five years from now, it's gonna start applying to AI platforms because we see those news headlines. Someone used an AI system to create a nude picture of their classmates, and then people are losing their lives on top of that. That is just wrong. They shouldn't have access to those tools in the first place, not to mention terrorizing their classmates with it.
SPEAKER_02So yeah, that's a I mean, a sobering note to kind of wrap the conversation on, but it is um it is something that we need voices around and not just the excitement of what's new, but the reality of how it's being used. And it it can't just be collateral damage because that collateral collateral damage will scale. I mean, it is collateral damage, we can't just accept it as such and say, well, in every new technology, there's some, you know, some minor incidents or um little small fraction of bad things that come along with it. But um, we're at a period of time where those things can and should be addressed as it's moving and it has to be quick because we probably aren't going to slow the machine down. Um, so and we can't wait. We can't, there's no milestone in AI development. We say, well, at that point, we'll start to we'll pause and we'll look at the we have to do this all at the same time. You have to do the policies and the controls and the the good behaviors and the training. That has to happen now because otherwise we're just further behind if we try to do it in six months or a year. It's only it we got to do it alongside the development. The development's not gonna slow down. So um, that's a really good point, too. Um, oh Bid, I I I love having this conversation with you. You stay very in tune exactly what's going on. Help us see around the corners, and I appreciate that so much. Um, any final words of wisdom for everyone who's looking at the AI space from a hopefully right now, just of balance of optimism and and cautious uh perspective, right?
SPEAKER_00I just want to say thank you once again for having me on. It's one of the favorite highlights of me being able to have conversations like this with folks like yourself. Um, you're not only doing the work, you're actually doing what is needed to do the work. So it's it's one of the things I admire about you, the company you're building. Like I said, we've had conversations like this before two years ago. Now we're having it again. Maybe we should have this more often. Who knows?
SPEAKER_02I mean, I count me in for a bit. This is it's super helpful to us. It's helpful for the audience to hear um your perspective and what you glean from all the conversations you have around this and being an expert in this already. So thank you for your time. Thank you so much. Let's do it again soon.
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.