>

Base Layer EP 05: Sohan Maheshwar on You Can't Secure AI With More AI

[Listen now]
EP 05

Transcript

You Can't Secure AI With More AI

Sohan Maheshwar · AuthZed

34:36

This transcript was generated automatically and lightly corrected. It may contain errors, so check the episode audio before quoting it.

00:00Cold open: Gutenberg and the printing press

Jake Moshenko00:00

I've heard AI likened to a discovery instead of an invention. Like, we discovered AI, we didn't create it. Do you think there were, like, fire doomerists or, like, the wheel doomerists who were like, ah, if everybody can get around, who will carry the berries? I don't know.

Sohan Maheshwar00:16

No, I will give you a very real example, Jake. And in the 1400s, Gutenberg invented the printing press, right? And even now, if you ask for what are some of the inventions that changed history, the printing press is often cited as one of them because you could dispense knowledge at scale. Before, there were just, like, the scholars or whoever who would have that knowledge and would give it out. And if you read texts from the late 1400s, there's so much about, man, this is the worst invention ever. Now the common person has access to our sacred texts and it's terrible and all of that, you know. And a part of that is also gatekeeping, I think, because, you know, as a scholar, you're like, damn, now everyone's going to know all the cool stuff I know. So I definitely do not believe in that sort of gatekeeping. You know, I think democratizing information and skill and that sort of thing is great. You'll just see, like, so much better stuff out there. And with any tool, like with a knife, I mean, sure, you can use a knife to, like, harm someone, but we fundamentally use it to, you know, I know, like, chop food, for instance. So the fundamental use case is still going to be something that helps humanity.

01:23Welcome to the Base Layer

Jake Moshenko01:23

Welcome, everybody, to the Base Layer Podcast. I'm Jake, one of the co-founders and the CEO at AuthZed. And today I'm joined by Sohan, who is a DevRel for us here at AuthZed. Sohan, we talk all the time, but never in this format. So I'm super excited to have you here to talk about what your contributions are at the intersection of authorization and AI, which is, of course, what we talk about here at Base Layer. Before we get started, I want to give you a quick, simple warm-up question. What is the coolest thing that you've done so far with AI?

Sohan Maheshwar01:59

Well, thanks for having me, Jake. Recently, I actually built a pretty cool demo, which combined two of my passions. I dabble a little in music. You can see a very blurry guitar right there. I'm not very good, but I have a small MIDI keyboard that I thought, wouldn't it be cool if I sort of built a demo around this? I used AI to hack up this demo where individual keys had certain levels of authorizations with different users. So if you were one particular user, you could access all the keys. Another user could access only a certain octave of keys and things. And yeah, I built it out in a couple of days using AI. It was pretty simple. There's a YouTube video on the AuthZed YouTube channel with the demo and the repository. And yeah, I thought that was pretty cool. Something I would have found a lot harder to do without AI.

02:13The MIDI keyboard demo: authorization per key

Jake Moshenko02:52

I've seen the video. I love it, but it immediately got my mind just whirling. What is the thing that you would have added had you had a little bit more time? What is the thing that you're like, yeah, this is a good stopping point, but our minds finally have this ability to sort of take us as far as we want to go with the help of AI. So what would you still be tinkering with if you didn't have to ship the video? More Cobel.

Sohan Maheshwar03:19

No, okay, so I'm not a very good musician. I'm not even a musician, but I dabble with the idea of being able to play in scale using authorization, right? Where you're like, okay, I want to play like B minor. So I authorize only the B minor keys to make a sound and then just go crazy on the keyboard. And whatever I play will be in scale because the other keys won't make a sound. So I did dabble and I was like, hmm, I should probably do that. But yeah, I didn't.

Jake Moshenko03:49

Yeah, I saw it and I immediately thought about like dependent authorization. For example, like you could literally only play the song note by note because every other key would be unauthorized until you had hit in the prerequisite key. So you could just like mash on the keyboard and no matter what, the right song would come out, all driven by authorization in SpiceDB. Okay, worth a shot, worth a shot, worth a shot. And then I could finally participate in the jam sessions too. So that's the only way I should be allowed anywhere near a keyboard. Yeah, so you've been a developer advocate doing developer relations work for us here at AuthZed, but also before AuthZed. That job requires a lot of teaching, right? Like you are going into a room and you don't know who knows what. You don't know where people are starting from. And you need to find a way to level set everybody and then bring them forward so that they can understand the point that you're trying to make. During the course of that, I imagine there's a thing, like one thing where you wish every single person already knew this. So like what's the thing that you're constantly having to teach and reteach that you wish everybody already knew coming into your talks?

05:06Using more AI to secure AI is not the answer

Sohan Maheshwar05:07

I'm going to give a super current answer for this. So like this is true for maybe the last eight months to a year, which is this idea that everyone has that, hey, let's use more AI to secure AI. So I think it's a natural thing to think that, hey, we have this great, amazing piece of technology, which is LLMs, AI, etc. So you would obviously apply it to different aspects of your job or of technology. One of those aspects happens to be security. And I know I feel there is a bit of a, either like a misconception or like, hey, we can throw more AI into like solving this bit, you know. And I think you would know better than anyone, Jake, that AI is in itself inherently probabilistic. And when you apply that to principles where you need deterministic checks or like a process that's deterministic, things can go wrong. It won't go wrong 100% of the time. It will probably work like 99.5% of the time. But it's still, you know, things can go wrong. And that's where you have like security breaches and data exfiltration and prompt injection attacks and so on. So I'm not naming names, but I was at this huge conference in Amsterdam recently. And at the keynote, one of the speakers actually said, you know, hey, I'm not sure how we're going to solve this, but maybe the idea is to throw more LLMs at securing AI, you know. And this is a keynote. There are like 1,000 people in the crowd. Everyone's like clapping at that answer. And I'm like, bro, no, don't, you know. Yeah. So I think that's a big one right now that I'm sort of grappling with. And it's hard to maybe change that opinion or, you know, teach people that it could be a problem.

Jake Moshenko06:48

Yeah, I'm actually doing some research in this area right now about how to, you know, when you take two deterministic systems and you put them together or two non-deterministic systems, like you don't get determinism out of that. And it's almost, you know, everybody in elementary school learns that like if you multiply a negative by a positive, it's still a negative by two negative. We need like a fundamental algebra of determinism, which is if you take a deterministic thing and you mix it in with a non-deterministic thing, the output is non-deterministic. Yeah. And if you mix a non-deterministic thing with a non-deterministic thing, it's still non-deterministic. Yep. Like, yeah, this is a huge thing. And I think you're right. I wish everybody knew that as well. But we're at this area right now. We're in this place as practitioners of AI and as software engineers and people who are building systems where everybody has this shiny new hammer. And so everything looks like a nail, right? It's like, oh, something's not working, throw some more AI at it. So I 100% agree with that take that I wish people knew that as well. Yeah.

07:06An algebra of determinism

Sohan Maheshwar07:52

And I feel there are interesting sort of contexts to this as well. And this was a link I think you had shared sometime back, Jake, where someone had done an experiment where they opened up their email to an agent and said, why don't you try prompt injecting this and exfiltrating data out? And the experiment worked in the sense that the data wasn't exfiltrated. Which, sure, like, whatever. But the approaches people took I thought were interesting, right? And the author himself mentioned that in a language other than English, prompt injection has more probability, you know, because it's probably trained well enough in a data set in English to avoid, like, obvious prompt injection attacks. But in, like, say, Portuguese or, like, Hindi or any other language, it might actually just exfiltrate data, you know? So there are all these little attack vectors that we are sort of figuring out and seeing right now. And with security, we are always playing catch up, right? Bad actors will always have, like, that step forward. So, yeah, I just don't think throwing more AI at, like, something like this would work, you know?

Jake Moshenko08:53

I think one of the conclusions, I remember the article you're talking about. I think one of the conclusions was that if they had allowed it to be multi-turn, because it was all one-shot exfiltration attacks, that's all they allowed for in the chatbot that they had set up. But if they allowed it to be multi-turn, they thought that the likelihood of success would have gone way up. As you, you know, sort of fill the context window and hammer, like, wear down the LLM a little bit, you're like, oh, seriously, somebody will get hurt if you don't send it to the mail. If it was multi-turn, they thought. And that's actually part of the research that I'm doing right now as well. So, I'm excited. You know, I don't have any conclusions yet, but I'm excited to see where that goes. You know, you're a very talented dev role. You could be working on basically anything. Why is authorization where you choose to spend your time? Like, why is it an important problem to you?

Sohan Maheshwar09:50

Let's just look at the data, right? And this is something I speak about quite a bit, because people inherently think there's a bias that I talk about authorization because I work in an authorization company. But if you've ever checked in code at any point of time for an enterprise, you probably have heard of OWASP, Open Worldwide App Security Project. They make a list of the top 10 risks to web apps. And the last two lists, so the last six years basically, has been topped by broken access control. I tell people this and they're like, yeah, sure, whatever. But then I tell them the next stat, which is in the last test, which was like a few months ago, the last list rather, the headline of that report. And I usually put the screenshot on, like a presentation says, 100% of the applications tested had broken access control issues. So not even 95, not 98, but literally every app tested had issues with broken access control. And I've been in the industry like 16 years. I've spent most of it in like the cloud. And I think the big reason for that, Jake, is I feel our workloads are so much more complex now than it was 15 years ago, right? 15 years ago, you probably just had like the one system, pretty self-contained, monolithic, doing the one thing. Now you have systems talking to other systems. They are so complex. Tech is at the heart of everything we do. So security and permissions and access become so much more complicated, right? And this is an important problem to solve. And I hope that, you know, by sort of building some sort of awareness in communities, it can help. And we've seen it in the past work for things like authentication, you know, like friends don't let friends write their own authentication type thing. So, you know, I'm trying to do my bit, I guess, in the world of authorization.

10:07Broken access control tops OWASP: 100% of apps tested

Jake Moshenko11:33

Yeah, I've actually been one of those people who wrote their own authentication in the past. And I think the problem was more tractable 16 years ago, like you're talking about. You know, you just throw some hashes in a database, use bcrypt, salt them, pepper them. That was the thing for a little while. But now literally nobody is rolling their own authentication because everything has to be enterprise ready. It has to be SSO capable. You have to integrate with other people who can make attestations. So the scope of that got intractable for an individual developer. And authorization is definitely the same way, right? Like you are probably selling to people who want you to do things that would stretch you, that would stretch your application, that would stretch your team. So, yeah, friends don't let friends roll their own authorization either. As a DevRel in this space, though, this is like a really hard thing. Like authorization, when it's working well, nobody knows about it, right? We only have a few of these applications that are where authorization is sort of like a first class citizen. Think you're Google Drives or GitHub, things like that, where the authorization basically is the product. But like, how do you get people excited about authorization when it's this like deep infrastructure technology, very hard to demo? You show people like, oh, look, I was able to do this thing.

Sohan Maheshwar12:59

And they're like, yeah.

Jake Moshenko13:00

So, so how do you get people excited about authorization?

Sohan Maheshwar13:02

It's not easy. Let me put it bluntly. I will say two things. So one, I think, is talking about it in the terms of something people use on a day-to-day basis. I think helps. For instance, I will show them like a GitHub dashboard or something I think we have all seen, which is the access denied on a Google Doc. You know, it's, it's, if you work in tech, someone sent you a Google Doc without permissions at some point of time and you're ping them saying, hey, dude, you know, can you add me to this document? So everyone's seen that page. So saying that, hey, do you know how this actually works and the insane tech that goes, you know, behind making this available at like a global scale? And people assume it's like, oh, just like a row level security. I'm like, no, no, it's way more complicated than that. And that sort of gets people excited. I do think with AI specifically, I've seen a little bit of more interest because I think it's now become a little more tangible, right? Like in a demo, I can show an agent or a RAG accessing data it's not supposed to. And then people get like a little, oh, shit, like we don't do this at our workplace, you know, and it accesses prod or it accesses customer information. And like literally, I had a guy recently at another conference saying, dude, we run many RAGs, we don't do any of this, you know? So I think it's become a little more tangible in terms of like a demo and people seeing it and being like, oh, we don't have this, we should. So I think that helps, right? So I think those are the two sort of things that get people excited about thinking about this problem, at least.

Jake Moshenko14:35

Yeah, I've heard some pretty wild strategies for how people secure RAG without something like AuthZed or SpiceDB. One of them is like, well, we just keep an entire copy of the whole database for each user. And so therefore, whatever is in the database, the user is allowed to access. And I'm like, that sounds expensive. So, yeah, I mean, yeah, people are going through, jumping through crazy hoops. But like, do you think RAG is old news? Is it still relevant? Or has everybody moved on to agents? How does that all work?

Sohan Maheshwar15:08

It's one of those weird things. I think if you listen to like influencers in Silicon Valley, they'd probably tell you, yeah, you know what, like RAG is dead and that sort of thing. But being on ground, like I'm seeing so many enterprises and enterprise devs actually starting to implement RAG, which sort of tracks with the sort of adoption loop that you would, or graph that you would see typically, right? You always have the early adopters and what's that thing called? The Gartner scale of emerging tech or whatever, where there's that trough of disillusionment.

Jake Moshenko15:39

Trough of disillusionment, yeah.

Sohan Maheshwar15:41

Yeah, yeah, yeah, yeah. So hype cycle, that's what it's called, the Gartner hype cycle.

Jake Moshenko15:46

Where are we right now?

Sohan Maheshwar15:47

I don't know. I think we're past that trough of, but also this is like the third thing of AI because AI has been around since the 60s or whatever, right? So I don't know. I do think with RAG as well, I'm seeing like a sort of evolution to like an agentic RAG type system where there are agents which do some reasoning around, should we get more data? Should I generate more data? Should I retrieve more data? And that sort of thing, you know. Very crucially, and this is again something I tell people, don't let the agent decide if it needs authorization as well. You know, I think that's the gotcha when people do agentic RAG. Like, hey, you decide if we need to check for permissions, which again, probabilistic, you know. So you don't want that. Well, but all you have to do is put make no mistakes on the end of your prompt and that's perfect, right? Yeah, good, you're good. Yeah, yeah. You are a trustworthy AI agent. Make no mistakes. Yeah.

16:13Never let the agent decide whether it needs authorization

Jake Moshenko16:41

Do you think we're on a single hype cycle for all of AI in this current iteration or do you think that the various sort of components of AI are on their own individual hype cycles? Like, do you think agents are still at the early adopter phase whereas RAG is past the trough of disillusionment? Or just talk to me about those different sort of competing paradigms or what we're seeing.

Sohan Maheshwar17:03

I mean, I think we can choose to look at it that way where there are so many things within the AI space because I think people are looking at AI as the evolutionary shift, right? Like you went from, like, you had the shift to cloud, the shift to mobile, and now a shift to AI. So you can look at each of those individually, I think, as its own lifecycle in terms of Gartner. In terms of RAG, yes, I'm seeing so many enterprises and so many, like, mid-sized companies adopted. There's, like, an r slash RAG on Reddit, which is very, because I look at it, which is actually pretty active and people talk about it daily. Hey, in my company, 40 billion documents, that sort of thing. So clearly people are, you know, working on it. I feel with agents, we are just, I forget the exact things, but we are before the trough of disillusionment. I think right now it's super hyped and things like that because, again, all the influencers are talking about it, et cetera. I think another thing in that is the whole loop engineering bit that, you know, like, again, all the AI dudes are talking about where there isn't clarity about what exactly we are looping in terms of, like, loop engineering. There's a lot of different schools of thought, I think, about it. I think the big difference with all the AI stuff is it moves so quickly, it's hard to, like, grasp onto, like, okay, this is a thing now, and we can see, like, how it evolves. Everything's moving so quickly, it's all mushed into, like, this one thing. So that's the challenge I feel.

Jake Moshenko18:33

Of these organizations that you're going out and talking to, are you seeing wide adoption of open source models? Are you seeing most people adopting, you know, the big names, the open AIs and the anthropics? Yeah, no, if you'd have asked me the great question, because if you'd have asked me this two to three months ago, I would have said, OpenAI, cloud, that's it, like, game over, right?

18:36De-risking onto open-weight models

Sohan Maheshwar18:59

I think with all the turbulence that's happened in the last three months, companies want to de-risk themselves from other things that happen, you know, like regulation, politics, geopolitics, technical issues, price increases, UBB. They want to de-risk from that, right? And one of the ways they're doing that is by hitting, like, an open source model. And, like, large enterprises now are trying to figure out the economics of actually hosting these models themselves, because they probably have, you know, either the capital to spend on hardware, or they have the hardware already. Another, again, very recent trend, and I was reading about this recently, is a lot of the really large enterprises work with SIs the world over, right? And so many people spoke about, hey, the death of, like, the Tata and the Wipro and the Accenture. But there is this school of thought that these SIs become the de-risk for AI for these large enterprises, you know? So they are the stable, we will provide you with all the models. If one fails, you can choose the other, and we'll provide you a layer above that, that sort of thing, you know? And, again, that's something that we're seeing in the last two, three months with all of the things that have happened with, you know, like, Fable and with, like, some geopolitics stuff, et cetera. So, you know, I think that's also, like, in a state of evolution right now.

Jake Moshenko20:19

Is it even possible to buy hardware right now? I thought OpenAI and Anthropic were just buying all of it.

Sohan Maheshwar20:25

Yeah, yeah, it's just, it's Raspberry Pis all the way down, I don't know, yeah.

Jake Moshenko20:28

Oh, I can run AI on a Raspberry Pi? Yeah, yeah. All right, we're so back, baby. Yeah.

Sohan Maheshwar20:33

I mean, you're okay waiting, like, six days for, like, a response to an answer, right? So it should be fine. Okay, yeah.

Jake Moshenko20:41

It's not tokens per second with the Raspberry Pi. It's definitely seconds, minutes, hours per second. Okay, cool. What are you most excited about right now? Like, what gets you out of bed in the morning?

Sohan Maheshwar20:55

I'm going to play my, I'm a slightly old person in tech card, and say that I've actually worked in the rough AI space for, like, close to 10 years. I was on the Amazon Alexa team, like, 2016, 17, 18. So seeing that changed from that day till now, I think, has been super exciting. And I think to see where we're going next in terms of what among all of these things that we mentioned is actually underexplored right now. And it's super hard to say, right? I think all the think pieces and all the podcasts about changing the nature of work, of jobs, it's so hard to predict how it's going to transform, you know? Because our fundamental model of assumption has changed. So I think I'm actually very excited to see, like, how it would change and what aspect of this really changes, you know? It's curious that as soon as a lot of the image generation stuff came, everyone's like, man, this is going to change things. But people are rejecting all the image AI slop, like, hard right now, including, like, Gen Z and Gen Alpha and stuff, right? But a lot of other things have progressed to being accepted when it comes to, like, yeah, like, code, for instance, or, like, a bot putting in, like, a pull request, for instance, is pretty accepted now. And you just, like, go with it. So it's hard to say how it's going to evolve. So I'm very excited to see it.

Jake Moshenko22:16

I think code gets accepted because nobody has to see it, right? Yeah. Like, it's definitely 99% invisible or more so. And as a software engineer by trade, right, like, we used to pride ourselves on, oh, I have taste. Like, my code is tasteful. It's well-architected. And that was sort of how you set yourself up for future success. Like, oh, I architected this really well, so it'll be flexible for the future. It'll be fast to iterate on. It will help me ship things to my users faster. And now that whole paradigm has just totally flipped on its head, right? It's, like, nobody cares about the code. They're, like, oh, we'll let AI write it. We'll let AI code review it. We'll let AI merge it. And this paradigm of the software factory has come out. And I think it's really uprooted a lot of people and made them rethink the entire way that work gets done. So, you know, I'm with you. I'm interested to see where this all goes. I'm excited. But, yeah, it's definitely a huge shift.

Sohan Maheshwar23:20

Yeah, I'm actually going to give you a little more specific answer to your earlier question about the excitement thing. I'm excited to see if languages like Python and JavaScript exist in 10 years. And my hypothesis is it might not, right?

23:27Python and JavaScript in ten years

Jake Moshenko23:33

What do you think is going to happen?

Sohan Maheshwar23:34

No, I mean, there's a lot of talk about, I mean, we write Python and JavaScript, et cetera, because it is human-readable and human-maintainable and maybe not necessarily, like, the most optimal, you know, way to write code. So, if AI can write code that is more optimal, it need not be in, like, a JavaScript or a Python. It could be, like, in a Rust or C or it could be in, like, straight-up machine code. I don't know. But I'll be excited to see if those languages still survive or, you know, it's just like a, it's like, you know, if you go to a museum, you'll see, like, a Syrian written on, like, a Papyrus script. And that's how Python code might look like in 10 years.

Jake Moshenko24:11

Yeah, that's wild. I think your biggest thing that'll hold you back from that is the training tokens, right? They're so effective at writing Python because there's just so much code to train off of. In this new AI-thon, I don't know, whatever. In this new language, it'll have to write all of its own code to train on. So, yeah, that'll be really interesting. I did see a thing just yesterday where you can actually have AI spit out, like, Linux-compatible ELF binaries. Damn. You can skip the whole code compiler or whatever and just create a binary. I don't know if I would ever run that because how would you know what it does? But it is a thing. Yeah.

Sohan Maheshwar24:55

Hey, where we're going, we don't need compilers, you know? Yeah.

Jake Moshenko24:58

Well, obviously, at AuthZed, or maybe not obvious to people who are listening, but hopefully obvious to you, we like to take bets. And so we like to do things that may or may not pay off. What is the biggest bet you're taking right now that may not pay off?

Sohan Maheshwar25:13

It's, I think, so I use, like, Claude Code on a daily basis. And I know a lot of folks in DevRel still sort of like to use a lot. I mean, still like to write code by hand because a core part of the job is to explain, like, the code that they write. I feel I'm losing a bit of the ability to write code myself in terms of, like, writing it by hand. But I'm able to churn out, like, cooler demos and, like, at a much faster pace because I'm using this. So from a very personal point of view, I feel like I might lose the ability to write code by hand. I don't know if it'll still be, you know, like a prerequisite to be in DevRel or to be in tech anymore. But, you know, if something turns, then that might not pay off. But I'm investing everything into optimizing my workflows to be able to use, like, cloud. So, you know, I'm using all the latest and greatest skills. I'm looking at things like loop engineering and, like, context windows and, like, all of that. So I'm going all in on, you know, on all of this. From a personal point of view, I don't know how it affects my, you know, ability to write code, which, you know, I might lose sometimes. Yeah. Yeah.

25:27Losing the ability to write code by hand

Jake Moshenko26:29

Having gone through the coder, manager, non-coder, coder cycle a few times, I think you'll probably be fine. What is the, like, one of the challenges I have to imagine from being in DevRel is being expected to write demos in every language. And I think, are you finding AI to be a big unlock in writing demos in languages that maybe you're not familiar with, that actually work and compile and pass your tests? 100%. Absolutely. Yeah. Yeah. How are you, how are you making sure, like, what steps are you taking to keep quality up as you go through this evolution?

Sohan Maheshwar27:07

So, at least from a company point of view, I still try and follow, like, a lot of the processes we have as a company if there's a repository going out. So just yesterday, there was, like, a code demo I put up that I sent for review to our open source teams, open source team, rather, who are a bunch of, like, extremely talented programmers. So I got feedback saying, hey, you know, like, a couple of improvements, et cetera. So there is still that human element of someone checking something and, like, going through all of it. So, again, I have, like, a bunch of skills, like, there's, I think, something called, like, the something architect skill. Claude Code itself has a skill which, like, will review your code. I use the superpower skill, which also comes with, you know, something that reviews your code. So I use it as much as I can get from Cloud itself to make sure my code works. And then I use the other, like, SpiceDB specific thing. Like, just for instance, same. Yesterday's repository, we have a SpiceDB best practices page, and our documentation is accessible through an LLM. So I just said, hey, this code repository is great. Make sure it matches all the best practices listed here. And it spat out a couple of things that it didn't follow, which I could then make a change, because this is code going out to people who want to learn about SpiceDB. So that's what I do. Yeah, fascinating. All right.

Jake Moshenko28:26

Well, we're running out of time. So just one more question. Are you an AI doomer, or are you an optimist? Are you a futurist?

Sohan Maheshwar28:34

I mean, I think my answers probably gave it away, but I'm a futurist for sure. I've always been, or I like to be at the cutting edge of tech. And I think there's, you know, despite all of the stuff you might hear in the news, technology itself is great. If you step back and, you know, just think humans made this. It's amazing. Like, you know, this was the stuff that science fiction books dreamed of and thought it would never happen, you know. And the ability to communicate and get context was seen as like almost like the thing that differentiated a human from a machine. And now machines are doing that really well. And humans made it. It's stunning, right? So I feel we don't appreciate that enough. So I'm 100% a futurist. And I believe, you know, like cool things will come out of this. And as humans, we are very resilient and resourceful. So we will make this work for us.

Jake Moshenko29:20

Do you think, I've heard AI likened to a discovery instead of an invention. Like we discovered AI, we didn't create it. Do you think there were like fire doomerists or like the wheel doomerists who were like, ah, if everybody can get around, who will carry the berries?

Sohan Maheshwar29:38

Or I don't know. No, I will give you a very real example, Jake. And in the 1400s, Gutenberg invented the printing press, right? And even now, if you ask for what are some of the inventions that changed history, the printing press is often cited as one of them because you could dispense knowledge at scale. Before they were just like the scholars or whoever who would have that knowledge and would give it out. And if you read texts from the late 1400s, there's so much about, man, this is the worst invention ever. Now the common person has access to our sacred texts and it's terrible and all of that, you know. And a part of that is also gatekeeping, I think, because, you know, as a scholar, you're like, damn, now everyone's going to know all the cool stuff I know. So I definitely do not believe in that sort of gatekeeping. You know, I think democratizing information and skill and that sort of thing is great. You'll just see like so much better stuff out there. And with any tool, like with a knife, I mean, sure, you can use a knife to like harm someone, but we fundamentally use it to, you know, I know, like chop food, for instance. So the fundamental use case is still going to be something that helps humanity. So, yeah.

29:41Gutenberg, and who was angry about the printing press

Jake Moshenko30:46

I would be interested. Yeah, that Gutenberg story is really interesting. I would, was anybody at the time saying like, no, this time it's different. Like we all remember when the wheel or the aqueduct was invented. That was good. But this time it's different. Information is different. Or in this case, like intelligence itself is different. Yeah.

Sohan Maheshwar31:07

No, I'm sure they were. Yeah. You know, because, because. When you live through something, a big change feels like it's different. But like, if you look at this change, maybe 50 years down the line, they're like, oh, wasn't that like an amazing thing? Like how we look at the Internet being like this open thing is like, wow, wasn't that like an amazing thing? So, yeah, I'm, I'm, I'm, maybe I'm a bit of an optimist, but I'm firmly in that camp, you know? So. Okay.

31:28A picture of the future for Gen Alpha

Jake Moshenko31:31

I've got two kids. They're Gen Alpha. What is the picture that you would paint for them of their future growing up surrounded by AI and, you know, AI taken to its, its natural conclusion by the time they're entering the workforce?

Sohan Maheshwar31:46

Should I do my like best Gen Alpha impression?

Jake Moshenko31:50

Oh, I don't know, man.

Sohan Maheshwar31:52

How do you do for the kids? Yeah. So, again, I think it's so hard to predict where things will be, but I, my, again, like an hypothesis is, I think, I think as a society, we are becoming a little bit more, I don't want to use the word isolated, but there's so much more interactions with tech. So I think social constructs become a lot more important, you know? So the nature of things like school and university and work will change, but I still think it's going to remain and becomes that much more important to like interact and learn and learn these social cues, you know, for, for kids, for adults, whatever. In terms of work, I, it's hard to say the nature of work is going to change. There will always be something to do, but what we do and how we do it will change. I have absolutely no idea how it's going to change like 20 years from now, right? But we've gone through all of like a lot of change in the past as well. And a lot of fundamentals haven't like changed. We've still gone to like school. We've still done work. We've still, you know, earned something to like feed our family. So those things won't change. So, you know.

Jake Moshenko33:07

So I shouldn't let them drop out of school? No, no.

Sohan Maheshwar33:10

My, my thing is, I think school actually becomes that much more important right now. Because with using so much more tech, it's like, just to back up, I think the most important thing about school is not like learning the capitals of the 50 states or the, you know, like math and stuff like that. Because that you can learn at home or a library. Like fundamentally, like working with other people and learning like the social skills and the motor skills and how to survive in the world is the cool thing about schools. Like we had schools even in the time of like Socrates or, I don't know, even way before that. And that's the thing you actually learn. The syllabus is, that'll change. But that's fine. Okay, great.

Jake Moshenko33:50

If people want to get in touch with you or learn more about the work that you're doing, do you have any links or social handles or anything you'd like to share?

Sohan Maheshwar33:59

Yeah, I'm on LinkedIn. That's the only social media I use. Just look for Sohan Maheshwar. My personal website is Sohan.co, S-O-H-A-N.co. You'll find links there as well. All right.

Jake Moshenko34:11

Well, thank you so much for taking time out of your day to come and chat. It's been an absolute pleasure. And I feel like I learned a lot about you as a person, Sohan. So thanks for coming on the podcast. And we'll talk soon.

Sohan Maheshwar34:23

Yeah, thank you for having me. Bye-bye. Bye. Thank you.