Skip to main content
Malte Ubl

Malte Ubl

Aug 28, 2026

50:47
Um, now that I think offensive security has become extremely cheap with, with open weight models, and the frontier models that are often deployed are often deficient in addressing security for various reasons, including AI safety, how would an AI defense cloud look like? What is this kind of active AI defense for security look like?
51:11
Yeah.
51:12
I, I published a blog post on this, I think, last week, maybe somewhat negatively titled Everything Hackable Will Get Hacked.
51:20
We...
51:21
It's, it is a extreme moment, but I will push back on what you're saying because I think it's a very common misconception.
51:29
Two common misconceptions.
51:30
A, I don't think it's actually priced into the market yet how good, and especially Chemica 3 is at offensive cybersecurity, and that it has no safeguards.
52:40
Mm-hmm.
64:03
How would... an AI defense cloud look like? What does this kind of active AI defense for security look like?
64:13
Yeah.
64:14
I published a blog post on this, I think, last week, maybe somewhat negatively titled, Everything Hackable Will Get Hacked.
64:25
It is an extreme moment, but I will push back on what you're saying because I think it's a very common misconception.
64:33
Two common misconceptions.
64:35
A, I don't think it's actually priced into the market yet how good, and especially Kimmy K3 is at offensive cyber security, and that it has no safeguards.
64:46
Yeah.

9 MINS LATER

73:33
Maybe for an ignorant person like myself who would have thought that sandboxes were less hackable than it seems like they are until recent revelations updated my thinking, Give us a little background on why is it that the sandboxes are still so hackable here in mid 2026? And why are the agents not enough? Why do you need to go put a million dollar bounty on it, given how good the agents already are?
1:56
Um, what's driving that shift?
1:58
Yeah, I think you can really think of the, the abstractions going one level up, and I like...
2:08
Th- I think this is actually a very emerging trend.
2:10
So we will have, I think, more tooling in the future to, to help folks, um, like manage this thing.
2:17
But I think, um, when you think about maybe three months ago still, [chuckles] you would've thought, "Okay, I as an enterprise, I don't wanna bind myself to ever to Anthropic or forever to OpenAI," right? "So I want an abstraction that allows me to program this and like, you know, whether it's the response API or the legacy OpenAI API, it doesn't really matter.
2:37
Like I, I'm always just programming against the AI SDK." And I think the next thing is that I don't really, as an enterprise, I don't wanna bind myself to Claude or to Codex or to the, some kind of managed agent or some kind of like SDK that AWS brings out or that like OpenAI ships, right? I don't, I don't want to have this like vendor lock-in.
2:59
Um, so what if I could kind of go one level up and say, "Okay, can I program an agent that can run on all these har- harnesses?" And I think that's kind of the next step.

6 MINS LATER

9:03
Oh, yes.
18:47
I thought they were the same thing.
18:48
thing.(laughs) No, they're not the same thing.
18:50
That's actually...
18:50
It's...
18:51
I think that's quite, quite important.
18:52
Um, like we also be distinguishing between like agent as a service, right? And so th- the Vercel agent, that's what it is, right? It's ultimately a- a- a...
19:01
an agent-as-a-service product similar to, uh, you know, Codex in the cloud or the, the Cursor agent.

11 MINS LATER

29:50
Is it like a forward deployed engineering situation where, like, you have, like, a SWAT team that comes in and helps people?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.