> so there will be a displacement of medium to large companies by much smaller ones.
There are so many regulations EE companies follow and offer that no startup owner or worker could ever deal with. The moment your company shifts to that sort of work, you're automatically not anymore a startup (by definition).
Only if you get super smart robots that can manage a lot of bureaucracy etc. Starting from multicloud/region deployments, local regulations, accounting, taxes, laws, etc. Which is what companies like SAP (but not only them) do basically.
But if that happens we are all in a situation that we don't need companies anymore (the way we know them).
We pollute right outside our block, give credits to companies claiming to be "green" so that we can sell hardware here that is certified, so that we can go to sleep a bit happier as human beings, because we believe we're doing the right thing.
In all this, they make tons of money, make our economy worse than it ever was with no end game.
Sure, SPD didn't have anything to do with it. Schröder and the Greens didn't have anything to do with it at all.
The Green party itself was literally born out of a protest against nuclear reactors in the 70's (Whyl).
CDU tried to slow down the phase out, but when Fukishima happened Merkel thought about staying in power rather than doing the right thing (= not shutting down the power plants).
I don't care about CDU, which as usual never misses a chance to disappoint, but not saying that the phase out was planned and executed by the Greens (and obviously SPD) is just factually wrong, because they initiated it all and implemented it. It wasn't just a draft, "let's see if it gets amended, etc..".
EDIT: I was talking just purely about energy and such reforms. The last 30 years have been ... to say the least... "weird" and short term.
Disabling a technology is a huge mistake, no matter what. No country did it the way it was done in Germany.
All you need to do to understand what task is more complex (for a robot to solve) is just to ask a 6-8 years old child to do it. It takes days before they "understand".
So it cannot be that simple (for the reasons you mentioned).
Of course, you can mention all the things they can't do (what if there are stairs, what if the doors are smaller than the robot, etc) but it's mindblowing to see what they can do - and also the chat panel is really nice and makes it more interactive.
EU did the Green Deal, though, which is way worse than shutting down a few nuclear reactors that after all didn't produce that much energy anymore and were anyways planned to be shut down.
At my company someone has introduced an internal tool that should help understand and give a "score" to design documents from teams.
Needless to say, this tool gives scores exactly like the article mentions. Same document, same LLM, same prompt, and different results. It becomes even more ridiculous once you switch to other models, or if you ask a model to review the work of another model.
I am not sure why we insist on making LLMs do the work they are not supposed to do and/or in a way they are not supposed to do.
The worst part is that people are aware of the problem but they just ignore it and consider it as "a reference number, just to have an understanding".
If it were like that, it would be less of a problem. The issue comes from the fact that eventually someone without enough knowledge will trust the output (so X points out of Y is how it is), or someone will stop challenging the output and consider it for their process - like in this unfortunate case of hiring.
At a certain point, people who don't know what they are doing give a tool that doesn't know what its doingto people who don't know what they are doing. A pure mess. And everyone has to comply and applaud. If you go against, you are against AI.
This is what I hate the most about AI. Not the tool, but the shortcuts we're willing to take to justify its existence.
If the code is unreachable is obviously not a threat, Mythos or not. Can you do this analysis for all your 200+ services, libs etc?
This is the main issue about compliance nowadays. In a fedramp scenario you would very likely have to prove that it's unreachable, and you might even risk compliance over it.
From an attacker perspective they don't know the lib version you're using, but bruteforcing / finding patterns faster than a hacker can? That's what I believe AI can do. This is why for me CVEs are a useless metric, the number and/or criticality. It's a simple security control but they are giving it so much importance. Then you "forget" to secure access to your mcp server and this leaks company info, but hey, zero CVEs, soc2 compliance check check check.
I think it's a good practice to fix as many CVEs as possible, to have a clean/updated codebase, but I am of the opinion that if someone wants, with the tools they have nowadays, they will find a way in. Of course, using a lib that has obvious security issues for input validation, for example, should be a no-go. However, we're reaching a point of ridicule (like you said above, a critical CVE but unreachable).
I am not against AI but putting automation tools is in a different category than "AGI, you only need specs and they do the work for you".
20 years ago even with automation etc you needed armies of people to make something work. It was more of a transformation of the type of work. Look at the amount of work Amazon as a company has created. It changed how people buy stuff etc, but behind the scenes there is always human workforce, to deliver, to invent the recommendation algorithms, to package the items, etc (although here there is heavy automation).
Now the idea is that we need AI so we can replace humans, so "people can spend more time on what they like to do". Which is what, searching for jobs on LinkedIn?
Not as a metric, but it basically becomes one, like with Fedramp.
You need to fix also moderate/low CVEs within a certain time frame.
So CVE count becomes relevant, because the target is zero, although it doesn't mandate "zero CVEs" but that's finally what the desired outcome is.
It's basically unrealistic to ignore that number, because it's unlikely that you have a steady 1000 CVEs (that are being continuously fixed and new ones discovered), but more like "a few exceptions".
I'd like to know how a "critical CVE running in your software for 29 days" is acceptable from a security standpoint. With nowadays tooling, these AI agents can take you down in no time if they target you.
Compliance the way is done today is basically outdated, but everyone has to follow these rules to sell software basically.
This is true, but security teams often work on tooling dedicated to reduce the n. of CVEs so that a company can keep compliance. That is in fact part of compliance itself to have an automated/reliable processo to tackle CVEs...
In my experience it is becoming basically ridiculous that we disallow compliance based on a number of cve, their level, etc. It's just a checkbox, but it has nothing to do with security.
Was it a better prompt? Have you tried giving the same prompt to other models?
I have found out that the mistakes of other models (which I choose first to save money) help me refine the prompt more and more, until I am fed up and pick Opus 4.8 (for example) which magically seems to get it right, but there is a lot of pre-work there...
Can you give an example of what those "toughest problems/great code" are? I don't need to know the prompt nor the output, but the general idea, what it is about.
However, I think actually that while it won't give the results expected (AI agents run the company, build all features, etc.), it will nevertheless become a developer tool like IDEs, something "you have to have".
It's here to stay but probably with more realistic expectations than some CEO/CTO are pushing for (agents for everything, nobody writes 1 LOC, self healing systems, etc).
So the market expectations will be probably resized, but these tools are here to stay. Be it for cybersecurity (from CVEs to cyber warfare) alone, that's already worth all the money they are throwing a it.
>I've never worked at any company where there was any limit to the work to be done. Sales people don't give a shit what your product can do, only what they can sell, and they never sleep.
The issue is how much of that work is "valuable" in the sense = makes money.
I have both been in projects and seen projects which were canceled once it turned out they didn't make money (bad sales? bad product? bad market fit? a bit of everything?). This you can only afford when you have money to spare (= with debts? high profits...?).
With the interest rates so high, how can a company justify hiring dozens/hundreds of people more? It's a risk, and what I am seeing now is that companies are shrinking left and right to focus on the business that makes money and reduce headcount on what they believe doesn't make money at all, or it's a cost too high for their "long term strategy" or whatever. Right now the only metrics that they are caring about is EBIDTA. They don't even care anymore about ARR, they are becoming irrelevant as long as they stay within a range (we want 20% increase, but we're ok with 5%).
The AI will replace everything and everyone is working out pretty well for Anthropic/OpenAI, though.
I gave up on "people should read things". Especially with AI now telling you how to think and what your final design should look like, I would be at least happy if they did some test of their own design and criticize it constructively.
Just put a "designer" in one of these cars and let them drive in real life situations like:
- a wasp entering your car, while you're approaching the entrance to the highway
- a child suddenly appears on the street from behind an SUV so big you could barely see the sidewalk
- a traffic light, green for you, but red for the car coming straight for your door.
We're past the "happy path". Try real life shit in your tests and maybe we'll install less screens and more sensors to actually help you drive, instead of distracting you.
Saving someone's life should be more important than a dumb undeserved promotion because you digitalized the whole car.
There are so many regulations EE companies follow and offer that no startup owner or worker could ever deal with. The moment your company shifts to that sort of work, you're automatically not anymore a startup (by definition).
Only if you get super smart robots that can manage a lot of bureaucracy etc. Starting from multicloud/region deployments, local regulations, accounting, taxes, laws, etc. Which is what companies like SAP (but not only them) do basically.
But if that happens we are all in a situation that we don't need companies anymore (the way we know them).