And so if you have an incident that for some reason is adversarial or has some sort of has higher adversarialness than previous models, that could be really, really disastrous because it has sort of the same coordinated failures across the board. Now, you know, I've talked a lot about sort of we are thinking more about the sci-fi scenarios and we're kind of paranoid about those. But I think this is kind of where we're heading right now. So right now, people are sort of still mostly in the first category of single agents, but already starting with teams of agents where you kind of hand off more and more economically valuable tasks, longer time horizons, more complexity, and so on to agents. And eventually you will have companies of agents. So the way I expect in the future, every software company to look is each individual developer has sort of a swarm or actually a company of agents below them where you have some form of hierarchy to organize them. And so that means insane amounts of work at a speed that we cannot comprehend as humans or at least are hard to comprehend will be done. And you will be mostly managing the agents. I think to a large extent, that's what our developers are already doing anyway. But I think this will get just more and more and you can hand off more and more experiments and more and more like features and so on. And so in that world, the agents have way, way, way more power. And you also have way larger potential for losses because they could cause more harm. And you also are more reliant on them. And so if you're handing off that much power, you also want to have some mechanism of controlling the agents.
Then the reason why I think Evil Clawed could end most organizations by lunch today is it's still not super figured out how exactly you deploy agents without slowing down the developers at scale and organizations and keep the security aspect high. So many deployments happen in shadow IT and then the security teams are often flying blind. Typically, there wouldn't be a way in which you could just control F through all the different traces that the agents have produced in the past, which I think is sort of the minimum requirement. You kind of would want to know, okay, can I at least see what's going on, even if I couldn't prevent it? And so often when I ask people in the security space, like, assume your model had exfiltrated your data and just copied it somewhere else, and it wouldn't have caused any immediate harm. Would you even know? And I think often people cannot confidently say that they would. And then often people think like, oh, VMs just protect me from everything. They put it on the VM. At least it can't, you know, it definitely is an improvement. And you couldn't. And it reduces some problems, but not all of them.
The product that we are building is called Watcher, based on the chains of thought of O3. And the way you can think about it is, here are all the different coding agent deployments that you have within your organization. It works across all the different instances of the developers because many organizations have multiple. At the top here, you have one component that's sort of the high-level view, that's what the security team would see or your engineering manager. And they see all the incidents, they track everything, you can see the posture week over week, and you see all deployments in real time. So if you have 100 engineers and they deploy 10 agents each, you see 1,000 agents running in real time.
Comments