Discussion about this post

User's avatar
Stephanie So's avatar

Always worth reading because the insights are grounded in first principles "the specific threat is sector agnostic ... (but) not all software is created equal".

I wonder if you'd consider adding a new immutable primitive for software defensibility at scale: not "trust" per se, but the ability to produce evidence that the software behaved as advertised. Valid inputs -> valid workflow -> measurable performance -> validated outputs.

Since I consider AI to be the new Wizard of Oz, I'd like very much to see the man behind the curtain. Without a foundation to think about data-in-data-out, I think even Bustamante's (terrific) three-point framework needs to be qualified to: as long as it can show it's not GIGO.

Thoughts?

1 more comment...

No posts

Ready for more?