<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Chasing Polaris - Wickey's blog: AI & Investor POV]]></title><description><![CDATA[What I’m seeing in deal flow, how I evaluate AI cybersecurity startups, and where I think the market is headed. Written from the perspective of someone who has sat on both sides of the table.]]></description><link>https://wickey.substack.com/s/ai-and-investor-pov</link><image><url>https://substackcdn.com/image/fetch/$s_!s0xb!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c613d43-fd41-4bdb-bb7b-a5ca0e1b1aac_590x590.png</url><title>Chasing Polaris - Wickey&apos;s blog: AI &amp; Investor POV</title><link>https://wickey.substack.com/s/ai-and-investor-pov</link></image><generator>Substack</generator><lastBuildDate>Mon, 08 Jun 2026 22:40:02 GMT</lastBuildDate><atom:link href="https://wickey.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Wickey Wang]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[wickey@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[wickey@substack.com]]></itunes:email><itunes:name><![CDATA[Wickey Wang]]></itunes:name></itunes:owner><itunes:author><![CDATA[Wickey Wang]]></itunes:author><googleplay:owner><![CDATA[wickey@substack.com]]></googleplay:owner><googleplay:email><![CDATA[wickey@substack.com]]></googleplay:email><googleplay:author><![CDATA[Wickey Wang]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Gap Between Knowing and Doing]]></title><description><![CDATA[What Robotics Is Teaching Us About the Real Challenge of Enterprise AI]]></description><link>https://wickey.substack.com/p/the-gap-between-knowing-and-doing</link><guid isPermaLink="false">https://wickey.substack.com/p/the-gap-between-knowing-and-doing</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 07 Jun 2026 00:27:43 GMT</pubDate><enclosure url="https://i.scdn.co/image/ab6765630000ba8a41e2f33c72a2bc6f6d8cd53d" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>According to RAND Corporation&#8217;s 2025 analysis, 80% of enterprise AI projects fail to deliver their intended business value, twice the failure rate of conventional technology projects. McKinsey&#8217;s 2025 AI survey found that while 88% of organizations now use AI in at least one business function, only 39% report any measurable impact on earnings. In 2025, 42% of companies abandoned most of their AI initiatives, up from just 17% the year before.</p><p>Most explanations for these failures point to data quality, organizational readiness, or change management. These are real factors. But after years of working in AI Governance and Security Risk, I&#8217;ve come to believe there is a more fundamental problem, one that these explanations don&#8217;t fully capture. Organizations are confusing Intelligence with Capability. And that confusion is costing them billions.</p><p><strong>A Lesson From Robotics</strong></p><p>The distinction became clear to me through an unexpected source: a conversation with Joe Dong, co-founder and CTO of Chestnut Robotics. Joe observed that most people are amazed when they see a robot do a backflip. But in the robotics industry, the harder problem is usually not the backflip, it&#8217;s picking up a piece of paper from a table.</p><p>When I first heard this, it seemed counterintuitive. A backflip is obviously more complex. But the more I thought about it, the more I realized these are fundamentally different kinds of problems.</p><p>A backflip demonstrates what a system <em>can do</em>. Picking up a piece of paper verifies whether a system can actually <em>complete a task</em>. The former is a demonstration of Intelligence. The latter is a test of Capability. The former shows up in demo videos. The latter determines whether a system creates real value.</p><p>Joe explained that most people assume a robot&#8217;s intelligence is the neural network. But the robot&#8217;s intelligence is actually the entire system. Even if the model is perfectly correct, the robot can still fail, because of camera calibration errors, sensor drift, inconsistent hardware behavior, or latency in the control system. The model knows the answer. The system still can&#8217;t deliver the result. This is not a problem unique to robotics. It is the central problem of enterprise AI.</p><p><strong>The Intelligence-Capability Confusion</strong></p><p>For the past several years, the AI industry has competed primarily on one dimension: making models smarter. Every major release from the leading AI labs has focused on stronger reasoning, longer context windows, better benchmark performance.</p><p>This competition has produced genuinely remarkable results. But it has also created a dangerous assumption in the enterprise: that Intelligence naturally and automatically translates into Capability. It doesn&#8217;t.</p><p>Consider what happens when you give the same model to two organizations. One embeds it deeply into workflows and decision processes, redesigns how work gets done around it, and builds the data infrastructure to support it. The other lets employees use it occasionally to draft emails or summarize meetings. Same model. Radically different outcomes.</p><p>McKinsey&#8217;s research confirms this pattern quantitatively: organizations reporting significant financial returns from AI are twice as likely to have redesigned end-to-end workflows <em>before</em> selecting their modeling approach. The Intelligence was not the differentiator. The integration was.</p><p>The most successful AI companies of the past two years illustrate the same principle. Harvey in legal services, Cursor in software development, Perplexity in information retrieval, none of them won by offering a smarter model. They won by embedding AI into a complete workflow. The value users receive doesn&#8217;t come from the model itself. It comes from the combination of model, process, data, interface, and decision chain.</p><p>Between knowing and doing, between Intelligence and Capability, there are workflows, data pipelines, control systems, feedback loops, and countless organizational constraints. That gap is where most enterprise AI projects go to die.</p><p><strong>Why This Confusion Is So Persistent</strong></p><p>The Intelligence-Capability confusion persists for a reason: it is easy to see Intelligence and hard to see Capability.</p><p>When a model first demonstrates something impressive, summarizing a complex document, generating a detailed analysis, producing code that works, it is natural to conclude that the hard problem is solved. The system <em>knows</em> what to do. Surely value will follow.</p><p>But the real world has never worked that way. Knowing how to complete a task and actually completing it are separated by data quality, process integration, exception handling, user adoption, and organizational change. These factors don&#8217;t show up in demos. They show up in production.</p><p>There is a further complication: organizations lack the data to understand how AI will behave in their specific context. Unlike traditional software, which behaves predictably given defined inputs, AI systems make probabilistic decisions that interact with organizational processes in ways that are difficult to anticipate. There is no ready-made database telling an organization how its AI will perform in its specific workflows, where it will fail, what risks it will trigger, or how it will interact with existing systems. That understanding can only be built through deployment, observation, and iteration.</p><p>This is why so many AI projects stall after the pilot stage. The pilot demonstrates Intelligence. Production requires Capability. And the path from one to the other is longer and more demanding than most organizations expect when they approve the initial investment.</p><p><strong>A Framework for Closing the Gap</strong></p><p>Executives approving AI investments need a different set of questions, ones that probe Capability, not just Intelligence. Before committing to an AI initiative, consider three diagnostic questions:</p><p><strong>1. Have we redesigned the workflow, or are we adding AI to the existing one?</strong></p><p>AI deployed on top of a broken or inefficient workflow produces faster broken outputs. The organizations that generate measurable returns from AI invest significant time redesigning the work process before selecting the technology. If the answer to this question is &#8220;we&#8217;re adding AI to what we already do,&#8221; the project is likely to underperform.</p><p><strong>2. Do we have the data infrastructure to support this system in production?</strong></p><p>Gartner estimates that 85% of AI failures are attributable to data quality or data readiness problems. A model is only as good as the data it operates on. If the organization cannot answer clearly where the AI will get its data, how that data will be validated, and how the system will handle data gaps or errors, the project is not ready for production.</p><p><strong>3. What is our plan for observability and iteration after launch?</strong></p><p>This is the question most organizations skip. Deploying an AI system is not the end of the work, it is the beginning of a continuous process of monitoring, feedback, and improvement. Organizations that treat deployment as the finish line consistently underperform those that treat it as the starting line for learning.</p><p>These questions do not evaluate the Intelligence of the model. They evaluate whether the organization has the conditions to translate Intelligence into Capability.</p><p><strong>The Next Decade of AI</strong></p><p>The robotics industry is teaching us something important about the future of enterprise AI. In robotics, the frontier has shifted. Getting the model right is no longer the primary challenge. Getting the entire system, sensors, hardware, control systems, feedback loops, data pipelines, to work reliably in the real world is where the hard work now lives.</p><p>Enterprise AI is approaching the same inflection point. The models are capable enough. The limiting factor is no longer Intelligence. It is the organizational and technical infrastructure required to translate Intelligence into consistent, reliable, measurable Capability.</p><p>For executives, this reframe has significant practical implications. It shifts the investment question from &#8220;which model should we use?&#8221; to &#8220;what does our organization need to build to make any model work?&#8221; It shifts the success metric from &#8220;can the model perform this task?&#8221; to &#8220;can our system reliably deliver this outcome?&#8221; And it shifts the governance question from &#8220;is the AI smart enough?&#8221; to &#8220;is the AI embedded well enough?&#8221;</p><p>Most enterprise AI failures are not Intelligence failures. They are Capability failures, failures of workflow, data, process, and organizational readiness. Recognizing this distinction is the first step toward building AI programs that actually deliver.</p><p>The gap between knowing and doing is not a technology problem. It is a leadership and organizational challenge. And closing it may be the most important AI work of the next decade.</p><p>Reference: Innovator Coffee Podcast: <strong>Innovator Coffee EP-36 Beyond the model - The real challenge of robotics: </strong></p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a41e2f33c72a2bc6f6d8cd53d&quot;,&quot;title&quot;:&quot;Innovator Coffee EP-36 Beyond the model - The real challenge of robotics&quot;,&quot;subtitle&quot;:&quot;Wickeyjw&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/6hYjdeQEkYOJyzSDt8hLFy&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/6hYjdeQEkYOJyzSDt8hLFy" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe>]]></content:encoded></item><item><title><![CDATA[Security Companies vs. AI Companies: Two Business Models, Two Completely Different Logics]]></title><description><![CDATA[The Starting Point: Both Sell to Enterprises, But They&#8217;re Not Selling the Same Thing]]></description><link>https://wickey.substack.com/p/security-companies-vs-ai-two-business-models-logics-wickey-gimtc</link><guid isPermaLink="false">https://wickey.substack.com/p/security-companies-vs-ai-two-business-models-logics-wickey-gimtc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 02 May 2026 01:24:34 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cb5d9b74-d4c0-475d-868d-24213d6e6383_1279x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gqB9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gqB9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 424w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 848w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 1272w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gqB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gqB9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 424w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 848w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 1272w, https://substackcdn.com/image/fetch/$s_!gqB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a74c7f6-f461-4242-a214-4ea346287510_1279x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>The Starting Point: Both Sell to Enterprises, But They&#8217;re Not Selling the Same Thing</strong></p><p> On the surface, SentinelOne and OpenAI are both selling software to enterprises. Both have enterprise sales teams. Both are competing for the attention of CIOs and CTOs. Both talk about platforms and ecosystems. But look closely at how they get in the door, how they retain customers, and how they expand, and you&#8217;ll find two completely different business DNA strands.</p><p><strong>Security companies sell certainty.</strong> You can&#8217;t not buy, because the consequences of not buying are data breaches, regulatory fines, and board-level accountability. A security purchase isn&#8217;t a decision about &#8220;what do I want&#8221;, it&#8217;s a decision about &#8220;what risk can I not afford to take.&#8221; This fear-driven buying logic means security companies have always operated in a market defined by necessity.</p><p> <strong>AI companies sell possibility.</strong> You can choose not to buy, but if you do buy, efficiency goes up, costs go down, and your competitors might pull ahead. An AI purchase is a decision about &#8220;how do I get better.&#8221; This curiosity- and competitive-pressure-driven buying logic means AI companies face a market that needs to be educated and convinced.</p><p> This difference in starting point shapes almost everything that follows.</p><p> <strong>I. The Investor Perspective: Whose Moat Is Deeper?</strong></p><p><strong>The Security Company Moat: Platform Lock-In + Compliance Binding</strong></p><p>SentinelOne&#8217;s GTM can be captured in a single sentence: get in through the endpoint, hold them through the platform.</p><p>A customer&#8217;s initial purchase might be a single endpoint protection product. But once they&#8217;re inside the Singularity platform, running XDR, Purple AI, Data Lake, Identity Protection, the cost of switching rises sharply. The further customers go into the platform, the deeper SentinelOne&#8217;s moat becomes.</p><p>More importantly, security companies have a layer of moat that AI companies find very difficult to replicate: compliance binding. When a company uses a security product to pass a SOC2 audit, achieve ISO certification, or satisfy cyber insurance requirements, that product is no longer just a technology choice, it&#8217;s embedded in the company&#8217;s compliance architecture. Replacing it means re-auditing, re-certifying, and re-explaining the change to insurers. That friction is real, expensive, and time-consuming.</p><p>The ceiling on security company moats is also fairly clear: market size is relatively fixed, growth depends on new customer acquisition and existing customer module expansion, and exponential growth is difficult to achieve.</p><p><strong>The AI Company Moat: Data Flywheel + Usage Lock-In</strong></p><p>AI companies&#8217; moats are theoretically deeper, but currently more fragile.</p><p> In theory, AI company moats come from two places. First, the data flywheel: the more people use the product, the more data is generated, the better the model gets, attracting more users. Second, usage lock-in: once an enterprise&#8217;s workflows, codebases, and internal documents are built around a particular AI model, switching costs rise quickly.</p><p> In practice, AI company moats are thinner than they appear. Model capability is commoditizing faster than expected, what GPT-4o can do, Claude 3 can also do, and so can Gemini. The rise of open-source models is further eroding the barriers around closed models. DeepSeek&#8217;s emergence prompted many enterprises to seriously ask for the first time: is frontier model capability becoming a commodity?</p><p>The deeper question is this: does an AI company&#8217;s moat come from its model or its data? If it&#8217;s the model, open source is eroding it. If it&#8217;s the data, then the enterprise&#8217;s own private data is the most valuable asset &#8212; not the AI company&#8217;s. This question remains unanswered, but it will determine AI company valuations a decade from now.</p><p> <strong>The Core Investor Contrast</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yNQH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yNQH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 424w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 848w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 1272w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yNQH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png" width="1086" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:1086,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!yNQH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 424w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 848w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 1272w, https://substackcdn.com/image/fetch/$s_!yNQH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc68040-ecbe-4d5e-b499-a70ed8e01aa1_1086x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p><strong>II. The Industry Observer Perspective: Two Industries Converging</strong></p><p><strong>Security Companies Are Becoming AI Companies</strong></p><p>Security companies recognized early that AI isn&#8217;t just a threat to defend against, it&#8217;s a weapon to enhance their own products.</p><p>SentinelOne&#8217;s Purple AI is the clearest example. It brings natural language querying into security operations, letting analysts ask &#8220;were there any suspicious lateral movements in the last 24 hours&#8221; in plain English, rather than writing complex query strings by hand. CrowdStrike&#8217;s Charlotte AI does something similar. Zscaler has introduced AI into dynamic zero-trust policy adjustment.</p><p>These aren&#8217;t just feature updates, they&#8217;re GTM strategy upgrades. Security companies have discovered that AI capabilities can justify expanding modules with existing customers, increasing ARR, and differentiating against new competitors. Security companies are AI-ifying faster than the market expects, because they already have two things AI companies lack: customer relationships and security data.</p><p> <strong>AI Companies Are Becoming Security Companies</strong></p><p>AI companies are moving in the opposite direction, but with similar logic. Anthropic has made AI safety alignment the core narrative of its brand differentiation, translating it into a trust signal for enterprise buyers. OpenAI continues to invest in AI safety research and has begun positioning model safety and compliance as purchase prerequisites for enterprise customers.</p><p>This isn&#8217;t just a PR move, it&#8217;s GTM strategy. Enterprise customers are increasingly treating security and compliance as necessary conditions for AI procurement, not nice-to-haves. Particularly in highly regulated industries like financial services, healthcare, and government, AI products without a security and compliance story can&#8217;t even enter the procurement process. AI companies are learning the thing security companies do best: using compliance and trust as a sales weapon.</p><p><strong>Where Is the Boundary?</strong></p><p>The convergence is real, but the boundary is currently still clear. Security companies have customer relationships and industry trust, but lack frontier model capabilities. AI companies have model capabilities and developer ecosystems, but lack the trust credentials and compliance track record that enterprise security demands.</p><p>The most interesting question isn&#8217;t who wins. It&#8217;s whether the speed of cross-industry convergence will outpace the speed at which each side can build the other&#8217;s core capabilities.</p><p><strong>III. The CISO/CTO Perspective: How Is the Buying Decision Different?</strong></p><p><strong>Two Different Budget Pockets</strong></p><p>The most direct way to understand the difference between security and AI company business models is this: they are competing for different budget pockets.</p><p>Security budgets are controlled by the CISO, funded by risk management and compliance requirements, relatively fixed, with clear annual budget cycles. The logic of this pocket is: not spending this money creates a quantifiable risk.</p><p>AI budgets are currently controlled more by the CTO or engineering team, funded by efficiency improvement and innovation investment, flexible but unpredictable. The logic of this pocket is: spending this money creates possible, but uncertain, returns.</p><p>Something interesting is happening to these two pockets: AI security is beginning to emerge as its own budget line. As enterprises deploy AI at scale, CISOs are starting to ask: are our AI systems secure? Is there a data leakage risk? Can our models be compromised by adversarial attacks? These questions are pulling AI budgets and security budgets to the same table.</p><p><strong>The Fundamental Difference in Procurement Process</strong></p><p><strong>How security procurement works:</strong> CISO identifies risk &#8594; issues RFP &#8594; multiple vendors compete &#8594; third-party evaluation (MITRE, Gartner) &#8594; proof of concept &#8594; legal contract negotiation &#8594; deployment &#8594; annual review</p><p>This process typically takes several months, and complex projects can span an entire fiscal year. Decision-makers need hard data they can present to the board, need industry-standard compliance certifications, and need to reference what peer organizations have chosen. Sales cycles are long, but once signed, renewal rates are high.</p><p><strong>How AI procurement works:</strong> Engineer discovers tool &#8594; self-service trial &#8594; escalates internally &#8594; enterprise contract negotiation &#8594; deployment</p><p>This process can be completed in a matter of weeks. The decision driver is actual developer experience, not compliance requirements. Sales cycles are short, but customer loyalty is relatively low in the early stages, because switching costs haven&#8217;t yet accumulated.</p><p> <strong>What&#8217;s changing:</strong></p><p>These two procurement processes are beginning to influence each other. AI companies are discovering that to get into core enterprise systems, they must pass security reviews, produce compliance documentation, and survive lengthy procurement processes, they are learning the patience of security companies. Security companies are discovering that developer-tool buying logic is permeating enterprise decisions, and the CTO&#8217;s voice is getting louder, they are learning the agility of AI companies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jLPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jLPQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 424w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 848w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 1272w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jLPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png" width="1084" height="614" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:614,&quot;width&quot;:1084,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!jLPQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 424w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 848w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 1272w, https://substackcdn.com/image/fetch/$s_!jLPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb240f43-1e7d-4afe-b461-6c952a1125f7_1084x614.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p><strong>Takeaway: Two Logics, Two Markets, One Emerging Intersection</strong></p><p>Put all three perspectives together, and what emerges isn&#8217;t an answer about who wins. It&#8217;s a map of two fundamentally different commercial logics.</p><p>Security companies&#8217; business models are built on <strong>certainty</strong>. Customers buy because the cost of not buying is too high. The moat comes from compliance binding and platform lock-in. Growth is linear, predictable, and stable. This is the mature logic of a mature industry.</p><p>AI companies&#8217; business models are built on <strong>possibility</strong>. Customers buy because the imagined future is compelling enough. The moat comes from data flywheels and accumulated usage. Growth is expected to be exponential, but remains full of uncertainty. This is the emerging logic of an emerging industry.</p><p>These two logics are not competing for the same destination. One sells &#8220;you have to buy this.&#8221; The other sells &#8220;you should want this.&#8221; One drives purchasing through fear, the other through curiosity. One measures its sales cycle in quarters, the other in days.</p><p>But they are forming an intersection: AI security. As enterprises deploy AI at scale, security questions inevitably become a prerequisite for AI procurement. At this intersection, the two logics meet for the first time, the trust credentials of security companies encounter the model capabilities of AI companies, the risk language of the CISO meets the efficiency language of the CTO.</p><p>This intersection is still small. But it is growing. Understanding the fundamental difference between these two business models is the prerequisite for understanding how that intersection will evolve.</p>]]></content:encoded></item><item><title><![CDATA[Co-Creation Over Consumption: The Openclaw-Harley Effect in AI Consumer industry]]></title><description><![CDATA[If you put Openclaw, Harley-Davidson, and today&#8217;s AI-powered consumer business side by side, a surprisingly clear pattern emerges: what really hooks people isn&#8217;t just buying a product, it&#8217;s participating in the process of making it their own.]]></description><link>https://wickey.substack.com/p/co-creation-over-consumption-openclaw-harley-effect-wickey-m0cjc</link><guid isPermaLink="false">https://wickey.substack.com/p/co-creation-over-consumption-openclaw-harley-effect-wickey-m0cjc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 18 Apr 2026 19:43:36 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/750a8159-b022-4f81-b587-a2ff9f0fb727_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9eKc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9eKc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9eKc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9eKc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9eKc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4b71d-1d03-43b0-b495-05cb44d66bd6_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>If you put Openclaw, Harley-Davidson, and today&#8217;s AI-powered consumer business side by side, a surprisingly clear pattern emerges: what really hooks people isn&#8217;t just <em>buying a product</em>, it&#8217;s <em>participating in the process of making it their own</em>.</p><p><strong>Let&#8217;s start with the most intuitive point: these things don&#8217;t end at purchase, they begin there.</strong> Very few Harley owners keep their bikes stock. They swap exhausts, repaint, tweak seats,sometimes even tune the sound until it feels &#8220;just right.&#8221; Openclaw works the same way: if you don&#8217;t touch it, it&#8217;s only half alive. Once you start modifying it, it becomes yours.</p><p>AI retail is now bringing this dynamic into everyday life. Imagine buying clothes where you don&#8217;t just pick a size, you tweak the fit, colors, and style with AI. Or furniture that adapts to your space. Or skincare generated around your personal data. You&#8217;re no longer selecting products, you&#8217;re <em>co-creating</em> them.</p><p>And that shift matters: the moment people invest time and decisions, they form emotional attachment. Engagement stops being transactional and becomes personal.</p><p><strong>Second, these aren&#8217;t driven by ads, they&#8217;re driven by people.</strong> The iconic Harley image isn&#8217;t a bike in a showroom, it&#8217;s a group riding together down an open road. That&#8217;s not just a product; it&#8217;s a culture: freedom, exploration, self-determination. Openclaw, if it has a community, follows the same pattern. People share how they tweak, build, and improve things. A product becomes a shared playground.</p><p>AI retail amplifies this even further. Instead of static product pages, you get streams of user creations,outfits people designed, spaces they styled, templates they share. Suddenly, discovery comes from <em>other users</em>, not the brand. At that point, the brand&#8217;s role shifts,from creator to enabler. What really drives adoption is seeing something and thinking: &#8220;That&#8217;s cool,I want to make my own version.&#8221;</p><p><strong>Third, and this is the addictive part, the final result feels like you.</strong> A customized Harley is basically a reflection of its owner. The same goes for anything shaped through Openclaw. AI makes this scalable. It can generate outcomes based on your taste, habits, even lifestyle. For example:</p><ul><li><p>A wardrobe that evolves based on what you actually wear</p></li><li><p>Home designs that adapt to your space and aesthetic</p></li><li><p>Gifts generated specifically for one person</p></li></ul><p>When you see the result, the reaction is immediate: <em>&#8220;This is so me.&#8221;</em></p><p>That feeling creates two powerful effects: deep satisfaction and a strong urge to share. People post it, talk about it, recommend it, not because they&#8217;re told to, but because they&#8217;re proud of it. That&#8217;s organic, user-driven virality at its purest.</p><p><strong>That said, a quick reality check:</strong> Not every product should work this way. If something&#8217;s core value is speed, convenience, or low cost, adding participation can feel like friction. This model works best for categories tied to identity and self-expression, fashion, lifestyle, creative tools, and anything people want to personalize.</p><p><strong>So in simple terms:</strong> What Openclaw, Harley, and AI consumer all get right is this, they don&#8217;t try to deliver a perfectly finished product. They deliberately leave space for you to step in. Because once you do, it&#8217;s no longer just something you bought. It becomes something you helped create.</p><p>This isn&#8217;t just a product design shift. It&#8217;s a distribution and retention model. The companies that win in AI consumer won&#8217;t be the ones with the best products. They&#8217;ll be the ones that turn users into creators.&#8221;</p>]]></content:encoded></item><item><title><![CDATA[Innovator Coffee Podcast EP-32 The Age of Agents: What RSAC 2026 Tells US About]]></title><description><![CDATA[40,000 attendees.]]></description><link>https://wickey.substack.com/p/innovator-coffee-podcast-ep-32-age-agents-what-rsac-wickey-hshdc</link><guid isPermaLink="false">https://wickey.substack.com/p/innovator-coffee-podcast-ep-32-age-agents-what-rsac-wickey-hshdc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Thu, 02 Apr 2026 07:49:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9a889c95-013e-4c05-acd3-b1bd381c5a63_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gTTk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gTTk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gTTk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gTTk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gTTk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eefad17-08c2-4e81-ae4b-cc74567aeb38_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>40,000 attendees. 600+ exhibitors. Nearly everyone talking about the same thing: AI Agents.</p><p>Forge Point Capital investor Jimmy Park and Wickey Wang, cybersecurity and compliance management who also focuses on ecosystem insights and innovation support on AI and cybersecurity, just got back from the show floor, and sat down together for 50 minutes. A few core observations:</p><p><strong>RSA has changed.</strong> This no longer feels like a cybersecurity conference, it feels more like an AI conference with cybersecurity use cases. Companies that were selling LLM security last year have all pivoted to Agent security this year.</p><p><strong>Non-Human Identity is evolving.</strong> The conversation has moved from &#8220;how many non-human identities do I have&#8221; to active remediation, Key Rotation, Just-in-Time Access. Okta and Microsoft are entering the space, while startups race to own the remediation layer.</p><p><strong>AI SOC is everywhere.</strong> Over 60 companies are pushing the same label. But the real signal is this: large enterprises are starting to actually deploy, not just demo.</p><p><strong>Vibe Coding Security is a new category.</strong> Jimmy admitted it himself: &#8220;When I vibe code, I just auto-approve everything.&#8221; The problem is when that habit moves into enterprise production environments, the attack surface follows. AI-generated code has its own vulnerability patterns that traditional scanners can&#8217;t keep up with.</p><p><strong>Something new this year: You can find out more from the full version of this episode.</strong></p><p><strong>One quiet concern to end on.</strong> The ladder has been removed &#8212; AI is taking over junior-level work, but in three years, where do senior engineers come from? This isn&#8217;t just a security industry problem.</p><div id="youtube2-r08f5PhWmTk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;r08f5PhWmTk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/r08f5PhWmTk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Welcome to the Innovator Coffee, a podcast that bridges the gap between people and the world of AI and innovation. Follow us to explore the top AI products, ecosystem insights, and the emerging trends.</p><p><strong>About Innovator Coffee</strong></p><p>Innovator Coffee is a podcast created with a simple intention: to go beyond surface-level conversations on the latest AI products, ecosystem insights and emerging trends. Each episode brings together top minds and real insightful innovators/operators to unpack not just what they are building, but how they think, what they prioritize, where they struggle, and how they navigate uncertainty. The show is designed for people who are not just watching the AI wave, but actively shaping it.</p><p><strong>What Makes It Different</strong></p><p>Most AI conversations fall into two extremes: highly technical discussions that lack business context, or high-level narratives that miss the underlying reality. Innovator Coffee lives in the middle. The result is a deeper understanding of how AI actually impact the tech and business world.</p><p><strong>Scale &amp; Reach</strong></p><p>Innovator Coffee has published over 30 episodes, featuring more than 40 guests across the boarder AI ecosystem. The podcast continues to grow organically through high-signal conversations and strong network effects within the AI and multiple layers of the communities.</p><p><strong>Collaboration</strong></p><p>Innovator Coffee the podcast is open to conversations, helpers and high quality guest recommendations that contribute meaningful insights to the AI ecosystem. Please DM me if you have any questions.</p>]]></content:encoded></item><item><title><![CDATA[Transitive Trust]]></title><description><![CDATA[A few weeks ago, a supply chain attack quietly unfolded in a place that almost every security team would consider trustworthy.]]></description><link>https://wickey.substack.com/p/transitive-trust-wickey-wang-cisa-six-sigma-green-belt-iabkc</link><guid isPermaLink="false">https://wickey.substack.com/p/transitive-trust-wickey-wang-cisa-six-sigma-green-belt-iabkc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Thu, 02 Apr 2026 03:17:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e3514637-79a5-48fd-8015-7fd279ee8973_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6nVS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6nVS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6nVS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6nVS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6nVS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74a85898-42ea-4c1d-abb7-0cc2e305bf0c_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p>A few weeks ago, a supply chain attack quietly unfolded in a place that almost every security team would consider trustworthy. The attackers did not target production systems directly, nor did they breach databases.</p>]]></content:encoded></item><item><title><![CDATA[The New Security Problem Nobody Saw Coming: AI Agent Security]]></title><description><![CDATA[Most security teams are still thinking about AI the old way, as a chatbot you type questions into and get answers back.]]></description><link>https://wickey.substack.com/p/new-security-problem-nobody-saw-coming-ai-agent-wickey-jqhqc</link><guid isPermaLink="false">https://wickey.substack.com/p/new-security-problem-nobody-saw-coming-ai-agent-wickey-jqhqc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 22 Mar 2026 23:00:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/36979501-dc3a-4d08-9091-98996c7e6c9f_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wuKh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wuKh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wuKh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wuKh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wuKh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8186dc-0160-46b3-bd02-e6df80cc1a97_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Most security teams are still thinking about AI the old way, as a chatbot you type questions into and get answers back. That model is rapidly becoming irrelevant.</p><p>Today&#8217;s AI systems don&#8217;t just generate text. They call your APIs, access your SaaS apps, modify your databases, and trigger real-world actions, autonomously, at machine speed, across every system they&#8217;re connected to. The moment an AI agent can <em>act</em>, the entire security equation changes.</p><p>In the past several months, I collaborated with some friends in SafenAI, reviewing 75+ startups, shortlisting 50, and conducting 30+ direct conversations with founders building in this space. What follows is what we found.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mOGd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mOGd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 424w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 848w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 1272w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mOGd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png" width="1456" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!mOGd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 424w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 848w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 1272w, https://substackcdn.com/image/fetch/$s_!mOGd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe352f147-8c3f-4961-9133-b39b8bd17239_1488x839.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><h3><strong>What Is AI Agent Security?</strong></h3><p>Think of a traditional AI assistant like a consultant locked in a room, they can read documents and give you advice, but they can&#8217;t actually do anything without you physically carrying out each step. An AI agent is more like handing that consultant a full set of keys to your office, your systems, and your vendors, and telling them to get the job done.</p><p>That&#8217;s enormously powerful. It&#8217;s also a fundamentally different threat surface.</p><p>When an AI agent is compromised, it doesn&#8217;t just say something harmful, it <em>does</em> something harmful. It can silently exfiltrate data over months. It can execute fund transfers. It can spread across connected systems before any human notices. These attacks have already happened:</p><ul><li><p>A <strong>healthcare AI agent</strong> silently leaked patient data for <strong>3 months</strong> before discovery &#8212; $14M in losses.</p></li><li><p><strong>EchoLeak (CVE-2025-32711)</strong> achieved zero-interaction data exfiltration. No user action needed.</p></li><li><p>A <strong>nation-state attack on Anthropic</strong> completed its entire kill chain before human detection was even possible.</p></li></ul><p>This is not a theoretical risk. It&#8217;s happening now.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MkF8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MkF8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 424w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 848w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 1272w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MkF8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png" width="1456" height="824" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:824,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!MkF8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 424w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 848w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 1272w, https://substackcdn.com/image/fetch/$s_!MkF8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3f677e-1726-4b93-bc53-c0ca63a82d4c_1488x842.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><h3><strong>The Landscape: 50 Companies, 4 Categories</strong></h3><p>We mapped the emerging AI agent security market into four primary categories, each addressing a distinct layer of the problem.</p><h3><strong>1. Discovery &amp; Security Posture Management (12 companies)</strong></h3><p><em>OptimusLabs, Evoke Security, Akto, Zenity, Oryo, Nokod Security, Noma Security, MCPTotal, Helmet, Onyx Security, Geordie AI, Obot</em></p><p><strong>The core question:</strong> What agents are actually running in your environment, and what are they doing?</p><p>Most organizations have no idea how many AI agents are deployed across their teams. Shadow agents, built by developers or business units without formal security review, are already common. This category gives CISOs the visibility they need before they can do anything else. It consistently wins the first enterprise budget in AI security.</p><h3><strong>2. Identity &amp; Access Management (10 companies)</strong></h3><p><em><strong><a href="http://arcade.dev/">Arcade.dev</a></strong>, Descope, Natoma, Keycard, Pomerium, WorkOS, Identity Machines, DeepTrail, Sonoma, Opti AI</em></p><p><strong>The core question:</strong> When an agent acts on behalf of a user, how do you ensure it only has access to what it actually needs?</p><p>Human IAM has been a solved problem for decades. Agent IAM is brand new. Agents need delegated identities, scoped tokens that expire, just-in-time access provisioning, and the ability to revoke permissions mid-task. None of the traditional IAM playbooks transfer directly.</p><h3><strong>3. Runtime Security (18 companies)</strong></h3><p><em>Runlayer, Aira Security, ZenGuard, Operant AI, Vijil, Straiker, Giskard, Adversa AI, Pillar Security, Virtue AI, Tenet Security, Skyrelis, Aiceberg, Gopher Security, PromptArmor, Fortifai, CodeIntegrity, Xyra Security</em></p><p><strong>The core question:</strong> Can you detect and stop a dangerous action before it executes?</p><p>This is the most active area of the market, 18 companies, the largest category. The critical differentiator is whether a vendor can <em>block</em> a harmful action in real time, or only <em>observe and alert</em> after the fact. Vendors with enforcement capability (not just monitoring) are building the most defensible positions.</p><h3><strong>4. Governance &amp; Audit (10 companies)</strong></h3><p><em>Barndoor AI, EqtyLab, WitnessAI, SurePath AI, Liminal AI, MintMCP, Lumia Security, Beltic, Lunar Dev, Eve Security</em></p><p><strong>The core question:</strong> When something goes wrong, can you prove what happened, why, and who authorized it?</p><p>Regulatory pressure is real and accelerating. The EU AI Act, California&#8217;s 2026 behavioral compliance requirements, and board-level risk mandates in regulated industries are creating budget line items for agent governance that didn&#8217;t exist 18 months ago.</p><h3><strong>3 Insights From the Data</strong></h3><h3><strong>Insight 1: Runtime is the moat&#65292;but only if you can block, not just watch</strong></h3><p>With 27 of 50 companies covering runtime protection in some form, it&#8217;s the most contested layer. But there&#8217;s a sharp divide: companies that can intercept and block a dangerous action <em>before</em> it executes versus those that can only log and alert after.</p><p>This distinction matters enormously. An agent that deletes a database or transfers funds does the damage in milliseconds. Alerting after the fact is nearly useless. Watch this gap widen over the next 12 months.</p><h3><strong>Insight 2: Visibility wins first, but it won&#8217;t win forever</strong></h3><p>Discovery &amp; SPM is where enterprise needed to start. CISOs have a simple rule: you can&#8217;t secure what you can&#8217;t see. Knowing what agents exist, what tools they can access, and what they&#8217;ve been doing is the obvious first purchase.</p><p>But visibility is also the most commoditizable layer. Once the market matures, discovery features will get bundled into broader platforms, and standalone SPM vendors will face pressure. The smart ones are already extending into enforcement. Personally, I feel that governance will be the budgeting area while you cannot start without discovery.</p><h3><strong>Insight 3: Agent attacks are designed to be invisible</strong></h3><p>Agent attacks are designed to be invisible. They operate silently over weeks or months, completing their objectives before any human ever sees a flag. The healthcare breach mentioned above ran for a full quarter undetected. The companies being attacked right now mostly don&#8217;t know it yet. By the time detection capability improves, the damage is already done.</p><h3><strong>What&#8217;s Next</strong></h3><p>This blog is a preview. We are releasing a full research report covering:</p><ul><li><p>Detailed company profiles and capability breakdowns across all 50 companies</p></li><li><p>The complete lifecycle coverage matrix (how each company maps to Design, Build, Runtime, and Governance stages)</p></li><li><p>Framework mapping to NIST CAISI, OWASP Top 10 for Agents, and MAESTRO</p></li><li><p>Other analysis of this market and some insights</p></li></ul><p>To get notified when it drops, follow my newsletter or us at <strong><a href="http://luma.com/Safenai">luma.com/Safenai</a></strong>.</p><p><em>SafenAI is a lightweight industry research and collaboration initiative focused on AI infrastructure governance, enterprise AI operational risk, AI progress and AI-era security challenges.<br> <br>Collaborate with security leaders, operators, founders, and researchers on governance frameworks, infrastructure risk discussions, AI operational trust, and enterprise AI adoption considerations through research, events, and educational initiatives.</em></p>]]></content:encoded></item><item><title><![CDATA[What first time Founders Get Wrong and Get Right]]></title><description><![CDATA[What I Learned Judging the First Pitch Competition at Santa Clara University]]></description><link>https://wickey.substack.com/p/what-first-time-founders-get-wrong-right-wickey-ucfrc</link><guid isPermaLink="false">https://wickey.substack.com/p/what-first-time-founders-get-wrong-right-wickey-ucfrc</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 14 Mar 2026 05:37:23 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ecf6639f-b9ad-4091-a64a-44f7034793e4_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!glAs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!glAs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!glAs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!glAs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!glAs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!glAs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!glAs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!glAs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!glAs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!glAs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14b15a98-6826-4b29-9daa-0bff85047454_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>What I Learned Judging the First Pitch Competition at Santa Clara University</strong></p><p>Last week I had the privilege of serving as a judge at SCU INFORMS&#8217; first-ever pitchathon at Santa Clara University. Watching student teams take the stage with their ideas, many of them for the very first time, reminded me why I believe so strongly in Silicon Valley innovation ecosystem, where early-stage innovation gets real feedback, not just applause.</p><p>Here are two things I took away: the patterns I saw holding teams back, and the four teams that stood out of 13 (18 were selected.).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MoF2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MoF2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 424w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 848w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 1272w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MoF2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png" width="1456" height="820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abee2232-895a-409c-9474-f28f32da4e54_1488x838.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!MoF2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 424w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 848w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 1272w, https://substackcdn.com/image/fetch/$s_!MoF2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabee2232-895a-409c-9474-f28f32da4e54_1488x838.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p><strong>Three Mistakes I Kept Seeing</strong></p><p><strong>1. Start focused. Resist the urge to scale your idea before you&#8217;ve validated it.</strong></p><p>One team came up with a genuinely interesting solution on AI application, and then proceeded to apply it to five different industries starting with healthcare in the same pitch. I understand the instinct. It feels like a bigger market, a stronger case. But early-stage ideas need a sharp edge, not a wide net. Pick the one problem you understand best, go deep on it, and let focus become your competitive advantage.</p><p><strong>2. A nice-to-have is not a pain point.</strong></p><p>Several teams had clever ideas that I could imagine people appreciating, but others may want to talk to some people from their ideal customer profile group to confirm the real needs. The question that separates a real startup from an interesting concept is simple: <em>is this solving a pain that someone would actively seek out a solution for, even before you approached them?</em> If you have to convince people they have the problem, or make something they are not paying for, you&#8217;re building for the wrong problem.</p><p><strong>3. Know what already exists before you build.</strong></p><p>A few teams were solving problems that already have products on the market, sometimes very mature ones. This doesn&#8217;t automatically kill an idea, but it changes the pitch entirely. If you don&#8217;t know your competitive landscape, a judge will find it for you, and that&#8217;s not the moment you want to discover it.</p><p><strong>Four Teams That Caught My Eye</strong></p><p>&#129351; <strong>BlindSpot</strong> &#8212; <em>Nikhil Ranjit, Victor Joulin-Batejat, Nikash Shanbhag, Jemian Lam, Gavin Morris, Aveed Gorji</em> Clear problem, clear solution, and a team that clearly did their homework. They are doing a wearable technology by using AI to help blind people guide their way when they walk. Great idea and real needs even I saw the mature product on the market already.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Xax!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Xax!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 424w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 848w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 1272w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Xax!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!4Xax!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 424w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 848w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 1272w, https://substackcdn.com/image/fetch/$s_!4Xax!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cbbdd88-cb41-45e3-86f6-7635ab50929e_1488x992.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>&#129352; <strong>ElderShield AI</strong> &#8212; <em>Ali Parpia, Matthew Collins</em> The aging population is one of the most underleveraged areas in tech innovation. ElderShield helps elder by leveraging AI technology and the team clearly mentioned that this is the first step (AI-Powered Scam Simulation &amp; Training) to validate the market needs so I am looking forward to hear their next product.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BbQD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BbQD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 424w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 848w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 1272w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BbQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png" width="948" height="1422" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1422,&quot;width&quot;:948,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!BbQD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 424w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 848w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 1272w, https://substackcdn.com/image/fetch/$s_!BbQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ede85a-bb54-44fe-90bb-74e96b6ae902_948x1422.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>&#129353; <strong>Storybox</strong> &#8212; I can imagine <em>Stefan Bocanegra</em> becoming a good entrepreneur, he brainstormed the idea for a week, made the MVP including ESP32 firmware, a Python cloud API, a React web portal, and the hardware prototype within 2-3 days and has great storytelling skills. I had a good chat with him and noted that he is in tech major and currently helps a startup on engineer+sales role. StoryBox is a screen-free, AI-powered storytelling device for kids. A child taps their own RFID-tagged toy on the box and hears a personalized adventure narrated with unique character voices, no screen involved. StoryBox was awarded both 3rd Place and the Audience Choice Award.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dDtB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dDtB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 424w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 848w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 1272w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dDtB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!dDtB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 424w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 848w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 1272w, https://substackcdn.com/image/fetch/$s_!dDtB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81cf4f52-b8c5-467d-ae25-e07740c13d22_1488x993.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>&#127894;&#65039; <strong>Savebox (Honorable Mention)</strong> &#8212; <em>Tianbao Yang, Zhaotong Wang</em> A team I didn&#8217;t want to leave without recognizing. I personally like this one because it solves the energy saving problem by helping household identify the electricity saving by using small device and AI. The team also made Hack for Humanity 2026 1st Place Winner and was recognized by AMD. They also mentioned the big price down compared to the current product on the market.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o6Bj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o6Bj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 424w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 848w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o6Bj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png" width="1019" height="1000" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1000,&quot;width&quot;:1019,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!o6Bj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 424w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 848w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!o6Bj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd8a41a-20c2-4a08-882c-d47b5f9c7784_1019x1000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CJPi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CJPi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 424w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 848w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 1272w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CJPi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!CJPi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 424w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 848w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 1272w, https://substackcdn.com/image/fetch/$s_!CJPi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff83a2e98-7b3b-4045-a8fc-2ae8dda39929_1488x994.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p><strong>To Every Team That Took the Stage</strong></p><p>The three mistakes I listed above? Every experienced founder has made all of them. The difference is that you&#8217;re learning them now, in a room full of people who want you to succeed, instead of after you&#8217;ve spent two years and your savings on the wrong version of your idea.</p><p>Pitching is hard. Standing up and saying <em>I believe in this, and I&#8217;m willing to defend it</em> is an act of courage that most people never attempt. Every single team that walked onto that stage last week was already winning at the thing that matters most: the willingness to try.</p>]]></content:encoded></item><item><title><![CDATA[AI: Bubble or Backbone?]]></title><description><![CDATA[During a recent field trip as a mentor with SantaClaraUniversity SCUCioccaCenter at the StartupWorldCup, discussions around AI overheating were prevalent in both VC and media panels.]]></description><link>https://wickey.substack.com/p/ai-bubble-or-backbone</link><guid isPermaLink="false">https://wickey.substack.com/p/ai-bubble-or-backbone</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 09 Nov 2025 06:48:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s0xb!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c613d43-fd41-4bdb-bb7b-a5ca0e1b1aac_590x590.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>During a recent field trip as a mentor with <a href="https://www.linkedin.com/search/results/all/?keywords=%23santaclarauniversity&amp;origin=HASH_TAG_FROM_FEED">SantaClaraUniversity</a> <a href="https://www.linkedin.com/search/results/all/?keywords=%23scucioccacenter&amp;origin=HASH_TAG_FROM_FEED">SCUCioccaCenter</a> at the <a href="https://www.linkedin.com/search/results/all/?keywords=%23startupworldcup&amp;origin=HASH_TAG_FROM_FEED">StartupWorldCup</a>, discussions around <a href="https://www.linkedin.com/search/results/all/?keywords=%23ai&amp;origin=HASH_TAG_FROM_FEED">AI</a> overheating were prevalent in both VC and media panels. Some also have pointed out that the adoption of enterprise AI is slow and profits remain elusive, classic indicators of hype. However, a recent report from Coatue presents a compelling counter-narrative:<br><br>- The top 10 tech firms generate approximately $1 trillion in free cash flow before capital expenditures, indicating that AI infrastructure is being funded by private sector cash rather than government support or significant debt.<br>- Valuations appear more stable compared to the dot-com peak: the Nasdaq-100 forward P/E is projected at 28&#215; in 2025, contrasting with 89&#215; in 1999.<br>- Tangible productivity gains are already emerging outside the tech sector: logistics firm C.H. Robinson reported a 50% productivity improvement, while Rocket Mortgage achieved over $40 million in annual cost savings through AI.<br>- Rapid adoption is evident, with ChatGPT reaching 800 million users faster than many previous technologies.<br><br>This suggests that we may not be facing a bubble set to burst, but rather a significant infrastructure build-out akin to electrification, highways, or the internet.</p><p>If you ask my point of view:</p><ul><li><p>AI models may have rooms in finance, legal and healthcare vertical as ChatGPT gives up those areas.</p></li><li><p>AI Infrastructure has lots of needs but will take longer time to the return.</p></li><li><p>AI Application layers have adoption challenges and lots of bubbles while again cybersecurity, finance and healthcare are still good areas. I am very bull on workflow embedded applications in regulated industries, where general-purpose LLMs cannot go and where ROI, defensibility and adoption are strongest.<br></p><p>While risks remain-such as market concentration, margin debt, and execution gaps-the foundation for AI appears more robust than many hype-driven comparisons indicate. The positive part, just like Chris, CRO @Snowflake mentioned in a podcast, that a bubble doesn&#8217;t mean the tech has no value. After the .com crash, the internet companies that truely changed the world finally rose.</p></li></ul><p><br><br><a href="https://www.linkedin.com/search/results/all/?keywords=%23cybersecurity&amp;origin=HASH_TAG_FROM_FEED">Cybersecurity</a> is now a core pillar of this transformation: as AI systems scale, companies may be investing heavily in secure model deployment, data protection, and AI-driven threat detection, turning security from a cost center into a competitive advantage.</p><p></p>]]></content:encoded></item><item><title><![CDATA[The story of Figma]]></title><description><![CDATA[Figma&#8217;s stock made its debut on the New York Stock Exchange on Thursday, surging nearly threefold.]]></description><link>https://wickey.substack.com/p/the-story-of-figma</link><guid isPermaLink="false">https://wickey.substack.com/p/the-story-of-figma</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 23 Aug 2025 03:17:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s0xb!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c613d43-fd41-4bdb-bb7b-a5ca0e1b1aac_590x590.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Figma&#8217;s stock made its debut on the New York Stock Exchange on Thursday, surging nearly threefold. Just a day earlier, the design software company had priced its initial public offering (IPO) at $33 per share. After digging into its financials, it&#8217;s clear that this is a high-quality business: gross margins exceed 91%, monthly active users hit 13 million, it serves 95% of the Fortune 500, and it's posting approximately 46% quarter-over-quarter growth. No wonder the IPO was met with a frenzy.</p><p>The IPO also created significant windfalls for major investors:</p><ul><li><p><strong>Index Ventures:</strong> Led Figma's seed round in 2013 and owned a stake worth <strong>$7.2 billion</strong> after the IPO. This stake is part of the multibillion-dollar gains reaped by early VC firms.</p></li><li><p><strong>Greylock Partners:</strong> A key backer, saw its stake valued at <strong>$6.7 billion</strong> following the first day of trading.</p></li><li><p><strong>Kleiner Perkins:</strong> Invested early and held a stake worth approximately <strong>$6 billion</strong>after the IPO.</p></li><li><p><strong>Sequoia Capital:</strong> Led a funding round in 2019 and owned a stake worth <strong>$3.8 billion</strong>post-IPO.</p></li></ul><p>As such, I figured that it is worth of writing a short story of this company.</p><p>Figma&#8217;s story starts with a college dropout. In the spring of 2012, Dylan Field made a bold decision: he dropped out of Brown University and took a $100,000 Thiel Fellowship grant to &#8220;reimagine design tools.&#8221;</p><p>At the time, Adobe Photoshop still dominated the market. Sketch was just starting to attract a niche group of tech-savvy users. And Figma? It didn&#8217;t even have a product demo.</p><p>&#8220;We wanted to build a design tool that worked like Google Docs&#8212;for real-time collaboration,&#8221; the then 20-year-old Dylan envisioned. Thirteen years later, the company has not only delivered on that promise&#8212;it also made a spectacular Wall Street debut.</p><p>A startup once set to be acquired by Adobe for $20 billion, an acquisition that ultimately fell through, has now completed its journey to capitalization on its own terms.</p><p>Figma didn&#8217;t start in a gleaming high-rise in San Francisco. Its beginnings were in a browser window. Unlike most Silicon Valley startup legends, Figma didn&#8217;t explode overnight, it spent four years quietly perfecting its core technology, focused solely on achieving smooth graphical rendering in a web browser.</p><p>Initially, few believed designers would abandon native apps. But Figma made two correct bets:</p><ol><li><p>Design isn&#8217;t a solo act, it&#8217;s a language for team communication.</p></li><li><p>The future of software collaboration would naturally emerge in the cloud.</p></li></ol><p>These bets paid off massively in the post-COVID world. Remote work became the norm, and Figma became the go-to tool for design teams&#8212;and increasingly for product managers, developers, and even marketing teams.</p><p>By 2023, Figma had reached over 4 million design professionals worldwide. Its enterprise clients include tech giants like Google, Airbnb, Spotify, and Microsoft.</p><p>In 2022, Adobe announced its intent to acquire Figma for $20 billion-a record-setting deal in the design software space. The news caused an uproar. Some designers feared that Figma would &#8220;turn into the next Adobe XD.&#8221; Others saw the deal as the end of a design revolution.</p><p>Ultimately, due to regulatory and antitrust concerns, the acquisition was officially called off in early 2024.</p><p>For Figma, this could&#8217;ve been an exit, but instead, staying independent became a turning point. According to insiders, over the past 18 months, Figma achieved profitability, expanded its developer platform, launched AI-assisted design tools, and deepened enterprise integrations.</p><p>&#8220;We're no longer just a product, we&#8217;re a platform,&#8221; Dylan said during the IPO roadshow.</p><p>Design is no longer just a tool, it&#8217;s part of a platform strategy.</p><p>Figma&#8217;s IPO is more than just a success story for a startup, it signals a broader shift: design has moved from backstage to center stage. It is now a core productivity engine for companies.</p><p>In a world where AI-native tools like OpenAI, Notion, and Runway are on the rise, design language, prototyping speed, and collaboration efficiency have become critical factors in whether a product gets adopted and loved.</p><p>And Figma stands at the center of this ecosystem. Figma has now launched Dev Mode, bridging the gap between design and development. It is also collaborating with AI leaders like OpenAI to explore the frontier of &#8220;AI + design.&#8221;</p><p>This company is no longer just serving designers, it is reshaping the entire product development lifecycle.</p><p>The ringing of the Nasdaq bell is not the end of Figma&#8217;s story, it&#8217;s the start of a more complex chapter.</p><p>In a market still largely dominated by Adobe, can an independent, publicly listed Figma become something like Atlassian for engineering collaboration, or Snowflake for data, an &#8220;operating system-level&#8221; company?</p><p>That will take years to fully answer.</p>]]></content:encoded></item><item><title><![CDATA[The New AI Attack Surface: What MCP Means for Security Teams]]></title><description><![CDATA[Since last November, MCP has been widely discussed.]]></description><link>https://wickey.substack.com/p/the-new-ai-attack-surface-what-mcp</link><guid isPermaLink="false">https://wickey.substack.com/p/the-new-ai-attack-surface-what-mcp</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 03 Aug 2025 05:39:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XAXI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Since last November, MCP has been widely discussed. To understand its significance, LangChain even launched a poll on X (formerly Twitter): based on real-world use cases, comparisons with OpenAI Plugins, and MCP&#8217;s own limitations&#8212;do people think MCP is just a flash in the pan, or a future industry standard?</p><p>The results showed that 40.8% of respondents believe MCP is the future standard, 25.8% think it's merely a passing trend, and the remaining 33.4% chose to wait and see. These results indirectly reflect the importance MCP holds in the future development of AI. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>What exactly is Model Context Protocol (MCP)?</strong> </p><p>To understand MCP&#8217;s origin, we have to start with its creator, Anthropic, and the strategy behind it. As everyone knows, building large AI models in itself isn&#8217;t profitable&#8212;so companies working on foundation models have been actively exploring how to monetize. One of the more viable paths is to build downstream AI agents or applications.</p><p>But how do you build powerful agents? The key challenge is that current AI models are limited by data silos, making it hard for them to access tools or external data. Without this capability, models can&#8217;t interact with data like traditional software does, preventing them from reaching their full potential.</p><p>Before MCP, integrating diverse data sources was extremely complex because every system had its own way of doing things. Developers had to do an enormous amount of integration work. With MCP, connecting AI to tools and data sources becomes almost effortless&#8212;like playing with Lego blocks.</p><p>That&#8217;s how MCP was born as a universal standard protocol. Its significance, in my view, is comparable to the invention of TCP/IP during the early internet era. It&#8217;s also been described as the &#8220;USB plug-and-play&#8221; for AI. With MCP, the spark of AI can now spread widely&#8212;accessing data, tools, and services to unlock real-world capabilities.</p><p>But what exactly does MCP stand for?</p><ul><li><p><strong>Model</strong>: the AI models we know, like GPT or Claude</p></li><li><p><strong>Context</strong>: the external information fed to those models</p></li><li><p><strong>Protocol</strong>: a universal standard for how that data is exchanged</p></li></ul><p>Together, they form a framework for what MCP is meant to do: standardize how AI models access context and connect with tools.</p><p><strong>Why it is important&#65311;</strong></p><p>I believe MCP and A2A are important because they unlock the potential for network effects among AI agents. Before these two protocols existed, each model had its own architecture, creating a heavy burden for developers and contributing to the siloed nature of AI systems. With MCP and A2A as the starting point of a new set of standardized protocols, connecting data and tools becomes much simpler and more streamlined&#8212;making the network effects increasingly visible.</p><p><strong>How tech part works&#65311;</strong></p><p>Each MCP service (also known as an MCP Server) is designed to focus on a specific task. It&#8217;s typically a locally run program, often written in Python. Large language models communicate with MCP Servers via standard input/output (stdio) channels using JSON-formatted data to exchange information and process commands.</p><p>Once the MCP Server receives a request, it executes the task using its own code or by calling external tool APIs. This is similar to the Function Calling capability you may know from various AI models&#8212;but MCP smartly unifies this process under a standardized protocol.</p><p><strong>How to use it?</strong></p><p>The best free class I see is the &#8220;MCP: Build Rich-Context AI Apps with Anthropic&#8221;&#12290;</p><p>This course provides a practical and strategic introduction to the Model Context Protocol (MCP), designed to help developers build rich-context AI applications. You'll learn how it simplifies tool and data integration for large language models, and how to build your own MCP-compatible tools. The course covers communication between models and MCP Servers, how to structure contextual inputs, and how MCP enables more capable AI agents by standardizing interactions. You'll also explore how MCP works alongside A2A (Agent-to-Agent) protocols to drive network effects and composability in agent ecosystems. Ideal for those building the next generation of intelligent, tool-augmented AI systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XAXI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XAXI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 424w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 848w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 1272w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XAXI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png" width="1202" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:210685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/169900791?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XAXI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 424w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 848w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 1272w, https://substackcdn.com/image/fetch/$s_!XAXI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda7d0674-6cc5-482c-8c26-8e8aa4d91052_1202x808.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I did two sessions of podcast for the first-hands experience of the real world AI Agent and MCP adoption. One is below and the other one related to the MIT project Nanda will be issued soon. If you are interested, please check the link below for more details:</p><p><a href="https://open.spotify.com/episode/4C6uiiy6crLug1zz8iyg92?si=sUt2ficOSI60LmbVktQz2w">Innovator Coffee PE-15</a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TCza!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TCza!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 424w, https://substackcdn.com/image/fetch/$s_!TCza!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 848w, https://substackcdn.com/image/fetch/$s_!TCza!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 1272w, https://substackcdn.com/image/fetch/$s_!TCza!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TCza!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png" width="1456" height="318" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:318,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80846,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/169900791?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TCza!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 424w, https://substackcdn.com/image/fetch/$s_!TCza!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 848w, https://substackcdn.com/image/fetch/$s_!TCza!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 1272w, https://substackcdn.com/image/fetch/$s_!TCza!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd344ef6-343e-4699-8832-fa03c12fcdcf_1576x344.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>How to Secure MCP?</strong></p><p>To secure MCP (Model Context Protocol), organizations must rethink and reinforce security across its lifecycle, which requires merging agent-level and API-level security&#8212;combining runtime context validation, identity-driven policy, and purpose-bound access. Organizations should treat MCP like a high-value identity-aware gateway, not just a passive middleware:</p><h5>1. Build Phase (Pre-deployment)</h5><ul><li><p>Risks: Shadow MCPs, untracked APIs, and supply chain threats via unverified services or third-party integrations.</p></li><li><p>Controls:</p><ul><li><p>API registration governance: enforce whitelisting, source validation.</p></li><li><p>MCP-specific API penetration testing: assess not just endpoints, but how services interact through MCP.</p></li><li><p>SBOM (Software Bill of Materials): track dependencies to identify hidden risks.</p></li></ul></li></ul><h5>2. Runtime Phase</h5><ul><li><p>Risks: Prompt injection, data leakage, over-privileged actions, unauthorized LLM access.</p></li><li><p>Controls:</p><ul><li><p>Fine-grained identity &amp; access control: enforce least privilege for both users and services.</p></li><li><p>Prompt hygiene: sanitize and validate context/prompt before LLM invocation.</p></li><li><p>Audit &amp; monitoring: real-time logging of context flows, data access, and agent-triggered actions.</p></li></ul></li></ul><h5>3. Identity &amp; Policy Enforcement</h5><ul><li><p>Risks: Weak identity modeling undermines trust in centralized MCP.</p></li><li><p>Controls:</p><ul><li><p>Establish strong identity federation for tools, users, and services within the MCP mesh.</p></li><li><p>Implement policy orchestration engines to handle conditional access, approval chains, and escalation logic.</p></li></ul></li></ul><h5>4. Delegated Action Safeguards</h5><ul><li><p>Risks: Actions initiated by LLMs through MCP can misuse SaaS APIs or critical systems.</p></li><li><p>Controls:</p><ul><li><p>Context-aware authorization: restrict actions based on intent, sensitivity, and data context.</p></li><li><p>Dry-run and runtime validation: pre-check agent-initiated actions before execution.</p></li><li><p>Quarantine modes: sandbox uncertain behaviors for review.</p></li></ul><p></p></li></ul><p><strong>What security tools in place to help out:</strong></p><p>Per research from Sixty Degree Capital, there are more than 20 startups pioneer to address the security risks in this area so far. </p><p>https://www.linkedin.com/pulse/demystifying-mcp-security-missing-layer-enterprise-ai-brett-afbdc/?trackingId=cf5F22CWjQR8oLlX7e%2Fb0w%3D%3D</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LDFE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LDFE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 424w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 848w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 1272w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LDFE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png" width="1324" height="734" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:734,&quot;width&quot;:1324,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:687206,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/169900791?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LDFE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 424w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 848w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 1272w, https://substackcdn.com/image/fetch/$s_!LDFE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1e93e57-609c-4f75-964a-21fad488ee6e_1324x734.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You can also find useful information from <strong><a href="https://hackerone.com/anthropic-vdp/policy_scopes?type=team">&#120276;&#120315;&#120321;&#120309;&#120319;&#120316;&#120317;&#120310;&#120304; &#120297;&#120322;&#120313;&#120315;&#120306;&#120319;&#120302;&#120303;&#120310;&#120313;&#120310;&#120321;&#120326; &#120279;&#120310;&#120320;&#120304;&#120313;&#120316;&#120320;&#120322;&#120319;&#120306; (&#120297;&#120279;&#120291;) &#120291;&#120319;&#120316;&#120308;&#120319;&#120302;&#120314;</a> and <a href="https://github.com/modelcontextprotocol/modelcontextprotocol/blob/ec1418927730e3ffeede8ea6475d6f4c36f6d10c/docs/specification/draft/basic/security_best_practices.mdx">MCP best practice</a>.</strong></p><p><strong>Conclusion</strong></p><p>As AI agents become more powerful and interconnected, protocols like MCP are quickly becoming foundational to the next phase of intelligent software. Whether you see it as a passing trend or the TCP/IP of the AI era, MCP is already reshaping how models interact with tools, data, and each other. But as with any foundational infrastructure, security must evolve in parallel. </p><p>From development pipelines to runtime safeguards, MCP opens up a new surface area that demands thoughtful governance, fine-grained access controls, and secure-by-design implementations. For builders, researchers, and security professionals alike, now is the time to engage&#8212;because the future of AI may very well be built on top of MCP.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Talent Wars Are Escalating - from Windsurf’s Split Deal to Meta’s Billion-Dollar Hiring]]></title><description><![CDATA[From Windsurf&#8217;s Split Deal to Meta&#8217;s Billion-Dollar Hiring Spree, Silicon Valley Enters the "Engineering Gold Rush", can cybersecurity industry encounter the similar?]]></description><link>https://wickey.substack.com/p/the-ai-talent-wars-are-escalating</link><guid isPermaLink="false">https://wickey.substack.com/p/the-ai-talent-wars-are-escalating</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 19 Jul 2025 01:31:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s0xb!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c613d43-fd41-4bdb-bb7b-a5ca0e1b1aac_590x590.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This summer, something shifted in Silicon Valley.</p><p>The headlines weren&#8217;t dominated by another record-breaking model or benchmark. This time, the spotlight is on people, more specifically, the rare breed of engineering teams that can train frontier models, build real platforms, and ship AI-native products.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>And the story starts with a startup you may not have heard of: Windsurf.</p><div><hr></div><h3>Windsurf&#8217;s Split-Deal Signals a New Acquisition Playbook</h3><p>Last week, Google DeepMind quietly announced that it had hired Windsurf&#8217;s CEO Varun Mohan, co-founder Douglas Chen, and most of the company&#8217;s core engineering team. Their mission? To accelerate development on Gemini and DeepMind&#8217;s AI code agents, tools that directly challenge OpenAI&#8217;s GPT&#8209;4o and Code Interpreter.</p><p>Days later, the <em>rest</em> of Windsurf, its product, infrastructure, customer base, IPs and remaining staff, was acquired by <strong>Cognition</strong>, the company behind Devin, the AI software engineer, and a fast-growing startup already hitting $82 million ARR.</p><p>Industry insiders didn&#8217;t see it as a breakdown but a calculated bifurcation.</p><ul><li><p>Google got the team, without the baggage of buying the shell.</p></li><li><p>Cognition got the product, IP, and strategic hires to bolster its devtool stack.</p></li><li><p>Windsurf&#8217;s leadership got top-tier roles, while ensuring the rest of the team landed well.</p></li><li><p>And OpenAI? They were reportedly in talks to acquire Windsurf&#8212;but got cut out of the deal.</p></li></ul><p>But this wasn&#8217;t just a win for the founders. It was the beginning of a new M&amp;A template in the AI world, one centered on teams, not companies.</p><div><hr></div><h3>Meta's High-Stakes Bet: "Buy the Engineers, Not the Models"</h3><p>While Windsurf was quietly split in two, another major play was unfolding behind the scenes.</p><p>Meta has reportedly been on a hiring spree, poaching more than 40 top AI engineers and researchers from Google DeepMind, OpenAI, and Scale AI. These aren&#8217;t junior hires, they&#8217;re veterans of model training, infrastructure, and productization.</p><p>And Meta&#8217;s offers? Nearly $10&#8211;12 million total comp, permission to build teams from scratch, direct access to the CTO, and, in some cases&#8212;guaranteed early-stage funding if they choose to spin out later.</p><p>This isn't just aggressive recruiting. It&#8217;s a war strategy.</p><p>Meta isn&#8217;t betting it can outpace GPT-4 in the lab. It&#8217;s betting it can build the best, most usable AI platforms faster, with nimble, startup-style teams inside the company.</p><div><hr></div><h3>Venture Capital Now Follows the Talent</h3><p>Behind this wave of movement, top-tier VCs are adapting just as fast.</p><ul><li><p>Founders Fund, a16z, Khosla, and Index have all reportedly offered soft commitments to teams inside Meta and Cognition, even before they launch a product or spin out.</p></li><li><p>Cognition&#8217;s deal to acquire Windsurf&#8217;s remaining assets took under 48 hours to get investor approval. The pitch wasn&#8217;t about IP, it was about developer distribution and execution speed.</p></li></ul><p>The logic is clear: capital follows teams, not ideas.<br>Especially when those teams are capable of building the next layer of the AI stack.</p><div><hr></div><h2>Trend Forecast: Engineering Speed Will Overtake Model Size</h2><p>We're now at a clear inflection point. AI's next competitive advantage won&#8217;t come from larger models, but from faster teams.  Yes, GPT&#8209;4o, Gemini 1.5, Claude 3 Opus, and LLaMA 3 are converging in raw capability. The performance gap is closing. But the real competition is shifting downstream:</p><ul><li><p>Who can productize models with minimal friction?</p></li><li><p>Who can win developer adoption with low-latency, no-prompt-needed workflows?</p></li><li><p>Who can ship weekly updates without breaking things?</p></li><li><p>Who can monetize without waiting for API paywalls?</p></li></ul><p>The answer lies not in parameters, but in the people and systems behind them.</p><div><hr></div><h2>The "AI Engineering Gold Rush" Has Just Begun</h2><p>From Windsurf&#8217;s split acquisition to Meta&#8217;s internal founder tracks, to VCs pre-betting on elite engineering leaders, Silicon Valley is sending a very clear signal:</p><ul><li><p>Model competition is giving way to ecosystem wars.</p></li><li><p>Engineering teams are the new strategic assets.</p></li><li><p>The future belongs to those who can integrate models, infra, tools, and workflows, fast.</p></li></ul><p>In other words, AI's next chapter won&#8217;t be written by the biggest GPU clusters.  It will be written by the teams that can run faster, hire smarter, and build the tools that developers can&#8217;t live without.</p><h2>Can Cybersecurity face the similar M&amp;A model?</h2><p>Just as AI is shifting from model size to engineering velocity, cybersecurity is poised for a similar evolution, from tool stacks to talent stacks. We&#8217;re entering a phase where top-tier security engineers are recruited not just to detect threats, but to architect internal systems, lead red teams, or spin out new ventures from within Big Tech. Startups may have a similar chance to be split in acquisition deals: one buyer takes the platform and IP, another takes the talent to embed into internal security efforts. </p><p><strong>P.S: Something not relevant but I want to record here:</strong> </p><p>Recently, leveraging AI Vibe Code, I developed a small lean Python automation solution. This automation slashed hours of repetitive file handling down to just 5 minutes, showcasing the tangible impact of applied AI on operational efficiency.<br><br>Effective leadership in AI isn't just about embracing the technology; it's about strategically implementing it where it can truly make a difference, in the processes that consume time without adding significant value. This practical effort of AI isn't a lofty goal but a direct response to genuine operational challenges, resulting in concrete efficiency gains.<br><br>For those delving into AI's potential to streamline team workflows, focusing on the daily pain points can yield substantial returns. Addressing these friction areas directly translates into measurable improvements, highlighting the compelling ROI of integrating AI technologies.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Cybersecurity Frontier: 100 Emerging Startups to Watch (2021–2024)]]></title><description><![CDATA[As the cyber threat landscape intensifies and generative AI reshapes both offense and defense, a new generation of cybersecurity startups has emerged to meet the moment.]]></description><link>https://wickey.substack.com/p/the-ai-cybersecurity-frontier-100</link><guid isPermaLink="false">https://wickey.substack.com/p/the-ai-cybersecurity-frontier-100</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sat, 07 Jun 2025 03:46:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PBP4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>As the cyber threat landscape intensifies and generative AI reshapes both offense and defense, a new generation of cybersecurity startups has emerged to meet the moment. The latest market map my friends and I did early this year highlights <strong>100 pre-Seed to Series B AI-related cybersecurity startups</strong> founded between <strong>2021 and 2024</strong>, showcasing how AI is transforming every subdomain of security&#8212;from cloud to compliance, from identity to LLM protection.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PBP4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PBP4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 424w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 848w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 1272w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PBP4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png" width="1456" height="903" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39c5e239-e48b-4016-a394-52482f9be829_1512x938.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:903,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:951953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/164454213?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PBP4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 424w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 848w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 1272w, https://substackcdn.com/image/fetch/$s_!PBP4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c5e239-e48b-4016-a394-52482f9be829_1512x938.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Key Observations</h3><h4>1. <strong>GenAI Governance &amp; Compliance Is Gaining Ground</strong></h4><p>With AI governance, model risk, and regulatory exposure (e.g., EU AI Act, NIST AI RMF) rising, this is a breakout category. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4>2. <strong>Cloud-Native Security Continues Its Expansion</strong></h4><p>Categories like <strong>Application Security</strong>, <strong>Software Supply Chain</strong>, and <strong>Threat Detection</strong> remain red hot&#8212;thanks to generative AI&#8217;s ability to both find and exploit vulnerabilities faster than ever. </p><h4>3. <strong>LLM Security and Privacy Is the New Gold Rush</strong></h4><p>Dozens of startups are springing up around <strong>LLM privacy, prompt injection protection, and secure AI agent deployment</strong>. </p><h4>4. <strong>Deepfake &amp; Synthetic Media Detection Is Rising as a Standalone Sector</strong></h4><p>With the explosion of misinformation, voice cloning, and identity manipulation, startups are taking on the deepfake threat using AI-forensics. Expect these tools to be vital in fraud prevention, elections, and media integrity.</p><h4>5. <strong>IAM Is Getting Smarter, Not Just More Secure</strong></h4><p>Identity and access management startups are applying AI to enhance behavior analytics, policy enforcement, and insider threat detection. </p><div><hr></div><h3>What This Map Signals to CISOs, Builders, and Investors</h3><ul><li><p><strong>CISOs</strong>: The security stack of the future will be <em>context-aware</em>, <em>AI-native</em>, and <em>board-ready</em>. Expect more point solutions to consolidate or integrate via APIs and marketplaces (e.g., Wiz, CrowdStrike, SentinelOne).</p></li><li><p><strong>Founders</strong>: Product-led growth, deep vertical knowledge, multi-modal AI, and clear ROI will win in this crowded market. Security buyers are overwhelmed&#8212;your value must be clear in the first 30 seconds.</p></li><li><p><strong>Investors</strong>: The next Wiz or SentinelOne is likely among these logos. Sectors like GenAI governance, LLM security, and data privacy are still early. Look for signs of enterprise traction, co-sell with hyperscalers, and modularity.</p></li></ul><div><hr></div><p><strong>Security isn&#8217;t a moat anymore&#8212;it&#8217;s a mandate. And AI is the new perimeter.</strong></p><p>&#128204; What other categories are we missing? Know a company that&#8217;s missing? Who are your top emerging picks in AI + security? If you find this useful, please tell your friends and network. Let&#8217;s continue the conversation. </p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Inside RSA: Insights and Observations from Two Intense Days - AI is everywhere]]></title><description><![CDATA[My take aways of 2025 one of the biggest cybersecurity conference]]></description><link>https://wickey.substack.com/p/inside-rsa-insights-and-observations</link><guid isPermaLink="false">https://wickey.substack.com/p/inside-rsa-insights-and-observations</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 04 May 2025 19:31:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c613d43-fd41-4bdb-bb7b-a5ca0e1b1aac_590x590.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p>Last week, RSA happened in Moscone Center, San Francisco, California on April 28-May 1, 2025. Two days&#8217; RSAC experience for me was great! I met so many great people and up industry insights. Below are some of my take aways:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol start="0"><li><p><strong>What is RSAC</strong></p></li></ol><p>For people who are not familiar with RSAC: The RSA Conference is <strong>a major global cybersecurity conference where professionals gather to learn, network, and explore the latest security technologies and trends</strong>.  On average, 45,000 people attend the conference each year. In 2025, it featured 450+ sessions, 730+ speakers, and 650+ exhibitors.<br><br><strong>1. The tech side of <a href="https://www.linkedin.com/search/results/all/?keywords=%23rsa&amp;origin=HASH_TAG_FROM_FEED">#RSA</a> is buzzing with AI innovations this year.</strong></p><p>According to the 2025 RSAC official info, as recently as 2023, AI-related submissions only accounted for about 5% of the talks people wanted to deliver at RSA Conference. When the RSAC 2025 Conference Call for Submissions opened, of the more than 2,800 proposals, over 40% referenced AI and its companion topics of machine learning and agents.<br><br>&#127793; Among the 10 <a href="https://www.linkedin.com/search/results/all/?keywords=%23sandboxinnovation&amp;origin=HASH_TAG_FROM_FEED">#SandboxInnovation</a> finalists, AI plays a pivotal role, from identity management to virtual workforce solutions and vulnerability assessments, even delving into red teaming strategies.<br><br>&#129716; CISOs and tech experts from industry giants like <a href="https://www.linkedin.com/search/results/all/?keywords=%23openai&amp;origin=HASH_TAG_FROM_FEED">#OpenAI</a>, <a href="https://www.linkedin.com/search/results/all/?keywords=%23meta&amp;origin=HASH_TAG_FROM_FEED">#Meta</a>, and <a href="https://www.linkedin.com/search/results/all/?keywords=%23anthropic&amp;origin=HASH_TAG_FROM_FEED">#Anthropic</a> showcased their internal security applications, spanning blue teaming operations, supply chain security enhancements, automated ticket queues, code reviews, and streamlined questionnaire processes. The evolution of tool functionalities, data integrations via protocols like <a href="https://www.linkedin.com/search/results/all/?keywords=%23mcp&amp;origin=HASH_TAG_FROM_FEED">#MCP</a> and <a href="https://www.linkedin.com/search/results/all/?keywords=%23a2a&amp;origin=HASH_TAG_FROM_FEED">#A2A</a>, and the continuous enhancement of self-reflective prompt generation are paving the way for a surge in diverse AI applications.<br><br>&#127806; This year witnessed major corporations unveiling new AI-driven products and features at the conference. Simultaneously, established startups are broadening their offerings to tackle emerging AI-related challenges and prospects. For instance, event management tools now leverage AI coding capabilities downstream to streamline code composition and rectification processes, while email security firms are venturing into deepfake detection based on their data sources.<br><br>Innovations across various sectors aim to enhance customer efficiency, provide transparency, and save time. Despite the focus on specific verticals, the emphasis remains on enhancing operational efficiency and risk management in alignment with security and compliance standards.<br><br>&#128161; The tech landscape underscores the significance of AI as a business enabler, emphasizing risk management and compliance adherence, while also highlighting the need for tailored solutions aligned with diverse business requisites.</p><ol start="2"><li><p><strong>The product trends: Platform vs address the niche pain with innovation</strong></p></li></ol><p>Although the industry has reached an annual market size of $140 billion, no single vendor holds more than 1.5% market share (roughly equivalent to $2 billion in revenue). The main reasons for this fragmentation include several different elements, (I may write the other article about it.) such as organization&#8217;s security requirements, compliance requirements in different industries and regions and decentralized purchasing process etc.</p><p>While multiple consolidations through M&amp;A and partnerships happened at the Q1&#8217;2025, we still see majority security companies address the niche pain at the expo for the major security processes such as event management to incident response, IAM, Application Security, Compliance etc vs a few &#8220;platformized&#8221; products such as Palo Alto&#12289;Microsoft&#12289;Cisco and maybe Wiz etc. </p><p>The top four startups really address the niche pains with innovation mindsets during my expo observation (purely the observer standpoint and no affiliation) are below:</p><p><strong>Mesh security: </strong>They are doing cross domain data collection from different security points and add a layer on top of everything to get the full context, visibility and control via CSMA Platform.</p><p><strong>Panther:</strong> &#8220;Next-gen&#8221; SIEMs which just embedded AI capabilities to auto coding and make the automated follow up analysis steps transparent.</p><p><strong>Border: </strong>The world&#8217;s first application aware VPN (VPN with PAM and etc)</p><p><strong>Axoflow: </strong>provides an end-to-end pipeline automating the collection, management and ingestion of security data. The data transformation happens in the pipeline, resulting in data that is immediately actionable.</p><p>There are a few non-human identity companies, AI-agents to fix the unknown threats and cloud run-time also impressed me as well. </p><ol start="3"><li><p><strong>Marketing at RSA is insanely competitive:</strong></p></li></ol><p>One of the coolest parts of cybersecurity conferences is how companies turn something typically dry and technical into pure fun for the sake of marketing. Every time I attend, it feels like stepping into an amusement park for grown-ups.</p><ul><li><p>If your company hands out swag bags that people can carry around the venue, <em>I&#8217;ll make mine twice as big so they dominate the floor.</em></p></li><li><p>If you&#8217;re passing out flyers or buying out lunch spots, <em>I&#8217;ll station a team at the main lunch route giving out brochures with Starbucks gift cards inside.</em></p></li><li><p>If you're hanging banners and sticking ads everywhere, <em>I'll bring a decked-out car and park it in the busiest spot for foot traffic.</em></p></li><li><p>And that's not even counting the eye masks, hats, bags, snacks, drinks, games, signed books, and magic show raffles &#8212; all branded to perfection. &#128518;<br>This year? We saw a mini petting zoo and even a puppy playground. &#128518;</p><p>This year&#8217;s biggest raffle prize? A <strong>Mini Cooper</strong>.</p><p>And of course &#8212; no shortage of this year&#8217;s trend: AI-generated photo booths.</p></li></ul><p>Overall, everyone&#8217;s trying to stand out while the products with innovation and address the daily pain stay in my brain.</p><ol start="4"><li><p><strong>Last but not least: the people connections are the best</strong></p></li></ol><p>In cybersecurity, technology, processes, and people all play critical roles. During conference week, I finally met several friends I had only known through online conversations. In person, they were just as sharp, insightful, and fun as expected &#8212; and our shared discussions uncovered even more common ground than I imagined.</p><p><strong>The End:</strong></p><p>As the conference came to a close, I walked away not just with new insights into the evolving threat landscape and cutting-edge technologies, but with deeper connections and renewed energy for the work ahead. RSA is a reminder that cybersecurity is not just about tools and frameworks &#8212; it&#8217;s about a global community solving complex problems together. I'm already looking forward to the next opportunity to learn, share, and grow with this vibrant ecosystem. </p><p>#ai #cybersecurity #auditing #compliance #emergingtech #startup #corporate #venturecapital<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Behind the Scenes: Pitch Judging in the Heart of Tech at Silicon Valley]]></title><description><![CDATA[Judge at an accelerator's Idea Lab startup pitch event hosted by #SantaClaraUniversityBroncoVentureAccelerator]]></description><link>https://wickey.substack.com/p/behind-the-scenes-pitch-judging-in</link><guid isPermaLink="false">https://wickey.substack.com/p/behind-the-scenes-pitch-judging-in</guid><dc:creator><![CDATA[Wickey Wang]]></dc:creator><pubDate>Sun, 04 May 2025 17:58:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Asjv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>As a third-year <a href="https://www.linkedin.com/search/results/all/?keywords=%23mentor&amp;origin=HASH_TAG_FROM_FEED">#mentor</a> at Santa Clara University, this weekend, I had the privilege of serving as a judge at an accelerator's Idea Lab startup pitch event hosted by <a href="https://www.linkedin.com/search/results/all/?keywords=%23santaclarauniversitybroncoventureaccelerator&amp;origin=HASH_TAG_FROM_FEED">#SantaClaraUniversityBroncoVentureAccelerator</a>. The event showcased numerous intriguing projects, with several focusing on <a href="https://www.linkedin.com/search/results/all/?keywords=%23ai&amp;origin=HASH_TAG_FROM_FEED">#AI</a> and with <a href="https://www.linkedin.com/search/results/all/?keywords=%23cybersecurity&amp;origin=HASH_TAG_FROM_FEED">#cybersecurity</a> and <a href="https://www.linkedin.com/search/results/all/?keywords=%23compliance&amp;origin=HASH_TAG_FROM_FEED">#compliance</a> elements.<br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Asjv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Asjv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 424w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 848w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 1272w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Asjv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png" width="1118" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1118,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:876693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/162831481?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Asjv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 424w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 848w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 1272w, https://substackcdn.com/image/fetch/$s_!Asjv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73aac099-73c8-4f7b-9000-d0437561100e_1118x612.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Among the standout projects were:<br><br>- **<strong><a href="https://www.linkedin.com/search/results/all/?keywords=%23diskfly&amp;origin=HASH_TAG_FROM_FEED">#Diskify</a>:</strong>** This project centers on intelligent file management, leveraging Large Language Models (LLMs) within the file system for searches and disk space organization. Distinguished from <a href="https://www.linkedin.com/search/results/all/?keywords=%23glean&amp;origin=HASH_TAG_FROM_FEED">#Glean</a>'s enterprise AI and search solutions, Diskfly targets individuals for managing personal files. The founder, a recent university graduate, has successfully launched the product with 4500 downloads already and identified the ideal customer profiles. He also plans to use smaller models on edge computing devices ensures both sufficient performance and user <a href="https://www.linkedin.com/search/results/all/?keywords=%23privacy&amp;origin=HASH_TAG_FROM_FEED">#privacy</a>. @Francisco Salinas is looking for <a href="https://www.linkedin.com/search/results/all/?keywords=%23cofounder&amp;origin=HASH_TAG_FROM_FEED">#cofounder</a> now, please reach out to him if you are a good fit in this area.<br><br>- **<strong><a href="https://www.linkedin.com/search/results/all/?keywords=%23polymerdynamics&amp;origin=HASH_TAG_FROM_FEED">#PolymerDynamics</a></strong>:** This initiative addresses the gap between design and high-volume manufacturing of plastic injection molded parts. Despite a modest sales budget, they have already sold 4 devices, showcasing early success. The founding team demonstrates a strong founder-market fit. <a href="https://www.linkedin.com/in/brendanmarshalloneill/">Brendan O'Neill</a> <br><br><strong><a href="https://www.linkedin.com/search/results/all/?keywords=%23reflecting&amp;origin=HASH_TAG_FROM_FEED">#Reflecting</a></strong> on the experience, as a professional who is continually enhance my communication skills, particularly in English as a second language. Practicing concise and storytelling-oriented speech is crucial, and it's reassuring to know that even native English speakers encounter similar challenges. The adage "practice makes perfect" holds true across all skill levels and disciplines.<br><br>Engaging with judges from diverse backgrounds and decades of industry and venture experience provided invaluable insights and perspectives as well. <br><br>Special thanks to <a href="https://www.linkedin.com/in/cristina-cismas-florea-069a7b84/">Cristina Cismas Florea</a> and <a href="https://www.linkedin.com/in/michael-kovalich/">Michael Kovalich</a> for organizing this enlightening event and extending the invitation to participate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IFl1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IFl1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 424w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 848w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IFl1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png" width="1456" height="1124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1124,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:309947,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://wickey.substack.com/i/162831481?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IFl1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 424w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 848w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!IFl1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ca290b3-e204-420e-93f5-29638b3bb878_1458x1126.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://wickey.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Chasing Polaris - Wickey's blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>