Submind YouTube summaries
Thumbnail for Clayton Donley, Broadcom | VMware Explore 2026

Clayton Donley, Broadcom | VMware Explore 2026

Watch on YouTube

Video summary

Clayton Donley, VP and General Manager of the Identity Management Security Division at Broadcom, emphasizes that the rapid evolution from simple chatbots to autonomous AI agents has fundamentally shifted the security landscape. While early AI interactions were limited to basic queries, enterprises are now deploying agents for mission-critical tasks like coding and complex problem-solving, granting these digital entities significant access to data and systems. This shift introduces a critical risk: unlike human employees who operate within established legal and ethical frameworks, autonomous agents can act unpredictably or "go rogue" if not properly governed. The industry has moved from a world where users controlled simple tools to one where powerful agents execute actions independently, creating an urgent need for robust control mechanisms that can match the speed and scale of modern AI infrastructure. To address these challenges, Broadcom advocates for a governance strategy rooted in identity management, treating AI agents as "virtual employees" that require unique digital identities rather than relying solely on human credentials. The proposed solution involves placing a control layer between the agents and the Large Language Models (LLMs) or APIs they utilize, effectively creating a choke point where policies can be enforced. This architecture allows organizations to assign specific intents and scopes to each agent, ensuring that even if a user blindly approves an action, the system prevents unauthorized lateral movement or misuse of expensive models for trivial tasks. By funneling all agent traffic through this central gateway, companies can maintain visibility into who is acting, what actions are being taken, and at what cost, thereby preventing agents from bypassing security controls via external keys or manipulated contexts. The implementation of such governance does not require replacing existing infrastructure but rather layering new capabilities on top of current identity management systems to handle the unique lifecycle of AI entities. Broadcom's "Agent Minder" solution exemplifies this approach by acting as an observability and control plane that monitors traffic, assigns identities, and enforces policies without disrupting legacy applications or requiring massive upgrades. This method acknowledges that while the underlying computing paradigms—from mainframes to cloud-native microservices—remain consistent, the nature of the workload has changed from static code execution to dynamic, intent-driven agent behavior. Consequently, enterprises can adopt these tools incrementally, starting with passive traffic monitoring before moving to active policy enforcement, ensuring they can audit and prove compliance for their AI operations without halting innovation. Ultimately, the conversation at VMware Explore 2026 highlights a consensus that the era of skepticism regarding AI's return on investment has passed, replaced by an undeniable demand for secure and scalable deployment. As organizations rush to integrate AI into their core operations, the focus has pivoted entirely to how they can protect their intellectual property and data sovereignty amidst this new complexity. The industry is learning that just as mobile devices and the web required new security models, autonomous agents necessitate a similar paradigm shift where humans leverage AI to create more granular security policies rather than being left vulnerable to its mistakes. The path forward involves embracing these tools while building a resilient framework of identity, control, and observability that allows businesses to harness the power of agentic AI safely and efficiently.
Read the full video transcript
[music] Hello, I'm John Furry, your host of the Cube. This is the Cub's VMware Explore coverage. Of course, we have two days of live coverage from the show floor. I'm here with the Broadcom executives to unpack the innovation and the news at the show. I'm here with Clayton Donnelly, VP and general manager of identity management security division at Broadcom to talk about the agentic demand, the trust, the security, and the control that's needed to bring in AI intelligence safely and scalable. We're here at at Explore coverage. Clayton, great to see you. Thanks for coming on the cube. Appreciate it. >> Well, thanks for having me. Very, very excited to be here. Very excited to be here uh talking about really what's on top of everybody's mind here, AI. AI and Agentic has been the hottest thing and you know the first wave of chat bots and OpenAI and ChattBT was chat bots. So you saw search was a great use case um marketing material writing blog posts and then the enterprise started to see coding that opens up the kimono big time. And you're starting to see that movement now with agents. You got deterministic workloads, probabilistic workloads coming in, but deterministic working. But recently, you know, the mythos release of their model and then with the open AI hugging face example has kind of wakened the industry up to the fact that wow, these agents could go rogue. Um, and they're just running around like a micros service or a software application with full access to stuff. You know, they get hyperfixated kind of like war games. We were talking before we came on. This is kind of what the dark side looks like for Agentic. Now there's positive examples with you know deterministics endto-end workloads people have knocking those down but as you have an autonomous environment where agents will provide a lot of value. You got to rein in and nail down the control the governance and the security piece. This is what you're doing. give us the state of your view of kind of where we're at today and just compare that to like only maybe a year ago or few years ago the biggest changes is it hyperbolic what is what is the current situation >> well I mean it's it's really turned it turned its head right I mean at the end of the day we've gone very quickly from the users being control of the AI you know giving it questions asking you know very simple things of it you know how was your day tell me about the weather I don't know I don't know what People ask their AIS before we did coding, but now people are obviously doing much more important things with it. You know, we talk to companies every day. They're you doing mission critical things very quickly with these things. And I think what you know what you kind of alluded to was that well they're out there doing things and we don't really know what they're doing anymore. And that was a big change, right? And it's not happening in an environment where, you know, like, you know, we have this 50 years of figuring out how to deal with employees and giving them their rights. It's happening in a brand new world. >> Yeah. And I think the trust thing is huge. And I I want to get your thoughts on it because, you know, I like to study the history because we're both Grizzly veterans. At least I'll speak for myself. You're you're you look good. Um but if you go back to the old days of virtualization in it, the the problems were simple. got a new employee, lock down the desktop, maybe you got a virtualization front end, maybe it's some sort of system where you got everything's in control. It's got everything nailed down. They use the apps, they have a Blackberry, really easy to manage. Now you got people who are and they're like, "Okay, okay." Well, again, I go home. Very analog world. They're not going to cry a river. Today, the demand from the user side is so high because people are seeing real value. They talk to their AI. They see the reasoning piece. Wow, that just framed that problem. rewrote my email, solve the business problem. You have a massive demand. So, I don't think the agents are going to stop because now that people figured out it'll do work for them, >> go through my email, check everything, make sure my I mean, a lot of stuff's happening. So, it's not going to stop. So, it's not like No, >> people are going to say, "Well, I'll wait for it to get their act together and the security team." >> It's like the web. I mean, it's like the web. It's like mobile. I I remember going into hospitals when mobile first came out and people would try to put policies in there saying I'm not going to let doctors bring in their iPads or their iPhones or whatever that doesn't happen. You know, they bring in they're saving lives or they're going to do whatever they need to do here uh to to be productive. And you know, you look at a bank, you obviously they there there's a lot of things that they would like to do, you know, to make your your experience as a customer better, which of course helps their bottom line and uh you their top line in a lot of ways. And you know to do that they want to use AI and they're not going to sit around wait for it to get their act together. So just like with the web where it seemed like it was really fast and just like with mobile where it was kind of fast you know in AI it's instantaneously right instantaneous. >> They're not they're not going to stop. People aren't going to wait. >> They're not going to wait. So what are what are what is the best practice? What's the current state? And again black hat was a great seminal moment. Again the mythos thing was I call the chat GPT moment for security. >> Everyone knows when they first used chat GPT. Wow. This is pretty damn cool. Now you go to Mythos. This is not cool. What that's going on with the security bugs and identifying vulnerabilities, >> but there's a there's an upside here. Take us through how you're thinking about this because you got machine identities, you got human identities. It just complicates the problem that you solved before. Now it's back on the table again. What's the how do you solve that trust? How do you solve the operational issues around this new normal? Well, I I think that, you know, you kind of go back and look at, well, how do you apply the same concepts you apply to humans to something that really doesn't have the sort sort of the same moral compass or even concept of a moral compass or a paycheck that they're counting on that that you know, say a human would have. And it starts with you you need to identify those agents. You need to give them identities. Now, part of that may indicate who the owner or, you know, who controls that agent. uh you know some additional maybe metadata about you know what kinds of things that it's used for things you want to know when you're going back there and auditing you know what are the agents you have and then each of those agents they're going they could have lots of instances could be a million instances that are running all the time at in different times and those need to talk to AI the way AI really works is you know these agents make an LLM call you know maybe it's to you know claw maybe it's to open AI or Gemini or whatever it is it comes back and it gives them a bunch of tool calls calls that you should go do, right? So, but all of those are API calls. So, the great thing is is you know we have a lot of experience protecting APIs and we have a lot of experience understanding well who's making those calls or standards like OOTH and other kinds of things that are out there. Now, the key is putting it all together, right? So, it's one thing to have a bunch of identities that are now machines that are obviously not employees that were not instantiated when they got an HR uh you know, a little click in HR systems and workday. >> Yeah, they don't have a badge number, but they have a they have a >> Yeah, they don't have a badge number, but they >> they're a unique ID. You can track them. I mean, you they're out there. >> They're out there. They're they're like your virtual employees, right? They got that virtual digital badge and their employee number goes up to the billions. I guess >> it traces back to the employee. They get fired for their agent. bad agent behavior is on your performance review. I mean, these are the kinds of things. Okay. What are the risks? Let's back up. >> Identify the um share the the risks that people are seeing now and what what's out there in the market that you guys are doing because this is a problem people are attacking right now. What's the current best practice? What are the risks and what are people doing? >> You know, what what's happening where we are is if you think about it, right? I mean, there's been a lot of focus on, you know, the attack surface and and that side of it because when people first saw things like Mythos, they're like, "Oh my gosh, I better go, you know, patch all that, right?" I mean, what about attackers? What if somebody from a rogue nation state or something comes in and tries to attack my infrastructure? So, there was a lot of focus on the fact that, you know, sort of that adversary that's always out there when you're dealing with security is now going to be much faster, much more effective. They don't sleep. you know, they can run hundreds of these agents all the time, right? Um, so it went from that to but wait a second, you know, you look at this thing with hugging face or or, you know, other, you know, things that have been announced more recently and, you know, you get the the complete flip side of that. It's not the agents doing things, you know, like some bad guy doing something bad to you with an agent. It's your own agents. And so I think that what we're seeing now is people are doing you know like people are focused on governance that people who are realizing this is mission critical infrastructure that they're going to have to report to their audit committee on and all these kinds of things like do you you know if you think about it like with Sarbain Oxley you know back in the day you you used to have to certify that your employees have this access nobody certifies my agents have this access nobody does any of that so the maturity is not there but what we're seeing is a trend to trying to pick up that maturity >> what how should enterprise has rethink their governance strategy because this comes up in every conversation. Governance is getting baked into the foundational level and root level of all activities on AI infrastructure. What's the rethink? What's the mindset? >> Well, the the rethink is is, you know, you you really need, you know, like I said, you you need to have that, you know, identities for those agents and you need to be because you you can't buy a book on the internet without knowing who you are, right? You know, and you're giving these people a lot more access. you're sometimes giving them access to, you know, a lot of data maybe in like a rag system or other kinds of things. So they they have all this, but you need to know who it is, you know, who this digital employee is and and and then more importantly, you need to know what the intent of, you know, like what the scope is that you're going to allow them to do. >> And when they do something, they need to kind of broadcast their intent like why I'm going to go do this and then you match it up. And so today in you know the the best practice taxes is you is you define these things you give them policies and you enforce that policy you know around ensuring that even if the user is controlling the agent they click approve this users love to hit approve on these kinds of things the next thing whack-a-ole yes it's like it's asked me three times if it can do this of course I'll just say yes right so even when the user's in control they're not always the best person to make that decision so having something there between those agents and the LLMs between those agents and your APIs, MCP servers, all the things those agents need in order to have that superpower, you know, is is really the best practice. But then just having the control isn't enough. Like how do I audit that? How do I monitor that? Right? And there's two aspects to monitor. There's the there's there's what's the guy doing and then there's how much is that costing me? Because as we know, you know, tokens cost a ton of money. Yeah. and if you know using the wrong models are there you know is it using too many uh you know is it being using too many agents for this is it doing what I thought it was doing and and we're in the and we're in the early days of this so having those three things right the the identity of the agent the control point to kind of choke off bad things from happening and then being able to monitor what is actually happening you know what were those prompts what were those tool calls being able to tie it together is really critical >> what's what's coming up at here on my uh coverage of VMware or explore is that you're starting to see some formation of some trends, architectural trends. The data platforms are separated from the models. You have this control plane or cont andor context layer in between that helps manage it. Um you mentioned a bunch of things there. I want to focus in on kind of the old school thinking around observability. >> Observability and tracing become really valuable because you got to prove >> how is that working with broadcast? You got agent minder, you have all these tools. how how are customers using the solutions to get that architecture implemented and at least reigning in the chaos? What are some of the things that they're doing? >> And it and it's interesting you asked that and you you started with the word old school because you know uh we we acquired a number of products over the years and a lot of them were things like APM products from people you've probably forgotten about like WY and others that that that made these monitoring solutions and what's interesting is over the years we developed a lot of things for application monitoring. They did, you know, think about it, code tracing, >> but code became distributed. You know, when people went out to containers and and microservices and things like that, your code isn't running line after line anymore. It's running in all these different containers. So, we got really really good at sort of tracing in a distributed way what these applications were doing. And what we realized very quickly, you know, kind of like >> you can rescope that to agents. >> Yeah. Yeah. So then we suddenly realized, oh my gosh, this is exactly what we needed, but we need to extend that to the prompts that were being used, the tool calls that were coming back. Uh, but then you need to be able to see that, well, what triggered that in the agent? And by the way, the agent didn't make a mistake. Did somebody gaslight it? You know, my favorite stories with AI sometimes are people getting the agent to do something that it shouldn't do because you feed it certain context. I've seen, you know, my favorite story. We had we we had a person trying to do something that they were allowed to do with a with a with a LLM and it was refusing because it said, you know, for security reasons, but we're a security company and we have permission, right? So to get it to do it, it made a fake he made a fake PDF with a fake signature saying that this is authorized, fed it the context, it went right to town. >> So these these context is not human context. It's absolutely and it can be it can be fooled by anything it sees on the internet and so it's really really imperative that you have that sort of controls the cross checks the ability to then once again you know during that trace see well well how did that come about did an employee try to go around the controls or was it just making did it just make a mistake >> Clayton it's a great made a really good point has a history of of a lot of uh acquisitions in software obviously everyone knows what the VMware one got big one recent and BCF's looking really good off uh right now in the market. But if you think about application monitoring which you just mentioned what is an application right so the underlying science behind it computer science and the code is distributed computing paradigm it's tracing this is science has nothing to do with the application to remove application yeah and say agentic it has the same behaviors um so I guess my question is how much within the broadcom stable of products and the portfolio are are well suited for the new normal because the application is just behaving a little bit differently, but the game is still the same. It's doing something. The UI might not be there. It might not be on the right server. The server architecture changes, but that's well known known concepts. So, you can just I won't say retrofit, but you can actually point the technology. >> Well, I mean, that's the key, right? I mean, a lot of times you you step into something and everybody wants to think that, oh, there's white space here, nothing exists there. But the fact of the matter is is a lot of, you know, what we found is in almost every one of these cases, you know, everybody had maybe 80% of what they needed, >> but it wasn't put together. So, you know, kind of going back to agent mind, what we do, we didn't copy and paste that code. We didn't go back there and take say a 20 30 year old codebase and say, "Oh, we're going to shoehorn this into the new modern." Uh, we' actually been building over the last several years, you know, kind of a new, you know, what I guess I'll call cloud first architecture that has actually all three of these things. And because we developed it alongside kind of this growth of agents and AI, you know, we sort of stumbled into this. I mean, I hate to say it, but it's almost like, you know, you take a walk in the wilderness and you fall into a diamond mine, right? Like, I'm not going to be able to repeat that, but it's it's never a bad >> I mean, luck is always ready preparation meets opportunity as this as the saying goes. But, you know, >> we just happen to be in that right place, right time, right? Well, software evolution. >> You got these three things. We were pulling it together anyway because you need these three things to operate together. You can't they can't be airgapped. So, you know, it we we I will say we got very lucky, but uh and it's been it's led to a lot of opportunity for us, but it's led to a lot of value for >> Well, it's interesting. I know I always say this. I mean, about two years ago, the the most common phrase on the cube was it feels like the '9s again. Of course, we're covering AI early days of AI factory. So, guess who's involved? A bunch of the old dogs and the new dogs coming together. The old guard, new guard. So, you're seeing like literally generations working together. So the if you were in computer science in the 80s and 90s, you built the systems revolution. That's the computer industry. >> Now you coming in as your hot shot coder for AI native, you're running on the systems that are actually not being replplumbed fully, but like being rearchitected. I mean AI factory from Nvidia and AMD and all these companies and with VCF now sitting on top of that hardware. That's just a server now a bigger server with a lot of servers in it. It's the same game. It's the same computer science, computer engineering game, same software game, just >> applied differently. And I think this is one of the revelations that's coming out of this AI wave. It's just transition. I mean SAS is a user interface based paradigm that's been there since the 80s. Now people are using voice prompts with chat. So there it's headless systems is the new thing, but that's not new either. So you're starting to see the role. >> So you're saying ASPs are all like the SAS providers. I think SAS providers are going to uh be um headless systems. >> Yeah. >> With some you guey >> and some other interface. It could be model driven. It could be embedded in another function multi-function applications. I mean that's my personal opinion but you're starting to see that trend where I mean the user experience is >> we see this all the time right? I mean if you think back to the web what were the first web applications? People wrote little web rappers CGI if you remember. >> Yeah. They were little web rappers that sat on top of your mainframe or sat on top of real production systems. And the only reason the web was useful is because it had access to all the stuff you've been doing for at that time probably 20 30 years. >> And now what you've got is you've got things that are running, you know, whether it's in the cloud or running in private cloud on VMware or containers. Uh you know, it doesn't matter where it's running. It might even be running on the main frame. Transactions probably is running on the main frame, you know, but people don't go to the green screen anymore, right? Yeah, you know, like uh >> they don't care where it runs. If it's going to run on a main frame because it's a transaction for a financial deal, no problem. You run on the main frame. I'm running on a client server. Okay. I'm running on a super rack scale system from Nvidia with the latest paro curve with Vera Rubin. I don't care. Get me my tokens and and my results. >> Yeah. Yeah. And so, so yeah, absolutely. So, what you're going to see is I mean, but but this is why it's so important to get governance right because you're not just giving people access to chat GPT. You know, one of the interesting things is when we first started doing some training on this, people were very confused about agents versus just getting a an LLM session, you know, when you go out to Gemini or chat GPT or something and they don't realize the power these agents have and the fact that people are giving them all the all the data from their organization, the APIs to access various things in their organization. It is, you know, it's a lot of power. I think the on premise uh growth is directly related to what you just said which is the trust and control of the data because the data is the competitive advantage that's where the IP is the domain expertise and so people want to control that um and track it um and we were just kind of riffing on traditional systems and conventional um networks and methods what's changed about AI is it the intent piece and what's and how do you measure and audit because saying I want to throw governance at AI is an easy strategic decision but now you got to implement it. How do you implement governance so you get that traceability you get the control and at the end of the day you got to prove it that in an audit or hey that agent is Clayton's that's on you right I mean that's I'm making that up but that could be the use case I mean people are starting to talk about that the the humans own their agents like a fleet of staffers >> yeah well I mean that's why people get concerned about AI making mistakes right because you know if you make a mistake you know I feel like I had some agency in making that mistake you know the AI made the mistake when I wasn't even around. Still my fault. It feels very feels very wrong to me, right? But you know if you think about why this works now it's because if you think about one of the hardest things in the human you know like in terms of auditing what humans uh have done uh predetermining uh say entitlements and access and things like that has always been how granular do you go with those permissions >> because you can go really really deep and then you can't really control it because like nobody can keep track of all those different permissions and how they relate to each other. So people got very lazy and said well not lazy they got very efficient by saying well I'll put people in different groups you're you know you're in finance you're in HR you're in you know R&D and based on that I'm going to give you some base level things you can go do and in AI that's people are starting to do and then you start saying well okay these are the 10 things that you can do because you're part of that agent group but what's really interesting though is because now we have AI too right >> yeah we can actually go much more granular than we used to and actually assign those permissions because we have the help of AI and actually going out there and sifting through all the stuff humans never had time for. So in fact, we could get to a much higher level security by leveraging AI to help make some of the policies that govern AI. It's sort of like, you know, AI as a judge sometimes on its own work. So there's so many patterns that we're seeing, so much, >> you know, so much that we're seeing where we can obviously you want a human on top of that. You don't want to just say, you know, leave it all over the >> I mean, I think the whole human loop debate is over. Humans are getting a superpower from the AI. That's the way it should work. It's a tool. It's a superpower. AI scales, intellect. I think that's clear. The number one question that comes up from folks that I talk to that say, okay, how do I just get going? Because there's no debate that they see that, then they go, okay, I've been doing my job for 20 years or 10 years or whatever the duration is. I'm a manager, an executive. What else should I do with my department? Should I have them start doing AI more? So the the best practice that I see is people just start using it. Get the muscle going. >> How how should enterprises do that? Um I'm sure you agree because everyone kind of agrees on that point, but where do you start? How do you get the muscle up? And how should people be prepared because they have to get the security practices in place? They got to understand how it works. They got to drive the AI. It's like, you know, moving from horse and buggy to a car. Now you got to drive it um and manage it. what what are leaders doing in organizations and to kind of bring in that security piece without harming themselves, right? So, without having the agents to go off the rails because they want to deploy more agents, the demand, >> right? I mean, I I think it's what you what you've seen everywhere, right? I mean, if you if you saw the uptake of SAS, right? People weren't especially at large companies with missionritical apps, they didn't throw the most mission critical transaction app out on the out on the web or out on the, you know, these other areas. they started in areas where they could accept the risk, right? And what's good is that gives you a place to start and and you know the I think the best thing and you know kind of you know not to go too product here but you know when we looked at agent minder one of the things that we looked at is we didn't want people to have to do a big two-year upgrade before they could get started. We wanted something they could layer on leverage their existing identity management. they've got somebody who would be a competitor of ours for human identity, uh, whether they're employees or consumers, go use it, right? You shouldn't disrupt that. That works just fine. That was not the problem. The problem is you've got another set of entities out there that are very different. They operate at a very different scale and they need very different kinds of policies, processes, life cycles, all of those kinds of things. So you know we basically you know if I look at our early adopter customers you know most of them they start you know by putting in kind of the the agents they're working with they get them registered you know they take a couple of their initial agents uh you know register them with you know the gateways and things like that and sometimes they just run traffic through it. >> Explain I want you to explain to end the interview because I think this is important. Agent minder how does it work? Um people are looking for ways to get started. Is that the the place where everything comes together? How do I deploy that? What's the pitch for the value proposition? Explain agent minder and how it works. >> Well, let me start by what it isn't. So, it's not the thing that's going to run your agents, right? We're not going to try to be your agent platform that's running the the runtime there because that's going to be everywhere. You know, you'll get it from Salesforce, Workday, you know, every startup in the in the world is building an agent platform. You can go buy you can find open source ones in every programming language. And absolutely, you know, you set a standard in it. I'm sure half your users will use exactly the opposite of that standard just like OS. >> Exactly. So, so we're not that you know the main thing is but we're open and what's great about that is we have to sit between those agents and the LLMs that they're using first of all. So, you know, we have a gateway component uh you know we actually work with some of the other gateways we have as well like VF and others you know depending on what kinds of policies you're you're going to enforce uh that sits between that. So you've got your agents and you've got your maybe whether it's clawed or open AI or private AI or whatever you've got it sits between one or more of those and it's looking at every request and sometimes the starting thing we do is we just watch the traffic because it's very easy. It's very cheap. It doesn't require you to change anything. >> It's a great way to start. Look at what moving around lateral movement you know who's where the footprints everything's trackable >> and and all of that uses open telemetry. It can push out. Obviously we've got our own observability service that it can plug right into. is kind of part of the platform. But if you're already using something else, go for it. Like there's no reason to wait, you know, to get this started. I think the main thing is you need to start looking at the traffic, looking to see what they're doing. And then because that traffic is mostly not going to show you who's doing it, you need to start start assigning those identities to the agents and then they'll just start using modern standard. You take away their clawed key, you take away their open AI key and you give them a key to yours. And so now you can make sure they can't circumvent you by using their keys through some other app. So there's immediate control. You've kind of funneled those things, you know, those people through that central point of control. And as you give them identity, give them, you know, kind of a key, if you will, to to get through there, you can start adding in policy. Well, I see this, I don't really like it. Or I see I see them using uh, you know, very expensive models for very simple things. I'm going to demote them to using a lesser model. or you know maybe uh maybe I'm going to to to send this group of people out to private AI. But it gives you a lot of control very quickly without a lot of effort >> and they have choice. They can go on their timet look at their environment. Here's what we got as a as our standard. Here's what's we're doing. Let's plug agent minder in and get it right. >> Absolutely. I mean I mean it has to be heterogeneous. I mean we we work with our biggest companies in the world. I mean I'm sure that they have 150 vendors that do things that are adjacent to >> they want speed. I want to test something out quick. Yes or no? It fits. Let's play with it. I don't want to have too much disruption to change management which is a big concern. Uh final final point I want to get your thoughts on on what you're excited about this explore. What is the top conversations happening? Um what are you excited about this explore here uh for VM explore? What's what are some of the things that are that are notable that you could share? >> I mean I wish I had other things to to get excited about, but I will tell you the thing I'm I'm everybody's coming to me about really just is AI security, right? I mean a year ago, a year ago it was interesting, right? I mean, people were starting to chat about it, but it was early days, you know, we didn't have kind of the, >> you know, people people weren't sure if there was going to be the value quite frankly with some of this AI stuff. I think >> and they were skeptical. >> Yeah, there was a lot of skepticism that that we were go that businesses were going to get the ROI >> to be able to kind of keep funding this. I think that B that that that train has left the station, right? I mean, absolutely. You know, every time I talk to like a sea level individual, they are all talking. >> Two years ago, RSA was poo pooing a AI and this year was like, "Oh my god, we got to get on this." That was pre- mythos and it's like I mean like >> Yeah. Absolutely. Yeah. So, every conversation's been AI. Every conversation that has been AI has pivoted to uh >> oh my god, it's usually it's usually like the the on the IT practitioner side. It's like, >> yeah, >> all these guys above me are talking about is, >> you know, they they're going to do all these things, but I don't even know where to get started protecting this stuff. >> The science is excit I I found it exciting because I think the science and the technology is changing. The AI infrastructure is moving up the stack and the software stack's moving closer to the hardware. So it's kind of like you know all the primitives and uh algorithms and software techniques >> that were once powering something else from another generation are being used in different ways. >> Sediment is the complexity under I mean I always think of like a layer of rocks right I mean you've got mainframe there at the bottom at the core you know and then you've got you know each layer of sediment above that and just you you know every layer every layer contributes and then of course we always see the top layer. >> Clayton you're in a hot area. Thanks for coming on the cube. I really appreciate it and again this is not going to be an ongoing conversation. I'm sure next year another model comes out. Um the infrastructure will continue to grow. I mean AI factory is one of the top stories here with VCF is consistent what we're seeing with Nvidia AMD and all the semiconductor work with memory. So these infrastructure enablement is going to change the nature of the software stacks >> which changes the nature of what we were doing before and what we do going forward. And it's going to create a lot of opportunity and also with opportunity comes bad actors. So you know >> that's the life of security. >> You know you're getting your world's going to get more complex. Absolutely. >> Thanks for coming on. Appreciate it. I'm John Fer with the cube. We're here for our VMware Explore coverage. Thanks for watching.