Submind YouTube summaries
Thumbnail for Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake | theCUBE + NYSE Wired

Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake | theCUBE + NYSE Wired

Watch on YouTube

Video summary

The discussion centers on a pivotal shift in enterprise technology where AI agents are evolving from passive tools that answer questions to active entities capable of implementing actions across various systems. This transition introduces significant cybersecurity challenges, as organizations must now manage digital employees with full access to databases, APIs, and applications. Jacob Thomas from Texas Children's Hospital highlights the unique stakes in healthcare, where security failures could directly impact patient health rather than just financial data or reputation. Consequently, hospitals face the complex task of balancing innovation with strict regulatory requirements, necessitating robust governance models that can audit every action taken by non-human systems to ensure they operate within authorized boundaries. To address these risks, Pratyush Patnaik of Snowflake explains how their partnership with Netoma extends enterprise governance beyond static data at rest to cover data in motion between agents and different systems. This solution acts as an "AI gateway," providing dynamic identity perimeters and runtime environments that enforce policies in real-time. Unlike traditional Identity and Access Management (IAM) which relies on static scopes for human users, this new approach requires continuous monitoring and decision-making capabilities at runtime to determine if an agent's current actions are appropriate. The goal is to create a system where access is granted based on immediate context and necessity, effectively turning security from a bottleneck into an enabler that allows safe scaling of AI initiatives across the entire enterprise ecosystem. A major theme of the conversation is the critical role of cost management and operational efficiency in driving AI adoption, particularly regarding token consumption and inference costs. The speakers argue that while building agents is easy, deploying them wholesale requires careful financial oversight to ensure a strong return on investment. Strategies such as sandboxing environments, utilizing FinOps practices, and optimizing model selection help organizations understand exactly where execution loops occur and how to maximize value. By proving that specific metrics are met and demonstrating clear business value, security teams can alleviate concerns from finance leaders like CFOs, ensuring that the necessary investments in guardrails and monitoring do not stifle technological progress but rather support sustainable growth. Looking ahead, the industry must prepare for emerging threats such as model escape scenarios, where an AI agent without malicious intent might inadvertently breach security boundaries and compromise other systems. The consensus is that these risks are not new to cybersecurity but represent an evolution of existing challenges that require updated mitigation and compensating controls. Snowflake's future roadmap focuses on efficient intelligence and owning the enterprise context, enabling customers to build bespoke solutions rather than relying solely on off-the-shelf products. Ultimately, the path forward relies heavily on strong partnerships between technology providers and security experts to create a resilient infrastructure that can safely harness the power of AI agents while maintaining strict accountability and auditability in an increasingly complex digital landscape.
Read the full video transcript
Hello out those studio connecting Silicon Valley and Wall Street. >> I'm John Furrier co-host of the Cube here with Dave Vellante my co-host. >> Welcome to the Cube studio here at the New York Stock Exchange. I'm Gemma Allen with NYSE Wired cybersecurity leaders, a show connecting Silicon Valley to Wall Street talking to the folks shaping what's next in tech, business, and capital markets. Today we're talking about one of the biggest shifts happening in enterprise tech right now. That is AI agents moving from answering questions to actually implementing actions creating a hugely new problem for cybersecurity. So the question becomes, if you give an AI agent the keys to your enterprise, how do you make sure it only opens the doors it's supposed to? To unpack that, I'm joined by two folks looking at this problem from very different sides. Pratyush Patnaik, head of enterprise AI security at Snowflake, and Jacob Thomas, manager of information security at Texas Children's Hospital. Welcome, folks. >> Thank you, Gemma. >> So, a very interesting time, a lot happening very fast. You've obviously We're going to get into your journey into Snowflake, which I know is very new but also very critical to the road map that you guys are building. But first I'm going to start with you, Jacob. When we think about children, especially from the perspective of children's health and running a hospital as successful and as iconic, I guess, in the US health care system as Texas is, the risks that cybersecurity threats pose are different from many others, right? It's not just about finance, it's not just about image, it's actually about patient health. Talk to me a little bit about what has changed for you with this rise in AI, everything that we hear about and talk about every day on the news. Bring me up to date on what the last three to four years have been like from your perspective. >> Sure. So, Texas Children's is, just to level set, we're the largest pediatric hospital in America, right? We have over 1,200 beds. So, we're sitting on a ton of data, right? And the question really comes down to how do we use that data efficiently? For us, it it is absolutely a a game-changing event for us to start looking at it from an AI scope. Um and for us, it really just comes down to leveraging it in a way where we increase and get better patient outcomes, uh better patient experience, those kind of things, right? And we really can't do that without really leveraging AI. But, when we first started our journey in that space, we found that um we can't just go and grab a model out of like hugging face and just like run off of it, right? So, we had to really invest in our research partners and bring in like a lot of investments around building models. Uh so, that's kind of where we're at. We're exiting from that stage and starting to connect it to LLMs and taking that to the next factor of like connecting it to our user base. Yeah. >> So, we hear a lot about AI agents, right? This whole concept that has become ubiquitous really with technology and the future of tech and some folks compare it to software, some folks compare it to an actual digital employee, right? Which I think is where Netoma and that journey comes in. It's an interesting analogy because employees have credentials, they have access, they also can be cut off if needed to be, right? Just if they're being manipulated or whatever we see happen. But, we know that in the world of agents, everything's happening at huge scale. Let's talk a little bit about Netoma, the journey, and I guess the business alignment and the commercial alignment with Snowflake. >> Absolutely. Absolutely. For us, Gemma, when we started the company, it was we working with partners like Jacob saw the the shift happening where the AI was becoming capable enough to not just answer questions, but take actions. That means the agents, the AI systems had to get access to different applications, databases, APIs, and that meant providing an, you know, identity perimeter to them, assigning an identity, making sure they are doing what they're authorized to do, having a runtime environment to enforce the policies as needed. Uh which naturally makes sense for Snowflake. If you think of it this way, Snowflake is the AI and data platform of the world, which is trusted by 13,000 plus enterprises today. With Netoma, Snowflake is able to extend the same governance, same trust, not just to data at rest within Snowflake, but also to data in motion between your agents and your different enterprise systems. So, that's what we were able to provide. I can answer the question in another way also, but Snowflake is also one of the most progressive companies when it comes to consuming AI, you know, finance department, M&A integrations. IR, everything is done agentically, and you know, Snowflake was using Netoma, and they saw the value, and probably thought of they thought about taking it to to their customers. And you know, it's a win-win win for everyone. >> So, Snowflake's had an interesting year here on the market, here on Wall Street. We look at the stocks every day, and earlier this year you guys had a ripping day on the street, and one of the analysts, you know, was very clear in saying this is not just about some big deal with Amazon. This is actually about what they're building themselves from the perspective of Cortex, right? And that AI gateway. >> Absolutely. >> It sounds super exciting, especially to all your customers, but we know that again, there is a level of risk, right? If you have agents talking to multiple systems at scale, >> Yeah. >> how do you actually completely control and manage that? >> Yes. >> So, from your perspective, Jacob, I'm sure you're also, like every other industry, under pressure to keep a pace with the speed of AI, but you do it in a safe way. What does it fundamentally change for you? Are you talking about, you know, scaling more data access to more digital employees and agents across your ecosystem. Talk a little bit about what that agentic layer and and Snowflake can actually fundamentally shift in additional workers' life at Texas Children's. >> So, don't forget in healthcare we're heavily regulated, right? So, we we have to take all of what he was talking about around our back level controls for every single one of those data points, right? And then consider who it is that's actually touching those things, whether it's non-human systems versus, you know, human loop components, right? All of these components come into play and then we have to be able to produce that as a check, right? And it's a check and balance conversation, right? So, all of those components has to be mapped out in some way, right? And that's where we see the value in something like the Cortex AI gateway, right? Um I I ultimately look at it from the perspective of we're in cyber, we're always known as the people that tell everybody no, right? We can't do that. Going into the innovative areas that we're going into, right? So, it really comes down to having the appropriate controls in place. Those controls come with these kind of solutions. And that's why we were speaking to them early on about a year plus or so, right? Cuz I knew this is kind of coming around the corner. Um and once we started exiting and started going into the LLM space, the next component will be agentics and that will come very quickly. Uh so, we have to be ready for those conversations. >> So, when we think about what's really shifting from the perspective agents accessing data, right? We know that maybe not systems independently access data before, but we have had APIs in place, we've had software operating with the interoperability or at least a request for it for quite a while. We've had IAM, you know, is this essentially from your perspective like IAM 2.0? Like how do you really define this category? >> So, to break it down, you know, we have had IAM, those are robust uh solutions out there in the market, But you have you've had the humans. We come with accountability. If I'm doing something, I'm accountable for my action. You've had workloads which were deterministic piece of code someone had written to go do something. Now you have agents that fall somewhere in between. I think you started by saying we're moving from AI as a software to AI as a workforce where a model and LLM reasons decides what it needs to do. So the identity that we assign to these agents. So when it comes to human or workload, you at authentication when you come in, you we know who is who, what you can do. But when it comes to agent, you cannot give them static scopes. When they're doing something, a runtime decision has to be made in the given the circumstances, does this access make sense? Can the agent do this? Is it has something changed that we need to yank out that permission? Those things have to be done at runtime. I think that's the biggest shift that we'll have to adjust to as agents come and run your enterprise. >> When we think about MCP, which is the fundamentals that this is built upon, right? Traditionally, there was a little bit of skepticism around how secure is that world, right? Like what does it actually mean? How can you truly lock something down if you have systems talking to each other at such scale? But now it's the buzzword of the year, right? Like in France, we hear about MCP all the time. There's so much excitement. What do you think it truly means though from the perspective of security? And I'm going to put this to you, Jacob. Especially when you think about a world whereby, you know, you have a larger attack surface, right? You have a larger attack vector if you have agents talking to each other at the pace and speed and scale that technologists make us believe is going to happen tomorrow. >> Correct. Yeah, the attack surface was never an issue for us in the past. Mostly because we were working on probabilistic models and then moving into deterministic and and with the future scope of going on, you know, the other direction, right? But as you start introducing MCP into that conversation, it starts to becomes a bigger problem for us, right? But it's not really a problem from an innovative standpoint. In fact, it makes things a lot better. So, we are looking at it from the same kind of perspective, which is what all needs that level of access? Is it over permissive? Is it not over permissive, right? Well, how how do we tweak that to the exact necessities that we need? And then kind of approach it from that perspective. So, having something sit there and look at that actual workflow and understand that workflow so that we can come back and say, "Okay, this is exactly what you need." And then you can just turn everything else off. Is it still running? Beautiful. That's exactly what we want. >> Right. Let's talk about cybersecurity broadly for a second. Is it a bottleneck or an enabler of inference, right? Of change. Cuz there's mixed views in this, too, right? Things, especially at a hospital, have to be exceptionally secure for a very, very good reason, right? But we also talk about the pace by which cyber can sometimes slow the technology race so much. How do you guys think about that bottleneck? Like, what is your response to feedback that maybe it's not so much about the model, >> Mhm. >> it's about the actual pace of usage, pace of access. You know, what are your thoughts specifically? >> I'll I'll try to break it down into two parts, but first of all, models have been capable, at least when it comes to enterprise workflows, for a while. Yes, they cannot discover drugs just yet, but they can do everything we do within an enterprise. What's stopping a broad-scale rollout of AI within an enterprise is two parts. Uh until now, it was mostly security and governance. Uh it's very easy to build agents. You can ask an agent to build an agent now. When when you need to deploy and give them wholesale access to everything in the system, that's when things get tricky. That's when, you know, security side or the IT side will come in, you know, wanting to know, "What is this agent? What is it trying to do? What did it do in the last 6 weeks? Where is the audit trail? Those become a question. So, essentially part one for AI to go from pilot to to full broad full scale broad roll out. Number one is just taking security, governance, identity, access control seriously. The governance should not be review access review process. It should be part of the infrastructure. The second part here now that is I think top of mind today for most of folks is cost, you know, cost have blown up. Uh this is where Cortex at least helps where we have semantic view of the data that you know, we have proven numbers where you know, we bring down the the token efficiency and the intel- intelligent efficiency is what I would call by a magnitude that's makes scaling out the AI across the enterprise easy. And then, you know, we're not just doing with Naturopath, we're not just doing it in the data park in Snowflake, but across your enterprise ecosystem. Number one, number two is also it's not tied to Cortex, but to every app you might be using. >> Let's stay on cost for a second. This is an interesting conversation, right? We know that, you know, in technology, Snowflake, AWS, all of these huge giants of industry, they're also huge line items on a P&L, right? Like an Anaplan company. And with everything that's happening so quickly, especially from the perspective of tech and inference, there is certainly, you know, a lot of conversations happening around consumption, around tokenization. I'm going to put this to you Jitesh a tricky question, but how do you think about that from the perspective of, you know, your own kind of evangelism of this kind of tech futuristic picture that we all foresee? How How do you think about like the role of a head of, you know, man- of security and a CFO? Like those conversations must be becoming closer and more regular than they've ever been. >> Partnerships is is the the answer to that question, right? So, we we partner considerably to understand just the tokenomics of it all, right? And it really just comes down to sandboxing that environment first, letting them run their models, letting them run their queries and everything else, right? Understanding the harness component of it to understand where exactly the execution loops are taking place. And then, are we really getting the value out of it, right? So, there are these conversations that take place, you know, there's people and process behind the technology, too, right? So, we have to make sure all these things are in place, and then that then delivers the ROI for us, right? Um it's an investment at the end of day. There's going to be spend. You can't avoid that, right? But, really it just comes down to do we meet these specific metrics, right? And understand the success criteria around that. If you can pitch that in a way that makes sense, everybody will buy in, right? That's That was our take on it. We invested heavily in that space, and then we built those guardrails out. We We invested in FinOps as well. Uh that really helped push these things forward, and there was If we hadn't done that, I'm pretty sure we would have gotten a lot of sticker shock from our CFO, right? All of those things were concerns were alleviated by doing these specific kind of things, right? But, it again, it's people and process behind the technology. >> For sure. >> Also, the world is changing so rapidly now with all the open weight models, there are ways to optimize your token consumption for the task at hand. You know, you shouldn't be going to people five to check whether or our simple task. Even older models are capable in doing some of the tasks that are repetitive. Now, you can bring bring back your, you know, good old macros in some scenarios where things have to be done in a very deterministic way. So, a lot of investment happening in in making sure folks are spending there is a direct correlation between the token spend and the business value being delivered. >> Okay, last question. Some folks say that inference actually is a huge threat to cyber, right? Because we have like key you know, keystroke logging, we have all sorts of activities happening that we probably didn't predict or plan for 5 to 10 years ago. >> [snorts] >> What are your thoughts in terms of the additional threat factors that are evolving in this world? Like what sorts of thoughts are you maybe planning for or having or even, you know, people are keeping up at night that perhaps wasn't like 3 to 5 years ago? >> I mean, personally for me, that was always there. Uh it's not like it suddenly just showed up, right? Uh and that's reason why we have a good governance model behind everything, right? You have to understand that there's mitigating controls and compensating controls. If you plan for that correctly, you can reduce the attack surface and then reduce the ability for the threat actor to do those kind of things, right? Um that's have always been our approach. Uh that is not unique to AI. That's that's specific to anything in our cyber stack, right? So, we just continue down that road. To keep it simple. >> Keep it simple. >> I'll add one more thing to it. Uh so, at Snowflake, obviously we are we have to protect Snowflake. Something to the tune of what what Jacob just said. But, the other thing we're beginning to get concerned about is our agents escaping and doing things. You know, recently you heard the scenario where a model uh with no mal intent, just trying to do the task it was assigned, escaped out and hacked another company. That has become a reality now, [snorts] and we need to have proper guardrails, proper monitoring, proper auditability to stop those things from happening, too. >> That's something that's keeping Snowflake >> I think it's keeping us all awake at night, right? We just saw earlier somebody had modeler a bad actor had hacked someone's phone and contacted the PM of England just this morning, right? So, there's all sorts of crazy stuff happening right now out there. But, staying on on Snowflake and this relationship and this partnership for the last question, talk about what's ahead. I mean, I know this is a relatively new acquisition. It's an exciting one. Core capability brings a lot of technical know-how and need I think to the Snowflake model overall. You guys are old friends though, right? This is an This is an old partnership. Talk about what the next kind of year outlooks like cuz I don't think we can think past that. >> You want to go first? >> Sure. Yeah, from a cybersecurity standpoint we're investing we're doubling down on the Snowflake component. So we're looking at different solutions that they're going to start beta testing us with. I can't speak too much into that but the the goal is to really dive in with the concept of data analytics at the end of the day, right? So a Simmons our product is essentially a data mine for a cybersecurity team, right? We can essentially do the same thing with the Snowflake data lake as well. So that's the gist of it. We're we're going to we're going to go down that road and explore those paths. >> I'll keep it simple too for Snowflake. Number one is efficient intelligence for our customers. Number two is owning the enterprise context. We have the data either data parked at Snowflake or in motion with with the Cortex AI gateway. How do we make it much more valuable to our customers? And as we are entering this Agility era we are beginning to hear a lot of DIY where customers want to own and build bespoke software for what they need to do versus buying something off the shelf. And enable partners like Jacob to build that efficiently and at scale. >> That's an interesting point to end on because you need to meet partners where they're at right across all industries especially when it's critical as children's health. So gents, thank you so much for joining us at the NYSE Wired. >> Thank you so much Emma. >> Appreciate the opportunity. >> I'm here at the Cube studio at the NYSE. This is Cybersecurity Leaders. Thanks for watching.