Loading summary
A
Welcome to Cybersecurity Today on the Weekend. With me on today's show is Prat Datta Pratt's a full professor at Kent State University in their business college and he teaches about cybersecurity, AI IT and digital transformation. Our conversation today is going to focus on the last six months on AI and public policy. Everything from the explosion of Mythos onto the scene to the issues around the export controls of AI, whether AI is a toaster or a nuclear weapon. What lessons we have from history as countries around the world, but particularly the United States, wrestles with the issues around how to manage AI with issues particularly in the United States, but around the world as governments wrestle with what to deal with and how to deal with AI. I hope you enjoy listening to this conversation as much as I had having it. Let's get started. Prat, it's great to have you on the show. We've been talking back and forth by emails and had a few chats over the last year and really excited to have you on. If you wouldn't mind, in your own words, can you tell the audience a little bit about yourself?
B
Yes. I'm a professor and a research scientist at the Ambassador Crawford College of Business and Entrepreneurship at Kent State University. Mainly work on cybersecurity but from the process side of the puzzle and research a lot in terms of global ICTs and the influence of both AI and or gen AI as based on NCT conditions and how that's reshaping. Cybersecurity came out of global consulting and that's who I am.
A
So this is a wild time to be trying to study a technology that seemingly reinvents itself over a 12 to 18 month period at best. And this last six months has been particularly wild from a policy standpoint. So I want to rewind a little bit and walk our audience through some of the things that we've seen, some of the implications and what may be next. Because even as we're talking this week there are talks about potentially limiting the availability of certain open weight open source models depending on country of origin. We have this whole issue of an OpenAI cybersecurity model apparently breaking out of its constraints and hacking another party hugging face to try and cheat at a cybersecurity test. There's been a lot. But let's rewind the clock and go back to those Calmer Days of March 2026 and we have this announcement of mythos, the AI hacking. So good we can't give it to you now. It sounds a lot like someone hired Don Draper from Mad Men and said, how do we hype this product? And you could almost picture don in his 1950s SU coming in. The hottest product is the one you're not allowed to have. What were your thoughts when you first started seeing the over the top headlines from Anthropic? That it alone had created the super hacking AI?
B
Yeah, I think that Don Draper analogy is perfect. And I was joking that Mythos is meant to be mythical and Fable is meant to be fabulous. And that's how they came up with the name. But then again, I'd done some research prior to that with some people in some of the top cybersecurity firms and they were talking about the impending coming of AI and sort of burgeoning effects of AI in cybersecurity. And when I heard that, my thing was, I don't know if this is pure marketing or if anthropic, by at least, if its reputation precedes itself, is actually putting its fingers onto something. Of course, it's making that whole idea that if it's scarce, you'll want it more. But scarce you want it more. For white good is very different from scarce you want it more because suddenly it allows script kiddies. And it reminds me of if you remember Joshua in War Games.
A
Yes.
B
Yep. And it doesn't even have to be a sophisticated hacker like Matthew Broderick, I think. So was the actor. Right. And it can be anybody. The question is, what happens if something like that is truly as these parameters are just going bonkers in terms of variety and specs and the most interesting convoluted matrices in the world. Does that actually really pose a threat? Is Anthropic doing something from like a Kantian categorical imperative perspective? Right. Some idea of altruism saying that if something like this were everywhere, would you want to live in a world where everything is just going to go berserk? So that's what my initial thought was that. And you know, that there's a mix of marketing, but there's also a mix of, I don't know, some. A bit of scary truth embedded in it.
A
That's the best myths. Right? The best myths have some element of truth. We think about the. The Iliad and the Odyssey for those reaching back to Homer's two epics. And we didn't know for the longest time that Troy was a real city. And so there were fantastical elements and there were truth embedded in that. And the narratives were always interesting. Right. About ego and pride and power and relationships. And what I thought was fascinating About Mythos was when I first saw this and I was deluged with media calls because I often play the role of a security awareness guy, translating tech to human. And the point that I made to the reporters was it's not just that these tools are so good at acting autonomously or the fact that they're doing this at machine speed, because we saw similar impact when fuzzing came out with vulnerability. Discovery and automation tools went large and we've been through this drama at a smaller scale. The difference is, in this particular moment, the sheer volume of bad code. And what I have been telling people is that we live in a digitally polluted environment. We live in what I will call, and those who may not be familiar, there's this famous story, I think it's New York or New Jersey, Love Canal, which was an industrial site that was horrifically polluted and it became one of the first EPA Superfund sites where it was going to take multi generations to clean up this industrial mess. And so it's not just that these AIs are good at hacking. They are. It's that there is so much more for them to hack on this side. So now we're here. OpenAI's got their hacking model. The Chinese have released their hacking model. From a public policy standpoint, are we in the arms race that everyone was so desperately trying to avoid or do we just continuously wander into it?
B
Yeah, I think you're absolutely spot on. Yeah, I think we are in an arms race. The question becomes. The question is a tricky one, right? Which is, remember the old mercatorial maps, where it's used to the places that you knew, but the terror that was unknown, right? Sic sunt draconis. We are the dragons, right? And to a certain degree, the frontier AI models remind me of that. Because oftentimes the weirdness of AI models, especially frontier ones, is that it's never deterministic. Right. If you pose a question, the same question is very much, what was it? One of those fractal geometry, right? Every time a drop of water falls, it always splatters in a different way. Nobody can figure out exactly why, even in the most controlled elements. Therefore, the question is, if it's non deterministic, where do the dragons lie? And who controls the dragons? Does the government control them or do companies control them?
A
And this is an interesting segue because government stepped in on Mythos and Fable. So all of a sudden we had this export control regime, which is typically for those listening. These were designed primarily to prevent components or actual Weapon systems from being shipped to hostile countries. These are sensible, necessary policy tools in the arms of government. I can't think of a time where a major American frontier flag wearing what we call a standard bearer brand company and of like a caliber of an Apple or a Microsoft, because I'd argue Anthropic and OpenAI are now there in that club. Their tool gets an export control. And it's not just no foreign countries, it's no foreign nationals. So even if you're working in the United States with a valid work permit, but you're not a US Citizen, you're not touching this code. And I have to think that was stunning for me from a policy standpoint to see that. But I wasn't shocked. I'm curious, Pratt, what was your take when all of a sudden we had Fable was released and then it was unreleased?
B
Yeah, they did that with Fable. And it was interesting because even when they did a limited release for particular partners, I think there was a company called SK Telecom in Korea. They released it to them. I think it was Mythos, not Fable. Fable has its own guardrails. Mythos is the. The one that is without any boundary conditions of sorts. Right. And when then they really realized that SK Telecom has some connection with China and therefore it ought to be stopped. And then that brought the question to mind, which is, is AI even deadlier than what we think of as a typical arms control would be? Is that the new arms, the very famous arms. And the man, right, is the. Is that the new arms? Is this something? And you hear this. Ukraine using AI, embedding AI into their drones to search for certain objects. Right. The US is now even contemplating buying a stake into an equity stake into some of these companies. That reminds me of what China would do.
A
Yeah, we'll talk about the economics of this because I think there's a lot of deep questions of whether the economics of the frontier AI companies work. And one of the things that I have become deeply concerned about is repeating all of the mistakes we made with the financial markets in the build up to the 2008 financial crisis. And all of a sudden that OpenAI and anthropic and Google and Microsoft and have convinced policymakers, through fear of missing out, that they now are the new too big to fail. And the average American or Canadian or European taxpayer is going to have to now be on the hook to bail these companies out because they Enron themselves with these incredibly complex accounting arrangements between data centers and chip makers and the bond market. This stuff is incredibly complex. And Jim's been covering in trending. He's doing his best not to have a story every episode or every week about the data center pushback movement. But when Aaron Brockovich is one of the lead people now, fighting against big data center like this has become a real thing for everyday Americans and others. But I want to stay on the policy side. So we have these export controls. And at first, when I saw this, at first, when I saw this come out, I thought this is a problematic policy position for the US Government because they were having open negotiations and talk about taking a stake in a competitor and they just handcuffed another company like that didn't look good. Plus, transparently, it was well known that there was a beef between the U.S. department of Defense, Anthropic and others. Was this revenge? There was a lot of big questions. And then OpenAI got itself pulled back a little bit in the same way, so at least fair play on that. And then as quickly as it started, it was over. But it was enough to freak out governments around the world. Ottawa, Brussels, you name it. All of a sudden, this idea that American tech, which has led the world for 30 years, the cloud hyperscalers are all American and dominant the global market, that they could be made to go away by government, which is not what we normally associate with the American experience, free enterprise, et cetera, from your standpoint, is that the biggest sort of fallout from the decision to pull these models back and then let them go back out, that it may have freaked out allies about the reliability of American tech?
B
It's such a difficult thing to answer. But you ask yourself, is AI the core question, is AI a weapon? And if AI is a weapon, should that become a part of our country's arms control? That is the biggest question to ask. Is AI a consumer good? Or is AI, in some variation, an arms in its own right? That ought to therefore be deliberated upon by the Congress and by the executive. That would then decide the fate of these companies. Now, of course, somebody like Ayn Rand would say, no, we want truly laissez capitalism. Let the companies decide what happens. But then on the other hand, you can have. I think we were mentioning a conscient perspective. Right now we need to ensure that decisions are being made for the good of the state or good of the people. And the government is the only one that can come to defense, come to the defense of the people. Only when things get so awry that there's no other way to handle it other than declare that AI is the new weapon of choice and that's I think there's maybe a poor Cicero. Do forgive me, I might be saying this wrong. There's this very famous line called salus populi lex suprema este. Right. The protection of the people is the primary objective of the state. And if protection of the people is the primary objective of the state, then the question becomes, all right, what can not protect a person? Can a piece of software be the next biggest existential threat that we face? If that's the case, then who is the one that steps in? Should we leave it to the companies to decide? And anthropic, of course is saying that of course you're setting a dreadful oftentimes a deadly precedent by saying we are the ones who will adjudicate on what you can release, even though we are being very canny about what we are releasing, how we are releasing. And then the government might say, I don't know, what you're doing is basically tempting people to go bonkers with whatever is out there.
A
Yep.
B
That's why the next arms race.
A
And what's interesting is Katie Musaras, who is one of the top thinkers that I always turn to when it comes to what do we how do we be responsible with technology, what is responsible disclosure, handling bugs, et cetera. And those who may not be familiar. Katie was the one who founded and helped get start the responsible disclosure program at Microsoft. She runs Ludus Security. Earlier today on LinkedIn she had written about this OpenAI hugging face incident and she said we're holding the new radium. Don't know what we're fully dealing with here, but it is radioactive in ways that we didn't understand. And she put forward some ideas around different ways that we have to contain this. So I would raise your Is it a toaster or is it an Apache helicopter weapon to AI to also is it closer to nuclear in the sense of the explosive potential, but also the fact that there are unknowns or in the early days of nuclear side. But Marie Curie did not understand that she was getting radioactive doses to the extent there we didn't know. We didn't have the concept of milliserverts and other things. And my wife is a radiological technologist, an X ray technologist. Like I don't pretend to understand radiation. But I turned to her whenever we're watching a documentary or movie, we watched Chernobyl and I'm like, is that real? She's like, yeah. And I don't know if we have those experts yet in AI to turn around and say, okay, was this OpenAI hugging face thing real? Like, how would I even know that? It's like trying to prove radiation. Or is this. They figured out a way to one up Mythos with their marketing by saying rai so good it broke out and hacked something. It's even super, super better than the area. I don't know what your thoughts are. Like, how do we prove if it's a toaster or an attack helicopter?
B
This mention of this is like radium. I think it's spot on. Remember reading about stories where during the first World War, they didn't know what radium did? Right? So they used to dip the. What do you call it, the little brushes to paint the watch faces. And they licked it all the time to make sure that the paint, the paintbrush tips, follicular tips were all straightened and they didn't know. The question is, I think that is such a good analogy. I was musing. I was thinking how incredibly prescient that kind of thinking is. That is the new radium. It is something that once upon a time we just. People just said, wow, this is so cool. I think they even advertise that having a little bit of radium in your diet might be brilliant for you.
A
That sounds eerily like everyone should be using AI all the time.
B
That's exactly it, Right? The question is, when things have this unknown potential for being either brilliant, a toaster or a nuclear device, what. What does society do and what should companies do? What should governments do if the government assumes control? I want the government to assume control only when they know exactly what they're doing so it doesn't turn into another Enron. Right. Or another buy out or buy into. And that is the essential question.
A
And what's interesting is one of the things for the cybersecurity today listeners is that there's always an undercurrent and a concern that a cybersecurity show is talking about politics. And to be clear, we're not talking about partisan politics at this moment. This is not a Republican issue or a Democrat issue or in Canada, liberal or conservative. It's not a partisan political issue, but it is a political issue when we think about public policy. And I think, Pratt, you said it well, government. And this is not a criticism of anybody in the White House. They don't know because nobody knows yet fully what this thing is. It bothers me that some people come out and they're like, I can conclusively, definitively tell you everything about AI right now. No, you can't. And the other side of that is the People that, that are deifying AI, that are treating it, they're anthropomorphizing it. I'm sure I butchered that word. But they're humanizing it in ways to give us metaphors and analogies that we can relate to. But it's not that it's not human, it's not intelligent the way that we are. And we don't know if it's a toaster or a nuke. But let's talk about the economics for a second because this is where things are also as messy as we don't fully understand what this technology is because we don't know what it is, we don't know how valuable it is. And so we've got this moment where the US government is signaling open weighted open source Chinese AIs are potentially about to be banned. If not, they can't legally prevent anyone from accessing and using it per se, but they can prohibit it from its use in commercial products. And on the other side, China is actually considering banning the export of its AI because it's maybe we are better and we don't want to give away our economic advantage, which the irony would be if they are doing what many alleged they are doing and the US government is deeply concerned about when it comes to distillation, then China saying we're not going to let foreign powers touch our AI is more like we're not going to let you do to us what we may probably have done to you. But this is unlike anything economically we've ever faced with the Internet. We didn't have these debates about aws. Maybe this is a vital economic resource that we don't want to have hyperscaler clouds available to others because we want to have the most efficient economy. And of course it is tied up into the de globalization of trade. We can't. This is all about who's going to have economic supremacy between the United States, someone said, and China on the other. And I'm curious, has this put it policymakers, business leaders in the weirdest, most uncertain technological environment of the last 50 years?
B
Let me try on seeing if I can even broach tiny bits of it. First part of the puzzle is there was this fantastic book written by somebody I've forgotten and I'm dreadfully sorry, but it was called the Cathedral versus the Bazaar, which was the story of open source versus closed cells software a long time ago that do we have a bazaar where we where the market decides what they want? Or should we have a cathedral where you have to say nominee patri before you enter, and once you enter, then you go to get a chance to visit the inner sanctum, right, the sanctum sanctorum. And I don't know really, I wish I had a better idea, but I have no clue whatsoever which model is better. I personally think that if what we talked about, the very fact that AI has a greater chance to be weaponized deliberately and with specific parameters in mind, then maybe a cathedral is the right place for it to be right. Or it should be shrouded and should be moated as a cathedral. But if it's a cathedral, then it goes into this very interesting question you ask government ownership and equity stake, because government is inherently public. Are you making the cathedral a bazaar? Because at the end of the day then whoever, any government, not only the current administration, but any government, ends up purchasing or buying an equity stake. Does that mean that therefore that part is a public good? Because at the end of the day it's being using public money to buy it. So that makes it a very complicated both philosophical, political, partisan issue. Should they then say based on whoever the administration is, we want certain parameters to be instituted? I remember being in China, been to China many times in my life. Once I was watching something on BBC International at my hotel and suddenly they said, I know about Tibet. And then suddenly the screen went white noise. And then I called downstairs and I called them and they said, no, I think the TV system is perfectly fine. And then by the time I even finished the call, the TV was back again, which was dynamic censoring going on. Should therefore AI models have dynamic censoring based on what any kind of government, any kind of administration wants or does not want to hear? So that becomes that incredibly messy and murky waters that you start venturing in. Whether it's open, weighted or not doesn't really matter. The question is who controls even the smallest piece of the puzzle that they can tweak? And given that an AI system, the parameters are interlinked, every butterfly flap can create swarming. Right.
A
I was just thinking about the butterfly effect. And the interesting thing is ask a Chinese AI about tian and square and you're going to get a non answer. But then what is the compound effect of that relationship being missed in that entire corpus? How does that, and not just that, but any kind of politically sensitive topic. And I don't feel confident anyone can tell me, because this goes back to what you were saying at the start. These are non deterministic chaotic systems. And the interesting thing is, of course I jokingly refer to Myself as the pop culture critic on cybersecurity today when we do the panels, and I keep reminding people of Jeff Goldblum's amazing character in the original 1990s, Jurassic park, and Ian Malcolm, that character, the chaos mathematician, he was telling John Hammond, the arrogant wielder of a technology he didn't fully understand, which at the time was genetic manipulation, and also overconfidence in IT systems while underpaying and not recognizing insider threat. Delicious irony. I often teach cybersecurity analogies using Jurassic park, but I've been thinking of late who John Hammond is. If AI are the new dinosaurs and we're living in Jurassic park and I can't figure out if it's us, the people that are so desperate and hungry to use these tools to advance our lives and make things easier, if it is these companies, the big tech bros. Selling it, if they're the John Hammond or if it's government, if they're John Hammond. But I'm struggling with that side and I love this cathedral or. Bizarre analogy. I think it's fascinating. And as a Canadian, you have to be keenly aware, we tend to be very arrogant of what we think we know about the United States transparently as a country. Maybe it's the older sibling, younger sibling thing, I don't know. But reality is we don't know. We don't know the full story of the American side. But as an outside observer, I think sometimes I have an interesting perspective and I see a fundamental battle between the very strong pull of national security which has run a multi generational pre Cold War, second World War, Cold War, post Cold war. National security is part of American culture. It's an important valuable part. And on the opposite pole is American exceptionalism, entrepreneurialism, free enterprise, the, for lack of a better analogy, the Protestant work ethic, raise yourself by your bootstraps, et cetera. And AI is forcing the most uncomfortable conversation I have ever seen as an outside observer in America. And it's. I don't think there's a middle ground. Does that make sense? Like it is. It's the cathedral or the bazaar.
B
There isn't. You're right. Just you mentioned this very interesting thing with Ian Malcolm and John Hammond and I personally think that the visitors are the ones that are going to decide how well Jurassic park runs and if it succeeds or fails. Right.
A
Hmm.
B
And because at the end of the day it's market driven, national security or not, AI is truly market driven. And to return one of the quips, it's very much like the song from Eagles Hotel, California. Right? We are all just prisoners here of our own device, right? In a master's chamber, we gather for the beast. We stab it with a steel knife, but we just can't kill the beast very much. Like, you can check out anytime you like, but you can never leave. AI is become a participle of life itself, and it is only going to enmesh itself and embed itself into our psyches with every single day extricating it from. So it's. If you're. If you bought an eternal past to Jurassic park, it doesn't matter where the genetic experiment has gone wrong or not. It's too late. We signed up for it. And that makes it so unique and such. The sort of the Dickensian thing, the best of times, the worst of times, right? The age of hope, the age of despair. And that is what it is. But we've already bit into that poison pill, right? We've already drunk from the chalice. There's no way we're getting it back. We're old. We've all been sequestered to live a life with AI Whether we like it or not. And what is going to be next? Different stereotypes. Sorry, Zone.
A
No, it's just a reminder. In Jurassic park, the people get eaten by the dinosaurs.
B
You stab it with the steel knife, but you just can't kill the beast, right?
A
What I love about the Hotel California reference is my understanding of the interpretation of the song is that it is a damning criticism of the music industry itself and the way that artists get locked into these contracts and everything else, which also has its own deeper playback into what tech we're going to get locked into. Pratt, this has been a fascinating conversation. I think what I loved about this conversation today is we didn't solve anything. So, any listeners who are going, well, David, I wanted an answer to these big, burning questions. I don't think we're there, but I think what we covered today is some of these issues have been wrestled with. You reference Cicero from Roman times. We have talked about Charles Dickens from the last major economic upheaval of the same rel. Significance. We think of Victorian England and, of course, our trip into Jurassic park and the Eagles. So, Pratt, thank you so much for your time today. It's been a pleasure. I hope to have you back on the show. Hopefully we're not dealing with another six months of this much insanity. But if Katie is right and we're in the new radium, we'll probably be having some deeper chats still to come.
B
Thank you very much. It's been absolute pleasure. And I have to say that if we're dealing with frontier models, frontiers are always being discovered, and it's never the destination. Right. So, yeah, it's. It's absolute pleasure. Thank you so much for giving me the opportunity. Enjoy yourself. And brilliant chef. Thank you very much.
A
Thank you so much. All right.
B
Thank you very much. Enjoy yourself. Best regards to you and your family. And best regards to Jim and his family, too.
A
Will do. Thank you so much. Take care.
B
Take care, boy.
A
Cheers.
Cybersecurity Today: David Shiply Interviews Pratim Datta, PhD from Kent State (July 25, 2026)
In this engaging episode of Cybersecurity Today, David Shiply sits down with Dr. Pratim Datta, a professor at Kent State University specializing in cybersecurity, AI, and digital transformation, to dissect the whirlwind changes in AI and public policy over the past six months. Their conversation navigates the explosion of cutting-edge AI tools like Mythos and Fable, government intervention and export controls, the blurring lines between technology as consumer good or weapon, and the profound uncertainties now facing policymakers, companies, and society at large.
This episode does not present clear solutions but rather exposes the tangled, overlapping uncertainties facing technology, policy, and society. Shiply and Datta artfully draw on historical, literary, and pop-culture references—Cicero, Dickens, Jurassic Park, and Hotel California—to underscore that AI is simultaneously exhilarating, terrifying, and deeply inscrutable. As Dr. Datta wryly puts it: the frontier is “never the destination,” and for better or worse, society has already taken its first irrevocable steps into this new, unpredictable landscape.