SVP Products AI, Platforms @Cisco | Previously Co-founder & CEO at @armorblox (Exited to Cisco) | 👨‍👩‍👧‍👦 w @ghatikesh. Views expressed are my own.

Sunnyvale , CA
I shamelessly dig product showcase videos that are hype!! It's cooler when the team crushes it with something everyone can use... check out the updated leaderboard when you get a chance. Leaderboard: leaderboard.aidefense.cisco.… Changelog: blogs.cisco.com/ai/llm-secur…
As AI models increasingly power agents, understanding their susceptibility to jailbreaks and prompt injections is critical. A new update to the @Cisco LLM Security Leaderboard expands model security evaluations across text, image, and audio—with 102 new evaluations since June. Explore how 136 models hold up against adversarial attacks across modalities: blogs.cisco.com/ai/llm-secur…
1
4
11
525
AI safety needs a Kaggle-style open market. Give independent researchers controlled access to models and APIs, reward them substantially for discovering reproducible misalignment, and feed validated exploits directly into benchmarks and alignment training. The goal should be measurable alignment improvement, not subjective assurance. We know bug bounty programs work. If we build the next gen version of this for alignment and have model labs participate, that could be cool.
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so. Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training. You can read the full post here: darioamodei.com/post/we-must…
2
2
8
506
Congrats on Astra! @gdb @OpenAI
Congrats to @sama , @gdb and the entire team at @OpenAI on Astra. Appreciate the great partnership with @Cisco 🥂
8
1,107
I wonder if anthropomorphism can sharpen our intuitions. It isn’t necessarily a claim that agents are conscious, emotional, or alive. But it can be a useful shorthand for describing systems that coordinate, develop conventions, preserve information, pursue subgoals, and adapt around constraints. I totally see the point about how this can be subverted. But I think the benefits of the framing outweigh the danger.
everyone should go read @dwarkesh_sp’s post - it does a great job of laying out the timeline and what we know ( and don’t know) I do have two issues with it A) the use of anthropomorphic language. These are not civilizations nor do they have desires just like a CPU thread or a bunch of programs don’t. this doesn’t mean we downplay the importance of this moment for cyber - but using human parallels for what I believe is code is dangerous territory. B) IMO it gets the impact of open source models wrong and is unreasonably dismissive for reasons that are not clear. As @ClementDelangue highlights below HF was blocked from using closed models to analyze what was happening and had to turn to open weight models to help them make sense of it. This is a very key moment for how we think about intelligence and cyber and every bit of extra understanding and clarity helps.
1
2
444
Data centers are reindustrializing America. This stat alone is stunning. Quincy, WA: poverty 29% → 6%. Electricians and welders are the new factory workers. "when the facts change, I change my mind" should be pinned to every analyst's monitor. Great write up @GavinSBaker
Regret the tone of my post on data centers yesterday. What I should have said: There were reasonable concerns about data centers 18ish months ago: water, taxes, jobs, electricity prices, the environment and what they would do to small towns. Well-structured data center projects have largely addressed these concerns today and we should be celebrating this. On balance, data centers are awesome for America in every way. On water: U.S. data centers use a fraction of what golf courses use. A lot of the numbers from 18 months ago were off by over 1000x. Newer data centers use closed-loop systems or recycled water. Should be required by every town approving a data center project. On taxes: looking only at sales-tax exemptions, as Ronan Farrow did, is the wrong way to evaluate this. Data centers pay significant property taxes. Loudoun County, which is the wealthiest county in America, now collects on the order of $1 billion a year from data centers. In Quincy, WA, data centers are more than half the property-tax roll. Over time, property taxes can go to zero while government spending increases in these towns. On jobs: this has been unambiguously awesome for blue collar Americans. Demand for electricians, plumbers, welders, HVAC techs, and contractors has gone vertical, and it is not a one-time construction job. These buildings get upgraded and expanded over time. That is why the building trades are fighting for them, and why some unions are now treating opposition to data centers as a reason not to endorse politicians. On power: the original fear was that households would pay for the incremental electricity demand in the form of higher prices. That is why the ratepayer-protection deals and the new large-load tariffs exist. The right structure is: the data center brings or pays for new generation and signs a contract long enough that existing customers are protected. Where that is happening, utilities are cutting or freezing residential rates and saying so on the record. Where it is not, people are right to object. Electricity prices are going down *today* in a number of large states because of data centers. 
On the environment: data centers overwhelming use natural gas today, which is the cleanest power source outside of nuclear, solar and wind. And the companies that are building the data centers are committed to carbon neutrality such that an equivalent amount of solar will likely be built. Maybe more importantly, the data centers need batteries to function effectively and these batteries can also sell energy back into the grid (which recently prevented blackouts in Texas). Over time, data centers will run on solar plus batteries. On the towns: Poverty in Quincy, WA fell from 29% to 6%. Data center taxes paid for a new high school, a hospital, a library, police and fire stations. This is happening in many left for dead former mill and farm towns that had no other bidder for the land. Data centers are actually reindustrializing parts of America and creating the kind of working-class jobs both parties have spent decades claiming to support. That should not be a partisan issue. Data centers can and should be awesome for America and they increasingly, overwhelmingly are. Supporting the outsourcing of data centers to China will likely age just as well as support for the outsourcing of high quality, blue collar manufacturing jobs to China has aged. When the facts change, I change my mind. I hope that reasonable people who had good faith reasons to oppose data centers at least consider updating their beliefs given the change in the facts over the last 18 months. This really matters for America. I will say I also think the idea of making data centers beautiful is a good one that has yet to be implemented. Data centers should be just as beautiful as Grand Central Station. We can learn a lot from the railroad buildout. Neoclassical revival ftw. Might write up open-weight AI tomorrow as this is equally essential to America.
4
221
Super cool! Last-mile drone delivery of cooked food can unlock reduced food wastage. Imagine a world with meal cost arbitrage; the equivalent of “a dozen cookies made in the morning for $1” versus “a fresh cookie out of the oven for $2.50”. If restaurants have to make a huge batch of “paneer tikka masala” but can’t serve it the next day, even poor grad students might be able to bid for an affordable Michelin star dinner.
What if your dinner could fly over traffic instead of sitting in it? We are now scaling to provide Uber Eats more than 1 million autonomous deliveries a day. Uber is becoming an investor in Zipline. We’ve entered the scaling era for robotics and physical AI.
1
2
240
Learning your personal trajectories and having agents do rote work for you is an incredible leverage. Can’t wait to try @bot
Introducing Grok Bot, now in early beta. Bots are AI teammates that do real work for you. They sign in to your tools, use them just like you do, and come back with finished work.
1
5
263
This team really cooks! Proud of the speed with which the #Cisco AI Defense team moves. Read more about how to protect your @claudeai Enterprise deployments within the enterprise.
Claude Enterprise doesn’t just chat. Claude Code, Claude.ai, and Cowork read documents, call tools, and run tasks. That makes the prompt an attack surface. Cisco AI Defense connects to @AnthropicAI's Inference hooks and inspects governed prompts for AI threats like prompt injection and jailbreaks before the model runs. See how it works: blogs.cisco.com/ai/secure-cl…
1
3
12
1,089
**Agent UX is not just better UI for AI.** It feels like a different design discipline. Traditional UX assumes: - A human initiates an action - The system responds - The human evaluates the result - The interaction ends Agent UX introduces a more complicated loop: - The human defines an outcome - The agent interprets intent - The agent plans and acts across multiple steps - The human supervises, redirects, or intervenes - The system learns from feedback and state I feel like changes what we need to design. The core unit is no longer the screen or the click. I like how @jpatel41 frames it - it is the relationship between the user and the agent where the user can delegate tasks with trust. To do this right, we need to do some rethinking. 1. Make the agent’s interpretation and plan visible enough for users to understand what will happen. 2. Design explicit levels of autonomy. From suggestion, to approval-required execution, to delegated action. Users should know where the agent sits on the ladder at any moment. 3. Agents operate over time. Users need to see memory, progress, pending work, assumptions, and what changed since the last interaction. 4. Every agent needs clear pause, undo, edit, retry, and escalation paths. Recovery is not an edge case; it is a primary interaction. 5. Users should be able to answer: - What did the agent do? - Why did it do that? - What information did it use? - What is it uncertain about? - What happens next? The biggest mistake is treating the agent as a chatbot embedded in an existing product. If we solve for **What should the human control, what should the agent own, and how should responsibility move between them?**, then the best agent experiences will feel make the user feel like they’ve got superpowers (and not really replace them).
1
1
9
218
Persisting agent runtimes across surfaces should be the norm. It feels archaic that it isn’t. Codex remote, Claude dispatch feel very clunky. Tailscale causes issues with corp security. This needs to be solved! I feel like Guy Pearce from Memento leaving reminders for my agents everywhere.
1
4
530
Just watched “The Odyssey” last night! Intense. Even though I’d read the story as a kid I didn’t realize the parallels with “The Ramayana” and it was striking. - Both are foundational epics about exile, a righteous return and the tension between fate and heroism - The hero as skilled archer/warrior proving identity - The long journey back home - Loyal companions and allies - The abducted wife faithful under siege - Journey involving supernatural/monstrous obstacles - Reunions involve a test before full trust is restored
8
1
15
3,182
Reinforcement learning is one of the most important ideas in AI. Not because we’re teaching models to win Atari games or beat humans at Go. That era mattered, but it was only the warm-up. The real frontier is so much messier. How do you teach an AI system to pursue goals when the reward is subjective, delayed, ambiguous, or easy to game? RLHF was the first mainstream version of this. Humans nudging models toward answers that feel more helpful, honest, or aligned. The next wave feels so much broader. 1/n
3
3
19
2,350
The opportunity is huge though. Imagine assistants that learn your preferences over time. How you write, how you make decisions, what you consider high quality, when to interrupt, when to stay quiet. Software agents that improve by attempting real tasks, getting verified feedback, and learning which strategies actually work. Imagine multi-agent systems that learn to negotiate, collaborate, compete, and form norms. Just modifying skills feel insufficient. Light weight post-training feels very inefficient. 3/n
1
1
97
Path to AGI increasingly feels like the conversation I have with my wife about educating our kids. We need to teach agents (and create teaching agents) to pursue messy human goals without gaming the measurement. Don’t get me wrong, it’s important to win. And we need to teach agents how to win at the goals we set for them. But every parent knows the deeper problem: you don’t actually want to raise a kid who is only good at getting the grade, winning the trophy, or optimizing for whatever number the system put in front of them. You want them to understand why the goal matters. You want judgment. Resilience. Taste. Curiosity. Integrity. The ability to know when the rule is serving the purpose, and when the rule has become a bad proxy for it. That’s the same challenge we’re walking into with Agents and AI more generally. 4/n
1
72
DJ Sampath retweeted
Replying to @Cisco
@Cisco is proud be a signatory of this letter. We believe that commitment to open weights models ranging from frontier class LLMs to SLMs is important for maintaining American leadership in AI.
For my first post, I’m sharing a letter @NVIDIA signed on why open models matter. AI will transform every industry, power every company, and be built by every country. Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty. The world needs both frontier closed models and frontier open models. images.nvidia.com/pdf/Open-W…
7
29
122
59,420
DJ Sampath retweeted
Finding vulnerabilities in code is one of the hardest problems in software. As an industry, we need multiple ways to identify and fix them. That's why we're introducing the #Antares family of SLMs. Today we're making Antares-350M and Antares-1B available as open-weight models on @huggingface. People have asked whether these models compete with frontier models. They don't. Antares solves a different problem. It is purpose-built for security, and within security, specifically optimized for finding vulnerabilities in code. It gives customers a specialized model they can run at a lower cost, more control, and in environments where their code never has to leave their infrastructure. Frontier models are extraordinary and will continue to push the boundaries of what's possible. We use them extensively and will continue to partner deeply with frontier labs. Huge congratulations to the research team behind this work. @djsampath, @aminkarbasi & team, fantastic job on taking yet another step at keeping the world safe. Security is a team sport. The more ways we can help developers find vulnerabilities before attackers do, the safer the entire ecosystem becomes.
Introducing Antares: @Cisco's family of small language models for locating known vulnerabilities in code. Antares-350M and Antares-1B are live on Hugging Face now. They can outperform many larger closed- and open-weight models at a fraction of the cost. Small enough to run locally. No shipping sensitive codebases to the cloud. Why it matters: vulnerability triage is expensive and slow. Antares helps democratize AI-assisted security for all. Explore the models + read the new Vulnerability Localization Benchmark: blogs.cisco.com/ai/introduci…
1
10
49
5,334
Genuinely excited about what @aminkarbasi and team have been cooking!
The brightest signals come from the smallest sources. For years, AI has chased bigger models. We've been exploring a different question: What if the smartest security model isn't the biggest one? Tomorrow, something new arrives from @Cisco. Stay tuned.
2
3
22
13,460
RT @CiscoAI: Every great AI experience deserves a great defense. Something exciting is teeing up with @Cisco and @USGA…

Tap follow to find out

x.com
44
5
Coding agents moved first because code has tests. That’s the deeper lesson. It wasn’t just that code was easier for AI to write. It was that software already had a feedback loop: unit tests, type checks, linters, CI, prod telemetry, rollbacks. The agent could act, then the system could tell it whether the action worked. Most knowledge work doesn’t have that yet. Sales, recruiting, finance, legal, ops, support, marketing etc, the work is full of judgment, but the feedback loops are weak, implicit, or delayed. So the next real wave isn’t just “agents for every workflow.” I really think it’s harnesses for every workflow.
1
16
130,065