Intelligent CIO Europe Issue105 | Page 18

CASE STUDY
The idea is that you can run the technology with a sovereign provider or even on your own premises. The technology can run across all these different scenarios and you can decide which approach is most appropriate for your business.
You might decide that most of your workloads should run in the public cloud. But if something changes, whether that is a new risk, a change in the geopolitical landscape or something else, you might decide to run more of those workloads locally with a sovereign provider or even bring them back in-house.
The important thing is having that choice and making it as seamless as possible to move between these different environments.
If you had to distil Red Hat ' s unique contribution to the EMEA sovereign AI landscape into a single, ultimate differentiator for a CISO, CIO or other IT decision makers, what would it be?
I think it is openness. Everything we do is designed to give you control and choice. That openness means you have control of the technology, you can see how the technology is built and you can contribute to that technology, which is unique.
I work for Red Hat, but I am a strong advocate for open source more broadly because open source allows us all to move faster. It allows us to leverage the ingenuity, capabilities and skills of many people across the world. We all benefit from open source. The differentiator is how you use that technology.
What Red Hat is doing in AI is pushing for that openness, enabling you to run your models locally and maintain control over them. We have invested heavily in enabling even the largest large language models to run across multiple architectures rather than restricting customers to one.
The aim is to lower the barriers and level the playing field so everybody can use AI and make the most of it. AI is still an emerging technology and it is evolving incredibly quickly, so the question is how we enable people to use these technologies as quickly as possible by democratising access to them.
Through Project Lightwell, Red Hat and IBM committed US $ 5 billion to secure open source dependencies. As threat actors leverage AI to exploit vulnerabilities in minutes, how does this initiative shift the advantage back to enterprise incident response teams?
The reality today is that we are seeing a huge number of vulnerabilities being discovered. We saw Microsoft release a significant number of patches recently and, in the Linux world, we are also seeing a large number of vulnerabilities being published and patches being generated.
What is happening now is an acceleration in the use of AI to find vulnerabilities. But a vulnerability without an exploit isn ' t necessarily the problem. The bigger issue is how quickly those exploits can now be created. From the moment a vulnerability is discovered, people are using AI to help write exploits and we are increasingly talking about hours or days.
To put that into context, it used to take three, six or nine months to go from discovering a vulnerability to developing an exploit. Now it can take days. That means that from the moment a vulnerability and an exploit exist, organisations need to be able to react very quickly.
This is where Project Lightwell comes in. It originated partly from conversations with customers that were using AI to discover thousands of vulnerabilities and coming back to us asking whether we could help fix the open source software where those vulnerabilities were being found.
In an ideal world, everybody would continuously upgrade their systems and move to the latest versions, but that isn ' t the reality for most businesses. There is a huge amount of technical debt and organisations simply cannot update everything at once.
There is another challenge. Traditionally, we haven ' t tackled every vulnerability in the same way. We focused on the highest severity vulnerabilities, addressed the medium-level ones where appropriate and often accepted the risk associated with lower-level vulnerabilities. AI is now finding ways of combining multiple lowerlevel vulnerabilities to compromise systems in ways that we didn ' t necessarily see before.
What we are doing with Project Lightwell is taking some of the work we have already been doing internally to protect the Linux kernel and our own systems and using it to help customers secure the open source software they rely on.
At the same time, we are working with organisations across the wider open source community because not everybody has access to the resources that we have. When we talk about the overall investment we are making, it isn ' t only about using AI. It is also about the engineering resources that Red Hat and IBM can bring to fixing these problems.
Hopefully, that will help the whole community in the long run. But unfortunately, I think we are entering a period where things are going to get worse before they get better. •
18
INTELLIGENT CIO EUROPE www. intelligentcio. com