NVIDIA's Justin Boitano makes the case for open-source AI as asymmetric defense and previews Nemotron roadmap

Jul 27, 2026 · Full transcript · This transcript is auto-generated and may contain errors.

Featuring Justin Boitano

Speaker 2: Who wants that? Sometimes I want my iPhone snapped.

Speaker 1: Diego said John needs someone to clear his desk with Diet Cokes every twenty minutes. Can I get a recycling bin over here? You're only on your third. Yeah. I'm almost This is a typical typical day for Well, it's an important day. We have Justin from NVIDIA. He's the VP of enterprise AI here to talk about NVIDIA launching the Open Source AI Alliance. Justin, thank you so much for taking the time to come talk to us.

Speaker 12: Yeah. Thanks for having us. So can you start

Speaker 1: by giving I mean, the the we we we discussed the letter. I think a lot of people have read it. But what what is your elevator pitch for the Open Secure AI Alliance, the letter, how they interact, like, the overall project here, the goals.

Speaker 12: Yeah. I think well, let's just say there's been this moment in the industry Mhmm. Especially with this incident that happened at Hugging Face Yeah. Where there's just this collective awareness across all the industry leaders that, you know, doing a lot of the work in cybersecurity out in the open where we can look at open models, open harnesses, open safety evaluations Mhmm. As an industry is gonna give basically the the broadest collective defense, of our organization. So, that's why we put the letter out there. That's why all these companies are kinda rushing in to talk about sort of the importance of, of this initiative. It seems like it's going extremely well.

Speaker 1: I I totaled it up. I think $1,818,000,000,000,000 dollars of market cap has signed on across something like 35 companies and more. I'm interested in what you are there any other outcomes, or is this purely just avoiding a bad outcome? Because the whole framing is is is basically, don't ban. Don't do something. It's don't take an action here. Allow the status quo to continue. Is that the correct formulation of the of the proposal?

Speaker 12: Well, I think it's a a recognition that you always wanna give the defenders of enterprises across Mhmm. Really critical industries, financial services, energy, telecommunications, an asymmetric advantage to protect their infrastructure. And the best way to do that is you give them, you know, state of the art frontier open systems that they can, you know, scan, remediate, patch their infrastructure. Now they should always have the advantage because they understand the code, the configurations, and how they have their infrastructure running, but they need access to the tools to basically get ahead of any potential security issues.

Speaker 1: Okay. I guess, like, the the the steel man of the other side is that this isn't an asymmetric advantage to the to to the to the organizations that you described. It's actually a perfectly symmetric advantage. The attackers will also have frontier open source, like great open source tools. And if we if we allow open source to proliferate, at least it will be balanced. But can you explain a little bit more about where the asymmetry on the defender side comes? Because that sounds amazing. We want the defenders to win, but it feels like if everyone is using the same tools, it's actually just a level playing field and this could just be a battle. Could still win. Could be fine. But what what's driving the asymmetry?

Speaker 12: Yeah. You gotta remember when when you're running a service Mhmm. And you have terms of service, like, you know who's who's accessing that service. Yeah. And there, you're putting additional guardrails on there on on safe use. Mhmm. You can also if there if people start to misuse the service, you can quickly patch guardrails and basically ensure that people are using the service appropriately. So so that in in and of itself should give the defensive teams the ability to run, I'd say, these these better capabilities to clean up their infrastructure, patch their infrastructure, and then service providers that are hosting any of the models, you know, should should run them with appropriate guardrails.

Speaker 1: How how do you think the the equilibrium plays out if sort of, you know, the companies get, like, big companies get access to advanced open source models. So they're patching their systems. They're they're doing stuff. But there's still a lot of attackers out there. And there's this weird scenario that people have been talking about where a small business that might have a credit card stored here or some piece of personally identifiable information stored in a less secure system. Now they're responsible for spinning up an open source cybersecurity defense system. Like, what's the equilibrium that keeps the the long tail of organizations secure?

Speaker 12: Yeah. You've gotta still pair, you know, openness with strong safeguards, like rules on malicious use, laws that prevent against malicious use, and then obviously rapid remediation of anything that you know that's going on. The conversation around open models is no different than the conversation around, I mean, I think open software. Yeah. And you think of open software, whether it's Linux or Kubernetes or PyTorch, that that open software, you know, built the foundation of our economy. 80% of our digital economy is powered by open source. Mhmm. I'll say good stewards of open source software can sort of debate open standards in an open way. They can look at evaluations. They can look at patching and remediation, and they can work collectively for the defense of The US economy. I think we've got to look at models the same way. As soon as models are out there in the, I'll call it, the public domain, you can fork them, you can patch them, and you can remediate any issues that cybersecurity people find in those models. The goal of this organization is to have those conversations out in the public. I think it's an important conversation for all of us to have, but we want to make sure, again, that you have, I'll say, a diverse set of tools at your disposal as a, as a cybersecurity defender so that, you know, if a model, refuses to do the work that you needed to do, you have other options to continue to defend your organization.

Speaker 1: What like, who do you think will step into the role of, like, model evaluator or model tester? Because we were we were just talking with Dean Meyer from Sequoia Capital, and he was, you know, illustrating a possible scenario where there's, like, a backdoor in a model or some nefarious thing sort of hidden below the surface. So the model still tests well on benchmarks. You deploy it, and then over time, it does something nefarious. It feels like, again, that's another big burden to potentially put on a small business. But if there's some sort of, you know, American company that steps up and validates and tests, Maybe there's an even balance there. How do you see that playing out?

Speaker 12: Well, I I think, you know, organizations like Red Hat have done this open source software. Right? Sure. Where they cleared up CVEs. They they provide the commercial support to enterprises. Mhmm. I feel like it creates an opportunity for businesses to step in and be able to do the same thing with open models and provide the same commercial patching and support into enterprises. I think that's a market that will emerge as we go forward. Ultimately, think allowing, I'll call it, cybersecurity professionals to continue to pen test and understand the limits of these models is what's going to allow us to build that lifecycle to do patching and remediation of any vulnerabilities that can exist in these model weights. Now the fact that they're open means you can test them and understand limits of them. The challenge is with a lot of the model weights that might be hosted. The terms of service prevent cybersecurity people from researching and looking for any backdoors in those as well. The problem doesn't go away whether it's hosted or open. Sure. They can exist. I think spotlight of having more cybersecurity professionals evaluating these things is just going to lead to better collective defense.

Speaker 2: I don't know how much you can speak to what the Nemotron team is doing, but broadly, what should organizations expect from Nemotron, the family of models, over the next, let's say, six months?

Speaker 12: Oh, man. I don't know that I can talk about where we're going. But generally, our approach has been like, let's, again, do it all in the open. Let's basically put the datasets out there that we're training into these models so people can understand the data that blends that went into the models. Let's put the model weights out there. Let's put the training techniques out there and the evaluations out there and basically use that as a foundation for building custom intelligence into enterprises. That's the other part of the conversation that's lost is these open models are critical for enterprises basically building their own intelligence and basically maintaining, I'll call it, a reinforcement learning wheel or flywheel on these open models so they can maintain their competitive advantage. Providing that foundation of data and open weights and data blends gives enterprises that. With Nemotron, they're really language models, but we have a bunch of other domains and models. We have Kosmos, which is world foundation models. We have Alpamayo for autonomous driving. We have Groot for vision language action models for robots. I think across industries, the idea of having these open models to build the startup ecosystem, allow enterprises to domain adapt them and build their own intelligence is really important really for the for the future growth of our industry.

Speaker 1: How important are can you give us some context on what you're seeing or hearing from other business leaders about the value of open source purely economically. Just we went through this token maxing boom. I think every enterprise leader feels that AI is valuable, but it can be very expensive. How are they thinking about efficiency

Speaker 12: right now with the current cost to benefit trade offs, and how does open source change that? I mean, I can I can put my NVIDIA hat on here? We we are the same way. Right? We use all frontier models. We love the frontier models. Yeah. They are they're amazing for for driving efficiency and how we do, you know, software development and chip design and how we run a competitive business. But the modern way to build applications now are really an ensemble of models where you want to use the frontier for where they're unique and they add differentiated value. Like a really complex agentic plan, you want to run through that frontier model, and then you wanna use the the open model weights for things that are more trivial, like document summarization. And the two can complement each other to drive a lot more cost efficient applications across the enterprise. Yeah. And then anything that's been fine tuned on your particular data, that example from thinking machines with Bridgewater's,

Speaker 1: like, information pipeline, obviously, they got incredible performance at great at very low cost because it was a a unique use case that was gonna run on a continuous basis, and so they were able to get a lot of value there. Just common sense. It wouldn't

Speaker 2: make sense to to hire you and then have you just be a BDR doing cold emails. You know? Like, you sure it wouldn't be a very efficient use of It's a great analogy.

Speaker 1: Sorry.

Speaker 12: Yeah. Sorry. I was just gonna say, yeah, I think I think your point's spot on. I think, you know, there's a bunch of other, you know, model makers. Like, like, TML is a great company, Reflection, you know, Runway, you know, many different model makers across different domains. I think you want a rich ecosystem here, you know, of startups, you know, building the future of what's possible with with this industrial revolution going on with AI. So we're just happy to, you know, advocate on behalf of the open ecosystem, but really it complements, you know, the closed ecosystem.

Speaker 1: And all of it sort of has its its unique value here. So the alliance is, like, pretty huge at this point. Do you want to grow it a lot bigger, or is this a solid enough base to go where you wanna go next, or will this be something that just continues to grow? What do you think?

Speaker 12: You know, I think, the the the inbound requests around this is, is is kinda blown us away Sure. By the the appetite and the interest. I I think, ultimately what we want to do is kind of work as a community and share sort of best practices. We also, with this, we put out a new agent harness that we think is phenomenal at you know, reasoning. It's great at coding, and it's and it's great at cybersecurity tasks. And so if we all sort of share advancements in the open, we can build, you know, the best technology together. And and, you know, I think some of the things that we'll keep working on as an ecosystem is I mean, to your point, what are the evaluations that we should be building? You know? How do we test and, you know, I'll call it open models and and look for, I'll say, safety issues in those models. How do you start to build, I'll call it, more cyber ranges that you put agents through to understand how truly capable they are? I mean, I think part of the part of the challenge with this cybersecurity discussion is it's been over indexed on, I'll call it, bench maxing for vulnerability discovery. Vulnerability discovery is not the same as going through an attack chain. So, you know, I think we've just got to have more more, like, sane conversation in the open as an ecosystem on, you know, what are the right ways to safeguard this stuff and and put it to work and to drive the efficiency that it can bring us, you know, across every business.

Speaker 1: Thank you so much for taking the time to come. Yeah. Great to meet you, Justin. Great to meet you. Yeah. Thank you so much. Have a good rest Goodbye. Of your

Speaker 2: That's

Speaker 1: our show, folks. Thank you so much for tuning in. We will see you tomorrow. There's a lot more news, but we can go through it tomorrow. Starship launched and there's a beautiful video that somehow got taken down, so we can't even share it. But you can go find it. There's some cool stuff there. Anyway, do Go the five

Speaker 2: have the best afternoon. Go have the best afternoon ever. Have the best Monday afternoon ever. Thank you to Cooper

Speaker 1: for always coming in at the market close. Good crew Get in like chat. Thank you so much for tuning in and chatting. We do read it. It's a lot of fun. Leave us five stars on Apple Podcasts and Spotify. Sign up for a newsletter at tbpn.com, and we will see you tomorrow at 11AM. Good bye.

Speaker 2: We love you. Goodbye. Goodbye.