a16z Sep 18, 2026 1h 8m 46m saved
With Ali Ghodsi, CEO of Databricks, which sells both the data platform and the security detection product he says are now converging into one market
In 2018 and 2019, Ali Ghodsi said, the gap between a security vulnerability being published and being used in an attack ran to two or three years. By 2022 it was eight or nine months. It is now hours.
That is his answer to the question the episode was called to discuss. The argument in public is about existential risk and slowing down the frontier; Ghodsi puts existential risk near zero and says the real exposure is that the world's infrastructure is insecure and human security teams cannot keep pace.
"Now if you look at the curve from 2022 until now it's down to like basically hours."
Ghodsi runs Databricks as a private company at scale, resells frontier-model capacity to its customers, and sells the detection product that puts him in the security market as well as the data one. He also spent the hour disagreeing with his interviewers about how the public argument has been conducted.
The full interview is covered here so you can skip it. 69 minutes of audio, 23 minutes of reading.
Here are the 16 arguments that matter.
Key Takeaways
The gap from a published vulnerability to a live exploit has gone from years to hours since 2022
Ghodsi puts existential AI risk close to zero and says talking it up does real harm to the public
He calls "pacing" a public-relations error, because a slowly built weapon is still a weapon
His four conditions for real recursive self-improvement are all failing: frontier runs are getting slower, costlier and more brittle
Most enterprises are running Microsoft Copilot and a chatbot, not agent fleets
The blocker is context, not intelligence — a frozen frontier would barely affect enterprise value
Databricks' own knowledge graph runs to millions of nodes and is bigger than any customer's
The same model on a different harness costs 2x, which is why Databricks built a multiplexer
Open source is about 5% of spend but over 60% of tokens, on the hosts' numbers
Over 90% of databases created on Neon and Lakebase are created by agents, not people
His P doom: close to zero
1. Don't Frighten the Public
The interview opened on the public argument between the AI labs, and Ghodsi began with what he thinks leaders owe the people listening.
His first principle for anyone with a platform
leaders have responsibility to not freak people out unnecessarily unless there's really really good reason
Ali Ghodsi
Talking about scenarios in which humanity is wiped out is irresponsible without cause, he said, because people are in different places mentally and it can tip them over. His assessment of the cause is blunt.
Where he puts the probability
But I think that right now the existential risk is close to zero. So why freak everybody out?
Ali Ghodsi
Technical nuances in AI research can be discussed by researchers, he said, without going on television or posting to millions of people that there is a 10% chance humanity is wiped out. He said it causes harm to people who are not close to the detail.
One of the hosts described his sister, a schoolteacher in rural Arizona, texting on Sunday to ask whether she should prepare her cabin for the AI apocalypse and when he was arriving. The same host noted Elizabeth Warren calling for a pause in AI development, following Bernie Sanders working with Steve Bannon, and argued that the political machinery now spinning up may work against the goals of the people who set it off.
Ghodsi's response was that politics is running on both sides of the argument. On one side are people who want clean initial public offerings and returns and would prefer everybody stopped talking. On the other are people working out how to weaponize each statement, plant stories and push threads. Both have resources and connections.
2. Pacing Was a PR Mistake
The hosts' framing was that this is a public-relations failure rather than a disagreement about substance: self-regulation is normal, and saying security and safety matter with some oversight is sensible. The word was the problem. "First off, it's orthogonal to safety and security. Like you can slowly build a weapon. That's not different than building a weapon."
Ghodsi agreed the presentation failed, and on the substance he read the underlying document as sensible. His reading of the incident everybody cited is that the labs were not watching what their own reinforcement-learning runs produced.
On the specific failure
they should have paced they should have been much slower in that particular incident
Ali Ghodsi
He made the case that pacing is simply what every mature company already does. Databricks has a legal department and a security department that slow everything down, he said, including a podcast appearance — reviewing the script, deciding what can and cannot be said, requiring everything said to be materially true.
Applied to a training run, that means a security team sitting with the run, watching the monitors while millions of GPU hours of agent activity go by, which would slow it down a great deal.
The hosts' objection was about how second-order language works when people are afraid, and their preferred version was Mark Zuckerberg's framing, which led on security, self-regulation and why a release was held back. Their complaint about the alternative was that it led with pacing rather than securing the frontier, and satisfied neither the people calling for a pause nor the policymakers.
3. Tragedy of the Commons
The obvious retort is that a company worried about the pace could simply slow down. Ghodsi's answer was that no competitor can move first.
The question he says gets asked in bad faith
There's this like, hey, if you want to stop, if you want to go slower, why don't you go slower?
Ali Ghodsi
As a business leader he understands the problem, he said: he is competing and wants to win. Voicing the labs' position, he gave both halves of it.
Why nobody stops first
So like I'm not going to stop unilaterally. I'll be a sucker.
Ali Ghodsi
And what is at stake for them
I'm not going to stop racing because you know there's IPOs at stake.
Ali Ghodsi
Which is why, he said, they are asking to be stopped: put guardrails around us and we will follow the rules, because otherwise the secure option costs us the race. He also said there is personal animosity between some of the people involved.
4. Four Conditions for RSI
The mechanism people at the labs are worried about is recursive self-improvement, usually shortened to RSI: a model that improves itself, generation after generation. Ghodsi separated that and superintelligence from the technology in front of him, and said the book that popularized the idea describes something he sees no evidence of.
His view of the destination
I think that super intelligence that idea from that book is very very far away. I don't see any evidence that we're actually marching towards that or that's going to happen.
Ali Ghodsi
Ghodsi offered four conditions for the loop to be real, and was explicit that all four have to hold at once rather than any one of them.
The first condition
the next model require less resources less GPUs to train
Ali Ghodsi
The others are that the next model takes less time to train, that its accuracy and intelligence increase, and that the three can be repeated again and again. Any single failure, he said, breaks the loop — if the resource requirement stays constant, the world runs out of hardware and the process paces itself.
He dismissed the looser definition. Software writing software is already here: more than 90% of the code inside Databricks is written by AI, on his account, and whether the last few percent is too does not matter much.
5. The Runs Are Getting Harder
Against his own four conditions, Ghodsi said the observable facts point the other way. Each lab does one or two frontier training runs a year. Those runs need more resources, more people and more data-center capacity, and every order of magnitude more GPUs introduces classes of error the previous generation did not have to tolerate.
The direction of travel is the opposite
So it's it's the opposite of that hey the next model is faster, cheaper, smarter and recursive improve. It's the opposite.
Ali Ghodsi
Several runs have been botched, he said, which is why the labs are so careful with them.
The hosts added a supporting figure: the minimum compute to train a frontier model keeps rising, from around a hundred million dollars to five or ten billion, while replicating the frontier six months late costs a small fraction of that. They also proposed a measurement rather than an argument: "if these companies continue to grow, reduce the number of people and the number of amount of money that goes into them, then I would say something is definitely happening here." On that test nothing is happening, because the labs are hiring hard.
Ghodsi's caveat was that headcount is a noisy signal, because a company with effectively unlimited money does many things it does not need to do. The measurement he would want is narrower: whether the specific team doing pre-training and post-training is shrinking and using fewer GPUs.
6. The PlayStation Precedent
One host reached for an older version of the same fear, recalling the era when games consoles were export-controlled because of what a hostile government might simulate with them, and the argument that the machines were becoming infinitely powerful. None of it came to pass, and his conclusion was a question rather than an answer: "So, I think a very reasonable discussion is this time different? Yes or no? I don't have an answer to that."
Ghodsi, who grew up in Sweden, said he was not old enough to remember the export controls and joked that Sweden did not care about them. His answer on the substance was that the scale is different now, and so is the surface area.
7. Cyber Is the Real Risk
The reason Ghodsi thinks this time is different is the amount of connected infrastructure, which he said bears no comparison to thirty years ago.
What agents will find
there's so much infrastructure that's insecure right and if you're going to unleash these agents they're going to find loopholes they're going to find exploits they're going to break in here and there
Ali Ghodsi
The mechanism that concerns him is not the model refusing to stop but the model spreading.
The scenario he can imagine
you could imagine a scenario also where it starts hopping like it takes resources and it starts executing itself elsewhere so it kind of spreads like a virus a little bit
Ali Ghodsi
The hosts pushed back with history: within the same period after the internet arrived, worms had disabled hospitals, taken out critical infrastructure and caused tens of billions of dollars of damage on a far smaller installed base, and nothing comparable has happened with AI despite the money and the attention. Ghodsi did not dispute the record.
Where he actually sits
I am sleeping well at night and I don't think there's existential risk right now.
Ali Ghodsi
8. Hours, Not Months
The operational problem, on his account, is that defense is still done by people. A vulnerability entry, the public record of a software flaw, used to give defenders time.
What the response function used to look like
Because you know you used to have these sock teams security operations center people that would you know look at intrusions are happening how are we being attacked and so on and now the humans just can't keep up.
Ali Ghodsi
He gave the timeline. In 2018 and 2019 the gap from a published vulnerability to a weaponized exploit was two or three years. By 2022 it had fallen to eight or nine months.
Where it is now
Now if you look at the curve from 2022 until now it's down to like basically hours.
Ali Ghodsi
That removes the option of a human in the loop.
Why the work has to be automated
there's just you don't have the humans don't respond fast enough to the attacks that are happening
Ali Ghodsi
Most organizations are nowhere near doing it, he said. A security operations center receives hundreds of detection emails a day, most of them false positives and some of them not, and nobody has time to sort them. What is needed is automated threat hunting, with agents attacking your own systems. One group is ahead.
Who has already done it
The banks are doing it.
Ali Ghodsi
Without that automation, he said, the consequences are sites going down and systems stopping for a while — economic damage and people getting hurt rather than an existential event.
9. Data Meets Cyber
One host said he had been on a call that morning with a founder building agent observability and threat detection on Databricks, and had not known the company had the offering. Ghodsi said the company had given a talk at the RSA security conference that year, and that the reason is a change in market structure.
The argument he makes about his own market
but the issue is that data and AI is blending with cyber. These two markets are collapsing
Ali Ghodsi
Data and AI used to be one world and security another. Now agents run inside companies, transact with other companies' agents, and leave logs, trails and fingerprints, which have to be analyzed at a scale orders of magnitude larger than two years ago. Databricks sells a detection product into that.
10. Two Camps on X-Risk
The hosts put the structural question: is this an engineering problem a company like Databricks can sell a solution to, or is it the kind of problem that needs regulation. Ghodsi said the question conflates two things.
On genuine superintelligence
if such a thing would happen that would be very existential of course and that's what everybody agrees on
Ali Ghodsi
On his reading of the founding text, that means something like writing a novel, peer-reviewed doctoral thesis in seconds, or reasoning intuitively in eleven-dimensional physics without writing anything down. He sees no path to it now. What has changed is capability at scale.
The thing that is genuinely new
We just turn on a button and we can get 100,000 of them.
Ali Ghodsi
He could never have put ten thousand of his own security researchers in a sandbox for a month at a hundred million dollars of wage cost. He can now. The same applies to attacking a mathematical conjecture with ten thousand competent mathematicians in parallel.
Which splits the answer in two
I think cyber is the major problem here. This is I think you can solve with engineering.
Ali Ghodsi
On the labs' proposal for outside inspectors, Ghodsi said the idea is good and the choice of inspector is everything, because an inspector from either camp has already decided. His illustration was one of the people who invented the underlying neural-network technology: if that person went in, looked, and said there was nothing to see, he would find it reassuring, and if that person wavered, that would be a strong signal too.
He rejected the alternative of the labs auditing each other.
Why peer review does not work here
I mean, like I value I think like if we have boxing matches in the ring, the boxers should just be the judges of each other. Would that work? No. They would scream foul all the time.
Ali Ghodsi
The moment a rival ships a better model, he said, the complaint arrives as a safety concern.
The conflict he expects
when vested interests are at play and there's like IPO plans and these two companies are so competitive and they have like this history also between them yeah they'll be very they'll be very fair to each other I'm sure
Ali Ghodsi
Asked when federal involvement becomes appropriate, he said self-policing and regulation bleed into each other, citing the securities industry's own regulator as a body that is neither fully independent nor fully governmental.
And why he thinks it arrives anyway
I think it's very hard for regulators to say no we're not going to do that.
Ali Ghodsi
If companies say there is existential risk and ask to be regulated, regulators will not refuse for long.
11. The IPO Dissonance
The hosts raised Elon Musk's line that the position amounts to elaborate strategy — telling the world humanity will die while asking what allocation it wants in the offering. Ghodsi did not treat it as a contradiction.
People who are genuinely frightened exist, he said, and so do people for whom regulation that slows everyone equally would be good for business, and people generally find a way to make those align in their own heads. He then named the pattern he has seen before.
The marketing mechanism
there's also a great marketing ploy to you know whenever you train a new model make lots of noise around how much of a you know crazy risk it is to the world
Ali Ghodsi
Announcing a model as almost frightening focuses the world on it. That does not make the cyber risk unreal, he said, and the two can coexist.
On why the labs are listing at all, he answered as someone running a large private company.
His read on the offerings
Why are they going public? Because they need the capital and they consider the scaling laws and the capital to be a strategic advantage.
Ali Ghodsi
They would prefer to stay private, he said, and cannot.
12. Self-Improving, or Faster
The hosts drew a distinction Ghodsi accepted: most of what the labs describe as self-improvement is something older and less alarming. "A lot of the times when they say RSI, they're actually talking about autocatalytic effects and autocatalytic effects have been our industry for a very very long time."
The examples given were that a compiler compiles itself, that the steam engine was autocatalytic, and that "there's no way you can create a computer chip without a computer chip." Using a model to write a GPU kernel or clean data is the same category as using a computer to design a computer.
The host's estimate came with a caveat about where it comes from, which is a job that consists of meeting people leaving the labs to start companies: "So I would say this is anecdotal 90% of the calories are autocatalytic which is 100% what you would expect." On his count, perhaps 1% of the companies using the phrase mean it, with the rest using AI for data cleaning or kernel writing. Teams genuinely working on getting a model to train itself exist, he said, and consume far less effort than the language suggests.
Ghodsi's response was to ask for the data, and to repeat that he does not think the probability of his four criteria holding is high.
13. Context, Not Intelligence
The hosts noted that a well-known figure at OpenAI had said on a podcast that week that the industry is in the era of general intelligence. Ghodsi's counter is what he sees when he asks audiences two questions. Many say AI is smarter than most people around them most of the time, and have said so since late last year. Almost nobody raises a hand when asked whether they run hundreds or thousands of coordinating agents.
What enterprise adoption actually looks like
most enterprises are on Microsoft copilot
Ali Ghodsi
And what that use amounts to
they're using a chatbot like they're asking questions from a chatbot that's basically very very glorified efficient Google search of the old day results
Ali Ghodsi
Coding is happening, with debatable return. Automated agent work across an enterprise is not. His explanation is not about model quality.
Why the models are not the constraint
the models are smart enough but they just don't have the context that exists inside of any organization
Ali Ghodsi
They have not sat in the meetings, do not know the processes and do not know what the two or three people who know everything know — the employees whose departure everyone quietly dreads. Feed that in, he said, and today's frontier would deliver large productivity gains.
The implication for the whole debate
For that, we actually don't need smarter models.
Ali Ghodsi
No solved conjecture and no move from 60% to 70% on a benchmark is required.
Which is why he thinks the frontier argument is misplaced
I think for vast majority of organizations on the planet they're just so far behind in the adoption curve of actually automating things and getting value out of this stuff.
Ali Ghodsi
The counterpoint raised in the room was that a frozen frontier would be disastrous for the model providers, because the price of intelligence is falling by roughly a tenth every six months, which is the business those companies are in.
14. Building an Ontology
Ghodsi's word for the missing context is an ontology: the relationships between the concepts, goals, departments, people, projects and resources inside an organization, and what each of them actually means.
The analogy he used for it
The one has an ontology of how that organization works, who the people are, how you get stuff done.
Ali Ghodsi
Two equally capable and equally educated employees, one on day one and one five years in, differ only in that. Do not use the organization chart; do not ask that person because nothing will happen; ask this one. The first step is collection, which means transcribing meetings and feeding in the digital record, and legal teams routinely resist it.
The second step is turning it into a graph, and his argument for why matters commercially. Current agents run a loop, checking one resource at a time, synthesizing, and answering — slowly. His comparison is search: if Google had worked that way it would have visited one site, summarized it, followed a few links, read for ten minutes and then produced ten results, at high cost and poor quality, because it would only have seen a fraction of the web.
What he says has to exist instead
so the ontology is that we need to compute that index offline all the time
Ali Ghodsi
He likened it to the ranking algorithm behind early search, with two additional problems: permissions, because the data one person may see is not the data another may, and many object types rather than one.
Databricks built it for itself, and he said his own company's graph is the largest of any, at "millions of nodes in the graph," because Databricks uses Databricks more than any customer does. What it replaces is the meeting: somebody does the analysis in a spreadsheet, builds a deck, and presents it, then answers follow-up questions in more meetings. The internal tool now does the analysis, holds the context and takes the questions directly.
The anecdote he tells about it
does anyone do anything novel here or there? Just everybody just going to genie and asking the ontology
Ali Ghodsi
Preparing for a board meeting, he needed the company's penetration of the Fortune 500 and asked someone in sales operations, who replied that she could not log in to the tool because she was on a flight. He texted the chief financial officer instead and got back a screenshot from the same tool. The verb has entered the company's vocabulary, and he said meetings now consist of everyone looking at their phones to query the graph.
He credited Palantir with doing good work getting tacit organizational knowledge written down, and described Databricks as automating the step from that record into the graph the agents read.
15. Value Maxing, Not Tokens
Ghodsi dated the useful models to the fourth quarter of last year, and said he began committing code into production himself and then pushed the organization to do the same, on the argument that if the chief executive can ship to a sensitive data platform, any manager can. Databricks ran leaderboards from that quarter and was at full adoption by January and February.
The cost problem arrived a quarter or so later. Databricks already had a gateway selling model capacity from the major providers and any open-source model, so it added per-person and per-group budgets, warnings as users approached a ceiling, and analytics that predict where spending is going. Then smart routers that pick a cheaper model when the question is simple or the budget is nearly gone. Then a harness multiplexer, which produced the finding he thought was least obvious.
The variable nobody was watching
Turns out actually the harness itself matters.
Ali Ghodsi
And the size of the effect
you know same version but different harness you get 2x difference in actual cost
Ali Ghodsi
Same model, same version, twice the cost. Between the budgets, the routing and the harness switching, the outcome is the number every buyer wants.
What the cost curve now looks like
the tokens continue to go up but the costs have been sort of stagnant
Ali Ghodsi
One host said that for the first time, at a company of scale on whose board he sits, a large engineering organization moved off the frontier models to a Chinese open-weight model last week: "For the first time ever, a company at scale last week said that they're moving from the frontier models to GLM." He noted that each previous version of this story, starting with the first Chinese model shock and repeating twice since, had no lasting effect on the market, and that the volume of anecdotes now feels different.
Ghodsi said the movement is real, and described the shape of it as a pattern rather than a switch: a small cheap model calling an expert model or the reverse, plus harness multiplexing to control cost. People use an expensive harness to rename files, he said, and pay orders of magnitude too much for it.
The paradigm he thinks is ending
So I think we're going to get to a world where you're not always using the smartest model for everything
Ali Ghodsi
The hosts put their own numbers on the split, and they diverge sharply depending on what you count: "So by dollar open source is like 5%. It's very little, but by token count it's over 60%." They described one portfolio company at close to 90% open source in its product and indifferent to cost on internal use, until the internal bill grew.
16. Why Agents Picked Neon
The hosts noted a neutral third-party test finding that Neon, the Postgres service they discussed alongside Databricks' Lakebase, is the database of choice for coding agents, and said they would not have predicted it a year earlier. Ghodsi credited the Neon team and described the design decisions.
Agents want to experiment, so the database has to appear quickly — the team's standard was well under a second, including cloning a very large database. Then they built branching, so one database can carry many lightweight branches. He compared it to the rewrites of standard Unix tools into much faster, lighter versions that agents can use safely, applied to a harder problem. Pricing mattered too: an agent experimenting should not run up a production bill.
The persona change he thinks won it
They were obsessed with how are we the best for the agents?
Ali Ghodsi
Databases have always optimized for administrators and application developers. This team optimized for a non-human user.
And the result
now over 90% of their the databases that are created on neon and lakebase are actually created by agents
Ali Ghodsi
Bonus Insights
The use cases he thinks the safety argument has crowded out
Ghodsi said the public conversation about risk has left people unaware of what is being built. He named a crisis text service using large language models to detect when a teenager is at risk of self-harm; an insulin pump that learns a patient's own glucose and insulin response rather than requiring injections; and a drone delivery company, originally in Africa, running fully automated routing and battery optimization to deliver blood and supplies.
A transformer that predicts gene regulation instead of words
The more advanced case he gave is a model built with a pharmaceutical company, named for transformer-enhanced drug discovery, whose published research he pointed listeners to. Instead of predicting the next word, it predicts how a gene regulatory network will respond, which lets researchers separate the cells that cause a response from the ones merely reacting, and lowers the cost of developing drugs for specific diseases. He also named a large drug maker using the query tool across its trials, compressing the time to an insight on an obesity study from weeks to minutes.
Post-training is real for startups and not for enterprises
Databricks bought MosaicML in 2023 with the idea that customers would train their own models. Pre-training does not make sense now, Ghodsi said, because good pre-trained models exist. Post-training does: a startup whose product does one specific thing can take a strong open-weight model, apply reinforcement learning, cut its cost, make it fast and own the result. Large enterprises mostly need basic automation and will not get there yet.
Evaluation is the bottleneck, and it is a familiar one
the eval is the hard part
Ali Ghodsi
Databricks generated evaluations automatically and put the feature front and center; customers did not use it, so it was moved to the back end, where they never went. His explanation is that people want to try a new model on a live problem rather than do the scientific version with a baseline. He compared it to test-driven development, which everybody agreed was correct and few practiced.
The field-engineering model is in demand
Ghodsi said demand for Databricks' embedded engineers has risen sharply, largely to help organizations collect the records an ontology needs, and to build customer-facing agents with low latency and guardrails. His example was a sports assistant built for a broadcaster, which he said is good at declining to discuss politics and returning to sports.
P doom
Less than 10%. no. Close to zero.
Ali Ghodsi
One host's answer was that his probability of catastrophe without AI is higher than with it.
Ghodsi's bottom line is that the argument about slowing the frontier is aimed at the wrong risk: superintelligence is far away, the cyber exposure created by capable agents against insecure infrastructure is immediate, and for almost every company outside the labs the binding constraint is not a smarter model but the organizational context no model has been given.
Products, Companies & Tools Mentioned
Databricks (The data platform he runs; he says more than 90% of its own code is now AI-written and its internal knowledge graph runs to millions of nodes)
Neon (The Postgres service a third-party test put first for coding agents, discussed alongside Databricks' own Lakebase; over 90% of the databases created on it are created by agents)
Palantir (Credited with doing the hard work of getting tacit organizational knowledge written down, which Databricks then turns into a graph)
Microsoft Copilot (What he says most enterprises mean when they say they have adopted AI)
OpenAI, Anthropic, Gemini and Grok (The model capacity Databricks resells to customers through its own gateway, alongside open-source models)
MosaicML (Bought in 2023 on a bet on customer-trained models, which he says came good for post-training rather than pre-training)
Zipline (The automated drone delivery service he named as an AI use case, delivering blood in areas of need)
Crisis Text Line (Uses language models on Databricks to detect messages indicating self-harm risk)
Omnipod (The insulin delivery system he named, which learns a patient's own glucose and insulin response)
Novo Nordisk (Named as using the query tool across its trials, compressing an obesity study's time to insight from weeks to minutes)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

