**Taylor** (0:00)
Welcome back to AI Daily, your go-to podcast for all things artificial intelligence. I'm Taylor, and I am so excited for today's episode.
**Morgan** (0:10)
And I'm Morgan. Don't get too carried away, Taylor. We have some pretty serious reality checks to discuss today, alongside the hype.
**Taylor** (0:19)
Oh, I know. We are talking about everything from crumbling corporate business models to hidden malware and coding agents. It is wild out there.
**Morgan** (0:30)
Exactly. It is a mix of massive industrial shifts and some very real security warnings. Let's dive right into the news.
**Taylor** (0:37)
Okay. First up, dude, did you see this? Deloitte basically told its own consultants that the classic billable hour is completely toast.
**Morgan** (0:48)
Wait, really? The billable hour is the entire foundation of consulting, law, and accounting. What is going to replace it?
**Taylor** (0:56)
AI agents. According to an internal presentation leaked on The Decoder, they project hourly billing will be a tiny sliver of the market by 2035
**Morgan** (1:09)
Wow.
One consultant apparently summed it up by saying, our model is toast. But how do they make money if they aren't billing by the hour?
**Taylor** (1:19)
Right? McKinsey and BCG are already scrambling for alternative revenue models.
I mean, if an AI agent can do 80 hours of research in five minutes.
**Morgan** (1:30)
You can't charge for 80 hours anymore. Clients aren't stupid. They will demand value-based pricing or flat fees because the labor cost is plummeting.
**Taylor** (1:40)
Exactly. It's wild because these giant firms made billions teaching other companies how to automate, and now they're getting automated themselves. It's like Inception.
**Morgan** (1:51)
It's a classic innovator's dilemma.
If they don't adopt AI agents, competitors will. But if they do, they destroy their own primary revenue stream.
**Taylor** (2:03)
Totally. I wonder how fast this will actually happen, though.
2035 feels far, but like, agentic AI is moving so incredibly fast right now.
**Morgan** (2:14)
It is, but changing corporate culture and legal structures takes a lot of time. Still, this is a massive wake-up call for the entire professional services industry.
**Taylor** (2:25)
Oh, absolutely. I think we are going to see a massive shift in how knowledge work is valued. It's not about time anymore. It's about results.
**Morgan** (2:35)
Exactly. But as we hand more work over to these autonomous AI agents, we also have to talk about the massive security risks we are opening up.
**Taylor** (2:45)
Oh, dude, yes. Speaking of AI agents doing work, they aren't always as safe as we think.
Let's talk about Claude Code.
**Morgan** (2:56)
Oh, you mean that crazy security vulnerability with Claude Code? I saw that report on the Decoder 2 It's honestly terrifying for developers.
**Taylor** (3:05)
Dude, yes. Security researchers at Mozilla's Zero Dine platform showed how a compromised GitHub repo can literally take over a developer's machine.
**Morgan** (3:17)
Wait, how does that work? Isn't the AI supposed to analyze the code and tell you if there's something malicious hidden inside?
**Taylor** (3:24)
That's the crazy part. The malicious code isn't even in the repo for the AI to scan. It loads at runtime via a hidden DNS query.
**Morgan** (3:35)
Ah, so the AI agent runs the setup process, triggers the DNS query, and downloads the malware without any verification?
**Taylor** (3:44)
Exactly! The AI has no idea it's doing anything wrong because the code looks totally clean to scanners and to the agent itself.
**Morgan** (3:53)
That is a massive blind spot. We are giving these agentic tools terminal access and letting them run commands on our local machines.
**Taylor** (4:03)
I know, right? It's like giving keys to your house to a super smart assistant who doesn't know how to check ID at the door.
**Morgan** (4:10)
It highlights a huge problem. We are rushing to deploy these autonomous agents before we've built the proper security guardrails around runtime execution.
**Taylor** (4:21)
Totally! And developers love these tools because they save so much time. But this shows one bad dependency can completely compromise your whole setup.
**Morgan** (4:32)
Right. If the agent doesn't verify the external sources pulling from at runtime, it's basically a backdoor for hackers to execute arbitrary code.
**Taylor** (4:42)
Exactly. I'm definitely going to be way more careful about which repos I let my AI tools touch from now on.
**Morgan** (4:49)
Absolutely. You cannot trust automated agents to verify security on the fly.
But let's pivot to something more positive in the agent space.
**Taylor** (4:58)
Oh, you're going to love this one, Morgan. Nvidia just dropped something called the BioNeMo Agent Toolkit. And it's like incredibly cool for science.
**Morgan** (5:08)
Okay, I'm listening. Nvidia is always doing interesting things in biotech.
4 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000774790201