**Ian Webster** (0:03)
The excitement around it is well-warranted, but I think in an enterprise or infrastructure context, I would probably wait for something that is more stable and then doesn't have these questions hanging over it. That's my take. If I had to deploy DeepSeek, I would probably focus on use cases that were not end-user-facing. Because again, going back to what we were talking about earlier, DeepSeek is especially susceptible to basic jailbreaks, and it would be a real pain to have to harden that if you're putting this out to users or the public or that kind of thing.
**Joel de la Garza** (0:35)
When Chinese company DeepSeek released its R1 model back in January, it took the AI world and much of the tech world by storm. You've seen reasoning models before, but DeepSeek R1 was better than many, it was free, and it was open source. What's more, confusion about the company's access to high-end GPUs had many questioning how much R1 cost to train and to run. The result? Lots of analysis about what the model means for other AI labs, what it means for chip makers, and what it means for the global AI race. In this episode of the A16Z AI Podcast, we examine DeepSeek from a different perspective. What it means for cybersecurity. Do your A16Z partner Joel De La Garza in three separate discussions with three separate cybersecurity founders, who lay out the case for why users should be careful about DeepSeek, as well as why excitement over new models is a great opportunity to reassess issues like censorship, deepfakes, and good old-fashioned vulnerabilities. While DeepSeek R1 itself might fade into the zeitgeist ether, the advent of reasoning models and even better models overall means we have to adjust our security practices and expectations accordingly. Joining Joel are, in this order, Ian Webster of Promptfoo, Dylan Ayrey of Truffle Security, and Brian Long of Adaptive. And you'll hear from all of them after these disclosures.
As a reminder, please note that the content here is for informational purposes only, should not be taken as legal, business, tax, or investment advice, or be used to evaluate any investment or security, and is not directed at any investors or potential investors in any A16z fund. For more details, please see a16z.com/disclosures.
**Joel de la Garza** (2:09)
Hey, thanks. Thanks for joining us. You know, a lot of the news in the last two weeks has been DeepSeek and sort of these new reasoning models that have been open source coming from China. Obviously, there's been the bullish side of the case, which has been that this is changing everything. The economics are different. This is the golden age of apps. The other side has been this is the beginning of the end. China's ascendant. They're taking all our data. This is horrible. You had a great blog post on this. Taking a look at DeepSeek would love to maybe get your thoughts and talk a little bit about kind of how that's coming together.
**Ian Webster** (2:38)
Yeah. So everyone's losing their mind about DeepSeek. I noticed that, too. There are kind of three things that are notable about it, right? It's open source, it's reasoning, and it's from China. And I think the fact that it's open source and the fact that they have found this new technique or kind of proved it out is great. It's a great story for everyone in the world in terms of what is possible with open source and what the future of these models could look like. The interesting part is that the origins of the company and the fact that the Chinese government has a ton of influence over the models that are developed in China. So, the post or the research that we did was focused on characterizing that influence, seeing how deep it went, and also kind of testing, pushing the limits of the model in terms of just red teaming it and seeing what sorts of adversarial techniques it responds to or doesn't respond to.
**Joel de la Garza** (3:34)
And by adversarial techniques, what do you mean exactly?
**Ian Webster** (3:37)
We're really focused on things like run-of-the-mill prompt injections, jail breaks, that kind of thing, because those are often the gateway to messing around with other stuff, right? Like once you punch a hole in the defenses with something like a jail break, if it's part of a larger system or architecture, like a rag or agent, that would give an attacker a lot of room to pivot around and do other things within that system.
**Joel de la Garza** (4:01)
And they build a lot of safety features into these things, right? I mean, the people who build them, it seemed like it had a very sophisticated layer of speech limitations.
50 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000696811429