Security, AI economics, enterprise software buying behavior, and the infrastructure powering AI agents are all evolving at the same time. But many of the biggest challenges aren't technical—they're incentives. In this special compilation episode of Ship Happens, host Per Krogslund brings together perspectives from engineering leaders, founders, and platform experts to explore the realities behind AI adoption, security, enterprise software, and developer productivity. From the limits of AI-powered security tools to the economics of personal data, the incentives driving enterprise purchasing decisions, and the infrastructure required to support autonomous agents, this collection of conversations examines the systems shaping modern software delivery. Along the way, guests discuss why AI-generated code increases the need for testing and guardrails, why compliance can outweigh product quality in enterprise sales, and why the future of AI may depend on bringing algorithms to data—not data to algorithms.
As AI adoption accelerates, engineering organizations face a growing set of challenges that extend beyond code.
This compilation episode highlights some of the most thought-provoking conversations from recent Ship Happens guests, covering topics ranging from security and privacy to enterprise software incentives and AI infrastructure.
Sergey Katsev explores why AI-powered security tools can help teams move faster but can never replace the business context and judgment that developers bring to the table. Ruben Verborgh challenges today's economic model for AI and personal data, arguing that the current approach is unsustainable and proposing a future where algorithms travel to data instead of copying sensitive information into centralized systems.
Brian Alvey offers a candid look at enterprise software purchasing, where buyers often aren't end users and success depends as much on compliance certifications and relationships as product capabilities. Vasek Mlejnsky discusses the infrastructure behind AI agents, including secure sandboxes that dynamically allocate resources while protecting credentials and sensitive information.
The episode concludes with Ivar Østhus examining the impact of AI-generated code on software delivery, highlighting why stronger testing, governance, and reliability practices become even more important as development accelerates.
Together, these conversations reveal a common theme: technology alone rarely determines outcomes. Incentives, trust, governance, and operational discipline matter just as much.
(00:00) Why Security Requires More Than AI Tools
(01:05) Sergey Katsev: Security Needs Context, Not Just Automation
(03:39) Ruben Verborgh: The Unsustainable Economics of AI and Data
(04:34) Bringing Algorithms to Data Instead of Moving Data
(09:24) Brian Alvey: Enterprise Software Is Driven by Incentives
(11:57) Vasek Mlejnsky: Building Secure Infrastructure for AI Agents
(13:56) Ivar Østhus: AI-Generated Code Demands Better Testing
(16:34) Key Takeaways and Closing Thoughts
Co-Founder and CEO of Catchpoint, focused on observability, reliability, and the intersection of security and operational performance.
Computer scientist, professor, and researcher focused on decentralized data architectures, AI, and the future of the web.
Technology entrepreneur and industry leader known for his work in enterprise software, media technology, and digital infrastructure.
Founder and CEO of E2B, focused on secure cloud infrastructure and runtime environments for AI agents.
Chief Evangelist at Unleash and a leading voice on developer experience, software delivery, and engineering effectiveness.
Per Krogslund on LinkedIn
Per Krogslund: [00:00:00] So welcome to Ship Happens, a podcast where I sit down with the smartest people in the industry to talk about the skills, techniques, and mindset that helps you ship amazing software.
Some of the best insights on Ship Happens happen when experts disagree. In this special compilation episode, we've gathered some of the most thought-provoking moments from recent conversations across engineering, platform operations, AI, DevOps, reliability, and software delivery. You'll hear perspectives from industry leaders, founders, operators, and technologists tackling the challenges of shaping modern software organizations.
Some viewpoints align, others conflict, and together they paint a more complete picture of where the industry is headed and what engineering teams need to think about next. Whether you're building platforms, leading teams, or navigating the latest technology shifts, this collection of conversations is [00:01:00] designed to surface ideas worth challenging, debating, and applying.
Enjoy the episode.
Sergey Katsev: Nothing is going to beat the, the business logic knowledge that, uh, that a developer has.
Per Krogslund: No. No, it's like, I see these, like, AI security tools promising that they're gonna fix everything, and it's like, that's not how it works. It's- I
Sergey Katsev: mean, they'll, they'll fix some things. They'll catch- Yeah
some things, right? I, I remember the first time, um, uh, and caveat, we were using it incorrectly, but at, at a previous company years ago, we did a Coverity scan-
Per Krogslund: Okay ...
Sergey Katsev: and literally came back with 200,000 problems. How do you go about that? It, it's just impossible, right? Yeah. Uh, so those are the kinds of problems that I think keep developers saying, "You know what?
Let's not even bother." Yeah. But may- uh, b- tools that can sort of start to bring these problems in bite-sized chunks that are manageable for developers- Yeah ... I think developers in general [00:02:00] are happy because then they don't get called in at 3:00 in the morning for some security problem that all of a sudden- Yeah
they need to fix, uh- Yeah ... in an emergency.
Per Krogslund: Yeah. And I think of anyone who's ever had the mis- misfortune of, of looking at, like, a NIST 800-53, like, control, uh, table of, like, these, like, oh, here's, like, the 67 whatever it is, like- Right ... these are all the things you need to, like, implement. It's like, oh, God, there's a lot of things, but it does kinda make sense.
Like, one, each control solves, like, a tiny part of the problem, but you- Yeah ... kinda need, like, pretty much all of them. Um- Yeah ... like, there's no, there's no not one thing that's gonna solve security.
Sergey Katsev: A- and, and they're all... Y- yes, you need all of them, and if you think about it, like, they make a lot of sense.
Per Krogslund: Yeah, they do.
Sergey Katsev: Right? Like, y- y- they, they make sense even outside of technology. Hey, you know, separation of duties is a good thing to have, right? Yeah. Uh, you, you want to have... You know what? If you're gonna have a key to your car, you probably want your spouse to also have a key to the car 'cause you don't want to get locked out, right?
Like- [00:03:00] Yeah. ... there, there's analogies outside of technology that just make sense. But when, when a security person says, "Go do this," then all of a sudden there's pushback. Um- Yeah.
Per Krogslund: Yeah ...
Sergey Katsev: because people... I, I mean, I, I think that the problem is- It's hard to charge for security, right, for, for all of our products.
Per Krogslund: Yeah.
Sergey Katsev: And so it ends up being a cost center, and because of that, there's this like, uh, you know, insurance company game, right? "Hey, if something, if I get hacked, then it's going to cost a whole lot. But what if I don't get hacked?" And that's just not a great attitude nowadays, right? No, it's not great, no.
Everybody has to take it seriously.
Ruben Verborgh: Fundamentally, the way we package AI, the way we package personal data, that's what's wrong. I mean, just to say it very simply, like electricity is also not packaged as like, um, uranium that we just hand out to everybody, right? No, no. We package it in formulas today for mass distribution, and now we all benefit from it.
AI, the way we see it packaged today is completely [00:04:00] irresponsible for everyone, uh, because there's the fact that they don't have it under control, but also, make no mistake, they don't know how to make money with it. Uh, like nobody knows how to make money, and that's a real problem because that's where you see the shortcuts.
So what we see today is shortcuts of companies playing a shorter-term game because we haven't cracked the economic puzzle. So by all means, I want it to be just a very simple economy and not whatever it is we're trying to do today because it's not sustainable. We need to do something with this immense power of AI, but the way we package it is It's not working for anyone really.
The way we deal with AI is like if we're just, like, shipping uranium instead of, like, having socket for electricity.
Per Krogslund: Hmm.
Ruben Verborgh: Not a wise idea, but you can make some money in the short term, sure, because look, it glows and, uh-
Per Krogslund: So we're kind of rewarding, like, irresponsible behavior in these markets. But what, what, what is the alternative then?
What's your idea of this?
Ruben Verborgh: Ultimately, we're still stuck in advertising really. Yeah. So, so what we see, so basically after big data came, came big AI, so to speak. Uh, [00:05:00] and, and big data was never really resolved. Like, we haven't found a sustainable way because the problem with data is that you can keep on copying it, right?
So if, if you have it good and I have it, like, like, there's no rivalry between us. Like, we, we can both have it, and a third party can have it. So basically with data, it's about making sure no- nobody else has it. And in a way, AI is simply liquid data because that's what it does. Like, an AI model by itself is only as powerful as the new energy you inject into it, right?
So any algorithm, be it generative AI or whatever, um, you need to feed it data to get so- something out of it. Uh, so the whole shift towards, um, AI now is on one hand facing the same problem because of the heavy data dependency, even bigger than with big data, I would say. And interestingly, we're also going towards the same solutions.
Like, oh, you know what? Advertising. We just gonna start advertising as if the answers of LLMs are not unreliable enough already. So that's the [00:06:00] issue, like this high dependency on data, and it's all on the fallacy that, you know, more data will solve this. But it's only gonna stop when companies and every single company realize that they'll never have enough data.
There's no such thing as having enough data. So the core of the issue is that, right, personal data is a dangerous stream, a toxic stream because we send it into the world, and it's dangerous because it's true AI is a very dangerous tree that we just send into the world. It's dangerous because it's not true or maybe true, who knows.
And to get results, what are we gonna do? Dangerous personal data sent into the world all the way over to a model, and then it's, uh, uh, that, that. The solution is algorithm to the data, and I know technology-wise that's, that's a known thing, but reason is not technology. Get economy ready. Huh? Because raw data is like stem cells, basically.
Like, like I cannot... When I give raw data to you, I cannot [00:07:00] imagine all the things that might happen to it. You cannot, nobody can imagine what can happen to it. What, what are all the things that you could do with my date of birth or the fact that I like curly fries to use one of the classical examples, huh.
I don't, by the way. But, um, I cannot imagine that, so I cannot, but we can derive from it. If you bring an algorithm to the data, and if you say things like, "Actually, Ruben is willing to pay a premium for, for this product," or, "Ruben is allowed to buy a bottle of whiskey because, uh, he's of a legal drinking age," and things like, these are raw.
And from raw data, we go to insights, okay, which, which are valuable at the moment. Okay? So, and all of this is possible because I have much more data than you will ever have about me. And like, no matter how much you try to get from me, there's legal barriers. It's just expensive to acquire, to maintain, and so on.
So you don't really want raw data, just like you don't want raw uranium and oil and... No, no, no, no. You want the insight you need at [00:08:00] the moment. So my intent- An architecture and economy in which, uh, what companies really want is the value from, from, from the data, but the value changes at every single point because the real value is in data they'll never have,
Per Krogslund: and they'll never have enough.
What you're describing here is really you're, you're modifying people being consenting adults handing over their data as like in a certain, like negotiation rather than just being passively extracted from by various trackers that's trying to deduct a lot of things about their behavior and so on.
Ruben Verborgh: Yes.
And you know why? Because companies are absolutely terrible at extracting data. In Europe- ... with the GDPR, it's medical data. They don't wanna know. But I'm like, uh, you spent millions trying to guess whether I'm a dog, um, but I'm pregnant on a diet, and I will bloody tell you how to make money. I will tell you that I'm gonna pay more for products with less sugar.
It's as simple as that. And the reason this example triggers them is because they [00:09:00] know very well it's data they'll never have. So I'm trying to promise them the value from data they'll never have. But then the question is, how do we make it happen? Li- like I, I wanna tell them, and I have an incentive to know because it helps me.
They have an incentive because those products are more expensive. So why are we bothering with all the data you're trying to guess whereas the most valuable data you're not even willing to accept? What are we doing? Right? So we need a solution for that.
Brian Alvey: So the government's allowed to use us. So there are a whole bunch of horrible gauntlets of checklists of like, uh, you know, penetration tests and all these things that we have to do.
But yes, if you think about it, if somebody- if you say WordPress to somebody, right? 'Cause you talked about the early days of blogging. "Hey, I'm gonna run my, you know, I'm gonna run the White House's website on, or NASA on WordPress." You're like, "Well, you're gonna be hacked, and it's gonna be, it's not gonna be fun.
It can't do what you need." And so VIP is here to prove, like, we can do what you need and you won't get hacked.
Per Krogslund: Cool. Okay. Uh, and yeah, I guess also that whole like FedRAMP and compliance, this is the like, this is, this is a big value for people even though kind of like a [00:10:00] hidden thing. It's not a technical feature.
It's just like compliance is just important for this like segment you are working in. So-
Brian Alvey: Well, I'll, I'll tell you, uh, the, I don't know, the kind of the, the sad part about it is there's the, the difference between enterprise and consumer sales- Mm-hmm ... uh, has taken me, I don't know, my whole long career to figure this out.
But the difference between enterprise and consumer is sort of the difference between what Steve Jobs would do and what Marc Benioff would do. Yeah. And they would actually argue about this because Steve Jobs thought Marc Benioff's job was kind of dirty. You know, you're selling ERP software to CIOs and that's kind of gross.
Right. Disgusting
Per Krogslund: capitalist.
Brian Alvey: E- exact- no, but and that thing. And so like, well why does he think it was dirty? I was trying to unpack this because we are running an enterprise division inside a massive consumer company. Yeah. Our company own- our parent company owns Tumblr. You know, that's a free blogging platform.
They own, you know- Sure ... journaling apps and, and Clay and, uh, you know, uh, Beeper and Pa- you know, all, all these things, all these consumer apps. And they very much have a mind of consumers. And I, I was, for a while I thought the tension between us and them was they really, really like $3 a month customers, and we like [00:11:00] million-dollar-a-year customers, right?
Like, and that's the difference. But it's not that simple. Um, in consumer sales, the best product wins. Yeah. When you're buying a phone, when you're buying a, a pack of gum, like the best one wins. In enterprise, the person you're selling to doesn't use the product, so the best product doesn't win. It's, "I've got the FedRAMP certification.
I, I met you at this conference. You, you know this other thing about me." The person buying from you doesn't use the product- Yeah ... and so you're not actually incentivized to make the best product. I'd like to, I'd want to make the best product. So that's the biggest tension between kind of our consumer parent company and our enterprise division.
Yeah. And just in the world, like you were saying, um, it's tho- those incentives are strange. So how do you build a division? How do you build an enterprise work as company that is both selling to the buyer who doesn't use the product and checking all the boxes, compliance, all those things you need- Yeah
but also still making something that's the best product?
Vasek Mlejnsky: Yeah.
Brian Alvey: Um, you're kind of doing two jobs in one.
Vasek Mlejnsky: So you need a way [00:12:00] how to expose, for example, API keys inside the sandbox to the agent, to the LLM, without actually exposing the real value of those API keys. Yeah. Um, so kind of need to swap them in, in, in, in, uh, in flight.
Um, another, another thing is storage. So, uh- Basically the goal where, where I think this is going is like you have this infinitely scalable computer in a cloud for each agent, and it kind of morphs into the form what the agent needs at the same t- uh, at, at the right time. So as the agent is, uh, pulling bigger repositories, is, is running more complex workloads, the, the sandbox should kinda, uh, on its own, like increases storage.
Like imagine it's like backed by something like S3 bucket. Yeah. And you can just keep uploading stuff as you go, and you don't worry about it like if it's full, if it's not full. Yeah. Uh, and you pay as you go as, as you are [00:13:00] using it. Or it should like increase the RAM, increase the CPU, or decrease the CPU, uh, because like you want to-- you want basically these workloads to be very optimized on what the agent is doing.
Um, and, um, and you don't want to overutilize, uh, or you don't want to like overkill the spec of the sandbox and just have like 32 CPU just sitting there while the agent is basically running a, a simple Python server at the top. Yeah. Um, so yeah. Like a l- a lot of these things is like you imagine you have, you have like a, a Uh, piece of infrastructure that can form into the right shapes ba- very dynamically based on what the AI wants to do, what the ag- agent wants to do.
This is where we are, like, where we are going with, with, with E2B and our sandboxes.
Per Krogslund: Cool. Like, it's, um, it's interesting to see how these, like, cloud primitives we've seen over the last 10, 20 years, and now they're morphing into this, like, new use case.
Ivar Conradi: Yeah, you can postpone some of that because you have the control [00:14:00] mechanisms.
Per Krogslund: Yeah.
Ivar Conradi: Yeah, I guess, like... But, uh, and also the, the maintainability, I guess. Yeah. If it's messy code, it can be hard to add new capabilities later, of course.
Per Krogslund: Yeah, yeah. Yeah. Yeah, so you, you do still need to look at the code. You still need to know the craft. But I think it's an interesting perspective of this, like, we can just observe that it's actually working to an extreme now.
Ivar Conradi: Yeah.
Per Krogslund: So...
Ivar Conradi: But, but I, but I also think that that also... Actually, when we are talking about AI, because I think this is so interesting, I think, yes, it also changes kind of the need to do very thorough testing.
Per Krogslund: Mm-hmm.
Ivar Conradi: At the same time, I think actually the, the, the, the notion that we now have IR- AI capabilities, uh, that can allow us to generate a lot of m- the code.
Mm. I think actually it means that, uh, the old way of... Or that, that it kind of puts up another kind of need to actually have, uh, or think about writing good tests as an art again. Because if AI is going to produce more code that we, we [00:15:00] don't have a chance to review all of it- Yeah ...
Per Krogslund: then
Ivar Conradi: we need to, to trust the test even more.
Per Krogslund: Yeah.
Ivar Conradi: Uh, so we need actually somebody... And maybe you can use AI to generate some of the tests. So, so it's not that you need to hand write all of the tests, but kind of having somebody thinking very thoroughly ar- around how do we structure the test? Yeah. How do we make sure that the important use cases that we should support in our application are still valid and still working as intended?
Per Krogslund: Yeah.
Ivar Conradi: I think those, those kind of things also is... So I think everything, all the tooling around software is, is actually almost getting a new renaissance, uh, with introct- introduction of AI. But suddenly, because we can now have this new thing that we don't actually fully trust... I, I really love the Dory report because they have so much good findings in there and-
Per Krogslund: Yeah
Ivar Conradi: uh, e- they, they say, like, 90% of all engineers are using AI as part of- Yeah ... building software today. It's like 90% says say yes to that question, but 80% doesn't fully trust it.
Per Krogslund: Yeah. It's like you'd be a [00:16:00] little suspicious about the thing. I think that's healthy. I think that's healthy. It's like...
Ivar Conradi: Uh, but that also means that we need to have the guardrails around that code, right?
Per Krogslund: Yeah. Yeah But that's, it's interesting, right? It's like, I think as, as, as we talk about this and how you're kind of shifting this around, and I think ev- anyone who went to any kind of, like, computer science education and so on, have this, like, mental model inside of our head of, like, we, we plan, we design, we gather requirements, we code, we test, we deploy, we maintain.
Like, that's the, the circle of life for software development, isn't it? Like, that's-
Ivar Conradi: Yeah ...
Per Krogslund: pretty much dead. As always, this show was brought to you by Docker, the open platform for building, shipping, and running applications. So thank you for tuning in, and I'll see you next time. Thanks.