Episode 43

Gidi Cohen: From Cybersecurity to AI Trust, Tackling Risk, Compliance & the Future of Enterprise Data

With Gidi Cohen, CEO and Co-founder of Bonfy
September 22, 2025

What we talked about

Gidi Cohen joins the PreVetted Podcast to share his remarkable journey as a serial entrepreneur, cybersecurity veteran, and now Co-founder & CEO of Bonfi.AI. With over two decades of experience building Skybox Security into a global enterprise and advising leading security companies like OTORIO and Octarine, Gidi has spent his career at the intersection of technology, risk, and trust. Today, he’s channeling that expertise into solving one of the biggest challenges of the AI era: making unstructured data ( whether human or AI-generated ) secure, compliant, and trustworthy.

Show notes

Gidi Cohen argues that most cybersecurity tools have spent decades securing the pipes, the network, identity, and infrastructure layers, while almost entirely ignoring what flows through them. His new company, Bonfy.AI, is built around the conviction that unstructured content moving across email, chat, and SaaS platforms is the real attack surface of the AI era, and that the existing solutions for controlling it simply do not work.

What we covered

  • Gidi describes AI adoption as moving roughly five times faster than the cloud security wave that preceded it, creating a situation where organizations face enormous risk before the industry has had time to develop reliable defenses, a dynamic he finds both alarming and genuinely exciting as a founder.
  • The core problem Bonfy tackles is that data loss prevention tools have had poor accuracy for years, generating so many false positives and false negatives that security teams stopped trusting them. Gidi argues that without accuracy, no policy enforcement system can work, and that gap is what Bonfy is built to close.
  • Bonfy’s platform inspects content as it moves, emails, chat messages, file uploads, SaaS activity, automatically applies business context to classify risk, and can either alert on or block dangerous transfers in real time, providing both granular per-content risk scores and an aggregated organizational risk picture.
  • Gidi introduced his concept of “techno feudalism,” a trend he sees as the inverse of meritocracy: as foundational AI models require massive compute, energy, land, and GPU resources, power concentrates among a handful of companies rather than rising with individual skill and effort, which he views as a serious societal risk.
  • On the question of compliance, he predicts regulations will arrive, and likely overcorrect, but that the more urgent shift is for organizations to treat AI data security as part of the fabric of adoption from day one, rather than bolting controls on afterward the way the industry did with cloud.
  • His advice to founders building deep enterprise technology: obsess over the product, ensure it genuinely solves the problem (not just checks a compliance box), make it fast to deploy and simple to operate, and align every aspect of the go-to-market strategy with the product reality rather than retrofitting them later.

About Gidi

Gidi Cohen is a serial entrepreneur and cybersecurity veteran who spent over two decades building and scaling Skybox Security, including through multiple significant liquidity events. He is now CEO and co-founder of Bonfy.AI, focused on AI data security for enterprise organizations.


Episode 43 of the PreVetted Podcast.

Full transcript

Federico Ramallo (00:00) Welcome back to the PreVetted Podcast where we spotlight extraordinary founders and people reshaping our world. Today we’re joined by Gidi Cohen. He’s a serial entrepreneur, cybersecurity veteran, and now CEO and co-founder of Bonfy.AI. ⁓ Bonfy is a company that is on a mission to take unstructured content, secure, compliant, and trusted, whether generated by humans or AI.

Before Bonfy, Gidi spent over two decades building skybox security, leading it through growth and multiple exits. He’s also served as an advisor to leading security companies, including Otorio and Octarine. So in our conversation today, we’re going to explore his journey from building enterprise cybersecurity solutions to tackling one of the most pressing challenges in the AI era.

trust, compliance and governance in unstructured data. Welcome to the show, Gidi.

Gidi Cohen (01:00) If it’s really cool, great to be here. Thank you. My pleasure to be here.

Federico Ramallo (01:03) Yeah, thank you for being

here. Yeah, yeah, I am honored. So let’s get into, you you build, you mean building companies for over 20 years in cybersecurity, right? What first drew you into this field?

Gidi Cohen (01:17) So, know, of if I look at myself since I was young, what I loved is I love technology. I loved all of the concept of cyber security, even before it was called the cyber security. And I liked the kind of how data and analytics all come together. since I was young, I know it’s probably an odd hobby for a kid, but that’s what I always was drawn to that. And then since then in my professional career as well. So when…

AI started to take off significantly, right? In mid of 2023, though it’s not a new field, but it took off in an exponential way since. said to myself, first of all, I must be part of that great wave. It’s amazing on one hand, but super risky on the other hand, which sounds to me like a great opportunity to provide value as I did in other domains in cybersecurity and apply this type of knowledge and experience and energy and excitement to tackle this kind of what we believe then.

which I think is absolutely clear now, a huge problem to tackle.

Federico Ramallo (02:17) Interesting, interesting. Yeah, the cyber security industry has changed so much in the last 30 years, right?

Gidi Cohen (02:25) Yeah, for sure.

Yeah, changed kind of it’s not overnight all of it. But if you’re looking at the gene AI and the impact on it, both in terms of adoption of the technology and mitigating risks associated with the technology, it’s definitely significantly faster, probably five X faster than let’s say the cloud security or cloud adoption and cloud security that came with that, that is still emerging. I think that AI is probably has a bigger magnitude and impact definitely in technology and also the cybersecurity elements of that. But it’s also in a much more

intense time frame. So it’s a pretty crazy situation, which we really enjoy being part of and contributing to with our technology.

Federico Ramallo (03:06) Yeah, yeah, yeah. And the tools has been evolving, but the tools that allow us to provide better cybersecurity can also be used. It’s a double-edged sword, right? Because it can also be used ⁓ for attacks, right? So the evolution goes both ways, right?

Gidi Cohen (03:24) Exactly. And that’s why it’s so important for organizations to realize that they cannot take it lightly the situation because the attackers, bad guys, the threat actors are already taking advantage of those tools a lot in fraud and making automated penetration and a lot of other type of techniques. And if organizations are not going to utilize properly AI technology to prepare them against AI threats,

and they’re going to have a very tough time to address those type of emerging risks.

Federico Ramallo (03:58) Right, right. I remember an anecdote. I’ll tell you that a little bit further down the conversation. So looking back at your time founding Skybox Security, what were the hardest lessons from scaling it to a global enterprise?

Gidi Cohen (04:15) think the hardest lessons, and there’s not only one, right? There are a lot of things which are hard, right? In building a company. But think the hardest is probably to try somehow combine your technology readiness for scale, for the need of large global enterprises with the demand, right? Because every startup starts with something. Initially it’s not prepared for that. Along the way it does.

But when it hits you in a positive way, let’s say when there’s a big demand that happens to a, let’s say in our case, then it took security, posture management, some other elements that we dealt with, then how to prepare the organization to serve as a startup, really large organizations that are, you you’re serving organizations which can be, not kidding, thousand times bigger than you. And you still need to stand there, have the right technology, being able to support them well.

Federico Ramallo (04:53) you

Gidi Cohen (05:08) and to do it repeatedly. we’re definitely kind of challenging both technologically, organizationally, management wise, et cetera. So that’s plenty.

Federico Ramallo (05:16) Interesting, ⁓ You had multiple exits in your career, right? What part, what patterns do you have you noticed in building companies that last versus those that don’t?

Gidi Cohen (05:21) Yes.

Yeah, yeah,

it’s actually pretty trivial, right? At the of the day, you get a good exit when you have a good momentum and you show the right numbers, metrics, whatever is relevant in that industry for the maturity of the company. as long as you can consistently grow consistently and show the result of that.

you can get really, really lucrative exits. If you don’t, it’s much more challenging. even Skype was like we had two big liquidity events that happened at a time where we can show very, very consistent execution. It didn’t last forever, right? Every company has kind of ups and downs, but when you have the up, right, in a consistent way, that’s typically when you can create situations where you can have a lot of opportunity for liquidity events.

Federico Ramallo (06:14) Right, interesting. So let’s talk a little bit more about Bonfy AI.

Gidi Cohen (06:22) Maybe let’s start

with that. We call it actually Bonfy for the Americans. So it’s Bonified.AI. Yeah, but they know that unless you speak, if you speak Latin, Bonafide is a good way to control them to Bonfy.AI. But there we call it Bonfy, like Bonified AI primarily because of the American type of pronunciation of “Bonafide”. ⁓ anyway. So AI in good faith basically, right?

Federico Ramallo (06:28) really?

Interesting bonfire, yeah

Yeah, thank you for correcting me. I’m always afraid of mispronouncing company names or guest name. ⁓

Gidi Cohen (06:58) I can compliment

you that you pronounce correctly Gidi, right? A lot of people don’t know if it’s “Giddy” or “Jidi”, etc. So it comes from Gideon, right? It’s my nickname since I was, you baby. So you pronounce it correctly. So we’re good for you. Exactly.

Federico Ramallo (07:11) One win, yeah, let it go.

Yeah, English is my second language. actually, I’m from Argentina, so I speak Spanish. Actually, not Spanish, “Castellano”, which is Castillian, right? ⁓ It’s mostly Spanish, but they have different ⁓ inflections, right? ⁓ So anyway. ⁓

Gidi Cohen (07:30) Okay?

Interesting.

Federico Ramallo (07:40) So it took me a while to not only learn English, but then think in English. Because when you’re coding, I believe that a good software engineer should think in English. Because the variables, the abstractions, the naming, the conventions, all of that. ⁓

Gidi Cohen (08:04) You know

it when you go to the right place, if you start to dream in English, then you know that you nailed it.

Federico Ramallo (08:15) Yes, yes. ⁓ And then I get used to, I go to a point where I don’t realize what language I’m talking about. I’m talking. So when I’m translating, it gets to a point where I switch and I start speaking in English to the Spanish speaker and in Spanish to the English teacher. And then I have two people looking at me angry, you know. Yeah, it happened to me a few times.

Anyway, it’s Bonfy AI. There you go. So what inspired you to start Bonfy AI? You started in 2024, right?

Gidi Cohen (08:52) Yes, correct. So I think that, you know, as I said in the beginning, right, all of my life since I was very young, right, I dealt with risk and cyber and attacks in different levels of the stack, right. Always when it’s requires a lot of analytics and algorithms and data, et cetera. That was always my passion. Don’t know why, but it was true since young age, since my military service and after that. And when the…

in January, I started to take off in 2023, it was clear to me that it’s going to pose significant challenges of risks in a lot of different levels, risk, trust, cybersecurity issues, integrity issues, compliance issues in so many different levels. So I said, okay, that’s a space I must be part of, right? And actually lead, not just be part of. When we dug in even more, we saw that there are multiple different problems, right? In dealing with this AI security, compliance, trust.

And one of them is data. And it was very, very clear to us that when you’re looking on data security, even prior to the GNI, a craziness starting 2023 and this accelerates since then, is that even part of that, the data security solutions for sure for data in motion, data in motion is when you are moving bits from left to right, emails, chat, web views, whatever it is, and the solution is just not good for many, many years.

while organizations need to put those technical controls like data loss prevention, they need to put controls in place, they are required for compliance, but they just don’t work. They don’t work for a lot of different reasons. I’ll be happy to maybe explain some of them. And it’s okay, that sounds like a very exciting opportunity for a startup because on one hand, there’s a great tailwind of AI adoption to create a lot of new type of phrase, huge scale on one hand. And on the other hand, there are…

There’s existing problem that was never sold. People are spending billions on that every year. And it’s just great opportunity. And that’s why we decided to say, great. We’re going to focus on the AI data security challenges ⁓ for enterprise organizations around the globe. And let’s solve it once and for all. And that’s what we’re doing.

Federico Ramallo (11:09) The challenge of cybersecurity and security overall is that it’s a balance, right? If you go too hard on setting too many rules on the sake of security, you can be hindering the operation of the business, right? ⁓ But if you have too many flexible rules, ⁓ then you’re exposing the business to risk, right? And that balance is difficult to have, right? ⁓ Because…

Gidi Cohen (11:33) Exactly.

Federico Ramallo (11:37) everything is okay until there is an incident, right? And then people start complaining, why haven’t we done better? And that’s when…

Gidi Cohen (11:48) Absolutely.

that’s what’s going on. Go ahead, sorry. Go ahead, Federico. So they would say that it’s part of the issue, right? That if you’re looking at false negatives and false positives, right, in data science, that’s a huge issue in the world of data security, definitely when you put AI in place. And I think part of the fault of this industry, right, for many years, even predating gene AI was that it just did not focus on developing the right technology to make sure

Federico Ramallo (11:51) Yeah, go ahead. ⁓ I was going to just…

Gidi Cohen (12:18) that analyzing the piece of content that structure data is accurate enough. And if it’s not accurate, people are not going to rely on it. You don’t want to create unnecessary friction in the organization, but by blocking a lot of what is expected, the common type of communication or sharing, while you want to catch the polyfuel, but really dangerous type of events and incidents.

And that’s why the accuracy is the name of the game here. If don’t have an accurate way to express the policies and enact them correctly for the organization, the solution would not work. And that’s why we decided to take a very different approach technologically to solve this issue, both for the historical challenges predated to GEN.AI and obviously to address all of the new emerging risks resulting from the adoption of GEN.AI.

Federico Ramallo (13:07) Right, right. ⁓ So how do you think compliance and trust will evolve in a world that is increasingly filled with AI generated content?

Gidi Cohen (13:20) First of all, I think it’s going to be a mess. I think that… But not a completely new mess. Because think about what happened with the social media, with all of its benefits.

We’re doing a podcast here, hopefully it will be a lot of people will listen and view it, et cetera, on social media. But I think that over the last, I would say 20 years plus, right, of innovation of technology, even before Gen.AI, think people got used to the fact that not everything they see or hear or read is actually trustworthy.

So that’s not new. I think what’s happening now that it’s been accelerated significantly and you don’t know if you’re talking to a human or human sent you the information whether it’s correct or not. You don’t have a great way to corroborate it. You’re going to ask CHEDGY-PT which might be the source of the same information, what’s correct and what’s not. So the definition of truth is absolutely not clear, which is not new. The ability to generate content…

in a way which looks so human-like, is so easy and so cheap, free, depends on what you are using at times, that I think whatever problem we’ve seen with social media and the trustworthiness of information or the lack of will increase exponentially, already increasing. So it’s a huge issue.

Federico Ramallo (14:38) Yes, yes, and ⁓ the complexity of the attacks are going to be much, much ⁓ higher now that hackers can use, or people could use AI to do cyber attacks, right?

Gidi Cohen (14:53) Exactly. If you think about historically, almost the entire cybersecurity space was securing the plumbing itself, right? The pipes. You know, what kind of pipe can go from one place to another, who can connect to the pipe, right? Identity level, network level, system level, et cetera. But rarely a cybersecurity solution were used effectively to understand what’s going through the pipe. And the issue that a lot of the risks is what’s going through the pipe. Information, data.

correct, incorrect, as a liquidation, as a leakage, no one really knows because the tools are not set to detect it and prevent it in an effective way. That’s why I think there’s going to be a need for the industry to evolve extremely fast to be able to deal with those type of risks.

Federico Ramallo (15:37) Yes, and the evolution of the defenses needs to go on par with the evolution of the complexity of the attacks,

Gidi Cohen (15:47) Exactly, exactly. And that’s where we are coming to play and probably other vendors as well.

Federico Ramallo (15:51) So can you describe for the audience what role do you see Bonfy will be playing in making AI more enterprise ready?

Gidi Cohen (16:00) Yeah, bonfire. ⁓ We’ll see kind of a more. Yeah, I’m even reminding some of the other employees once in a while about how we call ourselves. Yes, so in multiple ways, We’re basically providing what’s going to cyber security jargon, right? The technical control, right? The ability to inspect ⁓ on such a data as it moves from place to place on email, chats, web views.

Federico Ramallo (16:02) Bonfire, sorry

K

Gidi Cohen (16:29) SaaS applications, whatever it might be, either in motion or trust. So both inspect it, detect in real time with applying business context, we automatically learn and business logic to understanding this type, to analyzing each piece of content. Again, thinking about email, chat, file, post, whatever it might be, and understanding what the risk associated with that in the way it goes, shared, accessed by internal or external, let’s say people or systems.

and label it automatically and apply that such that can either, so you can both detect and potentially prevent those type of risky incidents from happening at all. So that’s one. And second, if you do it well and you quantify this risk on a content by content, email by email, post by post level well, you can then aggregate it and get the total picture. ⁓

of the data level risk for the organization. So you can say, ah, we have some employee here that might be leaking information because they’re going to leave soon the company with the list of our customers, let’s say, or other stuff that orders. Maybe we deploy a certain AI agent that looked like a great technology to whatever, introduce some automation or some productivity. And actually the way it was programmed, or maybe it was some malicious software or whatever, it started to suck information from the wrong places.

which we were not aware about and we want to track the understanding of risks. So the risks are coming and going in a lot of different ways and the ability to tap into those information flows and systems, quantify the risks, potentially prevent it on the spot and provide the big picture, I think will provide a great value for the organization to know where they are and ensure they can put the right policies in place and the right enforcement controls ⁓ to mitigate the risks that are not acceptable to

Federico Ramallo (18:17) Right, interesting. So I wanted to kind of change topic. I was reading one of your ⁓ blog posts, which I find very interesting. You wrote about a possible shift from techno meritocracy to techno feudalism. Can you explain it for the audience?

And what do you mean and why does that matter?

Gidi Cohen (18:48) Yeah. Yeah. So I would say first of all, it was more reflection on the entire industry, not just the data security side, not just the AI trust, but in general, the impact of AI, especially on the, I would say on the not just technology, but a lot of professions that typically you let’s say think about software engineering, think about authors of books, musicians, artists, architects, lawyers.

and a lot of other positions where typically the best and most skilled, most educated, most energetic, most passionate people could get to the top of their profession, right? Because they were good, others were willing to pay them, doesn’t matter if it’s by payroll or consultants or by their products or whatever it might be to reward them, right, for how good they are in their profession, right? So that’s meritocracy, right? A culture where the skilled, the educated,

best, energized, passionate, etc. can rise to the top in their profession or their market or their sector. And that’s not something you meritocracy write towards in the ancient world during the Roman and the Greek time. ⁓ Judaism writing maybe 2000 years ago, 2000 years ago, writing a lot of the post-Bible time later. ⁓ Renaissance.

the emergence of a science right from the 6th 7th century and on, definitely with all the technology innovation over the last few tens of years. But that’s the risk. So that’s the techno meritocracy, At the of the day, right? That building right to a, technologists and others, right? To rise to the top of their profession based on their merits. What happens now or the danger is that due to the

⁓ use of AI technologies, the world can change significantly. Where few vendors that have a lot of resources, ⁓ technological resource like ⁓ foundational models, energy to run them, a lot of GPUs, land, water to cool, those huge data centers, et cetera, will start to control more and more, right, of what humans and the best ones

could actually contribute to the economy or society, et cetera. so think about it’s almost a reversal, right? And that’s why I call it kind of techno feudalism. It’s a reversal of the best will rise. It’s the one that are going to have a lot of resources, land, energy, GPUs, foundational models, so access to them will rise. And a lot of the others will actually go down potentially because ⁓ AI can replace a lot of them in theory.

And I think we see that though, if you’re looking on unemployment, changes are look little. I think they are actually the undercurrents that if you inspect well, and even just, know, your friends, right, working in, let’s say the technology space and others, see some of the challenges already started because there’s a lot of belief and I think for a good reason that AI can replace, either replace a lot of professions or at least minimize the

level of merits required by individual to conduct their profession, which again will lower the skill level, lower the reward for the skilled or educated, hence kind of reversing a lot of the meritocracy trends that we’ve seen for many years. Make sense?

Federico Ramallo (22:27) yes, yes, I think it makes sense, what you’re saying is that now skill can be replaced by ⁓ resources, by you know, can put more resources, it’s about who has more resources rather than who has more skills, right? ⁓ and that’s why the merit is going away yes ⁓

Gidi Cohen (22:42) Exactly. that’s a huge risk for yourself. Exactly.

So, look at that. It’s a very dangerous trend that as society we need to watch and understand do we like it, don’t we like it, how do we want to tackle it, but I think it’s really dangerous.

Federico Ramallo (22:59) Yes, I think that something similar happened before ⁓ If you remember the samurais, they would develop for years and years the skills of sword fighting and ⁓ the same happened all throughout the world ⁓ sword fighting and who is the strongest was ⁓ a skill that would give you the merit of

winning the wars and winning the battles and winning, you know and then suddenly ⁓ the gun power is invented and now you don’t need anymore, you know, fighting skills because now somebody with a gun can kill somebody that is bigger and has been trained for so many years, right? And that, you know, the same thing happens now those who has the bigger guns can win the wars, right?

Gidi Cohen (23:54) Yeah.

No, exactly. I think that there is a lot of claim, of course, that like the Industrial Revolution and since then, the quality of life, the size of economy just grew because of technology. Yeah, there was some disruption here and there, dislocation of different professions, et cetera, but it always improved. I think that the big difference this time is different because the reason it was improved because it actually afraid people to do more skilled, more…

merit-like work where their skilled education energy could come even to a better gain in their impact than before. But if that is not suppressed, we may not see the same pattern as we’ve seen in the previous technological changes and I think that’s a risk.

Federico Ramallo (24:39) Right, right. I have a 10 year old son, so ⁓ I am teaching him ⁓ and one of the things I’m trying to teach is a value based system because I think that’s going to be much more important in the future than any particular skill because those skills are going to be eventually replaced by AI, right?

Gidi Cohen (25:03) Yeah, a lot of them at least.

Federico Ramallo (25:06) Yes, so I’m trying to teach him that because I feel that what happens right now with AI is that you’re still in control, you still have to be the one that guides, right? So I think that we’re still going to become the captain of a more complex AI eventually, right? ⁓ That is going to be able to give us more complex tasks, but still it will depend on us humans to tell where it should go, right?

Gidi Cohen (25:34) That’s at least the whole.

But that’s starting to change. Think about the genetic AI and basically AI becomes more autonomous and smarter. And again, there’s some amazing technology out there. It’s going to be super tempting to let it do its thing, which in many cases it’s actually great. It’s not bad, right? If you’re looking just technically on lot of the capabilities, it just might be bad for humanity or society or people that have dislocated positions or reverse meritocracy because

Federico Ramallo (25:37) Yes.

Gidi Cohen (26:04) everything we are trained on, that again, the energized, smart, passionate, skilled, educated can rise to the top. They know maybe I don’t need any of those skills anymore because it doesn’t apply. Something else smarter can do the work for the society instead of me, right? And I think that’s part of the danger. But you know, we only need to watch it and see what can be done about it, which is not very clear.

Federico Ramallo (26:20) Right

Right, right. ⁓ What other risks do you see if AI platforms consolidate too much power?

Gidi Cohen (26:35) Yes, so I think a lot of that are society level risks, right? So that’s why I call it techno feudalism. I don’t know that I want to live in a feudal society where only very, very few control the land resource, whatever it might be, right? Whatever they mentioned you would define the resource to be. So yeah, I it’s not going to be a pleasant society. think that the…

people think that actually there will be a lot of great free time, the government will pay you great salary for doing nothing because everyone will be richer. I don’t think that’s how economy works. I think what will happen is there’s going to be extreme resource ownership, let’s call it that way, ⁓ in fewer organizations and lot of people won’t enjoy those type of benefits. So yeah, I think we’re going to have more extreme society and that’s it.

more polarized society, which I think is a huge risk.

Federico Ramallo (27:33) Yes, yes. Reminds me of a story that I’ve read about. ⁓

Gidi Cohen (27:40) I don’t want to depress you or the audience. that’s thing that we have a really good direction.

Federico Ramallo (27:41) hahahaha

Yeah, I mean, it sounds like a dark future, but I can understand that that’s possible, right? So yeah. ⁓

Gidi Cohen (27:45) Yeah, go ahead.

Federico Ramallo (27:52) It reminds me to a story that I read many years ago. Isaac Asimov was talking about this centralized government that was basically an AI agent. He wouldn’t use that word, but a computer sophisticated enough to manage the economy and the production everywhere. And ⁓ it’s similar to what you’re describing.

Gidi Cohen (28:18) Yeah, and that’s exactly the risk of that, right? That you can say if this mega computer or mega entity is going to optimize its outcome to the society, it’s okay, that’s great. Why not let some smart something, whatever it is entity to do that? But typically that’s not how it works, right? When there is concentration of power, it goes to whoever owns the power and directs the power.

Federico Ramallo (28:43) Yeah, the idea of the benevolent… Yeah, the benevolent dictator is a dream. It sounds good, but it doesn’t usually happen, right? It happens for a little bit and then it decays.

Gidi Cohen (28:44) That’s human society.

Exactly. Exactly.

think it’s part of teaching. It sounds like the solution to some problem and then the solution you can never get rid of.

Federico Ramallo (29:09) Right. Right. ⁓ So what advice would you give to founders ⁓ trying to build a highly technical enterprise focused, to try to solve enterprise focused, highly technical problems? What advice would you give to them?

Gidi Cohen (29:29) Yeah. At least my perspective, and I’m sure other people have their own perspective, but when you’re looking on deep technology, at the end of the day, it’s about the product, right? There are a lot of people out there that have experience of how to grow a company, how to conduct marketing, sales, et cetera. But at the of the day, what you transact with the end customer, let’s say with enterprise, is a product or subscription or whatever service that provides value to them. And the…

And that should be kind of at the end of the day the core of the organization, right? So the products need to be really good, they need to have the technology to actually solve the problems, again part of the issues in our space. I think there are dozens of companies that are selling for a lot of money for 15 plus years in the security and never solved any real problem.

So you can ask why people buy them because they have to because of compliance reasons, because it was the best alternative. And I understand how it developed, how the industry develops. at of the day, my advice to founders, focus on the product. Make sure it really fits your target market. That’s one. Second, understand where the personas, which are changing over time, that are going to buy and use and operate those products. And nowadays organizations…

because of the economy and because of AI, have a lot of pressure on efficiency for the people that they have, right? Which means product need to be simple to deploy, ⁓ simple to use, bringing value very quickly, right? You just need to understand what environments organizations are ⁓ operating in and make sure that the product that you develop solve the issues. It fits the way that you can.

that consists with the go to market strategy, consists with the funding, all of this has be consistent with each other. It’s not kind of like, let’s develop some cool technology. Later on we’ll find customers, later on we’ll figure out if the product is a great match, if it’s not, we’ll fix it, et cetera. It has to be all of that by design.

Federico Ramallo (31:25) Right, right. Interesting. ⁓ So where do you see AI trust and compliance ⁓ would go five years from now or in the future? Where do you see that trend going?

Gidi Cohen (31:39) Yeah, I think that there will be multiple elements, right? If you can put them in a few big buckets. I’m sure there will be more more regulations and compliance requirements around that. Okay, I think it started, we’ll see a lot more. And I think the more society, governments, parliaments will understand some of the issues, there will be more control around it, right? People compare it, which I don’t think is comparable, but compared to nuclear energy,

knowing those were very dangerous technology, again, useful for certain purposes, can be challenging for others, but here, governments could agree, out control it and how to apply the right regulations, et cetera. Not saying it’s the same or not, the point is that it’s possible. And I think that the sooner a society will understand that there should be some bounding box on the use of those technologies.

There will be again regulations, sometimes overregulation, like happens a lot, right, overcorrection, but that’s one they mentioned that I’m absolutely sure will happen. ⁓ I think second thing that will happen is that the organizations will, there will be enough, let’s say, industry knowledge that controls around the use of AI and data, et cetera, must be put in place, not as an afterthought, but as part of the

fabric of every organization that is actually adopting those types of technologies. Now what happened a lot in the cybersecurity space, as I’m sure you know and the audience knows, typically cybersecurity solutions are adopted as a wave after there’s a technology adoption, say cloud, mobile, whatever it might be, web, before, et cetera. It takes a few years to understand the type of risk and then a few years to say, maybe I need to buy something or to put some policies in place. Then there’s a whole industry that develops around that.

Those cycles are going to be, must be much, shorter. Because the level of risk organizations are going to face is so high that if the industry, right, vendors like us and others are not going to be ready fast enough, an organization not adopt those technologies fast enough, are either going to be sidelined because they are not using this great technology or set of technology called AI and with all of the benefits on one hand, or they’re going to use those technologies recklessly and…

put themselves, their customers, employees, et cetera, at significant risks. So I think that all of this timeline is going to be condensed significantly, or at least must be condensed significantly.

Federico Ramallo (34:18) Right, right. What I’ve seen happening in the past is that there is innovation, right? I’ve been doing software since the dot-com era, right? So I’ve seen many cycles, right? And one of the things that I see happening is that there is innovation, right? Which flourished a new category, a new, you know,

a green field, right? There’s a lot of green field opportunities, right? And, you know, some of them become great, some don’t, right? ⁓ New projects become something great, some others don’t. But… ⁓ And the vision of what we’re seeing ⁓ changes throughout the time, I ⁓ was reading a review of Back to the Future, Where in the 90s, if you have a fax machine, you you were rich, so…

their portrayal of 2015 was in the house when they fired ⁓ Marty ⁓ they have four fax machines so for them that was they are so much advanced so ⁓ the same thing happens here so with innovation you have these paradigm shifts and this innovation of new things and then

Gidi Cohen (35:18) Sure.

Yes, okay. Yeah.

Federico Ramallo (35:47) ⁓ you get to a point where you need regulation, To regulate what’s going on. Now, with regulation, then what happens is that you kill innovation up to certain point, right? It’s a kind of necessary evil for that to happen, right? ⁓ Privacy rules ⁓ are something that we as users want, so those are one of the regulations that now we need to set in place, right?

Gidi Cohen (36:14) Yeah, great. I think that we also need to remember you have the example of the back to the future with a FoxeMine machine, which I think is a good story and a good reminder. But think about the rate of change that happens now with AI, it’s just amazing, which again means from a security or trust or risk perspective, that it’s a completely moving target. Think about terminologies that were used just two years ago.

like rag, right, the retrieval of many generations, the way to do stuff, cetera, seems like outdated. people didn’t even start using that yet. It’s already outdated potentially, right? So the rate of change is so high and there so many different elements. It’s not one thing that I think we’re going to drive a lot of organizations completely crazy until they will figure out what they need to do, what they shouldn’t do.

because not everything you need to chase just because someone said, okay, something is a risk, but to know what’s the real risk and what kind of the technology infrastructure fabric they need to put in place to protect will be a challenge by itself and due to the rate of change in the level of risk. But I think it will stabilize at the end of the day and there will be again some regulations, some best practices, some common technologies that everyone will understand that regardless of the specific AI implementation,

needs to be put in place to put the right type of godrex.

Federico Ramallo (37:37) Yeah, I think that maybe this is not completely accurate, but I felt that in the dot com era we were growing linearly and now with AI things are evolving exponentially, right? And I’m afraid that legislation is going to take a lot more time to catch up, right? As you said, right now it’s a moving target, right? So I’m afraid that the tail of regulation is going to come.

much later in the game,

Gidi Cohen (38:08) Very, very, very likely. Very likely.

Federico Ramallo (38:11) Yes, yes. And then there is the risk of AI building itself. AI building AI, which could become a whole other thing, a whole other risk, right?

Gidi Cohen (38:23) Thank you.

That’s what my thought exactly when you were just saying that because the reality that AI may build itself and improve itself and get out of control completely. So there will be some point in time, probably not very far in the future. I don’t know if it’s six months, but probably very few years that for a lot of situations, AI can be not just a source of the technical ability to execute something automatically and more smartly, but the origination of ideas.

planning the execution, execution, optimizing its own target function, whatever it want to optimize. And then it will become like a beast of its own, right? It will be tough to control.

Federico Ramallo (39:04) Yes, yes, ⁓ right now with you mentioned RAG, ⁓ it builds like 1500 dimensions that we have no idea what they are, but AI knows what it is, right? So we’re getting to a point that we understand how it works on the high level, but then we’re losing control on how it works on the deeper level because it’s complex enough that we don’t really know, right? ⁓

the non-deterministic ⁓ outcomes ⁓ of the process, those are factors that I believe are going to become a higher risk in the future.

Gidi Cohen (39:48) completely again circling back to bonfire and our focus on unstructured data that’s exactly part of the complex we are trying to solve because every time you analyze the same stuff it looks slightly differently the same stuff is not exactly the same stuff it comes up in different ways so there’s a huge amount of variation and therefore right you need to have type of solutions you actually can inherently deal with those variations without the need to

be over specific what kind of patterns to look for, et cetera. I can closing the loop on what you actually said in the opening as well.

Federico Ramallo (40:18) Right, right, that’s very interesting, yeah. And that is attached to the level of complexity of the attack that is coming, you know, more more complex, right? And mimicking humans, right? Real humans, right? Or legitimate users, right? ⁓ And they’re harder to detect, yeah. So I can see how Bonfy AI would have a big impact in the industry, yeah.

Gidi Cohen (40:38) Yes.

Yeah, that’s definitely our plan. And again, I think that this is going to be a long way to go for the industry, for the market, for enterprise, for humans, right? To understand what they’re up to. basically what we are here for is actually to help them in their journey, not to slow down AI adoption, probably to even accelerate potentially, but to put the right controls so you actually enjoy them for the benefits that they were designed for without a…

compromising on taking unbearable risks of all of the side effects you want to avoid.

Federico Ramallo (41:20) Right, right. ⁓ So, what, you know, after building companies for over a decade, right, decades, right, what still excites you every morning to keep going?

Gidi Cohen (41:34) Yeah, what I love personally is to solve, tackle big problems. I just enjoy it. I enjoy to build an organization that does that. I enjoy driving technology to do that. I enjoy working with customers to identify those pains and helping them, providing the value right there looking for. So I just enjoy kind of tackling big problems. And again, especially in the domain where it involves deep technology algorithms, in this case, AI, data, and all of it together. And that’s a…

Actually that’s great fun, I’m just looking forward to day. Waking up early is like gold because I just enjoy it a lot.

Federico Ramallo (42:09) Isn’t that funny? We just focus on the problems we have in front of our face, and we’re focusing on solving that. And then, ⁓ well, it happens to me. I’ve done that for many years. And then I look back and I realize, ⁓ how much further down the road I am without even realizing I walk so much. I make so much stuff.

Gidi Cohen (42:38) Yeah, I agree because I think it’s not just solving today’s problem, right? Part of it is thinking about where we want to go and how to drive the organization, how it will hit the market in the time where there will be enough demand and realization of that. it’s not about just the tactical.

improvements, which of course is absolutely part of the work, right? Every day you want to make at least one day worth of value to the organization you’re driving or working for, driving, et cetera. But a lot of it is actually spending time understanding how to drive to the future and make sure that we are doing these tactical steps with a purpose as opposed to just kind of, let’s let’s kind of run the treadmill and hopefully we’ll make some progress.

Federico Ramallo (43:22) Right, right, yeah I agree. mean we, as founder, we also have ⁓ a component of dreamers, right? We’re dreaming for a vision. What is not here today, ⁓ but we want that to become a reality, right? ⁓ Yeah, I agree.

Gidi Cohen (43:38) Exactly.

Federico Ramallo (43:39) ⁓ So before we wrap it up I ⁓ have a word from our sponsors ⁓ This episode is brought to you by Density Labs ⁓ If you need world-class engineers fast ⁓ Hire the top 2 % of better latam talent ready to join your team in 24 hours Save big, move fast, visit densitylabs.io So thank you Density Labs for sponsoring this podcast ⁓

and before we wrap it up, Gidi, we’re running out of time, do you have any final remarks you want to share with us?

Gidi Cohen (44:17) Yeah, would say that for every listener, right, just to be clear, I think that AI and all the innovation happens over many years, but definitely over the last two years and this year by itself, super exciting. And from my perspective, it’s not about, as I said, to slow it down, to regulate it, et cetera. It’s about to make sure that actually society, organizations, people can use it in a safe and productive way.

And that’s why we’re here, right? We’re not dealing with every problem on earth at Bonfy, right? We’re dealing with the data security side, which I think is the most exciting and probably the most challenging.

part of the let’s call it AI security because at end of the day, all the plumbing, as I mentioned earlier, are important, but what goes through the plumbing, right, through the pipes is the intellectual property, the knowledge, the private information, the regular information tends to be protected. And that’s what we’re focusing on. So we are here to help the organizations make sure that they can solve the problems they had, the predated GNI.

but definitely because of the partner of their journey of adopting AI technologies and just make sure that they do it without taking a risk on themselves that they should not take. And again, our technology can be the one, or least one of the components that can help them do so in a scalable and way that is compatible with their technology fabric and their AI initiatives.

Federico Ramallo (45:41) Amazing amazing. So thank you very much Gidi for joining us today I really appreciate it and I’m looking forward to see where you take Bonfy AI in the future

Presented by Density Labs. We help mid-market companies ship AI to production, not demos. New: Agentic AI, explained from production — what an AI agent actually is, and when a workflow ships instead.
Don't miss it

Listen on your favorite app