Video: Enterprise Readiness: A CISO's Guide to Deploying Claude | Duration: 3296s | Summary: Enterprise Readiness: A CISO's Guide to Deploying Claude | Chapters: Welcome & Introductions (4.72s), Heavy User Poll (130.24s), The AI Opportunity (233.265s), Empowering AI Adoption (330.505s), Raising AI Ceiling (465.735s), Breadth and Depth (598.435s), Security First Principles (756.095s), Data Controls Overview (959s), Compliance API Integration (1074.93s), Inference Hooks Innovation (1273.31s), Deployment Models (1507.475s), Audience Survey Analysis (1644.44s), AI Maturity Roadmap (1770.63s), Staged Rollout Strategy (2078.325s), Data Controls & Training (2420.63s), Security & Hooks Deployment (2804.25s), Closing Remarks (3115.735s), Closing Remarks (3171.675s)
Transcript for "Enterprise Readiness: A CISO's Guide to Deploying Claude": Hey, everyone. Really, really excited to to have you here. I see a lot of people join. I see some uploads in the in the flags and the people from, all around the world, including some people from very late hours. So I'm really excited that you joined, on a Friday night. Yes. So, I'm Dor. I'm, from our product, product team for security. My role here is to help enterprises really adopt cloud in a secure way and build the product so they fit exactly, what you what you wanna do. And I'll share in general that I'm very excited about, what we're doing here. If I had to give, one example of how security teams really empowered companies and really changed them, that's monumental. Like, for example, one automotive company I I know fairly well, they had a certain security approval to connect a few connectors to few data sources, and and we're able to reveal really how the data shows that they have misalignment in their production with inventory and things that really save how companies operate. And those companies who's gonna have the head start for AI are the companies who are really going to make the impact in the next era with AI. So really, really excited about what we're doing here and, with me, in the next hour will be Belinda. In general, we'll, share a recording. Feel free to ask any questions. We'll have enough time for q and a in the end and give us feedback. That's part of why why we do it and why we're excited. We'll go over these these topics. We'll try to be as practical as possible and as specific as possible and show you how we see success patterns and and what we're seeing in the market. I think Belinda, wanna introduce yourself? Excellent. Great to be here today, and thank you all for joining. My name is Belinda Neil. I'm the managing director for financial services here at Entropic. Incredible. So we'll start with the poll to see to see a bit on on the audience. So I'm curious how many of your users I know that defining heavy users is hard, but how many of your users are what you would define heavy? We we'll do it there blind in a way. So take a few seconds, and and, we'll share it, from our end. Drumbeat. Okay. I see the vote three still going up. We're gonna have another one. We'll try to have the same, participation rate, which is amazing. Great. So if I were to share, we're seeing, interesting stats. You're we're seeing that around 45% of the people who are here would say that between zero to 25% are are heavy users. Belinda, any any initial takes or observations on your end? Yeah. It's interesting. I think this actually holds quite true to the eighty twenty rule that I think we we generally see where we see really a concentration across heavy users in a lot of enterprises at that top 10 to 20% level. And so it's really great to see folks' feedback here in terms of what they're seeing in their own experiences, and and hopefully, we can share some lessons and some practices around how to encourage people within your company to kind of move up that adoption curve for AI. So that was a great way to start the webinar. Thank you so much for contributing to to our poll here. So moving into the first section, I thought I would start a little bit to talk about what the opportunity is. The business today is already using Agentica AI or is about to, if they haven't already. And so we really wanna talk about what that looks like as we bring Claude and Agentica AI to the enterprise. Firstly, to start off, I I like to reflect on the fact that, with new technologies, sometimes adoption does take time. With cloud, it took really a decade for that technology to go mainstream into the enterprise. And as you can see here from this timeline, we're just showing kind of the indication of what that took in terms of the first leap of cloud and then the broader adoption going upstream ten years later in 2026. With AI, I think sometimes we forget that AgenTik AI and AI technology has only really become, mainstream over the last few years with the launch of ChatGPT, back in 2022. The majority of enterprises started going mainstream in their own enterprise adoption programs really in the 2024 period. And here we are in 2026, only a handful of years later, seeing this technology not only mature in AgenTic technologies, but also, really capture the the adoption of the enterprise. But we are seeing that disproportionate adoption rate across enterprises with super users and kind of the the middle users and then kind of some low adoption as well. And so what we really wanna reflect on is, firstly, this is a new technology. Two, it's still very early in its adoption wave for the enterprise. And the reason for that is we wanna be really thoughtful, and we wanna build trust and governance as we bring this technology to enterprises. So we're here to really help share some perspectives on that journey. Yeah. And and at least what what I'm hearing in in my conversations is that some security leaders say that we figured out cloud security only, like, three, four years ago, not even in 2016. So there was a big time between that to actually take place. So as we think about, today, you know, we really think about the CISOs bind. You know, you say no to some of these technologies and and you create the risk of getting shadow adoption of these tools with individuals using it on their personal devices or their iPads. But the goal here isn't to, you know, say no. The goal here is to create a legible risk framework around how we think about these new technologies so that we can understand the risk controls we're putting in place to ensure we can adopt this technology across our business in a way that allows our teams to drive value from this technology and doesn't necessarily bind them or stop them from engaging completely. Because we know that business users want to use this technology to create really great value for their customers and also their own productivity. So the real question we have today is how can security empower our AI native 10 x workers? That goes back to the poll. We really do see this concentration of employees that are really getting multiples of impact using this technology. So where do we start? There's two main approaches we see in the enterprise today. One is what we call raising the floor and the other is what we call raising the ceiling. Raising the floor is really where we help support people in using tools to create everyday productivity. This is the tools that people would have in their enterprise chat or their enterprise co work type products where we're really enabling that baseline level enablement, giving people the skills, giving people the tools to be able to drive productivity in their day to day. This started first and foremost in engineering a number of years ago with a lot of Copilot products. Now we're starting to see that across the knowledge workers more broadly as people start to use these tools within their own work. What we're seeing is the first draft, the first email, some analysis, some, capturing of unstructured data in a way that may not have been possible before from a time or an experience perspective. We're really starting to see people from the ground up start to create productivity and benefits, using this technology. And and the conversation there is really about capability and cost. How do we scale this in a in a way that's impactful and drive productivity of our people? The second is raising the ceiling. How do we actually create one of a kind outcomes with this new technology? These projects are either sprinted from a top down approach where a part of the business, a process, a new product is reimagined with AI at the center, and we're really starting to think about how do we really transform something, not necessarily just make it incrementally better. This these, one of our kind outcomes can also come from individuals. Individuals that have simply created education around themselves to be able to use these tools and deploy these tools to reinvent the way they work from the bottom up or from the edge of the organization. And what we wanna do is really find ways to encourage the innovation from the top down or the bottom up so we can really start to rethink what's now possible using Agencia k I today in our enterprises. Now the question is where do we find this one of a kind, opportunity? Where do we find these Agenctic AI use cases that are really gonna transform the way we do work? And right now, every company does have a handful of these people. Sometimes we see it already. We've seen some innovative pilots or use cases that have already emerged from our existing programs or use cases we've invested in. But sometimes we don't even know yet. Sometimes people haven't even started their journey because they haven't had access to these tools in their roles. And we really wanna create the baseline opportunity to be able to give people access to the tools, to then be able to find ways to apply it to their work. And often we don't, know who they are necessarily, but we do find signals, as we start to look at usage data. So one of the things we recently discovered was we looked at some usage data from an example enterprise and we actually saw something really surprising. We found some usage on a Saturday and actually you would ask yourself the question, why is someone working on a Saturday? Well, actually, in this case, they were actually experimenting off hours on a project that they were really passionate about and using their time and passion and energy away from the meetings, away from their schedule to really reinvent and create something new. And so looking at some usage data can also show you patterns around who your super users are, who's really pushing the AI to the edges of your organization. And as you can see on the slide here, perhaps there was a speak of activity on on on Saturday and on Monday morning, maybe someone said, like, you have to see this. You start to see the passion and enthusiasm from people embracing this technology. And so giving them the opportunity to do that, in in my experiences, has led to things like champion networks across organizations, being able to drive and sponsor hackathons to be able to give people the tools and the capabilities to use their technologies, starting to rethink about the ways we do things. How do we change, our practice around code monetization? How do we reinvent the way we do KYC in a bank? How do we give people the opportunity to ask the foundational questions of what to transform and then give them the technology skills in the right governed way to enable them to be able to do that. So our challenge and opportunity is expand access to this technology so we can find these innovators. Giving access to breadth is allowing us to search to find those innovators in an organization. This usually starts with rolling out Claude across your organization, giving people the tools and the technologies, finding those signals, and then investing in-depth. How do we not limit the innovation these people have access to? How do we give them room to run and room to innovate within the security parameters that we wanna set at a at a at a guardrail baseline, but also not stop them from doing potentially transformative things to our business? So we like to think of finding the frontier at Anthropic as placing bets. So we could go and enable a few extraordinary people, but we also wanna be able to create the opportunity set of being able to to allow people doing their roles, doing their jobs, meeting customers, and finding these few, opportunities that will really return a high value. So what's our approach at Anthropic? How can we use what we do here to inspire you? At Anthropic, we really go deep. We really create a lot of leverage for each of our employees. And the way we do that is to create, the the innovation opportunity for everybody to have access to these tools and to really provide a lot of leverage so we can create the ability for people to innovate. Now we are a small team, and we we do provide unlimited access to these tools internally. But what we also find is the newest and greatest ideas can sometimes come from different areas of the organization that perhaps we wouldn't expect. So we've taken the approach of really going deep with each of our employees and provide, the access of what people do in terms of the depth. But also, what we see in the market is usually, breadth. So we give people a little leverage each in terms of how we roll out these tools. So I would encourage you as you think about your rollouts to think about breadth and depth with your employees and your your populations as you start to think about the capabilities, but also the opportunity ahead. So as we've gone through the opportunity set, now we wanna talk about what are the risks, what are the controls, what's a framework we can put in place from a CISO's perspective to actually create, well thought through deployment of Adenta k I in the enterprise. So, Dua, with that, I'll pass back to you. Amazing. Yeah. And I I love the examples. You gave me some flashbacks. Those of you who haven't seen the Marty McConaughey commercial yet, that is like an example of breadth you give every salesperson you have and and taking it from there. Yeah. So, we found that very, specifically what really helped security teams is going through first principles of security items, things that they're already used to and taking it from there. So really make it legible. So going first on, the content, the data, a lot of security goes back to that. Then going to permissions, actions, what can happen from there on which on what behalf and on behalf of a blast radius. So assuming breach always, what happens there? And then once it happens, what visibility and auditability would the security team have? Those four questions were not invented here, but they really help security teams think that through, and we'll now connect them to each one of the controls that we're adding. So with that in mind, I would love to take a step back and, and also emphasize why this webinar and what you're gonna see is is important. I'm meeting a lot of teams and actually, yesterday, I met a a few folks from Brazil, in New York. And they've said that they've taken a look at at what our security posture is six months ago, and they needed to reevaluate it, after after we went through through this content. And why? Because we at Infobrik put we saw how much it means to the enterprise to put enterprise readiness and security in first place, and we really put it as priority. So you can see the momentum, and we keep keep things rolling and and shipping those every week. We have, like, an admin, emails that are already showing you those things and and through our LinkedIn pages. So there's a lot of momentum because we saw the priority in helping securely adopt AI. And if we go back to the former side, we've created these controls. I laid them out in a second also in a different view. But really going through, the content we map to each one of those things and the actions, for example, RBAC and per tool policy on MCP connectors is something that really helped out our customers, really from their blast radius. So we're investing a lot, especially as models go stronger into a sandbox execution because we really believe that that's, like, the most safe and trustworthy way to go into, execution in host, and we're doing a lot. We'll share about that in a second as well. And then observability, which we'll go deeper into. So each one of those things really map into the first principles that we showed. And if I had to show you a high level and feel free to to get a a and see, but we bring those down internally to few different categories. And then in each one, we go very deep. Each one of them is a success story of a of a customer. I'll say that some of them have more dependency on their network controls because how they're built. Others who are more slightly more like cloud native companies care more about the data, so on and so forth. And we've just seen how companies really take this recipe and implement it as as we go forward. So the main thing I want you to take here is that there are a lot of controls. A lot of them evolved. Some of them are just regular SaaS controls like single sign on and scheme within reinvent the wheel. But on others, like what we're gonna show, for example, with Inference Hooks, that's much more AI specific and innovative on our end. So a big piece is is focusing on data controls, and we'll spend more time there. So I want you to take that we have this very unique composition now of, retroactive controls. That's our audit log compliance API. We're expanding the surfaces there as we speak. If you were looking at this slide two two months ago, it was only the top left of CloudCheck, but we believe that we need to allow you to consolidate and seeing things retroactively. We'll dive deeper into that in a second. And also on the right side, you can see your real time validation that is in line. So they both go end end in hand. And for that, we add additional layers of defense for each one of those things which we'll focus on soon. So I think Belinda and I were joking that you cannot talk about AI without talking about prompt injection. I would say that the like, there's a lot of, of statistics here that we've published in the past. But the main things I want you to take is that we've heard the market and we've made the models better. Like, the the one thing that cannot be replaced was improved and resolved it in the source. And we're seeing massive gains, and we're thinking that we're very close to to resolving this issue definitely as as much as the attention that we've got in the past. So our models are really state of the art on on the action. And also for everyone who's thinking about open source models and all those things, you can see how how those, behave with the same evils. I want to focus then on the compliance API, which I mentioned earlier, and, I'm working very closely with, an insurance company that's very excited about, those kinds of things. And, for example, the main things that they said they cared in AI specifically and maybe the best analogy we have is, like, productivity and communication tools like Slack or Teams or emails, but it's about the content, the sessions, the transcripts, and then activities, who did what, when, the settings. A lot of customers really want to make sure that they are configured to the postural level that they want to be configured. And also export and deleting, we don't only provide visibility, but if a user actually had done something that, that doesn't allow the policy, our customers can actually delete those things. So those are the main things, and we're going surface product by product, and we'll show you that in a second, and really consolidating into this primary audit tool. Those things evolve. We used to have OpenTelemetry. We used to have Outlook export, but this is what we propose and what we are, really focusing on as a strategy because it does have a server hosted version that you can, like, come and query, in the best way. And it all maps back to your existing security stack. So our approach as Anthropic is really to work with you and your security vendors to get the most out of the existing stack where you're already used to and meet our customers where they are. We have more than 85 security vendors who, integrated with us through compliance API. The best use cases I'm seeing are, DLP, to its extent and and, security vendors, which some of them are here on on the screenshot where you can see that they're pulling the transcripts and risky and, flagging risky content and similar. And, and we're really seeing how those pick up in the market a lot. And the other is SIMS and just, like, streaming, the events to to your SIM and really focusing on your existing security operations and how things are already set is massive. And we're seeing both ease of deployment with SIM, I would say, as a as a massive, massive integration and also a fairly high value to to allowing you to do that. So really focus on this is like a very unique catalog that we have, that allows you to plug it where you are. We're growing the list of vendors, that are working with us. So if you're a trusted vendor and you can check it online is is not there, please, push them to us. They can apply. They can be part of it. And we're already seeing that as a win win win for everyone on how do we push AI, faster. I had a chat with a health care a big health care company where I showed them, like, the catalog of integrations asked if if, they have their favorite vendor in there, and they said we we sort of have half of them, in in our, in our company. So really focusing on the very specific use cases, the three the risk models that you have really helped customers. Amazing. I want to go forward and go back to the real time enforcement. So this is true innovation that we've delivered here in Anthropic, one month ago, and we really like, to, to share it, even more broadly. Customers told us two main things. First is that they want to have inline enforcement on data. In some use cases, gateways were a solution for that, in the past, but as AI footprint evolves, goes beyond developers, the gateways fell short in in their coverage. And the second is that, they want this enforcement across all cloud products. Doesn't matter where it's via the mobile, via the web, wherever it came from, they want this coverage in an agentless way. That was the first thing they said. The second thing that they said is that DLP policies are fairly complicated. And why Belinda can see sensitive, credit cards, but door cannot is is a question that, is really, like, in the core of the business process that you run, and redefining those across the board is very complicated. Even if you can have one query, that's fine. Like, actually, delivering it in a in enterprise grade is fairly complicated. So what we've developed with that is what we call inference hooks. So from the left side, no matter where the user comes in a prompt, we actually made a proxy layer hook in our server that mimics what we had in cloud code on the device, but actually made it much broader. So beyond cloud code and maybe it's server side. The server side is, what catches all of our products, and then we can deliver that prompt into your AI security server. We can talk about and then that AI security server, if it's allowed, it goes to the inference, go back to the user. If it's blocked, shows the user notification of a blocked message with an education message that your teams can can, shift and modify. The interesting things about here that I'm seeing with customers are first the AI security server. Some like, 90% of customers go with off the shelf vendors, and we already have more than 10 vendors. Some of them are the biggest you can think of. Some of them are smaller start ups that that support it, and have, live customers in production. Or we've seen about 10% who self build this AI security server. They add their nuances. They want to fine tune some of the things there, and they just built it today with the cloud or whatever your AI secure your AI tool. Those things are easy to meet, say, protocol requirements, so on and so forth. So a lot of customers have built it, and, customers really loved on top of it the fact that it's server hosted because for their deployment, just one line of configuration, and it guarantees that every prompt that goes through on tropic goes through that validation layer. It doesn't require specific SDKs, gateways, so on and so forth that sometimes fall short in their coverage. So this protocol, is open. Nothing there is entropic, and we published it. And also this, method is open. We're really excited about having more vendors, more labs. Everyone really adopted and had the inline component. Some of my chat with the CASB veteran said that they wish they had it ten years ago in some of the of the SaaS products. And the best thing I want you to do is to take it from here. Try it fairly fairly simple to try. And if, you have additional use cases that you think that the hooks can allow, reach out. We'd love to hear the feedback. We're expanding our coverage beyond just a prompt as we speak, and we'll share more about it. But you can imagine what we allow with cloud code, and we're gonna support it on the server side in a nontemparable way, which is even more robust. Amazing. I'll share just because we spoke about gateways a bit and and, to to make sure that everyone kind of is on the same page. We have two main deployment models, and and we meet customers where they are. In the past, Bedrock, Vertex were very popular. And we're seeing a lot of growth in the what we call first party where you go through Entropic. There are more products that are supported through Entropic. You get the updates faster, and you get, additional features that we cannot push, through, through the first party, through a third party, and you have the Entropic managed, control. So for example, everything I show almost everything I showed you earlier maps into an admin console setting where you can set in a fairly easy way in anthropic. On the flip side, we're seeing customers that, that prefer to go through Bedrock. There are a lot of data residency in The U, small things there that that, they they just do better. And, and, and we're hopefully closing the gaps. And we're really but those deployments are fairly focused, I would say, on a cloud code, in in their nature with additional use cases of knowledge workers that are, that are constantly improving. In general, if the main issue that you're facing, I would say, is, working towards your cloud commits, There are solutions for those things. So in case that's the only issue, like, please, chat with us and and see if we can solve it because there are existing solutions for that. Incredible. So as I think Belinda started, we've seen how, AI is really picking up and, we're really, now want to focus in the second half on the knowledge workers. Those, the primary, populations of our for organizations. So I think we'll start with the with the survey. And, and curious about if we focus on your knowledge workers, how many of them what percentage actually use some type of a generic product? Doesn't matter where they can. So take a few seconds, vote. I think in the meantime, I'll say that really excited. I've checked through the the attendees. We have people from Thailand, which is really, late. So so thanks for bearing with us. And, we have a good representation of the Nordic countries as well. So that, surprised me a bit by you by the quantity here. But yeah. Yeah. So take another second or two. I see more flags now pop up, so so it's a good good sign. Awesome. So we'll we'll share a bit on on the results. So I think it it's maps, at least in my, very basic analysis, a bit to how people responded earlier, with the with the AI fluency of of heavy users. So not surprisingly, but these are are have good alignment. I'm seeing that a lot of them have, like, you're seeing less of your knowledge workers that are already using a generic product. And I think that matched the things I'm seeing in the market. Belinda, any any initial thoughts on your own? Yeah. I think this is an interesting representation of what we're seeing, which is a lot of our customers right now are a little bit more familiar on some of the chat tools for knowledge workers, and some of the agentic capabilities are still early in their rollout through enterprises. So we anticipate that to continue to grow, but we do know that some people are at the start of their journey enabling these tools in the right thoughtful way. So that's why we wanted to host the webinar today to update you on what the capability, has been in terms of what we've been developing on enterprise control. So that really does reflect well, probably what we're seeing in terms of where we are, but where people's ambition is to go for further forward. I I would also say is the developers are certainly probably the most advanced at the use of agentic tools within the enterprise today with the likes of, tools like Claude Code. And we're definitely seeing that capability move through into knowledge workers. So as we flip over here, we just wanted to take a minute to share kind of the road ahead in terms of where we've been and where we're going in terms of the maturity of the AI tools, that we're seeing. So as we mentioned before, you know, we really started rolling out AI in the enterprise as a chatbot. And this was really an interactive tool that we were giving people where they had to ask things and then wait for the response. And it was very active in terms of the person in the AI tool, interacting. What we saw next was the enterprises started to bring in more foundational knowledge to those chat based tools. And the reason for that is AI really did need that enterprise context to allow people to do more and higher value tasks with their AI systems. And we saw kind kind of in 2024, this kind of emergence of knowledge bases that would start to be aligned with these chatbots. What we saw next and where we are now is the ability to create agentic loops, within the knowledge worker tools that we have, which was a surface we we called Cowork previously, and that has just been rolled into Claude more broadly. This is where we can start to integrate Claude into more high value tasks, where we can start to create skills and schedule tasks where the agent can start to create real leverage, and and automation for an individual knowledge worker where they don't necessarily have to go into the experience to ask an AI for something. It can potentially happen, asynchronously or in the background as as the knowledge worker is using the tool. So we saw that first with with Claude code creating that kind of scale and multiplier effective value. We're now seeing that within Claude itself. What we're also seeing is the use of Claude within other surfaces. So the Microsoft suite or other embedded products, we're really starting to see people innovate and use Claude, within the capability stack across teams today. And hopefully what we're gonna start to see more and more in the future is as the frontier continues with the advances of capability is more long running agents. You know, how do we continue to allow Claude, to create more automation scale in some of the enterprise processes that we have today? So just to kind of give some examples outside of the engineering developer, personnel, you know, we're really starting to see real impact from our customers using Claude today across a couple of different areas, and we wanted to just call out a few examples here today. Marketing has actually been a very strong use case for the use of Claude where we're starting to create scale content, but also being able to allow customers to bring in their own style guides with their own customer voice and be able to create really impactful campaigns through a marketing lens. And you can see this customer story here from Cox, which created a seven x return on investment in their first year. The second is sales. You know, starting to think about ways we can really scale, the sales function, go to market areas around customer support and presentations and reports, and really starting to create more value, along the sales journey that that every customer is also thinking about creating scale for. And at ServiceNow, the example here was they found 95% less meeting prep time for sellers, and we're seeing that consistently across the board as people are using AI to now scale what used to be time and document heavy in their previous processes. And then lastly, in finance, you know, we're starting to see the adoption of these tools across the financial services industry, which is exciting. We're starting to see Claude show up in things like Excel and PowerPoint presentations, being able to create the first draft of investment memos and other scaled processes across, our our customers. This example here from Campfire was simply an example where they scaled their bank reconciliation by 90% using Claude. So we're really looking to help accelerate our customers use fraud within not only their knowledge worker enablement, but also the processes that they rely on to ensure they can deploy agents at a safe, scaled way. And we're starting to see these examples also come up in other areas such as HR, legal, other areas. On Monday, we launched Claude for Financial Advisors, which was another, product area where we're really starting to invest in bringing the connectors and the skills to our customers to allow them to use Claude to do more and more, of their work. So just before we transition back over to to Dor and then we're gonna have some q and a in in a few minutes, is just to explain what does this Claude enterprise look like? We use this word Claude enterprise. We just wanna kind of give you a little bit more insight under the hood about what that what that actually means and what's inside the Claude enterprise offering. So as you can see here below, traditionally, we've had the chat platform from Claude enterprise and we've had the product called Claude Cowork. We actually, this week, just talked about how we're gonna bring it together as one interface called Claude. So that's just to explain that that most recent update on on our product strategy this week. The second piece here is Claude Curd, a tool probably known and loved by the majority of people on this call today. Also, we're seeing Claude integrate into Microsoft three six five, as a login, which has been a really great opportunity, for people working in those services to use Claude directly in those tools. And then lastly, we're starting to see our customers build vertical solutions on top of Claude, and you're gonna start to see Claude embedded also in those in those areas that you're gonna see, your existing partners or vendors use Claude. And so we're really looking at continuing to provide value and support for our customers to bring Claude enabled, you know, offerings to you as a customer. I Yeah. My my consultant friends definitely ping me on how Claude changed, how they're doing macros today in in Excel. So yeah. love it. I love it. Okay. So let's let's talk about a roadmap to success, Joel. Like, obviously, we're not gonna go from zero to an entire enterprise overnight. How have you seen customers kind of stage their rollouts and and and adoption patterns from a security perspective? Yeah. So I think in in our conversations with customers, one of the things that came up is the change management as as a big item there, and especially as, as the people here voted. Like, AI fluency is still growing in the enterprises in the next year or so, as we expect. So we're thinking about, first of all, how does a cycle look like? And then how how can you make more cycles like that in your in your organization? So the main framework that we found very successful is really enabling people. Our teams can help with, with that. There is a lot of self serve content in the cloud academy where users can just see and see what can they do. We allow them, to run. We've seen security teams and IT teams really allow them to run, have some experiences, share, so on. And then really taking the feedback. I'll say that, one thing that that I heard, for example, is number of connectors really came up for security teams. As each one of the connectors for many noted workers. What we've seen is that it's not like they interact with 20 connectors every day. There are there is a very concentrated list of one, two, three, four connectors. Many times your email is part of that. Your, for example, that really makes the most value. And it wasn't obvious, in the beginning what those connect what all of those connectors were. So they're just one example. And then tuning. Really, for example, security teams that I was, working very closely with and, for example, a very big, a global firm that I think most people here in in the call know, they've accepted a certain certain risk profile for the initial pilots because they thought that it would be much better if they'll see the transcripts via compliance API, for example, and see what happens there, see how they play with it, and not make it a very waterfall, like, project that is all up in advance. So they actually tuned, as you can see here. After the pilot group, they've tuned their security controls as part of it and really realized what people are gonna do with a transcript. They were surprised for good and bad in the same time, but that gave them the data and the confidence to move forward. So as you can see, this is the the the cycle. And on the right, you'll see that really we've seen how expanded groups, especially in companies that have multiple business units, then targeting a very eager business unit with a a lot of, leverage where you think there would be impact and good leadership alignment was very valuable. And, really, going always on, like, very strong champions, very high leverage, and expanding your spending in those kinds of things, where the, like, holy grail is is what we see as as broad access, where you have much more maturity on what do you allow users and how how your controls are already battle tested in the way they work. And even this change management email that you are distributing or a or whether you're doing the enablement on a Thursday morning versus a Wednesday night, those things really matter, for the success. And I'll say that we're seeing companies who are doing it well and some are, you know, not surprisingly, are not. And you can really see on our side how usage metrics really pick up, once that change management process and that collaboration is being done very well between AI teams and and security teams. You can also think about maybe your own teams as part of that. Like, if you had to roll out, for example, in in entropic, we talk about a a threat, a a investigator agent that we have in our SIEM that really goes through the data. Nothing automatically is done, but just say just triage. You can think about it as, like, obviously, we started with read only mode into only some of the events and then expanded, and then more people could interact with it, so on and so forth. It's all part of this very gradual rollout processes where you have to start somewhere, but currently, if you started, you're getting fairly mature, capabilities out. Anything to add, Belinda? I think it's great. What I would just echo is, as we're seeing people adopt these tools for knowledge workers, they usually will start in various different groups that they're selecting to kind of target a user personnel or an area where you can get some real great feedback on the product, but also validating your security posture here. And and I think that pilot that pilot phase is definitely what we're seeing people start with and then expanding those user groups as as they get the comfort around the controls to then ensure they can get to that kind of broader rollout. So I think a staged approach is very prudent, especially with larger enterprises or financial services companies, and we really wanna help support and get your feedback around these rollout enablement opportunities so we can also support you in those in those journeys. So I think this is a really great way to start to think about how you can crawl before you walk, before you run with tools like Claude, but also provide great feedback to you and the team around what's resonating and what's working. So that's definitely what we're seeing is as we see enterprises scale. Amazing. And then when we think about a new product and and co work is is only one example. And and as we've said it, we're now we're merging it. But we think from our side that we would love to really allow you as much control on your hand in the in the frameworks we already provided. So the same IDP is gonna govern you. The same SIM is gonna push to the same telemetry method and the same the same activity feed. The same egress policies and networks, almost traffic that that you can send is gonna apply here as well. And same admins, so on and so forth. So whenever new innovation and another thing I'm seeing now in the market is that more companies gave chats or some or some basic AI as Belinda said to to their employees, but now want to expand to more breadth and raise this more depth and raise the ceiling. That's where we really see this adoption flow of adding new products, new capabilities, and we really map wanna map those capabilities into what we already provide. So if we go to Claude under the hood, just because we've we've heard it as as a hot topic, we see few different methods and, what most people, the general available product you see today is what we call the local approach, where a lot of the execution is running internally on on your device. We're actually moving that, to a cloud hosted execution in a micro VM. It has a lot of security and user productivity gains. When we released it, some of my friends told me they can finally close their laptops, because the cloud can, can really take that more longer running a generic loop, there. And the other side from security teams that they told us is that once you move the data from each one of the devices to actually, like, one centralized hosted location with all segmented by VMs, that really gives them the confidence that the blast radius is contained and the impact on on the endpoints is much better, and the lockdown is is much more contained. So you can see how we constantly evolve the architecture towards more security. And in general, what you'll see in the next few months is that we're going to promote more and more this one unified experience where it's very simple to the user. They don't need to choose in advance whether it's a chat or a co work. They just go and prompt the task, and based on the complexity, it all scales up and down. And the second piece of it, which is that it's gonna happen in the cloud where it fits in a secure way, remote execution, and interactions that are easier for them so they can one shot their laptops, but also get the best performance. I was on a flight yesterday, and thank god that that, that that thing the entire loop didn't happen and made my device. Yeah. I would just add Door as well just for a minute. I think, you know, we're really listening hard to the feedback of enterprises as they adopt Claude, and we've delivered a lot of new features and capabilities over the last six months. So we'd really encourage you to look at some of these remote options that we're now, you know, delivering and and really start to see, like, does that actually fit your enterprise better than perhaps if you'd actually rolled out some of these capabilities six months ago? So we are listening. We are looking to ship new features to ensure that we can make Claude continue, to to raise the bar of security and and listen to your feedback about what you need to do this securely within your own enterprise. So so thank you for the feedback, and and hopefully these new updates will really be great music to your ears as you start to think about scaling your own deployments. For sure. And I think one one last item I want to emphasize is as we're thinking about cloud then on the endpoint cloud desktop, which is now going to evolve, there again, this few layers of defense, some of them map back to what we already do, like compliance API. It's the same one. The others are much more product specific in a good way. Like the VM network egress is a configuration that that you can set. So really taking the time, we have in our trust center architecture diagrams and best practices that we publish, and we really think that we're seeing the massive gains of hub security teams who went through our guide in in in the took the time to get themselves familiar with it, said it well, really just felt better on on their adoption and slept better at night and really were able to accelerate responsibly their their business. With that in mind, very insightful. We've gotten a few questions. Feel free to to get them going. I don't think we'll have time for everything, but but definitely have time time for a few. We'll take a few questions and then, summarize. So I think, Belinda, maybe I'll, I'll start, with the question we've gotten about data controls. And specifically, the question there is about training on the user data. So I can tell on my end that this is one of the questions that potentially is similar to prompt injections. It's one of those questions that come up a lot and have a very positive answer actually that customers are not always used to. But in general, we guarantee that we don't train on on your data. You can have it in our, terms of service, and you can see it. It's even in the pricing page. It's listed in every one of the of the, pricing packages, especially for for cloud enterprise. We even sign say it again. So the training on the data, I think there was a time where this was perceived as something that is currently done. It it is not done, and, and, there is no risk for training on your data. The entire training, chains are going through very different pipelines than that. Anything to add, Belinda? No. I think you covered it quite well. I'd say I would encourage you to go visit the trust center and also look at the enterprise license for Claude for your enterprise. I think that provides the best compliance and guarantees around rollout of Claude for an enterprise. So would encourage you not to be rolling out personal plans and would be encouraging you to be looking at the enterprise offering for, for your appointments. Yep. I'll also say that those things are really, like, vendor specific as you as you can expect. So, apply your judgment for every vendor as a as a general tip. Great. The next question that that we've gotten was about, our corporate security. So I'll say that, we have a lot of people in our security team from various different different places. I've worked with some in the past. We've had the pleasure of working them with them in the past. I'll say that, when you're looking for assurance about our corporate security, I'll say two main things. First of all, as part of our responsive AI responsible AI commitment, we truly believe that we should be very secure and one of the most secure organizations in the world, and a lot of internal resources are being, used for that. Like, I can tell you from just a pure product management perspective, a lot of the things that, the teams are working around and the constraints we operate in come from a very high security bar that we hold for our customers. And we believe that we don't only need to do it for our customers, we actually need to do it for the future of AI safety, as as we see it. We see ourselves as leading the troops and and leading the, the environment for what we believe AI security should look like. So, for example, when I'm pulled to those conversations about, sandboxes and virtual machines, internally, we have all of those things and even more. And we we invest in those things very heavily because we think that as AI gets more capable and one day they'll be like Opus seven and even even more in Fable 10, we need to really send send today and set the the guardrails around it in a very secure way, and we take it really to heart. The second thing I'll say is that we're leveraging AI in a way that helps us accelerate our own security in a very material way, from what I've seen. And you can talk about the ASOC. You can talk about, TPRM processes that are, in my opinion, are being, done to a very good quality. And you can even talk about the, the supply chain risks that we're seeing and a lot of also validations that our products are are doing. So between, one line of code being written, the the SDLC around it is very, very strong. And the and I'm I'm excited about the things we're doing there, and I think it wasn't possible to be done to the same quality if we weren't a Frontier AI map, because we we leverage our own, things and on on models well in advance in into our own capabilities. So that's really exciting, and I don't think our team could have done what they've done in so little time, unless we had this, head start. Benind, anything to add to that? No. I think that was great. Yeah. Great. And, potentially one last question, and then we'll go to the summary. We we're asked about the the hooks solution. So in general, hooks are a global. We've taken a good balance on where can you deploy your hooks, And we've taken one approach which is very wide, and you can deal with it in your AI security server and fit there whatever you want, and we give you the full authority on doing doing that. Like, you it's your server. You can do whatever you want, while also balancing on helping you to have the least friction of a of their deployment. I'll give a few examples. We have what we call a shadow mode. So that's a mode where we send the data to the AI security server where you can fine tune it, but we ignore the responses. We always pass them. So you can really test those before you, roll out. Another one was gradual deployments. Those here who were, doing some some, very complicated rollouts. You can do, like, gradual deployment and only cover some of the messages. And the last is is, some customers asked us for exclusion groups. So making sure that a very sensitive group is not part of the hooks until they get full confidence is is another thing. So think about every both breadth and filtering thing which you you thought about, which we can set. We're really, like, up to it and think that that's part of it and it's documented in in our docs. And if there's anything missing, just just let us know. But, definitely, we're getting very, very strong feedback. I was last Friday with a pharmaceutical company that, many of you, I think, are using their products. And, and, they said that's their way to really protect their IP and what can, someone send, externally. AI just being one of those things that they protect. Incredible. Yeah. So just in general, maybe last question we had there was about core. It does fit to compliance API. It does fit to our role may based access control and admin control. So you can really check that all up in in our trust. So, Benita, I think with with that in mind, as we as we wrap it up with the questions and things we discussed, any last thing you want us to you want to leave the audience with? Yeah. Look, it's been a lot of great questions here, and we really do appreciate the engagement and and questions. And we really wanna help support you in your journeys to adopt AI. So please, be back to us on the back of this of on the back of this webinar with any questions or thoughts in the survey. Hopefully, we can inspire you to kind of progress your AI strategy and roadmap together and help show you the new features that we have available that will help you do that safely. So we're really excited about what you're gonna do with Claude, and we look forward to hearing your feedback. Incredible. And I think for me, the main thing is, like, pick the highest leverage. I think our security teams definitely now in AI, you're at the front door of a lot of it and pick the highest leverage item you can take. In every company, it looks different. Choose the trust boundary even more so just for that specific use case. Let's not boil the ocean and, use, the control families that we provided maybe with the trusted vendors you already have that that you already know where the relationships are strong and data is already streamed to work. You can realize the value very fast. And those are the success patterns that we've seen. So I think with that in mind, I truly believe in why I wake up in the morning is that we are now in this few years of what some people, internally in our research call, like, trouble and time in cybersecurity in AI adoption. And in this time, there would be organizations and people and leaders would know how to accept the risk. And in cloud, as Belinda showed, it took twenty years or fifteen years. Now we're doing that in two years. It's not gonna be perfect, and we're with you in the journey, and we believe that the organizations will know to how to adapt are gonna do it, and outlast, especially as AI is getting com compounded in its results. So with that in mind and to keep a high note, I really wanted to thank, the great audience. I see that, in some, part of after I said the the names of the countries, a lot of people from Spain popped up. So really thank you for for, staying with us. Also, the folks from Thailand and, and Romania. So really, really excited about what we're doing here. Belinda, thank you for, all the great work you're doing with our customers, and, and, really appreciate, you, spending this morning with me. Excellent. Thank you, Dore, and hope everyone found this helpful. Hope you have a great rest of your day. Bye. Thanks. Bye.