Before The Commit cover art

Before The Commit

Before The Commit

By: Danny Gershman Dustin Hilgaertner
Listen for free

AI is writing your code. Who's watching the AI? Before The Commit explores AI coding security, emerging threats, and the trends reshaping software development. Hosts Danny Gershman and Dustin Hilgaertner break down threat models, prompt injection, shadow AI, and practical defenses — drawing from experience across defense, fintech, and enterprise environments. Companion to the book Before The Commit: Securing AI in the Age of Autonomous Code. No hype, just tactical insight for developers, security engineers, and leaders building in the AI era.

2026 Danny Gershman, Dustin Hilgaertner
Episodes
  • Episode 32: Cursor
    Jun 5 2026

    The conversation covers the introduction to Cursor, the transition to Riverside, experimenting with Cursor and Crow, SpaceX's acquisition of Cursor, Cursor's evolution and future predictions, features of Cursor and comparison with other tools, Nvidia's RTX Spark, and a discussion on AI usage and Apple's AI performance. The conversation covers a range of topics including Apple's AI competition, Siri 2 and Gemini integration, challenges with AI assistants, GitHub's Co-Pilot billing shift, the AI coding arms race, recent AI model releases, new AI tools and models, Grok subscription and plateauing, Claude Code's workflows feature, understanding workflows and goals, US government's stake in OpenAI, implications of government involvement, executive orders and AI regulation, and Anthropic's position and government relations.

    Takeaways

    • Cursor's evolution and future predictions
    • Nvidia's RTX Spark and its impact on AI usage Competition in the AI space is intensifying, with new releases and features from major players.
    • Government involvement in AI regulation and oversight is a growing concern.

    Chapters

    • 00:00 Introduction to Cursor and News
    • 08:20 Experimenting with Cursor and Crow
    • 16:27 Cursor's Evolution and Future Predictions
    • 26:18 Nvidia's RTX Spark and Apple's AI Platform
    • 37:14 Apple's AI Competition
    • 43:12 Grok Build and Composer Integration
    • 52:21 Implications of Government Involvement
    • 57:23 Executive Orders and AI Regulation
    • 01:05:04 Government's Oversight of AI Models
    Show More Show Less
    1 hr and 7 mins
  • Episode 31: Sam Kassoumeh, Co-Founder @ SecurityScorecard
    May 22 2026

    The conversation covers the topics of AI security gateways, SaaS-based companies, AI in coding, the evolution of Security Scorecard, and the impact of AI on threat intelligence data. The conversation delves into the transformative impact of AI and Threat Intel on data analysis, product development, and organizational workflows. It explores the exponential growth in interconnectivity and observation data, the value of net flow data when run through models, and the automation of manual tasks in identifying and cross-correlating data sets. The intersection of AI and Threat Intel is redefining the assessment process, transforming workflows, and changing the roles and responsibilities within organizations.

    Takeaways

    • AI security gateways are a hot commodity in the security space.
    • SaaS companies are doing more with less, leveraging AI and automation.
    • AI is changing the way coding is done, reducing the need for human intervention.
    • Security Scorecard was founded to address the growing dependency on supply chain partners and third parties.
    • AI has revolutionized threat intelligence data, uncovering deeper insights and network connections. Exponential growth in interconnectivity and observation data
    • Value of net flow data when run through models
    • Redefining the assessment process and transforming workflows

    Chapters

    • 00:00 AI Security Gateways in the Security Space
    • 07:35 AI's Impact on Coding and Automation
    • 28:44 AI's Impact on Threat Intelligence Data
    • 34:31 Value of Net Flow Data When Run Through Models
    Show More Show Less
    1 hr and 5 mins
  • Episode 28: Cloudflare AI Gateway
    Apr 15 2026

    The video discusses several key topics related to AI and its impact on the tech industry.Firstly, it delves into Anthropic's "Mythos" model and "Project Glasswing." The speaker expresses skepticism about the hyped claims surrounding Mythos, suggesting that the limited release might be due to resource constraints (GPU availability) rather than its groundbreaking capabilities. The speaker draws parallels to Anthropic's past PR strategies, citing the "blackmailed engineer" story as an example of manufactured hype.Secondly, the video addresses the perceived "nerfing" of Anthropic's Claude Code. The speaker details a series of changes, including the introduction of "adaptive thinking," a reduction in default "effort" settings from high to medium, and the removal of visible "thinking" logs from the UI. These changes, while potentially offering cost savings for Anthropic, have led to performance degradation for users, particularly those engaging in complex tasks. The speaker notes that while these changes can be reverted manually, the opt-out nature and the timing of these updates are concerning.Thirdly, the discussion shifts to Cloudflare's AI Gateway. The speaker highlights its features, including virtual gateways with unique hashes for custom rules, compatibility with various SDKs (OpenAI, Anthropic), and logging capabilities. A key aspect is Cloudflare's use of Llama for processing "guardrails," which are implemented for content moderation (e.g., blocking defamation or political content). The speaker also notes the limitations of these guardrails, such as the lack of regex support for sensitive data like API keys, suggesting the gateway is more suited for corporate chatbots than coding environments. The caching, rate limiting, and alias features for API keys are also discussed as beneficial for managing AI access.Finally, the video touches upon the impact of AI on junior engineers. Statistics are presented indicating a decline in "programmer" job postings, contrasting with a smaller drop in "software developer" roles. The speaker suggests a shift from task-based junior roles to more AI-centric orchestration of agents. The speaker predicts a future shortage of software engineers, with companies increasingly needing junior engineers to manage AI systems, thereby elevating the importance of mentorship in AI agent management. The video concludes with a broader discussion on how AI is transforming various careers and the need for educational institutions to adapt their curricula to include AI proficiency. The overall sentiment is that while AI adoption presents challenges, it also creates significant opportunities for those who embrace it.

    Show More Show Less
    1 hr and 4 mins
adbl_web_anon_alc_button_suppression_t1
No reviews yet