Mato just raised pre-seed Read more

AI Caregivers, Hungry Chips, and the Race to Build Self-Writing Software

  • Mar 25, 2026
  • 28 min

Show notes

What the episode covers

This episode of Tech Insider Weekly follows Lauren and Derek through the real-world pressures behind today’s AI hype cycle: from caregiving apps that quietly cross into regulated medical territory, to GPU economics and AI coding agents, to the Delve fake-compliance scandal and what it reveals about security and trust in AI startups.

Listeners will learn how AI tools in healthcare end up “meeting the FDA,” why inference costs and GPU access can make or break an AI business, what makes autonomous coding agents both powerful and risky, and how to evaluate vendor security and compliance without being a specialist.

  • AI in healthcare: How a caregiver assistant turns into a clinical product, what FDA oversight looks like in practice, and how small teams manage risk when software influences medical decisions.
  • GPU economics and infrastructure: Why inference costs spike after launch, how hardware access shapes AI startup margins, and why “GPU discounts” rarely make a lasting competitive moat.
  • AI coding agents: The difference between copilots and desktop-controlling agents like Cursor, Astral, and Claude, plus the security and reliability questions they raise for production systems.
  • Compliance and scandals: What SOC 2 and ISO certifications actually signal, why faking them is a fundamental trust failure, and how hype-driven buying can overlook basic due diligence.
  • Practical vendor checks: Simple, direct questions any buyer can use to spot weak or fake compliance before adopting an AI tool.

If you find this conversation useful, subscribe, leave a review, and share it with someone evaluating AI tools or building in healthtech, infrastructure, or security. New episodes drop every Wednesday.

Timeline

In this episode

6 moments worth skipping to. The timecodes match the player above.

  1. 0:22Introduction
  2. 3:09AI caregivers and clinical copilots: Where healthtech startups meet real patients
  3. 8:30Hungry models, bigger bills: Inside the scramble for AI chips and GPU clouds
  4. 14:34AI agents as software engineers: From Cursor to Claude taking over your desktop
  5. 20:49Fake compliance and sky‑high valuations: Can you trust your AI legal tools?
  6. 26:45Outro

Quick answers

Straight from the episode

The questions this one settles, without the listen.

How do AI healthcare startups know when they need FDA approval?
Lauren and Derek explain that once an AI caregiving tool moves from “helpful assistant” into making or driving clinical decisions—like triage, diagnosis suggestions, or treatment paths—it’s effectively practicing medicine. That’s when you’re “meeting the FDA” and have to treat it like a regulated medical device, not just a wellness app.
What does “meeting the FDA” look like for AI doctor tools in practice?
Derek describes it as shifting from scrappy iteration to evidence and process: documenting how the model works, validating performance on real clinical data, defining indications for use, and preparing for audits and post-market monitoring. It’s less about a single form and more about proving safety, limits, and workflow fit over time.
Why are inference costs such a big problem for AI startups?
Derek walks through how cheap experimentation hides the real bill: once you have thousands of users, every query hits GPUs, and latency plus reliability demands push you to premium hardware. Lauren notes this turns into a brutal margin squeeze and makes “we have a GPU deal” a fragile moat that others can quickly match.
Are AI startups built on special GPU access actually defensible?
Lauren is skeptical. She argues that discounted GPU contracts or early hardware access rarely create lasting advantage because big clouds can replicate them and new, cheaper inference options keep emerging. Durable moats are more likely to come from product, data, and workflow lock-in than from raw compute access.
How are AI coding agents different from code copilots like GitHub Copilot?
The episode contrasts passive copilots that suggest snippets with active agents—like Claude controlling your desktop or tools like Cursor and Astral—that can open files, refactor codebases, run tests, and make changes autonomously. That jump from suggestions to actions raises new stakes around security, compliance, and production access.
What did the Delve “fake compliance” scandal reveal about SOC 2 and ISO claims?
Lauren and Derek use Delve to show that SOC 2 and ISO aren’t just logos—they’re audits of how a company handles security, availability, and data. Faking or exaggerating them is a deep trust breach. They suggest buyers ask vendors two simple things: to see the actual report (not just a badge) and to have someone who can walk through scope and exceptions in plain language.

Transcript

The full conversation

Every word of the episode, 4,545 of them, in the order they were said.

Read the transcriptHide the transcript

LaurenOkay, okay, okay. Welcome back to Tech Insider Weekly.

DerekHey everyone, good to have you here. New week, new version of the same tech chaos. I've watched this cycle repeat enough times to know the pattern by heart.

LaurenOh man, today is stacked. We're starting with AI in healthcare, where a friendly caregiver app suddenly has to meet the FDA like it just got called to the principal's office. I've watched this collision happen. Founders build something clever, then realize regulatory Regulatory wasn't an option.

DerekRight, right, right. One minute it's checking symptoms, next minute it's writing treatment plans and the legal team is having a very bad day. FDA, liability, the whole gnarly mess.

LaurenExactly. And under that drama is the ops question. Tiny startup, high stakes medical calls, real liability. I've sat through enough board conversations about liability attribution to know this one keeps CFOs up at night. Night.

DerekThen we zoom out to the actual money pit behind the magic trick, the hardware, GPUs, inference bottlenecks, margins that evaporate the second your cloud bill arrives. I've seen this story before.

LaurenPlus the fragile moat thing, where your big secret edge is basically a short-term discount from Nvidia's favorite reseller. We'll come back to that GPU economics mess. I've pattern matched on how that story ends.

DerekAnd then... Even agents, desktop-driving AI coders, Cursor, Astral, Claude, all promising an AI software engineer on your laptop, or at least that's the dream they're selling.

LaurenBut how do you let that thing near prod when you're not sure the startup even did its security homework? I've been both the operator asking that question and the investor watching founders skip it.

DerekWhich tees up our finale, the Dell fake compliance scandal, SOC 2 cosplay, and how hype around tools like Like Harvey can make buyers forget to ask basic questions. I've watched this pattern collapse before when speed becomes an excuse.

LaurenYeah, and we'll give you super simple checks so you can spot flimsy AI vendors without becoming a full-time security analyst. Trust me, the honest teams will light up when you ask the right questions.

DerekAll right, enough foreplay.

LaurenLet's get into it. Segment one, AI and healthcare startups begins right now. Okay, so a founder hacks together an AI caregiving system for aging parents. Meds, early warning signs, weekend project becomes a funded startup overnight.

DerekClassic pattern. You solve a family problem, suddenly every caregiver wants access. I've seen this at startups a thousand times. What works in one kitchen doesn't scale to a thousand clinics without someone asking hard questions first.

LaurenRight. At first it's duct tape, off-the-shelf LLM, cheap tablet, prompts so it talks like Mom's friendly nurse. But then you hit the wall where this isn't just reminders, it's health advice. I've sat in enough boardrooms to know that's when the legal team starts. Team Stop Smiling.

DerekThe second it suggests don't go to the hospital, you've crossed into medical decisions, not a calendar app.

LaurenCaregivers say anything is better than my dad forgetting his meds. Investors ask, are you a cute app or a clinical device the FDA will care about? I've watched those conversations happen in the same room, and they are not talking about the same product.

DerekOne path is ship fast, fix live. The other is build like infrastructure. Where the boring stuff, the logging and guardrails, actually matters because failures don't just cascade, they compound with liability.

LaurenCaregivers are drowning now, but I've learned the more these tools slip from calendar plus chat to diagnosis plus dosing, the more they look like medical devices. I've pattern matched this escalation at portfolio companies. Everything changes once you cross that line.

DerekYeah, systems that start as note-taking buddies, then scope creep hits. We'll summarize, we'll do billing codes, suddenly we'll suggest diagnoses, prioritize which patient to see first. You're not an app anymore.

LaurenSo when people say we're meeting the FDA, what does that look like?

DerekEngineers have this realization: Oh, this isn't a Chrome extension. It becomes data collection, prospective studies, documenting every model change. Hospitals ask, show me your AI is at least as good as standard care. And that's the moment founders realize they're not shipping software anymore.

LaurenThat evidence is slow and expensive. Founders think it's a scaling problem. It's not. It's validation. I've seen teams burn runway thinking regulatory is just... It's just another operational challenge you hire for. Interesting.

Speaker 3I talked to an engineer whose team shipped an AI scribe into a clinic—just note taking. They still had to integrate with creaky EHRs, handle edge cases like "patient has three middle names," prove the system never mangles medication lists. That's non-negotiable. That's also the unsexy stuff that makes the difference between worked great in trials and worked great in prod.

LaurenWhich is the one thing you really don't want mangled. I've watched what happens when an AI quietly creates liability nobody saw coming. quietly creates liability nobody saw coming.

Speaker 3Exactly. Once they touch triage, this chest pain goes urgent, that waits, the bar doesn't just scale, it transforms. Now they're logging every suggestion, override, outcome. Helpful tool becomes you could quietly increase risk and nobody notices until it's too late.

LaurenThis is where Ops freaks me out. When an AI suggestion harms a patient, who's on the hook? The startup, hospital, the doctor who clicked approve because they're drowning? I've been in enough board conversations around attribution to know that ambiguity is existential.

DerekSlowly, everyone is a little on the hook and nobody feels safe.

LaurenSmall teams need clinical validation, red teaming, guardrails. But move at regulator speed, you die as a startup. Move at hacker speed, someone gets hurt. I've watched founders try to thread that needle, and it's brutal.

Speaker 3They try hybrid moves, shadow mode, where AI suggests things but humans ignore them, just gather data. Hard constraints, like we never change medication doses automatically. Those guardrails protect everyone. It's boring infrastructure work, but it's the work that actually matters.

Laurenand tons of logging, the unglamorous stuff that actually protects you when something goes wrong.

Speaker 3So much logging, plus permissioning, so AI can't see notes it shouldn't touch. Boring infrastructure, unsexy permissioning, but it protects everyone. Doctors assume it's safe, startup cuts corners on the boring stuff, the clinician faces the lawsuit.

LaurenMeanwhile the caregiver founder thinks, I wanted mom to take pills on time. How did I end up in regulatory hell? I feel for them. I've been. Then the operator brought in to clean up that exact mess.

DerekIntent is beautiful; reduce burnout, give families a break; but software that talks like a nurse gets treated exactly like a nurse, with all the liability and all the expectations that come with it.

LaurenSo you have caregiver strain, clinical risk, regulation, and a third piece founders don't see coming—operations, who literally pays for twenty four seven AI nurse? First computation in every living room and clinic. I watch this blind spot constantly.

DerekThat's the unit economics question nobody's asking yet. And I have a hunch the math breaks when you add up 24-7 inference cost, compliance overhead, and clinical validation. That's where startups hit the wall.

LaurenRight.

DerekExactly.

LaurenShifting gears for a second, that AI caregiver we just talked about? Under the hood, it's basically a walking cloud bill. I've watched founders' eyes glaze over when they realize the unit economics.

DerekOh man, yes. As an engineer, here's what actually terrifies me. It's not the training, it's shipping, users loving it, and then watching your infrastructure costs climb faster than you can raise pricing. I've seen this exact trap close on good teams.

LaurenRight. Training is that one big bonfire. Inference is like leaving the stove on in a thousand apartments all day, every day. And as an operator, that's where I watch the unit economics story collapse.

DerekExactly. Every user query is a forward pass through this enormous model – you stack token limits, context windows, maybe tools – and suddenly each call is shockingly expensive compared with old school SaaS.

LaurenAnd then founders realize, wait. My gross margins might never look like normal software. I've seen that moment in a boardroom. It's brutal.

DerekBecause behind that chat box is a rack of GPUs that want power, cooling, and premium cloud pricing. If your product is always-on assistant, you are basically renting a Ferrari to do food delivery.

LaurenPainfully accurate. So talk through the inference bottleneck as an engineer. What does it feel like week to week?

DerekIn code, it starts simple. You hit an API, add logging, then traffic doubles, latency spikes. You start batching requests, rewriting prompts, caching responses, but you keep hitting the ceiling. You are bound by how many GPUs you can get and how tightly you can pack work onto them. I've watched this progression a hundred times. It never gets easier. easier

LaurenSo instead of can we build it, the question becomes can we afford for people to use it. Builders hate it.

DerekExactly, which is where new players show up. Someone builds the infrastructure layer, abstracts away the pain, and suddenly everyone plugs in. Gimlet Labs, Andromeda, whoever. Their pitches will give you cheaper, more flexible access to GPUs.

LaurenYeah, they're saying you don't have to be OpenAI to get decent economics. Usage-based, multi-cloud. Out spot instances all the messy optimization abstracted away. What they're really selling is we'll handle the infrastructure pain, but the pain just moves. It doesn't vanish.

DerekUnder the hood, they're doing gnarly things, packing multiple small models on the same GPU, routing workloads between data centers, swapping in cheaper hardware with latency allows. As an engineer, that is catnip.

LaurenAs an operator, I hear cheaper inference and my brain goes straight to margins. Cool your COGS come down; but now your whole advantage might be, we have a sweet deal on GPUs through Startup X. That's fragile; I've watched that story end.

DerekYeah, once every one can rent from Gimlet or Andromeda, your special sauce cannot be 'we got there first.' It becomes middleware, another line item on your bill, negotiable by quarter. That's the moat evaporation story playing out in real time.

LaurenAnd that's my question, if your edge is just Just ask Seth, how long before your moat evaporates? You're not a product, you're a reseller with good marketing. I've watched this pattern play out enough times to know it compounds against you.

DerekI'm half with you. There is real infrastructure there, scheduling, autoscaling, fault tolerance. But I agree, over time it looks like cloud 2.0. Margins compress, customers negotiate, and you get compared line by line. I watched this cycle play out before. Competitive window collapses, everyone becomes a commodity.

LaurenAnd we're already seeing young companies think like infrastructure players, Upstage grabbing thousands of AMD chips-small teams saying, if we don't own part of the stack, we're at the mercy of whoever does. I used to think that was founder paranoia; now I know better.

DerekWhich is wild for a seed stage founder. Now you're basically doing supply chain strategy before you've proven product market fit.

LaurenAnd burning a ton of capital early-that's the other risk-these are insanely capital intensive bets for companies that have not proven product market fit. I've sat in boardrooms where that realization was the quiet kill shot.

DerekSo someone listening who wants to start an AI company, how should they think about this?

LaurenFirmly, I'd draw a bright line: if your value prop is basically "we're cheaper GPUs" Assume that advantage decays fast; you'd better layer in something sticky—workflow, data network effects, proprietary models tuned on real usage. I've seen what happens when founders skip this step.

DerekAnd if you're building an application, be deeply suspicious of locking your whole business to one vendor discount; the margin is great until that partner realizes they're also your competitor. I've seen founders learn that lesson the expensive way.

LaurenOr until your customers realize they can talk directly to the same GPU cloud and cut you out. That's the "thanks for the intro" problem. I've watched operators do it.

DerekThe "thanks for the intro, we'll take it from here" problem.

LaurenExactly. The founders I like in this space treat cheap inference as an ingredient, not the main dish. They use it as a lever to think bigger. I've pattern matched on the ones who get this distinction versus the ones who don't. Don't—very different outcomes.

DerekAnd that connects to where we're headed next. Once you lower the cost of each inference call, the economics change. You stop thinking chatbot and start thinking agent that can actually do real work. It's that unsexy infrastructure moment enabling the flashy possibilities.

LaurenRight. Give that same compute to something that can click buttons and write code and now you're flirting with this AI software engineer idea. Yeah, that's where things get interesting and messier.

DerekAnd I've seen what happens when you give a coding agent a big shiny GPU credit card and no guardrails: it is chaotic. Very fun. Also occasionally expensive, and sometimes both at the same time.

LaurenOkay, Let's jump into what an AI engineer really is, and why every dev tool startup is suddenly promising one. Okay, okay, okay. Picture this. You go to bed and an AI agent quietly fans out across your code base. It refactors. right to test, opens pull requests, even comments in your team's snarky style. even comments in your team's snarky style. It's the automation dream we've been selling for 15 years, just with a new paint job. Oh man, so you wake up and your app is faster, cleaner, and slightly more passive-aggressive. I watched enough Sprint retros to know teams are already treating that as a feature, not a bug.

DerekExactly. That fantasy is what every startup is selling right now. now and what Cursor or getting that valuation is hinting at but here's the thing I've watched over and over the real question is whether that valuation survives the moment everyone can do it these

LaurenRight. And this is a level up from today's Copilots. Copilot, Cursor, they sit in your editor and autocomplete. They help, but they wait for you. I've pattern matched enough on founders to know the difference between a tool and an agent, and most teams haven't.

Dereknew agents act not just suggest they plan they click Click, they run commands, you give a goal, like "Kill this flaky test", and it goes hunting.

LaurenSo how does that compare to what OpenAI and Anthropic are rolling out?

DerekOpenAI is snapping up Astral, which handles agents navigating dev tools. Anthropic just shipped Claude with computer control. And when both labs move it like that, it's a signal the capability is finally baked. The race is heating up.

LaurenLike actually move the mouth and type?

DerekYep, remote control with a brain. Amazing for speed, absolutely terrifying for everything else.

LaurenThat is both incredible and mildly terrifying. I've watched what happens when founders get powerful tools without guardrails. The confidence outpaces judgment.

DerekMm-hmm. On the plus side, you get a tireless junior dev who never sleeps. On the scary side, you just handed a stochastic parrot the keys to production, which I've watched make very confident... But in very wrong decisions at big tech.

LaurenOkay, so that's exactly where my operator brain kicks in. If the core trick is we drive the mouse and keyboard, how do you build a company when every big LLM can copy that in three months? I've watched this commoditization play out before. You're not building defensibility. You're building a feature that gets cloned.

DerekInstinctively, you don't sell clicks, you sell workflow. The dream is your agent learns your stack, your tickets, your staging. Teaching quirks, it becomes the glue only you understand. But here's the thing most founders miss.

LaurenI buy that story, but I'm not sure most tools get that far. A lot feel like fancy macros. I've sat through enough pitch meetings to know most founders don't realize they're selling the wrong thing until their Series A conversations start falling apart.

DerekExactly. It's fancy wrapping around UI automation. Most teams never get past scripts that happen to ship. Chip.

LaurenAnd then there's the buyer side. Say I'm VP Eng at a bank. Some startup pitches AI software engineer can ship code to prod. My risk alarms are screaming, and I've sat through enough security reviews to know those alarms are exactly right. I've been both sides of that table.

DerekAbsolutely not. Thanks for coming.

LaurenExactly. So you get this tension. Founders need to move fast. Security teams want the up. The opposite. I've watched both people in the room and they are not incentivized the same way. I've watched that misalignment wreck shipping timelines.

DerekI watched this pattern at big tech repeatedly. The competitive window collapsed. What took three years to copy five years ago now takes weeks. Any startup that said we own your workflow had to fight the platform team cloning it, making it free, and the startup's moat just evaporated.

LaurenSo if you're building an AI coding agent now, you know to... You know two things—your UX is copyable and the cloud provider can squash you if you get traction. I've watched that movie before. It does not end well for the startup.

DerekWhich means your real moat is unglamorous stuff: integration depth, reliability. Maybe you're the one vendor that doesn't nuke prod at three a.m. and ruins a customer's quarter. In this market, that's not a nice to have, that's the entire game.

Speaker 3Meaningful.

DerekAnd this is where Founder psychology gets gnarly. Early, the incentives scream, ship the flashy agent demo, go viral, raise Series A. The enterprise buyer quietly wants, prove you won't wreck my systems. I've watched good teams get crushed in that gap.

LaurenAnd if this works even halfway, I'm not replacing senior engineers, I'm changing their job. They become reviewers, system designers, babysitters of a very fast, very confident intern. That's not just a culture shift, it's a hiring and incentive restructuring most teams aren't ready for.

DerekBut only if the buyer actually trusts the agent and trust doesn't ship in beta.

LaurenWhich loops us right into the next problem. If I'm going to let an AI touch production, I need to trust the company behind it did the boring homework. I've seen enough shortcuts in my career and I've had bored conversations about the ones that went wrong. to know when a startup is cutting corners on compliance.

DerekYou mean the have you actually locked this thing down homework?

LaurenExactly. Security, audits, the unsexy stuff, because if startups are already faking that on plain SaaS, and I've watched board conversations where that came up as a will address it later problem, imagine the temptation when they're selling agents with root access.

DerekYeah, for founders willing to fib on a compliance cert to close a deal. Still, what are they cutting corners on when it comes to an agent that can SSH into your servers? That's the question that keeps operators up at night.

LaurenAfter the break, I want to zoom in on that, the Dell fake compliance mess, what SOC2 actually means, and how a buyer tells the difference between a safe agent and a very pretty landmine. This is where I see founders either build real moats or dig their own graves. I've watched both outcomes.

DerekGood, because the trust story, the boring reliability and security work might be the only defensible moat these AI agents actually have.

Speaker 4Right.

LaurenOr saves a few real engineers from cleaning up catastrophic messes. I've been the person who had to run that cleanup. Never again. With that in mind, OK, we have to talk about Delve.

DerekOh man, yes, the fake compliance bomb. And I've seen this pattern before, not with agents yet, but with every wave where speed becomes the excuse for cutting corners.

LaurenSo get this, for anyone who missed the headlines, they were accused of claiming security certifications they did not actually have. I've watched this playbook before. Founders convince themselves the logo matters more than the substance.

DerekThat is not a rounding error. That is the kind of lie that gets board seats emptied.

LaurenNo, in B2B, especially with AI agents near code or legal data, those badges are basically you may now trust us with your crown jewels. I've sat in enough board meetings where a buyer's entire risk calculus hinged on seeing that checkmark.

DerekRight. Break down the badges, though. SOC 2 sounds fancy. What is it in plain English?

LaurenSOC 2. Who is basically an outside auditor checked your security and process controls. Things like access control, logging, how you onboard and off-board employees, how you handle incidents.

DerekSo it is, do you lock the doors, notice break-ins, and kick people out when they leave the company?

LaurenExactly. And ISO 27001 is similar, more global, but same idea. You defined how you protect data and an auditor verified you were doing the thing you wrote down. I wrote down.

DerekSo if you lie about that you're not just sloppy, you're telling customers we invited adults in the room and actually check things when the room is empty.

LaurenOr worse, full of interns with root access. From an operator lens, Fake is a hard red line. Stuff breaks, models hallucinate, fine. But when you fake the guardrails themselves, that's a character problem. I've watched it destroy companies once the truth came out.

DerekAnd a compounding risk, because other people then use your SOC 2 as their excuse to skip questions. That's how the lie spreads.

LaurenExactly; that's what scares me. These stratifications become a substitute for thinking; so a lie at the vendor quietly infects an entire chain of buyers; I've pattern matched this scenario before; it cascades in ways you cannot predict or unwind.

DerekOkay, okay, okay. Contrast that with Harvey. The legal AI, giant law firm logos, sky-high valuation, and suddenly the compliance mode becomes a halo that nobody questions.

LaurenYeah! Harvey gets this huge price tag, every law firm logo on the slide, and suddenly every GC is like, if they are in, it must be safe. Logo-driven security is not due diligence.

DerekAnd the risk is buyers start treating valuations in investor pedigree as a substitute. Up to date for actually asking hard questions: I've watched this play out-logo goes in the deck, Rigor goes out the window.

LaurenTotally. I've been the investor in the room, and I can tell you, nobody checks.

DerekHave you ever seen an investor pass on a hot round because the log retention policy was mid?

LaurenNever. Not once.

DerekMm-hmm. Right. In dev tool land, I've watched this pattern a hundred times. Explosive growth, big users, you bolt on SOC 2 soon to the sales deck and everyone squints and ships anyway because the competitive window is... That was brutal!

LaurenAnd then a deal like OpenAI buying Astral lands and every founder hears speed is life. I get the pressure, I've been there. But you cannot outrun a compliance disaster. I've watched it happen.

DerekYep, you think if I just survive long enough to get acquired or close a Series A, the compliance stuff becomes someone else's problem. That's the trap: founders mistake speed for strategy.

LaurenBut the boring stuff is the blast radius limiter. If your aging can catch prod or client contracts, those missing controls decide whether a mistake is a support ticket or a front page story. I've watched that gap firsthand.

DerekSo let me ask, do you think this is mostly bad actors doing a conscious con or good teams crushed by the velocity of the market?

LaurenI think there are a few outright liars, and a lot of people quietly convincing themselves that 'in progress' is close enough. That is still on leadership. I've sat across the table from both types. The conscious choice is what haunts you.

DerekYou do not accidentally put a fake certificate on your home page. That's where it gets dark.

LaurenExactly. Someone uploads that image, someone writes that line in a deck. Those are conscious acts. Axe.

DerekOK, practical mode: if I'm a buyer and I don't have a CISO reading every line item, what's the real move here? What actually protects me?

LaurenTwo super simple checks: first, ask for the official SOC 2 or ISO report letter, not just the logo. It will have a firm name and a date. Any team worth your trust will hand it over without hesitation, and their willingness tells you something.

DerekAnd if they will not share it, you have your answer.

Speaker 3RADAR.

LaurenPretty much, if they won't show it, something is off.

DerekSecond check?

LaurenAsk, "Who's your security owner and when was your last third party pen test?" You're not grading technically, you're listening for whether they have a person, a cadence and a clear story. I've done this enough times to know when the answer is real.

DerekSo if the answer is, "Our engineer sort of handles that," you walk.

LaurenOr at least you pause. Ask, "How do you revoke access when someone leaves? What logs do you look at when something seems off? Real teams have muscle memory stories, shaky ones hedge, and I've learned to trust that instinct.

DerekYou're not trying to be an auditor, you're just poking the facade to see if there's a building behind it.

LaurenExactly; trust the humans more than the badges. The honest teams will light up when you ask; the shaky ones'll get weird.

DerekAnd in this AI agent moment the boring follow up question might be the thing that stops a disaster before it's a front page story.

LaurenOr Your Customers

DerekOr both.

LaurenSo the thing sticking with me is that caregiver-founder story. we can hack for their care and suddenly they're staring down FDA playbooks and liability committees. I've been in that inflection point when your side project becomes someone's actual health care.

Speaker 4Yeah, that this is not a Chrome extension moment. I've watched that transition happen over and over at big tech. You start as a weekend hack, then you're touching real patients, and suddenly you're not building a toy. You're building infrastructure with actual stakes.

LaurenExactly. One line takeaway for me, if AI is touching people's health, money, or jobs, you're not building a toy. You're building infrastructure with actual stakes. I've pattern matched this wrong too many times to ignore it now.

Speaker 4And infrastructure has receipts. SOC 2, real audits, someone who can actually answer who is on the hook when this breaks. That's the line between serious operators and everyone else squinting and hoping.

LaurenWarmly, if this gave you something to argue about with your team, hit follow, drop a quick review, and share it with that one reckless founder friend. Those arguments are where real companies get built.

Speaker 4And if you've got a wild AI story or a guest we should absolutely grill, send it our way. Tag us, drop it in. We're always hunting for the gnarly stuff.

LaurenThanks for hanging out with us.

Speaker 4New episodes every Wednesday.

LaurenBrightly see you next time on Tech Insider Weekly

More episodes

Keep listening

Other episodes of Tech Insider Weekly, newest first.

All episodes of Tech Insider Weekly

Sources

Where this came from

20 reports behind the episode. Every one of them opens where it was published.