453- Make Approved AI Easier to Use w/Mason Herbel

Mike Kelley & Mason Herbel

453- Make Approved AI Easier to Use w/Mason Herbel

THE IT LEADERSHIP PODCAST
EPISODE 453

453- Make Approved AI Easier to Use w/Mason Herbel

20
1 X
20
00:00 | 00:00

Short Clips

Episode Highlights

Mason Herbel

GUEST BIO

Mason Herbel describes the shift from an AI startup to Parallel Systems, where the first questions were about governance and company data. Some employees already used AI. Others had barely started. His advice for IT leaders: give people a clear route to approved tools, then make that route easy enough to use at work.

He suggests company enterprise plans, agreements about data handling, and a trial period for tools employees request. After the trial, check actual usage and whether another paid app already does the job. Blocking a website has limits when someone can reach for a personal phone. Mason puts it plainly: “So you may as well make it easy for people to use in a secured manner.” This is his proposed approach, rather than a report of a completed company-wide AI rollout.

We also get into choosing infrastructure one workload at a time. Mason recounts moving an engineering firm away from aging local servers after checking its remaining applications and Microsoft licenses. At an AI company, he argued for examining owned GPUs as API bills grew. He describes that proposal and the conversations around it; he does not claim verified savings from a completed GPU deployment.

For IT leaders trying to get a useful idea heard, Mason explains how he kept discussing the GPU proposal with a principal engineer. He also recalls asking to join a server installation early in his first job and learning by doing when the lead technician had to leave. The practical thread: ask how the work gets done, bring colleagues into the decision, and keep everyday IT needs covered while taking on new projects.

Network Assessment

Your monthly IT spend should be boring.If it's not, something is wrong.

Network Friction Score
BoringChaotic
Do you have provider/support numbers handy, or is it 1-800-GO-POUND-SAND?

We review circuit consolidation, contracts, security, outage visibility, billing, and future flexibility to reduce chaos without forcing change.

Circuit consolidation
Contracts & pricing
Firewall management
Outage alerts
Edge security
Billing & licensing
Boring results. Reputable savings.
Consolidation that makes sense.
Show Notes

Episode Show Notes

Navigate through key moments in this episode with timestamped highlights, from initial introductions to deep dives into real-world use cases and implementation strategies.

[00:02:04] Introducing Mason Herbel

[00:07:30] How curiosity earns early responsibility

[00:11:10] Checking workloads before replacing old servers

[00:17:29] Why Mason proposed owned GPUs

[00:21:37] Getting a colleague behind the proposal

[00:24:21] Watch the business workflow first

[00:25:59] Staffing IT without neglecting the basics

[00:27:56] Parallel’s autonomous rail-car plans

[00:40:12] Make approved AI easy to access

[00:42:42] Mason’s prediction for open-weight models

KEY TAKEAWAYS

Give employees an easy route to company-approved AI tools.
Compare infrastructure options against workloads and licenses already paid for.
Bring trusted colleagues into proposals that need leadership attention.
453- Make Approved AI Easier to Use w/Mason Herbel
Community Invite

Private roundtable discussion. IT leaders only. No vendors. No salespeople.

🛡️ 🤖
Upcoming Topic: Cybersecurity Ops + AI
What's working, what's noise, and what to prioritize now.
Who's in
✓ CIOs, CTOs, VPs of IT
✓ IT Directors
✓ Security leaders
Who's not
✗ Vendors
✗ Salespeople
✗ Pitch decks
Takeaways get published as a co-authored piece: real insights from real leaders, with attribution.
Limited seats. Peer discussion.
No pitch.

TRANSCRIPT

453-Mason Herbel

Host: Mike Kelley

Guest: Mason Herbel

Mason Herbel: I have had an interesting entry into the IT world. I would say, I

built my first computer around, I think I was ten. My mom will say I was eight

years old though. She likes to give me more credit than I deserve. But, I

forwent a birthday party at a young age to buy computer parts off of Newegg

instead; a little bare bones kit and watch. And, I was just obsessed with tech

from a young age. So I built my first computer, started making websites around

age twelve. I would like mirror, templates off of these template websites that

you can use and probably not, super ethical nowadays to like download somebody's

template and then modify it and then sell it to somebody as a website. But when

you're twelve and you're making a website for your friends esports team. It is

what it is. And I really learned at an early age, I don't like programming. I

like putting the stuff together, making it happen, configuring systems. But the

building software is very tedious, right? It's one thing to write a script over

the course of three days. It's another thing to build an entire desktop

application that takes three years to come to fruition. Right? So, when I was

eighteen, I got my first IT help desk job at a small dental IT provider in

Houston. We had about two hundred and fifty clients all over, the greater

Houston area grew quickly there, became the help desk manager after about two

years, was able to get my hands into everything from solving weird Active

Directory replication issues between some of our bigger clients. Or one time we

had a doctor take his server like on a field trip. He took it home. He was

moving to a new office. He took it home for the weekend, brought it back to his

new office, and it wouldn't boot. It would just blue screen Windows Server. So I

had to run some things on his hard drive to like, fix it up. spent all day just

getting the windows boot loader to work again. I don't know why, but it wouldn't

boot. And from there, I know this is a very long winded answer, but at an early

age I always loved computers and was able to just level that up into other

positions. I did sales for a little while. I did the whole IT contractor thing

for a little while. And then one of my family friends, it's not who you know,

but it's who you know, that knows what you know. was head of HR at an

engineering company that was very upset with their MSP. they've been using it

provider managed service provider for a couple years. And they were at that

point where they could justify bringing it in-house. And so they took a chance

on me as their head of IT specialist at first, and I was able to just take the

reins there. And they had five on site Active Directory servers. We moved all

that up to Azure AD, did an entire entree migration, just completely got rid of

on site AD because they had a very distributed workforce to begin with. five

offices, forty employees across those, and then another fifteen just dotted

around the US. Nobody wanted to have to turn their VPN on to like receive the

newest updates from the group policy. So it just made sense to do a cloud

migration there. Learned a lot along the way and then moved on to another

position out here in California. And now I would say I'm on my third head of IT

position. So that's what led you guys to find me on LinkedIn, I guess.

Mason Herbel: There's a couple things that go into that. I think the first one

is always being curious. Even if it's not something that you could even wave a

finger at, you may as well ask and say, how does that work? Right. When it was

my third week at my first at Bat Dental, IT job and I was still eighteen and I'm

twenty. Four. Yes, I'm twenty four now. I had to do the math real quick. And

third week there they were installing a new server at a client. And I just said,

what's the process for plugging that in? I've assumed you guys are already

setting up all the gpos and everything, and I just have to go plug it in,

transfer the software. And because I asked those questions, they were like, tag

along, come see. And then it ended up being that I was thrown into the deep end

on that one. And the lead tech that was going to go with me had to go to a

different job. And I was there by myself calling the software provider, and

saying like, hey, I have this old server, I have this new server, help me move

the database and just got it done. So I think the willingness to ask and look

stupid gets you front of mind with your superiors so that they think of you when

they're like, hey, who could go fill in this gap? What about the super curious

guy that always wants to learn? And then the second one is, sometimes you have

bad bosses that really don't see what they have in you. They like to silo you.

You're getting done what they asked you to get done. And when you try to be

proactive, they'll be like, hey, wait, what business initiative was that work

for? Right. There's nothing that we thought needed you to go look up the best

antivirus provider this month. And it's like, guys, we don't even have antivirus

yet. Like, maybe we should get an EDR. So asking, but also having the right

people is a big thing for sure. as superiors.

Mike Kelley: Okay. You mentioned and or talked about that change from the five

on prem. Well, actually you said it was five locations, five on prem ad servers

and then migrated into Azure Active Directory. And then, leaned into it as it

went from Azure Active Directory into entra, talk about some of the experiences

and the challenges of, doing that. And are you finding yourself building more

cloud centric stuff or have you run into an organization yet? That's like, no,

we want everything on prem.

Mason Herbel: So I like that question because every ten years, it's like

cyclical that people are like all cloud and then they go back to on prem and

then they go back to cloud. And what really works is hybrid. You need to buy

things and host them locally, either in a co-location or get a good tier one

circuit piped into your building, and build a room with an extra split unit in

there for air conditioning when something is going to cost, I don't know. My

threshold is like ten thousand a month. If you're already spending ten thousand

a month on cloud services, you could probably buy a two or three hundred

thousand dollars HPC high performance computer system from Dell, Lenovo or Cisco

and amortize that over three years, lease it, whatever, and be in the black

making, a return on that investment. But when it comes to the Azure AD Astra

project, specifically, they had a bunch of old Dell T three twenty S or

whatever. They were all running Windows Server twenty twelve. And the options

were, do we do that CapEx of thirty or forty thousand dollars, get a bunch of

servers, buy all the device cows, user cows, whatever. Or do we take the three

softwares that run, which was like a licensing server for their GIS program, a

backup script for their cloud storage, because they had already migrated

everything from SMB to something called Lucid Link, which is mainly for

creatives like they have a Premiere Pro plugin. They have an After Effects

plugin. It's mainly for video workflows and creative workflows, but it's a bit

by bit storage system. So it will download the whole project file to your

computer, but then it will only transfer and upload the portions that you change

or download the new portions of the file. When somebody else made a change to

that file. And this was an engineering firm, so all of their CAD files and

everything were in Lucid Link. They have this fancy lib fuse magic that Lucid

Link had done with the software that goes on the computer to make it seem like

it's a local drive, even though it's a cloud drive. It would take, one hundred

gigs of of local cache to download all the recently opened files. But before I

came on, they had already did the file storage part. So now all that lives on

these servers is some very basic programs for their licensing. And then the

group policies and the Active Directory. So I said let's rip it out. This is

only going to be one hundred dollars a month virtual machine with all the bells

and whistles backups enabled on Azure. And you're already paying for Azure AD

because they had, Microsoft three hundred sixty five Business Premium, which

comes with all of these features already. So they're paying for it anyway. And

it was a month or two project to schedule with everybody, but I went on to each

person's computer and backed up their user profile to OneDrive, enabled that

sync, made sure that their Chrome or Edge profile was synced, removed them from

the ad, rebooted their computer, had them log in with their Antra instead joined

it and some of them took an hour. Some of them took four hours. I just did that

with every single employee, which you can't always do. But at that organization

of fifty sixty employees, it was, the best option, honestly. And now I've been

able to move on from them. They call me like once a month with an issue. The CEO

has kind of taken back the IT stuff and they have one, on site part time tech

that's like an intern. And I know I've gone on a few different tangents on this

answer, but it really is that per case, analysis that you have to do to decide

whether it's cloud or on prem. And I have another example with an AI workload

with much bigger numbers too.

Mike Kelley: Yeah, in all honesty, let me just throw this out there a little

bit. most of the people that I talk to are a little closer to my age and have

like twenty plus years of experience. So it's fresh to hear from you having that

six years of this working experience and being, having raised yourself into the

leadership. So I'm interested in your perspective and how it differs from what

I've had to go through because, the technology changes and what I've seen over

the last twenty four years, twenty five years, and compared to what you've seen

over the last six years. But so tell me about the AI stuff. Tell me about what

you did with AI workload.

Mason Herbel: I do want to touch on that though. It is interesting and I kind of

envy the people that started twenty, forty years before me because like you guys

got to really tinker with computers. My first computer was already like an I

five thirty five seventy K. We were already in the Intel I series, right? So I

never got to.

Mike Kelley: You never got.

Mason Herbel: I don't know.

Mike Kelley: Fifty six megs of RAM and that being the high end computer.

Mason Herbel: Exactly. So there's two sides of the coin there for sure. But at

one of my jobs, it was an AI based ad tech company. We had this awesome product

that gives students a place to learn more quickly. Their first product was

actually like an essay writing app, the co-founders, and it went viral on the

internet, four or five years ago. And they were getting payments, people were

using the product, but they didn't really feel good about what they were doing.

So they scrapped that and they replaced it with something that you would upload

your notes to. You take pictures of your textbook, you let it record your

lecture in the lecture hall or what have you. Maybe you're watching a video, you

let it record off to the side, just like meeting notes apps do, and it will

synthesize all that into flash cards, practice quizzes. It'll even make a

PowerPoint and you'll have a virtual tutor that you talk back and forth with to

help you learn your class content more quickly. You're not spending three hours

writing out index cards for your four hundred vocab word like nursing exam,

right? You would just put the textbook pages into study fetch, and it'll fetch

all that and turn it into all of these different learning modalities, and you

would pay us the same amount as ChatGPT or Claude. Twenty bucks a month. We have

a chat feature as well, so you could ask it other things, but it would always

steer back to like, hey, actually you left off on this flashcard set. Let's

continue. At one point, during a final season, we were spending hundreds of

thousands of dollars on API billing. Because when you build an AI app, they

charge you per token. A token is three to five characters, and people would

upload three hundred page PDFs and we would scan all that in. That's millions of

tokens that were synthesizing, and they call it embedding into the vector

databases for the LLMs to search in that infinite dimensional array. And like

six months before they made the decision to do it. I said, hey, like we spend

all this money, we should probably look into buying a couple million dollars

worth of GPUs, putting it in a data center, and then we own our platform and

we're able to do extra model training. And that's when you turn from a ChatGPT

wrapper, as they call it, into a company, making your own AI, because you can

retrain these public open weight models, with your data. So we had all these

learning outcomes because we would ask people what they made on their test after

using study fetch. And then we can use those inputs and outputs to make a

typically worse AI better for our use case. And then there's just all these

benefits that you can get from Self-hosting GPUs, even at, a couple million

dollars scale versus a billion dollar scale like space X or, Facebook is doing.

Right. Essentially, we spent millions of dollars on API costs making Google

rich, paying Google Cloud when we should have been investing sooner in the

infrastructure planning and getting quotes and laying out our roadmap for how we

can consolidate these AI costs into a capital expenditure that can be written

off. And all of these things around the time that I left them and came over to

my current job. one of their principal engineers had the same epiphany six

months after I did. I was new at the time when I suggested it. So they were kind

of like, we're moving too fast. We don't have time for that. Right, even though

the co-founders are younger than me, which is part of the problem, I guess it's

another double edged sword of having great ideas, moving super fast, but not

having worked at a large enterprise before, seeing how things are done

typically. Which is good because you have new ideas on how to do things. You're

not trying to break old habits. But sometimes it gets in the way of things. And

that's what I alluded to earlier, is when you don't have good bosses that they

hire you, they give you the title, they give you the paycheck, but they don't

want to let you run with it because they don't have enough experience delegating

and seeing the fruits of that delegation. So they kind of pigeonhole.

Mike Kelley: So how do you or what would you recommend to those that are

listening? How do they deal with that? Is it just, you know what, you're better

off just scrapping it and go and finding a new place or a better boss or are

there things that you've learned and experienced in ways to deal with that and

to try to help shift that old guy like me shift my perspective to see and

empower you to let you go and do.

Mason Herbel: Sure. I think there are a few things, but the main one is this

quote from, President Reagan. he essentially says a man has no limits when he

does not care who gets the credit. So that same principle engineer that had the

same epiphany, I was in his ear the whole time. I was like, hey, look at this AI

model on Hugging Face. Hey, look at how much an eight GPU cluster cost. Maybe we

do spend enough to go buy one. And you know, it's a good idea and you know it's

going to benefit the business. I've always been a company man, even when I do

get frustrated and I might go on LinkedIn and rage, apply to five jobs or

something and say, get me out of here. It's against my nature to actually silent

quit or anything like that because I want to see the people around me succeed

and do well, and for everybody to have a great time. And the just numbers keep

going up, right? So yeah, the other folks around you that might have a little

more pull and. Showing leadership that it's not just your idea.

Mike Kelley: It's interesting you stated that way. And I think back to part of

where we started the conversation of, what are the things that helped you learn

or helped you succeed and find your way to a leadership chair? I think that

right there is one of the key things that helps us is when people see that we're

there to help them, I'm not looking to win for me. I'm looking to win for us.

I'm looking for how do I help the organization? How do what we do or how does

that enhance or add to? I think that's a critical piece. and, so often, with

these conversations, when I'm talking to people, it's, well, you got to listen

to the business, you got to understand the business. I'm not hearing you say

that, but you're showing that you need to, but you're hitting on some of the

other key pieces that help you grow and bring value.

Mason Herbel: Yeah. I think when you work at places that have a large or all of

the employees as high performers, very flat organizations like the one I work at

now, where our head of engineering has twenty direct reports, and those people

might have zero or three people under them. There's not these massive, tree

branches with all these limbs in our org chart. I think that lends itself to

like, everybody understands the business. It's kind of a prerequisite to work

there that you need to understand how do we make money? How does the business

operate? And especially it being a cost center almost all the time, we need to

increase productivity across the rest of the business. And there's no way you're

going to increase productivity of a CAD workflow if you've never looked over the

shoulder of one of the engineers that uses CAD and been like, what did you just

do? You joined those two pieces of the assembly. What does that even mean?

Right? You need to understand those business processes for sure. And all of the

habits I've formed are definitely based around that. Even if I didn't say it up

front, it's a very important to be the I think I heard this on one of the other

You've Been Heard podcasts. It's important to be the IT department that people

want to come to and share what they're working with on, instead of be the one

that they dread calling because they know they're going to take their computer

for an hour and a half.

Mike Kelley: And it definitely is, I've worked at both of those types of

organizations. And it's definitely, it's a gift. And, sometimes it's a dual

sided gift. But when the organization looks to you or looks to it for the

solutions that everybody comes to you looking for help and they're expecting

that level of help, that's a gift. But it's also, a huge strain too, because now

everybody's looking to you and you're getting taffy pulled in so many different

directions. so it can be both, but recognize it for the true gift of they trust

you and they want to, they're looking for your advice. You've Been Heard, right?

Mason Herbel: You can definitely spoil people by being too good of a it,

personnel. It's true. And then you just have to hope that the leadership above

all those people that are coming to you and putting all these things on your

plate, recognize the impact, and then they'll let you hire other people to help

because I've seen where, yeah, sure, you're great. And people are coming to you

and bringing all these problems to you and you're helping them solve it, but

then something else falls to the wayside, like the conference rooms, speakers

not working when that should be one of the basic things you're doing, or making

sure that a new onboarding laptop is ready Monday morning instead of working on

all the cool shit. You also have to make sure that you get all the basics out of

the way, and that if you are working on all the cool shit, leadership will hire

other people to help you with that stuff.

Mike Kelley: So, if you don't mind, what exactly is the goal of the organization

that you're at now? And what are your plans when it comes to the thoughts of,

okay, you talked about AI at a level that I haven't had a chance to talk to too

many people about. What are you thinking on when it comes to AI and the new

organization and trying to help them there, or is there already a defined path?

Mason Herbel: No, there's not a defined path currently. It's definitely felt

like I was hit with a bucket of cold water when I went from the AI native

startup to this other startup. Granted, also a startup, but a few years older.

and a little further along and a little more mature in their business processes.

So Parallel systems is a train manufacturer, but it's not a normal train. It's

not one of these diesel engines where they'll have two or three on the front

pulling eight hundred cars. And it takes a mile to stop. Ours is a

self-contained rail car with batteries. Motors leader if you've ever seen a

Waymo on the street. I don't know if they have those everywhere now. Yeah. Or

Zoox. Exactly. It's an autonomous rail car. You put one container on it. you can

have a bunch of them in a platoon moving along together. You can see on our

LinkedIn, and they'll go up to five hundred miles, and then you'll still have an

eighteen Wheeler take it for the last mile, but it is cheaper than an eighteen

Wheeler by a mile. It is getting a lot of trucks off of the interstates. If this

all continues to go well and our business continues to thrive, we'll. We'll have

these out there in the wild and. A prime example of where this will help will be

the shipyards. They. Sometimes they have the railroad tracks right next to the

shipyard, but it can take up to three days to build a train to maneuver all the

rail cars and put them in the right order and then hook them up. And it requires

dozens of acres of rail yard to maneuver all of this stuff. So at a shipping

yard, draining. So they take the containers off of the ship, and they put them

on an eighteen Wheeler. And then that eighteen Wheeler could be sitting there

for, like, an hour waiting on his container to come off the ship. So he had to

drive however far to get there. He has to wait there, probably running his

engine for AC depending on where he's at and what time of the year it is. So

burning gas costing money, and then he has to take it to where it's going, which

is probably onto a train and then going somewhere else. And there's thousands,

tens of thousands of these containers on these ships. Parallel will have this

self-contained car, the shipping management system that they already have,

telling them this container contains this and is coming off this ship this day

will ping the parallel brain, and that rail car will be there at the time that

it needs to be. Automatically. And then somebody with the crane. The cranes

aren't automated yet. That's not our business yet. So somebody puts it on there

and then that takes it five hundred miles, possibly further, because we can fast

charge overnight and then take it another five hundred miles on existing

railroads. It all runs on existing railroads. We don't need any third rail or

anything fancy. And then wherever it needs to go, the Walmart eighteen Wheeler

comes and picks it up. He can go home to his kids the same night because he's

only taking it ten or fifty miles. He's not taking it seven hundred miles

anymore. So again, it's just cheaper, it's faster, it's more economical. It gets

drivers home sooner. It's reducing traffic. It's reducing emissions. It's just a

win win win product.

Mike Kelley: Well what I'm thinking is, it sounds like it's almost an autonomous

chassis. So those containers come off of the ships and then they go onto a

chassis on that dredge, and then the train cars that they go on to are versions

of the chassis also where they can stack them on that and have multiples or two

of them on a, one rail car. And what I'm envisioning is that bottom part of it,

that's between the container and the wheels that are on the track is where all

of the battery and the brains and everything else. Exactly. Right there. And

then it's just moving that individual cargo container.

Mason Herbel: Exactly.

Mike Kelley: Yeah. That's cool. It's interesting because I've been in

transportation or the majority of my career. So I've been working with those

eighteen Wheeler trucks. And some of what we were doing was we were taking and,

doing innovative things of like bringing the the rail car and, and the one that

they set it on for the trucks that are moving it because the containers

themselves usually don't have wheels. But we were running the eighteen wheelers

that had the wheels, so they would pick that up with the crane, set it on the

flatbed rail car, and then move that and, intermodal and the ones that are

coming off the ships and then going on to rail and then going on to an eighteen

Wheeler, that's intermodal too, because it's multiple types of modal

transportation. except we thought we were innovative when we were working with

the rail yard to take our trailers with the, tires on them, set it on that

flatbed and then run it.

Mason Herbel: Yeah.

Mike Kelley: I wonder about the puzzle you've got. So you've got fifty of these

parallel cars at one of the shipyards and you start loading them up. But one

like the fifteenth in line has a priority, and he needs to get to the front of

the line and the inner shuffle of all of those interconnected cars. And they're

not platooning, but they're solving the problem themselves. I assume to help get

that one to the front of the line so that it can head down the track.

Mason Herbel: Yes. So there is a lot of work happening right now with the

dropping off of cars, just like you're saying in the rearranging. The beauty of

it as well is it's also safer for the existing railroad workers because it's not

a linkage in between the cars. There's this other mechanism. They've come up

with these two pressure plates that go together to tell the cars, like how close

they are to each other. They're never actually, interlocked together with the

really big clasps that they use. Apparently people lose fingers weekly and

people get hurt a lot in between those rail cars. And our system, like you said,

we have fifty number fifteen needs to get dropped off. The first fourteen are

going to speed up a little bit, give some room and they're going to know where

the switch is on the track, because we're using GPS with super like up to two

centimeter accuracy on our GPS. And then the sixteen onward will give it some

room as well. And then somehow, I guess a lot of the switches are manual. So I

guess the shipyard or whoever's receiving it would know that they're waiting on

that one. They would be there to switch it. The first fourteen would keep going

a little bit. Maybe they slow down to wait for their friends to catch up. Number

fifteen gets put onto the other rail section. Yeah. The diversion. Thank you.

And then the switch gets put back. So the plan is to sell the vehicle to the

rail, to the operators. We're not we don't want to take money for your

container. We want to sell the vehicle and then sell the software and then let

them operate it. So the person doing the switch would tell his comm center, hey,

I put the switch back, send them on their way. And then whoever hits the button,

it's the button. And then the next, cars keep going and then they catch up with

their friends. So there's so many different ways to skin the cat. That's how I

speculate that it will be done. But by not having those linkages in between the

cars, it enables us to do these drop offs and things like this.

Mike Kelley: Chassis is the word I couldn't remember. Because chassis is what

the container gets put on, whether it's for the train or whether the eighteen

Wheeler.

Mason Herbel: Right. That makes sense.

Mike Kelley: So we started off on this and, obviously you're going to be

leveraging AI for some of those decisions for the. Fourteen you know, we were

talking about car number fifteen, trying to get to the front and all of those

pieces and knowing where they are and what they need to do and, some of those

communications. But what are your plans for like the AI within the organization

or, how are you? Maybe the other question is, all right, so you've got the

engineer who doesn't have a Claud account, doesn't want a Claud account, and is

still bringing value to the organization. How are you working with those kinds

of individuals and, what are your thoughts around trying to work around that

and, all of the governance and the guardrails and, anti hallucinations. How are

you dealing with that kind of stuff.

Mason Herbel: Yeah it's very interesting. It's a little bit of an uphill battle.

It's not as bad as I thought it was. When I first got here, only HR and finance

are using AI powered, none of the programmers using it. And then I learned,

okay, a few of them are using it. They have the Claud code plugin on their

Visual Studio code, but they've never heard of cursor. And I think the reason

they have been hesitant is because our head of infrastructure and cybersecurity,

my boss and his first question was what you ended with there and how do we

govern this? How do we make sure it's not going crazy? The hallucinating is kind

of up to the user to trust but verify. But the data loss protection, the making

sure that users aren't using their own personal AI subscription and uploading a

confidential PDF into it, things like that. There are a lot of tools for that.

Cloudflare has a really cool one. If you've ever used Cisco Umbrella or Zscaler

or any sort of device level firewall, Cloudflare has their Cloudflare one

platform, which started as Cloudflare Access and Cloudflare Warp. But with

Covid, everybody started working from home and your normal network perimeter was

no longer easily trustable barrier. You can't just say like, hey, they're in the

office, they're allowed to go access this, that, and the other. We know we're

monitoring their traffic because now they're working from home three days a

week, and we have no control into their Comcast or Spectrum modem. So you need

to take the firewall and move it from the network to the endpoint. Cloudflare

was one of the first big ones to do this. And more than just DNS filtering like

umbrella would do. And they will monitor every packet. You can set all these

different rules. You can, figure things out. I start with minimum DNS level

filtering. So if we've disallowed ChatGPT and they try to go to ChatGPT on their

work device. It's going to be like, you're blocked. Go to Claude or vice versa.

But then even deeper than that, they've launched some features, by working with

the AI providers and also their own forensics and reverse engineering to inspect

even the MCP calls. So when you have their proxy enabled with their agent on end

points, it will see the HTTP request body that is calling to an MCP server.

right. So like when you link up gmail to your ChatGPT, it's using MCP server to

make those API requests, to gmail to read your email and everything. So they

figured out a way to filter those out. And then they can scan for PII or

sensitive information or things that you've set as, words to flag, things like

that. So the tech stack is catching up in terms of catching people. But I think

at a basic level, if you're allowing AI in your organization, your policy needs

to be you're only allowed to use these approved apps, which we purchase

enterprise plans for. And we have a data processing agreement. You can be a

little bit more lax about it and be like, hey, if you have one that you like to

use, we'll buy it for three months. We'll put the company card on it. We'll get

the enterprise one, and then we'll evaluate in a few months to say like, how

much were you actually using it? What were you doing in it? Could that have been

done in the other app? So we're not double paying. But having that low friction

to it is really what keeps people from trying to skirt the line, because if you

tell them not to use it, they're going to just use it on their cell phone and

turn the Wi-Fi off on their personal device and keep using it. The cat's out of

the bag. We can't undo it. We can't get rid of AI. So you may as well make it

easy for people to use in a secured manner.

Mike Kelley: It's interesting. I've run into a couple of the, AI security groups

in our companies and like, one of them was, oh, it's just we've got a plug in

for your browser. And right. We will stop them. By, you have to install this

plugin on each of the browsers. And I'm like, that's not going to work. I need

this at a deeper level than that because, somebody's going to go to their phone

and ask how to get around it and then just get around it.

Mason Herbel: Exactly. Tools like like Cloudflare one or, Zscaler, I'm sure

Cisco zero trust Network access has come up with a way to do this. They hijack

your DNS settings and your proxy settings, whether it's windows, Linux, Mac OS,

they do whatever they're doing in the background to hijack that, and they proxy

it through their servers. What I like about Cloudflare is they have like four

hundred points of presence all over the US. So there's typically a data center

that's doing packet inspection that's within one hundred milliseconds round trip

time. So it's really not impacting the users too much.

Mike Kelley: I have been enjoying this conversation. I hope it's been

entertaining for you. unfortunately, we're running tight on time. I did prep you

and warned you about a question that I was going to ask. So make that

prediction. What do you predict that we're going to be talking about in eighteen

months that we're not talking about today? What do you think's going to pop up?

Mason Herbel: I've been mulling on that throughout, and I think it's the same

answer that first popped up in my head, which is open weight models, which I

mentioned briefly earlier. But these models have all these different parameters

and categories of things that they know in their memory that they were trained

on. And the edge right now that the frontier models have is they have all this

brain power that they've hired for hundreds of millions of dollars and poached

from this, that and the other company to help them create those category

weights. So they're doing these trainings and they're putting these weights to

the parameters. I'm probably butchering that, but the open source models with

the open weights that you can see how they trained it. You can see if they gave

this type of behavior, more emphasis versus another one like ChatGPT being

overly nice, you would be able to see that in the weight data if it was open

source, but it's closed right now. So as the open source models get better, the

deep seeks the gemas, the llama models. Then it will become more accessible and

it will become more transparent. We might not even need as much regulation

around it if it's just open source and the graybeards that have been doing it

for a while that care about security on GitHub and everything, or making sure

that it's not going to go hack the world, that is the thing we're going to be

talking about in eighteen months. I think that anthropic and ChatGPT, and

they're trying to build all this hype and like all this FUD around their model

being the scariest and the most capable, but all of the publicly available ones

are catching up for sure.

Mike Kelley: Yeah. And actually, one of the things that I've been surprised

about is how many of these models people are being able to, or starting to be

able to install on personal machines and, have self-contained or, fairly

contained and be able to do other work with those things. I was talking to a

former colleague and they were, he was telling me about how they were doing

that, to comb through all of the different logs at an organization to find

different things. And they were finding indicators faster than the MSPs or MSSPs

and that are using some of these larger models, as part of their MSSP offering.

So it was kind of interesting. So, I like that. I think you're right. I think we

will be talking deeper and, for sure more than just tokens right now, there

seems to be a lot of discussion around tokens. And then of course, the

Graybeards like myself trying to figure out the governance models and how do we

put the guardrails in and, how do we teach people to use it responsibly and all

of those kinds of things. So I appreciate your time, Mason. I invite anybody

that has listened to this and is interested. Reach out to me through the

youvebeenheard.com community. and if you got questions about these kinds of

topics or want to learn more or, you got some ideas that you want to bounce off

of Mason or try to help him, help parallel get even better, hit him up in the

community, hit us all.

Mason Herbel: Up. Yeah. Of course, tag me in there. And I really enjoyed this

conversation. Mike, I appreciate it And I feel Heard.

Mike Kelley: Oh right on. Appreciate your time. Thank you for your expertise and

for sharing with us.


453-Mason Herbel

Host: Mike Kelley

Guest: Mason Herbel

logo

You’ve Been Heard

You’ve Been Heard is where IT leaders stop being sidelined and start being amplified. We’re the triple-threat platform: podcast, community and vendor-neutral advisory that elevates your voice, your value, and your influence because when IT leaders rise, so does everything else.

© 2026 You've Been Heard. All rights reserved.