"I believe that type of leap is possible for everybody, but it requires people to have access to the modern-day tools to allow for something like that."
âPukar Hamal

About Pukar Hamal
Pukar Hamal is Founder & CEO of cybersecurity assurance platform SecurityPal AI and Nepalese startup ecosystem Silicon Peaks. He is on the Forbes Technology Council and has appeared in media including NBC, Axios, Business Insider, Techcrunch, and VentureBeat.
What you will learn
- Why AI-generated writing hasn't yet matched the emotional impact of human authors
- How AI tools like ChatGPT and Claude reduce the barrier to launching new projects, but human focus and perseverance remain key
- The evolving partnership of AI and human judgment in cybersecurity, ensuring both automation and critical verification
- Ways that AI can be easily deceived by surface signals, and why layered human validation is essential for trust
- The shifting landscape of cybersecurity, including concepts like zero data retention and agentic security
- How to support and expand human agency in an era where AI is increasingly driving decisions and outcomes
- The importance of compute equality as foundational infrastructure to unlock human potential everywhere
- Why augmenting rather than replicating humansâfocusing on intelligence augmentation over AGIâshould shape our use of AI
Episode Resources
Transcript
Ross: Pukar, it is amazing to have you on the show.
Pukar Hamal: Thank you, Ross. Yeah, really excited to be here. Thank you so much for having me.
Ross: So we were just chatting a moment ago, and you were asking a very interesting question about AI's writing capabilities. What's your frame there?
Pukar: Well, my frame is really simple. If I were to ask any human to name their favorite piece of writing or author, I think you would have one at the tip of your tongue before I even finish the question. But if I were to pose that same question and say, is there a single piece of writing from AI that you can recall that's totally knocked you off your seat and just made you think, like a great book or an essay or anything like that for that matterâwhy is it that that's not the case?
AI has been here for three to four years. We've been told it's getting better and better every few months. We've been told there are now civilizations within machines that are looking to take over GPU clusters and start a mini revolution. But why have they not been able to inspire even a single person to the point where you have tears streaming down your face, or you just can't keep going back to that piece of writing? I think there's something really interesting about that fact, and I think we should inspect it a lot deeper.
Ross: Yeah, absolutely. But having said that, you're also using AI extensively in your company and your work and finding it very valuable. So I guess it's kind of like, where are both of those things true? Which comes back to the humans plus AI.
Pukar: Yeah, I mean, I think I'm using AI extensively. I've played around pretty extensively with it. I was an early adopter of ChatGPT. When they did their yearly lookback, I think I was in the top 0.01% of users or something like that in their rankings. I've used Claude, I've used Codex and Claude Code, and I'm on Grok. Grokbot seems to be a great tool. I was on Claude very earlyâeven got a separate MacBook to make sure it didn't have any live credentials, as a cybersecurity nerd. So I've been playing around with these tools quite a bit, and I would say they've made my ability to engage with pixels on a machine much greater, giving me a wider range of motion on this glass screen that I look at every day.
There was a point at which I did not feel very accomplished at my range of motion in arranging those pixels because I was not a native engineer or something like that. They make me feel like I can do a lot more, and I think that's great. It's also allowing me to learn much more. But I do think one thing I've noticed about AI is it allows you toâif you have an idea for a new product, startup, website, or whateverâthe time to go from zero to a version of that, to a v1, is so fast.
But what's more interesting to me is, what are the things that have some degree of gravity and stick-to-itiveness? What are the things you're committing to building and working on, not just in that initial version where you put up a landing page and make a cool graphic or workflow, but what are you still building after week three, four, month two, three, four? That's what I'm more interested in, because the agency to startâthe cost of that has greatly decreasedâbut the stick-to-itiveness cost, the focus to actually stick with something, I think in some ways the price of that has maybe increased a little bit. There's always some additional opportunity cost, and you always want to go back to zero and start something new again. So I do find that to be a little bit interesting.
Ross: That goes to human attention and focus. Yes. We might come back to that, but I'm interestedâin the context of your organization, SecurityPal, where you explicitly say you are using AI plus human judgment, perhaps you can give the context of what SecurityPal does, and then dig into the specifics of how AI and human expertise are married in providing solutions.
Pukar: Yeah, we're really a company that started before AI, but the TLDR on the company is, we help enterprisesâlarge multinational companies. We have one of the largest airliners, one of the largest health insurers, a couple of the largest AI companies on our platform. We help them demonstrate assurance and trust to their customers, so we help them prove that they are a trustworthy and secure platform by responding to different sets of questions or attestation requirements, or providing proof that they have certain certifications and controls internally that ensure they are a secure platform.
As you can imagine, anytime you are in a commercial transaction, it's not just about having the best product; it's also about making sure that product and service is secure. So between buyers and sellers, there's a lot that needs to be understood. Before you're purchasing a product, you really need to deeply understand and vet that supplier and the product and service they're offering. And before you sell your product, you have to meet certain minimum bars of security, compliance, and assurance.
We started out as a platform that automated these things called security questionnaires and security assessments that companies like Figma and Airtable needed to answer here in San Francisco. But we've really expanded our capabilities to the universe of what we like to say are cybersecurity assurance jobs to be doneâwhich is, what are all the things you have to do to prove that you're secure to your customer base or partner base, and what are all the things you need to do to actually get security assurance from your vendors and suppliers? We automate a lot of the tasks in there, and obviously AI is a great tool for that.
But like anything, it's that old Reagan quote: trust but verify. You want to trust the software, but you also want to verify that you can trust the software, so you still need humans to reallyâwhether that means random sampling the outputs and taking a look at how much it's deviating from the expected value, expected safety, or security. It's also about making sure that proper processes are followed.
The thing about cybersecurity is, it's not enough to be great at yesterday's war. You have to be prepared for the future battles that are going to be fought in cyberspace. Cybersecurity is a tremendously exciting but very stressful place to be, especially for the chief information security officers, chief information officers, the GRC professionals, the go-to-market professionals that we engage with on a day-to-day basis. This dynamic space requires you to be quick on your feet and always be thinking about how to meet the novel requirements of the future and today.
Now, everything is about agentic security and how you secure agents and LLMs, and how you ensure zero data retention. There are all these different thingsâif I said zero data retention five years ago, ZDR, you'd have no idea what I'm talking about. But now, ZDR is all the rage for many enterprises. If I said agentic security ten years ago, you might think I'm talking about The Matrix and how to prevent ourselves from being attacked by a bunch of Mr. Smiths. But these terms now have real value today in the world. Technology is such that it's always exciting, and there's always a new battle to fight, and it's about how you meet that moment.
Ross: So, digging inâobviously there's a lot of automation in this, just through the amount of data, the amount of work, the extent of the space you're covering. So, what specifically then are human roles? Perhaps one of the most interesting parts is, as you say, the landscape is changing. How are you bringing inâor what is the specific application of human expertise in assessing new domains, how are those integrated into your processes, and then maintaining that human as part of those processes, so that as you say, it is verified and truly trustworthy?
Pukar: Yeah, a good example of this is, if you're assessing a supplier, you can have an AI agent go out there and find as much information as exists on the public web about that supplierâwhere are they based, who are their founders, are they compliant with certain industry standard certifications, maybe they even have those logos on their website. So you might say, "Aha! By virtue of a reasonable AI, the logos are on the website, so they must be secure, right?"
There was a famous video conferencing toolâI won't name whichâbut in order to show the user that they were encrypting data, they did not, in fact, encrypt the feed. They just put the picture of a lock on the screen. This is what I mean: as smart as these machines are, it is very easy to fool them, because there's some assumption that what you see and what you touch and what divs exist on a page, ipso facto, it must be secure. But that's not necessarily the case.
Somebody has to do the work of double-clicking and verifying. Okay, this vendor is saying they have these SOC 2 certifications and these ISO standards and have been through a pen test and have a bunch of fancy pages and white papers that say they're secure. Well, let's verify that. Can we actually call up the CPA firm or the firm that did their attestation? Do they remember working with them, or can they verify that they were indeed the ones behind this? What is the rating of that firm that did the assessment?
In a world where an AI can freely skate around the web, much like a human, it's really about that secondary and tertiary degree of validation and critical thinking that's required. It necessitates a degree of, dare I say, paranoia, but it's much needed for the types of customers we're serving. We're talking about major airlines, major health insurers, major cloud and AI companies, healthcare AI companies.
As AI gets better and better at doing things that a human traditionally didâphysically looking at a screen and clicking buttonsâit's really about, now that AI can do that and understands what it needs to look like to appear legit, where do we go next? When ChatGPT came out, I knew that the cybersecurity market had increased by several orders of magnitude, just because the most common problems in cybersecurity are never that you have to worry about some container not being encrypted when it should have been. Obviously, you should do that work and have a security team doing that. But the greatest risk that keeps most security leaders up at night is, are one of my 5,000 team members at this company going to click on that random phishing email and take down the entire network?
The things that keep us up at night are really much more, dare I say, benign in some ways. It reminds me of the COVID times. You don't want to be worried about some virus vector entering you when you walk into a hall or something like that. You really have to be worried about yourself not washing your hands enough after going to the bathroom or something like that. It's really about the basics.
Ross: Yeah, and also thinking beyond. One of the points there is that going beyond the specific parameters you can give the AI, the human can necessarily think beyond that as to what might not be an exact fit with the way in which the AI is being designed or framed. One of the things you've written about is human agency. As we get decision-making at all levels, both in the systems you're describing and more generallyâstrategic decisions, policy decisions, and beyondâhow do we shape and support human agency? Our ability to, as you mentioned before, start a startup, build that, have intention, and drive that. So, what are the systems or frameworks we can put in place that support human agency when more and more decision-making is AI-driven?
Pukar: I love this question, Ross, and I'm not just saying that because I'm on your podcast. I love this question because it's something I think about so much. I firmly believe every individual on the planet has agency. But the challenge is they've been put on the wrong field. Some of us are lucky that we are born on the right pitchâbe it a tennis court, a football field, Aussie football, or whatever it is. Some of us are actually born on the right pitch or close enough to the right pitch that we can find our way there, but some of us are not born anywhere near the right pitch, or the right pitch hasn't even been created yet. Technology has not allowed the right field to even be created to allow all these different forms of agency to come to life.
One of my great hopes for AI is it gives every human the ability to freely wrestle with the frontiers of their own capability, without having to worry about putting food on the table or how they might take care of their children. What would the world look like if everybody could actually reach their production frontier, to pull a term from economics? I believe we as humans, in many ways, have this innate desire to run after the jagged frontier. There's something very exciting about that. It's like that penguin going off into the bitter Antarctic. I don't know if you've seen March of the Penguins, but I think there is that in all of us, though not all of us have the luxury to actually do that.
For me, I've been able to find that in entrepreneurship and such. That's my hope.
Ross: I have to agree. This human potentialâI've always believed, from when I was young, I wanted to fulfill my potential. That's the aspiration: as many people as possible on the planet fulfill what they can possibly do to the best of their abilities. I agree that the positive potential of AI is that we can support that. But the question is, how specifically can we enable that? What are the systems we can put in place? What are the ways in which we can create organizations that do that? What are the ways we can actually bring this to pass?
Pukar: I'm a big believer inâwell, I really think we need to talk about compute equality and equality of opportunity, not necessarily outcomes, but I think everybody should have access to compute. It's going to be as fundamental as having access to roads and basic infrastructure in a city, to be able to go from point A to point B. In a city, you go from one three-dimensional space to another. I don't want to get too nerdy here, but compute is really your ability to travel across the fourth-dimensional space. You have all these various future outcomes that you can build through this magical melted sand in a box, and where do you want to take that point? Where do you want to go build?
I think we need to really talk about how to ensure the whole world has access to compute, and that's something I've been thinking a lot about. As someone who's an immigrant from Nepal to the United States at the age of seven, growing up in New York City, I've actually lived through about 150 years of technological change in my three decades on the planet. I grew up with kerosene lamps and outhouses, no indoor plumbing, no cars where I grew up. We used to cook by firewood. I used to look at airplanes in the sky and wonder what they were and if I would ever be in one. So I grew up in a place like that in the foothills of the Himalayas, and now I'm running an AI cybersecurity company in San Francisco, serving some of the most advanced companies in the world.
I believe that type of leap is possible for everybody, but it requires people to have access to the modern-day tools to allow for something like that. So compute equality is something I think deeply about. To the extent that we can give everybody access to intelligenceâone question I always ask people on my team or others is, how good are you at intelligence? How good are you at intelligence? I think I'm fairly good at intelligence, and the question is really meant to make you thinkâeverybody thinks, "If only I could be CEO of Apple, I'm sure I could do a great job." Well, that requires steering a great degree of intelligence that exists in that organization.
Think about it in the same wayâif somebody made me CEO of Apple, that company would crash overnight, because I just wouldn't know how to steer that intelligence. So I'm continuing to level up my ability to really steer intelligence. How good are you at steering intelligence? That's a muscle. That's a meta muscle. Normally we think about being smart, but can you actually guide smart? Can you guide intelligence to the future outcomes that you want? That's something I think a lot aboutâlowering the barriers to being able to do that and really learning about that as a muscle, almost algorithmically.
It's like the first time you learn how programming worksâyou click these buttons, you build this algorithm, and it runs, and it really opens your mind to a world of possibilities within this machine. It's like learning about linear algebra for the first timeâit blows your brain apart. It's a little bit like that.
Ross: So there's also the education, the way we think about it. We have this tool, and some peopleâand I think that's the very big difference, just crudely, between those who say, "Okay, AI, here's a tool which can go and do these little things for me," and those who think about it as a thinking partner. These are mental models and ways in which we are thinking. This idea of scaffoldingâhow can we get AI to support our better thinking? We have our mental models which guide how we interact with the AI. We also have the ability for AI to help us build better and more useful mental models and ways of thinking. So, the point of access to compute is a great starting point. We also need to have the right mental models and know how to use the tools, to build our own thinking and our own things. Are there ways we can enable that for ourselves or societies?
Pukar: Yeah, I totally agree with you. I think the greatest thing you can do is teach somebody how to do something once, and that's greatâthat has some linear impact on their ability to execute something. But you can teach someone the algorithm behind it, and that gives them much greater range of motion. I'm always more interested in learning about the algorithm. I don't want to hard code any of these things into my brain; I want to learn the algorithm. Right now, I'm trying to learn the algorithm of intelligence. I think I'm incredibly dumb at using intelligence, by the way. My answer for myself would be, how good am I at intelligence? I'm not sure I'm that good at intelligence, but I'm learning how to be better. That's why.
Ross: Well, it's trajectory. It's the direction that matters. It doesn't matter where you are. If you're continuing to get better at it, then you're going to end up in a good place.
Pukar: Yeah, yeah.
Ross: One of the things you've written about, which I think we probably strongly agree on, is around how do we frame AGI. A lot of people are saying, "Okay, well, AGI is something as good as or better than what humans are," but that's a pretty dumb thing to do because we've already got humans, so why try to replicate it? You've got this framing as AGI's expansion, and I'd love to hear how you frame it and think about that.
Pukar: Yeah, it's interesting. My definition of AGI, much like the market, is evolving. There's no doubt that the goalposts have shifted for everybody in what AGI means, because we blew past the Turing test over a weekend, more or less. But I think there's still some je ne sais quoi about being a human that we haven't been able to really point to. There's a reason why we can still tell AI-generated outputâif we apply a little bit of intelligence and reasoning, we can, in some ways, tell what has been generated by AI and what has not. So perhaps there's a new type of Turing test that needs to be created.
There's still the fact that, when I think about previous industrial revolutions, there was an entire assembly line workforce where we had humans at different stations, screwing things on, twisting caps, painting stuff, and you could have said, "Okay, they're doing something that only humans can do." If someone had said at the steam engine turn of the 19th century that one day a lot of this was going to be automated, maybe they would have called it AGIâ"How could you automate this very complex set of tasks?" But we have, and we don't necessarily think of that as getting rid of the work or our raison d'ĂȘtre, our reason for being. We've just gone and figured out other things to do with those skills.
For me, I'm excited for AGI to really push the frontier of what humans thinkâthe human expectations. What expectations do humans have for themselves? For a long time, we've been in a lull. We created the radio, we created the TV, and for half a century we sat in front of screens. We used to stare at screens, then we learned how to control and manipulate them, and then we put all our data in there. Maybe we needed that data, all that exhaust, to build this intelligent being, and now it's about, what are we doing as humans?
It almost feels like for half a century we forgotâoh wait, we're supposed to explore the stars! Of course! Oh my god, what have we been doing? Watching The Simpsons all day or something. So, 50 years after the 1960s space race, we're finally coming around, being like, "We have to stop watching memes and just go to space." That's where it is. Maybe we needed that time period. I don't want to sound too Thielian here, but I really do feel like fundamentally, we are explorers, and we need that.
Does AGI have that? I'm not quite sure. Like I said, I'm still waiting to read a piece that totally floors me from AIâwhere I'm just like, you know, I don't want to sound cheesy, but like that monologue from Robin Williams in Good Will Hunting. I'm in San Francisco, so I'll use Robin Williamsâwhere he has that monologue about love. You can read about love in a book, but have you ever looked at a woman? I'm sure you know what I'm talking about. It's a very famous monologue.
Something like that, something that really gives you goosebumps. I'm still waiting for even the slightest tinge of that. Maybe some folks have gotten it, but I certainly have not, and I think I would know off the top of my head if there was something so compelling. I think it's great at code, but I'm not surprisedâcode is so logical, and logical systems like machines are, of course, good at logical systems like that.
So my definition of AGI is changing. I'm curious to hear your perspective, especially with this new, you know, I'm sure you've been following the Darkesh Patel, the Hugging Face incident and stuff like that. What are your thoughts about AGI and where we are right now?
Ross: Well, the first point to me is that trying to emulate humans was never a good quest. We've got humans alreadyâwhy do we do that? That framing of artificial intelligence from the Dartmouth conference and so on probably set us on a wrong journey. Now everyone is saying, "All right, how do weâ" and so this definition from Sam Altman of being able to do anything which human workers can do, it's specifically targeting the economic value of humans. This does make sense, but why focus on that? I think there are many more ways to frame it, and as you say, the threshold could be anywhere.
But I think, exactly to your point, this needs to be around how can this push us up a level. As you say, instead of sitting in front of the TV and being passive, this is now something we can interact with. It is humans plus AI. We're moving beyond delegating; we are able to engage to take our own thinking to the next level, to do more than we could ever do before, to fulfill our potential.
So in a way, I always think that the AGI framing is the wrong framing. We need to be looking at how we build augmentative tools. Back to Doug Engelbartâhe got it right: intelligence augmentation. He said that from the start, and that's what we should be focusing on. We've gotten caught up in this AGI frame, but that's not the right one.
Pukar: Yeah, I mean, it's hard to know what the future holds. If you had told meâ I don't know what I would think if you had shown me some of these tools back in 2020.
Ross: Oh, be blown away. I think everybody has been.
Pukar: Yeah, I mean, it's like, whoa.
Ross: Whoa, whoa.
Pukar: I would probably think it's some sort of magic, just because the way in which we were trying to do thisâbecause we were so stuck in the pre-transformer era, old-school machine learning. I think we would have a hard time. But what is the nextâsomeone's working on a technology that is similar to what transformers were ten years ago. I know there are some papers out there and stuff like that. What does that next iteration look like?
Also, a long time ago, I used to do neuroscience research at Columbia University, and I gained a great appreciation for the brain and neuronal networks. What's crazy is, we were studying these neurons in a model organism like worms, and what was interesting is you had these symmetric neurons that looked the same but came to those expressions in completely different ways. Phenotypically, they were identical, but underneath the hood, they were very different in terms of the pathways they took to get there.
So it's very interesting. Sometimes I do wonderâ I understand how complex the brain is. I have maybe a deeper appreciation for that than the average individual, so if we're trying to mimic the brain, I'm not sure if this is the way to do it. But I also know that birds look very different from airplanes, and both accomplish the same thing, or rockets and so on. But I would not expect an airplane to do what a hummingbird does in my backyard. That's a different type of capability that we haven't quite adapted our machines to.
All of that is to say, I don't know. I can only analogize and reason through analogyâthat's where the human brain is sort of stuck in some ways. But I think what's interesting to me is, we think we're living in incredibly interesting times, and perhaps every time period thought that. If this is not the most interesting time, I'm very excited for the future. That's all I'm going to say.
Ross: That's fantastic, Pukar. So, where can people go to find out more about your work?
Pukar: Yeah, they can go to my personal website, pukarhamal.com, and all my different writings, companies, ideas, and thoughts are there, as well as initiatives that I'm leading right now. For folks that are listening, Nepal's going through floods, and there are many initiatives trying to raise money for the really catastrophic situation in Nepal due to the flooding in the Himalayas. If people want to contribute in any meaningful way, they can do that through the Nepal Relief Fund or any of the other organizations they're interested in contributing to. It would mean a lot for the country.
Ross: Thank you. Thank you for sharing. Thank you for all of your work. It's been a great conversation.
Pukar: Thank you so much Ross! Appreciate it. Thank you.
Podcast: Play in new window | Download






