[BidClub_]
Gradient Dissent · · 50 min

Inside the Dark Web, AI and Cybersecurity with Christopher Ahlberg CEO of Recorded Future

Lukas BiewaldChristopher Ahlberg

YouTube
TL;DR
  • Mastercard’s $2.65 billion acquisition gives Recorded Future a long-term home and a route to combine threat intelligence with financial intelligence. Christopher Ahlberg calls the product a “Bloomberg for intelligence”: it turns the internet into an intelligence sensor, organizes hostile activity, and produces geopolitical, cyber, and warfighter insights. Recorded Future continues operating standalone.

  • Cybercrime has become a specialized supply chain with unusually attractive economics. People obtain and sell access, ransomware developers franchise their software, operators execute attacks, and specialists move Bitcoin through money mules; Ahlberg describes an 80/20 revenue split and “one of the best business models ever operated on planet Earth.” Twenty- to 25-year-old forums remain active, but much of the market has moved to Telegram.

  • Recorded Future’s AI stack progressed from hand-coded rules to multilingual extraction and automated intelligence production. Its original entity and event extractors were stacks of if-then statements; one model now spans roughly 15–30 languages and transfers learning across languages. LLMs can also produce recurring analysis—such as second-order implications from Somalia, written in Arabic and delivered every week at 8 a.m.—that Ahlberg says would have seemed impossible three to five years ago.

  • Ukraine turned Recorded Future’s deployment into a defensive data flywheel. Deploying the system there exposed the company to modern malware and other threats, which could then feed protection for customers elsewhere, creating what Ahlberg cautiously likens to a “virtual Iron Dome.” The company supports national capabilities in 47 countries but screens every customer and excludes governments and companies it considers unacceptable.

  • AI is expanding the reach and potential speed of cyber offense, while human-only defense will not suffice. Better phishing already works across languages; Ahlberg expects software that autonomously traverses compromised networks, forcing defenders to deploy automated countermeasures. Rob Joyce’s rule—“you have to know your network better than the bad guy coming at you”—becomes harder when an AI-assisted crawler can outsmart veteran IT staff.

  • The second-time-founder lesson was to pair a broad technical insight with ruthless market focus. Ahlberg admits Recorded Future began as “a big-ass hammer,” not a customer pain point; it initially pursued intelligence and quantitative-trading signals until a Series C investor told the company to kill the latter. Focusing on a larger cybersecurity market let it ride a wave where “you can make a lot of mistakes,” contrasting with Spotfire’s narrower pharmaceutical niche and $195 million exit.

  • Ahlberg expects the internet to move from reflecting society to actively defining it, raising the stakes for platforms, democracy, and warfare. He remains an optimist—democracy is “the best of the worst,” and education may blunt primitive manipulation—but does not claim defenders will win. If perhaps 75% of future information is machine-generated, merely labeling synthetic content will be insufficient; armed drones could also make a designated 10-by-10k-kilometer area lethal to anything moving inside it.

Digest · the substance, structured for research

1. The internet became an intelligence sensor before it became a product

  • Ahlberg’s compact description is “AI for intelligence or intelligence for AI.” Recorded Future collects the world’s “bad news”—especially cyber threats—and organizes it into geopolitical, security, and battlefield insights, leading him to call the service “the Bloomberg for intelligence.”

  • The founding insight arrived while Ahlberg was running on a treadmill after signing Spotfire’s sale but before closing it: instead of analyzing an Oracle database or Excel spreadsheet, why not connect an analytical engine directly to the internet and extract entities, events, and future time points from human-produced text?

  • “Recorded Future” grew from tracking statements such as Xi Jinping traveling to Moscow on Friday and keeping tabs on everything known about that event. A co-founder initially suggested Recorded Time, invoking “the end of recorded time” from Macbeth, but that domain was taken; the deeper premise remained that “most secrets are known”—the challenge is reaching wherever they reside.

2. Cybercrime operates as a market with specialized labor

  • The defining early case came in 2016, when Recorded Future found a Russian actor selling access to the Election Assistance Commission after using SQL injection to extract information. The company bought the access, took custody of it, and warned the government: “You may want to make this thing go away.”

  • Old marketplaces including Maza and Exploit.in have survived for 20–25 years, mostly on Tor, because criminals holding stolen information need somewhere to monetize it. During the interview, Ahlberg said someone was actively selling access to servers belonging to a prominent software company and that the live situation was creating havoc; he deliberately kept the company and details fuzzy.

  • The labor is divided among people who obtain access, people who sell it, ransomware developers, attack operators, Bitcoin handlers, and money mules. Developers franchise or rent their ransomware; an operator might retain 80% of a payment while returning 20% to the software provider—economics Ahlberg calls extraordinarily effective.

  • Getting inside restricted communities takes human social engineering and automated scraping, sometimes through six access layers. Ahlberg says he would not necessarily call this AI; scrapers imitate criminal behavior closely enough to pass a “very limited Turing test.”

  • He recommends Signal because it publishes its source code and, in his description, has no real server to attack. He describes Telegram as centralized, with encryption unlike Signal’s end-to-end encryption. Its value to Recorded Future comes from a concentration of cybercriminals, traffickers, and other useful sources—not from every Telegram user being malicious. His practical advice remains: “Use Signal. Make good choices, Lukas.”

3. A broad technical hammer needed a narrow commercial target

  • Biewald’s pushback—worth keeping—is that neither Spotfire nor Recorded Future began with a precise customer pain point. Ahlberg agrees: Spotfire started by visualizing almost any dataset, then found a valuable pharmaceutical-discovery niche; Recorded Future was “inventing a big-ass hammer and trying to figure out where you could apply it.”

  • Spotfire’s specialization helped produce a $195 million sale to the Palo Alto company TIBCO, though Ahlberg believes the limited market capped its outcome. Biewald reframed that result for younger listeners by saying it would be like a $5 billion exit in 2025 terms. Recorded Future entertained commercial and sales intelligence before taking money from In-Q-Tel and Google Ventures around 2008 or 2009 and honing in on intelligence.

  • The repeat-founder mistake was trying to sustain both intelligence and quantitative-trading tracks for years. When a Series C investor told him to kill trading, Ahlberg conceded, “You’re actually right”; concentration freed the company to ride a much larger cybersecurity investment wave, where scale allowed “a lot of mistakes.”

4. AI moved from extracting facts to performing analyst work

  • Recorded Future’s first entity and event extractors were “stacks of if-then-else statements,” supported by extensive tests mapping sample text to expected outputs. Ahlberg says the company probably went through three generations of extractors; separate language-specific systems became one internally controlled model spanning perhaps 15–30 languages, with striking transfer across language families.

  • Ahlberg openly reverses his earlier call: while debating with co-founder Staffan whether another AI winter was arriving, he thought progress felt exhausted; Staffan predicted takeoff. “He was of course very right, and I was very wrong.”

  • His intelligence-agency analogy separates the collectors—the “James Bonds running around in the world”—from analysts assembling meaning. Generative systems now handle the latter: summarize Somalia last week, derive second-order implications, write the report in Arabic for an Egyptian partner, repeat weekly, and deliver it at 8 a.m. Ahlberg says he would not have believed this five years ago, perhaps even three years ago. “It just happens.”

  • The system also ingests images, NetFlow records, malware, and other technical data by wrapping them in human language that an LLM can process. Ahlberg repeatedly calls the result “mind-boggling”; some people in Washington, D.C., despite uneven public-sector adoption overall, were also exceptionally early and built systems he considers impressive.

5. Ukraine turned the battlefield into a defensive learning loop

  • Ukraine was already among the national customers using Recorded Future when Russia invaded; the company supports some form of national capability across 47 countries. Because Recorded Future did not approve of the invasion, it expanded its technology deployment in a number of places there.

  • Sophisticated spies may spend years pursuing a specific diary or travel record without exposing themselves, while destructive operations eventually reveal modern malware and infrastructure. Ukraine therefore became a “gigantic honeypot”: Recorded Future could detect attacks there and rapidly propagate the resulting intelligence to customers elsewhere—a “virtual Iron Dome type of thing.”

  • Government selection follows explicit exclusions, legal restrictions, an internal list or process, and committee review. Recorded Future has no customers in China, Russia, Iran, or North Korea; avoids places U.S. and European law restricts it from selling to, including Cuba and Sudan; and says selling to six or seven countries, including Syria, could mean prison. It also rejects companies engaged in illicit hacking. Ahlberg stresses that “no such choices will be perfect.”

  • Biewald worries that politically unpopular customers might be cut off arbitrarily. Ahlberg answers that all 2,000 customers undergo KYC, with products ranging from about $100,000 to “millions and millions”; the product is defensive, hosted, and can be cut off. Russia designated Recorded Future an “undesirable organization” in a statement from the Russian Prosecutor General just before Christmas. Ahlberg emphasizes information security, physical security, and careful travel, while noting that he doubts the company tops any adversary’s list.

6. An internet-first world accelerates manipulation and conflict

  • Ahlberg’s 25-year framing is that the internet first reflected physical transactions and relationships; increasingly, society reflects what originates online. When social life, business, and democracy become internet-first, political power may no longer fit national borders, raising the question of whether a country or Mark Zuckerberg with Facebook is really in control.

  • His democratic outlook is explicitly hedged. Democracy is historically rare and “the best of the worst,” yet online group formation and renewed nationalism could pull in opposing directions; he cannot tell whether today’s nationalism marks a new era or a reaction. His optimistic defense is deliberately unglamorous: follow Finland’s example, educate people well, and ensure they can read.

  • In cyber operations, AI has so far mainly improved phishing and made it possible to target more languages and audiences, but Ahlberg expects autonomous software to move through compromised systems either stealthily or at speed. Human-only defense will not suffice; whether defensive AI wins remains uncertain, especially when a crawler plus AI could outsmart most IT staff, even veterans who have worked at a company for 25 years.

  • Recorded Future already tries to flag likely machine-generated text and images, but Ahlberg wonders whether that matters if perhaps 75% of future information is synthetic. The physical endpoint is darker: someone could mark a 10-by-10k-kilometer square, fill it with drones carrying guns and grenades, and make “anything that moves in there” dead—changing warfare “in a brutal way.”

7. Mastercard connects threat intelligence to financial outcomes

  • The $2.65 billion acquisition followed multiyear discussions. Beyond Mastercard’s payments business, Ahlberg saw useful cyber and intelligence assets in its services business, a long-term-value mindset, and a credible home for a company he had spent roughly 15 years building; Recorded Future would continue operating standalone.

  • The clearest synergy is a stolen credit card: knowing whether it has actually been used reveals more than the credential itself. Joining that financial endpoint to Recorded Future’s intelligence could expose the supply chain from which those cards came.

  • Ahlberg’s post-acquisition advice is unsentimental: keep executing very well, build good friendships and relationships with the people who will make the plans happen, and never assume clever thoughts on paper will realize themselves. “Unfortunately, I guess it continues to be hard work. It’s sort of unavoidable.”

1. The Mastercard acquisition and what’s next for Recorded Future

Lukas Biewald

You're listening to Gradient Descent, a show about making machine learning work in the real world, and I'm your host, Lukas Biewald. Christopher Ahlberg is an old friend and the CEO and founder of Recorded Future, an AI cyber security startup that was founded in 2009 and sold recently to Mastercard for $2.65 billion. Previously, he was the founder of Spotfire, an information visualization startup, and we talk about AI applied to cyber threats, war in Ukraine, and compare notes on being two-time founders. All right, so Christopher, welcome to Gradient Descent. Great to see you. You're my favorite kind of guest: someone who's taking AI and applying it to an important domain that I don't understand very well. For our audience, you're going to have to tell us about your company, Recorded Future, and the problems you solve. Maybe we could start with that.

Christopher Ahlberg

You could—I wouldn't use this description widely, but in this context, maybe you could say that we're doing AI for intelligence, or intelligence for AI, if you want. We're an intelligence company—threat intelligence. We try to get our hands on everything bad that's going on in the world, but maybe more importantly, in the internet world.

There was an opportunity to think about the internet as an incredible intelligent sensor. That happened at the same time as the world slowly migrated onto the internet, and as that migration is happening, it's getting to the point where the world is actually becoming a reflection of the internet, crazily enough. We've done hard work over the last 10 to 15 years to organize and collect this data. You can imagine all kinds of crazy data; we've had to use a lot of machine learning, big-data analytics, and now AI—pick your favorite words—to make sense of a lot of it.

A lot of that work got started in natural-language processing and related areas, but then expanded to all kinds of other data. In the end, it's all about producing great insights. These could be insights about geopolitics, cyber threats, or things that support a warfighter. They could be insights of all kinds, but they're all in this bad-news domain, in the threat-intelligence domain. We've built a good business there. Sometimes I summarize it by saying that we're sort of the Bloomberg for intelligence.

Lukas Biewald

I'm sure that, like a lot of our guests, the most interesting things you've done are things you can't say. Is there any particular insight that you pulled out that you're proud of and can talk about?

Christopher Ahlberg

Through the years, there have been wild things. Going back to 2016, when the election stuff was sort of happening for the first time, we found some Russian guy who was selling access to the Election Assistance Commission. It was incredible stuff. That was probably the first moment when you were just like, "Wow, dude, what's going on?"

Lukas Biewald

Can you talk about how you figured that out? That's amazing. How does that work?

Christopher Ahlberg

In that case, it was this wonderful dark-web world. Back then, it was in forums that still exist; a lot of that has now moved on to Telegram, if you want. That's where a lot of the bad news of the world happens now.

2. From entity extraction to generative reporting with LLMs

Some guy had broken into this thing called the Election Assistance Commission, or EAC. He had hacked it using SQL injection, extracted a whole bunch of information, and then, more importantly, went back out and said, "I'm selling access to this. Who wants the access?" We found it before somebody else and actually bought the access, crazily enough.

Lukas Biewald

That's really—yeah. Wow.

3. How Recorded Future finds threats on the dark web

Christopher Ahlberg

We took custody of it and then went back to the government and said, "You may want to make this thing go away." I remember when a fantastic colleague, Andre, called me in the middle of the night and just said, "Something not so great is going on. What should we do?" It was a long time ago, but it's a good story.

Lukas Biewald

You're instantly pulling me off my script, which I've been trying to stay a little more on script, but I can't help myself. What is the dark web? Is it forums that people log into? Is it on Tor? What actually is it?

Christopher Ahlberg

It is. It's a portion of the internet, just to be clear, and it's changed recently. We can come back to this and talk about Telegram, but this stuff is still there. There are these forums, and it turns out that if you're in the business of buying and selling information, you need a place to buy and sell it. You can't just sit on it; then you're not going to make much money.

These guys' only real interest is in making money. That's different from spies and government spies. These guys want to make money, so they need places to buy and sell. Some of these forums were put up in the early 2000s. Maza and Exploit.in have these wonderful names. Some of them still exist 20 or 25 years later, crazily enough.

Most of them are on Tor, and some of them are not. They're essentially marketplaces, and we keep a close eye on them, if we put it that way. I can tell you that right now, somebody, as of an hour or a couple of hours ago, was selling access to a particular—I’ll just call it a big software company's—servers, and it's creating havoc right now, at this moment.

We got our hands on all this data. We're trying to upload it into our system, generate alerts to all the clients, and do all the things we need to do. This stuff is never-ending.

Lukas Biewald

So, literally right now, someone's selling access to a company's servers—many of them?

Christopher Ahlberg

The software is installed on the servers. Because something is going on in real time, I'll leave it a little bit fuzzy, but it's a big, prominent software company, and they're selling access to it.

Lukas Biewald

Who would typically buy it? Do you pretend to be someone who wants to buy it to lure them in? Who would even want that access?

Christopher Ahlberg

Typically, these guys will sell access. If you think about the people who want to buy access, there could obviously be somebody who wants to get after something very special. But what happens in this world is that it's very specialized.

You have people who go get access. You have people who sell access. You have people who will then, for example, sell ransomware software or rent access to ransomware software. You have people who will help you execute the ransomware, and people who then handle the actual Bitcoin flows all the way to money mules.

4. Criminal marketplaces, Telegram, and ransomware-as-a-service

It's a highly specialized world of criminals. A large portion of them are in Russia, but not all of them. In this case, it's probably somebody who's realized that they can sell access to all these different places, which opens up all kinds of opportunities for ransomware. I'm guessing, since it's happening in real time, but it's a pretty interesting world.

Lukas Biewald

It's an interesting world. I'm totally unaware of this, so who would want to buy this data? Is that other criminals? Or is that, like, other criminals?

Christopher Ahlberg

Other criminals—probably the ransomware actors. There is a whole slew of these ransomware actors. There are people who write and operate ransomware software. They then franchise out the use of this ransomware software to other actors, who use it to execute attacks.

In return for keeping, say, 80% of whatever money they get from the ransomware transaction, the operator gets the other 20%. It becomes one of the best business models ever operated on planet Earth.

Lukas Biewald

Presumably, if someone's selling something illegal, they want to make sure they're selling it to a criminal and not to you. Presumably, they're worried about selling it to you. How do you convince them that you're not going to turn them in or something like that?

Christopher Ahlberg

That's our job.

Lukas Biewald

Okay, I love it. Is there any AI involved in that, or is that a totally different thing?

Christopher Ahlberg

There is AI involved, because it turns out that these forums are tricky. They might be locked down in all kinds of different ways, so you need a lot of tradecraft to get in. It's a combination of human social engineering and smart scraping. There could be 6 layers of access to some of these places, so it's a pretty complicated sort of thing.

It's a combination of approaches. I wouldn't necessarily call it AI, but at the same time, these scrapers need to operate with humanlike behavior. I like to joke that they might actually pass a very limited Turing test, because they need to operate as if they're cybercriminals.

Lukas Biewald

I don't know. Is that a Turing test? I guess it's one kind of Turing test.

Christopher Ahlberg

Is it AI? It all depends on whose definition you go with, but, yeah, I guess it is.

Lukas Biewald

I guess there's a human looking at it. It's for sure a Turing test.

Christopher Ahlberg

Yeah. It's artificial criminal behavior, so I guess that's a Turing test of a special kind.

Lukas Biewald

Getting back on script—and I'm sure we're going to come back to this—one of the things we have in common is that we're both repeat entrepreneurs. You founded Spotfire back in, I think, 1996 and sold it 11 years later, and then you founded Recorded Future a little bit after that.

I was wondering if you could go back in time to when you started Recorded Future, what you were thinking at that moment, and what insight led you to start it.

Christopher Ahlberg

Yeah, that’s a great question. Spotfire was data visualization. I started that in the early 1990s while working on my PhD on how to visualize large data sets. It was sort of a predecessor to Palantir and a whole bunch of other things—not to claim that we were the first by any means, because we weren’t, but we did a nice job with certain kinds of data and so on.

We sold that to a company in Palo Alto called TIBCO. It worked out great, and we were very excited about that. But then the idea struck me that Spotfire was all about visualizing what was in an Oracle database or an Excel spreadsheet, or whatever—that sort of data. I was on the treadmill running, and we had signed the deal to sell Spotfire but hadn’t closed yet, so it was this weird in-between timing. It struck me: What if, instead of thinking about analyzing what’s in an Excel spreadsheet, I could hook up an analytical engine straight to the internet?

The internet, at the surface level at least, is mostly human-produced text. So you had to look for entities and events in text, try to make sense of that, and organize it in a way that you could analyze. That was the inspiration, and that’s how we got into it.

5. Starting Recorded Future: The idea behind connecting analytics to the internet

Lukas Biewald

Interesting. The name Recorded Future is super evocative. Did that come to you from the start?

Christopher Ahlberg

No, not immediately. It was one of my co-founders, Eric—a very clever guy. The idea from the beginning was that we’d find future time points in text. For example, Xi Jinping is traveling to Moscow on Friday. If you could keep tabs on everything that’s known in the world from all the sources, we should get a good picture of where Xi Jinping is, to use an extreme example.

From the beginning, Eric suggested we should call it Recorded Time. I guess it came from Shakespeare’s Macbeth: “until the end of recorded time” was sort of the idea. Then, of course, the domain name Recorded Time was taken, and it became Recorded Future, which was probably a better name to begin with. It fits well with the idea that most secrets are known; you just have to get to where they are. Let’s get to all of it.

Lukas Biewald

It’s interesting. It seems like a bit of an entrepreneurial anti-pattern here. It doesn’t sound like you were starting with a specific customer pain point and working backward. It sounds like you started with your interest. Was it obvious that intelligence was going to be a big customer for this? As broadly as you could apply it, almost any organization would benefit from this kind of analysis.

Christopher Ahlberg

Totally. That’s probably my weakness, but maybe it’s also a decent strength. Spotfire started as a tool where we could visualize any data set. In that case, we stumbled onto visualizing and analyzing pharmaceutical discovery data—a very high-end, very valuable application—and it worked out great. We ended up doing a lot of counterterrorism work in the intelligence space, and I’ve always loved that world. We did a lot of good work there.

When we started Recorded Future, we knew there was an application in strategic foresight or whatever. It turned out that we ended up in the cyber world with it. So, no, it was certainly more a matter of inventing a big-ass hammer and trying to figure out where you could apply it, rather than the other way around. But isn’t that how a lot of good stuff comes about? I don’t know what you would say.

Lukas Biewald

I think a lot of good ideas come that way. You’ve been incredibly successful, so I think people’s strengths and weaknesses are often connected. I’m curious about your process. When you started this company, did you have a big list of possible use cases and run down the list talking to people? How long did it take you to get to these specific use cases, and how did you approach that?

Christopher Ahlberg

We sort of knew there was something in intelligence, for sure. We also thought about commercial intelligence, sales intelligence, and lots of other things. There are people who have built similar types of companies in lots of different spaces. We had a long list. I think I still have those, whatever you want to call them, presentations—you can imagine the first venture presentations.

Lukas Biewald

Yeah, yeah.

Christopher Ahlberg

We quickly went to In-Q-Tel. Google Ventures barely existed at the time, but we ended up taking money from In-Q-Tel and Google Ventures back in 2008 or 2009, something like that. We honed in on this intel thing pretty early, but it could have gone many other places too, for sure.

Lukas Biewald

One question that I always get asked, and that I feel like I never have a good answer to—but I think I’m going to turn around and ask it to you—is: You’ve now done these 2 companies, and you’ve done both for quite a long period of time. What did you do differently in your second company? What did you take away as a second-time entrepreneur?

Christopher Ahlberg

That’s the Peter Thiel question. It sounds like that. I’ll start with the bad side. With the first company, it took us a little time. We started very generally, then focused on pharmaceutical discovery and killed it in that domain, and worked from there. That domain ended up being fairly limited and probably limited the outcome of the company to some degree. We sold out for $195 million—not to sneeze at, you know.

Lukas Biewald

Congratulations, man.

Christopher Ahlberg

No, no, but these days people are—

Lukas Biewald

Yeah, yeah, whatever. To put it in terms that the younger listeners are thinking about, that would be like a $5 billion exit in 2025.

Christopher Ahlberg

So, here, I think the failure point was that we thought we could do multiple application areas. For multiple years, we ran an intelligence track and a quant-trading track to create quant-trading signals. We had a serious Series C investor come aboard, and he—you shouldn’t listen too much to your board, but this one guy—just said, “Kill that.” I thought, “You’re actually right. We should just kill it.” We killed it, and that was great. It freed us, and we could just run. It had sort of already started withering a little bit.

We probably thought too highly of ourselves. In terms of what we did differently that was better, we picked a bigger problem, which was great. This cyber intelligence turned out to be something where we ended up riding a massive wave. The investment in cybersecurity over the last 10 or 15 years has been incredible. Even though we certainly solved only a subset of it, by riding a big wave, you can make a lot of mistakes. You’ve seen that in AI too—the wave is big enough that it allows for a lot of mistakes. That would probably be the answer. I’m sure there’s more, but that’s it.

Lukas Biewald

Actually, great segue to my next question. You’ve been in this massive wave of not just cybersecurity, but the application of ML and AI throughout your roughly 15-year arc at Recorded Future. I’m really curious how the availability of data and the new applications of ML and AI changed Recorded Future’s business over the time that you operated it.

Christopher Ahlberg

That’s good. There are sort of 2 aspects to that: the data, and what you can now do with data. We started off with the stuff that we called AI in 2008, 2009, and 2010. We wrote our first entity extractors and event extractors with lots of if-then-else statements—just stacks of if-then-else statements. We also wrote a lot of good test cases to test whether it was right or wrong: Does this text lead to this? That sort of thing. It was obviously ridiculous from the point of view of what people are doing now.

We’ve probably gone through 3 generations even for those entity extractors. We used some commercial software, and now we sort of own all that internally. It’s been a great journey with that, and now it’s all based on these models, as you could expect. The availability of data has certainly helped through that. We used to have entity extractors for each language. Now that’s 1 coherent model that spans, I don’t know, 15 or 30 languages, and it’s amazing how it cross-learns between languages—not just within Indo-European languages, but across languages. It’s sort of bananas that this stuff even works.

It’s mimicking the human brain. Somewhere, there’s something wild going on in that.

The other big piece—we could spend a lot of time on this—is how it was one thing to do text feature extraction, if you want, or data extraction out of content. Now, with all this generative stuff, you could obviously—so, in intelligence, there are two aspects to it. You think about it like this: if you run a fancy intelligence agency, you’ve got the collectors, the James Bonds running around in the world, and then you’ve got the analysts who are putting stuff together.

The collection part is what I first described. The second part is writing everything from “Summarize what happened in Somalia last week” to “What are the second-order implications of what happened in Somalia last week?” So, from basic questions to more advanced ones: “Summarize the second-order implications of what happened in Somalia and get a report written in Arabic that I can share with my partner in Egypt about that.”

Those are pretty juicy, heavy questions. And, by the way, “Do that every week for me and deliver it to me at 8:00 a.m.” Now you’ve taken a fair amount of work and stacked it up there. We do that, and it just happens. It’s sort of mind-boggling, isn’t it?

If somebody had told me that 5 years ago, I would not have believed it. Maybe 3 years ago. But it’s pretty mind-boggling that this works, and it works with a mix of text and images. Actually, we collect a lot of other weird data—more NetFlow data, malware data, and very technical data—and we spend a lot of time figuring out how to wrap that in human language so the LLMs can handle that sort of data, too.

Even there, it works. I’m falling off the chair here. Maybe that’s because I’m too dumb to understand it, but it’s pretty mind-boggling.

6. ChatGPT, the intelligence community, and adoption challenges

Lukas Biewald

I totally agree, for what it’s worth. I wanted to ask you: when ChatGPT came out, I think it was 2 or 3 years ago, was that the same kind of watershed moment in the intelligence community that it was here in Silicon Valley, or did it take longer for people to realize the implications?

Christopher Ahlberg

I think, first, even inside Recorded Future, it took me a while. I remember debating with my co-founder, Staffan, whether we were coming to yet another AI winter or whether it was about to take off. I was like, “It feels like it’s done. It’s going to take off, buddy.” He was, of course, very right, and I was very wrong to begin with.

But then I think there were people in D.C. who ran with this in very cool ways. I don’t want to put names to things and so on, but there are areas where people have been extremely forward-leaning and built incredible stuff. We’ve had the good chance to spend time with those people. If they’re listening now, they’ll know who I’m talking about and where.

We compare notes on what we’re doing and what they’re doing. Sometimes their benefit is that they have access to very special data, while we have access to the internet in a way that we think maybe other people don’t. We try to collaborate on some of that.

In general, the government is never the best at taking advantage of new technology—or “never” isn’t true, because sometimes they put crazy satellites in the sky and stuff—but in general, it’s not always the best adopter of technology. In this case, though, some parts of the government were pretty amazing.

7. Helping Ukraine during the war: AI deployed in real-world conflict

Lukas Biewald

Another big moment that I think happened around the same time as GPT was the invasion of Ukraine. I know that was an important moment for Recorded Future. Could you take me back to that moment inside Recorded Future—what you were doing and how you responded?

Christopher Ahlberg

I would say a couple of different things. Ukraine had been a customer before in some areas. We have probably 47 different countries around the world that use us in some sort of national capability, all sort of in the West, plus the extended West—or that’s a weird way of describing the world, especially for those who live in the East. But you’ve got to explain it in one way or the other.

In that world of 47 countries, Ukraine was one of them. When the invasion happened, we did not approve of that, so we said, “Let’s help out.” We provided our technology, and it’s been deployed nicely in a number of places over there. It has been very good for them.

There have been—you can find a lot of good proof points. I’ll leave it to you to find the very specific ones they’ve been willing to talk about.

Lukas Biewald

Why don’t you tell us about the proof points? I’d love to hear about them. You’re allowed to brag about this.

Christopher Ahlberg

You have to be careful with this, but there are some very specific examples where we’ve been able to help. Part of this is that, when something happens—think about a spy. Again, we talked about criminals, who can be pretty brutal. They’re brutal, of course, but they can be pretty unsubtle. They just want to go make money. In many cases, they don’t really care whether they burn something or create havoc, as long as they make money.

They don’t necessarily think the longest term. A spy—whether it’s a Russian spy, a Chinese spy, or frankly our own spies—if they want to get access to information, for example, and the policy is that we should know what’s in Putin’s diary or in Xi Jinping’s travel records, or the other way around, one is willing to spend any number of years getting to that information. You have to be very subtle about it.

If you assume that Russian spies, Chinese spies, or anybody trying to come at Ukraine are trying to do that, they’ll be very careful, very subtle, and so on. When somebody wants to come and destroy something in the world of computers, though, they sort of become a gigantic honeypot, if you think about it. Everything shows up there.

When we deployed Recorded Future across a whole bunch of places there, we ended up learning a ton. You get in the way of the most modern malware of various sorts, along with all the other stuff that comes around with it. Any number of times, we’ve been able to detect incredible things and then have that data flow to all our other customers so they can defend against the same things.

It ends up being sort of—I don’t know, probably not a popular analogy—a virtual Iron Dome type of thing. That’s what this turns into, and it’s a pretty incredible outcome. It continues to this day.

8. How Recorded Future decides which governments to work with

Lukas Biewald

One question that comes to mind for me there is: is it ever tricky to decide which governments to work with and which not to work with? Running Weights & Biases, I’ve been surprised by how many different customers we have where employees might object. I think it’s really not my expertise to figure out who the good guys and the bad guys are, but we’re not exactly at the same level that you are.

It’s kind of your job, maybe, to figure out who the good guys and bad guys are. It’s probably pretty complicated once you really start digging in. How do you approach that? If a new government wanted to work with you, do you have some kind of flowchart that decides if they’re on our team or not?

Christopher Ahlberg

As you can imagine, it’s not something we necessarily publish, but I can state some general principles. You’re right: first of all, it is our job to be able to make those sorts of judgments. You have to make choices, and no such choices will be perfect.

It’s not like we can claim to have the most expertise. We’re software people; we’re not necessarily moral philosophers, just to avoid overstating our own abilities. We chose not to have customers in China, Russia, Iran, and North Korea. Those were sort of easy choices.

There are countries that U.S. and European law restricts us from selling to—some of the same countries, to some degree, but also places like Cuba and Sudan. There are 6 or 7 countries, including Syria, where you actually go straight to prison if you sell them stuff. That makes it easy.

Then you have other places that are trickier. There, I’m not going to start naming names, but we made choices about a number of countries that we simply stay away from. The same goes for companies. There are a number of companies that, for example, engage in illicit hacking behavior that we stay away from.

We have a process—you can call it a list, call it whatever you want. We don’t publish that. There are companies that help out with some of these things, and so on. It is a process, and a flowchart isn’t a bad way of thinking about it.

We have a committee at the very core of this for when there are choices to be made. Sometimes you actually have to make choices, and we make those choices. I make no claims about that being easy, but it’s never been that hard either. Sometimes it can be hard to write down, but we have a committee, and in the end, that committee decides.

I think we’ve been able to do that in a way that lets us go to bed feeling good about it.

Our stuff is for cyber defense, too, so it’s pretty worthless [for malicious uses]. It’s not like you’re going to use our software to decide where you’re going to drop a bomb or do anything like that. You cannot even physically use our software to intrude into a phone or do any of the malicious stuff. It’s cyber defense. So even if a bad guy got their hands on it, it wouldn’t be great, but it’s not like it’s going to create complete havoc in the world.

In the endgame, it’s hosted software. If the wrong guy got their hands on it, we can cut it off at any time, so there are a number of controls to it.

Lukas Biewald

I guess one of the things that’s important to me is that our customers know we’re not going to cut them off if they get politically unpopular, which is why I want to be super clear about our criteria.

Do you worry about that at all for Recorded Future? Just so it’s kind of clear what you guys are willing to do and not willing to do.

Christopher Ahlberg

First of all, our stuff is fairly expensive. We only have 2,000 customers, whereas somebody else might have many, many more. We know who they are, and every one of those 2,000 customers goes through a sort of KYC process—know your customer, sort of thing.

If somebody shows up with a company name that we have no idea about, has no website, has no nothing, they’re just not going to spend $100,000. Our stuff ranges from $100,000 up to millions and millions, so that self-selects a lot of different things. Whereas if you have a little dev shop with 4 guys who might use some AI tools, it might be more difficult for you to make those sorts of choices.

I don’t know—tell me if I’m wrong—but I think there are a whole bunch of variables that have made this less of an issue, actually.

Lukas Biewald

That’s great. Actually, shifting gears, I think we found a saying of yours that you repeated earlier here that I want to ask you about. I think it’s something like, “In the last 25 years, the internet reflected the world, and in the next 25 years, the world will reflect the internet.” Can you expand on what you mean by that?

Christopher Ahlberg

The first part is the trivial one: everything that’s happened in the physical world, whether it’s transactions, interactions, how we do business, or the simple stuff, has moved onto the internet. Through that, the internet becomes a reflection of what’s going on in the world. I think we’re all very happy to see that, and there’s not a lot of drama that comes out of it.

But as soon as those systems become internet-first, that’s what’s starting to happen. Whether it’s the trivial social one—you see kids and what’s going on in TikTok or Facebook or whatever; maybe not kids and Facebook, that’s not true—or whatever the preference or social network of preference is, it starts in the internet world. When democracy is internet-first and then goes onto the world, when business is internet-first, we end up in a world where what happens on the internet is actually what defines the world.

That’s what I think becomes pretty interesting, because now, if you run a country, it becomes tricky. Who’s in power? Is it the country, or is it Mark Zuckerberg with Facebook? It’s been pretty interesting even observing Facebook and seeing how Facebook switched the head of government affairs at the same time as he was elected president. That was probably not random.

9. Democracy, the internet, and AI manipulation risks

I think we’re going to see a lot of this. If you fast-forward to where that will be 25 years from now, I wouldn’t be keen to be a politician at all. I certainly wouldn’t want to try to be a politician in 25 years, because it’s probably going to be pretty tricky.

Lukas Biewald

I guess you talked about elections earlier, and we’ve had a lot of people on the show talking about different kinds of election interference and mitigation efforts. When you roll forward the trends that you’re seeing, do you think that U.S. society has to operate in a different way to be successful in this more vulnerable world?

Christopher Ahlberg

That’s a big question. I’m a huge democracy fan. Whether you take it from a positive way, how positive is it that we can live in a world where humanity has been around for tens of thousands of years, and most of the time it’s been the strong man who rules and you follow? Even when there has been democracy, it’s only been for the super-privileged or whatever. It’s pretty damn positive that we can have a vote. It’s pretty amazing that we get to live in that time.

Now, if you fast-forward and start thinking about what’s going to happen there, first of all, I was going to say the downside—the other non-super-positive way—is just to say there are a lot of other ways, and maybe democracy isn’t the best, but at least it’s the best of the worst. None of this stuff is amazing. It all has problems and so on, but I certainly haven’t seen anything remotely as good as democracy.

If you look forward and just ask how democracy could develop, there’s this question, because we think very much in terms of countries. That’s important, and that’s probably going to remain true, but if groups of people aren’t necessarily following national borders, it might make things very difficult.

Maybe we’re in a new era right now—I can’t really make that judgment—where there’s a new set of nationalism going on in a bunch of different places. Better or worse, we can only observe it, and that seems to be the case. But maybe that’s a reaction, and what’s going on would have happened on the internet. I think there are many other things like this.

The negative view would be that the world has been manipulated in many different ways, and there are amazing opportunities in front of us to manipulate. If I put on my “I want to be evil” brain, there are many ways to be evil. But maybe, on the other hand, people are also—let’s be positive—getting smart, and a lot of manipulation is pretty primitive.

I’m always saying, “Look, people always come up with wonderful tech solutions to deal with this. How about we do what they do in Finland and just give people a great education, and we can solve a lot of these problems?” Let’s make sure that people can read really well and other sorts of things, and it can work out.

I’m rambling a little bit, but I guess I’m generally an optimist. Democracy is better than anything.

Lukas Biewald

Yeah, that’s great to hear. When you think about AI’s offensive and defensive techniques, do you have a sense of what wins in election interference or any other conflict that we come into here? You can use AI to look for security vulnerabilities and fix them, or look for security vulnerabilities and exploit them. If cyberattacks by and large have just happened faster and faster, what do you think happens next?

Christopher Ahlberg

If I start there, just because that’s closest to home, for now, the AI stuff you’re really seeing is really only better phishing emails and so on. Even there, there’s a reason most cyberattacks happened in English-speaking countries for a long time: writing phishing emails was easiest to do in English. Now you can do that in all kinds of different languages, and you can do more targeted stuff.

People are going to start writing software that, once it gets in, traverses through systems automatically. For sure, people are working on that, whether those are slow-moving things that try not to be detected or the sort of stuff where they don’t really care and just run through the system. That’s going to happen, and it’s going to set the bar for defenders to try to build things. You’re not going to be able to counter that with just humans. You’re going to have to use AI—or some version of automated analysis, but we can call it AI—to fight against that, for sure.

Lukas Biewald

And who wins that?

10. Election interference, phishing, and AI-powered cyberattacks

Christopher Ahlberg

Yeah. There’s a guy, Rob Joyce, who’s a terrific man who used to run cyber defense for the US government at the NSA. Before that, he ran the hacking team there, one of the groups famously called TAO at the time. He has a great saying: “You have to know your network better than the bad guy coming at you.”

If you’re a big company, it’s freaking hard to know your network. A crawler plus some AI is going to outsmart most IT guys, even if they’ve worked there for 25 years. So there you have that. I don’t think it’s certain who wins that.

For sure, in disinformation, to your point, I’d like to think that we should be able to write—so, in Recorded Future, when you get text and images and all this stuff, we try to classify it and say, “The set of information you’re looking at here is very likely machine-generated,” and identify that it was machine-generated with these models, that sort of stuff, to help the researcher.

Now, when that can be in our operational system—whether I’m on TikTok or in my email or whatever—to say that… But maybe, on the other hand, maybe 75% of what I’m going to deal with in the future is going to be machine-generated.

So maybe that's not enough. It's like the world—the future of it—is maybe machine-generated. So I think that's sort of interesting.

Then you have the actual warfare stuff, where what's going to happen is that I'm going to paint a square and say, “In this 10-by-10k-kilometer area, there are going to be drones hanging over that stuff with guns and grenades. What you pick—anything that moves in there is dead.” That sort of stuff. People are working on that right now, and that's going to change the nature of warfare in a brutal way.

So, no, there'll be all kinds of nasty stuff in front of us.

11. Signal vs. Telegram and why bad actors flock to Telegram

Lukas Biewald

Sorry to sound doom and gloom here, but in that vein, I guess—and maybe this is even a practical question—what does it mean that the dark web is moving from forums to Telegram?

I mean, I'm vaguely aware of Telegram as an alternative to Signal. I've watched many, maybe most, of my CEO friends gradually move to Signal over the last year or two, to the point where I feel like I'm using it quite a bit more than I expected to. Are Telegram and Signal equivalent? Why shouldn't us CEOs be using the same network that the criminals are using? Wouldn't that be the most secure?

Christopher Ahlberg

So, first of all, use Signal. Good choice. Make good choices, Lukas.

Lukas Biewald

All right. Yeah, I'm using Signal, just so you know.

Christopher Ahlberg

Signal is great. Signal publishes its source code. You could argue this is something I have still yet to really figure out, but there's no real server to attack in Signal. There are lots of really good things about it, and all the fancy spies of the world in all the good countries use Signal.

So the fact that they've gotten uncomfortable now might mean that they have a big cabal where they all share it all or, you know, look at your emails. But no, I've seen plenty of very smart people use Signal. I'm a huge Signal fan. It's great.

Telegram, on the other hand—the guy I'm not going to remember his name now, but a very cool entrepreneur in many ways—built VK first, sort of the Russian Facebook. He was forced to sell that because the Russian government did not appreciate that he had built it. They forced him to sell it to an oligarch in Russia. He then started Telegram and moved to Dubai to be able to run it separately, and built a messaging platform that, unlike Signal, has a centralized place to be. It has encryption that is not the same as the end-to-end encryption of Signal and others. Some of this is way above my pay grade, but there's a whole set of reasons why Telegram is not as good. It is interesting from this sort of—and in this it's dangerous to say good and evil—but many of the people that we don't necessarily love are on Telegram. So that means there's a lot of data to be picked up on Telegram. The signal-to-noise ratio ends up being good, especially because the criminals are on there, whether it's cybercriminals or people in trafficking, and all kinds of interesting stuff are there. It's turned into a very good information source.

Lukas Biewald

Is there something about Telegram's feature set that makes it better for criminals? If any criminals are listening to this podcast, do you think they'd be convinced to switch over from Telegram to Signal? I mean, surely they wouldn't watch it.

Christopher Ahlberg

I think it's a social thing, and it also turns out that Telegram is obviously very popular in the Russian sort of world. So it's popular in Ukraine as well. I'm not by any means saying that all Telegram users are bad. It just happens to be that a certain class of criminals ends up being concentrated on Telegram.

Lukas Biewald

Okay. Interesting stuff. All right. Well, rolling forward into the—

Christopher Ahlberg

There are some people who'd be very mad at me for saying this stuff, but—

Lukas Biewald

Wait, why? For what part of that would they be mad?

Christopher Ahlberg

Once you sort of say that one platform is more criminal than the other, you know, like—

Lukas Biewald

Well, we can edit it out if you want, but—

Christopher Ahlberg

No, no, it's all good.

Lukas Biewald

All right. People have been mad at me for many things, so it's all good. Actually, another question that comes to mind for me is that, at my very low level of celebrity, every month or two I get someone reaching out on LinkedIn saying, “I'm going to come kill you,” or something.

But you must get these kinds of threats all the time. Do you worry about your family's safety, being so involved in this world? Do you walk around with a bodyguard? You must be constantly concerned about getting hacked. How do you think about that?

Christopher Ahlberg

Do I look afraid?

Lukas Biewald

You don't look afraid. Is that for cause or for hubris, I guess?

Christopher Ahlberg

No, I'm not afraid. That's sort of how you choose to be when you get involved in this, and no bodyguards unless it's needed is sort of one way of thinking about it. One should be cautious.

12. Russian threats and personal safety concerns

Russia deemed us—whatever they call it—an undesirable organization. Just before Christmas, there was a verdict, if you want, from the Prosecutor General of the Russian Federation, which put out a statement explaining why Recorded Future is an undesirable organization. It wasn't random language; it was very specific, so that was less great, if you want.

Lukas Biewald

That sounds bad, man. I mean, don't people that are undesirable according to Russia get thrown out of windows and stuff? I'm not super up on this, but I can assure you I'm not traveling to Russia anytime soon.

Christopher Ahlberg

Sure, that seems to be off the table. No, look, I think we're very, very careful with information security here. We run a good physical security program here as well. We try to be very careful and thoughtful about how we travel and what we do, and to be thoughtful about things.

At the same time, one should not overestimate where you are on the list of problems that the bad guys have. Whether it's the Chinese government or the Russian government, they have a lot to deal with, and I don't think we're at the top of that list. I don't want to simplify it, but information security—we've got to be on our A-game.

Lukas Biewald

All right, well, let's wrap this up and come back to the here and now. A couple of months ago, you announced that you were getting acquired by Mastercard for $2.65 billion. It's got to be one of the biggest acquisitions of the last year. Could you talk about what the thesis was, how that came about, and what your plans are going forward?

Christopher Ahlberg

Yeah. We had a long discussion with them—multiyear discussions that had been going on. The simple thesis is that, while it may not be as well known, they run a great payments business. Of course, they have a services business that actually includes pretty nice assets on the cyber and intelligence side. They wanted to expand on this, and we could be a nice fit into that.

The financial intelligence side is super interesting, especially as we talked about cybercriminals and so on. The financial endpoint to things is interesting. If we get our hands on a stolen credit card, it would be awfully interesting to know whether that card has been used or not. Whether cards have been used or not actually tells you a whole lot about the whole supply chain of where those cards came from, just to have one random example.

So there are a lot of those sorts of things. We're going to be building out our business. We're continuing to operate on our own as a standalone business. There's a lot of cool synergy that we can create together.

It was also one of those situations where it just felt like a really good home for the company. They have great people and a long-term-value mindset, which was important to me. Because, to your point, for both you and me, who have built companies for a long time, you want to make sure they end up in places that aren't just going to be fly-by-night types of operations, but with people who are serious and want to do things over the long term.

So there are any number of reasons that stacked up to make this a great place to take it.

Lukas Biewald

Any advice for me for success post-acquisition?

Christopher Ahlberg

I think you have to keep executing very well. It's sort of like you have to keep at your A-game. We're early into it, but build good friendships and good relationships with people, because this stuff is not easy.

As you know, it's easy to come up with a lot of clever thoughts on paper, but when you're going to make it happen, it's with people. So make sure you have good relationships with those people.

I think that's it. Don't just think it happens automatically. Unfortunately, I guess, it continues to be hard work. It's sort of unavoidable.

Lukas Biewald

Awesome. Thank you, Christopher. It was a real pleasure to talk to you. Thanks for taking the time.

Christopher Ahlberg

This was great.

Lukas Biewald

This was great. Thank you.

Inside the Dark Web, AI and Cybersecurity with Christopher Ahlberg CEO of Recorded Future | BidClub