Software That Never Breaks: OutSystems CEO Woodson on Building Enterprise-Grade Apps at AI Speed
OutSystems’ AI thesis is that faster code generation only matters if enterprises can preserve the promise that software “never breaks.” Coding agents work against an abstract model of application intent, after which the platform deterministically generates software with security, role-based access, reuse, and governance built in. For investors, the proposed moat is not merely superior generation—it is 25 years of primitives and customer trust that AI-native startups cannot reproduce quickly.
AI has already produced a step-change in OutSystems’ development velocity: four major features in Q4 became 19 in Q1 and 26 in Q2. Token spending peaked in June and July, then declined after the company introduced internal tooling and an LLM gateway that routes work away from frontier models such as Opus 4 when cheaper models suffice. Martin also says some tasks are better handled by deterministic code. His conclusion is that enterprises can return to using “AI in everything,” but only if they do it intelligently.
Enterprise AI adoption is being constrained less by model capability than by governance, liability, and organizational “ossification.” Martin sees completed agent systems sitting in compliance queues while companies investigate model-training provenance, data permissions, and auditability—even when the task is merely extracting structured data from PDFs. The constraint is rational in lending and other high-stakes regulated decisions, but partly “old-fashioned conservatism” elsewhere.
AI is turning legacy modernization from a six-year proposition into a six-month one, potentially unlocking a backlog that enterprises previously refused even to contemplate. AI can help interpret COBOL, AS/400, and Lotus Notes systems, rewrite requirements, build replacements, test them, and support deployment. Simpler work is becoming self-service—“Hey, Claude, take this spreadsheet, make me a dashboard”—creating a second opportunity around standardizing the resulting sprawl.
The most important enterprise-agent question is still not how to build, but “what exactly to do.” OutSystems’ new “agent factory” analyzes application telemetry, architecture, and data flows to propose which manual workflows should become agentic, estimate time savings and ROI, and generate an initial implementation. That shifts the platform’s value proposition from development acceleration toward capital allocation and workflow redesign.
Martin expects software interfaces to fragment rather than collapse into a universal chatbot. Conversational agents may invoke small, contextual interface elements, but maps, regulated bank workflows, and other visual or privacy-sensitive experiences will still need purpose-built software. His example is a $30,000 pre-approved loan initiated in a Claude conversation and continued seamlessly inside a bank app, with one agent spanning both contexts.
As every software vendor accumulates the same AI primitives, competitive advantage should migrate toward specialization and execution inside particular industries. Martin calls the current market an “ocean of the same,” where Highway 101 billboards contain the same five words under different logos. OutSystems intends to differentiate through regulated-industry capabilities, model and cost optimization, and expertise in banking, insurance, government, healthcare, transportation, logistics, energy, and utilities.
1. OutSystems’ original promise has become more valuable in the AI era
Woodson Martin traces the company back to Paulo Rosado’s 2001 frustration with enterprise projects that ran years late, exceeded budgets, and produced rigid systems requiring another major project whenever the business changed. Rosado’s answer was deceptively simple: “build faster, reliably every time,” then evolve software at business speed without breaking it.
Martin argues that generative AI strengthens rather than supersedes that founding premise. When agents can produce vastly more software, enterprises inherit vastly more systems to secure, operate, and change; consequently, the “never breaks” requirement becomes more—not less—important.
The leadership fit combined continuity with scale experience. After 18 years at Salesforce across European marketing, the core sales product, and HR leadership, Martin believed he knew “ways we could turn on the afterburner,” while preserving the platform foundations and unusually strong customer attachment that drew him to OutSystems 16 months earlier.
2. Enterprise-grade AI begins beneath the generated code
OutSystems takes a different route from conventional AI coding tools: agents manipulate an intermediate abstraction of application intent rather than directly editing the eventual code. The platform then generates the asset deterministically, carrying forward role-based access control, security requirements, reusable components, and existing enterprise controls.
Martin’s concrete test is whether a company must recreate GDPR- or HIPAA-compliant controls for every new application. His preferred model is to “take what works, add the necessary features,” and move into production knowing that every generated asset inherits the organization’s established controls.
The platform’s range is illustrated by two sharply different workloads: Asian banking apps used for balances and bill payment, and a Rotterdam oil-terminal system that prevents diesel from entering pipes previously carrying kerosene. The latter coordinates pumping, quality control, cleaning, and flushing around products worth millions of euros.
Labenz’s pushback—worth keeping—is that fast-growing model providers have shown enterprises will tolerate weaker conventional uptime when a product has enough “flavour.” Martin’s answer is that critical autonomous workloads remain different: availability matters, but so do privacy, contractual obligations, data lineage, model permissions, and provable control over every step of a six-system workflow.
3. Compliance queues reflect both legitimate risk and institutional inertia
Martin sees sophisticated agent systems waiting for approval to use a particular model while compliance teams ask whether its training data was legally obtained. Even PDF-to-structured-data systems can stall because enterprise readiness now includes model provenance alongside the familiar requirements of security, availability, and governance.
His distinction is workload-specific. Automating internal IT-resource allocation carries a different risk from making lending decisions that regulators may challenge; the latter requires a defensible record of “what and how was decided at each stage.” Slowness therefore combines prudent due diligence with organizational “ossification” and “old-fashioned conservatism.”
Labenz asks whether model-provider indemnities or AI insurance can unblock adoption. Martin has spoken with agent-insurance entrepreneurs and thinks insurance “could potentially be a breakthrough,” but OutSystems is not yet seeing meaningful customer demand: for regulated enterprises, insurance itself remains another immature, untested dependency.
Labenz emphasizes that trust is not merely a technical scorecard: a regulated European enterprise also weighs privacy, contractual obligations, regulatory scrutiny, and the vendor’s history of delivering robust systems. Martin agrees that this accumulated reputation is “very hard for a startup to get.”
4. Security and token costs both reward consolidated infrastructure
On cyber risk, Martin rejects the idea of an endpoint: “There is no finish line when it comes to security and cyber threats.” Better technology strengthens both attackers and defenders, while large companies still operate 60-year-old COBOL systems alongside AS/400 and Lotus Notes estates.
A consolidated portfolio built from common components can remediate one vulnerability once and propagate the fix broadly. The alternative—hundreds of AI-generated systems built on unrelated frameworks, stacks, and open-source packages—makes it difficult even to locate exposure, much less eliminate it quickly.
OutSystems is adding security resources, using powerful AI for penetration testing, and automating more testing inside build, test, and deployment workflows. Martin expects defensive model usage and white-hat hacking to remain a permanent source of token consumption rather than a temporary tax that disappears after an 18-month cleanup.
Token expenditure peaked in June and July after an internal push to “translate everything into AI.” The spending produced measurable output—major feature releases rose from four in Q4 to 19 in Q1 and 26 in Q2—but also taught OutSystems that many tasks could be performed far more cheaply.
5. Model routing—not universal frontier-model use—drives enterprise economics
OutSystems built internal engineering tooling loaded with company context plus an LLM gateway that routes tasks by need. “Not all tasks should go to, say, Opus 4”; those optimizations brought third-quarter spending below forecast without surrendering the development acceleration.
Martin’s strongest cost claim is that almost no ordinary business-operation workload needs an advanced model. He distinguishes those tasks from creating new software products; many of the former are “actually quite boring” and can run on deterministic code, open-weight models, or base models already three years old.
Geographic attitudes complicate the model portfolio. Some clients use Chinese models, launch their own versions, distill models, or retrain them for cost reasons, while attitudes differ substantially across Europe and Asia; “not everyone is thrilled about trusting their data to American companies.”
Mentor hides much of this optimization. Users can work through the OutSystems IDE or access its MCP services from a coding agent of their choice, while backend model selection and platform-specific tuning reduce the workload imposed on whichever external model sits on top.
6. AI is clearing old backlogs while creating a new governance layer
Legacy systems that organizations were afraid even to place in the backlog are becoming tractable because AI accelerates each stage: understanding old behavior, translating it into modern requirements, turning manual work into agent work, building the replacement, testing it, and deploying it. Martin cites insurers reframing a six-year modernization as a six-month project.
At the other end of complexity, employees no longer wait in a development queue for dashboards and similar tools. They can ask Claude to turn a spreadsheet into one immediately; the tradeoff is proliferating applications that lack shared definitions, integrations, and role-based access standards.
The resulting opportunity is not simply faster development but structured cleanup. Self-service experiments reveal what users actually need because they “kept talking to Claude until they got the result”; a platform can then rebuild those observed needs around common data and security foundations.
Martin offers Axos Bank and YESCO as early productivity examples, while refusing to claim their financial outcomes. Axos is accelerating digital capabilities used to compete for deposits, customers, and lending; YESCO says higher productivity lets it accept business that its prior resource base could not serve. The hedge remains important: productivity takes time to reach financial statements, and “not all investments people make will pay off.”
7. The agent factory tackles the harder problem of choosing what to build
Mentor began in 2018, before generative AI, as an effort to apply machine learning throughout the development lifecycle. Its implementation has changed dramatically, but Martin says the enduring strategic problem is still deciding “what exactly should I create” to solve a real business problem.
OutSystems’ new agent factory uses telemetry, application structure, and data flows from portfolios containing thousands of applications. It identifies manual work that might become automated, estimates ROI through time savings and related measures, and offers a button that lets AI create the first version for normal development, testing, validation, and trials.
Labenz questions whether aggressive experimentation wastes effort when the next model generation may make today’s difficult engineering trivial—he cites later models described as “55 or Astra” potentially recreating earlier work in 10% of the time. Martin’s answer is to concentrate experimentation where workflow transformation offers the greatest expected return, rather than treating technical novelty as the objective.
8. Interfaces will atomize, while competitive advantage moves upward
Martin still expects to have more than 100 phone apps in a year because conversation is not ideal for every task. Google Maps could join an AI dialogue, but users may still benefit from seeing spatial structure and what they will encounter along the way; privacy, compliance, and preference likewise preserve multiple interaction models.
What may change is the monolithic portal containing 80 features. Capabilities could become widgets delivered exactly when needed, as in OutSystems’ demonstration of a home-renovation conversation with Claude surfacing a $30,000 loan pre-approval and handing the customer into a bank app without restarting the process or requesting documents the bank already holds.
Labenz’s competitive concern is that vendors are expanding into every adjacent niche until each becomes a horizontal “everything” platform. Martin agrees that the market currently resembles an “ocean of the same,” but expects shared primitives at the bottom and specialization at the top—in customization, distillation, model economics, industries, and workflows.
For OutSystems, specialization includes regulated-industry knowledge and what Martin calls roughly “37 features” beyond the basic checklist that determine whether a first solution can actually be deployed. Martin is also bullish on young professionals who have grown up with these technologies, while noting that companies must pair their fresh perspective with industry knowledge. OutSystems is leaning toward a full-time-employee model and asks whether each task belongs to a person, an agent, a team, or a combination; it is also replacing the traditional few-day-or-week introductory course with more timely, just-in-time onboarding.
Full transcript
1. OutSystems leadership transition
Hello, welcome back to the “Cognitive Revolution.” Today my guest is Woodson Martin, CEO of OutSystems, a leading enterprise software development platform that has helped many of the world's largest companies build and run complex, mission-critical applications since its founding in 2001, and now specializes in helping those same giants develop, orchestrate, and manage agent-based systems. Woodson succeeded OutSystems' legendary founding director, Paulo Rosado, in 2025. So, we start with his thoughts on leadership changes in the AI era, including how he assessed a company's readiness for AI and what it looked for in a new leader. We then discuss what makes a software platform “enterprise-grade” in today’s world, with Woodson emphasizing the importance of human trust built over years, as well as the crucial role of well-designed software abstractions that allow coding agents to accelerate the development process while maintaining the company’s core promise—software that never breaks. For OutSystems customers, including Petrobras, the Brazilian state-owned energy company; Vodafone, one of the world's largest mobile operators; and Toyota, the world's largest automaker, and many others, this new paradigm is allowing product plans to accelerate so much that some are actually starting to clear what were previously ever-growing development queues. Woodson says that most of what their customers are releasing today are still traditional deterministic applications that don't really require advanced AI. But internally at OutSystems, they went from four major feature releases in Q4 to 19 in Q1 and 26 in Q2. Meanwhile, they are rapidly “agentifying” their own business, implementing important initiatives, including an app development assistant for customers, which they call “Mentor.” Investments in internal AI infrastructure, which included a new system and dedicated gateway, have allowed them to reduce token spending from its peak in June and July to levels below their projections today. And also a new “agent factory” that they use to propose new agent systems to clients and predict the corresponding return on investment (ROI). Finally, we get Woodson's strategic analysis of the future of the software industry, including how competition will shape up as platforms expand to serve many related niches, what companies should do to differentiate themselves when everyone starts doing everything, and why he's so bullish on young AI talent. It is often said by outsiders that despite all the amazing things AI is capable of, we still don't see a tangible impact on productivity or global GDP growth. But I think you'll agree, hearing Woodson's perspective from the helm of a platform that serves many of the world's most influential and often conservative companies, that change is indeed in full swing. With that, I hope you enjoyed my conversation with Woodson Martin, CEO of OutSystems. Woodson Martin, CEO of OutSystems, welcome to Cognitive Revolution.
Thank you, Nathan. Exciting times. Glad to be here.
Yes, that's right. In the field of AI, it's never boring.
2. Sponsors: OutSystems | Tasklet
I would like to start with a somewhat sociological question. While preparing for the interview, I learned that you took over OutSystems after a legendary founding CEO who had run the business for 24 years. I think about how interesting this is as a leadership change at a software company—to be in your shoes, leading a company that is looking for a new leader.
3. Episode Outro
All of this is always challenging, but with AI comes another dimension: At what stage of its journey is the company? Where is this leader in terms of vision? Who understands the situation, and who doesn't? So I'd like to hear the story of how you came to this decision and how you understood each other well enough to know that this would be a good choice for the AI era.
Yes, great. I'll start with Paulo Rosada, who we're talking about here. Paulo is an incredible person. He founded OutSystems with a bold vision back in 2001, and this vision remains relevant.
The idea was to create specialized enterprise software. People are building very complex systems—ERP systems, terminal management systems, and global financial consolidation for reinsurance companies—based on the OutSystems platform. But those projects back then—software development projects—were always delayed for years, over budget, completely unpredictable, and resulted in very rigid software that, when you wanted to change it, required another huge project.
Paulo thought, “This is crazy. There must be a better way.” His vision was simple: build faster, reliably every time, and evolve software at the pace of the business without breaking anything. That's still the foundation of what OutSystems does today.
Of course, now we build all of this with AI agents doing most of the work, right? But the result is that corporate AI just works, every time, always. It's amazing how enduring his original vision and the platform foundations he laid have proven to be.
That's what inspired and captivated me about OutSystems 16 months ago, when I joined. I realized how powerful these foundational platform elements created by the company are, allowing even less experienced users and developers to create complex enterprise systems and quickly change them without the risk of breaking anything.
It was revolutionary then, but it's needed even more now. When AI can build everything for us, the pace of our development and the sheer volume of systems we manage make the “never breaks” feature even more important. That's what inspired me about OutSystems as a business and as an opportunity.
And then there was getting to know the clients. There is this fascination with the platform because of what it has made possible for so many people and companies. People just love this product, and you always want to be in a situation where your customers and users love your technology. That was also an important part of this experience for me.
I also saw that I already knew how to solve some problems that the company had not yet solved. I came here after 18 years at Salesforce. I held many positions there, from head of marketing in Europe to product manager of our main sales platform, and for a while I headed the company's HR department.
Through this experience, I learned a lot about scaling a business. I thought I knew a lot of ways we could turn on the afterburner and grow this company. This is extremely exciting.
It was amazing to hear your description of the original vision. I thought this all fit very well with where we are now in the AI era.
4. Software that never breaks
Yes, except, perhaps, for the “never breaks” principle, right? After all, we all—I would say at least most of us—live in a world where AI does a lot of things for us. The volume of results has grown incredibly, and I'm interested to hear some metrics on what this looks like at OutSystems.
But we also see things breaking quite often. How do you maintain the value of the “never breaks” principle in the vibe-coding era we are currently in?
Yes, we're using a completely different approach to AI for software development here than most solutions on the market today. That's because the OutSystems platform has an intermediate layer—an abstraction of the intent of the application that you build using AI.
You can use Cloud Code, our built-in AI assistant Mentor, build with Codex, or engage any other agent to code. Instead of manipulating code on our platform, they work with this abstract model of what you need.
Then, when you click a button or ask the Cloud to do it, we deterministically generate code that ultimately creates an asset that meets all your security requirements. Role-based access control and all of these things are built into the platform, so every software asset created in OutSystems is 100% compliant with that.
5. Optimizing token spend
By the way, it automatically reuses what you've already done. I can start developing with AI, open Claude, and say, “Hey, just write me an app.” It will actually start everything from scratch.
In a complex corporation where I already have secure systems in place that meet my GDPR or HIPAA compliance requirements, depending on the type of business, I don't want to constantly reinvent the wheel and go through the compliance cycle again. I want to take what works, add the necessary features, and bring it to production in a way that makes sure everything works the first time.
This is precisely the “secret ingredient” of OutSystems. When you build a new system on OutSystems, you inherit every element of your corporate control plane in every generated software asset. It's a completely different story compared to any other tools that people use today to create AI-based technologies.
Yes, in general, I often see this pattern: The market leader with well-developed foundational components stays ahead. At first, it seems like, “Here are these AI-native startups that can come and take over the market,” but more often than not, having such deeply developed primitives makes it easier to layer an AI layer on top of them, so you can get the most out of them and reconfigure them however you want.
These fundamentals are very important, and it's extremely difficult to create such basic elements that work at enterprise scale, as OutSystems did. And it's not only about that. Software is one thing. The other thing is trust.
For example, if you're a regulated enterprise operating somewhere in Europe, and hundreds of regulators are scrutinizing your activities, you have contractual obligations to various customers and partners, and privacy concerns at every turn, the trust you have in any system is not just a purely technical assessment of its fundamentals, right?
It's actually about the entire history of supplying systems like the one you need on this platform. There are many other companies you can ask about whether you can trust them, what works, what doesn't, and so on.
So the reputation that you build over time for that kind of trust, for these kinds of robust systems in regulated industries, is something that's very hard for a startup to get, no matter how cool your technology is.
6. What enterprise ready means
Yes, but it's really interesting. Maybe that's the answer to another question I wanted to ask you about what it means to be enterprise-ready in today's world. Of course, everyone claims this—both well-known companies and startups. But I thought it used to mean high uptime, reliability, and things like that.
Now I look at the world and see that the fastest-growing companies, like Anthropic or OpenAI, don't really have a very high uptime rate by conventional standards, do they? So it seems they've proven that if you have a “flavor,” businesses can actually be a little more lenient on some of these requirements that used to seem sacrosanct.
How do you look at this, and what do you think is really needed today to be considered ready to work with businesses?
Yeah, okay, there's a lot going on here, and it's not easy. The reality is that every enterprise is a little different, and what they need is different. The requirements for different workloads are not always the same.
Of course, in many regulated businesses, people have AI assistants doing the work. Today, there are few regulated enterprises that have released autonomous agents to perform critical tasks, and this is partly a matter of industry maturity. There are things like SRE, site reliability engineering, whether the model is always available and able to respond, uptime, and so on.
But in most of these organizations, it's much more than that. I have clients who are already well advanced, and I think, by the way, that's true for a lot of technology providers. Customers who are already at an advanced stage of developing an agent system that they have designed and tested and are very proud of are now forced to keep it in a compliance review queue somewhere in their organization, waiting for approval to use a specific AI model for this job.
The obstacles that arise along the way boil down to questions like: We need to understand whether all the data used to train this model was legally obtained by the person or organization that conducted this training. There are a number of requirements in place in many such organizations that make it extremely challenging to trust a workload to an autonomous agent.
This is despite the fact that some of them simply read data from PDF documents and convert it into structured data. Yet concerns about compliance are slowing progress.
So I think enterprise readiness means a lot of things, right? Of course, this means that systems should work when you need them to. But it also means that they have to meet a fairly broad set of nonfunctional requirements—not just whether everything works when you press a button or issue a command, but whether it helps us meet all of our regulatory requirements, contractual obligations, and so on.
The concept of enterprise readiness in today's market encompasses a lot, and much of it has not changed with the advent of AI. Something has changed, though: this question of the provenance of the model is relatively new. But much else remains the same.
For example, how do I know exactly how every bit of personal data is processed in this complex workflow spanning 6 systems to launch it into a production environment? That's where governance, as well as a security model, comes in.
How do I make sure that the model runs with access to only the relevant data, that it doesn't consume anything unnecessary? All of these are basic foundational capabilities that a platform needs to be ready for enterprise AI.
Regarding the applications that are already built and are in this compliance queue that you mentioned—you can elaborate on that—do you think this is just prudent risk management, or is it still a management error that they are not accelerating some of these processes in order to implement the transformation that I think everyone recognizes is inevitable?
It is definitely a combination of both factors. The processes of “ossification” in organizations are very real for large enterprises, and it is something that organizations need to overcome and change in order to move forward.
But much of this also has a very real basis. In many areas, regulatory constraints are significant, liability risks are high, and reputational risks are also high. So in many ways, it is a matter of informed decision-making.
The reality is that organizations take on different risks in different parts of the business for different types of workflows, right? There is one level of risk I will take, for example, managing the allocation of IT resources for company employees. Banks need it, insurance companies need it, and regulated businesses of all kinds need these kinds of things.
They risk more than perhaps in the lending process, where they make decisions that can be challenged by regulators. They need to prove what was decided and how it was decided at each stage, since all of this is subject to audit. Therefore, they need to make sure they have everything they need to defend themselves if they have to defend any decision they make.
So I think it's a combination of due diligence and just old-fashioned conservatism.
7. Balancing flexibility and security (Part 2)
What do you think about compensation from major model companies? Does this change things for people? What about the role of insurance in some of these issues? I previously did an episode with AIUC, a company that does underwriting in the AI space. They are developing standards and trying to stimulate the insurance market to hopefully simplify this process.
I've talked to a few entrepreneurs who work in this area. They offer AI agent insurance services. We don't really see a significant demand for this among our customers with the workloads they run on our platform.
So I think it's a very interesting idea. I think this could potentially be a breakthrough. But for many such organizations, it is also another untested thing, and the market needs to mature before regulated industries, which often operate on our platform, can get involved.
8. Managing cybersecurity risks (Part 2)
One of the apparently huge risks that everyone faces today is the risk of cyberattack. How do you deal with this? Obviously, you have a codebase that has been around for many years. A lot of people say we should move everything to Rust. We have to completely rewrite everything from scratch. We must ensure memory safety. We must have all these things. Otherwise, we are simply too vulnerable. How much investment do you plan to make in this?
We are investing a lot, and of course, we are focused on 2 things. We have our own platform, our own infrastructure, and the financial and business operations that we take care of. But there are thousands of other systems created by our customers, and we assess the risks in this area.
In both cases, we primarily think about the speed of threat remediation, right? The speed of cyber threats is increasing, as is the pace at which everyone must respond. We need to be able to react and update our own systems. We need customers to be able to respond and update their systems.
Let's consider 2 worlds. Imagine a world where there is a consolidated portfolio running on a platform with many common components.
In this context, it is much easier to ensure the speed of threat remediation than in the opposite case, where you have hundreds of AI-powered systems, each on its own frameworks and stacks, using different open-source components, and so on. You think, “Okay, now there is a vulnerability. How do I even know where it is, let alone how to eliminate it?”
The platform approach has a significant advantage over the chaotic world where AI creates everything at once. This is one area where we see the advantage of a platform like ours in quickly eliminating threats for our clients. Well-designed systems with multiple uses of common components allow you to fix a problem once in a specific place and have a broad effect everywhere.
This is exactly what we think about when we consider this issue. Are we improving our work? Certainly. Are we adding resources? Are we engaging the world’s most powerful AI to conduct penetration tests for our own systems? Do we encourage our customers to do the same? Do we automate a significant portion of this testing within the build, test, and deployment process on our platform so that customers have to think about it less? Yes, all of these things are important investments for us, given the increasingly risky cyber environment.
Do you think this will become a kind of permanent tax on the software industry that leading companies will collect forever as they constantly create new cyber risks that only they can solve? Or do you see another alternative: we fix all the mistakes and end up in a “happy place” in about 18 months or something?
There is no finish line when it comes to security and cyber threats, right? As technology evolves and becomes better at everything, it also becomes more effective at cyberattacks, and the world today is full of outdated technology.
Look at the big enterprises. We have a lot of customers who still have 60-year-old COBOL systems in the corner, or AS/400, Lotus Notes, and all of those things. There are so many of these systems that the idea that at some point we’ll reach stasis and everything will be perfect and safe—I think that’s an impossible dream.
So no, I don’t think we’ll ever reach a point where there are no threats at all. Will the companies that develop models that simultaneously fuel vulnerability research and penetration-testing technologies also benefit from using these models for protection, including white-hat hacking and everything else? Yes, definitely. Obviously, this is driving significant token consumption today, and it will probably continue to be like this. It’s hard to imagine why it would be otherwise.
How has your token spending changed? How much are you willing to share in detail, and how do you view it? I often ask people what their token-spending-to-payroll ratio is as one way to control that.
I can say one thing: for us, the peak was in June and July. Then it went into decline, and part of that was due to training and, frankly, focusing on it.
9. Managing cybersecurity risks (Part 1)
For example, last year at this time, our main task was, “Hey, translate everything into AI. Use models for everything.” This created a huge amount of new knowledge. We learned a lot. Secondly, it provided a huge acceleration in terms of delivering capabilities.
Think about software development. A big part of our job is releasing software products. We released 4 major features in Q4 last year, 19 in Q1, and 26 in Q2 this year. We had a huge leap, and it’s not a small thing. These are significant new opportunities that have resulted from a dramatic acceleration thanks to investments in AI.
We saw this in token consumption, but the result justified the cost. So that was great. But one of the things we learned was that most of the things we were doing could be done just as well, but much more cheaply, with better tools.
We created one for our own engineering organization, which is, of course, filled with our context and optimized for us. We built a gateway—an LLM router. We realized that not all tasks should go to, say, Opus 4 or something like that, and we could redirect them to cheaper models for specific tasks.
We’ve noticed that we are now spending less than we had forecast in the third quarter, largely due to the optimizations we have implemented. I think the reality for most organizations today is that they don’t need advanced models for enterprise workloads.
Almost no corporate tasks—by which I mean real business operations, not necessarily the creation of new software products—require them. For most of these tasks, you can use models that are already 3 years old.
If you look closely, most of the enterprise tasks where AI can make a real breakthrough today are actually quite boring. A significant portion of them can be done more cheaply with deterministic code than with a model, or with a cheaper model—either with open weights or simply an early version of one of the base models.
This, I think, is the key conclusion for us. We see this in our own work, and we see it in our clients. That’s why it’s important to build your workflows this way. Build your agent systems on a platform that allows you to change models very easily to get the best out of what’s on the market—maybe because the capabilities are improving, or maybe simply because another model would be cheaper.
I believe we will definitely see most enterprise tasks being performed at a much lower cost per token than what advanced models offer today. On the frontier, prices are being lowered, too. I think that’s another thing that’s happening right now.
We’re facing a lot of changes. I don’t think we were on a consistent trajectory in the first half of this year, were we? Every CFO received a token bill in February and March, and for the world, it was a moment of truth.
Everyone started implementing control measures, whatever they were: limiting token spending for each person, implementing a router that allows you to direct tasks to cheaper models, and abandoning the “AI above all else” strategy everywhere and all at once. We’ve seen this in some companies. We’ve seen loud statements about this.
I think Microsoft, Meta, and Uber—all of these companies—said, “Wow, maybe we went too far too fast.” But I think we can get back to a point where you really use AI in everything. You just have to do it wisely, right? That’s why you need platforms that will help you make this happen. This is exactly the work that our systems do for our customers.
Let’s look at this in a little more detail. I’d be very interested to know how you advise clients on their model set and what you think it should be. I assume that developers still immediately switch to Opus 5.5 when coding, but maybe not.
I understand that if you’re trying to convert a PDF to structured data, it can certainly be done more cheaply. Do you recommend even resorting to fine-tuning for some of these cases to really tune performance and cost? What about Chinese models? How do people react to—I personally don’t find it scary, but sometimes it is scary—the prospect of using Chinese AI in their business?
I don’t know if I have any unique views on the issue of Chinese models. I would say that we definitely have clients who are quite ready for this. They either launch their own versions, distill them, or retrain them after training. This definitely happens, and it is usually due to cost-effectiveness considerations.
Although I would also say that we have a very global business, right? Half of my clients are in Europe, and I have a lot of clients in Asia. Attitudes toward this issue vary greatly in different parts of the world. Not everyone is thrilled about trusting their data to American companies.
When you travel the world, you see a huge variety of models being used in the agent systems that customers build on our platform. We also did a huge amount of customization work ourselves.
Today, we offer a service for creating applications and agent systems on our platform. We have a service we call Mentor for this. Mentor offers a custom agent experience for you as a user. You can go to our site, use our IDE, and use Mentor directly there, but you can also manage it through MCP services, using any coding agent or tool of your choice.
What we did, of course, was select and configure a number of models on the backend to ensure that these developer workloads were executed efficiently on our platform. When you use an advanced model on top of these MCP services, or even an older version, you benefit from a whole host of hidden optimizations and a much lighter workload for your tool or its models to deliver the desired result on our platform.
Frankly, there are a lot of answers here about optimization at different levels of the stack. I think one of the things we do for our customers is simplify all of that. We’ve done the hard work of optimizing to give you what you need to quickly build, maintain, and manage complex AI systems, making it easy, affordable, and reliable for you, simplifying the world. So, this is a big part of the value proposition of the OutSystems platform.
What did you learn about balance? I used Mentor on the site, so I have an idea of that experience. On the one hand, it seems like the platform is designed to support anything, or almost anything, right? You have clients who want to connect to a variety of data sources—anything, right? I’m sure there’s no end to this.
But on the other hand, you also have these limitations and promises about security. It seems like that would be a real challenge: allowing any user to create anything while ensuring that everything created on the platform is secure to the standards that your end customer requires in their company. So how do you find that balance?
Well, the thing is, this is not a new balance for us. This has been the history of our systems for 25 years. How do you allow a relatively unskilled technologist who may not have a degree in computer science, doesn’t really understand software architecture, isn’t a database expert, and doesn’t have a deep understanding of open-source libraries to build the critical systems that a bank runs on?
This is the problem we’ve been solving for 25 years. Now we’re providing the same tools that you previously had access to through the visual editor: “Hey, let me drag these elements around the screen and add the field I need.” Of course, this all happens through communication with artificial intelligence. But under the hood, it uses the same primitives to produce a finished, reliable product.
And that takes a lot of effort, doesn’t it?
It is necessary to create a complex model under the hood that’s capable of supporting an almost unlimited number of use cases. So if you travel, or simply have a bank account, almost anywhere in Asia, chances are the app you use to manage your balance and pay bills runs on OutSystems. A multitude of frontends, mobile applications, and user interfaces are built on this platform.
If you are an oil tanker entering the port of Rotterdam and unloading millions of liters of oil into the terminal tanks for further transportation by trucks, trains, or other vessels to power Europe’s economy, the system that manages it all is built on OutSystems. It involves incredibly complex logic that ensures that when you pump diesel through a pump at the terminal, it doesn’t get into the pipe where kerosene was before.
All the quality control, the entire system for managing the cleaning and flushing process of pipes so that nothing spoils a product worth millions of euros—all of this runs on OutSystems. So, a huge number of complex backends and sophisticated frontends manage such a variety of capabilities on one platform. Yes, it was a lot of work. That’s why it took 25 years.
That’s also why we’re confident that the foundations we’ve laid serve all of these use cases and all of these highly regulated environments. They allow our customers in any industry, regulated or not, to trust the platform so they can quickly implement changes at the user-experience level and build new things that always work together. That’s the idea.
I noticed on the OutSystems website, or perhaps in an article with you, someone said that OutSystems clients have a limited budget and a very large to-do list. Does this change today? Is the to-do list getting shorter now that everyone is moving so much faster?
10. Modernizing legacy systems
Yes, the situation is changing. There’s so much going on here. Perhaps the most interesting thing for me is that projects everyone was afraid to add to the backlog—old legacy systems like COBOL, AS/400, Lotus Notes, and so on—are finally within reach. Now it’s possible thanks to AI, which accelerates work at every stage of this very complex process.
Even just understanding what these old legacy systems do, converting them into new, modernized requirements, taking the old, slow work and turning it into agent work, and then creating the new technology, testing it, and implementing it—all of that can now be significantly accelerated with AI.
We’re seeing customers take on modernization. For example, insurance companies are starting to modernize archaic, 60-year-old case-management systems and saying, “We’re finally ready to take on this project.” Instead of planning this as a 6-year endeavor, they’ll now do it in 6 months. That’s a huge change in terms of our backlog.
There’s something else going on, which is that we used to need someone’s approval to do something that’s pretty common in most businesses: “Hey, I need a new dashboard to track this new thing.” I asked someone for the dashboard, it ended up in someone’s backlog, and someone built it.
Now, in most organizations, you’re probably saying, “Hey, Claude, take this spreadsheet and make me a dashboard.” Boom—you get it yourself. So many things have become available for self-service.
A lot of companies are seeing that with so much self-service, we’re losing standardization and integration. We’re going to need to do some cleanup of these things. But the good news is that a lot of experience has already been gained.
What do people really need? They built it themselves and kept talking to Claude until they got the result. So now we can say, “Okay, how do I make sure that I’m bringing together the internals of these things so that they use our common data definitions and our common role-based access-control standards?”
This is where a platform like OutSystems is of great importance in handling a completely different type of backlog than the one that existed just a few months ago.
So how does this translate into company success and economic growth? It has become commonplace to talk about computers in general—we see AI everywhere—but where are the statistics on GDP growth? Do you feel like your clients are approaching a tipping point where they’ll start to see faster, measurable growth? And if not, why?
Yes, I think it’s a very individual story for each client. I have a few clients I can talk about. I remember a man named Kevin Hearn who runs software development at a bank called Axos Bank. They’re based in San Diego. This is a fully digital bank, and they’ve been doing this for a long time.
They see huge gains in their own productivity, and that was the original goal: significantly accelerating the provision of new capabilities for the bank so that they can better compete in the digital environment for deposits, customers, and lending. I think they’re way ahead. I’ll let them tell their own financial stories, but they have a pretty fascinating one.
I think we’ve seen other examples of companies like YESCO. I don’t know if you’ve ever been to Las Vegas and seen the “Welcome to Las Vegas” sign. They build such signs and maintain them all over the world. They’ve significantly accelerated their productivity in ways that inspire them because it means they can take on more new business opportunities than they could before with the resources they had.
I’ll have to let you talk to them about their own financial results, but they tell an optimistic story, which is very exciting for us because we can contribute to that. There’s so much potential. Everyone sees it.
It takes time for progress in an organization’s productivity to translate into financial results. That’s true for my business, and it’s true for any business. Everything doesn’t happen overnight.
I think not all investments people make will pay off. There’s a lot of experimentation here because a lot of these things are new. But I think everyone is pretty convinced that the potential is high, and we’ll see the payoff when we learn how to do these AI tasks at scale. I think that’s the same perspective. Now, yes, our job is to help make it happen.
So, when Alteryx takes on the implementation of this, how much of the productivity savings do you think gets passed on to the customer?
The first thing that comes to mind is that we can become more productive and achieve higher margins.
Obviously, there is competition, which in theory should limit high profits. What stage do you think we are at now? Will the margins after the transition be the same as before, with consumers simply getting more for their money? Will the structure of the industry change in terms of who gets the primary value?
I think the situation will be very different depending on the industry. There are many industries, such as discrete manufacturing, where a significant portion of costs are related to physical materials, and where business profitability is more likely to be affected by customs policy than by artificial intelligence. This is just one extreme example.
Let’s take another example that everyone likes to talk about: the consulting business. Here, we are essentially working with information, and in this world, AI can take on many more tasks and have a greater impact. I believe that this will affect both the demand for such work and the level of margin at which it can be provided.
I’m convinced that it will all depend on the specific industry, and there is no single answer. I also think that there will be significant differences within the industries themselves. Some companies move quickly, actively get involved, and test new things. Others take a wait-and-see approach, saying, “Let’s see. Let’s wait.” I believe that this will affect who gets there first, who wins on margins, who increases market share, and therefore who ultimately wins.
11. Strategic AI experimentation
When I tried Mentor—the product you described, with the developer experience—I was struck by a few things. One of them, and I’m curious about your thoughts, is the value of very early and aggressive experimentation. For me, it’s been confirmed again and again: I’m trying, working, and making an effort to finally make something work. Then, in the next generation of models, or two generations later, it suddenly becomes easy, right?
Even creating something like Mentor two generations ago must have been quite a challenge: making it work, making it semi-reliable, and so on. Now you can use 55 or Astra and probably create something very similar to what you have in 10% of the time, or even less.
When you think about what organizations should be doing strategically, how do you distinguish between wasting effort on something that will soon become easy and waiting? How do you understand what is worth tackling right away, and where a little patience can be an advantage?
Yes, good question. Let’s talk about this. Creating Mentor was certainly a serious challenge. We started this work in 2018, before I joined the company, and the state of the technology then was limited to machine learning. Generative AI didn’t exist at that point.
The question was how to use AI or machine learning at every stage of the software development lifecycle to speed up processes, improve quality, and so on. Of course, the project has evolved significantly over time, and now Mentor is a set of MCP services that can be used anywhere to reliably create software that meets all your non-functional requirements, helps you meet compliance standards, and more. It was a huge transformation.
The models we use under the hood are constantly changing as we optimize costs, as discussed earlier. The problem that most of our clients still face today isn’t radically different from the past. It’s just that the opportunities are better, and people can do more and do it faster. But the real question is: What exactly should I create to really solve the problems in my business and take advantage of new opportunities?
“What exactly to do” is still the most difficult question. Isn’t that right? How much should I experiment and try? I would say that most of the effort should be directed to where I will get the greatest return on investment. Where and what business process makes sense to transform into something more agile (Agilentic)?
We learned this the hard way with our clients. Today, we have portfolios of thousands of applications. That’s why we created AI that tells clients what smart system they should build based on assets already running on our platform.
12. Balancing flexibility and security (Part 1)
We just launched a brand-new opportunity. Now it’s in the hands of our customer success teams: an agent that simply tells you what to create and predicts your return on investment in terms of time savings and other metrics. We use all the telemetry data from the apps you create. We understand the structure of what you do, see the data flows in them, analyze it, and say, “Hey, maybe we should think about an agent to turn this manual work into an automated one. And, by the way, click this button to create it.”
The AI can actually create the first version, which you can then, of course, run through your development, testing, validation, and trial process. Solving the problem of “what to do” is a huge part of the challenge for most organizations trying to achieve agentic transformation of their business.
13. Future software user experience
Very interesting. Another big question I had about Mentor is: How do you see the future of user experience in software? The Mentor experience is a familiar AI sidebar that seems to embrace a legacy app, right? What you used to do with drag and drop can now be done through the use of tools, and now you have both.
But then there’s this MCP paradigm where I’m sitting in a completely different program, or maybe just going for a walk and talking to my agent via voice mode, and the tools might not even show up the way they do on the main platform. What do you expect in terms of the uptake? Where are you trying to stay ahead of these trends?
Yes, great question. I personally still imagine that, in a year, I will have over 100 apps on my phone, right? I think the user experience for the different things we want to do doesn’t always boil down to a conversational interface. We think mainly about whether we do things in voice mode, text mode, or some other way.
I don’t know how this will develop. I think there’s a very real chance that a lot of the apps we use today will be widgetized into little elements that pop up during a conversation. I’m thinking about a question involving Google Maps. Google Maps is one of the most useful things on my phone. I use it every day, whether it’s to find a place to order pizza, get directions to a destination when I’m driving, or walk through an unfamiliar city.
I wonder when Google Maps will just become part of my conversation with artificial intelligence. It could happen in an instant, right? I could just say to ChatGPT, “Give me step-by-step instructions on how to get from here to there.” But I still want to know what the world around me looks like, what its structure is, and what I’ll see along the way. I don’t think a conversational interface would be ideal here.
This is a microcosm of the whole issue you’re raising, but it’s an example of where I think there will still be differences. For many reasons—whether it’s privacy, compliance, or simply user preference—we will continue to see a variety of software interaction models.
I’m ready to accept the idea that the big monolithic blocks we have today—a portal with 80 features—could be delivered in a completely different way, in small pieces, exactly when I need them in the process. It will be interesting to watch how this develops.
I think at our user conference in June, we showed a pretty compelling demonstration of how one of our banking customers initiates a loan application through a conversation with Claude about home renovations.
“Hey, let’s think about this new stove and all that.”
“God, this is going to be expensive.”
“Maybe I need money.”
“Did you know you have pre-approval for a loan of 30 thousand?”
“Would you like to start the application?”
There’s a seamless transition from a conversation in Claude straight to the bank’s mobile app, where the same agent works behind the scenes in both contexts, seamlessly continuing the dialogue and recognizing what documents they already have for a loan application because they are already a bank client. They don’t need to ask for a bank statement.
There’s end-to-end processing of such a request through the backend, where agents perform work or provide recommendations to the people involved at each stage of the process, optimizing the entire experience for the consumer.
That’s interesting, right? A lot of the workflows flow directly into the agent experience, so to speak, but there are still certain software assets—in this case, a mobile app—that are required to meet a number of compliance, privacy, and regulatory requirements.
Will they change and evolve over time to the point where they will no longer be needed? I don’t know. We’ll see. I guess the interesting question for me is not how everything will become the same, but what the imagination of developers will create now that artificial intelligence and platforms like OutSystems are removing many of the typical traditional limitations when creating incredible products.
14. Specialization versus commoditization
This idea of everything becoming the same, along with your previous comments about how many big features you’ve released recently and how much it’s scaled, makes me wonder about the future of competition. I really feel like everyone has gained a newfound courage to pursue these adjacent niches, and the more niches they pursue, the more new opportunities come up.
So I see this convergence as all platforms becoming the same super-horizontal, “everything you need in one place” offering. I wonder if you see it the same way and if you think that’s where it’s going, but… Oh, yeah. How do we win? How can you even win in such an environment?
Yes, yes. I mean, of course. Let’s be honest: If you drive down Highway 101 in San Francisco, you’ll see all these billboards, and they all have the same 5 words written on them, right? It’s like the logo is just different.
Certainly, I think the industry is trying to articulate differentiated messages in this world. Part of it is because of the “ocean of the same,” right? Today, so many experiences in many dimensions can be realized through a conversational interface, and this is one of the factors.
Now the question is: What is behind this conversation? How do the systems work there, deep down? What kind of data is there in the depths? How do these things interact to give me more of what I want through such an experience?
You come to the conclusion pretty quickly: “Well, okay, great. I need an agent platform. I need an AI designer. I need integrations with a lot of things.” The things needed to solve this problem are the basic building blocks, right?
At this point, a lot of platforms are rushing into this space and saying, “Okay, let’s fill it with all this.” So how will we be different in the future? I think ultimately it will be specialization.
There will be a common set of building blocks that everyone needs, and then: What do you become really good at? What do you optimize? Some of that optimization will be in areas like customization, distillation, model specificity, and associated cost structures. I think part of it will be in industry and work optimization.
I think there will be a concentration of efforts that will allow us to go beyond a purely horizontal approach, where everyone has the same set of tools. Although everyone needs primitives, there must be specialization at the top.
For us, a lot of this is in regulated industries, where we’ve solved many problems in ways that we can apply to this platform. That’s about 37 features that aren’t on the basic list but are needed to overcome the barrier to building or deploying your first solution. I think that will be a big part of our work.
Additionally, we have expertise that we’ve built over the years in banking, insurance, the public sector, healthcare, transportation, logistics, energy, and utilities. These are large, regulated industries that form the core of our current client base, where our teams have specialized skills and understanding, and where we can quickly help organizations modernize processes.
I think this kind of specialization will help us stand out. We’re at a point right now where everyone is saying, “Yeah, we have all of that.” I think we all quickly realize that it just confuses everyone. Everyone says, “Oh, it’s all the same.”
I really think that, as an industry, we have a lot of work to do to up our game.
15. Hiring in AI era
How have your hiring practices changed? What advice would you give to people who are just starting their career path today? I think they’ve been getting a lot of signals lately that are making them worry about their own employment prospects. They feel a certain hostility toward AI because they believe it competes with them.
What do you do at Alteryx, and how would you adapt that to broader advice?
I’m very optimistic about young professionals—people who have grown up in the last 5 years, getting used to all these new technologies, and who can bring them into the organization, to our clients, to our partners, and to our own company, really accelerating innovation.
Of course, they need to learn a lot about key business processes in all these industries to be useful, but I think they generally bring a fresh perspective, a new attitude, and an approach to things where artificial intelligence is at the forefront. I have high hopes for this.
I don’t think organizations today have built the infrastructure to do the other part of the job well, which is really immersing these people in the industry and providing the specialized knowledge needed to make the most of their skills.
Do you know what exactly is changing in the way we hire employees?
We’re definitely leaning toward the full-time employee model, thinking about how we can directly help clients with their work planning. A big part of this is design: What exactly are we going to invest in, and where, to achieve significant impact?
We think of it as the people we hire, and at the same time, we think of the agents we hire, too. The work that I talked about today—our agent factory, which looks at your architecture and says, “This can be turned into generative technologies”—is another thing that we’re doing.
Today, we look at every new task that needs to be completed in a completely different way. Is this a job for a person? Is this a job for an agent or a team? Is it a combination of both options? How do we structure everything around this new model of doing work?
Additionally, we’re thinking about the journey of every employee we hire and how we can dramatically accelerate what we used to call onboarding. For decades, in most companies, it’s been, “Hey, here’s an introductory course for you for a few days or a week.” Then there are additional trainings that need to be completed on all these issues.
We’re transforming all of this into something more technological, more operational, and more timely. We provide you with the knowledge you need exactly when you can use it and, thus, learn it.
Many practices of working with people are changing rapidly. These are investments that we make ourselves, and we certainly encourage clients to think about this in their own businesses and how it fits them.
Is there anything else you’d like to tell people before I send you back to work?
Yes, of course, join the OutSystems World Tour from Las Vegas today, where we'll be showcasing many of these incredible technologies. The latest developments in agent experience for OutSystems, which significantly help organizations accelerate the reliable implementation of artificial intelligence systems for their business.
Winston Martin, thank you for being part of the cognitive revolution.
Thank you, Nathan.