As frontier AI models from the US and China approach parity, enterprises face a new strategic question: what happens when your entire security architecture depends on a single provider?

In this conversation, Ashish Tandon, Founder & CEO of Indusface, argues that model diversification isn’t just about cost or performance; it’s about resilience. From comparing outputs across models to catch missed vulnerabilities, to the risks of unmonitored AI-to-system connections, he unpacks why the real vulnerability often lies not in the model itself, but in the sprawling web of APIs, agents, and integrations around it and why remediation speed, not detection, is the next battleground.
Ashish Tandon: China has always been catching up. But, I think one has to understand the structure. The models, these are all very large language models, which are needing a lot of investment and a lot of hardware and a lot of capabilities to do it.
And both the U.S. and now China are clearly demonstrating that they can create these large language models, frontier models, which are extremely capable. And I think from an industry or from a business perspective, I’m pretty excited that, one has options now. Especially given the geopolitical situation, it is important to have options.
And I think it’s a very positive thing that we have equivalent options for businesses to leverage them and take advantage of that. Am I surprised? I don’t think so. I think everybody is working on it.
Everyone realises the power and the value of this capability. And hence, this is going to catch up and keep getting better, bigger, faster, and more efficient as we go forward.
Ashish Tandon: The way one should look at them is that, when you do business, you need the business to be resilient. When I say resilient, you don’t have a single point of failure. We want to make sure we’ve heard about business continuity and all those aspects.
Having comparable models available from a business perspective is great. Because you would generally want to have multiple options with you so that if there is any challenge—for example, some time back, one of the models was not available, or the government of that country took a decision that this model should not be available to anybody in the world.
I have built the entire business on that, and I have no other option. That’s the challenge. I feel this is a good thing: we have multiple options. It improves resilience. It ensures business continuity.
And I personally feel that, from a competitive perspective, the creators of the model will have a challenge commanding or demanding a higher price. But from a consumer and business perspective, I think it’s great news for those leveraging this model.
For example, we leverage models. For us, it’s good that we have options too, and we don’t have a single point of failure because we don’t depend on any one model.
Ashish Tandon: Exactly what I mentioned. If you depend only on one model and if that model is not available to you within 90 minutes, think about where your security architecture and the entire thing you have planned on it, where do you stand?
Reliance on a single model- forget models; reliance on any- in this day and age, especially anything critical to you, one needs to have an option. My strong recommendation is that you have multiple options.
Ashish Tandon: It depends from business to business. But I think the most important thing from a security officer’s mindset is that he can use this to, first, compare results from two models.
These days, you are finding differences between models in terms of vulnerabilities. For example, when we tested three different models, each one came up with unique vulnerabilities that differed from the others.
It gives them an option. Always, a business is built, and the security guy, the security officer, always thinks about how he can make sure that he finds enough or make sure he has his attack surface properly covered and having multiple models helps him because he gets more information and more attack-surface information he can use.
How does he integrate it? I think it depends on how the business works. For example, for anything we test or use to detect vulnerabilities, we generally leverage two models.
First, we compare them to ensure we haven’t missed anything, then integrate both findings into a single system where we review the outcome and take action. Security officers would follow a similar strategy.
Ashish Tandon: Fast, the models are working at machine speed. So, with GLM-5 and my thoughts and all that, they’re clearly demonstrating that they can detect vulnerabilities at machine speed, and what took days or months is now done in a few hours.
There is no doubt vulnerabilities exist, and these are often critical business-logic vulnerabilities a hacker can exploit; there is no debate that vulnerabilities and the discovery of weaknesses in systems are moving at machine speed.
I think what is really required is this: how do businesses first accept that vulnerabilities are being exposed at machine speed? How do they identify them and make that the protection mechanism? Meaning, whatever vulnerabilities are found, how do they protect them at machine speed as well?
For example, on our platform, as soon as we detect a vulnerability, we build autonomous virtual patching that humans verify, helping them virtually patch those vulnerabilities at similar speed and in a similar motion.
The answer now lies in how fast you can remediate. Detection at machine speed is a foregone conclusion.
Every CISO, every security officer, is thinking about how we can build a protection mechanism that also runs at machine speed.
Ashish Tandon: One has to realise that we keep talking about models, but a model doesn’t work in isolation. It is connecting to an MCP server; it talks to an API, it talks to your application, it talks to your database.
It has a lot of connections within that to come up with an outcome. I think the challenges with the models are that the agents or the model, the machine itself, is talking to all these systems and coming up with an action.
Every point, every agent, every aspect of AI that talks to various systems must be monitored; the right kind of access must be ensured; they must be tested; data leakage and any DLP mechanisms must be put in place; and humans must verify the outcome. An audit trail is in place.
It is a system that has to be put in place, considering what humans did earlier; now agents and machines do it at machine speed. How do you ensure compliance and regulatory mechanisms are in place so every agent action is monitored and audited, and it isn’t doing something it is not supposed to?
Because at the end of the day, the business owner or the people running the business are responsible for the outcome that comes out of the system.
The model itself isn’t the risk. The risk is whether it works across the system, and whether the outcome is audited, consistent, and monitored. Putting a compliance mechanism around each one of them, and monitoring everything, is going to be critical. I would say that is the weakest link in the architecture, not the model itself.
Ashish Tandon: It is the same philosophy. It’s great that you have open-source models.
Open-source models or regional models help you mitigate risk. For example, you might focus on a model; you might use an open-source model, maybe a smaller one. They are doing a particular… I think it fits the de-risking criteria, where you can leverage multiple models and make sure your business isn’t dependent on just one.
It is a very good aspect. Enterprises should embrace them and leverage each one depending on what works and what fits. More options are a very positive thing, and I am glad it is moving so quickly.
Ashish Tandon: Have an enterprise contract or zero down on them. I think when you clearly understand and identify it, you might start looking at enterprise contracting. Still, I think everyone is in the phase of figuring out what the models are, what the strategy should be, what’s best for business continuity, how to put an option in place, and so on. I would lean on the enterprise still moving, looking at that aspect before finalising the contract.
The global narrative and the information show that most people are using it and trying it out, so enterprise contracts are still a little bit away.
Ashish Tandon: Everybody started realising that there is a genuine power with AI. It has the capabilities which you all want to leverage.
But I think a lot of companies, including us, have started realising that the model becomes richer and better with the data you provide to it, the prompts you give it, the kind of information you put in, and the quality of the data we have.
Everybody thinks everything is fed into a global model, and that the information becomes available to everybody. So how do I, as a business or cybersecurity product company, keep delivering the capabilities we have built over the years to our customers?
We have started deploying models within our data centres, using our data to train them and leveraging them to provide value to our customers. We have years of data specific to our security capabilities, vulnerabilities, and attack vectors.
How do we leverage that, give it back, use it to improve our model, and keep it as our IP while leveraging it more?
That’s where most businesses will start moving toward. How do we, as you rightly said, avoid commoditising it and still retain our IP while leveraging the model?
I think that’s where the switch and the shift would start. I see people moving and businesses moving, especially technology companies like us.
Ashish Tandon: You won’t exist if you don’t wake up today. AI is real.
AI is reality. It has phenomenal benefits. It also comes with its challenges. But I feel the benefits far outweigh the challenges.
And I feel that if you’re not going to join the bandwagon quickly, you might not be a part of it. In my view, AI will remain relevant and ahead of the curve if you adopt it quickly.
But they and that stay won’t face serious challenges—existential challenges, I’d say.