Talking Cloud Episode 35 · February 26, 2026

WAF AI Dashboards, Kiro Powers, and the 2028 Labor Crisis That Spooked Wall Street

The new AWS WAF AI activity dashboard reveals that over half of Brett's website traffic is now ChatGPT—raising real questions about what content discoverability means in 2026. Meanwhile, a Citrini research paper modeling catastrophic white-collar displacement triggered a $200B stock sell-off, and Brett got banned from Gemini CLI for doing market research.


Top-Line Summary

AWS shipped a free AI activity dashboard in WAF that exposes just how much of your traffic is now AI bots—Brett’s site bot traffic is over 50% ChatGPT users. Kiro launched “Powers,” a bundled MCP packaging system the hosts suspect is convenience wrapped around IDE lock-in. The episode closes with an extended dissection of a Citrini research paper forecasting 2028 white-collar labor displacement that triggered a $200 billion sell-off in software stocks—and that Travers argues was written by someone who’s never worked inside a large organization.

Show Video

The “Pre-Show” Context

Travers deployed a Pokémon-modded Minecraft server (80–90 mods) on Fargate with a Discord bot for start/stop—then watched his friends play 11 hours a day, racking up $70 in AWS charges before switching to Spot. Brett’s own server, running the Distant Horizons mod on a c7g.xlarge, blew through his AWS Partner credits. Both hosts are quietly annoyed that their Discord friends won’t shut up about Arc Raiders.

Episode Artifacts

  • “I blew through my AWS partner credits running a Minecraft server”
  • “$70 of usage later”
  • “That’s what you’re supposed to use those credits for, I’m sure”
  • “Important R&D”
  • “Community power? No way. I’m not installing that.”
  • “Just avoid eye contact” (on Gemini CLI after getting unbanned)
  • “I had to stop reading it. I’m like, I don’t wanna read this.”
  • “Huh, I guess I better go learn a trade”

The Engineering Rundown

  • AWS Security Agent - Cross-Account VPC Penetration Testing (00:08)

    • The Update: The Frontier Security Agent now supports pen testing across shared VPCs in multiple accounts within an AWS Organization. You centralize the agent (e.g., in your security account), use RAM to share target VPCs, and run tests against them.
    • The Skepticism: Travers flags the offensive implication—if defenders get agent-driven pen testing this easy, attackers are building the same scaffolds. He’s already running his own agent against intentionally vulnerable instances like Juice Shop.
    • The Battle Scar: Brett reminds listeners that AWS still has a penetration testing agreement. If you’re using your own tools or a third party, check the EULA before scanning. Amazon seeing unexpected pen test traffic from your account is “not a good time.”
  • AWS WAF AI Activity Dashboard (00:12)

    • The Update: A new free dashboard in AWS WAF shows AI bot and agent traffic via a Sankey diagram. One-click blocking for specific bot categories is built in. No setup required—if you have a WAF, the dashboard appears.
    • The Skepticism: Brett’s site: 50–60% of all bot traffic is ChatGPT. Three-quarters of all traffic is non-human. GenAI hasn’t killed SEO—it’s transformed it. Your content now needs to be discoverable by AI tools, not just Google. Travers connects this to why Cloudflare built their markdown rendering feature.
    • The Battle Scar: Brett pays $10/month for WAF Bot Control and hates the new WAF UI. Regional availability is unclear—the announcement didn’t mention a rollout schedule.
  • Kiro Powers AWS Observability & AWS IAM Policy Autopilot (00:18)

    • The Update: Kiro “Powers” bundle MCP servers, steering files, and Hooks into installable packages. Two AWS Powers launched: Observability (CloudWatch, Application Signals, CloudTrail, Documentation MCPs) and IAM Policy Autopilot. Other catalog entries include Postman, Figma, Supabase, and Terraform. IDE-only—not supported in the CLI.
    • The Skepticism: Brett checked the IAM Policy Autopilot on GitHub—it’s just an mcp.json file. No steering files, no hooks. “Why wouldn’t I just configure the MCP myself?” Both hosts are firm on avoiding community-contributed Powers. Brett: “Community power? No way. I’ll build it myself.”
    • The Battle Scar: Brett admits he’s done the same lock-in dance with Docker MCP toolkit—wired into Kiro, Gemini, and Claude, and now switching would hurt. Travers notes these are all just markdown files—you can replicate any Power yourself.
  • Gemini 3.1 Pro (00:27)

    • The Update: On SWE-bench verified, Gemini 3.1 Pro is on par with Opus 4.6. It hit 77% on ARC-AGI-2 (visual reasoning)—up from 31% on Gemini 3 Pro, versus 53% for GPT 5.2 and 69% for Opus 4.6.
    • The Skepticism: Travers leans toward benchmark gaming. In actual CLI use, the model has “a lot of behavioral issues”—tangents, poor task steering. The knowledge is impressive; the agent-mode training isn’t there.
    • The Battle Scar: Brett got banned from Gemini CLI while doing market research over 2.5 days. Left the terminal open over a weekend, came back Monday to find access disabled—ToS violation. The error linked to a 404 on GitHub. He showed 70+ hours wall time versus ~1 hour agent time. Access was restored today, possibly part of a retroactive unban wave.
  • Sonnet 4.6 (00:37)

    • The Update: Anthropic’s Sonnet 4.6 ships with a 1M token context window and is now the default model in Claude CLI. On the Open World benchmark (real-world computer tasks): 72.5% success rate, matching the 72% human baseline. When that benchmark launched, agents were at 12%.
    • The Skepticism: Non-hallucination rate is 62%—under Haiku (74%) and GLM-5. Brett used it for a week without realizing he’d switched. Configuration suggestions against AWS docs kept being correct, though he caught it hallucinating a couple of times when he pushed back.
    • The Battle Scar: Kiro still defaults to Sonnet 4, not 4.6. Brett switched to auto mode. Travers is rotating between Opus 4.6, Sonnet 4.6, GPT Codex 5.3, Kimi K 2.5, and MiniMax 2.5—and just swapped his Anthropic Max sub for OpenAI because Anthropic is “being quite nasty about integrations” with custom agent tooling.
  • Developer Productivity - 93% Adoption, Productivity Stuck at 10% (00:46)

    • The Update: 121K developers across 450+ companies: 93% use AI coding tools monthly, 75% weekly. Savings: ~4 hours/week (unchanged from Q2 2025). 27% of production code is AI-authored. Onboarding time cut in half. Structured adoption plans produce force-multiplier effects; ad hoc does not.
    • The Skepticism: Travers calls it “busy work tasks getting picked up.” He questions ROI once subsidized pricing ends. Brett observes adoption is bimodal—people either use these tools constantly or not at all.
    • The Battle Scar: Brett admits he went through a phase of shipping AI output without reviewing it. Efficient, but he wasn’t learning anything. Travers references a 1,000-student study showing Socratic AI tutoring yields 4% improvement overall, 9% for the lowest cohort.
  • Sam Altman’s Energy Comments (00:53)

    • Brett’s entire review: “Oof.” Altman compared AI energy consumption to feeding and educating a human for 20 years. Both hosts agree it’s remarkably tone-deaf. Travers suspects these executives “will say anything to get their stock price high enough” before an IPO.
  • Cline NPM Supply Chain Compromise (00:52)

    • The Update: Cline was compromised via NPM for ~8 hours. The malicious package silently installed OpenClaw. Fixed quickly, but anyone who installed during that window should update and check for OpenClaw.
    • The Skepticism: Travers calls this endemic and nearly unsolvable—contributors get compromised, their keys get used, and NPM dependency chains are absurdly deep. He recommends pinning versions at known-good.
    • The Battle Scar: Brett spent 15 minutes manually configuring Playwright and Firecrawl MCPs from GitHub docs into a Docker custom catalog instead of using the one-click install. After weeks of supply chain stories, the convenience gave him pause.
  • Kiro Allegedly Took Down AWS Cost Explorer (00:59)

    • The Update: Multiple sources allege Kiro was given permissions to Cost Explorer, deleted and recreated the environment, and caused a 10–15 hour outage. Amazon blames developer error.
    • The Skepticism: Travers: “Well, yes, but the error was giving it too much access.” Kiro is now in GovCloud. Travers deadpans: “I think we’re gonna get some kind of government leak this year.” There’s also an ongoing Anthropic/DOD dispute over target selection use cases.
  • The 2028 Global Intelligence Crisis - Citrini Research Paper (01:02)

    • The Update: Citrini models a worst-case 2028 where AI displaces white-collar workers at scale—SaaS vendors facing 30% discount demands, organizations building internal replacements (Kanban boards, newsletters, time tracking), and service industry wages dropping from labor oversupply.
    • The Skepticism: Travers argues it “reads as if it was written by someone who’s never worked in a large organization.” Doesn’t account for network effects, product stickiness, switching costs, or maintenance overhead. Despite this, it triggered a $200 billion software stock sell-off.
    • The Battle Scar: Brett compared reading it to watching Hereditary—he had to stop and take a break. He half-jokingly considered learning a trade. The practical concern: CFOs doing simple math on SaaS licensing. A thousand licenses at $100/year is a visible million-dollar line item. The cost of building and maintaining a replacement is harder to articulate, so it gets forgotten. Travers counters that this is exactly how the cloud ecosystem came about.

Off-the-Clock Recommendations

  • Movie: Bugonia - Both hosts loved it. Brett gave it 4–4.5 stars on Letterboxd. Figured out the twist immediately; still highly re-watchable.
  • Movie: Choke (2008) - Sam Rockwell as a con man. Not one for watching with parents. Book readers say the adaptation is weak but Rockwell saves it.
  • Movie: Good Luck, Have Fun, Don’t Die (2025): Sam Rockwell action movie. On Travers’ weekend watchlist.
  • Movie: Moon - Travers’ pick. Sam Rockwell alone on a lunar mining station. “Really good sci-fi.”
  • Movie: Mr. Right (2015) - Sam Rockwell and Anna Kendrick. Light comedy. Brett recommends.
  • Movie: Alien Romulus - Travers rewatching. Both agree it’s the first good Aliens entry in years.
  • Book: We Are Legion (We Are Bob) - Brett is three-quarters through book two. Light sci-fi, couldn’t put down.
  • Book: Co-Intelligence by Ethan Mollick - Alreay out of date but still worth a read.
  • Tool: Letterboxd - Actor filmography feature showing what percentage of their catalog you’ve watched.
All episodes Subscribe