TPTL #11 + Your Free Gift - Your Monthly Insights on Tech, AI & LLMs: Google Gemini, Shadow AI and OpenAI AARDVARK


The Pragmatic Tech Leader Issue #11

Hi there,

Welcome to the 11th edition of the Pragmatic Tech Leader newsletter (TPTL)! Ensure you scroll down to get your gift!

Let's jump into our key topics for this edition!

  • Google Launches Gemini 3 Pro
  • DeepSeek-V3.2-Exp: Long context, sparse attention, open weights
  • Shadow AI: when your riskiest AI system is the one you don’t know about
  • Can the internet Go Offline?
  • Aardvark: GPT-5 as an Autonomous Security Researcher
  • Bonus: Your Sustainable AI Course Free Access

Google Launches Gemini 3 Pro

Google DeepMind has introduced Gemini 3 Pro, as its most intelligent AI model to date.

This third-generation Gemini is designed for advanced reasoning across modalities and is deeply integrated with Google’s ecosystem, powering search-connected, multimodal “generative UI” experiences

In practice, Gemini 3 can handle text, images, and more, enabling features like high-resolution image generation (with the new Nano Banana Pro model - Amazing by the way) and even an AI content verification tool in Google’s apps. Currently in preview, Gemini 3 Pro is accessible via the Gemini mobile app, Google Cloud (Vertex AI), and Google’s AI Studio.

Google reports that it outperforms previous models in complex learning and planning tasks and it’s set to replace older assistants (even being tested in Android Auto).

DeepSeek-V3.2-Exp: Long context, sparse attention, open weights

DeepSeek released V3.2-Exp (around 2 months back, but I didn't had the opportunity to review it till recently), an open-weight experimental model built on V3.1-Terminus that debuts DeepSeek Sparse Attention (DSA). Instead of just scaling parameters, they reworked attention patterns to handle long context more efficiently, while keeping training configs comparable to the previous model. API prices dropped by more than 50%, signaling a push toward cheaper tokens rather than just bigger models.

From day 0, V3.2-Exp is supported in vLLM on modern Nvidia hardware (H100/H200/H20, B200/GB200). Benchmarks show parity with V3.1-Terminus across common tasks, while enabling much longer context at similar compute cost.

I think this is emblematic of a broader trend: efficiency and context length are now as strategic as raw IQ. Open-weight players like DeepSeek are creating viable alternatives to proprietary “maximalist” models, especially for workloads where you need to stuff entire repos, long specs or multi-quarter logs into a single context. The question for enterprises is less “Which is the smartest model?” and more “Which stack gives me acceptable quality at predictable cost?”

I speak about this both in my course on DeepSeek, and my course on Sustainable AI.

Shadow AI: when your riskiest AI system is the one you don’t know about

Gartner now predicts that by 2030, ~40% of enterprises will suffer a security or compliance incident caused by “shadow AI”, unsanctioned AI tools used by employees outside IT or security oversight. In recent surveys, 69% of security leaders say they suspect or have confirmed such tools in their org, and Microsoft data suggests 71% of workers in the UK alone use shadow AI, with 22% doing so for high-risk tasks like finance.

Analysts highlight three main risks: unvetted tools exfiltrating sensitive data, regulatory breaches (GDPR, HIPAA, financial regulations) when regulated data is pasted into random chatbots, and the accumulation of “AI technical debt”. Systems built in the shadows that later need to be replaced or secured at great cost.

I believe most companies still treat AI like “just another SaaS app,” but the risk profile is closer to an unmanaged data lake plus a junior analyst (with all due respect to junior analysts) with root access. A pragmatic approach is: 1) publish a clear AI usage policy, 2) offer good, approved tools so people don’t need shadow ones, 3) bake AI risk checks into vendor assessments, and 4) train staff on what never goes into a prompt (customer PII, trade secrets, health data, etc.).

Can the Internet Go Offline

The last weeks were another reminder of how much of the internet rests on a few critical providers.

After recent outages at AWS and Azure, Cloudflare also went down, taking with it a long list of services, including ChatGPT. When Cloudflare or a big cloud region fails, it’s not “one site” that breaks, it’s an entire slice of the internet experience.

This ties well with the Guardian article “Could the internet go offline?”. The core idea: the internet is built on creaking, decades-old protocols and a lot of concentration. A few unlucky events (extreme weather on data centres, a serious bug in a major provider, a routing or DNS issue) could cause cascading failures.

I do believe that we have accumulated many Single Points of Failure (SPOFs). Full global shutdown is unlikely, but large-scale, multi-day disruption is no longer a crazy scenario, remember Crowdstrike global outage. Rethinking resilience, multi-region, multi-cloud where it matters, and realistic outage playbooks, is becoming part of the job, not an “edge case”.

Aardvark: GPT-5 as an Autonomous Security Researcher

OpenAI has released Aardvark, an “agentic security researcher” powered by GPT-5.

Aardvark connects to your repositories, reads the code, builds a simple threat model, scans commits, tries to exploit what it finds in a sandbox, and then proposes patches. It behaves more like a human security engineer than a classic rule-based scanner.

In OpenAI’s tests on open-source projects, Aardvark reportedly identified 92% of known and synthetic vulnerabilities, and it already led to several CVEs being issued. It also integrates directly with GitHub and Codex to open pull requests with suggested fixes.

This is getting very interesting. Aardvark looks like a serious candidate to replace or augment SAST in many contexts: more context, better explanations, continuous watch. For DAST-style testing, it is less obvious today, but future versions integrated into staging and runtime could move in that direction. I do not think it is of a level yet to do Pen Testing, even if some AI agentic agents are starting to show good traction on such technologies like this open source repo Strix.

It’s a clear step toward “security by default,” where an AI agent quietly reviews your code all the time, and hopefully finds the bug before an attacker does. In terms of maturity, I do not believe it is yet to replace vertical specialized SAST tools.

Bonus: Your Sustainable AI Course Free Access

As promised when I initially launched this newsletter, I am more than glad to offer exclusive free access to my courses when I launch them.

I just launched a new course on Sustainable AI, and the idea came following a key note I delivered in Amsterdam, where some questions came on that topic, and when I looked, there were barely some educational material about it, so I built one :)

To get your free access, you just need to

The link is valid only for 2 days, so ensure you enroll quickly. Leaving a 5* review if you like the course is really helpful so it gets good ranking and I appreciate your support on that. I am looking forward to get your feedback.

In case the button didn't work, you can simple use this link or copy/paste it:

https://www.udemy.com/course/sustainable-ai-artificial-intelligence-footprint-and-what-todo/?couponCode=TPTL_DIGITAL

And if it doesn't work or it expires, please answer to this email and I'll send you a new one starting December 1st.

More Reads

Here are some articles and posts I shared recently that you might want to read

Talks and Events

  • Next Thursday, Dec 4th, I'll be signing copies of my book in Arthephage Bookstore in Tunis, Tunisia. A signing session in France is planned end of January, and I'll share an update by then.
  • Next Friday, Dec 5th, I'll be delivering a key note in Tunis for an invite-only event for Telecommunication Professionals. If you want to join feel free to contact me directly and I'll see if I can get some invites.

Digital Transformation - did you grab your copy?

I published my new book 3 months back, Digital Transformation: How to Lead Business Transformation through Digital Platforms and AI. Get your copy! It is now available as paperback, hardcover and ebook on Kindle! You can check here more insights and press coverage for the book.

You can already order it here on Amazon (link for Amazon US, but it is available on every Amazon store).

Feedback is a gift

Thank you for taking the time to read this newsletter, I hope you enjoyed it. It would be great if you can spare some time to leave your feedback here.

Want more ?

I regularly write about AI & Data, you can follow me :

If this newsletter was forwarded to you, you can get your own copy by subscribing here.

Ahmed Fessi

Read more from Ahmed Fessi
AI News

The Pragmatic Tech Leader Issue #14 Hi there, Welcome to the 14th edition of the Pragmatic Tech Leader newsletter (TPTL)! Let's jump into our key topics for this edition! Anthropic files for IPO at a near trillion dollar valuation Claude Fable 5 and Mythos Microsoft goes model independent with seven MAI models DeepSeek returns: cheap AI starts eating token volume US AI governance: softer rules, stronger politics Anthropic files for IPO at a near trillion dollar valuation Anthropic...

AI News

The Pragmatic Tech Leader Issue #13 Hi there, Welcome to the 13th edition of the Pragmatic Tech Leader newsletter (TPTL)! Let's jump into our key topics for this edition! AI agents are getting stranger, and more real Nvidia shifts the AI race from training to inference AI labs raise mega-funds and rewrite the capital game Microsoft pushes enterprise AI from copilots to governed agents The coding wars intensify: Anthropic and OpenAI go all-in on software agents AI agents are getting stranger,...

AI News

The Pragmatic Tech Leader Issue #12 Hi there, Welcome to the 12th edition of the Pragmatic Tech Leader newsletter (TPTL)! This is the last issue in 2025. Wishing you all the best for 2026! Let's jump into our key topics for this edition! Nvidia licenses Groq tech (and hires key execs) “Vibe coding” meets reality: humans still win ChatGPT ads: the monetization path nobody loves AI pentesting agents are doing better than humans OpenAI releases GPT-5.2 and GPT-5.2-Codex Bonus: Start 2026 by...