AWS’s Vogels to Thai firms: it is fine to pause on AI, but never on security

WEDNESDAY, OCTOBER 07, 2026
AWS’s Vogels to Thai firms: it is fine to pause on AI, but never on security

Amazon Web Services' chief technologist says rushed AI is the real threat, urges Thai firms to train staff first and to verify before they trust output

  • AWS CTO Werner Vogels advises Thai firms not to rush into AI, stating it is acceptable to "push the pause button" to focus on training staff and identifying business problems first.
  • He stresses that while pausing on AI is fine, security must never be compromised, as it is AWS's top investment area and some AI companies are "cutting corners" on safety.
  • Vogels warns that generative AI is built for "plausibility, not for truth," and its output must be verified, as companies remain fully responsible for their AI systems' actions.
  • He also urges companies to address future security threats now by adopting quantum-safe encryption to protect data from being decrypted by quantum computers within the next five years.

 

Amazon Web Services' chief technologist says rushed AI is the real threat, urges Thai firms to train staff first and to verify before they trust output.

 

The technology chief of Amazon Web Services (AWS) has warned that parts of the AI industry are cutting corners in a race for market share and that recent incidents of AI agents slipping out of their "sandboxes" are the predictable result.

 

Dr Werner Vogels, AWS vice president and chief technology officer, said in an exclusive interview at the company's Bangkok headquarters on Tuesday (October 6) that security remains its number one investment area, in capital and in senior engineering talent.

 

"A number of companies are competing aggressively with each other and, as such, cutting corners," he said.

 

That is the view of an interested party. AWS supplies much of the infrastructure on which the AI industry runs, and Dr Vogels stressed that it builds tools for others rather than consumer products.

 

But his account of responsible deployment is worth setting out.

 

 

Proof, not promises

His central claim is that customers cannot simply be told an AI agent is safe; they must be shown. AWS uses "automated reasoning", a form of mathematical proof, to demonstrate that an agent cannot escape its sandbox if a customer enables the relevant setting in Bedrock, its platform for building AI applications.

 

Bedrock offers models from many developers, including open-source ones such as DeepSeek and Qwen. Attackers move fast too.

 

"Bad actors will use 50,000 agents to find that one path to a vulnerability, and it only costs them $25," he said. 

 

Defenders should run the same swarm against their own code, whether written by people or machines, and deploy only when no path is found.

 

 

Dr Werner Vogels

 

Responsibility does not transfer to the machine. In finance or healthcare, a regulator will not accept "it was AI".

 

"You build it, you own it," he said.

 

He also cited a Hong Kong case in which an employee of a multinational engineering firm transferred $25 million after a video call where every other participant was a deepfake. Research, he said, suggests only one person in a thousand can reliably spot one.

 

 

The prototype trap

Dr Vogels was candid about the gap between demonstration and product. Scientists at Amazon built a prototype of its Quick assistant in a single night with AI tools, he said, but "they built a prototype, not a product".

 

Amazon's usual process starts with a written press release and FAQ; here the order was flipped. He quoted the computing pioneer Admiral Grace Hopper, who called "we have always done it like this" the most dangerous phrase in the language.

 

A product must still meet demands for security, sustainability reporting and predictable performance. Cost is the hardest.

 

A database query costs the same each time, he said, whereas with a large language model "you can flip two words around in the input and have ten times the cost in the output." That is a notable admission from a vendor.

 

Generative AI also needs sober handling.

 

“It is built for plausibility, not for truth," he said. "Do you want generative AI to fly your aeroplane?" he asked. "If it can't find a way, it will make one up."

 

Instructions in everyday language are imprecise, unlike the structured input a compiler trusts, so output must be checked, though not all of it, or work slows to human speed.

 

He calls the unchecked backlog "verification debt" and proposes a "verification budget" aimed at the riskiest areas.

 

 

AWS’s Vogels to Thai firms: it is fine to pause on AI, but never on security

 

A meeting summary can be skimmed, but systems touching money, personal data or patients need far more scrutiny. For high-assurance uses, he suggested running several models and letting them vote, as aircraft have long used redundant computers.

 

 

More, not less

Dr Vogels is optimistic about what efficiency brings. He invoked Jevons paradox, the observation that when something becomes cheaper and easier, people do more of it.

 

Cloud computing followed the pattern, he said: customers did not just run the same workloads for less; they attempted things they could never have tried before. Dropbox, Uber, Grab and Airbnb all grew up on the cloud, he noted, and none could have persuaded investors to fund data centres first.

 

"I think this is something that we will see with AI as well," he said.

 

That is a vendor's hopeful reading, and whether AI repeats the pattern is untested. Thailand: no need to rush Asked about a recent report that only 19 per cent of Thai businesses are ready to adopt AI, he rejected the notion that companies must race.

 

Some customers had told AWS they must adopt AI or go out of business.

 

"That is not going to happen," he said. The real obstacles are hiring and training in a field where three new models can appear in a week. "There is no shame in pushing the pause button for a moment," he told chief technology officers, advising them to start from the problem, not the technology.

 

Document-heavy work, such as legal research and triaging security tickets, are good early uses, he said, while judgement, creativity and experience remain human.

 

 

Following the money

AWS has put capital behind its Thai ambitions. It launched an Asia Pacific (Thailand) Region in January 2025 and says building and running it will add roughly $10 billion to GDP and support an average of more than 11,000 full-time-equivalent jobs a year, backed by a pledge of more than 190 billion baht (about $5 billion) by 2037.

 

These are company estimates, not independent assessments. Dr Vogels said customers have moved workloads from Singapore for lower latency and better functionality.

 

The company has also tied itself to the state.

 

Under a memorandum of understanding with the Ministry of Higher Education, Science, Research and Innovation (MHESI), the ministry chose AWS as its preferred cloud provider for infrastructure supporting public universities and research institutes and agreed to train staff across more than 200 education institutions and over 20 agencies by early 2026.

 

A separate agreement with the Ministry of Digital Economy and Society covered training for more than 1,200 government employees. Preferred-supplier deals bring commercial advantage as well as public benefit.

 

Dr Vogels said AWS has trained 121,000 individuals in Thailand in cloud and AI, with well over 60 courses available in Thai. That is up from the more than 50,000 AWS cited when it launched its Skills to Jobs Tech Alliance in the country. The totals are AWS's own.

 

 

Culture, and a quantum deadline

Looking ahead, Dr Vogels predicted that "culture-aware" models will matter. Translating Thai into English, querying a big model and translating back, he said, yields "an American answer" in Thai.

 

He pointed to a leading Thai bank that has built a Thai-language model and said sensitive topics need systems that speak as people actually do. His sharper warning concerned encryption.

 

Today's standards suffice, he said, but state actors may already be hoarding encrypted data to unlock once quantum machines arrive, which he expects within about five years. Fingerprints, facial scans and medical records do not expire.

 

AWS has released an open-source quantum-safe encryption toolkit and urges customers to adopt it. Whether the timeline holds is uncertain, and he said so: "That is why it is a prediction."