AI Screen Recorders + VDI: The ultimate secure, compliant, & powerful desktop?
I recently wrote about the upcoming Microsoft Recall feature, a forthcoming service that runs on your Windows computer and takes screenshots every few seconds which are processed by AI, allowing you to use an LLM to ask about past computing activities.
While Microsoft is in the process of sorting out some security issues before its general release, I strongly believe that the enterprise use case for this technology will be massive, and that in a few years we’ll see technologies like this become accepted and common at work. (For example, Apple just announced many new features leveraging AI-powered capabilities which access what’s happening locally on a device. I’ll do a full article on that next week.)
In my article on Recall (and my subsequent guest appearance on the Impact of AI: Explored podcast), I outlined how I envision the evolution of AI-power screen recorders at work:
I then outlined several benefits and use cases for companies which I won’t detail here, but the potential for companies is massive: security, business analytics, employee performance analysis, project and enterprise status, workforce management, and countless others.
The quickest path to this? VDI!
One of the downsides of Microsoft Recall is that is requires a “Copilot+ PC”, which means this capability won’t come along until a hardware refresh cycle takes place and then it will only be available on certain devices. (Of course other vendors could offer similar products with different requirements, and screen recording and analysis solutions for enterprises have existed for decades.)
Back in May I wrote an article, “Why the enterprise desktop still matters in 2024”, with the main takeaway being that the Windows desktop is still the easiest “aggregation point” for everything a company needs to deliver to an employee.
And for more than a decade, VDI / DaaS has been sold as an effective way to “secure” that desktop, primarily by separating the enterprise security from the client endpoint. (I realize I’m steamrolling lots of nuance with that statement, but the gist is still largely true today. This is why private equity and big cloud providers are paying billions even in the 2020s for Citrix, VMware EUC, Cameyo, Frame, etc.)
AI-powered screen recorders + VDI/DaaS is extremely attractive
Getting to the core point of this article, the opportunity is huge for AI-powered screen recorders to plug-in to the existing remote display delivery pipeline of today’s VDI and DaaS solutions.
This would have several advantages, including:
This is the ultimate security solution which would be more effective than today’s piecemeal solutions for DLP (data loss prevention). Rather than having a networking appliance that’s trying to decrypt and sniff packets, or a security agent sitting between the browser and the app backend, or some web service connected to the database tier, why not just look at the screen?
领英推荐
I could envision multiple engines being hooked into the screen flow, each doing a different thing and provided by a different specialized vendor. For example:
These are just some quick ideas off the top of my head—there are certainly dozens more.
While VDI isn't strictly needed for each of these, they are all made easier when VDI is used. The non-VDI alternative would look like Microsoft Recall. You'd have to record the screens locally, then either store and process them locally, or compress and send them up to some service. Each of these would add more touch points, transmissions, and require more client processing capabilities. Or, just leverage the existing stream from the current VDI solution.
These capabilities don't have to be offered by the VDI/DaaS vendor itself, rather, the VDI vendor simply needs to provide a framework which third parties can plug-in to as needed and do what they do best. The result is the VDI vendor doesn't have to offer some half-baked compliance solution, and the top tier compliance vendor doesn't have to figure out how to install screen recording agents on a million different laptops. Win/win.
All of this can be integrated with other existing trust signals. (Where is the employee? What level of authentication did they use? What's the client device trust level?) This can be passed on to the various AI processors which allow capabilities to be dynamically tuned as needed. e.g. A client device moves to a public location, and instantly all PII (personally identifiable information) is blurred.
It’s probable that things like this will be part of all devices everywhere in the future, but by focusing on VDI / DaaS use cases, this is something that could be in place relatively quickly and easily (both in terms of vendors providing these capabilities and the ability for companies to adopt them). I hope we soon see capabilities like this offered as subscription add-ons, so a customer can just click the “HIPAA compliance pack” for an extra $10/user/month and be all set.
Maybe 2024 really is the year of VDI after all?
Program note: We discuss and analyze all of this, and more, in my digital workplace master class which I'm teaching in several cities in Europe this year. Upcoming dates include:
Event Coordinator, Creative Consultant, Healthcare, Entertainment, Community Relations, Publicity
5 个月Good to know!
Senior System Engineer - VMware Professional
5 个月a data protection nightmare
Pre-Sales Head @ Accops | Ex-Citrix | Ex-IBM | Ex-HP
5 个月It will be a massive security breach if used by spyware. What if you are working on a confidential document and your screen is getting recorded and then send it to spyware creator when your system is ideal. Sniping tools and PSR tool are already contributing in such security violations. People will be back to paper and pen for doing confidential work. It will be like moving to Stone Age due to this AI.
VCDX-DTM #247, Passionate about helping businesses transform the way they deliver applications and services to end-users
5 个月I think this is what Sonet is doing…but without AI.
Executive, Technology Operations / Strategic Leadership
5 个月what you are describing is what many call "big brother". I understand what you are saying but let's be 1000% honest. It would mainly be used to monitor and track employees. Rightly and wrongly.