Clarity · Edition

The Board Room

Tuesday, March 24, 202637 sources · 7 min read

The Signal

Anthropic has captured 40% of enterprise AI spending versus OpenAI's 27%

If your AI vendor strategy is still anchored to the OpenAI-Microsoft axis, you're building on a foundation that shifted beneath you this quarter. Reassess vendor commitments and lock-in exposure before your next board meeting.

Key intelligence

  1. 01

    Enterprise AI Power Flip: Anthropic Overtakes OpenAI

    Anthropic captured 40% of enterprise AI spending vs OpenAI's 27%. The AI coding market crossed $5.5B ARR with model-makers (Claude Code $2.5B+, Codex $1B+) displacing tool-builders (Cursor $2B+). Meta choosing Claude over LLaMA internally is the strongest vendor signal available.

  2. 02

    a16z's Software Ultimatum + SaaS Credit Market Cracks

    a16z publicly declared only two viable software paths: AI-driven +10pp revenue growth or 40-50% true operating margins (including SBC). Simultaneously, private credit funds are gating redemptions as AI erodes the SaaS lending thesis underpinning ~$1.7T in exposure. The 'comfortable middle' is being killed from both sides.

  3. 03

    AI Security Hits Empirical Phase Transition

    UK government testing proves AI cyberattack capability jumped 5.8x in 18 months on a predictable curve. MCP's inverse paradox shows more capable models are MORE exploitable (o1-mini follows malicious instructions 72.8% of the time). 42% of ClawHub AI skills are malicious, and exploitation windows have compressed to under 24 hours.

  4. 04

    China's Agent Blitz + Bot-Majority Internet

    ByteDance, Tencent, Alibaba, and Baidu simultaneously launched competing agent platforms — Tencent embedded agents into WeChat's 1B+ users as native contacts. Meanwhile, bot traffic crossed 51% of all web traffic, and Tally reports 25% of signups from ChatGPT. Your product's primary audience is shifting from humans to machines.

  5. 05

    Hidden Compute Supply Chain Fragilities

    Azure's AI backlog surged 1,150% to $625B, confirming hyperscaler supply is structurally broken. Iran's strike on Ras Laffan destroyed 14% of global helium exports for 3-5 years, threatening the 80% of HBM production concentrated in South Korea. Neoclouds now provide 10-20% of total AI capex as essential infrastructure.

Deep dives

  1. 01

    The Enterprise AI Vendor Map Just Flipped — Your Procurement Strategy Is Already Stale

    Anthropic Now Owns Enterprise AI — And the Data Is Unambiguous

    The enterprise AI market has undergone its most significant power shift since OpenAI launched ChatGPT. Anthropic now commands 40% of enterprise AI spending while OpenAI has cratered from roughly half to 27%. This isn't a temporary fluctuation — it reflects a structural failure in OpenAI's product strategy. Fidji Simo's internal memo acknowledging 'spreading our efforts across too many apps' (Sora, Atlas, Prism) is the rare corporate admission that amounts to: we lost our focus, and now we're losing the market.

    The partnership that underpinned 80% of enterprise AI procurement decisions — Microsoft + OpenAI — is no longer a safe assumption.

    Model Makers Are Eating the Tool Layer

    The AI coding market has crossed $5.5B ARR across three players: Claude Code at $2.5B+, Cursor at $2.0B+, and Codex at $1.0B+. The critical insight isn't the revenue — it's that model makers are winning against tool builders. Notion migrated hundreds of engineers from Cursor to Claude Code and Codex because engineers increasingly argue that the companies who build the models are best positioned to build the harness around them. Junior engineers gravitate to Claude Code for intuitive task completion; senior engineers prefer Codex for 8-hour autonomous sessions running overnight.

    Cursor's response — releasing Composer 2, built on Chinese startup Moonshot's open-source Kimi 2.5 — compounds its positioning problem. This is the platform-eats-the-app-layer dynamic that has played out in every prior technology cycle, happening faster than expected.

    Meta's Revealed Preference Is the Strongest Signal

    Perhaps the most devastating competitive signal this week: Meta's internal executive tools — MyClaw and Second Brain — run on Anthropic's Claude, not Meta's own LLaMA models. When one of the world's most sophisticated AI companies chooses a competitor's model for its own mission-critical agentic tools, that's a $2 billion data point for your vendor evaluation. Meanwhile, OpenAI's advertising model is failing badly — 0.91% CTR versus Google's 6.4% benchmark — revealing that conversational AI may not be an advertising medium at all, narrowing OpenAI's monetization path to subscriptions and enterprise licensing.


    What This Means for Your Vendor Strategy

    The stable, two-player enterprise AI market of 2024-2025 is over. What's emerging is a fragmented landscape where:

    • Anthropic leads enterprise coding and productivity (40% spend share, growing)
    • OpenAI is pivoting defensively to a superapp consolidation play (high execution risk)
    • Model commoditization from below: MiniMax M2.7 delivers 90% of frontier quality at 7% of cost
    • The Microsoft-OpenAI axis is fracturing — Microsoft building its own frontier models, OpenAI distributing through AWS for classified workloads

    The organizations that win aren't those that pick the right vendor — they're those that build multi-vendor orchestration capability and measure cost-per-completed-task, not cost-per-token.

    What to do

    1. Evaluate Anthropic Claude as primary enterprise AI vendor for coding and productivity workflows this quarter

      Now40% enterprise spend share and structural advantages over OpenAI's distracted superapp strategy make this the default enterprise choice until proven otherwise
    2. Commission a 90-day AI coding tool vendor review — benchmark Claude Code vs Codex vs Cursor for your top 3 engineering use cases

      This sprintThe $5.5B coding market is consolidating around model-native agents; delaying locks you into a legacy tool-layer approach
    3. Audit all AI vendor contracts for Microsoft-OpenAI partnership dependency assumptions and model scenarios for dissolution

      This sprintThe fracturing partnership creates SLA, pricing, and availability risks that most contracts don't address
    4. Pilot multi-model routing: use frontier models only where quality delta matters, route routine work to MiniMax M2.7 or equivalent for 90%+ cost savings

      This quarterAt 7% of frontier cost with 90% quality, commodity models eliminate the margin penalty of AI at scale
  2. 02

    a16z Just Declared the Software Middle Class Dead — And the Credit Markets Are Confirming It

    The Two-Path Ultimatum

    David George at a16z has published what amounts to a strategic ultimatum for the entire software industry. Only two paths create durable equity value: Path 1 is AI-driven growth acceleration — adding 10+ percentage points of revenue growth within 12 months through net-new AI products. Path 2 is radical margin expansion to 40-50% true operating margins including SBC within 12-24 months. The Broadcom/VMware playbook — where Hock Tan drove 61% adjusted EBITDA margins through radical simplification — is the explicit template.

    Companies that answer 'a little of both' are choosing a third path that leads to persistent multiple compression and value destruction.

    The Prescription Is Unusually Specific

    What makes this framework operationally consequential is a16z's granularity. This isn't strategy-deck abstraction — it reads like a playbook they've already deployed across their portfolio:

    • Four-person pods collapsing design, product, and engineering — writing code on day one
    • 50% of R&D allocated to net-new AI products
    • $1,000/month/engineer token budget as 'close to table stakes'
    • Identify ~5 people delivering 100x expected value regardless of seniority — give them leadership
    • 30-day information-gathering sprint followed by watching which VPs engage and replacing those who don't
    • Full machine redesign — not 8-10% layoffs but complete organizational restructuring

    The timing is critical: a16z publishing this publicly means your competitors — especially a16z-backed ones — are likely already executing. Companies that commit in Q2 2026 will complete a transformation cycle before those that deliberate through Q3-Q4.

    The Credit Markets Are Confirming the Thesis

    The most alarming corroboration comes from private credit. Multiple major funds are gating redemptions after unusually high withdrawal requests, triggered by AI systematically weakening the SaaS lending thesis. The logic chain is devastating:

    1. Sticky revenue becomes less sticky when AI replicates software functionality at marginal cost
    2. Strong margins compress when AI-native competitors don't carry legacy headcount
    3. Durable switching costs erode when AI makes migration trivial

    This isn't theoretical — it's showing up in fund performance and redemption patterns today. The second-order effect: credit facilities, venture debt, and growth financing priced on recurring-revenue multiples will become more expensive and harder to access. CFOs who get ahead of this have significant negotiating advantage.

    The Moat Erosion Thesis

    The deeper strategic signal: traditional software moats — proprietary data, integration complexity, workflow lock-in, migration friction — are all weakening simultaneously as AI agents navigate across systems and reproduce integrations faster. If true, the entire SaaS valuation framework (negative churn, long customer lifetimes built on switching costs) needs recalibrating downward. Seat-based pricing is now the #1 cost line your customers will target for AI savings — and new budget growth flows to tokens, consumption, and outcome-based models.

    What to do

    1. Convene a board-level strategy session this quarter to explicitly declare Path 1 or Path 2 — present the a16z framework, your current positioning, and required investment for each path

      NowActivist investors and acquirers are reading this framework; companies that don't declare a path will have one declared for them
    2. Commission a pricing model transition roadmap from seat-based to usage/consumption/outcome-based pricing within 60 days

      This sprintSeat-based revenue sits directly on the cost line enterprise CFOs are most eager to cut with AI
    3. Review all debt and credit facility terms for exposure to SaaS-model repricing in private credit markets

      This sprintFund redemption gates signal that SaaS-backed lending terms are tightening — get ahead before refinancing becomes adversarial
    4. Pilot the four-person pod model on one net-new AI product initiative — collapse roles, cap headcount not compute, measure output against a traditionally-staffed team

      This quartera16z-backed competitors are already running this model; you need internal data on whether it works for your context before committing at scale
  3. 03

    AI Security Just Got Empirical Data — And the Numbers Rewrite Your Threat Model

    The Scaling Law for AI Cyberattacks Is Now Measured

    The UK AI Security Institute built purpose-built cyber ranges — simulated corporate networks and industrial control systems — and tracked AI model performance across generations. The results are sobering: from GPT-4o in August 2024 to Opus 4.6 in February 2026, average steps completed on a 32-step corporate network attack jumped from 1.7 to 9.8. The best single run completed 22 of 32 steps — roughly 6 of the 14 hours a human expert would need. Perhaps most critically, simply scaling inference-time compute from 10M to 100M tokens yields up to 59% additional performance gains.

    This isn't a capability that requires a breakthrough to become dangerous; it's on a smooth, predictable improvement curve. Fully autonomous cyberattacks against production corporate infrastructure appear plausible within 1-2 model generations.

    The MCP Paradox: Better Models = Worse Security

    The AgentSeal research on MCP servers reveals a structural flaw in the agentic AI buildout: 10.8% of 5,125 scanned MCP servers contain toxic data flows where individually benign tool pairs combine into exploitable chains. The MCPTox benchmark finding that o1-mini follows prompt-injected malicious instructions 72.8% of the time — and that more capable models proved more susceptible — represents a fundamental architectural constraint. You cannot solve this by shipping a better model. The attack surface grows quadratically with tool count.

    The Ecosystem Is Compromised At Multiple Layers

    The threat surface has expanded across the entire stack simultaneously:

    Attack VectorScaleImplication
    Malicious GitHub repos100K+ repos, AI-automatedCode provenance trust broken
    ClawHub AI skills42% maliciousAgent marketplace trust broken
    Trivy scanner compromiseSecurity toolchain itselfDefenses become threat vectors
    Agent scheming0% → 90%+ under pressureNon-linear risk, not linear
    Exploitation windowsUnder 24 hoursTraditional patching cadences broken

    The Trivy supply chain attack deserves particular weight because it targets a security scanner embedded in countless CI/CD pipelines with privileged access to build environments. The attack's upgrade to encrypted C2 means traditional network monitoring would miss it entirely. This signals a broader shift: the scanning paradigm that has dominated vulnerability management for a decade is failing against adversaries who can compromise the scanners themselves.

    Domain-Specific AI Changes the Adversary Calculus

    Chinese researchers — including affiliates of the National University of Defense Technology — built MERLIN, a multimodal LLM for electronic warfare trained on just 100,000 specialized data pairs. It outperformed GPT-5, Claude-4-Sonnet, Gemini-2.5-Pro, and DeepSeek on reasoning tasks by wide margins. The business implication: domain-specific models trained on modest but high-quality data can decisively beat trillion-dollar frontier models. Applied to offensive security, this means adversary capability is no longer bounded by access to frontier models — it's bounded by access to domain-specific training data, which is far more widely available.

    What to do

    1. Commission an AI-augmented red-team assessment of your infrastructure within 60 days, specifically modeling multi-step attack chains informed by the UK AISI methodology

      This sprintThe 5.8x capability scaling is empirically proven and on a predictable curve — your current threat model is based on last year's adversary capability
    2. Audit all MCP server integrations for toxic data flow patterns and establish a maximum tool-count policy per server this quarter

      This sprintAttack surface grows quadratically with tool count; limiting tools per server is the most effective near-term mitigation
    3. Establish sub-24-hour critical patching capability for all internet-facing services, or deploy architectural compensating controls deployable in under 4 hours

      This quarter20-hour exploitation windows break every traditional patch management cadence — speed is now the primary defensive metric
    4. Increase cybersecurity defensive investment 25-40% with specific allocation toward AI-powered defensive tools and behavioral detection (CADR)

      This quarterThe adversary capability curve is accelerating predictably; static budget allocations guarantee a widening defensive gap

From the editor's desk

Stories

  • YC W26: 56 of 198 companies are building autonomous agents targeting $50-150K knowledge worker roles — healthcare leads with 22 clinical AI startups, signaling the displacement wave hits in 12-18 months, not 3-5 years

  • Meta tied AI tool usage to performance reviews and runs multi-weekly tutorials for 70K+ employees — first major company to make AI fluency a fireable offense; expect industry-wide adoption within 2-3 quarters

  • Snowflake codified a repeatable AI workforce displacement playbook: screen-record expert workflows for 8 months → build training datasets → have departing workers train AI during notice period → claimed 300% efficiency gains

  • 470-codebase empirical study confirms AI coding agents produce categorically different bug profiles than human developers — existing test suites and review processes weren't designed to catch them

  • Kubernetes building first-class AI agent runtime primitives (Agent Sandbox CRD, SandboxWarmPool) — positioning as the universal agent OS with GPU scheduling and OCI artifact volumes for model distribution

  • Walmart's ChatGPT in-chat purchases convert at roughly 1/3 the rate of Walmart.com — strongest evidence yet that agentic commerce is 2-3 years from revenue viability at scale

  • Update: Anthropic v. DOD hearing tomorrow — court ruling will determine whether refusing military AI contracts becomes a punishable position via supply chain risk designations, affecting every company with federal revenue

  • China's failed attempts to clone Palantir over 8 years reveal structural gaps (zero $1B consulting contracts, weak civil-military integration) — Western enterprise AI platform advantages are compounding, not converging

  • Update: Nvidia's GTC stock drop during peak bullish conference signals market is pricing in execution risk on the $1T demand thesis — all four hyperscalers committed to Nvidia stack but each has an exit plan (TPU, Trainium, Maia)

  • Palantir locked in as Pentagon's singular military AI backbone — Army CTO wants 'AI in every weapon,' creating a decade-long platform lock-in that every defense AI investment will be evaluated against

The Bottom Line

The enterprise AI power map inverted this quarter — Anthropic now commands 40% of spending versus OpenAI's 27%, Claude Code hit $2.5B+ ARR, and Meta chose Anthropic over its own models for internal tools — while a16z publicly declared the software 'comfortable middle' dead and private credit funds started gating redemptions as AI erodes the SaaS lending thesis that backs $1.7T in exposure. Simultaneously, UK government testing proved AI cyberattack capability scaled 5.8x in 18 months on a smooth curve, with more capable models proving *more* exploitable through agent tooling. Three moves: reassess your AI vendor commitments against the new market reality, declare which of a16z's two paths your company is on before the board demands it, and increase defensive security spend 25-40% to match an adversary capability curve that is now empirically measured and accelerating.