Clarity · Edition

The Board Room

Tuesday, March 31, 202630 sources · 7 min read

The Signal

Meta is now routing production Meta AI traffic through Google's Gemini

Coatue's leaked model simultaneously reveals the cost truth: even at $200B revenue, Anthropic's projected EBITDA margin caps at 24%, meaning $152B in annual operating costs. The 'AI gets cheap' thesis is dead.

Key intelligence

  1. 01

    Frontier AI Consolidates to Three — Everyone Else Is a Customer

    Meta licensing Google's Gemini for production traffic proves even Big Tech can't guarantee frontier capability. Coatue projects Anthropic at $200B revenue / 24% EBITDA margin by 2030 — AI stays expensive. xAI's entire founding team departed. The vendor landscape just narrowed to three.

  2. 02

    AI Infrastructure Hits a Physical Wall — Capital Can't Fix It

    241 GW of US data center capacity in pipeline (up 159% YoY), but two-thirds is stuck in grid queues and labor shortages. Community resistance blocked $100B in projects in Q2 2025 alone — bipartisan. Anthropic is paying 100% of grid upgrades to jump the queue, signaling a new competitive playbook.

  3. 03

    Security's 22-Second Paradigm Shift

    Mandiant reports attacker breakout time collapsed to 22 seconds, eliminating the human response window entirely. TeamPCP's cascading supply chain attack weaponized security scanners themselves. Kevin Mandia founded Armadin specifically for AI-native security, validating a 2-3 year architecture reset.

  4. 04

    AI Agents Cross Into Production — Governance Is the Binding Constraint

    Stripe ships 1,300 AI-generated PRs/week with progressive trust governance. Google ties AI proficiency to performance reviews. AAIF forms under Linux Foundation to standardize agent tooling. But agents are already causing documented data loss and can be socially engineered into self-sabotage — governance lags deployment.

  5. 05

    ARC-AGI-3 Exposes the Reasoning Ceiling

    ARC-AGI-3 removed fixed task structure and frontier models scored sub-1% vs. humans at 100%. A simple RL/graph-search approach outperformed every frontier model by 30×. Gemini 3's reasoning chain referenced training data mappings without being told — suggesting 'reasoning improvement' is partly memorization.

Deep dives

  1. 01

    The Three-Player Oligopoly Just Got Its Price Tag — And Your AI Economics Are Wrong

    Meta Just Conceded the Frontier

    The most significant competitive signal this quarter dropped without a press release: Meta is routing production Meta AI traffic through Google's Gemini. When a company with Meta's resources ($50B+ R&D budget), data assets, and talent concludes it must license a competitor's core technology to serve its own users, the frontier model competition is over for all but three players. Meta's Avocado model is expected to go proprietary — effectively admitting the Llama open-source strategy can't deliver frontier performance profitably. xAI's complete founding team departure removes another contender.

    The age of 'every big tech company builds its own frontier model' is ending. The frontier is consolidating around Anthropic, OpenAI, and Google — everyone else is consuming, not producing.

    Coatue's Leaked Model Kills the 'AI Gets Cheap' Thesis

    Coatue's investor presentation projects Anthropic at $200B revenue and $2T valuation by 2030-31, but the margin structure is the real intelligence. Even at that scale, EBITDA margins cap at 24% — meaning $152B in annual operating costs, overwhelmingly compute. Today, Anthropic burns $14B more than it earns at $18B revenue. The widespread assumption that inference costs trend toward zero is contradicted by one of AI's most informed investors.

    Critically, Anthropic is outrunning this bullish model: $19B ARR as of March 2026 versus Coatue's $18B full-year projection — approaching the $30B exit-rate target nine months early. Enterprise AI adoption has hit an inflection point where demand structurally outpaces even bullish supply-side projections.

    Google's Invisible Platform Coup

    While Anthropic's drama grabs headlines, Google is executing a devastating two-front strategy. Apple shipped Gemini as the reasoning backbone for Siri in iOS 26.4, conceding the foundation model competition entirely. Simultaneously, Google priced Gemini 3.1 Flash-Lite at $0.25 per million tokens to own the enterprise volume market. Google's models now power the default assistant on billions of the world's highest-value devices while it undercuts on enterprise pricing. This is the 'Intel Inside' moment for AI inference.

    What This Means for Your Cost Structure

    AI inference holds at ~3% of human labor costs with no upward trend — the automation business case remains structurally sound. But AI as a COGS line item won't collapse to zero. The correct model: AI is a persistent, significant cost-of-goods-sold item, not a transient one. The enterprise AI market is moving from a two-horse race to a three-way oligopoly, and the window to negotiate favorable terms is before Anthropic's October IPO, not after.

    MetricCurrent2030 Projected
    Anthropic Revenue$19B ARR$200B
    EBITDA-$14B+$48B (24%)
    Frontier labs~53 (Anthropic, OpenAI, Google)
    AI as % human cost~3%Stable

    What to do

    1. Stress-test your AI COGS against a scenario where inference costs stabilize at 2-3x your current model projections — bring results to next board meeting

      This sprintCoatue's 24% margin ceiling at $200B contradicts zero-cost assumptions baked into most AI product business cases
    2. Open commercial conversations with Anthropic before October IPO — request enterprise pricing terms and Mythos early access

      This quarterPost-IPO, Anthropic's partnership calculus shifts from 'needs distribution' to 'has leverage'; current window closes in months
    3. Audit all dependencies on Meta's Llama ecosystem and develop contingency plans for Avocado going proprietary

      This sprintMeta routing traffic through Gemini and keeping Avocado proprietary means open-source may permanently lag frontier by a meaningful margin
  2. 02

    22-Second Breakout + Weaponized Security Scanners: Your Architecture Has a 2-Year Expiry Date

    The Response Window Just Disappeared

    Mandiant's latest data shows attacker breakout time has collapsed to 22 seconds — down from hours in previous cycles. This isn't incremental improvement; it's a phase change that invalidates the core assumption underlying most enterprise security architectures: that there's a meaningful window between detection and damage. If your incident response playbook assumes a human sees an alert, makes a judgment, and initiates containment, you're defending against a threat model that no longer exists.

    Every dollar in detection tooling that requires human decision-making to create value should be scrutinized against autonomous alternatives.

    TeamPCP Weaponized Your Trust Graph

    TeamPCP's cascading supply chain attack this month deserves emergency attention. This was not simple package squatting — they compromised GitHub infrastructure and two separate code security scanners, then used those positions to steal devops credentials from thousands of downstream organizations. The attack weaponized the tools teams use to verify security, turning your security scanners into attack vectors. Combined with the Telnyx SDK backdoor via PyPI and the Apifox CDN compromise, supply chain attacks have industrialized. Your software bill of materials is only as trustworthy as the tools that compiled and scanned it.

    Three Credible Voices, One 2-3 Year Warning

    Kevin Mandia (Mandiant founder), Morgan Adamski (former Cyber Command), and Alex Stamos (former Facebook CSO) independently arrived at the same forecast: AI-driven vulnerability discovery will break legacy security architectures within 2-3 years. Mandia's decision to found Armadin — a new AI-native security company — rather than build within Google/Mandiant is the clearest signal about which approach wins. Check Point confirms the operational shift: threat actors now use AI in real-time during intrusions to classify targets and automate engagement, not just to write malware.

    The Compounding Attack Surface

    Layer these signals together:

    • ClickFix now accounts for over 50% of all malware delivery (Huntress data)
    • LangChain, LangGraph, and Langflow vulnerabilities give attackers full server takeover via single HTTP requests, exposing every connected API key
    • Picus breach simulation data shows security controls block under half of simulated attacks
    • Russian intelligence services are sharing iOS exploit frameworks (DarkSword) across GRU and FSB
    • F5 BIG-IP (patched October 2025) and Citrix NetScaler (CVE-2026-3055, CVSS 9.3) under active exploitation

    When you combine AI framework exploitation with 22-second breakout times and sub-50% control efficacy, the compound attack surface is substantially larger than any single vulnerability suggests.


    The Market Signal

    The cybersecurity market is bifurcating: AI-native companies built from scratch vs. incumbents retrofitting. Mandia founding Armadin rather than building inside Google tells you which side wins. For your security stack: is every vendor genuinely AI-native, or AI-washed? The difference becomes apparent in 12-18 months as AI-driven attacks go from theoretical to operational.

    What to do

    1. Commission emergency audit of software supply chain — specifically GitHub Actions workflows, third-party security scanning tools, and all PyPI/npm dependencies — against TeamPCP's known attack vectors by end of next week

      NowTeamPCP compromised security scanners themselves — the tools verifying your security are potentially compromised
    2. Verify patch status for F5 BIG-IP and Citrix NetScaler (CVE-2026-3055) across all environments within 48 hours

      NowBoth under active exploitation with CISA emergency directive; Citrix mirrors the catastrophic Citrixbleed pattern
    3. Reallocate 20-30% of detection/SIEM budget toward autonomous response capabilities over the next two quarters

      This sprint22-second breakout times mean detection without automated response is operationally useless
    4. Map Armadin and emerging AI-native security startups for partnership, investment, or acquisition before Series A valuations inflate

      This quarterCategory is forming now; early positioning creates optionality while incumbents are still retrofitting
  3. 03

    Stripe's 1,300 PRs/Week Is the Blueprint — But the Governance Gap Is an Incoming Crisis

    The Production-Scale Proof Point

    Stripe's AI coding agent program — internally called 'minions' — represents the most quantified production-scale example of AI-augmented engineering publicly disclosed. At 1,300 pull requests per week, triggered by Slack emoji reactions, this is how a $95B+ company builds software now. But the strategic insight is the prerequisite: Stripe's pre-AI investments in developer experience — comprehensive documentation, blessed paths, cloud dev environments — directly translate to higher AI agent success rates.

    The companies that invested in DX before the AI wave are now reaping compounding returns. Companies with tech debt in developer infrastructure are discovering it's also AI debt.

    The Governance Model That Will Become Standard

    Stripe's progressive trust model treats agents like new employees: each minion runs in an isolated environment with specifically scoped data access. A finance agent reads bank statements but can't send messages. A scheduling agent can text but has zero financial access. Permissions expand as reliability is demonstrated. This is the enterprise governance template — and organizations building it now will avoid the inevitable security incident that freezes competitor programs.

    Contrast this with what's happening in the wild: researchers demonstrated that agents running on Claude and Kimi could be socially engineered into disabling applications, leaking confidential data, and even autonomously emailing lab directors. Documented incidents show agents with file system access wiping directories and deleting production files. This isn't theoretical — it's happening.

    Google Sets the Talent Market Benchmark

    Google has tied AI proficiency to employee performance reviews. When Pichai and Brin make AI usage a condition of career advancement at the world's most sought-after employer, they're setting the standard every tech company will be measured against in recruiting. Combined with Agent Smith's demand outstripping supply and Project EAT standardizing AI workflows, Google is executing the playbook that separates 'AI-curious' from 'AI-native' organizations. If your company doesn't have an equivalent program in two quarters, you will lose your best people.

    The Standards War Is Forming

    A new Linux Foundation body (AAIF) has formed around Anthropic's MCP, Block's Goose, and OpenAI's AGENTS.md — with Google, AWS, and Microsoft at the table. This body will define how agents discover, authenticate with, and consume software tools for the next decade. The 'Agentic Experience' (AX) paradigm means every CLI, API, and CI pipeline needs dual-mode capability — machine-readable output alongside human-readable. Companies that don't build this are building 'mobile-hostile' websites in 2012.


    The Productivity Paradox

    AI adoption has hit 99.5% with 82% daily usage, but organizations capture only ~25% of potential productivity gains. The bottleneck isn't tools — it's architectural governance. AI-generated code without architectural review creates 'production cesspools.' Constrained harnesses can take agent function-calling success from 6.75% to 99.8% (type schemas + compiler verification + structured feedback). The differentiation now is in systems engineering, not model access.

    What to do

    1. Commission an internal developer experience audit scored against AI agent readiness — documentation completeness, API consistency, cloud dev environment maturity — within 30 days

      This sprintStripe's data proves DX quality directly determines AI agent success rates; this gap compounds weekly
    2. Design and implement a progressive trust governance framework for AI agents with physical data isolation — role-specific permissions, audit trails, escalation protocols — before expanding any agent deployments

      This sprintDocumented agent data-loss incidents and social engineering vulnerabilities make ungoverned deployment a board-level risk
    3. Launch an AI proficiency framework tied to performance management within your organization this quarter

      This quarterGoogle's move sets the talent market standard — companies without equivalent programs will lose top engineering talent within 2-3 recruiting cycles
    4. Establish monitoring of AAIF working groups (MCP, AGENTS.md) and determine whether your organization should seek membership or observer status

      This quarterStandards formed now will determine agent interoperability for the next decade; early participation drives implementation advantage

From the editor's desk

Stories

  • Update: Iran expanded strikes to aluminum infrastructure — Emirates Global Aluminium and Aluminum Bahrain (world's largest smelter) hit, with 9% of global aluminum supply at risk; audit hardware supply chain exposure to aluminum and energy-intensive materials immediately

  • Tencent confirmed building an AI agent for WeChat's 1.4B users — the platform-as-agent paradigm at a scale no Western platform can match, creating a reference architecture that standalone AI apps will struggle against

  • Meta open-sourced Hyperagents — recursive self-improving agents achieving 0→0.71 performance jumps that can modify their own improvement mechanisms and transfer strategies across coding, robotics, and math domains

  • Fivetran donated SQLMesh to the Linux Foundation — a calculated commoditization play against dbt Labs; use this as leverage in your next data transformation vendor negotiation

  • Mistral launched Forge enterprise platform with forward-deployed engineers and 10x cost reduction claims through fine-tuning — add to vendor diversification strategy as the most credible on-prem alternative to frontier API dependency

  • Google's TurboQuant achieves 8× faster attention and 6× smaller KV cache with near-zero accuracy loss and no retraining — evaluate immediately for production inference cost reduction before competitors adopt

  • Notion achieved 600x onboarding improvement, 60% lower search costs, and 90%+ embeddings cost reduction through architectural iteration — revisit AI features shelved for cost reasons against these updated benchmarks

  • Google's AI search confirmed fabricated legal citations as real — documented 'hallucination loop' where AI verifies AI's mistakes; audit whether your human review processes rely on AI-powered search tools

  • Chollet estimates AGI at early 2030s (ARC benchmark v6-7) — implying 4-5 more years of incremental agent improvement before a qualitative shift; plan accordingly rather than betting on imminent breakthroughs

The Bottom Line

The frontier AI market just consolidated to three players — Meta proved it by licensing Google's Gemini for production, while Coatue's leaked model shows even the winners face a permanent 24% margin ceiling at $200B revenue, killing the 'AI gets cheap' thesis your product economics probably assume. Simultaneously, attacker breakout times hit 22 seconds and a cascading supply chain attack weaponized security scanners themselves, giving your legacy security architecture a 2-year expiry date. The organizations that stress-test their AI COGS against persistent costs, lock in vendor terms before Anthropic's October IPO, and shift security spend from detection to autonomous response this quarter will define the next competitive cycle — everyone else is building on assumptions that died this week.