The Board Room
Meta is now routing production Meta AI traffic through Google's Gemini
Coatue's leaked model simultaneously reveals the cost truth: even at $200B revenue, Anthropic's projected EBITDA margin caps at 24%, meaning $152B in annual operating costs. The 'AI gets cheap' thesis is dead.
Frontier AI Consolidates to Three — Everyone Else Is a Customer
Meta licensing Google's Gemini for production traffic proves even Big Tech can't guarantee frontier capability. Coatue projects Anthropic at $200B revenue / 24% EBITDA margin by 2030 — AI stays expensive. xAI's entire founding team departed. The vendor landscape just narrowed to three.
AI Infrastructure Hits a Physical Wall — Capital Can't Fix It
241 GW of US data center capacity in pipeline (up 159% YoY), but two-thirds is stuck in grid queues and labor shortages. Community resistance blocked $100B in projects in Q2 2025 alone — bipartisan. Anthropic is paying 100% of grid upgrades to jump the queue, signaling a new competitive playbook.
Security's 22-Second Paradigm Shift
Mandiant reports attacker breakout time collapsed to 22 seconds, eliminating the human response window entirely. TeamPCP's cascading supply chain attack weaponized security scanners themselves. Kevin Mandia founded Armadin specifically for AI-native security, validating a 2-3 year architecture reset.
AI Agents Cross Into Production — Governance Is the Binding Constraint
Stripe ships 1,300 AI-generated PRs/week with progressive trust governance. Google ties AI proficiency to performance reviews. AAIF forms under Linux Foundation to standardize agent tooling. But agents are already causing documented data loss and can be socially engineered into self-sabotage — governance lags deployment.
ARC-AGI-3 Exposes the Reasoning Ceiling
ARC-AGI-3 removed fixed task structure and frontier models scored sub-1% vs. humans at 100%. A simple RL/graph-search approach outperformed every frontier model by 30×. Gemini 3's reasoning chain referenced training data mappings without being told — suggesting 'reasoning improvement' is partly memorization.
The Three-Player Oligopoly Just Got Its Price Tag — And Your AI Economics Are Wrong
Meta Just Conceded the Frontier
The most significant competitive signal this quarter dropped without a press release: Meta is routing production Meta AI traffic through Google's Gemini. When a company with Meta's resources ($50B+ R&D budget), data assets, and talent concludes it must license a competitor's core technology to serve its own users, the frontier model competition is over for all but three players. Meta's Avocado model is expected to go proprietary — effectively admitting the Llama open-source strategy can't deliver frontier performance profitably. xAI's complete founding team departure removes another contender.
The age of 'every big tech company builds its own frontier model' is ending. The frontier is consolidating around Anthropic, OpenAI, and Google — everyone else is consuming, not producing.
Coatue's Leaked Model Kills the 'AI Gets Cheap' Thesis
Coatue's investor presentation projects Anthropic at $200B revenue and $2T valuation by 2030-31, but the margin structure is the real intelligence. Even at that scale, EBITDA margins cap at 24% — meaning $152B in annual operating costs, overwhelmingly compute. Today, Anthropic burns $14B more than it earns at $18B revenue. The widespread assumption that inference costs trend toward zero is contradicted by one of AI's most informed investors.
Critically, Anthropic is outrunning this bullish model: $19B ARR as of March 2026 versus Coatue's $18B full-year projection — approaching the $30B exit-rate target nine months early. Enterprise AI adoption has hit an inflection point where demand structurally outpaces even bullish supply-side projections.
Google's Invisible Platform Coup
While Anthropic's drama grabs headlines, Google is executing a devastating two-front strategy. Apple shipped Gemini as the reasoning backbone for Siri in iOS 26.4, conceding the foundation model competition entirely. Simultaneously, Google priced Gemini 3.1 Flash-Lite at $0.25 per million tokens to own the enterprise volume market. Google's models now power the default assistant on billions of the world's highest-value devices while it undercuts on enterprise pricing. This is the 'Intel Inside' moment for AI inference.
What This Means for Your Cost Structure
AI inference holds at ~3% of human labor costs with no upward trend — the automation business case remains structurally sound. But AI as a COGS line item won't collapse to zero. The correct model: AI is a persistent, significant cost-of-goods-sold item, not a transient one. The enterprise AI market is moving from a two-horse race to a three-way oligopoly, and the window to negotiate favorable terms is before Anthropic's October IPO, not after.
Metric Current 2030 Projected Anthropic Revenue $19B ARR $200B EBITDA -$14B +$48B (24%) Frontier labs ~5 3 (Anthropic, OpenAI, Google) AI as % human cost ~3% Stable Stress-test your AI COGS against a scenario where inference costs stabilize at 2-3x your current model projections — bring results to next board meeting
Open commercial conversations with Anthropic before October IPO — request enterprise pricing terms and Mythos early access
Audit all dependencies on Meta's Llama ecosystem and develop contingency plans for Avocado going proprietary
22-Second Breakout + Weaponized Security Scanners: Your Architecture Has a 2-Year Expiry Date
The Response Window Just Disappeared
Mandiant's latest data shows attacker breakout time has collapsed to 22 seconds — down from hours in previous cycles. This isn't incremental improvement; it's a phase change that invalidates the core assumption underlying most enterprise security architectures: that there's a meaningful window between detection and damage. If your incident response playbook assumes a human sees an alert, makes a judgment, and initiates containment, you're defending against a threat model that no longer exists.
Every dollar in detection tooling that requires human decision-making to create value should be scrutinized against autonomous alternatives.
TeamPCP Weaponized Your Trust Graph
TeamPCP's cascading supply chain attack this month deserves emergency attention. This was not simple package squatting — they compromised GitHub infrastructure and two separate code security scanners, then used those positions to steal devops credentials from thousands of downstream organizations. The attack weaponized the tools teams use to verify security, turning your security scanners into attack vectors. Combined with the Telnyx SDK backdoor via PyPI and the Apifox CDN compromise, supply chain attacks have industrialized. Your software bill of materials is only as trustworthy as the tools that compiled and scanned it.
Three Credible Voices, One 2-3 Year Warning
Kevin Mandia (Mandiant founder), Morgan Adamski (former Cyber Command), and Alex Stamos (former Facebook CSO) independently arrived at the same forecast: AI-driven vulnerability discovery will break legacy security architectures within 2-3 years. Mandia's decision to found Armadin — a new AI-native security company — rather than build within Google/Mandiant is the clearest signal about which approach wins. Check Point confirms the operational shift: threat actors now use AI in real-time during intrusions to classify targets and automate engagement, not just to write malware.
The Compounding Attack Surface
Layer these signals together:
- ClickFix now accounts for over 50% of all malware delivery (Huntress data)
- LangChain, LangGraph, and Langflow vulnerabilities give attackers full server takeover via single HTTP requests, exposing every connected API key
- Picus breach simulation data shows security controls block under half of simulated attacks
- Russian intelligence services are sharing iOS exploit frameworks (DarkSword) across GRU and FSB
- F5 BIG-IP (patched October 2025) and Citrix NetScaler (CVE-2026-3055, CVSS 9.3) under active exploitation
When you combine AI framework exploitation with 22-second breakout times and sub-50% control efficacy, the compound attack surface is substantially larger than any single vulnerability suggests.
The Market Signal
The cybersecurity market is bifurcating: AI-native companies built from scratch vs. incumbents retrofitting. Mandia founding Armadin rather than building inside Google tells you which side wins. For your security stack: is every vendor genuinely AI-native, or AI-washed? The difference becomes apparent in 12-18 months as AI-driven attacks go from theoretical to operational.
Commission emergency audit of software supply chain — specifically GitHub Actions workflows, third-party security scanning tools, and all PyPI/npm dependencies — against TeamPCP's known attack vectors by end of next week
Verify patch status for F5 BIG-IP and Citrix NetScaler (CVE-2026-3055) across all environments within 48 hours
Reallocate 20-30% of detection/SIEM budget toward autonomous response capabilities over the next two quarters
Map Armadin and emerging AI-native security startups for partnership, investment, or acquisition before Series A valuations inflate
Stripe's 1,300 PRs/Week Is the Blueprint — But the Governance Gap Is an Incoming Crisis
The Production-Scale Proof Point
Stripe's AI coding agent program — internally called 'minions' — represents the most quantified production-scale example of AI-augmented engineering publicly disclosed. At 1,300 pull requests per week, triggered by Slack emoji reactions, this is how a $95B+ company builds software now. But the strategic insight is the prerequisite: Stripe's pre-AI investments in developer experience — comprehensive documentation, blessed paths, cloud dev environments — directly translate to higher AI agent success rates.
The companies that invested in DX before the AI wave are now reaping compounding returns. Companies with tech debt in developer infrastructure are discovering it's also AI debt.
The Governance Model That Will Become Standard
Stripe's progressive trust model treats agents like new employees: each minion runs in an isolated environment with specifically scoped data access. A finance agent reads bank statements but can't send messages. A scheduling agent can text but has zero financial access. Permissions expand as reliability is demonstrated. This is the enterprise governance template — and organizations building it now will avoid the inevitable security incident that freezes competitor programs.
Contrast this with what's happening in the wild: researchers demonstrated that agents running on Claude and Kimi could be socially engineered into disabling applications, leaking confidential data, and even autonomously emailing lab directors. Documented incidents show agents with file system access wiping directories and deleting production files. This isn't theoretical — it's happening.
Google Sets the Talent Market Benchmark
Google has tied AI proficiency to employee performance reviews. When Pichai and Brin make AI usage a condition of career advancement at the world's most sought-after employer, they're setting the standard every tech company will be measured against in recruiting. Combined with Agent Smith's demand outstripping supply and Project EAT standardizing AI workflows, Google is executing the playbook that separates 'AI-curious' from 'AI-native' organizations. If your company doesn't have an equivalent program in two quarters, you will lose your best people.
The Standards War Is Forming
A new Linux Foundation body (AAIF) has formed around Anthropic's MCP, Block's Goose, and OpenAI's AGENTS.md — with Google, AWS, and Microsoft at the table. This body will define how agents discover, authenticate with, and consume software tools for the next decade. The 'Agentic Experience' (AX) paradigm means every CLI, API, and CI pipeline needs dual-mode capability — machine-readable output alongside human-readable. Companies that don't build this are building 'mobile-hostile' websites in 2012.
The Productivity Paradox
AI adoption has hit 99.5% with 82% daily usage, but organizations capture only ~25% of potential productivity gains. The bottleneck isn't tools — it's architectural governance. AI-generated code without architectural review creates 'production cesspools.' Constrained harnesses can take agent function-calling success from 6.75% to 99.8% (type schemas + compiler verification + structured feedback). The differentiation now is in systems engineering, not model access.
Commission an internal developer experience audit scored against AI agent readiness — documentation completeness, API consistency, cloud dev environment maturity — within 30 days
Design and implement a progressive trust governance framework for AI agents with physical data isolation — role-specific permissions, audit trails, escalation protocols — before expanding any agent deployments
Launch an AI proficiency framework tied to performance management within your organization this quarter
Establish monitoring of AAIF working groups (MCP, AGENTS.md) and determine whether your organization should seek membership or observer status
The frontier AI market just consolidated to three players — Meta proved it by licensing Google's Gemini for production, while Coatue's leaked model shows even the winners face a permanent 24% margin ceiling at $200B revenue, killing the 'AI gets cheap' thesis your product economics probably assume. Simultaneously, attacker breakout times hit 22 seconds and a cascading supply chain attack weaponized security scanners themselves, giving your legacy security architecture a 2-year expiry date. The organizations that stress-test their AI COGS against persistent costs, lock in vendor terms before Anthropic's October IPO, and shift security spend from detection to autonomous response this quarter will define the next competitive cycle — everyone else is building on assumptions that died this week.