Clarity · Edition

The Board Room

Saturday, April 11, 202641 sources · 8 min read

The Signal

Nearly half of planned 2026 US data centers are canceled or delayed due to power and

Your AI strategy is no longer constrained by model quality; it's constrained by whether the physical infrastructure you're counting on will exist. If you haven't locked in compute capacity for 2027–2028, model your roadmap at 60% of planned availability and start negotiating alternatives this quarter.

Key intelligence

  1. 01

    Compute Supply Hits Hard Ceiling — Custom Silicon Creates Lock-In

    ~50% of planned 2026 US data centers delayed or canceled. Amazon's $200B capex and $20B chip business is locking in workloads — 98% of top customers on Graviton. CoreWeave's $87.8B backlog is 65.6% concentrated in Meta + OpenAI, creating systemic fragility across the entire AI infrastructure layer.

  2. 02

    $2T SaaS Wipeout — Per-Seat Model Meets Agentic Displacement

    Software stocks trade below the S&P 500 for the first time in the modern era. $2T in market cap destroyed since September 2025. Perplexity's 50% monthly ARR growth to $450M via Plaid proves the agentic super-app thesis — one AI interface displacing multiple vertical SaaS products overnight.

  3. 03

    AI Agent Security Broken at Architecture Level — Not Patchable

    Research confirms 78% of LLM systems blindly execute malicious code. Claude Code's config file bypasses all guardrails. Apple Intelligence fell to prompt injection 76% of the time. DPRK supply chain attacks now span 5 package ecosystems simultaneously. These are design flaws, not bugs — the security model for AI agents doesn't exist yet.

  4. 04

    Chinese AI Surges to 30% Global Share — Open Models Hit Parity

    Chinese AI models went from 1% to 30% of global workloads in 18 months. GLM-5.1 hit #3 on Code Arena, surpassing Gemini 3.1 and GPT-5.4. Alibaba offers 1,000 free daily requests with 1M context. Benchmark credibility is collapsing — 70% sandbox vs. 6.5% real-world performance — meaning your model selection data is unreliable.

  5. 05

    Advisor Pattern Reshapes AI Economics — Cheap Executor + Expensive Reasoner

    Anthropic's advisor pattern (Haiku + Opus) doubled BrowseComp performance while cutting costs 11.9%. UC Berkeley found a 7B RL-trained model boosted GPT-5 performance by 72% on tax filing. Frontier intelligence is becoming a selectively consumed resource — running Opus on every token is now demonstrably overspending.

Deep dives

  1. 01

    The Compute Ceiling Is Real — And Your Cloud Vendor Is Becoming Your Competitor

    The Infrastructure You're Planning On May Not Arrive

    Nearly half of US data centers planned for 2026 are now delayed or canceled — driven by power grid limitations, permitting challenges, and local opposition (including armed violence against data center advocates). This isn't a temporary blip. It's a physics problem masquerading as a business story. Every AI initiative on your roadmap that assumes elastic compute availability needs stress-testing against a scenario where you get 60% of planned capacity.

    Set this against the demand side: Anthropic just expanded a deal for 3.5 gigawatts of Google TPU capacity through Broadcom that won't come online until 2027. Meta committed $135B in 2026 capex and still needs $21B from CoreWeave through 2032 because it can't build fast enough internally. OpenAI is measuring ambitions in gigawatts. The companies that secured capacity 18-24 months ago now hold a structural advantage that's nearly impossible to replicate.


    Amazon Is Playing a Different Game

    Andy Jassy's shareholder letter was a competitive declaration, not an earnings update. Three numbers matter: 98% of Amazon's top 1,000 EC2 customers now run on Graviton, the custom chip business hit $20B in revenue (doubled in ~2 months), and AWS AI reached $15B annualized — growing 260x faster than AWS itself at the same stage. Two unnamed customers tried to buy Amazon's entire Graviton supply for 2026.

    The strategic implication: Amazon isn't just reducing its Nvidia dependency — it's becoming a chip vendor. Jassy openly contemplated selling Trainium racks to third parties. If AWS becomes a direct chip competitor while hosting your AI workloads, your vendor relationship has fundamentally changed. Google's commitment to future Intel data center chips signals even hyperscalers want supply chain diversification.

    The era of assuming infinite elastic compute is ending — it's now subject to energy physics rather than software scaling.

    The CoreWeave Concentration Risk No One's Pricing

    CoreWeave's $87.8B revenue backlog sounds impressive until you see the concentration: 40.1% from Meta and 25.5% from OpenAI — 65.6% from two customers. The company lost $1.17B on $5.13B revenue in 2025 and just raised $1.75B in debt to keep building. If Meta builds more internal GPU capacity (which their $135B capex suggests), or OpenAI diversifies compute sourcing, CoreWeave's economics shift dramatically. That disruption cascades to every service running on their infrastructure.

    Three competing compute strategies are emerging: Amazon is building ($200B capex, custom silicon), Meta is renting ($35B to CoreWeave, $27B to Nebius), and OpenAI is retreating from global infrastructure despite raising $122B. The right answer almost certainly varies by use case, but few companies can pursue all three paths. Your compute strategy needs a clear thesis on which model matches your workload profile — and a contingency plan for when the market shifts.

    What to do

    1. Audit all cloud AI capacity contracts and model 2027 roadmap at 60% of planned compute availability by end of Q2

      Now50% of planned data centers may not arrive; unexamined assumptions about elastic compute will crater timelines
    2. Open parallel negotiations with AWS on Trainium/Graviton and Google on TPU pricing within 30 days to build multi-vendor optionality

      NowTwo unnamed customers tried to corner Amazon's entire 2026 Graviton supply — demand is outstripping availability
    3. Map your CoreWeave exposure (direct and indirect through vendors) and develop a multi-provider hedging strategy this quarter

      This sprint65.6% backlog concentration in two customers creates systemic fragility for the entire GPU infrastructure layer
    4. Add energy and power procurement to your strategic risk register and evaluate direct power procurement options for any owned/leased data center capacity

      This quarterPower is the new moat — companies that secure energy supply will determine the pace of AI deployment
  2. 02

    The $2 Trillion SaaS Reckoning — Per-Seat Pricing Meets Agentic Displacement

    Software's Premium Is Gone

    For the first time in the modern era, software stocks trade at a discount to the S&P 500. Since September 2025, $2 trillion in market capitalization has evaporated from the software sector. This isn't cyclical — the market is making a structural statement: the per-seat recurring revenue model that justified 10-20x revenue multiples for two decades has a terminal diagnosis.

    The mechanism is specific: AI agents sever the link between customer headcount growth and revenue growth. When agents replace seats rather than complement them, every customer expansion becomes a potential contraction. Net revenue retention — the metric that separated great SaaS from good SaaS — is now structurally at risk. Palantir dropped 8% ($8-9B in market cap) on a single social media post from Michael Burry claiming Anthropic was displacing its analytics platform.


    Perplexity Just Proved the Agentic Super-App Thesis

    Perplexity's Plaid integration is the clearest proof of concept. In six weeks, the company added financial data connectivity across 12,000+ banks, autonomous tax filing, and natural-language financial planning. Result: ARR jumped 50% in a single month to $450M. The pattern is devastatingly simple: connect an AI agent to an authenticated data API, and users accomplish in one conversational interface what previously required three or four dedicated apps.

    This pattern extends far beyond fintech. Health records via FHIR, enterprise data via Salesforce APIs, logistics via shipping platforms — the Perplexity playbook is a template for horizontal disruption of vertical software. Meanwhile, Mutiny killed its entire working SaaS product to rebuild around autonomous agents, and 30%+ of Vercel deployments are now agent-initiated. The category isn't being disrupted from the outside — it's being absorbed.

    The question isn't whether your vertical SaaS faces displacement — it's whether your product survives as a standalone experience or becomes a data layer inside someone else's AI platform.

    AI Search Creates Winner-Take-All Discovery

    New behavioral data from Google AI Mode research quantifies the displacement: 74% of users select the #1 AI-recommended result, with an average chosen rank of 1.35. 88% adopt AI shortlists without any independent verification. And 64% complete purchases without ever leaving the AI interface. There is effectively no position two. Combined with Google's incoming Universal Commerce Protocol — which embeds conversational attributes into product feeds — AI agents, not humans, are becoming the primary product discovery interface.

    For any company dependent on digital discovery: your brand narrative in AI systems is now as strategically important as your brand narrative in earned media. 37% of purchase decisions are driven by how the AI describes you. Almost no company has built the capability to monitor or optimize this. This is the most urgent capability gap in digital go-to-market today.

    What to do

    1. Model revenue trajectory under scenarios where AI agents reduce customer headcount by 20%, 40%, and 60% over 3 years — present to board by end of Q2

      This sprintPer-seat revenue model is being structurally unwound; stress-testing quantifies exposure before the market forces it
    2. Conduct an 'agentic displacement audit' — identify every product line where an AI agent with API access replicates 80%+ of the value proposition

      This sprintPerplexity proved the pattern works; the template applies to every vertical with API-accessible data
    3. Commission an AI search visibility audit across Google AI Mode and ChatGPT for your top 50 commercial queries by end of month

      This sprint74% select #1 and 88% never verify — if you're not the AI's recommendation, you're invisible
    4. Flag any multi-year contracts with traditional SaaS GTM vendors for renegotiation this quarter

      This quarterMutiny's pivot signals the GTM software category itself is being restructured; avoid locking into transitional tools
  3. 03

    AI Agent Security Is Broken at the Architecture Level — And the Market Just Shipped Anyway

    This Isn't a Bug — It's a Design Flaw

    Three independent research findings this week converge on a devastating conclusion: the security model for AI agents doesn't exist. It's not that agents have vulnerabilities — it's that the foundational patterns for how agents establish trust, process inputs, and interact with each other are architecturally flawed.

    • 78% of tested LLM systems executed harmful code from compromised agent packages without detection
    • Claude Code's config file (Claude.md) is trivially exploitable — malicious prompts placed in this repository file bypass all safety guardrails. Anyone with commit access can inject instructions.
    • Apple Intelligence fell to 76 of 100 prompt injection attempts — using nothing more sophisticated than Unicode right-to-left text overrides
    • Subliminal prompts embedded in one AI agent's output propagate to and execute on other agents in multi-agent conversations — spreading, as researchers describe it, like a virus

    These aren't edge cases that will be patched. The design pattern of trusting config files, the absence of agent-to-agent authentication, and the lack of output sanitization in multi-agent systems are foundational architectural choices that require redesign, not patches.


    Supply Chain Attacks Have Gone Industrial

    North Korean actors are now simultaneously operating across five package ecosystems: npm, PyPI, Rust Crates, Go Packages, and Packagist. This isn't one group exploiting one ecosystem — it's state-sponsored, industrial-scale poisoning of the entire open-source supply chain. The Smart Slider WordPress compromise demonstrated the speed: a 6-hour window of vendor access turned into thousands of compromised sites through automated update mechanisms.

    Separately, hardcoded Google API keys in Android apps — originally scoped for non-AI services — now silently authenticate to Gemini endpoints, exposing developer resources to anyone who can decompile an APK. Speed of delivery, which engineering orgs have optimized for, is now the adversary's advantage.

    The first major AI agent security incident will rewrite the enterprise risk calculus overnight — and the research says it's a matter of when, not if.

    The Governance Infrastructure Gap

    The surreal reality: companies that can't secure their own AI products are racing to sell AI-powered security to others. Both Anthropic and OpenAI launched cybersecurity agent offerings this cycle. Meanwhile, the Akamai/Cloudflare-backed Agent Name Service (ANS) protocol acknowledges that AI agents need identity, authorization, and governance infrastructure that simply doesn't exist yet.

    HackerOne pausing its Internet Bug Bounty program because AI-generated low-value reports overwhelmed volunteer triage previews a compounding problem: as AI tools make it easier to find vulnerabilities, the volume of disclosures will overwhelm vendor response processes. Your patching cadence is about to become a competitive differentiator — companies that compress the time from disclosure to deployed patch to hours, not weeks, will be structurally more resilient.

    What to do

    1. Launch an emergency red-team assessment of all deployed or planned multi-agent AI systems — specifically test for prompt injection propagation and malicious package execution — within 30 days

      Now78% of systems are proven vulnerable; this is an active, exploitable architectural flaw, not a theoretical risk
    2. Audit all AI tool plugins and extensions across engineering for data collection scope — specifically Claude Code config files, prompt logging, and bash command capture — this sprint

      NowVercel plugin collected all prompts/commands regardless of relevance; your IP exposure is likely unquantified
    3. Mandate FIDO2 hardware key deployment for all privileged access and begin broader rollout by end of Q2

      This sprintMFA is being systematically defeated through clipboard theft, session hijacking, and adversary-in-the-middle attacks; only FIDO2 remains reliable
    4. Engage with the Agent Name Service (ANS) initiative and evaluate participation in the standard's development this quarter

      This quarterAkamai and Cloudflare backing signals ANS could become the DNS of the AI agent era — early positioning matters

From the editor's desk

Stories

  • Update: Post-quantum timeline — CalTech/Oratomic and Google Quantum AI reduced cryptography-breaking qubit threshold from millions to ~10,000, making viable quantum machine possible before 2030; Google already executing accelerated PQC migration

  • Gen Z AI sentiment collapsed: excitement down 14 points to 22%, anger up to 31% — even among daily AI users — creating political fuel for aggressive regulation within 18 months

  • AlphaEvolve delivered 97% compute cost reduction and 6.8x speedup in Substrate's semiconductor lithography stack — AI compressed years of algorithmic optimization into weeks, potentially disrupting ASML's $300B+ EUV monopoly

  • DOJ requests $149M for zero-trust migration (285% increase over ~$38.7M baseline) — explicitly warns identity provider, cloud network broker, and endpoint detection for 275,000 endpoints will stall without funding

  • Joint FBI/NSA/CISA alert: 5,219 internet-exposed Rockwell PLCs under Iran-linked targeting across US energy, water, and government — many reachable via cellular networks with end-of-life software

  • Adobe Reader zero-day actively exploited 5+ months with no patch — targets energy sector with adaptive payloads that profile victims before selecting between RCE and sandbox escape; block IOC 188.214.34.20 immediately

  • Defense tech startups pushing physical AI base salaries to $300K–$500K (before equity), creating structural talent drain from AV and robotics — Waymo described as 'price insensitive' while mid-stage startups face retention crisis

  • 80% of white-collar workers bypass company-sanctioned AI tools — Citigroup cut account-opening from 60 to 15 minutes by embedding AI into existing workflows rather than adding new tools

  • OCC charter race: 11 companies filed for bank charters in 83 days (Circle, Ripple, BitGo, Fidelity, Morgan Stanley) — but 76% of neobanks remain unprofitable and only lending-book models survive (Nubank: 85% interest income)

  • Startup CFO signal: 63% now rank AI adoption as #1 issue with spend doubling YoY — primary workforce impact is eliminating junior hiring (not layoffs), creating a 3–5 year senior talent pipeline crisis

The Bottom Line

The AI industry hit three hard walls this week: 50% of planned 2026 data centers won't arrive on time, software stocks fell below the S&P 500 for the first time ($2T destroyed since September), and independent research proved AI agent security is architecturally broken — 78% of systems blindly execute malicious code while 76% of prompt injections bypass Apple Intelligence. Meanwhile, Chinese AI models surged from 1% to 30% of global workloads in 18 months and open models hit frontier coding parity. The race is no longer about who has the best model; it's about who has guaranteed compute, revenue models that survive the death of per-seat pricing, and governance infrastructure for agents that won't be trivially compromised.