Clarity · Edition

The Board Room

Thursday, May 7, 202637 sources · 6 min read

The Signal

OpenAI and Anthropic picked opposite futures this week

A reasonable skeptic would call the services arms they both launched a routine margin grab, and the skeptic is half right. The other half is that the vendor chosen last quarter is now deciding whether to compete with the customer, and the answer depends entirely on which vendor that was.

Key intelligence

  1. 01

    AI Labs Fork: Ads + Hardware vs. Finance + Compliance

    OpenAI projects $100B ad revenue by 2030 on 2.75B weekly users and is building a 30M-unit AI phone with dual-NPU architecture. Anthropic went opposite — $1.5B JV with Goldman/Blackstone/H&F for regulated financial services, explicit ad-free commitment. Both launched professional services arms that directly compete with enterprise AI teams and systems integrators.

  2. 02

    Pre-Release Government Vetting Creates Incumbency Moat

    The Trump administration reversed course and is building mandatory pre-release AI review, triggered by Anthropic's Mythos model generating national-security-grade cyber exploits. Google, Microsoft, and xAI already opted in voluntarily. CAISI completed 40+ evaluations on unreleased models. This adds 30-90 days to any frontier model release and structurally favors labs with deep government relationships.

  3. 03

    $1T Circular Financing: Systemic Counterparty Risk

    Google invests $40B in Anthropic. Anthropic commits $200B back to Google Cloud. Cloud backlog across hyperscalers hits $2T, majority AI. Oracle's backlog surging 438% on OpenAI alone. The loop holds only if reliability improves fast enough to convert enterprise pilots into revenue — and research shows reliability barely improved across 14 frontier models in 18 months.

  4. 04

    AI Security Emergency: MCP RCE + Mythos Exploit Window

    Anthropic's Model Context Protocol carries an RCE-by-design flaw across 150M+ downloads — every downstream AI framework inherited it. Simultaneously, Anthropic's Mythos model finds zero-day exploits surpassing skilled humans, with equivalent capabilities expected in the wild within 6-8 months. North Korean APTs are already targeting AI coding agents via slopsquatting attacks on hallucinated package names.

  5. 05

    AI-Native Org Flattening Becomes Board Expectation

    Coinbase formalized the template: 14% headcount cut, max 5 layers, no pure managers, one-person AI-augmented teams. Market rewarded it (+4%). The pattern is now standardized enough (Meta 2023 → Amazon 2024 → Coinbase 2026) that every board will ask for the equivalent plan. The real gap: 5x productivity for top-decile engineers vs. 20% for median — AI amplifies talent inequality.

Deep dives

  1. 01

    Your AI Vendor Just Became Your Competitor — And Chose a Side

    The Services Arms Race

    OpenAI has stood up "The Deployment Company," a $4B PE-backed services joint venture with 19 investors at $10B pre-money. Anthropic has stood up a $1.5B parallel venture with Blackstone, Goldman Sachs, and Hellman & Friedman. Both will acquire AI services firms, embed engineers inside customer environments, and compete directly with internal AI teams, systems integrators, and vertical SaaS. Brad Lightcap moved from COO to run OpenAI's enterprise push, which is how you signal that this is the central bet rather than a side project.

    The labs have decided the bottleneck to revenue is not model quality. It is implementation, and implementation is a service.

    The Business Model Fork

    The divergence is structural now, not incremental. OpenAI is becoming Google: $100M in advertising ARR within six weeks of launch, a projection of $100B by 2030 against 2.75B weekly users, and a 30M-unit AI-native phone targeting 2027-2028 with dual-NPU architecture. The play is consumer attention, advertising, and hardware lock-in. Anthropic is becoming Bloomberg: ad-free commitment, compliance-grade workflows, financial services templates wired to FactSet, S&P Global, Moody's, and Morningstar. The customer list already reads Goldman Sachs, Visa, Citi, AIG.

    Why This Fork Matters for the Vendor Decision

    An ad-funded model optimizes for attention and scale. A vertical-JV model optimizes for trust and compliance surface. Inside eighteen months those produce different roadmaps, different pricing behaviors, and different data-use incentives. Consumer-adjacent products get more leverage from OpenAI's advertising future. Regulated and enterprise workflows get structurally more from Anthropic's vertical future.

    The Hardware Pincer

    OpenAI's phone commitment — MediaTek Dimensity 9600, Luxshare manufacturing, cost-optimized mid-market — arrives alongside Apple's concession to open iOS 27 to rival AI models after paying $250M to settle a lawsuit over Siri features that "did not exist at the time, do not exist now, and will not exist for two or more years." Apple is becoming the marketplace. OpenAI is building the counter-device. A reasonable skeptic would note that every company currently building on the OpenAI API is a valued customer today. The skeptic is correct today. On the day the device ships, they are a competitor for attention on a surface where OpenAI has preferential access.

    A firm that is a partner in 2024 is a target in 2026 if the services arm decides the vertical is worth owning outright.

    What to do

    1. Classify each AI-dependent workstream as consumer-adjacent or regulated-enterprise and map it to the correct lab's trajectory by end of Q2

      This sprintThe business model divergence creates misalignment risk within 2-3 quarters if workloads are on the wrong platform
    2. Add competitive-services and data-use clauses to all AI vendor contracts before next renewal

      This sprintBoth labs' services arms will bid against their own customers' internal teams — contractual protections must be in place now
    3. Build or acquire agent orchestration capabilities independent of any single model provider within 6 months

      This quarterOrchestration is the only layer where durable value sits — model layer is commoditizing, services layer is being claimed by the labs
  2. 02

    The $1 Trillion Loop: Your AI Vendor's Revenue Is Its Own Investor's Backlog

    The Mechanics

    The structure is worth stating plainly, because the headline numbers obscure what is actually happening. Google invests $40B in Anthropic, of which $30B is compute credits. Anthropic commits $200B back to Google Cloud. Google books the commitment as backlog, which justifies $190B in annual capex, and the stock rises 2% on the news. Run that pattern across three hyperscalers and two AI startups and the committed cloud spend clears $1 trillion, sourced from companies whose continued existence depends on funding from the same cloud providers.

    The end demand underneath the current AI capex cycle is, in large part, the same three or four companies writing checks to each other.

    The Canary: Oracle

    A reasonable skeptic would point out that circular revenue is an old complaint and has been wrong before. The reasonable skeptic is correct, which is why Oracle matters. Oracle's backlog is growing at 438% year over year, driven almost entirely by OpenAI, which makes Oracle the cleanest early-warning instrument in the system. If Oracle's realization rate — actual recognized revenue against reported backlog — begins to miss, the most plausible reading is that OpenAI's consumption is lagging its commitments. That same dynamic would then be playing out at larger scale, and with more accounting cover, across Azure, GCP, and AWS.

    The Reliability Gap

    The commitments assume an adoption curve, the adoption curve assumes a reliability curve, and the reliability curve is the part with the least forgiving math. Research found reliability barely improved across 14 frontier models over 18 months. Anthropic's own data shows large gaps between theoretical capability and observed real-world usage. Only 15% of enterprises have the data foundation required to run agentic AI in production. The other 85% are funding pilots that will not survive contact with their own data estates.

    Three Scenarios Worth Carrying

    ScenarioTriggerConsequence
    BullReliability improves, adoption acceleratesCommitments validated, loop sustains
    BaseReliability drags, steady adoptionQuiet renegotiations, 15-25% equity correction
    BearEnterprise spending disappoints + rate pressureWrite-downs, backlog restatements, semiconductor cascade

    Most diversified portfolios carry exposure to this loop across semiconductor, hyperscaler, power/grid, and private credit lines simultaneously, without recognizing it as correlated risk. That is this quarter's oversight. It becomes next quarter's consequence when Oracle reports.

    What to do

    1. Commission a counterparty stress-test assuming 40-60% reduction in hyperscaler AI infrastructure spend — identify which vendor dependencies break

      This quarterThe loop is self-reinforcing on the way up and self-reinforcing on the way down; the time to model the downside is before it materializes
    2. Monitor Oracle's quarterly realization rate against backlog as the leading indicator for AI consumption vs. commitments

      WatchOracle is the most exposed single-counterparty canary — if consumption misses commitments there, it's happening everywhere
    3. Build a 'reliability-first' adoption thesis that assumes the capability-reliability gap persists 18-24 months — and budget accordingly

      This quarterEnterprise revenue conversion depends on reliability, not capability; budgets priced on capability curves will miss
  3. 03

    MCP's 150M-Download RCE and the 6-Month Exploit Window

    The Protocol Flaw

    Anthropic's Model Context Protocol, now the de facto wire protocol for AI agent communication, carries a remote code execution vulnerability that is architectural, not implementation-level. OX Security found that the STDIO core carries RCE-by-design, and the flaw propagates into every downstream implementation: IDEs, frameworks, developer toolchains, across 150M+ downloads. A reasonable skeptic would say this is the sort of finding that gets patched in a point release. The skeptic is wrong on the mechanism. Any framework that adopted MCP inherited the design, not a bug.

    MCP sits exactly where code execution capability meets model-directed action, the worst possible place for a systemic flaw to live.

    The Mythos Countdown

    Dario Amodei's public disclosure is unusually specific. Anthropic's Mythos model found thousands of exploitable vulnerabilities across banks and government systems, with a 6-8 month window before adversarial AI can weaponize them at scale. This is a named capability with a countdown attached. Equivalent capabilities are expected in the wild by early 2027. CISA accelerated policy in direct response, discussing compression from 14-day to 3-day patching windows, a 4.7x change in remediation velocity that the operating teams have not yet staffed for.

    Nation-State Targeting of AI Dev Tools

    North Korean APTs are now crafting malicious packages designed to exploit AI coding agents' tendency to hallucinate package names, a technique called 'slopsquatting'. They register the hallucinated names with malicious payloads and wait. The attack surface scales directly with AI coding adoption across Copilot, Cursor, and Claude Code. Most security teams have not modeled this because the vulnerability class is under 18 months old, which is roughly the age at which a threat stops being theoretical.

    CI Fortify: The Disconnection Mandate

    CISA's CI Fortify program instructs critical infrastructure operators to prepare for months of operation with IT networks, third-party vendors, and telecom all unavailable. That reverses the convergence assumption every OT architecture has been built on for 20 years. For vendors selling into utilities, defense, health, and government, the implication is specific: air-gapped operations and manual fallbacks are now table stakes, not edge cases.

    What to do

    1. Audit all MCP-based tooling and AI agent infrastructure adopted by engineering teams — map blast radius by end of week

      Now150M+ downloads means MCP is already inside your perimeter whether you deployed it deliberately or not; the flaw is architectural and inherited by all downstream implementations
    2. Stress-test patch management infrastructure against a 3-day SLA for critical vulnerabilities within 60 days

      This sprintCISA is signaling compression from 14 to 3 days — organizations that cannot validate, test, and deploy critical patches in 72 hours will run continuous compliance gaps
    3. Implement dependency validation and hallucinated-package detection for all AI coding agent usage before end of Q2

      This sprintNorth Korean APTs are actively exploiting slopsquatting; every team using AI coding tools without instrumentation has unknown exposure right now
    4. Assess product portfolio for disconnected-operation capability — flag any solution that fails without continuous connectivity for critical-infrastructure customers

      This quarterCI Fortify procurement requirements arrive within 12-18 months; products that cannot operate air-gapped will be designed out of refresh cycles

From the editor's desk

Stories

  • Apple paying $250M to settle Siri AI claims while opening iOS 27 to rival models — conceding model race, repositioning as AI marketplace aggregator across 1.5B devices

  • SubQ claims 12M-token context at 1/1000th compute cost using subquadratic attention — unverified but if even 50% holds, every RAG architecture decision becomes self-imposed constraint

  • DTCC tokenizing ETFs, Treasuries, and Russell 1000 equities by October 2026 with 50+ partners including BlackRock — $114T in liquid assets moving to blockchain-based records

  • ElevenLabs grew from $350M to $500M ARR in ~5 months on enterprise voice agents alone — voice AI crossed the commercial reliability threshold

  • Vision-based AI agents cost 45x more than API-based equivalents doing the same work — architecture choice, not model quality, determines agent unit economics

  • Google AI Overviews now appear in 84% of B2B queries; 51% of citations come from off-site platforms (Reddit + YouTube dominate) — decade of owned-property SEO value eroding

  • x402 agentic payments standard assembled unprecedented coalition (Visa, Mastercard, Stripe, Google, Amazon, Coinbase) — AI agents already settled $31B on Solana in 2025

  • Maryland dynamic pricing ban effective October 1 with 33 states following — any algorithmic pricing, surge model, or personalized offer faces regulatory exposure by 2027

  • Cerebras IPO closed 3x oversubscribed at $26.6B — OpenAI holds $10B+ contract, $1B loan, and equity options, effectively locking down inference supply chain

  • Onyx open-source deep research system ranks #1 on independent benchmark ahead of OpenAI, Gemini, and Perplexity — quality argument for proprietary research tools collapses

The Bottom Line

The two frontier AI labs chose opposite futures this week — OpenAI is becoming an advertising and hardware company, Anthropic is becoming a regulated financial institution — while both launched services arms that compete directly with the customers they serve. Meanwhile, the $1 trillion in circular financing holding the AI infrastructure boom together depends on a reliability curve that hasn't moved in 18 months, a 150M-download protocol flaw just exposed every AI agent framework to RCE, and the U.S. government quietly rebuilt the pre-release review regime it dismantled fifteen months ago. The vendor relationship you signed last year no longer describes the company on the other side of the contract.