Clarity · Edition

The Board Room

Tuesday, May 26, 202636 sources · 9 min read

The Signal

AI-assisted reverse engineering rendered all five major commercial EDR products

A skeptic will say one model on two ranges is not a trend, and the skeptic is correct until the next earnings call. The decision about whether detection sits at the endpoint or above it now belongs in this quarter's board pack, with a two-year consequence window attached.

Key intelligence

  1. 01

    Defensive Stack Becomes Transparent as AI Offense Hits Full Takeover

    TrustedSec found all 5 commercial EDRs share identical architecture now reverse-engineerable in days via LLM. Mythos cleared both AISI end-to-end cyber ranges. PraisonAI was weaponized within 4 hours of disclosure. Microsoft's MDASH runs 100+ coordinated agents finding 16 exploitable flaws per Patch Tuesday. The defensive moat was obscurity. Obscurity is gone.

  2. 02

    Agent Execution Layer War: Apple, SAP, and ServiceNow Collide

    Apple is gating AI agent distribution through the App Store this summer. SAP deployed €100M fund + Knowledge Graph for vertically integrated agents. ServiceNow adopted MCP as its agent communication standard. Agentic workloads hit 59% of all AI token volume. The contest is no longer which model wins — it's which platform owns the surface agents execute through.

  3. 03

    Anthropic's 80x Demand Spike Exposes AI Infrastructure Fragility

    Anthropic planned for 10x demand and got 80x — operating at ~12% of required capacity while degrading service without disclosure. xAI is leasing 45% of Colossus (220K GPUs) to Anthropic, conceding the frontier race. ServiceNow burned its full-year Anthropic budget by May. Revenue tripled from $9B to $30B ARR in four months. The vendor most enterprises are switching TO cannot yet reliably serve them.

  4. 04

    AI Liability Regime Crystallizing — 12-Month Window to Shape or Absorb

    a16z published the industry's most comprehensive liability blueprint. Courts are deciding AI cases now, before legislation exists. The ODNI vs Commerce fight determines whether pre-release evaluation becomes mandatory. Open-source AI is directly threatened by developer-liability frameworks. a16z deployed $115.5M into 2026 midterms to influence outcomes. Firms absent from drafting rooms will comply with rules they didn't write.

  5. 05

    Org Architecture Becomes Competitive Weapon — HI-IC Model Scales

    Lovable dissolved its growth management layer, replaced it with autonomous parallel contributors, and found it attracts elite VPs who voluntarily take IC roles. Cloudflare cut 20%, GitLab restructured, LinkedIn cut 5% — all citing AI. 103K tech cuts by mid-May approaching full 2024's 124K. The coordination cost that justified middle management is being eliminated by the same tools the managers were meant to deploy.

Deep dives

  1. 01

    Your EDR Just Became a Glass Box — The Detection Architecture Must Move Above the Endpoint

    The Defensive Moat Was Obscurity. It's Gone.

    TrustedSec pointed five LLMs at five commercial EDR products and discovered that all five are built the same way: YARA-style rules, behavioral logic, allowlists, prefilters, Lua-readable scripted engines, and local ML classifiers. The reverse engineering work that used to consume a skilled human for weeks now resolves in days with AI assistance. A reasonable skeptic would say this is one research shop and one method. The reasonable skeptic is correct. What the skeptic does not explain is why the entire endpoint security category was priced on obscurity in the first place, or why the cost of stripping that obscurity just fell by roughly an order of magnitude.

    The trend line confirms the direction. Anthropic's Mythos became the first model to clear both UK AISI end-to-end simulated attack ranges, including autonomous full network takeover. OpenAI's GPT-5.5-cyber cleared one of the two. Both results sit above what was already an exponential curve in AI cyber task completion, which the UK AISI describes as doubling every few months.


    The Exploitation Window Has Collapsed to Hours

    A PraisonAI vulnerability was weaponized within 4 hours of disclosure. In the same window, Microsoft's MDASH system, running 100+ coordinated AI agents, surfaced 16 exploitable flaws in a single Patch Tuesday. SANS noted that AI infrastructure tools — LiteLLM, Ollama, OpenClaw — now appear on CISA's Known Exploited Vulnerabilities catalog. Adversaries are targeting the AI routing layer that most organizations adopted without security review.

    A patch window measured in months because attackers needed months is now a patch window measured in months because procurement needs months. The attacker side moved. The defender side did not.

    The Compensating Controls That Matter

    The security model that priced in endpoint-agent obscurity as bought time has to be replaced with one that assumes the endpoint is transparent to a growing share of adversaries. The controls that earn their seat for the next 18 months are these:

    • Identity and blast radius — segmentation that limits what a compromised endpoint can reach
    • Network telemetry — detection above the endpoint layer, where the agent no longer provides cover
    • Behavioral analytics — correlation across signals the attacker cannot observe from the endpoint alone
    • Recovery time measured in hours — architecture that assumes breach and optimizes for restoration

    Palo Alto Networks' AI-driven scanning has already surfaced dozens of serious vulnerabilities across 130+ products. The same capability arriving in ransomware hands inside 12-18 months is the base case, not the tail. The Foxconn breach, with 8TB exfiltrated from Apple, Google, Intel, and Nvidia designs, says the supply chain hits are already landing at exactly the sites where AI hardware IP concentrates.

    What to do

    1. Commission red-team exercise specifically targeting your EDR with AI-assisted reverse engineering to quantify actual detection gap

      NowTrustedSec proved all 5 major EDRs fall to the same approach — you need to know your specific exposure before the technique proliferates further
    2. Restructure vulnerability response SLA to 72-hour maximum for critical internet-facing assets

      Now4-hour exploitation windows make 30-day patch cycles a known-exploitable state; 72 hours is the minimum defensible posture
    3. Invest in identity-based segmentation and network-layer detection as primary controls by Q4

      This sprintThe endpoint agent is no longer the load-bearing control — detection must move above the layer attackers can now read
    4. Evaluate Anthropic and OpenAI defensive cyber offerings for integration into security operations

      This quarterWithin 12-18 months this becomes an AI-vs-AI contest; organizations without frontier model integration in their defensive stack face an asymmetry headcount cannot close
  2. 02

    The Agent Execution Layer Is Being Claimed This Summer — Your Platform Position Sets the Next 3 Years

    Three Platforms, Three Architectures, One Quarter

    The enterprise software industry has, for once, agreed on the question, if not the answer. The next control point is the surface through which AI agents execute. SAP launched a €100M fund built around a vertically integrated Knowledge Graph, on the theory that owning the data universe makes its own agents contextually better than anyone else's. ServiceNow went the opposite direction and adopted MCP, the Model Context Protocol, as its standard for how agents talk to the platform. Apple, predictably, is preparing to gate agent distribution through the App Store and extend the 30% fee into the agent economy.

    These three bets are not reconcilable, and the positioning decision lands this quarter, not next year.

    PlatformTheoryLock-in Mechanism
    SAPData-moat integrationKnowledge Graph + process authority
    ServiceNowOpen interoperability via MCPWorkflow gravity across IT/HR/CS
    AppleDistribution gatekeeperOS-level agent default + approval gate

    59% of AI Traffic Is Already Agentic

    Vendor-published data deserves the usual discount, but the direction is hard to argue with. Vercel's production telemetry across 200K+ teams shows that more than half of AI API usage is now agents taking actions, not humans having conversations. a16z puts the number on the revenue side at $150 billion of go-to-market value migrating from traditional CRM to the AI orchestration layer, which is the kind of figure a venture firm produces and which is also probably directionally right. Google ships Gemini Intelligence on Android this summer with 97%+ market share in the relevant geographies, which makes the OS itself the agent surface whether anyone wanted that outcome or not.

    Agents that act across finance, HR, IT, and procurement need one authoritative place to reconcile state. Two authoritative places is zero authoritative places.

    The Pricing Model Breaks Simultaneously

    The Lemkin data point is the one to remember when the architecture conversation drifts back to abstractions: 80% fewer human seats, 83% higher total spend, 20+ agents running. Seat-based pricing cannot survive a world in which agents replace the humans those seats were sold to. SAP is already pricing around workflow execution rather than per-seat licensing. ServiceNow's headless architecture implies consumption-based pricing on agent API calls. The revenue model and the platform architecture turn out to be the same decision wearing two hats.

    The 81% agent bot bypass rate is the part the security teams have been quietly aware of for a year. Every WAF, CAPTCHA, and rate-limiting system built on behavioral patterns fails against agents that mimic human interaction, because that is what they were trained to do. The control point question and the security question converge on the same surface, which is the part most board decks still treat as separate.

    What to do

    1. Conduct agent-readiness audit of your platform — determine if third-party AI agents can discover, invoke, and orchestrate your workflows without a human UI

      This sprintBeing bypassed by agents is not disruption — it's invisibility. The window before agent routing tables calcify is 12-18 months.
    2. Evaluate MCP integration for your product and internal systems by end of Q3

      This sprintServiceNow legitimizing MCP at enterprise scale pulls the ecosystem toward it; early adopters get routing preference
    3. Model per-action/per-outcome pricing scenarios and pilot with 3-5 customers this quarter

      This quarterSeat-based pricing where agents replace seats creates a revenue ceiling that competitors will exploit
    4. Build Apple App Store agent compliance into your iOS roadmap before WWDC reveals the terms

      This quarterAgent behavior is harder to predict than a shipped binary; opaque approval process against unpredictable behavior is a roadmap tax that doesn't show up until a release slips
  3. 03

    The AI Vendor Everyone's Switching To Can't Handle the Load — Infrastructure Fragility Is Your Problem

    80x Against a 10x Plan

    Anthropic has conceded it grew 80x against a planned 10x, which is another way of saying it ran at roughly 12% of required capacity for extended stretches. Developers in that window got degraded service, rate limits, and quite possibly lower-quality model responses without disclosure. ServiceNow's CDIO has said publicly that the company blew its full-year Anthropic budget by May, and is now building AI Control Tower to sell the workaround to other enterprises. That is not a vendor partnership. That is the market routing around a vendor deficiency.

    The operational consequence is the part most executives are underweighting. Any engineering organization with production dependencies on Anthropic was taking degraded output for months. Productivity gains measured against that baseline are understated against what adequate provisioning would deliver.


    xAI Concedes the Frontier Race

    When Elon Musk, who publicly called Anthropic "misanthropic and evil," agrees to lease them 220,000 GPUs (45% of Colossus), the financial logic has overwhelmed the competitive logic. Grok never reached meaningful B2B or B2C traction. The lease revenue almost certainly exceeds what Grok could generate from those same GPUs. The population of viable frontier labs is contracting, and excess infrastructure is moving to the lease market.

    A provider that planned for 10x and got 80x was operating at roughly 12% of required capacity. The productivity gains measured in that period are very likely understated against what adequate provisioning would deliver.

    The Cost Governance Vacuum

    Anthropic does not offer SLAs, does not provide usage telemetry, and has no comment when enterprise customers publicly describe budget blowouts. Every major AI player is now admitting that deployment is human-intensive. Google is hiring hundreds of Forward Deployed Engineers. OpenAI acquired a 150-person consulting firm. ServiceNow and Salesforce are building FDE teams of their own. A program that needs 5-10 FDEs at $300-500K loaded cost each carries a true cost 3-5x the model fees.

    The Market Structure Is Not What It Was

    The numbers do most of the arguing. Anthropic: $30B ARR, raising at $900-950B, 120x growth in 24 months. Cerebras IPO at $56B with a 70% first-day pop. Microsoft has committed $100B+ to OpenAI. Nebius growing 684% with a 4:1 demand ratio. GPU supply is a financial instrument first and a strategic moat second. The firms shipping AI on schedule are the ones that locked capacity 12-18 months ago. Everyone else is operating at a structural handicap that does not resolve on its own.

    What to do

    1. Audit all AI model consumption spend vs. budget with per-team and per-use-case attribution by end of month

      NowServiceNow's experience — blowing annual budget by May — is likely replicated in your org if you lack granular telemetry
    2. Implement multi-model abstraction layer with under-48-hour switching capability

      This sprintThe provider that planned for 10x and got 80x will have capacity-driven degradation again; building swap capability during the current subsidy window preserves negotiating leverage
    3. Negotiate AI vendor contracts to include SLAs, usage telemetry, and committed pricing tiers

      This sprintAnthropic's enterprise immaturity is a known gap — lock in terms while both Anthropic and OpenAI are competing aggressively for enterprise commitments
    4. Model true AI program cost including FDE/services requirements at 3-5x model fees

      This quarterEvery major AI player converging on the Palantir FDE model means boards need realistic total-cost-of-ownership figures before approving expansion
  4. 04

    The AI Liability Regime Is Being Written Without You — Fund a Position or Fund a Defense

    Three Frameworks, One 18-Month Window

    The AI liability question is being settled in three places at once: the courts, Congress, and the regulatory agencies. The venture ecosystem has noticed, which is why it is spending $115.5M in 2026 midterm political donations on the outcome. a16z has published what amounts to the industry lobbying blueprint, with user-liability defaults and damages caps as the headline asks. Agree with the framework or not. The posture of the firms writing it is what determines compliance cost in 2028.

    The competing regimes do not produce variations on the same business. They produce different businesses.

    FrameworkWho PaysEffect on Market
    Product-liability (strict)DevelopersConsolidation toward deep pockets; open-source dies
    Safe harbor (with audits)Non-compliant actorsAudit infrastructure becomes table stakes
    User-liability presumptionDeployersIntegration quality becomes competitive moat

    Courts Are Moving Before Congress

    Active litigation against general-purpose AI tools could impose substantial penalties on developers for downstream user misuse well before any legislative framework exists. The likely sequence is precedent-setting rulings first, comprehensive federal law second, and a patchwork of judicial standards that subsequent legislation works around rather than replaces. Firms not watching those dockets are not managing the exposure.

    The ODNI vs. Commerce Fight Sets the Rules

    Inside the administration, the intelligence community wants a center inside ODNI for pre-release evaluation of frontier models. That is a licensing regime in everything but name. Commerce's alternative is voluntary agreements through CAISI, which preserves speed-to-market. A reasonable skeptic would call the difference cosmetic. The reasonable skeptic is wrong. An IC-led regime means release gating and classified compliance. A Commerce-led regime means disclosure obligations that are expensive but navigable. Those are not the same business model.

    If developer liability for downstream use becomes the standard, the economic logic of releasing an open-source model stops working. No rational actor open-sources a model that generates unbounded liability for every downstream application.

    Most product strategies in market today quietly assume continued access to open-weight models. That assumption is an unpriced dependency on regulatory outcomes the P&L does not show. The competitive moat for the next five years is the quality of the audit trail, the defensibility of the evaluation process, and the contractual allocation of residual risk with upstream vendors. The decision made in the next eighteen months sets the cost structure for the decade after.

    What to do

    1. Commission legal exposure audit against all three competing liability frameworks with quantified financial exposure under each

      This sprintCourts are deciding cases now that will set precedent before legislation arrives — you need to know your exposure across scenarios
    2. Begin building audit-ready AI governance infrastructure — model cards, safety testing documentation, incident reporting — that would satisfy proposed safe harbor requirements

      This quarterSafe harbor compliance will be table stakes regardless of which regime wins; building now is cheaper than retrofitting under enforcement pressure
    3. Evaluate open-source AI dependencies and develop contingency plans for a world where open-weight availability contracts

      This quarterDeveloper-liability frameworks make open-sourcing an uninsurable risk — most product strategies carry this unpriced dependency
    4. Engage in federal legislative process through industry coalitions before the framework hardens

      This quartera16z is spending $115.5M to shape rules that favor their portfolio — absence from the table means compliance with rules you had no hand in writing

From the editor's desk

Stories

  • Update: Cerebras IPO priced at $56B fully diluted with 70% first-day pop — the $20B OpenAI anchor commitment turned a regulatory cautionary tale into the most successful tech IPO in five years

  • Update: Sigstore provenance forgery is now a production capability — TeamPCP's Shai-Hulud extracts OIDC tokens from CI/CD runner memory and forges supply chain verification, compromising TanStack, UiPath, and Mistral AI npm packages

  • 85% of organizations spending millions on agentic AI lack adequate data foundations — the barrier is 95.2% organizational (ownership, training, standards) vs. 4.8% tooling, per PDC survey of 334 practitioners

  • Abridge raised at $5.3B to become healthcare's 'clinical intelligence layer' — 80M+ medical conversations create an irreplicable post-training corpus, with prior authorization compressed from 45 days to minutes

  • Update: H200 chip sales approved to 10+ Chinese companies as part of summit deal, but zero chips delivered; Tencent's CSO says domestic chips arriving 'month by month' — export leverage window closing faster than assumed

  • Fervo Energy IPO at $10B+ valuation with 33% first-day pop — Google's option for 3GW (enough for 60+ data centers) from a single geothermal supplier validates power as a platform business

  • Lovable dissolved its growth management layer and replaced it with autonomous parallel 'High-Impact ICs' — former VPs report 90% of time on building vs. coordination, attracting elite senior talent voluntarily taking IC roles

  • Two universal Linux LPEs (Dirty Frag + Copy Fail) affect every major distro since 2017 — Copy Fail modifies in-memory file copies without touching disk, invisible to all file integrity monitoring

  • OpenAI Daybreak launched with CrowdStrike, Palo Alto Networks, Cisco, Cloudflare, Zscaler, Akamai, Oracle, and Fortinet — the opening salvo of an AI platform war in cybersecurity

The Bottom Line

Your endpoint security just became transparent to AI-assisted attackers (days, not weeks to reverse-engineer all five major EDRs), your fastest-growing AI vendor can't handle the demand it's attracting (80x against a 10x plan), the platform that will own agent execution is being decided this summer by Apple, SAP, and ServiceNow simultaneously, and the liability regime that determines whether you or your AI vendor pays when things break is being written in courtrooms right now without most companies at the table. The two-quarter window to make architectural decisions on all four — detection posture, vendor concentration, platform positioning, and governance infrastructure — is open and closing.