Clarity · Edition

The Board Room

Friday, May 29, 202636 sources · 7 min read

The Signal

Two load-bearing security assumptions failed in the same seven days.

Anthropic's Mythos cleared both UK AISI end-to-end cyber ranges this week, a first, while TrustedSec showed that all five tested commercial EDR products can be reverse-engineered in days with LLMs, and share identical architectural patterns. Patch SLAs that assumed weaponization was the slow step now budget in hours.

Key intelligence

  1. 01

    Defensive Security Architecture Loses Three Pillars Simultaneously

    AI achieves full network takeover (not just persistence), EDR products are transparent to LLM-assisted reversing in days, and Sigstore provenance forgery breaks supply chain trust anchors. The 4-hour exploit window on PraisonAI confirms patch cadences calibrated for days are now exposure windows.

  2. 02

    Enterprise 'Execution Layer' Platform War Begins

    SAP (€100M fund + Knowledge Graph) and ServiceNow (Action Fabric via MCP) are both claiming the surface AI agents call. a16z estimates $150B of GTM value migrating from CRM to the orchestration layer. Apple is positioning as agent gatekeeper. The 12-18 month window to choose which platform your workflows route through is open now.

  3. 03

    AI Infrastructure Financializes — Compute Becomes Pre-Sold Asset

    Cerebras IPO at $56B (70% first-day pop) backed by OpenAI's $20B commitment. xAI leasing 45% of Colossus to Anthropic signals compute is now a financial instrument. Fervo Energy IPO at $10B+ (33% surge) confirms power as platform business. Microsoft's $100B OpenAI spend disclosed via court documents.

  4. 04

    Enterprise AI Cost Governance Vacuum Exposed

    ServiceNow blew its full-year Anthropic budget by May. Anthropic planned for 10x demand and got 80x, degrading service for paying customers. Only 15% of organizations have data foundations for agentic AI. Every major AI vendor now admits deployment requires expensive FDE layers at $300-500K loaded cost each.

  5. 05

    Org Design Disruption: The Management Layer Question

    VPs are voluntarily taking IC roles at AI-native startups. Lovable dissolved its growth management layer and found it attracts elite talent. One operator ships in hours what cross-functional squads shipped in weeks. The economic case for coordination-only management is collapsing as AI compresses that cost to near zero.

Deep dives

  1. 01

    Your Security Architecture Just Lost Three Load-Bearing Assumptions in Seven Days

    The Convergence That Matters

    Three independent security assumptions failed this week. Each one in isolation is manageable. Together they constitute an architectural revision, not a patch cycle. The board-deck version says raise the security budget. The complete version says the operating model has to change before the budget question becomes useful.

    The cost of understanding your EDR agent exceeded the value of bypassing it for most adversaries. That premise is no longer true for a growing share of the threat population.

    Assumption 1: EDR Obscurity Buys Time

    TrustedSec ran LLMs against five commercial EDR products and found all five share identical architectural patterns: YARA-style rules, behavioral logic, allowlists, prefilters, scripted engines (some readable as Lua after a single decryption pass), and local ML classifiers. Work that took a skilled reverser weeks now takes days. The population of attackers capable of this expanded by an order of magnitude, and the bypass refresh cycle moved from quarters to days.

    Assumption 2: Weaponization Is the Slow Step

    AISI confirmed Anthropic's Mythos became the first model to clear both end-to-end cyber ranges: full network takeover, not just persistence. OpenAI's GPT-5.5-cyber cleared one. Palo Alto Networks' AI-driven scanning surfaced dozens of serious vulnerabilities across 130+ products. A 4-hour exploit window on PraisonAI confirms the new baseline. The 30-day patch SLA was calibrated for attackers who needed 30 days. They no longer do.

    Assumption 3: Supply Chain Verification Works

    The TeamPCP/Shai-Hulud framework forges Sigstore provenance, extracts OIDC tokens from CI/CD runner memory, and persists through AI coding tools. It has already compromised npm packages for TanStack, UiPath, and Mistral AI. Foxconn separately lost 8TB of IP from Apple, Google, Intel, and Nvidia through a single breach. The trust anchor for software supply chain verification is now an attack surface.


    The Compensating Controls That Matter

    The endpoint agent is no longer the load-bearing control. The compensating controls for the next 18 months are identity (blast radius), network telemetry (behavioral analytics above the endpoint), and recovery architecture (hours, not weeks). OpenAI's Daybreak launch with CrowdStrike, Palo Alto, Cisco, Cloudflare, and four others signals the platform war for AI-native defense has begun. The question this quarter is whether defensive AI sits inside the firm or is rented from the vendor that shipped the offensive capability. That choice sets the dependency map for the next several years.

    Where Sources Diverge

    The intelligence community, with Congress routing Mythos access through NSA over CISA, has prioritized offense. The private sector is on its own for defensive AI for several years. A reasonable skeptic would say benchmark jumps outrun operational reality. The 4-hour PraisonAI window says otherwise.

    What to do

    1. Commission red team exercise targeting your EDR with AI-assisted reverse engineering — surface the actual detection gap before adversaries do

      NowAll five tested EDR products share identical architecture patterns that are now transparent to LLMs. Your detection baseline is almost certainly lower than your last pen test suggested.
    2. Compress critical vulnerability patch SLA from 30 days to 72 hours for internet-facing assets

      Now4-hour exploit windows mean your current patch cadence is an exposure window, not a remediation timeline.
    3. Audit all CI/CD pipelines for OIDC token exposure, GitHub Actions cache poisoning, and Sigstore provenance trust assumptions

      This sprintSigstore forgery means supply chain verification most boards were told to trust is, in current form, theater.
    4. Evaluate kernel-level isolation (Firecracker microVMs, gVisor) for CI/CD and multi-tenant workloads by end of Q3

      This quarterCopy Fail LPE modifies in-memory file copies without touching disk — invisible to every file integrity monitoring product. Affected every major Linux distribution since 2017.
  2. 02

    The Execution Layer War: Where AI Agents Live Determines Who Captures the Next Decade

    The Decision Being Forced

    Three of the largest enterprise platforms used the same quarter to announce that the UI-centric era is ending. SAP's Autonomous Enterprise, ServiceNow's Action Fabric, and Salesforce's Agentforce are not competing features in any meaningful sense. They are three different bets on who owns the surface that AI agents call. The settled question is which software humans use. The open question is which API agents invoke.

    Agents that act across finance, HR, IT, and procurement need one authoritative place to reconcile state. Two authoritative places is zero authoritative places.

    Two Incompatible Architectures

    DimensionSAPServiceNow
    StrategyVertically integrated Knowledge GraphOpen Action Fabric via MCP
    Moat thesisData superiority inside SAP's universeProtocol adoption across all systems
    Agent modelSAP's agents are contextually superiorAny agent can call ServiceNow
    BetData moat integrationOpen interoperability wins

    ServiceNow adopting MCP (Model Context Protocol) as the communication standard pulls the rest of the ecosystem toward that protocol. A company with workflow gravity across IT, HR, and customer service declaring that agents talk to it via MCP is a legitimization event for the protocol itself. SAP is playing a different game. The bet is that its own agents will be so contextually superior inside SAP's data universe that customers never reach for an external orchestrator.

    The $150B Value Migration

    a16z estimates more than $150 billion of GTM value is migrating from CRM to the AI orchestration layer. The thesis is that whoever owns the reasoning layer synthesizing across CRM, email, calls, telemetry, and billing becomes the new system of record. The Lemkin data point makes the abstraction concrete: 80% fewer human seats, 83% higher total spend, 20+ agents running. Consumption-based AI pricing is already dramatically accretive against seat-based models.

    The Platform Tax Arrives

    Anthropic's June 15 pricing restructure separates first-party from third-party usage. Third-party tools like Cursor and Zed get capped credits, then API rates. This is a platform tax in everything but name. Notion launched a developer platform positioning Claude and Codex as "teammates" on Notion infrastructure. Intercom rebranded entirely to "Fin." A reasonable skeptic would call this rebranding theater, and on a single-quarter view the skeptic is correct. The pattern across all three moves is consistent: the agent-hosting platform is the next defensible category, and the hosting decisions are being made now, while the market is still fluid.

    The 12-18 Month Window

    Startups are reportedly shipping agentic fabric faster than Salesforce and ServiceNow. That window closes when the incumbents' API-first AI offerings mature. Any platform whose roadmap still assumes a human-in-the-UI is the primary consumer has roughly 12-18 months before agents route around it rather than through it. Being bypassed is not disruption. Disruption leaves a seat at the table. Bypass does not.

    What to do

    1. Conduct an 'agent readiness' audit — determine whether third-party AI agents can discover, invoke, and orchestrate your workflows without a human UI

      This sprint59% of AI traffic is now agentic. Products without agent-compatible APIs will be bypassed on the same clock that sites without SEO were bypassed by search.
    2. Evaluate MCP as a strategic standard for your platform roadmap — build or integrate MCP server capabilities by end of Q3

      This quarterServiceNow's adoption legitimizes MCP at enterprise scale. Being discoverable via this protocol is becoming the minimum for agent-mediated workflows.
    3. Model consumption-based pricing scenarios and pilot with 3-5 customers this quarter if you sell seat-based software touching GTM workflows

      This quarter80% seat reduction + 83% spend increase demonstrates the new model already works. Customers will ask why they're paying for seats their agents made redundant.
    4. Stand up an AI governance function with authority over tool/vendor rationalization before Q3 budgeting

      This sprint81% AI agent bot bypass rate means security architectures designed for human adversaries are already obsolete. Governance cannot lag deployment by another quarter.
  3. 03

    AI Infrastructure Is Being Pre-Sold in $10B+ Blocks — The Spot Market Assumption Just Died

    The Market Structure Shift

    Cerebras opened day one at a $56 billion fully diluted valuation, priced sixteen percent above a range that was already generous, and closed the session up seventy percent. The proximate cause was OpenAI's $20 billion procurement commitment in December 2025, which converted a regulatory cautionary tale into the best-performing tech IPO in five years. A single anchor buyer did the work an entire roadshow used to do. The signal worth taking seriously is that frontier AI compute is now allocated through relationship-based bilateral commitments rather than open-market clearing.

    The marginal unit of frontier AI capacity now has a named buyer for the rest of the decade, and that buyer is not you.

    xAI Concedes — Compute Becomes Financial Instrument

    Elon Musk, who recently described Anthropic in public as "misanthropic and evil," has agreed to lease them 220,000 GPUs (45% of Colossus 1). The financial logic outran the competitive logic, which is what tends to happen once Grok fails to find traction and the lease revenue clears what those GPUs would earn running inference. The population of viable frontier labs is contracting, and excess infrastructure is moving onto the lease market. Enterprise compute economics will feel that over the next twelve to eighteen months.

    Energy Infrastructure Validates as Platform Business

    Fervo Energy went public at a $10B+ valuation with a thirty-three percent first-day move, and the demand story was AI datacenter load, not decarbonization. Google holds an option for 3 gigawatts against the 658 MW currently under contract, which at fifty megawatts per large facility implies sixty-plus datacenters out of one supplier. Power contracts signed this year set competitive position in 2028 through 2030. Community resistance is now numerate — four thousand complaints against a single project, states drafting outright bans — which means permitted, interconnected capacity trades at a scarcity premium that is still rising.

    The $100B Disclosure

    Microsoft's commitment to OpenAI, surfaced through the Musk lawsuit at over $100 billion by June 2026 with thirty billion of direct revenue offsetting it, is the cleanest read on what frontier model participation actually costs. OpenAI has committed another $280B to Microsoft servers on top. Fewer than five companies on earth can carry that math. If the best-positioned buyer in the world is paying this, every other buyer is looking at a floor rather than a ceiling.

    Where Sources Diverge

    One reading says the xAI lease and the Cerebras print together ease compute scarcity as excess capacity reaches the market. The other says bilateral lock-ups at ten to twenty billion dollars leave 2026 buyers with access but not 2024 pricing. Both are correct for different tiers of buyer, which is why the procurement discipline now required of CIOs looks like the discipline energy and semiconductor buyers adopted a decade ago.

    What to do

    1. Audit compute capacity contracts and model the cost of 12-18 month lock-in versus spot pricing exposure — present options at next board meeting

      This sprintThe assumption that capacity would be available at some price when workloads show up is the line item being deleted. 4:1 demand-to-supply ratio is the operating condition, not a distortion to wait out.
    2. Explore whether becoming a 'transformational customer' for an emerging AI chip or infrastructure company could secure strategic advantage

      This quarterCerebras achieved $56B valuation on a single $20B commitment. Smaller commitments to emerging providers may unlock preferential access and economics.
    3. Secure long-term power supply agreements or partnerships for any planned AI infrastructure expansion

      This quarterFervo's $10B validation and community opposition to datacenters mean power and permitted sites are becoming binding constraints with multi-year lead times.
    4. Accelerate M&A conversations with AI infrastructure targets before IPO window fully reprices expectations

      This quarterTiger Global's 249% return in 8 months on Cerebras will pull capital into AI infrastructure faster, inflate private valuations, and give targets credible IPO alternatives.

From the editor's desk

Stories

  • Update: Anthropic reached $30B ARR (up from $9B in ~4 months), 120x growth in 24 months on $75B total capital raised — the revenue curve tripled without typical signs of pull-forward

  • ServiceNow blew its full-year Anthropic budget by May — Anthropic offers no SLAs, no usage telemetry, and had no comment when the CDIO said so publicly

  • Training efficiency breakthroughs compounding: 2-3x from Nous Research token superposition, 360x from NVIDIA elastic post-training, 17x from Datology data curation — custom model economics shifting

  • a16z published definitive AI liability lobbying blueprint proposing user-liability defaults and damages caps — while active court cases could impose massive penalties on developers before any legislation exists

  • AI infrastructure tools (LiteLLM, Ollama, OpenClaw) now on CISA's Known Exploited Vulnerabilities catalog — most organizations adopted them without security review

  • VPs voluntarily taking IC roles at AI-native startups — Lovable's HI-C model 5 months in shows 90% time on building, attracting elite talent who reject traditional management

  • Abridge raised at $5.3B on 80-100M+ medical conversations — clinical intelligence layer positioning above EHR creates irreplicable data moat in healthcare AI

  • Google's Gemini Intelligence ships this summer on 3B+ Android devices as an autonomous agent layer — apps become infrastructure the agent calls, not the surface users touch

  • Vercel production data: Anthropic captures 61% of AI spend (expensive reasoning) while Google captures 38% of volume (cheap throughput) — structural bifurcation, not temporary

  • Only 15% of organizations have data foundations for agentic AI while 85% are spending millions — 95.2% of data modeling pain is organizational (ownership, training), not tooling (4.8%)

The Bottom Line

AI achieved full autonomous network takeover the same week that commercial EDR products were revealed as transparent to LLM-assisted reversing — your defensive stack just lost two load-bearing assumptions simultaneously. Meanwhile, AI compute is being locked up in $10-20B bilateral commitments (Cerebras IPO validated at $56B on a single OpenAI deal), the enterprise 'execution layer' platform war started with SAP and ServiceNow making incompatible architectural bets, and ServiceNow blew its full-year Anthropic budget by May because no one has solved AI cost governance. The decisions that matter this quarter: compress patch SLAs from 30 days to 72 hours, choose which execution-layer platform your agents route through, and build the cost governance infrastructure before the next budget cycle discovers it was assumed to exist.