Nvidia on Monday launched an AI agent safety platform whose Sentry watchdog runs on its BlueField-4 data processors. The design assumes agents will work around their limits, so its strongest enforcement runs on hardware only Nvidia makes.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 44%
- Investor
- Investor 21%
Reality
- Evidence55
- Adoption35
- Hype gap+25
- Incentives75
- Confidence60
About a third of organizations in a 1,719-person McKinsey survey passed on at least one software purchase because they could build it with AI. The exposure is vendors' add-on revenue. Each builder also takes on upkeep a vendor would otherwise carry.
Reality
- Evidence45
- Adoption40
- Hype gap+15
- Incentives60
- Confidence45
Dodge AI raised $2.65 million from Accel and Google's AI Futures Fund for agents that fix incidents in SAP and other business systems. The backers are betting that maintenance money moves from outside contractors to software, on results only Dodge AI has reported so far.
Reality
- Evidence35
- Adoption18
- Hype gap+50
- Incentives75
- Confidence40
Dodge AI raised $2.65 million, led by Accel and Google's venture arm, for agents that fix SAP incidents and record the custom rules behind them. Buyers who pay integrators for that work have two unnamed customer stories, both told by the company, to judge it by.
Reality
- Evidence22
- Adoption18
- Hype gap+45
- Incentives88
- Confidence30
NVIDIA's Open Agent Safety Platform, launched September 28, makes its OpenShell runtime available now while its Sentry hardware watchdog has no release date. Sentry's promised millisecond stop has no independent test yet, so the hardware half rests on NVIDIA's word.
Perspective Coverage
4 publishers
- Builder
- Builder 39%
- Operator
- Operator 37%
- Investor
- Investor 24%
Reality
- Evidence55
- Adoption35
- Hype gap+30
- Incentives70
- Confidence60
CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
A $100 million Series C led by ICONIQ, the third round in about a year, buys a board seat and a claim on general ledger spend. The growth disclosure is rates, not levels.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 31%
- Investor
- Investor 49%
Reality
- Evidence45
- Adoption40
- Hype gap+35
- Incentives70
- Confidence60
A record count that Microsoft's own AI bug-hunting produced arrives with two flaws already under attack, and the affected-product lists an operator would use to scope them are the part of the record two vendors read differently.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
n8n went from $2.5bn to $5.2bn in seven months and SAP is embedding its canvas in Joule Studio, while the single number offered for agent failure, an 88% security incident rate, arrives without a population or a definition.
Reality
- Evidence42
- Adoption58
- Hype gap+30
- Incentives52
- Confidence45
On one utility program, operations, billing, payments and finance all asked for fresher data in the same words. Cognizant's Govinda now asks what decision the data triggers before asking how fast a platform can move it.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+8
- Incentives45
- Confidence55
Claudeforce lets a seller work the pipeline without opening Salesforce. Vivek Acharya argues in Forbes that the packaging unit is now the skill, and that per-seat licensing stops cohering once agents are the users.
Reality
- Evidence30
- Adoption20
- Hype gap+35
- Incentives65
- Confidence35
The rate comes from UST's chief solutions officer, who called it healthy for the product's current stage. It sits inside the same pipeline UST credits with halving the time from a defined requirement to a deployable change.
Reality
- Evidence45
- Adoption20
- Hype gap+30
- Incentives80
- Confidence55
An OECD survey of 6,047 employers found this software in most workplaces on both continents. The countries split over what firms are allowed to do with it, and most of these tools are not AI at all.
Reality
- Evidence68
- Adoption82
- Hype gap+8
- Incentives30
- Confidence62
Onapsis found CVE-2026-44756 in SAP's Extended Passport code, Pathlock and nullFaktor reproduced remote code execution in a lab, and technical write-ups went public within 48 hours of the patch. Mandiant's AI report is the week's other substance.
Reality
- Evidence58
- Adoption45
- Hype gap+10
- Incentives68
- Confidence50
SAP is folding n8n's visual canvas into Joule Studio so multi-agent flows run on an SAP-hosted runtime with SAP's own governance and observability, and general availability is anticipated in Q3 2026.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence28
Onapsis, which found the flaw alongside SAP, rates it CVSS 10.0 and recommends immediate patching. A second kernel note in the same batch reaches every S/4HANA 2025 system and any older release already on a current kernel.
Publishers:onapsis.com
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives75
- Confidence48
SAP shipped Security Note 3747649 on September 8 for CVE-2026-44756, a memory corruption bug in Extended Passport processing that Onapsis says gives unauthenticated callers command execution as the account owning the SAP install.
Publishers:securityweek.com · socprime.com Reality
- Evidence72
- Adoption24
- Hype gap+14
- Incentives68
- Confidence66
Ivan Mans of SecurityBridge says the SAP security question is now what an agent already inside the system is allowed to do and whether anyone can prove it afterward. His incident record comes from developer tooling.
Reality
- Evidence33
- Adoption28
- Hype gap+38
- Incentives84
- Confidence64
Onapsis says the OVERPASS overflow fires while the SAP kernel processes an Extended Passport at session initiation, which happens before authentication or logon policy is consulted. That leaves reachability and patch state as the only variables.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+9
- Incentives62
- Confidence43
Google Cloud will train up to 1,000 Accenture engineers to work inside client offices on Gemini Enterprise, which tells a rollout owner what the platform costs in calendar time before it costs anything in licences.
Reality
- Evidence52
- Adoption28
- Hype gap+34
- Incentives80
- Confidence66
Earlier coverage
- Shai-Hulud's third wave printed SAP's npm token straight into a workflow log
Security · September 8, 2026 · 1 publisher
- SAP names token spending as the competitor for its customers' budgets
Leadership · September 5, 2026 · 1 publisher
- Why cheaper tool-creation won't shrink the enterprise software estate
Leadership · September 3, 2026 · 1 publisher
- The Mini Shai-Hulud worm passed provenance checks by running inside the release pipeline
Build · September 3, 2026 · 1 publisher
- Brussels gathers information on Oracle's cloud licensing, echoing its pre-SAP approach
Product · September 2, 2026 · 1 publisher
- Corporate venture arms are writing deep tech's first purchase order
Invest · August 28, 2026 · 1 publisher
- Snowflake's backlog is growing faster than its revenue, and that is the AI story
Invest · August 26, 2026 · 1 publisher
- Basware buys Trustpair because approving the invoice no longer tells you who gets the money
Invest · August 26, 2026 · 1 publisher
- Porsche sells its digital bench for €320m and rents it back for €1.25bn
Product · August 24, 2026 · 1 publisher
- Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end
Product · August 21, 2026 · 1 publisher
- AI skills now in 28.5% of security job ads, and the SOC job family is being quietly rewritten
Security · August 21, 2026 · 2 publishers
- Rillet's $1bn bet: rebuild the general ledger around agents, not bolt a copilot onto it
Product · August 19, 2026 · 2 publishers
- Brinqa buys PlexTrac because a ranked exposure list never proved anything got fixed
Product · August 19, 2026 · 1 publisher
- Rent the ledger, build the screen: where AI actually moved the buy-versus-build line
Leadership · August 18, 2026 · 1 publisher
- Fourteen of SAP's 33 August notes are top-severity: build the named-system list this week
Product · August 16, 2026 · 1 publisher
- A Commerce Cloud RCE chain reached a honeypot three days after the patch shipped
Build · August 14, 2026 · 1 publisher
- SAP's CVSS 10.0 Commerce Cloud bug needs a re-deploy, not just a patch window
Security · August 14, 2026 · 1 publisher