The Board Room
Your EDR's defensive moat evaporated this week.
AI-assisted reverse engineering made all five tested commercial endpoint products architecturally transparent in days instead of weeks, CISA added AI infrastructure tools (LiteLLM, Ollama, OpenClaw)
Security Operating Model Failure — Three Layers at Once
EDR architectures transparent to AI reversing in days. AI infra tools (LiteLLM, Ollama) now in CISA KEV — actively exploited before most firms inventoried them. Mythos first model to clear both AISI attack ranges. PraisonAI exploited 4 hours after disclosure. Foxconn lost 8TB of Apple/Google/Nvidia/Intel IP. The entire stack failed simultaneously.
AI Infrastructure Capital Scale Revealed
Microsoft's OpenAI commitment disclosed at $100B via lawsuit. Cerebras IPO at $56B with 70% pop on $20B OpenAI contract. xAI leasing 220K GPUs (45% of Colossus) to Anthropic — financial logic now overrides competitive logic in compute. Fervo Energy IPO at $10B+ validates power as platform business. Nebius at 684% growth, 4:1 demand ratio.
Execution Layer War — Four Platforms Move in One Week
SAP (€100M fund + Knowledge Graph), ServiceNow (MCP-based Action Fabric), Apple (App Store agent framework with fee gates), and Google (Gemini Intelligence on 3B+ Android devices this summer) all claimed the agent execution layer simultaneously. 59% of AI traffic is now agentic. The question is no longer 'which model' but 'which platform does the agent call through.'
AI Governance Gap — From Budget Blowouts to Legal Exposure
ServiceNow blew its full-year Anthropic budget by May — no SLAs, no telemetry, no predictable pricing from the model provider. a16z published the industry's liability blueprint while active courts could impose strict liability on developers for user misuse. Only 15% of orgs have data foundations for agentic AI. Duolingo quantified the 'slop tax' at ~20%.
Workforce Architecture Fracture
VPs are voluntarily taking IC roles at AI-native startups — the economic case for coordination-layer management is inverting. 103K tech layoffs by mid-May approaching 2025's full-year total. Lovable dissolved its growth management layer and found it attracts elite talent. One operator ships in hours what cross-functional squads took weeks to produce.
Your Security Stack Failed on Three Axes This Week — Architecture Response Required
The Convergence
The frame to use this week is architecture, not budget. The security operating model built over the past decade no longer describes the threat environment it was purchased to defend against, and the gap is now visible across endpoint detection, AI routing infrastructure, and offensive tooling at the same time.
The cost curve on reverse engineering a commercial endpoint agent has collapsed in a way the defensive stack's threat model never priced in.
Layer 1: Endpoint Detection Becomes Transparent
TrustedSec ran LLMs against five commercial EDR products and found the same internals across all five: YARA-style rules, behavioral logic, allowlists, prefilters, scripted engines (some readable as Lua after a single decryption pass), and local ML classifiers. Work that used to require a skilled reverser and weeks of effort now takes days with AI assistance. The category was running on security-through-obscurity, and the obscurity just left.
Layer 2: AI Infrastructure Under Active Exploitation
CISA added LiteLLM, Ollama, and OpenClaw to the Known Exploited Vulnerabilities catalog, which means adversaries are already targeting AI routing infrastructure in production. A Raspberry Pi honeypot dressed as an AI stack was indexed by Shodan in 3 hours and absorbed 113,000 attacks per month. The AI tooling layer went from experiment to production without the security review traditional enterprise software gets on the way in.
Layer 3: Offensive AI Crosses the Discontinuity
Anthropic's Mythos became the first model to clear both UK AISI simulated attack ranges, with full network takeover rather than mere persistence. Congress is holding closed-door demos and routing access through NSA rather than CISA, which signals offensive and intelligence priorities over civilian defense. Microsoft's MDASH found 16 exploitable flaws in a single Patch Tuesday using multi-model AI, and the PraisonAI framework was exploited 4 hours after disclosure.
The Compound Effect
Each layer compounds the others. An adversary with transparent EDR visibility, AI-speed exploit development, and access to unpatched AI infrastructure tools is operating against an attack surface measured in hours rather than months, not the one the current security posture was calibrated for. The NGINX 18-year RCE, present since 2008 and affecting nearly every modern web application, shows how long a latent defect waits for the discovery economics to reach it.
Defenders are still patching on a monthly cycle while attackers have compressed exploit development from months to hours, which means the window between disclosure and exploitation is now shorter than most enterprise change-control processes.
The AI security operating model, the AI vendor hierarchy, and the AI execution layer ownership question all broke open in the same week. EDR architectures are now transparent to AI-assisted reversing, Microsoft's $100B OpenAI commitment establishes the cost floor of frontier participation at a level only 4-5 entities can sustain, and four major platforms (SAP, ServiceNow, Apple, Google) made incompatible claims on where agents live — while 85% of enterprises lack the data foundations to make any of it work. The decisions being made this quarter about security architecture, vendor diversification, and platform positioning will compound over the next two years in ways that cannot be reversed at renewal time.