The Board Room
ServiceNow exhausted its annual Anthropic budget by May.
In the same quarter, Google, OpenAI, Anthropic, ServiceNow, and Salesforce have all independently converged on Palantir's forward-deployed-engineer model, which puts the true cost of enterprise AI at three to five times the model fees most budgets were built around.
Your Defensive Stack Is Now Transparent
TrustedSec proved all 5 major EDR products are reverse-engineered by AI in days, not weeks. Simultaneously, CISA added AI infrastructure tools to KEV. PraisonAI was weaponized within 4 hours of disclosure. The defender's response window and the defender's detection architecture both failed in the same week.
Enterprise AI Cost Governance Has Failed
ServiceNow exhausted its full-year Anthropic budget by May. Every major vendor now requires 5-10 forward-deployed engineers at $300-500K loaded each, making true AI deployment cost 3-5x model fees. Anthropic offers no SLAs, no usage telemetry, and had zero comment on customer budget blowouts.
Execution Layer War: SAP vs ServiceNow
SAP bet on a vertically integrated Knowledge Graph with a €100M fund. ServiceNow adopted MCP as its agent communication standard. Both are rebuilding to be consumed headlessly by AI agents, not humans. The 12-18 month window to decide which platform owns your agent execution layer is open now.
AI Liability Regime Being Written Now
a16z published the industry's lobbying blueprint while courts are actively setting precedent on AI developer liability. ODNI and Commerce are fighting for model assessment authority. If developer-liability wins, open-source AI becomes uninsurable. If user-liability wins, incumbents lose their compliance moat.
Org Design Becomes Competitive Weapon
Lovable dissolved its growth management layer, replaced it with autonomous parallel contributors, and found the move attracts elite VPs. One operator ships in hours what a cross-functional squad shipped in weeks. Duolingo quantified the counter-risk: blanket AI mandates produce ~20% unusable output.
Your Defensive Architecture Is Now Transparent — And Your AI Infrastructure Was Never Secured
Two Failures Arrived in the Same Week
The week produced two security findings that would each define a bad quarter on their own. Together they retire the operating model most security programs still run on. TrustedSec pointed LLMs at five commercial EDR products and found all five architecturally identical: YARA-style rules, behavioral logic, allowlists, prefilters, Lua-based scripted engines readable after a single decryption pass, and local ML classifiers. Reverse engineering work that used to take a skilled human weeks now takes days. The endpoint detection category has been running on obscurity, and the obscurity is gone.
The security model assumed the cost of understanding the agent exceeded the value of bypassing it for most adversaries. That assumption no longer holds for a growing share of the threat population.
In the same window, CISA added five AI infrastructure tools to its Known Exploited Vulnerabilities catalog, including LiteLLM, Ollama, and OpenClaw. These are tools most engineering teams adopted without security review, in the narrow gap between experiment and production that AI tooling closed in roughly two quarters. A Raspberry Pi honeypot configured as an AI stack was indexed by Shodan in 3 hours and absorbed 113,000 attacks per month, with 23% of traffic aimed at AI-specific endpoints.
The Response Window Has Collapsed
PraisonAI was weaponized within 4 hours of disclosure. An 18-year-old RCE in NGINX sat undisturbed across most of the web. Traefik shipped a CVSS 10.0 authentication bypass. Argo CD allows plaintext Kubernetes secret extraction at CVSS 9.6. Stack those disclosures against the same remediation teams, change windows, and testing capacity, and any organization on a quarterly patch cadence is operating with permanent known exposure.
Microsoft's MDASH system found 16 exploitable flaws in a single Patch Tuesday cycle using multi-model AI analysis. That capability, or its functional equivalent, reaches adversaries within 12-18 months. The UK AISI confirms AI cyber task completion is doubling every few months, and Anthropic's Mythos became the first model to clear both simulated attack ranges. Congress is routing Mythos access through NSA rather than CISA, which is the clearest available signal about which use case the government treats as primary.
The Foxconn Proof Point
Nitrogen ransomware exfiltrated 8TB of confidential designs from Apple, Google, Intel, and Nvidia through a single contract manufacturer. The concentration of AI infrastructure work at a small number of assembly partners produces concentration of intellectual property, which produces concentration of target value. Supply chain data custody is now a first-class security surface, not a procurement annex.
What Changed Since Tuesday's Coverage
Tuesday's briefing argued that offensive capability was arriving. The finding this week is that defensive capability simultaneously failed. The endpoint agents are hollow. The AI infrastructure underneath them went into production without controls, and exploit windows are now compressed below most patch cadences. A reasonable skeptic will note that any single finding could be reversed by a vendor patch or a process change. The skeptic is right about any one of them. The point is that all of them landed at once, against the same teams, in the same week, which is what turns this from a patching problem into an architecture decision.
Your security architecture was proven hollow the same week your AI budget was proven uncontrolled. TrustedSec showed all five major EDR products are transparent to AI-assisted reverse engineering in days; ServiceNow showed a $150B enterprise company can blow its entire annual AI budget by May with no telemetry to explain why. Meanwhile, SAP and ServiceNow are making incompatible bets on who owns the agent execution layer — a decision that determines your platform economics for the next three years. The common thread: assumptions written into last year's plans no longer describe the ground, and the organizations that discover this through failure rather than through audit will pay the difference in public.