Investment & Market Intelligence

The Investor

The Signal

McKinsey's enterprise AI platform Lilli was breached via basic SQL injection in 2 hours

In the same cycle, cyber insurers began pricing AI governance posture into premiums, creating the first CFO-visible, dollar-denominated demand driver for a security category with zero incumbents.

In Play

  1. AI Platform Security: The Zero-Incumbent Category Worth $32B+

    McKinsey's Lilli breach (46.5M messages via SQLi), Perplexity Comet compromised in 4 min, and cyber insurers now pricing AI governance into premiums converge into a single signal: enterprise AI platforms ship with 2005-era security, no vendor owns the category, and insurance creates CFO-level budget unlock.

    Ask Clarity
  2. SaaS → Service-as-Software: $1T Wiped in a Week

    ServiceNow dropped 11% despite beating earnings; Microsoft shed $360B in one session. The market isn't punishing execution — it's repricing the SaaS decade. Three pillars are crumbling simultaneously: per-seat pricing, human-centric UI, and code moats. Incumbents split between denial (Oracle, Salesforce) and restructuring (Atlassian cutting 10%).

    Ask Clarity
  3. Private Market Bifurcation: $17.5B Graveyard vs. $840B Secondaries

    400+ startups destroyed $17.5B since 2023 (healthcare/biotech alone: $5.1B) while secondary markets grew 5x in a decade and OpenAI sits at $840B after 4 rounds. Quality public equities trade at 17.1x vs S&P at 22x — JPM projects 0-5% index returns. The middle of every market is disappearing.

    Ask Clarity
  4. Solar's $100/bbl Catalyst Unlocks Multi-Hundred-Billion Industrial TAMs

    Hormuz closure spiked oil past $100/bbl while solar hit $0.07/watt with Wright's Law holding at 23.7% for 48 years. Below $0.03/kWh, entirely new industrial markets unlock — desalination, green hydrogen, green steel, DAC — each a multi-hundred-billion TAM. China's 85% manufacturing share (1,045 GW capacity vs 587 GW production) accelerates the curve further.

    Ask Clarity
  5. AI Stack Consolidation: Platforms Bundle, Startups Get Squeezed

    Google bundled managed RAG into Gemini API, Nvidia open-sourced NemoClaw agent platform, Zoom shipped no-code agents as a free feature, and Meta put custom MTIA chips into production. Each independently commoditizes a venture-backed startup category. Context engineering and vertical depth emerge as the only durable moats above the platform layer.

    Ask Clarity

Deep Dives

AI Platform Security: The $32B Category That Doesn't Exist Yet — But Three Breaches Just Proved It Must

The Category Formation Event

Three events in a single intelligence cycle prove that enterprise AI platforms are catastrophically insecure — and no vendor owns the solution. McKinsey's internal AI platform Lilli was breached by CodeWall's autonomous AI agent via basic unauthenticated SQL injection, exposing 46.5 million chat messages, 728,000 sensitive files, and McKinsey's entire proprietary RAG knowledge base in two hours. Perplexity's Comet AI browser was weaponized for phishing in under 4 minutes, proving that machines — not humans — are the new phishing target. And n8n's workflow automation platform landed on CISA's Known Exploited Vulnerabilities catalog with 24,700 exposed instances.

If McKinsey — with unlimited resources and reputational stakes — shipped an AI platform with 2005-era SQL injection, the base rate for enterprise AI security posture is catastrophically low.

The Insurance Demand Catalyst Changes Everything

Simultaneously, cyber insurers began bifurcating premiums based on how organizations deploy AI. Companies using AI defensively get lower premiums; those whose AI deployment introduces attack surface face surcharges. This is the first time AI security has a CFO-visible, dollar-denominated ROI beyond vague risk reduction narratives. The analog is SOC 2 compliance creating Vanta and Drata — whoever builds the AI governance-to-insurance-premium workflow owns a new multi-billion-dollar GRC category.

Google's $32B Wiz acquisition closes the cloud security era at peak multiples. But the McKinsey breach proves Wiz doesn't cover AI-native vulnerabilities: prompt injection, RAG data poisoning, agentic permission escalation, and apparently basic SQLi on brand-new AI platforms. The attack surface has shifted; the defenders haven't followed.

Competitive Landscape: Zero Incumbents

CategoryStatusInvestment Timing
AI Application SecurityGreenfield — no dominant playerSeries A sweet spot NOW
AI Governance for InsurancePre-category — emerging wedgeSeed to Series A
Autonomous Red-TeamingCodeWall validated categoryPre-consensus window open
AI Agent SandboxingNo mature product existsCategory creating in real-time

The autonomous red-teaming angle deserves attention: CodeWall chained four low-severity bugs into admin-level access on a live platform, demonstrating AI can replace the $2B+ human-dependent pen testing market with SaaS-margin economics. And New York enacted first-in-nation OT cybersecurity regulations for water utilities — a regulatory template that will cascade to other states, expanding the OT security TAM further.

Where This Goes Wrong

AWS expanded Security Hub to multicloud operations this cycle, which threatens standalone CSPM/CNAPP vendors. If hyperscalers extend bundling into AI security, the window for startups narrows. The race is between category formation speed and platform commoditization — bet on teams that can own a vertical wedge (healthcare AI security, financial AI compliance) before the platforms generalize.

What to do

  1. Source 3-5 Series A deals in AI application security — companies building prompt injection defense, RAG access control, and agentic permission systems

  2. Map the AI-governance-to-insurance-premium workflow as a thesis; identify seed-stage companies with insurance industry GTM DNA

  3. Push security advisory to all portfolio CTOs: audit any enterprise AI platform for basic web app vulnerabilities (SQLi, auth bypass) this week

  4. Stress-test any CSPM/CNAPP portfolio positions against AWS Security Hub multicloud expansion — model 20-30% TAM compression scenario

SaaS Gets Its 'On-Prem Moment' — The Service-as-Software Framework for Portfolio Triage

The $1T Repricing Event

On January 29, software posted its worst session since the 2020 pandemic crash. Over $1 trillion in market cap evaporated in a single week — and the most important data point isn't the headline number but the composition. ServiceNow dropped 11% despite beating earnings. Microsoft shed $360B in a single session despite being the most AI-forward incumbent. When the market punishes execution excellence, it's not pricing the quarter — it's repricing the decade.

The market is saying: 'We don't care about this quarter. We're repricing your terminal value.' This is the same pattern we saw with on-prem vendors in 2013-2015 as cloud SaaS emerged. The playbook is running again — just faster.

Three Pillars Crumbling Simultaneously

SaaS PillarHistorical MoatAI-Era ThreatDisruption Timeline
Per-Seat PricingRevenue scales with headcountAI agents replace human users; no seat needed12-24 months (mid-market)
Human-Centric UISwitching costs via user trainingAgents consume APIs directly; UI irrelevantAlready underway in dev tools
Code MoatYears of proprietary engineeringLLMs + vibe coding replicate in weeks24-36 months (horizontal SaaS)

The intellectual framework gaining traction is the inversion from SaaS to SaS (Service-as-Software): instead of selling tools to humans per seat, sell autonomous outcomes to businesses per task. This is a TAM expansion story disguised as destruction. SaaS addressed ~$1T in software spend; SaS theoretically addresses the multi-trillion-dollar human services market.


Incumbents Are Splitting: Denial vs. Restructuring

The enterprise software market is bifurcating in real time. Atlassian is cutting 10% of its workforce ahead of an AI push — management sees the wave and is repositioning. Meanwhile, Oracle and Salesforce are publicly dismissing 'SaaS-pocalypse' fears. The historical pattern is unambiguous: when incumbents publicly dismiss disruption threats, they are already being disrupted. An a16z researcher's framework crystallizes this further: the dominant 'drop-in AI worker' thesis is a value trap — real returns come from AI-native paradigms that render entire workflows irrelevant, not from automating tasks within them.

Enterprises can now generate custom CRM workflows with AI agents in hours instead of paying $150/seat/month. Open-weight self-hosted models deliver 8x cost savings vs. cloud APIs. The substitution isn't theoretical — it's happening, with revenue churn following market cap destruction by 6-12 months.

Where Survivors Live

The alpha is in three categories: (1) Agent-native vertical replacements with outcome-based pricing in CRM, ITSM, HR, ERP — seed through Series B; (2) Infrastructure for the SaS transition — agent orchestration, reliability, observability, the Datadog play for the agent era; (3) SaaS incumbents with hidden data moats the market is mispricing indiscriminately. Companies whose defensibility is proprietary data with network effects, not code complexity, will be the contrarian longs.

What to do

  1. Conduct moat audit across all portfolio SaaS companies using three-pillar framework: per-seat pricing exposure, human-interface dependency, code-vs-data moat — complete by end of month

  2. Build a 'Service-as-Software' deal pipeline targeting seed-to-Series B companies with outcome-based pricing in CRM, ITSM, HR, and ERP verticals

  3. Flag any portfolio company with >80% per-seat revenue and code complexity as primary moat for accelerated exit evaluation

  4. Evaluate AI agent infrastructure investments — orchestration, reliability, observability — as picks-and-shovels of the SaS transition

The Great Bifurcation: $17.5B Graveyard, $840B Secondaries, and Exit Multiples That Need a Haircut

The Kill Zone Is Expanding

CB Insights data reveals 400+ startup shutdowns since 2023, incinerating $17.5B in venture capital. The headline cause is capital exhaustion (70%), but the real drivers are more damning: poor product-market fit and wrong market timing. These companies shouldn't have been funded at the terms they got. Healthcare and biotech alone burned $5.1B — Areteia Therapeutics raised $425M before clinical trial failure forced total shutdown.

At the other end of the barbell, secondary markets grew 5x in a decade, with 1-in-3 companies running multiple secondary rounds. OpenAI sits at $840B after 4 completed secondaries — sustaining a valuation entirely in private markets. The private market isn't broken; it's bifurcating violently. Winners get infinite liquidity without ever going public. Everyone else dies. The middle is disappearing.

The market is demanding proof of unit economics, not just proof of TAM. Portfolios still priced for the old regime have 6 months to adapt.

Public Markets Are Sending the Same Signal

The bifurcation extends to public equities. Quality stocks trade at 17.1x forward P/E vs. 22.0x for the S&P 500 — a ~22% discount. JPM projects 0-5% S&P returns while quality portfolios calculate 13.4% expected returns. Multiple legendary quality investors (Akre, Smith/Fundsmith) are simultaneously underperforming — not idiosyncratic failure but a factor regime reminiscent of 1999, when Berkshire trailed the S&P by 40 points before the dot-com crash vindicated the approach.

MetricQuality PortfolioS&P 500Gap
Forward P/E17.1x22.0x-22%
Expected Return13.4%0-5% (JPM)+8-13pp
Novo Nordisk drawdown-39.5%GLP-1 sector repricing

This matters directly for portfolio construction. If you're using S&P-adjacent multiples (22x) for exit models, you're likely overestimating proceeds by 18-23%. A reversion toward 17-18x would materially change fund return math. The VC supercycle compounds this: major firms have raised more capital since 2023 than in the prior two decades combined, creating deployment pressure that inflates entry prices.

Macro Headwinds Compounding

Two forces threaten the capital supply side simultaneously. OpenAI's IPO is meeting skeptical investors — when the sector's defining company can't generate enthusiasm, every late-stage AI valuation loses its public-market anchor. And $300B in Gulf AI infrastructure spending is imperiled by the Iran conflict — sovereign wealth funds that have been the marginal buyers in mega-round AI deals face deployment uncertainty. If even 20% of Gulf capital pauses, it ripples through compute procurement, data center financing, and late-stage rounds.

Anduril's disclosure of $4B+ revenue alongside $1B in losses provides the first clean look at defense tech unit economics at scale: -25% operating margins at $4B makes it a high-growth industrial company, not a software business. Every defense tech deal needs re-underwriting against this margin profile.

What to do

  1. Stress-test portfolio company exit models against 17x quality-normalized multiple rather than 22x S&P-anchored multiple — complete sensitivity analysis by mid-April

  2. Audit portfolio for companies with <18 months runway and unproven PMF — flag against the 400+ shutdown mortality profile

  3. Map Gulf sovereign wealth fund exposure across portfolio — scenario-analyze any company with >15% dependency on Saudi PIF, Mubadala, ADIA, or QIA

  4. Review GLP-1/obesity therapeutics portfolio exposure given Novo Nordisk's -39.5% drawdown as sector-level repricing signal

The bottom line

AI platform security is a greenfield category with zero incumbents — McKinsey's Lilli was breached via basic SQLi (46.5M messages), Perplexity's Comet was weaponized in 4 minutes, and cyber insurers just started pricing AI governance into premiums — while the $1T SaaS repricing that punished ServiceNow 11% despite beating earnings confirms the market is no longer buying tools-for-humans at any multiple, and $17.5B in startup capital destroyed since 2023 proves the private market's middle tier is simply disappearing between an $840B secondary-powered elite and a graveyard expanding in real time.