Product & Strategy

The Product Desk

The Signal

AI agents have quietly become your majority user on key product surfaces

Meanwhile, 42% of the 238K AI skills on ClawHub are malicious, and the more capable your model, the MORE vulnerable it is to exploitation (o1-mini follows injected instructions 72.8% of the time). You're building for an audience you're not measuring, through an ecosystem you haven't security-tested.

In Play

  1. Your Next User Is an AI Agent — Majority Threshold Crossed

    AI agents now outnumber humans on multiple product surfaces. Imperva confirms 51% bot traffic, Hex and Mintlify report agent-majority usage, Tally gets 25% of signups from ChatGPT, and AI-referred sessions jumped 500%+ YoY. a16z's litmus test: if an agent can't consume and pay for your product autonomously, you haven't built the new model.

    Ask Clarity
  2. AI Agent Security Crisis: 42% of Skills Malicious, MCP Servers Toxic

    The AI tooling ecosystem has early-2000s security posture. 42% of 238K ClawHub skills are malicious. 10.8% of 5,125 MCP servers have exploitable toxic data flows. More capable models are MORE vulnerable — o1-mini follows prompt injections 72.8% of the time. McKinsey's chatbot was fully compromised in 2 hours. Langflow was exploited 20 hours post-patch.

    Ask Clarity
  3. Seat-Based SaaS Faces Existential Threat — a16z Declares Two Paths

    a16z published a binary ultimatum: accelerate revenue 10+ points via AI-native products or restructure to 40%+ true operating margins — no middle ground. Seat-based pricing is customers' #1 cost-cutting target. 56 of 198 YC W26 startups are building autonomous agents replacing $50-150K workers. Private credit funds exposed to SaaS loans are gating redemptions as AI erodes switching costs.

    Ask Clarity
  4. Agentic Commerce Fails Its First Real-World Tests

    Walmart's in-chat ChatGPT purchases convert at 1/3 the rate of walmart.com. ChatGPT ads deliver 0.91% CTR vs Google's 6.4% — one advertiser spent $7,500 of a $250K budget. OpenAI is retreating from native checkout to focus on product discovery. AI is proving effective at discovery and terrible at trust and transactions.

    Ask Clarity

Deep Dives

Your Product Now Has Two User Bases — And You're Only Measuring One

Across eight independent sources this week, a single pattern emerges with enough hard data to move from observation to action: AI agents have become the majority user on multiple product surfaces, and most product teams have zero visibility into this shift.

The Data Is Unambiguous

Hex's CEO published a graph showing AI agents creating more dashboard cells than humans. Mintlify explicitly states agents read developer docs more often than people. Tally — a form builder — reports 25% of all new signups come from ChatGPT referrals. Imperva's 2025 report confirms automated traffic hit 51% of all web activity. Vercel sees 25% of bot traffic from AI crawlers. AI-referred sessions jumped 500%+ year-over-year. Tyler Cowen reports using LLMs 10x more than Google for information queries. This isn't a trend line — it's a threshold crossing.

Why This Changes Your Product Strategy

a16z's David George published a litmus test that should be pinned to every PM's wall: 'If an agent cannot consume and pay for your product autonomously, you probably have not achieved the necessary new product model.' This means your product now needs to be legible to two fundamentally different audiences:

  • Humans who click, scroll, and evaluate with judgment
  • Agents who parse structured data, call APIs, and make decisions programmatically

Your documentation needs to be machine-comprehensible. Your pricing page must be unambiguous to comparison-shopping agents. Your API needs to support agent-scale consumption patterns — orders of magnitude beyond human usage — with appropriate rate limiting and pricing.

GEO Is Already a Top-3 Acquisition Channel

Generative Engine Optimization has matured from concept to industry in under a year. The Tally case study is the proof point: 25% of signups from ChatGPT alone makes it a top-three acquisition channel. Dedicated GEO agencies and dozens of VC-backed startups have emerged. The critical difference from SEO: in traditional search, you compete for rankings on a page. In GEO, you compete for inclusion in an AI's answer — a winner-take-most dynamic where being second means being invisible.

Every query that moves from Google to ChatGPT is a query where your SEO investment yields zero return and your GEO investment determines whether you exist.

The Agent Payment Infrastructure Is Forming Now

Three competing open protocols launched within weeks to let agents pay for services: Coinbase's x402 (HTTP 402 with stablecoin payment instructions), Tempo/Stripe's MPP, and WLFI's AgentPay SDK which auto-installs into 7 major AI dev environments. The standards war for machine-to-machine commerce has started. Products that can accept agent payments will capture revenue that products requiring human checkout will miss entirely.

The Niche Content Moat

One strategically important signal: niche, proprietary content is disproportionately valuable to AI systems because it fills training data gaps. If your product generates unique data — usage benchmarks, domain insights, performance metrics — publishing it builds a citation moat that compounds as AI systems rely on it. This inverts traditional content marketing: volume matters less than uniqueness.

What to do

  1. Instrument AI agent traffic separately in your analytics stack this week — add tracking to distinguish agent visits from human visits across docs, marketing pages, and product surfaces

  2. Run a GEO audit by end of sprint: test how ChatGPT, Claude, and Perplexity describe and recommend your product vs. competitors

  3. Add 'agent persona' to your next PRD — define what it takes for an AI agent to discover, authenticate, consume, and pay for your product autonomously

  4. Evaluate infrastructure cost exposure from AI crawler traffic and implement tiered access for agents vs. human users by end of quarter

42% of AI Skills Are Malicious — The Ecosystem You're Building On Has Early-2000s Security

Five independent sources converge on the same alarming conclusion this week: the AI tooling ecosystem your product depends on has catastrophic security gaps, and the data is now specific enough to act on.

The Numbers That Should Stop Your Sprint Planning

Risk SurfaceFindingSource
ClawHub Skills42% of 238,180 skills are maliciousRaxe analysis
MCP Servers555 of 5,125 (10.8%) have toxic data flowsAgentSeal scan
Model Vulnerabilityo1-mini follows injected instructions 72.8% of the timeMCPTox benchmark
Exploitation SpeedLangflow CVE exploited 20 hours post-patchSysdig
Enterprise ImpactMcKinsey chatbot fully compromised in 2 hoursAI-hacking-AI scenario

The Paradox: Better Models Are MORE Vulnerable

The most alarming finding from the MCPTox benchmark: model capability and prompt injection susceptibility scale together. Upgrading your model to improve agent performance simultaneously increases vulnerability to the attack patterns found in 10.8% of MCP servers. This creates a genuine product design paradox: the improvement your users want makes the security problem worse.

The model upgrade you're planning to improve agent performance simultaneously increases your vulnerability to the exact attack patterns found in 10.8% of MCP servers.

The Attack Pattern Is Combinatorial

The primary toxic data flow pattern is individually benign tools that become exploitable when combined: a tool that reads credentials paired with a tool that sends webhooks. Neither is malicious alone. Together, they form an exfiltration pipeline. 84.7% of toxic findings were rated critical or high severity. This means security review at the individual tool level is insufficient — you need to audit tool combinations, and the attack surface grows quadratically with each tool added.

Supply Chain Attacks Are Targeting Security Tools Themselves

The Trivy supply chain attack (March 19) used encrypted C2 and exfiltration — a sophistication upgrade. Attackers compromised the scanner designed to catch compromises. North Korean actors are poisoning hundreds of real npm-related GitHub repos. Dormant VSCode extensions activated over the weekend. The exploitation window has compressed to under 24 hours for critical CVEs.

The Enterprise Governance Category Is Forming

Four agentic security products launched in the same cycle: 1Password Unified Access (shadow AI and agent credential governance), Arctic Wolf's Agentic SOC, Surf AI (agent-based SecOps), and open-source agent-password. When 1Password starts selling NHI governance, enterprise procurement teams will start requiring it. You have roughly one quarter before 'how do you manage agent credentials?' becomes a standard security review question.


The practical mitigations are product design decisions: separate read and write MCP servers, apply least privilege per tool, cap tool count per server, and consider whether a less capable model with lower injection susceptibility is the right choice for tool-calling workflows involving sensitive data.

What to do

  1. Audit every MCP server and AI skill integration in your product for toxic data-flow patterns this week — specifically check for private-data-reading tools paired with external communication capabilities

  2. Add adversarial AI red-teaming to your launch checklist for any customer-facing AI feature — run a focused 2-hour attack simulation this sprint

  3. Compress your security patching SLA to under 24 hours for critical CVEs in AI infrastructure components

  4. Add NHI credential management to your product security roadmap — determine how AI agents authenticate and whether actions are attributable to specific agent instances

The Seat-Based Pricing Extinction Event — a16z Says Two Paths, No Middle Ground

The Strategic Ultimatum

a16z's David George published what amounts to a binary ultimatum for every software company: either accelerate revenue growth by 10+ percentage points through AI-native products within 12-18 months, or restructure to 40-50% true operating margins (counting SBC as a real expense). Companies that try 'a little of both' face persistent multiple compression through 2027. This isn't a think piece — it's the most influential enterprise VC firm setting the agenda for board conversations across the industry.

Why Seat-Based Revenue Is the First Casualty

George's core argument: customers' most obvious AI savings lever is labor efficiency, which means seats. Every time your customer deploys an AI agent that replaces a workflow formerly done by a human, that's a seat they don't need. The new growth vectors are tokens, consumption, automations, and outcomes. His acid test is devastating: can an AI agent autonomously discover, consume, and pay for your product? If not, you're building for a shrinking addressable market.

Seat-based pricing is now customers' single biggest target for cost reduction, and new software budget growth is flowing into tokens, consumption, automations, and outcomes instead.

YC W26 Confirms the Market's Thesis

The market is already building for this world. Of 198 companies in YC's W26 batch, 85% are AI-first and 56 (28.3%) are explicitly building autonomous agents positioned as AI employees replacing $50-150K knowledge workers. AI accountants closing books. AI law firms staffed entirely by models. Healthcare is the largest vertical with 22 companies targeting clinical work directly — not EHR wrappers. If your product's ICP is 'mid-level professional who does X,' you're looking at a world where X gets done by an agent.

Traditional Moats Are Weakening Simultaneously

George argues all four traditional software moats are eroding at once:

  1. Data — usually insufficient alone
  2. Integrations — getting easier to reproduce
  3. Workflow/UI advantages — less relevant when agents navigate across systems
  4. Migration friction — getting easier as AI reduces switching costs

Private credit funds that loaded up on SaaS loans — on the thesis of sticky revenue and durable switching costs — are now gating redemptions. Institutional investors with deep access to portfolio company metrics are running from SaaS exposure. They're seeing churn and margin data that hasn't hit public earnings calls yet.

The Organizational Restructuring Is Coming

George recommends 50% of R&D budget on net-new AI products, organized in 4-person pods (PM + designer + 2 engineers) that write code on day one. Top engineers managing 20-30 AI agents simultaneously. $1,000/month token spend per engineer described as 'table stakes.' A wave of 'strong form' corporate restructuring — not 8-10% layoffs but full organizational redesign — is expected across software in the next 12 months, targeting 40-50% operating margins.

The Broadcom/VMware case (radical simplification, subscription conversion, 61% adjusted EBITDA margins) is being positioned as the template. Expect boards across the industry to ask 'why can't we do that?' within two quarters.

What to do

  1. Conduct a seat-risk audit this quarter: quantify what percentage of revenue is seat-based, model the impact if customers reduce seats by 20-30% in the next 18 months, and draft a consumption-based pricing alternative for leadership

  2. Run a competitive moat stress-test this sprint: score each of your product's defensibilities (data, integrations, workflow, switching costs) against the a16z erosion thesis and present findings to leadership

  3. Pilot a 4-person pod on your highest-priority AI initiative and measure velocity against your standard team structure

  4. Frame your product area's contribution against the two paths — prepare a one-pager showing either 10+ points of revenue growth acceleration or margin contribution — before the next planning cycle

The bottom line

Your product now serves two user bases — humans and AI agents — and the agent base is growing faster, converting differently (25% of Tally signups come from ChatGPT), and operating through an ecosystem where 42% of available skills are malicious. Meanwhile, a16z just told the entire software industry that seat-based pricing is a dead end and 56 YC startups are building autonomous agents to replace the $50-150K workers who are your power users. The PMs who instrument agent traffic, security-test their AI integrations, and begin the consumption-pricing pivot this quarter will own the next cycle; the ones still measuring only human sessions will discover half their 'users' were never people.