Investment & Market Intelligence

The Investor

The Signal

ServiceNow ran through its entire annual Anthropic budget by May

Anthropic also closed the seventy-to-ninety percent subscription arbitrage that quietly underwrote most Claude-wrapper economics, which we have flagged before and which finally happened on Friday. Nine hundred billion dollars of valuation prices perfection on top of consumer-grade plumbing.

In Play

  1. Anthropic's Revenue Quality Crisis Undercuts the $900B Mark

    ServiceNow exhausted its full-year Claude budget by May with zero usage telemetry. Anthropic has no enterprise SLAs, no per-user dashboards, and just converted subscriptions to metered API credits — killing the arbitrage. Enterprise ARR growing at 120x is real; the reversibility risk underneath it is unpriced.

    Ask Clarity
  2. Agent Infrastructure: Incumbents Define the Category Before Startups Can

    SAP committed €100M to an Autonomous Enterprise fund, ServiceNow shipped Action Fabric as headless agent APIs, and Vercel data confirms 59% of token volume is agentic. The incumbents are drawing category boundaries before pure-plays can name the market — compressing the Series A/B window to 2-3 quarters.

    Ask Clarity
  3. AI Security Crosses KEV Threshold — Category Is Now a Budget Line

    LiteLLM became the first AI gateway on CISA's KEV catalog. Microsoft's MDASH shipped 16 validated CVEs in one Patch Tuesday. DepthFirst claims 10x cost advantage over Mythos. PraisonAI was exploited within 4 hours. The AI security category just graduated from narrative to procurement line item.

    Ask Clarity
  4. Cerebras First-Day Print Confirms the Exit Window + SPV Era

    Cerebras closed at $311 vs $89 last private round — a 70% first-day pop yielding Eclipse 17x and Tiger $1B paper gain. Benchmark broke its own model with a $225M SPV. The AI-infra exit window is confirmed open, but only for names inside hyperscaler procurement graphs.

    Ask Clarity
  5. Neocloud Unit Economics Revealed as Structurally Cash-Negative

    Nebius disclosed $2.47B capex against $2.26B operating cash on 684% revenue growth — the neocloud model requires perpetual capital raises to function. Anthropic leasing 220K GPUs from xAI confirms supply is scarce but the business model funding that supply is not self-sustaining.

    Ask Clarity

Deep Dives

Anthropic's $900B Valuation vs. Consumer-Grade Enterprise Infrastructure

The Revenue Is Real. The Revenue Quality Is Not SaaS.

Several threads converge this week on something the nine-hundred-billion-dollar valuation is not pricing: Anthropic's enterprise revenue is structurally fragile, or rather, fragile in a way SaaS comps do not capture. ServiceNow, which is roughly as sophisticated an enterprise buyer as exists, exhausted its full-year Claude budget by May because Anthropic ships no per-user, per-tool dashboards and no SLAs. National Life Group's CIO put it without ornament: Anthropic is 'great for consumer usage but not great for companies.'

Read that next to the May 12-13 credit conversion, in which Anthropic now matches every subscription dollar with API credits and eliminates the 70-90% arbitrage that Cline, OpenCode, and OpenClaw were quietly running on subscription tokens. This is margin recovery dressed for the likely October IPO. It also reprices every Claude wrapper in the ecosystem in one stroke.


The Duopoly Mispricing

Ramp's April panel shows Anthropic at 34.4% of business spend vs. OpenAI at 32.3%, which is the first documented lead change and also a single month of card data skewed toward SMBs paying by credit card. Large enterprise pays by invoice, which understates OpenAI. A 2.1 point gap on that base is a signal to trade around. It is not a regime to bet the book on.

What the panel does establish is that vendor stickiness in AI is effectively zero. OpenAI's share jumped on its last model release and gave it back. Anthropic quadrupled in a year while OpenAI grew 0.3%. Customers flip on capability, which means the nine-hundred-billion-dollar mark has to be earned on continuous model leadership rather than installed-base compounding.

Enterprise AI ARR is not SaaS ARR. It reverses quickly, has no contractual lock-in, and the buyer discovered the budget was gone before the vendor told them.

The Wrapper Extinction Event

OpenAI replied to the credit conversion within hours with two months of free Codex for enterprise switchers, which is a price the incumbent can afford and the wrappers cannot. Notion's External Agents API now hosts Claude, Codex, Cursor, Decagon, Warp, and Devin inside one workspace, which commoditizes the interface layer from the other direction.

The honest recalculation for affected portfolio companies is that 20-40% of effective runway evaporated since Friday for any business running COGS against subscription-tier tokens. The change is days old. Most founders have not yet done the arithmetic.

What to do

  1. Audit every Claude-dependent portfolio company's gross margins by Friday — request updated cohort economics assuming full API-rate billing

  2. Apply a 20-40% 'reversibility discount' to any LLM-layer ARR in portfolio marks where SLAs and telemetry are absent

  3. Source AI observability and FinOps-for-AI companies at Seed through Series A before the category winner emerges

Agent Infrastructure: Incumbents Draw the Map While Startups Still Name the Category

The Data That Changes Everything

Vercel published the first production-grade index of real AI usage across 200K+ teams, and the headline number is definitive: agentic workloads are 59% of all token volume. The agent era is not coming. It is the majority case in production. But the bifurcation underneath is where the investment thesis lives: Anthropic captures 61% of spend (premium reasoning via Opus), while Google captures 38% of volume (commodity throughput via Flash). Two different businesses are now visible inside what we've been calling 'foundation models.'


Incumbents Move First

Three platform moves arrived in the same week that together redraw the investable surface:

  • SAP committed €100M to an Autonomous Enterprise fund with NVIDIA and Microsoft wired in
  • ServiceNow shipped Action Fabric — decoupling logic from UI, exposing workflows as headless APIs for agents to consume
  • a16z published its GTM thesis — system of intelligence captures the majority of the next decade's value, with Stitch as the first deployed check

The pattern is clear: the autonomous enterprise category is being defined by incumbents before pure-play startups can name it. This is the opposite of the cloud transition, where AWS defined infrastructure while incumbents caught up late.

When SAP underwrites a thesis with €100M and ServiceNow ships headless agent APIs in the same week, the question isn't whether agents matter — it's whether the startup opportunity window is 2-3 quarters or 4-6.

The Lemkin Proof Point

Jason Lemkin's SaaStr anecdote is the unit-economics template: cutting Salesforce from 10+ human seats to 2 humans + 1 API seat, while spend rose 83% ($12K → $22K) and 20+ agents run on top. The seat count collapsed. The bill went up. That is consumption-based GTM in one customer.

The investable wedge is narrow. Horizontal 'AI CRM' plays walk into Salesforce's API-first counter-punch. The survivors are companies with vertical orchestration depth, measurable outputs, and accumulating institutional context. The moat has shifted from data gravity to orchestration gravity — and the window before incumbents absorb the category is 12-18 months.

What Gets Compressed

Notion's developer platform hosting Claude, Codex, and Cursor as teammates, plus Airtable's $10M Hyperagent credit program, mean standalone agent-orchestration startups face distribution problems they cannot outspend. Vertical beats horizontal in agent ops from here.

What to do

  1. Source 3-5 agent infrastructure deals in MCP tooling, agent identity, and agent observability at seed/Series A pricing before SAP's corp dev team activates

  2. Map every pipeline deal against Notion/Airtable/ServiceNow platform displacement risk — flag any horizontal orchestration play that lacks vertical depth

  3. Request consumption/agent-usage metrics in all active AI-GTM diligence — specifically agent-to-seat ratio, API call growth, and NRR on existing logos

AI Security Exits the Thesis Phase — LiteLLM on KEV Is the MongoDB Moment

The Regulatory Milestone

LiteLLM became the first AI gateway to land on CISA's Known Exploited Vulnerabilities catalog — the federal register that mandates patching timelines for government systems. This is not a narrative event. It is the regulatory validation that turns 'AI security' from a pitch slide into a procurement line item with a budget code. Layer in Ollama's GGUF model-loader bug (CVSS 9.1, data exfiltration via malicious model files) and OpenClaw shipping six critical CVEs in one cycle, and the AI-infra stack is at the security maturity level enterprise SaaS was in 2014.


Three Converging Proofs

The evidence arrived from three separate directions this week:

  1. Microsoft's MDASH shipped 16 validated Windows CVEs in a single Patch Tuesday — the first production-scale proof that autonomous vulnerability discovery works. This compresses legacy scanner moats (Qualys, Tenable, Rapid7) on a timeline that matters.
  2. DepthFirst's Open Defense Initiative found 12 memory corruption bugs in FFmpeg for ~$1,000 vs. Anthropic's Mythos missing the same bugs at ~$10,000 — a 10x cost delta between specialized harness and frontier-model rental.
  3. PraisonAI's auth-bypass was exploited within 4 hours of disclosure — proving open-source AI-agent frameworks are now active attacker targets, not research curiosities.

The bifurcation matters for thesis construction: harness quality beats model selection. Mozilla found 271 bugs in Firefox with a custom agentic harness; Anthropic's Mythos found 1 real CVE in curl with a generic scan. The moat is in orchestration IP, not compute access.

AI infrastructure just crossed its first KEV threshold. The AI-security category is no longer a thesis pitch — it's a budget line, and the Series A window for the winners is opening now.

The EDR Moat Is Cracking From Both Sides

TrustedSec ran LLMs against five commercial EDRs and found all share identical architectural building blocks — YARA rules, Lua engines, local ML classifiers. Reverse engineering that took weeks now takes days. In the same week, OpenAI launched Daybreak with Cloudflare, Cisco, CrowdStrike, PANW, Oracle, Zscaler, Akamai, and Fortinet listed as launch partners — the classic platform-eating-partners setup.

Cloudflare cutting 20% (1,100 people) citing the 'agentic AI era' in the same week it joins Daybreak as a partner confirms at least one name on that list already reads the wind. Current EDR multiples price a detection-IP moat that is now visibly eroding.

What to do

  1. Run portfolio-wide exposure sweep for LiteLLM, Traefik, Argo CD, MOVEit, and PAN-OS by end of week — escalate any internet-exposed instances

  2. Pull forward AI-security diligence — target AI-gateway firewalls, model-artifact scanners, and LLM-runtime sandbox plays at Series A pricing

  3. Stress-test public EDR exposure (CRWD, PANW, S) assuming 30-50% detection-rule moat erosion over 24 months; revisit any private EDR deals at 2025 prices

The bottom line

Anthropic's $30B ARR is real but its enterprise infrastructure is consumer-grade — no SLAs, no telemetry, and ServiceNow blew its annual budget by May without either side noticing. Meanwhile Anthropic killed the subscription arbitrage that powered every Claude wrapper's economics. The $900B mark prices a franchise; the operating reality prices a reversible spend line with a metering problem. Your portfolio's Claude-dependent gross margins changed last Friday — find out by how much before the founders do.