Investment & Market Intelligence

The Investor

The Signal

Anthropic is at thirty billion in ARR with enterprise plumbing that would embarrass a

ServiceNow burned its full-year Claude budget by May, which is what happens when the vendor offers no SLAs, no per-user telemetry, and no granular cost controls. On June 15 the seventy to ninety percent subscription arbitrage funding the Claude wrapper ecosystem goes away.

In Play

  1. Enterprise AI Revenue Quality ≠ SaaS Revenue Quality

    ServiceNow blew its full-year Anthropic budget by May with zero telemetry warning. Anthropic's June 15 credit unbundling kills the 70-90% arbitrage third-party harnesses ran on subscriptions. Enterprise AI ARR lacks SLAs, usage attribution, and switching costs — it reverses faster than SaaS ever did.

    Ask Clarity
  2. Agent Infrastructure: Platform Owners Draw the Category Line First

    SAP deployed €100M into an autonomous enterprise fund. ServiceNow shipped Action Fabric, decoupling logic from UI for agent consumption. Vercel's production data shows 59% of token volume is now agentic. a16z published the system-of-intelligence thesis and wrote a check to Stitch. Apple is gating agents through App Store governance. The incumbents are defining the category before startups can name it.

    Ask Clarity
  3. AI Security Crosses the KEV Threshold — Category Formation

    LiteLLM's AI Gateway landed on CISA's KEV — the first LLM-routing control plane federally flagged as actively exploited. Microsoft's MDASH shipped 16 validated CVEs in one Patch Tuesday cycle. DepthFirst claims 10x cost advantage over Anthropic's Mythos on vulnerability discovery. Mythos cleared both UK AISI ranges and Congress routed access through NSA, not CISA. AI security moved from pitch slide to budget line in a single week.

    Ask Clarity
  4. Cerebras First-Day Returns Validate SPV-Augmented Ownership Model

    Cerebras closed at $311 — a 70% first-day pop against Tiger's $89 entry months prior. Eclipse netted 17x on its $146.5M total cost basis. Benchmark broke its own dogma to raise a $225M SPV, which represented 93% of its cost basis and lowered its fund multiple. The message to LPs: SPV infrastructure is now mandatory to defend ownership through AI megarounds.

    Ask Clarity
  5. xAI Exits Frontier Race — Becomes a Compute Landlord

    Anthropic leased the entire Colossus 1 cluster — 220K+ GPUs including GB200s — from xAI, confirming 80x growth vs. 10x plan forced capacity triage. xAI renting 45% of its current compute to a declared enemy signals frontier retreat. Developer surveys show Grok behind DeepSeek and Qwen. Reprice any xAI exposure as infrastructure + X-distribution, not a frontier lab.

    Ask Clarity

Deep Dives

The Anthropic Paradox: $30B ARR on Consumer-Grade Enterprise Plumbing

The Revenue Quality Problem Nobody Wants to Name

ServiceNow, one of the most sophisticated enterprise software buyers on the planet, exhausted its full-year Anthropic budget by May 2026. Not because Claude underdelivered. Because Anthropic ships no granular per-user or per-tool telemetry, no SLAs worth the name, and no enterprise dashboard that would have passed muster at a mid-tier SaaS vendor in 2014. National Life Group's CIO put it plainly: Anthropic is 'great for consumer usage but not great for companies.'

This lands the same week Anthropic conceded it planned for 10x growth and got 80x, which is how you end up leasing the entire Colossus 1 cluster (220K+ GPUs) from Elon Musk's xAI. The same Musk who recently called Anthropic 'misanthropic and evil.' When you are renting compute from a declared enemy, the word for your situation is not glut. It is a shortage that bends strategy.


The June 15 Margin Event

On June 15 Anthropic converts every Claude subscription into a dollar-matched API credit pool. Two hundred dollars of subscription buys exactly two hundred dollars of programmatic tokens, which kills the 70-90% arbitrage that Cline, OpenCode and OpenClaw were running against subscription-tier usage. OpenAI answered inside the day with two months of free Codex for enterprise switchers.

Every Claude-wrapper portco whose COGS assumed subsidized subscription tokens just lost 20-40% of effective runway. The change is four days old; founders may not have flagged it yet.

The interesting framing is that this is a margin-recovery move explicitly timed to IPO diligence. A new CFO, credit unbundling, and a likely October target add up to a textbook pre-book cleanup. Anthropic is trading short-term developer goodwill for public-market-ready margins. There is a version where developer churn matters more than the margin print. Probably not the version the bankers are pitching.


The Observability Gap Is the Category

Four firms independently reached the same conclusion this week: deployment is the bottleneck, not model capability. Google Cloud is hiring hundreds of forward-deployed engineers. OpenAI stood up DeployCo with Bain. Salesforce and ServiceNow are staffing the same function. The industry has quietly conceded what Palantir worked out twenty years ago.

Meanwhile ServiceNow is selling its AI Control Tower to the same customers panicking over their Anthropic bills, which is not coincidence so much as a CDIO who watched a category form inside her own P&L and decided to be the vendor rather than the line item. Modal at $4.5B and the rest of the AI FinOps layer are being born out of one failure mode.

The Investable Layer

  • AI observability / FinOps — token-level cost attribution, per-user caps, SLA monitoring across model APIs. No category winner yet. 6-12 month sourcing window.
  • Deployment-services tooling — productizing 60% of FDE work (context ingestion, eval harnesses, workflow templates).
  • Vertical AI with contractual lock-in — in a world where horizontal LLM spend reverses quarterly, vertical AI with data moats gets structurally more valuable.

What to do

  1. Demand updated gross-margin models from every Claude-dependent portco assuming the 70-90% subscription arbitrage is permanently gone — deadline May 23

  2. Source 5-8 AI observability/FinOps companies at Seed-Series A and schedule first meetings within 14 days

  3. Apply a 20-40% 'reversibility discount' to any LLM-layer ARR multiple in active deal flow where SLAs, telemetry, and contractual switching costs are absent

  4. Map portfolio to forward-deployed-engineering category — identify which portcos benefit from or compete against the Google/OpenAI/Bain/Salesforce FDE buildout

Agent Infrastructure: Incumbents Are Drawing the Map Before Startups Can Name the Territory

The Category Formation Event

Three moves landed in the same week that, taken together, draw the autonomous enterprise as a funded category rather than a deck slide. SAP put €100M into an Autonomous Enterprise partner fund, wiring NVIDIA and Microsoft into the platform layer. ServiceNow shipped Action Fabric, which decouples workflow logic from UI and exposes it as headless APIs for agents to call. And a16z published its system-of-intelligence thesis, arguing that most next-decade GTM enterprise value migrates from the system of record (Salesforce at $140B, HubSpot at $9B) to the orchestration layer, and wrote a check to Stitch to back the argument with money rather than prose.

When SAP underwrites a thesis with a hundred-million-euro fund and ServiceNow simultaneously ships a headless architecture built for third-party AI agents, what you are watching is the autonomous enterprise category being drawn by the incumbents before the pure-plays get to name it.

Vercel's Production Data: Agents Are the Majority Case

Vercel published the first production-grade index of real AI usage across more than 200,000 teams. The numbers do most of the work:

  • 59% of token volume is now agentic workloads, which is the base case rather than the upside case
  • Anthropic captures 61% of spend, paid for premium long-context agent calls
  • Google captures 38% of volume, absorbing the commodity high-throughput tier

Two different businesses are now visible inside what people kept calling 'foundation models.' Anthropic is being paid a premium for tool-using agent calls. Google is absorbing cheap throughput that looks excellent on a volume chart and considerably less excellent on a margin table. Multi-model routing is the enterprise default, not a sophistication.


The Platform Tax Arrives

Apple is building agent governance directly into the App Store, blocking agents from spinning up sub-apps outside review and defending the 30% fee on agent-mediated transactions. Google's Gemini Intelligence embeds autonomous task execution into Android at the OS level. Both moves reprice every pure-play mobile agent startup whose GTM assumed distribution was free, which is most of them.

The a16z proof point earns its own paragraph. Jason Lemkin cut Salesforce from 10+ human seats to 2 humans + 1 API seat, while spend rose 83% ($12K → $22K) with 20+ agents running underneath. Seats collapsed, the bill went up, and that is the consumption-based GTM pitch delivered in a single customer. A sample size of one, which is how every thesis starts.

Where Alpha Remains

WedgeWindowBar to Clear
Agent identity, MCP governance, observabilitySeed/Series A — 6-12 monthsMust solve the compliance gap incumbents are flagging
Vertical orchestration (regulated, high-frequency)Series A — 12-18 months before absorptionProprietary workflow data + measurable outputs
Cross-platform agent runtimesSeries A/B — the Apple/Android split creates demandMCP-native, web-native, neutral across OS

The counter-thesis is straightforward: incumbents absorb this functionality in one quarter rather than two, and the window closes before Series A checks clear. That has happened before in enterprise software. It is also not what SAP's €100M or ServiceNow's architecture choices suggest, both of which read as explicit admissions that the incumbents need external help.

What to do

  1. Source 3-5 agent infrastructure deals in MCP tooling, agent identity/auth, and agent observability — schedule IC presentations within 45 days

  2. Stress-test every portfolio company against the Apple WWDC agent-governance announcement — identify any whose GTM assumes friction-free agent distribution on iOS

  3. Request consumption/agent-usage metrics in all active AI-GTM diligence — specifically agent-to-seat ratio and NRR on existing logos

  4. Map pipeline against the 'agent-hosting platform' displacement risk — identify which deals die if Notion, Airtable, or Cursor absorb the workflow

AI Security Hit Its KEV Moment — Fund the Category Before Series B Prices It

The Production Threshold

LiteLLM hit KEV the same week MDASH shipped sixteen CVEs and DepthFirst beat Mythos ten-to-one on FFmpeg, which is enough to move AI security from conference track to enterprise line item with unusual specificity. LiteLLM's AI Gateway landed on CISA's Known Exploited Vulnerabilities catalog, the first LLM-routing control plane federally flagged as actively exploited. Microsoft's MDASH multi-model system shipped 16 validated Windows CVEs in a single Patch Tuesday cycle, which is the first auditable evidence that autonomous vulnerability discovery actually works in production rather than at conferences. And DepthFirst's Open Defense Initiative found twelve memory corruption bugs in FFmpeg for roughly a thousand dollars of compute, against Anthropic's Mythos missing the same bugs at about ten thousand.

When a routing layer hits KEV, the procurement consequence is concrete: a CISO now has a documented, federally-listed exploited control plane to point at, which is the first defensible reason to cut an enterprise check specifically for AI infrastructure security.

The Bifurcation: Offense vs. Defense Economics

Two economics are forming at once and they do not rhyme. On offense, capability is compounding faster than anyone modeled, with AI cyber tasks breaking above the 'doubling every few months' trendline to the upside. Anthropic's Mythos cleared both UK AISI simulated attack ranges as the first model to do so, and Congress routed access through NSA — not CISA. That routing matters more than the clearance does. Intelligence-community procurement runs on different budgets and meaningfully higher margins than civilian defensive distribution, with a different buyer attached.

On defense, the attack surface is expanding at machine speed. A single AI honeypot absorbed 113K+ requests in a month after Shodan indexed it within three hours. PraisonAI's CVE was weaponized within four hours of disclosure. And the Shai-Hulud supply-chain framework was open-sourced under MIT, documenting industrial-grade Sigstore provenance forgery and OIDC token extraction from GitHub Actions runner memory.


The Incumbent Moat Is Cracking

TrustedSec ran LLMs at five commercial EDRs and found that reverse engineering which used to take weeks now takes days, because all five products share the same architectural furniture (YARA rules, a Lua engine, local ML classifiers). In the same week, OpenAI launched Daybreak with Cloudflare, CrowdStrike, PANW, Cisco, Zscaler, Akamai, and Fortinet listed as 'partners.' The partner list is the tell. It is the pre-disintermediation setup that has played out in four prior enterprise software waves, and the partners on that list have presumably read the same history.

The Investment Map

Sub-categoryStageEntry Window
AI-gateway security (LiteLLM-class defense)Pre-category, first KEV triggerSeries A — now
Autonomous vuln discovery (harness + orchestration)Category forming — DepthFirst, XBOWSeries A/B — this quarter
AI-native identity/deepfake defense$40B 2027 TAM anchor establishedSeries B — before consensus
Supply-chain/SBOM (Sigstore forgery response)Demand certain after Shai-Hulud leakSeries A — 12 months
Legacy scanner/EDRMoat eroding via AI-assisted RETrim/short — 18-36 months

The diligence question for any AI AppSec pitch, or rather the only one that matters: does the harness produce 271 bugs (Mozilla's Firefox result) or 1 bug (Mythos on curl)? The difference is the harness investment, not the model. Fund harnesses, not wrappers.

What to do

  1. Run a portfolio-wide exposure sweep for LiteLLM (versions 1.81.16–1.83.7), Traefik, Argo CD, and Ollama — confirm patched or mitigated by end of week

  2. Open dedicated diligence tracks on AI-gateway security and autonomous AppSec — target 3-5 companies and schedule first meetings within 30 days

  3. Stress-test every security portfolio company's value prop against a world where AI-assisted reverse engineering extracts EDR detection logic in days, not weeks

  4. Add 'Daybreak competitive displacement' to the standing agenda for every security portco board meeting — require a written 18-month defensibility rationale

The bottom line

Anthropic's $30B ARR masks consumer-grade enterprise plumbing that ServiceNow blew through by May without a single telemetry warning — and on June 15, the subscription arbitrage powering the Claude wrapper ecosystem dies permanently. The AI revenue quality gap between headline growth and contractual durability is the most actionable mispricing in the stack right now: short the model-layer revenue-quality premium, long the observability and deployment-services layer being born from its absence, and fund AI security before the KEV listing reprices the Series A window.