Investment & Market Intelligence

The Investor

The Signal

Anthropic's June 15 pricing change closed the seventy-to-ninety percent subscription

ServiceNow, separately, burned its full-year Anthropic budget by May with no enterprise telemetry or SLAs to slow it down — call that reversible spend rather than SaaS ARR, or at least the more interesting version of that argument.

In Play

  1. Enterprise AI Revenue Quality Is Structurally Fragile

    ServiceNow exhausted its full-year Anthropic budget by May due to zero usage telemetry. Anthropic's June 15 credit unbundling kills 70-90% arbitrage for Claude wrappers. No SLAs, no per-user dashboards, reversible spend. Enterprise AI ARR ≠ SaaS ARR — apply 20-40% reversibility discount.

    Ask Clarity
  2. Agentic Workloads Hit 59% — Platform Absorption Accelerates

    Vercel's production gateway shows agentic workloads now carry 59% of all token volume. Anthropic captures 61% of spend while Google takes 38% of volume — two different businesses inside 'foundation models.' Notion, SAP (€100M fund), and Airtable ($10M credits) are absorbing the agent-hosting layer, compressing standalone orchestration startups.

    Ask Clarity
  3. AI Infrastructure Security Crosses KEV Threshold

    LiteLLM's AI gateway landed on CISA's KEV catalog — first LLM-routing control plane flagged as actively exploited. Microsoft MDASH shipped 16 validated CVEs in one Patch Tuesday. DepthFirst claims 10x cost efficiency over Anthropic Mythos. PraisonAI exploited within 4 hours. AI-sec is now a budget line, not a pitch slide.

    Ask Clarity
  4. Vertical AI Data Moats Validated — Horizontal Wrappers Compress

    Abridge raised $550M at $5.3B with 250 health systems and 80M+ conversations — an unreplicable data moat. Claude for Small Business ships QuickBooks/HubSpot connectors, killing generic SMB AI. a16z's GTM thesis explicitly says orchestration gravity > data gravity. The bar for new AI deals is proprietary per-use data flywheels, not model access.

    Ask Clarity
  5. GTM Software Value Migrates from Record to Intelligence Layer

    a16z published its thesis and backed Stitch: system of intelligence captures majority of next decade's GTM enterprise value. Lemkin's proof point — 2 human seats replacing 10+, spend up 83%, 20+ agents running — is the unit-economics template. Salesforce ($140B) becomes infrastructure consumed at API layer. Investable window: 12-18 months before incumbents or consensus close it.

    Ask Clarity

Deep Dives

Enterprise AI ARR Is Not SaaS ARR — The Revenue Quality Problem Nobody Is Pricing

The Structural Problem

ServiceNow, which is one of the more sophisticated enterprise software buyers on the planet, burned through its full-year Anthropic budget by May 2026. Not because Claude underdelivered. Because Anthropic offers no per-user telemetry, no granular usage dashboards, and no SLAs worth printing. The National Life Group CIO put it about as plainly as a CIO ever puts anything: Anthropic is 'great for consumer usage but not great for companies.'

Then on May 12 Anthropic converted every Claude subscription into a dollar-matched API credit pool, which is to say it killed the 70-90% arbitrage the wrapper crowd (Cline, OpenCode, dozens more) had been quietly running. OpenAI countered inside the same news cycle with two months of free Codex for enterprise switchers. The coding-agent category is now in an open subsidy war, conveniently timed to Anthropic's likely October IPO.

Enterprise AI spend reverses quickly once cost-efficient alternatives land. No SLAs + no telemetry + no switching costs = a cliff-shaped revenue risk profile.

What This Means for Your Book

Ramp has Anthropic at 34.4% of business spend against OpenAI at 32.3%, which is the first documented lead change and is being read by some as a regime shift. It is not. Billing share is not the same as durable revenue, and three things make enterprise AI ARR structurally unlike SaaS:

  • Zero contractual lock-in: no multi-year contracts, no SLAs, no data gravity in most deployments
  • Budget opacity: customers cannot see per-user or per-workflow spend until the bill arrives
  • Instant reversibility: the Ramp data itself shows vendor share flipping on each model release cycle

The FDE land-grab is the tell. Google is hiring hundreds of forward-deployed engineers, OpenAI stood up DeployCo with Bain, Salesforce and ServiceNow are staffing the same function. When four firms independently conclude the margin sits in deployment rather than the model, the margin sits in deployment rather than the model.

The Arbitrage That Just Died

Any portfolio company running COGS against Claude subscription tokens lost somewhere between 20% and 40% of effective runway since Friday. The June 15 change is explicit: programmatic usage bills at API rates. Founders may not have flagged it yet because the change is days old. This is a triage call for this week, not a line item for next quarter's board deck.


Where the Alpha Moves

The displacement trade is unusually clean, or rather, the more interesting version of it is: short the model layer's revenue-quality premium, long the observability and deployment layer that fixes what Anthropic will not build. This is probably wrong in at least one direction, but here is the shape.

  1. AI observability and FinOps-for-AI: token-level cost attribution, per-user spend caps, SLA monitoring. ServiceNow's AI Control Tower is the first comp and there is no independent category winner yet.
  2. Deployment services tooling: productize 60% of FDE work, meaning context ingestion, custom eval harnesses, workflow templates. Palantir alumni are the sourcing pool.
  3. Vertical AI with contractual lock-in: in a world where horizontal spend is reversible, vertical AI with data moats and compliance integration becomes structurally more valuable.

What to do

  1. Request updated gross-margin models from every Claude-dependent portfolio company assuming API-rate billing replaces subscription arbitrage

  2. Build AI observability/FinOps sourcing sprint targeting Seed-Series A companies with token-level attribution

  3. Apply a 20-40% 'reversibility discount' to any portfolio LLM-layer ARR where SLAs and telemetry are absent

  4. Demand SLA and usage-telemetry roadmap from Anthropic/OpenAI in next board cycle for any model-dependent portco

Agent Infrastructure Is Consolidating Into Platforms — 12-Month Window Before Absorption

The Data Point That Changes the Frame

Vercel's first production-grade AI Gateway index covers more than 200,000 teams, which is a sample large enough that the headline number stops being a vendor anecdote: agentic workloads now carry 59% of all token volume. The majority case in production is no longer human-in-the-loop chat. The bifurcation has been visible in earnings transcripts for two quarters. The index just makes it numerical, and the spend-volume split shows two businesses hiding inside the phrase 'foundation models'.

MetricAnthropicGoogle
Share of spend61% (via Opus)~15%
Share of volume~25%38% (via Flash)
Business modelPremium reasoningCommodity throughput

Anthropic is being paid a premium for the long tool-using calls that agents generate, the ones that happen to be expensive. Google absorbs cheap high-throughput work that looks excellent in a volume chart and considerably less excellent in a gross margin table. Multi-model routing is now the enterprise default, which validates the orchestration layer and quietly retires any thesis still underwriting a single-model moat.

Platforms Are Moving First

Three platform moves landed in one quarter. Anthropic's June 15 third-party credit unbundling recovered margin the resellers had been sitting on. Notion's developer platform now hosts Claude, Codex, Cursor, Decagon, Warp, and Devin as teammates inside a surface enterprises already pay for. SAP's €100M Autonomous Enterprise fund wires NVIDIA and Microsoft into the platform layer with capital the standalone vendors do not have. Airtable's $10M Hyperagent credit program rounds out the picture: workflow incumbents are absorbing the agent-hosting surface before pure-play orchestration startups can define it.

When SAP underwrites a thesis with €100M and ServiceNow ships headless APIs for agents to consume, the standalone agent-ops category has 12-18 months before it becomes a feature inside an existing renewal.

Where the Investable Window Remains

a16z's GTM thesis lines up with Lemkin's proof point, where 2 human seats replaced more than 10 and spend rose 83% on the back of 20+ agents in production. That confirms the value migration is real. The system of intelligence layer is where the moat now sits, built on orchestration gravity and the accumulated workflow context that competitors cannot replay cheaply. The window is narrower than it sounds.

  1. Agent infrastructure picks-and-shovels: MCP gateways, agent identity and auth, knowledge-graph tooling, observability. Series A pricing is still rational. Expect a reset inside 2 quarters as corp dev activates.
  2. Vertical orchestration with institutional context: narrow high-frequency workflows like research, prospecting, and structured note-taking, with measurable outputs and NRR exceeding 150%. The Stitch archetype.
  3. Consumption-pricing proof points: 3+ customers showing 10x agent deployment, 80% seat reduction, and 80%+ spend increase clears the bar for premium multiples.

What to Avoid

Horizontal agent-ops companies face distribution asymmetry they cannot outspend. This is probably wrong in one or two specific cases we will eventually have to write about, but the pattern of Notion, Cursor, and Airtable absorbing agent hosting into existing workflow surfaces is not a problem standalone orchestration startups solve with capital alone. Vertical beats horizontal in agent ops from here.

What to do

  1. Map pipeline against 'agent-hosting platform' displacement risk — identify which deals get absorbed if Notion/SAP/Airtable ship the feature

  2. Source 3-5 agent infrastructure deals in MCP tooling, agent identity, and agent observability before SAP's corp dev team does

  3. Request Vercel AI Gateway production index as recurring data source; use spend/volume split as diligence benchmark

  4. Stress-test portfolio cos using third-party Claude integrations against June 15 pricing — model gross margin impact if API-rate billing kicks in

AI Security Crosses from Pitch Deck to Budget Line — Fund the Category Before Series B Reprices

The KEV Moment

LiteLLM, the LLM-routing control plane sitting inside thousands of enterprise AI deployments, landed on CISA's Known Exploited Vulnerabilities catalog this cycle, which is the first time the federal government has flagged an AI-infrastructure component as actively exploited in the wild. Ollama shipped a CVSS 9.1 data-exfiltration bug via malicious model files in the same window, and PraisonAI was weaponized within 4 hours of disclosure. The AI-infra stack is, in security maturity terms, somewhere around where enterprise SaaS was in 2014.

Meanwhile Microsoft's MDASH multi-model system quietly shipped 16 validated Windows CVEs in a single Patch Tuesday, which is the first auditable evidence that autonomous vulnerability discovery works at production scale rather than in a demo. DepthFirst's Open Defense Initiative claims 10x cost efficiency over Anthropic's Mythos, finding 12 memory corruption bugs in FFmpeg for roughly a thousand dollars where Mythos missed the same at ten thousand. Take the cost ratio with a grain of salt; the directional point survives the discount.

When rivals rent compute from enemies and AI gateways land on KEV, you are not in a security narrative. You are in a category formation event with a 6-12 month pricing window.

The Bifurcation

AI security is splitting into two businesses with economics that share almost nothing:

SegmentSignalWindow
AI gateway securityLiteLLM KEV; Ollama CVSS 9.1Series A now
Autonomous vuln discoveryMDASH 16 CVEs; DepthFirst 10xSeries A-B, 12 months
LLMjacking defense113K requests/month on honeypot; 175 hijack attempts/weekPre-category seed
Agentic SOC/GRCExaforce, Drata, Teleport all shipped same weekSaturating — raise bar
Identity/deepfake defense$40B projected US losses 2027Series B before consensus

That Mythos Congressional briefing routed through NSA rather than CISA is the tell. The first federal dollars in this category flow through intelligence community procurement, not civilian defense, which means weight toward teams with TS/SCI cleared talent and offensive-AI primitives wrapped in compliance. The capital is not going where the press releases imply.

What Gets Repriced Down

TrustedSec pointed LLMs at five commercial EDRs and reported reverse engineering now takes days, not weeks. All five products rest on identical architectural furniture, YARA rules, Lua engines, local ML classifiers, which is fine until the cost of pulling them apart drops by an order of magnitude. OpenAI's Daybreak launched with CrowdStrike, PANW, Zscaler, and Fortinet as 'partners', which is the pre-disintermediation seating chart that has played out in four prior waves of enterprise software. This is probably wrong, but: detection-rule IP is becoming a commodity input, and current EDR multiples are priced for the old moat.

The Harness Is the Moat

Mozilla's custom agentic harness on top of Claude found 271 bugs in Firefox. Anthropic's Mythos, running a generic scan, found 1 real CVE in curl, which the maintainer publicly called 'primarily marketing.' The delta is harness quality, not model quality, which is the more interesting version of the bull case. Fund the orchestration and CI-integration layers. The generic 'LLM finds bugs' pitch is already cheap.

What to do

  1. Pull forward AI-security diligence by one quarter — specifically AI-gateway firewalls, model-artifact scanners, and LLM-runtime sandboxing

  2. Request DepthFirst data room and validate 10x cost claim against Mythos on 2-3 additional codebases before next round prices up

  3. Run portfolio-wide exposure sweep for LiteLLM, Ollama, Traefik, Argo CD, and PraisonAI — escalate any internet-exposed instances

  4. Apply the 'Mozilla vs curl' test to every AI AppSec pitch — if founder can't explain 271 bugs vs 1, they're selling the model not the product

Vertical AI Moats Are Built from Data, Not Models — The Abridge Template

The Category Winner Print

Abridge raised $550M in 2025 alone ($250M early year, $300M at a $5.3B mark in June), services 250 large US health systems, and processes 80M+ patient-clinician conversations annually across 28 languages and 50 specialties. That corpus is unreplicable — no foundation model or new entrant can buy or scrape it. The category is effectively closed for ambient clinical documentation in US large health systems.

The more under-appreciated signal: health systems — historically the slowest enterprise buyers on earth — compressed release cadence from quarterly/biannual to monthly for Abridge. This rewrites velocity assumptions in every healthcare SaaS DCF.

The Template for Vertical AI Underwriting

Abridge's three-act structure is the playbook to generalize:

  1. Save Time (documentation) → wedge into CMIO budget
  2. Save Money (prior auth, RCM) → expand to CFO budget
  3. Save Lives (clinical decision support) → unlocked by Jan 2026 FDA guidance

Each act monetizes the same proprietary conversation asset against a different stakeholder. The non-compete posture with Epic/Cerner — framing itself as a 'clinical intelligence layer' rather than a workflow replacement — is the existential-risk mitigation that makes the story investable at scale.

The investable wedge in vertical AI isn't better models — it's per-use data flywheels that compound with every customer interaction and can't be accessed by competitors.

Why Horizontal AI Wrappers Are Getting Killed

Claude for Small Business shipped with connectors into QuickBooks, PayPal, HubSpot, Google Workspace, and Microsoft 365. That is a horizontal land grab where the connectors are the product. Survivors need vertical depth, regulated workflow access, or proprietary data the connectors cannot replicate. Most pitches do not clear this bar.

The contrast with pre-product thesis bets is stark: Recursive Superintelligence raised $650M at $4B+ on seven co-founders and a thesis. Mind Robotics hit $3.4B at six months old. These are late-cycle optionality plays, not category-defining moats. The Abridge template — per-use data flywheel + ≥2 monetization vectors + explicit non-compete with system-of-record — is what separates durable vertical AI from expensive bets.

Adjacent Opportunities

The category-leader print at $5.3B doesn't close the healthcare AI book — it opens three chapters:

  • Payer-side prior authorization: Abridge attacks from provider side; payer counterparty remains greenfield
  • Nursing and short-form clinical workflows: 30-second visits are a fundamentally different product surface
  • International and specialty verticals: Vet, dental, behavioral health — markets Abridge won't prioritize for 24+ months

What to do

  1. Kill or de-prioritize any active deals on direct ambient-scribe competitors targeting US large health systems

  2. Update vertical AI underwriting framework to require per-use data flywheel, ≥2 monetization vectors, and explicit non-compete posture vs. dominant system-of-record

  3. Build thesis memo on payer-side prior-auth automation with target list of 8-12 startups to meet this quarter

  4. Diligence SMB vertical AI pipeline against Claude for Small Business connector roadmap — kill or double down

The bottom line

Enterprise AI revenue isn't SaaS revenue — ServiceNow blew its Anthropic budget by May with no telemetry to stop it, Anthropic's June 15 pricing change just killed the 70-90% wrapper arbitrage, and Ramp's enterprise share flip (34.4% vs 32.3%) proves vendor loyalty in AI is effectively zero. The three highest-conviction plays this week: triage every Claude-dependent portfolio company's unit economics before month-end, fund AI observability and agent infrastructure before platforms absorb the category in 12 months, and concentrate vertical AI bets on companies with unreplicable per-use data moats (the Abridge template) while killing horizontal wrappers that Anthropic's own connector roadmap makes redundant.