Leadership & Executive

The Board Room

The Signal

Canva cut its growth outlook by a third because customers used the AI features too much.

Adoption above plan turns inference into cost of goods, and the pattern is not isolated: Figma's free-cash-flow margin halved to 14% over the same window. The fix here was architectural rather than commercial, a rebuilt delivery system that has taken cost per task down nearly 90% since April, deeper than any vendor price cut on the market. Which means the discount you are negotiating with your own provider this quarter is the smaller of the two levers available.

In Play

  1. Inference Cost Reaches the Guidance Line

    Canva cut its expected revenue growth by a third, to 20%, after AI feature costs came in above plan. CEO Melanie Perkins said demand for those features significantly exceeded expectations. Figma's free-cash-flow margin fell from 27% to 14% in the following quarter. PitchBook's Derek Hernandez names both as the clearest evidence that inference cost is eroding software economics. AI unit economics is now a CFO input, not an engineering footnote — and it lands before your next guidance cycle.

    Ask Clarity
    Try
  2. Announced Valuations Decouple From Price Paid

    Starcloud announced $170 million at a $1.1 billion valuation in March. Newcomer reports the first tranche, led solely by Benchmark, priced at roughly $250 million; the rest of the round closed days later at more than four times that. MVP Ventures' Weston Moyer puts dual-valuation rounds at about 25% of deals he has seen, and six other early-stage investors echo the estimate. Every comp band and acquisition comp you set against announced marks is biased upward, most of all in AI.

    Ask Clarity
    Try
  3. Offense Priced Like a Consumable

    Microsoft's AI security lead put the cost of finding a vulnerability and generating a targeted exploit at $3.61 and 21 minutes. Separately, one AI-assisted researcher found zero-click remote code execution flaws in Zoom using fewer than 20 prompts on publicly available models in under a day. Your risk model still prices attacker effort as scarce, which is why vulnerability counts and patch coverage no longer track loss. Treat the $3.61 as directional: it comes from a vendor selling the remedy.

    Ask Clarity
    Try
  4. Product-Design Liability Goes to Trial in Oakland

    A coalition of state attorneys general takes Meta to trial in Oakland later this month over claims its products harmed millions of young users, and Bloomberg calls it Meta's Big Tobacco moment. The remedies sought are mandated changes to age verification and data collection, not fines. If minors enter your funnel anywhere, whatever the court orders becomes the reference specification other regulators apply to you. Age assurance becomes platform infrastructure you have not built.

    Ask Clarity
    Try
  5. The Agent Harness Stops Being a Moat

    Meta shipped Muse Code, a coding agent whose model and orchestration harness were trained as one system, and Prime Intellect open-sourced a standalone harness, Prime Agent, in the same week. TheSequence reads them together: scaffolding is being absorbed from above and given away from below. If your agent differentiation is orchestration engineering, that line is now a cost center rather than a moat. The underlying analysis is paywalled; verify before you reallocate.

    Ask Clarity
    Try

Deep Dives

Customers Loved the AI Features and the P&L Broke

Inference stopped behaving like a project cost and started behaving like cost of goods, which is why the gate that saves next year's guidance has to be installed at this quarter's ship reviews.

The fix that worked was not a discount

Canva's remediation is the most transferable fact here and the least discussed. Instead of throttling the features customers were consuming, the company rebuilt its delivery architecture, and it reports cost per task down nearly 90% since Canva AI 2.0 launched in April. That is a deeper reduction than any vendor price cut on the market. The conclusion is uncomfortable for anyone waiting out token deflation: margin recovery lives in your stack, not in your vendor's price list.

Look also at what actually broke. Melanie Perkins' explanation is that demand for the AI features significantly exceeded expectations. The forecast error sat on the demand side; the damage landed on the cost side. Average-case cost modeling cannot catch that shape of failure, which is why the gate that matters is cost per task at projected peak demand rather than at plan.


Where the evidence converges

Four independent readings converge on one point: compute became continuous cost of goods while most companies were still budgeting it as project capex. Roughly two-thirds of enterprises run AI in production, and many have no cost or utilization visibility by workload. In the same body of research, 95% delayed or canceled AI projects, with governance and compliance among the top blockers, and nearly three-quarters say AI made data governance harder rather than easier. Adoption is not the constraint. Instrumented adoption is.

What's in the plan todayWhat it missesWhat replaces it
Token or seat price by vendorRetries, reasoning overhead, human reworkCost per completed task
Average-demand cost modelSuccess cases where usage overshoots planPeak-demand unit economics at the ship gate
AI spend as a project lineContinuous cost-of-goods behaviorWorkload cost reported beside gross margin

The open question is which cost metric wins. Frontier labs are defending premium list prices with an efficiency argument rather than a capability one, and at least one industry analysis claims premium models finish work for less once retries and human rework are counted. That analysis does not disclose its sponsor and it happens to flatter two US labs, so treat it as a hypothesis. The hypothesis still hands you the right question before your vendors do.


The demand-side version of the same bill

Upwork cut guidance and blamed AI automation and deteriorating organic search performance in the same breath. That is the template for any business that monetizes human hours or acquires customers through search: the cost line and the revenue line move against you at once. If either describes part of your portfolio, the pricing question — outcomes or time — is immediate rather than planning-season.

The smart move

Install the gate before you fund more scope. A measured cost-per-task number, owned jointly by the CFO and the CTO, does three things no vendor negotiation can: it makes an AI feature refusable, it makes guidance defensible, and it converts inference efficiency from an engineering hobby into a named function with a target attached.

Customers loving your AI features is no longer evidence the strategy works.

What to do

  1. Install a cost-per-task gate on every AI feature before the next ship approval, modeled at projected peak demand rather than average, with the CFO owning the gate and the CTO co-signing.

  2. Commission a 30-day effective-cost benchmark across your top five production AI workloads, counting retries and human rework, and report it beside gross margin at the next board meeting.

  3. Name an owner for inference efficiency this quarter with a target reduction on your three highest-volume workflows, covering routing, caching and distillation.

Your Comp Bands Are Priced Off a Number Nobody Paid

Tranched rounds, vintage-sorted discounts and record trophy marks are one signal: private prices now encode allocation panic, and your internal benchmarks inherited the error.

The first exposure sits on the cap table

This lands as a people problem before it becomes a diligence problem. Candidates and current staff get recruited and paid against a headline number the lead investor declined to pay, and the discounted tranche surfaces eventually. Mercor CEO Brendan Foody counted roughly half a dozen two-tranche Sequoia rounds in six months and called the practice deceptive in public, with names attached. Two consequences follow from that. A materially lower contemporaneous price inside the same financing raises fair-market-value questions around option strikes and 409A methodology. The second is slower and harder to unwind: an internal equity narrative anchored to the headline has a shelf life measured in news cycles rather than years.


What it does to every number worth benchmarking

The bias does not stay in the press release. If a quarter of announced marks overstate the blended price actually paid, everything built downstream inherits the error: acquisition comps built on those marks, comp bands set to what the market supposedly pays, and competitive threat assessments scaled to a rival's valuation. The distortion is widest exactly where attention is highest, in AI and frontier infrastructure. The venture-ethics version of this argument is one nobody wins and it is not worth having. The data-integrity version is a defect sitting inside board materials.

The tranching case does not stand alone. The other markers from the same week carry the same signature.

MarkerThe numberWhat it actually encodes
Tranched roundRoughly $250M lead tranche against a $1.1B headline, days apartBrand converted into a direct price concession
Kalshi re-rating$22B to $40B in about twelve weeksA run-rate doubled in two months, over 80% sports volume, active state litigation
Trophy assets$12.5B for the Lakers, about 25% above the roughly $10B paid a year earlierAn AI-first investor buying scarcity from a distressed seller instead of funding growth

Underneath the froth, capital is sorting with real discipline, just not on fundamentals. 87.5% of US venture dollars went to megadeals. 2021-vintage startups trade at a 59.1% median secondary discount while 2026 vintages trade at par. Funding year is setting price. That is a mispricing available to transact against rather than merely note.


The credibility question

A Sequoia partner publicly called tranching rare. Newcomer's reporting, seven investors on the record, and a founder-CEO's public accounting point the other way. Once a prevalence question turns into a credibility question for tier-one firms, the reputational asymmetry sits on the founder's side of the table, which makes one round, one price a demand that can be won today. The window closes as the story cools.

The move

There are two available, one defensive and one offensive. The defensive one is to haircut third-party marks in every internal model and to put counsel through the firm's own financing history for multi-price rounds. The offensive one is larger: a discount applied by vintage rather than by fundamentals is the best acquisition window since 2022, and the targets worth screening are teams carrying capability that would otherwise have to be hired in a talent market that just discovered its own price.

A 4x price move inside one round, closing days apart, prices allocation pressure. It does not price the company.

What to do

  1. Apply a written haircut policy this quarter to all third-party announced valuations used in board decks, compensation banding and acquisition comps, flagging AI and frontier-tech peers as high-distortion.

  2. Have counsel and your 409A provider review whether any tranched or multi-price financing sits in your own history, and pressure-test strike-price defensibility before the next option grant.

  3. Open an acquisition screen this quarter on 2021-2022 vintage assets trading at deep secondary discounts, prioritizing teams whose capability you would otherwise have to build.

The Metric That Still Tracks Loss Is Mean-Time-to-Contain

Attacker effort stopped being the scarce input this cycle, which retires the two numbers most boards still use to measure security and promotes one they rarely see.

Patched stopped describing a state

The useful reading of this cycle is not that three vendors had a bad week. A researcher published a working bypass of a shipped Microsoft Defender patch that escalates any level of access to SYSTEM, so organizations that patched on schedule remain exploitable and the pivot runs through their primary endpoint agent. SAP shipped a fix in the same window for a maximum-severity flaw in Commerce Cloud, a revenue system whose patch window is gated by change control rather than by security's calendar. A SharePoint authentication bypass, CVE-2026-55040 at CVSS 9.1, went from disclosure to in-the-wild exploitation the moment public proof-of-concept code shipped.

Assurance reporting now describes a condition that does not exist. The vocabulary of patched, covered and compliant rests on one assumption, which is that a shipped fix removes exposure. Publication of proof-of-concept code, not assignment of a CVE, is the operational start gun, and no enterprise test-and-deploy pipeline runs at that speed.


The asymmetry is organizational, not technical

DimensionOffensive AIDefensive AI
Cost of entryPublic models at consumables pricingSix-figure licenses plus integration
Integration requiredNoneDeep: monitoring, endpoint, ticketing, identity
Trust requiredNone, because false positives are freeHigh, because analysts must act on output
Binding constraintCompute, which is elasticHuman adoption, which is not

The bottom row is where the argument actually sits. Of the gaps slowing AI inside enterprise security operations, none is model capability; workflow fit, tool interoperability and analyst trust do the damage. A skeptic would answer that better models are arriving and will dissolve the problem. Better models are arriving. They do not fix workflow fit. The constraint on defensive AI return is a change-management problem in a technology costume, which moves the purchase criteria toward integration depth and explainability rather than benchmark scores, with change management funded at parity with license cost.


The math that should move the budget

Across 338 million attack simulations, controls blocked 69% of attacks at the perimeter but stopped an attacker already inside only 37% of the time. As a portfolio statement, prevention dollars are roughly twice as productive as containment dollars, which is precisely why the marginal dollar now belongs on the containment side. Phishing supplies the timing: links are clicked a median of 21 seconds after an email is opened, so any response depending on user reporting or queue triage arrives after the outcome has been decided. Both figures come from vendor-sponsored research; reproduce them against your own purple-team telemetry before either enters a board deck.

One layer sits outside all of this. New research localizes agent compromise to the harness, meaning the orchestration, tool-call boundaries and glue code wrapped around the model, where almost no one has telemetry. That exposure accrues to platform engineering rather than the security team, it compounds fastest, and it is still cheap to get ahead of.

The board reporting is the lagging indicator

Vulnerability counts and patch-coverage percentages no longer correlate to loss, so they lose their slide to blast-radius coverage, segmentation completeness and mean-time-to-contain. The endpoint consolidation decision justified on bundling economics deserves a rerun with the patch bypass as the test case. That choice is made this quarter and shows up as blast radius next year.

When weaponizing a bug costs less than a coffee, raising attacker cost is finished as a strategy; shrinking what a successful attacker reaches is what remains.

What to do

  1. Replace vulnerability counts and patch-coverage percentages in the next board security review with blast-radius coverage, segmentation completeness and mean-time-to-contain.

  2. Demand a named owner and a compensating control, not a patch date, for the Defender bypass, the SAP Commerce Cloud flaw and the Zoom zero-click within the week.

  3. Rerun the endpoint consolidation decision this quarter against one independent detection option, using the shipped-patch bypass as the evaluation test case.

The bottom line

The numbers you plan against are increasingly produced by whoever benefits from them — a headline mark, a sticker price, a coverage percentage, a detection score — while the number that predicts your outcome has to be computed inside your own systems. Benchmarking against public figures is not cheap diligence; it is the most expensive shortcut on your P&L, and the gap widens every quarter you defer instrumentation. Pick the three decisions most dependent on someone else's arithmetic, assign each a named owner, and fund the internal measurement that replaces it.