Product & Strategy

The Product Desk

The Signal

McDonald's mailed a journalist its predictions of his next order, spend, and churn.

The export ran 515 pages, and buried in it was a 0% churn score — a model output nobody designed for a customer's eyes. Subject-access rights turn every derived field in a personalization stack into publishable copy, which means the disclosure surface opens the moment the field is written, not when legal gets around to reviewing it. The forcing question for your next scoring feature: if the person being scored read this value tomorrow, would you still ship it?

In Play

  1. Attackers Want Sessions, Not Passwords

    Today's through-line: what your product infers, what it iterates, and what it retains each acquired an outside auditor — and each of those auditors prices it differently than your roadmap does. Two comfortable assumptions die with that: that an unmetered cost is not a cost, and that governance is work you schedule after a feature ships. Start with the item that is live right now. A spoofed CCleaner download site is stealing Chrome session cookies and authentication tokens, which breaks the remediation copy your product ships today. Argued in the first deep dive.

    Ask Clarity
    Try
  2. Derived Predictions Are Export Artifacts

    One subject-access request turned a loyalty program's internal predictions into publishable copy. And the pricing layer is where personalization turns adversarial. Same deep dive, one door over.

    Ask Clarity
    Try
  3. The 2027 Inference Discount Loses Two Legs

    Two independent supply signals plus a pre-listing model vendor argue against the annual cost deflation baked into your FY27 plan. Note that the trend below plots that vendor's projected annual revenue, not your compute cost. What to change in the model is in the second deep dive.

    Ask Clarity
    Try
  4. Agents Became A Capacity Line Item

    Brex's environment bill and AMD's host-CPU argument name the same missing entry: agent cost scales with invocations, not seats. The third deep dive has the funding template and the vendors now selling that layer.

    Ask Clarity
    Try
  5. Compliance Is Becoming Negotiated Approval

    NHTSA and DOT granted Zoox a commercial exemption from eight federal motor vehicle safety standards over two days in late July 2026, per TLDR Hardware. The condition: NHTSA issues evolving 'Operational Authorizations' as the self-driving system matures. If you ship into a regulated domain, static compliance is turning into capability-linked approval that rewards early agency engagement — and can be narrowed after one high-profile incident.

    Ask Clarity
    Try

Deep Dives

What Your Product Keeps Is Now Somebody Else's Evidence

One active campaign steals sessions your logout never ends. One export request exposed predictions a brand never meant to show. Same defect class, two different doors.

The payload names the objective

A user downloads what looks like CCleaner, runs it, and by the time the support ticket lands has already rotated their password and feels finished. Read the exfiltration list on that spoofed-CCleaner campaign in the order of what each item actually buys the attacker: credentials, then cookies and authentication tokens, then keystrokes and screenshots, delivered by multi-stage malware that hijacks Chrome, per Computerworld. Credentials are the least valuable item on the list. A live session token is already authenticated, frequently long-lived, and in many implementations survives both a password change and a second factor. So the sentence most products ship in their incident email, reset your password and you are safe, is factually false here. The support macro is telling users to rotate a secret the attacker stopped needing.

Three requirements this puts in the auth PRD

  1. Device-bound or short-TTL tokens, so a stolen cookie decays or fails outside its origin device.
  2. Server-side global sign-out that actually invalidates refresh tokens, not a client-side clear that leaves the session alive.
  3. Anomaly-triggered re-authentication in front of irreversible actions: payment changes, data export, permission grants.

Calibration on the urgency number. Microsoft's AI security lead prices finding a vulnerability and generating a targeted exploit at 21 minutes and $3.61, and recommends scrapping outdated defensive best practices outright. The methodology behind those figures was not published, and Microsoft is both the industry's largest attack surface and a vendor selling the remedy. The number is useful for winning a prioritization argument with stakeholders. It does not belong in a technical review as a benchmark.


The same weakness, one door over

A Wired journalist filed an access request against a loyalty program and received 515 pages, per Morning Brew. The expected material was in there: favorite items, most-visited locations. What should reset a privacy design review is what came after, namely modeled future visit frequency, future spend, likely order, and a churn probability computed at 0%. The company answered with the standard line about using past purchases to provide a more engaging, personal experience. That line does not survive a screenshot of a churn score.

Scale is what makes this structural rather than anecdotal. The program has 210 million active users and its CFO calls it the single most important digital metric, while the average US consumer already belongs to 15 or more loyalty programs (BCG, 2024). The pricing layer is where personalization turns adversarial. A Washington Post columnist found Starbucks may have shown him fewer discounts after judging him willing to pay full price, with Consumer Reports alleging the same pattern at Kroger.

Two product decisions fall out of this. Both are cheap this month and expensive after a headline:

  • Derived fields are export surface. A churn score and a price-sensitivity tier are one access request from becoming a quote. Classify each one exportable or internal-only, with a written rationale that would read acceptably in print.
  • Personalize relevance, not discount depth. Willingness-to-pay-based discount suppression now has two named brands attached to it. Published prices plus relevant offers is the defensible position with consumers already fatigued by 15 programs.

Someone already shipped the template

Flock Safety, under bipartisan pressure over law-enforcement misuse of its license-plate network, cut data retention from one month to one week and deployed lockouts for operators whose search activity looks abnormal. That is a copyable specification: shortest defensible retention, per-record audit trail, anomaly detection pointed at internal users rather than outsiders. Shipped ahead of pressure it reads as trust marketing. Shipped after, it reads as a remediation plan.

A churn score is one access request away from being a quotation in somebody else's article.

What to do

  1. Add session-integrity requirements to your auth PRD this sprint — short-lived or device-bound tokens, server-side global sign-out, anomaly-triggered re-auth — and rewrite the breach copy that promises a password reset ends the compromise.

  2. Pull a full subject-access export on your own account within two weeks and mark every derived field exportable or internal-only, with a written rationale.

  3. Audit personalized-offer logic for discount suppression on price-insensitive users this quarter and move to relevance-based personalization on published prices.

The Compute Price Relief In Your FY27 Plan Is Not Arriving On Schedule

Memory scarcity, a fully absorbed data center market, and a pre-listing model vendor all point one way, and your negotiating window closes on someone else's calendar.

The constraint is structural, and it has names

Somewhere there is a 2027 cost model with a line that assumes memory per accelerator keeps climbing every year. Open that line first. High Bandwidth Memory stacking, the practice of layering memory dies next to a GPU to feed it faster, is hitting three specific physical walls: thermal dissipation, substrate warping, and micro-bump defects. The lithography road behind it slipped in the same direction. Samsung Foundry pushed 1.4nm out to 2029 and deferred 1nm-class and sub-1nm work to 2030 and beyond pending High-NA EUV tooling, per TLDR Hardware, redirecting near-term effort into 2nm Gate-All-Around and packaging. Progress is migrating from shrinking transistors to Cu-Cu hybrid bonding and advanced packaging. Those gains are real. They do not arrive on the annual cadence the cost curve extrapolates.

Separate the thing being pitched from the thing being done. Cheaper inference is the pitch. Memory per accelerator is the variable per-request cost actually rides on. Longer context windows, bigger batches, and multi-step agent runs all get cheaper as memory per instance grows. When the market leader is testing configurations with less of it, the cheapest scenario in a 2027 plan quietly becomes the least likely one.


The commercial leg

Morning Brew reports Anthropic heading toward a fall 2026 listing at a $2 trillion valuation. Those are projections and targets, not settled prices. Backers project up to $120 billion in annual revenue by the end of 2026, against a roughly $12 billion run rate at the start of the year. At $2T that is about 17x projected forward revenue. Bulls argue $3T at 30x by pointing at Palantir and Nebius trading near 55x. A company underwriting a tenfold single-year ramp into a public listing does not discount its flagship in the two quarters before it trades, and its top model, Fable, already prices at 2.5x a comparable OpenAI product. Morning Brew's own read is the one to internalize: Anthropic is vulnerable to businesses scaling back AI use over the price tag. A buyer's budget is its risk factor, and that leverage expires at listing.

Price is not the only exposure. The June 2026 export controls on its most powerful models "alarmed some customers and slowed revenue growth," and those customers were companies with shipped features. The Pentagon has designated its products a supply-chain risk, which the company is litigating. Cost relief is genuinely being built, including a reported $6B pursuit of Decart aimed at cutting training cost and enabling in-house chip design. It lands after FY27 plans are signed.

Assumption in most FY27 modelsWhat the evidence showsWhat to change
Inference gets cheaper each yearFlagship memory specs trimmed to fit supply; node roadmap slipped to 2029+Add a flat-cost and a +20% case beside the deflation case
Capacity is available when needed1% North American data center vacancy; renewals repriced, not negotiatedContract headroom and name fallback instance families
Premium model list prices will softenPre-listing vendor with a 2.5x price premium and a 10x revenue ramp to defendGet price protection in writing before the listing

Two asymmetries

OpenAI is losing its chief revenue officer less than a year in, part of pre-IPO executive churn. A revenue organization mid-rebuild, needing logos for its S-1 narrative, writes the cheapest enterprise contract signed this year. Apple's answer to memory inflation is the second asymmetry: leasing, configuration downgrades, refurbishment, and repair, per Computerworld. Under scarcity, monetize the lifecycle rather than the unit. The forcing function for both is one question per contract, asked before fall 2026. Can this price be renegotiated after the counterparty lists? Where the answer is no and gross margin is exposed to compute, metered or tiered packaging beats flat pricing that has to be walked back later.

A quality lead is a demo advantage. A price you cannot renegotiate after a listing is a permanent line in your P&L.

What to do

  1. Re-run unit economics on your two highest-volume AI surfaces before the next pricing review, with three cases: annual cost deflation, flat cost, and +20% cost.

  2. Open renegotiation with your cheaper model vendor this month, and require capability-continuity, advance-notice, and price-protection language from your premium vendor before its fall 2026 listing.

  3. Get a written 2027 capacity commitment from your infrastructure partner by end of quarter that names memory-per-instance and fallback instance families.

Your Agents Bill You Twice, And Neither Line Is In The Model

Brex's environment math and AMD's host-CPU argument name the same missing entry: iteration cost that scales with invocations, not headcount — plus the vendors now selling that layer.

The three numbers underneath the case study

An engineer pushes a branch and waits somewhere between 30 and 60 minutes, because the environment behind that branch duplicates 800+ microservices in order to test one of them. Brex's fix was request-level isolation: run only the services under test. Strip the logo off and what remains is the funding template most platform requests never assemble. Hard dollars: roughly $2 million a year recovered. Latency: under five minutes. Sentiment: +28 developer CSAT points. Three numbers that read to finance, engineering, and leadership at the same time, which is why the story earned a marquee slot, per Pointer. The caveat is load-bearing: every figure is vendor-supplied inside a paid placement, with no baseline, sample size, or methodology disclosed. Directional, not a forecast input.

What makes this capacity planning rather than marketing is the row that got added to the dashboard. Agents do not iterate at human cadence. They change the shape of the infrastructure cost curve, not its slope. An environment consumed by a coding agent is consumed continuously, at machine speed, with no lunch breaks and no sprint boundaries. A cost model keyed to seats is wrong by the ratio of agent iterations to human ones, and that multiple has not been measured in most planning meetings.


The second uncounted consumer

AMD corporate VP Madhu Rangarajan argues, via Chipstrat, that agentic deployment is reviving server CPU demand, because multi-step workflows — tool calls, code sandboxing, API orchestration, context retrieval — land real computational burden on the host processor rather than the accelerator. AMD sells high-core EPYC into exactly that, so this is a vendor talking its book. It is also almost certainly true. What gets pitched in the business case is a token bill. What gets paid is orchestration compute, cheap model call or not.

The convergence is the uncomfortable part. Pointer's evidence says the agent's environment is unpriced. TLDR Hardware's says the agent's orchestration is unpriced. Neither one is a token cost, which is the only number most teams instrument.

Iteration latency is a product metric, not a platform one

Instrument p95 by stage — model call, tool call, sandbox spin-up, retrieval, API round-trip — and publish the breakdown where the product team actually reads it. Two failure modes get diagnosed correctly only with that table in hand. If orchestration dominates p95, the whole optimization backlog is aimed at the wrong layer. And above roughly five minutes of build-test-preview latency, the productivity gain from an agent feature is absorbed by wait time, at which point flat adoption gets read as a model-quality problem when it is a queue. Adoption is the wrong metric there. Time to a usable result is the one that moves.


The layer scoped as a build now has vendors

LayerVendor signalWhat it displacesYour decision
Harness / orchestrationClaude Code Workflows (shareable, reusable)Ad-hoc prompt scaffoldingPortability stance, written down
IntegrationCorsair (unified connectors)Per-tool bespoke glueBuy versus build; check auth and governance gaps
Runtime / sandboxComputer ("give your agent a computer")Home-rolled VM and container sandboxesEvaluate cold-start latency and per-session cost
Code comprehensionSourcebot (self-hosted)Cloud code searchEnterprise-tier gating requirement

Anthropic shipping dynamically created, shareable harnesses — with a third-party plugin ecosystem already forming around them — moves this from a design decision to a procurement one. Shareable workflows accumulate switching cost quietly, because the asset the team builds lives in someone else's format. Two branches: native adoption for speed, or a thin vendor-neutral wrapper with a documented swap estimate. Pick one this sprint and write the swap cost down next to it. Defaulting into one of them without deciding is the expensive branch.

Agents consume environments, not seats — and a cost model keyed to seats is wrong by the ratio of agent iterations to human ones.

What to do

  1. Instrument p95 build-test-preview latency by stage on your agent-in-the-loop workflow this sprint and publish the breakdown, with five minutes as the threshold.

  2. Request an agent-adjusted infrastructure cost model from platform engineering — cost per preview environment, cost per agent invocation, break-even environment count — before any agentic feature enters a committed sprint.

  3. Write a harness-portability decision record this quarter that picks native adoption or a neutral abstraction and states the estimated swap cost.

The bottom line

Run the count instead of assuming it. Pick your highest-usage AI surface this week, hand one owner the mandate to list every hidden consumer and every retained field it depends on, and require a number and a date beside each line.