Leadership & Executive

The Board Room

The Signal

Microsoft's shift to post-quantum code signing breaks shipped apps by mid-October.

The exposure isn't in code your team wrote. It's in the signed third-party components you redistribute, and in the auto-updaters that carry them: a client that can't validate a new signature can't deliver its own fix. A reasonable skeptic would say the inventory pass can wait until the quarter is closed. The tradeoff is that a break surfaced by customer escalation costs roughly ten times what finding it now does, and finding it now means finding it during quarter close.

In Play

  1. Microsoft's Signing Cutover Lands Mid-October

    Microsoft is migrating its code-signing infrastructure to post-quantum algorithms and has explicitly warned developers their apps will break, with completion set for mid-October, per Risky Business. Every signed installer, driver, agent, auto-updater and signed third-party component you ship is in scope. The real exposure is your Q4 release calendar: a break found in a customer escalation costs roughly ten times what finding it now costs — and it costs it during quarter close.

    Ask Clarity
    Try
  2. Your Chip Supplier Joins the App Layer's Cap Table

    Nvidia is in talks to invest billions in Perplexity at a valuation above $30B, more than 50% above an implied roughly $20B a year earlier, The Information reports. Deeper commercial ties came before the equity talks, which makes this a template rather than a one-off: compute agreements convert into ownership of demand. The supplier that sets your inference cost now holds a position in a company chasing the same workflows. The same reporting notes Nvidia is also investing in data-center developers and model makers.

    Ask Clarity
    Try
  3. Regulators Price an Automated Decision at €825M

    The Dutch data protection authority fined Uber €825 million for disabling driver accounts through automated systems with no human review and no reason given — the second-largest EU data protection fine behind Meta's €1.2 billion, per Risky Business. Any automated suspension, denial, payout hold or deranking in your product now sits against that benchmark. Human review, a stored rationale and an appeal path stop being legal artifacts and become shippable features.

    Ask Clarity
    Try
  4. Growth Stopped Earning a Multiple in the Application Layer

    Salesforce guided to 11% full-year growth, an improvement on last year's 9.6%, and has been repriced downward anyway, The Information reports. The proof point sits in procurement: the U.S. Agriculture Department reduced its Salesforce footprint in favor of AI-enabled suppliers. Meanwhile Nvidia is projected to generate $213B in free cash flow this fiscal year against Apple's expected $144B. The profit pool has moved to infrastructure, and any seat-priced footprint thin on proprietary data is now contestable.

    Ask Clarity
    Try
  5. AI's Credibility Correction Comes From Inside the Tent

    Eric Topol, a cardiologist who calls Demis Hassabis "a hero of mine" and secured a Hassabis blurb for his 2025 bestseller, publicly called the claim that AI will cure all diseases within a decade hype, The Information reports. Daphne Koller's widely shared "magic wands" post made a similar argument. The defense that critics simply do not understand the technology stops working when the critic is a supporter. Roadmaps that borrowed model-release timelines for outcomes gated by real-world validation are now a credibility exposure.

    Ask Clarity
    Try

Deep Dives

Seven Weeks, One Owner, and Every Signed Artifact You Ship

A forced cryptographic migration lands inside the quarter you close revenue in, and the artifacts most likely to break are the ones you did not build.

The inventory is the hard part

Microsoft owns the migration. The inventory belongs to whoever ships the software, and it runs wider than the release train: installers, kernel drivers, endpoint agents, auto-updaters, build-time signing steps, and the signed third-party components a vendor redistributes without having written. Auto-updaters go first, because a client that cannot validate a new signature cannot deliver its own fix. After that point remediation takes a human touch per install, which makes it a support-cost problem rather than an engineering one.

Risky Business's reporting leaves no room on the developer warning. Microsoft has said apps will break, and has put completion at mid-October. That converts a cryptography roadmap slide into a release-calendar dependency with no negotiating counterparty. There is no extension to request, and by default nobody on the software vendor's side owns the date.


Why finding it late costs roughly ten times more

The same fix carries two prices. Found now, it is an inventory exercise and a test matrix. Found in a customer escalation, it becomes an emergency release, a support surge, a trust conversation with the largest accounts, and the opportunity cost of engineers who were supposed to be shipping Q4 features, all of it landing during quarter close. An internal cutover of October 1 buys two weeks of buffer against a date held by someone else.

Turn the fire drill into a capability

This is one in a series of forced cryptographic migrations, not a one-time event. Treated as an emergency each time, it carries the emergency premium annually. Funded as a named platform capability, crypto-agility gets paid for once: centralized signing, pluggable primitives, no hardcoded algorithm assumptions, and an enterprise security questionnaire that answers cleanly. That is the part with revenue attached: within three years, crypto-agility is a procurement question in regulated and enterprise deals, not platform hygiene competing for sprint capacity.


The concentration quantified

The same body of reporting covers a 10.0-severity remote code execution flaw in Entra ID (CVE-2026-69836), a one-click Copilot data-exfiltration bug (CoSnitch, CVE-2026-24301), an advisory published with an exploitation flag enabled by mistake, and this breaking change to the distribution trust those products depend on. All patched, and individually routine. Collectively they put a number on something most technology companies have never actually modeled: identity, agentic data access, and software distribution trust in one supplier.

A reasonable skeptic says Microsoft remains the safest place to hold those dependencies, and the skeptic is probably right. The question was never whether Microsoft is secure. It is the size of the blast radius, and whether detection survives a vendor advisory being wrong, which already happened. The detail worth sitting with is that the Copilot bug was surfaced by Copilot itself during normal use. AI assistants create self-revealing data paths existing monitoring was never designed to observe, which means the vendor's telemetry and a customer's own are not interchangeable.

Post-quantum cryptography stopped being a 2030 roadmap item the moment Microsoft put a mid-October date on it.

The board-reportable version is two lines: the date signed artifacts are verified against the new chain, and the detection held in-house that does not depend on a Microsoft advisory being accurate. Neither line requires a strategy change. Both require an owner.

What to do

  1. Name one accountable engineering owner and produce a complete inventory of signed artifacts — installers, drivers, agents, auto-updaters and redistributed third-party components — by September 5.

  2. Freeze the Q4 release calendar around an internal signing cutover of October 1, two weeks ahead of Microsoft's completion date.

  3. Fund crypto-agility as a named platform capability in the next planning cycle: centralized signing, pluggable primitives, no hardcoded algorithm assumptions.

Nvidia Is Buying the Demand It Sells To

Compute neutrality was a procurement assumption; it is now a competitive variable — and the same week handed you a model vendor moving into your delivery channel.

The sequence carries the argument

Commercial ties were strengthened first. The equity talks came second. A financial investor does not order it that way; a supplier converting a commercial relationship into ownership of demand for its own hardware does. That ordering is what makes this a template rather than an event. If compute supply agreements convert into application-layer equity once, they convert again, and every AI company's cap table becomes a disclosure about who holds preferential access to capacity and price.

Qualify it properly before anyone builds a slide. The Information describes a round under discussion, not closed, sourced to people with knowledge of the talks, and the roughly 40x figure is measured against annualized revenue rather than an audited annual result.


What the multiple is actually paying for

Perplexity's annualized revenue went from under $250M in January 2026 to over $750M by August, credited in part to Perplexity Computer, an agent professionals use to complete work on their own machines. That is an architecture change wearing a product name. Retrieval and synthesis produce an answer engine and a consumer subscription. Task completion produces a professional tool with budget authority behind it. The market paid roughly 40x for the second thing while repricing the first downward. A 2027 roadmap that still sells assistance rather than completion is carrying the wrong multiple into its next financing or its next renewal cycle.

The channel gets conflicted on the same timeline

Anthropic's enterprise arm bought a consultancy while the company prepares supervoting founder shares ahead of a mega-IPO, per The Information. A model provider with delivery capability competes with the systems integrators it depends on, and eventually with any differentiation that amounts to knowing how to deploy the model. Neutrality is a wasting asset. The window to sign integrator alliances as the credible non-competing partner is measured in quarters, and it is the only item here that moves without another party's cooperation.

VectorOld assumptionNew realityYour exposure
Compute supplyNeutral vendor, negotiate on priceVendor holds equity in application-layer playersCompetitors may get structurally better cost and capacity
Product valueBetter answers, seat-based pricingCompleted tasks, outcome-based pricingSeat models cannot capture value an agent creates
Enterprise channelIntegrators deploy, model vendors supplyModel vendors buying delivery capabilityChannel partners become conflicted or hostile
Infrastructure accountingLong, stable accelerator useful lifeMixed supplier messaging on chip longevityDepreciation schedules may overstate AI margin

The accounting correction nobody wants to run

Both reports flag the same soft input: Nvidia's mixed messaging on chip longevity. Useful life drives depreciation, refresh cadence, and the AI gross margin already sitting in the board deck. Ambiguity from the supplier means that number is softer than the model implies. A reasonable skeptic would say this is a footnote adjustment, not a strategy question, and for one quarter that is fair. Run the sensitivity at a 30–40% shorter competitive life anyway; if it moves the margin story materially, the board should hear it from management rather than from an analyst. It also hands transparent-TCO competitors an opening.

One timing note sets the working assumption. Hyperscalers respond to accelerator price increases by accelerating custom silicon, and that takes 18–36 months. Most planning windows sit inside that gap.

When the chip supplier starts buying equity in the application layer, compute neutrality stops being a procurement detail and becomes a budget line against 2027 inference demand.

What to do

  1. Commission a compute-neutrality audit this month that maps every disclosed Nvidia equity position and strategic partnership against your competitive set, and quantify the cost gap if preferential capacity or pricing goes to a portfolio company.

  2. Commit a funded second-source serving path for a meaningful share of 2027 inference demand before Q4 planning locks.

  3. Re-run the AI gross margin model at a 30–40% shorter accelerator useful life and put the breakpoints in front of the board this quarter.

The Dutch Regulator Wrote a Product Spec and Priced It

Human review, a stated reason and a way to appeal just moved from legal boilerplate to product features with a euro figure attached — and acquisitions carry the exposure too.

Three absences, not one algorithm

The ruling did not penalize automation. It penalized automation arriving with three absences: no human in the loop, no reason given, and no route to contest. Uber's automated driver-account deactivations supplied all three at once. Written as a checklist, that reads less like a legal finding than a product specification: a named human reviewer, a rationale stored where it can be retrieved, and an appeal path the subject can actually reach. The fine is the price of shipping without them.

The scope inside a given product is wider than legal's list. Suspensions, bans, denials, payout holds, deranking, fraud declines, risk scores, moderation actions, and any AI-driven enforcement still on the roadmap all qualify. The test survives a review meeting: a model decides against a person, and the question is whether that person can see why and whether a human can overturn it. Where the answer is no both times, the exposure is already priced.


The liability travels with the asset

Two readings of the same $400M privacy settlement, and both are worth keeping. Risky Business notes that TikTok's payment partly covered infractions inherited in a 2017 acquisition. The Information treats the figure as the working enforcement benchmark for how AI assistants reach personal data. The diligence conclusion is the same either way: legacy privacy and automated-decisioning liability belong on the M&A scorecard in the same pass as security debt, because the acquirer buys the enforcement exposure along with the code.

This is the cheapest control on the page. Two more questions on a diligence template cost nothing. Finding a decade-old automated-decisioning practice after close costs whatever the regulator decides it costs.

The surface is growing, not shrinking

AI assistants are heading toward operating-system-level access to personal data, per The Information. That means more automated decisions, on more sensitive data, with less explainability per decision. Every assistant feature that acts on a user's own files and accounts widens the set of consequential actions nobody can reconstruct afterward. Where the roadmap includes agentic actions on customer data, the audit is a prerequisite rather than a follow-on.


Why this shows up in win rates

Finance prices this as compliance cost, and finance is usually right about compliance spending. The competitive read is the more useful one here. Enterprise buyers probe human-in-the-loop design and permission scoping during security and procurement review, and they ask where the decision rationale is stored; almost nobody answers with artifacts rather than assurances. A capability sheet built before the market demands one turns a legal expense into a differentiator in the buying committee. Privacy posture works as a go-to-market wedge precisely because most competitors will wait for an incident.

The order of operations is unremarkable. The audit of what already ships comes before the gate on what ships next, and both come before the diligence template stops importing other companies' exposure. None of it is a strategy change. All of it needs someone senior owning the inventory of automated adverse actions, which almost certainly does not exist in one place today.

An automated decision your customer cannot see the reason for has a published price, and it was set in euros.

What to do

  1. Commission an inventory this month of every automated adverse action in the product — suspensions, denials, payout holds, deranking, risk scores — scored for human review, stored rationale and appeal path, with findings to the exec team by quarter end.

  2. Gate every AI-driven enforcement or moderation feature entering the roadmap this half on a documented human-review step and a customer-visible rationale.

  3. Add legacy privacy and automated-decisioning liability to the M&A diligence scorecard before the next letter of intent.

The bottom line

One pattern runs under these items: the parties you treated as neutral background — the supplier that stamps your releases, the vendor that sells you compute, the regulator that never had an opinion on your product defaults — are all making decisions on their own calendars that land inside your operating plan. A dependency chosen once no longer stays a quiet cost line; the binding constraint is the switching cost you never measured. Name the three dependencies whose terms you cannot change this year, and fund the ability to swap or contain each one before your next planning cycle closes.