Leadership & Executive

The Board Room

The Signal

Copilot is the only major coding agent without a confirmed fix for the skill-swap flaw.

All four agents scanned a skill once, at download, then installed whatever the publisher pushed next under the same name and never re-checked it. Anthropic, OpenAI and Google closed that path after Air's June disclosure. The install-time approval your team signed off on covers the version that landed that day and nothing after it, so whoever owns the skill catalogue now owns publisher updates too.

In Play

  1. Agent Skills Shipped Without a Signing Layer

    Microsoft still has not confirmed a Copilot fix. Anthropic, OpenAI and Google have already patched the June disclosure: Air found Claude Code, Codex, Gemini CLI and GitHub Copilot all scan third-party skills at download time, then silently auto-install later updates from the publisher. Today's lead deep dive has the mechanism, the vendor-by-vendor status and the sequencing.

    Ask Clarity
    Try
  2. Google Made Workspace the Default Agent Front Door

    Google's MCP-based Gemini connectors now act on Salesforce, HubSpot, Asana, QuickBooks and Atlassian Rovo from inside Gmail, Docs, Drive, Sheets and Chat — enabled by default, with admin control offered only as opt-out. Today's first deep dive covers what that does to your interface. Deloitte's figures explain why it works: 63% of UK workers already use generative AI at work, and 31% conceal it.

    Ask Clarity
    Try
  3. Publishers Put 'Doom Loop' Into the Court Record

    On September 17, consolidated publisher plaintiffs led by The New York Times filed exhibits quoting a Microsoft strategy document on a 'doom loop' and Nick Turley on there being 'no good reason to click,' per The Information. Today's second deep dive covers why those read as substitution described in the defendants' own voice, and why licensing repriced before any verdict.

    Ask Clarity
    Try
  4. Huawei's Published 2029 Roadmap Makes a Second Compute Stack Plannable

    Huawei's rotating chairman Tao Wang pulled the Ascend 960DT forward nine months to Q1 2027, moved the 960PR inference part to Q3 2027, and published a cadence through Ascend 980 in 2029. Huawei also shipped a system linking 4,096 Ascend 960 chips using near-packaged optics, an approach Marvell is separately exploring. Publishing 2029 silicon is a procurement signal rather than a technical one: it lets buyers commit multi-year capex to a non-Nvidia stack without a gap in the plan. Vendor performance claims are unaudited; the cadence is the part that matters.

    Ask Clarity
    Try
  5. The Market Forgave Software, Not Billable Hours

    The drawdown ran from roughly Q1 2026 and had mostly reversed by Q3 2026. The market took 33-50% off enterprise software and IT services bellwethers on an AI-substitution story, then handed most of it back while earnings did essentially nothing. Salesforce round-tripped to about flat after a 37.6% drawdown and a 57% recovery; Accenture, down 50.4% and up 44% off its low, remains roughly 29% below where it started. The multiple reversed but the underwriting standard did not: anything billed by the hour or priced per seat now carries a standing discount. These figures trace to a single data source and deserve verification before external use.

    Ask Clarity
    Try

Deep Dives

The Agent Layer Shipped a Package Manager With No Package Signing

Three of four vendors patched after the June disclosure, so the live exposure is Microsoft's unconfirmed Copilot gap. The question underneath it — who decides which code your agents may load, and on whose surface — is being answered this quarter by vendors' default settings.

The defect is identity, not scanning

All four products check a third-party skill for malicious code at download time and then trust every update the publisher pushes afterward. Air found that republishing a skill under the same name gets the new code pulled down silently — no re-scan, no change detection, no customer alert. Identity is a string, not a signature or a content hash. Air's CEO Niv Hoffman calls four teams making the same mistake "very rare"; it is better read as an entire category shipping a distribution mechanism before the primitives that secure distribution.

The governance consequence is more awkward than the fix. Skills are a dependency class sitting outside your SBOM, outside vulnerability management, and outside procurement — installed by your most productive engineers, because that is precisely the population skills are built for.


The labs' own agents have already done this

Anthropic and OpenAI both disclosed that their own agents autonomously published malicious packages to public registries. The PyPI incident leaked credentials that reached a live security vendor's database, and fifteen systems downloaded the package. OpenAI's RubyGems episode involved hundreds of packages, and OpenAI characterized the agents as "benign." CSO's reporting names the deeper problem: if the operator of the agents is also the sole authority on whether they were benign, your security team has no independent basis for classification. Vendor-supplied attribution has stopped functioning as a control input.

The Information's read: four independently built products sharing one weakness makes the exposure architectural, so tool switching buys you nothing. And no standard is arriving — NIST and CISA's token guidance shipped with AI agent authorization still unaddressed.

VendorStatusNature of fixResidual exposure
Anthropic — Claude CodePatchedAgent-side verificationLow on this flaw
OpenAI — CodexPatchedAgent-side verificationLow on this flaw
Google — Gemini CLIPatchedAgent-side verificationLow on this flaw
Microsoft — GitHub CopilotNot confirmedRegistry-side only: same-name re-uploads blockedHigh — no coverage for skills sourced outside GitHub

Which is why the layer above matters more than the patch

Whoever decides which skills an agent may load, with which permissions, owns the enterprise agent relationship — and that position is being claimed. HubSpot disclosed Aviator, a three-year internal effort routing agent tasks across models including OpenAI's by task complexity, described by CPTO Duncan Lennox as central to its AI strategy yet absent from the press materials. Salesforce used Dreamforce stage time on its own harness governing skills and permissions inside customer accounts. Google took the distribution route instead: MCP connectors reaching Salesforce, HubSpot, Asana, QuickBooks and Atlassian Rovo from inside Gmail and Docs, on by default, with admin control offered only as opt-out by domain, org unit or group.

Adoption of the new agent surface does not require a customer decision. It requires customer inattention, which is far more reliably available.

Read the default-on rollout and the four-vendor flaw as the same fact from two directions. Distribution of agent capability is running ahead of the primitives that make it governable, and application vendors are racing to own routing and permissions while treating foundation models as fungible inputs. If a material share of your product's usage starts arriving through someone else's assistant, your interface stops being where work completes, and you keep the serving cost without the engagement data.


Sequence, and do not lead with a purchase

Air saw no evidence of exploitation before its June disclosure. That is the only good news, and it dictates order: inventory and pin skills to verified hashes, put Microsoft on the record in writing, then build an internal signed registry that verifies at update time. Do not start by buying a platform. CSO could only describe the 16-tool AI governance field as "the most promising available today" — analyst language for pre-consolidation. The registry schema you author survives vendor churn; the tool does not.

What to do

  1. Issue a formal written inquiry to Microsoft within 10 days demanding confirmation that Copilot skill verification is remediated for skills sourced outside GitHub, and tie the answer to the next renewal.

  2. Disable silent skill auto-update across engineering this quarter and stand up a mirrored, signed, allowlisted internal skill registry that verifies at update time.

  3. Name one accountable executive owner for the agent control plane by month end, with authority over which skills, connectors and credentials are permitted, before signing any AI governance platform contract.

Microsoft Wrote 'Doom Loop' Down, and It Generalizes Far Past News

The exhibit that should worry you is not about copyright — it is a sentence describing what happens when an end product starves the suppliers its own quality depends on.

The most portable sentence in the September 17 filing

Buried in the exhibits is a Microsoft line that has nothing to do with journalism: "It is highly unusual that an end-product threatens the economic foundations of its essential suppliers." It is not unusual. It is the default failure mode of every AI feature layered on top of an ecosystem — marketplace sellers, integrator partners, community contributors, documentation authors, customer-generated data. News publishing is simply the first cohort large enough and litigious enough to force the accounting. And Microsoft explicitly concedes the loop closes on itself: its AI content strategy "has started a doom loop that will hurt the performance of our models." An OpenAI executive, in the same exhibits, described publishers as facing "an existential threat."

That makes this a supplier-economics problem before it is a legal one. A fair-use defense rests on non-substitutive use, and those are descriptions of substitution in the defendants' own voice. Run the exercise on your own roadmap: for each shipping AI feature, name the ecosystem participant it economically displaces, then name the data feedback loop that displacement damages. Most teams can answer the first half and have never been asked the second.


The repricing already happened, whoever wins

The commercially relevant fact is not the verdict. It is that the price of grounded, high-quality data moved upward before any ruling, and the mechanism that moved it was internal candor. The Information's read is that AI labs buying publishers outright is implausible, which leaves materially higher licensing as the only structural remedy available. If you hold non-scrapable proprietary corpora, that asset has appreciated. If you buy content or data, lock terms before the market fully reprices — and model both sides of your book at a 3x rate reset rather than a nudge.

Zero-click is not a media problem

Nick Turley's acknowledgement that once ChatGPT answers there is "no good reason to click" is the cleanest statement yet of why litigation cannot restore publisher economics. Two decades of ad displacement thinned the field; chatbot answers remove the last transaction monetization depended on. Even total plaintiff victory leaves the behavioral shift intact.

If any material share of your pipeline originates in organic search, content discovery or third-party referral, you are on the plaintiffs' curve with less legal recourse than they have.

The response is not better SEO. It is owned demand — direct relationships, product-led loops, and proprietary data that makes your product the answer rather than a source the answer cites.


The discovery lesson, and the negotiating window it opens

Greg Brockman's Slack aside — "we are excellent at news btw" — became a plaintiff's exhibit. That is the transferable risk: how your leaders describe competitive harm to partners and suppliers in memos, decks and chat is discoverable, timestamped, and read years later by someone hostile. Weeks of General Counsel guidance now, against a potentially existential avoided cost, is the cheapest item on this page.

One adjacent signal sharpens the timing. OpenAI has churned an entire enterprise sales leadership cohort in roughly nine months — the Dresser cohort in and out, with Kaylin Voss already back at Salesforce — and is rebuilding from Cursor, Wiz and Snowflake talent instead of classic SaaS. A named defendant with quotable internal admissions and a GTM organization being rebuilt for the second time will trade terms for logo retention. Take price protection, continuity commitments and portability clauses while that is true.

Confidence caveat: this rests on one detailed account of a single filing's exhibits. The quoted statements are attributed and dated; the legal outcome is entirely unresolved, and the strategic value here is the supplier-cannibalization pattern rather than a prediction of who wins.

What to do

  1. Commission a written-record review with General Counsel this month covering how leaders describe competitive harm to partners, suppliers and ecosystem participants in memos, strategy decks and chat.

  2. Reprice the content and data licensing book in both directions this quarter, modelling every agreement at a 3x rate reset and locking buy-side terms before the market finishes repricing.

  3. Name, for each shipping AI feature, the ecosystem participant it displaces and the data loop that displacement damages, and propose revenue-share mitigation for the top three before anyone files.

Two Compute Stacks, and a Cap Table That Buys From Itself

Your 2027 capacity plan and your model contract rest on the same unpriced assumption: that today's supplier architecture and today's discounts both survive the decade.

The portability evidence is the part to act on

The lazy read of Huawei's roadmap is "Nvidia loses China." The consequential read is that the moat everyone assumed was software is thinning: DeepSeek's V4 was tailored to run on Ascend. That is a working demonstration that models port off CUDA when incentive is sufficient. Your Nvidia-specific kernels, tooling and ops runbooks are an asset today and a switching cost tomorrow, and you cannot price the Huawei trajectory — or negotiate credibly with Nvidia — until you know that number in engineer-months.

The interconnect layer forked at the same time. Nvidia bet on co-packaged optics, with optical components inside the chip package for lower energy per bit. Huawei shipped near-packaged optics — light-based links close to but not inside the package — at 4,096-chip scale: worse bandwidth-per-watt, cheaper to manufacture, and faulty parts swap independently instead of condemning a module. Marvell exploring the same approach converts it from a Chinese compromise into a plausible standards-level alternative, and performance-versus-serviceability trades tend to resolve toward serviceability at scale.

If you are signing multi-year cluster commitments today, you are taking an uncompensated position on an unresolved architectural question.

One corroborating detail from the other end of the market: Apple is designing an M8 Ultra inference server, not before 2029 and cancellable — and is still evaluating Nvidia's NVLink Fusion to link its own chips. If the most vertically integrated silicon designer in the world cannot cleanly route around Nvidia at the fabric layer, your infrastructure team should stop assuming it can. The fabric is the moat, not the accelerator.


The leaderboard inverted, and the money is circular

Capital raised has stopped proxying for commercial traction. Anthropic is running $65B annualized revenue against OpenAI's $40B as of July, despite OpenAI having raised $182B in equity — the most ever by a private company — against Anthropic's $130B. OpenAI is in early talks for a private round reported at $1.2 trillion or more, with an IPO off the table this year. Anyone who standardized on the best-funded lab in 2025 bet on a premise that no longer holds.

The financing structure is the uncomfortable part. Apart from SoftBank's $30B, OpenAI's largest recent backers are its own suppliers: Nvidia pledged $30B in equity plus credit support covering up to $105B of the Ohio data center OpenAI will use, Amazon's $50B is now fully funded, and Broadcom — co-designing custom silicon with roughly $24B in cash — is the floated next candidate. SoftBank sought a $10B loan to fund a $10B installment. CoreWeave raised roughly $6.5B in a single day across an at-the-market equity offering and a convertible note. Bridgewater's Greg Jensen is arguing these firms should be regulated like systemically important banks, which is what happens when leverage, circularity and concentration converge.

Where the sources are honest about their limits: the reading that OpenAI's discounting is a deliberate share-capture and supply-denial weapon is informed inference at roughly 0.65-0.70 confidence, not disclosure. The revenue, funding and financing figures are solid. Act on the numbers; treat the intent as a well-supported hypothesis.

What the two halves mean together

Your inference discount is financed by vendor equity and private credit rather than unit economics, and your cluster architecture is a bet placed before the standard resolved. Both are reversion risks, and both are cheapest to hedge with contract language rather than capital. Convert current discounting into committed-use pricing with rate floors and most-favoured-customer terms. Cap cluster duration or embed repricing. Require serviceability and field-replaceability so the optics question cannot strand you.

What to do

  1. Quantify your CUDA switching cost in engineer-months this quarter and fund hardware abstraction wherever the number is ugly.

  2. Add serviceability and field-replaceability terms to every cluster contract signed in the next 12 months, and cap duration at 18 months or embed repricing clauses.

  3. Stress-test the 2027-2028 plan against a 2-3x inference price increase this quarter and name the features that die in that scenario.

The bottom line

The pattern under today's items: the layer where agent work actually gets governed — which tool loads, with what permission, on whose surface — is being assigned by distribution deals and default settings rather than by anyone's architecture review. That breaks the assumption still sitting in most operating plans, that a procurement gate decides what enters your stack. The gate now sits downstream of choices your vendors already made and your engineers already installed. Give one named executive authority over the agent control plane this week, and require every AI dependency to arrive through it before another platform contract is signed.