Leadership & Executive

The Board Room

The Signal

Anthropic can walk away from most of $84.5B in SpaceX compute on 90 days' notice.

The same company's Claude marketplace wants your committed spend pooled into partner software, while power financiers want 10–15 year tenant terms on assets paid off in 6–8. The buyer with the clearest view of AI volatility priced duration as risk. The long end is left for whoever signs next, and anyone negotiating a multi-year commitment this quarter is deciding whether to be that signer.

In Play

  1. Machine-Speed Attacks Hit Cloud and Edge

    Treat any NetScaler still unpatched after Monday as compromised. Risky.Biz reports mass exploitation began within hours of Monday's proof-of-concept releases. CSO First Look reports Microsoft now sees Jadepuffer, an autonomous AI attacker first reported in July, destroying Azure resources. The security deep dive has the response plan.

    Ask Clarity
    Try
  2. Frontier Buyers Shed Duration Risk

    The exit clause is now the price. The Information reports Anthropic can cancel most of up to $84.5B in SpaceX compute through 2029 on 90 days' notice. Meanwhile, Alex Eichenstein reports that power financiers want 10–15 year tenant terms on assets paid off in 6–8 years.

    Ask Clarity
    Try
  3. OpenAI and Anthropic Bid to Hold Your AI Budget

    According to Turing Post and TLDR IT, OpenAI's DevDay Marketplace and Anthropic's Claude marketplace both let committed spend buy partner software. Commit only on terms that let your spend follow the winning model.

    Ask Clarity
    Try
  4. Data Walls Fall, Access Tolls Rise

    Applied AI reports that Microsoft joined the Apache Ossie metric-standards group alongside Snowflake, about four months after it blocked partner tools from Power BI. a16z argues Amazon blocks Meta's Muse because its $69B ad line likely out-earns its $34B ex-AWS operating income. Expect AI-access fees in your system-of-record renewals.

    Ask Clarity
    Try
  5. Shopify Reprices 'Write Once' Architecture

    The Pragmatic Engineer reports that Shopify is rewriting all six of its mobile apps in Swift and Kotlin, about 20 months after publicly praising its React Native bet. The Shop app went native in 12 weeks; moving onto React Native took five years. The apps weren't failing. AI agents made building every feature twice cheap. Any architecture you justified by avoiding duplicate human effort needs re-costing. Shopify's safety net was a shared test suite.

    Ask Clarity
    Try

Deep Dives

Your Security Stack Is Now the Way In

Treat any NetScaler still unpatched after Monday as compromised. The breaches covered here came through the tools and vendors bought to reduce risk, so the metric your board sees must move from detection to recovery.

The pattern across six incidents

Bitget's $388M loss is the clearest template. Attackers exploited a flaw in a third-party security product and took valid admin credentials. They then sent two small test transfers that slipped under the risk threshold and began large withdrawals 30 minutes later. Risky.Biz and Daniel Miessler read it the same way: attackers didn't break the exchange itself, they broke a tool bought to protect it. Bitget's Protection Fund covers the loss. That reserve is the only reason this is a bad quarter rather than an existential one.

NetScaler repeats the pattern at the network edge. CyberScoop reports that Citrix took most of a weekend to confirm active exploitation of CVE-2026-88771 and CVE-2026-88772. Public exploit code was available, tens of thousands of instances were exposed, and CISA publicly criticized the response. SANS editors say the flaws were reportedly exploited for weeks before confirmation. Their detection guidance shapes what your team will tell you. Citrix's detection script depends on log history many teams don't keep on the device, so a team with short retention can run it and report a false all-clear. Oracle's PeopleSoft CVE-2026-35273 shows the same trap. A firewall rule meant to block it was bypassed with URL encoding, and mass exploitation returned three months after the patch shipped.

Destruction changes the metric

Microsoft now sees Jadepuffer, an autonomous attacker, destroying Azure resources. That shifts the board metric from time-to-detect to time-to-restore. CSO First Look adds the economics: at about $25 per target, hitting a thousand organizations costs roughly $25,000. Defense that scales with analyst headcount loses that race. The posture that holds limits what one compromised identity can delete and keeps backups out of that identity's reach. Microsoft is hedged on whether exposed credentials were the way in, and the number of victims is not public.

Liability now follows the vendor chain

SANS NewsBites highlights Labcorp's settlement with 44 state attorneys general: $2.3M, though GovInfoSecurity reports $2.2M. It covers a 2019 breach at AMCA, Labcorp's debt collector, which has since dissolved. Seven years later the liability landed on the client. The settlement mandates four terms that plaintiffs and customers will now cite:

  • security requirements in vendor contracts
  • a response plan for vendor incidents
  • limits on the data shared with vendors
  • a team that verifies vendor compliance

Kiteworks showed the better version of vendor behavior. It told customers to take servers offline based on federal intelligence, then found and fixed a previously unknown critical flaw during the downtime.

In Bitget, NetScaler, PeopleSoft, Jadepuffer and Labcorp, the failing controls are the ones leaders assume belong to someone else: vendor security, vendor disclosure and workaround controls such as firewall rules. That makes this a governance and contract question as much as a patching one.

Patched is not clean, mitigated is not fixed, and a vendor's balance sheet does not cap your exposure.

What to do

  1. Require written CISO confirmation within 48 hours of a compromise assessment for every NetScaler, PeopleSoft and Kiteworks instance: a webshell hunt plus a 30-day SIEM log review, not just patch status.

  2. Fund deletion guardrails and immutable backups, kept in a separate trust domain, for tier-1 cloud workloads this quarter. Validate them with a tabletop exercise in which an autonomous agent holds one of your privileged identities.

  3. Benchmark contracts with every vendor holding regulated data against the four Labcorp settlement terms, and add exploitation-notification SLAs with weekend coverage at each renewal.

The Smartest AI Buyer Just Refused the Risk You're Signing

Frontier labs and power financiers are writing deals that keep the flexibility for themselves and leave the enterprise tenant holding the long end.

The loop the prospectus exposes

The Information's Martin Peers describes a chain that feeds itself. Frontier buyers demand flexibility. Suppliers' order backlogs soften. Lenders discount contracts that can be canceled. Build-outs slow. Peers sees the same constraint limiting Anthropic's own growth, which is why he calls a delay to its roughly $100B listing a question of "when, not whether." Holtec, a supplier to data centers, cited "uncertainty over data center development" when it postponed its IPO in mid-September.

Anthropic's reported numbers explain its caution. Reuters' reading of the confidential draft shows a 2025 net loss of roughly $42B. About $34B of that is a non-cash accounting charge, which leaves an operating loss above $8B on about $4.6B of revenue. Nearly a quarter of revenue came from two unnamed customers. Paul Smalera's Augment calculates that compute cost per revenue dollar fell from about $6.40 to $1.60 in a year. Augment also flags a reported $518B in obligations, set against $20.28B of cash, as the least reliable figure: it may be total commitments rather than one year's spending. Augment discloses a position in Anthropic, so weigh its framing accordingly.

Power is being financed the other way

Further down the stack, the risk moves toward the tenant. Fitch estimates that new grid-connected plants and transmission take 5–10 years. Williams brought 200 MW of on-site generation online in under 18 months, so operators pay a premium for speed. A Blackstone-led group paid $5.3B for 49% of five Williams gas projects. Investors now want 10–15 year terms plus renewals. Meanwhile, IDF's CEO says a power block is "significantly amortized" in 6–8 years. On a 15-year contract, that leaves the last seven to nine years running on a largely paid-off asset. IDF also says it can sell the power into the grid if the tenant leaves.

The capital behind all this is crowding in. Tech accounts for about 60% of U.S. convertible bond issuance this year, roughly $78B through Sept. 11, and that total excludes CoreWeave's $4.2B deal. The cost of AI-specific debt is also rising.

What this means for your contracts

That asymmetry is your leverage. Without meaning to, the best-informed buyer in the market has shown what a sophisticated compute contract looks like. Suppliers who need your credit to finance their builds have their own amortization math on the record. Together, those give you grounds to ask for flex-down rights, lower prices once the asset is paid off, and termination rights when grid power arrives.

Sources split on how to time deals with the labs. Augment argues for 24–36 month Anthropic commitments with price caps before the prospectus goes public, because its customer concentration gives Anthropic a reason to sign diversified revenue now. Others argue for holding commitments until the post-DevDay pricing settles. The defensible middle is to use the pre-IPO window to win flexibility rather than volume: price caps, capacity guarantees, notice before models are retired, and exit rights, not larger minimums.

A lab that won't hold compute risk beyond 90 days is telling you what that risk is worth.

What to do

  1. By quarter-end, audit every compute, cloud and power commitment longer than three years against the 90-day cancellation benchmark. Renegotiate for flex-down rights, price step-downs after amortization, or exits when grid power arrives.

  2. Have Treasury map how every material compute provider is financed (GPU financing vehicles, power project debt, convertibles) against your step-in and portability rights, and report back this quarter.

  3. Assign an analyst to read Anthropic's public S-1 within 48 hours of filing, verifying the obligations figure, customer concentration and voting structure.

Your AI Commitment Is Becoming Someone Else's App Store

The vendors keenest to pool your budget sell into a market where leadership now flips in weeks, so portability is the term worth fighting for.

Two data points that should change how you sign

Per-task economics are moving faster than any buying cycle. AINews reports that GPT-6.1 Sol completes tasks for about $0.72, versus $3.26 for GPT-6 Astra, while scoring one point below it on the Artificial Analysis index. Anthropic kept Sonnet 5.5 at $2/$10 per million tokens and claims up to 30% lower cost per task. Simplifying AI notes that Sonnet 5.5 beats Opus 5.5 on Terminal-Bench 4.0 (70.6% vs 66.4%). Builder loyalty moved just as fast. Daniel Miessler reports that Claude went from trailing Codex to twice its popularity in T3 Code in about two weeks. What drove it was usage economics and harness quality, not benchmarks.

Caveats: the Sol figures come from OpenAI and one outside evaluator. AINews also notes Sol uses 10–30% more output tokens, so real savings trail the list-price math.

Why the vendors want your budget pooled now

Pricing and loyalty are that volatile, yet both leading labs are building ways to make your commitment sticky. OpenAI's Marketplace can route your OpenAI commitment to open models through Baseten. OpenAI keeps the billing relationship even when a workload leaves its models. Turing Post puts it this way: "OpenAI is willing to lose the runtime as long as it keeps the meter." Dots are always-on agents, each with its own cloud computer and 4,000+ app connectors. They extend that meter to agent labor. Specialist Dots add organizational credentials. TLDR IT reports that Anthropic's Claude marketplace, with 2,000+ connectors and partner agents, lets eligible partner software draw on Anthropic commitments. Which partners qualify, and what share of a commitment is eligible, were not disclosed.

The quieter move is routing, meaning which model handles each task. Turing Post counts a roughly 30x per-token price spread between Sol standard and Astra Ultrafast inside OpenAI's own catalog. Dots run only on Astra today. OpenAI says it is working on routing and that simplicity will win. In practice, the vendor intends to make your cost-quality trade-off for you. Flat seats are also losing value. AINews reports the new plan structure roughly halved the value of the old Pro 200 plan, which pushes spending toward metered agent usage.

Where sources agree and where they split

Every source that covered DevDay agrees that routing and evaluation belong in-house. They split on commitments. AINews advises freezing new single-vendor commitments until they include portability. Others argue that the period before Anthropic's IPO is when buyers have the most leverage to lock in terms. The two views can be reconciled: commit, but only on terms that survive a change in which lab is ahead.

If you sell software, the same hooks force a channel decision. A marketplace listing turns a new budget request into a draw on money the customer has already approved. It also lets another company's agent own the user's intent. In Casey Newton's hands-on test, a Dot did about two hours of cross-app work in 15 minutes. That shows how quickly your product can become plumbing that someone else's agent calls. Newton had the product for only a couple of hours, and pricing is unconfirmed.

When model leadership lasts weeks, the most valuable clause in an AI contract is the one that lets your spend follow the winner.

What to do

  1. Require that every new or renewed OpenAI or Anthropic commitment signed this quarter includes credits usable across models, eligibility for open models, and a defined exit ramp. Procurement should not sign without them.

  2. Commission a cost-per-completed-task comparison of your top five AI workloads across Sol, Astra, Sonnet 5.5, Opus 5.5 and one open model, reported back to you within 30 days.

  3. Decide at the executive team before year-end whether your product lists in the OpenAI or Claude marketplaces and supports Sign in with ChatGPT, with the effect on customer ownership modeled first.

The bottom line

These stories share one pattern. The parties with the clearest view of AI's volatility keep their own exits open while asking customers to commit longer and pool more. That breaks the habit of treating unit price as the headline term. When leadership, pricing and even a vendor's funding path can turn within a quarter, the exit clause is effectively the price. Route every AI, compute, power and security-vendor commitment through one review this month that scores exit rights, portability and notification duties before anyone negotiates the rate.