Listen to this newsletter ⬆️

Subscribe Forward this edition

The Agentic Enterprise -- July 20, 2026 (Hybrid)
The Agentic Enterprise
AK · Morning Edition · 7 min read
Monday, July 20, 2026
AI bug hunting is about to go on sale.
Microsoft's Project Perception, reported this week and due before month's end, routes vulnerability hunting across cheaper models to undercut the tightly restricted AI most companies could never buy.
The vulnerability-hunting AI at the center of Anthropic's Project Glasswing has spent the past year behind a velvet rope. Claude Mythos helped roughly 50 partners find more than 10,000 high- or critical-severity flaws in the world's critical software, and by Anthropic's own account can outperform all but the most skilled human researchers. Almost no other organization could touch it. This week The Information reported that Microsoft is about to pull the rope aside, doing the same job across cheaper models that run constantly and cost little. That reframes AI security from a capability question into a procurement one, and it starts a clock every CISO should hear ticking.
The Big Story Governance / Security
AI vulnerability hunting just stopped being a luxury good.
The 20-second version
  • The Information reported on July 17 that Microsoft will launch Project Perception before month's end.
  • It scans enterprise code for vulnerabilities and routes each task to a different model to keep costs low.
  • It's a direct shot at Anthropic's Claude Mythos, which is more capable but rationed to about 50 partners.
  • For buyers, AI vulnerability scanning becomes a cost-and-coverage decision, not a research privilege.
  • The same cheap scanning arms attackers too, so how fast you fix now matters more than how fast you find.
M icrosoft is preparing to launch Project Perception, a security platform that scans enterprise codebases for exploitable flaws, and it is built as a direct cost-and-access argument against Anthropic's Claude Mythos. The Information first reported the plan on July 17. Where Mythos is a single, tightly restricted frontier model, meaning a large, state-of-the-art AI model, Perception is an orchestration layer that decides which model handles each step. A cheap, distilled model runs inventory checks, log parsing, and first-pass triage. A frontier model gets called only to reason through a complex exploit chain or write a remediation plan that touches production. The point is to make continuous scanning cheap enough to leave running.

The reason this matters is not that AI can now find bugs. It's that the capability is about to become ordinary. For a year, Anthropic's approach defined the category: extraordinary capability, deliberately rationed. Glasswing's partners, a roster that includes AWS, Apple, Cisco, CrowdStrike, JPMorganChase, and Palo Alto Networks, used Mythos to surface more than 10,000 critical vulnerabilities. Impressive, and beside the point for the CISO who couldn't get access. Microsoft's bet is that most enterprises don't need the sharpest tool on every job. They need a competent one that never sleeps and doesn't blow the budget.

For enterprise buyers, three things follow. AI-driven vulnerability discovery is becoming a line item you evaluate on cost and coverage, not a research privilege. Multi-model routing, not single-vendor loyalty, is emerging as the enterprise default. And the same cheap, always-on scanning is available to whoever is attacking you, which means the window to find your flaws before someone else does is closing.

When everyone can find the flaws, the advantage goes to whoever fixes fastest.
The Spearhead Take
The buying instinct here is to ask which model is strongest. That's the wrong question. In the systems we build, the frontier model is the expensive specialist you call sparingly, not the default that runs every task. Perception's architecture, cheap models for volume and a frontier model for the hard reasoning, is simply good engineering, and it's how production AI economics actually work. The harder question is what happens after the scan. Finding the flaw was never the bottleneck.
The Obvious & The Overlooked
Three reads the market has. Four it is missing.
The Obvious
AI can out-hunt human security researchers.
Glasswing partners used Claude Mythos to find more than 10,000 critical vulnerabilities. Anthropic
Microsoft will compete on price and reach.
Perception's whole pitch is lower cost and wider access than a restricted frontier model. TechRepublic
Multi-model routing is winning.
Perception mixes Microsoft, OpenAI, and Anthropic models rather than betting on one. TechTimes
The Overlooked
Cheap detection floods the remediation queue.
Constant scanning produces more findings than most teams can patch. Windows News
Attackers get the same discount.
Democratized vulnerability hunting is a defensive win and an offensive one at once. TechTimes
The scarce resource is trust, not detection.
Only 5% of enterprises trust AI agents enough to run them in production. VentureBeat
Agent identity is the next attack surface.
Non-human identities now outnumber human ones, and most enterprises can't see them. SailPoint
Moving Pieces
Five developments worth a CIO's attention.
Policy
The EU just pried open the phone in your pocket for rival AI

The European Commission issued two binding Digital Markets Act decisions on July 16, under the EU law that sets rules for large platforms, forcing Google to open Android and Google Search to competitors. Users must be able to summon a third-party AI assistant by voice the way they invoke "Hey Google," and rivals must be allowed to act across apps. Google must also start sharing anonymized search ranking, query, and click data with eligible competitors in January 2027. The enterprise read: the assistant layer on 60% of EU phones is being unbundled from Gemini, which widens real model choice for any company building consumer-facing AI in Europe. Most of the device changes don't reach users until July 2027, so this is a planning signal, not a switch you flip today.

Sources: Semafor · Bloomberg
Product
OpenAI ships an agent that wants to do the whole task

OpenAI launched ChatGPT Work on July 9 and broadened its GPT-5.6 rollout, which had been held to a limited preview under US government concerns about cyber and bio capabilities. ChatGPT Work is an agent, software that carries out multi-step tasks with some autonomy. It operates across apps and files, runs long tasks, coordinates tools, and produces documents, decks, and spreadsheets, so employees delegate workflows rather than fire off single prompts. GPT-5.6 comes in three sizes, Sol, Terra, and Luna, with Sol at $5 per million input tokens. The enterprise read: this is the same platform bet Microsoft, Google, and Anthropic are all making, that the unit of AI work is shifting from the answer to the completed task. The gate, as ever, is whether you trust it to act unsupervised.

Sources: InfoWorld · Axios
Deals
Together AI raises $800M betting the open models catch up

Together AI closed an $800 million Series C on July 1 at an $8.3 billion valuation, led by Aramco Ventures with Nvidia, Salesforce Ventures, and others in. The company runs and trains workloads on open models, models whose weights are public, like DeepSeek, Nemotron, and Kimi, and reported bookings above $1.15 billion in its most recent quarter. It also lined up more than 500 megawatts of compute to fund a roughly fiftyfold infrastructure buildout. The enterprise read: capital is validating the thesis that open-weight models, run on cheaper infrastructure, are good enough for a growing share of production work. That's optionality for buyers tired of single-vendor pricing, and a reason to keep an inference-cost comparison in every AI budget review.

Governance
SailPoint buys Entro because your agents have logins too

SailPoint completed its acquisition of Tel Aviv-based Entro on June 29 to fold non-human identity security into its Agentic Fabric platform. A non-human identity is a login or credential used by software rather than a person. The combined product claims out-of-the-box coverage for more than 1,000 agent and machine-identity types and discovery of over 1,200 credential types across cloud, CI/CD, and SaaS. The enterprise read: every AI agent you deploy is a new account with permissions, secrets, and the ability to act, and in most enterprises non-human identities already outnumber human ones. That's a fast-growing attack surface almost no identity program was built to see. Before you scale agents, ask who governs their credentials, because right now the honest answer is usually no one.

Infrastructure
TSMC's numbers say the AI demand is still real

Taiwan Semiconductor reported second-quarter revenue of about $39.6 billion, up 36% year over year, driven by orders for the advanced chips that power AI training and inference. The company that fabricates the silicon under Nvidia, AMD, and the hyperscalers is the cleanest available proxy for whether AI spending is holding. The enterprise read: for all the debate about tightening AI budgets and returns, the demand signal at the bottom of the stack is not softening. If you're planning capacity or negotiating multi-year compute contracts, the supplier with the most pricing power is still the one that makes the chips, and it's still selling everything it can make.

Sources: CNBC · Reuters
On the Radar
Eight signals, sharpened.
Security Anthropic's Project Glasswing has expanded to 150 organizations across 15 countries. The controlled-access program that trained the market on AI vulnerability hunting is scaling even as Microsoft moves to undercut it. Anthropic
Deals Anthropic is reportedly tracking to roughly $47 billion annualized revenue and profitability in 2026. Treat as reported, not audited; if real, it makes Anthropic the enterprise revenue leader on Claude Code and API demand. CNBC
Product Google unveiled an expanded Gemini Enterprise portfolio for building and governing agents. The pitch shifted from selling a chatbot to selling an orchestration and governance layer across an organization. AI News
Model Google's Gemini 3.5 Pro has slipped a third time on weak coding performance. Every quarter it's absent, enterprise model contracts get signed with someone else. CNBC
Deals Harvey AI raised $200 million Series C at a $2.1 billion valuation. Legal AI keeps pulling growth capital as firms move it from pilot to billable work. Crunchbase News
Deals Glean raised $180 million Series D at a $2.7 billion valuation. Enterprise search and the context layer beneath agents continue to consolidate fast. Crunchbase News
Workforce Cisco is rolling AI agents out to all 90,000 of its employees. The vendor selling agent security is also its own largest deployment, a useful tell on where internal-facing agents work first. Fortune
Deals Taktile raised $110 million Series C, led by Goldman Sachs Alternatives. Its agentic decisioning platform targets banks and insurers, where automated decisions carry real regulatory weight. Crunchbase News
Quick Hits
The wider field, one line each.
Lovable raised $200 million Series B at a $2.8 billion valuation for AI app-building. Crunchbase News
Hebbia raised $130 million Series B at a $1.0 billion valuation for document-heavy finance work. Crunchbase News
OpenAI's Deployment Company agreed to acquire Northslope, its second applied-AI acquisition since May. TechCrunch
AI agent startups raised roughly $1.8 billion across 12-plus deals in July. Crunchbase News
Google must begin sharing anonymized search data with eligible rivals in January 2027. Bloomberg
GPT-5.6 Sol scored 53.6 on Agents' Last Exam, a long-horizon workflow benchmark. Axios
Cisco says its 5% of production agents are almost entirely internal: IT, SecOps, and finance. VentureBeat
Project Perception reserves frontier-model calls for hard steps and uses cheap models for volume scans. Windows News
Together AI secured more than 500 megawatts of compute to fund a fiftyfold buildout. TechCrunch
SailPoint's Entro deal adds coverage for more than 1,000 agent and machine-identity types. SailPoint
Microsoft is reportedly coaching salespeople to compare OpenAI, Google, and Anthropic unfavorably to its own AI. TechCrunch
Sequoia, Index Ventures, and Andreessen Horowitz dominated July's AI deal flow. Crunchbase News
The Number
5%
Of enterprises trust AI agents enough to run them in production
85% are piloting agents. 5% trust them enough to ship.
The figure comes from Cisco research shared by product chief Jeetu Patel, and it's the cleanest measure of the real gate on enterprise AI. Capability is not the constraint anymore; a cheap model can already find your vulnerabilities, and a capable one can already do the work. What almost no one has is enough confidence to let an agent act without a human watching. The 5% who shipped did it in low-blast-radius internal domains: IT, security operations, finance. The gap between piloting and trusting is where this year's budgets will either convert or quietly expire.
Source: VentureBeat
Counter-Signal
Risk
Cheap detection doesn't buy you cheap remediation.

The tidy story this week is that AI just democratized world-class vulnerability hunting. The uncomfortable part is what happens next. Finding flaws was never the expensive step. Fixing them is. Turn on always-on scanning across a large codebase and you don't get safety, you get a backlog, thousands of ranked findings landing on the same security team that was already underwater. One early account of AI-driven hunting described more than 600 patches in a single month for one organization. That is not a victory lap, it's a new operational load.

So the honest read on Project Perception is that it moves the bottleneck rather than removing it. The constraint shifts from detection, now cheap and fast, to human remediation capacity, still slow and expensive. And the same economics that arm your defenders arm your attackers, who face no change-management board and no regression testing. The enterprises that win here won't be the ones that scan the most. They'll be the ones that can triage, prioritize, and actually ship fixes at the speed the scanning now generates them. Buy the detection. Then ask, honestly, whether you can keep up with what it finds.

From the Field
There's a moment in every security review where someone asks the vendor, "but can it actually find the hard bugs?" This week made clear that isn't the question anymore.

For a while it was the right question. Capable AI can already find the hard bugs, and soon a cheaper AI running constantly will find most of them too. The question quietly changed while everyone was still asking the old one. The new question is trust. Not "can it find the flaw" but "will you let it act on what it finds." That's why the 5% number is the most important thing I read all week. Eighty-five percent of enterprises are running agents somewhere. Five percent trust them enough to ship. The whole industry is stacked up at that gate, and no model release moves it, because trust isn't a capability you can benchmark. It's earned in narrow domains, with tight blast radius, where a wrong answer is recoverable.

So here's what I'd take into this week. Stop shopping for the smartest tool and start building the conditions under which you'd let one act:

  1. Pick a low-stakes domain where a mistake is visible and reversible.
  2. Instrument it so an error gets caught and undone fast.
  3. Run the tool there and measure what it actually does, not what the demo promised.
  4. Widen the blast radius only once it has earned the trust.

The companies that pull ahead won't be the ones with the sharpest bug hunter. Everyone's about to have a capable one.

They'll be the ones who learned to trust it on purpose, one bounded decision at a time.
Let's get to production,
AK
Talk to Spearhead Forward this edition

Keep Reading