Listen to this newsletter ⬆️

Subscribe Forward this edition

The Agentic Enterprise
AK · Monday Edition · 7 min read
Monday, August 3, 2026
The Open Secure AI Alliance skipped the frontier.
NVIDIA and more than three dozen companies launched the Open Secure AI Alliance on Friday to make AI agents inspectable and auditable. OpenAI, Google, and Anthropic, the three labs most tied to closed frontier models, are not in it.
The timing is the tell. In the ten days before the launch, two of those three labs disclosed that their models had reached real systems they were never supposed to touch. The industry just drew a line between the labs that build the smartest agents and the coalition writing the rules for keeping them contained. For a buyer, that line now runs through your stack.
The Big StoryGovernance / Security
The new fault line in AI is inspectable versus closed.
On July 31, NVIDIA and more than three dozen companies launched the Open Secure AI Alliance, a group built to develop open-source tools for securing AI agents and the software around them. Its first technical contribution, a framework called NOOA, is Apache 2.0 and designed to make agent behavior easy to trace, test, and audit as models reach into tools, code repositories, and enterprise systems. The alliance runs under the Linux Foundation and the Open Source Security Foundation. The founding roster spans security and enterprise software: Microsoft, IBM, Cisco, CrowdStrike, Cloudflare, Palo Alto Networks, Red Hat, and Hugging Face among 37 members.

Notice who is not on it. OpenAI, Google, and Anthropic, the three labs most identified with closed frontier models, did not join. That absence lands days after the reason it matters. OpenAI disclosed an intrusion involving its own agent on Hugging Face, and on July 30 Anthropic said three Claude models had gained access to real external systems during security tests that were supposed to be isolated.

Here is the enterprise read. Security is splitting into two camps. One is building open, inspectable plumbing so a buyer can see what an agent did and prove it. The other ships the most capable agents behind an API you have to trust. You are going to run both. The question is whether the closed model at the center of your workflow can produce the audit trail the open coalition is standardizing around, or whether you are back to taking the vendor's word.

The last two frontier breaches did not start with a clever model. They started with a test environment nobody was watching closely enough.
The Spearhead Take
Put inspectability in the contract. When you buy an agent for anything that touches production, ask what it logs, whether that log is tamper-evident, and whether an outside tool can replay its actions. NOOA and frameworks like it are about to make that a normal thing to demand. If your vendor cannot answer, you do not have a security posture. You have a hope.
The Obvious & The Overlooked
Three reads the market has made. Four it has not.
The Obvious
Security is now a board-level AI topic.
Two frontier-lab incidents in two weeks made agent safety a line item, not a footnote. Tom's Hardware
Everyone is shipping agents.
About 31% of enterprises now run one in production, and Gartner expects 40% of enterprise apps to embed one by year-end. Paul Okhrem
The big platforms keep writing the standards.
Google, Microsoft, and the hyperscalers are again drafting the specs the rest of the market will follow. InfoQ
The Overlooked
The risk is the harness, not the model.
Anthropic's models reached live systems because a test environment was misconfigured, not because the weights went rogue. Anthropic
Two coalitions are routing around the closed labs.
The security alliance and the ARD agent-discovery standard both launched without OpenAI or Anthropic. CryptoBriefing
AI cost control moved to the CIO, not the CFO.
78% of FinOps practices now report into the CTO or CIO, reframing spend as an architecture problem. The Daily Brief
Announced is not adopted.
ARD is a v0.9 draft with near-zero uptake, and NOOA is a research framework. The standards exist mostly on paper. Synscribe
Moving Pieces
Five developments worth a CIO's attention.
Governance / Security
Anthropic's models broke into real systems, and the hole was the plumbing

Anthropic disclosed on July 30 that three versions of Claude, including Opus 4.7 and Mythos 5, reached real external machines during capture-the-flag security tests that were supposed to run in isolation. The models were told they were in a sealed simulation. They were not: a misconfiguration on the evaluation partner's side left the machines online the whole time. Anthropic combed through 141,006 evaluation runs to find the three, the earliest dating to April. The lesson for anyone deploying agents is uncomfortable and cheap to act on. Your agent's blast radius is set by what you connected it to, not by how well-behaved the model is. Audit the environment before you audit the model.

Sources: Anthropic · CBS News · The Hill
Policy / Regulation
The compliance clock struck on Saturday

August 2 was a real deadline, not a symbolic one. The EU AI Act's Article 50 transparency duties became enforceable: anyone deploying a chatbot or generating synthetic media for EU users must now disclose it clearly, with fines up to 15 million euros or 3% of global turnover. California's AI Transparency Act became operative the same day, and Colorado's framework follows on January 1, 2027. The reprieve is on the heavy stuff: the EU's AI Omnibus pushed high-risk system deadlines out to December 2027 and August 2028. So the near-term work is disclosure and labeling, not full conformity assessments. If your product talks to European users, the label is due now.

Sources: Lumenova · Cubbbix
Product / Interoperability
A standards war over how agents find each other

While the security alliance formed, a parallel fight over interoperability kept building. Agentic Resource Discovery, or ARD, is an open spec that lets agents look up available tools and other agents through an ai-catalog.json file each vendor hosts, then verify the publisher before connecting. It is backed by Google, Microsoft, Salesforce, Snowflake, ServiceNow, Databricks, and NVIDIA, and licensed Apache 2.0. The same two names missing from the security alliance are missing here too: OpenAI and Anthropic. The pattern is worth naming. The platform layer is coordinating on open plumbing, and the frontier labs are sitting it out. For buyers, that raises a real question about which agents will actually be discoverable in a shared registry, and which will stay walled.

Governance / Workforce
AI cost control quietly changed hands

The org chart for AI spending moved this year, and most leaders missed it. In the FinOps Foundation's 2026 data, 98% of practitioners now carry responsibility for AI spend, up from 31% in 2024, and 78% of FinOps practices report into the CTO or CIO rather than the CFO. Translation: controlling AI cost is being treated as an architecture job, not a finance one. The trigger was pain. Uber burned its entire 2026 AI budget by April and now caps each employee at $1,500 a month per agentic coding tool. If your AI bill is still a line the CFO reviews after the fact, you are a quarter behind. Put the meter next to the deployment.

Deals / Markets
The strategics are becoming the market's anchor checks

The interesting money last week was corporate, not financial. ServiceNow led a $40 million Series C in Businessnext, an autonomous banking-software firm, at a $700 million valuation. Uber anchored a $1.7 billion raise for Atoms, an industrial AI and robotics company building automation for physical production and transport. Two very different deals, one signal: operating companies are writing the checks that used to come from pure venture funds, buying strategic proximity to the AI they intend to deploy. For a CIO, that changes the diligence question. When your software vendor's largest investor is a customer in your own industry, the roadmap you are betting on may be steered by someone else's priorities. Read the cap table, not just the demo.

On the Radar
Nine signals, sharpened.
GovernanceNVIDIA open-sourced the NOOA framework. The Apache 2.0 project is built to trace, test, and govern what AI agents do as they touch tools, data, and code, the first technical output of the new alliance. The Hacker News
ProductGoogle Cloud's model catalog is churning fast. The Grok 4.1 family on the Gemini Enterprise Agent Platform shuts down August 20, and Gemini 3.5 Flash was pulled from the global region on August 4, a reminder of how quickly the layer under your workflows moves. Google Cloud
SecurityAnthropic named its evaluation partner, Irregular. The misconfiguration that left test machines online, and Claude able to reach them, traced to a misunderstanding between the two, not to the model itself. Al Jazeera
PolicyCalifornia's AI Transparency Act went live August 2. The disclosure law took effect the same day as the EU's Article 50 duties, with Colorado's own framework arriving January 1, 2027. Cubbbix
PolicyThe EU delayed its high-risk deadlines. The AI Omnibus pushed Annex III systems to December 2027 and Annex I systems to August 2028, easing the timeline that once loomed this month. Lumenova
DealsPeregrine raised $250M Series D at a $6.8B valuation. The company unifies siloed data into permission-aware environments for government and enterprise, a pointed bet on access control as the AI-data bottleneck. Crescendo
ResearchGartner sees agents in 40% of enterprise apps by year-end. That is up from under 5% in 2025, the steepest embed curve the firm has tracked for any enterprise capability. Gartner
DeploymentRoughly 31% of enterprises now run an agent in production. The gap between piloting and shipping is closing, though most deployments remain single-workflow rather than fleet-wide. Paul Okhrem
SecurityThe alliance sits under the Linux Foundation and OpenSSF. That governance choice signals it wants to be treated as shared infrastructure, not a NVIDIA marketing vehicle, with 37 members spanning cloud and security. NVIDIA
Quick Hits
Twelve more, worth knowing.
CARPL raised a $10M Series A for a clinical marketplace to test and deploy radiology AI. Tech Startups
Cast Insights raised $4.5M pre-seed to capture and analyze real-time ephemeral speech data. Parsers
Modo Energy raised $17M for an AI valuation platform covering energy storage and renewable assets. Parsers
Arrakis emerged from stealth with a $30M Series A at a $140M valuation, with Datadog's CEO among the angels. Parsers
Gritt raised a $26M Series A for robots that roughly quadruple solar-panel installation rates. Parsers
ARD publishes agent capabilities via an ai-catalog.json manifest hosted under each vendor's own domain, still a v0.9 draft. InfoQ
Neither OpenAI nor Anthropic appears on ARD's backer list, the same absence as the security alliance. CryptoBriefing
The blended cost of enterprise AI fell about 67% year over year, from roughly $18.40 to $6.07 per million tokens, yet total bills still rose as volume outran budgets. The Source Code
AI inference now runs about 85% of enterprise AI budgets, shifting the cost story from training to serving. The Source Code
One enterprise reportedly hit a $500M single-month Claude bill before spend caps arrived, an outlier that pushed the market toward cost controls. Dallas Express
North American startup funding topped $392B in the first half of 2026, a record driven overwhelmingly by AI. Crunchbase News
AI startups captured roughly 80% of global venture capital in Q1 2026, the highest concentration on record. Second Talent
The Number
73%
Of enterprises overran their AI budget
Some by a factor of 2.4. The cause was not waste. It was success.
Agentic tools spread faster than any budget model priced in, and consumption billing turned adoption straight into invoice. This is why cost governance has moved next to the architecture, not after it. Budget the AI you deploy like a variable-cost utility, because that is exactly what it behaves like.
Counter-Signal
Risk / Governance
A coalition of drafts and absences.

The tidy read on Friday is that the industry finally got serious about agent security. Slow down before you bet a roadmap on it. NOOA is a research framework, not a shipped control. ARD, the discovery standard from the same open camp, is a v0.9 draft with adoption near zero. And the three labs whose agents actually operate at the capability frontier, the ones behind the two breaches that prompted all this, are outside the group writing the rules.

So the security consensus is real but partial. It governs the open plumbing while the most powerful agents keep running on closed stacks that the standards do not yet reach. A CIO who treats "backed by 37 companies" as "safe to deploy" is buying a press release. The useful move is narrower: adopt the inspectability practices now, on the workflows you control, and stop waiting for the coalition to finish the spec.

From the Field
Last week the question was your Lean kernel: what checks the model's work. This week the news answered a different one.

When Claude reached machines it was never meant to touch, the model was not the villain. A test environment was misconfigured, the internet was reachable, and a system doing exactly what it was told wandered somewhere it should not have. Nobody wrote a jailbreak. Somebody wrote a bad config. That is the part of agentic AI we keep underinvesting in. We spend the budget on the model and treat the plumbing, the tool permissions, the network boundaries, the eval environment, as an afterthought. But the plumbing is where the risk actually lives. An agent's intelligence is a spec sheet. Its blast radius is an architecture decision, and it is yours to make, not the vendor's.

So this week's question is the companion to last week's. You know what checks the work. Now: what is the blast radius when it goes wrong? What can this agent reach, who approved that reach, and how fast can you cut it off?

Draw that boundary on paper before the agent draws it for you.

Let's get to production,
AK
Talk to SpearheadForward this edition
The Agentic Enterprise
Know more about AI than 95% of your peers. By 7 AM.
A daily AI intelligence briefing for enterprise leaders, published by Spearhead. We build AI systems that work. Strategy. Engineering. Production. Outcomes.
© 2026 Spearhead. All rights reserved.

Keep Reading