Leader daily

Edition 2026-05-09 · read as Leader

AWS,GoogleandAnthropicRewritetheVendorExitClause

Sources
41
Words
1,786
Read
9min

Topics Agentic AI AI Capital AI Regulation

◆ The signal

AWS and Google shipped competing agent identity frameworks in the same week, which is the opening move in a control-plane fight over who owns the audit log, the permission model, and the billing relationship for every AI agent an organization deploys. In the same stretch, Anthropic signed a compute deal with SpaceX that includes a 'kill switch' clause letting the infrastructure provider revoke access if the AI 'harms humanity.' The vendor decision this quarter is no longer about compute or models. It is about whose exit clauses govern the relationship, and they are not written for the buyer.

◆ INTELLIGENCE MAP

  1. 01

    Agent Identity Control Plane War Goes Live

    act now

    AWS made MCP Server GA with 15,000+ authenticated API operations. Google launched agent IAM with OAuth and certificates the same week. Cisco acquired Astrix for agent security. The hyperscaler that defines how agents authenticate, delegate, and audit will own the stickiest enterprise lock-in since cloud IAM.

    15,000
    AWS agent API operations
    6
    sources
    • AWS MCP APIs (GA)
    • Cisco agent acq.
    • Lock-in horizon
    1. 01AWS (MCP GA)15000 APIs
    2. 02Google Cloud (Agent IAM)OAuth + certs
    3. 03Cisco (Astrix acq.)Agent security
    4. 04Anthropic (Managed)20 parallel agents
  2. 02

    AI Infrastructure: $35B Bets on Faith-Based Financing

    monitor

    CoreWeave spending 3x revenue ($35B capex vs $12-13B revenue) with $24.8B debt, 2/3 of cash from Nvidia equity. Nvidia invested $2.6B in infrastructure in 48 hours. Core Automation reached $4B valuation in 6 weeks. The entire AI compute layer is financed by overlapping counterparties — if one large buyer pulls back, the stress travels everywhere.

    $35B
    CoreWeave 2026 capex
    5
    sources
    • CoreWeave debt
    • CoreWeave backlog
    • Core Automation val.
    • Nvidia infra (48hr)
    1. CoreWeave Capex35
    2. CoreWeave Debt24.8
    3. CoreWeave Revenue12.5
    4. CoreWeave Cash3
  3. 03

    AI Regulatory Architecture Forks: Federal Preemption vs. Criminal Liability

    monitor

    DOJ filed to support xAI's constitutional challenge against Colorado's AI law — signaling federal preemption preference. Tennessee enacted Class A felony liability for developers who 'knowingly train harmful models.' EU Cloud Act may structurally exclude US hyperscalers. Three incompatible regimes crystallizing simultaneously.

    3
    sources
    • DOJ filing date
    • TN felony class
    • EU debate date
    • States w/ AI laws
    1. Federal preemption35
    2. State fragmentation45
    3. EU sovereignty20
  4. 04

    AI ROI Credibility Gap: Markets Punish the Narrative

    act now

    Cloudflare lost 18% on a profitable quarter after naming 'agentic AI-first' as the layoff reason. Research shows AI coding tools deliver <25% real success vs 80-90% benchmarks. 'AI Psychosis' label gaining currency among engineering leaders. The market wants AI returns but punishes companies that show what producing them costs.

    3-4x
    benchmark overstatement
    7
    sources
    • Cloudflare stock drop
    • Real vs benchmark
    • Augment vs replace
    • Zero AI headcount impact
    1. Vendor benchmark88
    2. Real-world success24
  5. 05

    Voice AI Crosses Production Threshold

    background

    OpenAI's GPT-Realtime-2 delivers GPT-5 reasoning in live voice with instruction retention jumping from 36.7% to 70.8%. Pricing held flat at $1.15/$4.61/hr despite 3x capability gain. Glean reports 43% helpfulness increase in production. Google matching on benchmarks means competition shifts to ecosystem, not models.

    70.8%
    instruction retention
    4
    sources
    • Retention (old)
    • Retention (new)
    • Languages supported
    • Price/hour (input)
    1. Instruction Retention70.8
    2. Big Bench Audio96.6
    3. Glean Helpfulness43

◆ DEEP DIVES

  1. 01

    The Agent Control Plane War: Whoever Owns Authentication Owns the Decade

    The Race Is On — And the Stakes Are IAM-Level Lock-in

    AWS and Google Cloud shipped production-grade AI agent identity frameworks in the same week. The coincidence is not a coincidence. Both hyperscalers have independently concluded that agent IAM is where the next round of enterprise lock-in gets decided, and they are correct to conclude it. AWS made its MCP Server generally available with authenticated access to all 15,000+ API operations, sandboxed execution, and curated 'Skills.' Google shipped agent identity built on OAuth, certificates, and runtime defense. Whoever defines how an agent authenticates ends up being integrated against by everyone else.

    The company that defines how an agent authenticates, what it is allowed to do on a human's behalf, and how that delegation is logged will own the layer every other vendor has to integrate against.

    A reasonable skeptic would say this is still early. The reasonable skeptic is correct. What the skeptic does not explain is why Cisco just acquired Astrix Security. Six months ago, agent security was a conference track. It is now a line item on the balance sheet of the largest networking vendor in the world.


    The Governance Dimension Nobody Priced In

    Anthropic's SpaceX compute deal adds a clause most procurement teams have never had to evaluate. The contract includes a 'kill switch' clause allowing SpaceX to reclaim compute if Anthropic's AI 'harms humanity.' The infrastructure provider is now a de facto AI safety regulator. When Musk simultaneously leases capacity to Anthropic, retains a kill switch on that capacity, and vertically integrates xAI inside SpaceX, the contract is political risk wearing a SaaS label.

    Anthropic's 'dreaming' feature compounds the dependency. When agents analyze 100 past sessions to optimize future workflows, every day of operation makes the deployment more valuable and harder to replicate. Combined with 20-agent parallel orchestration and Microsoft 365 integration, the platform becomes load-bearing for enterprise operations within 6-12 months of deployment.


    The Pentagon Validates the Urgency

    Pentagon CTO Emil Michael called cyber-capable AI 'inevitable' and said the government must 'operationalize defense before adversaries do.' In the same window, LayerX researchers demonstrated they could hijack Claude's browser extension to exfiltrate Google Drive files and steal GitHub code, even after a patch attempt.

    The board-deck version of this is that agent identity governance is optional plumbing. The complete version is that it is the category that decides whether AI agents are treated as trusted users with extra steps, which is wrong, or as untrusted intermediaries with narrow grants, which is right. The first framing will not survive the first serious incident.

    Action items

    • Convene CTO + CISO to determine whether agent identity is a procurement question or an architecture question — decide which delegation semantics your agents operate under before a vendor writes them for you
    • Audit all deployed AI agents for cross-tool injection risks and overprivileged access patterns within 30 days
    • Evaluate thin abstraction layer across AWS MCP and Google Agent IAM to preserve switching capability
    • Monitor Cisco Astrix integration and Opal Security positioning as potential partners for vendor-neutral agent governance

    Sources:TLDR IT · TLDR DevOps · AI Breakfast · CyberScoop · Risky.Biz · Executive Offense

  2. 02

    The $35B House of Cards: AI Infrastructure Is Financed by Its Own Customers

    CoreWeave's Numbers Tell the Whole Story

    There is a version of AI infrastructure financing that looks like ordinary enterprise capex. CoreWeave's Q1 print is not that version. The numbers are the clearest public view of how the build-out is actually getting paid for.

    MetricValueSignal
    2026 Capex (projected)$35B3x revenue
    Total Debt$24.8B8x cash
    Cash on Hand$3B2/3 from Nvidia equity
    Q1 Revenue$2BDoubled YoY
    Backlog$100BUp from $67B

    Jensen Huang's line that CoreWeave "would not exist" without Nvidia is both a boast and a disclosure. Nvidia is financing its own customers' GPU purchases. That is excellent strategy for Nvidia. For everyone else in the chain, it is concentrated counterparty exposure wearing the clothes of a diversified market.

    When the supplier is also the financier, the risk is not distributed. It is concentrated in one counterparty relationship.

    The Talent Repricing Accelerates the Instability

    Core Automation went from founding to a $4B valuation in six weeks, with Nvidia in the seed round. Referral bonuses are quoted at $30-50K, which is a year's rent. The implied fully-loaded cost of a working AI engineer has crossed $600K per year. This is not a recruiting anecdote. It is the cost structure the infrastructure layer has to service out of revenue that has not shown up yet.

    The retention math now reads the same way for every senior researcher. Vest equity over four years at a modest multiple, or leave and plausibly generate a hundred times more personal wealth in six weeks. That choice reprices everyone, whether any individual actually takes it or not.


    The OpenAI Chip Financing Failure Is the Canary

    Broadcom required Microsoft to commit to 40% of chip purchases before underwriting an $18B production run for OpenAI. Microsoft will not commit. A reasonable skeptic would point out that Microsoft has its own reasons and one deal is one deal. The reasonable skeptic is correct. The skeptic does not explain why the best-capitalized AI buyer on earth cannot unilaterally finance custom silicon. If that is the binding constraint, the optimistic timeline for Nvidia displacement is wrong by two to three years, and GPU pricing power stays exactly where it is.

    For enterprise compute planning, the implication is direct. Pure-play GPU providers are the most levered expression of a single demand assumption held by three or four buyers. If even one anchor buyer renegotiates, or moves to its own silicon on a timeline it controls, the stress does not stay inside one vendor's 10-K. It travels.

    Action items

    • Stress-test AI compute supply chain for counterparty failure — specifically model what happens if CoreWeave or similar pure-play providers face a liquidity event
    • Negotiate locked-in pricing with hyperscalers while pure-play competitive pressure still exists — secure contract flexibility and alternative sourcing
    • Design talent retention strategy with venture-economics-competitive mechanisms for top 15 AI researchers — co-creation vehicles, internal ventures, research sabbaticals
    • Build distressed-acquisition watchlist for AI companies that raised at inflated fast-follow valuations but lack growth path

    Sources:Martin Peers · The Information AM · The Information · Katie Roof · Bloomberg Technology · a16z

  3. 03

    Three Incompatible Regulatory Regimes Are Crystallizing — Pick Your Position Now

    Federal Preemption: The Government Picked a Side

    On April 24 the DOJ filed an amicus brief supporting xAI's constitutional challenge to Colorado's AI law, on Equal Protection grounds. That is the clearest signal the federal executive branch can send that it prefers to preempt state AI regulation. If Colorado's law falls, the precedent reaches every state AI bias and fairness law currently enacted or pending.

    A reasonable skeptic would point out that preemption, if it arrives, does not eliminate regulation. The skeptic is correct. It consolidates regulation at a level where rules are written by fewer people with different incentives, and the rulemaking calendar runs in years rather than quarters. Firms that over-invested in state-by-state compliance architectures are sitting on stranded cost. Firms that under-invested are about to discover that the federal version of the rule is the one that matters.

    The firms that help write the NIST pre-deployment evaluation framework are the firms that will find it easiest to comply with. The firms that wait will comply with someone else's version of their business.

    Criminal Liability: The Category Shift Nobody Budgeted For

    Tennessee's SB 1493 makes developers potentially liable for Class A felonies if they 'knowingly train models for harmful conduct.' Civil liability can be insured, budgeted, and managed. Criminal liability cannot. The word 'knowingly' applied to pre-training on internet-scale data is genuinely unresolved, and copycat legislation in other states is the base case, not the risk case.


    EU Sovereignty: Structural Exclusion, Not Behavioral Conditions

    The EU Cloud and AI Development Act goes to debate at the end of May. Unlike GDPR, which required compliance, this legislation contemplates structural exclusion of non-European providers. EU officials describe US pushback as 'very effective lobbying,' which is the language of people who have already decided to push through. Planning a European cloud footprint without the three US incumbents is not this quarter's decision. The architecture work starts now.


    NIST as De Facto Gatekeeper

    NIST CAISI pre-deployment evaluation agreements now cover Google DeepMind, Microsoft, and xAI. Anthropic is conspicuously excluded and carries an active supply chain risk designation. Federal procurement is tightening around demonstrated safety evaluations. Companies outside CAISI face a growing barrier to the government market. This is competitive positioning wearing a compliance badge.

    Action items

    • Determine your position on xAI v. Colorado — file amicus or join industry coalition within 60 days if you want to influence the outcome
    • Apply to NIST Community of Interest for AI in Critical Infrastructure profile this quarter
    • Commission legal analysis of Tennessee criminal liability exposure and develop model training documentation protocols
    • Initiate scenario planning for EU Cloud Act implications — model architecture running from EU-controlled infrastructure with mandatory European partners

    Sources:a16z AI Policy Brief · Risky.Biz · SANS NewsBites · Matt Johansen

  4. 04

    The AI ROI Credibility Gap: Your Board Will Ask Before You're Ready

    Markets Established a New Rule This Week

    Cloudflare grew revenue 34%, beat earnings, and watched its stock fall 18% after management framed 1,100 layoffs as an 'agentic AI-first operating model.' The signal from the tape is specific. Investors will pay for AI-driven margin expansion described in the passive voice. The moment a CEO narrates the mechanism — people out, agents in — the same investors discover execution risk questions they did not have the day before.

    DeepL cut 25% of headcount in the same window. The capability sells when it is invisible. The restructuring does not sell when it is named.

    Investors are willing to pay for AI-driven margin expansion as long as the margin expansion is described in the passive voice. The moment a CEO narrates the mechanism, the same investors discover questions they did not have the day before.

    The Benchmark Fraud Is Now Quantified

    A study across 57 LLMs finds the top models complete fewer than 1 in 4 refactoring tasks without errors. Vendor benchmarks claim 80-90%. That 3-4x gap is not a rounding error. It is a category error sitting inside the capex line, and every board narrative built on vendor benchmarks is one QBR away from a credibility event.

    In parallel, 'AI Psychosis' is picking up currency in a community of 30,000+ engineering leaders — the working label for agent platforms that simulate delegation without producing measurable output. Once a CFO hears the phrase twice, the accountability question follows.


    The Data Says Augmentation, Not Replacement

    Earnings calls are running an 8:1 ratio of augmentation language over displacement language. More than 90% of firms report zero headcount impact from AI deployments. Enterprise buyers are purchasing capability elevation, not substitution: a team of 10 doing what required 30, with the 10 retained. Products pitched as displacement tools are targeting the wrong buyer psychology and the wrong budget line.

    The Klarna arc is now complete. The company publicly celebrated replacing 700 agents with AI in early 2024, then rehired inside eighteen months when quality collapsed. Philippines BPO employment climbed to 1.9M over the same window.


    What This Means for Your Next Board Meeting

    The organizations that survive the rationalization cycle will be the ones that tie AI spend to value before the CFO imposes measurement unilaterally. This is the cloud cost management story running a second time. The difference is that the hype-to-accountability gap has compressed from years to quarters.

    Action items

    • Segment AI agent deployments into 'riding a revenue loop' vs. 'looking for one' and bring that segmentation to the board before someone else names the second category
    • Commission internal audit of AI tool ROI claims vs. actual measured productivity — independent of vendor metrics — completed within 45 days
    • Revise AI transformation communications strategy to separate restructuring narrative from AI capability narrative in all investor materials
    • Reframe board AI metrics from revenue-first to usage-first (DAU/WAU ratio alongside ARR) for all AI-enhanced products

    Sources:StrictlyVC · Techpresso · TLDR · TLDR Founders · The Download from MIT Technology Review · Pointer

◆ QUICK HITS

  • Update: Anthropic's Mythos produced 12x Mozilla's security output — 423 bug fixes in April vs 31 the prior year, including a 15-year-old HTML parsing error at $20K bounty tier

    Simplifying AI

  • DigiCert certificate authority breached via social engineering — signed malware reaching 100+ organizations across 100+ countries, cascading Microsoft Defender false positives on legitimate roots

    Matt Johansen

  • CISA's CI Fortify directive tells critical infrastructure operators to architect for 'weeks or months' of complete network isolation during conflict — cloud-native without offline mode is now a disqualifier for federal RFPs

    SANS NewsBites

  • Coinbase embedded x402 crypto payments into AWS Bedrock AgentCore — positioning USDC micropayments as default settlement for autonomous AI agents on world's most popular cloud AI platform

    TLDR Crypto

  • Datadog rose 30% on AI-usage print: 20% of AI customers drive 80% of ARR — power-law economics in AI SaaS now quantified and market-priced

    The Information AM

  • Token costs scale 54% higher with smarter models on unoptimized backends — agent-native infrastructure (InsForge) demonstrated 64% cost reduction vs. legacy patterns on identical tasks

    Daily Dose of DS

  • Google rolling out continuous AI-powered user profiling across Gmail, Calendar, Maps — two prospects searching the same query now see entirely different results, structurally obsoleting keyword-based SEO

    TLDR Marketing

  • Aalo Atomics received DOE safety approval for 50MWe modular reactor purpose-built for hyperscale data centers — zero-power criticality targeted July 4, 2026

    Not Boring

  • State actors (MuddyWater) deliberately wearing ransomware-as-a-service brands as operational cover — attribution layer of every IR playbook now unreliable by design

    Matt Johansen

  • Uber spent ~$1B across Lucid ($500M) and Nuro (~$500M) assembling closed-loop robotaxi stack — 35,000-vehicle Lucid order denies competitors access to autonomous-ready hardware at scale

    Kirsten at TechCrunch Mobility

◆ Bottom line

The take.

The AI industry just split into three simultaneous wars — who owns the agent control plane (AWS vs. Google, decided in 12 months), who survives the infrastructure financing bubble ($35B in capex on $24.8B in debt at CoreWeave alone), and who navigates a regulatory landscape where the federal government, individual states, and the EU are building three incompatible regimes at once — while the market just demonstrated it will punish any company that says out loud what the AI restructuring actually costs in human terms. The firms that win the next 18 months are the ones that pick their agent platform deliberately, stress-test their compute supply chain for counterparty failure, file their regulatory positions before the window closes, and have an honest ROI number ready before the board asks for one.

— Promit, reading as Leader ·

Frequently asked

Why does agent identity matter more than the model or compute decision this quarter?
Agent identity defines who owns the audit log, the permission model, and the billing relationship for every AI agent you deploy. AWS and Google shipping competing frameworks in the same week signals that the control plane is being decided now, and whichever vendor's defaults you accept will harden into IAM-level lock-in within two quarters.
What is the 'kill switch' clause in the Anthropic-SpaceX deal and why should buyers care?
The contract lets SpaceX revoke Anthropic's compute access if its AI is judged to 'harm humanity,' making the infrastructure provider a de facto AI safety regulator. For enterprise buyers, this means vendor exit clauses are now governed by third parties whose incentives are not aligned with yours, and procurement needs to evaluate political and revocation risk alongside SLAs.
How exposed is the AI infrastructure layer to a single counterparty failure?
Heavily. CoreWeave is carrying $24.8B in debt against $3B cash, two-thirds of which came from Nvidia equity, while projecting $35B in 2026 capex. Nvidia is effectively financing its own customers, so a stress event at one pure-play GPU provider would travel through the supply chain rather than stay contained in one vendor's filings.
Why did Cloudflare's stock fall 18% despite beating earnings?
Management explicitly framed 1,100 layoffs as a shift to an 'agentic AI-first operating model,' and investors immediately repriced execution risk. The lesson is that markets will reward AI-driven margin expansion when it is described passively, but punish the same results when leadership narrates people-out, agents-in as the mechanism.
How wide is the gap between vendor AI benchmarks and real-world performance?
A study across 57 LLMs found top models complete fewer than 1 in 4 refactoring tasks without errors, against vendor claims of 80-90%. That 3-4x gap means board narratives built on published benchmarks are one quarterly review away from a credibility event, and internal ROI audits independent of vendor metrics need to happen before the CFO demands them.

◆ Same day, different angle

Read this day as…

◆ Recent in leader

Keep reading.