Hi everyone,

Took a week off with family in California, ending in Death Valley. Standing below sea level, surrounded by rock that's been sitting there for longer than I can really hold in my head, has a way of putting timescales and dimensions in perspective.

The last couple of weeks brought a strange AI operations story. Anthropic's Fable 5 and Mythos 5 went from frontier-model launch story to export-control story in a week. On Friday, June 12, the U.S. Commerce Department restricted foreign use of the models, and Anthropic shut off access broadly rather than try to split eligibility at runtime. That matters less as a one-company drama than as a new continuity question: what happens when a model your operations depend on can disappear by regulatory letter?

This week I'll be more focused on the practitioner side of AI adoption, the unglamorous basics where AI tooling actually begins: who owns what in the tech stack, and finding accountability for making connections work.

Cheers.
Reza

📶 Signals This Week

A few patterns kept showing up this week, in what I was reading and in the rooms I was in.

The bottleneck moved from production to review. Addy Osmani, an engineering leader at Google, called this the orchestration tax: starting agents is cheap, but closing the loop still runs through one human reviewer. HBR saw the same pressure on managers, with AI making teams faster than old review rhythms can absorb. The operator so-what: before scaling AI output, decide who reviews it, at what altitude, and what can safely ship without another human pass.

The AI bill is moving from curiosity to control. The Wall Street Journal reported that companies are starting to ration AI as costs rise. The more important shift is that usage stopped being a useful metric. "People are using AI" was a fine answer last year; now finance wants cost per outcome. I heard the same question in several meetings this month: how do we know we're actually winning? If you can't tie AI spend to a redesigned workflow with a named outcome, expect the budget conversation to get harder.

The control surface moved from apps to agents. Dun & Bradstreet rebuilt its 642-million-company graph because systems built for human analysts were not ready for machine consumers, and its "Know Your Agent" idea resonated with me. The question is no longer only who owns the app. It is who owns the agent's permission to act through it, which data it can touch, and how anyone proves what happened afterward.

🎯 AI's first demand is an ownership map

Try this for one minute. List five tools an AI agent would need to touch to do real work in your company. Your CRM, probably. The data warehouse. A couple of the systems where the actual work lives. Now for each one, don't ask who pays for it. Ask who could say yes or no to an agent connecting to it, and then defend the answer.

Almost anyone can build a prototype now. A finance analyst can wire together a workflow. A sales ops person can create a deal-review assistant. A marketer can build a campaign triage agent. The moment it starts coming together, though, it usually asks for production access: CRM, warehouse, ticketing, email, document store. That is where a personal experiment becomes an enterprise decision. The builder can be anyone. Approval needs a name.

In practice, people get stuck on tool two or three. The answer is often "I'm not sure anyone owns that," or "three people would all claim they do." Zylo's 2026 numbers put the average company at 305 SaaS applications, and 46% of licenses sit unused, about $19.8 million in annual waste. Someone signed every contract. Far fewer can answer a hard question about the tool on short notice.

For years that gap was survivable, even boring. Tools accumulated, nobody fully owned half of them, and the org limped along because people were the integration layer. And to be fair, this isn't always rogue shadow IT. Some companies are designed to be decentralized. Some grew that way through acquisitions, regional teams, business-unit autonomy, and "let the team closest to the work pick the tool." Centralized or decentralized, someone still needs to find the decision path.

A human moving data between two systems is slow, forgiving, and improvises around missing context. If a report looked wrong, someone noticed and fixed it before it reached anyone important. Agents don't give you that buffer. They may validate what you tell them to validate, but they don't inherit the informal judgment people use to work around bad systems.

Simon Willison, who co-created Django and writes closely on AI security, coined a phrase for this last June: the "lethal trifecta." Give a system access to private data, expose it to untrusted content, and let it communicate externally, and an attacker can "easily trick it into accessing your private data and sending it to that attacker." Shared tool access is where security, data quality, and external communication risk all meet. Once a tool is wired to an agent, an unowned tool becomes an operations problem.

We all have seen examples of integrations stop working because they were wired to one person's login, and that person had moved teams. Reconnecting it doesn't fix the behavior, because by then nobody could say what "working" was even supposed to look like. That was already a mess before agents. Now add an agent that acts on that data automatically, on its own schedule, and you get an incident nobody can explain.

The public data points in the same direction. The Cloud Security Alliance's March 2026 survey found that 68% of organizations can't reliably tell AI-agent activity from human activity, and nearly three-quarters said agents often get more access than they need. Microsoft's agent guidance now tells companies to keep a registry that tracks ownership, purpose, platform, and access scope for every agent. That registry is the minimum operating record for something that can act inside the company.

That connects to last month's argument, that your next important AI hire may be an operator rather than an engineer. If that's right, the first job is a map of who can decide. Cloud is the old warning: teams moved faster, then CloudOps and FinOps had to rebuild control after the fact.

So what does ownership actually mean here? I'd boil it down to four questions per tool: who owns the application, who owns the workflow it serves, who owns the data inside it, and who can judge whether an AI integration should exist at all. The hard part comes after that, when the answers come back blank or contested. That is the exercise working.

Two principles to stick with. First, if nobody can say no to an agent connecting to a tool, the answer is no until someone can. That sounds rigid, but it's the only thing that scales when requests arrive faster than committees meet. Second, don't assign owners on paper just to make the map look finished. An owner who doesn't know they own something is worse than a known gap, because the agent still gets approved and nobody knows who to call when it breaks at 2 am.

The obvious pushback is: won't this slow everyone down? It can, if ownership becomes another committee. Aaron Levie, the CEO of Box, has been making the case that enterprise AI is leaving the chat window and becoming agents that use tools, process company data, and execute real work. He is right about that direction. Gartner's May 2026 warning is the other side of the same problem: if every agent is governed the same way, either everything gets blocked or risky agents get treated too casually. So the operating move is a fast yes: someone who owns the decision, knows the scope, can approve access, and knows who gets called when it breaks.

One practical note, because "map your tools" can easily become a project that never starts. Don't try to map all 300 applications. List the ten an agent would plausibly touch first, the CRM, the warehouse, the ticketing system, email, the document store, and answer the four questions for those before your first pilot. Listing the first ten is a Friday afternoon. Resolving the blanks is the work.

The approval flows, governance gates, and cost dashboards many companies will build all assume this map already exists. It mostly doesn't. The operating answer is not permission theater. It is a named decision path. The companies that can answer "who owns this" will move faster with agents because they'll spend less time figuring out who let the thing in.

So, run the test this week. Five tools, sixty seconds. If you get stuck on tool two, you're not behind. You've found the first place to work.

"I cancelled my $10/mo Calendly subscription and vibe coded my own with Fable for $12,000"

📡 The Wire

Washington can now switch off the model you depend on. A U.S. ban on foreign use of Anthropic's top models was broad enough that Anthropic shut them off for everyone rather than split eligibility at runtime. Export control just jumped from chips to named model weights. For CIOs and CISOs, the takeaway is blunt: a model your operations run on can vanish by a regulator's letter, not just an outage. Single-model dependence is now a continuity exposure.

Corporate America starts rationing AI as the bill comes due. After a year of telling employees to use AI freely, big companies are pulling it back. Some hit their annual budget in three months; Uber blew through its agentic-AI budget by March. One analysis found only 18% of advanced coding-token spend ships to real users. For CFOs and COOs, the constraint is shifting from access to disciplined consumption, model routing, and proof that spend becomes shipped work.

Memory is now worth more than oil. AI demand has handed memory-chip makers real pricing power and a combined valuation roughly 22% above the world's three most valuable oil companies. Hyperscalers have already secured about two-thirds of server-DRAM production. For CFOs and COOs, AI cost is no longer just GPUs and tokens. It is becoming a supply-chain line.

OpenAI is coming for the gate, not just the app. Per analyst Ming-Chi Kuo, OpenAI is working with Qualcomm and MediaTek on AI-optimized smartphone processors, with mass production targeted for 2028. The device in your pocket is the gate to AI apps, and OpenAI wants to own it. For CIOs, BYOD and MDM planning may need a third platform alongside iOS and Android, and vendor-lock-in reviews need an interface-layer column.

AI's data-center bill becomes a CFO story. The New York Times reports the AI buildout is pushing tech giants deeper into data-center spending. For CFOs and COOs, AI strategy now carries an infrastructure cost line: capex, power demand, and ROI have to be owned and defended, not assumed.

GaaS: Gaslighting as a Service

🌍 Meanwhile...

AI catches pancreatic cancer years before doctors can. Pancreatic cancer is one of the deadliest because it stays invisible until it's too late: more than 85% of patients are diagnosed after it has spread. Mayo Clinic just published a validation study in Gut on REDMOD, an AI model that reads routine abdominal CT scans (the kind already taken for unrelated reasons) and flags the cancer's signature in a pancreas that looks normal to the human eye. Across nearly 2,000 scans it caught 73% of cancers a median of 16 months before diagnosis, nearly double the rate of specialists reviewing the same images unaided, and it held up across multiple hospitals, scanners, and protocols. A live trial is now testing it in real care. The quietly fitting part: the breakthrough comes from reading data the health system already collects, not from a new scanner or screening program. The cleanest "earn your complexity" you'll find in the wild.

🌙 After Hours

Eden (2024)

Dir. Ron Howard | 129 min | ★★★★★

This one grew on me the more I sat with it. It dramatizes the real Floreana affair: a handful of European idealists who flee to a remote Galápagos island in the 1930s, each carrying a different version of the dream. A philosopher wants to escape civilization and write a new way of living. A German family just wants to survive and raise their son. A self-styled baroness wants to turn the whole thing into a spectacle. What makes it work is how all that idealism quietly dissolves once the characters actually have to live with each other. A microcosm of human society. The philosophies fall away and people circle back to the basics: food, survival, status, self-preservation. A civilized version of animal behavior, which is exactly why it stayed with me.

Middlemarch (1871)

George Eliot | 904 pages | ★★★★☆

This was a project. Nine hundred pages of Victorian England, and the first half was a climb: too many characters, slow to develop. But somewhere around the Bulstrode scandal and Lydgate's financial collapse the threads pulled together and the book found its groove. What stayed with me was the small-town dynamics, how gossip becomes fact and judgments spread without anyone stopping to question them. The prose was excellent once I adjusted to the rhythm. Not a book I'd recommend lightly, you have to earn the payoff, but worth it if you commit.

🎙️ Listen

Prefer to listen? Quanta Bits is also available on Apple Podcasts and Spotify.

How this gets made

I collaborate with Spock, my AI agent. He researches extensively: scanning, filtering, and surfacing what's relevant across my business. I read, listen, and watch what resonates, and decide what matters. I provide direction, we draft together. The editorial judgment is mine. He'd tell you the same. Most logical. 🖖

Reply

Avatar

or to participate

Recommended for you