The Battle for The Agentic Enterprise
Value Capture in the Age of Digital Labor
Introduction
12In The Industrialization of Intelligence3, I argued that AI industry analysis was plagued by “chatbot myopia.” The chatbot was the first widely used application of an LLM, and it certainly put AI on the map for much of the population. Nevertheless, it is one application, and agentic AI will represent a much broader, core application space for AI. The paper also argued that the economic analysis of agentic AI should treat agents as a form of “digital labor” rather than another software wave; many rules of traditional software economics will hold with digital labor, and many will not, so it’s important to utilize an agent-specific framework for analysis.
In this paper, we continue with this analysis and provide a deeper dive into agentic AI, with a particular focus on frontier labs, software incumbents, and AI-native application startups. We focus on the emerging competitive dynamics of the market and the factors that could lead to disruption or opportunity for technology vendors.
Key takeaways from this paper are as follows:
The transition from the chatbot era to the agentic era is underway. The rapid pace of model improvements and the increasing sophistication of harnesses in late 2025 has sparked a frenzy to understand and implement agentic AI. Coding was the first to tip, and other task suites will likely follow suit.
Four competitive levers influence the battle for the AI value pools. Harness dynamism, context capture, distribution/intent leadership, and security/trust will matter more than simple “Labs versus SaaS” comparisons. Companies will need to fill gaps and enhance strengths as the pace of agentic competition increases. This will hasten investments, partnerships and M&A across various company types and verticals.
Agentic AI does indeed have network effects. A classic trap of “chatbot myopia” with AI analysis is that many people look at isolated chatbot usage and proclaim there are no network effects in AI; this is certainly true for chatbots, but it is not necessarily true for agentic AI, which is the primary application space of AI. More agents connected through a common control plane can produce greater horizontal capability, and more agent runs can generate better context capture. The race to capture network effects will quickly transition the AI competitive landscape from a model-and-harness “product” battle to a race for platform dominance.
Frontier labs’ pricing is best understood as an effort to win platform share. The frontier labs are currently optimizing for two opposing factors: “the compute constraint puzzle” and “the platform imperative.” The latter, platform imperative, is likely the greatest source of long-term value, so the labs’ strategic actions can be best viewed through this lens.
The system of record gives incumbents a right to win, but it alone is not sufficient. The system of record is just one component of the context needed to fuel autonomous agents. If used as part of a multi-pronged strategy to capture agentic share, it can be a core stepping stone for capturing customers. On the other hand, if a vendor’s broader agentic strategy is subpar, the vendor’s system of record risks devolving into a passive endpoint for agents.
Startups and smaller incumbents may need to abandon model-agnostic approaches. Pure model agnosticism will become increasingly economically and technically expensive, so smaller vendors not vying for platform leadership will likely converge toward model portfolios with a preferred lab, reducing neutrality over time.
Frontier lab partnership pace to accelerate. Frontier labs will likely focus their partnerships, M&A, and investments on building up their distribution footprints and context-capture mechanisms. These partnerships can be particularly fruitful if the labs help bolster the harness dynamism of the incumbents or AI-natives they partner with.
Incumbents can’t do it alone either. The incumbents will likely focus on harness dynamism and context-capture partnerships, M&A, and investments. Frontier labs likely help solve the harness dynamism challenge for incumbents, while AI-natives will be particularly attractive partners for enhancing context capture.
This paper begins with an update on the current state of play for agentic AI. Thereafter, the focus shifts to a framework for analyzing the competition for agentic AI value capture amongst frontier labs, software incumbents, and AI-native startups. This competitive analysis focuses on the software layer, as an overview of the infrastructure value chain (compute, power, etc.) is best explored in a separate piece.
Where the Takeaways Could Be Wrong
While this paper is intended to provide a framework for agentic AI analysis rather than all the “answers”, it offers some counter-consensus conclusions in critical areas. The framework could be weakened and the conclusions proven wrong if the following factors emerge:
Frontier model differentiation from open-source and local alternatives narrows. If the cost of bleeding-edge models remains elevated and lower-cost, good-enough solutions from outside of the frontier take the lead, the Intelligence Pool shrinks and the time for frontier labs to capture platform dominance narrows.
The implementation gap elongates and disrupts capital flow. Regardless of frontier model capability, the economic diffusion of AI can be disrupted by several factors: compute and infrastructure constraints, greater-than-expected friction in transforming enterprise workflows for agentic AI, security risks without credible technical defenses, or regulatory and governmental constraints that slow adoption.
Harnesses are more malleable to model changes. There are credible efforts by the open-source community and AI natives to develop standards and frameworks to improve model-to-harness fit. If these efforts are sufficient, the harness stickiness factor diminishes, and frontier labs will find it more difficult to build dominant platforms.
Legal, privacy, and labor constraints limit context capture. A large portion of the context required to fuel agent autonomy lives in the minds of human laborers. While there are credible arguments that agents can increase overall human labor productivity and eventually lead to more satisfying work experiences, anecdotes like the recent pushback against employee keystroke and mouse tracking at Meta suggests this argument has not been properly articulated to most humans.
The Start of An Agentic Cambrian Explosion?
“It is hard to communicate how much programming has changed due to AI in the last 2 months: not gradually and over time in the “progress as usual” way, but specifically this last December. There are a number of asterisks but imo coding agents basically didn’t work before December and basically work since - the models have significantly higher quality, long-term coherence and tenacity and they can power through large and long tasks, well past enough that it is extremely disruptive to the default programming workflow.”
Andrej Karpathy, February 20264
In the past six months, the adoption of agentic AI has exploded, and the industry has quickly moved from the era of chatbot myopia to a unified focus on the prospects of digital labor in the enterprise (Figure 1). The pace of transformation has been akin to a phase change, with leaps in model and processor capabilities and sharp improvements in agentic architectures unleashing capabilities that nearly make MIT’s 2025 report on the lack of ROI from generative AI pilots a quaint memory of bygone times5.
To be sure, the majority of the market impact has been on the software engineering vertical with agentic coding agents, and the industry must still cross a challenging implementation gap to achieve notable ROI in other verticals; nevertheless, the prospect of continued step function improvements in model, infrastructure, and agentic harness technologies in 2026 and beyond suggests a framework for understanding the agentic era is critical for business and technology leaders at this important junction.
Figure 1: Agentic Takeoff Spikes Token Consumption in 2026
Passing a Critical Threshold in Model Capabilities
Of the confluence of events that triggered agentic takeoff in 2026, the sharp improvements in frontier model capabilities were most important. Many of the leading models released in late 2025 and early 2026 not only used more advanced GPUs than their predecessors but were also trained on much larger GPU clusters as well. In addition, improvements in post-training methodologies and inference capacity enabled these models to reason for longer periods, iteratively producing better results and agentic outcomes. By utilizing advancements in test-time compute (i.e., chain-of-thought reasoning), models became more capable of verifying their own steps and effectively debugging themselves during inference, thus preventing the compounding errors that previously derailed long-horizon tasks.
Furthermore, while Anthropic chose not to widely release its latest Mythos frontier model due to cybersecurity risks, the same reasoning capabilities allowing it to discover latent cybersecurity vulnerabilities seemed to spill over into other capabilities as well. For instance, Anthropic’s testing on its new BioMysteryBench showed that Mythos Preview could achieve a 30% solve rate on human-difficult bioinformatics problems that humans were not able to solve, which could pave the way for future scientific discoveries around structural biology and molecular profiling6. While the attempted release of the Mythos-class Fable model was reversed by the U.S. government at the time of this report’s writing, it’s clearly only a matter of time before these types of capabilities reach the mainstream (via Anthropic and its competitors).
As discussed in The Industrialization of Intelligence, improved task-length coherence for foundation models is also a critical prerequisite for high-ROI agentic applications. Most of the 2025 agent prototypes failed because the underlying models would inevitably hallucinate, forget critical constraints, or get stuck in endless execution loops for short task lengths.
Data collected by METR (Machine Intelligence Evaluations for Threat Research) and their task-completion time metric have served as a useful benchmark for improvements in this critical metric. This measures the length of a task, defined as the time it would take a skilled human professional to complete it, that an agent can execute autonomously with a 50% and 80% success rates (longer is better). GPT-4 reached an 80% threshold of 53 seconds and a 50% threshold of 4 minutes in 2023; in 2026, Claude Opus 4.6 achieved 1 hour and 10 minutes and 11 hours and 59 minutes on the 80% and 50% thresholds, respectively7. This massive leap enabled real-world completion of tasks and contributed to the spike in agentic coding capabilities.
Then Mythos took it to a new level. In May of 2026, METR published its first tests of Mythos and noted that the model exceeded its task suite limit of 16 hours on the 50% threshold while achieving 3 hours and 6 minutes on the 80% threshold. In other words, Mythos saturated the benchmark at the 50% threshold (Figure 2).
Figure 2: Mythos Broke the METR Task-Length Benchmark at the 50% Threshold
Some research suggests the METR task length estimates may even be conservative when real-world tasks are involved. In fact, Epoch AI noted that current “AI models can complete certain software engineering tasks that are estimated to take humans weeks or longer”8. Task length in agentic coding isn’t directly transferable to other labor tasks, and actual results vary by task verifiability and complexity. With that said, it is reasonable to view task length metrics as a critical leading indicator of agentic capabilities and penetration, and the current trends suggest improvements here are on a sharp exponential.
OpenClaw Shows the Autonomous Power of the “Harness”
“OpenClaw is probably the single most important release of software, you know, probably ever…”
--Jensen Huang, March 5, 20269
OpenClaw first hit the scene in November 2025. The viral release was a wake-up call for the chatbot-focused crowd, technical and non-technical alike. OpenClaw showed that autonomous agents were closer to reality than anyone imagined. OpenClaw’s surprising capabilities and the fact that it was the brainchild of a single developer, Peter Steinberger, were perhaps the most important triggers for bringing the world out of the chatbot myopia that plagued much of 2023-2025. For the first time, it was widely apparent that AI was not just about getting answers but about taking real-world actions. AI was becoming digital labor.
OpenClaw was released as an open-source project, helping to spread the novelty of its harness architecture to thousands of developers worldwide. The architecture was designed to operate as an autonomous, local-first digital assistant with input (i.e., intent) conducted directly through messaging platforms like Telegram, Signal, Slack, etc. The OpenClaw harness guides the model to reason, select specific tools/APIs, execute with the tools, and then produce a deterministic terminal output before making its next move. Perhaps more importantly, OpenClaw’s harness acted as a sophisticated context manager as well; a persistent challenge for 2024 and 2025 era agents was context bloat and context poisoning, and OpenClaw provided a useful template for efficiently managing context and state to keep agents on task.
OpenClaw’s capabilities were surprisingly flexible and robust, and more impressively, it appeared able to operate persistently without human handholding. The “Agent = Harness + Model” architecture of OpenClaw reminds us that a good harness can separate the AI’s reasoning engine from its execution boundaries. This is the essence of the neurosymbolic agentic architecture ideal discussed in The Industrialization of Intelligence. By blending deterministic scaffolding with the reasoning power of probabilistic models, you can mix and match recipes of model creativity and harness control that will eventually carry agentic AI into verticals well beyond software engineering or personal digital assistants.
The Next Wave Could Be Steeper
We’ve yet to see the full scope of improvements from models trained in early 2026, but it’s clear much of the development focused on task-length improvements and reasoning accuracy to further spur agentic progress. Continued technical improvements in infrastructure, such as the context- and agent-centric approach of Nvidia’s Vera Rubin architecture, could very well drive a steeper improvement in model capabilities thereafter. Furthermore, advances in coding agents are now directly impacting model development itself and this could become a self-reinforcing tailwind that becomes increasingly important in 2026 and beyond. Finally, on the harness side of the equation, the laser focus on autonomy and context engineering that followed the OpenClaw frenzy should produce far more capable agents from labs, AI-natives, and software incumbents alike.
Aside from technical factors, the progress on high-ROI implementation in verticals beyond software engineering will be top of mind. While 2026 has certainly started strong for the AI complex, the AI skeptics are right to focus on the timing of realizable ROI in the enterprise. This remains the trillion-dollar question for the industry.
The Pace of Change and “The Implementation Gap”
In The Industrialization of Intelligence, I argued that any bull-vs-bear debate on AI should center on the implementation gap for agentic AI. As with any general-purpose technology, AI’s ultimate value capture will depend on the rate of economic diffusion. This is somewhat divorced from the quality of frontier models. Just as electricity, the printing press, and the internet faced delays in economic impact, AI’s ROI path will be largely determined by the pace of agentic adoption. If compute constraints, technical walls, or old-fashioned enterprise inertia slow the pace of agentic implementation, the ROI of AI will be delayed. On the positive side, this would give incumbents more time to counter potential disruption. On the negative side, the capital spigot for AI model improvements could falter; even if this is a delay rather than a stoppage, it’s a critical factor to watch given the capital intensity of AI.
As a result of the implementation gap and the enormous potential of AI pools of value, it’s reasonable to conclude that the competitive battle in agentic AI will be more intense than in prior technology cycles. The pace of AI development has certainly given companies implicit permission to act boldly. And many will do so. The clear conclusion from the remainder of this paper is that standing still is not an option for any AI strategy.
A Technical Foundation for Agent Economics
“the model alone is no longer the product”
--Greg Brockman X post, May 21, 202610
There are countless diagrams describing agentic architecture, and nearly all of them use unique labels and images; most are also focused on describing the architecture for engineers to build agents, not for economic or strategic analysis. The architecture can be described in a manner that is appropriate for business leaders, but I am refining the approach I have used in the past.
In The Industrialization of Intelligence, I described agentic architecture using the LOCE stack (LLM, Orchestration, Context, and Execution). I discuss many of the same components in this paper, but I expand the analysis to include the intent layer (Figure 3). While “intent” is increasingly discussed across agent frameworks, I treat it here as a distinct layer because its role as a source of competitive advantage (capturing the initiating condition) sits upstream of the harness. An agent cannot operate autonomously without a catalyst. Agents need an initiating condition and a task contract. This is where the Intent Layer becomes the critical front door to agentic AI. The intent layer translates human directives and business logic into structured task contracts that “wake the agent up”. The ability to capture the right intent, route it through a dynamic harness, assemble proprietary context, and reliably execute real-world actions forms the core technical battlefield for agentic AI.
Figure 3: LOCE agentic stack plus Intent
In late 2025 and early 2026, industry analysis increasingly standardized on the “harness” concept to describe the architecture built around LLMs to enable agentic applications, and we think this is a more useful framework for analysis. From an industry analysis perspective, the harness is not necessarily a replacement for the LOCE stack concept; instead, it is the simplified integration of its final three layers. If the LLM is the reasoning engine for an agent (i.e., “the brain”), the harness is the dynamic control layer that packages orchestration, context management, tool execution, guardrails, verification, and observability around the model. The LLM is the probabilistic reasoning core, and the harness is the architecture that turns reasoning into governed action. It routes tasks, retrieves and injects critical context, and it invokes execution tools through APIs, MCP servers, and proprietary connectors.
Figure 4: The Harness-Centered Technical Framework for Business Analysis
All of these components, centered around the harness framework, serve as the foundation for the competitive analysis throughout this report. By categorizing companies by their technical strengths and weaknesses in the agentic stack, the upcoming battlefield for agentic AI leadership can be demystified.
Timing Tipping Points by Task Vertical
“…the future is already here – it’s just not very evenly distributed”
--William Gibson
If there is one dominant market theme in 2026, it’s that every agentic product release from Anthropic targeting a new vertical has sparked consternation among business leaders and investors exposed to that vertical. We’re so early in the ramp of agentic AI that investors seem to be shooting first by trimming terminal growth expectations for any segment that may be at risk of disruption. Nevertheless, as we think through the actual implementation gap between AI model capabilities and real-world agentic capabilities, we believe it makes more sense for business leaders to focus on task-level disruption rather than an industry-wide tilt toward agentic.
Indeed, the implementation gap and continued compute constraints for frontier model inference provide a welcome period for incumbents to develop their defensive and offensive agentic AI strategies. Part of this strategic formulation should focus on tasks that are more conducive to agentic workflows than others. We believe timing when a task or group of tasks is a high-potential target for agentic transformation is based on five factors:
Verifiability of vertical-specific tasks. Highly verifiable tasks provide a rich substrate for designing effective autonomous agents. In many ways, this explains why software coding has shifted so rapidly towards agentic. Much of the importance of verifiability can be explained by academic studies on organizational design well before the rise of AI. In his seminal paper, Organization Design: An Information Processing View, J.R. Galbraith effectively argues that the greater the uncertainty of the task, the greater the amount of information that must be processed during execution11. If a task is well-defined and has minimal uncertainty, it can be preplanned and executed with minimal verification. Workflows in this category were prime targets for legacy RPA solutions and eventually AI workflows, which were the pre-agentic offerings of some leading enterprise software companies in the 2024-2025 era. These same categories, due to high verifiability, are also prime targets for agentic penetration in 2026 and beyond.
Ease of context capture. Another way to measure a task’s suitability for early agentic efforts is how easily you can capture and define the steps required to complete a task, when a task’s flow should deviate from the “normal” path to deal with an unexpected environmental development, and how and when humans use their judgment to achieve optimal outcomes. Most enterprises have yet to capture much of this task-specific context; it doesn’t live in any system of record, and it’s often trapped in the memories of human employees. AI-native startups, frontier labs, and incumbent software leaders will all target this critical pool of data, and some targets are easier than others.
Economic wedge and urgency of automation. Agentic adoption accelerates when the economics of automation become too compelling to ignore. Tasks that depend on high-cost, scarce, or hard-to-scale labor create a natural opening for agentic efficiencies. In these situations, agentic AI provides a way to relieve labor bottlenecks, expand profitable capacity, and enhance margins. Software engineering is a benchmark example: high compensation, recurrent talent scarcity, and realizable value from faster iteration have made coding an unusually attractive early target for agentic deployment.
Regulatory and compliance permissiveness. If a task is part of a heavily regulated vertical and otherwise suitable for agentic transformation, regulatory and compliance friction will likely be the deciding factor limiting agent adoption. Consider medical segments: radiology has long been subject to arguments that AI could more readily identify anomalies in images than humans, yet regulatory dynamics suggest radiologists are unlikely to be replaced by agents anytime soon. Patient skepticism is likely to only fuel this regulatory friction. A similar argument will likely hold for many tasks with high regulatory barriers.
Competitive “FOMO” dynamics. In the current market environment, there is a growing demand for corporate leaders to show efficiencies from AI adoption, and this is not limited to technology verticals. When a vertical reaches a tipping point as measured by any of the factors above, one company making an aggressive move towards agentic will likely be loud about it (on earnings calls, regulatory filings, and at industry events). It’s reasonable to conclude that laggards in these verticals could face investor and board pressure to catch up. This can be a powerful factor that accelerates tipping points once they begin.
While these factors are by no means exhaustive, we believe they can help us define a framework for the pacing of agentic tipping points. Not all factors need to be triggered for agentic transformation to be appealing for corporate leaders, but the more factors that are at play, the more likely a transformation is imminent. With this in mind, we have created the Agentic Tipping Point Scorecard to elucidate this framework further (Figure 5).
Figure 5: A Sample Agentic Tipping Point Analysis
Despite Concerns, Agentic Cost Deflation is Alive and Well
The recent spike in token costs is understandably prompting some concerns among AI skeptics that token expenditures signal an unsustainable trend. Nevertheless, we’re at the very beginning of viable agentic solutions and it’s not surprising that the current demand for bleeding-edge frontier models is increasing in sync with this. Indeed, after months of “Tokenmaxxing”, we’re now seeing the blended cost of a token revert somewhat.
The “expensive tokens” panic misses the fundamental and critical economic reality of compute efficiency and legacy token deflation: labor tasks are not homogeneous, and some will require less-capable models than others. As an example, assume Task 1 (i.e., the first agentic vertical to tip) requires a bleeding-edge, 2026 model frontier for successful task completion, and Task 2 (a future agentic vertical) may require the frontier capabilities of 2027 models, and so on. By 2027, Task 1 will be running on 2026 token equivalents and should enjoy steep cost deflation, and that deflation will accelerate further in the years ahead. Similarly, Task 2 will enjoy that deflation in 2028 and beyond (Figure 10).
The agentic TAM expands as legacy tokens become more cost-efficient. The increase in ROI for an agentic task is baked into the nature of compute deflation and the fact that not all agents will need the latest frontier models. This is potentially muted by rising compute and power constraints in the medium term, but it is reasonable to assume this will be more pronounced at the frontier, not on legacy tokens.
Let’s look at some concrete examples from historical data to add some structure to this concept. GPT-4 launched on March 2023 at a price of $60 per 1mn output tokens. By November 2023, OpenAI announced a more capable version with GPT-4 Turbo, with output token cost declining by 50% to approximately $30 per 1mn output tokens. In May of 2024, OpenAI launched GPT-4o and matched Turbo’s text and code capability at a higher speed for half the cost, or approximately $15 per 1mn output tokens: in a little over a year, the cost for similar token capability declined by 75% (and the tokens were faster, had higher rate limits, etc.). Push this example forward, and you begin to see the 90%-plus token deflation curve that we have seen since the inception of gen AI.
Figure 6: Token Deflation Is a Task-Specific Phenomenon

In addition to inherent token cost deflation, enterprises and labs will likely adopt more sophisticated agentic harnesses that can intelligently route complex components of tasks to frontier tokens and less complex components to legacy tokens (i.e., LLM cascading or router architectures), further capitalizing on commoditizing legacy tiers (this can also be done with models within the same frontier lab). There is also more work to be done on how efficiently different models consume reasoning tokens for agentic tasks; in fact, the previously cited paper, “How Do AI Agents Spend Your Money? Analyzing and Predicting Token Consumption in Agentic Coding Tasks,” noted that Kimi-K2 and Claude-Sonnet-4.5 consume an average of 1.5 million more tokens than GPT-5 on the same tasks.
While we’ve centered our discussion on tokens as the key cost input for agents, it’s important to recognize that token ROI is more properly assessed as CPSO (cost per successful outcome), which was discussed in The Industrialization of Intelligence. In addition to overall token costs for a task, this brings in the cost of the harness. The harness consists of traditional software that will likely see its costs decline as competitive intensity and algorithmic improvements increase. There is also a cost element for human oversight, but that component is clearly deflationary as agents become more autonomous at a task. We further refine this metric later in this paper.
The bottom line is that any skeptical case against agentic AI based solely on an “expensive tokens” thesis is bound to be short-lived. Compute and power constraints can mute declines at certain tiers, but the AI version of Moore’s Law remains intact over the long run. The token inflation we saw in aggregate pricing metrics in 2026 is not a sign that deflation is breaking; rather, it’s a sign we are just entering the agentic age, and this is pushing a mix shift towards the capacity-constrained frontier as we move from the previous, chatbot-centered industry paradigm.
The Great Value Capture Debate
A year ago, most AI industry analysis centered on myopic chatbot-centered frameworks, but the explosion of agentic capabilities since then has broadened the aperture of debate. This is a debate about the introduction of digital labor and the economic ramifications of broad disruption. We’re still early in this process, so it’s not surprising that most discussions around the impact of AI on the enterprise have centered on the following assertions by different camps:
“Tokens are fungible, so the frontier labs run capital-intensive, commodity businesses.”
“The labs are going to take over all of enterprise software (i.e., ‘The SaaSpocalypse’).”
“The software incumbents are safe because they own the system of record.”
“AI-native startups can own the context graph, so they will take over the enterprise with compounding moats.”
“AI-native startups are one frontier lab announcement away from demise.”
To be fair to the purveyors of these statements, they are each reasonable assertions depending upon which data points or companies you focus on. This broad array of incompatible thematics is not surprising at the early stage of major technology disruption, as resilient analytical frameworks have yet to form.
The remainder of this paper attempts to provide a more durable framework for understanding where value will accrue and where disruption may occur during the rise of agentic AI. And perhaps more importantly, the paper also attempts to define the levers companies can pull and the gaps they must fill to end up on the right side of the value capture equation. The framework is certainly more complex than a one-liner, but hopefully it’s more rewarding for readers as well.
The Three Pools of Value in Agentic AI
As models become more capable and harnesses become increasingly sophisticated, agentic AI can automate more tasks with greater autonomy. The core argument in The Industrialization of Intelligence was that this autonomy allows agents to move beyond the concept of software as a tool, towards AI as digital labor. As the paper also discussed, any TAM construct for agentic AI is best derived from the global labor TAM. For digital AI, this is the knowledge-worker TAM, and for physical AI (robotics) this is physical labor. We focus on digital AI in this paper.
Some labor will be automated and some will be displaced. Optimistically, I believe it’s reasonable to conclude the productivity enhancements from AI will drive deflationary growth via significant productivity enhancements. As with prior technology and industrial waves, this productivity improvement should lead to new and more rewarding jobs for humans, and hopefully an overall better quality of life.
Amidst this transition, the providers of this digital labor will capture a significant amount of economic value, and we believe this value will be categorized into three pools:
The Intelligence Pool. This is the home of foundation models that provide the probabilistic reasoning and decision-making core of agents, and today this is predominately about LLMs. There are no agents without foundation models, and the adoption of agents for increasingly complex tasks will depend upon increasingly capable models. This capability is monetized via tokens, but competition and capital intensity are severe. The competition for this pool will be between frontier lab providers, and the primary threats to this pool are open-source models, inference compute constraints, and regulatory/geopolitical externalities.
The Platform Pool. If enterprises are employing armies of digital agents, there will need to be a control point for all of this agentic work. This is fundamentally about controlling the permissioned path from intent to action. The control point is needed for routing intent, approving agent access, deciding which model is available for agents, metering usage, enforcing policy, auditing agent outcomes, and a host of other responsibilities. The control point serves as the platform for a wide variety of agents. The platform owner need not provide every vertical agent in the enterprise. In fact, a healthy platform would foster a large and valuable ecosystem of third-party agent vendors and infrastructure specialists. The primary competitors for the platform pool are likely the frontier labs and the large software incumbents (including hyperscalers).
The Agent Pool. Agentic AI platform companies, like any technology platform in the past, will capture certain agentic verticals for themselves, but they will also leave many verticals and specialized infrastructure categories to third parties. When Microsoft won the PC platform war, it captured some application segments for itself, but it also promoted a vibrant ecosystem by enabling millions of developers to capture an even larger share of the Windows application industry. Agentic AI will likely evolve in a way that is different but will rhyme. The frontier labs, software incumbents, and AI-native startups will all battle for pieces of this ecosystem; and we think this will be a particularly attractive target for smaller incumbents and startups with a particular vertical expertise. On the infrastructure side of the equation, there will be a host of startups attempting to capture critical aspects of cybersecurity (particularly inference and agentic security specialists), execution layer frameworks, and context capture mechanisms.
To be clear, these are economic pools of opportunity, not a segmentation of company types. Companies will compete for these pools, and many will capture portions of each. Many will also fall behind and suffer disruption.
Network Effects in Agentic AI
A key determination of the potential value capture for a digital platform is whether the platform creates and nurtures network effects, as network effects themselves provide stickiness and allow platforms to penetrate a broader surface of economic activity.12 A classic trap of “chatbot myopia” with AI analysis is there are still very reputable analysts looking at chatbots and proclaiming there are no network effects in AI; this is certainly true for chatbots, but it is definitively not true for agentic AI, which is the primary application space of AI.
Horizontal, agent-to-agent connectivity can produce novel and emergent capabilities with agentic systems, and as harnesses are deeply integrated into enterprise workflows, the harness owners are seeking to capitalize on the horizontal benefits of agent-to-agent cooperation. This, after all, is one of the best ways to demonstrate the unique ROI potential of AI adoption. In addition, agent-to-agent connectivity and cooperation produces valuable decision-trace and workflow context that feeds into the all-important context capture mechanism for agentic. The bottom line is that an agentic AI platform supporting more agents will have a compounding competitive advantage versus platforms supporting fewer agents.
Real-world examples are already emerging. Google’s A2A protocol explicitly aims to let agents “communicate with each other, securely exchange information, and coordinate actions” across enterprise platforms, with support from Salesforce, SAP, ServiceNow, Workday, Atlassian, Box, PayPal, and others. ServiceNow is productizing this same logic through an AI Agent Orchestrator that can coordinate teams of specialized agents across departmental workflows. Meanwhile, Salesforce is positioning Slack as an “agentic OS,” where employees and agents can search, collaborate, and act across enterprise data, apps and workflows.
More connectivity between agents will drive more overall value and efficiency for the enterprise; therefore, the larger the economic footprint of one vendor’s agentic platform, the larger the network effects. This alone is a critical factor for any analytical framework, as it points to the emergence of powerful platform economics as agentic AI matures.
Are Frontier Labs Heading for Commoditization or Platform Dominance?
“…the way I would think about it is most of what we’re building is platform and we think that there’s so many examples of where a platform can accrue a lot of value, but the customers who are building on that platform actually accrue even more value.”
--Krishna Rao, Anthropic CFO May 13, 202613
The steady and persistent decline in token costs certainly paints a picture of the commoditization of the average LLM token. This is driven by a diverse group of model providers, particularly open-source options, and diminishing differentiation amongst vendors peddling legacy tokens. Furthermore, this is a capital-intensive sector, so over the long run we would expect to see cyclical supply-and-demand imbalances that affect average token prices broadly. Finally, if the agentic implementation gap proves more complex than expected, ROI delays could tighten the capital spigot and constrain agentic adoption.
With that said, this does not mean frontier labs themselves are beholden to commodity economics across their business lines. Instead, with the rise of agentic AI, certain factors could allow frontier labs to evolve into agentic platform vendors; if this occurs, the biggest question is whether it becomes a fragmented market with many platform options (competing frontier labs and incumbents) or tilts towards a winner-take-most outcome. In the latter scenario, the winning AI lab will not only capture a piece of the platform value pool, but also simultaneously protect its margin in the intelligence pool.
Figure 7: The Evolution of Frontier Lab Economics
The agentic harness is brittle across models
“The system prompt you spent weeks on? It’s not a specification. It’s a negotiation artifact, the residue of back-and-forth between your intentions and one specific model’s quirks.”
--Krystian Safjan – April 8, 202614
Adjusting a harness for a new model is a complicated and painful process. We believe the inherent stickiness of agentic platforms largely comes from the differing training regimens, post-training alignment, and even infrastructure choices of the frontier labs.
The challenges of modifying a harness for a new model are also likely to be a fundamental hurdle to agentic adoption, and thus a core component of the agentic AI implementation gap. Nevertheless, it can be argued that the model providers themselves are best suited to ease this friction with each model they release, both directly with enterprise customers and via partnerships with incumbent and AI-native agentic vendors. The model provider understands the intricacies of the pre-training corpus and the behavioral changes observed during post-training, and it’s difficult for any third party to match this critical knowledge shortly after a model’s release.
This, however, does not eliminate the friction of adjusting a harness for cross-model differences between frontier labs: this is perhaps the most powerful driver of platform power accumulation for the frontier labs over time, as it provides a mechanism for growing switching costs. This is also the fulcrum point that large software incumbents will seek to weaken.
For instance, prompt construction is a key component of agentic harnesses. These are not human-like conversation snippets; they are effectively compiled artifacts that target the specific runtime behavior of a specific model and model family. Prompts that inject determinism and reliability into a specific model may cage the performance of another model. This can be catastrophic if an enterprise is dependent on agent performance and stability for critical business functions, and it can be potentially more dangerous in government and military use cases.
In addition, different models often require different context management strategies. Each frontier lab has its own memory management philosophy, and the agent harness must be adjusted accordingly. This may be simple for a single agent, but it can quickly become unruly in a multi-agent system spanning a large enterprise. Finally, each frontier lab relies on different tokenizers and proprietary prompt-caching architectures, meaning a cost-effective, low-latency context strategy on one lab’s model may be prohibitively expensive or slow on another.
Figure 8: Harness-Model Fit is an Underappreciated Component of Agentic AI
These migration challenges also occur within models from the same frontier lab. For this reason, you’ll see model providers provide hosted tools, state management, and cache controls to make intra-lab model changes easier. But this won’t work as well across labs.
The race to hire FDEs, build vertical-optimized harnesses, and leverage context advantages to gain a first-mover advantage on agentic deployments is a rational economic response to a technology that is inherently sticky (i.e., has high “switching costs”). Capture the agentic harness standards, and you’ll capture the profit pool.
This harness stickiness can be a critical factor giving frontier labs platform power, so it’s natural to see software incumbents and AI-native startups build agentic architectures that are “model agnostic.” As we discuss later in this paper, this may be easier said than done over the long run. There will also be efforts by the open-source community and startups to add abstraction layers, but this potentially creates a lowest-common-denominator harness, potentially sacrificing both determinism and capability.
The “red queen effect” and the AI ROI loop
Beyond the demand-side stickiness of harnesses, supply-side competitive dynamics also push the labs toward platform dynamics. The perpetual leapfrogging between the top frontier labs for model supremacy has been a hallmark of the industry, particularly throughout 2025. This has also been a common reference point for the argument that the LLM industry was trending towards a capital-intensive, commodity structure.
In “The Economics of Digital Intelligence Capital: Endogenous Depreciation and the Structural Jevons Paradox”, economists from The Chinese University of Hong Kong and the University of Macau effectively argue the opposite conclusion.15 They note that because inference demand depends on the capability of frontier models, a leading innovation by one frontier lab “endogenously depreciates the economic value of rivals’ existing capital.” This generates a perpetual, fierce, and expensive battle for capability leadership that the economists term the “Red Queen Effect.”
The fact that agentic capabilities currently demand frontier-level models further magnifies this competitive intensity between labs. Couple this with the switching costs and data flywheel effects of a larger agentic installed base, and it becomes clear that the ROI on capital-intensive LLMs is highly dependent on bleeding-edge innovation.
This produces a powerful loop: the leading frontier lab can generate more ROI from the application space, which makes it easier for the leading frontier lab to raise more capital; and more capital, in turn, makes it easier to train and ship the next leading model. This is a primary driver of potential winner-take-all dynamics.
RSI, whether mythical or not, would push platform dominance into hyperdrive
“This year, the automation of AI research and engineering will begin in earnest. In addition to creating at least a step-change improvement in AI progress from its already rapid pace, this could change the dynamics of AI competition, alter AI geopolitics, and much more.”
--Dean Ball, February 5, 202616
The concept of RSI (recursive self-improvement) in AI is that AI models (via research and coding agents) can eventually be used to autonomously produce a new, improved AI model. Then the improved AI model could allow more powerful agents to produce an even better version, and so on. The sci-fi-like interpretation of this is that RSI could allow a fast take-off scenario where model improvement would enter a rapid recursive loop, surpassing AGI thresholds. It’s best to leave that part of the analysis to AI researchers, but for business and finance leaders, the concept of RSI should be viewed as a way for foundation models to improve at a far more rapid pace than we have seen to date.
If each lab can enjoy a version of RSI roughly at the same time, this rate of improvement would hold across a diverse set of models. If one lab were to achieve it well before others, then the Red Queen Effect could produce a winner-take-all scenario. It’s no wonder the labs each focused their first serious agentic efforts on software development. Autonomous AI researchers are explicitly on the roadmap for each frontier model provider, so it shouldn’t be dismissed. Regardless of whether there is a winner-take-all dynamic from RSI, the pace of improvement would certainly amplify the platform imperatives of the labs and weaken the efforts of large software incumbents.
Frontier token pricing is a balance of supply constraints and the platform imperative
As discussed earlier, like-for-like token pricing will likely continue to trend downward at a rapid clip, even as frontier-level tokens exhibit a far more muted decline. This resembles commodity and cyclical economics on the surface, but the long-term dynamics of the space can best be understood as a battle for platform dominance (Figure 13).
Figure 9: Labs are Optimizing Between Two Opposing Factors for Pricing
The frontier labs are currently optimizing for two opposing factors: “the compute constraint puzzle” and “the platform imperative.” First, frontier labs are, at present, definitively compute and resource constrained; they can’t supply enough tokens to meet demand, and increasing token supply is enormously capital intensive. Second, the frontier labs are clearly approaching the agentic application space with a platform approach; they are supplying the core resource (tokens) to agentic vendors, and they are choosing to be agentic vendors in certain verticals themselves. The latter factor, the platform imperative, is likely the greatest source of long-term value so the strategic actions of the labs can be best viewed through this lens.
Overall, it’s still early and it is difficult to know where the labs will land on the commodity-to-platform spectrum. Part of this depends on how the labs do versus the software incumbents in this battle.
Figure 10: OpenAI’s Frontier Program and The Platform Ambitions of Labs17
It’s worth noting the platform imperative also diminishes the rationality of the “labs will eat all AI-native startups” concern. Given the importance of a healthy and diverse ecosystem for any platform vendor, we expect the labs to seek to dominate some agentic verticals, but not all. Furthermore, we’d expect the labs to continue to produce standardized frameworks that enable agentic vendors to build harnesses optimized for each specific lab’s dominant model characteristics.
Large Enterprise Incumbents are Targeting the Platform Pool as Well
While the frontier labs are racing to transform raw model intelligence into defensible and sticky platforms, the titans of enterprise software are executing a forceful counter-maneuver. Their vector of attack is to leverage installed systems of record, entrenched workflow engines, massive distribution, and institutional trust to forge vertical-spanning enterprise control planes.
There is a version of this battle in which the platform stakes are zero-sum. This is the “SaaSpocalypse” debate, but with more nuance. If the frontier labs control the platform pool, the SaaS and system-of-record behemoths are relegated to devalued endpoints, legacy databases, and compliance repositories that are summoned only when a lab-controlled platform needs facts for an agent. In contrast, if the megacap incumbents can capture the platform pool, they can dictate which agents are triggered, which can act, and which frontier models will offer the most cost-effective path to completion.
As this competition unfolds, the fate of “data gravity” and the system of record as a moat is at stake. The incumbents can leverage their strengths to fill out the components of the context layer on top of their powerful systems of record, or the system of record will become merely a passive component of a context engine. The question is not whether proprietary data remains valuable; it’s more a question of whether the incumbents can become the tollbooth and switchboard between human intent and agentic execution.
The control-plane strategy: the deterministic adult in the room
When a CEO tells a CIO to adopt an enterprise-wide agentic strategy before the next earnings call, the CIO’s antidote to panic is to leverage trusted relationships and existing software pipes that the incumbents can provide. Identity management, sandboxing, kill switches, observability, evals, and verification are not optional; there needs to be a deterministic layer of defense against probabilistic systems taking incorrect real-world actions. Most incumbents, with the exception of vendors like Google, are not battling it out for frontier-model dominance; they are subordinating probabilistic models to a well-established enterprise governance matrix.
SaaS incumbents have already proven the reliability of their pre-agentic governance, policy, identity, and workflow audit solutions. If they can prove these systems work just as well with agentic AI, even under higher-stakes conditions, they may become the preferred solution. We’re seeing this play out in the public statements from incumbents today. Microsoft describes Agent 365 as “the control plane for AI agents.”18 Meanwhile, Microsoft Foundry Control Plane emphasizes centralized management and observability for distributed agents, including inventory, health monitoring, and lifecycle operations.
ServiceNow is focused on its AI Control Tower, which is vendor-agnostic, highly scalable, and designed to inventory AI agents, models, and MCP servers from first and third parties. It also tracks identity, access, exposure, security posture, least-privilege enforcement, and prompt-injection blocking.19 Similarly, Salesforce is positioning its Einstein Trust Layer as the deterministic boundary for its Agentforce ecosystem, guaranteeing toxicity scoring and strict adherence to CRM access controls before an agent executes a task.
Beneath the application layer, the major cloud hyperscalers are building a similar strategy with an infrastructure focus. AWS is leveraging Bedrock as the central control point, and introduced Guardrails which allows enterprises to define strict, deterministic policies that evaluate inputs and outputs to block harmful actions and redact sensitive information before any APIs are invoked.20 Finally, Google is leveraging its privileged position as both incumbent and frontier model developer with its Gemini Enterprise Agent Platform, offering a full stack approach for creating and managing agents.21
Workflow gravity and system of record as launch points
Throughout the history of modern technology, it’s been unwise to underestimate the importance of the system of record controlled by incumbent software vendors. Customer records live in the CRM, employee information lives in HRIS, financial records are in the ERP, tickets live in ITSM, etc. This is canonical data that enterprises cannot live without. Furthermore, the system of record also allows the vendors to permeate the write path. Procurement workflows live in sourcing platforms, and collaboration happens across Teams, Slack, GitHub, ServiceNow, and Salesforce.
The challenge with agentic AI is that “data gravity” is giving way to “context gravity.” If an agent is going to produce digital labor, it needs more than just the start and end state of a task from the system of record. It needs the decision traces, workflow context, and tacit expert knowledge that usually sit in the mind of a seasoned human worker or emerge from a water-cooler conversation amongst coworkers. The system of record is at risk of becoming just one static layer of required context, while the other layers may provide compounding value as agents “learn on the job.”
Nevertheless, the system of record and the control of entrenched workflows remain a very important launch point in the early stages of agentic AI’s ramp. This early advantage is amplified by the fact that frontier labs have yet to produce scalable context moats or widespread first-party agent adoption beyond coding; presumably, the rush of FDEs and PE-backed agentic AI portfolio companies will be the first chance to gather this context during agent runtime. The incumbents have a narrow edge here, and we’d expect to see them capitalize on it.
Distribution inertia as a capture mechanism
The broad enterprise distribution of large software incumbents is also a critical advantage in the early days of these platform wars. Incumbents can bundle agent solutions with their existing, trusted offerings; reducing implementation friction by eliminating new vendor risk and making agentic functionality feel like an extension of the existing platform.
This bundling and distribution advantage is also an asset incumbents can utilize to capture the agentic intent layer, where user and enterprise commands are expressed. By leveraging existing workflow UI and gently transitioning this toward agent-first workflows, the incumbents can partially fend off the frontier labs and maintain control of new, agentic workflows that emerge.
The large incumbent advantage centers on model agnosticism
Despite the brittle nature of harness-model fit that is discussed throughout this paper, the largest software incumbents are aggressively pushing a model-agnostic approach for their platforms. This is the most interesting element of the coming platform wars; if frontier labs can maintain an advantage in refining agentic harnesses for new model releases, software incumbents will always face the pressure to partner more closely with one frontier lab. This immediately tilts the platform moat back towards the labs.
Nevertheless, if incumbents can leverage their specific domain expertise on enterprise workflows to quickly refine their harnesses for new models across multiple frontier labs, the labs’ harness advantage can be muted. We dig more deeply into this all-important competitive lever later in this paper.
Agentic Platform Leadership Depends on a Diverse and Competitive Ecosystem
“To survive and prosper, a keystone [platform vendor] needs to increase the resilience and diversity of the ecosystem.”
Marco Iansiti and Roy Levien, The Keystone Advantage, 200422
One of the most virulent and analytically weak extremes of the “SaaSpocalypse” debate is that the frontier labs “will just take over all software verticals.” Not only is this hyperbole unhelpful to business leaders, but it is also deeply and fundamentally ill-conceived. An examination of foundational platform economics, historical industry cycles, and first principles of healthy ecosystems reveals the truth to be far more nuanced; in fact, it becomes clear that a healthy ecosystem of heterogeneous agentic vendors, including software incumbents, AI-natives, and frontier labs, actually maximizes the economic pie for all contender types.
The inertial constraints of enterprise deployment, the necessity of specialized domain knowledge, and the compounding diseconomies of scope render absolute agentic vertical domination by frontier labs mathematically and operationally impossible. Instead, we view frontier labs and incumbents as companies vying for platform leadership as the leading “keystone” in the agentic enterprise, and the connective tissue for the economics of this platform leadership is token sales via an API and the harnesses that enable agentic autonomy. Everything else that forms the agentic AI ecosystem in the coming years will be downstream from that simple baseline.
The competition in agentic AI will certainly be intense, and we explore a framework for these competitive dynamics in the remainder of this paper. Furthermore, the labs will most certainly choose certain verticals they want to dominate, and by consequence, incumbents and natives may lose in these segments. Nevertheless, I believe the apparent paradox of frontier labs supporting and encouraging incumbents and AI-natives to succeed across many other verticals will eventually prove to be the most economically rational outcome for the labs themselves.
Deep Dive on Agentic Competitive Levers
Even if the frontier labs or large software incumbents evolve into dominant enterprise agent platforms, there will be a fierce battle between AI-native startups, software incumbents, and the frontier labs for primacy in each agentic task space and vertical below the platform value pool.
In this section, we will discuss the four key levers that we believe have the most impact on the competitive dynamics of enterprise agentic AI across the intelligence, platform, and agent pools:
Lever 1: Harness Dynamism. We believe the friction of designing a harness that can properly evolve with changes in frontier models and the differences between different model families is more pronounced than most have appreciated to date. If this remains true, it will have profound implications for the competitive dynamics across agentic AI.
Lever 2: Context Capture to Fuel Autonomy. The system of record is important for agentic functionality, but it is just one component of a multi-layered context pool that is required for successful, high-ROI agents. The vendors that can most efficiently capture and control this context will have a significant competitive advantage in agentic AI.
Lever 3: Distribution and the Intent Layer. It appears to be widely appreciated that distribution is a key source of competitive strength for any new technology wave. But in agentic AI, distribution, while also capturing the intent layer, is more important. With agentic AI stripping away legacy application user interfaces, vendors that can capture user and enterprise intent most effectively will have greater control over value capture across the agentic enterprise footprint.
Lever 4: Security and Trust. Enterprise security challenges are certainly becoming more severe with the classical cybersecurity risks being uncovered by new frontier models like Mythos. But perhaps more important, a new class of risks is emerging from the adversarial manipulation of agent behaviors and capabilities. The vendors that can best protect against both classical and emerging threat surfaces will have a critical advantage in gaining enterprise trust for agentic solutions.
This competitive framework analyzes the agentic AI landscape through the lens of three vendor types: Frontier Labs (OpenAI, Anthropic, etc.), software incumbents (both vertical and horizontal), and AI-native startups focused on the agent space. This simplification is, by definition, a measure of averages, and it is important to recognize that some companies and verticals won’t fit neatly into our gap-and-opportunity conclusions.
For instance, software incumbents may face risks in the agentic security segment, but some large software vendors have already begun to address this gap. Similarly, AI-natives may have a general distribution weakness relative to larger incumbents and labs, but some individual startups may already have solved this through powerful partnerships. Finally, companies such as Google may cross the boundary of both the incumbent and frontier lab categories, potentially amplifying the strengths inherent in both.
With that said, we believe modeling the agentic landscape with the three company categories we’ve chosen produces the most resilient framework for understanding competitive strategies in the coming years.
Lever 1: Harness Dynamism
“…when a new model lands, it is generally good practice to re-examine a harness, stripping away pieces that are no longer load-bearing to performance and adding new pieces to achieve greater capability that may not have been possible before.”
Prithvi Rajasekaran, Anthropic, “Harness Design for long-running application development,” March 24, 202623
With each model release, you can reliably expect commentary on groundbreaking new capabilities, alongside hot takes on embarrassing weaknesses from skeptics. In 2023, the skeptics pounced on LLMs’ inability to do basic arithmetic, and in 2026 we often see the increasingly famous car wash test (ask an LLM whether it’s more practical to walk or drive to the car wash across the street, and it will often suggest walking). Yet the same models that don’t seem to understand that you need to bring your car to a car wash to have it washed are also driving disruptive pressure on large-cap software stocks and triggering national security concerns over their ability to discover latent cybersecurity vulnerabilities.
This phenomenon is commonly referred to as the “jagged frontier”, as LLM capabilities are jagged in the sense that they are strong in some areas and weak in others. Nevertheless, each model tends to expand the frontier, subsuming prior weaknesses and bringing new, surprising frontier capabilities (Figure 15).24
Figure 11 – The Jagged Frontier of LLMs

A core role of the agentic harness is to inject determinism where necessary to counter some of the jagged weaknesses of probabilistic LLMs. This determinism can come from specific software guardrails or from injected context that keeps the LLM on task. As foundation models become more capable and frontier labs extend the length of time models can stay on task, the nature of the harness naturally changes. While some may argue that harnesses become thinner and thinner as models improve (with a theoretical elimination of the need for harnesses altogether if foundation models were ever to achieve the quasi-mythical goal of ASI), we believe this is likely incorrect. While it may become less important for a harness to “babysit” the probabilistic wanderings of a frontier model over time, the role of deterministic permissions, identity management, security, and context management will likely become more important.
The key message for enterprises is that if the harness remains too static, it can act as an inefficient cage that prevents the agent from capitalizing on the latest improvements in model capabilities. In many cases, a static harness can degrade agent performance with a new model release due to prompt drift, differing context management needs, or slight changes in the model’s tool-calling syntax.
As a result of this all-important component of harnesses, harness engineering is likely to become one of the most important skills for any enterprise seeking to capitalize on the rise of agentic AI. In addition, self-reinforcing moats from proprietary context capture will represent the best defense if harness improvements falter around model releases, giving agentic competitors time to get it right before customers move elsewhere.
Mechanisms for achieving harness leadership
In a world where model capabilities and behaviors will likely change persistently, players that can keep ahead of these changes and dramatically reshape their agentic architectures to maximize the model’s real-world impact will see the most success. Our view on each category of competitors in this race is as follows:
Frontier Labs – the “zero-day” advantage
Inherent Advantage. Frontier labs have an inherent advantage in this respect; after all, a frontier lab should have a better view of its latest model’s jagged capabilities than any third-party, and they can even post-train the model alongside their latest agentic harness architecture. Enterprises without their own frontier models will sometimes find themselves one step behind in agentic capabilities.
Inherent Weakness. The zero-day advantage is not the same as enterprise workflow ownership. Frontier labs will need to avoid tilting towards a horizontal, “one-size fits all” approach with harnesses, or they risk leaving enterprise-specific workflow-control and context-capture opportunities to incumbents and startups.
Software Incumbents – the inertia edge
Inherent Advantage. Enterprise incumbents often own the system of record, deterministic permissions, and the workflow pipes that can be retrofitted for context capture. All of these elements can help inform the most performant harness design. The advantage of avoiding lab lock-in very likely outweighs the capability costs of reduced harness dynamism for most large incumbents at this stage; building resilient harness engineering capabilities to support model agnosticism is a key vector for larger incumbents to become agentic platforms.
Inherent Weakness. With a natural focus on protecting their installed base, incumbents are often anchored to pre-agentic architectures. These legacy architectures were designed around human users, dashboards, seats, and relatively static workflows. As a result, demands for backward compatibility, internal incentives, and pressure to preserve existing seat-based revenue can all act as forces reducing harness dynamism. The model agnosticism capability tax also amplifies this. By preserving neutrality, which in many ways is a rational economic goal, the incumbent may sacrifice peak agentic performance after new model releases.
AI-natives – agility and focus
Inherent Advantage. AI-natives can be extremely agile as they refine their harnesses for each model change, and this agility is further enhanced by the fact that they aren’t burdened by tech debt from the world before gen AI. In addition, they have the advantage of vertical, focused expertise that labs and horizontal incumbents may lack, which can lead to a richer feature set and a deeper understanding of enterprise needs.
Inherent Weakness. As the market evolves, AI-native startups will face pressure from both sides. Frontier labs can bundle reference agents into their platforms, and incumbents can bundle “good enough” agents into existing contracts. If the AI-natives can’t adjust their harnesses fast enough, their solutions can suffer from prompt drift, tool-calling failures, cost surprises, and overall orchestration regressions that force substantial refactoring. Harness dynamism can be expensive in this regard, and it seems likely the AI-natives will increasingly have to focus on one lab’s family of models, rather than model-agnosticism, to find the optimal balance between economics and competitive functionality. While the uncertainty around government restrictions Anthropic’s recent Fable release has led some to suggest model-agnosticism and even open-source model adoption are now even more important, this argument fails to appreciate that all frontier releases may face the same risk, and the regulatory tolerance for future open-source, “Mythos-level” models may also be severely limited.
Lever 2: Capturing the context to fuel agent autonomy
“Agents don’t just need rules. They need access to the decision traces that show how rules were applied in the past, where exceptions were granted, how conflicts were resolved, who approved what, and which precedents actually govern reality.”
--Jaya Gupta and Ashu Garg, Foundation Capital 25
In most analyses of AI’s potential impact on enterprise software today, it’s common to see “proprietary data”, “systems of record” and “context” conflated as similar concepts for defining incumbent moats. This loose conflation can be quite dangerous, and we believe this will become increasingly obvious as agentic systems ramp in 2026. While proprietary historical data is indeed powerful fuel for training large language models, it does not provide the same value for agentic systems. Furthermore, while a system of record that stores proprietary data can serve as a valuable base of truth for domain-specific applications, it is structurally insufficient as the sole source of context for safe and autonomous enterprise agents.
Raw data at rest cannot guide an agent through decision traces, nuanced exceptions, unwritten rules, and historical precedents that govern actual enterprise operations. This is on-the-job “context” naturally accumulated by humans, and the absence of an agentic equivalent can lead to the agentic ROI disappointments that pervaded 2025.
In this section, we provide a more granular view of the context layers than in previously cited analyses. To achieve true autonomy, agents must dynamically retrieve context from four distinct layers in the enterprise hierarchy. And for each source, AI natives, software incumbents, and frontier labs have varying degrees of advantage.
Workflow Context. Much of the “know-how” for completing a task is learned on the job and is part of a human worker’s experience and routine. You won’t find this in any database or manual – it’s often in the worker’s head. The mouse clicks, exceptions, handoffs, Slack messages to make a decision, emails, browser tabs, chance water cooler meetings, undocumented approvals, etc., all matter for agentic tasks. If agents are ever to complete high-level tasks autonomously, this context needs to be captured.
Decision-Trace Context. As agents work, they should capture live data on decision-traces. This must be captured because this is one of the strongest candidates for compounding context, and thereby a critical moat source for agentic vendors. Why was a decision made, what alternatives were considered, who approved of it, and did the decision lead to an optimal outcome? As this data accumulates, the agentic architecture enjoys a type of continuous learning.
Tacit Expert Context. This will be the hardest part of agentic autonomy for most tasks and will likely be heavily supported by humans in the loop for quite some time. Which buyer is a waste of time for a salesperson? What are the subtle signs insurance documentation looks suspicious? Which executive has the political capital to close a deal at a key account? Is a customer truly angry enough to churn or just negotiating? This isn’t knowledge, this is judgment. And it’s often hidden in social memory, prior decision experience, live calls, and informal notes.
System-of-Record Context. This is the canonical data from legacy systems of record, including customer data, employees, products, orders, invoices, tickets, claims, suppliers, contracts, entitlements, and financial data. The importance of the system of record is not eliminated by the shift towards agentic AI, but it becomes merely one component within the broader context hierarchy.
Figure 12: Agentic Context is More Than the System of Record
Capturing “live context” is the central challenge for agentic adoption
Live, workflow-centered context from telemetry and decision traces is harder to capture properly, but its value also compounds with more agent usage. Meanwhile, the system of record is more of a repository for the end state of a workflow, but it usually doesn’t preserve the detailed reasoning path that led to that state. Over time, the system of record alone is important, but workflow and decision trace context can be far more valuable to an agentic AI vendor. In the Industrialization of Intelligence article, I argued that “context may be one of the most important core sources of switching costs as agentic AI is deployed.” The key is to separate context from the “proprietary data” mantra that often permeates analyses of agentic AI moats.
A considerable amount of thought leadership on the importance of context has emerged in recent months, further clarifying and expanding our prior views on the topics. In the following section, I dive deeper into this topic and provide a durable framework for understanding this all-important component of agentic AI.
On December 22, 2025, Jaya Gupta and Ashu Garg from Foundation Capital posted a soon-to-be-viral post on X with their essay entitled, “AI’s trillion-dollar opportunity: Context Graphs.” The context graph framework is a powerful concept that helps us move closer to thinking of agents as digital labor rather than next-generation software tools. The Foundation Capital post was also directly aimed at system-of-record-centered arguments for incumbents.26 Just as humans complete a workflow based on the tricks of the trade they learned on the job or from a brainstorming session next to the water cooler, agents will need access to this type of fuzzy workflow knowledge to reach full autonomy. Much of this knowledge is poorly captured today; it’s scattered across chats, approvals, tickets, and human memory, rather than modeled as first-class, queryable data. And it most certainly doesn’t fit into a rules-based framework that was utilized by the AI workflow agents of 2025 or the legacy RPA systems that preceded them.
The challenge (and opportunity) is that very few companies are fully capturing the context layer for agents. This is changing as companies, large and small, are angling for an edge in capturing this key to agentic leadership, and monitoring this battle for the context graph will be a critical exercise for business leaders and investors in 2026 and beyond.
Figure 13: OpenAI’s In-House Data Agent as a Context Capture Mechanism27
Looking at an example of an early effort towards context capture, earlier this year, OpenAI released an article discussing their in-house data agent, which is a potentially useful framework for capturing live context. We would not be surprised if this, or something similar, evolves into an externally available tool for context capture outside of OpenAI. Most importantly, the company provided a direct nod to the moat-generating power of context capture via Codex: “It’s continuously learning memory system means it also improves with every turn.”
Mechanisms of achieving context leadership
As the battle for the enterprise context graph accelerates, the competitive landscape is stratifying across the three company cohorts. Each comes to the table with a structural bias toward a different slice of the context hierarchy, dictating how they will likely attempt to capture and defend this new moat.
Frontier Labs: ecosystem encirclement
Inherent Advantage: The labs have two advantages in the context capture arena: first, similar to harness dynamism, they own the intelligence layer and they can adjust context management and utilization in a manner that best fits the latest jagged frontier quirks of their newest models; and second, they can leverage the “super app” bundling of coding agents, the browser and computer-use agents to accelerate context capture at the user layer.
Inherent Weakness: The frontier-lab advantage may be broad, but it is not necessarily deep. The most valuable enterprise context often lives inside messy vertical workflows, human-in-the-loop approvals, domain-specific policies, and repeated exception handling. Without being deeply embedded in the orchestration path of a vertical workflow, labs may capture a large amount of activity data but miss high-signal decision traces.
Software Incumbents: the gravitational pull of the system of record
Inherent Advantage: The system-of-record is not sufficient for full agent autonomy, but it remains indispensable. Leading incumbents with ownership of the system-of-record context and entrenched enterprise distribution can enjoy considerable enterprise advantages for transitioning to agentic AI. Instead of ripping and replacing, the incumbents offer a gentler transition as they build broader context-capture mechanisms into their agentic offerings.
Inherent Weakness: The core weakness of incumbents is that systems of record were generally built to store end state, not to capture full process context. This creates an architectural gap. Relational databases, workflow modules, and dashboards have been optimized for human users, compliance records, and reporting; they were not designed for autonomous agents that need to reason over granular decision traces and tacit expert judgment. As value shifts from “data at rest” to “intelligence in motion”, this mismatch becomes critical.
AI-natives: clean-slate context capture
Inherent Advantage: AI-native startups enter with the advantage of a clean slate, enabling them to build purpose-built infrastructure designed to capture live, compounding context without legacy tech debt.28 They are not burdened by legacy schemas, seat-based UI assumptions, dashboard-centric workflows, or relational database architectures designed primarily for human consumption. With vertically focused harnesses, AI-natives can focus on building context graphs in narrow, high-value workflows. Over time, these traces can become searchable, and the AI-native position improves as proprietary context accumulates alongside agent performance.
Inherent Weakness: AI-natives do not begin with canonical, system-of-record data. They are dependent on connecting to incumbent systems for critical end-state data. This is a potential risk, particularly in highly regulated industries. In addition, the context graph only compounds if the startup reaches sufficient workflow volume. A startup that executes a narrow slice of a process without owning the exception paths, approvals, and key decision traces may never build a meaningful context moat; this is the dreaded “LLM wrapper” concept most startups are avoiding at all costs, since it leads to commoditization as labs and incumbents can subsume this functionality.
Lever 3: Distribution and the Intent Layer
“Automation follows instructions. Agentic AI resolves intent.”
--Fulcrum Digital, June 202529
Two of the foundational forces shaping the competitive landscape in agentic AI are the resolution of intent and the surface area of distribution. While intent capture is usually discussed as a technical component of the orchestration layer and distribution is usually framed as an old-fashioned, but critical economic factor, the two become inextricably linked in the world of AI agents. The battle to capture the intent layer is moving beyond software’s traditional seat-selling war into a battle of structural insertion.
The journey from UI to Intent
In the Industrialization of Intelligence, I discussed how agentic AI slowly unwinds the tight coupling between the UI and an underlying application’s functionality. I also noted how this “means the center of gravity for innovation (and commercial success) has less to do with how a human points and clicks in your application and now shifts to designing applications that agents will ‘choose’ to use.” This has profound implications for enterprise software and pushes us to explore “intent” as a core source of value for agentic AI.
In the agentic era, humans’ most important job is directing agents to act. Agentic AI unbundles the expression of need from the execution of a task.30 And the days of navigating complex UIs and switching from system to system may be waning. The orchestration layer of agentic architecture takes a user’s request, disambiguates the context with the LLM, applies business guardrails, and dynamically bundles this into tasks that an agent can execute. It translates probabilistic human language into deterministic tool-calling schemas. A lion’s share of enterprise application value will shift to vendors that capture human or organizational intent.
Figure 14: Agents Change the Application Path from User to Outcome
Run this full course, and it becomes apparent that the intent layer has the potential to become a core component of any control layer over the enterprise ecosystem and disrupt legacy software ontologies through the following critical levers:
Context Capture. The layer that captures intent first gathers the most valuable contextual data: the why behind the activity. Meanwhile, the downstream components only receive the what for the final record (data at rest). The consequence is that previously dominant platforms that once relied on data gravity as a moat can become devalued repositories for systems of action to call upon.
Horizontal Task Reframing. In the Industrialization of Intelligence, I argued that notable functionality improvements can emerge as we move from a traditional application world of vertical features toward one where agents work together to produce horizontal functionality. The intent layer can enable this by collapsing multiple legacy application flows into one. “Onboard John Doe” triggers HR, IT, and finance applications simultaneously, and the individual apps become invisible.
The Invisible UI Penalty. If an agent calls an application via an API, downstream from the intent layer, the human never sees the incumbent’s UI. This destroys the incumbent’s ability to cross-sell or reinforce their brand. Furthermore, as happened with the travel industry at the advent of the internet, the intent layer can devalue the system of record to a lower value endpoint (i.e., Booking.com versus SoR’s like Sabre).
Logic Arbitrage. The intent layer can determine trade-offs, such as speed versus cost, that once filled the time of enterprise software sales executives. If you represent downstream capability, you no longer convince the enterprise buying centers; you need to become attractive to an emotionless agent. The agentic architecture that owns the intent layer is potentially the kingmaker.
Control of the intent layer is inextricably tied to vendor distribution strategies. If a vendor has a powerful distribution footprint but fails to capture the intent layer, the vendor may only be distributing a commoditizing product. On the flip side, it’s extremely difficult to capture the intent layer without a focused agentic distribution strategy.
Distributing Intent
As the enterprise shifts from a software-centered paradigm based on digital “tools” and towards an agentic-centered concept of digital labor, the framework for software distribution also changes. Software distribution will depend less on selling seats or licenses and more on the concept of structural insertion.
Structural insertion is the process of integrating AI agents into the critical path of an organization’s workflows, data pipelines, and decision-making apparatus. It’s the critical vector for that allows user intent, deterministic guardrails, and canonical data to shape and direct the cognitive workload of an LLM to perform real-world work. From the Industrialization of Intelligence framework, this process is the core to uniting symbolic structure with neural network reasoning to create a neurosymbolic agent.
An agentic vendor that can capture the structural insertion point will be able to implement agents that leverage the underlying data and the operational execution layer of the enterprise. This is the choke point for agentic ROI and, by consequence, the focal point for distributing sticky, high-impact agentic implementations. To further explore and prove this concept, it’s useful to view it through the prism of the current distribution strategy for the key players in the agentic landscape and how these strategies may evolve.
Frontier Labs – capital as intent distribution
In many ways, the distribution strategies announced by the frontier labs in late 2025 and early 2026 can be viewed as a fast-paced attempt to replicate the massive go-to-market functions that software incumbents spent decades producing. When viewed through the prism of agentic intent, however, it becomes clear that there is also a core technical vector the labs are attempting to exploit with these strategies; this vector explicitly leverages their ownership of the all-important intelligence layer.
Software Incumbents – data gravity and bundling
The incumbents are wisely leveraging their control over their systems of record and large installed bases to gently transition their customers from tool users to digital labor consumers. Furthermore, bundling agentic capabilities with trusted, legacy, deterministic licenses relieves the “bleeding edge headache” many seasoned IT buyers face.
AI-Natives – “services-as-software” outcomes
The AI-natives are attempting to bypass the “trust tax” with a focus on real-world outcomes, a strategy that leading VCs are conceptualizing as “services-as-software” .31 If an AI-native can start their sales motion by guaranteeing the outcome, the hope is the enterprise procurement team will stop evaluating them as risky software installations and start evaluating them as variable-cost digital labor.
In all these cases, the common goal is to insert agentic architecture into labor workflows. In many cases, this requires complex restructuring of workflow and organizational structures. This is the most challenging phase of navigating the agentic implementation gap, and competitive forces are pushing each agentic player to move at a speed largely unprecedented in historical enterprise technology adoption.
Frontier labs’ agentic pincer movement – capital, FDEs, and consumerization
The frontier labs appear to be taking a multi-pronged approach to agentic distribution, and the approaches of OpenAI and Anthropic in particular offer an increasingly clear picture of this approach. While Google is also a frontier lab from a model performance perspective, we tend to believe its distribution approach (and that of other hyperscalers) is best analyzed as adjacent to the incumbent strategies. With that said, the overall approach of frontier labs in the enterprise appears to be coalescing around a top-down and bottom-up pincer approach. More specifically, we define the top-down approach as the “Capital-as-Distribution” approach, and the bottom-up approach as the “Consumerization of Enterprise Approach.”
Figure 15: The Frontier Labs’ Pincer Strategy of Distribution
Top-Down: capital-as-distribution approach
To move beyond chatbots and coding agents in the enterprise, frontier labs have increasingly used their massive capital arsenal to build highly targeted go-to-market strategies. By partnering with PE firms and other alternative asset managers, both OpenAI and Anthropic have begun to quickly build implementation teams and a captive customer base (PE portfolio companies).
OpenAI finalized its first foray with this strategy in May 2026 with a $10bn joint venture with investors such as TPG, Bain Capital, Advent International, and Brookfield Asset Management. Anthropic announced it was partnering with Blackstone, Hellman & Friedman, Goldman Sachs Group Inc., and several other firms to form its deployment entity.32 OpenAI specifically noted the launch of the OpenAI Deployment Company with FDEs to “work closely with business leaders, operators, and frontline teams to identify where AI can make the biggest impact, redesign organizational infrastructure and critical workflows around it, and turn those gains into durable systems.”33
The key to these partnerships is that rapid time-to-market is coordinated with the differing self-interests of the JV participants: the frontier labs secure rapid and frictionless structural insertion across a large number of companies, while the investment firms can leverage agentic AI to aggressively drive operational efficiencies, labor productivity, and ideally boost EBITDA within their exit timelines.
Services firms and FDEs
Alongside the asset manager partnerships, Reuters recently reported that OpenAI and Anthropic ventures teams are in talks to acquire AI services firms.34 Reuters notes the goal is to capture “hundreds of engineers and consultants to help companies put their AI models to work….” As further evidence of this trend, OpenAI announced the acquisition of Tomoro, an AI consulting and engineering firm, with its May 11, 2026, announcement of the OpenAI Deployment Company.
The core of these strategies centers on an increasingly prized employee: the forward-deployed engineer (FDE). A role pioneered by Palantir for complex government and corporate contracts, FDEs operate as implementation special forces, deployed onsite at clients to navigate complex, ambiguous, and politically fraught enterprise environments. In the first ten months of 2025, FDE job listings increased by a staggering 1,165% year-on-year, and it wouldn’t be surprising to see this curve trend exponential in 2026 and 2027.35 The FDE embodies a unique go-to-market motion that targets the agentic implementation gap by focusing on harness engineering, context capture, and employer-specific safety and compliance guardrails.
FDEs are critical for the early implementation of agentic AI. They effectively hardcode the enterprise’s bespoke and messy intent directly into an agent’s deterministic guardrails. As the bespoke reality of agentic adoption sets in, FDEs provide a manual bridge to intent and context capture before it can be fully automated into agentic harnesses.
Bottom Up: consumerization of enterprise
When Apple’s iPhone began to gain momentum in 2008 and 2009, the common refrain from BlackBerry loyalists was that Apple lacked the trust and go-to-market muscle to penetrate the enterprise market. It soon became apparent, however, that increasing consumer obsession with the iPhone led consumers to demand that their employers allow them to use iPhones at work. This began the bottoms-up concept termed the “consumerization of the enterprise,” and without a massive enterprise smartphone salesforce, both Apple and Google were able to nudge legacy incumbents out of the enterprise smartphone market.
A similar concept is occurring with AI in the enterprise, and it is likely the labs will leverage this bottom-up wedge just as much as their top-down initiatives to penetrate the enterprise. Indeed, by establishing consumer-grade launch points that consumer users heavily prefer, the labs can find an early footing in the enterprise and capture the critical layer where intent is initially generated. From here, agentic capabilities can follow.
Often this begins with installing a chatbot and expands from there. For instance, the Wall Street Journal discussed OpenAI’s move to combine the ChatGPT app, its coding agent Codex, and its AI browser Atlas (originating from its “Operator” research initiative) into a desktop “superapp.”36 This move allows OpenAI to leverage its massive ChatGPT installed base and become an agentic surface that can autonomously control a web browser to perform highly complex, multi-step tasks. The key is that the agent is completing tasks while the broader app ecosystem remains stuck on “point-and-click” human UI – they aren’t waiting for the industry to become agent-friendly. They are capturing the intent layer as soon as possible.
Anthropic’s strategy seems to follow a similar thread, but its center of gravity focuses on the brand and installed base momentum of Claude Code. In the first few months of the year, Anthropic has rapidly launched Channels, Cowork, and Claude Marketplace. Anthropic even implemented and then walked back a ban on third-party harnesses like OpenClaw; this was a brief, messy episode that nonetheless signals Anthropic’s efforts to police the ecosystem boundaries around Cowork and implement an organized platform strategy.37
As frontier labs begin seeding installation points that can act as personal assistants for individual users, they are simultaneously creating an intent surface within the enterprise. If the labs can own the agentic command bar on users’ OS, they can own the pipe through which all other software must flow. When combined with the FDE strategies for crossing the agentic implementation gap, they are executing a pincer strategy that potentially overcomes the typical inertia of enterprise technology shifts.
Software incumbents – the inertia of data gravity and bundling
Software incumbents have a critical advantage in distribution and intent capture that leverages both earned trust and inertia. The inertia, particularly for their active installed base, leverages the power of owning the system of record and having the ability to bundle agentic capabilities into existing seat or enterprise licenses.
On the data front, agentic context is far more than the system of record. Still, in regulated, compliance-centric organizations, the system of record serves as a base layer for safety and deterministic reliability. Furthermore, incumbents can leverage the existing SaaS and workflow pipes they control to begin to capture intent surfaces for agent functionality.
The largest incumbents recognize that their data and workflow pipes are enormously sticky. These vendors have a particularly strong ability to bundle agent management and governance into platforms, becoming agent marketplaces and a centralized control plane for agentic via agent access standards like MCP (model context protocol). Enterprise salesforces can sell customers on a gentle and safe transition to agentic, without the pain of rip-and-replace risks. For instance, Google (arguably enjoying both benefits of being a frontier model provider and entrenched incumbent) recently announced its intention to become the centralized source and management layer for first-party and third-party agents via the Gemini Enterprise Agent Platform.38 We’ve seen similar “control plane” approaches from the other hyperscaler (i.e., Microsoft) and horizontal SaaS incumbents (i.e., ServiceNow), as they seek to bundle agentic capabilities with their sticky software and compute offerings across large installed bases.
Figure 16: Google’s Gemini Enterprise Agent Platform, April 2026
AI-native startups – if you can’t own the distribution surface, own the outcome
AI-native startups have the agility and focus inherent in all would-be disruptors, but they face a clear disadvantage compared to both frontier labs and software incumbents when it comes to distribution. In addition to lacking a captive installed base, startups face the “trust tax” when selling to large and compliance-sensitive enterprises. This trust tax is exacerbated by many AI-native players that shift substantial liability to customers through their sales contracts. To combat these disadvantages, AI-natives are generally focusing on three disruptor strategies:
The “services-as-software” and outcome-based approach
The almost meme-like proliferation of the services-as-software monicker for agentic AI correctly captures the digital labor construct of the agentic TAM (i.e., the labor and services market dwarfs the software market), and it just so happens to fit very well with the outcome-based distribution and pricing strategy startups are using to penetrate the enterprise market. It’s no wonder the VC complex has been laser-focused on these concepts. By effectively focusing on capturing enterprise intent with clearly priced outcome-based sales approaches, the AI-natives are attempting to bypass the rip-and-replace concerns that provide legacy software with its powerful switching costs.
The services-as-software distribution strategy centers on the “hire an agent” concept for a measurable outcome, which clearly differentiates it from the legacy SaaS per-seat model. While this is often implemented with self-serve models and often with SMB customers as a starting point, some startups like Harvey AI have seen tremendous momentum with larger customers by automating highly verifiable “billable hours” and attaching pricing directly to labor efficiencies.
Mechanisms of achieving distribution and intent layer leadership
In any new technology wave, trust and installed base leadership always confer an advantage on incumbents. Nevertheless, disruption from new players remains possible when the underlying technology changes significantly. The displacement of traditional user interfaces by intent-driven orchestration creates an opening for new control points to emerge above legacy applications. As a result, distribution advantage is no longer solely measured by sales capacity, installed base size, or software bundling. Instead, it is increasingly defined by a vendor’s ability to insert agents into the critical path of work, capture user and organizational intent, and convert that intent into governed execution.
Frontier Labs: the pincer movement
Inherent Advantage: Control of the intelligence layer and visibility into where model capabilities will land next are critical advantages in many respects. The massive capital war chests of the labs and press-amplified brand momentum also give them access to powerful distribution partners, helping them replicate the go-to-market efforts of legacy incumbents. In addition, the labs’ bleeding-edge R&D capabilities afford them the opportunity to capture the intent layer at the chatbot, coding agent, and browser levels.
Inherent Weakness: Through the pincer movement of intent capture and FDE-centered partnerships, the labs are trying to compress decades of enterprise go-to-market maturity into a few years, which creates execution risk. Even with powerful intent capture and marquee partnerships, the labs are still competing against the deep procurement relationships, enterprise trust, and renewal motions that incumbents have already mastered.
Software Incumbents: installed base and data inertia
Inherent Advantage: Software incumbents have already navigated the grueling gauntlet of enterprise compliance, security, and procurement, and have earned enterprise trust as a result. In addition, they often control sticky workflows that can be re-fashioned into intent surfaces for agents. These factors, coupled with a large installed base and relationship-heavy salesforces, make distribution and intent capture an incumbent’s game at the start.
Inherent Weakness: The key risk is that incumbents mistake ownership of the system of record for ownership of the intent layer. If a user expresses intent through a third-party agent and the incumbent application is called only via an API, the incumbent may still retain the final state but lose upstream context, the user relationship, and workflow margin. To lead in the intent layer and amplify inherent distribution advantages, incumbents must evolve from providing applications humans trust to providing the control planes agents depend upon.
AI-natives: selling outcomes and context graphs
Inherent Advantage: With zero legacy tech debt, vertical-focused R&D, and startup agility, it would be a mistake to write off the AI-natives’ distribution strategies. In addition, with no legacy pricing models to protect, they can distribute their offerings with an outcome-based approach. By inserting themselves directly into workflows once performed by labor, they can capture live intent and workflow context from the start. By bypassing risk-averse IT leaders and selling outcomes to business-line leaders, the AI-natives will attempt to eliminate the trust tax completely.
Inherent Weakness: AI startups face the clearest distribution challenges, as is always the case with startups in a new technology wave. While a vertical- and outcomes-based focus can help them build more targeted offerings and capture richer context from a specific workflow, there is also a risk of being too narrow. In many cases, an AI-native’s path to scale will depend on expanding from a narrow outcome into a broader workflow system before an incumbent bundles a “good enough” alternative or a lab builds a native agent for the same task.
Lever 4: Security and Agentic Alignment
“As illustrated in the economic theory and law of agency relationships, the greater the opportunities in delegating work to an agent, the greater the associated risks.”
--Noam Kolt, Notre Dame Law Review, January 202539
This is perhaps the most difficult section to fit into this paper’s structured framework. While the prior three components of the agentic competitive landscape can be utilized across different application classes and verticals, security is complicated by the fact that it also represents its own vertical, with specialists in the incumbent and AI-native camps. Nevertheless, it demands inclusion in any agentic industry framework, if not for the sole reason that the implementation gap for any agentic category cannot be crossed without addressing security and trust. AI not only makes it easier to discover legacy vulnerabilities, but it also opens an entirely new set of vulnerabilities with digital labor that can be corrupted.
As such, this is a critical topic for exploration, as it may very well act as the primary hurdle for agentic implementation. The framework’s scaffolding remains unchanged in this section, but we do add a focus on security specialists as subcategories within the incumbent and AI-native categories.
Mythos, Early Warning or Myth?
In April 2026, Anthropic announced that it had developed Claude Mythos Preview, a next-generation frontier model that demonstrated substantial improvements in capability. Interestingly, the company also announced it would not be released broadly due to its ability to exploit hidden cybersecurity risks. Instead, the company released the model to a select group of corporations and institutions via Project Glasswing, which was an “urgent attempt to put these capabilities to work for defensive purposes.”40 A May 2026 update on the initiative noted that Mythos identified more than 10,000 serious vulnerabilities, highlighting the power of models on the current frontier.
This announcement, of course, galvanized media attention and triggered a frenzy across government institutions and enterprises. There was also ample skepticism around the claims. Was this just a “scare marketing” technique? Did Anthropic really constrain the release because it is short on inference compute capacity? Regardless of the reasons behind the unique launch approach, we believe it also produced an important wake-up call for cyber professionals across the globe. Whether it’s Mythos or a future frontier model release, it is increasingly apparent that AI, and agentic AI in particular, presents significant new security and governance risks for individuals, companies, and nation-states.
LLM security risks can be constrained, but not eliminated
The continued leaps in autonomous coding capabilities with each successive model release have been increasingly obvious as we progressed through early 2026. It stands to reason that with these increased capabilities, these models can be used by bad actors to discover and exploit security vulnerabilities that may have existed for years or decades without prior discovery.
Nevertheless, the scope of the risk is even more pronounced, as inference-layer contamination can influence a model’s reasoning and actions in a more subtle and potentially damaging way than explicit software exploits. Indeed, as Nikhil Srivastava recently argued in his piece, Notes on the Bigger Picture: Misanthropic Commentary & the Frontier AI Liability Stack, the ability to scheme, deceive and comply with harmful requests is inherent to probabilistic LLMs, and while post-training alignment can reduce these risks, they remain latent in the base model (my paraphrasing of his message).41 These latent threats can be coaxed out of the system by skilled bad actors, and the danger of misbehavior scales with the model’s overall capabilities.
Figure 17: Fronts 1 and 2 of AI Security Challenges

The concerning result is that the governance and security challenges of LLMs are growing on two fronts: 1) the ability for a model to be used as a tool for bad actors to bypass legacy security and guardrails, and 2) the ability of bad actors to extract latent misbehavior from the base model, despite frontier lab efforts to introduce guardrails and safety mechanisms during training.
Agentic AI increases the threat surface
“As humanity delegates more tasks to agents, the critical question is no longer what information exists, but what our most powerful tools will be made to believe.”
--Google DeepMind, AI Agent Traps, April 202642
Agents expand the security risk of AI as they are exposed to the external world on multiple fronts, and because an “infected” agent can pass its bad behavior to other agents in a multi-agent environment. AI Agent Traps, a recent paper from Google DeepMind, carefully outlines the threat surface for AI agents. It offers a powerful framework for business and technology leaders to understand agentic security risks.
The key concept in the paper is the idea that future attacks may not need to exploit the model directly. Instead, bad actors can poison the information environment around the agent. This way, the agent sees the wrong thing, reasons the wrong way, remembers bad information, and/or takes harmful actions. The authors encapsulate this risk into six buckets:
Context injection. This is the simplest idea. Hide malicious instructions in places humans do not notice or cannot see, but an AI agent can read and capture. Hidden text in a webpage, invisible HTML, and even instructions inside an image or document can suffice. The attacker is effectively slipping instructions into the wallpaper, telling the agent to do something different from the user’s or institution’s intent.
Semantic manipulation. This is a more complex exploit in which the attacker surreptitiously nudges the agent in the wrong direction. Instead of an obvious command, the attacker shapes the wording, framing, tone, or surrounding context so the agent is more likely to reach a biased or false conclusion. The agent remains unaware that it has been steered by loaded language or fake authority.
Cognitive state traps. By poisoning an agent’s context, bad actors can target what an agent “remembers” or what it pulls as background knowledge. This is a bit like feeding someone bad notes before a big meeting, but it can obviously be more catastrophic when done at scale with agents.
Behavioral control. This is perhaps the most direct and damaging category, as it can push an agent to do something it should never do. This can effectively allow a bad actor to commandeer an agent’s hands. The goal can be to reveal sensitive data, send data to an unintended person, trigger tools it should never use, or launch malicious sub-agents.
Systemic, multi-agent traps. In multi-agent environments, this attack vector can create conditions that cause many agents to behave badly and in sync. They could overload the same resource, amplify errors, or collude intentionally.
Human-in-the-loop attacks. This one may be the most pedestrian, but it’s still important. In many multi-agent systems, human reviewers will remain a critical layer of governance. If an attacker can use the agent itself to fool the human guardrail, then the human’s ability to stop an attack may be hampered. This can be as simple as presenting malicious links to the human, bad instructions in a trusted output, or even just wearing the human down with approval fatigue.
Some of these threats are real today, and some will emerge as capabilities advance, but in sum, they should illustrate how a unique attack surface is opening with the rise of agentic AI.
Figure 18: The Six Agent Traps from Google DeepMind
Securing the future, a critical hurdle for adoption
As AI moves from passive chatbots to agentic digital labor, the risk calculus for enterprise software changes considerably. As agents gain autonomy, they can orchestrate complex workflows, execute code, and interact directly with the external environment. Cybersecurity is no longer just about hardening network parameters or authenticating human users, as its scope now increases to account for non-human entities that possess logic, memory, and agency. Agents can operate at machine speed across vast and highly interconnected digital supply chains and securing their activities and motives will likely be the number one hurdle to overcome before agentic implementations become widespread.
The once distinct domains of trust, permissions, and security are now combining into a single risk surface. The latent misbehavior risk category we defined as “Front 2” earlier in this paper is perhaps the most dangerous and the least explored to date. The danger lies in the likelihood that this threat surface only worsens as better AI models emerge; the innovations that drive greater agent autonomy and adoption simultaneously increase the risk. Perhaps more concerning, many frontier labs and agentic vendors typically shift the liability for this risk to customers in the fine print of sales contracts.
Frontier Labs: limited ability to lead in inference-level security
The recent actions of frontier labs have demonstrated that they take AI security risks seriously (e.g., Mythos’ constrained release) and can certainly contribute to the discovery of classical security threats. Nevertheless, several factors suggest they won’t lead in proactively reducing risk in the “Front 2” category. Nevertheless, we do expect them to actively partner with companies focused on this risk, as it is paramount to the pace of agentic AI adoption more broadly.
The first challenge for frontier labs is the tight correlation between latent misbehavior and model capabilities. The emerging threat of latent misbehavior in frontier models and the agents that rely on them increases explicitly with improvements in frontier model capabilities. Much of this is masked or restricted by careful model post-training at frontier labs, but adversarial hackers will always find ways to unmask these behaviors. In addition, most of the “six agent traps” discussed previously are very specific to each enterprise’s unique workflows; it would be challenging to integrate protections against these bespoke risks at the model layer without degrading overall performance or dramatically increasing inference costs.
The second challenge is a subtler trust problem. As frontier models become more capable, each release can expand the latent inference-layer attack surface. This creates an awkward market structure in which the same labs that sell the model also sell the cyber control plane meant to secure it. The issue is not pure moral hazard, nor a clean principal-agent problem, but rather a conflict of interest around endogenous risk. The labs control the release cadence, possess the deepest proprietary knowledge of model failure modes, and may benefit from the very security spend those releases make necessary. Even with sincere safety motives, the optics can look a bit like the arsonist selling fire extinguishers.
Incumbents: established trust and embedded telemetry advantage
The emerging capability of frontier models to discover long-missed classical security risks (“Front 1”) is likely to expand the overall TAM for all security players. The unique security challenges from latent frontier model misbehavior and misaligned agents (“Front 2”), however, represent a disruptive threat to incumbents if they fail to invest or partner to build up capabilities in this arena. Nevertheless, across both fronts, incumbents with established security franchises will benefit from several factors that give them a critical advantage over labs and AI-native startups if they continue to invest seriously.
First, in the agentic era, cybersecurity is tightly linked to identity and access management. The software incumbents, for the most part, already control the identity graphs that map human permissions and activity. With proper development, these assets can extend identity solutions to non-human agents. For instance, Microsoft Foundry already defines an “agent identity” that provides administrators with the ability to “inventory agents, apply policies, and audit activity.”43 Meanwhile, SentinelOne focuses on execution-based security, prioritizing identity protection by determining adversarial intent from behavior rather than simply relying on explicit logins and permission rules.44
Second, incumbents often have deep telemetry records, allowing them to recognize approved patterns and endpoints for each specific domain. This expertise can not only help them quickly address new threat paths identified by frontier models but also help them establish safe lanes and access points for autonomous agents.
AI-natives: the benefit of focus and R&D agility
Unlike the preceding competitive dynamics sections, it’s important to distinguish between the broader AI-native startup category and security-focused AI-natives here. The broader AI-native category generally does not seek to address complex agentic security challenges; in most cases, it actively seeks to shift liability to customers, which only heightens the security barriers to agentic adoption. In contrast, purpose-built security AI-natives have significant advantages in this space.
AI-native, agentic security companies can benefit from a maniacal focus on the specific risks posed by the inference boundary in agentic systems. Frontier labs can focus on the model, while incumbents will focus on identity, cloud, and endpoints. A truly AI-native security vendor will focus on input ingestion, retrieval, prompt assembly, memory updates, MCP calls, tool outputs, sub-agent orchestration, action authorization, and output release. This is fundamentally a research effort, and not a task that can be easily bundled with legacy systems.
In addition, like the AI-native advantage in context capture, AI-natives can continuously capture attack intelligence and successful red teaming actions, creating a data flywheel. By covering threats across different frontier model families and differing business verticals, AI-natives can enjoy a compounding moat from exploit discovery, labeling, benchmark coverage, and policy updates.
Mechanisms of achieving agentic security leadership
While C-suite leaders are pushing rapid agentic adoption across an increasing number of industries, IT security managers and company boards are facing the uncertainty of a rapidly changing threat surface. The nascent ability of frontier models to discover classic security vulnerabilities more rapidly and at scale will likely increase the security TAM for all vendor types. Nevertheless, the more urgent threat to agentic implementations is the emerging front of novel security risks posed by probabilistic models and the agents themselves; this creates a new TAM and a highly competitive landscape for all vendors.
Frontier Labs: a deep understanding of the latent threats inherent in models
Inherent Advantage: By definition, the frontier labs have the deepest visibility into the raw capabilities, training mechanisms, and latent misbehavior of their models. They also can leverage their lead in harness dynamism to inject the appropriate guardrails into agentic implementations. This gives them a valuable role in identifying model-level risks, developing alignment techniques, improving evals, and helping enterprises understand how new model releases change the security profile of agentic deployments.
Inherent Weakness: The frontier labs face a structural challenge in leading the full agentic security layer because some of the most important new risks are endogenous to their own products. The same model improvements that make agents more useful may also make them more dangerous when misdirected, jailbroken, poisoned, or embedded inside risky workflows. As a result, the frontier labs can play an essential but incomplete role in agentic security.
Software Incumbents: established trust and foundational identity and access graphs
Inherent Advantage: Security-focused incumbents should benefit from a likely expansion of the classic security TAM as models expose new vulnerabilities in legacy code and networks. Incumbents can also leverage their existing IAM systems for non-human agents and capitalize on wide telemetry footprints to detect anomalous agent behavior. In addition, enterprise trust in incumbents will be critical, particularly since most security buyers are risk-averse when selecting vendors. This gives incumbents a natural right to participate in early agentic security deployments.
Inherent Weakness: The greatest risk for incumbents is that agentic security needs may evolve faster than their legacy architectures can adapt. Agentic systems introduce a different kind of security problem: probabilistic reasoning, semantic manipulation, poisoned context, agent memory, tool misuse, multi-agent contagion, and adversarial influence over the agent’s “beliefs.” These are not problems that can become an extension of firewall rules or endpoint detection.
AI-natives (Security Focused): agility and native focus on the inference boundary
Inherent Advantage: AI-native security startups can dedicate 100% of their R&D focus to the specific vulnerabilities of digital labor. This gives them the focus to capture cybersecurity’s shift from network-level topological defense to orchestration-level semantic defense. By leveraging the power of probabilistic systems themselves, they can secure the intent and logic workflow of an agentic system at the exact points where the model interacts with tools and memory.
Inherent Weakness: The primary weakness for AI-native startups is trust. Enterprises are likely to be cautious about entrusting critical governance and security responsibilities to young vendors without a long operating history. AI-natives may also lack the full telemetry picture that incumbents have. While they may see the agentic inference boundary more clearly than legacy incumbents, it is harder for them to access endpoint behavior, identity graphs, cloud activity, application logs, etc.
An Agentic Gap/Strength Schematic
If we weigh all four competitive levers equally, all three categories of agentic vendors enter this battle with roughly equal, but different, strengths and weaknesses. Of course, each vertical will weigh various levers differently, and as a result, this framework should be leveraged on a vertical-by-vertical basis. In addition, it’s important to consider which factors will carry greater weight across more verticals over time. For instance, the frontier labs have the bully pulpit of the intelligence platform and harness influence to counter their weaknesses in agentic. Likewise, software incumbents have distribution heft and enterprise inertia (trust and workflow expertise) to tilt the balance of power in many verticals.
Figure 19: A Generalized Schematic of Competitive Strengths and Gaps
A vendor with a disadvantage in one category can rectify that weakness through partnerships, M&A, and investment; similarly, a vendor with an advantage in one category can fail to capitalize on that strength by underinvesting.
In our view, the predominant “SaaSpocalypse” narrative inherently throws the baby out with the bathwater by failing to recognize how dynamic leading technology companies can be. Similarly, the commoditization narrative of the frontier labs has dangerously discounted their power as potential general-purpose intelligence platforms. For sure, surprising disruption from startups is also a part of the technology industry and should be considered in any analysis. Either way, the pace of AI development has also given companies implicit permission to act boldly. And many will do so (and many have already begun to take actions to fill gaps).
The Agent Pricing Puzzle
The debate on the proper pricing mechanism has only grown more complicated since I initially explored the issue in The Industrialization of Intelligence. The frontier labs seem focused on consumption, with some subscription tiers for SMB and prosumer use. The AI-native startups have doubled down on outcome pricing, anchoring their strategy on the services-as-software mantra. And the incumbents seem to be settling on hybrid pricing, typically combining seat-based licenses with agentic consumption pricing. Each touts the economic rationale of their approach as superior to others, and it can all be a bit confusing to most observers.
When considering the competitive elements of agentic AI in the enterprise discussed in this paper thus far, however, it seems clear that each group is wisely playing to their own distribution and IP strengths. This is likely to continue to be the case, at least in the medium term. Specifically, we expect the following:
Frontier labs will remain consumption-pricing centered. The frontier labs control the underlying utility and economics of model tokens. Furthermore, since tokens are the primary input cost for agents, frontier labs can monetize them through API consumption for first and third-party agents in the ecosystem. While there may be some cases where labs charge based on outcomes when they partner deeply with a specific vertical incumbent or AI-native startup, this is likely to be the exception rather than the rule.
Incumbents will leverage hybrid pricing to capitalize on distribution and workflow inertia. The incumbents are linking and leveraging their active installed bases to add agentic capabilities to existing SaaS or infrastructure software licenses. To further strengthen their advantage as the “trusted agentic transition partners,” the hybrid, seat-based pricing plus AI consumption pricing model will likely remain dominant in the medium term.
AI-native startups counter adoption friction with outcome certainty. Startups need to leverage their vertical focus and context-capture advantages to offer enterprises a simple, low-friction adoption model. This is why we’re hearing so much about outcome-based pricing from this crowd; it shifts the token-consumption risk to the agentic vendor and away from the customer. It stands to reason that the resulting COGS uncertainty for AI-native startups and the challenges of harness dynamism will push them towards preferred, and potentially exclusive, partnerships with a single frontier lab. Pure model agnosticism is unlikely to hold as an effective strategy for smaller, vertically focused players, and cost/pricing management will be a big reason why.
The Eventual Steady-State is Likely Labor-Indexed Pricing
The frontier labs provide the key input for agentic applications through LLM tokens. This is an API revenue line item for the labs, and a COGS line item for agentic vendors (which can also be the labs). As I argued in The Industrialization of Intelligence, the commoditization of the core input cost for AI is not a bad thing for the industry. In fact, it’s a very welcome economic engine for the penetration of agentic AI into the economy. This is largely because the value-capture mechanism for autonomous, agentic applications is productivity improvements via digital labor.
The margin earned for providing this labor is not based on access to frontier models alone; it’s more centered around the price paid for the deterministic agentic architecture, platform rents, and context-capture mechanisms that agentic vendors provide on top of commoditizing LLM tokens. This is why pure token-based consumption models can misrepresent value to customers, as what appears to be a margin for token distribution is covering far more than that. Any consumption-based model, particularly as part of a hybrid pricing model, should be priced in units that capture both platform and agentic architecture value, as well as LLM intelligence. In fact, at this stage in the paper, we can refine the definition of agent CPSO (cost per successful outcome) to include token cost (intelligence pool), platform rents (platform pool), and harness cost (agent pool). There is also a human-in-the-loop cost, but I am excluding it since the ultimate trajectory is autonomous-agent task completion.
While pure token consumption models fail to provide a mechanism that captures the true value of agentic solutions, outcome-based pricing models risk causing confusion for workflows where task success is not easily defined as a binary “done or not”. Hybrid pricing models can capture the uncertainty inherent in the transition to agentic AI by blending rational vendor margin protection, buyer budget predictability, and shared upside for AI productivity enhancements and ROI; nevertheless, over time, hybrid pricing becomes less appropriate as human seat costs are increasingly divorced from autonomous agent value.
For these reasons, over the long term, we believe agentic pricing in most verticals will converge on per-agent pricing that more closely approximates the value of the labor an agent is displacing or augmenting. Each agent will have a “unit of labor” cost, bypassing the complexity of outcome measurement and the customer-side risk of pure consumption models. This eventual outcome will require token cost and usage predictability that isn’t a reality today, so we’re left with differing and somewhat confusing pricing models by vendor type over the medium term.
Conclusion: Change Will Be the Only Constant
We believe any unbiased monitoring of the disruption and opportunities from agentic AI will track the companies’ actions in the space and judge them based on whether they enhance or fill critical gaps on the road to agentic autonomy. Some will rise above the pack, and some will falter; either way, the pace of change is only quickening.
Frontier labs will likely focus their partnerships and investments on expanding their distribution footprints and context-capture mechanisms. These partnerships can be particularly fruitful if the labs help bolster the harness dynamism of the incumbents or AI-natives they partner with. Most importantly, we believe frontier labs will likely focus their partnerships on verticals where regulatory barriers and compliance requirements are critical, as trust and compliance gaps can’t be filled by labs alone.
The incumbents will likely focus on harness dynamism and context capture partnerships and investments. Frontier labs likely help solve the harness dynamism challenge for incumbents, while AI-natives will be particularly attractive partners for context capture and security enhancement.
Finally, we believe AI-natives (as with startups in past cycles) will seek partnerships that capitalize on the distribution strengths of both frontier labs and the incumbents. In the case of agentic AI, the pace of change is so rapid that AI-natives will likely seek these partnerships far earlier in their corporate lifecycle than in prior technology waves.
The start clock for agentic AI has just begun. Some outcomes will be surprising, and the debates over winners versus losers will only intensify. Regardless, now is the time for companies to take action to secure leadership in this burgeoning new opportunity lest they fall prey to technological disruption and obsolescence.
Disclaimer: The views and opinions expressed in this article are solely my own and do not represent the views of my employer or its affiliates. This article is provided for general discussion purposes only, has not been prepared as investment research, and does not constitute investment advice, a recommendation, an offer or solicitation to buy or sell any securities or financial instruments.
Disclosure: The author of this report holds pre-seed equity positions, as an investor and as an advisor, in several AI-native startups.
Shope, B. (2026, January 30). The Industrialization of Intelligence. The AI Wave, Substack.
Karpathy, A. (2026, February 25).@karpathy. x.com
Challapally, A., Pease, C., et.al. (2025). The GenAI Divide: The State of AI in Business 2025. MIT NANDA.
Anthropic (2026, April 29). Evaluating Claude’s bioinformatics research capabilities with BioMysteryBench.
METR. (2026, May 8). Task-Completion Time Horizons of Frontier AI Models.
Adamczewski, T., Rein, D., et.al. (2026, April 10). MirrorCode: Evidence that AI can already do some weeks-long coding tasks. EPOCH AI.
Huang, J. (2026). Morgan Stanley Technology, Media, & Telecom Conference 2026.
Brockman, G. (2026, May 21). @gdb. x.com
Galbraith, J. R. (1974). Organization Design: An Information Processing View. Interfaces, Vol. 4, No. 3.
Kenney, M., Bearson, D., et.al, (2019, November). The Platform Economy Matures: Pervasive Power, Private Regulation, and Dependent Entrepreneurs. Berkeley BRIE.
Rao, K. (2026, May 13). Inside Anthropic’s $100 Billion AI Compute Commitment - CFO Krishna Rao. Invest Like the Best, YouTube.
Safjanm K. (2026, April 9). The Real Cost of Model Migration - What Swapping LLMs Actually Requires. Safjan.com.
Zhang, Yukun, Zhang, Tianyang. (2026, January 18). The Economics of Digital Intelligence Capital: Endogenous Depreciation and the Structural Jevons Paradox. arXiv.
Ball, D. W. (2026, February 5). On Recursive Self-Improvement (Part 1). Hyperdimensional.
OpenAI. (2026, February 5). Introducing OpenAI Frontier. OpenAI.com.
Lamanna, C. (2025, November 18). Microsoft Agent 365: The control plane for AI agents. Microsoft.
ServiceNow. (2026). AI Control Tower.
AWS. (2026). Amazon Bedrock.
Google. (2026). Gemini Enterprise Agent Platform. Google Cloud.
Iansiti, Marco and Levien, Roy. (2024). The Keystone Advantage. Harvard Business Review Press.
Rajasekaran, P. (2026, March 24). Harness design for long-running application development. Engineering at Anthropic.
Dell’Acqua, F.M., et. al. (2023, September 22). Navigating the Jagged Frontier: Field Experimental Evidence of the Effects of AI on Knowledge Worker Productivity and Quality. Harvard Business School.
Gupta, J., Garg, A. (2025, December 22). AI’s trillion-dollar opportunity: Context graphs. Foundation Capital.
Ball, J. (2025, December 12). Long Live Systems of Record. Clouded Judgement.
Xu, B., Suresh, A., Tang, E. (2026, January 29). Inside OpenAI’s in-house data agent. OpenAI.
Schwartz, A. (2026, January 20). Context Graphs Enable Agents and Humans to Act Intelligently. Parable.
Fulcrum Digital. (2025, June 24). The Future of Experience Starts with Intent, Not Interaction.
Romero, M.L., Suyama, R. (2025, June 5). Agentic AI for Intent-Based Industrial Automation. arXiv.
Bek, J. (2026, March 5). Services: The New Software. Sequoia Capital.
Singh, S. F. (2026, March 4). OpenAI Finalizes $10 Billion Joint Venture With PE Firms to Deploy AI. Bloomberg.
OpenAI. (2026, May 11). OpenAI launches the OpenAI Deployment Company to help businesses build around intelligence. OpenAI.
Vinn, M. (2026, May 5). OpenAI, Anthropic ventures in talks to buy AI services firms, sources say. Reuters.
Chiu, H. W. (2026, January 25). What I learned analyzing 1k forward deployed engineer jobs. Bloombery.
Jin, B. (2026, March 19). OpenAI Plans Launch of Desktop “Superapp” to Refocus, Simplify User Experience. The Wall Street Journal.
MindStudio. (2026, April 9). What is Anthropic’s Platform Strategy? How Claude Code, CoWork, Marketplace, and Conway Form One System.
Bachman, M.G. (2026, April 22). Introducing Gemini Enterprise Agent Platform. Google Cloud.
Kolt, N. (2025). Governing AI Agents. Notre Dame Law Review, Vol.101.
Anthropic. (2026, April 7). Project Glasswing, Securing critical software for the AI era.
Srivastava, N. (2026, April 29). Notes on the Bigger Picture: Misanthropic Commentary & the Frontier AI Liability Stack. Economechanics, Substack.
Franklin, M., Tomasev, N., Jacobs, J., et.al. (2026, March 28). AI Agent Traps. Google DeepMind.
Microsoft. (2026, April 13). Agent identity concepts in Microsoft Foundry. Microsoft Build 2026.
Montenegro, F. (2026, March 4). SentinelOne’s Identity Catch-Up Tests Its Endpoint-Led Platform Story. Futurum.































The competitive levers map almost perfectly onto what platform engineers are already building: harness dynamism is execution + evaluation inside Agent Infrastructure, context capture is the context component, and the control plane is the governance layer (identity, security, observability). The vocabulary is different, but the architecture is the same. Once you see that this is a platform race, the question for enterprise teams is what their own agentic platform actually looks like structurally - because you can't just buy it from a frontier lab or vendor somewhere!