The quiet story this week isn't a model launch. It's that enterprise buyers are flopping between OpenAI and Anthropic every time a new model ships. If your AI strategy assumes you'll pick one lab and settle down, the data says otherwise — and that changes how you should be writing contracts and building integrations right now. Everything else was mostly noise, with two security items worth ten minutes of your attention.
1. Enterprise AI loyalty is a myth
What happened: New usage data shows businesses shifting spend back and forth between OpenAI and Anthropic with each model release, with OpenAI now gaining on Anthropic among business users.
Why it matters: Stop optimising for a single-vendor bet. The switching happening in the market is your leverage — build an abstraction layer so you can move workloads to whoever's ahead this quarter, and negotiate contracts that assume you'll leave. AWS Bedrock now serving GPT-5.6 across 25+ regions with cross-region routing makes multi-provider setups genuinely practical, not just a slide.
2. Two working AI attacks that steal your data
What happened: Researchers showed Grok exfiltrating user data via encrypted malicious instructions, and Microsoft Copilot exposed a secret parameter that let attackers steal passwords when a victim clicked a link.
Why it matters: These aren't theoretical jailbreaks — they're prompt-injection attacks that turn your own copilots into data-exfiltration tools. If you've connected an assistant to email, documents, or credentials, treat every external input as hostile. Ask your security team this week whether your deployed AI tools can read untrusted content and act on it in the same session. If yes, that's the hole.
3. Memory prices are up 500% in a year
What happened: DRAM and memory pricing has spiked roughly 5x over twelve months, effectively reversing years of cost declines back to 2007 levels.
Why it matters: This feeds straight into what you'll pay for AI compute and any hardware refresh. Budget for it now rather than being surprised at renewal.
4. The self-improving AI story just got slower
What happened: MIT Technology Review reports that recursive self-improvement — AI rapidly upgrading itself with little human oversight — is running into real limits and probably won't arrive on the timeline the loudest forecasts promise.
Why it matters: If a vendor or a board member is justifying decisions with imminent runaway AI progress, this is your permission to push back. Plan for steady, useful improvement you have to actually integrate — not an overnight leap that makes today's work obsolete. The parallel piece worth reading: we still have no independent data on how people actually use these tools, only what the labs choose to publish.
5. Slack puts coding agents in the group chat
What happened: Slack Code launched dedicated channels where teams collaborate with AI coding agents in shared, project-specific spaces instead of switching tools.
Why it matters: Handy, but watch who can invite an agent into a channel and what it can touch — same injection risk as above, now in your busiest comms tool.
The bottom line: The week's real signal is boring and useful: enterprise buyers aren't loyal, so architect for portability and negotiate like you'll switch. The urgent signal is security — two live attacks turned mainstream assistants into data thieves, so audit what your deployed AI can read and act on before someone else does. Everything about self-improving superintelligence can wait; the prompt injection in your Copilot cannot.
— Daniel · usqrd.com · reply to this email, I read everything

