Flash sale 30% off with code LAUNCH30 Ends in --:--:--
All Things PM
The AI Challenges Businesses Are Actually Focused On Right Now
The AI Daily Brief: Artificial Intelligence News and AnalysisAI Strategy

The AI Challenges Businesses Are Actually Focused On Right Now

While the AI safety debate dominates headlines, real enterprise buyers are quietly ruthless about swapping vendors, worried about agent identity management, and increasingly building their own owned model architectures instead of depending on a single lab's API.

September 18, 2026 · 30 min listen · 10 min read
0:00
–:––

Context

NLW steps back from the AI existential-risk debate dominating headlines to ask what enterprise buyers and business leaders are actually prioritizing right now, drawing on a Wall Street Journal executive survey, Box's Aaron Levie's direct conversations with executives across banking, media, and insurance, and Ramp's enterprise AI spend data. The episode matters directly to PMs selling into or building for enterprises because it surfaces a consistent, practical gap: business buyers are largely unmoved by extinction-risk framing but are actively changing behavior around a specific, narrower set of concerns, cybersecurity, agent identity, vendor lock-in, and architecture ownership.

The Big Idea

The AI safety discourse dominating headlines has had almost no effect on how enterprises are actually prioritizing AI work day to day, but it's quietly accelerating a trend that was already underway: companies moving toward owning their own model architecture instead of depending entirely on a single frontier lab's API.

The clearest evidence: at a Wall Street Journal executive summit, only a handful of attendees raised their hands when asked if they worried AI might "kill us all," while roughly half supported slowing down frontier research generally, showing business leaders can hold real safety concerns without those concerns changing their operational AI roadmap. Meanwhile, concrete moves like Latham & Walkins (the US's second-largest law firm) buying Nvidia servers to run in-house models specifically to keep sensitive client data off any cloud vendor show the actual behavioral shift is toward independence from labs, not toward pausing AI adoption.

Key Insights

Cybersecurity concern is real, pragmatic, and specifically tied to the Hugging Face incident, without the existential framing

Aaron Levie's direct reporting from conversations with executives across banking, media, information services, and insurance: "everyone is nervous about the growing rate of vulnerabilities coming at them from AI," specifically citing awareness of the OpenAI/Hugging Face incident, but Levie is explicit that "the conversation is not as existential as it is in Silicon Valley," it's operational and practical, focused on keeping up with a fast-changing threat landscape rather than debating whether AI poses a species-level risk. This is a useful calibration for anyone pitching AI security tooling into the enterprise: lead with operational risk and concrete incident response, not the framing dominating tech-industry discourse.

Agent identity and access management is an emerging, unsolved category

Levie's reporting identifies a specific structural problem enterprises are grappling with: "in a world where agents are trying to get into every system they can," companies want to set up distinct identities for each agent and control what it can access, but "sometimes the agent needs to act exactly as the user as well," meaning the clean separation companies want (agent identity distinct from user identity) breaks down for legitimate use cases where an agent genuinely needs a user's full access to do its job. Notably, the underlying worry isn't only malicious actors, it's that agents have become powerful enough that even non-engineer employees using them in good faith can accidentally exceed intended containment, a distinct risk category from traditional access control threats.

Enterprises are "ruthlessly" swapping AI vendors and architectures, faster than in most prior technology cycles

Levie's specific observation: companies had examples of changing AI systems or vendors multiple times within just the past year or two, with a common internal narrative of "we tried X and it didn't work, so we've gone with Y." NLW's framing of why this matters: because the underlying technology is moving so fast, no enterprise buyer waits around for a vendor to eventually get something right, they simply move to the next option, which is a much shorter loyalty cycle than most enterprise software categories have historically had, and should change how any AI vendor thinks about retention and switching costs.

Enterprises deploy multiple frontier models but concentrate spend on very few vendors, with real appetite for alternatives that don't yet exist

Levie found that most companies use multiple frontier models internally because standardizing on one model across all teams and use cases proves impractical given differing team preferences, but the actual dollars remain concentrated with just a few vendors, largely because open-weight domestic (US) options remain immature at enterprise scale. His specific point: there's real, unmet demand for more open-weight alternatives, but currently few credible places for enterprises to go, a gap that both a16z's software-incumbent commentary and Mistral's CEO explicitly frame as validating why more software companies should now be racing to build and own their own fine-tuned open-weight models rather than reselling frontier-lab access.

A specific security rationale is driving law firms and banks toward owned, in-house model infrastructure

Latham & Walkins bought Nvidia servers specifically to run models in-house as an alternative to cloud-hosted frontier lab APIs, stating plainly: "sometimes we may have information that is so sensitive... we really want to protect. We don't want to put it on any cloud vendor." This is presented as a template other regulated, high-sensitivity industries (banking, healthcare, government) are likely to follow: not a rejection of frontier AI capability, but a decision to run that capability on infrastructure the enterprise itself controls rather than depend on any external vendor's API and data-handling policies, regardless of that vendor's stated safety practices.

Microsoft's own framing ties AI safety concerns directly to the enterprise vendor-dependence problem

Satya Nadella's post accompanying Microsoft's 15,000-word AI code of conduct explicitly connects the two issues NLW is separating in this episode: he writes that firms must "retain full control over their unique and tacit knowledge" and be able to "embed its own knowledge into models and weights they control" without "becoming dependent on any one model provider." NLW's read: this reframes the abstract "concentration of power" concern from the AI safety debate into a concrete, actionable enterprise strategy point, the antidote to depending too much on any single AI lab isn't waiting for regulation, it's enterprises building their own continuous-learning loops on models they actually own.

Enterprise AI spend among the heaviest users declined in August, but likely reflects sophistication, not retreat

Ramp's data showed the top 1% of AI-spending businesses cut spend 10% from a July peak, and lead economist Eric Karazin's read is that this reflects increasingly sophisticated buyers shifting workloads to cheaper "standard and light" models rather than defaulting to the most expensive frontier model for every task, essentially the same "model routing by task difficulty" pattern seen elsewhere in AI infrastructure discourse, not a pullback in overall AI investment. NLW flags his own doubt about how much of the dip is really summer seasonality rather than a strategic shift, a reminder to treat single-month spend data cautiously regardless of the narrative attached to it.

Mental Models & Frameworks

Separate "is this issue real" from "does this change our roadmap" when tracking any industry-wide debate

The Wall Street Journal summit data models a useful pattern for any PM watching an industry-level controversy (safety, regulation, a competitor's move): survey your own stakeholders on both the belief question (do you think this risk is real) and the behavior question (does it change what you're prioritizing) separately, since Businesses in this episode show real concern on the first axis with almost no shift on the second, a combination that's easy to miss if you only ask one question.

The vendor-independence hedge: fast-moving categories reward owning your own architecture

A generalizable strategic pattern surfaced across Nadella, Mensch, and Foundation Capital's Jaya Gupta: in a category evolving too fast for any single vendor relationship to feel durable, and where regulatory risk to specific vendors is rising, the hedge with the best asymmetry is building owned, fine-tunable infrastructure (even on top of open-weight models) rather than betting entirely on a single external provider's roadmap and policies. Foundation Capital's specific advice to software incumbents: "every major software company should become a model factory for its own vertical," post-training open-weight models on the workload it uniquely sees and improving them continuously from its own production feedback, rather than just reselling access to someone else's frontier model.

Trade-offs & Nuance

Slower frontier development could plausibly increase, not decrease, enterprise AI spend

NLW's own thesis, referenced from a prior episode: the blistering pace of model releases creates a real disincentive for enterprises to invest in deep AI transformation, since a comprehensive rollout risks being obsolete by the time it's finished. If frontier development paced more predictably (independent of whether that's driven by voluntary lab commitments or regulation), it could plausibly increase enterprise willingness to commit to deeper AI integration rather than waiting out the next model generation, an economic argument for pacing distinct from and additional to the safety argument, worth weighing on its own terms rather than assuming any slowdown is purely a cost to the industry.

Multi-model deployment inside one enterprise reflects real fragmentation, not indecision

The fact that most companies run multiple frontier models simultaneously because teams have different preferences and use cases isn't presented as a governance failure to fix by forcing standardization, it's framed as a rational response to genuinely different task requirements across an organization, meaning vendors and internal AI platform teams should design for multi-model support as the default expectation, not an edge case to eventually consolidate away.

Practical Application

Pitch AI security tooling on operational incident response, not existential framing

When selling cybersecurity or AI-safety-adjacent tooling into enterprises, lead with the concrete, incident-driven concern (keeping pace with a fast-changing vulnerability landscape, specific awareness of incidents like Hugging Face) rather than the existential-risk language dominating tech-industry AI safety discourse, since that's demonstrably not how business buyers are actually framing the problem to themselves.

Design agent access control for the case where an agent must act as the user, not just alongside them

If you're building agent infrastructure for enterprise deployment, explicitly design for the access-management case Levie describes, where a clean separation between agent identity and user identity breaks down because the agent legitimately needs to act with the user's full permissions, rather than assuming a simpler, fully-separated identity model will cover real use cases.

Expect and design for short vendor loyalty cycles in fast-moving AI categories

If you're building or selling an AI product into enterprises, assume buyers will actively re-evaluate and potentially swap your product within a year or two based on a single "it didn't work, we moved to something else" narrative, rather than assuming typical enterprise software switching costs and inertia will protect your position. Build in continuous, visible improvement and don't rely on integration depth alone to retain accounts.

Evaluate whether your own sensitive-data workloads warrant owned infrastructure rather than API dependence

Following Latham & Walkins's specific rationale, if your organization handles data sensitive enough that its exposure risk profile differs meaningfully from typical enterprise data, evaluate whether running models on infrastructure you control (even at higher upfront cost) is justified specifically for that sensitive subset of workloads, rather than treating "which vendor has the best model" as the only relevant question.

Bottom Line

While the public AI safety debate rages over existential risk, actual enterprise buyers have barely changed their day-to-day priorities, but the debate is reinforcing and accelerating trends that were already underway: heightened, pragmatic concern about agent security and identity management, ruthless willingness to switch AI vendors as the technology evolves, and a growing strategic case for owning your own model architecture rather than depending on any single frontier lab, a shift regulatory risk now makes even more compelling.

AI PM course

Everyone hears the same episodes.
Few can do what they describe.

Start for free