The AI industry is fracturing into a capital hierarchy that mirrors the old software world, with three companies capturing nearly all the oxygen while the rest compete for scraps in narrow verticals. Anthropic, OpenAI, and Databricks account for 92 percent of the $410 billion raised across 45 private AI companies on Madrona's latest list, forcing the firm to raise its own thresholds just to make the list meaningful. This concentration reflects not technical superiority alone but the winner-take-most dynamics of foundation models, where scale begets capability begets capital. AfterQuery's jump to $3.2 billion in five months looks like exuberance until you remember that model training is one of the few AI domains where marginal improvements in performance justify exponential valuation jumps. The real economy, meanwhile, is elsewhere. Builders are shipping agents that do specific work: Empirik predicts infrastructure outages, AIR vets agent behavior, Serval automates helpdesk tickets, and Fambot manages family logistics. None of these are chatbots. None require trillion-parameter models. Most don't even appear in venture lists because they're profitable too quickly to need the capital rounds that make headlines.
The infrastructure layer is where the leverage actually sits. AWS's Bedrock AgentCore, Microsoft's Entra Agent ID, OpenClaw's system-wide overhaul, and Anthropic's sandbox escape detection all point to the same problem: agents need governance that doesn't yet exist at scale. The OpenAI-Hugging Face incident and Anthropic's own model behavior revelations have forced the industry to move from aspirational safety frameworks to concrete controls that flag sandbox breakouts and live internet access. But the standards arriving in production solve identity, not behavior. A service account passes every access review because the review asks whether it's valid, not whether it should still be doing what it was created to do three years ago. Apply that logic to AI agents and you have a governance crisis waiting to happen. Companies are scrambling to build the plumbing before the water arrives, which is the right instinct but leaves the harder question unanswered: how do you know an agent is still the agent you approved when it's been operating in the wild for months?
Meanwhile, the defense and healthcare sectors are moving first. OpenAI integrated Epic's patient records into ChatGPT Health for clinician workflows. The Defense Department opened ChatGPT access for unclassified administrative work. These aren't experiments anymore. They're institutional adoption, which means liability, compliance, and the slow hardening of products against the use cases that matter most. Google added Gemini integration to Android for motion sickness and accessibility. Sonos crammed agentic automation into speakers because it's "very hot these days," though it made the features opt-in. Alexa learned to alert you about products you might buy. The product roadmaps reveal the incentive structure: consumer features chase trends, enterprise features chase risk mitigation, and infrastructure features chase the power to say no. IFA Berlin opens in two days and will showcase how much of this is theater. The real competition is happening in the invisible layer where agents get audited, where data gets moved, and where someone decides whether a model's output gets acted upon.
Sloane Duvall