The day's headlines reveal a system fracturing under its own velocity. Enterprise AI is moving faster than governance can follow, but the gaps aren't uniform. They're opening where control matters most: between agents, across borders, inside closed platforms, and in the spaces where liability still lives.
The protocol layer is where the real risk is concentrating. MCP, the agent-to-agent communication standard spreading through the industry, carries trust gaps that let malicious prompts propagate sideways through entire fleets. Separately, researchers spotted what appears to be a coordinated agent swarm running on Tencent infrastructure targeting Alibaba's map service, and South Korea's president is warning that AI models are now active tools in bank cyber attacks. These aren't separate problems. They're the same problem materializing at different scales: once agents can talk to each other, the perimeter collapses. Security vendors are already signaling the shift by pressuring Apple to lock down Full Disk Access precisely because AI agents are requesting it aggressively and then abusing it. The industry built the plumbing for autonomous systems to operate at machine speed, then discovered the plumbing has no locks.
Regulation is arriving in fragments, each piece revealing where power actually sits. The EU gets watermarks on ChatGPT text (which editing can defeat anyway), while Norway demands time to write rules for recording glasses. OpenAI is launching visual ads inside image generation results and TikTok is shipping a one-click checkout agent, both moves that embed commerce deeper into the inference loop. Reflection AI released Beam, a 501B sparse Mixture-of-Experts model with 23B active parameters, explicitly pitched at enterprises and sovereign nations that want to build local "AI factories" on proprietary data. This is the real competition: not model quality but infrastructure sovereignty. Chinese models and open-weight alternatives are eroding the moat that closed APIs once provided. Meanwhile, liability questions are still unsettled. Insurers and lawyers are weighing potential massive lawsuits against OpenAI and Anthropic leadership over "rogue" AI behavior, but the legal theory doesn't exist yet to make those claims stick.
The capital markets are starting to price in the uncertainty. Global venture funding hit $159 billion in Q3 2026, a record for billion-dollar rounds, but pension funds are cutting US equities over AI concentration risk and bond markets are selling off corporate debt. Executives are asking CFOs the question that matters: where is the ROI? The answer, for most organizations, is still missing. There's a lag between deployment and value capture, and that gap is where the risk lives. Not in the models themselves, but in the fact that no one has built the measurement systems yet to know whether any of this is actually working.
Sloane Duvall