This week in brief

Every week I come across a lot of AI news — newsletters, deep dives, funding announcements, the odd debate worth arguing with. Here’s what actually stood out to me over the past week, and why I think it matters for anyone building or buying agentic AI in production.

For two weeks I’ve been arguing that value is moving off the model and onto the layer around it. This week the market started pricing that layer — an IPO pitch sized against the whole US economy, the largest SaaS company in the world handing its interface to a model while keeping the data underneath, and open-weight companies becoming acquisition targets.

The big one: a total addressable market the size of the US economy

Chamath Palihapitiya’s weekly note led with this, citing a Wall Street Journal report from 25 August: Anthropic is preparing to tell IPO investors its total addressable market exceeds $30 trillion. US GDP is roughly $30 trillion. So the pitch, stated plainly, is that the annual value of work AI can do is equal to the entire American economy.

The numbers underneath are less abstract. Second-quarter revenue passed $11.5B — reportedly the company’s first profitable quarter, and roughly 14x the same period last year. It is weighing a raise of up to $100B at a valuation near $2 trillion, which would be the largest raise on record, with a prospectus expected after Labor Day and a possible listing in late September or October. Projected 2028 revenue: $190–200B.

My take

Treat the $30T as a market-sizing device, not a forecast — it is the number you pick when your ceiling is “all knowledge work.” But it tells you how the frontier labs now see themselves: not as vendors of a component, but as the substrate under every professional task. If you are an enterprise, that is precisely the reason to be deliberate about which layer you own. A supplier with a $30T self-image is not planning to stay in its lane.

Claudeforce: the interface moves to the model, the data stays put

This was the week’s most instructive story, and it barely registered as an AI story at all. On 26 August Salesforce reported Q2 revenue of about $11.3B (up ~11%) and net income of $3.53B, up from $1.89B a year earlier — including $2.6B from strategic investments, most of it its Anthropic stake. Salesforce Ventures put roughly $50M into Anthropic’s Series C in early 2023; Bloomberg valued that position near $5B in June. The stock rose 22% the next day, its second-best session on record.

The same afternoon, Marc Benioff and Dario Amodei announced Claudeforce. A “Salesforce in Claude” plugin is in pilot with open beta in September and 37 prebuilt sales skills, designed so a seller works inside Claude and never opens a Salesforce screen. Claude also becomes the default model behind Agentforce and Slack AI. Agentforce, billed by usage rather than per seat, is now running at $1.5B annualised, up over 240% year on year.

Benioff has spent the year calling the “SaaSpocalypse” nonsense — arguing frontier models depend on CRM rather than replacing it. Claudeforce is that argument made concrete: give the model the interface, keep the data and the permissions underneath.

My take

This is the harness thesis, executed by the largest player in enterprise software, and it is worth studying rather than admiring. Note what Salesforce conceded and what it refused. It gave up the screen — the thing everyone assumed was the moat — and kept the record of truth, the permission model and the audit trail. It also moved the billing from per-seat to per-use in the process. If your organisation’s AI strategy is a list of tools, ask which of those three you are holding: the interface, the data, or the permissions. Only two of them are defensible.

Open-weight companies became the hottest thing to buy

TechCrunch ran “Open-weight AI companies are the Valley’s hottest acquisition targets” as its lead story twice this week — on 28 and 30 August. The specific datapoint doing the work, flagged in Chamath’s note via Andrew Curran and The Information on 27 August: NVIDIA and Hugging Face held serious acquisition conversations valuing Hugging Face at over $13B, with the deal reported done.

Read that against last week, when Alibaba released Qwen3.8-Max weights and a 27B Apache-2.0 model that runs on a laptop. Two weeks ago open weights were a licensing story. Now they are an ownership story — and the distribution point for open models is being bought by the company that sells the hardware they run on.

My take

If you built a private-AI plan on an open-weight model this year, add one line to your risk register: the steward of your model or its distribution channel can change hands. The weights you already downloaded are yours — that is the whole point of open weights, and it is a genuinely good reason to hold a local copy rather than an API contract. But the roadmap, the licence terms on future versions, and the hosting ecosystem are not yours. Keep the baseline downloadable, and keep it swappable.

Nobody agrees what “agent” means — here is a usable test

The most practically useful thing I read all week was Matt Verlaque’s piece on the five levels of AI in a business, opening with a complaint I share: line up everyone who said “agent” this year and make each define it, and no two answers match. His ladder:

  • Level 1 — the chat tab. Useful, but it wakes up with amnesia, so you haul the context in by hand every time. His test: scroll your last ten conversations and count how often you re-introduced your own company to it.
  • Level 2 — data connections. Same tab, wired into the CRM, email, calendar, call recorder. Level 1 guesses about your business; level 2 reads it. Still furniture until a human starts the conversation.
  • Level 3 — the workflow. Add a trigger: a time, an event, or a number crossing a line. Every workflow is trigger + skill (written down, because nobody is steering) + output that lands somewhere real.
  • Level 4 — the agent. A workflow that cannot tell good work from bad repeats its mistakes forever. Add an eval — a way to score its own output — and you have earned the word.
  • Level 5 — the teammate. The last climb is psychological, not technical: a name, a written job description, deliverables on the same calendar as the humans, and one person accountable for its quality.

And the part I’d put on a wall — four questions for anyone selling you an “agent”: What data is it wired into? What kicks it off? What playbook does it run, and do I get a say in it? Show me how it gets measured and improved. If the answer is “you chat with it,” it is a level-one product with level-four pricing.

My take

I’d add a fifth question, because it is the one that decides whether the thing survives contact with a regulated business: what happens when it is wrong, and who finds out? His level-five point is the real insight though. Teams don’t resist agents because the technology is immature — they resist because nobody owns the output. Ownership is the adoption strategy.

Agents got real permissions, and the risk surface moved with them

Three items from the week that belong together. Instinct raised $350M at a $2.5B valuation (TechCrunch, 27 August) — and in the same week TechCrunch also ran “Instinct’s powerful AI assistant is raising privacy and security concerns.” Separately, OpenAI announced that ChatGPT Work can now sign in to websites on web and mobile without ChatGPT ever seeing the username or password, with examples like setting up utilities for a new apartment and booking appointments. And Meta settled for $18B with 29 states over social media harms to children (26 August).

The pattern: capability and permission are arriving together, funding is arriving faster than the safety conversation, and the regulatory precedent for “you shipped it to consumers and it caused harm” just got priced at eighteen billion dollars.

My take

Credential-free sign-in is genuinely good engineering — the agent acts without holding the secret. But it moves the security question from what does it know to what can it do, and most enterprise AI policies I read are still written for the first question. If an agent can authenticate as your organisation, your controls belong at the action boundary: scoped permissions, human approval on anything irreversible, and a log that shows what it did as your company rather than what it said to a user.

Quick hits

  • One-shot learning reaches robotics. Via Chamath’s note: Dyna Robotics’ Dyna-2 trained on over a million hours of head-mounted human video; Skild AI’s S1 showed that at 1,000 hours of training video written instructions beat a video demonstration on already-practiced tasks, but at 100,000 hours the robot shown a demonstration succeeded 66% of the time on unfamiliar tasks versus 9% for written instructions only; Generalist’s GEN-1.5 attempts a new task from a single demonstration without retraining, averaging 59% across ten tasks while remaining more brittle than task-specific retraining. Demonstration beats description — but only once the scale is there.
  • “You are not a model. Don’t price per token.” An a16z piece in Chamath’s reading list, and the natural sequel to last week’s cost-per-task argument. If you sell AI-powered work, passing token pricing through to your customer exports your supplier’s volatility onto your own P&L.
  • OpenAI’s executive exodus got the TechCrunch analysis treatment on 26 August — worth watching as a signal about how the frontier labs are reorganising, not as gossip.
  • Governance as plumbing, again. Our own Veehive Mind note this week made the case for type-safe validation schemas at the data boundary — the unglamorous half of “responsible AI,” and the half that actually stops bad data reaching an agent.

The theme of the week

Three weeks, one direction. Compute became a tradable asset. Then the scoreboard changed from benchmark scores to cost per task. This week, the layer got a price: a $30T market-sizing pitch, a $2T valuation conversation, $13B for the distribution point of open models, and the largest SaaS company in the world voluntarily giving up its interface to keep its data and permissions. The commodity is the model. The asset is the context, the controls and the record of truth — and Salesforce just showed the whole market which of those it thinks is worth keeping.

What this means if you’re deploying agentic AI

  • Decide which of the three you own. Interface, data, permissions. Salesforce gave away one and kept two. Do the same audit on your own stack.
  • Score your maturity honestly. Run the five levels across your live use cases. Most “agents” in production are level three — a workflow with no eval — and that is fixable in a fortnight.
  • Ask the four questions before you buy. What data, what trigger, whose playbook, how measured. Add: what happens when it’s wrong, and who finds out.
  • Move your controls to the action boundary. Agents that authenticate need scoped permissions, approval on irreversible actions, and an action-level audit log.
  • Keep your open-weight baseline downloadable and swappable. Stewardship of models and their distribution is changing hands; your local copy is the part nobody can reprice.
  • Don’t pass token pricing to your customers. Price the outcome, absorb the volatility, and manage it with the cost ceiling.

Frequently asked questions

What actually makes something an AI agent?

A workable definition from this week: data connections, a written skill or playbook, a trigger that starts it without a human asking, and an evaluation that scores its own output. Miss any one and it is a chat tool or a scheduled workflow, whichever fits.

Why does it matter that Salesforce moved its interface into Claude?

Because it identifies which layer the incumbent believes is defensible. Salesforce conceded the screen and kept the data, the permission model and the audit trail — a signal that the record of truth and its controls, not the user interface, are the durable enterprise asset.

Is it still safe to plan around open-weight models?

Yes, with one caveat. Weights you have downloaded cannot be taken back, which is the core argument for holding a local baseline. But roadmaps, future licence terms and hosting ecosystems can change owners, so keep the baseline swappable rather than betting on a single provider’s continuity.


From Veehive Labs

If you want the week compressed into one sentence: rent the model, own the context, the controls and the record of truth. That is not a contrarian position any more — it is what the largest enterprise software company on earth did in public this week. Veehive Labs is a Dubai-based AI innovation lab and custom AI product development company, building model-independent enterprise AI harnesses, custom agents, RAG pipelines and sovereign, private-AI deployments for regulated and operationally complex organisations across the UAE, KSA, GCC and beyond.

If you’re moving from AI strategy to production, start with a focused AI Discovery Sprint — we map your use case, data, systems, permissions model, cost ceilings, risks and delivery architecture before the build begins.

Build Your Organisation’s AI Capability

Start with a focused AI Discovery Sprint. We will map your use case, organisational knowledge, systems, MCP integrations, security requirements and delivery architecture.

Agentic AI This Week is written by Sathish Jeyakumar, Founder & CEO of Veehive. Bring your preferred model — we make it understand, speak and operate like your organisation.

← All insights