The newest evidence splits cleanly into two stories that only look contradictory. On the revenue side, the numbers are large and concentrated: Palantir reported second-quarter 2026 revenue of 1.935 billion dollars, up 93% year over year, with US commercial revenue at 764 million dollars, up 149%, and US government revenue at 809 million dollars, up 90%, and raised full-year guidance to between 8.150 and 8.158 billion dollars. OpenAI said on July 31 that its models reach more than 1 billion active users and more than 2 million businesses, without specifying a measurement window and without independent audit. Yellow.ai agreed on August 3 to a Bluerock Acquisition Corp. business combination the companies put at roughly 550 million dollars in pro forma equity value, though the same-day SEC filing values the merger consideration at 300 million dollars and closing remains subject to shareholder approval. On the adoption side, the picture is thinner: Booking Holdings reported second-quarter revenue of 7.4 billion dollars, up 8%, and gross bookings of 51 billion dollars, up 9%, while PYMNTS reported that traffic from large language models remained below 1% of room nights and that Booking was applying AI inside customer service and supplier workflows rather than at the top of the funnel. A Box-commissioned Harris Poll of 1,640 IT decision-makers, conducted April 30 to May 8, found 83% saying their organizations were running AI agents while only 36% of those using or testing agents had connected them to trusted internal content across many use cases, 49% reported an AI-related data-exposure incident, and only 34% said they had formal standards governing agent access to company data. Those figures are vendor-commissioned, unweighted and self-reported, but they describe the same gap the product releases are chasing.
Which is the second story: the control plane is now something you buy. Cloudflare open-sourced Cloudflare OS on August 5 under Apache 2.0, a browser-based agent workspace it had run internally that pairs organization-curated context and an isolated code runtime with a governance layer using Gatekeepers and Cloudflare Access, released as early access. The same day it detailed dollar-based spend limits in AI Gateway, in open beta, with identity-driven budgets that attach verified user, group or service-token context via Cloudflare Access still in closed beta and able to block requests or route them to a cheaper fallback model. 1Password launched Privileged Access on July 28, provisioning task-scoped permissions for people, service accounts and AI agents in target systems and removing them at session end. Cyera announced a 1 billion dollar agreement to acquire non-human identity company Oasis Security, which Globes describes as currently a letter of intent subject to a binding agreement. Ethyca launched Astralis on August 4 for real-time purpose-based access checks on agent data paths, running inside the customer's cloud. CrowdStrike connected Falcon AI Detection and Response to Microsoft Copilot Studio and Claude Code on July 30, with the important caveat in its own documentation that the Copilot integration evaluates only tool name and input parameters and that the Claude Code collector cannot see model responses, system prompts or subagent context. Microsoft moved on two fronts, refining Restricted Content Discovery so recently accessed files from protected SharePoint sites stop resurfacing through Search and Copilot discovery, and putting a Purview DLP control that excludes externally received email from Copilot grounding into preview with general availability listed for January 2027. The motivating threat is concrete: Barracuda published a controlled proof of concept on August 4 in which an attacker already holding an employee mailbox used Copilot to find targets, imitate colleagues and escalate to a CEO account, redirecting a simulated 247,500 dollar wire transfer. Underneath all of it, cost discipline stayed unresolved. Reports published July 30 said a failed Amazon Claude Sonnet deployment cost about 1.8 million dollars, ran 860% over budget and went undetected for five months, with Amazon calling the cases isolated learning examples and saying it was developing automated spending guardrails, while Harness's vendor-sponsored 2026 State of AI in FinOps survey of 700 respondents estimated 26% of AI spending wasted, 52% with no clear cost owner and only 20% able to diagnose a doubled bill within hours. OpenAI's price cuts, to 0.20 dollars per million input tokens for GPT-5.6 Luna and 2 dollars for Terra, and ABC's reporting on Australian companies routing simpler work to open-weight Chinese models after Moonshot AI published Kimi K3's weights on July 27, both push in the same direction without solving attribution.