The Executive Briefing

DX Today

The AI Ecosystem in Focus

Published Every Tuesday and Friday

September 4, 2026  ·  Weekly Intelligence

Welcome to the DX Today Executive Briefing

This week the AI economy stopped arguing about whether the spending is real and started arguing about who controls what the spending buys. A semiconductor supplier reported a quarter in which artificial intelligence revenue more than tripled and then guided to a number four times larger two years out. A frontier lab cut the price of the one thing agents consume most and gated its most capable model behind a verification program. The United States government walked into a Manhattan federal courtroom and told a judge that training models on copyrighted work is lawful, and framed the alternative as a national security problem. And a security vendor shipped an offensive model into commercial availability on the theory that the only realistic way to test enterprise defenses is to attack them continuously.

Read together, the four stories describe a market that has moved past proof of concept and into contested infrastructure. The compute is being committed years in advance. The unit economics of agent workloads are being rewritten in public. The legal foundation under every trained model is being litigated with the federal government on one side of the caption. And the security tooling is beginning to assume that both attacker and defender are machines. Below, DX Today cuts through the noise on Broadcom's results, Anthropic's pricing move, the Justice Department's copyright filing, and CrowdStrike's dual use models, with the strategic implication for the executives who have to act on each.

In this edition: Broadcom's AI revenue triples and Hock Tan puts $230 billion on fiscal 2028, Anthropic cuts agent cache pricing by 75 percent and gates its strongest model, the Justice Department tells a federal court that model training is fair use, and CrowdStrike ships an offensive AI model into the Falcon platform.

01

Broadcom's AI Revenue Triples in a Quarter and Hock Tan Puts $230 Billion on Fiscal 2028

Broadcom reported third quarter fiscal 2026 results on September second that make the current AI capital cycle difficult to argue with. Revenue reached $29.6 billion for the quarter ended August second, up 86 percent from the prior year period. AI semiconductor revenue alone came to $16.7 billion, up 221 percent year over year, and semiconductor solutions revenue reached $20.8 billion. Free cash flow was $13.7 billion. Adjusted earnings per share were $3.32, up 96 percent. These are not the numbers of a company selling into an experiment. They are the numbers of a company selling into a buildout that its customers have already committed to funding.

The guidance is where the story turns from a strong quarter into a strategic signal. Broadcom guided fourth quarter revenue to approximately $34.8 billion, which would be growth of 93 percent, with AI semiconductor revenue of $21.7 billion, or growth of 236 percent. On the earnings call, Hock Tan, President and Chief Executive Officer of Broadcom Inc., told analysts the company expects fiscal 2026 AI revenue of $58 billion for the full year, up 186 percent. He then extended the horizon further than the company ever has, saying Broadcom has secured the supply to again double AI revenue to approximately $115 billion in fiscal 2027, and that it has line of sight for fiscal 2028 AI semiconductor revenue to double again to $230 billion.

Executives should read the word secured carefully, because it is the operative claim. A forecast is a hope about demand. Secured supply is a set of signed manufacturing commitments that only make sense if the buyers on the other side have already placed orders they intend to take delivery on. Tan was explicit that the binding constraint is no longer whether Broadcom can build the accelerators. It is whether the customers can install them. He named land, power and data center shell availability as the factors that dictate deployment timing, and pointed to leading edge wafers, substrates and high bandwidth memory as the components the industry is still fighting over.

That inversion matters for anyone planning capacity. For three years the scarce input in the AI stack was silicon, and the enterprise question was how far up the allocation queue a company could buy its way. Broadcom's own account now says the scarce inputs are electricity, real estate and the physical shell that holds the racks. Those are municipal permitting problems, utility interconnection problems and construction labor problems. They move on timelines measured in years and they do not respond to a larger purchase order.

Wall Street's reaction was instructive precisely because it was muted. The fourth quarter revenue guide of $34.8 billion landed slightly below what analysts had modeled, a shortfall of well under one percent, and that was enough to dampen the response to a quarter in which AI revenue more than tripled. When a shortfall of well under one percent can offset triple digit growth, the market has fully priced perfection into the AI infrastructure supply chain. That is a risk condition, not a confidence condition, and it applies to every enterprise whose roadmap assumes the current supply of accelerators continues to expand smoothly.

There is a second order implication for buyers of AI capacity that has nothing to do with owning the stock. Broadcom's custom accelerator business exists because the largest model developers decided they did not want to buy general purpose parts at merchant margins forever. A $115 billion fiscal 2027 forecast for that business is a statement that the hyperscale buyers intend to keep designing their own silicon rather than consolidating on a single vendor. For enterprises, that means the price and availability of inference over the next two years will be set by a small number of vertically integrated platforms, each running on parts nobody else can buy. Portability of workloads across those platforms stops being an architectural nicety and becomes a commercial hedge.

Strategic Takeaway

For CIOs, CTOs and Heads of Infrastructure

Treat Broadcom's commentary as a supply planning document rather than a market update. If the constraint on AI capacity has moved from chips to power, land and buildings, then capacity you have not already contracted for is capacity you may not get on your timeline, and vendor promises of elastic inference should be tested against the physical buildout behind them. Ask your cloud and model providers which specific accelerators your workloads run on through 2027 and 2028, what the contracted floor is, and what happens to your unit pricing if their own deployment slips because a substation was late. At the same time, keep at least one production workload portable across two silicon families, because a market in which each hyperscaler runs on parts nobody else can buy is a market in which switching costs are set by hardware you do not control.

02

Anthropic Cuts Cached Reads by 75 Percent and Reprices the Long Running Agent

Anthropic released Claude Fable 5.1 into general availability on September first, alongside Claude Mythos 5.1, which the company says is available only through its trusted access programs. The headline for most readers was the benchmark table. The headline for anyone running agents in production was a single line in the pricing section: cache reads now cost $0.25 per million tokens, down from $1.00 on the previous model, a 75 percent reduction. Input and output pricing did not move, holding at $10 and $50 per million tokens respectively.

That asymmetry is the point. In a chat product, cached tokens are a rounding error. In an agent that runs for hours, rereads the same repository, the same policy documents and the same tool schemas on every turn, cached reads are the dominant line item on the invoice. Anthropic put its own numbers on the effect, saying customers should see roughly 25 percent lower cost on typical workloads and up to roughly 45 percent lower cost on agentic tasks. Nothing about the model got cheaper to think. The part that got cheaper is the part that remembers, which is exactly the part that long running automation cannot avoid paying for.

The capability numbers support the same reading. Anthropic reports that Fable 5.1 scored 52.6 percent on Terminal-Bench-Science 0.1, against 24.7 percent for the prior Fable 5, and 55.8 percent on Terminal-Bench 4.0, against 42.0 percent. It reports 41.7 percent on OSWorld 2.0 under strict scoring and 60.9 percent on Humanity's Last Exam without tools. The pattern across those results is that the largest gains show up on the long horizon, tool using, multi step evaluations rather than on single turn knowledge tests. A model that is better at sustained tool use, paired with a pricing change that specifically discounts sustained context, is a product decision aimed squarely at the workloads enterprises have been piloting all year.

The distribution and access story is equally deliberate. Fable 5.1 is available through the Claude Platform and through cloud marketplaces including Amazon Web Services and Google Cloud, which puts it inside procurement paths most large enterprises have already approved. Mythos 5.1 goes the other way. Anthropic says it is available to vetted cyberdefenders and life scientists through trusted access programs, and that the company is currently able to offer it only to a set of United States organizations. The Life Sciences Verification Program is described as an invite only beta with reduced biology safeguards for advanced researchers, and the Cyber Verification Program offers reduced cyber safeguards for defensive security work.

That is a two tier market being built in the open, and executives should recognize the shape of it. The generally available model is the one that goes into procurement, into cloud marketplaces and into everyday production. The most capable model in the sensitive domains is gated behind identity verification and organizational vetting, with geography as an additional filter. Access to frontier capability in cybersecurity and life sciences is becoming a credential you apply for rather than a price you pay, and companies that expect to need it should be starting that application process now rather than at the moment of need.

Anthropic also shipped safeguards changes that speak directly to a complaint enterprise teams have been making for two years, which is that safety filters break legitimate work. The company says cyber protections now create about 60 percent fewer interventions per Claude Code session than the previous version, and that biology safeguards flag benign elementary biology and medical questions about 85 percent less often. Alongside the models, Anthropic introduced Enterprise Frontier Safeguards, which lets enterprise customers keep Claude safety and misuse monitoring data inside their own Amazon Web Services, Azure or Google Cloud environments rather than handing that telemetry to the vendor. For regulated buyers, that last item may matter more than any benchmark on the page, because it removes a data residency objection that has been quietly blocking deployments in banking and healthcare.

Strategic Takeaway

For Heads of AI Platform, FinOps Leaders and Chief Data Officers

Reprice your agent roadmap against cached context rather than against headline token rates, because that is where the vendor just moved and where your bill actually lives. Pull the last quarter of usage, separate cache reads from fresh input, and rerun the business case for the automations you shelved as too expensive, since a 75 percent cut on the dominant line item changes which workflows clear the bar. Then treat access as a separate planning problem from price: if your security or research organization will need frontier capability in cyber or life sciences, start the verification process now, and use the arrival of customer controlled safety telemetry to reopen deployments your risk function blocked on data residency grounds.

03

The Justice Department Tells a Federal Court That Model Training Is Fair Use, and Calls the Alternative a Security Risk

On September first the United States Department of Justice filed a statement of interest in the consolidated copyright litigation against OpenAI, urging the court to hold that using copyrighted works to train large language models is fair use. The case is In re OpenAI, Inc. Copyright Infringement Litigation in the United States District Court for the Southern District of New York. The filing was signed by Associate Attorney General Stanley E. Woodward Jr., Assistant Attorney General Brett Shumate of the Civil Division, and Senior Counsel Michael Weisbuch. It is unusual for the federal government to weigh in on a private copyright dispute at all, and rarer still for it to do so on the side of the defendant.

The substantive argument is narrower than the headlines suggest, and the narrowness is where the value is for executives. The government focused on whether the use of copyrighted works at the training stage constitutes fair use, arguing that training is highly transformative because the process converts text into statistical patterns rather than using the works for the purpose they were created to serve. The filing did not extend that reasoning to everything a model does. It stated plainly that at the output rather than training stage, certain uses may not be transformative if the model reconstructs and disseminates an original copyrighted work.

That distinction is the practical guidance buried in the brief. The federal government's position, as filed, is that learning from a corpus is defensible and that regurgitating a work is a separate question the court should treat separately. Any enterprise fine tuning on licensed or scraped material should read that as a map of where the remaining exposure sits, which is at retrieval, at generation and at anything that reproduces a recognizable original, not at the act of training itself.

The competitive argument is more contested. The Justice Department warned that a licensing requirement would mean only the largest technology companies might have the capital necessary to pay licensing fees, and that such a regime would disproportionately benefit legacy media outlets. It offered an example that has already drawn criticism, suggesting that authors with limited resources can use large language models to compete by, for example, generating an image to accompany an article that would otherwise require a photographer or a license. The government also framed the stakes in national security terms, warning that a ruling for the plaintiffs would threaten national security and hand a competitive advantage to foreign adversaries.

The plaintiffs are not a single aggrieved publisher. The consolidated litigation includes The New York Times, The Intercept, book authors, and newspapers owned by Alden Global Capital. A Times spokesperson, Graham James, responded that both AI companies and creators can thrive, and that AI companies simply need to pay fairly for the content that makes their products possible, as copyright law requires. That is the entire dispute compressed into a sentence: not whether models may learn, but whether learning at commercial scale from someone else's work is a taking that requires payment.

For enterprise leaders, the filing changes the risk calculus without settling it. A statement of interest is advocacy, not a ruling, and the court is free to disagree. What it does establish is that the executive branch has staked out a public position that training is lawful, which lowers the probability of a federal legislative or regulatory move against training in the near term and raises the probability that the fight continues to be resolved case by case in the courts. Companies that paused generative deployments waiting for legal clarity should notice that clarity is not arriving as a single settled rule. It is arriving as a slowly forming consensus about training, with the messier questions about outputs, data acquisition and storage still fully open.

Strategic Takeaway

For General Counsel, Chief Risk Officers and Heads of AI Governance

Move your copyright exposure analysis downstream, because the government's own filing separates training from outputs and concedes that outputs reproducing an original work may not be transformative. That means the controls worth funding this quarter are output side: retrieval provenance, similarity and regurgitation testing before generated material is published or shipped, and logging that can demonstrate what a model was asked and what it returned. Keep the licensing question live rather than closed, since a statement of interest is advocacy and the court has not ruled, and make sure any indemnity you hold from a model vendor actually covers output infringement and not merely the training corpus, because that is precisely the boundary the Justice Department drew.

04

CrowdStrike Ships an Offensive AI Model Into Its Own Platform and Pairs It With a Defender

CrowdStrike used its Fal.Con conference to launch SafeMind, an agentic system that pairs an offensive model called Red Tempest with a defensive model called Blue Solano. The two run against each other in a closed loop inside customer environments, with the offensive model probing for attack paths while the defensive model closes them, repeating until the offensive side stops finding a way through. The company built the models on NVIDIA Nemotron open models with NVIDIA as its AI design partner, and CoreWeave provides the training and inference infrastructure behind them.

The training corpus is the part competitors will find hardest to answer. CrowdStrike says SafeMind was trained on Falcon sensor telemetry, its own threat intelligence, Falcon Complete managed detection and response annotations, and fifteen years of incident response fieldwork. That last input is the differentiator. Publicly available security data teaches a model what attacks look like after they have been written up. Incident response fieldwork teaches it what attackers actually did inside real networks, including the steps that never made it into a disclosure. A general purpose frontier model has no access to that material at any price.

The performance figures come from CrowdStrike and should be read as vendor claims until independently tested, but they are specific enough to hold the company to. CrowdStrike says SafeMind delivers a 29 percent higher detection rate, six times faster remediation, and 99 percent cost savings compared with frontier models. The cost claim is the one security buyers should press on, because it implies the economics of continuous automated red teaming have changed by an order of magnitude, which is the only condition under which running an offensive model against production continuously becomes affordable rather than aspirational.

George Kurtz, founder and Chief Executive Officer of CrowdStrike, framed the launch as bringing offensive and defensive models together in a system trained on the company's own cyber data, and Bartley Richardson, the company's Chief AI and Autonomous Systems Officer, described the goal as letting defenders act at machine speed. Jensen Huang, founder and Chief Executive Officer of NVIDIA, and Michael Intrator, Chief Executive Officer of CoreWeave, appeared in the announcement as the compute and model partners. SafeMind runs natively in the Falcon platform, with standalone access offered through a program called Project QuiltWorks.

Alongside SafeMind, CrowdStrike announced Falcon Guardian, which is designed to shrink the blast radius of an AI agent. That pairing tells the more interesting story. The same vendor is simultaneously selling a system that attacks your environment autonomously and a system that limits what your own autonomous agents can reach when they misbehave. Both products assume the same premise, which is that machine speed actors are now on both sides of the perimeter and that human review cycles are too slow to sit in the middle of either one.

The governance question this raises is not hypothetical and boards should ask it directly. A commercially available offensive model trained on fifteen years of real intrusion data is a capability that does not care which direction it is pointed. CrowdStrike's answer is containment by architecture, keeping the offensive model inside the Falcon platform and behind a vetted access program rather than shipping it as a general tool. That is a reasonable answer and it is also a promise that now has to hold, because the same logic that makes continuous automated red teaming valuable to a defender makes it valuable to everyone else. Enterprises adopting this class of tooling should be asking who at the vendor can authorize the offensive model to run, against which assets, with what approval trail, and what the failure mode looks like if that authorization is ever obtained by someone it was not meant for.

Strategic Takeaway

For CISOs, Heads of Security Engineering and Audit Committees

Evaluate autonomous red teaming on the assumption that it is arriving whether or not you buy it, since the same economics that make it affordable to defenders make it affordable to attackers. Before any pilot, define the authorization boundary in writing: who can point an offensive model at production, which asset classes are in scope, what the approval trail looks like, and how a run is stopped mid execution. Demand independent validation of the detection and remediation claims rather than accepting vendor benchmarks, and pair any offensive capability you adopt with agent containment controls, because an environment that can be attacked at machine speed by your own tooling needs a blast radius limit that does not depend on a human noticing in time.

The Analysis

The Bottom Line

The through line this week is that the AI market has started pricing control rather than capability. The fiscal 2028 AI target of $230 billion that Hock Tan set on Broadcom's earnings call is only credible because customers have already committed to the buildout, and the company's own account of the constraint has moved from silicon to substations. Anthropic did not cut the price of intelligence, it cut the price of memory, which is the input long running agents cannot stop consuming, while placing its strongest model behind a verification program rather than a price list. Both are decisions about who gets access on what terms, made by suppliers with enough leverage to make them stick.

The same pattern holds on the legal and security side. The Justice Department did not argue that everything a model produces is lawful. It argued that training is transformative and then explicitly reserved the question of outputs that reconstruct an original work, which draws the line exactly where enterprise exposure actually sits. CrowdStrike did not release an offensive model into the world. It kept one inside its own platform and sold containment for agents alongside it. In each case the interesting decision was about boundaries, and in each case the boundary was set by the vendor or the government rather than by the buyer.

For executives the practical conclusion is consistent across all four stories. The questions that decide outcomes over the next eighteen months are no longer about model quality, which is improving fast enough that any specific benchmark lead is temporary. They are about contracted capacity, unit economics on sustained context, the provenance of what your systems output, and the authorization boundary around any autonomous capability you deploy. Those are procurement, finance, legal and governance questions, and none of them are answered by picking a better model.