AI to ROI News & Analysis: March 13, 2026
More Anthropic, Oracle puts up big numbers, NVIDIA builds open-source models + agents, and a lot more
The Biggest AI News This Week
🛒 Anthropic Launches Claude Marketplace for Enterprise AI Procurement
💰 Oracle Cloud Revenue Beats on AI Demand and CapEx Tops Estimates
🤖 NVIDIA at GTC 2026 Preview: Open Models, Agentic Software, and the Full-Stack Play
🖌️ Microsoft Launches Copilot Cowork, Powered by Anthropic’s Claude
🪖 Anthropic Sues the Department of Defense With Billions at Stake
🌏 AMI Labs Raises $1.03 Billion to Bet Against Large Language Models
⚖️ Amazon Wins Preliminary Injunction That Prevents Perplexity’s Comet Shopping Agent from Accessing Its eCommerce Site
🎼 OpenAI Acquires Promptfoo to Embed Security Into Its Enterprise Agent Platform
🃏 Definitely Not AI: Furby, the $100 hot dog, the Brady Bunch House, dinosaurs with bad habits, and a brutally honest lion.
Anthropic Launches Claude Marketplace for Enterprise AI Procurement
Anthropic launched the Claude Marketplace, giving enterprise customers a way to purchase third-party software built on Claude and charge it against their existing Anthropic spending commitments. The platform launched in limited preview with six partners: GitLab, Harvey, Lovable, Replit, Rogo, and Snowflake. Anthropic is not taking a commission on transactions at launch, a deliberate departure from the model used by AWS and Microsoft Azure marketplaces.
What It Is
Claude Marketplace is an enterprise procurement platform that lets organizations with an existing Anthropic spend commitment apply a portion of that commitment toward Claude-powered tools offered by external partners. Anthropic handles all invoicing, including for partner products, and acts as the central billing relationship for enterprise customers.
Partner purchases count against a portion of a customer’s existing Anthropic commitment. Anthropic does not take a commission on marketplace transactions at launch, per SiliconAngle (citing Bloomberg). Enterprises not yet on a committed contract must contact Anthropic to participate. New partners can join a waitlist.
Why It Matters
The marketplace consolidates AI procurement, reducing the “shadow procurement” problem where teams adopt tools that finance and IT have not approved. It also positions Anthropic as a distribution layer, not just a model provider, for enterprise software.
OpenAI launched a comparable ChatGPT App Directory in December 2025, focused on consumer and individual workflows. Anthropic’s marketplace targets procurement officers and CIOs, further up the enterprise stack. AWS, Azure, and Salesforce run established software marketplaces that take commissions. Source:
Launch Partners
What Vendors & Analysts Say
“The Claude Marketplace lets Cox Automotive teams move faster by extending our Anthropic investment into the partner tools we need, with simplified procurement and the confidence that it all works together.” Marianne Johnson, Chief Product Officer, Cox Automotive
“Organizations can now use their existing Anthropic commitment to purchase GitLab and orchestrate agentic AI across the entire software lifecycle, while maintaining enterprise-grade security, quality, and governance.” Gitlab
The launch “positions Anthropic as a procurement and distribution layer for Claude-powered enterprise software, not only a model and API provider.” Alex Smith, analyst at Futurum Research
The Takeaway
Anthropic is moving up the enterprise stack from model provider to platform company. By handling invoicing, curating partners, and consolidating spend, Anthropic becomes the central commercial relationship for an enterprise’s Claude-based software, not just the API underneath it. This mirrors the AWS and Azure marketplace model, with the notable difference that Anthropic is forgoing commissions at launch to accelerate adoption.
The marketplace inverts the SaaS disruption narrative. Prior Claude product launches triggered SaaS stock selloffs on fears that Claude would replace enterprise software. The marketplace positions existing SaaS vendors (GitLab, Snowflake, Harvey) as complements rather than targets, distributed through Anthropic’s own channel.
Vendor lock-in is a legitimate concern. Analysts and trade press note that routing both model access and application procurement through a single provider deepens dependency. Only Claude-powered applications qualify for the marketplace, creating an incentive structure that favors Anthropic-integrated software over competitors.
Oracle Cloud Revenue Beats on AI Demand and CapEx Tops Estimates in Q3-26
Oracle reported superior Q3-26 results on March 10, 2026, beating analyst consensus estimates for both revenue and earnings. Cloud infrastructure revenue grew 84% year-over-year to $4.9 billion, ahead of the 79% analysts had forecasted, and above the 68% growth rate from the prior quarter. Oracle shares rose as much as 15% in Wednesday trading.
Key Financial Results
Management Commentary
“Demand for AI and advanced compute will continue to expand broadly across the economy.” Co-CEO Clay Magouyrk
“Some smaller or single-focused SaaS players may well be disrupted. But Oracle will not be among them.” Co-CEO Mike Sicilia
Analyst Commentary
Oracle’s decision to maintain its $50 billion full-year capital expenditure outlook “could address concerns about overspending that have plagued Oracle and other cloud infrastructure providers.” Anurag Rana, analyst at Bloomberg Intelligence
Forward GuidanceThe Takeaway
The Takeaway
Oracle produced superior financial performance in Q3-26 and provided a positive forward outlook; however, the company’s hyperscaler future is tied directly to the success of OpenAI, its ability to bring data center capacity online on time and on budget, and its access to advanced AI chip technologies. If OpenAI falters, Oracle will face a substantial cash crunch, given that it has procured more than $100 billion in debt financing (with plans to raise $50 billion more) to support its hyperscaler ambitions.
NVIDIA at GTC 2026 Preview: Open Models, Agentic Software, and the Full-Stack Play
NVIDIA’s strategic shift at GTC 2026 is not primarily about faster chips; it is about owning the layer above the chips. For three years, Jensen Huang built the dominant AI training platform. Now, with inference workloads eclipsing training in volume, NVIDIA is moving to control how AI agents run, reason, and orchestrate tasks across enterprise infrastructure.
The motivation is vertical integration:
If enterprises standardize on NVIDIA’s open models and agent platform, demand for NVIDIA compute follows.
Nemotron 3 Model Family
NVIDIA released Nemotron 3 Nano in December 2025 and Nemotron 3 Super on March 11, 2026. Super is a 120-billion-parameter hybrid Mamba-Transformer mixture-of-experts model with 12 billion active parameters per token and a one-million-token context window. It is designed specifically for multi-agent workloads. A third model, Nemotron 3 Ultra, is expected in H1 2026; no parameter specifications have been disclosed. The models are already in deployment. Perplexity, Palantir, CrowdStrike, Siemens, and ServiceNow are among the named early adopters.
NemoClaw and the NeMo Agentic Platform
NemoClaw is NVIDIA’s forthcoming open-source enterprise agent platform, first reported by Wired on March 9 and confirmed by CNBC and The Information. Jensen Huang is expected to formally announce the platform during his March 16 GTC keynote. NemoClaw integrates three existing NVIDIA components:
The NeMo framework for agent reasoning pipelines and fine-tuning.
The Nemotron 3 model family is the default inference backbone.
NIM microservices for deployment — making it more of an orchestration layer and packaging decision than a ground-up software build. NIM is optimized for NVIDIA’s CUDA software platform.
NemoClaw builds enterprise-grade security and privacy tooling as standard features. NVIDIA has reportedly been in discussions with Salesforce, Cisco, Google, Adobe, and CrowdStrike about early access in exchange for code contributions. No formal agreements have been announced by any of these companies.
The Takeway
Open weights as a competitive wedge against China. Nemotron 3 Super’s published training datasets, RL environments, and permissive license are a direct counter to DeepSeek, Alibaba Qwen, and Moonshot Kimi, all of which have built community adoption through open-weight releases. NVIDIA is using the same playbook, but combining it with commercial hardware credibility and enterprise-grade distribution.
Software revenue is the new test. NemoClaw and the Nemotron platform represent NVIDIA’s first serious attempt to convert that infrastructure dominance into recurring software revenue. Enterprise buyers should evaluate whether NemoClaw’s hardware-agnostic claim is validated in practice before making it a strategic dependency.
Microsoft Launches Copilot Cowork - Powered by Anthropic’s Claude
Microsoft announced Copilot Cowork, a cloud-based AI agent built in collaboration with Anthropic that executes long-running, multi-step work across Microsoft 365 applications on a user’s behalf. The launch is the centerpiece of Wave 3 of Microsoft 365 Copilot, a sweeping platform update designed to shift Copilot from a chat assistant to an autonomous execution engine. The stakes for Microsoft are high:
As of early 2026, only 15 million users - roughly 3% of the M365 installed base - hold paid Copilot licenses, and the Wave 3 announcement is explicitly aimed at accelerating that adoption.
What Copilot Cowork Does
Copilot Cowork combines Anthropic and Microsoft technologies. Anthropic’s contribution to Copilot Cowork is threefold:
Claude provides the reasoning model,
The same agentic feature set that powers Claude Cowork underlies the Microsoft implementation.
Claude is available inside Copilot Chat.
There are some key differences, too. Unlike Claude Cowork, which runs locally, Microsoft’s Copilot CoWork deploys in the cloud within a customer’s M365 tenant, giving it access to the full enterprise data graph that Claude Cowork cannot see.
Enterprises deeply embedded in the Microsoft 365 ecosystem are the ideal targets for Copilot Cowork. For a Fortune 500 company whose employees live in Outlook, Teams, and SharePoint all day, the value proposition is compelling:
An AI agent that already understands their organizational context, operates within their existing security and compliance framework, and doesn’t require employees to adopt a new application or manage local file permissions.
About Wave 3
Wave 3 provides agentic functionality that extends beyond Copilot Cowork, with new agentic features now available in Word and Excel. Agentic access to Outlook and PowerPoint will roll out over the coming months. Using the Wave 3 agentic features, Copilot Cowork users can direct meaningful, multi-step workflows directly inside the M365 environment. For example:
A user can say, “Prepare for my client meeting next week.”
Copilot Cowork will reason over Outlook threads, Teams conversations, SharePoint files, calendar history, and Excel workbooks.
It will then draw on Work IQ, Microsoft’s intelligence layer that maps a user’s work relationships and content.
Finally, Copilot Cowork will then perform the necessary tasks to support the meeting, drafting the appropriate documents, pulling data into spreadsheets, scheduling the meeting, or sending emails, all in the background.
Additional Wave 3 functionality enables third-party agents from Adobe, Monday.com, and Figma to connect to the Copilot environment via open MCP standards. Plus, Agent 365, Microsoft’s control plane for observing, securing, and governing all AI agents across an organization, including those from third-party vendors, goes generally available on May 1, 2026. It functions as the governance and audit layer within which Copilot Cowork operates.
Purchasing Options
The new Microsoft 365 E7 “Frontier Suite” bundles M365 Copilot, Agent 365, Entra Suite, Defender, Intune, and Purview into a single package at $99/user/month, below the sum of individual list prices. Copilot Cowork itself is included in the existing $30/user/month M365 Copilot license, with additional capacity available for purchase. Copilot Cowork is currently in Research Preview with a limited number of customers; broader access through the Frontier program is expected in late March 2026.
What the Analysts Say
Analyst reactions are mixed:
Copilot Cowork “taps into the growing hype around Anthropic’s Claude Cowork concept” and “significantly extends it by embedding the capability across Microsoft 365 applications rather than keeping it as a desktop-centric tool.” Also cautioned that adoption risk remains: “Enterprise leaders tell me that Copilot, though backed by OpenAI’s models, consistently underperforms ChatGPT and ChatGPT Enterprise.”
J.P. Gownder, VP and Principal Analyst, Forrester Research
“[Copilot Cowork] does not support local computer use, cannot interact directly with local files or applications, and lacks native integrations with third-party tools and services. These omissions constrain Cowork’s autonomy and limit its ability to operate end-to-end workloads outside Microsoft 365.”
The Takeaway
Microsoft’s multi-model strategy is now structural. While OpenAI remains the primary model provider across most Microsoft products, Wave 3 makes Anthropic a co-equal option inside the company’s flagship enterprise suite. Claude powers Copilot Cowork’s reasoning and is now selectable in mainline Copilot Chat. Enterprise buyers should treat model diversity as a durable feature of the Microsoft platform, not a temporary hedge against OpenAI.
Agent 365 and E7 are the real enterprise play. Copilot Cowork is the attention-getter, but Agent 365 and the E7 bundle ($99/user/month) are the products with the most significant procurement implications. Agent 365 provides IT and security teams with a single governance layer for all AI agents across an organization, including those built on non-Microsoft platforms. Enterprises already managing a growing inventory of AI agents should evaluate Agent 365 independently of Copilot Cowork, and assess whether E7 represents a consolidation opportunity relative to their current per-product spend on M365, Copilot, Defender, Entra, and Purview.
Anthropic Sues the Department of Defense With Billions at Stake
On March 9, 2026, Anthropic filed two federal lawsuits against the Trump administration, seeking to reverse the Pentagon’s February 27 designation of the company as a national security supply-chain risk. The designation represents the first time an American company has received that label.
The lawsuits, filed in the Northern District of California and the D.C. Circuit Court of Appeals, allege First Amendment retaliation and an unlawful exercise of executive power. At a March 10 hearing before U.S. District Judge Rita F. Lin, Anthropic’s CFO estimated the designation could reduce the company’s 2026 revenue by hundreds of millions to billions of dollars. The judge moved the injunction hearing from April 3 to March 24, signaling the urgency of the case.
What the Lawsuits Say
Anthropic’s California complaint alleges the Pentagon’s designation (issued under 10 U.S.C. § 3252) was issued without the notice, written determination, or congressional notification that procurement law requires.
The suit argues the designation is retaliation for protected speech, specifically Anthropic’s public position on AI safety, and that the administration exceeded the authority granted by Congress. The lawsuit reads: “The Constitution does not allow the government to wield its enormous power to punish a company for its protected speech.”
The D.C. Circuit filing directly challenges the legal authority invoked by Defense Secretary Pete Hegseth. Anthropic is seeking to vacate the designation, block enforcement, and require federal agencies to withdraw stop-use directives.
An Anthropic spokesperson told CNBC on March 9: “Seeking judicial review does not change our longstanding commitment to harnessing AI to protect our national security, but this is a necessary step to protect our business, our customers, and our partners.”
Anthropic has some Influential Supporters
More than 30 researchers and engineers at OpenAI and Google DeepMind filed an amicus brief in their personal capacities on March 9, arguing the designation “could harm U.S. competitiveness in the industry” and that existing AI systems cannot “safely or reliably handle fully autonomous lethal targeting.”
Microsoft filed its own brief urging a temporary restraining order, warning that removing Anthropic software would impose significant compliance costs on defense contractors and leave some with no alternatives.
Google, Amazon, and Apple each confirmed that Anthropic tools remain available on their platforms for non-defense work.
Separately, a bipartisan group of congressmen has publicly criticized the Pentagon’s handling of the dispute as “sophomoric,” per Axios.
Other Actions the Government Could Take
During the March 10 hearing, Anthropic’s attorney asked the court for assurances that the government would not retaliate further before the March 24th hearing, specifically, that no executive order would be issued to formally codify the agency-wide ban. The DOJ’s James Harlow declined, stating he was “not prepared to offer any commitments.”
News reports cited in the hearing indicated the White House was preparing an executive order to formally instruct federal agencies to remove Anthropic’s AI from all operations. Earlier, Defense Secretary Pete Hegseth had threatened to invoke the Defense Production Act to compel Anthropic’s cooperation, but the administration pivoted to a supply-chain risk designation instead.
Claude Uptake Since the Dispute Began
Claude reached #1 in U.S. App Store free downloads on February 28, rising from #42 at the start of 2026, per 9to5Mac / Anthropic. An Anthropic spokesperson told TechCrunch that:
Daily sign-ups broke all-time records every day during the week of February 28
Free users grew more than 60% since January
Paid subscribers more than doubled year-to-date.
Apptopia estimated that Claude downloads rose 220% and that ChatGPT uninstalls increased approximately 295% following news of OpenAI’s Pentagon contract, per TechCrunch.
Analyst & Expert Commentary
“They just touched the third rail with this. For Anthropic, enterprises are now putting pencils down on projects because the government sees them as a supply chain risk. This is a nightmare situation for Anthropic…. I think the worry for investors and the industry is the unintended consequences. I believe there potentially could be more fallout from this. Being on the wrong side of the White House and the Pentagon is not a good thing.”
Dan Ives, analyst, Wedbush Securities
“They don’t point to any technical failing; they don’t point to any hack. They say things like ‘They’re arrogant’ and ‘We don’t want you telling the DoD what to do in some hypothetical situation that hasn’t happened yet.’”
The Takeaway
The dispute is an existential stress test for Anthropic’s safety-first strategy, and, so far, it has produced an apparent commercial tailwind. The designation threatens federal revenue and rattles enterprise customers (100+ have raised concerns with Anthropic), but it also drove a surge in consumer and commercial adoption. Anthropic’s positioning as the principled alternative to OpenAI strengthened in the short term. The long-term risk is that a sustained government-wide ban strains relationships with the government’s largest cloud partners/investors (Amazon and Google), both of which are significant federal contractors.
The legal outcome will set a precedent for every federal AI contractor. Anthropic’s lawsuits argue that the supply-chain risk designation cannot be used as a policy punishment for a domestic company’s protected speech. If the court agrees, it limits the government’s ability to coerce AI vendors into loosening safety guardrails. If the government prevails, it establishes that agencies can effectively blacklist companies whose policies the administration dislikes.
AMI Labs Raises $1.03 Billion to Bet Against Large Language Models
Yann LeCun is a Turing Award winner and the architect of Meta’s AI research operation for 12+ years, where he oversaw the development of Llama and PyTorch before leaving in November 2025. He has spent years arguing publicly that large language models are structurally incapable of genuine reasoning. His view:
LLMs predict tokens, not consequences.
Now his new company, Advanced Machine Intelligence Labs (AMI Labs), is building an alternative architecture - JEPA, the Joint Embedding Predictive Architecture he first proposed in 2022 - that learns abstract representations of how the world works rather than predicting text word by word.
The JEPA architecture is architecturally distinct from current LLMs in one key respect: Rather than generating predictions pixel-by-pixel or token-by-token, JEPA learns compressed, abstract representations of future states. The model ignores unpredictable details and focuses on structure. Whether that translates into commercial reliability at scale has not yet been demonstrated. The product roadmap consists of a first model, AMI Video, with robotics, manufacturing, and wearables as initial target verticals.
$1.03 Billion!!!! Seed Round
On March 10, 2026, AMI Labs announced a $1.03 billion seed round at a $3.5 billion pre-money valuation, in what could be the largest seed round ever raised by a European startup. AMI Labs attracted an august group of tier one investors:
● The round was co-led by Cathay Innovation, Greycroft, Hiro Capital, HV Capital, and Bezos Expeditions.
● Strategic investors include NVIDIA, Samsung, Temasek, Toyota Ventures, and French industrial groups Publicis Groupe and Groupe Industriel Marcel Dassault.
● Individual angels include Eric Schmidt, Jim Breyer, Mark Cuban, Xavier Niel, and Tim and Rosemary Berners-Lee.
AMI Labs was founded just four months before the announcement. The company currently has twelve employees.
Funds will be directed to compute and talent across four offices: Paris (headquarters), New York (where LeCun is a professor at NYU), Montreal, and Singapore.
AMI Labs has no near-term revenue plans. CEO Alexandre LeBrun — co-founder and former CEO of medical AI company Nabla — has indicated that partner discussions are 1–2 years out, with general-purpose systems targeting a 3–5 year horizon. AMI Labs plans to open-source code and publish research as it goes.
The Competitive Landscape Is Heating Up
The competitive context is nascent but accelerating. Fei-Fei Li’s World Labs raised $1 billion in February 2026, targeting 3D spatial intelligence.
European startup SpAItial raised a $13 million in seed funding for a related approach.
The established LLM players, including OpenAI, Google DeepMind, Anthropic, and
Meta’s own research division is the implicit incumbent AMI that is betting will hit a ceiling. LeBrun has said he expects ‘world model’ to become the next AI buzzword within six months, with many companies adopting the label without the underlying architecture.
Investor & Participant Commentary
The Takeaway
The technical thesis is credible but contested. LeCun and his team at AMI Labs maintain that LLMs cannot plan, reason about physical causality, or avoid hallucination in high-stakes settings. This theory has strong empirical support across domains, such as robotics and medical AI. JEPA is a serious research program, not a marketing reframe. But the LLM incumbents are not standing still: Reasoning-focused models, post-training reinforcement learning, and tool-use architectures are all chipping away at this theory.
Execution risk is high, and the timeline is long. AMI Labs closed a $1.03 billion round with 12 employees, no product, and no revenue. The funding is driven by LeCun’s track record, not the company’s business model. LeBrun has been explicit that this is a multi-year fundamental research program. Enterprise buyers evaluating world-model vendors should treat any predictions of late 2026 or 2027 product releases in the world model market with significant caution.
Worth tracking for robotics, manufacturing, and healthcare buyers. If world models prove out, the first beneficiaries are likely enterprises operating in physical environments where LLMs already fail: Unstructured robotic manipulation, real-time industrial process control, and clinical decision support, where hallucination is not acceptable. Enterprise technology buyers in those verticals should monitor AMI Labs’ open-source releases and academic publications as a leading indicator of whether world models will live up to their promises.
Amazon Wins Preliminary Injunction that Prevents Perplexity’s Comet Shopping Agent from Access its eCommerce Site
On March 9, 2026, a federal judge in San Francisco issued a preliminary injunction blocking Perplexity AI from using its Comet browser agent to access password-protected sections of Amazon‘s platform and complete purchases on behalf of users. The ruling is not a final verdict, but it is one of the first significant legal rulings in the fast-moving agentic commerce market. As the case moves forward, the central issue will be whether a user’s authorization is sufficient to permit an AI agent to access a third-party platform, or whether the platform’s explicit consent is also required. For now, the court’s answer is that both are needed.
How We Got Here
Here’s the chain of events that got Amazon and Perplexity into the courtroom:
The dispute began in November 2024, when Amazon first warned Perplexity (on at least five separate occasions) to stop Comet from accessing its platform.
Amazon’s core allegation was that Perplexity had deliberately configured Comet to disguise its automated sessions as ordinary Google Chrome browser traffic, evading detection rather than transparently identifying itself as a bot.
When Amazon deployed a technical barrier to block Comet’s access in August 2025, Perplexity released a software update within 24 hours to circumvent it.
Amazon filed suit on November 4, 2025, in the Northern District of California, alleging violations of the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act.
Amazon also cited October 2025 research from Brave that documented prompt-injection security vulnerabilities in Comet and evidence that it spent more than $5,000, the CFAA threshold, of employee time to build systems to detect and block Comet’s access.
Perplexity called the lawsuit “a bully tactic” and argued in its legal filings that Comet merely automates what users have explicitly directed it to do.
Perplexity argued that user consent should be sufficient, and that Amazon’s actual concern was not security but the loss of advertising revenue when AI agents bypass sponsored listings. Amazon generated $68.6 billion in advertising revenue in 2025; an agent that routes directly from search query to checkout skips every sponsored result along the way.
Amazon denied the advertising framing, citing customer trust and data security as its primary concerns, and noting that CEO Andy Jassy has said Amazon expects to partner with third-party agents over time — but on its own terms, with agents identifying themselves transparently.
What the Judge Said
Senior U.S. District Judge Maxine Chesney granted the preliminary injunction based on several factors:
Perplexity’s Comet browser agent accessed Amazon accounts “with the Amazon user’s permission, but without authorization by Amazon.”
The court rejected Perplexity’s argument that user consent is sufficient, finding that platform authorization is a separate and equally required condition.
Chesney found that Amazon satisfied all four legal requirements for a preliminary injunction, including likelihood of success on the merits and irreparable harm.
Under the order, Perplexity must cease all Comet access to Amazon’s protected systems and destroy Amazon customer data already collected. The injunction was stayed for seven days to allow an appeal. The judge also said that the ruling does not threaten Perplexity’s core business since Comet remains operational on all other websites.
The Larger Market Implications
Amazon updated its Business Solutions Agreement, effective March 4, 2026, to formally require all AI agents to identify themselves when accessing its services. Other retailers have also made moves:
eBay updated its user agreement earlier in 2026 to ban shopping bots.
Walmart and Target are testing more collaborative approaches, working with AI shopping platforms while preserving their own role in the transaction.
If the Ninth Circuit upholds the preliminary injunction and the underlying CFAA claims survive trial, it will establish that platforms can refuse AI agent access even when users have explicitly authorized it. That would create a precedent that would reshape how every agentic commerce product is designed.
“There’s a huge amount of value at stake for anyone who wants to have a relationship with their customers,” noting that agentic shopping could cannibalize ad revenue while degrading direct consumer relationships.”
The Takeaway
Platform authorization and user consent are now legally distinct. The court’s ruling says that user permission alone does not authorize an AI agent to access a third-party platform. Any AI shopping agent that operates without explicit platform agreements is now operating in legally contested territory.
Agentic AI poses a significant risk to major revenue streams. Amazon’s $68.6 billion advertising business depends on human shoppers seeing sponsored listings. An AI agent that routes directly from intent to checkout eliminates that revenue layer entirely. This economic conflict will drive litigation, platform policy changes, and the structure of agentic programs across the eCommerce industry.
Negotiated access is the likely endpoint, not open access. Amazon CEO Andy Jassy has stated he expects to partner with third-party agents over time. Amazon’s own agentic tools — Rufus and Buy For Me — show the company is building in this direction. The question is not whether AI agents will shop on Amazon, but whether access will be unilaterally asserted or commercially negotiated. The ruling strongly signals the latter.
OpenAI Acquires Promptfoo to Embed Security Into Its Enterprise Agent Platform
OpenAI agreed to acquire Promptfoo, an AI security and evaluation startup founded in 2024 by Ian Webster and Michael D’Angelo. The deal is not yet closed, and terms were not disclosed. Once finalized, Promptfoo’s technology will be integrated into OpenAI Frontier, the enterprise platform OpenAI launched in February 2026 for building and operating AI agents. The acquisition is a direct acknowledgment that security, evaluation, and compliance have become the primary gatekeepers blocking enterprise AI agent deployments from moving from pilot to production.
The Background & the Transaction
Promptfoo was built to solve a problem that enterprise security and engineering teams had already identified:
Systematic testing of AI systems for adversarial vulnerabilities is a prerequisite for production deployment, but no platform-native tooling existed to do it at scale.
Promptfoo’s platform covers automated red-teaming, prompt-injection detection, data-leak prevention, jailbreak identification, tool misuse detection, and compliance monitoring, all applied during development, not after deployment. Promptfoo also distributes a widely used open-source CLI and library for evaluating and red-teaming LLM applications across any AI provider. The project has attracted more than 350,000 developers and 130,000 monthly active users.
Promptfoo’s commercial tools are trusted by teams at more than 25% of Fortune 500 companies. The company raised $18.4 million in a Series A in July 2025, led by Insight Partners with participation from Andreessen Horowitz, bringing total funding to approximately $23 million at an $86 million post-money valuation.
Promptfoo Integrated Into Frontier
Promptfoo’s capabilities will become native to the Frontier platform rather than a standalone add-on. Enterprises building agents on Frontier will gain access to:
Automated security testing and red-teaming built into their development workflows.
Reporting and traceability features to support audit and governance requirements.
Tools to identify and remediate risks like prompt injections, jailbreaks, data leaks, and out-of-policy agent behaviors earlier in the build cycle.
OpenAI has committed to maintaining Promptfoo’s open-source offering and to supporting multiple AI providers and models.
“AI agents have an enterprise accountability problem. The Promptfoo acquisition is recognition that the market is moving ahead of the platform.” Citing Futurum research showing 78% of CIOs name governance, compliance, and data security as top barriers to scaling AI — “not a preference; it is a procurement gate.”
Mitch Shely, VP & Practice Lead, Software Lifecycle Engineering, Futurum Grup
The Takeaway
Security is now a production gate, not a post-deployment concern. Futurum Research finds that 78% of CIOs cite governance, compliance, and data security as the top barriers to moving AI agents from proof of concept to production. Promptfoo’s integration into Frontier directly addresses those blockers. Enterprise buyers evaluating AI agent platforms should treat native security testing as a procurement criterion, not a future roadmap item.
OpenAI is closing Frontier’s platform gaps through a targeted acquisition. Promptfoo had reached Fortune 500 adoption, so OpenAI is buying a solution the market had already validated and integrating it on a compressed timeline. Expect OpenAI to acquire additional companies to enhance Frontier’s capabilities.
Definitely NOT AI
The cute and cursed story of Furby. The caviar-topped $100 hot dog. The Brady Bunch house gets an exalted status.
In a classic Far Side, we learn the real reason why dinosaurs became extinct, and a lion leaves a brutally honest review of a cruise.













