AI Infrastructure Story 1 of 12
Nvidia Tells Its Biggest Customers That AI Server Prices Are Going Up
Bloomberg News reported on Saturday that Nvidia has notified some of its largest customers that prices for servers containing its AI chips are going up by more than 15 percent in many cases. According to that reporting, the increases take effect on systems shipped early next year, they affect machines built around the flagship Vera Rubin and Grace Blackwell chips, and the size of the increase varies with the chip generation and the memory configuration of the system. The stated cause is the soaring cost of memory chips. Nvidia has not published a price schedule of its own, and Reuters said it could not immediately verify the report.
Treat the number as reported rather than confirmed, and the direction still matters more than the decimal. For most of the past three years the working assumption inside enterprise AI budgets has been that the cost of a unit of compute falls over time. Chips get faster, the same workload gets cheaper, and a plan written in one fiscal year looks conservative by the next. A double digit increase on the hardware itself inverts that assumption for the first time in this cycle, and it does so at the layer buyers have the least ability to substitute away from.
The reason is worth understanding because it is not about Nvidia's margin. Memory is the constraint. A modern accelerator is a large amount of high bandwidth memory sitting next to a compute die, and the memory market has been tight all year. The same pressure is visible upstream: Reuters reported that Samsung raised prices for its 4nm and 5nm foundry processes by 10 to 15 percent in July and by about 10 percent for its 8nm node, with the largest increases falling on customers who have the fewest alternatives. When the foundry raises prices and the memory supplier raises prices, the system integrator either absorbs the difference or passes it on. Nvidia is reported to be passing it on.
For a CIO or a CFO the practical consequence lands in three places. Any multi year compute budget built on flat or declining hardware costs needs a revised sensitivity case, because a 15 percent hardware increase compounds through depreciation schedules and cloud contract renewals alike. Second, the calculus on renting versus owning shifts, since cloud providers buying at scale will face the same increase and will eventually reflect it in instance pricing, just on a slower clock. Third, workload efficiency stops being an engineering nicety and becomes a budget line, because the cheapest token is still the one you never generate.
The quieter signal is about the shape of the market. Price increases of this size are what a supplier does when demand exceeds what it can build, not when it is fighting for share. That is a comfortable position for Nvidia and an uncomfortable one for everyone writing the checks.
NvidiaCompute CostsMemoryCapital Planning
Industry Dynamics Story 2 of 12
Anthropic Hires the Founder of Google's TPU Program
Bloomberg reported on Friday that Anthropic has hired Amir Salek onto its compute team as the company lays the groundwork for its own chips. Salek led Google's tensor processing unit business until 2022 and oversaw the development of the first seven generations of Google's AI accelerators. He worked at Nvidia before that, and most recently served as a senior managing director at Cerberus Capital Management. It is a single hire, and single hires are usually not news. This one is, because of what the person built the last time.
The TPU is the only sustained counterexample to the assumption that a model company should rent its silicon. Google decided more than a decade ago that the arithmetic of serving its own models at its own scale justified designing the chip, and it kept deciding that through seven generations. Hiring the person who ran that program is not how a company staffs a research project. It is how a company starts a silicon organization.
The strategic logic is straightforward once you look at the cost structure of a frontier lab. Training is a capital event that happens a few times a year. Inference is an operating expense that happens every second, and it scales with commercial success rather than with research ambition. A lab whose revenue is growing faster than its efficiency gains eventually finds that its gross margin is set by a supplier's price list. Owning the accelerator does not remove that dependency, since somebody still has to fabricate the part, but it moves the negotiation from a purchase order to a design decision.
There is a second motive that has nothing to do with price. A custom accelerator can be shaped around the specific arithmetic a lab's models actually perform, which is a narrower target than the general purpose part a merchant vendor has to sell to everyone. Google's advantage with the TPU was never only cost. It was the ability to co design the model and the machine, and to keep both moving in the same direction.
Executives evaluating vendors should read this as a signal about where the frontier labs think their durable advantage lies. The model layer is converging: capabilities that were exclusive eighteen months ago are now available from four or five suppliers. The layers that are hard to copy are the ones with lead times measured in years, and silicon has the longest lead time of all. Anthropic is not going to ship a chip this quarter or next. Hiring Salek is a statement that it intends to still be making that argument at the end of this decade, and that it would rather own the argument than rent it.
AnthropicCustom SiliconTalentVertical Integration
Policy & Regulation Story 3 of 12
OpenAI Asks California to Make Its Own AI Safety Law Tougher
OpenAI's global affairs team said in a post on LinkedIn on Saturday that California's SB 53 should be strengthened. The company asked for two specific amendments: that the law require monitoring of frontier models under training or evaluation for potential serious incidents, and that it strengthen cybersecurity protections throughout the model development lifecycle. Neither request appears in a filing on OpenAI's own site, so the details rest on what the company posted publicly and on how the press reported it.
The reversal is the story. In an August 2025 letter to Governor Gavin Newsom, OpenAI argued that frontier developers who enter safety agreements with the federal Center for AI Standards and Innovation, or who sign the European Union's Code of Practice, should be treated as compliant with California's requirements. The letter warned against creating what it called a CEQA for AI innovation, a reference to the state environmental review statute that has become shorthand in Sacramento for well intentioned process that stops things from getting built. That was an argument for harmonizing state rules downward toward a federal or international baseline. Asking the legislature to add monitoring and cybersecurity obligations is an argument in the other direction.
Two readings are available and both are probably partly true. The charitable one is that the technical situation changed. Monitoring a model while it is being trained or evaluated, rather than only certifying it before release, is a meaningfully different control, and it is the kind of control a lab asks for when it has watched something surprising happen inside its own evaluation harness. The commercial reading is that a large incumbent with a mature safety apparatus benefits when compliance costs rise, because those costs are a smaller fraction of its revenue than of a competitor's.
For enterprises the practical takeaway is about where AI rules are going to come from. Congress has not produced a general framework. In its absence, state statutes are becoming the operative compliance surface for anyone deploying frontier models, and the largest developers have now started treating California specifically as the venue that matters. If SB 53 acquires training time monitoring and lifecycle security requirements, those obligations flow downstream through vendor contracts, model cards and audit requests, regardless of where your company is headquartered.
The unglamorous advice: read SB 53 as it stands, then read the amendments if they are introduced, and ask your model vendors in writing which of the obligations they will carry and which they will push to you. That question is easy to ask now and expensive to ask later.
OpenAISB 53CaliforniaRegulation
AI Safety Story 4 of 12
Five Federal Agencies Say AI Wrote the Exploit Scripts Aimed at Factory Controllers
The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency released a joint cybersecurity advisory, AA26-231A, on August nineteenth. The agencies said cyber actors are conducting targeted reconnaissance and capability development against Siemens programmable logic controllers based in the United States, using artificial intelligence generated exploitation scripts disguised as legitimate monitoring tools.
The scope is broad. The advisory names the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series, across all CPU variants, including the F-series safety rated controllers whose entire purpose is to stop a machine before it hurts someone. The sectors listed are Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. In plain terms: the equipment that moves water, keeps the lights on, and runs production lines.
The technique described is not exotic, and that is the point. The advisory says the actors used internet scanning services including Censys and ZoomEye to find exposed and outdated controllers, then wrote custom Python scripts built on open source industrial libraries, notably python-snap7, and dressed them up to look like ordinary monitoring utilities. The scripts perform initial access, credential harvesting and denial of service, and they exploit known vulnerabilities that already have published fixes. Every ingredient has been available for years. What changed is how quickly someone with moderate skill can assemble them into working code.
That is the honest framing of the AI contribution here, and executives should resist both of the easy exaggerations. This is not an autonomous system deciding to attack a water utility. Nor is it business as usual with a new adjective attached. What a model does in this workflow is compress the distance between knowing that a vulnerability exists and having a reliable script that uses it. It lowers the skill floor and shortens the timeline. When the underlying targets are decades old controllers that were never designed to face a network, a shorter timeline is the whole risk.
The recommended mitigations are the ones every operational technology program already has on a list somewhere: run current software, get these devices off the public internet, enforce strong access controls, and monitor for anomalous industrial control activity. The reason they are worth revisiting this week is that the economics of ignoring them just changed. A backlog item that was tolerable when exploitation required a specialist is a different item when exploitation requires a prompt and an afternoon.
Boards with any physical operations should ask one question at the next meeting: how many of our controllers are reachable from the internet, and who knows the answer without having to go find out.
Critical InfrastructureCybersecurityCISAOT Security
AI Research Story 5 of 12
Nvidia's AVO Clears Every Level of ARC-AGI-3, and Credits the Harness
Nvidia said on Friday that AVO, its general purpose coding agent system, scored 100.00 RHAE across all 25 environments of the ARC-AGI-3 public set, clearing all 183 levels. The company was unusually careful about the caveat and stated it plainly: the results cover the public set using the official scorecard and metric, and they are not results on the semi private or fully private competition sets. That distinction is the difference between a benchmark result and a competition result, and Nvidia put it in writing rather than leaving it to a reader to discover.
The interesting number is not the 100. It is the comparison underneath it. Nvidia said AVO instantiates its harness with Claude Opus 5, and cited ARC Prize scoring Claude Opus 5 on its own at approximately 30 percent on ARC-AGI-3 at high reasoning effort. The same model, wrapped in a different system, went from roughly a third of the levels to all of them. Nvidia also reported that AVO used 6,624 environment actions to finish, about 12 percent fewer than the 7,542 that the VISTA system required to complete the same 183 levels with the same base model.
The lesson Nvidia draws from its own result is the one worth carrying into a budget meeting: the model matters, but the model is not the entire agent. AVO's architecture is persistent memory, supervision, and a loop that inspects, plans, implements and evaluates rather than attempting a task in one pass. None of that is a new idea in isolation. Assembled well and measured honestly, it accounts for a larger performance gap than the difference between any two frontier models currently on the market.
For anyone deciding where to spend engineering effort, this reframes a common argument. Teams spend months evaluating which model to standardize on, then hand the winner to a thin wrapper that calls it once and hopes. The evidence here says the wrapper is where the leverage is. Memory across steps, a supervisor that notices when the agent is stuck, an evaluation loop that catches a wrong turn before it compounds over forty more actions: those choices are within the control of an internal team, and they do not require access to a frontier lab's training run.
Two cautions. Long horizon puzzle environments are not customer support queues or claims processing, and a result on one does not transfer to the other. And a public set score invites the obvious question of how much of the gain survives on problems the system has not seen. Nvidia raised that question itself, which is more than most benchmark announcements manage.
BenchmarksAgentsARC-AGI-3Nvidia
AI Models Story 6 of 12
DeepSeek Bolts Vision Onto V4-Flash and Lands Near the Frontier
DeepSeek released DeepSeek-V4-Flash-Vision-Exp on Friday, an experimental multimodal model available under the model name deepseek-v4-flash-vision-exp. The company's own change log makes two claims. On pure text work, meaning agentic tasks, reasoning and world knowledge, the vision variant is on par with the standard V4-Flash. On visual understanding it is a significant step up from V4-Flash, and DeepSeek describes its multimodal agent capabilities as close to Opus-4.8.
The published numbers are specific. DeepSeek reports 83.9 on Terminal Bench 2.1, 64.3 on Chartography and 63.6 on DSBench-Hard. The first of those measures whether a model can operate in a terminal and finish real tasks. The second and third are about reading charts and doing data science work against messy inputs. That is a deliberate benchmark selection: it is not a suite designed to show off image captioning, it is a suite designed to show that a model can look at a screen or a chart and then do something useful with what it saw.
The word to hold onto is experimental. DeepSeek labeled it that way, and the honest reading is that this is a preview of a capability rather than a production commitment. Enterprises evaluating it should assume the model name may change, the behavior may shift, and support expectations should be set accordingly.
What makes the release commercially interesting is the pattern it continues. The gap between the most capable proprietary multimodal models and the aggressive fast follower releases keeps compressing, and it is compressing fastest in exactly the workloads enterprises actually deploy. Reading a chart in a quarterly report, parsing a scanned invoice, looking at a dashboard and deciding what to click: these are not frontier research problems. They are volume problems, and volume problems are won on cost per task, not on the last three points of a benchmark.
For a buyer, the practical move is to stop treating multimodal capability as a single procurement decision. Route the work. A model that reads ten thousand invoices a day does not need to be the same model that handles the ambiguous exception, and paying frontier prices for both is a habit rather than a requirement. The evaluation question is no longer whether a cheaper model can do the task at all. It is what fraction of your volume it can do at an acceptable error rate, and what the routing logic costs to maintain.
That fraction has been moving in one direction all year, and each release like this one moves it further.
DeepSeekMultimodalOpen ModelsBenchmarks
Generative AI Story 7 of 12
Alibaba's Qwen-UI-Agent Is Built to Drive Screens, Not to Chat
Alibaba released Qwen-UI-Agent on Thursday, a GUI agent foundation model built for real devices covering phones, desktops and the web. The premise is different from a chat assistant. This model is trained to look at a screen the way a person does, then click, type and swipe its way through a task across applications that were never designed to be driven by software.
The reported results are strong across a spread of environments. Alibaba reports success rates of 82.1 percent on MobileWorld, 92.2 percent on MobileWorld-Real, 97.5 percent on AndroidDaily, 79.5 percent on OSWorld-Verified and 73.6 percent on WebArena. The spread across those five is more informative than any one of them. Phone tasks score highest, desktop operating system tasks land in the high seventies, and open web navigation is the hardest of the group. That ordering makes sense: a mobile app has a constrained set of controls and predictable layouts, while the open web is an adversarial environment full of overlays, consent banners and pages that move under the cursor.
Why this category matters commercially is worth stating clearly, because it is easy to dismiss as a demo genre. Most enterprise software cannot be automated through an API, not because an API is technically impossible but because nobody is going to build one. The claims system a regional insurer bought last decade, the vendor portal a supplier insists you use, the internal tool whose maintainer left four years ago: these are the places where work actually gets stuck, and they are exactly the places where an integration project cannot be justified. A model that can operate the interface directly is the only automation path that does not require the software vendor's cooperation.
The engineering caution is that screen driving is brittle in ways APIs are not. A layout change breaks a workflow silently. A permissions dialog appears and the agent stalls. And a model that can click anything can also click the wrong thing, which is why confirmation before consequential actions belongs in the design and not in the roadmap.
For executives the useful frame is neither hype nor dismissal. Treat GUI agents as a bridge technology for systems you cannot integrate and cannot replace. Pick a workflow where the cost of an error is low and the volume is high, instrument it heavily, and measure the true completion rate against a human baseline over weeks rather than in a demo. Benchmark numbers in the eighties and nineties are genuinely impressive. They are also measured in controlled environments, and the distance between those environments and your vendor portal is the whole project.
AlibabaGUI AgentsAutomationBenchmarks
Funding & Investment Story 8 of 12
Apollo Atomics Raises 31 Million Dollars to Build Reactors in a Factory
Apollo Atomics announced on Thursday that it secured 31 million dollars in oversubscribed seed financing led by FCVC, with participation from Y Combinator, Telesoft Partners, Alumni Ventures, Robinhood Ventures, Nucleation Capital, Pelion VC and Duke Capital Partners. The company is an MIT spinout founded by Assil Halimi and Drew Walker, and it is building pressurized water reactors in three sizes: the A-10 at 10 megawatts electric, the A-50 at 50 megawatts and the A-300 at 300 megawatts.
The technical claim is about manufacturing rather than physics. Pressurized water reactors are the most thoroughly understood design in commercial nuclear power, which is precisely the point. Apollo says a compact steam system reduces the overall reactor footprint by roughly 40 times, which is what allows the unit to be built in a factory, transported by truck and deployed in less than 24 months. The company reports more than 20 gigawatts of signed letters of intent in its commercial pipeline.
Read that pipeline number with the appropriate skepticism. A letter of intent is not a purchase order, it is not financed, and in nuclear it is not licensed. Twenty gigawatts is an enormous figure for a company at seed stage, and the gap between a letter of intent and a operating reactor is measured in regulatory years, not engineering months. What the number does tell you is that demand for firm, dispatchable power near data centers has reached the point where buyers will sign something long before there is anything to buy.
That demand is the real story here, and it is the reason a 31 million dollar seed round belongs in an AI newsletter at all. The binding constraint on AI capacity has been migrating steadily down the stack: first it was chips, then it was the ability to build data center shells fast enough, and now, increasingly, it is interconnection. A site with power available today is worth more than a site with better economics and a seven year queue position. Every serious operator is now shopping for generation the way they used to shop for bandwidth.
The strategic question for anyone planning capacity is one of timing horizons. Factory built reactors, if they work as advertised, arrive at the end of this decade, not during the current buildout. Nothing announced this week changes a power plan for the next two years. What it changes is the assumption that the power constraint is permanent. Capital is now flowing to the supply side at seed stage, which is what the beginning of a solution looks like, several years before it looks like anything at all.
NuclearData CentersSeed FundingEnergy
Enterprise AI Story 9 of 12
Firecrawl Builds a Search Index for Coding Agents Instead of People
Firecrawl announced the Firecrawl Developer Index on Thursday, a specialized index for coding agents covering more than 70 million artifacts. What it contains is the material an agent needs and a general search engine buries: READMEs, external documentation, issues, pull requests and OpenAPI specs, searchable with semantic retrieval and metadata filters. Access is through an API, a CLI, MCP and SDKs, and Firecrawl says a developer search costs 2 credits per 10 results.
The company also published an open benchmark called DevDex, built from 1,179 developer search queries, and reported that the Developer Index scored 0.63 Recall at 10 against 0.45 for native web search. Publishing the benchmark alongside the product is worth noting on its own. It is a claim a competitor can contest, which is more than most launch numbers permit.
The idea underneath is more interesting than the product. Web search was built for a human who will read three results, apply judgment, and reformulate the query if the answer is not there. An agent behaves differently. It burns a tool call on every search, it cannot easily tell a stale blog post from current documentation, and each wasted call costs both tokens and elapsed time inside a loop that a user is waiting on. Ranking optimized for human patience is the wrong objective function for a system with none.
That mismatch is going to produce a category. The retrieval layer for agents is a different product from the retrieval layer for people, with different freshness requirements, different result formats, and pricing measured per call rather than per user. Firecrawl is early to it in the developer vertical, which is the obvious first vertical because coding agents are the workload with real production volume today. The same argument extends to legal filings, regulatory text, product catalogs and internal knowledge bases, and it explains why several infrastructure companies have started describing themselves as context providers rather than search providers.
For engineering leaders running coding agents in production, the immediate question is measurable: what fraction of your agents' tool calls are searches, and what fraction of those searches return something the agent actually uses. Most teams have never instrumented that, and the answer tends to be worse than expected. If a meaningful share of your agent latency and token spend is going to retrieval that misses, the fix is not a better model. It is a better index.
The broader point for buyers is that the AI stack keeps growing new layers, and the layers that look boring are frequently where the cost lives.
Developer ToolsRetrievalCoding AgentsBenchmarks
Policy & Regulation Story 10 of 12
A Judge Throws Out the Espionage Half of the Google AI Secrets Case
On August twentieth, United States District Judge Vince Chhabria in San Francisco granted a motion for judgment of acquittal on seven economic espionage counts against Linwei Ding, a former Google software engineer. The court found insufficient evidence that Ding intended or knew his conduct would benefit the Chinese government at the time of the thefts. The seven theft of trade secrets convictions stand, and each carries a maximum of 10 years in prison and a fine of up to 250,000 dollars. Reuters reported that sentencing is scheduled for September first.
The distinction the court drew is narrow and consequential. Ding was found guilty in January on all fourteen counts, seven of economic espionage and seven of theft of trade secrets, following an indictment in March 2024 and a superseding indictment in February 2025. The Justice Department said he took more than two thousand pages of confidential information containing Google's AI trade secrets between May 2022 and April 2023, covering custom tensor processing unit chips, graphics processing unit systems, the software that lets chips communicate, supercomputer orchestration software and SmartNIC network interface cards. Economic espionage requires proving that the defendant intended to benefit a foreign government. The court concluded that evidence dated from a period more than a year after the uploads could not establish what was in his mind when he took the files.
For general counsel and security leaders, the ruling clarifies something important about how these cases are actually won and lost. The theft itself was proven and the convictions on that charge survive. What did not survive was the geopolitical framing layered on top. Prosecutors reach for the espionage statute because it carries the heavier sentence and the stronger headline, and this decision is a reminder that the intent element is a genuine burden rather than an inference the government gets for free.
The operational lesson is unchanged and predates the ruling. The material at issue was the design of AI infrastructure, which is exactly the category most companies protect least well because it lives with the engineers who need it daily. Two thousand pages left over roughly eleven months. That is not a sophisticated exfiltration campaign, it is an access control and monitoring gap.
The strategic point is that AI hardware design has become the crown jewel category in a way that model weights, for all the attention they get, have not. Weights depreciate as the next generation arrives. A chip architecture and the orchestration software around it represent years of accumulated work that a competitor cannot shortcut. Companies auditing what they guard most carefully should check whether their protections have caught up with where the value moved.
Trade SecretsLitigationGoogleInsider Risk
Enterprise AI Story 11 of 12
Slack Puts Coding Agents in a Channel Where Everyone Can Watch
Salesforce announced Slack Code on Thursday, a feature that puts AI coding agents into dedicated Slack code channels rather than leaving them in an individual developer's terminal. A channel spins up when someone mentions a coding agent, the work happens in the open with side by side diffs and live HTML previews, and the channel archives itself when the work is done. At launch it supports Claude from Anthropic, Devin from Cognition, GitHub Copilot and Vercel, with OpenAI's ChatGPT listed as coming soon.
Rob Seaman, EVP and GM of Slack at Salesforce, framed the reasoning directly: "AI only creates value when it's part of how a team actually works, not something people go do alone in another tab." Mario Rodriguez, Chief Product Officer at GitHub, put the division of labor this way: "Slack is a strategic part of a broader GitHub promise: humans set direction, agents close the loop."
The product decision worth studying is the choice of venue. Coding agents today mostly run in a terminal or an editor, which means the work is invisible to everyone except the person who launched it. That has been fine while adoption was individual and experimental. It becomes a problem the moment a meaningful share of a codebase is being written this way, because nobody can see what was attempted, what was rejected, what context the agent was given, or why a particular approach was chosen. The reasoning evaporates and only the commit survives.
Putting the loop in a channel changes the artifact. A code channel is a record of the prompt, the plan, the diff and the discussion around it, sitting in a searchable place next to every other decision the team made that week. That is valuable for review, it is valuable for onboarding, and it is quietly valuable for governance, since an auditor asking which changes were agent generated has somewhere to look.
The risk is equally clear to anyone who has watched a Slack channel fill up. Making agent work visible is only useful if the visibility is signal. A team running a dozen agents in parallel can generate more diffs than any human will read, and unread visibility is worse than no visibility because it manufactures the appearance of oversight.
The recommendation for engineering leaders is to treat this as a policy question rather than a tooling question. Decide first what agent generated work must be reviewed by a person, and by whom, and what evidence you expect to keep. Then choose the venue that produces that evidence. Slack Code is a reasonable answer to that question. It is not a substitute for having asked it.
SalesforceSlackCoding AgentsCollaboration
AI Business Models Story 12 of 12
Google Hands Publishers a Button and Calls It Traffic Insurance
Google announced on Thursday an embeddable Preferred Sources button that publishers can place on their own websites. A reader clicks it, and the publication is marked as a preferred source in that reader's Google Search, Discover and Google News. The underlying feature has been live since May, and Google said that more than 345,000 unique sources have been selected across the web since then, and that people are twice as likely to click through to a preferred source when one is available.
The context is not subtle. AI generated answers now sit at the top of a large share of search results, and the traffic that used to flow to the pages those answers were assembled from has been falling. Publishers have spent the year describing this as an existential problem and Google has spent the year insisting the picture is more complicated. A button that lets a publisher ask its own readers to vote for it is Google's answer to that argument, and it is a revealing one.
What Google is offering is a way to convert an audience you already have into distribution you can keep. That is a real thing. The 2x click through figure, which is Google's own, suggests the mechanism works for readers who use it. But notice what it requires. To use the button effectively you need people already visiting your site who care enough to click it. A publication with a loyal direct audience gains a reinforcing loop. A publication that depended on being discovered through search has nothing to convert. The tool helps most where help is needed least, which is a pattern worth recognizing because it recurs in almost every platform remedy of this shape.
For marketing and communications leaders the implication runs past publishing. If distribution in an AI mediated interface increasingly depends on an explicit audience preference rather than on ranking, then the asset that matters is the one that survives an algorithm change. Email lists, apps, communities, direct relationships: the unfashionable channels that companies have been under investing in for a decade because search and social were cheaper. They are not cheaper any more, and this button is a small piece of evidence that the platforms themselves expect preference to matter more than crawlability.
The broader shift underneath is that the open web's traffic economy was built on an implicit bargain: publishers made content freely crawlable and received visitors in return. AI answers have made the first half of that bargain more valuable to the platform and the second half less reliable for the publisher. Preferred Sources does not restore the bargain. It offers a partial workaround to the publishers best positioned to not need one.
GooglePublishersSearch TrafficDistribution