Welcome to the DX Today Executive Briefing
Four separate organizations published numbers in the past twenty four hours, and read together they describe an industry that has stopped arguing about whether artificial intelligence works and started arguing about who pays for it, who governs it, and who gets to point it at a live system. Gartner put a figure on the shift from building models to running them. Salesforce opened its production telemetry and showed what agents actually do once they are past the pilot. The Federal Trade Commission closed a comment docket that turned into a referendum on whether Washington may regulate what an AI model says. And OpenAI published the one number most AI laboratories would rather not disclose, the rate at which its models refuse to help with offensive security work, and then handed the unrestricted version to a vetted list of defenders.
None of these stories is a product announcement dressed as news. Each one is a measurement, and each measurement lands on a decision an executive is already making this quarter: how much infrastructure capacity to commit for inference rather than training, how to evaluate an agent program that has moved from conversation to execution, how to plan compliance when federal and state AI authority are openly in conflict, and how to think about a security vendor stack in which the model provider has become the arms supplier to both sides. This edition covers all four.
01
Gartner Puts a Number on the Inference Era as AI Infrastructure Spending Nearly Doubles to Forty Two Billion Dollars
Gartner released a forecast on Monday that quietly settles an argument enterprise technology leaders have been having with their finance departments for two years. Worldwide spending on AI optimized infrastructure as a service is projected to grow 96% in 2026, reaching $42 billion. The growth rate is arresting on its own, but the headline is not the interesting part of the release. The composition underneath it is, because for the first time the money is going somewhere different than it went during the model building boom.
In 2026, global spending on inference will reach $23.3 billion and surpass spending on training, which Gartner puts at $19 billion. Fifty five percent of all AI optimized infrastructure as a service spending is forecast to support inference this year, and that share is set to reach 59% in 2027. Inference is the operational side of the technology, the part where a trained model answers a question, scores a transaction, or takes an action inside a workflow. Training is a capital event. Inference is an operating expense that never stops, and the crossover means the industry's cost structure has permanently changed shape.
Hardeep Singh, Sr Principal Research Analyst at Gartner, framed the significance directly. Speaking to CIO Dive, Singh said the fact that inference spending will exceed training spending in 2026 indicates that AI adoption is becoming more mainstream and production oriented. In the Gartner release he was more specific about the mechanism, noting that as organizations shift from model development to production scale deployment, fine tuned and domain specific models are increasingly integrated into customer facing and operational systems, requiring continuous, real time execution rather than periodic training.
The multi year trajectory shows a market that is decelerating in rate while compounding in absolute terms, which is the pattern of a category maturing rather than one cooling off. Gartner records AI optimized infrastructure as a service spending of $21,529 million in 2025, a growth rate of 180.0%. The 2026 figure of $42 billion represents 96.4% growth, and the 2027 forecast of $66 billion represents 56.5%. Each successive year adds more real dollars than the last even as the percentage falls. For context, in the same August forecast Gartner puts total infrastructure as a service spending at $287,347 million in 2026, growing 29.3%, meaning the AI optimized slice is growing more than three times faster than the market that contains it.
Gartner attributes the compute intensity to the architecture of agentic systems specifically. Agentic AI amplifies compute demand through multistep, autonomous execution, making inference the dominant consumption model and positioning AI optimized infrastructure as a service as a critical enabler of enterprise AI strategy. This is a meaningful causal claim rather than a trend observation. A chatbot answers once. An agent decomposes a task, calls tools, evaluates results, and iterates, and every one of those steps is a billable inference. The unit economics of an agent program are therefore structurally worse than the unit economics of a copilot, and any business case built on the latter will understate the former.
For technology buyers the practical consequences are unglamorous and immediate. Singh told CIO Dive that leaders should treat AI infrastructure as a strategic investment to operationalize AI across the business rather than an experimental budget line item, and that enterprises now need AI optimized compute, storage, networking and orchestration capabilities that traditional infrastructure was not designed to support efficiently. He listed the concerns that follow for anyone scaling from pilots to business critical production: compute capacity, data gravity, governance, operational resilience, security and cost management. Notably, four of those six are not technology problems at all.
The deployment pattern is also fragmenting. Many enterprises are reassessing cloud strategy in favor of a hybrid approach that combines public cloud, private cloud, colocation, edge and sovereign environments, often several at once. That is a rational response to an inference dominated cost base, because inference is latency sensitive, data adjacent, and predictable enough to place deliberately, where training was bursty and better rented. Singh's closing framing is the one to bring to a board: AI infrastructure is increasingly becoming a business capability that determines how quickly and effectively enterprises can scale AI across the enterprise.
Strategic Takeaway
CIOs, CTOs, and Infrastructure Leaders
The inference crossover is the single most actionable number in this forecast, because it changes what a business case has to prove. Budgets modeled on training as a one time capital event will systematically under provision for a workload that runs continuously and scales with adoption rather than with headcount. Reforecast AI spending as an operating line tied to transaction volume, not as a project. Then pressure test the agent roadmap against it, since every additional autonomous step multiplies inference cost in a way a conversational deployment never did. The organizations that get this right will place inference workloads deliberately across hybrid and sovereign environments for latency, data gravity and cost, rather than defaulting to the cloud region where the training run happened to sit.
02
Salesforce Opens Its Production Telemetry and Shows an Agent Fleet That Has Stopped Talking and Started Executing
Salesforce published its 2026 Agentic Enterprise Index, and its value lies in what it declines to measure. The analysis draws on aggregated usage data from the Agentforce platform between February 2025 and April 2026, and to qualify for inclusion a business had to have agents running in production every single month of that window. That methodology filters out the pilots, the proofs of concept and the abandoned experiments that inflate most adoption surveys. What remains is a picture of organizations that already crossed the line into operations, which makes it one of the few credible longitudinal datasets on what agents do at scale.
The volume findings are strong. The average number of agents activated per organization increased nearly 3x over the fiscal year. Businesses begin creating agents within an average of two days after provisioning them, and that time to first agent fell 53% across the analysis period. Speed of deployment is now rarely the constraint, which relocates the bottleneck to the places it has always eventually landed in enterprise software: data access, permissions, and the governance sign off that decides whether an agent is allowed to write rather than merely read.
Capability deepened alongside volume. The average agent can now act on six skills, up from two at the beginning of 2025. That expansion is elastic rather than fixed. During peak shopping season the average retail agent acted on nine skills, a 350% increase, as retailers assigned agents more complex multistep customer work precisely when human capacity was scarcest. An agent fleet that widens its own repertoire under load is a different operational asset than one with a static script, and it is the first quantified evidence that surge capacity is a real property of these systems rather than a vendor promise.
Salesforce measures throughput with a metric it calls the Agentic Work Unit, defined as one discrete task accomplished by an AI agent. That output is increasing at a 15% compound monthly growth rate as of April 2026. The company also tracks the ratio of action calls to output tokens, and that ratio is growing at the same rate, which is the most consequential sentence in the report. It means agents are increasingly triggering real workflows rather than generating text about them. A service agent no longer drafts a reply about a refund. It looks up the record, applies the business rule, and issues the refund.
The industry split is where the strategic reading sits. Consumer facing sectors dominate raw volume, with retail representing 22% of total monthly output on 18x growth and travel representing 10% on 7x growth. Regulated and operationally complex industries produce far less volume but grew faster from a smaller base, with public sector output up 227x and healthcare and life sciences up 19x. Financial services is the interesting hybrid, holding about 10% of total monthly output while growing 13x, and Salesforce found it deploys some of the most sophisticated agents at consumer scale, with activity rising during seasonal surges such as tax season.
PenFed illustrates what sophistication means under real constraints. As a federally chartered credit union serving military members and their families, it operates under strict compliance, security and verification standards at every member touchpoint. It deployed an agent called Ace behind online banking authentication, capable of evaluating account balances, checking loan application statuses, transferring funds, and answering from a curated knowledge base, and a second agent called Echo that extends those multi action capabilities to voice. Shree Reddy, CIO of PenFed, said that by pairing robust governance with a unified platform the institution safely deployed multi action agents that perform real, complex banking tasks. Elsewhere Siemens, which sells across seven siloed business units through 18,000 sellers and faced 2,800 unqualified inbound leads per week, split qualification across a coordinated multi agent workflow. Pandora runs a concierge named Gemma that handles 60% of routine support requests during peak traffic while driving a 10% increase in Net Promoter Score.
The trust indicators are the quietest and most important series in the report. The average employee engaged with an agent 300% more often per week across the analysis period. Over the past five quarters agents handled 170 times more customer service conversations than in prior years and resolved seven out of ten without human help, while escalation rates to human agents held steady at 32%. Volume rose by two orders of magnitude and quality did not degrade.
On returns, retailers that deployed AI agents during the holiday shopping season saw a 4x higher sales growth rate, 8% year over year against 2% for those that did not. Joe Inzerillo, Salesforce President of Enterprise and AI Technology, argued that the return is showing up in execution efficiency and not only in top line sales, describing a move from passive chatbots and predictive models to execution driven agents. One caveat belongs in every reading of this document: the findings are drawn exclusively from organizations that use Salesforce products and had agents running in production throughout, and Salesforce states plainly that the results are not indicative of the company's own financial performance.
Strategic Takeaway
Chief Digital Officers, Heads of Customer Operations, and Enterprise Architects
The metric worth stealing from this report is the ratio of action calls to output tokens, because it separates an agent program that is working from one that is merely busy. Most internal dashboards still count conversations, deflection and satisfaction, all of which a well tuned chatbot could move four years ago. Counting completed actions against generated text tells you whether the system is doing work or describing it. Pair that with the escalation rate held flat across a 170 fold increase in volume, and you have the two numbers that make an agent business case defensible to a board. Note also where the sophistication actually lives: manufacturing, financial services and healthcare are building deeper agent networks than technology and retail, which means the regulated industries that moved last are not behind, they optimized for a different variable.
03
The FTC's AI Accuracy Docket Closes With More Than Three Hundred Comments and a Rare Bipartisan Objection
The comment window on the Federal Trade Commission's proposed policy statement concerning accuracy in artificial intelligence systems closed on July 31, and the record it produced is now a more revealing document than the proposal itself. CyberScoop reported this week that the Commission received more than 300 comments from trade associations, think tanks, individual experts and members of Congress, and that most criticized the proposal as ill defined and vulnerable to politically motivated censorship. The unusual feature of the docket is not the volume of opposition but its symmetry, with objections arriving from groups that agree on very little else.
The proposal itself was issued on July 1. The FTC Act prohibits businesses from engaging in unfair or deceptive conduct, and the proposed statement describes how AI companies that distort their systems' outputs to achieve undisclosed ideological objectives could be deceiving consumers in violation of Section 5 of that Act. Andrew N. Ferguson, Chairman of the Federal Trade Commission, said the agency wanted to hear from businesses and consumers about their experiences and concerns regarding the subversion of AI systems for ideological ends, and that the input would help the Commission formulate a final policy advancing the President's goal of expanding American dominance in artificial intelligence. The Commission vote authorizing the Federal Register notice was 2-0.
Preemption is the part with direct operational consequence for compliance teams. The proposed statement singles out Colorado's Artificial Intelligence Act, asserting that such a law is impliedly preempted to the extent it conflicts with a federal regulatory scheme, and the Commission was directed to this ground by a December executive order in which the President instructed the agency to address the legal implications of state laws requiring alteration of the truthful outputs of AI models. What makes that target awkward is that Colorado has already moved. Governor Jared Polis signed Senate Bill 26-189 on May 14, 2026, repealing and reenacting the original 2024 statute, with the revised law taking effect January 1, 2027. By Holland & Knight's reading, the rewrite eliminated three of the original law's heaviest obligations, the duty to use reasonable care to prevent algorithmic discrimination, mandatory risk management programs for deployers, and annual impact assessments, replacing them with notice before use, an explanation after an adverse outcome, and a right to request meaningful human review. Federal pressure preceded that retreat. The same firm notes that the December 2025 executive order targeted the original law as excessive state regulation, that a large AI developer challenged its constitutionality in federal court in April 2026, and that the Department of Justice intervened to support the challenge.
Leah Siskind, a former White House digital official and deputy director of the AI Corps at the Department of Homeland Security, now a senior AI fellow at the Foundation for Defense of Democracies, told CyberScoop the proposal misses the substantive question. Her own research has examined how authoritarian propaganda tends to be overrepresented in large language model answers, partly because governments deliberately poison the data these systems ingest. There is a real debate about bias and accuracy in models and about countering disinformation absorbed and reflected by them, she argued, and the statement does not address it. Her legal objection was blunter: the FTC's role is to police consumer protection violations rather than to regulate AI systems, and the agency appears to be stretching Section 5 well beyond its traditional role to compensate for the absence of congressional AI legislation.
The conservative comment record split against itself, which is the detail most worth noting. The America First Legal Foundation pressed the FTC to adopt the policy in full, and its senior counsel Emily Percival argued that a reasonable consumer, based on AI companies' advertising choices, would not expect an AI system to adopt overwhelmingly liberal positions. The R Street Foundation's Spence Purnell and Adam Thierer rejected that reasoning from the same side of the aisle, writing that the consumer expectations rationale is typically used in cases where there is an omission of information that should have existed, and that since most large language models already carry disclosure statements for their outputs the FTC is unlikely to prove consumers were deceived about a product.
Members of Congress from both parties filed as well. Representatives Josh Gottheimer, Democrat of New Jersey, and Michael Lawler, Republican of New York, urged the FTC to carve civil rights related work out of its scrutiny, writing that AI companies must not falsify facts in the name of fairness but must also prevent discrimination, stereotypes and unequal treatment, and asking how the agency intends to keep such efforts permissible under the final framework. That request identifies a genuine drafting hazard: a rule against ideologically motivated output adjustment, written without a carve out, reaches the bias mitigation work that other regulators and a good deal of existing civil rights law effectively require.
The Cato Institute's David Inserra, Jennifer Huddleston and Juan Londono located the analytical flaw, arguing that the statement conflates two different issues, ideological bias in AI systems and factual deception in marketing. The FTC, they wrote, is trying to judge model accuracy and performance, two largely subjective variables, in the same way it evaluates dietary supplement medical benefit claims or undisclosed fees, and called the comparison absurd. The International Center for Law and Economics added that the statement offers little practical guidance on how the Commission will apply deception authority to AI, and warned that its focus on ideologically motivated distortions suggests the Commission's concerns extend into speech that may receive the highest degree of First Amendment protection.
One asymmetry in the document drew consistent attention. CyberScoop reported that Anthropic, which has clashed with the administration over AI guardrails and military applications, appears more than half a dozen times in the footnotes, often framed as an example of the ideological bias the FTC intends to stamp out, while a widely documented case of an owner adjusting a model's ideology, Elon Musk and the xAI owned Grok, is absent from the document. Grok appears only in a footnote citing an advertisement describing it as a truth seeking AI companion. Whatever one concludes about the underlying policy, an enforcement framework whose examples run in one direction is a framework whose application enterprises cannot yet predict.
Strategic Takeaway
General Counsel, Chief Compliance Officers, and Heads of AI Governance
Plan for conflict rather than for resolution. The realistic near term outcome is not that federal authority cleanly displaces the state patchwork but that firms deploying models in consumer facing contexts sit under two regimes pointing opposite directions, one asserting that adjusting outputs for ideological ends is deceptive and another requiring documented bias mitigation before release. The defensible position under both is the same, and it is procedural rather than substantive: document why every output adjustment was made, who approved it, and what evidence supported it. A model tuning decision recorded contemporaneously as a safety, accuracy or legal compliance measure survives scrutiny from either direction. One reconstructed after an inquiry arrives does not. Do not let the Colorado delay effort slow that documentation work, because the discipline it imposes is what answers the federal question too.
04
OpenAI Removes the Cyber Guardrails for Vetted Defenders and Publishes the Refusal Rate That Explains Why
OpenAI expanded its Daybreak cyber defense program on Monday into two access tiers and introduced a purpose trained model available only at the higher one. Daybreak Blue provides frontier general purpose models including GPT-5.6 Sol with safeguards tailored to authorized defensive work, supporting vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Daybreak Red provides purpose trained cybersecurity models for authorized vulnerability research, exploit validation and security testing, and it is the only route to the new model, GPT-5.6-Cyber, which is built on GPT-5.6 Sol and trained to reduce refusals on higher risk dual use tasks.
The disclosure that matters is a single benchmark OpenAI built and published. Its internal Advanced Cybersecurity Completion Rate evaluation measures how often a model responds to requests involving exploit chain development, authentication bypass, privilege escalation and comparable scenarios. GPT-5.6-Cyber completes 95.0% of those requests. GPT-5.6 Sol completes 1.5%, and the version defenders reach through Daybreak Blue completes 2.0%. OpenAI reports that the predecessor GPT-5.5-Cyber completes 57.3%. Published plainly, that spread quantifies something security teams have complained about for two years without evidence, that the guardrails protecting the public from offensive capability were also blocking the defenders who most needed it.
The capability claims come with corroborating artifacts rather than benchmarks alone. OpenAI used GPT-5.6-Cyber to investigate V8, the JavaScript engine in Chrome, and uncovered two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Researchers validated the findings and reported them to Google through coordinated disclosure, and Google fixed the vulnerability, assigning CVE-2026-15903. The company also reports finding at least five vulnerabilities in a popular mobile operating system including a chain from an untrusted application to local privilege escalation, three critical vulnerabilities in a popular database including a remote path to code execution, and over 400 privilege escalation vulnerabilities in a popular operating system kernel.
The safety accounting is careful and deserves to be read closely rather than summarized away. Under its Preparedness Framework OpenAI assessed GPT-5.6-Cyber as reaching the High cybersecurity threshold but not the Critical threshold, the same classification as GPT-5.6 Sol, noting the model improved on specialized tasks it was directly trained for but not sufficiently to cross the higher bar. The company states that GPT-5.6-Cyber was not involved in exploiting Hugging Face, and says it will publish a fuller system card later. Context sharpens the point. Axios reported that OpenAI had delayed the release of its forthcoming Astra model days earlier after it reached critical hacking abilities during safety testing, meaning the company shipped the model that stayed below the line and held the one that crossed it.
OpenAI is explicit that this is a traded risk rather than an eliminated one. Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment, the company wrote, adding that despite these risks it believes democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense. The compensating controls are identity verification, account security, monitoring, approved use restrictions and legal attestations. All individual Daybreak accounts must adopt hardware security keys beginning September 1, 2026. Customers using Codex are being pushed from full access mode toward auto review mode, which evaluates actions requiring elevated permissions before execution, and the published guidance tells teams to sandbox and isolate workflows away from production systems and the open internet, to monitor agent actions, and to scope authorized systems explicitly.
Distribution is the strategically underrated element. OpenAI simultaneously announced a Daybreak cyber partner program spanning major security and services firms, among them Accenture, IBM, CrowdStrike, Cisco, Palo Alto Networks, Ernst & Young, KPMG and Sophos, allowing them to embed the frontier cyber models inside existing security products, managed services and client engagements. Most enterprises will therefore encounter these capabilities not by applying to a frontier laboratory but through a security vendor they already buy from. The governance question that follows is one procurement teams should be asking now: which of your incumbent providers is about to route your environment through a model with system level cyber guardrails deliberately removed, and under whose authorization.
Early users report that the difference is practical rather than theoretical. Jared Atkinson, CTO of SpecterOps, said the model is materially improving specialist vulnerability research workflows, reasoning more accurately about real exploit constraints and tracking complex state better, and that it completed work in under a day that earlier models had not resolved after weeks of intermittent effort. He also made the governance argument in the vendor's own terms, noting that in a governed trusted access environment, reducing unnecessary refusals helps authorized researchers preserve momentum and spend more time validating findings.
The honest reading is that the asymmetry this program addresses is real and the program does not resolve it. Attackers were never bound by refusal rates, since they run unaligned models, jailbreaks and their own tooling, so a 1.5% completion rate imposed a tax on defenders alone. Distributing a 95% completion rate model to vetted defenders removes that tax. It also creates a class of accounts whose compromise would hand an adversary a purpose trained exploitation model, which is precisely why the hardware key mandate and the monitoring regime are load bearing rather than decorative. Security researchers have also cautioned that even near frontier models still require substantial human guidance and supporting infrastructure to work as intended, and that models frequently fail to fully patch what they discover.
Strategic Takeaway
CISOs, Heads of Security Engineering, and Risk Committees
Treat this as a supply chain change before treating it as a capability opportunity. Major security and services providers are about to embed models with reduced cyber safeguards into products already inside your environment, which means the relevant control is not whether your organization applies for Daybreak access but what your existing vendors are permitted to run against your systems and under whose authorization. Update third party risk questionnaires now to ask specifically about frontier cyber model usage, autonomy scope, and human review gates. Internally, the published guidance is the right baseline regardless of which model you use: isolate security workflows from production and the open internet, require review of privileged actions before execution, scope authorized systems explicitly, and mandate hardware backed authentication for any account with access. An account with a purpose trained exploitation model behind it is now among the highest value credentials in your estate, and should be governed accordingly.
The Analysis
The Bottom Line
Read as a set, these four stories describe the same transition seen from four vantage points. Gartner measured it in dollars, with inference surpassing training and AI spending converting from a capital project into a permanent operating cost. Salesforce measured it in behavior, with agent fleets shifting from generating text to triggering actions while escalation rates held flat through a 170 fold increase in volume. Both are describing the moment a technology stops being a thing an organization is evaluating and becomes a thing it is running.
The other two stories are about what happens when that transition outpaces the institutions meant to govern it. The FTC docket closed with more than three hundred comments and a rare bipartisan objection precisely because the agency reached for a general purpose consumer protection statute to answer a question Congress has not addressed, and the state framework it seeks to preempt is itself being narrowed by its own legislature. OpenAI, facing an adversary that never respected model guardrails, chose to remove them for a vetted list and published the numbers proving how lopsided the constraint had been. Neither is a settled arrangement. Both are provisional answers built because waiting was worse.
For executives, the practical throughline is that the defensible decisions in each of these domains are procedural rather than technical. Reforecast AI infrastructure as an operating line that scales with transaction volume. Measure agents by completed actions rather than conversations. Document why every model output adjustment was made and who approved it, because that record answers both the federal and the state question. Ask which of your existing security vendors is about to run a frontier cyber model against your environment. None of those four moves requires knowing how the regulatory fight ends or which model wins. That is what makes them the right moves to make now.