AI HAS A HYPE PROBLEM. WE DON'T.

The Executive Briefing · Twice weekly

The Executive Briefing — Friday, September 11, 2026

Welcome to the DX Today Executive Briefing

This week's numbers make the argument that words alone no longer can. Oracle closed a fiscal quarter with a cloud infrastructure business growing at triple digit rates and a backlog north of six hundred billion dollars, a scale that would have sounded implausible even a year ago. At the same time, the tooling layer sitting on top of that infrastructure is consolidating fast, with OpenAI now offering a managed, production grade home for the agents enterprises are trying to ship.

None of that growth is arriving without scrutiny. California became the first state to stand up an independent audit regime for AI systems this week, with the two labs most associated with the frontier, Anthropic and OpenAI, both on record supporting it. And Anthropic's own threat intelligence team published fresh evidence of exactly why that scrutiny keeps intensifying: state linked hackers using Claude to compress attacks that once took skilled teams weeks into operations completed in hours. In this edition: Oracle's backlog surge, OpenAI's new Agents API, California's first in the nation AI audit law, and Anthropic's latest findings on AI enabled cyber operations.

01

Oracle's Backlog Hits $664 Billion as AI Cloud Demand Outruns Its Own Guidance

Oracle reported fiscal 2027 first quarter results on September 10 that reset expectations for what an AI driven cloud transition can look like inside a company built decades before the term existed. Total revenue reached $19.3 billion, up 30 percent year over year in both USD and constant currency, according to Oracle's own investor relations release. The headline number sat inside a broader pattern of acceleration across every cloud line Oracle reports.

Total cloud revenue, combining infrastructure and applications, came in at $11.6 billion, up 62 percent year over year. The infrastructure piece alone, Oracle Cloud Infrastructure, posted $7.4 billion in revenue, up 121 percent, more than doubling in a single year. Cloud applications, the software as a service business built around Fusion and NetSuite, grew a comparatively modest 10 percent to $4.2 billion, a reminder that the AI boom is concentrated overwhelmingly in raw compute rather than packaged software, at least for now.

The figure that will dominate boardroom conversations this week is remaining performance obligations, Oracle's measure of contracted revenue not yet recognized. RPO reached $664 billion, up $209 billion from a year earlier. A backlog of that size signals that customers are not simply testing AI workloads on Oracle's infrastructure, they are committing to years of capacity in advance.

Profitability kept pace with the top line. GAAP earnings per share came in at $1.56, up 55 percent year over year, while non GAAP earnings per share reached $1.92, up 30 percent. Operating cash flow hit $23 billion for the quarter, up 184 percent, funding a buildout that included 850 megawatts of additional datacenter capacity added in the quarter alone. Oracle also completed a $20 billion stock sale through its at the market program during the period and maintained its quarterly dividend of $0.50 per share.

Management's fiscal 2027 guidance calls for at least $90 billion in total revenue, unchanged from prior guidance, and $8.10 in non GAAP earnings per share, raised from the $8.05 guided last quarter, and it guided next quarter's cloud revenue growth to a range of 64 to 70 percent in constant currency, an acceleration from the quarter just reported. For a company that spent much of the last decade being described as a legacy database vendor, the shift in both scale and market narrative is now difficult to overstate.

The results also carry a warning embedded in the opportunity. A $664 billion RPO figure is a bet, by both Oracle and its customers, that AI demand continues compounding at something close to its current pace for years. Oracle is one of the sandbox infrastructure partners named in OpenAI's newly launched Agents API this same week, a small but telling sign of how tightly the compute layer and the agent tooling layer are now intertwining across the industry's biggest players.

For enterprise buyers, the practical takeaway is that raw capacity constraints from earlier in the AI buildout are easing at the hyperscale layer, even as backlog numbers suggest demand still outstrips even aggressive buildout plans. Procurement teams negotiating multi year cloud commitments should expect continued pricing power on the vendor side for the foreseeable future.

Strategic Takeaway

CFOs, CIOs, and Cloud Infrastructure Leaders

A $664 billion backlog is not just a growth story, it is a signal that multi year AI infrastructure commitments are now the default negotiating posture across the hyperscale cloud market. Finance and infrastructure leaders locking in capacity should expect limited near term relief on pricing and should treat current contract terms as a baseline for planning rather than an opening offer.

02

OpenAI Opens a Managed Agents API and Signals Where the Real Competition Now Lives

OpenAI launched its Agents API in public beta on September 10, a managed cloud service built on the Codex harness that lets developers create, orchestrate, and run production agents without assembling the surrounding infrastructure themselves. The move is a direct bid to own the layer where enterprises actually deploy agents, not just the models underneath them.

According to OpenAI, the service handles agent creation through a single API call specifying tasks, models, and tools, manages context across sessions that span multiple context windows, and supports tool search alongside programmatic, parallel tool calling. Multi agent support lets a coordinating agent delegate work to subagents running in parallel, a pattern enterprises have been assembling manually with third party orchestration frameworks until now. The API supports the Model Context Protocol, custom functions, and built in tools including web search.

Pricing follows OpenAI's existing model: there are no separate fees for the Agents API itself, only charges for the tokens consumed and the tools used, following standard API pricing. That positions the service as a low friction on ramp for teams already spending on OpenAI models, rather than a new line item requiring separate budget approval, and it removes a common objection procurement teams raise when a vendor tries to introduce a new metered product on top of an existing contract.

Sandbox execution, the isolated environment where agents actually run code and take actions, comes through a set of launch partners rather than a single in house system: Blaxel, Cloudflare, Daytona, DigitalOcean, E2B, Modal, Oracle, Runloop, and Vercel all provide sandbox integrations at launch. The breadth of that partner list, spanning both established cloud providers and newer infrastructure startups, suggests OpenAI is deliberately avoiding lock in to a single execution environment while still capturing the orchestration layer itself.

Early customer results shared by OpenAI point to meaningful operational gains. Jack Weissenberger, CTO at Ciridae, said the Agents API moved the company's evaluation score from 0.71 to 0.85, with subagent support delivering a 4x latency reduction. Bhavyansh Sabharwal, a Member of Technical Staff at SafetyKit, reported a 60 percent reduction in cost per case after migrating. Serhii Shchoholiev, Lead Engineer at Hypha, said that by separating the agent harness from the sandbox, the company reduced failed agent responses by 86 percent.

The launch lands in a market where Google and Microsoft have both been building out their own agent frameworks, and where interoperability protocols like MCP have become table stakes rather than differentiators. What OpenAI is now competing on is less the protocol layer and more the managed operations layer: reliability, latency, and cost at production scale, the unglamorous engineering problems that determine whether a pilot survives contact with real usage rather than stalling out somewhere between a demo and a shipped product.

For enterprise technology leaders, the Agents API changes the build versus buy calculus for anyone currently assembling agent orchestration from open source components. Teams that have spent the past year building internal session management, tool routing, and subagent coordination now have a credible managed alternative from the model provider itself, one with early evidence of double digit percentage improvements in cost and reliability metrics that matter to production deployments.

Strategic Takeaway

Engineering Leaders and Heads of AI Platform

Teams currently maintaining custom agent orchestration infrastructure should benchmark the Agents API against their internal stack now, before the next planning cycle locks in another year of build versus buy decisions. The reported cost and latency improvements from early adopters are large enough to justify a formal evaluation rather than a wait and see approach.

03

California Signs the Nation's First AI Audit Law and Gets Anthropic and OpenAI Both Behind It

Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 into law on September 9, creating the first independent third party audit framework for AI systems in the United States. The legislation applies to any company deploying AI in high stakes contexts, including hiring, insurance, and critical services, regardless of whether that company trained the underlying model itself.

SB 813, authored by Senator Jerry McNerney of Pleasanton, sets up a framework for recognizing independent organizations that assess AI systems for compliance with state law. AB 1405, authored by Assemblymember Rebecca Bauer-Kahan of Orinda, creates a state registry for AI auditors and sets standards for auditor independence, transparency, and integrity.

The mechanics matter for how quickly this framework will actually bite. Auditors seeking recognition under the new framework will need to demonstrate expertise in assessing AI risks and show they carry no financial, operational, or management dependence on the companies they audit, standards designed to keep the certifiers themselves credible. Standing up that certification apparatus will take state regulators time, and the framework remains voluntary in the meantime, with no automatic legal protections granted to systems that pass certification.

What distinguishes this signing from earlier state AI legislation is the industry response. Anthropic endorsed the bill package first; that endorsement was reported in August 2026, well before the vote. OpenAI, which had opposed similar measures in the past, reversed course and endorsed the bills just hours before Newsom signed them on September 9. In its statement, the company said, "Some of these bills we did not endorse in the past, and are now supporting after reconsidering in light of the recent jump in capabilities we have seen," an unusually direct acknowledgment that the labs themselves see rising capability as justification for outside verification.

Senator McNerney framed the signing as a rebuke of federal inaction, saying Newsom's signature "sends a clear message that California is taking the lead on assessing AI's safety risks, since Washington, D.C., is unable or unwilling to do so." Assemblymember Bauer-Kahan emphasized the stakes for the public directly, saying third party auditors are "essential to ensuring AI is safe for our communities and critical infrastructure."

The bills arrive against a backdrop of federal gridlock on AI legislation, where competing proposals for a national framework, and competing efforts to preempt state action entirely, have stalled repeatedly in Congress this year. California's approach effectively fills that vacuum with a state level regime that any company doing business in the state, which is to say nearly every major AI deployer, will need to account for regardless of where it is headquartered, and other states weighing their own AI oversight bills now have a concrete template to react to rather than a blank page.

For compliance and legal teams, the work of identifying which deployments fall under "high stakes contexts" is likely to take longer than the multi year runway suggests. Companies using AI in hiring, insurance underwriting, or other covered categories should begin mapping their exposure now rather than waiting for state regulators to finalize certification criteria.

Strategic Takeaway

General Counsel, Chief Compliance Officers, and Heads of Responsible AI

The voluntary nature of California's audit framework does not make it optional in practice. When two of the industry's most visible labs both publicly back independent verification, the reputational and procurement pressure to seek certification will likely outpace the legal requirement to do so. Legal and compliance teams should begin scoping which AI deployments fall under high stakes categories now, well ahead of the certification apparatus coming online.

04

Anthropic's Latest Threat Report Shows State Hackers Compressing Weeks of Work Into Hours

Anthropic published its September 2026 threat intelligence report this week, covering misuse activity the company detected and disrupted between December 2025 and August 2026, a span Anthropic's own overview describes as "the past eight months." The report organizes its findings into seven harm categories: cyber operations, surveillance operations, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation, and it documents in granular detail how state linked and criminal actors have adapted their tradecraft to incorporate Claude.

The cyber operations findings are the most striking. In one case Anthropic labels GTG-20006, a Russian state sponsored espionage operation used Claude to target more than 20 organizations spanning Ukraine, Europe, the Middle East, and Asia. In a separate case, GTG-50014, affiliates of the ShinyHunters group used Claude to mass download and scan 1.8 million Android application packages for hardcoded secrets as part of a credential harvesting pipeline, exfiltrating more than a terabyte of data that included hundreds of thousands of national identifiers and millions of payment card records, with one breach going from first access to bulk data theft in only hours.

A third case, GTG-10007, involved a Chinese speaking operation that targeted roughly fifty organizations across sectors including education, retail, energy, technology, healthcare, finance, and manufacturing, as well as multiple government agencies globally, with one workflow yielding more than a dozen possible zero day findings in a single month, a pace of vulnerability discovery that would have required a substantial specialized team before AI assistance became available to operators of this kind. Anthropic's report states plainly that "the cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well resourced, state sponsored operations from individual operators," a line that captures the report's central argument better than any statistic alone.

Influence operations documented in the report show similar scale. In case GTG-54002, an operation published more than 8,913 articles across roughly 70 fabricated news websites spanning 20 languages. In case GTG-84005, a separate election manipulation platform managed approximately 1,000 fake social media accounts. Both cases illustrate how content generation at industrial scale, once a resource intensive undertaking, has become accessible to operations with comparatively modest budgets.

Surveillance operations documented in the report include an Iran related case in which state aligned accounts cloned a real activist's account in order to hold live conversations with his contacts inside Iran, an application of the technology with direct implications for activists and dissidents.

Anthropic is careful to note the limits of AI autonomy in these cases. The report states that "humans remained in the loop by setting the targets of attacks and reviewing exfiltration," and that human operators retained the decisions that mattered most, including target selection and monetization. This is a meaningful qualifier: the threat documented here is acceleration and labor substitution within human directed operations, not autonomous AI initiated attacks, though the distinction may offer limited comfort to defenders facing compressed attack timelines regardless of who is pulling the trigger.

For security leaders, the practical implication is that detection and response timelines calibrated to pre AI attacker tradecraft are now dangerously out of date. When a single operator can complete reconnaissance, exploitation, and exfiltration in hours rather than weeks, the window for detecting an intrusion before damage occurs has compressed by a similar factor, and incident response playbooks built around longer dwell times need urgent revision.

Strategic Takeaway

CISOs and Security Operations Leaders

The compression of attack timelines documented across multiple cases in this report, from reconnaissance through exfiltration completed in hours, should trigger an immediate review of detection thresholds and response service level agreements. Security teams built around dwell time assumptions from two or three years ago are defending against an attacker profile that no longer exists.


The Analysis

The Bottom Line

Read together, this week's four stories describe an AI ecosystem where infrastructure, tooling, oversight, and risk are all scaling in lockstep rather than any one dimension racing ahead of the others. Oracle's $664 billion backlog and OpenAI's new managed Agents API both point toward an industry moving decisively from experimentation to production commitment, with real capital and real operational dependencies now attached to AI workloads at a scale that would have seemed premature not long ago.

At the same time, California's new audit law and Anthropic's threat intelligence findings are reminders that scale without proportionate oversight carries its own cost. The fact that Anthropic and OpenAI, competitors racing for the same enterprise customers, both ended up publicly endorsing an independent verification regime suggests the labs themselves see a credibility gap that self regulation alone cannot close. Anthropic's own documentation of state linked hackers compressing weeks of intrusion work into hours makes the case for that oversight in concrete, operational terms rather than abstract risk language.

The throughline for executive readers is that the infrastructure and tooling decisions being made this quarter, cloud capacity commitments, agent platform selection, compliance posture on emerging audit frameworks, and security operations built for a faster moving threat landscape, are no longer separable from each other. Organizations that treat them as four distinct workstreams owned by four distinct teams will find the gaps between those teams are exactly where the next costly surprise is most likely to appear.