Friday, June 12, 2026
FRIDAY – AI FOR THE C SUITE®
Read time: 9-10 min · Read online
Hi, it’s Chad. Every Friday, I serve as your AI guide to help you navigate a rapidly evolving landscape, discern signals from noise and transform cutting-edge insights into practical leadership wisdom. Here’s what you need to know:
1. Sound Waves: Podcast Highlights
This past Monday on AI for the C Suite®, I flew solo to hand you the most valuable strategic position in the market right now: the gap between what AI can do and what your competitors are actually doing. AI capability is now doubling roughly every four months and the researchers at METR who measure it say their own ruler is bending, because the best systems are running off the end of what they can reliably track. I break down why “we can’t measure this anymore” is the signal, not the noise and why history says you have roughly eighteen months before that gap stops being your opportunity and becomes the thing your competitors used while you watched.
Hit one of the below links to check it out:
Apple · Spotify · iHeart · Amazon · YouTube
2. Algorithmic Musings: Pop Quiz, Hotshot
Two months ago I sent you a forecast and stapled a warning label to the front of it. I told you it was a forecast and not a prophecy, and that I fight the urge to believe a couple of accurate calls add up to a crystal ball. I’m holding myself to that this week, because the thing I have to report is that the forecast came true, and being right this fast is the part that should bother you, not the part that should impress you.
On April 3rd I wrote that you should get ready for a very interesting six months in cybersecurity. I quoted Alex Stamos at RSA describing a near-future where AI tools reverse-engineer Microsoft’s monthly patches into working exploits, and I passed along his timeline of roughly six months to a year. I want to be honest about how that aged. It took two months, not six to twelve. And Stamos wasn’t being careless. He was describing a capability that, on the day he described it, didn’t exist yet. It exists now, it’s measured, and the people who measured it published the receipts.
What the receipts actually say.
Anthropic’s red team ran six AI models against real, already-patched security holes: 18 in Firefox and 21 in the Windows kernel. The setup matters. These are N-day vulnerabilities, the kind that are already public and already patched, but still wide open on every machine that hasn’t installed the fix yet. The window between “fix ships” and “everyone installs it” is the patch gap, and it’s where attackers do their work. The irony the report leans on is that the patch itself is a map to the bug. Compare the old code to the new code, find what changed, and you’ve found the flaw. That work used to take expert-weeks. There were never many experts, so the math protected you.
The math just changed. Anthropic’s most capable model, the one it isn’t releasing publicly, built eight working Firefox exploits and eight full Windows privilege-escalation chains. Its first Windows proof-of-concept landed in 31 minutes. To put a finer point on it: on Firefox, it had a working exploit within an hour of the patch going public, while the stable release carrying that same fix was still eighteen days away. Anthropic’s own phrase for this is the shift from N-day to N-hour, and the report’s blunt summary is that a single operator can now turn a month of patches into working exploits in an afternoon, for a few thousand dollars in API credits, with no specialized expertise required. The per-exploit cost they cite is roughly two thousand dollars.
Remember the bus.
In Speed, the premise was elegantly cruel. The bus could not drop below fifty miles an hour, or the bomb underneath it went off. The whole movie is people trying to keep a heavy, hard-to-maneuver vehicle above a line it was never built to hold.
Your patch process is the bus. For years it cruised comfortably above its safety line, because the line sat way down at expert-weeks and you were patching in expert-days. Monthly maintenance windows, two-week testing cycles, change-control sign-offs, vendor-coordinated update schedules: all of it was built when the floor was low and you had room to spare. Nothing about your process got slower this spring. The floor came up to meet you. And if your current cadence sits below where that line just moved, you’re already under it, and the dashboard hasn’t told you yet.
This is where most of the coverage stops. The trade press read the same report I did and arrived, almost to a publication, at the same closing sentence: patch faster. It’s not wrong. It’s just the advice you’d give the Fortune 150, written for people who have a security operations center to receive it. You don’t. So let me take the next step the security press keeps skipping, which is what this means specifically for a company your size.
Your “we’re too small to bother with” defense just expired.
Mid-market leaders have leaned on a quiet assumption for years: a skilled attacker’s time is expensive, and we’re not a juicy enough target to justify it. That was a reasonable bet when weaponizing a patch required a scarce specialist. It is no longer a reasonable bet, because the specialist isn’t in the loop anymore. When the cost of building an exploit falls to a couple thousand dollars and a weekend, the question stops being “are we worth an expert’s attention” and becomes “are we worth a script’s attention,” and the answer to that is always yes. The attacker pool didn’t grow. The expertise requirement that kept it small collapsed.
The systems you can’t patch are the exact ones in the crosshairs.
The report points its highest-risk warning at industrial control systems, medical devices, and internet-of-things equipment running on vendor-locked firmware, fixed maintenance windows, and uptime guarantees. That list is a description of a mid-market manufacturer’s plant floor. Your MES, the PLCs on the line, the ERP integration your vendor will only touch during a scheduled window negotiated three years ago: those weren’t designed to be patched on a Tuesday afternoon. They were designed to not be touched, because touching them stops the line. That was a feature under the old economics. It’s an exposure now.
Your risk triage is reading a stale actuarial table.
This is the finding I can’t stop thinking about. Microsoft rated 14 of the 21 Windows vulnerabilities in the study as “Exploitation Less Likely” or “Exploitation Unlikely.” The model built working proof-of-concepts for 13 of those 14, including a full privilege escalation for one Microsoft had rated unlikely. Those ratings are honest. They’re also calibrated to human researchers, a point Anthropic’s report makes directly. If your IT lead or your MSP is deprioritizing patches based on vendor likelihood scores, they’re triaging this year’s threats with last year’s odds.
So here’s what I’d put in front of your leadership team, not your IT team.
Three questions, and notice none of them are technical. First: what is our actual median time from a critical patch dropping to that patch being live across our environment? Not the policy. The policy is fiction. The real number, the one your logs would show. Second: which of our systems cannot be patched inside a week, and what specifically compensates for that gap while it’s open? Third, and this is the one that ties back to the authority piece I wrote you in April: who in this company actually has the standing to accelerate a patch outside the maintenance window when it matters? If the answer is “nobody, without a meeting,” you’ve found the bottleneck, and the bottleneck is organizational, not technical.
In April I suggested that you compress your assumptions about response time while it was still a planning exercise and not a crisis. That window is narrower than it was eight weeks ago. It is not closed.
My takeaway? The patching playbook your company runs on isn’t an IT detail. It’s a business process resting on an economic assumption that died on June 8th, and you’re the only person in the building with the authority to redesign it before someone else’s script forces the redesign on your timeline. The bus didn’t slow down. The floor came up. The job now is finding out, honestly, how much daylight you’ve actually got left, and there’s no shame in the answer being “less than I assumed.”
What’s your real time-to-patch, and which system would keep you up at night if a fix dropped tomorrow? Drop me a line at chad@chadharvey.com and tell me where you’re feeling the floor rise. I read every one.
3. Research Roundup: What the Data Tells Us
AI Agents vs Chatbots: The Real Story Isn’t Speed, It’s Reach
An agent that runs a task end to end is a different tool than a chatbot and new production-data research confirms it. Agents are faster and cheaper, but the real finding is what they change about the work. One person can now do jobs that used to need a team.
The numbers that matter: On matched requests, the agent did roughly 48 times the work on its own. A four-and-a-half-hour chatbot task finished in about thirty-five minutes, cutting time by seven-eighths and cost by more than nine-tenths. Agent queries crossed occupational boundaries more often, 59% versus 50% for chatbot queries.
What this means for your Monday morning: The headline isn’t productivity. It’s that a marketer can build the dashboard, an operator can draft the contract, leaning on fewer outside vendors. For a company that can’t staff every function, that’s everything.
The catch: This is vendor research, not peer reviewed: three of four authors work for the vendor studied, on its own unverifiable data. The users were power users, so treat the multiples as a ceiling. And verification becomes your new bottleneck.
Action item: Pick one long, multi-step task your team avoids because it crosses functions. Ask: “Could an agent draft this end to end, and who checks it?” Run it before trusting any speed claim.
Read our full analysis of this research at AI for the C Suite®.
4. Radar Hits: What’s Worth Your Attention
Anthropic’s new Fable 5 collects your data, no exceptions. Anthropic now retains all prompts and outputs on its Mythos-class models for 30 days, and existing zero-retention agreements don’t apply, even through AWS Bedrock or Microsoft Foundry. Microsoft restricted employee use within a day of launch. If your teams are testing Fable 5, loop in legal before sensitive data flows through it. Your zero-retention assumption just expired.
OpenAI’s Codex hit $1 billion in annualized revenue chasing Claude Code. Wired’s inside account shows OpenAI closing fast on a market leader, with both vendors reaching billion-dollar run rates within months. Translation for buyers: rapid feature releases and real pricing leverage. If you’re signing a coding tool contract right now, keep the term short. This market moves too fast for three-year commitments.
Complexity is the ceiling on AI coding gains. A study of 300,000 AI-written commits found 15% introduced new problems, mostly structural issues that accumulate quietly. Google’s DORA data shows the pattern clearly: AI amplifies strong engineering foundations and magnifies weak ones. Before scaling AI coding tools, ask your engineering lead one question: how healthy is our codebase? That answer caps your ROI.
5. Elevate Your Leadership with AI for the C Suite®
The floor came up for everyone this spring, including your competitors. The difference is who finds out from a planning exercise versus an incident report. I’m taking on a small number of mid-market strategy engagements this summer (shameless plug: that’s a hint), and the conversation starts with one email. If this issue made you rethink a maintenance window, send AI for the C Suite® to the person who owns it.
Stay safe. Stay healthy. Be strong. Lead well.
Chad
