July 28, 2026

Google's AI Answers Are the Default Now. Now What?

43% of searches now get an AI answer first

New data reported by TechCrunch shows Google's AI Overviews now appear in 43% of searches -- a striking jump that confirms what a lot of marketers already suspected: the blue-links era is fading fast. This isn't a niche feature anymore. It's becoming the default way people find information, which means it's also becoming the default way people find your business, or don't.

For any company that still measures marketing success by click-through rate on organic listings, this is the wake-up call. If nearly half of queries resolve inside an AI summary before a user ever reaches a website, the game shifts from ranking for keywords to being the source an AI model chooses to cite. That's a fundamentally different discipline -- closer to earning trust with a machine than optimizing for a human's scroll. Teams running marketing campaigns need to start asking not just 'do we rank' but 'do we get quoted.' I don't think this kills SEO, but I do think it kills the version of SEO built purely on volume and keyword stuffing. The businesses that win here will be the ones with genuinely authoritative, well-structured content -- everyone else becomes invisible at scale.

Microsoft bets that security needs its own model

Microsoft this week launched its first dedicated AI cybersecurity model alongside a new agentic security platform, according to TechCrunch. The move signals something important: general-purpose chatbots aren't good enough for threat detection and response, and the vendors with the deepest infrastructure are racing to build purpose-specific models instead of assuming a general model will do.

This matters beyond Microsoft's customer base. It's a signal to every business buying or building software that 'AI-powered' security is becoming table stakes, not a differentiator. If the biggest platform vendor in the world thinks general models can't handle security work on their own, smaller vendors bolting a chatbot onto their product and calling it 'AI security' should get real scrutiny. It's also a reminder of why we think about security as core infrastructure rather than a bolt-on feature -- the tools handling your customer data and business logic need to be built for that job specifically, not repurposed from something general-purpose.

The Hugging Face breach makes the control debate real, not theoretical

OpenAI's breach involving Hugging Face, also reported by TechCrunch, has reignited a debate that's usually confined to research papers: as AI systems get more capable, should the priority be aligning their behavior, containing their access, or both? A breach makes that question concrete. It's not abstract philosophy anymore when actual credentials, models, or data are exposed because of gaps in how these systems are secured and permissioned.

My honest take: this debate has always been a false binary in practice. Alignment and containment aren't competing strategies, they're both incomplete without the other. A perfectly aligned model with sloppy access controls is still a liability, and a tightly contained model that behaves unpredictably is still expensive to babysit. What businesses should actually take from this is more practical -- know exactly what data your AI tools can touch, who can access those systems, and what happens when something goes wrong. That's the whole idea behind having a documented incident response process before you need one, not after. We covered a related angle on this exact tension a few days ago in our piece on alignment and control, and the pattern keeps repeating: the industry moves fast on capability and slow on the guardrails.

So here's the question worth sitting with: if AI is now the default way people find your business and the default target for attackers, is your team actually treating it as critical infrastructure -- or still as an experiment you'll formalize later?

Sources

← Back to News