TechCrunch reported that Runlayer, a startup building an MCP gateway, is suing Rippling after accusing the HR-and-payroll giant of evaluating its product, then building a competing version in-house. If the allegations hold up, this is one of the least original moves in enterprise software: let a small vendor pitch you their idea, then decide you'd rather own it. What makes this instance notable is the category. MCP -- the protocol that lets AI assistants securely connect to a company's internal tools -- is suddenly valuable enough that a platform as large as Rippling wants to control the gateway itself rather than depend on a startup for it. We've written before about how MCP is changing the way AI assistants connect to your tools, and this lawsuit is a pretty direct illustration of why that layer matters: whoever owns the connection layer between AI and your business systems has enormous leverage, and everyone building a platform knows it. My take: this will keep happening as long as 'let me evaluate your product' remains a legal way to get a free look at a roadmap. Startups pitching infrastructure to platform companies should assume the worst-case outcome is on the table and structure NDAs and diligence calls accordingly. It's also a caution for buyers -- if you're picking a vendor specifically because they're independent and focused, ask what happens if their biggest platform partner decides to build it themselves.
Sam Altman told TechCrunch he's newly open to slowing down, crediting a security incident he says he felt "very viscerally." That's a striking admission from the executive who has spent years arguing the industry can't afford to move slower than its competitors. I don't think this is OpenAI suddenly turning cautious as a company policy -- it reads more like one person's gut reaction to a scare, which is a different thing than an institutional course correction. But it's still worth taking seriously, because it confirms something buyers should already assume: the labs building these systems are themselves surprised by their own security exposure. If the person at the top of the frontier-model race says an incident rattled him personally, that's a signal that the industry's internal risk models are still catching up to reality. For any business layering AI into daily operations, the practical lesson isn't to wait for the labs to get comfortable -- it's to control what you can control now, which is why we built out a dedicated Security posture and incident response process rather than assuming a vendor's calm public messaging means the underlying risk is handled.
Two smaller stories today say a lot about where AI money is actually going. Recursive Superintelligence signed a $410 million compute deal with Amazon, explicitly to pour money into automating its own product development rather than hiring people -- a company betting its budget on machines building the next version of itself faster than a team could. Meanwhile, Fish Audio raised a $52 million seed round on the strength of real numbers: over 8 million users and $21 million in annual recurring revenue for its voice models, according to TechCrunch. Put those next to each other and you see two very different bets on the same boom. One is speculative compute infrastructure chasing a self-improvement thesis that hasn't been proven at scale; the other is a company that already has paying customers and a working product. As a buyer evaluating AI tools, that distinction matters more than the funding headline. Revenue and retention are still the best predictor of whether a tool will be around and improving in two years, not how large the compute commitment is. It's the same logic we'd apply to any buy vs. build decision -- impressive infrastructure spend on its own tells you nothing about whether the product in front of you actually works for your team today.
Which of these stood out to you more -- a platform allegedly copying a startup's product, or a lab's own CEO admitting a security scare changed his mind about the pace of the race?
Sources