Market Pulse

Market Pulse

Your AI Vendor Looks Like a Franchisor

A supplier embeds engineers at your site, brings the orchestration layer and the standard operating procedures, and asks you to supply the proprietary data and domain expertise. Structurally, that's a franchise — and franchise economics has decades of evidence on how value splits between the party who owns the system and the party who owns the location. Most of it favors the system owner.

Your AI Vendor Looks Like a Franchisor
A supplier embeds engineers at your site, brings the orchestration layer and the standard operating procedures, and asks you to supply the proprietary data and domain expertise. Structurally, that's a franchise — and franchise economics has decades of evidence on how value splits between the party who owns the system and the party who owns the location. Most of it favors the system owner.
Research Digest
READY or Not: Reliable Enterprise Agent Deployment
Evaluation moves from "how capable is this agent?" to "what does it cost to operate this agent at a given reliability target?"
Agents 0.3 points apart in accuracy needed 29.6% vs. 39.2% human review to qualify at the same reliability threshold.
Research Digest
τ^τ-Bench: An Environment for End-To-End, Realistic Agent Construction
Process, not raw capability: developers searched docs instead of reading them, rarely interviewed simulated clients, and rewrote inherited code without running it.
58 points between AI-built and expert-built agents, with failures tracing overwhelmingly to implementation discipline rather than model limitations.
Operating Manual

Australia's Signals Directorate published guidance on September 11 specifying what belongs in the infrastructure wrapping an AI agent — the "harness," in their language. Eleven components, from permission systems and sandboxed execution environments to audit logging and supply-chain update paths. If you've ever written a runbook for production systems, the shape is familiar.
What's worth paying attention to: ASD treats the model itself as a replaceable part. The harness is the organizational investment that persists across model upgrades, and the place where security controls actually live. Prompt injection can't be reliably solved inside the model, so you solve it outside — least privilege, human approval gates for high-impact actions, cost monitoring as a security signal.
ASD also includes seven governance questions for boards, starting with whether the system needs to be agentic at all. And a useful caveat: no harness is inherently secure. You still defend in depth.






