The AI Brief

Vol. I · No. 2 · Wednesday, May 27, 2026
Anthropic is closing a $30B+ round at a $900B+ valuation this week, vaulting past OpenAI in the private-market rankings just as both companies race toward public listings. Git pushes rose 78% year-over-year in Q1 2026 — yet U.S. software developer employment hit a record high, defying displacement predictions. A one-month update on Project Glasswing reveals that Anthropic's unreleased Mythos model has already found more than 10,000 critical-severity software vulnerabilities, shifting the security industry's bottleneck from discovery to patching. AI now outperforms the average human on standardised divergent-thinking tests, though the top 10% of human creatives still lead every model. And Microsoft's computer-using agents — capable of operating any software a human can — reached general availability in May, quietly drawing the boundary on legacy robotic process automation.

Anthropic closes in on a $900 billion private valuation, overtaking OpenAI

Why it matters
Anthropic is set to close a funding round exceeding $30 billion at a pre-money valuation above $900 billion during the week of May 26, which would make it the world's most valuable private AI company, surpassing OpenAI's $852 billion valuation from March. The round came together in weeks, not months — inbound proposals arrived in late April and term discussions kicked off in early May. That pace signals investor urgency rather than a company on a standard fundraising cycle. The underlying revenue trajectory explains the pricing: Anthropic projects $10.9 billion in Q2 2026 revenue, more than double Q1's $4.8 billion, and has told investors its annualised run rate will exceed $50 billion by end of June. The company also expects Q2 to be its first profitable quarter. This is the second $30 billion round Anthropic has closed inside a single calendar year; in February it raised the same amount at a $380 billion valuation.
What's at stake
For most operators, this is context, not a decision. For enterprise buyers already under multi-year contracts with either Anthropic or OpenAI, the valuation gap sets up a competitive dynamic that will intensify through the dual IPO runway: both companies are expected to go public as early as autumn 2026. Investors evaluating secondary-market exposure or IPO participation face the question of whether a $900 billion private entry price — structured with preferred-stock protections — already captures the trajectory, or whether post-IPO re-rating remains plausible at current revenue growth rates.
Detail

Bloomberg reported on May 22 that Sequoia Capital, Dragoneer Investment Group, Altimeter Capital, and Greenoaks Capital Partners are co-leading the round, each contributing roughly $2 billion. Existing investors including Founders Fund and General Catalyst are also participating. Total commitments are tracking north of the $30 billion target, per people familiar with the matter. Three of the four co-leads have prior investment ties to OpenAI, a notable shift in allegiance that reflects Anthropic's revenue acceleration relative to its rival. Big Tech cloud partners — Google and Amazon, each of which has committed tens of billions in separate strategic arrangements — are not expected in this specific round.

Anthropic's annualised revenue run rate stood at roughly $4 billion in July 2025; CEO Dario Amodei described "80x growth" in revenue and usage in the first quarter of 2026 at a conference this month. The primary drivers are Claude Code (annualised revenue of $2.5 billion as of February, with enterprise users representing more than half) and the broader Claude enterprise suite. The company is also suing the U.S. Department of Defense over a supply-chain-risk designation issued after Anthropic declined to permit its technology for autonomous weapons use; a preliminary injunction is in place, but the case remains active. That litigation puts hundreds of millions to several billion dollars of 2026 government revenue at risk — a bearish counterweight to the headline valuation.

On May 22, OpenAI separately filed its IPO prospectus confidentially with the SEC, with Goldman Sachs and Morgan Stanley leading, targeting a public listing as early as September 2026. Both frontier labs are now on parallel paths to public markets before year-end.

Disclosure: Anthropic, mentioned in this item, is the company that develops Claude, which generates this brief.


78%
Year-over-year increase in global Git pushes, Q1 2026 · Microsoft AI Economy Institute · May 7, 2026

AI coding tools are producing more code — and more software developers

Why it matters
The volume of code being pushed to repositories globally surged 78% year-over-year in Q1 2026, a figure that sits alongside a counterintuitive labour-market data point: U.S. software developer employment reached approximately 2.2 million in 2025, up 8.5% year-over-year and a record high for the profession. Early Q1 2026 data shows developer employment in March running about 4% above March 2025 levels. The pattern is consistent with Jevons' Paradox — when the cost of producing something falls, demand often rises fast enough to increase total consumption, including total labour input. The displacement narrative, which dominated coverage through 2025, is running ahead of the observable employment data.
What's at stake
The paradox has distributional limits. Entry-level developer hiring has dropped sharply even as aggregate employment holds; the 73% decline in junior role postings reported in Ravio's 2025 data sits alongside the record aggregate employment figure. The pipeline question — whether suppressed junior hiring creates a senior talent shortage in five to ten years — is not resolved by the current aggregate numbers. Organisations building workforce plans around AI-driven developer headcount reduction may be working from a flawed baseline, but those assuming all roles are safe are reading only half the data.
Detail

Microsoft's Q1 2026 Global AI Diffusion Report, published by the AI Economy Institute on May 7, is the primary source for the 78% git-push figure and the 2.2 million developer employment count. The report draws on aggregated, anonymised Microsoft telemetry adjusted for OS market share, internet penetration, and population. It notes the causal chain explicitly: AI coding tools lower the cost of producing software; if demand for software is elastic, organisations respond by building more, which can sustain or increase developer headcount even as individual productivity rises. Japan, where model performance on Japanese-language benchmarks improved sharply, saw git pushes rise 129% year-over-year — nearly double the global rate — alongside a jump from 56th to 48th in the AI adoption rankings. New Git repositories rose 45% globally compared with Q1 2025. Vendor-interest caveat: Microsoft publishes this report and sells GitHub Copilot; readers should apply independent verification before using the figures as the sole basis for workforce projections.

Microsoft AI Economy Institute: Global AI Diffusion Q1 2026 (primary)/ Microsoft On the Issues blog/ CaveatData derived from Microsoft's own telemetry; the company sells AI coding tools. Figures should be cross-checked against independent labour-market sources before use in workforce planning.

Project Glasswing's first-month update: patching is now the bottleneck, not finding bugs

Why it matters
Anthropic's unreleased Claude Mythos Preview model has identified more than 10,000 high- or critical-severity zero-day vulnerabilities across systemically important software in the first month of Project Glasswing, the company announced May 26. The figure includes work by approximately 50 partner organisations — among them AWS, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, NVIDIA, and Palo Alto Networks. Several partners report that their rate of bug discovery increased by more than a factor of ten. Cloudflare alone found 2,000 bugs, 400 of them high or critical severity, with a false-positive rate that Cloudflare's team rates as better than human testers. The operational implication is a phase shift: progress on software security is now limited by how quickly humans can verify, disclose, and patch vulnerabilities — not by how quickly they can find them.
What's at stake
For most operators, the immediate practical effect will arrive as an unusually heavy patch cycle in the second half of 2026, as Glasswing-discovered vulnerabilities clear their 90-day coordinated disclosure windows and reach public advisories. Microsoft has already signalled that its patch releases will "continue trending larger for some time." The deeper structural question is whether the traditional 90-day disclosure window — designed for a world where finding bugs was the constraint — remains fit for purpose when a single model can discover thousands in weeks. Security teams that measure mean time to remediate in days rather than hours are not calibrated for this environment.
Decode
Zero-day vulnerability = a software flaw unknown to the vendor and therefore unpatched at the time of discovery. "Zero-day" refers to the number of days the vendor has had to fix it. Because no patch exists, exploitation carries higher risk than for disclosed, patchable flaws. The term is distinct from bugs that are known but unpatched — those are tracked via CVE identifiers after disclosure.
Detail

Anthropic's initial Glasswing update, published at anthropic.com on May 26, reports that Mythos Preview has scanned more than 1,000 open-source projects and found 6,202 high- or critical-severity issues, of which 1,752 have been independently assessed by six security research firms. Of those assessed, 90.6% proved to be valid true positives. At current post-triage rates, Anthropic projects nearly 3,900 confirmed high- or critical-severity vulnerabilities in open-source code alone — separate from the partner-organisation findings. Mozilla found and fixed 271 vulnerabilities in Firefox 150, ten times the number found in Firefox 148 using the previous-generation Claude Opus 4.6. Mythos also identified a 27-year-old flaw in OpenBSD and a 16-year-old bug in FFmpeg that survived five million automated scanner passes.

A significant operational challenge is already surfacing on the maintainer side. Several open-source maintainers have told Anthropic they are capacity-constrained and have asked the company to slow its disclosure rate. Of the 530 high- or critical-severity bugs disclosed to maintainers so far, only 75 have been patched and 65 public advisories have been issued — a reflection of both the 90-day disclosure clock and the ecosystem's remediation bandwidth. Anthropic has committed $100 million in model usage credits to Project Glasswing participants and donated $4 million to open-source security foundations. The UK AI Security Institute independently assessed Mythos Preview as the first model to solve both of its multistep cyberattack simulation scenarios end-to-end.

Anthropic has stated it will not release Mythos publicly until it has developed stronger safeguards; the model's offensive capabilities are described as an emergent consequence of general improvements in code, reasoning, and autonomy rather than intentional security training.

Disclosure: Anthropic, mentioned in this item, is the company that develops Claude, which generates this brief.

Anthropic: Project Glasswing initial update (primary)/ Anthropic: Project Glasswing programme page (primary)/ Help Net Security (May 26, 2026)/ CaveatAggregate statistics are from Anthropic's own reporting. True-positive rates assessed by six independent firms per Anthropic's disclosure; underlying firm names and methodology not yet public.

AI now outscores the average human on creativity tests — but not the top 10%

Why it matters
A peer-reviewed study published in Scientific Reports in January 2026 has circulated widely this week, representing the largest direct comparison of human and machine creativity to date: more than 100,000 human participants tested against leading large language models including GPT-4, Gemini Pro 1.5, Llama 3, and Llama 4. The headline result — that several AI models now outperform the average human on the Divergent Association Task, a standardised divergent-thinking benchmark — is being cited across hiring, creative-services, and knowledge-work discussions. The limiting finding receives less coverage: the most creative humans, particularly the top 10%, still decisively outperform every model, and the gap widens sharply on richer narrative tasks such as haiku composition, story plots, and flash fiction. The study does not resolve whether AI "creativity" is generative or recombinative, but it establishes an empirically testable baseline for the first time at scale.
What's at stake
For most operators, this is context about where AI capability currently sits, not a decision point. The operative question is which creative tasks in a given organisation sit in the "above average but below top-decile" range — that is the zone where AI substitution is most credible today. The finding also has a measurement caveat: the Divergent Association Task captures semantic divergence, one dimension of creativity, not narrative depth, emotional resonance, or craft. Benchmark performance on DAT should not be extrapolated to creative domains where those dimensions dominate.
Decode
Divergent Association Task (DAT) = a psychometric test that asks participants to generate ten words as semantically distant from each other as possible (e.g., "telescope," "legislation," "whisper"). Distance is measured via word-embedding models. It correlates with broader creative aptitude measures in humans and is designed to be fast enough to administer at internet scale — which is why it enabled 100,000-participant comparison. It captures divergent thinking, not all dimensions of creativity.
Detail

The paper, "Divergent creativity in humans and large language models," was published in Scientific Reports on January 21, 2026, led by Professor Karim Jerbi of Université de Montréal's Department of Psychology, with contributions from Yoshua Bengio (Mila/Université de Montréal), and collaborators at Concordia University, University of Toronto Mississauga, Google DeepMind, and other institutions. GPT-4 scored higher than typical humans on the DAT; Google's Gemini Pro 1.5 matched average human performance; Meta's Llama 3 and Llama 4 also exceeded the average. All models fell short of the top 10% of human performers. The study explicitly noted that AI creativity is shaped by human instruction — parameter settings like temperature and prompt framing produced significant output variation.

The study is peer-reviewed and published in a Nature Portfolio journal, which provides stronger methodological grounding than vendor-published benchmarks. The primary caveat is that DAT measures one dimension of creativity. The researchers themselves note that performance on richer narrative tasks — haiku, fiction, story synopsis — showed a wider gap in favour of top human performers. The paper has resurfaced in mainstream circulation this week alongside the broader Anthropic funding news, producing a misleading aggregated framing ("AI beats humans at creativity") that the study's nuance does not support.


Microsoft's computer-using agents reach general availability, making RPA's limits visible

Why it matters
Microsoft made computer-using agents in Copilot Studio generally available on May 13, rolling the feature out to all commercial geographies across the Microsoft Power Platform — with limited industry coverage outside enterprise IT circles. A computer-using agent operates any software application a human can use — browser, desktop UI, legacy portal — without requiring custom API integrations or hard-coded screen selectors. It uses vision and reasoning to navigate live interfaces, which means it does not break when a vendor updates their UI. This distinction matters structurally: it removes the primary fragility of robotic process automation (RPA) and makes any process a human can navigate manually a candidate for automation, regardless of whether the underlying system exposes an integration layer.
What's at stake
For most operators, this is context. For organisations in sectors with high administrative burden — professional services pulling data from multiple portals, healthcare navigating insurance clearinghouses, logistics managing carrier websites — the economics of the previous constraint (RPA brittleness, custom connectors, maintenance overhead) have materially changed. The GA release includes session isolation, audit logging, and human-approval triggers for sensitive actions, which addresses the primary enterprise governance objection. Early adopters in preview reportedly automated invoice processing, customer data verification, and compliance checks previously requiring five-system toggling.
Decode
Robotic process automation (RPA) = software that mimics human actions in a user interface by recording and replaying clicks, keystrokes, and screen coordinates. Traditional RPA is brittle: it locks onto specific UI elements and breaks when those elements change. Computer-using agents replace the hard-coded script with live vision and reasoning, making them resilient to UI changes and capable of handling exceptions the original script never anticipated.
Detail

The Copilot Studio May 2026 update — confirmed in Microsoft's Community Hub on May 13 — also delivers a redesigned workflow designer in early release, native voice capabilities, and Work IQ interoperability. Microsoft simultaneously moved Agent 365, its governance and observability layer for AI agents across cloud and local endpoints, to general availability on May 1, priced at $15 per user per month standalone or included in the new Microsoft 365 E7 bundle at $99 per user per month. Agent 365 provides inventory, policy controls, and audit trails for agents built on Microsoft Foundry, AWS Bedrock, and Google Gemini Enterprise — extending coverage to third-party-built agents running on managed Windows endpoints.

The market-structure implication is direct: when Microsoft ships computer-using agent capability to GA across all commercial geographies, it sets the competitive clock for RPA incumbents. UiPath and Automation Anywhere have both been developing vision-based agents, but the integration into Copilot Studio's existing low-code builder and Microsoft's enterprise licensing stack gives the GA release distribution advantages independent of raw capability. Microsoft describes the driver as "accelerating agent sprawl" inside organisations — a framing that lacks independent confirmation but is consistent with enterprise IT governance trends observed since agentic tools began reaching production scale in 2025.

Microsoft Community Hub: M365 E7 and Agent 365 GA (primary)/ Microsoft Security Blog: Agent 365 GA (primary)/ Enterprise DNA (May 24, 2026)/ Note"Agent sprawl" framing is Microsoft's own characterisation; independent quantification of unmanaged local agent prevalence has not been published.