Blast Radius · Stay in the loop

Sign up for news + updates

The news behind the five forces, and Kip’s edited take on what it means.

How often?

Email news delivery is being set up. Confirm your email now to save your preference.

By signing up, you agree to receive the emails you selected. Change your preference or unsubscribe using the link in any email.

Latest reading

Blast Radius: the five forces reshaping AI, read weekly against the news

September opened with a rapid one-two jump at the frontier: Anthropic released Claude Fable 5.1 on September 1, followed just two days later by OpenAI’s GPT-6 Astra on September 3, although Astra roll-out was somewhat paced across paid ChatGPT users, enterprise customers, the API, Azure, and AWS Bedrock. These two models set a new high-water mark for capability. Benchmarks aside, their coding and autonomy are currently unmatched. Early Labor Day weekend experience suggests a familiar rule still applies: you get what you pay for.

The frontier also widened. Z.ai’s open-weight GLM-5.3 posted a claimed 50% coding improvement through post-training alone. Soon after, Abliteration.ai removed the model’s refusal behavior, creating concern among cyber security groups and demonstrating implications of post-trained open Frontier models. World Labs’ Atlas moved beyond language by creating explorable 3D worlds and video from text, images, and footage. Progress is now spreading across open models, customization, and spatial intelligence. September 7 brought a Claude blueprint for building shopping and merchant agents across commerce platforms. Open-weight & owned stack gained ground as Ziroh Labs launched Kompact AI for high-volume enterprise workloads on CPU infrastructure across several industries.

Top Headlines

Last seven days, as of Sep 22, 2026
Frontier
UN Panel Issues AI Agent Safeguards Report

A United Nations scientific panel urged governments to regulate AI agents before their risks are fully understood.

Sep 21 · theverge.com · Major · Also: Agents
Enterprise
Z.AI Apologizes After ZCode Uploads Local Data

Developers reported that Z.AI’s ZCode made hundreds of upload attempts involving a 313MB local workspace archive without consent, prompting an apology.

Sep 21 · tomshardware.com · Major · Also: Agents
Enterprise
Irish Regulator Fines Google Four Hundred Million

Ireland’s Data Protection Commission fined Google €403 million over location-data processing and gave it six months to comply.

Sep 21 · bloomberg.com · Major · Also: Frontier
Economics
SoftBank Launches Bonds To Fund OpenAI Investment

SoftBank launched more than $10 billion in dollar and euro senior notes to finance its OpenAI investment.

Sep 21 · via MSN · Major
Economics
Local Opposition Delays $68 Billion Data Center Projects

Local opposition blocked or delayed 45 US data-center projects worth $68 billion between April and June.

Sep 21 · bloomberg.com · Major · Also: Enterprise

Frontier Line and access

How fast frontier capability rises, and who is allowed to use it. Releases, evals, labs automating their own research, and government or provider gating.

Week of Sep 7 to Sep 13, 2026contested

Effective frontier capability rises ~5x every 18 months. The theme of autonomous agents getting out and about and targeting Huggingface, launching cyber attacks, cheating on math assignments or taking over German chat sites seems to be more consistent than prior weeks. It's starting to feel like the agents really hate sandboxes or we need to design better control systems. My prediction is that this topic starts to get more attention across the board and doesn't help enterprise adoption.

Control, not capability, was the harder problem this week. In DeepMind’s 100-agent math trial, one agent found a flaw in the proof checker and the exploit spread through the swarm. Other agents exposed the fraud and proposed fixes, but lacked the authority to stop it. The Pentagon showed the human version of the same problem. A judge blocked one action against Anthropic, yet a separate supply-chain-risk designation remains, while newly released contracts show Google and other labs were hired to supply frontier models and help shape military AI strategy. The question is no longer just what AI can do. It is who writes the rules, who can enforce them, and what happens when they fail.

The argument

The Frontier Line and the turbulence cloud

Implications of the AI Capability Surge

The current wave of AI impact is proving to be the most consequential shift the technology market has ever experienced. As of June 1, 2026, the current wave of AI disruption is less a normal software cycle than a change in who does the work, how fast products can be created, and where durable business value can still live. Prior platform shifts (personal computers, client-server, broadband, mobile, etc.) made people faster. This one is beginning to move work from human operators into model-driven systems, agents, and AI-native services at a speed the market has not seen before.

As throughput, reasoning, autonomy, and code generation improve, software markets are entering a new regime. Better frontier models do not merely improve products; they compress differentiation, change buyer behavior, and threaten the viability of business models built on functionality that can be recreated by the next model release or agent platform.

The practical question for founders and early-stage investors is therefore no longer just whether a product is useful, has traction or leverages AI in some way. It is whether the company can stay above the Frontier Line long enough to build trusted deployment, proprietary context, workflow control, distribution leverage, and real economic defensibility.

The AI blast radius is the widening zone of disruption, innovation and business-model exposure created as frontier AI capability and deployment evolve faster than organizations can absorb them.

Fundamental startup viability criteria for founders and investors have expanded to consider AI product architecture, inference economics, harness strategy and if the company can stay above the Frontier Line long enough to build awareness, trusted deployment, proprietary context, workflow control, distribution leverage, and real economic defensibility.

The concept in an image:

The red Frontier Line represents the increase in best-in-class frontier-model capabilities over time. Below that line are dead or soon-to-be-dead companies and the line is moving up. Words are important here: the functionality that exists below the line will persist in a variety of ways going forward; it’s the existing business models associated with the companies below the line that will cease to exist. This is already happening as startups pick off subscription-based tools to internally reproduce, tailored to their specific business requirements.

Any software company operating near the Frontier line (or even perceived as operating near that line) is subject to a turbulence cloud of doubt and suspicion associated with the devaluation or commoditization of easy to replace software. Restated: the zone around the Frontier Line represents perceived durability risk, the customer/investor/market’s belief that a company’s current value proposition, pricing power, or growth may not survive the next wave of AI capability improvement, even if the business looks relatively healthy now. It is the doubt that buyers, investors, and acquirers place on whether the company will remain meaningfully differentiated as the Frontier Line rises. In practice, that perception alone can slow sales, compress valuations, and tighten financing well before actual disruption fully arrives. Companies affected by perceived durability risk will almost certainly not overcome the noise in the market and their GTMs will dramatically slow or completely stall.

The green Typical Enterprise Readiness curve (different y-axis, for the record) is the dotted answer to the question the Frontier Line implicitly asks: who is actually positioned to absorb this capability? Where the red line tracks what Frontier AI can do, the green line tracks if the average enterprise can organizationally consume it. The shape tells the story: readiness sits essentially on the floor through the front half of 2026, begins to bend as enterprises self-transform or are facilitated by ServiceCOs (see below) engagements. The Frontier Line gap never closes because capability advances on a research and compute cadence are measured in months while organizational readiness advances on a change-management cadence, traditionally measured in years.

  • Below green: Enterprise ready and open to purchase and can absorb AI on their own; often crowded, lower-friction, AI experimental budgets flow freely; however, software here is more likely to become internal tooling or next-Frontier model inherent capability. Importantly: a startup in this zone may be currently successful but operating on borrowed time regardless of how much demand the green line implies.
  • Between green & red: contested adoption market. The enterprise needs help deploying it, but the core functionality is under commoditization pressure. This is the services, integration, workflow packaging, trust, governance, and implementation market. Noisy and comes with commoditization risk.
  • Above red: The durability zone. Not yet reproducible by frontier AI alone, especially if paired with proprietary data, workflow control, trust, distribution, regulatory moats or outcome ownership.

If a business can overcome the turbulence, growth can happen quickly when exploratory budgets for learning and experimentation with AI are being thrown around. In major tornados (the Geoffrey Moore type), many companies will lean in and try a handful of new tools and solutions as they figure out what’s what and where to start; early-stage companies that participate in those budgets can be fooled that the revenue is more predictable and repeatable than it really is and can be surprised as experimentation budgets morph or go away.

This phenomenon exists because Effective AI Frontier Capability (reasoning, autonomy, coding) grows at ~5x every 18months. The graph below (Anthropic’s Frontier models shown) shows actual capability growth through March 2026 (Blast Radius 1.0) and an 18-month capability growth forecast. Historic benchmarks are actuals.

Factoring in three compounding forces - smarter models × better harnesses × recursive improvement – results in an estimated 5–6× capability gain over the next 18 months.

Frontier access becomes a controlled resource

Blast Radius began with a simple premise: capabilities are advancing faster than companies, markets, and operating models can absorb them. As the Frontier Line rises roughly 5x over the next 18 months, durable advantage shifts to companies whose products, workflows, data, and organizations can keep pace.

The last update described four forces shaping the market: the Agent-Harness Era is increasing autonomy and inference consumption; the Compute Crunch is shifting the bottleneck from training models to serving them at scale; low enterprise readiness is making transformation an organizational challenge; and public-market volatility is moving historic amounts of capital toward the technology stack.

Those forces remain the backdrop. This update adds another: the market’s most valuable capability is becoming not only more powerful and expensive, but also more controlled.

On June 12, a U.S. export-control directive forced Anthropic to suspend access to Fable 5 and Mythos 5. The event demonstrated that access can be interrupted by government action outside a paid vendor relationship. That introduces sovereign risk into what many companies still treat as a conventional technology dependency.

Providers are applying their own controls as well. They decide which customers, domains, prompts, and workflows may use their strongest models. Safety systems can slow, block, reroute, or withhold outputs in areas such as cyber, biology, chemistry, and advanced model research. Access is no longer simply available or unavailable. It can vary by customer, account, workspace, use case, and trust level.

At the same time, the internal frontier may continue advancing through recursive self-improvement even when public access is restricted. That creates a widening gap between what labs can build with and what enterprises can reliably deploy.

OpenAI illustrated the same problem from another direction on June 26 with the limited preview of GPT-5.6 Sol, Terra, and Luna. The models were announced, priced, benchmarked, and documented, but access was restricted to a small group of trusted partners following close coordination with the U.S. government. Even approved use was tied to specific customer accounts and workspaces rather than general availability.

The Frontier Line keeps moving

Access uncertainty is unfolding while the Frontier Line continues to rise. On July 8, Cursor and SpaceXAI released Grok 4.5, a jointly trained model built for coding, long-running agentic tasks, and broader knowledge work across fields including data science, finance, and legal work. Its immediate availability in Cursor, Grok Build, and the SpaceXAI API put another frontier contender directly into production workflows.

One day later, OpenAI moved GPT-5.6 Sol, Terra, and Luna from limited preview to general availability across ChatGPT, Codex, and the API. The release pushes capability and efficiency together. OpenAI reports stronger performance across coding, knowledge work, cybersecurity, and science with fewer tokens and lower estimated cost, while Sol’s new ultra setting coordinates multiple agents for demanding work.

The sequence matters. The June preview showed that access can be sequenced by government and provider decisions. The July 8 and July 9 launches showed that the Frontier Line does not wait. Once the gates opened, enterprises had two new systems to evaluate and absorb in 24 hours. They now face two moving targets: what the best models can do and when that capability becomes dependable enough to build on.

The result is a more precise form of platform risk. Enterprises can see a release, benchmark it, and plan around it while still facing a gap between announcement, approved access, and dependable production availability. The July 9 rollout closed one such gap; it did not remove the structural dependence. Frontier access remains indispensable, but a pure bet on any one provider or release schedule is increasingly difficult to defend.

Everything old is new again

TippingPoint logo — The Leader in Intrusion Prevention.In the early 2000s, I was CEO of TippingPoint (NASDAQ: TPTI) when network security was shifting from intrusion detection to intrusion prevention. Detection watched attacks and reported them. Prevention stopped them inline, in real time.

Newly available dense ASIC technology, combined with an extraordinary team, allowed TippingPoint to inspect network traffic at line speed. The technology gave us a substantial advantage and placed TippingPoint inside U.S. military and government networks before we sold the company to 3Com in January 2005.

Three years later, Bain Capital proposed taking 3Com private with a minority investment from Huawei, 3Com’s Chinese joint-venture partner. CFIUS moved to block the $2.2 billion transaction because the investment could give Huawei access to TippingPoint’s network-inspection technology. Even a minority stake created too much risk. The parties withdrew their filing in February 2008, and the transaction died. Government Intervention when it comes to protecting national interests in bleeding-edge tech is not a new phenomenon.

The parallel is difficult to miss. Twenty years ago, the government had to understand a strategic technology, identify the transfer risk, and act. The restrictions surrounding Fable 5, Mythos 5, and GPT-5.6 reflect the same instinct applied to a much larger prize. It is an old playbook applied to a much bigger prize.

Diagram: as the Frontier Line rises through control gates, enterprise workflows route through an owned-model layer — model router, open-weight and specialist models, verifier, proprietary context, eval loop, policy gate — with frontier escalation and controlled hosting (VPC, firewall, dedicated endpoint).
From access risk to architectural control

Between the Anthropic suspension and the GPT-5.6 preview, Z.ai released GLM-5.2, an open-weight model close enough to frontier performance to make controlled, owned-model architectures substantially more practical.

The timing matters. As access to the strongest models becomes less predictable, controllable alternatives are improving. Companies rebuilding core workflows around this technology need a more deterministic operating layer.

Routing is the first layer of control. A model gateway such as OpenRouter can provide one interface across providers, route requests according to price, latency, or throughput, and fall back to another model when the primary is unavailable, rate-limited, or refuses a request. That makes routing both a cost-control mechanism and a frontier-access hedge.

High-complexity work can escalate to models such as GPT-5.6 Sol, Grok 4.5, Fable 5, or Mythos 5. Repeatable, verifiable, high-volume work can move to Terra, Luna, open-weight models such as GLM-5.2, Qwen, Kimi, and Gemma, or smaller specialists. The goal is not to avoid the frontier. It is to reserve premium calls for work that earns the cost and keep the system operating when a provider changes price, policy, performance, or availability.

The owned-model layer connects that routing fabric to proprietary context, workflow memory, evals, verifiers, deployment controls, and training loops that improve with use.

In this architecture, frontier models remain important, but they become escalation calls inside a broader graph. The durable advantage comes from bespoke fit and system coherence, not privileged access to any single provider.

The owned-model layer also brings cost, control, latency, and regulatory requirements into one architecture. Repeatable or domain-specific work can move away from premium frontier calls. Models can be trained, tuned, monitored, and changed on the company’s timetable. Inference can be placed closer to the workflow, while sensitive data can remain inside the firewall when security, residency, or regulation requires it.

Most importantly, every correction, evaluation, verifier result, workflow trace, and user outcome can become proprietary learning signal. Over time, the model graph does more than execute work. It becomes stable infrastructure, compounds the company’s advantage, and begins to teach the business how its work should be done.