The hardest part of deploying AI inside a real company has nothing to do with how smart the model is.
That’s the quiet thread running through the TechCrunch Disrupt 2026 conversation featuring Anthropic, Gamma, and Clay — three companies sitting at very different points in the stack, all dealing with the same unglamorous reality. Once AI stops being a demo and starts being a dependency, the interesting questions turn into plumbing questions. Where does the data live? Who can see it? What happens when something breaks at 2am? Who signs off?
If you’re reading this without an engineering background, that’s actually good news. The stuff that determines whether AI works at a company is largely stuff you already understand.
Data control became the product feature
In August 2026, Reuters reported that Anthropic plans to let enterprise customers exercise greater control over their data by keeping their 30-day retained data on their own cloud infrastructure, rather than only inside Anthropic’s systems. The 30-day retention requirement stays. What changes is where those records sit.
On paper that sounds like a footnote. In practice it’s the kind of thing that decides whether a deal closes. I’ve watched plenty of AI pilots stall not because the tool underperformed, but because a legal or compliance team couldn’t get a clear answer about data residency. A bank, a hospital system, a European retailer — these organizations have rules that predate generative AI by decades, and those rules don’t bend for a good demo.
So when a frontier model provider starts shipping features aimed at data location instead of data cleverness, read it as a signal. The buyers have changed. They’re asking procurement questions, not research questions.
Anthropic’s revenue mix explains its behavior
Roughly 80% of Anthropic’s revenue comes from enterprise customers, compared with around 40% for OpenAI. That single number explains a lot of product decisions that otherwise look strange from the outside.
A company whose money comes from consumers optimizes for delight, virality, and reasons to open the app. A company whose money comes from enterprises optimizes for audit logs, permissions, contracts, and predictability. Both are legitimate businesses. They just produce different-looking roadmaps.
And the competitive picture isn’t settled. Enterprise technology forecasters including Dave Vellante and Gemma Allen have predicted OpenAI will exit 2026 with more enterprise revenue than Anthropic, while still expecting Anthropic to do well. Two companies can both grow fast in a market this young.
Safety policy is now a shared negotiation
Anthropic’s Responsible Scaling Policy v3.0, published February 24, 2026, kept its capability-threshold framework but shifted emphasis toward transparency and industry-wide recommendations rather than unilateral pauses. The policy openly acknowledges the risk of one company stopping development while competitors keep going.
That’s a candid admission, and I think a useful one for non-technical readers to sit with. Safety commitments from a single lab have a ceiling. If pausing simply hands the market to someone with fewer commitments, the pause achieves less than it appears to. Which is why the newer framing leans on disclosure and coordination — the kind of thing that only works if multiple parties participate.
There’s a security dimension too. Anthropic has disclosed industrial-scale distillation attacks it attributes to three Chinese AI labs. Distillation, in plain terms, is training a cheaper model by systematically querying an expensive one and learning from its answers. It shows that frontier providers are targets, not just suppliers — and that the security burden in this market runs in every direction.
What the deployment data actually shows
The 2026 State of AI Agents Report drew on insights from over 500 technical leaders and real-world implementations at companies including Novo Nordisk, Doctolib, L’Oréal, and Shopify. Those are not startups experimenting on a whim. They’re large organizations with existing systems, existing staff, and existing risk tolerance.
What you learn from that group is rarely a story about model benchmarks. It’s a story about scoping a problem narrowly enough to measure, wiring an agent into tools it’s allowed to touch, and building a review step for the cases where it guesses wrong.
What this means if you’re the one evaluating AI at work
You don’t need to understand transformer architecture to ask good questions. Try these:
- Where is our data stored, for how long, and can we choose the location?
- What exactly is this agent allowed to do without a human approving it?
- How do we find out when it fails, and who owns the fix?
- If we switched providers next year, what would break?
- What does the vendor publish about its own safety and security practices?
None of that is exciting. All of it is what separates a pilot that quietly dies from a system people actually use. The vendors have noticed, which is why their announcements have started to sound less like science fiction and more like enterprise software. That’s a sign of a market maturing, not cooling.
🕒 Published: