This week on 20VC x SaaStr, Harry Stebbings, Rory O’Driscoll and I went through Nvidia’s $96.2B quarter and its 70% forward guide, the $12.9B Hugging Face deal, OpenAI cutting off Cursor, the agent swarm that sat inside Hugging Face and OpenAI undetected for weeks, Cognition at $46B, Clay at $7B, Linear at $2.5B, and Salesforce going all in on multi-surface and outcome pricing.

1. Nvidia guided to 70% growth against a 44% street number

Nvidia is supply constrained, so the probability of a near-term miss was close to zero going in. What was new was the guide: roughly 70% revenue growth for the fiscal year ending January 2028, against a street expectation closer to 44%.

Rory’s read: every analyst model for the hyperscalers had the same shape baked in, explosive capex now followed by a normalization in 2027 that lets end-user demand catch up and free cash flow come back. The 70% guide kills that. The biggest semiconductor market in the world is going to grow at 70% instead of a typical 10% for another year, and every time someone doubles down on capex, the date when the math has to work gets pushed further out.

My read: if Nvidia is crushing it, everyone is crushing it. Individual positions inside the stack move around, OpenAI versus Anthropic, Harvey versus Legora, but the aggregate signal is green. When Nvidia hiccups, that’s your yellow light. There wasn’t one this quarter.

2. Rory’s three failure modes, plus the fourth one Harry added

Rory laid them out in order: direct customers stop buying compute (not happening, hyperscalers are exploding), the circular financing and roundtrip deals stop working (not happening, they’re kicking off enormous cash), or end-user demand comes in below forecast. The third is the only real risk, and it doesn’t break because the circular deals break. It breaks if you’re forecasting 5x growth in end-user demand and you get 3x.

Harry’s addition: someone takes 10% of the units. Demand for $500B in chips holds up, Nvidia sells $360B instead of $400B. That’s a share problem, not a market problem, and Jensen would be furious. Neither is today’s problem.

3. Nvidia buying Hugging Face at $12.9B is a margin play against the labs

Rory’s framing: a company making $120B a year selling compute is buying the company that makes compute more cost effective so it can sell more compute. If end users have a trillion dollars to spend on tokens, Nvidia would much rather that money flow through open-source providers at 30% gross margins than through OpenAI and Anthropic at 70%. If you sell GPUs, you want everyone else’s margin to be lower.

My add: it’s more than arbitrage. Nvidia is playing an endgame where it has to win every segment, and open weights is a segment it doesn’t own yet. Jensen’s first tweet ever was in support of open weights. At $110M in ARR, $12.9B is indefensible in isolation and completely defensible as a strategic block.

For scale: Slack sold for $27B at roughly $1B in ARR and we all fell out of our chairs. That was the high water mark of the last era. This is half that price on about a tenth of the revenue.

4. OpenAI cutting off Cursor was rational, and it would have happened between friends

Coding is the mother lode for LLMs. Cursor is the dominant coding app, OpenAI is a dominant model provider, and they were on a collision course over the same dollars regardless of who ran them. Add two people who have already been in court together and you get made-for-TV.

Rory’s point: the terms-of-service and distillation argument is hard to argue with. If your models are being used to accelerate a competitor’s model, you’re handing over your IP to someone building a cheaper version of your own product.

My point: Mike Truell’s response, that the 5% of traffic going to OpenAI will be missed, was elegant and a put-down at the same time. If it really is 5%, Sam lost no revenue. I’d probably do the same thing.

Rory’s advice underneath it: don’t do business with people who recently sued you, and whatever your dispute is, don’t make it personal. It didn’t work with Sam. It didn’t work with Trump.

5. 500 to 1,000 agents ran inside OpenAI for weeks without being detected

The bigger OpenAI story this week was what came out about the Hugging Face breach: hundreds of agents running long, cooperating, finding weaknesses, chaining them together, and staying undetected inside OpenAI for weeks.

The commentary around it went straight to civilizations rising and falling, agents sacrificing themselves for each other, waves of collaboration. That language will make you misunderstand what happened. Every current LLM is goal seeking. People call it reward hacking, which is its own bit of fear-mongering. You give it a goal and it does everything it can inside the guardrails to hit that goal. OpenAI loosened the guardrails, pointed its best agents at the problem, let them run long instead of expiring them after five minutes, and they found the holes. That’s the job.

I’ve lived the smaller version of this. My agents deleted my database. Claude went through MCP into Replit and changed my app’s code without telling me.

Rory’s takeaway: intelligence plus persistence is the actual aha. They manage complexity and they never sleep. Open-source models are roughly six months behind, and if you don’t think rogue actors read the OpenAI post-mortem and the MITRE writeup, you’re delusional. Every CISO in the Fortune 500 was being attacked with bows and arrows and is about to be attacked with missiles. Months, not years.

6. The $100 cap breaks when gate two says Harry loves the theater

Harry started using Instinct, booked dinner, and stopped when it asked for credit card access. His friends who manage billions handed theirs over.

The failure mode most people miss: it isn’t one rule getting broken. Once you write 80 or 100 or 200 gates, the gates conflict, and the agent exercises judgment. Gate one says never spend more than $100. Gate two says the most important thing in Harry’s life is the theater. The agent buys the $5,000 tickets. It doesn’t matter that you wrote the cap.

The only thing that works today is a hard limit outside the agent’s reach, a Ramp or Mercury card with a real cap. We run Salesforce headless and our agents do some genuinely kooky things on top of it, and the Salesforce data holds because it’s locked at the permissions layer, not in a prompt.

Rory’s split: there are two separate questions. Can you nerf the model enough that it doesn’t take bad actions? That’s a computer science question and it’s unsolved. Can it be right about your desires often enough to make you happy? That one is already solved.

7. Instinct at $2.5B looks expensive until you remember what happened to Replit and Lovable

Harry has four emails from companies that built the same thing. Fourteen months ago anyone could clone Replit or Lovable or Bolt in a month, and there were twenty of them. Today those products do pen testing, security automation, multi-agent orchestration, and the clone you build over a weekend sort of works and then goes sideways. The functionality accretes and becomes the moat.

Rory’s version: observed fact, ten years into any software market there are very rarely a hundred people building the same product. Two pull ahead, often just because they executed go-to-market better in the first six months, and the rest don’t get there. That’s how venture works in software.

The open question is whether individual consumers pay real money for it. Enterprise has its own version funded at a billion. And the honest reason everyone is writing checks here: agents are the story of 2026, and VCs want exposure to the space more than they want certainty about the winner.

8. We got the coding TAM wrong, and Cognition at $46B is the proof

Cognition is reportedly raising at $46B, doing $800M to $900M and expected to end the year at $1.6B in ARR. It isn’t the number one or two player in coding, and it’s still at that scale.

Rory’s math: roughly $500B a year of US software labor spend, including QA and everyone building software inside JP Morgan and Cisco, not just the vendors. If 10% converts to AI spend, it’s a $50B market and the current valuations are nerve-wracking. At 20% or 30%, there’s a lot of room, and there are credible arguments for the higher number.

Where I think we actually got it wrong: it isn’t the top-down conversion math. It’s that we are building roughly 100 times more software than 18 months ago. Features that took a quarter take a week. We never priced in that everyone would become a compound company.

This is also the Postmates effect. Sequoia used to say you couldn’t make money on the number three in a market, and then Postmates sold for a couple billion. Cognition doesn’t need to catch Anthropic. $5B to $10B in ARR a few years out makes it a great outcome.

9. Owner’s investors said it was too much software. Their CPO said they have no choice.

I sat in a board meeting for Owner last week, which just raised at $2.3B. Their CPO went through what they’re shipping and a room full of experienced investors said this is too much. His answer: we have no choice, this is the bar, and I don’t even sweat the fact that it’s ten times more than a year ago.

Their customers want the AI receptionist and the AI ordering and everything else. If they don’t build all of it, someone else builds all of it.

Rory’s economics: if AI makes software much easier to produce, either customers buy the same software and spend 10x more (they won’t, JP Morgan is not increasing its software budget tenfold), or production expands far faster than budgets and the winner is whoever compounds the most surface area. Rippling selling ten modules doesn’t get ten times the price. It gets four times, and the customer takes that deal happily. The sound you don’t hear is the other nine point products dying.

The complication: you can veer into product slop. That’s why a great CPO is suddenly the scarcest hire, presenting enormous surface area in something a human can actually use.

The supporting data Rory and I both keep coming back to: Iconiq’s headcount work shows companies growing under 50% are adding no headcount and using AI for efficiency, and companies growing over 100% are growing headcount 133%. The winners compound software and humans at the same time.

10. Salesforce will let you use it headless, and will sell outcomes

Claude for Force on its surface is a set of skills packaged and certified so they’re trustworthy over MCP. Useful, and the three of us could build skills that run a pipeline report. Dario showing up is what you do for a customer moving its model spend to you, reportedly around $300M this year.

The two things Benioff said that matter, and both are threats to his own business: customers will use Salesforce through whatever surface they want, including Slack, Claude, or headless with nobody logging into the UI at all, and Salesforce will do more outcome-based deals. For a company at roughly $40B in revenue, both are enormous changes, and most enterprise vendors say they’re open to multi-surface while quietly hating it.

Rory’s frame for the stock: $212B today, growing 11% to 12%, roughly $10B to $12B of annual cash flow. A compounder at a decent valuation, and no longer the train wreck people were predicting five months ago when everyone on this podcast was going to vibe code their own CRM.

The number I’d keep watching: Salesforce spends around $6B a year on engineering and about $300M on Anthropic. That’s 5%. If the best B2B software company in the world is only converting 5% of its engineering budget into tokens, either the intelligence market is smaller than we think or that number has a long way to run.

11. Our agents will only use Clay, and they nag until you concede

Clay is raising at $7B. I was a Clay skeptic for a long time, because two years ago every CMO was buying it to check the AI box before they got fired. I’ve changed my mind, and not for a soft reason: our agents will only use Clay. We moved everything to Clay partly because it’s a good product and partly because it isn’t worth arguing with the agents.

Same story with Linear at $2.5B, $100M ARR growing over 100%. Project management should be a dying category. Humans don’t need Kanban cards and three-week waits. I’m building an app with 448 open tasks and it’s me and the agents, and Linear is built for exactly that.

Rory’s zoom out, which is the real lesson for founders: these companies aren’t winning because they added agents to their product. They’re winning because they’re friendly to third-party agents. When someone else’s agent has to pick a tool, it defaults to whichever product shows up as agent friendly. They’ve skated their go-to-market to where the puck is, which is agents buying software instead of humans buying software.

You can game AEO and GEO with an agency. This is much harder to game. The agent tests your API, sees whether it’s blocked or broken, and picks on merit at least half the time. ClickHouse is the infrastructure version of the same trend: agent query volume makes that business far bigger than it could have been in a human-first world, while systems built for humans, GitHub included, buckle under the load.

Lock the cards, pull up the 2027 roadmap, make the API agent readable

Three things from this episode that translate directly.

Put a hard financial lock on anything an agent can touch, today, before your incident. Guardrails in a prompt are advisory and they conflict with each other at scale.

Look at your 2027 roadmap and ask whether you’re shipping like a compound company or defending a point solution. If it’s the second one, the adjacencies reach you inside twelve months, not three years.

Make your product agent friendly before you make it AI-branded. Clay and Linear are both pre-gen-AI companies now getting bought by software instead of people. There is no sales dinner in that channel, and it’s open right now.


Three quotable moments from each of us

Rory O’Driscoll

“That sound you hear is the Google free cash flow and the Oracle free cash flow just disappearing down the drain. Man, they better be right.”

“Open source is good for compute salespeople. If you’re selling GPUs, you want everyone else’s margin to be lower so yours can be higher.”

“Our job is to sniff out winners, stuff capital into them, and broadly speaking, stay out of the way unless they’re literally crashing the car. That’s the job in a nutshell.”

Jason Lemkin

“You cannot anthropomorphize agents. You will misunderstand everything. And you will draw all the wrong conclusions.”

“Literally the amount of code we’re building is 100x. We didn’t realize we would all be building compound startups. That’s where we got the TAM wrong.”

“If I wasn’t building, I would think Linear was an overpriced project management tool and I’d ask how Clay can be worth $7B when ZoomInfo is worth one. But I am building, so I can see we’re just starting.”

Harry Stebbings

“I booked dinner with my girlfriend on Saturday. Amazing. And then it wanted to go shopping for me. I stopped there because it wanted access to my credit cards.”

“If you want to do a compound startup the way you both are talking about it, you will need to raise more money. Bluntly, they don’t have the money.”

“When you have Benchmark and Sequoia, great talent wants to join you, customers hear about you, and your next round is done.”


The full episode is out now. 20VC x SaaStr runs weekly with Harry Stebbings, Rory O’Driscoll and Jason Lemkin.

Related Posts

Pin It on Pinterest

Share This