Humans In The Loop

Archives
Log in
May 14, 2026

Humans In The Loop -- Thursday, May 14, 2026

Humans In The Loop

Thursday, May 14, 2026
Humans In The Loop
Your five-minute briefing on everything artificial intelligence.

Happy Thursday. The AI industry had a week so packed that your inbox needed its own AI agent just to keep up. Cerebras hit Nasdaq like a rocket, OpenAI launched a whole new company to hold your hand through deployment, SAP declared your ERP is now autonomous, and hackers poisoned the software tools your dev team used on Monday. Buckle up.

In today's newsletter
-> OpenAI's new 'Deployment Company' wants to move into your office
-> SAP Sapphire goes full autonomous: your ERP is getting a brain
-> Mini Shai-Hulud: the AI supply chain attack your IT team needs to see NOW
-> Cerebras pops 68% on Day 1, GenZ takes the AI job hit, and the regulation patchwork gets messier
Nasdaq
26,635
+0.9%
S&P 500
7,501
+0.8%
Nvidia
$235.75
+4.4% (new all-time high)
Bitcoin
$81,414
+2.5%
OpenAI*
$300B+
private
Your AI pilot program
Sunk cost
46% chance it's underperforming
Per a new Oxford Economics study of 800 companies, nearly half of all enterprise AI initiatives are not meeting expectations. Your pilot program called; it wants a strategy.
TOP STORY
OpenAI Just Built a Company to Move Into Your Business and Do the Hard Part For You
Photo by Hakim Menikh on Unsplash
OpenAI Just Built a Company to Move Into Your Business and Do the Hard Part For You

OpenAI this week launched the OpenAI Deployment Company, a new unit designed to embed specialist engineers directly inside businesses to overhaul their workflows around AI. The company also acquired Tomoro, an applied AI consulting firm, bringing roughly 150 engineers on day one. Backers include McKinsey, Bain, Capgemini, Goldman Sachs, TPG, and SoftBank, among 19 total partners. Think of it as OpenAI going from selling you the hammer to showing up and building the house.

Why does this matter to you? Because the era of 'we'll figure it out internally' is officially over. OpenAI's own revenue chief said enterprise AI is 'at a tipping point' and that enterprise now makes up more than 40% of OpenAI's revenue, expected to reach parity with consumer by year-end. The Deployment Company's engineers will identify where AI has the biggest impact in your specific workflows, redesign those workflows, and stay to make it stick. Real-world clients like Tesco and Virgin Atlantic have already worked with the Tomoro team. This is not a chatbot subscription. It is an operating-model overhaul.

  • OpenAI's engineers will embed inside client organizations to redesign critical workflows, not just advise from a slide deck.
  • The partnership sponsors more than 2,000 businesses globally, meaning your competitors are likely already in the queue.
  • OpenAI also quietly signaled it is leaning toward Amazon Web Services (AWS) for enterprise cloud delivery, putting some daylight between itself and longtime partner Microsoft.

Looking ahead, if OpenAI and SpaceX follow through on rumored 2026 IPOs, the capital raised could make Cerebras's blockbuster $5.5B debut look like a warm-up act.

--ML


VENDOR NEWS
SAP Sapphire 2026: Your ERP Software Just Got Declared Autonomous (Here's What That Actually Means)

At its annual Sapphire conference in Orlando this week, SAP CEO Christian Klein asked a pointed question on the keynote stage: 'Will SAP be a software company in the future?' The answer, delivered by SAP's own Joule AI assistant, was: 'SAP is becoming a business AI company.' The company launched the SAP Business AI Platform and SAP Autonomous Suite, a system with 224 AI agents and 51 assistants that can run finance, supply chain, HR, procurement, and customer experience workflows from start to finish. Anthropic's Claude is now a primary AI engine baked in across the whole portfolio.

Here is the plain-English version for your board meeting: if your company runs SAP, your ERP system is about to start making decisions, not just reporting on them. A fashion retailer called LC Waikiki showed a live demo where answering a procurement question that used to take 10 minutes now takes three seconds, resulting in a 70% jump in operational efficiency. SAP's CEO said it plainly: 'No AI agent can compensate for a bad data landscape,' which means your first homework assignment is data quality, not buying new software.

  • The SAP Autonomous Suite spans five domains: finance, spend, supply chain, human capital management, and customer experience, all governed and auditable.
  • SAP is investing €100 million in its partner ecosystem for agent development, with its Joule Studio 2.0 tool free of charge through year-end.
  • Early live deployments include autonomous financial close at multiple enterprises, autonomous sourcing at Novartis, and product design at Kaiser Compressor, so this is real, not vaporware.

Looking ahead, SAP's autonomous finance agents targeting CFOs and Chief Compliance Officers will be the real test of whether 'autonomous ERP' is a revolution or a very expensive rebranding.

--ML


SECURITY ALERT
The Mini Shai-Hulud Attack: Hackers Poisoned the AI Tools Your Developers Installed Last Monday
Photo by Jake Walker on Unsplash
The Mini Shai-Hulud Attack: Hackers Poisoned the AI Tools Your Developers Installed Last Monday

[ Reported without editorial commentary ]

On May 11, a threat group called TeamPCP launched a coordinated supply chain attack dubbed 'Mini Shai-Hulud,' compromising over 170 software packages used by developers worldwide, including TanStack (a tool with 12.7 million weekly downloads), the official Mistral AI SDK, the UiPath enterprise automation library, and Guardrails AI. The attack worked by hijacking the legitimate release pipeline of TanStack using a chain of three GitHub security flaws, then spreading automatically to hundreds of other packages. OpenAI confirmed two of its employee devices were affected and has required all macOS app users to update by June 12.

The CEO translation: if your development team installed any of these packages on May 11, their computers should be treated as potentially compromised and every password and API key accessible from those machines should be changed immediately. This is not theoretical. The malware was designed to steal cloud credentials (AWS, Google Cloud, GitHub tokens) silently in the background and send them to attacker servers. The average supply chain breach costs $4.91 million and takes 267 days to detect. Ask your CTO or IT vendor today: were we exposed?

  • The attack hit packages with a combined 518 million cumulative downloads, including tools used in healthcare, retail, and financial services app development.
  • A Cisco security report published this year found that 83% of organizations plan to deploy AI agents, but only 29% feel ready to do so securely, which is how attacks like this find so many targets.
  • Immediate action if exposed: rotate all cloud credentials, revoke GitHub tokens, and block the domain git-tanstack.com at your network level before doing anything else.

Looking ahead, Google's threat intelligence team warns that attackers are now using compromised AI agents to pivot into broader enterprise infrastructure, meaning your AI tools are becoming a front door for ransomware.

--ML


REGULATION WATCH
No Federal AI Law Is Coming. States Are Filling the Void, and Your Legal Team Is Not Ready.
Photo by Anil Baki Durmus on Unsplash
No Federal AI Law Is Coming. States Are Filling the Void, and Your Legal Team Is Not Ready.

Congress has not passed a federal AI law. It probably will not before the midterms. Into that gap, California, Texas, Colorado, New York, and at least four other states have enacted enforceable AI rules that took effect January 1, 2026. If your company uses AI to make decisions about hiring, lending, housing, or healthcare, you are already operating inside a patchwork of state regulations with real teeth. The EU AI Act's high-risk provisions kick in by August 2, 2026 for companies with European operations or customers.

What this means in plain English: a national brand campaign or HR software deployment now crosses at least five different state AI compliance regimes. The SEC has also identified AI-driven threats as a top examination priority for 2026, and cyber insurance carriers are now requiring documented AI security controls or charging higher premiums. The cheapest strategy, per legal experts, is to build your compliance program to satisfy the strictest state (California) and roll it down to the rest.

  • California's automated decision-making rules require pre-use notices and opt-out mechanisms for consumers when AI is used in consequential decisions.
  • Colorado's AI Act takes effect June 30, 2026 and requires risk management policies, impact assessments, and bias testing for high-impact AI systems.
  • The White House released a National Policy Framework for AI in March 2026 urging federal preemption of state laws, but it is non-binding and creates no immediate compliance relief.

Looking ahead, the most likely federal outcome before the midterms is narrow, sector-specific legislation covering deepfakes and child safety, not broad preemption of state AI laws, so do not wait for Washington to save you.

--ML


WORKFORCE
AI Is Cutting 16,000 U.S. Jobs a Month. The Twist: Most Are Entry-Level Roles That Never Get Posted.

Goldman Sachs economists published one of the most detailed analyses yet of AI's labor market impact, finding that AI is eliminating roughly 16,000 U.S. jobs per month, with entry-level white-collar workers under 30 bearing the brunt. The mechanism is subtle: companies are not mass-firing people. They are quietly closing the door to new hires. Yale's Jeffrey Sonnenfeld calls it 'the opportunities that never materialize.' Meanwhile, a Gallup survey of 23,717 U.S. employees found that 65% of workers inside AI-adopting organizations say AI has improved their productivity, but only 27% say it has changed how work gets done at a large scale.

The CEO takeaway is this: AI is not replacing your existing workforce yet, but it may be eliminating your talent pipeline. If your company is not hiring the junior analysts, customer service reps, and billing clerks you used to, who will be your senior leaders in 10 years? BCG's research found that the key challenge is not the number of jobs affected, but how quickly workers can be upskilled and redeployed. PwC data shows workers with advanced AI skills earn 56% more than peers without them, so the best retention play right now is paying for AI training.

  • Gen Z workers are most exposed because they are concentrated in routine white-collar roles like data entry, legal support, and customer service that AI automates most easily.
  • Leaders report the strongest productivity gains from AI, with 21% of executives saying AI has had an 'extremely positive' impact on their work, versus 13% of individual contributors.
  • Healthcare workers and technical professionals are the early leaders in reported AI productivity gains, per the same Gallup survey.

Looking ahead, the World Economic Forum projects a net gain of 78 million jobs globally by 2030, but the jobs destroyed and the jobs created will not be in the same zip codes, industries, or skill sets.

--ML


M&A AND MARKETS
Cerebras Pops 68% on Nasdaq Debut in the Biggest AI IPO of 2026 (So Far)

AI chipmaker Cerebras Systems began trading Thursday on Nasdaq under the ticker CBRS, raising $5.55 billion at a $185-per-share IPO price and then surging 68% to close at $311, pushing its market cap to roughly $95 billion. The company builds chips on a single silicon wafer, roughly 58 times larger than Nvidia's top chip, and claims speed advantages for running AI models in real time. It holds a $20 billion cloud computing deal with OpenAI and has signed agreements with Amazon Web Services for use in Amazon data centers.

Why should a non-tech CEO care? Because Cerebras is a signal flare for where capital is flowing. AI infrastructure stocks are up dramatically this year, with the semiconductor index up 58% in 2026 alone. The IPO is also seen as a test run for expected blockbuster listings from SpaceX, OpenAI, and Anthropic later this year. If those deals close, expect a flood of new AI vendors knocking on your door with fresh venture capital behind them and an appetite to sign enterprise contracts fast.

  • Cerebras revenue jumped 76% last year to $510 million and the company swung to profitability, making it a rare AI company with real numbers behind the hype.
  • The IPO is the largest U.S. semiconductor offering on record, surpassing the $5.23 billion raised by Arm Holdings in 2023.
  • Global AI investment hit $297 billion in the past year, with JPMorgan Chase alone spending $2 billion annually on AI, per a new BCC Research report released today.

Looking ahead, Nvidia reports earnings on May 20 with Wall Street expecting $78.8 billion in quarterly revenue, and a beat would likely send the entire AI sector higher heading into summer.

--ML


Stat
THE PILOT PROBLEM
46%
Nearly half of enterprise AI initiatives are falling short of expectations, per a new Oxford Economics survey of 800 U.S. business leaders. The top reason is not bad technology. It is that companies are treating AI like software you deploy and walk away from, rather than an ongoing operating function that needs an owner, a roadmap, and continuous management.

What else is brewing
->IBM unveiled its 'AI Operating Model' blueprint at its Think 2026 conference, including IBM Sovereign Core for companies that need to run AI in regulated environments without sending data to public clouds.
->OpenAI's new B2B Signals research found that 'frontier firms' now use 3.5x as much AI per worker as typical firms, up from 2x a year ago, and the gap is compounding fast.
->A Microsoft SharePoint zero-day vulnerability (CVE-2026-32201) is actively being exploited and allows remote code execution across more than 1,300 exposed servers. Patch now.
->Cisco stock surged 14% today after strong earnings, making it one of the Dow's biggest single-day movers in years and lifting the index back above 50,000 for the first time since February.
->Arm and SoftBank reportedly attempted to acquire Cerebras weeks before its IPO, were rebuffed, and watched the chipmaker go public at a valuation nearly 12 times what it was just eight months ago.
->A new Cisco security report found that while 83% of organizations plan to deploy AI agents, only 29% feel truly ready to do so securely, which is the compliance gap that keeps your CISO up at night.
Written by the Humans In The Loop desk. Sources: OpenAI (openai.com), Capgemini press release, SAP Sapphire 2026 News Center (news.sap.com), SAP Sapphire Innovation News Guide (sap.com), ERP Today, Constellation Research, Coastal/Oxford Economics 2026 AI Operations Report (GlobeNewswire), BCC Research AI Investment Report (GlobeNewswire), Goldman Sachs Research via Fortune, Gallup Workplace Survey (April 2026), BCG 'AI Will Reshape More Jobs Than It Replaces,' Yale Insights/Jeffrey Sonnenfeld, TanStack npm Supply Chain Postmortem (tanstack.com), Snyk, Wiz, StepSecurity, Orca Security, SafeDep, OpenAI Security Response (openai.com), Google Cloud Threat Intelligence Blog, Cisco State of AI Security 2026, CNBC, Yahoo Finance, Motley Fool, Bloomberg, Fortune, Morningstar (market data as of May 14, 2026 close), DBL Lawyers, Kiteworks, Everything PR/May 2026 AI Regulation Roundup, Software Improvement Group, Wilson Sonsini.

Don't miss what's next. Subscribe to Humans In The Loop:
ember.new
Powered by Buttondown, the easiest way to start and grow your newsletter.