Four signals from the past 48 hours that operators should read together: the AI software market is maturing faster than expected, the supply chain behind frontier models is consolidating, a widely deployed AI compute framework has an active exploit that reaches its federal deadline today, and state regulators are beginning to set legally enforceable terms for AI infrastructure.

OpenAI's enterprise business overtakes consumer — and its CFO names 2027 for the IPO

On 14 August, CFO Sarah Friar confirmed to investors that OpenAI's enterprise revenue has crossed its consumer revenue for the first time, ahead of her own prior forecast. The company entered 2026 at a 60-40 consumer-to-enterprise split; those lines have since reversed. At current trajectory, the overall revenue run rate stands at $40 billion, up roughly 35% this quarter, with the enterprise side growing at 50%. A third pillar is emerging: advertising is approaching a $1 billion annualised run rate, with testing underway inside ChatGPT since February.

At an all-hands on 19 August, Friar told staff that OpenAI "will be a public company in 2027," potentially sooner if the business "continues to inflect." On the question of timing pressure from Anthropic — which is targeting an October IPO at a $2 trillion valuation — she said: "We are running our own race." An IPO prospectus is expected on SEC EDGAR before month-end, which will make audited unit economics visible to competitors for the first time.

The operator implication is direct: OpenAI is no longer primarily a consumer product company. The structural shift toward enterprise contracts changes how its pricing, product roadmap, and support behaviour will be weighted going forward. Teams evaluating OpenAI as a long-term partner should be reading its prospectus as carefully as any vendor contract.

Nvidia explores a strategic stake in its own data annotation supplier

The Information reported on 19 August that Nvidia is in discussions to invest in Mercor, an AI data annotation startup, as part of a round that would value Mercor at $20 billion — double the $10 billion valuation from its Series C nine months ago. The round is being led by General Catalyst. Mercor earned tens of millions of dollars from Nvidia in the last quarter alone, labelling training data for Nvidia's Nemotron open-source model family.

The move is not philanthropic. Nvidia's compute dominance depends on continuous model improvement, and continuous model improvement depends on quality labelled data at scale. An equity stake in a supplier that already earns the majority of its revenue from Nvidia is vertical integration by another name — and it puts Nvidia closer to the training economics of the labs it supplies.

For operators who buy AI training data or use annotation services: Mercor's rapid valuation growth, and Nvidia's interest in anchoring it, is evidence of how tight the frontier data supply chain has become. Access to quality labelled data at competitive prices may not remain a commodity much longer.

Actively exploited Ray RCE reaches its federal patch deadline today

CVE-2025-62593, a remote code execution flaw in the Ray distributed AI compute framework, carries a CVSS 4.0 score of 9.4 and was added to CISA's Known Exploited Vulnerabilities catalogue on 17 August after the agency upgraded its status from proof-of-concept to active exploitation. US federal civilian agencies were given three days to apply the fix — a deadline that expires today.

The attack path is a browser-based DNS rebinding technique that bypasses Ray's only access control: a check of whether the HTTP User-Agent header starts with "Mozilla." Because browsers allow modification of that header, an attacker who can get a developer to visit a malicious web page while Ray is running can reach Ray's dashboard and execute arbitrary code on the developer's machine, CI/CD runner, or Kubernetes cluster. Ray is used by Amazon, Apple, and OpenAI to scale machine learning workloads.

The fix is straightforward: upgrade to Ray 2.52.0 or later. The harder problem is discovery. Ray is frequently installed on developer workstations, container images, and cloud-based data-processing clusters without central inventory. Any organisation using Ray should audit all environments immediately, including build pipelines that import it as a dependency.

Pennsylvania makes AI data centre guardrails legally binding

Governor Josh Shapiro signed an executive order on 18 August converting Pennsylvania's voluntary Governor's Responsible Infrastructure Development (GRID) standards into legally enforceable requirements. All AI data centre proposals are removed from the state's Fast Track permitting programme. Developers must now execute a consent order with the Department of Environmental Protection committing to binding targets on energy sourcing, water conservation, local hiring, and community approval — with penalties for non-compliance.

Pennsylvania's action is the first in the US to mandate — not merely encourage — environmental and community-benefit commitments as a condition of AI infrastructure permitting. Other states watching power-grid strain from data centre growth are likely to treat it as a template.

For operators evaluating US data centre locations, the effective cost of new capacity in Pennsylvania has increased in ways not visible in the headline lease rate. Consent-order compliance, extended permitting timelines, and community-approval requirements should all factor into total infrastructure cost models.

The through-line across today's brief: the AI industry is exiting the permissive early phase. Revenue structures are consolidating around enterprise contracts; supply chains are being locked in through equity stakes; ML infrastructure is being actively targeted by attackers; and state regulators are filling the vacuum left by slow federal action. Operators who built strategy on the assumption that the current open environment persists should update their models.