The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Monday, September 7, 2026 · Issue #87

Hey there 👋

I read the McKinsey survey everyone is citing this week, once for the number everyone would quote, and again for the number nobody would.

The loud one is easy: a third of companies skipped buying a piece of software this year and built it instead with coding agents. Every write-up will lead with that. So here is my bias, for what it is worth. That stat is real, and it is also a trap, because the money you save by not buying does not disappear. It moves. It becomes a compute-and-tokens bill that arrives every month for as long as you run the thing you built, and only one company in five is tracking it. Today is about the decision underneath the headline.


The Big Thing

A third of companies skipped a software buy to build it themselves

McKinsey’s State of AI 2026 came out in late August, and the build-versus-buy line it draws moved hard this year. 32% of organizations decided against buying at least one off-the-shelf product or feature this year and built it with agentic coding tools instead. The pull is strongest where you would expect: technology firms at 41%, healthcare payers and providers at 39%, professional services and energy at 38%. Among the roughly 6% McKinsey calls high performers, the ones crediting 5% or more of their profit to AI, nearly half are skipping purchases, against 31% of everyone else.

The other headline number is scale. 40% of billion-dollar-plus enterprises now run agents in one or more functions, up from 27% a year ago. Agents crossed from pilot to line-of-business inside twelve months at the top of the market.

The roundups will skip this part. The savings on the software you did not buy is not free money. It turns into a run cost: the compute and the tokens to operate what you built, for as long as it runs, plus the engineers who now own a system a vendor used to maintain. McKinsey found 20% of organizations already naming AI operating cost as a real constraint. That is one company in five, before most of these home-built systems have hit their second year of upkeep.

Grade the source honestly. This is a self-reported global survey, so treat it as directional. People overstate how much they built and understate what it costs to keep running. Believe the direction here, and treat the exact decimals with more caution.

Why it matters / Ship it? This is not a thing you deploy. It is a budgeting call you make this quarter. Pull your SaaS renewals, mark the ones a coding agent could plausibly replace, then price the run cost of owning each one for three years before you cancel anything. Build when you own the workflow and can carry the bill; keep buying when what you are really paying a vendor for is maintenance you would rather not hire for.

Sources: McKinsey, The State of AI 2026 (primary survey). Coverage: Yahoo Finance, ANI.


Tour de Headlines

👥 Cisco handed all 90,000 employees a personal agent. MyAgent runs on Cisco’s own governed platform, Circuit, mostly on-premises, and it does one clever thing worth copying: it routes each task to the cheapest model that can handle it instead of defaulting to the priciest. An employee sets an objective, the context, and the outcome they want, and the agent sequences the steps across Outlook, Webex, Jira, and SharePoint, with a human still approving the real actions. Skip the headcount number. The part worth copying is the shape: cost-aware model routing, persistent memory, and supervised autonomy over tools people already live in. Cisco has not published productivity numbers yet, so treat the win as a design pattern for now.

📈 The Trade Desk shipped agentic buying with Kokai Zuma. The new release puts “Ask Koa” at the center: one conversational door to a set of agents that build audiences, create campaigns, pull insights, and troubleshoot inside the programmatic workflow. It is rolling out to Kokai clients worldwide now. The Trade Desk says recent Kokai upgrades drove an average 32% improvement in cost-per-acquisition in early results, which is the vendor’s own number from its own early data. AdExchanger, less breathless, called the update a set of “AI-powered easy buttons.” Agentic buying is arriving in the RevOps and GTM stack for real. Judge it on qualified conversions you can trace, because a smoother chat box does not move that number.

⚙️ CIQ gave agents the keys to compute orchestration. Fuzzball 4.2 adds an MCP server that lets an AI agent inspect a Fuzzball environment and then draft, submit, and monitor real workflows, while running workflows can spin up more work on their own. Admins keep the permission fence: who can touch which resources, plus new org-level storage isolation. It also broadens AMD GPU support. This is the same governed-MCP move we keep flagging, now aimed at infrastructure rather than data. A year ago MCP was mostly about reading your files; this points an agent at your cluster, inside the rails you set. Niche if you do not run HPC, and a clean template to copy if you do.


Sponsor

Your team’s calls are full of signal you never grade.

RapportScore reads your recorded calls and measures how your people communicate, then coaches them on it. Real measurement, not vibes.

See your team’s score →

Tool of the Day

🛡️ OpenAI’s Defense Factory (the pattern, not a product)

A continuous agent loop that finds, proves, and fixes your own bugs before an attacker does.

It is a blueprint you can copy this week. OpenAI described the Defense Factory as an agent-first pipeline that continuously hunts vulnerabilities, validates them in isolation, and prepares tested fixes for a human to approve. To prove it, they pointed GPT-5.6-Cyber at V8, the JavaScript engine inside Chrome, and it surfaced two unknown flaws that chain together to escape the sandbox. The framing they use is a “defender’s window”: you can hand an agent your entire codebase, and an outside attacker cannot. That access is the edge. The steal-this move is small and doable: wire a scheduled agent to your own repo, have it look for one class of bug, and require a human to sign off on every fix it proposes. Start narrow, keep the human on the trigger.

Read the Defense Factory writeup →


Worth a Click

  • McKinsey, State of AI 2026. The primary survey behind today’s lead. Read it and grade the numbers yourself. mckinsey.com
  • OpenAI, The Defense Factory. The defender’s-window argument, plus the two V8 zero-days they found to make the point. openai.com
  • AdExchanger on Kokai Zuma. The skeptical read on The Trade Desk’s “easy buttons,” handy for grading that 32% CPA claim. adexchanger.com

The value question moved again this year, from which model you pick to whether you build or buy and can carry the run cost. McKinsey says a third of companies already skipped a purchase to build. Cisco built its own agent layer on-premises and routes to the cheapest capable model. CIQ shipped the plumbing so you can run your own. The base model is a commodity input now, cheap and interchangeable. The thing that costs real money is owning the workflow on top of it, and only one company in five is pricing that. Build the part you want to own. Buy the part you would rather not babysit.

See you tomorrow.
— Ron