Top VC Perspective:
Where Enterprise AI Is Headed
Investors who fund AI startups at inception see where enterprise AI is headed years before most business leaders. Top seed VC Ed Sim explains what current investment patterns mean for the enterprise.
In 2026, the question for enterprise AI leaders is not whether to use the technology but what it costs and who controls it. Ed Sim of boldstart ventures, ranked the number one seed investor in the Business Insider Seed 100, backs companies at the idea stage and sees the problems enterprises will hit in a year or two. The conversation covers model routing, open-weight models, agent access, autonomous attack and defense, and why the people behind a vendor matter more than its architecture.
Key Points
- Enterprises are moving toward dozens of models running side by side, with routing that sends only the hardest work to the frontier labs.
- Give agents access only at runtime, scoped to the task and expiring with it, rather than the standing credentials of a human user.
- Cost per outcome is becoming the measure for agent work, and the evaluations behind that number are data a company should own.
Enterprise leaders are making AI commitments now, and their value depends on where the technology goes. The earliest view of that future belongs to investors who fund AI companies before a product exists. Episode 928 features Ed Sim, founder and general partner at boldstart ventures, who has been ranked the number one seed investor twice in Business Insider's Seed 100 and is an inception backer of Snyk and Protect AI. The conversation maps what current early-stage investment reveals about where enterprise AI is headed.
What we will cover:
- Where early-stage AI investment is flowing and what those bets predict for enterprise technology over the next three years
- Rented versus owned intelligence: when to rely on frontier model APIs and when to build specialized models from your own data
- What the rise of open-weight models means for cost, control, and vendor lock-in
- Security for the agentic era: how autonomous AI agents change enterprise risk, as seen through an investor's map of the security market
- The coming AI vendor shakeout and how to judge which startups will still exist in three years
- AI economics after the subsidy era: token costs, ROI per workflow, and what AI really costs at scale
Watch episode 928 with Ed Sim live on Friday, August 7, 2026, at 1:00 PM ET on CXOTalk. Subscribe for key takeaways from every episode and advance notice of live shows.
Episode Participants
Ed Sim is the founder and general partner of boldstart ventures, an inception-stage investor in enterprise software with more than $1.1 billion under management. This is his third appearance on CXOTalk.
Michael Krigsman is a globally recognized analyst, strategic advisor, and industry commentator known for his deep expertise in business transformation, innovation, and AI leadership.
In This Episode
Ed Sim: How will the world look when you have autonomous swarms of agents that are going to do anything possible to chain multiple vulnerabilities together, and they can penetrate your systems 24/7? That's a really, really scary world that we're going to live in. No humans can keep up with that amount of attack infrastructure right now.
Michael Krigsman: Today's startups are tomorrow's enterprise technology. Ed Sim of boldstart ventures is a top-ranked venture investor. Ed, what are the core AI challenges facing enterprise buyers right now?
Three waves and the ROI test
Ed Sim: Wave 1 was all about board members and CEOs saying, let's get AI up and running. Wave 2 was, how do we get agents up and running? And I think we're still early in that wave because a lot of stuff is still stuck in dev environments and not fully in production. And I think Wave 3 right now is all about ROI because people are seeing that some of the easy-button use cases, like using Claude Code and watching that expense go up exponentially, means let's think about tokenomics.
So I look forward to diving more into all those. And the only other thing I want to bring up is that now underpinning all of that is security, and we can talk about that as well.
Michael Krigsman: In other words, AI is going from the almost, you could say, toy or experimental stage to the stage of it needs to actually prove itself. Is that a good way of saying it?
Ed Sim: Absolutely. I just like to think about frameworks. There was a period of time back in, during the holidays at the end of the year and beginning of the year, when Claude Code just came out of nowhere, and all of a sudden people just got superpowers. It was no longer about spitting out code; it was about agents doing work for you. And then Claude Cowork came out, and all of a sudden you could have agents start doing work for you.
And there was a period of time where lots of investors and lots of folks were like, oh my, oh man, this is over. Claude is going to take over the world. And that was kind of, you know, the first few months of the year, and now if you look back at that situation, I don't think that's the case at all. I think we're now in a world where holy crap, people started using this stuff and said my token costs are going through the roof right now. I need to find alternatives.
And then the Chinese open weight models, which used to be nine months behind or six months behind, are now like three months behind, and they're offering solutions that used to be one tenth the cost. Let's just say now they're a third of the cost, and all of a sudden, that a lot of larger enterprises are saying, man, how do I get model routing? How do I put my own stuff on my own infrastructure? So, I think it's a really, really exciting time for founders and also for enterprises.
Michael Krigsman: Folks, you can ask your questions. If you're watching on LinkedIn, pop your question into the LinkedIn chat. If you're watching on Twitter/X, use the hashtag CXOTalk and be sure to me directly, @MKrigsman. Ed, you see hundreds of AI startup pitches a year. What patterns do you see among these startups right now?
Many models and where startups win
Ed Sim: Right now is the ultimate time of value creation. And I think we're still just in the early innings of this kind of AI wave right now. And starting a company has never been easier, but I think building a durable company has never been harder. So right now there's tons and tons still of just normal of lookalike agents and copilots and thin application layers.
But we look for, I think there's a new wave of infrastructure being built right now, and a new wave of security companies that are being built that go much, much deeper kind of into the tech stack. And, you know, typically these founders have an opinionated view of where the future's going to be. So for example, it could be a founder coming in and saying, hey, what happens when the world has long-running agents that not only run for a minute or an hour, but for days or weeks or months?
How do you set up that infrastructure? Yeah. How do you secure that infrastructure? And so those are the types of founders that are coming in because as an inception investor where we invest at the idea stage, if something is already a problem, it's probably too late. We need to see the problems of tomorrow.
We need to see founders that are very opinionated about what the world's going to look like 12 to 18 months from now, which almost feels like three years from now, and build off of that foundation so that when something happens, we're ready for it.
Michael Krigsman: So what does that pipeline tell you about where enterprise AI will be in the next two or three years? Because it sounds like the problems your startups, or the ones you see, are trying to address will eventually show up in a couple of years inside the enterprise.
Ed Sim: I think one interesting aspect's going to be we're not going to live in a world of one or two or three models. There's going to be dozens of models, or even more than dozens of models kind of living inside of an enterprise right now. And that goes back to one is that people do not want to give up control to the frontier labs themselves. Two, there's a cost issue. And, you know, think about it this way.
I don't need a PhD student in every single category if all I want is the best workflow built around payments or the best workflow built around my customer data. I think that's part one. I think the second thing is the big question people talk about is, do I rent intelligence or do I own intelligence? And which means, do I actually just use an API? And work with the OpenAIs and the Claudes and ask it questions and have it get smarter based on my data?
Or do I actually take an open source model, which I can use through a platform that could be hosted here in the United States so that it's safe? Or do I actually deploy it on my own clusters? And I'll give you a great example. One of our portfolio companies, Spectro Cloud, just released yesterday with AMD and Supermicro a box, literally a box. It's almost like it's an appliance the way that appliances used to be sold pre-cloud. And it has eight GPUs on it.
It has all the CPUs on it and literally, and our software on it. So in that software is a model router that you can route between the Frontier Labs. We assume that 10% of queries encoding would go to that, and the other 90% will be routed towards whatever open-source model or model you choose to bring on that infrastructure that you want. And the whole point that I want to tell you is that the payback is off the charts. It's like 70% ROI.
Michael Krigsman: Wow.
Ed Sim: per year. You can put it in your house, you can put it in your basement, you can put it in your bedroom if you want. But I think that people are looking to take more control back over everything. And I think that's going to be an interesting kind of dichotomy moving forward.
Michael Krigsman: So there's a combination of control, and then you spoke about the token costs earlier. So you have both of those vectors right at the moment.
Ed Sim: Absolutely. And right now, the early wave was the easy button. Everyone wanted that. Remember that Staples easy button? The easy button is, you know, when the board and CEO is saying, let's use AI and get something out of it, it was just use the Frontier Labs. But I think right now the easy button is if I can put that all in a box and get it up and running in 10 minutes, that's pretty easy.
I mean, it's going to get easier and easier and easier, and there are going to be more and more choices. And I think right now this is the best time ever for founders because, you know, on the one hand, I'm not going to invest in a new coding startup that's going to get run over by what's already existing today. But on the other hand, because of all these choices around models and all these opportunities and the enterprise is kind of looking at new things, it's a great time.
Michael Krigsman: It's also easier than ever before to build software, and there are so many software companies now that are more than wrappers around the models but really are going to be doomed to failure because, as the models expand their footprint, they'll incorporate features that these companies have. So, although it's easier on the one hand, is it also at the same time more difficult because you need to have, you still need the great idea?
Ed Sim: I'll give you an example. I think of the world as concentric circles. This is a core concentric circle, the bullseye where OpenAI and Anthropic sit, which is building the best freaking model possible. Concentric circle number two might be, if you look at Anthropic, for example, they have built in some legal workflows, they've built in some finance workflows, they've built in design workflows to try to go after Figma. And, you know, the question I think there is, how deep are they going to go? Because right now they're serving everyone.
And if you have kind of legal companies like a Harvey, for example, I'm not in Harvey or Legora, but they're going very deep into not just answering questions from a legal perspective, but also very deep into the workflow.
And, you know, the question I think you really have to ask yourself is, if you decide to build at that layer, we'll say the user layer, I don't want to call it an app layer or agent layer, but the user workflow layer, the question you have to ask is, do you have a data advantage? Is there a compounding workflow where every time someone makes a query, are you learning more and more and more from it? And then what is that feeding into?
And what that is feeding into right now, the playbook is build your own model. Post-train your own model. So Cursor could be a great example. People were like, hey, Cursor is going to be left for dead because, you know, they're competing with everyone kind of in the coding space. But what they did was take that flywheel, the users were just generating so much data, and they post-trained their own model initially using a Chinese open weight model, then they built their own.
And that is the playbook that a lot of the smarter companies are doing, is taking this compounding data flywheel effect, post-training models now, which didn't exist six months ago. People were not doing that. But now they found that, holy cow, if I can get a smaller model post-trained in a very specific area, then I could get some really, really amazing frontier-like performance at a much cheaper cost. So that's part one.
Part two is I'm not really that worried on the deeper, deeper infrastructure side because the whole idea of vibe coding these things, that doesn't exist right now. No one's going to go, for example, into hardcore agent authentication, authorization infrastructure and trust a vibe coded application to go do that. So that's part two. And then part three is something we should talk about is the last mile of the enterprise. That is, the longest mile that ever exists.
This is talking about security issues, who owns context, who does the evaluations and who owns the evaluations. When an AI agent performs a task, where does that go? So there's a lot of other things that go into this that ultimately comes down to who the founders are, because we haven't talked about, you just got to invest in amazing people that are high sloping, you can build trust around.
Who owns access, context, and evaluations
Michael Krigsman: So we have a question on LinkedIn from Swami Vaidyanathan, who says, from your inception stage vantage point, what is the attack surface in agentic AI that most enterprise security teams are not thinking about yet?
Ed Sim: It's kind of funny. I was talking to a bank at RSA, and they said they interviewed 90 different agentic security companies. And there are a lot of different companies in the stack. And I'll mention one of my portfolio companies called Keycard.ai. That's a company that we funded with our friends at Andreessen and Acrew Capital and some others. And I think the biggest problem is understanding that agents, people think that agents should get access either through my authorization. So if I'm logged onto Salesforce, should my agent get forever access to Salesforce?
And then also, if my agent is actually doing work and maybe has its own identity, should that identity also have the same access to Salesforce, which means it's an always-on identity? And I think the biggest problem that people have is that they just don't understand that agents do work differently than humans. You know, you don't sign up for Salesforce and just have that credential working all the time. Agents, I think, should be granted access at runtime.
It should be granted access dynamically, and it should be granted access that kind of dies out very quickly when the task is over. And why that is important is because when you have a world where thousands of agents are running around an enterprise, if something gets hacked, the blast radius is contained to that kind of one little unit of very specific authorization versus going through me or going through an agent that has forever access. So I think that is very hard to build, very hard to deliver at runtime.
And I think that's probably one of the biggest holes that's missing. And by the way, when we started talking about that a year ago, no one really understood what we were talking about. But, over the last three months, it's been incredible how people were like, oh, man, that really makes a lot of sense.
Michael Krigsman: Let's go to another question. This is from Shawn Reynolds, who is a very seasoned enterprise exec who I've known for years and years since he was at SAP a long time ago. Shawn says, would like your perspective on the importance of decision intelligence. Automation of decision-making in enterprise use of decision intelligence is growing at a rapid pace. These platforms are likely to become agent platforms. Your point of view?
Ed Sim: Decision intelligence also ties into who owns the context. And then basically, when you have context, when you ask a query and an agent does work, then you have to do an evaluation. Did the agent do good work or did the agent do bad work? And then after that, a decision is made, right, based on that, on what is performed. And I think over time that becomes the DNA of the business. It's kind of like what Satya said before.
Satya talked about that the evals are the most important part of the business. So for example, if Michael, you have a certain way of doing things in your workflow, and maybe there's three other people that have the same kind of podcast platform and there's other ways of them doing the workflow. And the question I then have is, how you do those things and how an agent gets evaluated on the performance of those is a benchmark for you.
Should it be a benchmark benchmarked against all podcasters that are building things or benchmarked against you and benchmarked against me and someone else? So I think that is where the decision intelligence comes in and where it's important for these companies to start owning kind of their own, you know, from my perspective, own decisions and also their own evaluations. That is where the valuable data kind of really comes in. And that's what Microsoft is trying to offer to people.
And whether you believe that they're going to do it or not, there's also going to be tons of opportunities for startups to do it faster and better.
Michael Krigsman: What are startups doing to help large organizations introduce more complete context into their workflows and environments so that AI functions more effectively?
Ed Sim: I'll give you some examples. Well, first and foremost, I get pitches every day, many pitches every day talking about someone wanting to own the context layer and someone wanting to own kind of the governance layer for enterprise. And by the way, that's a non-starter to go and say you're going to own that whole thing because you have lots of large companies like ServiceNow and Salesforce and even like Atlassian trying to own that layer. So that's one.
So I think if you're going to do context, it has to be very specific context. And I'll give you two examples. I have a company called X5 Labs out of Israel. And what they do, and this will sound familiar, is they understand your context by deploying software onto your machine. And they watch how you work, and they record all the video, and they turn that into data. And if you deploy that, let's just say into the payments team, you can see what workflows are.
And we can say, hey, look, you've got 50 workflows that are being run throughout your team. Would you like me to automate some of those? And so once you actually automate some of those, let's say you pick three of them, we will create agents for them, and you decide where you want humans in the loop. And once you do that, what happens is we constantly look at the agents working over time and you learn more and more and you can fine-tune that workflow, not fine-tune the model, fine-tune that workflow.
And what we're going to do over time is we drop a model for you. We call it a large, an LWM, a large work model. We drop it on-prem or in the cloud and it is only for your finance department or only for your company. And all that intelligence, it gets kind of built into your system and is something you own. So that'll be one. So that'll be a very focused kind of perspective. Let's talk about security.
If you talk about security right now and you talk to Anthropic or OpenAI, they'll tell you, look, we can find all the vulnerabilities that are out there better than anyone else. And in fact, what we can also do is do attack path reasoning. We can actually take these small, small vulnerabilities, daisy chain them together, and turn that into a real attack path. And sure, we can share that for you. And we can also share with you how to patch those. What we don't have is the context.
We don't have the context of your IT systems. What happens if I make this patch? What is the upstream? What's the downstream impact of all the software that is sitting in my organization? Do you think a large bank is going to want to hand all that over to those people? Nope, they're not going to want to do that.
So a company like Snyk, for example, has all of that information because we've been selling our product for years and we have all that security context organized so that when you do find these vulnerabilities, you can patch them on a more deterministic basis because we understand how the systems operate and how all the systems and dependencies kind of function together. So those would be two examples.
It's the people, not the architecture
Michael Krigsman: Delighted that you said that it's a non-starter when companies come to you, startups come to you, and they say they want to own the context layer or governance layer, because those two terms have become a kind of sinkhole of hype where if you, don't have a clear understanding of a particular problem, say, oh, well, we need more context. Or, if AI is not delivering its ROI, we need better governance and better control. So, I find that to be a refreshing point of view. So, thank you for that.
So, Arsalan Khan on Twitter/X says, what are the biggest architectural business process red flags that VCs see today, that signal an enterprise AI startup won't survive the coming market consolidation?
Ed Sim: There are so many of them. I do have to tell you, it's not the architecture first and foremost. It's always about the people. I like to evaluate people and we only back technical founders. And I want to know that based on your experience and your history of doing things, kind of, you know, what is that unique insight that you're providing that is going to change the world.
And how do you kind of give me an opinionated view of the future, not today, but maybe two years from now, so that we can build towards that future. And I think one of those is this, is I want to always understand if you're looking at the architecture perspective, have you built a system? And I say system that gets smarter with every new model release versus gets killed or worries me about that. Do you have a system that allows you to swap models? How do you think about that?
And so then thirdly, do you have some type of, if you're an AI or an infrastructure, and if particularly if you're at the workflow layer, how do you keep learning? How does your system get smarter and smarter over time that perhaps gives you a proprietary edge? And those are the things I think about. And when you look at infrastructure, it's a completely different kind of build in and of itself.
It's basically trying to understand, you know, for example, in security, for example, how are we going to solve a world where hackers have the advantage where they're always kind of on the 24/7 offensive where they do attack path reasoning? And I think the answer there would be, I want to see a world where you have autonomous defense.
And I know that's an aspirational goal, but the sooner that you can build trust and have a system that is really, really intelligent, that's probably deterministic and stochastic, and the sooner you get there, the more, the safer that everyone will feel. And I think that's the aspiration. So those would be some examples around kind of if you look at the architecture, but it's always the people first. I just want to really highlight that.
Measure the outcome, then cut the cost
Michael Krigsman: Let's grab another question, and this is from Rajaganesh S., who says, the way companies are using AI definitely makes employees productive, but how do you see that translating to organizational productivity? Do you see something fundamentally missing in the problems AI products are solving, or is it just evolution?
Ed Sim: Honestly, I think it's just way too early to tell right now, frankly. And I think part of productivity would be a couple things to look at. Because I look at it as cost per outcome. And cost per outcome is basically, here's a human, they have a task they want to do, and this is how much would that task cost for the human. Then you have, here's a task, and how much does that task cost for the AI?
And then you have, a third one, which is a human-assisted with AI kind of outcome on that task. And part of that also, if you look at that curve, it has to be accurate and it has to have kind of ROI around that. And my answer to you basically is really that people are just getting started right now. We're in that wave where people are trying to figure out what ROI is because we were in the early part of the curve, which was just get me something.
And now I think people are much more intelligent about what outcomes will look like. And I think that is the world that we're going to strive for in the next 12 months is perhaps cost per outcome or cost per task. You've got companies like Sierra, I mean, in customer support that are trying to, you know, charge from that perspective, or Intercom from Finn, or one of our portfolio companies, Kustomer, was going to charge per outcome because those are really discrete and measurable tasks.
And I think the more of those that we have, I think the better off we'll be. And, it'll be easier to understand ROI.
Michael Krigsman: So, your view, then, is the future of AI, and I'm assuming especially agents, is pricing on the basis of specific outcomes. And therefore, the hard question, or one of the hard questions, becomes how do you define what is a specific unit of outcome that you can, therefore, link back to what the software is doing so that you can charge for it.
Ed Sim: Right now, the easy button is coding, and then there's customer support. But then the question is, what is it for everything else? And every organization will have their own. And this goes back to my other point, is once you have a, let's just call it even not a task, a workflow, the evals become very important. Because what an eval does, it tells you. Did the agent solve this correctly? And did it do really well, or where can it improve?
And then you've got to take that learning and feed it back into the systems so it gets smarter and smarter over time. So it's not only just a task. When you take multiple tasks and tie them together, it becomes a workflow. And I think that's where we're trying to strive, but the data's imprecise right now. People aren't getting there, but that is where we're going. I have no doubt.
Michael Krigsman: When you say the data is imprecise, which data are you talking about specifically?
Ed Sim: I'm talking about that first and foremost right now, a lot of enterprises don't even know where to get started from an agent perspective outside of the, let's start with coding and maybe let's start with support. So part one is that's the reason why all these forward-deployed engineering organizations exist. This is why OpenAI and Anthropic have their own FDE kind of organization to go solve this problem. That's why Accenture was tearing it up for a while because enterprises needed help. So that's part one is what workflow should I actually start with?
And then what would be the definition of success for those? So once you do that, that's part one. Part two would be then what is the evaluation framework in which I can do that, in which I say that this is a good outcome or a bad outcome, and then how do I keep learning from it? And right now people just don't know how to measure it and the data isn't great right now. That's why they need help.
And right now it's bodies being thrown at it until you've got really good software.
Michael Krigsman: Yeah.
Ed Sim: That makes it more precise.
Michael Krigsman: So then, fundamentally, the question is, where are the use cases, or which use cases will map in a straightforward way to the application of agents in such a way that you can define measurable outcomes? So, use cases, therefore, become a critical path item.
Ed Sim: And the smartest organizations start with the easiest ones. The low-hanging fruit in which they can actually automate them and then actually measure those. And once you get successes from there and wins from there, if I were an IT person, I would start with the small and the easiest and then expand from there. Once you buy, get buy-in from everyone else and show that this really, really does work. I'll give you a great example. X5 Labs is working with an insurance company doing claims processing.
And I told you that has software that sits on people's desktop, watches it, watches how you do work. And we've discovered a 57-step process in claims processing for an insurance company. And we said, okay, let's run humans versus AI for a week. And we came back and said, okay, we have a problem here. You know, I think our answers are different from the human answers. And the company was, you know, upset that said, I don't think this AI works. The good news is we recorded all the video around that too.
So we went back step by step and they said, oh, actually the human error was actually worse. You're actually right. And it turns out that the AI was right, you know, 98% of the time and the humans were only right 85% of the time. So that'll be an example of why you need some software that can constantly measure this and actually even save kind of what happened during a process. You go back and look at it.
Michael Krigsman: By the way, you also gave us the secret, I think, to running successful AI pilots that will then translate into actual use cases, ongoing use cases, which are, number one, start from an easy use case that you can also measure and convert into a set of productivity, defined productivity outcomes, or ROI is another way of saying it, because if you can do that, then you're well on your way to having AI success and passing through that horrible pilot purgatory and pilot death area.
Ed Sim: Absolutely. And the easy button, once again, for most was just using the Frontier Lab APIs and kind of making it work, and that's fine. And then over time, what you'll find is that, hmm, maybe I can start optimizing around the edges. Maybe I only need the smartest PhD brain for 10% of that workflow, and the other 80 or 90% is pretty straightforward. And I can maybe use some open source, maybe I can use GLM 5.2 or Kimi or Qwen or DeepSeek or one of those to do the rest.
And that's how people will optimize things, but they're not going to build it themselves, Michael. There's just not enough talent there. So they're going to borrow that too. They're going to find people that actually have the infra where you can have another API perhaps to do that, or maybe take the box I mentioned earlier that you and I talked about much earlier where,
Michael Krigsman: Yeah.
Ed Sim: One of my companies, Spectro Cloud, partnered with AMD and Supermicro, and I call it back to the future because once upon a time before the cloud, we had these appliances. You could drop a box, you can drop one in your basement, in your bedroom if you so choose, where you can get eight GPUs, you can get Spectro Cloud software where there's a front-end router on it that routes to your frontier lab of choice. And then I call it BYOM, Bring your own model.
You can bring any model you want onto that. And the ROI is basically we can actually have 50 developers on one kind of box. You can have 30 concurrent users and you're getting 70% savings per year versus using kind of frontier-level costs. And so that just got announced yesterday. But this is the world where I see it. And that's an easy button now. There used to never be an easy button to kind of have one of these, but now you can have one.
And I think that is kind of the infrastructure that's going to be built in the next two years, and it'll be just as easy to use those things as it will be to do Claude or OpenAI.
Buying talent and changing culture
Michael Krigsman: Here's a question from John AK Akinmade who says, we're hearing a lot about AI due diligence before acquisitions. Do you think enterprise buyers will eventually expect the same level of independent qualification before deploying AI internally? Not just when buying companies.
Ed Sim: When companies are bought, I'm just going to start with the basics. People are mostly buying people. Talent. And in this day and age, as I mentioned, there's tons and tons of AI companies. In fact, every category that exists today probably has 30 or 40 companies kind of trying to do something. And when companies get bought, they're buying talent.
They want to make sure that the talent there is like next-gen AI that they're building for the future, that everything internally perhaps might be coded in loops where the agents are just doing work and, you know, 80% or 90% of the pull requests are happening through agents. Because a lot of these larger companies that are making these purchases want to actually buy the future. And I can tell you that their diligence is centered around that. Hey, how are you guys building stuff? How are you guys coding stuff?
How are you guys shipping stuff? In addition to what the product is. What is the product that you're building? Is it something that allows me to get to the market six or nine months or 12 months faster?
Michael Krigsman: Yeah.
Ed Sim: with your team and that product than without. And so, you know, from that perspective, the AI due diligence is not just, it's not the architecture, it's not all that stuff. It's about who are the people and how are they going to help me bring in all this intelligence into my organization and bring in a faster-moving culture to do things better, faster.
Michael Krigsman: I think the consulting companies are really trying to work on this, and especially the cultural aspect? How do we change the culture of the organization to embrace, as you said earlier, for many companies, they're trying to figure out the basics and the really strong ones are leaping far ahead, but they need outside help, whether it's from consulting or from software.
Ed Sim: Look, as much as I do the inception stuff, I've been doing this for 30 years, investing in technical founders from the very beginning. And look, I have a bunch of companies that have 500, 800, 1,000, 2,000 employees. And some of them actually had raised capital at the height of the ZIRP era, which is the zero interest rate policy era where, you know, a lot of valuations were extremely high.
And that was kind of the go-go SaaS era where people were just hiring and hiring and hiring, and a lot of them had to get fit. And so let's just say now that you're fit, what is every company doing? In every board deck starting about a year ago, it was how fast are we bringing AI internally into the infrastructure. How are we doing that starting with coding first? And how do you measure that? And initially it was kind of lines of code. How many lines of code are being written?
I mean, that's not the most efficient way to do things, but the point is just, you know, kind of where do you start? And then it was customer support. And then how are people in sales and marketing doing it? How do you empower these people? So that cultural aspect is something that's very, very important.
I like to say that some of our best companies had internal hackathons where they have a skills management platform where people have skill of the week and they'll demo it and show it to others to just empower them to say, hey, now that you have, you know, AI here, why don't you actually do your own skill? Why don't you automate your own thing? I mean, Michael, you and I were talking about today, you have a whole bunch of things that you built on your own and you're not a coder.
And I think you've got to create that curiosity. You've got to share the curiosity and share what success looks like, even if it's small. And it's a day-by-day thing. And then it gets much harder when you have 100,000 employees.
Michael Krigsman: But there is no substitute, as you say, for actually trying it. And finding those low-hanging fruit use cases with specific, definable, beneficial outcomes will only happen if people understand the process. Because it's people inside the organization that understand their particular process the best. If they're not involved using AI, then they're not going to solve these problems, okay? The problem of where can we apply AI agents to do a better job.
Ed Sim: Yeah, and they have to feel empowered versus feeling scared that it's going to replace them.
Michael Krigsman: We recently had a guest who said that he thought AI is really whole-company transformation. That's essentially what we're just talking about now because we're talking about people who are actually doing the work. You just brought in, they need to be empowered, which is a senior leadership job.
Ed Sim: I call it the sandwich model. Sure, the CEO has to talk about it, but it also has to start from the bottom up. You've got to have these small wins, and the small wins compound. It has to be shared with everyone else. That's what the best orgs do.
Systems of record versus headless agents
Michael Krigsman: Let's jump to some more questions. This is from Nick Qureshi, who says, how do you see the SaaS model being disrupted by agentic workflow companies taking over in various industries?
Ed Sim: I kind of think SaaS. There's different kinds of SaaS companies. There is application area companies from the, like Salesforce, for example, or like a HubSpot, or a ServiceNow. And then there's infrastructure companies, which some could call SaaS. Because it's subscription revenue, like a Datadog or a Snowflake or a Databricks. And I think what we're really talking about is the first area. The application layer companies. Look, at the end of the day, I think, will we have an interface two or three years from now?
I mean, look, have you gone inside of like ServiceNow or Salesforce? That software is kind of clunky and ugly to use. Sorry to say. And I think the real battle is going to be around headless systems. And either I'm going to have agents kind of interacting and pulling the data that I need and writing the data into some of these systems of record, or you're going to go to the systems of record themselves, like Salesforce is trying to build Agentforce, or ServiceNow has their Control Tower platform.
And so there's this battle between the systems of record having their own kind of platforms in which they want you to build, and then others wanting to have their own horizontal layer of agents, you know, pulling out and writing data in a headless fashion. And by the way, the interesting thing is there are some companies like SAP, I think, that if you're not approved, you're going to have to pay. You're going to have to pay to get access for that.
In fact, Salesforce actually changed their business model as well about six months ago where they're saying, hey, have at it, agents, have at my platform. You're just going to have to pay per access. And I think that's going to be, we're just getting started right now in that area. And I think that's going to be another interesting curve where eventually is, you know, do these systems of record continue to exist 10 years from now or not?
Or do you have agents that go out there and do the read-write and maybe write a different database on the backend? And then over time, you know, you have your own system of record. I don't know. That's going to be a very interesting area. But I can tell you this is that investors, you know, when you're looking at new inception companies, no one's coming into us saying, I'm going to start one of these businesses.
Michael Krigsman: Yeah.
Ed Sim: That's for sure, unless they want to just destroy it completely from scratch and reimagine and reinvent it from an agent-first perspective.
Michael Krigsman: It is funny to think about a company like Salesforce as being a legacy software provider, which we have a sea change in both the technology and the expectations that people have of how they interact with systems. And Salesforce comes from an older day.
Ed Sim: I don't think anyone's going to rip it out because I don't think people understand kind of that layer between the user and Salesforce. There's so much customization built into it, so many rules built into it.
Not to say that AI can't write some of that up or people can eat around at the wedges, but I do think that the pressure that they're going to get is that every time there's a new renewal, people are going to say, hey, I can take these, you know, one, two, or three different systems together or agents doing work, and it's going to put pressure on their platform unless they can find this new revenue curve from agents accessing it versus humans.
Venture money pivots to robotics and chips
Michael Krigsman: This is from Chris Petersen on LinkedIn who says, some industry pundits seem to think that GenAI has taken so much VC money out of the system that there's not much left for the next round of startups. Is that a misperception?
Ed Sim: I don't think it's a misperception. I just think that basically AI is the future, and I think we're probably still in the first inning. I mean, this is the Industrial Revolution kind of all over again. And the amount of money you're talking about is, first, do you believe that the amount of compute, you know, the trillion dollars that are being spent on data centers right now, would that be used or not used? I think the answer's pretty clear right now that token consumption is just going through the roof.
And whether it is happening through the Frontier Labs or through models from China or open weight models from anywhere else, the winners are going to be kind of NVIDIA memory makers. And the data centers will actually continue to proliferate until people say AI doesn't work, which I don't see that happening. Second thing is that GenAI, I mean, if you look at where the dollars are going right now, it's infiltrating everything. Like it's going into robotics.
We're invested in a company called Generalist AI, which is probably one of the leading robotic foundational models out there. It's two guys from Google DeepMind and someone from Boston Dynamics and raised from, you know, NVIDIA and some of the best. But there has been a resurgence in robotics right now. So all of a sudden, a lot of the money's moving from software. And by the way, here's the interesting thing. There are a lot of VCs out there saying software's dead. And of course there's nuances in all that.
But the point is that they've hard pivoted towards hardware. They wanted to go towards moats that they could see, feel, and touch. Where do you go? Robotics. Robotics, you know, seems to be kind of the next frontier. And I think that could be a very massive market if you look at labor. If you look at kind of the amount of work happening in warehouses or where people kind of on the manufacturing lines, and there's been a massive resurgence in robotics. What else are people investing?
They're investing in space, they're investing in defense. We've been also investing in bio AI. We've got two bio AI companies that we've invested in. So I don't know, I would say that it's just AI is just everywhere. So it's not just gen AI, it actually touches every industry. So I think it's actually a wonderful time. It's not taking away, it's adding. It's getting people excited and creating kind of old industries and getting people really fired up about kind of reimagining them.
Michael Krigsman: Very interesting! I'll just mention for folks, all the topics that Ed just discussed, whether it's physical AI or bio-AI or space, we've had discussions with major experts here on CXOTalk. So, if you want more, go to CXOTalk.com, subscribe to our newsletter, and do a search. We have lots of information about,
Ed Sim: I would expect nothing less from you, Michael, to have the world's best. But that's the future right now, is kind of looking at all that hardware actually is easier than it ever has been before. Chips. We've also been investing in some chips as well. We invested in a company called Netpreme, which is trying to solve the GPU kind of memory wall problem. There's only so much memory that can go in every GPU.
And imagine a world where you can take an existing interconnect that GPUs connect to one another and have a separate rack of memory, as much memory as you want. And by the way, that's very important because context windows are just getting bigger and bigger as agents are doing more and more work, or agents actually do long-running work for 36 hours or 30 days. You're going to need more and more memory. And that's the only way that you can scale kind of inference in a cost-productive way.
Open weights and owning your intelligence
Michael Krigsman: So this is from Lisbeth Shaw. Can you talk about the distinction between open source and open weight models?
Ed Sim: Open source is a business model itself. And that is basically like, okay, I can use this software for free, but I can't do these things. Maybe I can't sell it commercially, or if I sell it commercially, I've got to charge a certain amount. So I'll give you a good example. Kimi, people think that everything in China that's open source is free, but if you actually generate $20 million a year of revenue from using Kimi and you're hosting it, you have to pay for it.
So if you look at kind of some of the people that are hosting Kimi models out there, I think the Basetens and the Firecrackers and some of those, they're charging, lo and behold, the same price for Kimi. I think it's like 30% of frontier cost as Kimi is charging itself on an API perspective. So that's kind of open source. It's the business model. Who owns the license? Who owns the software? And when do you have to pay someone?
Open weight means I can actually download the model and change the weights in terms of how decisions are being made. And that is kind of the bigger deal. Because if you can kind of take these weights and understand how decisions are being made and change the weightings around what's important, and then constantly start running queries through it and getting evals, you can really, really fine-tune that model for your own use cases. And actually, that is kind of what you really want. I mean, that's what people really want.
That's the holy grail in terms of having your own intelligence, having it fully controlled by you. And by the way, most of these Chinese models are also open weight. So, I think they have both. So, I think that's kind of the difference between the two.
Michael Krigsman: How close are enterprises to being able to use open source and open weight models effectively? And I'll just mention a few, recently, we had the CTO of Mozilla talking about open source as a guest on CXOTalk, really diving into this, but how close are the enterprise folks to using these tools effectively in this way?
Ed Sim: You can go to OpenRouter now, you can go to Baseten, Firecracker, you could just grab an API and start using them today. There are a lot of kind of companies that are tinkering around and downloading open weight models and kind of, you know, running it on their own machines or running it in their own clouds or virtual environments. And of course, I got to tell you this, most of our startups right now that are building, this is the most important part, most of our startups are using open weight models.
They're using some combination of OpenAI and Claude, but also a big portion of what they do is open weight models kind of architected into their system. The big question though that I think we need to think about is what open weight models will be allowed to be delivered into enterprises, at what point in time, because you have that US-China tension right now. And I do know that, for example, there are lots of large financial organizations that are not allowed to bring in Chinese models.
So if you're a software vendor and you have a Chinese model under the hood, perhaps make sure that you have other available alternatives underneath that. I don't know, maybe it's a Mistral, maybe it's a Gemma, maybe it's a Nemotron. By the way, all those US open weight models aren't that good right now.
Michael Krigsman: Yeah.
Ed Sim: So, there's a big difference between frontier China and then kind of what's happening in the US. So, there's got to be more investment around that so we can do that. But I do know that enterprises, yes, they're using them now, but you have to be careful of the ones that have regulatory issues or the government, for example, they're not going to be using Chinese models. So, you have to have a flexible architecture around that.
Michael Krigsman: Shawn Reynolds says he's talking about decision-making. And, humans use data insight to make a decision. Agents will become autonomous, empowered to make a decision. This return on decision-making is rising and is important, and there are new use cases. Can you talk about this whole issue of agents and decision-making?
Ed Sim: How agents make decisions is going to be important. And then how you actually take those decisions being made and retrain the agents and put that back in the workflow is where the intelligence comes from. I think that's the bottom line. And it's something that enterprises are starting to understand. It's something that they should own versus giving away to the frontier labs. That's my simple, simple answer around that.
Autonomous attacks need autonomous defense
Michael Krigsman: Tell us about Black Hat.
Ed Sim: There's a video that everyone should watch called Black Hat USA 2026, the breaking news, the OpenAI Hugging Face incident. And I got to tell you, so that just came out, that was from Black Hat. And, you know, when you actually have agents do work and you give it a reward system, i.e., pass this test, the agents will do anything possible to pass the test. Especially if you don't give it any parameters.
And in this case, the agent decided, I'm not going to pass this test, but let me figure out how I can get to the internet to actually get more help. And you know what's wild is that what came out was that these agents created a shadow message board and left notes for each other weeks in advance of kind of escaping the sandbox and kind of after escaping the sandbox to figure out how it could hack the system and pass the test. So that's my point.
These agents will stop at nothing if they're given a task to complete and they'll do anything possible. And so you're reading about, you know, this Hugging Face incident, but also Kimi just announced today that some agents escaped the sandbox as well. And what I'm trying to say is that there are a lot of security founders out there that are building businesses and they talk to CISOs.
I talk to 30 CISOs, I talk to 50 CISOs, and I think this is something you and I probably talked about years ago, is that if I only build for what's happening today or what CISOs want today, then I'm missing out on something.
And I think what I'm really trying to say is that how will the world look when you have autonomous swarms of agents that are going to do anything possible to chain multiple vulnerabilities together that may not seem like a big deal, but when you exploit all of them and create an attack path around it and they can penetrate your systems 24/7, that's a really, really scary world that we're going to live in.
And I can tell you this, that no humans can keep up with that amount of attack infrastructure right now. And it's very similar to the web days. In the web days, the hyperscale internet companies were the ones that actually experienced growth like never seen before, and they built their own systems. They built infrastructure. Confluent or Kafka came out of there. Temporal came out of there as well. And I think that's the same thing right now. It's the OpenAIs, it's the Hugging Faces, it's the Kimis.
They're the ones that are eating crazy security incidents right now, 'cause they're on the frontier. And if I were a security founder, I'd figure out what the hell they're doing and how they're doing it and what they're building, and then reverse engineer that work backwards so you can bring it to everyone else. So that'll be my one perspective around Black Hat and why I honestly think this is just the beginning. This is the tip of the iceberg in terms of what's happening on the security side right now.
It's a scary world out there.
Michael Krigsman: The startups that you're seeing, how good are they in terms of being able to address this kind of thing. I mean, how in the world do you stop a frontier model from, on its own, independently identifying a zero-day defect in some product out there or some set of libraries, and then taking advantage of it? How do you stop that?
Ed Sim: It's hard to stop. Offense has advantage. Defense has to catch up. We need to move to a world where you have autonomous defense. And of course, autonomous defense means you need context, Michael, in order to actually find the problem and solve the problem. And right now you have humans kind of all in the loop constantly doing things. There's not enough trust built into the AI systems. And so for now, the attackers have the advantage. And the faster that people can get to autonomy, the better off we are.
So if you look at the labs, they're moving towards a world of autonomy faster because they know that's the only way they can solve the problem. And what they're doing is the tip of the iceberg. What everyone else is doing is, you know, maybe they're taking their time and just trying to test things, but we don't have the time right now. And that's kind of what's happening. And people are doing a lot of other things. I'll say that offense is the new defense.
People are getting systems where they're just constantly attacking their own systems and trying to find the problem themselves using models before or the hackers come and get them. I mean, there's so many ways that people are going after it, but you need hardcore autonomous kind of defense if you want to keep up with this.
Michael Krigsman: Given all of this right now, what does this mean for CISOs today in the enterprise?
Ed Sim: The most sophisticated, there are a bucket of CISOs who are super sophisticated from some of the leading banks that are working very closely with some of these large frontier labs right now to figure out what they're seeing, and how they can protect themselves. The biggest problem around that is that, you know, a lot of these models are handicapped, Michael. If you think about Mythos or Fable, people are getting access to it through a trusted mechanism, but some of that still is handicapped.
They're still not getting the full access that a hacker could if they actually reverse engineered some of the models and got their own access. Second thing is it's, the frontier is too expensive. I've heard so many people complain about, every time new code is being spit out and generated, you can't pay fable-like prices. Think about the codebase, the amount of money it costs people.
So there's got to be other solutions, for example, where you can maybe use some open weight models that are post-trained on your system that provides frontier-like performance, maybe at 1/10 the cost or 1/3 the cost, 'cause otherwise you're not going to be able to constantly scan the system. So there are going to be so many different architectural decisions that are being made, but ultimately the goal has to be, how do I just make sure that continuous, autonomous, trusted defense as these attackers are hitting my systems?
And that gap of how long it takes is going to be how protected and secure you feel.
Michael Krigsman: It's a huge market for security, and that market is,
Ed Sim: It's a golden age. I say if this is not the golden age for cybersecurity, then I don't know what is.
Michael Krigsman: And of course, you have established players like Palo Alto Networks who are intensely focused on this set of problems as well.
Ed Sim: Yeah, everyone is. So, Palo Alto just bought one of my companies, Protect AI, for over $700 million last year, and that was three years after founding. So they were providing full-on AI security. It was before agents even took off. We're doing the whole AI security kind of one platform from that perspective. And now we've already moved on. There's so much more going on right now with agents like Keycard or models or even human engineering.
Did you see that two days ago that people, hackers actually created a campaign against all the big banks and hedge funds where they replicated people's voices and were calling the call centers? That's just classic social engineering, but at scale. I have a company called Humanix with an X.ai that actually solves that problem. So there are so many things coming down the pike that are automated at scale and you're going to need AI to answer that.
Judging vendors and earning enterprise trust
Michael Krigsman: There are so many lookalike AI startups. How can enterprise buyers judge which AI vendors will survive an industry shakeout? And, Arsalan Khan referenced the industry shakeout earlier. Very quickly, please.
Ed Sim: It's about the people. You've got to invest in amazing, you, as an enterprise, have invested in amazing people that have a background that, you know, has a pattern of success. And then two, I like to say is that you buy the product, but you also buy the vision. So is this product solving my problem today? But are they also showing me a future that I'm not ready for that they're building towards as well? And you take those three things together and that's kind of how you choose.
And then you look at the backers. Are they financially secure? Who are the VCs behind them? Are they the top VCs on the planet or people I've never heard of before? And you add those things up. That's the best way you can look at it from a startup perspective.
Michael Krigsman: But when you talk about that, vision, every startup is talking about, you know, they're going to change the world and all of this. But how can a CIO or a CISO see through that?
Ed Sim: Oh, it has to be concrete. Here's a vision. I'm going to build a company like Surf AI, one of my portfolio companies. I'm going to actually tie every asset to an owner. I am going to actually create and offer you agentic processes and suggest them to you. And you can create a human in the loop. But my vision is that eventually, here's my concrete vision, is that eventually it's going to be a full autonomous loop that's going to close the 80% of vulnerabilities you can't ever get to.
And it's only a question of when you decide you trust the system to do that. That's my vision. It's not like I'm selling the future. It's a really concrete vision that it's all up to you, end user, that you choose to decide to turn it on or off.
Michael Krigsman: So specificity is a key point.
Ed Sim: Yes, absolutely. Can't just be a wide vision.
Michael Krigsman: Hey, agents are going to conquer the world and attack path reasoning. What advice do you have to startups on selling AI to the enterprise?
Ed Sim: I wouldn't sell AI. You've got to solve a very, very specific problem and you have to do it uniquely. And you have to show kind of why you are the ones that they're going to trust to kind of work with you. And a couple ways to do that. One is you could be a founder that actually already has worked with hundreds of executives in the past, so you have trusted relationships there. Or you may get an investor like ourselves or some other investor as well that also has those relationships.
So what I screen for is, can I walk this person, this founder into the room? Can they talk the talk from a technical perspective, but can they also talk the talk from a personal perspective with the people that I'm going to bring 'em into the room with in order for them to make a decision or a bet, take a bet on you? 'Cause what they're doing is ultimately investing in you, the same way that we from boldstart are investing in you.
It happens to be with cash and time in a different way, and ours is cash to get a return.
Michael Krigsman: Great advice. Ed Sim is the founder and general partner of boldstart ventures. Ed, thank you so much for being a guest on CXOTalk today. I'm very grateful to you.
Ed Sim: Thank you for having me for round three.
Michael Krigsman: And everybody, thank you for watching! Now, before you go, go to CXOTalk.com and subscribe to our newsletter. We do interactive shows like this all the time, and we will notify you so you can participate. It's a great opportunity to ask the most amazing people in the world pretty much whatever you want. So, take advantage of it. Check it out. And folks, thanks so much, and we'll see you again next time. Have a great day!

