THE DEEP TAKE

Google shipped a circuit breaker for AI agents. Nobody owns the trip.

Google Cloud added project-level spend caps for agent workloads on Tuesday. You set a monthly ceiling in the billing console. Alerts fire at 50%, 80% and 100%. At the ceiling, the agent's API calls pause. An admin resumes them with one click, or switches on pay-as-you-go overages. Google shipped it alongside a new consumption edition of Gemini Enterprise and savings plans at 10% and 20%.

Read what the cap admits. Cloud cost control has always been a provisioning problem. You picked the instance size, the vendor billed the size, and an overrun traced back to a decision a person made. Agents break that chain. The agent decides how many model calls to make, which model to call, how many tools to invoke and how many times to retry. It decides per request, at machine speed, with nobody in the loop. The buyer no longer controls the cost driver. A vendor does not ship a hard ceiling for a workload it expects you to forecast.

Google's own framing is the tell. Hitting the limit pauses the agent's API calls. Google says that protects "your budget without affecting the rest of your production infrastructure." That sentence only reassures if the agent is not production. For a pilot, fair. For the claims-triage agent, the support-deflection agent, the invoice-matching agent, it is false. The cap does not remove the risk. It converts a budget risk into an availability risk. And it moves the failure from month-end, where finance is watching, to whenever the ceiling happens to land.

That is the part with no owner. Finance sets the number, because a spend cap looks like a budget control. The workflow breaks in operations. No runbook on your floor today says "the agent stopped because the project hit its ceiling." The alert goes to a billing admin. The pager stays quiet. Whoever works the incident checks the model provider, the network and the app. The answer sits in a console they have no reason to open.

So do three things before you turn a cap on. First, list every agent running a customer-facing or revenue-bearing workflow, and decide for each whether hitting the ceiling should pause it or page someone. Write the answer down. Second, give the cap an owner in operations rather than finance, and route the 80% alert into the same channel as your other production alerts. Third, ask every AI vendor in your stack what Google just answered: is there a hard cap, and what happens at the ceiling? Most cannot answer yet. That answer belongs in the contract, not in a console.

The wider read is about who is building your control plane. Deloitte surveyed 3,235 leaders across 24 countries and found 21% with a mature governance model for agentic AI, against 74% expecting at least moderate agent use by next year. The gap is being filled by vendors, on their release schedule, in their consoles. Each control arrives useful and unassigned. This is the first one that can take a workflow down.

Powered by the DoGood network

The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.

QUICK HITS

Citrix called it a crash. Researchers made it root.

Citrix patched CVE-2026-8452 on June 30. It described the flaw as a high-severity memory overflow leading to unpredictable behavior and denial of service. On August 14, watchTowr published its analysis and working proof-of-concept code. The same bug yields unauthenticated remote code execution as root. It hits NetScaler ADC and Gateway appliances configured as AAA virtual servers or Gateway VPN servers. Attackers arrived within days, dropping web shells and running discovery commands. One sensor network logged 36 exploitation attempts from 12 addresses over 12 days. CISA added the CVE to its exploited catalog on August 26, with a federal deadline of August 29. Fixed builds are 14.1-72.61, 13.1-63.18 and 13.1-37.272. Patch, then take the wider point. Your patch priority is inherited from the vendor's own severity call, and that call is a claim rather than a fact. Pull the internet-facing appliance advisories you deferred on a low or medium rating this year. Check whether anyone has reclassified them since.

CISA's exploited list is drifting old.

The same CISA update carried five more vulnerabilities. All five predate 2026. Two are Red Hat flaws from 2015. The rest: a Microsoft SQL Server bug from 2019, an Ajax.NET Professional deserialization flaw from 2021, and a Linux kernel out-of-bounds write from 2022. Four carry a September 9 federal deadline. The SQL Server flaw is due August 29. None of these are discovery problems. Your scanner has reported them for years. They live in the exceptions register, on the appliance nobody owns, on the box someone marked compensating-controlled in 2019 and never reopened. Run this week's additions against your exception list, not your patch queue. That is where they will be.

Your LTSB 2016 estate has 46 days.

Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise LTSB 2016 stop receiving security updates on October 13. Windows Server 2016 follows on January 12, 2027. Extended Security Updates have been purchasable since April 1 through Volume Licensing or a CSP partner, for up to three years. So the decision date is not October. It is now, because procurement is the long pole, not patching. LTSB is also the SKU nobody has a clean count of. It runs the imaging console, the plant floor terminal, the kiosk and the lab instrument. That estate reports to a business unit, not to the endpoint team, which is why the CMDB number is usually wrong. Ask the business units for the count this week.

THE NUMBER: $89.0 billion

Nvidia reported $89.0 billion in data center revenue for the quarter ended July 26, inside $96.2 billion total, and guided to $108.0 billion next quarter. Treat that as the cost base underneath every per-token price you are quoted. The industry selling you inference is standing up a capital structure it has to recover. So "the price comes down over time" is an assumption, not a trend. Price your three-year agent workloads against a flat unit cost. If your business case only works on a falling one, you are betting on somebody else's margin decision.

Agent cost and agent governance are arriving together in what DoGood network members are putting in front of vendors this month. The question they keep landing on is not what the agent costs. It is who is allowed to stop it.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.