The Budget Opened. The Decision Froze.
-By Geoff McDonald, CEO, Ambassador

PitchBook published a piece this morning about a market I do not work in, and it describes my market exactly.
The story is about cybersecurity. CISOs have more budget than they have ever had. Fear of what AI can do in the hands of an attacker pried it loose. And they still cannot decide what to buy.
I read it twice, because the mechanism has nothing to do with security. It is what happens in any category where the money arrives before the clarity does. The budget is real. So is the paralysis. Both at the same time, in the same room, in the same quarter.
If you are running a company right now, you are living some version of this. So I want to walk through what the data actually says, and then tell you what we decided to do about it here, because the honest version of that answer is more useful to you than the confident one.
What the money actually bought:
The numbers in the PitchBook piece are worth sitting with.
SYN Ventures, a cybersecurity-focused firm, met 559 companies it had never met before during 2025. In the first six months of 2026 it met another 370. Jay Leek, the firm's managing partner and a former CISO at Blackstone, says many of them were features rather than complete products.
Across the category, startups have closed 737 venture deals worth 12.94 billion dollars so far this year.
Now sit on the other side of it. Jay Kaplan, who runs Synack, puts the buyer's position bluntly: a company can raise at a two billion dollar valuation and still be a complete stranger to the buyer it needs to reach. He calls the froth real, and says the cruel irony is that it works against the companies creating it.
It gets harder once a seller is actually in the door. Phil Venables, formerly the CISO at Goldman Sachs and now at Ballistic Ventures, points out that a large company does not have one buyer. It has a chief information security officer plus deputies running specialist functions underneath. Leek's read on the consequence is blunt: a lot of people are talking to the wrong people, and finding the right buyer is considerably harder than it was five years ago.
Megan Dubofsky at Ten Eleven Ventures names the seller's error from the other direction. The mistakes are mistaking volume for fit, getting the ideal customer profile wrong, and spending time on the wrong deals. And the thing buyers now demand, in her words, is proof of trustworthiness.
Hold that phrase. It is the most useful line in the article, and I will come back to it.
There is a last detail in the piece that most readers will skim past, and it is the one that should worry every founder in a crowded category. With so many companies offering roughly the same thing, pricing has become a race to the bottom. That is what a frozen market does. When a buyer cannot tell two vendors apart on substance, the only lever left is price, and the whole category gets cheaper without getting better.
The same pattern, one category over:
None of this stops at security. Look at what the broader enterprise AI data says about the distance between buying and doing.
The Stanford AI Index reported that 88 percent of surveyed organizations were using AI in at least one business function, while actual agent deployment sat in the single digits across nearly every function. McKinsey's 2026 read finds 62 percent of organizations at least experimenting with agents and only 23 percent scaling them in even one part of the business. Deloitte's 2026 research lands in the same place from a different angle: worker access to AI rose sharply through the year, but only about a third of organizations were using it to genuinely change a product, a process, or a business model.
And the MIT NANDA study put a number on where all that effort goes. Roughly 95 percent of custom enterprise generative AI pilots never reached production with measurable impact.

Almost everyone has bought. Almost nobody is running it.
Then there is the honesty gap, which is the part I find hardest to read. In a 2026 survey WRITER ran with Workplace Intelligence across 1,200 executives and 1,200 employees, three quarters of executives said their company's AI strategy was more for show than actual internal guidance. Nearly half described adoption as a disappointment.
Read that again as an operator rather than as a statistic. Three out of four executives are telling a researcher that the document they present to their own board is theater. Not wrong, not early. Theater.
Where the money is actually going:
Here is the part that connects the two halves of this argument, and it comes from the spend side rather than the survey side.
Zylo's SaaS Management Index tracks real enterprise software spend rather than stated intent. Its read is that the average enterprise portfolio has stopped growing in app count and now sits around three hundred applications, and that roughly half of provisioned licenses are never actually used. The average company wastes something on the order of twenty one million dollars a year on software nobody opens, and that waste figure is rising year over year rather than falling.
Inside that flat portfolio, one line item is growing fast. Zylo puts spend on AI-native applications up more than 75 percent in a single year, the fastest-growing category in the whole index.
Hold those two facts next to each other. AI-native spend is the fastest-growing line on the invoice. Twenty three percent of companies have scaled AI into even one business function.

Read together, those two numbers describe a purchasing pattern that has decoupled from an operating capability, and it has been running for about two years.
One more figure in that index is worth flagging, because it lands directly on something we have been writing about all year. Two thirds of IT leaders reported surprise charges from consumption-based AI pricing. Fixed per-seat budgets, variable per-usage bills, and nothing in between to predict the difference. The pricing unit is the trap, and AI moved the unit while most buyers were still budgeting the old way.
A second read on why the fear is so loud:
There is one more thread worth pulling, because it changes how you should weigh the pressure you are feeling this quarter.
On CNBC last Thursday, Steve Eisman argued that the AI companies publicly calling for a slowdown have a commercial motive for doing it. He said they know there are no moats around their business, and in his view they are trying to manufacture a crisis that produces regulation favorable to the largest players. He also said the era of maximizing token consumption is finished, and that open-weight models are taking real share.
I am not going to tell you whether he is right. I have no special insight into anyone's motives, and the safety argument deserves a better hearing than a blog post can give it. There are serious people on both sides of that question who have thought about it far longer than I have.
What I will say is that the answer does not change your job.
If the fear is warranted, you still have to decide what to buy. If the fear is engineered, you definitely have to decide what to buy. Either way, the urgency you are feeling is being manufactured somewhere outside your business, by people who are not accountable for your outcome.
That is worth knowing before you sign anything this quarter.
So here is how we are thinking about our own AI strategy
I will be direct about what we decided. All three of these are constraints on us, not asks of you.

We are not going to sell you another AI tool:
You already run hundreds of applications and half of those licenses are never opened. Adding one more does not help you, it helps our quarter, and those are different things. Every vendor in this market has an incentive to tell you that your problem is a missing capability, because a missing capability is something they can sell you before the end of the quarter. That is usually not your problem.
We build agents for our own team first:
Our engineers run agent tooling inside our own delivery process before anything touches a customer. That is not a marketing position, it is a sequencing decision. If we cannot make it work on people we can walk over to and ask, we have no business asking you to trust it.
It also means we find out what actually breaks, which is the part most vendors skip. The failure modes in agentic systems are not the ones in the demo. They are the boring ones. Something upstream changes shape and nothing downstream notices. A job runs twice. A handoff between two systems drops a field nobody was watching. You cannot learn those from a pilot you designed to succeed, and you should not be learning them on a customer's data.
What we build for you should make the software you already own work better together:
Most companies do not have an AI problem. They have a context problem. The customer history lives in one system, the spend in another, the outcome in a third, and no agent can be smarter than the picture it is allowed to see. Point the best model in the world at a fragmented record and you get a confident answer to the wrong question, faster than before.
Fixing the seams between the tools you already bought is less exciting than launching a new one. It is also worth considerably more. That is why the integrations layer gets as much of our attention as anything else we do, and why HiroAI is built to orchestrate across systems rather than to be one more destination you have to log into.
None of that is modesty. It is a read on where businesses actually are. Most of you are further behind your own board deck than you would like, and being sold to as though you were not is exhausting.
What I would actually do this quarter:
Since the whole point of this piece is that decisions are frozen, here is the unfreezing I would run. None of it requires buying anything.
Pick one workflow, not one technology. The 95 percent pilot failure rate says far more about scoping than about models. Choose a process that is repetitive, bounded, measurable, and forgiving of a mistake. Then ask what would have to be true for an agent to run it end to end.
Write down the number before you start. Not a productivity feeling. A number that already exists in a report somebody reads. If you cannot name the metric that should move, you are not running a pilot, you are running a demo.
Audit the context, not the capability. For that one workflow, list every system that holds a piece of the record. If the answer is more than three and none of them talk to each other, your next purchase should be a seam, not a brain.
Ask every vendor the Dubofsky question. Not what it does. What outcome it has already produced for a company that looks like yours, and who you can call about it. Proof of trustworthiness is a verifiable thing, and the answers separate very quickly.
Check who set your deadline. If the urgency traces back to a keynote, a headline, or a competitor's press release rather than to something inside your own business, you have more time than you think.
Where this is headed:
I am not going to pretend the ambition is small. The long-term bet, which I have written about at length before, is to become the most connected customer lifecycle network on the planet. Every signal a customer gives you, from every system, resolving into one picture the whole business can act on. I believe that is where this goes, and I believe the company that gets there will be the one that made itself useful inside other people's stacks first.
Because you do not get to a network by demanding that everyone rebuild around you. You get there by being genuinely useful inside the systems people already run, and earning the right to connect one more thing, and then one more after that.
Which brings it back to Dubofsky's phrase. Proof of trustworthiness. In a market this crowded and this loud, the only thing that moves a frozen decision is evidence of an outcome you already produced for somebody else.
That is a harder way to sell. It is the only one that survives the correction.
Grow. Keep. Prove.