Founders Return for the Last Stand as EU Cyber Rules Kick In
6 min read · 16 sources
- Founders are returning to lead pre-AI B2B companies because AI is forcing a "last stand" moment, per SaaStr.
- EU Cyber Resilience Act incident reporting obligations begin September 11, 2026, applying to all manufacturers regardless of size.
- Sequoia told 80 portfolio founders that owning AI models down to the weights is now a performance edge, not a sacrifice.
- Vercel introduced flat-rate CDN pricing, replacing usage-based metering for Pro customers.
- Only 3% of VCs have ten or more successful investments, and the top 1% capture over half of all net profits.
Only 3% of VCs have ten or more successful investments, and the top 1% capture over half of all net profits.
Founders Are Coming Back, and It's the Last Stand
SaaStr’s Jason Lemkin sees a pattern: founders are returning to run their pre-AI B2B companies. Not because boards panicked over a bad quarter, but because AI is a generational shift and the incumbents need the original vision to navigate it. Lemkin calls it “the last stand” - the moment where the founder’s deep domain knowledge and willingness to make painful cuts matter more than any hired CEO’s playbook.
The contrast is Twilio, which grew 22% last quarter (17% organic) and raised its full-year guidance by four points under a professional CEO. That’s a company where the machine works. The founder-return trend is for companies where AI is a headwind, especially seat-priced SaaS products getting squeezed by AI-native alternatives. If you’re a founder sitting on the sidelines while your old company faces that, Lemkin suggests you’re the only one who can do what needs doing.
EU Cyber Resilience Act: Reporting Starts September 11
The Cyber Resilience Act’s incident reporting obligations kick in on September 11, 2026, even though most other requirements land in December 2027. If you make any product with digital elements sold in the EU, you now have to report actively exploited vulnerabilities and incidents. The first warning is due within 24 hours of discovery, and a fuller report follows 72 hours later.
There’s no revenue threshold - a five-person startup with one EU customer is inside the rule. This is a significant operational change for small shops that never had a security incident response process. If you’re shipping anything connected to the EU market, today is the day to check your reporting workflow, because the clock starts now.
Sequoia's New Line: Own Your AI Models
Sequoia’s Sonya Huang gave a talk to 80 portfolio founders titled “Own Your Intelligence,” arguing that the old assumption is dead. Previously, building your own AI models was a performance sacrifice - you’d get worse results than OpenAI or Anthropic, so you rented. Huang claims that’s no longer true. Open-weight models like Qwen and GLM are close enough to the frontier that you can start there and fine-tune past the API-only options.
The four-step roadmap: pick an open-weight base, fine-tune on your proprietary data, deploy on your own infrastructure, and iterate. The pitch is that owning the weights turns your data into a moat, while renting from an API provider means your differentiation evaporates the moment a competitor uses the same model. For engineers, this is a shift from “prompt engineering” to actual model customization - a different skillset and a different cost structure.
Vercel Goes Flat-Rate for CDN
Vercel is changing Pro pricing for CDN from usage-based to flat-rate. The company says customers kept getting surprised by bandwidth bills, which made growth feel like a punishment. Under the old model, a viral launch or a spike in traffic meant a painful invoice. Now Pro customers pay a predictable monthly fee regardless of how much data moves.
This is a direct response to the anxiety every developer has felt watching a CDN bill climb. Vercel’s bet is that predictability is worth more than metering precision, and it removes the “should I be worried about this?” question from the deploy process. If you’re running on Vercel Pro, your CDN costs just became a fixed line item.
The New Moats Are the Old Moats
A short post from Josh Elman makes the case that AI doesn’t create new defensive strategies. The moats are still network effects, marketplaces, and platforms. The underlying tech is incredible, but almost every AI product being built today is single-player - a user talks to a model, gets an answer, and leaves. That’s not a moat.
The challenge is that AI products are vulnerable to rapid switching as model performance changes. If your only differentiator is “we use a better model,” you lose the day a competitor uses the same one. The moat comes from getting multiple users interacting with each other, from creating a marketplace where supply and demand meet, or from building a platform others depend on. AI is the feature, not the business.
Firing People: The Manager's Uncomfortable Duty
A personal essay from a VC-turned-founder covers the first time they fired someone - and botched it so badly the employee asked if they were getting a promotion minutes into the conversation. The point is that firing is a skill, and most first-time founders avoid it until it’s too late. You’re ending someone’s salary and changing their life in a way they rarely want, but if you’re not perfect at hiring (no one is), you will need to do it.
The blunt rule: you’ve failed as a manager if someone is surprised they’re being let go. If you’re retaining people who aren’t beneficial to the company, you’re failing everyone else on the team. It’s uncomfortable, but it’s the job.
Hire Every Engineer Like You'd Hire a VP
A hiring review story: 1,100 applications, 40-something phone screens, and when asked who the strongest engineer was, nobody at the table could answer. They’d filtered 1,100 people and had no idea what excellent looked like for the role. The lesson is to define “excellent” before you start filtering, and apply the same bar you’d use for a VP hire to every engineering role.
Most hiring funnels are noise. If you can’t name the best person you talked to, you haven’t been hiring - you’ve been counting.
Grok @Bot's Product Secrets
The product lead for Grok @Bot shared two decisions that made it work. First, bots can be kicked off from a phone and run while the user sleeps - that’s a fundamental design choice that enables asynchronous workflows. Second, each bot has its own computer, so it can operate tools that have no API by using the interface like a human would.
They also cut internal model thinking and memory traces from the product. Initially exposed for developer-style observability, these were removed because they confused users. The lesson: build for the user’s mental model, not your debugging convenience.
AI Can Write the Memo, But It Can't Sit in the Meeting
A post from Hitesh makes the case that AI-generated content has tells - the emojis, the single-sentence paragraphs, the “it’s not just X, it’s Y” cadence. But the real problem isn’t the style; it’s that you can’t defend work you never understood. Bryan Cantrill’s phrase for someone who pastes a language model’s output and hits publish: their intellectual fly is open.
The author is the only one who can’t see the tells. When someone asks a follow-up question in a meeting, the AI isn’t there to answer. If you’re using AI to write your memos, make sure you can defend every line, because at some point someone will ask.
Quick Links
- Lightfield is a CRM that learns what a good customer looks like - you define strategy, it builds the list and updates itself after meetings.
- How to give away free product and make money doing it - 17-minute read on the economics of free tiers.
- My biggest takeaways from Grok @Bot product lead - 5-minute read on the two early decisions that made it work.
You May Also Like
California taxes SaaS 8 - 10%, AI Mode shows pricier goods, China hands out tokens with dumplings
California signed SB 122 and from January 1, 2027 will apply a 7.25% - 10.75% sales tax to SaaS and AI tools, with the state projecting about $2B a year in …
Startup ARR is a six-month rental now, and other fundraising math that broke
New research from Madrona finds 77% of enterprises reevaluate AI vendors every six months or continuously, turning claimed ARR into a much softer number than …
The New Valley: Why $5M-$25M ARR Is Where AI Startups Go to Die
Series A financing for AI startups has hit a wall. Carta data shows just 15.4% of Q1 2022 seed companies reached a Series A within two years, down from 30.6% …




