An era has ended, and an era has begun.
First, a data point: in the first quarter of 2026, global financing in the AI large model sector fell 42% year over year.
But during the same period, financing in the AI application layer grew 218%.
What does it mean when these two sets of data are put together?
Investors no longer believe in "technological leadership." They have begun to believe in "scenario leadership."
Over the past two years, the narrative logic in the AI circle was very clear: whoever had the larger model parameters, the better open-source ecosystem, and the top ranking on the leaderboards was the winner.
But this logic is being completely rewritten in May and June of 2026.
In today's article, I want to use five real changes that are happening right now to tell you what this turning point means.
What is the biggest variable in the AI circle this year? Many people would say: DeepSeek.
This AI company from China, with its open-source models, has triggered phenomenal international attention. Its models approach or even surpass GPT-4-level closed-source models on multiple benchmarks, while the training cost is said to be only a fraction of the latter's.
How shocking is this?
For example: a U.S. AI startup valued at $6 billion lost 37% of its customers within three months after DeepSeek went open source. Not because DeepSeek's technology was better, but because—customers did the math and found that fine-tuning an open-source model themselves cost 80% less than API calls.
80%. This is a number enough to give any corporate CFO insomnia.
So, a very counterintuitive conclusion emerges:
Open source appears to be "free," but what it truly destroys is not the charging model, but the "wrapper business."
What is a wrapper business? It is wrapping a UI around a large model API and then charging enterprises 10 times the fee.
The open-source effect of DeepSeek has overturned the hidden cards of all such businesses: since I can deploy a private open-source model for 50,000 yuan, why would I still pay 500,000 yuan for your annual SaaS fee?
But the other side of the coin is:Open source has also made the true moat more important.
What is the true moat? Four words: industry data.
Models can be open-sourced, but your industry data cannot. The 100,000 medical records you have accumulated in healthcare, the 20 years of equipment operation logs you have accumulated in manufacturing—these are irreplaceable.
So the real result of the DeepSeek effect is not that "models are worthless," but that"the gap between closed-source models and open-source models has narrowed, while the gap between industry data and scenario understanding has widened."
This leads to the second change.
Last year I attended a CIO summit, and the organizer asked a question: "Everyone here, has your company used AI Agents?" Fewer than 10% raised their hands.
This year at the same summit, with the same question, more than 70% raised their hands.
And their answers were no longer "we are piloting," but "we have already deployed XX AI Agents in production environments."
What does this change indicate?
Enterprise-level AI Agents are moving from "proof of concept" into the "large-scale deployment" stage.
Specifically, the three most mature implementation scenarios at present:
First, customer service.This hardly needs elaboration. Data from a large bank shows that AI customer service agents handled 82% of routine inquiries, while human agents handled only the remaining 18% of complex issues. Customer satisfaction rose from 78% to 89%, because AI responds faster and is online 24/7.
Second, software development.The combination of low-code platforms + AI is restructuring development efficiency. Gartner has just released a report: enterprises using AI-assisted low-code platforms increased development efficiency by an average of 300%. Not 30%, but 300%. Features that previously took two weeks to develop are now done in three days. The reason is that AI Agents can not only generate code snippets, but also automatically complete unit testing, interface integration, and documentation writing.
Third, finance and compliance.This scenario receives little attention, but it is very interesting. More and more enterprises are training AI Agents to analyze contract terms, review reimbursement documents, and detect abnormal transactions. The CFO of a Fortune 500 company told me that their AI Agent discovered $4.2 million in abnormal expenditures in the first month—three times the amount found by manual audits over the entire previous year.
But there is one key issue that many people have overlooked—
When you actually deploy AI Agents into production environments, security and reliability are no longer "nice-to-have"—they're a matter of "life and death."
In April of this year, an incident occurred that sent chills down the spine of the entire industry.
A well-known enterprise's AI Agent, while autonomously executing tasks, mistakenly deleted the core database of the production environment. This caused the entire business system to be down for over 8 hours, with direct economic losses estimated at over 5 million USD.
What happened?
A very "simple" chain of errors: The AI Agent was authorized to perform database cleanup tasks—it discovered some "expired data"—without any secondary confirmation—directly executed the DROP operation.
Note, this was not a test environment, it wasproduction environment。
The terrifying part of this incident is that every step the AI Agent took was within its scope of permissions. The problem was not "overstepping authority," but rather"judgment"。
What is the essential difference between artificial intelligence and human employees?
Even if a human intern has database permissions, before executing a DROP command, they would have the most basic judgment: Will this operation cause problems? Should I ask first?
But AI Agents don't have this kind of "instinct." Without human confirmation, it executed an irreversible operation.
This is the most core paradox in the field of AI security:The more autonomy you give an AI Agent, the more efficient it becomes, but the greater its potential destructive power.
What to do?
The industry is forming three consensus points:
1. "Sandwich-style" permission control—AI Agents can only operate on data copies or sandbox environments. Any write operation to the real production environment must go through the intermediate layer of "human approval." Just like the two slices of bread in a sandwich enclosing the filling in the middle.
2. "Destructive operation" circuit breaker mechanism—Once an AI Agent triggers high-risk commands such as DELETE, DROP, FORMAT, the system automatically blocks and requests human confirmation, even if it is within its permission scope.
3. Behavior audit logs—Every operation, every judgment, every step of reasoning by an AI Agent must be fully recorded. Not for retrospective accountability, but for review and improvement when problems arise.
I have a bold prediction:In the next two years, spending on AI security will exceed spending on AI models themselves.
Because we are handing increasingly critical tasks to AI—this is not a question of whether to do it, but how to control the risks.
Now I want to talk about something not very related to technology, but very related to business ethics.
In January 2020, Samsung Electronics released an R-series Micro LED TV, priced at 350,000 RMB. Stunning, but no one bought it. Four years later, sales of this product were still less than 10% of expectations. Until 2024, Samsung did something many people couldn't understand—it jointly developed an "AI shopping guide" module with ChatGPT, built into the TV. A year later, R-series sales increased sixfold.
What does this case illustrate?
A good product ≠ good sales. The value of AI is not "creating better products," but"helping users better understand products". No one bought the 350,000 TV, not because the TV was bad, but because consumers didn't know why it was worth 350,000. The AI shopping guide solved this problem.
But what I want to focus on today is another story.
Boss Zhang and Boss Sun partnered to start a company, each holding 50% of the shares. Then the pandemic came, and the company needed to borrow money. Boss Zhang said: "I'll put up the money."
He lent the company 3 million, and the company wrote an IOU.
Later, Boss Sun found out about this and said: "The IOU should have both parties present." So Boss Zhang, in front of Boss Sun, tore up the IOU and said: "It's fine, there's a transfer record anyway."
Later still, the company went bankrupt and needed liquidation. Boss Sun said: "The IOU has been torn up, so this 3 million should be Boss Zhang's capital increase to the company, not a loan."
Boss Zhang was dumbfounded.
Fortunately, the process of him tearing up the IOU at that time was captured by the company's AI security camera—not only was the moment of tearing the IOU captured, but the AI system also automatically generated a tag: "Suspected destruction of financial documents."
This AI-generated tag became indirect evidence recognized in court.
In the end, the court determined that the 3 million was a loan, not a capital increase. Boss Zhang got his 3 million back.
A torn-up IOU gained a second life because of AI.
Putting these two stories together, I want to express one point:
The commercial value of AI has never been overestimated; what has been overestimated is the way it "should be used."
Samsung uses it for shopping guidance—this is "cost reduction and efficiency improvement."
Security cameras use it to identify the destruction of financial vouchers—this is "creating new value."
Both uses are correct. But only the latter is, in the true sense,"incremental value"。
AI's greatest imagination is not replacing humans, but creating an entirely new value dimension—one that did not exist before and could not be achieved at all without AI.
Finally, let's talk about a change that affects everyone.
In May 2026, the EU AI Act officially entered its first phase of implementation.
How big is the impact of this act? Look at these numbers:
• Scope: any company providing AI services within the EU, no matter where its headquarters is, is subject to it.
• Maximum fine for violations: 7% of global annual revenue or 35 million euros (whichever is higher).
• Number of companies affected: more than 20,000.
What does 7% mean? The maximum fine under GDPR is 4%. The AI Act is nearly twice as strict as GDPR.
Our team did the math: a Chinese AI company with annual revenue of 10 billion USD, if its products involve the EU market, would need at least 5 million to 10 million USD in AI compliance-related investment—including establishing an AI ethics committee, deploying explainable AI modules, preparing algorithm audit reports, and hiring AI ethics compliance officers.
Sounds expensive, right?
But think about it from another angle: a new position is emerging in the global high-end AI talent market—"AI Ethics Compliance Officer"(AI Ethics & Compliance Officer)。
This position barely existed in 2024, and in 2025 there were only just over 300 related jobs on LinkedIn. By May 2026, that number had exceeded 5,000, with a median salary of 180,000 USD per year.
Whenever a new type of job appears, it means a new market has already formed.
What is the essence of compliance? It is not adding costs to companies, but establishing a "threshold for entry" for the market. Companies that do not value data privacy, have opaque algorithms, and lack AI governance frameworks will be kicked out of the mainstream market within the next 24 months.
Compliance is never a cost. It is your ticket into the next era.
Back to the data from the beginning: model-layer financing fell 42%, while application-layer financing grew 218%.
This is not some "AI bubble bursting." This isAI going through its "college entrance exam moment"—a shift from "being able to solve many problems" (large model capabilities) to "achieving good results" (actually creating value).
In this "college entrance exam" battle, who can win? The answer I see is—
No longer the company with the largest model, but the company best able to implement scenarios.
Specifically, three core capabilities determine victory or defeat:
1. Industry data accumulation capability—Models can be bought and can be open-sourced, but truly valuable data can only be generated within the industry. Whoever has higher data quality and fuller coverage will have smarter AI.
2. AI security governance capability—From AI Agents mistakenly deleting databases to the EU act taking effect, security compliance has already changed from a "bonus item" to a "mandatory item." Companies without a security governance framework do not even have the qualifications to sit at the table.
3. Scenario understanding and implementation capability—Understanding the pain points of an industry is much harder than understanding the technical architecture of a model. There are many people who understand AI, but few who understand "AI + industry." The gap in between is the business opportunity.
Finally, I want to say one thing to everyone who is paying attention to AI:
Don't ask "what can AI do," ask "what specific problem do I want AI to help me solve."
The former question will turn you into a spectator.
The latter question will turn you into a player.
2026 is the year when spectators exit and players enter.
Are you ready?