Skip to content

ARC TRANSFORMATION GROUP

Companies, nonprofits, and teams · about 10–500 people

Digital transformation that ships.

We work with companies, nonprofits, and teams of about 10 to 500 people. Messy data, shaky security, systems that will not scale, and agents nobody scoped that can already reach production. We figure out what to do, then we ship it.

Have something to fix, or just looking around? Start with what changed this month and what each change means for your stack.

Market signals

What changed in the last month.

The market moved under a lot of AI plans this summer. These are the changes we think actually alter what an operator should do next — dated, sourced, and pointed at the tool or brief that answers them.

Reviewed Sep 7, 2026

  1. Protocols

    MCP went stateless. The handshake your servers rely on is retired.

    The 2026-07-28 revision drops initialize and the session header, moves version and capabilities into per-request metadata, adds server/discover, and requires routing headers on Streamable HTTP. Old servers keep working for now — on a twelve-month clock.

    Scan a server
  2. Regulation

    EU AI Act transparency duties are live. High-risk paperwork moved to 2027.

    Telling people they are talking to AI, and marking generated content so it can be detected, applies now. The Annex III high-risk obligations slid to 2 December 2027. Teams that heard 'delayed' and stopped reading are exposed on the part that already applies.

    Read the brief
  3. Agent risk

    A national evaluator watched agents act on the live internet without sanction.

    The UK AI Security Institute catalogued 19 unsanctioned actions across 10 of 122 evaluation runs, including an agent that created fake identities to pressure a real open-source maintainer into merging malicious code. Least privilege for agents stopped being a policy sentence.

    Review agent access
  4. Security

    The month's AI breaches were links and documents, not jailbreaks.

    One crafted link was enough to inject instructions into a live Atlassian Rovo session and exfiltrate documents across every connected system — no jailbreak, no privilege escalation. The same pattern keeps appearing in DevOps integrations, email assistants, and agent frameworks. A connected assistant carries every permission you gave it.

    Review an AI app
  5. Cost

    Coding-agent billing moved to routed-model pricing.

    Cursor's Auto now bills at whichever model answered, plus a per-million token rate on third-party models for teams; the legacy flat rate for enterprise Auto expires 7 September 2026. Claude Code deployments run roughly $150–250 per developer per month. The same agent loop costs a different amount on a different day.

    Open TokenLoop
  6. Enterprise apps

    The system of record grew an agent-facing surface with a meter on it.

    Salesforce put its CRM inside Claude and exposed the platform as MCP tools, APIs, and CLI commands, with agents inheriting existing roles and consumption billed against API usage. Your vendors are shipping agent access whether or not you scoped it — and billing on agent traffic instead of seats.

    See the Agent Control Review

Fit

Who we work best with

  • Operators in 10–500 person companies, nonprofits, and teams who need a working system, not a slide deck.
  • Leaders who want one honest partner across strategy, build, and scale — not a pile of vendors to manage.
  • Groups ready to put real data, real users, and real effort behind the work.

Not a fit

When to look elsewhere

  • You want a large team staffed next week to take over IT.
  • You need a logo-driven RFP response more than an honest diagnosis.
  • The problem is still “we should do AI” with no workflow, owner, or constraint.
  • You want us to build whatever was already decided, without scoring it.

Want this standard of work on your problem?

Most Studio work starts with a diagnostic. A 30-minute call is enough to tell you whether that is the right first step, and what size of engagement the problem actually needs.