None of it applied to everyone
How we organise
We studied 3,500+ AI-powered apps to see why some retain users better than others (RevenueCat)
RevenueCat ranked 3,519 AI-powered apps in its own subscription data by how many paying subscribers each one keeps after a year. One in four subscription apps is now AI-powered, on its count, and those apps take 41 per cent more revenue per payer in the first year than the rest. They also churn about 30 per cent faster. The average is one number over a very wide spread. The high group keeps 13.9 per cent of paid subscriptions active at a year, the middle group 5.3 per cent, and the low group 1.4 per cent. Most of that gap opens at the first renewal, where 57.9 per cent of monthly subscribers renew at the best apps and 30.2 per cent at the worst.
Finance: the category rate is the number that gets quoted, and it describes almost none of the apps inside it. A leader who takes the 41 per cent and the 30 per cent together concludes that AI products trade retention for revenue, which reads an average as a fact. The condition sits underneath it. Apps launched between 2020 and 2023 are 10.6 percentage points more common in the high group, and apps launched from 2024 are 20.2 points more common in the low one. RevenueCat reads its own low-retention profile as the playbook for turning a spike of attention into revenue: new app, no trial, weekly plan, higher price. These are consumer apps, and the rates are patterns rather than causes. An organisation selling to businesses should take the shape and leave the rates. We read the spread before the average.
Take one rate your organisation quotes about itself and find its spread. If the top and the bottom of that range differ by an order of magnitude, the average is not a fact about anything you run.
How we build
Is there a relationship between cycle time and PR throughput? (DX Research)
DX measured median pull-request cycle time against throughput per developer across more than 500 customer organisations, on data from January to July 2026. Cutting the time a change waits is supposed to raise throughput. The raw data does not show that. Organisations with similar review times ship at very different rates, and the median trend stays flat across most of the distribution. Quantile regression separates it out. At the 25th percentile of throughput there is no statistically significant relationship at all. The median shows a modest one. At the 75th and the 90th it is strong. Throughput falls only beyond about 17 hours.
Engineering: speed is worth having and it is not a universal lever. For an organisation in the bottom quarter, cutting review time changes nothing, because whatever limits it sits somewhere else. For an organisation in the top tenth it matters a great deal. The condition is the result here, not the correlation. We read the condition before the correlation, and 17 hours is a warning sign rather than a target. DX is measuring its own customers. It reports an association rather than a cause.
Find where your slowest teams lose time before funding a programme to make review faster. If they sit nowhere near 17 hours, the review queue is not what holds them.
How we assure
Fool’s Gold: defensive deception against safety-removal attacks on open-weight models (Mark Russinovich, Microsoft Azure)
Refusal in an open-weight model is removable in minutes. Abliteration projects the direction that mediates refusal out of the weights, and it runs in minutes on consumer hardware. This defence concedes that and attacks what the strip opens. The released model is trained, inside a simulation of the attack, to answer hazardous requests in the attacked state with confident, fluent answers whose critical details are false. Across the six models that passed its efficacy gate, 0.51 to 0.90 of the attacker’s answers are decoys, on prompts the defence never trained on. Clean-state behaviour and benchmark scores stay within noise.
Security: a control that cannot hold can still be made to cost an attacker something, which is a different claim from a control that works. Russinovich states the condition. The defence is inert against in-context jailbreaks by design, and it applies to first-release models only. An organisation publishing weights gets one attempt at this and none after. What it gets is doubt rather than refusal, because an attacker without an independent source of correct values cannot separate a falsified answer from a real one, and voting across draws does not recover it.
If your organisation releases model weights, make the deception decision before the first release rather than after it. A control you cannot reapply later is a decision, and it is being made either way.