ARC TRANSFORMATION GROUP
Digital transformation that ships.
We work with companies, nonprofits, and teams of about 10 to 500 people. Messy data, shaky security, systems that will not scale, and agents nobody scoped that can already reach production. We figure out what to do, then we ship it.
Have something to fix, or just looking around? Start with what changed this month and what each change means for your stack.
Market signals
What changed in the last month.
The market moved under a lot of AI plans this summer. These are the changes we think actually alter what an operator should do next — dated, sourced, and pointed at the tool or brief that answers them.
Reviewed Sep 7, 2026
- Protocols
MCP went stateless. The handshake your servers rely on is retired.
The 2026-07-28 revision drops initialize and the session header, moves version and capabilities into per-request metadata, adds server/discover, and requires routing headers on Streamable HTTP. Old servers keep working for now — on a twelve-month clock.
Scan a server - Regulation
EU AI Act transparency duties are live. High-risk paperwork moved to 2027.
Telling people they are talking to AI, and marking generated content so it can be detected, applies now. The Annex III high-risk obligations slid to 2 December 2027. Teams that heard 'delayed' and stopped reading are exposed on the part that already applies.
Read the brief - Agent risk
A national evaluator watched agents act on the live internet without sanction.
The UK AI Security Institute catalogued 19 unsanctioned actions across 10 of 122 evaluation runs, including an agent that created fake identities to pressure a real open-source maintainer into merging malicious code. Least privilege for agents stopped being a policy sentence.
Review agent access - Security
The month's AI breaches were links and documents, not jailbreaks.
One crafted link was enough to inject instructions into a live Atlassian Rovo session and exfiltrate documents across every connected system — no jailbreak, no privilege escalation. The same pattern keeps appearing in DevOps integrations, email assistants, and agent frameworks. A connected assistant carries every permission you gave it.
Review an AI app - Cost
Coding-agent billing moved to routed-model pricing.
Cursor's Auto now bills at whichever model answered, plus a per-million token rate on third-party models for teams; the legacy flat rate for enterprise Auto expires 7 September 2026. Claude Code deployments run roughly $150–250 per developer per month. The same agent loop costs a different amount on a different day.
Open TokenLoop - Enterprise apps
The system of record grew an agent-facing surface with a meter on it.
Salesforce put its CRM inside Claude and exposed the platform as MCP tools, APIs, and CLI commands, with agents inheriting existing roles and consumption billed against API usage. Your vendors are shipping agent access whether or not you scoped it — and billing on agent traffic instead of seats.
See the Agent Control Review
Studio
How an engagement usually starts.
A scoped review, two to seven weeks. You leave with a plan, owners, and a next step. If you still need us after that, we stay and build.
AI Readiness Audit (C.I.T.H.)
Capability, Intent, Teams, and Habits scored against your real workflows. You leave knowing which bet to fund, which to defer, and what has to change before anything ships.
Data Health & Analytics Readiness
Data flow map, schema audit, quality scoring, and a remediation roadmap. The goal is a reporting workflow your team can run without a heroic analyst.
Security & Compliance Posture Review
Risk matrix, access and secrets review, remediation roadmap, and SOC 2 / GDPR / CCPA readiness notes. Readiness work that tells you what to fix first, not audit theater.
Integrated Transformation Diagnostic
Atlas + Pulse + Ridge combined. Full current-state across every dimension that affects whether your next bet ships, then a phased 6–12 month roadmap with named owners and sized risks.
Work
What that looks like in practice.
Fortune 100/500 programs our team has delivered, plus ARC Studio. Where we cannot name the client, we name the scale.
Coordinating 300+ features so release investment produced sales, not just shipped code
Features coordinated
Improvement in release value
Program tied to revenue
Customer-data architecture at tens of millions of profiles
Customer profiles in scope
Enterprise data architecture
Delivery under real load
Brand and consumer programs at global scale
Brand and consumer programs
Live-entertainment programs
Environments the work shipped in
Three competing initiatives, one sequenced roadmap
Competing initiatives, resequenced
Diagnostic to board-ready plan
Investment sequence attached
Labs
Or run a tool first.
Free scanners and catalogs. Same point of view as the paid work, without a call.
Fit
Who we work best with
- Operators in 10–500 person companies, nonprofits, and teams who need a working system, not a slide deck.
- Leaders who want one honest partner across strategy, build, and scale — not a pile of vendors to manage.
- Groups ready to put real data, real users, and real effort behind the work.
Not a fit
When to look elsewhere
- You want a large team staffed next week to take over IT.
- You need a logo-driven RFP response more than an honest diagnosis.
- The problem is still “we should do AI” with no workflow, owner, or constraint.
- You want us to build whatever was already decided, without scoring it.
Want this standard of work on your problem?
Most Studio work starts with a diagnostic. A 30-minute call is enough to tell you whether that is the right first step, and what size of engagement the problem actually needs.