The consolidation of the data stack just accelerated — twice in one week
When we covered the completed Fivetran and dbt Labs merger in July, we suggested the modern data stack era of independent point solutions was giving way to integrated foundations. The past two weeks turned that suggestion into a trend line.
On August 26, AWS announced it was acquiring DuckLabs, the Amsterdam-based company behind DuckDB, the enormously popular in-process analytical database that many data teams use for local analysis, pipeline work, and lightweight transformation. The deal closed within days, and the entire DuckLabs team, including co-founders Hannes Mühleisen and Mark Raasveldt, joined AWS on September 1. Notably, the transaction does not include the DuckDB open-source project itself, which remains under the nonprofit DuckDB Foundation, stays MIT-licensed, and is adding a technical advisory board to give community members input on the project’s direction.
Then on September 2, NVIDIA entered a definitive agreement to acquire Hugging Face — the de facto home of open-source AI, with more than 18 million developers, over 3 million shared models, and more than 200,000 companies using the platform — for approximately $12.9 billion. The deal is expected to close in the first half of 2027, pending regulatory approval, and NVIDIA has stated Hugging Face will continue to support open-source and open-weight models.
Both acquirers went out of their way to promise continuity, and there is no reason to assume bad faith. But the structural fact remains: two of the most important pieces of open, vendor-neutral data and AI infrastructure are now owned by, or soon will be owned by, the largest cloud provider and the dominant AI chipmaker. For organizations that build on these tools, the practical checklist is the same one we offered after the Fivetran-dbt merger. Confirm the capabilities you depend on remain on the roadmap. Watch pricing and packaging over the next several quarters. And understand where the governance of the open-source project actually lives — in DuckDB’s case, the foundation structure is a meaningful protection; in others, it may not exist at all. The broader question for buyers is shifting from “which tool is best” to “how much independence does this tool retain, and how much do we need it to.”
Sources:
Power BI’s August release keeps building on the semantic model
Microsoft’s August 2026 Power BI update reads, at first glance, like routine housekeeping: an overhauled Theme pane with more control over colors, fonts, and visual defaults; chart formatting refinements; and mobile and embedded improvements. But three items continue the pattern we identified in July, when we wrote that Power BI is being rebuilt around the semantic model.
First, semantic model refresh in the Power BI Service is now more flexible, with separate options to refresh schema, data, or both — a small change that matters for teams managing large governed models, because it reduces the cost of keeping model structure and model contents in sync. Second, Direct Lake on OneLake now supports composite models, so teams can mix Direct Lake tables with Import and DirectQuery sources in one model rather than maintaining parallel versions. Third, and most significant for adoption: in early September, Fabric Apps built from the data app template will require only Read permission on the underlying semantic model, rather than Build permission. That sounds like a permissions footnote. In practice, it removes one of the main barriers to distributing data applications broadly, because consumers no longer need elevated model access just to use an app.
The through-line is the same one we have been tracking all year. Every new capability — apps, Copilot answers, AI-built reports — inherits the quality of the semantic model underneath it. Microsoft keeps lowering the friction between a governed model and the people who consume it, which raises the return on having well-governed models and raises the cost of not having them. If your organization runs on Power BI, the most valuable work available is still not building more reports. It is cleaning up the models the reports sit on.
Source:
Boston Scientific joins a pattern that is no longer possible to call isolated
On August 25, Boston Scientific identified a cybersecurity incident affecting some of its information technology systems, resulting in what the company described in its SEC filing as “a global disruption to the Company’s operations.” The disruption affected core business applications, including the ability to process and ship customer orders. As of the filing, the company had not determined a timeline for full restoration, and had not yet determined whether the incident is reasonably likely to have a material financial impact.
If this sounds familiar, it should. In our first issue, we covered a nearly identical disclosure from Stryker: a cyber incident that became, within days, an operational crisis affecting orders, manufacturing, and shipping. What has changed since May is that the pattern is now quantifiable. Between March 1 and August 18 of this year, 31 public companies filed 8-K disclosures for cybersecurity incidents, including Stryker, Coca-Cola, Medtronic, Amgen, Hasbro, and Levi Strauss. Boston Scientific makes the list longer, not different.
We include these stories in a data and analytics newsletter for a specific reason. When enterprise systems go down, the visible damage is operational — orders stop shipping. The less visible damage is informational: leadership loses the reporting, forecasting, and monitoring signals it relies on precisely when decisions are hardest. Companies that have invested in understanding their data flows — which systems feed which reports, which metrics have a single source of record, which processes can run on a degraded environment — recover their decision-making capability faster, even when system restoration takes weeks.
The planning question this raises is not “are we secure,” which belongs to the security function. It is “what does our data environment look like on day three of an outage” — which numbers leadership would still trust, which reporting would be reconstructible, and which decisions would have to be made blind. At a rate of more than one major disclosed incident per week among public companies, that is no longer a hypothetical exercise. It is a scenario with a base rate.
Sources: