GitLab shipped a spending meter for its AI agents, and the founder's trust sold $101M
Buried beneath the /goal agent command, GitLab's 19.4 release notes ship credit caps and spend alerts at 50% and 80% of monthly budgets: the vendor's own documentation of what uncapped agents cost. In the ten days to 2 October, its AI stack took a 9.9 command-execution flaw while the founder's trust sold $101.1M against one $124,802 CEO buy.
Vincent Jiang · 3 min read
The meter buried three sections down
The headline item in GitLab 19.4, released 17 September, is /goal: hand a Duo agent an objective and let it plan, execute and check its own work 1. Three sections below sit the Credit Caps screen, per-user overrides, automatic alerts when a team burns 50% and then 80% of its monthly AI spend, and a rule that included credits draw down before evaluation credits 1. A vendor that ships a meter for its own product is telling you the product has no natural stopping point.
GitHub moved Copilot to usage-based billing on 1 June; Cursor made the switch in June 2025 and refunded users after the backlash 1. GitLab shows the same pressure from the other side of the ledger: GAAP gross margin fell to 84.1% in the July quarter, a sixth straight decline, and SaaStr's operator read, relayed by SaasRise, charges 400 basis points of that slide to AI 2.
GAAP gross margin has fallen six straight quarters, to 84.1%
Data
| GAAP gross margin | |
|---|---|
| Q3 '24 | 88.7% |
| Q4 '24 | 89.2% |
| Q1 '25 | 88.3% |
| Q2 '25 | 87.9% |
| Q3 '25 | 86.8% |
| Q4 '25 | 86.6% |
| Q1 '26 | 85.8% |
| Q2 '26 | 84.1% |
A 9.9 sandbox escape sits under the meter
The credits run through the AI Gateway, and on 2 October GitLab disclosed CVE-2026-90970 in that self-hosted component 34: an authenticated Duo Agent Platform user could escape the prompt-template sandbox into command execution on the gateway host. CVSS 9.9, no workaround listed, and the second template-engine weakness in that gateway this year after a February fix also rated 9.9 34.
The platform beneath it fared worse. CVE-2026-85706, a CVSS 10.0 unauthenticated file read that needs only one public project, was patched 11 September, drew in-the-wild probes within hours, and reached CISA's exploited-vulnerabilities catalog the same day on a 14 September federal clock; watchTowr has since logged attackers dumping config and SSH files 567. GitLab has since backported the fix to end-of-life releases 5.
$101M out, $125K in
Through those weeks, the revocable trust of Sytse Sijbrandij, GitLab's co-founder and a director 28, sold 2,116,200 Class A shares for $101,089,788 across 24 to 28 September, leaving 12,785,851, under a trading plan entered 25 June, three weeks after GitLab said it would cut about 350 roles 289. The counter-signal was small: chief executive Bill Staples bought 2,677 shares at $46.62 on 30 September, about $124,802 and 0.4% of his 735,080-share holding, under a plan dated 25 September 2025 10. The stock closed 2 October at $49.78, up 32.6% on the year 9.
The trust sold $101.1M in a week; the CEO's buy was 0.12% of that
Data
| Value | |
|---|---|
| 842,084 sh, 24 Sep | $40.88M |
| 138,626 sh, 24 Sep | $6.81M |
| 281,121 sh, 25 Sep | $13.28M |
| 424,369 sh, 25 Sep | $20.4M |
| 90,995 sh, 28 Sep | $4.08M |
| 295,460 sh, 28 Sep | $13.61M |
| 43,545 sh, 28 Sep | $2.02M |
| CEO 2,677 sh, 30 Sep | $0.12M |
What the plans cannot schedule
Both trades ran on pre-set plans: the trust's predates the September patches, and the chief executive's predates all of it. GitLab says it has already fixed the gateways it runs for customers, and CISA's 2 October assessment lists the new flaw's exploitation as "none" 4. What no plan scheduled is the meter itself. On 19 October new rate limits reach free-tier users, where agentic code reviews already bill at $0.25 each, and the next quarter lands on a guide of $281 to 283 million 2. The caps tell administrators what agents cost. They do not yet tell anyone what agents cost GitLab.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.


